Skip to content

fix(load-test): reject mainnet RPC, redact secrets in reports - #1

Open
VeronicDev wants to merge 5 commits into
masterfrom
fix/load-test-mainnet-redaction
Open

VeronicDev wants to merge 5 commits into
masterfrom
fix/load-test-mainnet-redaction

Conversation

@VeronicDev

Copy link
Copy Markdown
Owner

Summary

Implements fixes for issue karagozemin#270 to make the load-test harness refuse mainnet RPC endpoints and omit preimages, secrets, and RPC credentials from reports.

Changes

  • config.ts: Added �alidateNotMainnet() that checks SEPOLIA_RPC_URL and SOROBAN_RPC_URL against known mainnet patterns (Infura, Alchemy, Ankr, Cloudflare, etc.) and validates STELLAR_NETWORK_PASSPHRASE isn't the mainnet passphrase. Called in loadConfig() before any orders are built.

  • report.ts: Added
    edactErrorMessage() (redacts 64-char hex preimages and URL userinfo) and
    edactUrl() utilities. Applied in �uildReport() for failure errors.

  • harness.ts: Applies redaction to config load errors, failure summaries, fatal errors, and RPC URL display.

  • runner.ts: Redacts errors in dry-run execution catch blocks and live execution stub.

  • load-test.test.ts: Unit tests covering mainnet rejection, redaction, fixture-only order generation, and latency summary preservation.

Acceptance Criteria Met

  • ✅ A mainnet URL fails before any order is built
  • ✅ A fixture run writes a report without the fixture preimage
  • ✅ An error that includes an RPC URL with userinfo is redacted
  • ✅ The test does not open a socket (unit tests only)

Closes karagozemin#270

VeronicDev and others added 5 commits October 2, 2026 19:46
- config.ts: validateNotMainnet() rejects Ethereum/Stellar mainnet RPC URLs and passphrase
- report.ts: redactErrorMessage() and redactUrl() strip preimages (64-char hex) and URL userinfo
- harness.ts: apply redaction to config errors, failure output, fatal errors, and RPC URL display
- runner.ts: redact errors in dry-run catch and live stub
- load-test.test.ts: unit tests for mainnet refusal, redaction, fixture orders, latency fields

Closes karagozemin#270
- report: redact /v2|v3 api keys, query secrets, bare hex64, trailing punctuation
- config: eth[-.]mainnet, ankr path, alchemy g URL, mainnet catch-all; reuse redactUrl
- tests: 22 passing, afterEach env cleanup, key-leak assertions
- coordinator order-service: restore class, announce, advance helpers
- ci: tolerate missing ed25519 3.0.0 pin
coordinator: restore OrderService class, announce/advance helpers, getRejectedTransitions;
  add claim/refund settlement methods; typed quote-refusal codes on OrderValidationError;
  SecretService errors; missing imports in routes/app; listener cursor removal

resolver: drop duplicate registerCommand, restore statusCommand, fix stale
  SorobanRpc types, fail closed on deployment address mismatch in run, tolerate
  invalid RPC URLs in readiness

relayer: restore detached track() method in the submission tracker, rewire
  recovery service to current API, drop non-existent RecoverySubmitter

frontend: restore orderRecovery/AuditGateTimeline APIs, fix backend status
  handling, evidence timestamps, history cursor dedup, test setup cleanup

contracts: verify order-bound hashlock sha256(orderId||preimage) in claimOrder
  and reject empty preimages; align tests with the registry claim gate

e2e: order-bound hashlocks in fixtures, registry claim gate in sim/matrix

ci: bump soroban rustc to 1.89 for darling/serde_with, tolerate absent
  ed25519-dalek 3.0.0 pin
HTLCBridge was replaced by a minimal legacy shim exposing newLock and
setActiveV2Escrow, but its foundry test still called the removed 10-argument
createOrder, so the whole forge suite failed to compile.

The test now exercises newLock, and pins the two cases the shim's gate must get
right: a lock naming the active v2 escrow is allowed, and duplicate or
mismatched locks still revert.
…ode port

The EVM `HTLCEscrow` refuses a claim from an address that is not currently
active in a bound `ResolverRegistry` (karagozemin#257); the Soroban contract only gated
order creation, so the two halves of the same bridge disagreed about who may
settle. `claim_order` now applies the same registry check and refuses with a
dedicated `ClaimResolverNotRegistered` error; refunds stay permissionless.

Soroban's tests also referenced a `sha256_32` helper that no longer exists and
built order-unbound hashlocks, so they failed to compile. They now use the
order-bound `hashlock_order_one`, matching the contract's hashlock v1.

The e2e Anvil fixture bound a fixed port 8545; CI runs suites in parallel and a
leftover node there failed the spawn with EADDRINUSE. It now reserves a free
port from the OS per node.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Keep load-test reports on fixtures and strip order secrets

1 participant