fix(remote): 补 ReadVncServerConfig 漏读的 LogLevel(读/写/结构体三处均达 37 项全集)+VncPasswordDecrypt 短于 8 字节直接返回空串(底层 DES 按前 8 字节切片, 短输入必 panic); 新增字段数锁定与短密文防护单测
This commit is contained in:
+23
-1
@@ -2,7 +2,10 @@
|
|||||||
|
|
||||||
package remote
|
package remote
|
||||||
|
|
||||||
import "testing"
|
import (
|
||||||
|
"reflect"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
func TestGetServiceStatusNonExist(t *testing.T) {
|
func TestGetServiceStatusNonExist(t *testing.T) {
|
||||||
// 不存在的服务应返回错误(Radmin 服务普通机器上不会安装)
|
// 不存在的服务应返回错误(Radmin 服务普通机器上不会安装)
|
||||||
@@ -91,3 +94,22 @@ func TestInstallVncServerMissingExe(t *testing.T) {
|
|||||||
t.Fatal("exe 不存在时应返回错误")
|
t.Fatal("exe 不存在时应返回错误")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// TestVncServerConfigFieldCount 锁定配置字段总数:必须与本机最新版 TightVNC(2.8.x)
|
||||||
|
// 注册表 SOFTWARE\TightVNC\Server 下的 37 个值一一对应。加/删字段前先核对注册表全集,
|
||||||
|
// 并同步检查 ReadVncServerConfig / WriteVncServerConfig 的逐项覆盖(此前曾漏 LogLevel 写、
|
||||||
|
// ConnectToRdp 误读、LogLevel 漏读, 靠本测试与脚本对账拦截)。
|
||||||
|
func TestVncServerConfigFieldCount(t *testing.T) {
|
||||||
|
if got := reflect.TypeOf(VncServerConfig{}).NumField(); got != 37 {
|
||||||
|
t.Errorf("VncServerConfig 字段数 = %d, want 37(最新版注册表全集)", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestVncPasswordDecryptShortInput 短于 8 字节的密文(缺失/截断)必须返回空串而非 panic
|
||||||
|
func TestVncPasswordDecryptShortInput(t *testing.T) {
|
||||||
|
for _, data := range [][]byte{nil, {}, []byte("abc"), []byte("1234567")} {
|
||||||
|
if got := VncPasswordDecrypt(data); got != "" {
|
||||||
|
t.Errorf("VncPasswordDecrypt(len=%d) = %q, want 空串且不 panic", len(data), got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
+6
-1
@@ -40,6 +40,7 @@ func ReadVncServerConfig() (VncServerConfig, error) {
|
|||||||
config.RepeatControlAuthentication, _, _ = GetDwordValue(key, "RepeatControlAuthentication")
|
config.RepeatControlAuthentication, _, _ = GetDwordValue(key, "RepeatControlAuthentication")
|
||||||
config.LoopbackOnly, _, _ = GetDwordValue(key, "LoopbackOnly")
|
config.LoopbackOnly, _, _ = GetDwordValue(key, "LoopbackOnly")
|
||||||
config.AcceptHttpConnections, _, _ = GetDwordValue(key, "AcceptHttpConnections")
|
config.AcceptHttpConnections, _, _ = GetDwordValue(key, "AcceptHttpConnections")
|
||||||
|
config.LogLevel, _, _ = GetDwordValue(key, "LogLevel")
|
||||||
config.EnableFileTransfers, _, _ = GetDwordValue(key, "EnableFileTransfers")
|
config.EnableFileTransfers, _, _ = GetDwordValue(key, "EnableFileTransfers")
|
||||||
config.RemoveWallpaper, _, _ = GetDwordValue(key, "RemoveWallpaper")
|
config.RemoveWallpaper, _, _ = GetDwordValue(key, "RemoveWallpaper")
|
||||||
config.UseD3D, _, _ = GetDwordValue(key, "UseD3D")
|
config.UseD3D, _, _ = GetDwordValue(key, "UseD3D")
|
||||||
@@ -177,7 +178,11 @@ func VncPasswordCrypt(password string) []byte {
|
|||||||
return vncpasswd.Crypt(password)
|
return vncpasswd.Crypt(password)
|
||||||
}
|
}
|
||||||
|
|
||||||
// VncPasswordDecrypt 解密 VNC 密码
|
// VncPasswordDecrypt 解密 VNC 密码。密文恒为 8 字节(标准 VNC DES),
|
||||||
|
// 不足 8 字节(缺失/截断)直接返回空串——底层 DES 解密会按前 8 字节切片,短输入必 panic。
|
||||||
func VncPasswordDecrypt(data []byte) string {
|
func VncPasswordDecrypt(data []byte) string {
|
||||||
|
if len(data) < 8 {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
return vncpasswd.Decrypt(data)
|
return vncpasswd.Decrypt(data)
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user