feat: add FuseV1Options.EnableDeviceBoundSessions - #138
MarshallOfSound wants to merge 1 commit into
Conversation
Adds the option for the deviceBoundSessions fuse, which enables Device Bound Session Credentials in Electron. Binaries whose fuse wire is shorter ignore it unless it is explicitly configured.
There was a problem hiding this comment.
Additional findings (outside the current diff — GitHub can't attach inline comments there):
-
🔴
src/config.ts— Adding EnableDeviceBoundSessions=9 to FuseV1Options makes the strictlyRequireAllFuses:true branch's Record<FuseV1Options, T> (config.ts:34-36) require a value for fuse 9 too, but any config key >= the real wire length is rejected at runtime by buildFuseV1Wire (src/index.ts:20-29), and no released Electron has a wire longer than 9 entries yet. So once a strictlyRequireAllFuses consumer upgrades and fixes the resulting TS error by adding the new key, flipFuses throws 'Trying to configure EnableDeviceBoundSessions but the fuse wire ... is not long enough' against every currently released Electron. …Extended reasoning...
…Fix: keep strictlyRequireAllFuses's required-key set in sync with what the target binary's wire actually supports, e.g. exclude fuses newer than the wire length from the Record requirement, instead of unconditionally widening it to every enum member.
test/index.spec.ts:172 has to add a @ ts-expect-error to keep compiling against real Electron 41.0.0-beta.4, proving Record<FuseV1Options,T> now forces key 9 into every strictlyRequireAllFuses config. A real library consumer using strictlyRequireAllFuses:true with all 9 prior fuses set will get a TS compile error on upgrade (missing property 9). Adding [FuseV1Options.EnableDeviceBoundSessions]: true/false to fix the type error puts key '9' into nonVersionConfig. buildFuseV1Wire (src/index.ts:20-22) computes badFuseOption = Object.keys(nonVersionConfig).find(k => parseInt(k,10) >= wireLength); since every shipped Electron's wireLength is 9 (indices 0-8), 9 >= 9 is true. This throws 'Trying to configure EnableDeviceBoundSessions but the fuse wire in this version of Electron is not long enough' (src/index.ts:24-28) for every real binary,…
Verification: normal. Adding EnableDeviceBoundSessions=9 to the numeric enum (src/config.ts:18) makes the strict branch
Record<FuseV1Options, T> & { strictlyRequireAllFuses: true }(src/config.ts:34-36) require key9in every config. The PR itself proves this: test/index.spec.ts:172 had to add@ ts-expect-errorto the pre-existing "all fuse configurations" strict test because the type now demands key…
Adds
FuseV1Options.EnableDeviceBoundSessions(index 9) for thedeviceBoundSessionsfuse in electron/electron#54074, which enables Device Bound Session Credentials.src/config.ts,src/index.ts: the new option and its slot in the fuse wire.README.md: the example config lists it.flipFuses()sets the fuse on a wire with room for it, rejects it on a 9-fuse wire, and leaves it alone when not configured. These use a small fake binary because no released Electron has the fuse yet. The all-fuses test against a real release carries a@ts-expect-erroruntil one does.Safe to merge before the Electron change ships: older binaries have a shorter wire and ignore the new entry unless it is explicitly configured.