Skip to content

feat: add FuseV1Options.EnableDeviceBoundSessions - #138

Open
MarshallOfSound wants to merge 1 commit into
mainfrom
sam/enable-device-bound-sessions
Open

MarshallOfSound wants to merge 1 commit into
mainfrom
sam/enable-device-bound-sessions

Conversation

@MarshallOfSound

Copy link
Copy Markdown
Member

Adds FuseV1Options.EnableDeviceBoundSessions (index 9) for the deviceBoundSessions fuse in electron/electron#54074, which enables Device Bound Session Credentials.

  • src/config.ts, src/index.ts: the new option and its slot in the fuse wire.
  • README.md: the example config lists it.
  • Tests: flipFuses() sets the fuse on a wire with room for it, rejects it on a 9-fuse wire, and leaves it alone when not configured. These use a small fake binary because no released Electron has the fuse yet. The all-fuses test against a real release carries a @ts-expect-error until one does.

Safe to merge before the Electron change ships: older binaries have a shorter wire and ignore the new entry unless it is explicitly configured.

Adds the option for the deviceBoundSessions fuse, which enables Device
Bound Session Credentials in Electron. Binaries whose fuse wire is
shorter ignore it unless it is explicitly configured.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Additional findings (outside the current diff — GitHub can't attach inline comments there):

  • 🔴 src/config.ts — Adding EnableDeviceBoundSessions=9 to FuseV1Options makes the strictlyRequireAllFuses:true branch's Record<FuseV1Options, T> (config.ts:34-36) require a value for fuse 9 too, but any config key >= the real wire length is rejected at runtime by buildFuseV1Wire (src/index.ts:20-29), and no released Electron has a wire longer than 9 entries yet. So once a strictlyRequireAllFuses consumer upgrades and fixes the resulting TS error by adding the new key, flipFuses throws 'Trying to configure EnableDeviceBoundSessions but the fuse wire ... is not long enough' against every currently released Electron. …

    Extended reasoning...

    …Fix: keep strictlyRequireAllFuses's required-key set in sync with what the target binary's wire actually supports, e.g. exclude fuses newer than the wire length from the Record requirement, instead of unconditionally widening it to every enum member.

    test/index.spec.ts:172 has to add a @ ts-expect-error to keep compiling against real Electron 41.0.0-beta.4, proving Record<FuseV1Options,T> now forces key 9 into every strictlyRequireAllFuses config. A real library consumer using strictlyRequireAllFuses:true with all 9 prior fuses set will get a TS compile error on upgrade (missing property 9). Adding [FuseV1Options.EnableDeviceBoundSessions]: true/false to fix the type error puts key '9' into nonVersionConfig. buildFuseV1Wire (src/index.ts:20-22) computes badFuseOption = Object.keys(nonVersionConfig).find(k => parseInt(k,10) >= wireLength); since every shipped Electron's wireLength is 9 (indices 0-8), 9 >= 9 is true. This throws 'Trying to configure EnableDeviceBoundSessions but the fuse wire in this version of Electron is not long enough' (src/index.ts:24-28) for every real binary,…

    Verification: normal. Adding EnableDeviceBoundSessions=9 to the numeric enum (src/config.ts:18) makes the strict branch Record<FuseV1Options, T> & { strictlyRequireAllFuses: true } (src/config.ts:34-36) require key 9 in every config. The PR itself proves this: test/index.spec.ts:172 had to add @ ts-expect-error to the pre-existing "all fuse configurations" strict test because the type now demands key…

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants