fix(qr): accept a one-frame invitation; release v5.9.1
CodeQL Analysis / Analyze CodeQL (push) Canceled after 0s
Deploy Application / deploy (push) Canceled after 0s
Mirror to Codeberg / mirror (push) Canceled after 0s
Mirror to PrivacyGuides / mirror (push) Canceled after 0s

The scanner waited for four frames when shown a single one. Its chunk assembler
was written for SB1, which the generator always cuts into exactly four frames,
and its fallback branch claims any non-JSON string longer than 100 characters —
which a 151-character SBQ2 invitation is. A complete invitation was filed as
chunk 1 of 4, and the scan never finished.

SBQ2 payloads are now recognised as complete before any assembly runs, in both
the text and raw-byte forms, and the hard-coded frame count is marked as
belonging to SB1 so it is not read as a general rule.
This commit is contained in:
lockbitchat
2026-08-06 23:32:20 -04:00
parent 808fd99b73
commit 556727eb6f
13 changed files with 179 additions and 43 deletions
+2 -2
View File
@@ -7,7 +7,7 @@ this document describes.
| | |
| --- | --- |
| Release | v5.9.0 |
| Release | v5.9.1 |
| Protocol version | 4.1 |
| Ratchet wire version | 1 |
@@ -238,5 +238,5 @@ worse than one that reports nothing.
## Scope
This describes the browser implementation as it stands in v5.9.0. It is not a
This describes the browser implementation as it stands in v5.9.1. It is not a
substitute for independent cryptographic review.