diff options
| author | Yuriy Andamasov <yuriy@vyos.io> | 2026-07-03 16:01:19 +0300 |
|---|---|---|
| committer | Yuriy Andamasov <yuriy@vyos.io> | 2026-07-03 16:01:19 +0300 |
| commit | e736bccd74630a8119638e6a2a30040851d91803 (patch) | |
| tree | c2830d30ddc9d7699260ff6ce490e541b93890ac /src/migration-scripts/ipsec/4-to-5 | |
| parent | 7ec5405e5024f3f360d0d87fd753f15276fd5e54 (diff) | |
| download | vyos-1x-fix/T8859-dh-keysize-validation.tar.gz vyos-1x-fix/T8859-dh-keysize-validation.zip | |
python: T8859: raise TypeError/ValueError on invalid min_keysizefix/T8859-dh-keysize-validation
Per dmbaturin's review on
https://github.com/vyos/vyos-1x/pull/5194: the only callers of
verify_diffie_hellman_length() are its own unit tests, so the contract
can change freely. An invalid min_keysize indicates a logic error in
the calling script and should fail loudly instead of silently
returning False:
- signature is now verify_diffie_hellman_length(file: str, min_keysize: int)
- non-integer min_keysize raises TypeError (bool explicitly rejected)
- non-positive min_keysize raises ValueError
- regex pattern converted to a raw string (invalid escape sequence)
- openssl invoked with list arguments instead of an interpolated
command string, so the file path never hits a shell (CodeRabbit)
Tests updated to pass integer keysizes and extended to cover both
exception paths.
🤖 Generated by [robots](https://vyos.io)
Diffstat (limited to 'src/migration-scripts/ipsec/4-to-5')
0 files changed, 0 insertions, 0 deletions
