Skip to content

Fix Python DTLS PSK handshake compatibility and probe validation - #116

Merged
QuiteYellow merged 1 commit into
QuiteYellow:scratch/test-scriptsfrom
KRZ303:krz303/purepy-psk-probe-fixes
Oct 4, 2026
Merged

QuiteYellow merged 1 commit into
QuiteYellow:scratch/test-scriptsfrom
KRZ303:krz303/purepy-psk-probe-fixes

Conversation

@KRZ303

@KRZ303 KRZ303 commented Oct 4, 2026

Copy link
Copy Markdown

This follows the Python DTLS proposal in #115.
I tested the corrected probe against my oven inside HA Core on October 3.
It authenticated with the complete 16-byte PSK identity containing a zero byte.
One GET /oic/d returned CoAP 2.05 and my oven's expected device ID.

What needed fixing

  • Keep the initial ClientHello in the transcript when the server skips the cookie exchange.
  • Accept DTLS 1.0 framing for the initial plaintext HelloVerifyRequest, while retaining DTLS 1.2 checks elsewhere.
  • Use unconnected UDP so replies from another source port can arrive.
  • Allow a fixed local port so the probe can reuse the integration's existing peer endpoint.
  • Validate response correlation, CoAP 2.05, the CBOR map, and the expected device ID before reporting success.
  • Handle empty ACKs and acknowledge separate CON responses.
  • Attempt shutdown and socket closure after success or failure.
  • Remove addresses and identity/key fingerprints from output.
  • Document the probe's required runtime dependencies: cryptography and cbor2.

Result on my oven

identity      : 16 bytes, contains a zero byte: yes
handshake     : OK in 0.1s (DTLS 1.2, ECDHE-PSK-AES128-CBC-SHA256)
GET /oic/d    : OK (2.05, CBOR map, expected device ID matched)
close_notify  : sent

The probe exited with code zero and no stderr.
I temporarily unloaded only the oven entry and restored it afterward.
The oven resumed Observe mode, and both oven and washer entries were loaded.
close_notify: sent records local UDP submission; I did not measure its receipt on the oven.

Checks

  • All 26 regression tests passed, including real OpenSSL exchanges with and without cookies.
  • Negative tests cover malformed empty CoAP messages, rejected non-HVR DTLS 1.0 records, and local-port bind failure with cleanup.
  • A separate local Mbed TLS 3.6.7 fixture passed both exchanges with encrypt-then-MAC and extended master secret disabled.
  • The README records the tested dependencies and the command for reproducing the 26-test suite.

Since the hardware run, the probe gained dependency instructions in its module docstring; its executable code and the engine are unchanged.
The additional regression tests ran offline. I did not repeat the hardware test.

This PR updates the standalone scripts on scratch/test-scripts.
Integration into the library remains separate.
The installed HA integration and protocol library were unchanged by this probe.

Preserve the ClientHello transcript and accept initial HelloVerifyRequest records with DTLS 1.0 framing.
Validate correlated CoAP responses and attempt shutdown and socket cleanup.
Add regression tests for transport failures and real OpenSSL exchanges.
Document runtime dependencies and test malformed messages, bind failures, and record-version rejection.
@KRZ303 KRZ303 closed this Oct 4, 2026
@KRZ303
KRZ303 deleted the krz303/purepy-psk-probe-fixes branch October 4, 2026 00:40
@KRZ303
KRZ303 restored the krz303/purepy-psk-probe-fixes branch October 4, 2026 00:47
@KRZ303 KRZ303 reopened this Oct 4, 2026
@QuiteYellow
QuiteYellow merged commit 961bf60 into QuiteYellow:scratch/test-scripts Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants