Skip to content

Close HID connections when device initialization fails - #295

Open
FiraSenax wants to merge 1 commit into
Yubico:mainfrom
FiraSenax:codex/close-failed-hid-open
Open

FiraSenax wants to merge 1 commit into
Yubico:mainfrom
FiraSenax:codex/close-failed-hid-open

Conversation

@FiraSenax

Copy link
Copy Markdown

When the CTAPHID INIT handshake raises after open_connection() succeeds, open_device() and CtapHidDevice.list_devices() never return a device that the caller can close. The connection remains open. This can happen during a disconnect or a failed initial exchange.

Route both factories through a small classmethod that closes the connection on construction failure and re-raises the original exception. A cleanup error does not replace the initialization error. Successful construction still transfers ownership to the returned device, and enumeration preserves cls construction. The public constructor's handling of caller-provided connections is unchanged.

Validation on macOS / Python 3.11:

  • Added tests for both factories: initialization failure, interruption, cleanup failure and successful ownership transfer. Eight failure cases fail before the fix and pass afterward.
  • pytest tests --ignore=tests/device -q: 160 passed.
  • Ruff lint/format checks and git diff --check: passed for the changed files.

The new tests mock HID I/O and do not access physical authenticators. Native hardware/other-platform execution has not been tested for this patch.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant