You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
DateKeys-App/testdata/vectors/resolved_ip.json

288 lines
10 KiB

{
Specification 0.16 draft: a seal without accuracy, drand's JSON read strictly The draft v0.16 of datekeys-go at 4f78854 (branch v0.16): SPEC_VERSION 0.16, and testdata, wordlists and annex synced from that commit. The annex is §79 of the draft, with the CC BY-ND 4.0 license of the specification in its title and the key of words in 79.7. A seal without accuracy proves nothing before the opening date (§29.7, §29.11, as 7e3b810): a valid seal is S4 only when its token carries accuracy and t plus the accuracy is before round_time; otherwise S5, with the first reason that holds: late, no accuracy under the BTSP policy of ETSI EN 319 421 (0.4.0.2023.1.1), or no accuracy. cms.ts reads hasAccuracy and the policy of the token (tokenIsBTSP); securitycms.ts gives SealReason, Detail.sealReason and SignerLine.reason; S5 has no fixed text any more, and verdictLines writes it and the line of a signer of F6 with the reason, the texts of Go byte for byte (sealReasonText). encryptFiles returns the verdicts of the area it wrote in Encrypted.security, as Result.Security of Go, so that a writer warns of a seal without accuracy (§62.1 rule 19). drand's JSON is read strictly (§47.1, as b570338): parseDrandJSON, as ParseDrandJSON of Go, reads RFC 8259 JSON in valid UTF-8 whose value is an object, with no name repeated in any object, names compared exactly once their escapes are decoded, a lone escaped surrogate malformed, the round a number without sign, fraction or exponent from 1 to 2^53 - 1, and signature and randomness strings, with the error texts of Go. ParsedRelease is now a Release: no round above 2^53 - 1 is read. The page reads the answers of the relays with it (drand.ts), as the client of Go does, and the pasted release with strictJSON and jsonRound (release-input.ts), so that it never reads another round than step 10. Tests: security_cms.json with seal_reason (143 cases), the 38 JSON inputs of release.json, the new cases of signature2_test.go and drandjson_test.go (with the escapes written as escapes), and the new fixtures: format3_time_and_key_words opens with the identity that the words of its words_text give with normalizeWords and wordKey, in the library and in the page, and format3_full_chunk, whose PAYLOAD_AGE ends in a full STREAM chunk, opens. check-build.mjs counts words_text among the secrets of the fixtures. Reference files made again with Go at 4f78854: mutation-texts.json (its spec field only), ibe-vectors.json (the two new fixtures, the rest unchanged) and signing-vectors.json, in an export of 4f78854 with the same frozen samples read again: the capsules are the same, and the tokens of the sealer, without accuracy, now give S5. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
5 hours ago
"spec": "0.16",
"description": "The IP address that the name of an https address of a locator resolves to, and whether a reader may connect (spec v0.13, 44.1): a public address, or an address of NAT64 (RFC 6052) of 64:ff9b::/96 or of the NAT64 prefix of the network, whose IPv4 address inside is public. See testdata/README.md.",
"cases": [
{
"name": "a public IPv4 address",
"ip": "203.0.114.5",
"nat64": "",
"result": "ok"
},
{
"name": "a public IPv6 address",
"ip": "2a01:4f8::1",
"nat64": "",
"result": "ok"
},
{
"name": "a private IPv4 address",
"ip": "192.168.1.10",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to 192.168.1.10, an IP address that is not public"
},
{
"name": "loopback",
"ip": "127.0.0.1",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to 127.0.0.1, an IP address that is not public"
},
{
"name": "IPv6 loopback",
"ip": "::1",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to ::1, an IP address that is not public"
},
{
"name": "an IPv6 link-local address",
"ip": "fe80::1",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to fe80::1, an IP address that is not public"
},
{
"name": "an IPv6 unique local address",
"ip": "fd00::1",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to fd00::1, an IP address that is not public"
},
{
"name": "an IPv4-mapped address of a public IPv4 address",
"ip": "::ffff:203.0.114.5",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to ::ffff:203.0.114.5, an IP address that is not public"
},
{
"name": "6to4",
"ip": "2002:cb00:7205::1",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to 2002:cb00:7205::1, an IP address that is not public"
},
{
"name": "Teredo",
"ip": "2001:0:cb00:7205::1",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to 2001:0:cb00:7205::1, an IP address that is not public"
},
{
"name": "the well-known prefix with a public IPv4 address",
"ip": "64:ff9b::cb00:7205",
"nat64": "",
"result": "ok"
},
{
"name": "the well-known prefix with 8.8.8.8",
"ip": "64:ff9b::808:808",
"nat64": "",
"result": "ok"
},
{
"name": "the well-known prefix with an IPv4 address of 10.0.0.0/8",
"ip": "64:ff9b::a00:1",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to 64:ff9b::a00:1, an address of NAT64 that holds 10.0.0.1, an IP address that is not public"
},
{
"name": "the well-known prefix with 192.168.1.10",
"ip": "64:ff9b::c0a8:10a",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to 64:ff9b::c0a8:10a, an address of NAT64 that holds 192.168.1.10, an IP address that is not public"
},
{
"name": "the well-known prefix with loopback",
"ip": "64:ff9b::7f00:1",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to 64:ff9b::7f00:1, an address of NAT64 that holds 127.0.0.1, an IP address that is not public"
},
{
"name": "the well-known prefix with 169.254.169.254",
"ip": "64:ff9b::a9fe:a9fe",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to 64:ff9b::a9fe:a9fe, an address of NAT64 that holds 169.254.169.254, an IP address that is not public"
},
{
"name": "the well-known prefix with 100.64.0.1",
"ip": "64:ff9b::6440:1",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to 64:ff9b::6440:1, an address of NAT64 that holds 100.64.0.1, an IP address that is not public"
},
{
"name": "the well-known prefix with 0.0.0.0",
"ip": "64:ff9b::",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to 64:ff9b::, an address of NAT64 that holds 0.0.0.0, an IP address that is not public"
},
{
"name": "the well-known prefix with 255.255.255.255",
"ip": "64:ff9b::ffff:ffff",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to 64:ff9b::ffff:ffff, an address of NAT64 that holds 255.255.255.255, an IP address that is not public"
},
{
"name": "the well-known prefix with a documentation address",
"ip": "64:ff9b::cb00:7105",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to 64:ff9b::cb00:7105, an address of NAT64 that holds 203.0.113.5, an IP address that is not public"
},
{
"name": "an address of 64:ff9b::/16 outside 64:ff9b::/96",
"ip": "64:ff9b::1:cb00:7205",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to 64:ff9b::1:cb00:7205, an IP address that is not public"
},
{
"name": "the local-use prefix of RFC 8215 without the prefix of the network",
"ip": "64:ff9b:1::cb00:7205",
"nat64": "",
"result": "error",
"error": "locator: an https address whose name resolves to 64:ff9b:1::cb00:7205, an IP address that is not public"
},
{
"name": "the well-known prefix, given as the prefix of the network",
"ip": "64:ff9b::cb00:7205",
"nat64": "64:ff9b::/96",
"result": "ok"
},
{
"name": "the well-known prefix with another prefix of the network",
"ip": "64:ff9b::cb00:7205",
"nat64": "64:ff9b:1::/48",
"result": "ok"
},
{
"name": "the local-use prefix of RFC 8215, /48",
"ip": "64:ff9b:1:cb00:72:500::",
"nat64": "64:ff9b:1::/48",
"result": "ok"
},
{
"name": "the local-use prefix, /48, with a private IPv4 address",
"ip": "64:ff9b:1:c0a8:1:a00::",
"nat64": "64:ff9b:1::/48",
"result": "error",
"error": "locator: an https address whose name resolves to 64:ff9b:1:c0a8:1:a00::, an address of NAT64 that holds 192.168.1.10, an IP address that is not public"
},
{
"name": "the local-use prefix, /48, with bits 64 to 71 set",
"ip": "64:ff9b:1:cb00:172:500::",
"nat64": "64:ff9b:1::/48",
"result": "error",
"error": "locator: an https address whose name resolves to 64:ff9b:1:cb00:172:500::, an address of the NAT64 prefix 64:ff9b:1::/48 whose bits 64 to 71 are not zero"
},
{
"name": "a public prefix of the network, /96",
"ip": "2a01:4f8:c0:64::cb00:7205",
"nat64": "2a01:4f8:c0:64::/96",
"result": "ok"
},
{
"name": "a public prefix of the network, /96, with a private IPv4 address",
"ip": "2a01:4f8:c0:64::c0a8:10a",
"nat64": "2a01:4f8:c0:64::/96",
"result": "error",
"error": "locator: an https address whose name resolves to 2a01:4f8:c0:64::c0a8:10a, an address of NAT64 that holds 192.168.1.10, an IP address that is not public"
},
{
"name": "a public prefix of the network, /96, with loopback",
"ip": "2a01:4f8:c0:64::7f00:1",
"nat64": "2a01:4f8:c0:64::/96",
"result": "error",
"error": "locator: an https address whose name resolves to 2a01:4f8:c0:64::7f00:1, an address of NAT64 that holds 127.0.0.1, an IP address that is not public"
},
{
"name": "a public prefix of the network, /32",
"ip": "2a01:4f8:cb00:7205::",
"nat64": "2a01:4f8::/32",
"result": "ok"
},
{
"name": "a public prefix of the network, /40",
"ip": "2a01:4f8:c0cb:72:5::",
"nat64": "2a01:4f8:c000::/40",
"result": "ok"
},
{
"name": "a public prefix of the network, /56",
"ip": "2a01:4f8:c0:64cb:0:7205::",
"nat64": "2a01:4f8:c0:6400::/56",
"result": "ok"
},
{
"name": "a public prefix of the network, /64",
"ip": "2a01:4f8:c0:64:cb:72:500:0",
"nat64": "2a01:4f8:c0:64::/64",
"result": "ok"
},
{
"name": "a public prefix of the network, /64, with a private IPv4 address",
"ip": "2a01:4f8:c0:64:c0:a801:a00:0",
"nat64": "2a01:4f8:c0:64::/64",
"result": "error",
"error": "locator: an https address whose name resolves to 2a01:4f8:c0:64:c0:a801:a00:0, an address of NAT64 that holds 192.168.1.10, an IP address that is not public"
},
{
"name": "a public address outside the prefix of the network",
"ip": "2a01:4f8::1",
"nat64": "64:ff9b:1::/48",
"result": "ok"
},
{
"name": "a prefix of the network of 80 bits",
"ip": "64:ff9b:1::cb00:7205",
"nat64": "64:ff9b:1::/80",
"result": "error",
"error": "locator: the NAT64 prefix 64:ff9b:1::/80 is not of 32, 40, 48, 56, 64 or 96 bits (RFC 6052)"
},
{
"name": "a link-local prefix of the network",
"ip": "fe80::cb00:7205",
"nat64": "fe80::/96",
"result": "error",
"error": "locator: the NAT64 prefix fe80::/96 is neither in 64:ff9b::/16 nor a public IPv6 prefix"
},
{
"name": "a unique local prefix of the network",
"ip": "fd00::cb00:7205",
"nat64": "fd00::/96",
"result": "error",
"error": "locator: the NAT64 prefix fd00::/96 is neither in 64:ff9b::/16 nor a public IPv6 prefix"
},
{
"name": "a prefix of the network of 2001:db8::/32",
"ip": "2001:db8::cb00:7205",
"nat64": "2001:db8::/96",
"result": "error",
"error": "locator: the NAT64 prefix 2001:db8::/96 is neither in 64:ff9b::/16 nor a public IPv6 prefix"
},
{
"name": "a prefix of the network with bits after its length",
"ip": "64:ff9b::cb00:7205",
"nat64": "64:ff9b::1/96",
"result": "error",
"error": "locator: the NAT64 prefix 64:ff9b::1/96 has bits set after its length"
},
{
"name": "an IPv4 prefix of the network",
"ip": "203.0.114.5",
"nat64": "203.0.114.0/24",
"result": "error",
"error": "locator: the NAT64 prefix 203.0.114.0/24 is not an IPv6 prefix"
}
]
}

Powered by TurnKey Linux.