- testdata.test.ts runs the sync-testdata check inside npm test, so a truncated or edited vector file fails instead of running fewer cases; the quicknet_rounds and inspect_differential blocks also assert that they are not empty. - A boundary test pins the 2 MiB age header limit: exactly 2 MiB is accepted and 2 MiB + 1 byte rejected, as filippo.io/age does. - The page no longer says time_and_key needs a .dkk: the credential is a .dkk or the X25519 identity of a recipient (spec §38, §63 step 9.b). - The landing text says the guarantee rests on drand not revealing the signature early, instead of claiming nobody can open a capsule (§4). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>main
parent
4574a65c57
commit
4b0aa60277
@ -0,0 +1,17 @@
|
||||
import { execFileSync } from 'node:child_process';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
import { describe, expect, it } from 'vitest';
|
||||
|
||||
// vectors.test.ts runs whatever testdata/ holds, so the shared Go vectors are
|
||||
// only as good as their integrity: a truncated or edited file must fail here
|
||||
// rather than pass with fewer cases. The check is the one of
|
||||
// scripts/sync-testdata.mjs: every file matches the SHA-256 recorded in
|
||||
// testdata/SOURCE.json for the pinned datekeys-go commit, with none missing
|
||||
// and none extra.
|
||||
describe('testdata', () => {
|
||||
it('matches testdata/SOURCE.json byte for byte, with no missing or extra file', () => {
|
||||
const root = fileURLToPath(new URL('../../../', import.meta.url));
|
||||
const out = execFileSync(process.execPath, ['scripts/sync-testdata.mjs', 'check'], { cwd: root, encoding: 'utf8' });
|
||||
expect(out).toMatch(/^testdata: \d+ files match g\.activething\.com\/go\/DateKeys at [0-9a-f]{40}/);
|
||||
});
|
||||
});
|
||||
Loading…
Reference in new issue