Test data: security_cms.json labeled with SpecVersion, and the fuzzing of CMS and DER

security_cms.json says 0.11, as every file of testdata, until SpecVersion
moves with the approval of the draft v0.12 whose verdicts it gives; its test
checks SpecVersion. scripts/fuzz.sh runs FuzzDERCheck, FuzzParseSignature,
FuzzParseToken and FuzzParseCert.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
v0.12
dev 6 days ago
parent 0e7ec36e77
commit ad40329913

@ -9,6 +9,7 @@ import (
"testing"
"time"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/capsule"
"g.activething.com/go/DateKeys/internal/testkit"
)
@ -22,7 +23,7 @@ func TestCMSVectors(t *testing.T) {
if err := testkit.ReadJSON(filepath.Join("..", "testdata", "vectors", "security_cms.json"), &f); err != nil {
t.Fatal(err)
}
if f.Spec != "0.12" || !strings.Contains(f.Description, "v0.12") || len(f.Cases) < 100 {
if f.Spec != datekeys.SpecVersion || !strings.Contains(f.Description, "v0.12") || len(f.Cases) < 100 {
t.Fatalf("spec %q, %d cases: %s", f.Spec, len(f.Cases), f.Description)
}
seen := map[string]bool{}

@ -58,10 +58,11 @@ var (
vecSigned = time.Date(2026, 9, 30, 12, 0, 0, 0, time.UTC)
)
// cmsVectorSpec is the version of the spec whose verdicts security_cms.json
// gives: the draft v0.12, with the profile of the certificate of §29.10 and
// the texts of §29.7.
const cmsVectorSpec = "0.12"
// cmsVectorSpec labels security_cms.json, as every file of testdata, with
// SpecVersion. Its verdicts are those of the draft v0.12, with the profile of
// the certificate of §29.10 and the texts of §29.7, which this branch
// implements: SpecVersion becomes 0.12 when the draft is approved.
const cmsVectorSpec = testkit.SpecVersion
func hex32(b [32]byte) string { return hex.EncodeToString(b[:]) }

@ -31,6 +31,10 @@ targets=(
"./locator FuzzUnmarshal"
"./locator FuzzParseInfo"
"./locator FuzzCheckURI"
"./internal/der FuzzDERCheck"
"./internal/cms FuzzParseSignature"
"./internal/cms FuzzParseToken"
"./internal/cms FuzzParseCert"
"./capsule FuzzInspect"
"./capsule FuzzEncodeImpliesDecode"
)

@ -1,6 +1,6 @@
{
"description": "SECURITY_CBOR with an author signature of alg 2 or a time seal of seal_type 2, the context of its capsule, and the verdicts, the result of each signer and the lines of spec v0.12 29.7, 29.10 and 29.11. Certificates and tokens are made once with test keys and the file is frozen. See testdata/README.md.",
"spec": "0.12",
"spec": "0.11",
"cases": [
{
"name": "alg 2: two signers, each sealed before the round time: F6",

Loading…
Cancel
Save

Powered by TurnKey Linux.