From ad40329913ee46720281d0d17e650738971e1a11 Mon Sep 17 00:00:00 2001 From: dev Date: Fri, 2 Oct 2026 04:58:52 +0200 Subject: [PATCH] Test data: security_cms.json labeled with SpecVersion, and the fuzzing of CMS and DER security_cms.json says 0.11, as every file of testdata, until SpecVersion moves with the approval of the draft v0.12 whose verdicts it gives; its test checks SpecVersion. scripts/fuzz.sh runs FuzzDERCheck, FuzzParseSignature, FuzzParseToken and FuzzParseCert. Co-Authored-By: Claude Opus 5.5 --- capsule/cmsvectors_test.go | 3 ++- internal/testkit/genfixtures/cmsvectors.go | 9 +++++---- scripts/fuzz.sh | 4 ++++ testdata/vectors/security_cms.json | 2 +- 4 files changed, 12 insertions(+), 6 deletions(-) diff --git a/capsule/cmsvectors_test.go b/capsule/cmsvectors_test.go index 4888fe5..5e98765 100644 --- a/capsule/cmsvectors_test.go +++ b/capsule/cmsvectors_test.go @@ -9,6 +9,7 @@ import ( "testing" "time" + datekeys "g.activething.com/go/DateKeys" "g.activething.com/go/DateKeys/capsule" "g.activething.com/go/DateKeys/internal/testkit" ) @@ -22,7 +23,7 @@ func TestCMSVectors(t *testing.T) { if err := testkit.ReadJSON(filepath.Join("..", "testdata", "vectors", "security_cms.json"), &f); err != nil { t.Fatal(err) } - if f.Spec != "0.12" || !strings.Contains(f.Description, "v0.12") || len(f.Cases) < 100 { + if f.Spec != datekeys.SpecVersion || !strings.Contains(f.Description, "v0.12") || len(f.Cases) < 100 { t.Fatalf("spec %q, %d cases: %s", f.Spec, len(f.Cases), f.Description) } seen := map[string]bool{} diff --git a/internal/testkit/genfixtures/cmsvectors.go b/internal/testkit/genfixtures/cmsvectors.go index 7f09954..fc75106 100644 --- a/internal/testkit/genfixtures/cmsvectors.go +++ b/internal/testkit/genfixtures/cmsvectors.go @@ -58,10 +58,11 @@ var ( vecSigned = time.Date(2026, 9, 30, 12, 0, 0, 0, time.UTC) ) -// cmsVectorSpec is the version of the spec whose verdicts security_cms.json -// gives: the draft v0.12, with the profile of the certificate of §29.10 and -// the texts of §29.7. -const cmsVectorSpec = "0.12" +// cmsVectorSpec labels security_cms.json, as every file of testdata, with +// SpecVersion. Its verdicts are those of the draft v0.12, with the profile of +// the certificate of §29.10 and the texts of §29.7, which this branch +// implements: SpecVersion becomes 0.12 when the draft is approved. +const cmsVectorSpec = testkit.SpecVersion func hex32(b [32]byte) string { return hex.EncodeToString(b[:]) } diff --git a/scripts/fuzz.sh b/scripts/fuzz.sh index 7ed3cb7..da58188 100644 --- a/scripts/fuzz.sh +++ b/scripts/fuzz.sh @@ -31,6 +31,10 @@ targets=( "./locator FuzzUnmarshal" "./locator FuzzParseInfo" "./locator FuzzCheckURI" + "./internal/der FuzzDERCheck" + "./internal/cms FuzzParseSignature" + "./internal/cms FuzzParseToken" + "./internal/cms FuzzParseCert" "./capsule FuzzInspect" "./capsule FuzzEncodeImpliesDecode" ) diff --git a/testdata/vectors/security_cms.json b/testdata/vectors/security_cms.json index 95c84db..ff3c0a0 100644 --- a/testdata/vectors/security_cms.json +++ b/testdata/vectors/security_cms.json @@ -1,6 +1,6 @@ { "description": "SECURITY_CBOR with an author signature of alg 2 or a time seal of seal_type 2, the context of its capsule, and the verdicts, the result of each signer and the lines of spec v0.12 29.7, 29.10 and 29.11. Certificates and tokens are made once with test keys and the file is frozen. See testdata/README.md.", - "spec": "0.12", + "spec": "0.11", "cases": [ { "name": "alg 2: two signers, each sealed before the round time: F6",