package capsule_test import ( "bytes" "context" "encoding/hex" "errors" "fmt" "net/http" "net/http/httptest" "strings" "sync/atomic" "testing" datekeys "g.activething.com/go/DateKeys" "g.activething.com/go/DateKeys/capsule" "g.activething.com/go/DateKeys/internal/testkit" "g.activething.com/go/DateKeys/profile" "g.activething.com/go/DateKeys/provider" "g.activething.com/go/DateKeys/provider/drand" ) // Spec §63 steps 9 and 10: a source that fetches releases over a network // verifies each response with the rules of step 10 and discards the one that // fails, so a relay whose only answer is a release of another round, or a // signature that does not verify, gives ERR_RELEASE_UNAVAILABLE at step 9. // The codes of step 10 are those of a release supplied directly, as in the // official vectors. func TestReleaseFromANetworkSource(t *testing.T) { f := loadFixture(t, "time_only") for _, tc := range []struct { name string release provider.Release direct error // the code of step 10, nil when the release is valid }{ {"the published release", f.release, nil}, {"a release of another round, signed for that round", testkit.Release(1001), datekeys.ErrRoundMismatch}, {"a negated signature", provider.Release{Round: 1000, Signature: testkit.Negated(f.release.Signature)}, datekeys.ErrReleaseInvalid}, } { var requests atomic.Int32 relay := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { requests.Add(1) fmt.Fprintf(w, `{"round":%d,"signature":"%s"}`, tc.release.Round, hex.EncodeToString(tc.release.Signature)) })) o := f.openOptions(t) o.Source = drand.NewWithHTTPClient(relay.Client(), relay.URL) step, err := openAt(t, f.dkc, o) relay.Close() switch { case requests.Load() != 1: t.Errorf("%s: %d relay requests", tc.name, requests.Load()) case tc.direct == nil && err != nil: t.Errorf("%s, from a relay: %v at step %d", tc.name, err, step) case tc.direct != nil && (!onlyCode(err, datekeys.ErrReleaseUnavailable) || step != 9): t.Errorf("%s, from a relay: got %v at step %d, want ERR_RELEASE_UNAVAILABLE alone at step 9", tc.name, err, step) } // The same release, supplied directly. o.Source = provider.ReleaseSourceFunc(func(context.Context, *profile.Profile, provider.Condition) (provider.Release, error) { return tc.release, nil }) step, err = openAt(t, f.dkc, o) if tc.direct == nil { if err != nil { t.Errorf("%s, supplied directly: %v at step %d", tc.name, err, step) } continue } expectStep(t, tc.name+", supplied directly", step, err, tc.direct, 10) } } // Spec §63 step 9: whatever the failure of the release source, the code is // ERR_RELEASE_UNAVAILABLE and the error wraps no other normative error // (errors.go). The error of a caller's source that carries another code, // several or none keeps only its text; one that wraps ERR_RELEASE_UNAVAILABLE // alone is returned as it is, with its other causes. func TestReleaseSourceErrorsAtStep9(t *testing.T) { f := loadFixture(t, "time_only") for _, tc := range []struct { name string err error kept bool // returned as it is }{ {"ERR_RELEASE_INVALID", fmt.Errorf("source: bad release: %w", datekeys.ErrReleaseInvalid), false}, {"ERR_ROUND_MISMATCH", fmt.Errorf("source: another round: %w", datekeys.ErrRoundMismatch), false}, {"ERR_INTEGRITY", fmt.Errorf("source: corrupt cache: %w", datekeys.ErrIntegrity), false}, {"ERR_RELEASE_UNAVAILABLE and ERR_RELEASE_INVALID", fmt.Errorf("source: %w: %w", datekeys.ErrReleaseUnavailable, datekeys.ErrReleaseInvalid), false}, {"no code", errors.New("source: connection refused"), false}, {"ERR_RELEASE_UNAVAILABLE and a context error", fmt.Errorf("source: %w: %w", datekeys.ErrReleaseUnavailable, context.DeadlineExceeded), true}, } { o := f.openOptions(t) calls := 0 o.Source = provider.ReleaseSourceFunc(func(context.Context, *profile.Profile, provider.Condition) (provider.Release, error) { calls++ return provider.Release{}, tc.err }) step, err := openAt(t, f.dkc, o) switch { case calls != 1: t.Errorf("%s: %d release requests", tc.name, calls) case step != 9 || !onlyCode(err, datekeys.ErrReleaseUnavailable): t.Errorf("%s: got %v at step %d, want ERR_RELEASE_UNAVAILABLE alone at step 9", tc.name, err, step) case !strings.Contains(err.Error(), tc.err.Error()): t.Errorf("%s: the text of the source's error is lost: %v", tc.name, err) case errors.Is(err, tc.err) != tc.kept || tc.kept && !errors.Is(err, context.DeadlineExceeded): t.Errorf("%s: kept whole %v, want %v: %v", tc.name, errors.Is(err, tc.err), tc.kept, err) } } } // onlyCode reports whether code is the one normative error that err wraps. func onlyCode(err error, code *datekeys.Error) bool { for _, e := range datekeys.All() { if errors.Is(err, e) != (e == code) { return false } } return true } // openAt runs the whole flow and returns the step that failed, 0 on success. func openAt(t *testing.T, dkc []byte, o capsule.OpenOptions) (int, error) { t.Helper() out, err := capsule.Open(context.Background(), discardWriter{}, bytes.NewReader(dkc), o) if out == nil { t.Fatalf("Open returned no result: %v", err) } return failedStep(t, out.Inspection.Checks, err), err }