package testkit // CMSVectorFile is testdata/vectors/security_cms.json: SECURITY_CBOR areas // with an author signature of alg 2 (CMS with certificates) or a time seal // of seal_type 2 (RFC 3161), each with the context of its capsule and the // verdicts that spec v0.11 §29.7, §29.10 and §29.11 give. The certificates // and the tokens are made once, with test keys, and the file is frozen: a // second implementation reads them and must reach the same verdicts. type CMSVectorFile struct { Description string `json:"description"` Spec string `json:"spec"` Cases []CMSVectorCase `json:"cases"` } // CMSVectorContext is what a verdict needs besides SECURITY_CBOR (§29.7): // control_commit and head_digest in hexadecimal, and round_time in RFC 3339. type CMSVectorContext struct { ControlCommit string `json:"control_commit"` HeadDigest string `json:"head_digest"` RoundTime string `json:"round_time"` } // CMSVectorCase is one case: the area, its context, and the verdicts. type CMSVectorCase struct { Name string `json:"name"` SecurityCBOR string `json:"security_cbor"` // NoContext is true when the area is read without the context of a // capsule, as a reader of v0.10 does: any signature is F1, any seal S1. NoContext bool `json:"no_context,omitempty"` Context CMSVectorContext `json:"context"` Signature string `json:"signature"` Seal string `json:"seal"` // Signers and Foreign are the results of an alg 2 signature, in the // order of SIGNERS; SealHolder and SealTime are those of a valid seal. Signers []FixtureSignerResult `json:"signers,omitempty"` Foreign []FixtureSignerResult `json:"foreign_signers,omitempty"` SealHolder string `json:"seal_holder,omitempty"` SealTime string `json:"seal_time,omitempty"` } // LocatorVectorFile is testdata/vectors/locator.json: the extension // datekeys.capsule of a .dkk and what it points to (spec v0.11, §44.1). It is // made once and frozen: the envelope and the sealed locator hold randomness. type LocatorVectorFile struct { Description string `json:"description"` Spec string `json:"spec"` // Round is the round of the DateKey of the extension, and the locator is // sealed with tlock for it: it opens with the release of that round. Round uint64 `json:"round"` DateKey string `json:"datekey"` Note string `json:"note"` // DKC is the capsule that the envelope hides, in hexadecimal. DKC string `json:"dkc"` // Rest is what is kept outside, Header what the locator carries, and Host // a file with the rest appended at HostOffset. Rest string `json:"rest"` Header string `json:"envelope_header"` Host string `json:"host"` HostOffset uint64 `json:"host_offset"` // Plaintext is the plaintext of the locator, in 4096 bytes; Sealed, the // age file with the tlock stanza; Extension, the data of datekeys.capsule. Plaintext string `json:"locator_plaintext"` Sealed string `json:"locator_sealed"` Extension string `json:"extension_data"` // The fields of the locator, for a reader that compares them. Addresses []LocatorVectorAddress `json:"addresses"` EnvelopeKey string `json:"envelope_key"` RestDigest string `json:"rest_digest"` RestSize uint64 `json:"rest_size"` CapsuleDigest string `json:"capsule_digest"` // PaddingCases give the length of the plaintext for a length of the CBOR // without key 6, around the boundaries where the CBOR length of key 6 // changes: the least multiple of 4096 that key 6 can fill exactly. PaddingCases []LocatorPaddingCase `json:"padding_cases"` // URICases give the verdict of the rules of §44.1 on an address. URICases []LocatorURICase `json:"uri_cases"` } // LocatorVectorAddress is an address of the locator. type LocatorVectorAddress struct { URI string `json:"uri"` Offset uint64 `json:"offset"` Host string `json:"host"` } // LocatorPaddingCase is a length of the CBOR without padding and the length of // the plaintext that results. type LocatorPaddingCase struct { Base int `json:"base"` Total int `json:"total"` } // LocatorURICase is an address and whether it is accepted. type LocatorURICase struct { URI string `json:"uri"` OK bool `json:"ok"` }