You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
163 lines
6.9 KiB
163 lines
6.9 KiB
package testkit
|
|
|
|
// CMSVectorFile is testdata/vectors/security_cms.json: SECURITY_CBOR areas
|
|
// with an author signature of alg 2 (CMS with certificates) or a time seal
|
|
// of seal_type 2 (RFC 3161), each with the context of its capsule and the
|
|
// verdicts, the results and the lines that spec v0.16 §29.7, §29.10 and
|
|
// §29.11 give. The certificates and the tokens are made once, with test
|
|
// keys, and the file is frozen: a second implementation reads them and must
|
|
// reach the same verdicts and write the same lines, byte for byte.
|
|
type CMSVectorFile struct {
|
|
Description string `json:"description"`
|
|
Spec string `json:"spec"`
|
|
Cases []CMSVectorCase `json:"cases"`
|
|
}
|
|
|
|
// CMSVectorContext is what a verdict needs besides SECURITY_CBOR (§29.7):
|
|
// control_commit and head_digest in hexadecimal, and round_time in RFC 3339.
|
|
type CMSVectorContext struct {
|
|
ControlCommit string `json:"control_commit"`
|
|
HeadDigest string `json:"head_digest"`
|
|
RoundTime string `json:"round_time"`
|
|
}
|
|
|
|
// CMSVectorCase is one case: the area, its context, and what a reader gives.
|
|
type CMSVectorCase struct {
|
|
Name string `json:"name"`
|
|
SecurityCBOR string `json:"security_cbor"`
|
|
Context CMSVectorContext `json:"context"`
|
|
Signature string `json:"signature"`
|
|
Seal string `json:"seal"`
|
|
// Signers and Foreign are the results of an alg 2 signature, in the
|
|
// order of SIGNERS and of the SignerInfo; SealHolder and SealTime are
|
|
// those of a valid seal of key 3. A time is in RFC 3339, with the
|
|
// fraction of the token when it has one.
|
|
Signers []FixtureSignerResult `json:"signers,omitempty"`
|
|
Foreign []FixtureSignerResult `json:"foreign_signers,omitempty"`
|
|
SealHolder string `json:"seal_holder,omitempty"`
|
|
SealTime string `json:"seal_time,omitempty"`
|
|
// SealReason is the reason of S5 (spec v0.16, §29.7), as
|
|
// FixtureSignerResult writes it.
|
|
SealReason string `json:"seal_reason,omitempty"`
|
|
// Lines are the verdicts as the official SDK shows them (§29.7):
|
|
// Verdicts.Lines.
|
|
Lines []string `json:"lines"`
|
|
}
|
|
|
|
// LocatorVectorFile is testdata/vectors/locator.json: the extension
|
|
// datekeys.capsule of a .dkk and what it points to (spec v0.12, §44.1), and
|
|
// what a reader rejects and uses of it (§64). It is made once and frozen: the
|
|
// envelope and the sealed locators hold randomness.
|
|
type LocatorVectorFile struct {
|
|
Description string `json:"description"`
|
|
Spec string `json:"spec"`
|
|
// Round is the round of the DateKey of the extension, and the locator is
|
|
// sealed with tlock for it: it opens with the release of that round.
|
|
Round uint64 `json:"round"`
|
|
DateKey string `json:"datekey"`
|
|
Note string `json:"note"`
|
|
// DKC is the capsule that the envelope hides, in hexadecimal.
|
|
DKC string `json:"dkc"`
|
|
// Rest is what is kept outside, Header what the locator carries, and Host
|
|
// a file with the rest appended at HostOffset.
|
|
Rest string `json:"rest"`
|
|
Header string `json:"envelope_header"`
|
|
Host string `json:"host"`
|
|
HostOffset uint64 `json:"host_offset"`
|
|
// Plaintext is the plaintext of the locator, in 4096 bytes; Sealed, the
|
|
// age file with the tlock stanza; Extension, the data of datekeys.capsule.
|
|
Plaintext string `json:"locator_plaintext"`
|
|
Sealed string `json:"locator_sealed"`
|
|
Extension string `json:"extension_data"`
|
|
// The fields of the locator, for a reader that compares them.
|
|
Addresses []LocatorVectorAddress `json:"addresses"`
|
|
EnvelopeKey string `json:"envelope_key"`
|
|
RestDigest string `json:"rest_digest"`
|
|
RestSize uint64 `json:"rest_size"`
|
|
CapsuleDigest string `json:"capsule_digest"`
|
|
// PaddingCases give the length of the plaintext for a length of the CBOR
|
|
// without key 6, around the boundaries where the CBOR length of key 6
|
|
// changes: the least multiple of 4096 that key 6 can fill exactly.
|
|
PaddingCases []LocatorPaddingCase `json:"padding_cases"`
|
|
// URICases give the verdict of the rules of §44.1 on an address.
|
|
URICases []LocatorURICase `json:"uri_cases"`
|
|
// Mixed is a second locator of the same envelope, sealed for Round, whose
|
|
// addresses break and meet the rules of §44.1: a reader reads it, rejects
|
|
// the ones that break them and uses the others.
|
|
Mixed LocatorMixed `json:"mixed"`
|
|
// RestCases are resources, as a reader downloads them, with the offset
|
|
// that an address gives, and whether the rest read there opens the
|
|
// envelope of the locator.
|
|
RestCases []LocatorRestCase `json:"rest_cases"`
|
|
// ExtensionCases are data of datekeys.capsule and whether a reader can use
|
|
// them: one it cannot is unusable, never the .dkk (§54).
|
|
ExtensionCases []LocatorExtensionCase `json:"extension_cases"`
|
|
// PlaintextCases are plaintexts of a locator of the same envelope, each
|
|
// with one defect or none, and whether a reader reads them: the map of
|
|
// §44.1 and the length that key 6 completes.
|
|
PlaintextCases []LocatorPlaintextCase `json:"plaintext_cases"`
|
|
}
|
|
|
|
// LocatorVectorAddress is an address of the locator.
|
|
type LocatorVectorAddress struct {
|
|
URI string `json:"uri"`
|
|
Offset uint64 `json:"offset"`
|
|
Host string `json:"host"`
|
|
}
|
|
|
|
// LocatorPaddingCase is a length of the CBOR without padding and the length of
|
|
// the plaintext that results.
|
|
type LocatorPaddingCase struct {
|
|
Base int `json:"base"`
|
|
Total int `json:"total"`
|
|
}
|
|
|
|
// LocatorURICase is an address and whether it is accepted.
|
|
type LocatorURICase struct {
|
|
URI string `json:"uri"`
|
|
OK bool `json:"ok"`
|
|
}
|
|
|
|
// LocatorMixed is a sealed locator, its plaintext and its addresses, each
|
|
// with whether a reader uses it.
|
|
type LocatorMixed struct {
|
|
Plaintext string `json:"locator_plaintext"`
|
|
Sealed string `json:"locator_sealed"`
|
|
Addresses []LocatorMixedAddress `json:"addresses"`
|
|
}
|
|
|
|
// LocatorMixedAddress is an address of a locator and whether a reader uses
|
|
// it.
|
|
type LocatorMixedAddress struct {
|
|
URI string `json:"uri"`
|
|
Offset uint64 `json:"offset"`
|
|
Usable bool `json:"usable"`
|
|
}
|
|
|
|
// LocatorRestCase is a resource in hexadecimal, the offset where an address
|
|
// says that the rest starts in it, and whether the rest opens the envelope:
|
|
// a reader reads RestSize bytes from the offset, whatever follows, and checks
|
|
// that their SHA-256 is RestDigest and that of the .dkc, CapsuleDigest.
|
|
type LocatorRestCase struct {
|
|
Name string `json:"name"`
|
|
Resource string `json:"resource"`
|
|
Offset uint64 `json:"offset"`
|
|
Opens bool `json:"opens"`
|
|
}
|
|
|
|
// LocatorExtensionCase is the data of a datekeys.capsule extension, version
|
|
// 1, and whether a reader can use it.
|
|
type LocatorExtensionCase struct {
|
|
Name string `json:"name"`
|
|
Data string `json:"extension_data"`
|
|
OK bool `json:"ok"`
|
|
}
|
|
|
|
// LocatorPlaintextCase is the plaintext of a locator and whether a reader
|
|
// reads it.
|
|
type LocatorPlaintextCase struct {
|
|
Name string `json:"name"`
|
|
Plaintext string `json:"locator_plaintext"`
|
|
OK bool `json:"ok"`
|
|
}
|