You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
DateKeys/internal/testkit/cmsvectors.go

160 lines
6.8 KiB

package testkit
// CMSVectorFile is testdata/vectors/security_cms.json: SECURITY_CBOR areas
// with an author signature of alg 2 (CMS with certificates) or a time seal
// of seal_type 2 (RFC 3161), each with the context of its capsule and the
// verdicts, the results and the lines that spec v0.12 §29.7, §29.10 and
// §29.11 give. The certificates and the tokens are made once, with test
// keys, and the file is frozen: a second implementation reads them and must
// reach the same verdicts and write the same lines, byte for byte.
type CMSVectorFile struct {
Description string `json:"description"`
Spec string `json:"spec"`
Cases []CMSVectorCase `json:"cases"`
}
// CMSVectorContext is what a verdict needs besides SECURITY_CBOR (§29.7):
// control_commit and head_digest in hexadecimal, and round_time in RFC 3339.
type CMSVectorContext struct {
ControlCommit string `json:"control_commit"`
HeadDigest string `json:"head_digest"`
RoundTime string `json:"round_time"`
}
// CMSVectorCase is one case: the area, its context, and what a reader gives.
type CMSVectorCase struct {
Name string `json:"name"`
SecurityCBOR string `json:"security_cbor"`
Context CMSVectorContext `json:"context"`
Signature string `json:"signature"`
Seal string `json:"seal"`
// Signers and Foreign are the results of an alg 2 signature, in the
// order of SIGNERS and of the SignerInfo; SealHolder and SealTime are
// those of a valid seal of key 3. A time is in RFC 3339, with the
// fraction of the token when it has one.
Signers []FixtureSignerResult `json:"signers,omitempty"`
Foreign []FixtureSignerResult `json:"foreign_signers,omitempty"`
SealHolder string `json:"seal_holder,omitempty"`
SealTime string `json:"seal_time,omitempty"`
// Lines are the verdicts as the official SDK shows them (§29.7):
// Verdicts.Lines.
Lines []string `json:"lines"`
}
// LocatorVectorFile is testdata/vectors/locator.json: the extension
// datekeys.capsule of a .dkk and what it points to (spec v0.12, §44.1), and
// what a reader rejects and uses of it (§64). It is made once and frozen: the
// envelope and the sealed locators hold randomness.
type LocatorVectorFile struct {
Description string `json:"description"`
Spec string `json:"spec"`
// Round is the round of the DateKey of the extension, and the locator is
// sealed with tlock for it: it opens with the release of that round.
Round uint64 `json:"round"`
DateKey string `json:"datekey"`
Note string `json:"note"`
// DKC is the capsule that the envelope hides, in hexadecimal.
DKC string `json:"dkc"`
// Rest is what is kept outside, Header what the locator carries, and Host
// a file with the rest appended at HostOffset.
Rest string `json:"rest"`
Header string `json:"envelope_header"`
Host string `json:"host"`
HostOffset uint64 `json:"host_offset"`
// Plaintext is the plaintext of the locator, in 4096 bytes; Sealed, the
// age file with the tlock stanza; Extension, the data of datekeys.capsule.
Plaintext string `json:"locator_plaintext"`
Sealed string `json:"locator_sealed"`
Extension string `json:"extension_data"`
// The fields of the locator, for a reader that compares them.
Addresses []LocatorVectorAddress `json:"addresses"`
EnvelopeKey string `json:"envelope_key"`
RestDigest string `json:"rest_digest"`
RestSize uint64 `json:"rest_size"`
CapsuleDigest string `json:"capsule_digest"`
// PaddingCases give the length of the plaintext for a length of the CBOR
// without key 6, around the boundaries where the CBOR length of key 6
// changes: the least multiple of 4096 that key 6 can fill exactly.
PaddingCases []LocatorPaddingCase `json:"padding_cases"`
// URICases give the verdict of the rules of §44.1 on an address.
URICases []LocatorURICase `json:"uri_cases"`
// Mixed is a second locator of the same envelope, sealed for Round, whose
// addresses break and meet the rules of §44.1: a reader reads it, rejects
// the ones that break them and uses the others.
Mixed LocatorMixed `json:"mixed"`
// RestCases are resources, as a reader downloads them, with the offset
// that an address gives, and whether the rest read there opens the
// envelope of the locator.
RestCases []LocatorRestCase `json:"rest_cases"`
// ExtensionCases are data of datekeys.capsule and whether a reader can use
// them: one it cannot is unusable, never the .dkk (§54).
ExtensionCases []LocatorExtensionCase `json:"extension_cases"`
// PlaintextCases are plaintexts of a locator of the same envelope, each
// with one defect or none, and whether a reader reads them: the map of
// §44.1 and the length that key 6 completes.
PlaintextCases []LocatorPlaintextCase `json:"plaintext_cases"`
}
// LocatorVectorAddress is an address of the locator.
type LocatorVectorAddress struct {
URI string `json:"uri"`
Offset uint64 `json:"offset"`
Host string `json:"host"`
}
// LocatorPaddingCase is a length of the CBOR without padding and the length of
// the plaintext that results.
type LocatorPaddingCase struct {
Base int `json:"base"`
Total int `json:"total"`
}
// LocatorURICase is an address and whether it is accepted.
type LocatorURICase struct {
URI string `json:"uri"`
OK bool `json:"ok"`
}
// LocatorMixed is a sealed locator, its plaintext and its addresses, each
// with whether a reader uses it.
type LocatorMixed struct {
Plaintext string `json:"locator_plaintext"`
Sealed string `json:"locator_sealed"`
Addresses []LocatorMixedAddress `json:"addresses"`
}
// LocatorMixedAddress is an address of a locator and whether a reader uses
// it.
type LocatorMixedAddress struct {
URI string `json:"uri"`
Offset uint64 `json:"offset"`
Usable bool `json:"usable"`
}
// LocatorRestCase is a resource in hexadecimal, the offset where an address
// says that the rest starts in it, and whether the rest opens the envelope:
// a reader reads RestSize bytes from the offset, whatever follows, and checks
// that their SHA-256 is RestDigest and that of the .dkc, CapsuleDigest.
type LocatorRestCase struct {
Name string `json:"name"`
Resource string `json:"resource"`
Offset uint64 `json:"offset"`
Opens bool `json:"opens"`
}
// LocatorExtensionCase is the data of a datekeys.capsule extension, version
// 1, and whether a reader can use it.
type LocatorExtensionCase struct {
Name string `json:"name"`
Data string `json:"extension_data"`
OK bool `json:"ok"`
}
// LocatorPlaintextCase is the plaintext of a locator and whether a reader
// reads it.
type LocatorPlaintextCase struct {
Name string `json:"name"`
Plaintext string `json:"locator_plaintext"`
OK bool `json:"ok"`
}

Powered by TurnKey Linux.