You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
dateKeys-dart/test/securitycms_support.dart

82 lines
3.0 KiB

Stage 5c: the verdicts of alg 2 and seal_type 2, and the opening gives them securitycms.dart ports evaluateCMS, signerLine and evaluateSeal of signature2.go of Go at the draft v0.12, on the reader of CMS of stage 5a, with the same order of checks: SIGNERS with its profile and at most 16 entries, then the SignedData; each required signer in the order of SIGNERS and each foreign one in the order of the encoding, valid, invalid, absent, not verifiable, without seal, with an invalid seal or out of validity at the time of its seal; F2, F5 and F6 with their detail; and the seal over SEAL_SUBJECT, S1 to S5 with the authority and t. A round time at Go's zero time is no round time, as IsZero, and Verdicts.sealedAt skips a seal at that time, as SealedAt. cmsReader is the default CmsEvaluator of evaluateSecurity, and so of evaluateSecurityInput and the opening: nothing that Go evaluates is left not evaluated; a caller that passes cms: null still gets the parts without CMS alone. encodeSigners and maxSigners are exported, as EncodeSigners and MaxSigners of Go. The tests compare every part with Go: the 135 cases of security_cms.json with the result of each signer, the 24 of security.json, the 56 signatures of alg 2 and 105 seals of seal_type 2 of security_vectors.json, the 755 cases of securitycms_vectors.json with their detail and earliest seal, the fixtures format3_signed_cms and format3_sealed, and their openings in open_cases.json. On Node.js, a part of the vectors and the two fixtures opened in full. 1572 tests on the VM and 332 on Node.js. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
3 days ago
// Helpers of the tests of the signatures of alg 2 and the seals of
// seal_type 2 against the vectors of Go: the areas of
// test/vectors/securitycms_vectors.json, which tool/security_go_vectors.go
// makes and evaluates with package capsule of the reference, put together
// again from their pieces, or from a base and its edit. They read no file,
// so that the tests that run on Node.js can use them.
library;
import 'dart:typed_data';
import 'package:datekeys/datekeys.dart';
import 'package:datekeys/src/sha256.dart' show sha256;
import 'open_vectors_support.dart';
import 'tlock_support.dart' show applyEdits;
/// The bytes of [pieces]: the hexadecimal of some bytes, or the index of a
/// chunk of [chunks].
Uint8List joinPieces(List<Object?> pieces, List<Uint8List> chunks) =>
concatBytes([
for (final p in pieces) p is int ? chunks[p] : fromHex(p! as String),
]);
/// The chunks of a vector file, each made of the ones before it.
List<Uint8List> chunksOf(Json f) {
final out = <Uint8List>[];
for (final c in (f['chunks']! as List).cast<Json>()) {
out.add(joinPieces(c['pieces']! as List<Object?>, out));
}
return out;
}
/// The bases of the file, from their pieces, or their hexadecimal in the
/// part of the file that the tests compiled to JavaScript read.
List<Uint8List> basesOf(Json f, List<Uint8List> chunks) => [
for (final b in f['bases']! as List)
b is String
? fromHex(b)
: joinPieces((b as Json)['pieces']! as List<Object?>, chunks),
];
/// The area of the case [c]: its hexadecimal, its pieces, or its base with
/// the edit of its target, the SignedData of key 2 (value), its SIGNERS
/// (signers) or the token of key 3 (token), written again with the
/// encoders of this library as Go writes it with those of capsule. The
/// first 8 bytes of its SHA-256 must be those of Go's.
Uint8List cmsAreaOf(Json c, List<Uint8List> chunks, List<Uint8List> bases) {
final Uint8List area;
final hex = c['hex'] as String?;
final pieces = c['pieces'] as List<Object?>?;
if (hex != null) {
area = fromHex(hex);
} else if (pieces != null) {
area = joinPieces(pieces, chunks);
} else {
final w = decodeSecurity(bases[c['base']! as int])!;
final edits = (c['edits']! as List).cast<Object?>();
var signature = w.signature;
var seal = w.seal;
switch (c['target']) {
case 'value' || 'signers':
final a = decodeAuthorSignature(signature!)!;
final value = c['target'] == 'value';
signature = encodeAuthorSignature(
algCms,
value ? a.key : applyEdits(a.key, edits),
value ? applyEdits(a.value, edits) : a.value,
);
case 'token':
final s = decodeSeal(seal!)!;
seal = encodeSeal(sealTypeRfc3161, applyEdits(s.token, edits));
default:
throw StateError('a target ${c['target']}');
}
area = encodeSecurityWith(signature: signature, seal: seal);
}
if (toHex(sha256(area).sublist(0, 8)) != c['sha256']) {
throw StateError('the area of ${canonical(c)} is not the one of Go');
}
return area;
}

Powered by TurnKey Linux.