|
|
|
|
// The primitives against files: the copy of test/vectors/primitives.json
|
|
|
|
|
// that primitives_test.dart reads, a Dart constant for the tests compiled to
|
|
|
|
|
// JavaScript, is the JSON file byte for byte, as
|
|
|
|
|
// tool/gen_primitive_vectors.go writes both; and the strict Ed25519
|
|
|
|
|
// verification gives the results of testdata/vectors/ed25519_strict.json of
|
|
|
|
|
// datekeys-go.
|
Stage 2: the primitives, against vectors that Go computes
SHA-256 with its own compression, and on it HMAC-SHA256 with the inner and
outer states of the key computed once, HKDF-SHA256 and PBKDF2-HMAC-SHA256,
whose iterations are two compressions over words; scrypt with Salsa20/8;
ChaCha20, Poly1305 in 13-bit limbs and ChaCha20-Poly1305 with the tag
compared in constant time; X25519 on the field of TweetNaCl in doubles,
with the all-zero secret refused; the strict Ed25519 verification of
internal/ed25519strict; Go's Base64 with the offsets of its errors, and
age's Bech32.
tool/gen_primitive_vectors.go computes every expected value with Go and
x/crypto, from the inputs of RFC 5869, 7748, 7914, 8032 and 8439, edge
cases and seeded random ones. The tests also run compiled to JavaScript,
from a Dart copy of the JSON, without the cases that would take too long.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
4 days ago
|
|
|
@TestOn('vm')
|
|
|
|
|
library;
|
|
|
|
|
|
|
|
|
|
import 'dart:convert';
|
Stage 2: the primitives, against vectors that Go computes
SHA-256 with its own compression, and on it HMAC-SHA256 with the inner and
outer states of the key computed once, HKDF-SHA256 and PBKDF2-HMAC-SHA256,
whose iterations are two compressions over words; scrypt with Salsa20/8;
ChaCha20, Poly1305 in 13-bit limbs and ChaCha20-Poly1305 with the tag
compared in constant time; X25519 on the field of TweetNaCl in doubles,
with the all-zero secret refused; the strict Ed25519 verification of
internal/ed25519strict; Go's Base64 with the offsets of its errors, and
age's Bech32.
tool/gen_primitive_vectors.go computes every expected value with Go and
x/crypto, from the inputs of RFC 5869, 7748, 7914, 8032 and 8439, edge
cases and seeded random ones. The tests also run compiled to JavaScript,
from a Dart copy of the JSON, without the cases that would take too long.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
4 days ago
|
|
|
import 'dart:io';
|
|
|
|
|
|
|
|
|
|
import 'package:datekeys/datekeys.dart' show fromHex;
|
|
|
|
|
import 'package:datekeys/src/curve25519.dart';
|
Stage 2: the primitives, against vectors that Go computes
SHA-256 with its own compression, and on it HMAC-SHA256 with the inner and
outer states of the key computed once, HKDF-SHA256 and PBKDF2-HMAC-SHA256,
whose iterations are two compressions over words; scrypt with Salsa20/8;
ChaCha20, Poly1305 in 13-bit limbs and ChaCha20-Poly1305 with the tag
compared in constant time; X25519 on the field of TweetNaCl in doubles,
with the all-zero secret refused; the strict Ed25519 verification of
internal/ed25519strict; Go's Base64 with the offsets of its errors, and
age's Bech32.
tool/gen_primitive_vectors.go computes every expected value with Go and
x/crypto, from the inputs of RFC 5869, 7748, 7914, 8032 and 8439, edge
cases and seeded random ones. The tests also run compiled to JavaScript,
from a Dart copy of the JSON, without the cases that would take too long.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
4 days ago
|
|
|
import 'package:test/test.dart';
|
|
|
|
|
|
|
|
|
|
import 'vectors/primitives.g.dart';
|
|
|
|
|
|
|
|
|
|
void main() {
|
|
|
|
|
test('primitives.g.dart holds primitives.json', () {
|
|
|
|
|
final file = File('test/vectors/primitives.json').readAsStringSync();
|
|
|
|
|
expect(primitivesJson, file);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('testdata/vectors/ed25519_strict.json', () {
|
|
|
|
|
final file = jsonDecode(
|
|
|
|
|
File('testdata/vectors/ed25519_strict.json').readAsStringSync(),
|
|
|
|
|
) as Map<String, Object?>;
|
|
|
|
|
final vectors = (file['vectors']! as List).cast<Map<String, Object?>>();
|
|
|
|
|
expect(vectors, isNotEmpty);
|
|
|
|
|
for (final v in vectors) {
|
|
|
|
|
expect(
|
|
|
|
|
verifyStrict(
|
|
|
|
|
fromHex(v['public_key']! as String),
|
|
|
|
|
fromHex(v['message']! as String),
|
|
|
|
|
fromHex(v['signature']! as String),
|
|
|
|
|
),
|
|
|
|
|
v['valid'],
|
|
|
|
|
reason: v['name'] as String?,
|
|
|
|
|
);
|
|
|
|
|
}
|
|
|
|
|
});
|
Stage 2: the primitives, against vectors that Go computes
SHA-256 with its own compression, and on it HMAC-SHA256 with the inner and
outer states of the key computed once, HKDF-SHA256 and PBKDF2-HMAC-SHA256,
whose iterations are two compressions over words; scrypt with Salsa20/8;
ChaCha20, Poly1305 in 13-bit limbs and ChaCha20-Poly1305 with the tag
compared in constant time; X25519 on the field of TweetNaCl in doubles,
with the all-zero secret refused; the strict Ed25519 verification of
internal/ed25519strict; Go's Base64 with the offsets of its errors, and
age's Bech32.
tool/gen_primitive_vectors.go computes every expected value with Go and
x/crypto, from the inputs of RFC 5869, 7748, 7914, 8032 and 8439, edge
cases and seeded random ones. The tests also run compiled to JavaScript,
from a Dart copy of the JSON, without the cases that would take too long.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
4 days ago
|
|
|
}
|