Stage 5c: SIGNERS of 16 and 17 entries and two foreign signers in the part

Injected faults showed two rules that only the tests on the VM checked:
SIGNERS of more than 16 entries, whose only case was in security_cms.json,
and the order of the foreign signers. securitycms_vectors.json gains
SIGNERS of 16 and of 17 entries with Ana among them, beside her signature
for those SIGNERS or for SIGNERS with her alone, and a required signer
beside two foreign ones, without seals so that the area stays small; the
part for Node.js holds them. 760 cases.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
v0.11
dev 2 days ago
parent ff38c861d5
commit ded624a63a

File diff suppressed because one or more lines are too long

File diff suppressed because one or more lines are too long

@ -1996,6 +1996,9 @@ func signersOf(certs ...cmsCert) []byte {
return must(capsule.EncodeSigners(hashes)) return must(capsule.EncodeSigners(hashes))
} }
// signersOfHashes is SIGNERS of the hashes, as EncodeSigners writes it.
func signersOfHashes(hashes [][32]byte) []byte { return must(capsule.EncodeSigners(hashes)) }
func cmsMessage(ctx int, signers []byte) []byte { func cmsMessage(ctx int, signers []byte) []byte {
c := contexts[ctx] c := contexts[ctx]
return capsule.AuthorMessage(c.cc, c.hd, capsule.SignersDigest(capsule.AlgCMS, signers)) return capsule.AuthorMessage(c.cc, c.hd, capsule.SignersDigest(capsule.AlgCMS, signers))
@ -2145,6 +2148,37 @@ func cmsSecurityCases() {
addCMS("one signer", k.name, cmsArea(signers, signedData(*m.m), nil), c0) addCMS("one signer", k.name, cmsArea(signers, signedData(*m.m), nil), c0)
} }
// Two foreign signers, which show in the order of the encoding, beside a
// required one; without seals, so that the area stays small.
two := []cmsSigned{*required[9].m}
for _, c := range []cmsCert{otro, caducada} {
two = append(two, *memberOf(mA, kind{"", c, signOpts{}}).m)
}
addCMS("order", "Ana without seal, and two foreign signers without seal", cmsArea(signersA, signedData(two...), nil), c0)
// SIGNERS of 16 entries, the most, and of 17, with Ana among them, beside
// her signature over the AUTHOR_MESSAGE of those very SIGNERS, or of
// SIGNERS with her alone: 17 entries are F1, whatever the signature.
for _, n := range []int{16, 17} {
hashes := [][32]byte{sha256.Sum256(ana.raw)}
for i := 1; i < n; i++ {
hashes = append(hashes, digest(fmt.Sprintf("datekeys-dart: a certificate that signs nothing, %d", i)))
}
var e bytes.Buffer
e.Write(head(4, uint64(n)))
slices.SortFunc(hashes, func(a, b [32]byte) int { return bytes.Compare(a[:], b[:]) })
for _, h := range hashes {
e.Write(bstr(h[:]))
}
signers := e.Bytes()
if n == 16 && !bytes.Equal(signers, signersOfHashes(hashes)) {
panic("SIGNERS is not what EncodeSigners writes")
}
own := memberOf(cmsMessage(c0, signers), kind{"", ana, signOpts{token: sealed}})
addCMS("SIGNERS", fmt.Sprintf("SIGNERS of %d entries, Ana valid among them", n), cmsArea(signers, signedData(*own.m), nil), c0)
addCMS("SIGNERS", fmt.Sprintf("SIGNERS of %d entries, beside the signature of Ana for SIGNERS with her alone", n), cmsArea(signers, signedData(*required[1].m), nil), c0)
}
// B: three required signers, Ana, Luis and Beatriz, each absent or in // B: three required signers, Ana, Luis and Beatriz, each absent or in
// one of her kinds, beside foreign signers, drawn from the seed. // one of her kinds, beside foreign signers, drawn from the seed.
signersB := signersOf(ana, luis, bea) signersB := signersOf(ana, luis, bea)

Loading…
Cancel
Save

Powered by TurnKey Linux.