All checks were successful
check / check (push) Successful in 23s
Every element of the derivation path is hardened, so an index above 2147483647 has no child to derive: the hardened offset wrapped around and the tool silently produced a non-hardened key that no other implementation reading the path as written would reproduce. Such an index is now refused with a message before anything is derived, and tests pin the refusal at both the derivation and the command level. Also use the hook path variable in script/install-precommit instead of repeating the literal beside it. Model: opus-5
62 lines
1.4 KiB
Go
62 lines
1.4 KiB
Go
package derive_test
|
|
|
|
import (
|
|
"bytes"
|
|
"strings"
|
|
"testing"
|
|
|
|
"git.eeqj.de/sneak/keyfunc/internal/derive"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
// application is the number the SSH key type uses.
|
|
const application = 838372
|
|
|
|
// example returns the mnemonic every BIP-39 document uses to show its
|
|
// test vectors: eleven abandons and about.
|
|
func example() string {
|
|
return strings.Repeat("abandon ", 11) + "about"
|
|
}
|
|
|
|
func TestPathIsTheOneTheSpecificationGives(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
require.Equal(t, "m/83696968'/838372'/3'", derive.Path(application, 3))
|
|
}
|
|
|
|
func TestEveryIndexGivesItsOwnBytes(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
first, err := derive.Bytes(example(), application, 0)
|
|
require.NoError(t, err)
|
|
require.Len(t, first, derive.Size)
|
|
|
|
second, err := derive.Bytes(example(), application, 1)
|
|
require.NoError(t, err)
|
|
require.Len(t, second, derive.Size)
|
|
|
|
require.False(t, bytes.Equal(first, second))
|
|
}
|
|
|
|
func TestAnIndexWithNoHardenedChildIsRefused(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
_, err := derive.Bytes(example(), application, derive.MaxIndex+1)
|
|
require.ErrorIs(t, err, derive.ErrIndexTooLarge)
|
|
|
|
_, err = derive.Bytes(example(), application, derive.MaxIndex)
|
|
require.NoError(t, err)
|
|
}
|
|
|
|
func TestTheSameInputAlwaysGivesTheSameBytes(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
once, err := derive.Bytes(example(), application, 7)
|
|
require.NoError(t, err)
|
|
|
|
again, err := derive.Bytes(example(), application, 7)
|
|
require.NoError(t, err)
|
|
|
|
require.Equal(t, once, again)
|
|
}
|