tests: make each of the four bounds fail on its own - #151
Merged
aido merged 1 commit intoAug 4, 2026
Merged
Conversation
Removing all four guards at once made the file fail, which says the set of them is needed and nothing about any one. Mutating them one at a time left two alive. The check on the CBOR additional information survived because the frame the test used was malformed in another way as well, so it was refused further down whether or not the reserved forms are looked for, and the assertion held either way. Read as a length rather than as a form, 25 is the size of a real shard -- five metadata bytes over a 20-byte secret -- so the frame is now built around a share set generated for that size, and parses, combines and answers with the secret when the guard is gone. Deriving the header length from the additional information rather than from the decoded length survived because no test used the one encoding that tells the two apart: a 21-byte shard written in the long form, which CBOR allows. The shard then starts at offset 5, where hex_check() also looks for it, and at offset 4 under the older derivation. The control set is reframed that way and has to combine to the same secret. All four mutants now fail the file.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Removing all four guards at once made the file fail, which says the set of
them is needed and nothing about any one. Mutating them one at a time left
two alive.
The check on the CBOR additional information survived because the frame the
test used was malformed in another way as well, so it was refused further
down whether or not the reserved forms are looked for, and the assertion
held either way. Read as a length rather than as a form, 25 is the size of a
real shard -- five metadata bytes over a 20-byte secret -- so the frame is
now built around a share set generated for that size, and parses, combines
and answers with the secret when the guard is gone.
Deriving the header length from the additional information rather than from
the decoded length survived because no test used the one encoding that
tells the two apart: a 21-byte shard written in the long form, which CBOR
allows. The shard then starts at offset 5, where hex_check() also looks for
it, and at offset 4 under the older derivation. The control set is reframed
that way and has to combine to the same secret.
All four mutants now fail the file.