Skip to content

tests: make each of the four bounds fail on its own - #151

Merged
aido merged 1 commit into
aido:bip85from
buzzromain:tests/sskr-combine-bounds-mutants-bip85
Aug 4, 2026
Merged

aido merged 1 commit into
aido:bip85from
buzzromain:tests/sskr-combine-bounds-mutants-bip85

Conversation

@buzzromain

Copy link
Copy Markdown

Removing all four guards at once made the file fail, which says the set of
them is needed and nothing about any one. Mutating them one at a time left
two alive.

The check on the CBOR additional information survived because the frame the
test used was malformed in another way as well, so it was refused further
down whether or not the reserved forms are looked for, and the assertion
held either way. Read as a length rather than as a form, 25 is the size of a
real shard -- five metadata bytes over a 20-byte secret -- so the frame is
now built around a share set generated for that size, and parses, combines
and answers with the secret when the guard is gone.

Deriving the header length from the additional information rather than from
the decoded length survived because no test used the one encoding that
tells the two apart: a 21-byte shard written in the long form, which CBOR
allows. The shard then starts at offset 5, where hex_check() also looks for
it, and at offset 4 under the older derivation. The control set is reframed
that way and has to combine to the same secret.

All four mutants now fail the file.

Removing all four guards at once made the file fail, which says the set of
them is needed and nothing about any one. Mutating them one at a time left
two alive.

The check on the CBOR additional information survived because the frame the
test used was malformed in another way as well, so it was refused further
down whether or not the reserved forms are looked for, and the assertion
held either way. Read as a length rather than as a form, 25 is the size of a
real shard -- five metadata bytes over a 20-byte secret -- so the frame is
now built around a share set generated for that size, and parses, combines
and answers with the secret when the guard is gone.

Deriving the header length from the additional information rather than from
the decoded length survived because no test used the one encoding that
tells the two apart: a 21-byte shard written in the long form, which CBOR
allows. The shard then starts at offset 5, where hex_check() also looks for
it, and at offset 4 under the older derivation. The control set is reframed
that way and has to combine to the same secret.

All four mutants now fail the file.
@aido
aido merged commit 08f7ff2 into aido:bip85 Aug 4, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants