crates/veilvoice-verify/src/tests.rs
veilvoice-verify · 1373 lines · read the source here · or on GitHub
The verifier's own tests.
The property that matters most here is not "a good signature is accepted" but "a bad one is refused". A verifier that accepts everything passes every happy-path test ever written, and would ship looking perfect while doing the opposite of its job -- so most of what follows is negative: corrupted signatures, wrong keys, truncated input, mismatched hashes.
This file is //!-documented rather than //-commented so that the reasoning above appears in the generated documentation. A reader deciding whether to trust veilvoice-verify should be able to see what it was tested against without cloning the repository, because the whole purpose of that binary is to be the thing you check a download with.
In plain words
The verifier's own tests, and most of them are about failure rather than success.
That is deliberate. A verifier that accepted everything would pass every happy-path test ever written and would ship looking perfect while doing the opposite of its job. So most of what is here is corrupted signatures, wrong keys, truncated files and mismatched hashes, and the question each time is whether it says no.
WHAT THIS FILE CONTAINS
1373 lines defining 33 functions (0 public), 0 types and 0 constants. Everything below is read out of the source, so it cannot disagree with the code.
WHAT CALLS WHAT
The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one. 22 of 33 functions are drawn; the diagram is bounded at 22 so it stays readable.
The same graph as Mermaid source
%%{init: {"theme":"base","themeVariables":{"background":"#1a1b26","primaryColor":"#1f2335","primaryTextColor":"#c0caf5","primaryBorderColor":"#7aa2f7","secondaryColor":"#16161e","tertiaryColor":"#16161e","lineColor":"#737aa2","textColor":"#c0caf5","mainBkg":"#1f2335","nodeBorder":"#7aa2f7","clusterBkg":"#16161e","clusterBorder":"#2f3549","fontFamily":"ui-monospace, SFMono-Regular, Consolas, monospace","fontSize":"14px"}}}%%
flowchart TD
n_the_embedded_key_parses_and_is_the_expected_one["the_embedded_key_parses_and_is_the_<br/>expected_one<br/>line 30"]
n_the_embedded_key_carries_no_email_address["the_embedded_key_carries_no_email_<br/>address<br/>line 36"]
n_the_fingerprint_constant_is_written_out_not_computed["the_fingerprint_constant_is_written_<br/>out_not_computed<br/>line 51"]
n_a_hash_is_found_by_its_file_name["a_hash_is_found_by_its_file_name<br/>line 64"]
n_a_binary_mode_star_is_not_part_of_the_name["a_binary_mode_star_is_not_part_of_the_<br/>name<br/>line 76"]
n_a_file_that_is_not_listed_is_not_found["a_file_that_is_not_listed_is_not_found<br/>line 88"]
n_a_name_that_merely_contains_the_wanted_one_does_not_match["a_name_that_merely_contains_the_<br/>wanted_one_does_not_match<br/>line 94"]
n_blank_and_comment_lines_are_skipped["blank_and_comment_lines_are_skipped<br/>line 101"]
n_a_malformed_line_is_skipped_rather_than_panicking["a_malformed_line_is_skipped_rather_<br/>than_panicking<br/>line 110"]
n_digests_compare_case_insensitively_and_ignore_surrounding_space["digests_compare_case_insensitively_<br/>and_ignore_surrounding_space<br/>line 121"]
n_a_signature_that_is_not_openpgp_is_refused["a_signature_that_is_not_openpgp_is_<br/>refused<br/>line 130"]
n_an_empty_signature_is_refused["an_empty_signature_is_refused<br/>line 137"]
n_an_armoured_block_that_is_not_a_signature_is_refused["an_armoured_block_that_is_not_a_<br/>signature_is_refused<br/>line 143"]
n_every_line_printed_by_a_check_goes_through_the_level["every_line_printed_by_a_check_goes_<br/>through_the_level<br/>line 173"]
n_nothing_exits_with_an_undocumented_status["nothing_exits_with_an_undocumented_<br/>status<br/>line 248"]
n_every_test_that_reads_source_normalises_its_line_endings["every_test_that_reads_source_<br/>normalises_its_line_endings<br/>line 285"]
n_searching_for_a_brace_on_its_own_line_fails_against_crlf["searching_for_a_brace_on_its_own_line_<br/>fails_against_crlf<br/>line 317"]
n_the_repository_pins_its_line_endings["the_repository_pins_its_line_endings<br/>line 336"]
n_the_contents_list_is_verified_before_it_is_parsed["the_contents_list_is_verified_before_<br/>it_is_parsed<br/>line 369"]
n_a_release_without_a_contents_list_is_not_a_failure["a_release_without_a_contents_list_is_<br/>not_a_failure<br/>line 392"]
n_a_contents_list_with_nothing_to_check_it_against_is_unusable["a_contents_list_with_nothing_to_check_<br/>it_against_is_unusable<br/>line 406"]
n_matches_name["matches_name<br/>line 421"]
n_a_contents_list_with_nothing_to_check_it_against_is_unusable --> n_matches_name
click n_the_embedded_key_parses_and_is_the_expected_one href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L30" "open the source"
click n_the_embedded_key_carries_no_email_address href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L36" "open the source"
click n_the_fingerprint_constant_is_written_out_not_computed href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L51" "open the source"
click n_a_hash_is_found_by_its_file_name href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L64" "open the source"
click n_a_binary_mode_star_is_not_part_of_the_name href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L76" "open the source"
click n_a_file_that_is_not_listed_is_not_found href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L88" "open the source"
click n_a_name_that_merely_contains_the_wanted_one_does_not_match href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L94" "open the source"
click n_blank_and_comment_lines_are_skipped href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L101" "open the source"
click n_a_malformed_line_is_skipped_rather_than_panicking href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L110" "open the source"
click n_digests_compare_case_insensitively_and_ignore_surrounding_space href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L121" "open the source"
click n_a_signature_that_is_not_openpgp_is_refused href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L130" "open the source"
click n_an_empty_signature_is_refused href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L137" "open the source"
click n_an_armoured_block_that_is_not_a_signature_is_refused href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L143" "open the source"
click n_every_line_printed_by_a_check_goes_through_the_level href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L173" "open the source"
click n_nothing_exits_with_an_undocumented_status href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L248" "open the source"
click n_every_test_that_reads_source_normalises_its_line_endings href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L285" "open the source"
click n_searching_for_a_brace_on_its_own_line_fails_against_crlf href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L317" "open the source"
click n_the_repository_pins_its_line_endings href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L336" "open the source"
click n_the_contents_list_is_verified_before_it_is_parsed href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L369" "open the source"
click n_a_release_without_a_contents_list_is_not_a_failure href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L392" "open the source"
click n_a_contents_list_with_nothing_to_check_it_against_is_unusable href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L406" "open the source"
click n_matches_name href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/src/tests.rs#L421" "open the source"
classDef helper fill:#1f2335,stroke:#bb9af7,color:#c0caf5
class n_the_embedded_key_parses_and_is_the_expected_one,n_the_embedded_key_carries_no_email_address,n_the_fingerprint_constant_is_written_out_not_computed,n_a_hash_is_found_by_its_file_name,n_a_binary_mode_star_is_not_part_of_the_name,n_a_file_that_is_not_listed_is_not_found,n_a_name_that_merely_contains_the_wanted_one_does_not_match,n_blank_and_comment_lines_are_skipped,n_a_malformed_line_is_skipped_rather_than_panicking,n_digests_compare_case_insensitively_and_ignore_surrounding_space,n_a_signature_that_is_not_openpgp_is_refused,n_an_empty_signature_is_refused,n_an_armoured_block_that_is_not_a_signature_is_refused,n_every_line_printed_by_a_check_goes_through_the_level,n_nothing_exits_with_an_undocumented_status,n_every_test_that_reads_source_normalises_its_line_endings,n_searching_for_a_brace_on_its_own_line_fails_against_crlf,n_the_repository_pins_its_line_endings,n_the_contents_list_is_verified_before_it_is_parsed,n_a_release_without_a_contents_list_is_not_a_failure,n_a_contents_list_with_nothing_to_check_it_against_is_unusable,n_matches_name helper
This site loads no third-party script, so it cannot run Mermaid; the diagram above is the same nodes and edges drawn by the generator instead. GitHub renders the source below directly.
ITEMS
| Item | Line | Documentation |
|---|---|---|
the_embedded_key_parses_and_is_the_expected_one fn | 30 | |
the_embedded_key_carries_no_email_address fn | 36 | |
the_fingerprint_constant_is_written_out_not_computed fn | 51 | |
a_hash_is_found_by_its_file_name fn | 64 | |
a_binary_mode_star_is_not_part_of_the_name fn | 76 | |
a_file_that_is_not_listed_is_not_found fn | 88 | |
a_name_that_merely_contains_the_wanted_one_does_not_match fn | 94 | |
blank_and_comment_lines_are_skipped fn | 101 | |
a_malformed_line_is_skipped_rather_than_panicking fn | 110 | |
digests_compare_case_insensitively_and_ignore_surrounding_space fn | 121 | |
a_signature_that_is_not_openpgp_is_refused fn | 130 | |
an_empty_signature_is_refused fn | 137 | |
an_armoured_block_that_is_not_a_signature_is_refused fn | 143 | |
every_line_printed_by_a_check_goes_through_the_level fn | 173 | Nothing may print without asking the level first. |
nothing_exits_with_an_undocumented_status fn | 248 | Every exit this program can take is one of the documented statuses. |
every_test_that_reads_source_normalises_its_line_endings fn | 285 | F-72. |
searching_for_a_brace_on_its_own_line_fails_against_crlf fn | 317 | The failure mode itself, so it is on record as reachable rather than theoretical. |
the_repository_pins_its_line_endings fn | 336 | .gitattributes exists and pins text to LF. |
the_contents_list_is_verified_before_it_is_parsed fn | 369 | Roadmap item 97. |
a_release_without_a_contents_list_is_not_a_failure fn | 392 | A release that published no contents list is still checkable. |
a_contents_list_with_nothing_to_check_it_against_is_unusable fn | 406 | A contents list with no signed hash list beside it cannot be used, and "cannot be used" is reported rather than quietly skipped. |
matches_name fn | 421 | A name for a Manifest, for a failing assertion to print. |
a_gnupg_that_cannot_run_is_never_counted_against_the_release fn | 436 | Roadmap item 97. |
a_named_directory_that_is_not_there_is_refused_before_anything_is_searched fn | 472 | F-108. |
no_interface_string_has_a_gap_where_a_line_continuation_belongs fn | 522 | No interface string carries a run of spaces left behind by its own source indentation. |
every_command_line_drawing_is_shown_in_the_readme fn | 636 | Nothing a reader is meant to type still names a veilvoice-verify program. |
every_tab_has_a_picture_in_the_readme_and_on_the_website fn | 684 | Every tab the window shows has a picture in the README and on the website. |
the_readme_counts_the_window_tabs_the_window_actually_has fn | 736 | The README's count of the window's tabs is the number of tabs there are. |
no_page_tells_a_reader_to_run_a_program_that_no_longer_exists fn | 789 | |
no_desktop_test_opens_a_device_a_dialog_or_a_window fn | 929 | No test in the desktop crate may open a device, a dialog or a window. |
only_the_session_builds_a_recorder fn | 1053 | F-166. |
the_desktop_starts_a_live_session_in_exactly_one_place fn | 1127 | Roadmap item 130. |
no_audio_callback_allocates_or_blocks fn | 1235 | Roadmap item 126. |