//! SPDX-License-Identifier: GPL-3.0-or-later
import { constants, derive, sign, verify, verify_blocks } from 'nano25519'
-import { NANO_ORG_VECTOR, PROBLEM_VECTOR, PYTHON_ED25519_BLAKE2B_VECTORS } from './vectors.mjs'
+import { IDENTITY, NANO_ORG_VECTOR, PROBLEM_VECTOR, PYTHON_ED25519_BLAKE2B_VECTORS } from './vectors.mjs'
/**
* @param {string} name
passes += +test
failures += +!test
+// identity A and S=0 pin check_r so only R moves; any other A hides equalbytes bugs
+const forgery = IDENTITY.signatureBytes.slice()
+const accepted = []
+for (let i = 0; i < constants.KEY_BYTELENGTH; i++) {
+ for (let j = 1; j < 256; j++) {
+ forgery[i] ^= j
+ result = verify_blocks(IDENTITY.publicKeyBytes, [{ signature: forgery, hash: new Uint8Array(32) }])[0]
+ forgery[i] = IDENTITY.signatureBytes[i]
+ if (result !== false) {
+ accepted.push({ byte: i, mask: `0x${j.toString(16).padStart(2, '0')}` })
+ }
+ }
+}
+test = accepted.length === 0
+check(`verify_blocks rejects R xor mask${test ? '' : ` (failed to reject ${accepted})`}`, test)
+passes += +test
+failures += +!test
+
// Check output buffer offset handling
try {
outbuf = new Uint8Array(33)
export const IDENTITY = {
publicKey: '0100000000000000000000000000000000000000000000000000000000000000',
publicKeyBytes: new Uint8Array([0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00]),
+ signature: '01000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000',
+ signatureBytes: new Uint8Array([0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00]),
}
/**
/**
* https://github.com/rsnano-node/rsnano-node/blob/develop/types/src/private_key.rs
*
- * Small-order public key producing malleable signatures
+ * Identity point as public key producing malleable signatures
*
* Address: nano_11a11111111111111111111111111111111111111111111111116iq5p4i8
*/