Oregami
Repositories/oxedyne/fe2o3

oxedyne/fe2o3/fe2o3_sbj/fixtures

showing fe2o3_sbj/fixtures/README.md

SBJ conformance fixtures

The teeth of SPEC.md §7. Written by examples/gen_fixtures.rs, run by tests/conformance.rs, and regenerated rather than patched:

cargo run -p oxedyne_fe2o3_sbj --example gen_fixtures
cargo test -p oxedyne_fe2o3_sbj

Each fixture is a directory.

Acceptance fixtures carry doc.jdat, the payload in JDAT text form and the source of truth; doc.sbj, the canonical signed artefact; and meta.jdat, what the artefact must turn out to be: its address, the length of its payload region, and -- where the payload is a node tree -- its node count and its depth. The suite reads doc.jdat, signs it with the committed key, and requires the bytes it gets back to be doc.sbj, byte for byte.

Not every payload is a node tree. The container carries any schema (§1.2), and the fixtures named post_*, card_* and share_* carry daimond/post/0, daimond/card/0 and daimond/share/0, which are flat canonical maps rather than trees. Those declare no node count and no depth, because they have neither, and their doc.jdat is written in plain JDAT with none of the sbj_ node labels below. Everything else about them is identical: the same header, the same envelope, the same address, the same signature, and every rule of §3.

The share_* fixtures carry one rule the others do not, and it is the reason that schema exists: code is the sender's SIGNED statement about whether the share carries a program, and it is checked against the files both ways. share_code_hidden is a page under a claim of no code, and share_code_claimed_without_code is the opposite. A share is a COPY the receiver comes to own, so there is no live view, nothing to revoke, and no third party in the middle of it.

Rejection fixtures carry doc.sbj, the bad artefact, and reject.jdat, which declares the rule broken, the step of §2 that must catch it, what the error must say, and the node or the byte it must name. "It was rejected" is not the claim: the claim is that it was rejected for the right reason. A rejection fixture also carries doc.jdat where the tree region is the encoding of a tree that can be written down; where the fault is in the bytes themselves, there is no tree to write.

Every rejection fixture past the header is correctly hashed and correctly signed, so that the rejection can only have come from the rule the fixture breaks, and never from a signature that happened not to check out.

key.jdat holds the fixed key every fixture is signed with, and a second key that signs nothing but the fixture of a signature by the wrong hand. It is committed on purpose: a fixture signed by a fresh key would be a different file on every run, and a suite that has to be regenerated to pass tests nothing. It is a test key, published here, and signs nothing else.

Node labels in doc.jdat carry an sbj_ prefix, because two of the v0 kind labels, box and list, are JDAT's own kind labels as well: (box|{..}) would read back as a Dat::Box. None of this reaches the wire, where BDAT carries the u16 kind code and no label at all.

The kind code 99 appears in the unknown_kind and unknown_kind_fallback fixtures. It names no v0 node kind, which is the point of it: the first carries no fallback and is refused, and the second carries a fallback of known nodes and is accepted (§4.5).

The kind codes 14 (edit) and 15 (surface) appear in the three reserved_* fixtures. They are not unknown: §4.2 reserves them to the chrome and to applications, and oxeweb/doc/0 admits the kinds 1 to 13 and no others. All three are refused, and the third carries a valid fallback and is refused anyway, which is the point of it: a fallback admits a code the reader has never heard of, and never one the reader knows a document may not carry.

NameSizeWhat
align_is_local/2.0 KiB3 files
bad_hash/4.2 KiB3 files
bad_magic/1.1 KiB2 files
bad_sig/4.1 KiB3 files
bad_version/1.1 KiB2 files
bdat_not_sbj/1.0 KiB2 files
bytes_trailing_the_tree/1.2 KiB2 files
canon_rule1_undeclared_field/1004 bytes3 files
canon_rule2_ordmap/989 bytes3 files
canon_rule3_duplicate_key/856 bytes2 files
canon_rule3_uppercase_key/929 bytes3 files
canon_rule4_empty_children/891 bytes3 files
canon_rule4_opt_none/1.1 KiB3 files
canon_rule5_control_char/956 bytes3 files
canon_rule5_not_nfc/1007 bytes3 files
canon_rule6_int_width/1.0 KiB3 files
canon_rule7_vek_children/1005 bytes3 files
card_enc_width/744 bytes3 files
card_first/967 bytes3 files
card_rotated/971 bytes3 files
corrupt_tree_byte/1.2 KiB2 files
depth_at_limit/44.7 KiB3 files
depth_over_limit/2.1 KiB2 files
empty/721 bytes3 files
empty_list/859 bytes3 files
envelope_missing_key/4.1 KiB3 files
envelope_nonminimal_c64/1.1 KiB2 files
every_kind/4.2 KiB3 files
foreign_schema/1.1 KiB3 files
heading_level_0/916 bytes3 files
heading_level_7/880 bytes3 files
indexed/1.2 KiB3 files
link_by_hash/1.3 KiB3 files
link_by_name/1.2 KiB3 files
link_two_entries/1.4 KiB3 files
one_para/1000 bytes3 files
para_in_para/1.0 KiB3 files
post_body_over_limit/19.5 KiB3 files
post_duplicate_key/945 bytes2 files
post_every_target/2.6 KiB3 files
post_minimal/1.0 KiB3 files
post_nonce_width/910 bytes3 files
post_refs_empty_list/1022 bytes3 files
post_relabelled_as_card/998 bytes2 files
reserved_edit_in_doc/1.1 KiB3 files
reserved_surface_in_doc/1.0 KiB3 files
reserved_surface_with_fallback_still_refused/1.5 KiB3 files
share_capp/1.9 KiB3 files
share_carries_capp_record/1.3 KiB3 files
share_carries_the_log/1.2 KiB3 files
share_code_claimed_without_code/1.3 KiB3 files
share_code_hidden/1.8 KiB3 files
share_data/1.6 KiB3 files
share_files_out_of_order/1.4 KiB3 files
share_missing_code_bit/1.3 KiB3 files
share_path_walks/1.3 KiB3 files
share_relabelled_as_post/1.1 KiB2 files
size_at_limit/8.0 MiB3 files
size_over_limit/4.0 MiB2 files
style_missing_entry/1.3 KiB3 files
style_out_of_enum/1.2 KiB3 files
styled/1.7 KiB3 files
tree_longer_than_tree_len/1.3 KiB2 files
truncated_tree/1.3 KiB2 files
unknown_kind/1013 bytes3 files
unknown_kind_fallback/2.3 KiB3 files
wrong_key/4.1 KiB3 files
README.md3.7 KiB
key.jdat353 bytes