testlog

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 31, 2026 License: Apache-2.0 Imports: 19 Imported by: 0

Documentation

Overview

Package testlog is an in-memory transparency log and a fake of the Compliance API surface axt-verify reads, for hermetic tests. Tree hashes and proofs come from golang.org/x/mod/sumdb/tlog — an implementation independent of the transparency-dev/merkle code the verifier checks them with.

Index

Constants

View Source
const APIKey = "sk-ant-test-compliance-key"

APIKey is the key the fake accepts.

Variables

This section is empty.

Functions

This section is empty.

Types

type Log

type Log struct {
	Origin string
	Key    *LogKey
	// contains filtered or unexported fields
}

Log is an append-only in-memory Merkle log.

func New

func New(origin string) *Log

func (*Log) Append

func (l *Log) Append(entries ...[]byte) uint64

Append adds entries and returns the index of the first one.

func (*Log) Checkpoint

func (l *Log) Checkpoint(size uint64) []byte

Checkpoint returns the checkpoint for the first size leaves, signed by the log key.

func (*Log) CheckpointFor

func (l *Log) CheckpointFor(origin string, size uint64, root []byte) []byte

CheckpointFor signs an arbitrary (origin, size, root) — for forging.

func (*Log) ConsistencyProof

func (l *Log) ConsistencyProof(from, to uint64) [][]byte

func (*Log) Entry

func (l *Log) Entry(i uint64) []byte

func (*Log) InclusionProof

func (l *Log) InclusionProof(index, size uint64) [][]byte

func (*Log) RootAt

func (l *Log) RootAt(size uint64) []byte

func (*Log) SignedNote

func (l *Log) SignedNote(text string) []byte

SignedNote signs arbitrary note text with the log key.

func (*Log) Size

func (l *Log) Size() uint64

type LogKey

type LogKey struct {
	VKey string
	// contains filtered or unexported fields
}

LogKey is an ECDSA P-256 note signer shaped like the production log key: key name = origin, key hash = SHA-256(SPKI DER)[:4], verifier string "<origin>+<hash>+base64(0x02 || SPKI DER)".

func NewLogKey

func NewLogKey(origin string) *LogKey

func (*LogKey) KeyHash

func (k *LogKey) KeyHash() uint32

func (*LogKey) Name

func (k *LogKey) Name() string

func (*LogKey) Named

func (k *LogKey) Named(name string) *LogKey

Named returns the same key material under another name — how production signs every organization's log with one key named for each origin.

func (*LogKey) Sign

func (k *LogKey) Sign(msg []byte) ([]byte, error)

type Server

type Server struct {
	Log     *Log
	OrgUUID string
	HTTP    *httptest.Server

	// Published is the tree size the served checkpoint commits to; proofs
	// are computed against it. Publish() advances it to the log's size.
	Published uint64
	// Fault hooks. Zero values serve honestly.
	CheckpointOverride []byte            // served verbatim by /checkpoint
	InclusionAgainst   map[uint64]uint64 // leaf index → tree size its proof (and embedded checkpoint) use
	InclusionLeafSwap  map[uint64]uint64 // leaf index → index whose proof is served instead
	InclusionIndexLie  map[uint64]uint64 // leaf index → the leaf_index the answer reports
	ConsistencyGarbage bool              // /consistency serves a wrong proof
	FailNext           map[string][]int  // endpoint name → statuses to return before serving honestly
	FeedStuckCursor    bool              // /activities always reports more, with a cursor that never moves
	ProofsAhead        bool              // proof endpoints answer at the log's real size while /checkpoint lags at Published
	FeedStuckWithNew   bool              // /activities holds last_id constant while serving one new event per page
	Events             []json.RawMessage // the activity feed, any order
	Requests           map[string]int    // endpoint name → count
	// contains filtered or unexported fields
}

Server fakes the Compliance API endpoints axt-verify reads, over one Log.

func NewServer

func NewServer(l *Log) *Server

NewServer starts a fake over l for the organization its origin names.

func (*Server) Client

func (s *Server) Client() *http.Client

Client returns an HTTP client that trusts the fake's TLS certificate.

func (*Server) Close

func (s *Server) Close()

func (*Server) Publish

func (s *Server) Publish()

Publish makes the served checkpoint cover everything appended so far.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL