trackslash
VAULT-86 P2

Pin the encryption formats with golden fixtures

0
Sub-issue of VAULT-83 P2 Test that lock, unlock, encryption and restore work end to end

Description

Part of VAULT-83.

Why

The formats are tested piece by piece:

  • VaultSlotFileTests pins the header offsets, the HKDF labels, the byte-flip checks and the identical slot lengths.
  • Argon2idKeyDeriverTests has RFC 9106 known-answer tests.
  • VaultBackupEncryptorTests has a known-answer test for an empty backup.
  • Encrypted items are only round-tripped (VaultItemEncryptorTests, VaultItemDecryptorTests).

A change made on both the write side and the read side still passes all of these. Examples: the AAD layout (header with the slot size zeroed ‖ index ‖ nonce), the key box layout, a renamed payload field, or a padding change. Existing vaults, notes and backups would then stop opening. The README promises that old backups can always be restored, and vaults are on people's phones now.

Fixtures to add

Put them under the tests, with a README that says for each one: how it was made (the commit or release tag, and the script), the password, and what it should contain. The script must fix salts and nonces, or record them.

  • Slot file: a whole vault-slots.v1 file with several slots: a real vault, a duress vault and random slots. Each password opens its own slot to exactly the expected items, tags and settings. A wrong password opens nothing.
  • Encrypted items: an encrypted note and a recovery phrase, as a shipped build stores them. They must decrypt to the expected text with the known password.
  • Backup encryption: a known-answer test for a populated backup at a VAULT-75 bucket size, plus one from before VAULT-75's padding. Whole PDFs and QR codes belong to the restore sub-issue. This one pins the VaultBackupEncryptor / VaultBackupDecryptor bytes.
  • Calibration: a slot file made with one set of Argon2 parameters opens on a "device" that would calibrate differently. The design doc's "Test strategy" lists this test, but it doesn't exist.

Also

  • Zeroing: the design doc says some buffers are zeroed with memset_s: key-box and body plaintexts, the JSON, and the compression scratch space. Where it's practical, test that, the way Argon2idKeyDeriverTests does for the KDF's working memory. Where it isn't practical, say so in "Residual limits".
  • Rule, written in the fixtures README: never regenerate a fixture to make a test pass. A format change adds a new fixture and keeps every old one.

Done when

Each kind of fixture above is in the repo and opened by a test. The README explains how to add a fixture when a format changes.

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Done in https://github.com/badbundle/vault-app/pull/679, merged as 78a35cc6. It adds golden fixtures:

  • a slot file (a real vault, a duress vault and random slots, stored as the header plus its two vault slots, 2 MiB, with the rest rebuilt at test time);
  • an encrypted note and a recovery phrase;
  • a populated backup padded to 32 KiB, and one with random padding.

The READMEs set the rule: fixtures are never regenerated, and a format change adds one. Calibration is covered, and so is the compression scratch buffer being wiped.

While doing this, a flaky test turned up: encryptBackupPayload_toFixedSize_fillsTheMinimum. The padding missed its 16-byte window about once in 200 tries. That's fixed in https://github.com/badbundle/vault-app/pull/680, merged as 020d4df7.