chiark / gitweb /
doc: Document summary values of TOFU_STATS
[gnupg2.git] / tests / openpgp / verify.scm
1 #!/usr/bin/env gpgscm
2
3 ;; Copyright (C) 2016 g10 Code GmbH
4 ;;
5 ;; This file is part of GnuPG.
6 ;;
7 ;; GnuPG is free software; you can redistribute it and/or modify
8 ;; it under the terms of the GNU General Public License as published by
9 ;; the Free Software Foundation; either version 3 of the License, or
10 ;; (at your option) any later version.
11 ;;
12 ;; GnuPG is distributed in the hope that it will be useful,
13 ;; but WITHOUT ANY WARRANTY; without even the implied warranty of
14 ;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15 ;; GNU General Public License for more details.
16 ;;
17 ;; You should have received a copy of the GNU General Public License
18 ;; along with this program; if not, see <http://www.gnu.org/licenses/>.
19
20 (load (with-path "defs.scm"))
21 (setup-legacy-environment)
22
23 ;;
24 ;; Two simple tests to check that verify fails for bad input data
25 ;;
26 (for-each-p
27  "Checking bogus signature"
28  (lambda (char)
29    (lettmp (x)
30      (call-with-binary-output-file
31       x
32       (lambda (port)
33         (display (make-string 64 (integer->char (string->number char)))
34                  port)))
35      (if (= 0 (call `(,@GPG --verify ,x data-500)))
36          (fail "no error code from verify"))))
37  '("#x2d" "#xca"))
38
39 ;; A plain signed message created using
40 ;;  echo abc | gpg --homedir . --passphrase-fd 0 -u Alpha -z0 -sa msg
41 (define msg_ols_asc "
42 -----BEGIN PGP MESSAGE-----
43
44 kA0DAAIRLXJ8x2hpdzQBrQEHYgNtc2dEDFJaSSB0aGluayB0aGF0IGFsbCByaWdo
45 dC10aGlua2luZyBwZW9wbGUgaW4gdGhpcyBjb3VudHJ5IGFyZSBzaWNrIGFuZAp0
46 aXJlZCBvZiBiZWluZyB0b2xkIHRoYXQgb3JkaW5hcnkgZGVjZW50IHBlb3BsZSBh
47 cmUgZmVkIHVwIGluIHRoaXMKY291bnRyeSB3aXRoIGJlaW5nIHNpY2sgYW5kIHRp
48 cmVkLiAgSSdtIGNlcnRhaW5seSBub3QuICBCdXQgSSdtCnNpY2sgYW5kIHRpcmVk
49 IG9mIGJlaW5nIHRvbGQgdGhhdCBJIGFtLgotIE1vbnR5IFB5dGhvbgqIPwMFAEQM
50 UlotcnzHaGl3NBECR4IAoJlEGTY+bHjD2HYuCixLQCmk01pbAKCIjkzLOAmkZNm0
51 D8luT78c/1x45Q==
52 =a29i
53 -----END PGP MESSAGE-----
54 ")
55
56 ;; A plain signed message created using
57 ;;  echo abc | gpg --homedir . --passphrase-fd 0 -u Alpha -sa msg
58 (define msg_cols_asc "
59 -----BEGIN PGP MESSAGE-----
60
61 owGbwMvMwCSoW1RzPCOz3IRxLSN7EnNucboLT6Cgp0JJRmZeNpBMLFFIzMlRKMpM
62 zyjRBQtm5qUrFKTmF+SkKmTmgdQVKyTnl+aVFFUqJBalKhRnJmcrJOalcJVkFqWm
63 KOSnKSSlgrSU5OekQMzLL0rJzEsEKk9JTU7NK4EZBtKcBtRRWgAzlwtmbnlmSQbU
64 GJjxCmDj9RQUPNVzFZJTi0oSM/NyKhXy8kuAYk6lJSBxLlTF2NziqZCYq8elq+Cb
65 n1dSqRBQWZKRn8fVYc/MygAKBljYCDIFiTDMT+9seu836Q+bevyHTJ0dzPNuvCjn
66 ZpgrwX38z58rJsfYDhwOSS4SkN/d6vUAAA==
67 =s6sY
68 -----END PGP MESSAGE-----
69 ")
70
71 ;; A PGP 2 style message.
72 (define msg_sl_asc "
73 -----BEGIN PGP MESSAGE-----
74
75 iD8DBQBEDFJaLXJ8x2hpdzQRAkeCAKCZRBk2Pmx4w9h2LgosS0AppNNaWwCgiI5M
76 yzgJpGTZtA/Jbk+/HP9ceOWtAQdiA21zZ0QMUlpJIHRoaW5rIHRoYXQgYWxsIHJp
77 Z2h0LXRoaW5raW5nIHBlb3BsZSBpbiB0aGlzIGNvdW50cnkgYXJlIHNpY2sgYW5k
78 CnRpcmVkIG9mIGJlaW5nIHRvbGQgdGhhdCBvcmRpbmFyeSBkZWNlbnQgcGVvcGxl
79 IGFyZSBmZWQgdXAgaW4gdGhpcwpjb3VudHJ5IHdpdGggYmVpbmcgc2ljayBhbmQg
80 dGlyZWQuICBJJ20gY2VydGFpbmx5IG5vdC4gIEJ1dCBJJ20Kc2ljayBhbmQgdGly
81 ZWQgb2YgYmVpbmcgdG9sZCB0aGF0IEkgYW0uCi0gTW9udHkgUHl0aG9uCg==
82 =0ukK
83 -----END PGP MESSAGE-----
84 ")
85
86 ;; An OpenPGP message lacking the onepass packet.  We used to accept
87 ;; such messages but now consider them invalid.
88 (define bad_ls_asc "
89 -----BEGIN PGP MESSAGE-----
90
91 rQEHYgNtc2dEDFJaSSB0aGluayB0aGF0IGFsbCByaWdodC10aGlua2luZyBwZW9w
92 bGUgaW4gdGhpcyBjb3VudHJ5IGFyZSBzaWNrIGFuZAp0aXJlZCBvZiBiZWluZyB0
93 b2xkIHRoYXQgb3JkaW5hcnkgZGVjZW50IHBlb3BsZSBhcmUgZmVkIHVwIGluIHRo
94 aXMKY291bnRyeSB3aXRoIGJlaW5nIHNpY2sgYW5kIHRpcmVkLiAgSSdtIGNlcnRh
95 aW5seSBub3QuICBCdXQgSSdtCnNpY2sgYW5kIHRpcmVkIG9mIGJlaW5nIHRvbGQg
96 dGhhdCBJIGFtLgotIE1vbnR5IFB5dGhvbgqIPwMFAEQMUlotcnzHaGl3NBECR4IA
97 oJlEGTY+bHjD2HYuCixLQCmk01pbAKCIjkzLOAmkZNm0D8luT78c/1x45Q==
98 =Mpiu
99 -----END PGP MESSAGE-----
100 ")
101
102
103 ;; A signed message prefixed with an unsigned literal packet.
104 ;; (fols = faked-literal-data, one-pass, literal-data, signature)
105 ;; This should throw an error because running gpg to extract the
106 ;; signed data will return both literal data packets
107 (define bad_fols_asc "
108 -----BEGIN PGP MESSAGE-----
109
110 rF1iDG1zZy51bnNpZ25lZEQMY0x0aW1lc2hhcmluZywgbjoKCUFuIGFjY2VzcyBt
111 ZXRob2Qgd2hlcmVieSBvbmUgY29tcHV0ZXIgYWJ1c2VzIG1hbnkgcGVvcGxlLgqQ
112 DQMAAhEtcnzHaGl3NAGtAQdiA21zZ0QMUlpJIHRoaW5rIHRoYXQgYWxsIHJpZ2h0
113 LXRoaW5raW5nIHBlb3BsZSBpbiB0aGlzIGNvdW50cnkgYXJlIHNpY2sgYW5kCnRp
114 cmVkIG9mIGJlaW5nIHRvbGQgdGhhdCBvcmRpbmFyeSBkZWNlbnQgcGVvcGxlIGFy
115 ZSBmZWQgdXAgaW4gdGhpcwpjb3VudHJ5IHdpdGggYmVpbmcgc2ljayBhbmQgdGly
116 ZWQuICBJJ20gY2VydGFpbmx5IG5vdC4gIEJ1dCBJJ20Kc2ljayBhbmQgdGlyZWQg
117 b2YgYmVpbmcgdG9sZCB0aGF0IEkgYW0uCi0gTW9udHkgUHl0aG9uCog/AwUARAxS
118 Wi1yfMdoaXc0EQJHggCgmUQZNj5seMPYdi4KLEtAKaTTWlsAoIiOTMs4CaRk2bQP
119 yW5Pvxz/XHjl
120 =UNM4
121 -----END PGP MESSAGE-----
122 ")
123
124 ;; A signed message suffixed with an unsigned literal packet.
125 ;; (fols = faked-literal-data, one-pass, literal-data, signature)
126 ;; This should throw an error because running gpg to extract the
127 ;; signed data will return both literal data packets
128 (define bad_olsf_asc "
129 -----BEGIN PGP MESSAGE-----
130
131 kA0DAAIRLXJ8x2hpdzQBrQEHYgNtc2dEDFJaSSB0aGluayB0aGF0IGFsbCByaWdo
132 dC10aGlua2luZyBwZW9wbGUgaW4gdGhpcyBjb3VudHJ5IGFyZSBzaWNrIGFuZAp0
133 aXJlZCBvZiBiZWluZyB0b2xkIHRoYXQgb3JkaW5hcnkgZGVjZW50IHBlb3BsZSBh
134 cmUgZmVkIHVwIGluIHRoaXMKY291bnRyeSB3aXRoIGJlaW5nIHNpY2sgYW5kIHRp
135 cmVkLiAgSSdtIGNlcnRhaW5seSBub3QuICBCdXQgSSdtCnNpY2sgYW5kIHRpcmVk
136 IG9mIGJlaW5nIHRvbGQgdGhhdCBJIGFtLgotIE1vbnR5IFB5dGhvbgqIPwMFAEQM
137 UlotcnzHaGl3NBECR4IAoJlEGTY+bHjD2HYuCixLQCmk01pbAKCIjkzLOAmkZNm0
138 D8luT78c/1x45axdYgxtc2cudW5zaWduZWREDGNMdGltZXNoYXJpbmcsIG46CglB
139 biBhY2Nlc3MgbWV0aG9kIHdoZXJlYnkgb25lIGNvbXB1dGVyIGFidXNlcyBtYW55
140 IHBlb3BsZS4K
141 =3gnG
142 -----END PGP MESSAGE-----
143 ")
144
145
146 ;; Two standard signed messages in a row
147 (define msg_olsols_asc_multiple "
148 -----BEGIN PGP MESSAGE-----
149
150 kA0DAAIRLXJ8x2hpdzQBrQEHYgNtc2dEDFJaSSB0aGluayB0aGF0IGFsbCByaWdo
151 dC10aGlua2luZyBwZW9wbGUgaW4gdGhpcyBjb3VudHJ5IGFyZSBzaWNrIGFuZAp0
152 aXJlZCBvZiBiZWluZyB0b2xkIHRoYXQgb3JkaW5hcnkgZGVjZW50IHBlb3BsZSBh
153 cmUgZmVkIHVwIGluIHRoaXMKY291bnRyeSB3aXRoIGJlaW5nIHNpY2sgYW5kIHRp
154 cmVkLiAgSSdtIGNlcnRhaW5seSBub3QuICBCdXQgSSdtCnNpY2sgYW5kIHRpcmVk
155 IG9mIGJlaW5nIHRvbGQgdGhhdCBJIGFtLgotIE1vbnR5IFB5dGhvbgqIPwMFAEQM
156 UlotcnzHaGl3NBECR4IAoJlEGTY+bHjD2HYuCixLQCmk01pbAKCIjkzLOAmkZNm0
157 D8luT78c/1x45ZANAwACES1yfMdoaXc0Aa0BB2IDbXNnRAxSWkkgdGhpbmsgdGhh
158 dCBhbGwgcmlnaHQtdGhpbmtpbmcgcGVvcGxlIGluIHRoaXMgY291bnRyeSBhcmUg
159 c2ljayBhbmQKdGlyZWQgb2YgYmVpbmcgdG9sZCB0aGF0IG9yZGluYXJ5IGRlY2Vu
160 dCBwZW9wbGUgYXJlIGZlZCB1cCBpbiB0aGlzCmNvdW50cnkgd2l0aCBiZWluZyBz
161 aWNrIGFuZCB0aXJlZC4gIEknbSBjZXJ0YWlubHkgbm90LiAgQnV0IEknbQpzaWNr
162 IGFuZCB0aXJlZCBvZiBiZWluZyB0b2xkIHRoYXQgSSBhbS4KLSBNb250eSBQeXRo
163 b24KiD8DBQBEDFJaLXJ8x2hpdzQRAkeCAKCZRBk2Pmx4w9h2LgosS0AppNNaWwCg
164 iI5MyzgJpGTZtA/Jbk+/HP9ceOU=
165 =8nLN
166 -----END PGP MESSAGE-----
167 ")
168
169 ;; A standard message with two signatures (actually the same signature
170 ;; duplicated).
171 (define msg_oolss_asc "
172 -----BEGIN PGP MESSAGE-----
173
174 kA0DAAIRLXJ8x2hpdzQBkA0DAAIRLXJ8x2hpdzQBrQEHYgNtc2dEDFJaSSB0aGlu
175 ayB0aGF0IGFsbCByaWdodC10aGlua2luZyBwZW9wbGUgaW4gdGhpcyBjb3VudHJ5
176 IGFyZSBzaWNrIGFuZAp0aXJlZCBvZiBiZWluZyB0b2xkIHRoYXQgb3JkaW5hcnkg
177 ZGVjZW50IHBlb3BsZSBhcmUgZmVkIHVwIGluIHRoaXMKY291bnRyeSB3aXRoIGJl
178 aW5nIHNpY2sgYW5kIHRpcmVkLiAgSSdtIGNlcnRhaW5seSBub3QuICBCdXQgSSdt
179 CnNpY2sgYW5kIHRpcmVkIG9mIGJlaW5nIHRvbGQgdGhhdCBJIGFtLgotIE1vbnR5
180 IFB5dGhvbgqIPwMFAEQMUlotcnzHaGl3NBECR4IAoJlEGTY+bHjD2HYuCixLQCmk
181 01pbAKCIjkzLOAmkZNm0D8luT78c/1x45Yg/AwUARAxSWi1yfMdoaXc0EQJHggCg
182 mUQZNj5seMPYdi4KLEtAKaTTWlsAoIiOTMs4CaRk2bQPyW5Pvxz/XHjl
183 =KVw5
184 -----END PGP MESSAGE-----
185 ")
186
187 ;; A standard message with two one-pass packet but only one signature
188 ;; packet
189 (define bad_ools_asc "
190 -----BEGIN PGP MESSAGE-----
191
192 kA0DAAIRLXJ8x2hpdzQBkA0DAAIRLXJ8x2hpdzQBrQEHYgNtc2dEDFJaSSB0aGlu
193 ayB0aGF0IGFsbCByaWdodC10aGlua2luZyBwZW9wbGUgaW4gdGhpcyBjb3VudHJ5
194 IGFyZSBzaWNrIGFuZAp0aXJlZCBvZiBiZWluZyB0b2xkIHRoYXQgb3JkaW5hcnkg
195 ZGVjZW50IHBlb3BsZSBhcmUgZmVkIHVwIGluIHRoaXMKY291bnRyeSB3aXRoIGJl
196 aW5nIHNpY2sgYW5kIHRpcmVkLiAgSSdtIGNlcnRhaW5seSBub3QuICBCdXQgSSdt
197 CnNpY2sgYW5kIHRpcmVkIG9mIGJlaW5nIHRvbGQgdGhhdCBJIGFtLgotIE1vbnR5
198 IFB5dGhvbgqIPwMFAEQMUlotcnzHaGl3NBECR4IAoJlEGTY+bHjD2HYuCixLQCmk
199 01pbAKCIjkzLOAmkZNm0D8luT78c/1x45Q==
200 =1/ix
201 -----END PGP MESSAGE-----
202 ")
203
204 ;; Standard cleartext signature
205 (define msg_cls_asc "
206 -----BEGIN PGP SIGNED MESSAGE-----
207 Hash: SHA1
208
209 I think that all right-thinking people in this country are sick and
210 tired of being told that ordinary decent people are fed up in this
211 country with being sick and tired.  I'm certainly not.  But I'm
212 sick and tired of being told that I am.
213 - - Monty Python
214 -----BEGIN PGP SIGNATURE-----
215
216 iD8DBQFEDVp1LXJ8x2hpdzQRAplUAKCMfpG3GPw/TLN52tosgXP5lNECkwCfQhAa
217 emmev7IuQjWYrGF9Lxj+zj8=
218 =qJsY
219 -----END PGP SIGNATURE-----
220 ")
221
222 ;; Cleartext signature with two signatures
223 (define msg_clss_asc "
224 -----BEGIN PGP SIGNED MESSAGE-----
225 Hash: SHA1
226
227 What is the difference between a Turing machine and the modern computer?
228 It's the same as that between Hillary's ascent of Everest and the
229 establishment of a Hilton on its peak.
230 -----BEGIN PGP SIGNATURE-----
231
232 iD8DBQFEDVz6LXJ8x2hpdzQRAtkGAKCeMhNbHnh339fpjNj9owsYcC4zBwCfYO5l
233 2u+KEfXX0FKyk8SMzLjZ536IPwMFAUQNXPr+GAsdqeOwshEC2QYAoPOWAiQm0EF/
234 FWIAQUplk7JWbyRKAJ92ZJyJpWfzb0yc1s7MY65r2qEHrg==
235 =1Xvv
236 -----END PGP SIGNATURE-----
237 ")
238
239 ;; Two clear text signatures in a row
240 (define msg_clsclss_asc_multiple (string-append msg_cls_asc msg_clss_asc))
241
242
243 ;; An Ed25519 cleartext message with an R parameter of only 247 bits
244 ;; so that the code to re-insert the stripped zero byte kicks in.  The
245 ;; S parameter has 253 bits but that does not strip a full byte.
246 (define msg_ed25519_rshort "
247 -----BEGIN PGP SIGNED MESSAGE-----
248 Hash: SHA256
249
250 Dear Emily:
251         I'm still confused as to what groups articles should be posted
252 to.  How about an example?
253                 -- Still Confused
254
255 Dear Still:
256         Ok.  Let's say you want to report that Gretzky has been traded from
257 the Oilers to the Kings.  Now right away you might think rec.sport.hockey
258 would be enough.  WRONG.  Many more people might be interested.  This is a
259 big trade!  Since it's a NEWS article, it belongs in the news.* hierarchy
260 as well.  If you are a news admin, or there is one on your machine, try
261 news.admin.  If not, use news.misc.
262         The Oilers are probably interested in geology, so try sci.physics.
263 He is a big star, so post to sci.astro, and sci.space because they are also
264 interested in stars.  Next, his name is Polish sounding.  So post to
265 soc.culture.polish.  But that group doesn't exist, so cross-post to
266 news.groups suggesting it should be created.  With this many groups of
267 interest, your article will be quite bizarre, so post to talk.bizarre as
268 well.  (And post to comp.std.mumps, since they hardly get any articles
269 there, and a \"comp\" group will propagate your article further.)
270         You may also find it is more fun to post the article once in each
271 group.  If you list all the newsgroups in the same article, some newsreaders
272 will only show the the article to the reader once!  Don't tolerate this.
273                 -- Emily Postnews Answers Your Questions on Netiquette
274 -----BEGIN PGP SIGNATURE-----
275
276 iJEEARYIADoWIQSyHeq0+HX7PaQvHR0TlWNoKgINCgUCV772DhwccGF0cmljZS5s
277 dW11bWJhQGV4YW1wbGUubmV0AAoJEBOVY2gqAg0KMAIA90EtUwAja0iJGpO91wyz
278 GLh9pS5v495V0r94yU6uUyUA/RT/StyPWe1wbnEZuacZnLbUV6Yy/aTXCVAlxf0r
279 TusO
280 =vQ3f
281 -----END PGP SIGNATURE-----
282 ")
283
284 ;; An Ed25519 cleartext message with an S parameter of only 248 bits
285 ;; so that the code to re-insert the stripped zero byte kicks in.
286 (define msg_ed25519_sshort "
287 -----BEGIN PGP SIGNED MESSAGE-----
288 Hash: SHA256
289
290 All articles that coruscate with resplendence are not truly auriferous.
291 -----BEGIN PGP SIGNATURE-----
292
293 iJEEARYIADoWIQSyHeq0+HX7PaQvHR0TlWNoKgINCgUCV771QhwccGF0cmljZS5s
294 dW11bWJhQGV4YW1wbGUubmV0AAoJEBOVY2gqAg0KHVEBAI66OPDYXKWO3r6SaFT+
295 uxmh8x4ZerW41vMA9gkJ4AEKAPjoe/Z7fDqo1lCptIFutFAGbfNxcm/53prfx2fT
296 GisM
297 =L7sk
298 -----END PGP SIGNATURE-----
299 ")
300
301
302
303 ;; Fixme:  We need more tests with manipulated cleartext signatures.
304
305 ;;
306 ;; Now run the tests.
307 ;;
308 (for-each-p
309  "Checking that a valid signature is verified as such"
310  (lambda (armored-file)
311    (pipe:do
312     (pipe:echo (eval armored-file (current-environment)))
313     (pipe:spawn `(,@GPG --verify))))
314  '(msg_ols_asc msg_cols_asc msg_sl_asc msg_oolss_asc msg_cls_asc msg_clss_asc))
315
316 (for-each-p
317  "Checking that a valid signature over multiple messages is verified as such"
318  (lambda (armored-file)
319    (pipe:do
320     (pipe:echo (eval armored-file (current-environment)))
321     (pipe:spawn `(,@GPG --verify --allow-multiple-messages)))
322    (catch '()
323           (pipe:do
324            (pipe:defer (lambda (sink)
325                          (display armored-file (fdopen sink "w"))))
326            (pipe:spawn `(,@GPG --verify)))
327           (fail "verification succeeded but should not")))
328  '(msg_olsols_asc_multiple msg_clsclss_asc_multiple))
329
330 (for-each-p
331  "Checking that an invalid signature is verified as such"
332  (lambda (armored-file)
333    (catch '()
334           (pipe:do
335            (pipe:echo (eval armored-file (current-environment)))
336            (pipe:spawn `(,@GPG --verify)))
337           (fail "verification succeeded but should not")))
338  '(bad_ls_asc bad_fols_asc bad_olsf_asc bad_ools_asc))
339
340
341 ;;; Need to import the ed25519 sample key used for
342 ;;; the next two tests.
343 (call-check `(,@GPG --quiet --yes --import ,(in-srcdir key-file2)))
344 (for-each-p
345  "Checking that a valid Ed25519 signature is verified as such"
346  (lambda (armored-file)
347    (pipe:do
348     (pipe:echo (eval armored-file (current-environment)))
349     (pipe:spawn `(,@GPG --verify))))
350  '(msg_ed25519_rshort msg_ed25519_sshort))