Skip to content

Testing

The library is tested at four levels: the draft's test vectors, unit tests, fuzz targets and an independent implementation in a separate module. This page explains how to run each level and what it proves.

Test vectors and unit tests

make test

Runs go vet and every test under the race detector with coverage written to the scratch directory. The root package tests load the draft-19 test vectors for all 15 algorithms and check encodings, signatures and the published certificates, as Tested implementations describes. Further tests cover signing options, context and pre-hash handling, tampered signatures, label separation between algorithms and malformed keys.

The compositex509 tests build a composite hierarchy for every algorithm, mixed hierarchies with ECDSA, RSA, RSA-PSS, Ed25519 and ML-DSA issuers, remote and faulty signers. They also cover the cases that must be refused.

Fuzzing

make fuzz
make fuzz FUZZ_TIME=2m

Fuzzes public key and PKCS #8 parsing, signature verification and certificate signature checks for FUZZ_TIME each. CI runs 30 seconds per target on every push. Go writes a failing input under the package's testdata/fuzz directory. Commit that input with the fix so it stays a regression test.

The target passes -fuzzminimizetime 0, so Go does not minimize inputs. Minimization stalls the workers for seconds at a time and a worker that is still busy when FUZZ_TIME expires makes Go report the run as failed with context deadline exceeded. Set FUZZ_MINIMIZE_TIME to a duration such as 1m when a crash is found and a smaller reproducer is wanted.

Interoperability

make test-interop

Downloads the pinned Bouncy Castle jars from Maven Central, checks their SHA-256 digests and runs interop/java/CompositeInterop.java with the java found on PATH. Go writes certificates, revocation lists, requests, keys and signatures for every algorithm. The Java program verifies them, writes its own set and reports one line per check. The Go test then verifies the Bouncy Castle set and fails when any expected check is missing.

The program runs as a single-file Java source, so no build tool is needed. Set BC_VERSION and the matching digests in the Makefile to test another Bouncy Castle release.