cms: tag TimeStampedData / ERS types implicitly, as RFC 5544 and RFC 4998 define - #2465
Open
yuxi-liu-wired wants to merge 1 commit into
Open
yuxi-liu-wired wants to merge 1 commit into
yuxi-liu-wired wants to merge 1 commit into
Conversation
…4998 define Both ASN.1 modules are DEFINITIONS IMPLICIT TAGS, but the context-tagged fields of Evidence, EvidenceRecord and ArchiveTimeStamp used the derive's default, EXPLICIT. So cms could not decode an RFC-encoded evidence record: e.g. EvidenceRecord.encryptionInfo [1] fails with "expected SEQUENCE, got OBJECT IDENTIFIER", and encoding produced bytes other implementations don't read. Mark the eight fields tag_mode = "IMPLICIT" (constructed for the CHOICE alternatives, as in revocation.rs). New tests decode and re-encode an EvidenceRecord produced by pyasn1 from the RFC 4998 module, standalone and as Evidence::ErsEvidence.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
cms::timestamped_dataimplements RFC 5544 (TimeStampedData) and the RFC 4998 Evidence Record Syntax types it embeds. Both RFCs' ASN.1 modules areDEFINITIONS IMPLICIT TAGS(RFC 5544 Appendix A; RFC 4998 Appendices A and C), but the context-tagged fields here use the derive's default,EXPLICIT:Evidence ::= CHOICE { tstEvidence [0] …, ersEvidence [1] EvidenceRecord, otherEvidence [2] … }EvidenceRecord:cryptoInfos [0],encryptionInfo [1]ArchiveTimeStamp:digestAlgorithm [0],attributes [1],reducedHashtree [2]So RFC-encoded data doesn't decode. For an
EvidenceRecordencoded by pyasn1 from the RFC 4998 module:because
encryptionInfo [1]isa1 06 06 02 2a03 0500(the SEQUENCE tag replaced), while the derive expectsa1 08 30 06 …. Encoding has the mirror problem, and anArchiveTimeStampcarrying adigestAlgorithmorreducedHashtree(both present in practice) is affected the same way.The fix marks the eight fields
tag_mode = "IMPLICIT". The CHOICE alternatives are also markedconstructed = "true", asrevocation.rsalready does forRevocationInfoChoice.Tests:
tests/timestamped_data.rsdecodes the pyasn1-encodedEvidenceRecord(withencryptionInfo [1],digestAlgorithm [0]andreducedHashtree [2]) and re-encodes it byte for byte, standalone and asEvidence::ErsEvidence. Both fail on master. Thecms.ymlmatrix passed locally: powerset tests on stable and 1.85, thumbv7em powerset build, fmt, clippy.This PR was produced by AI agents (Claude) and reviewed by me before submission.