aere-proof-of-software/tools/proof-of-software/test/semnatar-control-negativ.mjs
Aere Network 065f84e34a Aere Proof of Software 1.4.0: an attestation of what was built, from what, by whom and when, verifiable without trusting Aere Network
Every artifact's SHA-256 and size, the SBOM's digest, the git commit and tree of the source, a hybrid signature (classical + ML-DSA,
both required) and, when notarized, a first-seen time on Aere Network covered by the validators' post-quantum certificate. verify
recomputes everything from the files; --rebuild-from repeats an npm pack build from a clone the verifier chose; the SBOM is
re-derived from the committed package-lock.json or, new in 1.4.0, from the committed go.mod and go.sum; --signer requires the
signing keys you expect (1.4.0); a developer credential binds the keys to a person, judged against a trust root you choose. The
builder's declared date can only accuse, never acquit (1.4.0). Includes the GitHub Action and the hybrid signature library it uses.

Laid out as in the development repository (tools/proof-of-software/, sdk-pq-sign/, sdk/) so that nothing is rewritten for
publication. Tests and negative controls measured on 2026-09-29 are listed in README.md.
2026-09-29 22:46:57 +03:00

12 lines
1.0 KiB
JavaScript

// Controlul negativ al semnatarului (semnatar.test.mjs, B-18), prin mecanismul comun din _control.mjs: fiecare paznic scos intr-o
// copie a lui pos.mjs trebuie sa inroseasca exact proba lui.
// node aerenew/tools/proof-of-software/test/semnatar-control-negativ.mjs
import { controleaza } from './_control.mjs';
process.exitCode = controleaza('semnatar.test.mjs', [
['--signer nu mai compara cheile', "!!semnatar && semnatar === keyId(publicKeysOf(signer))", '!!semnatar', '3. ATAC'],
['o atestare nesemnata trece de --signer', "!!semnatar && semnatar === keyId(publicKeysOf(signer))", 'true', '5. o atestare nesemnata'],
['randul "signer" nejudecat nu mai apare', "else if (!(att.statement.builder && att.statement.builder.credential && trustIssuer)) checks.push({ name: 'signer', pass: null,", "else if (false) checks.push({ name: 'signer', pass: null,", '2. fara --signer'],
['amprenta cheilor scoasa din numele verificarii', "by keys ${semnatar ? semnatar.slice(0, 18) : '?'}:", ':', '1. numele verificarii'],
]);