289 lines
13 KiB
HTML
289 lines
13 KiB
HTML
<!DOCTYPE html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="UTF-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
|
|
<title>Testing Strategy | ChronoSeal Documentation</title>
|
|
<meta name="description" content="ChronoSeal testing strategy, detailing test categories, execution instructions, mock simulations, and release verification processes.">
|
|
<link rel="stylesheet" href="css/chronoseal.css">
|
|
<link rel="stylesheet" href="css/docs.css">
|
|
<link rel="stylesheet" href="css/print.css" media="print">
|
|
<link rel="manifest" href="site.webmanifest">
|
|
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
|
|
|
|
<!-- Font Awesome for Icons -->
|
|
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
|
|
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
|
|
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
|
|
crossorigin="anonymous"
|
|
referrerpolicy="no-referrer" />
|
|
</head>
|
|
<body>
|
|
|
|
<!-- Floating Background Spheres -->
|
|
<div class="bg-animation">
|
|
<div class="gradient-sphere sphere-1"></div>
|
|
<div class="gradient-sphere sphere-2"></div>
|
|
<div class="gradient-sphere sphere-3"></div>
|
|
</div>
|
|
|
|
<!-- Header / Navbar -->
|
|
<nav class="navbar" id="navbar">
|
|
<div class="nav-container">
|
|
<a href="index.html" class="logo">
|
|
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
|
|
<span>ChronoSeal</span>
|
|
</a>
|
|
<div class="nav-links" id="navLinks">
|
|
<a href="philosophy.html">Philosophy</a>
|
|
<a href="architecture.html">Architecture</a>
|
|
<a href="protocol.html">Protocol</a>
|
|
<a href="comparison.html">Comparison</a>
|
|
<div class="nav-dropdown">
|
|
<a href="#" class="nav-link">More <small>▼</small></a>
|
|
<div class="nav-dropdown-menu">
|
|
<a href="api.html">API Reference</a>
|
|
<a href="deployment.html">Deployment Guide</a>
|
|
<a href="operations.html">Operations Guide</a>
|
|
<a href="testing.html" class="active">Testing Strategy</a>
|
|
<a href="performance.html">Performance Tuning</a>
|
|
<a href="threat-model.html">Threat Model</a>
|
|
<a href="security.html">Security Policy</a>
|
|
<a href="privacy.html">Privacy Policy</a>
|
|
</div>
|
|
</div>
|
|
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
|
|
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
|
</button>
|
|
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
|
|
<i class="fab fa-github"></i> GitHub
|
|
</a>
|
|
</div>
|
|
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
|
|
<i class="fas fa-bars"></i>
|
|
</button>
|
|
</div>
|
|
</nav>
|
|
|
|
<!-- Doc Page Shell -->
|
|
<div class="doc-page">
|
|
<div class="doc-layout">
|
|
|
|
<!-- Sidebar -->
|
|
<aside class="doc-sidebar">
|
|
<button class="doc-sidebar-toggle">
|
|
<i class="fas fa-bars"></i> Sidebar Menu
|
|
</button>
|
|
<div class="doc-nav-group">
|
|
<div class="doc-nav-label">Core Concepts</div>
|
|
<a href="philosophy.html" class="doc-nav-item">Design Philosophy</a>
|
|
<a href="architecture.html" class="doc-nav-item">Architecture Overview</a>
|
|
<a href="comparison.html" class="doc-nav-item">ChronoSeal vs Others</a>
|
|
</div>
|
|
<div class="doc-nav-group">
|
|
<div class="doc-nav-label">Protocol & API</div>
|
|
<a href="protocol.html" class="doc-nav-item">Protocol Specification</a>
|
|
<a href="api.html" class="doc-nav-item">API Reference</a>
|
|
</div>
|
|
<div class="doc-nav-group">
|
|
<div class="doc-nav-label">Operations & Security</div>
|
|
<a href="threat-model.html" class="doc-nav-item">Threat Model</a>
|
|
<a href="security.html" class="doc-nav-item">Security Policy</a>
|
|
<a href="privacy.html" class="doc-nav-item">Privacy Policy</a>
|
|
<a href="performance.html" class="doc-nav-item">Performance Tuning</a>
|
|
</div>
|
|
<div class="doc-nav-group">
|
|
<div class="doc-nav-label">Lifecycle & Dev</div>
|
|
<a href="deployment.html" class="doc-nav-item">Deployment Guide</a>
|
|
<a href="operations.html" class="doc-nav-item">Operations Handbook</a>
|
|
<a href="testing.html" class="doc-nav-item active">Testing Strategy</a>
|
|
</div>
|
|
</aside>
|
|
|
|
<!-- Main Content Area -->
|
|
<main class="doc-main">
|
|
<nav class="doc-breadcrumb" aria-label="Breadcrumb">
|
|
<a href="index.html">Home</a>
|
|
<span class="sep">/</span>
|
|
<a href="#">Lifecycle & Dev</a>
|
|
<span class="sep">/</span>
|
|
<span>Testing Strategy</span>
|
|
</nav>
|
|
|
|
<article class="doc-content">
|
|
<h1>ChronoSeal Testing Strategy</h1>
|
|
<p class="doc-subtitle">ChronoSeal maintains a security-focused test suite designed to validate cryptographic correctness, client/server deterministic parity, and sandbox limits.</p>
|
|
|
|
<hr>
|
|
|
|
<p>As of <strong>v1.0.2</strong>, the project contains <strong>100 passing tests</strong> across the workspaces:</p>
|
|
<table>
|
|
<thead>
|
|
<tr>
|
|
<th>Workspace Crate</th>
|
|
<th>Test Count</th>
|
|
<th>Validation Scope</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr>
|
|
<td><code>chronoseal-server</code></td>
|
|
<td>38</td>
|
|
<td>API handlers, rate limiters, storage persistence, and fingerprint constraints</td>
|
|
</tr>
|
|
<tr>
|
|
<td><code>chronoseal-wasm</code></td>
|
|
<td>24</td>
|
|
<td>Key generation, signing, VM instruction runners, and state transitions</td>
|
|
</tr>
|
|
<tr>
|
|
<td><code>shared</code> (unit tests)</td>
|
|
<td>36</td>
|
|
<td>Blake3 folding, gene mutation opcodes, and program serializations</td>
|
|
</tr>
|
|
<tr>
|
|
<td><code>shared</code> (property tests)</td>
|
|
<td>2</td>
|
|
<td>Proptest input fuzzing to confirm panic-resistance invariants</td>
|
|
</tr>
|
|
<tr>
|
|
<td style="font-weight: bold;">Total</td>
|
|
<td style="font-weight: bold;">100</td>
|
|
<td style="font-weight: bold;">Comprehensive Attestation Coverage</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
<h2>Core Test Categories</h2>
|
|
|
|
<h3>1. Browser Fingerprint Hardening (v1.0.2)</h3>
|
|
<p>Enforces strict limits on metadata values to protect the attestation pipeline from adversarial inputs. Tests assert limits like CPU count (<code>1..=256</code>), device pixel ratio, aspect ratio bounds, and the rejection of malformed or non-finite values (<code>NaN</code> and <code>Infinity</code>).</p>
|
|
|
|
<h3>2. Session Lifecycle & Replay Resistance</h3>
|
|
<p>Verifies session establishing, expiration rules, and invalid key boundaries. Critical checks assert that repeating a successful heartbeat or tampering with the synthetic gene commitment leads to immediate rejection.</p>
|
|
|
|
<h3>3. Mathematical VM Engine Parity</h3>
|
|
<p>Evaluates VM opcode parsing, stack underflow boundaries, and wrapping arithmetic calculations (XOR, AND, Rotate, Add, Sub, Mul). Tests run the VM state engine across both WebAssembly and server Rust environments to confirm absolute mathematical consensus.</p>
|
|
|
|
<h3>4. Synthetic Gene Mutation Parity</h3>
|
|
<p>Validates state vector updates across seeded RNG sequences, table-driven inputs, and random program arrays to assert that the client and server gene buffers never drift.</p>
|
|
|
|
<h3>5. Property-Based Fuzzing</h3>
|
|
<p>Leverages <code>proptest</code> to exercise the VM execution and gene serialization paths under billions of random input vectors, guaranteeing that the daemon never panics on malformed network payloads.</p>
|
|
|
|
<h2>Running the Test Suite</h2>
|
|
<p>Run the entire workspace suite:</p>
|
|
<div class="code-block">
|
|
<div class="code-header">
|
|
<span class="code-lang">Shell</span>
|
|
<button class="code-copy-btn">Copy</button>
|
|
</div>
|
|
<pre><code>cargo test --workspace</code></pre>
|
|
</div>
|
|
|
|
<p>Run crate-specific test sets:</p>
|
|
<div class="code-block">
|
|
<div class="code-header">
|
|
<span class="code-lang">Shell</span>
|
|
<button class="code-copy-btn">Copy</button>
|
|
</div>
|
|
<pre><code># Test server components only
|
|
cargo test -p chronoseal-server
|
|
|
|
# Test fingerprint hardening suite only
|
|
cargo test -p chronoseal-server fingerprint
|
|
|
|
# Test WASM modules only
|
|
cargo test -p chronoseal-wasm
|
|
|
|
# Test shared libraries and property tests
|
|
cargo test -p shared</code></pre>
|
|
</div>
|
|
|
|
<h2>Release-Blocking Security Invariants</h2>
|
|
<p>The following unit tests guard critical security boundaries. Any failure in these tests blocks release compilation:</p>
|
|
<ul>
|
|
<li><code>test_replay_attack_is_rejected</code>: Protects against session hijack.</li>
|
|
<li><code>test_mutation_commitment_tamper_is_rejected</code>: Ensures gene commitment authenticity.</li>
|
|
<li><code>test_vm_execute_never_panics</code>: Ensures VM robustness against invalid opcodes.</li>
|
|
<li><code>rejects_invalid_aspect_ratios</code> / <code>rejects_invalid_hardware_concurrency</code>: Protects against fingerprint parser exploits.</li>
|
|
</ul>
|
|
</article>
|
|
|
|
<!-- Pager -->
|
|
<nav class="doc-pager" aria-label="Doc navigation Pager">
|
|
<a href="deployment.html" class="doc-pager-link">
|
|
<div class="doc-pager-label">Previous</div>
|
|
<div class="doc-pager-title">Deployment Guide</div>
|
|
</a>
|
|
<a href="index.html" class="doc-pager-link doc-pager-link--next">
|
|
<div class="doc-pager-label">Next</div>
|
|
<div class="doc-pager-title">Home Page</div>
|
|
</a>
|
|
</nav>
|
|
|
|
<div class="doc-meta">
|
|
Last Updated: June 2026 (v1.0.2)
|
|
</div>
|
|
</main>
|
|
|
|
</div>
|
|
</div>
|
|
|
|
<!-- Footer -->
|
|
<footer class="footer">
|
|
<div class="footer-content">
|
|
<div class="footer-section">
|
|
<h4>
|
|
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
|
|
</h4>
|
|
<p>Next-generation browser attestation daemon built for the modern web.</p>
|
|
</div>
|
|
<div class="footer-section">
|
|
<h4>Resources</h4>
|
|
<a href="philosophy.html">Design Philosophy</a>
|
|
<a href="architecture.html">Architecture</a>
|
|
<a href="protocol.html">Protocol</a>
|
|
<a href="api.html">API Reference</a>
|
|
<a href="comparison.html">Comparison</a>
|
|
</div>
|
|
<div class="footer-section">
|
|
<h4>Community</h4>
|
|
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
|
|
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
|
|
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
|
|
</div>
|
|
<div class="footer-section">
|
|
<h4>Legal & Security</h4>
|
|
<a href="security.html">Security Policy</a>
|
|
<a href="privacy.html">Privacy Policy</a>
|
|
<a href="performance.html">Performance Tuning</a>
|
|
<a href="operations.html">Operations Guide</a>
|
|
</div>
|
|
</div>
|
|
<div class="footer-bottom">
|
|
<p>© 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
|
|
</div>
|
|
</footer>
|
|
|
|
<!-- Search Overlay -->
|
|
<div class="search-overlay">
|
|
<div class="search-box">
|
|
<div class="search-input-wrap">
|
|
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
|
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
|
|
<span class="search-kbd">/</span>
|
|
</div>
|
|
<div class="search-results"></div>
|
|
</div>
|
|
</div>
|
|
|
|
<!-- Back to top -->
|
|
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
|
|
|
|
<!-- JS Scripts -->
|
|
<script src="js/search.js"></script>
|
|
<script src="js/app.js"></script>
|
|
</body>
|
|
</html>
|