swisspost-evoting-go-poc/pkg/party/ceremony_test.go
saymrwulf 313db92321 Add party layer scaffolding: PKI bootstrap + signed handshake
pkg/party models each endpoint of the system as a separate object holding only
its own private state, wired together through the transport bus.

- ceremony.go: NewCeremony bootstraps the Ed25519 root CA, enrolls all parties
  (setup, 4 CCs, electoral board, voting server, verifier, N voters) with
  CA-signed identity certs, registers each in the directory, and wires its
  handler into the bus.
- parties.go: the six party types and a shared hello/ack handshake; Handshake()
  proves the full sign -> route -> verify -> reply -> verify path for every
  party before any election logic runs.
- state.go: per-party private state structs (nothing shared across parties).
- transcript.go: PublicTranscript, the append-only bulletin board a remote
  verifier will consume (no secrets).
- phases.go: phase handlers reject unknown message types cleanly (the transport
  boundary never panics on unexpected input) — filled in over the next commits.

Transport CA API simplified to own its serial counter (NewCA/Issue).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 15:07:31 +02:00

60 lines
1.7 KiB
Go

package party
import (
"math/big"
"testing"
emath "github.com/user/evote/pkg/math"
"github.com/user/evote/pkg/protocol"
)
const (
testP = "179688417486862032111147025351064878713905624387098436271724698527496946737299"
testQ = "89844208743431016055573512675532439356952812193549218135862349263748473368649"
testG = "4"
)
func testConfig(t *testing.T, numVoters, numOptions int) *protocol.Config {
t.Helper()
p, _ := new(big.Int).SetString(testP, 10)
q, _ := new(big.Int).SetString(testQ, 10)
g, _ := new(big.Int).SetString(testG, 10)
group, err := emath.NewGqGroup(p, q, g)
if err != nil {
t.Fatalf("test group: %v", err)
}
return &protocol.Config{
Group: group,
NumCCs: 4,
NumOptions: numOptions,
NumVoters: numVoters,
ElectionID: "party-unit-test",
SecurityLvl: 128,
}
}
// TestCeremonyBootstrapAndHandshake proves the full PKI + transport wiring:
// every party is enrolled with a CA-signed Ed25519 cert, registered in the
// directory, and reachable via a signed hello/ack exchange over the bus.
func TestCeremonyBootstrapAndHandshake(t *testing.T) {
cfg := testConfig(t, 3, 3)
c, err := NewCeremony(cfg, nil)
if err != nil {
t.Fatalf("NewCeremony: %v", err)
}
// Expected enrolled parties: setup, EB, server, verifier, 4 CCs, 3 voters.
wantParties := 4 + cfg.NumCCs + cfg.NumVoters
if got := len(c.CCs) + len(c.Voters) + 4; got != wantParties {
t.Fatalf("party count = %d, want %d", got, wantParties)
}
before := c.Bus.Count()
if err := c.Handshake(); err != nil {
t.Fatalf("handshake: %v", err)
}
// Each hello + ack is two verified messages; one exchange per non-setup party.
if c.Bus.Count() <= before {
t.Fatal("handshake carried no verified messages")
}
}