diff --git a/conformance/driver-ct/deltic/README.md b/conformance/driver-ct/deltic/README.md index 164c992..d55987f 100644 --- a/conformance/driver-ct/deltic/README.md +++ b/conformance/driver-ct/deltic/README.md @@ -93,7 +93,7 @@ that version in **two** places, cross-checked by SAME `@deltic/runtime/embedder` version (the module-identity constraint: deltic's `wasi-shims` imports that specifier by bare name internally, so every config resolving it must agree, or the embedder - module loads twice and `instanceof WitError` stops holding across the + module loads twice and `instanceof ComponentException` stops holding across the boundary). Both `deno.json` files also carry diff --git a/conformance/driver-ct/deltic/browser/worker-entry.ts b/conformance/driver-ct/deltic/browser/worker-entry.ts index f51597f..6ad3bc0 100644 --- a/conformance/driver-ct/deltic/browser/worker-entry.ts +++ b/conformance/driver-ct/deltic/browser/worker-entry.ts @@ -3,7 +3,7 @@ // exact-pinned JSR import map), the upstream // worker message loop, and this repo's deltic host module, resolved // through ONE import map so the emitted bundle carries exactly one -// embedder module instance — which is what keeps `instanceof WitError` +// embedder module instance — which is what keeps `instanceof ComponentException` // true when the host module throws across the component boundary // (workers resolve no import maps, so bundling is the only sound shape; // see @polymorph/component-test-js's runner-deltic README). diff --git a/conformance/driver-ct/deltic/deno.json b/conformance/driver-ct/deltic/deno.json index 03aa33d..ccb26f6 100644 --- a/conformance/driver-ct/deltic/deno.json +++ b/conformance/driver-ct/deltic/deno.json @@ -1,11 +1,11 @@ { - "//": "MODULE-IDENTITY CONSTRAINT: deltic's wasi-shims module imports @deltic/runtime/embedder by bare specifier internally. The @deltic/runtime/embedder entry here must map to the IDENTICAL exact-pinned JSR version as ../../../js/deltic/deno.json's entry, or the embedder module loads twice and `instanceof WitError` stops holding across the module boundary. The hash names one upstream commit; deno.lock carries integrity, --frozen enforced; the pin gate (just conformance-ct::deltic-pin-check) asserts one @deltic version repo-wide.", + "//": "MODULE-IDENTITY CONSTRAINT: deltic's wasi-shims module imports @deltic/runtime/embedder by bare specifier internally. The @deltic/runtime/embedder entry here must map to the IDENTICAL exact-pinned JSR version as ../../../js/deltic/deno.json's entry, or the embedder module loads twice and `instanceof ComponentException` stops holding across the module boundary. The hash names one upstream commit; deno.lock carries integrity, --frozen enforced; the pin gate (just conformance-ct::deltic-pin-check) asserts one @deltic version repo-wide.", "imports": { - "@deltic/ct-runner": "jsr:@deltic/ct-runner@0.1.0-pre.ga67ee83", - "@deltic/runtime/embedder": "jsr:@deltic/runtime@0.1.0-pre.ga67ee83/embedder", - "@deltic/runtime/shim": "jsr:@deltic/runtime@0.1.0-pre.ga67ee83/shim", - "@deltic/wasi-shims": "jsr:@deltic/wasi-shims@0.1.0-pre.ga67ee83", - "@deltic/translator": "jsr:@deltic/translator@0.1.0-pre.ga67ee83", + "@deltic/ct-runner": "jsr:@deltic/ct-runner@0.1.0-pre.g078aa15", + "@deltic/runtime/embedder": "jsr:@deltic/runtime@0.1.0-pre.g078aa15/embedder", + "@deltic/runtime/shim": "jsr:@deltic/runtime@0.1.0-pre.g078aa15/shim", + "@deltic/wasi-shims": "jsr:@deltic/wasi-shims@0.1.0-pre.g078aa15", + "@deltic/translator": "jsr:@deltic/translator@0.1.0-pre.g078aa15", "@polymorph/component-test-js/deltic-worker-main": "./node_modules/@polymorph/component-test-js/js/runner-deltic/worker-main.mjs" }, "minimumDependencyAge": { "age": "P1D", "exclude": ["jsr:@deltic/*"] }, diff --git a/conformance/driver-ct/deltic/deno.lock b/conformance/driver-ct/deltic/deno.lock index 61b993e..998de3a 100644 --- a/conformance/driver-ct/deltic/deno.lock +++ b/conformance/driver-ct/deltic/deno.lock @@ -1,33 +1,41 @@ { "version": "5", "specifiers": { - "jsr:@deltic/ct-runner@0.1.0-pre.ga67ee83": "0.1.0-pre.ga67ee83", - "jsr:@deltic/runtime@0.1.0-pre.ga67ee83": "0.1.0-pre.ga67ee83", - "jsr:@deltic/runtime@~0.1.0-pre.ga67ee83": "0.1.0-pre.ga67ee83", - "jsr:@deltic/translator@0.1.0-pre.ga67ee83": "0.1.0-pre.ga67ee83", - "jsr:@deltic/wasi-shims@0.1.0-pre.ga67ee83": "0.1.0-pre.ga67ee83", + "jsr:@deltic/ct-runner@0.1.0-pre.g078aa15": "0.1.0-pre.g078aa15", + "jsr:@deltic/protocol@0.2": "0.2.0", + "jsr:@deltic/runtime@0.1.0-pre.g078aa15": "0.1.0-pre.g078aa15", + "jsr:@deltic/runtime@~0.1.0-pre.g078aa15": "0.1.0-pre.g078aa15", + "jsr:@deltic/translator@0.1.0-pre.g078aa15": "0.1.0-pre.g078aa15", + "jsr:@deltic/wasi-shims@0.1.0-pre.g078aa15": "0.1.0-pre.g078aa15", "npm:playwright-core@1.62.1": "1.62.1" }, "jsr": { - "@deltic/ct-runner@0.1.0-pre.ga67ee83": { - "integrity": "d78e96eba54e53dabe7c1de5a67782aad755362824d741913ab4d36941ebfbcc", + "@deltic/ct-runner@0.1.0-pre.g078aa15": { + "integrity": "d777a53e6be337d999a80de030628e1226ae7649ca62e49dd444e58d0973e6be", "dependencies": [ - "jsr:@deltic/runtime@~0.1.0-pre.ga67ee83" + "jsr:@deltic/runtime@~0.1.0-pre.g078aa15" ] }, - "@deltic/runtime@0.1.0-pre.ga67ee83": { - "integrity": "2a2b0949031747a2340dc186299e654ea9f361ae39ac6bd633019940682db4ed" + "@deltic/protocol@0.2.0": { + "integrity": "028be6a3623c5e910598aa7a199209b85e8931ae484ac7f6638d610ddb0e19fa" }, - "@deltic/translator@0.1.0-pre.ga67ee83": { - "integrity": "e4f1bb219e56b62262b0c9665e3f6646aa13883b2cfbb9d6306f69d19974d412", + "@deltic/runtime@0.1.0-pre.g078aa15": { + "integrity": "5e64f8dc6d32190ecd394d6ad9881eb0fa97b6598b1e7f2ef1d52cff4674287c", "dependencies": [ - "jsr:@deltic/runtime@~0.1.0-pre.ga67ee83" + "jsr:@deltic/protocol" ] }, - "@deltic/wasi-shims@0.1.0-pre.ga67ee83": { - "integrity": "a5754e65d50873e675695a51279989e22b3771e31f16a84a09feb15905c574a7", + "@deltic/translator@0.1.0-pre.g078aa15": { + "integrity": "7125f99ac46af4a69f1c432def2b7ea4be63509c3a7ebae83537357615ec33ef", "dependencies": [ - "jsr:@deltic/runtime@~0.1.0-pre.ga67ee83" + "jsr:@deltic/runtime@~0.1.0-pre.g078aa15" + ] + }, + "@deltic/wasi-shims@0.1.0-pre.g078aa15": { + "integrity": "fba2081f804eaaccf95e31cdd634fd85a2d724f6be7f62578ddc26aef03524a1", + "dependencies": [ + "jsr:@deltic/protocol", + "jsr:@deltic/runtime@~0.1.0-pre.g078aa15" ] } }, @@ -39,10 +47,10 @@ }, "workspace": { "dependencies": [ - "jsr:@deltic/ct-runner@0.1.0-pre.ga67ee83", - "jsr:@deltic/runtime@0.1.0-pre.ga67ee83", - "jsr:@deltic/translator@0.1.0-pre.ga67ee83", - "jsr:@deltic/wasi-shims@0.1.0-pre.ga67ee83" + "jsr:@deltic/ct-runner@0.1.0-pre.g078aa15", + "jsr:@deltic/runtime@0.1.0-pre.g078aa15", + "jsr:@deltic/translator@0.1.0-pre.g078aa15", + "jsr:@deltic/wasi-shims@0.1.0-pre.g078aa15" ], "packageJson": { "dependencies": [ diff --git a/conformance/driver-ct/deltic/run.ts b/conformance/driver-ct/deltic/run.ts index 1afd953..dd2f6c5 100644 --- a/conformance/driver-ct/deltic/run.ts +++ b/conformance/driver-ct/deltic/run.ts @@ -75,7 +75,7 @@ // `@deltic/runtime/embedder` by bare specifier internally; this leg's // `deno.json` AND `js/deltic/deno.json` must map that specifier to the // IDENTICAL exact-pinned JSR version, or the embedder module loads twice -// and `instanceof WitError` stops holding across the module boundary. +// and `instanceof ComponentException` stops holding across the module boundary. // `just conformance-ct::deltic-pin-check` gates that. import { Translator } from "@deltic/runtime/shim"; diff --git a/js/deltic/README.md b/js/deltic/README.md index 04d4f5f..e341fb3 100644 --- a/js/deltic/README.md +++ b/js/deltic/README.md @@ -5,7 +5,7 @@ host — one platform-WebCrypto-backed implementation of every `polymorph:webcrypto@0.1.0` interface — rewritten over deltic's embedder API (typed `Stream` rather than jco's bare-payload `Stream`, and -`WitError` throws rather than `throw { tag, val }`). It was developed as +`ComponentException` throws rather than `throw { tag, val }`). It was developed as deltic's own `ports/webcrypto` reference-host port and is upstreamed here per [lann/deltic#40](https://github.com/lann/deltic/pull/40); the WIT contract is [`wit/`](../../wit), and every doc comment quoting a contract @@ -43,7 +43,7 @@ pinned JSR version as [`conformance/driver-ct/deltic/deno.json`](../../conformance/driver-ct/deltic/deno.json). deltic's `wasi-shims` module imports that specifier by bare name internally; if the two configs ever disagreed, the embedder module would -load twice and `instanceof WitError` would stop holding across the +load twice and `instanceof ComponentException` would stop holding across the boundary. Keep both import maps' version identical for that one entry — `just conformance-ct::deltic-pin-check` gates that. diff --git a/js/deltic/deno.json b/js/deltic/deno.json index bd42855..fa592b8 100644 --- a/js/deltic/deno.json +++ b/js/deltic/deno.json @@ -2,9 +2,9 @@ "name": "@polymorph/webcrypto-deltic", "version": "0.0.0", "exports": "./src/mod.ts", - "//": "MODULE-IDENTITY CONSTRAINT: deltic's wasi-shims module imports @deltic/runtime/embedder by bare specifier internally. Every config in this repo (this file AND conformance/driver-ct/deltic/deno.json) must map that specifier to the IDENTICAL exact-pinned JSR version, or the embedder module loads twice and `instanceof WitError` stops holding across the module boundary. The hash names one upstream commit; deno.lock carries integrity, --frozen enforced; the pin gate (just conformance-ct::deltic-pin-check) asserts one @deltic version repo-wide.", + "//": "MODULE-IDENTITY CONSTRAINT: deltic's wasi-shims module imports @deltic/runtime/embedder by bare specifier internally. Every config in this repo (this file AND conformance/driver-ct/deltic/deno.json) must map that specifier to the IDENTICAL exact-pinned JSR version, or the embedder module loads twice and `instanceof ComponentException` stops holding across the module boundary. The hash names one upstream commit; deno.lock carries integrity, --frozen enforced; the pin gate (just conformance-ct::deltic-pin-check) asserts one @deltic version repo-wide.", "imports": { - "@deltic/runtime/embedder": "jsr:@deltic/runtime@0.1.0-pre.ga67ee83/embedder" + "@deltic/runtime/embedder": "jsr:@deltic/runtime@0.1.0-pre.g078aa15/embedder" }, "minimumDependencyAge": { "age": "P1D", "exclude": ["jsr:@deltic/*"] }, "tasks": { diff --git a/js/deltic/deno.lock b/js/deltic/deno.lock index 347b64c..dc47957 100644 --- a/js/deltic/deno.lock +++ b/js/deltic/deno.lock @@ -1,16 +1,23 @@ { "version": "5", "specifiers": { - "jsr:@deltic/runtime@0.1.0-pre.ga67ee83": "0.1.0-pre.ga67ee83" + "jsr:@deltic/protocol@0.2": "0.2.0", + "jsr:@deltic/runtime@0.1.0-pre.g078aa15": "0.1.0-pre.g078aa15" }, "jsr": { - "@deltic/runtime@0.1.0-pre.ga67ee83": { - "integrity": "2a2b0949031747a2340dc186299e654ea9f361ae39ac6bd633019940682db4ed" + "@deltic/protocol@0.2.0": { + "integrity": "028be6a3623c5e910598aa7a199209b85e8931ae484ac7f6638d610ddb0e19fa" + }, + "@deltic/runtime@0.1.0-pre.g078aa15": { + "integrity": "5e64f8dc6d32190ecd394d6ad9881eb0fa97b6598b1e7f2ef1d52cff4674287c", + "dependencies": [ + "jsr:@deltic/protocol" + ] } }, "workspace": { "dependencies": [ - "jsr:@deltic/runtime@0.1.0-pre.ga67ee83" + "jsr:@deltic/runtime@0.1.0-pre.g078aa15" ] } } diff --git a/js/deltic/src/errors.ts b/js/deltic/src/errors.ts index c479b68..2f09810 100644 --- a/js/deltic/src/errors.ts +++ b/js/deltic/src/errors.ts @@ -2,7 +2,7 @@ // // Governing docs: // - contracts/embedder-api.md §"Error model" — host imports report a WIT -// `result<_, error>` err case by throwing `new WitError(payload)`; an +// `result<_, error>` err case by throwing `new ComponentException(payload)`; an // UNBRANDED throw becomes a host-fatal trap. That is a deliberate // inversion of jco's convention (any stray `TypeError` was fed to the // lift), which is why the polymorph reference wraps every platform call @@ -13,47 +13,48 @@ // mapping targets. // // `error` is a WIT variant; per the value-mapping table -// (contracts/embedder-api.md §"Value mapping", `variant` row) its payload -// shape is `{ tag, val? }` with `val` absent for payloadless cases. +// (contracts/embedder-api.md §"Value mapping", `variant` row; A10) its +// payload shape is `{ kind, value? }` with `value` absent for payloadless +// cases. -import { WitError } from "@deltic/runtime/embedder"; +import { ComponentException } from "@deltic/runtime/embedder"; /** The `types.error` payload shape (the value-mapping table's variant row). */ export type WcErrorPayload = - | { tag: "invalid-key"; val: string } - | { tag: "invalid-nonce"; val: string } - | { tag: "authentication-failed" } - | { tag: "not-extractable" } - | { tag: "unsupported"; val: string } - | { tag: "not-permitted"; val: string } - | { tag: "other"; val: string } - | { tag: "extension"; val: { origin: string; name: string; message: string } }; + | { kind: "invalid-key"; value: string } + | { kind: "invalid-nonce"; value: string } + | { kind: "authentication-failed" } + | { kind: "not-extractable" } + | { kind: "unsupported"; value: string } + | { kind: "not-permitted"; value: string } + | { kind: "other"; value: string } + | { kind: "extension"; value: { origin: string; name: string; message: string } }; /** Throw the branded `result<_, error>` err value for a WIT-declared case. */ export function witError(payload: WcErrorPayload): never { - throw new WitError(payload); + throw new ComponentException(payload); } export function errInvalidKey(detail: string): never { - return witError({ tag: "invalid-key", val: detail }); + return witError({ kind: "invalid-key", value: detail }); } export function errInvalidNonce(detail: string): never { - return witError({ tag: "invalid-nonce", val: detail }); + return witError({ kind: "invalid-nonce", value: detail }); } export function errAuthenticationFailed(): never { - return witError({ tag: "authentication-failed" }); + return witError({ kind: "authentication-failed" }); } export function errNotExtractable(): never { - return witError({ tag: "not-extractable" }); + return witError({ kind: "not-extractable" }); } export function errUnsupported(detail: string): never { - return witError({ tag: "unsupported", val: detail }); + return witError({ kind: "unsupported", value: detail }); } export function errNotPermitted(detail: string): never { - return witError({ tag: "not-permitted", val: detail }); + return witError({ kind: "not-permitted", value: detail }); } export function errOther(detail: string): never { - return witError({ tag: "other", val: detail }); + return witError({ kind: "other", value: detail }); } /** The refusal an operation renders on a usage-denied key (reference parity: js/jco/webcrypto.js:162-164). */ @@ -75,8 +76,8 @@ function asPlatformError(err: unknown): { name: string | undefined; detail: stri * js/jco/webcrypto.js:251-262). `NotSupportedError` is the WIT's * "well-formed request this implementation does not serve" * (`error.unsupported`); everything else platform-thrown is operational - * (`error.other`). Anything already a `WitError` passes through unchanged. - * An exception that is neither a `WitError` nor DOMException-shaped is a + * (`error.other`). Anything already a `ComponentException` passes through unchanged. + * An exception that is neither a `ComponentException` nor DOMException-shaped is a * host bug, not a taxonomy case: it is rethrown as-is and becomes a trap * per contracts/embedder-api.md's error model, not smuggled into `other`. */ @@ -84,7 +85,7 @@ export async function platformCall(what: string, run: () => Promise): Prom try { return await run(); } catch (err) { - if (err instanceof WitError) throw err; + if (err instanceof ComponentException) throw err; const { name, detail } = asPlatformError(err); if (err instanceof DOMException) { if (name === "NotSupportedError") { diff --git a/js/deltic/src/mod.ts b/js/deltic/src/mod.ts index c4034cd..bca8f4b 100644 --- a/js/deltic/src/mod.ts +++ b/js/deltic/src/mod.ts @@ -10,7 +10,7 @@ // (`../../../runtime/src/embedder/…`) to the pinned `@deltic/runtime/embedder` // specifier this repo's import maps resolve (see ../README.md). It is the // deltic-conventions sibling of [`js/jco/webcrypto.js`](../jco/webcrypto.js) -// — same behavioral reference host, `WitError` throws and typed `Stream` +// — same behavioral reference host, `ComponentException` throws and typed `Stream` // instead of jco's bare-payload conventions. The WIT contract is // [`wit/`](../../wit); every doc comment quoting a contract quotes it. // diff --git a/js/deltic/src/platform.ts b/js/deltic/src/platform.ts index 7b1300b..2c36f57 100644 --- a/js/deltic/src/platform.ts +++ b/js/deltic/src/platform.ts @@ -10,7 +10,7 @@ // authority for which verdict each is. import { errInvalidKey, errNotExtractable, errUnsupported, platformCall } from "./errors.ts"; -import { WitError } from "@deltic/runtime/embedder"; +import { ComponentException } from "@deltic/runtime/embedder"; import { asBufferSource } from "./util.ts"; const subtle = globalThis.crypto.subtle; @@ -64,7 +64,7 @@ export async function importPlatformKey( try { return await subtle.importKey(format, asBufferSource(bytes), algorithm, extractable, usages); } catch (err) { - if (err instanceof WitError) throw err; + if (err instanceof ComponentException) throw err; invalidKey(err, what); } } @@ -81,7 +81,7 @@ export async function importPlatformKeyJwk( try { return await subtle.importKey("jwk", jwk as JsonWebKey, algorithm, extractable, usages); } catch (err) { - if (err instanceof WitError) throw err; + if (err instanceof ComponentException) throw err; invalidKey(err, what); } } @@ -206,7 +206,7 @@ export async function redactingInvalidKey(what: string, run: () => Promise try { return await run(); } catch (err) { - if (err instanceof WitError && (err.payload as { tag?: string })?.tag === "invalid-key") { + if (err instanceof ComponentException && (err.payload as { kind?: string })?.kind === "invalid-key") { errInvalidKey(`invalid ${what}`); } throw err; diff --git a/js/deltic/src/publicEncryption.ts b/js/deltic/src/publicEncryption.ts index 98e5849..9bf3ee0 100644 --- a/js/deltic/src/publicEncryption.ts +++ b/js/deltic/src/publicEncryption.ts @@ -70,8 +70,8 @@ function oaepAlgorithm(entry: { hash: string; digestBytes: number }, modulusLeng /** The named plaintext-bound condition: the signal to switch to hybrid wrapping (reference: webcrypto.js:5461). */ function errMessageTooLong(what: string, length: number, algorithm: OaepAlgorithm): never { witError({ - tag: "extension", - val: { + kind: "extension", + value: { origin: "polymorph:webcrypto", name: "message-too-long", message: `${what} is ${length} bytes; this key's RSA-OAEP bound is ${algorithm.plaintextBound}`, diff --git a/js/deltic/tests/families_test.ts b/js/deltic/tests/families_test.ts index 666569f..326a90f 100644 --- a/js/deltic/tests/families_test.ts +++ b/js/deltic/tests/families_test.ts @@ -40,7 +40,7 @@ import { AgreementKeyOptions, } from "../src/mod.ts"; import { arrayStream } from "./testStream.ts"; -import { WitError } from "@deltic/runtime/embedder"; +import { ComponentException } from "@deltic/runtime/embedder"; // This file sits at js/deltic/tests/, so the repo root is three levels up // and the vector tree is in-repo — no absolute path, and no skip guard: @@ -65,8 +65,8 @@ function tc(doc: any, tcId: number, group = 0): any { if (found === undefined) throw new Error(`tcId ${tcId} not in group ${group}`); return found; } -function tag(err: unknown): string { - return ((err as WitError).payload as { tag: string }).tag; +function kindOf(err: unknown): string { + return ((err as ComponentException).payload as { kind: string }).kind; } function cipherOptions(): CipherKeyOptions { const o = new CipherKeyOptions(); @@ -95,7 +95,7 @@ Deno.test("aes-cbc: a tampered ciphertext fails the WIT's uniform error.other (n const ct = hexToBytes(t.ct); ct[ct.length - 1] ^= 0xff; // corrupt the final block: bad padding on decrypt const err = await assertRejects(() => key.decrypt(hexToBytes(t.iv), undefined, arrayStream(ct))); - assertEq(tag(err), "other"); + assertEq(kindOf(err), "other"); }); Deno.test("aes-ctr: a counter length is required, and AES-CBC refuses one (error.invalid-nonce both ways)", async () => { @@ -103,10 +103,10 @@ Deno.test("aes-ctr: a counter length is required, and AES-CBC refuses one (error const missing = await assertRejects(() => ctr.encrypt(new Uint8Array(16), undefined, arrayStream(new Uint8Array(4))) ); - assertEq(tag(missing), "invalid-nonce"); + assertEq(kindOf(missing), "invalid-nonce"); const cbc = await aesCbc.generateKey("aes256", cipherOptions()); const extra = await assertRejects(() => cbc.encrypt(new Uint8Array(16), 64, arrayStream(new Uint8Array(4)))); - assertEq(tag(extra), "invalid-nonce"); + assertEq(kindOf(extra), "invalid-nonce"); }); Deno.test("aes-ctr: encrypt/decrypt round-trip at a 128-bit counter", async () => { @@ -148,7 +148,7 @@ Deno.test("aes-kw: a tampered wrapped blob fails error.authentication-failed (in const wrapped = hexToBytes(t.ct); wrapped[0] ^= 0xff; const err = await assertRejects(() => key.unwrap(wrapped)); - assertEq(tag(err), "authentication-failed"); + assertEq(kindOf(err), "authentication-failed"); }); Deno.test("pbkdf2-sha2: KAT against pbkdf2_hmacsha256_test.json tcId 1 (RFC 7914)", async () => { @@ -167,7 +167,7 @@ Deno.test("pbkdf2-sha2: a zero iteration count fails error.other at prepare, bef o.canDeriveBits(true); const password = await pbkdf2.importPassword(new Uint8Array([1, 2, 3]), o); const err = await assertRejects(() => pbkdf2Sha2.prepare("sha256", password, new Uint8Array(8), 0)); - assertEq(tag(err), "other"); + assertEq(kindOf(err), "other"); }); Deno.test("ecdh: KAT against ecdh_secp256r1_webcrypto_test.json tcId 1 (agreed secret matches the vector)", async () => { @@ -187,7 +187,7 @@ Deno.test("ecdh: an off-curve peer point is refused (error.invalid-key; ecdh_sec const t = tc(doc, 332); assertEq(t.result, "invalid"); const err = await assertRejects(() => ecdh.importPublicKeyRaw("p256", hexToBytes(t.public))); - assertEq(tag(err), "invalid-key"); + assertEq(kindOf(err), "invalid-key"); }); Deno.test("ecdsa-verify: KAT against ecdsa_secp256r1_sha256_p1363_test.json tcId 2 (valid P1363 signature)", async () => { @@ -205,7 +205,7 @@ Deno.test("ecdsa-verify: an upstream-invalid signature fails error.authenticatio const t = g.tests.find((x: { result: string }) => x.result === "invalid"); const key = await ecdsaVerify.importVerifyingKeyJwk("p256-sha256", JSON.stringify(g.publicKeyJwk)); const err = await assertRejects(() => key.verify(arrayStream(hexToBytes(t.msg)), hexToBytes(t.sig))); - assertEq(tag(err), "authentication-failed"); + assertEq(kindOf(err), "authentication-failed"); }); Deno.test("ecdsa-sign: generate -> sign -> verify round-trip (P-384/SHA-384)", async () => { @@ -226,7 +226,7 @@ Deno.test("rsassa-pkcs1-v15-verify: KAT against rsa_signature_2048_sha256_test.j await key.verify(arrayStream(hexToBytes(ok.msg)), hexToBytes(ok.sig)); const bad = g.tests.find((x: { result: string }) => x.result === "invalid"); const err = await assertRejects(() => key.verify(arrayStream(hexToBytes(bad.msg)), hexToBytes(bad.sig))); - assertEq(tag(err), "authentication-failed"); + assertEq(kindOf(err), "authentication-failed"); }); Deno.test("rsa-pss-verify: KAT against rsa_pss_2048_sha256_mgf1_32_test.json (salt length bound at mint)", async () => { @@ -239,7 +239,7 @@ Deno.test("rsa-pss-verify: KAT against rsa_pss_2048_sha256_mgf1_32_test.json (sa // key's salt length is mint-bound (`import-verifying-key-jwk`'s contract). const other = await rsaPssVerify.importVerifyingKeyJwk("sha256", 0, JSON.stringify(g.publicKeyJwk)); const err = await assertRejects(() => other.verify(arrayStream(hexToBytes(ok.msg)), hexToBytes(ok.sig))); - assertEq(tag(err), "authentication-failed"); + assertEq(kindOf(err), "authentication-failed"); }); Deno.test("rsa-oaep: KAT against rsa_oaep_2048_sha256_mgf1sha256_test.json tcId 1 (valid) and tcId 32 (truncated ciphertext)", async () => { @@ -259,7 +259,7 @@ Deno.test("rsa-oaep: KAT against rsa_oaep_2048_sha256_mgf1sha256_test.json tcId key.decrypt(bad.label.length > 0 ? hexToBytes(bad.label) : undefined, hexToBytes(bad.ct)) ); // RFC 8017's single verdict: every decryption failure is detail-free. - assertEq(tag(err), "authentication-failed"); + assertEq(kindOf(err), "authentication-failed"); }); Deno.test("sha1-checked: both postures decline with error.unsupported (no platform carries sha1dc)", () => { @@ -270,6 +270,6 @@ Deno.test("sha1-checked: both postures decline with error.unsupported (no platfo } catch (e) { caught = e; } - assertEq(tag(caught), "unsupported"); + assertEq(kindOf(caught), "unsupported"); } });