Skip to content

Validator: allow more types for tags 1 (Unix time_t) , 21-23 (expected Base64 encodings) - #340

Open
thiagomacieira wants to merge 2 commits into
intel:mainfrom
thiagomacieira:allow-more-types-in-cborvalidator
Open

thiagomacieira wants to merge 2 commits into
intel:mainfrom
thiagomacieira:allow-more-types-in-cborvalidator

Conversation

@thiagomacieira

@thiagomacieira thiagomacieira commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

For Unix time_t, this was a mistake in the original content. Even RFC 7049 said:

The tagged item can be a positive or negative integer (major types 0 and 1), or a floating-point number (major type 7 with additional information 25, 26, or 27)

For the base64 encoding expectations, the tags were meant to tag byte strings, directly or indirectly. But the wording in RFC 7049 and 8949 is

The data item tagged can be a byte string or any other data item.

That means it can be used to tag numbers and text strings, which in my opinion makes no sense, but let's allow them.

Fixes #339

This comment was marked as resolved.

@thiagomacieira
thiagomacieira force-pushed the allow-more-types-in-cborvalidator branch from 15e710c to b9b3d7b Compare October 2, 2026 20:54
This was a mistake in the original content. Even RFC 7049 said:

> The tagged item can be a positive or negative
> integer (major types 0 and 1), or a floating-point number (major type
> 7 with additional information 25, 26, or 27)

For intel#339.

Signed-off-by: Thiago Macieira <thiago.macieira@intel.com>
They were meant to tag byte strings, directly or indirectly. But the
wording in RFC 7049 and 8949 is

> The data item tagged can be a byte string or any other data item.

That means it can be used to tag numbers and text strings, which in my
opinion makes no sense, but let's allow them.

For the testing, we can reuse and combine with the data for the other
tag that accepted anything: the CBOR signature one.

For intel#339.

Signed-off-by: Thiago Macieira <thiago.macieira@intel.com>
@thiagomacieira
thiagomacieira force-pushed the allow-more-types-in-cborvalidator branch from b9b3d7b to 577d42b Compare October 2, 2026 20:57

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CborValidateTagUse rejects valid tag 1 (epoch) with a floating-point value, and restricts tags 21-23 too much

3 participants