mirror of
https://github.com/Abdess/retroarch_system.git
synced 2026-10-10 21:43:23 -05:00
verify.py reaches these through a dynamic import and nothing exercised them, so a signature check that accepted everything would have looked exactly like one that worked. Console dumps are personal data and cannot be committed, but the verifiers only read structure and signatures: the fixtures are built from the layouts in unique_data.cpp and otp.cpp, signing with a key the test owns and passing the matching public key in through the keys file. That covers the region-change detection in SecureInfo_A, the embedded LFCS in movable.sed, and the OTP path down to the sect233r1 certificate including the pre-v5 expiry endianness. crypto_verify goes from 9 to 89 percent. Disabling the OTP hash check and the movable.sed magic check each fails a test.