New `aliro-bench-profile` entry point drives the applet's INS_DIAG_* commands over PC/SC at two iteration counts (N=4 / N=16 by default) and computes per-op cost as the slope, factoring out APDU round-trip + any one-time Signature.init setup. Reports HMAC, ECDH, ECDSA sign, and AES-GCM 137B costs side by side, then reconstructs an AUTH1 budget using the per-primitive counts from the applet's processAuth1 flow so we can compare the reconstructed estimate against bench-test wall-clock and see how much of AUTH1 is crypto vs TLV parsing / I/O. Also extends `aliro-bench-test` to time SELECT / AUTH0 / AUTH1 / total via time.perf_counter() bracketing each transmit() call. The TransactionResult now carries a latencies_ms dict, threaded through all return sites so both success and failure paths print the new "APDU latencies (ms):" block. Made the 1.78x AUTH1 wall-clock speedup from the 4-bit GHASH commit quantifiable on real hardware (5,795 -> 3,244 ms). Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Aliro test harness
PC-side tools for the Aliro Java Card applet project.
Layout
src/aliro_harness/
├── issuer/ Test CA: keypairs, X.509 certs, signed Access Documents
├── personalize/ pyscard-based loader driving the PersonalizationApplet
├── reader_log/ pyserial VCP capture, tag parser, trace differ
└── trustgen/ CLI emitting reader/aliro_trust.h from CA + reader keys
tests/ pytest suite (unit + end-to-end)
Setup
python3 -m venv .venv
source .venv/bin/activate
pip install -e '.[dev]'
pytest
Not for production
All keys generated or accepted by this harness are TEST-ONLY. Do not reuse in a production Aliro deployment.