Sync testdata with DateKeys spec-v0.11 (datekeys-go ae33434)

SPEC_VERSION is 0.11. testdata brings format3_signed, format3_signed_cms and
format3_sealed, and the vectors ed25519_strict.json, security_cms.json and
locator.json; the mutation corpus has 210 cases. ibe-vectors.json adds the
three fixtures and remakes the two that Go regenerated, and
mutation-texts.json is made again with that reference.

This library still reads the security area as a reader of v0.10, so a
signature or a seal that the reference checks gives F1 or S1 here. The
Verdict type and the texts know F2 to F6 and S3 to S5, and the tests state
the gap with testing/pending.ts instead of hiding it; porting the
verification makes that file the identity. npm run verify and
testdata:check pass.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
main
dev 7 days ago
parent c3c124ae34
commit e3cf2409cd

@ -4,6 +4,11 @@ Cambios notables de la librería TypeScript y de la página. El proyecto usa ver
## Especificación 0.10, en la rama `v0.10` — sin versión
### `testdata` en `spec-v0.11` (01-10-2026)
- `testdata` se sincroniza con el tag `spec-v0.11` de `datekeys-go` (`ae33434`), y `SPEC_VERSION` pasa a `0.11`. Trae tres fixtures (`format3_signed`, con firma de clave propia; `format3_signed_cms`, con dos certificados sellados; `format3_sealed`, con firma y sello RFC 3161) y tres ficheros de vectores (`ed25519_strict.json`, `security_cms.json` y `locator.json`). El corpus de mutaciones pasa a 210 casos, con uno fuera del §64: una firma de `alg` 1 que no verifica, F2. `ibe-vectors.json` añade los tres fixtures y rehace los de `format3_signature_unsupported` y `format3_seal_unsupported`; `mutation-texts.json` se rehace con el `capsule.Open` de esa referencia.
- **Lo que esta biblioteca no hace todavía:** lee el área de seguridad como un lector de la v0.10, así que una firma o un sello que la referencia comprueba da F1 o S1 aquí, y la referencia da F2 a F6 y S3 a S5. El tipo `Verdict` y los textos ya los conocen. Los tests lo dicen en lugar de ocultarlo: `testing/pending.ts` da lo que esta biblioteca devuelve donde la referencia registra una verificación, y un bloque de `vectors.test.ts` comprueba la estructura de los vectores que aún no se portan. Portar la verificación (§29.8 a §29.11 y el localizador del §44.1) hace esas funciones la identidad.
El formato 3 de la especificación 0.10, según `PLAN_formato3_ts.md` (en `../docs`). La versión que lo publique la decide el autor.
### Llave de palabras y firma de drand

@ -1,6 +1,6 @@
# datekeys-ts
Implementación en TypeScript del protocolo DateKeys v0.10 y página de prueba en el navegador. Sustituye al prototipo, archivado en `../archive/prototype` (API Quicknet en Go, CLI tlock y cliente Svelte, commit `4d2b0a1`).
Implementación en TypeScript del protocolo DateKeys (formato 3 de la v0.10; con los datos de prueba de la v0.11, cuya verificación de firmas y sellos está pendiente) y página de prueba en el navegador. Sustituye al prototipo, archivado en `../archive/prototype` (API Quicknet en Go, CLI tlock y cliente Svelte, commit `4d2b0a1`).
La implementación de referencia es la librería Go `g.activething.com/go/DateKeys`, en `../datekeys-go`. Los planes y el estado del trabajo están en `../docs`, el repositorio privado de documentación del proyecto.
@ -21,7 +21,7 @@ Hay tres números de versión, cada uno con su significado, como en la referenci
| Versión | Dónde | Cambia cuando |
|---|---|---|
| Formato | Dentro de los objetos: el formato de la cápsula, el `VERSION` del prelude de DKC1, 1, 2 o 3 al leer, que fija también la versión de schema de CONTROL_CBOR; y 1 en la trama DKK1 y en el schema de los demás objetos | Cambia el formato. Un lector rechaza una versión que no conoce (§22, §70) |
| Especificación | `SPEC_VERSION` de `src/lib/dkc/version.ts`, hoy `0.10`: la del tag `spec-v0.10` de `datekeys-go` | Cambia el texto normativo |
| Especificación | `SPEC_VERSION` de `src/lib/dkc/version.ts`, hoy `0.11`: la del tag `spec-v0.11` de `datekeys-go` | Cambia el texto normativo |
| Librería | `VERSION` de `src/lib/dkc/version.ts`, igual al campo `version` de `package.json` | Cambia la API o el comportamiento. Versionado semántico, sin promesa de estabilidad antes de 1.0.0 |
`version.test.ts` comprueba que `VERSION` coincide con `package.json` y con su lockfile, y que `SPEC_VERSION` es la versión que nombran los vectores y fixtures compartidos; `vectors.test.ts` exige esa versión a cada fichero. El pie de la página muestra las dos.
@ -81,7 +81,7 @@ Los tests (`*.test.ts`) están junto a cada fichero.
El comportamiento se contrastó con la librería Go en `3820066` (`692cf87` solo cambia la regla de UTF-8 de `dk1_` descrita abajo) mediante un oráculo diferencial fuera del repositorio: 483 527 entradas de tres semillas. Son mutaciones de los cinco `.dkc` oficiales de todas las clases (bits, bytes, truncados, inserciones, borrados, longitudes y campos del prelude, cabeceras reescritas con cambios de CBOR, DateKeys, arrays de extensiones con y sin registro de extensiones, cabeceras `age` de SEALED_CONTROL y de PAYLOAD_AGE, argumentos del stanza tlock, rondas, secciones cambiadas de sitio y combinaciones de varios defectos); CBOR de cada esquema (PUBLIC_HEADER, CONTROL_CBOR, cuerpo y fichero `.dkk`, Provider Profile, arrays de extensiones); `walk`, `peek` y `checkSchema`; cabeceras `age`, preludes, cadenas `dk1_`, rondas y fechas. En todas coinciden el veredicto, el código y el paso, y también el texto del error, el valor decodificado y la salida entera de `datekeys inspect -json`, byte a byte. Un segundo diferencial con otro generador, de 407 196 entradas, se repitió contra `f6f2e9f` (la enmienda de canonicidad de puntos) con el mismo resultado, textos incluidos.
Con la v0.9 se contrastaron contra `spec-v0.9` los 125 casos de `mutations.json`, en memoria y desde un `Blob` con salida, y coinciden el código, el paso y el texto del error de `capsule.Open` en todos. Desde la v0.10 ese contraste está en el repositorio: `src/lib/dkc/testing/mutation-texts.json` congela el texto de `capsule.Open` en `spec-v0.10` para los 209 casos, y `vectors.test.ts` exige el mismo en las dos aperturas. El validador de extensiones del arnés da los textos de `testkit.KnownExtensions`, así que ya coinciden también los casos de extensiones conocidas con datos inválidos.
Con la v0.9 se contrastaron contra `spec-v0.9` los 125 casos de `mutations.json`, en memoria y desde un `Blob` con salida, y coinciden el código, el paso y el texto del error de `capsule.Open` en todos. Desde la v0.10 ese contraste está en el repositorio: `src/lib/dkc/testing/mutation-texts.json` congela el texto de `capsule.Open` en `spec-v0.11` para los 210 casos, y `vectors.test.ts` exige el mismo en las dos aperturas. El validador de extensiones del arnés da los textos de `testkit.KnownExtensions`, así que ya coinciden también los casos de extensiones conocidas con datos inválidos.
Como la referencia desde `f6f2e9f`, los errores no copian el texto de una librería: una cabecera `age` que no se puede leer da siempre `agewrap: not an age v1 header: malformed, truncated or beyond the parser limits` (`ERR_INTEGRITY`). El motivo del parser, con las palabras de `age`, queda en `cause` del error, fuera del mensaje, y los tests lo comparan con los textos de `age` para comprobar que se rechaza por la misma razón.
@ -279,7 +279,7 @@ Umbrales de cobertura (`vitest.config.ts`), al 100 % en líneas, ramas, funcione
Para regenerarlo: `node scripts/tlock-ts-samples.mjs > ts-samples.json`, y desde el mismo módulo Go temporal, `go run tlock-go-vectors.go ts-samples.json > tlock-vectors.json`.
En `ibe-vectors.json`, H2, H3 y H4 no son públicas en kyber: el script las reescribe con sus etiquetas y las comprueba en cada fixture contra la file key de tlock y contra U = r·G2. Los cifrados de kyber usan un sigma aleatorio, así que el fichero se genera una vez y se congela. Para regenerarlo, desde un módulo Go temporal que requiera la referencia (`replace g.activething.com/go/DateKeys => ../datekeys-go`, `GOFLAGS=-mod=mod`, y la directiva `go` de la referencia, para que se use su toolchain): `go run ibe-go-vectors.go ../datekeys-ts/testdata/fixtures > ibe-vectors.json`. Los siete fixtures del formato 2 se añadieron el 29-09-2026 así, sobre `spec-v0.9`, tomando solo el bloque `fixtures`: los valores de los cinco anteriores salieron idénticos, y el resto del fichero no cambió. Los nueve del formato 3 se añadieron igual el 30-09-2026, sobre `spec-v0.10`, con los doce anteriores idénticos.
En `ibe-vectors.json`, H2, H3 y H4 no son públicas en kyber: el script las reescribe con sus etiquetas y las comprueba en cada fixture contra la file key de tlock y contra U = r·G2. Los cifrados de kyber usan un sigma aleatorio, así que el fichero se genera una vez y se congela. Para regenerarlo, desde un módulo Go temporal que requiera la referencia (`replace g.activething.com/go/DateKeys => ../datekeys-go`, `GOFLAGS=-mod=mod`, y la directiva `go` de la referencia, para que se use su toolchain): `go run ibe-go-vectors.go ../datekeys-ts/testdata/fixtures > ibe-vectors.json`. Los siete fixtures del formato 2 se añadieron el 29-09-2026 así, sobre `spec-v0.9`, tomando solo el bloque `fixtures`: los valores de los cinco anteriores salieron idénticos, y el resto del fichero no cambió. Los nueve del formato 3 se añadieron igual el 30-09-2026, sobre `spec-v0.10`, con los doce anteriores idénticos. El 01-10-2026, sobre `spec-v0.11`, se añadieron `format3_signed`, `format3_signed_cms` y `format3_sealed`, y se rehicieron los dos de `format3_signature_unsupported` y `format3_seal_unsupported`, que Go regeneró con `alg` 4294967295; los demás salieron idénticos.
- El writer (`encrypt.test.ts`, `encrypt.stream.test.ts`, `encrypt.internal.test.ts`, `encrypt.property.test.ts`):
- con los valores de su registro, reproduce byte a byte el PRELUDE, PUBLIC_HEADER, `header_binding` y CONTROL_CBOR de los siete fixtures de formato 2 de Go, con las mismas longitudes; cada credencial cae en el hueco del registro y la `.dkk` sale igual, salvo su `capsule_digest`;
- lo que escribe se abre con `open`: las dos políticas, de 1 a 16 credenciales, cada una sola y todas juntas; contenidos en todos los bordes de trozo y de relleno, hasta 5 000 000 de bytes, con las dos reglas; rondas 1000, 1001 y 2000;
@ -397,7 +397,7 @@ Comprueba que los ficheros coinciden con `SOURCE.json`, sin faltantes ni sobrant
`.gitattributes` marca `testdata/**` como binario para que git no altere ningún byte.
Copia actual: la de `testdata/SOURCE.json` (tag `spec-v0.10`, `cc35d2c`), que se sincroniza con `node scripts/sync-testdata.mjs sync --commit spec-v0.10`.
Copia actual: la de `testdata/SOURCE.json` (tag `spec-v0.11`, `ae33434`), que se sincroniza con `node scripts/sync-testdata.mjs sync --commit spec-v0.11`.
## Licencia

@ -16,6 +16,7 @@ import { checkHeadEnd, decodeHead, encodeHead } from './head.ts';
import { inspect, inspectView } from './inspect.ts';
import { paddedLength, type Padding, payloadAgeLength } from './padding.ts';
import { evaluateSecurity, type Verdict, verdictLines } from './security.ts';
import { isPending, ported } from './testing/pending.ts';
import { h, hx, listTestdata, readBytes, readJSON } from './testing/testdata.ts';
interface FixtureExt {
@ -207,8 +208,11 @@ describe.each(dkcFixtures)('$json.file', ({ json: fx }) => {
}
expect(hx(encodeHead(decoded))).toBe(fx.head_cbor);
const verdicts = evaluateSecurity(security);
expect(verdicts).toEqual({ signature: fx.verdicts!.signature, seal: fx.verdicts!.seal });
expect(verdictLines(verdicts)).toEqual(fx.verdicts!.lines);
// Where the reference checks a signature or a seal, this library gives what
// a reader of v0.10 gives, until it ports the verification (testing/pending.ts).
const want = ported(fx.verdicts!);
expect(verdicts).toEqual(want);
if (!isPending(fx.verdicts!)) expect(verdictLines(verdicts)).toEqual(fx.verdicts!.lines);
});
});

@ -26,6 +26,7 @@ import { type Release, type ReleaseSource, suppliedRelease } from './release.ts'
import { type Verdict, verdictLines } from './security.ts';
import { MemorySink, type Sink } from './sink.ts';
import { frame, split } from './testing/capsule.ts';
import { isPending, ported } from './testing/pending.ts';
import { h, hx, listTestdata, readBytes, readJSON } from './testing/testdata.ts';
import { applyEdits, edits } from './testing/vectors.ts';
import { parseX25519Identity, unwrapX25519, x25519PublicKey } from './x25519.ts';
@ -101,8 +102,8 @@ function expectFiles(f: Fixture, r: Opened, sink: MemorySink): void {
f.name,
).toEqual(f.side.files ?? []);
expect(opened.files.map(hx), f.name).toEqual(r.head!.files.map((x) => hx(f.plaintext.subarray(f.side.content_offset! + x.start, f.side.content_offset! + x.end))));
expect(r.verdicts, f.name).toEqual({ signature: f.side.verdicts!.signature, seal: f.side.verdicts!.seal });
expect(verdictLines(r.verdicts!), f.name).toEqual(f.side.verdicts!.lines);
expect(r.verdicts, f.name).toEqual(ported(f.side.verdicts!));
if (!isPending(f.side.verdicts!)) expect(verdictLines(r.verdicts!), f.name).toEqual(f.side.verdicts!.lines);
expect(r.areaLen, f.name).toBe(f.side.area_len);
expect([r.plaintext, r.unusableHeadExtensions], f.name).toEqual([undefined, []]);
}

@ -82,4 +82,14 @@ describe('verdictLines', () => {
expect(lines('F1', 'S2')).toEqual([F1, S2]);
expect(verdictText('S0')).toBe('');
});
// The verdicts of spec v0.11 (§29.7) that this library does not reach yet: it knows their fixed texts, and leaves to whoever shows
// F3, F4, F6 and S4 the text that names a key, a holder or a time.
it('has the text of the verdicts of v0.11 that do not name anything, and none for those that do', () => {
expect(verdictText('F2')).toBe('La firma no corresponde a este contenido.');
expect(verdictText('F5')).toBe('Faltan firmas o sellos que la propia cápsula exige: trátala como no firmada.');
expect(verdictText('S3')).toBe('El sello no corresponde a este contenido.');
expect(verdictText('S5')).toBe('Sellado después de la fecha de apertura: no prueba nada anterior.');
for (const v of ['F3', 'F4', 'F6', 'S4'] as const) expect(verdictText(v), v).toBe('');
});
});

@ -30,7 +30,7 @@ const MAX_ALG = 2 ** 32 - 1;
* - S1: a seal_type this reader does not implement;
* - S2: a seal that does not decode or breaks its schema.
*/
export type Verdict = 'X' | 'F0' | 'F1' | 'S0' | 'S1' | 'S2';
export type Verdict = 'X' | 'F0' | 'F1' | 'F2' | 'F3' | 'F4' | 'F5' | 'F6' | 'S0' | 'S1' | 'S2' | 'S3' | 'S4' | 'S5';
/** The verdicts of the security area of a format 3 capsule. */
export interface Verdicts {
@ -51,6 +51,19 @@ export function verdictText(v: Verdict): string {
return 'Lleva un sello de tiempo que esta versión no sabe comprobar: aquí no prueba nada.';
case 'S2':
return 'El sello de tiempo es ilegible: no prueba nada.';
case 'F2':
return 'La firma no corresponde a este contenido.';
case 'F5':
return 'Faltan firmas o sellos que la propia cápsula exige: trátala como no firmada.';
case 'S3':
return 'El sello no corresponde a este contenido.';
case 'S5':
return 'Sellado después de la fecha de apertura: no prueba nada anterior.';
// F3, F4, F6 and S4 name a key, a holder or a time: whoever shows them writes the text (spec §29.7).
case 'F3':
case 'F4':
case 'F6':
case 'S4':
case 'S0':
return '';
}

@ -208,11 +208,21 @@
"name": "format3_seal_unsupported",
"round": 2000,
"signature": "b6cb8f482a0b15d45936a4c4ea08e98a087e71787caee3f4d07a8a9843b1bc5423c6b3c22f446488b3137eaca799c77e",
"body": "b07b6d9607a20f7f5fc773bea1a8f77a9ad42fffaa359e1449a0412fc657c467bcbfa115bc63ac1ea9bd4285ced4dbd40a5e9559e83c8624c1b99e0a9bf3509ab7c00a12de474f334b900a52307d78cb5968ba02e9b44888a5cc4b444ab31f1477683fac56082e39d2f83e9a1061cbb67e3bd7b05d9475e0f070703733d3afc7",
"gt": "04d467ae9024b08afd732304fd9868df5bbda57bfa9d5bfebf65d031e905d2bf857f8a88fcee62952d39e65c799055d404d766707bb062e52e3c8eea4f66163c20ba7817f9fe5a111cf36ef5fd844386f7ae7bd4d11d6d5c93e2926c8da91fc502b35641a7f0190002912096edc9c76d49962360d2bad1911df467eb86fd72b9c09285f1add48191dff6347f20bd44c50648b4a3bf87eed4d8d7d95a60165d2e946e1ea6fed6810ee4f94d52d953f066c0422adfd4b236f4421c074fb974bec00c4c618c0583f7c2f28e408feb9f90a52e264e5eecf79f00d7ca9a3b4c77008506cf3f0cc7585409ff2d59136776dbb30ff91083ab27c3180009db81de239ad3fc4b9f02ad3d216e582422dcfb82dfa57ef09e4a294cb2190f7a6080193c8c2c0d0f01c1873d1c1d73d955b1e2fb050f943a1fdb1e891e2957985f3bbffd6d7903fa7d9ae10c759bc4024e692c16243e09b054b35400ca1b83f1c3cd6ebf0474315b18f122064eae18a3a76e36ec0261f42fdc6af5117ffc31fbcfcb13d0990319b37af84e940338613f7ec5237fc2fd99830ba1982d4553a85b7039baeb2cd5dc4c3506f64d77b5c181fab62b0552f6092dc25e5ab457a2507c0cf2981130a94390ed662b93141656cf6f62c8345420524d7b17bf4b021b5375b17b6646dbd810f754dd221c39f521b1d1f7bf5b196faff6d7264c00d9971703b0d754c122ebc3eee3ad4c380e4c0cadde7a2207966500b1fcc9f1d5fce28a74457f08bb52d0fe611e970f9fd3b0720245c5a702efb71e71063831d96d4807448f9ac083249d",
"sigma": "bcd006607f91de520e715d7188d07be4",
"r": "6c6bf922679e1ca92f2527fa5874adf3837ddf35851c0d92f79997f9c1cfa987",
"file_key": "d09d6d78026155a099f10861789c5601"
"body": "8f2cb7577b036e54ca2019d01c6941d0ea9f18e3caade81e41c8f77f1514c0a5c75583d6372db607f902d5056c942b0c16c48999c5897a1b44953499a2da59eabc7fbd6ec27886882ce0bf2becdb259b8c62b940dcdfa43865e8de37c74dc49bffa90f04530e33134cc4ee5a843aae112b49ea99eaefc5645b5f963866ed94cb",
"gt": "0a6e979e201b2e75f93ab0af0d266ac7cc8a3617b6aff1e69b65b22dc64055057ce04a5b011c9575306692d12c7673c300aa12d22ecfbf09672bb412f563e8fded84b9a21751c88acffe5802d9a7df55a66be413cd3d2212633403270b96ad32142cc55923292008525f833f2d7b747dbb6f9c7653e219bff4e9c9e0516ebef129884263c4121939b278118d94a42d901045dc777ad453d5d0fe2733da0d22659d61391e6bce2b2cf285ccda5ccbd4d55c7b4d6173131e7fc67d9abd4849f67916e95986d61a47008f4c999f4181b6bf252ad1e82a4e8d28b197d76c08d533427159b66b7e1b2f9b07fda931aa2c5055059ec52f03addc43093aa3e4a9128f8853f2f13cafadf09ceb83a6e2a03c4c289fca5a290db1f1ff03037ad33fee894a0ad29276146cbccdf7433b8c24a1be750355e7c4f9c5d8ffc9824596530677d7fbe31da1424572493ab046340201c20708ae6c523eee32e21fc5ecd62de2fd764180372f617b7fb3fc960554cc4594fa31d74041a3fda4c1291a47a853bcbd3714d9735ee0b398de27283f571d68e37dfcf947d135c0f8db36556318a580de154f874271a4ebdde23bb966d3ef9977640e3b0943c1ee44872ddd379b2a307d1c3baae21bf9546b625f6f2a0aa11bd15c63df7d2315cfa16cf1b59629babca09818e8baab411f7943b1d16ca53df07a417eaeb19b1fb48c3451fe53c0b8d00398872b83f6836e7dc37b3005624488cf81123bfc106d79e3f41e8cfc338b9f960153b4f7a011d90cd0eb81ef3bf6264be3fb165f8989621ee8543ca1741e87091d",
"sigma": "25fedf2e4e3d2db30d94a0b468b90e38",
"r": "51d85fb4996c5c96c33e15def42a07200863bcda50cb31b102ac1e062e361e8a",
"file_key": "ad1ef55f85be2eb6be3b14c2e29d3b10"
},
{
"name": "format3_sealed",
"round": 1000,
"signature": "b44679b9a59af2ec876b1a6b1ad52ea9b1615fc3982b19576350f93447cb1125e342b73a8dd2bacbe47e4b6b63ed5e39",
"body": "a997ce105da38e371d30e785139a09988fa76d996731b452b367b2f162e45e7e50d6b637ba7859285c30d2c4f820af1b102a566baedafd449bf5822b312e47687e42c0415c75d6a1c28f53535f030161d7f76ed21ad0559c06c944134f76171b999565fdc59b95d4ed7e86cde4d69425cc468c85b1034a7b9b9a59bca57851ec",
"gt": "001c6f2698d3a4bc7f23c878263702983399303c88873844513fe85d10955c2b7e69936c732c1077c153c6601d825cf7062afd39ff72904bf52af7a30585da8cb4f0f6ee9d2ac12baf3814c278c09c1742b36a40705b91fe0b227e06497f8083102a98bd58616c3bbb4fb0aad092bb87ba93e3d86b9a9e68140036de255647436b4accad045b329e91fbf432621b28c413e0ca8716dae6632087060a2925f7714d649528aac5b42071c4252435ec7591fd4c7dd13b99e25a1f9e53d3d2ed51c00a4fa88689bdf09ecd5f4ba2900ea126e217e73192188618cb1f458c9e9f7eceb05fd552fc01d1e51197164ed04a84640745cded02537d0586f312159d36ef30e0d7f67b166159a3cac2d6c7de7b9d3d106bd35bde3336ee925cbd3201056c0a0f8437f0bc1acc98afd51c0f0f729f271cbdccd1481da059f6854efe3843897997353495e4b769de981eb57c5639257b0d3b7a8c53f45c42cee145a111e86abd6def541e2bc10a5626499d4f4aa697c64c005e0b1f3b87944ce8267f3e0dad6a012b5c49b77b9917ffa0bad6983b19370c4cbe51c2af02cb987240faf1bac6492214ea3fa45ec28e075ed88df84553660c63ea07fd57c53ce6342d58b9f41025f252e5344ebba00f0df57fd477604b48516c722c5c11f3bfa0eb5d09b8709711190135845ffd12c9e4fb9f90a2f630006304a92e51412710aa7e4dec55628584aa39a84713225957a9bec21771697bd501b4b3b3c0d17725736a05883e1420af57f4985ea2127f7f088250d4fa1470a50fc37311f01ad479d34f6c58c7fb27ab",
"sigma": "561ecf99d0ee7b65b9b8eabdf1326d49",
"r": "2cb8d938e57ac3f488a86ae32e8b8cf337e53d1dc4026251fbb765c7d55a5f56",
"file_key": "e28fad3c090481bd1c51bbe29c1e51e3"
},
{
"name": "format3_security_v2",
@ -228,11 +238,31 @@
"name": "format3_signature_unsupported",
"round": 1001,
"signature": "b33bf3667cbd5a82de3a24b4e0e9fe5513cc1a0e840368c6e31f5fcfa79bea03f73896b25883abf2853d10337fb8fa41",
"body": "85ddc68a8dcec80a9e9d123d066b83dc0c16283cb740cfc36ce35d2196ba4826be94684aab2555c03c269fcaf624274419dfe8b4d1dba7a9a04e326decb075d7420688adb9ce607dd827549ef3d089d43b4106818de6e75b8b55360305cc7623cd12ab07ae61078c8b91bf5baf00fe3cb8603745428506a3b78b325dfede923a",
"gt": "0d43b966f4f1f1a43e4bdf25a60b60eedf15cc1f7dc698de7b6d042072d1265b5e501dbb7f0c746c3095682b2e86fda305cf124564884f21141871d5185898cfb7317513c357f95a8fa2755db12fa0eaeb794b157a870a4225df6a0626537cdf1055f6226bd8e3d1abac2688f5511d7e07c9ac7dac5e345fc70a018cbff6f399621d8005e145b9b021142149d4870621140503d9db1e8208b4e8ee73f0091368a3a9e84e8960a611814c63af01ad09140abfb4e1dc5c307af0c308e72ea004571179484e7f6f3de09e88a36de8e979bb4dbeec4371e533ff21efecbc3b56d945e032f5b229908f11bd409c4591adfa850c767c96aa8d3583247a0d2c17afb47861f21766175b7c7b6c6870247aa3750253f17d01603ec0108c633970a2b65ce50733126a7b9af02d813168206328058b7522c1bb09b77ace44a35a2df3a96501440bef3fcd0bab7842d02932771cdf56010035abebd08058b988dc959c722e83bde308eb10a08da4723c21ca948c8823c890d27e84bf0c5943ff0579f958af7002154a40d6481bef47c9b09638dd4f59a704b09c1965e009e5c5109436611d4e763e1db38ef66f66bd2c911cac21dd83038822faaf86b2831099093ed1af66cecb24f7255d3023bedbd26cc79f094c2a388ff7089e59e970f42a6eb64e9d50bb07448cbb244d810db75642ef82cc21b59b42614228a81d85a29159730f96485bc39207dcd0861bdea4b1349026271b4817d8977da1d306dd135e5f7ab85f3f2b5a8e46f71052efa32c0c8e22e38c541ac28c516fa6259a97d0f26db37ae3e25f",
"sigma": "ac43dcfd4164774fc61831d88d384157",
"r": "5bebc6873b788ffcca50e40aad9a76566d44c2240c12f1db6c546a48c08b4ae9",
"file_key": "b48f1a33fd384618c3e5316af390311d"
"body": "956a20295b5d8ff897cdf7fc9e533de6fcb6057fa10b755893897c4c6fb3fb72374e60eec44a7f2389b6b49972e368160c1479b4a14ecaf4ea8c27fb160c585f3c2ac8357be1005d783aa174ffac39775b5f51e4f6f7623fc82b77969cbe6186e5d95281941b126463673b5d33ed12972719d40fc8602bc1952750a42f0d6ea2",
"gt": "14700225b064ece17f372d5137af4c4242db24d8c3bd506b1259ecd21ae3c2845cd56b84fadc5723771e18ae2cc94285051cda39cf875302162539268801b7e9143809495233e5a77842edcbe0baf59ffe085f971329b670b17b0bcf84d8d74b088b75aaf80aae14e624de290d416fa31abe62dedb1c9dd2155d2dc026c4b5eb68121276680026783a36472429454f7f17cecd5400cf6356659665e72b200f750aa9047e84fd5721b5cc40a077dca09d2b9b6b126689439731b196ef1eef50b0095f10ea1f86cdc4d3db1d7ff339584f614f4eaef8463a35c40b6b9025d390dbafde382e73f3394690a3814cdfa65a6615bc8c8bdc4f3a010c6884bc7ff56268d301b4b631698df49a8a8153440cac5a37dda08280dc8bdfce96cbc3193862bb092955dcccd05445bd6fda0b30ef07177a12f241b2b80751528b136bcfd2b92ce0f8d00f892d7523bdb7de3f6f1ab59008d716fe3eaea532f8d76fc46350cb08cab7b28c4aedaa6536ed2023ce0ad4b124f9f734cb8ea7f555510cafb4808e9111a92d0565798da927e5931f6112a132b7e7976c65373e42edbe8444a2f81882e16326c244d6b3bb338dfc54e2c01fe4100a9a2965a72a1d812ecd45fe7d687b2123bd5e2ad48363ebfabe7368c709ee0ae934fe01c4d8328f877f080f334b761568ef4d037787ad6024c736d783c5e10152c2764e6371df3c9d62fd38ad3a5868a46ecb9413ea8f444e25cbf2e655880004d7773e1a83f1396610bee578b948cecab442db420df57323ea0d092001112a10809b0681797825abac68cfd3553f",
"sigma": "d0cc7b69b9ff4006bfff36a70c7987e2",
"r": "42793a9f250083ed5340c13d093381f71f800fdcaa65bf0058c7893e9f29a56a",
"file_key": "7043ce939cf88f8fd50476bb8fc45014"
},
{
"name": "format3_signed",
"round": 1000,
"signature": "b44679b9a59af2ec876b1a6b1ad52ea9b1615fc3982b19576350f93447cb1125e342b73a8dd2bacbe47e4b6b63ed5e39",
"body": "a633e4d9d6b63893e7441848e2e8530fa4aa912d86df7644feee085701a3bb1269a640556de1b08f233397edc405969e006d17781bf2e447a0d23c75ed8b8b5dbb14aec6d2b485ee4a58487a5b6c51645dd9bde14f62ab4676ced2da368e3eae4f292d6ba505506c8c854ff0df690005d909ad470606ab6780d56ddb77e09f3e",
"gt": "08afd5eb35cc1269ffcb356ed60fc50514363f9c7ac28e310558bbfd129f039fe4abdcccfd5294ebdbcce0bd61484a8d0533dd91cfe34dd9871a498e3e7e1ad410993906255df086d2c5112b603941f01e9813f94ad6da342c8a699bc83cee7308fcf55b062be1141aa2a9be56f66dc1ed15d9fcf48310aaf1f614844c206d2b10ebba135df7a55f017233fb362896e00f3d95613ca8ee5dc62bd02fdc87cfc074839593157c74afdda2960d65b5c025dbbc4f2949e2e347a743dd0b3b6ad15c11cd03f50f84c7e67a2d02f8831c2da4a07b64b8981742dab4586b1be1b53145624aa83c44447b7d56b725e288fb4ddd195a69cae2e84b3ac99b9d779f1d174f926528198669acda970e8dfafc2252e96501c92d29e62097da1dab49ffd679ee08c86b5c002068cfcac503d945701b94a27056d9474eacb32e7f1d5c20f81c31c77d77315d3b65239f537c7b728c32dd01d991e294dac259982a5b8ecf5c954574f886dfadc91b76fa981229bebd46183b6f098de205dc203e001494d7aa04a017a9939c3a6398651d3bd58b09f93ce42a4831b1e337a923c451dc1b58c174ed709d2a4b65cfbaa86e545d96ab9744cc05daa4e03fe2484769236636e2c014a767c4fa4aa1b34e5fa0e04da48e7d50ebd8f7957a4a656ec35d5670d2f88fbf561827704a5eed2156f22a7e34458ac470095930f2d816c8a128faf5f89bd22f987f355b94012c7b03823c7f3505986cb917e21873b81d2f71ff0ca7deca1de541ceb4821550edb824aea7be01e8b9d3ca69d248a2c2cbb726776661d3965377b0",
"sigma": "05def51763185fe63e7fe7f2ae189eea",
"r": "222d8e58e9e99a41cb3d32f3aa8dce673ed42ddeb04fad64c3a2251c5ca64d85",
"file_key": "956e9ef859948545f4adb5e8d6c76e0e"
},
{
"name": "format3_signed_cms",
"round": 1000,
"signature": "b44679b9a59af2ec876b1a6b1ad52ea9b1615fc3982b19576350f93447cb1125e342b73a8dd2bacbe47e4b6b63ed5e39",
"body": "9504af06ca444a66940de36d5c15d197d828d2e5f8de834a29190c4d61efe831d719a5acaf7b598b3338134baf78846e139247bf66b694f39d4b6c756c51d8c22264de003d1188485c8ab853438a01eed8acd71beaec168e8507586b56f9216120bec147e04e1c6e2c1c9faa0a0dc5a9f28ba97f3fca64ce81cf4bfe9f7f56e9",
"gt": "194557dea3992a89e3f3c9e18bd7830dcfa80e6ce353e6a978df7f0747790286aa441c1d6625e7a078f93d3d430bd3d5186a9d396b29f82ef16a9d491bd6a7f95ccbb0e67dbbdf387cdaa98f6a8466932bb879d56cde79f2642184087b89bdac020f1902e5b89e119b611134d2de3dadbfe28573bca6fac7e3bace78ace8a10104643f5ba979a0ff1fe78d92c9f1265c12cb2b75750e810c30ef56da94cc08ab70a728526d541eba29659b3a61924fe6e300231f16de4f0e54add69d0020e256032ea3f894c5de0b39bf15fb6e0851931b78579990d9f339032ef7906834e0173bc7149735a716f3f1f22c3d8741e1ca0af3b81cbde5a78bba9116a9f4700de4b6ea6e38681eac76a113a4a5fda67b6b4742faeb7b18396630e045fee91131f70da39c61e72730299206fed44981f8d5ebfb9cf42b60330db1602d6a91f529e4eb0f6fd312f20db3fdc6b5b1066d5e92019ee088f5e8a2cc8351ad059e5d44831cdf4cdfb2b4c4b5e55ea36c6a02c98bfb38b5353b9fcc55409df61050e9d26f0f5113f8bc466a6a875f44ff724391e2c33df0723ff631e0c12f01d9c85be7a987e7a9b755560b07e40cd74a3cf4e481128c4da457ef651a5b439405ec92507fdfe5dfa15f6d93c0369606427896156a6788672f70fbdcdfde021fc706b1f074130af3acb4b84d1e6c08ebf0ffe331d68db84803e1d6ad49ec9a1903e634a5d25607e0d48425cfab07168615bebac1a60793b2e6b11df0594cd7cb6616f6c412946f364fad59057432b7f635bac46ed65a5cd10ccc6eeb429edc5779bb058471",
"sigma": "644b74a1d11765ce2aea0b119b0bc161",
"r": "12b28076640c9005c18ded711e0d83e826039657477a9ab9c2c0973018d9bd6a",
"file_key": "7a27fbf3d45ec8133a3d27340f76f8b3"
},
{
"name": "format3_single",

@ -1,7 +1,7 @@
{
"description": "The text of the error of capsule.Open for every case of testdata/vectors/mutations.json, or ok for a capsule that opens; see the header of scripts/mutation-go-texts.go.",
"generator": "scripts/mutation-go-texts.go",
"spec": "0.10",
"spec": "0.11",
"cases": [
{
"name": "PUBLIC_HEADER_A + SEALED_CONTROL_B",
@ -820,7 +820,11 @@
"text": "ok"
},
{
"name": "a signature of alg 1 opens with the verdict F1",
"name": "a signature of alg 4294967295 opens with the verdict F1",
"text": "ok"
},
{
"name": "a signature of alg 1 that does not verify opens with the verdict F2",
"text": "ok"
},
{

@ -0,0 +1,32 @@
// What this library does not do yet of spec v0.11: it reads the security area
// of a format 3 capsule as a reader of v0.10 does, so a signature or a seal that
// the reference checks gives F1 or S1 here. The shared fixtures and vectors
// already record the verdicts of the reference (F2 to F6, S3 to S5), and these
// helpers say what this library gives meanwhile, so that the tests state the
// gap instead of hiding it. Porting the verification (spec §29.8 to §29.11)
// makes every function here the identity, and the guard test fails until the
// entries are removed.
import type { Verdict } from '../security';
/** Verdicts that a reader of v0.10 cannot reach: those of a signature or a seal that is checked. */
const SIGNATURE_CHECKED: readonly Verdict[] = ['F2', 'F3', 'F4', 'F5', 'F6'];
const SEAL_CHECKED: readonly Verdict[] = ['S3', 'S4', 'S5'];
export interface Recorded {
readonly signature: Verdict;
readonly seal: Verdict;
}
/** The verdicts that this library gives where the reference records `recorded`. */
export function ported(recorded: Recorded): Recorded {
return {
signature: SIGNATURE_CHECKED.includes(recorded.signature) ? 'F1' : recorded.signature,
seal: SEAL_CHECKED.includes(recorded.seal) ? 'S1' : recorded.seal,
};
}
/** Whether the verification of the reference is something this library does not do yet for `recorded`. */
export function isPending(recorded: Recorded): boolean {
const p = ported(recorded);
return p.signature !== recorded.signature || p.seal !== recorded.seal;
}

@ -80,14 +80,14 @@ export function result(v: unknown, where: string): string {
return s === 'ok' ? s : code(s, where);
}
/** A verdict of the security area of format 3 (spec §29.7): X, F0, F1, S0, S1 or S2. */
/** A verdict of the security area of format 3 (spec §29.7): X, F0 to F6 or S0 to S5. */
export function verdict(v: unknown, where: string): Verdict {
const s = str(v, where);
if (!(VERDICTS as readonly string[]).includes(s)) throw new FormatError(where, `"${s}" is not a verdict`);
return s as Verdict;
}
const VERDICTS: readonly Verdict[] = ['X', 'F0', 'F1', 'S0', 'S1', 'S2'];
const VERDICTS: readonly Verdict[] = ['X', 'F0', 'F1', 'F2', 'F3', 'F4', 'F5', 'F6', 'S0', 'S1', 'S2', 'S3', 'S4', 'S5'];
/** A step of the reading flow of spec §63, 1 to 18. */
export function step(v: unknown, where: string): number {

@ -61,6 +61,7 @@ import {
import type { Release, ReleaseSource } from './release.ts';
import { evaluateSecurity, type Verdict, verdictLines } from './security.ts';
import { MemorySink } from './sink.ts';
import { isPending, ported } from './testing/pending.ts';
import { hasTestdata, hx, listTestdata, readBytes, readJSON } from './testing/testdata.ts';
import {
applyEdits,
@ -584,22 +585,25 @@ describe('vectors/mutations.json', () => {
const inspected = f.filter((c) => c.error !== 'ok' && c.step <= LAST_INSPECT_STEP);
const opened = f.filter((c) => c.step > LAST_INSPECT_STEP);
it('has the cases README counts: 209, 169 of §64 in their runs, 57 in steps 1 to 8 (39 of them from §64), 3 that open', () => {
it('has the cases README counts: 210, 169 of §64 in their runs, 57 in steps 1 to 8 (39 of them from §64), 4 that open', () => {
// v0.8.2 had 65 cases, which stay first; v0.9 ran the 33 mutations of the
// first two lists of §64 on the format 2 fixtures, the 22 of its third
// list and 5 companions with a .dkk; v0.10 adds a case to that list, the
// same 33 on the format 3 fixtures, the 47 of the list of format 3 and 3
// further cases.
expect(f).toHaveLength(209);
// further cases. v0.11 adds one outside §64, a signature of alg 1 that
// does not verify, before the seal of seal_type 1: 205 of the 210 cases.
expect(f).toHaveLength(210);
const run = (from: number, to: number, spec: boolean): boolean => f.slice(from, to).every((c) => c.spec === spec);
expect([
run(0, 33, true),
run(33, 65, false),
run(65, 121, true),
run(121, 126, false),
run(126, 206, true),
run(206, 209, false),
]).toEqual([true, true, true, true, true, true]);
run(126, 205, true),
run(205, 206, false),
run(206, 207, true),
run(207, 210, false),
]).toEqual([true, true, true, true, true, true, true, true]);
expect(f.filter((c) => c.spec).length).toBe(169);
// README: the same 33 on the fixtures of formats 2 and 3 are named
// "format 2: …" and "format 3: …".
@ -610,6 +614,7 @@ describe('vectors/mutations.json', () => {
expect(opens.map((c) => [c.spec, c.verdicts!.signature, c.verdicts!.seal])).toEqual([
[true, 'X', 'X'],
[true, 'F1', 'S0'],
[false, 'F2', 'S0'],
[true, 'F0', 'S1'],
]);
expect(inspected.length + opened.length + opens.length).toBe(f.length);
@ -676,7 +681,8 @@ describe('vectors/mutations.json', () => {
expect(r.error?.message ?? 'ok', 'the text of capsule.Open').toBe(TEXTS.cases[c.index]!.text);
if (c.error === 'ok') {
expect({ step: last.step, ok: last.ok, error: r.error }).toEqual({ step: 18, ok: true, error: undefined });
expect([r.verdicts, verdictLines(r.verdicts!)]).toEqual([{ signature: c.verdicts!.signature, seal: c.verdicts!.seal }, c.verdicts!.lines]);
expect(r.verdicts).toEqual(ported(c.verdicts!));
if (!isPending(c.verdicts!)) expect(verdictLines(r.verdicts!)).toEqual(c.verdicts!.lines);
expect(sink.opened?.head).toBe(r.head);
} else {
expect({ step: last.step, ok: last.ok, error: last.error }).toEqual({ step: c.step, ok: false, error: c.error });
@ -716,7 +722,7 @@ describe('vectors/mutations.json', () => {
expect(r.error?.message ?? 'ok', 'the text of capsule.Open').toBe(TEXTS.cases[c.index]!.text);
if (c.error === 'ok') {
// A format 3 capsule that opens leaves the output untouched.
expect([last.step, last.ok, r.verdicts?.signature, r.verdicts?.seal, closed, aborted]).toEqual([18, true, c.verdicts!.signature, c.verdicts!.seal, false, false]);
expect([last.step, last.ok, r.verdicts?.signature, r.verdicts?.seal, closed, aborted]).toEqual([18, true, ported(c.verdicts!).signature, ported(c.verdicts!).seal, false, false]);
} else {
expect({ step: last.step, ok: last.ok, error: last.error }).toEqual({ step: c.step, ok: false, error: c.error });
expect([closed, aborted, sink.opened]).toEqual([false, true, undefined]);
@ -1145,8 +1151,10 @@ describe('vectors/security.json', () => {
const VECTOR_FILES = [
'vectors/cbor.json',
'vectors/dk1.json',
'vectors/ed25519_strict.json',
'vectors/head_schema.json',
'vectors/inspect_differential.json',
'vectors/locator.json',
'vectors/mutations.json',
'vectors/padding.json',
'vectors/path_fold.json',
@ -1154,6 +1162,7 @@ const VECTOR_FILES = [
'vectors/profile_quicknet.json',
'vectors/quicknet_rounds.json',
'vectors/security.json',
'vectors/security_cms.json',
'vectors/tlock_ibe.json',
];
@ -1186,6 +1195,38 @@ describe('testdata/', () => {
for (const f of VECTOR_FILES) expect(readme, f).toContain(`\`${f}\``);
});
// The vectors of spec v0.11 for the verification of the signature, the seal
// and the locator (§29.8 to §29.11, §44.1) that this library does not port
// yet: their structure is checked here, and what a reader of v0.10 gives on
// them, so that the gap is stated. Porting makes these blocks check the
// verdicts and the locator themselves.
describe('vectors of v0.11 not ported yet', () => {
it('security_cms.json: every case has a context and verdicts of the table, and the cases without a context are read as the reference reads them', () => {
const f = object(readJSON('vectors/security_cms.json'), 'security_cms.json');
expect(f.spec).toBe(SPEC_VERSION);
const cases = array(f.cases, 'cases').map((c, i) => object(c, `cases[${i}]`));
expect(cases.length).toBeGreaterThanOrEqual(20);
for (const [i, c] of cases.entries()) {
const at = `cases[${i}] ${String(c.name)}`;
const recorded = { signature: verdict(c.signature, `${at}.signature`), seal: verdict(c.seal, `${at}.seal`) };
const ctx = object(c.context, `${at}.context`);
expect(hexOf(ctx.control_commit), at).toHaveLength(32);
expect(hexOf(ctx.head_digest), at).toHaveLength(32);
// Read without the context of a capsule, as a reader of v0.10 does, the reference says exactly what this library says.
if (c.no_context === true) {
expect(evaluateSecurity(hexOf(c.security_cbor)), at).toEqual(recorded);
expect(isPending(recorded), at).toBe(false);
}
}
});
it('locator.json and ed25519_strict.json name this specification', () => {
for (const name of ['vectors/locator.json', 'vectors/ed25519_strict.json']) {
expect(object(readJSON(name), name).spec, name).toBe(SPEC_VERSION);
}
});
});
it('checks the harness itself', () => {
const base = Uint8Array.of(0x30, 0x31, 0x32, 0x33, 0x34, 0x35, 0x36, 0x37, 0x38, 0x39);
const ed = (list: unknown): Edit[] => edits(list, 'test');
@ -1211,9 +1252,15 @@ describe('testdata/', () => {
expect(() => keys({ b: 2 }, 'x', ['a'], ['b'])).toThrow(/missing "a"/);
expect(() => code('ERR_NOPE', 'x')).toThrow(/not a normative code/);
expect(() => step(19, 'x')).toThrow(/outside 1..18/);
expect(() => checkSpec({ spec: '0.8.2' }, 'x')).toThrow(/want 0\.10/);
expect(() => verdict('F2', 'x')).toThrow(/not a verdict/);
expect(() => checkSpec({ spec: '0.8.2' }, 'x')).toThrow(new RegExp(`want ${SPEC_VERSION.replace('.', '\\.')}`));
expect(() => verdict('F7', 'x')).toThrow(/not a verdict/);
expect(hasTestdata('README.md')).toBe(true);
expect(errorCode(new Error('x'))).toBe('');
});
});
/** The bytes of a hexadecimal string of a vector file. */
function hexOf(v: unknown): Uint8Array {
if (typeof v !== 'string' || !/^([0-9a-f]{2})*$/.test(v)) throw new FormatError('vector', 'not a hexadecimal string');
return Uint8Array.from(v.match(/../g) ?? [], (b) => parseInt(b, 16));
}

@ -12,7 +12,7 @@ export const VERSION = '0.2.0-dev';
/**
* The version of the DateKeys Protocol Specification that this library
* implements: the tag spec-v0.10 of the Go reference, whose shared vectors
* implements: the tag spec-v0.11 of the Go reference, whose shared vectors
* and fixtures (testdata/) all name it.
*/
export const SPEC_VERSION = '0.10';
export const SPEC_VERSION = '0.11';

114
testdata/README.md vendored

@ -44,6 +44,7 @@ Conventions for every file:
| `vectors/path_fold.json` | the key of R7 of segments, and their NFD | §29.5, §29.5.1 |
| `vectors/head_schema.json` | heads of format 3 and the result of decoding them | §29.4 to §29.6, §69.1 |
| `vectors/security.json` | security areas of format 3 and their verdicts | §29.3, §29.7 |
| `vectors/ed25519_strict.json` | Ed25519 signatures and the result of the strict profile of the author signature | v0.11 §29.9 |
| `vectors/mutations.json` | the mutation corpus: the 169 mutations of §64 and further cases | §63, §64 |
| `vectors/inspect_differential.json` | 5110 mutations of fourteen fixtures with the verdict of steps 1 to 8 | §63 |
| `fixtures/<name>.dkc`, `<name>.json` | official capsules and every intermediate value | §67 |
@ -72,7 +73,7 @@ extension and a noncritical CONTROL_CBOR extension. The release that opens each
capsule, a published Quicknet signature, is in its `<name>.json`, so they all
decrypt offline.
Nine are in format 3. Their plaintext file is BODY, L bytes: the frame, the
Twelve are in format 3. Their plaintext file is BODY, L bytes: the frame, the
security area, the head and the files (spec §29.2).
| Fixture | Policy | Files | Comment | L | Padding code | P | Area | Verdicts |
@ -86,14 +87,45 @@ security area, the head and the files (spec §29.2).
| `format3_security_v2` | `time_only` | 1 | — | 659 | 2 | 768 | 512 | X |
| `format3_signature_unsupported` | `time_only` | 1 | — | 659 | 2 | 768 | 512 | F1, S0 |
| `format3_seal_unsupported` | `time_only` | 1 | — | 659 | 2 | 768 | 512 | F1, S1 |
| `format3_signed` | `time_only` | 1, `nota.txt`, with mtime | — | 32915 | 2 | 34816 | 32768 | F4, S0 |
| `format3_signed_cms` | `time_only` | 1, `nota.txt`, with mtime | — | 32915 | 2 | 34816 | 32768 | F6, S0 |
| `format3_sealed` | `time_only` | 1, `nota.txt`, with mtime | — | 32915 | 2 | 34816 | 32768 | F4, S4 |
The first five are what `capsule.EncryptFiles` writes. The other four only a
The first five were written by a writer of v0.10, with the area of 512 bytes;
a writer of v0.11 writes the area of 32768 bytes, as in the last three, which
`capsule.EncryptFiles` writes with a signer and a sealer. The next four only a
generator of test vectors may write (spec §62.1 rule 13): an area larger than
the 512 bytes of this version, which a reader accepts, a security map of
version 2, which a reader of this version cannot read, an author signature of
`alg` 1 with a random key of 32 bytes and a random signature of 64, and that
512 bytes, a security map of version 2, which a reader of this version cannot
read, an author signature of `alg` 4294967295, an `alg` that no version
defines, with a random key of 32 bytes and a random signature of 64, and that
with a seal of `seal_type` 1 and a random token of 32 bytes. None of them has
a verdict that stops the opening. The BODY of `format3_tree` is over two STREAM
a verdict that stops the opening.
The last three are signed and sealed with test keys (spec v0.11, §29.8 to
§29.11), and their record has a `signature` object, and `seal` in the third:
- `format3_signed`: `alg` 1. The seed of the test key, which is not a secret,
is in `secret_seed`: Ed25519 is deterministic, so signing `author_message`
with it gives `signature` again. Opening it gives F4 and the key `author_key`,
`dkauthor1…`; with that key among the saved ones, F3.
- `format3_signed_cms`: `alg` 2, two certificates, an ECDSA P-256 one and an
RSA 2048 one, each with a seal CAdES-T from a test authority, dated before
the round time. The record has `signers` (SIGNERS in hexadecimal),
`certificates` (the DER of each), `signature` (the DER of the CMS signature)
and `signer_results`, one for each required signer in the order of SIGNERS:
holder, issuer that the certificate says, result, seal time, and whether the
seal, with its accuracy, precedes the round time. The private keys are not
kept: ECDSA and RSA-PSS are not deterministic, and a reader only verifies.
- `format3_sealed`: `alg` 1 as the first, and a seal of `seal_type` 2 over
`SEAL_SUBJECT`. The record has `seal`: `seal_subject`, the `token` in
hexadecimal, the `holder` of the authority as §29.7 shows it, and the time.
In the three, the record gives the commitments `control_commit`, `head_digest`
and `signers_digest`, the text `author_message` and its `author_code`, and the
exact content of key 2 of `SECURITY_CBOR`. An implementation checks them from
the control, the head and the security area of the fixture, and the verdicts
from `verdicts`. The certificates and the tokens are random, so these fixtures
are frozen once written like the others. The BODY of `format3_tree` is over two STREAM
chunks, with its head in the first.
## Edited files
@ -380,6 +412,76 @@ signature and the seal are evaluated apart, and the first row of the table of
give F1 with the seal intact, and a seal that breaks its schema gives S2 even
with an unknown `seal_type`, which is read only from a seal that meets it.
## `vectors/security_cms.json`
Security areas with an author signature of `alg` 2, a CMS signature with
certificates, or a time seal of `seal_type` 2, an RFC 3161 token, each with
the context of its capsule and the verdicts of spec v0.11 §29.7, §29.10 and
§29.11. They complete `security.json`, whose areas have no valid signature or
seal. The file is frozen: the certificates and the tokens are made once, with
test keys, so a second implementation reads them and must reach the same
verdicts. Delete the file to make it again.
```json
{ "name": "alg 2: a required signer is absent", "security_cbor": "a4…",
"context": { "control_commit": "…", "head_digest": "…", "round_time": "2030-01-01T00:00:00Z" },
"signature": "F5", "seal": "S0", "signers": [ { "holder": "Ana López", "result": "valid", … }, { "holder": "<sha256>", "result": "absent", … } ] }
```
`context` is what a verdict needs besides `SECURITY_CBOR`; with `no_context`
the area is read as a reader of v0.10 does, without a capsule, and any
signature is F1 and any seal S1. `signers` are the results of the required
signers in the order of SIGNERS, and `foreign_signers` those that are not
required and never count. A valid seal gives `seal_holder` and `seal_time`.
The cases cover F6 with two signers, with a seal after the round time and
with a signer who is not required; F5 for an absent signer, no seal, a seal
from before the certificate was valid and a key 3 beside the signature; F2 in
the context of another head; F1 for SIGNERS out of order or empty, a signature
that is not a CMS, and the lack of a context; and, over an `alg` 1 signature,
the seals S4, S5 (also when the accuracy reaches the round time), S3 (another
subject, an authority expired at its time), S2 (a TSTInfo of version 2, not
DER), S1 (a SHA-384 imprint) and a seal over a capsule without a signature.
## `vectors/locator.json`
The extension `datekeys.capsule` of a `.dkk` and what it points to (spec
v0.11, §44.1): a `.dkc` of patterned bytes in an envelope of age whose header
(`envelope_header`) goes in the locator and whose `rest`, without a mark, is
hidden in a `host` file at `host_offset`; the locator sealed with tlock for
round 1000 (`locator_sealed`), with its plaintext of 4096 bytes
(`locator_plaintext`) and its fields; and the data of the extension
(`extension_data`), with the note `note` and the DateKey `datekey`. A reader
opens the locator with the release of round 1000 (`quicknet_rounds.json`),
finds the rest in the host, checks `rest_size`, `rest_digest` and
`capsule_digest`, and gets the `.dkc` back. The file is frozen: the envelope
and the locator hold randomness.
`padding_cases` give the length of the plaintext of the locator for the length
of its CBOR without the padding of key 6: the least multiple of 4096 that key 6
can fill exactly, which skips a multiple where the CBOR length of key 6 jumps
(a base of 4070 gives 8192). `uri_cases` give the verdict of the rules of §44.1
on an address: the scheme `https` or `ipfs`, the raw ASCII authority with no
percent sign or userinfo, a host of letters, digits and hyphens or a public IP
literal, and a port from 1 to 65535.
## `vectors/ed25519_strict.json`
Ed25519 signatures, in hexadecimal, and whether the strict profile of the
author signature accepts them (spec v0.11, §29.9): the equation of RFC 8032
without the cofactor, A and R canonical, S below ℓ and A not of small order.
They follow the cases of «Taming the many EdDSAs»: S + ℓ, the top bits of S, a
non-canonical R, the eight points of small order as A, non-canonical
encodings of A, a key of mixed order with and without the cofactor, and an R
of small order with a key of prime order, which this profile accepts.
```json
{ "name": "A of small order, the point 0 of the torsion, R the identity and S = 0", "message": "…", "public_key": "0100…", "signature": "0100…", "valid": false, "stdlib": true }
```
`stdlib` is what `crypto/ed25519` of Go answers, for the record: where it is
true and `valid` is false, an implementation needs the checks of the profile
before the equation, as `internal/ed25519strict` does.
## `vectors/mutations.json`
The mutation corpus of spec §64, as frozen data. Each case is a `.dkc`, what

109
testdata/SOURCE.json vendored

@ -1,115 +1,130 @@
{
"module": "g.activething.com/go/DateKeys",
"commit": "2213b8c3fd7e20dac09b82ae3fba383d8993edd6",
"commit": "ae334343bfa2433bd82b679c8119596dbd4840a4",
"files": {
"README.md": "e6d0c3a0fe0fcfdefec609d2c02c4ac667430e45b2eb3756b17d745cb056ae03",
"README.md": "bc32fe488a0e4d2298a9048711c235661187ba57dc3f156767f8cb5b2f3e6416",
"fixtures/empty_payload.dkc": "871e9bf05b52bbae17f3adfbbf97b46e7f0e53aa8f57bcaa506e43f36f53a9d4",
"fixtures/empty_payload.inspect.json": "373e5d012b023ad58bbb54cbdffe0bed9e50c637438a4083ddb74d5414c59f59",
"fixtures/empty_payload.json": "aa83c8380496b41baf92e582b4cec2a8433a8ec151ee9ebd83b24533dbb9a839",
"fixtures/empty_payload.json": "588c2573d99b953d490e3d9caaa392b804398b1f91d4f95492a01dd5e7e1f8ba",
"fixtures/empty_payload.plaintext": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
"fixtures/format2_empty_payload.dkc": "7aea2b5aa48b1a46053716f733d50fab9cd0b80b1be67631bcc06c5bb765dc21",
"fixtures/format2_empty_payload.inspect.json": "d0bb7356d3970986e6b197640f0b3b38abe9fabf1740b745171b358aa28903ff",
"fixtures/format2_empty_payload.json": "ad76dbc182318553f8ef320bf64018366d30d20e85d5d24dab250457a88d35f9",
"fixtures/format2_empty_payload.json": "0ddce7b0888be7220d1de108d645cfec9fe15d2e33bc00180ae0a0f417a0f1a9",
"fixtures/format2_empty_payload.plaintext": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
"fixtures/format2_time_and_key_portable.dkc": "600892659fe4890223e895876275f656995d170fda42b07fb2bec0ca51ce4b43",
"fixtures/format2_time_and_key_portable.dkk": "095b7bc516a22bf0c2366f0af3cd48bfe857a2354d6e2a9b285278b95e450fe0",
"fixtures/format2_time_and_key_portable.dkk.json": "341c824f6046d9aaa53f7ef5b8f2848cb711a303ae394f1959e9a84445a46f7b",
"fixtures/format2_time_and_key_portable.dkk.json": "7365f2050bd124daf15b3c623254073389e47e43b13e09fc6e03e79b292ecf0a",
"fixtures/format2_time_and_key_portable.inspect.json": "522c9a98e5911c86f5f24f278971cf7c7588f6c88aaede3dd1129ee4e042868a",
"fixtures/format2_time_and_key_portable.json": "02077acd5b03b48f9b2f2b92b5c59196004eea85eb9282ed6d556ca578c55e82",
"fixtures/format2_time_and_key_portable.json": "203e39ef29d74a2f28fb7d8530e01869ece0fa8c8e2c86e81a758eca15f39268",
"fixtures/format2_time_and_key_portable.plaintext": "937492203d207d6fe36161b8696bf1f05b8b4cc56d855c44853f4b76aad3a05b",
"fixtures/format2_time_and_key_recipients.dkc": "1a44fd8708c92e2e0a10cfcb1d864a71331ea9af25d97e1a42e969dc898959e3",
"fixtures/format2_time_and_key_recipients.dkk": "2ad99b1556086ec311d7f0b3bd3aaba05e75f45c4fa22490b0d5e8bb0b1a222e",
"fixtures/format2_time_and_key_recipients.dkk.json": "64fdfdbe30bdba18ccd1168e373c8c7bb2882ae0f645aae9545240f87b89e9e2",
"fixtures/format2_time_and_key_recipients.dkk.json": "57edcc56c16ba7e17e6b7ba079688f04431967a90ce3592f065c838a0c9b2a35",
"fixtures/format2_time_and_key_recipients.inspect.json": "d975a9eddd45f5d59618ea2455d574d807e57daf08585e840d07986f261bf099",
"fixtures/format2_time_and_key_recipients.json": "3675d94a03fa28539fe84790602d87f7c022bc3247e40555b70c69a106316b15",
"fixtures/format2_time_and_key_recipients.json": "2a1dd1fa810f0b76ccee04320061ffc664c744da1206d60dbb14e0ac01b9635a",
"fixtures/format2_time_and_key_recipients.plaintext": "0e9fd50e98a85953aa9cf07a11ee3c62bb3d7622f344f1c6ce744d1ed111659f",
"fixtures/format2_time_and_key_sixteen.dkc": "7aaac5c18f216bf53df326ecc817179640a53408cf25dfd50488910a762dc381",
"fixtures/format2_time_and_key_sixteen.inspect.json": "492cd0b0dca0030df9332b098d22b4f6aa4adfb57d5540de5325e3e6d5aa3667",
"fixtures/format2_time_and_key_sixteen.json": "f07523610cb7747d1a6c9ce85ca40e807777b357701cbe90ac0debe3383aaa31",
"fixtures/format2_time_and_key_sixteen.json": "5686913ae6c4dd94fc90a96d28d2f7f7ef6fdd5213416d27c7fd85a423be1023",
"fixtures/format2_time_and_key_sixteen.plaintext": "e5abfb7b5fdbf297277b6cc4729c15d85435e890b653c2e2342b7031ecd9eab9",
"fixtures/format2_time_only.dkc": "f5a40ac6b8a08a0c12db6114c2bca23522d6a77b512b509a217fb15f367813c4",
"fixtures/format2_time_only.inspect.json": "40a8683f5204c7b6369558e4775ae6bb6fed978097e9e660de64c06c167b043e",
"fixtures/format2_time_only.json": "63ce6c0888241414c96b39897aabb25fb1170b0560963e5e12f5c8ea82c6bd60",
"fixtures/format2_time_only.json": "db863e7480eae1e1a4df985aa0cfb8456de67a1f0f5a6bcb3dd5fadf2837eb06",
"fixtures/format2_time_only.plaintext": "53b8ee821fb7b678e89d4f93da1812339f6cc1ab83aac6ed1432db99df784be5",
"fixtures/format2_time_only_bloque256.dkc": "aae769c30d04920801d8b293d30864fbe223c9c9353ec2b4907a1ee1996e39f9",
"fixtures/format2_time_only_bloque256.inspect.json": "767766414ad547f0ba95b40059e14b62c81b5489a2afcbc683bf227334d61be7",
"fixtures/format2_time_only_bloque256.json": "8331cd25a8fa504ae9c36cb196eece0e582a0622134e9565118c57937d38e0a9",
"fixtures/format2_time_only_bloque256.json": "9c7db52db560ec1203e811a214d3c6dd5324dac586331332f774a3fccc6ad515",
"fixtures/format2_time_only_bloque256.plaintext": "53b8ee821fb7b678e89d4f93da1812339f6cc1ab83aac6ed1432db99df784be5",
"fixtures/format2_time_only_extensions.dkc": "fb406100d5703a2e888983b3175ed34a09a34469cc722256e5cf535dd728fbe9",
"fixtures/format2_time_only_extensions.inspect.json": "1595d793c1d35bfdaa36576b75f53d734a9e07c2a8a12036295dbaee7f5a7f5a",
"fixtures/format2_time_only_extensions.json": "3c88e91aee4c0e29b212777d910f9d3ba7cfb8875f0b5c510ce5715a4c3d4a9e",
"fixtures/format2_time_only_extensions.json": "5f48a438c8220951df7734fb4fd2172206827145597c43307d12514ce6c3c85a",
"fixtures/format2_time_only_extensions.plaintext": "1129768e195e2f1e50b7a6f926b6eebef120212c29b5642c8a662c503b2a9131",
"fixtures/format3_area_1024.dkc": "41ea2eed0293e4fef7f4a307b7f16aaf1339f5bf6f4ded7a6a9ae1aebeb0133c",
"fixtures/format3_area_1024.inspect.json": "06e6b347926242ae5540f16a053f6a3545743986989bc0be8c39918bce968686",
"fixtures/format3_area_1024.json": "6699df0c349508aab2b604c5387e1e7460b3e5d408832162be9e85e3e430e727",
"fixtures/format3_area_1024.json": "d2722c99bf6c543a1eeb1fdd9cf57506d71b0a324b33458865b043698b7729d3",
"fixtures/format3_area_1024.plaintext": "043830350a287cba1fd50f6c063f70a74209895ff0cf03147bb4e5ccdfc206b5",
"fixtures/format3_bloque256.dkc": "ff18444f434164ba8e7b26d38c76c7855dc6b0593b2fc8b4e9a95dbf9252d55d",
"fixtures/format3_bloque256.inspect.json": "d0007080da5ce079c6ffa3a56bf8ce519d2846a31cc1082fd027f401e4f7bade",
"fixtures/format3_bloque256.json": "c8e25c23ad75935cf40b87300e13a97ca494f3d659ef99c6df7abf8b4edd93ab",
"fixtures/format3_bloque256.json": "9fe4131d6e108a8ed2206ae33ced33ed6ca770b7a0111748cf208fcdd4a916c4",
"fixtures/format3_bloque256.plaintext": "9ff2843e40bc1280dbfea8dce9386a42d06e8b43742c2cc6257540770cb53c73",
"fixtures/format3_comment_only.dkc": "7f98a89413f08655bbbab28b96585dfa6173c1705dd81a900deba2100d19f2ef",
"fixtures/format3_comment_only.inspect.json": "fb56eca8bf42c8c47fde4a1d6b2580fcff386f2f58b566820731dce388542196",
"fixtures/format3_comment_only.json": "2a07ae3535feddb3fab50a449254f702a62269611b296276e85fdc4832decee7",
"fixtures/format3_comment_only.json": "8731bcb3641d7f99f63729e85f1e2960d3f38a6ac64bb3321369bfe3e21fa2b1",
"fixtures/format3_comment_only.plaintext": "bc5b05885e608f036d8a14fde8738a8c53b395b71c3bcee99c1eab37ea23e80e",
"fixtures/format3_seal_unsupported.dkc": "9e729c4d523aa8235c1f94b6c4366500a442a7ce69a5f92b9780662daca070e3",
"fixtures/format3_seal_unsupported.inspect.json": "c1adce954b84fd0f43313dc5bec6f294d24aee5b0a26e4deaeafcab3ed41d17e",
"fixtures/format3_seal_unsupported.json": "0e96f0118694149794c9dd2475df551885ef78c65099293cae116daedeeb47f4",
"fixtures/format3_seal_unsupported.plaintext": "b7e84ded53528372d35ef5aef5c7935eff5827824832f8556e6ed06eb2951ef5",
"fixtures/format3_seal_unsupported.dkc": "cd3f68e430c8d41df92a364d65fe29b4aed8ec50e5129595735ede6a8d7df88b",
"fixtures/format3_seal_unsupported.inspect.json": "3300ec8a6024c4b7d4569e31100f8ee9b7d6ef6483120e79c60c4d7d3fec9d8c",
"fixtures/format3_seal_unsupported.json": "593310199c21384c393332de177dddf04ade56d8dd9891d4679fc5fd38e139c6",
"fixtures/format3_seal_unsupported.plaintext": "18e5a8d45af211d036dfe64fc4065c8ada927265200f48a3094aa7ded519b94e",
"fixtures/format3_sealed.dkc": "dde5a072d8783227d28279d06d3d226a1fb967c766da626f889d1c6fd76ac9c7",
"fixtures/format3_sealed.inspect.json": "b984a0755332bad838025e47f8e917b9f18b9bb5c068c2d1ef0070db8e42849c",
"fixtures/format3_sealed.json": "52cda41e8d665c8c734124f9eeb8d4e81b15c59693dff62b3aba497d4aec910e",
"fixtures/format3_sealed.plaintext": "aea0f5feb40acd81ca3b02dd21ea15510234da3ab52b374322f3206e7632d47b",
"fixtures/format3_security_v2.dkc": "3d02b39ace010d74604554e378d22fe5ce00cecd998c0f797d657b17620b8912",
"fixtures/format3_security_v2.inspect.json": "dba4d21f1d4e228a17c761bae9a4b8c5a91cd9c0123e3141d3782a43c139321e",
"fixtures/format3_security_v2.json": "9edf6cf16d4895d9c34a7f875d9e4d6345a8a143f7c0c42f2200fdc57b13669b",
"fixtures/format3_security_v2.json": "78218ca96fdfe6629853c4b8826e2ba11ee010677e54169ba8286ff9d00c9d6a",
"fixtures/format3_security_v2.plaintext": "0c58ef40e4b1c7afde0f6e0a1f4ed7e3d45405757c5143a095f0c2b58042669f",
"fixtures/format3_signature_unsupported.dkc": "83dc0f3b71cd57f2c06b5ea5860c1fd709627c2ab11c86ca1fc3b5a16d89c497",
"fixtures/format3_signature_unsupported.inspect.json": "92ff22c1679229c6ff05345a6d75be6614cefc8b6f41ee151a9697f3c88db34d",
"fixtures/format3_signature_unsupported.json": "1887025edf235540fbe516ac65ca4ac11e401059f2645fb31f53f21ae0603b76",
"fixtures/format3_signature_unsupported.plaintext": "414deeb8dc9f45fcf5f3883154e9f0e5a872ee9438a01b997d2f513b3d5a1eb7",
"fixtures/format3_signature_unsupported.dkc": "e8e3106d8d73bb7b845062e0fe42af21df7d7cd8f63c335cab8dedb3e690df31",
"fixtures/format3_signature_unsupported.inspect.json": "6db653db27604cb07e2cb2c23545fb68542c121e85002762f26c6d39e63bf00c",
"fixtures/format3_signature_unsupported.json": "427dd9201e57c2c6242722bc5b2882dd310225c40b883f9339cdd6c04f87b751",
"fixtures/format3_signature_unsupported.plaintext": "9fe05e6b3a463371b33fc6a81b81d538e572789a8d03ace9f752a931f4ca4728",
"fixtures/format3_signed.dkc": "3c7d3c9e24c02853a0c7761b93bea1120b27fce396468d8d0f68e53aeb668c5e",
"fixtures/format3_signed.inspect.json": "7c37054d542869e766147350e2fa72695f209d39a03726757008e2c2291b0e97",
"fixtures/format3_signed.json": "9d602cda39ce124b604410101a63bd981d21677f9bebb4eda5e4dedbd93531bb",
"fixtures/format3_signed.plaintext": "3de3ccab0ac74f95a76aa45c0f85e1749d4b4a051d87e81828eff6bf24372000",
"fixtures/format3_signed_cms.dkc": "d658f8d5ac2c5550c07b8f8fd6883b2f6dc02ceafc47d436ea02d8950b2548d2",
"fixtures/format3_signed_cms.inspect.json": "afadf530e8146687b25c03f26100ebff18e7f481e0ef09378816bad582270de5",
"fixtures/format3_signed_cms.json": "e88e549a0d0351df83c065a11101e3158b48d473aa9f6dfce1b8adbca96b26d7",
"fixtures/format3_signed_cms.plaintext": "31c35eeeee856277b605fe44203a8f4786bb8f591eda3b6ee58252df5b3cf2f0",
"fixtures/format3_single.dkc": "9f68664af8733255084be9036a100b75d27bd16106bf0acff94ce469dd1d1743",
"fixtures/format3_single.inspect.json": "7878da921c17aada50e00d5911ea97e8558633a1684fb96acbd00d6f1b117529",
"fixtures/format3_single.json": "dc04aac307230279d004edea594ed2000999a3f207b8b775a62fd0abea6084c4",
"fixtures/format3_single.json": "c99a175287c9555b74e8ae813326f3d7cdce0692a0144ee8e47158775970bcd4",
"fixtures/format3_single.plaintext": "74f9dd84d07e95a31e6dc063bf65ce414197acf84aac445eabc76fa4e3f24936",
"fixtures/format3_time_and_key_portable.dkc": "680d29962e575689a31543df28433dae7737abd9a793e9cae92ef40920d09636",
"fixtures/format3_time_and_key_portable.dkk": "54cc64d849395234b3e093e47f432b72781ccc13f455c9ef394e3554ab566751",
"fixtures/format3_time_and_key_portable.dkk.json": "89c9b07f2089dd8949b8116c69228ad7a2fd8fbf17b9135807d7a3f570544cdf",
"fixtures/format3_time_and_key_portable.dkk.json": "36d343d729d126990754be34f0f67c9faf1529b7d8946e6b34b4d0de5b46b744",
"fixtures/format3_time_and_key_portable.inspect.json": "f269af86f5bf84c22a1038fd78db146af93166150755eb1ca35cf15e224035b4",
"fixtures/format3_time_and_key_portable.json": "042965163bb269cab1dd5916629932bd03d24902957b9af8313b982f3edb532b",
"fixtures/format3_time_and_key_portable.json": "ca6623323ada21445c1c131cf278b060c2b22abc670f0889b30540f0abbb8dc6",
"fixtures/format3_time_and_key_portable.plaintext": "e6684cf607c102bfa4d6977742d5a7520b0e09483282181bd6d8f5f4ba5f7726",
"fixtures/format3_tree.dkc": "217f378faaf795f6a9c416b564fb8931bb2e896918aee870120fd14f9a5da7d1",
"fixtures/format3_tree.inspect.json": "643a9dfdc2d0c44b8a1636909c66ed81bfd8c50df2a4cad6566832a8e47ba938",
"fixtures/format3_tree.json": "7ad0c3c54fab4da8b22fb9b9a8bcd4b4752817cb75f89565921995926ae81c53",
"fixtures/format3_tree.json": "1d11d2f12603542039ac6b396ffec69e92bde2689fd54dfc9ef800b6b9f7746b",
"fixtures/format3_tree.plaintext": "f69ac5f450966f7d0e9161aa37451d4260b194a750e3e132c02e8a15ba561cfa",
"fixtures/time_and_key_portable.dkc": "2e97878078bae6358037a9c264f379a3cbe839f767d69836b0343f35657b2972",
"fixtures/time_and_key_portable.dkk": "e528fa2c832c91119f0684bb9d6fb3c4c2d0d55183482890e7c4fe92f668426a",
"fixtures/time_and_key_portable.dkk.json": "1bfbfbc8a24c8169f67aba7706478d722d41057a7522c587cc8c397872db40f4",
"fixtures/time_and_key_portable.dkk.json": "b057c25c9950533c01122cb907a43242b7538a7d427f8fa3cfa34ab6dfb7e390",
"fixtures/time_and_key_portable.inspect.json": "238c1f8ca6a6bf69f20bf26f5676e89a0b07e83b4362628560fc2f7522a202c9",
"fixtures/time_and_key_portable.json": "f9db3833709e4cb3f58a96c8ff14fd2b37b0574bcfa44f41a7a564b06ff6f06e",
"fixtures/time_and_key_portable.json": "26467c1b6feafde9b6b49742a87bdb648c1effff6ac99b824561566282ea60ba",
"fixtures/time_and_key_portable.plaintext": "937492203d207d6fe36161b8696bf1f05b8b4cc56d855c44853f4b76aad3a05b",
"fixtures/time_and_key_portable_extension.dkk": "0bf463a7c65627b7dda2234d728df89ec5b835816a2a37b91497d8fecc5ea548",
"fixtures/time_and_key_portable_extension.dkk.json": "1b2e6eb9ecbeece13b9ec4b9ebf94df6af58792731e690bf571170f631d68402",
"fixtures/time_and_key_portable_extension.dkk.json": "89a96dd9dd1fe30187758d78211a6fbcb4b8cb7487e3a2f224e38874b246e834",
"fixtures/time_and_key_recipients.dkc": "69ac110380f5d768b5b6afaa157a50ed17d8ceccfbd4604ffa5b6da38539b635",
"fixtures/time_and_key_recipients.dkk": "19f6c47150c3194712d454f43c7392b7344e6b4e7b074d83e9ca5f563a8e072f",
"fixtures/time_and_key_recipients.dkk.json": "8f2bb78f972ccff8d2e2f68ea8e005bd6c1b52435ba92b889c796f018dab8e16",
"fixtures/time_and_key_recipients.dkk.json": "c3712a6afc1e0ad73615ec4329a0009261b32536fd630aff3b01f28b9384b6e9",
"fixtures/time_and_key_recipients.inspect.json": "4b32c63d18febe0772837fbcd75a0c971e31378bf799201b720a9d32bdcd8c2b",
"fixtures/time_and_key_recipients.json": "fac88a0fbaabcf0f39191fbbce4bf3882e4bbce68f13e4d8238c2535b5447bc7",
"fixtures/time_and_key_recipients.json": "a00a49e7140fff35f253e42d13d221cfb339a2e59b7b53dbb3b8a32dd00cfe4b",
"fixtures/time_and_key_recipients.plaintext": "0e9fd50e98a85953aa9cf07a11ee3c62bb3d7622f344f1c6ce744d1ed111659f",
"fixtures/time_only.dkc": "99e915810d595f1092700b728f5e5081d78efe83f5343e76325b1bcc2c33ccf2",
"fixtures/time_only.inspect.json": "a4d45f945d6ba6616c01e120ac1133785e5279fea7dcab706b5feee287be8884",
"fixtures/time_only.json": "b1279806b96467cd26b881e4bd7186e92053e210317b4fd974d065c3610a0882",
"fixtures/time_only.json": "cfb7a43154189692ef3a1f08e9a12b5855df1b95c10ae13e05935160a3f9aaaa",
"fixtures/time_only.plaintext": "53b8ee821fb7b678e89d4f93da1812339f6cc1ab83aac6ed1432db99df784be5",
"fixtures/time_only_extensions.dkc": "0446c9b73e267adcb24e5cc89afba2544a386ec9a050016e06517a4a57aa2085",
"fixtures/time_only_extensions.inspect.json": "6f957b028da8a4a495b5e951ced0b91e0678128dac4e962b02d024b9439a0ba1",
"fixtures/time_only_extensions.json": "9f4dca446768b2a523ad0a5ee95de825ee63a0da6c4798b3b3302dd5936ef9d5",
"fixtures/time_only_extensions.json": "c5b6b253c03a95a3878538d98c8114041042f8dce8dbbb382727651781f4a146",
"fixtures/time_only_extensions.plaintext": "1129768e195e2f1e50b7a6f926b6eebef120212c29b5642c8a662c503b2a9131",
"vectors/cbor.json": "a955ae65b6e17019992fd3b5348600c5bbb029a462a1f3900c021d934c6aef19",
"vectors/dk1.json": "767e14f10c72efe335b52baf18129a79fe0e33d8f118ed92efeb9b78251826ab",
"vectors/head_schema.json": "f6e5901a15bafdc9c5f6879c46a9c784a50ad23730ce09390475f2c95a6c04d9",
"vectors/inspect_differential.json": "f4215d4ffff091f09ee9bc056a761898d059e073286e4d95841868e447c72e37",
"vectors/mutations.json": "6550d80c4de1e0e72ed5c78be773eb9e101a7e29e42c4ef338723ce0e97500c2",
"vectors/padding.json": "2396fc02db96857de9cdb054ea22b898ab2cda964960d1a00761706a59998f6f",
"vectors/path_fold.json": "bdfad44d28076a48418d9ab18c7f001fd7adc2e27f70330c3d285a779ce58c7d",
"vectors/paths.json": "e8ad92847ded09d4f67c61477dd8403864d04f54a15af6bd7203b514eb342dc2",
"vectors/profile_quicknet.json": "6e67ac8956295229fe1bbe639877c89f4bb4d06b769ff8c0c4c0e186f1b6570b",
"vectors/quicknet_rounds.json": "c1a4c7d9240d438c770cb386c489409b05029df4185a617ff65555128fb4c830",
"vectors/security.json": "425ae16dfd95b9c1eb4f911db6232b6a6e3b29d9f3ea14fecbf1bda9d900957d",
"vectors/tlock_ibe.json": "4f2eb44f3b46387afc35cd92c556ae4c584b7e3aed1cbe53df730b0b07e0a40c"
"vectors/cbor.json": "79d750994eafc4fa718b0997fbb0a70673dc08a129efcd7d0ddc2db922406913",
"vectors/dk1.json": "f5547be887d6ca405518636925018fdec22a5027009651705b07aec80151314a",
"vectors/ed25519_strict.json": "342d866584435b291832d34deb9ce17aef10d99db148b85443e39e9bed321d0a",
"vectors/head_schema.json": "3c7bcf57aa22943cd17005ea9ce426c0b3e7c365a0527a790b5e9e1973f9753f",
"vectors/inspect_differential.json": "e8c99d025ec761690e71ee0c6adfcfd5b680cdcb89024463d8ebbc24be6b0774",
"vectors/locator.json": "a378453dadbafad4c18b5d9fdf4e49cd69f391e08cf16a04935c446395a9767f",
"vectors/mutations.json": "bd2f86fc13d50acd759acf36374df513687566bfdc5b391759c2040a0d796fb3",
"vectors/padding.json": "53d71fc9679d6eda3ba7b7a15752927a1a5fe026bdbd7f93b0ce3569a6a4b22a",
"vectors/path_fold.json": "94c708bf04379984326f786ba1a954a94dc958fa06013c525e7f7a2c14f856bc",
"vectors/paths.json": "3466da7dd82d82c1c43fe956eb91e674065d159c9326e3bc0dcbbe2c6b774251",
"vectors/profile_quicknet.json": "c15ecb111635ecae2084da8511efbee133e97ff07c1c951658b036ce05b69781",
"vectors/quicknet_rounds.json": "0f11bf5c5da88b1e929bb39439001a3a1f8447a85a4b3a25296d40d71a261e50",
"vectors/security.json": "c5c7a0a508daf6a56ee0d2a9a3c1982e8b2d5104621fb78e768bb2a69e5c4c85",
"vectors/security_cms.json": "c29458496bf58ad01514d7d0e0c2a3223a2a95a81d8c426ce642827363b43b68",
"vectors/tlock_ibe.json": "27e9d9ebac4f07700661d2b4c524b10d065c9698e9acc68baa3d2c01bdbb24f2"
}
}

@ -1,6 +1,6 @@
{
"description": "time_only capsule with an empty payload",
"spec": "0.10",
"spec": "0.11",
"format": 1,
"file": "empty_payload.dkc",
"sha256": "871e9bf05b52bbae17f3adfbbf97b46e7f0e53aa8f57bcaa506e43f36f53a9d4",

@ -1,6 +1,6 @@
{
"description": "format 2 time_only capsule with an empty content: L = 0, P = 256",
"spec": "0.10",
"spec": "0.11",
"format": 2,
"file": "format2_empty_payload.dkc",
"sha256": "7aea2b5aa48b1a46053716f733d50fab9cd0b80b1be67631bcc06c5bb765dc21",

@ -1,6 +1,6 @@
{
"description": "portable X25519 .dkk of format2_time_and_key_portable.dkc",
"spec": "0.10",
"spec": "0.11",
"file": "format2_time_and_key_portable.dkk",
"sha256": "095b7bc516a22bf0c2366f0af3cd48bfe857a2354d6e2a9b285278b95e450fe0",
"credential_id": "e3c7be83cbf1fbd6b115c96411b3bd01",

@ -1,6 +1,6 @@
{
"description": "format 2 time_and_key capsule with one credential, a portable .dkk, and 15 dummies",
"spec": "0.10",
"spec": "0.11",
"format": 2,
"file": "format2_time_and_key_portable.dkc",
"sha256": "600892659fe4890223e895876275f656995d170fda42b07fb2bec0ca51ce4b43",

@ -1,6 +1,6 @@
{
"description": "portable X25519 .dkk of format2_time_and_key_recipients.dkc",
"spec": "0.10",
"spec": "0.11",
"file": "format2_time_and_key_recipients.dkk",
"sha256": "2ad99b1556086ec311d7f0b3bd3aaba05e75f45c4fa22490b0d5e8bb0b1a222e",
"credential_id": "93cedf68421710e83908ec683b104436",

@ -1,6 +1,6 @@
{
"description": "format 2 time_and_key capsule for three known X25519 recipients and a portable .dkk, and 12 dummies",
"spec": "0.10",
"spec": "0.11",
"format": 2,
"file": "format2_time_and_key_recipients.dkc",
"sha256": "1a44fd8708c92e2e0a10cfcb1d864a71331ea9af25d97e1a42e969dc898959e3",

@ -1,6 +1,6 @@
{
"description": "format 2 time_and_key capsule for sixteen known X25519 recipients, without dummies",
"spec": "0.10",
"spec": "0.11",
"format": 2,
"file": "format2_time_and_key_sixteen.dkc",
"sha256": "7aaac5c18f216bf53df326ecc817179640a53408cf25dfd50488910a762dc381",

@ -1,6 +1,6 @@
{
"description": "format 2 time_only capsule, padding code 2 (reforzado): L = 78000, P = 79872, two STREAM chunks",
"spec": "0.10",
"spec": "0.11",
"format": 2,
"file": "format2_time_only.dkc",
"sha256": "f5a40ac6b8a08a0c12db6114c2bca23522d6a77b512b509a217fb15f367813c4",

@ -1,6 +1,6 @@
{
"description": "format 2 time_only capsule with the content of format2_time_only and padding code 1 (bloque256): L = 78000, P = 78080",
"spec": "0.10",
"spec": "0.11",
"format": 2,
"file": "format2_time_only_bloque256.dkc",
"sha256": "aae769c30d04920801d8b293d30864fbe223c9c9353ec2b4907a1ee1996e39f9",

@ -1,6 +1,6 @@
{
"description": "format 2 time_only capsule with a noncritical PUBLIC_HEADER extension and a noncritical CONTROL_CBOR extension",
"spec": "0.10",
"spec": "0.11",
"format": 2,
"file": "format2_time_only_extensions.dkc",
"sha256": "fb406100d5703a2e888983b3175ed34a09a34469cc722256e5cf535dd728fbe9",

@ -1,6 +1,6 @@
{
"description": "format 3 time_only capsule with a security area of 1024 bytes, as a later version may write it, holding the empty security",
"spec": "0.10",
"spec": "0.11",
"format": 3,
"file": "format3_area_1024.dkc",
"sha256": "41ea2eed0293e4fef7f4a307b7f16aaf1339f5bf6f4ded7a6a9ae1aebeb0133c",

@ -1,6 +1,6 @@
{
"description": "format 3 time_only capsule with padding code 1 (bloque256) and one file of 20000 bytes",
"spec": "0.10",
"spec": "0.11",
"format": 3,
"file": "format3_bloque256.dkc",
"sha256": "ff18444f434164ba8e7b26d38c76c7855dc6b0593b2fc8b4e9a95dbf9252d55d",

@ -1,6 +1,6 @@
{
"description": "format 3 time_only capsule with a comment of two lines, the second one with a TAB, a declared author and no files",
"spec": "0.10",
"spec": "0.11",
"format": 3,
"file": "format3_comment_only.dkc",
"sha256": "7f98a89413f08655bbbab28b96585dfa6173c1705dd81a900deba2100d19f2ef",

Binary file not shown.

@ -1,7 +1,7 @@
{
"file": "format3_seal_unsupported.dkc",
"format": 3,
"capsule_id": "48da6a985c7bf92b0fbf2042c36b1039",
"capsule_id": "3517684914fad908ad9e46d7f7b811d5",
"datekey": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MjAwMH0",
"profile": "datekeys:quicknet:v1",
"round": 2000,
@ -31,7 +31,7 @@
"step": 4,
"name": "header validation",
"ok": true,
"detail": "capsule_id=48da6a985c7bf92b0fbf2042c36b1039 datekey=dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MjAwMH0 policy=time_only profile=datekeys:quicknet:v1"
"detail": "capsule_id=3517684914fad908ad9e46d7f7b811d5 datekey=dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MjAwMH0 policy=time_only profile=datekeys:quicknet:v1"
},
{
"step": 5,

@ -1,21 +1,21 @@
{
"description": "format 3 time_only capsule with an author-signature of alg 1, as in format3_signature_unsupported, and a seal of seal_type 1 with a random token of 32 bytes: verdicts F1 and S1",
"spec": "0.10",
"description": "format 3 time_only capsule with an author-signature of alg 4294967295, as in format3_signature_unsupported, and a seal of seal_type 1 with a random token of 32 bytes: verdicts F1 and S1",
"spec": "0.11",
"format": 3,
"file": "format3_seal_unsupported.dkc",
"sha256": "9e729c4d523aa8235c1f94b6c4366500a442a7ce69a5f92b9780662daca070e3",
"sha256": "cd3f68e430c8d41df92a364d65fe29b4aed8ec50e5129595735ede6a8d7df88b",
"release": {
"round": 2000,
"signature": "b6cb8f482a0b15d45936a4c4ea08e98a087e71787caee3f4d07a8a9843b1bc5423c6b3c22f446488b3137eaca799c77e"
},
"prelude": "444b43310300000000000079000001ca",
"public_header": "a5006a646174656b65796361700101025048da6a985c7bf92b0fbf2042c36b1039037853646b315f65794a325a584a7a61573975496a6f784c434a755a58523362334a72496a6f695a4746305a57746c65584d3663585670593274755a585136646a45694c434a79623356755a4349364d6a41774d48300400",
"public_header": "a5006a646174656b6579636170010102503517684914fad908ad9e46d7f7b811d5037853646b315f65794a325a584a7a61573975496a6f784c434a755a58523362334a72496a6f695a4746305a57746c65584d3663585670593274755a585136646a45694c434a79623356755a4349364d6a41774d48300400",
"datekey": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MjAwMH0",
"capsule_id": "48da6a985c7bf92b0fbf2042c36b1039",
"capsule_id": "3517684914fad908ad9e46d7f7b811d5",
"access_policy": "time_only",
"structure": "time_only",
"unlock_at": "2023-08-23T16:49:24Z",
"header_binding": "bc80975e44978cb51465890b4499f591ad0b7af61337bb35b25ad2d1d500b6b3",
"header_binding": "2c34950c31c80b62c31da9aa1ca72cf46d38361a60fdf37519c1f734c6646fb9",
"outer_stanzas": [
{
"type": "tlock",
@ -29,21 +29,21 @@
{
"type": "X25519",
"args": [
"irINIJ7PYPkx0Asd7r+Nw3GfeeEnQc6M1u2QWGBtIyc"
"sfu28SAWdZaPq6c3v4bLopEk8YveD80i8b59V4JMfkM"
]
}
],
"control_cbor": "a60070646174656b6579732d636f6e74726f6c0103025820bc80975e44978cb51465890b4499f591ad0b7af61337bb35b25ad2d1d500b6b303582075b43a62e103df83789f741e0b2cc4b22a15e948d9105902cae0c735bbf9fa86064800000000000002930702",
"payload_identity": "75b43a62e103df83789f741e0b2cc4b22a15e948d9105902cae0c735bbf9fa86",
"control_cbor": "a60070646174656b6579732d636f6e74726f6c01030258202c34950c31c80b62c31da9aa1ca72cf46d38361a60fdf37519c1f734c6646fb9035820a0cae1dd0fb24ae1ea350ad408afa77bb040fe4553ca5a5e6283be84f1775184064800000000000002930702",
"payload_identity": "a0cae1dd0fb24ae1ea350ad408afa77bb040fe4553ca5a5e6283be84f1775184",
"payload_length": 659,
"padding": 2,
"padded_length": 768,
"plaintext_file": "format3_seal_unsupported.plaintext",
"plaintext_sha256": "b7e84ded53528372d35ef5aef5c7935eff5827824832f8556e6ed06eb2951ef5",
"plaintext_sha256": "18e5a8d45af211d036dfe64fc4065c8ada927265200f48a3094aa7ded519b94e",
"area_len": 512,
"security_cbor": "a40071646174656b6579732d73656375726974790101025869a30001015820296414f1ab39ebe5d7f366597d677ee979e2071266a1a9d59fd4688810795bde025840eb7530c2c468fd7d86dd2238551c436a713a978219baec42f7b4763ef2a9f3977d52353e8783875a4ee8d03e504883ff1390be2dde82ac86c182b5a79ad4d624035826a2000101582029bdc2748984e5be979d7c79e6c382cb29cfd8924a645fd8c2446f686700f343",
"head_cbor": "a4006d646174656b6579732d686561640101025820ac66fed2ff62fd1bb417ee393b4476a5694b859e7feceb37aaf6cb49401895400581a600686e6f74612e7478740116020003160458205d596d5f49c179f0ec337f4610155fc237e727f9dee85377a5fce67a3c853510051a6abcf9c0",
"salt": "ac66fed2ff62fd1bb417ee393b4476a5694b859e7feceb37aaf6cb4940189540",
"security_cbor": "a40071646174656b6579732d7365637572697479010102586da3001affffffff0158208beec85fe1db5d53dfa1fa5b95afe208c355a1fabe0d3637c1acc09fef0f04c10258400ccc209b32e7826b70b4befbe7bbe504584631422a3b51086e9491885e8aac6d2a0c92c4c85d6c03750ddaa2d873f6d4dce20030b31669f347ee6b9b4f3abd56035826a20001015820c19dc75c9766f13383b991f54a7cfcb16701ad0299fa68d84c5ce2e82a8f18d7",
"head_cbor": "a4006d646174656b6579732d6865616401010258208eb5e2f0920209323e39c54391a74cc873690cd6d7ce94a45b12772f2a5081c10581a600686e6f74612e7478740116020003160458205d596d5f49c179f0ec337f4610155fc237e727f9dee85377a5fce67a3c853510051a6abcf9c0",
"salt": "8eb5e2f0920209323e39c54391a74cc873690cd6d7ce94a45b12772f2a5081c1",
"content_offset": 637,
"files": [
{

Binary file not shown.

Before

Width:  |  Height:  |  Size: 659 B

After

Width:  |  Height:  |  Size: 659 B

Binary file not shown.

@ -0,0 +1,61 @@
{
"file": "format3_sealed.dkc",
"format": 3,
"capsule_id": "b3d25bb6c74cda4e014c65e3d2f43a69",
"datekey": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMH0",
"profile": "datekeys:quicknet:v1",
"round": 1000,
"unlock_at": "2023-08-23T15:59:24Z",
"access_policy": "time_only",
"valid": true,
"checks": [
{
"step": 1,
"name": "parse DKC1",
"ok": true,
"detail": "magic DKC1"
},
{
"step": 2,
"name": "prelude",
"ok": true,
"detail": "DKC1 v3, PUBLIC_HEADER_LEN=121, SEALED_CONTROL_LEN=458"
},
{
"step": 3,
"name": "public header",
"ok": true,
"detail": "121 bytes"
},
{
"step": 4,
"name": "header validation",
"ok": true,
"detail": "capsule_id=b3d25bb6c74cda4e014c65e3d2f43a69 datekey=dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMH0 policy=time_only profile=datekeys:quicknet:v1"
},
{
"step": 5,
"name": "sealed control structure",
"ok": true,
"detail": "one tlock stanza"
},
{
"step": 6,
"name": "payload structure",
"ok": true,
"detail": "one X25519 stanza"
},
{
"step": 7,
"name": "condition",
"ok": true,
"detail": "round 1000, unlock at 2023-08-23T15:59:24Z"
},
{
"step": 8,
"name": "tlock stanza",
"ok": true,
"detail": "round 1000, chain 52db9ba70e0cc0f6eaf7803dd07447a1f5477735fd3f661792ba94600c84e971"
}
]
}

@ -0,0 +1,173 @@
{
"description": "format 3 time_only capsule with a single file, nota.txt, signed with alg 1 by the test key of format3_signed and sealed with seal_type 2 by a test time-stamping authority before the round time: verdicts F4 and S4, with SEAL_SUBJECT and the token in the record",
"spec": "0.11",
"format": 3,
"file": "format3_sealed.dkc",
"sha256": "dde5a072d8783227d28279d06d3d226a1fb967c766da626f889d1c6fd76ac9c7",
"release": {
"round": 1000,
"signature": "b44679b9a59af2ec876b1a6b1ad52ea9b1615fc3982b19576350f93447cb1125e342b73a8dd2bacbe47e4b6b63ed5e39"
},
"prelude": "444b43310300000000000079000001ca",
"public_header": "a5006a646174656b657963617001010250b3d25bb6c74cda4e014c65e3d2f43a69037853646b315f65794a325a584a7a61573975496a6f784c434a755a58523362334a72496a6f695a4746305a57746c65584d3663585670593274755a585136646a45694c434a79623356755a4349364d5441774d48300400",
"datekey": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMH0",
"capsule_id": "b3d25bb6c74cda4e014c65e3d2f43a69",
"access_policy": "time_only",
"structure": "time_only",
"unlock_at": "2023-08-23T15:59:24Z",
"header_binding": "c108d8b34eb0a4237e6aff192364a28d544cb79c84ac5c80d88c26f8bd5560d8",
"outer_stanzas": [
{
"type": "tlock",
"args": [
"1000",
"52db9ba70e0cc0f6eaf7803dd07447a1f5477735fd3f661792ba94600c84e971"
]
}
],
"payload_stanzas": [
{
"type": "X25519",
"args": [
"PQPwIpsXx8ZNHf1Xpr7gnPamVYWLPgD8zIGmXqvSkjY"
]
}
],
"control_cbor": "a60070646174656b6579732d636f6e74726f6c0103025820c108d8b34eb0a4237e6aff192364a28d544cb79c84ac5c80d88c26f8bd5560d803582087351091f87f94f2c1155e5bde726116123e321f6cc2c3f2bb934298e0d02ea8064800000000000080930702",
"payload_identity": "87351091f87f94f2c1155e5bde726116123e321f6cc2c3f2bb934298e0d02ea8",
"payload_length": 32915,
"padding": 2,
"padded_length": 34816,
"plaintext_file": "format3_sealed.plaintext",
"plaintext_sha256": "aea0f5feb40acd81ca3b02dd21ea15510234da3ab52b374322f3206e7632d47b",
"area_len": 32768,
"security_cbor": "a40071646174656b6579732d73656375726974790101025869a3000101582092d3a82b1e2387a860d57cae4cc55091d43904fdd625e4d2b285e3a1b4ba674002584024c8a0fd4ef7338a2607c1489e33eb32b2d2c6a9438e8d01d5beb04911acd5bdf7eb4bd958141293e5fe4074276097cd0df21d8ca12b9c2e6cb5164304666c060359038ba20002015903843082038006092a864886f70d010702a08203713082036d020101310d300b06096086480165030402013065060b2a864886f70d0109100104a0560454305202010106032a0304302f300b060960864801650304020104201ce5a87549e8bed1af2238888c5a4e942b3b3de1fa8d757c70941cd21522638d02012a180f32303233303832333135303932375a3003020101a08201b8308201b430820159a0030201020208074ecca73c287e79300a06082a8648ce3d040302304131163014060355040a130d446174654b6579732074657374312730250603550403131e4175746f72696461642064652053656c6c61646f20646520707275656261301e170d3230303130313030303030305a170d3430303130313030303030305a304131163014060355040a130d446174654b6579732074657374312730250603550403131e4175746f72696461642064652053656c6c61646f206465207072756562613059301306072a8648ce3d020106082a8648ce3d03010703420004aa2eb21e68c810b6271dadcc25575401ceccac2461de40cb2bfde25bceaa384abbbba098880bf14316b62769b3596d701d60c8dd1f1313f257d93c4d5f213a53a33b3039300e0603551d0f0101ff04040302078030270603551d0e0420041e4175746f72696461642064652053656c6c61646f20646520707275656261300a06082a8648ce3d0403020349003046022100a05f22801b8432108d6330dd777a25bcfdd1b32db72bc8feb9be522291559e11022100cfd71b1445e68079aa98af90ac7037ab938eb7e4f11279f1476a93ce0b693aff3182013430820130020101304d304131163014060355040a130d446174654b6579732074657374312730250603550403131e4175746f72696461642064652053656c6c61646f206465207072756562610208074ecca73c287e79300b0609608648016503040201a07a301a06092a864886f70d010903310d060b2a864886f70d0109100104302b060b2a864886f70d010910020c311c301a30183016041426e0465376bf0d652c266e5940c9d01ba8cea5e9302f06092a864886f70d01090431220420545889d11d3289646f8156538dbcc608e8cc543fa052056a56a85eb7356523f1300a06082a8648ce3d04030204473045022100883cfcc51038245652e767fdfecea1b7153b9158df02d95f3fcfc2b58e575cb1022029b9727ead61a3022bcddd62d704ee26f71de738556d97796de3ce1c408c7419",
"head_cbor": "a4006d646174656b6579732d686561640101025820990d6781941d508558b06652f4c4db8fc56da5a443811b723adfe4370ea139710581a600686e6f74612e7478740116020003160458205d596d5f49c179f0ec337f4610155fc237e727f9dee85377a5fce67a3c853510051a6abcf9c0",
"salt": "990d6781941d508558b06652f4c4db8fc56da5a443811b723adfe4370ea13971",
"content_offset": 32893,
"files": [
{
"path": "nota.txt",
"size": 22,
"start": 0,
"end": 22,
"sha256": "5d596d5f49c179f0ec337f4610155fc237e727f9dee85377a5fce67a3c853510",
"mtime": 1790769600
}
],
"verdicts": {
"signature": "F4",
"seal": "S4",
"lines": [
"Firmado con la clave dkauthor1jtf6s2c7ywr6scx40jhye32sj82rjp8a6cj7f54jsh36rd96vaqqcg54xg. No prueba quién la tiene.",
"Según un sello a nombre de Autoridad de Sellado de prueba, existía el 2023-08-23T15:09:27Z, antes de que la cápsula pudiera abrirse. DateKeys no comprueba quién emitió el sello."
],
"author_key": "dkauthor1jtf6s2c7ywr6scx40jhye32sj82rjp8a6cj7f54jsh36rd96vaqqcg54xg"
},
"signature": {
"alg": 1,
"secret_seed": "294b60d256e79fc4c18b4bcc0a156810b44144619969dadedcbf01d3b37c1054",
"author_key": "dkauthor1jtf6s2c7ywr6scx40jhye32sj82rjp8a6cj7f54jsh36rd96vaqqcg54xg",
"control_commit": "1793cc0adaba31bdbf18cb4c97ba86dcff05bec498c8ecf11668a74bfd71718a",
"head_digest": "a5537946c281a8e22ca9d3a4deb1aebcddf0d299abe47bded31c90157dd72d3a",
"signers_digest": "1665c6f3f1afb37b1a87d87e4265f156d7108c3c1762972d2a4241e6e5ab824e",
"author_message": "datekeys:dkc3:author-signature:v1\n111b174e204e0eaa73b87601e1e1d9b3d60799b5a0a5c0e371a9dc65d1d39f38\n",
"author_code": "111b-174e",
"signature": "24c8a0fd4ef7338a2607c1489e33eb32b2d2c6a9438e8d01d5beb04911acd5bdf7eb4bd958141293e5fe4074276097cd0df21d8ca12b9c2e6cb5164304666c06",
"security_key_2": "a3000101582092d3a82b1e2387a860d57cae4cc55091d43904fdd625e4d2b285e3a1b4ba674002584024c8a0fd4ef7338a2607c1489e33eb32b2d2c6a9438e8d01d5beb04911acd5bdf7eb4bd958141293e5fe4074276097cd0df21d8ca12b9c2e6cb5164304666c06"
},
"seal": {
"seal_type": 2,
"seal_subject": "8e60fd12a9475d95f77adacf81772774f4a8f508ffc7edda2e15df9ccebf163e",
"token": "3082038006092a864886f70d010702a08203713082036d020101310d300b06096086480165030402013065060b2a864886f70d0109100104a0560454305202010106032a0304302f300b060960864801650304020104201ce5a87549e8bed1af2238888c5a4e942b3b3de1fa8d757c70941cd21522638d02012a180f32303233303832333135303932375a3003020101a08201b8308201b430820159a0030201020208074ecca73c287e79300a06082a8648ce3d040302304131163014060355040a130d446174654b6579732074657374312730250603550403131e4175746f72696461642064652053656c6c61646f20646520707275656261301e170d3230303130313030303030305a170d3430303130313030303030305a304131163014060355040a130d446174654b6579732074657374312730250603550403131e4175746f72696461642064652053656c6c61646f206465207072756562613059301306072a8648ce3d020106082a8648ce3d03010703420004aa2eb21e68c810b6271dadcc25575401ceccac2461de40cb2bfde25bceaa384abbbba098880bf14316b62769b3596d701d60c8dd1f1313f257d93c4d5f213a53a33b3039300e0603551d0f0101ff04040302078030270603551d0e0420041e4175746f72696461642064652053656c6c61646f20646520707275656261300a06082a8648ce3d0403020349003046022100a05f22801b8432108d6330dd777a25bcfdd1b32db72bc8feb9be522291559e11022100cfd71b1445e68079aa98af90ac7037ab938eb7e4f11279f1476a93ce0b693aff3182013430820130020101304d304131163014060355040a130d446174654b6579732074657374312730250603550403131e4175746f72696461642064652053656c6c61646f206465207072756562610208074ecca73c287e79300b0609608648016503040201a07a301a06092a864886f70d010903310d060b2a864886f70d0109100104302b060b2a864886f70d010910020c311c301a30183016041426e0465376bf0d652c266e5940c9d01ba8cea5e9302f06092a864886f70d01090431220420545889d11d3289646f8156538dbcc608e8cc543fa052056a56a85eb7356523f1300a06082a8648ce3d04030204473045022100883cfcc51038245652e767fdfecea1b7153b9158df02d95f3fcfc2b58e575cb1022029b9727ead61a3022bcddd62d704ee26f71de738556d97796de3ce1c408c7419",
"holder": "Autoridad de Sellado de prueba",
"time": "2023-08-23T15:09:27Z"
},
"stages": [
{
"step": 1,
"name": "parse DKC1",
"ok": true
},
{
"step": 2,
"name": "prelude",
"ok": true
},
{
"step": 3,
"name": "public header",
"ok": true
},
{
"step": 4,
"name": "header validation",
"ok": true
},
{
"step": 5,
"name": "sealed control structure",
"ok": true
},
{
"step": 6,
"name": "payload structure",
"ok": true
},
{
"step": 7,
"name": "condition",
"ok": true
},
{
"step": 8,
"name": "tlock stanza",
"ok": true
},
{
"step": 9,
"name": "release",
"ok": true
},
{
"step": 10,
"name": "release verification",
"ok": true
},
{
"step": 11,
"name": "open sealed control",
"ok": true
},
{
"step": 12,
"name": "policy structure",
"ok": true
},
{
"step": 14,
"name": "control",
"ok": true
},
{
"step": 15,
"name": "header binding",
"ok": true
},
{
"step": 16,
"name": "payload identity",
"ok": true
},
{
"step": 17,
"name": "open payload",
"ok": true
},
{
"step": 18,
"name": "commit",
"ok": true
}
]
}

Binary file not shown.

@ -1,6 +1,6 @@
{
"description": "format 3 time_only capsule whose security is of version 2: verdict X",
"spec": "0.10",
"spec": "0.11",
"format": 3,
"file": "format3_security_v2.dkc",
"sha256": "3d02b39ace010d74604554e378d22fe5ce00cecd998c0f797d657b17620b8912",

@ -1,7 +1,7 @@
{
"file": "format3_signature_unsupported.dkc",
"format": 3,
"capsule_id": "d2296b10c37ba96cd7cf2af7f1b95717",
"capsule_id": "a6bf56d5084eb0054779492620b8af34",
"datekey": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMX0",
"profile": "datekeys:quicknet:v1",
"round": 1001,
@ -31,7 +31,7 @@
"step": 4,
"name": "header validation",
"ok": true,
"detail": "capsule_id=d2296b10c37ba96cd7cf2af7f1b95717 datekey=dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMX0 policy=time_only profile=datekeys:quicknet:v1"
"detail": "capsule_id=a6bf56d5084eb0054779492620b8af34 datekey=dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMX0 policy=time_only profile=datekeys:quicknet:v1"
},
{
"step": 5,

@ -1,21 +1,21 @@
{
"description": "format 3 time_only capsule with an author-signature of alg 1, a random key of 32 bytes and a random signature of 64: verdicts F1 and S0",
"spec": "0.10",
"description": "format 3 time_only capsule with an author-signature of alg 4294967295, a random key of 32 bytes and a random signature of 64: verdicts F1 and S0",
"spec": "0.11",
"format": 3,
"file": "format3_signature_unsupported.dkc",
"sha256": "83dc0f3b71cd57f2c06b5ea5860c1fd709627c2ab11c86ca1fc3b5a16d89c497",
"sha256": "e8e3106d8d73bb7b845062e0fe42af21df7d7cd8f63c335cab8dedb3e690df31",
"release": {
"round": 1001,
"signature": "b33bf3667cbd5a82de3a24b4e0e9fe5513cc1a0e840368c6e31f5fcfa79bea03f73896b25883abf2853d10337fb8fa41"
},
"prelude": "444b43310300000000000079000001ca",
"public_header": "a5006a646174656b657963617001010250d2296b10c37ba96cd7cf2af7f1b95717037853646b315f65794a325a584a7a61573975496a6f784c434a755a58523362334a72496a6f695a4746305a57746c65584d3663585670593274755a585136646a45694c434a79623356755a4349364d5441774d58300400",
"public_header": "a5006a646174656b657963617001010250a6bf56d5084eb0054779492620b8af34037853646b315f65794a325a584a7a61573975496a6f784c434a755a58523362334a72496a6f695a4746305a57746c65584d3663585670593274755a585136646a45694c434a79623356755a4349364d5441774d58300400",
"datekey": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMX0",
"capsule_id": "d2296b10c37ba96cd7cf2af7f1b95717",
"capsule_id": "a6bf56d5084eb0054779492620b8af34",
"access_policy": "time_only",
"structure": "time_only",
"unlock_at": "2023-08-23T15:59:27Z",
"header_binding": "fdb39427d6f10d3ad89a81161fa1f65293c73291a45d18ca139e6d12a44f919e",
"header_binding": "bc6877680d44462fd92546d3f82eeaea2234505721c3b588dd7676a2eb7fc7a7",
"outer_stanzas": [
{
"type": "tlock",
@ -29,21 +29,21 @@
{
"type": "X25519",
"args": [
"6nefFx+947eX7B7qEcU6R9btIgMg69ldm+3OS6hOPns"
"qxmJwwotwDawKgsGMI+wJv5XlldCGOUP4qutXZJbQ20"
]
}
],
"control_cbor": "a60070646174656b6579732d636f6e74726f6c0103025820fdb39427d6f10d3ad89a81161fa1f65293c73291a45d18ca139e6d12a44f919e035820ba8f5da6c9464c35f9680be7a7948bc6d61522ccba72123cc5a187b248673132064800000000000002930702",
"payload_identity": "ba8f5da6c9464c35f9680be7a7948bc6d61522ccba72123cc5a187b248673132",
"control_cbor": "a60070646174656b6579732d636f6e74726f6c0103025820bc6877680d44462fd92546d3f82eeaea2234505721c3b588dd7676a2eb7fc7a70358200d50b7c8f4aa63f49c590f417b410dc3c71941e6827f407ee7921c99aba3ccdd064800000000000002930702",
"payload_identity": "0d50b7c8f4aa63f49c590f417b410dc3c71941e6827f407ee7921c99aba3ccdd",
"payload_length": 659,
"padding": 2,
"padded_length": 768,
"plaintext_file": "format3_signature_unsupported.plaintext",
"plaintext_sha256": "414deeb8dc9f45fcf5f3883154e9f0e5a872ee9438a01b997d2f513b3d5a1eb7",
"plaintext_sha256": "9fe05e6b3a463371b33fc6a81b81d538e572789a8d03ace9f752a931f4ca4728",
"area_len": 512,
"security_cbor": "a30071646174656b6579732d73656375726974790101025869a30001015820dd7f33121df820b64504dcb4f63133fbf7fefc26b9a79cdc83000540d8b3c35d025840a9717fe754465361c6d1a9a781628d8c11eda5a46b4a80f574328fa2a9d566a9923a4a796e3c52fdefa05daea4f135a4a4b73206f52643396aee6bfd29558f97",
"head_cbor": "a4006d646174656b6579732d6865616401010258206dd3b33fb1a390aa6d63404a29b677aec03285f97da6625a3a3ecae612f9d94e0581a600686e6f74612e7478740116020003160458205d596d5f49c179f0ec337f4610155fc237e727f9dee85377a5fce67a3c853510051a6abcf9c0",
"salt": "6dd3b33fb1a390aa6d63404a29b677aec03285f97da6625a3a3ecae612f9d94e",
"security_cbor": "a30071646174656b6579732d7365637572697479010102586da3001affffffff015820da2a88c336770633057e3b53daed5bc074fc8dc1679bc43eb6a173e3ef10a93102584053c88f03105b77470a999d92a268c7964be74ae856ba87a6cf6756ccae09631d0e971d3356bf39862540dd11476fc98e4fc75686dcd43742f0f6ea0105f4e47e",
"head_cbor": "a4006d646174656b6579732d686561640101025820e5e946ad436f63f659a1660ab7022355f4724d593e55766ec571776d73e3a6520581a600686e6f74612e7478740116020003160458205d596d5f49c179f0ec337f4610155fc237e727f9dee85377a5fce67a3c853510051a6abcf9c0",
"salt": "e5e946ad436f63f659a1660ab7022355f4724d593e55766ec571776d73e3a652",
"content_offset": 637,
"files": [
{

Binary file not shown.

Before

Width:  |  Height:  |  Size: 659 B

After

Width:  |  Height:  |  Size: 659 B

Binary file not shown.

@ -0,0 +1,61 @@
{
"file": "format3_signed.dkc",
"format": 3,
"capsule_id": "681476c1bfa81dd12fec810ee44fe7f7",
"datekey": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMH0",
"profile": "datekeys:quicknet:v1",
"round": 1000,
"unlock_at": "2023-08-23T15:59:24Z",
"access_policy": "time_only",
"valid": true,
"checks": [
{
"step": 1,
"name": "parse DKC1",
"ok": true,
"detail": "magic DKC1"
},
{
"step": 2,
"name": "prelude",
"ok": true,
"detail": "DKC1 v3, PUBLIC_HEADER_LEN=121, SEALED_CONTROL_LEN=458"
},
{
"step": 3,
"name": "public header",
"ok": true,
"detail": "121 bytes"
},
{
"step": 4,
"name": "header validation",
"ok": true,
"detail": "capsule_id=681476c1bfa81dd12fec810ee44fe7f7 datekey=dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMH0 policy=time_only profile=datekeys:quicknet:v1"
},
{
"step": 5,
"name": "sealed control structure",
"ok": true,
"detail": "one tlock stanza"
},
{
"step": 6,
"name": "payload structure",
"ok": true,
"detail": "one X25519 stanza"
},
{
"step": 7,
"name": "condition",
"ok": true,
"detail": "round 1000, unlock at 2023-08-23T15:59:24Z"
},
{
"step": 8,
"name": "tlock stanza",
"ok": true,
"detail": "round 1000, chain 52db9ba70e0cc0f6eaf7803dd07447a1f5477735fd3f661792ba94600c84e971"
}
]
}

@ -0,0 +1,165 @@
{
"description": "format 3 time_only capsule with a single file, nota.txt, signed with alg 1 by a test key whose seed the record gives: verdict F4, and the commitments and the message of the signature",
"spec": "0.11",
"format": 3,
"file": "format3_signed.dkc",
"sha256": "3c7d3c9e24c02853a0c7761b93bea1120b27fce396468d8d0f68e53aeb668c5e",
"release": {
"round": 1000,
"signature": "b44679b9a59af2ec876b1a6b1ad52ea9b1615fc3982b19576350f93447cb1125e342b73a8dd2bacbe47e4b6b63ed5e39"
},
"prelude": "444b43310300000000000079000001ca",
"public_header": "a5006a646174656b657963617001010250681476c1bfa81dd12fec810ee44fe7f7037853646b315f65794a325a584a7a61573975496a6f784c434a755a58523362334a72496a6f695a4746305a57746c65584d3663585670593274755a585136646a45694c434a79623356755a4349364d5441774d48300400",
"datekey": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMH0",
"capsule_id": "681476c1bfa81dd12fec810ee44fe7f7",
"access_policy": "time_only",
"structure": "time_only",
"unlock_at": "2023-08-23T15:59:24Z",
"header_binding": "10c269d7fcc8ae1f92c9854b8d01b23781fd6c615474c018b5e75c8620d476eb",
"outer_stanzas": [
{
"type": "tlock",
"args": [
"1000",
"52db9ba70e0cc0f6eaf7803dd07447a1f5477735fd3f661792ba94600c84e971"
]
}
],
"payload_stanzas": [
{
"type": "X25519",
"args": [
"TO8ryXIRUX0S1odrqs9IZJ43q7yYotzn/fMycGebKGQ"
]
}
],
"control_cbor": "a60070646174656b6579732d636f6e74726f6c010302582010c269d7fcc8ae1f92c9854b8d01b23781fd6c615474c018b5e75c8620d476eb0358203ffe484f443014980f2b2ee8bb66095f6ea418d4c2fce2ae6ad74c550bbefc21064800000000000080930702",
"payload_identity": "3ffe484f443014980f2b2ee8bb66095f6ea418d4c2fce2ae6ad74c550bbefc21",
"payload_length": 32915,
"padding": 2,
"padded_length": 34816,
"plaintext_file": "format3_signed.plaintext",
"plaintext_sha256": "3de3ccab0ac74f95a76aa45c0f85e1749d4b4a051d87e81828eff6bf24372000",
"area_len": 32768,
"security_cbor": "a30071646174656b6579732d73656375726974790101025869a3000101582092d3a82b1e2387a860d57cae4cc55091d43904fdd625e4d2b285e3a1b4ba67400258406f8efe0dfadaf89bf71295167f8d8cc4890de0441a37a26d1f7d0b1f56b79c43c4010861e11742a5431b072b21490d4a976dc9ff385d36242047ad4cb996270b",
"head_cbor": "a4006d646174656b6579732d68656164010102582092a0fe390ff1063d9e93bbafe3ca75be219d950128e2e5aca6a9c12d5c1f1c9b0581a600686e6f74612e7478740116020003160458205d596d5f49c179f0ec337f4610155fc237e727f9dee85377a5fce67a3c853510051a6abcf9c0",
"salt": "92a0fe390ff1063d9e93bbafe3ca75be219d950128e2e5aca6a9c12d5c1f1c9b",
"content_offset": 32893,
"files": [
{
"path": "nota.txt",
"size": 22,
"start": 0,
"end": 22,
"sha256": "5d596d5f49c179f0ec337f4610155fc237e727f9dee85377a5fce67a3c853510",
"mtime": 1790769600
}
],
"verdicts": {
"signature": "F4",
"seal": "S0",
"lines": [
"Firmado con la clave dkauthor1jtf6s2c7ywr6scx40jhye32sj82rjp8a6cj7f54jsh36rd96vaqqcg54xg. No prueba quién la tiene."
],
"author_key": "dkauthor1jtf6s2c7ywr6scx40jhye32sj82rjp8a6cj7f54jsh36rd96vaqqcg54xg"
},
"signature": {
"alg": 1,
"secret_seed": "294b60d256e79fc4c18b4bcc0a156810b44144619969dadedcbf01d3b37c1054",
"author_key": "dkauthor1jtf6s2c7ywr6scx40jhye32sj82rjp8a6cj7f54jsh36rd96vaqqcg54xg",
"control_commit": "9f296b40049889c944be75c61827b694a0104eb5c5424e17217ff1fd32529efe",
"head_digest": "0111835cdde5ef15710cea96fc600757e1695ddc8f44b2b20e57eead31278b92",
"signers_digest": "1665c6f3f1afb37b1a87d87e4265f156d7108c3c1762972d2a4241e6e5ab824e",
"author_message": "datekeys:dkc3:author-signature:v1\n58aedcded250af5f798eeace817f8a5bbd0c245d05627949970b5eb998bb0413\n",
"author_code": "58ae-dcde",
"signature": "6f8efe0dfadaf89bf71295167f8d8cc4890de0441a37a26d1f7d0b1f56b79c43c4010861e11742a5431b072b21490d4a976dc9ff385d36242047ad4cb996270b",
"security_key_2": "a3000101582092d3a82b1e2387a860d57cae4cc55091d43904fdd625e4d2b285e3a1b4ba67400258406f8efe0dfadaf89bf71295167f8d8cc4890de0441a37a26d1f7d0b1f56b79c43c4010861e11742a5431b072b21490d4a976dc9ff385d36242047ad4cb996270b"
},
"stages": [
{
"step": 1,
"name": "parse DKC1",
"ok": true
},
{
"step": 2,
"name": "prelude",
"ok": true
},
{
"step": 3,
"name": "public header",
"ok": true
},
{
"step": 4,
"name": "header validation",
"ok": true
},
{
"step": 5,
"name": "sealed control structure",
"ok": true
},
{
"step": 6,
"name": "payload structure",
"ok": true
},
{
"step": 7,
"name": "condition",
"ok": true
},
{
"step": 8,
"name": "tlock stanza",
"ok": true
},
{
"step": 9,
"name": "release",
"ok": true
},
{
"step": 10,
"name": "release verification",
"ok": true
},
{
"step": 11,
"name": "open sealed control",
"ok": true
},
{
"step": 12,
"name": "policy structure",
"ok": true
},
{
"step": 14,
"name": "control",
"ok": true
},
{
"step": 15,
"name": "header binding",
"ok": true
},
{
"step": 16,
"name": "payload identity",
"ok": true
},
{
"step": 17,
"name": "open payload",
"ok": true
},
{
"step": 18,
"name": "commit",
"ok": true
}
]
}

Binary file not shown.

Binary file not shown.

@ -0,0 +1,61 @@
{
"file": "format3_signed_cms.dkc",
"format": 3,
"capsule_id": "fb1b4917149f996c9c9561997593d37d",
"datekey": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMH0",
"profile": "datekeys:quicknet:v1",
"round": 1000,
"unlock_at": "2023-08-23T15:59:24Z",
"access_policy": "time_only",
"valid": true,
"checks": [
{
"step": 1,
"name": "parse DKC1",
"ok": true,
"detail": "magic DKC1"
},
{
"step": 2,
"name": "prelude",
"ok": true,
"detail": "DKC1 v3, PUBLIC_HEADER_LEN=121, SEALED_CONTROL_LEN=458"
},
{
"step": 3,
"name": "public header",
"ok": true,
"detail": "121 bytes"
},
{
"step": 4,
"name": "header validation",
"ok": true,
"detail": "capsule_id=fb1b4917149f996c9c9561997593d37d datekey=dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMH0 policy=time_only profile=datekeys:quicknet:v1"
},
{
"step": 5,
"name": "sealed control structure",
"ok": true,
"detail": "one tlock stanza"
},
{
"step": 6,
"name": "payload structure",
"ok": true,
"detail": "one X25519 stanza"
},
{
"step": 7,
"name": "condition",
"ok": true,
"detail": "round 1000, unlock at 2023-08-23T15:59:24Z"
},
{
"step": 8,
"name": "tlock stanza",
"ok": true,
"detail": "round 1000, chain 52db9ba70e0cc0f6eaf7803dd07447a1f5477735fd3f661792ba94600c84e971"
}
]
}

File diff suppressed because one or more lines are too long

Binary file not shown.

@ -1,6 +1,6 @@
{
"description": "format 3 time_only capsule with a single file, nota.txt, with its mtime",
"spec": "0.10",
"spec": "0.11",
"format": 3,
"file": "format3_single.dkc",
"sha256": "9f68664af8733255084be9036a100b75d27bd16106bf0acff94ce469dd1d1743",

@ -1,6 +1,6 @@
{
"description": "portable X25519 .dkk of format3_time_and_key_portable.dkc",
"spec": "0.10",
"spec": "0.11",
"file": "format3_time_and_key_portable.dkk",
"sha256": "54cc64d849395234b3e093e47f432b72781ccc13f455c9ef394e3554ab566751",
"credential_id": "bdb483fba42daf0b409f44d23033f362",

@ -1,6 +1,6 @@
{
"description": "format 3 time_and_key capsule with one credential, a portable .dkk, and 15 dummies",
"spec": "0.10",
"spec": "0.11",
"format": 3,
"file": "format3_time_and_key_portable.dkc",
"sha256": "680d29962e575689a31543df28433dae7737abd9a793e9cae92ef40920d09636",

@ -1,6 +1,6 @@
{
"description": "format 3 time_only capsule with five files in three folders, one of them over two STREAM chunks and one without mtime, a comment of two lines and a declared author",
"spec": "0.10",
"spec": "0.11",
"format": 3,
"file": "format3_tree.dkc",
"sha256": "217f378faaf795f6a9c416b564fb8931bb2e896918aee870120fd14f9a5da7d1",

@ -1,6 +1,6 @@
{
"description": "portable X25519 .dkk of time_and_key_portable.dkc",
"spec": "0.10",
"spec": "0.11",
"file": "time_and_key_portable.dkk",
"sha256": "e528fa2c832c91119f0684bb9d6fb3c4c2d0d55183482890e7c4fe92f668426a",
"credential_id": "3955e944a3c60cfa1fd6485e9693c77d",

@ -1,6 +1,6 @@
{
"description": "time_and_key capsule whose only recipient is a portable .dkk",
"spec": "0.10",
"spec": "0.11",
"format": 1,
"file": "time_and_key_portable.dkc",
"sha256": "2e97878078bae6358037a9c264f379a3cbe839f767d69836b0343f35657b2972",

@ -1,6 +1,6 @@
{
"description": "portable X25519 .dkk of time_and_key_portable.dkc with a noncritical extension: the credential of time_and_key_portable.dkk re-issued with org.example.delivery",
"spec": "0.10",
"spec": "0.11",
"file": "time_and_key_portable_extension.dkk",
"sha256": "0bf463a7c65627b7dda2234d728df89ec5b835816a2a37b91497d8fecc5ea548",
"credential_id": "3955e944a3c60cfa1fd6485e9693c77d",

@ -1,6 +1,6 @@
{
"description": "portable X25519 .dkk of time_and_key_recipients.dkc",
"spec": "0.10",
"spec": "0.11",
"file": "time_and_key_recipients.dkk",
"sha256": "19f6c47150c3194712d454f43c7392b7344e6b4e7b074d83e9ca5f563a8e072f",
"credential_id": "b89292aedf6d05d584cec9a871ce8735",

@ -1,6 +1,6 @@
{
"description": "time_and_key capsule for two known X25519 recipients and a portable .dkk",
"spec": "0.10",
"spec": "0.11",
"format": 1,
"file": "time_and_key_recipients.dkc",
"sha256": "69ac110380f5d768b5b6afaa157a50ed17d8ceccfbd4604ffa5b6da38539b635",

@ -1,6 +1,6 @@
{
"description": "time_only capsule, two STREAM chunks, no extensions",
"spec": "0.10",
"spec": "0.11",
"format": 1,
"file": "time_only.dkc",
"sha256": "99e915810d595f1092700b728f5e5081d78efe83f5343e76325b1bcc2c33ccf2",

@ -1,6 +1,6 @@
{
"description": "time_only capsule with a noncritical PUBLIC_HEADER extension and a noncritical CONTROL_CBOR extension",
"spec": "0.10",
"spec": "0.11",
"format": 1,
"file": "time_only_extensions.dkc",
"sha256": "0446c9b73e267adcb24e5cc89afba2544a386ec9a050016e06517a4a57aa2085",

@ -1,5 +1,5 @@
{
"spec": "0.10",
"spec": "0.11",
"description": "CBOR profile of spec §58 and the schemas of spec/datekeys.cddl, generated by the reference implementation. accept and reject are walked as one data item of the profile with the limits of walk; schemas are decoded with the decoder of their schema. See testdata/README.md.",
"walk": {
"max_depth": 3,

@ -1,5 +1,5 @@
{
"spec": "0.10",
"spec": "0.11",
"description": "Canonical dk1_ strings and rejected encodings (spec §18, §19, §66), generated by the reference implementation.",
"vectors": [
{

@ -0,0 +1,150 @@
{
"spec": "0.11",
"description": "Ed25519 signatures and the result of the strict profile of the author signature (spec v0.11, §29.9), after the cases of «Taming the many EdDSAs»; stdlib is the result of crypto/ed25519 of Go, for the record. Generated by the reference implementation. See testdata/README.md.",
"vectors": [
{
"name": "a valid signature",
"message": "446174654b657973",
"public_key": "10770005d22145b75334902d3dbd10491a6f210afa80d3937d761a56c308d5ea",
"signature": "5119b0822de6d25331d7c21c528f4945b8b77253241cc6b83c16ba265409ff0f1fdd979c37e18f4bd6bc9c1c18d4b8746ffdee1ce723e404feb1ca90288c3900",
"valid": true,
"stdlib": true
},
{
"name": "S + ℓ",
"message": "446174654b657973",
"public_key": "10770005d22145b75334902d3dbd10491a6f210afa80d3937d761a56c308d5ea",
"signature": "5119b0822de6d25331d7c21c528f4945b8b77253241cc6b83c16ba265409ff0f0cb18df95144a2a3ac5994bff6cd97896ffdee1ce723e404feb1ca90288c3910",
"valid": false,
"stdlib": false
},
{
"name": "S with bit 253 set",
"message": "446174654b657973",
"public_key": "10770005d22145b75334902d3dbd10491a6f210afa80d3937d761a56c308d5ea",
"signature": "5119b0822de6d25331d7c21c528f4945b8b77253241cc6b83c16ba265409ff0f1fdd979c37e18f4bd6bc9c1c18d4b8746ffdee1ce723e404feb1ca90288c3920",
"valid": false,
"stdlib": false
},
{
"name": "R not canonical",
"message": "446174654b657973",
"public_key": "10770005d22145b75334902d3dbd10491a6f210afa80d3937d761a56c308d5ea",
"signature": "edffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f1fdd979c37e18f4bd6bc9c1c18d4b8746ffdee1ce723e404feb1ca90288c3900",
"valid": false,
"stdlib": false
},
{
"name": "A of small order, the point 0 of the torsion, R the identity and S = 0",
"message": "446174654b657973200000000000000002",
"public_key": "0100000000000000000000000000000000000000000000000000000000000000",
"signature": "01000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
"valid": false,
"stdlib": true
},
{
"name": "A of small order, the point 1 of the torsion, R the identity and S = 0",
"message": "446174654b65797320000000000000000d",
"public_key": "c7176a703d4dd84fba3c0b760d10670f2a2053fa2c39ccc64ec7fd7792ac037a",
"signature": "01000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
"valid": false,
"stdlib": true
},
{
"name": "A of small order, the point 2 of the torsion, R the identity and S = 0",
"message": "446174654b657973200000000000000001",
"public_key": "0000000000000000000000000000000000000000000000000000000000000080",
"signature": "01000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
"valid": false,
"stdlib": true
},
{
"name": "A of small order, the point 3 of the torsion, R the identity and S = 0",
"message": "446174654b657973200000000000000002",
"public_key": "26e8958fc2b227b045c3f489f2ef98f0d5dfac05d3c63339b13802886d53fc05",
"signature": "01000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
"valid": false,
"stdlib": true
},
{
"name": "A of small order, the point 4 of the torsion, R the identity and S = 0",
"message": "446174654b65797320000000000000000f",
"public_key": "ecffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
"signature": "01000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
"valid": false,
"stdlib": true
},
{
"name": "A of small order, the point 5 of the torsion, R the identity and S = 0",
"message": "446174654b657973200000000000000019",
"public_key": "26e8958fc2b227b045c3f489f2ef98f0d5dfac05d3c63339b13802886d53fc85",
"signature": "01000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
"valid": false,
"stdlib": true
},
{
"name": "A of small order, the point 6 of the torsion, R the identity and S = 0",
"message": "446174654b657973200000000000000002",
"public_key": "0000000000000000000000000000000000000000000000000000000000000000",
"signature": "01000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
"valid": false,
"stdlib": true
},
{
"name": "A of small order, the point 7 of the torsion, R the identity and S = 0",
"message": "446174654b657973200000000000000001",
"public_key": "c7176a703d4dd84fba3c0b760d10670f2a2053fa2c39ccc64ec7fd7792ac03fa",
"signature": "01000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
"valid": false,
"stdlib": true
},
{
"name": "A not canonical, y = p, sign 0, R the identity and S = 0",
"message": "446174654b657973200000000000000002",
"public_key": "edffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
"signature": "01000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
"valid": false,
"stdlib": true
},
{
"name": "A not canonical, y = p, sign 1, R the identity and S = 0",
"message": "446174654b657973200000000000000001",
"public_key": "edffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
"signature": "01000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
"valid": false,
"stdlib": true
},
{
"name": "A the identity with the sign bit, R the identity and S = 0",
"message": "446174654b657973200000000000000000",
"public_key": "0100000000000000000000000000000000000000000000000000000000000080",
"signature": "01000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
"valid": false,
"stdlib": true
},
{
"name": "A of mixed order, 8 divides k: the equation without the cofactor holds",
"message": "446174654b657973200000000000000006",
"public_key": "b95f1903e3141ba54412bd1138119fbc7ab21aba35be980650ec3337b0a5c5e1",
"signature": "57890b19a0fb99cfa5fae15f2f8364a4d2d70474bea04f66c611aa5e250026a60ccf279cc11141ef368a21cfdad37a727e43f59936c20d753dea73a0e508d60e",
"valid": true,
"stdlib": true
},
{
"name": "A of mixed order, 8 does not divide k: only the equation with the cofactor holds",
"message": "446174654b657973200000000000000000",
"public_key": "b95f1903e3141ba54412bd1138119fbc7ab21aba35be980650ec3337b0a5c5e1",
"signature": "57890b19a0fb99cfa5fae15f2f8364a4d2d70474bea04f66c611aa5e250026a642a681ccd920aa6da440dc535484ec7ec2904a332dd86256e024a37f6040900f",
"valid": false,
"stdlib": false
},
{
"name": "R the identity, A of prime order",
"message": "446174654b6579733a205220746865206964656e74697479",
"public_key": "0368d6193d5242089bb4a5c019cceffe6a55d83495e57de52d7711ed864ca77d",
"signature": "01000000000000000000000000000000000000000000000000000000000000007b2ee545c254e47cbe2f2774f74d640944034cc59d1ba903de7ecb767cf95304",
"valid": true,
"stdlib": true
}
]
}

@ -1,5 +1,5 @@
{
"spec": "0.10",
"spec": "0.11",
"description": "HEAD_CBOR of format 3 (spec §29.4 to §29.6) and the result of decoding it with no extension known, generated by the reference implementation: layer 2 (type tag and version), layer 3 (the CDDL with R1 and R8), then layer 4 in key order (spec §69.1). See testdata/README.md.",
"heads": [
{

@ -1,5 +1,5 @@
{
"spec": "0.10",
"spec": "0.11",
"description": "Differential corpus of the pre-unlock checks (spec §63 steps 1 to 8): deterministic mutations of the official .dkc fixtures with the verdict of the reference implementation. See testdata/README.md.",
"format": "Each mutation is bases[base].file (in testdata/fixtures) with its edits applied. An edit is [at, delete, insert]: the delete bytes at offset at of the base are replaced by the bytes of the hex string insert. The edits of one mutation refer to offsets of the unmodified base, are sorted by offset and do not overlap. result is the verdict of steps 1 to 8 of spec §63 (capsule.Inspect, the Quicknet profile pinned, no extension known, no network, no secret): ok, or the normative error code, with step the step that failed. kind names the generator of the mutation and is informative.",
"seed": 20260925,

File diff suppressed because one or more lines are too long

File diff suppressed because one or more lines are too long

@ -1,5 +1,5 @@
{
"spec": "0.10",
"spec": "0.11",
"description": "Padding rules of the payload of a format 2 capsule (spec §29.1): for each content length L, P with code 1 (bloque256) and code 2 (reforzado), and the length of PAYLOAD_AGE for each. e, s and last_bits are informative. Generated by the reference implementation. See testdata/README.md.",
"l_max": 8936830510563328,
"vectors": [

@ -1,5 +1,5 @@
{
"spec": "0.10",
"spec": "0.11",
"description": "The key of R7 (spec §29.5) of segments, with the Unicode 18.0.0 tables of §29.5.1, generated by the reference implementation: nfd is NFD(segment) and key is NFD(fold(NFD(s'))), s' the segment without ZWNJ, ZWJ, VS15 and VS16. See testdata/README.md.",
"unicode_version": "18.0.0",
"tables_digest": "07cf5d54aea1cd13a3ecef14a06976cc49a3cdad755cf9bc10395178b93aeb07",

@ -1,5 +1,5 @@
{
"spec": "0.10",
"spec": "0.11",
"description": "Paths of a format 3 head (spec §29.5) with the Unicode 18.0.0 and best-fit tables of §29.5.1, generated by the reference implementation. paths: one path and the rules of one entry, R2 to R6c and R10; trees: the paths of a head, of 0 bytes each, and the result of decoding it. See testdata/README.md.",
"unicode_version": "18.0.0",
"tables_digest": "07cf5d54aea1cd13a3ecef14a06976cc49a3cdad755cf9bc10395178b93aeb07",

@ -1,5 +1,5 @@
{
"spec": "0.10",
"spec": "0.11",
"description": "Quicknet Provider Profile V1: exact Deterministic CBOR and profile_hash (spec §11, §12, §75 item 2), generated by the reference implementation.",
"profile_id": "datekeys:quicknet:v1",
"provider": "drand",

@ -1,5 +1,5 @@
{
"spec": "0.10",
"spec": "0.11",
"profile": "datekeys:quicknet:v1",
"description": "Quicknet date to round resolution (spec §15, §16, §65), generated by the reference implementation.",
"vectors": [

@ -1,5 +1,5 @@
{
"spec": "0.10",
"spec": "0.11",
"description": "SECURITY_CBOR of format 3, exactly its SECURITY_LEN bytes, and the verdicts of the signature and of the seal (spec §29.3, §29.7), generated by the reference implementation, which implements no alg and no seal_type. See testdata/README.md.",
"vectors": [
{

File diff suppressed because one or more lines are too long

@ -1,5 +1,5 @@
{
"spec": "0.10",
"spec": "0.11",
"description": "H2 of the IBE-CCA of tlock (spec §63 step 11): SHA-256 of \"IBE-H2\" and the 576 bytes of an element of GT, c1 before c0 at every level of the tower and each coordinate of Fp in 48 bytes big-endian (the order of kilic/bls12-381), truncated to 16 bytes. Generated by the reference implementation with drand/kyber-bls12381, the pairing of tlock.",
"vectors": [
{

Loading…
Cancel
Save

Powered by TurnKey Linux.