The author confirmed the decisions of PLAN_fase2_ibe_noble2.md (v2),
with the adjustments of two reviews verified against the code, the spec
and npm: the ReleaseSource contract (a source that obtains no verified
release fails at step 9 with ERR_RELEASE_UNAVAILABLE, a caller-supplied
release at step 10 with ERR_RELEASE_INVALID, as Go's drand client);
age-encryption 0.3.1 without npm overrides, accepting the nested noble
2.0.x of @noble/post-quantum (~2.0.0) under guards that keep the BLS
code on the exact 2.4.0; streaming decryption of PAYLOAD_AGE into OPFS,
released only after age succeeds (§56), with the storage quota as the
limit; IBE test vectors generated from the Go reference; verifyRelease
in the order of provider.Verify; the canonicality spec change as an
amendment of v0.8.2.
App is now Apache-2.0, like the Go reference.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
TypeScript aligned with the Go reference at 692cf87: layered error
precedence, the refined spec rules and the §19 UTF-8 rule; every shared
Go vector file runs in the suite (2,375 tests, 24 phase-2 cases skipped
and counted). Two differentials against Go, 483,527 and 407,208 inputs
from independent generators, found no disagreement on verdict, code or
step; an independent review approved the merge.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- testdata.test.ts runs the sync-testdata check inside npm test, so a
truncated or edited vector file fails instead of running fewer cases;
the quicknet_rounds and inspect_differential blocks also assert that
they are not empty.
- A boundary test pins the 2 MiB age header limit: exactly 2 MiB is
accepted and 2 MiB + 1 byte rejected, as filippo.io/age does.
- The page no longer says time_and_key needs a .dkk: the credential is
a .dkk or the X25519 identity of a recipient (spec §38, §63 step 9.b).
- The landing text says the guarantee rests on drand not revealing the
signature early, instead of claiming nobody can open a capsule (§4).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
testdata is synced from datekeys-go 692cf87, where the reference stopped
replacing invalid UTF-8 in the dk1_ JSON with U+FFFD and fails step 2
with ERR_DATEKEY_INVALID, as §19 requires. parseJSON checks the bytes
first in the same way, the test that pinned the old reference behaviour
now pins the spec's, and the README drops the Go-vs-spec conflict note.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Finishes the interrupted alignment of 3305bbb. The TypeScript now
follows the reference at 3820066 on steps 1 to 8, decoding and profile
validation:
- §69.1 precedence: the schema head is read strictly (a null or simple
version is ERR_NON_CANONICAL_CBOR, version 2 is ERR_UNSUPPORTED_VERSION
whatever follows) and every CDDL rule, including access_policy,
extension_version and the 64-extension cap read from the array head,
is checked before the DateKey; the wideUint path that imitated the
old Go order is gone.
- §19: CR or LF in dk1_ is ERR_DATEKEY_INVALID; §15: a round at exactly
9999-12-31T23:59:59Z is valid; §12.1: period above one day is
rejected on decode and pin; BODY_LEN 0 is ERR_INTEGRITY.
- Inspector texts no longer call header data authenticated at step 15
(§55.1: binding, never authorship or date); the fixture list ignores
the new *.inspect.json goldens.
The harness runs every shared Go vector: dk1.json 30, quicknet_rounds
17, profile 1, cbor.json 103 generic and 135 schema vectors,
mutations.json 31 through inspect with 24 phase-2 cases skipped and
counted, inspect_differential.json 1,825, and the five inspect goldens
byte-identical. A differential of 483,527 inputs against the Go
reference found no disagreement on verdict, code or step.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Supersedes the phase 2 block of the v2 plan, which named decryptOnG1 for Quicknet (it is decryptOnG2) and gave release verification to drand-client. Grounded in the 2026-09-26 fact-check of tlock-js 0.9.0: the noble 1.9.7 discrepancies are non-canonical encodings only, an override to noble 2 does not load, a 44-line decrypt module on noble 2.4.0 matches Go on all five fixtures, and drand-client is not needed.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
testdata synced from datekeys-go 3820066 (verified with sync-testdata
check --against): cbor.json, mutations.json, inspect_differential.json,
the inspect goldens, testdata/README.md and the three new dk1.json
vectors. The alignment of src/lib/dkc and of the vector harness was cut
off by a usage limit halfway through a refactor: tests and typecheck
fail. Kept on this branch so that main stays green; it is finished here
and merged when every check passes.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Two samples of every class of the 41,686-input differential corpus and
the 2,765-input adversarial corpus (cofactor torsion, small-order points,
points plus torsion, sign edge cases, coordinates >= p, every flag
combination, other lengths), with the Go reference verdict recomputed by
scripts/bls12381-go-verdicts.go. On those corpora bls12381.ts matched the
Go reference on all 49,451 inputs, at the same rejection stage; noble
>= 2.3.0 with a length check matched too, while noble 1.9.7 (the version
tlock-js 0.9.0 pulls in) differed on 5,615.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Our checkCompressedPoint stays: it matches the Go reference on every edge
case, is 1.3 KB gzip and adds no runtime dependency. Its assurance now
comes from a contrast test run on every test pass:
- 41 frozen edge-case encodings with the Go reference verdict (drand crypto
KeyGroup over kyber-bls12381 and kilic/bls12-381, as profile.Validate
uses it), reproducible with scripts/bls12381-go-verdicts.go;
- the audited @noble/curves 2.4.0 on the same edge cases and on a
fixed-seed corpus of valid points, negations, bit flips, random x and G1
points on the curve outside the subgroup.
Breaking the G1 or the G2 subgroup check makes the test fail.
@noble/curves 2.4.0 is a development dependency only; a test fails if
anything that is not a test imports it, and the build contains none of it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Skeleton for the TypeScript implementation of DateKeys v0.8.x: the plans
in docs/, testdata/ vendored from g.activething.com/go/DateKeys at 5719f6a
with a zero-dependency sync and check script, and the TypeScript and vitest
tooling already used by the prototype, which now lives in ../AppOld.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>