v0.10
main
v0.5.0
v0.4.0
v0.3.0
v0.2.0
v0.1.0
${ noResults }
8 Commits (f79d8e2de84486fe79bc96543bc166bb561599fa)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
f79d8e2de8 |
Specification 0.16 draft: a seal without accuracy, drand's JSON read strictly
The draft v0.16 of datekeys-go at 4f78854 (branch v0.16): SPEC_VERSION 0.16, and testdata, wordlists and annex synced from that commit. The annex is §79 of the draft, with the CC BY-ND 4.0 license of the specification in its title and the key of words in 79.7. A seal without accuracy proves nothing before the opening date (§29.7, §29.11, as 7e3b810): a valid seal is S4 only when its token carries accuracy and t plus the accuracy is before round_time; otherwise S5, with the first reason that holds: late, no accuracy under the BTSP policy of ETSI EN 319 421 (0.4.0.2023.1.1), or no accuracy. cms.ts reads hasAccuracy and the policy of the token (tokenIsBTSP); securitycms.ts gives SealReason, Detail.sealReason and SignerLine.reason; S5 has no fixed text any more, and verdictLines writes it and the line of a signer of F6 with the reason, the texts of Go byte for byte (sealReasonText). encryptFiles returns the verdicts of the area it wrote in Encrypted.security, as Result.Security of Go, so that a writer warns of a seal without accuracy (§62.1 rule 19). drand's JSON is read strictly (§47.1, as b570338): parseDrandJSON, as ParseDrandJSON of Go, reads RFC 8259 JSON in valid UTF-8 whose value is an object, with no name repeated in any object, names compared exactly once their escapes are decoded, a lone escaped surrogate malformed, the round a number without sign, fraction or exponent from 1 to 2^53 - 1, and signature and randomness strings, with the error texts of Go. ParsedRelease is now a Release: no round above 2^53 - 1 is read. The page reads the answers of the relays with it (drand.ts), as the client of Go does, and the pasted release with strictJSON and jsonRound (release-input.ts), so that it never reads another round than step 10. Tests: security_cms.json with seal_reason (143 cases), the 38 JSON inputs of release.json, the new cases of signature2_test.go and drandjson_test.go (with the escapes written as escapes), and the new fixtures: format3_time_and_key_words opens with the identity that the words of its words_text give with normalizeWords and wordKey, in the library and in the page, and format3_full_chunk, whose PAYLOAD_AGE ends in a full STREAM chunk, opens. check-build.mjs counts words_text among the secrets of the fixtures. Reference files made again with Go at 4f78854: mutation-texts.json (its spec field only), ibe-vectors.json (the two new fixtures, the rest unchanged) and signing-vectors.json, in an export of 4f78854 with the same frozen samples read again: the capsules are the same, and the tokens of the sealer, without accuracy, now give S5. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
5 hours ago |
|
|
3c95d1a523 |
Specification 0.15: the release object, a release in hand and step 9.c
- SPEC_VERSION 0.15, version 0.4.0-dev; testdata synced from datekeys-go at 3c3e737 (v0.15), which adds vectors/release.json and releases/ and the field source of mutations.json. - releaseobject.ts, without noble, as provider/release.go and archive.go of Go: encodeRelease, decodeRelease with the layers of step 10 (size of 1 to 1024 bytes, type and version, schema), parseRelease, which reads drand's JSON as encoding/json does, the ReleaseSupplier of a release in hand (encodedRelease) and ReleaseArchive, the informative local archive, whose failures are ERR_RELEASE_UNAVAILABLE; all with Go's texts. - verifyRelease compares the chain hash a release names with the pinned profile first (ERR_PROFILE_MISMATCH). - open takes OpenOptions.release, exclusive with source: it is not compared with the clock (step 9.c, option B), Opened.clockBehind reports a clock behind it, and it is decoded at step 10; a network source is still never asked before the round time. The verified release carries the chain hash of the pinned profile. - vectors.test.ts runs release.json and every file of releases/, and the mutation corpus with the source of each case, as testkit's singleSource; scripts/mutation-go-texts.go does the same, and testing/mutation-texts.json is regenerated: the spec field, "round not reached yet" now ok, and the four new cases. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
23 hours ago |
|
|
4e23f88c0a |
Specification 0.14, approved: SPEC_VERSION 0.14, testdata at spec-v0.14, one drand scheme and tlock_steps.json
- SPEC_VERSION 0.14; testdata synced from datekeys-go at 39b2033 (spec-v0.14), which adds vectors/tlock_steps.json; testing/mutation-texts.json regenerated with Go: only its spec field changes. - Decision 8: validateProfile admits only bls-unchained-g1-rfc9380, with its public key in G2, in the order and with the texts of Go's validateDrand at c041fa3; any other drand scheme fails with ERR_UNKNOWN_PROFILE before the key and the chain hash. - vectors.test.ts walks tlock_steps.json value by value with the code of ibe.ts, release.ts and bls12381.ts, with its negative checks, and the testdata guard requires it. ibe.ts exports h3Base, h3Try and hashToG1, which h3, the encryption and release.ts now use. - The comment of h3 said the top bit is cleared: the first byte is shifted one bit to the right, as kyber does. - README and CHANGELOG. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
1 day ago |
|
|
a670d9768f |
Specification 0.13, approved: the spec version 0.13 and testdata at spec-v0.13
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
1 day ago |
|
|
45e7e499d4 |
Specification 0.12, approved: SPEC_VERSION 0.12 and testdata at spec-v0.12
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
1 day ago |
|
|
95329eef4a |
Follow the draft v0.12: testdata at 601e6d2, the reader of certificates, the texts of the verdicts
testdata is synced with the head of the branch v0.12 of datekeys-go
(601e6d2); SPEC_VERSION stays 0.11 until the author approves the draft.
- CMS as Go reads it at the draft v0.12 (review of 2 October, T2, T6 to T8
and the TypeScript side of E7 to E9):
- the certificate field by field with the profile of section 29.10, its
errors in CertificateError with the texts of Go; one that breaks it
decides nothing unless a SignerInfo names it, and two copies are one;
- the text of a name only from UTF8String, PrintableString, IA5String,
TeletexString in ASCII and BMPString without surrogates, never from an
attribute that appears twice; the holder by givenName and surname
before the commonName, the issuer by its commonName or its
organizationName;
- object identifiers by the bytes of their DER; a SET OF may repeat an
element; RSA with NULL parameters and an odd modulus; a key of another
scheme than its algorithm is invalid; a messageImprint of another
length is S3; the crls of a token decide nothing;
- DER: UTCTime and GeneralizedTime in their X.690 forms with a date that
exists, the restricted string types as primitive, the accuracy as
minimal INTEGERs. The test of cms.test.ts that compared a function
with itself has an expected value of its own.
- The verdicts in the texts of the draft: names between « and », shown
with at most 64 code points and no two spaces in a row, or their SHA-256;
in F6 the authority of each seal and the warning that nobody checks who
issued it; foreign signers in Spanish; times with their fraction.
- security.json in its context with lines, and the 135 cases of
security_cms.json, compared field by field, lines included.
- The 218 cases of mutations.json, with the texts of capsule.Open
regenerated by scripts/mutation-go-texts.go, and ibe-vectors.json with
the fixtures format3_note, format3_unsigned and the new
format3_seal_unsupported; its frozen values do not change.
- note.json, run with checkNoteData, publicNote and unusableNote.
- inspect reads the public note on demand, only for a header with one, so
that the Unicode tables never load with /inspect; the view of inspect
-json gives public_note and public_note_unusable, as Go.
A Go/TypeScript differential of 63,623 security areas, made from the
vectors, edited element by element and signed afresh with varied
certificates, tokens and authorities, gave no difference in verdicts,
results or lines; the code before this change differed in 13,296 of the
first 42,986.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
2 days ago |
|
|
e3cf2409cd |
Sync testdata with DateKeys spec-v0.11 (datekeys-go ae33434)
SPEC_VERSION is 0.11. testdata brings format3_signed, format3_signed_cms and format3_sealed, and the vectors ed25519_strict.json, security_cms.json and locator.json; the mutation corpus has 210 cases. ibe-vectors.json adds the three fixtures and remakes the two that Go regenerated, and mutation-texts.json is made again with that reference. This library still reads the security area as a reader of v0.10, so a signature or a seal that the reference checks gives F1 or S1 here. The Verdict type and the texts know F2 to F6 and S3 to S5, and the tests state the gap with testing/pending.ts instead of hiding it; porting the verification makes that file the identity. npm run verify and testdata:check pass. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
6 days ago |
|
|
b176ad2f17 |
Format 3, step 3: read capsule format 3 of spec v0.10
Syncs testdata with datekeys-go at the tag spec-v0.10 (cc35d2c) and moves the reader to the DateKeys Protocol Specification v0.10. The three capsule formats are read. - framing: FORMAT_3, and isPadded for formats 2 and 3. control: schema version 3, with the keys 6 and 7 of version 2. SPEC_VERSION is 0.10. - open: OpenOptions.sink receives the files of a format 3 capsule (sink.ts: Sink with begin, create, commit and abort, as capsule.Sink, and MemorySink). Without one, open rejects with a TypeError right after step 2, before any request, as ErrSinkRequired. Opened gains head, verdicts, areaLen and unusableHeadExtensions. - open3.ts: step 17 of format 3 in its substeps 17.2 to 17.8, as openBody of the reference: a failure of age or a plaintext whose length is not P prevails, the first failing substep decides, and the codes other than ERR_INTEGRITY are reported only after reading PAYLOAD_AGE to its end. Reads grow with the bytes received, never with the lengths BODY declares. A failure of the sink is ERR_INTEGRITY with its text, and the sink is aborted once after begin. - The page: opener.ts opens the fixtures of format 3 into a MemorySink; the open panel says that it does not deliver their files yet, and the glosses of the steps name format 3. check-build.mjs refuses to ship the heads, salts, comments and paths of the format 3 fixtures. Tests: the 21 fixtures, format 3 laid out byte by byte from its record and opened into a sink with its files and verdicts; the 209 cases of the corpus from memory and from a Blob, with the code, the step and, new, the exact text of capsule.Open, frozen by scripts/mutation-go-texts.go in testing/mutation-texts.json, which replays the corpus as internal/testkit does (its extension validator texts included); the 5110 differential cases over 14 bases; paths, path_fold, head_schema and security vectors; the control of schema version 3 in cbor.json; and step 17 on crafted plaintexts sealed again to I_PAYLOAD, whose texts capsule.Open gives on the same plaintexts. ibe-vectors.json gains the nine format 3 fixtures from scripts/ibe-go-vectors.go; the twelve before are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
1 week ago |