Fixes T9, T11 and T12 of the review of the session of 1 and 2 October:
- T9: EncryptOptions no longer has testVectors nor areaLen, with which any
caller could write format 2, or an area of 512 bytes, which rule 13
forbids and which tells that the capsule has no signature (§55.2). What
only a generator of test vectors asks, as Go's TestVectors, is the
TestVectors argument of the core of writer.ts, which only the helpers of
testing/encrypt.ts pass: encryptVectors and encryptWith write format 2,
and encryptFilesWith another area, with which the tests still reproduce
byte for byte the fixtures of 512 bytes. encrypt keeps the shape of
capsule.Encrypt: without a generator it fails with the text of Go,
whatever the caller adds. dependencies.test.ts refuses an import of
testing/ from anything but the tests and testing/ itself, check-build.mjs
refuses a test or a module of testing/ in the bundle of the pages, and
note.ts joins the modules that index.ts must not re-export.
- T12: encrypt as a generator refuses a public note and an area with the
text of Go, "capsule: format 2 has no security area or public note: ...",
after the head and the length, as capsule.Encrypt. The errors of the note
carry "capsule: ", and newSealer checks the note, then the profile and the
clock, in the order of Go. The tests compare the texts byte for byte, also
for two faults at once.
- T11: capsuleLength takes the public note and predicts exactly the size of
the .dkc with it: eight notes of 1 to 1024 bytes, across the boundaries of
the heads of CBOR, with both policies and with other extensions.
The 40 texts that capsule.EncryptFiles and extension.CheckNote give at
spec-v0.11 on the same notes and options, taken with an oracle, are those
of this library; HEAD gave another one in 23 of them. npm run verify
passes.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>