Initial implementation of the DateKeys Protocol v0.8.1
Reference implementation in Go, built from the implementation plan
(milestones M0 to M5): datekey, profile, provider, codec, agewrap,
extension, capsule, accesskey, the datekeys CLI, official vectors and
fixtures, the mutation corpus, fuzz targets, interop and live tests,
CI workflows, traceability and policy documents.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2 weeks ago
|
|
|
#!/usr/bin/env bash
|
|
|
|
|
# Runs every parser fuzz target for the given duration each (default 20s).
|
|
|
|
|
# FUZZ_PARALLEL limits the number of fuzzing workers; each one keeps a
|
|
|
|
|
# 100 MB shared-memory file in the temporary directory.
|
|
|
|
|
# FUZZ_MINIMIZE is the time spent minimising each new input (default 0):
|
|
|
|
|
# minimisation stalls FuzzInspect for minutes, so short runs skip it; a
|
|
|
|
|
# failing input is still saved under testdata/fuzz as found.
|
|
|
|
|
set -euo pipefail
|
|
|
|
|
duration="${1:-20s}"
|
|
|
|
|
parallel=(-fuzzminimizetime="${FUZZ_MINIMIZE:-0}")
|
|
|
|
|
if [[ -n "${FUZZ_PARALLEL:-}" ]]; then
|
|
|
|
|
parallel+=(-parallel "$FUZZ_PARALLEL")
|
|
|
|
|
fi
|
|
|
|
|
targets=(
|
|
|
|
|
"./codec FuzzDecoder"
|
|
|
|
|
"./codec FuzzWalk"
|
|
|
|
|
"./codec FuzzPeek"
|
|
|
|
|
"./codec FuzzUnmarshal"
|
|
|
|
|
"./codec FuzzEncodeImpliesWalk"
|
|
|
|
|
"./extension FuzzDecodeArray"
|
Initial implementation of the DateKeys Protocol v0.8.1
Reference implementation in Go, built from the implementation plan
(milestones M0 to M5): datekey, profile, provider, codec, agewrap,
extension, capsule, accesskey, the datekeys CLI, official vectors and
fixtures, the mutation corpus, fuzz targets, interop and live tests,
CI workflows, traceability and policy documents.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2 weeks ago
|
|
|
"./profile FuzzDecode"
|
Release object, release in hand and step 9.c option B (spec v0.15 draft)
The release of a round becomes a file, .dkr: a release object in
deterministic CBOR, {0: "datekeys-release", 1: 1, 2: chain_hash, 3: round,
4: signature}, which provider.EncodeRelease writes and DecodeRelease reads
with its layers (size, type and version, schema). provider.ParseRelease
also reads drand's JSON as the input of the caller. Verify checks the chain
hash a release names before its round and its signature, with
ERR_PROFILE_MISMATCH. provider.Archive reads a local release archive, the
informative format of the draft.
capsule.OpenOptions.Release takes a release in hand, a provider.Supplier,
exclusive with Source: Open does not compare it with the clock (step 9.c,
option B) and reports a clock behind it in Opened.ClockBehind; a network
source is still never asked before the round time. The CLI gains
decrypt -release FILE (.dkr, drand's JSON or a local archive),
decrypt -save-release FILE.dkr and the command release, which fetches,
verifies and saves the .dkr without opening the capsule.
Test data: vectors/release.json, releases/<round>.dkr for rounds 1000,
1001, 1004 and 2000, and a local archive of rounds 1000 to 1004. In
mutations.json every case says its source, "supplied" or "network"; the
case "round not reached yet", a release in hand, now opens, and four cases
are added: the same with a network source, a release of another round from
a network source, and two release objects of another chain. SpecVersion
stays 0.14 until the author approves the draft.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
22 hours ago
|
|
|
"./provider FuzzDecodeRelease"
|
Initial implementation of the DateKeys Protocol v0.8.1
Reference implementation in Go, built from the implementation plan
(milestones M0 to M5): datekey, profile, provider, codec, agewrap,
extension, capsule, accesskey, the datekeys CLI, official vectors and
fixtures, the mutation corpus, fuzz targets, interop and live tests,
CI workflows, traceability and policy documents.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2 weeks ago
|
|
|
"./datekey FuzzParse"
|
|
|
|
|
"./agewrap FuzzStanzas"
|
|
|
|
|
"./accesskey FuzzDecode"
|
|
|
|
|
"./capsule FuzzParsePrelude"
|
|
|
|
|
"./capsule FuzzDecodeHeader"
|
|
|
|
|
"./capsule FuzzDecodeControl"
|
Format 3, step 8: fuzzing of format 3 and the SHA-256 of spec v0.10
- Three fuzz targets, in scripts/fuzz.sh too: FuzzDecodeHead (a head
that is accepted re-encodes to its input, and a rejection carries one
normative code), FuzzEvaluateSecurity (verdicts of this version, X for
both or for neither) and FuzzCheckPath (the rules of one entry and the
decoder of the head agree on every path). About a million runs each,
clean; scripts/check.sh 60s is clean.
- Spec v0.10, section 67: the fixtures of format 3 exist, so "Serán ...
(por implementar)" reads "Son ...", as for those of format 2. No rule
changes.
- spec/README.md: v0.10 approved by its author on 30 September 2026 and
implemented on this branch, with the SHA-256 of its text; the tag
spec-v0.10 waits for the author.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
|
|
|
"./capsule FuzzDecodeHead"
|
|
|
|
|
"./capsule FuzzEvaluateSecurity"
|
|
|
|
|
"./internal/pathrule FuzzCheckPath"
|
|
|
|
|
"./locator FuzzUnmarshal"
|
|
|
|
|
"./locator FuzzParseInfo"
|
|
|
|
|
"./locator FuzzCheckURI"
|
|
|
|
|
"./locator FuzzCheckResolvedIP"
|
|
|
|
|
"./internal/der FuzzDERCheck"
|
|
|
|
|
"./internal/cms FuzzParseSignature"
|
|
|
|
|
"./internal/cms FuzzParseToken"
|
|
|
|
|
"./internal/cms FuzzParseCert"
|
Initial implementation of the DateKeys Protocol v0.8.1
Reference implementation in Go, built from the implementation plan
(milestones M0 to M5): datekey, profile, provider, codec, agewrap,
extension, capsule, accesskey, the datekeys CLI, official vectors and
fixtures, the mutation corpus, fuzz targets, interop and live tests,
CI workflows, traceability and policy documents.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2 weeks ago
|
|
|
"./capsule FuzzInspect"
|
|
|
|
|
"./capsule FuzzEncodeImpliesDecode"
|
Initial implementation of the DateKeys Protocol v0.8.1
Reference implementation in Go, built from the implementation plan
(milestones M0 to M5): datekey, profile, provider, codec, agewrap,
extension, capsule, accesskey, the datekeys CLI, official vectors and
fixtures, the mutation corpus, fuzz targets, interop and live tests,
CI workflows, traceability and policy documents.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2 weeks ago
|
|
|
)
|
|
|
|
|
for t in "${targets[@]}"; do
|
|
|
|
|
read -r pkg name <<<"$t"
|
|
|
|
|
echo "== $pkg $name ($duration)"
|
|
|
|
|
go test -run='^$' -fuzz="^${name}\$" -fuzztime="$duration" "${parallel[@]}" "$pkg"
|
|
|
|
|
done
|