Recovery check: open fixtures with the annex and no DateKeys code
scripts/recovery is a program that opens a capsule with only the Go
standard library, golang.org/x/crypto, filippo.io/age and the BLS12-381
library of drand/kyber-bls12381, as the informative annex of the draft
v0.15 describes it: the pinned Quicknet parameters, the release object,
the frame, the BLS verification of the release, the tlock stanza with H2,
H3 and H4, the age file of SEALED_CONTROL opened with its file key (HKDF,
header MAC and STREAM written out), the X25519 layers with age, and the
content of formats 1, 2 and 3. A test forbids importing this module, tlock
and drand. scripts/recovery_check.sh opens a time_only and a time_and_key
fixture of format 3 with it and compares what it recovers; scripts/check.sh
runs it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 day ago
|
|
|
#!/usr/bin/env bash
|
|
|
|
|
# Opens official fixture capsules with scripts/recovery, a program that uses
|
|
|
|
|
# no DateKeys code (only Go, age, kyber and x/crypto), and compares what it
|
|
|
|
|
# recovers with the plaintext fixtures. It shows that the annex
|
|
|
|
|
# "Recuperación sin software DateKeys" of the specification is enough.
|
|
|
|
|
#
|
|
|
|
|
# scripts/recovery_check.sh
|
|
|
|
|
set -euo pipefail
|
|
|
|
|
cd "$(dirname "$0")/.."
|
|
|
|
|
|
|
|
|
|
tmp=$(mktemp -d)
|
|
|
|
|
trap 'rm -rf "$tmp"' EXIT
|
|
|
|
|
|
|
|
|
|
fx=testdata/fixtures
|
|
|
|
|
rel=testdata/releases
|
|
|
|
|
|
|
|
|
|
recover_one() {
|
|
|
|
|
local name=$1 round=$2
|
|
|
|
|
shift 2
|
|
|
|
|
echo "== $name (round $round)"
|
Spec v0.15 draft: remove the .dkr file
The author's decision of 7 October 2026. A release saved next to a capsule
cannot exist when the capsule is made, and once the date comes the capsule
can be opened: such a file only opens it again and does not cover the real
case, someone opening it decades later when drand is gone and nobody saved
anything. Long-term recovery rests instead on archives and cache services
that keep the releases of all rounds; a reader asks for its round and
verifies the signature against the pinned key.
Spec: the .dkr extension (section 20, back to v0.14), sections 1, 4, 8, 45,
47.1, 49, 50 (rewritten), 53, 62.1 (rule 28 removed, rule 26 reworded),
63, 70, 73, 74 (the datekeys.release .dkk extension dropped too), 76
(the v0.15 block, with the discarded design) and the annex 79. The
release object, the chain hash at step 10, step 9.c option B and the
archive format stay.
Code: decrypt -save-release and the command datekeys release are gone,
with writeRelease and their tests; decrypt -release FILE stays. The
release objects of testdata/releases are now <round>.cbor, and
TestVectorFilesAreCurrent fails on a file the generator no longer writes.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
23 hours ago
|
|
|
go run ./scripts/recovery -dkc "$fx/$name.dkc" -release "$rel/$round.cbor" "$@" \
|
Recovery check: open fixtures with the annex and no DateKeys code
scripts/recovery is a program that opens a capsule with only the Go
standard library, golang.org/x/crypto, filippo.io/age and the BLS12-381
library of drand/kyber-bls12381, as the informative annex of the draft
v0.15 describes it: the pinned Quicknet parameters, the release object,
the frame, the BLS verification of the release, the tlock stanza with H2,
H3 and H4, the age file of SEALED_CONTROL opened with its file key (HKDF,
header MAC and STREAM written out), the X25519 layers with age, and the
content of formats 1, 2 and 3. A test forbids importing this module, tlock
and drand. scripts/recovery_check.sh opens a time_only and a time_and_key
fixture of format 3 with it and compares what it recovers; scripts/check.sh
runs it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 day ago
|
|
|
-out "$tmp/$name" -body "$tmp/$name.body"
|
|
|
|
|
cmp "$tmp/$name.body" "$fx/$name.plaintext"
|
|
|
|
|
echo "files written:"
|
|
|
|
|
(cd "$tmp/$name" && find . -type f | sort)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
recover_one format3_single 1000
|
|
|
|
|
recover_one format3_time_and_key_portable 1000 -dkk "$fx/format3_time_and_key_portable.dkk"
|
|
|
|
|
|
|
|
|
|
echo "recovery check passed"
|