Initial implementation of the DateKeys Protocol v0.8.1
Reference implementation in Go, built from the implementation plan
(milestones M0 to M5): datekey, profile, provider, codec, agewrap,
extension, capsule, accesskey, the datekeys CLI, official vectors and
fixtures, the mutation corpus, fuzz targets, interop and live tests,
CI workflows, traceability and policy documents.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2 weeks ago
|
|
|
{
|
|
|
|
|
"spec": "0.8.2",
|
Initial implementation of the DateKeys Protocol v0.8.1
Reference implementation in Go, built from the implementation plan
(milestones M0 to M5): datekey, profile, provider, codec, agewrap,
extension, capsule, accesskey, the datekeys CLI, official vectors and
fixtures, the mutation corpus, fuzz targets, interop and live tests,
CI workflows, traceability and policy documents.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2 weeks ago
|
|
|
"description": "Canonical dk1_ strings and rejected encodings (spec §18, §19, §66), generated by the reference implementation.",
|
|
|
|
|
"vectors": [
|
|
|
|
|
{
|
|
|
|
|
"name": "round 1",
|
|
|
|
|
"network": "datekeys:quicknet:v1",
|
|
|
|
|
"round": 1,
|
|
|
|
|
"canonical_json": "{\"version\":1,\"network\":\"datekeys:quicknet:v1\",\"round\":1}",
|
|
|
|
|
"base64url": "eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MX0",
|
|
|
|
|
"dk1": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MX0"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "round 1000",
|
|
|
|
|
"network": "datekeys:quicknet:v1",
|
|
|
|
|
"round": 1000,
|
|
|
|
|
"canonical_json": "{\"version\":1,\"network\":\"datekeys:quicknet:v1\",\"round\":1000}",
|
|
|
|
|
"base64url": "eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMH0",
|
|
|
|
|
"dk1": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMH0"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "normative 2030-01-01 round",
|
|
|
|
|
"network": "datekeys:quicknet:v1",
|
|
|
|
|
"round": 66884212,
|
|
|
|
|
"canonical_json": "{\"version\":1,\"network\":\"datekeys:quicknet:v1\",\"round\":66884212}",
|
|
|
|
|
"base64url": "eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6NjY4ODQyMTJ9",
|
|
|
|
|
"dk1": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6NjY4ODQyMTJ9"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "last Quicknet round",
|
|
|
|
|
"network": "datekeys:quicknet:v1",
|
|
|
|
|
"round": 83903165811,
|
|
|
|
|
"canonical_json": "{\"version\":1,\"network\":\"datekeys:quicknet:v1\",\"round\":83903165811}",
|
|
|
|
|
"base64url": "eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6ODM5MDMxNjU4MTF9",
|
|
|
|
|
"dk1": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6ODM5MDMxNjU4MTF9"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "whitespace in JSON",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjogMSwgIm5ldHdvcmsiOiAiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCAicm91bmQiOiA2Njg4NDIxMn0",
|
|
|
|
|
"error": "ERR_DATEKEY_NON_CANONICAL"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "keys reordered",
|
|
|
|
|
"input": "dk1_eyJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJ2ZXJzaW9uIjoxLCJyb3VuZCI6NjY4ODQyMTJ9",
|
|
|
|
|
"error": "ERR_DATEKEY_NON_CANONICAL"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "trailing whitespace",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6NjY4ODQyMTJ9Cg",
|
|
|
|
|
"error": "ERR_DATEKEY_NON_CANONICAL"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "exponent notation",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6Ni42ODg0MjEyZTd9",
|
|
|
|
|
"error": "ERR_DATEKEY_NON_CANONICAL"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "fraction notation",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLjAsIm5ldHdvcmsiOiJkYXRla2V5czpxdWlja25ldDp2MSIsInJvdW5kIjo2Njg4NDIxMn0",
|
|
|
|
|
"error": "ERR_DATEKEY_NON_CANONICAL"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "escaped character",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXNcdTAwM2FxdWlja25ldDp2MSIsInJvdW5kIjo2Njg4NDIxMn0",
|
|
|
|
|
"error": "ERR_DATEKEY_NON_CANONICAL"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "duplicate key",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MSwicm91bmQiOjY2ODg0MjEyfQ",
|
|
|
|
|
"error": "ERR_DATEKEY_NON_CANONICAL"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "padded Base64URL",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMH0=",
|
|
|
|
|
"error": "ERR_DATEKEY_NON_CANONICAL"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "non-zero trailing bits",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMH1",
|
|
|
|
|
"error": "ERR_DATEKEY_NON_CANONICAL"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "extra field",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6NjY4ODQyMTIsInB1YmxpY19rZXkiOiIwMCJ9",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "missing field",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEifQ",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "version 2",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoyLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6NjY4ODQyMTJ9",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "round 0",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MH0",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "negative round",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6LTF9",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "fractional round",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MS41fQ",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "round above 2^53-1",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6OTAwNzE5OTI1NDc0MDk5Mn0",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "round as string",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6IjY2ODg0MjEyIn0",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "uppercase network",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiREFURUtFWVM6UVVJQ0tORVQ6VjEiLCJyb3VuZCI6NjY4ODQyMTJ9",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "trailing data",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6NjY4ODQyMTJ9eA",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "byte order mark",
|
|
|
|
|
"input": "dk1_77u_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6NjY4ODQyMTJ9",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "not Base64",
|
|
|
|
|
"input": "dk1_!!!",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "missing prefix",
|
|
|
|
|
"input": "eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6NjY4ODQyMTJ9",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "uppercase prefix",
|
|
|
|
|
"input": "DK1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6NjY4ODQyMTJ9",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
Spec v0.8.2 refinements: error precedence, trust model, strict order
Approved refinements, each recorded with its reproducible case in the
§76 v0.8.2 subsection:
- §69.1: layered error model with normative precedence (frame, type tag
and version, CBOR profile and CDDL, then fields with their own code in
ascending key order; across steps the §63 order decides), with a scope
paragraph for the optional steps 5, 6 and 8.
- §55.1: normative trust table per section (who can write it, from which
step it is bound, what it never proves); §72: security-relevant claims
go in CONTROL_CBOR or under a signature, .dkk data is advisory.
- §31/§54: extension arrays in strictly ascending unsigned byte order of
extension_id (one rule for order and uniqueness).
- Gaps a second implementation needed: §28.1 malformed age headers,
§15/§19 latest unlock time and dk1_ reading rules, §22/§23/§57 length
lower bounds, §63 step 8 tlock argument comparison and step 9 order,
§12.1 profile validation with the drand chain-hash formula, §74 table
of implementation limits.
Reference alignment: .dkk errors only at step 9.a (new
OpenOptions.AccessKeyFile, used by the CLI), CR/LF in dk1_ is
ERR_DATEKEY_INVALID, BODY_LEN 0 is ERR_INTEGRITY, nil identities are not
credentials, and AccessIdentity tries every identity on every stanza so
its verdict does not depend on their order. dk1.json gains three
vectors; every other testdata file is byte-identical.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "line feed inside the Base64",
|
|
|
|
|
"input": "dk1_eyJ2ZXJz\naW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6NjY4ODQyMTJ9",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "carriage return and line feed after the Base64",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6NjY4ODQyMTJ9\r\n",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "version 1.0000000000000001: its exact value, not a double",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLjAwMDAwMDAwMDAwMDAwMDEsIm5ldHdvcmsiOiJkYXRla2V5czpxdWlja25ldDp2MSIsInJvdW5kIjo2Njg4NDIxMn0",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"name": "invalid UTF-8 in a member a repeated name overwrites",
|
|
|
|
|
"input": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoi_yIsIm5ldHdvcmsiOiJkYXRla2V5czpxdWlja25ldDp2MSIsInJvdW5kIjo2Njg4NDIxMn0",
|
|
|
|
|
"error": "ERR_DATEKEY_INVALID"
|
Initial implementation of the DateKeys Protocol v0.8.1
Reference implementation in Go, built from the implementation plan
(milestones M0 to M5): datekey, profile, provider, codec, agewrap,
extension, capsule, accesskey, the datekeys CLI, official vectors and
fixtures, the mutation corpus, fuzz targets, interop and live tests,
CI workflows, traceability and policy documents.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2 weeks ago
|
|
|
}
|
|
|
|
|
]
|
|
|
|
|
}
|