package main
import (
"os"
"path/filepath"
Review fixes: author keys, the writer, the CLI, extensions and the locator
Fixes of the review of the session of 1 and 2 October that the text of
spec v0.11 already asks for:
- authorkey: String and GoString hide the secret key, which only Secret
returns; ParsePublic refuses a key that is not a point of the curve
(ed25519strict.OnCurve, checked against the square root of testkit).
- capsule: a typed nil in AuthorKey, CMSSigner or Sealer is an error, never
a capsule without the signature or the seal that was asked for. A panic
while evaluating the signature or the seal fails only that part, F1 or
S2, not both. OpenOptions.Accept sees the verdicts before step 18 and can
refuse to publish the files.
- extension.CheckWrite, the rule of encoders of spec 72: the writers of
capsules and .dkk files refuse datekeys.note and datekeys.capsule outside
the arrays where they are registered, or with invalid data.
- CLI: encrypt -sign shows the author key and the code of AUTHOR_MESSAGE
before it signs (rule 20); decrypt -expect-author compares the key of an
F4 and writes nothing unless it matches; decrypt notifies a public note
that it does not show; the lines of the verdicts break at the last space
that fits, each row after the first behind a mark, so that the terminal
never breaks them; L is the payload, not the content.
- locator: a reader rejects an address that breaks 44.1 and keeps the
others; addresses refuse the special-purpose blocks of IANA, IPv6 outside
2000::/3, localhost and local names, characters outside RFC 3986, dot
segments, and a CID that does not decode to version 1 and a multihash;
ParseInfo checks that the locator is an age file with one tlock stanza
for the round of its DateKey; Info.Extension reads what it writes; its
errors carry no normative code.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
6 days ago
"regexp"
"strings"
"testing"
"time"
"g.activething.com/go/DateKeys/profile"
)
// Spec v0.11, §29.9, §29.12: author keygen, encrypt -sign and decrypt
// -expect-author, with the passphrase in a file and in the standard input.
func TestAuthorSignRoundTrip ( t * testing . T ) {
dir := t . TempDir ( )
in := filepath . Join ( dir , "carta.txt" )
os . WriteFile ( in , [ ] byte ( "firmada" ) , 0 o600 )
pass := filepath . Join ( dir , "pass.txt" )
os . WriteFile ( pass , [ ] byte ( "una contraseña larga\r\n" ) , 0 o600 )
p := profile . Quicknet ( )
unlock := time . Unix ( p . GenesisTime + 999 * 3 , 0 ) . UTC ( ) // round 1000
genesis := time . Unix ( p . GenesisTime , 0 )
keyFile := filepath . Join ( dir , "autor.key" )
pub , stderr , err := cli ( t , genesis , "author" , "keygen" , "-out" , keyFile , "-pass-file" , pass )
if err != nil || ! strings . HasPrefix ( pub , "dkauthor1" ) || ! strings . Contains ( stderr , "keep it" ) {
t . Fatalf ( "keygen: %q %v %s" , pub , err , stderr )
}
pub = strings . TrimSpace ( pub )
if b , _ := os . ReadFile ( keyFile ) ; ! strings . HasPrefix ( string ( b ) , "age-encryption.org/v1" ) {
t . Error ( "the key file is not encrypted" )
}
if _ , _ , err := cli ( t , genesis , "author" , "keygen" , "-out" , keyFile , "-pass-file" , pass ) ; err == nil {
t . Error ( "overwrote a key" )
}
if _ , _ , err := cli ( t , genesis , "author" , "keygen" , "-out" , filepath . Join ( dir , "x.key" ) ) ; err == nil {
t . Error ( "wrote a key without a passphrase and without -plain" )
}
if got , _ , err := cli ( t , genesis , "author" , "public" , "-key" , keyFile , "-pass-file" , pass ) ; err != nil || strings . TrimSpace ( got ) != pub {
t . Errorf ( "public: %q %v" , got , err )
}
if _ , _ , err := cli ( t , genesis , "author" , "public" , "-key" , keyFile ) ; err == nil || ! strings . Contains ( err . Error ( ) , "-pass-file" ) {
t . Errorf ( "public of an encrypted key without its passphrase: %v" , err )
}
other := filepath . Join ( dir , "otra.key" )
otherPub , _ , err := cli ( t , genesis , "author" , "keygen" , "-out" , other , "-plain" )
if err != nil {
t . Fatal ( err )
}
otherPub = strings . TrimSpace ( otherPub )
dkc := filepath . Join ( dir , "c.dkc" )
Review fixes: author keys, the writer, the CLI, extensions and the locator
Fixes of the review of the session of 1 and 2 October that the text of
spec v0.11 already asks for:
- authorkey: String and GoString hide the secret key, which only Secret
returns; ParsePublic refuses a key that is not a point of the curve
(ed25519strict.OnCurve, checked against the square root of testkit).
- capsule: a typed nil in AuthorKey, CMSSigner or Sealer is an error, never
a capsule without the signature or the seal that was asked for. A panic
while evaluating the signature or the seal fails only that part, F1 or
S2, not both. OpenOptions.Accept sees the verdicts before step 18 and can
refuse to publish the files.
- extension.CheckWrite, the rule of encoders of spec 72: the writers of
capsules and .dkk files refuse datekeys.note and datekeys.capsule outside
the arrays where they are registered, or with invalid data.
- CLI: encrypt -sign shows the author key and the code of AUTHOR_MESSAGE
before it signs (rule 20); decrypt -expect-author compares the key of an
F4 and writes nothing unless it matches; decrypt notifies a public note
that it does not show; the lines of the verdicts break at the last space
that fits, each row after the first behind a mark, so that the terminal
never breaks them; L is the payload, not the content.
- locator: a reader rejects an address that breaks 44.1 and keeps the
others; addresses refuse the special-purpose blocks of IANA, IPv6 outside
2000::/3, localhost and local names, characters outside RFC 3986, dot
segments, and a CID that does not decode to version 1 and a multihash;
ParseInfo checks that the locator is an age file with one tlock stanza
for the round of its DateKey; Info.Extension reads what it writes; its
errors carry no normative code.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
6 days ago
_ , stderr , err = cli ( t , genesis , "encrypt" , "-at" , unlock . Format ( time . RFC3339 ) , "-in" , in , "-out" , dkc , "-sign" , keyFile , "-sign-pass-file" , pass )
if err != nil {
t . Fatalf ( "%v\n%s" , err , stderr )
}
Review fixes: author keys, the writer, the CLI, extensions and the locator
Fixes of the review of the session of 1 and 2 October that the text of
spec v0.11 already asks for:
- authorkey: String and GoString hide the secret key, which only Secret
returns; ParsePublic refuses a key that is not a point of the curve
(ed25519strict.OnCurve, checked against the square root of testkit).
- capsule: a typed nil in AuthorKey, CMSSigner or Sealer is an error, never
a capsule without the signature or the seal that was asked for. A panic
while evaluating the signature or the seal fails only that part, F1 or
S2, not both. OpenOptions.Accept sees the verdicts before step 18 and can
refuse to publish the files.
- extension.CheckWrite, the rule of encoders of spec 72: the writers of
capsules and .dkk files refuse datekeys.note and datekeys.capsule outside
the arrays where they are registered, or with invalid data.
- CLI: encrypt -sign shows the author key and the code of AUTHOR_MESSAGE
before it signs (rule 20); decrypt -expect-author compares the key of an
F4 and writes nothing unless it matches; decrypt notifies a public note
that it does not show; the lines of the verdicts break at the last space
that fits, each row after the first behind a mark, so that the terminal
never breaks them; L is the payload, not the content.
- locator: a reader rejects an address that breaks 44.1 and keeps the
others; addresses refuse the special-purpose blocks of IANA, IPv6 outside
2000::/3, localhost and local names, characters outside RFC 3986, dot
segments, and a CID that does not decode to version 1 and a multihash;
ParseInfo checks that the locator is an age file with one tlock stanza
for the round of its DateKey; Info.Extension reads what it writes; its
errors carry no normative code.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
6 days ago
// Spec §62.1 rule 20: the key and the code of AUTHOR_MESSAGE, before the
// signature.
if code := regexp . MustCompile ( ` AUTHOR_MESSAGE code ([0-9a-f] { 4}-[0-9a-f] { 4})\n ` ) . FindStringSubmatch ( stderr ) ; code == nil || ! strings . Contains ( stderr , "Signing with the author key " + pub + "\n" ) {
t . Errorf ( "encrypt -sign does not show the key and the code:\n%s" , stderr )
}
// The passphrase from the standard input.
stdin = strings . NewReader ( "una contraseña larga\n" )
t . Cleanup ( func ( ) { stdin = os . Stdin } )
dkc2 := filepath . Join ( dir , "c2.dkc" )
if _ , stderr , err := cli ( t , genesis , "encrypt" , "-at" , unlock . Format ( time . RFC3339 ) , "-in" , in , "-out" , dkc2 , "-sign" , keyFile , "-sign-pass-file" , "-" , "-large-area" ) ; err != nil {
t . Fatalf ( "%v\n%s" , err , stderr )
}
Review fixes: author keys, the writer, the CLI, extensions and the locator
Fixes of the review of the session of 1 and 2 October that the text of
spec v0.11 already asks for:
- authorkey: String and GoString hide the secret key, which only Secret
returns; ParsePublic refuses a key that is not a point of the curve
(ed25519strict.OnCurve, checked against the square root of testkit).
- capsule: a typed nil in AuthorKey, CMSSigner or Sealer is an error, never
a capsule without the signature or the seal that was asked for. A panic
while evaluating the signature or the seal fails only that part, F1 or
S2, not both. OpenOptions.Accept sees the verdicts before step 18 and can
refuse to publish the files.
- extension.CheckWrite, the rule of encoders of spec 72: the writers of
capsules and .dkk files refuse datekeys.note and datekeys.capsule outside
the arrays where they are registered, or with invalid data.
- CLI: encrypt -sign shows the author key and the code of AUTHOR_MESSAGE
before it signs (rule 20); decrypt -expect-author compares the key of an
F4 and writes nothing unless it matches; decrypt notifies a public note
that it does not show; the lines of the verdicts break at the last space
that fits, each row after the first behind a mark, so that the terminal
never breaks them; L is the payload, not the content.
- locator: a reader rejects an address that breaks 44.1 and keeps the
others; addresses refuse the special-purpose blocks of IANA, IPv6 outside
2000::/3, localhost and local names, characters outside RFC 3986, dot
segments, and a CID that does not decode to version 1 and a multihash;
ParseInfo checks that the locator is an age file with one tlock stanza
for the round of its DateKey; Info.Extension reads what it writes; its
errors carry no normative code.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
6 days ago
// The expected key is not a saved one: the line is F4, with the whole key.
// A capsule that is not signed with it writes nothing.
for i , tc := range [ ] struct {
file , expect , want string
fails bool
} {
{ dkc , "" , "Firmado con la clave " + pub , false } ,
Review fixes: author keys, the writer, the CLI, extensions and the locator
Fixes of the review of the session of 1 and 2 October that the text of
spec v0.11 already asks for:
- authorkey: String and GoString hide the secret key, which only Secret
returns; ParsePublic refuses a key that is not a point of the curve
(ed25519strict.OnCurve, checked against the square root of testkit).
- capsule: a typed nil in AuthorKey, CMSSigner or Sealer is an error, never
a capsule without the signature or the seal that was asked for. A panic
while evaluating the signature or the seal fails only that part, F1 or
S2, not both. OpenOptions.Accept sees the verdicts before step 18 and can
refuse to publish the files.
- extension.CheckWrite, the rule of encoders of spec 72: the writers of
capsules and .dkk files refuse datekeys.note and datekeys.capsule outside
the arrays where they are registered, or with invalid data.
- CLI: encrypt -sign shows the author key and the code of AUTHOR_MESSAGE
before it signs (rule 20); decrypt -expect-author compares the key of an
F4 and writes nothing unless it matches; decrypt notifies a public note
that it does not show; the lines of the verdicts break at the last space
that fits, each row after the first behind a mark, so that the terminal
never breaks them; L is the payload, not the content.
- locator: a reader rejects an address that breaks 44.1 and keeps the
others; addresses refuse the special-purpose blocks of IANA, IPv6 outside
2000::/3, localhost and local names, characters outside RFC 3986, dot
segments, and a CID that does not decode to version 1 and a multihash;
ParseInfo checks that the locator is an age file with one tlock stanza
for the round of its DateKey; Info.Extension reads what it writes; its
errors carry no normative code.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
6 days ago
{ dkc , pub , "Firmado con la clave " + pub , false } ,
{ dkc2 , pub , "Firmado con la clave " + pub , false } ,
{ dkc , otherPub , "Firmado con la clave " + pub , true } ,
} {
Review fixes: author keys, the writer, the CLI, extensions and the locator
Fixes of the review of the session of 1 and 2 October that the text of
spec v0.11 already asks for:
- authorkey: String and GoString hide the secret key, which only Secret
returns; ParsePublic refuses a key that is not a point of the curve
(ed25519strict.OnCurve, checked against the square root of testkit).
- capsule: a typed nil in AuthorKey, CMSSigner or Sealer is an error, never
a capsule without the signature or the seal that was asked for. A panic
while evaluating the signature or the seal fails only that part, F1 or
S2, not both. OpenOptions.Accept sees the verdicts before step 18 and can
refuse to publish the files.
- extension.CheckWrite, the rule of encoders of spec 72: the writers of
capsules and .dkk files refuse datekeys.note and datekeys.capsule outside
the arrays where they are registered, or with invalid data.
- CLI: encrypt -sign shows the author key and the code of AUTHOR_MESSAGE
before it signs (rule 20); decrypt -expect-author compares the key of an
F4 and writes nothing unless it matches; decrypt notifies a public note
that it does not show; the lines of the verdicts break at the last space
that fits, each row after the first behind a mark, so that the terminal
never breaks them; L is the payload, not the content.
- locator: a reader rejects an address that breaks 44.1 and keeps the
others; addresses refuse the special-purpose blocks of IANA, IPv6 outside
2000::/3, localhost and local names, characters outside RFC 3986, dot
segments, and a CID that does not decode to version 1 and a multihash;
ParseInfo checks that the locator is an age file with one tlock stanza
for the round of its DateKey; Info.Extension reads what it writes; its
errors carry no normative code.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
6 days ago
out := filepath . Join ( dir , "out" + string ( rune ( 'a' + i ) ) )
args := [ ] string { "decrypt" , "-in" , tc . file , "-out" , out , "-relay" , relay ( t ) }
if tc . expect != "" {
args = append ( args , "-expect-author" , tc . expect )
}
stdout , _ , err := cli ( t , later , args ... )
Review fixes: author keys, the writer, the CLI, extensions and the locator
Fixes of the review of the session of 1 and 2 October that the text of
spec v0.11 already asks for:
- authorkey: String and GoString hide the secret key, which only Secret
returns; ParsePublic refuses a key that is not a point of the curve
(ed25519strict.OnCurve, checked against the square root of testkit).
- capsule: a typed nil in AuthorKey, CMSSigner or Sealer is an error, never
a capsule without the signature or the seal that was asked for. A panic
while evaluating the signature or the seal fails only that part, F1 or
S2, not both. OpenOptions.Accept sees the verdicts before step 18 and can
refuse to publish the files.
- extension.CheckWrite, the rule of encoders of spec 72: the writers of
capsules and .dkk files refuse datekeys.note and datekeys.capsule outside
the arrays where they are registered, or with invalid data.
- CLI: encrypt -sign shows the author key and the code of AUTHOR_MESSAGE
before it signs (rule 20); decrypt -expect-author compares the key of an
F4 and writes nothing unless it matches; decrypt notifies a public note
that it does not show; the lines of the verdicts break at the last space
that fits, each row after the first behind a mark, so that the terminal
never breaks them; L is the payload, not the content.
- locator: a reader rejects an address that breaks 44.1 and keeps the
others; addresses refuse the special-purpose blocks of IANA, IPv6 outside
2000::/3, localhost and local names, characters outside RFC 3986, dot
segments, and a CID that does not decode to version 1 and a multihash;
ParseInfo checks that the locator is an age file with one tlock stanza
for the round of its DateKey; Info.Extension reads what it writes; its
errors carry no normative code.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
6 days ago
if ( err != nil ) != tc . fails || ! strings . Contains ( joined ( stdout ) , tc . want ) {
t . Errorf ( "case %d: %v\n%s" , i , err , stdout )
}
Review fixes: author keys, the writer, the CLI, extensions and the locator
Fixes of the review of the session of 1 and 2 October that the text of
spec v0.11 already asks for:
- authorkey: String and GoString hide the secret key, which only Secret
returns; ParsePublic refuses a key that is not a point of the curve
(ed25519strict.OnCurve, checked against the square root of testkit).
- capsule: a typed nil in AuthorKey, CMSSigner or Sealer is an error, never
a capsule without the signature or the seal that was asked for. A panic
while evaluating the signature or the seal fails only that part, F1 or
S2, not both. OpenOptions.Accept sees the verdicts before step 18 and can
refuse to publish the files.
- extension.CheckWrite, the rule of encoders of spec 72: the writers of
capsules and .dkk files refuse datekeys.note and datekeys.capsule outside
the arrays where they are registered, or with invalid data.
- CLI: encrypt -sign shows the author key and the code of AUTHOR_MESSAGE
before it signs (rule 20); decrypt -expect-author compares the key of an
F4 and writes nothing unless it matches; decrypt notifies a public note
that it does not show; the lines of the verdicts break at the last space
that fits, each row after the first behind a mark, so that the terminal
never breaks them; L is the payload, not the content.
- locator: a reader rejects an address that breaks 44.1 and keeps the
others; addresses refuse the special-purpose blocks of IANA, IPv6 outside
2000::/3, localhost and local names, characters outside RFC 3986, dot
segments, and a CID that does not decode to version 1 and a multihash;
ParseInfo checks that the locator is an age file with one tlock stanza
for the round of its DateKey; Info.Extension reads what it writes; its
errors carry no normative code.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
6 days ago
if strings . Contains ( stdout , "guardaste" ) {
t . Errorf ( "case %d: the expected key shown as a saved one:\n%s" , i , stdout )
}
if tc . fails {
if err == nil || ! strings . Contains ( err . Error ( ) , "not signed with the expected key" ) || ! strings . Contains ( err . Error ( ) , "nothing was written" ) {
t . Errorf ( "case %d: %v" , i , err )
}
if _ , err := os . Stat ( out ) ; ! os . IsNotExist ( err ) {
t . Errorf ( "case %d: %s was created: %v" , i , out , err )
}
}
}
Review fixes: author keys, the writer, the CLI, extensions and the locator
Fixes of the review of the session of 1 and 2 October that the text of
spec v0.11 already asks for:
- authorkey: String and GoString hide the secret key, which only Secret
returns; ParsePublic refuses a key that is not a point of the curve
(ed25519strict.OnCurve, checked against the square root of testkit).
- capsule: a typed nil in AuthorKey, CMSSigner or Sealer is an error, never
a capsule without the signature or the seal that was asked for. A panic
while evaluating the signature or the seal fails only that part, F1 or
S2, not both. OpenOptions.Accept sees the verdicts before step 18 and can
refuse to publish the files.
- extension.CheckWrite, the rule of encoders of spec 72: the writers of
capsules and .dkk files refuse datekeys.note and datekeys.capsule outside
the arrays where they are registered, or with invalid data.
- CLI: encrypt -sign shows the author key and the code of AUTHOR_MESSAGE
before it signs (rule 20); decrypt -expect-author compares the key of an
F4 and writes nothing unless it matches; decrypt notifies a public note
that it does not show; the lines of the verdicts break at the last space
that fits, each row after the first behind a mark, so that the terminal
never breaks them; L is the payload, not the content.
- locator: a reader rejects an address that breaks 44.1 and keeps the
others; addresses refuse the special-purpose blocks of IANA, IPv6 outside
2000::/3, localhost and local names, characters outside RFC 3986, dot
segments, and a CID that does not decode to version 1 and a multihash;
ParseInfo checks that the locator is an age file with one tlock stanza
for the round of its DateKey; Info.Extension reads what it writes; its
errors carry no normative code.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
6 days ago
// An unsigned capsule does not meet -expect-author, and writes nothing.
plain := filepath . Join ( dir , "plain.dkc" )
if _ , _ , err := cli ( t , genesis , "encrypt" , "-at" , unlock . Format ( time . RFC3339 ) , "-in" , in , "-out" , plain ) ; err != nil {
t . Fatal ( err )
}
Review fixes: author keys, the writer, the CLI, extensions and the locator
Fixes of the review of the session of 1 and 2 October that the text of
spec v0.11 already asks for:
- authorkey: String and GoString hide the secret key, which only Secret
returns; ParsePublic refuses a key that is not a point of the curve
(ed25519strict.OnCurve, checked against the square root of testkit).
- capsule: a typed nil in AuthorKey, CMSSigner or Sealer is an error, never
a capsule without the signature or the seal that was asked for. A panic
while evaluating the signature or the seal fails only that part, F1 or
S2, not both. OpenOptions.Accept sees the verdicts before step 18 and can
refuse to publish the files.
- extension.CheckWrite, the rule of encoders of spec 72: the writers of
capsules and .dkk files refuse datekeys.note and datekeys.capsule outside
the arrays where they are registered, or with invalid data.
- CLI: encrypt -sign shows the author key and the code of AUTHOR_MESSAGE
before it signs (rule 20); decrypt -expect-author compares the key of an
F4 and writes nothing unless it matches; decrypt notifies a public note
that it does not show; the lines of the verdicts break at the last space
that fits, each row after the first behind a mark, so that the terminal
never breaks them; L is the payload, not the content.
- locator: a reader rejects an address that breaks 44.1 and keeps the
others; addresses refuse the special-purpose blocks of IANA, IPv6 outside
2000::/3, localhost and local names, characters outside RFC 3986, dot
segments, and a CID that does not decode to version 1 and a multihash;
ParseInfo checks that the locator is an age file with one tlock stanza
for the round of its DateKey; Info.Extension reads what it writes; its
errors carry no normative code.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
6 days ago
stdout , _ , err := cli ( t , later , "decrypt" , "-in" , plain , "-out" , filepath . Join ( dir , "outz" ) , "-relay" , relay ( t ) , "-expect-author" , pub )
if err == nil || ! strings . Contains ( stdout , "Sin firma de autor." ) {
t . Errorf ( "an unsigned capsule met -expect-author: %v\n%s" , err , stdout )
}
if _ , err := os . Stat ( filepath . Join ( dir , "outz" ) ) ; ! os . IsNotExist ( err ) {
t . Errorf ( "the files of an unsigned capsule were written: %v" , err )
}
if _ , _ , err := cli ( t , later , "decrypt" , "-in" , plain , "-out" , filepath . Join ( dir , "outy" ) , "-relay" , relay ( t ) , "-expect-author" , "dkauthor1x" ) ; err == nil {
t . Error ( "a malformed -expect-author was accepted" )
}
}
// Spec v0.11 §24.1: -note puts the public note in clear, inspect shows it
// before the date with its warning, and decrypt shows it as text of the
// creator after the date.
func TestPublicNoteCLI ( t * testing . T ) {
dir := t . TempDir ( )
in := filepath . Join ( dir , "carta.txt" )
os . WriteFile ( in , [ ] byte ( "con nota" ) , 0 o600 )
p := profile . Quicknet ( )
unlock := time . Unix ( p . GenesisTime + 999 * 3 , 0 ) . UTC ( ) // round 1000
genesis := time . Unix ( p . GenesisTime , 0 )
dkc := filepath . Join ( dir , "n.dkc" )
if _ , stderr , err := cli ( t , genesis , "encrypt" , "-at" , unlock . Format ( time . RFC3339 ) , "-in" , in , "-out" , dkc , "-note" , "Cartas del viaje a Lisboa" ) ; err != nil {
t . Fatalf ( "%v\n%s" , err , stderr )
}
if _ , _ , err := cli ( t , genesis , "encrypt" , "-at" , unlock . Format ( time . RFC3339 ) , "-in" , in , "-out" , filepath . Join ( dir , "bad.dkc" ) , "-note" , "dos\nlíneas" ) ; err == nil {
t . Error ( "a note of two lines was written" )
}
out , _ , err := cli ( t , genesis , "inspect" , "-in" , dkc )
Review fixes: addresses, safe integers, the note on screen, -expect-author, author keys
CheckURI works on the raw authority, as an HTTP client reads it: no percent
signs, userinfo or backslashes, a host of letters, digits and hyphens or a
public IP literal, a port from 1 to 65535, and Host returns that host. The
integers of the locator stop at 2^53 - 1, and Info.Extension refuses what
ParseInfo would. extension.Standard validates datekeys.capsule through
locator.Standard, and Info.OpenLocator ties the locator to the round of its
own DateKey.
inspect shows the public note as text of the creator, with its prefix and
wrapping and the warning, and says when a note is unusable. encrypt -note
warns that it is public. decrypt -expect-author fails before the release
is requested when the capsule is not format 3. Author key files are read
with the work factor of the spec as their maximum, the passphrase is not
read from a terminal, and two copies of secrets are cleared.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
6 days ago
if err != nil || ! strings . Contains ( out , "┌ " + noteTitle + "\n│ Cartas del viaje a Lisboa\n└\n Nadie puede comprobar antes de la fecha quién creó la cápsula ni si va firmada." ) {
t . Errorf ( "inspect: %v\n%s" , err , out )
}
js , _ , err := cli ( t , genesis , "inspect" , "-in" , dkc , "-json" )
if err != nil || ! strings . Contains ( js , ` "public_note": "Cartas del viaje a Lisboa" ` ) {
t . Errorf ( "inspect -json: %v\n%s" , err , js )
}
shown , _ , err := cli ( t , later , "decrypt" , "-in" , dkc , "-out" , filepath . Join ( dir , "out" ) , "-relay" , relay ( t ) )
if err != nil || ! strings . Contains ( shown , "┌ " + noteTitle + "\n│ Cartas del viaje a Lisboa\n└\n" ) {
t . Errorf ( "decrypt: %v\n%s" , err , shown )
}
}
Spec v0.11 approved: the text of the review, SpecVersion 0.11 and its SHA-256
The author approved the text and the six open decisions on 1 October 2026.
The spec says now what the review left open: the form of the CMS signature
and of the TSTInfo field by field, the ESSCertIDv2 with SHA-256 written, the
padding of the locator at its boundaries, base32 CIDs, the addresses read
without decoding, the issuer shown by the rules of the holder, and the area
decided after the signatures. SpecVersion is 0.11, the records of fixtures
and vectors say so, and decrypt shows an mtime later than a valid seal as an
inconsistency, which 29.7 asks as a SHOULD.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
6 days ago
// Spec v0.11 §29.7: under a valid seal, an mtime later than the seal is shown
// as an inconsistency. format3_sealed has a file dated 2026, sealed in 2023.
func TestMTimeAfterSeal ( t * testing . T ) {
out := filepath . Join ( t . TempDir ( ) , "out" )
shown , _ , err := cli ( t , later , "decrypt" , "-in" , filepath . Join ( fixtures , "format3_sealed.dkc" ) , "-out" , out , "-relay" , relay ( t ) )
Review fixes: author keys, the writer, the CLI, extensions and the locator
Fixes of the review of the session of 1 and 2 October that the text of
spec v0.11 already asks for:
- authorkey: String and GoString hide the secret key, which only Secret
returns; ParsePublic refuses a key that is not a point of the curve
(ed25519strict.OnCurve, checked against the square root of testkit).
- capsule: a typed nil in AuthorKey, CMSSigner or Sealer is an error, never
a capsule without the signature or the seal that was asked for. A panic
while evaluating the signature or the seal fails only that part, F1 or
S2, not both. OpenOptions.Accept sees the verdicts before step 18 and can
refuse to publish the files.
- extension.CheckWrite, the rule of encoders of spec 72: the writers of
capsules and .dkk files refuse datekeys.note and datekeys.capsule outside
the arrays where they are registered, or with invalid data.
- CLI: encrypt -sign shows the author key and the code of AUTHOR_MESSAGE
before it signs (rule 20); decrypt -expect-author compares the key of an
F4 and writes nothing unless it matches; decrypt notifies a public note
that it does not show; the lines of the verdicts break at the last space
that fits, each row after the first behind a mark, so that the terminal
never breaks them; L is the payload, not the content.
- locator: a reader rejects an address that breaks 44.1 and keeps the
others; addresses refuse the special-purpose blocks of IANA, IPv6 outside
2000::/3, localhost and local names, characters outside RFC 3986, dot
segments, and a CID that does not decode to version 1 and a multihash;
ParseInfo checks that the locator is an age file with one tlock stanza
for the round of its DateKey; Info.Extension reads what it writes; its
errors carry no normative code.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
6 days ago
if err != nil || ! strings . Contains ( joined ( shown ) , "aviso: la fecha de modificación de un fichero es posterior al sello (2023-08-23T15:09:27Z)" ) {
Spec v0.11 approved: the text of the review, SpecVersion 0.11 and its SHA-256
The author approved the text and the six open decisions on 1 October 2026.
The spec says now what the review left open: the form of the CMS signature
and of the TSTInfo field by field, the ESSCertIDv2 with SHA-256 written, the
padding of the locator at its boundaries, base32 CIDs, the addresses read
without decoding, the issuer shown by the rules of the holder, and the area
decided after the signatures. SpecVersion is 0.11, the records of fixtures
and vectors say so, and decrypt shows an mtime later than a valid seal as an
inconsistency, which 29.7 asks as a SHOULD.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
6 days ago
t . Errorf ( "%v\n%s" , err , shown )
}
clean := filepath . Join ( t . TempDir ( ) , "out" )
shown , _ , err = cli ( t , later , "decrypt" , "-in" , filepath . Join ( fixtures , "format3_single.dkc" ) , "-out" , clean , "-relay" , relay ( t ) )
if err != nil || strings . Contains ( shown , "no es coherente" ) {
t . Errorf ( "an unsealed capsule: %v\n%s" , err , shown )
}
}