diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml new file mode 100644 index 0000000..4e46718 --- /dev/null +++ b/.gitea/workflows/ci.yml @@ -0,0 +1,114 @@ +# Gitea Actions workflow (Gitea 1.21 or later with a registered act_runner). +# Actions come from the gitea.com mirrors; every tool is installed with the Go +# toolchain from its module. The same checks run on any machine with +# scripts/check.sh, which is the gate while no runner is available. +name: ci + +on: + push: + branches: [main] + pull_request: + +jobs: + test: + name: test (Go ${{ matrix.go }}) + strategy: + fail-fast: false + matrix: + # Add windows or macos runner labels here when such runners exist. + go: [stable, oldstable] + runs-on: ubuntu-latest + steps: + - uses: https://gitea.com/actions/checkout@v4 + - uses: https://gitea.com/actions/setup-go@v5 + with: + go-version: ${{ matrix.go }} + - run: go mod verify + - run: go vet ./... + - run: go test -race -count=1 ./... + + coverage: + runs-on: ubuntu-latest + steps: + - uses: https://gitea.com/actions/checkout@v4 + - uses: https://gitea.com/actions/setup-go@v5 + with: + go-version: stable + - name: at least 90 % in codec, capsule, accesskey, datekey and agewrap + run: | + set -euo pipefail + for pkg in codec capsule accesskey datekey agewrap; do + pct=$(go test -count=1 -cover "./$pkg" | sed -n 's/.*coverage: \([0-9.]*\)% of statements.*/\1/p') + echo "$pkg: $pct%" + awk -v p="$pct" 'BEGIN { exit !(p >= 90) }' + done + + lint: + runs-on: ubuntu-latest + steps: + - uses: https://gitea.com/actions/checkout@v4 + - uses: https://gitea.com/actions/setup-go@v5 + with: + go-version: stable + - run: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.14.0 + - run: golangci-lint run + - name: gosec (advisory) + continue-on-error: true + run: golangci-lint run --enable-only gosec + + vuln: + runs-on: ubuntu-latest + steps: + - uses: https://gitea.com/actions/checkout@v4 + - uses: https://gitea.com/actions/setup-go@v5 + with: + go-version: stable + - run: go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./... + + fuzz-short: + runs-on: ubuntu-latest + steps: + - uses: https://gitea.com/actions/checkout@v4 + - uses: https://gitea.com/actions/setup-go@v5 + with: + go-version: stable + - name: every parser, 20 s each + run: ./scripts/fuzz.sh 20s + + interop: + runs-on: ubuntu-latest + steps: + - uses: https://gitea.com/actions/checkout@v4 + - uses: https://gitea.com/actions/setup-go@v5 + with: + go-version: stable + - name: official age and tle command-line tools + run: | + go install filippo.io/age/cmd/age@v1.3.2 + go install github.com/drand/tlock/cmd/tle@v1.2.0 + go test -tags interop -count=1 -v ./capsule -run Interop + + sbom: + runs-on: ubuntu-latest + steps: + - uses: https://gitea.com/actions/checkout@v4 + - uses: https://gitea.com/actions/setup-go@v5 + with: + go-version: stable + - run: go run github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.12.0 mod -licenses -json -output sbom.cdx.json + - uses: https://gitea.com/actions/upload-artifact@v4 + with: + name: sbom + path: sbom.cdx.json + + fixtures: + name: vectors reproduce and fixtures are frozen + runs-on: ubuntu-latest + steps: + - uses: https://gitea.com/actions/checkout@v4 + - uses: https://gitea.com/actions/setup-go@v5 + with: + go-version: stable + - run: | + go run ./internal/testkit/genfixtures -out testdata + git diff --exit-code testdata diff --git a/.gitea/workflows/nightly.yml b/.gitea/workflows/nightly.yml new file mode 100644 index 0000000..62fed05 --- /dev/null +++ b/.gitea/workflows/nightly.yml @@ -0,0 +1,58 @@ +# Gitea Actions workflow (Gitea 1.21 or later with a registered act_runner). +name: nightly + +on: + schedule: + - cron: "17 3 * * *" + workflow_dispatch: + +jobs: + integration: + name: live Quicknet + runs-on: ubuntu-latest + steps: + - uses: https://gitea.com/actions/checkout@v4 + - uses: https://gitea.com/actions/setup-go@v5 + with: + go-version: stable + - run: go test -tags integration -count=1 -v -timeout 10m ./capsule ./provider/drand -run Live + + fuzz-long: + runs-on: ubuntu-latest + timeout-minutes: 120 + steps: + - uses: https://gitea.com/actions/checkout@v4 + - uses: https://gitea.com/actions/setup-go@v5 + with: + go-version: stable + - name: every parser, 10 min each + env: + FUZZ_MINIMIZE: 10s + run: ./scripts/fuzz.sh 10m + - name: keep failing inputs + if: failure() + uses: https://gitea.com/actions/upload-artifact@v4 + with: + name: fuzz-corpus + path: "**/testdata/fuzz/**" + + vuln: + runs-on: ubuntu-latest + steps: + - uses: https://gitea.com/actions/checkout@v4 + - uses: https://gitea.com/actions/setup-go@v5 + with: + go-version: stable + - run: go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./... + + updates: + name: dependency updates available + runs-on: ubuntu-latest + steps: + - uses: https://gitea.com/actions/checkout@v4 + - uses: https://gitea.com/actions/setup-go@v5 + with: + go-version: stable + # Informational. Any change to age, tlock, drand or kyber is reviewed by + # hand against SECURITY.md before it is applied. + - run: go list -m -u all | grep '\[' || echo "no updates" diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml new file mode 100644 index 0000000..47c7eec --- /dev/null +++ b/.gitea/workflows/release.yml @@ -0,0 +1,29 @@ +# Gitea Actions workflow (Gitea 1.21 or later with a registered act_runner). +# Publishes a release on this Gitea server (.goreleaser.yaml, gitea_urls). +# Repository secrets: GITEA_TOKEN (a token with write access to releases), +# COSIGN_PRIVATE_KEY and COSIGN_PASSWORD (the project's cosign key). +name: release + +on: + push: + tags: ["v*"] + +jobs: + release: + runs-on: ubuntu-latest + steps: + - uses: https://gitea.com/actions/checkout@v4 + with: + fetch-depth: 0 + - uses: https://gitea.com/actions/setup-go@v5 + with: + go-version-file: go.mod + - run: go test -count=1 ./... + - run: go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.12.0 + - run: go install github.com/sigstore/cosign/v2/cmd/cosign@v2.6.5 + - run: go install github.com/goreleaser/goreleaser/v2@v2.18.2 + - run: goreleaser release --clean + env: + GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} + COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }} + COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }} diff --git a/.github/dependabot.yml b/.github/dependabot.yml deleted file mode 100644 index fedbbe7..0000000 --- a/.github/dependabot.yml +++ /dev/null @@ -1,18 +0,0 @@ -# Patch updates only. Any change to age, tlock, drand or kyber is reviewed by -# hand against SECURITY.md before merging, even when Dependabot proposes it. -version: 2 -updates: - - package-ecosystem: gomod - directory: / - schedule: - interval: weekly - open-pull-requests-limit: 5 - labels: [dependencies] - ignore: - - dependency-name: "*" - update-types: ["version-update:semver-major", "version-update:semver-minor"] - - package-ecosystem: github-actions - directory: / - schedule: - interval: weekly - labels: [dependencies] diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml deleted file mode 100644 index b67d84d..0000000 --- a/.github/workflows/ci.yml +++ /dev/null @@ -1,135 +0,0 @@ -name: ci - -on: - push: - branches: [main] - pull_request: - -permissions: - contents: read - -jobs: - test: - name: test (${{ matrix.os }}, Go ${{ matrix.go }}) - strategy: - fail-fast: false - matrix: - os: [ubuntu-latest, macos-latest, windows-latest] - go: [stable, oldstable] - runs-on: ${{ matrix.os }} - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: ${{ matrix.go }} - - run: go mod verify - - run: go vet ./... - - run: go test -race -count=1 ./... - - coverage: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: stable - - name: at least 90 % in codec, capsule, accesskey, datekey and agewrap - shell: bash - run: | - set -euo pipefail - for pkg in codec capsule accesskey datekey agewrap; do - pct=$(go test -count=1 -cover "./$pkg" | sed -n 's/.*coverage: \([0-9.]*\)% of statements.*/\1/p') - echo "$pkg: $pct%" - awk -v p="$pct" 'BEGIN { exit !(p >= 90) }' - done - - lint: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: stable - - uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0 - with: - version: v2.14.0 - - name: gosec (advisory) - continue-on-error: true - uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0 - with: - version: v2.14.0 - args: --enable-only gosec - - vuln: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: stable - - run: go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./... - - fuzz-short: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: stable - - name: every parser, 20 s each - shell: bash - run: ./scripts/fuzz.sh 20s - - interop: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: stable - - name: official age and tle command-line tools - run: | - go install filippo.io/age/cmd/age@v1.3.2 - go install github.com/drand/tlock/cmd/tle@v1.2.0 - go test -tags interop -count=1 -v ./capsule -run Interop - - sbom: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: stable - - run: go run github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.12.0 mod -licenses -json -output sbom.cdx.json - - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - with: - name: sbom - path: sbom.cdx.json - - fixtures: - name: vectors reproduce and fixtures are frozen - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: stable - - run: | - go run ./internal/testkit/genfixtures -out testdata - git diff --exit-code testdata diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml deleted file mode 100644 index f7fa6fc..0000000 --- a/.github/workflows/nightly.yml +++ /dev/null @@ -1,55 +0,0 @@ -name: nightly - -on: - schedule: - - cron: "17 3 * * *" - workflow_dispatch: - -permissions: - contents: read - -jobs: - integration: - name: live Quicknet - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: stable - - run: go test -tags integration -count=1 -v -timeout 10m ./capsule ./provider/drand -run Live - - fuzz-long: - runs-on: ubuntu-latest - timeout-minutes: 120 - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: stable - - name: every parser, 10 min each - shell: bash - env: - FUZZ_MINIMIZE: 10s - run: ./scripts/fuzz.sh 10m - - name: keep failing inputs - if: failure() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - with: - name: fuzz-corpus - path: "**/testdata/fuzz/**" - - vuln: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: stable - - run: go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./... diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml deleted file mode 100644 index 8f0d6be..0000000 --- a/.github/workflows/release.yml +++ /dev/null @@ -1,32 +0,0 @@ -name: release - -on: - push: - tags: ["v*"] - -permissions: - contents: read - -jobs: - release: - runs-on: ubuntu-latest - permissions: - contents: write # publish the GitHub release - id-token: write # keyless cosign signature - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - fetch-depth: 0 - persist-credentials: false - - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version-file: go.mod - - run: go test -count=1 ./... - - run: go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.12.0 - - uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 - - uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3 - with: - version: "~> v2" - args: release --clean - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.golangci.yml b/.golangci.yml index 945e800..a53006b 100644 --- a/.golangci.yml +++ b/.golangci.yml @@ -25,4 +25,4 @@ formatters: settings: goimports: local-prefixes: - - github.com/datekeys/datekeys-go + - g.activething.com/go/DateKeys diff --git a/.goreleaser.yaml b/.goreleaser.yaml index 72a973e..0c934ec 100644 --- a/.goreleaser.yaml +++ b/.goreleaser.yaml @@ -46,20 +46,28 @@ sboms: args: ["bin", "-json", "-output", "$document", "$artifact"] signs: - # Keyless signature of the checksum file with the workflow's OIDC identity. + # Signature of the checksum file with the project's cosign key, supplied at + # release time through COSIGN_PRIVATE_KEY and COSIGN_PASSWORD. - cmd: cosign artifacts: checksum signature: "${artifact}.sig" - certificate: "${artifact}.pem" args: - sign-blob + - --key=env://COSIGN_PRIVATE_KEY - --output-signature=${signature} - - --output-certificate=${certificate} - ${artifact} - --yes changelog: disable: true +# Releases are published on the project's Gitea server. +gitea_urls: + api: https://g.activething.com/api/v1 + download: https://g.activething.com + # The server presents a certificate Go and goreleaser do not trust by + # default. Remove this when a trusted certificate is installed. + skip_tls_verify: true + release: prerelease: auto diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 4d837d0..042f05e 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -38,6 +38,7 @@ dependencies are not accepted without prior discussion. ## Tests ```bash +./scripts/check.sh # everything ci.yml runs, on any machine; run before pushing go test -race ./... FUZZ_PARALLEL=4 ./scripts/fuzz.sh 60s # every parser; each worker uses a 100 MB temp file go test -tags interop ./capsule # needs the age and tle CLIs diff --git a/README.es.md b/README.es.md index 86bd44c..00f9dc7 100644 --- a/README.es.md +++ b/README.es.md @@ -54,9 +54,14 @@ PAYLOAD_AGE = age(X25519 R_PAYLOAD → tus datos), en streaming ## CLI ```bash -go install github.com/datekeys/datekeys-go/cmd/datekeys@latest +go install g.activething.com/go/DateKeys/cmd/datekeys@latest ``` +El módulo se sirve desde el Gitea del proyecto, cuyo certificado Go no +reconoce por defecto. Define `GOPRIVATE=g.activething.com` para que el proxy y +la base de datos de sumas de Go no intervengan, e instala el certificado del +servidor o, en una red de confianza, define `GOINSECURE=g.activething.com`. + ```bash datekeys datekey resolve -at 2030-01-01T00:00:00Z datekeys encrypt -at 2030-01-01T00:00:00Z -in carta.txt -out carta.dkc diff --git a/README.md b/README.md index 6b8f889..f4a4f44 100644 --- a/README.md +++ b/README.md @@ -53,9 +53,14 @@ PAYLOAD_AGE = age(X25519 R_PAYLOAD → your data), streamed ## CLI ```bash -go install github.com/datekeys/datekeys-go/cmd/datekeys@latest +go install g.activething.com/go/DateKeys/cmd/datekeys@latest ``` +The module is served by the project's own Gitea, whose certificate Go does not +trust by default. Set `GOPRIVATE=g.activething.com` so that the Go proxy and +checksum database are bypassed for it, and either install the server's +certificate or, on a trusted network, set `GOINSECURE=g.activething.com`. + ```bash datekeys datekey resolve -at 2030-01-01T00:00:00Z datekeys encrypt -at 2030-01-01T00:00:00Z -in letter.txt -out letter.dkc diff --git a/SECURITY.md b/SECURITY.md index 8786297..d5279da 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -4,10 +4,10 @@ Please report vulnerabilities privately, not in public issues: -- GitHub private vulnerability reporting on this repository (Security → Report - a vulnerability), once the `datekeys` organisation hosts it. -- Until then, contact the maintainers privately and ask for an encrypted - channel. +- Send an e-mail to the maintainers at info@activething.com with "DateKeys + security" in the subject. Ask for an encrypted channel before sending + sensitive material. +- Do not open an issue on the repository for a vulnerability. Include a reproducible case: ideally a `.dkc` or `.dkk` file, or a test in the style of `capsule/mutation_test.go`. We aim to acknowledge reports within @@ -81,6 +81,6 @@ All versions are pinned in `go.mod` and verified through `go.sum`. Changes to - Reproducible builds: `-trimpath`, `CGO_ENABLED=0`, pinned toolchain in CI. - Releases publish SHA-256 checksums and a CycloneDX SBOM, and are signed with - cosign once the organisation's signing identity exists. + cosign using the project's signing key. - The Quicknet root of trust is compiled into the binary and checked against its pinned `profile_hash` (`4147645109798ecbc9f630c2f709835bb5846fe7911a6bd5c5755e25ade2ada4`). diff --git a/accesskey/accesskey.go b/accesskey/accesskey.go index 3bc2db4..78df01c 100644 --- a/accesskey/accesskey.go +++ b/accesskey/accesskey.go @@ -15,10 +15,10 @@ import ( "filippo.io/age" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/agewrap" - "github.com/datekeys/datekeys-go/codec" - "github.com/datekeys/datekeys-go/extension" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/agewrap" + "g.activething.com/go/DateKeys/codec" + "g.activething.com/go/DateKeys/extension" ) // Framing and schema constants (spec §40, §41). diff --git a/accesskey/accesskey_test.go b/accesskey/accesskey_test.go index bfdce09..00e162e 100644 --- a/accesskey/accesskey_test.go +++ b/accesskey/accesskey_test.go @@ -15,13 +15,13 @@ import ( "filippo.io/age" "github.com/fxamacker/cbor/v2" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/accesskey" - "github.com/datekeys/datekeys-go/agewrap" - "github.com/datekeys/datekeys-go/codec" - "github.com/datekeys/datekeys-go/extension" - "github.com/datekeys/datekeys-go/internal/testkit" - "github.com/datekeys/datekeys-go/profile" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/accesskey" + "g.activething.com/go/DateKeys/agewrap" + "g.activething.com/go/DateKeys/codec" + "g.activething.com/go/DateKeys/extension" + "g.activething.com/go/DateKeys/internal/testkit" + "g.activething.com/go/DateKeys/profile" ) const fixtures = "../testdata/fixtures" diff --git a/agewrap/agewrap.go b/agewrap/agewrap.go index d544b7d..e234f35 100644 --- a/agewrap/agewrap.go +++ b/agewrap/agewrap.go @@ -35,10 +35,10 @@ import ( "github.com/drand/kyber" "github.com/drand/tlock" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/codec/bech32" - "github.com/datekeys/datekeys-go/profile" - "github.com/datekeys/datekeys-go/provider" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/codec/bech32" + "g.activething.com/go/DateKeys/profile" + "g.activething.com/go/DateKeys/provider" ) // Stanza types of V1. diff --git a/agewrap/agewrap_test.go b/agewrap/agewrap_test.go index 3997693..9b86793 100644 --- a/agewrap/agewrap_test.go +++ b/agewrap/agewrap_test.go @@ -13,11 +13,11 @@ import ( "github.com/drand/kyber" "github.com/drand/tlock" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/agewrap" - "github.com/datekeys/datekeys-go/internal/testkit" - "github.com/datekeys/datekeys-go/profile" - "github.com/datekeys/datekeys-go/provider" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/agewrap" + "g.activething.com/go/DateKeys/internal/testkit" + "g.activething.com/go/DateKeys/profile" + "g.activething.com/go/DateKeys/provider" ) // tlockNetwork adapts the pinned profile to tlock.Network, to run the diff --git a/capsule/conformance_test.go b/capsule/conformance_test.go index 7b0904b..e1ac99c 100644 --- a/capsule/conformance_test.go +++ b/capsule/conformance_test.go @@ -14,12 +14,12 @@ import ( "filippo.io/age" - "github.com/datekeys/datekeys-go/accesskey" - "github.com/datekeys/datekeys-go/agewrap" - "github.com/datekeys/datekeys-go/capsule" - "github.com/datekeys/datekeys-go/internal/testkit" - "github.com/datekeys/datekeys-go/profile" - "github.com/datekeys/datekeys-go/provider" + "g.activething.com/go/DateKeys/accesskey" + "g.activething.com/go/DateKeys/agewrap" + "g.activething.com/go/DateKeys/capsule" + "g.activething.com/go/DateKeys/internal/testkit" + "g.activething.com/go/DateKeys/profile" + "g.activething.com/go/DateKeys/provider" ) const fixtureDir = "../testdata/fixtures" diff --git a/capsule/encrypt.go b/capsule/encrypt.go index 8d65ec4..8a28f05 100644 --- a/capsule/encrypt.go +++ b/capsule/encrypt.go @@ -11,12 +11,12 @@ import ( "filippo.io/age" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/accesskey" - "github.com/datekeys/datekeys-go/agewrap" - "github.com/datekeys/datekeys-go/datekey" - "github.com/datekeys/datekeys-go/extension" - "github.com/datekeys/datekeys-go/profile" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/accesskey" + "g.activething.com/go/DateKeys/agewrap" + "g.activething.com/go/DateKeys/datekey" + "g.activething.com/go/DateKeys/extension" + "g.activething.com/go/DateKeys/profile" ) // EncryptOptions configures Encrypt. diff --git a/capsule/encrypt_test.go b/capsule/encrypt_test.go index 8ebded9..270f182 100644 --- a/capsule/encrypt_test.go +++ b/capsule/encrypt_test.go @@ -11,13 +11,13 @@ import ( "filippo.io/age" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/accesskey" - "github.com/datekeys/datekeys-go/capsule" - "github.com/datekeys/datekeys-go/datekey" - "github.com/datekeys/datekeys-go/extension" - "github.com/datekeys/datekeys-go/internal/testkit" - "github.com/datekeys/datekeys-go/profile" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/accesskey" + "g.activething.com/go/DateKeys/capsule" + "g.activething.com/go/DateKeys/datekey" + "g.activething.com/go/DateKeys/extension" + "g.activething.com/go/DateKeys/internal/testkit" + "g.activething.com/go/DateKeys/profile" ) func past(t *testing.T, round uint64) capsule.EncryptOptions { diff --git a/capsule/example_test.go b/capsule/example_test.go index ed6dd1f..f009d8c 100644 --- a/capsule/example_test.go +++ b/capsule/example_test.go @@ -9,11 +9,11 @@ import ( "strings" "time" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/accesskey" - "github.com/datekeys/datekeys-go/capsule" - "github.com/datekeys/datekeys-go/profile" - "github.com/datekeys/datekeys-go/provider" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/accesskey" + "g.activething.com/go/DateKeys/capsule" + "g.activething.com/go/DateKeys/profile" + "g.activething.com/go/DateKeys/provider" ) // The published Quicknet signature of round 1000. In real use the release diff --git a/capsule/framing.go b/capsule/framing.go index fcba1fd..4270bea 100644 --- a/capsule/framing.go +++ b/capsule/framing.go @@ -15,10 +15,10 @@ import ( "encoding/hex" "fmt" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/codec" - "github.com/datekeys/datekeys-go/datekey" - "github.com/datekeys/datekeys-go/extension" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/codec" + "g.activething.com/go/DateKeys/datekey" + "g.activething.com/go/DateKeys/extension" ) // Framing constants (spec §22, §23) and parser limits (spec §57). diff --git a/capsule/framing_test.go b/capsule/framing_test.go index b7628ad..e4df020 100644 --- a/capsule/framing_test.go +++ b/capsule/framing_test.go @@ -9,13 +9,13 @@ import ( "strings" "testing" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/capsule" - "github.com/datekeys/datekeys-go/codec" - "github.com/datekeys/datekeys-go/datekey" - "github.com/datekeys/datekeys-go/extension" - "github.com/datekeys/datekeys-go/internal/testkit" - "github.com/datekeys/datekeys-go/profile" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/capsule" + "g.activething.com/go/DateKeys/codec" + "g.activething.com/go/DateKeys/datekey" + "g.activething.com/go/DateKeys/extension" + "g.activething.com/go/DateKeys/internal/testkit" + "g.activething.com/go/DateKeys/profile" ) func TestPolicyNames(t *testing.T) { diff --git a/capsule/fuzz_test.go b/capsule/fuzz_test.go index 7fcdcb8..d56cf48 100644 --- a/capsule/fuzz_test.go +++ b/capsule/fuzz_test.go @@ -10,9 +10,9 @@ import ( "path/filepath" "testing" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/capsule" - "github.com/datekeys/datekeys-go/internal/testkit" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/capsule" + "g.activething.com/go/DateKeys/internal/testkit" ) func seedFixtures(f *testing.F, part func(testkit.Parts) []byte) { diff --git a/capsule/inspect.go b/capsule/inspect.go index d850b04..d768581 100644 --- a/capsule/inspect.go +++ b/capsule/inspect.go @@ -9,11 +9,11 @@ import ( "filippo.io/age" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/agewrap" - "github.com/datekeys/datekeys-go/datekey" - "github.com/datekeys/datekeys-go/extension" - "github.com/datekeys/datekeys-go/profile" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/agewrap" + "g.activething.com/go/DateKeys/datekey" + "g.activething.com/go/DateKeys/extension" + "g.activething.com/go/DateKeys/profile" ) // InspectOptions configures Inspect. diff --git a/capsule/interop_test.go b/capsule/interop_test.go index 8f7c0f3..07da4ad 100644 --- a/capsule/interop_test.go +++ b/capsule/interop_test.go @@ -23,8 +23,8 @@ import ( "filippo.io/age" - "github.com/datekeys/datekeys-go/agewrap" - "github.com/datekeys/datekeys-go/internal/testkit" + "g.activething.com/go/DateKeys/agewrap" + "g.activething.com/go/DateKeys/internal/testkit" ) func tool(t *testing.T, env, name string) string { diff --git a/capsule/live_test.go b/capsule/live_test.go index 329e8fe..e2b37d9 100644 --- a/capsule/live_test.go +++ b/capsule/live_test.go @@ -15,10 +15,10 @@ import ( "filippo.io/age" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/capsule" - "github.com/datekeys/datekeys-go/profile" - "github.com/datekeys/datekeys-go/provider/drand" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/capsule" + "g.activething.com/go/DateKeys/profile" + "g.activething.com/go/DateKeys/provider/drand" ) // Encrypt to now + 30 s, check that the capsule stays locked without any diff --git a/capsule/mutation_test.go b/capsule/mutation_test.go index 4222a89..4994645 100644 --- a/capsule/mutation_test.go +++ b/capsule/mutation_test.go @@ -12,13 +12,13 @@ import ( "filippo.io/age" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/capsule" - "github.com/datekeys/datekeys-go/datekey" - "github.com/datekeys/datekeys-go/extension" - "github.com/datekeys/datekeys-go/internal/testkit" - "github.com/datekeys/datekeys-go/profile" - "github.com/datekeys/datekeys-go/provider" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/capsule" + "g.activething.com/go/DateKeys/datekey" + "g.activething.com/go/DateKeys/extension" + "g.activething.com/go/DateKeys/internal/testkit" + "g.activething.com/go/DateKeys/profile" + "g.activething.com/go/DateKeys/provider" ) // mutation is one entry of the mutation corpus (spec §64): a function over a diff --git a/capsule/open.go b/capsule/open.go index 295d6c1..fd86d9f 100644 --- a/capsule/open.go +++ b/capsule/open.go @@ -12,12 +12,12 @@ import ( "filippo.io/age" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/accesskey" - "github.com/datekeys/datekeys-go/agewrap" - "github.com/datekeys/datekeys-go/extension" - "github.com/datekeys/datekeys-go/profile" - "github.com/datekeys/datekeys-go/provider" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/accesskey" + "g.activething.com/go/DateKeys/agewrap" + "g.activething.com/go/DateKeys/extension" + "g.activething.com/go/DateKeys/profile" + "g.activething.com/go/DateKeys/provider" ) // OpenOptions configures Open. diff --git a/cmd/datekeys/main.go b/cmd/datekeys/main.go index 183d712..0966dee 100644 --- a/cmd/datekeys/main.go +++ b/cmd/datekeys/main.go @@ -27,12 +27,12 @@ import ( "filippo.io/age" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/accesskey" - "github.com/datekeys/datekeys-go/capsule" - "github.com/datekeys/datekeys-go/datekey" - "github.com/datekeys/datekeys-go/profile" - "github.com/datekeys/datekeys-go/provider/drand" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/accesskey" + "g.activething.com/go/DateKeys/capsule" + "g.activething.com/go/DateKeys/datekey" + "g.activething.com/go/DateKeys/profile" + "g.activething.com/go/DateKeys/provider/drand" ) const usage = `usage: diff --git a/cmd/datekeys/main_test.go b/cmd/datekeys/main_test.go index d3057fc..4ab9151 100644 --- a/cmd/datekeys/main_test.go +++ b/cmd/datekeys/main_test.go @@ -17,9 +17,9 @@ import ( "filippo.io/age" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/internal/testkit" - "github.com/datekeys/datekeys-go/profile" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/internal/testkit" + "g.activething.com/go/DateKeys/profile" ) const fixtures = "../../testdata/fixtures" diff --git a/codec/bech32/bech32_test.go b/codec/bech32/bech32_test.go index bd70018..20d3ef9 100644 --- a/codec/bech32/bech32_test.go +++ b/codec/bech32/bech32_test.go @@ -20,7 +20,7 @@ import ( "strings" "testing" - "github.com/datekeys/datekeys-go/codec/bech32" + "g.activething.com/go/DateKeys/codec/bech32" ) func TestBech32(t *testing.T) { diff --git a/codec/codec.go b/codec/codec.go index a796a92..318b56c 100644 --- a/codec/codec.go +++ b/codec/codec.go @@ -15,7 +15,7 @@ import ( "github.com/fxamacker/cbor/v2" - datekeys "github.com/datekeys/datekeys-go" + datekeys "g.activething.com/go/DateKeys" ) // Decoding limits. Structural sizes are additionally bounded by the framing diff --git a/codec/codec_test.go b/codec/codec_test.go index a45a4d0..bd63272 100644 --- a/codec/codec_test.go +++ b/codec/codec_test.go @@ -7,8 +7,8 @@ import ( "strings" "testing" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/codec" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/codec" ) type sample struct { diff --git a/datekey/datekey.go b/datekey/datekey.go index 4c11ba4..841a14e 100644 --- a/datekey/datekey.go +++ b/datekey/datekey.go @@ -16,8 +16,8 @@ import ( "strings" "time" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/profile" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/profile" ) // Prefix and JSON version of the V1 representation (spec §18). diff --git a/datekey/datekey_test.go b/datekey/datekey_test.go index be01445..2bf7f2b 100644 --- a/datekey/datekey_test.go +++ b/datekey/datekey_test.go @@ -8,10 +8,10 @@ import ( "testing" "time" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/datekey" - "github.com/datekeys/datekeys-go/internal/testkit" - "github.com/datekeys/datekeys-go/profile" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/datekey" + "g.activething.com/go/DateKeys/internal/testkit" + "g.activething.com/go/DateKeys/profile" ) func TestNormativeRoundVector(t *testing.T) { diff --git a/errors_test.go b/errors_test.go index 2d034f6..6db8a2a 100644 --- a/errors_test.go +++ b/errors_test.go @@ -7,7 +7,7 @@ import ( "strings" "testing" - datekeys "github.com/datekeys/datekeys-go" + datekeys "g.activething.com/go/DateKeys" ) // The catalogue matches spec §69 exactly, in order. diff --git a/extension/extension.go b/extension/extension.go index a3fbd7f..7a7876e 100644 --- a/extension/extension.go +++ b/extension/extension.go @@ -18,8 +18,8 @@ import ( "github.com/fxamacker/cbor/v2" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/codec" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/codec" ) // MaxIDLen bounds extension_id. It is an implementation limit (spec §74). diff --git a/extension/extension_test.go b/extension/extension_test.go index 16f4214..9942bfa 100644 --- a/extension/extension_test.go +++ b/extension/extension_test.go @@ -4,8 +4,8 @@ import ( "errors" "testing" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/extension" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/extension" ) func ext(t *testing.T, id string, v uint64, data any) extension.Extension { diff --git a/go.mod b/go.mod index 55eb0d1..ffeb41c 100644 --- a/go.mod +++ b/go.mod @@ -1,4 +1,4 @@ -module github.com/datekeys/datekeys-go +module g.activething.com/go/DateKeys go 1.26.8 diff --git a/internal/testkit/agefile.go b/internal/testkit/agefile.go index 7959034..1989056 100644 --- a/internal/testkit/agefile.go +++ b/internal/testkit/agefile.go @@ -13,7 +13,7 @@ import ( "filippo.io/age" "golang.org/x/crypto/hkdf" - "github.com/datekeys/datekeys-go/agewrap" + "g.activething.com/go/DateKeys/agewrap" ) // CaptureRecipient forwards to Recipient and records the file key that age diff --git a/internal/testkit/builder.go b/internal/testkit/builder.go index 27e06c2..1c7f0d5 100644 --- a/internal/testkit/builder.go +++ b/internal/testkit/builder.go @@ -8,12 +8,12 @@ import ( "filippo.io/age" - "github.com/datekeys/datekeys-go/agewrap" - "github.com/datekeys/datekeys-go/capsule" - "github.com/datekeys/datekeys-go/codec" - "github.com/datekeys/datekeys-go/datekey" - "github.com/datekeys/datekeys-go/extension" - "github.com/datekeys/datekeys-go/profile" + "g.activething.com/go/DateKeys/agewrap" + "g.activething.com/go/DateKeys/capsule" + "g.activething.com/go/DateKeys/codec" + "g.activething.com/go/DateKeys/datekey" + "g.activething.com/go/DateKeys/extension" + "g.activething.com/go/DateKeys/profile" ) // Build assembles a capsule step by step like capsule.Encrypt, but lets a test diff --git a/internal/testkit/genfixtures/main.go b/internal/testkit/genfixtures/main.go index 2d31481..8fe67ff 100644 --- a/internal/testkit/genfixtures/main.go +++ b/internal/testkit/genfixtures/main.go @@ -26,13 +26,13 @@ import ( "filippo.io/age" - "github.com/datekeys/datekeys-go/accesskey" - "github.com/datekeys/datekeys-go/agewrap" - "github.com/datekeys/datekeys-go/capsule" - "github.com/datekeys/datekeys-go/datekey" - "github.com/datekeys/datekeys-go/extension" - "github.com/datekeys/datekeys-go/internal/testkit" - "github.com/datekeys/datekeys-go/profile" + "g.activething.com/go/DateKeys/accesskey" + "g.activething.com/go/DateKeys/agewrap" + "g.activething.com/go/DateKeys/capsule" + "g.activething.com/go/DateKeys/datekey" + "g.activething.com/go/DateKeys/extension" + "g.activething.com/go/DateKeys/internal/testkit" + "g.activething.com/go/DateKeys/profile" ) func main() { diff --git a/internal/testkit/testkit.go b/internal/testkit/testkit.go index 0511206..4e5a4e2 100644 --- a/internal/testkit/testkit.go +++ b/internal/testkit/testkit.go @@ -11,9 +11,9 @@ import ( "fmt" "time" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/profile" - "github.com/datekeys/datekeys-go/provider" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/profile" + "g.activething.com/go/DateKeys/provider" ) // Published Quicknet signatures. They are public data obtained from drand diff --git a/internal/testkit/vectors.go b/internal/testkit/vectors.go index 7b7eec7..04a1c8a 100644 --- a/internal/testkit/vectors.go +++ b/internal/testkit/vectors.go @@ -7,9 +7,9 @@ import ( "strings" "time" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/datekey" - "github.com/datekeys/datekeys-go/profile" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/datekey" + "g.activething.com/go/DateKeys/profile" ) // SpecVersion is the specification the vectors and fixtures implement. diff --git a/profile/profile.go b/profile/profile.go index f08fe05..6674475 100644 --- a/profile/profile.go +++ b/profile/profile.go @@ -13,8 +13,8 @@ import ( "github.com/drand/drand/v2/common/chain" "github.com/drand/drand/v2/crypto" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/codec" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/codec" ) // Schema constants of the Provider Profile CBOR map (spec §11). diff --git a/profile/profile_test.go b/profile/profile_test.go index 3198546..d353c8b 100644 --- a/profile/profile_test.go +++ b/profile/profile_test.go @@ -7,10 +7,10 @@ import ( "testing" "time" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/codec" - "github.com/datekeys/datekeys-go/internal/testkit" - "github.com/datekeys/datekeys-go/profile" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/codec" + "g.activething.com/go/DateKeys/internal/testkit" + "g.activething.com/go/DateKeys/profile" ) func TestQuicknetMatchesGoldenVector(t *testing.T) { diff --git a/profile/registry.go b/profile/registry.go index b0eb46b..6d611a1 100644 --- a/profile/registry.go +++ b/profile/registry.go @@ -4,7 +4,7 @@ import ( "encoding/hex" "fmt" - datekeys "github.com/datekeys/datekeys-go" + datekeys "g.activething.com/go/DateKeys" ) // Registry resolves a profile_id to a locally trusted Provider Profile. The diff --git a/provider/drand/client.go b/provider/drand/client.go index cf0c10d..eaa3520 100644 --- a/provider/drand/client.go +++ b/provider/drand/client.go @@ -18,9 +18,9 @@ import ( "strings" "time" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/profile" - "github.com/datekeys/datekeys-go/provider" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/profile" + "g.activething.com/go/DateKeys/provider" ) // Limits of a single relay exchange. diff --git a/provider/drand/client_test.go b/provider/drand/client_test.go index 32299c8..49c615a 100644 --- a/provider/drand/client_test.go +++ b/provider/drand/client_test.go @@ -11,11 +11,11 @@ import ( "testing" "time" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/internal/testkit" - "github.com/datekeys/datekeys-go/profile" - "github.com/datekeys/datekeys-go/provider" - "github.com/datekeys/datekeys-go/provider/drand" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/internal/testkit" + "g.activething.com/go/DateKeys/profile" + "g.activething.com/go/DateKeys/provider" + "g.activething.com/go/DateKeys/provider/drand" ) var sig1000 = hex.EncodeToString(testkit.Release(1000).Signature) diff --git a/provider/drand/live_test.go b/provider/drand/live_test.go index a27cf84..0f9dc26 100644 --- a/provider/drand/live_test.go +++ b/provider/drand/live_test.go @@ -7,10 +7,10 @@ import ( "context" "testing" - "github.com/datekeys/datekeys-go/internal/testkit" - "github.com/datekeys/datekeys-go/profile" - "github.com/datekeys/datekeys-go/provider" - "github.com/datekeys/datekeys-go/provider/drand" + "g.activething.com/go/DateKeys/internal/testkit" + "g.activething.com/go/DateKeys/profile" + "g.activething.com/go/DateKeys/provider" + "g.activething.com/go/DateKeys/provider/drand" ) // Every default relay serves the same, locally verified release. diff --git a/provider/provider.go b/provider/provider.go index 0ecc395..0d9260c 100644 --- a/provider/provider.go +++ b/provider/provider.go @@ -12,8 +12,8 @@ import ( "github.com/drand/drand/v2/common" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/profile" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/profile" ) // Condition is the time condition of a Quicknet-style profile: a round. diff --git a/provider/provider_test.go b/provider/provider_test.go index f48cc66..0ed7f63 100644 --- a/provider/provider_test.go +++ b/provider/provider_test.go @@ -5,10 +5,10 @@ import ( "errors" "testing" - datekeys "github.com/datekeys/datekeys-go" - "github.com/datekeys/datekeys-go/internal/testkit" - "github.com/datekeys/datekeys-go/profile" - "github.com/datekeys/datekeys-go/provider" + datekeys "g.activething.com/go/DateKeys" + "g.activething.com/go/DateKeys/internal/testkit" + "g.activething.com/go/DateKeys/profile" + "g.activething.com/go/DateKeys/provider" ) func TestVerifyPublishedReleases(t *testing.T) { diff --git a/scripts/check.sh b/scripts/check.sh new file mode 100755 index 0000000..eee6da4 --- /dev/null +++ b/scripts/check.sh @@ -0,0 +1,58 @@ +#!/usr/bin/env bash +# Local gate: the same checks as .gitea/workflows/ci.yml, for any machine and +# for forges without runners. Run it before every push. +# +# scripts/check.sh # format, modules, vet, race tests, coverage, +# # govulncheck, vectors and fixtures +# scripts/check.sh 20s # additionally fuzz every parser for 20 s +set -euo pipefail +cd "$(dirname "$0")/.." + +fuzz="${1:-}" + +echo "== gofmt" +bad=$(gofmt -l .) +if [ -n "$bad" ]; then + echo "not formatted:"; echo "$bad"; exit 1 +fi + +echo "== go mod verify" +go mod verify + +echo "== go mod tidy leaves go.mod and go.sum unchanged" +tmp=$(mktemp -d) +cp go.mod go.sum "$tmp"/ +go mod tidy +if ! cmp -s go.mod "$tmp/go.mod" || ! cmp -s go.sum "$tmp/go.sum"; then + cp "$tmp"/go.mod "$tmp"/go.sum . + rm -rf "$tmp" + echo "go mod tidy would change go.mod or go.sum"; exit 1 +fi +rm -rf "$tmp" + +echo "== go vet" +go vet ./... + +echo "== go test -race" +go test -race -count=1 ./... + +echo "== coverage: at least 90 % in codec, capsule, accesskey, datekey and agewrap" +for pkg in codec capsule accesskey datekey agewrap; do + pct=$(go test -count=1 -cover "./$pkg" | sed -n 's/.*coverage: \([0-9.]*\)% of statements.*/\1/p') + echo "$pkg: $pct%" + awk -v p="$pct" 'BEGIN { exit !(p >= 90) }' +done + +echo "== govulncheck" +go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./... + +echo "== vectors reproduce and fixtures are frozen" +go run ./internal/testkit/genfixtures -out testdata +git diff --exit-code -- testdata + +if [ -n "$fuzz" ]; then + echo "== fuzz every parser for $fuzz" + ./scripts/fuzz.sh "$fuzz" +fi + +echo "all checks passed" diff --git a/spec/datekeys.cddl b/spec/datekeys.cddl index 627d4a3..119f4f4 100644 --- a/spec/datekeys.cddl +++ b/spec/datekeys.cddl @@ -1,7 +1,7 @@ ; DateKeys Protocol Specification v0.8.1 - CBOR schemas (RFC 8610 CDDL). ; ; Normative companion of spec/DateKeys_Protocol_Specification_v0.8.1.md, as -; implemented by the reference implementation github.com/datekeys/datekeys-go. +; implemented by the reference implementation g.activething.com/go/DateKeys. ; ; Encoding rules that CDDL cannot express (spec section 58, 58.1): ; - Every structure is Deterministic CBOR (RFC 8949 section 4.2.1): map keys