Host on Gitea, not GitHub

The module is imported as g.activething.com/go/DateKeys, the path the
project's Gitea advertises. The .github directory is gone: workflows
now live in .gitea/workflows, use the gitea.com action mirrors and
install every tool from its Go module; releases go to this Gitea with
goreleaser and a key-based cosign signature; Dependabot is replaced by
a nightly report of available updates. scripts/check.sh runs the same
checks on any machine and is the gate while the server has no runner.
SECURITY.md, README and CONTRIBUTING no longer refer to GitHub.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
v0.8.2
dev 2 weeks ago
parent 3ed9cafe61
commit 13dcca119c

@ -0,0 +1,114 @@
# Gitea Actions workflow (Gitea 1.21 or later with a registered act_runner).
# Actions come from the gitea.com mirrors; every tool is installed with the Go
# toolchain from its module. The same checks run on any machine with
# scripts/check.sh, which is the gate while no runner is available.
name: ci
on:
push:
branches: [main]
pull_request:
jobs:
test:
name: test (Go ${{ matrix.go }})
strategy:
fail-fast: false
matrix:
# Add windows or macos runner labels here when such runners exist.
go: [stable, oldstable]
runs-on: ubuntu-latest
steps:
- uses: https://gitea.com/actions/checkout@v4
- uses: https://gitea.com/actions/setup-go@v5
with:
go-version: ${{ matrix.go }}
- run: go mod verify
- run: go vet ./...
- run: go test -race -count=1 ./...
coverage:
runs-on: ubuntu-latest
steps:
- uses: https://gitea.com/actions/checkout@v4
- uses: https://gitea.com/actions/setup-go@v5
with:
go-version: stable
- name: at least 90 % in codec, capsule, accesskey, datekey and agewrap
run: |
set -euo pipefail
for pkg in codec capsule accesskey datekey agewrap; do
pct=$(go test -count=1 -cover "./$pkg" | sed -n 's/.*coverage: \([0-9.]*\)% of statements.*/\1/p')
echo "$pkg: $pct%"
awk -v p="$pct" 'BEGIN { exit !(p >= 90) }'
done
lint:
runs-on: ubuntu-latest
steps:
- uses: https://gitea.com/actions/checkout@v4
- uses: https://gitea.com/actions/setup-go@v5
with:
go-version: stable
- run: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.14.0
- run: golangci-lint run
- name: gosec (advisory)
continue-on-error: true
run: golangci-lint run --enable-only gosec
vuln:
runs-on: ubuntu-latest
steps:
- uses: https://gitea.com/actions/checkout@v4
- uses: https://gitea.com/actions/setup-go@v5
with:
go-version: stable
- run: go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./...
fuzz-short:
runs-on: ubuntu-latest
steps:
- uses: https://gitea.com/actions/checkout@v4
- uses: https://gitea.com/actions/setup-go@v5
with:
go-version: stable
- name: every parser, 20 s each
run: ./scripts/fuzz.sh 20s
interop:
runs-on: ubuntu-latest
steps:
- uses: https://gitea.com/actions/checkout@v4
- uses: https://gitea.com/actions/setup-go@v5
with:
go-version: stable
- name: official age and tle command-line tools
run: |
go install filippo.io/age/cmd/age@v1.3.2
go install github.com/drand/tlock/cmd/tle@v1.2.0
go test -tags interop -count=1 -v ./capsule -run Interop
sbom:
runs-on: ubuntu-latest
steps:
- uses: https://gitea.com/actions/checkout@v4
- uses: https://gitea.com/actions/setup-go@v5
with:
go-version: stable
- run: go run github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.12.0 mod -licenses -json -output sbom.cdx.json
- uses: https://gitea.com/actions/upload-artifact@v4
with:
name: sbom
path: sbom.cdx.json
fixtures:
name: vectors reproduce and fixtures are frozen
runs-on: ubuntu-latest
steps:
- uses: https://gitea.com/actions/checkout@v4
- uses: https://gitea.com/actions/setup-go@v5
with:
go-version: stable
- run: |
go run ./internal/testkit/genfixtures -out testdata
git diff --exit-code testdata

@ -0,0 +1,58 @@
# Gitea Actions workflow (Gitea 1.21 or later with a registered act_runner).
name: nightly
on:
schedule:
- cron: "17 3 * * *"
workflow_dispatch:
jobs:
integration:
name: live Quicknet
runs-on: ubuntu-latest
steps:
- uses: https://gitea.com/actions/checkout@v4
- uses: https://gitea.com/actions/setup-go@v5
with:
go-version: stable
- run: go test -tags integration -count=1 -v -timeout 10m ./capsule ./provider/drand -run Live
fuzz-long:
runs-on: ubuntu-latest
timeout-minutes: 120
steps:
- uses: https://gitea.com/actions/checkout@v4
- uses: https://gitea.com/actions/setup-go@v5
with:
go-version: stable
- name: every parser, 10 min each
env:
FUZZ_MINIMIZE: 10s
run: ./scripts/fuzz.sh 10m
- name: keep failing inputs
if: failure()
uses: https://gitea.com/actions/upload-artifact@v4
with:
name: fuzz-corpus
path: "**/testdata/fuzz/**"
vuln:
runs-on: ubuntu-latest
steps:
- uses: https://gitea.com/actions/checkout@v4
- uses: https://gitea.com/actions/setup-go@v5
with:
go-version: stable
- run: go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./...
updates:
name: dependency updates available
runs-on: ubuntu-latest
steps:
- uses: https://gitea.com/actions/checkout@v4
- uses: https://gitea.com/actions/setup-go@v5
with:
go-version: stable
# Informational. Any change to age, tlock, drand or kyber is reviewed by
# hand against SECURITY.md before it is applied.
- run: go list -m -u all | grep '\[' || echo "no updates"

@ -0,0 +1,29 @@
# Gitea Actions workflow (Gitea 1.21 or later with a registered act_runner).
# Publishes a release on this Gitea server (.goreleaser.yaml, gitea_urls).
# Repository secrets: GITEA_TOKEN (a token with write access to releases),
# COSIGN_PRIVATE_KEY and COSIGN_PASSWORD (the project's cosign key).
name: release
on:
push:
tags: ["v*"]
jobs:
release:
runs-on: ubuntu-latest
steps:
- uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: 0
- uses: https://gitea.com/actions/setup-go@v5
with:
go-version-file: go.mod
- run: go test -count=1 ./...
- run: go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.12.0
- run: go install github.com/sigstore/cosign/v2/cmd/cosign@v2.6.5
- run: go install github.com/goreleaser/goreleaser/v2@v2.18.2
- run: goreleaser release --clean
env:
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}

@ -1,18 +0,0 @@
# Patch updates only. Any change to age, tlock, drand or kyber is reviewed by
# hand against SECURITY.md before merging, even when Dependabot proposes it.
version: 2
updates:
- package-ecosystem: gomod
directory: /
schedule:
interval: weekly
open-pull-requests-limit: 5
labels: [dependencies]
ignore:
- dependency-name: "*"
update-types: ["version-update:semver-major", "version-update:semver-minor"]
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
labels: [dependencies]

@ -1,135 +0,0 @@
name: ci
on:
push:
branches: [main]
pull_request:
permissions:
contents: read
jobs:
test:
name: test (${{ matrix.os }}, Go ${{ matrix.go }})
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
go: [stable, oldstable]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: ${{ matrix.go }}
- run: go mod verify
- run: go vet ./...
- run: go test -race -count=1 ./...
coverage:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: stable
- name: at least 90 % in codec, capsule, accesskey, datekey and agewrap
shell: bash
run: |
set -euo pipefail
for pkg in codec capsule accesskey datekey agewrap; do
pct=$(go test -count=1 -cover "./$pkg" | sed -n 's/.*coverage: \([0-9.]*\)% of statements.*/\1/p')
echo "$pkg: $pct%"
awk -v p="$pct" 'BEGIN { exit !(p >= 90) }'
done
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: stable
- uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0
with:
version: v2.14.0
- name: gosec (advisory)
continue-on-error: true
uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0
with:
version: v2.14.0
args: --enable-only gosec
vuln:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: stable
- run: go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./...
fuzz-short:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: stable
- name: every parser, 20 s each
shell: bash
run: ./scripts/fuzz.sh 20s
interop:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: stable
- name: official age and tle command-line tools
run: |
go install filippo.io/age/cmd/age@v1.3.2
go install github.com/drand/tlock/cmd/tle@v1.2.0
go test -tags interop -count=1 -v ./capsule -run Interop
sbom:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: stable
- run: go run github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.12.0 mod -licenses -json -output sbom.cdx.json
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: sbom
path: sbom.cdx.json
fixtures:
name: vectors reproduce and fixtures are frozen
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: stable
- run: |
go run ./internal/testkit/genfixtures -out testdata
git diff --exit-code testdata

@ -1,55 +0,0 @@
name: nightly
on:
schedule:
- cron: "17 3 * * *"
workflow_dispatch:
permissions:
contents: read
jobs:
integration:
name: live Quicknet
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: stable
- run: go test -tags integration -count=1 -v -timeout 10m ./capsule ./provider/drand -run Live
fuzz-long:
runs-on: ubuntu-latest
timeout-minutes: 120
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: stable
- name: every parser, 10 min each
shell: bash
env:
FUZZ_MINIMIZE: 10s
run: ./scripts/fuzz.sh 10m
- name: keep failing inputs
if: failure()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: fuzz-corpus
path: "**/testdata/fuzz/**"
vuln:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: stable
- run: go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./...

@ -1,32 +0,0 @@
name: release
on:
push:
tags: ["v*"]
permissions:
contents: read
jobs:
release:
runs-on: ubuntu-latest
permissions:
contents: write # publish the GitHub release
id-token: write # keyless cosign signature
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
- run: go test -count=1 ./...
- run: go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.12.0
- uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
- uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
with:
version: "~> v2"
args: release --clean
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

@ -25,4 +25,4 @@ formatters:
settings:
goimports:
local-prefixes:
- github.com/datekeys/datekeys-go
- g.activething.com/go/DateKeys

@ -46,20 +46,28 @@ sboms:
args: ["bin", "-json", "-output", "$document", "$artifact"]
signs:
# Keyless signature of the checksum file with the workflow's OIDC identity.
# Signature of the checksum file with the project's cosign key, supplied at
# release time through COSIGN_PRIVATE_KEY and COSIGN_PASSWORD.
- cmd: cosign
artifacts: checksum
signature: "${artifact}.sig"
certificate: "${artifact}.pem"
args:
- sign-blob
- --key=env://COSIGN_PRIVATE_KEY
- --output-signature=${signature}
- --output-certificate=${certificate}
- ${artifact}
- --yes
changelog:
disable: true
# Releases are published on the project's Gitea server.
gitea_urls:
api: https://g.activething.com/api/v1
download: https://g.activething.com
# The server presents a certificate Go and goreleaser do not trust by
# default. Remove this when a trusted certificate is installed.
skip_tls_verify: true
release:
prerelease: auto

@ -38,6 +38,7 @@ dependencies are not accepted without prior discussion.
## Tests
```bash
./scripts/check.sh # everything ci.yml runs, on any machine; run before pushing
go test -race ./...
FUZZ_PARALLEL=4 ./scripts/fuzz.sh 60s # every parser; each worker uses a 100 MB temp file
go test -tags interop ./capsule # needs the age and tle CLIs

@ -54,9 +54,14 @@ PAYLOAD_AGE = age(X25519 R_PAYLOAD → tus datos), en streaming
## CLI
```bash
go install github.com/datekeys/datekeys-go/cmd/datekeys@latest
go install g.activething.com/go/DateKeys/cmd/datekeys@latest
```
El módulo se sirve desde el Gitea del proyecto, cuyo certificado Go no
reconoce por defecto. Define `GOPRIVATE=g.activething.com` para que el proxy y
la base de datos de sumas de Go no intervengan, e instala el certificado del
servidor o, en una red de confianza, define `GOINSECURE=g.activething.com`.
```bash
datekeys datekey resolve -at 2030-01-01T00:00:00Z
datekeys encrypt -at 2030-01-01T00:00:00Z -in carta.txt -out carta.dkc

@ -53,9 +53,14 @@ PAYLOAD_AGE = age(X25519 R_PAYLOAD → your data), streamed
## CLI
```bash
go install github.com/datekeys/datekeys-go/cmd/datekeys@latest
go install g.activething.com/go/DateKeys/cmd/datekeys@latest
```
The module is served by the project's own Gitea, whose certificate Go does not
trust by default. Set `GOPRIVATE=g.activething.com` so that the Go proxy and
checksum database are bypassed for it, and either install the server's
certificate or, on a trusted network, set `GOINSECURE=g.activething.com`.
```bash
datekeys datekey resolve -at 2030-01-01T00:00:00Z
datekeys encrypt -at 2030-01-01T00:00:00Z -in letter.txt -out letter.dkc

@ -4,10 +4,10 @@
Please report vulnerabilities privately, not in public issues:
- GitHub private vulnerability reporting on this repository (Security → Report
a vulnerability), once the `datekeys` organisation hosts it.
- Until then, contact the maintainers privately and ask for an encrypted
channel.
- Send an e-mail to the maintainers at info@activething.com with "DateKeys
security" in the subject. Ask for an encrypted channel before sending
sensitive material.
- Do not open an issue on the repository for a vulnerability.
Include a reproducible case: ideally a `.dkc` or `.dkk` file, or a test in the
style of `capsule/mutation_test.go`. We aim to acknowledge reports within
@ -81,6 +81,6 @@ All versions are pinned in `go.mod` and verified through `go.sum`. Changes to
- Reproducible builds: `-trimpath`, `CGO_ENABLED=0`, pinned toolchain in CI.
- Releases publish SHA-256 checksums and a CycloneDX SBOM, and are signed with
cosign once the organisation's signing identity exists.
cosign using the project's signing key.
- The Quicknet root of trust is compiled into the binary and checked against
its pinned `profile_hash` (`4147645109798ecbc9f630c2f709835bb5846fe7911a6bd5c5755e25ade2ada4`).

@ -15,10 +15,10 @@ import (
"filippo.io/age"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/agewrap"
"github.com/datekeys/datekeys-go/codec"
"github.com/datekeys/datekeys-go/extension"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/agewrap"
"g.activething.com/go/DateKeys/codec"
"g.activething.com/go/DateKeys/extension"
)
// Framing and schema constants (spec §40, §41).

@ -15,13 +15,13 @@ import (
"filippo.io/age"
"github.com/fxamacker/cbor/v2"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/accesskey"
"github.com/datekeys/datekeys-go/agewrap"
"github.com/datekeys/datekeys-go/codec"
"github.com/datekeys/datekeys-go/extension"
"github.com/datekeys/datekeys-go/internal/testkit"
"github.com/datekeys/datekeys-go/profile"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/accesskey"
"g.activething.com/go/DateKeys/agewrap"
"g.activething.com/go/DateKeys/codec"
"g.activething.com/go/DateKeys/extension"
"g.activething.com/go/DateKeys/internal/testkit"
"g.activething.com/go/DateKeys/profile"
)
const fixtures = "../testdata/fixtures"

@ -35,10 +35,10 @@ import (
"github.com/drand/kyber"
"github.com/drand/tlock"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/codec/bech32"
"github.com/datekeys/datekeys-go/profile"
"github.com/datekeys/datekeys-go/provider"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/codec/bech32"
"g.activething.com/go/DateKeys/profile"
"g.activething.com/go/DateKeys/provider"
)
// Stanza types of V1.

@ -13,11 +13,11 @@ import (
"github.com/drand/kyber"
"github.com/drand/tlock"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/agewrap"
"github.com/datekeys/datekeys-go/internal/testkit"
"github.com/datekeys/datekeys-go/profile"
"github.com/datekeys/datekeys-go/provider"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/agewrap"
"g.activething.com/go/DateKeys/internal/testkit"
"g.activething.com/go/DateKeys/profile"
"g.activething.com/go/DateKeys/provider"
)
// tlockNetwork adapts the pinned profile to tlock.Network, to run the

@ -14,12 +14,12 @@ import (
"filippo.io/age"
"github.com/datekeys/datekeys-go/accesskey"
"github.com/datekeys/datekeys-go/agewrap"
"github.com/datekeys/datekeys-go/capsule"
"github.com/datekeys/datekeys-go/internal/testkit"
"github.com/datekeys/datekeys-go/profile"
"github.com/datekeys/datekeys-go/provider"
"g.activething.com/go/DateKeys/accesskey"
"g.activething.com/go/DateKeys/agewrap"
"g.activething.com/go/DateKeys/capsule"
"g.activething.com/go/DateKeys/internal/testkit"
"g.activething.com/go/DateKeys/profile"
"g.activething.com/go/DateKeys/provider"
)
const fixtureDir = "../testdata/fixtures"

@ -11,12 +11,12 @@ import (
"filippo.io/age"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/accesskey"
"github.com/datekeys/datekeys-go/agewrap"
"github.com/datekeys/datekeys-go/datekey"
"github.com/datekeys/datekeys-go/extension"
"github.com/datekeys/datekeys-go/profile"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/accesskey"
"g.activething.com/go/DateKeys/agewrap"
"g.activething.com/go/DateKeys/datekey"
"g.activething.com/go/DateKeys/extension"
"g.activething.com/go/DateKeys/profile"
)
// EncryptOptions configures Encrypt.

@ -11,13 +11,13 @@ import (
"filippo.io/age"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/accesskey"
"github.com/datekeys/datekeys-go/capsule"
"github.com/datekeys/datekeys-go/datekey"
"github.com/datekeys/datekeys-go/extension"
"github.com/datekeys/datekeys-go/internal/testkit"
"github.com/datekeys/datekeys-go/profile"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/accesskey"
"g.activething.com/go/DateKeys/capsule"
"g.activething.com/go/DateKeys/datekey"
"g.activething.com/go/DateKeys/extension"
"g.activething.com/go/DateKeys/internal/testkit"
"g.activething.com/go/DateKeys/profile"
)
func past(t *testing.T, round uint64) capsule.EncryptOptions {

@ -9,11 +9,11 @@ import (
"strings"
"time"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/accesskey"
"github.com/datekeys/datekeys-go/capsule"
"github.com/datekeys/datekeys-go/profile"
"github.com/datekeys/datekeys-go/provider"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/accesskey"
"g.activething.com/go/DateKeys/capsule"
"g.activething.com/go/DateKeys/profile"
"g.activething.com/go/DateKeys/provider"
)
// The published Quicknet signature of round 1000. In real use the release

@ -15,10 +15,10 @@ import (
"encoding/hex"
"fmt"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/codec"
"github.com/datekeys/datekeys-go/datekey"
"github.com/datekeys/datekeys-go/extension"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/codec"
"g.activething.com/go/DateKeys/datekey"
"g.activething.com/go/DateKeys/extension"
)
// Framing constants (spec §22, §23) and parser limits (spec §57).

@ -9,13 +9,13 @@ import (
"strings"
"testing"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/capsule"
"github.com/datekeys/datekeys-go/codec"
"github.com/datekeys/datekeys-go/datekey"
"github.com/datekeys/datekeys-go/extension"
"github.com/datekeys/datekeys-go/internal/testkit"
"github.com/datekeys/datekeys-go/profile"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/capsule"
"g.activething.com/go/DateKeys/codec"
"g.activething.com/go/DateKeys/datekey"
"g.activething.com/go/DateKeys/extension"
"g.activething.com/go/DateKeys/internal/testkit"
"g.activething.com/go/DateKeys/profile"
)
func TestPolicyNames(t *testing.T) {

@ -10,9 +10,9 @@ import (
"path/filepath"
"testing"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/capsule"
"github.com/datekeys/datekeys-go/internal/testkit"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/capsule"
"g.activething.com/go/DateKeys/internal/testkit"
)
func seedFixtures(f *testing.F, part func(testkit.Parts) []byte) {

@ -9,11 +9,11 @@ import (
"filippo.io/age"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/agewrap"
"github.com/datekeys/datekeys-go/datekey"
"github.com/datekeys/datekeys-go/extension"
"github.com/datekeys/datekeys-go/profile"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/agewrap"
"g.activething.com/go/DateKeys/datekey"
"g.activething.com/go/DateKeys/extension"
"g.activething.com/go/DateKeys/profile"
)
// InspectOptions configures Inspect.

@ -23,8 +23,8 @@ import (
"filippo.io/age"
"github.com/datekeys/datekeys-go/agewrap"
"github.com/datekeys/datekeys-go/internal/testkit"
"g.activething.com/go/DateKeys/agewrap"
"g.activething.com/go/DateKeys/internal/testkit"
)
func tool(t *testing.T, env, name string) string {

@ -15,10 +15,10 @@ import (
"filippo.io/age"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/capsule"
"github.com/datekeys/datekeys-go/profile"
"github.com/datekeys/datekeys-go/provider/drand"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/capsule"
"g.activething.com/go/DateKeys/profile"
"g.activething.com/go/DateKeys/provider/drand"
)
// Encrypt to now + 30 s, check that the capsule stays locked without any

@ -12,13 +12,13 @@ import (
"filippo.io/age"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/capsule"
"github.com/datekeys/datekeys-go/datekey"
"github.com/datekeys/datekeys-go/extension"
"github.com/datekeys/datekeys-go/internal/testkit"
"github.com/datekeys/datekeys-go/profile"
"github.com/datekeys/datekeys-go/provider"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/capsule"
"g.activething.com/go/DateKeys/datekey"
"g.activething.com/go/DateKeys/extension"
"g.activething.com/go/DateKeys/internal/testkit"
"g.activething.com/go/DateKeys/profile"
"g.activething.com/go/DateKeys/provider"
)
// mutation is one entry of the mutation corpus (spec §64): a function over a

@ -12,12 +12,12 @@ import (
"filippo.io/age"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/accesskey"
"github.com/datekeys/datekeys-go/agewrap"
"github.com/datekeys/datekeys-go/extension"
"github.com/datekeys/datekeys-go/profile"
"github.com/datekeys/datekeys-go/provider"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/accesskey"
"g.activething.com/go/DateKeys/agewrap"
"g.activething.com/go/DateKeys/extension"
"g.activething.com/go/DateKeys/profile"
"g.activething.com/go/DateKeys/provider"
)
// OpenOptions configures Open.

@ -27,12 +27,12 @@ import (
"filippo.io/age"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/accesskey"
"github.com/datekeys/datekeys-go/capsule"
"github.com/datekeys/datekeys-go/datekey"
"github.com/datekeys/datekeys-go/profile"
"github.com/datekeys/datekeys-go/provider/drand"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/accesskey"
"g.activething.com/go/DateKeys/capsule"
"g.activething.com/go/DateKeys/datekey"
"g.activething.com/go/DateKeys/profile"
"g.activething.com/go/DateKeys/provider/drand"
)
const usage = `usage:

@ -17,9 +17,9 @@ import (
"filippo.io/age"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/internal/testkit"
"github.com/datekeys/datekeys-go/profile"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/internal/testkit"
"g.activething.com/go/DateKeys/profile"
)
const fixtures = "../../testdata/fixtures"

@ -20,7 +20,7 @@ import (
"strings"
"testing"
"github.com/datekeys/datekeys-go/codec/bech32"
"g.activething.com/go/DateKeys/codec/bech32"
)
func TestBech32(t *testing.T) {

@ -15,7 +15,7 @@ import (
"github.com/fxamacker/cbor/v2"
datekeys "github.com/datekeys/datekeys-go"
datekeys "g.activething.com/go/DateKeys"
)
// Decoding limits. Structural sizes are additionally bounded by the framing

@ -7,8 +7,8 @@ import (
"strings"
"testing"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/codec"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/codec"
)
type sample struct {

@ -16,8 +16,8 @@ import (
"strings"
"time"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/profile"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/profile"
)
// Prefix and JSON version of the V1 representation (spec §18).

@ -8,10 +8,10 @@ import (
"testing"
"time"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/datekey"
"github.com/datekeys/datekeys-go/internal/testkit"
"github.com/datekeys/datekeys-go/profile"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/datekey"
"g.activething.com/go/DateKeys/internal/testkit"
"g.activething.com/go/DateKeys/profile"
)
func TestNormativeRoundVector(t *testing.T) {

@ -7,7 +7,7 @@ import (
"strings"
"testing"
datekeys "github.com/datekeys/datekeys-go"
datekeys "g.activething.com/go/DateKeys"
)
// The catalogue matches spec §69 exactly, in order.

@ -18,8 +18,8 @@ import (
"github.com/fxamacker/cbor/v2"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/codec"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/codec"
)
// MaxIDLen bounds extension_id. It is an implementation limit (spec §74).

@ -4,8 +4,8 @@ import (
"errors"
"testing"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/extension"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/extension"
)
func ext(t *testing.T, id string, v uint64, data any) extension.Extension {

@ -1,4 +1,4 @@
module github.com/datekeys/datekeys-go
module g.activething.com/go/DateKeys
go 1.26.8

@ -13,7 +13,7 @@ import (
"filippo.io/age"
"golang.org/x/crypto/hkdf"
"github.com/datekeys/datekeys-go/agewrap"
"g.activething.com/go/DateKeys/agewrap"
)
// CaptureRecipient forwards to Recipient and records the file key that age

@ -8,12 +8,12 @@ import (
"filippo.io/age"
"github.com/datekeys/datekeys-go/agewrap"
"github.com/datekeys/datekeys-go/capsule"
"github.com/datekeys/datekeys-go/codec"
"github.com/datekeys/datekeys-go/datekey"
"github.com/datekeys/datekeys-go/extension"
"github.com/datekeys/datekeys-go/profile"
"g.activething.com/go/DateKeys/agewrap"
"g.activething.com/go/DateKeys/capsule"
"g.activething.com/go/DateKeys/codec"
"g.activething.com/go/DateKeys/datekey"
"g.activething.com/go/DateKeys/extension"
"g.activething.com/go/DateKeys/profile"
)
// Build assembles a capsule step by step like capsule.Encrypt, but lets a test

@ -26,13 +26,13 @@ import (
"filippo.io/age"
"github.com/datekeys/datekeys-go/accesskey"
"github.com/datekeys/datekeys-go/agewrap"
"github.com/datekeys/datekeys-go/capsule"
"github.com/datekeys/datekeys-go/datekey"
"github.com/datekeys/datekeys-go/extension"
"github.com/datekeys/datekeys-go/internal/testkit"
"github.com/datekeys/datekeys-go/profile"
"g.activething.com/go/DateKeys/accesskey"
"g.activething.com/go/DateKeys/agewrap"
"g.activething.com/go/DateKeys/capsule"
"g.activething.com/go/DateKeys/datekey"
"g.activething.com/go/DateKeys/extension"
"g.activething.com/go/DateKeys/internal/testkit"
"g.activething.com/go/DateKeys/profile"
)
func main() {

@ -11,9 +11,9 @@ import (
"fmt"
"time"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/profile"
"github.com/datekeys/datekeys-go/provider"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/profile"
"g.activething.com/go/DateKeys/provider"
)
// Published Quicknet signatures. They are public data obtained from drand

@ -7,9 +7,9 @@ import (
"strings"
"time"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/datekey"
"github.com/datekeys/datekeys-go/profile"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/datekey"
"g.activething.com/go/DateKeys/profile"
)
// SpecVersion is the specification the vectors and fixtures implement.

@ -13,8 +13,8 @@ import (
"github.com/drand/drand/v2/common/chain"
"github.com/drand/drand/v2/crypto"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/codec"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/codec"
)
// Schema constants of the Provider Profile CBOR map (spec §11).

@ -7,10 +7,10 @@ import (
"testing"
"time"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/codec"
"github.com/datekeys/datekeys-go/internal/testkit"
"github.com/datekeys/datekeys-go/profile"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/codec"
"g.activething.com/go/DateKeys/internal/testkit"
"g.activething.com/go/DateKeys/profile"
)
func TestQuicknetMatchesGoldenVector(t *testing.T) {

@ -4,7 +4,7 @@ import (
"encoding/hex"
"fmt"
datekeys "github.com/datekeys/datekeys-go"
datekeys "g.activething.com/go/DateKeys"
)
// Registry resolves a profile_id to a locally trusted Provider Profile. The

@ -18,9 +18,9 @@ import (
"strings"
"time"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/profile"
"github.com/datekeys/datekeys-go/provider"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/profile"
"g.activething.com/go/DateKeys/provider"
)
// Limits of a single relay exchange.

@ -11,11 +11,11 @@ import (
"testing"
"time"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/internal/testkit"
"github.com/datekeys/datekeys-go/profile"
"github.com/datekeys/datekeys-go/provider"
"github.com/datekeys/datekeys-go/provider/drand"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/internal/testkit"
"g.activething.com/go/DateKeys/profile"
"g.activething.com/go/DateKeys/provider"
"g.activething.com/go/DateKeys/provider/drand"
)
var sig1000 = hex.EncodeToString(testkit.Release(1000).Signature)

@ -7,10 +7,10 @@ import (
"context"
"testing"
"github.com/datekeys/datekeys-go/internal/testkit"
"github.com/datekeys/datekeys-go/profile"
"github.com/datekeys/datekeys-go/provider"
"github.com/datekeys/datekeys-go/provider/drand"
"g.activething.com/go/DateKeys/internal/testkit"
"g.activething.com/go/DateKeys/profile"
"g.activething.com/go/DateKeys/provider"
"g.activething.com/go/DateKeys/provider/drand"
)
// Every default relay serves the same, locally verified release.

@ -12,8 +12,8 @@ import (
"github.com/drand/drand/v2/common"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/profile"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/profile"
)
// Condition is the time condition of a Quicknet-style profile: a round.

@ -5,10 +5,10 @@ import (
"errors"
"testing"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/internal/testkit"
"github.com/datekeys/datekeys-go/profile"
"github.com/datekeys/datekeys-go/provider"
datekeys "g.activething.com/go/DateKeys"
"g.activething.com/go/DateKeys/internal/testkit"
"g.activething.com/go/DateKeys/profile"
"g.activething.com/go/DateKeys/provider"
)
func TestVerifyPublishedReleases(t *testing.T) {

@ -0,0 +1,58 @@
#!/usr/bin/env bash
# Local gate: the same checks as .gitea/workflows/ci.yml, for any machine and
# for forges without runners. Run it before every push.
#
# scripts/check.sh # format, modules, vet, race tests, coverage,
# # govulncheck, vectors and fixtures
# scripts/check.sh 20s # additionally fuzz every parser for 20 s
set -euo pipefail
cd "$(dirname "$0")/.."
fuzz="${1:-}"
echo "== gofmt"
bad=$(gofmt -l .)
if [ -n "$bad" ]; then
echo "not formatted:"; echo "$bad"; exit 1
fi
echo "== go mod verify"
go mod verify
echo "== go mod tidy leaves go.mod and go.sum unchanged"
tmp=$(mktemp -d)
cp go.mod go.sum "$tmp"/
go mod tidy
if ! cmp -s go.mod "$tmp/go.mod" || ! cmp -s go.sum "$tmp/go.sum"; then
cp "$tmp"/go.mod "$tmp"/go.sum .
rm -rf "$tmp"
echo "go mod tidy would change go.mod or go.sum"; exit 1
fi
rm -rf "$tmp"
echo "== go vet"
go vet ./...
echo "== go test -race"
go test -race -count=1 ./...
echo "== coverage: at least 90 % in codec, capsule, accesskey, datekey and agewrap"
for pkg in codec capsule accesskey datekey agewrap; do
pct=$(go test -count=1 -cover "./$pkg" | sed -n 's/.*coverage: \([0-9.]*\)% of statements.*/\1/p')
echo "$pkg: $pct%"
awk -v p="$pct" 'BEGIN { exit !(p >= 90) }'
done
echo "== govulncheck"
go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./...
echo "== vectors reproduce and fixtures are frozen"
go run ./internal/testkit/genfixtures -out testdata
git diff --exit-code -- testdata
if [ -n "$fuzz" ]; then
echo "== fuzz every parser for $fuzz"
./scripts/fuzz.sh "$fuzz"
fi
echo "all checks passed"

@ -1,7 +1,7 @@
; DateKeys Protocol Specification v0.8.1 - CBOR schemas (RFC 8610 CDDL).
;
; Normative companion of spec/DateKeys_Protocol_Specification_v0.8.1.md, as
; implemented by the reference implementation github.com/datekeys/datekeys-go.
; implemented by the reference implementation g.activething.com/go/DateKeys.
;
; Encoding rules that CDDL cannot express (spec section 58, 58.1):
; - Every structure is Deterministic CBOR (RFC 8949 section 4.2.1): map keys

Loading…
Cancel
Save

Powered by TurnKey Linux.