Delivery 2 of capsule format 3, with the decisions the author took on 1 October 2026 after the review of Fable and Astra: - A fixed area of 32 KiB for every capsule of a v0.11 writer, signed or not, and 64 KiB only when the person enlarges it expressly (29.2). - What is signed (29.8): AUTHOR_MESSAGE of 66 bytes over control_commit of CONTROL_SIG, without I_PAYLOAD and with payload_length at zero, head_digest and signers_digest. The size of the area never changes what is signed, so the area can grow after signing. - alg 1, strict Ed25519 with dkauthor1 keys (29.9, 29.12), and alg 2, a detached CMS signature with one or more X.509 signers, the list of required signers in key 1 and a CAdES-T timestamp per signer (29.10). - seal_type 2, an RFC 3161 seal over SEAL_SUBJECT for capsules without a certificate signature (29.11), and the verdicts F2 to F6 and S3 to S5. - The key of words (38.1), the public note datekeys.note (24.1) and the capsule extension datekeys.capsule of the .dkk, with the note, the date and a locator encrypted for the date (44.1). - Writer rules 19 to 24, privacy, threat model 7.9, mutation tests, compatibility with v0.10 readers, the extension registry, provisional items (the 32 KiB to be measured) and the change log in 76. The CDDL adds the schemas of alg 1, alg 2, seal_type 2 and the two extensions. The reference still implements v0.10. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>v0.11
parent
5b3d2d4f34
commit
e224119f8f
File diff suppressed because it is too large
Load Diff
Loading…
Reference in new issue