diff --git a/CHANGELOG.md b/CHANGELOG.md index e1de1d3..8c3085e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,13 +3,18 @@ All notable changes to this module are documented here. The project follows semantic versioning; `v0.x` versions make no API stability promise. -## Unreleased — specification v0.12 draft +## Unreleased — specification v0.12 -Implements the draft v0.12 of the DateKeys Protocol Specification, on the -branch `v0.12` and not approved yet. It fixes what the review of the -implementation of v0.11 found on 2 October 2026, and changes no format: a +Implements the DateKeys Protocol Specification v0.12, which its author +approved on 6 October 2026, tagged `spec-v0.12`. It fixes what the review of +the implementation of v0.11 found on 2 October 2026, and changes no format: a reader of v0.11 opens these capsules, and this one opens those of v0.11. -`SpecVersion` stays 0.11 until the author approves the draft. + +- **Approval.** `SpecVersion` is 0.12, and so is the `spec` field of every + file of `testdata`: the records of the fixtures and the vectors, regenerated, + and the frozen `security_cms.json` and `locator.json`, whose `spec` field + alone changes. The text approved is the draft as it stood, with only its + date changed; `spec/README.md` records its SHA-256. - **Review of 2 October.** Six adversarial reviews of the implementation of v0.11 found nothing blocking: what is signed, the strict Ed25519, the CMS diff --git a/README.es.md b/README.es.md index cd7c1db..a7444cc 100644 --- a/README.es.md +++ b/README.es.md @@ -1,10 +1,8 @@ # datekeys-go Implementación de referencia en Go de la **DateKeys Protocol Specification -v0.11** ([`spec/`](spec/DateKeys_Protocol_Specification_v0.11.md)), etiquetada -`spec-v0.11`. Esta rama, `v0.12`, implementa además el borrador v0.12 -([`spec/`](spec/DateKeys_Protocol_Specification_v0.12.md)), aún sin aprobar, -que no cambia ningún formato. +v0.12** ([`spec/`](spec/DateKeys_Protocol_Specification_v0.12.md)), etiquetada +`spec-v0.12`, que no cambia ningún formato de la v0.11. [English version](README.md). DateKeys cifra datos de forma que solo puedan abrirse a partir de un instante @@ -64,13 +62,13 @@ Hay tres números de versión, cada uno con su significado: | Versión | Dónde | Cambia cuando | |---|---|---| | Formato | Dentro de los objetos: el formato de la cápsula, el `VERSION` del prelude de DKC1, 3 al escribir y de 1 a 3 al leer, que es también la versión de schema de CONTROL_CBOR; y 1 en la trama de DKK1 y en el schema de los demás objetos, incluidos el head y `security` del formato 3 | Cambia el formato. Un lector rechaza una versión que no conoce (spec §22, §70) | -| Especificación | `datekeys.SpecVersion`, hoy `0.11`, y el tag `spec-v0.11`. Un borrador, como la v0.12, no tiene tag ni la cambia | Cambia el texto normativo. §76 del spec recoge cada cambio con su caso | +| Especificación | `datekeys.SpecVersion`, hoy `0.12`, y el tag `spec-v0.12`. Un borrador, como la v0.12, no tiene tag ni la cambia | Cambia el texto normativo. §76 del spec recoge cada cambio con su caso | | Módulo | Los tags de este módulo Go, `vX.Y.Z`, y `datekeys.Version()` | Cambia la API o el comportamiento. Versionado semántico, sin promesa de estabilidad antes de v1.0.0 | `datekeys version` imprime la versión del módulo, la del spec y la del toolchain de Go. Un binario compilado en un checkout muestra la pseudo-versión de su commit, por ejemplo `v0.0.0-20260928105528-9ac9cd952f04`. Cada release dice qué cubre, aquí y en el [CHANGELOG](CHANGELOG.md). El código de esta rama, aún sin publicar, cubre: -- la especificación 0.11 y el borrador v0.12: escribe el formato 3 de cápsula y lee los formatos 1, 2 y 3; +- la especificación 0.12: escribe el formato 3 de cápsula y lee los formatos 1, 2 y 3; - el perfil Quicknet pinneado, y cualquier perfil de los tres schemes de drand que soporta tlock; - cifrado, inspección y apertura, firmas de autor y sellos, la nota pública, la llave de palabras y el localizador, y la CLI; - todos los vectores y fixtures compartidos de [`testdata/`](testdata). diff --git a/README.md b/README.md index 781c595..7be0b0d 100644 --- a/README.md +++ b/README.md @@ -1,10 +1,8 @@ # datekeys-go Reference implementation in Go of the **DateKeys Protocol Specification -v0.11** ([`spec/`](spec/DateKeys_Protocol_Specification_v0.11.md)), tagged -`spec-v0.11`. This branch, `v0.12`, also implements the draft v0.12 -([`spec/`](spec/DateKeys_Protocol_Specification_v0.12.md)), not approved yet, -which changes no format. +v0.12** ([`spec/`](spec/DateKeys_Protocol_Specification_v0.12.md)), tagged +`spec-v0.12`, which changes no format of v0.11. [Versión en español](README.es.md). DateKeys encrypts data so that it can only be opened after a chosen instant. @@ -64,13 +62,13 @@ Three version numbers, each with its own meaning: | Version | Where | Changes when | |---|---|---| | Format | Inside the objects: the capsule format, the `VERSION` of the DKC1 prelude, 3 when written and 1 to 3 when read, which is also the schema version of CONTROL_CBOR; and 1 for the framing of DKK1 and the schema of the other objects, the head and security of format 3 included | The format changes. A reader rejects a version it does not know (spec §22, §70) | -| Specification | `datekeys.SpecVersion`, today `0.11`, and the tag `spec-v0.11`. A draft, such as v0.12, has no tag and does not change it | The normative text changes. Spec §76 records each change with its case | +| Specification | `datekeys.SpecVersion`, today `0.12`, and the tag `spec-v0.12`. A draft, such as v0.12, has no tag and does not change it | The normative text changes. Spec §76 records each change with its case | | Module | The tags of this Go module, `vX.Y.Z`, and `datekeys.Version()` | The API or the behaviour changes. Semantic versioning, with no stability promise before v1.0.0 | `datekeys version` prints the module version, the specification and the Go toolchain. A binary built in a checkout shows the pseudo-version of its commit, for example `v0.0.0-20260928105528-9ac9cd952f04`. Each release states what it covers, here and in the [CHANGELOG](CHANGELOG.md). The code of this branch, not yet released, covers: -- specification 0.11 and the draft v0.12: it writes capsule format 3 and reads formats 1, 2 and 3; +- specification 0.12: it writes capsule format 3 and reads formats 1, 2 and 3; - the pinned Quicknet profile, and any profile on the three drand schemes that tlock supports; - encryption, inspection and opening, author signatures and seals, the public note, the key of words and the locator, and the CLI; - every shared vector and fixture of [`testdata/`](testdata). diff --git a/SECURITY.md b/SECURITY.md index b5e9cd3..de4ce24 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -19,9 +19,8 @@ The module is pre-1.0 (`v0.x`). Only the latest `v0.x` release receives fixes. ## Scope and assumptions -In scope: every rule of the DateKeys Protocol Specification v0.11, tagged -`spec-v0.11`, and of the draft v0.12 of the branch `v0.12`, that this module -implements (see `docs/traceability.md`), the CLI, and the handling of +In scope: every rule of the DateKeys Protocol Specification v0.12, tagged +`spec-v0.12`, that this module implements (see `docs/traceability.md`), the CLI, and the handling of untrusted input (`.dkc`, `.dkk`, relay responses, author key files). Among it: the paths and texts of a format 3 head, which the CLI writes to disk and to a terminal; the signatures, certificates and seals of the security area, whose diff --git a/docs/traceability.md b/docs/traceability.md index 24be925..000eff3 100644 --- a/docs/traceability.md +++ b/docs/traceability.md @@ -7,9 +7,8 @@ reviewer together with the specification, the fixtures and the mutation corpus (plan §10). Paths are relative to the repository root. `§` numbers refer to -`spec/DateKeys_Protocol_Specification_v0.12.md`, the draft of the branch -`v0.12`, not approved yet; v0.11, tagged `spec-v0.11`, numbers its sections -the same. A case of §64 that is not in the repository yet is marked +`spec/DateKeys_Protocol_Specification_v0.12.md`, tagged `spec-v0.12`; +v0.11, tagged `spec-v0.11`, numbers its sections the same. A case of §64 that is not in the repository yet is marked *pending*. ## Section map diff --git a/internal/testkit/genfixtures/cmsvectors.go b/internal/testkit/genfixtures/cmsvectors.go index 4ed93d0..9c20e02 100644 --- a/internal/testkit/genfixtures/cmsvectors.go +++ b/internal/testkit/genfixtures/cmsvectors.go @@ -55,9 +55,8 @@ var ( ) // cmsVectorSpec labels security_cms.json, as every file of testdata, with -// SpecVersion. Its verdicts are those of the draft v0.12, with the profile of -// the certificate of §29.10 and the texts of §29.7, which this branch -// implements: SpecVersion becomes 0.12 when the draft is approved. +// SpecVersion. Its verdicts are those of v0.12, with the profile of the +// certificate of §29.10 and the texts of §29.7. const cmsVectorSpec = testkit.SpecVersion func hex32(b [32]byte) string { return hex.EncodeToString(b[:]) } diff --git a/internal/testkit/genfixtures/locatorvectors.go b/internal/testkit/genfixtures/locatorvectors.go index 45124de..0db1963 100644 --- a/internal/testkit/genfixtures/locatorvectors.go +++ b/internal/testkit/genfixtures/locatorvectors.go @@ -37,7 +37,7 @@ const locatorCID = "bafybeigdyrzt5sfp7udm7hu76uh7y26nf3efuylqabf3oclgtqy55fbzdi" // plaintexts of the locator. Each case is checked against this module. // // It labels locator.json, as every file of testdata, with SpecVersion: its -// cases are those of the draft v0.12, which this branch implements. +// cases are those of v0.12. func locatorVectors() (any, error) { p := profile.Quicknet() dkc := patterned("locator dkc", 5000) diff --git a/spec/DateKeys_Protocol_Specification_v0.12.md b/spec/DateKeys_Protocol_Specification_v0.12.md index 551b5ca..bed2856 100644 --- a/spec/DateKeys_Protocol_Specification_v0.12.md +++ b/spec/DateKeys_Protocol_Specification_v0.12.md @@ -3,7 +3,7 @@ ### Borrador normativo v0.12 **Estado:** Draft / pre-estándar -**Fecha:** 2 octubre 2026 (borrador en curso, sin aprobar) +**Fecha:** 6 octubre 2026, aprobado por su autor ese día **Proyecto:** DateKeys **Implementación de referencia prevista:** Go **Proveedor temporal V1:** drand Quicknet diff --git a/spec/README.md b/spec/README.md index 94d1885..7709f2e 100644 --- a/spec/README.md +++ b/spec/README.md @@ -31,20 +31,22 @@ changing the format. Its §76 records each change with its reproducible case. - `DateKeys_Protocol_Specification_v0.11.md`: frozen copy of the normative draft v0.11 (1 October 2026), approved by its author on that date and - tagged `spec-v0.11`; this module implements it. SHA-256: + tagged `spec-v0.11`. SHA-256: `25cf1039d16666199c662e88e838a1d2ef0507be68e17fecd9aeee5d85a5bb6e`. It defines the author signature of format 3, with an Ed25519 key of one's own or with X.509 certificates (CMS, one or several signers, a CAdES-T timestamp each), the RFC 3161 seal, a fixed area of 32 KiB, the key of words, the public note and the capsule extension of the .dkk. Its §76 records each change with its reproducible case. -- `DateKeys_Protocol_Specification_v0.12.md`: the draft v0.12, work in - progress and not approved; this branch implements it. It changes no - format: it fixes what the review of the implementation of v0.11 found, the +- `DateKeys_Protocol_Specification_v0.12.md`: frozen copy of the normative + draft v0.12 (6 October 2026), approved by its author on that date and + tagged `spec-v0.12`; this module implements it. SHA-256: + `afc31fd8105d650773d093ac01bd2f5e0b56af04726f4e75c652e2cf9308ac3f`. + It changes no format: it fixes what the review of the implementation of v0.11 found, the names of certificates and the warning of the seal in the verdicts, a profile of the certificate field by field, the addresses and the padding of the locator, and errata. Its §76 records each change with its case. -- `datekeys.cddl`: the CBOR schemas of the v0.12 draft, the three control +- `datekeys.cddl`: the CBOR schemas of v0.12, the three control versions and the security and head objects of format 3 included, with the encoding rules CDDL cannot express. Those of v0.9 and v0.8.2 are at the tags `spec-v0.9` and `spec-v0.8.2`. diff --git a/testdata/README.md b/testdata/README.md index 2422f03..314ca5b 100644 --- a/testdata/README.md +++ b/testdata/README.md @@ -1,7 +1,7 @@ # DateKeys test data Official vectors, fixtures and corpora of the DateKeys Protocol Specification -v0.11 and of the draft v0.12, generated by the reference implementation. +v0.12, generated by the reference implementation. Another implementation consumes them as they are: this file documents every format, so that no Go code has to be read. The rules that decide each verdict are in the specification; this file points to them, and states only what @@ -21,12 +21,12 @@ added since. The local gate (`scripts/check.sh`) and CI run it and fail if any committed file changes: every file below is exactly what the implementation computes today. -The `spec` field of every file is `"0.11"`, the version this module declares, -until the author approves the draft v0.12. What the draft changes, the texts -of the verdicts of a certificate and of a seal, the profile of a certificate -and the rules of the addresses and of the padding of a locator, is already in -the files: the verdicts and the lines of `security.json`, `security_cms.json` -and `mutations.json`, and the cases of `locator.json`, are those of the draft. +The `spec` field of every file is `"0.12"`, the version this module declares. +What v0.12 changes from v0.11, the texts of the verdicts of a certificate and +of a seal, the profile of a certificate and the rules of the addresses and of +the padding of a locator, is in the files: the verdicts and the lines of +`security.json`, `security_cms.json` and `mutations.json`, and the cases of +`locator.json`, are those of v0.12. Conventions for every file: @@ -457,7 +457,7 @@ in `security_cms.json`. Security areas with an author signature of `alg` 2, a CMS signature with certificates, or a time seal of `seal_type` 2, an RFC 3161 token: 135 cases, each with the context of its capsule, the verdicts, the result of each signer -and the lines of the draft v0.12, §29.7, §29.10 and §29.11. They complete +and the lines of v0.12, §29.7, §29.10 and §29.11. They complete `security.json`, whose areas have no valid signature or seal of these kinds. The file is frozen: the certificates and the tokens are made once, with test keys, so a second implementation reads them and must reach the same verdicts diff --git a/testdata/fixtures/empty_payload.json b/testdata/fixtures/empty_payload.json index 5635a6a..75c98b2 100644 --- a/testdata/fixtures/empty_payload.json +++ b/testdata/fixtures/empty_payload.json @@ -1,6 +1,6 @@ { "description": "time_only capsule with an empty payload", - "spec": "0.11", + "spec": "0.12", "format": 1, "file": "empty_payload.dkc", "sha256": "871e9bf05b52bbae17f3adfbbf97b46e7f0e53aa8f57bcaa506e43f36f53a9d4", diff --git a/testdata/fixtures/format2_empty_payload.json b/testdata/fixtures/format2_empty_payload.json index e8fdf9b..009a53f 100644 --- a/testdata/fixtures/format2_empty_payload.json +++ b/testdata/fixtures/format2_empty_payload.json @@ -1,6 +1,6 @@ { "description": "format 2 time_only capsule with an empty content: L = 0, P = 256", - "spec": "0.11", + "spec": "0.12", "format": 2, "file": "format2_empty_payload.dkc", "sha256": "7aea2b5aa48b1a46053716f733d50fab9cd0b80b1be67631bcc06c5bb765dc21", diff --git a/testdata/fixtures/format2_time_and_key_portable.dkk.json b/testdata/fixtures/format2_time_and_key_portable.dkk.json index 174c9a6..1ab2d16 100644 --- a/testdata/fixtures/format2_time_and_key_portable.dkk.json +++ b/testdata/fixtures/format2_time_and_key_portable.dkk.json @@ -1,6 +1,6 @@ { "description": "portable X25519 .dkk of format2_time_and_key_portable.dkc", - "spec": "0.11", + "spec": "0.12", "file": "format2_time_and_key_portable.dkk", "sha256": "095b7bc516a22bf0c2366f0af3cd48bfe857a2354d6e2a9b285278b95e450fe0", "credential_id": "e3c7be83cbf1fbd6b115c96411b3bd01", diff --git a/testdata/fixtures/format2_time_and_key_portable.json b/testdata/fixtures/format2_time_and_key_portable.json index 48e9301..059ee59 100644 --- a/testdata/fixtures/format2_time_and_key_portable.json +++ b/testdata/fixtures/format2_time_and_key_portable.json @@ -1,6 +1,6 @@ { "description": "format 2 time_and_key capsule with one credential, a portable .dkk, and 15 dummies", - "spec": "0.11", + "spec": "0.12", "format": 2, "file": "format2_time_and_key_portable.dkc", "sha256": "600892659fe4890223e895876275f656995d170fda42b07fb2bec0ca51ce4b43", diff --git a/testdata/fixtures/format2_time_and_key_recipients.dkk.json b/testdata/fixtures/format2_time_and_key_recipients.dkk.json index 077f928..e96aa23 100644 --- a/testdata/fixtures/format2_time_and_key_recipients.dkk.json +++ b/testdata/fixtures/format2_time_and_key_recipients.dkk.json @@ -1,6 +1,6 @@ { "description": "portable X25519 .dkk of format2_time_and_key_recipients.dkc", - "spec": "0.11", + "spec": "0.12", "file": "format2_time_and_key_recipients.dkk", "sha256": "2ad99b1556086ec311d7f0b3bd3aaba05e75f45c4fa22490b0d5e8bb0b1a222e", "credential_id": "93cedf68421710e83908ec683b104436", diff --git a/testdata/fixtures/format2_time_and_key_recipients.json b/testdata/fixtures/format2_time_and_key_recipients.json index 9cf68cf..50a5e43 100644 --- a/testdata/fixtures/format2_time_and_key_recipients.json +++ b/testdata/fixtures/format2_time_and_key_recipients.json @@ -1,6 +1,6 @@ { "description": "format 2 time_and_key capsule for three known X25519 recipients and a portable .dkk, and 12 dummies", - "spec": "0.11", + "spec": "0.12", "format": 2, "file": "format2_time_and_key_recipients.dkc", "sha256": "1a44fd8708c92e2e0a10cfcb1d864a71331ea9af25d97e1a42e969dc898959e3", diff --git a/testdata/fixtures/format2_time_and_key_sixteen.json b/testdata/fixtures/format2_time_and_key_sixteen.json index f68f0e8..447d153 100644 --- a/testdata/fixtures/format2_time_and_key_sixteen.json +++ b/testdata/fixtures/format2_time_and_key_sixteen.json @@ -1,6 +1,6 @@ { "description": "format 2 time_and_key capsule for sixteen known X25519 recipients, without dummies", - "spec": "0.11", + "spec": "0.12", "format": 2, "file": "format2_time_and_key_sixteen.dkc", "sha256": "7aaac5c18f216bf53df326ecc817179640a53408cf25dfd50488910a762dc381", diff --git a/testdata/fixtures/format2_time_only.json b/testdata/fixtures/format2_time_only.json index b512421..92fda84 100644 --- a/testdata/fixtures/format2_time_only.json +++ b/testdata/fixtures/format2_time_only.json @@ -1,6 +1,6 @@ { "description": "format 2 time_only capsule, padding code 2 (reforzado): L = 78000, P = 79872, two STREAM chunks", - "spec": "0.11", + "spec": "0.12", "format": 2, "file": "format2_time_only.dkc", "sha256": "f5a40ac6b8a08a0c12db6114c2bca23522d6a77b512b509a217fb15f367813c4", diff --git a/testdata/fixtures/format2_time_only_bloque256.json b/testdata/fixtures/format2_time_only_bloque256.json index e33a559..4998ff4 100644 --- a/testdata/fixtures/format2_time_only_bloque256.json +++ b/testdata/fixtures/format2_time_only_bloque256.json @@ -1,6 +1,6 @@ { "description": "format 2 time_only capsule with the content of format2_time_only and padding code 1 (bloque256): L = 78000, P = 78080", - "spec": "0.11", + "spec": "0.12", "format": 2, "file": "format2_time_only_bloque256.dkc", "sha256": "aae769c30d04920801d8b293d30864fbe223c9c9353ec2b4907a1ee1996e39f9", diff --git a/testdata/fixtures/format2_time_only_extensions.json b/testdata/fixtures/format2_time_only_extensions.json index 5ed3d23..aaf7d3b 100644 --- a/testdata/fixtures/format2_time_only_extensions.json +++ b/testdata/fixtures/format2_time_only_extensions.json @@ -1,6 +1,6 @@ { "description": "format 2 time_only capsule with a noncritical PUBLIC_HEADER extension and a noncritical CONTROL_CBOR extension", - "spec": "0.11", + "spec": "0.12", "format": 2, "file": "format2_time_only_extensions.dkc", "sha256": "fb406100d5703a2e888983b3175ed34a09a34469cc722256e5cf535dd728fbe9", diff --git a/testdata/fixtures/format3_area_1024.json b/testdata/fixtures/format3_area_1024.json index b3a0fd8..8e339d9 100644 --- a/testdata/fixtures/format3_area_1024.json +++ b/testdata/fixtures/format3_area_1024.json @@ -1,6 +1,6 @@ { "description": "format 3 time_only capsule with a security area of 1024 bytes, as a later version may write it, holding the empty security", - "spec": "0.11", + "spec": "0.12", "format": 3, "file": "format3_area_1024.dkc", "sha256": "41ea2eed0293e4fef7f4a307b7f16aaf1339f5bf6f4ded7a6a9ae1aebeb0133c", diff --git a/testdata/fixtures/format3_bloque256.json b/testdata/fixtures/format3_bloque256.json index 71902ca..a09df15 100644 --- a/testdata/fixtures/format3_bloque256.json +++ b/testdata/fixtures/format3_bloque256.json @@ -1,6 +1,6 @@ { "description": "format 3 time_only capsule with padding code 1 (bloque256) and one file of 20000 bytes", - "spec": "0.11", + "spec": "0.12", "format": 3, "file": "format3_bloque256.dkc", "sha256": "ff18444f434164ba8e7b26d38c76c7855dc6b0593b2fc8b4e9a95dbf9252d55d", diff --git a/testdata/fixtures/format3_comment_only.json b/testdata/fixtures/format3_comment_only.json index 455aa3e..a6e8d3d 100644 --- a/testdata/fixtures/format3_comment_only.json +++ b/testdata/fixtures/format3_comment_only.json @@ -1,6 +1,6 @@ { "description": "format 3 time_only capsule with a comment of two lines, the second one with a TAB, a declared author and no files", - "spec": "0.11", + "spec": "0.12", "format": 3, "file": "format3_comment_only.dkc", "sha256": "7f98a89413f08655bbbab28b96585dfa6173c1705dd81a900deba2100d19f2ef", diff --git a/testdata/fixtures/format3_note.json b/testdata/fixtures/format3_note.json index f927304..11538d3 100644 --- a/testdata/fixtures/format3_note.json +++ b/testdata/fixtures/format3_note.json @@ -1,6 +1,6 @@ { "description": "format 3 time_only capsule with a single file, nota.txt, and the public note «Cartas del viaje a Lisboa» in the noncritical array of PUBLIC_HEADER (spec v0.11, §24.1)", - "spec": "0.11", + "spec": "0.12", "format": 3, "file": "format3_note.dkc", "sha256": "da1bee54231252a0fd98439e24588125c5521f6e5a2c6641b499e6b22192c0eb", diff --git a/testdata/fixtures/format3_seal_unsupported.json b/testdata/fixtures/format3_seal_unsupported.json index 5eff7fa..72cb7c8 100644 --- a/testdata/fixtures/format3_seal_unsupported.json +++ b/testdata/fixtures/format3_seal_unsupported.json @@ -1,6 +1,6 @@ { "description": "format 3 time_only capsule with an author-signature of alg 4294967295, as in format3_signature_unsupported, and a seal of seal_type 4294967295, reserved for tests, with a random token of 32 bytes: verdicts F1 and S1", - "spec": "0.11", + "spec": "0.12", "format": 3, "file": "format3_seal_unsupported.dkc", "sha256": "ae3219fbdbd1de4cef6fade1a3fb3f6e5d5e2e8af54d9516b05f0a48136913ad", diff --git a/testdata/fixtures/format3_sealed.json b/testdata/fixtures/format3_sealed.json index 06fc87c..17e6c2e 100644 --- a/testdata/fixtures/format3_sealed.json +++ b/testdata/fixtures/format3_sealed.json @@ -1,6 +1,6 @@ { "description": "format 3 time_only capsule with a single file, nota.txt, signed with alg 1 by the test key of format3_signed and sealed with seal_type 2 by a test time-stamping authority before the round time: verdicts F4 and S4, with SEAL_SUBJECT and the token in the record", - "spec": "0.11", + "spec": "0.12", "format": 3, "file": "format3_sealed.dkc", "sha256": "dde5a072d8783227d28279d06d3d226a1fb967c766da626f889d1c6fd76ac9c7", diff --git a/testdata/fixtures/format3_security_v2.json b/testdata/fixtures/format3_security_v2.json index 15700b5..425a2d5 100644 --- a/testdata/fixtures/format3_security_v2.json +++ b/testdata/fixtures/format3_security_v2.json @@ -1,6 +1,6 @@ { "description": "format 3 time_only capsule whose security is of version 2: verdict X", - "spec": "0.11", + "spec": "0.12", "format": 3, "file": "format3_security_v2.dkc", "sha256": "3d02b39ace010d74604554e378d22fe5ce00cecd998c0f797d657b17620b8912", diff --git a/testdata/fixtures/format3_signature_unsupported.json b/testdata/fixtures/format3_signature_unsupported.json index 0b7aaae..fcaa121 100644 --- a/testdata/fixtures/format3_signature_unsupported.json +++ b/testdata/fixtures/format3_signature_unsupported.json @@ -1,6 +1,6 @@ { "description": "format 3 time_only capsule with an author-signature of alg 4294967295, a random key of 32 bytes and a random signature of 64: verdicts F1 and S0", - "spec": "0.11", + "spec": "0.12", "format": 3, "file": "format3_signature_unsupported.dkc", "sha256": "e8e3106d8d73bb7b845062e0fe42af21df7d7cd8f63c335cab8dedb3e690df31", diff --git a/testdata/fixtures/format3_signed.json b/testdata/fixtures/format3_signed.json index b24064c..3a72218 100644 --- a/testdata/fixtures/format3_signed.json +++ b/testdata/fixtures/format3_signed.json @@ -1,6 +1,6 @@ { "description": "format 3 time_only capsule with a single file, nota.txt, signed with alg 1 by a test key whose seed the record gives: verdict F4, and the commitments and the message of the signature", - "spec": "0.11", + "spec": "0.12", "format": 3, "file": "format3_signed.dkc", "sha256": "3c7d3c9e24c02853a0c7761b93bea1120b27fce396468d8d0f68e53aeb668c5e", diff --git a/testdata/fixtures/format3_signed_cms.json b/testdata/fixtures/format3_signed_cms.json index 84b6165..27af426 100644 --- a/testdata/fixtures/format3_signed_cms.json +++ b/testdata/fixtures/format3_signed_cms.json @@ -1,6 +1,6 @@ { "description": "format 3 time_only capsule with a single file, nota.txt, signed with alg 2 by two test certificates, an ECDSA P-256 one and an RSA 2048 one, each sealed by a test time-stamping authority before the round time: verdict F6, with the certificates, the commitments, SIGNERS and the result of each signer in the record", - "spec": "0.11", + "spec": "0.12", "format": 3, "file": "format3_signed_cms.dkc", "sha256": "d658f8d5ac2c5550c07b8f8fd6883b2f6dc02ceafc47d436ea02d8950b2548d2", diff --git a/testdata/fixtures/format3_single.json b/testdata/fixtures/format3_single.json index 002ad2a..f541493 100644 --- a/testdata/fixtures/format3_single.json +++ b/testdata/fixtures/format3_single.json @@ -1,6 +1,6 @@ { "description": "format 3 time_only capsule with a single file, nota.txt, with its mtime", - "spec": "0.11", + "spec": "0.12", "format": 3, "file": "format3_single.dkc", "sha256": "9f68664af8733255084be9036a100b75d27bd16106bf0acff94ce469dd1d1743", diff --git a/testdata/fixtures/format3_time_and_key_portable.dkk.json b/testdata/fixtures/format3_time_and_key_portable.dkk.json index 0882b2b..01d4e23 100644 --- a/testdata/fixtures/format3_time_and_key_portable.dkk.json +++ b/testdata/fixtures/format3_time_and_key_portable.dkk.json @@ -1,6 +1,6 @@ { "description": "portable X25519 .dkk of format3_time_and_key_portable.dkc", - "spec": "0.11", + "spec": "0.12", "file": "format3_time_and_key_portable.dkk", "sha256": "54cc64d849395234b3e093e47f432b72781ccc13f455c9ef394e3554ab566751", "credential_id": "bdb483fba42daf0b409f44d23033f362", diff --git a/testdata/fixtures/format3_time_and_key_portable.json b/testdata/fixtures/format3_time_and_key_portable.json index b17e49e..7fe5cf5 100644 --- a/testdata/fixtures/format3_time_and_key_portable.json +++ b/testdata/fixtures/format3_time_and_key_portable.json @@ -1,6 +1,6 @@ { "description": "format 3 time_and_key capsule with one credential, a portable .dkk, and 15 dummies", - "spec": "0.11", + "spec": "0.12", "format": 3, "file": "format3_time_and_key_portable.dkc", "sha256": "680d29962e575689a31543df28433dae7737abd9a793e9cae92ef40920d09636", diff --git a/testdata/fixtures/format3_tree.json b/testdata/fixtures/format3_tree.json index 19145d1..0c3d770 100644 --- a/testdata/fixtures/format3_tree.json +++ b/testdata/fixtures/format3_tree.json @@ -1,6 +1,6 @@ { "description": "format 3 time_only capsule with five files in three folders, one of them over two STREAM chunks and one without mtime, a comment of two lines and a declared author", - "spec": "0.11", + "spec": "0.12", "format": 3, "file": "format3_tree.dkc", "sha256": "217f378faaf795f6a9c416b564fb8931bb2e896918aee870120fd14f9a5da7d1", diff --git a/testdata/fixtures/format3_unsigned.json b/testdata/fixtures/format3_unsigned.json index c94e6a8..534563a 100644 --- a/testdata/fixtures/format3_unsigned.json +++ b/testdata/fixtures/format3_unsigned.json @@ -1,6 +1,6 @@ { "description": "format 3 time_only capsule with a single file, nota.txt, as format3_signed, without a signature: the area of 32 KiB of spec v0.11 holds the empty security, and P is the one of format3_signed", - "spec": "0.11", + "spec": "0.12", "format": 3, "file": "format3_unsigned.dkc", "sha256": "317ab722ae3812a25ddd78b4c98c586363e5587c8d3634c881ce7c421af19168", diff --git a/testdata/fixtures/time_and_key_portable.dkk.json b/testdata/fixtures/time_and_key_portable.dkk.json index 32c7264..be683aa 100644 --- a/testdata/fixtures/time_and_key_portable.dkk.json +++ b/testdata/fixtures/time_and_key_portable.dkk.json @@ -1,6 +1,6 @@ { "description": "portable X25519 .dkk of time_and_key_portable.dkc", - "spec": "0.11", + "spec": "0.12", "file": "time_and_key_portable.dkk", "sha256": "e528fa2c832c91119f0684bb9d6fb3c4c2d0d55183482890e7c4fe92f668426a", "credential_id": "3955e944a3c60cfa1fd6485e9693c77d", diff --git a/testdata/fixtures/time_and_key_portable.json b/testdata/fixtures/time_and_key_portable.json index 535b9e9..b4de7a8 100644 --- a/testdata/fixtures/time_and_key_portable.json +++ b/testdata/fixtures/time_and_key_portable.json @@ -1,6 +1,6 @@ { "description": "time_and_key capsule whose only recipient is a portable .dkk", - "spec": "0.11", + "spec": "0.12", "format": 1, "file": "time_and_key_portable.dkc", "sha256": "2e97878078bae6358037a9c264f379a3cbe839f767d69836b0343f35657b2972", diff --git a/testdata/fixtures/time_and_key_portable_extension.dkk.json b/testdata/fixtures/time_and_key_portable_extension.dkk.json index 904069d..e32ab2a 100644 --- a/testdata/fixtures/time_and_key_portable_extension.dkk.json +++ b/testdata/fixtures/time_and_key_portable_extension.dkk.json @@ -1,6 +1,6 @@ { "description": "portable X25519 .dkk of time_and_key_portable.dkc with a noncritical extension: the credential of time_and_key_portable.dkk re-issued with org.example.delivery", - "spec": "0.11", + "spec": "0.12", "file": "time_and_key_portable_extension.dkk", "sha256": "0bf463a7c65627b7dda2234d728df89ec5b835816a2a37b91497d8fecc5ea548", "credential_id": "3955e944a3c60cfa1fd6485e9693c77d", diff --git a/testdata/fixtures/time_and_key_recipients.dkk.json b/testdata/fixtures/time_and_key_recipients.dkk.json index 8d63d98..9d3cab7 100644 --- a/testdata/fixtures/time_and_key_recipients.dkk.json +++ b/testdata/fixtures/time_and_key_recipients.dkk.json @@ -1,6 +1,6 @@ { "description": "portable X25519 .dkk of time_and_key_recipients.dkc", - "spec": "0.11", + "spec": "0.12", "file": "time_and_key_recipients.dkk", "sha256": "19f6c47150c3194712d454f43c7392b7344e6b4e7b074d83e9ca5f563a8e072f", "credential_id": "b89292aedf6d05d584cec9a871ce8735", diff --git a/testdata/fixtures/time_and_key_recipients.json b/testdata/fixtures/time_and_key_recipients.json index 5d83caa..ea18209 100644 --- a/testdata/fixtures/time_and_key_recipients.json +++ b/testdata/fixtures/time_and_key_recipients.json @@ -1,6 +1,6 @@ { "description": "time_and_key capsule for two known X25519 recipients and a portable .dkk", - "spec": "0.11", + "spec": "0.12", "format": 1, "file": "time_and_key_recipients.dkc", "sha256": "69ac110380f5d768b5b6afaa157a50ed17d8ceccfbd4604ffa5b6da38539b635", diff --git a/testdata/fixtures/time_only.json b/testdata/fixtures/time_only.json index ac9576d..5f226a2 100644 --- a/testdata/fixtures/time_only.json +++ b/testdata/fixtures/time_only.json @@ -1,6 +1,6 @@ { "description": "time_only capsule, two STREAM chunks, no extensions", - "spec": "0.11", + "spec": "0.12", "format": 1, "file": "time_only.dkc", "sha256": "99e915810d595f1092700b728f5e5081d78efe83f5343e76325b1bcc2c33ccf2", diff --git a/testdata/fixtures/time_only_extensions.json b/testdata/fixtures/time_only_extensions.json index 65e2fd9..d1109fd 100644 --- a/testdata/fixtures/time_only_extensions.json +++ b/testdata/fixtures/time_only_extensions.json @@ -1,6 +1,6 @@ { "description": "time_only capsule with a noncritical PUBLIC_HEADER extension and a noncritical CONTROL_CBOR extension", - "spec": "0.11", + "spec": "0.12", "format": 1, "file": "time_only_extensions.dkc", "sha256": "0446c9b73e267adcb24e5cc89afba2544a386ec9a050016e06517a4a57aa2085", diff --git a/testdata/vectors/cbor.json b/testdata/vectors/cbor.json index fafd867..c642cf8 100644 --- a/testdata/vectors/cbor.json +++ b/testdata/vectors/cbor.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "description": "CBOR profile of spec §58 and the schemas of spec/datekeys.cddl, generated by the reference implementation. accept and reject are walked as one data item of the profile with the limits of walk; schemas are decoded with the decoder of their schema. See testdata/README.md.", "walk": { "max_depth": 3, diff --git a/testdata/vectors/dk1.json b/testdata/vectors/dk1.json index f9e4d3e..a56b565 100644 --- a/testdata/vectors/dk1.json +++ b/testdata/vectors/dk1.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "description": "Canonical dk1_ strings and rejected encodings (spec §18, §19, §66), generated by the reference implementation.", "vectors": [ { diff --git a/testdata/vectors/ed25519_strict.json b/testdata/vectors/ed25519_strict.json index 027ba46..0f431aa 100644 --- a/testdata/vectors/ed25519_strict.json +++ b/testdata/vectors/ed25519_strict.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "description": "Ed25519 signatures and the result of the strict profile of the author signature (spec v0.11, §29.9), after the cases of «Taming the many EdDSAs»; stdlib is the result of crypto/ed25519 of Go, for the record. Generated by the reference implementation. See testdata/README.md.", "vectors": [ { diff --git a/testdata/vectors/head_schema.json b/testdata/vectors/head_schema.json index ea79eef..dbaa389 100644 --- a/testdata/vectors/head_schema.json +++ b/testdata/vectors/head_schema.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "description": "HEAD_CBOR of format 3 (spec §29.4 to §29.6) and the result of decoding it with no extension known, generated by the reference implementation: layer 2 (type tag and version), layer 3 (the CDDL with R1 and R8), then layer 4 in key order (spec §69.1). See testdata/README.md.", "heads": [ { diff --git a/testdata/vectors/inspect_differential.json b/testdata/vectors/inspect_differential.json index dbd21d3..574ac98 100644 --- a/testdata/vectors/inspect_differential.json +++ b/testdata/vectors/inspect_differential.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "description": "Differential corpus of the pre-unlock checks (spec §63 steps 1 to 8): deterministic mutations of the official .dkc fixtures with the verdict of the reference implementation. See testdata/README.md.", "format": "Each mutation is bases[base].file (in testdata/fixtures) with its edits applied. An edit is [at, delete, insert]: the delete bytes at offset at of the base are replaced by the bytes of the hex string insert. The edits of one mutation refer to offsets of the unmodified base, are sorted by offset and do not overlap. result is the verdict of steps 1 to 8 of spec §63 (capsule.Inspect, the Quicknet profile pinned, no extension known, no network, no secret): ok, or the normative error code, with step the step that failed. kind names the generator of the mutation and is informative.", "seed": 20260925, diff --git a/testdata/vectors/locator.json b/testdata/vectors/locator.json index 8fc3cf8..0114c01 100644 --- a/testdata/vectors/locator.json +++ b/testdata/vectors/locator.json @@ -1,6 +1,6 @@ { "description": "The extension datekeys.capsule of a .dkk and what it points to (spec v0.12, 44.1): an envelope of age with its header apart from its rest, the rest hidden in a host file, the locator sealed with tlock for round 1000, and the data of the extension. On the same envelope, what a reader rejects and what it uses (64): addresses, a locator with rejected and usable addresses, resources of the rest, data of the extension and plaintexts of the locator. Frozen. See testdata/README.md.", - "spec": "0.11", + "spec": "0.12", "round": 1000, "datekey": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMH0", "note": "Cartas del viaje a Lisboa", diff --git a/testdata/vectors/mutations.json b/testdata/vectors/mutations.json index e81eb70..b3ddd19 100644 --- a/testdata/vectors/mutations.json +++ b/testdata/vectors/mutations.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "description": "Mutation corpus of spec §64 and further cases of capsule.TestMutationCorpus, generated by the reference implementation: each case is a .dkc and what the reader is given, with the normative error and the step of spec §63 at which capsule.Open fails. See testdata/README.md.", "cases": [ { diff --git a/testdata/vectors/note.json b/testdata/vectors/note.json index afaac31..cdcc148 100644 --- a/testdata/vectors/note.json +++ b/testdata/vectors/note.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "description": "The data of the public note, datekeys.note version 1 in the noncritical array of PUBLIC_HEADER (spec §24.1): the text in UTF-8, from 1 to 1024 bytes, that meets the rules of the declared author of §29.6. See testdata/README.md.", "notes": [ { diff --git a/testdata/vectors/padding.json b/testdata/vectors/padding.json index 1fee966..837f2d3 100644 --- a/testdata/vectors/padding.json +++ b/testdata/vectors/padding.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "description": "Padding rules of the payload of a format 2 capsule (spec §29.1): for each content length L, P with code 1 (bloque256) and code 2 (reforzado), and the length of PAYLOAD_AGE for each. e, s and last_bits are informative. Generated by the reference implementation. See testdata/README.md.", "l_max": 8936830510563328, "vectors": [ diff --git a/testdata/vectors/path_fold.json b/testdata/vectors/path_fold.json index cd4ccea..5aa2709 100644 --- a/testdata/vectors/path_fold.json +++ b/testdata/vectors/path_fold.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "description": "The key of R7 (spec §29.5) of segments, with the Unicode 18.0.0 tables of §29.5.1, generated by the reference implementation: nfd is NFD(segment) and key is NFD(fold(NFD(s'))), s' the segment without ZWNJ, ZWJ, VS15 and VS16. See testdata/README.md.", "unicode_version": "18.0.0", "tables_digest": "07cf5d54aea1cd13a3ecef14a06976cc49a3cdad755cf9bc10395178b93aeb07", diff --git a/testdata/vectors/paths.json b/testdata/vectors/paths.json index e8d4318..b6df43b 100644 --- a/testdata/vectors/paths.json +++ b/testdata/vectors/paths.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "description": "Paths of a format 3 head (spec §29.5) with the Unicode 18.0.0 and best-fit tables of §29.5.1, generated by the reference implementation. paths: one path and the rules of one entry, R2 to R6c and R10; trees: the paths of a head, of 0 bytes each, and the result of decoding it. See testdata/README.md.", "unicode_version": "18.0.0", "tables_digest": "07cf5d54aea1cd13a3ecef14a06976cc49a3cdad755cf9bc10395178b93aeb07", diff --git a/testdata/vectors/profile_quicknet.json b/testdata/vectors/profile_quicknet.json index de68fdf..00fc2e5 100644 --- a/testdata/vectors/profile_quicknet.json +++ b/testdata/vectors/profile_quicknet.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "description": "Quicknet Provider Profile V1: exact Deterministic CBOR and profile_hash (spec §11, §12, §75 item 2), generated by the reference implementation.", "profile_id": "datekeys:quicknet:v1", "provider": "drand", diff --git a/testdata/vectors/quicknet_rounds.json b/testdata/vectors/quicknet_rounds.json index 20c2ddc..f0cc376 100644 --- a/testdata/vectors/quicknet_rounds.json +++ b/testdata/vectors/quicknet_rounds.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "profile": "datekeys:quicknet:v1", "description": "Quicknet date to round resolution (spec §15, §16, §65), generated by the reference implementation.", "vectors": [ diff --git a/testdata/vectors/security.json b/testdata/vectors/security.json index f1bb4fc..2b45062 100644 --- a/testdata/vectors/security.json +++ b/testdata/vectors/security.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "description": "SECURITY_CBOR of format 3, exactly its SECURITY_LEN bytes, the verdicts of the signature and of the seal in the context of the file, and their lines (spec §29.3, §29.7, §29.9). See testdata/README.md.", "context": { "control_commit": "0101010101010101010101010101010101010101010101010101010101010101", diff --git a/testdata/vectors/security_cms.json b/testdata/vectors/security_cms.json index ff3c0a0..95c84db 100644 --- a/testdata/vectors/security_cms.json +++ b/testdata/vectors/security_cms.json @@ -1,6 +1,6 @@ { "description": "SECURITY_CBOR with an author signature of alg 2 or a time seal of seal_type 2, the context of its capsule, and the verdicts, the result of each signer and the lines of spec v0.12 29.7, 29.10 and 29.11. Certificates and tokens are made once with test keys and the file is frozen. See testdata/README.md.", - "spec": "0.11", + "spec": "0.12", "cases": [ { "name": "alg 2: two signers, each sealed before the round time: F6", diff --git a/testdata/vectors/tlock_ibe.json b/testdata/vectors/tlock_ibe.json index dc16e05..31602b3 100644 --- a/testdata/vectors/tlock_ibe.json +++ b/testdata/vectors/tlock_ibe.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "description": "H2 of the IBE-CCA of tlock (spec §63 step 11): SHA-256 of \"IBE-H2\" and the 576 bytes of an element of GT, c1 before c0 at every level of the tower and each coordinate of Fp in 48 bytes big-endian (the order of kilic/bls12-381), truncated to 16 bytes. Generated by the reference implementation with drand/kyber-bls12381, the pairing of tlock.", "vectors": [ { diff --git a/testdata/vectors/wordkey.json b/testdata/vectors/wordkey.json index 3dfe96d..e0b2f03 100644 --- a/testdata/vectors/wordkey.json +++ b/testdata/vectors/wordkey.json @@ -1,5 +1,5 @@ { - "spec": "0.11", + "spec": "0.12", "description": "The key of words (spec §38.1): the words of a text, after NFD, without U+0300 to U+036F, in simple lower case of Unicode 18.0.0 and split by the spaces of the list; what a writer refuses; and the identity, PBKDF2-HMAC-SHA256 of 600000 rounds, for a chain hash, a round and a capsule_id. See testdata/README.md.", "normalize": [ { diff --git a/version.go b/version.go index 7ef6dc2..c93aec3 100644 --- a/version.go +++ b/version.go @@ -10,7 +10,7 @@ import ( // spec-v0.11 in its repository. It is neither the version of the module (see // Version) nor the versions inside the objects: the capsule format, 1 to 3, // and the schema versions (spec §22, §70). -const SpecVersion = "0.11" +const SpecVersion = "0.12" // modulePath is the path of this module: the import path of its root // package, whatever the module is called.