The author approved the draft v0.16 on 7 October 2026 with the
recommendation of each of its decisions: the review of v0.15 by Astra, a
seal without accuracy, the key of words in the recovery annex, a full last
chunk of age, the evidence of a signature with certificates and drand's
JSON read strictly. Only the date of the header changes in the text;
spec/README.md records its SHA-256, and annex/recovery.md is written again
with it. The READMEs, SECURITY.md, the traceability, the CDDL header, the
README of testdata and the CHANGELOG name v0.16 and its tag.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The editor had written the escapes of the sources as their characters:
the cases "round escaped as round" and "round twice, once escaped as
round" of release.json had a plain round, and the surrogate pair of
"a surrogate pair in a value" a plain emoji, so the shared vectors tested
no escaped name. TestStrictJSON had lost its escaped é, its pair and the
escape after a lone high surrogate. They are escapes again, and the texts
of words_test.go too, so that no mark or invisible character hides in the
source. release.json gained 26 cases of drand's JSON, not 25 as b570338
says; the draft and the CHANGELOG now say 26.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
SpecVersion is 0.16, and so is the spec field of every file of testdata,
the frozen security_cms.json and locator.json included. annex/recovery.md
is §79 of the draft v0.16, with the key of words in 79.7. The draft lists
the two new fixtures in 67, says in 79 what recovery_check.sh opens, and
names in 76 the tests that now exist. The CHANGELOG has its section.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The author chose CC-BY-ND-4.0 over CC-BY-4.0: the specification may be
copied and shared unchanged, with credit; a modified version or a
translation needs the written permission of its author. The recovery
annex, which travels alone next to every capsule, says so in its title.
The code stays Apache-2.0 and the word lists keep their own licenses.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The SHOULDs of the official SDK that the CLI did not follow yet. encrypt
writes next to the .dkc the recovery annex, FILE.dkc.recuperacion.txt
(spec §62.1, rule 27): datekeys.RecoveryAnnex, annex/recovery.md, which is
§79 of the specification under a title with its version and SHA-256, the
same for every capsule; TestRecoveryAnnex checks it against the text of
SpecVersion. -no-recovery leaves it out. encrypt also says what opening the
capsule years later will take (rule 26): the .dkc, a credential of a
time_and_key capsule, and the release of its round, which an archive of
releases or a cache service must keep if drand no longer serves it; and
beyond one year it recommends time_and_key to a time_only capsule (§7.6).
profile.Status and StatusOf give the state of a pinned profile in the
registry of §71, which DateKeys does not publish yet: Quicknet is active.
encrypt writes no capsule with a profile that is not active, and decrypt
and inspect warn when the profile of a capsule is compromised.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>