- Three fuzz targets, in scripts/fuzz.sh too: FuzzDecodeHead (a head
that is accepted re-encodes to its input, and a rejection carries one
normative code), FuzzEvaluateSecurity (verdicts of this version, X for
both or for neither) and FuzzCheckPath (the rules of one entry and the
decoder of the head agree on every path). About a million runs each,
clean; scripts/check.sh 60s is clean.
- Spec v0.10, section 67: the fixtures of format 3 exist, so "Serán ...
(por implementar)" reads "Son ...", as for those of format 2. No rule
changes.
- spec/README.md: v0.10 approved by its author on 30 September 2026 and
implemented on this branch, with the SHA-256 of its text; the tag
spec-v0.10 waits for the author.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
internal/pathrule checks the paths and the texts of a format 3 head
(spec 29.5, 29.6) with its own tables, never with the Unicode functions
of the platform, whose version changes with each runtime.
- gen reads the 19 pinned data files (UnicodeData, DerivedCoreProperties,
CaseFolding and emoji-variation-sequences of Unicode 18.0.0, and the
15 WindowsBestFit tables), checks their SHA-256 and writes tables.go:
assigned code points, Default_Ignorable_Code_Point, full canonical
decompositions and combining classes, C and F folding, the bases of
the emoji variation sequences, and the non-ASCII code points each
code page maps to ASCII. The data files stay out of git, in .cache.
- NFD, Fold and the key of R7; CheckPath with R2 to R6c and R10,
CheckTree with R7 and then R9, and CheckComment and CheckAuthor with
the invisible-character rule. Errors name the rule and never echo the
creator's text, so that another implementation can match them.
- The canonical text of the tables has a SHA-256, TablesDigest, which
the tests recompute and a TypeScript implementation will share.
- Checked against golang.org/x/text (Unicode 15.0.0) outside this
module: NFD matches on every code point both know, and folding only
differs on the 86 Cherokee letters that CaseFolding.txt folds to upper
case, as these tables do.
- The spec pins the SHA-256 of the 19 files in 29.5.1.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The author approved it on 30-09-2026, after Unicode 18.0.0 warned that
sequences of invisible variation selectors are used to attack AI
applications. The comment and the declared author allowed the tag
characters and loose variation selectors, which hide text a model
reads, and paths allowed runs of ZWJ, ZWNJ, VS15 and VS16.
- R4b: VS15 and VS16 only right after a character that
emoji-variation-sequences.txt pairs with that selector, and ZWJ and
ZWNJ never first, last or twice in a row in a segment.
- Section 29.6: the comment and the declared author carry no
Default_Ignorable_Code_Point except that whitelist, placed as R4b
says, each line standing for a segment.
- The tables add emoji-variation-sequences.txt; section 76 records the
change as number 12, with mutations and vectors.
- The five new references of section 77 regain the two trailing spaces
that break their line, like the others.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The author chose Unicode 18.0.0, released on 16 September 2026, over
the 17.0.0 of the design: the tables freeze with capsule format 3, so
an older version would refuse for good characters that are already
standard. Section 29.5.1 now says the Unicode version is fixed with
the format, and that moving to another needs a new format (22).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- R6c only rejects a best-fit projection with '/', '\', ':' or U+0000,
and still applies R3, R5, R6 and R6b to it: bestfit1250 maps "¿" to
'?' and bestfit874 maps "§" and "♥" to C0 controls, so the stricter
rule would have refused ordinary Spanish names.
- Step 17: codes other than ERR_INTEGRITY are reported only after
reading PAYLOAD_AGE to EOF; 17.1 leaves the padding to 17.8; 17.3 and
17.6 never fail. The precedence case is the cut right after a
complete chunk, where filippo.io/age and age-encryption differ.
- Verdicts: the first matching row decides, and alg or seal_type are
read only from content that meets its schema. Sections 58 and 70
exempt SECURITY_CBOR, which only changes verdicts.
- Normative verdict texts, and the presentation rule for any text
output, paths included.
- The sink rule of section 70, the test-vector exemption of writer
rule 13 and the mtime rule 16.
- More mutations and vector coverage; a complete list of changed test
data in section 76 (checked: only two of the 125 mutations and none
of the 4380 differential cases leave VERSION 3); corrected cases.
- A closed list of the Unicode and WindowsBestFit tables, and
editorial fixes.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Delivery 1 of capsule format 3, as the author decided on 30-09-2026:
several files with their paths, sizes, SHA-256 and dates, encrypted in
the plaintext of PAYLOAD_AGE, and a security area that later versions
will fill with an author signature and a timestamp seal without
changing the format.
- VERSION 3 and CONTROL_CBOR schema 3; writers write only format 3,
readers open the three formats.
- BODY with a 12-byte frame (AREA_LEN, SECURITY_LEN, HEAD_LEN), the
security area fixed by spec version (512 bytes here), the head and
the files (new sections 29.2 to 29.7).
- The head is always version 1 in format 3; path rules R1 to R10 on
pinned Unicode 17.0.0 and WindowsBestFit tables; text rules; the
verdicts X, F0, F1, S0, S1 and S2 and their presentation.
- Step 17 split into 17.1 to 17.8 with its precedence, and the new
code ERR_HEAD_INVALID.
- Atomic delivery of several files (56), limits (57), writer rules 13
to 18, mutation tests, fixtures and the change log in 76.
- The CDDL gains control-v3, security, author-signature, seal, head and
file.
The reference implementation still implements v0.9. The design, its
reviews and the author's decisions are in the private docs repository,
spec_v0.10/formato3_diseno.md.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>