You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
5.8 KiB
5.8 KiB
Changelog
All notable changes to this module are documented here. The project follows
semantic versioning; v0.x versions make no API stability promise.
Unreleased — specification v0.8.2
Moves the module to the DateKeys Protocol Specification v0.8.2, whose one normative change closes the extension format (spec §76). Framing and schema versions do not change.
Breaking changes
extension.New(id, version, data []byte)takes the opaque data bytes instead of a value that it encoded as CBOR, and rejects nil or empty data. An extension without data is the literalextension.Extension{ID, Version}, which omits key 2.- Extension data (key 2) must be a byte string of at least one byte. Any other
CBOR type,
nullorh''at key 2 is nowERR_NON_CANONICAL_CBOR, so a v0.8.1 object with such data no longer decodes. The base protocol never decodes the content (§54). extension.Wire.Datais[]byte, the content of the byte string, instead ofcbor.RawMessage.codec.Validis removed: nothing decodes extension data any more.codec.FuzzValidis replaced bycodec.FuzzUnmarshal.- At most 64 extensions per array and
extension_versionat most 2^32−1, on encode and decode (ERR_NON_CANONICAL_CBOR). Anextension_idappears at most once per object, and arrays are ordered byextension_idonly. - Provider Profile:
genesis_timeis an unsigned integer, andperiodandgenesis_timeare at most 2^53−1; a negative or larger value isERR_NON_CANONICAL_CBOR. nullin a byte-string field isERR_NON_CANONICAL_CBOR(for example anullaccess_materialwasERR_ACCESS_INVALID): nil byte strings, arrays and maps now encode as empty ones, never asnull.capsule.EncodeHeaderandcapsule.DecodeHeaderenforce the 1 MiB PUBLIC_HEADER limit andaccesskey.DecodeBodythe 16 MiB BODY limit. Every frame-limit refusal, including those ofaccesskey.MarshalBodyand ofcapsule.Encryptfor SEALED_CONTROL, now wrapsERR_INTEGRITY(§57).profile.Profile.CanonicalCBORrefuses aperiodorgenesis_timeoutside the schema withERR_NON_CANONICAL_CBOR, asprofile.Decodedoes.- The official fixture
time_only_extensionsis regenerated: its header data is the raw UTF-8 bytes of "public label" and its control data is{0: 7, 1: "sealed"}(a2000701667365616c6564). Every other.dkcand.dkkkeeps its bytes; the fixture and vector metadata name spec 0.8.2.
Added
ErrExtensionDataInvalid(ERR_EXTENSION_DATA_INVALID, §69).extension.DataValidator, an optional interface of aRegistrythat validates the data of the extensions it knows: a known critical extension with invalid data fails withErrExtensionDataInvalid(§63 steps 4 and 14, and the.dkkcheck); a known noncritical one is reported incapsule.Inspection.UnusableExtensions,capsule.Opened.UnusableControlExtensionsorcapsule.Opened.UnusableAccessKeyExtensions(extension.CheckNoncritical,extension.Unusable) and does not fail.- Encoder self-checks:
capsule.Encryptdecodes its PUBLIC_HEADER and CONTROL_CBOR, andaccesskey.MarshalBodyits body, with the readers' decoders before sealing or writing (§72). extension.MaxExtensions,MaxVersion,MaxDataLenandcodec.MaxSafeUint.- The
.dkkfixturetime_and_key_portable_extension, which carries a noncritical extension with data (§68). genfixtures -only NAME[,NAME...]regenerates the named fixtures only.- Tests: the three new §64 mutations (data that is not a byte string,
h''data, 65 extensions), regression tests for the cases of §76, conformance checks on the exact data bytes, and the fuzz targetcapsule.FuzzEncodeImpliesDecode(header, control and.dkk).
Fixed
extension.CheckDisjointis a linear merge of the two sorted arrays; a PUBLIC_HEADER with 40 000 + 40 000 extensions took 8.3 s in the pairwise check (§76, case 6).- Control data made of 14 or 15 nested arrays was sealed by
Encryptand rejected byOpenat step 14, after the unlock (§76, case 5). - Header data
{NaN: 0, NaN: 1}gave a nondeterministic verdict (§76, case 3). extension.New(id, v, nil)wrotenullas data (§76, case 2).codec.Unmarshalwipes its re-encoding, which after the new self-checks held a copy of I_PAYLOAD oraccess_material, andaccesskey.DecodeBodywipes the material on its error paths.
Unreleased — v0.1.0
First implementation of the DateKeys Protocol Specification v0.8.1.
Added
datekey: local date → round resolution at full precision (§15), canonicaldk1_encoding and strict parsing (§18, §19).profile: Provider Profile Deterministic CBOR andprofile_hash(§11), the pinned Quicknet profile with its chain-hash self-check (§12), and pinned registries (§13).provider: release sources and local BLS verification (§51);provider/drand: racing public relays, verifying every answer (§48, §49, §52).codec: Deterministic CBOR with a re-encoding canonicality check (§58, §58.1).extension: the generic extension mechanism (§54).agewrap: strict tlock and X25519 age identities that enforce the stanza rules (§27, §29, §32, §33, §35), and a secret-free header probe.capsule:.dkcframing,Encryptfortime_onlyandtime_and_key(§61, §62),Inspect(§63 steps 1–8) andOpen(§63 steps 9–18).accesskey:.dkkencoding and decoding (§40–§44).cmd/datekeys:encrypt,decrypt,inspect,datekey resolve,profile hash, with atomic, non-overwriting outputs.- Official vectors (§65, §66),
.dkc/.dkkfixtures (§67, §68), the mutation corpus (§64), fuzz targets for every parser, interoperability tests with the officialageandtleCLIs, and live Quicknet integration tests. spec/datekeys.cddlanddocs/traceability.md.