Amendment of the unreleased v0.8.2, recorded in §76 with its case: the
second implementation's phase-2 research found that tlock-js over
@noble/curves 1.9.7 accepts U re-encoded as c0 + p and a signature
x + p and returns the same file key, while the reference rejects both
(noble 1.9.7 differed from kilic on 5,615 of 41,686 encodings), and the
spec did not say which encodings are valid.
- §12.2 defines the canonical encoding of a BLS12-381 point (drand's
compressed ZCash form) and requires decoders to reject every other
byte string; §12.1 applies it to public_key.
- §63 step 10 applies it to the release signature (ERR_RELEASE_INVALID)
and step 11 defines the tlock stanza body U || V || W (96 + 16 + 16
bytes for Quicknet) with a canonical, non-infinity U (ERR_INTEGRITY).
- §64 gains ten mutations, exported to mutations.json (65 cases). The
signature x + p case uses published Quicknet round 1004, the first
after 1000 whose x allows x + p < 2^381. The reference already gave
every stated code and step.
Errors no longer copy text from tlock, kyber, age, drand or
kyber-bls12381. kyber's IBE error carried the candidate plaintext and r,
and with one bit of W flipped the message disclosed the real tlock file
key with that bit flipped. Every such place now uses a fixed reason with
its normative sentinel; TestTlockFailureDiagnosticsCarryNoSecrets fails
with the old wrapping.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
DateKeys_Protocol_Specification_v0.8.2.md: frozen copy of the normative
draft v0.8.2 (26 September 2026) implemented by this module. SHA-256:
e6e59490284e0efe112704931b6d5997fca60e38b866afc17b7bacdcf395df03.
v0.8.2 replaces v0.8.1 with one normative change to extensions, refined
before release (error precedence, trust model, extension order, and rules
the reference had applied without normative text) and amended (the
canonical encoding of BLS12-381 points and the tlock stanza body), all
recorded with their reproducible cases in the specification's §76.
datekeys.cddl: the CBOR schemas of the specification as implemented, with
the encoding rules CDDL cannot express.
The specification is licensed under the Creative Commons Attribution 4.0
International License (CC-BY-4.0): https://creativecommons.org/licenses/by/4.0/.
The code of this repository is licensed separately under Apache-2.0.
Changes to the specification follow its §76: a normative change should answer a
reproducible case found through the reference implementation, the CDDL, a
fixture, a mutation test, an interoperability test, fuzzing, a second
implementation or an external review.