You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
dateKeys-dart/lib/datekeys.dart

109 lines
4.7 KiB

/// The DateKeys protocol in pure Dart: DateKey, DateKeyCap (`.dkc`) and the
/// DateKeys Access Key (`.dkk`), as `datekeys-go` and `datekeys-ts` implement
/// them, checked against the same test data.
///
Stage 5c: the verdicts of alg 2 and seal_type 2, and the opening gives them securitycms.dart ports evaluateCMS, signerLine and evaluateSeal of signature2.go of Go at the draft v0.12, on the reader of CMS of stage 5a, with the same order of checks: SIGNERS with its profile and at most 16 entries, then the SignedData; each required signer in the order of SIGNERS and each foreign one in the order of the encoding, valid, invalid, absent, not verifiable, without seal, with an invalid seal or out of validity at the time of its seal; F2, F5 and F6 with their detail; and the seal over SEAL_SUBJECT, S1 to S5 with the authority and t. A round time at Go's zero time is no round time, as IsZero, and Verdicts.sealedAt skips a seal at that time, as SealedAt. cmsReader is the default CmsEvaluator of evaluateSecurity, and so of evaluateSecurityInput and the opening: nothing that Go evaluates is left not evaluated; a caller that passes cms: null still gets the parts without CMS alone. encodeSigners and maxSigners are exported, as EncodeSigners and MaxSigners of Go. The tests compare every part with Go: the 135 cases of security_cms.json with the result of each signer, the 24 of security.json, the 56 signatures of alg 2 and 105 seals of seal_type 2 of security_vectors.json, the 755 cases of securitycms_vectors.json with their detail and earliest seal, the fixtures format3_signed_cms and format3_sealed, and their openings in open_cases.json. On Node.js, a part of the vectors and the two fixtures opened in full. 1572 tests on the VM and 332 on Node.js. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
/// Stages 0 to 5 of docs/PLAN_dart.md: the package and its test data, the
/// normative errors of spec §69, byte helpers and the CBOR profile of spec
/// §58, the primitives and the reading of age files, then BLS12-381 and
/// tlock: the check of a compressed point and the verification of releases,
/// with the sources that deliver them. Then the key of words of spec §38.1,
/// and the formats: the frames of the .dkc and the .dkk, PUBLIC_HEADER,
/// CONTROL_CBOR of the three formats, the .dkk, the extensions with their
/// registries, the Provider Profile with the pinned Quicknet, the DateKey
/// with its rounds and times, the padding, the head of format 3 and the
/// public note. And the reading of a capsule: its inspection, steps 1 to 8
/// of spec §63, and its opening, steps 9 to 18, in memory or from a source
/// read by ranges, to a sink of bytes or of files.
/// And the security area of format 3: what an author signs and a seal seals,
Stage 5c: the verdicts of alg 2 and seal_type 2, and the opening gives them securitycms.dart ports evaluateCMS, signerLine and evaluateSeal of signature2.go of Go at the draft v0.12, on the reader of CMS of stage 5a, with the same order of checks: SIGNERS with its profile and at most 16 entries, then the SignedData; each required signer in the order of SIGNERS and each foreign one in the order of the encoding, valid, invalid, absent, not verifiable, without seal, with an invalid seal or out of validity at the time of its seal; F2, F5 and F6 with their detail; and the seal over SEAL_SUBJECT, S1 to S5 with the authority and t. A round time at Go's zero time is no round time, as IsZero, and Verdicts.sealedAt skips a seal at that time, as SealedAt. cmsReader is the default CmsEvaluator of evaluateSecurity, and so of evaluateSecurityInput and the opening: nothing that Go evaluates is left not evaluated; a caller that passes cms: null still gets the parts without CMS alone. encodeSigners and maxSigners are exported, as EncodeSigners and MaxSigners of Go. The tests compare every part with Go: the 135 cases of security_cms.json with the result of each signer, the 24 of security.json, the 56 signatures of alg 2 and 105 seals of seal_type 2 of security_vectors.json, the 755 cases of securitycms_vectors.json with their detail and earliest seal, the fixtures format3_signed_cms and format3_sealed, and their openings in open_cases.json. On Node.js, a part of the vectors and the two fixtures opened in full. 1572 tests on the VM and 332 on Node.js. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
/// SECURITY_CBOR, the signature of alg 1, the signature of alg 2 with
/// certificates and the seal of seal_type 2 with the reader of CMS, and the
/// verdicts with their texts and lines, which the opening evaluates as Go.
/// And part 6a of stage 6: the writing of age files, with the injectable
/// source of the random values of the writers and the X25519, scrypt and
/// tlock recipients, for the writer of a capsule and the files of author
/// keys.
///
/// And part 7a of stage 7: the extension datekeys.capsule of a .dkk, its
/// data, which [StandardExtensions] checks by default as locator.Standard of
/// Go, and what it points to, the locator sealed for the date and the
/// envelope of the .dkc: reading and opening a locator, the rules of its
/// addresses and of the IP that a name resolves to, and the rest of the
/// envelope. And part 7b: sealing a locator and making an envelope, and the
/// author keys of alg 1, dkauthor1… and DKAUTHOR-SECRET-KEY-1…, with their
/// Ed25519 signature and their key file encrypted with scrypt.
///
/// And part 6b of stage 6: the writer of capsules of format 3,
/// [encryptFiles], with its options, its sources read in streaming, its
/// result and the hooks of the signature and the seal, [AuthorSigner],
/// [CmsSigner] and [Sealer]; and what its options take: the X25519
/// recipients and the source of the random values.
///
/// DER, the primitives, the reading and the writing of age, the recipients
/// and the random sources, agewrap, the curve arithmetic, the IBE of tlock
/// and its stanza, the rules of paths and texts on the Unicode tables, the
/// frame of BODY, the digest of a capsule, the steps of the opening, the
/// reader of CMS with its ECDSA and RSA, the parser of IP addresses, the
/// Ed25519 signing and the Unicode sets of Go are internal, as in the Go
/// reference and datekeys-ts.
library;
export 'src/accesskey.dart';
export 'src/author.dart';
export 'src/authorkey.dart' hide parseAuthorPublicUtf8, parseAuthorSecretUtf8;
export 'src/bls12381_curve.dart'
show BlsGroup, PointVerdict, checkCompressedPoint;
export 'src/bytes.dart'
show compareBytes, concatBytes, decodeUtf8, equalBytes, fromHex, toHex;
Stage 1: the CBOR profile of section 58, as package codec of Go lib/src/cbor.dart is the port of codec/codec.go: CborEncoder, CborDecoder, unmarshalCbor, peekSchema, checkSchema and walkCbor, with the same reads, the same checks in the same order and the same error texts, such as "codec: offset 0: 23 is not in its shortest form (initial byte 0x18): ERR_NON_CANONICAL_CBOR". Integers are exact on the VM and on the web, where an int is a double and the bit operators work on 32 bits. An argument of eight bytes is read as two halves of 32 bits, and is an int up to 2^53-1 and a BigInt above, map keys and the numbers of the error texts included. uint returns an int, since every schema bounds its integers at 2^53-1, and uint64 a BigInt. The map that peekSchema reads is bounded at 2^63-1, Go's math.MaxInt, on the web too. Two kinds of text are of Dart only. CborEncoder.uint refuses an int outside 0..2^53-1 and uint64 a BigInt outside 0..2^64-1, with the text of datekeys-ts, where Go's uint64 cannot hold such a value. And the only invalid text that a Dart String holds is a lone surrogate: the error quotes it as Go quotes its bytes in generalized UTF-8. The tests port codec_test.go, internal_test.go and vectors_test.go, with the texts that Go prints, and cbor.test.ts. The fuzz targets are properties over seeded inputs, checked against a reference encoder and decoder written apart, as internal/cbortest. cbor.json runs its 36 accept and 67 reject vectors with the walk limits and the values; its 172 schema vectors are read and wait for the schema decoders of stage 4. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
export 'src/cbor.dart';
export 'src/control.dart';
export 'src/datekey.dart';
export 'src/encrypt3.dart';
export 'src/errors.dart';
export 'src/extension.dart';
export 'src/framing.dart';
export 'src/head.dart' hide decodeWrittenHead;
export 'src/header.dart';
export 'src/inspect.dart'
show
CheckResult,
Inspection,
StanzaInfo,
inspectCapsule,
inspectCapsuleSource,
inspectJson,
inspectView,
inspectedLength,
maxAccessKeyRead;
export 'src/locator.dart';
export 'src/locator_seal.dart';
export 'src/note.dart';
Stage 4c: steps 9 to 18, the opening of the three formats lib/src/open.dart and open3.dart port Open and openBody of package capsule of datekeys-go at c531e93, with the checks, codes, steps and texts of the reference and the detail of each check: the .dkk of step 9.a, decoded or still encoded, with its material, its critical extensions, its capsule_id and its capsule_digest; at least one credential; the clock and the release, with the rule of step 9 for the failures of its source (sourceFailure); its verification at step 10; OUTER_TIME_AGE with the tlock stanza; INNER_ACCESS_AGE with the X25519 identities, those of the .dkk and the key of words, and the rules of the slots; CONTROL_CBOR, header_binding, I_PAYLOAD and P; PAYLOAD_AGE streamed, with the padding of format 2 checked and never delivered, and in format 3 the frame of BODY, the area, the head, each file to the sink with its SHA-256 and the padding, with the precedence of spec §63; and the commit. A failure of age keeps the code of the identity that reports it, or is ERR_INTEGRITY with the reason of its phase, as classify of Go. openCapsule opens a capsule in memory and openCapsuleSource one that a ByteSource reads: the prefix of the inspection and the nonce of PAYLOAD_AGE before the release, then pieces of 1 MiB. lib/src/sink.dart has ByteSink, for the content of formats 1 and 2 and for each file, and FileSink, for the files of format 3, as the dst and the Sink of Go, with MemoryByteSink and MemoryFileSink. Nothing is presented as valid before step 17 ends: the output is closed only then and aborted after any failure, and the sink aborted after any failure that follows its begin (spec §56). The signature and the seal are stage 5: lib/src/verdicts.dart has the verdicts and the SecurityEvaluator, given what newSecurityContext and EvaluateSecurityIn of Go take, which never fails the opening; the default evaluates nothing. OpenOptions.accept is Accept of Go. And AgePayloadDecryptor.wipe clears the key of a STREAM left unread. The tests run open_cases.json and the mutation corpus with the texts and the checks of Go, in memory and from a source read in pieces; capsules of several MiB made from the fixtures, for the streaming; a capsule with a stanza for a key of words; and the caller, the sinks and the evaluator. open_test.dart runs on Node.js too, with open_vectors.g.dart. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
export 'src/open.dart' show OpenOptions, Opened, openCapsule, openCapsuleSource;
export 'src/padding.dart';
export 'src/profile.dart';
export 'src/random.dart' show RandomSource, secureRandom;
export 'src/recipient.dart' show X25519Recipient, checkX25519Recipient;
export 'src/release.dart'
show
PinnedProfile,
Release,
ReleaseSource,
fetchRelease,
quicknetScheme,
suppliedRelease,
verifyRelease;
export 'src/security.dart';
Stage 5c: the verdicts of alg 2 and seal_type 2, and the opening gives them securitycms.dart ports evaluateCMS, signerLine and evaluateSeal of signature2.go of Go at the draft v0.12, on the reader of CMS of stage 5a, with the same order of checks: SIGNERS with its profile and at most 16 entries, then the SignedData; each required signer in the order of SIGNERS and each foreign one in the order of the encoding, valid, invalid, absent, not verifiable, without seal, with an invalid seal or out of validity at the time of its seal; F2, F5 and F6 with their detail; and the seal over SEAL_SUBJECT, S1 to S5 with the authority and t. A round time at Go's zero time is no round time, as IsZero, and Verdicts.sealedAt skips a seal at that time, as SealedAt. cmsReader is the default CmsEvaluator of evaluateSecurity, and so of evaluateSecurityInput and the opening: nothing that Go evaluates is left not evaluated; a caller that passes cms: null still gets the parts without CMS alone. encodeSigners and maxSigners are exported, as EncodeSigners and MaxSigners of Go. The tests compare every part with Go: the 135 cases of security_cms.json with the result of each signer, the 24 of security.json, the 56 signatures of alg 2 and 105 seals of seal_type 2 of security_vectors.json, the 755 cases of securitycms_vectors.json with their detail and earliest seal, the fixtures format3_signed_cms and format3_sealed, and their openings in open_cases.json. On Node.js, a part of the vectors and the two fixtures opened in full. 1572 tests on the VM and 332 on Node.js. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
export 'src/securitycms.dart';
Stage 4c: steps 9 to 18, the opening of the three formats lib/src/open.dart and open3.dart port Open and openBody of package capsule of datekeys-go at c531e93, with the checks, codes, steps and texts of the reference and the detail of each check: the .dkk of step 9.a, decoded or still encoded, with its material, its critical extensions, its capsule_id and its capsule_digest; at least one credential; the clock and the release, with the rule of step 9 for the failures of its source (sourceFailure); its verification at step 10; OUTER_TIME_AGE with the tlock stanza; INNER_ACCESS_AGE with the X25519 identities, those of the .dkk and the key of words, and the rules of the slots; CONTROL_CBOR, header_binding, I_PAYLOAD and P; PAYLOAD_AGE streamed, with the padding of format 2 checked and never delivered, and in format 3 the frame of BODY, the area, the head, each file to the sink with its SHA-256 and the padding, with the precedence of spec §63; and the commit. A failure of age keeps the code of the identity that reports it, or is ERR_INTEGRITY with the reason of its phase, as classify of Go. openCapsule opens a capsule in memory and openCapsuleSource one that a ByteSource reads: the prefix of the inspection and the nonce of PAYLOAD_AGE before the release, then pieces of 1 MiB. lib/src/sink.dart has ByteSink, for the content of formats 1 and 2 and for each file, and FileSink, for the files of format 3, as the dst and the Sink of Go, with MemoryByteSink and MemoryFileSink. Nothing is presented as valid before step 17 ends: the output is closed only then and aborted after any failure, and the sink aborted after any failure that follows its begin (spec §56). The signature and the seal are stage 5: lib/src/verdicts.dart has the verdicts and the SecurityEvaluator, given what newSecurityContext and EvaluateSecurityIn of Go take, which never fails the opening; the default evaluates nothing. OpenOptions.accept is Accept of Go. And AgePayloadDecryptor.wipe clears the key of a STREAM left unread. The tests run open_cases.json and the mutation corpus with the texts and the checks of Go, in memory and from a source read in pieces; capsules of several MiB made from the fixtures, for the streaming; a capsule with a stanza for a key of words; and the caller, the sinks and the evaluator. open_test.dart runs on Node.js too, with open_vectors.g.dart. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
export 'src/sink.dart';
export 'src/source.dart' show ByteSource, BytesSource;
Stage 4c: steps 9 to 18, the opening of the three formats lib/src/open.dart and open3.dart port Open and openBody of package capsule of datekeys-go at c531e93, with the checks, codes, steps and texts of the reference and the detail of each check: the .dkk of step 9.a, decoded or still encoded, with its material, its critical extensions, its capsule_id and its capsule_digest; at least one credential; the clock and the release, with the rule of step 9 for the failures of its source (sourceFailure); its verification at step 10; OUTER_TIME_AGE with the tlock stanza; INNER_ACCESS_AGE with the X25519 identities, those of the .dkk and the key of words, and the rules of the slots; CONTROL_CBOR, header_binding, I_PAYLOAD and P; PAYLOAD_AGE streamed, with the padding of format 2 checked and never delivered, and in format 3 the frame of BODY, the area, the head, each file to the sink with its SHA-256 and the padding, with the precedence of spec §63; and the commit. A failure of age keeps the code of the identity that reports it, or is ERR_INTEGRITY with the reason of its phase, as classify of Go. openCapsule opens a capsule in memory and openCapsuleSource one that a ByteSource reads: the prefix of the inspection and the nonce of PAYLOAD_AGE before the release, then pieces of 1 MiB. lib/src/sink.dart has ByteSink, for the content of formats 1 and 2 and for each file, and FileSink, for the files of format 3, as the dst and the Sink of Go, with MemoryByteSink and MemoryFileSink. Nothing is presented as valid before step 17 ends: the output is closed only then and aborted after any failure, and the sink aborted after any failure that follows its begin (spec §56). The signature and the seal are stage 5: lib/src/verdicts.dart has the verdicts and the SecurityEvaluator, given what newSecurityContext and EvaluateSecurityIn of Go take, which never fails the opening; the default evaluates nothing. OpenOptions.accept is Accept of Go. And AgePayloadDecryptor.wipe clears the key of a STREAM left unread. The tests run open_cases.json and the mutation corpus with the texts and the checks of Go, in memory and from a source read in pieces; capsules of several MiB made from the fixtures, for the streaming; a capsule with a stanza for a key of words; and the caller, the sinks and the evaluator. open_test.dart runs on Node.js too, with open_vectors.g.dart. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
export 'src/verdicts.dart';
export 'src/version.dart';
export 'src/wordkey.dart'
show
WordKeyException,
checkWords,
minLetters,
minWords,
normalizeWords,
wordKey,
wordKeyRounds;

Powered by TurnKey Linux.