Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
// The locator against files, on the VM: every case of
|
Stage 7a: the data of datekeys.capsule
lib/src/locator.dart gains the data of the extension, as Info, ParseInfo
and Info.Extension of Go, with the same checks in the same order and the
same texts:
- parseCapsuleInfo: the map of spec 44.1 with the note under the rules of
spec 24.1, the canonical DateKey, and a sealed locator that is an age
file with one tlock stanza for its round; every failure is
ERR_EXTENSION_DATA_INVALID and nothing else, so that it makes the
extension unusable and never the .dkk (spec 54).
- CapsuleInfo.toExtension, which reads back what it writes (spec 72), and
CapsuleInfo.openLocator, OpenLocator of Go, with the default registry of
pinned profiles when none is given, as the opening of a capsule takes it.
- checkCapsuleData, the ValidateCapsule of Go's locator.Standard, for
StandardExtensions.
The tests run the extension cases of locator.json with their code, the
writing and the reading of the data, OpenLocator, the registry of
locator.Standard through checkCritical, checkNoncritical and checkWrite,
and the opening of a fixture whose .dkk carries datekeys.capsule, whose
unusable extensions and checks are those of Go.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
// testdata/vectors/locator.json with the result, the code and the text of
|
|
|
|
|
// Go; every case of test/vectors/locator_vectors.json, of which
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
// locator_test.dart runs a part also compiled to JavaScript; the sealed
|
|
|
|
|
// locators whose plaintext passes 1 MiB, which Go reads through
|
Stage 7a: the data of datekeys.capsule
lib/src/locator.dart gains the data of the extension, as Info, ParseInfo
and Info.Extension of Go, with the same checks in the same order and the
same texts:
- parseCapsuleInfo: the map of spec 44.1 with the note under the rules of
spec 24.1, the canonical DateKey, and a sealed locator that is an age
file with one tlock stanza for its round; every failure is
ERR_EXTENSION_DATA_INVALID and nothing else, so that it makes the
extension unusable and never the .dkk (spec 54).
- CapsuleInfo.toExtension, which reads back what it writes (spec 72), and
CapsuleInfo.openLocator, OpenLocator of Go, with the default registry of
pinned profiles when none is given, as the opening of a capsule takes it.
- checkCapsuleData, the ValidateCapsule of Go's locator.Standard, for
StandardExtensions.
The tests run the extension cases of locator.json with their code, the
writing and the reading of the data, OpenLocator, the registry of
locator.Standard through checkCritical, checkNoncritical and checkWrite,
and the opening of a fixture whose .dkk carries datekeys.capsule, whose
unusable extensions and checks are those of Go.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
// io.LimitReader; and the opening of a fixture whose .dkk carries
|
|
|
|
|
// datekeys.capsule, with the registry of locator.Standard. The constants of
|
|
|
|
|
// locator_uris.g.dart and locator_vectors.g.dart are checked against their
|
|
|
|
|
// files.
|
Stage 7a: the addresses of a locator and the IP addresses of netip
lib/src/locator.dart starts with the addresses of spec 44.1, a port of
CheckURI and Address.Host of package locator of datekeys-go: the same
checks in the same order and the same texts, on the UTF-8 of the address,
with Go's %q of the first byte that RFC 3986 does not allow. And
checkResolvedIp, the check of the IP that a name resolves to, which a
reader runs on every connection: the classification of publicIP on the 4
or 16 bytes of an address, an IPv4-mapped one not public. Go has no such
function, since its reader does not download.
lib/src/ipaddr.dart, internal, parses IPv4 and IPv6 with the exact
acceptance of netip.ParseAddr, writes them as its String, and classifies
them as publicIP, with the blocks of spec 44.1. It works byte by byte, so
that the 128 bits of IPv6 stay exact on the web, and never uses dart:io.
The tests run the 247 addresses of locator.json and the 2 800 of the
vectors, the 1 700 strings of netip and the 868 byte strings of publicIP,
on the VM and on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
@TestOn('vm')
|
|
|
|
|
library;
|
|
|
|
|
|
|
|
|
|
import 'dart:io';
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
import 'dart:typed_data';
|
Stage 7a: the addresses of a locator and the IP addresses of netip
lib/src/locator.dart starts with the addresses of spec 44.1, a port of
CheckURI and Address.Host of package locator of datekeys-go: the same
checks in the same order and the same texts, on the UTF-8 of the address,
with Go's %q of the first byte that RFC 3986 does not allow. And
checkResolvedIp, the check of the IP that a name resolves to, which a
reader runs on every connection: the classification of publicIP on the 4
or 16 bytes of an address, an IPv4-mapped one not public. Go has no such
function, since its reader does not download.
lib/src/ipaddr.dart, internal, parses IPv4 and IPv6 with the exact
acceptance of netip.ParseAddr, writes them as its String, and classifies
them as publicIP, with the blocks of spec 44.1. It works byte by byte, so
that the 128 bits of IPv6 stay exact on the web, and never uses dart:io.
The tests run the 247 addresses of locator.json and the 2 800 of the
vectors, the 1 700 strings of netip and the 868 byte strings of publicIP,
on the VM and on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
|
Stage 7a: the data of datekeys.capsule
lib/src/locator.dart gains the data of the extension, as Info, ParseInfo
and Info.Extension of Go, with the same checks in the same order and the
same texts:
- parseCapsuleInfo: the map of spec 44.1 with the note under the rules of
spec 24.1, the canonical DateKey, and a sealed locator that is an age
file with one tlock stanza for its round; every failure is
ERR_EXTENSION_DATA_INVALID and nothing else, so that it makes the
extension unusable and never the .dkk (spec 54).
- CapsuleInfo.toExtension, which reads back what it writes (spec 72), and
CapsuleInfo.openLocator, OpenLocator of Go, with the default registry of
pinned profiles when none is given, as the opening of a capsule takes it.
- checkCapsuleData, the ValidateCapsule of Go's locator.Standard, for
StandardExtensions.
The tests run the extension cases of locator.json with their code, the
writing and the reading of the data, OpenLocator, the registry of
locator.Standard through checkCritical, checkNoncritical and checkWrite,
and the opening of a fixture whose .dkk carries datekeys.capsule, whose
unusable extensions and checks are those of Go.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
import 'package:datekeys/src/accesskey.dart';
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
import 'package:datekeys/src/bytes.dart';
|
|
|
|
|
import 'package:datekeys/src/chacha20poly1305.dart';
|
Stage 7a: the data of datekeys.capsule
lib/src/locator.dart gains the data of the extension, as Info, ParseInfo
and Info.Extension of Go, with the same checks in the same order and the
same texts:
- parseCapsuleInfo: the map of spec 44.1 with the note under the rules of
spec 24.1, the canonical DateKey, and a sealed locator that is an age
file with one tlock stanza for its round; every failure is
ERR_EXTENSION_DATA_INVALID and nothing else, so that it makes the
extension unusable and never the .dkk (spec 54).
- CapsuleInfo.toExtension, which reads back what it writes (spec 72), and
CapsuleInfo.openLocator, OpenLocator of Go, with the default registry of
pinned profiles when none is given, as the opening of a capsule takes it.
- checkCapsuleData, the ValidateCapsule of Go's locator.Standard, for
StandardExtensions.
The tests run the extension cases of locator.json with their code, the
writing and the reading of the data, OpenLocator, the registry of
locator.Standard through checkCritical, checkNoncritical and checkWrite,
and the opening of a fixture whose .dkk carries datekeys.capsule, whose
unusable extensions and checks are those of Go.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
import 'package:datekeys/src/datekey.dart';
|
|
|
|
|
import 'package:datekeys/src/errors.dart';
|
|
|
|
|
import 'package:datekeys/src/extension.dart';
|
Stage 7a: the addresses of a locator and the IP addresses of netip
lib/src/locator.dart starts with the addresses of spec 44.1, a port of
CheckURI and Address.Host of package locator of datekeys-go: the same
checks in the same order and the same texts, on the UTF-8 of the address,
with Go's %q of the first byte that RFC 3986 does not allow. And
checkResolvedIp, the check of the IP that a name resolves to, which a
reader runs on every connection: the classification of publicIP on the 4
or 16 bytes of an address, an IPv4-mapped one not public. Go has no such
function, since its reader does not download.
lib/src/ipaddr.dart, internal, parses IPv4 and IPv6 with the exact
acceptance of netip.ParseAddr, writes them as its String, and classifies
them as publicIP, with the blocks of spec 44.1. It works byte by byte, so
that the 128 bits of IPv6 stay exact on the web, and never uses dart:io.
The tests run the 247 addresses of locator.json and the 2 800 of the
vectors, the 1 700 strings of netip and the 868 byte strings of publicIP,
on the VM and on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
import 'package:datekeys/src/locator.dart';
|
Stage 7a: the data of datekeys.capsule
lib/src/locator.dart gains the data of the extension, as Info, ParseInfo
and Info.Extension of Go, with the same checks in the same order and the
same texts:
- parseCapsuleInfo: the map of spec 44.1 with the note under the rules of
spec 24.1, the canonical DateKey, and a sealed locator that is an age
file with one tlock stanza for its round; every failure is
ERR_EXTENSION_DATA_INVALID and nothing else, so that it makes the
extension unusable and never the .dkk (spec 54).
- CapsuleInfo.toExtension, which reads back what it writes (spec 72), and
CapsuleInfo.openLocator, OpenLocator of Go, with the default registry of
pinned profiles when none is given, as the opening of a capsule takes it.
- checkCapsuleData, the ValidateCapsule of Go's locator.Standard, for
StandardExtensions.
The tests run the extension cases of locator.json with their code, the
writing and the reading of the data, OpenLocator, the registry of
locator.Standard through checkCritical, checkNoncritical and checkWrite,
and the opening of a fixture whose .dkk carries datekeys.capsule, whose
unusable extensions and checks are those of Go.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
import 'package:datekeys/src/open.dart' show OpenOptions, openCapsule;
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
import 'package:datekeys/src/profile.dart';
|
Stage 7a: the data of datekeys.capsule
lib/src/locator.dart gains the data of the extension, as Info, ParseInfo
and Info.Extension of Go, with the same checks in the same order and the
same texts:
- parseCapsuleInfo: the map of spec 44.1 with the note under the rules of
spec 24.1, the canonical DateKey, and a sealed locator that is an age
file with one tlock stanza for its round; every failure is
ERR_EXTENSION_DATA_INVALID and nothing else, so that it makes the
extension unusable and never the .dkk (spec 54).
- CapsuleInfo.toExtension, which reads back what it writes (spec 72), and
CapsuleInfo.openLocator, OpenLocator of Go, with the default registry of
pinned profiles when none is given, as the opening of a capsule takes it.
- checkCapsuleData, the ValidateCapsule of Go's locator.Standard, for
StandardExtensions.
The tests run the extension cases of locator.json with their code, the
writing and the reading of the data, OpenLocator, the registry of
locator.Standard through checkCritical, checkNoncritical and checkWrite,
and the opening of a fixture whose .dkk carries datekeys.capsule, whose
unusable extensions and checks are those of Go.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
import 'package:datekeys/src/release.dart' show suppliedRelease;
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
import 'package:datekeys/src/sha256.dart';
|
Stage 7a: the data of datekeys.capsule
lib/src/locator.dart gains the data of the extension, as Info, ParseInfo
and Info.Extension of Go, with the same checks in the same order and the
same texts:
- parseCapsuleInfo: the map of spec 44.1 with the note under the rules of
spec 24.1, the canonical DateKey, and a sealed locator that is an age
file with one tlock stanza for its round; every failure is
ERR_EXTENSION_DATA_INVALID and nothing else, so that it makes the
extension unusable and never the .dkk (spec 54).
- CapsuleInfo.toExtension, which reads back what it writes (spec 72), and
CapsuleInfo.openLocator, OpenLocator of Go, with the default registry of
pinned profiles when none is given, as the opening of a capsule takes it.
- checkCapsuleData, the ValidateCapsule of Go's locator.Standard, for
StandardExtensions.
The tests run the extension cases of locator.json with their code, the
writing and the reading of the data, OpenLocator, the registry of
locator.Standard through checkCritical, checkNoncritical and checkWrite,
and the opening of a fixture whose .dkk carries datekeys.capsule, whose
unusable extensions and checks are those of Go.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
import 'package:datekeys/src/sink.dart';
|
Stage 7a: the addresses of a locator and the IP addresses of netip
lib/src/locator.dart starts with the addresses of spec 44.1, a port of
CheckURI and Address.Host of package locator of datekeys-go: the same
checks in the same order and the same texts, on the UTF-8 of the address,
with Go's %q of the first byte that RFC 3986 does not allow. And
checkResolvedIp, the check of the IP that a name resolves to, which a
reader runs on every connection: the classification of publicIP on the 4
or 16 bytes of an address, an IPv4-mapped one not public. Go has no such
function, since its reader does not download.
lib/src/ipaddr.dart, internal, parses IPv4 and IPv6 with the exact
acceptance of netip.ParseAddr, writes them as its String, and classifies
them as publicIP, with the blocks of spec 44.1. It works byte by byte, so
that the 128 bits of IPv6 stay exact on the web, and never uses dart:io.
The tests run the 247 addresses of locator.json and the 2 800 of the
vectors, the 1 700 strings of netip and the 868 byte strings of publicIP,
on the VM and on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
import 'package:test/test.dart';
|
|
|
|
|
|
|
|
|
|
import 'locator_support.dart';
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
import 'locator_test.dart' show locatorCases;
|
Stage 7a: the addresses of a locator and the IP addresses of netip
lib/src/locator.dart starts with the addresses of spec 44.1, a port of
CheckURI and Address.Host of package locator of datekeys-go: the same
checks in the same order and the same texts, on the UTF-8 of the address,
with Go's %q of the first byte that RFC 3986 does not allow. And
checkResolvedIp, the check of the IP that a name resolves to, which a
reader runs on every connection: the classification of publicIP on the 4
or 16 bytes of an address, an IPv4-mapped one not public. Go has no such
function, since its reader does not download.
lib/src/ipaddr.dart, internal, parses IPv4 and IPv6 with the exact
acceptance of netip.ParseAddr, writes them as its String, and classifies
them as publicIP, with the blocks of spec 44.1. It works byte by byte, so
that the 128 bits of IPv6 stay exact on the web, and never uses dart:io.
The tests run the 247 addresses of locator.json and the 2 800 of the
vectors, the 1 700 strings of netip and the 868 byte strings of publicIP,
on the VM and on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
import 'vectors/locator_uris.g.dart';
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
import 'vectors/locator_vectors.g.dart';
|
Stage 7a: the addresses of a locator and the IP addresses of netip
lib/src/locator.dart starts with the addresses of spec 44.1, a port of
CheckURI and Address.Host of package locator of datekeys-go: the same
checks in the same order and the same texts, on the UTF-8 of the address,
with Go's %q of the first byte that RFC 3986 does not allow. And
checkResolvedIp, the check of the IP that a name resolves to, which a
reader runs on every connection: the classification of publicIP on the 4
or 16 bytes of an address, an IPv4-mapped one not public. Go has no such
function, since its reader does not download.
lib/src/ipaddr.dart, internal, parses IPv4 and IPv6 with the exact
acceptance of netip.ParseAddr, writes them as its String, and classifies
them as publicIP, with the blocks of spec 44.1. It works byte by byte, so
that the 128 bits of IPv6 stay exact on the web, and never uses dart:io.
The tests run the 247 addresses of locator.json and the 2 800 of the
vectors, the 1 700 strings of netip and the 868 byte strings of publicIP,
on the VM and on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
|
|
|
|
|
Json readJson(String path) => decodeJson(File(path).readAsStringSync());
|
|
|
|
|
|
|
|
|
|
void main() {
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
final v = readJson('test/vectors/locator_vectors.json');
|
Stage 7a: the addresses of a locator and the IP addresses of netip
lib/src/locator.dart starts with the addresses of spec 44.1, a port of
CheckURI and Address.Host of package locator of datekeys-go: the same
checks in the same order and the same texts, on the UTF-8 of the address,
with Go's %q of the first byte that RFC 3986 does not allow. And
checkResolvedIp, the check of the IP that a name resolves to, which a
reader runs on every connection: the classification of publicIP on the 4
or 16 bytes of an address, an IPv4-mapped one not public. Go has no such
function, since its reader does not download.
lib/src/ipaddr.dart, internal, parses IPv4 and IPv6 with the exact
acceptance of netip.ParseAddr, writes them as its String, and classifies
them as publicIP, with the blocks of spec 44.1. It works byte by byte, so
that the 128 bits of IPv6 stay exact on the web, and never uses dart:io.
The tests run the 247 addresses of locator.json and the 2 800 of the
vectors, the 1 700 strings of netip and the 868 byte strings of publicIP,
on the VM and on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
final uris = readJson('test/vectors/locator_uris.json');
|
|
|
|
|
final td = readJson('testdata/vectors/locator.json');
|
|
|
|
|
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
group('the constants', () {
|
|
|
|
|
test('locator_uris.g.dart holds locator_uris.json', () {
|
|
|
|
|
expect(
|
|
|
|
|
locatorUrisJson,
|
|
|
|
|
File('test/vectors/locator_uris.json').readAsStringSync(),
|
|
|
|
|
);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('locator_vectors.g.dart holds a part of locator_vectors.json', () {
|
|
|
|
|
final part = decodeJson(locatorVectorsJson);
|
|
|
|
|
List<Object?> every(Object? xs, int n) => [
|
|
|
|
|
for (final (i, x) in (xs! as List<Object?>).indexed)
|
|
|
|
|
if (i % n == 0) x,
|
|
|
|
|
];
|
|
|
|
|
for (final MapEntry(:key, :value) in part.entries) {
|
|
|
|
|
if (key == 'description') continue;
|
|
|
|
|
final want = switch (key) {
|
|
|
|
|
'plaintexts' => every(v[key], 3),
|
|
|
|
|
'open' => (v[key]! as List<Object?>).sublist(0, 24),
|
|
|
|
|
'parse' => every(v[key], 2),
|
|
|
|
|
_ => v[key],
|
|
|
|
|
};
|
|
|
|
|
expect(value, want, reason: key);
|
|
|
|
|
}
|
|
|
|
|
expect(
|
|
|
|
|
part.keys.toSet(),
|
|
|
|
|
v.keys.toSet().difference({'limit', 'capsule'}),
|
|
|
|
|
);
|
|
|
|
|
});
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
group('locator_vectors.json', () => locatorCases(v));
|
|
|
|
|
|
|
|
|
|
group('testdata/vectors/locator.json', () {
|
|
|
|
|
final p = quicknet();
|
|
|
|
|
final round = td['round']! as int;
|
|
|
|
|
final release = releaseOf(v, round);
|
|
|
|
|
final tdTexts = v['testdata']! as Json;
|
|
|
|
|
|
Stage 7a: the data of datekeys.capsule
lib/src/locator.dart gains the data of the extension, as Info, ParseInfo
and Info.Extension of Go, with the same checks in the same order and the
same texts:
- parseCapsuleInfo: the map of spec 44.1 with the note under the rules of
spec 24.1, the canonical DateKey, and a sealed locator that is an age
file with one tlock stanza for its round; every failure is
ERR_EXTENSION_DATA_INVALID and nothing else, so that it makes the
extension unusable and never the .dkk (spec 54).
- CapsuleInfo.toExtension, which reads back what it writes (spec 72), and
CapsuleInfo.openLocator, OpenLocator of Go, with the default registry of
pinned profiles when none is given, as the opening of a capsule takes it.
- checkCapsuleData, the ValidateCapsule of Go's locator.Standard, for
StandardExtensions.
The tests run the extension cases of locator.json with their code, the
writing and the reading of the data, OpenLocator, the registry of
locator.Standard through checkCritical, checkNoncritical and checkWrite,
and the opening of a fixture whose .dkk carries datekeys.capsule, whose
unusable extensions and checks are those of Go.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
test('the extension reads, its locator opens with the release of its '
|
|
|
|
|
'round, and the rest in the host opens the envelope', () {
|
|
|
|
|
final info = parseCapsuleInfo(
|
|
|
|
|
Extension(
|
|
|
|
|
capsuleExtensionId,
|
|
|
|
|
1,
|
|
|
|
|
fromHex(td['extension_data']! as String),
|
|
|
|
|
),
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
);
|
Stage 7a: the data of datekeys.capsule
lib/src/locator.dart gains the data of the extension, as Info, ParseInfo
and Info.Extension of Go, with the same checks in the same order and the
same texts:
- parseCapsuleInfo: the map of spec 44.1 with the note under the rules of
spec 24.1, the canonical DateKey, and a sealed locator that is an age
file with one tlock stanza for its round; every failure is
ERR_EXTENSION_DATA_INVALID and nothing else, so that it makes the
extension unusable and never the .dkk (spec 54).
- CapsuleInfo.toExtension, which reads back what it writes (spec 72), and
CapsuleInfo.openLocator, OpenLocator of Go, with the default registry of
pinned profiles when none is given, as the opening of a capsule takes it.
- checkCapsuleData, the ValidateCapsule of Go's locator.Standard, for
StandardExtensions.
The tests run the extension cases of locator.json with their code, the
writing and the reading of the data, OpenLocator, the registry of
locator.Standard through checkCritical, checkNoncritical and checkWrite,
and the opening of a fixture whose .dkk carries datekeys.capsule, whose
unusable extensions and checks are those of Go.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
expect(info.note, td['note']);
|
|
|
|
|
expect(compactDateKey(info.dateKey), td['datekey']);
|
|
|
|
|
expect(info.dateKey.round, round);
|
|
|
|
|
expect(toHex(info.sealed!), td['locator_sealed']);
|
|
|
|
|
final loc = info.openLocator(release);
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
expect(summaryOf(loc), expandSummary(tdTexts['main']));
|
|
|
|
|
expect(toHex(loc.marshal()), td['locator_plaintext']);
|
|
|
|
|
expect(loc.marshal(), hasLength(locatorBlock));
|
|
|
|
|
expect(toHex(loc.envelopeKey), td['envelope_key']);
|
|
|
|
|
expect(toHex(loc.restDigest), td['rest_digest']);
|
|
|
|
|
expect(loc.restSize, td['rest_size']);
|
|
|
|
|
expect(toHex(loc.capsuleDigest), td['capsule_digest']);
|
|
|
|
|
expect(toHex(loc.envelopeHeader), td['envelope_header']);
|
|
|
|
|
final addresses = (td['addresses']! as List<Object?>).cast<Json>();
|
|
|
|
|
expect(loc.addresses, hasLength(addresses.length));
|
|
|
|
|
for (final (i, a) in addresses.indexed) {
|
|
|
|
|
expect(
|
|
|
|
|
[
|
|
|
|
|
loc.addresses[i].uri,
|
|
|
|
|
loc.addresses[i].offset,
|
|
|
|
|
loc.addresses[i].host,
|
|
|
|
|
],
|
|
|
|
|
[a['uri'], a['offset'], a['host']],
|
|
|
|
|
);
|
|
|
|
|
}
|
|
|
|
|
final rest = loc.restIn(
|
|
|
|
|
fromHex(td['host']! as String),
|
|
|
|
|
td['host_offset']! as int,
|
|
|
|
|
);
|
|
|
|
|
expect(toHex(rest), td['rest']);
|
|
|
|
|
expect(toHex(loc.openEnvelope(rest)), td['dkc']);
|
Stage 7a: the data of datekeys.capsule
lib/src/locator.dart gains the data of the extension, as Info, ParseInfo
and Info.Extension of Go, with the same checks in the same order and the
same texts:
- parseCapsuleInfo: the map of spec 44.1 with the note under the rules of
spec 24.1, the canonical DateKey, and a sealed locator that is an age
file with one tlock stanza for its round; every failure is
ERR_EXTENSION_DATA_INVALID and nothing else, so that it makes the
extension unusable and never the .dkk (spec 54).
- CapsuleInfo.toExtension, which reads back what it writes (spec 72), and
CapsuleInfo.openLocator, OpenLocator of Go, with the default registry of
pinned profiles when none is given, as the opening of a capsule takes it.
- checkCapsuleData, the ValidateCapsule of Go's locator.Standard, for
StandardExtensions.
The tests run the extension cases of locator.json with their code, the
writing and the reading of the data, OpenLocator, the registry of
locator.Standard through checkCritical, checkNoncritical and checkWrite,
and the opening of a fixture whose .dkk carries datekeys.capsule, whose
unusable extensions and checks are those of Go.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
// The same with the top-level opening of Go's Open.
|
|
|
|
|
final again = openLocator(p, round, release, info.sealed!);
|
|
|
|
|
expect(summaryOf(again), summaryOf(loc));
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('the padding of each base', () {
|
|
|
|
|
for (final c in (td['padding_cases']! as List<Object?>).cast<Json>()) {
|
|
|
|
|
expect(locatorPlaintextLength(c['base']! as int), c['total']);
|
|
|
|
|
expect((c['total']! as int) % locatorBlock, 0);
|
|
|
|
|
}
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('every address, with the text of Go', () {
|
|
|
|
|
final cases = (td['uri_cases']! as List<Object?>).cast<Json>();
|
|
|
|
|
final texts = rows(uris, 'testdata');
|
|
|
|
|
expect(texts, hasLength(cases.length));
|
|
|
|
|
for (final (i, c) in cases.indexed) {
|
|
|
|
|
final uri = c['uri']! as String;
|
|
|
|
|
expect(texts[i][0], uri);
|
|
|
|
|
final got = errorText(() => checkAddressUri(uri));
|
|
|
|
|
expect(got.isEmpty, c['ok'], reason: uri);
|
|
|
|
|
expect(got, textOf(uris, texts[i][1]), reason: uri);
|
|
|
|
|
expect(LocatorAddress(uri).host, texts[i][2], reason: uri);
|
|
|
|
|
}
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test(
|
|
|
|
|
'the mixed locator reads, and a reader uses the address it accepts',
|
|
|
|
|
() {
|
|
|
|
|
final m = td['mixed']! as Json;
|
|
|
|
|
final mixed = openLocator(
|
|
|
|
|
p,
|
|
|
|
|
round,
|
|
|
|
|
release,
|
|
|
|
|
fromHex(m['locator_sealed']! as String),
|
|
|
|
|
);
|
|
|
|
|
final back = unmarshalLocator(
|
|
|
|
|
fromHex(m['locator_plaintext']! as String),
|
|
|
|
|
);
|
|
|
|
|
expect(summaryOf(mixed), expandSummary(tdTexts['mixed']));
|
|
|
|
|
expect(summaryOf(back), summaryOf(mixed));
|
|
|
|
|
final usable = <LocatorAddress>[];
|
|
|
|
|
for (final (i, a)
|
|
|
|
|
in (m['addresses']! as List<Object?>).cast<Json>().indexed) {
|
|
|
|
|
expect(
|
|
|
|
|
mixed.addresses[i],
|
|
|
|
|
LocatorAddress(a['uri']! as String, a['offset']! as int),
|
|
|
|
|
);
|
|
|
|
|
if (a['usable'] == true) usable.add(mixed.addresses[i]);
|
|
|
|
|
}
|
|
|
|
|
expect(usable, isNotEmpty);
|
|
|
|
|
expect(mixed.usable, usable);
|
|
|
|
|
// It cannot be written: a writer never writes an address that a reader
|
|
|
|
|
// rejects.
|
|
|
|
|
expect(() => mixed.marshal(), throwsA(isA<LocatorException>()));
|
|
|
|
|
final rest = mixed.restIn(
|
|
|
|
|
fromHex(td['host']! as String),
|
|
|
|
|
usable.first.offset,
|
|
|
|
|
);
|
|
|
|
|
expect(toHex(mixed.openEnvelope(rest)), td['dkc']);
|
|
|
|
|
},
|
Stage 7a: the addresses of a locator and the IP addresses of netip
lib/src/locator.dart starts with the addresses of spec 44.1, a port of
CheckURI and Address.Host of package locator of datekeys-go: the same
checks in the same order and the same texts, on the UTF-8 of the address,
with Go's %q of the first byte that RFC 3986 does not allow. And
checkResolvedIp, the check of the IP that a name resolves to, which a
reader runs on every connection: the classification of publicIP on the 4
or 16 bytes of an address, an IPv4-mapped one not public. Go has no such
function, since its reader does not download.
lib/src/ipaddr.dart, internal, parses IPv4 and IPv6 with the exact
acceptance of netip.ParseAddr, writes them as its String, and classifies
them as publicIP, with the blocks of spec 44.1. It works byte by byte, so
that the 128 bits of IPv6 stay exact on the web, and never uses dart:io.
The tests run the 247 addresses of locator.json and the 2 800 of the
vectors, the 1 700 strings of netip and the 868 byte strings of publicIP,
on the VM and on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
);
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
|
|
|
|
|
test('the rests: rest_size bytes from the offset, used only when their '
|
|
|
|
|
'SHA-256 is resto_digest, with the texts of Go', () {
|
|
|
|
|
final loc = openLocator(
|
|
|
|
|
p,
|
|
|
|
|
round,
|
|
|
|
|
release,
|
|
|
|
|
fromHex(td['locator_sealed']! as String),
|
|
|
|
|
);
|
|
|
|
|
final texts = rows(tdTexts, 'rest_cases');
|
|
|
|
|
for (final (i, c)
|
|
|
|
|
in (td['rest_cases']! as List<Object?>).cast<Json>().indexed) {
|
|
|
|
|
Uint8List? r;
|
|
|
|
|
expect(
|
|
|
|
|
errorText(
|
|
|
|
|
() => r = loc.restIn(
|
|
|
|
|
fromHex(c['resource']! as String),
|
|
|
|
|
c['offset']! as int,
|
|
|
|
|
),
|
|
|
|
|
),
|
|
|
|
|
textOf(v, texts[i][0]),
|
|
|
|
|
reason: '${c['name']}',
|
|
|
|
|
);
|
|
|
|
|
var opens = false;
|
|
|
|
|
if (r != null) {
|
|
|
|
|
Uint8List? dkc;
|
|
|
|
|
expect(
|
|
|
|
|
errorText(() => dkc = loc.openEnvelope(r!)),
|
|
|
|
|
textOf(v, texts[i][1]),
|
|
|
|
|
reason: '${c['name']}',
|
|
|
|
|
);
|
|
|
|
|
opens = dkc != null && toHex(dkc!) == td['dkc'];
|
|
|
|
|
}
|
|
|
|
|
expect(opens, c['opens'], reason: '${c['name']}');
|
|
|
|
|
}
|
|
|
|
|
});
|
|
|
|
|
|
Stage 7a: the data of datekeys.capsule
lib/src/locator.dart gains the data of the extension, as Info, ParseInfo
and Info.Extension of Go, with the same checks in the same order and the
same texts:
- parseCapsuleInfo: the map of spec 44.1 with the note under the rules of
spec 24.1, the canonical DateKey, and a sealed locator that is an age
file with one tlock stanza for its round; every failure is
ERR_EXTENSION_DATA_INVALID and nothing else, so that it makes the
extension unusable and never the .dkk (spec 54).
- CapsuleInfo.toExtension, which reads back what it writes (spec 72), and
CapsuleInfo.openLocator, OpenLocator of Go, with the default registry of
pinned profiles when none is given, as the opening of a capsule takes it.
- checkCapsuleData, the ValidateCapsule of Go's locator.Standard, for
StandardExtensions.
The tests run the extension cases of locator.json with their code, the
writing and the reading of the data, OpenLocator, the registry of
locator.Standard through checkCritical, checkNoncritical and checkWrite,
and the opening of a fixture whose .dkk carries datekeys.capsule, whose
unusable extensions and checks are those of Go.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
test('the data of the extension: a reader cannot use some, and that has '
|
|
|
|
|
'ERR_EXTENSION_DATA_INVALID only', () {
|
|
|
|
|
final texts = tdTexts['extension_cases']! as List<Object?>;
|
|
|
|
|
for (final (i, c)
|
|
|
|
|
in (td['extension_cases']! as List<Object?>).cast<Json>().indexed) {
|
|
|
|
|
final x = Extension(
|
|
|
|
|
capsuleExtensionId,
|
|
|
|
|
1,
|
|
|
|
|
fromHex(c['extension_data']! as String),
|
|
|
|
|
);
|
|
|
|
|
final want = textOf(v, texts[i]);
|
|
|
|
|
expect(
|
|
|
|
|
errorText(() => parseCapsuleInfo(x)),
|
|
|
|
|
want,
|
|
|
|
|
reason: '${c['name']}',
|
|
|
|
|
);
|
|
|
|
|
expect(want.isEmpty, c['ok'], reason: '${c['name']}');
|
|
|
|
|
if (want.isNotEmpty) {
|
|
|
|
|
expect(
|
|
|
|
|
() => parseCapsuleInfo(x),
|
|
|
|
|
throwsA(
|
|
|
|
|
isA<DateKeysException>().having(
|
|
|
|
|
(e) => e.code,
|
|
|
|
|
'code',
|
|
|
|
|
ErrorCode.extensionDataInvalid,
|
|
|
|
|
),
|
|
|
|
|
),
|
|
|
|
|
);
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
});
|
|
|
|
|
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
test('the plaintexts of the locator, with the texts of Go', () {
|
|
|
|
|
final texts = tdTexts['plaintext_cases']! as List<Object?>;
|
|
|
|
|
for (final (i, c)
|
|
|
|
|
in (td['plaintext_cases']! as List<Object?>).cast<Json>().indexed) {
|
|
|
|
|
final want = textOf(v, texts[i]);
|
|
|
|
|
expect(
|
|
|
|
|
errorText(
|
|
|
|
|
() => unmarshalLocator(fromHex(c['locator_plaintext']! as String)),
|
|
|
|
|
),
|
|
|
|
|
want,
|
|
|
|
|
reason: '${c['name']}',
|
|
|
|
|
);
|
|
|
|
|
expect(want.isEmpty, c['ok'], reason: '${c['name']}');
|
|
|
|
|
}
|
|
|
|
|
});
|
Stage 7a: the addresses of a locator and the IP addresses of netip
lib/src/locator.dart starts with the addresses of spec 44.1, a port of
CheckURI and Address.Host of package locator of datekeys-go: the same
checks in the same order and the same texts, on the UTF-8 of the address,
with Go's %q of the first byte that RFC 3986 does not allow. And
checkResolvedIp, the check of the IP that a name resolves to, which a
reader runs on every connection: the classification of publicIP on the 4
or 16 bytes of an address, an IPv4-mapped one not public. Go has no such
function, since its reader does not download.
lib/src/ipaddr.dart, internal, parses IPv4 and IPv6 with the exact
acceptance of netip.ParseAddr, writes them as its String, and classifies
them as publicIP, with the blocks of spec 44.1. It works byte by byte, so
that the 128 bits of IPv6 stay exact on the web, and never uses dart:io.
The tests run the 247 addresses of locator.json and the 2 800 of the
vectors, the 1 700 strings of netip and the 868 byte strings of publicIP,
on the VM and on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
});
|
|
|
|
|
|
Stage 7a: the locator, its opening and the envelope
lib/src/locator.dart gains the rest of package locator of datekeys-go but
Seal and the data of the extension, with the same checks in the same
order and the same texts:
- Locator: unmarshalLocator, the map of spec 44.1 with the length that
Marshal gives and nothing else, and marshal, its form, its addresses and
key 6 up to the least multiple of 4096 that it fills, as padFor and
PlaintextLength; usable, the addresses that a reader uses.
- openLocator, Open of Go: the profile, then age with the tlock identity
of agewrap, and at most 1 MiB of plaintext, as io.LimitReader: the
chunks after it are neither decrypted nor checked.
- The envelope: restIn, openEnvelope with the size and the SHA-256 of the
rest and of the .dkc, hideRest, and splitEnvelope, the part of
NewEnvelope after its age encryption, which needs the writer of age.
A Locator keeps the types of Go: keys and digests of 32 bytes, and no
negative size or offset. Its errors carry no code, as in Go.
The tests run the cases of locator.json, the padding of every base, 482
plaintexts, Marshal at its limits, 118 openings, the files past 1 MiB, the
envelope, the rests and the split; a part also on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
test('openLocator reads at most 1 MiB of plaintext, as Go through '
|
|
|
|
|
'io.LimitReader: what follows is neither decrypted nor checked', () {
|
|
|
|
|
final lim = v['limit']! as Json;
|
|
|
|
|
final header = fromHex(lim['header']! as String);
|
|
|
|
|
final nonce = fromHex(lim['nonce']! as String);
|
|
|
|
|
final streamKey = hkdfSha256(
|
|
|
|
|
fromHex(lim['file_key']! as String),
|
|
|
|
|
nonce,
|
|
|
|
|
'payload'.codeUnits,
|
|
|
|
|
32,
|
|
|
|
|
);
|
|
|
|
|
expect(toHex(streamKey), lim['stream_key']);
|
|
|
|
|
final plain = fromHex(
|
|
|
|
|
(v['plaintext_bases']! as List<Object?>)[0]! as String,
|
|
|
|
|
);
|
|
|
|
|
final release = releaseOf(v, lim['round']! as int);
|
|
|
|
|
for (final c in (lim['cases']! as List<Object?>).cast<Json>()) {
|
|
|
|
|
final chunks = rows(c, 'chunks');
|
|
|
|
|
final total = chunks.fold(0, (n, ch) => n + (ch[0]! as int));
|
|
|
|
|
final content = Uint8List(total)
|
|
|
|
|
..setRange(0, plain.length < total ? plain.length : total, plain);
|
|
|
|
|
final out = BytesBuilder(copy: false)
|
|
|
|
|
..add(header)
|
|
|
|
|
..add(nonce);
|
|
|
|
|
var at = 0;
|
|
|
|
|
for (final (i, ch) in chunks.indexed) {
|
|
|
|
|
final n = ch[0]! as int;
|
|
|
|
|
// An 11-byte big-endian counter and the flag of the last chunk.
|
|
|
|
|
final chunkNonce = Uint8List(12)
|
|
|
|
|
..[7] = i >> 24
|
|
|
|
|
..[8] = (i >> 16) & 0xff
|
|
|
|
|
..[9] = (i >> 8) & 0xff
|
|
|
|
|
..[10] = i & 0xff
|
|
|
|
|
..[11] = ch[1] == true ? 1 : 0;
|
|
|
|
|
final ct = chacha20Poly1305Seal(
|
|
|
|
|
streamKey,
|
|
|
|
|
chunkNonce,
|
|
|
|
|
Uint8List.sublistView(content, at, at + n),
|
|
|
|
|
);
|
|
|
|
|
if (ch[2] == true) ct[0] ^= 1;
|
|
|
|
|
out.add(ct);
|
|
|
|
|
at += n;
|
|
|
|
|
}
|
|
|
|
|
out.add(Uint8List(c['trailing']! as int));
|
|
|
|
|
final file = out.takeBytes();
|
|
|
|
|
expect([file.length, sha256Hex(file)], [c['length'], c['sha256']]);
|
|
|
|
|
expect(
|
|
|
|
|
errorText(() => openLocator(quicknet(), 1000, release, file)),
|
|
|
|
|
textOf(v, c['text']),
|
|
|
|
|
reason: '${c['name']}',
|
|
|
|
|
);
|
Stage 7a: the addresses of a locator and the IP addresses of netip
lib/src/locator.dart starts with the addresses of spec 44.1, a port of
CheckURI and Address.Host of package locator of datekeys-go: the same
checks in the same order and the same texts, on the UTF-8 of the address,
with Go's %q of the first byte that RFC 3986 does not allow. And
checkResolvedIp, the check of the IP that a name resolves to, which a
reader runs on every connection: the classification of publicIP on the 4
or 16 bytes of an address, an IPv4-mapped one not public. Go has no such
function, since its reader does not download.
lib/src/ipaddr.dart, internal, parses IPv4 and IPv6 with the exact
acceptance of netip.ParseAddr, writes them as its String, and classifies
them as publicIP, with the blocks of spec 44.1. It works byte by byte, so
that the 128 bits of IPv6 stay exact on the web, and never uses dart:io.
The tests run the 247 addresses of locator.json and the 2 800 of the
vectors, the 1 700 strings of netip and the 868 byte strings of publicIP,
on the VM and on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
}
|
|
|
|
|
});
|
Stage 7a: the data of datekeys.capsule
lib/src/locator.dart gains the data of the extension, as Info, ParseInfo
and Info.Extension of Go, with the same checks in the same order and the
same texts:
- parseCapsuleInfo: the map of spec 44.1 with the note under the rules of
spec 24.1, the canonical DateKey, and a sealed locator that is an age
file with one tlock stanza for its round; every failure is
ERR_EXTENSION_DATA_INVALID and nothing else, so that it makes the
extension unusable and never the .dkk (spec 54).
- CapsuleInfo.toExtension, which reads back what it writes (spec 72), and
CapsuleInfo.openLocator, OpenLocator of Go, with the default registry of
pinned profiles when none is given, as the opening of a capsule takes it.
- checkCapsuleData, the ValidateCapsule of Go's locator.Standard, for
StandardExtensions.
The tests run the extension cases of locator.json with their code, the
writing and the reading of the data, OpenLocator, the registry of
locator.Standard through checkCritical, checkNoncritical and checkWrite,
and the opening of a fixture whose .dkk carries datekeys.capsule, whose
unusable extensions and checks are those of Go.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
|
|
|
|
|
test('openCapsule with a .dkk that carries datekeys.capsule reports its '
|
|
|
|
|
'data as Go does with locator.Standard', () async {
|
|
|
|
|
final cap = v['capsule']! as Json;
|
|
|
|
|
final name = cap['fixture']! as String;
|
|
|
|
|
final dkc = File('testdata/fixtures/$name.dkc').readAsBytesSync();
|
|
|
|
|
final dkk = decodeAccessKey(
|
|
|
|
|
File('testdata/fixtures/$name.dkk').readAsBytesSync(),
|
|
|
|
|
);
|
|
|
|
|
final now = parseRfc3339(cap['now']! as String);
|
|
|
|
|
for (final c in (cap['cases']! as List<Object?>).cast<Json>()) {
|
|
|
|
|
final k = AccessKey(
|
|
|
|
|
credentialId: dkk.credentialId,
|
|
|
|
|
capsuleId: dkk.capsuleId,
|
|
|
|
|
type: dkk.type,
|
|
|
|
|
material: Uint8List.fromList(dkk.material),
|
|
|
|
|
verification: dkk.verification,
|
|
|
|
|
critical: dkk.critical,
|
|
|
|
|
noncritical: [
|
|
|
|
|
for (final x in rows(c, 'noncritical'))
|
|
|
|
|
Extension(x[0]! as String, x[1]! as int, fromHex(x[3]! as String)),
|
|
|
|
|
],
|
|
|
|
|
);
|
|
|
|
|
final file = encodeAccessKey(k);
|
|
|
|
|
expect(sha256Hex(file), c['dkk_sha256']);
|
|
|
|
|
final output = MemoryByteSink();
|
|
|
|
|
final opened = await openCapsule(
|
|
|
|
|
dkc,
|
|
|
|
|
OpenOptions(
|
|
|
|
|
source: suppliedRelease(releaseOf(v, 1000)),
|
|
|
|
|
now: () => now,
|
|
|
|
|
accessKeyFile: file,
|
|
|
|
|
output: output,
|
Stage 7a: the default registry checks datekeys.capsule; README, changelog
StandardExtensions checks by default the data of datekeys.capsule with
checkCapsuleData, as locator.Standard of Go: when a .dkk is opened with
it, an extension whose data does not read is unusable, with the text of
Go. With validateCapsule: null it checks only that there is data, as
Go's extension.Standard without ValidateCapsule: the writer of a .dkk
keeps that one, as Go's writer does, and so do the tests of the formats
that compare with extension.Standard. Inspection and opening give Go's
results on every fixture and vector, and the tests of the locator use the
default registry.
lib/datekeys.dart exports locator.dart. The README has the section of
part 7a, its vectors and how the generator makes them; the changelog has
its entry, with its tests and its injected faults.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
extensions: c['standard'] == true ? const StandardExtensions() : null,
|
Stage 7a: the data of datekeys.capsule
lib/src/locator.dart gains the data of the extension, as Info, ParseInfo
and Info.Extension of Go, with the same checks in the same order and the
same texts:
- parseCapsuleInfo: the map of spec 44.1 with the note under the rules of
spec 24.1, the canonical DateKey, and a sealed locator that is an age
file with one tlock stanza for its round; every failure is
ERR_EXTENSION_DATA_INVALID and nothing else, so that it makes the
extension unusable and never the .dkk (spec 54).
- CapsuleInfo.toExtension, which reads back what it writes (spec 72), and
CapsuleInfo.openLocator, OpenLocator of Go, with the default registry of
pinned profiles when none is given, as the opening of a capsule takes it.
- checkCapsuleData, the ValidateCapsule of Go's locator.Standard, for
StandardExtensions.
The tests run the extension cases of locator.json with their code, the
writing and the reading of the data, OpenLocator, the registry of
locator.Standard through checkCritical, checkNoncritical and checkWrite,
and the opening of a fixture whose .dkk carries datekeys.capsule, whose
unusable extensions and checks are those of Go.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
),
|
|
|
|
|
);
|
|
|
|
|
expect(opened.error?.message ?? '', textOf(v, c['text']));
|
|
|
|
|
expect(
|
|
|
|
|
[
|
|
|
|
|
for (final u in opened.unusableAccessKeyExtensions)
|
|
|
|
|
[u.id, u.version, u.error.message],
|
|
|
|
|
],
|
|
|
|
|
[
|
|
|
|
|
for (final u in rows(c, 'unusable')) [u[0], u[1], textOf(v, u[2])],
|
|
|
|
|
],
|
|
|
|
|
);
|
|
|
|
|
expect([
|
|
|
|
|
for (final ch in opened.checks)
|
|
|
|
|
[ch.step, ch.name, ch.ok, ch.detail, ch.error ?? ''],
|
|
|
|
|
], c['checks']);
|
|
|
|
|
expect(sha256Hex(output.bytes ?? Uint8List(0)), c['content']);
|
|
|
|
|
}
|
|
|
|
|
});
|
Stage 7a: the addresses of a locator and the IP addresses of netip
lib/src/locator.dart starts with the addresses of spec 44.1, a port of
CheckURI and Address.Host of package locator of datekeys-go: the same
checks in the same order and the same texts, on the UTF-8 of the address,
with Go's %q of the first byte that RFC 3986 does not allow. And
checkResolvedIp, the check of the IP that a name resolves to, which a
reader runs on every connection: the classification of publicIP on the 4
or 16 bytes of an address, an IPv4-mapped one not public. Go has no such
function, since its reader does not download.
lib/src/ipaddr.dart, internal, parses IPv4 and IPv6 with the exact
acceptance of netip.ParseAddr, writes them as its String, and classifies
them as publicIP, with the blocks of spec 44.1. It works byte by byte, so
that the 128 bits of IPv6 stay exact on the web, and never uses dart:io.
The tests run the 247 addresses of locator.json and the 2 800 of the
vectors, the 1 700 strings of netip and the 868 byte strings of publicIP,
on the VM and on Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
}
|