v0.16
v0.15
v0.14
v0.13
v0.12
v0.11
${ noResults }
4 Commits (b23a0eeb5cb89c7a29e59d0ada494905344145d0)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
8dc45c2712 |
Stage 5c: the verdicts of alg 2 and seal_type 2, and the opening gives them
securitycms.dart ports evaluateCMS, signerLine and evaluateSeal of signature2.go of Go at the draft v0.12, on the reader of CMS of stage 5a, with the same order of checks: SIGNERS with its profile and at most 16 entries, then the SignedData; each required signer in the order of SIGNERS and each foreign one in the order of the encoding, valid, invalid, absent, not verifiable, without seal, with an invalid seal or out of validity at the time of its seal; F2, F5 and F6 with their detail; and the seal over SEAL_SUBJECT, S1 to S5 with the authority and t. A round time at Go's zero time is no round time, as IsZero, and Verdicts.sealedAt skips a seal at that time, as SealedAt. cmsReader is the default CmsEvaluator of evaluateSecurity, and so of evaluateSecurityInput and the opening: nothing that Go evaluates is left not evaluated; a caller that passes cms: null still gets the parts without CMS alone. encodeSigners and maxSigners are exported, as EncodeSigners and MaxSigners of Go. The tests compare every part with Go: the 135 cases of security_cms.json with the result of each signer, the 24 of security.json, the 56 signatures of alg 2 and 105 seals of seal_type 2 of security_vectors.json, the 755 cases of securitycms_vectors.json with their detail and earliest seal, the fixtures format3_signed_cms and format3_sealed, and their openings in open_cases.json. On Node.js, a part of the vectors and the two fixtures opened in full. 1572 tests on the VM and 332 on Node.js. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
3 days ago |
|
|
a7f6f94c19 |
Stage 5b: the opening evaluates the security area as Go
OpenOptions.evaluator is now evaluateSecurityInput, so that opening a capsule of format 3 gives the verdicts of Go at step 17: the signature of alg 1 and every verdict of the form, with the author keys of the options, and the signature of alg 2 and the seal of seal_type 2 not evaluated until a reader of CMS is given. notEvaluated stays for a caller that shows no verdict. tool/open_go_vectors.go records the verdicts of each capsule of format 3 that opens, with their lines, the key and the label of alg 1 and the earliest valid seal, and opens the fixtures signed with alg 1 also with their author key saved, F3, and with another, F4. Every case of open_cases.json and every case of the mutation corpus that opens gives those verdicts and lines: format3_signed, format3_unsigned, format3_signature_unsupported, format3_seal_unsupported, format3_security_v2 and format3_note all of them, and format3_signed_cms and format3_sealed the part that needs no reader of CMS. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
3 days ago |
|
|
95f9c5a333 |
Test data of the branch v0.12 of datekeys-go at c531e93
testdata/ is synced with datekeys-go at c531e93, the head of the branch v0.12, whose testdata is that of 601e6d2, the copy of datekeys-ts. Every file keeps "spec": "0.11": the draft v0.12 is not approved yet. From the tag spec-v0.11 it brings the fixtures format3_unsigned and format3_note, format3_seal_unsupported with seal_type 4294967295, the records of format3_sealed and format3_signed_cms, the mutation corpus of 218 cases, note.json, security.json with a context and lines, security_cms.json of 135 cases and locator.json. The vectors that the generators of tool/ make from the testdata are written again by Go at c531e93: mutation_texts.json, open_cases.json, formats_*.json with formats_vectors.g.dart, ibe_vectors.json and age_fixtures.json; release_vectors.json, primitives.json and the views of open_vectors.g.dart come out the same. age.json does not read the testdata, and stays frozen: age draws its keys from crypto/rand. The tests count 26 fixtures and 218 cases, and the inspection of format3_note gives the note of its record. No difference with Go. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
3 days ago |
|
|
f03a0acf1c |
Stage 4c: steps 9 to 18, the opening of the three formats
lib/src/open.dart and open3.dart port Open and openBody of package capsule of datekeys-go at c531e93, with the checks, codes, steps and texts of the reference and the detail of each check: the .dkk of step 9.a, decoded or still encoded, with its material, its critical extensions, its capsule_id and its capsule_digest; at least one credential; the clock and the release, with the rule of step 9 for the failures of its source (sourceFailure); its verification at step 10; OUTER_TIME_AGE with the tlock stanza; INNER_ACCESS_AGE with the X25519 identities, those of the .dkk and the key of words, and the rules of the slots; CONTROL_CBOR, header_binding, I_PAYLOAD and P; PAYLOAD_AGE streamed, with the padding of format 2 checked and never delivered, and in format 3 the frame of BODY, the area, the head, each file to the sink with its SHA-256 and the padding, with the precedence of spec §63; and the commit. A failure of age keeps the code of the identity that reports it, or is ERR_INTEGRITY with the reason of its phase, as classify of Go. openCapsule opens a capsule in memory and openCapsuleSource one that a ByteSource reads: the prefix of the inspection and the nonce of PAYLOAD_AGE before the release, then pieces of 1 MiB. lib/src/sink.dart has ByteSink, for the content of formats 1 and 2 and for each file, and FileSink, for the files of format 3, as the dst and the Sink of Go, with MemoryByteSink and MemoryFileSink. Nothing is presented as valid before step 17 ends: the output is closed only then and aborted after any failure, and the sink aborted after any failure that follows its begin (spec §56). The signature and the seal are stage 5: lib/src/verdicts.dart has the verdicts and the SecurityEvaluator, given what newSecurityContext and EvaluateSecurityIn of Go take, which never fails the opening; the default evaluates nothing. OpenOptions.accept is Accept of Go. And AgePayloadDecryptor.wipe clears the key of a STREAM left unread. The tests run open_cases.json and the mutation corpus with the texts and the checks of Go, in memory and from a source read in pieces; capsules of several MiB made from the fixtures, for the streaming; a capsule with a stanza for a key of words; and the caller, the sinks and the evaluator. open_test.dart runs on Node.js too, with open_vectors.g.dart. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
3 days ago |