lib/datekeys.dart exports the writer of capsules, and what its options
take: X25519Recipient and checkX25519Recipient, RandomSource and
secureRandom. The tests that imported them from their modules no longer
need to. tool/encrypt3_bench.dart times the writer on the VM and in
Node.js.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
tool/capsule_interop_dart_samples.dart writes the capsules of twelve
recipes, six with SeededRandomSource and six with the CSPRNG of the
platform, among them three MiB in three files, two hundred files, and a
capsule of fourteen recipients, a key of words and a portable key.
tool/capsule_interop_go_verdicts.go inspects and opens each with
capsule.Open of Go, with each credential alone, all together and none,
encodes PUBLIC_HEADER, CONTROL_CBOR and the .dkk again, and writes each
seeded one with capsule.EncryptFiles.
Go opens every capsule to the files of its recipe, refuses each without a
credential, finds the layers and the .dkk encoded as it encodes them, and
writes the seeded ones byte for byte. The tests check those verdicts and
write the seeded samples again.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>