specVersion is 0.15 and testdata is synced with datekeys-go at 3c3e737
(branch v0.15): every file changes its spec field, mutations.json gains the
field source and four cases, and vectors/release.json and releases/ are new
(142 files).
release.dart, as provider of Go at 2eeca40, with its texts: encodeRelease
and decodeRelease of the release object (spec v0.15, 47.1) with the CBOR
profile of the library, its size first, then its type and version, then its
schema; parseRelease, which also reads drand's JSON with the rules of
encoding/json of Go for its three fields; verifyRelease checks the chain hash
a release names, ERR_PROFILE_MISMATCH, before its round and its signature;
ReleaseSupplier, EncodedRelease and supplyRelease, a release in the caller's
hand; and ReleaseArchive, the lookup of a local release archive (50), whose
failures are ERR_RELEASE_UNAVAILABLE at step 9.
open: OpenOptions.release takes a release in hand, exclusive with source. It
is not compared with the clock (step 9.c); Opened.clockBehind reports a clock
behind it, and the step 9 detail is Go's. Step 10 starts with the layers of
the object. A network source keeps its behaviour. Opened.release carries the
chain hash of the pinned profile.
Vectors: mutation_texts.json is regenerated with tool/mutation_go_texts.go,
which now replays each case with its source as testkit does: 149 cases
change only the detail of step 9 ("release supplied by the caller"), the
case "round not reached yet" now opens, and the four new cases are added.
release_vectors.json, the open vectors, and the formats, locator, security
and seal vectors come out the same at 3c3e737 but for their spec field.
tool/release_archive_go_texts.go writes the texts of provider.Archive on
edited archives; tool/release_copy.dart copies release.json, releases/ and
those texts to release.g.dart for the tests compiled to JavaScript.
errors_spec_test reads the spec at the commit of testdata/SOURCE.json rather
than at its tag.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The author approved the draft v0.14 with the recommendation of each of its
ten decisions; datekeys-go closes it with the tag spec-v0.14 (39b2033).
specVersion is 0.14 and testdata is synced with that commit: every file
changes its spec field, and vectors/tlock_steps.json is new (136 files).
Decision 8: validateProfile admits only bls-unchained-g1-rfc9380, with its
public key in G2, as validateDrand of Go since c041fa3, in its order and
with its text. formats_profile.json and its part of formats_vectors.g.dart
are regenerated with tool/formats_go_vectors.go on 39b2033: only the
thirteen cases of another drand scheme change. The other Go-generated
vectors change only their spec field.
tlock_steps_vm_test.dart walks tlock_steps.json value by value with the
code of the library, and tlock_steps_test.dart walks its copy,
tlock_steps.g.dart from tool/tlock_steps_copy.dart, compiled to JavaScript.
The comment of h3 in ibe.dart now says what the code does: it shifts the
first byte one bit to the right, as kyber does.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Injected faults showed two rules that only the tests on the VM checked:
SIGNERS of more than 16 entries, whose only case was in security_cms.json,
and the order of the foreign signers. securitycms_vectors.json gains
SIGNERS of 16 and of 17 entries with Ana among them, beside her signature
for those SIGNERS or for SIGNERS with her alone, and a required signer
beside two foreign ones, without seals so that the area stays small; the
part for Node.js holds them. 760 cases.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
tool/security_go_vectors.go also writes securitycms_vectors.json:
EvaluateSecurityIn of package capsule at the draft v0.12 on 755 areas
whose CMS signature or RFC 3161 seal it makes, as internal/cms/cmstest
makes them, with the verdicts, the lines, the detail of every signer and
of a valid seal, and SealedAt. Required and foreign signers of every
result; three required signers drawn from a seed; the validity of a
certificate at the time of its seal, at the nanosecond; t plus the
accuracy against the round time on both sides of it, Go's zero time and
the last second of 9999; a seal of each verdict beside a signature of
each verdict; and mutations of a SignedData, of SIGNERS and of tokens.
cmstest cannot be imported from outside the tree of datekeys-go, so the
part of it these cases need is restated. The keys come from labels, ECDSA
signs with the nonce of RFC 6979 and RSA with PKCS #1 v1.5: every run
writes the same bytes, and security_vectors.json and its part are the
same as before. Certificates, tokens and SignerInfo are written once, as
chunks. securitycms_vectors.g.dart holds a part of the cases, each verdict
pair of each group among them, and the fixtures format3_signed_cms and
format3_sealed, for the tests compiled to JavaScript.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>