specVersion is 0.16, and testdata, wordlists and annex are synced with
datekeys-go at 3fd0e93 (branch v0.16, the draft v0.16): 150 files, with
the two fixtures of v0.16, security_cms.json made again (143 cases, with
seal_reason), 26 cases of drand's JSON in release.json, the annex vector in
wordkey.json, and the annex of the draft. The code follows 4f78854; 3fd0e93
only restores the escapes of the JSON vectors.
A valid seal is S4 only when its token carries accuracy and t plus the
accuracy is before round_time; otherwise S5, with the first reason that
holds: late, no accuracy under the BTSP policy of ETSI EN 319 421, or no
accuracy (spec v0.16, 29.7, 29.11), as 7e3b810 of Go. cms.Token gains
hasAccuracy, policy and btsp; SealReason, Detail.sealReason and
SignerLine.reason carry the reason, and the lines of S5 and of a signer of
F6 say it with the texts of Go. A CmsEvaluator that gives S5 without a
reason or S4 with one is out of range: S2. EncryptResult.security gives the
verdicts of the area the writer wrote, as Result.Security, so that the app
warns of a seal that proves nothing before the opening date (rule 19).
drand's JSON is read strictly, as b570338 of Go: parseDrandJson, exported,
reads RFC 8259 JSON in valid UTF-8 whose value is an object, with no name
repeated in any object, names compared exactly after their escapes are
decoded, no lone surrogate escape, a round without sign, fraction or
exponent from 1 to 2^53 - 1 (compared as text at 16 digits, exact on the
web), and string signature and randomness. The error texts are those of
Go. A round above 2^53 - 1 is no longer a difference with Go.
Tests: the new fixtures (format3_time_and_key_words opens with the identity
of its words_text, as TestFixtureWords; format3_full_chunk is one full
STREAM chunk), the annex vector of wordkey.json, seal_reason in every case
of security_cms.json, the reasons and their lines, the token fields, and
TestStrictJSON and TestJSONRound of Go, also compiled to JavaScript.
Vectors regenerated by the Go programs of tool/ in an export of datekeys-go
at 4f78854: security and securitycms (reasons, BTSP tokens, an accuracy of
0 seconds and an empty one; the part for Node.js has each reason), the CMS
files (has_accuracy, policy and btsp of each token, oidBTSP, the new
corpus), the capsule writer (sealed with an accuracy of a second, two
recipes without accuracy, Result.Security), and the formats, open,
mutation, IBE and age fixture vectors, for the new fixtures and the spec
field.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>