Commit deba613
committed
encryption: X25519, HKDF-SHA384 and signed bundles — the sealed-channel primitives
W0 of the sealed-channel plan: the three pieces both tracks need, none of
which commit us to the open decision about where the client key lives.
kx.rs — X25519 key agreement. Ephemerals are single-use by TYPE (agreement
consumes self), not by convention, because our feature set deliberately
excludes the crate's own RNG path: entropy here comes only from
crate::fill_random. Low-order peer keys are rejected via was_contributory()
— without that check an attacker who can inject a public key forces both
sides to derive a shared secret it already knows. RFC 7748 vector included.
hkdf_sha384.rs — the key schedule. Separate c2s/s2c keys from one
derivation: with a single key in both directions, a reflected record is
indistinguishable from a genuine one. RFC 5869 publishes no SHA-384 vectors,
so there is a real SHA-256 vector as a wiring check and a marked TODO rather
than an invented one — a fabricated vector looks exactly like verification
and is worse than none.
bundle.rs — Ed25519-signed content bundles, the unit an "app" ships as. The
signature covers header AND body, so kind/classid/version cannot be spliced
between two legitimately signed bodies. The publisher key travels in the
blob but is checked against a caller-supplied allowlist: a self-signed
bundle is not valid, and carrying the key exists to make the failure legible
("unknown publisher") rather than silent. sign() overwrites the publisher
field from the signing key, so a caller cannot mint a bundle that lies about
its own signer. Fixed byte layout rather than signed JSON because JSON
canonicalisation is a documented signature-bypass source: two parsers, two
readings, one signature.
wasm.rs — verify_bundle returns a VerifiedBundle with no constructor. The
only route to a body is through the signature check, so "render whatever
arrived" is not expressible rather than merely discouraged. An empty
allowlist throws instead of quietly accepting anything.
54 tests green, clippy clean, wasm-bindings feature compiles.
Generated by [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Mwq1QKpw4zRd6oaGRoJhF21 parent 8aef362 commit deba613
7 files changed
Lines changed: 1197 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
21 | 24 | | |
22 | 25 | | |
23 | 26 | | |
| |||
0 commit comments