Public Access
docs/crypto.md is now the normative, frozen specification. This had to land before anything else in M1: the server holds ciphertext and no keys, so it can never re-encrypt, and a format change after users hold data is a coordinated client rewrite with no rollback. Specification: - DSH1 envelope layout, canonical 64-byte AAD encoding, SealTo construction, key hierarchy, Argon2id profiles, fingerprints, and the change rules for each version field. - AAD encoding is fixed-width binary rather than delimited string concatenation, so no field value can forge a field boundary. This supersedes the illustrative form sketched in ADR 0001, which now points here. - UUIDs are RFC 4122 big-endian. Guid.ToByteArray() emits the first three groups little-endian and would have made our ciphertext unreadable by any other implementation of this spec, failing only at a cross-implementation boundary. Verified rather than assumed: - PrimitiveAvailabilityTests proves X25519, Ed25519, XChaCha20-Poly1305, Argon2id and HKDF-SHA512 all function on net10.0. NSec 26.4.0 targets net9.0 and is consumed by forward compatibility; this closes one of the two package questions the plan flagged. - Argon2Profile exists because NSec's MemorySize is in KIBIBYTES, not bytes. Passing bytes gives either a 256 GiB allocation or a 256 KiB KDF that cracks instantly. The type takes mebibytes so the unit cannot be got wrong at a call site. Found by benchmarking: the first measurements were ~1000x too slow, which turned out to be 19 GiB of work. - Parameters measured, not guessed: 256 MiB/t=4 is 323 ms on this machine; the table of candidates is in the spec. Implementation and tests (83 total, up from 17): - AadDescriptor, DshEnvelope, DshCrypto (Seal/Open/SealTo/OpenSealed/fingerprints). - Decryption returns null rather than throwing: ciphertext comes from a server that is explicitly not trusted, so a failed tag is an expected outcome. - Envelope readers reject unknown algorithms and any non-zero flag bit, so an envelope that is not fully understood fails closed. - Executable form of the spec's substitution claims: a server cannot move ciphertext between resources, roll back a key generation or item version, repurpose a payload as metadata, or confuse the two constructions. - Golden vectors in tests/fixtures/crypto/vectors.json guard the format. Mutation-checked: a one-byte schema version change trips four tests including the guard. Two build-infrastructure bugs found and fixed along the way: - .editorconfig forced camelCase on const and static readonly fields. PascalCase is the .NET convention for both; the config was wrong, not the code. - The golden fixture was resolved with [CallerFilePath], which ContinuousIntegrationBuild rewrites to /_/... under deterministic source paths. It passed locally and would have failed only in CI. Now copied to the output directory and read from there.
135 lines
6.1 KiB
INI
135 lines
6.1 KiB
INI
# EditorConfig for DodoSSH — https://editorconfig.org
|
|
root = true
|
|
|
|
[*]
|
|
charset = utf-8
|
|
end_of_line = lf
|
|
indent_style = space
|
|
indent_size = 4
|
|
insert_final_newline = true
|
|
trim_trailing_whitespace = true
|
|
|
|
[*.{json,yml,yaml,js,ts,css,html,axaml,xaml,csproj,props,targets,slnx}]
|
|
indent_size = 2
|
|
|
|
[*.md]
|
|
# Two trailing spaces are a hard line break in Markdown.
|
|
trim_trailing_whitespace = false
|
|
|
|
[*.{cmd,bat,ps1}]
|
|
end_of_line = crlf
|
|
|
|
[*.cs]
|
|
indent_size = 4
|
|
|
|
#### Language conventions ####
|
|
|
|
csharp_style_namespace_declarations = file_scoped:error
|
|
csharp_using_directive_placement = outside_namespace:error
|
|
csharp_style_var_for_built_in_types = false:suggestion
|
|
csharp_style_var_when_type_is_apparent = true:suggestion
|
|
csharp_style_var_elsewhere = false:suggestion
|
|
csharp_prefer_braces = true:suggestion
|
|
csharp_style_prefer_primary_constructors = true:suggestion
|
|
csharp_style_expression_bodied_methods = when_on_single_line:suggestion
|
|
csharp_style_expression_bodied_properties = true:suggestion
|
|
|
|
dotnet_sort_system_directives_first = true
|
|
dotnet_separate_import_directive_groups = false
|
|
|
|
dotnet_style_qualification_for_field = false:suggestion
|
|
dotnet_style_qualification_for_property = false:suggestion
|
|
dotnet_style_qualification_for_method = false:suggestion
|
|
dotnet_style_readonly_field = true:warning
|
|
dotnet_style_require_accessibility_modifiers = for_non_interface_members:warning
|
|
dotnet_style_coalesce_expression = true:suggestion
|
|
dotnet_style_null_propagation = true:suggestion
|
|
dotnet_style_prefer_is_null_check_over_reference_equality_method = true:suggestion
|
|
|
|
# Async methods must be suffixed Async (VSTHRD200 equivalent via naming rules below).
|
|
dotnet_naming_rule.async_methods_end_in_async.severity = warning
|
|
dotnet_naming_rule.async_methods_end_in_async.symbols = any_async_method
|
|
dotnet_naming_rule.async_methods_end_in_async.style = ends_with_async
|
|
dotnet_naming_symbols.any_async_method.applicable_kinds = method
|
|
dotnet_naming_symbols.any_async_method.required_modifiers = async
|
|
dotnet_naming_style.ends_with_async.required_suffix = Async
|
|
dotnet_naming_style.ends_with_async.capitalization = pascal_case
|
|
|
|
dotnet_naming_rule.interfaces_start_with_i.severity = warning
|
|
dotnet_naming_rule.interfaces_start_with_i.symbols = any_interface
|
|
dotnet_naming_rule.interfaces_start_with_i.style = starts_with_i
|
|
dotnet_naming_symbols.any_interface.applicable_kinds = interface
|
|
dotnet_naming_style.starts_with_i.required_prefix = I
|
|
dotnet_naming_style.starts_with_i.capitalization = pascal_case
|
|
|
|
# Constants and static readonly fields are PascalCase, per .NET convention. These rules must
|
|
# come before the camelCase rule below: the first matching rule wins, and a rule matching all
|
|
# private fields would otherwise force `const int Foo` to be named `foo`.
|
|
dotnet_naming_rule.constants_are_pascal_case.severity = warning
|
|
dotnet_naming_rule.constants_are_pascal_case.symbols = any_const_field
|
|
dotnet_naming_rule.constants_are_pascal_case.style = pascal_case_style
|
|
dotnet_naming_symbols.any_const_field.applicable_kinds = field
|
|
dotnet_naming_symbols.any_const_field.applicable_accessibilities = *
|
|
dotnet_naming_symbols.any_const_field.required_modifiers = const
|
|
|
|
dotnet_naming_rule.static_readonly_fields_are_pascal_case.severity = warning
|
|
dotnet_naming_rule.static_readonly_fields_are_pascal_case.symbols = static_readonly_field
|
|
dotnet_naming_rule.static_readonly_fields_are_pascal_case.style = pascal_case_style
|
|
dotnet_naming_symbols.static_readonly_field.applicable_kinds = field
|
|
dotnet_naming_symbols.static_readonly_field.applicable_accessibilities = *
|
|
dotnet_naming_symbols.static_readonly_field.required_modifiers = static, readonly
|
|
|
|
dotnet_naming_style.pascal_case_style.capitalization = pascal_case
|
|
|
|
# Private instance fields are camelCase.
|
|
dotnet_naming_rule.private_fields_are_camel_case.severity = warning
|
|
dotnet_naming_rule.private_fields_are_camel_case.symbols = private_field
|
|
dotnet_naming_rule.private_fields_are_camel_case.style = camel_case_style
|
|
dotnet_naming_symbols.private_field.applicable_kinds = field
|
|
dotnet_naming_symbols.private_field.applicable_accessibilities = private
|
|
dotnet_naming_style.camel_case_style.capitalization = camel_case
|
|
|
|
#### Diagnostics ####
|
|
|
|
# Formatting violations fail the build; `dotnet format --verify-no-changes` gates CI.
|
|
dotnet_diagnostic.IDE0055.severity = error
|
|
|
|
# ConfigureAwait is not meaningful in ASP.NET Core (no SynchronizationContext). It IS
|
|
# meaningful in the Avalonia client, which re-enables CA2007 in its own .editorconfig.
|
|
dotnet_diagnostic.CA2007.severity = none
|
|
|
|
# Prefer LoggerMessage source generation over ILogger extension calls — allocation-free
|
|
# and gives structured events by construction. Warning, so it is visible but not a wall
|
|
# during early development; raised to error once the logging pass lands in M4.
|
|
dotnet_diagnostic.CA1848.severity = warning
|
|
|
|
# Exceptions carry ProblemDetails codes, not localised text.
|
|
dotnet_diagnostic.CA1303.severity = none
|
|
|
|
# CA1711 reserves the suffixes Flags, Permission, Collection, Stream and friends for
|
|
# .NET Framework CAS and BCL base types that have no bearing on this codebase. The BCL
|
|
# itself ships BindingFlags. PermissionFlags is the clearest name for a [Flags] enum of
|
|
# permissions, and contorting domain vocabulary to satisfy a legacy rule costs more than
|
|
# it returns.
|
|
dotnet_diagnostic.CA1711.severity = none
|
|
|
|
# CA1724 flags any type whose name collides with a BCL *namespace* (e.g. a type named
|
|
# Permissions vs System.Security.Permissions). Namespace-qualified resolution makes this
|
|
# a non-issue in practice and it heavily constrains domain naming.
|
|
dotnet_diagnostic.CA1724.severity = none
|
|
|
|
# We use file-scoped namespaces and modern C#; these fire on deliberate style choices.
|
|
dotnet_diagnostic.CA1812.severity = none # internal types instantiated by DI
|
|
dotnet_diagnostic.CA1849.severity = warning # sync call in async method
|
|
|
|
[tests/**/*.cs]
|
|
# Test classes are instantiated by xunit, and test data is often public static.
|
|
dotnet_diagnostic.CA1812.severity = none
|
|
dotnet_diagnostic.CA1034.severity = none
|
|
|
|
[src/DodoSSH.Infrastructure/Migrations/*.cs]
|
|
# EF Core generates these; do not lint or format them.
|
|
generated_code = true
|
|
dotnet_analyzer_diagnostic.severity = none
|
|
dotnet_diagnostic.IDE0055.severity = none
|