boring 0.4.1
boring: ^0.4.1 copied to clipboard
Raw FFI bindings to BoringSSL with Dart Native Assets and OPENSSL_cleanse-backed native allocation.
0.4.1 #
- Fixed
libbssl_dart.sodynamically linkinglibc++_shared.soon Android when built from source with CMake (LINKER_LANGUAGE C).
0.4.0 #
- Breaking:
package:boringnow only exposes the rawffigenBoringSSL bindings (package:boring/bindings.dart) plus a minimal FFI toolkit. The high-level Dart crypto, X.509, and ASN.1 APIs from 0.3.0 were removed. - Added
opensslAllocator(OPENSSL_malloc/OPENSSL_free, scrubbed withOPENSSL_cleanse) withnativeFree,addresses.*symbol addresses for all*_free/*_cleanupfunctions,NativeHandle<T>, andextractBoringSslError(). - Added
BoringArena, anopensslAllocator-backed arena withusing,onReleaseAll,move(for BoringSSL'sset0ownership transfer), Future-awareBoringArena.run, andBoringArena.stream, pluscopyBytes,cbs(),cbb(), andCBB.toBytes(). - Added tree-shaking: the bindings are annotated with
@RecordUse(), and when linking is enabled (dart build, and Flutter profile and release builds),hook/link.dartlinks a dynamic library with only the functions the application uses.addresses.*are now getters of theSymbolAddressesextension, so their uses are recorded too. - Breaking: Removed the bindings to 29 functions that BoringSSL declares but
that aren't compiled, such as
EVP_bf_cbcandRSA_generate_keyfromdecrepit/. They failed to resolve when called. - Every GitHub Release now has the dynamic and the static library for each prebuilt target. The Linux libraries are built on Ubuntu 22.04, and require glibc 2.35 instead of 2.38.
0.3.0 #
Expanded cryptographic primitives to match modern native application and
package:webcrypto capabilities:
- X25519 Key Agreement: Added
BoringX25519(generateKeyPair,publicKeyFromPrivate,computeSharedSecret),KeyType.x25519,BoringPrivateKey.generateX25519(), andderiveSharedSecret/deriveBitssupport for X25519 keys. - Constant-Time Verification: Added
BoringCrypto.timingSafeEqual(wrappingCRYPTO_memcmp),BoringHmac.verify, andBoringHmac.verifyStream. - Key Generation & Raw Key Import/Export: Added
BoringPrivateKey.generateEd25519(),BoringPrivateKey.fromRawKey(),BoringPublicKey.fromRawKey(), and.toRawBytes()for 32-byte Ed25519/X25519 keys, plus optionalpasswordsupport onBoringPrivateKey.fromPemandtoPemfor encrypted PKCS#8 PEM keys. Also allowedBoringEd25519.signto accept a 32-byte seed directly. - PBKDF2: Added
BoringPbkdf2.deriveBitsandderiveKeyfor password-based key derivation (RFC 2898 / PKCS #5 v2.0) across all supported hash algorithms. - Symmetric Ciphers (AES-CBC & AES-CTR): Added
BoringCipherandCipherAlgorithmsupporting AES-128/192/256 in CBC mode (with PKCS#7 padding) and CTR mode (standard 128-bit counter stream). - AES Key Wrap: Added
BoringAesKeyWrap.wrapandunwrapfor RFC 3394 / NIST SP 800-38F key wrapping. - RSA-PSS: Added Probabilistic Signature Scheme support to
BoringPrivateKey.signandBoringPublicKey.verifyviaRsaSignaturePadding.pssand configurablepssSaltLength. - RSA-OAEP: Added
BoringPublicKey.encryptOaepandBoringPrivateKey.decryptOaepfor RFC 8017 asymmetric encryption with configurable OAEP hash, MGF1 hash, and optional labels. - ECDH Key Agreement: Added
BoringPrivateKey.deriveSharedSecretandderiveBitsfor elliptic-curve Diffie-Hellman key agreement across P-256, P-384, and P-521. - Streaming APIs: Added stream-based operations:
BoringDigest.hashStreamandsha1Stream/sha224Stream/sha256Stream/sha384Stream/sha512Stream/blake2b256Stream.BoringHmac.computeStream,verifyStream, andsha256Stream/sha384Stream/sha512Stream.BoringPrivateKey.signStreamandBoringPublicKey.verifyStreamfor RSA, ECDSA, and Ed25519.
- Deterministic Disposal & Memory Cleansing: Added
.dispose()toBoringPrivateKey,BoringPublicKey,X509Certificate,X509Verifier,DigestContext, andHmacContext, and ensured ephemeral secret buffers in FFI arenas are scrubbed viaOPENSSL_cleansebefore deallocation. - Wycheproof Conformance: Added conformance test suites for AES-CBC, AES Key Wrap, PBKDF2, RSA-PSS, RSA-OAEP, and ECDH.
X509Verifier can now check peer identity, key usage and chain length, and the
package is validated against the x509-limbo path
validation suite.
- Breaking:
X509Certificate.keyUsagenow returnsint?(nullwhen the certificate does not carry akeyUsageextension) instead of0xFFFFFFFF. X509Certificategainedsha256Fingerprint,authorityKeyIdentifier,signatureAlgorithm(OID), andsignatureAlgorithmName.X509VerifiergainedaddTrustedCertificatesandaddTrustedCertificatesPem.X509Verifier.verifygained seven options:peerNames: names the leaf must assert, asX509PeerName.dnsName,X509PeerName.ipAddressorX509PeerName.emailAddress. Several DNS names are matched with OR semantics.hostnameFlags:X509HostnameFlag.neverCheckSubject(the default, which suppresses BoringSSL's legacy subject common name fallback) andX509HostnameFlag.noWildcards.purpose: anX509Purposeenabling key usage and extended key usage checks, e.g.X509Purpose.tlsServer.maxIntermediates: a chain length limit, excluding leaf and trust anchor.insecurelyAllowWeakSignatureDigests: opts out of the weak digest rejection described below.insecurelyAllowWeakKeysandminimumRsaKeyBits: opt out of, and tune, the key strength rejection described below.
- Behaviour change:
X509Verifier.verifynow rejects a chain containing a certificate signed with MD4, MD5 or SHA-1.X509_verify_certapplies no signature algorithm policy of its own — BoringSSL has neither OpenSSL'sX509_VERIFY_PARAM_set_auth_levelnor itsset1_sigalgs— so the verified chain is walked afterwards. The trust anchor is exempt, since its self-signature is never verified. PassinsecurelyAllowWeakSignatureDigests: trueto restore the old behaviour. - Behaviour change: the same walk now also rejects weak public keys: RSA
below
minimumRsaKeyBits(2048 by default, as the CA/Browser Forum baseline requirements demand), EC on any curve other than P-256, P-384 and P-521, DSA, and keys BoringSSL cannot decode at all such as P-192. Unlike the digest check this includes the trust anchor, whose key signs the certificate below it. Ed25519, ML-DSA and future algorithms are deliberately left alone rather than rejected as unrecognised. PassinsecurelyAllowWeakKeys: trueto restore the old behaviour. X509VerificationResultgainederrorDepth, the position in the chain at which verification failed.- Added the x509-limbo conformance suite (
./tool/run_x509_limbo_tests.sh), covering 9,770 chain building and validation testcases. 94.5% agree with the suite; the remainder are listed with an explanation intest/conformance/x509_limbo_expected_failures.txt.
This release also removes hand-written parsing logic from the Dart layer. Every
ASN.1 operation is now delegated to BoringSSL, keeping package:boring a thin
wrapper rather than a reimplementation.
- Breaking:
Asn1Value.identifier(the raw DER identifier octet) is replaced byAsn1Value.tag, which holds BoringSSL'sCBS_ASN1_TAG. UsetagClass,isConstructed, andtagNumberinstead of decoding it by hand. - Breaking: the
Asn1Valueconstructor is now private; values are produced byAsn1Reader. - The DER reader is now backed by BoringSSL's
CBSparser:- Tag/length parsing uses
CBS_get_any_asn1_element. asObjectIdentifier()usesCBS_asn1_oid_to_text.asInteger()usesCBS_is_valid_asn1_integerwithBN_bin2bn/BN_bn2dec.asBoolean()usesCBS_get_asn1_bool.asString()usesASN1_STRING_to_UTF8, which correctly transcodes every ASN.1 string type BoringSSL supports.Asn1TagandAsn1Classnow re-export BoringSSL'sCBS_ASN1_*constants.- As a result, DER encoding rules are enforced by BoringSSL: non-minimal
long-form lengths and non-minimal
INTEGERencodings are now rejected.
- Tag/length parsing uses
Asn1Value.asString()accepts an optionalstringTypefor IMPLICIT context-specific tags, where the tag number identifies theCHOICEalternative rather than the underlying string type.- Certificate validity times are parsed with
ASN1_TIME_to_posixinstead of slicing theGeneralizedTimestring in Dart. - Fixed
X509Extension.stringValuemangling non-ASCII values in the raw (non-DER) fallback path, which decoded UTF-8 bytes as UTF-16 code units. - Internal: the repeated FFI marshalling patterns are now shared combinators
(
withResource,withOutputBuffer,withSizedOutput,takeOwnedString,withMemBioString,withMemBufBio), removing every hand-writtentry/finallyaround a BoringSSLX_new/X_freepair and the duplicated BIO-to-string reader. This also fixes a latent bug in that reader, which decoded UTF-8 in fixed 1 KiB chunks and could split a multi-byte sequence across a chunk boundary.
0.2.0 #
- Added a minimal ASN.1 DER reader (
package:boring/asn1.dart) for decoding the application-specific payloads of X.509 extensions:Asn1Reader,Asn1Value,Asn1Class,Asn1Tag, andAsn1Exception.- Decodes strings, integers, booleans, object identifiers, and nested constructed elements, including long-form lengths and context-specific tags.
- Added X.509 v3 extension support to
X509Certificate:extensionsenumerates every extension with its OID, short name, criticality, and raw DER payload.getExtension(oid)andgetExtensionString(oid)look up an extension by dotted-decimal OID, transparently unwrapping DER-encoded ASN.1 strings and falling back to raw UTF-8 payloads.subjectAlternativeNamesandissuerAlternativeNamesdecodeGeneralNameentries, withemailAddresses,dnsNames, andurisconvenience getters.keyUsage,extendedKeyUsage,isCertificateAuthority, andsubjectKeyIdentifier.
- Added
X509Oidconstants for standard X.509 extensions, Certificate Transparency SCTs, and all Sigstore Fulcio OIDC extensions (1.3.6.1.4.1.57264.1.*), plusKeyUsagebit constants. - Added a Project Wycheproof conformance test suite (
tool/run_conformance_tests.sh) covering AEAD, Ed25519, ECDSA, RSA, HKDF, and HMAC. - Added GitHub Actions CI running formatting, analysis, unit tests, and the conformance suite.
0.1.0 #
- Initial release of
package:boring. - High-performance cryptography and PKI powered by BoringSSL with Dart Native Assets.
- Isolated symbols with
bssl_dartprefix to guarantee 100% collision-free execution alongside Flutter and Dart VM internal BoringSSL. - Cryptographic primitives:
- CSPRNG (
BoringRand.secureRandom) - Digests (
BoringDigest: SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, streamingDigestContext) - HMAC (
BoringHmac: SHA-256, SHA-384, SHA-512, streamingHmacContext) - HKDF (
BoringHkdf: extract, expand, deriveBits) - AEAD (
BoringAead: AES-128-GCM, AES-256-GCM, ChaCha20-Poly1305, XChaCha20-Poly1305) - Ed25519 (
BoringEd25519: keypair generation, sign, verify) - Asymmetric Keys (
BoringPrivateKey,BoringPublicKey: RSA, ECDSA P-256/P-384/P-521, PKCS#8 & SPKI DER/PEM)
- CSPRNG (
- PKI & X.509:
- Certificate parsing (
X509Certificate: DER and PEM, metadata getters, public key extraction) - Chain verification (
X509Verifier: trust store management, intermediate chain resolution, time-based verification)
- Certificate parsing (