pqtransport 0.1.0
pqtransport: ^0.1.0 copied to clipboard
Pure-Dart post-quantum transport: UDP, TLS 1.3 hybrid (X25519MLKEM768 / SecP256r1MLKEM768 / SecP384r1MLKEM1024), DNS/DoH/DoT, mDNS, QUIC, HTTP/1.1–3.
0.1.0 #
Added #
-
IANA
TLS_AES_256_GCM_SHA384(0x1302) on the wire (OPEN-02). The TLS schedule is HKDF-SHA-384. Finished verify_data is 48 bytes. Private-use0xFF00is retired (0.1.0 unpublished). -
IANA
TLS_CHACHA20_POLY1305_SHA256(0x1303) (OPEN-13). Client offers0x1302then0x1303. Server prefers0x1302. ChaCha records call pqforgechacha20Poly1305Encrypt/DecryptthroughPqTransportCrypto. -
TlsCipherSuitebinds Hash and AEAD.TransportAeadselects AES-GCM or ChaCha. UDP stays AES-256-GCM. -
Live SecP256r1MLKEM768 and SecP384r1MLKEM1024 TLS and encrypted-UDP handshakes via pqforge 0.4.4 P-256 / P-384 ECDH (
PqTransportCrypto.p256*/p384*/classicalKeyGen/classicalAgree). NIST groups no longer fail-closed. -
PqTransportCrypto.requireGroup— refusesPqForgeProfile.maximumwith ML-KEM-768 groups andbalanced/compactwith SecP384r1MLKEM1024 (OPEN-03). -
PqKemPrimitives.checkEncapsulationKeybefore encapsulate; a bad modulus isillegal_parameterwithout catching pqcrypto (BLK-05). -
PqTlsSocketacceptsHybridGroup. -
RFC 8446-shaped ClientHello / ServerHello:
legacy_version0x0303,legacy_session_id,cipher_suites,legacy_compression_methods, extensionssupported_versions,supported_groups,key_share,signature_algorithms, SNI, ALPN (OPEN-01). Compact 0.1 hello body is retired (0.1.0 unpublished). Cipher on the wire is IANA0x1302/0x1303(OPEN-02, OPEN-13). Private-use0xFF00is refused. -
EncryptedExtensions is a real extensions vector carrying RFC 7250
server_certificate_type = RawPublicKey(OPEN-04). Certificate payload is still raw ML-DSA-65, but the raw-pk path is negotiated, not silent. ClientHello offers the same type. Not X.509. -
HelloRetryRequest on the wire (OPEN-05):
randomis SHA-256("HelloRetryRequest"),key_shareisselected_grouponly, cookie extension 44 is required. Client echoes the cookie on ClientHello2 and the transcript uses the RFC 8446 §4.4.1message_hashwrapper. Once-only machine edge kept. Same-group handshakes do not emit HRR. -
DNS rdata name compression into the outer message (OPEN-08). CNAME / NS / PTR / MX / SRV / HTTPS / SVCB names that are RFC 1035 pointers are resolved against the full datagram. A truncated rdata name cannot consume the next RR. Our encoder still emits uncompressed names.
-
PqDatagramChannel.joinMulticast/leaveMulticast(OPEN-09).IoDatagramChannelcallsRawDatagramSocket.joinMulticaston224.0.0.251/ff02::fb(TTL 255 for mDNS). Memory channels record membership so flood delivery only hits sockets that joined.PqMdnsClient.browseandPqMdnsServer.beginProbejoin both families (joinMdnsGroups).beginProbeis nowFuture. Browsers still have no raw UDP (LIM-04).
Changed #
- Floor is pqforge ^0.4.5. Sync ChaCha20-Poly1305 uses that package's
Dart engine (
DartChacha20.poly1305Aead), so IANA0x1303completes on dart2js as well as the VM and dart2wasm. Default ClientHello always offers[0x1302, 0x1303]. The dart2js protocol guard (transportHasFullWidthInteger,chachaUnavailableMessage,TlsCipherSuite.select(chachaOk:),tlsOfferedCipherSuitesForRuntime) is deleted — capability isPqSymmetricPrimitives.supportsChaCha20Poly1305(alwaystrue). Do not wrap a PointyCastlePlatformExceptionaskex. - TLS default Hash is SHA-384. SHA-256 remains for UDP HKDF and for the
ChaCha suite (
0x1303). hkdfExtract/hkdfExpandnow call pqforge RFC 5869 SHA-256 helpers (local HMAC loop deleted). Expand-Label stays in TLS. RFC 5869 A.1 pin unchanged (BLK-02 SHA-256 half).combineSharedSecretusesPqForgeCombiner.concatenateSharedSecretsafter length / all-zero checks. TLS still does not callcombine()(BLK-04).PqEncryptedUdpSocket.completeInitiateparameter renamedresponderClassicalPublic(0.1.0 is unpublished).PqEncryptedUdpSocket.initiate/acceptno longer take unusedrolenamed args (OPEN-11). Putting a role string in HKDF extra would desynchronise peers; the info string stays"pqtransport udp-session v1|udp".- Tag
vX.Y.Znow publishes to pub.dev via GitHub Actions OIDC (.github/workflows/publish.yml, environmentpub.dev), matching pqforge. The GitHub Release workflow no longer treats pub.dev as a manual step. First package upload is still a one-time maintainerdart pub publishbecause pub.dev only enables automated publishing after the package exists.
Tests #
- Live P-256 / P-384 TLS and encrypted-UDP handshakes,
requireGrouprefuse tests, modulus-corrupted ek →illegal_parameter, concat pins against pqforgeconcatenateSharedSecrets. RFC 8446 hello structural tests. HelloRetryRequest flight, cookie echo, second-HRR fail-closed, live - Live
0x1302and0x1303handshakes on VM and dart2js (no platform branch). RFC 8439 §2.8.2 pin throughPqTransportCrypto. Leftover DNS/UDP/TLS error paths (OPEN-12). Foreign-message rdata compression pointers (OPEN-08).joinMulticastIO loopback + memory membership (OPEN-09).
Baseline release surface #
Added
- Core length contracts and RFC 10024 hybrid share encode/decode/combine for X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024.
PqUdpSocket,PqDatagramAEAD codec, replay window (sequence peek before AEAD),PqEncryptedUdpSocket(X25519MLKEM768 session).PqTlsClient/PqTlsServer/PqTlsSocketwith swissarmyknifeStateMachine, ML-DSA-65 CertificateVerify, Finished MAC, TLS exporter, handshake vs application record epochs.- DNS wire codec for A, AAAA, CNAME, MX, TXT, SRV, CAA, HTTPS, SVCB, OPT, PTR,
NS;
PqDnsClientwithCircuitBreaker+ TTLCache; DoH/DoT helpers. PqMdnsClient/PqMdnsServerplus optional ML-DSA-65 TXT signatures.- QUIC 1-RTT packet protect, CRYPTO/STREAM frames, flow control.
- HTTP/1.1 encoder/decoder and HTTP/3 frames;
PqHttpClient.roundTripH1over a completedPqTlsSocket. - In-memory
MemoryByteSocket/MemoryDatagramNetwork(multicast flood on 224.0.0.251 / ff02::fb) so the stack is easy to consume in tests.
Tests
- Analyzer clean.
dart testcovers hybrid concat (all three groups), AEAD round-trip, replay-before-open, TLS machines, live X25519MLKEM768 handshake, HTTP/1.1 GET over mock TLS, DNS circuit-breaker + TTL cache, mDNS probe/announce/browse, ML-DSA-65 TXT, QUIC CRYPTO frames carrying the 1216-byte share, anddart:ioUDP bind.
Limits (honest)
- No OpenSSL interop fixture yet. Wording is RFC 10024-aligned encoding with unit-tested concatenation, not "interoperable with OpenSSL".
- No FIPS 140 module validation claim. Best-effort zeroization only.
- TLS schedule in the initial 0.1.0 snapshot was HKDF-SHA-256; this release
records the IANA
0x1302/0x1303update above. - QUIC is 1-RTT packet protect + frames, not a full RFC 9000 stack.
- HTTP/3 is frames, not QPACK.