reticiulum-specification/tools
Rob cfd0d8249b Re-anchor against RNS 1.2.4 / LXMF 0.9.7 + track upstream distribution shift
Upstream RNS 1.2.4 (2026-05-07) announces it is "probably the last
release that is also published to GitHub" — pip continues until rnpkg
is complete and RNS is self-hosting. All 13 verifiers pass against
1.2.4 / 0.9.7; no wire-format, signing, or protocol behavior changed
between 1.2.0 and 1.2.4, so the changes here are purely currency:

- Pin tools/requirements.txt to rns==1.2.4 / lxmf==0.9.7 so the
  verifier stays reproducible if upstream stops mirroring to PyPI
  before the migration is ready.
- Add an "Upstream distribution shift" watch-list to todo.md (local
  Reticulum node, repo destination hash, rnpkg install/upgrade
  commands, rsg signature verification, mirroring source citations).
- Bump SPEC.md frontmatter and re-anchor ~50 line citations across
  Identity.py, Transport.py, Resource.py, Link.py, Reticulum.py,
  Packet.py, and LXMF/* (Identity.py drift was the heaviest at +13
  to +31 lines; Transport.py was variable). Fix one numeric
  (MAX_RANDOM_BLOBS = 32 → 64) and one semantic (§6.6.3 LRPROOF MTU
  clamp citation pointed at the wrong location — corrected to point
  at the transit-relay clamp at Transport.py:1539-1556).
- Update §10.4 decompression-bomb hazard to note upstream's 1.1.9 cap
  adoption, with citations to Resource.py:686-691 and Buffer.py:95-97
  plus a "do not use one-shot bz2.decompress()" warning.
- Re-anchor 11 flows/ files (version pins + ~30 line citations).
- Bump version labels in tools/README.md, test-vectors/README.md, and
  4 verifier docstrings + 2 hardcoded print strings.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-08 07:42:25 -04:00
..
_gen_toc.py SPEC.md: collapsible ToC + collapse §11.6 NomadNet specifics 2026-05-04 22:05:17 -04:00
README.md Re-anchor against RNS 1.2.4 / LXMF 0.9.7 + track upstream distribution shift 2026-05-08 07:42:25 -04:00
regen_announces.py Bootstrap test-vectors/{announces,lxmf,links}.json + regenerators 2026-05-04 21:56:44 -04:00
regen_identities.py Verify §2.3, §4.3, §7.1, §7.4 against upstream RNS 1.2.0 / LXMF 0.9.6 2026-05-03 10:14:51 -04:00
regen_links.py Bootstrap test-vectors/{announces,lxmf,links}.json + regenerators 2026-05-04 21:56:44 -04:00
regen_lxmf.py Bootstrap test-vectors/{announces,lxmf,links}.json + regenerators 2026-05-04 21:56:44 -04:00
requirements.txt Re-anchor against RNS 1.2.4 / LXMF 0.9.7 + track upstream distribution shift 2026-05-08 07:42:25 -04:00
verify_announce_app_data.py Re-anchor against RNS 1.2.4 / LXMF 0.9.7 + track upstream distribution shift 2026-05-08 07:42:25 -04:00
verify_announce_roundtrip.py Add three high-value verifiers: token crypto, announce, LXMF opportunistic 2026-05-03 12:41:20 -04:00
verify_destination_hash.py Fix and expand §1.3 — on-disk identity format (real spec bug!) 2026-05-03 11:54:54 -04:00
verify_link_handshake.py Add four more verifiers + receive-propagated flow + frontmatter version 2026-05-03 12:54:34 -04:00
verify_lxmf_opportunistic.py Add three high-value verifiers: token crypto, announce, LXMF opportunistic 2026-05-03 12:41:20 -04:00
verify_msgpack_quirk.py Add four more verifiers + receive-propagated flow + frontmatter version 2026-05-03 12:54:34 -04:00
verify_packet_header.py Re-anchor against RNS 1.2.4 / LXMF 0.9.7 + track upstream distribution shift 2026-05-08 07:42:25 -04:00
verify_path_request.py Verify §2.3, §4.3, §7.1, §7.4 against upstream RNS 1.2.0 / LXMF 0.9.6 2026-05-03 10:14:51 -04:00
verify_proof_packet.py Re-anchor against RNS 1.2.4 / LXMF 0.9.7 + track upstream distribution shift 2026-05-08 07:42:25 -04:00
verify_ratchet_dedup.py Resolve issue #1 — five §7.2/§7.3 gaps from clean-room JS implementation 2026-05-03 20:38:01 -04:00
verify_rnode_split.py Add four more verifiers + receive-propagated flow + frontmatter version 2026-05-03 12:54:34 -04:00
verify_stamps.py Add tools/verify_stamps.py — runtime-lock §5.7 2026-05-03 15:13:59 -04:00
verify_token_crypto.py Re-anchor against RNS 1.2.4 / LXMF 0.9.7 + track upstream distribution shift 2026-05-08 07:42:25 -04:00

Verifier scripts

Self-contained Python scripts that test claims in ../SPEC.md against the upstream RNS / LXMF Python stack.

Conventions

  • Each script verifies one claim or one related cluster of claims.
  • Exit code 0 on PASS, non-zero on FAIL.
  • Print a one-line PASS/FAIL summary plus a unified diff or hex dump on mismatch.
  • Reference the SPEC.md section the script verifies in a docstring at the top.

Required environment

pip install rns lxmf

The scripts read RNS.__version__ at startup and print it in their output so a future reader can tell which RNS version a verification ran against.

Status

Populated against RNS 1.2.4 / LXMF 0.9.7:

Script Verifies SPEC.md section Status
verify_destination_hash.py §1.1, §1.2, §1.3 — identity composition, dest_hash = SHA256(name_hash || identity_hash)[:16], on-disk private-key round-trip via to_file/from_file
verify_packet_header.py §2.1, §2.2, §2.3 — flag byte layout, HEADER_1/HEADER_2 form, originator HEADER_1→HEADER_2 conversion via upstream Transport.outbound
verify_token_crypto.py §3 — Token encrypt/decrypt, HKDF salt = identity_hash, HMAC-then-AES order, PKCS#7 padding
verify_announce_app_data.py §4.3 — LXMF announce app_data 2-element form, parser tolerance
verify_announce_roundtrip.py §4.1, §4.2, §4.5 — announce body layout, signature, dest_hash recompute, tamper rejection
verify_lxmf_opportunistic.py §5.1, §5.2, §5.5, §5.6 — full identity → encrypt → decrypt → parse round-trip
verify_proof_packet.py §6.5 — implicit (64B) and explicit (96B) proof body forms, validator length-dispatch
verify_link_handshake.py §6.1, §6.2, §6.3, §6.6 — LINKREQUEST/LRPROOF body order, link_id derivation, signalling
verify_path_request.py §1.2 well-known hashes, §7.1 LXMF path-preamble gating
verify_rnode_split.py §8.3 — RNode air-frame split-packet TX/RX state machines
verify_msgpack_quirk.py §9.3 — encoding name as bytes vs str affects upstream parsing
verify_stamps.py §5.7 — workblock determinism, PoW stamp search/validate, ticket shortcut
verify_ratchet_dedup.py §7.3 / §4.5 step 6.3 — confirms replay defence is keyed on random_blob, NOT on (dest_hash, ratchet_pub)
regen_identities.py regenerates test-vectors/identities.json
regen_announces.py regenerates test-vectors/announces.json (deterministic announce wire bytes, with and without ratchet)
regen_lxmf.py regenerates test-vectors/lxmf.json (deterministic opportunistic-LXMF plaintext + Token ciphertext)
regen_links.py regenerates test-vectors/links.json (deterministic LINKREQUEST + LRPROOF + derived session key)

See ../agent.md §5 and ../todo.md for the remaining priority order.