Commit Graph

4 Commits

Author SHA1 Message Date
a44164a6f5 The age commands: pub, priv, encrypt and decrypt (closes #3)
All checks were successful
check / check (push) Successful in 2m38s
The application number is 657169, so the path is
m/83696968'/657169'/<n>'. The 32 derived bytes are clamped the way
X25519 requires and go through bech32 into an age identity, the only
route age offers from raw bytes to a key; these are the steps
sneak/secret takes in its agehd package. A test fixes the secret key
the example mnemonic gives at index 0, so a change to any of those
steps is caught.

The derived recipient is always first, so the mnemonic that encrypted
a file can read it back. Decrypting recognises the text form by its
first line, so it needs no flag. A file named with -o is written
beside the target, readable only by its owner, and renamed into place
once the work succeeds, so a refused decryption leaves what was
already there untouched.

Model: opus-5
2026-09-07 16:10:34 +00:00
d69bed722a The mnemonic command: child mnemonics (closes #4)
All checks were successful
check / check (push) Successful in 4s
keyfunc mnemonic derives a 12, 18 or 24 word child mnemonic through BIP-85's own mnemonic application, with the specification's test vectors as tests. One review round, passed with no findings; the reviewer reproduced the vectors from an implementation written from the specification alone.

Model: opus-5 (implementation and review); fable-5-1 (landing)
2026-09-07 18:05:08 +02:00
279cba6bcf Skeleton, mnemonic input, derivation, and the ssh pub and priv commands (closes #1)
All checks were successful
check / check (push) Successful in 5s
The module, the script entrypoints and Makefile, Docker-only linting, the mnemonic sources in the specified order with their refusals, the BIP-85 derivation, and keyfunc ssh pub and priv with the README test vectors as tests. Two review rounds; the second passed with no findings.

Model: opus-5 (implementation and review); fable-5-1 (landing)
2026-09-07 17:34:54 +02:00
clawbot
c3fd26a1de keyfunc: the specification
The README is the specification sneak approved on 2026-09-07, moved
here from the hacks repository: deterministic SSH keys, age identities
with encrypt and decrypt, and child mnemonics, all derived from one
BIP-39 mnemonic and stored nowhere.

Model: fable-5-1
2026-09-07 14:27:57 +00:00