Format and check markdown with prettier in make fmt and fmt-check (closes #110)
check / check (push) Failing after 3s

script/fmt and script/fmt-check follow the model scripts in the prompts
repo: Go as before, plus prettier over every markdown file with 4-space
tabs and proseWrap always. Prettier is pinned by hash in package.json and
yarn.lock; script/bootstrap now installs node, yarn and prettier. The
Dockerfile lint stage copies node and yarn from a node image pinned by
hash and runs script/bootstrap, so its make fmt-check fails the build on
unformatted markdown. Every markdown file is formatted once; wording is
unchanged (CLAUDE.md's "*" list markers become "-").

Model: opus-5-5
This commit is contained in:
2026-10-04 23:48:03 +00:00
parent 2503f2db96
commit 94b0a831a2
11 changed files with 589 additions and 515 deletions
+45 -28
View File
@@ -1,14 +1,21 @@
# agehd - Deterministic Age Identities from BIP85
The `agehd` package derives deterministic X25519 age identities using BIP85 entropy derivation and a deterministic random number generator (DRNG). This package only supports proper BIP85 sources: BIP39 mnemonics and extended private keys (xprv).
The `agehd` package derives deterministic X25519 age identities using BIP85
entropy derivation and a deterministic random number generator (DRNG). This
package only supports proper BIP85 sources: BIP39 mnemonics and extended private
keys (xprv).
## Features
- **Deterministic key generation**: Same input always produces the same age identity
- **Deterministic key generation**: Same input always produces the same age
identity
- **BIP85 compliance**: Uses the BIP85 standard for entropy derivation
- **Multiple key support**: Generate multiple keys from the same source using different indices
- **Two BIP85 input methods**: Support for BIP39 mnemonics and extended private keys (xprv)
- **Vendor/application scoped**: Uses vendor-specific derivation paths to avoid conflicts
- **Multiple key support**: Generate multiple keys from the same source using
different indices
- **Two BIP85 input methods**: Support for BIP39 mnemonics and extended private
keys (xprv)
- **Vendor/application scoped**: Uses vendor-specific derivation paths to avoid
conflicts
## Derivation Path
@@ -19,6 +26,7 @@ m/83696968'/592366788'/733482323'/n'
```
Where:
- `83696968'` is the BIP85 root path ("bip" in ASCII)
- `592366788'` is the vendor ID (sha256("berlin.sneak") & 0x7fffffff)
- `733482323'` is the application ID (sha256("secret") & 0x7fffffff)
@@ -34,19 +42,19 @@ package main
import (
"fmt"
"log"
"git.eeqj.de/sneak/secret/pkg/agehd"
)
func main() {
mnemonic := "abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon about"
// Derive the first identity (index 0)
identity, err := agehd.DeriveIdentity(mnemonic, 0)
if err != nil {
log.Fatal(err)
}
fmt.Printf("Secret key: %s\n", identity.String())
fmt.Printf("Public key: %s\n", identity.Recipient().String())
}
@@ -60,19 +68,19 @@ package main
import (
"fmt"
"log"
"git.eeqj.de/sneak/secret/pkg/agehd"
)
func main() {
xprv := "xprv9s21ZrQH143K2LBWUUQRFXhucrQqBpKdRRxNVq2zBqsx8HVqFk2uYo8kmbaLLHRdqtQpUm98uKfu3vca1LqdGhUtyoFnCNkfmXRyPXLjbKb"
// Derive the first identity (index 0) from the xprv
identity, err := agehd.DeriveIdentityFromXPRV(xprv, 0)
if err != nil {
log.Fatal(err)
}
fmt.Printf("Secret key: %s\n", identity.String())
fmt.Printf("Public key: %s\n", identity.Recipient().String())
}
@@ -86,20 +94,20 @@ package main
import (
"fmt"
"log"
"git.eeqj.de/sneak/secret/pkg/agehd"
)
func main() {
mnemonic := "abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon about"
// Derive multiple identities with different indices
for i := uint32(0); i < 3; i++ {
identity, err := agehd.DeriveIdentity(mnemonic, i)
if err != nil {
log.Fatal(err)
}
fmt.Printf("Identity %d: %s\n", i, identity.Recipient().String())
}
}
@@ -113,25 +121,25 @@ package main
import (
"fmt"
"log"
"git.eeqj.de/sneak/secret/pkg/agehd"
)
func main() {
mnemonic := "abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon about"
// First derive entropy using BIP85
entropy, err := agehd.DeriveEntropy(mnemonic, 0)
if err != nil {
log.Fatal(err)
}
// Then create identity from entropy
identity, err := agehd.IdentityFromEntropy(entropy)
if err != nil {
log.Fatal(err)
}
fmt.Printf("Secret key: %s\n", identity.String())
fmt.Printf("Public key: %s\n", identity.Recipient().String())
}
@@ -151,7 +159,8 @@ Derives a deterministic age identity from a BIP39 mnemonic and index.
#### `DeriveIdentityFromXPRV(xprv string, n uint32) (*age.X25519Identity, error)`
Derives a deterministic age identity from an extended private key (xprv) and index.
Derives a deterministic age identity from an extended private key (xprv) and
index.
- `xprv`: A valid extended private key in xprv format
- `n`: The derivation index (0, 1, 2, ...)
@@ -167,7 +176,8 @@ Derives 32 bytes of entropy from a BIP39 mnemonic and index using BIP85.
#### `DeriveEntropyFromXPRV(xprv string, n uint32) ([]byte, error)`
Derives 32 bytes of entropy from an extended private key (xprv) and index using BIP85.
Derives 32 bytes of entropy from an extended private key (xprv) and index using
BIP85.
- `xprv`: A valid extended private key in xprv format
- `n`: The derivation index
@@ -182,20 +192,27 @@ Converts 32 bytes of entropy into an age X25519 identity.
## Implementation Details
1. **BIP85 Entropy Derivation**: The package uses the BIP85 standard to derive 64 bytes of entropy from the input source
2. **DRNG**: A BIP85 DRNG (Deterministic Random Number Generator) using SHAKE256 is seeded with the 64-byte entropy
3. **Key Generation**: 32 bytes are read from the DRNG to generate the age private key
4. **RFC-7748 Clamping**: The private key is clamped according to RFC-7748 for X25519
5. **Bech32 Encoding**: The key is encoded using Bech32 with the "age-secret-key-" prefix
1. **BIP85 Entropy Derivation**: The package uses the BIP85 standard to derive
64 bytes of entropy from the input source
2. **DRNG**: A BIP85 DRNG (Deterministic Random Number Generator) using SHAKE256
is seeded with the 64-byte entropy
3. **Key Generation**: 32 bytes are read from the DRNG to generate the age
private key
4. **RFC-7748 Clamping**: The private key is clamped according to RFC-7748 for
X25519
5. **Bech32 Encoding**: The key is encoded using Bech32 with the
"age-secret-key-" prefix
## Security Considerations
- The same mnemonic/xprv and index will always produce the same identity
- Different indices produce cryptographically independent identities
- The vendor/application scoping prevents conflicts with other BIP85 applications
- The vendor/application scoping prevents conflicts with other BIP85
applications
- The DRNG ensures high-quality randomness for key generation
- Private keys are properly clamped for X25519 usage
- Only accepts proper BIP85 sources (mnemonics and xprv keys), not arbitrary passphrases
- Only accepts proper BIP85 sources (mnemonics and xprv keys), not arbitrary
passphrases
## Testing
@@ -203,4 +220,4 @@ Run the tests with:
```bash
go test -v ./internal/agehd
```
```
+17 -10
View File
@@ -1,10 +1,15 @@
# BIP85 - Deterministic Entropy From BIP32 Keychains
This package implements [BIP85](https://github.com/bitcoin/bips/blob/master/bip-0085.mediawiki), which allows for deterministic derivation of entropy from a BIP32 master key. This enables a single seed to generate multiple wallet keys, mnemonics, and random values in a fully deterministic way.
This package implements
[BIP85](https://github.com/bitcoin/bips/blob/master/bip-0085.mediawiki), which
allows for deterministic derivation of entropy from a BIP32 master key. This
enables a single seed to generate multiple wallet keys, mnemonics, and random
values in a fully deterministic way.
## Overview
BIP85 enables a variety of use cases:
- Generate multiple BIP39 mnemonic seeds from a single master key
- Derive Bitcoin HD wallet seeds (WIF format)
- Create extended private keys (XPRV)
@@ -114,15 +119,16 @@ m/83696968'/{app}'/{parameters}
```
Where:
- `83696968'` is the BIP85 root path (BIP in ASCII)
- `{app}'` is the application number:
- `39'` for BIP39 mnemonics
- `2'` for HD-WIF keys
- `32'` for XPRV
- `128169'` for HEX data
- `707764'` for Base64 passwords
- `707785'` for Base85 passwords
- `828365'` for RSA keys
- `39'` for BIP39 mnemonics
- `2'` for HD-WIF keys
- `32'` for XPRV
- `128169'` for HEX data
- `707764'` for Base64 passwords
- `707785'` for Base85 passwords
- `828365'` for RSA keys
- `{parameters}` are application-specific parameters
## Test Vectors
@@ -135,7 +141,8 @@ This implementation passes all the test vectors from the BIP85 specification:
- XPRV
- SHAKE256 DRNG output
The implementation is also compatible with the Python reference implementation's test vectors for the DRNG functionality.
The implementation is also compatible with the Python reference implementation's
test vectors for the DRNG functionality.
Run the tests with verbose output to see the test vectors and results:
@@ -149,4 +156,4 @@ go test -v git.eeqj.de/sneak/secret/pkg/bip85
- [Python Reference Implementation](https://github.com/ethankosakovsky/bip85)
- [Bitcoin Core](https://github.com/bitcoin/bitcoin)
- [BIP32](https://github.com/bitcoin/bips/blob/master/bip-0032.mediawiki)
- [BIP39](https://github.com/bitcoin/bips/blob/master/bip-0039.mediawiki)
- [BIP39](https://github.com/bitcoin/bips/blob/master/bip-0039.mediawiki)