Skip to content

feat: add Ed25519 signature verification for website activation - #742

Closed
logbie wants to merge 5 commits into
mainfrom
cursor/ed25519-verify-c45d
Closed

logbie wants to merge 5 commits into
mainfrom
cursor/ed25519-verify-c45d

Conversation

@logbie

@logbie logbie commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Adds a small WFL public-key verifier so the Logbie website can later activate licences offline, without changing current HMAC licensing.

Why

The website’s existing keys are LOGBIE-<id>-<HMAC-SHA256>. That path stays online and secret-keyed. Future activation needs RFC 8032 Ed25519 verification in the same runtime the site already runs. WFL had no public-key primitive.

Contract

Resolved in Engineering/designs/2026-09-21-ed25519-verify.md before the implementation:

  • Algorithm: Ed25519 (RFC 8032) via ed25519-dalek 2.2
  • Public key: 32 bytes as 64 hex characters
  • Signature: 64 bytes as 128 hex characters
  • Signed bytes: UTF-8 of the WFL message text
  • ed25519_verify of public_key and message and signature → yes / no
  • Malformed or unsupported encodings fail closed with diagnostics that do not echo inputs
  • Message cap: 1 MiB

Test evidence

  • Risk class: R3 (crypto, untrusted input, backward compatibility)
  • Acceptance criteria → tests: RFC 8032 TEST 1/2 through WFL, TEST 3 at the byte helper, tampered message, wrong key, truncated/malformed/unsupported formats, oversized message, website-shaped WFL call
  • Red evidence: test-only ancestor 98f6d5ab; cargo test --test crypto_ed25519_verify_test failed with Undefined variable 'ed25519_verify' (8 failed / 9 passed). Record: Engineering/evidence/2026-09-21-ed25519-verify-red.md
  • Unit/component: cargo test --lib builtins::tests — 4 passed
  • Integration/contract: crypto_ed25519_verify_test 18 passed; new-builtin compatibility 19 passed; existing sha256/hmac_sha256 9 passed
  • End-to-end: target/release/wfl --test TestPrograms/crypto_ed25519_verify_test.wfl — 7 passed, exit 0; TestPrograms/crypto_standard_test.wfl still 7/0
  • Website runtime: reproduced Logbie license_test.wfl (8/8) and checkout_test.wfl (6/6) plus a website-shaped verifier call (1/1) against this release binary. Full website/scripts/test.sh (Scriptorium smoke) was not run — LogbieLLC/logbie is private and not in this environment
  • Pushed-revision CI: implementation head f85745a6; run 35575701421 — 18 successful, 0 failed, 1 skipped (version bump). Linux and Windows integration, fuzz compile, hygiene, fmt/clippy/test, and both Run WFL Programs matrices passed. Current head ba6ee0ab only adds that CI record.
  • Security/other: fail-closed format errors; no key/signature echo; SECURITY_SENSITIVE_BUILTINS includes ed25519_verify
  • Coverage: Rust integration + gated TestPrograms; RFC 8032 TEST 3 is byte-level because af82 is not valid UTF-8
  • Platforms: Linux x86-64 and Windows x86-64 (CI)
  • Not applicable: web-server e2e (no listen/HTTP change); VS Code extension
  • Rollback/recovery: revert the commits; no durable state
  • Residual risk: official website CI still pins WFL 26.9.16 until a release ships this builtin. After that release, bump the website README pin and add tests/ed25519_verify_test.wfl to scripts/test.sh. This PR does not change licence issue/validate or checkout.

Scope

Verification prerequisite only. No activation workflow, no signing API, no HMAC licence changes.

Head: ba6ee0ab.

Open in Web Open in Cursor 

Add RFC 8032 and fail-closed tests for ed25519_verify before the
runtime builtin exists. Record the Red cargo-test result
(Undefined variable 'ed25519_verify') and the resolved signing
contract for later activation work.

Co-authored-by: logbie <logbie@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

cursoragent and others added 4 commits September 21, 2026 07:59
Introduce ed25519_verify of public_key and message and signature,
implemented with ed25519-dalek against RFC 8032. Hex keys and
signatures, UTF-8 message bytes, fail-closed malformed input, and
a 1 MiB message cap. Existing HMAC licensing is unchanged.

Co-authored-by: logbie <logbie@users.noreply.github.com>
Note that official website CI still ships WFL 26.9.16, and record the
HMAC license/checkout suites plus the website-shaped verifier call
run against this branch's release binary.

Co-authored-by: logbie <logbie@users.noreply.github.com>
Note the pushed-revision GitHub Actions run for f85745a, including
Linux and Windows integration and fuzz compile.

Co-authored-by: logbie <logbie@users.noreply.github.com>
@logbie logbie closed this Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants