mirror of
https://github.com/permissionlesstech/bitchat.git
synced 2026-07-26 14:45:22 +00:00
Split-out safe half of #1437 (the kind-1402 wire migration stays held for Android coordination). Docs (README/WHITEPAPER/PRIVACY_POLICY/privacy-assessment) now describe the actual proprietary DM construction — kind 1059 gift wrap carrying XChaCha20-Poly1305 with a 24-byte nonce, base64url v2: framing, and an HKDF that borrows the nip44-v2 info label but is not the NIP-44 key schedule — instead of claiming NIP-17/44/59. Hardens the existing legacy inbound path: 64 KiB ciphertext cap before decode (~46x the largest producible legacy envelope), outer kind/recipient-tag/signature binding, tagless kind-13 seal binding, unsigned kind-14 inner binding, inner tags restricted to the two shapes deployed clients emit (verified against every historical iOS release and a fixture frozen from Android production), SecRandomCopyBytes failure now throws, non-UTF-8 plaintext now throws instead of returning empty. Adds frozen cross-platform fixtures with hash-pinned generators; interop-reviewed with no rejection surface for deployed clients.
75 lines
2.5 KiB
Swift
75 lines
2.5 KiB
Swift
// swift-tools-version: 5.9
|
|
|
|
import PackageDescription
|
|
|
|
let package = Package(
|
|
name: "bitchat",
|
|
defaultLocalization: "en",
|
|
platforms: [
|
|
.iOS(.v16),
|
|
.macOS(.v13)
|
|
],
|
|
products: [
|
|
.executable(
|
|
name: "bitchat",
|
|
targets: ["bitchat"]
|
|
)
|
|
],
|
|
dependencies: [
|
|
.package(path: "localPackages/Arti"),
|
|
.package(path: "localPackages/BitFoundation"),
|
|
.package(path: "localPackages/BitLogger"),
|
|
.package(url: "https://github.com/21-DOT-DEV/swift-secp256k1", exact: "0.21.1")
|
|
],
|
|
targets: [
|
|
.executableTarget(
|
|
name: "bitchat",
|
|
dependencies: [
|
|
.product(name: "P256K", package: "swift-secp256k1"),
|
|
.product(name: "BitFoundation", package: "BitFoundation"),
|
|
.product(name: "BitLogger", package: "BitLogger"),
|
|
.product(name: "Tor", package: "Arti")
|
|
],
|
|
path: "bitchat",
|
|
exclude: [
|
|
"Info.plist",
|
|
"Assets.xcassets",
|
|
"_PreviewHelpers/PreviewAssets.xcassets",
|
|
"bitchat.entitlements",
|
|
"bitchat-macOS.entitlements",
|
|
"LaunchScreen.storyboard",
|
|
"ViewModels/Extensions/README.md"
|
|
],
|
|
resources: [
|
|
.process("Localizable.xcstrings")
|
|
]
|
|
),
|
|
.testTarget(
|
|
name: "bitchatTests",
|
|
dependencies: [
|
|
"bitchat",
|
|
.product(name: "BitFoundation", package: "BitFoundation")
|
|
],
|
|
path: "bitchatTests",
|
|
exclude: [
|
|
"Info.plist",
|
|
"README.md",
|
|
// CI perf gate data (read by scripts/check-perf-floors.sh),
|
|
// not a test resource.
|
|
"Performance/perf-floors.json"
|
|
],
|
|
resources: [
|
|
.process("Localization"),
|
|
// Only the vector fixture: declaring the whole "Noise"
|
|
// directory would claim its .swift test files as resources
|
|
// and silently drop them from compilation.
|
|
.process("Noise/NoiseTestVectors.json"),
|
|
// Frozen envelopes produced by the released iOS (733098bb)
|
|
// and Android (b7f0b33d) private-DM implementations; prove
|
|
// receive compatibility independently of the local generator.
|
|
.process("Nostr/Fixtures")
|
|
]
|
|
)
|
|
]
|
|
)
|