Skip to content

Record the 1.0.x changes and the 0.8.1 release in the CHANGELOG - #199

Merged
TheStormN merged 1 commit into
cisco:mainfrom
OpenIDC:changelog-1.0.0
Sep 15, 2026
Merged

TheStormN merged 1 commit into
cisco:mainfrom
OpenIDC:changelog-1.0.0

Conversation

@zandbelt

Copy link
Copy Markdown
Contributor

Summary

Follow-up to your comment on #198. Documentation only, no code.

The README already covers ML-DSA

#198 updated it: the JWS alg table has the ML-DSA-44, ML-DSA-65, ML-DSA-87 row with build option CJOSE_ENABLE_ML_DSA, OpenSSL >= 3.5, the JWK kty table has the AKP row with the same requirement, the build options table has CJOSE_ENABLE_ML_DSA, and a paragraph says the algorithms are pure ML-DSA with the empty context string and that HashML-DSA is not offered.

The one place that did not mention it is Prerequisites → Libraries, which said OpenSSL >= 3.0.0 and nothing more. That line now names the 3.5 requirement and points at the build option. It is the only README change here.

The CHANGELOG had a larger gap than ML-DSA

The 1.0.0 (unreleased) section held only the Breaking list that #187 wrote. Nothing merged after it had an entry — not ML-DSA, and not the nine PRs before it:

#185 PBES2-HS256+A128KW, PBES2-HS384+A192KW, PBES2-HS512+A256KW
#186 X25519 and X448 ECDH-ES, the epk private-member refusal, the EC d refusal
#188 A128GCMKW, A192GCMKW, A256GCMKW; the crit refusal; JWE header disjointness
#189, #190, #192, #193 the RSA JWK import refusals
#191 the NULL cjose_err crash in ECDH-ES+A*KW decryption
#196 EVP_Q_mac for HMAC
#198 ML-DSA-44/65/87 and the AKP key type

All of them are now recorded under Update and Fix. The entries reference pull requests, which is what the Breaking list of that section already does, rather than the commit links the released sections use. Nothing in the released sections is touched — the diff is 51 added lines and no deletions.

Classification. The crit refusal is under Breaking: it refuses a JWE or JWS that 0.8.0 accepted. Three more rules refuse input or calls that 0.8.0 accepted without changing the API, so they stay under Fix and a short Compatibility paragraph names them — the disjointness of the header locations, the refusal of a header parameter the algorithm generates, and the refusal of a valueless private member. That mirrors how the 0.8.1 notes handled the same rules.

0.8.1 was missing from this file entirely

You released 0.8.1 from the 0.8.x branch on 2026-09-14, and its section only ever existed on that branch. On main the file jumped from the unreleased 1.0.0 straight to 0.8.0, so a released version was invisible in the release notes. Its section is copied over unchanged, including the autotools test-build fix, which describes what 0.8.1 shipped rather than what main has.

Comparing the two also turned up an entry the 1.0.0 list would otherwise have missed: the EC d refusal, which 0.8.1 lists separately and which main got in #186 rather than with the RSA members in #189.

Testing

No code changes, so nothing to build or run. Verified instead that every entry is true of the tree at 8d1afeb: each function, macro, build option, header parameter and error code exists with that spelling, each behavioural claim matches the end state rather than an intermediate commit of a multi-commit PR (#188 scoped crit per algorithm family before refusing it outright; #185 changed how p2s is handled), and each PR attribution matches the commit that introduced the behaviour.

🤖 Generated with Claude Code

The 1.0.0 section carried only the Breaking list that cisco#187 wrote, so nothing
merged after it was recorded: the A*GCMKW, PBES2, X25519/X448 and ML-DSA
algorithms, the "crit" refusal and the JWE header disjointness, the JWK import
refusals of cisco#189, cisco#190, cisco#192 and cisco#193, the NULL cjose_err crash of cisco#191 and the
EVP_Q_mac change of cisco#196. The entries reference pull requests, as the rest of
that section does, rather than the commit links the released sections use.

The "crit" refusal is listed as breaking because it refuses a JWE or JWS that
0.8.0 accepted. Three more rules do the same without changing the API, so they
stay under Fix and a Compatibility paragraph names them, the way the 0.8.1
notes do: the disjointness of the header locations, the refusal of a header
parameter the algorithm generates, and the refusal of a valueless private
member in an RSA or EC key.

0.8.1 was released from the 0.8.x branch on 2026-09-14 and its section only
ever existed there, so this file jumped from the unreleased 1.0.0 straight to
0.8.0 and the release was invisible here. It is copied over unchanged.

The README already describes the ML-DSA algorithms, the AKP key type and the
CJOSE_ENABLE_ML_DSA option; the only thing missing was the OpenSSL requirement
in the prerequisites, which named 3.0.0 alone.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Hans Zandbelt <hans.zandbelt@openidc.com>
@TheStormN
TheStormN merged commit d3d9887 into cisco:main Sep 15, 2026
27 checks passed
@TheStormN

Copy link
Copy Markdown
Contributor

Thanks!

@zandbelt
zandbelt deleted the changelog-1.0.0 branch September 15, 2026 14:12
TheStormN pushed a commit that referenced this pull request Sep 15, 2026
Three sentences #199 added describe the 0.8.x line or an earlier commit
rather than what main does, found by a review of the merged text against
the source at 0.8.0 and at each pull request.

The generated-parameter entry said the check for a caller-supplied "epk" had
read it as a string and so never saw one. That defect existed only on the
0.8.x backport, whose 0.8.1 notes the sentence was taken from; on main the
helper has looked the parameter up as JSON since #188 introduced it. What
0.8.0 did on main was silently replace a protected "epk" with the generated
one, and leave one in the shared or a per-recipient header beside it.

The RSA private-member entry gave "imported as a public key" as the outcome
for every valueless form. That is true of an empty, null or padding-only
member (#189, #192) but not of a zero one (#193), which imported as a private
key whose export cjose could not read back, as the 0.8.1 section below it
already says.

The Compatibility paragraph counted three rules that refuse input 0.8.0
accepted and missed two: the "oth" refusal of #190, since 0.8.0 knew no such
member and imported a multi-prime key as a two-prime one, and the refusal of
an "epk" naming a private member of #186. It also listed "iv", "tag" and
"p2s" as if 0.8.0 had accepted them, when the algorithms that use them are
new in this release. The paragraph now names the rules without counting them.

Signed-off-by: Hans Zandbelt <hans.zandbelt@openidc.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants