<feed xmlns='http://www.w3.org/2005/Atom'>
<title>meshbay.git/docs/MESHBAY_DESIGN.md, branch 0.17</title>
<subtitle>MeshBay — read-only public mirror</subtitle>
<id>https://git.meshbay.org/meshbay.git/atom?h=0.17</id>
<link rel='self' href='https://git.meshbay.org/meshbay.git/atom?h=0.17'/>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/'/>
<updated>2026-10-01T13:52:08Z</updated>
<entry>
<title>fix(client): rotating a group key asks nothing</title>
<updated>2026-10-01T13:52:08Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T13:52:08Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=fcac9dcb6ba0ad346a754c7b9e7c59d38b64a4e8'/>
<id>urn:sha1:fcac9dcb6ba0ad346a754c7b9e7c59d38b64a4e8</id>
<content type='text'>
Rotation narrows rather than widens: members still connected receive the
new key, and nothing already shared changes.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(client): hosting a group asks nothing when its folder came from the picker</title>
<updated>2026-10-01T13:49:42Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T13:49:42Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=a64fe23de95f1495a831a1595b398fdd6149097e'/>
<id>urn:sha1:a64fe23de95f1495a831a1595b398fdd6149097e</id>
<content type='text'>
The folder chosen in the native picker is the consent; the dialog that
followed on every group creation asked the same thing twice.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(hub): a username is unique whatever its case</title>
<updated>2026-10-01T11:37:38Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T11:37:38Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=7ca80a47dd8ff529951f59ef586c511e4debb057'/>
<id>urn:sha1:7ca80a47dd8ff529951f59ef586c511e4debb057</id>
<content type='text'>
Registration refuses a name that differs from an existing one only by case;
accounts that already do keep their names, and a pending retry needs the exact
name (F-26).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(hub): what an offer or a node message costs the hub is bounded</title>
<updated>2026-10-01T11:37:38Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T11:37:38Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=aeec8ee7c9e39704433d93c82fafc0f5721d6fbf'/>
<id>urn:sha1:aeec8ee7c9e39704433d93c82fafc0f5721d6fbf</id>
<content type='text'>
An offer's IP-log row (kept a year) was written before any check, for any
string named as a node; it is written once the offer goes to a node. The ICE
list is capped (64 candidates, 32 KiB). A node's update_groups, a database read
each, is budgeted like chat_notify and claims at most 1000 groups (F-22).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(node): the reaper deletes only the .part files the node wrote</title>
<updated>2026-10-01T11:24:11Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T11:24:11Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=1d6189b6e6db7d0d6c126717b081901c5f552174'/>
<id>urn:sha1:1d6189b6e6db7d0d6c126717b081901c5f552174</id>
<content type='text'>
Any *.part older than a day in a writable root was deleted — a browser's
download in progress in a shared folder included. Only names carrying the
node's tag (name.&lt;8 hex&gt;.part) are reaped now (F-28).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(node): a revoked account is disconnected, not only refused next time</title>
<updated>2026-10-01T11:24:11Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T11:24:11Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=f0019e366fef813b22d2d55cf7604e20f0a08707'/>
<id>urn:sha1:f0019e366fef813b22d2d55cf7604e20f0a08707</id>
<content type='text'>
A user revocation closed nothing: the denylist stopped the next connection and
left the live ones streaming and chatting. Revocations now go through one
method that closes the account's or the group's sessions (F-21).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix: an MBK2 bundle is opened once and stored again as MBK3</title>
<updated>2026-10-01T11:06:32Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T11:06:32Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=e0905bd447f6214dc34e360554826ace45bde676'/>
<id>urn:sha1:e0905bd447f6214dc34e360554826ace45bde676</id>
<content type='text'>
Transitional. The Argon2 run that makes M makes A, the key MBK2 bundles were
sealed under; a session keeps it as a decrypt-only key (IndexedDB in a browser,
the key storage in the desktop app). A client meeting an MBK2 bundle opens it —
or its recovery copy — and stores the same identity as MBK3 once connected; the
desktop app reseals or withdraws it as browser access says. A session without
A asks for the passphrase once. Older formats stay refused by name. Replaces
the unpin-and-reinvite step the 0.17 flag day required on every node.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>docs: chat at rest is protected from a copy without the unlock key, not from a disk</title>
<updated>2026-10-01T10:05:12Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T10:05:12Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=0d9d91eeea9001ea3838272416e3d526b6a2a1fc'/>
<id>urn:sha1:0d9d91eeea9001ea3838272416e3d526b6a2a1fc</id>
<content type='text'>
unlock.key sits beside keystore.enc by default, so a whole disk, an image or a
home-directory backup opens the stored chat. The claims table, §4.5 and the
user guide say so and name what protects those: disk encryption, or the unlock
key on other storage (F-20).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix: downloads are marked and keep their extension; Explorer files are refused</title>
<updated>2026-10-01T09:47:39Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T09:47:39Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=760ac421b1944cd69a80e3a92127a1a966f15938'/>
<id>urn:sha1:760ac421b1944cd69a80e3a92127a1a966f15938</id>
<content type='text'>
The desktop app writes the Mark-of-the-Web on each file it saves on Windows, as
a browser does. Bidirectional controls are reserved characters in a saved name
(portable-name.js and paths.sanitize_for_download, and again in the main
process), so a name cannot display one extension and carry another. The node
refuses uploads of files Windows Explorer acts on by itself: desktop.ini,
.lnk, .url, .scf, .library-ms, .searchConnector-ms (F-19).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(node): one member holds a share of the node, sized past real use</title>
<updated>2026-10-01T08:34:26Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T08:34:26Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=15e117673d2303bf476d4f78699e47913ce1aec0'/>
<id>urn:sha1:15e117673d2303bf476d4f78699e47913ce1aec0</id>
<content type='text'>
128 peer sessions on the node, at most 64 per account (the hub names the
account with each offer; the node's own account is not counted). One account
plays at most half the stream slots, rounded up, and runs two subtitle
extractions at once. Frames after the handshake are 8 MiB (was 64), decoded
with per-container bounds, and a frame refused for either ends the session
instead of jamming its buffer (F-16).

Sized for the heaviest real member: twenty groups on one node, three devices
and a tab, up to 52 sessions. Measured: ~0.15 MiB and one fd per idle session.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
</feed>
