<feed xmlns='http://www.w3.org/2005/Atom'>
<title>meshbay.git/docs/MESHBAY_NODE_PROTOCOL.md, branch 0.17</title>
<subtitle>MeshBay — read-only public mirror</subtitle>
<id>https://git.meshbay.org/meshbay.git/atom?h=0.17</id>
<link rel='self' href='https://git.meshbay.org/meshbay.git/atom?h=0.17'/>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/'/>
<updated>2026-10-01T11:06:32Z</updated>
<entry>
<title>fix: an MBK2 bundle is opened once and stored again as MBK3</title>
<updated>2026-10-01T11:06:32Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T11:06:32Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=e0905bd447f6214dc34e360554826ace45bde676'/>
<id>urn:sha1:e0905bd447f6214dc34e360554826ace45bde676</id>
<content type='text'>
Transitional. The Argon2 run that makes M makes A, the key MBK2 bundles were
sealed under; a session keeps it as a decrypt-only key (IndexedDB in a browser,
the key storage in the desktop app). A client meeting an MBK2 bundle opens it —
or its recovery copy — and stores the same identity as MBK3 once connected; the
desktop app reseals or withdraws it as browser access says. A session without
A asks for the passphrase once. Older formats stay refused by name. Replaces
the unpin-and-reinvite step the 0.17 flag day required on every node.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(node): one member holds a share of the node, sized past real use</title>
<updated>2026-10-01T08:34:26Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T08:34:26Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=15e117673d2303bf476d4f78699e47913ce1aec0'/>
<id>urn:sha1:15e117673d2303bf476d4f78699e47913ce1aec0</id>
<content type='text'>
128 peer sessions on the node, at most 64 per account (the hub names the
account with each offer; the node's own account is not counted). One account
plays at most half the stream slots, rounded up, and runs two subtitle
extractions at once. Frames after the handshake are 8 MiB (was 64), decoded
with per-container bounds, and a frame refused for either ends the session
instead of jamming its buffer (F-16).

Sized for the heaviest real member: twenty groups on one node, three devices
and a tab, up to 52 sessions. Measured: ~0.15 MiB and one fd per idle session.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>docs: state the pepper's proof, signing by kind and device retirement as they are</title>
<updated>2026-09-30T19:04:39Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-09-30T19:04:39Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=5b0cd92012bb162f6290fbfb97938f41cad81b7a'/>
<id>urn:sha1:5b0cd92012bb162f6290fbfb97938f41cad81b7a</id>
<content type='text'>
Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>docs: state the pepper, MBK3, the desktop keyring and browser access as they are</title>
<updated>2026-09-30T15:26:59Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-09-30T15:26:59Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=d692db441680eef8969573047cf5da00cfb61362'/>
<id>urn:sha1:d692db441680eef8969573047cf5da00cfb61362</id>
<content type='text'>
Design §2.2-§3.7, §4, §5.6, §7.7, §8, §9.10 and the registers; protocol §7,
§7.1, §7.1a and §13; the user guide; CLAUDE.md's parity rule.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>docs: state hosting, invitations, the roster check and link previews as they are</title>
<updated>2026-09-30T10:00:58Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-09-30T10:00:58Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=1684fcb64531eaf2e9bb8567ba4bdcbada6469d8'/>
<id>urn:sha1:1684fcb64531eaf2e9bb8567ba4bdcbada6469d8</id>
<content type='text'>
Present-tense statements of what holds, in place of before/after phrasing:
host designation (§7.2, AV32), invitations (§3.4, §7.3, AV33), the roster
check at the handshake (§5.2, protocol §6.3), the wrong-code lock (protocol
§8.3), and what the link-preview gate does and does not refuse (§6.5).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(node): the roster, not the key alone, decides who gets a session</title>
<updated>2026-09-30T09:57:03Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-09-30T09:57:03Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=5612dbbac41609b3f84784f57f1de538262db9a9'/>
<id>urn:sha1:5612dbbac41609b3f84784f57f1de538262db9a9</id>
<content type='text'>
The handshake opened a session for anyone holding the group key with a hub
token naming the group; the roster was consulted only when wrapping the key
in a join. A member revoked or unpinned on the node but still a member on
the hub kept a full session with the key they already held — and was handed
the chat epoch their removal had just opened, since chat keys go to any
session. An honest client never met this (it asks for the key through
join_request every time); one that kept the key did not have to.

- After the proof, the node asks the roster and refuses with
  `not_authorized_for_group` unless the account is an active member of the
  group or the node's operator.
- A removal from any door — MNP, the node page, the CLI — now opens a new
  chat epoch in each group the person could read, broadcasts it, and closes
  every connection they hold (`ops.members._after_removal`). The CLI and the
  node page did neither.
- Design §5.2, protocol §6.1, §6.3, §14.2.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix: only the owner decides who hosts a group, and nobody is made a member unasked</title>
<updated>2026-09-30T09:49:56Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-09-30T09:49:56Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=d3ad243c4ae3a273f623bd5fc631e3266aa4d0e4'/>
<id>urn:sha1:d3ad243c4ae3a273f623bd5fc631e3266aa4d0e4</id>
<content type='text'>
- hub: a node may host a group only if its account owns it or the owner
  approved that node (new `group_hosts`). Membership was the ceiling, and
  every member holds the group key, so any member's node could register as a
  host and be the one clients kept. A node claiming a group it may not host
  is recorded as a request; the owner is notified once and approves or
  refuses it (GET/POST/DELETE /v1/groups/{id}/hosts[/{node_id}]), which
  takes effect on a connected node at once.
- hub: an owner adding a username creates an invitation (new
  `group_invitations`), accepted or declined by the invitee
  (/v1/groups/invitations, /{id}/invitation/accept|decline). Until then the
  group is not listed, not dialled, not searched and not in any token.
  Invitation links, open joins and group creation still make members
  directly: they are the account's own act.
- hub: the MNP token names only the group it is minted for (group_id is now
  required), so a node operator no longer learns a member's other groups.
- SPA: invitations on the home page; invited people and host requests in
  the group's settings; the transport sends group_id. Ten catalogues.
- Browser probes for both screens, run in Chrome and Firefox.
- Design §5.2, §7.2, §7.3, AV32, AV33; protocol §6.3; user guide.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix: a member can no longer lock a node, crash it with a link, or stop hub cleanup</title>
<updated>2026-09-30T09:22:24Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-09-30T09:22:24Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=69554fac7eba6eef7eb8a1c0111c5b92e7f21256'/>
<id>urn:sha1:69554fac7eba6eef7eb8a1c0111c5b92e7f21256</id>
<content type='text'>
- node: only a wrong code counts towards the join lock, now per account
  (5) as well as node-wide (20), and it is consulted only when a code is
  tried. Every member reconnecting gets the group key through join_request,
  so a lock checked before recognition let one member refuse it to everyone.
- node: link previews read the body as a stream and stop at the cap,
  counted on decoded bytes; a declared oversized image is not read; 15 s
  total deadline; image decoding off the loop. `client.get` had buffered
  the whole (decompressed) response before the caps looked at it.
- hub: the daily purge of never-verified accounts detaches their IP-log
  rows (keeping the name) and clears every other reference first, and each
  cleanup step runs on its own. On PostgreSQL the bare DELETE violated the
  ip_logs foreign key and stopped every purge behind it for good.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>refactor(node): remove five loopback routes nothing called</title>
<updated>2026-09-28T20:47:23Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-09-28T20:47:23Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=6bb2fa48ef13e0630e155565c4c0e046de03a1a1'/>
<id>urn:sha1:6bb2fa48ef13e0630e155565c4c0e046de03a1a1</id>
<content type='text'>
The group-setting routes for app directories, chat directory, link
previews, Search listing and scan settings had no caller and no test;
those settings are signed MNP operations only.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>docs: keypair_bundle_delete is reserved for device_policy (O3)</title>
<updated>2026-09-28T20:39:05Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-09-28T20:39:05Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=215864bf655f7dcb793e80c836598655d6d945a9'/>
<id>urn:sha1:215864bf655f7dcb793e80c836598655d6d945a9</id>
<content type='text'>
The node honours it and no interface sends it; offered alone it would
strand the next browser that signs in. Stated in both documents.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
</feed>
