<feed xmlns='http://www.w3.org/2005/Atom'>
<title>meshbay.git/packages/meshbay-node/src/meshbay_node/transport/webrtc, branch 0.17</title>
<subtitle>MeshBay — read-only public mirror</subtitle>
<id>https://git.meshbay.org/meshbay.git/atom?h=0.17</id>
<link rel='self' href='https://git.meshbay.org/meshbay.git/atom?h=0.17'/>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/'/>
<updated>2026-10-01T11:25:35Z</updated>
<entry>
<title>fix(node): the clear fields beside a chat message are bounded</title>
<updated>2026-10-01T11:25:35Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T11:25:24Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=10552e576528e97884b8b7587526e70843a13bb3'/>
<id>urn:sha1:10552e576528e97884b8b7587526e70843a13bb3</id>
<content type='text'>
sender_name and thread_id travel in clear beside the sealed envelope and were
stored and relayed whatever their type and size. A name longer than a username
or a thread id that is not a short id is now dropped (F-27).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(node): a member is told a media tool failed, not what ffmpeg said</title>
<updated>2026-10-01T11:24:11Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T11:24:11Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=8bdeacc966d24cb47713df7b4213340565c505c8'/>
<id>urn:sha1:8bdeacc966d24cb47713df7b4213340565c505c8</id>
<content type='text'>
Stream, transcode and subtitle failures sent the exception's text — operator
paths, versions — to the member. Fixed messages now, the cause in the log
(F-24).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix: downloads are marked and keep their extension; Explorer files are refused</title>
<updated>2026-10-01T09:47:39Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T09:47:39Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=760ac421b1944cd69a80e3a92127a1a966f15938'/>
<id>urn:sha1:760ac421b1944cd69a80e3a92127a1a966f15938</id>
<content type='text'>
The desktop app writes the Mark-of-the-Web on each file it saves on Windows, as
a browser does. Bidirectional controls are reserved characters in a saved name
(portable-name.js and paths.sanitize_for_download, and again in the main
process), so a name cannot display one extension and carry another. The node
refuses uploads of files Windows Explorer acts on by itself: desktop.ini,
.lnk, .url, .scf, .library-ms, .searchConnector-ms (F-19).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(node): one member holds a share of the node, sized past real use</title>
<updated>2026-10-01T08:34:26Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T08:34:26Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=15e117673d2303bf476d4f78699e47913ce1aec0'/>
<id>urn:sha1:15e117673d2303bf476d4f78699e47913ce1aec0</id>
<content type='text'>
128 peer sessions on the node, at most 64 per account (the hub names the
account with each offer; the node's own account is not counted). One account
plays at most half the stream slots, rounded up, and runs two subtitle
extractions at once. Frames after the handshake are 8 MiB (was 64), decoded
with per-container bounds, and a frame refused for either ends the session
instead of jamming its buffer (F-16).

Sized for the heaviest real member: twenty groups on one node, three devices
and a tab, up to 52 sessions. Measured: ~0.15 MiB and one fd per idle session.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(node): an upload never replaces a file, nor shares a part with another</title>
<updated>2026-10-01T07:57:11Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T07:57:11Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=b3c031881b38b4c95e2945c05537b6a681a096d9'/>
<id>urn:sha1:b3c031881b38b4c95e2945c05537b6a681a096d9</id>
<content type='text'>
A name an upload in flight will take is reserved; each upload writes its own
`name.&lt;tag&gt;.part`; the finished file is published by a hard link, which
refuses an existing target, and takes the next free name if one appeared
meanwhile — the last ack names it. Two members sending one name at once wrote
one part and published it twice; a file copied in during an upload was
replaced (F-09).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(node): ffprobe over a member's file is bounded, and stopped when it is</title>
<updated>2026-10-01T07:53:34Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T07:53:34Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=0673922e704f718037eeffd2724debcfa8ac0b4b'/>
<id>urn:sha1:0673922e704f718037eeffd2724debcfa8ac0b4b</id>
<content type='text'>
probe_video waits 30 s at most and kills ffprobe on a timeout or when its
caller gives up — a cancelled wait left the process running. The seek probe
kills what it timed out on. Stream, subtitle and enrichment requests no longer
hang on a file that keeps ffprobe busy (F-18, timeouts; the protocol
whitelist was dropped: ffmpeg already confines nested protocols of a local
input, measured on 8.0 against HLS and concat inputs).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(node): link previews connect to the address they checked, without blocking</title>
<updated>2026-10-01T07:49:58Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T07:49:58Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=6426912946270bb02e7b94508008edf8f949d993'/>
<id>urn:sha1:6426912946270bb02e7b94508008edf8f949d993</id>
<content type='text'>
The name is resolved off the event loop and every answer checked; the socket
is then opened to that IP literal through a pinned httpcore backend, TLS still
verifying the certificate for the name, and no proxy from the environment.
A name that answers clean and then with a LAN address no longer gets a
request sent there, and a slow name no longer stalls the node (F-12).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix: an identity signs a named kind, and a device approval answers a request</title>
<updated>2026-09-30T19:04:39Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-09-30T19:04:39Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=0378e8e0912a1a7e6cea4424e69d524e7afecbf8'/>
<id>urn:sha1:0378e8e0912a1a7e6cea4424e69d524e7afecbf8</id>
<content type='text'>
The desktop main process builds every transcript itself from fields
(transcripts.js) and signs no raw bytes; the page's identity has the same
contract (crypto.js transcriptFor). The keyring seals no bundle while browser
access is off. On the node, device_add must redeem a pending request filed by
the same keys, and device_revoke is signed under its own prefix
(meshbay:device_revoke:v1), so a retirement signature admits nothing.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(node): the roster, not the key alone, decides who gets a session</title>
<updated>2026-09-30T09:57:03Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-09-30T09:57:03Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=5612dbbac41609b3f84784f57f1de538262db9a9'/>
<id>urn:sha1:5612dbbac41609b3f84784f57f1de538262db9a9</id>
<content type='text'>
The handshake opened a session for anyone holding the group key with a hub
token naming the group; the roster was consulted only when wrapping the key
in a join. A member revoked or unpinned on the node but still a member on
the hub kept a full session with the key they already held — and was handed
the chat epoch their removal had just opened, since chat keys go to any
session. An honest client never met this (it asks for the key through
join_request every time); one that kept the key did not have to.

- After the proof, the node asks the roster and refuses with
  `not_authorized_for_group` unless the account is an active member of the
  group or the node's operator.
- A removal from any door — MNP, the node page, the CLI — now opens a new
  chat epoch in each group the person could read, broadcasts it, and closes
  every connection they hold (`ops.members._after_removal`). The CLI and the
  node page did neither.
- Design §5.2, protocol §6.1, §6.3, §14.2.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix: a member can no longer lock a node, crash it with a link, or stop hub cleanup</title>
<updated>2026-09-30T09:22:24Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-09-30T09:22:24Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=69554fac7eba6eef7eb8a1c0111c5b92e7f21256'/>
<id>urn:sha1:69554fac7eba6eef7eb8a1c0111c5b92e7f21256</id>
<content type='text'>
- node: only a wrong code counts towards the join lock, now per account
  (5) as well as node-wide (20), and it is consulted only when a code is
  tried. Every member reconnecting gets the group key through join_request,
  so a lock checked before recognition let one member refuse it to everyone.
- node: link previews read the body as a stream and stop at the cap,
  counted on decoded bytes; a declared oversized image is not read; 15 s
  total deadline; image decoding off the loop. `client.get` had buffered
  the whole (decompressed) response before the caps looked at it.
- hub: the daily purge of never-verified accounts detaches their IP-log
  rows (keeping the name) and clears every other reference first, and each
  cleanup step runs on its own. On PostgreSQL the bare DELETE violated the
  ip_logs foreign key and stopped every purge behind it for good.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
</feed>
