aboutsummaryrefslogtreecommitdiffstats
path: root/CLAUDE.md
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 17:26:59 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 17:26:59 +0200
commitd692db441680eef8969573047cf5da00cfb61362 (patch)
tree4a67e4bd2a6421a154c706d2aeb8cc7bfd548187 /CLAUDE.md
parentb1ebcdeb9082457972c41a47e77494902335d262 (diff)
downloadmeshbay-d692db441680eef8969573047cf5da00cfb61362.tar.gz
docs: state the pepper, MBK3, the desktop keyring and browser access as they are
Design §2.2-§3.7, §4, §5.6, §7.7, §8, §9.10 and the registers; protocol §7, §7.1, §7.1a and §13; the user guide; CLAUDE.md's parity rule. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'CLAUDE.md')
-rw-r--r--CLAUDE.md12
1 files changed, 7 insertions, 5 deletions
diff --git a/CLAUDE.md b/CLAUDE.md
index dfe0e49..5a5d9c4 100644
--- a/CLAUDE.md
+++ b/CLAUDE.md
@@ -262,10 +262,12 @@ These are about working on the tree rather than about the design:
`docs/MESHBAY_DESIGN.md` §13.5b is the register; `test_availability_between_
members.py` is where a new case goes, and every test in it is two accounts,
because a one-member test proves a one-member property
-- **Never change the KDF parameters in one place.** `keyderive.js`,
- `keyderive.py`, the QE harness and `test_bundle_kdf_parity.py` are held
- byte-identical by that test, and a mismatch does not look like an error — it
- looks like an account nobody can open
+- **Never change the KDF parameters in one place.** `keyderive.js` (the page),
+ `meshbay-client/src/keyring.js` (the desktop main process) and a Python
+ reference written from `MESHBAY_DESIGN.md` §3.7 are held byte-identical, down
+ to opening a bundle, by `test_bundle_kdf_parity.py` and
+ `test_desktop_keyring.py`; a mismatch does not look like an error — it looks
+ like an account nobody can open
- **Raw answer SDP is saved before `setRemoteDescription`** — Chrome strips
sha-256 from a multi-hash SDP, and the fingerprint is the channel binding
- **Upload chunk size is 48 KB**, which is what fits the aiortc SCTP limit after
@@ -921,7 +923,7 @@ here are kept only where they are a rule about *editing* the code.
| Handshake, version range | `meshbay_common/handshake.py` — `MNP_MIN_SUPPORTED`, `check_version` | read by both servers and both clients |
| Wire messages, `req_id`, `IndexEntry` | `meshbay_common/protocol.py` | §5.3 |
| Signed admin transcripts | `meshbay_common/adminop.py`, `join.py`, `device.py` | §5.4 |
-| Key derivation from a passphrase | `meshbay_common/keyderive.py` + `static/keyderive.js` | §3.1. **Parity-tested — never change the parameters in one place** |
+| Key derivation from a passphrase, bundle format | `static/keyderive.js` (page) + `meshbay-client/src/keyring.js` (desktop main process) | §3.1, §3.7. **Parity-tested — never change the parameters in one place.** `meshbay_common/keyderive.py` is an older, unused derivation, not this one |
| Path folding, NFC, long paths, reserved names | `meshbay_common/paths.py` | §10 |
| ~~Double Ratchet / Sender Keys~~ | — | **Deleted.** Both were written and never called. Kept code that nothing calls reads as an alternative somebody may reach for, and its green tests read as evidence of a protection that is not in the product. The reasoning that ruled them out is at the top of `chatbox.py` |