summaryrefslogtreecommitdiffstats
path: root/docs/MESHBAY_NODE_PROTOCOL.md
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-10-01 13:06:32 +0200
committerChristophe Besson <cbesson@gmail.com>2026-10-01 13:06:32 +0200
commite0905bd447f6214dc34e360554826ace45bde676 (patch)
tree64c371d7675861f4af6ade210c46652bd610707a /docs/MESHBAY_NODE_PROTOCOL.md
parent0d9d91eeea9001ea3838272416e3d526b6a2a1fc (diff)
downloadmeshbay-e0905bd447f6214dc34e360554826ace45bde676.tar.gz
fix: an MBK2 bundle is opened once and stored again as MBK3
Transitional. The Argon2 run that makes M makes A, the key MBK2 bundles were sealed under; a session keeps it as a decrypt-only key (IndexedDB in a browser, the key storage in the desktop app). A client meeting an MBK2 bundle opens it — or its recovery copy — and stores the same identity as MBK3 once connected; the desktop app reseals or withdraws it as browser access says. A session without A asks for the passphrase once. Older formats stay refused by name. Replaces the unpin-and-reinvite step the 0.17 flag day required on every node. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs/MESHBAY_NODE_PROTOCOL.md')
-rw-r--r--docs/MESHBAY_NODE_PROTOCOL.md12
1 files changed, 7 insertions, 5 deletions
diff --git a/docs/MESHBAY_NODE_PROTOCOL.md b/docs/MESHBAY_NODE_PROTOCOL.md
index 676b96f..e7fce90 100644
--- a/docs/MESHBAY_NODE_PROTOCOL.md
+++ b/docs/MESHBAY_NODE_PROTOCOL.md
@@ -685,11 +685,13 @@ the node that proved it, for the account that stored it.
(`keyderive.js` in a browser, `keyring.js` in the desktop application's main
process), and optionally a second copy under the account recovery key. The node
stores bytes and serves them back to the same `user_id`.
-* **A client reads `MBK3` and nothing else.** A bundle in an earlier format was
- sealed under the passphrase alone; the client refuses it by name
- (`bundle_format_retired`) and does not mint a replacement identity, which would
- leave the node pinning a key nobody holds. `member unpin` drops the bundle, and
- the next join is a first contact.
+* **A client writes `MBK3` and nothing else.** It reads one earlier format once,
+ to replace it (*transitional*): `MBK2`, `"MBK2" ‖ nonce (12) ‖ AES-GCM` under the
+ passphrase's Argon2 key, no associated data. The identity in it is stored again
+ as `MBK3` with `keypair_bundle_store` once the session is up. Anything older is
+ refused by name (`bundle_format_retired`), and the client does not mint a
+ replacement identity, which would leave the node pinning a key nobody holds;
+ `member unpin` drops the bundle, and the next join is a first contact.
* `keypair_bundle_store` is accepted **after** authentication (it is not in the
pre-proof list); the fetch is what happens before.
* A `store` omitting `bundle_enc_recovery` leaves any existing recovery copy in place.