diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-19 17:58:05 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-19 17:58:05 +0200 |
| commit | 1ec316035ce9aa656dd18a05889856bce9e3aba3 (patch) | |
| tree | b50e97f50d485ef2a88ce36fe4d7511d9fe3e288 /packages/meshbay-common/src | |
| parent | 171a3e175889ce30f201fcdf5c4632f480344ae6 (diff) | |
| parent | 95dd3dc13aecec85c2fd72410cd4d1f4ed582dfa (diff) | |
| download | meshbay-1ec316035ce9aa656dd18a05889856bce9e3aba3.tar.gz | |
Merge origin/main: the tree-wide ruff pass beside the Music reconnect work
Diffstat (limited to 'packages/meshbay-common/src')
5 files changed, 28 insertions, 25 deletions
diff --git a/packages/meshbay-common/src/meshbay_common/background.py b/packages/meshbay-common/src/meshbay_common/background.py index 1f25dfd..0afc3e8 100644 --- a/packages/meshbay-common/src/meshbay_common/background.py +++ b/packages/meshbay-common/src/meshbay_common/background.py @@ -30,7 +30,8 @@ from __future__ import annotations import asyncio import logging -from typing import Any, Coroutine +from collections.abc import Coroutine +from typing import Any log = logging.getLogger(__name__) diff --git a/packages/meshbay-common/src/meshbay_common/crypto.py b/packages/meshbay-common/src/meshbay_common/crypto.py index eadb42b..e537500 100644 --- a/packages/meshbay-common/src/meshbay_common/crypto.py +++ b/packages/meshbay-common/src/meshbay_common/crypto.py @@ -5,17 +5,17 @@ Validated in Spike 1 and Spike 6 of the POC. All operations use PyCA cryptography (OpenSSL-backed, hardware-accelerated). """ -import os import base64 +import os +import blake3 +from cryptography.hazmat.primitives import hashes, serialization from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey, Ed25519PublicKey from cryptography.hazmat.primitives.asymmetric.x25519 import X25519PrivateKey, X25519PublicKey +from cryptography.hazmat.primitives.ciphers import Cipher, algorithms, modes from cryptography.hazmat.primitives.ciphers.aead import ChaCha20Poly1305 -from cryptography.hazmat.primitives.kdf.hkdf import HKDF from cryptography.hazmat.primitives.kdf.argon2 import Argon2id -from cryptography.hazmat.primitives.ciphers import Cipher, algorithms, modes -from cryptography.hazmat.primitives import hashes, serialization -import blake3 +from cryptography.hazmat.primitives.kdf.hkdf import HKDF # ── Key serialisation helpers ───────────────────────────────────────────────── diff --git a/packages/meshbay-common/src/meshbay_common/keyderive.py b/packages/meshbay-common/src/meshbay_common/keyderive.py index 497f877..4b90af3 100644 --- a/packages/meshbay-common/src/meshbay_common/keyderive.py +++ b/packages/meshbay-common/src/meshbay_common/keyderive.py @@ -24,11 +24,11 @@ See keyderive.js for the browser-side implementation. """ import hashlib + from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey from cryptography.hazmat.primitives.asymmetric.x25519 import X25519PrivateKey from cryptography.hazmat.primitives.kdf.argon2 import Argon2id - # Argon2id parameters — same as keystore (see crypto.py) _ITERATIONS = 3 _MEMORY_COST = 65536 # 64 MB — increase to 262144 for production @@ -85,9 +85,11 @@ def encrypt_keypair_bundle( Returns: AES-256-GCM ciphertext (nonce prepended). """ import os + + import msgpack from cryptography.hazmat.primitives.ciphers.aead import AESGCM + from meshbay_common.crypto import sk_to_raw - import msgpack # Derive an AES key from the password (different info string from key derivation) salt = hashlib.sha256(f"meshbay:bundle:v1:{username}".encode()).digest() diff --git a/packages/meshbay-common/src/meshbay_common/protocol.py b/packages/meshbay-common/src/meshbay_common/protocol.py index c444711..5374742 100644 --- a/packages/meshbay-common/src/meshbay_common/protocol.py +++ b/packages/meshbay-common/src/meshbay_common/protocol.py @@ -32,12 +32,11 @@ which local promise a reply belongs to. import os from dataclasses import dataclass, field -from typing import Any # The wire versions live in meshbay_common/__init__.py — one source, because a # second copy here said "0.1" while every message on the wire carried "0.2". # Nothing imported it, which is the only reason it was harmless. -from meshbay_common import MNP_VERSION, MHP_VERSION # noqa: F401 (re-export) +from meshbay_common import MHP_VERSION, MNP_VERSION # noqa: F401 (re-export) from meshbay_common.groupbox import PURPOSE_UPLOAD, seal, unseal from meshbay_common.webcrypto import ( chunk_key_aes, @@ -45,7 +44,6 @@ from meshbay_common.webcrypto import ( encrypt_chunk_aes, ) - # ── MNP message types ───────────────────────────────────────────────────────── class MNP: @@ -70,7 +68,8 @@ class MNP: # and no client: removed rather than repaired. # # Not a Double Ratchet message, and never was — finding C1 - # (`docs/MESHBAY_DESIGN.md` §13.1) rejected exactly that for groups. Since MNP 2.0 it is AES-256-GCM under a + # (`docs/MESHBAY_DESIGN.md` §13.1) rejected exactly that for groups. Since + # MNP 2.0 it is AES-256-GCM under a # per-device subkey of the group's chat epoch key, signed over the # ciphertext with the sending device's pinned Ed25519 key. There is no # plaintext form on the wire (`chatbox.py`, docs/MESHBAY_DESIGN.md §4.5); @@ -160,21 +159,21 @@ class MNP: MEMBER_UNPIN_ACK = "member_unpin_ack" APPS_ENABLED = "apps_enabled" # operator → node: which group apps to show APPS_ENABLED_ACK = "apps_enabled_ack" - TRANSFER_LIMITS = "transfer_limits" # operator → node: per-member caps for this group + TRANSFER_LIMITS = "transfer_limits" # operator → node: per-member caps here TRANSFER_LIMITS_ACK = "transfer_limits_ack" # node → this group: the new caps SET_SCAN_SETTINGS = "set_scan_settings" # operator → node: reconcile/debounce timing SET_SCAN_SETTINGS_ACK = "set_scan_settings_ack" MEDIA_META_REQ = "media_meta_req" # client → node: TMDB metadata for a path MEDIA_META_RESP = "media_meta_resp" # node → client: TMDB metadata (or none) - TMDB_CONFIG = "tmdb_config" # operator → node: set custom TMDB token/language (node-wide) - TMDB_CONFIG_ACK = "tmdb_config_ack" # node → everyone: new TMDB config (never the token) - TMDB_ENABLED = "tmdb_enabled" # operator → node: enable/disable TMDB for this group - TMDB_ENABLED_ACK = "tmdb_enabled_ack" # node → this group: new per-group TMDB enabled state - SEASON_META_REQ = "season_meta_req" # client → node: TMDB overview/poster for one season - SEASON_META_RESP = "season_meta_resp" # node → client: season-level TMDB fields (or none) - TMDB_SEARCH_REQ = "tmdb_search_req" # client → node: candidate TMDB matches for a query - TMDB_SEARCH_RESP = "tmdb_search_resp" # node → client: candidate list (id, title, year, poster) - TMDB_OVERRIDE = "tmdb_override" # operator → node: replace a show/movie's TMDB match + TMDB_CONFIG = "tmdb_config" # operator → node: token/language, node-wide + TMDB_CONFIG_ACK = "tmdb_config_ack" # node → everyone: config, never the token + TMDB_ENABLED = "tmdb_enabled" # operator → node: TMDB on/off here + TMDB_ENABLED_ACK = "tmdb_enabled_ack" # node → this group: TMDB on/off here + SEASON_META_REQ = "season_meta_req" # client → node: one season's overview + SEASON_META_RESP = "season_meta_resp" # node → client: season fields, or none + TMDB_SEARCH_REQ = "tmdb_search_req" # client → node: candidates for a query + TMDB_SEARCH_RESP = "tmdb_search_resp" # node → client: id, title, year, poster + TMDB_OVERRIDE = "tmdb_override" # operator → node: replace a match TMDB_OVERRIDE_ACK = "tmdb_override_ack" TMDB_REMATCH = "tmdb_rematch" # operator → node: drop one file's match TMDB_REMATCH_ACK = "tmdb_rematch_ack" @@ -257,7 +256,7 @@ class MNP: # key without having to reconnect. CHAT_EPOCH = "chat_epoch" CHAT_EPOCH_ACK = "chat_epoch_ack" - ROOT_UPDATE = "root_update" # operator → node: change writable/removable on a root + ROOT_UPDATE = "root_update" # operator → node: a root's flags ROOT_UPDATE_ACK = "root_update_ack" ROOT_EJECT = "root_eject" # operator → node: mark removable root as ejected ROOT_EJECT_ACK = "root_eject_ack" @@ -271,7 +270,7 @@ class MNP: # node's `sender_id` (Tier 2, docs/MESHBAY_DESIGN.md §3.3). GROUP_ROSTER_REQ = "group_roster_req" GROUP_ROSTER_RESP = "group_roster_resp" - ROSTER_READ = "roster_read" # operator → node: list pinned identities + members + ROSTER_READ = "roster_read" # operator → node: identities + members ROSTER_READ_ACK = "roster_read_ack" DENYLIST_READ = "denylist_read" # operator → node: show denylist entries DENYLIST_READ_ACK = "denylist_read_ack" diff --git a/packages/meshbay-common/src/meshbay_common/webcrypto.py b/packages/meshbay-common/src/meshbay_common/webcrypto.py index 58958f8..3bd5ae6 100644 --- a/packages/meshbay-common/src/meshbay_common/webcrypto.py +++ b/packages/meshbay-common/src/meshbay_common/webcrypto.py @@ -26,9 +26,10 @@ This ensures AES and ChaCha20 keys are always distinct even from the same GEK. """ import os + +from cryptography.hazmat.primitives import hashes from cryptography.hazmat.primitives.ciphers.aead import AESGCM from cryptography.hazmat.primitives.kdf.hkdf import HKDF -from cryptography.hazmat.primitives import hashes def chunk_key_aes(gek: bytes, file_hash: bytes, chunk_index: int) -> bytes: |