aboutsummaryrefslogtreecommitdiffstats
path: root/CLAUDE.md
diff options
context:
space:
mode:
Diffstat (limited to 'CLAUDE.md')
-rw-r--r--CLAUDE.md12
1 files changed, 7 insertions, 5 deletions
diff --git a/CLAUDE.md b/CLAUDE.md
index dfe0e49..5a5d9c4 100644
--- a/CLAUDE.md
+++ b/CLAUDE.md
@@ -262,10 +262,12 @@ These are about working on the tree rather than about the design:
`docs/MESHBAY_DESIGN.md` §13.5b is the register; `test_availability_between_
members.py` is where a new case goes, and every test in it is two accounts,
because a one-member test proves a one-member property
-- **Never change the KDF parameters in one place.** `keyderive.js`,
- `keyderive.py`, the QE harness and `test_bundle_kdf_parity.py` are held
- byte-identical by that test, and a mismatch does not look like an error — it
- looks like an account nobody can open
+- **Never change the KDF parameters in one place.** `keyderive.js` (the page),
+ `meshbay-client/src/keyring.js` (the desktop main process) and a Python
+ reference written from `MESHBAY_DESIGN.md` §3.7 are held byte-identical, down
+ to opening a bundle, by `test_bundle_kdf_parity.py` and
+ `test_desktop_keyring.py`; a mismatch does not look like an error — it looks
+ like an account nobody can open
- **Raw answer SDP is saved before `setRemoteDescription`** — Chrome strips
sha-256 from a multi-hash SDP, and the fingerprint is the channel binding
- **Upload chunk size is 48 KB**, which is what fits the aiortc SCTP limit after
@@ -921,7 +923,7 @@ here are kept only where they are a rule about *editing* the code.
| Handshake, version range | `meshbay_common/handshake.py` — `MNP_MIN_SUPPORTED`, `check_version` | read by both servers and both clients |
| Wire messages, `req_id`, `IndexEntry` | `meshbay_common/protocol.py` | §5.3 |
| Signed admin transcripts | `meshbay_common/adminop.py`, `join.py`, `device.py` | §5.4 |
-| Key derivation from a passphrase | `meshbay_common/keyderive.py` + `static/keyderive.js` | §3.1. **Parity-tested — never change the parameters in one place** |
+| Key derivation from a passphrase, bundle format | `static/keyderive.js` (page) + `meshbay-client/src/keyring.js` (desktop main process) | §3.1, §3.7. **Parity-tested — never change the parameters in one place.** `meshbay_common/keyderive.py` is an older, unused derivation, not this one |
| Path folding, NFC, long paths, reserved names | `meshbay_common/paths.py` | §10 |
| ~~Double Ratchet / Sender Keys~~ | — | **Deleted.** Both were written and never called. Kept code that nothing calls reads as an alternative somebody may reach for, and its green tests read as evidence of a protection that is not in the product. The reasoning that ruled them out is at the top of `chatbox.py` |