diff options
Diffstat (limited to 'packages/meshbay-common/src/meshbay_common/__init__.py')
| -rw-r--r-- | packages/meshbay-common/src/meshbay_common/__init__.py | 18 |
1 files changed, 17 insertions, 1 deletions
diff --git a/packages/meshbay-common/src/meshbay_common/__init__.py b/packages/meshbay-common/src/meshbay_common/__init__.py index f10302f..1271c4e 100644 --- a/packages/meshbay-common/src/meshbay_common/__init__.py +++ b/packages/meshbay-common/src/meshbay_common/__init__.py @@ -220,5 +220,21 @@ __version__ = "0.15.0" # the node's own `stream_init` and from no version number, so the request is # never sent to a peer that could not answer it. `MNP_MIN_SUPPORTED` does not # move. -MNP_VERSION = "3.3" +# +# **3.4 (2026-09-23): the node signs its challenge.** +# +# `handshake_challenge` carries `sig`, Ed25519 by the node key over +# `meshbay:mnp:challenge:v1` ‖ group_id ‖ nonce_c ‖ nonce_s ‖ binding +# (`handshake.challenge_transcript`). Until now `node_pk` in the challenge was a +# claim: the ack proves it, but a join is sent *before* the ack, so an +# invitation code went to whichever peer answered signaling. With the +# signature, a client that knows which node it means to reach — an invitation +# link names it — can refuse to send the code anywhere else. +# +# **Additive, and MINOR because nothing is required of an older peer.** A client +# that ignores `sig` behaves exactly as before; a client that reads it refuses a +# *wrong* one outright and treats an absent one as "this node cannot prove +# itself early", which it discovers from the node's answer and never from the +# version number. `MNP_MIN_SUPPORTED` does not move. +MNP_VERSION = "3.4" MHP_VERSION = "0.1" |