aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-common/src/meshbay_common/__init__.py
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-common/src/meshbay_common/__init__.py')
-rw-r--r--packages/meshbay-common/src/meshbay_common/__init__.py18
1 files changed, 17 insertions, 1 deletions
diff --git a/packages/meshbay-common/src/meshbay_common/__init__.py b/packages/meshbay-common/src/meshbay_common/__init__.py
index f10302f..1271c4e 100644
--- a/packages/meshbay-common/src/meshbay_common/__init__.py
+++ b/packages/meshbay-common/src/meshbay_common/__init__.py
@@ -220,5 +220,21 @@ __version__ = "0.15.0"
# the node's own `stream_init` and from no version number, so the request is
# never sent to a peer that could not answer it. `MNP_MIN_SUPPORTED` does not
# move.
-MNP_VERSION = "3.3"
+#
+# **3.4 (2026-09-23): the node signs its challenge.**
+#
+# `handshake_challenge` carries `sig`, Ed25519 by the node key over
+# `meshbay:mnp:challenge:v1` ‖ group_id ‖ nonce_c ‖ nonce_s ‖ binding
+# (`handshake.challenge_transcript`). Until now `node_pk` in the challenge was a
+# claim: the ack proves it, but a join is sent *before* the ack, so an
+# invitation code went to whichever peer answered signaling. With the
+# signature, a client that knows which node it means to reach — an invitation
+# link names it — can refuse to send the code anywhere else.
+#
+# **Additive, and MINOR because nothing is required of an older peer.** A client
+# that ignores `sig` behaves exactly as before; a client that reads it refuses a
+# *wrong* one outright and treats an absent one as "this node cannot prove
+# itself early", which it discovers from the node's answer and never from the
+# version number. `MNP_MIN_SUPPORTED` does not move.
+MNP_VERSION = "3.4"
MHP_VERSION = "0.1"