feat: SRV discovery (_smolmail._tcp) and port-scoped trust syntax in the CLI
This commit is contained in:
parent
13c624f2b0
commit
1468f3cbc0
5 changed files with 761 additions and 6 deletions
|
|
@ -17,6 +17,10 @@ smol+rns://alice@8f2c1d0a7b6e5f4c3d2a1b0e9f8c7d6a short form over
|
|||
smol+rns://alice@8f2c1d0a7b6e5f4c3d2a1b0e9f8c7d6a/mfrggzdfzt... self-certifying over Reticulum
|
||||
```
|
||||
|
||||
When a TCP address carries no port, the CLI discovers one by DNS SRV before dialing: `_smolmail._tcp.<host>` states the target and port serving that domain's mail (lowest priority wins, weight ignored), the discovered target is only a dial hint, and the domain keeps every identity role. No record, a failing lookup, or an explicit port means the default 1961 — the feature is purely additive, and old deployments never notice it existed. Discovery runs when an address is given; a stored account is dialed at the port it was registered with.
|
||||
|
||||
Server pins are scoped by port: `trust example.org` pins the default port, and `trust example.org:1962` pins any other — one host may serve several domains, each with its own key. The fallback is asymmetric by design: the default port inherits the bare-host pin existing stores already hold, and a non-default port never falls back to it — the first dial at a new port is trust on first use, like any first contact, rather than a mismatch against its sibling's key.
|
||||
|
||||
## Usage
|
||||
|
||||
One master per store, selected by the global `--key` and `--db` flags; a second identity is a second pair of files.
|
||||
|
|
@ -31,7 +35,7 @@ fumi restore <address> recover local state from the master a
|
|||
fumi rotate advance the rotation index, sign and push the certificate
|
||||
|
||||
# servers and contacts
|
||||
fumi trust <host> <key-b32> [--force] pin a server's Noise static key
|
||||
fumi trust <host[:port]> <key-b32> [--force] pin a server's Noise static key, scoped by port
|
||||
fumi register <address> [--invite TOKEN] bind this identity to a username
|
||||
fumi resolve <address> look up a contact's key, walk the chain, pin it
|
||||
fumi import <smol-uri> add a contact from a self-certifying address
|
||||
|
|
@ -96,7 +100,7 @@ Every mail column holds a sealed envelope, never plaintext. Timestamps are Unix
|
|||
| Table | Columns | Meaning and invariants |
|
||||
|---|---|---|
|
||||
| `state` | one row, `id = 1`, always present | `username`, `host`, `port`, `scheme` (`tcp` or `rns`) are the account; `rotations` is the sec 2 rotation index the account is at; `after_time` and `after_id` are the sec 6.1 fetch cursor; `sync_ok` (0/1) says whether the local accept-token set may replace the server's — a client restored from the master alone must not erase it (sec 4) |
|
||||
| `servers` | `host`, `static`, `pinned_at` | The sec 4 pins: a server's Noise static key, keyed by host without port |
|
||||
| `servers` | `host`, `static`, `pinned_at` | The sec 4 pins: a server's Noise static key, keyed by host on the default port and by `host:port` on any other — the same label the trust errors name |
|
||||
| `contacts` | `address`, `identity`, `verified`, `seen_at` | Every key known for an address; `verified` is 1 only when it came from a self-certifying URI |
|
||||
| `accepted` | `address`, `identity`, `active`, `added_at` | Main-tier admission (sec 5.8). `identity` is frozen at acceptance because the token the correspondent holds is derived from it; `active = 0` is a block and keeps the row |
|
||||
| `tokens` | `address`, `token`, `seen_at` | Accept tokens correspondents issued us, filed under their address, which outlives the keys behind it (sec 5.8) |
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue