3.2 KiB
キラキラ kirakira
A mobile and desktop client for smolmail, a minimalist end-to-end encrypted mail protocol: one Ed25519 identity, five operations, sealed and signed messages over a Noise_NX transport.
kirakira began as FlashMail, a Flutter UI template for a disposable-email app built on mail.tm. Its protocol core is now fumi-core, the Rust library the reference CLI is built on: native/ wraps it into a C ABI and ships it in the APK as libsmol_mail_native.so (SQLite bundled), lib/native/ speaks that ABI over dart:ffi, and lib/smol/ is the thin facade the UI reads. The UI is Material 3 — dark navy and mint green by default, with a matching light theme — built from a single ColorScheme and AppColors extension rather than hardcoded colors per screen.
What it does
- Create or restore an identity from a 32-byte seed — that's the only secret.
- Pin a server's key, register or recall an address, then fetch and send sealed mail.
- Trust-on-first-use for server and contact keys, with rotation support and on-screen warnings for anything unverified.
- Export/import inbox, sent mail, contacts and server pins as one shareable backup file — never the seed.
Mail, contacts and pinned server keys live in fumi-core's SQLite store, bundled into the native library; the seed, read marks and settings stay app-side in Hive.
Layout
lib/native/ dart:ffi binding: handles, error codes, isolate plumbing
lib/smol/ thin facades over the binding: address, store, client
lib/presentation/ screens, widgets and theme (Riverpod + auto_route)
lib/data/ Riverpod providers
native/ Rust wrapper crate: the C ABI over fumi-core, pinned by rev
integration_test/ Patrol device tests against a live server
test/ store, recall, binding, interop and e2e tests
Run and verify
devbox run build-native-android # the .so the APK loads — once per Rust change
devbox run analyze
devbox run test
flutter run --flavor prod
test/e2e_test.dart runs a live round-trip against the local bunshin on 127.0.0.1:1961 and skips itself when nothing's listening there. On-device flows are covered by the Patrol suite — devbox run test-integration builds the integration flavor (installed beside the real app, its data cleared between tests) and drives onboarding, registration, fetch cancellation, rotation and the unchanged-key refresh against the same server.
License
MIT — see LICENSE.md.