fix: reject line breaks in frontmatter header values; note reference-impl limits
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
864daa0bad
commit
43e4be2b8a
3 changed files with 27 additions and 1 deletions
11
README.md
11
README.md
|
|
@ -33,6 +33,10 @@ The short form is typeable. The long form carries the key itself, so an address
|
|||
|
||||
Ed25519 · X25519 · ChaCha20-Poly1305 · SHA-256. Four established primitives, no novel cryptography, nothing else anywhere in the protocol. Transport is TCP with a Noise handshake. No certificates, no CA, no expiry.
|
||||
|
||||
## Reference code
|
||||
|
||||
The four Python files are a reference, not production software. They were written entirely by an AI agent from [SPEC.md](SPEC.md) alone: if one agent can implement both ends of the protocol, across two transports, from the document and nothing else, the specification is coherent and complete enough to build from. The code favours clarity over hardening and carries simplifications a deployed server would not — see [Audit](#audit). Treat it as an executable illustration of the spec.
|
||||
|
||||
## Reference server
|
||||
|
||||
[smolmaild.py](smolmaild.py) is a complete server in one file. It declares its own dependencies inline, so there is nothing to install:
|
||||
|
|
@ -69,6 +73,13 @@ Sent mail carries the sender's full `smol://` address in a signed `Reply-To` fie
|
|||
|
||||
Mail is stored sealed and opened on demand, so the local database holds no plaintext.
|
||||
|
||||
## Audit
|
||||
|
||||
A security review of the protocol and these reference implementations found no issues in the protocol itself: the trust model, sealing, key rotation, accept tokens and the two transports' authentication binding all hold up as specified. Two findings were implementation-level and specific to the reference code:
|
||||
|
||||
- The server's rate limiter uses a fixed window, which admits up to twice the configured rate across a window boundary. A production limiter should use a sliding window or token bucket.
|
||||
- The TCP server runs one unbounded thread per connection, so a distributed connection flood can exhaust threads. A production server should cap concurrency, as the Reticulum server already does (SPEC.md §13.8).
|
||||
|
||||
## Specification
|
||||
|
||||
[SPEC.md](SPEC.md) defines the wire format, the operations and the trust model.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue