docs: unified smolmail
This commit is contained in:
parent
bd9bcf1076
commit
864daa0bad
8 changed files with 12 additions and 12 deletions
2
FAQ.md
2
FAQ.md
|
|
@ -10,7 +10,7 @@ Trusting a mail server carries more. Once you trust a server, it is allowed to a
|
||||||
|
|
||||||
Adding a server is a manual, deliberate step. It is never a link you can be tricked into clicking.
|
Adding a server is a manual, deliberate step. It is never a link you can be tricked into clicking.
|
||||||
|
|
||||||
## Why does Smol Mail not have native WebSocket support?
|
## Why does smolmail not have native WebSocket support?
|
||||||
|
|
||||||
It does, kept separate as an optional annex ([WS.md](WS.md)) rather than built into the core protocol.
|
It does, kept separate as an optional annex ([WS.md](WS.md)) rather than built into the core protocol.
|
||||||
|
|
||||||
|
|
|
||||||
6
SPEC.md
6
SPEC.md
|
|
@ -1,6 +1,6 @@
|
||||||
<!-- SPDX-License-Identifier: CC-BY-SA-4.0 -->
|
<!-- SPDX-License-Identifier: CC-BY-SA-4.0 -->
|
||||||
|
|
||||||
# Smol Mail Protocol, version 1.2
|
# smolmail Protocol, version 1.2
|
||||||
|
|
||||||
A minimalist, decentralised, end-to-end encrypted mail protocol.
|
A minimalist, decentralised, end-to-end encrypted mail protocol.
|
||||||
|
|
||||||
|
|
@ -375,7 +375,7 @@ RNS facts cited below were read from Reticulum 1.5.4. Constants in that stack ar
|
||||||
|
|
||||||
### 13.1 Server destination
|
### 13.1 Server destination
|
||||||
|
|
||||||
A server holds one **Reticulum identity**, persisted, separate from every Smol Mail identity in §2 and never used as one. RNS writes its private key unencrypted, so the file MUST be protected as any long-term server key is: mode 0600, backed up by the operator, never transmitted.
|
A server holds one **Reticulum identity**, persisted, separate from every smolmail identity in §2 and never used as one. RNS writes its private key unencrypted, so the file MUST be protected as any long-term server key is: mode 0600, backed up by the operator, never transmitted.
|
||||||
|
|
||||||
```
|
```
|
||||||
RNS.Destination(identity, IN, SINGLE, "smolmail", "server")
|
RNS.Destination(identity, IN, SINGLE, "smolmail", "server")
|
||||||
|
|
@ -471,7 +471,7 @@ A mailbox reachable over both transports has one queue, and §6.1 requires a rec
|
||||||
|
|
||||||
The per-IP connection and `SEND` limits of §10 have no analogue. Reticulum gives a server no stable handle on an initiator that does not identify itself, and that is the point: a sender is absent from the wire format by construction (§5.2), and a transport that reintroduced a durable sender identifier would undo it.
|
The per-IP connection and `SEND` limits of §10 have no analogue. Reticulum gives a server no stable handle on an initiator that does not identify itself, and that is the point: a sender is absent from the wire format by construction (§5.2), and a transport that reintroduced a durable sender identifier would undo it.
|
||||||
|
|
||||||
- A server MUST NOT require Reticulum link identification for any operation. It proves a Reticulum identity rather than a Smol Mail one, and a durable one is exactly the handle this section says a server must not have.
|
- A server MUST NOT require Reticulum link identification for any operation. It proves a Reticulum identity rather than a smolmail one, and a durable one is exactly the handle this section says a server must not have.
|
||||||
- A server SHOULD limit requests and bytes per link, and cap concurrent links. Reticulum enforces neither.
|
- A server SHOULD limit requests and bytes per link, and cap concurrent links. Reticulum enforces neither.
|
||||||
- A server SHOULD keep a global `SEND` ceiling in place of the per-peer one.
|
- A server SHOULD keep a global `SEND` ceiling in place of the per-peer one.
|
||||||
- The per-accept-token `SEND` limit of §10 is unchanged and becomes the main defence. It never needed a peer identity: a token is issued by the mailbox owner (§5.8), which is exactly the handle this transport still has.
|
- The per-accept-token `SEND` limit of §10 is unchanged and becomes the main defence. It never needed a peer identity: a token is issued by the mailbox owner (§5.8), which is exactly the handle this transport still has.
|
||||||
|
|
|
||||||
2
WS.md
2
WS.md
|
|
@ -1,6 +1,6 @@
|
||||||
<!-- SPDX-License-Identifier: CC-BY-SA-4.0 -->
|
<!-- SPDX-License-Identifier: CC-BY-SA-4.0 -->
|
||||||
|
|
||||||
# Smol Mail over WebSocket annex
|
# smolmail over WebSocket annex
|
||||||
|
|
||||||
This annex is not part of the protocol. It adds no version, no section, no address form and no label, and a server that ignores it is fully conformant. It records one convention for carrying the transport of §4 through a WebSocket, so that browsers, which cannot open TCP sockets, and clients on networks that pass only port 443 can reach a mailbox, and so that independent implementations of that carriage agree. The keywords below bind only an implementation that claims to follow this annex. Section references are to [SPEC.md](SPEC.md).
|
This annex is not part of the protocol. It adds no version, no section, no address form and no label, and a server that ignores it is fully conformant. It records one convention for carrying the transport of §4 through a WebSocket, so that browsers, which cannot open TCP sockets, and clients on networks that pass only port 443 can reach a mailbox, and so that independent implementations of that carriage agree. The keywords below bind only an implementation that claims to follow this annex. Section references are to [SPEC.md](SPEC.md).
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -5,7 +5,7 @@
|
||||||
# ///
|
# ///
|
||||||
# Copyright 2026 randogoth
|
# Copyright 2026 randogoth
|
||||||
# SPDX-License-Identifier: Apache-2.0
|
# SPDX-License-Identifier: Apache-2.0
|
||||||
"""Smol Mail reference client.
|
"""smolmail reference client.
|
||||||
|
|
||||||
Implements SPEC.md version 1.1 from both ends: one master secret, sealed and
|
Implements SPEC.md version 1.1 from both ends: one master secret, sealed and
|
||||||
signed messages, server key pinning, trust on first use with rotation chains,
|
signed messages, server key pinning, trust on first use with rotation chains,
|
||||||
|
|
@ -282,7 +282,7 @@ def unseal(identities: list[Identity], envelope: bytes) -> dict:
|
||||||
if len(envelope) < ENVELOPE_HEADER + 16:
|
if len(envelope) < ENVELOPE_HEADER + 16:
|
||||||
raise SmolError("envelope too short")
|
raise SmolError("envelope too short")
|
||||||
if envelope[:4] != MAGIC:
|
if envelope[:4] != MAGIC:
|
||||||
raise SmolError("not a Smol Mail envelope")
|
raise SmolError("not a smolmail envelope")
|
||||||
if envelope[4] != VERSION:
|
if envelope[4] != VERSION:
|
||||||
raise SmolError(f"unsupported envelope version {envelope[4]}")
|
raise SmolError(f"unsupported envelope version {envelope[4]}")
|
||||||
to, epk, sealed = envelope[5:37], envelope[37:69], envelope[69:]
|
to, epk, sealed = envelope[5:37], envelope[37:69], envelope[69:]
|
||||||
|
|
|
||||||
|
|
@ -5,7 +5,7 @@
|
||||||
# ///
|
# ///
|
||||||
# Copyright 2026 randogoth
|
# Copyright 2026 randogoth
|
||||||
# SPDX-License-Identifier: Apache-2.0
|
# SPDX-License-Identifier: Apache-2.0
|
||||||
"""Smol Mail reference client -- Reticulum transport.
|
"""smolmail reference client -- Reticulum transport.
|
||||||
|
|
||||||
Implements reticulum.md (protocol 1.2), the Reticulum-transport addendum to
|
Implements reticulum.md (protocol 1.2), the Reticulum-transport addendum to
|
||||||
SPEC.md's version 1.1. Identities, envelopes, message identifiers, operations,
|
SPEC.md's version 1.1. Identities, envelopes, message identifiers, operations,
|
||||||
|
|
@ -314,7 +314,7 @@ def unseal(identities: list[Identity], envelope: bytes) -> dict:
|
||||||
if len(envelope) < ENVELOPE_HEADER + 16:
|
if len(envelope) < ENVELOPE_HEADER + 16:
|
||||||
raise SmolError("envelope too short")
|
raise SmolError("envelope too short")
|
||||||
if envelope[:4] != MAGIC:
|
if envelope[:4] != MAGIC:
|
||||||
raise SmolError("not a Smol Mail envelope")
|
raise SmolError("not a smolmail envelope")
|
||||||
if envelope[4] != VERSION:
|
if envelope[4] != VERSION:
|
||||||
raise SmolError(f"unsupported envelope version {envelope[4]}")
|
raise SmolError(f"unsupported envelope version {envelope[4]}")
|
||||||
to, epk, sealed = envelope[5:37], envelope[37:69], envelope[69:]
|
to, epk, sealed = envelope[5:37], envelope[37:69], envelope[69:]
|
||||||
|
|
|
||||||
|
|
@ -5,7 +5,7 @@
|
||||||
# ///
|
# ///
|
||||||
# Copyright 2026 randogoth
|
# Copyright 2026 randogoth
|
||||||
# SPDX-License-Identifier: Apache-2.0
|
# SPDX-License-Identifier: Apache-2.0
|
||||||
"""Smol Mail reference server.
|
"""smolmail reference server.
|
||||||
|
|
||||||
Implements SPEC.md version 1.1: a store-and-forward mailbox reachable over TCP
|
Implements SPEC.md version 1.1: a store-and-forward mailbox reachable over TCP
|
||||||
with a Noise_NX handshake. The server never sees plaintext, sender identities,
|
with a Noise_NX handshake. The server never sees plaintext, sender identities,
|
||||||
|
|
|
||||||
|
|
@ -5,7 +5,7 @@
|
||||||
# ///
|
# ///
|
||||||
# Copyright 2026 randogoth
|
# Copyright 2026 randogoth
|
||||||
# SPDX-License-Identifier: Apache-2.0
|
# SPDX-License-Identifier: Apache-2.0
|
||||||
"""Smol Mail reference server -- Reticulum transport.
|
"""smolmail reference server -- Reticulum transport.
|
||||||
|
|
||||||
Implements reticulum.md (protocol 1.2), the Reticulum-transport addendum to
|
Implements reticulum.md (protocol 1.2), the Reticulum-transport addendum to
|
||||||
SPEC.md's version 1.1. It is the same store-and-forward mailbox as
|
SPEC.md's version 1.1. It is the same store-and-forward mailbox as
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue