Commit Graph
2139 Commits
Author SHA1 Message Date
Evgeny @ SimpleX Chat a3a184af4d Merge branch 'master' into sh/resync-atomic 2026-10-03 22:00:57 +00:00
EvgenyandEvgeny @ SimpleX Chat e11dfb985d consider IP address protected only if it is used for the chosen host (#1895)
* consider IP address protected only if it is used for the chosen host

* simplify

* simplify

* simplify

---------

Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-10-03 22:45:44 +01:00
Evgenyandshum 76248dd767 sntrup761: bound KeyGen retries on R3 inversion (#1918)
Co-authored-by: shum <github.shum@liber.li>
2026-10-03 17:01:36 +01:00
brenzi 9c641fed91 reject e2e params with kem_ct and without kem_key (#1901) 2026-10-03 15:10:42 +01:00
sh 91e070cb5e crypto: document 16-byte GCM IV in double ratchet (#1914) 2026-10-03 15:00:18 +01:00
sh 9fe3745401 docs: use role names for key exchange parties (#1912) 2026-10-03 14:59:22 +01:00
EvgenyandEvgeny @ SimpleX Chat 24036368f8 xrcp: limit multicast validity time window (#1899)
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-10-03 14:51:48 +01:00
sh acd5c0f530 docs: add cryptographic primitive registry (#1913) 2026-10-03 14:21:21 +01:00
EvgenyandEvgeny @ SimpleX Chat ead8f10f26 smp protocol: bind agreed version of forwarded command (#1915)
* smp protocol: bind agreed version of forwarded command

* refactor

* pass proxied relay version range via config

* simplify

* refactor

* packZipWith

---------

Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-10-03 08:56:19 +01:00
shum 90bec26ada agent: commit ratchet key hash with resync state 2026-10-02 11:02:05 +00:00
sh 053e83b704 resolver: multicall reads, keep-alive, workers and structured logs (#1883)
* resolver: queue up to 128 pending connections

* resolver: reuse connections to the node

* resolver: read each round in one multicall

* resolver: run worker processes, log durations

* resolver: keep smp-server connections alive

* resolver: test with pytest, lock dependencies

* resolver: structured logs and real client addresses

* resolver: refuse requests with a body

* resolver: harden pool, health and odd answers

* resolver: pin images, rotate logs

* resolver: stricter body check, redact RPC URL

* resolver: ship .env as .env.example

* resolver: pass settings from .env

* resolver: name the image snrc-resolve:local
2026-10-01 09:10:42 +01:00
sh 234b5cd856 smp-server: rework message expiration (#1873)
* smp server: rework message expiration

* smp server: paginate message expiration sweep
2026-10-01 09:08:16 +01:00
Evgeny Poberezkin 38fdc0c544 7.1.0.10 2026-09-30 13:03:16 +01:00
EvgenyandEvgeny @ SimpleX Chat b4c288c597 docs: clarify security model (#1902)
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-09-30 10:18:52 +01:00
EvgenyandEvgeny @ SimpleX Chat 0e1ecdcff6 xftp server: validate paths in store log (#1894)
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-09-30 09:36:45 +01:00
EvgenyandEvgeny @ SimpleX Chat c1776dc5a4 server: improve control port auth (#1898)
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-09-30 09:04:28 +01:00
EvgenyandEvgeny @ SimpleX Chat e2df2e1b7c docs: update SMP protocol (#1900)
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-09-30 08:10:35 +01:00
EvgenyandEvgeny @ SimpleX Chat 267e2e0727 agent: fix ratchet - dont save if body auth failed (#1892)
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-09-29 21:32:21 +01:00
EvgenyandEvgeny @ SimpleX Chat 551a79d99b smp server: validate client version in forwarded command (#1890)
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-09-29 19:52:15 +01:00
EvgenyandEvgeny @ SimpleX Chat 972e50e768 docs: update XRCP doc to make code verification optional for known connections (#1891)
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-09-29 18:08:54 +01:00
Evgeny Poberezkin 5eecd99bc2 7.1.0.9 2026-09-26 12:52:57 +01:00
69eb28b3ab agent: share server value across subscription rows of server-keyed queries (#1877)
* agent: share server value across subscription rows of server-keyed queries

* reduce fields in query

---------

Co-authored-by: Evgeny Poberezkin <evgeny@poberezkin.com>
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-09-26 12:05:20 +01:00
EvgenyandEvgeny @ SimpleX Chat 875ba7d53f agent: make QUOTA error temporary for async commands (#1881)
* agent: make QUOTA error temporary for async commands

* retry commands on quota

---------

Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-09-25 18:13:49 +01:00
EvgenyandEvgeny @ SimpleX Chat 35f1b145a7 xftp: fix race when sending the file (#1879)
* xftp: fix race when sending the file

* simpler test

* fix tests

* test

---------

Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-09-25 11:59:06 +01:00
sh c7163afa3a ci: cancel stale runs (#1878) 2026-09-24 15:33:22 +01:00
EvgenyandEvgeny @ SimpleX Chat 5294b7d8b7 agent: PQ rachet security code, store AD and pqAD in database, bulk reading (#1874)
* agent: PQ rachet security code, store AD and pqAD in database, bulk reading

* rename to verify code

* diff

* refactor

* query

* reduce transactions

* request binding

* simplify

* fix query and security code derivation

---------

Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-09-23 21:21:09 +01:00
Simplex Operations 900c45ffae 7.1.0.8 v7.1.0-beta.3 2026-09-19 08:04:24 +00:00
sh 7056ae22cc smp-server: reduce Prometheus and expiration DB load (#1872)
* smp server: add prometheus scan indexes

* smp server: estimate queue count in metrics

* docs: add smp server db load report

* smp server: reduce msg_queues write load

* docs: document batch-2 fixes and operator actions
2026-09-19 09:02:04 +01:00
Simplex Operations c6ef2876f1 7.1.0.7 2026-09-19 07:17:34 +00:00
ea43df2349 extend SMP protocol to support name availability queries by labelhash (#1863)
* implement resolving 2LD names by labelhash

* tiny test addition

* simplify language

* report expiry and availability correctly

* compare block instead of wall clock

* simplify language

* simplify language

* map resolver 410 to NAME NOT_FOUND (a lapsed name is an answer, not a failure)

* split error into a machine-readable code and a human message

* resolver: reduce comments

* resolver: reduce comments, remove REVIEW.html

* extend SMP protocol to support name availability queries with accurate and meaningful replies

* review fixes

* more review fixes

* docs shortening and other review fixes

* add catch all for furture variants

* adversarial review (against simplex-chat) fix

* next iteration fixes

* adapt house style

* eth_call guard and cache constants

* revert NAVL command and wrap it all into RSLV

* doc fixes

* Update src/Simplex/Messaging/Server/Names.hs

Co-authored-by: Evgeny <evgeny@poberezkin.com>

* Update src/Simplex/Messaging/Protocol.hs

Co-authored-by: Evgeny <evgeny@poberezkin.com>

* Update src/Simplex/Messaging/Protocol.hs

Co-authored-by: Evgeny <evgeny@poberezkin.com>

* Update src/Simplex/Messaging/Protocol.hs

Co-authored-by: Evgeny <evgeny@poberezkin.com>

* Update src/Simplex/Messaging/Protocol.hs

Co-authored-by: Evgeny <evgeny@poberezkin.com>

* protocol types refactoring

* next iteration on types only

* rentPrices map

* claude answering ep review. to be continued...

* separate labelhash and plaintext names cleanly

* align implementation with latest type changes to test against client

* fix adversarial review findings

* trim diff

* align resolver with contract changes for names v2

* fix reverse compatibility with .testing mainnet

* fix more robustly

* NameQuery simplification

* revert drive-by refactoring

* implement full type change and introduce resolver endpoint versioning

* fix stale docs

* derive NameRegistration JSON the same way on every build

  sumTypeJSON switches to the _owsf form on swift builds, but this JSON is
  the RNAME payload and the resolver's HTTP contract, so a swift client and
  a Linux relay would disagree on every field. taggedObjectJSON is what it
  already resolves to everywhere else.

  The label modifier keeps the reservedReason_ collision escape out of the
  API, as AgentWorkersDetails does: both arms now say reservedReason.

* fix resolver boundary: status before body, cover /v2, drop dead field

  httpGet read the response body before checking the status, so an oversized
  error page surfaced as a transient "response too large" instead of the
  authoritative status. Reverting it to its previous shape restores that and
  removes the status test both callers had been re-deriving.

  registration() had no tests at all, though it is the endpoint SMP v22
  consumes. RegistrationV2Tests covers the three answer shapes, the error
  paths and the exact key set of each, which is the wire contract.

  auctionUntil was always None with no consumer. The spec claimed a reason
  word travels unchanged; a resolver can only send a word it has, and SNRC's
  registry records a number.

* fix review findings

* resolver errors say what went wrong, not "no such name"

  /v2/resolve answers 200, 400 or 502, and an unregistered name is
  NRAvailable, so no status means "not registered". Mapping 400/404/410 to
  NOT_FOUND made a misconfigured relay deny every name, and hid a relay
  upgraded ahead of its resolver. All three now surface as RESOLVER.

  rslvNotFound would have gone dead, so it counts what its name says: an
  availability answer the encoder downgrades for a session below v22. The
  wire is unchanged.

  A hashed query the registrar cannot name is refused with 502 rather than
  answered with a record named "unknown", which the client rejects anyway.
  NRRUnknown is capped to 32 printable characters again, as the spec says.
  A registered name that is also reserved no longer offers a date it will
  never free up on. rentPrices is registrationPrices throughout, and
  yearPriceUSD is USDCents rather than a bare Int64.

* fix regressions found reviewing the last two commits

  resolveNameMsg read the version off thParams', which on the PFWD path is
  the proxy's session, not the client's. It takes the version as an argument
  now, so each call site passes its own — the forwarded one uses fwdVersion.

  reservedReasonOf matched the reason words before capping, so "internal
  review" became NRRUnknown "internal", which encodes back as NRRInternal.
  Capping precedes the match, so what is kept encodes to what it decoded.

  Four agent tests still pinned NAME NOT_FOUND from a 404 stub, and two spec
  statements still described the old mapping. A registrar that does not
  record labels cannot answer a hashed query, which the resolver README now
  says.

* docs sweep

* simplify encoding

* drop resolver caching (#1866)

* rename

* remove trailing_ filter

* fix resolver v2 for subnames (#1867)

* fix resolver v2 for subnames

* simplify doc

* resolver should report response truth freshness (#1868)

* first shot at reporting freshness

* fix review findings

* renaming

---------

Co-authored-by: sh <github.shum@liber.li>
Co-authored-by: Evgeny <evgeny@poberezkin.com>
2026-09-16 09:58:44 +01:00
Evgeny Poberezkin 7f0218e1d5 7.1.0.6 v7.1.0-beta.2 2026-09-12 10:34:03 +01:00
EvgenyandEvgeny @ SimpleX Chat 0b97e025ce xftp server: disable ack command (#1871)
* xftp server: disable ack

* fix tests

---------

Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-09-12 10:06:09 +01:00
EvgenyandEvgeny @ SimpleX Chat a00e225d74 xftp: hash of the shared part of file description (#1865)
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-09-12 08:30:13 +01:00
sh 200129af54 servers: fix stale git commit in version (#1859) 2026-09-03 09:57:50 +01:00
Evgeny Poberezkin 2d4b40e104 7.1.0.5 v7.1.0-beta.1 2026-09-02 10:18:21 +01:00
EvgenyandEvgeny @ SimpleX Chat 1876357c7f xftp server: support storage time and BBS proofs of badge credential to extend it (#1856)
* xftp server: support storage time and BBS proofs of badge credential to extend it

* update

* types

* implementation

* update

* remove permanent and FTTL

* refactor

* refactor

* refactor

* simplify

* simplify

* simpler

* remove comments

* add file expiration time to agent event

* add test of upload with entitlement

* update schema

* fix header and test

* fix store log encoding, add xftp store log tests

* send entitlement proof in handshake

* type, query

* more fixes

* test entitlement keys

* update

* fixes

* fix

* comment

* remove log

* simpler

* ignore entitlement proofs in browser requests

* remove condition

---------

Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-09-01 12:59:00 +01:00
79d1b48252 feat: add server public information handling in XFTP protocol (#1846)
* feat: add server public information handling in XFTP protocol

* test

---------

Co-authored-by: sh <github.shum@liber.li>
Co-authored-by: Evgeny Poberezkin <evgeny@poberezkin.com>
2026-08-31 17:31:57 +01:00
Evgeny Poberezkin ac4bf690b6 7.1.0.4 2026-08-20 09:33:10 +01:00
EvgenyandEvgeny @ SimpleX Chat 0d3cf39c27 agent: fast queue rotation not requiring the current server to be online (#1847)
* agent: fast queue rotation does not requiring the current server to be online

* update plan

* update plan and rfc

* corrections

* update plan

* implementation

* test

* refactor

* test switching notificaitons

* rename

* fix, refactor

* fix possible crash

* simplify

* refactor

* simplify

* refactor

* simplify

* order, avoid re-reading connection

---------

Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
2026-08-20 09:02:41 +01:00
Evgeny Poberezkin c5ff829cfb 7.1.0.3 2026-08-18 13:57:10 +01:00
Evgenyandsh d95eb47a4d agent: drop versions before 07/2024 (support of PQ encryption and securing reply queue) (#1841)
* agent: drop versions before 07/2024 (support of PQ encryption and securing reply queue)

* fix encoding, add error context

* fix agent tests

* fix test

---------

Co-authored-by: sh <github.shum@liber.li>
2026-08-17 12:51:45 +01:00
spaced4ndy c377f2c1b1 xftp: prevent sender from writing files outside the destination folder (#1850) 2026-08-12 18:39:03 +01:00
Evgeny Poberezkin 413f30bee5 7.1.0.2 2026-08-12 10:58:20 +01:00
sh 3996472494 build: expose Server.Information for client_library (#1849) 2026-08-12 10:57:48 +01:00
Evgeny Poberezkin 21568ab277 7.1.0.1 v7.1.0-beta.0 2026-08-10 09:12:44 +01:00
Ed Asriyan e3d53428a0 smp server: fix handshake compatibility by moving server info to SMP v21 (#1845) 2026-08-08 21:27:02 +01:00
spaced4ndy a908de6416 server: prevent concurrent SKEY commands from overwriting queue sender key (#1844)
* server: prevent concurrent SKEY commands from overwriting queue sender key

* wip
2026-08-07 22:27:24 +01:00
Narasimha-scandEvgeny 33c458ffd4 agent: report PRXY broker errors as proxy-to-relay errors (#1842)
* agent: report PRXY broker errors as proxy-to-relay errors

The proxy returns PROXY BROKER errors only when it fails to connect to the
destination relay, but for PRXY they were mapped to SMP <proxy> (PROXY ...),
losing the relay address, so the clients reported them as errors of the
connection to the forwarding server. Map them to PROXY {proxyServer,
relayServer, ...}, the same shape PFWD errors already use.

* Apply suggestion from @epoberezkin

* agent: keep ProxyProtocolError for PRXY broker errors

Reverts 826a2377.

ProxyResponseError wraps PCEResponseError, a response that failed to
parse, and both clients match protocolError when rendering this error,
so the connect alert falls through to the raw error dump - and released
clients cannot render it at all. temporaryAgentError and serverHostError
also match ProxyProtocolError only, so the failure stops being retried
and proxy fallback no longer engages.

---------

Co-authored-by: Evgeny <evgeny@poberezkin.com>
2026-08-06 12:23:44 +01:00
EvgenyandEd Asriyan 0e13d46a2a smp-server: add serverInfoBytes to THandleParams and related functions (#1836)
* smp-server: add serverInfoBytes to THandleParams and related functions

* server information

* fix test

---------

Co-authored-by: Ed Asriyan <service.github@asriyan.me>
2026-08-02 11:45:04 +01:00
Evgeny Poberezkin ee4dd0d8de 7.1.0.0 2026-08-01 12:15:58 +01:00