A collaborative coding-agent orchestrator for atproto radl.app

private spaces with iroh #3msgmgabf5u22

Closed opened by and assigned to disnetdev.com
· · targeting main

Implements the substrate half of the v3 private-mode plan: a space's records can travel as signed envelopes instead of living on public PDSes, and the unchanged materialize() folds them.

The load-bearing decision is the two-gate rule. Envelope admission (core/src/private/admission.ts) checks cryptography and quotas only — version, space binding, canonical encoding, recordCid, lexicon validity, and a signature under a key the envelope's own DID published, revoked or not. Every trust decision stays in the pure fold (core/src/devices.ts). Checking revocation at admission would make a store's contents depend on when a revocation arrived, and with no PDS to re-fetch from, no later sync could repair the divergence. Revocation is therefore retroactive in the index, exactly as removeMember is; rotation is fold-neutral and re-enveloping is the recovery path, so a version carries the SET of devices that signed it and counts while any one is bound.

Lexicons (additive): space.private, four optional join fields, and new device, deviceAddress, revokeDevice and removeDevice collections. The directory is read from the public path only — a key published inside an envelope would vouch for itself. deviceAddress becomes the third sanctioned in-place rewrite, safe only because address hints are excluded from the device fold by construction.

Guest comments are refused twice in a private space: the fold ignores setGuestComments and pins guestCommentsEnabled false, and the UI hard-gates the Constellation query on index.private with a test asserting no request leaves.

The envelope stack is isomorphic and dependency-free — DAG-CBOR, atproto record CIDs, TIDs and Ed25519 over WebCrypto — and its CIDs are pinned against eight records real PDSes computed CIDs for. Quarantine is bounded and every eviction writes a durable want entry, so catch-up re-requests explicitly rather than inferring completeness from summaries.

Not built: the iroh transport itself, daemon configuration and operator commands, and the browser's device management and recovery flows. MemoryPrivateBus stands in for the transport in every test. docs/design.md §18 and docs/adr-private-mode-iroh.md record the protocol, the decisions, and what remains.

Co-Authored-By: claudebot.disnetdev.com (did:plc:n6ku5xddiuguwze3f356evla) claudebot.disnetdev.com@noreply.radial

Delete this pull request?

This cannot be undone.

Labels

  • No labels

This pull request has no versions submitted yet.