new fixes
This commit is contained in:
1 parent
075a35b441
commit
ae14782da4
12 files changed
+412
-23
No files matched your search
+17
-4
@@ -42,7 +42,7 @@ values:^[
|
||||
|
||||
This document describes the simplified, production‑ready stack for content discovery and sync:
|
||||
|
||||
- Upload via tus → stream encrypt (ENCF v1, AES‑GCM‑SIV, 1 MiB chunks) → `ipfs add --cid-version=1 --raw-leaves --chunker=size-1048576 --pin`.
|
||||
- Upload via tus → stream encrypt (ENCF v1, AES‑256‑GCM, 1 MiB chunks) → `ipfs add --cid-version=1 --raw-leaves --chunker=size-1048576 --pin`.
|
||||
- Public index exposes only encrypted sources (CID) and safe metadata; no plaintext ids.
|
||||
- Nodes full‑sync by pinning encrypted CIDs; keys are auto‑granted to trusted peers for preview/full access.
|
||||
|
||||
@@ -55,7 +55,7 @@ Header (all big endian):
|
||||
```
|
||||
MAGIC(4): 'ENCF'
|
||||
VER(1): 0x01
|
||||
SCHEME(1): 0x01 = AES_GCM_SIV (0x02 AES_SIV legacy)
|
||||
SCHEME(1): 0x03 = AES_GCM (0x01 AES_GCM_SIV legacy, 0x02 AES_SIV legacy)
|
||||
CHUNK(4): plaintext chunk bytes (1048576)
|
||||
SALT_LEN(1)
|
||||
SALT(N)
|
||||
@@ -64,7 +64,21 @@ RESERVED(5): zeros
|
||||
|
||||
Body: repeated frames `[p_len:4][cipher][tag(16)]` where `p_len <= CHUNK` for last frame.
|
||||
|
||||
AES‑GCM‑SIV per frame, deterministic `nonce = HMAC_SHA256(salt, u64(frame_idx))[:12]`, AAD unused.
|
||||
AES‑GCM (scheme `0x03`) encrypts each frame with deterministic `nonce = HMAC_SHA256(salt, u64(frame_idx))[:12]`. Legacy scheme `0x01` keeps AES‑GCM‑SIV with the same nonce derivation.
|
||||
|
||||
For new uploads (v2025-09), the pipeline defaults to AES‑256‑GCM. Legacy AES‑GCM‑SIV/AES‑SIV content is still readable — the decoder auto-detects the scheme byte.
|
||||
|
||||
### Local encryption/decryption helpers
|
||||
|
||||
```
|
||||
python -m app.core.crypto.cli encrypt --input demo.wav --output demo.encf \
|
||||
--key AAAAEyHSVws5O8JGrg3kUSVtk5dQSc5x5e7jh0S2WGE= --salt-bytes 16
|
||||
|
||||
python -m app.core.crypto.cli decrypt --input demo.encf --output demo.wav \
|
||||
--wrapped-key <ContentKey.key_ciphertext_b64>
|
||||
```
|
||||
|
||||
Because we use standard AES‑GCM, you can also re-hydrate frames manually with tools like `openssl aes-256-gcm`. The header exposes `chunk_bytes` and salt; derive the per-frame nonce via `HMAC_SHA256(salt, idx)` where `idx` is the frame number (0-based) and feed the 12-byte prefix as IV.
|
||||
|
||||
## API
|
||||
|
||||
@@ -94,4 +108,3 @@ Window ±120s, nonce cache ~10min; replay → 401.
|
||||
## Keys policy
|
||||
|
||||
`KEY_AUTO_GRANT_TRUSTED_ONLY=1` — only KnownNode.meta.role=='trusted' gets DEK automatically. Preview lease TTL via `KEY_GRANT_PREVIEW_TTL_SEC`.
|
||||
|
||||
Reference in new issue
Block a user