Session Chat is a protocol-first project for disposable, end-to-end encrypted conversations with pluggable admission and delivery. The project is currently a headless research and implementation laboratory, not a deployable chat product.
Current milestone: Phase 1 is complete. The security-stabilized source-only
protocol-laboratory prerelease for the next two-computer test is documented as
v0.1.0-alpha.2.
The design principle is: publish the door, not the key.
The Rust workspace currently contains:
session-protocol, with a bounded opaque envelope, canonical v1/v2 domain-separated Ed25519 capability invitations, and bounded canonical protected-join outer, inner, AAD, and local deposit-endpoint value typessession-core, with configurable expiration checks and a bounded inviter-owned v1/v2 availability, reservation, release, and post-membership consumption lifecyclesession-admission, with an object-safe, provider-neutral approval context that exposes no proof, bearer capability, parsed KeyPackage, or membership authoritysession-crypto, with the provider-neutral established-session message seam implemented by the current MLS adaptersession-crypto-hpke, with provider-neutral one-shot RFC 9180 PSK join protection, an AWS-LC implementation, an RFC known-answer vector, and an independent-provider interoperability test, plus provider-owned creation of every random invitation-v2 fieldadmission-capability, with HPKE-proof provenance, exact provider-validated KeyPackage ownership, bounded in-memory request-ID/nonce replay reservation, exact v2 invitation binding, the shared non-authorizing approval seam, and ownership-preserving invitation/MLS prepare/apply coordinationsession-crypto-mls, with an isolated in-memory two-party MLS 1.0 adapter for bounded KeyPackage validation, Add/Welcome, messages, path updates, and removalsession-native-fs, a publish-disabled safe boundary around the narrow Windows file/DACL operations required by the FastV1 evidence harnesssession-transport, with provider-generated, right-specific local Welcome mailboxes, one-envelope idempotency, expiry, bounded in-memory state, and the provider-neutral right-specific opaque-envelope transport contracttransport-memory, with bounded deterministic drop, hold, duplicate, reordering, retry, and acknowledgement controls for headless protocol teststransport-iroh, with a bounded authenticated Iroh frame link used by the explicit FastV1 online experiment; it is not an offline mailbox or a complete reusable transport providertransport-conformance, with publish-disabled, offline adverse-trace parsing and reusable LocalV1 memory-adapter verdictssession-inviter-transaction, with a bounded fault-injectable conformance model for atomic invitation/replay/approval/MLS-snapshot/Welcome-outbox statesession-storage, with a deterministic session-scoped sealed-vault lifecycle, bounded external unlock preparation, one-shot credential acquisition, cancellation/stale-result rejection, and a bounded canonical opaque inbox whose local import requires the exact open session and state generationkey-protector-passphrase, with an exact-session Argon2id/AES-256-GCM wrapped-key protector behind that lifecycle contract; it remains a non-production conformance adapter and does not supply SQLCipherstorage-sqlcipher, with a keyed file-backed laboratory adapter proving the real inviter MLS/join/outbox transaction and the separate joiner MLS plus one-time-KeyPackage deletion transaction on required Linux, macOS, and Windows CI runnersstorage-sqlcipher-fault-vfs, with a publish-disabled, explicitly selected named SQLite VFS for bounded L2 fault evidencesessionctl, with headless in-process and bounded independent-process Alice/Bob conformance flows covering protected join, explicit approval, SQLCipher close/reopen and application-kill recovery, Welcome delivery, bidirectional MLS messages, path update, removal, and post-removal rejection over local test adapters, plus an explicitly selected scripted two-computer proof over the experimental Iroh FastV1 link
The signing key authenticates the invitation bytes, not a GitHub identity or
person. The capability invitation is a secret bearer object and must not be
posted publicly or placed in a transport envelope. The MLS adapter exposes a
generic persistence boundary, and the headless conformance client composes its
approved Add with SQLCipher and a durable Welcome outbox. Invitation,
approval, and replay shadows remain in the initialization process and cannot be
reloaded as one durable authorization owner in that in-memory composition; its
LocalV1 delivery path is not a network path.
The protected-join and capability-admission adapters prove possession for one
exact typed HPKE context, preserve the exact signed-invitation instance,
independently validate and own the exact KeyPackage, and reserve replay values
within bounded in-memory state. The approval-gated path binds that value to the
local v2 invitation reservation before MLS preparation. Explicit rejection,
expiry, pre-commit failure, or abandonment releases both reservations; a
successful in-memory Add consumes invitation state. This sequencing is not a
durable transaction. A separate conformance model now proves the required
atomic visibility, ambiguous-commit recovery, and resumable Welcome-outbox
semantics over bounded memory records. The SQLCipher laboratory separately
proves both owner-local transactions through actual MLS persistence calls.
Integrated product persistence for approval/replay/invitation state, network
mailbox behavior, human approval UX, and a user-facing chat interface remain
unimplemented. The in-memory approved-join result now carries
only the exact authenticated deposit endpoint beside its MLS outputs, and a
retained test delivers the encrypted Welcome through the local adapter. The
SQLCipher conformance path separately proves its durable outbox; neither path
proves a network profile.
The sessionctl binaries compose those present pieces into an in-process flow
and an ADR 0021 independent-process conformance run. The latter keeps the
bearer invitation outside the forwarding interface and transfers the disposable
SQLCipher key through an Alice-only inherited pipe. It admits only canonical
public wire objects to bounded IPC, reloads
Alice in a fresh process, and prints only a redacted manifest. The same-account
processes are not OS-isolated; running truly untrusted local code remains
unsupported. This is retained
integration evidence, not a deployable client, human approval UX, durable
vault, hosted realm, abrupt-crash guarantee, or production transport.
The session-storage model now rejects key protectors whose factual capability
report is weaker than the selected policy, bounds concurrent unlock work, and
accepts only a result bound to the current vault instance, session, and
generation. The portable passphrase adapter exercises that boundary with a
one-shot credential, but storage-sqlcipher remains disconnected and no
production platform protector exists.
The required cross-platform build and bounded L2 fault matrices are now
configured; rollback resistance, power-loss/filesystem evidence, packaging,
and production key protection remain unimplemented.
ADR 0018 makes macOS, Windows, and Linux a single local-app delivery gate. The required Rust CI matrix now builds, lints, and tests the workspace on all three; native capabilities may add stronger modes behind shared interfaces, but a platform-only implementation is not considered a completed feature.
ADR 0014 defines the exact local-only invitation-v2, HPKE capability-join, and one-Welcome response contract. Its canonical protocol value types are now implemented and tested, its one-shot HPKE operation has RFC and cross-provider evidence, and its capability-admission boundary now retains explicit simulated approval plus in-memory invitation/MLS/Welcome-delivery coordination. The SQLCipher laboratory retains one atomic inviter MLS/outbox transaction, while human approval UX, a durable product authorization owner, rollback resistance, and network behavior remain accepted design boundaries rather than production claims.
cargo fetch --locked
cargo fmt --all --check
cargo clippy --workspace --all-targets --all-features --locked --offline -- -D warnings
cargo test --workspace --all-features --locked --offline
RUSTDOCFLAGS="-D warnings" cargo doc --workspace --all-features --no-deps --locked --offline
cargo deny --all-features --locked check
cargo run -p sessionctl --locked --offline
cargo run -p sessionctl --bin sessionctl-l1 --locked --offlineThe retained JavaScript research and repository tooling have no third-party runtime dependencies:
node --test scripts/check-repository.test.mjs scripts/setup-codex-links.test.mjs
node --test spikes/sealed-invitation-provider/test/provider.test.mjs
node scripts/check-repository.mjsThe Astro project under site/ presents the product thesis, protocol
flow, security claim ledger, current implementation, and roadmap. GitHub Pages
publishes it at dills122.github.io/session-chat.
cd site
npm ci
npm run check
npm run build
npm run dump:copy
npm run devnpm run dump:copy regenerates site/CONTENT_DUMP.md from the production
build so reviewers can assess every route without the visual layout. CI rejects
copy changes that leave this generated review artifact stale.
The site must preserve the same implemented, accepted-but-unimplemented,
proposed, deferred, and out-of-scope claim boundaries as the canonical v2
documents. The Pages workflow builds only static output from master.
apps/contains headless composition and conformance clients.crates/contains retained Rust protocol code.docs/contains the product definition, architecture, threat model, roadmap, research, ADRs, and legacy evidence.spikes/contains disposable feasibility experiments; production crates must not depend on them.scripts/contains tested repository setup tooling.site/contains the static Astro project and its portable design tokens.
Start with the v2 document index. Security claims are bounded by the evidence recorded there and in the tests. The secure-development policy explains the required merge gate and the repository settings that must back it.
The retired Angular/NestJS prototype is preserved by the legacy-v1 tag rather
than duplicated in the active source tree. See the
legacy archive index for recovery commands, behavior,
and security lessons.