mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-06 03:38:23 +00:00
Publishing preview records was blocked on one thing: the spec requires a publisher to never restart or reuse a `seq` for one key context — "including after reconnect, retry, process restart, or daemon resume" — and to stop publishing entirely when it cannot prove which value is next. That is a cryptographic requirement, not bookkeeping. `seq` is XORed into the ChaCha20-Poly1305 record nonce and the key is fixed for the stream, so a repeated `seq` repeats a (key, nonce) pair, which leaks the XOR of the two plaintexts and forfeits authentication for every record under that key. `AgentTextStreamPublisher` owns that discipline. Sequence values are reserved in the durable store before a record is handed out, in windows so a chatty stream is not a write per record — a crash then skips the unused tail of a window rather than replaying it, and a gap is something the transport binding already handles while a repeat is a nonce collision. `resume` returns null, rather than starting over at 1, both when nothing was retained and when the stream was finished or aborted; the caller falls back to the authoritative final kind:9 and a later preview needs a fresh stream id. A frame the group's `max_plaintext_frame_len` refuses is rejected before it claims a value, so a refused frame does not leave every receiver with a permanent gap where no record ever existed. Only an in-memory sequence store ships here. `send` (0xF2D2) and `fanout` (0xF2D4) stay unadvertised: there is no QUIC data plane behind them yet, and claiming a role we cannot serve is worse for a group than not claiming it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016kCuA6tc4JQzHPCDd39GHq
quartz plans
Audited 2026-09-08. 12 plans: 7 shipped (archived), 0 in-progress, 4 queued, 1 closed (negative result).
Queued
| Plan | Summary |
|---|---|
| 2026-05-08-local-headers-explorer.md | Headers-only Bitcoin P2P client to verify NIP-03 OTS attestations without a trusted block explorer. |
| 2026-06-12-giftwrap-deletion-requests.md | Let a recipient-authored kind-5 delete/block a gift wrap (kind 1059) addressed to them. |
| 2026-07-03-incremental-negentropy-storage.md | Always-current (created_at, id) index so cold NEG-OPENs stop paying a full scan + seal (~340 ms at 50k vs strfry's ~21 ms). |
| 2026-07-04-small-req-floor.md | Small-REQ dispatch floor: decomposed, inline fast path tried and reverted (no wire-level win); floor is transport-side. |
| 2026-08-13-gpu-pow-mining.md | GPU NIP-13 mining declined (ARMv8 has SHA-256 in silicon, mobile GPUs do not). Midstate is ~3x on JVM targets; Android hinges on Conscrypt per-digest JNI cost, still unmeasured. created_at refresh while mining shipped. |
| 2026-09-08-marmot-spec-resync.md | Marmot moved off the MIP-era spec (2026-07-02): group state split into app_data_dictionary components, account identity proof v2, and a convergence engine. Current MDK rejects our groups outright. Gap analysis + 8-stage plan; Stages 0-4 done (mdk interop reference, app_data_dictionary, identity proof v2, the six group components, transport corrections); lifecycle + branch selection landed. |
Archived (shipped)
| Plan | Summary |
|---|---|
| archive/2026-06-03-fix-nip46-bunker-double-resume-plan.md | Fix NIP-46 bunker double-resume crash and retry id-reuse races via Channel-per-request + fresh id per attempt. |
| archive/2026-06-04-auth-scope-vs-policy.md | Move relay-server authenticated-identity state from the policy into the engine-owned connection scope. |
| archive/2026-06-09-clink.md | Implement CLINK (Offers/Debits/Manage) Lightning-over-Nostr pointers, events, and client/server in Quartz. |
| archive/2026-06-11-runstr-interop.md | RUNSTR kind-1301 workout events and supporting fitness kinds in Quartz plus Amethyst fitness screens. |
| archive/2026-06-19-napplet-nip5a-resolver.md | Platform-agnostic NIP-5A static-site resolver verifying content-addressed Blossom blobs against signed manifests. |
| archive/2026-06-20-powr-interop.md | Parse and render the POWR/NIP-101e kind-1301 strength-workout dialect alongside the existing RUNSTR dialect. |
| archive/2026-06-28-git-smart-http-browser.md | Git smart-HTTP v2 client to browse NIP-34 repo file trees and render source from the clone URL. |