Repository navigation
v0.3.5 — the Conduit over the Shrine path
A Pilgrim could fetch a page (Oracle), attend a live feed (Auspice) and pull verified bulk content (Relic), but never simply hold a session. The Conduit — the raw duplex rite, framed and sealed but otherwise uninterpreted — is now reachable from a Pilgrimage.
Closes #3.
What's new
// Host
node.HostShrine(signet, handler, feeds, relics, conduit: new DelegateConduitHandler(async (session, token) =>
{
while (await session.ReceiveAsync(token) is { } frame && !frame.IsSealed)
await session.SendAsync(Handle(frame), token);
}));
// Pilgrim
await shrine.Conduits.SendAsync(new ConduitFrame { ProtocolId = 7, SchemaVersion = 1, Flags = 0, Payload = bytes }, ct);
var reply = await shrine.Conduits.ReceiveAsync(ct);IConduitHandler, DelegateConduitHandler, ConduitHost.ServeAsync, a HostShrine overload, the matching AcceptPilgrimageOverVesselAsync, and ShrineSession.Conduits — the last in CupriNet.Shrine, so it reaches a WASM build. One conduit on stream 4, with ProtocolId as the discriminator.
This is the seam an existing framed protocol lands on when it moves to L2: the transport below it changes, the protocol above it does not. Without it, such a protocol had to be re-expressed as Oracle consults plus Auspice topics — a second implementation of its own semantics, kept in sync forever.
Keyless and author-less, deliberately
The Pilgrimage constructor takes no session key: the Noise vessel is already the confidentiality and authenticity boundary there, as it is for the Oracle, Auspice and Relic, so no key is plumbed out of the handshake. It takes no author identity either — authenticated authorship belongs in an Arcanum channel where members are durable; on a visit the Pilgrim is meant to be unlinkable, and signing frames under a lasting key would quietly undo that.
What the Shrine path adds, because a browser is on it
- the 192 KiB payload ceiling both ways, so an oversized frame fails at the rite naming the Relic, not inside an SCTP association that rejects it. The Arcanum conduit keeps the 16 MiB a Vessel frame allows, and its wire is unchanged byte for byte;
- padding on by default — a duplex session leaks size and timing at least as richly as a live feed;
- a sealed frame when no conduit is hosted or a handler throws, so a peer is told rather than left waiting;
- the
conduitCupriMark component, on Pilgrimage frames only.
One bad rite still never takes the Shrine down: ConduitHost drains after sealing rather than returning, since the accept loop ends a visit when any rite's loop ends.
434 unit tests green.