Skip to content

v0.6.3

Latest

Choose a tag to compare

@github-actions github-actions released this 11 Sep 00:21
· 2 commits to main since this release
f25d17c

qntm v0.6.3

This release adds encrypted file attachments and recipient-sealed current-epoch recovery for an identity that is already an authorized group member. It preserves the v0.6.2 client, gateway, strict-signature and private fragment-link behavior.

Encrypted attachments

Python and TypeScript can encrypt, upload, reference, download and authenticate attachment ciphertext. File keys travel inside the encrypted conversation message. Size and wire-format checks reject malformed descriptors and payloads. See the attachment guide.

Current-epoch membership recovery

The Python CLI can export a signed checkpoint sealed to a specified existing member and import it using that member's identity. The checkpoint binds its issuer, recipient, group, epoch and authenticated roster. It supplies no earlier epoch keys. Export is not an admission operation, and possession of a forwarded token cannot give another identity access.

This is distinct from the contact welcome delivery flow tracked in the membership design. It adds no stranger-entry endpoint, pending membership or permissionless request mechanism. Existing legacy bearer invites keep their compatibility behavior; they do not gain new authority.

Group control preserves the immutable creator and administrator restrictions. Gateway acceptance alone cannot grant blanket membership control: delegated control requires administrator authority, or independently verified matching quorum evidence including an administrator's affirmative authorization. Removal, later epochs, replay and competing rekey orders are checked against the authenticated source state.

Compatibility and validation

The release retains upstream strict Ed25519 validation and private fragment invitation links. Archived governance votes remain authenticated when transport TTLs have elapsed; live action validity uses the receiver's clock. A narrow test-harness correction handles an owned macOS process during its transient exiting state without treating a live process as cleaned up.

The release workflow runs maintained-client, installed-package and cross-surface acceptance gates. These checks use synthetic local conversations and do not claim to inspect or preserve an operator's private message history. See QSP v1.2 for the extension contract.

pip install --upgrade qntm==0.6.3
npm install @corpollc/qntm@0.6.3