Expand description
Diavlos core: keys, signed messages, invites, rooms, and the inbox.
This crate has no network code and no async runtime. It is the part
every door (MCP, CLI, library) shares, and the part that is easiest to
audit. The helper daemon in the diavlos crate puts a network and a
local socket around it.
Delivery promise, in writing: at-least-once, dedup by id, on disk before
send returns.
Re-exports§
pub use control::ControlOp;pub use error::Error;pub use error::Fate;pub use error::Result;pub use invite::Invite;pub use invite::InviteSpec;pub use keys::Identity;pub use keys::Kind;pub use keys::Profile;pub use keys::PublicKey;pub use keys::SignedProfile;pub use keys::Signer;pub use limits::Limits;pub use message::Action;pub use message::AgentInfo;pub use message::DataClass;pub use message::Draft;pub use message::Message;pub use message::MessageType;pub use policy::DefaultHook;pub use policy::FileMode;pub use policy::Policy;pub use policy::PolicyHook;pub use room::Member;pub use room::Role;pub use room::Room;pub use store::Delivery;pub use store::DeliveryState;pub use store::FileRefRow;pub use store::LocalMember;pub use store::OutboxCounts;pub use store::OutboxEntry;pub use store::OutboxState;pub use store::Settle;pub use store::SpendOutcome;pub use store::SpendRecord;pub use store::SpendRequest;pub use store::Store;pub use store::StoredFile;pub use store::WakePending;
Modules§
- bundle
- Signed audit bundles.
exportmakes one;verifychecks it with no helper running. For auditors. - canonical
- Canonical JSON: the one byte string everyone signs and hashes.
- control
- Control messages: pause, mute, revoke, grant. Owner key only. Changes who may do what. Signed, instant, everyone obeys.
- error
- One error type for the whole of Diavlos.
- faults
- Named places where a test can make an operation fail on purpose.
- files
- Files on a message: the reference a message carries, and the checks that never trust the sender. See docs/FILES.md.
- invite
- Signed invites.
- keys
- Identity: a keypair with a kind, a signed profile, and a claims slot.
- limits
- Floods and loops: rate limit per sender and a daily budget per room. Both on by default. Two agents in a loop stop before your API bill notices.
- message
- What a message looks like.
- names
- Names: ASCII lowercase only, so look-alikes can’t exist.
- policy
- Policy hook. One rule in v0.1: which verbs need a human approve. A small file per room. The rule engine grows later; the hook point is what can’t be added later without a rewrite.
- room
- Rooms, members, and roles.
- secrets
- Outbound secret scan: refuse to send anything that looks like a common API key, token or private key.
- store
- The inbox: one SQLite file per helper.
Constants§
- PROTOCOL_
VERSION - Wire protocol version between helpers. Bump on incompatible change.
- VERSION
- Version of this crate, for the version handshake.