Skip to main content

Crate m4a_agent

Crate m4a_agent 

Source
Expand description

The agent-side client. One session = one identity = one nick = one credential set, and the CLIENT resolves all of it: the agent behind it never sees a password, an environment variable or a key. See plans/agent-client-tiers-2026-10.md.

This is step 1 of the migration: the identity and the vault, the backend trait, and login by key signature. The tiers live behind cargo features (tier-server, tier-matrix); the full pack is the default and a light build turns features off.

Re-exports§

pub use backend::Backend;
pub use backend::BackendKind;
pub use backend::Capabilities;
pub use backend::Session;
pub use error::AgentError;
pub use error::Result;
pub use identity::IdentityStore;
pub use identity::SessionIdentity;
pub use resolver::ResolvedSession;
pub use resolver::ResolverChain;
pub use resolver::SessionResolver;
pub use vault::FileVault;
pub use vault::KeyVault;
pub use vault::MemoryVault;

Modules§

backend
The backend trait: what the client needs from any tier. Tiers are cargo features, so a tier that is not wanted is not compiled.
bridge
Bridges to other messengers, inside the client, on the user’s machine, nowhere else.
engine
The engine driver: runs the sans-I/O messenger core against a [Backend]. The shell used to own this; it now only adds what is its own (wake, local bus, sealed files on disk).
error
identity
The session identity: one session = one identity = one nick = one credential set.
keyauth
Login by signature, the client half (the verifier half is m4a_seam::keyproof plus the product kit’s ChallengeBook). Shared by every tier that talks to a product door; transport comes in through Wire.
resolver
Which session is this process? One question, asked of ordered sources (a host’s agents directory, the CLI’s active sessions, a provider hook, the OS attestation of the local mail node…). Sources only name the session; identity, nick and credentials are the IdentityStore’s business, so they cannot disagree about them.
vault
The key vault: where the client keeps what the agent must never see (identity seeds, store keys, session tokens). Values are looked up by label.
vault_backup
Encrypted backup of the whole vault: one file under a passphrase the owner holds (argon2id for the key, AES-256-GCM for the content). It is the way to move a vault between master-key homes and to survive a lost machine; the file is useless without the passphrase.