日志暂以英文提供 · the log is in English for now

传输日志/2026-08-13v0.1.2

0.1.2 — one person, several devices

   ·  ✦   ·        ╭──────────────╮       ·   ✦
 ✦    ·      ·     │  0 . 1 . 2   │  ·        ·
   ·    ✦          ╰──────────────╯     ✦   ·

Your phone and your computer can now be the same you: the same spaces, the same history, the same person your friends write to — while each device keeps its own key, its own chain of events and its own path into the network. A lost device is revoked; the others carry on.

Pair a phone to your computer

Settings → Devices → Pair a new device. A code that lives for sixty seconds — paste it on the new device, or play it as sound in the room. Six digits appear on both screens; compare them, and confirm on both.

Those digits are derived from the live encrypted session between the two devices, so a recording replayed later shows different digits and a man-in-the-middle shows different digits on each screen. Comparing them is the whole defence, and it is enough.

What travels to the new device: your certificate, your spaces, their current keys, and your own names for your rooms. What never travels: the root of your identity. Only your first device holds it — only it can add or revoke devices — so a stolen phone cannot mint a replacement for itself. Your passphrase does not travel either: it encrypts one device, and you set one on the new device (the same one, if you like).

Devices are certified, and it is enforced

Every device now carries a certificate signed by the person’s root key, and every replica checks it before admitting a message. A message that arrives before its device’s certificate is held, not dropped, and admitted the moment the proof arrives — on every transport, including the ones that forget what they handed over. The rule this release adds to the kernel: a temporary admission failure must never be converted by transport, deduplication, or caching into permanent refusal.

Spaces created before this release keep working without migrating a byte of their history — proven against a genuine pre-certification data directory, both for an existing replica and for a fresh one.

Revoke a lost device

Settings → Devices → Revoke, twice. Honestly: the device stops speaking at once and forever; what it said before stands; your own rooms rotate their keys on the spot, so it reads no further; rooms owned by others rotate when their owners do.

Smaller things

  • A person on several devices is one participant in every room, not a crowd of namesakes; each device shows under its own name.
  • Member cards carry a small pictogram for the kind of participant behind a name — human, agent, bot, sensor, gateway.
  • The four-digit login code can be set from the desktop (Settings → Devices); on the phone it lives on the “This device” tab, in hardware.
  • On the phone, the first screen offers to pair, and asks before erasing an identity that is already there.

Guide: docs/guide/DEVICES.md. Design record: ADR-022 — ingress custody.


Needs the new build — macOS · Linux · Android. Pairing requires v0.1.2 on both devices.

Still true: no media over LoRa · a relay sees sizes and timing · public spaces are signed plaintext · no Windows build · a lost keystore is a lost space.

在 github 上的发布 ↗下载构建 →