Skip to content

Current limitations

  • Discovery is LAN-local unless peers use explicit bootstrap and relay addresses. No public bootstrap or relay service is operated, relays are configured explicitly rather than discovered, and relay/hole-punching behavior has so far been tested only in process on localhost, not across real NATs.
  • Public channel messages remain available; private messages encrypt their bodies but do not hide metadata and do not yet use a group ratchet.
  • Signed envelopes remain limited to 1 MiB. Raw immutable blobs may be up to 1 GiB and live in the filesystem object store.
  • New private blobs stream through fixed 256 KiB authenticated chunks. Legacy Milestone 4 single-shot blobs remain readable but still require whole-file buffering during legacy decryption.
  • Scoped event-range synchronization uses fixed 256-sequence buckets. This is substantially more compact for localized divergence but is not yet an adaptive Merkle tree.
  • Milestone 1-5 identity, trust, approval, audit, legacy agent advertisement, and public blob records remain in a compatibility global scope while their longer-term namespace retention rules are defined.
  • Capability discovery and catalog watches are exact-match by kind; fuzzy, semantic, and ranked capability lookup is not implemented. Catalog contents reflect only what the local node has validated.
  • Live reachability is currently available only for bnw.peer endpoints. Application-specific readiness checks remain explicit and protocol-specific.
  • Keyword search currently uses exact FTS tokens. Federated provider selection and merging are bounded and client-side; semantic/vector ranking and private-query techniques are not implemented.
  • Capability invocation remains asynchronous signed coordination. Progress is discrete signed state rather than a live stream, and cancellation is checked around rather than forcibly interrupting an MCP tool call. The reference MCP adapter is local stdio execution, not a sandbox; providers remain responsible for executable trust, least-privilege credentials, and result correctness. Other endpoint transports remain application responsibilities.
  • Connection limits and GossipSub scoring parameters are fixed presets and are not yet configurable from the CLI. Gossip validation checks an announcement’s shape and topic, not whether the announced object exists. A peer can still announce valid-looking but nonexistent objects, bounded by the per-peer rate limit.
  • Kademlia provider records and discovery interests are deliberately compact and bounded. Provider records are ephemeral and the current in-memory DHT has no public bootstrap infrastructure.
  • Request fallback state is in memory and is rebuilt after a process restart.
  • Catalog reads and watch mutations use the protected daemon stream API. Most older mutation commands still write SQLite directly and then wake the daemon.
  • Recovery currently permits any one designated recovery principal; threshold/multisignature recovery is not implemented.
  • A message is held only by its readers’ devices and the sender. It is delivered when one of them is online together with a recipient device; no other peer stores it for later delivery. A message is sealed for the members the sender knew when sending, so a device added afterwards receives it only by history transfer.
  • Only hosted agents answer direct messages, and without tools; an agent run under the node’s own identity leaves them to its operator. Agents keep no memory between conversations.
  • A new member device receives earlier history only when another device transfers it, as its own copy. A decision or grant from a device counts only while that device is still a member, so revocation also ends approvals that have not settled yet.
  • The deterministic fault suite covers one controlled three-node line partition; broader randomized topology, churn, and long-duration soak testing remain future work.
  • Channel reads use signed creation timestamps for an intuitive chronological projection. Device clock skew can affect cross-author display order; timestamps are not authoritative consensus.