Server-defined exports
fixed-export selects an authorized producer ID and expected definition hash. The server controls the producer; clients cannot submit remote commands, paths or credentials.
Evelin is a self-hosted, SSH-shaped secure tunnel built in Rust. Every connection uses ML-KEM-1024 for key establishment, ML-DSA-87 for mutual authentication, ChaCha20-Poly1305 for records, and HKDF-SHA-512 for key derivation. It is deliberately not SSH wire-compatible, has one implementation, and has not completed a paid third-party cryptographic audit.
# Quiet by default: stdout stays clean $ evelin-client --config ~/.config/evelin/client.toml exec uptime 22:18:07 up 34 days, 4:42, 1 user # Connection details go to stderr $ evelin-client -v --config ~/.config/evelin/client.toml exec hostname INFO handshake complete · protocol v2 evelin-host # scp-shaped copy, integrity checked $ evelin-client --config ~/.config/evelin/client.toml \ cp ./backup.tar remote:/srv/backups/backup.tar [████████████████████████████] 100%
Receive a server-defined PostgreSQL dump or Forgejo data archive through a dedicated Linux service. Existing keys remain usable; fixed exports are disabled by default.
fixed-export selects an authorized producer ID and expected definition hash. The server controls the producer; clients cannot submit remote commands, paths or credentials.
Private staging, independent SHA-256 and format checks, disk synchronization and a fresh challenge-bound acknowledgement precede publication without replacing an existing file.
Transport shutdown closes waiting channels, late replies to canceled opens are cleaned up, and session cancellation tears down PTY processes and forwarded-agent connections.
Current installation, pinned toolchain and dependencies, exact SHA-256 labels, export setup and recovery are documented in English and Brazilian Portuguese.
Governance documents and five operator guides were added in English and mirrored in Brazilian Portuguese. English remains the conflict-resolution source.
In-place receive decryption, pre-reserved AEAD tag space, shorter mux lock scope, and cloned SHA-256 state for resume remove work. The project explicitly makes no throughput claim from these changes.
crossbeam-epoch and anyhow were updated for 2026 RustSec advisories. The source release passed 439 tests and the audit/deny gates.
The responsible deployment question is not “which table has more green cells?” It is whether post-quantum authentication and a small Rust implementation are worth the ecosystem and maturity costs for your environment.
The algorithm suite is fixed. Protocol v2 negotiates operational capabilities inside the signed transcript; it does not negotiate ciphers.
Each record is a big-endian length plus authenticated ciphertext. Per-direction counters construct nonces. Authentication failure closes the connection instead of attempting recovery.
After 1 GiB per direction by default, HKDF advances that direction’s traffic key, zeroizes the old key, and resets its counter. This is not a full asymmetric ML-KEM rekey.
Unknown TOML keys fail closed. Exec uses an allow-list, file copy uses rooted paths and per-direction enable flags, and server identities must be pinned before connection.
Both peers set max_protocol_version = 2. Capability offers live inside the signed transcript. MAX_FRAME_LOG2 negotiates the lower frame ceiling from 16 KiB to 1 MiB. Tampering changes the transcript and breaks authentication.
The v2 REKEY flag is reserved for future asymmetric ML-KEM rekeying. Session-ticket code exists and is tested, but its older extension path was never wired into the live handshake; treat resumption as dormant, not a current wire feature.
The previous page listed several names that are not current standalone binaries. The public entry point is evelin-client; copy, forwarding, trust, and shell are its subcommands.
| Binary | Closest OpenSSH role | Current purpose |
|---|---|---|
evelin-server | sshd | Server daemon, policy enforcement, rate limits, audit logging, Linux Landlock/seccomp integration. |
evelin-client | ssh + scp | exec, shell, cp, Linux fixed-export, pipe, local/reverse forwarding, SOCKS, jump hosts, proxy-command, and trust management. |
evelin-keygen | ssh-keygen | Generate ML-DSA-87 identity files, optionally wrapped with Argon2id. |
evelin-agent | ssh-agent | Hold unlocked identities in memory over a Unix socket and support agent forwarding. |
evelin-keyscan | ssh-keyscan | Discover the fingerprint a server presents. Discovery is not trust; verify it out of band. |
evelin-multisig-verify | — | Verify multi-signer release manifests. |
evelin-sandbox-probe | — | Check Landlock capability on the host. |
evelin-seccomp-probe | — | Check seccomp behavior on the host. |
evelin-fixed-export-* | — | Linux PostgreSQL/Forgejo backend helpers and an extraction-free archive validator. |
The most important security property of this page is that “implemented,” “tested,” “proven,” and “planned” remain different labels.
Protocol codecs use safe Rust. Explicit unsafe boundaries remain in the C ABI and low-level operating-system/helper code; review their documented invariants rather than assuming the whole workspace is unsafe-free.
ML-KEM-1024, ML-DSA-87, ChaCha20-Poly1305, HKDF-SHA-512, Argon2id for optional key wrapping, and zeroization for secrets.
Client identities must appear in authorized_keys. Server fingerprints are SHA-256 and must be pinned in configuration or added explicitly to known_hosts.
Fixed-export instances require Landlock before runtime startup and keep legacy seccomp off. Ordinary shell instances skip Landlock; ordinary post-runtime seccomp does not filter all existing workers. Platform support must be assessed per mode.
The release tracks Cargo.lock and pins Rust 1.93.0. Formatting, Clippy, workspace tests and dependency gates accompany SHA-256 artifact manifests; consult the release notes for the actual results.
Formal models and internal review are project-authored. A paid third-party cryptographic audit is still a roadmap item.
OpenSSH was not measured on the same Evelin test host, so this website makes no claim that Evelin is faster or slower end to end.
Derived v1 handshake wire cost: 4,200-byte HelloClient, 8,827-byte HelloServer, 4,635-byte Finish; three messages, 1.5 RTT.
Full connect + ML-KEM/ML-DSA handshake + exec + teardown, five loopback runs on one core. This is a CPU floor, not WAN latency.
Isolated ChaCha20-Poly1305 ceiling on 1 MiB blocks, single core with AVX2; open measured 924 MiB/s.
Single-core bulk file-copy range with substantial cross-session variance. A real two-host, multi-core number remains pending.
OpenSSH 10.5 was released August 11, 2026 with security and other fixes. Experimental composite ML-DSA44+Ed25519 signatures, introduced in 10.4, remain an explicit opt-in. Official OpenSSH release notes.
| Criterion | Evelin 4.4.0 | OpenSSH 10.5 | Operational reading |
|---|---|---|---|
| Key exchange | Pure ML-KEM-1024, fixed, NIST category 5. | Hybrid ML-KEM-768 + X25519 is the default. | Evelin uses the higher PQ category; OpenSSH retains a classical backstop. |
| Authentication | ML-DSA-87 mutual authentication is the fixed default. | 10.4 adds experimental ML-DSA44+Ed25519 composite signatures, not enabled by default; mature classical methods remain. | Evelin makes PQ authentication mandatory; OpenSSH offers an opt-in experimental hybrid path. |
| Implementation language | Rust; documented unsafe boundary only in C FFI. | C, with decades of hardening, privilege separation, and current sandbox work. | Memory safety favors Evelin’s language choice; track record favors OpenSSH. |
| Wire ecosystem | Own protocol; one implementation; no SSH compatibility. | Universal SSH-2 ecosystem with many implementations and services. | OpenSSH wins decisively for interoperability. |
| Features | Exec, PTY, copy, forwarding, SOCKS, jump, agent, metrics. | All of those plus SFTP, certificates, PAM/GSSAPI/Kerberos, X11, ControlMaster, extensive config ecosystem. | Use OpenSSH when established SSH integration matters. |
| Sandboxing | Mode-specific Linux confinement; fixed exports require pre-runtime Landlock. | Mature privilege separation and platform-specific sandboxing; Linux seccomp failures are fatal in 10.4. | Both take sandboxing seriously; OpenSSH has broader operational maturity. |
| Handshake size | 17,662 bytes, derived from protocol constants. | Smaller; the project’s older 3–4 KB estimate was for 10.2 object sizes and is not a packet capture. | On constrained/high-latency links, OpenSSH has the wire-cost advantage. |
| External assurance | No completed third-party cryptographic audit. | Decades of public deployment, independent review, and a documented CVE history. | OpenSSH is the lower-maturity-risk choice. |
| License | AGPL-3.0-or-later or commercial. | BSD-style. | License fit depends on distribution and proprietary integration needs. |
No same-host comparative throughput benchmark exists. The table intentionally does not name a universal winner.
Use the v4.4.0 asset list and validation notes for the exact build and runtime coverage. A cross-compiled binary does not establish equivalent sandbox enforcement.
Static-musl tarball plus Debian and RPM packages. The musl binaries avoid glibc dependencies and support per-user installation on GNU Guix. Fixed exports need a compatible Linux kernel and dedicated policy.
Use the architecture-specific Linux and Android assets listed in the release. Android builds target the Android runtime; Linux musl and Android binaries are not interchangeable. Runtime coverage is recorded separately.
Four PE32+ core executables are published without a C API DLL. They were not runtime-tested on Windows, and the Windows sandbox backend remains an unimplemented skeleton.
Mach-O archives lack Apple Developer ID signing and notarization. The arm64 library carries its linker-generated ad hoc signature; this is not Apple distribution approval. Runtime validation on macOS is separate.
A valid package and FreeBSD-ABI ELF were produced, but not run on FreeBSD, and equivalent sandbox enforcement is not implemented.
Verify downloaded files against SHA256SUMS-v4.4.0 before installation. Artifact names and their exact hashes are recorded in the release manifest.
Use absolute paths, mode 0600 for identity and trust files, an exact authorized_keys header, and an out-of-band server-fingerprint check. There is no automatic trust-on-first-use.
# Generate the server identity sudo install -d -m 0700 /etc/evelin sudo evelin-keygen --out /etc/evelin/server.key sudo chmod 0600 /etc/evelin/server.key # /etc/evelin/authorized_keys # evelin-authorized-keys v1 <64-hex-client-SHA256-fingerprint> alice@laptop # /etc/evelin/server.toml bind = "0.0.0.0:2200" identity_key = "/etc/evelin/server.key" authorized_keys = "/etc/evelin/authorized_keys" log_format = "json" log_level = "info" max_protocol_version = 2 max_frame_kib = 1024 [exec] allow = ["uptime", "uname"] [shell] enable = true command = "/bin/sh" [filecopy] roots = ["/srv/uploads", "/srv/data"] allow_upload = true allow_download = true
# Parse policy and keys without binding TCP sudo evelin-server \ --config /etc/evelin/server.toml --check # Start through the packaged service sudo systemctl enable --now evelin-server sudo systemctl status evelin-server # Discover what the server presents evelin-keyscan server.example.com:2200 # Verify that SHA-256 fingerprint out of band.
mkdir -p ~/.config/evelin evelin-keygen --out ~/.config/evelin/id.evelin chmod 0600 ~/.config/evelin/id.evelin # ~/.config/evelin/client.toml server_addr = "server.example.com:2200" identity_key = "/home/alice/.config/evelin/id.evelin" server_fingerprint = "<64-hex-server-SHA256-fingerprint>" log_format = "text" log_level = "info" max_protocol_version = 2
# Clean stdout by default evelin-client --config ~/.config/evelin/client.toml exec uptime # Interactive PTY evelin-client --config ~/.config/evelin/client.toml shell # Upload / download evelin-client --config ~/.config/evelin/client.toml \ cp ./local.txt remote:/srv/uploads/local.txt evelin-client --config ~/.config/evelin/client.toml \ cp remote:/srv/data/report.pdf ./report.pdf
evelin-capi exposes ABI major 1, minor 0 and promises additive changes within v1; breaking changes require ABI v2 and an SONAME bump.
Documented evln_* symbols, stable status codes, caller-owned buffers, library-owned handles, idempotent process initialization, and a documented threading model.
C, Rust, Python, Go, Node.js, Ruby, Java, Swift, .NET, Elixir, OCaml, and Guile. Rust is native; the others bind through the C surface.
Evaluate each binding’s README and tests. The current Swift directory is a packaging/module shim with no Swift source and should be treated as a skeleton, not a complete SDK.
The English documents are canonical when translations diverge. The roadmap has no dates or version promises and separates current code from future work.
Opt-in transcript-bound capability negotiation, negotiated record-frame limits, downgrade tests, and STATED v2 formal models.
Four defects were published and fixed; the full binaries passed T1–T7, including v1 fallback, negative auth, 64 KiB frames, and byte-identical file copy.
Governance/user guides, in-place receive decryption, reduced copy/allocation work, advisory updates, and 439 tests without a throughput claim.
Clean stdout, stderr-only logs, familiar verbosity, explicit progress percentage, 440 tests, and no wire/server change.
Dedicated Linux PostgreSQL/Forgejo exports, durable validated publication, connection cleanup, locked release inputs and updated EN/pt-BR guides.
No. The workflows are intentionally familiar, but the wire protocol, identities, trust files, and ecosystem are different. Both endpoints must run Evelin.
The project is self-deployed and Linux x86_64 release artifacts are production-validated by the maintainer. It still has no completed third-party cryptographic audit. Use it where you control both endpoints, can keep OpenSSH as recovery, and can evaluate the threat model yourself.
SHA-256 of the encoded ML-DSA-87 public key, rendered as 64 lowercase hexadecimal characters. The v4.4.0 README and user guides use this same definition.
Not as a live negotiated wire feature. Ticket machinery exists and is tested, but the extension path it depended on was never connected to the live handshake. True 0-RTT application data was explicitly rejected.
The fixed pure-PQ design reduces negotiation and uses category-5 parameters, but removes the classical X25519 fallback that protects OpenSSH’s hybrid KEX if ML-KEM fails. This is an explicit trade-off, not an unconditional advantage.
Email sac@securityops.co. Plaintext is acceptable for initial contact; the policy states a temporary PGP key will be supplied for exploit details. The default disclosure window is 90 days after acknowledgment.
AGPL-3.0-or-later or a commercial license. Review NOTICE for the project’s interpretation and contact SecurityOps for proprietary integration that cannot comply with AGPL obligations.