Dehydrated devices (MSC3814): spec section first, then create/rotate/claim #107
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Sub-issue of #86. The spec has no dehydrated-device text: add it under §10.4 (which MSC variant, when a dehydrated device is created and rotated, claim-on-login and key import into the new device, 4S-stored dehydration key, what is never logged — CR-19, what happens with no 4S). Then implement via the CryptoMachine push/pull contract (§3.4) with testkit coverage and a real-Synapse e2e (Synapse supports MSC3814 behind experimental_features.msc3814_enabled).
Scope decided 2026-08-21 (D55): MSC3814 full — create a dehydrated device keyed by a 4S-stored secret, rotate on schedule, claim on a fresh login and import its room keys before first sync; inert-and-honest without 4S.
Done (D73, §10.4.7): MSC3814 v2 dehydrated devices — create/rotate/claim. Driver primitive pair (toDehydratedDevice/accountFromDehydratedDevice) on all four drivers (oracle typed-Unsupported), machine DehydrationManager (cross-signed flagged device; rehydrate via throwaway keeper/channel — only room keys cross in, healing UTDs, CR-12), peers refuse an uncross-signed dehydrated device. 32-byte key is a 4S secret held only while 4S is open (§9), inert-and-honest without it; availability discovered from M_UNRECOGNIZED. Engine manageDehydratedDevice/dehydratedDeviceState, claim-then-replace at 4S open + 7-day rotation. Verified: conformance kit 22/22 on jvm/js/wasmJs/oracle, machine corpus 41/41 (vodozemac+oracle, 4 new rows), real-Synapse e2e green (msc3814_enabled), spec-lint + spec-coverage + apiCheck + checkDependencyRules + bot-footprint clean, wasm-lock.json regenerated (CI-host hash). Uncommitted in the working tree.