Session crypto transparency: encrypted echo bot with 0 new lines #28

Closed
opened 2026-08-04 21:20:19 +02:00 by thecrealm · 1 comment
Owner

§10.4.2 transparency contract: decryption transparent in every event surface (typed/raw; UTD states, never fake content — CR-6); encryption transparent on send; refuse-plaintext guard holds with typed error (CR-7, §2.5); crypto constructed with the session — no init-ordering trap. M1 exit criterion: the same echo bot works in an encrypted room with 0 new lines (CR-20). Crypto-store failure wedges typed, never downgrades to plaintext (§10.4.6, §9).

§10.4.2 transparency contract: decryption transparent in every event surface (typed/raw; UTD states, never fake content — CR-6); encryption transparent on send; refuse-plaintext guard holds with typed error (CR-7, §2.5); crypto constructed with the session — no init-ordering trap. M1 exit criterion: the same echo bot works in an encrypted room with 0 new lines (CR-20). Crypto-store failure wedges typed, never downgrades to plaintext (§10.4.6, §9).
Author
Owner

Discovered while scoping #27: engine-side wiring this issue needs — SyncBatch currently carries only toDevice; it lacks device_lists (changed/left), device_one_time_keys_count and device_unused_fallback_key_types. Extending SyncBatch means touching both sources (SyncV2Source.parse, SlidingSyncSource) and the replay corpus fact hash. Also still missing engine-side: keys/upload, keys/query, keys/claim, sendToDevice endpoint definitions in katrix-core Endpoints. The machine's input type (CryptoSyncChanges, katrix-crypto) is defined by #27 and ready to be fed.

Discovered while scoping #27: engine-side wiring this issue needs — SyncBatch currently carries only toDevice; it lacks device_lists (changed/left), device_one_time_keys_count and device_unused_fallback_key_types. Extending SyncBatch means touching both sources (SyncV2Source.parse, SlidingSyncSource) and the replay corpus fact hash. Also still missing engine-side: keys/upload, keys/query, keys/claim, sendToDevice endpoint definitions in katrix-core Endpoints. The machine's input type (CryptoSyncChanges, katrix-crypto) is defined by #27 and ready to be fed.
thecrealm added
now
and removed
next
labels 2026-08-04 23:52:30 +02:00
thecrealm 2026-08-05 10:18:23 +02:00
  • closed this issue
  • removed the
    now
    label
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
thecrealm/katrix#28
No description provided.