CR-7 regression: v2 incremental joined payloads falsely certify state-complete #69
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Follow-up to #66 (D34): the v2 rule 'every joined payload marks state-complete' is unsound — it is an inductive step whose base case (the room's full state actually committed once) does not hold for stores that predate the state projection or lost state. An incremental v2 joined delta (timeline only) then falsely commits the sticky marker, and absent m.room.encryption reads as known-unencrypted: plaintext leaks resume. User-reported on prod: the 1:1 DM continued sending unencrypted after
5579d06. Fix: v2 marks only on provable full-state deliveries — the initial-sync response (since=null, source-level flag) and join transitions (reducer observes stored membership != JOIN before the delta commits). Sliding stays initial-flag-only. Remediation: migration purges all existing markers (false ones are indistinguishable); sliding re-heals at cold boot (D34 addendum), v2 rooms fail closed pending #68. Regression test: store with JOIN membership + incremental v2 joined payload must refuse plaintext (CR-7).