CR-7 regression: v2 incremental joined payloads falsely certify state-complete #69

Closed
opened 2026-08-07 19:02:13 +02:00 by thecrealm · 0 comments
Owner

Follow-up to #66 (D34): the v2 rule 'every joined payload marks state-complete' is unsound — it is an inductive step whose base case (the room's full state actually committed once) does not hold for stores that predate the state projection or lost state. An incremental v2 joined delta (timeline only) then falsely commits the sticky marker, and absent m.room.encryption reads as known-unencrypted: plaintext leaks resume. User-reported on prod: the 1:1 DM continued sending unencrypted after 5579d06. Fix: v2 marks only on provable full-state deliveries — the initial-sync response (since=null, source-level flag) and join transitions (reducer observes stored membership != JOIN before the delta commits). Sliding stays initial-flag-only. Remediation: migration purges all existing markers (false ones are indistinguishable); sliding re-heals at cold boot (D34 addendum), v2 rooms fail closed pending #68. Regression test: store with JOIN membership + incremental v2 joined payload must refuse plaintext (CR-7).

Follow-up to #66 (D34): the v2 rule 'every joined payload marks state-complete' is unsound — it is an inductive step whose base case (the room's full state actually committed once) does not hold for stores that predate the state projection or lost state. An incremental v2 joined delta (timeline only) then falsely commits the sticky marker, and absent m.room.encryption reads as known-unencrypted: plaintext leaks resume. User-reported on prod: the 1:1 DM continued sending unencrypted after 5579d06. Fix: v2 marks only on provable full-state deliveries — the initial-sync response (since=null, source-level flag) and join transitions (reducer observes stored membership != JOIN before the delta commits). Sliding stays initial-flag-only. Remediation: migration purges all existing markers (false ones are indistinguishable); sliding re-heals at cold boot (D34 addendum), v2 rooms fail closed pending #68. Regression test: store with JOIN membership + incremental v2 joined payload must refuse plaintext (CR-7).
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
thecrealm/katrix#69
No description provided.