Repository navigation
feat(chat-cipher): wrap and unwrap a private group's key - #1745
Merged
Merged
Conversation
ChatCipher gains newGroupKey, wrapGroupKey and unwrapGroupKey for the chat.v1.KeyEnvelope X25519_XCHACHA20POLY1305 scheme, following chat/v1/model.proto steps 1-4. The wrap reuses the DM key's X25519 + HKDF-SHA256 steps under the flipcash-group-key-wrap-v1 label; the AAD is the label, chat id, wrapper key, then recipient key. There are no shared vectors for the wrap yet, so GroupKeyWrapTest checks round trips and rejections (another chat, another wrapper or recipient, a short key), and that the wrapping key differs from the DM chat key, rather than fixed bytes. FakeChatCipher implements the new methods so the services test fixtures still compile.
bmc08gt
force-pushed
the
feat/chat-cipher-group-key-wrap
branch
from
October 9, 2026 18:01
48d9725 to
4b5dea2
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Private groups store their chat key as a
chat.v1.KeyEnvelope, and iOS needs the wrap from shared-core before it can build create or approve. This adds it toChatCipheron its own so shared-core can release it; the Android create and approve flows stay onfeat/private-groups.The wrap follows the
X25519_XCHACHA20POLY1305steps 1-4 inchat/v1/model.proto. It shares the DM key's X25519 + HKDF-SHA256 derivation (salt is both Ed25519 public keys in bytewise order) under theflipcash-group-key-wrap-v1label. The AAD is label, chat id, wrapper key, then recipient key. A creator wraps for themselves by passing their own public key asrecipientPk.There are no shared vectors for the wrap yet, so
GroupKeyWrapTestchecks round trips and rejections (another chat, another wrapper or recipient, a short key), and that the wrapping key differs from the DM chat key, rather than fixed bytes. Once iOS has an implementation, a cross-platform vector would pin it.FakeChatCipherin the services test fixtures implements the new methods so that module still compiles.