Skip to content

Stop for good when the server says device_removed (GRYT-1555) - #27

Merged
sivert-io merged 1 commit into
mainfrom
claude/GRYT-1555-remove-means-removed
Sep 28, 2026
Merged

sivert-io merged 1 commit into
mainfrom
claude/GRYT-1555-remove-means-removed

Conversation

@sivert-io

Copy link
Copy Markdown
Member

The driver's half of GRYT-1555. The server half is Gryt-chat/server#249, which refuses every mls:* call from a removed device id with device_removed.

What changes

  • Every transport call goes through a guard. When a reply is device_removed, the driver:
    • marks itself removed
    • fires the new events.onDeviceRemoved(), once
    • throws MlsDriverError with code device_removed
  • After that it sends the server nothing. So it can't publish KeyPackages and register the device again, which is what brought a removed device back before.
  • A removed device that's online finds out straight away. The server pushes mls:devices:changed to your own sockets too, so when a push names you, handleDevicesChanged syncs first, and a removed device gets refused there.
  • The driver can't clear anything itself, since its state belongs to the app. onDeviceRemoved says what the app does: wipe this server's MLS state, and don't make a new device until the person asks. Client#713 and mobile#271 do that.

Test

The stolen-phone case, against the fake delivery service, which now keeps removed ids the way server#249 does:

  1. The laptop removes the phone while the phone is online.
  2. The phone hears about it from the push, and loses the group.
  3. Its next start() sends the server nothing.
  4. A fresh driver on the same state, which is what reconnecting looks like, sends one sync, gets refused and never publishes.
  5. Ola's next message reaches the laptop, and no Welcome is ever made for the phone.

I checked that the test fails without the sync on your own push, and fails if the event isn't fired.

What to look at

  • The extra sync on every mls:devices:changed that names you. It's one small request, and only on a device that's registered.
  • ownDevices() on a removed device now throws device_removed instead of listing. The apps show the removed line in that case.

Released together with core#25 as 0.13.0, and the apps pin that.

🤖 Generated with Claude Code

Every transport call now goes through a guard. When a reply is
device_removed, the driver marks itself removed, fires the new
events.onDeviceRemoved once, and throws MlsDriverError("device_removed").
After that it sends the server nothing at all, so nothing can publish
KeyPackages and register this device again.

A removed device that's online finds out straight away. The server
pushes mls:devices:changed to your own sockets too, and when a push
names you, the driver syncs first. A removed device gets refused there.

The test is the stolen-phone case. The laptop removes the phone while
it's online. The phone hears about it from the push. Its next start
sends nothing. A fresh driver on the same state sends one sync, is
refused and never publishes. The peer's next message reaches the laptop
and no Welcome is made for the phone.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
@sivert-io
sivert-io merged commit 4f18940 into main Sep 28, 2026
5 checks passed
@sivert-io
sivert-io deleted the claude/GRYT-1555-remove-means-removed branch September 28, 2026 14:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant