Repository navigation
Tables for the MLS delivery service (GRYT-1500) - #240
Merged
Merged
Conversation
Stage 1 of docs/mls-design.md in the crypto repo needs somewhere to keep KeyPackages, Welcomes and each DM group's log. Five new tables, all holding MLS bytes the server can't open plus what ordering and routing need: - mls_devices: which devices a member has here, five at most. - mls_key_packages: up to 20 per device plus one last-resort package. Handing one out clears its bytes but keeps the row, so a Welcome that names it by ref can still be routed. The retention sweep drops it later. - mls_groups: one per conversation, with the current epoch and the last seq handed out. head_seq is kept here and not read off the log, because the log gets swept and a seq must never be handed out twice. - mls_log: commits, proposals and application messages, in seq order. - mls_welcomes: one row per receiving device, until that device acks it. appendMlsCommit is where commits get ordered. In one IMMEDIATE transaction it checks the commit's epoch against the group's, writes it and moves the epoch on, or refuses and says what the epoch is now. The same bytes sent again within the last 100 entries get the first seq back rather than a second row, for a client retrying after a lost reply. Two existing paths change. Purging an empty conversation drops its group too: a DM id comes from the pair, so a group left behind would be handed to the next DM those two open. And a guest merged into an account takes its devices, KeyPackages and Welcomes along. Nothing calls these yet. The socket handlers are in the next PR. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What to look at
appendMlsCommitinsrc/db/sqlite/mls.ts. It's the only place commitordering is decided: read the group's epoch, compare, write, move it on,
all inside
BEGIN IMMEDIATE. The handlers in the next PR trust it.recentDuplicate, the resend check, compares blobs against the last 100rows of a group's log. It's meant for a client retrying after a lost
reply. I'm not sure a blob compare is how you'd want it done.
purgeOrphanedConversationsnow drops the MLS group as well. That's achange to an existing function.
mergeGuestIntoAccountmoves MLS devices across. Where both identitieshave the same device id, the account's row is kept.
What's in it
Five tables for the MLS delivery service, stage 1 of
docs/mls-design.md:
devices (five per member), KeyPackages (20 per device plus a last-resort
one, each handed out once), groups (one per conversation, with the epoch and
the last seq), the log, and Welcomes waiting for their device. Every blob
is MLS wire bytes. The server never gets a key.
sweepMlsis the retention sweep: log rows, Welcomes and handed-outKeyPackage refs older than the cutoff, plus any group whose conversation is
gone. A group's epoch and head_seq never go back, so a cursor still means
the same thing after a sweep.
Nothing calls this yet. The handlers are in #241, which carries this commit
too so its CI can run. It's a draft until this one merges.
Tests
src/db/sqlite/mls.test.ts, 19 tests: the device cap, KeyPackages handedout once and oldest first, the last-resort fallback, the first group per
conversation winning, one commit per epoch, resends, cursor paging,
Welcomes only deleted by their own device, retention, and the two lifecycle
changes.
mergeGuest.test.ts's column audit caught the new columns, whichis how the merge change got written. Full suite: 1729 pass.
Task: GRYT-1500. Part of GRYT-754 and GRYT-1244.
🤖 Generated with Claude Code