Skip to content

feat(wire-format): per-document XChaCha announce and lock (TEC-2936) - #32

Merged
nadeem-fileverse merged 1 commit into
mainfrom
nk/collab-wire-xchacha
Sep 11, 2026
Merged

nadeem-fileverse merged 1 commit into
mainfrom
nk/collab-wire-xchacha

Conversation

@nadeem-fileverse

Copy link
Copy Markdown
Contributor

Clients declare the wire ciphers they can read on auth. With WIRE_FORMAT_TARGET set to xchacha the server announces xchacha for a room once every socket in it can read it, locks the document (a DocumentWireFormat row, kept separate from DocumentMeta so that row's $setOnInsert fields are never stranded by an auth-time upsert), sweeps any socket that cannot read it, and tells the incumbents over /document/wire_format so a long-lived tab converts without a re-auth. A locked document refuses a non-capable client with 426 WIRE_FORMAT_UNSUPPORTED before any session bookkeeping, including on a rotation-cutover re-auth, where the prior room is left explicitly. The disconnect handler ratchets a room whose last ECIES-only socket just left. With the target unset the server announces ECIES everywhere and never locks; existing locks keep refusing.

Infrastructure failures degrade instead of failing the auth: a rejected cross-instance enumeration or lock write announces ECIES and takes no lock, and a failed post-lock sweep is logged without suppressing the event. Refusals are logged once per document per minute with a capped view of the declared list. The ratchet is skipped while the process is draining, since io.close() fires disconnecting for every socket and the reconnect auth after the restart resolves the same state.

Clients declare the wire ciphers they can read on auth. With WIRE_FORMAT_TARGET set to
xchacha the server announces xchacha for a room once every socket in it can read it,
locks the document (a DocumentWireFormat row, kept separate from DocumentMeta so that
row's $setOnInsert fields are never stranded by an auth-time upsert), sweeps any socket
that cannot read it, and tells the incumbents over /document/wire_format so a
long-lived tab converts without a re-auth. A locked document refuses a non-capable
client with 426 WIRE_FORMAT_UNSUPPORTED before any session bookkeeping, including on a
rotation-cutover re-auth, where the prior room is left explicitly. The disconnect
handler ratchets a room whose last ECIES-only socket just left. With the target unset
the server announces ECIES everywhere and never locks; existing locks keep refusing.

Infrastructure failures degrade instead of failing the auth: a rejected cross-instance
enumeration or lock write announces ECIES and takes no lock, and a failed post-lock
sweep is logged without suppressing the event. Refusals are logged once per document
per minute with a capped view of the declared list. The ratchet is skipped while the
process is draining, since io.close() fires disconnecting for every socket and the
reconnect auth after the restart resolves the same state.
@nadeem-fileverse
nadeem-fileverse merged commit 9cf7890 into main Sep 11, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant