119f9dd966
Implements the core MLS (RFC 9420) engine for Marmot Protocol integration, targeting ciphersuite 0x0001 (DHKEM-X25519, AES-128-GCM, SHA-256, Ed25519). Components: - codec/: TLS presentation language encoder/decoder (RFC 8446 Section 3) - crypto/: Ed25519 signatures, X25519 ECDH, HPKE (RFC 9180), MlsCryptoProvider with ExpandWithLabel, DeriveSecret, SignWithLabel, EncryptWithLabel - tree/: Left-balanced binary tree, LeafNode/ParentNode, RatchetTree with TreeKEM encap/decap, tree hashing, resolution, path secret derivation - schedule/: Key schedule (epoch secret derivation chain), SecretTree (per-sender encryption ratchets), MLS-Exporter function - framing/: MLSMessage, PublicMessage, PrivateMessage, content types - messages/: Proposal (Add/Remove/Update/SelfRemove), Commit, UpdatePath, Welcome, GroupInfo, GroupContext, KeyPackage, GroupSecrets - group/: MlsGroup high-level API (create, join via Welcome, add/remove members, encrypt/decrypt messages, export keys for Marmot outer layer) Crypto uses expect/actual pattern: JVM/Android via java.security (EdDSA, XDH), native platforms stubbed for future implementation. Reuses existing Quartz primitives (AESGCM, HKDF, SHA-256, HMAC, ChaCha20-Poly1305). Includes tests for TLS codec, binary tree arithmetic, and MLS type roundtrips. https://claude.ai/code/session_01966YzookEUQDwszM3YCgeR