ed5515a7c5
Phase 1 - Critical/High cryptographic fixes: - Fix sender data nonce reuse: derive key/nonce from ciphertext sample per §6.3.1 - Add PrivateContentAAD binding (group_id, epoch, content_type) per §6.3.2 - Add SenderDataAAD binding per §6.3.1 - Fix KDFLabel encoding: use TLS fixed-width (putOpaque1/putOpaque4) not QUIC VarInt - Add reuse_guard (4-byte random XOR into nonce) per §6.3.1 - Fix parent hash verification: capture sibling hashes before UpdatePath applied - Fix Welcome confirmation tag: use HMAC instead of ExpandWithLabel - Make confirmation tag mandatory in processCommit (was nullable) - Fix off-by-one in path secret derivation during processCommit - Fix TokenEncryption: extract 32-byte x-only pubkey from 33-byte compressed key - Fix SELF_REMOVE proposal type: move from 0x0008 to 0xF001 (private-use range) Phase 2 - Protocol compliance and thread safety: - Validate KeyPackage ciphersuite is supported (0x0001 only) - Synchronize KeyPackageRotationManager read operations with mutex - Synchronize EpochCommitTracker with lock object - Synchronize processedEventIds with lock in MarmotInboundProcessor - Synchronize MlsGroupManager encrypt/decrypt with mutex - Synchronize MarmotSubscriptionManager read methods - Require unresolved proposal references to error per §12.4.2 Phase 3 - Hardening: - Add path traversal validation in AndroidMlsGroupStateStore (hex-only groupId) - Bind nostrGroupId as AAD in outer ChaCha20-Poly1305 encryption - Track failed events in dedup set to prevent CPU exhaustion - Validate nostrGroupId in processWelcome against Welcome event's own h tag - Validate sender leaf index bounds during decryption Phase 4 - Low priority fixes: - Fix externalJoin: compute confirmedTranscriptHash and interimTranscriptHash - Add snapshot methods for non-suspend filter access https://claude.ai/code/session_017SjKXS4Vpu4xRg9zHTgpmC