fix(session): remember where aliasSession moved a session
aliasSession knew that two labels name the same peer, then threw that knowledge away. The binding lived only in the caller's memory, so a restart lost it — and the peer could not repair it from its side. First contact forces the receiver to label a session by the only sender hint a relay surfaces, an 8-byte signing-key fingerprint (`fp:<hex>`). Once the peer announces its canonical address, aliasSession moves the session there. But the peer keeps sending under `fp:<hex>`, because its transport derives the same label from the same hint every time. After a restart the session sat under the canonical address, inbound frames resolved to `fp:<hex>`, and nothing matched. The peer held a valid session so it never re-ran X3DH: the failure was permanent, and only a manual re-link cleared it. Observed in Prism as `No session for address: fp:579c3b335d66e2c0` on every receive for three days, with a phone whose every RPC timed out. StorageProvider gains saveSessionAlias / getSessionAlias / removeSessionAliasesFor, optional so third-party implementations keep compiling, and implemented across all seven backends. Lookups resolve through resolveLabel(), which runs BEFORE the peer mutex — locking the alias while mutating the canonical session would let an aliased and a canonical caller ratchet the same state concurrently. A live session under a label always wins over an alias, and prekey envelopes never resolve: both keep a re-link establishing a fresh session instead of being redirected into the stale one. Aliases are dropped in resetSession and acceptIdentityChange, and memoized so the hot path costs no extra read. The sdk.test.ts case that asserted a dead fp-label encoded the old behaviour; it now pins the new contract. Verified: 1166 tests pass (from 1160). With alias persistence disabled as a negative control, 5 of the 6 new tests fail, including both restart cases. Also drops `baseUrl` from the consumer-strict tsconfig — removed in TS 6.0, and it was failing the typecheck that gates publishing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -41,6 +41,9 @@ export class SQLiteStorage implements StorageProvider {
|
||||
getSession: ReturnType<Database['prepare']>;
|
||||
saveSession: ReturnType<Database['prepare']>;
|
||||
removeSession: ReturnType<Database['prepare']>;
|
||||
getSessionAlias: ReturnType<Database['prepare']>;
|
||||
saveSessionAlias: ReturnType<Database['prepare']>;
|
||||
removeAliasesFor: ReturnType<Database['prepare']>;
|
||||
getTrust: ReturnType<Database['prepare']>;
|
||||
saveTrust: ReturnType<Database['prepare']>;
|
||||
addRetired: ReturnType<Database['prepare']>;
|
||||
@@ -100,6 +103,12 @@ export class SQLiteStorage implements StorageProvider {
|
||||
address TEXT PRIMARY KEY,
|
||||
state_json TEXT NOT NULL
|
||||
);
|
||||
CREATE TABLE IF NOT EXISTS session_aliases (
|
||||
alias TEXT PRIMARY KEY,
|
||||
canonical TEXT NOT NULL
|
||||
);
|
||||
CREATE INDEX IF NOT EXISTS idx_session_aliases_canonical
|
||||
ON session_aliases(canonical);
|
||||
CREATE TABLE IF NOT EXISTS trusted_identities (
|
||||
address TEXT PRIMARY KEY,
|
||||
identity_key TEXT NOT NULL
|
||||
@@ -179,6 +188,9 @@ export class SQLiteStorage implements StorageProvider {
|
||||
getSession: this.db.prepare('SELECT state_json FROM sessions WHERE address = ?'),
|
||||
saveSession: this.db.prepare('INSERT OR REPLACE INTO sessions (address, state_json) VALUES (?, ?)'),
|
||||
removeSession: this.db.prepare('DELETE FROM sessions WHERE address = ?'),
|
||||
getSessionAlias: this.db.prepare('SELECT canonical FROM session_aliases WHERE alias = ?'),
|
||||
saveSessionAlias: this.db.prepare('INSERT OR REPLACE INTO session_aliases (alias, canonical) VALUES (?, ?)'),
|
||||
removeAliasesFor: this.db.prepare('DELETE FROM session_aliases WHERE canonical = ?'),
|
||||
getTrust: this.db.prepare('SELECT identity_key FROM trusted_identities WHERE address = ?'),
|
||||
saveTrust: this.db.prepare('INSERT OR REPLACE INTO trusted_identities (address, identity_key) VALUES (?, ?)'),
|
||||
addRetired: this.db.prepare('INSERT INTO retired_identities (data_json, retired_at) VALUES (?, ?)'),
|
||||
@@ -337,6 +349,21 @@ export class SQLiteStorage implements StorageProvider {
|
||||
this.stmts.removeSession.run(address);
|
||||
}
|
||||
|
||||
// ─── Session label aliases ────────────────────────────────
|
||||
|
||||
async getSessionAlias(alias: string): Promise<string | null> {
|
||||
const row = this.stmts.getSessionAlias.get(alias) as { canonical: string } | undefined;
|
||||
return row?.canonical ?? null;
|
||||
}
|
||||
|
||||
async saveSessionAlias(alias: string, canonical: string): Promise<void> {
|
||||
this.stmts.saveSessionAlias.run(alias, canonical);
|
||||
}
|
||||
|
||||
async removeSessionAliasesFor(canonical: string): Promise<void> {
|
||||
this.stmts.removeAliasesFor.run(canonical);
|
||||
}
|
||||
|
||||
// ─── Trust ────────────────────────────────────────────────
|
||||
|
||||
async isTrustedIdentity(address: string, identityKey: Uint8Array): Promise<boolean> {
|
||||
|
||||
Reference in New Issue
Block a user