Files
amethyst/amethyst
Vitor PamplonaandClaude Opus 5 bf99eb740c feat(cordn): carry the messages in a backup, so a restore keeps the conversation
Restoring a backup handed back the groups with an empty history. The archive
carried the MLS state, the cursor and the key packages but not one message,
and the cursor it *did* carry told the sync loop the stream had been read to
the end — so the coordinator was never asked to resend them either. Verified
on the tablet with a true no-op round trip (export, restore that same file
minutes later): both groups came back with names, icons, members and health,
and every message gone, still gone after a cold start, and gone from the
Messages inbox entirely for want of anything to sort on.

That is not what the screen offers. Its first line is that losing the device
without a backup loses "everything already said in it", which only reads one
way.

Archive version 2 adds the delivered messages per group, written as the same
JSON the on-disk message log already stores so the two cannot drift. Version 1
files still open, and still restore empty — there is nothing in them to do
better with. The import writes the messages back before the cursor is trusted
again, because nothing will re-deliver them afterwards.

The alternative was to reset the cursor on restore and re-pull from the
coordinator, which does hold the complete ordered history. It is cheaper, but
it only recovers the epochs the restored state can still open; carrying the
plaintext is whole regardless of how often the group has rotated. Vitor picked
this one. The "What is in the file" copy now says messages are in there, since
that materially changes what the file is worth to whoever finds it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-26 12:56:24 -04:00
..