Files
amethyst/quartz/src
Claude 4fc99021ae fix: correct key schedule welcome_secret derivation order
The welcome_secret must be derived from member_secret (the Extract of
joiner_secret and psk_secret), not directly from joiner_secret. This
matches the RFC 9420 key schedule diagram where welcome_secret is
derived after the psk extraction step.

Before: welcome = DeriveSecret(joiner_secret, "welcome")
After:  member = Extract(joiner_secret, psk_secret)
        welcome = DeriveSecret(member, "welcome")
        epoch = ExpandWithLabel(member, "epoch", GroupContext, Nh)

This fix was discovered and validated by the IETF interop test vectors.
Key schedule tests now pass all 11 derived secrets across multiple epochs.

https://claude.ai/code/session_01NocQDWj2Y92FugjfgazzL3
2026-04-03 19:51:54 +00:00
..