Repository navigation
0.0.6 — invitation-owned key packages, A.4 bootstrap, A.2 ratchet
Integration build for downstream (AbstractTwoMLS, germDM feat/pq) — built from the mark/combined-cryptokit-api branch at a1be8fa. Not a release off main, and the FFI surface is still moving (session persistence lands separately via #21; A.5 re-key/rotation pending) — expect 0.0.x churn.
What's new since 0.0.5
- Invitation-owned key packages (#22 content):
TwoMlsPqClient(clientId:)takes opaque identity bytes;TwoMlsPqClient.generateInvitation()→ self-contained, archivableTwoMlsPqInvitation(signing identity + key-package private material + transport-dedup set) withreceive/hpkeOpen. - Opaque combiner key-package codec (
encodeCombinerKeyPackage/decodeCombinerKeyPackage) andhpkeSealToKeyPackage— the initial envelope seals to the PQ EK in KP′ (real ML-KEM-768 HPKE) per docs/08-twoMLSPQ-APQ.md A.1. - A.4 deferred PQ bootstrap: the acceptor's send group starts classical-only;
pqBootstrapBegin/Respond/Applystand the PQ half up off the critical path, withmyPqTurn/isFullyEstablished/epochs. The A.3 ratchet methods (pqRatchetBegin/Respond/Bind/Apply) are now exported, with responder replies parked in-session (pqTakePendingOutbound). - A.2 classical ratchet: only a group's owner commits; routine rounds staple an
Upd(self)proposal,queueProposalgates the peer's Upd into the send-group cache, and the consuming commit carries the cross-party TwoMLS-PSK. Frame0x05=[commit?][Upd proposal][app](0x07retired).
Integration
.binaryTarget(
name: "TwoMLSPQrs",
url: "https://github.com/germ-network/TwoMLSPQ/releases/download/0.0.6/TwoMLSPQ.xcframework.zip",
checksum: "9862ab98da8036dba9a4ebb9d22bf0867a5d2aac3e201ba7fc8ef02fe517ebe7"
)Copy the attached two_mls_pq.swift into your wrapper target from this same release — uniffi verifies a binding↔binary checksum at init.