Critical Bug Fix
This release fixes the root cause of MAC verification failures that occurred even with brand new accounts.
What Was Fixed
The ephemeral_key field in encrypted messages was incorrectly set to the sender's identity key instead of the actual ephemeral key generated during session establishment. This caused the sender and receiver to compute different shared secrets, resulting in MAC verification failures.
Changes
- Added
our_ephemeral_keyfield to Session struct to store the real ephemeral key - Updated
establish_session()to store the ephemeral key during session creation - Updated
encrypt_message()to include the real ephemeral key from the session - Both sender and receiver now use the same ephemeral key in DH operations, computing identical shared secrets
Impact
- ✅ Fixes MAC verification failures for ALL accounts (new and existing)
- ✅ Ensures proper X3DH key agreement protocol implementation
- ✅ Both sender and receiver can now successfully decrypt messages
Installation
Download the appropriate binary for your platform below, make it executable, and run it.
🤖 Generated with Claude Code