Skip to content

fix: carry ring_vrf_domain_entropy in AutoSigning secrets on iOS and Android - #1264

Open
decrypto21 wants to merge 5 commits into
mainfrom
nidish/ios-autosigning-entropy
Open

decrypto21 wants to merge 5 commits into
mainfrom
nidish/ios-autosigning-entropy

Conversation

@decrypto21

Copy link
Copy Markdown
Contributor

Fixes paritytech/platform-bugs#13.

An AutoSigning allocation granted on the phone carries the product's 32-byte ring-VRF domain entropy, so the core decodes the reply as SsoAllocatedResource::AutoSigning.

  • iOS: AutoSigningSecrets holds ringVrfDomainEntropy, encoded after the 64-byte key. deriveAutoSigningSecrets derives it from the root entropy for the calling product, as the core's derive_ring_vrf_domain_entropy does, through RingVrfEntropyDeriver.deriveDomainEntropy.
  • Android: the AutoSigning wire and domain types carry the same field. Android still answers AutoSigning with NotAvailable; the shape is ready for when it allocates.
  • Signing host: the domain entropy comes from the normalized calling product id, the same id the product subtree secret uses.

Verification:

  • Live, a CLI pairing host paired with the iOS app on its native SSO path: on main the AutoSigning allocation fails with Could not decode SsoAllocatedResource::AutoSigning::ring_vrf_domain_entropy; with this change it returns Allocated.
  • Shared vectors: Swift AutoSigningWireEncodingTests and Android SsoResourceAllocationScaleTest pin the bytes the core decodes; Swift and Rust (product_ring_vrf_domain_entropy_matches_ios_vector) pin the same domain entropy.
  • auto_signing_allocation_derives_both_secrets_from_the_normalized_product_id fails without the signing host change.
  • iOS unit test plan, Android feature:sso:impl tests and detekt, cargo test -p truapi and fmt pass.

Reproduce with truapi-host pairing-host --network previewnet --script verify-13.ts, paired with the iOS app with the TrUAPI runtime switched off in Debug Settings:

export {};
const login = await truapi.account.requestLogin({ reason: undefined });
assert(login.isOk(), "login failed", login);
const allocation = await truapi.resourceAllocation.request({ resources: [{ tag: "AutoSigning" }] });
console.log("allocation:", JSON.stringify(allocation.isOk() ? allocation.value : allocation.error));

@decrypto21
decrypto21 requested review from a team and pgherveou October 7, 2026 05:12
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

This pull request touches an app, which is not built by default. Add a label for each build you want:

  • iOS simulator build, ios-simulator-build: builds the iOS app, runs its tests and attaches a build for the iOS Simulator on a Mac.
  • iOS device build, ios-device-build: attaches a signed build that installs on a registered iPhone or iPad.
  • Android build, android-device-build: attaches an APK that installs on an Android phone or an emulator.

Each starts as soon as it is added and follows the branch from then on.

@github-actions github-actions Bot added rust Pull requests that update rust code host-ios Touches the iOS host tree host-android Touches the Android host tree labels Oct 7, 2026
@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Bundle size report

Compared with main at 63a450d.

Raw Gzip Brotli
truapi-host 7.81 MiB 5.63 MiB 5.37 MiB
truapi-provider 4.03 MiB 1.27 MiB 959.8 KiB
truapi 6.00 MiB 848.0 KiB 695.0 KiB
Total 17.84 MiB 7.74 MiB 6.99 MiB

WebAssembly modules

Raw Gzip Brotli
truapi-host/wasm/web/truapi_server_bg.wasm 2.70 MiB 965.5 KiB 731.0 KiB
truapi-host/wasm/web/truapi_verifiable_bg.wasm 4.89 MiB 4.64 MiB 4.61 MiB
truapi-provider/truapi_provider_bg.wasm 3.99 MiB 1.26 MiB 952.1 KiB

No file changed size.

Commit: 5cbcef3

@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

CI Status: 24 required jobs green, 21 passed and 3 skipped by path filter.

All job results
job result
android-bindings success
bundle-size success
changes success
changeset-guard success
cli-package success
codegen success
e2e skipped
explorer success
headless-install success
host-android-bindings success
host-android-detekt success
host-wasm success
ios-bindings success
ios-swift success
licenses success
playground success
provider-android-bindings skipped
release-guard success
rust success
ts-client success
ts-debugger success
ts-host success
wasm-provider success
workflow-lint skipped

Signing credentials: failure as of 2026-10-07, a release may fail

Commit 5cbcef3f · run log

@pgherveou pgherveou left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can run that just fine from main, can you provide a complete error script

Verification:

Live, a CLI pairing host paired with the iOS app on its native SSO path: on main the AutoSigning allocation fails with Could not decode SsoAllocatedResource::AutoSigning::ring_vrf_domain_entropy; with this change it returns Allocated.
Shared vectors: Swift AutoSigningWireEncodingTests and Android SsoResourceAllocationScaleTest pin the bytes the core decodes; Swift and Rust (product_ring_vrf_domain_entropy_matches_ios_vector) pin the same domain entropy.
auto_signing_allocation_derives_both_secrets_from_the_normalized_product_id fails without the signing host change.
iOS unit test plan, Android feature:sso:impl tests and detekt, cargo test -p truapi and fmt pass.
Reproduce with truapi-host pairing-host --network previewnet --script verify-13.ts, paired with the iOS app with the TrUAPI runtime switched off in Debug Settings:

export {};
const login = await truapi.account.requestLogin({ reason: undefined });
assert(login.isOk(), "login failed", login);
const allocation = await truapi.resourceAllocation.request({ resources: [{ tag: "AutoSigning" }] });
console.log("allocation:", JSON.stringify(allocation.isOk() ? allocation.value : allocation.error));

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

host-android Touches the Android host tree host-ios Touches the iOS host tree rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants