Repository navigation
fix: carry ring_vrf_domain_entropy in AutoSigning secrets on iOS and Android - #1264
Open
decrypto21 wants to merge 5 commits into
Open
decrypto21 wants to merge 5 commits into
decrypto21 wants to merge 5 commits into
Conversation
Contributor
|
This pull request touches an app, which is not built by default. Add a label for each build you want:
Each starts as soon as it is added and follows the branch from then on. |
Contributor
Bundle size reportCompared with
WebAssembly modules
No file changed size. Commit: 5cbcef3 |
Contributor
|
CI Status: 24 required jobs green, 21 passed and 3 skipped by path filter. All job results
Signing credentials: failure as of 2026-10-07, a release may fail Commit |
pgherveou
requested changes
Oct 8, 2026
pgherveou
left a comment
Collaborator
There was a problem hiding this comment.
I can run that just fine from main, can you provide a complete error script
Verification:
Live, a CLI pairing host paired with the iOS app on its native SSO path: on main the AutoSigning allocation fails with Could not decode SsoAllocatedResource::AutoSigning::ring_vrf_domain_entropy; with this change it returns Allocated.
Shared vectors: Swift AutoSigningWireEncodingTests and Android SsoResourceAllocationScaleTest pin the bytes the core decodes; Swift and Rust (product_ring_vrf_domain_entropy_matches_ios_vector) pin the same domain entropy.
auto_signing_allocation_derives_both_secrets_from_the_normalized_product_id fails without the signing host change.
iOS unit test plan, Android feature:sso:impl tests and detekt, cargo test -p truapi and fmt pass.
Reproduce with truapi-host pairing-host --network previewnet --script verify-13.ts, paired with the iOS app with the TrUAPI runtime switched off in Debug Settings:
export {};
const login = await truapi.account.requestLogin({ reason: undefined });
assert(login.isOk(), "login failed", login);
const allocation = await truapi.resourceAllocation.request({ resources: [{ tag: "AutoSigning" }] });
console.log("allocation:", JSON.stringify(allocation.isOk() ? allocation.value : allocation.error));
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes paritytech/platform-bugs#13.
An AutoSigning allocation granted on the phone carries the product's 32-byte ring-VRF domain entropy, so the core decodes the reply as
SsoAllocatedResource::AutoSigning.AutoSigningSecretsholdsringVrfDomainEntropy, encoded after the 64-byte key.deriveAutoSigningSecretsderives it from the root entropy for the calling product, as the core'sderive_ring_vrf_domain_entropydoes, throughRingVrfEntropyDeriver.deriveDomainEntropy.NotAvailable; the shape is ready for when it allocates.Verification:
mainthe AutoSigning allocation fails withCould not decode SsoAllocatedResource::AutoSigning::ring_vrf_domain_entropy; with this change it returnsAllocated.AutoSigningWireEncodingTestsand AndroidSsoResourceAllocationScaleTestpin the bytes the core decodes; Swift and Rust (product_ring_vrf_domain_entropy_matches_ios_vector) pin the same domain entropy.auto_signing_allocation_derives_both_secrets_from_the_normalized_product_idfails without the signing host change.feature:sso:impltests and detekt,cargo test -p truapiand fmt pass.Reproduce with
truapi-host pairing-host --network previewnet --script verify-13.ts, paired with the iOS app with the TrUAPI runtime switched off in Debug Settings: