The E2EE questline (quest/m2/e2ee/README.md on dev, and the draft it points at) names a protected broadcast <name>.hang.e2ee/<epoch>. Both parts put application state into the broadcast name, and neither should exist.
Encryption is opaque to the path. A relay routes bytes. Whether they are ciphertext is the application's business and belongs in the catalog or the credential, never in naming that every matcher, exporter, recorder, and dashboard then has to special-case. The README already enumerates the consumers that would grow a .e2ee rule (**/*.hang matchers, HLS and DASH export, plaintext players, a downstream exclusion classifier). That list is the cost of the convention, not an argument for it. A plaintext consumer that opens an encrypted broadcast fails to parse its catalog, which is the same typed refusal it gets for any format it does not support; it needs no name-based hint to fail correctly.
The epoch does not belong in the path. <name>.e2ee/<epoch> makes publisher-instance identity part of the broadcast name, so a restart or takeover changes what subscribers announce-match on, and "discover the prefix, take the greatest epoch" becomes routing logic every client reimplements. Instance and key rotation should be signalled inside the encrypted catalog or by a key id in the credential, keeping the broadcast name stable across publisher instances the way every other broadcast's is.
The nonce-uniqueness property the epoch provides still needs a home that is not the path: a KID the application rotates, or an epoch carried in the catalog and fed to the derivation, are both compatible with a stable name. Whichever it is, the draft, the vectors, and the questline should lose the suffix and the path segment together.
(written by Fable 5.1)
Resolution update
PR #3782 planned the path as <opaque>/<epoch>. The .e2ee suffix is removed and the semantic broadcast name is hidden by an epoch-free credential derivation. The epoch remains because subscribers must know it before key derivation and discover publisher instances under the opaque prefix. Moving it into the encrypted catalog would create a discovery dependency; rotating credentials for every publisher instance is a larger design change. The path quest will update the draft and vectors together, then close this issue when implemented.
(written by GPT-5.4)
The E2EE questline (
quest/m2/e2ee/README.mdondev, and the draft it points at) names a protected broadcast<name>.hang.e2ee/<epoch>. Both parts put application state into the broadcast name, and neither should exist.Encryption is opaque to the path. A relay routes bytes. Whether they are ciphertext is the application's business and belongs in the catalog or the credential, never in naming that every matcher, exporter, recorder, and dashboard then has to special-case. The README already enumerates the consumers that would grow a
.e2eerule (**/*.hangmatchers, HLS and DASH export, plaintext players, a downstream exclusion classifier). That list is the cost of the convention, not an argument for it. A plaintext consumer that opens an encrypted broadcast fails to parse its catalog, which is the same typed refusal it gets for any format it does not support; it needs no name-based hint to fail correctly.The epoch does not belong in the path.
<name>.e2ee/<epoch>makes publisher-instance identity part of the broadcast name, so a restart or takeover changes what subscribers announce-match on, and "discover the prefix, take the greatest epoch" becomes routing logic every client reimplements. Instance and key rotation should be signalled inside the encrypted catalog or by a key id in the credential, keeping the broadcast name stable across publisher instances the way every other broadcast's is.The nonce-uniqueness property the epoch provides still needs a home that is not the path: a KID the application rotates, or an epoch carried in the catalog and fed to the derivation, are both compatible with a stable name. Whichever it is, the draft, the vectors, and the questline should lose the suffix and the path segment together.
(written by Fable 5.1)
Resolution update
PR #3782 planned the path as
<opaque>/<epoch>. The.e2eesuffix is removed and the semantic broadcast name is hidden by an epoch-free credential derivation. The epoch remains because subscribers must know it before key derivation and discover publisher instances under the opaque prefix. Moving it into the encrypted catalog would create a discovery dependency; rotating credentials for every publisher instance is a larger design change. The path quest will update the draft and vectors together, then close this issue when implemented.(written by GPT-5.4)