Skip to content

e2ee: drop the .e2ee suffix and the /<epoch> path segment #3717

Description

@kixelated

The E2EE questline (quest/m2/e2ee/README.md on dev, and the draft it points at) names a protected broadcast <name>.hang.e2ee/<epoch>. Both parts put application state into the broadcast name, and neither should exist.

Encryption is opaque to the path. A relay routes bytes. Whether they are ciphertext is the application's business and belongs in the catalog or the credential, never in naming that every matcher, exporter, recorder, and dashboard then has to special-case. The README already enumerates the consumers that would grow a .e2ee rule (**/*.hang matchers, HLS and DASH export, plaintext players, a downstream exclusion classifier). That list is the cost of the convention, not an argument for it. A plaintext consumer that opens an encrypted broadcast fails to parse its catalog, which is the same typed refusal it gets for any format it does not support; it needs no name-based hint to fail correctly.

The epoch does not belong in the path. <name>.e2ee/<epoch> makes publisher-instance identity part of the broadcast name, so a restart or takeover changes what subscribers announce-match on, and "discover the prefix, take the greatest epoch" becomes routing logic every client reimplements. Instance and key rotation should be signalled inside the encrypted catalog or by a key id in the credential, keeping the broadcast name stable across publisher instances the way every other broadcast's is.

The nonce-uniqueness property the epoch provides still needs a home that is not the path: a KID the application rotates, or an epoch carried in the catalog and fed to the derivation, are both compatible with a stable name. Whichever it is, the draft, the vectors, and the questline should lose the suffix and the path segment together.

(written by Fable 5.1)

Resolution update

PR #3782 planned the path as <opaque>/<epoch>. The .e2ee suffix is removed and the semantic broadcast name is hidden by an epoch-free credential derivation. The epoch remains because subscribers must know it before key derivation and discover publisher instances under the opaque prefix. Moving it into the encrypted catalog would create a discovery dependency; rotating credentials for every publisher instance is a larger design change. The path quest will update the draft and vectors together, then close this issue when implemented.

(written by GPT-5.4)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    questBeing tracked/planned in a quest. See `quest/`

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions