docs-matrix-spec/changelogs
Sumner Evans 9a5cacda90
Clarify that the key backup MAC is implemented incorrectly (#1712)
* Clarify that the key backup MAC is implemented incorrectly

Due to a bug in libolm, all implementations of the
m.megolm_backup.v1.curve25519-aes-sha2 key backup algorithm incorrectly
pass an empty string through HMAC-SHA-256 to generate the `mac` property
of the `session_data`.

It was intended for the entire raw encrypted data to be passed through
HMAC-SHA-256, but the issue was caught too late in the process, and thus
we are stuck with this until a new key backup algorithm is introduced.

This commit clarifies the real-world behavior of all current
implementations.

Signed-off-by: Sumner Evans <sumner@beeper.com>
2024-01-16 14:11:44 -05:00
..
appendices/newsfragments Matrix 1.9 2023-11-29 10:05:20 -07:00
application_service/newsfragments Normalize changelog for 1.9 2023-11-27 15:58:06 -07:00
client_server/newsfragments Clarify that the key backup MAC is implemented incorrectly (#1712) 2024-01-16 14:11:44 -05:00
identity_service/newsfragments Matrix 1.8 changelog 2023-08-23 09:24:08 -06:00
internal/newsfragments Wording tweak in CONTRIBUTING.rst (#1697) 2023-12-21 18:13:26 +00:00
legacy Add a hyphen between third and party when used as an adjective (#1447) 2023-03-08 09:58:29 +00:00
push_gateway/newsfragments Matrix 1.6 2023-02-14 08:26:14 -07:00
room_versions/newsfragments Matrix 1.8 changelog 2023-08-23 09:24:08 -06:00
server_server/newsfragments Matrix 1.9 2023-11-29 10:05:20 -07:00
header.md Fix broken links to matrix-doc (#1032) 2022-04-20 16:36:14 +01:00
pyproject.toml Fix rendered changelog with new version of towncrier (#1598) 2023-07-18 17:52:38 +01:00
README.md Release process: changelog generation and docs (#3446) 2021-10-18 10:09:35 -06:00
template.md.jinja Fix rendered changelog with new version of towncrier (#1598) 2023-07-18 17:52:38 +01:00

Changelogs

Towncrier is used to manage the changelog and keep it up to date. Because of this, updating a changelog is really easy.

Generating the changelog

Please see the release docs for more information.

Creating a new changelog

There are a few places you'll have to update:

  • /layouts/shortcodes/changelog/changelog-changes.html to account for the new changelog.
  • /scripts/generate-changelog.sh to render the changelog for releases.
  • Supporting documentation such as the contributing guidelines.