Skip to main content

vector_core/community/v2/
derive.rs

1//! Concord v2 key derivations — CORD-02 Appendix A. **FROZEN.**
2//!
3//! Everything v2 addresses on the wire derives from a Community secret through
4//! one of the shapes below; changing any labeled byte re-addresses every prior
5//! event ("a breaking change re-labels and becomes a different universe").
6//! The layout is locked by the golden vectors in the test module — minted by an
7//! independent implementation — treat those as the spec.
8//!
9//! Construction (A.1): `HKDF-SHA256(ikm=secret, salt=∅, info, L=32)` where
10//! `info = utf8(label) || 0x00 || id[32] || epoch_be[8]?`
11//!   - `id` is ALWAYS present: 32 raw bytes, all-zeroes where a label has no
12//!     meaningful id.
13//!   - the epoch (u64 big-endian) is the ONLY omittable field: labels marked
14//!     no-epoch omit the 8 bytes entirely.
15//!   - the `scalar_normalize` retry counter (A.3) appends AFTER whatever fields
16//!     are present, starting at byte value 0. (v1's equivalent starts its retry
17//!     byte at 1 — the two conventions differ only in a ~2⁻¹²⁸ branch, but v2
18//!     follows the spec exactly.)
19//!
20//! These are DISTINCT from v1's `vector-community/v1/*` labels — the two
21//! protocols are different address universes by construction. The one label the
22//! specs share is the edition hash (`vector-community/v1/edition`,
23//! `community::version::EDITION_LABEL`), which upstream froze verbatim.
24
25use hkdf::Hkdf;
26use nostr_sdk::prelude::nip44::v2::ConversationKey;
27use nostr_sdk::prelude::{Keys, PublicKey, SecretKey};
28use sha2::{Digest, Sha256};
29
30use super::super::{ChannelId, CommunityId, Epoch};
31
32/// A.6 purpose labels. Part of the wire format — append, never edit or reuse.
33const LABEL_CHANNEL: &str = "concord/channel";
34const LABEL_CONTROL: &str = "concord/control";
35const LABEL_REKEY_PSEUDONYM: &str = "concord/rekey-pseudonym";
36const LABEL_BASE_REKEY_PSEUDONYM: &str = "concord/base-rekey-pseudonym";
37const LABEL_RECIPIENT_PSEUDONYM: &str = "concord/recipient-pseudonym";
38const LABEL_GUESTBOOK: &str = "concord/guestbook";
39const LABEL_VOICE_SIGNER: &str = "concord/voice-signer";
40const LABEL_VOICE_MEDIA: &str = "concord/voice-media";
41const LABEL_VOICE_SENDER: &str = "concord/voice-sender";
42const LABEL_DISSOLVED: &str = "concord/dissolved";
43const LABEL_GRANT: &str = "concord/grant";
44const LABEL_BANLIST: &str = "concord/banlist";
45const LABEL_PINS: &str = "concord/pins";
46const LABEL_INVITE_LINKS: &str = "concord/invite-links";
47const LABEL_INVITE_KEY: &str = "concord/invite-key";
48/// A.4 community_id commitment prefix — plain SHA-256, NOT the hkdf shape.
49const LABEL_COMMUNITY: &str = "concord/community";
50/// A.5 epoch-key commitment prefix — plain SHA-256.
51const LABEL_EPOCH_COMMITMENT: &str = "concord/epoch-key-commitment";
52
53const ZERO32: [u8; 32] = [0u8; 32];
54
55/// The size of a public-invite unlock token (CORD-05 §2) — 16 bytes in v2
56/// (v1 tokens were 32).
57pub const TOKEN_LEN: usize = 16;
58
59/// Build the frozen A.1 `info` byte string. `epoch` is `None` for the no-epoch
60/// labels (grant/banlist/invite-links/invite-key/dissolved/voice-sender).
61fn build_info(label: &str, id32: &[u8; 32], epoch: Option<u64>) -> Vec<u8> {
62    let mut info = Vec::with_capacity(label.len() + 1 + 32 + 8);
63    info.extend_from_slice(label.as_bytes());
64    info.push(0x00);
65    info.extend_from_slice(id32);
66    if let Some(e) = epoch {
67        info.extend_from_slice(&e.to_be_bytes());
68    }
69    info
70}
71
72/// HKDF-SHA256 to 32 bytes with a zero-length salt (RFC 5869: identical PRK to
73/// a 32-zero-byte salt under HMAC-SHA256). `ikm` length varies by caller: 32
74/// for keys/ids, 64 for the recipient-locator pair, 16 for an invite token.
75fn hkdf32(ikm: &[u8], info: &[u8]) -> [u8; 32] {
76    let hk = Hkdf::<Sha256>::new(None, ikm);
77    let mut okm = [0u8; 32];
78    hk.expand(info, &mut okm)
79        .expect("HKDF expand of 32 bytes is infallible");
80    okm
81}
82
83/// A.3 `scalar_normalize`: reduce an hkdf seed to a valid secp256k1 secret key.
84/// First attempt carries NO counter byte; on rejection append one incrementing
85/// counter byte to the info and retry, the counter starting at 0. The reject
86/// branch is ~2⁻¹²⁸ rare; the counter keeps it deterministic cross-impl.
87fn hkdf_to_secret_key(ikm: &[u8], base_info: &[u8]) -> SecretKey {
88    if let Ok(sk) = SecretKey::from_slice(&hkdf32(ikm, base_info)) {
89        return sk;
90    }
91    for counter in 0u8..=255 {
92        let mut info = base_info.to_vec();
93        info.push(counter);
94        if let Ok(sk) = SecretKey::from_slice(&hkdf32(ikm, &info)) {
95            return sk;
96        }
97    }
98    unreachable!("secp256k1 scalar rejection 257 times running is impossible")
99}
100
101/// A.2 `group_key` — a plane's stream keypair. The x-only pubkey is the on-wire
102/// Stream address (the `authors` filter), the secret key signs the plane's
103/// wraps, and the NIP-44 self-ECDH conversation key encrypts them. Only a
104/// holder of the deriving secret can produce any of the three, so only members
105/// can even *identify* a plane's traffic.
106#[derive(Clone)]
107pub struct GroupKey {
108    keys: Keys,
109    conv_key: ConversationKey,
110}
111
112impl GroupKey {
113    fn derive(label: &str, secret: &[u8], id32: &[u8; 32], epoch: Option<u64>) -> Self {
114        let info = build_info(label, id32, epoch);
115        let sk = hkdf_to_secret_key(secret, &info);
116        let keys = Keys::new(sk);
117        let conv_key = ConversationKey::derive(keys.secret_key(), &keys.public_key())
118            .expect("self-ECDH of a valid keypair cannot fail");
119        GroupKey { keys, conv_key }
120    }
121
122    /// The Stream address (x-only pubkey) — what `authors` filters match.
123    pub fn pk(&self) -> PublicKey {
124        self.keys.public_key()
125    }
126
127    /// The Stream address as lowercase hex.
128    pub fn pk_hex(&self) -> String {
129        self.keys.public_key().to_hex()
130    }
131
132    /// The keypair that signs this plane's wraps.
133    pub fn keys(&self) -> &Keys {
134        &self.keys
135    }
136
137    /// The NIP-44 conversation key (self-ECDH) that encrypts this plane's wraps.
138    pub fn conv_key(&self) -> &ConversationKey {
139        &self.conv_key
140    }
141}
142
143impl std::fmt::Debug for GroupKey {
144    // No key material in logs — address only.
145    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
146        f.debug_struct("GroupKey").field("pk", &self.pk_hex()).finish()
147    }
148}
149
150// ── Plane keys (CORD-02 §5, CORD-03 §1, CORD-06 §2) ─────────────────────────
151
152/// A Channel's Chat Plane group key. `secret` is the `community_root` for a
153/// Public Channel (at the root epoch) or the Channel's independent key for a
154/// Private one (at its own channel epoch) — CORD-03 §1. The channel id in the
155/// derivation gives every Channel a distinct address regardless of which secret
156/// feeds it.
157pub fn channel_group_key(secret: &[u8; 32], channel_id: &ChannelId, epoch: Epoch) -> GroupKey {
158    GroupKey::derive(LABEL_CHANNEL, secret, &channel_id.0, Some(epoch.0))
159}
160
161/// The Control Plane's group key (community_root-keyed, community-id-bound).
162pub fn control_group_key(community_root: &[u8; 32], community_id: &CommunityId, epoch: Epoch) -> GroupKey {
163    GroupKey::derive(LABEL_CONTROL, community_root, &community_id.0, Some(epoch.0))
164}
165
166/// The Guestbook Plane's group key (community_root-keyed, community-id-bound).
167pub fn guestbook_group_key(community_root: &[u8; 32], community_id: &CommunityId, epoch: Epoch) -> GroupKey {
168    GroupKey::derive(LABEL_GUESTBOOK, community_root, &community_id.0, Some(epoch.0))
169}
170
171/// A private Channel's rekey address for `new_epoch`, keyed by the
172/// community_root the receiver already holds (CORD-06 §2) — root-keyed, not
173/// channel-keyed, so any member recovers any epoch's rekey directly (no
174/// ratchet; epochs stay independently recoverable).
175pub fn channel_rekey_group_key(root: &[u8; 32], channel_id: &ChannelId, new_epoch: Epoch) -> GroupKey {
176    GroupKey::derive(LABEL_REKEY_PSEUDONYM, root, &channel_id.0, Some(new_epoch.0))
177}
178
179/// The base-rotation rekey address for `new_epoch`, keyed by the PRIOR
180/// community_root — the base has no stable key above it, so the prior root is
181/// the one handle every retained member holds through the rotation (CORD-06 §2/§3).
182pub fn base_rekey_group_key(prior_root: &[u8; 32], community_id: &CommunityId, new_epoch: Epoch) -> GroupKey {
183    GroupKey::derive(LABEL_BASE_REKEY_PSEUDONYM, prior_root, &community_id.0, Some(new_epoch.0))
184}
185
186/// The dissolution tombstone's group key — derived from the community_id ALONE
187/// (no key, no epoch), so every member past or present resolves the same
188/// address and a Refounding can never strand the grave (CORD-02 §9).
189pub fn dissolved_group_key(community_id: &CommunityId) -> GroupKey {
190    GroupKey::derive(LABEL_DISSOLVED, &community_id.0, &ZERO32, None)
191}
192
193// ── Voice sub-keys (CORD-07 §1/§3 — Vector defers voice; derivations frozen
194//    now so the registry can't drift) ─────────────────────────────────────────
195
196/// A voice Channel's SFU room keypair: `pk` IS the room name, `sk` signs token
197/// grants. Same (secret, epoch) pair that addresses the Channel's Chat Plane,
198/// so the room rolls exactly when the Channel's key does.
199pub fn voice_group_key(secret: &[u8; 32], channel_id: &ChannelId, epoch: Epoch) -> GroupKey {
200    GroupKey::derive(LABEL_VOICE_SIGNER, secret, &channel_id.0, Some(epoch.0))
201}
202
203/// A voice Channel's raw 32-byte media-encryption root — never feeds a cipher
204/// directly, every publisher's per-sender frame key derives from it.
205pub fn voice_media_key(secret: &[u8; 32], channel_id: &ChannelId, epoch: Epoch) -> [u8; 32] {
206    hkdf32(secret, &build_info(LABEL_VOICE_MEDIA, &channel_id.0, Some(epoch.0)))
207}
208
209/// A publisher's per-sender frame key material:
210/// `hkdf(voice_media_key, "concord/voice-sender", sha256(utf8(identity)))` —
211/// epoch omitted, the media key already carries it. Distinct per-sender keys
212/// partition the AEAD nonce domains.
213pub fn voice_sender_key(media_key: &[u8; 32], identity: &str) -> [u8; 32] {
214    let id: [u8; 32] = Sha256::digest(identity.as_bytes()).into();
215    hkdf32(media_key, &build_info(LABEL_VOICE_SENDER, &id, None))
216}
217
218// ── Keyless coordinates (32-byte edition locators; community-id-bound so they
219//    survive every Refounding — CORD-04 §1) ──────────────────────────────────
220
221/// A member's Grant entity coordinate (the edition `eid`).
222pub fn grant_locator(community_id: &CommunityId, member_xonly: &[u8; 32]) -> [u8; 32] {
223    hkdf32(&community_id.0, &build_info(LABEL_GRANT, member_xonly, None))
224}
225
226/// The community-wide Banlist coordinate.
227pub fn banlist_locator(community_id: &CommunityId) -> [u8; 32] {
228    hkdf32(&community_id.0, &build_info(LABEL_BANLIST, &ZERO32, None))
229}
230
231/// A Channel's Pin List coordinate (CORD-04 §7).
232pub fn pins_locator(community_id: &CommunityId, channel_id: &ChannelId) -> [u8; 32] {
233    hkdf32(&community_id.0, &build_info(LABEL_PINS, &channel_id.0, None))
234}
235
236/// A creator's invite-link Registry coordinate (CORD-05 §5) — bound to the
237/// creator so each creator owns exactly their own list.
238pub fn invite_links_locator(community_id: &CommunityId, creator_xonly: &[u8; 32]) -> [u8; 32] {
239    hkdf32(&community_id.0, &build_info(LABEL_INVITE_LINKS, creator_xonly, None))
240}
241
242/// A rekey blob's per-recipient locator (CORD-06 §2):
243/// `hkdf(rotator_xonly || recipient_xonly, "concord/recipient-pseudonym", scope_id, new_epoch)`.
244///
245/// Derived from PUBLIC inputs on purpose (full NIP-46 bunker parity, no raw-key
246/// access) — which means a locator match proves NOTHING. It is a lookup index
247/// only; authenticity rests on the rotator's seal + authority check and the
248/// blob's bound plaintext (D1 security relocation — never port v1's
249/// locator-match-⇒-authentic assumption).
250pub fn recipient_locator(
251    rotator_xonly: &[u8; 32],
252    recipient_xonly: &[u8; 32],
253    scope_id: &[u8; 32],
254    new_epoch: Epoch,
255) -> [u8; 32] {
256    let mut ikm = [0u8; 64];
257    ikm[..32].copy_from_slice(rotator_xonly);
258    ikm[32..].copy_from_slice(recipient_xonly);
259    hkdf32(&ikm, &build_info(LABEL_RECIPIENT_PSEUDONYM, scope_id, Some(new_epoch.0)))
260}
261
262/// The public-invite bundle decrypt key, derived from the link's 16-byte
263/// unlock token alone (CORD-05 §2).
264pub fn invite_bundle_key(token: &[u8; TOKEN_LEN]) -> [u8; 32] {
265    hkdf32(token, &build_info(LABEL_INVITE_KEY, &ZERO32, None))
266}
267
268// ── A.4: the self-certifying community_id ────────────────────────────────────
269
270/// `community_id = sha256("concord/community" || owner_xonly || owner_salt)` —
271/// a plain SHA-256 commitment, NOT the hkdf shape. Ownership is a property of
272/// the id itself: forging a different owner onto an existing id is a
273/// second-preimage on SHA-256. (This is the root fix for the v1 forgeable
274/// owner-attestation anchor.)
275pub fn community_id_of(owner_xonly: &[u8; 32], owner_salt: &[u8; 32]) -> CommunityId {
276    let mut h = Sha256::new();
277    h.update(LABEL_COMMUNITY.as_bytes());
278    h.update(owner_xonly);
279    h.update(owner_salt);
280    CommunityId(h.finalize().into())
281}
282
283/// Verify a claimed `(owner, salt)` pair reproduces `community_id`. Every
284/// bundle, pointer, and rehydrate path MUST pass this before trusting a claimed
285/// owner.
286pub fn verify_community_id(community_id: &CommunityId, owner_xonly: &[u8; 32], owner_salt: &[u8; 32]) -> bool {
287    community_id_of(owner_xonly, owner_salt) == *community_id
288}
289
290// ── A.5: the epoch-key commitment ────────────────────────────────────────────
291
292/// `sha256("concord/epoch-key-commitment" || prev_epoch_be[8] || prev_key[32])`
293/// — the `prevcommit` continuity check on every rekey (CORD-06 §2). A
294/// convergence mechanism, never a secrecy one.
295pub fn epoch_key_commitment(prev_epoch: Epoch, prev_key: &[u8; 32]) -> [u8; 32] {
296    let mut h = Sha256::new();
297    h.update(LABEL_EPOCH_COMMITMENT.as_bytes());
298    h.update(prev_epoch.0.to_be_bytes());
299    h.update(prev_key);
300    h.finalize().into()
301}
302
303#[cfg(test)]
304mod tests {
305    use super::*;
306
307    // Fixed test inputs. The golden hex below was produced by an INDEPENDENT
308    // implementation (Python: hmac+hashlib RFC 5869 HKDF, and pure-integer
309    // secp256k1 point math for the x-only pubkeys), so a match proves the
310    // construction — including the secp keypair step — is correct
311    // cross-implementation, not merely self-consistent. If any of these
312    // assertions ever change, the wire format changed — that must be a
313    // conscious, versioned decision.
314    fn secret() -> [u8; 32] {
315        // 0x00,0x01,..,0x1f
316        let mut k = [0u8; 32];
317        for (i, b) in k.iter_mut().enumerate() {
318            *b = i as u8;
319        }
320        k
321    }
322
323    fn id32() -> [u8; 32] {
324        // 0xff,0xfe,..,0xe0
325        let mut id = [0u8; 32];
326        for (i, b) in id.iter_mut().enumerate() {
327            *b = (255 - i) as u8;
328        }
329        id
330    }
331
332    fn alt() -> [u8; 32] {
333        [0x11u8; 32]
334    }
335
336    fn cid() -> CommunityId {
337        CommunityId(id32())
338    }
339
340    fn chan() -> ChannelId {
341        ChannelId(id32())
342    }
343
344    /// A multibyte epoch whose big-endian bytes are order-revealing.
345    const EPOCH_MULTI: u64 = 0x0102030405060708;
346
347    const GOLDEN_CHANNEL_E0_SEED: &str = "1a99a5958bf9fcc5336e6e19db42aabf36ffbfa12f38a1d5fbde2ae383ed751b";
348    const GOLDEN_CHANNEL_E0_PK: &str = "7a5c5dff759a63f1fc2779864487432bae3d1ea72c4ffabd39f4c1fdaf62097a";
349    const GOLDEN_CHANNEL_EMULTI_PK: &str = "f20c7d192cc87615d7341e86f38f85303f4708b40232d4fea521ab8217767391";
350    const GOLDEN_CONTROL_E0_PK: &str = "c43df20bf4d6eeaea5149619662ffe9b211f31e11bb4a59f56b6e906f702d46f";
351    const GOLDEN_GUESTBOOK_E0_PK: &str = "ad09de582026fa7a052db18bb5827fa24c15e929d59aadcc91efb8508f5368ad";
352    const GOLDEN_CHANNEL_REKEY_E1_PK: &str = "7c55cdb957e9db2b4800d687b2a07d3f7066b1a35824a1e86ba871f55e87e8b5";
353    const GOLDEN_BASE_REKEY_E1_PK: &str = "fb2fa44fba66ba15595f784255a1cb569531db8784432ac0e4fe838498dd9dea";
354    const GOLDEN_DISSOLVED_PK: &str = "4d3d55d88fdf9d9c2089651e5cbb0dfa93b6b9b10cdcb2319b0dce1a1398096a";
355    const GOLDEN_GRANT_LOCATOR: &str = "fd2f88cc7f1eb8d7d862c91dc22afe700c358d1845158b3f353b769ce4898e35";
356    const GOLDEN_BANLIST_LOCATOR: &str = "88089214afae6d3c412fd817ada44d6df4d485a53565646471e74476397693c9";
357    const GOLDEN_INVITE_LINKS_LOCATOR: &str = "f4ae29994165767bac23e8dce630f81b926d2c8aa150e5cbf0bdf75865e8379a";
358    const GOLDEN_RECIPIENT_LOCATOR: &str = "342deb400e191f0f52c81f27600934552550beb85aa9bf169f02d0e7f826cf74";
359    const GOLDEN_INVITE_KEY: &str = "94bf8b0d89e579ddaeccf8d9db3f5de5c86a1259c597f2560ff0120173bc5e1f";
360    const GOLDEN_VOICE_MEDIA_E0: &str = "8ab5b935c5e17f156563860ae6263f3700bfd836c326f8b3d7082be2fbaef6a0";
361    const GOLDEN_VOICE_SIGNER_E0_PK: &str = "7591f1306c265ee1dce6a07b72c76fadb3af13bf9ccce0d284cb3af6134211a1";
362    const GOLDEN_VOICE_SENDER: &str = "9ce1c11a39ce16a84b72c2697724a39e5c41ec07f4d703dcb01241271837599e";
363    const GOLDEN_COMMUNITY_ID: &str = "2b790bd59df98bdc52092b74ebd6933a89ef8eaeecc9030861cbdeae7c814c46";
364    const GOLDEN_EPOCH_COMMITMENT: &str = "3e6d6a3c9973c16d1ca7c5602d36979927c55c21a7e2c840f883af3f047e80a4";
365
366    fn hex(bytes: &[u8]) -> String {
367        crate::simd::hex::bytes_to_hex_32(bytes.try_into().expect("32 bytes"))
368    }
369
370    #[test]
371    fn channel_group_key_golden_vector() {
372        let gk = channel_group_key(&secret(), &chan(), Epoch(0));
373        // The hkdf seed is a valid scalar (overwhelming case), so sk == seed —
374        // pinning both proves hkdf AND the secp keypair step.
375        assert_eq!(hex(gk.keys().secret_key().as_secret_bytes()), GOLDEN_CHANNEL_E0_SEED);
376        assert_eq!(gk.pk_hex(), GOLDEN_CHANNEL_E0_PK);
377    }
378
379    #[test]
380    fn channel_group_key_golden_multibyte_epoch_is_big_endian() {
381        let gk = channel_group_key(&secret(), &chan(), Epoch(EPOCH_MULTI));
382        assert_eq!(gk.pk_hex(), GOLDEN_CHANNEL_EMULTI_PK);
383    }
384
385    #[test]
386    fn control_group_key_golden_vector() {
387        assert_eq!(control_group_key(&secret(), &cid(), Epoch(0)).pk_hex(), GOLDEN_CONTROL_E0_PK);
388    }
389
390    #[test]
391    fn guestbook_group_key_golden_vector() {
392        assert_eq!(guestbook_group_key(&secret(), &cid(), Epoch(0)).pk_hex(), GOLDEN_GUESTBOOK_E0_PK);
393    }
394
395    #[test]
396    fn rekey_group_keys_golden_vectors() {
397        assert_eq!(
398            channel_rekey_group_key(&secret(), &chan(), Epoch(1)).pk_hex(),
399            GOLDEN_CHANNEL_REKEY_E1_PK
400        );
401        assert_eq!(
402            base_rekey_group_key(&secret(), &cid(), Epoch(1)).pk_hex(),
403            GOLDEN_BASE_REKEY_E1_PK
404        );
405    }
406
407    #[test]
408    fn dissolved_group_key_golden_and_is_epoch_free() {
409        assert_eq!(dissolved_group_key(&cid()).pk_hex(), GOLDEN_DISSOLVED_PK);
410        // Epoch omission is real omission, not epoch=0: a manual derivation WITH
411        // an epoch field of 0 must land elsewhere.
412        let with_epoch = GroupKey::derive(LABEL_DISSOLVED, &cid().0, &ZERO32, Some(0));
413        assert_ne!(with_epoch.pk_hex(), GOLDEN_DISSOLVED_PK);
414    }
415
416    #[test]
417    fn locator_golden_vectors() {
418        assert_eq!(hex(&grant_locator(&cid(), &alt())), GOLDEN_GRANT_LOCATOR);
419        assert_eq!(hex(&banlist_locator(&cid())), GOLDEN_BANLIST_LOCATOR);
420        assert_eq!(hex(&invite_links_locator(&cid(), &alt())), GOLDEN_INVITE_LINKS_LOCATOR);
421        assert_eq!(
422            hex(&recipient_locator(&secret(), &alt(), &id32(), Epoch(3))),
423            GOLDEN_RECIPIENT_LOCATOR
424        );
425        assert_eq!(hex(&invite_bundle_key(&[0x07u8; TOKEN_LEN])), GOLDEN_INVITE_KEY);
426    }
427
428    #[test]
429    fn voice_golden_vectors() {
430        let media = voice_media_key(&secret(), &chan(), Epoch(0));
431        assert_eq!(hex(&media), GOLDEN_VOICE_MEDIA_E0);
432        assert_eq!(voice_group_key(&secret(), &chan(), Epoch(0)).pk_hex(), GOLDEN_VOICE_SIGNER_E0_PK);
433        assert_eq!(
434            hex(&voice_sender_key(&media, "00112233445566778899aabbccddeeff")),
435            GOLDEN_VOICE_SENDER
436        );
437    }
438
439    #[test]
440    fn community_id_golden_and_verifies() {
441        let id = community_id_of(&secret(), &alt());
442        assert_eq!(hex(&id.0), GOLDEN_COMMUNITY_ID);
443        assert!(verify_community_id(&id, &secret(), &alt()));
444        // Wrong owner or wrong salt must fail the commitment.
445        assert!(!verify_community_id(&id, &alt(), &alt()));
446        assert!(!verify_community_id(&id, &secret(), &id32()));
447    }
448
449    #[test]
450    fn epoch_key_commitment_golden_and_binds_both_inputs() {
451        assert_eq!(hex(&epoch_key_commitment(Epoch(2), &secret())), GOLDEN_EPOCH_COMMITMENT);
452        assert_ne!(hex(&epoch_key_commitment(Epoch(3), &secret())), GOLDEN_EPOCH_COMMITMENT);
453        assert_ne!(hex(&epoch_key_commitment(Epoch(2), &alt())), GOLDEN_EPOCH_COMMITMENT);
454    }
455
456    #[test]
457    fn labels_domain_separate_every_plane() {
458        // One (secret, id, epoch) triple across every keyed label — all
459        // addresses must be pairwise distinct.
460        let pks = [
461            channel_group_key(&secret(), &chan(), Epoch(0)).pk_hex(),
462            control_group_key(&secret(), &cid(), Epoch(0)).pk_hex(),
463            guestbook_group_key(&secret(), &cid(), Epoch(0)).pk_hex(),
464            channel_rekey_group_key(&secret(), &chan(), Epoch(0)).pk_hex(),
465            base_rekey_group_key(&secret(), &cid(), Epoch(0)).pk_hex(),
466            voice_group_key(&secret(), &chan(), Epoch(0)).pk_hex(),
467        ];
468        let unique: std::collections::HashSet<_> = pks.iter().collect();
469        assert_eq!(unique.len(), pks.len(), "two labels collided on one address");
470    }
471
472    #[test]
473    fn epoch_rotates_every_keyed_address() {
474        assert_ne!(
475            channel_group_key(&secret(), &chan(), Epoch(0)).pk_hex(),
476            channel_group_key(&secret(), &chan(), Epoch(1)).pk_hex()
477        );
478        assert_ne!(
479            control_group_key(&secret(), &cid(), Epoch(0)).pk_hex(),
480            control_group_key(&secret(), &cid(), Epoch(1)).pk_hex()
481        );
482        assert_ne!(
483            guestbook_group_key(&secret(), &cid(), Epoch(0)).pk_hex(),
484            guestbook_group_key(&secret(), &cid(), Epoch(1)).pk_hex()
485        );
486    }
487
488    #[test]
489    fn recipient_locator_binds_direction_scope_and_epoch() {
490        let base = recipient_locator(&secret(), &alt(), &id32(), Epoch(1));
491        // Rotator↔recipient direction matters (concatenation order).
492        assert_ne!(recipient_locator(&alt(), &secret(), &id32(), Epoch(1)), base);
493        assert_ne!(recipient_locator(&secret(), &alt(), &id32(), Epoch(2)), base);
494        assert_ne!(recipient_locator(&secret(), &alt(), &ZERO32, Epoch(1)), base);
495    }
496
497    #[test]
498    fn conv_key_is_deterministic_self_ecdh() {
499        let a = channel_group_key(&secret(), &chan(), Epoch(0));
500        let b = channel_group_key(&secret(), &chan(), Epoch(0));
501        assert_eq!(a.conv_key().as_bytes(), b.conv_key().as_bytes());
502    }
503}