[parked] Matrix 2.0 call membership via MSC4354 sticky events — investigated, deliberately NOT enabled #196
Open
opened 2026-09-17 23:24:14 -04:00 by jared
·
0 comments
No Branch/Tag Specified
lotus
update-packages
sw-fix
read-me-update
image-path-changes
dm-calls
fix-2469
renovate/element-hq-element-call-embedded-0.x
renovate/npm-i18next-http-backend-vulnerability
renovate/npm-vite-vulnerability
dev
docs-update
more-theme
fix-257
imporve-thread-reply
revert-2402-improve-menu-congestion
mxidColor-toggle
update-sw-main-msg
v4.11.1
v4.10.5
v4.10.4
v4.10.3
v4.10.2
v4.10.1
v4.10.0
v4.9.1
v4.9.0
v4.8.1
v4.8.0
v4.7.1
v4.7.0
v4.6.0
v4.5.1
v4.5.0
v4.4.0
v4.3.2
v4.3.0
v4.2.3
v4.2.2
v4.2.1
v4.2.0
v4.1.0
v4.0.3
v4.0.0
v3.2.0
v3.1.0
v3.0.0
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.8.2
v1.8.1
v1.8.0
v1.7.0
v1.6.1
v1.6.0
v1.5.1
v1.5.0
v1.4.0
v1.3.2
v1.3.1
v1.3.0
v1.2.1
v1.2.0
v1.1.0
v1.0.0
Labels
Clear labels
a11y
area: appearance
area: auth-session
area: build-ci
area: calls
area: desktop
area: media
area: messaging
area: mobile
area: moderation
area: navigation
area: notifications
area: settings
area: threads
bug
dependencies
docs
duplicate
enhancement
help wanted
invalid
needs-human-review
performance
planning
priority: critical
priority: high
priority: low
priority: medium
qa
question
research
security
tech-debt
ux
wontfix
Accessibility: keyboard, screen reader, contrast, motion
Client area: appearance
Client area: auth-session
Client area: build-ci
Client area: calls
Client area: desktop
Client area: media
Client area: messaging
Client area: mobile
Client area: moderation
Client area: navigation
Client area: notifications
Client area: settings
Client area: threads
Something is not working
Third-party package versions and advisories
README / LOTUS_* docs wrong or missing
This issue or pull request already exists
New feature
Need some help
Something is wrong
Re-render storms, leaks, heavy work on hot paths
Data loss, security hole, or crash on a main path
Broken feature or serious usability problem
Minor issue or polish
Wrong behaviour in an edge case or notable degradation
Manual QA: shipped, needs a human in a real environment
More information is needed
XSS, unsafe URLs, data leaks, auth/session
Code health, dead code, fragile patterns
Usability or visual inconsistency
This won't be fixed
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: LotusGuild/cinny#196
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Migrated from
LOTUS_TODO.mdon 2026-09-17 (the file is now reference-only).[PARKED] Matrix 2.0 call membership — MSC4354 Sticky Events (investigated 2026-07, 3 agents + live infra check)
Move MatrixRTC/Element Call call-membership from state events (MSC3401) to sticky events — the "Matrix 2.0" path. Not a flag flip; a coordinated rollout. Parked deliberately.
Findings:
msc4354_enableddefaultsfalse. Enabling is low-risk, additive, reversible — schema (sticky_eventstable) already ships unconditionally, no migration/backfill, all runtime paths flag-gated, residual rows self-expire ≤1h. The one historical/syncEDU-filter bug (#19787) was fixed in 1.155.0; SQLite guard N/A (we're Postgres).@lotusguild/element-call-embedded, bundled into Cinny at build → fleet upgrades atomically) gates sticky mode behind BOTH server support AND a per-device developer-settings radio (matrix-rtc-mode, defaultsLegacy). Enabling the flag only un-greys that radio; no client changes what it sends until a human toggles it.livekit_alias+ uses lk-jwt-service/get_token(slotm.call#ROOM); legacy uses/sfu/get(room=roomId). Both endpoints are live on our lk-jwt-service, but whether they resolve to the same LiveKit room is unverified — must confirm with a two-account cross-mode test call (one deviceMatrix_2_0, oneLegacy) before changing the default, else split-at-media.To actually adopt (future): (1) enable
msc4354_enabled: true+ restart; (2) two-account media-interop test; (3) if unified, flip EC default modeLegacy→Compatibility/Matrix_2_0in the fork + redeploy; (4) keep legacy fallback during transition. No user benefit until step 3.[ ] Matrix 2.0 call membership — MSC4354 sticky events (INVESTIGATED 2026-07, deliberately NOT enabled)
3-agent investigation after the 1.157.1 upgrade (EC-fork behavior · Synapse/upstream readiness · client-fleet composition). Conclusion: leave
msc4354_enabledOFF for now — enabling it is safe but delivers zero user-visible benefit on its own, and introduces a latent footgun.Why it's a no-op alone: the EC fork's
doesServerSupportUnstableFeature(MSC4354)probe feeds exactly one thing — whether the "Matrix 2.0" radio in Developer Settings is greyed out (DeveloperSettingsTab.tsx:349-353). The real switch is the per-devicematrixRTCModesetting (settings.ts:149-152), which defaults toLegacyand never auto-enables. Sticky sending is gated atLocalMember.ts:862(unstableSendStickyEvents: mode === Matrix_2_0). So flipping the server flag changes nothing any client sends.Verified safe: Synapse-side is additive and cleanly reversible — the
sticky_eventsschema ships unconditionally (no migration/backfill on enable), every write/read/serialize/replication path is flag-gated, disabling stops it instantly and residual rows self-expire ≤1h. The one relevant bug (#19787/syncEDU-filter) was fixed in 1.155.0; the SQLite<3.40 guard doesn't apply (we're on PG 17.10). Matrix-layer mixed-mode visibility is safe: js-sdkcollectMembersEventsreads both sticky and state membership and merges them, so sticky-mode and legacy-mode participants see each other. Ourlk-jwt-servicealready serves both JWT endpoints (legacy/sfu/getand the sticky-mode/get_token— both probed live, 400-with-validation-error = present). EC is bundled into cinny's build (@lotusguild/element-call-embedded), so the fleet upgrades atomically — the "all EC clients ≥ v0.17.0" precondition is structurally guaranteed for our own users.The one unresolved risk (blocks a real rollout, not the flag): sticky mode drops
livekit_aliasand uses/get_token(slotm.call#ROOM) while legacy uses/sfu/get(room=roomId). Whether both resolve to the same LiveKit room is a property of lk-jwt-service, not the client — unverified. If they diverge, cross-mode participants appear in each other's member list but are split at the media layer (silent, no error). Requires a two-account test call (one device on Legacy, one on Matrix 2.0) to confirm before anyone relies on it.If we ever do this: (1) run the two-account media-interop test; (2) only then consider enabling
msc4354_enabled: truein/etc/matrix-synapse/homeserver.yaml(LXC 151) + restart; (3) treat a default-mode change as a separate coordinated EC rollout. MSC4354 is still OPEN upstream (not in FCP,needs-implementation), so this stays experimental regardless.Do not enable without re-reading the investigation above; revisit when Synapse + Element Call both ship stable support.