DAVE (Discord Audio/Video End-to-End Encryption) protocol library — pure data and state layer on rfc9420
Project description
sorrydave
Production-quality Python library for the DAVE (Discord Audio/Video End-to-End Encryption) protocol. It implements the protocol as a pure data-transformation and state-management layer on top of rfc9420 (PyMLS), with no I/O or networking: you pass in bytes (Voice Gateway opcodes, encoded media frames) and get back bytes (opcode payloads, encrypted/decrypted frames).
Features
- MLS integration: Key packages, external sender handling, proposals, commit/welcome (opcodes 25–30), exporter-based sender keys
- Sender key ratchet: Per-sender, per-epoch keys via MLS-Exporter + HKDF; cache for out-of-order decryption
- Frame transform: Codec-aware encrypt/decrypt (OPUS, VP9, VP8, H264, H265, AV1), ULEB128, truncated AES128-GCM, DAVE footer (
0xFAFA) - Identity: Pairwise fingerprint (scrypt) and displayable codes (45-digit / 30-digit)
Install
pip install -e .
Requires Python 3.9+, rfc9420, cryptography, and pycryptodome.
Minimal lifecycle
- Create a session:
DaveSession(local_user_id=123456789). - On select_protocol_ack (or prepare_epoch with
epoch=1), callsession.prepare_epoch(1)and send the returned bytes as opcode 26 (Key Package). - On opcode 25 (External Sender Package), call
session.handle_external_sender_package(package_bytes). - On opcode 27 (Proposals), call
session.handle_proposals(proposal_bytes); if it returns bytes, send them as opcode 28. - On opcode 29 (Announce Commit), call
session.handle_commit(transition_id, commit_bytes). - On opcode 30 (Welcome), call
session.handle_welcome(transition_id, welcome_bytes). - On opcode 22 (Execute Transition), parse with
parse_execute_transition(payload)to gettransition_id, then callsession.execute_transition(transition_id). - Use
session.get_encryptor().encrypt(frame, codec="OPUS")andsession.get_decryptor(sender_id).decrypt(protocol_frame)for media.
Error recovery: On InvalidCommitError, send build_invalid_commit_welcome(transition_id) as opcode 31 to the voice gateway, then call session.prepare_epoch(1) and send the returned key package as opcode 26.
API overview
DaveSession:handle_external_sender_package,prepare_epoch,handle_proposals,handle_commit,handle_welcome,execute_transition,leave_group,get_encryptor,get_decryptorFrameEncryptor.encrypt(encoded_frame, codec)/FrameDecryptor.decrypt(protocol_frame)generate_fingerprint(local_id, local_pub, remote_id, remote_pub)→ 45-digit stringdisplayable_code(data, total_digits, group_size)for epoch authenticator (e.g. 30 digits, group 5)
Scope
- In scope: MLS state, ratchet, OPUS/VP9/VP8/H264/H265/AV1 codec handling, frame encrypt/decrypt, identity fingerprint, opcode 22 parse and opcode 31 build for transition and error recovery.
- Out of scope: Voice Gateway WebSocket I/O, SFU silence packets, WebRTC depacketizer patches.
License
MIT.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file sorrydave-0.8.0.tar.gz.
File metadata
- Download URL: sorrydave-0.8.0.tar.gz
- Upload date:
- Size: 78.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
0e49445d73952a5a64415cd082c64e76c348a10829b6e071aee82d6ff3c18f72
|
|
| MD5 |
ec629d46dcc96bc1bf45f4f87f288352
|
|
| BLAKE2b-256 |
97a111eb76b83eb8153c4fe50abdbe186d0a828498cf3913475984d13b4d320a
|
File details
Details for the file sorrydave-0.8.0-py3-none-any.whl.
File metadata
- Download URL: sorrydave-0.8.0-py3-none-any.whl
- Upload date:
- Size: 43.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
e4cc776b678cde0302f075389e8e1ae3441d838c8aded701765f8b9f9521e7bf
|
|
| MD5 |
9390ead4537edf8a4411f12606535ad0
|
|
| BLAKE2b-256 |
499f2623b35edc8ce2b9c5fabfead94cd8ff7ad454313274b4d590691c39a096
|