Skip to content

perf(profile-sync-controller): Replace JS AES implementation with cryptography package - #10621

Merged
FrederikBolding merged 12 commits into
mainfrom
fb/profile-sync-encryption
Oct 1, 2026
Merged

FrederikBolding merged 12 commits into
mainfrom
fb/profile-sync-encryption

Conversation

@FrederikBolding

@FrederikBolding FrederikBolding commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Explanation

Replace @noble/ciphers AES implementation with @metamask/cryptography in encryption utilities used by profile-sync-controller. As a result of this I also had to change some of the internal types to the narrower Uint8Array<ArrayBuffer> type.

References

https://consensyssoftware.atlassian.net/browse/WPC-1331

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating changelogs for packages I've changed
  • I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them

Note

Medium Risk
Changes the AES-GCM implementation backing client-side profile sync encryption while keeping the same payload format; wrong crypto behavior would break decrypt compatibility across clients.

Overview
Profile sync encryption now uses @metamask/cryptography/aes-gcm instead of @noble/ciphers, with @metamask/cryptography added as a dependency and @noble/ciphers removed. The on-disk layout is unchanged: scrypt-derived keys and IV + ciphertext still use a 12-byte IV (via IV_LENGTH), but #encrypt / #decrypt are async and byte handling goes through @metamask/utils (stringToBytes, concatBytes, getErrorMessage).

Internal types are tightened to Uint8Array<ArrayBuffer> in the encryption cache, KDF paths, and NativeScrypt. createSHA256Hash now returns hex without a 0x prefix (remove0x(bytesToHex(...))). Tests expect generic WebCrypto-style decrypt failures instead of noble’s invalid ghash tag message.

Monorepo wiring adds @metamask/cryptography to TS project references, tsconfig.packages.json paths, Jest moduleNameMapper, README dependency graph, and changelog entry.

Reviewed by Cursor Bugbot for commit 8e2bd03. Bugbot is set up for automated code reviews on this repo. Configure here.

@FrederikBolding
FrederikBolding marked this pull request as ready for review September 30, 2026 13:15
@FrederikBolding
FrederikBolding requested review from a team as code owners September 30, 2026 13:16
@FrederikBolding
FrederikBolding marked this pull request as draft September 30, 2026 13:29
@FrederikBolding
FrederikBolding force-pushed the fb/profile-sync-encryption branch from f34700a to f7600fc Compare October 1, 2026 08:18
@FrederikBolding
FrederikBolding marked this pull request as ready for review October 1, 2026 09:17
@FrederikBolding
FrederikBolding deployed to default-branch October 1, 2026 09:17 — with GitHub Actions Active
@mathieuartu

Copy link
Copy Markdown
Contributor

@metamaskbot publish-preview

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Preview builds have been published. Learn how to use preview builds in other projects.

Expand for full list of packages and versions.
@metamask-previews/account-tree-controller@11.0.0-preview-9e306636a
@metamask-previews/accounts-controller@40.0.0-preview-9e306636a
@metamask-previews/address-book-controller@8.0.0-preview-9e306636a
@metamask-previews/advanced-chart-core@1.0.0-preview-9e306636a
@metamask-previews/ai-controllers@2.0.0-preview-9e306636a
@metamask-previews/analytics-controller@3.2.0-preview-9e306636a
@metamask-previews/analytics-data-regulation-controller@0.0.0-preview-9e306636a
@metamask-previews/announcement-controller@9.0.0-preview-9e306636a
@metamask-previews/app-metadata-controller@3.0.0-preview-9e306636a
@metamask-previews/approval-controller@10.0.0-preview-9e306636a
@metamask-previews/assets-controller@17.0.0-preview-9e306636a
@metamask-previews/assets-controllers@112.1.0-preview-9e306636a
@metamask-previews/authenticated-user-storage@4.1.0-preview-9e306636a
@metamask-previews/base-controller@10.0.0-preview-9e306636a
@metamask-previews/base-data-service@2.1.0-preview-9e306636a
@metamask-previews/bitcoin-regtest-up@2.0.0-preview-9e306636a
@metamask-previews/bridge-controller@82.0.0-preview-9e306636a
@metamask-previews/bridge-status-controller@76.3.4-preview-9e306636a
@metamask-previews/build-utils@4.0.0-preview-9e306636a
@metamask-previews/chain-agnostic-permission@2.0.0-preview-9e306636a
@metamask-previews/chomp-api-service@6.0.1-preview-9e306636a
@metamask-previews/claims-controller@1.0.2-preview-9e306636a
@metamask-previews/client-controller@2.0.0-preview-9e306636a
@metamask-previews/client-utils@3.0.3-preview-9e306636a
@metamask-previews/compliance-controller@3.0.0-preview-9e306636a
@metamask-previews/composable-controller@13.0.0-preview-9e306636a
@metamask-previews/config-registry-controller@4.0.0-preview-9e306636a
@metamask-previews/connectivity-controller@1.0.0-preview-9e306636a
@metamask-previews/controller-utils@13.0.0-preview-9e306636a
@metamask-previews/core-backend@11.0.0-preview-9e306636a
@metamask-previews/cryptography@1.0.0-preview-9e306636a
@metamask-previews/delegation-controller@4.0.0-preview-9e306636a
@metamask-previews/earn-controller@13.0.2-preview-9e306636a
@metamask-previews/eip-5792-middleware@4.0.1-preview-9e306636a
@metamask-previews/eip-7702-internal-rpc-middleware@1.0.0-preview-9e306636a
@metamask-previews/eip1193-permission-middleware@3.0.0-preview-9e306636a
@metamask-previews/eth-block-tracker@16.0.0-preview-9e306636a
@metamask-previews/eth-json-rpc-middleware@25.0.0-preview-9e306636a
@metamask-previews/eth-json-rpc-provider@7.0.0-preview-9e306636a
@metamask-previews/foundryup@2.0.0-preview-9e306636a
@metamask-previews/gas-fee-controller@27.0.0-preview-9e306636a
@metamask-previews/gator-permissions-controller@6.0.1-preview-9e306636a
@metamask-previews/geolocation-controller@2.0.0-preview-9e306636a
@metamask-previews/java-tron-up@2.0.0-preview-9e306636a
@metamask-previews/json-rpc-engine@11.0.0-preview-9e306636a
@metamask-previews/json-rpc-middleware-stream@9.0.0-preview-9e306636a
@metamask-previews/keyring-controller@28.1.0-preview-9e306636a
@metamask-previews/kyc-controller@0.6.0-preview-9e306636a
@metamask-previews/local-node-utils@2.0.0-preview-9e306636a
@metamask-previews/logging-controller@10.0.0-preview-9e306636a
@metamask-previews/message-manager@15.0.0-preview-9e306636a
@metamask-previews/messenger@3.0.0-preview-9e306636a
@metamask-previews/messenger-cli@1.0.0-preview-9e306636a
@metamask-previews/money-account-api-data-service@2.1.0-preview-9e306636a
@metamask-previews/money-account-balance-service@3.1.2-preview-9e306636a
@metamask-previews/money-account-controller@2.0.0-preview-9e306636a
@metamask-previews/money-account-upgrade-controller@5.1.0-preview-9e306636a
@metamask-previews/money-account-utils@2.1.0-preview-9e306636a
@metamask-previews/multichain-account-service@14.1.0-preview-9e306636a
@metamask-previews/multichain-api-middleware@5.0.0-preview-9e306636a
@metamask-previews/multichain-network-controller@4.0.0-preview-9e306636a
@metamask-previews/multichain-transactions-controller@8.0.0-preview-9e306636a
@metamask-previews/name-controller@10.0.0-preview-9e306636a
@metamask-previews/network-connection-banner-controller@1.0.0-preview-9e306636a
@metamask-previews/network-controller@37.0.0-preview-9e306636a
@metamask-previews/network-enablement-controller@7.0.1-preview-9e306636a
@metamask-previews/notification-services-controller@29.0.2-preview-9e306636a
@metamask-previews/passkey-controller@4.1.0-preview-9e306636a
@metamask-previews/permission-controller@14.0.0-preview-9e306636a
@metamask-previews/permission-log-controller@6.0.0-preview-9e306636a
@metamask-previews/perps-controller@19.0.0-preview-9e306636a
@metamask-previews/phishing-controller@18.2.0-preview-9e306636a
@metamask-previews/platform-api-docs@0.2.1-preview-9e306636a
@metamask-previews/polling-controller@17.0.0-preview-9e306636a
@metamask-previews/preferences-controller@24.0.0-preview-9e306636a
@metamask-previews/profile-controller@1.0.0-preview-9e306636a
@metamask-previews/profile-metrics-controller@5.1.2-preview-9e306636a
@metamask-previews/profile-sync-controller@33.0.0-preview-9e306636a
@metamask-previews/ramps-controller@26.1.0-preview-9e306636a
@metamask-previews/rate-limit-controller@8.0.0-preview-9e306636a
@metamask-previews/react-data-query@2.0.0-preview-9e306636a
@metamask-previews/remote-feature-flag-controller@7.0.0-preview-9e306636a
@metamask-previews/sample-controllers@6.0.0-preview-9e306636a
@metamask-previews/seedless-onboarding-controller@11.0.1-preview-9e306636a
@metamask-previews/selected-network-controller@27.0.0-preview-9e306636a
@metamask-previews/sentinel-api-service@2.0.0-preview-9e306636a
@metamask-previews/shield-controller@7.0.3-preview-9e306636a
@metamask-previews/signature-controller@40.0.0-preview-9e306636a
@metamask-previews/smart-transactions-controller@27.0.3-preview-9e306636a
@metamask-previews/snap-account-service@4.0.0-preview-9e306636a
@metamask-previews/social-controllers@3.4.0-preview-9e306636a
@metamask-previews/solana-test-validator-up@2.0.0-preview-9e306636a
@metamask-previews/stellar-quickstart-up@0.0.0-preview-9e306636a
@metamask-previews/storage-service@2.0.0-preview-9e306636a
@metamask-previews/subscription-controller@11.0.0-preview-9e306636a
@metamask-previews/transaction-controller@72.0.1-preview-9e306636a
@metamask-previews/transaction-pay-controller@30.0.0-preview-9e306636a
@metamask-previews/user-operation-controller@42.0.1-preview-9e306636a
@metamask-previews/utils@12.0.0-preview-9e306636a
@metamask-previews/wallet@15.1.0-preview-9e306636a
@metamask-previews/wallet-cli@0.0.0-preview-9e306636a

@mathieuartu mathieuartu left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tested manually on extension, features relying on it work without issues. Left one question, would feel more comfortable if somebody more crypto-litterate than me would also have a look, but overall looks good

Comment on lines -222 to -225
const nonce = randomBytes(ALGORITHM_NONCE_SIZE);

async #encrypt(
plaintext: Uint8Array<ArrayBuffer>,
key: Uint8Array<ArrayBuffer>,
): Promise<Uint8Array<ArrayBuffer>> {
// Encrypt and prepend nonce.
const ciphertext = gcm(key, nonce).encrypt(plaintext);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm really not an expert on those matters, so please bear with me here. Genuine question: wasn't ALGORITHM_NONCE_SIZE of importance here?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@metamask/cryptography uses a 12-byte nonce/IV as well! It is equivalent, just generated within the encryption function: https://github.com/MetaMask/core/blob/main/packages/cryptography/src/aes-gcm.ts#L5

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I wonder if we could have exported this constant? E.g we could have re-used it while decoding the bytes on the other part of the code?

So we avoid having drifiting values for ALGORITHM_NONCE_SIZE and AES_GCM_IV_LENGTH

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, makes sense, thanks! But then, if it changes one day in @metamask/cryptography, wouldn't we start having problems here:

async #decrypt(
    ciphertextAndNonce: Uint8Array<ArrayBuffer>,
    key: Uint8Array<ArrayBuffer>,
  ): Promise<Uint8Array<ArrayBuffer>> {
    // Create buffers of nonce and ciphertext.
    const nonce = ciphertextAndNonce.slice(0, ALGORITHM_NONCE_SIZE);
    const ciphertext = ciphertextAndNonce.slice(
    ...

The fact that rely both on a "silent" external constant AND a local one is making me a bit uncomfortable. WDYT?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's fair, we can export it and re-use!

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Though tbf this shouldn't change, the defacto standard is 12 bytes.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yep that's right, I feel like it still helps with the code here (especially for the encoding/decoding part)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agree and am inclined to approve as-is. But for the sake of future readers, this asymmetry should probably be fixed in a follow up PR.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@FrederikBolding FrederikBolding changed the title chore(profile-sync-controller): Replace JS AES implementation with cryptography package perf(profile-sync-controller): Replace JS AES implementation with cryptography package Oct 1, 2026

@ccharly ccharly left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM (left 1 nit about wording, but that's really minor and not necessarily "incorrect")

Comment on lines +233 to +244
ciphertextAndNonce: Uint8Array<ArrayBuffer>,
key: Uint8Array<ArrayBuffer>,
): Promise<Uint8Array<ArrayBuffer>> {
// Create buffers of nonce and ciphertext.
const nonce = ciphertextAndNonce.slice(0, ALGORITHM_NONCE_SIZE);
const nonce = ciphertextAndNonce.slice(0, IV_LENGTH);
const ciphertext = ciphertextAndNonce.slice(
ALGORITHM_NONCE_SIZE,
IV_LENGTH,
ciphertextAndNonce.length,
);

// Decrypt and return result.
return gcm(key, nonce).decrypt(ciphertext);
return decrypt(key, nonce, ciphertext);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: But I think we can use the right wording now, I'd go with Iv/iv instead of Nonce/nonce

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

They are interchangeable tbh, do you feel strongly about this?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not that much 😄 I usually see IV rather than nonce in the context of AES, but that's not incorrect neither

@FrederikBolding
FrederikBolding added this pull request to the merge queue Oct 1, 2026
Merged via the queue into main with commit f2a8ba5 Oct 1, 2026
346 checks passed
@FrederikBolding
FrederikBolding deleted the fb/profile-sync-encryption branch October 1, 2026 12:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants