The monolithic open-questions.md (1310 lines, 47 OQs) was large enough to be unmanageable, with high size variance (OQ-42 at 220 lines next to OQ-06 at 8). Decomposed into one file per OQ under docs/architecture/questions/ (NNN-slug.md, mirroring the ADR convention), with open-questions.md retained as the index: theme-grouped tables plus a cross-theme Deferred/Blocked section that surfaces the 6 deferred OQs with their Blocked-on conditions inline (the safe-exit visibility surface). Per-OQ content moved verbatim; all 62 inbound links stay valid (none used anchors). README's curated OQ summary dropped (now redundant with the index tables). Also seeds tasks/architecture/ with this task plus two follow-ups found during the decompose: OQ-09/10 missing structured Blocked-on fields, and the tasks/architecture/ blocker-task half of the Safe Exit protocol being unenforced.
882 B
882 B
OQ-20: Salt/KDF and Encryption Key Derivation Method
- Origin: encryption.md
- Status: resolved
- Door type: One-way (key derivation method), two-way (salt field usage)
- Priority: high
- Resolution: The vault uses SLIP-0010 HD derivation from the BIP39 seed at path
m/74'/2'/0'/0'to produce the AES-256-GCM encryption key — not PBKDF2. Thesaltfield inEncryptedDatais unused for key derivation (kept for wire-format compatibility with the TS predecessor). The TypeScript@alkdev/storagecrypto module used PBKDF2 with a password + salt; data encrypted by that method (key_version=1) cannot be decrypted by the vault and must be migrated via one-time re-encryption to key_version=2. See ADR-020 for the full rationale and migration path. - Cross-references: ADR-020, encryption.md