Phase C: resolve signer from spire seed / bunker binding at bootstrap (#52) #60
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "phase-c-bunker-bootstrap"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Phase C of the NIP-46 bunker migration (#52) — the bootstrap cutover. The ATM stops loading a local signing nsec and instead resolves its signer from the spire pairing (seed → bunker, or resume from the persisted binding). Behavioural change, so it's a PR against
devrather than direct commits (the Sintra dev unit auto-pullsdev).Phases A + B (the
Signerseam, the v1 retirement, theBunkerSigner/seed parser, state.db v11) already merged todev; this PR is only the bootstrap wiring on top. ~306/-121 across 13 files.Suggested review order (smallest blast radius → largest)
packages/nostr-client/src/bunker-signer.ts(8 lines) — just a docstring correction (TTL is now a post-bind deauth cause per nsecbunkerd#27). Skim.apps/machine/electron/state-store.ts(+10) — one newresetBootstrapGate()helper. Thebunker_bindingtable + accessors already landed in Phase B.apps/machine/electron/{main,preload}.ts+src/types/electron.d.ts— the IPC bridge:get-atm-secretsnow returns{ spireSeed, bunkerBinding }instead of the raw nsec; three new handlers (save/clear binding, reset gate). Mechanical; the three declarations must stay in lockstep.apps/machine/src/services/signer-resolver.ts(NEW, 116 lines) — the heart of the PR. The pair/resume/dev-fallback decision. This is where to spend your attention. Key things to sanity-check:seedFingerprint(seed) !== binding.seedFingerprint(so a stable seed resumes, doesn't re-redeem);resetBootstrapGate()(folds in #56);apps/machine/src/services/lightning.ts(-56/+, net simpler) — drops allatmPrivateKeyplumbing, callsresolveSigner. The Phase-A seam means the swap touches exactly one point. Verify the strict-mode block and thatCONFIGno longer carries a secret.packages/clink/src/client.ts(~91 changed) — CLINK migrated fromMachineIdentityto the asyncSigner(sign/nip44). Largest single-file diff but mechanical, same pattern as Phase A. Migrated fully (not stubbed) because CLINK is returning soon for ndebit/k1. Live path is kind-21003 management; offer/debit are dormant-but-bunker-ready.apps/machine/src/App.vue(+13) — maintenance beacon resolves the same way (best-effort).fund-atm.ts+.env.example+CLAUDE.md+package.json— fund-atm resumes from the binding (better-sqlite3external in the bundle); docs forVITE_SPIRE_SEED. fund-atm is slated for deprecation.What CI / local checks cover
pnpm typecheck12/12,pnpm test104 passing, full electron prod build (vite + electron tsc + fund-atm bundle) clean.connectNewSeed/resumeFromBindingare unit-tested against a fake inner client only; the real nsecbunkerd handshake is Phase F. So this PR is safe to read/merge-to-devas the staging step, but the live pairing gets vetted on Sintra before anything reachesmain.Open coordination (not blocking this PR)
expiresAtin the seed) — posted on #52, awaiting their call.Do NOT use the MCP merge endpoint — merge via the Forgejo UI after review (per our convention).
🤖 Generated with Claude Code
get-atm-secrets now returns { spireSeed, bunkerBinding } instead of the raw nsec (one-shot semantics kept). Adds IPC handlers + preload bindings for saveBunkerBinding / clearBunkerBinding / resetBootstrapGate so the renderer can persist a pairing and re-arm the cassette-state hello on re-pair (#56). resetBootstrapGate added to state-store. Types mirrored in electron.d.ts. Part of Phase C, aiolabs/bitspire#52. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>