diff --git a/CHECKPOINT-encryption.md b/CHECKPOINT-encryption.md index f4cb723..e88cb10 100644 --- a/CHECKPOINT-encryption.md +++ b/CHECKPOINT-encryption.md @@ -1,3 +1,58 @@ +# Checkpoint — forensics log cleaned + live publish confirmed (2026-09-26) + +## Where things are +- Project: `/home/avi/Projects/Keynctr` +- Branch: `master` @ **`332ab64`** ("fix(nip46): gate remaining trace + writes to live relay sessions"). Previous: `704addc` (checkpoint), + `bc736ff` (auto-name retry), `b5c61de`, `fc2fe93`. +- Working tree clean except the standing untracked files + (COSMIC_THEME.md, icon jpeg, deferred/). +- Release binary rebuilt at 332ab64 (mtime Sep 26 20:34, real 22s + compile, not a cache hit). + +## What was completed +1. **LIVE PUBLISH CONFIRMED (was the last open item)** — el.log shows + three sign_event responses ~19:50 Sep 25 and relay probes confirm + kind:1 notes (id 5191172d01f9…, fe9a256f597f…, text "test" + + image) from npub1qn0w4… accepted on primal/damus/snort/nos.lol at + exactly those timestamps. End-to-end Amber signing works. +2. **False alarms retired**: the repeated "restored signer answered as + a different account" and duplicate "auto-name attempt" lines in + pairing-trace.log were E2E TEST traffic (wrong-identity refusal test + + loopback auto-name loop), not live Amber failures — each bogus + npub appeared exactly at test-run times (17:09 rebuild, 20:07 suite). +3. **Trace gating fix (332ab64)**: `fail()` and the background + auto-name traces now check `live_relays()` like every other site. + Verified by measurement: e2e suite run leaves pairing-trace.log + byte-identical (was 240 lines before, 240 after). +4. **Live vault pruned (not in git)**: dropped the legacy `fac852dc…` + connection row (15:37 pairing, predates client-key persistence, + superseded by 19:35 `4148a9a1…` pairing) so startup restore can't + waste a re-dial on a keyless row. Backup: + profiles_vault.json.backup-cron-20260926. Done with backend down. + +## Verified this session +- cargo test: 216 unit + 5 e2e green. clippy --all-targets: 0 warnings. + cargo fmt --check clean. cargo build --release rebuilt at 332ab64. +- Frontend untouched this session (no npm run needed). +- Serve smoke test on the REAL vault (backend was down): startup + restore fires "restoring session: peer=4148a9a1… client + pubkey=64ea18e8…" (the persisted key from the 19:35 pairing), relays + connect, no errors. Full handshake needs Amber online — user test. +- kind-0 'web5osint' confirmed live on nos.lol; profile row already + carries the name + picture in the vault. + +## Outstanding / next user steps +- One scanless restart check: launch the GUI with Amber online and + watch for "identity check on restored session: PASS" without + scanning (restore now targets only the restorable 4148a9a1 row). +- Optional: publish kind-0 to primal/damus too so naming doesn't + depend on nos.lol alone (needs one Amber signature). +- reminder: pkill patterns matching their own launch string kill the + cron shell — resolve PID by full binary path first. + +--- + # Checkpoint — auto-naming hardened (2026-09-25 eve) ## What changed since the label-step checkpoint