checkpoint: docs honesty fix at d4d87b8 (2026-09-22)

This commit is contained in:
Avi 2026-09-22 17:47:06 -05:00
commit 2e5938a3fa

View file

@ -1,3 +1,57 @@
# Checkpoint — 'keys never leave' claim corrected per-mode (2026-09-22); prior: pairing forensics de-noised
## Where things are
- Project: `/home/avi/Projects/Keynctr`
- Branch: `master` @ **`d4d87b8`** ("docs: replace blanket 'keys never leave
the machine' claim with per-mode truth"). Previous: `f6bf6a9`, `edd4e56`
(pairing feature HEAD), `deeb4f9`, `d52fa58`.
- Working tree: clean for tracked files. Untracked intentionally NOT
committed: `COSMIC_THEME.md`, `KeynectrAppIconPossibility02.jpeg`,
`deferred/` (stays deferred).
- Release binary: still built at `f6bf6a9` — `d4d87b8` changed only
Markdown docs, no rebuild needed.
- Verification at `d4d87b8`: `cargo fmt --check` clean, `cargo test` **208
unit + 3 e2e passed / 0 failed** (first run showed 1 e2e flake; both the
targeted `cargo test --test nip46_e2e` rerun and the full rerun were
green). No frontend changes (npm suite last green at `edd4e56`).
## What was completed since the last checkpoint
- **Honest security copy (`d4d87b8`)**: the blanket "keys never leave the
machine" claim in README.md (tagline), PRODUCT.md (purpose, positioning,
principle 1), and DESIGN.md (North Star) was replaced with the per-mode
truth: in embedded/bunker modes keys stay in the local encrypted vault
and never reach the renderer; in external NIP-46 signer mode the key
never *arrives* on this machine — a strictly stronger posture against
desktop compromise. README security notes gained an explicit bullet
saying external signer mode can be *more* secure. App UI
(`SignerModeScreen.tsx`) already ranked external signer "Most Secure /
Private key NEVER on this device" — no code or test changes were needed.
## Commits added (newest first)
- `d4d87b8` docs: replace blanket 'keys never leave the machine' claim with per-mode truth
## How to reproduce / exercise
- **LIVE AMBER TEST (still the only missing step from `f6bf6a9`)**: launch
the app: `cd frontend && npx vite --port 5173` then
`NOSTR_GUI_DEV_URL=http://localhost:5173 KEYNCTR_ENABLE_GPU=1 npx electron .`
Signer mode -> Show QR -> scan in Amber -> approve. Expected trace:
`pairing started: ephemeral=…` -> `inbound 24133 from …` -> `connect
response accepted (secret echo verified)` -> `paired: connection stored;
handing over to identity handshake` -> `identity adopted: npub=… —
CONNECTED`. Watch with `bash ~/Tools/keynctr-debug/watch-pairing.sh 240`.
- Docs-only change: `git show d4d87b8`.
## Outstanding / next steps
1. **Live Amber re-scan required** (cannot be done from an unattended run).
2. If trace shows `pre-handshake 'get_public_key' ignored`, relax the
connect-only gate.
3. `publish_profile_metadata` (kind 0) still signs locally — reroute
through `Signing` for external profiles (P2).
4. Step 5 (KDF upgrade), Step 6 (undo preserves ProfileSummary), Step 7
(rename pass incl. `homepage` URL).
---
# Checkpoint — pairing forensics fully de-noised; Amber fix still awaiting live test (2026-09-21)
## Where things are