From 4e79d7ed0072c6e65fe8b5abfa342d493b35601f Mon Sep 17 00:00:00 2001 From: Avi Date: Sun, 20 Sep 2026 20:45:52 -0500 Subject: [PATCH] =?UTF-8?q?checkpoint:=20sync=20to=20deeb4f9=20=E2=80=94?= =?UTF-8?q?=20e2e=20vault-isolation=20bug=20fixed;=20live=20Amber=20scan?= =?UTF-8?q?=20still=20pending=20(2026-09-20)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- CHECKPOINT-encryption.md | 72 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 72 insertions(+) diff --git a/CHECKPOINT-encryption.md b/CHECKPOINT-encryption.md index 5c08463..7c916ed 100644 --- a/CHECKPOINT-encryption.md +++ b/CHECKPOINT-encryption.md @@ -1,3 +1,75 @@ +# Checkpoint — e2e vault-isolation bug found; Amber fix awaiting live test (2026-09-20) + +## Where things are +- Project: `/home/avi/Projects/Keynctr` +- Branch: `master` @ **`deeb4f9`** ("test(e2e): assert vault isolation + actually isolated") + `d52fa58` ("test(e2e): isolate the e2e vault at the + real data_dir path"). Feature HEAD unchanged: `edd4e56` (connect-response + root-cause fix). Previous: `21c522b`, `188b2eb`, `aedde8f`, `759b5dd`, + `5aa122d`, `f59c2b1`. +- Working tree: clean for tracked files. Untracked intentionally NOT + committed: `COSMIC_THEME.md`, `KeynectrAppIconPossibility02.jpeg`, + `deferred/` (stays deferred). +- Release binary: still the `edd4e56` build (2026-09-19 20:46). Sep 20 + commits touch only `tests/` — no rebuild needed. +- **STILL NO LIVE AMBER SCAN against the fixed binary.** Proof: trace log + has zero `pairing started` lines (every real pairing writes one) and the + capture file's newest event is Sep 16 21:03. +- Verification (all green at `deeb4f9`): `cargo fmt --check` clean, + `cargo test` **208 unit + 3 e2e passed / 0 failed**, `cargo clippy + --all-targets` 0 warnings. No frontend changes (npm suite last green at + `edd4e56`). + +## What was completed since the last checkpoint +- **e2e vault-isolation bug found and fixed (`d52fa58` + `deeb4f9`)**: + both e2e tests seeded their isolation vault at + `$XDG_DATA_HOME/profiles_vault.json`, but `vault::data_dir()` is + `$XDG_DATA_HOME/keynectr` — so `App::load()` never saw the seed and + `try_migrate_legacy_vault()` silently migrated the **legacy repo vault + (real profile, plaintext secret key)** into the test process. Forensic + proof: legacy-vault backups `profiles_vault.json.backup-1789868634/670` + timestamped Sep 19 20:43:54 + 20:44:30 — exactly the cargo-test runs + around `edd4e56`. Consequence: the `identity adopted` trace lines from + Sep 19 20:43 were **e2e sessions, not a live Amber scan** (session-level + traces are not gated by `live_capture`). Fix: seed at + `tmp/keynectr/profiles_vault.json` + assert-empty guard after every e2e + `App::load()` so any future silent migration fails loudly. Verified after + the fix: repo legacy vault byte-identical, backup count unchanged (77). +- **Pairing status unchanged**: `edd4e56` (accept the NIP-46 connect + *response* shape) remains the root-cause fix; it has never yet faced a + live scan. + +## Commits added (newest first) +- `deeb4f9` test(e2e): assert vault isolation actually isolated +- `d52fa58` test(e2e): isolate the e2e vault at the real data_dir path + +## How to reproduce / exercise +- **LIVE TEST (the only missing step)**: launch the app (release binary is + current): `cd frontend && npx vite --port 5173` then + `NOSTR_GUI_DEV_URL=http://localhost:5173 KEYNCTR_ENABLE_GPU=1 npx electron .` + (or run the packaged app). Signer mode -> Show QR -> scan in Amber -> + approve. Expected: trace shows `connect response accepted (secret echo + verified)` then `identity adopted: npub=… — CONNECTED`, and the profile + row + `nip46_connections` entry land in the vault. +- Watch during a live scan: `bash ~/Tools/keynctr-debug/watch-pairing.sh 240`. +- E2E: `cargo test --test nip46_e2e` (no network; 3 tests, both connect + shapes, empty-vault isolation guards). + +## Outstanding / next steps +1. **Live Amber re-scan required** (cannot be done from an unattended + run). Trace log names the exact stop point if it stalls. +2. If trace shows `pre-handshake 'get_public_key' ignored`, relax the + connect-only gate. +3. Consider whether `identity adopted` / `session failed` trace lines + should also carry a live/e2e marker (the empty-vault guard keeps e2e out + of the real vault now, but the trace file can still mix both). +4. `publish_profile_metadata` (kind 0) still signs locally — reroute + through `Signing` for external profiles (P2). +5. Step 5 (KDF upgrade), Step 6 (undo preserves ProfileSummary), Step 7 + (rename pass incl. `homepage` URL). + +--- + # Checkpoint — Amber pairing: accept the NIP-46 connect *response* shape (2026-09-19) ## Where things are