diff --git a/CHECKPOINT-encryption.md b/CHECKPOINT-encryption.md index 189fdc8..fc3881d 100644 --- a/CHECKPOINT-encryption.md +++ b/CHECKPOINT-encryption.md @@ -1,3 +1,56 @@ +# Checkpoint — sign_event given the human-approval timeout leash (2026-09-23 evening) + +## Where things are +- Project: `/home/avi/Projects/Keynctr` +- Branch: `master` @ **`f53bc56`** ("fix(nip46): give sign_event the + human-approval timeout leash"). Previous: `a76d8df` (feed authors). +- Working tree: clean for tracked files. Untracked intentionally NOT + committed: `COSMIC_THEME.md`, `KeynectrAppIconPossibility02.jpeg`, + `deferred/` (stays deferred). +- Release binary: **rebuilt at `f53bc56`**. No frontend changes — no + renderer rebuild needed. Restart Electron before retesting. + +## What was completed this session +1. **Confirmed live pairing WORKS**: today's trace log shows two full + successes against real Amber (identity adopted, CONNECTED at 15:17 + and 15:37). The "Dev" profile row exists in + `~/.local/share/keynectr/profiles_vault.json` in `nip46_client` + mode — the original complaint (no profile row, no persisted + connection) is resolved as of the `c789cb4` relay-set fix. +2. **Diagnosed + fixed the remaining sign failure (`f53bc56`)**: + logs show `sign_event` timing out at 30s while Amber's valid + signature for the last request arrived ~61s after publication + ("stale/duplicate response: no waiter ... dropped"). Every sign + waits on a human approving Amber's prompt, so it was using the + wrong leash. `sign_event` now uses `SIGN_TIMEOUT` = 120s (same as + the connect handshake); `get_public_key` keeps the 30s + retry-cadence timeout unchanged. +- Verification (all green at `f53bc56`): `cargo test` **213 unit + 4 + e2e passed / 0 failed** (incl. `nip46_qr_pairing_handshake_and_sign`, + which signs through the changed path), `cargo clippy --all-targets` + 0 warnings, `cargo fmt --check` clean, `cargo build --release` green. + Frontend untouched. + +## Commits added (newest first) +- `f53bc56` fix(nip46): give sign_event the human-approval timeout leash + +## How to resume / reproduce +- Restart Electron (new release binary), re-pair or restore, then + Publish name / publish a note: approve in Amber within 2 minutes and + the signature will be accepted even if the prompt took a while. +- If a sign still fails, check `~/Tools/keynctr-debug/` logs — a + "TIMED OUT after 120s" now means the phone truly never answered. + +## Outstanding / next steps +1. **Live sign/publish through real Amber with the 120s leash** (fix + is log-evidence-based; needs one live publish to confirm). +2. **NIP-46 session restore on startup** (re-scan needed after restarts). +3. Prune the 11 stale profileless `nip46_connections` rows (cosmetic). +4. Remote picture/nip05 edits, KDF upgrade (Step 5), rename pass + (Step 7) — unchanged. + +--- + # Checkpoint — feed shows author names/pictures (2026-09-23 PM) ## Where things are