diff --git a/CHECKPOINT-encryption.md b/CHECKPOINT-encryption.md index d2a7665..c3eb848 100644 --- a/CHECKPOINT-encryption.md +++ b/CHECKPOINT-encryption.md @@ -1,4 +1,57 @@ -# Checkpoint — pairing relay set canary-tested; 24133-blocking relays removed (2026-09-22) +# Checkpoint — first live Amber pairing succeeded; subscription race fixed (2026-09-23) + +## Where things are +- Project: `/home/avi/Projects/Keynctr` +- Branch: `master` @ **`2e98e69`** ("fix(pairing): subscribe to signer replies + BEFORE the handshake publishes"). Previous: `13a66f2` + ("feat(onboarding): first-run screen offers import-existing-account and + external-signer paths"), `963b740`, `c789cb4` (relay-set canary fix). +- Working tree: clean for tracked files. Untracked intentionally NOT + committed: `COSMIC_THEME.md`, `KeynectrAppIconPossibility02.jpeg`, + `deferred/` (stays deferred). +- Release binary: **rebuilt at `2e98e69` (2026-09-23 ~08:45 CDT)** — Electron + spawns this one. Dev loop: vite :5173 + + `NOSTR_GUI_DEV_URL=http://localhost:5173 KEYNCTR_ENABLE_GPU=1 + KEYNCTR_FORCE_WAYLAND=1 KEYNCTR_NO_RELAUNCH=1 npx electron .` (the + FORCE_WAYLAND/NO_RELAUNCH pair keeps the crash-fallback ladder from drifting + the window onto XWayland, where it fails to map on this Hyprland session). +- What was completed this session: + 1. **First genuine live pairing captured** (Sep 23 08:31 CDT): pairing + started → inbound 24133 → `connect` accepted with secret echo → + `paired: connection stored` — the c789cb4 relay fix is proven end to end. + The session then died at identity adoption: `get_public_key` timed out. + 2. **Root cause `2e98e69`**: both connect flows spawned the handshake task + BEFORE `run_demux` registered the kind-24133 author subscription, so the + relay delivered Amber's fast identity reply into a gap with no active + subscription and it was dropped; 30s later the RPC timed out, leaving the + vault with a stored connection (`profile_npub: None`) but no profile — + UI said "connected" while Home still showed first-run. Fix: new + `subscribe_to_signer` opens the notification stream + subscription before + any publish; `run_sign_task` and `run_paired` both subscribe first and + pass the stream to `run_demux`. `futures-util` promoted to runtime dep. + 3. **Onboarding `13a66f2`**: first-run Home now offers three paths — Create + a new profile / I already have an account (ImportProfileModal) / Sign in + with a signer (navigates to Signer Mode). Copy states per-mode key truth + (local vault vs remote signer key never on this device). +- Verification (all green): `cargo test` **209 unit + 3 e2e passed / 0 + failed**, `cargo clippy --all-targets` 0 warnings, `cargo fmt --check` + clean, `cargo build --release` green; frontend `npm test` **116 passed**, + `typecheck`, `lint`, `format:check` clean. +- Resume / reproduce: dev-loop command above; scan the pairing QR with Amber + from Signer Mode. Expected trace in `/home/avi/Tools/keynctr-debug/ + pairing-trace.log`: `pairing started → inbound 24133 → connect response + accepted → paired: connection stored → identity adopted … CONNECTED`, and a + profile row appearing in `~/.local/share/keynectr/profiles_vault.json`. +- Outstanding / next steps: + - **Live re-scan against `2e98e69`** — the only missing proof; the stale + half-paired connection row (`Remote Signer`, signer_pubkey 9597b46d…) is + replaced by the new pairing. + - Consider pruning stale `Remote Signer` connection rows on failed + adoption so the vault never keeps a profileless connection. + +--- + +# Previous checkpoint — pairing relay set canary-tested; 24133-blocking relays removed (2026-09-22) ## Where things are - Project: `/home/avi/Projects/Keynctr`