checkpoint: relay-set canary fix at c789cb4 (2026-09-22)
This commit is contained in:
parent
c789cb4784
commit
963b740992
1 changed files with 88 additions and 0 deletions
|
|
@ -1,3 +1,91 @@
|
|||
# Checkpoint — pairing relay set canary-tested; 24133-blocking relays removed (2026-09-22)
|
||||
|
||||
## Where things are
|
||||
- Project: `/home/avi/Projects/Keynctr`
|
||||
- Branch: `master` @ **`c789cb4`** ("fix(pairing): drop purplepag.es and
|
||||
nostr.band from the pairing relay set"). Previous: `2e5938a`, `d4d87b8`,
|
||||
`f6bf6a9`, `edd4e56` (pairing feature HEAD).
|
||||
- Working tree: clean for tracked files. Untracked intentionally NOT
|
||||
committed: `COSMIC_THEME.md`, `KeynectrAppIconPossibility02.jpeg`,
|
||||
`deferred/` (stays deferred).
|
||||
- Release binary: **rebuilt at `c789cb4` (2026-09-22 20:39)** — Electron
|
||||
spawns this one.
|
||||
- Verification (all green at `c789cb4`): `cargo test` **209 unit + 3 e2e
|
||||
passed / 0 failed**, `cargo clippy --all-targets` 0 warnings,
|
||||
`cargo fmt --check` clean, `cargo build --release` green. No frontend
|
||||
changes (npm suite last green at `edd4e56`).
|
||||
|
||||
## What was completed since the last checkpoint
|
||||
- **First real live pairing attempt was captured — and diagnosed
|
||||
(`c789cb4`)**: the trace log now shows a genuine live session for the
|
||||
first time: `pairing started` at 18:01:29 CDT (ephemeral
|
||||
`7c695714…`, relays damus/nostr.band/primal/purplepag) followed by
|
||||
`session failed: Pairing timed out` at 18:06:39 — the 5-min window ran
|
||||
with ZERO inbound 24133 events (capture file untouched since Sep 18).
|
||||
Post-hoc relay sweep (read-only REQ, results in
|
||||
`/tmp/probe-results.json` + `/tmp/window-24133.json`) found **no
|
||||
kind-24133 event tagged to the ephemeral key on any of the four
|
||||
relays, and no kind-24133 at all in the whole 18:01–18:06 window**.
|
||||
So Amber connected to a relay and published, but the event was
|
||||
discarded before storage.
|
||||
- **Smoking gun via anonymous canary** (throwaway random keys, zero user
|
||||
data; `~/Tools/keynctr-debug/canary-24133.py`, results
|
||||
`/tmp/canary-results.json`): writing a kind-24133 event to each pairing
|
||||
relay → **purplepag.es: `OK false "blocked: kind 24133 is not
|
||||
allowed"`** — it silently drops signer connect traffic;
|
||||
**relay.nostr.band: WebSocket handshake hangs** (also pay-to-read);
|
||||
relay.damus.io + relay.primal.net + nos.lol: accepted + readable;
|
||||
relay.snort.social: accepted live ("ephemeral: will not be stored"),
|
||||
fine for pairing push. If Amber picked purplepag.es (it is in the URI),
|
||||
it would say "connected" while its connect event was rejected —
|
||||
exactly the observed symptom, and consistent with the earlier
|
||||
parse-failure theories being dead ends (the payload never arrived).
|
||||
- **Fix (`c789cb4`)**: `pairing_relays()` is now damus.io, primal.net,
|
||||
nos.lol, relay.snort.social — both blockers removed, both replacements
|
||||
canary-verified for ephemeral 24133. Regression test
|
||||
`pairing_relays_exclude_24133_blockers` pins the blockers out.
|
||||
- **Debug-dir hygiene**: `inspect.py` removed (it shadowed the stdlib
|
||||
`inspect` module for any script run from that directory and leaked
|
||||
stale forensics output into terminal sessions); moved to
|
||||
`inspect-capture.txt`. Canary + probe scripts kept under
|
||||
`~/Tools/keynctr-debug/` (untracked tools dir).
|
||||
|
||||
## Commits added (newest first)
|
||||
- `c789cb4` fix(pairing): drop purplepag.es and nostr.band from the
|
||||
pairing relay set
|
||||
|
||||
## How to reproduce / exercise
|
||||
- **LIVE AMBER RE-SCAN (the decisive test, cannot run unattended)**:
|
||||
launch the app (release binary is current at `c789cb4`):
|
||||
`cd frontend && npx vite --port 5173` then
|
||||
`NOSTR_GUI_DEV_URL=http://localhost:5173 KEYNCTR_ENABLE_GPU=1 npx electron .`
|
||||
Signer mode -> Show QR -> scan in Amber -> approve. The QR's relay list
|
||||
no longer contains purplepag.es/nostr.band. Expected trace:
|
||||
`pairing started` -> `inbound 24133 from …` -> `connect response
|
||||
accepted (secret echo verified)` -> `paired: connection stored;
|
||||
handing over to identity handshake` -> `identity adopted: npub=… —
|
||||
CONNECTED`. Watch with `bash ~/Tools/keynctr-debug/watch-pairing.sh 240`.
|
||||
- Canary: `python3 ~/Tools/keynctr-debug/canary-24133.py` (throwaway
|
||||
keys; results to /tmp/canary-results.json).
|
||||
- E2E: `cargo test --test nip46_e2e` (no network; trace file stays
|
||||
untouched).
|
||||
|
||||
## Outstanding / next steps
|
||||
1. **Live Amber re-scan against `c789cb4`** — the relay-set fix is the
|
||||
best-evidenced change yet but only a live scan proves it.
|
||||
2. Consider whether the user's two enabled relays (settings.json:
|
||||
damus.io + nostr.band) should swap nostr.band for nos.lol for
|
||||
ordinary traffic too (it hangs the handshake today; also pay-to-read).
|
||||
3. If trace still shows timeout with the new set, next hypothesis is
|
||||
Amber not actually publishing (its "connected" = relay socket open);
|
||||
compare against Amber's own relay debug screen.
|
||||
4. `publish_profile_metadata` (kind 0) still signs locally — reroute
|
||||
through `Signing` for external profiles (P2).
|
||||
5. Step 5 (KDF upgrade), Step 6 (undo preserves ProfileSummary — done in
|
||||
`d101b8e`), Step 7 (rename pass incl. `homepage` URL).
|
||||
|
||||
---
|
||||
|
||||
# Checkpoint — 'keys never leave' claim corrected per-mode (2026-09-22); prior: pairing forensics de-noised
|
||||
|
||||
## Where things are
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue