diff --git a/CHECKPOINT-encryption.md b/CHECKPOINT-encryption.md index 1c7d768..d2a7665 100644 --- a/CHECKPOINT-encryption.md +++ b/CHECKPOINT-encryption.md @@ -1,3 +1,91 @@ +# Checkpoint — pairing relay set canary-tested; 24133-blocking relays removed (2026-09-22) + +## Where things are +- Project: `/home/avi/Projects/Keynctr` +- Branch: `master` @ **`c789cb4`** ("fix(pairing): drop purplepag.es and + nostr.band from the pairing relay set"). Previous: `2e5938a`, `d4d87b8`, + `f6bf6a9`, `edd4e56` (pairing feature HEAD). +- Working tree: clean for tracked files. Untracked intentionally NOT + committed: `COSMIC_THEME.md`, `KeynectrAppIconPossibility02.jpeg`, + `deferred/` (stays deferred). +- Release binary: **rebuilt at `c789cb4` (2026-09-22 20:39)** — Electron + spawns this one. +- Verification (all green at `c789cb4`): `cargo test` **209 unit + 3 e2e + passed / 0 failed**, `cargo clippy --all-targets` 0 warnings, + `cargo fmt --check` clean, `cargo build --release` green. No frontend + changes (npm suite last green at `edd4e56`). + +## What was completed since the last checkpoint +- **First real live pairing attempt was captured — and diagnosed + (`c789cb4`)**: the trace log now shows a genuine live session for the + first time: `pairing started` at 18:01:29 CDT (ephemeral + `7c695714…`, relays damus/nostr.band/primal/purplepag) followed by + `session failed: Pairing timed out` at 18:06:39 — the 5-min window ran + with ZERO inbound 24133 events (capture file untouched since Sep 18). + Post-hoc relay sweep (read-only REQ, results in + `/tmp/probe-results.json` + `/tmp/window-24133.json`) found **no + kind-24133 event tagged to the ephemeral key on any of the four + relays, and no kind-24133 at all in the whole 18:01–18:06 window**. + So Amber connected to a relay and published, but the event was + discarded before storage. +- **Smoking gun via anonymous canary** (throwaway random keys, zero user + data; `~/Tools/keynctr-debug/canary-24133.py`, results + `/tmp/canary-results.json`): writing a kind-24133 event to each pairing + relay → **purplepag.es: `OK false "blocked: kind 24133 is not + allowed"`** — it silently drops signer connect traffic; + **relay.nostr.band: WebSocket handshake hangs** (also pay-to-read); + relay.damus.io + relay.primal.net + nos.lol: accepted + readable; + relay.snort.social: accepted live ("ephemeral: will not be stored"), + fine for pairing push. If Amber picked purplepag.es (it is in the URI), + it would say "connected" while its connect event was rejected — + exactly the observed symptom, and consistent with the earlier + parse-failure theories being dead ends (the payload never arrived). +- **Fix (`c789cb4`)**: `pairing_relays()` is now damus.io, primal.net, + nos.lol, relay.snort.social — both blockers removed, both replacements + canary-verified for ephemeral 24133. Regression test + `pairing_relays_exclude_24133_blockers` pins the blockers out. +- **Debug-dir hygiene**: `inspect.py` removed (it shadowed the stdlib + `inspect` module for any script run from that directory and leaked + stale forensics output into terminal sessions); moved to + `inspect-capture.txt`. Canary + probe scripts kept under + `~/Tools/keynctr-debug/` (untracked tools dir). + +## Commits added (newest first) +- `c789cb4` fix(pairing): drop purplepag.es and nostr.band from the + pairing relay set + +## How to reproduce / exercise +- **LIVE AMBER RE-SCAN (the decisive test, cannot run unattended)**: + launch the app (release binary is current at `c789cb4`): + `cd frontend && npx vite --port 5173` then + `NOSTR_GUI_DEV_URL=http://localhost:5173 KEYNCTR_ENABLE_GPU=1 npx electron .` + Signer mode -> Show QR -> scan in Amber -> approve. The QR's relay list + no longer contains purplepag.es/nostr.band. Expected trace: + `pairing started` -> `inbound 24133 from …` -> `connect response + accepted (secret echo verified)` -> `paired: connection stored; + handing over to identity handshake` -> `identity adopted: npub=… — + CONNECTED`. Watch with `bash ~/Tools/keynctr-debug/watch-pairing.sh 240`. +- Canary: `python3 ~/Tools/keynctr-debug/canary-24133.py` (throwaway + keys; results to /tmp/canary-results.json). +- E2E: `cargo test --test nip46_e2e` (no network; trace file stays + untouched). + +## Outstanding / next steps +1. **Live Amber re-scan against `c789cb4`** — the relay-set fix is the + best-evidenced change yet but only a live scan proves it. +2. Consider whether the user's two enabled relays (settings.json: + damus.io + nostr.band) should swap nostr.band for nos.lol for + ordinary traffic too (it hangs the handshake today; also pay-to-read). +3. If trace still shows timeout with the new set, next hypothesis is + Amber not actually publishing (its "connected" = relay socket open); + compare against Amber's own relay debug screen. +4. `publish_profile_metadata` (kind 0) still signs locally — reroute + through `Signing` for external profiles (P2). +5. Step 5 (KDF upgrade), Step 6 (undo preserves ProfileSummary — done in + `d101b8e`), Step 7 (rename pass incl. `homepage` URL). + +--- + # Checkpoint — 'keys never leave' claim corrected per-mode (2026-09-22); prior: pairing forensics de-noised ## Where things are