checkpoint: sync to 21c522b — durable pairing trace log, forensics hygiene (2026-09-18)
This commit is contained in:
parent
21c522ba99
commit
a28d76e7d0
1 changed files with 68 additions and 0 deletions
|
|
@ -1,3 +1,71 @@
|
|||
# Checkpoint — durable pairing trace log + forensics-file hygiene (2026-09-18)
|
||||
|
||||
## Where things are
|
||||
- Project: `/home/avi/Projects/Keynctr`
|
||||
- Branch: `master` @ **`21c522b`** ("chore(pairing): durable trace log + keep
|
||||
e2e loopback traffic out of forensics files"). Previous feature HEADs:
|
||||
`188b2eb`, `aedde8f`, `759b5dd`, `5aa122d`, `f59c2b1`.
|
||||
- Working tree: clean for tracked files. Untracked intentionally NOT
|
||||
committed: `COSMIC_THEME.md`, `KeynectrAppIconPossibility02.jpeg`,
|
||||
`deferred/` (stays deferred).
|
||||
- Release binary rebuilt at `21c522b` (2026-09-18 ~21:00) — Electron spawns
|
||||
this one. **No live Amber scan has run against `188b2eb` or `21c522b`
|
||||
yet**: the capture file shows no real scan since Sep 16 21:03.
|
||||
- Verification (all green at `21c522b`): `cargo fmt --check` clean,
|
||||
`cargo test` **208 unit + 2 e2e passed / 0 failed**, `cargo clippy
|
||||
--all-targets` 0 warnings, `cargo build --release` green. Frontend:
|
||||
`npm test` **116 passed**, `npm run typecheck` / `lint` /
|
||||
`format:check` / `build` / `electron:build` all clean.
|
||||
|
||||
## What was completed since the last checkpoint
|
||||
- **Forensics contamination found and fixed**: pairing-capture.jsonl had
|
||||
grown two new lines (Sep 18 20:08 + 20:42) that were NOT Amber — they were
|
||||
the e2e harness's fake-scanner events, appended because the capture path
|
||||
was hardcoded and the loopback e2e test pairs through the same
|
||||
`run_pairing_task`. Removed the two test events from the capture file
|
||||
(backup: `pairing-capture.jsonl.bak-20260918`); loopback pairings now skip
|
||||
the capture file and the pairing-session trace lines entirely (the
|
||||
session-level `identity adopted` / `session failed` lines are shared with
|
||||
the bunker flow and can still include a labelled e2e entry — distinguish
|
||||
by the loopback relay set in the preceding `pairing started` line, which
|
||||
real sessions never have).
|
||||
- **Durable pairing trace (`pairing-trace.log`)**: every pairing decision
|
||||
point now appends a timestamped line to
|
||||
`~/Tools/keynctr-debug/pairing-trace.log` — pairing started (ephemeral key
|
||||
+ relay set), inbound 24133, decrypt failure (real NIP-44 error),
|
||||
not-a-request (exact payload), pre-handshake method, connect answered,
|
||||
identity adopted (npub), session failed (reason). Backend stderr only
|
||||
reaches the Electron console and /tmp gets cleaned, so previously a failed
|
||||
live handshake left NO durable trace. Verified working: the e2e run after
|
||||
the change wrote `identity adopted ... CONNECTED` lines proving the trace
|
||||
path end-to-end.
|
||||
|
||||
## Commits added (newest first)
|
||||
- `21c522b` chore(pairing): durable trace log + keep e2e loopback traffic
|
||||
out of forensics files
|
||||
|
||||
## How to reproduce / exercise
|
||||
- Dev loop (unchanged): `npx vite --port 5173` in `frontend/` FIRST, then
|
||||
`NOSTR_GUI_DEV_URL=http://localhost:5173 KEYNCTR_ENABLE_GPU=1 npx electron .`.
|
||||
- GUI: Signer mode -> "Show QR" -> scan in Amber -> approve. After the scan
|
||||
(success OR failure), read `~/Tools/keynctr-debug/pairing-trace.log` — the
|
||||
last lines name exactly where the handshake stopped. Raw frames still
|
||||
append to `pairing-capture.jsonl` (live pairings only now).
|
||||
|
||||
## Outstanding / next steps
|
||||
1. **Live Amber re-scan still required** — nothing has exercised the
|
||||
`188b2eb` lenient parser against real Amber traffic yet. The trace log
|
||||
will show, without any terminal capture, whether the connect arrives,
|
||||
decrypts, parses, and how far the handshake gets.
|
||||
2. If trace shows `pre-handshake 'get_public_key' ignored`, relax the
|
||||
connect-only gate (the log line names it outright).
|
||||
3. `publish_profile_metadata` (kind 0) still signs locally — reroute
|
||||
through `Signing` for external profiles (P2).
|
||||
4. Step 5 (KDF upgrade), Step 6 (undo preserves ProfileSummary), Step 7
|
||||
(rename pass incl. `homepage` URL).
|
||||
|
||||
---
|
||||
|
||||
# Checkpoint — Amber pairing: lenient NIP-46 payload parse + real decrypt-error logging (2026-09-16)
|
||||
|
||||
## Where things are
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue