From e6ddc53261598c891dddf0c66a0aa432fd98f00e Mon Sep 17 00:00:00 2001 From: Avi Date: Mon, 21 Sep 2026 20:42:11 -0500 Subject: [PATCH] =?UTF-8?q?checkpoint:=20sync=20to=20f6bf6a9=20=E2=80=94?= =?UTF-8?q?=20pairing=20trace=20fully=20de-noised;=20live=20Amber=20scan?= =?UTF-8?q?=20still=20pending=20(2026-09-21)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- CHECKPOINT-encryption.md | 80 ++++++++++++++++++++++++++++++++++------ 1 file changed, 69 insertions(+), 11 deletions(-) diff --git a/CHECKPOINT-encryption.md b/CHECKPOINT-encryption.md index 7c916ed..a28541a 100644 --- a/CHECKPOINT-encryption.md +++ b/CHECKPOINT-encryption.md @@ -1,24 +1,82 @@ -# Checkpoint — e2e vault-isolation bug found; Amber fix awaiting live test (2026-09-20) +# Checkpoint — pairing forensics fully de-noised; Amber fix still awaiting live test (2026-09-21) ## Where things are - Project: `/home/avi/Projects/Keynctr` -- Branch: `master` @ **`deeb4f9`** ("test(e2e): assert vault isolation - actually isolated") + `d52fa58` ("test(e2e): isolate the e2e vault at the - real data_dir path"). Feature HEAD unchanged: `edd4e56` (connect-response - root-cause fix). Previous: `21c522b`, `188b2eb`, `aedde8f`, `759b5dd`, +- Branch: `master` @ **`f6bf6a9`** ("fix(pairing): keep e2e traffic out of + the live pairing trace + trace the handover"). Feature HEAD unchanged: + `edd4e56` (connect-response root-cause fix). Previous: `deeb4f9`, + `d52fa58`, `5f9c64f`, `21c522b`, `188b2eb`, `aedde8f`, `759b5dd`, `5aa122d`, `f59c2b1`. - Working tree: clean for tracked files. Untracked intentionally NOT committed: `COSMIC_THEME.md`, `KeynectrAppIconPossibility02.jpeg`, `deferred/` (stays deferred). -- Release binary: still the `edd4e56` build (2026-09-19 20:46). Sep 20 - commits touch only `tests/` — no rebuild needed. +- Release binary: **rebuilt at `f6bf6a9` (2026-09-21 ~20:25)** — the + current Sep 19 binary was superseded. Electron spawns this one. - **STILL NO LIVE AMBER SCAN against the fixed binary.** Proof: trace log has zero `pairing started` lines (every real pairing writes one) and the - capture file's newest event is Sep 16 21:03. -- Verification (all green at `deeb4f9`): `cargo fmt --check` clean, + capture file's newest event is Sep 16 21:03. NOTE: the `identity + adopted — CONNECTED` lines dated Sep 18–21 (20:59, 20:43, 20:39–20:44, + 20:13) are all **cargo-test / cron-verification e2e traffic**, not live + scans — that exact confusion was the reason for `f6bf6a9` below. +- Verification (all green at `f6bf6a9`): `cargo fmt --check` clean, `cargo test` **208 unit + 3 e2e passed / 0 failed**, `cargo clippy - --all-targets` 0 warnings. No frontend changes (npm suite last green at - `edd4e56`). + --all-targets` 0 warnings, `cargo build --release` green. No frontend + changes (npm suite last green at `edd4e56`). + +## What was completed since the last checkpoint +- **Forensics de-noising (`f6bf6a9`)**: `adopt_identity`'s + `identity adopted — CONNECTED` trace line had no loopback gate, so every + e2e run appended fake CONNECTED entries to + `~/Tools/keynctr-debug/pairing-trace.log` — three appeared during this + cron's own `cargo test` runs and had to be manually distinguished from a + real Amber scan. The line is now gated on `live_relays()` (same loopback + test the event capture already uses; verified live: re-running + `cargo test --test nip46_e2e` no longer touches the trace file's mtime). + Also added a `paired: connection stored; handing over to identity + handshake` trace line at the QR-pairing handover, so a stall between the + connect echo and `get_public_key` now names itself in the trace. +- **Post-fix audit of the pairing flow** (read-through, no code change): + the QR path (pairing loop -> connect-response echo -> connection+secret + persisted -> demux + `adopt_identity` -> profile row + vault save) is + coherent end to end; `send_rpc` waiters register before publish; demux + routes responses by id; failure paths call `fail()` which traces + `session failed: …`. Nothing further to fix without live data. + +## Commits added (newest first) +- `f6bf6a9` fix(pairing): keep e2e traffic out of the live pairing trace + trace the handover + +## How to reproduce / exercise +- **LIVE TEST (the only missing step)**: launch the app (release binary is + current): `cd frontend && npx vite --port 5173` then + `NOSTR_GUI_DEV_URL=http://localhost:5173 KEYNCTR_ENABLE_GPU=1 npx electron .` + (or run the packaged app). Signer mode -> Show QR -> scan in Amber -> + approve. Expected trace: `pairing started: ephemeral=…` -> + `inbound 24133 from …` -> `connect response accepted (secret echo + verified)` -> `paired: connection stored; handing over to identity + handshake` -> `identity adopted: npub=… — CONNECTED`; the profile row + + `nip46_connections` entry then land in + `~/.local/share/keynectr/profiles_vault.json` (its mtime is Sep 12 — + untouched since, further proof no live pairing has ever persisted). +- Watch during a live scan: `bash ~/Tools/keynctr-debug/watch-pairing.sh 240`. +- E2E: `cargo test --test nip46_e2e` (no network; 3 tests, both connect + shapes, empty-vault isolation guards; trace file stays untouched). + +## Outstanding / next steps +1. **Live Amber re-scan required** (cannot be done from an unattended + run). Trace log names the exact stop point if it stalls. +2. If trace shows `pre-handshake 'get_public_key' ignored`, relax the + connect-only gate. +3. `publish_profile_metadata` (kind 0) still signs locally — reroute + through `Signing` for external profiles (P2). +4. Step 5 (KDF upgrade), Step 6 (undo preserves ProfileSummary), Step 7 + (rename pass incl. `homepage` URL). + +--- + +# Checkpoint — e2e vault-isolation bug found; Amber fix awaiting live test (2026-09-20) + +## Where things are (as of 2026-09-20) +- Branch: `master` @ `deeb4f9` + `d52fa58`. Feature HEAD: `edd4e56`. ## What was completed since the last checkpoint - **e2e vault-isolation bug found and fixed (`d52fa58` + `deeb4f9`)**: