diff --git a/CHECKPOINT-encryption.md b/CHECKPOINT-encryption.md index beafb08..6267a3e 100644 --- a/CHECKPOINT-encryption.md +++ b/CHECKPOINT-encryption.md @@ -1,3 +1,35 @@ +# Checkpoint — restore secret-echo fix LIVE-VERIFIED (2026-09-25 late PM) + +## Where things are +- Project: `/home/avi/Projects/Keynctr` +- Branch: `master` @ **`01ce5de`** ("fix(nip46): restored sessions no + longer demand a connect secret re-echo"). Previous: `a809a67` (label + step), `5b13162` (Add-profile choice), `a6a4e6f` (flake kill). +- SESSION RESTORE LIVE-VERIFIED against real Amber at 01ce5de: log shows + restoring session -> secret validation SKIPPED (restore) -> + get_public_key -> identity check PASS -> Connected, no scan. (Amber + answered a plain 'ack' here, not 'true' — the restore path now accepts + any ack shape and trusts the re-proved identity.) +- Remaining live proof: one publish/note approved in Amber within the + 120s leash (fresh pairing at 15:37 already exercised sign? — the + last_publish.json entry from 10:57 was BEFORE the fresh pairing; the + fresh profile has not published yet). + +## What was completed +1. **Restore secret-echo fix (`01ce5de`)**: session restore failed 100% + against real Amber — the re-dial resent the pairing secret and the + client demanded an echo, but an already-approved signer legitimately + answers without re-echoing (echo = initial-pairing possession proof + only). ConnectUri gained a `restore` flag (only reactivate_saved_sessions + sets it): restore skips the echo and relies on expected_identity in + adopt_identity; fresh pairings still fail closed on a wrong echo. + e2f model updated: run_fake_amber now mirrors Amber ack shapes and + the restore test seeds a pairing secret (fails without the fix). + cargo test 216 unit + 5 e2e green; clippy 0; fmt clean; release + rebuilt at 01ce5de; backend restarted and LIVE restore verified. + +--- + # Checkpoint — signer pairing label step + vault prune (2026-09-25 PM) ## Where things are