fix(pairing): keep e2e traffic out of the live pairing trace + trace the handover

The trace log's "identity adopted - CONNECTED" line fired in the e2e
harness too (adopt_identity had no relay gate), so every test run
appended fake CONNECTED entries to the forensics log. Three such lines
landed there during today's cron verification and had to be manually
distinguished from a real Amber scan. Gate the line on live_relays()
(same loopback test the capture already uses) and add a "paired:
connection stored" trace line at the QR-pairing handover so a stall
between connect-echo and get_public_key is visible in the trace.
This commit is contained in:
Avi 2026-09-21 20:39:08 -05:00
commit f6bf6a979a

View file

@ -64,6 +64,18 @@ fn pairing_trace(msg: &str) {
} }
} }
/// Whether a relay set touches the public network. Loopback-only sets
/// belong to the e2e harness, and their traffic must never land in the
/// live pairing forensics files: a test-run "identity adopted — CONNECTED"
/// line sitting among real ones was twice mistaken for a live Amber
/// pairing during debugging.
fn live_relays(relays: &[String]) -> bool {
relays.iter().any(|u| {
let u = u.to_lowercase();
!(u.contains("127.0.0.1") || u.contains("localhost") || u.contains("[::1]"))
})
}
/// Internal state for a pending approval. /// Internal state for a pending approval.
struct PendingApprovalInner { struct PendingApprovalInner {
method: String, method: String,
@ -803,6 +815,9 @@ impl Nip46ClientSigner {
// status) and move the session state where send_rpc expects it. The // status) and move the session state where send_rpc expects it. The
// phase stays `Connecting` — identity is still unverified — and the // phase stays `Connecting` — identity is still unverified — and the
// demux loop (which answers the handshake's RPCs) takes over. // demux loop (which answers the handshake's RPCs) takes over.
if live_capture {
pairing_trace("paired: connection stored; handing over to identity handshake");
}
let demux_uri = ConnectUri { let demux_uri = ConnectUri {
peer, peer,
relays, relays,
@ -1713,11 +1728,17 @@ impl Nip46ClientSigner {
conn.profile_npub = Some(identity_npub.clone()); conn.profile_npub = Some(identity_npub.clone());
} }
inner.phase = Nip46Phase::Connected; inner.phase = Nip46Phase::Connected;
pairing_trace(&format!( // Only trace LIVE pairings: adopt_identity runs in the e2e harness
"identity adopted: npub={} peer={} — CONNECTED", // too, and an un-gated line here put test-run "CONNECTED" entries
identity_npub, // into the forensics log where they were mistaken for a live Amber
peer.to_hex() // scan during debugging.
)); if live_relays(&connection.relays) {
pairing_trace(&format!(
"identity adopted: npub={} peer={} — CONNECTED",
identity_npub,
peer.to_hex()
));
}
drop(inner); drop(inner);
// Background enrichment (post-Connected by design): look up the // Background enrichment (post-Connected by design): look up the