Skip to content

Put header bytes and KDF parameters behind a format detail switch (Section 06c) - #233

Merged
404SecNotFound merged 3 commits into
claude/serene-carson-0739mv-06bfrom
claude/serene-carson-0739mv-06c
Sep 28, 2026
Merged

404SecNotFound merged 3 commits into
claude/serene-carson-0739mv-06bfrom
claude/serene-carson-0739mv-06c

Conversation

@404SecNotFound

Copy link
Copy Markdown
Owner

Section 06, part c (roadmap 9.6). Stacked on #232 (06b), which is stacked on #231 (06a), so this shows only its own diff.

What changes

  • One switch, "Format detail", in the container pane's header. It is off by default and not stored, since the app keeps nothing between visits.
  • Off, the page leaves out:
    • the inspector's header hex row, the magic, version-byte and offset line, and the "salts and nonces" line;
    • KDF parameters (memory, time cost, parallelism, iterations) in the inspector, the receipt, the Recovery tab and the Decrypt tab's "Format:" line;
    • the self-extract notice's list of per-format reasons. The notice keeps its heading and the trade it names: PBKDF2 and AES-256-GCM, easier to open later, weaker today.
  • Off, the page still shows the byte map (BAR.md keeps the preview beside the form), every KDF and cipher name, the ways in, the version pill, the "Format: KEYM vN" line, every check, and every warning. That covers unlock cost, the v2 slot table, the weak-KDF heads-up and the slot-table change.

How the trimming stays safe

src/lib/detail-level.ts handles two label shapes:

  • Receipt and inspector labels join segments with " · ", and a parameter is always a segment of its own.
  • The readers behind the "Format:" line put parameters in brackets, as in PBKDF2 (1,000,000 iters).

Only a whole segment, or a parameter token inside brackets, is dropped. A bracket without one ((HKDF-SHA-256), (read from the file, not authenticated)) is kept, and running text is never touched, so the weak-KDF warning keeps the numbers it quotes. The first version trimmed only segments. The new browser spec caught the bracket shape, and 9542ec9 fixes it.

Tests

  • npm run test:backup-workflow has 13 new checks, 63 in total, covering both shapes and a warning that quotes numbers. Three faults each failed their own checks: dropping any segment with a digit, skipping the bracket trimming, and ignoring the switch.
  • tests/browser/workflow-expert-view.spec.ts (new, 4 tests) reads each screen both ways. The screens are the inspector, the receipt, the parsed slot rows, the Recovery tab, the unlock line and the self-extract notice. It also checks that a reload starts with the switch off.
  • container-inspector.spec.ts now turns the switch on in beforeEach, since it reads the bytes. So does the self-extract test that reads the reasons.

Gates run locally

  • On bac7586, npm run typecheck, all Node test:* scripts and the 4 Python gates pass. test:palette, test:icons and test:verify-recipe first failed because out/ was missing, and passed once the build existed.
  • npm run build passes.
  • Chromium full suite: 328 passed, 5 skipped, 3 failed.
    • Two failures were this spec's, fixed in 9542ec9. After the fix, the spec and the 6 specs it touches passed (38 tests).
    • The third was the known async-guard.spec.ts flake ("switching tabs mid-derivation"). Over 20 repeats it failed 2 times on this branch and 1 time on 06b's build, with the same message both times. So it is not introduced here.
  • Firefox and WebKit were not run locally. CI covers them.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr


Generated by Claude Code

404SecNotFound and others added 3 commits September 28, 2026 12:28
Section 06, part c. Format and KDF detail was on screen by default: the
header hex row and offsets in the container pane, full KDF parameters on
the receipt, the Recovery tab and the Decrypt tab's format line, and a
list of per-format reasons under the self-extract notice after every
text encrypt with the default Argon2id.

One switch, "Format detail", in the container pane's header, now shows
them. It is off by default and not stored.

Off still shows the byte map, every KDF and cipher name, the ways in,
the version, every check and every warning. src/lib/detail-level.ts
drops only " · " segments that are exactly a KDF parameter, so a warning
that quotes a number survives whole.

container-inspector.spec.ts turns the switch on, since it reads the
bytes, and so does the self-extract test that reads the reasons.
tests/browser/workflow-expert-view.spec.ts reads each screen both ways.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
The Decrypt tab's "Format:" line comes from the readers, which put
parameters in brackets: "PBKDF2 (1,000,000 iters)", "Argon2id (64 MiB,
t=3, p=4)", "both needed (PBKDF2 1,000,000 iters)". Only the " · "
segment shape was trimmed, so the line kept its parameters with format
detail off. workflow-expert-view.spec.ts caught it.

A parameter token inside brackets is now dropped, and the bracket with
it when nothing is left. A bracket with no parameter in it, such as
"(HKDF-SHA-256)" or "(read from the file, not authenticated)", is left
alone, and running text is never touched, so a weak-KDF warning keeps
its numbers.

Also fixes the spec's hex expectation: the gaps between bytes are
margins, so the text runs together.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
@404SecNotFound
404SecNotFound merged commit 731ad23 into claude/serene-carson-0739mv-06b Sep 28, 2026
15 checks passed
404SecNotFound added a commit that referenced this pull request Sep 29, 2026
#233 (06c) and #234 (06d) merged into their stacked bases, not main.
This brings them onto the branch #235 carries to main.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant