Put header bytes and KDF parameters behind a format detail switch (Section 06c) - #233
Merged
404SecNotFound merged 3 commits intoSep 28, 2026
Conversation
Section 06, part c. Format and KDF detail was on screen by default: the header hex row and offsets in the container pane, full KDF parameters on the receipt, the Recovery tab and the Decrypt tab's format line, and a list of per-format reasons under the self-extract notice after every text encrypt with the default Argon2id. One switch, "Format detail", in the container pane's header, now shows them. It is off by default and not stored. Off still shows the byte map, every KDF and cipher name, the ways in, the version, every check and every warning. src/lib/detail-level.ts drops only " · " segments that are exactly a KDF parameter, so a warning that quotes a number survives whole. container-inspector.spec.ts turns the switch on, since it reads the bytes, and so does the self-extract test that reads the reasons. tests/browser/workflow-expert-view.spec.ts reads each screen both ways. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
The Decrypt tab's "Format:" line comes from the readers, which put parameters in brackets: "PBKDF2 (1,000,000 iters)", "Argon2id (64 MiB, t=3, p=4)", "both needed (PBKDF2 1,000,000 iters)". Only the " · " segment shape was trimmed, so the line kept its parameters with format detail off. workflow-expert-view.spec.ts caught it. A parameter token inside brackets is now dropped, and the bracket with it when nothing is left. A bracket with no parameter in it, such as "(HKDF-SHA-256)" or "(read from the file, not authenticated)", is left alone, and running text is never touched, so a weak-KDF warning keeps its numbers. Also fixes the spec's hex expectation: the gaps between bytes are margins, so the text runs together. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
404SecNotFound
merged commit Sep 28, 2026
731ad23
into
claude/serene-carson-0739mv-06b
15 checks passed
404SecNotFound
added a commit
that referenced
this pull request
Sep 29, 2026
#233 (06c) and #234 (06d) merged into their stacked bases, not main. This brings them onto the branch #235 carries to main. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Section 06, part c (roadmap 9.6). Stacked on #232 (06b), which is stacked on #231 (06a), so this shows only its own diff.
What changes
How the trimming stays safe
src/lib/detail-level.tshandles two label shapes:PBKDF2 (1,000,000 iters).Only a whole segment, or a parameter token inside brackets, is dropped. A bracket without one (
(HKDF-SHA-256),(read from the file, not authenticated)) is kept, and running text is never touched, so the weak-KDF warning keeps the numbers it quotes. The first version trimmed only segments. The new browser spec caught the bracket shape, and9542ec9fixes it.Tests
npm run test:backup-workflowhas 13 new checks, 63 in total, covering both shapes and a warning that quotes numbers. Three faults each failed their own checks: dropping any segment with a digit, skipping the bracket trimming, and ignoring the switch.tests/browser/workflow-expert-view.spec.ts(new, 4 tests) reads each screen both ways. The screens are the inspector, the receipt, the parsed slot rows, the Recovery tab, the unlock line and the self-extract notice. It also checks that a reload starts with the switch off.container-inspector.spec.tsnow turns the switch on inbeforeEach, since it reads the bytes. So does the self-extract test that reads the reasons.Gates run locally
bac7586,npm run typecheck, all Nodetest:*scripts and the 4 Python gates pass.test:palette,test:iconsandtest:verify-recipefirst failed becauseout/was missing, and passed once the build existed.npm run buildpasses.9542ec9. After the fix, the spec and the 6 specs it touches passed (38 tests).async-guard.spec.tsflake ("switching tabs mid-derivation"). Over 20 repeats it failed 2 times on this branch and 1 time on 06b's build, with the same message both times. So it is not introduced here.🤖 Generated with Claude Code
https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Generated by Claude Code