Land #232, #233 and #234 (Section 06b, 06c, 06d) on main - #235
Merged
Merged
Conversation
Section 06, part b. The Encrypt tab lists the six steps of making a backup: content, access rule, review, create, check saved copy, prepare recovery. BAR.md keeps one form with no Next-button wizard, so this is status only and gates nothing. workflowSteps in src/lib/backup-workflow.ts marks a step done only on evidence the page has: - A download or print is Started, never Done. - Check saved copy is Done only when every printed container symbol has been photographed on the Recovery tab and matched to this backup. Checks add up across photos; strips, unmatched symbols and symbols from another backup do not count. - Prepare recovery is Done only after a rehearsal from the shares. - Once the form moves on, Create reads Changed and nothing is next. Every state is a word as well as a colour, and the step to act on carries aria-current="step". Adds the step rules to test:backup-workflow and tests/browser/workflow-steps.spec.ts. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Two Chromium failures from the step list. workspace-layout.spec.ts holds the Content section within 340px of the top at 1440x1000. The list above it pushed Content to 432px. On a wide screen the workbench grid now puts the list in the right column, above the container pane; below 980px it is the first row, above the form. It stays first in the DOM, so it still reads first. share-lifecycle.spec.ts found the form's "Keep open" behind the shares dialog. Radix hides the page behind a modal once, when it opens, with the aria-hidden package, which keeps every [aria-live] element and its ancestors exposed. The list's live region kept the form's wrapper exposed, so a lock warning mounted later inside it was never hidden. In the original position the test fails with the live region and passes without it. The live region is gone: it would also have re-announced on every keystroke, and aria-current marks the step to act on. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Section 06, part c. Format and KDF detail was on screen by default: the header hex row and offsets in the container pane, full KDF parameters on the receipt, the Recovery tab and the Decrypt tab's format line, and a list of per-format reasons under the self-extract notice after every text encrypt with the default Argon2id. One switch, "Format detail", in the container pane's header, now shows them. It is off by default and not stored. Off still shows the byte map, every KDF and cipher name, the ways in, the version, every check and every warning. src/lib/detail-level.ts drops only " · " segments that are exactly a KDF parameter, so a warning that quotes a number survives whole. container-inspector.spec.ts turns the switch on, since it reads the bytes, and so does the self-extract test that reads the reasons. tests/browser/workflow-expert-view.spec.ts reads each screen both ways. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
The Decrypt tab's "Format:" line comes from the readers, which put parameters in brackets: "PBKDF2 (1,000,000 iters)", "Argon2id (64 MiB, t=3, p=4)", "both needed (PBKDF2 1,000,000 iters)". Only the " · " segment shape was trimmed, so the line kept its parameters with format detail off. workflow-expert-view.spec.ts caught it. A parameter token inside brackets is now dropped, and the bracket with it when nothing is left. A bracket with no parameter in it, such as "(HKDF-SHA-256)" or "(read from the file, not authenticated)", is left alone, and running text is never touched, so a weak-KDF warning keeps its numbers. Also fixes the spec's hex expectation: the gaps between bytes are margins, so the text runs together. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Section 06, part d. "The backup opens with this password" stayed on screen until a wipe or the next run, so loading another backup, choosing another key file, switching to shares or a passkey, or typing a new password left the green result beside an input it had never checked. The page now records what a verify checked when it starts: the input type, the file (by identity, since picking a file again makes a new one) or the pasted container, the key file, and whether shares or a passkey were used. verifyChanges in src/lib/verify-evidence.ts compares that with the form on every render. A successful check clears the password and any shares it used, so anything typed there afterwards is a new attempt. Once anything differs, the green result gives way to a notice naming what changed, and the old backup's format line does not show in its place. Putting the checked input back brings the result back. Adds the rules to test:backup-workflow and tests/browser/verify-evidence.spec.ts. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
#233 (06c) and #234 (06d) merged into their stacked bases, not main. This brings them onto the branch #235 carries to main. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
This was referenced Sep 29, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
#232 (06b), #233 (06c) and #234 (06d) each merged into its stacked base within a minute of #231 (06a) landing on
main. None reachedmain:claude/serene-carson-0739mv(the 06a branch, already merged);claude/serene-carson-0739mv-06b;claude/serene-carson-0739mv-06c.This PR carries all three to
main.fc2b331merges the 06c branch, which holds 06b, 06c and 06d, into this branch. No new code: the resulting tree is byte-identical toede97bc, the 06d head that #234 was reviewed and CI-tested on (git diff ede97bc fc2b331is empty). It merges cleanly intomain.Why it happened
GitHub retargets a stacked PR to
mainonly when its base branch is deleted after that base's PR merges. This repo keeps merged branches, so no stacked PR is retargeted automatically. The note in #232 to #234 that GitHub would do it was wrong, and so is the same line in CLAUDE.md ("GitHub retargets tomainas they merge in order").From here
The Section 06 PRs after this one (06e onwards) will be opened against
maindirectly once this lands, so each shows only its own diff and cannot merge anywhere else.🤖 Generated with Claude Code
https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr