Skip to content

Land #232, #233 and #234 (Section 06b, 06c, 06d) on main - #235

Merged
404SecNotFound merged 9 commits into
mainfrom
claude/serene-carson-0739mv
Sep 29, 2026
Merged

404SecNotFound merged 9 commits into
mainfrom
claude/serene-carson-0739mv

Conversation

@404SecNotFound

@404SecNotFound 404SecNotFound commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

#232 (06b), #233 (06c) and #234 (06d) each merged into its stacked base within a minute of #231 (06a) landing on main. None reached main:

This PR carries all three to main. fc2b331 merges the 06c branch, which holds 06b, 06c and 06d, into this branch. No new code: the resulting tree is byte-identical to ede97bc, the 06d head that #234 was reviewed and CI-tested on (git diff ede97bc fc2b331 is empty). It merges cleanly into main.

Why it happened

GitHub retargets a stacked PR to main only when its base branch is deleted after that base's PR merges. This repo keeps merged branches, so no stacked PR is retargeted automatically. The note in #232 to #234 that GitHub would do it was wrong, and so is the same line in CLAUDE.md ("GitHub retargets to main as they merge in order").

From here

The Section 06 PRs after this one (06e onwards) will be opened against main directly once this lands, so each shows only its own diff and cannot merge anywhere else.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr

404SecNotFound and others added 9 commits September 28, 2026 11:47
Section 06, part b. The Encrypt tab lists the six steps of making a
backup: content, access rule, review, create, check saved copy, prepare
recovery. BAR.md keeps one form with no Next-button wizard, so this is
status only and gates nothing.

workflowSteps in src/lib/backup-workflow.ts marks a step done only on
evidence the page has:
- A download or print is Started, never Done.
- Check saved copy is Done only when every printed container symbol has
  been photographed on the Recovery tab and matched to this backup.
  Checks add up across photos; strips, unmatched symbols and symbols
  from another backup do not count.
- Prepare recovery is Done only after a rehearsal from the shares.
- Once the form moves on, Create reads Changed and nothing is next.

Every state is a word as well as a colour, and the step to act on
carries aria-current="step".

Adds the step rules to test:backup-workflow and
tests/browser/workflow-steps.spec.ts.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Two Chromium failures from the step list.

workspace-layout.spec.ts holds the Content section within 340px of the
top at 1440x1000. The list above it pushed Content to 432px. On a wide
screen the workbench grid now puts the list in the right column, above
the container pane; below 980px it is the first row, above the form. It
stays first in the DOM, so it still reads first.

share-lifecycle.spec.ts found the form's "Keep open" behind the shares
dialog. Radix hides the page behind a modal once, when it opens, with
the aria-hidden package, which keeps every [aria-live] element and its
ancestors exposed. The list's live region kept the form's wrapper
exposed, so a lock warning mounted later inside it was never hidden.
In the original position the test fails with the live region and
passes without it. The live region is gone: it would also have
re-announced on every keystroke, and aria-current marks the step to
act on.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Section 06, part c. Format and KDF detail was on screen by default: the
header hex row and offsets in the container pane, full KDF parameters on
the receipt, the Recovery tab and the Decrypt tab's format line, and a
list of per-format reasons under the self-extract notice after every
text encrypt with the default Argon2id.

One switch, "Format detail", in the container pane's header, now shows
them. It is off by default and not stored.

Off still shows the byte map, every KDF and cipher name, the ways in,
the version, every check and every warning. src/lib/detail-level.ts
drops only " · " segments that are exactly a KDF parameter, so a warning
that quotes a number survives whole.

container-inspector.spec.ts turns the switch on, since it reads the
bytes, and so does the self-extract test that reads the reasons.
tests/browser/workflow-expert-view.spec.ts reads each screen both ways.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
The Decrypt tab's "Format:" line comes from the readers, which put
parameters in brackets: "PBKDF2 (1,000,000 iters)", "Argon2id (64 MiB,
t=3, p=4)", "both needed (PBKDF2 1,000,000 iters)". Only the " · "
segment shape was trimmed, so the line kept its parameters with format
detail off. workflow-expert-view.spec.ts caught it.

A parameter token inside brackets is now dropped, and the bracket with
it when nothing is left. A bracket with no parameter in it, such as
"(HKDF-SHA-256)" or "(read from the file, not authenticated)", is left
alone, and running text is never touched, so a weak-KDF warning keeps
its numbers.

Also fixes the spec's hex expectation: the gaps between bytes are
margins, so the text runs together.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Section 06, part d. "The backup opens with this password" stayed on
screen until a wipe or the next run, so loading another backup,
choosing another key file, switching to shares or a passkey, or typing
a new password left the green result beside an input it had never
checked.

The page now records what a verify checked when it starts: the input
type, the file (by identity, since picking a file again makes a new
one) or the pasted container, the key file, and whether shares or a
passkey were used. verifyChanges in src/lib/verify-evidence.ts compares
that with the form on every render. A successful check clears the
password and any shares it used, so anything typed there afterwards is
a new attempt.

Once anything differs, the green result gives way to a notice naming
what changed, and the old backup's format line does not show in its
place. Putting the checked input back brings the result back.

Adds the rules to test:backup-workflow and
tests/browser/verify-evidence.spec.ts.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
#233 (06c) and #234 (06d) merged into their stacked bases, not main.
This brings them onto the branch #235 carries to main.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant