mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-06 11:48:24 +00:00
§8 of the interop plan ends with a requirement: the metadata-exposure analysis "should be surfaced in the UI if we ship this, not buried. A Marmot group and a cordn group have materially different metadata exposure and users cannot infer that from either one looking like a group chat." GroupExposure existed so there would be something to render; this renders it. The disclosure sits where it can still change a decision — on a pasted cordn1… link, before joining, rather than in a settings page nobody opens. The screen reads the link, names the coordinator and its relays, and shows the exposure. It deliberately does not join: joining needs a live coordinator and Tier B is blocked on licensing (§7), so a join button would be half a feature whose other half has never been run. - commonsUI/.../cordn/ui/: CordnExposureCard, CoordinatorHealthRow, CordnGroupBadge. Material3 only, so Desktop gets them for free. - commons/.../CordnLinkInspection: parse-and-disclose, headless and tested, so the screen only draws. A ref naming no coordinator is valid but not followable, and carries no exposure — inventing a threat model for a server we cannot identify would be worse than saying nothing. - Settings → Cordn group link, with a route and search keywords. Rendering it found two bugs compiling could not: - The severity colours were not monotonic. `tertiary` for the middle level rendered pink against a dark `onSurface` for the worst one, so "under a throwaway key" read as more alarming than "tied to your real account". Emphasis for the worst case is now weight rather than another hue. Nothing uses `error`: everything on the card is how cordn works, not a fault, and painting normal operation red teaches people to ignore red. - Note order is part of the disclosure. Cross-group linkage (§8.2), the item nobody predicts, sat below message padding, the least consequential one. notes() now returns most-surprising-first. CordnExposureRenderTest rasterises the surface headlessly (ImageComposeScene, software Skia, no display, no new dependency — the same Compose Desktop artifact jvmMain already uses) and asserts on pixels. It catches what a compile cannot: a missing string resource, which throws at render because the generated Res.string.* accessors compile regardless, and a composable that draws nothing. Mutation-checked — hardcoding the card background and disabling the §8.2 conditional each kill exactly one test. The first version of the theme test sampled only the page background and let the hardcoded card through, so it now samples inside the card as well. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012BfD4txdnsaPRXmNXbup9n
quartz plans
Audited 2026-09-17. 13 plans: 7 shipped (archived), 0 in-progress, 5 queued, 1 closed (negative result).
Queued
| Plan | Summary |
|---|---|
| 2026-05-08-local-headers-explorer.md | Headers-only Bitcoin P2P client to verify NIP-03 OTS attestations without a trusted block explorer. |
| 2026-06-12-giftwrap-deletion-requests.md | Let a recipient-authored kind-5 delete/block a gift wrap (kind 1059) addressed to them. |
| 2026-07-03-incremental-negentropy-storage.md | Always-current (created_at, id) index so cold NEG-OPENs stop paying a full scan + seal (~340 ms at 50k vs strfry's ~21 ms). |
| 2026-07-04-small-req-floor.md | Small-REQ dispatch floor: decomposed, inline fast path tried and reverted (no wire-level win); floor is transport-side. |
| 2026-08-13-gpu-pow-mining.md | GPU NIP-13 mining declined (ARMv8 has SHA-256 in silicon, mobile GPUs do not). Midstate is ~3x on JVM targets; Android hinges on Conscrypt per-digest JNI cost, still unmeasured. created_at refresh while mining shipped. |
| 2026-09-17-cordn-interop.md | Cordn (cordn.net) is an alternative binding of MLS onto Nostr, not an alternative to MLS: same ciphersuite 0x0001, byte-identical ChaCha20-Poly1305 seal and NIP-01 envelope, but the delivery service is an MCP server over ContextVM with no key-package event kind. Only the RFC 9420 engine is shareable, and it is not yet Marmot-clean (3 files, 10 imports, 3 hardcoded policies). ContextVM must be written from scratch: full review of the spec + all 12 CEPs, with a per-CEP compliance matrix, CVM-* rule ids and a 5-tier test method (including a fixture server that misbehaves on demand, and RFC 8785 JCS which Quartz lacks). Blocked on the credential-identity encoding (raw 32 bytes vs 64-byte hex ASCII). Includes a coordinator metadata-exposure analysis. |
| 2026-09-08-marmot-spec-resync.md | Marmot moved off the MIP-era spec (2026-07-02): group state split into app_data_dictionary components, account identity proof v2, and a convergence engine. Current MDK rejects our groups outright. Gap analysis + 8-stage plan; Stages 0-4 done (mdk interop reference, app_data_dictionary, identity proof v2, the six group components, transport corrections); lifecycle + branch selection landed. |
Archived (shipped)
| Plan | Summary |
|---|---|
| archive/2026-06-03-fix-nip46-bunker-double-resume-plan.md | Fix NIP-46 bunker double-resume crash and retry id-reuse races via Channel-per-request + fresh id per attempt. |
| archive/2026-06-04-auth-scope-vs-policy.md | Move relay-server authenticated-identity state from the policy into the engine-owned connection scope. |
| archive/2026-06-09-clink.md | Implement CLINK (Offers/Debits/Manage) Lightning-over-Nostr pointers, events, and client/server in Quartz. |
| archive/2026-06-11-runstr-interop.md | RUNSTR kind-1301 workout events and supporting fitness kinds in Quartz plus Amethyst fitness screens. |
| archive/2026-06-19-napplet-nip5a-resolver.md | Platform-agnostic NIP-5A static-site resolver verifying content-addressed Blossom blobs against signed manifests. |
| archive/2026-06-20-powr-interop.md | Parse and render the POWR/NIP-101e kind-1301 strength-workout dialect alongside the existing RUNSTR dialect. |
| archive/2026-06-28-git-smart-http-browser.md | Git smart-HTTP v2 client to browse NIP-34 repo file trees and render source from the clone URL. |