mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-05 19:28:25 +00:00
Three leftovers from the extraction, plus the documentation it needs to
survive.
`KeyPackageRotationManager` still built its leaf capabilities from bare hex
(`0x000A`, `0xF2EE`, `0x000A`) with the two meanings of `0x000A` -- last_resort
as an extension, self_remove as a proposal -- distinguishable only by which
list they were in. That set is now `MarmotCapabilities.mipKeyPackageLeaf()`,
beside the other two profiles, with the ordering marked load-bearing: those
bytes go into published KeyPackages and define KeyPackageBundleStore's v4
snapshot format.
`MarmotManager` and `MarmotConvergenceEngine` still spelled
`exporterSecret("marmot", "group-event", 32)` literally at three call sites, so
the binding's key derivation was stated in four places. They read it off
`MarmotGroupPolicy.commitExporter` now, which is where the engine reads it too.
`CurrentProfileWelcomeTest` and `CommitPreservesLeafIdentityTest` sat in the
`mls/` test tree with ten and three Marmot imports between them; they test
Marmot's current profile, so they move to `marmot/appComponents/`.
The README states the invariant as a command you can run, and scopes it
honestly: shipped code only. Two tests under `mls/components/` do decode real
Marmot components, because an interop test is worth more against payloads that
actually exist -- a fixture is data, an import in the engine is a dependency.
It also writes down the three things a second binding has to know, the one
that will bite (a policy is behaviour, not state, so a restore that forgets it
silently drops the rules), and why the default is permissive rather than
closed.
The plan's Stage 1 is marked landed with what it cost and what Stage 3 still
owes: MlsGroupManager names `nostrGroupId` 147 times, so cordn needs its own
manager over the same MlsGroup rather than reusing that one. §5.1's coupling
measurements are marked superseded rather than deleted -- they are what the
stage was scoped against.
Verified: :quartz:jvmTest 5082, :commons:jvmTest 2202, both green;
:quic, :cli, :marmotBench and :amethyst all compile.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012BfD4txdnsaPRXmNXbup9n
quartz plans
Audited 2026-09-17. 13 plans: 7 shipped (archived), 0 in-progress, 5 queued, 1 closed (negative result).
Queued
| Plan | Summary |
|---|---|
| 2026-05-08-local-headers-explorer.md | Headers-only Bitcoin P2P client to verify NIP-03 OTS attestations without a trusted block explorer. |
| 2026-06-12-giftwrap-deletion-requests.md | Let a recipient-authored kind-5 delete/block a gift wrap (kind 1059) addressed to them. |
| 2026-07-03-incremental-negentropy-storage.md | Always-current (created_at, id) index so cold NEG-OPENs stop paying a full scan + seal (~340 ms at 50k vs strfry's ~21 ms). |
| 2026-07-04-small-req-floor.md | Small-REQ dispatch floor: decomposed, inline fast path tried and reverted (no wire-level win); floor is transport-side. |
| 2026-08-13-gpu-pow-mining.md | GPU NIP-13 mining declined (ARMv8 has SHA-256 in silicon, mobile GPUs do not). Midstate is ~3x on JVM targets; Android hinges on Conscrypt per-digest JNI cost, still unmeasured. created_at refresh while mining shipped. |
| 2026-09-17-cordn-interop.md | Cordn (cordn.net) is an alternative binding of MLS onto Nostr, not an alternative to MLS: same ciphersuite 0x0001, byte-identical ChaCha20-Poly1305 seal and NIP-01 envelope, but the delivery service is an MCP server over ContextVM with no key-package event kind. Only the RFC 9420 engine is shareable, and it is not yet Marmot-clean (3 files, 10 imports, 3 hardcoded policies). ContextVM must be written from scratch: full review of the spec + all 12 CEPs, with a per-CEP compliance matrix, CVM-* rule ids and a 5-tier test method (including a fixture server that misbehaves on demand, and RFC 8785 JCS which Quartz lacks). Blocked on the credential-identity encoding (raw 32 bytes vs 64-byte hex ASCII). Includes a coordinator metadata-exposure analysis. |
| 2026-09-08-marmot-spec-resync.md | Marmot moved off the MIP-era spec (2026-07-02): group state split into app_data_dictionary components, account identity proof v2, and a convergence engine. Current MDK rejects our groups outright. Gap analysis + 8-stage plan; Stages 0-4 done (mdk interop reference, app_data_dictionary, identity proof v2, the six group components, transport corrections); lifecycle + branch selection landed. |
Archived (shipped)
| Plan | Summary |
|---|---|
| archive/2026-06-03-fix-nip46-bunker-double-resume-plan.md | Fix NIP-46 bunker double-resume crash and retry id-reuse races via Channel-per-request + fresh id per attempt. |
| archive/2026-06-04-auth-scope-vs-policy.md | Move relay-server authenticated-identity state from the policy into the engine-owned connection scope. |
| archive/2026-06-09-clink.md | Implement CLINK (Offers/Debits/Manage) Lightning-over-Nostr pointers, events, and client/server in Quartz. |
| archive/2026-06-11-runstr-interop.md | RUNSTR kind-1301 workout events and supporting fitness kinds in Quartz plus Amethyst fitness screens. |
| archive/2026-06-19-napplet-nip5a-resolver.md | Platform-agnostic NIP-5A static-site resolver verifying content-addressed Blossom blobs against signed manifests. |
| archive/2026-06-20-powr-interop.md | Parse and render the POWR/NIP-101e kind-1301 strength-workout dialect alongside the existing RUNSTR dialect. |
| archive/2026-06-28-git-smart-http-browser.md | Git smart-HTTP v2 client to browse NIP-34 repo file trees and render source from the clone URL. |