diff --git a/core/archipelago/src/api/rpc/media_registration.rs b/core/archipelago/src/api/rpc/media_registration.rs index a2a2a380..115d29f9 100644 --- a/core/archipelago/src/api/rpc/media_registration.rs +++ b/core/archipelago/src/api/rpc/media_registration.rs @@ -201,12 +201,12 @@ impl RpcHandler { anyhow::ensure!( state .package_data - .get("indeedhub-api") + .get("indeedhub") .is_some_and(|entry| matches!( entry.state, crate::data_model::PackageState::Running )), - "The installed IndeeHub API must be running to register its media" + "The installed IndeeHub app must be running to register its media" ); let identity = crate::identity::NodeIdentity::load_existing(&self.config.data_dir.join("identity")) diff --git a/core/archipelago/src/container/registration_pin.rs b/core/archipelago/src/container/registration_pin.rs index bb13c2ea..c1be5e28 100644 --- a/core/archipelago/src/container/registration_pin.rs +++ b/core/archipelago/src/container/registration_pin.rs @@ -48,6 +48,12 @@ pub(crate) fn installed_context( state: &crate::data_model::DataModel, ) -> Result { for id in ["indeedhub", "indeedhub-api"] { + // Stack components are not separate package records on managed installs. + // Keep validating legacy standalone API records when they exist; the + // installed parent and its existing API identity pin are mandatory. + if id == "indeedhub-api" && !state.package_data.contains_key(id) { + continue; + } let entry = state .package_data .get(id) @@ -613,6 +619,12 @@ mod tests { assert!(installed_context(root.path(), &identity, &state).is_err()); let pin = ensure_for_installation(root.path(), "indeedhub-api", &identity).unwrap(); let first = installed_context(root.path(), &identity, &state).unwrap(); + let api_entry = state.package_data.remove("indeedhub-api").unwrap(); + assert_eq!( + installed_context(root.path(), &identity, &state).unwrap(), + first + ); + state.package_data.insert("indeedhub-api".into(), api_entry); assert_eq!(first.app_audience, pin.app_audience); assert_eq!(first.app_origins, vec!["https://localhost:7778"]); state.package_data.get_mut("indeedhub-api").unwrap().state = diff --git a/docs/post-1.8.22-regressions-20261001.md b/docs/post-1.8.22-regressions-20261001.md index 36d21ca0..52e27009 100644 --- a/docs/post-1.8.22-regressions-20261001.md +++ b/docs/post-1.8.22-regressions-20261001.md @@ -42,6 +42,79 @@ acceptance; this is a new paid-file incident. ## Current tasks +- 2026-10-09 live repair checkpoint (supersedes the pending deployment notes + immediately below): Yaya now runs management backend SHA256 + `938a90c7d9ecbdb179b1cf2886b5ed03e4d78c0d454f2cec42c0d9de3d447eb9`, + built from the registration correction in `424070d2`. Optimized build passed. + Management health, unchanged running container IDs, unchanged node identity key + and unchanged registration pin/marker checks passed. The old binary is retained + under `/var/lib/archipelago/support/indee-registration-424070d2/`. + The first context probe during inventory startup still failed; after inventory + recovery the authenticated `media.registration.context` probe succeeds and + returns all installation bindings. No catalog or app-data mutation was used. + The probe initially treated JSON-RPC `error: null` as failure; corrected it and + repeated the successful live request. Isolated backend regression compilation + remains pending after severe build-host swapping; do not claim its test passed. + + A real native Home Serve login then exposed another defect: `UserDTO` omitted + `nostrPubkey`, so the strict frontend profile check correctly refused the + otherwise matching signed session. IndeeHub `08586e3` adds this public field; + two DTO regressions and backend production build pass. Deployed only the built + DTO module with its previous copy saved under the private + `indee-profile-08586e3` artifact directory, then restarted only `indeedhub-api`. + API health passes. A clean real browser selected native **Home Serve**, approved + only its kind-27235 authentication request, and verified that the native choice, + session subject and API profile key match. The signer closes normally. No + identity was created/replaced and no payment or publication was submitted. + Frontend `7b18912` and API DTO remain running-container patches; durable image/ + managed deployment, complete video upload/publication and cached-account-switch + acceptance remain open. Preserve the operator's native identities throughout. + +- 2026-10-09 UI checkpoint: IndeeHub commit `40b3798` is served on Yaya + (index SHA256 `d921a88448f89674809dbe623ec045849012b1fb0330e3abf1d2d6836e9b3c96`). + Publishing now appears only in its own editor tab; Assets remains mounted + across tab switches. Copy distinguishes computer upload from Cloud-backed + catalog publication; saved-registration recovery is under a details control. + Production build and 26 focused frontend tests pass. Browser checks verify + native signer availability, no automatic login, removal of local account + controls and clearing of legacy app-local accounts. Real selected-identity + sign-in and video upload/publication remain unverified. This is a running + container frontend patch, not a durable pinned-image/catalog deployment. + Backend correction `424070d2` has ngit proposal + `9d6de783f5022b3b859e0b1f3e881e389da4482dd5dd15ff29a40b4e25dafcb8`; + isolated regression and optimized build are still running, not passed or + deployed. Preserve this distinction when resuming the backend work. + +- 2026-10-09 follow-up: operator reports missing autosign and the same generic + registration error. `40b3798` disabled provider auto-authentication without + replacing it with app authentication on native selection; this was a regression. + IndeeHub `7b18912` adds a single shared automatic/manual login path driven by + the trusted provider's `onIdentitySelected`. It rejects mismatching signer keys + and changed selections, checks the backend profile, and never falls back to a + cached app identity. Twenty-one focused tests and the production build pass. + Yaya serves index SHA256 + `1c7fee64430b0d993288408dbe493d0f4f55a49fe2422a3507c7204c12343632`; + the native provider bytes are unchanged. A disposable served-app browser test + verifies selection triggers exactly one kind-27235 signature request without + clicking login; it intentionally stops before signing with a stub. This is not + real-identity login acceptance. The first browser run raced deployment and + failed against the previous build; the post-deployment rerun passes. + Authenticated read-only registration RPC still reproduces the generic failure, + with server cause `IndeeHub is not installed`; backend build/test remain pending. + +- [ ] **2026-10-09 IndeeHub UAT remains failed:** operator still reports wrong + Nostr identity, upload failure and confusing always-visible publishing UI. + Preserve native identities; remove only app-local generated/imported accounts. + Require explicit Archipelago selection and matching API profile. On Yaya, + `media.registration.context` logs `IndeeHub is not installed` while all seven + containers run. Authenticated state includes only the parent `indeedhub` + package; the registration code incorrectly requires a separate + `indeedhub-api` package record. Candidate correction retains parent running/ + installed checks and the existing API installation pin; it checks a legacy + API package when present. Source tests/build and live registration acceptance + must complete before closing. Move publishing to its own editor tab, preserve + computer-upload state and existing pending registration requests. + - [x] Yaya App Store component/alias regression (reported 2026-10-02): one Cuprate entry (hide Cuprate UI companion), one BTCPay Server in Commerce with its icon (merge legacy btcpay pins), one NetBird entry (hide server diff --git a/docs/release-1.9.0-acceptance.md b/docs/release-1.9.0-acceptance.md index af553bc9..7b8dfb8b 100644 --- a/docs/release-1.9.0-acceptance.md +++ b/docs/release-1.9.0-acceptance.md @@ -92,8 +92,46 @@ hardening rather than claiming every cache key was erased. The IndeeHub frontend commits `0d6434e` and `71cf546a` remain local because that repository has no ngit coordinate; do not publish them Gitea-only under the mirror policy. +### IndeeHub selected-identity regression — UAT reopened 9 October 2026 + +Operator UAT disproved the earlier sign-out acceptance: choosing the homeserver +identity could continue with a previously active saved account and display a +different npub. `loginWithExtension` caught selection/provider failures without +rethrowing, after which the modal read `accountManager.active`; that pointer could +still name the old account. IndeeHub commits `a4d3946` and `86256ee` now clear the +active pointer before an explicit native switch, propagate failure, bind the +authentication call to the exact returned signer account, and retain the +Archipelago provider hook in the source index. A regression starts with a stale +saved account and proves a failed selection cannot fall back to it while the +saved key itself remains preserved. + +All 155 frontend tests, type checking and the production build pass. A live Yaya +frontend-only correction is installed with rollback under the operator's private +artifact directory. The served index references the provider, provider SHA256 is +still `ad4c93b3b25545dca1b391c5add75e5bc618c865290805f7ac5d1ad0fd18b469`, +the service worker was regenerated to invalidate the brief provider-less cache, +and `/health` passes. Automated Chromium confirms the provider loads and no stale +active account is restored. Real homeserver selection and displayed-npub matching +remain pending operator UAT; the current live filesystem correction is not yet a +new signed catalog/image activation and must not be described as durable managed +deployment acceptance. + ## Combined Yaya UAT candidate — 9 October 2026 +Follow-up operator request: retain all node-native identities; remove IndeeHub's +Create Account/private-key import and reset only its old browser accounts. +IndeeHub commit `7fbdc74` removes generation/import handlers and screens, performs +a one-time removal of `indeedhub-accounts`, `indeedhub-active-account` and app +session credentials, and corrects the default API base from browser localhost +to `/api`. The previous live hotfix was built without explicit API settings, +explaining its network error; its earlier success claims were premature. +Twenty-one focused authentication/reset tests pass and the production build +passes with `/api`, `/storage`, `/relay`, mock off and publication enabled. +This updated static bundle is deployed to Yaya's existing frontend container; +its index SHA256 is `a14834acab5fc9b42f55a92c540b9b765334ac7d2d2628ddc82bc1c5725d53ad`. +Node identity storage was not modified. Signed-image recreation and real native +identity sign-in acceptance remain outstanding. + The combined source is published on ngit and mirrored byte-for-byte to Gitea at main `bb933d409187a8181e284a5a91a81b4e036b3036`, based on accepted main `aff408cc`. Its integration commits retain each proposal head as a parent: