From 30e855f55f1d920b25da0bdd8e538c249d3c0c26 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Tue, 18 Aug 2026 09:42:34 +0200 Subject: feat(client): the platform seam, and an Electron shell that has never been run MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Stage D, and the honest half of it. D1 — the seam (done, and verified) ---------------------------------- `static/platform.js`. `HUB` becomes `platform.hubBase()` and the transport is built with the same base, so one address has one source. In a browser it returns '' and every path stays relative to the origin that served the page — the acceptance criterion for this split was "the browser SPA behaves identically", and it does. `platform.js` joins `_ASSETS`, or a change to it would not move the content hash and a cached browser would never ask for it. D2 — the shell (written, never launched) ----------------------------------------- **There is no npm on this machine. Electron was never installed and `packages/meshbay-client/` has not been run once.** That is stated here rather than discovered later. What is there: a main process serving the packaged interface over a privileged `app://` scheme (`secure` and `standard` are not cosmetic — without them the service worker refuses to register and streamed downloads break silently), a preload exposing an enumerated bridge that never passes a filesystem path, a window with `sandbox`, `contextIsolation` and no node integration, navigation away from the package refused, and a CSP where the hub is reachable over connect-src and is not a script source. The hub address arrives as a process argument because `platform.hubBase()` runs before anything can await. `test_desktop_shell.py` pins each of those by reading the source — the treatment `test_downloads.py` already gives the three browser save paths. It catches a property being removed and proves nothing about the application running. Two were checked by breaking them. The interface is *copied* into the package by `build/sync-ui.js` from the hub's static directory, and `ui/` is gitignored: a silent fork is the only real way to end up maintaining the interface twice. D3 — partial ------------ The bridge, and the part worth having now: safeStorage's backend is reported rather than assumed. On Linux it falls back to a fixed key when no keyring is running, silently — someone who believes the OS is holding their keys is told when it is not. The native key lifecycle belongs with D4 and needs a running application to mean anything. D8 — partial, and a real defect found -------------------------------------- `meshbay-node.spec` installed the SYSTEM template — the one carrying `User=%i` — into `%{_userunitdir}`. A user unit already runs as its owner and cannot carry `User=`; systemd refuses the file, so the packaged unit could never have started. Nothing noticed because nobody had built and installed the RPM. Two units now: the template to `%{_unitdir}`, and a new `meshbay-node-user.service` that a person enables themselves without a password — which is what lets the desktop client install a node without asking for one. It carries ExecReload, so `meshbay-node reload` does not have to stop a service somebody is streaming from, and documents the drop-in for a drive outside the home, RequiresMountsFor included. 798 tests pass; e2e.py still passes end to end. Nothing here was built or launched: no npm, no rpmbuild. Co-Authored-By: Claude Opus 5 --- CLAUDE.md | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) (limited to 'CLAUDE.md') diff --git a/CLAUDE.md b/CLAUDE.md index 7a944af..c117c5e 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -338,6 +338,24 @@ anything that assumes one key per person. key from the per-node identities. What it does cost is metadata: the hub now knows how many devices an account has and when each last signed in +- **The desktop client exists as source and has never been run.** There is no + npm on the development machine, so Electron was never installed and + `packages/meshbay-client/` has not been launched once. `test_desktop_shell.py` + pins its security contract by reading the source — sandbox, contextIsolation, + the privileged `app://` scheme, the CSP keeping `wasm-unsafe-eval`, the + traversal check, the bridge exposing no path. That is the same weak evidence + `test_downloads.py` gives the browser save paths, and for the same reason: it + catches a property being *removed*, and proves nothing about the thing running + +- **A user unit cannot carry `User=`.** `meshbay-node.spec` installed the system + template into `%{_userunitdir}`, where systemd refuses the file outright — the + packaged unit could never have started, and nothing noticed because nobody had + built and installed the RPM. Two units now, `test_packaging_units.py` holds + each in its own directory. Note the test's own first version searched the + whole file and matched the *comment* explaining why `User=` is absent; parse + directives, not text — the same mistake as reading a CSP out of the comment + above the meta tag + ## Two lessons that cost four rounds of live testing - **`QE/deploy/e2e.py` cannot test `app.js`.** It is a second implementation of the -- cgit v1.2.3