Repository navigation
Source Kit 0.1.2 - #73
Merged
Merged
Conversation
Signer Information becomes three peer credentials, and the typed byline is gone. A name a user simply typed is not something a verifier can check, so there is nowhere left to type one. Website (new, sourcekit-site/1): publish one file at /.well-known/sourcekit-site.json listing the phones allowed to sign as you. No certificate authority, no account, and no DNS record — the file rests on the certificate already on the website. It is a separate type from OrgCredential rather than a flag on it, so the weaker claim cannot be mistaken for the stronger one at any call site. Verified Identity (new): the app builds a PKCS#10 certification request and signs it with the Enclave key, which is how the request proves it controls the key it names. Trust is evaluated against anchor lists the device holds and reported as trusted or self-asserted, never assumed. The pinned list ships empty and is filled from the published list at runtime; no fingerprint is written by hand. Organization Credential moves to its own screen with the key-sharing half it always needed. The x5chain now follows the identity mode. Anonymous signs with the bare device certificate: shipping the org chain named an organization the capture had promised to leave out. Settings keeps three rows and one line. Everything a row used to explain lives behind the tap. Tests: the certification request is verified by OpenSSL, issued against by a test CA, and the issued certificate is walked back through the install path, including the key-mismatch and missing-purpose refusals. The site document round-trips and every way it can disagree with itself is rejected. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01P3RisvkEsx2cgseTRMmUdB
The record named the raw LPCM master, the sensor log and the ring buffer
by path. A path says where a file was and nothing about what it held, so a
swapped master or a rewritten sensor log left every signature valid. The
evidence a desk reaches for first was the evidence nothing bound.
Each sink now carries a digest taken before the record is signed:
file sink SHA-256 over the bytes.
directory sink SHA-256 over the listing — each frame's own digest beside
its name, sorted by name, hashed together. The sort is
what makes it reproducible; readDirectoryAsync promises
no order.
The three states survive. A sink that reports 'never-recorded' has no
digest by construction, a sink whose file cannot be read yields null, and
a reader that finds no digest says the sidecar is uncommitted rather than
assuming a match. Records sealed before this change carry none, so the
fields are optional and their absence is reported as absence.
The raw audio card recomputes the file hash it already reads and states
one of the three outcomes against the sealed value.
Also removes a doc comment in the store describing a weather opt-in
setting that does not exist: the archive lookup is gated by the tap on
"Check the archive" and by nothing else.
Lab: 32/32 suites, including a new evidence-digest suite that checks the
file digest against node crypto, the directory digest for order
independence and content sensitivity, and every absence path.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P3RisvkEsx2cgseTRMmUdB
Anonymous, personal and organization, what credential each one rests on, and who vouches for it: a certificate authority, a domain over TLS, or an organization's own CA. States the recognition rule under the CAWG interim trust model, and why an unrecognized issuer reads as self-asserted rather than as a failure. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01P3RisvkEsx2cgseTRMmUdB
The credentials section named only the organization route and claimed it was the only thing that can attach a name to a key. A personal certificate and a website credential both do, on different evidence: an authority that checked a person, and a domain that published a key over TLS. Each is now described with what it rests on and what it does not carry. The raw audio paragraph promised the master's hash was signed into the record, in a clause that ran on from the resampling sentence. That is now true of all three sidecars, and the sentence says which and how, including what a reader does when it finds no hash. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01P3RisvkEsx2cgseTRMmUdB
noah-pi
force-pushed
the
claude/source-kit-open-source-launch-w4030i
branch
2 times, most recently
from
September 13, 2026 17:00
c6f6cf1 to
8f52314
Compare
The two detail screens read every file through one grammar: five questions, one answer each, one word naming who vouches. A file another signer sealed is read the same way, with its chain checked against a pinned list of public signers. Identity is two rows on one screen, a website or a certificate, and the words a reader sees are Domain verified, Certified, Verified, Certificate, Not provided, and Redacted. Each capture carries a fresh App Attest assertion over its own digest, checked against either of the build's two app ids. Newsroom rosters are not installed on the device, so the roster store, the desk seal, and the two identity screens they served are gone, with the custom endpoint fields that had no screen. The Face ID signing switch is back under Device key. The soak check lives under Diagnostics. The lab stages the label grammar and the foreign reader and checks them: the foreign, capture-assertion, and label blocks join the verification suite, and the Shamir checks keep their own suite. 33 suites, both typechecks, knip, and the dependency budget pass. The docs describe this app. SETTINGS.md is rewritten from the screen. NETWORK.md lists all eleven calls. THREAT-MODEL.md places the signature for five designs, retires the roster scenarios, and states what a de-identified copy carries. INTEGRITY.md documents the parallax measurement and the dual-camera depth map as shipped. IDENTITY.md, ARCHITECTURE.md, and PROVENANCE.md follow the code. LABEL.md is new. The README and the site carry the September 13 note on Apple's Reference Mode, place the iPhone 18 Pro at the sensor in the pipeline figure, and name the six optional calls. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01P3RisvkEsx2cgseTRMmUdB
noah-pi
force-pushed
the
claude/source-kit-open-source-launch-w4030i
branch
from
September 13, 2026 17:04
8f52314 to
8cb5f89
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this brings
The open tree matches the 0.26 app, minus the pieces that stay closed.
Code
src/components/detail/). A file another signer sealed is read the same way (src/reader/foreign.ts), with its chain checked against a pinned list of public signers (src/lib/signerTrustList.ts).app/identity/certificate.tsx). The old organization and verified screens are removed.AppAttestModule.generateAssertiontakes the key id from the caller.rosterStore.ts,seal.ts, the desk handoff in the export sheet, and the dead ladder card are gone, with the custom TSA, OTS calendar, and beacon endpoint fields that had no screen.Lab
tests/test-verification.mtsgains the foreign-manifest, capture-assertion, and label blocks. The label grammar and the foreign reader are staged as shipped, with a type-only shim for the screen state shapes.tests/test-shamir.mts; the desk-seal suite goes with the module it tested.Docs
SETTINGS.mdrewritten from the screen, in screen order.NETWORK.mdlists all eleven calls, with the website file, the organization file, and the IPTC anchor list, and says attestation runs locally.THREAT-MODEL.mdplaces the signature for five designs, retires the roster scenarios, and restates malleability, timestamp authorities, replay, and what a de-identified copy carries.INTEGRITY.mddocuments the parallax measurement and the dual-camera depth map as shipped.IDENTITY.md,ARCHITECTURE.md,PROVENANCE.md,BUILDING.md, andSECURITY.mdfollow the code.LABEL.mdis new.README and site
Not in this PR
🤖 Generated with Claude Code
https://claude.ai/code/session_01P3RisvkEsx2cgseTRMmUdB