v0.2.6-pre.016-fix.002

This commit is contained in:
2026-08-22 08:37:56 +02:00
parent 738b340cc7
commit 5c0be421da
10 changed files with 206 additions and 159 deletions

View File

@@ -6,7 +6,7 @@ resolver = "3"
members = ["crates/ksp-app-config-desk", "crates/ksp-app-wallet-desk", "crates/ksp-config-lib", "crates/ksp-core-lib", "crates/ksp-logging-lib", "crates/ksp-onchain-transport-lib", "crates/ksp-wallet-lib"] members = ["crates/ksp-app-config-desk", "crates/ksp-app-wallet-desk", "crates/ksp-config-lib", "crates/ksp-core-lib", "crates/ksp-logging-lib", "crates/ksp-onchain-transport-lib", "crates/ksp-wallet-lib"]
[workspace.package] [workspace.package]
version = "0.2.6-pre.16.fix.1" version = "0.2.6-pre.16.fix.2"
edition = "2024" edition = "2024"
license = "MIT" license = "MIT"
repository = "https://git.sasedev.com/Sasedev/khadhroony-solana-project" repository = "https://git.sasedev.com/Sasedev/khadhroony-solana-project"

View File

@@ -914,23 +914,23 @@ impl AppState {
std::result::Result::Err(_) => return std::result::Result::Err(session_lock_error()), std::result::Result::Err(_) => return std::result::Result::Err(session_lock_error()),
}; };
let previous = std::mem::replace(&mut *session, crate::WalletSession::no_selection()); let previous = std::mem::replace(&mut *session, crate::WalletSession::no_selection());
match previous { return match previous {
crate::WalletSession::ViewOperation { wallet_id: reserved_wallet_id, path: reserved_path, pubkey: reserved_pubkey } crate::WalletSession::ViewOperation { wallet_id: reserved_wallet_id, path: reserved_path, pubkey: reserved_pubkey }
if reserved_wallet_id == wallet_id && reserved_path == path && reserved_pubkey == pubkey => if reserved_wallet_id == wallet_id && reserved_path == path && reserved_pubkey == pubkey =>
{ {
*session = crate::WalletSession::View { wallet_id: wallet_id.clone(), path, wallet: view }; *session = crate::WalletSession::View { wallet_id: wallet_id.clone(), path, wallet: view };
ksp_logging_lib::info!(target: crate::TRACING_TARGET, domain = crate::TRACING_DOMAIN_WALLET_SESSION, wallet_id = wallet_id.as_str(), operation, "Wallet VIEW privileged operation completed"); ksp_logging_lib::info!(target: crate::TRACING_TARGET, domain = crate::TRACING_DOMAIN_WALLET_SESSION, wallet_id = wallet_id.as_str(), operation, "Wallet VIEW privileged operation completed");
return std::result::Result::Ok(dto); std::result::Result::Ok(dto)
}, },
other => { other => {
*session = other; *session = other;
drop(view); drop(view);
return std::result::Result::Err(ksp_core_lib::Error::new( std::result::Result::Err(ksp_core_lib::Error::new(
crate::ERROR_CODE_WALLET_SESSION_INVALID, crate::ERROR_CODE_WALLET_SESSION_INVALID,
"Wallet VIEW operation completion no longer owns the selected session", "Wallet VIEW operation completion no longer owns the selected session",
)); ))
}, },
} };
} }
fn restore_view_after_operation_failure(&self, context: ViewOperationContext) { fn restore_view_after_operation_failure(&self, context: ViewOperationContext) {
@@ -1039,7 +1039,7 @@ impl AppState {
std::result::Result::Err(_) => return std::result::Result::Err(session_lock_error()), std::result::Result::Err(_) => return std::result::Result::Err(session_lock_error()),
}; };
let previous = std::mem::replace(&mut *session, crate::WalletSession::no_selection()); let previous = std::mem::replace(&mut *session, crate::WalletSession::no_selection());
match previous { return match previous {
crate::WalletSession::OwnerOperation { crate::WalletSession::OwnerOperation {
wallet_id: reserved_wallet_id, wallet_id: reserved_wallet_id,
path: reserved_path, path: reserved_path,
@@ -1048,17 +1048,17 @@ impl AppState {
} if reserved_wallet_id == wallet_id && reserved_path == path && reserved_pubkey == pubkey && reserved_view_enabled == view_enabled => { } if reserved_wallet_id == wallet_id && reserved_path == path && reserved_pubkey == pubkey && reserved_view_enabled == view_enabled => {
*session = crate::WalletSession::Owner { wallet_id: wallet_id.clone(), path, view_enabled: result_view_enabled, wallet: owner }; *session = crate::WalletSession::Owner { wallet_id: wallet_id.clone(), path, view_enabled: result_view_enabled, wallet: owner };
ksp_logging_lib::info!(target: crate::TRACING_TARGET, domain = crate::TRACING_DOMAIN_WALLET_SESSION, wallet_id = wallet_id.as_str(), operation, "Wallet OWNER privileged operation completed"); ksp_logging_lib::info!(target: crate::TRACING_TARGET, domain = crate::TRACING_DOMAIN_WALLET_SESSION, wallet_id = wallet_id.as_str(), operation, "Wallet OWNER privileged operation completed");
return std::result::Result::Ok(dto); std::result::Result::Ok(dto)
}, },
other => { other => {
*session = other; *session = other;
drop(owner); drop(owner);
return std::result::Result::Err(ksp_core_lib::Error::new( std::result::Result::Err(ksp_core_lib::Error::new(
crate::ERROR_CODE_WALLET_SESSION_INVALID, crate::ERROR_CODE_WALLET_SESSION_INVALID,
"Wallet OWNER operation completion no longer owns the selected session", "Wallet OWNER operation completion no longer owns the selected session",
)); ))
}, },
} };
} }
fn restore_owner_after_operation_failure(&self, context: OwnerOperationContext) { fn restore_owner_after_operation_failure(&self, context: OwnerOperationContext) {

View File

@@ -1,5 +1,5 @@
// file: crates/ksp-app-wallet-desk/tests/desktop_contract.rs // file: crates/ksp-app-wallet-desk/tests/desktop_contract.rs
// version: 17 // version: 18
//! Desktop build, shell and Config-status contract audits for Wallet Desk. //! Desktop build, shell and Config-status contract audits for Wallet Desk.
@@ -16,6 +16,11 @@ fn read_text(path: &std::path::Path) -> String {
}; };
} }
fn read_source(relative_path: &str) -> String {
let root = app_root();
return read_text(root.join(relative_path).as_path());
}
fn read_json(path: &std::path::Path) -> serde_json::Value { fn read_json(path: &std::path::Path) -> serde_json::Value {
let source = read_text(path); let source = read_text(path);
let parsed = serde_json::from_str::<serde_json::Value>(source.as_str()); let parsed = serde_json::from_str::<serde_json::Value>(source.as_str());

View File

@@ -1,5 +1,5 @@
// file: crates/ksp-wallet-lib/src/runtime.rs // file: crates/ksp-wallet-lib/src/runtime.rs
// version: 1 // version: 2
//! Version-neutral unlocked Wallet state dispatch used by stable OWNER/VIEW handles. //! Version-neutral unlocked Wallet state dispatch used by stable OWNER/VIEW handles.
@@ -16,14 +16,6 @@ pub(crate) enum OwnerState {
} }
impl OwnerState { impl OwnerState {
/// Returns the native format version owned by this OWNER state.
pub(crate) const fn format_version(&self) -> u32 {
return match self {
Self::V1(_) => crate::KSPWALLET_FORMAT_VERSION_V1,
Self::V2(_) => crate::KSPWALLET_FORMAT_VERSION_V2,
};
}
/// Exports the Solana identity through the requested external transfer format. /// Exports the Solana identity through the requested external transfer format.
pub(crate) fn export_transfer(&self, format: crate::WalletTransferFormat) -> ksp_core_lib::Result<std::vec::Vec<u8>> { pub(crate) fn export_transfer(&self, format: crate::WalletTransferFormat) -> ksp_core_lib::Result<std::vec::Vec<u8>> {
return match self { return match self {
@@ -43,8 +35,8 @@ impl OwnerState {
/// Stages an authenticated metadata replacement without publishing it. /// Stages an authenticated metadata replacement without publishing it.
pub(crate) fn stage_metadata_payload(&self, payload: crate::MetadataPayloadV1) -> ksp_core_lib::Result<(StagedEnvelope, crate::WalletInfo)> { pub(crate) fn stage_metadata_payload(&self, payload: crate::MetadataPayloadV1) -> ksp_core_lib::Result<(StagedEnvelope, crate::WalletInfo)> {
return match self { return match self {
Self::V1(state) => state.stage_metadata_payload(payload).map(|(envelope, info)| (StagedEnvelope::V1(envelope), info)), Self::V1(state) => state.stage_metadata_payload(payload).map(|(envelope, info)| return (StagedEnvelope::V1(envelope), info)),
Self::V2(state) => state.stage_metadata_payload(payload).map(|(envelope, info)| (StagedEnvelope::V2(envelope), info)), Self::V2(state) => state.stage_metadata_payload(payload).map(|(envelope, info)| return (StagedEnvelope::V2(envelope), info)),
}; };
} }
@@ -67,16 +59,16 @@ impl OwnerState {
/// Stages strong VIEW disable while retaining OWNER authority. /// Stages strong VIEW disable while retaining OWNER authority.
pub(crate) fn stage_disable_view(&self) -> ksp_core_lib::Result<(StagedEnvelope, crate::SecretKeyV1)> { pub(crate) fn stage_disable_view(&self) -> ksp_core_lib::Result<(StagedEnvelope, crate::SecretKeyV1)> {
return match self { return match self {
Self::V1(state) => state.stage_disable_view().map(|(envelope, key)| (StagedEnvelope::V1(envelope), key)), Self::V1(state) => state.stage_disable_view().map(|(envelope, key)| return (StagedEnvelope::V1(envelope), key)),
Self::V2(state) => state.stage_disable_view().map(|(envelope, key)| (StagedEnvelope::V2(envelope), key)), Self::V2(state) => state.stage_disable_view().map(|(envelope, key)| return (StagedEnvelope::V2(envelope), key)),
}; };
} }
/// Stages strong VIEW recreation under a new credential. /// Stages strong VIEW recreation under a new credential.
pub(crate) async fn stage_recreate_view(&self, password: crate::ViewPassword) -> ksp_core_lib::Result<(StagedEnvelope, crate::SecretKeyV1)> { pub(crate) async fn stage_recreate_view(&self, password: crate::ViewPassword) -> ksp_core_lib::Result<(StagedEnvelope, crate::SecretKeyV1)> {
return match self { return match self {
Self::V1(state) => state.stage_recreate_view(password).await.map(|(envelope, key)| (StagedEnvelope::V1(envelope), key)), Self::V1(state) => state.stage_recreate_view(password).await.map(|(envelope, key)| return (StagedEnvelope::V1(envelope), key)),
Self::V2(state) => state.stage_recreate_view(password).await.map(|(envelope, key)| (StagedEnvelope::V2(envelope), key)), Self::V2(state) => state.stage_recreate_view(password).await.map(|(envelope, key)| return (StagedEnvelope::V2(envelope), key)),
}; };
} }
@@ -155,14 +147,6 @@ pub(crate) enum ViewState {
} }
impl ViewState { impl ViewState {
/// Returns the native format version owned by this VIEW state.
pub(crate) const fn format_version(&self) -> u32 {
return match self {
Self::V1(_) => crate::KSPWALLET_FORMAT_VERSION_V1,
Self::V2(_) => crate::KSPWALLET_FORMAT_VERSION_V2,
};
}
/// Stages a VIEW credential rotation in the state native format. /// Stages a VIEW credential rotation in the state native format.
pub(crate) async fn stage_view_password_rotation(&self, password: crate::ViewPassword) -> ksp_core_lib::Result<StagedEnvelope> { pub(crate) async fn stage_view_password_rotation(&self, password: crate::ViewPassword) -> ksp_core_lib::Result<StagedEnvelope> {
return match self { return match self {

View File

@@ -1,5 +1,5 @@
// file: crates/ksp-wallet-lib/unit_tests/format.rs // file: crates/ksp-wallet-lib/unit_tests/format.rs
// version: 1 // version: 2
#[test] #[test]
fn default_and_latest_are_explicit_and_currently_v2() { fn default_and_latest_are_explicit_and_currently_v2() {
@@ -12,7 +12,15 @@ fn default_and_latest_are_explicit_and_currently_v2() {
fn detector_distinguishes_v1_json_and_v2_binary_without_crypto() -> ksp_core_lib::Result<()> { fn detector_distinguishes_v1_json_and_v2_binary_without_crypto() -> ksp_core_lib::Result<()> {
let v1 = include_bytes!("../tests/fixtures/kspwallet_v1_wire_only.json"); let v1 = include_bytes!("../tests/fixtures/kspwallet_v1_wire_only.json");
let v2 = include_bytes!("../tests/fixtures/kspwallet_v2_wire_only.bin"); let v2 = include_bytes!("../tests/fixtures/kspwallet_v2_wire_only.bin");
assert_eq!(crate::detect_wallet_format(v1)?, crate::WalletFormat::V1); let detected_v1 = match crate::detect_wallet_format(v1) {
assert_eq!(crate::detect_wallet_format(v2)?, crate::WalletFormat::V2); std::result::Result::Ok(value) => value,
std::result::Result::Err(error) => return std::result::Result::Err(error),
};
let detected_v2 = match crate::detect_wallet_format(v2) {
std::result::Result::Ok(value) => value,
std::result::Result::Err(error) => return std::result::Result::Err(error),
};
assert_eq!(detected_v1, crate::WalletFormat::V1);
assert_eq!(detected_v2, crate::WalletFormat::V2);
return std::result::Result::Ok(()); return std::result::Result::Ok(());
} }

View File

@@ -0,0 +1,50 @@
<!-- file: deltas/0.2.6/pre.016-fix.002.md -->
<!-- version: 1 -->
# Delta `0.2.6-pre.016-fix.002` — nettoyage compile/Clippy des dispatchs V1/V2
## Base requise
```text
0.2.6-pre.016-fix.001 appliquée
workspace.package.version = 0.2.6-pre.16.fix.1
```
Le checkpoint opérateur confirme que le correctif AAD de `fix.001` élimine les erreurs `E0308`, mais expose quatre défauts résiduels de `pre.016` :
- deux méthodes internes `OwnerState::format_version` / `ViewState::format_version` inutilisées ;
- six closures de mapping dans `runtime.rs` incompatibles avec `clippy::implicit-return = deny` ;
- deux usages de `?` dans `unit_tests/format.rs`, incompatibles avec `clippy::question-mark-used = deny` ;
- le canari Desktop `pre_016_wallet_desk_uses_version_neutral_wallet_dispatch` utilise un helper `read_source` non défini.
## Signal technique
```text
workspace.package.version = 0.2.6-pre.16.fix.2
commit = v0.2.6-pre.016-fix.002
```
Aucun tag prerelease. Aucun changement npm/Tauri.
## Corrections
- suppression des deux méthodes internes mortes `format_version`; les projections publiques restent basées sur `WalletInfo` ;
- `return` explicites dans les closures de mapping V1/V2 ;
- remplacement des deux `?` de test par des `match` explicites ;
- ajout du helper local `read_source(relative_path)` dans le canari Wallet Desk.
Aucun changement du wire V1/V2, des transcripts/AAD, des fixtures, des APIs publiques, du dispatch fonctionnel ou de la politique `DEFAULT_WALLET_FORMAT` / `LATEST_SUPPORTED_WALLET_FORMAT`.
## Validation opérateur requise
```bash
cargo fmt --all
python3 scripts/audit_rust_workspace_rules.py
cargo check --workspace
cargo clippy --workspace --all-targets
cargo test -p ksp-wallet-lib
cargo test -p ksp-app-wallet-desk
cargo test --workspace
```
Si ce checkpoint est vert, `0.2.6-pre.016-fix.002` peut être commitée et la suite reste `0.2.6-pre.017`. Ne pas exécuter `cargo tauri build` avant `pre.018`.

View File

@@ -18,7 +18,7 @@ Ce document maintient l'inventaire synthétique des composants retenus ou presse
## Inventaire synthétique ## Inventaire synthétique
| Domaine | Composant | Type | Statut | Première cible actuelle | Mission | | Domaine | Composant | Type | Statut | Première cible actuelle | Mission |
|-------------------------|------------------------------------------|--------------------|--------------|---------------------------------|-------------------------------------------------------------| |-------------------------|------------------------------------------|--------------------|--------------|---------------------------------|--------------------------------------------------------------|
| Core | `ksp-core-lib` | lib | Stable | `0.1.1` | Error/Result, Program IDs et primitives fondamentales | | Core | `ksp-core-lib` | lib | Stable | `0.1.1` | Error/Result, Program IDs et primitives fondamentales |
| Logging | `ksp-logging-lib` | lib | Stable | `0.1.2` | façade unique tracing KSP | | Logging | `ksp-logging-lib` | lib | Stable | `0.1.2` | façade unique tracing KSP |
| Config | `ksp-config-lib` | lib | Stable | `0.1.3` | documents, profils, env et persistence Config | | Config | `ksp-config-lib` | lib | Stable | `0.1.3` | documents, profils, env et persistence Config |

View File

@@ -105,7 +105,7 @@ Une implémentation conforme doit vérifier les bornes **avant** toute allocatio
Le début de fichier est strictement : Le début de fichier est strictement :
| Ordre | Champ | Taille | Valeur / règle | | Ordre | Champ | Taille | Valeur / règle |
|---:|---|---:|---| |------:|---------------------------|-----------------:|------------------------------------------------|
| 1 | `magic` | 9 | ASCII exact `KSPWALLET` | | 1 | `magic` | 9 | ASCII exact `KSPWALLET` |
| 2 | `format_version` | 2 | `0x0002` | | 2 | `format_version` | 2 | `0x0002` |
| 3 | `document_length` | 4 | longueur totale exacte du fichier | | 3 | `document_length` | 4 | longueur totale exacte du fichier |
@@ -155,7 +155,7 @@ Aucun compteur de slots ou de compartiments n'est nécessaire : leur cardinalit
Chaque key slot est encodé ainsi : Chaque key slot est encodé ainsi :
| Champ | Taille | Valeur / règle | | Champ | Taille | Valeur / règle |
|---|---:|---| |--------------------------|---------:|-----------------------------------------|
| `role` | 1 | `0x01` OWNER, `0x02` VIEW | | `role` | 1 | `0x01` OWNER, `0x02` VIEW |
| `slot_id` | 16 | identifiant binaire exact | | `slot_id` | 16 | identifiant binaire exact |
| `kdf_algorithm` | 1 | `0x01` Argon2id | | `kdf_algorithm` | 1 | `0x01` Argon2id |
@@ -190,7 +190,7 @@ Toute divergence est invalide avant KDF/déchiffrement.
Chaque compartiment est encodé : Chaque compartiment est encodé :
| Champ | Taille | Valeur / règle | | Champ | Taille | Valeur / règle |
|---|---:|---| |---------------------|---------:|------------------------------------------------------|
| `kind` | 1 | `0x01` OWNER-CONTROL, `0x02` METADATA, `0x03` SECRET | | `kind` | 1 | `0x01` OWNER-CONTROL, `0x02` METADATA, `0x03` SECRET |
| `payload_version` | 4 | `1` pour le profil initial V2 | | `payload_version` | 4 | `1` pour le profil initial V2 |
| `algorithm` | 1 | `0x01` XChaCha20-Poly1305 | | `algorithm` | 1 | `0x01` XChaCha20-Poly1305 |
@@ -215,7 +215,7 @@ Les payloads plaintext V2 conservent le modèle fonctionnel établi en V1 pour c
La fin du document est : La fin du document est :
| Champ | Taille | Valeur / règle | | Champ | Taille | Valeur / règle |
|---|---:|---| |-----------------------------|-------:|---------------------------|
| `state_signature.algorithm` | 1 | `0x01` Ed25519 | | `state_signature.algorithm` | 1 | `0x01` Ed25519 |
| `state_signature.signature` | 64 | signature detached exacte | | `state_signature.signature` | 64 | signature detached exacte |
@@ -378,7 +378,7 @@ Le nonce/ciphertext n'est pas inclus dans son propre AAD.
V1 et V2 sont deux formats explicites : V1 et V2 sont deux formats explicites :
| Propriété | V1 | V2 | | Propriété | V1 | V2 |
|---|---|---| |--------------------------|------------------------------------|---------------|
| enveloppe | JSON UTF-8 | binaire KSP | | enveloppe | JSON UTF-8 | binaire KSP |
| champs binaires | Base64url no-pad | bytes directs | | champs binaires | Base64url no-pad | bytes directs |
| version | `1` | `2` | | version | `1` | `2` |

View File

@@ -771,7 +771,7 @@ outil de logging contrôlé
## 12. Command map ## 12. Command map
| Command | Entrée frontend | Sortie sûre | Délégation | | Command | Entrée frontend | Sortie sûre | Délégation |
|----------------------------------------------|--------------------|-------------------------------------|---------------------------------| |----------------------------------------------|--------------------|-------------------------------------|-------------------------------------|
| `get_runtime_status` | — | `WalletRuntimeStatusDto` | Config/app state | | `get_runtime_status` | — | `WalletRuntimeStatusDto` | Config/app state |
| `list_wallets` | — | `Vec<WalletInventoryEntryDto>` | app filesystem + Wallet inspect | | `list_wallets` | — | `Vec<WalletInventoryEntryDto>` | app filesystem + Wallet inspect |
| `refresh_wallets` | — | inventory DTO | app filesystem + Wallet inspect | | `refresh_wallets` | — | inventory DTO | app filesystem + Wallet inspect |

View File

@@ -52,7 +52,7 @@ Le checkpoint opérateur `pre.012` du 21 août 2026 est vert : `cargo fmt`, audi
## 3. Matrice de frontières ## 3. Matrice de frontières
| Frontière | Contrat `0.2.6` | Preuve durable | | Frontière | Contrat `0.2.6` | Preuve durable |
|---|---|---| |------------------------------|--------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------|
| Frontend -> Config | aucun accès direct env/.env | `release_compliance::backend_keeps_config_wallet_transport_and_logging_ownership_boundaries` + ownership Config | | Frontend -> Config | aucun accès direct env/.env | `release_compliance::backend_keeps_config_wallet_transport_and_logging_ownership_boundaries` + ownership Config |
| Frontend -> Wallet secret | passwords uniquement request-only ; jamais de keypair en IPC | `desktop_security` + `release_compliance::response_dtos_keep_secret_key_material_out_of_ipc` | | Frontend -> Wallet secret | passwords uniquement request-only ; jamais de keypair en IPC | `desktop_security` + `release_compliance::response_dtos_keep_secret_key_material_out_of_ipc` |
| Frontend -> filesystem | aucun path arbitraire ; picker natif Rust | tests import/export + capability audit | | Frontend -> filesystem | aucun path arbitraire ; picker natif Rust | tests import/export + capability audit |