node wifi-share: hand a PC's Wi-Fi to a headless box by sound (ADR-0243, sender half) - #423
Merged
Merged
Conversation
…-0243, sender half) Adds murakumo.onboard (seal/open over node:crypto, rules from grant.acoustic-onboard), murakumo.wifi-share and its localhost page, and the `murakumo node wifi-share` command. The passphrase is read from the OS into the helper process, sealed there, and never printed or sent to the browser; the envelope is bound to the box's label secret; a person confirms the heard code before anything is sealed. Pins grant to the acoustic-onboard branch commit, adds ggwave 0.4.0 to the packaged runtime, rebuilds release/node.mjs and the installer hashes, and adds unit tests (golden vector from grant) and a packaged-CLI integration test run in CI. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This was referenced Oct 1, 2026
The site's cljk-mirror refuses a .cljk file with no entry in its repo's cljk-origin.edn (the Worker build of murakumo.cloud mirrors this repo), so these files must be recorded or merging would stop that build. They are node-side (js interop), so .cljs. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…o feat/node-onboard-helper
com-junkawasaki
changed the base branch from
feat/device-claim-responder
to
main
October 2, 2026 06:16
com-junkawasaki
marked this pull request as ready for review
October 2, 2026 06:16
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #421 (base is
feat/device-claim-responder, because the node CLI dispatcher,device_claimandnixos-node.nixexist only there). Retarget tomainonce #421 merges. Draft, and depends on kotoba-lang/grant#6 and kotoba-lang/aiueos#416 (both draft).What
murakumo node wifi-share: on a PC that is on the Wi-Fi to share, read its passphrase from the OS (macOS keychain with the OS prompt, NetworkManager,netsh), seal it in this process, and serve a localhost page that hears the box's beacon and plays the sealed bytes by sound.murakumo.onboard:seal/openover node:crypto (X25519, HKDF-SHA256, AES-256-GCM) using the byte rules ingrant.acoustic-onboard.murakumo.wifi-share+wifi-share-page: loopback-only server, per-run token, at most five distinct codes sealed per run, a person confirms the heard code.Verification
kbb -M:test -n murakumo.onboard-test(8 tests, 24 assertions, repeated with random keys) reproduces the grant golden message byte for byte and opens it; refuses wrong label secret, wrong session, wrong box, tampered ciphertext and tag.kbb -M:test -n murakumo.wifi-share-test: 4 tests, 13 assertions.node test/wifi_share_test.mjs(added to CI): runs the packaged CLI, then opens its output with an independent node:crypto implementation. Existingnode test/node_cli_distribution_test.mjsstill passes.Found while building this
Generating real X25519 keys in these tests exposed a bug in grant#6 (base64url last-character check reversed; about three in four real keys refused). Fixed there (kotoba-lang/grant@46406645) and this PR pins that commit.
Not verified / not in this PR
--passphrase-stdinwere run, and the macOS keychain read was not executed by me.murakumo node onboard, the beacon sender, applying the profile, and the NixOS unit are the next PR.ggwave0.4.0 npm dependency (MIT) to the packaged runtime, sorelease/package*.json,release/node.mjsandinstall.shhashes change; the installer pin (cloud-murakumo-installer) needs regenerating when this ships.🤖 Generated with Claude Code