Skip to content

node wifi-share: hand a PC's Wi-Fi to a headless box by sound (ADR-0243, sender half) - #423

Merged
com-junkawasaki merged 6 commits into
mainfrom
feat/node-onboard-helper
Oct 2, 2026
Merged

com-junkawasaki merged 6 commits into
mainfrom
feat/node-onboard-helper

Conversation

@com-junkawasaki

Copy link
Copy Markdown
Member

Stacked on #421 (base is feat/device-claim-responder, because the node CLI dispatcher, device_claim and nixos-node.nix exist only there). Retarget to main once #421 merges. Draft, and depends on kotoba-lang/grant#6 and kotoba-lang/aiueos#416 (both draft).

What

murakumo node wifi-share: on a PC that is on the Wi-Fi to share, read its passphrase from the OS (macOS keychain with the OS prompt, NetworkManager, netsh), seal it in this process, and serve a localhost page that hears the box's beacon and plays the sealed bytes by sound.

  • murakumo.onboard: seal / open over node:crypto (X25519, HKDF-SHA256, AES-256-GCM) using the byte rules in grant.acoustic-onboard.
  • murakumo.wifi-share + wifi-share-page: loopback-only server, per-run token, at most five distinct codes sealed per run, a person confirms the heard code.
  • Bound to the label secret; if the label names a DID, a different box in the room is refused (409).
  • The passphrase is never printed, put in a URL, or sent to the browser (tested).

Verification

  • kbb -M:test -n murakumo.onboard-test (8 tests, 24 assertions, repeated with random keys) reproduces the grant golden message byte for byte and opens it; refuses wrong label secret, wrong session, wrong box, tampered ciphertext and tag.
  • kbb -M:test -n murakumo.wifi-share-test: 4 tests, 13 assertions.
  • node test/wifi_share_test.mjs (added to CI): runs the packaged CLI, then opens its output with an independent node:crypto implementation. Existing node test/node_cli_distribution_test.mjs still passes.
  • The release build is reproducible here (same hash before and after).

Found while building this

Generating real X25519 keys in these tests exposed a bug in grant#6 (base64url last-character check reversed; about three in four real keys refused). Fixed there (kotoba-lang/grant@46406645) and this PR pins that commit.

Not verified / not in this PR

  • No audio run on this PR's code: nothing here has been heard through a speaker or microphone. The acoustic channel was only exercised in the earlier browser prototype.
  • Windows and Linux passphrase/SSID paths are written but only the macOS path and --passphrase-stdin were run, and the macOS keychain read was not executed by me.
  • Box side is not here: murakumo node onboard, the beacon sender, applying the profile, and the NixOS unit are the next PR.
  • Adds the ggwave 0.4.0 npm dependency (MIT) to the packaged runtime, so release/package*.json, release/node.mjs and install.sh hashes change; the installer pin (cloud-murakumo-installer) needs regenerating when this ships.
  • Nothing is promised publicly until the ADR-0243 acceptance run passes on real hardware.

🤖 Generated with Claude Code

…-0243, sender half)

Adds murakumo.onboard (seal/open over node:crypto, rules from grant.acoustic-onboard),
murakumo.wifi-share and its localhost page, and the `murakumo node wifi-share`
command. The passphrase is read from the OS into the helper process, sealed
there, and never printed or sent to the browser; the envelope is bound to the
box's label secret; a person confirms the heard code before anything is sealed.

Pins grant to the acoustic-onboard branch commit, adds ggwave 0.4.0 to the
packaged runtime, rebuilds release/node.mjs and the installer hashes, and adds
unit tests (golden vector from grant) and a packaged-CLI integration test run in CI.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
com-junkawasaki and others added 2 commits October 2, 2026 11:14
The site's cljk-mirror refuses a .cljk file with no entry in its repo's cljk-origin.edn
(the Worker build of murakumo.cloud mirrors this repo), so these files must be recorded
or merging would stop that build. They are node-side (js interop), so .cljs.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@com-junkawasaki
com-junkawasaki changed the base branch from feat/device-claim-responder to main October 2, 2026 06:16
@com-junkawasaki
com-junkawasaki marked this pull request as ready for review October 2, 2026 06:16
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@com-junkawasaki
com-junkawasaki merged commit 8313c94 into main Oct 2, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant