Skip to content

feat(open): freenet: handler support, shared vector test, uninstall.sh sync - #186

Merged
sanity merged 2 commits into
mainfrom
feat/freenet-scheme-followup
Sep 28, 2026
Merged

sanity merged 2 commits into
mainfrom
feat/freenet-scheme-followup

Conversation

@sanity

@sanity sanity commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Problem

freenet/freenet-core#5753 (merged as 5bc43553) ships the freenet:// scheme handler (freenet/freenet-core#5726). Three things on the site need to follow:

  1. The /open button form. The button emits freenet://<id>, which puts the case-sensitive contract id in the URL's host position. Some desktops lowercase hosts before the handler sees them (Qt's QUrl, under KDE). About a quarter of lowercased ids still decode to a valid but different id. The handler refuses those, so those users just get an "invalid link" page.
  2. The two validators can drift. The page's validation and the handler's are meant to be identical, but nothing enforces that on this side.
  3. static/uninstall.sh is stale. It doesn't remove the new handler registration, and it was already out of sync with freenet-core (it's missing the macOS Launch-at-Login agent removal).

Approach

  • Button form. "Open in Freenet" now links to the authority-less freenet:<id><rest>, which has no host to lowercase. The handler accepts both forms, so links already out there keep working. The button stays secondary until a release carrying the handler has reached peers; the notes in the markup and in the Share Links page say when to swap it.
  • Drift check. hugo-site/tests/open-link-vectors.test.mjs runs the page's actual <script>, with a stub DOM, over share-link-vectors.json. The freenet-core handler's tests use the same vectors. The new workflow runs it on change, on push to main, and daily, and fails if the copy here differs from freenet-core main.
  • Uninstall script. static/uninstall.sh is now byte-identical to freenet-core main.
  • Left out on purpose: static/install.sh. It is also behind freenet-core: fix: restore SELinux file context after installing binaries, create user level service if using user level binary. freenet-core#4958, the SELinux fix, was never mirrored. Nothing in this change needs it, and it is a separate installer change that deserves its own review, so it isn't synced here.

Testing

  • node hugo-site/tests/open-link-vectors.test.mjs: 57 vectors, 0 failures. Both mutations make it fail:
    • reverting the button to freenet:// gives 20 failures;
    • dropping the dot-segment check gives 9 failures.
  • The vector file is freenet-core main's copy, unchanged.
  • static/uninstall.sh is identical to freenet-core main. Its behaviour is tested in freenet-core by scripts/test-uninstall-sh.sh, including the new handler cases.

Refs freenet/freenet-core#5726

[AI-assisted - Claude]

https://claude.ai/code/session_013fuenPkF3T7ZkeypDFSRmx

…h sync

freenet-core#5753 (merged 5bc43553) ships the freenet:// scheme handler
(#5726). Follow-ups on the site:

- /open's "Open in Freenet" button now emits the authority-less
  freenet:<id><rest>. In freenet://<id> the case-sensitive contract id is
  the URL host, which some desktops (Qt/KDE) lowercase before the handler
  sees it; the handler accepts both forms. The button stays secondary until
  a release carrying the handler has reached peers.
- A CI check runs the page's own validation JS over the share-link vectors
  the freenet-core handler is also tested against (a copy, drift-checked
  daily and on change against freenet-core main), so the two sides cannot
  diverge silently.
- Sync static/uninstall.sh with freenet-core main: removes the freenet://
  handler's desktop entry and association (only Freenet's own), and brings
  in the macOS Launch-at-Login agent removal the mirror was missing.
- Share Links manual page updated.

Claude-Session: https://claude.ai/code/session_013fuenPkF3T7ZkeypDFSRmx
Review of #186: the vector test checked the local and freenet: buttons but
not try.freenet.org (a mutation pointing it elsewhere stayed green; now 20
failures). Two comments still described the freenet:// handler as future.

Claude-Session: https://claude.ai/code/session_013fuenPkF3T7ZkeypDFSRmx

@sanity sanity left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review: #186 (tier: Full, since it touches deploy/CI and an installer mirror)

Lenses: combined security + test-harness + deploy (Opus), big-picture, and Gemini. Gemini reported no findings. There were no Must findings.

  • The test didn't check the try.freenet.org button (security lens). Fixed in 173ba06e: pointing that button elsewhere now fails 20 vectors.
  • Stale "future handler" comments (both lenses). Fixed.
  • Nothing tracks swapping the button back to primary after the release (big-picture). Filed #188.
  • static/install.sh is behind core (security lens; this predates the PR). Filed #187. It stays out of this PR on purpose, as an installer change that needs its own review.
  • Checked:
    • uninstall.sh is byte-identical to freenet-core main (cmp).
    • The freenet: prefix is a fixed literal, so no fragment can change the scheme.
    • The harness genuinely executes the page's script. Mutations fail it: reverting to freenet:// gives 20 failures, and removing any single validation rule gives 1-9.

[AI-assisted - Claude]

@sanity
sanity merged commit ad54d61 into main Sep 28, 2026
4 checks passed
@sanity
sanity deleted the feat/freenet-scheme-followup branch September 28, 2026 00:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant