Files
echolot/echolot-app
mrambossekandClaude Opus 5 e0428b4c84 server: enroll against fmr.echo-lot.app; mint links from the CLI
The control plane now advertises the same name the web UI answers on.
That is safe because the client authenticates by SPKI pin and explicitly
does not verify the hostname — "pin is the trust, not the name" — so no
certificate covers or needs to cover either name.

The per-host name still means something, though, and the rule it encodes
has to survive: pinning binds a client to one server's key, so fmr may be
a CNAME to exactly one host and never a multi-address service record. A
second server gets enrolled as fmr-2 explicitly, because a client that
reaches a different key does not fail over, it fails.

Minting a link was broken and had been since the authenticated admin UI
replaced the old admin API: enroll-link.sh still posted to
127.0.0.1:8444/admin/enroll-tokens, an endpoint that no longer exists on
a listener that no longer binds loopback. Rather than add a second
unauthenticated door — which is how the old one ended up briefly reachable
from the network — the binary mints its own link. Whoever can run it
against the state directory already holds every privilege the server has,
so authenticating them to themselves would be theatre.

EnrollmentURI is shared with the running server's EnrollmentLink rather
than reimplemented. Two copies of that encoding would eventually disagree,
and the failure mode is a pin that looks right and surfaces as an
inscrutable TLS error rather than as a bad pin.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-01 23:16:23 +02:00
..

Echolot app

The production Android client (spec). Native Kotlin + Jetpack Compose. Multi-module; built bottom-up from a verifiable protocol spine.

Modules

Module Type Status
core-protocol pure Kotlin/JVM done — client half of probe-protocol.md, verified live against the server
core-measurement pure Kotlin/JVM planned — measurement-schema.md types
core-probe Android lib planned — app-tier probes, ported from echolot-prober
core-shizuku Android lib planned — dual-path executor (UserService + newProcess fallback)
app Android app planned — Compose UI

core-protocol is deliberately Android-free so it builds and unit-tests on any JDK (no Android SDK) and can run integration tests against a live server.

core-protocol

Implements the control plane (SPKI-pinned enrollment/profile/sessions via HttpsURLConnection — Android-API-1 compatible, hostname verification off because trust is the pin), the HKDF-SHA256 session-key schedule, and the binary ELT1 UDP data plane (HMAC gate, ECHO + observation block, MTU probe) — byte-compatible with the Go server.

./gradlew :core-protocol:test              # unit tests (crypto vectors, wire round-trip)
scripts/test-fmr.sh                         # live end-to-end test against the deployed server

test-fmr.sh mints an enrollment token over SSH, enrolls via the public control plane, computes the SPKI pin from the served cert, and runs LiveServerTest — proving the client speaks the wire protocol to the real server (enroll → profile → session → echo+observation → MTU → observations). The live test self-skips when ECHOLOT_LIVE_* env vars are absent, so unit runs and CI stay green offline.