Skip to content

Protect Shield IP boundary and document hosted releases - #22

Draft
ResearchForumOnline wants to merge 10 commits into
mainfrom
agent/protect-zmath-ip-boundary
Draft

Protect Shield IP boundary and document hosted releases#22
ResearchForumOnline wants to merge 10 commits into
mainfrom
agent/protect-zmath-ip-boundary

Conversation

@ResearchForumOnline

@ResearchForumOnline ResearchForumOnline commented Jul 12, 2026

Copy link
Copy Markdown
Owner

What changed

  • removes premium Shield/ZMath browser source, development tests, test vectors, and implementation-level release material from the MIT community distribution
  • removes the public QPU-factor derivation implementation while retaining bounded capability descriptions
  • adds a CI disclosure gate preventing premium module paths and implementation markers from being recommitted
  • clarifies the separate AGPL/GPL corresponding-source obligation for modified Element clients
  • documents account-bound mobile recovery and the verified bot-room boundary without publishing private implementation details
  • documents the 13 July hosted reliability release covering mobile usability, private OpenZero transport, truthful reply routing, integrity checks, two-copy recovery, TURN restrictions, and commercial clarity
  • documents the 14 July hosted release covering automatic protected-room synchronization, protected-message reliability, call-audio recovery, signup, and narrow-screen usability
  • documents the task-based Help center, automatic-first Shield panel, branded app-entrypoint repair, and release gate for missing compiled assets

Why

The repository policy says premium Shield/ZMath implementation belongs outside the public community tree. The previous tree duplicated licensed browser implementation and detailed derivation material under MIT. This change restores the intended community-versus-licensed boundary while keeping customer-visible capabilities, limitations, deployment guidance, and required open-source client materials public.

The hosted notes give users and evaluators an accurate account of the two security layers, automatic protected-room setup, browser audio recovery, progressive recovery controls, and remaining device-level call check without publishing private derivation, credentials, account data, or production configuration.

Validation

  • public disclosure boundary check passed after the release-note update
  • staged sensitive-pattern and infrastructure-detail scan passed
  • hosted release manifest and version-integrity lock verified every deployed client asset
  • Help search and category filters passed functional checks
  • Help, manuals, guide, hosted app, and Shield panel passed 360, 390, 768, and 1440 pixel layout checks without page overflow or off-screen controls
  • the hosted app entrypoint loaded its branded custom bundle, command bar, and Shield control; deployment now rejects missing entry JavaScript, CSS, or initialization assets
  • signup UI and nine backend boundary tests passed, including 11, 12, 128, and 129 character password cases
  • protected-message, room-approval, file-container, QPU-factor boundary, and media-key contract checks passed against local and hosted assets
  • focused call-audio component suite passed 17/17 with type, lint, formatting, and production-build checks
  • a newly protected production message appeared exactly once as plaintext after a full reload, with no pending protection state or visible transport envelope
  • hosted bot, Matrix, call, TURN, registration, security-header, source-map exclusion, and rollback-retention checks passed

An audible two-person call remains the final device-level confirmation because browser permissions and speaker routing belong to each participant's device.

@ResearchForumOnline ResearchForumOnline changed the title Protect the public Shield IP boundary Protect Shield IP boundary and document hosted reliability Jul 13, 2026
@ResearchForumOnline ResearchForumOnline changed the title Protect Shield IP boundary and document hosted reliability Protect Shield IP boundary and document hosted releases Jul 14, 2026
@ResearchForumOnline

Copy link
Copy Markdown
Owner Author

Added the public hosted-call permission flow: microphone on join, camera only after Start video, Safari Enable sound recovery, and separate screen-sharing permission. No deployment paths, credentials, room data, or private cryptographic implementation details are included.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants