Skip to content

Adopt hzrd149 napplelets as a signed interoperability and design-practice corpus #21

Description

@jodobear

Parent: #9

User-provided upstream: https://github.com/hzrd149/napplelets/

Context

Uzel relies heavily on Good Morning as its positive-path napplet fixture. That leaves independent-producer interoperability, zero-capability rendering, storage/configuration, subscription cleanup, resizing, and wider domain behavior under-tested.

hzrd149/napplelets is also a strong design reference: runtime-owned injection, OUTBOX-first social access, explicit relay-local exceptions, lifecycle-bound subscriptions/object URLs, shell-owned storage/config/resources, strict single-file builds, and refusal to invent app-local NAP wire domains.

This corpus is interoperability evidence and design reference—not Uzel's protocol authority. NAP behavior remains governed by napplet/naps; Nostr data behavior remains NMP-owned.

Exact audit baseline

  • Source: hzrd149/napplelets@aa4dc7a0799d95e3066b50055b29685d6e376045 (2026-07-26)
  • License: MIT; attribution required for copied source
  • Eight source napplets; pnpm/Turbo monorepo; local build/unit/type/conformance scripts; no GitHub Actions workflows
  • Locked package resolution: @napplet/core/@napplet/nap 0.28.0, SDK 0.24.4, conformance CLI 0.2.15, Kehto CLI 0.2.16
  • Published kind-35129 author: 266815e0c9210dfa324c6cba3573b14bee49da4209a9456f9484e5106cd408a5
  • Live events signature-verified with pinned nak; Ditto, Primal, and nos.lol answered; Damus returned HTTP 503 during the probe
  • All eight audited artifacts fetched from cdn.hzrd149.com; every byte SHA-256 matched its signed path tag
  • Source commit and audited publication are only temporally associated. There is no source-commit attestation or independently proven reproducible source-to-artifact link.

A kind-35129 naddr is a replaceable coordinate. Deterministic tests must freeze the resolved event ID, author, d, required domains, path hash, aggregate hash, and artifact bytes—not trust the coordinate, title, relay hint, or HTTPS host alone.

Initial layered corpus

Napplet Purpose Boundary
Good Morning Existing identity/OUTBOX/resource/link/theme control Keep as overlap/control
Rubik Cube Zero-grant iframe, resize, input, WebGL stress Safest new positive case; large artifact
Nap Feed Read-only config plus query/subscription lifecycle Requires working config provider; useful/empty/explicit-error accepted
WiFi Map Storage, OUTBOX subscription, resize, link boundary Never automate outbound-link click

Defer Nostr Bubbles until relay-local ownership is explicit. Exclude Comic Upload and Article Highlights from automated tests because they expose upload/publication flows. dsui-gm-proto mostly duplicates Good Morning.

Recommended coordinates:

  • Good Morning: naddr1qqxxwmm0vskk6mmjde5kuecpzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhgq3qye5ptcxfyyxl5vjvdjar2ua3f0hynkjzpx552mu5snj3qmx5pzjsxpqqqzynjsul3vr
  • Rubik Cube: naddr1qq98yatzd94j6cm4vfjsz9nhwden5te0wfjkccte9ec8y6tdv9kzumn9wspzqfngzhsvjggdlgeycm96x4emzjlwf8dyyzdfg4hefp89zpkdgz99qvzqqqyf8y9pvhkw
  • Nap Feed: naddr1qqyxucts94nx2etyqyt8wumn8ghj7un9d3shjtnswf5k6ctv9ehx2aqzyqnxs90qeyssm73jf3kt5dtnk997ujw6ggy6j3t0jjzw2yrv6sy22qcyqqqgjwglxcuwy
  • WiFi Map: naddr1qqy8w6txdykk6ctsqyt8wumn8ghj7un9d3shjtnswf5k6ctv9ehx2aqzyqnxs90qeyssm73jf3kt5dtnk997ujw6ggy6j3t0jjzw2yrv6sy22qcyqqqgjwggda37g

Relay hints are discovery hints only and do not change coordinate identity.

Required work

  • Add a data-only external-corpus lock/registry.
  • Resolve and fetch through production napd/NMP ownership; no renderer relay access.
  • Verify signature, kind, author, d, path SHA-256, aggregate hash, exact bytes, and declared capabilities before review/install.
  • Reject event/artifact drift until an explicit refresh PR revalidates it.
  • Launch only through Uzel's strict-CSP opaque-origin iframe path.
  • Exercise each fixture without upload, signing, publishing, or outbound navigation.
  • Cover review, confirmation, NAP-SHELL, focus/input, narrow/short resizing, screenshot, cleanup, restart reconciliation, direct-network denial, and native-bridge isolation.
  • Preserve append-only ignored success/failure evidence.
  • Keep live corpus tests separate from deterministic mocked renderer acceptance and Uzel-owned fixtures.
  • Adopt useful practices only through separate focused PRs; no wholesale framework/theme import.

Acceptance

  • Good Morning remains green.
  • Rubik Cube launches with zero grants and no native/network capability.
  • Nap Feed reaches a useful loaded, empty, or explicit-error state and closes subscriptions.
  • WiFi Map proves storage/subscription lifecycle without opening external links.
  • At least one case contributes real rendered-image/resource evidence after Verify profile pictures through NAP-RESOURCE to rendered WebKit pixels #17.
  • All four tolerate narrow and short frame sizes without shell layout failure.
  • Hostile direct-network and native-bridge sentinels remain zero.
  • Any resolved-event or hash drift fails closed with actionable diagnostics.
  • All surfaces, subscriptions, object URLs, and harness processes are cleaned.
  • No signer secret/private relay credential enters logs or Git.

Non-goals

  • No bundled app store or automatic arbitrary publisher execution.
  • No Kehto/Paja product dependency.
  • No floating dependency ranges; Uzel retains exact pins.
  • No copying publisher signer/keychain design.
  • No source-to-binary reproducibility claim until independently proven.
  • MIT repo license does not automatically settle every embedded third-party asset.

Dependencies

This does not block #19 and must not be implemented inside another issue branch.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions