Skip to content

Add the Windows 7 compatibility probe (S0-01) - #2

Open
malinkin-s wants to merge 3 commits into
mainfrom
claude/s0-01-probe-2026-10-03-0551
Open

malinkin-s wants to merge 3 commits into
mainfrom
claude/s0-01-probe-2026-10-03-0551

Conversation

@malinkin-s

Copy link
Copy Markdown
Owner

Task S0-01, the gate before any server work: a client built like the real one — Python 3.8.10 32-bit, PyInstaller, standard library only — must prove on a Windows 7 shop-floor PC that it can do what the architecture relies on.

What is in tools/probe/

File Purpose
probe_server.py HTTPS test server (stdlib): JSON endpoint and an SSE stream that drops connections on purpose and resumes from Last-Event-ID
make_cert.py Self-signed certificate and its SHA-256 fingerprint
probe_client.py The checks, stdlib only, Python 3.8: tls_pinned, tls_pin_rejects, sse, dpapi_user, dpapi_machine; writes probe-report.txt
probe.spec PyInstaller build (pinned to 5.13.2)
test_probe.py Every check against a local server
README.md How to run it on the target and what a failure means

CI — .github/workflows/probe.yml

  • Tests on Windows / Python 3.8 x86 (DPAPI runs here), Linux / 3.8, Linux / 3.13.
  • Builds nestrack-probe.exe on Windows / Python 3.8 x86, runs it against a local server, uploads it as the nestrack-probe-win32 artifact.

Verified locally

  • Tests: 7 passed, 2 skipped (DPAPI, Linux) on Python 3.8 and 3.11.
  • End to end with a real server process and probe.ini: TLS 1.3 with pinning, a wrong certificate refused, 15 SSE events over 2 forced reconnects with no gaps.

Not done here

The actual run on a Windows 7 32-bit PC — that needs the hardware. S0-01 stays in progress until its report is recorded in docs/FINDINGS.md. Running the .exe in CI proves only that it works on the CI's Windows Server.

🤖 Generated with Claude Code

https://claude.ai/code/session_01CW3WfPRekjK4x6M8VNRckz


Generated by Claude Code

malinkin-s and others added 3 commits October 3, 2026 05:54
Before any server work, a client built like the real one must prove on a
Windows 7 32-bit PC that it can do what the architecture relies on.

tools/probe/:
- probe_server.py: HTTPS test server (stdlib) with a JSON endpoint and an
  SSE stream that can drop connections on purpose and resumes from
  Last-Event-ID.
- make_cert.py: self-signed certificate and its SHA-256 fingerprint.
- probe_client.py: stdlib-only, Python 3.8 checks — TLS 1.2+ with the
  certificate pinned by fingerprint, refusal of any other certificate,
  SSE reading with reconnects and no gaps, DPAPI round-trips in user and
  machine scope. Writes probe-report.txt next to the program.
- probe.spec: PyInstaller build, pinned to PyInstaller 5.13.2.
- test_probe.py: every check against a local server.

CI (.github/workflows/probe.yml): tests on Windows/Python 3.8 x86 (with
DPAPI), Linux/3.8 and Linux/3.13; builds nestrack-probe.exe on
Windows/Python 3.8 x86, runs it against a local server and uploads it as
an artifact for the run on the real target.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CW3WfPRekjK4x6M8VNRckz
The build job's openssl call failed because Git Bash turned "/CN=..." into
"C:/Program Files/Git/CN=...". The .exe itself had built fine.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CW3WfPRekjK4x6M8VNRckz
The frozen probe passes all checks on the CI's Windows; Windows 7 itself
is still to be checked. The bundled OpenSSL is 1.1.1k from 2021.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CW3WfPRekjK4x6M8VNRckz
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant