feat(peer)!: cut over to authenticated catalog sharing

Replace address-only trust and pushed peer state with installation identities,
SPKI-pinned QUIC, candidate-only discovery, and bounded responder-owned
protocol-8 pulls. The runtime now owns each network generation and all admitted
work through shutdown.

Add exact bundled content identities, reproducible manifest publishing,
capability-confined downloads, streaming BLAKE3 verification, quarantine and
retry, and crash-recoverable download and install transactions. Ship generated
fixture catalogs and fail closed when production manifests are absent.

The Tauri backend exposes durable sharing policy, redacted identity state, and
attempt-keyed transfer snapshots. Frontend consumption follows in the next
commit. Repository-wide test certificates and protocol-7 paths are removed.

BREAKING CHANGE: peers must use protocol 8 and exact catalog content artifacts;
protocol-7 frames and shared-certificate identities are no longer accepted.

Test Plan:
- `just test` -- passed on the completed stack (708 workspace tests)
- `just clippy` -- passed on the completed stack
- `just build` -- passed with fixture catalogs on the completed stack
- `just catalog-check-production` -- failed closed because the external
  production manifest corpus is absent
- `git diff --cached --check` -- passed
This commit is contained in:
ddidderr committed 2026-08-10 13:59:18 +02:00
1 parent 36c4785775
commit 60fd7ba0c2
128 files changed
+51759 -10784

No files matched your search

@@ -0,0 +1,51 @@
//! Trusted catalog content manifests.
//!
//! Manifest JSON is a reproducible transport for catalog-publisher output. The
//! content identity is derived from the versioned binary transcript in
//! [`encoding`], never from JSON formatting. Sealed manifests deliberately do
//! not implement [`serde::Deserialize`]; untrusted bytes must pass through the
//! bounded canonical loader [`CatalogContentManifest::from_json_slice`].
#![allow(clippy::missing_errors_doc)]
mod bundle;
mod digest;
mod encoding;
mod index;
mod model;
mod path;
mod store;
pub use bundle::CatalogBundle;
pub use digest::{Blake3Digest, ContentId};
pub use index::{
CATALOG_CONTENT_INDEX_NAME,
CATALOG_CONTENT_INDEX_SCHEMA_VERSION,
CatalogContentIdentity,
CatalogContentIndex,
CatalogContentIndexEntry,
MAX_CATALOG_CONTENT_INDEX_BYTES,
};
pub use model::{
CATALOG_CHUNK_SIZE,
CATALOG_CONTENT_MANIFEST_SCHEMA_VERSION,
CatalogContentManifest,
CatalogContentManifestBody,
CatalogEntryKind,
CatalogExtractedEntry,
CatalogFileEntry,
MAX_CATALOG_COMPONENT_BYTES,
MAX_CATALOG_ENTRIES,
MAX_CATALOG_FILE_BYTES,
MAX_CATALOG_MANIFEST_BYTES,
MAX_CATALOG_PATH_BYTES,
MAX_CATALOG_TOTAL_BYTES,
};
pub use path::CanonicalCatalogPath;
pub use store::{
CATALOG_PUBLICATION_MARKER_NAME,
CatalogManifestStore,
reject_incomplete_catalog_publication,
write_canonical_content_index_atomic,
write_canonical_manifest_atomic,
};