feat(peer)!: cut over to authenticated catalog sharing
Replace address-only trust and pushed peer state with installation identities, SPKI-pinned QUIC, candidate-only discovery, and bounded responder-owned protocol-8 pulls. The runtime now owns each network generation and all admitted work through shutdown. Add exact bundled content identities, reproducible manifest publishing, capability-confined downloads, streaming BLAKE3 verification, quarantine and retry, and crash-recoverable download and install transactions. Ship generated fixture catalogs and fail closed when production manifests are absent. The Tauri backend exposes durable sharing policy, redacted identity state, and attempt-keyed transfer snapshots. Frontend consumption follows in the next commit. Repository-wide test certificates and protocol-7 paths are removed. BREAKING CHANGE: peers must use protocol 8 and exact catalog content artifacts; protocol-7 frames and shared-certificate identities are no longer accepted. Test Plan: - `just test` -- passed on the completed stack (708 workspace tests) - `just clippy` -- passed on the completed stack - `just build` -- passed with fixture catalogs on the completed stack - `just catalog-check-production` -- failed closed because the external production manifest corpus is absent - `git diff --cached --check` -- passed
This commit is contained in:
128 files changed
+51759
-10784
No files matched your search
@@ -0,0 +1,51 @@
|
||||
//! Trusted catalog content manifests.
|
||||
//!
|
||||
//! Manifest JSON is a reproducible transport for catalog-publisher output. The
|
||||
//! content identity is derived from the versioned binary transcript in
|
||||
//! [`encoding`], never from JSON formatting. Sealed manifests deliberately do
|
||||
//! not implement [`serde::Deserialize`]; untrusted bytes must pass through the
|
||||
//! bounded canonical loader [`CatalogContentManifest::from_json_slice`].
|
||||
|
||||
#![allow(clippy::missing_errors_doc)]
|
||||
|
||||
mod bundle;
|
||||
mod digest;
|
||||
mod encoding;
|
||||
mod index;
|
||||
mod model;
|
||||
mod path;
|
||||
mod store;
|
||||
|
||||
pub use bundle::CatalogBundle;
|
||||
pub use digest::{Blake3Digest, ContentId};
|
||||
pub use index::{
|
||||
CATALOG_CONTENT_INDEX_NAME,
|
||||
CATALOG_CONTENT_INDEX_SCHEMA_VERSION,
|
||||
CatalogContentIdentity,
|
||||
CatalogContentIndex,
|
||||
CatalogContentIndexEntry,
|
||||
MAX_CATALOG_CONTENT_INDEX_BYTES,
|
||||
};
|
||||
pub use model::{
|
||||
CATALOG_CHUNK_SIZE,
|
||||
CATALOG_CONTENT_MANIFEST_SCHEMA_VERSION,
|
||||
CatalogContentManifest,
|
||||
CatalogContentManifestBody,
|
||||
CatalogEntryKind,
|
||||
CatalogExtractedEntry,
|
||||
CatalogFileEntry,
|
||||
MAX_CATALOG_COMPONENT_BYTES,
|
||||
MAX_CATALOG_ENTRIES,
|
||||
MAX_CATALOG_FILE_BYTES,
|
||||
MAX_CATALOG_MANIFEST_BYTES,
|
||||
MAX_CATALOG_PATH_BYTES,
|
||||
MAX_CATALOG_TOTAL_BYTES,
|
||||
};
|
||||
pub use path::CanonicalCatalogPath;
|
||||
pub use store::{
|
||||
CATALOG_PUBLICATION_MARKER_NAME,
|
||||
CatalogManifestStore,
|
||||
reject_incomplete_catalog_publication,
|
||||
write_canonical_content_index_atomic,
|
||||
write_canonical_manifest_atomic,
|
||||
};
|
||||
Reference in new issue
Block a user