feat(peer)!: cut over to authenticated catalog sharing

Replace address-only trust and pushed peer state with installation identities,
SPKI-pinned QUIC, candidate-only discovery, and bounded responder-owned
protocol-8 pulls. The runtime now owns each network generation and all admitted
work through shutdown.

Add exact bundled content identities, reproducible manifest publishing,
capability-confined downloads, streaming BLAKE3 verification, quarantine and
retry, and crash-recoverable download and install transactions. Ship generated
fixture catalogs and fail closed when production manifests are absent.

The Tauri backend exposes durable sharing policy, redacted identity state, and
attempt-keyed transfer snapshots. Frontend consumption follows in the next
commit. Repository-wide test certificates and protocol-7 paths are removed.

BREAKING CHANGE: peers must use protocol 8 and exact catalog content artifacts;
protocol-7 frames and shared-certificate identities are no longer accepted.

Test Plan:
- `just test` -- passed on the completed stack (708 workspace tests)
- `just clippy` -- passed on the completed stack
- `just build` -- passed with fixture catalogs on the completed stack
- `just catalog-check-production` -- failed closed because the external
  production manifest corpus is absent
- `git diff --cached --check` -- passed
This commit is contained in:
ddidderr committed 2026-08-10 13:59:18 +02:00
1 parent 36c4785775
commit 60fd7ba0c2
128 files changed
+51759 -10784

No files matched your search

+1 -74
View File
@@ -252,46 +252,11 @@ impl GameCatalog {
}
}
#[derive(Clone, Serialize, Deserialize)]
pub struct GameFileDescription {
pub game_id: String,
pub relative_path: String,
pub is_dir: bool,
pub size: u64,
}
impl GameFileDescription {
#[must_use]
pub fn is_version_ini(&self) -> bool {
let expected = format!("{}/version.ini", self.game_id);
self.relative_path.replace('\\', "/") == expected
}
#[must_use]
pub fn file_size(&self) -> u64 {
if self.is_dir { 0 } else { self.size }
}
}
impl fmt::Debug for GameFileDescription {
#[allow(clippy::cast_precision_loss)]
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
write!(
f,
"{}: [{}] path:{} size:{}",
self.game_id,
if self.is_dir { 'D' } else { 'F' },
self.relative_path,
self.size,
)
}
}
#[cfg(test)]
mod tests {
use serde_json::json;
use super::{Availability, Game, GameFileDescription};
use super::{Availability, Game};
fn game_fixture() -> Game {
Game {
@@ -364,42 +329,4 @@ mod tests {
game.downloaded = true;
assert_eq!(game.normalized_availability(), Availability::Ready);
}
#[test]
fn version_ini_predicate_matches_only_game_root_sentinel() {
let root = GameFileDescription {
game_id: "aoe2".to_string(),
relative_path: "aoe2/version.ini".to_string(),
is_dir: false,
size: 8,
};
assert!(root.is_version_ini());
let nested = GameFileDescription {
game_id: "aoe2".to_string(),
relative_path: "aoe2/local/version.ini".to_string(),
is_dir: false,
size: 8,
};
assert!(!nested.is_version_ini());
let other_game = GameFileDescription {
game_id: "aoe2".to_string(),
relative_path: "other/version.ini".to_string(),
is_dir: false,
size: 8,
};
assert!(!other_game.is_version_ini());
}
#[test]
fn version_ini_predicate_accepts_windows_separators() {
let root = GameFileDescription {
game_id: "aoe2".to_string(),
relative_path: r"aoe2\version.ini".to_string(),
is_dir: false,
size: 8,
};
assert!(root.is_version_ini());
}
}