feat(peer)!: cut over to authenticated catalog sharing

Replace address-only trust and pushed peer state with installation identities,
SPKI-pinned QUIC, candidate-only discovery, and bounded responder-owned
protocol-8 pulls. The runtime now owns each network generation and all admitted
work through shutdown.

Add exact bundled content identities, reproducible manifest publishing,
capability-confined downloads, streaming BLAKE3 verification, quarantine and
retry, and crash-recoverable download and install transactions. Ship generated
fixture catalogs and fail closed when production manifests are absent.

The Tauri backend exposes durable sharing policy, redacted identity state, and
attempt-keyed transfer snapshots. Frontend consumption follows in the next
commit. Repository-wide test certificates and protocol-7 paths are removed.

BREAKING CHANGE: peers must use protocol 8 and exact catalog content artifacts;
protocol-7 frames and shared-certificate identities are no longer accepted.

Test Plan:
- `just test` -- passed on the completed stack (708 workspace tests)
- `just clippy` -- passed on the completed stack
- `just build` -- passed with fixture catalogs on the completed stack
- `just catalog-check-production` -- failed closed because the external
  production manifest corpus is absent
- `git diff --cached --check` -- passed
This commit is contained in:
ddidderr committed 2026-08-10 13:59:18 +02:00
1 parent 36c4785775
commit 60fd7ba0c2
128 files changed
+51759 -10784

No files matched your search

-12
View File
@@ -20,18 +20,6 @@ pub(crate) fn portable_name_key(name: &str) -> String {
name.to_uppercase()
}
/// Matches the committed install directory according to the host filesystem.
#[cfg(target_os = "windows")]
pub(crate) fn is_local_dir_name(name: &str) -> bool {
name.eq_ignore_ascii_case(LOCAL_DIR)
}
/// Matches the committed install directory according to the host filesystem.
#[cfg(not(target_os = "windows"))]
pub(crate) fn is_local_dir_name(name: &str) -> bool {
name == LOCAL_DIR
}
/// Returns whether a top-level entry belongs to install, recovery, or legacy state.
///
/// This deliberately uses a conservative platform-independent comparison because