feat(peer)!: cut over to authenticated catalog sharing

Replace address-only trust and pushed peer state with installation identities,
SPKI-pinned QUIC, candidate-only discovery, and bounded responder-owned
protocol-8 pulls. The runtime now owns each network generation and all admitted
work through shutdown.

Add exact bundled content identities, reproducible manifest publishing,
capability-confined downloads, streaming BLAKE3 verification, quarantine and
retry, and crash-recoverable download and install transactions. Ship generated
fixture catalogs and fail closed when production manifests are absent.

The Tauri backend exposes durable sharing policy, redacted identity state, and
attempt-keyed transfer snapshots. Frontend consumption follows in the next
commit. Repository-wide test certificates and protocol-7 paths are removed.

BREAKING CHANGE: peers must use protocol 8 and exact catalog content artifacts;
protocol-7 frames and shared-certificate identities are no longer accepted.

Test Plan:
- `just test` -- passed on the completed stack (708 workspace tests)
- `just clippy` -- passed on the completed stack
- `just build` -- passed with fixture catalogs on the completed stack
- `just catalog-check-production` -- failed closed because the external
  production manifest corpus is absent
- `git diff --cached --check` -- passed
This commit is contained in:
ddidderr committed 2026-08-10 13:59:18 +02:00
1 parent 36c4785775
commit 60fd7ba0c2
128 files changed
+51759 -10784

No files matched your search

+54 -1
View File
@@ -1,9 +1,20 @@
use std::{
path::{Path, PathBuf},
sync::atomic::{AtomicU64, Ordering},
sync::{
Arc,
atomic::{AtomicU64, Ordering},
},
time::{SystemTime, UNIX_EPOCH},
};
use lanspread_db::content_manifest::{
Blake3Digest,
CatalogBundle,
CatalogContentManifest,
CatalogContentManifestBody,
CatalogFileEntry,
};
static NEXT_TEMP_ID: AtomicU64 = AtomicU64::new(0);
pub(crate) struct TempDir(PathBuf);
@@ -39,3 +50,45 @@ impl Drop for TempDir {
let _ = std::fs::remove_dir_all(&self.0);
}
}
pub(crate) fn empty_catalog_bundle() -> Arc<CatalogBundle> {
catalog_bundle(std::iter::empty::<(String, String)>())
}
pub(crate) fn catalog_bundle<I, G, V>(entries: I) -> Arc<CatalogBundle>
where
I: IntoIterator<Item = (G, V)>,
G: Into<String>,
V: Into<String>,
{
let manifests = entries
.into_iter()
.map(|(game_id, game_version)| {
let game_version = game_version.into();
let version_digest = Blake3Digest::hash(game_version.as_bytes());
CatalogContentManifest::seal(
CatalogContentManifestBody::new(
game_id,
&game_version,
vec![
CatalogFileEntry::file(
"version.ini",
u64::try_from(game_version.len())
.expect("test version length should fit u64"),
version_digest,
vec![version_digest],
)
.expect("test version.ini entry should be valid"),
],
Vec::new(),
)
.expect("test catalog manifest body should be valid"),
)
.expect("test catalog manifest should seal")
})
.collect::<Vec<_>>();
Arc::new(
CatalogBundle::from_manifests(manifests)
.expect("test catalog bundle should be a complete immutable authority"),
)
}