Commit Graph
5 Commits
Author SHA1 Message Date
ddidderr 60fd7ba0c2 feat(peer)!: cut over to authenticated catalog sharing
Replace address-only trust and pushed peer state with installation identities,
SPKI-pinned QUIC, candidate-only discovery, and bounded responder-owned
protocol-8 pulls. The runtime now owns each network generation and all admitted
work through shutdown.

Add exact bundled content identities, reproducible manifest publishing,
capability-confined downloads, streaming BLAKE3 verification, quarantine and
retry, and crash-recoverable download and install transactions. Ship generated
fixture catalogs and fail closed when production manifests are absent.

The Tauri backend exposes durable sharing policy, redacted identity state, and
attempt-keyed transfer snapshots. Frontend consumption follows in the next
commit. Repository-wide test certificates and protocol-7 paths are removed.

BREAKING CHANGE: peers must use protocol 8 and exact catalog content artifacts;
protocol-7 frames and shared-certificate identities are no longer accepted.

Test Plan:
- `just test` -- passed on the completed stack (708 workspace tests)
- `just clippy` -- passed on the completed stack
- `just build` -- passed with fixture catalogs on the completed stack
- `just catalog-check-production` -- failed closed because the external
  production manifest corpus is absent
- `git diff --cached --check` -- passed
2026-08-10 13:59:18 +02:00
ddidderr 642463d7eb certs fixed 2026-05-18 16:19:27 +02:00
ddidderr 84f533aeee fix(peer): renew expired QUIC dev certificate
Manual peer CLI runs could discover peer advertisements, but QUIC handshakes did
not complete. The checked-in self-signed certificate expired on March 2, 2026,
so peers running on May 17, 2026 could start listening but could not establish
valid TLS sessions with each other.

Regenerate cert.pem from the existing key.pem, preserving the existing subject
and DNS:localhost SAN. The renewed development certificate is valid until April
23, 2126 and still matches key.pem.

Test Plan:
- openssl x509 -in cert.pem -noout -subject -issuer -dates -ext subjectAltName
- openssl x509 -noout -modulus -in cert.pem | openssl sha256
- openssl rsa -noout -modulus -in key.pem | openssl sha256
- just peer-cli-image
- just peer-cli-alpha, just peer-cli-bravo, just peer-cli-charlie

Refs: PEER_CLI_SCENARIOS.md
2026-05-17 09:34:00 +02:00
ddidderr 0b381ee198 [certs] update certificates 2025-03-02 14:41:08 +01:00
ddidderr 70e3aaea17 lanspread: Game Distribution on LAN parties (WIP) 2024-09-29 16:16:58 +02:00