Replace address-only trust and pushed peer state with installation identities, SPKI-pinned QUIC, candidate-only discovery, and bounded responder-owned protocol-8 pulls. The runtime now owns each network generation and all admitted work through shutdown. Add exact bundled content identities, reproducible manifest publishing, capability-confined downloads, streaming BLAKE3 verification, quarantine and retry, and crash-recoverable download and install transactions. Ship generated fixture catalogs and fail closed when production manifests are absent. The Tauri backend exposes durable sharing policy, redacted identity state, and attempt-keyed transfer snapshots. Frontend consumption follows in the next commit. Repository-wide test certificates and protocol-7 paths are removed. BREAKING CHANGE: peers must use protocol 8 and exact catalog content artifacts; protocol-7 frames and shared-certificate identities are no longer accepted. Test Plan: - `just test` -- passed on the completed stack (708 workspace tests) - `just clippy` -- passed on the completed stack - `just build` -- passed with fixture catalogs on the completed stack - `just catalog-check-production` -- failed closed because the external production manifest corpus is absent - `git diff --cached --check` -- passed
81 lines
3.0 KiB
Rust
81 lines
3.0 KiB
Rust
//! Shared names and ownership policy for entries below a game root.
|
||
|
||
pub(crate) const LOCAL_DIR: &str = "local";
|
||
pub(crate) const INSTALLING_DIR: &str = ".local.installing";
|
||
pub(crate) const BACKUP_DIR: &str = ".local.backup";
|
||
pub(crate) const INSTALL_OWNED_MARKER: &str = ".lanspread_owned";
|
||
pub(crate) const VERSION_INI: &str = "version.ini";
|
||
pub(crate) const VERSION_TMP_FILE: &str = ".version.ini.tmp";
|
||
pub(crate) const VERSION_DISCARDED_FILE: &str = ".version.ini.discarded";
|
||
pub(crate) const LEGACY_LIBRARY_INDEX_DIR: &str = ".lanspread";
|
||
pub(crate) const LEGACY_INTENT_FILE: &str = ".lanspread.json";
|
||
pub(crate) const LEGACY_INTENT_TMP_FILE: &str = ".lanspread.json.tmp";
|
||
pub(crate) const LEGACY_FIRST_START_DONE_FILE: &str = ".softlan_first_start_done";
|
||
pub(crate) const LEGACY_SOFTLAN_INSTALL_MARKER: &str = ".softlan_game_installed";
|
||
pub(crate) const INSTALL_INTENT_FILE: &str = "install_intent.json";
|
||
pub(crate) const INSTALL_INTENT_TMP_FILE: &str = "install_intent.json.tmp";
|
||
|
||
/// Returns the conservative cross-platform comparison key used for reserved names.
|
||
pub(crate) fn portable_name_key(name: &str) -> String {
|
||
name.to_uppercase()
|
||
}
|
||
|
||
/// Returns whether a top-level entry belongs to install, recovery, or legacy state.
|
||
///
|
||
/// This deliberately uses a conservative platform-independent comparison because
|
||
/// a manifest accepted on one peer may be materialized on another operating system.
|
||
pub(crate) fn is_download_protected_root_name(name: &str) -> bool {
|
||
let key = portable_name_key(name);
|
||
key == "LOCAL"
|
||
|| key.starts_with(".LOCAL.")
|
||
|| key.starts_with(".VERSION.INI.")
|
||
|| matches!(
|
||
key.as_str(),
|
||
".SYNC"
|
||
| ".LANSPREAD"
|
||
| ".LANSPREAD.JSON"
|
||
| ".LANSPREAD.JSON.TMP"
|
||
| ".LANSPREAD_OWNED"
|
||
| ".SOFTLAN_FIRST_START_DONE"
|
||
| ".SOFTLAN_GAME_INSTALLED"
|
||
| "INSTALL_INTENT.JSON"
|
||
| "INSTALL_INTENT.JSON.TMP"
|
||
)
|
||
}
|
||
|
||
/// Returns whether an entry in the configured games directory is application state.
|
||
pub(crate) fn is_ignored_games_root_name(name: &str) -> bool {
|
||
portable_name_key(name) == ".LANSPREAD"
|
||
}
|
||
|
||
#[cfg(test)]
|
||
mod tests {
|
||
use super::*;
|
||
|
||
#[test]
|
||
fn protected_policy_covers_current_and_legacy_state() {
|
||
for name in [
|
||
LOCAL_DIR,
|
||
"LOCAL",
|
||
INSTALLING_DIR,
|
||
BACKUP_DIR,
|
||
VERSION_TMP_FILE,
|
||
VERSION_DISCARDED_FILE,
|
||
".sync",
|
||
LEGACY_LIBRARY_INDEX_DIR,
|
||
LEGACY_INTENT_FILE,
|
||
LEGACY_INTENT_TMP_FILE,
|
||
INSTALL_OWNED_MARKER,
|
||
LEGACY_FIRST_START_DONE_FILE,
|
||
LEGACY_SOFTLAN_INSTALL_MARKER,
|
||
INSTALL_INTENT_FILE,
|
||
INSTALL_INTENT_TMP_FILE,
|
||
".ſync",
|
||
] {
|
||
assert!(is_download_protected_root_name(name), "missed {name}");
|
||
}
|
||
assert!(!is_download_protected_root_name(VERSION_INI));
|
||
assert!(!is_download_protected_root_name("archive.eti"));
|
||
}
|
||
}
|