Security audit finding EXP2-SEC-06. When no explicit state directory,
`LANSPREAD_STATE_DIR`, `HOME` or `USERPROFILE` was available,
`resolve_state_dir` silently used `<temp_dir>/lanspread`. On a
multi-user machine that is a predictable, world-writable location:
another local user could pre-create it and then read or replace the
Ed25519 peer identity and the download ownership journals stored there.
Both shipping callers always provide a directory (the Tauri app passes
its app-data path, the CLI its `--state-dir`), so the fallback was only
reachable in unusual environments. Rather than derive a UID-specific
temp path, peer startup now returns an error naming the accepted
sources. This is the same fail-closed stance the codebase already takes
for a malformed sharing policy.
Test plan: `just test`. Manually, `LANSPREAD_STATE_DIR= HOME=
lanspread-peer-cli ...` without `--state-dir` must refuse to start with
a clear message; normal `just run` and `just peer-cli-run` are
unaffected.
Claude-Session: https://claude.ai/code/session_017C3Nbgwpdm3YNwZhhFLHwg