Replace address-only trust and pushed peer state with installation identities, SPKI-pinned QUIC, candidate-only discovery, and bounded responder-owned protocol-8 pulls. The runtime now owns each network generation and all admitted work through shutdown. Add exact bundled content identities, reproducible manifest publishing, capability-confined downloads, streaming BLAKE3 verification, quarantine and retry, and crash-recoverable download and install transactions. Ship generated fixture catalogs and fail closed when production manifests are absent. The Tauri backend exposes durable sharing policy, redacted identity state, and attempt-keyed transfer snapshots. Frontend consumption follows in the next commit. Repository-wide test certificates and protocol-7 paths are removed. BREAKING CHANGE: peers must use protocol 8 and exact catalog content artifacts; protocol-7 frames and shared-certificate identities are no longer accepted. Test Plan: - `just test` -- passed on the completed stack (708 workspace tests) - `just clippy` -- passed on the completed stack - `just build` -- passed with fixture catalogs on the completed stack - `just catalog-check-production` -- failed closed because the external production manifest corpus is absent - `git diff --cached --check` -- passed
95 lines
2.7 KiB
Rust
95 lines
2.7 KiB
Rust
use std::{
|
|
path::{Path, PathBuf},
|
|
sync::{
|
|
Arc,
|
|
atomic::{AtomicU64, Ordering},
|
|
},
|
|
time::{SystemTime, UNIX_EPOCH},
|
|
};
|
|
|
|
use lanspread_db::content_manifest::{
|
|
Blake3Digest,
|
|
CatalogBundle,
|
|
CatalogContentManifest,
|
|
CatalogContentManifestBody,
|
|
CatalogFileEntry,
|
|
};
|
|
|
|
static NEXT_TEMP_ID: AtomicU64 = AtomicU64::new(0);
|
|
|
|
pub(crate) struct TempDir(PathBuf);
|
|
|
|
impl TempDir {
|
|
pub(crate) fn new(prefix: &str) -> Self {
|
|
let mut path = std::env::temp_dir();
|
|
let unique_id = NEXT_TEMP_ID.fetch_add(1, Ordering::Relaxed);
|
|
path.push(format!(
|
|
"{prefix}-{}-{}-{}",
|
|
std::process::id(),
|
|
unique_id,
|
|
SystemTime::now()
|
|
.duration_since(UNIX_EPOCH)
|
|
.unwrap_or_default()
|
|
.as_nanos()
|
|
));
|
|
std::fs::create_dir_all(&path).expect("temp dir should be created");
|
|
Self(path)
|
|
}
|
|
|
|
pub(crate) fn path(&self) -> &Path {
|
|
&self.0
|
|
}
|
|
|
|
pub(crate) fn game_root(&self) -> PathBuf {
|
|
self.0.join("game")
|
|
}
|
|
}
|
|
|
|
impl Drop for TempDir {
|
|
fn drop(&mut self) {
|
|
let _ = std::fs::remove_dir_all(&self.0);
|
|
}
|
|
}
|
|
|
|
pub(crate) fn empty_catalog_bundle() -> Arc<CatalogBundle> {
|
|
catalog_bundle(std::iter::empty::<(String, String)>())
|
|
}
|
|
|
|
pub(crate) fn catalog_bundle<I, G, V>(entries: I) -> Arc<CatalogBundle>
|
|
where
|
|
I: IntoIterator<Item = (G, V)>,
|
|
G: Into<String>,
|
|
V: Into<String>,
|
|
{
|
|
let manifests = entries
|
|
.into_iter()
|
|
.map(|(game_id, game_version)| {
|
|
let game_version = game_version.into();
|
|
let version_digest = Blake3Digest::hash(game_version.as_bytes());
|
|
CatalogContentManifest::seal(
|
|
CatalogContentManifestBody::new(
|
|
game_id,
|
|
&game_version,
|
|
vec![
|
|
CatalogFileEntry::file(
|
|
"version.ini",
|
|
u64::try_from(game_version.len())
|
|
.expect("test version length should fit u64"),
|
|
version_digest,
|
|
vec![version_digest],
|
|
)
|
|
.expect("test version.ini entry should be valid"),
|
|
],
|
|
Vec::new(),
|
|
)
|
|
.expect("test catalog manifest body should be valid"),
|
|
)
|
|
.expect("test catalog manifest should seal")
|
|
})
|
|
.collect::<Vec<_>>();
|
|
Arc::new(
|
|
CatalogBundle::from_manifests(manifests)
|
|
.expect("test catalog bundle should be a complete immutable authority"),
|
|
)
|
|
}
|