cloud: encrypted owner catalog and source-off OpenCloud SDK reads - #3
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Functional slice
Explicit encrypted owner catalog, authenticated read-only loopback DAV listing/full/range/conditional reads, and a foreground read service connected to the shared core's actual fragment restore adapter. No source fallback, new scheduler, replica setting or account/sharing authority. Restore/decrypt/verify precedes private response and temporary-file disposal.
Verification
12 actual-GPG catalog tests; 12 real HTTP boundary/lifecycle tests; 5 CLI/lifecycle tests; 2 actual pinned OpenCloud Web8 SDK tests, one joining genuine import, encrypted catalog, read service and SDK with source off and local ciphertext removed. The joined local test explicitly substitutes ONLY the core storage adapter and is not protected-peer proof. Syntax and whitespace passed. SDK staging is explicit, exact-integrity verified, all109 original package files/notices retained, no npm install or package scripts; no source-build claim for the published SDK.
The earlier actual protected-peer run36909989038 passed on Cloud541cc826/core41e404 with8 encrypted copies, provider loss, two restores and full cleanup. That predates this catalog/read-service commit and does not prove the new joined path. The subsequent source-bound SDK proof PASSES: core run36916040042 on5d9d347fc52e4cc13498ed3b6790d1f00de370c3 with Clouda67b91fbed42ecd23ba215eb21ef54397fc9f06a. Exact-source replay of44 original artifacts reproduces the aggregate. Source and local ciphertext absent, A offline, four B/C reconstructions including actual SDK full/range reads;32 protected MPTCP/TLS exchanges; retained charges; all-copy deletion; private cleanup and unchanged host state. The current Cloud head changes only documentation to record this evidence. Original ZIP SHA256 f59a2c2baf693b5087c0827c0971589da23bf15610f96c885db6f2bbe0abdaef.
Remaining full goal
OIDC/accounts, LibreGraph, sharing/revocation, writable synchronization, full OpenCloud UI, peer catalog distribution and second-device key/journal recovery remain open. This is an executable source-off owner-read slice, not completed server-independent OpenCloud or alpha.