Skip to content

feat: upload owner-private files through core fragment storage - #7

Draft
erikleblansch wants to merge 2 commits into
mainfrom
feature/offline-private-upload
Draft

erikleblansch wants to merge 2 commits into
mainfrom
feature/offline-private-upload

Conversation

@erikleblansch

@erikleblansch erikleblansch commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Change

Adds an explicitly configured owner-private upload space alongside unchanged read-only imports. The original OpenCloud Files/Uppy upload action uses authenticated loopback DAV PUT; files are privately staged and encrypted using the existing GPG helper, then sent through the existing core fragment create/deposit interface. A new file becomes visible only after confirmed redundant storage and durable encrypted-catalog publication.

Core retains placement, uniform redundancy, grants and accounting. There is no second storage ledger or application-specific copy-count option. New owner files carry distinct authenticated provenance; they do not impersonate imported OpenCloud account rights.

Working boundaries

  • New files only; imported spaces remain read-only. No overwrite, folder creation, sharing, original-account writes or upstream fallback.
  • Incomplete uploads retain the same journal/ciphertext. Explicit retry requires the same name and exact content; restart and repeated restore do not consume stored data.
  • READY publication is atomic after fsync; the targeted partial-write regression fails on the old path and passes on this implementation.
  • Original Files upload control is enabled only in explicit upload mode; read-only mode is unchanged.
  • Bounded owner workspace, serialized uploads, ciphertext/read budgets, original scope and private cleanup remain enforced.

Verification

Focused real HTTP/GPG, encrypted catalog, restart/retry, cancellation and provenance checks pass using an explicit in-memory core-provider fixture. Actual pinned OpenCloud Web8 SDK PUT/list/read/overwrite-refusal checks pass against that fixture. The source patch applies to the exact pinned upstream source. Six pure native-driver boundary checks and three asset checks pass. Independent product review found and fixed the READY interruption issue.

The new guest-only driver exercises the original Files file input/Uppy action and a fresh browser's two verified downloads. It is prepared, not yet a native browser/live-peer upload PASS. The separate core cloud-private-upload scenario now pins exact Cloud source 3e3d6587012ed46d200218e4447506300f8a4f18.

The previous live trial reached UI provisioning but the strict builder rejected noncanonical patch bytes. This revision fixes patch metadata/order/context prefixes, with all eight postimage files byte-identical and the builder guard unchanged. Two regressions execute that actual guard: canonical passes; applicable but noncanonical still fails. No upload/recovery PASS is inferred from this source-admission fix.

Remaining scope

The original server-off read-only proof remains valid only for its original sources. Full server-independent OpenCloud accounts, synchronization, sharing, cross-device key recovery, automatic repair and native upload evidence remain unfinished. Owner keys/catalogs/journals still live locally. Setup and precise limitations: docs/OWNER_UPLOADS.md.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant