fetch: destination directory, skip files already present, save the manifest, require a signer (closes #101)
check / check (push) Failing after 3s

fetch takes --dest (default .) and writes every file there through the
existing symlink and hard-link guards, which now work relative to that
directory. A file already there with the listed size and hash is
skipped; a leftover temp file is still replaced. Once every file
verifies, the manifest is saved as index.mf through the same temp file
and rename, so check runs on the result. --require-signature is shared
with check and enforced through verifyRequiredSigner, on a Checker over
the manifest held in memory, before anything is downloaded or written.

Model: opus-5-5
This commit is contained in:
2026-10-04 15:20:55 +00:00
parent 400a2f8f63
commit 438b73eddf
6 changed files with 486 additions and 134 deletions
+1 -1
View File
@@ -317,7 +317,7 @@ func (mfa *CLIApp) checkManifestOperation(ctx *cli.Context) error {
}
// Check signature requirement
requiredSigner := ctx.String("require-signature")
requiredSigner := ctx.String(flagRequireSignature)
if requiredSigner != "" {
err = verifyRequiredSigner(ctx.Context, chk, requiredSigner)
if err != nil {