fetch: destination directory, skip files already present, save the manifest, require a signer (closes #101)
check / check (push) Failing after 3s
check / check (push) Failing after 3s
fetch takes --dest (default .) and writes every file there through the existing symlink and hard-link guards, which now work relative to that directory. A file already there with the listed size and hash is skipped; a leftover temp file is still replaced. Once every file verifies, the manifest is saved as index.mf through the same temp file and rename, so check runs on the result; a manifest that lists index.mf or its temp name at the top of the tree is refused, since saving would replace that file. --require-signature is shared with check and enforced through verifyRequiredSigner. Both refusals come before any file is downloaded or anything is written. Model: opus-5-5
This commit is contained in:
@@ -43,9 +43,11 @@ bin/mfer gen .
|
||||
# it lists is missing or corrupted; warns about files it does not list.
|
||||
bin/mfer check index.mf
|
||||
|
||||
# Download and cryptographically verify a tree published over HTTP: mfer
|
||||
# fetches <url>/index.mf, then downloads every file it lists.
|
||||
bin/mfer fetch https://example.com/tree/
|
||||
# Download and cryptographically verify a tree published over HTTP into
|
||||
# ./mirror: mfer fetches <url>/index.mf, downloads every file it lists,
|
||||
# skipping any already there with the right hash, then saves the manifest as
|
||||
# mirror/index.mf.
|
||||
bin/mfer fetch --dest mirror https://example.com/tree/
|
||||
```
|
||||
|
||||
Run `bin/mfer help` for the full command list, or `bin/mfer <command> --help`
|
||||
@@ -258,9 +260,18 @@ are now tracked only in the [issues](https://git.eeqj.de/sneak/mfer/issues).
|
||||
list, hidden files included; with `--no-extra-files` each one is a failure
|
||||
instead
|
||||
- `mfer fetch https://example.com/stuff/`
|
||||
- fetches `/stuff/index.mf` and downloads all files listed in manifest,
|
||||
optionally resuming any that already exist locally, and assures
|
||||
cryptographic integrity of downloaded files.
|
||||
- fetches `/stuff/index.mf` and downloads all files listed in manifest into
|
||||
the current directory, or the one given with `--dest`, and assures
|
||||
cryptographic integrity of downloaded files. A file already there with the
|
||||
size and hash the manifest lists is skipped. Once every file is in place,
|
||||
the manifest is saved there as `index.mf`, so `mfer check` can verify the
|
||||
tree later. A manifest that lists `index.mf` (in any letter case) or
|
||||
`.index.mf.tmp` at the top of the tree is refused before any file is
|
||||
downloaded, since saving the manifest would replace it.
|
||||
- `mfer fetch --require-signature <fingerprint> https://example.com/stuff/`
|
||||
- as above, but first refuses a manifest not signed by the key with that
|
||||
fingerprint, as `mfer check --require-signature` does, before downloading
|
||||
any file.
|
||||
|
||||
# Implementation Plan
|
||||
|
||||
|
||||
Reference in New Issue
Block a user