Commit Graph
4 Commits
Author SHA1 Message Date
clawbot 0762a728d4 Compare --require-signature with the key that signed (closes #167)
check / check (push) Waiting to run
check and fetch --require-signature compared the required fingerprint
with the first key in the manifest's embedded public key block, while
gpg accepted a good signature by any key in that block.

Loading a signed manifest now refuses one whose embedded block holds
more than one primary key, counted as gpg reads the block, or whose
signer field is not the primary key fingerprint gpg reports for the
signature. --require-signature compares with the signer field, which
loading has checked. Signing names and embeds the key gpg reports it
signed with, so a key ID matching several keys still writes a manifest
that loads. docs/FORMAT.md states what a verifier checks.

Model: opus-5-5
2026-10-07 13:59:17 +02:00
clawbot 2a270b40c5 Record file mode in the manifest, 0000 unless asked (closes #161)
check / check (push) Failing after 4s
MFFilePath gains mode (field 304): a file's permission bits, 0777 at
most, or 0000, meaning none recorded. gen and freshen record real modes
only with --include-permissions (ScannerOptions.IncludePermissions); the
builder keeps only mode.Perm(), so setuid, setgid and sticky are never
written. list -l and export show the mode in octal. check reports
MODE_MISMATCH for a recorded mode other than 0000 the file lacks. fetch
refuses a manifest with a mode above 0777 before requesting any file,
sets only the permission bits of each recorded mode on the files it
writes, and downloads again a present file whose mode differs. The decoding-cost bound counts a file
entry at 176 bytes, up from 160.

Model: opus-5-5
2026-10-06 11:43:18 +02:00
clawbot 343431dd30 Drop atime from the format spec and pin the file entry fields (closes #158)
check / check (push) Successful in 2m16s
atime left mf.proto earlier and nothing reads or writes it, but
docs/FORMAT.md still narrated its removal and listed it among the
determinism rules. The spec now describes the file entry by its fields
only.

A new test compares the MFFilePath message descriptor, by name and
number, with a list copied from the spec's field table. It does not read
the spec, so changing a field means changing the proto, the spec and
that list together.

Model: opus-5-5
2026-10-06 03:26:16 +02:00
clawbot 400a2f8f63 Move FORMAT.md to docs/ and contrib/ to bin/, fix bash script style (closes #74)
check / check (push) Failing after 3s
FORMAT.md moves to docs/ and every reference follows; its two relative
links to mfer/mf.proto now point up one directory, its text is otherwise
unchanged. contrib/usage.sh moves to bin/, not docs/: it is a script you
run (it builds mfer, then generates and checks a manifest of the repo),
not reading material. Both scripts now use #!/usr/bin/env bash,
set -euo pipefail and a main function. bin/gitrev.sh still exits non-zero
outside a git checkout, so the Makefile still falls back to unknown.
.gitignore now ignores only the built bin/mfer rather than all of bin/,
which holds tracked scripts.

Model: opus-5-5
2026-10-04 17:09:20 +02:00