MFFilePath gains mode (field 304): a file's permission bits, 0777 at
most, or 0000, meaning none recorded. gen and freshen record real modes
only with --include-permissions (ScannerOptions.IncludePermissions); the
builder keeps only mode.Perm(), so setuid, setgid and sticky are never
written. list -l and export show the mode in octal. check reports
MODE_MISMATCH for a recorded mode other than 0000 the file lacks. fetch
refuses a manifest with a mode above 0777 before requesting any file,
sets each recorded mode on the files it writes, and downloads again a
present file whose mode differs. The decoding-cost bound counts a file
entry at 176 bytes, up from 160.
Model: opus-5-5
atime left mf.proto earlier and nothing reads or writes it, but
docs/FORMAT.md still narrated its removal and listed it among the
determinism rules. The spec now describes the file entry by its fields
only.
A new test compares the MFFilePath message descriptor, by name and
number, with a list copied from the spec's field table. It does not read
the spec, so changing a field means changing the proto, the spec and
that list together.
Model: opus-5-5
FORMAT.md moves to docs/ and every reference follows; its two relative
links to mfer/mf.proto now point up one directory, its text is otherwise
unchanged. contrib/usage.sh moves to bin/, not docs/: it is a script you
run (it builds mfer, then generates and checks a manifest of the repo),
not reading material. Both scripts now use #!/usr/bin/env bash,
set -euo pipefail and a main function. bin/gitrev.sh still exits non-zero
outside a git checkout, so the Makefile still falls back to unknown.
.gitignore now ignores only the built bin/mfer rather than all of bin/,
which holds tracked scripts.
Model: opus-5-5