Compare commits

..
1 Commits
Author SHA1 Message Date
sneak b89254f1b0 Bring README and TODO.md in line with next after the milestone merge (closes #132)
check / check (push) Successful in 1m6s
Docs only. TODO.md's Next Step no longer says open issues wait on
`next`: no implementation work is open, and the cache design waits on
sneak's review. The README is corrected where the code contradicts it:
where SRP lives and how the login subkey is derived, when email OTP is
used, how the auth token is encoded, the download retry's temporary
files (two for a live photo), which CLI commands open a library, what
`--exif` records, which commands take `--json`, the ML data fetch
during `quak backup`, the default cache directory, and the `408`/`429`
retries.

Model: opus-5-5
2026-09-29 02:00:23 +00:00
2 changed files with 24 additions and 22 deletions
+8 -7
View File
@@ -399,11 +399,11 @@ download layer rather than in `ApiClient`, and that is the common failure for
multi-megabyte photos over a CDN. The secretstream pull state is not resumable multi-megabyte photos over a CDN. The secretstream pull state is not resumable
and these endpoints have no Range support, so a retry starts the file over. The and these endpoints have no Range support, so a retry starts the file over. The
atomic write is part of the retried unit: each attempt writes its own temporary atomic write is part of the retried unit: each attempt writes its own temporary
file and removes it if the attempt fails, and only the attempt that completes files, one for most files and two for a live photo (its image and its video),
renames its file into place, so a download that needed three attempts still and removes them if it fails. Only the attempt that completes renames anything
performs exactly one rename. `runBackup` and `runMetadataBackup` are unchanged: into place. `runBackup` and `runMetadataBackup` are unchanged: the retry sits
the retry sits below them, and a file that fails after exhausting it is still below them, and a file that fails after exhausting it is still logged, counted,
logged, counted, and stepped over. and stepped over.
One imprecision is deliberate and worth knowing about. When a body ends part-way One imprecision is deliberate and worth knowing about. When a body ends part-way
through a secretstream chunk, Poly1305 fails and carries no framing signal, so a through a secretstream chunk, Poly1305 fails and carries no framing signal, so a
@@ -463,7 +463,7 @@ quak get-thumb <fileID> [--out] [--collection] download and decrypt a thumbnail
quak backup <dir> [--json] full incremental backup quak backup <dir> [--json] full incremental backup
quak backup-metadata <dir> [--exif] dump all decrypted metadata as JSON quak backup-metadata <dir> [--exif] dump all decrypted metadata as JSON
quak helper list-missing-thumbnails [--json] find files with missing thumbnails quak helper list-missing-thumbnails [--json] find files with missing thumbnails
quak helper fix-missing-thumbnails [--file ids] generate + upload missing thumbnails quak helper fix-missing-thumbnails [--file ids] [--json] generate + upload missing thumbnails
``` ```
Every command except `login`, `whoami` and `logout` runs on the cache-backed Every command except `login`, `whoami` and `logout` runs on the cache-backed
@@ -483,7 +483,8 @@ Ente's clients name them (`IMG_0001.heic` and `IMG_0001.mov`). With
`PATH`'s name and the video's extension; a `PATH` with the video's extension is `PATH`'s name and the video's extension; a `PATH` with the video's extension is
refused. `backup-metadata --exif` (alias `--all`) additionally fetches each refused. `backup-metadata --exif` (alias `--all`) additionally fetches each
file's original through the cache and records its XMP metadata and, for a JPEG, file's original through the cache and records its XMP metadata and, for a JPEG,
its EXIF metadata and dimensions. The listing and backup commands support its EXIF metadata and dimensions. `collections`, `files`, `backup`,
`helper list-missing-thumbnails` and `helper fix-missing-thumbnails` take
`--json` for machine-readable output. `--json` for machine-readable output.
`backup-metadata` fetches ML data in requests of up to 200 files. When a request `backup-metadata` fetches ML data in requests of up to 200 files. When a request
+5 -4
View File
@@ -29,11 +29,12 @@ declares one.
the SRP handshake uses `fast-srp-hap`, outside `crypto/`; the SRP password is the SRP handshake uses `fast-srp-hap`, outside `crypto/`; the SRP password is
the first 16 bytes of a 32-byte subkey; email OTP replaces SRP when the the first 16 bytes of a 32-byte subkey; email OTP replaces SRP when the
account has email MFA on; the auth token is sent as URL-safe base64 with account has email MFA on; the auth token is sent as URL-safe base64 with
padding; each download attempt writes its own temporary file; `login`, padding; each download attempt writes its own temporary files, two for a live
photo, and only the attempt that completes renames them into place; `login`,
`whoami` and `logout` open no library; `--exif` records XMP and, for a JPEG, `whoami` and `logout` open no library; `--exif` records XMP and, for a JPEG,
EXIF, and no IPTC; `quak backup` still fetches ML data; the default cache EXIF, and no IPTC; which commands take `--json`; `quak backup` still fetches
directory is the per-user one, not an XDG path on macOS; and `408` and `429` ML data; the default cache directory is the per-user one, not an XDG path on
are retried. macOS; and `408` and `429` are retried.
- 2026-09-28: Tested the live-photo writer's fsyncs (issue 130). A test checks - 2026-09-28: Tested the live-photo writer's fsyncs (issue 130). A test checks
that the image's and the video's temp files are fsynced before either is that the image's and the video's temp files are fsynced before either is