Compare commits

..
1 Commits
Author SHA1 Message Date
sneak 55738a5107 Bring README and TODO.md in line with next after the milestone merge (closes #132)
check / check (push) Successful in 40s
Docs only. TODO.md's Next Step no longer says open issues wait on
`next`: no implementation work is open, and the cache design waits on
sneak's review. The README is corrected where the code contradicts it:
where SRP lives and how the login subkey is derived, when email OTP is
used, how the auth token is encoded, the download retry's temporary
files, which CLI commands open a library, what `--exif` records, the ML
data fetch during `quak backup`, the default cache directory, and the
`408`/`429` retries.

Model: opus-5-5
2026-09-29 01:37:26 +00:00
2 changed files with 22 additions and 24 deletions
+18 -19
View File
@@ -399,11 +399,11 @@ download layer rather than in `ApiClient`, and that is the common failure for
multi-megabyte photos over a CDN. The secretstream pull state is not resumable
and these endpoints have no Range support, so a retry starts the file over. The
atomic write is part of the retried unit: each attempt writes its own temporary
files, one for most files and two for a live photo (its image and its video),
and removes them if it fails. Only the attempt that completes renames anything
into place. `runBackup` and `runMetadataBackup` are unchanged: the retry sits
below them, and a file that fails after exhausting it is still logged, counted,
and stepped over.
file and removes it if the attempt fails, and only the attempt that completes
renames its file into place, so a download that needed three attempts still
performs exactly one rename. `runBackup` and `runMetadataBackup` are unchanged:
the retry sits below them, and a file that fails after exhausting it is still
logged, counted, and stepped over.
One imprecision is deliberate and worth knowing about. When a body ends part-way
through a secretstream chunk, Poly1305 fails and carries no framing signal, so a
@@ -452,18 +452,18 @@ thumbnails), for the user to delete if they want it gone.
### CLI surface
```
quak [--cache-dir <path>] <command> global: local metadata/content cache location
quak login interactive or QUAK_EMAIL/QUAK_PASSWORD
quak whoami print logged-in account as JSON
quak logout end the session, delete it
quak collections [--json] list all collections
quak files --collection <id> [--json] list files in a collection
quak get <fileID> [--out path] [--collection] download and decrypt a file
quak get-thumb <fileID> [--out] [--collection] download and decrypt a thumbnail
quak backup <dir> [--json] full incremental backup
quak backup-metadata <dir> [--exif] dump all decrypted metadata as JSON
quak helper list-missing-thumbnails [--json] find files with missing thumbnails
quak helper fix-missing-thumbnails [--file ids] [--json] generate + upload missing thumbnails
quak [--cache-dir <path>] <command> global: local metadata/content cache location
quak login interactive or QUAK_EMAIL/QUAK_PASSWORD
quak whoami print logged-in account as JSON
quak logout end the session, delete it
quak collections [--json] list all collections
quak files --collection <id> [--json] list files in a collection
quak get <fileID> [--out path] [--collection] download and decrypt a file
quak get-thumb <fileID> [--out] [--collection] download and decrypt a thumbnail
quak backup <dir> [--json] full incremental backup
quak backup-metadata <dir> [--exif] dump all decrypted metadata as JSON
quak helper list-missing-thumbnails [--json] find files with missing thumbnails
quak helper fix-missing-thumbnails [--file ids] generate + upload missing thumbnails
```
Every command except `login`, `whoami` and `logout` runs on the cache-backed
@@ -483,8 +483,7 @@ Ente's clients name them (`IMG_0001.heic` and `IMG_0001.mov`). With
`PATH`'s name and the video's extension; a `PATH` with the video's extension is
refused. `backup-metadata --exif` (alias `--all`) additionally fetches each
file's original through the cache and records its XMP metadata and, for a JPEG,
its EXIF metadata and dimensions. `collections`, `files`, `backup`,
`helper list-missing-thumbnails` and `helper fix-missing-thumbnails` take
its EXIF metadata and dimensions. The listing and backup commands support
`--json` for machine-readable output.
`backup-metadata` fetches ML data in requests of up to 200 files. When a request
+4 -5
View File
@@ -29,12 +29,11 @@ declares one.
the SRP handshake uses `fast-srp-hap`, outside `crypto/`; the SRP password is
the first 16 bytes of a 32-byte subkey; email OTP replaces SRP when the
account has email MFA on; the auth token is sent as URL-safe base64 with
padding; each download attempt writes its own temporary files, two for a live
photo, and only the attempt that completes renames them into place; `login`,
padding; each download attempt writes its own temporary file; `login`,
`whoami` and `logout` open no library; `--exif` records XMP and, for a JPEG,
EXIF, and no IPTC; which commands take `--json`; `quak backup` still fetches
ML data; the default cache directory is the per-user one, not an XDG path on
macOS; and `408` and `429` are retried.
EXIF, and no IPTC; `quak backup` still fetches ML data; the default cache
directory is the per-user one, not an XDG path on macOS; and `408` and `429`
are retried.
- 2026-09-28: Tested the live-photo writer's fsyncs (issue 130). A test checks
that the image's and the video's temp files are fsynced before either is