diff --git a/README.md b/README.md index 6fb2d9c..c097ef6 100644 --- a/README.md +++ b/README.md @@ -577,22 +577,16 @@ complete annotated example also lives in ## roadmap -Items still to do before / shortly after 1.0. Loosely ordered by -priority. +Work planned after 1.0. Loosely ordered by priority. ### correctness and operability -* **Security audit of the encryption implementation.** Pre-1.0 - blocker if we're advertising "secure" at the top of this README. - age + zstd + content-defined chunking is mostly off-the-shelf - pieces, but the seams (key handling, recipient parsing, manifest - trust boundary, restore-time identity validation) need an outside - read. -* **Error-condition tests.** Today's coverage is the happy path - plus a few specific regressions. Need fault-injection coverage: - network failures mid-blob, disk-full during restore, corrupted / - truncated / missing blobs, partial uploads, kill -9 between - manifest and db.zst.age writes. +* **Outside security audit.** Before 1.0 the encryption and + blob-generation code was reviewed and every finding fixed; no + outside audit has been done. age + zstd + content-defined chunking + is mostly off-the-shelf pieces, but the seams (key handling, + recipient parsing, manifest trust boundary, restore-time identity + validation) need an outside read. * **Verify restored content end-to-end in CI.** The current integration test does this for a small synthetic snapshot but not at scale. A nightly job against a multi-GB representative @@ -620,8 +614,6 @@ priority. * **Man pages and richer `--help` examples.** Cobra generates basic help; man pages would be a separate target. -* **`--bwlimit` style human-readable size flags** across the - command surface where they're currently raw integers. * **`vaultik snapshot diff `** — show which files changed between two snapshots without restoring either. * **Status reporting hook for `--cron`.** When a backup fails diff --git a/TODO.md b/TODO.md index feb0f2a..c490f04 100644 --- a/TODO.md +++ b/TODO.md @@ -14,14 +14,11 @@ pre-1.0 # Next Step -Define the remaining scope for the first tagged release under the 1.0.0 -milestone, then cut that tag. The mechanism to cut it now exists and is -exercised; what is left is the scope decision, which is the owner's. -This step deliberately names one version number: it previously said -"cut v0.1.0" while the `Makefile` baked in `1.0.0-rc.1` and the issue -milestone said 1.0.0, and three different answers to "what is the next -release" is exactly the contradiction -[issue #65](https://git.eeqj.de/sneak/vaultik/issues/65) was filed over. +The 1.0 work is complete on `next`: the scope settled on +[issue #125](https://git.eeqj.de/sneak/vaultik/issues/125) was the work +already planned for 1.0, and all of it has landed. The mechanism to cut +the tag exists and is exercised; what is left is merging `next` to +`main` and tagging, both the owner's. # Completed Steps @@ -693,4 +690,5 @@ release" is exactly the contradiction # Future Steps -None queued; the release-scoping item is now the Next Step. +Work planned after 1.0 is listed in the README +[roadmap](README.md#roadmap).