Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
88 commits
Select commit Hold shift + click to select a range
eff07df
feat: surface pending iCloud provider indexing on current main
seonghobae Aug 24, 2026
c9ac3b2
docs: record latest iCloud indexing backlog
seonghobae Aug 24, 2026
32c3df9
docs: refresh exact-head PR audit
seonghobae Aug 24, 2026
16f511f
docs: record current iCloud copy stall evidence
seonghobae Aug 24, 2026
3557ef9
test: exercise destination headroom preview authority
seonghobae Aug 24, 2026
35ca9c3
docs: refresh exact-head queue status
seonghobae Aug 24, 2026
618acff
test: preserve folded mail metadata regression across restack
seonghobae Aug 24, 2026
a279484
docs: record latest exact-head queue
seonghobae Aug 24, 2026
f235396
merge: converge provider follow-up with current main
seonghobae Aug 24, 2026
beb81a8
docs: refresh live product queue evidence
seonghobae Aug 24, 2026
e9a3fd8
test: keep destination headroom fixture fresh
seonghobae Aug 24, 2026
43b696b
docs: record destination fixture regression repair
seonghobae Aug 24, 2026
9256001
docs: record latest iCloud stall evidence
seonghobae Aug 24, 2026
8b0be93
docs: record latest icloud backlog evidence
seonghobae Aug 24, 2026
336d83b
docs: separate strix provider evidence
seonghobae Aug 24, 2026
59057c0
docs: record latest icloud indexing backlog
seonghobae Aug 24, 2026
d2da212
docs: refresh exact-head review queue
seonghobae Aug 24, 2026
1535320
docs: record latest icloud health recheck
seonghobae Aug 24, 2026
f3562dc
docs: record current review repairs
seonghobae Aug 24, 2026
27357c4
docs: record cli review repair
seonghobae Aug 24, 2026
7eca444
docs: record worktree audit queue status
seonghobae Aug 24, 2026
4470c99
docs: record Homebrew review status
seonghobae Aug 24, 2026
1d50cfd
docs: record customer UI queue status
seonghobae Aug 24, 2026
c0b9af0
docs: record homebrew status verification
seonghobae Aug 24, 2026
a2bc920
docs: record current icloud provider backlog
seonghobae Aug 24, 2026
214951a
docs: record exact-head review repairs
seonghobae Aug 24, 2026
fe9514c
docs: record worktree test cleanup
seonghobae Aug 24, 2026
8e960cb
docs: refresh exact-head review queue
seonghobae Aug 24, 2026
9137dc6
docs: record current icloud backlog
seonghobae Aug 24, 2026
6b31fbc
docs: record concurrent test target repair
seonghobae Aug 24, 2026
a12e6b2
docs: record live brctl Finder stall evidence
seonghobae Aug 24, 2026
8d6de50
docs: record long-lived Finder provider session
seonghobae Aug 24, 2026
e057ac0
docs: refresh exact-head PR inventory
seonghobae Aug 24, 2026
394e8a0
test: prove mixed native copy headroom is not a plan-wide blocker
seonghobae Aug 24, 2026
5458965
test: bind mixed headroom regression to desktop plan normalization
seonghobae Aug 24, 2026
c5eb317
fix: keep mixed native copy headroom from blanket-blocking the plan
seonghobae Aug 24, 2026
48399b8
docs: record audit test disk-pressure repair
seonghobae Aug 24, 2026
b8a17eb
fix: preserve health stall history across schema additions
seonghobae Aug 24, 2026
e551ace
docs: record upgrade-compatible stall history
seonghobae Aug 24, 2026
933ce7d
docs: refresh current provider backlog evidence
seonghobae Aug 24, 2026
d9b67a1
test: bind mixed headroom fixture to dated path
seonghobae Aug 24, 2026
d5ffedb
docs: record dated headroom fixture repair
seonghobae Aug 24, 2026
d66ed78
docs: refresh exact PR inventory head
seonghobae Aug 24, 2026
7b45ada
feat: explain Finder cancellation permission
seonghobae Aug 24, 2026
14c9cb1
docs: record Finder permission guidance
seonghobae Aug 24, 2026
ce5a8cb
docs: record current icon runtime PR head
seonghobae Aug 24, 2026
776a87d
docs: refresh icon runtime PR head
seonghobae Aug 24, 2026
a38d7e8
docs: refresh exact-head PR baseline
seonghobae Aug 24, 2026
e4cfd1c
docs: record organize path safety amendment
seonghobae Aug 24, 2026
2cfe934
docs: bind baseline to ADR maintenance head
seonghobae Aug 24, 2026
4d05e08
docs: record current CI and provider evidence
seonghobae Aug 24, 2026
cf6c4f7
docs: record current iCloud provider stall evidence
seonghobae Aug 24, 2026
7f43848
docs: record exact iCloud health receipt
seonghobae Aug 24, 2026
a1a0fa2
docs: record latest git audit repair
seonghobae Aug 24, 2026
36a5695
docs: record post-recovery iCloud blocker recheck
seonghobae Aug 24, 2026
f295c80
feat(ui): export path-free cloud lineage graph
seonghobae Aug 24, 2026
14993d7
test(ui): cover lineage export action contract
seonghobae Aug 24, 2026
f453354
feat(ui): bind remote provider item in lineage export
seonghobae Aug 24, 2026
47071bc
docs: record live Finder preparation blocker
seonghobae Aug 24, 2026
0cfb448
fix: scope destination headroom to each candidate
seonghobae Aug 24, 2026
11fa162
fix(ui): label unverified headroom blockers
seonghobae Aug 24, 2026
2a6c69e
docs: make cloud blocker states explicit in Goal
seonghobae Aug 24, 2026
847fff6
fix(icloud): classify native pending scan backlog
seonghobae Aug 24, 2026
076965b
fix(ui): label bounded pending scan evidence
seonghobae Aug 24, 2026
9fdf292
feat(icloud): project health blockers into goal state
seonghobae Aug 25, 2026
72e8c29
docs: record current Google Drive provider stall
seonghobae Aug 25, 2026
87c9089
fix(cloud): project provider sync blockers into goal
seonghobae Aug 25, 2026
7edae17
docs(cloud): record provider blocker projection
seonghobae Aug 25, 2026
5c3b873
fix(cloud): keep unverified preview headroom diagnostic
seonghobae Aug 25, 2026
2ec4b8f
docs(cloud): bind headroom to data volume
seonghobae Aug 25, 2026
a9c868a
docs(cloud): record repeated zero-progress receipt
seonghobae Aug 25, 2026
dc57a15
test(cloud): make headroom normalization deterministic
seonghobae Aug 25, 2026
8ad12e1
docs(cloud): record deterministic headroom proof
seonghobae Aug 25, 2026
a6a8f45
docs(queue): record current exact-head handoff
seonghobae Aug 25, 2026
8e98b74
docs(cloud): record current finder preparation receipt
seonghobae Aug 25, 2026
0d1b604
docs(cloud): record persistent provider stall recheck
seonghobae Aug 25, 2026
dda0f1d
fix(cloud): allow canceling provider indexing stalls
seonghobae Aug 25, 2026
445215d
docs(cloud): record indexing stall cancellation gap
seonghobae Aug 25, 2026
58e1dc5
fix(cloud): preserve provider api admission invariants
seonghobae Aug 25, 2026
b3e00c6
fix(cloud): preserve unverified destination blockers
seonghobae Aug 25, 2026
56dcb19
docs(adr): record destination blocker proof gate
seonghobae Aug 25, 2026
0de3f6a
fix(cloud): bind provider projections to receipt contract
seonghobae Aug 25, 2026
8622b05
Merge remote-tracking branch 'origin/main' into HEAD
seonghobae Aug 26, 2026
67830c8
fix: verify Windows release artifact namespace
seonghobae Aug 26, 2026
aefa086
fix: bind release artifacts to platform directories
seonghobae Aug 26, 2026
b9ad2bd
fix: verify tag artifacts before sbom
seonghobae Aug 26, 2026
629cd15
test: update iCloud readiness fixture fields
seonghobae Aug 26, 2026
ff70f81
fix: make cloud sync guidance actionable
seonghobae Aug 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 21 additions & 19 deletions .github/scripts/verify-release-artifacts.sh
Original file line number Diff line number Diff line change
Expand Up @@ -23,17 +23,17 @@ require_exactly_one_path() {
}

require_exactly_one_file() {
local file_name="$1" count=0 matched_path=""
while IFS= read -r -d '' matched_path; do count=$((count + 1)); done < <(find "$artifact_root" -type f -name "$file_name" -print0)
local directory="$1" file_name="$2" count=0 matched_path=""
while IFS= read -r -d '' matched_path; do count=$((count + 1)); done < <(find "$artifact_root/$directory" -type f -name "$file_name" -print0)
if [[ $count -ne 1 ]]; then
printf 'Expected exactly one release artifact named %s, found %s.\n' "$file_name" "$count" >&2
printf 'Expected exactly one release artifact named %s in %s, found %s.\n' "$file_name" "$directory" "$count" >&2
exit 1
fi
}

expected_dirs=(
"release-disksage-ubuntu-22.04-${run_attempt}"
"release-disksage-windows-latest-${run_attempt}"
"release-disksage-windows-2022-${run_attempt}"
"release-disksage-macos-latest-${run_attempt}"
)

Expand All @@ -55,22 +55,24 @@ if [[ -n "$unexpected_entry" ]]; then
exit 1
fi

require_exactly_one_path '*/bundle/deb/*.deb' 'Debian bundle'
require_exactly_one_path '*/bundle/appimage/*.AppImage' 'AppImage bundle'
require_exactly_one_path '*/bundle/msi/*.msi' 'Windows MSI bundle'
require_exactly_one_path '*/bundle/nsis/*.exe' 'Windows NSIS bundle'
require_exactly_one_path '*/bundle/dmg/*.dmg' 'macOS DMG bundle'
require_exactly_one_path "$artifact_root/${expected_dirs[0]}/bundle/deb/*.deb" 'Debian bundle'
require_exactly_one_path "$artifact_root/${expected_dirs[0]}/bundle/appimage/*.AppImage" 'AppImage bundle'
require_exactly_one_path "$artifact_root/${expected_dirs[1]}/bundle/msi/*.msi" 'Windows MSI bundle'
require_exactly_one_path "$artifact_root/${expected_dirs[1]}/bundle/nsis/*.exe" 'Windows NSIS bundle'
require_exactly_one_path "$artifact_root/${expected_dirs[2]}/bundle/dmg/*.dmg" 'macOS DMG bundle'

for required_name in \
disksage-cloud-plan-linux-x86_64 \
disksage-duplicate-audit-linux-x86_64 \
disksage-cloud-plan-windows-x86_64.exe \
disksage-duplicate-audit-windows-x86_64.exe \
disksage-cloud-plan-macos-arm64 \
disksage-duplicate-audit-macos-arm64; do
require_exactly_one_file "$required_name"
require_exactly_one_file "$required_name.sha256"
done
require_exactly_one_file "${expected_dirs[0]}" disksage-cloud-plan-linux-x86_64
require_exactly_one_file "${expected_dirs[0]}" disksage-cloud-plan-linux-x86_64.sha256
require_exactly_one_file "${expected_dirs[0]}" disksage-duplicate-audit-linux-x86_64
require_exactly_one_file "${expected_dirs[0]}" disksage-duplicate-audit-linux-x86_64.sha256
require_exactly_one_file "${expected_dirs[1]}" disksage-cloud-plan-windows-x86_64.exe
require_exactly_one_file "${expected_dirs[1]}" disksage-cloud-plan-windows-x86_64.exe.sha256
require_exactly_one_file "${expected_dirs[1]}" disksage-duplicate-audit-windows-x86_64.exe
require_exactly_one_file "${expected_dirs[1]}" disksage-duplicate-audit-windows-x86_64.exe.sha256
require_exactly_one_file "${expected_dirs[2]}" disksage-cloud-plan-macos-arm64
require_exactly_one_file "${expected_dirs[2]}" disksage-cloud-plan-macos-arm64.sha256
require_exactly_one_file "${expected_dirs[2]}" disksage-duplicate-audit-macos-arm64
require_exactly_one_file "${expected_dirs[2]}" disksage-duplicate-audit-macos-arm64.sha256

checksum_files=()
checksum_file=""
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -259,6 +259,10 @@ jobs:
path: release-artifacts
merge-multiple: false

- name: Verify downloaded release artifact contract
shell: bash
run: bash .github/scripts/verify-release-artifacts.sh release-artifacts "${{ github.run_attempt }}"

- name: Generate and validate source-bound SBOM
shell: bash
run: |
Expand Down
23 changes: 23 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,19 @@ The format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and
- Show the last read-only iCloud File Provider evidence timestamp beside the
new-copy admission state, so a stalled `no progress`/`hard expired` queue has
an actionable retry context without exposing provider paths.
- Include the redacted iCloud File Provider `pending-indexable-count` in admission evidence and
surface `icloud-file-provider-indexing-pending` when Finder remains in “복사 준비 중”.
- Record the redacted File Provider `disk import: yes` marker as
`icloud-file-provider-disk-import-active`, show it beside the iCloud admission evidence, and
keep Finder copy, attestation, and source cleanup blocked while macOS is importing a provider
disk.
- Persist the earliest retained timestamp for an unchanged iCloud admission-blocker set, so a
restart cannot reset the stalled-copy duration; this diagnostic never grants copy, attestation,
or eviction authority.
- Persist bounded, path-free OneDrive/Google Drive provider-global observations and return
`admission_blocked_since_ms` for an unchanged blocker cohort, so a Finder “복사 준비 중” stall
remains visible across DiskSage or system restarts; tampered evidence is ignored and the journal
never grants copy, attestation, or source-eviction authority.
- Bind Tauri packaging to a fail-closed cross-manifest release-version verifier so `package.json`, `Cargo.toml`, `tauri.conf.json`, and any `v*` release tag must agree on one valid Semantic Version before a bundle is built.
- Add retry-safe release concurrency: fresh first attempts may supersede stale runs, while explicit GitHub rerun attempts do not self-cancel inside the same concurrency group.
- Replace generator-era Cargo package metadata with the DiskSage product description, MIT license expression, canonical source repository URL, and `publish = false` registry-publication boundary; deliberately omit Cargo's deprecated `authors` field, verify publication refusal through Cargo's versioned parsed metadata rather than substring matching, and regression-test commented/out-of-table decoys together with the retained acquisition metadata and doctoring evidence.
Expand All @@ -52,6 +65,9 @@ The format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and

### Fixed

- Consume the persisted iCloud `admission_blocked_since_ms` diagnostic in the UI stall clock, so a
system or application restart preserves the visible duration of an unchanged provider block;
durable evidence remains advisory and fail-closed.
- Reject ontology organize destinations that are relative to the process working directory,
named-user tilde paths, or parent-traversal paths; only an absolute destination or a home token
(`~`/`~/`, plus native Windows `~\`) can produce a move plan, and literal tildes in absolute
Expand All @@ -64,6 +80,13 @@ The format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and
- Keep the shipped Naruon readiness verifier source includable by its integration boundary test;
the terminal parser contract now compiles in both the binary and test-module contexts.

- Bound numeric File Provider disk-full markers for `errno`, `odresult_errno`, and
`OSStatus -34`, so longer codes such as `errno 280` cannot be misclassified as
local-disk-full evidence.

- Include `icloud-file-provider-indexing-pending` in the Naruon iCloud admission-blocker binding,
so a signed non-iCloud envelope cannot smuggle that provider blocker through validation.

- Cover the `sensitive-config` archive-kind wire label in the generated cloud-plan implementation,
so the macOS/Linux/Windows cloud-plan binaries compile after the sensitive-config safety
boundary is enabled.
Expand Down
Loading
Loading