Commit Graph
95 Commits
Author SHA1 Message Date
archipelago 9f0df2ac44 Preserve app gate TLS access through provisioning and certificate rotation 2026-10-06 15:19:38 -04:00
archipelago a3f0bf0af7 Select peer ecash wallet before spending and forbid ambiguous fallback 2026-10-06 12:06:14 -04:00
archipelago 19207282f9 Publish content with an atomic price and visibility policy 2026-10-06 07:51:00 -04:00
archipelago d46f6ceeeb Format payment-method and interrupted-delivery regressions 2026-10-06 07:10:48 -04:00
archipelago 607f54260e Exercise interrupted HTTP body in on-chain delivery recovery regression 2026-10-06 07:03:31 -04:00
archipelago b984b2a698 Check durable file payments against their actual payment method 2026-10-06 07:03:11 -04:00
archipelago 2e761666d5 Stream confirmed on-chain file deliveries into the owned cache 2026-10-06 06:43:19 -04:00
archipelago b8e512fed6 Keep authentication failures refundable and bound inline peer previews 2026-10-06 06:27:06 -04:00
archipelago 8ffbf5ff6e Check on-chain item visibility and reduce test debug-data pressure 2026-10-06 06:17:49 -04:00
archipelago 744923f7d3 Merge branch 'work/post-190-session-key' into work/post-190-peer-content-auth 2026-10-06 06:09:26 -04:00
archipelago 140f4d91cd Correct cached purchase test case tuple after API update 2026-10-06 06:09:25 -04:00
archipelago a9edcd6b3e Verify scoped peer identity proofs before restricted content access 2026-10-06 06:07:55 -04:00
archipelago 6fba95fe5a Exercise existing purchase regressions through streamed Files copies 2026-10-06 06:03:20 -04:00
archipelago 9ce04627dd Stream purchased files into durable cache and avoid duplicate concurrent payments 2026-10-06 05:48:05 -04:00
archipelago 2fee0339cb Prepare large paid files on disk and stream peer responses in bounded chunks 2026-10-06 05:31:19 -04:00
yaya 2fad10c8de Show DATUM login credentials and document complete app launch requirements 2026-10-06 08:13:20 +01:00
yaya 3fc37642cd fix(apps): preserve manifest presentation during installation 2026-10-06 08:13:20 +01:00
archipelago aa10bd1247 Fail closed when persistent session signing material is unavailable 2026-10-06 01:30:04 -04:00
archipelago 7e11f78eb4 Recover stale authenticated CSRF cookies and distinguish interface fetch failures 2026-10-06 01:08:31 -04:00
archipelago 2fa82e4506 Keep peer file downloads and previews on mandatory FIPS transport 2026-10-06 00:53:34 -04:00
archipelago e54f83df8f Add signed node-scoped demo catalogs and retained app media sessions 2026-10-06 00:53:34 -04:00
archipelago bf7fb425eb Require FIPS for peer playback and stream owned media with bounded reads 2026-10-05 23:52:44 -04:00
archipelago 9af49291e9 Bind accepted npub requests to peer identities and serialize cancellation 2026-10-05 23:52:44 -04:00
archipelago fefcbfdbc4 Accept authenticated npub-only peering replies with validated DID keys 2026-10-05 23:52:44 -04:00
archipelago 83ba98ab42 Guide AI connection setup with private node credentials and explicit providers 2026-10-05 23:41:29 -04:00
archipelago 10d31ae13c Persist encrypted peer approval delivery and bind discovery invite identities 2026-10-05 22:27:43 -04:00
archipelago 041f1fa2d3 fix: report collected fleet metrics and distinguish unavailable readings 2026-10-05 20:31:40 -04:00
archipelago 9a041bed18 fix: send peer replies through managed Nostr relays 2026-10-05 19:53:05 -04:00
archipelago daac47cac4 fix: harden node upgrades and prepare 1.9.0-alpha 2026-10-05 12:43:49 -04:00
archipelago 7dfb0e0013 Merge opt-in app owner identity placeholder
nevent1qqs9d76qm6f5xj2vrtjfnkqz5exrc8r0s9zev4f672kqyd0wjh7wwvqpz3mhxue69uhhyetvv9ujumn8d96zuer9wcx2tvaw
2026-10-05 09:29:18 -04:00
TheCryptoDonkey 494d248356 feat: add NODE_IDENTITY_PUBKEYS derived-env placeholder
Lets an app grant the node's users owner rights, e.g. a Blossom server's
allowed uploaders. The value is the Nostr keys of the identities the app
identity picker offers for NIP-07 signing, chosen by the same rule as
NostrIdentityPicker.vue, so the node's own appliance identity is never
included. It is resolved only for manifests that template it, and an
empty set is an error rather than an empty owner list.

identity.list now shares its is_node test with the new helper.
2026-10-03 11:10:29 +02:00
archipelago d6e0c142c6 Return retryable payment status errors and record NPM release gate 2026-10-01 14:24:24 -04:00
archipelago f4d3455496 Fix paid-file recovery, app lifecycle regressions and wallet controls
Demo images / Build & push demo images (push) Failing after 1m10s
2026-10-01 10:31:55 -04:00
archipelago 5ab65f7581 Preserve apostrophes in Quadlet commands and record funded acceptance 2026-09-30 12:08:35 -04:00
archipelago 169bf77de6 Add headless Angor services and shared-index install guard
Demo images / Build & push demo images (push) Failing after 43s
2026-09-30 11:52:19 -04:00
archipelago eb3ccfa00b Merge branch 'fix/gitea-portainer-20260930' 2026-09-30 09:57:49 -04:00
archipelago eda28c4cd6 fix(portainer): repair same-node Git routing with recoverable network migration 2026-09-30 09:57:25 -04:00
archipelago d69e845216 Merge remote-tracking branch 'origin/main'
Demo images / Build & push demo images (push) Failing after 1m10s
2026-09-30 09:32:20 -04:00
archipelago 6ac26f637c fix(apps): preserve lifecycle state and wait for usable launch endpoints 2026-09-30 09:10:30 -04:00
chaum b02ba4100d Merge pull request 'fix(files): save purchased files atomically with rootless ownership' (#162) from fix/filebrowser-purchase-filing into main 2026-09-30 12:58:36 +00:00
archipelago 0677924a64 Merge current main and make purchase filing atomic under concurrent writes 2026-09-30 07:26:51 -04:00
archipelago 971d477795 Merge current main and harden paid-download delivery 2026-09-30 07:25:47 -04:00
ssmithxandClaude Opus 5.5 33477f284b fix(files): file purchased content into FileBrowser folders again
Every paid download logged "filing into filebrowser/Music/... failed
(non-fatal): Permission denied". The purchase played in-app but never
appeared in Files. FileBrowser's folders belong to its rootless container
range (host uid 100000, mode 755). This service is host uid 1000, outside
that range, so it can read them but not create files in them.

New container::filebrowser::save_new_file:
- Writes directly when the folder allows it.
- Otherwise writes through `podman unshare`, where that uid range is
  ours: to a temp file, then chowned to the folder's owner, set to 0644,
  and hard-linked into place. FileBrowser never sees a partial file and an
  existing file is never replaced. A missing folder is created and given
  its parent's owner. No sudo.
- Keeps the "name (2).ext" de-duplication the RPC did inline.

Checked the unshare script on amishparadise in a scratch folder owned
like FileBrowser's: new folder + file OK, owner/mode right, no clobber,
no temp file left, and the service can read the result.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-29 22:36:31 +00:00
archipelago b634f41a1c Complete paid-file caching and deliver LND waiting UI to existing nodes 2026-09-29 14:59:08 -04:00
archipelago 0f85f588fb Fix Cashu file redemption and Bitcoin-dependent wallet readiness 2026-09-29 14:42:44 -04:00
ssmithxandClaude Opus 5.5 e5fc99d66c fix(content): never charge for a file the seller can't serve or replay a spent token
After the keyset-id fix, a Minibits paid download still failed and the
buyer lost the sats. What happened, 2026-09-29, amishparadise:

1. The seller redeemed the token, then failed to read the file. It was a
   FileBrowser upload owned by the container subuid (100999) with mode
   0640. The handler mapped that Err to 404.
2. The buyer's FIPS dial treats 404 as "fall back to Tor" and resent the
   request with the same, now spent, token. The seller answered 402, and
   the buyer showed "seller doesn't accept your Cashu mint".

Fixes:
- serve_content checks the file is readable before the paid gate. If it
  isn't, it grants read with `podman unshare chmod a+r`, which matches
  the other shared files. If that also fails it returns Unavailable (503)
  without taking payment.
- The content handler returns 500 on internal errors and logs them,
  instead of a silent 404.
- New PeerRequest::single_delivery(), used for the paid download: the
  FIPS answer is final, FIPS retries only when it never connected, and
  there's no Tor replay once the request may have been delivered.
- The buyer shows the seller's error text for non-402 failures.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-29 18:42:20 +00:00
archipelago 4237fb5e79 fix(wallet): prioritize LND boot and reject unavailable balances 2026-09-15 15:09:08 -04:00
archipelago 9c6580f5c0 fix: prevent stale catalog updates and redundant container recreation
Demo images / Build & push demo images (push) Failing after 40s
2026-09-15 03:40:21 -04:00
archipelago cb3f7e8720 Merge PR #157: Cuprate disk gate and companion dashboard
Demo images / Build & push demo images (push) Successful in 3m19s
2026-09-13 01:37:46 -04:00
archipelago eb98ebb682 Merge PR #158: preserve Bitcoin Core Tor service naming 2026-09-13 01:37:15 -04:00