You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: CHANGELOG.md
+175-1Lines changed: 175 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,13 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
9
9
10
10
### Breaking Changes
11
11
12
-
-**JSR support removed** — The JSR registry publication workflow has been removed. `npm run release:verify -- --skip-jsr` now supports skipping JSR dry-runs. Consumers of the `@git-stunts/git-cas` JSR package should migrate to the npm package.
12
+
-**JSR publication deferred for v6.0.0** — The npm package and GitHub Release
13
+
are the release targets for v6.0.0. JSR metadata and the `jsr-publish`
14
+
verification step remain in the repository, while
15
+
`npm run release:verify -- --skip-jsr` records the skipped dry-run during the
16
+
upstream JSR/Deno toolchain blocker. Consumers of the
17
+
`@git-stunts/git-cas` JSR package should migrate to npm for v6.0.0 or stay on
18
+
the last JSR-published version.
13
19
-**Encryption scheme identifiers simplified** — `whole-v1`/`whole-v2` collapsed to `whole`, `framed-v1`/`framed-v2` collapsed to `framed`, `convergent-v1` collapsed to `convergent`. Legacy v1/v2 scheme strings in stored manifests now throw `LEGACY_SCHEME` at `readManifest()` time with migration guidance. The `scheme` field in `ManifestSchema` is now required for all encryption metadata (previously optional for backward-compatible schemeless whole manifests).
14
20
-**AAD is always on** — `whole` and `framed` encryption always bind slug-based AAD into the GCM tag. The v1 no-AAD path is removed.
15
21
-**Core byte contract is now `Uint8Array`** — public and port byte surfaces now accept and return `Uint8Array` rather than Node-specific `Buffer` types. Node callers can continue passing `Buffer` values because `Buffer` extends `Uint8Array`, but restored data, chunkers, codecs, and Web Crypto adapter outputs should be treated as `Uint8Array`.
@@ -28,6 +34,11 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
`docs/STORE_RESTORE_PIPELINE.md` as the maintainer map for store, restore,
30
36
tree publication, and vault boundaries.
37
+
-**Vault internals maintainer docs** — added
38
+
`docs/VAULT_INTERNALS.md` to document the vault collaborator model, cache
39
+
rules, boundary codecs, privacy index, key verifier, and retry policy.
40
+
-**Public `CasError` export** — `CasError` is now re-exported from the package
41
+
root for callers that need typed error handling without deep imports.
31
42
-**`CasService.readManifestRaw()`** — reads a manifest from a Git tree OID and returns the raw decoded object without Manifest construction or scheme assertion. Migration entry point for inspecting legacy manifests.
32
43
-**`CasService``legacyMode` constructor option** — when `true`, `readManifest()` maps legacy scheme identifiers (v1/v2) to their current names instead of throwing `LEGACY_SCHEME`. Legacy v1 manifests (no AAD) are correctly decrypted without AAD during restore.
33
44
-**`mapToCurrentScheme()` and `isLegacyNoAad()` in `schemes.js`** — public helpers for mapping legacy scheme strings to current names and detecting v1 no-AAD schemes.
@@ -73,6 +84,151 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
73
84
record parsing, and store/restore strategy execution now live in dedicated
74
85
domain services and strategy entities with direct unit coverage. Public
75
86
`CasService` store/restore/manifest/recipient APIs are unchanged.
87
+
-**VaultService decomposed into cohesive collaborators** — `VaultService.js`
88
+
now orchestrates public vault use cases while `VaultPersistence` owns
89
+
`refs/cas/vault` persistence, `VaultStateCache` owns tree-OID keyed state
90
+
memoization, `VaultMetadataCodec` and `VaultTreeCodec` own pure boundary
91
+
encoding, and dedicated privacy, verifier, and retry-policy collaborators own
92
+
HMAC index handling, constant-time key verification, and CAS retry timing.
93
+
Public vault APIs and the on-disk vault tree format are unchanged.
94
+
-**Privacy vault passphrase rotation preserved** — vault passphrase rotation now
95
+
reads metadata before full state so privacy-enabled vaults can derive the old
96
+
key, decrypt `.privacy-index`, and rebuild the index under the replacement key.
97
+
-**Structured KDF algorithm errors** — unsupported stored or requested KDF
98
+
algorithms now fail with `KDF_POLICY_VIOLATION`, and vault metadata decoding
99
+
normalizes those policy failures to `VAULT_METADATA_INVALID` instead of
100
+
leaking raw `Error` instances.
101
+
-**Vault ref creation is create-only** — first vault writes now pass Git's
102
+
all-zero expected OID when `expectedOldOid` is `null`, preserving CAS
103
+
semantics during concurrent vault initialization.
104
+
-**Metadata blob limits reach the default Git adapter** — `maxBlobSize`
105
+
constructor options now configure `GitPersistenceAdapter.readBlob()` when no
106
+
per-call limit is supplied.
107
+
-**Git blob per-call limits are validated** — `GitPersistenceAdapter.readBlob()`
108
+
now rejects invalid caller-provided `maxBytes` limits with `INVALID_OPTIONS`
109
+
before opening a Git blob stream.
110
+
-**API `maxBlobSize` wording** — `docs/API.md` now documents the constructor
111
+
option as the metadata blob read limit, matching the runtime service contract.
112
+
-**Manifest diff JSDoc boundary** — `ManifestDiff.js` now declares its
113
+
`Manifest` typedef locally so generated docs and declaration checks can
114
+
resolve the pure diff helper parameters.
115
+
-**Vault metadata API docs** — `docs/API.md` now includes the optional
116
+
`privacy` shape in the `VaultMetadata` example alongside the privacy error
resolution now awaits the async `@git-stunts/vault` secret lookup before
78
234
validating and returning the passphrase.
@@ -123,10 +279,28 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
123
279
124
280
### Fixed
125
281
282
+
-**Agent diagnostic passphrase resolver guard** — encrypted `git cas agent
283
+
doctor` requests now fail with a controlled credential error when a structured
284
+
passphrase source is supplied without the resolver dependency.
285
+
-**Doctor byte dedupe metric** — vault health statistics now compute byte
286
+
dedupe from stored chunk bytes instead of logical file size, keeping
287
+
compression and deduplication signals separate.
288
+
-**Docker version fallback** — CLI version resolution now ignores the
289
+
`unknown` build metadata sentinel written when Docker test images have neither
290
+
`.git` metadata nor a stamped package SHA, so `git-cas --version` falls back to
291
+
plain semver instead of emitting `+unknown`.
292
+
-**Docker unit-test stability** — vault passphrase-rotation unit coverage now
293
+
uses in-memory persistence and ref ports, keeping domain behavior validation
294
+
independent from Docker Git subprocess scheduling.
126
295
-**Shared CLI/agent credential resolution** — human CLI and agent protocol
127
296
flows now use `bin/credentials.js` for key-file length checks, ambiguous
128
297
credential-source rejection, vault passphrase-derived key verification, and
129
298
encrypted-restore input classification.
299
+
-**CLI restore output authority** — human and agent CLI restore commands now
300
+
treat an explicit `--out` path as authority to write in that path's parent
301
+
directory, while `restoreFile()` keeps enforcing its library-level
302
+
`baseDirectory` boundary. The low-level path check now uses path-relative
303
+
containment instead of a string-prefix comparison.
130
304
-**Type declaration accuracy** — `CasServiceOptions` now marks `chunker` and `compressionAdapter` as required for direct domain-service construction, and `StoreEncryptionOptions` exposes the supported `convergent` opt-in/opt-out flag.
131
305
-**Constructor validation consistency** — direct `CasService` construction now
132
306
validates all required ports through the unified constructor argument
0 commit comments