ROADMAP: R-75 catalog-derived userdata skeleton + import surfaces; R-76 setgid-chain break
R-75 (spiked, GO) names the capability-map row it would flip: "File access via browser" (00-capability-map.md line 96), currently IMPLEMENTED with the caveat that browse/download through FileBrowser is exercised in no doc. Carries the mandatory determinism constraint from P6 (sort + red-proof, or FileBrowser force-recreates on every sync pass), the zero-removals invariant for `documents`, the url.PathEscape-not-QueryEscape trap, and the four design forks with evidence + recommendation, all awaiting operator ruling. R-76 is minted for the two PRE-EXISTING defects the spike surfaced and deliberately did not fix: FileBrowser Quantum creating 0644/0755 without propagating setgid (breaking the shared-group chain one level below any customer-created folder -- latent only because every userdata-touching app runs uid 1000), and import/calibre living at 755 on demo-felhom where its same-app sibling media/books is 2775. Source: audits/SPIKE-catalog-data-paths-2026-07-26.md
This commit is contained in:
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user