Skip to content

Implement Portable Project Archive import and export #61

Description

@qisoft

Outcome

Round-trip complete retained Project history while treating every imported archive as hostile.

Scope

  • versioned ZIP manifest, hashes, revisions/edits/lyrics/practice/receipts and safe provenance
  • external exact dependencies and optional verified Project Range media
  • quarantine plus bounded path/link/normalization/compression/hash/schema/reference/invariant validation
  • duplicate/collision/Imported Project Copy and unavailable Source behavior

Acceptance gates

  • traversal, links, collisions, undeclared files, bombs, encryption and active content are rejected
  • import performs no network, model download, credential use or execution
  • identity conflicts never overwrite or auto-merge histories
  • included media becomes verified Offline Media Cache

Planning authority

Constraints

  • Implement through tests at the module interface and the named packaged seams.
  • Preserve normative security, privacy, provenance, nondestructive-state, accessibility, and no-unmeasured-claim rules.
  • Native GitHub blockers define readiness.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

implementation:taskExecutable Open Chords implementation work item

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions