2 months ago
4930bffImplement publication-protocol steps 3-4: before the manifest compare-and-swap, the executor enumerates every managed-asset path referenced by the working database (media, cdg, stems, artwork) and verifies each one is present remotely with the expected size. A missing or truncated asset fails closed with `remote_integrity_failed` and the manifest is NOT committed, so remote readers can never observe a database that references missing assets. This closes the gap left by PR#4, which deferred asset verification to a follow-up. The deferral comment is removed. Tests cover: missing media/stem/artwork asset prevents manifest commit, size mismatch prevents manifest commit, existing manifest is left unchanged on asset failure, publish succeeds when all assets are present, empty path columns are skipped, and the path validator rejects traversal/absolute/out-of-scope paths.
Parent6549fae