From 1d6189b6e6db7d0d6c126717b081901c5f552174 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Thu, 1 Oct 2026 13:24:11 +0200 Subject: fix(node): the reaper deletes only the .part files the node wrote MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Any *.part older than a day in a writable root was deleted — a browser's download in progress in a shared folder included. Only names carrying the node's tag (name.<8 hex>.part) are reaped now (F-28). Co-Authored-By: Claude Opus 5.5 --- docs/MESHBAY_DESIGN.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'docs') diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index 8c1f446..0aa00d1 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -2595,7 +2595,9 @@ Asking on the lease message instead would have put the operator's filenames on a unsealed message — precisely what sealing the write path bought. The partial state is keyed by member, directory and filename in the **group** context rather than the session, so a reconnect finds it, and an orphaned partial with no live lease is -reaped on a timer and at startup. The four upload protections (§6.4) are untouched +reaped on a timer and at startup — only a `.part` the node wrote, which carries +its tag (`name.<8 hex>.part`); any other `.part` in a shared folder is somebody +else's download or copy in progress and is never touched. The four upload protections (§6.4) are untouched by any of this. **Video streaming** is fragmented-MP4 remux (or transcode where the codec has no -- cgit v1.2.3