From 24547e4efd3a45b36b3bea8c29cfc687230a6d3a Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Sat, 10 Oct 2026 16:15:48 +0200 Subject: feat(android): send a manifest of what each backup run sent Photos, videos and files record, per file, their path on the node, their path and album on the phone, dates, size and SHA-256, uploaded as meshbay-manifest/manifest-.jsonl once the run is done. Co-Authored-By: Claude Opus 5.5 --- docs/MESHBAY_DESIGN.md | 21 ++++++++++++++++++--- docs/USERGUIDE.md | 5 +++++ 2 files changed, 23 insertions(+), 3 deletions(-) (limited to 'docs') diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index bc6e20a..6025875 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -3435,9 +3435,24 @@ answered 206 by `ByteRange.kt`), so a video of gigabytes costs the WebView one chunk of memory; the SHA-256 the ledger keeps is then read from the phone once the node has the file. The Photos tab shows them in their albums (§9.9). -**Location.** The manifest does not ask for `ACCESS_MEDIA_LOCATION`, so a -photo or video read through MediaStore has its location **redacted by the -platform** (Android 10+): a photo's EXIF, and in an MP4 or MOV the location +**A manifest, for a restore or a merge later.** The node keeps the files; only +the phone knew where each came from. Every file the node takes adds a line to +a log the phone keeps (`ManifestLog.kt`): its path on the node, its path and +album on the phone (`DCIM/Camera/PXL_….jpg`, `Camera`), when it was taken and +last modified, its size, MIME type and the SHA-256 of the bytes sent. A run +that sent anything ends by uploading the waiting lines as +`/meshbay-manifest/manifest-.jsonl`; the phone forgets them +only once the node has that file, so a run cut short sends them with the next +one. Restoring puts each photo back into its album and each file back under +its own name and date; merging onto a phone that already has some of them +compares hashes without downloading anything. Photos, videos and files have +one; contacts, calendars and messages are each one file that describes +itself. What the manifest cannot bring back is a photo's location, removed +before it left the phone. + +**Location.** The application's Android manifest does not ask for +`ACCESS_MEDIA_LOCATION`, so a photo or video read through MediaStore has its +location **redacted by the platform** (Android 10+): a photo's EXIF, and in an MP4 or MOV the location boxes MediaProvider finds (`IsoInterface`). A camera roll going to a group does not say where its owner lives, and nobody had to do anything for it. On Android 8 and 9 nothing redacts it. diff --git a/docs/USERGUIDE.md b/docs/USERGUIDE.md index 207e57e..dc57f27 100644 --- a/docs/USERGUIDE.md +++ b/docs/USERGUIDE.md @@ -479,6 +479,11 @@ backup at all. earlier copy, with `-modified-` and the date in its name; nothing is ever replaced, and a file you delete on the phone stays in the group. +Beside your photos and files, a `meshbay-manifest` folder holds a small file +per backup run that records where each one came from on the phone (its +album or folder, its original name and dates). It is what will let a restore +put everything back where it was. Leave it in place. + If a backup cannot go on (the node's disk is full, the folder no longer accepts files, somebody else joined the group), it stops, says why once in a notification and on the Android Sync page, and tries again the next day. -- cgit v1.2.3