diff --git a/docs/architecture.md b/docs/architecture.md index e7ea1c3..5dfb4b9 100644 --- a/docs/architecture.md +++ b/docs/architecture.md @@ -2,7 +2,7 @@ Appa is local-first folder synchronization. One daemon owns the local Iroh endpoint, SQLite state, file watchers, and synchronization loop. Clients use a -user-owned local socket so they do not create competing synchronizers. +user-owned local socket. ## Model @@ -15,9 +15,7 @@ user-owned local socket so they do not create competing synchronizers. requests. It is not stored in folder-inventory files. - A **peer** is a direct or relay route to a member device. -The daemon discovers LAN routes with mDNS and can use Iroh relays when a direct -route is unavailable. Discovery supplies routes only; membership and encrypted -connections remain enforced by Iroh and Appa. +The daemon discovers LAN routes with mDNS and uses Iroh relays when needed. ## Synchronization @@ -34,9 +32,8 @@ announcement is missed. ## Audit evidence -Folder history and audit evidence have different jobs. Local revision history -is compact and bounded for restore. The audit log is append-only and retained -independently. +Local revision history is compact and bounded for restore. The audit log is +append-only and retained independently. Every device has a signed chain of audit events. Each event includes its parent hash, manifest root, and roster hash. Peers exchange missing events through the @@ -44,9 +41,6 @@ authenticated control protocol. A device that retained a newer head can detect a later rollback, altered event, omission, or conflicting event at the same author sequence. -Version clocks order file changes. Merkle trees compare manifests efficiently. -Audit chains record signed state transitions. - Audit verification detects changes relative to heads retained by other members. A compromised device key can still sign events. @@ -68,5 +62,4 @@ existing shared folder. - Folder format version `2` covers rosters and manifests. - Folder inventory format version `1` covers `appa.toml`. -SQLite state has a migration ladder. Network and signed-format versions change -only when their corresponding representation becomes incompatible. +SQLite state uses a migration ladder.