Files
LisherSong--ps5-web-file-ma…/docs/HANDOVER.md
T
Songlx516 ba668ade50 release: v1.9.3M -- encrypted archives, plus the UI round that followed
First release under the fork-marker convention: VERSION_TAG carries a trailing
`M`, so /api/version, the PS5 start-up notification, the stdout banner, the UI
footer and the ELF file name all read "v1.9.3M" in one move -- and a fork build
can no longer collide with an upstream artifact of the same version, a mix-up
that already happened twice. The footer carries a tooltip spelling the marker
out.

Two bodies of work.

1. Encrypted archives (ZIP / RAR / 7z)

   - ZIP: ZipCrypto (traditional PKWARE) and WinZip AES-256, through
     minizip-ng plus a vendored crypto layer (mz_crypt_wfm.c,
     mz_strm_pkcrypt.c, mz_strm_wzaes.c).
   - RAR: RARSetPassword, wired after RAROpenArchiveEx and before the first
     RARReadHeaderEx. The ordering is load-bearing, not stylistic.
   - 7z: 7zAES including -mhe=on encrypted headers, via a virtual
     ISeekInStream that splices a pseudo-header + the real archive + the
     decrypted header, so no offset stored inside the archive has to move.

   A wrong password is reported as ZIPX_ERR_PASSWORD, and a failed attempt
   leaves no staging directory behind.

2. Reporting, and the UI round that on-device testing produced

   - A RAR whose dictionary exceeds what the build supports now gets its own
     extract_dict_too_large code instead of being mis-reported as "entry too
     large"; the message names both the required and the supported size. The
     behaviour is deliberately unchanged -- such archives are still refused,
     because admitting one means allocating the whole window up front, which
     is why rarlab's own CLI refuses them by default.
   - The upload entry is a menu again: one "Upload" button opening "Upload
     files / Upload folder". The previous main-button-plus-small-arrow made
     "upload folder" effectively undiscoverable.
   - A drag-and-drop hint sits in the footer (hidden on the console browser,
     where drag is not how anyone uploads).
   - The extract button is now always present and merely disabled until
     exactly one archive is selected, instead of appearing out of nowhere.
   - Upload-and-extract on an encrypted archive now prompts for the password
     directly. The retry table used to be keyed by PATH, and for a non-ASCII
     directory the string the page holds and the string the server reports
     are not the same bytes -- the lookup missed, so the user got a bare
     error box and had to press Extract by hand before the prompt appeared.
     It is now keyed by task id, which the server assigns and echoes back
     verbatim.
   - Error text passes through decodeFsText(), so a GBK entry name no longer
     surfaces as `â®…ç§.psd`.
   - Local names are encoded with encodeFsText() before being joined onto a
     server-side path. fs_path_value() declines to rewrite a path if ANY code
     point exceeds 0xFF, so concatenating a local name onto a server directory
     produced a mixed representation and a silently dead path.
   - The menu row highlight was losing the cascade to the generic button rule
     (identical specificity, later in the file) while inheriting the toolbar's
     3px focus ring, which overflowed a 46px row. Both rules are now scoped to
     the panel and the keyboard cue is an inset ring, so it cannot escape the
     row at any line height.
   - The footer status line is clamped to a single line; a long
     "uploading 3/12: some-name.zip" used to wrap out of the 46px footer.
   - A first failed password attempt now says the archive is encrypted,
     instead of blaming a password the user was never asked for.

Artifact
  web-file-mgr-v1.9.3M.elf
  903,448 B
  sha256 8ca47d5aaca75085b32641300cce30fadb7df7749cb6b53d04f129bcecc286b7
  e_machine 0x003e (x86-64 / PS5)

  The file size is identical to the four builds before it, and every one of
  them carries a different sha256: only .rodata moved, and by less than the
  16 KiB section alignment absorbs. Compare sections with `readelf -SW` --
  never infer "nothing changed" from the byte count.

Verification
  - host suites: 140 ZIP + 37 RAR = 177 checks, 0 failures
  - 7z suite: 27 cases, 0 failures. The `aeshe` entry that used to sit in
    KNOWN_GAPS is gone -- the -mhe=on fixture now passes both the folder
    decoder and the extraction facade
  - frontend: .build/ui_retry_test.mjs (40 checks), .build/ui_upload_menu_test.mjs
    (40 checks), .build/preview_check.mjs (12 assertions in headless Chromium
    against the real page and a fixture API). Two layout regressions and the
    highlight cascade bug were caught by the last one and by nothing else --
    reading the source, both CSS rules "look correct"
  - built twice from this tree: byte-identical (cmp clean). rsync refreshes
    every asset mtime, so this is a genuine recompile, not make short-circuiting
    on unchanged sources
  - embedded assets verified in place with .build/check-elf-gzip.py, because
    gen-asset-module.py gzips them and plain `strings` finds none of their text
  - exercised end to end on a real PS5; the checklist is
    docs/DEVICE-TEST-v1.9.3M.md

Docs
  - docs/USER-GUIDE-zh-CN.md (new, simplified Chinese user guide)
  - docs/DEVICE-TEST-v1.9.3M.md (new, on-device acceptance checklist)
  - docs/REAL-CONSOLE-PROFILE.md (new, measured console behaviour)
  - docs/archive/HANDOVER-v1.8-planning.md (superseded v1.8 design notes)
  - CHANGELOG / README (both languages) / HANDOVER updated with the artifact
    fingerprint, the section deltas and the new test counts
2026-09-24 21:07:12 +08:00

2.2 KiB
Raw Blame History

PS5 Web File Manager — v1.8 开发方案(已废弃)

这份文件已不再维护,不要拿它当参考。

原文写于 2026-09-04,是一份 v1.8(RAR 支持)开发计划,对应代码版本 aef4a44 (v1.7 时代)。其中大量结论已被后续版本推翻,例如它至今仍写着:

  • 「❌ RAR 分卷」「❌ 加密 RAR」
  • 「dmc_unrar 不支持 / 已移除」
  • 「7z 尚不支持」「加密解压尚未接线」

而 v1.9 已用 rarlab UnRAR 7.20.1 解决 RAR 分卷与加密,v1.9.2/v1.9.3 补齐了 ZIP/RAR/7z 三格式加密内容与 7z -mhe=on 加密头,dmc_unrar 也已整体移除。

当前权威文档(按优先级)

文档 用途
仓库根 ../HANDOVER.md 状态速览、真机待验证清单、坑清单 —— 以此为唯一准绳
../README.md / ../README.zh-CN.md 功能范围与使用方式
../CHANGELOG.md 逐版本变更
EXTRACTION-PERF.md 解压性能实测与优化账目
REAL-CONSOLE-PROFILE.md 真机性能验证清单
REWRITE-FEASIBILITY.md 许可与拆库可行性分析
SIZE-OPTIMIZATION.md 二进制体积优化记录
UPSTREAM-V1.8-COMPARISON.md 与上游 v1.8 helper 路线的对比

任何关于「现在支持什么」的陈述,一律以根 HANDOVER.md 与源码为准。

为什么归档

这份 1713 行(65 KB)的文件停留在 v1.7/v1.8 时代,却与根 HANDOVER.md 并行存在。 它的过时结论在多轮开发中反复误导整仓 grep(本项目自己就踩过数次:搜 "RAR 分卷"/"加密" 会命中这里,得到与现状完全相反的答案),因此 2026-09-23 把它移出主文档树。

保留它的唯一理由是历史价值:§9「坑清单」以及 v1.7/v1.8 时代的设计推导, 对理解「当时为什么这么取舍、踩过什么坑」仍有考古意义。

原文完整副本(内容一字未改,含归档前的 md5): archive/HANDOVER-v1.8-planning.md