# DCTL v0.1.2

**Pre-1.0 and under active development.** Read the warning at the top of the
README before trusting it with anything.

## Install or update

    sudo -v ; curl -fsSL https://dl.dctl.sh/install.sh | sudo bash

The installer verifies the SHA-256 of what it downloaded against `SHA256SUMS`
and refuses on mismatch. There is no flag to skip that.

## What changed since v0.1.1

Internal groundwork for the read-write mount, with no change to what the tool
does yet: sealing can now take any seekable reader rather than only a path, and
there is an encrypted spill for writes that are still in flight. Mounts remain
read-only.

The spill matters even before it is wired up, because it settles how this will
work: a file being written through a mount is held in frames sealed under a key
that exists only in memory and is never written anywhere. A spill left behind by
a crash is undecryptable by anyone, including this program. An interrupted write
loses the write; it does not leak it.

## What changed in v0.1.1

**The Linux build is now statically linked (musl).** v0.1.0 was built against
glibc 2.39 and would not start on Ubuntu 22.04, Debian 12, RHEL/Rocky/Alma 9 or
Fedora 39 and earlier — it failed with `GLIBC_2.39 not found` before reaching
`main`. The static build has no libc requirement at all and is verified running
on Ubuntu 22.04 and 24.04, Debian 12, Rocky 9, Fedora 41 and 44, and Alpine.

The installer also handles dependencies properly now: it names the right
package command for your distribution when a prerequisite is missing, and it
distinguishes FUSE — needed only by `dctl mount` — from the tools it genuinely
cannot proceed without.

## Verifying by hand

    curl -fsSL -O https://dl.dctl.sh/v0.1.2/dctl-v0.1.2-<target>.tar.gz
    curl -fsSL -O https://dl.dctl.sh/v0.1.2/SHA256SUMS
    shasum -a 256 -c SHA256SUMS --ignore-missing

## Builds

| target | platform |
|---|---|
| `x86_64-unknown-linux-musl` | Linux x86-64, static, any distribution |
| `aarch64-apple-darwin` | macOS on Apple silicon |

No Windows build. The code compiles but has never been executed on Windows, and
shipping a binary nobody has run would contradict what this tool promises.

Both are release builds. A debug build writes vaults with a reduced Argon2id
cost meant for tests and must never hold real data.

## Optional dependency

`dctl mount` needs FUSE. Everything else — copy, sync, restore, verify, check —
works without it.

    Debian/Ubuntu   sudo apt-get install -y fuse3
    Fedora/RHEL     sudo dnf install -y fuse3
    Alpine          sudo apk add fuse3
    macOS           https://macfuse.io  (kernel extension; needs approval and a restart)

## Known limits

- The cryptography has had no independent audit
- Mounts are read-only; every write through a mount is refused explicitly
- Windows is unreleased and untested
- Interfaces will change before 1.0
