d9b2f69213
Q1 from assessment Part 6.2 — closes the largest robustness gap (Mechanism #2): corrupt cached pkgar that passes mtime check was previously not detected until runtime. Publish side (repo_builder.rs): - Accumulates BLAKE3 hash of each published file (pkgar, toml, dep_hashes, auto_deps) into a BinaryStoreManifest - Writes <recipe>.manifest.toml alongside published artifacts in repo/ Restore side (cook_build.rs): - BinaryStoreManifest struct with read() returning Result<Option<Self>, String> (same pattern as DepHashes: Ok(None) for missing = backward compat, Err for corrupt TOML = loud WARN + skip) - After restoring from binary store, verifies each file's BLAKE3 against the manifest. On mismatch or missing file: WARN + all_restored=false (forces rebuild). Missing manifest = backward compatible (older cookbook published without one). Helper (fs.rs): - compute_file_blake3_hex(): 64KB chunked BLAKE3 hash, avoids loading entire pkgar into memory Tests: 3 new (roundtrip, missing-file Ok(None), corrupt-TOML Err). Total: 38/38 pass. cargo check clean. No new clippy warnings. Assessment doc Part 6.2/6.3/7 updated: Q1-Q6 all marked resolved. Auto-correction table updated: transient network failure (Q2 retry) and corrupt cached pkgar (Q1 BLAKE3 manifest) moved from 'does NOT auto-correct' to 'auto-corrects'.