Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
92 commits
Select commit Hold shift + click to select a range
32a3cd8
fix(evidence): name the Transit fault that stops signing initialization
jeremi Sep 24, 2026
e1ee2a2
feat(evidence): check a candidate beside the running writer without i…
jeremi Sep 24, 2026
6090a62
feat(evidence): trust a private CA for the access-token issuer throug…
jeremi Sep 24, 2026
6c46adf
feat(evidence): refuse a derivation that reads a fact its source does…
jeremi Sep 24, 2026
603985b
feat(breg): rehearse successor migrations in bregctl test
jeremi Sep 24, 2026
e68fbee
feat(breg)!: rebaseline history coverage without a live-row limit
jeremi Sep 24, 2026
d8ae46b
feat(breg)!: journal every reviewed chunked backfill chunk
jeremi Sep 24, 2026
1169e83
feat(bregctl): state that removed field values remain in history
jeremi Sep 24, 2026
6976cc4
feat(breg): raise a text field's maxLength on live data
jeremi Sep 24, 2026
de71c1b
docs(breg): record the rehearsal and rebaseline changes in the changelog
jeremi Sep 24, 2026
ee6e151
feat(breg)!: name the SQLSTATE of a statement apply refuses
jeremi Sep 24, 2026
7a00e50
feat(breg): lower a string field's minLength on live data
jeremi Sep 24, 2026
97e9d8c
fix(casework): name the failed doctor check and fail readiness on stu…
jeremi Sep 24, 2026
e2abcbd
test(casework): hold the migration ledger contiguous and the outbox d…
jeremi Sep 27, 2026
4650f8b
feat(casework): refuse a policy package that strands pinned in-flight…
jeremi Sep 24, 2026
06b586f
fix(casework): refuse a BReg engine from another release by name
jeremi Sep 24, 2026
aa16a95
feat(casework): serve operator metrics on an opt-in private listener
jeremi Sep 24, 2026
db9c65f
feat(breg): recover reviews an authority lost and poll live reviews f…
jeremi Sep 25, 2026
dbac0e0
style(breg): format the rehearsal mutation schema call
jeremi Sep 27, 2026
1112224
fix(breg): classify server-ended sessions as connection failures
jeremi Sep 25, 2026
4c211a2
fix(breg): refuse history-step SQL the metadata check cannot read
jeremi Sep 25, 2026
a0cb455
feat(platform)!: add the shared runtime configuration loader and blocks
jeremi Sep 24, 2026
f5f093e
feat(scheduling)!: read runtime.yaml through the shared configuration…
jeremi Sep 24, 2026
4566e9c
feat(render)!: read runtime.yaml through the shared configuration loader
jeremi Sep 24, 2026
6118d4e
feat(platform): bound listener.bind to 128 characters
jeremi Sep 24, 2026
f79ebba
feat(discovery)!: read runtime.yaml through the shared configuration …
jeremi Sep 24, 2026
cda0c25
feat(platform): serialize the shared configuration blocks
jeremi Sep 24, 2026
37f0fb3
feat(relay)!: read runtime.yaml through the shared configuration loader
jeremi Sep 25, 2026
27da82a
feat(relay,render)!: refuse environment expressions in authored files
jeremi Sep 25, 2026
4405584
feat(platform): add the runtime configuration conformance gate
jeremi Sep 25, 2026
de9725b
fix(platform)!: refuse other members beside a discovery jwksSource
jeremi Sep 25, 2026
d5fb81f
fix(platform)!: withhold configured text and fail closed on unreadabl…
jeremi Sep 25, 2026
064b69b
fix(relay): pin the runtime envelope in the editor schema
jeremi Sep 25, 2026
507d0ed
test(platform): cite RFC 8037 as the source of the Ed25519 thumbprint…
jeremi Sep 25, 2026
a54ba21
fix(platform): hold schema-less runtimes and hand-written blocks to t…
jeremi Sep 25, 2026
cd8a6ec
docs(relay): state where runtime substitution applies and that no lit…
jeremi Sep 25, 2026
d61e6dc
feat(breg): add the import operation that change control does not cou…
jeremi Sep 24, 2026
7d04249
feat(breg): serve import grants through the ingestion-run surface
jeremi Sep 24, 2026
41cbe30
feat(breg): open import authorities and require one to create an impo…
jeremi Sep 24, 2026
74a92ce
feat(breg): count every import chunk against its authority and block …
jeremi Sep 24, 2026
b3120f4
feat(bregctl): open, close, settle, and list import authorities
jeremi Sep 24, 2026
458588b
feat(bregctl): name the import authority when a data import stops
jeremi Sep 24, 2026
eb63b0b
docs(breg): document import authorities for operators and in the prod…
jeremi Sep 24, 2026
8e9ec1d
feat(breg): refuse to serve a restored copy until an operator adopts …
jeremi Sep 25, 2026
5c267d4
fix(breg): list import authorities without taking the registry lock
jeremi Sep 25, 2026
605c76b
fix(breg): record an authority block as its own last-attempt outcome
jeremi Sep 25, 2026
63493a2
fix(casework): bound dead database connections
jeremi Sep 25, 2026
f6b24a6
fix(casework): count open work items from a removed source as strande…
jeremi Sep 25, 2026
c1523be
fix(casework): match a development build of BReg to the release of th…
jeremi Sep 25, 2026
1bf3b7e
fix(casework): bound the database work behind metrics scrapes
jeremi Sep 25, 2026
729d738
docs(breg): state what closing and resubmitting a lost review commit to
jeremi Sep 25, 2026
bf64941
feat(platform): add the shared audit key and OIDC issuer blocks
jeremi Sep 25, 2026
025b71a
feat(evidence)!: read runtime.yaml through the shared configuration l…
jeremi Sep 25, 2026
1a0820a
docs: fold the split Registry Discovery changelog entry
jeremi Sep 25, 2026
5f1b8b9
feat(breg)!: read runtime.yaml through the shared configuration loader
jeremi Sep 25, 2026
4c306f5
feat(platform): share OIDC client admission and static JWKS parsing
jeremi Sep 25, 2026
b5d292c
refactor(scheduling)!: use the shared OIDC and audit key blocks
jeremi Sep 25, 2026
41d9a9d
feat(platform): share the removed jwksUri key and static JWKS schema …
jeremi Sep 25, 2026
2f7002d
feat(casework)!: read runtime.yaml through the shared configuration l…
jeremi Sep 25, 2026
4dbf0bb
test: prove each runtime's static JWKS arm refuses untrusted key sets
jeremi Sep 25, 2026
b958226
test(breg): hold the shared configuration crate on the compiler surface
jeremi Sep 25, 2026
8148e3c
fix(platform): refuse a query component in the shared OIDC issuer
jeremi Sep 25, 2026
b8efdc3
fix(casework): report an authored expression before the typed project…
jeremi Sep 25, 2026
aa083da
feat(casework)!: require named OIDC clients behind an operator-contro…
jeremi Sep 25, 2026
74b6057
ci(casework): run the Evidence deployment fixture regression by exact…
jeremi Sep 25, 2026
9102c15
docs(evidence): state what enabling the environment secret provider g…
jeremi Sep 25, 2026
abf1497
docs(breg): recommend an https issuer for production deployments
jeremi Sep 25, 2026
79bc1cf
docs(casework): cite the configuration symbols the shared loader uses
jeremi Sep 25, 2026
73200af
chore(identifiers): refresh catalog digests for the readiness runtime…
jeremi Sep 25, 2026
79d1498
feat(platform): add the shared package writer and verifier
jeremi Sep 25, 2026
8e6199e
feat(casework)!: serve the shared package format
jeremi Sep 25, 2026
9774c8c
feat(scheduling)!: serve the shared package format
jeremi Sep 25, 2026
6600339
feat(platform): let a product name package.root instead of its directory
jeremi Sep 25, 2026
b730f1f
feat(relay)!: serve the shared package format
jeremi Sep 25, 2026
6ebf127
feat(breg)!: serve the shared package format
jeremi Sep 25, 2026
a1d2e6d
fix(casework): bind served files to package identity
jeremi Sep 25, 2026
691a4e2
fix(scheduling): log the served package identity
jeremi Sep 25, 2026
57f630f
fix(breg): bind consumers to verified package bytes
jeremi Sep 25, 2026
74f4979
fix(casework): validate consumers from one package load
jeremi Sep 25, 2026
156dbaa
test(breg): assert exact database secret canaries
jeremi Sep 26, 2026
5dd33e8
feat(evidence)!: serve the shared package format
jeremi Sep 26, 2026
6583b19
feat(render): adopt shared package envelope
jeremi Sep 26, 2026
824c1e9
feat(discovery)!: package immutable indexes
jeremi Sep 26, 2026
307ad55
feat(platform): close shared package convergence
jeremi Sep 26, 2026
f4f9246
docs(evidence): remove retired package layout claims
jeremi Sep 26, 2026
866a20a
test(evidence): republish mutated fixture packages
jeremi Sep 26, 2026
44ec0ff
test(breg): republish mutated package fixtures
jeremi Sep 26, 2026
1315a77
test(casework): count the source reconciliation migration in the sche…
jeremi Sep 27, 2026
ca51907
fix(hooks): record an unknown disposition when a lease commit cannot …
jeremi Sep 27, 2026
5b779ae
docs(breg): describe pinned import digests as labels the client annou…
jeremi Sep 27, 2026
43aae05
docs(breg): record security review notes for the first-adopter changes
jeremi Sep 27, 2026
4945694
docs(site): record the reviewed CLI reference for the shared package …
jeremi Sep 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
30 changes: 30 additions & 0 deletions .github/scripts/ci_changes.py
Original file line number Diff line number Diff line change
Expand Up @@ -106,6 +106,30 @@
SCHEDULING_PACKAGES = frozenset(SHARDS["scheduling"])
STACK_CLIENT_PACKAGES = frozenset(SHARDS["stack-client"])

# The runtime configuration conformance gate reads the sources of the runtimes
# it holds rows for, their generated runtime schemas, and the canonical shared
# configuration blocks schema. A product that joins the gate joins this set.
CONFIG_CONFORMANCE_PACKAGES = frozenset(
{
"registry-platform-config",
"registry-breg",
"registry-casework",
"registry-discovery",
"registry-evidence",
"registry-relay-v2",
"registry-relayctl",
"registry-render",
"registry-scheduling",
}
)
CONFIG_CONFORMANCE_INPUTS = (
"products/platform/generated/*",
"products/platform/scripts/*config-conformance*",
"products/breg/generated/runtime/*",
"products/casework/generated/runtime/*",
"products/scheduling/generated/runtime/*",
)

# These are the cross-product semantic commitments implemented independently by
# Base Registry Engine and Relay V2. A change must replay both real product routers,
# while profile-only tooling and ordinary positive/negative fixtures remain on
Expand Down Expand Up @@ -1002,6 +1026,11 @@ def classify(
or path in {"clippy.toml", "deny.toml", "rustfmt.toml"}
for path in paths
)
config_conformance = (
complete
or any(matches(path, *CONFIG_CONFORMANCE_INPUTS) for path in paths)
or bool(affected & CONFIG_CONFORMANCE_PACKAGES)
)
release_tool = (
complete
or "release_tool" in security_workflow_gates
Expand Down Expand Up @@ -1175,6 +1204,7 @@ def classify(
"platform_assurance": platform_assurance,
"platform_coverage": platform_coverage,
"platform_hygiene": platform_hygiene,
"config_conformance": config_conformance,
"discovery_contracts": complete
or bool(affected & DISCOVERY_PACKAGES)
or any(matches(path, *DISCOVERY_PROVIDER_INPUTS) for path in paths)
Expand Down
70 changes: 69 additions & 1 deletion .github/scripts/test_ci_changes.py
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
from __future__ import annotations

import fnmatch
import importlib.util
import json
import os
import re
Expand Down Expand Up @@ -31,6 +32,7 @@
RELAY_CLIENT_PACKAGES,
RELAY_TUTORIAL_INPUTS,
STACK_CLIENT_PACKAGES,
CONFIG_CONFORMANCE_PACKAGES,
SECURITY_WORKFLOW_GATES,
SHARDS,
LockChange,
Expand Down Expand Up @@ -316,6 +318,9 @@ def test_deferred_ci_work_keeps_its_selector_and_explicit_status_guard(
),
"docs-archives": "needs.changes.outputs.docs_archives == 'true'",
"editor-extensions": "needs.changes.outputs.editors == 'true'",
"config-conformance": (
"needs.changes.outputs.config_conformance == 'true'"
),
}
deferred = {
name
Expand Down Expand Up @@ -400,6 +405,7 @@ def test_ci_scheduling_graph_retains_every_job_and_aggregate_dependency(
"breg-contracts",
"breg-wasm",
"identifiers",
"config-conformance",
"rust-result",
"casework-postgres",
"scheduling-contracts",
Expand Down Expand Up @@ -439,6 +445,7 @@ def test_ci_scheduling_graph_retains_every_job_and_aggregate_dependency(
"casework-postgres",
"scheduling-postgres",
"scheduling-contracts",
"config-conformance",
),
"release-tool-required": ("changes", "release-tool"),
"release-source-proof-required": ("changes", "release-source-proof"),
Expand All @@ -462,6 +469,7 @@ def test_ci_scheduling_graph_retains_every_job_and_aggregate_dependency(
"casework-postgres",
"scheduling-postgres",
"scheduling-contracts",
"config-conformance",
"release-tool",
"release-source-proof",
"evidence-tutorials",
Expand Down Expand Up @@ -515,7 +523,7 @@ def test_final_aggregate_flattens_rust_results_with_equivalent_outcomes(
final_needs,
previous_final_needs.difference({"rust-result"}).union(rust_needs),
)
self.assertEqual(29, len(final_needs))
self.assertEqual(30, len(final_needs))
# Platform line coverage publishes from main and the nightly sweep;
# it does not hold the merge queue.
self.assertNotIn("platform-coverage", final_needs)
Expand Down Expand Up @@ -615,6 +623,66 @@ def status(job: str, selected: str, result: str) -> int:
with self.subTest(job=job, selected=selected, result=result):
self.assertEqual(expected, status(job, selected, result))

def test_config_conformance_inputs_select_the_conformance_gate(self) -> None:
for path in (
"crates/registry-platform-config/src/blocks.rs",
"crates/registry-breg/src/runtime_config.rs",
"crates/registry-relay-v2/src/contract.rs",
"crates/registry-relayctl/schemas/authoring/runtime.schema.json",
"crates/registry-render/src/manifest.rs",
"crates/registry-discovery/src/startup.rs",
"crates/registry-evidence/src/config.rs",
"crates/registry-casework/src/config.rs",
"crates/registry-scheduling/src/config.rs",
"products/platform/generated/runtime-config-blocks.schema.json",
"products/platform/scripts/check-config-conformance.py",
"products/breg/generated/runtime/runtime.schema.json",
"products/casework/generated/runtime/runtime.schema.json",
"products/scheduling/generated/runtime/runtime.schema.json",
):
with self.subTest(path=path):
self.assertTrue(
classify(self.workspace, (path,))["config_conformance"]
)
self.assertFalse(
classify(self.workspace, ("docs/site/src/content/docs/index.mdx",))[
"config_conformance"
]
)

def test_every_config_conformance_row_is_routed(self) -> None:
script = Path("products/platform/scripts/check-config-conformance.py")
spec = importlib.util.spec_from_file_location("config_conformance", script)
assert spec is not None and spec.loader is not None
gate = importlib.util.module_from_spec(spec)
sys.modules[spec.name] = gate
spec.loader.exec_module(gate)
packages = {
Path(source).parts[1]
for row in gate.ROWS
for source in row.loader_sources
}
self.assertLessEqual(packages, CONFIG_CONFORMANCE_PACKAGES)
self.assertIn("registry-platform-config", CONFIG_CONFORMANCE_PACKAGES)
schemas = {
entry.path for row in gate.ROWS for entry in row.hand_schemas
} | {
row.runtime_schema
for row in gate.ROWS
if isinstance(row.runtime_schema, str)
}
for path in sorted(schemas):
with self.subTest(path=path):
self.assertTrue(
classify(self.workspace, (path,))["config_conformance"]
)
digest_tests = {row.digest_mismatch.path for row in gate.ROWS}
for path in sorted(digest_tests):
with self.subTest(path=path):
self.assertTrue(
classify(self.workspace, (path,))["config_conformance"]
)

def test_shards_cover_every_workspace_package_once(self) -> None:
assigned = [package for packages in SHARDS.values() for package in packages]
self.assertCountEqual(assigned, self.workspace.package_names)
Expand Down
43 changes: 43 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,7 @@ jobs:
platform_assurance: ${{ steps.filter.outputs.platform_assurance }}
platform_coverage: ${{ steps.filter.outputs.platform_coverage }}
platform_hygiene: ${{ steps.filter.outputs.platform_hygiene }}
config_conformance: ${{ steps.filter.outputs.config_conformance }}
discovery_contracts: ${{ steps.filter.outputs.discovery_contracts }}
relay_v2_contracts: ${{ steps.filter.outputs.relay_v2_contracts }}
relay_client_contracts: ${{ steps.filter.outputs.relay_client_contracts }}
Expand Down Expand Up @@ -724,6 +725,18 @@ jobs:
CASEWORKCTL_BIN: ${{ github.workspace }}/target/debug/caseworkctl
BREGCTL_BIN: ${{ github.workspace }}/target/debug/bregctl
run: products/casework/scripts/check-checkpoint.sh
- name: Verify the rewritten Evidence deployment loads through the Evidence loader
# The fixture machinery lives behind postgres-test, but this test needs
# neither a database nor an issuer. An inexact name filter that selects
# nothing still exits 0, so the step names the test exactly and fails
# unless it reports one pass.
shell: bash
run: |
set -euo pipefail
cargo test --locked -p registry-casework --features postgres-test --lib \
-- --exact task_grants::native_exchange_tests::the_rewritten_evidence_deployment_loads_through_the_evidence_loader \
| tee "${RUNNER_TEMP}/casework-evidence-fixture.log"
grep -q 'test result: ok\. 1 passed' "${RUNNER_TEMP}/casework-evidence-fixture.log" || { echo "::error::expected exactly one passing test for the_rewritten_evidence_deployment_loads_through_the_evidence_loader"; exit 1; }
- name: Verify claims, reconciliation, and durable attempts
env:
CASEWORK_TEST_DATABASE_URL: postgresql://casework:casework_test@localhost:${{ job.services.postgres.ports['5432'] }}/casework
Expand Down Expand Up @@ -1104,6 +1117,34 @@ jobs:
- name: Check Registry Record profile artifacts
run: products/registry-record/scripts/check.sh

config-conformance:
name: Runtime configuration conformance
needs:
- changes
- rust-policy
if: ${{ !cancelled() && needs.changes.result == 'success' && needs.changes.outputs.config_conformance == 'true' }}
runs-on: ubuntu-24.04
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
persist-credentials: false
submodules: false

- name: Cache Cargo registry
uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2
with:
shared-key: workspace-registry
cache-targets: false
save-if: ${{ github.ref == 'refs/heads/main' }}

- name: Test runtime configuration conformance gate
run: python3 -m unittest products/platform/scripts/test_check_config_conformance.py

- name: Check runtime configuration conformance
run: products/platform/scripts/check-config-conformance.py --check-generated

rust-result:
name: Rust workspace
if: always()
Expand All @@ -1122,6 +1163,7 @@ jobs:
- casework-postgres
- scheduling-postgres
- scheduling-contracts
- config-conformance
runs-on: ubuntu-slim
timeout-minutes: 5
env:
Expand Down Expand Up @@ -2155,6 +2197,7 @@ jobs:
- casework-postgres
- scheduling-postgres
- scheduling-contracts
- config-conformance
- release-tool
- release-source-proof
- evidence-tutorials
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release-candidate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -1764,7 +1764,7 @@ jobs:
"${casework_install_dir}/caseworkctl" test "${casework_project}"
"${casework_install_dir}/caseworkctl" package \
"${casework_project}" --output "${casework_package}"
test -f "${casework_package}/casework.package.json"
test -f "${casework_package}/SHA256SUMS"
rm candidate/bundle-root/SHA256SUMS
fi
evidencectl_installer="evidencectl-${{ needs.validate.outputs.tag }}-install.sh"
Expand Down
15 changes: 11 additions & 4 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions crates/registry-breg-client-node/client.d.ts
Original file line number Diff line number Diff line change
Expand Up @@ -608,6 +608,7 @@ export type BRegIngestionAttemptOutcome =
| 'invalidItem'
| 'refused'
| 'bindingChanged'
| 'importAuthorityClosed'
| 'chunkMismatch'
| 'runNotOpen'
| 'unavailable'
Expand Down
Loading
Loading