Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
76 commits
Select commit Hold shift + click to select a range
73c9497
fix: harden Phase 1 real-authority conformance
BunsDev Aug 30, 2026
8306536
fix: preserve Coven authority hardening
BunsDev Aug 30, 2026
6bee23b
fix: preserve complete reviewed hardening
BunsDev Aug 30, 2026
b8537aa
Bound Cave production build memory
BunsDev Aug 30, 2026
1033182
Pin bounded Cave build harness
BunsDev Aug 30, 2026
8a945e4
Repair consolidated conformance metadata
BunsDev Aug 30, 2026
560be3b
Repin corrected Cave authority
BunsDev Aug 30, 2026
7a26d6d
Pin corrected Cave authority harness
BunsDev Aug 30, 2026
300ebf2
Accept corrected Cave authority version
BunsDev Aug 30, 2026
b9872cc
Pin corrected authority lock reader
BunsDev Aug 30, 2026
a82d366
docs: design Grok-inspired agent inspector
BunsDev Aug 30, 2026
9ce8f6b
docs: plan Grok-inspired agent inspector
BunsDev Aug 30, 2026
da8b57e
Classify native conformance stages
BunsDev Aug 30, 2026
7d2e5fa
Pin native stage diagnostic harness
BunsDev Aug 30, 2026
1d3707c
diagnose native pairing stages
BunsDev Aug 30, 2026
2e58dd4
pin pairing diagnostic harness
BunsDev Aug 30, 2026
51665d3
refine native reservation diagnostics
BunsDev Aug 30, 2026
8685bfb
pin refined reservation diagnostics
BunsDev Aug 30, 2026
dc1ccc3
restore macOS native keychain context
BunsDev Aug 30, 2026
dfd5b48
pin macOS native keychain fix
BunsDev Aug 30, 2026
6630b99
stabilize checkout deadline test
BunsDev Aug 30, 2026
e232d2c
pin stabilized keychain harness
BunsDev Aug 30, 2026
20bb892
fix: preserve keychain context during cleanup
BunsDev Aug 30, 2026
bc27a51
chore: pin emergency keychain cleanup fix
BunsDev Aug 30, 2026
fa9b2c6
diagnose native credential cleanup
BunsDev Aug 30, 2026
9550f22
pin cleanup diagnostic harness
BunsDev Aug 30, 2026
8a0e535
diagnose native credential cleanup
BunsDev Aug 30, 2026
a96012c
pin integrated cleanup diagnostics
BunsDev Aug 30, 2026
fda4aea
refresh discovery before credential cleanup
BunsDev Aug 30, 2026
fe8d717
pin cleanup rediscovery harness
BunsDev Aug 30, 2026
6120555
preserve native assertion failure stage
BunsDev Aug 30, 2026
97df02f
pin revocation diagnostic harness
BunsDev Aug 30, 2026
8edd265
merge: integrate cleanup diagnostics
BunsDev Aug 30, 2026
f45e8a5
merge: reconcile remote cleanup rediscovery
BunsDev Aug 30, 2026
e373519
Overhaul chat demo sidebar and thread UX
BunsDev Aug 30, 2026
0db8b55
Clarify Darwin conformance home isolation
BunsDev Aug 30, 2026
092a34d
Pin persist-credentials:false on token checkouts and exact Node in se…
Copilot Aug 30, 2026
0c2415a
Harden CI checkout credentials
BunsDev Aug 30, 2026
5f78781
diagnose native restart stages
BunsDev Aug 30, 2026
2b25e10
pin restart diagnostic harness
BunsDev Aug 30, 2026
5275256
fix duplicate checkout workflow inputs
BunsDev Aug 30, 2026
d84f129
fix evidence environment typing
BunsDev Aug 30, 2026
4fd148c
test: reject duplicate checkout settings
BunsDev Aug 30, 2026
d69c6ef
pin complete restart diagnostic authority
BunsDev Aug 30, 2026
f5cde35
Merge branch 'phase1d/real-authority-conformance-restacked' of https:…
BunsDev Aug 30, 2026
d70febf
fix: relaunch Cave before restart status
BunsDev Aug 30, 2026
5a1b167
chore: pin restart handoff fix
BunsDev Aug 30, 2026
74b83e2
diagnose missing keychain scenario
BunsDev Aug 30, 2026
73e69d1
pin missing keychain diagnostics
BunsDev Aug 30, 2026
5cbbc19
test: format missing keychain diagnostics
BunsDev Aug 30, 2026
4e31408
format missing keychain diagnostics test
BunsDev Aug 30, 2026
733c843
wire missing keychain supervisor diagnostics
BunsDev Aug 30, 2026
c05cf10
pin missing keychain supervisor fix
BunsDev Aug 30, 2026
023e5a1
Merge branch 'phase1d/real-authority-conformance-restacked' of github…
BunsDev Aug 30, 2026
e264194
fix: compare missing-keychain responses semantically
BunsDev Aug 30, 2026
285e684
test: pin semantic response validation
BunsDev Aug 30, 2026
3d11479
test: classify failed runtime assertions
BunsDev Aug 30, 2026
959d563
test: pin runtime assertion diagnostics
BunsDev Aug 30, 2026
f8c5adb
test: classify Coven identity stages
BunsDev Aug 30, 2026
11fc1a9
test: pin Coven identity diagnostics
BunsDev Aug 30, 2026
dd928fc
fix: align Coven refusal diagnostics
BunsDev Aug 30, 2026
1349e4f
test: pin Coven refusal diagnostics
BunsDev Aug 30, 2026
cb90e6e
test: classify post-runtime failures
BunsDev Aug 30, 2026
d180272
propagate verified runner diagnostics
BunsDev Aug 30, 2026
9bd5bd7
pin verified runner diagnostic propagation
BunsDev Aug 30, 2026
bd79146
fix: classify operator isolation failures
BunsDev Aug 30, 2026
9d859f4
test: pin post-runtime diagnostics
BunsDev Aug 30, 2026
6e7b377
Merge remote-tracking branch 'origin/phase1d/real-authority-conforman…
BunsDev Aug 30, 2026
60b8561
test: pin merged Phase 1 diagnostics
BunsDev Aug 30, 2026
028c554
test: classify evidence validation failures
BunsDev Aug 30, 2026
001f68e
fix: compact Windows supervisor evidence binding
BunsDev Aug 30, 2026
c17b8ae
test: classify evidence complexity limits
BunsDev Aug 30, 2026
efd05ca
test: pin compact evidence binding
BunsDev Aug 30, 2026
04afcec
test: pin evidence validation diagnostics
BunsDev Aug 30, 2026
b24eaa7
Merge remote-tracking branch 'origin/phase1d/real-authority-conforman…
BunsDev Aug 30, 2026
3fd0ed7
test: pin merged evidence validation fix
BunsDev Aug 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
scripts/phase1-conformance-launcher.sh text eol=lf
scripts/phase1-conformance-launcher.ps1 text eol=lf
220 changes: 198 additions & 22 deletions .github/workflows/ci.yml

Large diffs are not rendered by default.

19 changes: 10 additions & 9 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,11 +52,10 @@ write-oriented design exploration.
The native host now uses the reviewed `hpke-bound-v1` request and response
binding, and production Coven health uses the producer-backed native adapter.
The immutable runtime gate is documented in
[`docs/phase1-conformance.md`](docs/phase1-conformance.md). It deliberately
reports `blocked` rather than substituting mocks when a locked producer does
not expose a required compatibility or real-keychain fault fixture. Release
evidence still requires complete real-authority runs on the frozen platform
matrix.
[`docs/phase1-conformance.md`](docs/phase1-conformance.md). It emits only
complete SDK #38 platform records and never substitutes mocks for missing
release assertions. Release evidence still requires complete real-authority
runs on the frozen three-platform matrix.

## Prerequisites

Expand Down Expand Up @@ -89,9 +88,10 @@ pnpm exec playwright install chromium
| `pnpm test:e2e` | Run Playwright smoke coverage against a dedicated local preview server on `127.0.0.1:4174` |
| `pnpm test:native-e2e` | Run the feature-gated native RPC subprocess integration tests |
| `pnpm test:contract-canary -- --sdk-root <sdk-root> --cave-root <cave-root>` | Verify reviewed clean checkouts, frozen SDK artifact digests, isolated packed imports, and the Cave authority fixture |
| `pnpm test:phase1-conformance` | Package the revisions in `phase1-conformance.lock.json`, run the real Cave/native/Coven matrix, and retain one secret-scanned JSON report |
| `/bin/sh scripts/phase1-conformance-launcher.sh "$(command -v node)"` | Exercise the exact locked release through the trusted non-Node launcher and retain one SDK-compatible platform record |
| `pnpm cargo:fmt` | Verify Rust formatting |
| `pnpm cargo:check` | Run Rust compile checks |
| `pnpm cargo:check:windows-gnu` | Check all Rust targets for `x86_64-pc-windows-gnu` |
| `pnpm cargo:clippy` | Run Rust lint checks with warnings denied |
| `pnpm cargo:test` | Run Rust smoke tests |
| `pnpm app:dev` | Start the Tauri desktop scaffold in development |
Expand Down Expand Up @@ -172,8 +172,9 @@ Local explicit-root canary runs still use
and the script rejects staged, unstaged, or untracked changes before it
verifies that the checked-out HEADs match the tracked lock.

`phase1-conformance.lock.json` independently pins Chat, SDK, Cave, and Coven
for the packaged real-authority gate. It does not replace or loosen the Phase 0
`phase1-conformance.lock.json` independently pins Chat, the SDK package
candidate and evidence authority, Cave, Coven, and the canonical package
metadata for the real-authority gate. It does not replace or loosen the Phase 0
canary lock.

## CI coverage
Expand All @@ -189,7 +190,7 @@ canary lock.
- the cross-repository packed-tarball contract canary with explicit SDK and Cave checkouts pinned by `contract-canary.lock.json`
- the macOS packaged real-authority matrix with exact counterpart checkouts
pinned by `phase1-conformance.lock.json`, an isolated keychain, and a
secret-scanned JSON report
secret-scanned SDK platform record
- Rust `fmt`, `check`, `clippy`, and `test`

The Tauri capability schema at `src-tauri/gen/schemas/desktop-schema.json` is
Expand Down
27 changes: 16 additions & 11 deletions docs/developer-toolchains.md
Original file line number Diff line number Diff line change
Expand Up @@ -77,10 +77,11 @@
dependency.
- Run the local canary with
`pnpm test:contract-canary -- --sdk-root <sdk-root> --cave-root <cave-root>`.
- Run the packaged real-authority matrix with
`pnpm test:phase1-conformance`. Its independent
`phase1-conformance.lock.json` pins Chat, SDK, Cave, and Coven; the harness
creates exact clean detached clones rather than trusting the source
- Run the packaged real-authority matrix through the trusted outer launcher:
`/bin/sh scripts/phase1-conformance-launcher.sh "$(command -v node)"`. Its independent
`phase1-conformance.lock.json` pins Chat, the SDK package candidate, Cave,
Coven, all four frozen SDK artifacts, and the SDK evidence authority; the
harness creates exact clean detached clones rather than trusting source
repositories' current branches.
- CI reads `contract-canary.lock.json`, checks out those exact reviewed SDK and
Cave revisions, rejects dirty SDK or Cave checkouts, and verifies the
Expand All @@ -98,18 +99,22 @@
permissions for the `main` window.
- No shell, filesystem, opener, or network plugin permissions are configured.
- The feature-gated `phase1-native-rpc` binary is a headless conformance-only
NDJSON bridge. It is excluded from default Cargo and Tauri builds, uses an
in-memory test custody instead of the operator keyring, and accepts Cave
launch paths only through its two explicit
NDJSON bridge. It is excluded from default Cargo and Tauri builds. Unit
scenarios default to in-memory custody, while the real-authority runner
explicitly selects the production `NativeKeyring`, restarts the RPC process,
and verifies credential reuse and deletion. Cave launch paths are accepted
only through its two explicit
`OPENCOVEN_PHASE1_CONFORMANCE_NODE_PATH` and
`OPENCOVEN_PHASE1_CONFORMANCE_CAVE_SERVER_PATH` environment variables.
- Run its subprocess integration gate with `pnpm test:native-e2e`; normal
`pnpm app:dev` selects the `opencoven-chat` desktop binary by default.
- CI compiles every Rust target on a native Windows runner in addition to the
macOS Rust checks, so Tauri's Windows resource build is validated with the
platform toolchain it requires.
- Run the persisted Windows GNU cross-target compile gate with
`pnpm cargo:check:windows-gnu`.
- The Phase 1 harness creates mode-`0700` process-owned roots under the real OS
temporary directory, reaps only tracked child processes, scans the completed
report for secrets and private content, and retains only
SDK platform record for secrets and private content, and retains only
`test-results/phase1-conformance/report.json`. See
[`phase1-conformance.md`](phase1-conformance.md).
- Coven conformance starts the real locked daemon and invokes Chat
`phase1-native-rpc` command `coven_health`; it never uses `coven daemon
status` or reimplements producer-owned peer/pipe identity checks.
Loading
Loading