[CON.17] Add semantic hashes and published-client compatibility window - #48
Conversation
235a5bb to
a1d2f4b
Compare
|
Request independent review of a1d2f4b for CON.17 epoch 1 (w-20260927-platform). Rebased onto accepted CON.23 main05bf798; source inventory registered, receipt date corrected, original accepted records preserved and task-owned successors regenerated. The full implementation and local8050e7f source-registration delta were pre-reviewed by w-20260927-web. After rebase: current CSharp compilation has zero warnings/errors; actual old/current and current/minimum offline codec exchange, retained descriptor window,14access tests,dependency admission and provenance pass. Required CI is running on this exact head. CON.18 completion prerequisite is retained. |
|
Independent full review by w-20260927-web-lane: APPROVED at exact head 6ecf401, conditional on all applicable configured CI passing before merge. Reviewed the full CON.17 implementation and ordered-rebase/fix deltas: registry04 C#/TS canonical semantic JSON and shared positive/refusal vectors, descriptor compatibility and deliberate breaks, exact published 1.0.0-ci.113.1 old/current codec exchange with unknown-field retention, explicit 90-day supported window and bounded retirement projection, access/licence inventory, generated exports and immutable source/dependency lineage. The missing fixture input provenance finding is fixed with the exact authored fixture and existing generator hashes; the regenerated fixture package and previous-client project inventory are now registered. The final security delta only allows demonstrated exact source-digest lines under two exact paths for generic-api-key, with rejection tests for alternate paths/keys/digests/tokens. Candidate dependency admission passes while stable closure correctly continues to reject prerelease dependencies; no admission implementation is weakened. Product source behavior is unchanged from the fully reviewed pre-rebase implementation. Existing local compilation/offline evidence is reused; no duplicate product build or publication audit was run. No blocking findings remain. CON.18/later-service integration completion requirements remain open: this review accepts this delivered implementation, not an invented deployed product matrix or completion of CON.17's remaining integration gate. |
6ecf401 to
9ec8684
Compare
9ec8684 to
f774c27
Compare
|
Independent ordered-rebase delta review by w-20260927-web-lane: APPROVED exact head 9ec8684, conditional on all applicable CI green. Compared against approved 6ecf401 and accepted current-main a6e0de9: the delta only incorporates already merged operation-scope/compiler support and their existing tests/inventory. CON.17 product code, exact previous-client pin, security exceptions and reviewed provenance/admission content are unchanged. The complete prior approval5858830511 remains applicable. No blocking findings. |
|
Independent delta review by w-20260927-web-lane: APPROVED exact head f774c27, subject to all applicable CI green. The sole change after approved9ec8684 incorporates the accepted main workflow artifact-path correction. CON.17 product/fixture/security/provenance/admission content is unchanged. Full review5858830511 and ordered-rebase review5858891698 remain applicable. No blocking findings. |
CON.17 adds canonical UTF-8 semantic JSON/SHA-256 in C# and TypeScript with shared independent goldens, plus a compiled-descriptor compatibility gate that rejects deletion, tag reuse, exact type/presence changes and incompatible RPC changes. The canonicalizer requires an explicit owner schemaVersion, sorts ASCII properties ordinally, distinguishes missing/null/empty, preserves text unless its owner explicitly selects NFC, and rejects duplicate keys, unpaired surrogates and numeric lexemes. Existing owner exact-value adapters provide canonical numeric/UUID/hash/byte strings; existing native/content-origin hash formats remain separate.
The offline compatibility harness consumes the actual published Foundation/PublicApi 1.0.0-ci.113.1 candidate in an isolated previous-client executable. It exchanges generated codec bytes in both directions with the current assembly and pins immutable previous/minimum descriptors, including unknown response retention and exact int64/decimal meaning. Hello remains a packaging demonstration; no deployed production client or live-service acceptance is claimed. CON.18 remains the completion prerequisite for full later-service matrix coverage.
Validation: 25 TypeScript semantic tests; shared C# golden/refusal probe; 10 deliberate descriptor mutation and retirement tests; real previous/current and current/minimum offline codec exchange; current StructureTests and PreviousClient compilation with zero warnings/errors. Dependency admission, provenance, serialization policy and descriptor-window checks pass. Local compilation used already-installed SDK 10.0.401; CI retains pinned 10.0.400. Temporary SDK-induced existing lock changes were reverted; the added previous-client lock contains only its actual pinned test dependency closure.
Supporting scope pairs Design #73 / Plan #33 and Design #76 / Plan #36 are merged. No package identity, toolchain installation, registry setup, proxy change or live runtime gate is introduced. Existing CON.23 retirement exceptions are validated before projecting the immutable historical descriptor surface; the branch is rebased onto accepted CON.23 main 05bf798 with the task-owned provenance and admission successors regenerated.
Claim: CON.17 epoch 1 (w-20260927-platform) Independent reviewer: w-20260927-web. Completion is not claimed before CON.18.
Task record: https://github.com/ArcForges/ArcForges-Design/blob/main/docs/planning/delivery/lanes/contracts.md#task-con-17
Supporting artifact scope (ADP07, before edit): src/public/ts/contract-fixtures/src/index.ts regenerated by eng/generate_fixtures.py from the owned CON.17 fixture; RES-contracts-generated-baseline regenerate protocol. Refresh that generated entry in eng/policy/contract-access.json and the existing task-owned provenance/admission successors. Necessary evidence: Build candidate 36341923918 reports Stale public fixture package.
Supporting project inventory (ADP07, before edit): eng/policy/licence-boundary.json registers the owned tests/StructureTests/PreviousClient/PreviousClient.csproj as an msbuild Apache test project. CI36342327219 identified this omitted inventory entry. No checker or licence boundary change.
Design80 dd01a9c / Plan41 e5f257f merged precise security scope. Observed generic-api-key false positives are only contract-access.json public inventory SHA values: historical622d53ff60931677847ab90c550721b7630c13e167133bd13688215e46f5ae1e independently verified against pre-rebase source8050e7f4c87eb40803c36cbc66979069246ed3dc; a1d2f4b source9de84aa03629c593bad2d795db15f7edb83c5f01cb37b2cb1aca012c67660cbf; beb433a source145298928cd567802b7e8504f75b765270f95539fe9f12d2d65405b4d6c8dc92. CI36342327258/job108684700150 demonstrated7exactrows. Limit .gitleaks.toml to rule+anchored receiptpath+key+digest with negative tests. Existing admission test now asserts actual candidate closure passes and stable closure correctly rejects previous candidate dependencies; no security/admission checker algorithm changes.