Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
79 commits
Select commit Hold shift + click to select a range
7ef409a
Fix exact-token tenant proof and refresh
adamgell Aug 30, 2026
67ab1d1
Wire production token single-flight
adamgell Aug 30, 2026
65f06e4
build: bind releases to canonical test proof
adamgell Aug 30, 2026
5f706b5
fix: harden credential and module lifecycle
adamgell Aug 31, 2026
76feb01
docs: freeze the GraphKit Auth R8 train
adamgell Aug 31, 2026
f432bd1
feat: establish r8 prerelease identity
adamgell Aug 31, 2026
cc4d4bd
fix: harden r8 release proof authority
adamgell Aug 31, 2026
208736c
fix: canonicalize r8 dirty source entries
adamgell Aug 31, 2026
c934739
fix: harden r8 source inventory
adamgell Aug 31, 2026
ebd44bf
fix: bind r8 identity to safe source handles
adamgell Aug 31, 2026
2051a20
fix: harden r8 source identity proof
adamgell Aug 31, 2026
59a79db
fix: close r8 release proof breaker gaps
adamgell Aug 31, 2026
0aba617
test: define the GraphKit Auth package boundary
adamgell Aug 31, 2026
614f756
fix: bind r8 helper through physical root aliases
adamgell Aug 31, 2026
3f404c2
test: stage clean r8 repair proof point
adamgell Aug 31, 2026
bc060f1
test: harden the GraphKit Auth boundary
adamgell Aug 31, 2026
5392dd7
feat: define the GraphKit Auth ABI
adamgell Aug 31, 2026
73d9bb1
fix: harden GraphKit Auth contract isolation
adamgell Aug 31, 2026
c5bc803
fix: bound GraphKit Auth shutdown
adamgell Aug 31, 2026
69ec2a2
fix: sanitize GraphKit Auth shutdown failures
adamgell Aug 31, 2026
cb0acd9
feat: add the isolated GraphKit Auth provider
adamgell Aug 31, 2026
1e01420
fix: harden GraphKit Auth provider boundaries
adamgell Aug 31, 2026
a8b74d8
fix: keep provider ownership markers collectible
adamgell Aug 31, 2026
a204d85
build: package the isolated GraphKit Auth runtime
adamgell Aug 31, 2026
d16ca57
feat: use compiled token sources for built-in auth
adamgell Sep 1, 2026
863155a
test: prove GraphKit Auth parity and runspace isolation
adamgell Sep 1, 2026
0fcc707
feat: enforce Task 8 auth and proof boundaries
adamgell Sep 1, 2026
1937cbd
test: isolate packaged proof harness scopes
adamgell Sep 1, 2026
c1dbec6
fix: preserve cancellation and incomplete response semantics
adamgell Sep 1, 2026
beceb22
test: add protected GraphKit Auth parity runner
adamgell Sep 1, 2026
27c1ff1
docs: close no-adopter R9 gates
adamgell Sep 2, 2026
501cf25
docs: record R8 deterministic-complete vs approval-gated split
adamgell Sep 2, 2026
6aee19b
fix: restore lazy SecretManagement boundary
adamgell Sep 4, 2026
0e3b1c3
test: isolate token partition concurrency harness
adamgell Sep 4, 2026
bf71102
fix: harden release gate integrity
adamgell Sep 4, 2026
d340dca
fix: scan compiled package privacy surface
adamgell Sep 4, 2026
604ac0b
fix: scan authored auth source for privacy
adamgell Sep 4, 2026
dbbc0ad
test: synchronize portable suite floor
adamgell Sep 4, 2026
22410ff
fix: address auth boundary review findings
adamgell Sep 4, 2026
f69e436
fix: close r8 review and portability gaps
adamgell Sep 4, 2026
479989e
fix: resolve r8 cross-platform review findings
adamgell Sep 5, 2026
8a621f3
fix: close remaining r8 review findings
adamgell Sep 5, 2026
27b02b4
fix: close exact-head r8 review findings
adamgell Sep 5, 2026
dddd9cb
fix: harden r8 cleanup and deadline bounds
adamgell Sep 5, 2026
09c1a2a
test: isolate build failure regression
adamgell Sep 5, 2026
100f7b4
test: preserve the portable test floor
adamgell Sep 5, 2026
e691127
fix: close final r8 review edge cases
adamgell Sep 5, 2026
a06dab8
fix: preserve optional release and factory contracts
adamgell Sep 5, 2026
d8fbe42
test: harden final review harnesses
adamgell Sep 5, 2026
cc9fe4a
test: bound lifecycle drain beyond scheduling window
adamgell Sep 5, 2026
b446a2c
fix: preserve auth parity fixture bytes on Windows
adamgell Sep 5, 2026
b1a36b7
test: ratchet GraphKit suite floor
adamgell Sep 5, 2026
b915509
fix: close final review findings
adamgell Sep 5, 2026
c5a7a7a
test: resolve final review gaps
adamgell Sep 5, 2026
0adb2ed
fix: synchronize parity capture helper
adamgell Sep 5, 2026
e6ec53a
test: isolate lifecycle workers from thread job throttle
adamgell Sep 5, 2026
9dedd01
docs: clarify verified tenant result contract
adamgell Sep 5, 2026
6e8f8a8
fix: resolve final R8 review findings
adamgell Sep 5, 2026
5a5bb40
test: harden async cleanup seams
adamgell Sep 5, 2026
5825ff9
test: isolate parity fan-out workers
adamgell Sep 5, 2026
f91f4f2
fix: atomically secure Windows stage files
adamgell Sep 5, 2026
7e7af10
fix: reject RFC-shaped placeholder identifiers
adamgell Sep 5, 2026
2279348
fix: close final R8 cleanup review gaps
adamgell Sep 5, 2026
a86db13
fix: preserve shared build authority roots
adamgell Sep 5, 2026
4574f6e
fix: preserve partial create-new destinations safely
adamgell Sep 5, 2026
0865876
fix: preserve Windows GraphKit.Auth ACL transitions
adamgell Sep 5, 2026
1b4e9a7
test: make R8 gates portable on Windows
adamgell Sep 5, 2026
377c823
fix: harden Windows auth stage portability
adamgell Sep 5, 2026
2f4c6e2
fix: bind staging evidence to native ownership
adamgell Sep 5, 2026
4207364
feat: isolate GraphKit Auth parity verification
adamgell Sep 5, 2026
e554a6e
test: await Task 8 fixture termination
adamgell Sep 5, 2026
4d345f3
test: tolerate loaded source proof startup
adamgell Sep 5, 2026
b709f23
fix: allow bounded worker teardown proof
adamgell Sep 5, 2026
36bc95d
test: separate runspace startup bounds
adamgell Sep 5, 2026
ed7f989
test: harden Windows hostile-link fixtures
adamgell Sep 5, 2026
3914579
test: finish Windows fixture cleanup
adamgell Sep 5, 2026
6262e5e
test: harden sealed fixture teardown
adamgell Sep 5, 2026
cdc0101
test: preserve Windows fixture parent ACL
adamgell Sep 5, 2026
5ce9bdc
test: isolate Windows alias cleanup ACLs
adamgell Sep 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1,828 changes: 1,828 additions & 0 deletions .build/GraphKitAuth.tasks.ps1

Large diffs are not rendered by default.

20 changes: 20 additions & 0 deletions .build/ReleaseProof.tasks.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
<#
Invoke-Build integration for the canonical tested-release proof.

Capture runs before Pester and deletes stale proof/result material. Finalize runs only
after Pester and coverage gates, rechecks the captured candidate and complete result,
then writes tested-release-proof.json. The scripts hold the behavior so the exact same
boundary is exercised by focused subprocess tests.
#>

task Capture_Tested_Release_Proof_Candidate {
& (Join-Path $BuildRoot 'scripts/New-GraphKitTestedReleaseProof.ps1') `
-Stage Capture `
-RepositoryRoot $BuildRoot
}

task Record_Tested_Release_Proof {
& (Join-Path $BuildRoot 'scripts/New-GraphKitTestedReleaseProof.ps1') `
-Stage Finalize `
-RepositoryRoot $BuildRoot
}
2 changes: 2 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
* text=auto eol=lf
tests/Fixtures/GraphKitAuthParityCases.json text eol=lf
27 changes: 27 additions & 0 deletions .github/powershell-release-sha256.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
{
"schemaVersion": 1,
"provenance": {
"7.4.19": {
"releaseUrl": "https://github.com/PowerShell/PowerShell/releases/tag/v7.4.19",
"hashesUrl": "https://github.com/PowerShell/PowerShell/releases/download/v7.4.19/hashes.sha256"
},
"7.6.5": {
"releaseUrl": "https://github.com/PowerShell/PowerShell/releases/tag/v7.6.5",
"hashesUrl": "https://github.com/PowerShell/PowerShell/releases/download/v7.6.5/hashes.sha256"
}
},
"sha256": {
"7.4.19/PowerShell-7.4.19-win-arm64.zip": "ac3a0249c0cd9f5b55f198f681485099ea73f45838dfd676457571a94d793463",
"7.4.19/PowerShell-7.4.19-win-x64.zip": "cd62ad6d8174cc6fb85b335a0058444bc934fe27c39fa97fe342134286d28af9",
"7.4.19/powershell-7.4.19-linux-arm64.tar.gz": "2b11aafacf574222abaf691a0b3b2d463e617d17fe337343c2fb93ea871a4691",
"7.4.19/powershell-7.4.19-linux-x64.tar.gz": "1b023e097b0e0546ad9566f7a2126cbe0eb8455fa7b0c5de558e317b8ddc16c8",
"7.4.19/powershell-7.4.19-osx-arm64.tar.gz": "fb9d6656d0c78c6d3f6e8d08ff15e5e0d867f886bf4ebecfde6484d2fa06c042",
"7.4.19/powershell-7.4.19-osx-x64.tar.gz": "bb67378d9b9d469d0c3863aa8a5576a38ad8eaa0fd7aae2c4819e7caf06cb79c",
"7.6.5/PowerShell-7.6.5-win-arm64.zip": "20514a755d16428dc4355c85e0883c859531e71cc3e122670aa1fccdbf96ba7e",
"7.6.5/PowerShell-7.6.5-win-x64.zip": "32eb8f6cdce08f86e987d625a2733e54ac3e289ae7e1621b14c0b5bcec2434ea",
"7.6.5/powershell-7.6.5-linux-arm64.tar.gz": "ed4084f215d8bce2edd23aa7cb1f1e7b0818e41363a635a22065d2701b6141df",
"7.6.5/powershell-7.6.5-linux-x64.tar.gz": "b34ab3b19acac1d3d4d0d3cfdb02acf62f457b0b6a962ff008132033f7566844",
"7.6.5/powershell-7.6.5-osx-arm64.tar.gz": "8196d4b4e7c21b7f6df9d45687bb4e42dc8335f330b580d9eb15f3ef5042a8c3",
"7.6.5/powershell-7.6.5-osx-x64.tar.gz": "3db1d177ab39511c1b6b73b05a1630a5db4e8dce22857ca76f14c5d98f2733fd"
}
}
42 changes: 42 additions & 0 deletions .github/scripts/Install-VerifiedPowerShellArchive.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
[CmdletBinding()]
param(
[Parameter(Mandatory)][string] $Version,
[Parameter(Mandatory)][string] $AssetName,
[Parameter(Mandatory)][string] $ArchivePath,
[Parameter(Mandatory)][string] $InstallDirectory,
[Parameter(Mandatory)][string] $HashMapPath
)

$ErrorActionPreference = 'Stop'
Set-StrictMode -Version 3.0

$hashMap = Get-Content -LiteralPath $HashMapPath -Raw | ConvertFrom-Json -AsHashtable
if ([int]$hashMap.schemaVersion -ne 1) {
throw 'The reviewed PowerShell release hash map has an unsupported schema version.'
}
$key = "$Version/$AssetName"
$matchingKeys = @($hashMap.sha256.Keys | Where-Object { [string]$_ -ceq $key })
if ($matchingKeys.Count -ne 1) {
throw "PowerShell release asset '$key' has no reviewed SHA-256 mapping."
}
$expectedHash = [string]$hashMap.sha256[$matchingKeys[0]]
if ($expectedHash -cnotmatch '^[0-9a-f]{64}$') {
throw "The reviewed digest for PowerShell release asset '$key' is not a lowercase 64-character SHA-256."
}
$actualHash = (Get-FileHash -LiteralPath $ArchivePath -Algorithm SHA256).Hash.ToLowerInvariant()
if (-not [string]::Equals($actualHash, $expectedHash, [StringComparison]::Ordinal)) {
throw "PowerShell release asset '$key' does not match its reviewed SHA-256."
}
Write-Host "Verified SHA-256 for $AssetName."

$null = New-Item -ItemType Directory -Path $InstallDirectory -Force
if ($AssetName.EndsWith('.zip', [StringComparison]::Ordinal)) {
Expand-Archive -LiteralPath $ArchivePath -DestinationPath $InstallDirectory -Force
}
elseif ($AssetName.EndsWith('.tar.gz', [StringComparison]::Ordinal)) {
& tar -xzf $ArchivePath -C $InstallDirectory
if ($LASTEXITCODE -ne 0) { throw "PowerShell archive extraction failed for '$AssetName'." }
}
else {
throw "PowerShell release asset '$AssetName' is not a supported archive."
}
70 changes: 53 additions & 17 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,9 @@ name: CI

on:
push:
branches: [main]
branches: [main, 'codex/**']
pull_request:
workflow_dispatch:

permissions:
contents: read
Expand All @@ -21,11 +22,34 @@ jobs:
steps:
- name: Checkout
uses: actions/checkout@v4
with:
repository: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name || github.repository }}
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || github.sha }}
fetch-depth: 0
persist-credentials: false

- name: Assert exact source revision
shell: pwsh
env:
EXPECTED_SOURCE_SHA: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || github.sha }}
run: |
$ErrorActionPreference = 'Stop'
$expected = $env:EXPECTED_SOURCE_SHA
$actual = (& git rev-parse HEAD).Trim()
if (-not [string]::Equals($actual, $expected, [StringComparison]::Ordinal)) {
throw "Checked-out source mismatch: expected $expected, got $actual"
}
Write-Host "Exact source revision asserted: $actual"

- name: Setup .NET SDK
uses: actions/setup-dotnet@v4
with:
dotnet-version: '10.0.400'

# Each row installs its exact PowerShell version rather than trusting the
# runner image, then asserts the running version matches before doing work.
# Pinned release tags + direct GitHub release assets: no third-party action,
# no secrets, fork-safe.
# Pinned release tags + direct GitHub release assets + committed official
# checksums: no third-party action, no secrets, fork-safe.
- name: Install PowerShell ${{ matrix.pwsh-version }}
shell: pwsh
run: |
Expand All @@ -45,16 +69,13 @@ jobs:

$installDir = Join-Path $env:RUNNER_TOOL_CACHE "pwsh-$version"
$archive = Join-Path $env:RUNNER_TEMP $asset
$hashMap = Join-Path $env:GITHUB_WORKSPACE '.github/powershell-release-sha256.json'

New-Item -ItemType Directory -Path $installDir -Force | Out-Null
Write-Host "Downloading $asset"
Invoke-WebRequest -Uri "https://github.com/PowerShell/PowerShell/releases/download/v$version/$asset" -OutFile $archive

if ($IsWindows) {
Expand-Archive -Path $archive -DestinationPath $installDir -Force
} else {
tar -xzf $archive -C $installDir
}
& (Join-Path $env:GITHUB_WORKSPACE '.github/scripts/Install-VerifiedPowerShellArchive.ps1') `
-Version $version -AssetName $asset -ArchivePath $archive `
-InstallDirectory $installDir -HashMapPath $hashMap

Add-Content -Path $env:GITHUB_PATH -Value $installDir
Write-Host "Installed PowerShell $version to $installDir"
Expand All @@ -63,19 +84,17 @@ jobs:
shell: pwsh
run: |
$expected = '${{ matrix.pwsh-version }}'
$actual = $PSVersionTable.PSVersion
$expectedMajorMinor = (($expected -split '\.')[0..1] -join '.')
$actualMajorMinor = "$($actual.Major).$($actual.Minor)"
if ($actualMajorMinor -ne $expectedMajorMinor) {
throw "PowerShell version mismatch: expected $expectedMajorMinor.x, got $actual"
$actual = $PSVersionTable.PSVersion.ToString()
if (-not [string]::Equals($actual, $expected, [StringComparison]::Ordinal)) {
throw "PowerShell version mismatch: expected $expected, got $actual"
}
Write-Host "PowerShell version asserted: $actual"

- name: Resolve build dependencies
shell: pwsh
run: pwsh -File ./build.ps1 -ResolveDependency -Tasks noop

- name: Pack candidate
- name: Pack candidate with Build_GraphKitAuth
shell: pwsh
run: pwsh -File ./build.ps1 -Tasks pack

Expand All @@ -93,4 +112,21 @@ jobs:
if ($resultFiles.Count -gt 1) {
throw "Multiple NUnit result files produced: $($resultFiles.Name -join ', ')"
}
pwsh -File ./tests/QA/Assert-GateResult.ps1 -ResultPath $resultFiles[0].FullName -MinimumTests 777 -AllowedSkips 0
pwsh -File ./tests/QA/Assert-GateResult.ps1 -ResultPath $resultFiles[0].FullName -MinimumTests 1482 -AllowedSkips 0
if ($LASTEXITCODE -ne 0) {
throw 'The standalone whole-result gate failed.'
}

$proofPath = 'output/testResults/tested-release-proof.json'
if (-not (Test-Path -LiteralPath $proofPath -PathType Leaf)) {
throw "No canonical tested-release proof was produced at $proofPath"
}
$packageFiles = @(Get-ChildItem -Path 'output/GraphKit.*.nupkg' -File -ErrorAction SilentlyContinue)
if ($packageFiles.Count -ne 1) {
throw "Expected exactly one GraphKit package, found $($packageFiles.Count): $($packageFiles.Name -join ', ')"
}
& ./scripts/Test-GraphKitReleaseProof.ps1 `
-PackagePath $packageFiles[0].FullName `
-ProofPath $proofPath `
-TestResultPath $resultFiles[0].FullName `
-RepositoryRoot $PWD | Out-Null
Loading
Loading