Skip to content

v0.8.0: reliable requests and verifiable audit inspection - #13

Merged
renezander030 merged 1 commit into
masterfrom
feat/v0.8.0-reliability
Oct 1, 2026
Merged

renezander030 merged 1 commit into
masterfrom
feat/v0.8.0-reliability

Conversation

@renezander030

Copy link
Copy Markdown
Owner

Webhook retries could repeat a completed workflow, older state stores could fail during upgrade, and run history did not record engine runs. This release adds reliable request handling and verifiable audit inspection for version 0.8.0.

  • Add durable, pipeline-scoped webhook idempotency keys that return the original admission and reject changed bodies.
  • Claim signed webhook replay identities atomically under concurrent requests.
  • Migrate legacy SQLite schemas transactionally before indexing new columns; keep lock timeout settings on every store operation.
  • Recheck tool rules and operator authorization when consuming a permit, including after restart.
  • Reject oversized, unreadable, duplicate-key, unknown-field, trailing, and excessively nested tool request data.
  • Preserve exact tool argument numbers and compare numeric bounds without rounding the supplied argument.
  • Persist completed and failed pipeline runs with exact approval correlation; preserve identity-less historical reporting.
  • Add offline verification of exported v1/v2 receipt JSONL without trusting the exported verdict.
  • Open audit and inspection commands read-only, without creating or migrating state databases.

Validation: complete short Go suite; voice-tagged suite; race checks for the new concurrency, storage, binding, and audit regressions; golangci-lint with zero new issues; configuration validation with zero errors; npm tests, package-content verification, and native launcher smoke tests; native builds for Linux, macOS, and Windows on amd64 and arm64.

Review notes: based on master at 741c2ec; no other open PRs were present when work started. Changes cover request admission, tool consumption, SQLite persistence, audit commands, tests, upgrade documentation, and release packaging. Provider integrations and the experimental cryptographic circuits are unchanged. Existing receipt signatures keep their v1/v2 formats. Start the engine once to migrate an older store before read-only inspection; existing v0.7.0 unconsumed permits need fresh approvals because the policy binding now includes operator authorization. Numeric token spelling is part of retry identity. Offline verification checks signed fields rather than export completeness or unsigned lifecycle metadata.

The package version is 0.8.0. A version-tag workflow verifies the release, builds native assets and checksums, publishes GitHub/GHCR artifacts, smoke-tests the native installer, and publishes npm with trusted publishing or an NPM_TOKEN. Publishing remains pending review and a version tag; npm publisher authentication must be configured before running the tag workflow.

@renezander030
renezander030 merged commit 7cafc50 into master Oct 1, 2026
1 check passed
@renezander030
renezander030 deleted the feat/v0.8.0-reliability branch October 1, 2026 12:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant