Skip to content

feat(components): orchestrate signed extension registries - #39

Closed
ZhiXiao-Lin wants to merge 5 commits into
recovery/code-use-first-usefrom
recovery/remote-extension-registry
Closed

ZhiXiao-Lin wants to merge 5 commits into
recovery/code-use-first-usefrom
recovery/remote-extension-registry

Conversation

@ZhiXiao-Lin

Copy link
Copy Markdown
Contributor

Summary

  • add deterministic review/apply component plans, exact release resolution, preflight checks, and cross-process component locks
  • replace reachability-only registry administration with pinned-root TUF configuration and full metadata verification
  • resolve signed external Use packages through trusted registries and bind registry identity, metadata versions, target identity, and archive digest into the umbrella plan
  • preserve signed registry provenance during update checks and upgrades, querying only the recorded registry and channel
  • delegate the exact reviewed package and inner registry-plan digest to A3S Use
  • select the existing ring provider explicitly for Codex TLS when the TUF dependency also brings AWS-LC into the process

Safety properties

  • registry refresh and dry-run never download package targets
  • apply recomputes and verifies the outer plan before delegation
  • ambiguous package sources, registry identity drift, expired metadata, root mismatch, rollback, and semantic-version downgrade fail closed
  • signed installs reject --allow-unsigned; local unsigned packages still require both explicit --from and --allow-unsigned
  • an unchanged signed target converges without download or activation

Validation

  • cargo fmt --all -- --check
  • standalone CI graph: cargo clippy --all-targets -- -D warnings
  • cargo check --workspace --all-targets --all-features --locked
  • cargo test --test remote_registry_components (3 passed, 1 real-Use E2E ignored)
  • cargo test --test administration_contract
  • cargo test --test component_commands
  • cargo test --test component_lifecycle
  • registry unit tests and Codex real-wire TLS regression tests

Stack

Batch journals, crash recovery, DeepResearch work, and unrelated checkpoint changes are intentionally excluded.

@ZhiXiao-Lin

Copy link
Copy Markdown
Contributor Author

Follow-up validation for f51fa9b completed in an isolated published-dependency mirror.

Additional hardening in this commit rejects symbolic-link and hard-link operation locks without truncating their targets, verifies lock identity/ownership on Unix, adds four regression tests, and splits the oversized command/plan modules.

Validation:

  • cargo fmt --all -- --check
  • cargo test components::lock::tests — 4 passed
  • cargo clippy --all-targets -- -D warnings
  • cargo check --workspace --all-targets --all-features --locked
  • component unit tests — 29 passed
  • registry/use unit filter — 19 passed, 1 network test ignored
  • remote registry integration — 3 passed, 1 real-a3s-use E2E ignored
  • administration contract — 5 passed
  • component commands — 17 passed
  • component lifecycle — 6 passed
  • git diff --check

A local x86_64-pc-windows-msvc cross-check was also attempted. It stopped while compiling aws-lc-sys because this macOS host has no Windows SDK (windows.h missing); no Rust diagnostic was emitted before that environment limitation.

@ZhiXiao-Lin

Copy link
Copy Markdown
Contributor Author

Integrated through #40 at merge commit c252583e413f70a4cb265012d776f9d050b94de5. The consolidated v0.9.7 branch contains this PR's latest head f51fa9b78c970de76b43dc423981a182444b3775 and passed Linux, macOS, and Windows CI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant