You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
feat(components): orchestrate signed extension registries - #39
replace reachability-only registry administration with pinned-root TUF configuration and full metadata verification
resolve signed external Use packages through trusted registries and bind registry identity, metadata versions, target identity, and archive digest into the umbrella plan
preserve signed registry provenance during update checks and upgrades, querying only the recorded registry and channel
delegate the exact reviewed package and inner registry-plan digest to A3S Use
select the existing ring provider explicitly for Codex TLS when the TUF dependency also brings AWS-LC into the process
Safety properties
registry refresh and dry-run never download package targets
apply recomputes and verifies the outer plan before delegation
Follow-up validation for f51fa9b completed in an isolated published-dependency mirror.
Additional hardening in this commit rejects symbolic-link and hard-link operation locks without truncating their targets, verifies lock identity/ownership on Unix, adds four regression tests, and splits the oversized command/plan modules.
A local x86_64-pc-windows-msvc cross-check was also attempted. It stopped while compiling aws-lc-sys because this macOS host has no Windows SDK (windows.h missing); no Rust diagnostic was emitted before that environment limitation.
Integrated through #40 at merge commit c252583e413f70a4cb265012d776f9d050b94de5. The consolidated v0.9.7 branch contains this PR's latest head f51fa9b78c970de76b43dc423981a182444b3775 and passed Linux, macOS, and Windows CI.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Safety properties
--allow-unsigned; local unsigned packages still require both explicit--fromand--allow-unsignedValidation
cargo fmt --all -- --checkcargo clippy --all-targets -- -D warningscargo check --workspace --all-targets --all-features --lockedcargo test --test remote_registry_components(3 passed, 1 real-Use E2E ignored)cargo test --test administration_contractcargo test --test component_commandscargo test --test component_lifecycleStack
1b2a60d9c8930dcc9935b6841ed4a7778111f884Batch journals, crash recovery, DeepResearch work, and unrelated checkpoint changes are intentionally excluded.