All checks were successful
Standalone registry checks / check (push) Successful in 5m52s
242 lines
14 KiB
Markdown
242 lines
14 KiB
Markdown
# Validation
|
|
|
|
## Version 0.5.0 release and security validation, 2026-09-13
|
|
|
|
Implementation commit: `557ba7cd6982b02754d34fb99cba5a116f78f153`, signed by
|
|
Nic Weyand. Version 0.5 adds the ROR 2.1 adapter, source-bound provider checksums,
|
|
explicit source lineage, multiline Wikidata dump and JSON-delta replay, compact
|
|
runtime generations with authenticated external audit bundles, signed retention
|
|
checkpoints, lineage-aware evaluation reports and a bounded benchmark harness.
|
|
Writer stores retain schema version 5; source manifests advance to v3 and compact
|
|
generation receipts to v3.
|
|
|
|
Linux x86_64 with Rust/Cargo 1.98.1 and Python 3.14.7 passed:
|
|
|
|
- Formatting, locked all-target compilation, Clippy with warnings denied, strict
|
|
API documentation, all 70 Rust tests and all 10 Python tests.
|
|
- Native CLI, reusable Rust and Python consumer parity across the synthetic
|
|
fixture, including trust failures.
|
|
- Adversarial checks for ZIP member and expanded-size drift, multiline and large
|
|
Wikidata records, P856 tombstones, killed and disk-full imports, audit omission
|
|
and substitution, compact/full equivalence, receipt selection mismatches,
|
|
retention signatures, benchmark output exhaustion and no-clobber publication.
|
|
- `cargo audit --deny warnings` scanned 1,243 RustSec advisories across 277 locked
|
|
dependency nodes without a finding. The final security review found no unresolved
|
|
critical, high or medium issue in its reviewed scope; see
|
|
[SECURITY-REVIEW-0.5.md](SECURITY-REVIEW-0.5.md).
|
|
|
|
Two source packages from the clean implementation commit were byte identical.
|
|
Receipt pin:
|
|
`51dff46d846bbfe794fb33d507a694ac15fbc899591e5515d33d114db3bee553`.
|
|
Archive SHA-256:
|
|
`63a0571061385a36197beabadfd4c29e3d15bb5948570bea74b04cfb3f784abc`.
|
|
The receipt verifier accepted both copies. The archive was extracted outside the
|
|
repository without Git metadata and passed the complete acceptance gate again.
|
|
|
|
[Hosted Forgejo Actions run 9](https://git.argand.org/nicweyand/argand-site-registry/actions/runs/9)
|
|
passed the exact implementation commit on the isolated registry runner. It fetched
|
|
the public revision without credentials, ran the offline acceptance gate, compared
|
|
and verified two deterministic source packages, extracted one without Git metadata,
|
|
and passed the complete gate again from that source tree. The runner has no dataset,
|
|
reviewer, signing or activation authority.
|
|
|
|
A separate real-provider canary used ROR release `v2.12-2026-08-25` from Zenodo
|
|
record `22099990` and the same-day Public Suffix List. The 36,246,232-byte ROR ZIP
|
|
had SHA-256
|
|
`5779c7baf71771fd8ea829201e7bd4343a3c68ff36c595f480b3a00292f78931`
|
|
and provider-bound MD5 `ce8807691455d4ada3216c31408e9e1a`. It expanded to
|
|
362,619,018 bytes and imported 137,398 records with 914,439 facts in 62.30 seconds,
|
|
using 25,032 KiB peak RSS. Exact replay produced zero changes. A deliberately
|
|
killed import resumed from its last committed checkpoint and converged on the same
|
|
record and fact totals.
|
|
|
|
The resulting compact registry contained 137,398 entities, 131,591 properties,
|
|
133,398 edges and 169 rejected facts. Its generation pin was
|
|
`b4f639e3d4f759833914a34aded2389442eeca142952d78fb7f66343f6f4224d`.
|
|
The 824,705,024-byte compact database was 38.69% smaller than the full audit-bearing
|
|
database. Two compact builds were byte identical. Full verification covered
|
|
686,468,048 audit bytes, 137,399 source records and 914,440 facts. A 1,000-case
|
|
evaluation produced 1,000 expected safe abstentions with 72 microsecond median and
|
|
96 microsecond p95 lookup latency. These single-machine import and warm-read
|
|
measurements characterize this release canary, not production serving capacity;
|
|
see [BENCHMARKING.md](BENCHMARKING.md).
|
|
|
|
The final inventory was reviewed for credentials, private paths, datasets,
|
|
generated artifacts, unsafe Rust and unrelated changes. Provider data, generated
|
|
registries and audit bundles remain outside Git. No production review or signing
|
|
key was used, and no Argand source tree, build cache, service or public route was
|
|
changed during implementation or validation.
|
|
|
|
## Version 0.4.0 release and security validation, 2026-09-13
|
|
|
|
Implementation commit: `e26efc19fa7f73e63cd98cb32b446d1fe10eed40`, signed by
|
|
Nic Weyand. Version 0.4 completes plan phases 0 through 2: typed source coverage,
|
|
granular name/edge/equivalence trust, authenticated quorum votes, structured
|
|
observation batches, a bounded candidate observer, deterministic review queues,
|
|
drift classification, sticky revocation, and publisher-signed emergency feeds.
|
|
Writer stores migrate to schema version 5 and `argand.site-rules/v4`.
|
|
|
|
Linux x86_64 with Rust/Cargo 1.98.1 and Python 3.14.7 passed:
|
|
|
|
- Formatting, locked all-target compilation, Clippy with warnings denied, strict
|
|
API documentation, all 61 Rust tests and all eight Python source-release tests.
|
|
- Native CLI, reusable Rust and Python consumer parity across the five-source
|
|
synthetic fixture, including trust failures.
|
|
- The strict two-reviewer acceptance flow from source assertions through separate
|
|
name, edge and equivalence votes, observation replay, evidence invalidation,
|
|
drift, revocation, signed release, emergency-feed application, explicit
|
|
reinstatement, and policy-epoch revocation retention.
|
|
- Adversarial coverage for source-coverage forks and gaps, signature tampering,
|
|
future and expired decisions, duplicated physical reviewer keys, publisher key
|
|
reuse, stale and cross-generation revocation feeds, late observation inserts,
|
|
SSRF address classes, redirect loops, compressed bodies, extraction limits and
|
|
a deterministic 512-case parser mutation corpus.
|
|
- `cargo audit --deny warnings` scanned 1,243 RustSec advisories across 272 locked
|
|
dependencies without a finding. `systemd-analyze verify` accepted the observer
|
|
units; its sole output was an unrelated warning from the host's installed
|
|
`arch-audit.service`.
|
|
|
|
Two source packages from the clean signed implementation commit were byte
|
|
identical. Receipt pin:
|
|
`a1614fcd44c91c5d842d2c391b2d31f530ab2fceed295aab834612cd885f8a19`.
|
|
Archive SHA-256:
|
|
`d260bfce000cc1d2e6fb81db4f9fda4a4b0727a729af1cab761fc46bda53bb17`.
|
|
The receipt verifier accepted both copies. The archive was extracted outside the
|
|
repository without Git metadata and passed the complete acceptance gate again.
|
|
|
|
The final inventory was reviewed for credentials, private paths, datasets,
|
|
generated artifacts, unsafe Rust and unrelated changes. The 0.4 security review
|
|
found and fixed seven issues before release; no known critical, high or medium
|
|
finding remains in its reviewed scope. See
|
|
[SECURITY-REVIEW-0.4.md](SECURITY-REVIEW-0.4.md).
|
|
|
|
No provider dataset was acquired or published, no production review or signing
|
|
key was used, and no Argand source tree, build cache, service or public route was
|
|
changed during implementation or validation.
|
|
|
|
## Version 0.3.0 security validation, 2026-09-13
|
|
|
|
Implementation commit: `9705b01fe4bca201220c22aed7aab10c17abbf1d`, signed by
|
|
Nic Weyand. This release closes the version 0.2 mutable-path, reviewer-trust,
|
|
resource-bound, compatibility and disclosure findings while preserving the
|
|
source/provenance/review architecture. Writer stores migrate to schema version 3
|
|
and `argand.site-rules/v3`.
|
|
|
|
Linux x86_64 with Rust/Cargo 1.98.1 and Python 3.14.7 passed:
|
|
|
|
- Formatting, locked all-target compilation, Clippy with warnings denied, strict
|
|
API documentation, all 38 Rust tests and all eight Python source-release tests.
|
|
- Native CLI, reusable Rust and Python consumer parity across the all-five-source
|
|
fixture, signed approval, activation, revocation and rollback refusal.
|
|
- Regression checks for post-open SQLite mutation, exact-stream import cleanup,
|
|
consumer reviewer-trust mismatch, reviewer validity epochs, v1 current-generation
|
|
activation, metadata-bound identity decisions, Curlie diff redaction and CrUX
|
|
job identity.
|
|
- `cargo audit --deny warnings` against 1,243 RustSec advisories reported no findings
|
|
in the 246 locked dependencies.
|
|
|
|
[Hosted Forgejo Actions run 4](https://git.argand.org/nicweyand/argand-site-registry/actions/runs/4)
|
|
passed the exact implementation commit in the isolated registry runner. It ran the
|
|
offline acceptance, produced two byte-identical source archives and receipts,
|
|
verified the receipt pin, extracted the archive without Git metadata and reran the
|
|
complete acceptance from that source tree. The runner had no dataset, reviewer,
|
|
signing or activation authority.
|
|
|
|
No provider data was acquired, no review or destination was promoted, and no
|
|
Argand source, build cache, service or public route was changed during this work.
|
|
|
|
## Version 0.2.0 release validation, 2026-09-13
|
|
|
|
Implementation commit: `e83f43d00f38fb1a8973316fc045ac4139069aaa`, signed by
|
|
Nic Weyand. This release hardens immutable generation reads and authenticated
|
|
review evidence, adds typed diffs and explicit resolution outcomes, and exposes
|
|
read-only audit and evaluation commands. Schema version 2 preserves legacy
|
|
review history but requires cryptographically authenticated decisions for release
|
|
signing.
|
|
|
|
Linux x86_64 with Rust/Cargo 1.98.1, Python 3.14.7 and two Cargo build jobs passed:
|
|
|
|
- Rust formatting, all-target compilation, Clippy with warnings denied, strict
|
|
API documentation and all 32 Rust tests.
|
|
- All eight Python source-release tests, Python and shell syntax checks,
|
|
ShellCheck, documentation links, and native CLI/Rust/Python consumer parity.
|
|
- Adversarial checks for unsigned SQLite WAL injection and generation symlinks,
|
|
unauthenticated or tampered reviewer evidence, reviewer identity and trust-file
|
|
mismatch, approval invalidation, revocation-only diffs, ambiguous identities,
|
|
confusable domain queries, malformed evaluation cases and observation scope.
|
|
- `cargo audit --deny warnings` with no vulnerabilities, unmaintained packages,
|
|
unsound packages or yanked dependencies reported.
|
|
|
|
The warm local acceptance run took 16.39 seconds with 1,140,856 KiB peak process
|
|
RSS. It produced 32 passing Rust tests and eight passing Python tests. These are
|
|
single-machine development measurements, not provider-scale import or serving
|
|
capacity claims.
|
|
|
|
[Hosted Forgejo Actions run 1](https://git.argand.org/nicweyand/argand-site-registry/actions/runs/1)
|
|
passed the exact implementation commit in 3 minutes 43 seconds. The repository-scoped
|
|
runner used image `argand-site-registry-ci@sha256:9dfad38312b7384839893225cd01835a6e8cb24c75e870fc959e460590be9c3d`,
|
|
built from the digest-pinned Rust 1.98.0 image declared in `ci/Dockerfile`. The
|
|
workflow fetched the public commit without credentials, ran acceptance, compared
|
|
two deterministic source archives and receipts, verified the receipt pin, then
|
|
reran acceptance from extracted source. The runner has no production mounts,
|
|
signing material or dataset-publishing authority.
|
|
|
|
No provider data was acquired, no reviewer decision or dataset generation was
|
|
created, and no Argand integration or production route was changed during this
|
|
release validation.
|
|
|
|
## Initial standalone validation, 2026-09-12
|
|
|
|
Implementation commit: `2a0fe1714b8ffb2e80203722bcb7987c630f432d`, signed by Nic Weyand.
|
|
The subsequent completion documentation changes no runtime or packaging code.
|
|
|
|
The baseline is Argand commit `47911062b00d87f215ba61c41965faf8a7f4b7f7`.
|
|
All extracted Rust, migration and provider-license bytes match UPSTREAM.json.
|
|
The extracted operator README changes only its working-directory instruction.
|
|
New files provide independent build metadata, examples, policy and release tooling.
|
|
The lockfile shrank from 642 packages to 246 with no new dependency versions.
|
|
|
|
## Acceptance
|
|
|
|
Linux x86_64, Rust/Cargo 1.98.1, Python 3.14, two Cargo build jobs. Passed:
|
|
|
|
- Rust formatting, all-target compilation and Clippy with warnings denied.
|
|
- All 23 Rust tests, zero failures or ignored tests; strict API documentation.
|
|
- Eight Python source-release tests, Python syntax checks, shell syntax and
|
|
ShellCheck for the check script and every workflow shell step.
|
|
- Native all-five-source fixture import, idempotency, alias lookup, explicit
|
|
identity joining, signed approval/activation, revocation and rollback refusal.
|
|
- Identical native CLI, Rust library example and Python example lookup envelopes,
|
|
including provenance, attribution and multiple regional properties. Every
|
|
consumer refused an incorrect generation pin.
|
|
- Two source archives and receipts from the implementation commit were byte-for-byte
|
|
identical. Receipt pin: `811af8fe2fd1e747b7745a44dba24e2397c01b43381e11846753e284caf6a275`.
|
|
- Full acceptance rerun from the verified archive outside the Git checkout, then
|
|
from `/tmp` to exclude the developer's ancestor Cargo configuration. Neither
|
|
extracted copy had a `.git` directory or accessed Argand's source tree.
|
|
|
|
The primary check took 28.24 seconds with 566,388 KiB peak process RSS after the
|
|
initial compiler check. A separate optimized build took 84.15 seconds with
|
|
602,340 KiB peak RSS. The archive check under `/tmp` took 101.64 seconds with
|
|
569,228 KiB peak RSS, including recompilation. These are local single-run toolchain
|
|
measurements, not serving-latency or full-provider capacity claims. Build output,
|
|
fixtures, disposable keys and detailed logs were retained outside the repository.
|
|
|
|
The final initial inventory was reviewed for credentials, private paths, datasets,
|
|
unrelated files and provenance loss. Source archives exclude private-key and dataset
|
|
extensions, symlinks, submodules, traversal paths and uncommitted changes. Tests
|
|
exercise receipt/archive tampering, duplicate JSON keys, unsafe members and
|
|
no-clobber output. All documentation links resolve locally.
|
|
|
|
### Operational state at initial publication
|
|
|
|
The code was independently buildable. The public Forgejo repository required
|
|
signed commits and restricts direct pushes and merges to the maintainer; review
|
|
rules applied to administrators. CI workflow commands were validated locally.
|
|
Actions was disabled pending a dedicated isolated runner, so the initial
|
|
validation made no hosted CI run or automatically produced remote artifact claim.
|
|
|
|
No provider dataset was newly acquired, no production approval was fabricated,
|
|
and no dataset timer, public Navigate route or registry generation was promoted.
|
|
Argand's live source/build window remained with its beta agent. Its embedded
|
|
registry dependency has not been replaced; docs/CONSUMERS.md describes cutover.
|