argand-site-registry/docs/VALIDATION.md
nicweyand 3e0cc1bc50
Some checks failed
Standalone registry checks / check (push) Has been cancelled
release: add Web Graph authority evidence for v0.6
2026-09-22 08:25:24 -04:00

264 lines
15 KiB
Markdown

# Validation
# Version 0.6.0 Web Graph and updater validation, 2026-09-22
The evaluation contract was written before implementation. The new Common Crawl
domain-rank integration passed five default integration tests; its sixth test is
an explicit resource benchmark. The benchmark parsed 100,000 valid provider-shaped
rows, retained exactly one identity-matched domain, and completed in 0.52 seconds
of test time. The enclosing warm Cargo process used 79,944 KiB peak RSS, wrote
9,136 filesystem blocks, and used no swap on the development machine. These are
engineering bounds, not a full 2 GiB provider-object throughput claim.
`scripts/check.sh` passed after the v0.6 version and Rustls lockfile updates. It
covered formatting, offline all-target checks, strict Clippy, all Rust and CLI
tests, documentation, Python release-package tests, and native/Python consumer
parity. The focused graph suite proves full-stream schema/value validation,
source-line provenance, gzip authentication, exact URL allowlisting, deterministic
builds, compact candidate-domain selection, and zero route authorization from
rank evidence.
The networked `cargo audit --deny warnings` gate initially detected
RUSTSEC-2026-0285 in Rustls 0.23.43. The lockfile was updated to Rustls 0.23.45;
the repeated audit passed with no findings.
## Version 0.5.0 release and security validation, 2026-09-13
Implementation commit: `557ba7cd6982b02754d34fb99cba5a116f78f153`, signed by
Nic Weyand. Version 0.5 adds the ROR 2.1 adapter, source-bound provider checksums,
explicit source lineage, multiline Wikidata dump and JSON-delta replay, compact
runtime generations with authenticated external audit bundles, signed retention
checkpoints, lineage-aware evaluation reports and a bounded benchmark harness.
Writer stores retain schema version 5; source manifests advance to v3 and compact
generation receipts to v3.
Linux x86_64 with Rust/Cargo 1.98.1 and Python 3.14.7 passed:
- Formatting, locked all-target compilation, Clippy with warnings denied, strict
API documentation, all 70 Rust tests and all 10 Python tests.
- Native CLI, reusable Rust and Python consumer parity across the synthetic
fixture, including trust failures.
- Adversarial checks for ZIP member and expanded-size drift, multiline and large
Wikidata records, P856 tombstones, killed and disk-full imports, audit omission
and substitution, compact/full equivalence, receipt selection mismatches,
retention signatures, benchmark output exhaustion and no-clobber publication.
- `cargo audit --deny warnings` scanned 1,243 RustSec advisories across 277 locked
dependency nodes without a finding. The final security review found no unresolved
critical, high or medium issue in its reviewed scope; see
[SECURITY-REVIEW-0.5.md](SECURITY-REVIEW-0.5.md).
Two source packages from the clean implementation commit were byte identical.
Receipt pin:
`51dff46d846bbfe794fb33d507a694ac15fbc899591e5515d33d114db3bee553`.
Archive SHA-256:
`63a0571061385a36197beabadfd4c29e3d15bb5948570bea74b04cfb3f784abc`.
The receipt verifier accepted both copies. The archive was extracted outside the
repository without Git metadata and passed the complete acceptance gate again.
[Hosted Forgejo Actions run 9](https://git.argand.org/nicweyand/argand-site-registry/actions/runs/9)
passed the exact implementation commit on the isolated registry runner. It fetched
the public revision without credentials, ran the offline acceptance gate, compared
and verified two deterministic source packages, extracted one without Git metadata,
and passed the complete gate again from that source tree. The runner has no dataset,
reviewer, signing or activation authority.
A separate real-provider canary used ROR release `v2.12-2026-08-25` from Zenodo
record `22099990` and the same-day Public Suffix List. The 36,246,232-byte ROR ZIP
had SHA-256
`5779c7baf71771fd8ea829201e7bd4343a3c68ff36c595f480b3a00292f78931`
and provider-bound MD5 `ce8807691455d4ada3216c31408e9e1a`. It expanded to
362,619,018 bytes and imported 137,398 records with 914,439 facts in 62.30 seconds,
using 25,032 KiB peak RSS. Exact replay produced zero changes. A deliberately
killed import resumed from its last committed checkpoint and converged on the same
record and fact totals.
The resulting compact registry contained 137,398 entities, 131,591 properties,
133,398 edges and 169 rejected facts. Its generation pin was
`b4f639e3d4f759833914a34aded2389442eeca142952d78fb7f66343f6f4224d`.
The 824,705,024-byte compact database was 38.69% smaller than the full audit-bearing
database. Two compact builds were byte identical. Full verification covered
686,468,048 audit bytes, 137,399 source records and 914,440 facts. A 1,000-case
evaluation produced 1,000 expected safe abstentions with 72 microsecond median and
96 microsecond p95 lookup latency. These single-machine import and warm-read
measurements characterize this release canary, not production serving capacity;
see [BENCHMARKING.md](BENCHMARKING.md).
The final inventory was reviewed for credentials, private paths, datasets,
generated artifacts, unsafe Rust and unrelated changes. Provider data, generated
registries and audit bundles remain outside Git. No production review or signing
key was used, and no Argand source tree, build cache, service or public route was
changed during implementation or validation.
## Version 0.4.0 release and security validation, 2026-09-13
Implementation commit: `e26efc19fa7f73e63cd98cb32b446d1fe10eed40`, signed by
Nic Weyand. Version 0.4 completes plan phases 0 through 2: typed source coverage,
granular name/edge/equivalence trust, authenticated quorum votes, structured
observation batches, a bounded candidate observer, deterministic review queues,
drift classification, sticky revocation, and publisher-signed emergency feeds.
Writer stores migrate to schema version 5 and `argand.site-rules/v4`.
Linux x86_64 with Rust/Cargo 1.98.1 and Python 3.14.7 passed:
- Formatting, locked all-target compilation, Clippy with warnings denied, strict
API documentation, all 61 Rust tests and all eight Python source-release tests.
- Native CLI, reusable Rust and Python consumer parity across the five-source
synthetic fixture, including trust failures.
- The strict two-reviewer acceptance flow from source assertions through separate
name, edge and equivalence votes, observation replay, evidence invalidation,
drift, revocation, signed release, emergency-feed application, explicit
reinstatement, and policy-epoch revocation retention.
- Adversarial coverage for source-coverage forks and gaps, signature tampering,
future and expired decisions, duplicated physical reviewer keys, publisher key
reuse, stale and cross-generation revocation feeds, late observation inserts,
SSRF address classes, redirect loops, compressed bodies, extraction limits and
a deterministic 512-case parser mutation corpus.
- `cargo audit --deny warnings` scanned 1,243 RustSec advisories across 272 locked
dependencies without a finding. `systemd-analyze verify` accepted the observer
units; its sole output was an unrelated warning from the host's installed
`arch-audit.service`.
Two source packages from the clean signed implementation commit were byte
identical. Receipt pin:
`a1614fcd44c91c5d842d2c391b2d31f530ab2fceed295aab834612cd885f8a19`.
Archive SHA-256:
`d260bfce000cc1d2e6fb81db4f9fda4a4b0727a729af1cab761fc46bda53bb17`.
The receipt verifier accepted both copies. The archive was extracted outside the
repository without Git metadata and passed the complete acceptance gate again.
The final inventory was reviewed for credentials, private paths, datasets,
generated artifacts, unsafe Rust and unrelated changes. The 0.4 security review
found and fixed seven issues before release; no known critical, high or medium
finding remains in its reviewed scope. See
[SECURITY-REVIEW-0.4.md](SECURITY-REVIEW-0.4.md).
No provider dataset was acquired or published, no production review or signing
key was used, and no Argand source tree, build cache, service or public route was
changed during implementation or validation.
## Version 0.3.0 security validation, 2026-09-13
Implementation commit: `9705b01fe4bca201220c22aed7aab10c17abbf1d`, signed by
Nic Weyand. This release closes the version 0.2 mutable-path, reviewer-trust,
resource-bound, compatibility and disclosure findings while preserving the
source/provenance/review architecture. Writer stores migrate to schema version 3
and `argand.site-rules/v3`.
Linux x86_64 with Rust/Cargo 1.98.1 and Python 3.14.7 passed:
- Formatting, locked all-target compilation, Clippy with warnings denied, strict
API documentation, all 38 Rust tests and all eight Python source-release tests.
- Native CLI, reusable Rust and Python consumer parity across the all-five-source
fixture, signed approval, activation, revocation and rollback refusal.
- Regression checks for post-open SQLite mutation, exact-stream import cleanup,
consumer reviewer-trust mismatch, reviewer validity epochs, v1 current-generation
activation, metadata-bound identity decisions, Curlie diff redaction and CrUX
job identity.
- `cargo audit --deny warnings` against 1,243 RustSec advisories reported no findings
in the 246 locked dependencies.
[Hosted Forgejo Actions run 4](https://git.argand.org/nicweyand/argand-site-registry/actions/runs/4)
passed the exact implementation commit in the isolated registry runner. It ran the
offline acceptance, produced two byte-identical source archives and receipts,
verified the receipt pin, extracted the archive without Git metadata and reran the
complete acceptance from that source tree. The runner had no dataset, reviewer,
signing or activation authority.
No provider data was acquired, no review or destination was promoted, and no
Argand source, build cache, service or public route was changed during this work.
## Version 0.2.0 release validation, 2026-09-13
Implementation commit: `e83f43d00f38fb1a8973316fc045ac4139069aaa`, signed by
Nic Weyand. This release hardens immutable generation reads and authenticated
review evidence, adds typed diffs and explicit resolution outcomes, and exposes
read-only audit and evaluation commands. Schema version 2 preserves legacy
review history but requires cryptographically authenticated decisions for release
signing.
Linux x86_64 with Rust/Cargo 1.98.1, Python 3.14.7 and two Cargo build jobs passed:
- Rust formatting, all-target compilation, Clippy with warnings denied, strict
API documentation and all 32 Rust tests.
- All eight Python source-release tests, Python and shell syntax checks,
ShellCheck, documentation links, and native CLI/Rust/Python consumer parity.
- Adversarial checks for unsigned SQLite WAL injection and generation symlinks,
unauthenticated or tampered reviewer evidence, reviewer identity and trust-file
mismatch, approval invalidation, revocation-only diffs, ambiguous identities,
confusable domain queries, malformed evaluation cases and observation scope.
- `cargo audit --deny warnings` with no vulnerabilities, unmaintained packages,
unsound packages or yanked dependencies reported.
The warm local acceptance run took 16.39 seconds with 1,140,856 KiB peak process
RSS. It produced 32 passing Rust tests and eight passing Python tests. These are
single-machine development measurements, not provider-scale import or serving
capacity claims.
[Hosted Forgejo Actions run 1](https://git.argand.org/nicweyand/argand-site-registry/actions/runs/1)
passed the exact implementation commit in 3 minutes 43 seconds. The repository-scoped
runner used image `argand-site-registry-ci@sha256:9dfad38312b7384839893225cd01835a6e8cb24c75e870fc959e460590be9c3d`,
built from the digest-pinned Rust 1.98.0 image declared in `ci/Dockerfile`. The
workflow fetched the public commit without credentials, ran acceptance, compared
two deterministic source archives and receipts, verified the receipt pin, then
reran acceptance from extracted source. The runner has no production mounts,
signing material or dataset-publishing authority.
No provider data was acquired, no reviewer decision or dataset generation was
created, and no Argand integration or production route was changed during this
release validation.
## Initial standalone validation, 2026-09-12
Implementation commit: `2a0fe1714b8ffb2e80203722bcb7987c630f432d`, signed by Nic Weyand.
The subsequent completion documentation changes no runtime or packaging code.
The baseline is Argand commit `47911062b00d87f215ba61c41965faf8a7f4b7f7`.
All extracted Rust, migration and provider-license bytes match UPSTREAM.json.
The extracted operator README changes only its working-directory instruction.
New files provide independent build metadata, examples, policy and release tooling.
The lockfile shrank from 642 packages to 246 with no new dependency versions.
## Acceptance
Linux x86_64, Rust/Cargo 1.98.1, Python 3.14, two Cargo build jobs. Passed:
- Rust formatting, all-target compilation and Clippy with warnings denied.
- All 23 Rust tests, zero failures or ignored tests; strict API documentation.
- Eight Python source-release tests, Python syntax checks, shell syntax and
ShellCheck for the check script and every workflow shell step.
- Native all-five-source fixture import, idempotency, alias lookup, explicit
identity joining, signed approval/activation, revocation and rollback refusal.
- Identical native CLI, Rust library example and Python example lookup envelopes,
including provenance, attribution and multiple regional properties. Every
consumer refused an incorrect generation pin.
- Two source archives and receipts from the implementation commit were byte-for-byte
identical. Receipt pin: `811af8fe2fd1e747b7745a44dba24e2397c01b43381e11846753e284caf6a275`.
- Full acceptance rerun from the verified archive outside the Git checkout, then
from `/tmp` to exclude the developer's ancestor Cargo configuration. Neither
extracted copy had a `.git` directory or accessed Argand's source tree.
The primary check took 28.24 seconds with 566,388 KiB peak process RSS after the
initial compiler check. A separate optimized build took 84.15 seconds with
602,340 KiB peak RSS. The archive check under `/tmp` took 101.64 seconds with
569,228 KiB peak RSS, including recompilation. These are local single-run toolchain
measurements, not serving-latency or full-provider capacity claims. Build output,
fixtures, disposable keys and detailed logs were retained outside the repository.
The final initial inventory was reviewed for credentials, private paths, datasets,
unrelated files and provenance loss. Source archives exclude private-key and dataset
extensions, symlinks, submodules, traversal paths and uncommitted changes. Tests
exercise receipt/archive tampering, duplicate JSON keys, unsafe members and
no-clobber output. All documentation links resolve locally.
### Operational state at initial publication
The code was independently buildable. The public Forgejo repository required
signed commits and restricts direct pushes and merges to the maintainer; review
rules applied to administrators. CI workflow commands were validated locally.
Actions was disabled pending a dedicated isolated runner, so the initial
validation made no hosted CI run or automatically produced remote artifact claim.
No provider dataset was newly acquired, no production approval was fabricated,
and no dataset timer, public Navigate route or registry generation was promoted.
Argand's live source/build window remained with its beta agent. Its embedded
registry dependency has not been replaced; docs/CONSUMERS.md describes cutover.