Pin public_ci certified identities and pending latch

Keep the three certified consumer-backed rows by id, image, and
evidence. Allow at most one pending row, and only when it is the
upstream.json image.
This commit is contained in:
2026-08-18 14:24:49 -07:00
parent a0ee487f47
commit 88809aa98d

View File

@@ -13,30 +13,6 @@ class RepositoryTest < Minitest::Test
JSON.parse(File.read(File.join(ROOT, path))) JSON.parse(File.read(File.join(ROOT, path)))
end end
def assert_certified_public_target(target)
current = target.fetch("current_certification")
assert_equal "certified", current.fetch("status")
assert_match(/\A[0-9a-f]{40}\z/, current.fetch("client_commit"))
assert_match(/\A[0-9a-f]{40}\z/, current.fetch("rails_commit"))
assert_equal current.fetch("expected_text"), current.fetch("full_text")
assert_equal 1, current.fetch("llm_request_count")
assert_path_exists File.join(ROOT, current.fetch("evidence"))
previous = target["previous_certification"]
return unless previous
assert_equal "certified", previous.fetch("status")
assert_match(/\A[0-9a-f]{40}\z/, previous.fetch("client_commit"))
assert_equal previous.fetch("expected_text"), previous.fetch("full_text")
assert_equal 1, previous.fetch("llm_request_count")
end
def assert_pending_public_target(target)
refute target.key?("current_certification")
refute target.key?("previous_certification")
assert_empty target.fetch("consumers")
assert_empty target.fetch("required_consumer_profiles")
end
def test_every_json_document_parses def test_every_json_document_parses
paths = Dir.glob(File.join(ROOT, "{evidence,fixtures,manifests,profiles}/**/*.json")) paths = Dir.glob(File.join(ROOT, "{evidence,fixtures,manifests,profiles}/**/*.json"))
refute_empty paths refute_empty paths
@@ -73,16 +49,65 @@ class RepositoryTest < Minitest::Test
assert_equal ["ruby-rest-sse"], target.fetch("profiles") assert_equal ["ruby-rest-sse"], target.fetch("profiles")
assert_equal "shared-client-contract-only", assert_equal "shared-client-contract-only",
target.fetch("certification_scope", "shared-client-contract-only") target.fetch("certification_scope", "shared-client-contract-only")
case target.fetch("certification_status") assert_includes %w[certified pending], target.fetch("certification_status")
when "certified" end
assert_certified_public_target(target)
when "pending" certified_rows = targets.select { |target| target.fetch("certification_status") == "certified" }
assert_pending_public_target(target) assert_equal %w[upstream-1.16.1 upstream-1.17.18 upstream-1.18.3],
else certified_rows.map { |target| target.fetch("id") }.sort
flunk "#{target.fetch("id")} certification_status must be pending or certified" certified = certified_rows.to_h { |target| [target.fetch("id"), target] }
end
travelwolf = certified.fetch("upstream-1.16.1")
assert_equal "ghcr.io/anomalyco/opencode@sha256:e975a0647576016dfdf77d54b979ca30d32b4750472c10263e9894aad6628c2a",
travelwolf.fetch("image")
assert_equal ["travelwolf"], travelwolf.fetch("consumers")
assert_equal ["rails-persisted-turn"], travelwolf.fetch("required_consumer_profiles")
assert_equal "9277646a4bb2cf25a8384ffc140b154f49ea5766",
travelwolf.dig("current_certification", "client_commit")
assert_equal "evidence/2026-07-20-opencode-alpha8-shared-client-ci.json",
travelwolf.dig("current_certification", "evidence")
ajent_plugin = certified.fetch("upstream-1.17.18")
assert_equal "ghcr.io/anomalyco/opencode@sha256:bf9d0e84b7cedef436a8f57db4d48767cd5d8fc6604f666335c1cc916b199a97",
ajent_plugin.fetch("image")
assert_equal ["opencode-ajent"], ajent_plugin.fetch("consumers")
assert_equal ["plugin-ledger"], ajent_plugin.fetch("required_consumer_profiles")
assert_equal "9277646a4bb2cf25a8384ffc140b154f49ea5766",
ajent_plugin.dig("current_certification", "client_commit")
assert_equal "evidence/2026-07-20-opencode-alpha8-shared-client-ci.json",
ajent_plugin.dig("current_certification", "evidence")
ajent_rails = certified.fetch("upstream-1.18.3")
assert_equal "ghcr.io/anomalyco/opencode@sha256:c2d5d6398df72aac85cb1bdc8f900c71a9b75a33fb7c0a76dc1484e4b126e41e",
ajent_rails.fetch("image")
assert_equal ["ajent-rails"], ajent_rails.fetch("consumers")
assert_equal ["rails-persisted-turn", "plugin-ledger"],
ajent_rails.fetch("required_consumer_profiles")
assert_equal "9277646a4bb2cf25a8384ffc140b154f49ea5766",
ajent_rails.dig("current_certification", "client_commit")
assert_equal "evidence/2026-07-20-opencode-alpha8-shared-client-ci.json",
ajent_rails.dig("current_certification", "evidence")
certified.each_value do |target|
current = target.fetch("current_certification")
assert_equal "certified", current.fetch("status")
assert_equal "a9add2a7c1dd3eb978aa8b4ebf9ef7e111d1057f", current.fetch("rails_commit")
assert_equal current.fetch("expected_text"), current.fetch("full_text")
assert_equal 1, current.fetch("llm_request_count")
assert_path_exists File.join(ROOT, current.fetch("evidence"))
end
pending = targets.select { |target| target.fetch("certification_status") == "pending" }
assert_operator pending.length, :<=, 1
upstream_image = json("manifests/upstream.json").fetch("image")
assert_equal 1, targets.count { |target| target.fetch("image") == upstream_image }
pending.each do |target|
assert_equal upstream_image, target.fetch("image")
refute target.key?("current_certification")
refute target.key?("previous_certification")
assert_empty target.fetch("consumers")
assert_empty target.fetch("required_consumer_profiles")
end end
assert targets.any? { |target| target.fetch("certification_status") == "certified" }
end end
def test_candidate_client_train_is_lockstep_and_bound_to_unpublished_commits def test_candidate_client_train_is_lockstep_and_bound_to_unpublished_commits