Compare commits
6 Commits
8a90d1f46f
...
certify/up
| Author | SHA1 | Date | |
|---|---|---|---|
| 493421ad13 | |||
|
|
aed9ad3f90 | ||
| 88809aa98d | |||
| a0ee487f47 | |||
|
|
9006505cd2 | ||
| 755b9d2f0a |
4
.github/workflows/candidate.yml
vendored
4
.github/workflows/candidate.yml
vendored
@@ -304,9 +304,7 @@ jobs:
|
|||||||
test "$actual_client_sha" = "$EXPECTED_CLIENT_SHA"
|
test "$actual_client_sha" = "$EXPECTED_CLIENT_SHA"
|
||||||
echo "value=$actual_client_sha" >> "$GITHUB_OUTPUT"
|
echo "value=$actual_client_sha" >> "$GITHUB_OUTPUT"
|
||||||
- name: Resolve the private Docker host transport
|
- name: Resolve the private Docker host transport
|
||||||
run: |
|
run: echo "OPENCODE_PROBE_HOST=127.0.0.1" >> "$GITHUB_ENV"
|
||||||
probe_host="$(ruby scripts/private_default_gateway.rb)"
|
|
||||||
echo "OPENCODE_PROBE_HOST=$probe_host" >> "$GITHUB_ENV"
|
|
||||||
- name: Exercise the complete manifest matrix without artifact claims
|
- name: Exercise the complete manifest matrix without artifact claims
|
||||||
env:
|
env:
|
||||||
BUNDLE_GEMFILE: ${{ github.workspace }}/ruby-client/Gemfile
|
BUNDLE_GEMFILE: ${{ github.workspace }}/ruby-client/Gemfile
|
||||||
|
|||||||
59
evidence/2026-08-18-opencode-1.18.18-shared-client.json
Normal file
59
evidence/2026-08-18-opencode-1.18.18-shared-client.json
Normal file
@@ -0,0 +1,59 @@
|
|||||||
|
{
|
||||||
|
"schema_version": 1,
|
||||||
|
"kind": "shared-client-image-certification",
|
||||||
|
"status": "pass",
|
||||||
|
"certification_scope": "shared-client-contract-only",
|
||||||
|
"publication_state": "unpublished",
|
||||||
|
"clients": {
|
||||||
|
"opencode_ruby": {
|
||||||
|
"version": "0.0.1.alpha8",
|
||||||
|
"commit": "9277646a4bb2cf25a8384ffc140b154f49ea5766",
|
||||||
|
"executed": true
|
||||||
|
},
|
||||||
|
"opencode_rails": {
|
||||||
|
"version": "0.0.1.alpha8",
|
||||||
|
"commit": "a9add2a7c1dd3eb978aa8b4ebf9ef7e111d1057f",
|
||||||
|
"executed_by_image_contract": false
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"gitea_workflow": {
|
||||||
|
"run_id": "4055",
|
||||||
|
"run_attempt": 1,
|
||||||
|
"head_sha": "88809aa98dc6e76976bf42ba9ab28e86f1aca39b",
|
||||||
|
"repository": "ajaynomics/opencode-compat",
|
||||||
|
"run_url": "https://gitea.ajay.to/ajaynomics/opencode-compat/actions/runs/4055",
|
||||||
|
"completed_at": "2026-08-18T21:31:14Z",
|
||||||
|
"status": "pass",
|
||||||
|
"event": "workflow_dispatch",
|
||||||
|
"artifact_evidence_claimed": false
|
||||||
|
},
|
||||||
|
"reviewed_local_contract": {
|
||||||
|
"checked_at": "2026-08-18T22:07:51Z",
|
||||||
|
"kind": "shared-client-image-contract",
|
||||||
|
"status": "pass",
|
||||||
|
"platform": "linux/amd64",
|
||||||
|
"docker_image_id": "sha256:f3e00f8e25500150373c817e24b13f2f08e2ccd4cafd53dc3ad4827d47863b6f"
|
||||||
|
},
|
||||||
|
"exact_image_contracts": [
|
||||||
|
{
|
||||||
|
"id": "upstream-1.18.18-f3e00f8e25500150373c817e24b13f2f08e2ccd4cafd53dc3ad4827d47863b6f",
|
||||||
|
"checked_at": "2026-08-18T21:31:08Z",
|
||||||
|
"image": "ghcr.io/anomalyco/opencode@sha256:f3e00f8e25500150373c817e24b13f2f08e2ccd4cafd53dc3ad4827d47863b6f",
|
||||||
|
"reported_version": "1.18.18",
|
||||||
|
"status": "pass",
|
||||||
|
"expected_text": "compat-ok",
|
||||||
|
"full_text": "compat-ok",
|
||||||
|
"authoritative_assistant_message_count": 1,
|
||||||
|
"llm_request_count": 1,
|
||||||
|
"executed_profiles": ["ruby-rest-sse"],
|
||||||
|
"required_consumer_profiles": []
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"certified_at": "2026-08-18T22:08:30Z",
|
||||||
|
"limitations": [
|
||||||
|
"No GitHub artifact exists for this image. Gitea run 4055 executed the full exact-image matrix and claimed no durable artifacts.",
|
||||||
|
"The exact-image contract executes opencode-ruby, not opencode-rails.",
|
||||||
|
"Rails persistence and each consumer application profile remain unverified for this digest.",
|
||||||
|
"This certification does not promote any consumer runtime tuple."
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -102,6 +102,29 @@
|
|||||||
"full_text": "compat-ok",
|
"full_text": "compat-ok",
|
||||||
"llm_request_count": 1
|
"llm_request_count": 1
|
||||||
}
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "upstream-1.18.18-f3e00f8e25500150373c817e24b13f2f08e2ccd4cafd53dc3ad4827d47863b6f",
|
||||||
|
"version": "1.18.18",
|
||||||
|
"image": "ghcr.io/anomalyco/opencode@sha256:f3e00f8e25500150373c817e24b13f2f08e2ccd4cafd53dc3ad4827d47863b6f",
|
||||||
|
"tag_provenance": "ghcr.io/anomalyco/opencode:1.18.18",
|
||||||
|
"consumers": [],
|
||||||
|
"profiles": ["ruby-rest-sse"],
|
||||||
|
"required_consumer_profiles": [],
|
||||||
|
"certification_scope": "shared-client-contract-only",
|
||||||
|
"certification_status": "certified",
|
||||||
|
"current_certification": {
|
||||||
|
"status": "certified",
|
||||||
|
"client_commit": "9277646a4bb2cf25a8384ffc140b154f49ea5766",
|
||||||
|
"rails_commit": "a9add2a7c1dd3eb978aa8b4ebf9ef7e111d1057f",
|
||||||
|
"checked_at": "2026-08-18T21:31:08Z",
|
||||||
|
"expected_text": "compat-ok",
|
||||||
|
"full_text": "compat-ok",
|
||||||
|
"llm_request_count": 1,
|
||||||
|
"workflow_run_id": "4055",
|
||||||
|
"workflow_head_sha": "88809aa98dc6e76976bf42ba9ab28e86f1aca39b",
|
||||||
|
"evidence": "evidence/2026-08-18-opencode-1.18.18-shared-client.json"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"host_canary": [
|
"host_canary": [
|
||||||
|
|||||||
@@ -1,9 +1,9 @@
|
|||||||
{
|
{
|
||||||
"repository": "anomalyco/opencode",
|
"repository": "anomalyco/opencode",
|
||||||
"release_tag": "v1.18.3",
|
"release_tag": "v1.18.18",
|
||||||
"version": "1.18.3",
|
"version": "1.18.18",
|
||||||
"published_at": "2026-07-16T15:34:33Z",
|
"published_at": "2026-08-13T01:15:04Z",
|
||||||
"release_url": "https://github.com/anomalyco/opencode/releases/tag/v1.18.3",
|
"release_url": "https://github.com/anomalyco/opencode/releases/tag/v1.18.18",
|
||||||
"image": "ghcr.io/anomalyco/opencode@sha256:c2d5d6398df72aac85cb1bdc8f900c71a9b75a33fb7c0a76dc1484e4b126e41e",
|
"image": "ghcr.io/anomalyco/opencode@sha256:f3e00f8e25500150373c817e24b13f2f08e2ccd4cafd53dc3ad4827d47863b6f",
|
||||||
"observed_at": "2026-07-18T00:00:00Z"
|
"observed_at": "2026-08-18T19:30:00Z"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -49,21 +49,85 @@ class RepositoryTest < Minitest::Test
|
|||||||
assert_equal ["ruby-rest-sse"], target.fetch("profiles")
|
assert_equal ["ruby-rest-sse"], target.fetch("profiles")
|
||||||
assert_equal "shared-client-contract-only",
|
assert_equal "shared-client-contract-only",
|
||||||
target.fetch("certification_scope", "shared-client-contract-only")
|
target.fetch("certification_scope", "shared-client-contract-only")
|
||||||
assert_equal "certified", target.fetch("certification_status")
|
assert_includes %w[certified pending], target.fetch("certification_status")
|
||||||
|
end
|
||||||
|
|
||||||
|
certified_rows = targets.select { |target| target.fetch("certification_status") == "certified" }
|
||||||
|
assert_equal(
|
||||||
|
%w[
|
||||||
|
upstream-1.16.1
|
||||||
|
upstream-1.17.18
|
||||||
|
upstream-1.18.18-f3e00f8e25500150373c817e24b13f2f08e2ccd4cafd53dc3ad4827d47863b6f
|
||||||
|
upstream-1.18.3
|
||||||
|
],
|
||||||
|
certified_rows.map { |target| target.fetch("id") }.sort
|
||||||
|
)
|
||||||
|
certified = certified_rows.to_h { |target| [target.fetch("id"), target] }
|
||||||
|
|
||||||
|
travelwolf = certified.fetch("upstream-1.16.1")
|
||||||
|
assert_equal "ghcr.io/anomalyco/opencode@sha256:e975a0647576016dfdf77d54b979ca30d32b4750472c10263e9894aad6628c2a",
|
||||||
|
travelwolf.fetch("image")
|
||||||
|
assert_equal ["travelwolf"], travelwolf.fetch("consumers")
|
||||||
|
assert_equal ["rails-persisted-turn"], travelwolf.fetch("required_consumer_profiles")
|
||||||
|
assert_equal "9277646a4bb2cf25a8384ffc140b154f49ea5766",
|
||||||
|
travelwolf.dig("current_certification", "client_commit")
|
||||||
|
assert_equal "evidence/2026-07-20-opencode-alpha8-shared-client-ci.json",
|
||||||
|
travelwolf.dig("current_certification", "evidence")
|
||||||
|
|
||||||
|
ajent_plugin = certified.fetch("upstream-1.17.18")
|
||||||
|
assert_equal "ghcr.io/anomalyco/opencode@sha256:bf9d0e84b7cedef436a8f57db4d48767cd5d8fc6604f666335c1cc916b199a97",
|
||||||
|
ajent_plugin.fetch("image")
|
||||||
|
assert_equal ["opencode-ajent"], ajent_plugin.fetch("consumers")
|
||||||
|
assert_equal ["plugin-ledger"], ajent_plugin.fetch("required_consumer_profiles")
|
||||||
|
assert_equal "9277646a4bb2cf25a8384ffc140b154f49ea5766",
|
||||||
|
ajent_plugin.dig("current_certification", "client_commit")
|
||||||
|
assert_equal "evidence/2026-07-20-opencode-alpha8-shared-client-ci.json",
|
||||||
|
ajent_plugin.dig("current_certification", "evidence")
|
||||||
|
|
||||||
|
ajent_rails = certified.fetch("upstream-1.18.3")
|
||||||
|
assert_equal "ghcr.io/anomalyco/opencode@sha256:c2d5d6398df72aac85cb1bdc8f900c71a9b75a33fb7c0a76dc1484e4b126e41e",
|
||||||
|
ajent_rails.fetch("image")
|
||||||
|
assert_equal ["ajent-rails"], ajent_rails.fetch("consumers")
|
||||||
|
assert_equal ["rails-persisted-turn", "plugin-ledger"],
|
||||||
|
ajent_rails.fetch("required_consumer_profiles")
|
||||||
|
assert_equal "9277646a4bb2cf25a8384ffc140b154f49ea5766",
|
||||||
|
ajent_rails.dig("current_certification", "client_commit")
|
||||||
|
assert_equal "evidence/2026-07-20-opencode-alpha8-shared-client-ci.json",
|
||||||
|
ajent_rails.dig("current_certification", "evidence")
|
||||||
|
|
||||||
|
newest = certified.fetch(
|
||||||
|
"upstream-1.18.18-f3e00f8e25500150373c817e24b13f2f08e2ccd4cafd53dc3ad4827d47863b6f"
|
||||||
|
)
|
||||||
|
assert_equal "ghcr.io/anomalyco/opencode@sha256:f3e00f8e25500150373c817e24b13f2f08e2ccd4cafd53dc3ad4827d47863b6f",
|
||||||
|
newest.fetch("image")
|
||||||
|
assert_empty newest.fetch("consumers")
|
||||||
|
assert_empty newest.fetch("required_consumer_profiles")
|
||||||
|
assert_equal "9277646a4bb2cf25a8384ffc140b154f49ea5766",
|
||||||
|
newest.dig("current_certification", "client_commit")
|
||||||
|
assert_equal "evidence/2026-08-18-opencode-1.18.18-shared-client.json",
|
||||||
|
newest.dig("current_certification", "evidence")
|
||||||
|
assert_equal "2026-08-18T21:31:08Z", newest.dig("current_certification", "checked_at")
|
||||||
|
assert_equal "4055", newest.dig("current_certification", "workflow_run_id")
|
||||||
|
|
||||||
|
certified.each_value do |target|
|
||||||
current = target.fetch("current_certification")
|
current = target.fetch("current_certification")
|
||||||
assert_equal "certified", current.fetch("status")
|
assert_equal "certified", current.fetch("status")
|
||||||
assert_match(/\A[0-9a-f]{40}\z/, current.fetch("client_commit"))
|
assert_equal "a9add2a7c1dd3eb978aa8b4ebf9ef7e111d1057f", current.fetch("rails_commit")
|
||||||
assert_match(/\A[0-9a-f]{40}\z/, current.fetch("rails_commit"))
|
|
||||||
assert_equal current.fetch("expected_text"), current.fetch("full_text")
|
assert_equal current.fetch("expected_text"), current.fetch("full_text")
|
||||||
assert_equal 1, current.fetch("llm_request_count")
|
assert_equal 1, current.fetch("llm_request_count")
|
||||||
assert_path_exists File.join(ROOT, current.fetch("evidence"))
|
assert_path_exists File.join(ROOT, current.fetch("evidence"))
|
||||||
previous = target["previous_certification"]
|
end
|
||||||
next unless previous
|
|
||||||
|
|
||||||
assert_equal "certified", previous.fetch("status")
|
pending = targets.select { |target| target.fetch("certification_status") == "pending" }
|
||||||
assert_match(/\A[0-9a-f]{40}\z/, previous.fetch("client_commit"))
|
assert_operator pending.length, :<=, 1
|
||||||
assert_equal previous.fetch("expected_text"), previous.fetch("full_text")
|
upstream_image = json("manifests/upstream.json").fetch("image")
|
||||||
assert_equal 1, previous.fetch("llm_request_count")
|
assert_equal 1, targets.count { |target| target.fetch("image") == upstream_image }
|
||||||
|
pending.each do |target|
|
||||||
|
assert_equal upstream_image, target.fetch("image")
|
||||||
|
refute target.key?("current_certification")
|
||||||
|
refute target.key?("previous_certification")
|
||||||
|
assert_empty target.fetch("consumers")
|
||||||
|
assert_empty target.fetch("required_consumer_profiles")
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
@@ -170,6 +234,38 @@ class RepositoryTest < Minitest::Test
|
|||||||
assert evidence.fetch("limitations").any? { |entry| entry.include?("application profile") }
|
assert evidence.fetch("limitations").any? { |entry| entry.include?("application profile") }
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def test_v1_18_18_evidence_certifies_shared_client_only
|
||||||
|
evidence = json("evidence/2026-08-18-opencode-1.18.18-shared-client.json")
|
||||||
|
candidate = json("manifests/client-candidate.json").fetch("clients")
|
||||||
|
contract = evidence.fetch("exact_image_contracts").fetch(0)
|
||||||
|
target = json("manifests/image-matrix.json").fetch("public_ci")
|
||||||
|
.find { |row| row.fetch("version") == "1.18.18" }
|
||||||
|
|
||||||
|
assert_equal "pass", evidence.fetch("status")
|
||||||
|
assert_equal "shared-client-image-certification", evidence.fetch("kind")
|
||||||
|
assert_equal "shared-client-contract-only", evidence.fetch("certification_scope")
|
||||||
|
assert_equal "unpublished", evidence.fetch("publication_state")
|
||||||
|
refute evidence.key?("github_workflow")
|
||||||
|
assert_equal "4055", evidence.dig("gitea_workflow", "run_id")
|
||||||
|
assert_equal false, evidence.dig("gitea_workflow", "artifact_evidence_claimed")
|
||||||
|
assert_equal candidate.dig("opencode-ruby", "ref"), evidence.dig("clients", "opencode_ruby", "commit")
|
||||||
|
assert_equal candidate.dig("opencode-rails", "ref"), evidence.dig("clients", "opencode_rails", "commit")
|
||||||
|
assert_equal true, evidence.dig("clients", "opencode_ruby", "executed")
|
||||||
|
assert_equal false, evidence.dig("clients", "opencode_rails", "executed_by_image_contract")
|
||||||
|
assert_equal 1, evidence.fetch("exact_image_contracts").length
|
||||||
|
assert_equal target.fetch("id"), contract.fetch("id")
|
||||||
|
assert_equal target.fetch("image"), contract.fetch("image")
|
||||||
|
assert_equal target.dig("current_certification", "checked_at"), contract.fetch("checked_at")
|
||||||
|
assert_equal "2026-08-18T21:31:08Z", contract.fetch("checked_at")
|
||||||
|
assert_equal "compat-ok", contract.fetch("full_text")
|
||||||
|
assert_equal contract.fetch("expected_text"), contract.fetch("full_text")
|
||||||
|
assert_equal 1, contract.fetch("llm_request_count")
|
||||||
|
assert_equal 1, contract.fetch("authoritative_assistant_message_count")
|
||||||
|
assert_operator evidence.fetch("certified_at"), :>=, evidence.dig("gitea_workflow", "completed_at")
|
||||||
|
assert_operator evidence.fetch("certified_at"), :>=, evidence.dig("reviewed_local_contract", "checked_at")
|
||||||
|
assert evidence.fetch("limitations").any? { |entry| entry.include?("does not promote") }
|
||||||
|
end
|
||||||
|
|
||||||
def test_certified_migration_keeps_previous_tuple
|
def test_certified_migration_keeps_previous_tuple
|
||||||
tuples = json("manifests/runtime-tuples.json")
|
tuples = json("manifests/runtime-tuples.json")
|
||||||
return unless tuples.fetch("migration_state") == "certified"
|
return unless tuples.fetch("migration_state") == "certified"
|
||||||
@@ -381,8 +477,7 @@ class RepositoryTest < Minitest::Test
|
|||||||
assert_includes workflow, "exact-image-contract-gitea:"
|
assert_includes workflow, "exact-image-contract-gitea:"
|
||||||
assert_includes workflow, "if: github.server_url != 'https://github.com'"
|
assert_includes workflow, "if: github.server_url != 'https://github.com'"
|
||||||
assert_includes workflow, "run: scripts/run_image_matrix_contract.sh"
|
assert_includes workflow, "run: scripts/run_image_matrix_contract.sh"
|
||||||
assert_includes workflow, 'probe_host="$(ruby scripts/private_default_gateway.rb)"'
|
assert_includes workflow, 'echo "OPENCODE_PROBE_HOST=127.0.0.1" >> "$GITHUB_ENV"'
|
||||||
assert_includes workflow, 'echo "OPENCODE_PROBE_HOST=$probe_host" >> "$GITHUB_ENV"'
|
|
||||||
assert_operator workflow.scan('BUNDLE_GEMFILE: ${{ github.workspace }}/ruby-client/Gemfile').length, :>=, 2
|
assert_operator workflow.scan('BUNDLE_GEMFILE: ${{ github.workspace }}/ruby-client/Gemfile').length, :>=, 2
|
||||||
assert_operator workflow.scan("generated JSON is transient and is not review evidence").length, :>=, 3
|
assert_operator workflow.scan("generated JSON is transient and is not review evidence").length, :>=, 3
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user