Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
439 commits
Select commit Hold shift + click to select a range
ce2090c
fix(agent): close RFC-64 persistence review gaps
Jul 19, 2026
d956e8b
refactor(agent): name RFC-64 root ownership generically
Jul 19, 2026
5f696a8
test(agent): split RFC-64 control store suites
Jul 19, 2026
3ac099a
fix(agent): preserve package manifest subpath
Jul 19, 2026
9846c30
fix(agent): close RFC-64 Windows persistence gaps
Jul 19, 2026
813d538
ci: trigger Windows RFC-64 split suites
Jul 19, 2026
258fa6d
Merge reviewed RFC-64 durable control-object store
Jul 19, 2026
a2cbc7a
fix(devnet): harden RFC-64 evidence boundaries
Jul 19, 2026
f802ee2
fix(devnet): close RFC-64 evidence review gaps
Jul 19, 2026
0947ad5
fix(devnet): harden RFC-64 evidence verification
Jul 19, 2026
eece163
test(agent): add RFC-64 Gate 0 lifecycle harness
Jul 19, 2026
414fd18
test(agent): harden RFC-64 Gate 0 evidence
Jul 19, 2026
1cc2963
test(agent): verify RFC-64 Gate 0 evidence
Jul 19, 2026
dee3979
test(agent): pin Gate 0 fixture evidence
Jul 19, 2026
06f0c03
test(agent): synchronize no-replace collision proof
Jul 19, 2026
895ae36
fix(agent): harden RFC-64 internal boundaries
Jul 19, 2026
9fbb9e0
test(agent): prove cross-platform Gate 0 shutdown
Jul 19, 2026
57f0042
test(rfc64): harden Gate 0 harness cleanup
Jul 19, 2026
8c8d7bb
fix(devnet): close RFC-64 evidence input boundaries
Jul 19, 2026
2c209ae
ci(rfc64): align Gate 0 integration coverage
Jul 19, 2026
7aa38c3
test(rfc64): bound Gate 0 process cleanup
Jul 19, 2026
12eaae3
fix(devnet): make evidence discovery cross-platform
Jul 19, 2026
9dda05e
ci(rfc64): build before Gate 0 typecheck
Jul 19, 2026
f110362
feat(agent): wire RFC-64 public catalog transport into DKGAgent (Gate 1)
Jul 19, 2026
3a88afc
feat(agent): add RFC-64 catalog content transport
Jul 19, 2026
4ace754
feat(agent): activate one RFC-64 catalog row in SWM
Jul 19, 2026
70e146f
fix(agent): authenticate RFC-64 native activation
Jul 19, 2026
b5ad0a4
feat(agent): add RFC-64 public catalog head transport
Jul 19, 2026
1f9119a
build(agent): classify RFC-64 catalog modules
Jul 19, 2026
283071c
fix(agent): reconcile RFC-64 heads from applied state
Jul 19, 2026
406e52e
fix(agent): serialize RFC-64 native activation
Jul 19, 2026
b60b07f
feat(agent): persist RFC-64 applied catalog heads
Jul 19, 2026
63ca51f
test(devnet): freeze RFC-64 Gate 1 evidence contract
Jul 19, 2026
b0c72e7
feat(agent): bootstrap RFC-64 public catalog genesis
Jul 19, 2026
ef875bf
test(agent): prove RFC-64 catalog service lifecycle
Jul 19, 2026
f84894c
feat(agent): persist RFC-64 catalog provider content
Jul 19, 2026
0cbde1d
feat(agent): produce verified RFC-64 catalog successor
Jul 19, 2026
d0a9559
fix(agent): authorize RFC-64 successor publication
Jul 19, 2026
e9432ba
feat(agent): adapt RFC-64 native catalog reconciliation
Jul 19, 2026
20cc4ee
test(agent): align inventory lifecycle with schema v2
Jul 19, 2026
2a36643
fix(agent): authorize RFC-64 native receiver rows
Jul 19, 2026
f3af914
test(agent): preserve public-open receiver composition
Jul 19, 2026
591ff32
feat(agent): authorize RFC-64 catalog genesis
Jul 19, 2026
5bf493b
fix(agent): lazily create RFC-64 KA bundle namespace
Jul 19, 2026
b7256e0
feat(agent): wire RFC-64 native catalog service
Jul 19, 2026
ad0c7a8
feat(agent): publish RFC-64 catalog successors
Jul 19, 2026
847eea3
test(devnet): require real RFC-64 Gate 1 processes
Jul 19, 2026
de6e68e
test(devnet): require unchanged state after forged catalog
Jul 19, 2026
26a7159
test(agent): align native wiring with signed genesis
Jul 19, 2026
80e6414
fix(agent): bind RFC-64 native authorization scope
Jul 19, 2026
19892c1
fix(agent): compose trusted RFC-64 catalog scope
Jul 19, 2026
0d43956
feat(agent): expose RFC-64 reconciliation failures
Jul 19, 2026
8f45ed2
test(devnet): drive Gate 1 through production APIs
Jul 19, 2026
1bb183f
fix(devnet): detach Gate 1 evidence snapshots
Jul 19, 2026
4979017
feat(core): add finalized VM set accumulator
Jul 19, 2026
19a159e
test(agent): close RFC-64 successor-producer Gate-1 coverage gaps
Jul 19, 2026
fc130d3
test(agent): budget Windows signature ceiling
Jul 19, 2026
62a6ae3
feat(agent): verify bounded RFC-64 inventory completeness
Jul 19, 2026
0ffc759
test(agent): expose exact RFC-64 bundle evidence
Jul 19, 2026
99cdde0
fix(agent): snapshot RFC-64 completeness evidence
Jul 19, 2026
bb44c45
feat(agent): produce bounded RFC-64 exact sets
Jul 19, 2026
5187061
feat(agent): apply bounded RFC-64 multi-asset heads
Jul 19, 2026
bffd3d5
feat(agent): bind multi-row dedupe to staged head
Jul 19, 2026
a161b74
feat(agent): remove omitted RFC-64 catalog assets
Jul 19, 2026
f980785
test(agent): prove exact RFC-64 stale removal
Jul 19, 2026
23c5a16
fix(core): harden finalized VM set boundaries
Jul 19, 2026
d5e8358
test(devnet): add RFC-64 Gate 2 multi-asset completeness evidence con…
Jul 19, 2026
fe3a314
fix(devnet): bind Gate 2 evidence to product inventory
Jul 19, 2026
2295e8f
feat(agent): expose exact successor evidence
Jul 19, 2026
adcdf13
fix(agent): derive evidence from signed successor
Jul 19, 2026
c916852
test(devnet): connect Gate 2 real-process harness
Jul 19, 2026
463b0af
fix(devnet): bind Gate 2 canonical projections
Jul 19, 2026
9405499
fix(devnet): serialize receiver KA identifiers
Jul 19, 2026
3d75c3a
fix(devnet): prove one-row transition durably
Jul 19, 2026
152b6ad
fix(devnet): verify domain-bound projection digests
Jul 19, 2026
97245b8
fix(agent): bound RFC-64 exact-set bundle memory
Jul 19, 2026
1be230e
fix(agent): unify RFC-64 inventory digests
Jul 19, 2026
bb9cfee
feat(agent): roll back failed RFC-64 transitions
Jul 19, 2026
97a3c1b
test(agent): prove RFC-64 transition rollback
Jul 19, 2026
d2bc11d
test(rfc64): harden Gate 2 live evidence
Jul 19, 2026
d8cad4e
feat(agent): classify RFC-64 policy cells
Jul 19, 2026
0470e6b
fix(agent): close RFC-64 policy cell contract
Jul 19, 2026
d2fd903
feat(agent): authorize RFC-64 catalog policy cells
Jul 19, 2026
9edec44
fix(agent): fail closed at RFC-64 catalog access boundary
Jul 19, 2026
3089e57
Merge pull request #1835 from OriginTrail/codex/rfc64-v2-catalog-acce…
branarakic Jul 21, 2026
4a24aed
feat(agent): authorize RFC-64 catalog transports by policy
Jul 21, 2026
ea05841
feat(agent): compose RFC-64 generic catalog authoring service/API (CP1)
Jul 21, 2026
d0e23c5
fix(sync): retry foreground catchup under backpressure
branarakic Jul 21, 2026
2bdc5fd
Merge pull request #1895 from OriginTrail/fix/catchup-backpressure-retry
branarakic Jul 21, 2026
10ff3cf
feat(publisher): job-scoped terminal cleanup for publisher + SWM shar…
Jurij89 Jul 21, 2026
0e5ba77
merge: align RFC-64 integration with v10.0.9 main
Jul 21, 2026
47b760f
fix(rfc64): harden catalog transport authorization
Jul 21, 2026
7f04335
Merge remote-tracking branch 'origin/codex/rfc64-v2-transport-policy-…
Jul 21, 2026
8d9fc21
Revert "feat(publisher): job-scoped terminal cleanup for publisher + …
Jul 21, 2026
ae48423
Revert "Merge pull request #1895 from OriginTrail/fix/catchup-backpre…
Jul 21, 2026
9722975
Merge PR #1877 into 10.0.10 Day-One canary candidate
Jul 21, 2026
311ab26
Merge PR #1898 into 10.0.10 Day-One canary candidate
Jul 21, 2026
850fa8b
Merge current main into 10.0.10 Day-One canary candidate
Jul 21, 2026
99d7183
fix(rfc64): harden policy-bound catalog authoring
Jul 21, 2026
c1c942b
Merge pull request #1903 from OriginTrail/codex/10.0.10-day-one-canar…
branarakic Jul 21, 2026
4901daa
Merge pull request #1900 from OriginTrail/codex/rfc64-main-sync-20260721
branarakic Jul 21, 2026
7d82e6b
test(devnet): checkpoint RFC-64 policy matrix harness
Jul 21, 2026
4c0ec42
Merge remote-tracking branch 'origin/integration/rfc64-devnet' into c…
Jul 21, 2026
669d4ce
Merge pull request #1881 from OriginTrail/codex/rfc64-v2-transport-po…
branarakic Jul 21, 2026
5219669
test(rfc64): prove public SWM policy parity
Jul 21, 2026
dd696e3
Merge pull request #1882 from OriginTrail/codex/rfc64-v2-generic-cata…
branarakic Jul 21, 2026
77a78f6
Merge remote-tracking branch 'origin/integration/rfc64-devnet' into c…
Jul 21, 2026
9ee1f39
Revert "test(devnet): checkpoint RFC-64 policy matrix harness"
Jul 21, 2026
5fa0f45
fix(sync): probe explicitly selected catchup peer
Jul 21, 2026
dd2d461
test(rfc64): close CP1 evidence schema
Jul 21, 2026
bce0781
Merge pull request #1906 from OriginTrail/codex/10.0.10-explicit-peer…
branarakic Jul 21, 2026
0a92c91
fix(sync): keep incomplete reconnect progress non-fresh
Jul 21, 2026
028eabe
fix(sync): preserve incomplete durable aggregate
Jul 21, 2026
0b26797
Merge pull request #1908 from OriginTrail/codex/10.0.10-reconnect-fre…
branarakic Jul 21, 2026
f0d00a3
test(rfc64): bind CP1 evidence to policy cells
Jul 22, 2026
71d6692
refactor(core): separate finalized VM row and frontier
Jul 22, 2026
7e05444
test(rfc64): bind CP1 evidence to current runtime
Jul 22, 2026
99555b6
refactor(core): narrow finalized VM set boundary
Jul 22, 2026
35e55a5
test(rfc64): centralize CP1 policy envelope
Jul 22, 2026
38ee8f4
refactor(core): share RFC64 network identifiers
Jul 22, 2026
8862f44
Merge pull request #1905 from OriginTrail/codex/rfc64-m1-policy-matrix
branarakic Jul 22, 2026
6149821
Merge pull request #1821 from OriginTrail/codex/rfc64-gate6-vm-parity
branarakic Jul 22, 2026
dbbdf8d
feat(chain): add fail-closed finalized Context Graph policy snapshot …
Jul 19, 2026
26a7aba
fix(chain): harden finalized policy snapshot
Jul 19, 2026
08a13a0
refactor(chain): model finalized policy as chain read
Jul 22, 2026
1cba82d
refactor(chain): validate finalized CG bindings
Jul 22, 2026
487cd9c
test(chain): isolate finalized policy invariants
Jul 22, 2026
9972774
fix(rfc64): centralize publish policy domain
Jul 22, 2026
3d1e3ab
refactor(rfc64): model publish domain as value
Jul 22, 2026
af409a1
feat(rfc64): add finalized policy snapshot seam (#1822)
branarakic Jul 22, 2026
5f1221c
feat(chain): add same-anchor finalized reads
Jul 22, 2026
06c3eac
fix(rfc64): harden finalized RPC transport
Jul 22, 2026
074f7e6
fix(chain): make exact record keys order-independent
Jul 22, 2026
a33634e
Re-land #1883: job-scoped terminal cleanup for publisher + SWM share …
Jurij89 Jul 22, 2026
06b6580
refactor(chain): consolidate finalized read boundary
Jul 22, 2026
bc4f14c
feat(chain): retain authenticated finalized revert data
Jul 22, 2026
2485751
refactor(chain): make finalized call policy transport-owned
Jul 22, 2026
3d35b7b
test(chain): share loopback JSON-RPC harness
Jul 22, 2026
5c6bb0f
fix(chain): preserve finalized gateway compatibility
Jul 22, 2026
6463a6a
refactor(publisher): promote clearTerminalJob single canonical payloa…
Jurij89 Jul 22, 2026
590f738
fix(chain): preserve finalized read failures
Jul 22, 2026
17d7c08
fix(chain): retain EIP-1271 router policy
Jul 22, 2026
d56a7c8
refactor(publisher): named VmPublisherControl contract + neutral job-…
Jurij89 Jul 22, 2026
e44d66f
test(publisher): consolidate the async-lift KA VM-publish fixture int…
Jurij89 Jul 22, 2026
f30c869
refactor(cli): shared request-body boundary for publisher admin route…
Jurij89 Jul 22, 2026
3af0ec0
Merge pull request #1909 from OriginTrail/codex/rfc64-m2-finalized-rpc
branarakic Jul 22, 2026
c00fef3
feat(rfc64): resolve finalized CG policy over RPC
Jul 22, 2026
59e0779
fix(chain): tighten finalized CG resolver seam
Jul 22, 2026
699e3e4
fix(chain): scope finalized CG return cap
Jul 22, 2026
a5e855b
refactor(chain): keep finalized CG decode untrusted
Jul 22, 2026
9514d30
fix(chain): map missing finalized context graph
Jul 22, 2026
2e57097
fix(chain): preserve finalized resolver compatibility
Jul 22, 2026
0bb67ca
test(chain): reuse loopback RPC harness
Jul 22, 2026
8f0690f
test(chain): use canonical loopback RPC harness
Jul 22, 2026
f29d869
feat(chain): add scoped finalized snapshot reads
Jul 22, 2026
de38910
fix(chain): bind snapshot batch settlement deadline
Jul 22, 2026
a2e79c5
fix(published-ka-sync): seek directly to public snapshot pages (#1873)
zsculac Jul 22, 2026
1ba7ced
fix(chain): authenticate snapshot batch state
Jul 22, 2026
c88cd68
fix(chain): centralize finalized snapshot anchor policy
Jul 22, 2026
bbfa00d
fix(chain): own unawaited snapshot read rejection
Jul 22, 2026
bf29337
refactor(chain): own finalized batch validation
Jul 22, 2026
223eb59
fix(agent): retry transient chain reads during durable sync (#1904)
Jurij89 Jul 22, 2026
76ab629
fix(chain): prove snapshot endpoint capability
Jul 22, 2026
6fe8da0
fix(chain): classify malformed deployed code as RPC failure
Jul 22, 2026
b5754bd
refactor(chain): share finalized RPC transport lifecycle
Jul 22, 2026
7ad1bf4
refactor(chain): tighten finalized RPC boundaries
Jul 22, 2026
7034d2b
refactor(chain): split finalized RPC transport boundaries
Jul 22, 2026
7142820
refactor(chain): decouple finalized endpoint profiles
Jul 22, 2026
273caf3
fix(chain): tighten finalized snapshot transport ownership
Jul 22, 2026
e941ea0
fix(chain): retain finalized snapshot deadlines
Jul 22, 2026
ec6d0a1
test(chain): close finalized snapshot RPC deadlines
Jul 22, 2026
dffa027
refactor(chain): centralize finalized anchor policy
Jul 22, 2026
d231855
refactor(chain): keep snapshot factory on internal types
Jul 22, 2026
a760dc8
feat(chain): scan finalized VM ordinals
Jul 22, 2026
9d4a37b
fix(chain): bind finalized VM authority evidence
Jul 22, 2026
2413f11
fix(chain): harden finalized VM scan admission
Jul 22, 2026
f322140
test(chain): close finalized VM scanner review gaps
Jul 22, 2026
4e4d4b9
fix(core): type rootless KA network namespace
Jul 22, 2026
1a8cc24
test(chain): prove finalized VM scan budget
Jul 22, 2026
dd287dd
fix(chain): preserve transferred KA author evidence
Jul 22, 2026
8031d88
test(chain): cover snapshot capability preflight
Jul 22, 2026
1f64ca0
feat(agent): compose authorized finalized VM placements
Jul 22, 2026
babae3f
fix(agent): close finalized VM composition proofs
Jul 22, 2026
d0e4f7b
fix(agent): preserve finalized VM public contracts
Jul 22, 2026
8fd9605
fix(rfc64): keep finalized VM boundaries canonical
Jul 22, 2026
3407ca0
refactor(chain): separate finalized VM inventory model
Jul 22, 2026
7a85ac2
fix(rfc64): preserve VM model boundaries
Jul 22, 2026
3993ec6
refactor(agent): localize attestation receiver adapter
Jul 22, 2026
33a898f
test(chain): enforce finalized VM snapshot row ceilings
Jul 22, 2026
085ba20
feat(agent): run finalized public VM composition
Jul 22, 2026
4e8354d
feat(agent): materialize finalized catalog VM rows
Jul 22, 2026
4808c67
feat(agent): apply finalized VM before catalog head
Jul 22, 2026
27a5898
test(agent): cover finalized RPC capability preflight
Jul 22, 2026
2c76b37
fix(agent): isolate finalized VM precommit boundaries
Jul 22, 2026
c8ad314
test(devnet): prove finalized public VM across processes
Jul 22, 2026
79ffde5
fix(rfc64): close finalized VM runtime review gaps
Jul 22, 2026
9f48276
test(rfc64): prove VM precommit withholds head CAS
Jul 22, 2026
079cc9b
refactor(rfc64): close finalized VM review gaps
Jul 22, 2026
36ef27e
test(rfc64): expose guarded mock CG fixture seam
Jul 22, 2026
a54d608
test(rfc64): share finalized VM loopback fixture
Jul 22, 2026
b76eb6d
refactor(publisher): type graph confirmation state
Jul 22, 2026
4513549
fix(agent): bind finalized VM reads to contract identity
Jul 22, 2026
cb91ce2
fix(agent): authenticate finalized VM durable sync
Jul 22, 2026
889fe48
fix(rfc64): make finalized sync provenance explicit
Jul 22, 2026
f202f16
fix(rfc64): harden finalized VM durable sync boundaries
Jul 22, 2026
f05c391
fix(rfc64): harden finalized VM trust boundaries
Jul 22, 2026
6150af9
fix(rfc64): close final M2 review gaps
Jul 22, 2026
568ee9e
refactor(rfc64): isolate graph metadata state
Jul 22, 2026
41b6896
Merge pull request #1911 from OriginTrail/codex/rfc64-m2-finalized-cg…
branarakic Jul 22, 2026
2571761
Merge pull request #1913 from OriginTrail/codex/rfc64-m2-pinned-final…
branarakic Jul 22, 2026
fbd8526
Merge pull request #1914 from OriginTrail/codex/rfc64-m2-finalized-vm…
branarakic Jul 22, 2026
b83cbdb
Merge pull request #1915 from OriginTrail/codex/rfc64-m2-vm-composition
branarakic Jul 22, 2026
de28577
Merge pull request #1920 from OriginTrail/codex/rfc64-m2-public-vm-ru…
branarakic Jul 22, 2026
8e68615
Merge origin/main into integration/rfc64-devnet
Jul 22, 2026
ed5e58d
feat(agent): add RFC-64 current-head discovery seam
Jul 19, 2026
d57a259
fix(agent): harden RFC-64 head discovery boundaries
Jul 19, 2026
082756b
fix(agent): harden RFC-64 head discovery review boundaries
Jul 22, 2026
901c0b5
fix(agent): close RFC-64 discovery review boundaries
Jul 22, 2026
60cc042
feat(agent): cold-start RFC-64 from provider head
Jul 22, 2026
bde373f
Merge remote-tracking branch 'origin/codex/rfc64-gate3-head-discovery…
Jul 22, 2026
214b926
fix(publisher): terminal-fail definitive pre-acceptance sends; typed …
Jurij89 Jul 22, 2026
da06062
fix(agent): close RFC-64 discovery trust boundaries
Jul 22, 2026
5f35e47
Merge remote-tracking branch 'origin/codex/rfc64-gate3-head-discovery…
Jul 22, 2026
fed78e7
fix(agent): generalize RFC-64 discovery policy boundary
Jul 22, 2026
ecf34a8
Merge pull request #1819 from OriginTrail/codex/rfc64-gate3-head-disc…
branarakic Jul 22, 2026
ca9093a
Merge remote-tracking branch 'origin/integration/rfc64-devnet' into c…
Jul 22, 2026
ad230c2
fix(agent): close RFC-64 cold-start review gaps
Jul 22, 2026
ee3a408
feat(agent): advance RFC-64 catalog after public publish
Jul 22, 2026
8bd257d
Merge branch 'codex/rfc64-m3-cold-start' into codex/rfc64-m3-auto-pub…
Jul 22, 2026
47f07e4
Merge pull request #1926 from OriginTrail/codex/rfc64-m3-cold-start
branarakic Jul 22, 2026
da125dc
fix(agent): harden RFC-64 public catalog bridge
Jul 22, 2026
053dbb1
feat(agent): bootstrap pinned RFC-64 public catalogs
Jul 22, 2026
aaf56ea
Merge commit 'da125dce3' into codex/rfc64-m3-bootstrap
Jul 22, 2026
1d1b38d
fix(agent): make first catalog upsert atomic
Jul 22, 2026
a1f93be
fix(agent): canonicalize RFC-64 publish bridge
Jul 22, 2026
0a8d22b
Merge branch 'codex/rfc64-m3-auto-publish' into codex/rfc64-m3-bootstrap
Jul 22, 2026
10ba00f
test(agent): prove RFC-64 public release convergence
Jul 22, 2026
1662837
Merge branch 'codex/rfc64-m3-bootstrap' into codex/rfc64-m3-release-p…
Jul 22, 2026
d981fcb
fix(agent): bind RFC-64 bootstrap manifests
Jul 22, 2026
30d38d5
Merge branch 'codex/rfc64-m3-bootstrap' into codex/rfc64-m3-release-p…
Jul 22, 2026
023e39d
test(agent): bind release proof bootstrap policy
Jul 22, 2026
22a27d4
Merge pull request #1927 from OriginTrail/codex/rfc64-m3-auto-publish
branarakic Jul 23, 2026
ab10382
test(agent): prove offline RFC-64 restart durability
Jul 23, 2026
bbb1a9b
fix(agent): reject ephemeral RFC-64 bootstrap
Jul 23, 2026
15688b4
Merge remote-tracking branch 'origin/codex/rfc64-m3-bootstrap' into c…
Jul 23, 2026
b2e6886
Merge pull request #1928 from OriginTrail/codex/rfc64-m3-bootstrap
branarakic Jul 23, 2026
1af4912
Merge pull request #1929 from OriginTrail/codex/rfc64-m3-release-proof
branarakic Jul 23, 2026
6641868
merge: compose RFC-64 public RC on testnet canary
Jul 23, 2026
151654d
fix(agent): stabilize public RC validation
Jul 23, 2026
65a3206
fix(core): canonicalize trailing zeros in linear time
Jul 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
115 changes: 115 additions & 0 deletions .github/workflows/rfc64-inventory-windows.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,115 @@
name: RFC-64 inventory Windows gate

on:
push:
branches:
- integration/rfc64-devnet
paths:
- '.github/workflows/rfc64-inventory-windows.yml'
- 'devnet/_bootstrap/package.json'
- 'devnet/_bootstrap/rdf-canonize.d.ts'
- 'devnet/_bootstrap/rfc64-evidence*'
- 'devnet/_bootstrap/tsconfig.evidence.json'
- 'devnet/_bootstrap/vitest.evidence.config.ts'
- 'devnet/rfc64-persistence-lifecycle/**'
- 'package.json'
- 'packages/agent/**'
- 'packages/chain/**'
- 'packages/core/**'
- 'packages/publisher/**'
- 'packages/query/**'
- 'packages/random-sampling/**'
- 'packages/rdf-utils/**'
- 'packages/storage/**'
- 'pnpm-lock.yaml'
- 'pnpm-workspace.yaml'
- 'tsconfig.base.json'
pull_request:
paths:
- '.github/workflows/rfc64-inventory-windows.yml'
- 'devnet/_bootstrap/package.json'
- 'devnet/_bootstrap/rdf-canonize.d.ts'
- 'devnet/_bootstrap/rfc64-evidence*'
- 'devnet/_bootstrap/tsconfig.evidence.json'
- 'devnet/_bootstrap/vitest.evidence.config.ts'
- 'devnet/rfc64-persistence-lifecycle/**'
- 'package.json'
- 'packages/agent/**'
- 'packages/chain/**'
- 'packages/core/**'
- 'packages/publisher/**'
- 'packages/query/**'
- 'packages/random-sampling/**'
- 'packages/rdf-utils/**'
- 'packages/storage/**'
- 'pnpm-lock.yaml'
- 'pnpm-workspace.yaml'
- 'tsconfig.base.json'
workflow_dispatch:

concurrency:
group: rfc64-inventory-windows-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
inventory-lifecycle:
name: SQLite lifecycle (Windows)
runs-on: windows-latest
timeout-minutes: 40
steps:
- name: Checkout candidate
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false

- name: Install pnpm
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4.3.0

- name: Set up Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: 22
cache: pnpm

- name: Install dependencies
run: pnpm install --frozen-lockfile

- name: Typecheck RFC-64 evidence harness
run: pnpm typecheck:devnet:rfc64-evidence

- name: Test RFC-64 evidence harness
run: pnpm test:devnet:rfc64-evidence

- name: Build agent dependency closure
run: pnpm --filter @origintrail-official/dkg-agent... run build

- name: Strict-typecheck Gate 0 lifecycle harness
run: pnpm typecheck:gate0:rfc64-persistence-lifecycle

- name: Run Gate 0 production persistence lifecycle
# Nine sequential 60s process bounds plus bounded forced-close cleanup
# fit below 10m; reserve additional time for the build and verifier.
timeout-minutes: 20
run: pnpm test:gate0:rfc64-persistence-lifecycle

- name: Typecheck the lifecycle crash harness
run: >-
pnpm exec tsc --noEmit --target ES2022 --module NodeNext
--moduleResolution NodeNext --types node,vitest/globals --skipLibCheck
packages/agent/test/rfc64-inventory-v1-lifecycle.test.ts
packages/agent/test/fixtures/rfc64-inventory-v1-child.ts

- name: Run RFC-64 inventory tests
run: >-
pnpm --filter @origintrail-official/dkg-agent exec vitest run
--config vitest.unit.config.ts
test/rfc64-inventory-v1
test/rfc64-agent-inventory-lifecycle.test.ts
test/rfc64-author-catalog-producer.test.ts
test/rfc64-control-object-store-v1.test.ts
test/rfc64-control-object-store-lifecycle-v1.test.ts
test/rfc64-durable-file-store-v1.test.ts
test/rfc64-secure-filesystem-policy-v1.test.ts
99 changes: 99 additions & 0 deletions devnet/_bootstrap/RFC64_EVIDENCE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,99 @@
# RFC-64 deterministic devnet evidence

`rfc64-evidence.ts` is a protocol-independent evidence layer for RFC-64 Gate 0+
devnet harnesses. It does not discover peers, transfer data, retry operations,
or modify runtime sync behavior. A harness supplies the expected and observed
Knowledge Asset datasets after its own operation completes.

## Deterministic snapshot rules

1. UALs are parsed with `parseDeterministicKnowledgeAssetUal`, converted to the
canonical protocol spelling, rejected on duplicate canonical identity, and
sorted lexically.
2. Received N-Quads are parsed row-by-row and projected to S/P/O before hashing;
physical graph placement is never part of semantic equality. Any duplicate
S/P/O row after projection is rejected instead of silently deduplicated.
3. The placement-neutral dataset is canonicalized with RDFC-1.0, sorted
lexically, joined with LF, and terminated by one LF when non-empty.
4. `ualsSha256` is SHA-256 over the sorted UAL list (`UAL + LF` per entry).
5. Each `semanticNQuadsSha256` is SHA-256 over that KA's exact canonical
N-Quads UTF-8 bytes.
6. The snapshot-level semantic digest is SHA-256 over the domain string
`rfc64-semantic-nquads-manifest/v1\n` followed by stable JSON containing the
sorted `(UAL, quadCount, per-KA digest)` manifest.
7. Stable JSON recursively sorts object keys and rejects sparse/custom arrays,
accessors, symbols, hidden properties, custom prototypes, lossy values, and
non-finite numbers. An own `__proto__` key remains ordinary JSON data.

Snapshots contain KA and quad counts plus exact digests, without embedding the
potentially large N-Quads payload. Validation recomputes every redundant count
and manifest digest before comparison. Duplicate UALs, malformed snapshots,
missing KAs, unexpected KAs, count differences, and digest differences cannot
produce a passing comparison.

Created and validated snapshots are defensively copied and deeply frozen. Run
evidence closes over its own frozen expected/observed copies, so later caller
mutation cannot change a previously derived `passed` result. Public constructors
capture caller-owned records and arrays exactly once through data descriptors;
proxies, accessors, sparse/custom arrays, and custom containers are rejected
before caller code can affect validation. String timestamps must carry `Z` or an
explicit UTC offset, contain a real Gregorian calendar instant, and use at most
millisecond fractional precision. Timestamp inputs are exactly primitive strings
or genuine non-proxy `Date` objects. Dates are read through the intrinsic
`Date.prototype.getTime` and normalized through a fresh `Date`; durations must be
non-negative safe integers. Emitted timestamps use canonical UTC form.

The run artifact adds the stable gate/observer label, selected source peer,
canonical ISO timing and duration, attempt/retry/failure details, expected and
observed snapshots, and the derived comparison. `passed` is derived from the
comparison and terminal failure; a caller cannot manually force it to `true`.
Artifact publication uses a same-directory exclusive temporary file, fsyncs
its contents, atomically renames it, and verifies the published bytes. POSIX
publication enforces mode 0600 and fsyncs the containing directory. Every
directory created for a nested artifact path is made durable through a
parent-directory fsync before it is used. The caller must provide a trusted,
static parent-directory topology for the full call. Node has no portable
directory-handle-relative `openat`/`renameat` surface, so path checks cannot
prevent a cooperating process from changing a parent between validation and
rename. Initial checks reject existing symlinks and post-operation checks provide
best-effort detection, but an error raised after rename can leave publication
side effects in the changed topology. On Windows, Node cannot fsync a directory
through its ordinary filesystem API and POSIX mode bits do not prove ACL
isolation, so the returned publication metadata explicitly reports
`file-flush-rename-no-directory-flush` and `windows-inherited-acl` instead of
claiming the stronger POSIX policies.

## Harness use

```ts
import {
createRfc64DevnetEvidence,
createRfc64SemanticSnapshot,
writeStableJsonArtifact,
} from '@origintrail-official/dkg-devnet-harness/rfc64-evidence';

const expected = await createRfc64SemanticSnapshot(expectedAssets);
const observed = await createRfc64SemanticSnapshot(observedAssets);
const evidence = createRfc64DevnetEvidence({
gate: 'gate-1-semantic-recovery',
observer: 'receiver-node-2',
sourcePeerId,
startedAt,
completedAt: new Date(),
attemptCount,
retryFailures,
terminalFailure: null,
expected,
observed,
});

writeStableJsonArtifact(artifactPath, evidence);
if (!evidence.passed) throw new Error('RFC-64 evidence gate failed');
```

Run the focused no-devnet verification with:

```sh
pnpm test:devnet:rfc64-evidence
pnpm typecheck:devnet:rfc64-evidence
```
10 changes: 7 additions & 3 deletions devnet/_bootstrap/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,13 +4,17 @@
"private": true,
"type": "module",
"exports": {
".": "./harness.ts"
".": "./harness.ts",
"./rfc64-evidence": "./rfc64-evidence.ts"
},
"scripts": {
"test:smoke": "vitest run --config vitest.config.ts"
"test:smoke": "vitest run --config vitest.config.ts",
"test:rfc64-evidence": "vitest run --config vitest.evidence.config.ts",
"typecheck:rfc64-evidence": "tsc --project tsconfig.evidence.json"
},
"dependencies": {
"ethers": "^6.16.0"
"ethers": "^6.16.0",
"rdf-canonize": "^5.0.0"
},
"devDependencies": {
"vitest": "^4.0.18"
Expand Down
33 changes: 33 additions & 0 deletions devnet/_bootstrap/rdf-canonize.d.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
declare module 'rdf-canonize' {
interface RdfTerm {
termType: 'NamedNode' | 'BlankNode' | 'Literal' | 'DefaultGraph';
value: string;
datatype?: RdfTerm;
language?: string;
}

interface RdfQuad {
subject: RdfTerm;
predicate: RdfTerm;
object: RdfTerm;
graph: RdfTerm;
}

interface CanonizeOptions {
algorithm: 'RDFC-1.0' | 'URDNA2015';
inputFormat?: 'application/n-quads';
format?: 'application/n-quads';
maxWorkFactor?: number;
}

interface RdfCanonize {
canonize(input: string, options: CanonizeOptions): Promise<string>;
NQuads: {
parse(nquads: string): RdfQuad[];
serialize(dataset: readonly RdfQuad[]): string;
};
}

const rdfCanonize: RdfCanonize;
export default rdfCanonize;
}
Loading
Loading