test: gate releases on enforced conformance and installed package checks
Some checks failed
CI Smoke / host-smoke (push) Successful in 2s
CI Smoke / pytest-smoke (push) Failing after 5s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 12:26:40 +02:00
parent a15fe032b0
commit 1ece969f59
6 changed files with 206 additions and 17 deletions

View file

@ -325,6 +325,28 @@ T01–T04 remain `progress`; issuer registration/MFA, owner-facts composition,
MCP consumer adoption, operation-outcome auditing and platform conformance remain
open. No production listener or entitlement changed.
## Conformance and CI continuation — 2026-09-28
Added enforcement-mode Tier 2/3 conformance journeys with signed IAM tokens and
explicit synthetic owners. Denial/revocation/outage cases exercise reads and
writes and verify unchanged business state after restoring access. Event
attribution is joined to recorded authorization decisions.
Forgejo now runs `make ci-check`: the complete ordinary test suite, access
inventory drift checks, distribution builds and an isolated installed-wheel
resource/import check. CI checks out the full commit into a unique temporary
directory and installs locked development/runtime dependencies. The optional
owner-source interoperability suite remains separately identified.
See [conformance documentation](../docs/conformance.md#access-enforcement-and-ci-gates).
Validation: local `make ci-check` passed with **330 tests**, one explicitly
optional owner-source module skipped, inventory coverage (165 Hub surfaces),
distribution builds and installed-wheel checks. Final locked runtime dependency
sync and workflow YAML/shell syntax checks also pass.
These are local source/release gates, not live platform or remote CI acceptance;
T01–T04 remain `progress` and T06 remains open.
## Acceptance checkpoints
- [x] Architecture/source/runtime review captured; new implementation owner is hub-core