Close HUB-WP-0009 conformance gaps (C2, C7, C9, C10); mark blocked workplans
Implements the four residual conformance checks left open by the T04
minimal vertical:
- C2: GET /ports/registry/registrations/{hub_slug} resolves missing (404),
ambiguous (shared reuse_surface_id across hub_slugs), and stale
(deprecated/retired descriptor) registrations; a new .../audit route
exposes queryable registration history from the existing in-memory
history and the PostgreSQL runtime_audit_ledger.
- C7: harness proof that disabled compatibility groups deny access
(404) with no fixture credentials involved, matching the existing
fail-closed compat router behavior.
- C9: harness proof plus a dedicated test that /readyz degrades only on
an unavailable configured dependency while unrelated disabled
projections stay non-blocking.
- C10: ContractValidator now negotiates contract_version_min/max against
the runtime's contract version and rejects incompatible or inverted
ranges with an explicit 422 instead of silently accepting them.
HUB-WP-0009 is now finished. HUB-WP-0006 is marked blocked: its only open
task (T06) has no remaining hub-core code path and waits on an external
Forgejo identity/production deployment gate. HUB-WP-0011 is marked
blocked: T02/T03 already waited on external credential/deployment
review, and T01 needs a source/destination ownership and retention
decision against live message data before it can be implemented safely.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 310936@bnt-lap001
Assistant-Session: 00cd9abe-09a0-416b-88e0-f907b9101629
This commit is contained in:
parent
b0e89592c6
commit
e89d621f18
11 changed files with 496 additions and 20 deletions
|
|
@ -23,7 +23,11 @@ hub-core conformance --base-url http://127.0.0.1:8010 --json
|
|||
| C4 | 2 | Repeated manifest registration is reported as a duplicate |
|
||||
| C5 | 2 | Cataloged progress/interaction events are accepted; wrong-family and unknown events are rejected |
|
||||
| C6 | 2 | Contract and scenario fixtures reject secret-shaped keys, credentialed database URLs, and private keys |
|
||||
| C7 | 2 | Disabled compatibility groups (`/api/v2/hubs`, `/console`) deny access without needing fixture credentials |
|
||||
| C8 | 2 | Registry response propagates the request correlation identifier |
|
||||
| C9 | 2 | `/readyz` reports each dependency (database, `port.repo` projection, workload projection, authorization) individually, only degrading when a configured dependency is unavailable or stale |
|
||||
| C10 | 2 | A registration whose `contract_version_min`/`contract_version_max` excludes the runtime's contract version is rejected with an explicit incompatibility error |
|
||||
| C2 | 2 | `GET /ports/registry/registrations/{hub_slug}` resolves missing (404) and ambiguous (two hub_slugs sharing one `reuse_surface_id`) registrations, and `GET .../audit` returns queryable registration history |
|
||||
| F2 | 3 | Progress and interaction fixture events appear only in their respective projections |
|
||||
| F3 | 3 | Authority fixtures appear in projections with declared rebuild sources and provenance hashes |
|
||||
|
||||
|
|
@ -34,9 +38,9 @@ global row counts.
|
|||
|
||||
## Deliberately open checks
|
||||
|
||||
C2 registry resolution, C7 raw-port configuration policy, C9 dependency-aware
|
||||
readiness, C10 version negotiation, F1 registry audit history, F4 `/api/v2`
|
||||
consumer smokes, F5 MCP projection binding, F6 policy fail-closed behavior, F7
|
||||
F1 registry audit history at framework scale (beyond the per-`hub_slug` audit
|
||||
trail above), F4 `/api/v2` consumer smokes, F5 MCP projection binding, F6
|
||||
policy fail-closed behavior beyond the raw-port group check above, F7
|
||||
telemetry rejection, and F8 migration metadata isolation require ports or
|
||||
absorption slices that are not part of the T04 minimal vertical. Tenant
|
||||
isolation also remains open because the 0.1 runtime has no tenant identity or
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue