hub-core/docs/conformance.md
tegwick e89d621f18
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / pytest-smoke (push) Waiting to run
Close HUB-WP-0009 conformance gaps (C2, C7, C9, C10); mark blocked workplans
Implements the four residual conformance checks left open by the T04
minimal vertical:

- C2: GET /ports/registry/registrations/{hub_slug} resolves missing (404),
  ambiguous (shared reuse_surface_id across hub_slugs), and stale
  (deprecated/retired descriptor) registrations; a new .../audit route
  exposes queryable registration history from the existing in-memory
  history and the PostgreSQL runtime_audit_ledger.
- C7: harness proof that disabled compatibility groups deny access
  (404) with no fixture credentials involved, matching the existing
  fail-closed compat router behavior.
- C9: harness proof plus a dedicated test that /readyz degrades only on
  an unavailable configured dependency while unrelated disabled
  projections stay non-blocking.
- C10: ContractValidator now negotiates contract_version_min/max against
  the runtime's contract version and rejects incompatible or inverted
  ranges with an explicit 422 instead of silently accepting them.

HUB-WP-0009 is now finished. HUB-WP-0006 is marked blocked: its only open
task (T06) has no remaining hub-core code path and waits on an external
Forgejo identity/production deployment gate. HUB-WP-0011 is marked
blocked: T02/T03 already waited on external credential/deployment
review, and T01 needs a source/destination ownership and retention
decision against live message data before it can be implemented safely.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 310936@bnt-lap001
Assistant-Session: 00cd9abe-09a0-416b-88e0-f907b9101629
2026-09-27 23:59:46 +02:00

2.8 KiB

Hub-extension conformance

hub_core.conformance is the reusable Tier 2/3 harness scaffold for contract version 0.1.0. It drives only public HTTP ports, so a FastAPI TestClient, an httpx.Client, or another compatible target can be used without importing the runtime implementation.

The harness mutates its target. Run it against a disposable instance or a dedicated test namespace:

hub-core api --host 127.0.0.1 --port 8010
hub-core conformance --base-url http://127.0.0.1:8010
hub-core conformance --base-url http://127.0.0.1:8010 --json

Implemented profile

ID Tier Automated evidence
C1 2 Packaged descriptor, manifest, and catalog validate against Draft 2020-12 schemas
C3 2 Runtime health probe returns healthy
C4 2 Repeated manifest registration is reported as a duplicate
C5 2 Cataloged progress/interaction events are accepted; wrong-family and unknown events are rejected
C6 2 Contract and scenario fixtures reject secret-shaped keys, credentialed database URLs, and private keys
C7 2 Disabled compatibility groups (/api/v2/hubs, /console) deny access without needing fixture credentials
C8 2 Registry response propagates the request correlation identifier
C9 2 /readyz reports each dependency (database, port.repo projection, workload projection, authorization) individually, only degrading when a configured dependency is unavailable or stale
C10 2 A registration whose contract_version_min/contract_version_max excludes the runtime's contract version is rejected with an explicit incompatibility error
C2 2 GET /ports/registry/registrations/{hub_slug} resolves missing (404) and ambiguous (two hub_slugs sharing one reuse_surface_id) registrations, and GET .../audit returns queryable registration history
F2 3 Progress and interaction fixture events appear only in their respective projections
F3 3 Authority fixtures appear in projections with declared rebuild sources and provenance hashes

The projection scenario is shipped in the wheel as fixtures/projection-rebuild.json. Correlation and time fields are generated per run, allowing the harness to identify its own evidence without relying on global row counts.

Deliberately open checks

F1 registry audit history at framework scale (beyond the per-hub_slug audit trail above), F4 /api/v2 consumer smokes, F5 MCP projection binding, F6 policy fail-closed behavior beyond the raw-port group check above, F7 telemetry rejection, and F8 migration metadata isolation require ports or absorption slices that are not part of the T04 minimal vertical. Tenant isolation also remains open because the 0.1 runtime has no tenant identity or authorization context yet. These gaps must not be interpreted as passing; the harness reports only the implemented profile above.