Implements the four residual conformance checks left open by the T04
minimal vertical:
- C2: GET /ports/registry/registrations/{hub_slug} resolves missing (404),
ambiguous (shared reuse_surface_id across hub_slugs), and stale
(deprecated/retired descriptor) registrations; a new .../audit route
exposes queryable registration history from the existing in-memory
history and the PostgreSQL runtime_audit_ledger.
- C7: harness proof that disabled compatibility groups deny access
(404) with no fixture credentials involved, matching the existing
fail-closed compat router behavior.
- C9: harness proof plus a dedicated test that /readyz degrades only on
an unavailable configured dependency while unrelated disabled
projections stay non-blocking.
- C10: ContractValidator now negotiates contract_version_min/max against
the runtime's contract version and rejects incompatible or inverted
ranges with an explicit 422 instead of silently accepting them.
HUB-WP-0009 is now finished. HUB-WP-0006 is marked blocked: its only open
task (T06) has no remaining hub-core code path and waits on an external
Forgejo identity/production deployment gate. HUB-WP-0011 is marked
blocked: T02/T03 already waited on external credential/deployment
review, and T01 needs a source/destination ownership and retention
decision against live message data before it can be implemented safely.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 310936@bnt-lap001
Assistant-Session: 00cd9abe-09a0-416b-88e0-f907b9101629
48 lines
2.8 KiB
Markdown
48 lines
2.8 KiB
Markdown
# Hub-extension conformance
|
|
|
|
`hub_core.conformance` is the reusable Tier 2/3 harness scaffold for contract
|
|
version 0.1.0. It drives only public HTTP ports, so a FastAPI `TestClient`, an
|
|
`httpx.Client`, or another compatible target can be used without importing the
|
|
runtime implementation.
|
|
|
|
The harness mutates its target. Run it against a disposable instance or a
|
|
dedicated test namespace:
|
|
|
|
```bash
|
|
hub-core api --host 127.0.0.1 --port 8010
|
|
hub-core conformance --base-url http://127.0.0.1:8010
|
|
hub-core conformance --base-url http://127.0.0.1:8010 --json
|
|
```
|
|
|
|
## Implemented profile
|
|
|
|
| ID | Tier | Automated evidence |
|
|
| --- | --- | --- |
|
|
| C1 | 2 | Packaged descriptor, manifest, and catalog validate against Draft 2020-12 schemas |
|
|
| C3 | 2 | Runtime health probe returns healthy |
|
|
| C4 | 2 | Repeated manifest registration is reported as a duplicate |
|
|
| C5 | 2 | Cataloged progress/interaction events are accepted; wrong-family and unknown events are rejected |
|
|
| C6 | 2 | Contract and scenario fixtures reject secret-shaped keys, credentialed database URLs, and private keys |
|
|
| C7 | 2 | Disabled compatibility groups (`/api/v2/hubs`, `/console`) deny access without needing fixture credentials |
|
|
| C8 | 2 | Registry response propagates the request correlation identifier |
|
|
| C9 | 2 | `/readyz` reports each dependency (database, `port.repo` projection, workload projection, authorization) individually, only degrading when a configured dependency is unavailable or stale |
|
|
| C10 | 2 | A registration whose `contract_version_min`/`contract_version_max` excludes the runtime's contract version is rejected with an explicit incompatibility error |
|
|
| C2 | 2 | `GET /ports/registry/registrations/{hub_slug}` resolves missing (404) and ambiguous (two hub_slugs sharing one `reuse_surface_id`) registrations, and `GET .../audit` returns queryable registration history |
|
|
| F2 | 3 | Progress and interaction fixture events appear only in their respective projections |
|
|
| F3 | 3 | Authority fixtures appear in projections with declared rebuild sources and provenance hashes |
|
|
|
|
The projection scenario is shipped in the wheel as
|
|
`fixtures/projection-rebuild.json`. Correlation and time fields are generated
|
|
per run, allowing the harness to identify its own evidence without relying on
|
|
global row counts.
|
|
|
|
## Deliberately open checks
|
|
|
|
F1 registry audit history at framework scale (beyond the per-`hub_slug` audit
|
|
trail above), F4 `/api/v2` consumer smokes, F5 MCP projection binding, F6
|
|
policy fail-closed behavior beyond the raw-port group check above, F7
|
|
telemetry rejection, and F8 migration metadata isolation require ports or
|
|
absorption slices that are not part of the T04 minimal vertical. Tenant
|
|
isolation also remains open because the 0.1 runtime has no tenant identity or
|
|
authorization context yet. These gaps must not be interpreted as passing; the
|
|
harness reports only the implemented profile above.
|