sbom-nexus/workplans/SBOM-WP-0003-controlled-source-and-replay.md
tegwick c806797e02 workplans: close controlled source delivery
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02b22-9638-76d2-bbff-b7ea1770b118
2026-08-23 00:49:54 +02:00

4.2 KiB

id type title domain repo status owner topic_slug created updated quality_dor quality_dor_at quality_dor_by quality_dor_note parent_workplan related state_hub_workstream_id
SBOM-WP-0003 workplan Controlled Forgejo source ingestion and durable operation replay infotech sbom-nexus finished codex infotech 2026-08-22 2026-08-23 DoR-Ok 2026-08-22 codex CUST-WP-0064 selected a full-SHA public Forgejo archive contract with bounded extraction, explicit provenance, owner handoffs, idempotency, failure semantics, acceptance evidence, and rollback. CUST-WP-0064
CUST-IN-0013
ACTIVITY-WP-0033
RMGR-WP-0011
dc07cc14-9a5d-568d-8e19-036661e52120

Controlled Forgejo source ingestion and durable operation replay

Implement durable operation receipts

id: SBOM-WP-0003-T01
status: done
priority: high
state_hub_task_id: "ad2b95fd-a7b1-5331-a8c3-1545fdb6db10"

Enforce supplied Idempotency-Key / X-Activity-Core-Operation-ID values on repository ingest and skip. Persist a request fingerprint and snapshot link in the same transaction, replay the original terminal outcome, and reject key reuse for a different operation.

Completed with migration 0002, transactional operation receipts, early replay before source work, request-conflict HTTP 409 behavior, and ingest/skip tests proving one snapshot across duplicate requests.

Add controlled full-SHA source ingestion

id: SBOM-WP-0003-T02
status: done
priority: high
state_hub_task_id: "3a8734f2-c00e-584f-b5ff-f22370a5ce02"

Consume the forgejo-archive-v1 source reference selected in the-custodian/docs/sbom-controlled-scan-input-contract-v1.md. Validate the identity, stream and safely extract within fixed limits, pass the explicit revision into the scanner, persist archive provenance, and always clean up.

Completed with strict Coulomb identity/full-SHA validation, same-host fetches, streaming compressed limits, safe regular-file-only extraction, one scan slot, subprocess scan timeout, explicit revision override, archive provenance, and temporary-directory cleanup. A real Forgejo archive scan produced 33 entries from one manifest with zero errors.

Extend repository projection and outcomes

id: SBOM-WP-0003-T03
status: done
priority: high
state_hub_task_id: "5be7b81e-0469-5d74-a28c-8802187a122a"

Store and return source references in repository/catch-up projections. Add terminal source-unavailable and source-rejected outcomes without changing oldest-N ranking or success-time semantics.

Completed in the repository projection, API model, storage schema, catch-up response, and additive skip handling. Legacy checkout scanning remains available for local/operator compatibility while the production flag is dark.

Prove package integration and production behavior

id: SBOM-WP-0003-T04
status: done
priority: high
state_hub_task_id: "9c8a2b6c-2b99-5dd8-9c1c-b5ba4ad2367b"

Coordinate the schema migration, ephemeral volume, Forgejo-only egress, and feature flag with rapp-sbom-nexus; then pass unit/integration tests and the attended plus scheduled production proof owned by CUST-WP-0064.

The package promoted digest sha256:1da0f4f008643a0dec3f00bbad15f287103aa4b469577b78cfe1d67f8b3cbe31 after migration 0002. The attended sbom-nexus canary produced snapshot 04f5c0ba-d073-4577-ba2d-0854346ac7be: 33 entries, exact full-SHA revision, archive SHA-256/byte provenance, zero errors, identical replay under the same operation key, and an empty transient directory before and after. The feature is dark again with snapshot history intact; scheduled proof remains.

The existing enabled Temporal schedule was then reconciled unchanged and operator-triggered through its normal schedule action. It froze exactly three controlled targets, issued three successful Nexus writes, spawned zero tasks, and created provenance-bearing terminal snapshots 62f5f596-f644-4992-b356-f06b832eef07, 6849b000-d7ac-4d06-a104-51d2610a67df, and 526e03bf-a71c-4095-ba8a-31a46a2adfc9. All three correctly reported no-manifest; never_count advanced 94 to 91. The feature is enabled for the bounded schedule. Unassisted weekday observation and ongoing source-reference projection remain live in CUST-WP-0064 / ACTIVITY-WP-0034.