Repository navigation
v0.4.2
Desk v0.4.2
This update moves Desk to Runtime v0.25.0, Runner v0.4.0 and Gateway v0.8.1. The verification download now saves Runner's export version 3, which carries the audit record's exact bytes.
Verification download
Download verification record on a run now asks Runner for verification export version 3. That version carries the run's audit record exactly as the Runtime wrote it, so its digest can be compared with a gateway receipt's decision.recordDigest.
- Runner answers with version 2 for a run that holds no such bytes, such as one recorded before Runner v0.4.0. The saved file is named for the version it holds,
<run>-verification-v3.jsonor-v2.json, read from the export itself. A line beside the button says which version was saved. - The file is saved byte for byte as Runner sent it.
- Desk forwards a
versiononly on the verification route, and only when it is asked once for 2 or 3. It refuses anything else itself. - The verification and run routes now read up to Runner's export limit, about 18.7 MiB. Every other route stays at 16 MiB.
A version-3 file shows that the bytes are consistent with the exported record. Only a digest held independently, such as a gateway receipt's, shows they are the bytes the Runtime wrote, and verify-run does not make that comparison.
Component updates
- Runtime v0.25.0:
- Audit records also carry
unknownCausesandtypeMismatches. - A project may opt in to
requireComparableFactsunder configVersion"5". Desk does not write it. experimental comparewarns when two packs are different decisions or no input resolved.
- Audit records also carry
- Runner v0.4.0:
verify-runreports which inputs were asserted and which rule parameters no signed request commits.--require-sourcedrefuses such a run.- Runs keep the audit record's exact bytes, and export version 3 carries them.
- Gateway v0.8.1: no program changes. Its notes explain what a decision policy with
reviewedbut nopacksadmits.
Existing job releases keep their frozen Runtime. Records made with earlier bundles, development builds or explicit Runtime overrides still need their original binary for replay. State epoch remains 1.
Verification
CI ran frontend behaviour, all twelve locale catalogues, the Go proxy tests, the Jobs companion against the pinned Runner, the local Gateway checks and the native archive builds.
- Mutation checks: seventeen deliberate mutations of the new forwarding, bounds and download rules were caught by the new tests.
- Review: the change had one cross-vendor review round. It found two test gaps, both fixed, and no defect in the code.
Not exercised: a real Runner serving a version-3 export through Desk (the proxy tests use a fake Runner), and a download near the 18.7 MiB limit in a browser.
See installation and updates and release verification.
| Component | Pin |
|---|---|
| Runtime | v0.25.0 |
| Runner and source worker | v0.4.0 |
| Gateway and required Desk adapters | v0.8.1 |
Platforms
This release contains complete Linux/amd64, macOS Apple Silicon (arm64), and
macOS Intel (amd64) archives. All three archives were built and smoke-tested on
native GitHub-hosted runners before publication; neither macOS archive is merely
cross-compiled. Component versions come from the same release lock.
macOS executables are not Developer ID signed or notarized. Gatekeeper may block
downloaded executables; verify the release and checksums, then use Apple's
Privacy & Security → Open Anyway procedure
for the blocked executable. Native CI does not exercise these dialogs. The Codex
subscription subprocess bridge remains Linux-only.
No Windows archive is published. Windows execution is untested, and the managed
installer supports only Linux and macOS.