Skip to content

v0.4.2

Choose a tag to compare

@github-actions github-actions released this 02 Oct 19:28
· 76 commits to main since this release
0a0aa88

Desk v0.4.2

This update moves Desk to Runtime v0.25.0, Runner v0.4.0 and Gateway v0.8.1. The verification download now saves Runner's export version 3, which carries the audit record's exact bytes.

Verification download

Download verification record on a run now asks Runner for verification export version 3. That version carries the run's audit record exactly as the Runtime wrote it, so its digest can be compared with a gateway receipt's decision.recordDigest.

  • Runner answers with version 2 for a run that holds no such bytes, such as one recorded before Runner v0.4.0. The saved file is named for the version it holds, <run>-verification-v3.json or -v2.json, read from the export itself. A line beside the button says which version was saved.
  • The file is saved byte for byte as Runner sent it.
  • Desk forwards a version only on the verification route, and only when it is asked once for 2 or 3. It refuses anything else itself.
  • The verification and run routes now read up to Runner's export limit, about 18.7 MiB. Every other route stays at 16 MiB.

A version-3 file shows that the bytes are consistent with the exported record. Only a digest held independently, such as a gateway receipt's, shows they are the bytes the Runtime wrote, and verify-run does not make that comparison.

Component updates

  • Runtime v0.25.0:
    • Audit records also carry unknownCauses and typeMismatches.
    • A project may opt in to requireComparableFacts under configVersion "5". Desk does not write it.
    • experimental compare warns when two packs are different decisions or no input resolved.
  • Runner v0.4.0:
    • verify-run reports which inputs were asserted and which rule parameters no signed request commits. --require-sourced refuses such a run.
    • Runs keep the audit record's exact bytes, and export version 3 carries them.
  • Gateway v0.8.1: no program changes. Its notes explain what a decision policy with reviewed but no packs admits.

Existing job releases keep their frozen Runtime. Records made with earlier bundles, development builds or explicit Runtime overrides still need their original binary for replay. State epoch remains 1.

Verification

CI ran frontend behaviour, all twelve locale catalogues, the Go proxy tests, the Jobs companion against the pinned Runner, the local Gateway checks and the native archive builds.

  • Mutation checks: seventeen deliberate mutations of the new forwarding, bounds and download rules were caught by the new tests.
  • Review: the change had one cross-vendor review round. It found two test gaps, both fixed, and no defect in the code.

Not exercised: a real Runner serving a version-3 export through Desk (the proxy tests use a fake Runner), and a download near the 18.7 MiB limit in a browser.

See installation and updates and release verification.

Component Pin
Runtime v0.25.0
Runner and source worker v0.4.0
Gateway and required Desk adapters v0.8.1

Platforms

This release contains complete Linux/amd64, macOS Apple Silicon (arm64), and
macOS Intel (amd64) archives. All three archives were built and smoke-tested on
native GitHub-hosted runners before publication; neither macOS archive is merely
cross-compiled. Component versions come from the same release lock.

macOS executables are not Developer ID signed or notarized. Gatekeeper may block
downloaded executables; verify the release and checksums, then use Apple's
Privacy & Security → Open Anyway procedure
for the blocked executable. Native CI does not exercise these dialogs. The Codex
subscription subprocess bridge remains Linux-only.

No Windows archive is published. Windows execution is untested, and the managed
installer supports only Linux and macOS.