Skip to content

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 03 Oct 12:23
· 56 commits to main since this release
7707252

Desk v0.5.0

This update turns the gates on by default (ADR-0009):

  • new desks start under a reviewed set, with an audit trail;
  • the project Desk was started on, and older desks, are offered the same, and nothing is changed until the owner confirms;
  • Jobs refuse a release whose saved tests did not run and pass.

It also moves Desk to Runtime v0.26.0, Runner v0.5.0 and Gateway v0.9.0.

What changes for you

  • Create job refuses an untested release. Runner answers 409 release_untested, and Desk shows it. Existing jobs keep running. To allow untested releases again, restart Desk with --runner-require-tested-releases=false.
  • A new desk is gated. A deciding run of a pack that is not in the reviewed set is refused. Rehearsals and tests still answer, and every evaluation Desk itself makes is a rehearsal, with one exception the README names. requireComparableFacts refuses any evaluation, rehearsals included, that reads a fact of a type no comparison in the pack can match.
  • Your existing projects are not changed. Packs shows a note offering the gates, and Admin → Project has a Gates card. Before you confirm, read what the offer lists. If the project already keeps a lock, the upgrade writes a new one with the new jpack.json: commit both files together, or a CI step that runs packs verify fails on config-drift.
  • An inherited JPACK_SIGNING_KEY now has an effect. Runtime v0.26.0 signs audit records where a key is set. A JPACK_SIGNING_KEY set where Desk was started reaches every runtime Desk starts, for every desk, and the runtime can sign their records with it. ADR-0010 removes it for desks Desk made; that is not built yet.

Gates on by default (ADR-0009, #190)

  • New desks (#193). POST /api/desks writes jpack.json at configVersion "5", with requireReviewed, requireComparableFacts and the audit directory .desk-private/audit, made owner-only. The runtime then locks the empty project, in jpack.lock.json, before the desk exists.

    • With a runtime that reads "4" but not "5", the desk is made without requireComparableFacts, and the creation says so.
    • With an older runtime, or if the lock fails, no desk is made.
    • A JPACK_CONFIG set where Desk was started no longer applies to a desk Desk made.
  • Review and lock (#195). On Packs, Review and lock shows what the runtime's packs verify finds, file by file, in plain words. Each pack's finding is also shown beside its name.

    • A diff is shown only where Desk kept a copy of exactly the bytes the lock names, in .desk-private/reviewed/.
    • One confirmation locks the whole set, through the runtime's packs lock. Desk locks exactly the files it showed, or nothing.
    • Locking records that you confirmed these exact files as the project's reviewed set. It is not a second person's approval, and it records no name.
  • Tested releases by default (#194). --runner-require-tested-releases now defaults to on. Every desk's Runner boot line states the policy, true or false, and the page says which applies.

  • Jobs: is a release in the reviewed set? (#196) Review this release compares the SHA-256 of the release's exact pack bytes with what the project's lock pins for its decision id. It shows the runtime's findings beside that, and refuses nothing. "In the reviewed set" means the lock pins these exact bytes. It does not mean the pack is right, or say who reviewed it.

  • The offer for existing desks (#197). It lists each change with what it writes and why:

    • jpack.json: the gate members, changed by its bytes, so that every other member, its order and its spelling are kept;
    • .desk-private/ as the last line of .gitignore, where the project is in a Git work tree;
    • the first lock;
    • requireComparableFacts, as an item of its own that can be declined.

    The configuration and the lock go together: if the lock fails, every file is put back as it was. Desk offers no configuration version the runtime cannot read.

  • The README and in-app help (#199) say what each gate holds, what is recorded, and whom requireReviewed binds. They also say how to give an outside agent the project's tools under the gate.

Defensible decision records: decided, not built (ADR-0010, #198)

ADR-0010 is accepted. It decides how Desk will keep a desk's record defensible on top of Runtime ADR-0047:

  • key custody;
  • handing over checkpoints;
  • stamping;
  • a verification panel;
  • Runner's chain of runs.

None of it is in this release. The runtime this release pins chains each desk's audit trail by default. But Desk takes, shows and hands over no checkpoint, so the chain shows nothing yet to someone who does not trust the desk's owner.

Component updates

  • Runtime v0.26.0:
    • A project's audit trail is chained over its exact bytes, by default (ADR-0047).
    • New jpack audit verify, checkpoint, repair, key and stamp commands; Desk runs none of them yet.
    • Records are signed where a signing key is set.
  • Runner v0.5.0:
    • A chain of the installation's runs, and signed audit records.
    • Verification export versions 4 and 5.
    • Desk still asks for version 3, does not pass GET /v1/run-chain through, and gives Runner no signing key.
    • A run's answer now also carries its signature sidecar, so Desk reads a run and its verification export up to Runner v0.5.0's export limit, 19,596,893 bytes (#200).
  • Gateway v0.9.0:
    • A decision policy can require a signed record. Desk sends no writes through /act.
    • The engine refuses to start where another user could replace an adapter it launches, its decision-record directory, or a link to its seed or credentials. The bundle's adapters, owned by the user who runs Desk, pass.

Existing job releases keep their frozen Runtime. Records made with earlier bundles, development builds or explicit Runtime overrides still need their original binary for replay. State epoch remains 1.

Verification

CI ran frontend behaviour, all twelve locale catalogues, the Go chassis tests, the Jobs companion against the pinned Runner and Runtime, the local Gateway checks and the native archive builds.

  • Mutation checks: each change to a safeguard added rows to scripts/mutation-check.sh, and each row was run against the tests it targets and caught. A row that did not compile was not counted as caught.

  • Review: each change but #199, which is documentation and help, had cross-vendor review, recorded on its pull request with a disposition of every finding.

    • #193: two rounds; the first found two HIGH, both fixed.
    • #194: one round; one MEDIUM, a test gap, fixed.
    • #195: three rounds; the first found three HIGH, the second one more, all fixed.
    • #196: two rounds; the first found one HIGH, fixed.
    • #197: two rounds; the first found three HIGH, all fixed.

    #200, the pin update, raised one read bound by 23,457 bytes to match the pinned Runner, and took none.

Not exercised:

  • the reviewed-set comparison in a browser on an origin that is not a secure context, where it says "Not known";
  • a native speaker's reading of the new messages in the eleven catalogues other than English.

See installation and updates and release verification.

Component Pin
Runtime v0.26.0
Runner and source worker v0.5.0
Gateway and required Desk adapters v0.9.0

Platforms

This release contains complete Linux/amd64, macOS Apple Silicon (arm64), and
macOS Intel (amd64) archives. All three archives were built and smoke-tested on
native GitHub-hosted runners before publication; neither macOS archive is merely
cross-compiled. Component versions come from the same release lock.

macOS executables are not Developer ID signed or notarized. Gatekeeper may block
downloaded executables; verify the release and checksums, then use Apple's
Privacy & Security → Open Anyway procedure
for the blocked executable. Native CI does not exercise these dialogs. The Codex
subscription subprocess bridge remains Linux-only.

No Windows archive is published. Windows execution is untested, and the managed
installer supports only Linux and macOS.