Repository navigation
v0.5.2
Desk v0.5.2
Each job gains an Activity tab, the verification download asks Runner for its newest export and names what it answers, the runner's chain of runs can be downloaded as exact bytes, and the Tests workspace says which kind of invalid expectation the runtime found. Desk stays on Runtime v0.26.0, Runner v0.5.0 and Gateway v0.9.0.
What changes for you
- Activity, a fourth tab on each job. One row per record Runner serves: runs, occurrences and preparations, newest first by the time Runner first recorded each, with what it says, who initiated it (this installation, or a trigger by name and revision), the release, and what the run's record holds. Rows open the right pane; a run row links to the run page.
- The run page shows when the run started, who requested it, the release's pack and runtime digests, and whether the exact record bytes and a signature sidecar are retained. Each of those is shown as present or absent, never as checked.
- The verification download asks for export version 5 and names the version Runner answers, with one sentence per version; a version-4 or 5 export shows the run's chain entry as "chain entry N, not checked".
- Download the runner's chain of runs, beside Jobs | Runs: the whole chain, byte for byte as the runner sent it, unverified here.
- The Tests workspace says which kind of invalid expectation the runtime found: a §8.3 defect as the runtime words it, a limit as input the runtime did not admit, and an expectation no pack can produce as the expectation to change, not the draft.
- Admin → Project → Decision record now says that Jobs runs are recorded by the runner, not in that trail.
An Activity tab on each job (#222, closes #213)
The tab is built only from records Runner already serves. Nothing is synthesised: a record without the time that orders it gets no row, a missing later time is left out rather than filled in, and no row is shown until every list the filter reads has answered. An interrupted run's finish is labelled as the time the runner recorded the interruption, since Runner sets it at restart. No sentence says "verified", "valid", "witnessed" or "audit trail": nothing on this tab is checked against held material.
Export version 5, and the chain of runs as exact bytes (#220, closes #214)
This is the first half of ADR-0010's delivery PR 8, split out so it ships before hand-over, which it does not need. Runner v0.5.0 has served export versions 2 to 5 and GET /v1/run-chain since its release; Desk refused versions above 3 in two places and had no route for the chain.
- The proxy accepts versions 2 to 5, asked once; the page asks for 5 and names the version the body carries, since Runner answers the highest version a run's material allows: a run with no chain entry is answered at 3 or 2, an unsigned run at 4.
- A new GET-only route passes the chain through untouched as
application/jsonl, under a bound of 67,174,400 bytes that fails the download rather than truncating it; a transfer that ends early is an error on every route, never a shorter answer. - One cross-vendor round: no HIGH or MEDIUM; one LOW (the bound's wording in the documents) fixed, and the bound test strengthened to show the proxy stops reading near the bound.
What it establishes: the saved export and the saved chain are the runner's bytes. What it does not: nothing here checks them; Runner's verify-run does, with the material a holder keeps.
The Tests workspace names the kind of invalid expectation (#211, closes #208)
The workspace showed the runtime's bare message for any invalid expectation. It now words each kind the way the research feature does, through catalogue templates in all twelve locales. Harness rows for this and for #207 (#210, #212) now hold the branches.
ADR-0010 amended (#224, closes #217)
A dated amendment that reverses no decision: the status lines say what has shipped (PRs 1 and 2 in v0.5.1; PR 8a here), the checkpoint hand-over command gains --limit 300, the delivery table splits PR 8 and adds rows for a Runner signing key and a Jobs record panel, and §4, §5 and §8 carry verification of a chain copy with audit verify --trail. Section 5 says that Runner signs each run's record, not its chain entries, which the Jobs record panel's design must account for.
Component updates
None. The pins are unchanged, and newer releases exist upstream:
- Runtime v0.27.0 and v0.27.1 refuse a signing key kept where another user could remove or replace it, and say in every
audit verifyreport that the trail is silent about refused and rehearsed evaluations. Desk's key custody (ADR-0010 PR 3, in progress) places keys where that rule accepts them and shows that report; the pin moves with that work. - Runner v0.6.0 keeps a journal of job activity, exports runs of jobs with no mapping or a v1 mapping without lineage, and serves a failed run's diagnostics. A store it opens is migrated to its schema "2" and is then refused by Runner v0.5.0, so the pin moves only with a release note that says so and with the Activity tab reading the journal (#218). Do not replace the Runner this Desk bundles with v0.6.0 by hand: a store that Runner opens cannot be read by this Desk's Runner afterwards, and Desk's updater keeps the pinned one.
- Gateway v0.9.1 seals a session that only a discarded registry line names; Desk's managed gateway is unaffected on the paths Desk uses.
Existing job releases keep their frozen Runtime. State epoch remains 1.
Verification
CI ran frontend behaviour, all twelve locale catalogues, the Go chassis tests, the Jobs companion against the pinned Runner and Runtime, the local Gateway checks and the native archive builds.
- Mutation checks: #220 added Go and web rows to
scripts/mutation-check.shfor the version handling, the chain route, its bound and an early-ended transfer; #222 added 24 rows for the Activity tab; #210 and #212 added the rows for #207 and #211. Every row was run and caught by a named test. - Review: #220, whose proxy change is not frontend, had one cross-vendor round recorded on its pull request. #222 and #211 are frontend and had the in-house checks. #224 is documentation.
Not exercised: the Activity tab against a live Runner (its screenshots and tests use recorded fixtures); the chain download against a live Runner; a native speaker's reading of the new messages in the eleven catalogues other than English.
See installation and updates and release verification.
| Component | Pin |
|---|---|
| Runtime | v0.26.0 |
| Runner and source worker | v0.5.0 |
| Gateway and required Desk adapters | v0.9.0 |
Platforms
This release contains complete Linux/amd64, macOS Apple Silicon (arm64), and
macOS Intel (amd64) archives. All three archives were built and smoke-tested on
native GitHub-hosted runners before publication; neither macOS archive is merely
cross-compiled. Component versions come from the same release lock.
macOS executables are not Developer ID signed or notarized. Gatekeeper may block
downloaded executables; verify the release and checksums, then use Apple's
Privacy & Security → Open Anyway procedure
for the blocked executable. Native CI does not exercise these dialogs. The Codex
subscription subprocess bridge remains Linux-only.
No Windows archive is published. Windows execution is untested, and the managed
installer supports only Linux and macOS.