gateway v0.5.0
The first release of this repository that carries its programs, and the first made by its release workflow. Two candidates came before it, v0.5.0-rc.1 and v0.5.0-rc.2. It is built from the commit the second was built from.
What an operator must do
Nothing, to keep what v0.4.0 did. The gateway's contract is unchanged: SPEC.md and the frozen corpus are as v0.4.0 has them, and receiptVersion is what it was.
Three things an operator may notice:
- A released
gatewaynames its release.gateway versionprints it, and the MCP server reports the same asserverInfo.version. A build from a checkout still saysunversioned build. - Catalog v3 lists a provider under a second protocol,
web-search-v1. A host that knows onlyconnection-v1lists it as unsupported and calls nothing. - The adapters link two more modules,
golang.org/x/oauth2andcloud.google.com/go/compute/metadata.THIRD_PARTY_NOTICESnames them.
A release now carries the programs (#173, ADR-0008)
Releases up to v0.4.0 were a tag and notes. From this one, a release carries six archives, for Linux, macOS and Windows on amd64 and arm64. Each holds gateway, every program under adapters/cmd, SPEC.md, the corpus, the catalog and the licences.
To verify a download:
sha256sum --check --ignore-missing checksums.txt
gh attestation verify <archive> \
--repo Judgment-Pack/judgment-pack-gateway \
--signer-workflow Judgment-Pack/judgment-pack-gateway/.github/workflows/release.yml \
--source-ref refs/tags/v0.5.0What was checked before this release was published:
| Check | Where |
|---|---|
| Everything CI asks of a commit, at the tagged commit | Linux, macOS, Windows |
| Every archive read: its files are the commit's, byte for byte; each program is the bytes the packer built, from the package of its name, for the archive's platform | all six archives |
The archive run: gateway version, and gateway conform on the corpus it carries |
Linux amd64 and arm64, macOS arm64, Windows amd64 |
| Three adapters started | Linux amd64 and arm64, macOS arm64 |
docs/releasing.md says how a release is made and what each check does not establish.
Named web search connections (#180, ADR-0009)
A new source, web-search, read by adapter-sources, and a provider of the same name in gateway-connections. A connection is to Tavily or to Google Cloud Search grounding. A search gives links to read through web, not documents.
- Up to six named connections, each with a daily request budget that is reserved before the network is reached. Failed calls and connection tests count.
- Endpoints are fixed in the adapter. A caller supplies none.
- A connection is checked before a request and after its answer. An answer that arrives after the connection changed, or was blocked, is refused.
- A Google answer is a generated answer with links. The answer, the links, the queries and Google's attribution markup are kept apart, and an answer without links and attribution is refused. The markup is Google's: a consumer treats it as markup it did not write.
- The acquisition is under the existing HTTP receipt shape. Its statement names the request's parameters and is not the bytes sent.
No provider was called with an account. Every test answers from a local server or a stand-in. docs/web-search.md is the contract, and says what was tested.
adapter-render writes a Word file and a PDF (#168, #170, #174, under ADR-0006)
A new adapter, a bare source under the command shape. It reads a format, a title and content as a closed structure of blocks, and writes a version 1 render record that holds the file with its size and digest, so that a receipt's output commitment covers the file.
- A Word file is written by the adapter itself. The same content gives the same bytes from the same build. Microsoft Word was not available to open the file with; pandoc, LibreOffice and python-docx read it.
- A PDF is written by a rendering program the operator names with
--renderer. The program is handed the Word file of the same content and answers with the PDF. The adapter checks that the answer begins and ends as a PDF does; it does not open it. Without a program a PDF is refused asrenderer-not-configured. - No archive carries a rendering program, and nothing names the adapter yet: no engine configuration, image or desk plan. An operator adds the source.
docs/design/rendering.md is the contract.
Smaller changes
- The run of an operator's program has one home (#171). The code that runs the OCR program moved to a package of its own, and the rendering program is run from the same code. The document adapter behaves as it did, with one stated difference: page numbers are made into arguments before the run, where they were made after the deadline's check.
- A source's time bound, as the code has it (#177). Four places gave a figure for how long a source may run, and
SECURITY.mdgave a ceiling the gateway does not have. Each now says both figures and whose each is. - Design notes of what has shipped say so (#167).
Decided, and not built (ADR-0007, #172)
How an engine started from its configuration is to serve the adapters it ships, as services named in that configuration. Nothing in this release implements it.
What this release does not establish
- That a live Tavily or Google Cloud account is accepted, or what a live answer holds. The form of Google's source links, the size of its attribution markup and the models that support grounding are as its documentation states them, not as observed.
- That a rendering program makes a good PDF. The adapter vouches for the Word file it wrote, and for nothing of the step after.
- The
darwin/amd64andwindows/arm64archives are built and read, and run by nothing. - The adapters' tests run on Linux. Of the adapters in an archive, three are started by the release checks and the rest by none. No check reaches a platform account.
- The engine image is not published. CI builds it from every commit and never pushes it.
Review
#168, #170, #171, #172, #173, #174, #177 and #180 each went through the gateway's cross-vendor review regime. Every record and disposition is on the pull requests.
The frozen corpus and SPEC.md are unchanged since v0.4.0: 30 canon vectors and 41 store vectors.