gateway v0.7.0
Three changes to the adapters' Google Drive connection, one of them a decision of record, and one row of SPEC.md that states a behaviour the verifier had. The frozen corpus and the core module are as v0.6.0 has them.
What an operator must do
- A host that reads the catalog changes with this release. Drive's entry names
source-searchwhere it namedbrowser-picker; the methodpickis gone andsearchandselecttake its place; a selection answers withresourceIdwhere the chooser's answered withfileId. A host that expects the old entry refuses this release's catalog whole. So a desk moves to this release and changes how it chooses a Drive file in one change. - Every Drive connection is asked to connect again. A connection made by an earlier release is of the scope
drive.file. Its first request that needs Drive is answeredreconnect-required, and the person connects again.statusdoes not say so beforehand: it saysconnected, as it did. - A host may offer the new method,
files-prepare-google-document. Catalog v3 lists it for Drive. Nothing requires a host to offer it. - The owner's Google Cloud project changes. The consent screen's Data access lists
https://www.googleapis.com/auth/drivein place ofdrive.file; the Google Picker API is no longer needed, and the Google Drive API still is. Google restricts this scope: an owner who uses their own registration themselves, within their organization, or as a named test user needs no verification by Google; a registration offered to the public does. Public releases of this repository and of a desk carry no registration, as before.
A Drive connection is of the whole of a person's Drive (#189, ADR-0010)
A Drive connection asked for drive.file and opened Google's own chooser of files. Under that scope it saw the files it made and the files a person chose in the chooser, and no others. ADR-0010 decides otherwise, and this release builds the first three of its five determinations:
v0.6.0 |
v0.7.0 |
|
|---|---|---|
| Scope asked of Google | drive.file |
drive, and no other; a token of another scope is refused |
| How a file is chosen | Google's chooser, inside the consent | search, then select |
| Drive's methods | status, configure, connect, pick, poll, cancel, disconnect |
the same without pick, with search and select |
A storage listing's scope |
app-authorized-files |
account-files |
search takes { "query": "words" } and gives at most twenty files that adapter-drive would take, by what Drive says of each: with words, what Drive finds for them, in the order Drive gives them; without, what was changed last. select takes at most four IDs and gives a grant for each, for one read within five minutes. A grant says that the host asked to read the file; it does not say that a person chose it. adapter-drive reads as it did.
What a consent was for is recorded when it is given, in consent.json beside the connection's state, and again at every renewal: the connection, a digest of each token, and the scope. Every request that needs Drive is held to that record and not to what a renewal says. A connection without a record of a consent for drive for the tokens it holds is refused: a connection made by an earlier release, one whose tokens an earlier release replaced after a rollback, and one a process renewed and ended before it wrote the record. The state's own shape is unchanged, so an earlier release reads it and ignores the record.
Decided and not built. Determination 4: an update and a move to trash of a Drive file are to be held to the file's version, read immediately before the change, in place of a conditional request that Drive does not offer. Until it is built, both are refused with conditional-write-unavailable, as they were. This replaces, for Drive, one consequence of ADR-0005; it replaces nothing of ADR-0006.
A Google Doc made of a Word file, by Drive's conversion (#176)
The storage controls gain one method, for Drive alone: files-prepare-google-document. It takes a Word file (application/vnd.openxmlformats-officedocument.wordprocessingml.document, framed as one) with a name and, where given, a folder, and prepares a plan whose convertTo is google-document, so that a person sees what the file becomes before they confirm. The commit is one upload that asks Drive to convert, sent once and never again. Drive gives the document its ID; what was made is held to be a Google Doc by Drive's own answer, and where Drive made something else the plan says conversion-unconfirmed and names the file so that a person can find it. An ordinary create cannot ask for a conversion, and a conversion cannot be asked of anything but a Word file.
Tried once against a live Drive account on 2026-09-29: the plan was prepared with no confirmation asked, the commit completed in under three seconds with a target, and the listing showed the target as application/vnd.google-apps.document. ADR-0006's determination 6 left this to a contract and a review of its own; the contract is a section of docs/design/storage-files.md, and no decision record is added.
SPEC §4.1 states the verdict for a store root that cannot be read (#190)
One row: a store root that is a directory but cannot be read gives no verdict; the verifier refuses, as it does for a root that is not a directory. The row states what TestStoreRootShapes had asserted since before v0.4.0 and changes no program. It completes the table's three shapes of the root, as the three shapes of <root>/receipts below it were already stated.
A search of Drive by words asks for no order (#188)
Drive refuses an order asked of a search by words, and every files-list with words on Drive was answered provider-unavailable since v0.4.0. A search by words now asks for no order and comes in the order Drive gives it. A listing without words asks for Drive's order folder,name, as before.
To verify a download
sha256sum --check --ignore-missing checksums.txt
gh attestation verify <archive> \
--repo Judgment-Pack/judgment-pack-gateway \
--signer-workflow Judgment-Pack/judgment-pack-gateway/.github/workflows/release.yml \
--source-ref refs/tags/v0.7.0What was checked before this release was published:
| Check | Where |
|---|---|
| Everything CI asks of a commit, at the tagged commit | Linux, macOS, Windows |
| Every archive read: its files are the commit's, byte for byte; each program is the bytes the packer built, from the package of its name, for the archive's platform | all six archives |
The archive run: gateway version, and gateway conform on the corpus it carries |
Linux amd64 and arm64, macOS arm64, Windows amd64 |
| Three adapters started | Linux amd64 and arm64, macOS arm64 |
docs/releasing.md says how a release is made and what each check does not establish.
What this release establishes of Drive, and what not
One connection was tried against a live Drive account on 2026-09-29, with the programs of #189 and #188 and a registration made for it: the consent was granted for the scope asked; a search without words gave twenty files of four kinds; a search by one word found two files another client had made under drive.file; a listing of the root gave a page of folders; one file was read under a grant, and the grant was refused a second time; the consent was revoked at disconnect. That is one account on one day. Not tried: another account, a shared drive, an organization with an internal audience, a consent refused, a renewal of the token, a rollback.
- No update and no move to trash of a Drive file goes through: the try of
v0.6.0's controls found that Drive gives no ETag, and the refusal stands until determination 4 is built. That holds of a document made by conversion too: the controls make it and cannot move it to trash. - Of a conversion, one file on one account: not a conversion Drive refuses or leaves half done, an answer lost on the way, a shared drive, or a large file.
- That a live Tavily or Google Cloud account is accepted by the search source, as the notes of
v0.5.0andv0.6.0said. - That a desk takes this release: no desk is tested here, and a desk must change with the catalog.
- The
darwin/amd64andwindows/arm64archives are built and read, and run by nothing. - The adapters' tests run on Linux. No check reaches a platform account.
- The engine image is not published. CI builds it from every commit and never pushes it.
Review
#189 went through three rounds of the gateway's cross-vendor review regime, #176 through four, and #188 through one. Every record and disposition is on the pull requests. #190 is a clarification of one row, reviewed against its issue's acceptance criteria on the pull request.