Repository navigation
2.3.2
A remote UHP bind no longer serves the harness catalog without a bearer.
馃攼 UHP security
- A remote bind no longer serves the harness catalog without a bearer.
Architecture section 5 of the specification allows one unauthenticated
route, discovery, so opening the catalog left the bind failing the suite's
authentication checks and disclosing the harness id, the model list and the
harness configuration to anyone who found the host. The new
serve uhp --public-catalogflag restores the old behaviour for anyone who
wants it, and says in its help what it costs. Present sinceserve uhp
shipped in 2.2.2.
馃З Unified Harness Protocol
- Core conformance is now measured by HarnessRouter rather than by us. Their
conformance-measureworkflow ran suite2026.9.12against
uhp.superqode.devitself at class full: core passed 40 of 40, including
both authentication checks. The badge and report are on the UHP conformance
page. Extended stays out of reach on that host, because artifact retrieval
is deferred and session listing is off wherever one bearer is shared.
馃摝 Packaging
- The
uhpextra is recorded inuv.lock. It has been declared in
pyproject.tomlsince 2.2.4, so a locked install of the extra resolved
against a lock file that did not know it existed. - The
uhpextra is listed in the installation reference.