Repository navigation
v0.7.1 — with-device 0.2.1: signed, verified, and the fix for v0.7.0
with-device 0.2.1 — supersedes v0.7.0, which reported success for commands it never ran
If you pinned v0.7.0, move. That release's with-device 0.2.0 matched its mode flags across
the whole argv, so any wrapped command containing -h, --help, -V, --version, --status
or --self-test hijacked the invocation: the device was claimed and released around nothing,
and the caller got exit 0.
$ with-device d --registry reg.yaml -- echo --version
with-device 0.2.0 # its OWN version
rc=0 # and SUCCESS
Its --self-test was green throughout — it only ever wraps sleep, true and kill -9, none
of which carries such a flag, so the entire bug class sat outside every path it walks. Fixed by
splitting on -- first; nothing after it is interpreted. AFD-084.
This release is signed, and verified as a consumer sees it
v0.7.0 shipped a bare SHA256SUMS.txt and nothing else. That is not a supply-chain control —
whoever can replace an asset can replace the checksums beside it — and it meant varve's deposit,
which is fail-closed on a cosign-signed manifest, could not have ingested jess at all. Now
matched to the org pattern used by synth / loom / ordeal / rivet / spar / sigil:
| asset | what it is |
|---|---|
with-device-0.2.1-<triple>.tar.gz |
binary + devices.yaml.example, four targets |
with-device-0.2.1.cdx.json |
CycloneDX SBOM (generated before the checksums, so the signature covers it) |
SHA256SUMS.txt |
manifest over every asset |
SHA256SUMS.txt.cosign.bundle / .sig / .pem |
Sigstore keyless signature over that manifest |
Every archive also carries an in-toto SLSA v1 build-provenance statement in GitHub's attestation
store.
cosign verify-blob \
--certificate-identity-regexp \
'https://github.com/pulseengine/jess/.github/workflows/release.yml@.*' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
--bundle SHA256SUMS.txt.cosign.bundle SHA256SUMS.txt
sha256sum -c SHA256SUMS.txt
gh attestation verify with-device-0.2.1-<triple>.tar.gz --repo pulseengine/jessA verify job runs exactly that against the published release from a clean runner before this
release is considered good — because "cosign exited 0" and "the release verifies" are different
claims, and they diverge whenever the wrong file was signed or an asset was clobbered afterwards.
Nothing ships unexecuted
v0.7.0 cross-built aarch64-unknown-linux-gnu — the Raspberry Pi target — and skipped its
self-test. That caveat is gone rather than restated: every target is now built on a host that can
execute it (ubuntu-24.04-arm for aarch64-linux, Rosetta for x86_64-darwin), and each runs the
full 35-test suite there.
Testing
35 tests — 18 unit over the pure core, 17 behavioural spawning the real binary — at 96.8% line
coverage, gated at 90 in CI. --self-test remains as the field check that runs where there is
no source tree; this release is the reminder that it is not a substitute for a suite.
Two properties are now asserted that never were: a blocked claimant holds nothing while it
waits (the load-bearing deadlock mechanism identified in AFD-083, which --self-test does not
check), and exit 3 means nothing ran — asserted by the absence of a side effect, not by the
exit code.
Pin
release:pulseengine/jess@v0.7.1!with-device-0.2.1-<triple>.tar.gz!with-device
Falsification statement
If this release is what it claims: the cosign signature over SHA256SUMS.txt verifies against
this workflow's identity; every asset matches that manifest; each archive's SLSA provenance
verifies; a wrapped command containing -h/-V/--version/--status still runs and its exit
code passes through; a second claimant on a held device exits 3 having run nothing; a kill -9'd
holder's device is immediately claimable; an unregistered name is refused; and two processes
claiming the same two devices in opposite order both complete promptly. All are asserted by the
release's own verify job and by cargo test. If any fails, this release is wrong.