Repository navigation
v1.2.0 — Trust-chain transparency
[1.2.0] - 2026-04-26
v1.2 "Trust-chain transparency" makes the labeler's trust posture
auditable. Operators and external auditors can now read the full
signing-key history, maintainer roster (with HTTP-attested vs CLI-
inserted provenance), service record content hash, and instance
metadata via a single admin endpoint. The audit log gains a per-id
detail view to complement the existing list query, and the service-
record lifecycle gains its inverse —cairn unpublish-service-record
— closing a documented friction point in the operator workflow.
Added
tools.cairn.admin.getTrustChainadmin XRPC endpoint andcairn trust-chain showCLI subcommand. Read-only, admin-role-only summary of instance trust posture: signing-key history (active + rotated, withvalidFrom/validTo), maintainer roster withprovenanceAttestedflag distinguishing HTTP-attested adds from CLI/SQL inserts, published service-record content hash + declared label values, and instance metadata (build version, service endpoint). The envelope reuses thetools.cairn.admin.defsshared types so the CLI and any other consumer agree on wire shape (#35, #36, #37)tools.cairn.admin.getAuditLogadmin XRPC endpoint andcairn audit show <id>CLI subcommand. Per-id detail view complementingcairn audit list(the v1.1 list query). Admin-role-only; returns the bareauditEntryshape with the fullreasonpayload.AuditEntryNotFound404 on unknown id mirrorsgetReport's posture (#26)cairn unpublish-service-recordCLI subcommand. Removes theapp.bsky.labeler.servicerecord from the operator's PDS viacom.atproto.repo.deleteRecord(withswapRecordfor race detection), clearsservice_record_*labeler_configstate, and writes aservice_record_unpublishedaudit row in one transaction. Idempotent — running on an unpublished labeler is a no-op success that still audits. Subsequentcairn servestartup verify (§F19) fail-starts with the existing exit 13SERVICE_RECORD_ABSENTuntil republish; no new exit code needed (#34)
Changed
ReportStatusandResolutionActionextracted from string fields to typed Rust enums. Wire shape unchanged; the change is internal type safety + central enumeration of allowed values (#27)acquire_service_authandtruncatefactored from per-CLI-module copies into sharedsrc/cli/auth.rsandsrc/cli/output.rs. No behavior change; the factor-out triggered whencli/trust_chain.rsbrought the duplicatedacquire_service_authto eight identical copies across four modules (#28)- F10 audit-log actions list in cairn-design.md updated to include
service_record_unpublished(#34)
Fixed
tests/wellknown.rs::ALL_LEXICONSnow exercises every lexicon served at.well-known/lexicons/*—getTrustChain,retentionSweep, andgetAuditLogwere previously missing from the per-NSID serving test (coverage gap, not a correctness gap; the underlying handlers and routes were always tested) (#38)