Skip to content
Merged

Dev #1402

Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
69 commits
Select commit Hold shift + click to select a range
4972323
chore: back-merge v5.0.0 into dev (#1291)
github-actions[bot] Sep 15, 2026
b8442f1
fix: bind evidence provenance to the run apparatus (#1293)
Brad-Edwards Sep 15, 2026
22b5755
feat(sdl): add post-materialization attestations (#1292)
Brad-Edwards Sep 15, 2026
2ed2d97
fix(evidence): centralize capture admission and governance authority …
Brad-Edwards Sep 15, 2026
a0c4af3
build(release): generate output-bound SBOM and build provenance (#1295)
Brad-Edwards Sep 16, 2026
23f42a3
docs(sdl): audit product-shaped runtime semantics (#1300)
Brad-Edwards Sep 16, 2026
6e0f8d2
ci: shard verification graph and decouple the SonarCloud quality gate…
Brad-Edwards Sep 16, 2026
950b73e
feat(experiment): validate scoped evidence refinements (#1294)
Brad-Edwards Sep 16, 2026
d4fea22
feat(sdl): enforce open-by-default scenario augmentation scope (#1304)
Brad-Edwards Sep 16, 2026
fb75e57
feat(sdl): add explicit participant relationships (#1303)
Brad-Edwards Sep 17, 2026
08c363f
feat: add authoring adapter conformance vectors (#1302)
Brad-Edwards Sep 17, 2026
2a33497
fix(sdl): admit partial listener descriptions (#1306)
Brad-Edwards Sep 17, 2026
be4e778
build(oci): mirror and pre-seed digest-pinned release-test images (#1…
Brad-Edwards Sep 17, 2026
6ac01be
feat: define mixed participant composition semantics (#1307)
Brad-Edwards Sep 17, 2026
7785b44
fix(sdl): separate native service-manager contracts (#1308)
Brad-Edwards Sep 17, 2026
0d1dc87
test: consolidate redundant corpus and contract checks (#1310)
Brad-Edwards Sep 17, 2026
12025b4
feat(runtime): reconcile interrupted control-plane operations (#1311)
Brad-Edwards Sep 17, 2026
340ba7a
docs: reconcile implementation status prose (#1312)
Brad-Edwards Sep 17, 2026
015ad16
chore(deps-dev): bump hatchling from 1.27.0 to 1.32.0 in /implementat…
dependabot[bot] Sep 18, 2026
3c7d64a
chore(deps): bump github/codeql-action/upload-sarif from 4.37.9 to 4.…
dependabot[bot] Sep 18, 2026
926a595
fix(sdl): preserve extensible HTTP method identity (#1314)
Brad-Edwards Sep 18, 2026
87c0fd5
feat(runtime): enforce store ownership leases (#1316)
Brad-Edwards Sep 18, 2026
ad15124
refactor(tooling): simplify connected developer and release workflows…
Brad-Edwards Sep 18, 2026
803257b
feat(contracts): publish mixed composition profile (#1315)
Brad-Edwards Sep 18, 2026
245a5a3
test(sdl): verify progressive conformance end to end (#1318)
Brad-Edwards Sep 18, 2026
9f004b0
docs(dev): verify and document supported container entry points (#1320)
Brad-Edwards Sep 18, 2026
c745080
ci(release): publish only admitted bytes and reconcile destinations (…
Brad-Edwards Sep 18, 2026
aa02b04
fix(runtime): make idempotency claims atomic and scoped (#1321)
Brad-Edwards Sep 18, 2026
fe3b318
feat: admit mixed and staged trial realizations (#1322)
Brad-Edwards Sep 18, 2026
a2aed61
fix(runtime): align the served control-plane profile (#1323)
Brad-Edwards Sep 19, 2026
f40b98d
feat(runtime): add control-plane recovery operations (#1324)
Brad-Edwards Sep 19, 2026
e0cc608
ci(release): prevent docs-only release proposals (#1325)
Brad-Edwards Sep 19, 2026
a4972ca
fix(runtime): harden control-plane profile conformance (#1327)
Brad-Edwards Sep 20, 2026
65ca8e4
feat(semantics): publish modular participant-control semantics (#1328)
Brad-Edwards Sep 20, 2026
3fa5187
chore(deps): bump astral-sh/setup-uv from 10.0.1 to 10.1.0 in the git…
dependabot[bot] Sep 20, 2026
7128f0c
feat(runtime): declare control-plane profiles and capabilities (#1329)
Brad-Edwards Sep 20, 2026
cf0a291
docs(runtime): align API-404 with control-plane profiles (#1337)
Brad-Edwards Sep 20, 2026
4d4b712
feat(contracts): gate published-schema fixture and formal coverage (#…
Brad-Edwards Sep 20, 2026
f784be2
feat: publish participant-control provider and profile contracts (#1334)
Brad-Edwards Sep 20, 2026
24e6652
feat(runtime): coordinate mixed participant runtimes fail closed (#1336)
Brad-Edwards Sep 20, 2026
e4136a6
feat(processor): add reconciliation demonstration harness (#1333)
Brad-Edwards Sep 20, 2026
c4ab3ad
docs: audit participant identity and actor-target semantics (#1343)
Brad-Edwards Sep 21, 2026
6bfdb7e
feat(runtime): orchestrate modular participant control and governed e…
Brad-Edwards Sep 21, 2026
f92f3a2
feat!: separate participant identity and objective assignment (#1345)
Brad-Edwards Sep 21, 2026
c22ae7f
feat: support participant-local outcome categories and state (#1347)
Brad-Edwards Sep 21, 2026
eb0f763
docs(runtime): define operation supervision and recovery (#1375)
Brad-Edwards Sep 22, 2026
eb75e1a
feat: enforce bounded participant temporal guarantees (#1349)
Brad-Edwards Sep 22, 2026
c3a9154
docs: define reusable mixed-control policies and occurrences (#1376)
Brad-Edwards Sep 22, 2026
f6e26ff
docs: define control applicability and effect decisions (#1378)
Brad-Edwards Sep 22, 2026
ddba504
docs: define external inject semantics and install delivery finalizat…
Brad-Edwards Sep 22, 2026
8407a63
docs(runtime): select reusable execution architecture (#1382)
Brad-Edwards Sep 23, 2026
b00aba0
docs: define IFC profile variability and publication rules (#1383)
Brad-Edwards Sep 23, 2026
492a613
docs: define participant access trust boundary (#1386)
Brad-Edwards Sep 25, 2026
cbb5960
docs: clarify participant access across sdk and http (#1387)
Brad-Edwards Sep 25, 2026
fa99098
fix: forward governed context in v2 decision admission (#1384)
Brad-Edwards Sep 25, 2026
5a9d74b
fix: record denied terminal egress outcome (#1385)
Brad-Edwards Sep 25, 2026
023ff5b
feat: publish backend operation and supervision contracts (#1388)
Brad-Edwards Sep 26, 2026
9983647
chore(deps): bump the github-actions group with 4 updates (#1393)
dependabot[bot] Sep 27, 2026
a6382af
feat: execute mixed-backend mapping and time contracts (#1391)
Brad-Edwards Sep 27, 2026
f02a6ee
fix: admit participant delivery temporal subjects (#1390)
Brad-Edwards Sep 27, 2026
c4d90a3
feat: require backends to honour authored trial timeout and retry cho…
Brad-Edwards Sep 27, 2026
8e8d3b5
Revert "feat: require backends to honour authored trial timeout and r…
Brad-Edwards Sep 27, 2026
dc63de0
feat: publish applicable participant-control contracts (#1399)
Brad-Edwards Sep 28, 2026
79c50a9
feat(formal): add independent participant crossing models (#1397)
Brad-Edwards Sep 30, 2026
3eec4bc
feat: enforce the administrative-only runtime API trust boundary (#1394)
Brad-Edwards Sep 30, 2026
44a0fd9
fix: republish research evidence for the merged control-plane boundar…
Brad-Edwards Sep 30, 2026
c6eff0b
fix(deps): upgrade pyjwt to 2.15.1 and urllib3 to 2.8.0 for published…
Brad-Edwards Sep 30, 2026
2a5b0f4
fix: reject unprovable required evidence media types (#1403)
Brad-Edwards Oct 1, 2026
f51a2d1
fix: partition shard items with comprehensions for the SonarCloud gat…
Brad-Edwards Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
45 changes: 9 additions & 36 deletions .devcontainer/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,41 +1,14 @@
# Reviewed RAES development container.
#
# This file owns no version, digest, package, or platform fact. Every literal
# below is derived from the reviewed `container-ubuntu-24.04-x86_64` host profile in
# implementations/tooling/profiles/development-profiles.json and from
# implementations/tooling/artifacts.lock.json; the drift gate in
# tools/tooling_artifact_policy_container.py refuses any literal here that
# disagrees with that authority, so edit the authority, never this file.
#
# The image supplies host prerequisites and maintainer conveniences only. The
# dev-container lifecycle runs `tools.devcontainer_setup`, which acquires the
# locked uv, CPython, and generic CLI payloads through the repository's own
# verified installers, so no payload, checkout, credential, or reusable cache is
# baked into a layer. Isabelle proof execution is unsupported here
# (`proof_support: unsupported`); use the native proof host profile.
#
# Linux x86_64 is the one qualified platform: Ubuntu publishes immutable package
# snapshots only for it. Every stage pins the reviewed linux/amd64 manifest, so
# arm64 hosts such as Apple silicon run this same image under emulation instead
# of silently substituting an unqualified native build.

# The package snapshot is served only over HTTPS and the pinned base carries no
# CA bundle. This throwaway stage obtains one from the base image's own signed
# archive purely as TLS transport trust; none of its bytes reach the image.
FROM --platform=linux/amd64 docker.io/library/ubuntu@sha256:a61567bd31828687156d735ea8eb01ba4e37636e225dd6a48ba94136a70d9d61 AS transport-trust
# Optional connected development environment. The artifact lock owns the base
# digest; this native Dockerfile owns its packages, account, and environment.
# Signed Ubuntu repositories supply current native packages. Rebuilds are not
# byte-reproducible and do not qualify additional host architectures.
# The lifecycle separately verifies locked uv, Python, and CLI payloads.
# Proof isolation and a container daemon are intentionally not supplied.
FROM --platform=linux/amd64 docker.io/library/ubuntu@sha256:a61567bd31828687156d735ea8eb01ba4e37636e225dd6a48ba94136a70d9d61
RUN set -eu; \
export DEBIAN_FRONTEND=noninteractive; \
apt-get update; \
apt-get install -y --no-install-recommends ca-certificates

# Every installed package comes from the immutable reviewed snapshot and is
# authenticated by the Ubuntu archive keyring inside the digest-pinned base.
FROM --platform=linux/amd64 docker.io/library/ubuntu@sha256:a61567bd31828687156d735ea8eb01ba4e37636e225dd6a48ba94136a70d9d61
RUN --mount=type=bind,from=transport-trust,source=/etc/ssl/certs/ca-certificates.crt,target=/run/raes-transport-ca.crt \
set -eu; \
export DEBIAN_FRONTEND=noninteractive; \
apt-get -o APT::Snapshot=20260912T000000Z -o Acquire::https::CAInfo=/run/raes-transport-ca.crt update; \
apt-get -o APT::Snapshot=20260912T000000Z -o Acquire::https::CAInfo=/run/raes-transport-ca.crt install -y --no-install-recommends \
apt-get install -y --no-install-recommends \
bash-completion \
ca-certificates \
coreutils \
Expand All @@ -58,7 +31,7 @@ RUN --mount=type=bind,from=transport-trust,source=/etc/ssl/certs/ca-certificates
find /var/lib/apt/lists -mindepth 1 -delete

# A non-root development account owns the caches and never the mounted source.
# The reviewed base ships a stock account at 1000; replacing it keeps the
# The base ships a stock account at 1000; replacing it keeps the
# development user aligned with the typical host owner of a bind-mounted
# checkout, and dev-container clients remap it to the host owner otherwise.
RUN set -eu; \
Expand Down
13 changes: 7 additions & 6 deletions .gc/plan-rules.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,12 +3,13 @@
Mandatory constraints the `/implement` skill applies during plan phase.
These encode the hard rules previously in `AGENTS.md` prose.

- Plans MUST run `implementations/python/.venv/bin/python tools/check_repo_policy.py`
before declaring completion.
- Plans MUST run `implementations/python/.venv/bin/python tools/check_requirement_governance.py`
before declaring completion.
- Plans MUST run `implementations/python/.venv/bin/python tools/verify_all.py`
before declaring completion.
- Plans MUST follow `/implement`'s proportionate local verification rules:
run targeted tests and checks for the changed behavior locally. CI owns
repository-wide verification, completion, and policy suites. Preserve the
mandatory pre-publish hook, review, CI, SonarCloud, and readiness gates.
- Local test and completion commands MUST remain targeted. Never select a full
test, integration or fuzz suite locally, even on unknown changes, source edits,
base synchronization or review repairs. Full verification is CI/CD only.
- Plans MUST set `RAES_REQUIREMENT_UID` when the branch name does not
already contain a UID such as `GOV-918`.
- Plans MUST NOT add new authority-bearing artifacts outside `specs/`,
Expand Down
166 changes: 30 additions & 136 deletions .github/workflows/bootstrap-qualification.yml
Original file line number Diff line number Diff line change
@@ -1,14 +1,22 @@
name: Bootstrap qualification

# The main->dev back-merge PR changes only Release Please-managed files, which
# were qualified on the dev->main promotion; it does not trigger this (#1266).
# Qualify changed tooling components, not unrelated application or documentation edits.
on:
pull_request:
branches: [dev]
paths-ignore:
- CHANGELOG.md
- .release-please-manifest.json
- implementations/python/packages/raes/_version.py
paths:
- '.github/workflows/bootstrap-qualification.yml'
- '.devcontainer/**'
- 'implementations/tooling/**'
- 'implementations/python/pyproject.toml'
- 'implementations/python/uv.lock'
- 'implementations/python/tests/test_issue_1217_bootstrap_profiles.py'
- 'implementations/python/tests/test_issue_1219_verified_tool_installation.py'
- 'implementations/python/tests/test_issue_1220_isabelle_acquisition.py'
- 'implementations/python/tests/test_issue_1238_development_container.py'
- 'implementations/python/tests/test_issue_1313_workflow_policy.py'
- 'tools/**'
- 'noxfile.py'
workflow_dispatch:

permissions:
Expand All @@ -23,9 +31,9 @@ jobs:
fail-fast: false
matrix:
include:
- {profile: public-ubuntu-24.04-x86_64, runner: ubuntu-24.04, target: x86_64-unknown-linux-gnu, tool_closure: public-linux-x86_64-cp314-tools, tool_requirements: implementations/tooling/python/smoke/tools-linux-x86_64-cp314.txt, project_closure: public-linux-x86_64-cp314-all-extras}
- {profile: public-linux-arm64, runner: ubuntu-24.04-arm, target: aarch64-unknown-linux-gnu, tool_closure: public-linux-arm64-cp314-tools, tool_requirements: implementations/tooling/python/smoke/tools-linux-arm64-cp314.txt, project_closure: public-linux-arm64-cp314-all-extras}
- {profile: public-macos-arm64, runner: macos-15, target: aarch64-apple-darwin, tool_closure: public-macos-arm64-cp314-tools, tool_requirements: implementations/tooling/python/smoke/tools-macos-arm64-cp314.txt, project_closure: public-macos-arm64-cp314-all-extras}
- {profile: public-ubuntu-24.04-x86_64, runner: ubuntu-24.04, target: x86_64-unknown-linux-gnu, project_closure: public-linux-x86_64-cp314-all-extras}
- {profile: public-linux-arm64, runner: ubuntu-24.04-arm, target: aarch64-unknown-linux-gnu, project_closure: public-linux-arm64-cp314-all-extras}
- {profile: public-macos-arm64, runner: macos-15, target: aarch64-apple-darwin, project_closure: public-macos-arm64-cp314-all-extras}
env:
UV_PYTHON: "3.14.7"
UV_PYTHON_PLATFORM: ${{ matrix.target }}
Expand All @@ -41,7 +49,7 @@ jobs:
with:
python-version: "3.14.7"
- name: Install exact uv payload
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v8
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v8
with:
version: "0.12.4"
enable-cache: false
Expand All @@ -54,138 +62,25 @@ jobs:
- name: Exercise supported Python wheel and ABI closure
if: matrix.project_closure != ''
run: uv run --project implementations/tooling/python --frozen --no-default-groups nox -f noxfile.py -s python-compatibility
- name: Build the credential-free target payload kit
id: kit
- name: Exercise verified tool acquisition and reuse
run: |
tool_python=(uv run --project implementations/tooling/python --frozen --no-default-groups python)
"${tool_python[@]}" -m tools.bootstrap_profile generic-tools
mkdir -p .qualification-kit/bin .qualification-kit/python .qualification-kit/.cache/raes-sdl \
.qualification-kit/tool-wheelhouse
"${tool_python[@]}" -m tools.bootstrap_profile offline-kit-fetch \
"${{ matrix.profile }}" .qualification-kit --artifact-id cpython-3.14 --artifact-id uv \
--artifact-id conftest --artifact-id gitleaks --artifact-id osv-scanner --artifact-id vale
cp "$(command -v uv)" .qualification-kit/bin/uv
"${tool_python[@]}" -m tools.bootstrap_profile offline-kit-install-python \
"${{ matrix.profile }}" .qualification-kit --python-artifact-id cpython-3.14
"${tool_python[@]}" -m tools.python_closure materialize \
--profile "${{ matrix.tool_closure }}" --wheelhouse .qualification-kit/tool-wheelhouse
"${tool_python[@]}" -m tools.python_closure manifest-show \
--profile "${{ matrix.tool_closure }}" > .qualification-kit/tool-wheelhouse-manifest.json
if [ -n "${{ matrix.project_closure }}" ]; then
mkdir .qualification-kit/project-wheelhouse
"${tool_python[@]}" -m tools.python_closure materialize \
--profile "${{ matrix.project_closure }}" --wheelhouse .qualification-kit/project-wheelhouse
"${tool_python[@]}" -m tools.python_closure manifest-show \
--profile "${{ matrix.project_closure }}" > .qualification-kit/wheelhouse-manifest.json
fi
"${tool_python[@]}" -m tools.bootstrap_profile offline-kit-export-tool-seeds \
"${{ matrix.profile }}" .cache/raes-sdl/tooling/installations \
.qualification-kit/.cache/raes-sdl/tooling/installations
"${tool_python[@]}" -m tools.bootstrap_profile offline-kit-manifest \
"${{ matrix.profile }}" .qualification-kit --python-artifact-id cpython-3.14 \
> .qualification-kit/offline-kit-manifest.json
manifest_sha256="$("${tool_python[@]}" -m tools.bootstrap_profile \
offline-kit-manifest-digest .qualification-kit/offline-kit-manifest.json)"
echo "manifest_sha256=${manifest_sha256}" >> "$GITHUB_OUTPUT"
tar -cf bootstrap-offline-kit.tar .qualification-kit
- name: Restore and exercise the payload kit without network fallback
run: |
for cleanup_root in \
.qualification-kit/.cache/raes-sdl/tooling/installations \
.cache/raes-sdl/tooling/installations; do
if [ -d "${cleanup_root}" ]; then
chmod -R u+w "${cleanup_root}"
fi
done
rm -rf .qualification-kit .cache/raes-sdl/tooling .qualification-restored \
implementations/python/.venv implementations/tooling/python/.venv
mkdir .qualification-restored
tar -xf bootstrap-offline-kit.tar -C .qualification-restored --strip-components=1
restored_root="${{ github.workspace }}/.qualification-restored"
restored_python="$(find "${restored_root}/python" -path '*/bin/python3.14' -print)"
test -n "${restored_python}"
export UV_PYTHON="${restored_python}"
export PATH="${restored_root}/bin:/usr/bin:/bin"
export UV_PYTHON_INSTALL_DIR="${restored_root}/python"
export UV_PYTHON_DOWNLOADS=never
export UV_OFFLINE=1
runtime_root="$(mktemp -d "${GITHUB_WORKSPACE}/.raes-bootstrap-runtime.XXXXXX")"
export UV_CACHE_DIR="${runtime_root}/uv-cache"
mkdir "${UV_CACHE_DIR}"
"${restored_python}" -m tools.python_closure bootstrap-wheelhouse-verify \
--profile "${{ matrix.tool_closure }}" --wheelhouse "${restored_root}/tool-wheelhouse" \
--manifest-snapshot "${restored_root}/tool-wheelhouse-manifest.json"
if [ -n "${{ matrix.project_closure }}" ]; then
"${restored_python}" -m tools.python_closure bootstrap-wheelhouse-verify \
--profile "${{ matrix.project_closure }}" --wheelhouse "${restored_root}/project-wheelhouse" \
--manifest-snapshot "${restored_root}/wheelhouse-manifest.json"
fi
restored_tool_environment="${runtime_root}/tool-environment"
"${restored_root}/bin/uv" venv --no-project --python "${restored_python}" \
"${restored_tool_environment}"
restored_tool_python="${restored_tool_environment}/bin/python"
"${restored_root}/bin/uv" pip install --python "${restored_tool_python}" \
--requirements "${{ matrix.tool_requirements }}" --require-hashes --only-binary :all: \
--offline --no-index --find-links "${restored_root}/tool-wheelhouse"
"${restored_tool_python}" -m tools.bootstrap_profile offline-kit-verify \
"${{ matrix.profile }}" "${restored_root}" --python-artifact-id cpython-3.14 \
--trusted-manifest-sha256 "${{ steps.kit.outputs.manifest_sha256 }}"
if [ -n "${{ matrix.project_closure }}" ]; then
export UV_FIND_LINKS="${restored_root}/tool-wheelhouse,${restored_root}/project-wheelhouse"
export UV_NO_INDEX=1
export RAES_PYTHON_CLOSURE_WHEELHOUSE="${restored_root}/project-wheelhouse"
"${restored_tool_python}" -m nox -f noxfile.py -s python-compatibility
else
"${restored_tool_python}" -c \
'import cryptography; from importlib.metadata import version; print(version("nox"))'
fi
"${restored_tool_python}" -m tools.bootstrap_profile record-case T02 "${{ github.sha }}" noxfile.py \
--artifact-id cpython-3.14 --artifact-id uv --artifact-id conftest --artifact-id gitleaks \
--artifact-id osv-scanner --artifact-id vale > t02-result.json
if [ "${{ matrix.profile }}" = public-linux-arm64 ] || [ "${{ matrix.profile }}" = public-macos-arm64 ]; then
"${restored_tool_python}" -m tools.bootstrap_profile record-case T12 "${{ github.sha }}" \
tools/bootstrap_profile.py --artifact-id cpython-3.14 --artifact-id uv --artifact-id conftest \
--artifact-id gitleaks --artifact-id osv-scanner --artifact-id vale > t12-result.json
fi
uv run --project implementations/tooling/python --frozen --no-default-groups python \
-m tools.bootstrap_profile generic-tools
- name: Exercise maintained curl behavior
run: |
uv run --project implementations/tooling/python --frozen --no-default-groups python \
-m tools.bootstrap_profile inspect-profile "${{ matrix.profile }}"
uv run --project implementations/tooling/python --frozen --no-default-groups python -m pytest -q \
implementations/python/tests/test_issue_1217_bootstrap_profiles.py \
uv run --project implementations/tooling/python --frozen --no-default-groups --group acquisition-tests python \
-m pytest -q implementations/python/tests/test_issue_1217_bootstrap_profiles.py \
implementations/python/tests/test_issue_1220_isabelle_acquisition.py -m integration -k real_curl
uv run --project implementations/tooling/python --frozen --no-default-groups python \
-m tools.bootstrap_profile record-case T08 "${{ github.sha }}" \
implementations/python/tests/test_issue_1217_bootstrap_profiles.py > t08-result.json
- name: Exercise verified local installation behavior
run: >-
uv run --project implementations/tooling/python --frozen --no-default-groups nox -f noxfile.py
-s local-installation-qualification -- --output local-installation-qualification.json
- name: Record exact measured profile evidence
run: |
mkdir .qualification-evidence-root
tar -xf bootstrap-offline-kit.tar -C .qualification-evidence-root --strip-components=1
case_results=(--case-result t02-result.json --case-result t08-result.json)
if [ -f t12-result.json ]; then
case_results+=(--case-result t12-result.json)
fi
uv run --project implementations/tooling/python --frozen --no-default-groups python \
-m tools.bootstrap_profile qualification-evidence \
"${{ matrix.profile }}" "${{ github.sha }}" \
"github-actions:${{ github.repository }}:${{ github.run_id }}:${{ github.run_attempt }}" \
--python-artifact-id cpython-3.14 "${case_results[@]}" \
--slice-evidence local-installation-qualification.json \
--offline-kit-root .qualification-evidence-root --offline-kit bootstrap-offline-kit.tar \
--offline-kit-manifest-sha256 "${{ steps.kit.outputs.manifest_sha256 }}" \
> bootstrap-qualification.json
- name: Retain bounded qualification evidence
- name: Retain local installation results
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: bootstrap-${{ matrix.profile }}-${{ github.sha }}
path: |
bootstrap-qualification.json
bootstrap-offline-kit.tar
path: local-installation-qualification.json
if-no-files-found: error

development-image:
Expand All @@ -203,7 +98,7 @@ jobs:
with:
python-version: "3.14.7"
- name: Install exact uv payload
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v8
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v8
with:
version: "0.12.4"
enable-cache: false
Expand Down Expand Up @@ -234,8 +129,9 @@ jobs:
- name: Prepare a clean checkout owned by the development user
run: |
git clone --no-local --no-hardlinks "${GITHUB_WORKSPACE}" "${RUNNER_TEMP}/rae"
sudo chown -R "$(jq -r '"\(.development_user.uid):\(.development_user.gid)"' \
"${RUNNER_TEMP}/development-image-plan.json")" "${RUNNER_TEMP}/rae"
development_uid="$(docker run --rm --entrypoint id raes-development-image:smoke -u)"
development_gid="$(docker run --rm --entrypoint id raes-development-image:smoke -g)"
sudo chown -R "${development_uid}:${development_gid}" "${RUNNER_TEMP}/rae"
- name: Open the container as a dev-container client does
run: |
workspace=/workspaces/rae
Expand Down Expand Up @@ -265,7 +161,7 @@ jobs:
command -v "${tool}"
done
test -x .git/hooks/pre-commit
test -x .git/hooks/pre-push
test ! -e .git/hooks/pre-push
nox -s policy -- --skip-requirement
nox -s lint
nox -s tests
Expand Down Expand Up @@ -304,9 +200,7 @@ jobs:
source_revision: $source_revision,
declared_base_image_index_digest: .base_image_index_digest,
declared_base_image_digest: .base_image_digest,
native_repository_snapshot,
resulting_image_id: $image_id,
policy_sha256,
artifact_lock_sha256: $lock_sha256,
development_profiles_sha256: $profiles_sha256,
commands: [
Expand Down
Loading
Loading