Skip to content

fix: republish research evidence for the merged control-plane boundary source - #1404

Merged
Brad-Edwards merged 19 commits into
devfrom
1359-enforce-runtime-api-boundary
Sep 30, 2026
Merged

Brad-Edwards merged 19 commits into
devfrom
1359-enforce-runtime-api-boundary

Conversation

@Brad-Edwards

Copy link
Copy Markdown
Collaborator

Summary

#1394 merged at its base-sync commit. That commit carried dev's research evidence captures, which were cut before the #1394 control-plane source changes, so dev now records an implementation digest that no longer matches its source. This republishes both research evidence captures above dev's latest releases and binds them to the merged source. No runtime code changes.

Requirement UIDs

  • API-404

Related Issues

Refs #1359

ADR Impact

  • ADR-104

Changes

  • Specification-coverage release 64.0.0 (execution-snapshot-v64.json, analysis-v64.json, issue-1359 bundle) replays the retained matrix against the merged feat: enforce the administrative-only runtime API trust boundary #1394 source.
  • Formal-validation release 65.0.0 (execution-snapshot-v65.json, analysis-v65.json, retest-v65.json) replays the retained formal cases with baseline 64.0.0.
  • Revision pins advanced in tools/check_specification_coverage.py, tools/formal_semantic_validation/, and the three evidence test modules. Both research indexes record the new releases, and the formal index's current-release statement is corrected to 65.0.0.

Test Plan

  • Unit tests pass
  • Integration tests pass if applicable
  • Full completion suite required in CI before merge
  • No coverage regression

Both evidence checker CLIs pass (integrity and replay), the three evidence modules pass including their integration lane (223), the control-plane test files pass (1,060), and fast-feedback and repo policy are green.

Ground Control Checks

  • Repository policy checks required in CI before merge
  • Pre-push Codex review completed; all findings fixed or dispositioned

Traceability

  • IMPLEMENTS: API-404 ← implementations/python/packages/raes_runtime/control_plane_api/_auth.py
  • TESTS: API-404 ← implementations/python/tests/test_formal_semantic_validation.py, API-404 ← implementations/python/tests/test_specification_coverage.py, API-404 ← implementations/python/tests/test_issue_989_versioned_evidence.py

Checklist

  • Code follows the project's coding standards
  • Changelog: owned by Release Please (generated from the Conventional Commit PR title; no per-PR fragment)
  • Architectural docs updated if stack, package structure, or key behaviors changed

Documentation

Updated: see diff.

@Brad-Edwards

Copy link
Copy Markdown
Collaborator Author

Ground Control delivery — this pull request delivers issue #1359; Phase E runs on merge.

@Brad-Edwards
Brad-Edwards merged commit 44a0fd9 into dev Sep 30, 2026
33 checks passed
@Brad-Edwards
Brad-Edwards deleted the 1359-enforce-runtime-api-boundary branch September 30, 2026 21:44
Brad-Edwards added a commit that referenced this pull request Sep 30, 2026
… advisories (#1405)

* fix(deps): upgrade pyjwt to 2.15.1 and urllib3 to 2.8.0 for published advisories

The pyjwt 2.15.1 upgrade from #1404's branch was dropped by a later
merge-conflict resolution that took dev's uv.lock, so dev shipped
pyjwt 2.14.0 (GHSA-42vr-xj54-vc7v). urllib3 2.7.0 has three new
advisories fixed in 2.8.0 (GHSA-8988-9cw3-xx77, GHSA-gh4c-6fx4-qh6g,
GHSA-vxq7-64xx-v4gw). Both made the osv-scan supply-chain gate fail.

Regenerate the hash-complete smoke closures and republish both
research-evidence captures, which bind to the locked dependency set:
specification coverage 65.0.0 and formal semantic validation 66.0.0.

* style: format the specification-coverage release set

* fix(formal): rebind the crossing model bundle to the upgraded lock
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant