Skip to content

docs: revalidate Pingora 0.9.0 traceability - #96

Open
seonghobae wants to merge 1 commit into
docs/h2-h1-framing-owner-path-v1from
docs/pingora-0-9-traceability-v1
Open

seonghobae wants to merge 1 commit into
docs/h2-h1-framing-owner-path-v1from
docs/pingora-0-9-traceability-v1

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

Refs #51, #58, #95.

Writer-safe doctoring child of #93 exact 175b831895a58791c5243778c508b17c25f14e46.

Fresh claim-by-claim review found that docs/doctoring/TRACEABILITY.md still used historical 0.8-line commit 09696b51bc59315353d96686355861604d0bb48c as current authority and still called 0.8.1 the latest Pingora release. That is no longer valid for the candidate dependency graph.

This PR:

  • establishes released dependency authority at Pingora 0.9.0@702f69015e53f7244d6ad2e743de571d859a70a4, while keeping upstream protected main@4487f7b2ab50f159e4a2cf4f6a6b813f61bb6e19 prospective-only;
  • revalidates server/retry/graceful-shutdown, request-policy, HTTP/1 parser and per-read timeout, bounded HTTP/2 defaults, failover, framing, Prometheus, TLS peer/CA, diagnostics and socket-authority rows against the 0.9.0 release source rather than silently substituting a moving branch;
  • records the 0.9.0 breaking/default-policy changes that matter to those claims, including default hop-by-hop/Connection-nominated stripping, bounded HTTP/2 defaults, Prometheus crate split and shutdown/runtime changes;
  • records derivative 2.2.0 / RUSTSEC-2024-0388 as an unsuppressed supplier-release root with no patched crate version;
  • replaces the stale 0.8.1/latest and old seven-commit compare claims with current release/tag and release-vs-main authority evidence;
  • rebases APA-7 source URLs to the exact released source identity and removes the stale claim that a historical upstream pin proves current lru safety.

Exact source evidence includes Cloudflare's 0.9.0 tag resolving to 702f690..., GitHub release publication on 2026-09-09, the exact 0.9.0 docs/user_guide/peer.md per-read timeout and upstream-header-policy contract, exact failover semantics, and exact pingora-core/src/apps/http_app.rs request-header TRACE behavior. The historical source was not globally SHA-replaced without semantic review.

Current exact head: e23ed24c73b05c53050e5f4091de4e403153a76d.

Exact-head CI 34668917904, Supply Chain 34668917899, TLS H2 Performance 34668917916, PgErd bounded-origin capacity 34668917994, and Release Reproducibility 34668917895 are all terminal success. Review threads are empty; exact-head technical re-review 5184966507 found no further writer-safe defect. This PR is therefore Ready for independent review, but no self-approval or protected-merge credit is claimed.

No production Rust, workflow, dependency, Cargo lock, Admin Config implementation, deployment, release state, or dedicated baseline lane #61 is changed. This documentation repair does not bypass #889/#54 supplier RED, independent approval, protected integration, immutable release, NUMA, canary/rollback/cutover, or legacy-removal gates.

@coderabbitai

coderabbitai Bot commented Sep 12, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 19 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 391e28b9-92a7-404b-ab0d-df807ca0e094

📥 Commits

Reviewing files that changed from the base of the PR and between 175b831 and e23ed24.

📒 Files selected for processing (1)
  • docs/doctoring/TRACEABILITY.md

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head technical re-review on e23ed24c73b05c53050e5f4091de4e403153a76d: the one-file doctoring delta keeps released dependency authority at Pingora 0.9.0@702f69015e53f7244d6ad2e743de571d859a70a4, explicitly treats protected upstream main@4487f7b2ab50f159e4a2cf4f6a6b813f61bb6e19 as prospective only, and revalidates the affected HTTP/1, HTTP/2, failover, framing, TLS, Prometheus, diagnostics/socket and supplier-advisory claims rather than globally substituting a SHA. All five exact-head repository lanes are terminal success: CI 34668917904, Supply Chain 34668917899, TLS H2 Performance 34668917916, PgErd bounded-origin capacity 34668917994, Release Reproducibility 34668917895. Review threads are empty and no production/workflow/dependency/lock/deployment/release/baseline bytes changed. This is technical evidence only, not self-approval or protected-merge credit.

@seonghobae
seonghobae marked this pull request as ready for review September 12, 2026 03:05

Copy link
Copy Markdown
Contributor Author

@coderabbitai approve

@coderabbitai

coderabbitai Bot commented Sep 12, 2026

Copy link
Copy Markdown
✅ Action performed

Comments resolved. Approval is disabled; enable reviews.request_changes_workflow to allow explicit top-level @coderabbitai resolve or @coderabbitai approve commands.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 12, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

Fresh external revalidation on 2026-09-12: the Rust release index still identifies Rust 1.98.1 (2026-09-03) as the latest stable point release, so the existing TRACEABILITY Rust row remains materially current and does not warrant source churn. This does not promote the compiler foundation; #56 remains the repository's separate protected release-compiler gate.

@seonghobae seonghobae added documentation Improvements or additions to documentation priority: medium labels Sep 12, 2026 — with ChatGPT Codex Connector
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation priority: medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant