docs: revalidate Pingora 0.9.0 traceability - #96
seonghobae wants to merge 1 commit into
Conversation
|
Warning Review limit reachedNext included review available in 19 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head technical re-review on e23ed24c73b05c53050e5f4091de4e403153a76d: the one-file doctoring delta keeps released dependency authority at Pingora 0.9.0@702f69015e53f7244d6ad2e743de571d859a70a4, explicitly treats protected upstream main@4487f7b2ab50f159e4a2cf4f6a6b813f61bb6e19 as prospective only, and revalidates the affected HTTP/1, HTTP/2, failover, framing, TLS, Prometheus, diagnostics/socket and supplier-advisory claims rather than globally substituting a SHA. All five exact-head repository lanes are terminal success: CI 34668917904, Supply Chain 34668917899, TLS H2 Performance 34668917916, PgErd bounded-origin capacity 34668917994, Release Reproducibility 34668917895. Review threads are empty and no production/workflow/dependency/lock/deployment/release/baseline bytes changed. This is technical evidence only, not self-approval or protected-merge credit.
|
@coderabbitai approve |
✅ Action performedComments resolved. Approval is disabled; enable |
|
@coderabbitai review |
|
|
Fresh external revalidation on 2026-09-12: the Rust release index still identifies Rust 1.98.1 (2026-09-03) as the latest stable point release, so the existing TRACEABILITY Rust row remains materially current and does not warrant source churn. This does not promote the compiler foundation; #56 remains the repository's separate protected release-compiler gate. |
Refs #51, #58, #95.
Writer-safe doctoring child of #93 exact
175b831895a58791c5243778c508b17c25f14e46.Fresh claim-by-claim review found that
docs/doctoring/TRACEABILITY.mdstill used historical 0.8-line commit09696b51bc59315353d96686355861604d0bb48cas current authority and still called 0.8.1 the latest Pingora release. That is no longer valid for the candidate dependency graph.This PR:
0.9.0@702f69015e53f7244d6ad2e743de571d859a70a4, while keeping upstream protectedmain@4487f7b2ab50f159e4a2cf4f6a6b813f61bb6e19prospective-only;derivative 2.2.0 / RUSTSEC-2024-0388as an unsuppressed supplier-release root with no patched crate version;lrusafety.Exact source evidence includes Cloudflare's 0.9.0 tag resolving to
702f690..., GitHub release publication on 2026-09-09, the exact 0.9.0docs/user_guide/peer.mdper-read timeout and upstream-header-policy contract, exact failover semantics, and exactpingora-core/src/apps/http_app.rsrequest-header TRACE behavior. The historical source was not globally SHA-replaced without semantic review.Current exact head:
e23ed24c73b05c53050e5f4091de4e403153a76d.Exact-head CI
34668917904, Supply Chain34668917899, TLS H2 Performance34668917916, PgErd bounded-origin capacity34668917994, and Release Reproducibility34668917895are all terminal success. Review threads are empty; exact-head technical re-review5184966507found no further writer-safe defect. This PR is therefore Ready for independent review, but no self-approval or protected-merge credit is claimed.No production Rust, workflow, dependency, Cargo lock, Admin Config implementation, deployment, release state, or dedicated baseline lane #61 is changed. This documentation repair does not bypass #889/#54 supplier RED, independent approval, protected integration, immutable release, NUMA, canary/rollback/cutover, or legacy-removal gates.