Chore/backlog sweep 2026 07 - #66
Merged
Merged
Conversation
…ma $id Five file-disjoint backlog issues, all additive (no wire/Rust-logic change): - #20 Conformance registry page + reproducible-report seed + badge + PR submission checklist. Seed report is a verified 12/12 capture of `contextgraph-inspect stdio --json` against the bundled example provider. - #16 Tag-triggered, environment-gated crates.io release.yml + a credential-free `publish-dry-run` CI job + crates.io/docs.rs badges. Version cut and the crates-io environment/secret remain the owner's decision. - #59 sdk/PUBLISHING.md + tag-gated publish-sdks.yml; PyPI/Go publishes and the Go tag remain human-only. npm already live via #46. - #29 downstream-canary.yml builds stella's contextgraph-* consumers against HEAD (advisory); oxagen-canary activates once OXAGEN_PLATFORM_TOKEN is wired. - #58 schema $id repointed to the GitHub-raw URL that resolves today (interim until #57's Vercel relink); schema validate-examples.py green, mirror byte-identical. Closes #20, #29, #58 Refs #16, #59 (publish/tag/secret steps are human-only) Claude-Session: https://claude.ai/code/session_01Co9faUWdYC1SPqrof7njyD
…mment (#49) Closes the two remaining #49 "survivors": - SPEC.md gains a normative §7.3 "Usage reports" (UR1): a host MUST be able to produce a usage report whose budget_consumed equals the summed token_cost of served frames, referencing them by FrameId — backed by the existing, tested contextgraph-host::FanOut::usage_report. Resolves the "U1" anchor collision with §13's ignore-unknown-members rule by labelling this UR1 across SPEC.md, docs/context-reuse.md, and docs/protocol-surface.md, and repointing §14's A1 cross-reference at §7.3. - Reword the schema canonical_token_cost $comment so tokenizer_ref pairs only with canonical_token_cost (the exact-count companion), never the byte-formula token_cost (§B3/§7.2) — resolving #50's tokenizer residual. Source and site schema copies stay byte-identical. schema/validate-examples.py green. Closes #49 Refs #50 Claude-Session: https://claude.ai/code/session_01Co9faUWdYC1SPqrof7njyD
The graph itself is already real and witnessed — §8 specifies graph frames, the open `rel` vocabulary, and the G1/G2/G3/G4 checks (G4's anchored predicate and its `anchor-relevance` check landed in #63/#64). The one remaining #7 acceptance box was the design sketch for multi-hop traversal. Adds docs/sketches/context-neighbors.md (a `context/neighbors { uri, rels, depth }` envelope pair as a post-1.0 additive minor, defined so `depth: 1` ≡ the G4 anchored set) following the docs/sketches/resolve.md template, and a §8.3 forward-reference in SPEC.md mirroring the §6.4.1 deferral pattern. No wire change — traversal beyond one hop is explicitly out of scope for the 1.0 freeze. Closes #7 Claude-Session: https://claude.ai/code/session_01Co9faUWdYC1SPqrof7njyD
#9) The wire already carried `code: Option<ErrorCode>`; nothing read it. This plumbs it end to end and tightens the conformance floor: - ErrorCode gains `unsupported_representation` (§P5) and `incompatible_version` (§H3), wired through as_str/From<&str>/reaction(). incompatible_version is permanent — a new HostReaction::DropProvider (the request is fine, the provider is unusable; distinct from DoNotRetry/Respawn/ReportAndCount). - HostError::Provider now carries `code`; the four http.rs/stdio.rs error arms pass it through instead of discarding it, so FanOut::failures() surfaces it. - The malformed-input-tolerance conformance check now passes only on a `bad_request` code (was: any Envelope::Error), per SPEC.md R1. A new `--misbehave mislabel-malformed` mode (answers `internal`) exercises the tightened check in conformance-red.sh, with a matching suite test. Gate green: fmt, clippy -D warnings, test --workspace, conformance-green (12/12), conformance-red (all misbehave modes caught). Closes #9 Claude-Session: https://claude.ai/code/session_01Co9faUWdYC1SPqrof7njyD
C7/C8 were specified (§4.2) but listed as a live enforcement gap (§11.1). This implements them in the reference host: - C7 (TLS for non-loopback): HttpProvider refuses a plaintext http:// target to any non-loopback host with HostError::InsecureTransport, BEFORE the client is built or DNS resolves. Loopback (localhost / 127.0.0.0/8 / [::1]) stays exempt so the wiremock suite keeps working. - C8 (credentials never logged): a new Credential type whose Debug AND Display both render only "Credential(<redacted>)" (secret reachable only via a crate-private expose()); attached via reqwest bearer_auth, never a format string. A redaction test asserts no HostError/format string leaks the secret. - connect_with_auth / Host::add_http take an optional Credential (connect stays as a back-compat None wrapper); a 401 surfaces as HostError::Unauthorized. - SPEC.md §11.1 updated: C7/C8 now enforced + unit-tested at the transport-refusal/redaction level; full live-TLS-peer conformance remains the stated next increment (unchanged). Gate green: fmt, clippy -D warnings, test (119 host + 4 new), conformance green/red, schema validate. wiremock was already a dev-dep. Closes #13 Claude-Session: https://claude.ai/code/session_01Co9faUWdYC1SPqrof7njyD
There was a problem hiding this comment.
Sorry @macanderson, you have reached your weekly rate limit of 500000 diff characters.
Please try again later or upgrade to continue using Sourcery
Reviewer's GuideImplements HTTP transport hardening and credential redaction in the host, wires through structured error codes, and adds CI + documentation scaffolding for publishing crates/SDKs and tracking conformant providers and downstream consumers ahead of the protocol freeze. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
macanderson
added a commit
that referenced
this pull request
Jul 30, 2026
Resolves the conflicts on PR #69. Most of this branch had already landed on main via #66 and #67, so the merge is mainly about keeping what is genuinely new (#28, #21, #2) and taking main's side everywhere #68 made a decision. Resolution rules applied: - site/ is retired (ADR 0008, #68). All nine modify/delete conflicts under site/ take main's deletion; the branch's edits to the .mdx mirrors and to site/public/schema/ are dropped rather than resurrected. tests/ docs_site_witness_test.py goes with it — it asserted the site mirrored the markdown docs. - Advertised artifact URLs take main's rewrite: cgp.oxagen.sh/badges/... and site/public/... become the GitHub-raw paths that check-deploy-hygiene.py enforces. This covers the three SDK READMEs, docs/registry.md, docs/implementing-a-provider.md and the CHANGELOG entry for #20. - The CGP abbreviation convention (#21) is kept where it does not collide with the above: docs/index.md, docs/composition-walkthrough.md, and the "CGP maintainers" cell in the registry table now sit on top of main's paths. - .github/workflows/ci.yml: the branch's publish-dry-run job is dropped because main already carries it (via #66) — keeping both would have created a duplicate YAML job key. The branch's `site: docs site builds` job is dropped for the same reason site/ is; main's deploy-hygiene job stands. - schema/validate-examples.py keeps the new lifecycle-record section (#28) — 13 fixtures plus the detached attestation — with its site/public/schema/ mirror checks removed, since there is no second copy to keep in sync. - docs/profiles/context-exchange-provider.md LF2 is restated: the normative MUST was a byte-identical site/public/schema/ mirror enforced by a check that no longer exists. It now pins the $id to GitHub-raw per ADR 0008. This was in cleanly auto-merged text, so git did not flag it. Net contribution over main after the merge is 34 files / +2,507: the Context Exchange Provider lifecycle profile (#28), the CGP abbreviation pass (#21), and the README CI badge (#2 partial). Verified: cargo fmt --check, cargo test --workspace --all-features, cargo clippy -D warnings, python3 schema/validate-examples.py (all examples validate), python3 .github/scripts/check-deploy-hygiene.py (deploy hygiene holds), and all relative links in 58 markdown files resolve. Claude-Session: https://claude.ai/code/session_014H5SE4vnAP4Nw1MBMHfUpt
macanderson
added a commit
that referenced
this pull request
Jul 30, 2026
Resolves the conflicts on PR #69. Most of this branch had already landed on main via #66 and #67, so the merge is mainly about keeping what is genuinely new (#28, #21, #2) and taking main's side everywhere #68 made a decision. Resolution rules applied: - site/ is retired (ADR 0008, #68). All nine modify/delete conflicts under site/ take main's deletion; the branch's edits to the .mdx mirrors and to site/public/schema/ are dropped rather than resurrected. tests/ docs_site_witness_test.py goes with it — it asserted the site mirrored the markdown docs. - Advertised artifact URLs take main's rewrite: cgp.oxagen.sh/badges/... and site/public/... become the GitHub-raw paths that check-deploy-hygiene.py enforces. This covers the three SDK READMEs, docs/registry.md, docs/implementing-a-provider.md and the CHANGELOG entry for #20. - The CGP abbreviation convention (#21) is kept where it does not collide with the above: docs/index.md, docs/composition-walkthrough.md, and the "CGP maintainers" cell in the registry table now sit on top of main's paths. - .github/workflows/ci.yml: the branch's publish-dry-run job is dropped because main already carries it (via #66) — keeping both would have created a duplicate YAML job key. The branch's `site: docs site builds` job is dropped for the same reason site/ is; main's deploy-hygiene job stands. - schema/validate-examples.py keeps the new lifecycle-record section (#28) — 13 fixtures plus the detached attestation — with its site/public/schema/ mirror checks removed, since there is no second copy to keep in sync. - docs/profiles/context-exchange-provider.md LF2 is restated: the normative MUST was a byte-identical site/public/schema/ mirror enforced by a check that no longer exists. It now pins the $id to GitHub-raw per ADR 0008. This was in cleanly auto-merged text, so git did not flag it. Net contribution over main after the merge is 34 files / +2,507: the Context Exchange Provider lifecycle profile (#28), the CGP abbreviation pass (#21), and the README CI badge (#2 partial). Verified: cargo fmt --check, cargo test --workspace --all-features, cargo clippy -D warnings, python3 schema/validate-examples.py (all examples validate), python3 .github/scripts/check-deploy-hygiene.py (deploy hygiene holds), and all relative links in 58 markdown files resolve.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull request
Summary
What changed
Checklist
fmt,clippy -D warnings,testREADME.md,docs/, doc comments,--helptext)git commit -s, DCO)CHANGELOG.mdupdated under[Unreleased]if user-visibleProtocol-stability impact (if a spec/wire change)
contextgraph/1contextgraph/2; explain belowLicense
By submitting this pull request, I agree to dual-license this contribution
under MIT OR Apache-2.0, as certified by my DCO sign-off.
Summary by Sourcery
Enforce and document stricter protocol and transport guarantees around HTTP credentials and error codes, introduce a conformance registry and downstream canary tooling ahead of the 1.0 freeze, and add automated, gated publishing workflows for crates and SDKs.
New Features:
Enhancements:
Build:
CI:
Documentation:
Tests:
Chores: