Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
31 commits
Select commit Hold shift + click to select a range
69c9a1b
feat(config): bind native Compose routes to verified ingress
Oct 7, 2026
e1441ac
feat: add private native Compose hostname claims
Oct 7, 2026
27b6b8e
fix: bind hostname claim capabilities and durable rollback
Oct 7, 2026
c765887
feat(config): lower admitted routes onto external Compose ingress
Oct 7, 2026
0cb21f6
feat: verify native Compose proxy route policy
Oct 8, 2026
d26bd1b
feat: integrate owned native Compose route transitions
Oct 8, 2026
557317b
feat: integrate finite hooks with native Compose routing
Oct 8, 2026
d99c612
test: cover native route inventory and proxy proof boundaries
Oct 8, 2026
38794e2
feat: qualify native routes with the live Caddy API
Oct 8, 2026
72bef91
feat(config): integrate native routed startup ownership
Oct 8, 2026
4d64bae
chore: reconcile native routing with latest next
Oct 8, 2026
504e361
fix(config): finalize routes before completed generation receipts
Oct 8, 2026
1e4a186
feat: qualify native routing and saved open origins
Oct 8, 2026
f09e4a5
test: preserve routing fixture identity before recovery probes
Oct 8, 2026
aa2b63c
test: canonicalize routing fixtures and verify effect-free cleanup
Oct 8, 2026
5e27ddc
test(runtime): check native route stop recovery ordering
Oct 8, 2026
5e45bdf
fix(config): verify live Caddy automatic TLS before completion
Oct 8, 2026
b5e971e
fix(native-compose): preserve verified route stop recovery
Oct 8, 2026
69110f2
docs(runtime): state route retirement model bounds
Oct 8, 2026
a5cb910
test: observe spawned child ownership in timeout regression
Oct 8, 2026
c57d6a3
ci: retry verified model tool installation
Oct 8, 2026
a81626f
test: keep disposable Caddy state off host filesystems
Oct 8, 2026
e3d7cd2
test(config): qualify native workload process policy
Oct 8, 2026
fe57cf3
test: verify dynamic proxy ports remain unpublished
Oct 8, 2026
0eba59d
test(config): verify native observer read-only enforcement
Oct 8, 2026
fadc9ad
Merge commit 'fe57cf30cba32b50b8e09534c2a5990408287d61' into feat/nat…
Oct 8, 2026
7e91f68
test(config): refuse evidence reader image pulls
Oct 8, 2026
d33662e
chore: reconcile process fixture with merged native routing
Oct 8, 2026
413de47
test(config): qualify compiler and execution policy refusals separately
Oct 8, 2026
a61c6be
test(config): preserve immutable retry proof before cleanup
Oct 8, 2026
1c7b74c
test(config): narrow retry event mutation controls
Oct 8, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 24 additions & 0 deletions tests/e2e/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -85,6 +85,30 @@ fixture; host and provider proxy settings remain unchanged. In a real project,
add its internal service names to the existing proxy exceptions rather than
discarding the project's other entries.

## Native config process-policy qualification

`native-config-process-policy` is registered in required Docker CI. It needs the
current compiled CLI, matching compiler and cached `oven/bun:1.4.2-slim`; it resolves
the immutable image ID and never pulls, publishes ports, or activates DNS/trust.

```sh
HACK_E2E_CLI_BIN=./dist/hack HACK_E2E_DOCKER=1 HACK_E2E_REQUIRE_DOCKER=1 bun tests/e2e/run.ts --only=native-config-process-policy
```

The fixture observes `SIGUSR1` delivery, delayed graceful exit and forced termination
after authored grace. Persistent monotonic heartbeats distinguish grace enforcement
from merely setting a Compose field. A double-forked child is observed after adoption
by PID 1 and then after reaping by the actual init process. Failure counters and engine
restart counts prove two `on-failure` retries before a successful third start.
Readback uses the same retained volume through a separate native profile. Unsupported
resource/logging declarations, including inactive workloads, must refuse before any
engine access or lifecycle hook. These refusal controls do not qualify resource
limits, reservations, logging policy or the full advanced signals/resources corpus.

Cleanup checks exact native ownership and separately removes its captured read-only
evidence reader. An incomplete teardown fails and preserves both private roots and
recovery identities; ordinary successful cleanup remains unchanged.

## Native config routing qualification

`native-config-routing` is a required Docker CI scenario using the current compiled
Expand Down
2 changes: 2 additions & 0 deletions tests/e2e/run.ts
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ import { initScenario } from "./scenarios/init.ts";
import { lifecycleHostProcessScenario } from "./scenarios/lifecycle-host-process.ts";
import { lifecycleSessionRecoveryScenario } from "./scenarios/lifecycle-session-recovery.ts";
import { nativeConfigComposeScenario } from "./scenarios/native-config-compose.ts";
import { nativeConfigProcessPolicyScenario } from "./scenarios/native-config-process-policy.ts";
import { nativeConfigRoutingScenario } from "./scenarios/native-config-routing.ts";
import { portableMultiserviceScenario } from "./scenarios/portable-multiservice.ts";
import { upDownScenario } from "./scenarios/up-down.ts";
Expand Down Expand Up @@ -60,6 +61,7 @@ const ALL_SCENARIOS: readonly Scenario[] = [
upDownScenario,
portableMultiserviceScenario,
nativeConfigComposeScenario,
nativeConfigProcessPolicyScenario,
nativeConfigRoutingScenario,
lifecycleHostProcessScenario,
worktreeParallelUpScenario,
Expand Down
Loading
Loading