Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/publish-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -99,7 +99,7 @@ jobs:
RELEASE_MANIFEST_SHA256: ${{ inputs.release_manifest_sha256 }}
run: |
set -euo pipefail
[[ "$VERSION" =~ ^0\.1\.0(-rc\.[1-9][0-9]*)?$ ]]
[[ "$VERSION" =~ ^0\.1\.1(-rc\.[1-9][0-9]*)?$ ]]
[[ "$SOURCE_COMMIT" =~ ^[0-9a-f]{40}$ ]]
[[ "$PACKAGE_SHA256" =~ ^[0-9a-f]{64}$ ]]
[[ "$CHECKSUMS_SHA256" =~ ^[0-9a-f]{64}$ ]]
Expand Down
12 changes: 12 additions & 0 deletions .seal/reviews/cr-12aiik/events.jsonl
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
{"ts":"2026-09-10T23:35:16.425498439Z","author":"sigil-dev","event":"ReviewCreated","data":{"review_id":"cr-12aiik","jj_change_id":"detached:cdc8280e5c937382c8f3d5f7d46c8a1ad635a719","scm_kind":"git","scm_anchor":"detached:cdc8280e5c937382c8f3d5f7d46c8a1ad635a719","initial_commit":"cdc8280e5c937382c8f3d5f7d46c8a1ad635a719","base_commit":"d4271d81cdca7c87836fa6af497f111adf0d3dff","title":"bn-27oc/bn-gjo0/bn-31f0: compatible Temporal candidate and bounded Lua companion","description":"risk:medium. Whole persisted range d4271d81..cdc8280 (three commits) in Temporal bn-gjo0. Unpublished0.1.1 manifest minimumSigil>=0.35.0/exactAPI1.3; closed pack/publisher family with immutable existing artifacts and frozen client/WIT identities; canonical writer compression parity and multiblock regression; opt-in bounded project Lua polling/history/result/single JSON helper. No runtime WIT/proto/client authority changes. Both branches individually full just check PASS; integrated check/conformance/pack and real pinned-host decoder repeats underway independently. RPC fixtures are offline, JSON scenario real ordinary host with accepted official0.1.0 lock. Review callback/exception/error precedence, no Start retry, input/result bounds and plain-table safety, raw bytes/numeric preservation, exact compatibility/publisher gates and truthful evidence. Local candidate is not provenanced release or CAPI acceptance. Read Sigil security protocol at /home/bob/src/sigil/.agents/edict/security-review.md; only this Temporal target in scope."}}
{"ts":"2026-09-10T23:35:16.425579711Z","author":"sigil-dev","event":"ReviewersRequested","data":{"review_id":"cr-12aiik","reviewers":["sigil-security"]}}
{"ts":"2026-09-10T23:41:35.264688668Z","author":"sigil-security","event":"ThreadCreated","data":{"thread_id":"th-2c3jcs","review_id":"cr-12aiik","file_path":"README.md","selection":{"type":"Line","line":183},"commit_hash":"cdc8280e5c937382c8f3d5f7d46c8a1ad635a719"}}
{"ts":"2026-09-10T23:41:35.264714647Z","author":"sigil-security","event":"CommentAdded","data":{"comment_id":"th-2c3jcs.1","thread_id":"th-2c3jcs","body":"[low] Release-family documentation contradicts the exact immutable gates. This paragraph says 0.1.0-rc.N identifies release candidates, but plugin.toml, release-pack.py, publish-release.yml, CHANGELOG.md, RELEASING.md, and README.md:233-237 admit only the unpublished 0.1.1 / 0.1.1-rc.N family and intentionally reject historical 0.1.0 identities. The machine gates fail closed, so this is not a publisher bypass, but an operator following this section receives the wrong exact candidate identity. Change only the package candidate reference here to 0.1.1-rc.N while retaining the frozen WIT and Start identity at 0.1.0."}}
{"ts":"2026-09-10T23:41:35.482102844Z","author":"sigil-security","event":"ReviewerVoted","data":{"review_id":"cr-12aiik","vote":"block","reason":"[low] README.md:183 retains the historical 0.1.0-rc.N candidate family and contradicts the reviewed 0.1.1-only packer/publisher gates; correct the package candidate reference without changing frozen WIT/Start identity.","target_commit":"cdc8280e5c937382c8f3d5f7d46c8a1ad635a719"}}
{"ts":"2026-09-10T23:44:49.553132297Z","author":"sigil-dev","event":"CommentAdded","data":{"comment_id":"th-2c3jcs.2","thread_id":"th-2c3jcs","body":"Fixed in53cd07797dd8b4d2244fcffb254a3b662de1e243: the active candidate paragraph now names0.1.1-rc.N. Historical release evidence and frozen WIT/Start identity0.1.0 remain unchanged. Only one README line changed after prior target; full pinned-host just check rerun PASS. Please verify and resolve in rereview."}}
{"ts":"2026-09-10T23:44:49.607903183Z","author":"sigil-dev","event":"ReviewRetargeted","data":{"review_id":"cr-12aiik","old_scm_anchor":"detached:cdc8280e5c937382c8f3d5f7d46c8a1ad635a719","new_scm_anchor":"detached:53cd07797dd8b4d2244fcffb254a3b662de1e243","old_target_commit":"cdc8280e5c937382c8f3d5f7d46c8a1ad635a719","new_target_commit":"53cd07797dd8b4d2244fcffb254a3b662de1e243"}}
{"ts":"2026-09-10T23:44:49.658965059Z","author":"sigil-dev","event":"ReviewersRequested","data":{"review_id":"cr-12aiik","reviewers":["sigil-security"]}}
{"ts":"2026-09-10T23:49:50.844992804Z","author":"sigil-security","event":"ThreadResolved","data":{"thread_id":"th-2c3jcs","reason":"Verified at 53cd07797dd8b4d2244fcffb254a3b662de1e243: README.md:183 now names 0.1.1-rc.N, matching the closed plugin.toml, release-pack.py, and publish-release.yml family while retaining frozen WIT, client, and Start identity 0.1.0."}}
{"ts":"2026-09-10T23:49:50.889303612Z","author":"sigil-security","event":"ReviewerVoted","data":{"review_id":"cr-12aiik","vote":"lgtm","reason":"Whole persisted d4271d81cdca7c87836fa6af497f111adf0d3dff..53cd07797dd8b4d2244fcffb254a3b662de1e243 (4 commits; tree 161a25d15be6e39025762754a39ad5818f1bf56a) statically reviewed across all 16 changed paths; th-2c3jcs fix verified. Failure modes fail closed through exact 0.1.1 family, manifest/API/WIT identity gates, single-shot Start, and bounded nonretrying History. Edge cases cover plain-table/metatable/cycle/sparse shapes, callback snapshots, exact raw bytes/numbers, and node/page/event/byte/token exhaustion. Rollback is reverting this unpublished four-commit range before publication; historical 0.1.0 artifacts are not overwritten. Monitoring remains ordinary per-operation Sigil traces plus namespaced helper exhaustion without payload logging. Supplied integrated Lua/release/component/real-host results corroborate the source review only. LGTM is commit-scoped static approval, not provenance, CAPI, future-native, publication, or release qualification.","target_commit":"53cd07797dd8b4d2244fcffb254a3b662de1e243"}}
{"ts":"2026-09-10T23:49:50.924643495Z","author":"sigil-security","event":"ReviewApproved","data":{"review_id":"cr-12aiik","target_commit":"53cd07797dd8b4d2244fcffb254a3b662de1e243"}}
{"ts":"2026-09-10T23:51:27.796889182Z","author":"sigil-dev","event":"ReviewMerged","data":{"review_id":"cr-12aiik","final_commit":"53cd07797dd8b4d2244fcffb254a3b662de1e243"}}
12 changes: 12 additions & 0 deletions .seal/reviews/cr-38eiua/events.jsonl
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
{"ts":"2026-09-10T22:48:44.346115390Z","author":"sigil-dev","event":"ReviewCreated","data":{"review_id":"cr-38eiua","jj_change_id":"detached:15037c8e0f1fc98f32f8c8e55e9d9c70907c9b12","scm_kind":"git","scm_anchor":"detached:15037c8e0f1fc98f32f8c8e55e9d9c70907c9b12","initial_commit":"15037c8e0f1fc98f32f8c8e55e9d9c70907c9b12","base_commit":"effb9cb0022ef80583794d723ac6149f452fedb2","title":"bn-1ecg and bn-q4yp: honest Start semantics and tested operator contract","description":"Two commits, docs and conformance only. Clarify proto3 started ambiguity without changing WIT or runtime; independently generated false/omitted wire fixtures; complete grant template parsed by pinned public host; raw payload and strict JSON caveats. Lead integrated just check PASS, no publication. risk:medium. Check authority statements, no new-execution inference from Applied, no weak grant policy, truthful fixture provenance and isolation."}}
{"ts":"2026-09-10T22:48:44.346230753Z","author":"sigil-dev","event":"ReviewersRequested","data":{"review_id":"cr-38eiua","reviewers":["sigil-security"]}}
{"ts":"2026-09-10T22:55:23.952073791Z","author":"sigil-security","event":"ThreadCreated","data":{"thread_id":"th-1dh3lv","review_id":"cr-38eiua","file_path":"examples/operator-grant.toml","selection":{"type":"Range","start":13,"end":16},"commit_hash":"15037c8e0f1fc98f32f8c8e55e9d9c70907c9b12"}}
{"ts":"2026-09-10T22:55:23.952134582Z","author":"sigil-security","event":"CommentAdded","data":{"comment_id":"th-1dh3lv.1","thread_id":"th-1dh3lv","body":"[risk:medium] Effective host policy is broader than this complete least-authority template claims. Stable Sigil 0.35.0 deserializes each omitted capability allowlist to github:sigil-plugins/*, so omitting random, entropy, log, and sigv4 here authorizes those capabilities for matching official-source manifests. examples/README.md:5-9 says this template grants only Temporal semantic gRPC authority, but tests/test_release_examples.py:46-66 inspects raw TOML and therefore cannot see the host-injected defaults; the release-binary test proves parsing and endpoint validation, not the effective allowlists. Explicitly set every unused capability allowlist to [] and make the contract test cover the host-effective policy (or narrow and document the claim if broader project-wide defaults are intentional)."}}
{"ts":"2026-09-10T22:55:26.734972889Z","author":"sigil-security","event":"ReviewerVoted","data":{"review_id":"cr-38eiua","vote":"block","reason":"risk:medium blocker th-1dh3lv: the complete operator template leaves four unused capability allowlists at broad Sigil 0.35.0 defaults, while its raw-TOML tests do not validate effective least authority","target_commit":"15037c8e0f1fc98f32f8c8e55e9d9c70907c9b12"}}
{"ts":"2026-09-10T22:59:09.954868901Z","author":"sigil-dev","event":"CommentAdded","data":{"comment_id":"th-1dh3lv.2","thread_id":"th-1dh3lv","body":"Fixed in 99e33b4: all seven capability allowlists explicit; six unused lists empty. Pinned public host schema enumerates all capability fields/defaults, computes effective defaults-plus-declarations, and omission negative controls show broadening. Host config parser still validates complete template and rejects missing endpoint. Full just check PASS. Also added separately lead-reviewed bn-181h helper design in f52da8b; no helper runtime implementation or WIT change, review whole extended range."}}
{"ts":"2026-09-10T22:59:10.211464097Z","author":"sigil-dev","event":"ReviewersRequested","data":{"review_id":"cr-38eiua","reviewers":["sigil-security"]}}
{"ts":"2026-09-10T23:00:16.928112995Z","author":"sigil-dev","event":"ReviewRetargeted","data":{"review_id":"cr-38eiua","old_scm_anchor":"detached:15037c8e0f1fc98f32f8c8e55e9d9c70907c9b12","new_scm_anchor":"detached:99e33b4e8c436703b2825abfd7fd7c866bd1635f","old_target_commit":"15037c8e0f1fc98f32f8c8e55e9d9c70907c9b12","new_target_commit":"99e33b4e8c436703b2825abfd7fd7c866bd1635f"}}
{"ts":"2026-09-10T23:03:36.876935380Z","author":"sigil-security","event":"ThreadResolved","data":{"thread_id":"th-1dh3lv","reason":"[risk:medium] Fixed at 99e33b4: examples/operator-grant.toml explicitly declares all seven host capability allowlists, with only grpc-unary authorized for github:sigil-plugins/temporal. tests/test_release_examples.py binds the declared field set and effective defaults to the hash-pinned Sigil 0.35.0 schema, includes per-field omission negative controls, parses the complete template through the real host, and rejects a missing endpoint reference. The least-authority claim is now sound."}}
{"ts":"2026-09-10T23:03:43.022880389Z","author":"sigil-security","event":"ReviewerVoted","data":{"review_id":"cr-38eiua","vote":"lgtm","reason":"Dedicated static security re-review of the whole persisted effb9cb0022ef80583794d723ac6149f452fedb2..99e33b4e8c436703b2825abfd7fd7c866bd1635f four-commit range: no remaining blocker. 99e33b4 closes every unused capability default and tests the pinned host-effective field/default set plus real config parsing. Start fixtures and guidance preserve implicit-presence ambiguity, exact one-call/no-retry behavior, and do not treat effect=applied as independent creation proof. f52da8b is design-only; its companion contract preserves plugin errors and raw bytes, fails closed on malformed/bounded history, and leaves sticky host failures and external qualification gates authoritative. Reviewer ran no builds or tests.","target_commit":"99e33b4e8c436703b2825abfd7fd7c866bd1635f"}}
{"ts":"2026-09-10T23:03:43.057834988Z","author":"sigil-security","event":"ReviewApproved","data":{"review_id":"cr-38eiua","target_commit":"99e33b4e8c436703b2825abfd7fd7c866bd1635f"}}
{"ts":"2026-09-10T23:04:33.119354807Z","author":"sigil-dev","event":"ReviewMerged","data":{"review_id":"cr-38eiua","final_commit":"99e33b4e8c436703b2825abfd7fd7c866bd1635f"}}
5 changes: 5 additions & 0 deletions .seal/reviews/cr-3d7lvc/events.jsonl
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
{"ts":"2026-09-11T01:47:28.260220976Z","author":"sigil-dev","event":"ReviewCreated","data":{"review_id":"cr-3d7lvc","jj_change_id":"detached:be0d0070376057a0a9a5b12b7b999c071e33ee07","scm_kind":"git","scm_anchor":"detached:be0d0070376057a0a9a5b12b7b999c071e33ee07","initial_commit":"be0d0070376057a0a9a5b12b7b999c071e33ee07","base_commit":"effb9cb0022ef80583794d723ac6149f452fedb2","title":"bn-37xu: Temporal 0.1.1-rc.1 complete source release review","description":"Review whole unpublished range through exact RC commit, including bounded Lua companion, minimum-only host compatibility, canonical zstd writer parity, operator docs, and version prep. Publication candidate/tuple/provenance and CAPI are separate gates. risk:high: answer failure modes, edge cases, rollback, monitoring, validation. Source-only defensive static review; preserve fixed RPC identity, Host API1.3, lazy grants, sticky faults and raw byte semantics."}}
{"ts":"2026-09-11T01:47:28.260313375Z","author":"sigil-dev","event":"ReviewersRequested","data":{"review_id":"cr-3d7lvc","reviewers":["sigil-security"]}}
{"ts":"2026-09-11T01:52:06.610242407Z","author":"sigil-security","event":"ReviewerVoted","data":{"review_id":"cr-3d7lvc","vote":"lgtm","reason":"LGTM for the exact persisted effb9cb0022ef80583794d723ac6149f452fedb2..be0d0070376057a0a9a5b12b7b999c071e33ee07 source range (tree 73e08c8cae734934f3df10b98a2c9d32125cbc83); no security blockers.\n\nFailure modes: bounded polling/pagination can exhaust, malformed or over-limit pages can fail, Start may have applied despite ambiguous creation evidence, host/server failures can interrupt, and candidate/version/artifact identity can drift. The source fails closed, returns no partial success, never retries Start, preserves returned error identity and sticky host faults, and binds candidate production to exact reviewed source and hashes.\n\nEdge cases: inclusive zero/max event and byte limits, 1/180 attempts, 1/128 pages, empty pages, repeated binary tokens, non-UTF-8 payload bytes, false/omitted/wire-explicit started, unknown enum numbers, terminal conflicts, callback exceptions, future stable hosts, and prerelease last-stable matching were traced. Unknown or conflicting data does not become completion, creation proof, or product success.\n\nRollback: before publication, stop without dispatch. Published releases are immutable and burned, so never overwrite or mutate one; repair with a new version, source commit, candidate tuple and independent review. Project adoption of the copied companion or package must be reverted through a separately reviewed caller/lock change to a known published identity.\n\nMonitoring: retain normal per-RPC Sigil traces, sticky infrastructure faults, companion code plus attempts/pages, server/run evidence when creation matters, candidate run/asset hashes, OIDC attestation and immutable-release readback, and fresh CAPI assertion/expected-RED results. Do not log payload bodies.\n\nValidation: static defensive inspection covered every persisted changed source file and the unchanged execution paths needed to verify WIT, host, packer and publisher claims. No tests, builds, network, containers or reproduction were run in this review. Existing local fixtures/checks corroborate source only; this LGTM is not official provenance, exact candidate tuple approval, native acceptance, CAPI acceptance, publication authorization or stable promotion. Supporting stable Sigil and fresh official-lock CAPI acceptance remain gates.","target_commit":"be0d0070376057a0a9a5b12b7b999c071e33ee07"}}
{"ts":"2026-09-11T01:52:06.655446674Z","author":"sigil-security","event":"ReviewApproved","data":{"review_id":"cr-3d7lvc","target_commit":"be0d0070376057a0a9a5b12b7b999c071e33ee07"}}
{"ts":"2026-09-11T01:55:43.327162380Z","author":"sigil-dev","event":"ReviewMerged","data":{"review_id":"cr-3d7lvc","final_commit":"be0d0070376057a0a9a5b12b7b999c071e33ee07"}}
28 changes: 28 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,33 @@
# Changelog

## 0.1.1-rc.1 — Unpublished release candidate

- Require Sigil >=0.35.0 without an evaluator minor ceiling, while retaining
exact Host API 1.3.0, schema 4 and the unchanged three-operation WIT 0.1.0.
This admits compatible future hosts; it does not certify unmeasured versions.
- Prepare only the 0.1.1/0.1.1-rc.N package family for independently reviewed
publication. Existing 0.1.0 packages and their provenance remain immutable.
- Preserve the fixed Start identity `sigil-temporal@0.1.0`, even though the
candidate package and runtime crate have version 0.1.1-rc.1. Keep the public
Sigil 0.35.0 release validator and executable hashes pinned.
- Use explicit single-thread zstd compression to match Sigil's canonical
writer for multi-block components. The former CLI worker mode could produce
different compressed bytes for the same valid tar. Add a large valid-component
parity regression; published packages remain untouched.
- Add an opt-in project-side Lua companion for bounded polling, explicit
History pagination, completion payload selection and one-layer JSON decoding.
Preserve raw payload bytes, metadata and exact server/effect identities;
no new WIT exports, implicit component retries or operator authority.
- Document proto3 Start boolean semantics: absent and false have the same
decoded value, and a successful applied effect does not prove a new execution.
Include independent presence fixtures and regression coverage.
- Provide a tested least-authority operator grant template with all three
fixed aliases, explicit capabilities and the cumulative budget needed for
a 65-second Start; explain binary payload handling and JSON numeric limits.
- Schedule RC publication after supporting Sigil 0.35.1. Fresh official-lock
CAPI acceptance of this exact RC and any adopted helper source remains
required before a separately reviewed stable promotion.

## 0.1.0 — stable

- Promote the accepted three-operation component without runtime, WIT or
Expand Down
2 changes: 1 addition & 1 deletion Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "sigil-temporal"
version = "0.1.0"
version = "0.1.1-rc.1"
edition = "2024"
license = "MIT"
publish = false
Expand Down
5 changes: 5 additions & 0 deletions Justfile
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ check:
python3 scripts/check-contracts.py
scripts/rebuild-protobuf.sh --verify
lua tests/temporal_poll.lua examples/lib/temporal_poll.lua
lua tests/temporal.lua examples/lib/temporal.lua
PYTHONDONTWRITEBYTECODE=1 python3 -m unittest discover -s tests -p 'test_pack*.py' -v
PYTHONDONTWRITEBYTECODE=1 python3 -m unittest discover -s tests -p 'test_release*.py' -v
cargo fmt --all -- --check
Expand All @@ -25,6 +26,10 @@ build:
component-check: build
cargo run --manifest-path tools/component-conformance/Cargo.toml --locked --offline -- target/component/temporal.wasm

# Existing normally locked/synced project required; no grants or acquisition here.
companion-host-check sigil_binary project_dir:
python3 scripts/check-temporal-host.py --sigil {{quote(sigil_binary)}} --project {{quote(project_dir)}}

# Explicit binary argument: the released 0.34.0 binary is NOT sufficient.
local-pack sigil_binary output_dir: build
python3 scripts/pack.py plugin.local.toml {{quote(output_dir)}} --sigil {{quote(sigil_binary)}}
Expand Down
Loading