Repository navigation
OmniRoute 3.8.51 from npm: install, boot smoke, provenance and signature receipt (the component pin stays 3.8.50) - #533
Merged
Conversation
…ure receipt (the component pin stays 3.8.50) Qualifies the published package omniroute@3.8.51 as a candidate for the manifests/stack.json pin, with the returned outputs and scripts: the recipe's install and rebuild commands at the new version (exit 0), two boots without the lsof shim in a network-less namespace (health 200, store identical across the restart, SIGTERM exit 143, no orphan), the registry's SLSA provenance read (subject sha512 equals the tarball's; source commit is upstream's v3.8.51 tag commit), npm audit signatures on a throwaway project's tree (0 invalid, 0 missing), and counts showing the package carries neither of the running gateways' patches. Moves no pin and touches no gateway. Also drops two clauses from the rebuild record that described earlier, unpublished runs whose times no command printed, and adds a dated note to the decision record and one sentence to docs/foundation-stack.md. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
seathatflowsinourveins
deleted the
res-npm-3851-qualification-20260930
branch
September 30, 2026 06:23
6 of 7 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
omniroute@3.8.51as acompatibility_attemptreceipt with its returned outputs and scripts: the recipe's install and rebuild commands at the new version (exit 0), two boots without thelsofshim in a network-less namespace, the registry's SLSA provenance read,npm audit signatureson the package's tree, and counts showing the package carries neither of the running gateways' patches. It adds a dated note to the rebuild decision record and one sentence todocs/foundation-stack.md, and drops two clauses from the rebuild record (OmniRoute rebuild 2026-09-30: decision record, evidence artifacts, owner-record script, unit templates (records what runs; compression on 20128 not applied) #530) that described earlier, unpublished runs whose times no command printed. It moves no pin and touches no gateway, unit or client configuration.omnirouterow ofmanifests/stack.jsonand itscatalogs/landscape/upstream-snapshot.jsonrow (a separatelane:sharedchange; the receipt's limitations name the 7-day cooldown question), and any change to the running gateways (Gate A window W).b4056a355580f079560cb612cf03a0a2568c3af7(main after OmniRoute rebuild 2026-09-30: decision record, evidence artifacts, owner-record script, unit templates (records what runs; compression on 20128 not applied) #530).lane:foundation. It changes no path owned by the trading lane and no shared hot file's text:manifests/evidence.jsonis only registered through the hot-file protocol (last commit), whichdocs/lanes.mdsays does not by itself make a PR shared.evidence/receipts/,evidence/artifacts/omniroute-npm-3851-qualification-20260930/,evidence/artifacts/omniroute-rebuild-20260930/(two clauses),docs/decisions/2026-09-30-omniroute-rebuild.md,docs/foundation-stack.md,manifests/evidence.json.SOTA sources
v3.8.51, commitc1e30b7676975feb298b49eff6ff58923c04b89e, and its npm packageomniroute@3.8.51(https://registry.npmjs.org/omniroute/-/omniroute-3.8.51.tgz,dist.integritysha512-VwwSt+bP9lJiPJXFJMz0nNGGuoewPZU3nFe1SLuO11ADgdSwTegGCxhg8Ov75+31m/cocPxHiO63zygn1XQ0MQ==).docs/foundation-stack.md"Optional OmniRoute installation and bounded gateway acceptance" (it pins 3.8.50; run here with the version changed).npm audit signatures(npm 11.19.0, which refuses global installs withEAUDITGLOBAL, recorded in the artifact); the SLSA provenance v1 specification for the statement fields read.evidence/receipts/socraticode-1160-qualification-20260929.json(SocratiCode 1.16.0: qualification receipt and dated decision update (the Linux pin stays 1.15.0) #523).Evidence-class table
--version3.8.51,dist/BUILD_SHAc1e30b7; tarball digests equal the registry'slocal_integration(our scripts, outputs as returned)data.install,data.tarball;checks/install-steps-20260930.txt,checks/tarball-digests-20260930.txtlocal_integrationdata.smoke;checks/smoke-summary-20260930.txtnpm-publish.ymlatrefs/tags/v3.8.51; source commitc1e30b767(the tag commit)source_review(a registry read, not a signature check)checks/npm-attestation-20260930.jsonnpm audit signatures: 0 invalid, 0 missing, 1156 registry signatures verified, 233 attestations, omniroute's own includedlocal_integrationusing npm's own verificationchecks/audit-signatures-20260930.txt,checks/audit-signatures-summary-20260930.jsonlocal_integration(counts)checks/carry-presence-20260930.jsonLocal commands run
The full
unittestdiscovery runs in CI'svalidatecheck.Decision record
docs/decisions/2026-09-30-omniroute-rebuild.md(dated note under decision item 5); the receipt carries the limitations, the rollback (a scratch prefix, nothing to roll back) and the cooldown question.Host evidence
This PR adds an artifact directory and a receipt under
evidence/receipts/andevidence/artifacts/, notevidence/hosts/.scripts/validate.py(exit 0 above) validates the registered receipt and artifacts.platform_statuschange.Checklist
🤖 Generated with Claude Code