Skip to content

OmniRoute 3.8.51 from npm: install, boot smoke, provenance and signature receipt (the component pin stays 3.8.50) - #533

Merged
seathatflowsinourveins merged 1 commit into
mainfrom
res-npm-3851-qualification-20260930
Sep 30, 2026
Merged

seathatflowsinourveins merged 1 commit into
mainfrom
res-npm-3851-qualification-20260930

Conversation

@seathatflowsinourveins

Copy link
Copy Markdown
Owner

Scope

  • What this PR changes: records the qualification of the published npm package omniroute@3.8.51 as a compatibility_attempt receipt with its returned outputs and scripts: the recipe's install and rebuild commands at the new version (exit 0), two boots without the lsof shim in a network-less namespace, the registry's SLSA provenance read, npm audit signatures on the package's tree, and counts showing the package carries neither of the running gateways' patches. It adds a dated note to the rebuild decision record and one sentence to docs/foundation-stack.md, and drops two clauses from the rebuild record (OmniRoute rebuild 2026-09-30: decision record, evidence artifacts, owner-record script, unit templates (records what runs; compression on 20128 not applied) #530) that described earlier, unpublished runs whose times no command printed. It moves no pin and touches no gateway, unit or client configuration.
  • Not in this PR: the omniroute row of manifests/stack.json and its catalogs/landscape/upstream-snapshot.json row (a separate lane:shared change; the receipt's limitations name the 7-day cooldown question), and any change to the running gateways (Gate A window W).
  • Base commit: b4056a355580f079560cb612cf03a0a2568c3af7 (main after OmniRoute rebuild 2026-09-30: decision record, evidence artifacts, owner-record script, unit templates (records what runs; compression on 20128 not applied) #530).
  • Lane: lane:foundation. It changes no path owned by the trading lane and no shared hot file's text: manifests/evidence.json is only registered through the hot-file protocol (last commit), which docs/lanes.md says does not by itself make a PR shared.
  • Owned paths touched: evidence/receipts/, evidence/artifacts/omniroute-npm-3851-qualification-20260930/, evidence/artifacts/omniroute-rebuild-20260930/ (two clauses), docs/decisions/2026-09-30-omniroute-rebuild.md, docs/foundation-stack.md, manifests/evidence.json.

SOTA sources

Evidence-class table

Claim Evidence class Command / receipt
Recipe install and rebuild exit 0 on the published package; --version 3.8.51, dist/BUILD_SHA c1e30b7; tarball digests equal the registry's local_integration (our scripts, outputs as returned) receipt data.install, data.tarball; checks/install-steps-20260930.txt, checks/tarball-digests-20260930.txt
Two boots on one data directory without the shim: health 200 after 3 s and 4 s, store 193 rows / integrity ok / 138 tables across the restart, SIGTERM exit 143, no orphan local_integration receipt data.smoke; checks/smoke-summary-20260930.txt
Registry provenance: subject sha512 equals the tarball's; workflow npm-publish.yml at refs/tags/v3.8.51; source commit c1e30b767 (the tag commit) source_review (a registry read, not a signature check) checks/npm-attestation-20260930.json
npm audit signatures: 0 invalid, 0 missing, 1156 registry signatures verified, 233 attestations, omniroute's own included local_integration using npm's own verification checks/audit-signatures-20260930.txt, checks/audit-signatures-summary-20260930.json
The package has 0 alpha/search route files and 0 affinity-function occurrences (neither carry) local_integration (counts) checks/carry-presence-20260930.json
Upstream's own suite on the package not run limitation 2 of the receipt

Local commands run

$ python3 scripts/validate.py
{"components": 69, "hashed_files": 8373, "profiles": 4, "receipts": 175, "status": "passed"}                                             exit 0
$ python3 scripts/evidence_manifest.py --check
{"files": 8373, "status": "passed"}                                                          exit 0
$ python3 -B -m unittest tests.test_foundation_stack_pins tests.test_omniroute_gateway_unit tests.test_adoption_contract tests.test_freeze_snapshot tests.test_catalogs tests.test_stack_lifecycle
Ran 268 tests in 127.922s ... OK                                                                exit 0

The full unittest discovery runs in CI's validate check.

Decision record

docs/decisions/2026-09-30-omniroute-rebuild.md (dated note under decision item 5); the receipt carries the limitations, the rollback (a scratch prefix, nothing to roll back) and the cooldown question.

Host evidence

This PR adds an artifact directory and a receipt under evidence/receipts/ and evidence/artifacts/, not evidence/hosts/.

  • scripts/validate.py (exit 0 above) validates the registered receipt and artifacts.
  • Independent review: requested in this PR (one read-only evidence review of the receipt against the artifacts).
  • No platform_status change.

Checklist

  • No workflows or Actions are changed.
  • No secrets are printed, logged or committed.
  • No new paid hosting, subscription or billing surface.
  • Peer-owned untracked files and worktrees were preserved.

🤖 Generated with Claude Code

…ure receipt (the component pin stays 3.8.50)

Qualifies the published package omniroute@3.8.51 as a candidate for the manifests/stack.json pin, with the returned outputs and scripts:
the recipe's install and rebuild commands at the new version (exit 0), two boots without the lsof shim in a network-less namespace
(health 200, store identical across the restart, SIGTERM exit 143, no orphan), the registry's SLSA provenance read (subject sha512 equals
the tarball's; source commit is upstream's v3.8.51 tag commit), npm audit signatures on a throwaway project's tree (0 invalid, 0 missing),
and counts showing the package carries neither of the running gateways' patches. Moves no pin and touches no gateway.

Also drops two clauses from the rebuild record that described earlier, unpublished runs whose times no command printed, and adds a dated
note to the decision record and one sentence to docs/foundation-stack.md.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Sep 30, 2026
@seathatflowsinourveins
seathatflowsinourveins merged commit 7d01891 into main Sep 30, 2026
25 checks passed
@seathatflowsinourveins
seathatflowsinourveins deleted the res-npm-3851-qualification-20260930 branch September 30, 2026 06:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant