Skip to content

Fix signed CHIRP root ownership and renewal storage paths - #648

Merged
ty-everett merged 1 commit into
mainfrom
codex/chirp-root-receipt-retention-20260927
Sep 27, 2026
Merged

ty-everett merged 1 commit into
mainfrom
codex/chirp-root-receipt-retention-20260927

Conversation

@ty-everett

@ty-everett ty-everett commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

Program and scope

The new signed ownership envelope only accepted ordinary CDN paths, so valid CHIRP root advertisement creation failed. Renewal also tried to read a nonexistent CDN copy instead of the actual CHIRP root object. Accept the exact root route with the identifier bound to its advertised hash, read the real root during renewal, and extend its committed closure. Inactive or failed CHIRP leases fail closed.

Impact

  • No public package source or manifest changed
  • Infrastructure source changed
  • Security-sensitive boundary changed
  • Documentation changed

The existing unpublished Cloud Bucket 0.2.46 candidate contains this correction; latest published image is 0.2.45. No new JSON keys, signatures, wallet schema, storage copy, default network, API endpoint, third-party dependency or deployed image changes in this PR. Normal UHRP CDN ownership and renewal remain supported.

Verification

The added tests fail on the old source: 7 failures across valid CHIRP ownership, advertisement creation and renewal/failure handling. Changed source passes all 17 service suites / 92 tests, build, lint and audit (zero vulnerabilities).

Full workspace build, types, lint, formatting and strict repository health pass. The tests use actual SDK cryptographic signatures and bound ownership metadata with synthetic wallets; only storage, action completion and broadcast are mocked. They cover exact root/hash binding, unrelated root/member paths, query/fragment/credential rejection, ordinary CDN renewal, actual CHIRP object selection, inactive roots and closure/provider failures before acknowledgement.

  • Complete diff self-reviewed for correctness, security, compatibility, public API, artifacts, dependencies, docs and operations
  • All applicable exact-head hosted checks are terminal and successful

Security and dependencies

  • No dependency or lockfile change
  • Negative tests cover changed trust boundaries
  • No new override, dismissal, suppression, exclusion or skipped test
  • Exact-head CodeQL has no new alert
  • Exact-head Sonar has zero new findings and unreviewed hotspots

A CHIRP root must be the canonical identifier of the advertised hash and appear twice in the exact root route. Existing credential-free HTTPS, signatures, owner binding, selectors and request bounds remain enforced. An inactive CHIRP commit cannot fall back to unrelated CDN storage.

Release and operations

  • No workstation npm or image publication
  • Correct existing unpublished patch candidate retained
  • README describes paths, retention and inactive-root behavior

After green exact-main checks, build through protected Linux/amd64 Infra Release. Validate ordinary UHRP and CHIRP publish/default discovery/full and range download/HEAD/renewal/closure retention in staging before promoting the same verified digest to NanoStore production. No data migration or rollback schema change.

Completion evidence

Exact local head: 96f1d6896b04cc066bba0d4000955b8e1acd8e52.

Exact-head hosted CI 36282196293, runtime 36282196251, conformance 36282196261 and CodeQL 36282196321 passed. Sonar has zero unresolved new issues and zero unreviewed hotspots.

@sonarqubecloud

Copy link
Copy Markdown

@ty-everett
ty-everett marked this pull request as ready for review September 27, 2026 00:26
@ty-everett
ty-everett merged commit b0e02aa into main Sep 27, 2026
37 checks passed
@ty-everett
ty-everett deleted the codex/chirp-root-receipt-retention-20260927 branch September 27, 2026 00:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant