Skip to content

fix: ship stable route result UID and verify package integrity - #16

Merged
nicodes merged 1 commit into
mainfrom
phase2/router-173-uid
Sep 16, 2026
Merged

nicodes merged 1 commit into
mainfrom
phase2/router-173-uid

Conversation

@nicodes

@nicodes nicodes commented Sep 16, 2026 •

Copy link
Copy Markdown
Member

Scope

Related to aviorstudio/fieldsofrevik#173 (source package correction only; consumer adoption remains separate).

  • Ship src/core/route_result.gd.uid, genuinely generated by the checksummed official Godot 4.7.2 editor in a fresh isolated project: uid://7xotdfdrekmp.
  • Prepare plugin version 0.0.4 without changing navigation APIs or either legacy orphan sidecar.
  • Derive .gd UID completeness from actual source scripts independently of manifest sidecar entries; reject malformed and duplicate shipped-script UIDs.
  • Compare every installed addon-relative file and byte against the exact ZIP before startup and after every editor invocation, native smoke and Web export. Install once per fixture; never ignore generated files or reinstall to conceal mutation.
  • Add disposable source/manifest, UID/non-UID installed-tree, archive path/byte mutation and restored-good controls. Preserve consumer-owned autoload/configuration sentinels.

Local validation

Pinned archive SHA-512 values match .github/actions/setup-godot/action.yml; actual editor and used Web template bytes match archive members. Engine: 4.7.2.stable.official.ed1daf0bf. Isolated HOME/config/cache/tmp used.

  • python3 tests/package_contract_test.py -v: 9 passed, including six UID/non-UID installed mutations and three archive mutations, each restored.
  • ./tests/test.sh: passed, including package controls, six runner negative controls/restored positive, hosted router behavior.
  • Exact ZIP ./tests/package_lifecycle_test.sh: passed, four editor restarts, consumer ownership preserved, 13 complete installed-tree equality checks, native smoke and Web export.
  • Separately rebuilt ZIP byte-identical; final installed-tree comparison passed.
  • Shell syntax, Python compilation, git diff --check: passed.

Tested ZIP SHA-256: 133003d6fa9085902e529344959409873d84af914e130f1616caf10329c2af2b (37 files).

Installed-tree path/byte digest: 6b566c6a8b5dd75ad2769bae9936f82500c94cfb62233f5285f7298d5db755d2; actual installed fixtures matched every path and byte.

Failures, restoration and remaining gates

  • Initial Web export failed because the local tools fixture lacked web_nothreads_debug.zip/web_nothreads_release.zip. Extracted those exact members from the already checksum-verified official template archive; reran the complete lifecycle on fresh single-install fixtures and unchanged ZIP successfully. No source/preset/allowlist workaround.
  • Existing exact editor cleanup error allowlists were not broadened.
  • Browser runtime separately passed after explicit user approval: initial Chromium launch failed because host sandbox namespaces are denied. A fresh disposable browser used --no-sandbox only for the trusted, exact local export at 127.0.0.1, with isolated profile/HOME and no accounts, credentials or external navigation. Runtime emitted PASS gd-router web_package_smoke reachable=1 exactly once, console reported zero errors/warnings, canvas and exact local URL were asserted, and a screenshot was retained. Named browser and owned server were closed. This is a local security-qualified smoke, not a production sandbox change. Two auxiliary probe mistakes (absent status element and CLI callback signature) were preserved and corrected; they were not application runtime errors.
  • No release published or consumer repositories changed by this PR. v0.0.3 remains untouched; central issue completion requires separate adoption.

Local detailed logs and provenance retained at /tmp/router-173-source-evidence/ (including initial failures and successful restoration).

@nicodes
nicodes merged commit 0f7974e into main Sep 16, 2026
3 checks passed
@nicodes
nicodes deleted the phase2/router-173-uid branch September 16, 2026 02:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant