Skip to content

Explain normalization and delivery with portable client evidence - #102

Merged
tonit merged 10 commits into
mainfrom
94-client-evidence
Sep 27, 2026
Merged

tonit merged 10 commits into
mainfrom
94-client-evidence

Conversation

@tonit

@tonit tonit commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

Clients previously had to reconstruct repair decisions and intended delivery coverage from separate workspace files. This change makes rio normalize --gate fail && rio deliver --evidence target/rio/record.json produce one portable, validated account of selection, changes, checks, attempts and evidence gaps. rio record report renders the same facts as self-contained offline HTML.

  • Normalization records stable change pointers, selected repair provenance and exact mapping digests, plus effective selection and requirement checks. Existing source assertions are preserved; new identity evidence omits invented confidence.
  • Evidence delivery saves an immutable index snapshot and batch descriptor before requests, retains ordinary-return completion separately, and collects a v2 record even for rejected, partial or unknown results. Recovery works after source removal or index replacement; publication never retries an upload or replaces a journal namespace.
  • V1 collection remains the default; new readers accept v1/v2. Unknown optional normalization extensions stay explicitly unsupported. V2 supports 1,024 journals within existing aggregate byte/event bounds. Projection edits and inconsistent joins refuse.
  • Terminal and HTML views share validated facts and keep quality, acknowledgment, activity, TLS exceptions and authenticity separate. Reports have escaped text, embedded CSS, no scripts/assets, and the exact JSON digest.
  • Installed-binary examples, a disposable DTrack harness, authored release notes, exact-tag note selection and published-download/native/Homebrew verification support the release handoff.

Validation at 7736e894c5befba404f7377c9654305a349af8f4: go mod tidy -diff, build, vet, full race suite, installer tests, all CI Python suites and every installed-binary demo passed locally (macOS arm64, static release-equivalent build). Exact-head CI includes native Linux/macOS/Windows and disposable Distribution/Zot and DTrack 5.1.1/PostgreSQL18. Real HTTP/HTTPS integration includes trusted CA and explicit bypass through a test gateway; separate inventory observations are not native content-verification claims. Successful and partial HTML reports were reviewed at desktop and narrow widths without overflow or external requests. A fresh whole-branch review found a missing-journal publication collision; its failing regression and fix are included.

The complete synthetic handoff covers uplift, repair, unresolved mapping, inherited enrichment, exclusions, partial/lost responses, failed gate/override, actual process interruption, explicit retry/reconcile snapshots, source deletion, relocation, tamper refusal and secret-canary checks. Authored note and release-verifier tests pass; actual v0.5.0 download verification exercised the new verifier tooling. The forthcoming release and notification remain tracked in #94/#101 and are not claimed here.

Records remain unsigned consistency evidence; full payload/input retention, artifact-to-SBOM binding, broader quality checks and Artifactory validation are separate scopes. #45 and #47 remain open.

Fixes #44
Fixes #95
Fixes #96
Fixes #97
Fixes #98
Fixes #99
Fixes #100

Related: #94, #101, #45, #47.

@tonit
tonit marked this pull request as ready for review September 27, 2026 15:50
Copilot AI lite review requested due to automatic review settings September 27, 2026 15:50
@tonit
tonit merged commit 85ca1d4 into main Sep 27, 2026
12 checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved scope-validation and release-verification workflow issues remain.

Review effort: Lite
Findings: 2 Medium severity

Open (2)
What changed in this PR

This PR adds portable normalization and delivery evidence, v2 record collection, offline HTML reporting, release-note validation, and installed-binary verification.

Changes:

  • Records provenance, scope, checks, and immutable delivery batches.
  • Adds validated evidence recovery and self-contained reports.
  • Adds demos, documentation, CI coverage, and release tooling.
File Summary
tools/​verify-release.py Verifies published assets and native demos.
tools/​verify-release_test.py Tests release verification boundaries.
tools/​release-notes.py Selects authored release notes.
tools/​release-notes_test.py Tests release-note policies.
tools/​README.md Documents demos and verification.
tools/​demo-record/​run.py Extends record demonstrations.
tools/​demo-record/​README.md Documents record reports.
tools/​demo-normalization-evidence/​table.json Provides normalization demo data.
tools/​demo-normalization-evidence/​run.py Runs normalization evidence demo.
tools/​demo-normalization-evidence/​rio.yaml Configures normalization demo.
tools/​demo-normalization-evidence/​README.md Documents normalization demo.
tools/​demo-normalization-evidence/​bom.json Provides normalization fixture data.
tools/​demo-dtrack-tls/​run.py Checks report behavior.
tools/​demo-dtrack-tls/​README.md Documents TLS/report demo.
tools/​demo-delivery/​integration/​setup_test.py Tests integration setup safeguards.
tools/​demo-delivery/​integration/​README.md Documents disposable integration services.
tools/​demo-delivery/​integration/​compose.yaml Defines pinned integration services.
tools/​demo-client-record/​rio.yaml Configures client-record demo.
tools/​demo-client-record/​README.md Documents client handoff demo.
tools/​demo-client-record/​fixtures/​services/​alpha-server/​pom.xml Provides service fixture metadata.
tools/​demo-client-record/​fixtures/​services/​alpha-server/​bom.json Provides service SBOM fixture.
tools/​demo-client-record/​fixtures/​clients/​beta-client/​pom.xml Provides client fixture metadata.
tools/​demo-client-record/​fixtures/​clients/​beta-client/​bom.json Provides client SBOM fixture.
tools/​demo-batch-evidence/​run.py Runs batch evidence demo.
tools/​demo-batch-evidence/​rio.yaml Configures batch evidence demo.
tools/​demo-batch-evidence/​README.md Documents batch recovery.
tools/​demo-batch-evidence/​fixtures/​worker.json Provides worker fixture.
tools/​demo-batch-evidence/​fixtures/​app.json Provides application fixture.
tools/​demo-artifact-sets/​run.sh Demonstrates artifact-set inspection.
tools/​ci-changes_test.py Tests demo change detection.
README.md Documents the evidence workflow.
internal/​transform/​transform.go Adds resolution provenance types.
internal/​transform/​purl/​p2/​table.go Captures mapping metadata and digests.
internal/​transform/​purl/​p2/​provenance_test.go Tests provenance behavior.
internal/​transform/​purl/​p2/​p2.go Propagates repair provenance.
internal/​transform/​purl/​p2/​p2_test.go Updates repair expectations.
internal/​sbom/​document.go Adds identity assertions.
internal/​index/​scope.go Validates normalization scope and checks.
internal/​index/​normalization.go Validates normalization ledgers.
internal/​index/​normalization_test.go Tests ledger validation.
internal/​index/​index.go Adds index evidence extensions.
internal/​gate/​gate.go Records requirement evaluations.
internal/​evidence/​write.go Protects publication sources.
internal/​evidence/​types.go Extends evidence document types.
internal/​evidence/​report/​write.go Writes report output.
internal/​evidence/​report/​text.go Renders terminal reports.
internal/​evidence/​report/​sync_windows.go Provides Windows report synchronization.
internal/​evidence/​report/​sync_unix.go Provides Unix report synchronization.
internal/​evidence/​report/​model_test.go Tests report models.
internal/​evidence/​report/​html.go Renders self-contained HTML reports.
internal/​evidence/​preflight.go Adds bounded record parsing.
internal/​evidence/​parse.go Parses v1 and v2 records.
internal/​evidence/​marshal.go Marshals versioned records.
internal/​evidence/​coverage.go Computes batch exclusions.
internal/​evidence/​collect.go Supports bounded evidence collection.
internal/​evidence/​batch.go Collects immutable batch sources.
internal/​delivery/​verify.go Validates index extensions.
internal/​delivery/​runner/​submit.go Supports assigned attempt IDs.
internal/​delivery/​runner/​batch_evidence.go Builds completion evidence.
internal/​delivery/​record/​store.go Persists journal identities.
internal/​delivery/​record/​assigned_attempt_test.go Tests assigned attempts.
internal/​delivery/​json.go Handles future extensions.
internal/​delivery/​batchrecord/​types.go Defines batch descriptors and completions.
internal/​delivery/​batchrecord/​sync_windows.go Provides Windows batch synchronization.
internal/​delivery/​batchrecord/​sync_unix.go Provides Unix batch synchronization.
internal/​delivery/​batch_plan.go Captures delivery scope.
internal/​delivery/​batch_plan_test.go Tests captured batch scope.
internal/​cli/​testdata/​rcp-client.cdx.json Updates identity evidence fixture.
internal/​cli/​record.go Adds v2 collection and reporting.
internal/​cli/​record_v2_test.go Tests v2 collection.
internal/​cli/​record_report.go Adds the report command.
internal/​cli/​record_report_test.go Tests report safety and integrity.
internal/​cli/​record_inspect.go Preserves raw record bytes.
internal/​cli/​normalize.go Records normalization evidence.
internal/​cli/​normalization_scope_test.go Tests effective scope and checks.
internal/​cli/​normalization_evidence.go Builds change ledgers and provenance.
internal/​cli/​normalization_evidence_test.go Tests normalization evidence.
internal/​cli/​delivery_evidence.go Automates evidence collection.
internal/​cli/​deliver.go Adds evidence delivery flow.
internal/​cli/​client_demo_test.go Verifies client demo fixtures.
docs/​releases/​v0.6.0.md Adds authored release notes.
docs/​output.md Documents evidence schemas and limits.
docs/​manifest.md Documents scope and checks.
docs/​enrichment.md Documents enrichment ledgers.
docs/​cli.md Documents evidence and report commands.
AGENTS.md Documents release-note policy.
.github/​workflows/​verify-release.yaml Adds published-release verification.
.github/​workflows/​release.yaml Integrates authored release notes.
.github/​workflows/​ci.yaml Adds demos and integration checks.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread internal/index/scope.go
Comment on lines +179 to +180
if (c.Mode != "warn" && c.Mode != "fail") || c.ComponentScope != "all components including nested" || c.ComponentCount < a.Components || c.ComponentRequirements == nil || c.Evaluations == nil || c.GraphCheck != "dangling-dependency-references" || c.GraphFindings != len(a.IntegrityFindings) {
return bad()
Comment thread tools/release-notes.py
Comment on lines +27 to +35
if not source.exists():
if tuple(int(match[i]) for i in (1, 2, 3)) >= (0, 6, 0):
raise ValueError("authored notes required for " + tag)
if not output.is_file() or not output.read_bytes().strip():
raise ValueError("historical generated notes missing or empty")
print("NOTES: historical generated-note policy for " + tag)
return
if source.is_symlink() or not source.is_file():
raise ValueError("authored notes must be a regular file")
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants