Skip to content

Run the configured pipeline and publish one compact receipt - #107

Merged
tonit merged 11 commits into
mainfrom
106-compact-receipt
Sep 28, 2026
Merged

tonit merged 11 commits into
mainfrom
106-compact-receipt

Conversation

@tonit

@tonit tonit commented Sep 27, 2026

Copy link
Copy Markdown
Member

Bare rio now executes the pipeline in rio.yaml and publishes one compact receipt covering consumed SBOMs, meaningful metadata changes, checks, destinations, submitted bytes, TLS and receiver acknowledgments. Runs have isolated output directories; standalone normalization, delivery, retry and reconciliation retain their own scope and prior references.

The new rio-run-receipt contract replaces the previous client evidence bundle. Offline inspection/rendering validates bounded, source-free receipts; durable internal checkpoints support explicit recovery without replaying uploads. Ordinary failures retain failed/unattempted coverage, and publication never replaces an existing receipt. Native DTrack/OCI adapters distinguish actual body writes, HTTP acceptance, processing activity and content verification.

README and v0.7.0 authored notes lead with a generated two-SBOM example (5,791 bytes), complete runnable download and offline HTML. Demos and supporting tools consume invocation-specific output paths.

Validation: full Go build/vet/race suite and tidy check; focused failure, interruption/recovery, TLS, gate consistency, terminal/HTML safety and size regressions; all 12 installed-binary demos; enabled context interoperability smoke and storyboard capture; Python, installer and release-helper checks. Existing native-platform and disposable real-service CI jobs must pass before merge; published-artifact/Homebrew verification follows release publication.

Fixes #106

Copilot AI lite review requested due to automatic review settings September 27, 2026 23:58

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Three moderate unresolved issues affect recovery safety, destination handling, and receipt accuracy.

Review effort: Lite
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

This PR makes bare rio execute the configured pipeline and publish compact, source-free receipts with isolated outputs, recovery support, delivery facts, and updated documentation.

Changes:

  • Added receipt persistence, validation, reporting, checkpointing, and recovery.
  • Integrated pipeline execution with OCI and DTrack delivery metadata.
  • Updated demos, fixtures, documentation, tests, and CI for v0.7.0.

Review identified three moderate issues involving recovery safety, destination overlap handling, and inaccurate failed-run receipt coverage, plus two minor cleanup issues.

File Description
tools/​rio-context_test.py Tests structured run output paths.
tools/​demo-repair/​run.sh Verifies normalization receipts.
tools/​demo-record/​README.md Documents independent receipts.
tools/​demo-oci/​README.md Documents OCI receipt behavior.
tools/​demo-oci/​integration/​README.md Clarifies journal and receipt evidence.
tools/​demo-normalization-evidence/​run.py Validates normalization receipts.
tools/​demo-normalization-evidence/​README.md Updates receipt workflow documentation.
tools/​demo-normalization-evidence/​bom.json Exercises normalization behavior.
tools/​demo-enrichment/​run.sh Consumes structured execution results.
tools/​demo-enrichment/​README.md Updates enrichment demo instructions.
tools/​demo-dtrack-tls/​README.md Documents TLS receipt behavior.
tools/​demo-delivery/​README.md Documents one-command delivery.
tools/​demo-delivery/​integration/​README.md Documents delivery integration checks.
tools/​demo-context/​run.sh Handles isolated output directories.
tools/​demo-context/​README.md Documents failed receipts and run directories.
tools/​demo-client-record/​README.md Introduces the compact receipt example.
tools/​demo-client-record/​example/​worker.cdx.json Provides a synthetic worker SBOM.
tools/​demo-client-record/​example/​SYNTHETIC-ONLY-key.pem Provides synthetic TLS key material.
tools/​demo-client-record/​example/​SYNTHETIC-ONLY-cert.pem Provides synthetic TLS certificate material.
tools/​demo-client-record/​example/​rio.yaml Configures the example pipeline.
tools/​demo-client-record/​example/​README.md Documents the runnable example.
tools/​demo-client-record/​example/​pipeline.json Defines example pipeline data.
tools/​demo-client-record/​example/​normalized/​worker.cdx.json Provides normalized worker output.
tools/​demo-client-record/​example/​normalized/​api.cdx.json Provides normalized API output.
tools/​demo-client-record/​example/​demo-ca.pem Provides example CA material.
tools/​demo-client-record/​example/​api.cdx.json Provides a synthetic API SBOM.
tools/​demo-batch-evidence/​README.md Documents receipt recovery behavior.
tools/​demo-agent-integration/​run.sh Updates the integration walkthrough.
tools/​demo-agent-integration/​EVALUATION.md Updates runtime requirements.
tools/​demo-agent-integration/​ci.sh Publishes receipts in CI.
internal/​receipt/​tls_response_test.go Tests TLS response receipt facts.
internal/​receipt/​sync_windows.go Provides Windows receipt synchronization.
internal/​receipt/​sync_unix.go Provides Unix receipt synchronization.
internal/​receipt/​report_test.go Tests receipt reporting.
internal/​receipt/​paths.go Handles receipt and output paths.
internal/​receipt/​consistency_test.go Tests receipt consistency.
internal/​receipt/​bounds.go Defines receipt bounds.
internal/​manifest/​manifest.go Adds output and gate configuration.
internal/​evidence/​types.go Defines evidence types.
internal/​evidence/​sync_windows.go Provides Windows evidence synchronization.
internal/​evidence/​sync_unix.go Provides Unix evidence synchronization.
internal/​evidence/​report/​write.go Writes evidence reports.
internal/​evidence/​report/​html.go Renders evidence HTML.
internal/​evidence/​preflight_test.go Tests evidence preflight behavior.
internal/​evidence/​oci_bounds_test.go Tests OCI evidence bounds.
internal/​evidence/​marshal.go Handles evidence serialization.
internal/​evidence/​coverage.go Tracks evidence coverage.
internal/​delivery/​types.go Defines delivery submission facts.
internal/​delivery/​runner/​submit.go Tracks delivery submissions.
internal/​delivery/​runner/​reconcile.go Supports delivery reconciliation.
internal/​delivery/​runner/​batch.go Runs delivery batches.
internal/​delivery/​runner/​batch_evidence.go Records batch delivery evidence.
internal/​delivery/​record/​recovery_test.go Tests delivery recovery.
internal/​delivery/​record/​record.go Defines delivery records.
internal/​delivery/​record/​capture.go Captures delivery state.
internal/​delivery/​oci/​transmission.go Tracks OCI transmissions.
internal/​delivery/​oci/​transmission_test.go Tests OCI transmission tracking.
internal/​delivery/​oci/​submit.go Submits OCI content.
internal/​delivery/​oci/​observe.go Observes OCI processing.
internal/​delivery/​oci/​integration_harness_test.go Tests OCI integration behavior.
internal/​delivery/​oci/​evidence.go Records OCI delivery facts.
internal/​delivery/​oci/​client.go Implements the OCI client.
internal/​delivery/​dtrack/​transmission_test.go Tests DTrack transmission tracking.
internal/​delivery/​dtrack/​submit.go Submits DTrack content.
internal/​delivery/​dtrack/​client.go Implements the DTrack client.
internal/​delivery/​batchrecord/​types.go Defines batch record types.
internal/​delivery/​batchrecord/​sync_windows.go Provides Windows batch synchronization.
internal/​delivery/​batchrecord/​sync_unix.go Provides Unix batch synchronization.
internal/​delivery/​batch_plan.go Defines delivery batch planning.
internal/​cli/​testdata/​plan.json Provides CLI plan test data.
internal/​cli/​run_output_test.go Tests pipeline run output.
internal/​cli/​retired_record_test.go Tests retired record handling.
internal/​cli/​resolve.go Resolves CLI inputs and paths.
internal/​cli/​repair_demo_test.go Tests repair demonstrations.
internal/​cli/​record_v2_test.go Tests version-two records.
internal/​cli/​record_report.go Reports delivery records.
internal/​cli/​record_report_test.go Tests record reporting.
internal/​cli/​record_inspect.go Inspects records.
internal/​cli/​record_exit_test.go Tests record command exits.
internal/​cli/​reconcile_receipt.go Creates reconciliation receipts.
internal/​cli/​receipt_growth_test.go Tests receipt growth limits.
internal/​cli/​plan_test.go Tests CLI planning.
internal/​cli/​oci_review_test.go Tests OCI review behavior.
internal/​cli/​oci_fixture_test.go Provides OCI CLI fixtures.
internal/​cli/​normalization_scope_test.go Tests normalization scope.
internal/​cli/​normalization_evidence_test.go Tests normalization evidence.
internal/​cli/​main_test.go Tests CLI entry behavior.
internal/​cli/​exit_test.go Tests CLI exit behavior.
internal/​cli/​enrichment_test.go Tests enrichment behavior.
internal/​cli/​dtrack_tls_test.go Tests DTrack TLS behavior.
internal/​cli/​delivery.go Integrates CLI delivery execution.
internal/​cli/​delivery_test.go Tests CLI delivery.
internal/​cli/​delivery_registry.go Registers delivery adapters.
internal/​cli/​delivery_registry_test.go Tests delivery registration.
internal/​cli/​delivery_reconcile.go Integrates delivery reconciliation.
internal/​cli/​delivery_batch_test.go Tests delivery batching.
internal/​cli/​context_test.go Tests CLI context handling.
internal/​cli/​context_demo_test.go Tests context demonstrations.
internal/​cli/​compact_record.go Builds compact records.
internal/​cli/​compact_record_test.go Tests compact records.
internal/​cli/​client_demo_test.go Tests client demonstrations.
internal/​cli/​cli.go Defines root CLI behavior.
internal/​cli/​attest_test.go Tests attestation behavior.
internal/​cli/​artifact_sets_demo_test.go Tests artifact-set demonstrations.
docs/​releases/​v0.7.0.md Documents the v0.7.0 release.
docs/​quick-start.md Updates quick-start guidance.
docs/​project.md Updates project architecture documentation.
docs/​manifest.md Documents manifest configuration.
docs/​enrichment.md Documents enrichment and failed receipts.
docs/​delivery.md Documents delivery and receipts.
cmd/​rio/​nonetwork_test.go Tests offline package behavior.
AGENTS.md Updates repository workflow guidance.
.github/​workflows/​ci.yaml Runs receipt-focused CI checks.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread internal/cli/delivery_reconcile.go Outdated
Comment thread internal/receipt/store.go Outdated
@tonit
tonit merged commit 6ce064e into main Sep 28, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

rio v0.7.0: one manifest-driven run, one compact receipt

2 participants