didericis-codex
377f8d125b
build: make pinned image inputs portable
prd-number-check / require-numbered-prds (pull_request) Successful in 8s
refresh-image-locks / refresh (push) Successful in 28s
lint / lint (push) Successful in 1m3s
test / unit (pull_request) Successful in 53s
test / integration-docker (pull_request) Successful in 2m50s
test / coverage (pull_request) Failing after 22s
test / image-input-builds (pull_request) Successful in 3m35s
tracker-policy-pr / check-pr (pull_request) Failing after 11m8s
2026-07-26 09:42:54 +00:00
didericis-codex
023b23de6a
ci: isolate gateway lock refresh tooling
refresh-image-locks / refresh (push) Successful in 26s
prd-number-check / require-numbered-prds (pull_request) Successful in 8s
test / image-input-builds (pull_request) Failing after 9s
tracker-policy-pr / check-pr (pull_request) Successful in 8s
test / integration-docker (pull_request) Failing after 37s
test / unit (pull_request) Successful in 46s
test / coverage (pull_request) Has been skipped
2026-07-26 09:40:48 +00:00
didericis-codex
4597548f07
test: narrow pinned base match for type checking
prd-number-check / require-numbered-prds (pull_request) Successful in 13s
tracker-policy-pr / check-pr (pull_request) Successful in 11s
lint / lint (push) Successful in 1m4s
test / unit (pull_request) Has started running
test / integration-docker (pull_request) Waiting to run
test / coverage (pull_request) Blocked by required conditions
test / image-input-builds (pull_request) Has started running
2026-07-26 09:39:58 +00:00
didericis-codex
432a2573eb
ci: pin compatible gateway lock tooling
prd-number-check / require-numbered-prds (pull_request) Successful in 14s
refresh-image-locks / refresh (push) Failing after 1m17s
tracker-policy-pr / check-pr (pull_request) Successful in 8s
test / unit (pull_request) Successful in 1m46s
test / coverage (pull_request) Has been skipped
test / integration-docker (pull_request) Failing after 1m30s
test / image-input-builds (pull_request) Failing after 46s
2026-07-26 09:38:35 +00:00
didericis-codex
e619a88c66
test: assert reproducible provider image inputs
prd-number-check / require-numbered-prds (pull_request) Successful in 9s
test / image-input-builds (pull_request) Failing after 11s
tracker-policy-pr / check-pr (pull_request) Successful in 9s
test / integration-docker (pull_request) Failing after 40s
lint / lint (push) Failing after 58s
test / unit (pull_request) Successful in 6m24s
test / coverage (pull_request) Has been skipped
2026-07-26 09:37:28 +00:00
didericis-codex
8a4d1714ac
ci: make image input refreshes deterministic
lint / lint (push) Successful in 1m1s
prd-number-check / require-numbered-prds (pull_request) Successful in 6s
tracker-policy-pr / check-pr (pull_request) Successful in 9s
refresh-image-locks / refresh (push) Failing after 2m6s
test / unit (pull_request) Failing after 45s
test / image-input-builds (pull_request) Failing after 52s
test / integration-docker (pull_request) Failing after 1m15s
test / coverage (pull_request) Has been skipped
2026-07-26 09:34:21 +00:00
didericis-codex
a4fa420ce6
docs: explain image input refreshes
2026-07-26 09:28:50 +00:00
didericis-codex
01b20c9d42
ci: reject mutable image build inputs
lint / lint (push) Successful in 1m4s
2026-07-26 09:28:42 +00:00
didericis-codex
059fef1cac
build: freeze operating system package inputs
refresh-image-locks / refresh (push) Failing after 24s
lint / lint (push) Successful in 1m2s
2026-07-26 09:28:33 +00:00
Gitea Actions
67fea5fd5e
build: refresh image input locks
2026-07-26 09:25:15 +00:00
didericis-codex
a38bbfbae2
build: pin and verify image inputs
refresh-image-locks / refresh (push) Successful in 27s
lint / lint (push) Successful in 1m3s
2026-07-26 09:24:44 +00:00
Gitea Actions
c094b1ee68
build: refresh image input locks
2026-07-26 09:22:56 +00:00
didericis-codex
eaafc30577
ci: keep feature-branch image locks current
refresh-image-locks / refresh (push) Successful in 2m47s
2026-07-26 09:20:17 +00:00
didericis-codex
f79e73561b
ci: generate refreshed image input locks
refresh-image-locks / refresh (push) Successful in 31s
2026-07-26 09:18:33 +00:00
didericis-codex
aeb8ae1d78
build: declare reproducible image dependencies
2026-07-26 09:17:58 +00:00
didericis-codex
1827593b89
test(docker): authenticate multitenant egress probes
prd-number-check / require-numbered-prds (pull_request) Successful in 9s
test / unit (pull_request) Successful in 53s
test / integration-docker (pull_request) Successful in 1m7s
test / coverage (pull_request) Successful in 17s
tracker-policy-pr / check-pr (pull_request) Successful in 32s
test / unit (push) Successful in 57s
lint / lint (push) Successful in 1m4s
test / integration-docker (push) Successful in 1m11s
test / coverage (push) Successful in 21s
Update Quality Badges / update-badges (push) Successful in 56s
2026-07-26 08:41:00 +00:00
didericis-codex
73e70e326c
test(docker): wait for multitenant probe readiness
prd-number-check / require-numbered-prds (pull_request) Successful in 6s
tracker-policy-pr / check-pr (pull_request) Successful in 26s
test / unit (pull_request) Successful in 49s
lint / lint (push) Successful in 59s
test / integration-docker (pull_request) Failing after 1m1s
test / coverage (pull_request) Has been skipped
2026-07-26 08:38:16 +00:00
didericis-codex
d744bec7b1
fix(docker): configure the attributed gateway subnet
tracker-policy-pr / check-pr (pull_request) Successful in 12s
prd-number-check / require-numbered-prds (pull_request) Successful in 42s
lint / lint (push) Successful in 1m4s
test / unit (pull_request) Successful in 57s
test / integration-docker (pull_request) Failing after 1m5s
test / coverage (pull_request) Has been skipped
2026-07-26 08:35:37 +00:00
didericis-codex
f3fbfb3cc3
fix(ci): join control planes to the runner network
prd-number-check / require-numbered-prds (pull_request) Successful in 13s
tracker-policy-pr / check-pr (pull_request) Successful in 8s
test / integration-docker (pull_request) Failing after 35s
test / unit (pull_request) Successful in 52s
test / coverage (pull_request) Has been skipped
lint / lint (push) Successful in 1m7s
2026-07-26 08:30:57 +00:00
didericis-codex
b2245ae1f3
test(orchestrator): make wrong-key coverage deterministic
2026-07-26 08:30:57 +00:00
didericis-codex
f0fe33b1d0
fix(ci): bypass proxies for Docker host probes
prd-number-check / require-numbered-prds (pull_request) Successful in 6s
tracker-policy-pr / check-pr (pull_request) Successful in 7s
test / unit (pull_request) Failing after 45s
test / integration-docker (pull_request) Failing after 7m1s
test / coverage (pull_request) Has been skipped
2026-07-26 08:24:21 +00:00
didericis-codex
d4889663d1
fix(ci): enable the scheduled canary suite
prd-number-check / require-numbered-prds (pull_request) Successful in 9s
tracker-policy-pr / check-pr (pull_request) Successful in 9s
test / unit (pull_request) Successful in 50s
test / integration-docker (pull_request) Failing after 7m45s
test / coverage (pull_request) Has been skipped
2026-07-26 08:15:21 +00:00
didericis-codex
1022247ce5
test(ci): cover assurance gate entry points
prd-number-check / require-numbered-prds (pull_request) Successful in 7s
tracker-policy-pr / check-pr (pull_request) Successful in 8s
lint / lint (push) Successful in 58s
test / unit (pull_request) Successful in 48s
test / integration-docker (pull_request) Failing after 19m28s
test / coverage (pull_request) Has been skipped
2026-07-26 08:14:00 +00:00
didericis-codex
671d91070e
docs(ci): document the assurance topology
2026-07-26 08:02:12 +00:00
didericis-codex
1c6d30ffd8
test(canary): verify the pinned gitleaks release
2026-07-26 08:01:07 +00:00
didericis-codex
583ff98b27
ci(docker): require the full integration suite
2026-07-26 08:00:15 +00:00
didericis-codex
fafb828bb7
ci(coverage): enforce the critical core contract
2026-07-26 07:50:44 +00:00
Quality Badge Bot
f9ad6c85aa
chore: update quality badges
...
- Coverage: 83%
- Core coverage: 93%
[skip ci]
2026-07-26 07:38:37 +00:00
didericis-codex
7488110e71
chore: tighten upkeep boundaries and static checks
prd-number-check / require-numbered-prds (pull_request) Successful in 8s
test / integration-docker (pull_request) Successful in 12s
test / unit (pull_request) Successful in 49s
test / coverage (pull_request) Successful in 15s
tracker-policy-pr / check-pr (pull_request) Successful in 5s
test / integration-docker (push) Successful in 13s
test / unit (push) Successful in 48s
lint / lint (push) Successful in 56s
Update Quality Badges / update-badges (push) Successful in 50s
test / coverage (push) Successful in 13s
2026-07-26 06:55:49 +00:00
didericis-codex
22dde95561
fix(diagnostics): make optional failures observable and safe
2026-07-26 06:55:49 +00:00
didericis-codex
e29b79d517
refactor(backend): extract shared bottle preparation planner
2026-07-26 06:55:49 +00:00
didericis-codex
1d85acfd99
refactor(egress): make addon core a compatibility facade
2026-07-26 06:55:49 +00:00
didericis-codex
90defdc9cd
refactor(egress): separate matching, DLP, and context concerns
2026-07-26 06:55:49 +00:00
didericis-codex
2039ef635f
refactor: validate reconciliation inputs and neutralize CLI helpers
2026-07-26 06:55:49 +00:00
didericis-codex
0fc5457e41
docs(adr): align tracker policy title
test / integration-docker (push) Successful in 17s
test / unit (push) Successful in 48s
lint / lint (push) Successful in 59s
test / coverage (push) Successful in 16s
Update Quality Badges / update-badges (push) Successful in 4m4s
2026-07-26 02:54:56 -04:00
didericis-codex
c0493f0b01
ci(tracker): require one metadata owner per pull request
2026-07-26 02:54:56 -04:00
didericis-codex
5828f5e900
ci(tracker): allow labelled standalone pull requests
2026-07-26 02:54:56 -04:00
didericis-codex
be025ff8fb
docs(prd): explain superseded dashboard designs
2026-07-26 02:54:56 -04:00
didericis-codex
9537c96586
docs: streamline design workflow guidance
2026-07-26 02:54:56 -04:00
didericis-codex
6b43fe73c1
docs: add design workflow guide
2026-07-26 02:54:56 -04:00
didericis-codex
d3370a88bb
ci(prd): require manual numbering before merge
prd-number-check / require-numbered-prds (pull_request) Successful in 10s
tracker-policy-pr / check-pr (pull_request) Successful in 14s
test / unit (pull_request) Successful in 54s
test / integration-docker (pull_request) Successful in 54s
test / coverage (pull_request) Successful in 18s
test / integration-docker (push) Successful in 16s
test / unit (push) Successful in 50s
lint / lint (push) Successful in 1m0s
test / coverage (push) Successful in 15s
Update Quality Badges / update-badges (push) Successful in 4m1s
2026-07-26 02:33:14 -04:00
didericis-codex
39167528db
ci(test): publish infra after pre-release checks
tracker-policy-pr / check-pr (pull_request) Successful in 10s
test / integration-docker (pull_request) Successful in 20s
test / unit (pull_request) Successful in 4m11s
test / coverage (pull_request) Successful in 17s
test / integration-docker (push) Successful in 15s
test / unit (push) Successful in 49s
test / coverage (push) Successful in 23s
2026-07-26 06:24:28 +00:00
didericis-codex
b25ace4c00
ci(test): split automated and pre-release suites
tracker-policy-pr / check-pr (pull_request) Successful in 11s
test / integration-docker (pull_request) Successful in 22s
test / unit (pull_request) Successful in 54s
test / coverage (pull_request) Successful in 17s
2026-07-26 06:22:53 +00:00
didericis-codex
9c06702b32
docs(prd): number merged placeholder documents
prd-number / assign-numbers (push) Failing after 25s
lint / lint (push) Successful in 4m7s
Update Quality Badges / update-badges (push) Failing after 13m37s
test / coverage (push) Has been skipped
test / integration-docker (push) Failing after 13m51s
test / integration-firecracker (push) Failing after 13m48s
test / integration-macos (push) Failing after 13m54s
test / unit (push) Failing after 13m53s
test / publish-infra (push) Has been skipped
2026-07-26 06:06:04 +00:00
didericis-codex
cd0983d943
docs(prd): update shipped draft statuses
prd-number / assign-numbers (push) Failing after 24s
2026-07-26 06:04:15 +00:00
didericis-codex
99176b1edf
docs(prd): mark superseded architecture contracts
2026-07-26 06:02:47 +00:00
Quality Badge Bot
652f14dcb1
chore: update quality badges
...
- Coverage: 83%
- Core coverage: 94%
[skip ci]
2026-07-26 02:36:35 +00:00
didericis-claude
38c13708c7
Merge pull request 'PRD prd-new: macOS (Apple Container) CI runner' ( #479 ) from prd-macos-container-ci-runner into main
test / integration-macos (push) Has been skipped
prd-number / assign-numbers (push) Failing after 27s
test / integration-docker (push) Successful in 16s
lint / lint (push) Successful in 1m7s
Update Quality Badges / update-badges (push) Successful in 58s
test / unit (push) Successful in 2m11s
test / integration-firecracker (push) Successful in 5m2s
test / coverage (push) Successful in 25s
test / publish-infra (push) Successful in 2m1s
2026-07-25 22:34:47 -04:00
didericis-claude
82669b22d5
fix: doctor probes backend readiness; install.sh resolves user-scripts dir
...
test / integration-docker (push) Successful in 20s
prd-number / assign-numbers (push) Failing after 24s
test / unit (push) Successful in 57s
lint / lint (push) Successful in 1m1s
Update Quality Badges / update-badges (push) Failing after 54s
test / integration-firecracker (push) Successful in 5m7s
test / coverage (push) Successful in 27s
test / publish-infra (push) Successful in 2m34s
Addresses the third review round on PR #481 .
- `bot-bottle doctor` now checks `is_backend_ready()` (a full backend
status() probe: daemon reachable, network pool present, KVM usable)
instead of the cheap PATH-only `is_backend_available()`. A host with a
stopped Docker daemon or half-configured Firecracker no longer reports
`ok: backend` / exit 0 when `start` can't actually work; each not-ready
backend prints its own diagnostics, and doctor passes only if at least
one backend is ready.
- `install.sh` resolves the pip `--user` scripts directory from the
interpreter (`sysconfig.get_path("scripts", get_preferred_scheme("user"))`)
instead of hardcoding `~/.local/bin`, which is wrong on a python.org
macOS interpreter (`~/Library/Python/<X.Y>/bin`). The PATH guidance now
prints the actual directory.
Tests: doctor tests mock `is_backend_ready` (the readiness contract) and
cover the not-ready → fail path; a new install-script test drives the
macOS `osx_framework_user` scheme and asserts it resolves a
non-~/.local/bin directory.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-07-25 22:34:25 -04:00
didericis-claude
1a4b390e8a
fix: make installed wheel self-contained + harden install.sh prereqs
...
Addresses the review on PR #481 .
Self-contained wheel (review point 1): the gateway/infra/orchestrator
images build from a context that must hold bot_bottle/, pyproject.toml,
and the root-level Dockerfiles. Modules previously located these by
walking __file__ to the repo root, so an installed wheel (package in
site-packages, no repo root) passed `doctor` but failed `start`.
- Add bot_bottle/resources.py: build_root() returns the repo root in a
checkout (unchanged) or a staged copy from the wheel's bundled
_resources/ otherwise; dockerfile()/nix_netpool_module()/
netpool_script() derive from it.
- setup.py bundles the root Dockerfiles, nix module, netpool script, and
pyproject.toml into bot_bottle/_resources/ at build; MANIFEST.in ships
them in the sdist.
- Route every _REPO_ROOT/_REPO_DIR call site (docker/macos launch, macos
infra, firecracker infra_vm/infra_artifact/setup, orchestrator
lifecycle/gateway) through resources. Checkout behavior is unchanged.
install.sh prerequisites (review point 2): check for git when installing
a git+ spec, and — before the pip fallback — that pip is usable and the
interpreter isn't externally managed (PEP 668), pointing at pipx.
Tests: test_resources covers checkout + staged-wheel layouts;
test_wheel_install builds the wheel, installs it into an isolated venv,
and asserts `doctor` runs and build_root() yields a valid context.
Running `start` end-to-end still needs a Docker/KVM host (CI).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-07-25 22:34:25 -04:00