Sitelet https://github.com/atrinik/protocol/pull/46
Skip to content

feat(release): add reviewed manual crate publication - #46

Open
zoeyrose wants to merge 4 commits into
mainfrom
feat/reviewed-crate-publication
Open

zoeyrose wants to merge 4 commits into
mainfrom
feat/reviewed-crate-publication

Conversation

@zoeyrose

@zoeyrose zoeyrose commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Summary

Prepare an explicit, reviewed publication path for Rust crate 0.2.0 using the actual archive produced by the approved v2.8.0 preparation run. No registry publication or setup has occurred.

The reviewed source is a47537790f5ea8a08adf7e6dffee4fa794cf3665; archive atrinik-protocol-0.2.0.crate has SHA-256 cda65c3c322993cfab378454fb9b1182df8a000216f4abd1170e53cdfdc3b3bb. Independent local reproduction packaged the same clean source twice and matched those bytes.

Implementation / behavior

  • Keep the manual workflow default prepare. Only an explicit publish operation can reach publication; its inputs must match the reviewed source tag/revision.
  • Verify source/release identity, reproduce the archive, require an attached byte-identical release asset with complete flat checksum coverage, and check public crate owner/identity plus registry API/index state before environment/OIDC access.
  • Require the crates-io-release environment and repeat verification after environment review. Only the upload step receives the official pinned action's short-lived token.
  • Upload the verified archive snapshot through the documented Cargo registry API, without repackaging. Reject unsupported metadata, changed bytes, redirects and uncertain state; never retry a PUT.
  • Preserve immutable published 0.1.0 coordinates. Crate source, generated contracts, wire schemas and fixtures remain unchanged.

Validation

At 046f4db51f860c2cb1236949f5b5acd30173ca45, full tools/validate.sh, actionlint, shellcheck, clean-regeneration and full-base whitespace checks passed in pinned Linux image sha256:7904a1802054662b0ede5b55de72e4c92b0112a3c211125f994ed6c62e9ec9d8.

45 focused network-free policy/verifier/uploader tests passed, including exact upload framing/archive bytes, identity and digest conflicts, source/policy drift, unsupported manifest constructs, redirects, redacted failures and bounded uncertainty resolution. No upload was performed by tests. Independent security review approved this exact source revision and independently checked the actual prepared archive. Required GitHub checks Protocol validation and Conventional PR title passed on this head and accepted base.

Limitations / follow-up

This PR does not authorize merge or publication. Future operations remain separate: review/apply github-settings#86, configure the owner-reviewed environment and Trusted Publisher, attach the exact reviewed crate with a separately approved complete SHA256SUMS update, and explicitly authorize a publish dispatch.

Until those prerequisites exist, publication fails closed. After an authorized upload, public API and sparse-index checksums must match before consumers replace temporary test overrides with an actual registry dependency. Classic deployment remains separately coordinated; this PR deploys no game service.

@zoeyrose
zoeyrose marked this pull request as ready for review October 4, 2026 19:09
zoeyrose added a commit that referenced this pull request Oct 4, 2026
## Summary

Align Classic access-code administration with its existing
per-player/character command permissions. `/access` uses
`/cmd_permission`, and `[OP]` grants it automatically like other
operator commands.

## Implementation / behavior

- Check the active character's effective command permission on each
operation.
- Remove the separate root-managed account allowlist and access-specific
authority requirement.
- Preserve existing account passwords, stored character permissions and
the checked serialized token store.
- Retain root-only Unix-socket administration for a locked private
server's initial code, and keep access policy/store-path configuration
startup-only.

Only `spec/access-tokens.md` changes. Wire identities, schemas,
generated bindings, crate sources, fixtures and publication policy are
unchanged. The separate registry-publication proposal in #46 is
untouched.

## Validation

At `868a5cddaaaec9be264c414783182c51393b08e9`, independent review
approved the complete specification change. Full `tools/validate.sh`
passed in pinned Linux build image
`sha256:7904a1802054662b0ede5b55de72e4c92b0112a3c211125f994ed6c62e9ec9d8`;
regeneration left the tree clean and full-base whitespace checks passed.
Required GitHub checks `Protocol validation` and `Conventional PR title`
passed on this exact head and accepted base.

## Limitations / follow-up

Classic owns the command dispatcher and per-character permission
implementation, which are being updated separately. This source change
performs no deployment, crate preparation, registry operation or merge.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant