Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
256 commits
Select commit Hold shift + click to select a range
6d49a35
security(api): require preview owner identity
ebursztein Oct 8, 2026
6d65e0b
security(service): mint preview peer identity
ebursztein Oct 8, 2026
3ea6684
security(gateway): authenticate preview owner handoffs
ebursztein Oct 8, 2026
06b660c
security(foundation): retain child identity until explicit reap
ebursztein Oct 8, 2026
2fee094
security(service): revoke worker authority before reap
ebursztein Oct 8, 2026
0423c45
security(foundation): centralize inherited descriptor closure
ebursztein Oct 8, 2026
5ae0f9d
security(process): close ambient descriptors at entry
ebursztein Oct 8, 2026
4d10756
security(gateway): close ambient descriptors before runtime
ebursztein Oct 8, 2026
11bf70a
security(service): authenticate private DNS by peer identity
ebursztein Oct 8, 2026
b1bdb05
security(process): remove private DNS bearer material
ebursztein Oct 8, 2026
43eba59
refactor(telemetry): allow brokered metric transport
ebursztein Oct 8, 2026
bc268b0
feat(core): add bounded service byte requests
ebursztein Oct 8, 2026
04b2397
test(core): check expired reservation clock
ebursztein Oct 8, 2026
6a5435a
feat(process): add brokered metric transport
ebursztein Oct 8, 2026
bb4a787
security(service): broker worker metric export
ebursztein Oct 8, 2026
6aa544f
security(process): remove direct metric export
ebursztein Oct 8, 2026
9b8288c
security(service): cancel revoked broker work
ebursztein Oct 8, 2026
06da166
test(service): qualify metric broker end to end
ebursztein Oct 8, 2026
c7b9a18
refactor(foundation): generalize descriptor channel
ebursztein Oct 8, 2026
7526551
feat(proto): define upstream descriptor grants
ebursztein Oct 8, 2026
2f8ba52
refactor(core): compile active policy once
ebursztein Oct 8, 2026
e451d25
refactor(process): use compiled policy snapshot
ebursztein Oct 8, 2026
832598f
refactor(core): share upstream target selection
ebursztein Oct 8, 2026
38596b6
test(citadel): record waitid observation shape
ebursztein Oct 8, 2026
bf22841
security(service): broker upstream socket grants
ebursztein Oct 8, 2026
619416d
security(foundation): seal adopted descriptors on exec
ebursztein Oct 8, 2026
bf536c8
refactor(core): inject DNS datagram grants
ebursztein Oct 8, 2026
d85fd8a
refactor(core): reload DNS grant order
ebursztein Oct 8, 2026
182e674
security(proto): bind grants to active policy
ebursztein Oct 8, 2026
219714b
security(service): stamp upstream policy grants
ebursztein Oct 8, 2026
d9342c7
security(process): broker upstream DNS sockets
ebursztein Oct 8, 2026
9d41262
refactor(core): inject upstream TCP grants
ebursztein Oct 8, 2026
ca096af
test(core): exercise MITM through TCP grants
ebursztein Oct 8, 2026
ed3ba51
security(process): broker MITM upstream TCP
ebursztein Oct 8, 2026
d2196f4
test(service): stress upstream grant isolation
ebursztein Oct 8, 2026
de5a5a0
security(core): add resolver without host authority
ebursztein Oct 8, 2026
501ecc0
security(process): remove host resolver authority
ebursztein Oct 8, 2026
0d88d74
test(citadel): guard upstream grant boundary
ebursztein Oct 8, 2026
38c8696
fix(citadel): scope sparse fields to serde types
ebursztein Oct 8, 2026
81fb0c7
style(python): sort standard library imports
ebursztein Oct 8, 2026
1241b47
test(citadel): record isolation dependency lock
ebursztein Oct 8, 2026
ffe3d22
test(gate): classify internal metric ingestion
ebursztein Oct 8, 2026
c868fa6
test(service): split private name peer checks
ebursztein Oct 8, 2026
0d248e3
refactor(core): split MITM configuration fixtures
ebursztein Oct 8, 2026
837e84d
fix(gate): refresh qualified debug image pin
ebursztein Oct 8, 2026
76d20a5
test(api): approve internal metrics ingestion
ebursztein Oct 8, 2026
21cd01b
test(frontend): follow shared session errors
ebursztein Oct 8, 2026
1d9a79c
test(ironbank): follow split Anthropic fixtures
ebursztein Oct 8, 2026
7e79306
fix(container): budget image unpack separately
ebursztein Oct 8, 2026
27e8920
fix(test): qualify mock helper imports
ebursztein Oct 8, 2026
b870f80
test(service): preserve startup failure coverage
ebursztein Oct 8, 2026
9f1edd6
test(ironbank): flush plugin import ledger
ebursztein Oct 8, 2026
7d28f83
fix(gate): track shared worktree processes
ebursztein Oct 8, 2026
6cd640f
fix(core): expire caller-owned workspace attributes
ebursztein Oct 8, 2026
3e07b3f
perf(service): cache effective plugin policy
ebursztein Oct 8, 2026
21adddb
security(foundation): confine Linux workers
ebursztein Oct 9, 2026
0c91b63
security(service): scope VM owner routes
ebursztein Oct 9, 2026
0817b10
refactor(core): reuse prepared service channels
ebursztein Oct 9, 2026
decd0e8
refactor(process): stamp readiness sentinels
ebursztein Oct 9, 2026
3c81d04
refactor(service): require stamped worker readiness
ebursztein Oct 9, 2026
563fc4a
security(process): confine Linux VM owners
ebursztein Oct 9, 2026
696abc7
fix(foundation): close inherited descriptors without procfs
ebursztein Oct 9, 2026
126635e
fix(core): launch images without stage chmod
ebursztein Oct 9, 2026
6425a79
feat(proto): define gateway descriptor grants
ebursztein Oct 9, 2026
38ca38c
refactor(gateway): consume granted service channels
ebursztein Oct 9, 2026
390b351
security(service): broker gateway connections
ebursztein Oct 9, 2026
dc21dfc
fix(service): validate gateway readiness stamps
ebursztein Oct 9, 2026
1346d1e
security(gateway): confine Linux API worker
ebursztein Oct 9, 2026
98bd063
fix(service): own gateway marker cleanup
ebursztein Oct 9, 2026
aec5d55
security(gateway): attest denied Linux authority
ebursztein Oct 9, 2026
e8423bb
test(gateway): broker confined service grants
ebursztein Oct 9, 2026
0ec90f2
fix(logger): keep flush scratch state confined
ebursztein Oct 9, 2026
a8c3a21
feat(proto): broker guest metadata changes
ebursztein Oct 9, 2026
c1bc0aa
security(foundation): contain guest mode changes
ebursztein Oct 9, 2026
09ab450
style(proto): format metadata grant records
ebursztein Oct 9, 2026
27298b0
security(service): broker guest mode changes
ebursztein Oct 9, 2026
ab7c6c3
security(core): broker VirtioFS mode changes
ebursztein Oct 9, 2026
1091209
security(process): delegate guest metadata authority
ebursztein Oct 9, 2026
273d5f0
security(process): attest confined owner authority
ebursztein Oct 9, 2026
fd9a590
docs(changelog): record confined metadata fixes
ebursztein Oct 9, 2026
c0821f5
security(foundation): confine macOS workers
ebursztein Oct 9, 2026
12872b6
security(gateway): install macOS worker policy
ebursztein Oct 9, 2026
a2fcde2
security(process): install macOS owner policy
ebursztein Oct 9, 2026
7b4ccf5
docs(changelog): record macOS worker confinement
ebursztein Oct 9, 2026
47b82fd
feat(proto): define ledger channel authority
ebursztein Oct 9, 2026
56bae0f
feat(logger): define typed ledger operations
ebursztein Oct 9, 2026
bc49bf6
feat(logger): serve typed ledger operations
ebursztein Oct 9, 2026
7466aa1
feat(proto): frame ledger descriptor grants
ebursztein Oct 9, 2026
570cdd8
feat(ledger): own each session database
ebursztein Oct 9, 2026
ad6266b
security(foundation): confine ledger workers
ebursztein Oct 9, 2026
6289e13
security(ledger): confine session owners
ebursztein Oct 9, 2026
0eb5b31
security(proxy): apply atomic policy revisions
ebursztein Oct 9, 2026
a51b357
security(process): bind grants to request policy
ebursztein Oct 9, 2026
ff94dc4
security(proxy): scope engine capabilities
ebursztein Oct 9, 2026
17389de
refactor(process): construct proxy engine
ebursztein Oct 9, 2026
1645039
security(foundation): add descriptor-only proxy role
ebursztein Oct 9, 2026
9527680
feat(proto): frame proxy capability grants
ebursztein Oct 9, 2026
1dd2e8a
security(proxy): confine capability worker
ebursztein Oct 9, 2026
e44f32f
feat(proto): carry proxy policy revisions
ebursztein Oct 9, 2026
1a2844a
feat(proxy): compile path-free runtime policy
ebursztein Oct 9, 2026
f021ac0
security(proxy): apply policy inside worker
ebursztein Oct 9, 2026
626a013
security(service): supervise per-session proxy workers
ebursztein Oct 9, 2026
6e9adc9
security(packaging): ship confined workers
ebursztein Oct 9, 2026
0983e10
security(install): require confined workers
ebursztein Oct 9, 2026
71d8079
security(service): supervise ledger worker protocol
ebursztein Oct 9, 2026
f488ac5
security(service): serialize ledger worker lifetimes
ebursztein Oct 9, 2026
2af1b3f
security(install): pin ledger worker path
ebursztein Oct 9, 2026
dc87aa2
feat(logger): write through ledger descriptors
ebursztein Oct 9, 2026
d3efd45
feat(proto): grant ledger channels to workers
ebursztein Oct 9, 2026
7293848
test(service): use authenticated readiness stamps
ebursztein Oct 9, 2026
b11d6b2
security(service): grant VM ledger authority
ebursztein Oct 9, 2026
54ff7af
security(process): write through supervised ledger
ebursztein Oct 9, 2026
6aaf4da
feat(logger): add authenticated ledger client
ebursztein Oct 9, 2026
bcca744
refactor(logger): share named query dispatch
ebursztein Oct 9, 2026
85e3ba9
fix(logger): bound history offsets for sqlite
ebursztein Oct 9, 2026
356856e
security(service): read sessions through ledger grants
ebursztein Oct 9, 2026
ecffcf4
security(process): stop delegating ledger paths
ebursztein Oct 9, 2026
3248a5f
fix(service): reconnect failed ledger readers
ebursztein Oct 9, 2026
6c1ed6c
fix(logger): bound unread export delivery
ebursztein Oct 9, 2026
d15f215
feat(proto): define proxy traffic handoff
ebursztein Oct 9, 2026
28f8727
feat(proto): type proxy traffic grants
ebursztein Oct 9, 2026
b6526fb
refactor(proxy): distinguish traffic grants
ebursztein Oct 9, 2026
2c6b3e8
feat(service): broker guest traffic to proxy workers
ebursztein Oct 9, 2026
70a9c11
feat(process): surrender proxy traffic descriptors
ebursztein Oct 9, 2026
b5347d4
feat(proto): bind proxy ledger grants
ebursztein Oct 9, 2026
ba48571
feat(proxy): authenticate ledger capability
ebursztein Oct 9, 2026
f35678b
feat(service): grant proxy ledger authority
ebursztein Oct 9, 2026
f695021
feat(proto): define proxy credential capability
ebursztein Oct 9, 2026
0a707fd
feat(proxy): consume credential capability
ebursztein Oct 9, 2026
9471bb2
feat(service): broker proxy credentials
ebursztein Oct 9, 2026
a808faa
feat(service): grant proxy upstream broker
ebursztein Oct 9, 2026
20031cc
refactor(core): share upstream grant client
ebursztein Oct 9, 2026
c21a1d2
refactor(process): use shared upstream client
ebursztein Oct 9, 2026
fddd50a
feat(proxy): adopt upstream authority
ebursztein Oct 9, 2026
09599ab
style(process): format upstream adoption
ebursztein Oct 9, 2026
6588f5a
feat(proto): define private-name capability
ebursztein Oct 9, 2026
35af9af
feat(service): grant private-name capability
ebursztein Oct 9, 2026
399e997
feat(proxy): consume private-name capability
ebursztein Oct 9, 2026
84b289f
feat(proto): reject premature proxy traffic
ebursztein Oct 9, 2026
2d35805
feat(proxy): serve authenticated HTTP traffic
ebursztein Oct 9, 2026
193740f
refactor(core): share guest DNS sessions
ebursztein Oct 9, 2026
5369d1c
refactor(process): use shared DNS sessions
ebursztein Oct 9, 2026
2f9b2bb
feat(proxy): serve authenticated DNS traffic
ebursztein Oct 9, 2026
08d0226
security(process): surrender guest DNS traffic
ebursztein Oct 9, 2026
885a0a6
refactor(core): unify MCP policy snapshots
ebursztein Oct 9, 2026
c3163a1
feat(proto): bootstrap proxy MCP capability
ebursztein Oct 9, 2026
4f95656
refactor(core): share MCP aggregator driver
ebursztein Oct 9, 2026
a821a2b
refactor(process): use shared MCP driver
ebursztein Oct 9, 2026
067af62
feat(core): observe MCP driver closure
ebursztein Oct 9, 2026
64be80d
feat(proto): preserve proxy MCP runtime limits
ebursztein Oct 9, 2026
d2a0d50
feat(proxy): consume MCP capability
ebursztein Oct 9, 2026
f9ebed5
feat(proto): hand off proxy MCP channels
ebursztein Oct 9, 2026
675b5d2
feat(core): surrender proxy MCP capability
ebursztein Oct 9, 2026
c2112d8
feat(service): broker proxy MCP capability
ebursztein Oct 9, 2026
f77199e
feat(process): grant scoped MCP to proxy
ebursztein Oct 9, 2026
f10cc2d
security(process): surrender guest HTTP traffic
ebursztein Oct 9, 2026
8fe95b6
feat(proto): bound proxy metric relay
ebursztein Oct 9, 2026
137b83a
feat(service): broker proxy metric export
ebursztein Oct 9, 2026
61e5c6b
feat(proto): identify proxy metric grants
ebursztein Oct 9, 2026
41e2c0b
feat(service): identify proxy metric grants
ebursztein Oct 9, 2026
c13bd0a
feat(proxy): export brokered session metrics
ebursztein Oct 9, 2026
ee14ca6
feat(proto): coordinate frozen session clones
ebursztein Oct 9, 2026
4d2a461
security(process): remove clone path authority
ebursztein Oct 9, 2026
035b2d3
feat(proto): authorize ledger snapshots
ebursztein Oct 9, 2026
0756443
feat(logger): own coherent fork snapshots
ebursztein Oct 9, 2026
0a17615
refactor(core): split ledger-free session clone
ebursztein Oct 9, 2026
06f4a99
security(service): coordinate path-free session clones
ebursztein Oct 9, 2026
29d7dab
refactor(core): isolate mutable owner state
ebursztein Oct 9, 2026
0847cab
feat(proto): fix owner checkpoint location
ebursztein Oct 9, 2026
71a3baa
refactor(service): confine checkpoint state path
ebursztein Oct 9, 2026
f88b781
security(process): deny session ledger paths
ebursztein Oct 9, 2026
3103e8c
feat(core): pin standalone model upstreams
ebursztein Oct 9, 2026
1a02fff
feat(proxy): serve fixed provider traffic
ebursztein Oct 9, 2026
a716d2e
feat(api): define standalone proxy leases
ebursztein Oct 9, 2026
f320de6
feat(python-sdk): add proxy lease operations
ebursztein Oct 9, 2026
13e575b
feat(typescript-sdk): add proxy lease operations
ebursztein Oct 9, 2026
75cbfab
feat(rust-sdk): add proxy lease operations
ebursztein Oct 9, 2026
1b47331
style(api): format proxy lease route
ebursztein Oct 9, 2026
5cd67aa
security(service): supervise standalone proxy leases
ebursztein Oct 9, 2026
450cea8
feat(cli): add standalone model proxy
ebursztein Oct 9, 2026
bf690f3
test(mock-server): add SDK failure controls
ebursztein Oct 9, 2026
c84d760
fix(mock-server): escape streamed response text
ebursztein Oct 9, 2026
4846b87
test(python-sdk): probe standalone OpenAI endpoint
ebursztein Oct 9, 2026
0adb828
test(typescript-sdk): probe standalone OpenAI endpoint
ebursztein Oct 9, 2026
f538a25
test(ironbank): prove standalone model proxy
ebursztein Oct 9, 2026
c0931c4
chore(surface): register standalone proxy API
ebursztein Oct 9, 2026
2f19b63
test(ci): execute confined workers on both hosts
ebursztein Oct 9, 2026
0fdff40
fix(mcp): sync linked SDK dependency lock
ebursztein Oct 9, 2026
fe4d85b
docs(architecture): document confined host workers
ebursztein Oct 9, 2026
a914af9
merge(0.7): integrate current release line
ebursztein Oct 9, 2026
c7b7dc0
fix(foundation): gate legacy syscalls by architecture
ebursztein Oct 9, 2026
adf2a2b
refactor(archive): isolate block codec implementations
ebursztein Oct 9, 2026
b82efd8
refactor(logger): thread archive codec authority
ebursztein Oct 9, 2026
4d4990b
feat(archive): assign the zstd block codec id
ebursztein Oct 9, 2026
e71513b
security(ledger): confine streaming zstd archives
ebursztein Oct 9, 2026
0d3f195
test(citadel): pin confined zstd ownership
ebursztein Oct 9, 2026
dca38bb
test(ledger): measure archive codec tradeoffs
ebursztein Oct 9, 2026
6bd5f9e
feat(proto): define producer ledger commitments
ebursztein Oct 9, 2026
fb00695
feat(proto): grant trusted ledger checkpoint channels
ebursztein Oct 9, 2026
0a24e9a
security(logger): bind records to producer commitments
ebursztein Oct 9, 2026
c2576dd
security(service): anchor producer commitments externally
ebursztein Oct 9, 2026
a5591cd
feat(core): adopt ledger checkpoint channels
ebursztein Oct 9, 2026
4821a70
feat(process): attach trusted ledger checkpoints
ebursztein Oct 9, 2026
93834a0
feat(proxy): attach trusted ledger checkpoints
ebursztein Oct 9, 2026
3f79eaf
feat(logger): expose canonical commitment hashing
ebursztein Oct 9, 2026
098bab4
test(service): reuse canonical commitment hashing
ebursztein Oct 9, 2026
339b1eb
test(ledger): exercise committed producer records
ebursztein Oct 9, 2026
29035ae
style(service): format commitment verification
ebursztein Oct 9, 2026
421de73
test(ledger): preserve commitments across retention
ebursztein Oct 9, 2026
358ae5b
test(service): define unanchored commitment loss
ebursztein Oct 9, 2026
9c02b75
docs(architecture): define ledger commitment proof
ebursztein Oct 9, 2026
7bc0f3d
fix(proto): keep proxy frames sparse
ebursztein Oct 9, 2026
74f704a
refactor(logger): centralize ledger framing
ebursztein Oct 9, 2026
0d50c7e
refactor(process): trim owner bootstrap
ebursztein Oct 9, 2026
e47f786
test(citadel): follow confined worker ownership
ebursztein Oct 9, 2026
85223c9
style(tests): format gateway helper
ebursztein Oct 9, 2026
a1fcc12
test(sdk): type official client probes
ebursztein Oct 9, 2026
39b2487
test(isolation): type grant fixtures
ebursztein Oct 9, 2026
e9a0ca5
test(ts-sdk): provide package sandbox home
ebursztein Oct 9, 2026
40d1391
test(mcp): isolate packed package home
ebursztein Oct 9, 2026
1183618
fix(ts-sdk): preserve npm home during prewarm
ebursztein Oct 9, 2026
6557f58
fix(mcp): preserve npm home during prewarm
ebursztein Oct 9, 2026
73afa1c
style(tests): sort hermetic model imports
ebursztein Oct 9, 2026
a641e3f
chore(deps): accept worker dependency graph
ebursztein Oct 9, 2026
e2ffd81
test(docs): count isolation architecture page
ebursztein Oct 9, 2026
ad1d6ee
test(ledger): move codec measurement to bench rail
ebursztein Oct 9, 2026
4cefa6a
fix(sdk-python): make package proof cold-cache safe
ebursztein Oct 9, 2026
c3bcb8f
security(foundation): support older Landlock ABIs
ebursztein Oct 9, 2026
a93e387
security(logger): prepare ledger before starting workers
ebursztein Oct 9, 2026
8df00d1
security(ledger): start workers after confinement
ebursztein Oct 9, 2026
4262cc4
security(proxy): confine before starting worker threads
ebursztein Oct 9, 2026
3e58da6
test(proxy): authenticate ledger commitment channel
ebursztein Oct 9, 2026
634fc6a
security(foundation): prepare logs before confinement
ebursztein Oct 9, 2026
3e78c3e
security(gateway): confine before starting runtime threads
ebursztein Oct 9, 2026
1778ed6
fix(gateway): forward standalone proxy routes
ebursztein Oct 9, 2026
5892cad
security(core): prepare confined VM sockets reliably
ebursztein Oct 9, 2026
f488268
feat(proto): carry MCP tool schemas over owner IPC
ebursztein Oct 9, 2026
1847ea4
security(process): confine VM owners and cache authority
ebursztein Oct 9, 2026
b13d2f0
test(logger): allow bounded large-body admission
ebursztein Oct 9, 2026
d30366a
security(service): own MCP discovery and worker fixtures
ebursztein Oct 9, 2026
77350cf
docs(architecture): explain worker startup confinement
ebursztein Oct 9, 2026
f2b6062
test(gate): qualify extracted worker owners
ebursztein Oct 9, 2026
2156148
security(foundation): harden file target and watch boundaries
ebursztein Oct 9, 2026
a1b8cb0
merge(0.7): refresh worker authority candidate
ebursztein Oct 9, 2026
0fbf996
test(foundation): gate Linux sandbox permission import
ebursztein Oct 10, 2026
1c26e86
test(core): stabilize managed lifecycle timing proof
ebursztein Oct 10, 2026
3153cad
fix(service): drain terminal ledger worker event
ebursztein Oct 10, 2026
9f2caa3
test(service): cover terminal event after child exit
ebursztein Oct 10, 2026
ea857f3
test(foundation): handle profiler thread on old Landlock
ebursztein Oct 10, 2026
0b63536
docs(skills): align diagnostics with worker isolation
ebursztein Oct 10, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
26 changes: 23 additions & 3 deletions .github/workflows/ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -126,6 +126,12 @@ jobs:
timeout-minutes: 45
run: just test-linux-rust

# These integration targets execute the real self-confined worker
# binaries. The unit coverage command uses --lib/--bins and therefore
# cannot prove Landlock/seccomp took effect before readiness.
- name: Confined worker subprocess tests
run: cargo test --locked -p capsem-ledger -p capsem-proxy --test subprocess

# cargo check still runs BLAKE3's native SIMD build. Both guest targets
# belong on their native Linux C toolchain, already provisioned above.
# Build and link the production feature set, not a pure-Rust substitute.
Expand Down Expand Up @@ -281,8 +287,13 @@ jobs:
- name: Unit tests with coverage
run: |
set -o pipefail
cargo llvm-cov nextest --no-cfg-coverage --lib --bins --profile ci-unit --codecov --output-path cache/target/coverage/rust/unit.json -p capsem-api -p capsem-sdk -p capsem-archive -p capsem-telemetry -p capsem-assets -p capsem-config -p capsem-credentials -p capsem-foundation -p capsem-core -p capsem-admin -p capsem-agent -p capsem-logger -p capsem-proto -p capsem-guard -p capsem-gateway -p capsem-service -p capsem -p capsem-tui -p capsem-router -p capsem-network -p capsem-mcp-aggregator -p capsem-mcp-builtin -p capsem-tray -p capsem-app -p capsem-process -p capsem-bench -p capsem-mock-server
cargo llvm-cov report --summary-only -p capsem-api -p capsem-sdk -p capsem-archive -p capsem-telemetry -p capsem-assets -p capsem-config -p capsem-credentials -p capsem-foundation -p capsem-core -p capsem-admin -p capsem-agent -p capsem-logger -p capsem-proto -p capsem-guard -p capsem-gateway -p capsem-service -p capsem -p capsem-tui -p capsem-router -p capsem-network -p capsem-mcp-aggregator -p capsem-mcp-builtin -p capsem-tray -p capsem-app -p capsem-process -p capsem-bench -p capsem-mock-server 2>&1 | tee cache/target/coverage/rust/summary.txt
cargo llvm-cov nextest --no-cfg-coverage --lib --bins --profile ci-unit --codecov --output-path cache/target/coverage/rust/unit.json -p capsem-api -p capsem-sdk -p capsem-archive -p capsem-telemetry -p capsem-assets -p capsem-config -p capsem-credentials -p capsem-foundation -p capsem-core -p capsem-admin -p capsem-agent -p capsem-logger -p capsem-proto -p capsem-guard -p capsem-gateway -p capsem-service -p capsem -p capsem-tui -p capsem-router -p capsem-ledger -p capsem-proxy -p capsem-network -p capsem-mcp-aggregator -p capsem-mcp-builtin -p capsem-tray -p capsem-app -p capsem-process -p capsem-bench -p capsem-mock-server
cargo llvm-cov report --summary-only -p capsem-api -p capsem-sdk -p capsem-archive -p capsem-telemetry -p capsem-assets -p capsem-config -p capsem-credentials -p capsem-foundation -p capsem-core -p capsem-admin -p capsem-agent -p capsem-logger -p capsem-proto -p capsem-guard -p capsem-gateway -p capsem-service -p capsem -p capsem-tui -p capsem-router -p capsem-ledger -p capsem-proxy -p capsem-network -p capsem-mcp-aggregator -p capsem-mcp-builtin -p capsem-tray -p capsem-app -p capsem-process -p capsem-bench -p capsem-mock-server 2>&1 | tee cache/target/coverage/rust/summary.txt

# Run the production executables under the host's real Seatbelt policy.
# --lib/--bins above compiles but does not execute integration targets.
- name: Confined worker subprocess tests
run: cargo test --locked -p capsem-ledger -p capsem-proxy --test subprocess

# Integration tests (tests/ directory, cross-crate)
- name: Integration tests with coverage
Expand All @@ -297,6 +308,11 @@ jobs:
CAPSEM_FRONTEND_JUNIT: ${{ github.workspace }}/cache/target/coverage/junit/frontend.xml
run: bash build_system/scripts/web/check-web-surface.sh frontend-verify

- name: Build Python SDK distributions
run: |
uv sync --project sdk/python --frozen --no-install-project
uv run --project sdk/python --frozen --no-sync python -m build --no-isolation --outdir cache/target/sdk/python sdk/python

# Python schema tests with coverage
- name: Python SDK tests with coverage
working-directory: sdk/python
Expand All @@ -313,13 +329,15 @@ jobs:
working-directory: sdk/typescript
run: |
pnpm install --frozen-lockfile
pnpm run prewarm:package
pnpm test --reporter=default --reporter=junit --outputFile=../../cache/target/coverage/junit/typescript-sdk.xml

# Builds against the SDK package the step above just built.
- name: MCP server tests with coverage
working-directory: mcp/typescript
run: |
pnpm install --frozen-lockfile
pnpm run prewarm:packed
pnpm test --reporter=default --reporter=junit --outputFile=../../cache/target/coverage/junit/mcp-typescript.xml

- name: Cross-system Python schema tests with coverage
Expand Down Expand Up @@ -358,10 +376,12 @@ jobs:
- name: Python integration tests (non-VM suites)
run: |
bash build_system/scripts/test/prepare-install-test-assets.sh
cargo build -p capsem-process -p capsem-service -p capsem -p capsem-mock-server -p capsem-bench
cargo build -p capsem-process -p capsem-ledger -p capsem-proxy -p capsem-service -p capsem -p capsem-mock-server -p capsem-bench
for bin in cache/target/cargo/debug/capsem-process cache/target/cargo/debug/capsem-service cache/target/cargo/debug/capsem cache/target/cargo/debug/capsem-mock-server cache/target/cargo/debug/capsem-bench-rs; do
codesign --sign - --entitlements build_system/packaging/macos/entitlements.plist --force "$bin"
done
codesign --sign - --force cache/target/cargo/debug/capsem-ledger
codesign --sign - --force cache/target/cargo/debug/capsem-proxy
uv run --project build_system --frozen python -m pytest -c build_system/pyproject.toml --rootdir . tests/capsem-bootstrap/ \
tests/capsem-codesign/ \
tests/capsem-rootfs-artifacts/ \
Expand Down
10 changes: 6 additions & 4 deletions .github/workflows/release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -381,6 +381,8 @@ jobs:
-p capsem \
-p capsem-service \
-p capsem-process \
-p capsem-ledger \
-p capsem-proxy \
-p capsem-tui \
-p capsem-router \
-p capsem-mcp-aggregator \
Expand All @@ -396,9 +398,9 @@ jobs:
env:
APPLE_SIGNING_IDENTITY: ${{ secrets.APPLE_SIGNING_IDENTITY }}
run: |
for bin in capsem capsem-service capsem-process capsem-tui capsem-router capsem-mcp-aggregator capsem-mcp-builtin capsem-gateway capsem-tray capsem-admin capsem-mock-server capsem-bench-rs; do
for bin in capsem capsem-service capsem-process capsem-ledger capsem-proxy capsem-tui capsem-router capsem-mcp-aggregator capsem-mcp-builtin capsem-gateway capsem-tray capsem-admin capsem-mock-server capsem-bench-rs; do
entitlement_args=()
if [[ "$bin" != capsem-router ]]; then
if [[ "$bin" != capsem-router && "$bin" != capsem-ledger && "$bin" != capsem-proxy ]]; then
entitlement_args=(--entitlements build_system/packaging/macos/entitlements.plist)
fi
codesign --sign "$APPLE_SIGNING_IDENTITY" \
Expand Down Expand Up @@ -734,7 +736,7 @@ jobs:
pkgutil --pkg-info com.capsem.pkg | grep -F "version: $VERSION"
test -d "/Applications/Capsem.app"
test -x "/Applications/Capsem.app/Contents/MacOS/capsem-app"
for bin in capsem capsem-admin capsem-gateway capsem-router capsem-mcp-aggregator capsem-mcp-builtin capsem-process capsem-service capsem-tray capsem-tui capsem-mock-server capsem-bench-rs; do
for bin in capsem capsem-admin capsem-gateway capsem-router capsem-mcp-aggregator capsem-mcp-builtin capsem-process capsem-ledger capsem-proxy capsem-service capsem-tray capsem-tui capsem-mock-server capsem-bench-rs; do
test -x "$HOME/.capsem/bin/$bin"
"$HOME/.capsem/bin/$bin" --version | grep -F "$VERSION"
done
Expand Down Expand Up @@ -819,7 +821,7 @@ jobs:
sudo dpkg -i "$package"
test ! -e /var/run/capsem/install-manifest
dpkg-query -W -f='${Version}' capsem | grep -Fx "$VERSION"
for bin in capsem capsem-admin capsem-app capsem-gateway capsem-router capsem-mcp-aggregator capsem-mcp-builtin capsem-process capsem-service capsem-tray capsem-tui capsem-mock-server capsem-bench-rs; do
for bin in capsem capsem-admin capsem-app capsem-gateway capsem-router capsem-mcp-aggregator capsem-mcp-builtin capsem-process capsem-ledger capsem-proxy capsem-service capsem-tray capsem-tui capsem-mock-server capsem-bench-rs; do
test -x "/usr/bin/$bin"
if [ "$bin" != "capsem-app" ]; then
"/usr/bin/$bin" --version | grep -F "$VERSION"
Expand Down
2 changes: 2 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,7 @@ See `/dev-just` for the full recipe reference and dependency chains.
```
crates/capsem-foundation/ Low-level paths, UDS, logging, polling, and IPC handshake
crates/capsem-archive/ Block-compressed body archive for session ledgers (pure Rust)
crates/capsem-ledger/ Confined session-ledger worker and archive codec executor
crates/capsem-telemetry/ Every metrics-facade metric name, kind, unit, and description
crates/capsem-assets/ Asset manifest compatibility, resolution, download, and verification
crates/capsem-api/ Gateway wire types and OpenAPI contract shared by clients
Expand All @@ -52,6 +53,7 @@ crates/capsem-credentials/ Credential provider contracts and durable credent
crates/capsem-core/ VM, hypervisor, security engine, and host network runtime
crates/capsem-service/ Daemon service (axum HTTP over UDS, VM lifecycle)
crates/capsem-process/ Per-VM process (boots VM, bridges vsock, job store)
crates/capsem-proxy/ Confined HTTP/DNS proxy worker for VM and standalone traffic
crates/capsem/ CLI client (create, shell, exec, list, install, assets, update)
crates/capsem-tui/ Terminal control UI (reads and drives state via the gateway)
crates/capsem-admin/ Runtime image/asset/release administration (validate, materialize, publish)
Expand Down
Loading
Loading