feat: bootstrap the shared Pingora edge runtime - #1
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Current TDD direction needs one correction before GREEN: |
Merge the exact hosted-GREEN workflow repair into the #59 workflow-policy owner branch after CI and Supply Chain both completed successfully. Preserve normal ancestry; no force update or bypass.
Exact combined head completed CI 33971798747 and Supply Chain 33971798802 successfully. All returned review threads are resolved. Promote the reviewed five-file workflow-policy owner into foundation without force updates or gate weakening.
|
Fresh root-state correction: Cloudflare protected |
|
Fresh central-governance handoff (2026-09-12): canonical Predecessor Canonical The matching current-generation protected-handler run Do not manual-rerun, source-neutral retrigger, publish synthetic statuses, self-approve, auto-merge, copy the handler locally, or bypass protection. This governance path remains independent of supplier qualification. Cloudflare protected |
Purpose
Bootstrap the reusable ContextualWisdomLab Pingora edge runtime as a Supporting/Generic boundary. The gateway owns reusable transport/edge behavior only; product authentication/business routing, Keyverse identity, certificate issuance/key custody, static-site semantics, workflow state, Wardnet/EgressWeave policy and domain retry/failover decisions remain with their canonical owners.
Current exact foundation
PR head remains
0da81a93f93e869c15bb7d34c55fc87479d16522on protectedmain@f8b4c99b8e5d3de79af1ff0c00c0c8fd63b52991. Keep Draft. No force update, destructive rebase, self-approval, administrator bypass, security suppression or predecessor-success transfer is authorized.The foundation provides the initial Rust/Pingora serving path, verified upstream TLS/hostname identity with optional trust bundle, bounded timeout/body/keepalive/in-flight budgets, fail-fast backpressure, forwarding sanitation, health/readiness, low-cardinality observability, HTTP/TLS/failure/drain acceptance, non-root/read-only OCI packaging, committed dependency lock/policy, and DDD/security/operability documentation. Later stacked PRs extend protocol, performance and release evidence; their GREEN does not make this root protected-integrated.
Live root RED
Fresh exact-head Security Scan run
33976768725is terminal failure for a real dependency finding, not runner noise. The OSV job checked basef8b4c99...and head0da81a9...; base had zero findings while the head lockfile introducedderivative@2.2.0/RUSTSEC-2024-0388. The reporter records one affected package, no fixed version, and fails the PR-introduced finding gate. Do not rerun this as if transient and do not add an ignore merely to make the root GREEN.Cloudflare Pingora now has two distinct authorities that must not be conflated. Protected upstream
mainhas advanced to4487f7b2ab50f159e4a2cf4f6a6b813f61bb6e19, but the latest published release remains Pingora0.9.0, whose lightweight tag points to702f69015e53f7244d6ad2e743de571d859a70a4. Current upstreammainstill declares workspacederivative = "2.2.0", and owner issue #889 remains open with no maintainer-integrated derivative-removal disposition. A movingmain, downstream fork/patch, advisory ignore, or mutable contributor pin is not an acceptable release authority.Central CodeQL run
33976768716is also not GREEN. Itsactions,python, andjavascript-typescriptcompatibility shards dispatched current-head scans and intentionally failed pending an authenticatedcodeql-dispatch/<language>terminal verdict. The current commit-status feed contains no such authenticated dispatch verdict. Do not count those first-attempt failures as security findings, but also do not promote them to GREEN without the canonical central callback..githubremains a dedicated owner boundary.Stacked repair/evidence authority
#56
18fb38b1ba70c4bf222642ef347f3d57a98379a2is the Rust 1.98.1 compiler foundation on top of this branch. Its repository CI/Supply Chain gates are GREEN and it is Ready/mergeable, but fresh formal review history still has no independentAPPROVEDreview. Rust 1.98.1 therefore remains a gated successor, not protectedmainauthority.The intended supplier absence regression remains represented by #54; the current upstream
derivativegraph means that regression cannot become GREEN honestly until a maintainer-integrated, release-qualified supplier repair exists and the gateway regenerates its committed lock against that immutable authority.Protocol/performance/release successors have advanced far beyond the historical root body. The downstream TLS/H2 chain #75–#88 is exact-head GREEN/Ready; #89
bf66d0317f2f7709dee611b513f1a44551c1fac9closes handshake-vs-reuse performance; #90069e11e170cd60b321e28ef4499c88d690a45956closes controlled clean-build reproducibility; #91bc85547ebed648c03142edad661c57b1b42a2dc4adds signed GitHub OIDC/Sigstore provenance; and #92411ea0361fc392508c19c4ad0362c0cc845c3de3now binds protected evidence to the exact scanned OCI image as well as report digests. #92 has reacquired terminal GREEN on CI34657862357, Supply Chain34657862365, PgErd capacity34657862366, TLS H2 Performance34657862338, and Release Reproducibility34657862364; exact-current technical re-review5184411500found no additional writer-safe defect and review threads are 0. It is Ready/mergeable, but still has no independentAPPROVEDreview and cannot execute its real protected bundle before dependency-ordered integration.Dedicated documentation lane #61 remains owner of
docs/product-technical-gap-baseline.md. Current promotion/protocol handoff is maintained in #51/#58; do not race #61 source/docs/refs.Supplier and protocol boundary
Published Pingora 0.9.0 is not sufficient to clear all current supplier gates. In addition to #889, H2→H1 Cookie coalescing #901, H1 empty-final-body #976 and configurable H1 parser admission #1000 remain open contributor PRs; downstream whole-header lifetime owner issue #447 also remains open. Treat mutable contributor heads as evidence only until maintainer-integrated and release-qualified. HTTP/3/QUIC remains fail-closed.
Promotion boundary
The root cannot honestly reach Ready/merge while its exact dependency scan introduces
RUSTSEC-2024-0388. Current causal order is:maintainer-integrated release-qualified Pingora derivative repair → gateway immutable supplier bump + Cargo-generated lock → exact #1/#54 dependency RED→GREEN without advisory suppression → preserve/revalidate #62 supplier semantics and stacked protocol/performance acceptance → #56 independent approval and then-live protected governance → dependency-ordered non-force integration/restack → protected-main same-SHA Supply Chain/reproducibility/provenance + #92 evidence bundle → immutable-release administration verification → version/CHANGELOG/tag/package + immutable release/SBOM/provenance/reproducibility → representative NUMA and remaining release-qualified supplier gates → consumer parity/shadow/canary/observed rollback/cutover → verified Nginx/OpenResty removal.No release, cutover or legacy-removal credit is assigned before those gates exist.