Skip to content

Publish owner state before announcing finalized progress - #38

Merged
georgewhewell merged 1 commit into
masterfrom
codex/chain-owner-snapshot
Oct 3, 2026
Merged

georgewhewell merged 1 commit into
masterfrom
codex/chain-owner-snapshot

Conversation

@georgewhewell

Copy link
Copy Markdown
Contributor

Finalization could announce height 1 while the owner cursor still pointed at genesis. A reader woken by that notification could report ready and return no owner snapshot, causing the post-merge paid-work CI failure.

Publish the owner cursor before updating readiness and notifying readers. A deterministic regression test inspects the cursor synchronously when the notification wakes its receiver; it fails at height 0 on the previous ordering and passes with this fix.

Validation: all 154 chain tests passed with full-node,validator,work-watcher; strict all-target Clippy and formatting passed.

georgewhewell added a commit to hellas-ai/gate that referenced this pull request Oct 3, 2026
Gate uses the merged Work foundation for authorized and paid requests.
Imported contact Offers open grant sessions; paid pools use
authenticated provider offers and one shared executing chain node.
Providers serve both fundings through the SDK and preserve durable
quotas and revocations across restarts.

The gateway has explicit Responses and HTTP configurations. Responses
uses the selected Work target; HTTP retains paid-pool routing, provider
assurance and optional body archiving. Shutdown drains accepted work and
surfaces SDK failures after closing providers and chain state.

Pins Hellas `9c342ba1`, including hellas-ai/hellas#38 (finalized owner
publication ordering) and hellas-ai/hellas#39 (current App Attest
extensions and the Windows TLS fixture). Native archives use Xcode’s
compiler and linker. The shell follows `xcode-select`, with
`GATE_DEVELOPER_DIR` for provisioned SDK 27 builds; the signing guide
documents the requirement. The release binary has the recursion limit
needed by the chain transport futures.

Validation:
- Linux and native macOS `make check`: 25 tests, bindings, frontend,
formatting and strict Clippy passed.
- Native macOS release app built and passed bundle validation.
- Developer ID signed, provisioned test bundle on `mbp`: Apple
enrollment, pinned remote grant session, provider restart and a second
session passed. The test uses the installed `ai.hellas.app-attest-spike`
profile; production Gate keeps its own bundle ID.
- SDK TLS Responses, quota exhaustion, restart and revocation passed on
Linux, macOS and Windows.

Merge the two Hellas fixes first. Windows support is isolated in #585,
based on this PR.
georgewhewell added a commit to hellas-ai/gate that referenced this pull request Oct 3, 2026
Ports Gate’s host control and private state to Windows on top of #586.
The diff contains the Windows named-pipe listener, private-directory
ACLs and bundled SQLite; shared Work/SDK integration lives in the base
PR. The Windows diff is 7 files, 101 insertions and 14 deletions.

Pins the same Hellas revision as #586, including hellas-ai/hellas#38 and
hellas-ai/hellas#39. Published history is preserved with normal merges.

Validation:
- Linux `make check`: 26 tests, bindings, frontend, formatting and
strict Clippy passed.
- Windows GNU cross-compilation of the desktop app and test executable
passed.
- Native `win10` VM: all 9 core tests passed, including authenticated
host status over a named pipe, private state, history and grant offer
export.
- Native SDK TLS Responses/quota/restart/revocation test passed.
- Desktop executable with bundled frontend and WebView2 loader launched
successfully.

Merge #586 first.
@georgewhewell
georgewhewell merged commit 676b83c into master Oct 3, 2026
30 checks passed
@georgewhewell
georgewhewell deleted the codex/chain-owner-snapshot branch October 3, 2026 03:45
georgewhewell added a commit that referenced this pull request Oct 3, 2026
Native testing found two failures that Linux CI and the older App Attest
fixture missed.

Current macOS App Attest evidence sets the extensions-present bit
(`0xc0`). Accept it alongside the earlier `0x40` form, retaining all
existing certificate, signature, RP-ID, CDHash, validation-category and
counter checks. A new signed fixture from `mbp` reproduces the failure
before the fix; both fixture generations now pass. Missing CDHash
remains rejected for both flag forms.

The SDK TLS fixture also used the same subject name for its CA and
server certificate. Give them distinct names so Windows verifies the
certificate chain correctly.

Validation: all 8 attestation tests and strict Clippy pass; the TLS
Responses/quota/restart/revocation test passes natively on Linux, macOS
and Windows. A Developer ID signed, provisioned Gate test bundle on
`mbp` successfully enrolls, opens a pinned remote grant session,
restarts and opens another session with its persisted identity. That
build uses SDK 27; SDK 26.5 omitted CDHash evidence.

Based on #38; merge #38 first. Gate hellas-ai/gate#586 pins this
revision.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant