Skip to content
This repository was archived by the owner on Oct 1, 2026. It is now read-only.
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,16 @@ updates:
dependencies:
patterns:
- "*"
- package-ecosystem: "cargo"
directory: "/"
schedule:
interval: "weekly"
commit-message:
prefix: "deps-rust"
groups:
rust-dependencies:
patterns:
- "*"
- package-ecosystem: "github-actions"
directory: "/"
schedule:
Expand Down
19 changes: 19 additions & 0 deletions .github/required-status-checks.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# Status contexts required by branch protection on main, one per line.
#
# This list is a local mirror of the remote branch protection configuration and
# exists only so a workflow change that renames or drops a required job is
# caught before merge; the remote configuration remains authoritative and is
# changed separately. Refresh it from the branch protection API when the remote
# list changes.
#
# The "CodeQL" context is reported by the CodeQL GitHub App rather than by a
# workflow job name, so it is not listed here.
#
# Verified against the branch protection API for this repository:
# Lint GitHub Actions workflows
# Quality gates
# Analyze (javascript-typescript, actions)
# CodeQL
Lint GitHub Actions workflows
Quality gates
Analyze (javascript-typescript, actions)
25 changes: 24 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,8 @@ jobs:
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
bun-version: 1.4.2
- name: Install locked project dependencies
run: bun install --frozen-lockfile
- name: Run quality gates
run: just check

Expand All @@ -37,10 +39,31 @@ jobs:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Lint workflows with pinned actionlint
uses: docker://rhysd/actionlint:1.7.12
uses: docker://rhysd/actionlint:1.7.12@sha256:b1934ee5f1c509618f2508e6eb47ee0d3520686341fec936f3b79331f9315667
with:
args: -color

platform:
name: Offline platform contract (${{ matrix.os }})
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Bun
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
bun-version: 1.4.2
- name: Install locked project dependencies
run: bun install --frozen-lockfile
- name: Run offline platform contract tests
run: bun test tests/platform-contract.test.ts
- name: Exercise executable help without a target
run: bun run bin/bitty-devtools.ts --help

fuzz-smoke:
name: Fuzz smoke (pinned, read-only, offline)
runs-on: ubuntu-latest
Expand Down
35 changes: 35 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,10 +15,19 @@ permissions:
contents: read

jobs:
# Branch protection on main requires the status context
# "Analyze (javascript-typescript, actions)" under this exact name, so the
# combined analysis stays a single job with its historical name. Splitting it
# into a per-language matrix renames every check and blocks every pull
# request. Change the required context in branch protection before renaming
# this job. The emitted names are guarded by
# tests/platform-contract.test.ts against
# .github/required-status-checks.txt.
analyze:
name: Analyze (javascript-typescript, actions)
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write
steps:
Expand All @@ -28,5 +37,31 @@ jobs:
uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4
with:
languages: javascript-typescript, actions
build-mode: none
config-file: .github/codeql/codeql-config.yml
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4
with:
category: "/language:javascript-typescript,actions"

# Rust is a second language in this repository, analysed separately so the
# required combined context above is never renamed.
analyze-rust:
name: Analyze (rust)
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Initialize CodeQL
uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4
with:
languages: rust
build-mode: none
config-file: .github/codeql/codeql-config.yml
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4
with:
category: "/language:rust"
73 changes: 47 additions & 26 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,25 +42,18 @@ and this project adheres to no released version yet.
issue's strict-envelope requirement.

- **Diagnostics client phase 2 (CTX-0012)**: advanced tracing, control
surfaces, and real IPC socket/pipe peer-creds integration against the live
Bitty runtime. Reuses Panel Runtime and 14×4 compat matrix and extends
phase 1; bounded and `forbid(unsafe_code)`; strict TypeScript with no `any`.
Includes headless-testable `auth` (Unix `SO_PEERCRED` / Windows pipe ACL,
`0700`/`0600`, per-action re-verify, `BITTY_SOCKET` advisory, child token
`60s` bounded `64`) and `transport` (length-prefixed `256 KiB` frames,
`1 MiB` devtools logical, `RC-9` `100/s` `200` burst `16` conn, `RC-10`
`256 KiB` chunk, `Framer` `512 KiB` bound, `RateLimiter` deterministic,
`StdioTransportStub` + `IpcTransport` with `forwardTo` pipe simulation);
advanced `tracing` (filtering by kinds/owners `32`, coalescing `budget`,
structured attributable events, retention `4 MiB`/`5 min`/`4` traces,
GC `gcExpiredTraces`, chunked `256 KiB` export `0600` preview==export);
advanced `control` (pause/resume, generation exhaustion guard
`MAX_SAFE_INTEGER-1024`, transactional audit log `256` bounded,
`validateGeneration`, `listAuditLog`); client `DevtoolsClient` now
integrates `IpcTransport` (`connectWithTransport`, `connectLive` with
`XDG_RUNTIME_DIR` socket `0700`/`0600`, `isIpcConnected`,
per-privileged peer re-verify). TypeScript `62` tests and Rust
`37` tests pass; `just check` green.
surfaces, and a Linux-only endpoint-attested Unix-socket inspection adapter.
The adapter verifies the socket path, parent directory, endpoint ownership,
and modes before dialing, but does not authenticate a connected peer; live
sessions are therefore inspect-only. Windows named-pipe and macOS live
adapters are not implemented and fail closed. The client also retains a
headless transport/authentication fixture for caller-supplied values and
deterministic tests, not OS connectivity. Reuses Panel Runtime and the
14×4 compat matrix; bounded and `forbid(unsafe_code)` in Rust, strict
TypeScript with no `any`. `BITTY_SOCKET` and `BITTY_INSTANCE_ID` select a
bounded path but are not credentials or identity. Advanced tracing and
control remain simulation/test surfaces until a server-backed trace receipt
and connected-identity control contract exist.

- **Diagnostics client phase 1 (CTX-0011)**: human-facing inspection,
tracing, and control surfaces for local debugging over the accepted Panel
Expand All @@ -74,13 +67,11 @@ and this project adheres to no released version yet.
protocol `1.0`.

- **Toolchain pin (CTX-0046)**: pin `packageManager` to `bun@1.4.2` in
`package.json`, matching the workspace toolchain. `bun.lock` is unchanged
(`bun install --frozen-lockfile` passes). CI still installs Bun `1.4.0`
via `bun-version` (drift noted; workflow untouched by this slice).

- **CI Bun version (CTX-0047)**: align `bun-version` in
`.github/workflows/ci.yml` with the `bun@1.4.2` toolchain pin, removing the
drift noted by CTX-0046.
`package.json`, matching the workspace toolchain. `bun.lock` is synchronized
with the declared dependencies; `bun install --frozen-lockfile --dry-run`
passes.
- **CI Bun version (CTX-0047)**: pin CI to Bun `1.4.2` and use
`bun install --frozen-lockfile` in the quality and platform jobs.

- **Governance scaffolding**: MIT [LICENSE](./LICENSE), contribution guide
([CONTRIBUTING.md](./CONTRIBUTING.md)) with the Bitty delivery lifecycle and
Expand All @@ -102,3 +93,33 @@ and this project adheres to no released version yet.
unchanged retained state, opaque raw append distinct from typed stream
coalescing, and `fetchTraceChunk` pagination on retained UTF-8 byte offsets.
No code behavior changed.

### Fixed

- **Platform, version, and quality contracts (CTX-0080 / #141)**: the live
inspection path is now described as the code implements it. The live adapter
is Linux-only and attests the endpoint (socket path, parent directory,
ownership, and modes) before dialing; it does not authenticate a connected
peer, so live sessions stay inspect-only and `authenticated: false` is
reported. Windows and macOS return an explicit unsupported result and never
reach endpoint access. Unsupported live protocol versions and methods are
rejected with typed fail-closed errors before socket I/O, owned by
`src/protocol-boundary.ts` (live request admission only; `src/protocol.ts`
decoding stays with CTX-0079). `BITTY_SOCKET` and `BITTY_INSTANCE_ID` remain
bounded path selectors and are never credentials or identity, and no runtime
UID environment variable is read. CodeQL activates the checked-in
`.github/codeql/codeql-config.yml` for the combined `javascript-typescript,
actions` analysis and adds a separate Rust analysis with
`build-mode: autobuild`; the combined job keeps its exact name because branch
protection on `main` requires the status context
`Analyze (javascript-typescript, actions)`, now mirrored in
`.github/required-status-checks.txt` and asserted by
`tests/platform-contract.test.ts`. CI installs locked dependencies before the
quality and platform jobs, runs the offline platform contract on Linux, macOS,
and Windows, and pins the actionlint image by digest; Dependabot covers the
Cargo workspace. The `workflow-import` fixture suite derives its per-test
deadline from the fixture spawn budget, because Bun's 5 s per-test default is
shorter than one fixture run and so reported correct runs as timeouts under
load; `tests/workflow-import-budget.test.ts` fails if the two budgets cross
again. No `Verified` or `Compatible` platform status is claimed, and no
interoperability, release, or distribution claim is made.
Loading
Loading