Skip to content

feat(sending): prepare reviewed policy activation and readiness - #1067

Merged
jiashuoz merged 2 commits into
mainfrom
feat/sending-policy-readiness
Oct 2, 2026
Merged

jiashuoz merged 2 commits into
mainfrom
feat/sending-policy-readiness

Conversation

@jiashuoz

@jiashuoz jiashuoz commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Switching to database policy can select a legacy generation that predates the external-sending admission gate, while readiness previously checked only database connectivity and migrations. This adds the operator tools and readiness validation needed to prepare an explicit, approval-preserving source switch.

  • Add -sending-protection-policy-file for inspection and audited CAS activation of a complete, bounded runtime-policy JSON file. Config/environment overrides do not alter the candidate, the reviewed hash is required, and enabled controls require both trust roots. Duplicate JSON keys, including escaped and nested keys, are rejected.
  • In database-source mode, readiness validates the policy schema/hash and selected permanent recipient commitment in one read-only snapshot on the dedicated probe connection. Invalid policy/registry state fails readiness without auto-repair or fallback. Config-source readiness and shallow liveness retain their behavior.
  • Document candidate review, first-generation admission carryover, source rollback, and readiness semantics. A healthy probe establishes validity; deployment checks must still verify the intended generation/hash and admission rules.

Validation at 29690bc73: focused readiness/CLI race tests, the entire policy-package race suite, provider-call closure guard, formatting, and log-redaction checks pass. A rebuilt local two-process HTTP/SMTP drill verified missing-registry and corrupt-policy readiness failures, generation-1 file activation, stale-CAS rejection, unapproved external-send refusal in both sources, and one approved local SMTP delivery. Synthetic live-service data and processes were removed.

Independent and adversarial re-reviews both pass. Their findings were fixed with regressions: ambiguous duplicate keys (reproduced failing before the fix), and bounded readiness failure/recovery after a real policy-query lock timeout.

The full local integration suite was run but was not green: existing outreach-counting failures previously reproduced on unchanged main remain; overlapping local policy test runners also collided on their test database. The complete policy race suite subsequently passed against a separate database. A stuck local fsmonitor subprocess was bypassed for a passing log-redaction rerun. Final-commit CI supplies the clean complete-suite evidence: 28 checks passed, including the complete integration suite, coverage and race gate, with one expected release-only skip.

This PR does not change runtime defaults, activate hosted policy, seed trust history, advance the compiled closure contract, or deploy a release. Hosted policy payloads, deployment guards, and the staged source switch remain subsequent rollout steps.

@jiashuoz
jiashuoz marked this pull request as ready for review October 2, 2026 10:50
@jiashuoz
jiashuoz merged commit 6151b37 into main Oct 2, 2026
29 checks passed
@jiashuoz
jiashuoz deleted the feat/sending-policy-readiness branch October 2, 2026 11:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant