feat(sending): prepare reviewed policy activation and readiness - #1067
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Switching to database policy can select a legacy generation that predates the external-sending admission gate, while readiness previously checked only database connectivity and migrations. This adds the operator tools and readiness validation needed to prepare an explicit, approval-preserving source switch.
-sending-protection-policy-filefor inspection and audited CAS activation of a complete, bounded runtime-policy JSON file. Config/environment overrides do not alter the candidate, the reviewed hash is required, and enabled controls require both trust roots. Duplicate JSON keys, including escaped and nested keys, are rejected.Validation at
29690bc73: focused readiness/CLI race tests, the entire policy-package race suite, provider-call closure guard, formatting, and log-redaction checks pass. A rebuilt local two-process HTTP/SMTP drill verified missing-registry and corrupt-policy readiness failures, generation-1 file activation, stale-CAS rejection, unapproved external-send refusal in both sources, and one approved local SMTP delivery. Synthetic live-service data and processes were removed.Independent and adversarial re-reviews both pass. Their findings were fixed with regressions: ambiguous duplicate keys (reproduced failing before the fix), and bounded readiness failure/recovery after a real policy-query lock timeout.
The full local integration suite was run but was not green: existing outreach-counting failures previously reproduced on unchanged main remain; overlapping local policy test runners also collided on their test database. The complete policy race suite subsequently passed against a separate database. A stuck local fsmonitor subprocess was bypassed for a passing log-redaction rerun. Final-commit CI supplies the clean complete-suite evidence: 28 checks passed, including the complete integration suite, coverage and race gate, with one expected release-only skip.
This PR does not change runtime defaults, activate hosted policy, seed trust history, advance the compiled closure contract, or deploy a release. Hosted policy payloads, deployment guards, and the staged source switch remain subsequent rollout steps.