Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
39 commits
Select commit Hold shift + click to select a range
5936154
feat(c2pa-oracle): add a differential oracle over c2pa-rs
justin13888 Sep 9, 2026
c6bc972
test(c2pa-oracle): pin both directions against c2pa-rs
justin13888 Sep 9, 2026
e0a0f9f
fix(c2pa-oracle): read the two reserved JUMBF LBox values, and keep s…
justin13888 Sep 10, 2026
71bcd86
test(c2pa-oracle): assert the located range, and tolerate a padded slot
justin13888 Sep 10, 2026
126ba1c
build(c2pa-oracle): pin c2pa exactly and stop the manifest escaping i…
justin13888 Sep 10, 2026
19e24f8
test(c2pa-oracle): drive the copy-forward refusal through C2paPolicy
justin13888 Sep 10, 2026
429c540
docs(c2pa-oracle): say what the crate's automated reach actually is
justin13888 Sep 10, 2026
c0f8b21
fix(c2pa-oracle): refuse an XLBox shorter than the header it counts
justin13888 Sep 10, 2026
6cbc377
test(c2pa-oracle): drop the Reject duplicate and pin the model it needed
justin13888 Sep 10, 2026
721097e
test(c2pa-oracle): guard the offsets read ahead of the update store
justin13888 Sep 10, 2026
8417845
docs(c2pa-oracle): record the header minimums and the span's unchecke…
justin13888 Sep 10, 2026
f87c08a
docs(c2pa-oracle): stop the root manifest claiming CI runs the oracle
justin13888 Sep 10, 2026
4daeda8
Merge branch 'feat/444-avif-c2pa-reserve' into feat/447-c2pa-oracle
justin13888 Sep 10, 2026
c587591
refactor(c2pa-oracle): follow gamut-avif's renamed C2PA read accessors
justin13888 Sep 10, 2026
91e099f
Merge branch 'feat/444-avif-c2pa-reserve' into feat/447-c2pa-oracle
justin13888 Sep 10, 2026
06bc874
fix(c2pa-oracle): report an overrunning length as a length, not as ab…
justin13888 Sep 10, 2026
400c10f
fix(c2pa-oracle): refuse a to-end-of-buffer length below its own header
justin13888 Sep 10, 2026
5cda4bb
test(c2pa-oracle): compare the model's store against the parent's bytes
justin13888 Sep 10, 2026
f9895c4
docs(c2pa-oracle): cite the vendored specification for only what it says
justin13888 Sep 10, 2026
cbd3e30
Merge remote-tracking branch 'origin/feat/444-avif-c2pa-reserve' into…
justin13888 Sep 10, 2026
1677990
test(c2pa-oracle): pin both sides of every JUMBF header refusal
justin13888 Sep 10, 2026
6d8e733
test(c2pa-oracle): drive the reserved-slot length guard instead of re…
justin13888 Sep 10, 2026
67a5a25
test(c2pa-oracle): compare the carried store without assuming no padding
justin13888 Sep 10, 2026
805f10b
build(c2pa-oracle): commit the lockfile the resolved-graph check reads
justin13888 Sep 10, 2026
a1f6a61
docs(c2pa-oracle): point the pinned-refusal claim at its enumeration
justin13888 Sep 10, 2026
447ab4b
test(c2pa-oracle): name the span row for the span it pins
justin13888 Sep 10, 2026
3d47fb6
docs(c2pa-oracle): say what the refusal tests assert, exactly
justin13888 Sep 10, 2026
124eea9
build(c2pa-oracle): pass --locked so the committed lockfile is the on…
justin13888 Sep 10, 2026
09de2a4
docs(c2pa-oracle): name the panic ComposedBox::store can raise
justin13888 Sep 10, 2026
f4ff9ae
test(c2pa-oracle): refuse the nearest length that runs past the buffer
justin13888 Sep 10, 2026
d28fd70
test(c2pa-oracle): enumerate every discriminating branch, not only re…
justin13888 Sep 10, 2026
aa6340d
test(c2pa-oracle): check the enumeration against the functions it names
justin13888 Sep 10, 2026
0eb7b1b
docs(c2pa-oracle): keep the README's claims level with the code
justin13888 Sep 10, 2026
fa83a8a
docs(c2pa-oracle): derive the transitive-package count, and say what …
justin13888 Sep 10, 2026
82bd447
docs(c2pa-oracle): name the enumerated functions instead of glossing …
justin13888 Sep 10, 2026
c542bcb
docs(c2pa-oracle): say why no row can point at an integration test
justin13888 Sep 10, 2026
93b8b54
docs(c2pa-oracle): count the duplicated package names correctly
justin13888 Sep 10, 2026
722c5ba
style(c2pa-oracle): re-wrap the three comments the figure change left…
justin13888 Sep 10, 2026
c5b48e2
docs(c2pa-oracle): document the path-crate lockfile hazard and its re…
justin13888 Sep 25, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,17 @@ target
# regenerates a redundant local lockfile that should not be committed.
tooling/*/Cargo.lock

# One deliberate exception. `tooling/c2pa-oracle` resolves a real external dependency tree
# (`c2pa`, the C2PA reference implementation) that no other manifest in this repository pins, so
# there is no root lockfile standing behind it: without one of its own, its whole transitive graph
# re-resolves on every invocation. Two things depend on that resolution being held still —
# `README.md` cites `c2pa`'s source **by line number**, and
# `tests/build_configuration.rs` asserts no OpenSSL package reached the graph. The exact `=`
# version pin in its manifest holds only the direct dependency; the assertion about the *graph*
# can otherwise only ever inspect the resolution cargo has just written, which is not an
# assertion. Committing this one lockfile is what makes it one.
!tooling/c2pa-oracle/Cargo.lock

# The fuzz tier's search state (issues #264, #311). The corpus is a search aid, not the regression
# record: a saved input is only reproducible while the target's byte-to-input mapping is unchanged,
# so a crash is minimised and promoted into a NAMED DETERMINISTIC TEST in the crate's own suite
Expand Down
8 changes: 8 additions & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,14 @@ exclude = [
# pins stable, and because a coverage-guided engine is unbounded and so cannot sit in the
# `coverage` job, the only gate that runs tests. Run it with `mise run fuzz`.
"tooling/gamut-fuzz",
# Dev-only differential oracle against `c2pa-rs`, the C2PA reference implementation (issue
# #447 under the #239 epic). Excluded for the usual reason and one more: `c2pa-rs` is a large
# dependency tree carrying signing and verification crypto, and the epic's "no crypto in the
# shipped graph" criterion means no shipped crate may ever reach it. Being outside the
# workspace also puts it outside `mise run check-release-deps`. Run it with `mise run
# test-c2pa`, or `mise run check-c2pa` for the compile-only half. No workflow under `.github/`
# calls either task yet, so nothing in CI reaches this crate; wiring them up is issue #541.
"tooling/c2pa-oracle",
"tooling/gamut-iptc-oracle",
"tooling/zlib-oracle",
"tooling/libpng-oracle",
Expand Down
37 changes: 37 additions & 0 deletions mise.toml
Original file line number Diff line number Diff line change
Expand Up @@ -210,6 +210,43 @@ run = "cargo test --manifest-path tooling/gamut-dng-real-conformance/Cargo.toml"
description = "Compile the real-camera DNG conformance tier (no corpus needed)"
run = "cargo check --manifest-path tooling/gamut-dng-real-conformance/Cargo.toml --all-targets"

# The C2PA differential oracle (issue #447 under the #239 epic). Like the tier above it is
# workspace-excluded *and* nothing depends on it, so no per-PR gate reaches it; unlike that tier it
# needs no corpus and no native toolchain — `c2pa-rs` is a pure-Rust crate built
# `--no-default-features --features rust_native_crypto`, which is what keeps its vendored OpenSSL
# out of this repository entirely. It is still kept off `mise run test` because a shipped crate
# must never gain an edge to it, and the excluded manifest is what enforces that.
#
# `--locked` is what makes the committed `tooling/c2pa-oracle/Cargo.lock` load-bearing. Without it
# cargo silently re-resolves the 307 transitive packages under the pinned `c2pa` (the figure is
# derived in `tooling/c2pa-oracle/README.md`) and writes the result over the committed file, so the
# crate's own resolved-graph assertion would be reading a resolution cargo had produced moments
# earlier. With it, a lockfile that is missing or out of date fails the task instead of being
# regenerated.
#
# That lockfile also records the 15 `gamut-*` crates this one reaches by path (it is workspace-
# `exclude`d, so the root lockfile does not stand in for it). A release-plz version bump or a
# dependency change in any of them therefore fails both tasks with "cannot update the lock file …
# --locked was passed" even though nothing here changed. Refresh with
# `cargo update --workspace --manifest-path tooling/c2pa-oracle/Cargo.toml` (path entries only; the
# registry graph under `c2pa` stays put) and commit it — `tooling/c2pa-oracle/README.md`,
# "Refreshing the lockfile after a gamut crate changes".
[tasks.test-c2pa]
description = "Cross-check gamut's C2PA carriage against c2pa-rs, both directions (issue #447)"
run = "cargo test --locked --manifest-path tooling/c2pa-oracle/Cargo.toml"

# The compile half, shaped after `check-dng-real`: a `gamut-avif` or `gamut-heic` API change can
# break this crate while every per-PR gate stays green, and `check` catches that in seconds without
# signing anything.
#
# Unlike `check-dng-real`, **neither of these two tasks is called by any workflow in `.github/`.**
# The crate's whole automated reach today is `fmt-tooling-check`, which `fmt-check` hangs off, so a
# compile break or a differential regression is caught only when someone runs these by hand.
# Wiring them up — `check-c2pa` in the per-PR lint lane, `test-c2pa` in extended — is issue #541.
[tasks.check-c2pa]
description = "Compile the C2PA differential oracle (no signing, no corpus)"
run = "cargo check --locked --manifest-path tooling/c2pa-oracle/Cargo.toml --all-targets"

# Doctests only. On stable, `cargo llvm-cov` cannot instrument doctests (that needs nightly), so
# the coverage gate — which CI uses as its green-test gate — silently skips them. This task is the
# missing slice: CI's lint lane runs it, reusing the `--all-targets --all-features` build it just
Expand Down
Loading
Loading