- 11-06 records TestBroadcastGoldens/created and /updated and reports them
as skipped until Phase 12; the Phase 10 detector refused any skip, so
check-phase10.sh --all failed on the fonoteka.go suite
- mirrors 73cfed7 (check-phase10.1.sh): the detector accepts exactly those
skips when their output carries 'pending: Phase 12'; the self-test proves
a pending skip passes and one without the text fails
- 11-06 records TestBroadcastGoldens/created and /updated and reports them
as skipped until Phase 12; the 10.1 detector refused any skip, so
check-phase10.1.sh --all failed on the fonoteka.go suite
- the detector now accepts exactly those skips when their output carries
'pending: Phase 12' (the same rule check-phase11.sh enforces); the
self-test proves a pending skip passes and one without the text fails
- 11-SECURITY-REVIEW.md: T-11-01..T-11-30 and T-11-SC with each plan's
severity and disposition, mitigation, test and result; RC-01..RC-13
removal checks for every high mitigated threat; the three defects fixed
in 11-07
- 11-VALIDATION.md: task ids, plans and waves per row, commands run,
status validated, nyquist_compliant and wave_0_complete true
- scripts/check-phase11.sh: --self-test, --hygiene, --go, --postgres,
--named, --evidence, --all (prints 'phase11 all passed') and --removal
- the go test -json detector refuses failures, skips, zero tests and
'no tests to run'; only the two Phase 12 broadcast goldens may skip, and
only with their pending text
- hygiene refuses application names in the Phase 11 framework files, the
Centrifugo/Typesense/Web Push client libraries, a direct cron
requirement, River other than v0.47.0 and a module without README or
root row; each rule returns on its first violation and the self-test
proves each refuses its own plant and accepts look-alikes
- --removal: anchor-exact mutations for the high threats, each required to
fail its named test on an assertion and restored byte for byte (cmp)
- TestSyncEngineRegistration: the typesense import registers the driver
and a missing or blank api_key reports Configured false, the gate that
keeps beachcomber from sending anything
- TestCentrifugoRecorder: info/unsubscribe answers, 405 with Allow, 413
above the body cap (not recorded), authorization as a comparison that is
never stored, empty key never authorized, loopback ListenAndServe and
shutdown, waitListening and sleepCtx failures
- TestFlowIDNames: default masked id variables
- TestEngineWire: API key and Accept on every request, create on 404 with
the schema or auto fields, 409 as success, JSONL import with
success:false and unreadable lines as errors (message capped, no
document), 404-tolerant delete/flush with id escaping, SearchIDs
parameters and id parsing, typed errors without bodies, transport
errors without the URL, timeout
- TestEngineConfig: search.typesense.* parsing and the registered engine
(coverage 95.6%)
- beachcomber and lighthouse released their savepoint whenever the inner
function reported no error; a Gate that counts a failed read as off,
or a channel function or delete snapshot that swallows one, left the
caller's Postgres transaction aborted (25P02) and failed the write
- a failed RELEASE now rolls back to the savepoint, as the READMEs promise
- beachcomber gets its testcontainers harness and sync tests
(TestSyncGates, TestSyncAfterCommit, TestSyncDeleteAndSoftDelete,
TestSyncFailuresNonFatal, TestServiceSetup); lighthouse gets
TestBroadcastSwallowedReadFailure
- lighthouse:after_create/update/delete also declare
Before(gorm:commit_or_rollback_transaction); an After-only anchor put
them past GORM's own commit, so a plain gdb.Create enqueued its
broadcast job after the commit on the pool (deferred from 11-05)
- lighthouse gets the testcontainers Postgres harness and TestBroadcastTx
(commit publishes once, rollback nothing, single-statement write
enqueues on its own transaction, failed write enqueues nothing)
- lagoon.Transaction, the lagoon:after_commit flush and the immediate
AfterCommit path pass a handle with an empty statement on the write's
connection (Session NewDB+Context, Clauses(), Session NewDB)
- a WithContext query through the handle no longer continues from the
written model's statement (deferred from 11-05)
- TestTransactionAfterCommit/callback_handle_has_a_clean_statement covers
the implicit, plain-transaction and lagoon.Transaction paths
- centrifugo.Client.Info probes the info API method; an error body fails
- websockets:health ports CentrifugoHealthCheck: exits 1 without an API
key or when the probe fails, prints the Setting/Value table otherwise
- websockets:generate-vapid-keys prints a new P-256 pair, shows configured
keys only truncated, and --update persists them to overrides.yaml
- websockets:test-push reads subscriptions from an app-published
SubscriptionSource, refuses to send while push is disabled and sends
one encrypted push per subscription
- no command prints a configured private key or the Centrifugo API key
- flare and lighthouse READMEs document the CLI commands
Persist rewrote overrides.yaml with only this process's runtime values,
so saving one key (for example websockets:generate-vapid-keys --update)
dropped every key persisted earlier. It now starts from the saved file
and lets runtime values win.
- RFC 8291 aes128gcm encryption from crypto/ecdh, crypto/hkdf and AES-GCM,
matching the RFC 8291 Appendix A vector byte for byte
- RFC 8292 vapid t=<ES256 JWT>, k=<key> header (aud origin, exp +12h, sub)
- Pusher, Subscription, SendOptions, SubscriptionSource, Service and From
reading push.* (enabled, keys, subject, ttl, allowed_hosts)
- sends only to https endpoints on push.allowed_hosts, checked before
dialing, and never follows redirects; 404/410 map to ErrSubscriptionGone
- module README and root modules row
The recorded PHP 401 for a missing bearer (realtime token no-bearer
case) carries Laravel's default Cache-Control header; the Go guard's
401 omitted it, so the replay failed on header.Cache-Control.
- CentrifugoRecorder records publish/broadcast requests (method, path,
whether the API key matched, JSON body) and binds loopback only
- BroadcastGolden load/write, NormalizePublications (timestamps, actor,
captured ids only) and DiffPublications (structural, key order ignored)
- RecordBroadcasts runs a flow or one step against a loopback backend
- summer parity:broadcasts wraps it; README documents format and rules
- pin the sync callbacks before gorm:commit_or_rollback_transaction: an
After-only anchor is appended past the commit and lagoon's after-commit
flush, so single-statement writes never synced
- give the gate and the document builder a clean session: Session with NewDB
and a Context clones the write's statement, and a later WithContext queried
through the written model's table
- typesense.StatusError carries method, path and status, never the body
- README: sync semantics, the three gates, delete on soft delete, and the
SQL re-gate required of SearchIDs callers
- Searchable, Engine, Gate and an init-time engine registry with the null engine
- GORM callbacks installed through lagoon.OnDatabase register an after-commit
sync that reloads the row and upserts or deletes its document
- Gates run before any request: engine configured, database published, app Gate
- hand-rolled net/http Typesense engine following the Scout wire contract
- module README and root modules row
- Broadcastable contract and Bind[T] bindings; event {action}.{alias},
default {model, actor, timestamp, ttl} payload, delete snapshot taken
before the row goes
- GORM callbacks installed via lagoon.OnDatabase enqueue a summer.broadcast
job on the write's *sql.Tx inside a savepoint; failures are logged and
never abort the write; zero-key batch writes are skipped
- WithoutBroadcasting[T] (ctx-scoped, per type) and Service.Emit for one
summary event; the one-attempt job namespaces channels and publishes or
broadcasts; the payload travels as a JSON string so JSONB keeps its order
- no jobs for the null driver or Centrifugo without an API key
- lighthouse: Service/From with realtime.driver selection, RegisterDriver
registry, null/log/memory drivers, Route/Surface/Mount, users and actors
- centrifugo: HTTP API client (apikey header, 2xx success, no request
without a key), five-generator HS256 TokenIssuer, TokenHandler with the
WinterCMS 401/503 bodies
- module README and root modules table row
- schedule:run runs a worker on the scheduled queue with every plugin's periodic jobs
- schedule:run --once runs entries due in the current app.timezone minute without River,
warns and skips unregistered commands, and returns the first command error
- summer schedule:run delegate forwards --once
- tests for --once minute matching, forged-entry skipping (T-11-09) and ByPeriod dedupe
- pact.HasSchedule with ScheduledCommand and Daily/DailyAt/Every cadences (no River import)
- bonfire.Call, Catalog and ErrUnknownCommand for in-process command runs
- conga Daily/Every wall-clock schedules in app.timezone, periodic jobs on every worker,
scheduled queue (MaxAttempts 1, unique by args within the cadence period)
- scheduled worker runs only entries matching the compiled table; unregistered
commands are skipped with a Warn log
- generated app main publishes bonfire.NewCatalog(commands); hello main regenerated
- OnDatabase runs a callback once the database is published (now, or when
lagoon.Publish runs), so GORM callbacks registered at Boot also install
under serve, where Boot runs before the database is opened
- Transaction runs AfterCommit callbacks in order after a successful commit;
nested calls are savepoints whose callbacks drop with them
- the lagoon:after_commit GORM callback flushes single-statement AfterCommit
work after GORM's own commit; outside a transaction it runs immediately
- Manager gains the apparatus JobManager surface: StartJob, UpdateJobState,
UpdateMetadata, FailJob, CancelJob (is_canceled + STOPPED + River JobCancel),
StopJob (STOPPED only), CheckIfCanceled and GetMetadata, all raw column
writes so updated_at is untouched
- serve starts the in-process worker unless queue.work_in_serve is false and
stops it on shutdown; an app without jobs gets an idle worker
- queue:work runs a foreground worker with repeatable --queue filters;
queue:clear deletes available, scheduled and retryable jobs of one queue
- the generated main appends conga.RuntimeCommands; summer delegates
queue:work and queue:clear; make:job scaffolds a conga.Job
The scaffolder's ensureToolchain keeps 'toolchain go1.27.0' in every
module; the River tidy in the previous commit removed it from the example
app and its plugins.