Commit graph

5 commits

Author SHA1 Message Date
0480b2d8e8 wip(daily-reports): follow-up local updates for Phase 0 freeze (approvals/procurement screens, programme, pdf recording)
Some checks failed
sms / gates (push) Has been cancelled
sms / robius-sms (push) Has been cancelled
cad / cad-truth-gates (push) Has been cancelled
cad / cad-core-checks (push) Has been cancelled
cad / cad-consumers (push) Has been cancelled
sms / android (push) Has been cancelled
sms / nigig-sms (push) Has been cancelled
doc-engine / engine (push) Has been cancelled
doc-engine / coverage (push) Has been cancelled
doc-engine / consumer (push) Has been cancelled
nigig-site / Cargo check-all-targets (push) Has been cancelled
nigig-site / Cargo clippy-site-owned (push) Has been cancelled
nigig-site / Cargo contained-media-export-fixtures (push) Has been cancelled
nigig-site / Cargo containment-storage-crypto (push) Has been cancelled
nigig-site / Cargo core-clippy (push) Has been cancelled
nigig-site / Cargo core-contracts (push) Has been cancelled
nigig-site / Cargo integration-non-live (push) Has been cancelled
nigig-site / Cargo production-dependency-containment (push) Has been cancelled
nigig-site / Cargo site02-crypto (push) Has been cancelled
nigig-site / Cargo site02-repository (push) Has been cancelled
nigig-site / Cargo site02-store (push) Has been cancelled
nigig-site / Cargo unit (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (macos-latest) (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (ubuntu-latest) (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (windows-latest) (push) Has been cancelled
nigig-site / Real server interoperability (explicitly skipped until enabled) (push) Has been cancelled
nigig-site / Security and supply-chain baseline (push) Has been cancelled
repo hygiene / hygiene (push) Has been cancelled
spreadsheet / ui-controller-coverage (push) Has been cancelled
nigig-site / Release capability gate (push) Has been cancelled
2026-09-27 17:02:54 +03:00
88d46600e1 wip(daily-reports): preserve local site/report/worker, ocr and lite-common updates for Phase 0 freeze 2026-09-27 16:25:50 +03:00
Arena Agent
3d91404ab6 build(nimanyatta): make the protocol crate a workspace member and pin its wire format
Some checks failed
nigig-site / Cargo clippy-site-owned (push) Has been cancelled
nigig-site / Cargo contained-media-export-fixtures (push) Has been cancelled
nigig-site / Cargo containment-storage-crypto (push) Has been cancelled
nigig-site / Cargo core-clippy (push) Has been cancelled
nigig-site / Cargo core-contracts (push) Has been cancelled
nigig-site / Cargo integration-non-live (push) Has been cancelled
nigig-site / Cargo production-dependency-containment (push) Has been cancelled
nigig-site / Cargo site02-crypto (push) Has been cancelled
nigig-site / Cargo site02-repository (push) Has been cancelled
nigig-site / Cargo site02-store (push) Has been cancelled
nigig-site / Cargo unit (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (macos-latest) (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (ubuntu-latest) (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (windows-latest) (push) Has been cancelled
nigig-site / SITE-02 desktop runtime and normal shutdown (push) Has been cancelled
nigig-site / SITE-02 migration, recovery, and fault corpus (push) Has been cancelled
nigig-site / Media limits (explicitly skipped until enabled) (push) Has been cancelled
nigig-site / Real server interoperability (explicitly skipped until enabled) (push) Has been cancelled
nigig-site / Security and supply-chain baseline (push) Has been cancelled
nigig-site / Release capability gate (push) Has been cancelled
sms / gates (push) Has been cancelled
sms / robius-sms (push) Has been cancelled
sms / android (push) Has been cancelled
sms / nigig-sms (push) Has been cancelled
sms / supply-chain (push) Has been cancelled
spreadsheet / engine-coverage (push) Has been cancelled
spreadsheet / ui-controller-coverage (push) Has been cancelled
traffic / gates (push) Has been cancelled
traffic / nigig-traffic (push) Has been cancelled
traffic / supply-chain (push) Has been cancelled
First concrete step on SITE-12. Three of the four planned steps turned out to
be impossible from this repository, and that is now recorded with evidence
rather than assumed.

What this commit does:

1. `nimanyatta/crates/nimanyatta-protocol` is a workspace member. It has no
   path dependencies (only optional serde + postcard), so unlike its parent
   package it can be compiled and tested here. `cargo metadata` still exits 0.

2. Its 8 pre-existing tests HAD NEVER COMPILED. The crate is `#![no_std]`, so
   `use super::*` brings in alloc's `String` but not the `ToString` trait, and
   the test module calls `.to_string()` — 6 E0599 errors. Fixed with one
   import; 8 tests now run and pass.

3. Added 5 wire-format characterization tests pinning the exact postcard
   bytes. postcard encodes enum variants as POSITIONAL INDICES, so reordering
   or inserting a variant silently changes every frame on the wire while the
   code still compiles and every round-trip test still passes. Verified by
   mutation: swapping AuthMethod::Password/Token changes the login frame from
   [0, 0, 5, ...] to [0, 1, 5, ...] and the pinned test fails.

4. Corrected a false doc comment. `sync_protocol.rs` claimed "one canonical
   encoding is used by app, server, and tests". It is not. Read from source:
   the server's POST /sync uses Json<SyncRequest>/Json<SyncResponse> whose
   types come from `nigig_common` (not from nimanyatta-protocol, which is a
   WebSocket chat protocol the server uses only for `is_guest`), and
   sync_protocol.rs is a third, separate offline-envelope codec.

What could not be done, with evidence:

- `nimanyatta` itself cannot be a workspace member: adding it makes
  `cargo metadata` fail with exit 101 "failed to load manifest for workspace
  member", because Cargo resolves path dependencies even for features that are
  not enabled, and ../nigig-lite/crates/common and ../xitca-web/web do not
  exist. Verified by adding it, observing 101, and removing it.
- Neither sibling repo can be vendored or submoduled: `git ls-remote` on
  gitdab.com/andodeki/nigig-lite and /xitca-web both return HTTP 500,
  identical to a deliberately fake repo name, while /nigig-org resolves
  normally.
- Repointing xitca-web to crates.io would not unblock the build on its own:
  `nigig_common` is imported by 38 server files (~40 items) and has no
  published equivalent. Guessing RoomInfo/RoomEvent field definitions would
  produce a codec that silently mismatches the real server, which is worse
  than the current explicit "three incompatible protocols" state.

rustfmt was applied to the protocol crate (120 insertions / 29 deletions, all
whitespace: it had never been formatted, including a stray indent on
ServerToClientMsg::login_success). No semantic change.

Verified: cargo test -p nimanyatta-protocol = 13 passed; cargo test -p
nigig-site-core = 228 passed / 1 ignored; clippy -D warnings clean on both;
cargo fmt --check clean; cargo check -p nigig-site --locked clean; cargo
metadata exit 0; all 6 workflow python gates pass.
2026-09-26 11:53:58 +00:00
Arena Agent
99bb979850 feat(nigig-site-core): implement SITE-18/19/26/27/29/30 domain layers
Some checks failed
nigig-site / Owned paths and honest test contracts (push) Has been cancelled
nigig-site / Cargo check-all-targets (push) Has been cancelled
nigig-site / Cargo clippy-site-owned (push) Has been cancelled
nigig-site / Cargo contained-media-export-fixtures (push) Has been cancelled
nigig-site / Cargo containment-storage-crypto (push) Has been cancelled
nigig-site / Cargo core-clippy (push) Has been cancelled
nigig-site / Cargo core-contracts (push) Has been cancelled
nigig-site / Cargo integration-non-live (push) Has been cancelled
nigig-site / Cargo production-dependency-containment (push) Has been cancelled
nigig-site / Cargo site02-crypto (push) Has been cancelled
nigig-site / Cargo site02-repository (push) Has been cancelled
nigig-site / Cargo site02-store (push) Has been cancelled
nigig-site / Cargo unit (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (macos-latest) (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (ubuntu-latest) (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (windows-latest) (push) Has been cancelled
nigig-site / SITE-02 desktop runtime and normal shutdown (push) Has been cancelled
nigig-site / SITE-02 migration, recovery, and fault corpus (push) Has been cancelled
nigig-site / Media limits (explicitly skipped until enabled) (push) Has been cancelled
nigig-site / Real server interoperability (explicitly skipped until enabled) (push) Has been cancelled
nigig-site / Security and supply-chain baseline (push) Has been cancelled
nigig-site / Release capability gate (push) Has been cancelled
repo hygiene / hygiene (push) Has been cancelled
Six new UI-free modules in nigig-site-core, 53 tests added (175 -> 228):

- procurement_flow.rs (SITE-26): requisition -> LPO -> delivery, two-approver
  gate (three above KES 500,000), budget commitment at approval, Delivered
  reachable only via verify_delivery with evidence assets, supplier ratings
  that are None until evidence exists. Integer cents with i128 saturating
  multiplication; no f64 money anywhere.
- meeting_flow.rs (SITE-27): RSVP, per-participant recording consent where a
  refusal cannot be flipped to a grant, transcript refused until a recording
  has started, action-item tracker.
- dashboards.rs (SITE-29): integer chart series, per-site snapshots, worst-
  first cross-site comparison, and a client digest built from an explicit
  field allow-list that fails closed on a smuggled key.
- documents.rs (SITE-30): revision states where approval supersedes its
  predecessor and withdrawal clears `current` in the same operation, so a
  withdrawn drawing can never be served as current.
- notification_rules.rs (SITE-18): delivery modes, midnight-crossing quiet
  hours in the site zone, safety-critical subjects that cannot be muted and
  bypass suppression, bodies generated from a closed vocabulary so no PII can
  enter one.
- multi_site.rs (SITE-19): per-site roles, a switcher that refuses unknown or
  unregistered sites rather than falling back, sessions that authorize only
  their own site, and an offline queue that drains per site.

Two API gaps fixed while wiring these up:
- report_pack::Report::canonical_text is now public; it was private, so no
  caller outside report_pack could produce a valid approval signature.
- hse::HseStats now derives Serialize/Deserialize; FR-1.7 embeds it in the
  published monthly report but it could not be serialized.

EXECUTION_PLAN.md: §1a rows for these six tranches updated to their real
state, the honest completion statement recomputed (28/33 with tested domain
contracts, 4 externally blocked, 1 not started), and §2.1 corrected - it
still repeated the false "nimanyatta is only a README stub" claim that §1a
was already corrected for.

Verified: cargo test -p nigig-site-core = 228 passed / 0 failed / 1 ignored;
cargo clippy --all-targets --no-deps -D warnings clean; cargo fmt --check
clean; cargo check -p nigig-site clean; all 6 workflow python gates pass.
cargo test -p nigig-site remains unrunnable here (SIGKILL compiling
makepad-widgets on 2 vCPU / 1.9 GiB). CI workflow work deferred by request.
2026-09-26 11:32:43 +00:00
0819e97074 feat(nigig-site): compile and test the hardening core; add SITE-20..28 domain
Some checks failed
email / gates (push) Has been cancelled
nigig-site / Security and supply-chain baseline (push) Has been cancelled
nigig-site / Release capability gate (push) Has been cancelled
repo hygiene / hygiene (push) Has been cancelled
cad / cad-truth-gates (push) Has been cancelled
cad / cad-core-checks (push) Has been cancelled
cad / cad-consumers (push) Has been cancelled
doc-engine / engine (push) Has been cancelled
doc-engine / coverage (push) Has been cancelled
doc-engine / consumer (push) Has been cancelled
email / email-domain (push) Has been cancelled
email / nigig-email (push) Has been cancelled
email / supply-chain (push) Has been cancelled
nigig-build (CAD) / supply-chain (push) Has been cancelled
nigig-build (CAD) / cad-module (push) Has been cancelled
nigig-build (CAD) / full-crate-check (push) Has been cancelled
nigig-build (CAD) / cad-engine-coverage (push) Has been cancelled
nigig-build (CAD) / doc-workspace-coverage (push) Has been cancelled
nigig-build (CAD) / cad-widget-coverage (push) Has been cancelled
nigig-map / test (push) Has been cancelled
sms / gates (push) Has been cancelled
sms / robius-sms (push) Has been cancelled
sms / android (push) Has been cancelled
sms / nigig-sms (push) Has been cancelled
sms / supply-chain (push) Has been cancelled
spreadsheet / engine-coverage (push) Has been cancelled
spreadsheet / ui-controller-coverage (push) Has been cancelled
traffic / gates (push) Has been cancelled
traffic / nigig-traffic (push) Has been cancelled
traffic / supply-chain (push) Has been cancelled
Thirteen hardening modules (3,079 lines) sat in nigig-site/src/ declared in no
mod statement. They had never been compiled or tested: cargo check never saw
them, and the plan's "implemented in the worktree and pending verification"
status was unverifiable by construction.

Extract the UI-free core into crates/apps/nigig-site-core (scope 5's "Rust core
crate ... testable; safe"; plan 6's target architecture). nigig-site depends on
it and re-exports it, so there is one copy of each module source: the app and
the core's unit tests compile the same files. The core has no Makepad
dependency, so its contracts run on a memory-limited runner.

Compiling that code for the first time found four real defects, all fixed:
- Role/Capability lacked Ord, so every BTreeSet of them failed to compile
  (auth.rs)
- CaptureResult::empty never initialised site_id from its site parameter
  (ocr_policy.rs)
- negotiate_version(2, 5) agreed on a protocol the peer never offered, which is
  the silent downgrade the function exists to prevent (sync_protocol.rs)
- an absurd frame size returned Overflow instead of the actionable budget
  breach (media_bounds.rs)

New feature-tranche domain modules, each with unit tests:
- organisation.rs   SITE-20 invites, per-site roles, the 4.2 matrix as testable
                    data, site registry with geofence, settings
- report_pack.rs    SITE-21 report numbering, entry status, signatures binding
                    actor/device/timestamp/document hash, lock and versioning,
                    multi-site compilation, monthly packs
- site_diary.rs     SITE-22 weather with provenance, plant, deliveries, delay
                    log where a weather delay needs supporting rainfall,
                    visitors, manpower by trade
- workforce.rs      SITE-23 consent-gated registration, tag-only blocklist,
                    attendance with overtime, QR badges, payroll CSV that never
                    emits identity, offboarding tombstones
- programme.rs      SITE-25 dependencies with cycle detection and rollback,
                    topological order, critical path, frozen baselines with
                    slippage, checklists gating approval, snags, RFIs,
                    variations needing two distinct approvers
- hse.rs            SITE-28 append-only incidents, closure requires corrective
                    action, toolbox talks, inspections, monthly statistics

workflows.rs gains the FR-1.14 Locked state; commands.rs gains a bounded
non-empty text validator shared by the new modules.

CI: the SITE-02 crypto/repository/store lanes pointed at -p nigig-site, where
those suites no longer live; left alone they would have compiled nothing and
reported a vacuous green. Repointed at the core, and added core-contracts and
core-clippy lanes with a ">=100 tests collected" check so a lane cannot pass
vacuously. All six existing Python contract gates still pass.

Auto-purge of worker ID data refuses to run until the scope 18 retention
question is answered rather than inventing a window.

Verified 2026-09-26: cargo test -p nigig-site-core --locked = 175 passed,
0 failed, 1 ignored (needs a live Secret Service session); cargo clippy -p
nigig-site-core --all-targets --no-deps -- -D warnings clean; cargo check -p
nigig-site clean. cargo test -p nigig-site is still killed by SIGKILL compiling
makepad-widgets on a 2 GB host, as recorded in plan 2.1.

EXECUTION_PLAN.md gains a per-tranche status ledger (1a) that states plainly
which tranches are done, domain-only, externally blocked, or not started, and
records that this branch and main diverged at b3a9005 with SITE-03 published
only on main.
2026-09-26 10:50:33 +00:00