Commit graph

7 commits

Author SHA1 Message Date
arena-agent
f9c12359bf nimanyatta: drop vendored xitca-web, use crates.io sources
Some checks failed
repo hygiene / hygiene (push) Has been cancelled
Delete the vendored xitca-web framework checkout at repo root and
repoint all consumers at the published crates:

- nimanyatta/Cargo.toml: drop path overrides on xitca-web (deps +
  dev-deps), remove the xitca-client dep (never published on
  crates.io) from the manifest and the load/b_server features, and
  remove the [patch.crates-io] section that forced every xitca-*
  crate onto the vendored checkout.
- nigig-lite/crates/common: xitca-web path dep -> version 0.8 from
  crates.io (vendored snapshot was 0.8.1, identical).
- Test suites (shared_test_client, security_suite, enhanced_security,
  enhanced_security_tests) and kra-etims-sdk: migrate xitca-client
  HTTP usage to reqwest from crates.io, preserving request
  semantics (header-override order, error mapping).

Verified in a fresh clone on the pinned toolchain (1.97.1):
nigig-common checks, security/enhanced suites check, and the
session/fast/regression harness binaries build.
2026-09-26 17:16:51 +00:00
13ae5017af nimanyatta: align the WS wire format with nimanyatta-protocol (postcard)
Some checks failed
repo hygiene / hygiene (push) Has been cancelled
The remote's protocol-crate commits pinned the client wire format, and the
pre-existing chat_load_tester_consistency suite already decoded
ServerToClientMsg with postcard — but the reconstructed nigig-common was
encoding with serde_json. Switch to_bytes/from_bytes (both message enums)
to postcard to match, and rebuild decode_all on postcard::take_from_bytes
so a fragmented frame re-buffers and bytes trailing a complete message are
preserved instead of dropped.

AuthMethod (13 variants) is shape- and order-aligned with the client
library. The remaining server/client shape divergences (missing
reaction/upload/history variants, LoginSuccess/MessageDeleted/MessageContent
field differences) are pre-existing in the original design — the gateway
itself destructures MessageContent::Text { body } while the client emits
Text { text } — and are now documented with a remediation path in
KNOWN_ISSUES ("WS wire parity" section).

nigig-common: 21/21 tests green with the postcard round-trips.
2026-09-26 16:31:04 +00:00
dfffe9e6e6 nimanyatta: Phase 8 — reconstruct nigig-common, repair load suites, close REST coverage gaps
Foundation:
- Vendor xitca-web (upstream commit 7fa07dae, see xitca-web/VENDORED.md);
  pin all six xitca crates via [patch.crates-io] in nimanyatta/Cargo.toml
- Reconstruct the lost nigig-common crate as nigig-lite/crates/common
  (21 unit tests, clippy-clean), recovered from the wire contract in
  crates/nimanyatta-protocol plus the server's own call sites

REST API:
- Register the four unwired room routes that were documented but never
  reachable: {room_id}/invite POST, /typing PUT, /read_receipt POST,
  /redact/{event_id} POST (root cause of the rooms.rs 50% coverage ceiling)
- REST read receipts now return 501 Not Implemented (documented) instead of
  a 500 — receipts are recorded via the WebSocket MarkRead path
- README API tables corrected to the real paths/methods; env table expanded
  (PROXY_TRUSTED_IPS, WS_ALLOWED_ORIGINS, CORS_ALLOWED_ORIGINS, ENABLE_OTEL,
  token durations) plus proxy-trust and WS-origin explainer sections

Security & correctness:
- WS_ALLOWED_ORIGINS is now fail-closed in production: an empty list is a
  configuration error at startup ('*' remains an explicit opt-out)
- Fix the OTP attempt counter: the BEGIN/IF SurrealQL block was a parse
  error, so every wrong OTP failed the query and the fail-closed handler
  masked it as a first-try 429 OTP_MAX_ATTEMPTS_EXCEEDED. Now a single
  atomic conditional UPDATE ... WHERE attempts < $max, the handler logs the
  underlying error before failing closed, and a regression test covers
  store -> fetch -> increment -> persist
- Gateway KNOWN_ISSUES #1/#2/#5 fixed (centralised idempotent
  cleanup_connection on all close paths; LoggedOut sent before
  remove_session); #3 verified already enforced via session eviction
- DeliveryReceipt receipts now carry by_user: Option<String> per the
  protocol crate (was Option<UserId> at the call sites)

Test suites:
- Repair every load-test binary: added mains for the three bins whose bodies
  were #[tokio::test] functions (test items are cfg(test)-gated and vanish
  from normal builds), fixed protocol-shape drift in the rest —
  cargo check --features load --bins is clean
- New route coverage tests: invite/join/409-reinvite/404-unknown, typing
  (member + 403 non-member), redact (happy path/404/403), read_receipt 501,
  custom-role denial, non-member send 403, pagination edges (limit,
  direction, invalid from-token), sync filter paths (room filter,
  timeline_limit, invalid since-token, empty filter semantics)
- cargo test --features b_server: 51 passed / 0 failed

Docs:
- PLAN.md Phase 8 section + post-Phase-8 roadmap (per-site channels, pinned
  document library, document read receipts, mentions/search/broadcast/
  moderation/retention, offline queue — documented as open scope gaps)
- KNOWN_ISSUES.md statuses updated with the fixes above
2026-09-26 16:24:41 +00:00
Arena Agent
ac40ac923f fix(nigig-site): read the timeline field the protocol crate actually emits
Some checks failed
nigig-site / Cargo contained-media-export-fixtures (push) Has been cancelled
nigig-site / Cargo containment-storage-crypto (push) Has been cancelled
nigig-site / Cargo core-clippy (push) Has been cancelled
nigig-site / Cargo core-contracts (push) Has been cancelled
nigig-site / Cargo integration-non-live (push) Has been cancelled
nigig-site / Cargo production-dependency-containment (push) Has been cancelled
nigig-site / Cargo site02-crypto (push) Has been cancelled
nigig-site / Cargo site02-repository (push) Has been cancelled
nigig-site / Cargo site02-store (push) Has been cancelled
nigig-site / Cargo unit (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (macos-latest) (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (ubuntu-latest) (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (windows-latest) (push) Has been cancelled
nigig-site / SITE-02 desktop runtime and normal shutdown (push) Has been cancelled
nigig-site / SITE-02 migration, recovery, and fault corpus (push) Has been cancelled
nigig-site / Media limits (explicitly skipped until enabled) (push) Has been cancelled
nigig-site / Real server interoperability (explicitly skipped until enabled) (push) Has been cancelled
nigig-site / Security and supply-chain baseline (push) Has been cancelled
nigig-site / Release capability gate (push) Has been cancelled
repo hygiene / hygiene (push) Has been cancelled
sms / gates (push) Has been cancelled
sms / robius-sms (push) Has been cancelled
sms / android (push) Has been cancelled
sms / nigig-sms (push) Has been cancelled
sms / supply-chain (push) Has been cancelled
spreadsheet / engine-coverage (push) Has been cancelled
spreadsheet / ui-controller-coverage (push) Has been cancelled
traffic / gates (push) Has been cancelled
traffic / nigig-traffic (push) Has been cancelled
traffic / supply-chain (push) Has been cancelled
Pinning nimanyatta-protocol's JSON shape exposed a live bug in the E2E
fixture, and answering "is nigig_common in this repo?" narrowed the SITE-12
gap.

The bug: MessageContent::Text serializes as {"Text":{"text":"..."}}.
tests/support/nimanyatta_fixture.rs::event_text only looked for
content.Text.body — a field that type never emits, and which
serde_json::from_str::<MessageContent> actively rejects. Against a real
server every message would have been skipped, sync_timelines would return an
empty vec, and live_round_trip would still have passed. A silently vacuous
interop test is exactly the failure mode SITE-00 exists to prevent.

- event_text now tries `text` first and keeps `body` as a fallback.
- New test in nimanyatta-protocol pins the serialized shape and asserts the
  fixture's old guess does not decode.
- New cross-check test in the fixture builds its payload from the real
  MessageContent type, so parser and protocol cannot diverge silently again.

What was verified and what was not:
- The protocol-crate tests run: 14 passed.
- The fixture cross-check test COULD NOT be compiled or run here. nigig-site's
  test target pulls in makepad-widgets, which is SIGKILLed on this 2 vCPU /
  1.9 GiB host. The parser change was instead verified by extracting
  event_text/sync_timelines verbatim from the fixture into a standalone
  harness: {"Text":{"text":"slab done"}} -> Some(("alice","slab done")),
  the legacy {"Text":{"body":...}} shape still falls back, and a
  non-message event returns None. That harness is not part of the shipped
  tree; the shipped cross-check test is unverified until CI runs it.

Also recorded in EXECUTION_PLAN.md SITE-12: nigig_common is confirmed absent
from this repository (no package by that name; RoomEvent/RoomInfo/
JoinedRoomSync/SyncFilter/PaginationDirection defined nowhere here; nigig-core
is an email/IMAP crate), and it re-exports nimanyatta-protocol via a
`protocol` module — the server writes
nigig_common::protocol::{ClientToServerMsg, ServerToClientMsg}. So of the 75
items the server imports from nigig_common, 9 are the crate already pinned
here; the remaining 66 are the HTTP DTO layer, ~11 of which /sync needs.

Verified: cargo test -p nimanyatta-protocol = 14 passed; cargo test -p
nigig-site-core = 228 passed / 1 ignored; clippy -D warnings clean;
cargo fmt --check clean; cargo metadata exit 0; all 6 workflow python gates.
2026-09-26 12:37:08 +00:00
Arena Agent
3d91404ab6 build(nimanyatta): make the protocol crate a workspace member and pin its wire format
Some checks failed
nigig-site / Cargo clippy-site-owned (push) Has been cancelled
nigig-site / Cargo contained-media-export-fixtures (push) Has been cancelled
nigig-site / Cargo containment-storage-crypto (push) Has been cancelled
nigig-site / Cargo core-clippy (push) Has been cancelled
nigig-site / Cargo core-contracts (push) Has been cancelled
nigig-site / Cargo integration-non-live (push) Has been cancelled
nigig-site / Cargo production-dependency-containment (push) Has been cancelled
nigig-site / Cargo site02-crypto (push) Has been cancelled
nigig-site / Cargo site02-repository (push) Has been cancelled
nigig-site / Cargo site02-store (push) Has been cancelled
nigig-site / Cargo unit (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (macos-latest) (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (ubuntu-latest) (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (windows-latest) (push) Has been cancelled
nigig-site / SITE-02 desktop runtime and normal shutdown (push) Has been cancelled
nigig-site / SITE-02 migration, recovery, and fault corpus (push) Has been cancelled
nigig-site / Media limits (explicitly skipped until enabled) (push) Has been cancelled
nigig-site / Real server interoperability (explicitly skipped until enabled) (push) Has been cancelled
nigig-site / Security and supply-chain baseline (push) Has been cancelled
nigig-site / Release capability gate (push) Has been cancelled
sms / gates (push) Has been cancelled
sms / robius-sms (push) Has been cancelled
sms / android (push) Has been cancelled
sms / nigig-sms (push) Has been cancelled
sms / supply-chain (push) Has been cancelled
spreadsheet / engine-coverage (push) Has been cancelled
spreadsheet / ui-controller-coverage (push) Has been cancelled
traffic / gates (push) Has been cancelled
traffic / nigig-traffic (push) Has been cancelled
traffic / supply-chain (push) Has been cancelled
First concrete step on SITE-12. Three of the four planned steps turned out to
be impossible from this repository, and that is now recorded with evidence
rather than assumed.

What this commit does:

1. `nimanyatta/crates/nimanyatta-protocol` is a workspace member. It has no
   path dependencies (only optional serde + postcard), so unlike its parent
   package it can be compiled and tested here. `cargo metadata` still exits 0.

2. Its 8 pre-existing tests HAD NEVER COMPILED. The crate is `#![no_std]`, so
   `use super::*` brings in alloc's `String` but not the `ToString` trait, and
   the test module calls `.to_string()` — 6 E0599 errors. Fixed with one
   import; 8 tests now run and pass.

3. Added 5 wire-format characterization tests pinning the exact postcard
   bytes. postcard encodes enum variants as POSITIONAL INDICES, so reordering
   or inserting a variant silently changes every frame on the wire while the
   code still compiles and every round-trip test still passes. Verified by
   mutation: swapping AuthMethod::Password/Token changes the login frame from
   [0, 0, 5, ...] to [0, 1, 5, ...] and the pinned test fails.

4. Corrected a false doc comment. `sync_protocol.rs` claimed "one canonical
   encoding is used by app, server, and tests". It is not. Read from source:
   the server's POST /sync uses Json<SyncRequest>/Json<SyncResponse> whose
   types come from `nigig_common` (not from nimanyatta-protocol, which is a
   WebSocket chat protocol the server uses only for `is_guest`), and
   sync_protocol.rs is a third, separate offline-envelope codec.

What could not be done, with evidence:

- `nimanyatta` itself cannot be a workspace member: adding it makes
  `cargo metadata` fail with exit 101 "failed to load manifest for workspace
  member", because Cargo resolves path dependencies even for features that are
  not enabled, and ../nigig-lite/crates/common and ../xitca-web/web do not
  exist. Verified by adding it, observing 101, and removing it.
- Neither sibling repo can be vendored or submoduled: `git ls-remote` on
  gitdab.com/andodeki/nigig-lite and /xitca-web both return HTTP 500,
  identical to a deliberately fake repo name, while /nigig-org resolves
  normally.
- Repointing xitca-web to crates.io would not unblock the build on its own:
  `nigig_common` is imported by 38 server files (~40 items) and has no
  published equivalent. Guessing RoomInfo/RoomEvent field definitions would
  produce a codec that silently mismatches the real server, which is worse
  than the current explicit "three incompatible protocols" state.

rustfmt was applied to the protocol crate (120 insertions / 29 deletions, all
whitespace: it had never been formatted, including a stray indent on
ServerToClientMsg::login_success). No semantic change.

Verified: cargo test -p nimanyatta-protocol = 13 passed; cargo test -p
nigig-site-core = 228 passed / 1 ignored; clippy -D warnings clean on both;
cargo fmt --check clean; cargo check -p nigig-site --locked clean; cargo
metadata exit 0; all 6 workflow python gates pass.
2026-09-26 11:53:58 +00:00
fd8b0632ca Include nimanyatta as normal tree (not embedded git)
Some checks failed
repo hygiene / hygiene (push) Has been cancelled
2026-09-26 09:29:36 +03:00
cd802a9cab Initial project: app scope + Makepad skeleton
Some checks failed
repo hygiene / hygiene (push) Has been cancelled
2026-09-26 09:18:27 +03:00