Repository navigation
Conversation
* fix: generate strict X.509 chains for Hermes clients * test: declare secure TLS floor in strict client probe
ak5
left a comment
There was a problem hiding this comment.
Release review: c82eb63 is tree-identical to all-green reviewed #71 and is the only dev change since main d17a865. Reviewed complete generated CA/leaf profile, real strict Python 3.13.5/HTTPX 0.28.1 regression, certificate-role/identifier assertions, unchanged upstream trust/policy/mediation, and CA regeneration/public-trust handoff. Final mise run check and documentation parity pass. No unresolved source-review findings; implementing-agent review, not independent audit. Fresh release checks must pass before an ancestry-preserving merge commit. No Infra edit/deploy or issue creation; actual registry digest and isolated released-image proof will follow trusted main CI/publication.
|
Certificate compatibility release completed through reviewed dev PR #71 and merge-commit release #72. Main: Immutable gateway pin, verified from GHCR: The OCI index contains a linux/amd64 manifest and attestation manifest. Trusted main CI and publication succeeded. Evidence:
The new image itself generated the synthetic CA, only its public certificate entered the client, the client had only an internal Docker network, and the production gateway verified real upstream TLS. No real credentials, verification bypass or Infra edits/deployment were used. Disposable Docker resources were removed. Infra handoff: regenerate any installed CA missing required extensions with this corrected binary and distribute its matching public trust before rerunning acceptance. The image cannot rewrite an installed CA. Keep the convergence guard and egress isolation in place; retain installed image/layout/config/CA-key-trust bundles for rollback. No live cutover or GitHub issue was created. Infra draft #257 was only referenced; all work occurred in Charon. |
Release
Included changes
c82eb635d7b39f2b5513ab3e0263b1aba199e22e.mise run checkand Linux CI, certificate-extension/role assertions, and Infra CA regeneration/trust guidance.Release checks
main, headdev; normal staged release path.mise run checkpasses. Fresh release CI must pass on this source.git merge-base --is-ancestor c82eb635d7b39f2b5513ab3e0263b1aba199e22e origin/mainsucceeds. Main merge commitcbec5aa4a65e3de2960afce627cf8c6cf083bd6ehas two parents and matches the reviewed source tree.Risk and rollback