Skip to content

test(coven): pin the daemon canary to v0.4.8 and require revision digests - #339

Merged
BunsDev merged 2 commits into
mainfrom
test/80-daemon-canary-0.4.8
Oct 3, 2026
Merged

BunsDev merged 2 commits into
mainfrom
test/80-daemon-canary-0.4.8

Conversation

@BunsDev

@BunsDev BunsDev commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Refs #80, OpenCoven/coven#1054. This re-pins the Automations v1 daemon canary (#338) from @opencoven/cli@0.4.7 to the published 0.4.8. Now that the pinned release has the fix, it also makes the definition digest a requirement.

Why

#338 found that v0.4.7's lifecycle events, occurrences, runs and receipts published a digest of the legacy routine projection rather than the definition document's integrity. Coven v0.4.8 fixes that (OpenCoven/coven#1200). Until now the canary only reported the digest; now it fails closed if the behaviour regresses.

Changes

  • conformance/automations-v1-daemon/: @opencoven/cli 0.4.8 and a regenerated npm lockfile covering cli, cli-macos, cli-macos-x64, cli-linux-x64 and cli-windows, at the sha512 integrity npm serves.

  • .github/workflows/ci.yml: the step is now "Drive the released Coven v0.4.8 daemon through the SDK" with --expect-version 0.4.8. The pin test keeps the lock, package.json and the workflow in step.

  • scripts/verify-automations-v1-daemon.mjs: revise's stored integrity must now equal computeDefinitionDigest(), as create's already did. Each of the five lifecycle events must carry exactly its revision's definition integrity:

    • revisions 1 and 2: the integrity create and revise returned;
    • revisions 3–5 (activated, paused, disabled): the revised document regenerated at that revision and lifecycle state, which is how Coven's stored view regenerates it.

    Revisions 2 and 4 share a body, so a digest that ignored the revision could not match both. A missing or unrelated digest on any event fails. The summary still prints eventDefinitionDigest=matches-definition-integrity. That is now a requirement, so the scenario result no longer carries the field.

  • tests/automations-v1-daemon-canary.spec.ts: the in-memory daemon now publishes each revision's document digest. Four new deviations must fail closed:

    • events that publish a routine digest, as v0.4.7 did;
    • a paused event that repeats revision 2's digest;
    • an activation event with no digest;
    • a disable event with an unrelated digest.

    The suite has 30 tests.

  • README.md, docs/ROADMAP.md: the pin moves to v0.4.8. The README records that v0.4.7 published the projection digest, and that v0.4.7 events, being immutable, keep it.

Verification

  • The CI step, run literally against the published 0.4.8: npm ci, then npm audit signatures ("2 packages have verified registry signatures", "2 packages have verified attestations"), then the canary:
    Automations v1 daemon verified: covenVersion=0.4.8 daemonStarts=2 commands=9 replays=2 rejections=2 events=5 subscribePages=2 definitionIntegrity=matches-sdk adoptionReplayAcrossRestart=passed checkpointResumeAcrossRestart=passed eventDefinitionDigest=matches-definition-integrity peerIdentity=harness-asserted
    
  • Against the published 0.4.8, all five events match their revision's computed integrity.
  • Against the published 0.4.7, the canary now fails as intended: events: definition.created publishes 59af64ce…, not the created definition's integrity cca43536….
  • Local checks:
    • pnpm typecheck and pnpm lint are clean.
    • The canary spec passes 30/30, and the canary and workflow-pin specs together passed 41/41 before the last review fix.
    • The full pnpm test run passed 3,150 tests and failed 2, with 2 skipped. The two failures were the shared-deadline timing test in coven-automations-platforms.spec.ts and the annotated-tag test in release-readiness.spec.ts, neither of which this change touches. Re-run on their own, both files pass, 153/153, which fits load-dependent timing.

The second commit addresses Copilot's finding. The first version checked only the created and revised digests, so a transition event with no digest or an unrelated one would have passed.

🤖 Generated with Claude Code

…ests

Re-pins the daemon canary to the published @opencoven/cli@0.4.8, at the
integrity npm serves, and makes the digest check a requirement now that
the pinned release has the fix (coven#1200). The created and revised
events must carry exactly the integrity create and revise returned,
revise's stored integrity must match computeDefinitionDigest(), and the
paused revisions 2 and 4, which share a body, must publish different
digests. Against v0.4.7 the canary now fails on the created event.

Refs #80, OpenCoven/coven#1054.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 3, 2026 12:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Missing or incorrect transition digests can still pass despite the reported integrity guarantee.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Updates the SDK’s released-daemon canary to Coven v0.4.8 and makes definition-digest checks mandatory.

Changes:

  • Updates CLI package pins, lockfile integrity values, and CI invocation.
  • Adds digest assertions and regression cases.
  • Documents the new checks and v0.4.7 compatibility limitation.
File Description
tests/​automations-v1-daemon-canary.spec.ts Models revision digests and adds failure cases.
scripts/​verify-automations-v1-daemon.mjs Enforces digest checks.
scripts/​verify-automations-v1-daemon.d.mts Removes the informational digest result field.
README.md Updates usage and digest guarantees.
docs/​ROADMAP.md Records the canary upgrade.
conformance/​automations-v1-daemon/​package.json Pins CLI v0.4.8.
conformance/​automations-v1-daemon/​package-lock.json Updates platform packages and integrity hashes.
.github/​workflows/​ci.yml Runs the v0.4.8 canary.
Files not reviewed (1)
  • conformance/automations-v1-daemon/package-lock.json: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread scripts/verify-automations-v1-daemon.mjs Outdated
Copilot noted the canary checked only the created and revised event
digests, and that two paused digests differed, while reporting that
every event matched. An activation, pause or disable event with no
digest or an unrelated one would have passed.

Compute the integrity of every revision the scenario commits. Revisions
1 and 2 are what create and revise returned. Revisions 3-5 are the
revised document regenerated at that revision and lifecycle state, as
Coven's stored view does. Require each of the five events to carry
exactly its revision's value. The published v0.4.8 daemon matches all
five. New negative cases cover a missing activation digest and an
unrelated disable digest.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@BunsDev
BunsDev merged commit 5414c18 into main Oct 3, 2026
8 checks passed
@BunsDev
BunsDev deleted the test/80-daemon-canary-0.4.8 branch October 3, 2026 13:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants