Skip to content

Phase C — E2E verification + gateway↔gnosis seam tests #98

Description

@hyperpolymath

Weeks 5–7. End-to-end tests across the gateway → unified-Zig-core (gnosis handler) boundary; the seam contract is honoured under policy.

Parent: standards#91 (ADR-0004 phase C). Single-channel: do not work out of phase order; A→B→C→D→E.

Activity

  1. added a commit that references this issue on May 20, 2026
    4d196b9
  2. hyperpolymath commented on May 20, 2026

    @hyperpolymath
    OwnerAuthor

    Phase C — work landed 2026-05-20

    Three coordinated PRs constitute the Phase C deliverables:

    Gateway side

    • http-capability-gateway#11 — Proxy.build_backend_headers/1 now strips any client-supplied X-Trust-Level and X-Request-ID, re-emits the gateway-resolved values from conn.assigns. Honours Phase A §3 invariants 1 + 2. E2E + property tests on the seam.

    BoJ-server side

    • boj-server#90 — declares the gateway↔BoJ-gnosis seam in Trustfile.a2ml [SEAMS] (Trustfile-level reflection of the contract).
    • boj-server#93 (RFC ADR-0009 + 0010) also carried elixir/test/phase_c_seam_test.exs — BoJ-side seam tests for §3 invariant 3 enforcement.

    Open finding (owner-decision)

    BojRest.TrustPolicy.satisfies?/3 does NOT enforce §3 invariant 3 — its third clause matches regardless of is_local. 5 tests in phase_c_seam_test.exs are @tag :skip documenting the unfixed defect; they pass as-is once a one-line clause is added:

    def satisfies?(_required, _trust, false), do: false

    Mitigated in practice by §4 (back-side bind isolation). Fix is owner-gated; not opened as a PR.

    Phase C status

    Functionally complete at the gateway level + documented at the BoJ level. Per joint-close convention this sub-issue stays OPEN until owner agrees to close — flagged ready for that decision modulo the §3 enforcement choice above.

    Parent: standards#91. Refs #91.

    🤖 Generated with Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    majorMajor / load-bearing workrequirements-targetTracked requirements-target item (joint-close)

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions