Archive upstream v1 and remove retired runtime contract readers

This commit is contained in:
2026-10-01 11:11:29 +08:00
parent d85480c00c
commit 163e233419
60 changed files with 15 additions and 41 deletions
+2 -20
View File
@@ -2,19 +2,16 @@ package contracts
import (
"embed"
"encoding/json"
"fmt"
"path"
)
// Files contains the pinned upstream history and only the active local contract.
// Files contains only the active local machine contract.
// Runtime code never reads a checkout or resolves schema refs online.
//
//go:embed upstream local/*.json local/examples
//go:embed local/*.json local/examples
var Files embed.FS
const SourceCommit = "v1"
// ReadCurrent reads the sole active project-local contract, with no fallback
// to a historical bundle if a name is missing or invalid.
func ReadCurrent(name string) ([]byte, error) {
@@ -25,18 +22,3 @@ func ReadCurrent(name string) ([]byte, error) {
return nil, fmt.Errorf("invalid current contract %q", name)
}
}
func Read(name string) ([]byte, error) {
return Files.ReadFile(path.Join("upstream", SourceCommit, name))
}
func ReadJSON(name string, dst any) error {
data, err := Read(name)
if err != nil {
return fmt.Errorf("read contract %s: %w", name, err)
}
if err := json.Unmarshal(data, dst); err != nil {
return fmt.Errorf("decode contract %s: %w", name, err)
}
return nil
}
-13
View File
@@ -7,19 +7,6 @@ import (
"git.ipao.vip/rogee/go-sip/contracts"
)
func TestPinnedUpstreamBundleRemainsReadable(t *testing.T) {
if body, err := contracts.Read("mq.schema.json"); err != nil || len(body) == 0 {
t.Fatalf("pinned upstream schema missing: bytes=%d err=%v", len(body), err)
}
var schema any
if err := contracts.ReadJSON("mq.schema.json", &schema); err != nil || schema == nil {
t.Fatalf("pinned upstream schema is invalid: %v", err)
}
if _, err := contracts.Read("missing-contract.json"); err == nil {
t.Fatal("missing upstream source was accepted")
}
}
func TestRuntimeBundleExcludesHistoricalLocalContracts(t *testing.T) {
for _, name := range []string{
"local/v0.1/call-result-v0.1-proposal.schema.json",
+1 -1
View File
@@ -13,7 +13,7 @@ import (
"github.com/santhosh-tekuri/jsonschema/v6"
)
const v1Dir = "upstream/v1"
const v1Dir = "../docs/archive/upstream/v1"
const v1Base = "https://go-sip.local/contracts/v1/"
type offlineLoader struct{}
+2 -2
View File
@@ -13,7 +13,7 @@ import (
)
func TestV1BundleHashesAndOfflineFixtures(t *testing.T) {
const dir = "upstream/v1"
const dir = "../docs/archive/upstream/v1"
var manifest struct {
Files map[string]string `json:"files"`
}
@@ -83,7 +83,7 @@ func TestV1BundleHashesAndOfflineFixtures(t *testing.T) {
func TestV1PythonGoJCSGolden(t *testing.T) {
var vectors []struct{ Name, Input, Canonical, SHA256 string }
if err := json.Unmarshal(readV1(t, "upstream/v1/jcs-golden.json"), &vectors); err != nil {
if err := json.Unmarshal(readV1(t, "../docs/archive/upstream/v1/jcs-golden.json"), &vectors); err != nil {
t.Fatal(err)
}
for _, vector := range vectors {
+5
View File
@@ -0,0 +1,5 @@
# 上游 v1 原件(历史)
`manifest.txt` 和 `v1/` 保留原字节,仍按原始路径及 SHA-256 记录来源。`scripts/check-contracts.sh` 将清单中的旧仓库路径映射到此目录做**离线哈希校验**;发布清单也记录这里的历史来源哈希。
这是已退役的上游基线,不嵌入 `contracts.Files`,不作为运行回退或当前 SaaS 合同。当前唯一人类可读规范是 [`../../thirds/saas-dispatcher.md`](../../thirds/saas-dispatcher.md);当前机器合同只在 `contracts/local/`。
+1 -1
View File
@@ -70,7 +70,7 @@ manifest = {
"contract_attestation": {
"local_contract_manifest_sha256": project_sha256("contracts/local/manifest.json"),
"local_mq_topology_sha256": project_sha256("contracts/local/mq-topology.json"),
"historical_upstream_manifest_sha256": project_sha256("contracts/upstream/manifest.txt"),
"historical_upstream_manifest_sha256": project_sha256("docs/archive/upstream/manifest.txt"),
"proto_manifest_sha256": project_sha256("proto/manifest.json"),
},
"security": {
+3 -3
View File
@@ -2,13 +2,13 @@
set -eu
root=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd)
manifest="$root/contracts/upstream/manifest.txt"
manifest="$root/docs/archive/upstream/manifest.txt"
[ -f "$manifest" ] || { echo "missing contract manifest" >&2; exit 1; }
bundle=$(sed -n 's/^active_bundle=//p' "$manifest")
[ -n "$bundle" ] || { echo "missing active contract bundle" >&2; exit 1; }
[ -d "$root/contracts/upstream/$bundle" ] || { echo "missing pinned contract directory: $bundle" >&2; exit 1; }
[ -d "$root/docs/archive/upstream/$bundle" ] || { echo "missing archived contract directory: $bundle" >&2; exit 1; }
cd "$root"
grep '^sha256=' "$manifest" | sed 's/^sha256=//' | sha256sum -c -
grep '^sha256=' "$manifest" | sed -e 's/^sha256=//' -e "s% contracts/upstream/$bundle/% docs/archive/upstream/$bundle/%" | sha256sum -c -
bash scripts/check-current-contracts.sh
go test ./contracts ./internal/contract ./internal/ai
+1 -1
View File
@@ -68,7 +68,7 @@ assert topology["saas"]["result"]["queue"].endswith(".v1")
expected_attestation = {
"local_contract_manifest_sha256": hashlib.sha256((root / "contracts/local/manifest.json").read_bytes()).hexdigest(),
"local_mq_topology_sha256": hashlib.sha256((root / "contracts/local/mq-topology.json").read_bytes()).hexdigest(),
"historical_upstream_manifest_sha256": hashlib.sha256((root / "contracts/upstream/manifest.txt").read_bytes()).hexdigest(),
"historical_upstream_manifest_sha256": hashlib.sha256((root / "docs/archive/upstream/manifest.txt").read_bytes()).hexdigest(),
"proto_manifest_sha256": hashlib.sha256((root / "proto/manifest.json").read_bytes()).hexdigest(),
}
assert manifest["contract_attestation"] == expected_attestation