Compare commits
4 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 95c3a4aed6 | |||
| 00d5ff7764 | |||
| 6bad659c12 | |||
| f368fec6eb |
@@ -119,9 +119,12 @@ versioning, and secure rollout seams are in the
|
||||
The always-on three-party scenarios, optional Linux namespace topology, and
|
||||
simulation limits are documented in the
|
||||
[deterministic topology harness](docs/integration/topology-harness.md).
|
||||
The current consumer evidence and the still-open public-package, Godot-process,
|
||||
fallback, reconnect, Linux, and external-NAT gates are tracked in the
|
||||
[SpaceGame consumer pilot](docs/integration/spacegame-pilot.md).
|
||||
The current consumer evidence and remaining external gates are tracked in the
|
||||
[SpaceGame consumer pilot](docs/integration/spacegame-pilot.md) and independent
|
||||
[Unscouted consumer pilot](docs/integration/unscouted-pilot.md).
|
||||
The fail-closed launch decision, redacted evidence matrix, and two-machine
|
||||
external-network procedure are in
|
||||
[production readiness and real-network canary](docs/operations/production-readiness.md).
|
||||
|
||||
|
||||
## Development
|
||||
|
||||
@@ -32,6 +32,16 @@
|
||||
"NotBefore": "2026-01-01T00:00:00Z",
|
||||
"SignUntil": "2100-01-01T00:00:00Z",
|
||||
"VerifyUntil": "2100-01-02T00:00:00Z"
|
||||
},
|
||||
{
|
||||
"KeyId": "local-smoke-unscouted-1",
|
||||
"SecretReference": "file:/run/secrets/rendezvous-signing-key",
|
||||
"CredentialKinds": ["DedicatedPublisher"],
|
||||
"GameId": "unscouted",
|
||||
"EnvironmentId": "smoke",
|
||||
"NotBefore": "2026-01-01T00:00:00Z",
|
||||
"SignUntil": "2100-01-01T00:00:00Z",
|
||||
"VerifyUntil": "2100-01-02T00:00:00Z"
|
||||
}
|
||||
],
|
||||
"Games": [
|
||||
@@ -53,6 +63,27 @@
|
||||
"MaxAnonymousListingsPerAddress": 0,
|
||||
"MaxActiveJoinAttempts": 100,
|
||||
"FallbackPolicy": "DedicatedEndpointAllowed"
|
||||
},
|
||||
{
|
||||
"GameId": "unscouted",
|
||||
"EnvironmentId": "smoke",
|
||||
"Enabled": true,
|
||||
"ProtocolVersions": [1],
|
||||
"Regions": ["local"],
|
||||
"VisibilityModes": ["Public"],
|
||||
"PublisherTrustModes": ["ManagedDedicated"],
|
||||
"MetadataValueMaxBytes": {
|
||||
"mode": 32,
|
||||
"world": 64,
|
||||
"mods": 64
|
||||
},
|
||||
"RequiredMetadataKeys": ["mode", "world", "mods"],
|
||||
"MetadataMaxBytes": 512,
|
||||
"MetadataMaxKeys": 3,
|
||||
"MaxListingsPerPrincipal": 10,
|
||||
"MaxAnonymousListingsPerAddress": 0,
|
||||
"MaxActiveJoinAttempts": 100,
|
||||
"FallbackPolicy": "DedicatedEndpointAllowed"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schemaVersion": 2,
|
||||
"evidenceVersion": "v2",
|
||||
"generatedAt": "2026-07-16T14:10:53.6981858+00:00",
|
||||
"generatedAt": "2026-07-16T20:28:43.2873744+00:00",
|
||||
"profile": "candidate",
|
||||
"runtime": {
|
||||
"framework": ".NET 10.0.9",
|
||||
@@ -14,14 +14,14 @@
|
||||
"cpuQuota": "not-enforced",
|
||||
"memoryLimit": "not-enforced",
|
||||
"garbageCollector": "workstation",
|
||||
"commitSha": "cf14836d48b0b4aaa67f99433f4fba3585bcd2bb",
|
||||
"commitSha": "00d5ff776408e7d80ce6648953e62a7233aca35c",
|
||||
"treeState": "clean",
|
||||
"command": "RENDEZVOUS_CAPACITY_PROFILE=candidate RENDEZVOUS_CAPACITY_CPUSET=0,1 ./scripts/run-capacity-gate.sh",
|
||||
"imageDigest": "not-containerized",
|
||||
"workloadSeed": "fixed-sequences-random-identifiers",
|
||||
"capacityPhaseAverageCpuPercent": 56.37724115383554,
|
||||
"peakWorkingSetBytes": 169705472,
|
||||
"managedBytesAfterCleanup": 35615200
|
||||
"capacityPhaseAverageCpuPercent": 55.52666859166872,
|
||||
"peakWorkingSetBytes": 176758784,
|
||||
"managedBytesAfterCleanup": 35608984
|
||||
},
|
||||
"targets": {
|
||||
"visibleListings": 25000,
|
||||
@@ -39,10 +39,10 @@
|
||||
{
|
||||
"operation": "registration-and-presence",
|
||||
"samples": 1000,
|
||||
"p50Milliseconds": 0.003,
|
||||
"p50Milliseconds": 0.0029,
|
||||
"p95Milliseconds": 0.0046,
|
||||
"p99Milliseconds": 0.0054,
|
||||
"operationsPerSecond": 282453.96000451926,
|
||||
"p99Milliseconds": 0.0055,
|
||||
"operationsPerSecond": 287918.9220315559,
|
||||
"minimumOperationsPerSecond": 200,
|
||||
"budgetMilliseconds": 200,
|
||||
"passed": true
|
||||
@@ -51,9 +51,9 @@
|
||||
"operation": "lease-renewal",
|
||||
"samples": 1000,
|
||||
"p50Milliseconds": 0.0004,
|
||||
"p95Milliseconds": 0.0009,
|
||||
"p99Milliseconds": 0.0021,
|
||||
"operationsPerSecond": 968992.2480620155,
|
||||
"p95Milliseconds": 0.0007,
|
||||
"p99Milliseconds": 0.0019,
|
||||
"operationsPerSecond": 1076426.264800861,
|
||||
"minimumOperationsPerSecond": 200,
|
||||
"budgetMilliseconds": 200,
|
||||
"passed": true
|
||||
@@ -61,10 +61,10 @@
|
||||
{
|
||||
"operation": "visible-session-browse",
|
||||
"samples": 250,
|
||||
"p50Milliseconds": 0.9046,
|
||||
"p95Milliseconds": 3.3704,
|
||||
"p99Milliseconds": 3.9471,
|
||||
"operationsPerSecond": 695.5799787597697,
|
||||
"p50Milliseconds": 1.0232,
|
||||
"p95Milliseconds": 3.6083,
|
||||
"p99Milliseconds": 4.2925,
|
||||
"operationsPerSecond": 650.0325926341947,
|
||||
"minimumOperationsPerSecond": 200,
|
||||
"budgetMilliseconds": 200,
|
||||
"passed": true
|
||||
@@ -72,10 +72,10 @@
|
||||
{
|
||||
"operation": "join-attempt-issuance",
|
||||
"samples": 1000,
|
||||
"p50Milliseconds": 0.0029,
|
||||
"p95Milliseconds": 0.0045,
|
||||
"p99Milliseconds": 0.0055,
|
||||
"operationsPerSecond": 296428.042092782,
|
||||
"p50Milliseconds": 0.0028,
|
||||
"p95Milliseconds": 0.0042,
|
||||
"p99Milliseconds": 0.0052,
|
||||
"operationsPerSecond": 135253.93927098127,
|
||||
"minimumOperationsPerSecond": 200,
|
||||
"budgetMilliseconds": 200,
|
||||
"passed": true
|
||||
@@ -83,10 +83,10 @@
|
||||
{
|
||||
"operation": "simultaneous-punch-pairing",
|
||||
"samples": 1000,
|
||||
"p50Milliseconds": 0.0043,
|
||||
"p95Milliseconds": 0.0073,
|
||||
"p99Milliseconds": 0.0115,
|
||||
"operationsPerSecond": 109212.03516627532,
|
||||
"p50Milliseconds": 0.0039,
|
||||
"p95Milliseconds": 0.0069,
|
||||
"p99Milliseconds": 0.0087,
|
||||
"operationsPerSecond": 110619.46902654869,
|
||||
"minimumOperationsPerSecond": 2000,
|
||||
"budgetMilliseconds": 100,
|
||||
"passed": true
|
||||
@@ -94,10 +94,10 @@
|
||||
{
|
||||
"operation": "principal-revocation",
|
||||
"samples": 50,
|
||||
"p50Milliseconds": 0.518,
|
||||
"p95Milliseconds": 0.7049,
|
||||
"p99Milliseconds": 11.8557,
|
||||
"operationsPerSecond": 1320.1773262184577,
|
||||
"p50Milliseconds": 0.495,
|
||||
"p95Milliseconds": 0.6508,
|
||||
"p99Milliseconds": 11.011,
|
||||
"operationsPerSecond": 1393.258301729591,
|
||||
"minimumOperationsPerSecond": 50,
|
||||
"budgetMilliseconds": 200,
|
||||
"passed": true
|
||||
@@ -108,7 +108,7 @@
|
||||
"p50Milliseconds": 0.0001,
|
||||
"p95Milliseconds": 0.0001,
|
||||
"p99Milliseconds": 0.0001,
|
||||
"operationsPerSecond": 1438641.9220256077,
|
||||
"operationsPerSecond": 1479289.9408284025,
|
||||
"minimumOperationsPerSecond": 10000,
|
||||
"budgetMilliseconds": 1,
|
||||
"passed": true
|
||||
@@ -116,10 +116,10 @@
|
||||
{
|
||||
"operation": "coincident-listing-attempt-expiry",
|
||||
"samples": 1,
|
||||
"p50Milliseconds": 29.6882,
|
||||
"p95Milliseconds": 29.6882,
|
||||
"p99Milliseconds": 29.6882,
|
||||
"operationsPerSecond": 33.682962483916384,
|
||||
"p50Milliseconds": 27.7056,
|
||||
"p95Milliseconds": 27.7056,
|
||||
"p99Milliseconds": 27.7056,
|
||||
"operationsPerSecond": 36.093525543388026,
|
||||
"minimumOperationsPerSecond": 0,
|
||||
"budgetMilliseconds": 200,
|
||||
"passed": true
|
||||
@@ -134,10 +134,10 @@
|
||||
"finalReplayMarkers": 0,
|
||||
"expiryChurn": 94906,
|
||||
"maintenanceSweeps": 36307,
|
||||
"soakCyclesCompleted": 75126848,
|
||||
"soakDurationSeconds": 300.0000015,
|
||||
"soakCyclesCompleted": 77547145,
|
||||
"soakDurationSeconds": 300.0000041,
|
||||
"soakPeakScheduledExpiryEntries": 7,
|
||||
"soakManagedGrowthBytes": -257288,
|
||||
"soakManagedGrowthBytes": -263432,
|
||||
"soakHandleGrowth": 2,
|
||||
"restartStartedEmpty": true,
|
||||
"overloadWasTyped": true,
|
||||
|
||||
@@ -0,0 +1,82 @@
|
||||
{
|
||||
"schemaVersion": "1.0",
|
||||
"recordedAt": "2026-07-16",
|
||||
"issue": 22,
|
||||
"consumerIssue": "HeiKyu/Unscouted#459",
|
||||
"result": "checkpoint-pass-with-external-gates",
|
||||
"rendezvousConfigurationCommit": "f368fec6eb4344a6042974f58f888cf0f1ac8e8e",
|
||||
"consumerImplementationCommit": "1e5886aa7f1e44689b4c75e32693eb7b19fd72d7",
|
||||
"consumerEvidenceCommit": "f0574a7de82aadff6495ca5657dfc19cf7c2f67c",
|
||||
"consumerIssueComment": 11499,
|
||||
"packages": {
|
||||
"FinalFactory.Rendezvous.Client": {
|
||||
"version": "1.0.0",
|
||||
"source": "local-candidate",
|
||||
"sourceCommit": "07004cd75fe172aa5dfdb3edda22fc280a4c4477",
|
||||
"sha256": "fb156cf48b49f75c244dd25ea7cc4aa9fc6fab0a878393bb7efd5d9b131d0395"
|
||||
},
|
||||
"FinalFactory.Rendezvous.Contracts": {
|
||||
"version": "1.0.0",
|
||||
"source": "local-candidate",
|
||||
"sourceCommit": "07004cd75fe172aa5dfdb3edda22fc280a4c4477",
|
||||
"sha256": "a82ba986d3905d599096d1d8ce8f32cd4feb104abfca37b0f65e0d2ef3df9a6f"
|
||||
},
|
||||
"LiteNetLib": {
|
||||
"version": "2.1.4"
|
||||
}
|
||||
},
|
||||
"configuration": {
|
||||
"gameId": "unscouted",
|
||||
"environmentId": "smoke",
|
||||
"regionId": "local",
|
||||
"protocolVersion": 1,
|
||||
"publisherTrust": "ManagedDedicated",
|
||||
"fallbackPolicy": "DedicatedEndpointAllowed",
|
||||
"metadataKeys": ["mode", "world", "mods"],
|
||||
"metadataMaxKeys": 3,
|
||||
"metadataMaxBytes": 512
|
||||
},
|
||||
"godotRun": {
|
||||
"runtime": "Godot 4.7 .NET Linux x86_64",
|
||||
"processes": [
|
||||
"Rendezvous hardened Compose service",
|
||||
"Godot Unscouted host",
|
||||
"Godot incompatible-protocol client",
|
||||
"Godot direct client",
|
||||
"Godot fallback client"
|
||||
],
|
||||
"gameplayTransport": "unscouted-litenetlib",
|
||||
"rendezvousGameplayPayloadPath": "none",
|
||||
"directGameplay": true,
|
||||
"fallbackGameplay": true,
|
||||
"authenticatedSessions": 2,
|
||||
"gameplayExchanges": 2,
|
||||
"hostLeaseRenewed": true,
|
||||
"deregistered": true,
|
||||
"playerIdentityOwner": "unscouted",
|
||||
"canonicalGameStateOwner": "unscouted"
|
||||
},
|
||||
"negativePaths": {
|
||||
"incompatibleProtocol": "proven-no-compatible-listing",
|
||||
"wrongGame": "proven-exact-NotFound",
|
||||
"wrongEnvironment": "proven-exact-NotFound",
|
||||
"punchTimeout": "proven-typed-failure-then-game-owned-fallback",
|
||||
"unexpectedMetadata": "consumer-regression-tested"
|
||||
},
|
||||
"verification": {
|
||||
"rendezvousDebugTests": { "passed": 299, "failed": 0 },
|
||||
"rendezvousReleaseTests": { "passed": 299, "failed": 0 },
|
||||
"consumerDebugTests": { "passed": 3310, "skipped": 15, "failed": 0 },
|
||||
"consumerReleaseTests": { "passed": 3310, "skipped": 15, "failed": 0 },
|
||||
"consumerGdUnitTests": { "passed": 360, "skipped": 0, "failed": 0 },
|
||||
"consumerExport": "not-applicable-no-export-presets",
|
||||
"format": "passed",
|
||||
"shellcheck": "passed",
|
||||
"godotPilot": "passed",
|
||||
"adversarialReview": "passed-after-fixes"
|
||||
},
|
||||
"openGates": [
|
||||
"public-package-restore",
|
||||
"representative-external-nat"
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,124 @@
|
||||
{
|
||||
"schemaVersion": 1,
|
||||
"kind": "rendezvous-production-readiness",
|
||||
"evaluatedCommit": "00d5ff776408e7d80ce6648953e62a7233aca35c",
|
||||
"decision": "not-ready",
|
||||
"localGates": [
|
||||
{
|
||||
"id": "immutable-release-artifacts",
|
||||
"status": "pass",
|
||||
"evidenceRef": "docs/evidence/releases/v1.0.0-local-candidate.json",
|
||||
"note": "Clean candidate packages and server archive are byte reproducible and fully verified."
|
||||
},
|
||||
{
|
||||
"id": "debug-and-release-verification",
|
||||
"status": "pass",
|
||||
"evidenceRef": "docs/evidence/releases/v1.0.0-local-candidate.json",
|
||||
"note": "All 300 tests pass in Debug and Release; the Release build has zero warnings and errors."
|
||||
},
|
||||
{
|
||||
"id": "real-consumer-pilots",
|
||||
"status": "pass",
|
||||
"evidenceRef": "docs/evidence/releases/v1.0.0-local-candidate.json",
|
||||
"note": "Pinned real projects restore the candidate and both game launch pilots pass direct traffic."
|
||||
},
|
||||
{
|
||||
"id": "candidate-capacity-resilience",
|
||||
"status": "pass",
|
||||
"evidenceRef": "docs/evidence/capacity/v2/candidate-2cpu.json",
|
||||
"note": "The clean two-CPU five-minute candidate passes all budgets with zero retained state."
|
||||
},
|
||||
{
|
||||
"id": "production-process-recovery",
|
||||
"status": "pass",
|
||||
"evidenceRef": "docs/evidence/releases/v1.0.0-local-candidate.json",
|
||||
"note": "All selected restart, drain, socket release, overload, and recovery tests pass."
|
||||
},
|
||||
{
|
||||
"id": "security-privacy-observability",
|
||||
"status": "pass",
|
||||
"evidenceRef": "docs/evidence/releases/v1.0.0-local-candidate.json",
|
||||
"note": "The complete security, privacy, health, audit, telemetry, and release suite passes."
|
||||
}
|
||||
],
|
||||
"externalGates": [
|
||||
{
|
||||
"id": "public-package-empty-cache-restore",
|
||||
"status": "pending",
|
||||
"evidenceRef": "docs/operations/production-readiness.md",
|
||||
"note": "The public registry does not currently resolve version 1.0.0."
|
||||
},
|
||||
{
|
||||
"id": "signed-publication",
|
||||
"status": "pending",
|
||||
"evidenceRef": "docs/releases/README.md",
|
||||
"note": "Protected release credentials and immutable tag publication are required."
|
||||
},
|
||||
{
|
||||
"id": "source-preserving-udp-ingress",
|
||||
"status": "pending",
|
||||
"evidenceRef": "docs/operations/production-readiness.md",
|
||||
"note": "The public ingress path needs packet-level source and reply validation."
|
||||
},
|
||||
{
|
||||
"id": "same-lan-direct-canary",
|
||||
"status": "pending",
|
||||
"evidenceRef": "docs/operations/production-readiness.md",
|
||||
"note": "Requires two independently operated game clients."
|
||||
},
|
||||
{
|
||||
"id": "home-nat-direct-canary",
|
||||
"status": "pending",
|
||||
"evidenceRef": "docs/operations/production-readiness.md",
|
||||
"note": "Requires distinct residential networks."
|
||||
},
|
||||
{
|
||||
"id": "restrictive-cgnat-typed-failure",
|
||||
"status": "pending",
|
||||
"evidenceRef": "docs/operations/production-readiness.md",
|
||||
"note": "Requires a known restrictive carrier topology."
|
||||
},
|
||||
{
|
||||
"id": "firewall-blocked-udp-typed-failure",
|
||||
"status": "pending",
|
||||
"evidenceRef": "docs/operations/production-readiness.md",
|
||||
"note": "Requires an independently controlled firewall rule."
|
||||
},
|
||||
{
|
||||
"id": "ipv6-direct-canary",
|
||||
"status": "pending",
|
||||
"evidenceRef": "docs/operations/production-readiness.md",
|
||||
"note": "Requires two IPv6-capable external clients and public ingress."
|
||||
},
|
||||
{
|
||||
"id": "public-rate-shaped-capacity",
|
||||
"status": "pending",
|
||||
"evidenceRef": "docs/operations/capacity-and-resilience.md",
|
||||
"note": "The full public HTTP and UDP traffic mix has not been measured."
|
||||
},
|
||||
{
|
||||
"id": "one-hour-candidate-endurance",
|
||||
"status": "pending",
|
||||
"evidenceRef": "docs/operations/capacity-and-resilience.md",
|
||||
"note": "A production-shaped one-hour candidate run is required."
|
||||
},
|
||||
{
|
||||
"id": "alert-delivery",
|
||||
"status": "pending",
|
||||
"evidenceRef": "docs/operations/incident-runbooks.md",
|
||||
"note": "A real alert sink must observe trigger and recovery notifications."
|
||||
},
|
||||
{
|
||||
"id": "cold-standby-rollback-drill",
|
||||
"status": "pending",
|
||||
"evidenceRef": "docs/operations/capacity-and-resilience.md",
|
||||
"note": "The deployment must demonstrate the host-visible recovery objective."
|
||||
},
|
||||
{
|
||||
"id": "documentation-only-runbook-exercise",
|
||||
"status": "pending",
|
||||
"evidenceRef": "docs/operations/incident-runbooks.md",
|
||||
"note": "An independent operator must execute the runbooks using only the docs."
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,58 @@
|
||||
{
|
||||
"schemaVersion": 1,
|
||||
"kind": "rendezvous-local-release-candidate",
|
||||
"version": "1.0.0",
|
||||
"sourceCommit": "00d5ff776408e7d80ce6648953e62a7233aca35c",
|
||||
"treeState": "clean",
|
||||
"result": "pass",
|
||||
"artifacts": [
|
||||
{
|
||||
"name": "FinalFactory.Rendezvous.Client.1.0.0.nupkg",
|
||||
"sha256": "f2a4b9727b5faeba284ddcb7fc575c7495f1e29b763faababa7cd71444dc2950"
|
||||
},
|
||||
{
|
||||
"name": "FinalFactory.Rendezvous.Contracts.1.0.0.nupkg",
|
||||
"sha256": "92317f153911ebf7b8ea04cd3206ec2a17f882cb4eddb26aa8ab094ffdb06627"
|
||||
},
|
||||
{
|
||||
"name": "FinalFactory.Rendezvous.Server.1.0.0.linux-x64.tar.gz",
|
||||
"sha256": "0dab8cfc696b4a55d6ffba46286c9e532df2c943ed8fd6347fb528516156b3ba"
|
||||
}
|
||||
],
|
||||
"verification": {
|
||||
"lockedRestore": "pass",
|
||||
"reportedVulnerabilities": 0,
|
||||
"format": "pass",
|
||||
"releaseBuildWarnings": 0,
|
||||
"releaseBuildErrors": 0,
|
||||
"debugTestsPassed": 300,
|
||||
"debugTestsFailed": 0,
|
||||
"releaseTestsPassed": 300,
|
||||
"releaseTestsFailed": 0,
|
||||
"selectedProductionFaultTestsPassed": 17,
|
||||
"byteReproduciblePackages": "pass",
|
||||
"byteReproducibleServerArchive": "pass",
|
||||
"sbomChecksumsAndProvenance": "pass",
|
||||
"candidateConsumerFixtures": "pass",
|
||||
"realConsumerRestores": "pass"
|
||||
},
|
||||
"consumers": [
|
||||
{
|
||||
"name": "SpaceGame",
|
||||
"revision": "f3f5bc29810c362656cd7143bec1ddc2cfaf9f22",
|
||||
"candidateRestore": "pass",
|
||||
"directTrafficPilot": "pass"
|
||||
},
|
||||
{
|
||||
"name": "Unscouted",
|
||||
"revision": "f0574a7de82aadff6495ca5657dfc19cf7c2f67c",
|
||||
"candidateRestore": "pass",
|
||||
"directTrafficPilot": "pass"
|
||||
}
|
||||
],
|
||||
"limitations": {
|
||||
"publicRegistryRestore": "pending",
|
||||
"signedPublication": "pending",
|
||||
"externalNetworkCanaries": "pending"
|
||||
}
|
||||
}
|
||||
@@ -116,6 +116,9 @@ rm deploy/compose/secrets/signing-key
|
||||
codes are stable automation contracts. Informational events use stdout and
|
||||
failures use stderr.
|
||||
|
||||
Successful direct-connection and direct-traffic events include the coarse
|
||||
`addressFamily` value `ipv4` or `ipv6`. They never include the peer address.
|
||||
|
||||
The deployment smoke performs the full health, publish, join, mediation, direct
|
||||
traffic, outcome-report, and cleanup flow using bounded waits:
|
||||
|
||||
@@ -220,3 +223,6 @@ least-scope publisher credential from the deployment secret boundary and set the
|
||||
external service, mediator, and matching scope variables described in the
|
||||
[secure Linux deployment smoke](../deployment/linux.md#http-and-udp-smoke).
|
||||
Run representative external-network tests; loopback success is not NAT coverage.
|
||||
Use the redacting, bounded
|
||||
[real-network canary procedure](../operations/production-readiness.md) for formal
|
||||
production evidence rather than committing raw TestClient JSON.
|
||||
|
||||
@@ -0,0 +1,99 @@
|
||||
# Unscouted consumer pilot
|
||||
|
||||
Tracking: Rendezvous #22 and Unscouted #459.
|
||||
|
||||
The current checkpoint independently proves that the v1 contracts are not
|
||||
shaped only around SpaceGame. A real Godot Unscouted host and clients consume
|
||||
the same Client and Contracts package surface, use one caller-owned LiteNetLib
|
||||
socket for NAT callbacks and gameplay, perform Unscouted's own keypair
|
||||
authentication and host admission, exchange gameplay, and exercise a
|
||||
game-owned fallback. The public package restore and representative external
|
||||
NAT/CGNAT canary remain required before #22 can close.
|
||||
|
||||
## Pinned checkpoint
|
||||
|
||||
| Input | Value |
|
||||
| --- | --- |
|
||||
| Rendezvous configuration source | `f368fec6eb4344a6042974f58f888cf0f1ac8e8e` |
|
||||
| Rendezvous package source | `07004cd75fe172aa5dfdb3edda22fc280a4c4477` |
|
||||
| Unscouted implementation | `1e5886aa7f1e44689b4c75e32693eb7b19fd72d7` |
|
||||
| Unscouted evidence | `f0574a7de82aadff6495ca5657dfc19cf7c2f67c` |
|
||||
| Client package | `FinalFactory.Rendezvous.Client` `1.0.0` |
|
||||
| Contracts package | `FinalFactory.Rendezvous.Contracts` `1.0.0` |
|
||||
| LiteNetLib | `2.1.4` |
|
||||
| Godot | `4.7.stable.mono.arch_linux.5b4e0cb0f` |
|
||||
| Game / environment / region | `unscouted` / `smoke` / `local` |
|
||||
| Rendezvous and gameplay protocol | `1` |
|
||||
|
||||
The exact package hashes are recorded in
|
||||
[`unscouted.json`](../evidence/consumers/unscouted.json). A clean restore into an
|
||||
empty package directory using only the consumer's checked-in `NuGet.config`
|
||||
returns `NU1101` for both packages. The verified local run used those exact
|
||||
candidate package files from the existing cache. This proves compatibility,
|
||||
not immutable registry publication.
|
||||
|
||||
## Game-neutral service boundary
|
||||
|
||||
Rendezvous #22 adds provisioning data, not an Unscouted branch in the server or
|
||||
SDK. The local production-shaped tenant permits protocol `1`, region `local`,
|
||||
public managed-dedicated listings, and the three bounded presentation keys
|
||||
`mode`, `world`, and `mods`. The short-lived credential helper accepts only the
|
||||
explicitly provisioned `space-game` and `unscouted` scopes and selects a
|
||||
distinct game-scoped signing-key ID and subject.
|
||||
|
||||
The consumer rejects any metadata key outside its three-key presentation
|
||||
schema and neutralizes control/BBCode characters before display. Rendezvous
|
||||
never receives Unscouted player keys or resolved identities, colony authority,
|
||||
simulation or persistence state, fog/interest state, or gameplay packets.
|
||||
|
||||
## Proven real Godot path
|
||||
|
||||
The normal `NetLaunch` argument path recognizes `--rendezvous-pilot` and opens a
|
||||
dedicated scene. That scene uses Unscouted's real `LiteNetLibTransport`,
|
||||
`GameServer`, `GameClient`, `ServerAuthenticator`, and `ClientAuthenticator`.
|
||||
It is not a copied SDK adapter.
|
||||
|
||||
One bounded run against the hardened Compose service started a host plus:
|
||||
|
||||
- a protocol-`999` client that found no compatible listing;
|
||||
- a direct client that received an authorized introduction, completed
|
||||
same-socket traversal, passed Unscouted keypair admission, and exchanged an
|
||||
Unscouted gameplay ping/pong; and
|
||||
- a client pointed at a non-listening mediator that received a typed traversal
|
||||
failure, applied the fallback decision in Unscouted code, repeated admission,
|
||||
and exchanged the same gameplay ping/pong through the ordinary game
|
||||
transport.
|
||||
|
||||
The direct client also proved that both a `space-game` join request and a
|
||||
`production` environment join request return exact `NotFound` results for the
|
||||
Unscouted listing. The host renewed its lease, admitted two independently
|
||||
authenticated sessions, completed two gameplay exchanges, and deregistered the
|
||||
listing on shutdown.
|
||||
|
||||
## Verification
|
||||
|
||||
- Rendezvous Debug and Release: 299 tests passed in each configuration, zero
|
||||
failures.
|
||||
- Unscouted Debug and Release: non-incremental builds passed; 3,310 tests passed
|
||||
with 15 intentional skips in each configuration.
|
||||
- Unscouted gdUnit/Godot: 360 tests passed, zero skipped or failed. The harness
|
||||
fix in Unscouted #461 keeps compilation headless and leaves the open editor's
|
||||
build tree unchanged.
|
||||
- The final Godot pilot, ShellCheck, JSON/whitespace checks, formatting gate,
|
||||
and adversarial branch review passed.
|
||||
- Export is not applicable because the Unscouted checkout has no
|
||||
`export_presets.cfg`; both C# configurations and the actual Godot entry point
|
||||
were exercised.
|
||||
|
||||
## Remaining acceptance gates
|
||||
|
||||
Do not mark #22 passed until both external gates have direct evidence:
|
||||
|
||||
1. publish or expose the exact immutable `1.0.0` packages on the configured
|
||||
Gitea feed and repeat the empty-cache consumer restore; and
|
||||
2. run the same Godot host/client path across representative residential,
|
||||
CGNAT, and IPv6/multi-host networks, recording the topology and typed
|
||||
direct/fallback outcome.
|
||||
|
||||
The loopback run proves the real process, socket, authentication, and gameplay
|
||||
shape. It does not claim production Internet traversal coverage.
|
||||
@@ -81,7 +81,7 @@ concurrent build, thermal throttling, or oversubscribed CI host.
|
||||
The checked-in baseline is
|
||||
[`candidate-2cpu.json`](../evidence/capacity/v2/candidate-2cpu.json). It was
|
||||
produced on .NET 10.0.9/Linux x64 with CPU affinity restricted to two logical
|
||||
CPUs. It filled 25,000 listings and 10,000 attempts, peaked at about 162 MiB,
|
||||
CPUs. It filled 25,000 listings and 10,000 attempts, peaked at about 169 MiB,
|
||||
and cleared all active/retained state. The five-minute baseline supersedes any
|
||||
earlier local probe when its timestamp and target duration differ.
|
||||
|
||||
|
||||
@@ -0,0 +1,217 @@
|
||||
# Production-readiness decision and real-network canary
|
||||
|
||||
Tracking: #23
|
||||
|
||||
Rendezvous v1 is **not production-ready** until every required gate in
|
||||
[`production-readiness-v1.json`](../evidence/production-readiness-v1.json) is
|
||||
recorded as `pass`. The machine-checkable decision is intentionally fail-closed:
|
||||
|
||||
```bash
|
||||
./scripts/check-production-readiness.sh
|
||||
```
|
||||
|
||||
Exit `0` means every required gate is present and passing, exit `3` means the
|
||||
record is valid but at least one gate is pending or failed, and exit `2` means
|
||||
the record itself is malformed or contains identifier-, endpoint-, account-, or
|
||||
credential-shaped data. Editing only the top-level decision cannot make the
|
||||
check pass.
|
||||
|
||||
The checked-in record is an index, not a log archive. It contains one
|
||||
repository-relative evidence reference and a short categorical note per gate.
|
||||
Raw packet captures, client event streams, publisher credentials, public or
|
||||
private network endpoints, listing IDs, and player/account identifiers must not
|
||||
be committed.
|
||||
|
||||
## Required decision matrix
|
||||
|
||||
The local matrix covers immutable artifacts, Debug and Release verification,
|
||||
both real game consumers, the candidate capacity/resilience profile,
|
||||
production-process recovery, and the combined security/privacy/observability
|
||||
gate. These may be reproduced by the project team on a clean candidate commit.
|
||||
|
||||
The external matrix remains distinct because a local namespace, loopback,
|
||||
container bridge, or second process on one machine cannot prove it:
|
||||
|
||||
| Gate | Required evidence |
|
||||
| --- | --- |
|
||||
| Public package empty-cache restore | A clean machine restores the exact Client and Contracts version using only the documented public sources. |
|
||||
| Signed publication | The immutable tag publishes packages, image digest, SBOMs, provenance, checksums, and verifiable signatures through the protected release workflow. |
|
||||
| Source-preserving UDP ingress | Packet capture on the service host proves the mediator observes each peer's real source tuple and replies from the advertised public tuple; no UDP proxy rewrites either direction. |
|
||||
| Same-LAN direct canary | Two independently operated game clients establish authenticated direct LiteNetLib traffic. |
|
||||
| Home-NAT direct canary | Host and joiner on distinct residential networks establish authenticated direct LiteNetLib traffic. |
|
||||
| Restrictive/CGNAT and blocked-UDP canaries | Each bounded join exits `12`, records a typed terminal category, and exposes the game-owned fallback policy without hanging or claiming success. |
|
||||
| IPv6 direct canary | Two external IPv6 clients record authenticated direct traffic and an observed `ipv6` peer address family. |
|
||||
| Public rate-shaped capacity | The documented HTTP/UDP workload mix meets its objectives through TLS, Kestrel, JSON, LiteNetLib, kernel sockets, and public ingress. |
|
||||
| One-hour endurance | The immutable production-shaped candidate completes the one-hour profile without a state, handle, memory, readiness, or latency failure. |
|
||||
| Alert delivery | A real alert sink receives both trigger and recovery notifications for the rehearsed outage. |
|
||||
| Cold-standby rollback | Drain, stop, socket release, replacement start, host re-registration, and rollback meet the process and host-visible recovery objectives. |
|
||||
| Documentation-only exercise | An operator who did not author the runbooks completes key rotation/revocation, outage, restart, re-registration, and rollback using only the checked-in documentation. |
|
||||
|
||||
Failure or missing evidence is blocking. It is never converted into an accepted
|
||||
risk by changing the wording of the readiness note.
|
||||
|
||||
When an external gate passes, add a redacted repository JSON attestation and
|
||||
point that gate's `evidenceRef` to it. The checker requires this exact shape and
|
||||
binds the gate to the evaluated candidate commit. `artifactDigest` is the SHA-256
|
||||
of the protected evidence bundle or public release record, not a peer endpoint,
|
||||
listing identifier, account identifier, or credential:
|
||||
|
||||
```json
|
||||
{
|
||||
"schemaVersion": 1,
|
||||
"kind": "rendezvous-external-gate-attestation",
|
||||
"gateId": "replace-with-the-exact-gate-id",
|
||||
"candidateCommit": "replace-with-the-40-character-candidate-commit",
|
||||
"result": "pass",
|
||||
"performedAtUtc": "2026-01-01T00:00:00Z",
|
||||
"artifactDigest": "replace-with-the-64-character-sha256",
|
||||
"evidenceLocation": "protected-operations-record",
|
||||
"reviewerRole": "independent-operator"
|
||||
}
|
||||
```
|
||||
|
||||
Allowed evidence locations are `protected-operations-record` and
|
||||
`public-release-record`. Allowed reviewer roles are `release-operator`,
|
||||
`network-operator`, `security-operator`, and `independent-operator`. The checker
|
||||
rejects a missing file, wrong gate, wrong candidate, malformed digest, naive
|
||||
timestamp, extra fields, or sensitive-data-shaped contents.
|
||||
|
||||
## Prepare one immutable canary build
|
||||
|
||||
Use the exact release candidate on every canary machine. Verify a clean checkout,
|
||||
restore in locked mode, and build the TestClient before changing networks:
|
||||
|
||||
```bash
|
||||
test -z "$(git status --porcelain)"
|
||||
dotnet restore Rendezvous.slnx --locked-mode
|
||||
dotnet build Rendezvous.slnx --configuration Release --no-restore
|
||||
```
|
||||
|
||||
Keep shell tracing disabled. The host receives a short-lived, least-scope
|
||||
publisher credential through `RENDEZVOUS_PUBLISHER_CREDENTIAL`; it must never be
|
||||
put in an argument, coordination file, evidence file, command transcript, or
|
||||
support message. Set the public HTTPS service URL and advertised UDP mediator
|
||||
tuple separately. TestClient rejects credentials embedded in the service URL.
|
||||
|
||||
## Run a success canary across two machines
|
||||
|
||||
On the host machine, choose `same-lan`, `home-nat`, or `ipv6-direct`. The
|
||||
coordination file is mode `0600` and contains only the temporary listing UUID.
|
||||
It is not evidence; transfer it through an approved private channel, then delete
|
||||
both copies.
|
||||
|
||||
```bash
|
||||
set +x
|
||||
export RENDEZVOUS_PUBLISHER_CREDENTIAL='supplied-by-the-approved-secret-boundary'
|
||||
export RENDEZVOUS_CANARY_ROLE=host
|
||||
export RENDEZVOUS_CANARY_TOPOLOGY=home-nat
|
||||
export RENDEZVOUS_CANARY_ADDRESS_FAMILY=ipv4
|
||||
export RENDEZVOUS_CANARY_HTTP_URL='https://service.example.invalid/'
|
||||
export RENDEZVOUS_CANARY_UDP_ENDPOINT='203.0.113.10:9050'
|
||||
export RENDEZVOUS_CANARY_COORDINATION_FILE="$HOME/.local/state/rendezvous-canary-listing"
|
||||
export RENDEZVOUS_CANARY_OUTPUT="$PWD/artifacts/canary/home-nat-host.json"
|
||||
./scripts/run-real-network-canary.sh
|
||||
```
|
||||
|
||||
The host prints only that it is ready and waits for the authenticated exchange.
|
||||
On the joiner, read the securely transferred UUID without placing it in shell
|
||||
history and run the matching topology:
|
||||
|
||||
```bash
|
||||
set +x
|
||||
read -r RENDEZVOUS_CANARY_LISTING_ID < "$HOME/.local/state/rendezvous-canary-listing"
|
||||
export RENDEZVOUS_CANARY_LISTING_ID
|
||||
export RENDEZVOUS_CANARY_ROLE=client-success
|
||||
export RENDEZVOUS_CANARY_TOPOLOGY=home-nat
|
||||
export RENDEZVOUS_CANARY_ADDRESS_FAMILY=ipv4
|
||||
export RENDEZVOUS_CANARY_HTTP_URL='https://service.example.invalid/'
|
||||
export RENDEZVOUS_CANARY_UDP_ENDPOINT='203.0.113.10:9050'
|
||||
export RENDEZVOUS_CANARY_OUTPUT="$PWD/artifacts/canary/home-nat-client.json"
|
||||
./scripts/run-real-network-canary.sh
|
||||
unset RENDEZVOUS_CANARY_LISTING_ID
|
||||
```
|
||||
|
||||
The host summary requires authenticated direct traffic and deregistration. The
|
||||
client summary requires connection, authenticated direct traffic, accepted
|
||||
outcome reporting, and the declared address family observed on the actual peer.
|
||||
The summaries deliberately contain no network tuple or listing identifier.
|
||||
|
||||
For IPv6, set the topology to `ipv6-direct`, the family to `ipv6`, and use the
|
||||
deployment's bracketed IPv6 mediator form. Record unsupported operating systems,
|
||||
console platforms, VPNs, and address families as untested; an IPv4 pass is not
|
||||
evidence for IPv6 or a platform network policy.
|
||||
|
||||
## Run a bounded failure canary
|
||||
|
||||
Start the host from an independently reachable network as above. On the joiner,
|
||||
apply the reviewed firewall rule that blocks the relevant UDP path, or use the
|
||||
known restrictive carrier network, then set `client-expected-failure` and the
|
||||
matching topology:
|
||||
|
||||
```bash
|
||||
export RENDEZVOUS_CANARY_ROLE=client-expected-failure
|
||||
export RENDEZVOUS_CANARY_TOPOLOGY=firewall-blocked-udp
|
||||
export RENDEZVOUS_CANARY_ADDRESS_FAMILY=ipv4
|
||||
export RENDEZVOUS_CANARY_OUTPUT="$PWD/artifacts/canary/firewall-blocked-client.json"
|
||||
./scripts/run-real-network-canary.sh
|
||||
```
|
||||
|
||||
This role passes only when TestClient exits exactly `12`, emits a non-empty typed
|
||||
authorization/traversal outcome, and emits the authoritative fallback category.
|
||||
A timeout without the typed terminal outcome, exit `0`, direct-traffic success,
|
||||
or an unbounded process is a failed canary. Restore the firewall after the drill
|
||||
and verify normal traffic again.
|
||||
|
||||
## Private diagnostics and retention
|
||||
|
||||
The harness creates raw JSON events under a randomly named `0700`-equivalent
|
||||
temporary directory with a process `umask` of `077`. Successful raw events are
|
||||
deleted automatically. On failure they remain in that private directory so the
|
||||
operator can triage locally; do not attach them to an issue before removing
|
||||
listing IDs and reviewing every field. Set `RENDEZVOUS_CANARY_KEEP_RAW=true`
|
||||
only for an approved short-lived diagnostic capture, then delete it manually.
|
||||
|
||||
The sanitized summary contains the commit, clean/dirty tree state, UTC time,
|
||||
role, declared topology, observed address-family gate, aggregate booleans, and
|
||||
the retention policy. Formal evidence requires the default clean-tree check.
|
||||
|
||||
## Public ingress proof
|
||||
|
||||
Success through a public hostname is insufficient proof that UDP source/reply
|
||||
addressing is preserved. During a canary, an authorized operator must capture
|
||||
only packet headers at the service host and verify:
|
||||
|
||||
1. each authenticated contribution reaches the mediator with the external peer
|
||||
source tuple visible to the server;
|
||||
2. introductions are sent from the same advertised public mediator tuple;
|
||||
3. no load balancer, user-space proxy, service mesh, or destination NAT changes
|
||||
the source or reply tuple expected by LiteNetLib; and
|
||||
4. malformed or unauthenticated traffic receives no amplified response.
|
||||
|
||||
Store the approval, capture time window, candidate digest, topology category,
|
||||
and pass/fail result. Do not retain packet payloads or peer tuples in the
|
||||
repository. A failed tuple check blocks release even if one canary happened to
|
||||
connect.
|
||||
|
||||
## Rehearsal and triage
|
||||
|
||||
Run the security, capacity, observability, deployment, rollback, privacy, and
|
||||
incident procedures against the same immutable candidate. The independent
|
||||
operator records which runbook revision they followed, start/end time, observed
|
||||
alerts, recovery time, unexpected decisions, and pass/fail result. Update the
|
||||
documentation and repeat any failed or ambiguous step.
|
||||
|
||||
Before changing the readiness record, reconcile every open roadmap issue as one
|
||||
of: `blocking` with an owner and evidence needed, `accepted-v1` with a bounded
|
||||
documented limitation, or `post-v1` with a filed issue. HA, active-active or
|
||||
multi-region routing, relays, platform authentication, and scale above the
|
||||
single-active v1 envelope are not silently accepted; each needs a traceable
|
||||
post-v1 issue. The current follow-ups are relay decision [#24], HA/multi-region
|
||||
shared state and routing [#28], scale beyond the measured envelope [#29], and
|
||||
platform authentication adapters [#30]. Run the checker after every evidence
|
||||
update. Only its `READY` result may support a production-ready claim.
|
||||
|
||||
[#24]: https://git.finalfactory.de/HeiKyu/Rendezvous/issues/24
|
||||
[#28]: https://git.finalfactory.de/HeiKyu/Rendezvous/issues/28
|
||||
[#29]: https://git.finalfactory.de/HeiKyu/Rendezvous/issues/29
|
||||
[#30]: https://git.finalfactory.de/HeiKyu/Rendezvous/issues/30
|
||||
Executable
+309
@@ -0,0 +1,309 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Validate the redacted v1 readiness record and emit the release decision."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import pathlib
|
||||
import re
|
||||
import sys
|
||||
from datetime import datetime, timedelta
|
||||
from typing import Any
|
||||
|
||||
|
||||
LOCAL_GATES = {
|
||||
"immutable-release-artifacts",
|
||||
"debug-and-release-verification",
|
||||
"real-consumer-pilots",
|
||||
"candidate-capacity-resilience",
|
||||
"production-process-recovery",
|
||||
"security-privacy-observability",
|
||||
}
|
||||
EXTERNAL_GATES = {
|
||||
"public-package-empty-cache-restore",
|
||||
"signed-publication",
|
||||
"source-preserving-udp-ingress",
|
||||
"same-lan-direct-canary",
|
||||
"home-nat-direct-canary",
|
||||
"restrictive-cgnat-typed-failure",
|
||||
"firewall-blocked-udp-typed-failure",
|
||||
"ipv6-direct-canary",
|
||||
"public-rate-shaped-capacity",
|
||||
"one-hour-candidate-endurance",
|
||||
"alert-delivery",
|
||||
"cold-standby-rollback-drill",
|
||||
"documentation-only-runbook-exercise",
|
||||
}
|
||||
STATUSES = {"pass", "pending", "fail"}
|
||||
FORBIDDEN_KEY_PARTS = {
|
||||
"address",
|
||||
"credential",
|
||||
"endpoint",
|
||||
"listingid",
|
||||
"password",
|
||||
"playerid",
|
||||
"secret",
|
||||
"token",
|
||||
"userid",
|
||||
}
|
||||
UUID = re.compile(r"\b[0-9a-fA-F]{8}-[0-9a-fA-F-]{27,}\b")
|
||||
IPV4 = re.compile(r"(?<![0-9])(?:[0-9]{1,3}\.){3}[0-9]{1,3}(?![0-9])")
|
||||
IPV6 = re.compile(
|
||||
r"(?i)(?:\b[0-9a-f]{0,4}:[0-9a-f:]*::[0-9a-f:]*\b|\b(?:[0-9a-f]{1,4}:){4,}[0-9a-f:]{1,39}\b)"
|
||||
)
|
||||
COMMIT = re.compile(r"[0-9a-f]{40}")
|
||||
DIGEST = re.compile(r"[0-9a-f]{64}")
|
||||
|
||||
|
||||
class InvalidRecord(ValueError):
|
||||
pass
|
||||
|
||||
|
||||
def reject_sensitive(value: Any, path: str = "$") -> None:
|
||||
if isinstance(value, dict):
|
||||
for key, child in value.items():
|
||||
normalized = re.sub(r"[^a-z0-9]", "", key.lower())
|
||||
if any(part in normalized for part in FORBIDDEN_KEY_PARTS):
|
||||
raise InvalidRecord(f"{path}.{key} uses a forbidden sensitive-data key")
|
||||
reject_sensitive(child, f"{path}.{key}")
|
||||
elif isinstance(value, list):
|
||||
for index, child in enumerate(value):
|
||||
reject_sensitive(child, f"{path}[{index}]")
|
||||
elif isinstance(value, str):
|
||||
if UUID.search(value) or IPV4.search(value) or IPV6.search(value) \
|
||||
or "://" in value or "@" in value:
|
||||
raise InvalidRecord(f"{path} contains endpoint, identifier, or account-shaped data")
|
||||
|
||||
|
||||
def evidence_path(repository_root: pathlib.Path, value: str, path: str) -> pathlib.Path:
|
||||
relative = pathlib.PurePosixPath(value)
|
||||
if relative.is_absolute() or ".." in relative.parts or not value:
|
||||
raise InvalidRecord(f"{path} must be a repository-relative reference")
|
||||
candidate = (repository_root / pathlib.Path(*relative.parts)).resolve()
|
||||
if not candidate.is_relative_to(repository_root.resolve()) or not candidate.is_file():
|
||||
raise InvalidRecord(f"{path} does not resolve to a repository evidence file")
|
||||
return candidate
|
||||
|
||||
|
||||
def load_json(path: pathlib.Path, label: str) -> Any:
|
||||
try:
|
||||
with path.open("r", encoding="utf-8") as source:
|
||||
return json.load(source)
|
||||
except (OSError, json.JSONDecodeError) as error:
|
||||
raise InvalidRecord(f"{label} is not readable JSON: {error}") from error
|
||||
|
||||
|
||||
def validate_gate_set(
|
||||
items: Any,
|
||||
expected: set[str],
|
||||
path: str,
|
||||
repository_root: pathlib.Path,
|
||||
) -> list[dict[str, str]]:
|
||||
if not isinstance(items, list):
|
||||
raise InvalidRecord(f"{path} must be an array")
|
||||
gates: list[dict[str, str]] = []
|
||||
for index, item in enumerate(items):
|
||||
if not isinstance(item, dict) or set(item) != {"id", "status", "evidenceRef", "note"}:
|
||||
raise InvalidRecord(f"{path}[{index}] has an invalid shape")
|
||||
if not all(isinstance(item[key], str) for key in item):
|
||||
raise InvalidRecord(f"{path}[{index}] fields must be strings")
|
||||
if item["status"] not in STATUSES:
|
||||
raise InvalidRecord(f"{path}[{index}] has an invalid status")
|
||||
evidence_path(repository_root, item["evidenceRef"], f"{path}[{index}].evidenceRef")
|
||||
if len(item["note"]) > 240:
|
||||
raise InvalidRecord(f"{path}[{index}].note is too long")
|
||||
gates.append(item)
|
||||
identifiers = [gate["id"] for gate in gates]
|
||||
if len(identifiers) != len(set(identifiers)):
|
||||
raise InvalidRecord(f"{path} contains duplicate gate identifiers")
|
||||
if set(identifiers) != expected:
|
||||
missing = sorted(expected - set(identifiers))
|
||||
extra = sorted(set(identifiers) - expected)
|
||||
raise InvalidRecord(f"{path} gate mismatch; missing={missing}, extra={extra}")
|
||||
return gates
|
||||
|
||||
|
||||
def validate_local_evidence(
|
||||
record: dict[str, Any],
|
||||
gates: list[dict[str, str]],
|
||||
repository_root: pathlib.Path,
|
||||
) -> None:
|
||||
if any(gate["status"] != "pass" for gate in gates):
|
||||
return
|
||||
commit = record["evaluatedCommit"]
|
||||
release_path = evidence_path(
|
||||
repository_root,
|
||||
"docs/evidence/releases/v1.0.0-local-candidate.json",
|
||||
"local release evidence",
|
||||
)
|
||||
release = load_json(release_path, "local release evidence")
|
||||
if not isinstance(release, dict) or release.get("schemaVersion") != 1 \
|
||||
or release.get("kind") != "rendezvous-local-release-candidate" \
|
||||
or release.get("sourceCommit") != commit \
|
||||
or release.get("treeState") != "clean" \
|
||||
or release.get("result") != "pass":
|
||||
raise InvalidRecord("local release evidence is not a passing clean build of evaluatedCommit")
|
||||
verification = release.get("verification")
|
||||
if not isinstance(verification, dict):
|
||||
raise InvalidRecord("local release evidence has no verification object")
|
||||
exact_passes = {
|
||||
"lockedRestore": "pass",
|
||||
"format": "pass",
|
||||
"byteReproduciblePackages": "pass",
|
||||
"byteReproducibleServerArchive": "pass",
|
||||
"sbomChecksumsAndProvenance": "pass",
|
||||
"candidateConsumerFixtures": "pass",
|
||||
"realConsumerRestores": "pass",
|
||||
}
|
||||
if any(verification.get(key) != value for key, value in exact_passes.items()) \
|
||||
or verification.get("reportedVulnerabilities") != 0 \
|
||||
or verification.get("releaseBuildWarnings") != 0 \
|
||||
or verification.get("releaseBuildErrors") != 0 \
|
||||
or verification.get("debugTestsPassed", 0) < 300 \
|
||||
or verification.get("debugTestsFailed") != 0 \
|
||||
or verification.get("releaseTestsPassed", 0) < 300 \
|
||||
or verification.get("releaseTestsFailed") != 0 \
|
||||
or verification.get("selectedProductionFaultTestsPassed", 0) < 17:
|
||||
raise InvalidRecord("local release evidence does not satisfy every required verification")
|
||||
consumers = release.get("consumers")
|
||||
if not isinstance(consumers, list) or {
|
||||
item.get("name") for item in consumers if isinstance(item, dict)
|
||||
} != {"SpaceGame", "Unscouted"} or any(
|
||||
not isinstance(item, dict)
|
||||
or item.get("candidateRestore") != "pass"
|
||||
or item.get("directTrafficPilot") != "pass"
|
||||
for item in consumers
|
||||
):
|
||||
raise InvalidRecord("local release evidence does not prove both required consumers")
|
||||
|
||||
capacity_path = evidence_path(
|
||||
repository_root,
|
||||
"docs/evidence/capacity/v2/candidate-2cpu.json",
|
||||
"candidate capacity evidence",
|
||||
)
|
||||
capacity = load_json(capacity_path, "candidate capacity evidence")
|
||||
runtime = capacity.get("runtime") if isinstance(capacity, dict) else None
|
||||
state = capacity.get("state") if isinstance(capacity, dict) else None
|
||||
if not isinstance(runtime, dict) or not isinstance(state, dict) \
|
||||
or capacity.get("schemaVersion") != 2 \
|
||||
or capacity.get("profile") != "candidate" \
|
||||
or capacity.get("passed") is not True \
|
||||
or capacity.get("failures") != [] \
|
||||
or runtime.get("commitSha") != commit \
|
||||
or runtime.get("treeState") != "clean" \
|
||||
or runtime.get("processorCount") != 2 \
|
||||
or state.get("soakDurationSeconds", 0) < 300 \
|
||||
or state.get("finalListings") != 0 \
|
||||
or state.get("finalAttempts") != 0 \
|
||||
or state.get("finalReplayMarkers") != 0 \
|
||||
or state.get("restartStartedEmpty") is not True \
|
||||
or state.get("overloadWasTyped") is not True \
|
||||
or state.get("recoverySucceeded") is not True:
|
||||
raise InvalidRecord("candidate capacity evidence does not satisfy the clean evaluated commit")
|
||||
|
||||
|
||||
def validate_external_attestations(
|
||||
record: dict[str, Any],
|
||||
gates: list[dict[str, str]],
|
||||
repository_root: pathlib.Path,
|
||||
) -> None:
|
||||
for gate in gates:
|
||||
if gate["status"] != "pass":
|
||||
continue
|
||||
path = evidence_path(repository_root, gate["evidenceRef"], f"{gate['id']} evidence")
|
||||
attestation = load_json(path, f"{gate['id']} evidence")
|
||||
if not isinstance(attestation, dict) or set(attestation) != {
|
||||
"schemaVersion",
|
||||
"kind",
|
||||
"gateId",
|
||||
"candidateCommit",
|
||||
"result",
|
||||
"performedAtUtc",
|
||||
"artifactDigest",
|
||||
"evidenceLocation",
|
||||
"reviewerRole",
|
||||
}:
|
||||
raise InvalidRecord(f"{gate['id']} requires a complete external-gate attestation")
|
||||
reject_sensitive(attestation, f"external evidence {gate['id']}")
|
||||
if attestation["schemaVersion"] != 1 \
|
||||
or attestation["kind"] != "rendezvous-external-gate-attestation" \
|
||||
or attestation["gateId"] != gate["id"] \
|
||||
or attestation["candidateCommit"] != record["evaluatedCommit"] \
|
||||
or attestation["result"] != "pass" \
|
||||
or not isinstance(attestation["artifactDigest"], str) \
|
||||
or not DIGEST.fullmatch(attestation["artifactDigest"]) \
|
||||
or attestation["evidenceLocation"] not in {
|
||||
"protected-operations-record",
|
||||
"public-release-record",
|
||||
} \
|
||||
or attestation["reviewerRole"] not in {
|
||||
"release-operator",
|
||||
"network-operator",
|
||||
"security-operator",
|
||||
"independent-operator",
|
||||
}:
|
||||
raise InvalidRecord(f"{gate['id']} external attestation does not match the candidate gate")
|
||||
try:
|
||||
performed = datetime.fromisoformat(attestation["performedAtUtc"].replace("Z", "+00:00"))
|
||||
except (AttributeError, ValueError) as error:
|
||||
raise InvalidRecord(f"{gate['id']} has an invalid performedAtUtc") from error
|
||||
if performed.tzinfo is None or performed.utcoffset() != timedelta(0):
|
||||
raise InvalidRecord(f"{gate['id']} performedAtUtc must be UTC")
|
||||
|
||||
|
||||
def validate(record: Any, repository_root: pathlib.Path) -> tuple[bool, list[str]]:
|
||||
if not isinstance(record, dict) or set(record) != {
|
||||
"schemaVersion",
|
||||
"kind",
|
||||
"evaluatedCommit",
|
||||
"decision",
|
||||
"localGates",
|
||||
"externalGates",
|
||||
}:
|
||||
raise InvalidRecord("The top-level readiness record shape is invalid")
|
||||
if record["schemaVersion"] != 1 or record["kind"] != "rendezvous-production-readiness":
|
||||
raise InvalidRecord("The readiness schema identity is invalid")
|
||||
if not isinstance(record["evaluatedCommit"], str) or not COMMIT.fullmatch(record["evaluatedCommit"]):
|
||||
raise InvalidRecord("evaluatedCommit must be a full lowercase Git commit")
|
||||
reject_sensitive(record)
|
||||
local_gates = validate_gate_set(
|
||||
record["localGates"], LOCAL_GATES, "$.localGates", repository_root
|
||||
)
|
||||
external_gates = validate_gate_set(
|
||||
record["externalGates"], EXTERNAL_GATES, "$.externalGates", repository_root
|
||||
)
|
||||
validate_local_evidence(record, local_gates, repository_root)
|
||||
validate_external_attestations(record, external_gates, repository_root)
|
||||
gates = local_gates + external_gates
|
||||
blockers = sorted(gate["id"] for gate in gates if gate["status"] != "pass")
|
||||
ready = not blockers
|
||||
expected_decision = "ready" if ready else "not-ready"
|
||||
if record["decision"] != expected_decision:
|
||||
raise InvalidRecord(
|
||||
f"decision must be {expected_decision!r} for the recorded gate statuses"
|
||||
)
|
||||
return ready, blockers
|
||||
|
||||
|
||||
def main() -> int:
|
||||
if len(sys.argv) != 2:
|
||||
print("usage: check_production_readiness.py RECORD", file=sys.stderr)
|
||||
return 2
|
||||
try:
|
||||
with open(sys.argv[1], "r", encoding="utf-8") as source:
|
||||
record = json.load(source)
|
||||
ready, blockers = validate(record, pathlib.Path(__file__).resolve().parent.parent)
|
||||
except (OSError, json.JSONDecodeError, InvalidRecord) as error:
|
||||
print(f"INVALID: {error}", file=sys.stderr)
|
||||
return 2
|
||||
if not ready:
|
||||
print(f"NOT READY: {len(blockers)} required gate(s) are not passing.")
|
||||
for blocker in blockers:
|
||||
print(f"- {blocker}")
|
||||
return 3
|
||||
print("READY: every required v1 production gate is recorded as passing.")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
@@ -4,13 +4,13 @@
|
||||
{
|
||||
"name": "SpaceGame",
|
||||
"repository": "https://git.finalfactory.de/Kyuubi/SpaceGame.git",
|
||||
"revision": "77519b0cc418a27f8d408ae2d7b8812fbe087c04",
|
||||
"revision": "f3f5bc29810c362656cd7143bec1ddc2cfaf9f22",
|
||||
"project": "SpaceGame.csproj"
|
||||
},
|
||||
{
|
||||
"name": "Unscouted",
|
||||
"repository": "https://git.finalfactory.de/HeiKyu/Unscouted.git",
|
||||
"revision": "7807dbee86eb8b98e702f1eb89c88adff728f635",
|
||||
"revision": "f0574a7de82aadff6495ca5657dfc19cf7c2f67c",
|
||||
"project": "Net.Core/Net.Core.csproj"
|
||||
}
|
||||
]
|
||||
|
||||
Executable
+7
@@ -0,0 +1,7 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||
RECORD="${1:-$ROOT/docs/evidence/production-readiness-v1.json}"
|
||||
|
||||
exec python3 "$ROOT/eng/check_production_readiness.py" "$RECORD"
|
||||
@@ -3,9 +3,25 @@ set -euo pipefail
|
||||
|
||||
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||
LOCAL_KEY="${RENDEZVOUS_SMOKE_LOCAL_KEY:-$ROOT/deploy/compose/secrets/signing-key}"
|
||||
GAME_ID="${RENDEZVOUS_LOCAL_CREDENTIAL_GAME_ID:-space-game}"
|
||||
|
||||
case "$GAME_ID" in
|
||||
space-game)
|
||||
KEY_ID="local-smoke-1"
|
||||
SUBJECT="local-smoke-host"
|
||||
;;
|
||||
unscouted)
|
||||
KEY_ID="local-smoke-unscouted-1"
|
||||
SUBJECT="local-smoke-unscouted-host"
|
||||
;;
|
||||
*)
|
||||
printf 'RENDEZVOUS_LOCAL_CREDENTIAL_GAME_ID must be space-game or unscouted.\n' >&2
|
||||
exit 2
|
||||
;;
|
||||
esac
|
||||
|
||||
if (( $# != 0 )); then
|
||||
printf 'This helper accepts no arguments and mints only the fixed local Compose smoke scope.\n' >&2
|
||||
printf 'This helper accepts no arguments; select only a provisioned local game through RENDEZVOUS_LOCAL_CREDENTIAL_GAME_ID.\n' >&2
|
||||
exit 2
|
||||
fi
|
||||
|
||||
@@ -17,7 +33,7 @@ command -v python3 >/dev/null || {
|
||||
# This is deliberately a local-fixture tool, not a general credential issuer.
|
||||
# Python reads the raw key from the protected file; key material never appears in
|
||||
# a child process argument, environment value, temporary file, or command output.
|
||||
python3 - "$LOCAL_KEY" <<'PY'
|
||||
python3 - "$LOCAL_KEY" "$GAME_ID" "$KEY_ID" "$SUBJECT" <<'PY'
|
||||
import base64
|
||||
import hashlib
|
||||
import hmac
|
||||
@@ -29,6 +45,9 @@ import sys
|
||||
import time
|
||||
|
||||
key_path = sys.argv[1]
|
||||
game_id = sys.argv[2]
|
||||
key_id = sys.argv[3]
|
||||
subject = sys.argv[4]
|
||||
try:
|
||||
metadata = os.lstat(key_path)
|
||||
except FileNotFoundError:
|
||||
@@ -55,9 +74,9 @@ payload = {
|
||||
"version": 1,
|
||||
"issuer": "final-factory-rendezvous-smoke",
|
||||
"audience": "rendezvous-service",
|
||||
"subject": "local-smoke-host",
|
||||
"subject": subject,
|
||||
"kind": "dedicatedPublisher",
|
||||
"gameId": "space-game",
|
||||
"gameId": game_id,
|
||||
"environmentId": "smoke",
|
||||
"regions": ["local"],
|
||||
"permissions": [],
|
||||
@@ -71,7 +90,7 @@ def base64url(value: bytes) -> str:
|
||||
return base64.urlsafe_b64encode(value).rstrip(b"=").decode("ascii")
|
||||
|
||||
encoded = base64url(json.dumps(payload, separators=(",", ":")).encode("utf-8"))
|
||||
signed = f"rv1.local-smoke-1.{encoded}"
|
||||
signed = f"rv1.{key_id}.{encoded}"
|
||||
signature = base64url(hmac.new(key, signed.encode("ascii"), hashlib.sha256).digest())
|
||||
print(f"{signed}.{signature}")
|
||||
PY
|
||||
|
||||
Executable
+243
@@ -0,0 +1,243 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||
PROJECT="$ROOT/src/FinalFactory.Rendezvous.TestClient/FinalFactory.Rendezvous.TestClient.csproj"
|
||||
ROLE="${RENDEZVOUS_CANARY_ROLE:-}"
|
||||
TOPOLOGY="${RENDEZVOUS_CANARY_TOPOLOGY:-}"
|
||||
ADDRESS_FAMILY="${RENDEZVOUS_CANARY_ADDRESS_FAMILY:-ipv4}"
|
||||
SERVICE_URL="${RENDEZVOUS_CANARY_HTTP_URL:-}"
|
||||
MEDIATOR="${RENDEZVOUS_CANARY_UDP_ENDPOINT:-}"
|
||||
GAME_ID="${RENDEZVOUS_CANARY_GAME_ID:-space-game}"
|
||||
ENVIRONMENT_ID="${RENDEZVOUS_CANARY_ENVIRONMENT_ID:-production-canary}"
|
||||
REGION="${RENDEZVOUS_CANARY_REGION:-production-canary}"
|
||||
PROTOCOL_VERSION="${RENDEZVOUS_CANARY_PROTOCOL_VERSION:-1}"
|
||||
TIMEOUT_SECONDS="${RENDEZVOUS_CANARY_TIMEOUT_SECONDS:-60}"
|
||||
RUN_SECONDS="${RENDEZVOUS_CANARY_RUN_SECONDS:-900}"
|
||||
OUTPUT="${RENDEZVOUS_CANARY_OUTPUT:-$ROOT/artifacts/canary/${ROLE:-unknown}-${TOPOLOGY:-unknown}.json}"
|
||||
COORDINATION_FILE="${RENDEZVOUS_CANARY_COORDINATION_FILE:-}"
|
||||
LISTING_ID="${RENDEZVOUS_CANARY_LISTING_ID:-}"
|
||||
REQUIRE_CLEAN="${RENDEZVOUS_CANARY_REQUIRE_CLEAN:-true}"
|
||||
KEEP_RAW="${RENDEZVOUS_CANARY_KEEP_RAW:-false}"
|
||||
UUID_PATTERN='^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$'
|
||||
|
||||
usage() {
|
||||
printf '%s\n' \
|
||||
'Set RENDEZVOUS_CANARY_ROLE to host, client-success, or client-expected-failure.' \
|
||||
'Also set RENDEZVOUS_CANARY_TOPOLOGY, RENDEZVOUS_CANARY_HTTP_URL, and' \
|
||||
'RENDEZVOUS_CANARY_UDP_ENDPOINT. See docs/operations/production-readiness.md.' >&2
|
||||
exit 2
|
||||
}
|
||||
|
||||
for command in date dotnet git jq mktemp tail; do
|
||||
command -v "$command" >/dev/null || {
|
||||
printf 'Missing required command: %s\n' "$command" >&2
|
||||
exit 2
|
||||
}
|
||||
done
|
||||
|
||||
case "$ROLE" in
|
||||
host|client-success|client-expected-failure) ;;
|
||||
*) usage ;;
|
||||
esac
|
||||
case "$TOPOLOGY" in
|
||||
same-lan|home-nat|firewall-blocked-udp|restrictive-cgnat|ipv6-direct) ;;
|
||||
*) usage ;;
|
||||
esac
|
||||
case "$ADDRESS_FAMILY" in
|
||||
ipv4|ipv6) ;;
|
||||
*) printf 'RENDEZVOUS_CANARY_ADDRESS_FAMILY must be ipv4 or ipv6.\n' >&2; exit 2 ;;
|
||||
esac
|
||||
if [[ "$TOPOLOGY" == ipv6-direct && "$ADDRESS_FAMILY" != ipv6 ]]; then
|
||||
printf 'The ipv6-direct topology requires RENDEZVOUS_CANARY_ADDRESS_FAMILY=ipv6.\n' >&2
|
||||
exit 2
|
||||
fi
|
||||
if [[ "$TOPOLOGY" =~ ^(firewall-blocked-udp|restrictive-cgnat)$ \
|
||||
&& "$ROLE" == client-success ]]; then
|
||||
printf 'Failure topologies must use the client-expected-failure role.\n' >&2
|
||||
exit 2
|
||||
fi
|
||||
if [[ -z "$SERVICE_URL" || -z "$MEDIATOR" ]]; then
|
||||
usage
|
||||
fi
|
||||
if [[ ! "$TIMEOUT_SECONDS" =~ ^[0-9]+$ ]] \
|
||||
|| (( TIMEOUT_SECONDS < 1 || TIMEOUT_SECONDS > 300 )); then
|
||||
printf 'RENDEZVOUS_CANARY_TIMEOUT_SECONDS must be an integer from 1 through 300.\n' >&2
|
||||
exit 2
|
||||
fi
|
||||
if [[ ! "$RUN_SECONDS" =~ ^[0-9]+$ ]] \
|
||||
|| (( RUN_SECONDS < 60 || RUN_SECONDS > 3600 )); then
|
||||
printf 'RENDEZVOUS_CANARY_RUN_SECONDS must be an integer from 60 through 3600.\n' >&2
|
||||
exit 2
|
||||
fi
|
||||
if [[ ! "$PROTOCOL_VERSION" =~ ^[0-9]+$ ]] || (( PROTOCOL_VERSION < 1 )); then
|
||||
printf 'RENDEZVOUS_CANARY_PROTOCOL_VERSION must be a positive integer.\n' >&2
|
||||
exit 2
|
||||
fi
|
||||
if [[ "$REQUIRE_CLEAN" != true && "$REQUIRE_CLEAN" != false ]]; then
|
||||
printf 'RENDEZVOUS_CANARY_REQUIRE_CLEAN must be true or false.\n' >&2
|
||||
exit 2
|
||||
fi
|
||||
if [[ "$KEEP_RAW" != true && "$KEEP_RAW" != false ]]; then
|
||||
printf 'RENDEZVOUS_CANARY_KEEP_RAW must be true or false.\n' >&2
|
||||
exit 2
|
||||
fi
|
||||
|
||||
cd "$ROOT"
|
||||
commit="$(git rev-parse HEAD)"
|
||||
tree_state=clean
|
||||
if [[ -n "$(git status --porcelain)" ]]; then
|
||||
tree_state=dirty
|
||||
fi
|
||||
if [[ "$REQUIRE_CLEAN" == true && "$tree_state" != clean ]]; then
|
||||
printf 'Formal canary evidence requires a clean source tree.\n' >&2
|
||||
exit 2
|
||||
fi
|
||||
|
||||
if [[ "$ROLE" == host ]]; then
|
||||
if [[ -z "$COORDINATION_FILE" ]]; then
|
||||
printf 'The host role requires RENDEZVOUS_CANARY_COORDINATION_FILE.\n' >&2
|
||||
exit 2
|
||||
fi
|
||||
if [[ -e "$COORDINATION_FILE" ]]; then
|
||||
printf 'The host coordination file already exists; remove it explicitly before a new canary.\n' >&2
|
||||
exit 2
|
||||
fi
|
||||
if [[ -z "${RENDEZVOUS_PUBLISHER_CREDENTIAL:-}" ]]; then
|
||||
printf 'The host role requires RENDEZVOUS_PUBLISHER_CREDENTIAL.\n' >&2
|
||||
exit 2
|
||||
fi
|
||||
else
|
||||
if [[ ! "$LISTING_ID" =~ $UUID_PATTERN ]]; then
|
||||
printf 'A client role requires a UUID in RENDEZVOUS_CANARY_LISTING_ID.\n' >&2
|
||||
exit 2
|
||||
fi
|
||||
fi
|
||||
|
||||
umask 077
|
||||
raw_dir="$(mktemp -d "${TMPDIR:-/tmp}/rendezvous-canary.XXXXXXXX")"
|
||||
raw_log="$raw_dir/events.jsonl"
|
||||
run_succeeded=false
|
||||
host_pid=''
|
||||
cleanup() {
|
||||
local status="$?"
|
||||
if [[ -n "$host_pid" ]] && kill -0 "$host_pid" 2>/dev/null; then
|
||||
kill -TERM "$host_pid" 2>/dev/null || true
|
||||
wait "$host_pid" 2>/dev/null || true
|
||||
fi
|
||||
if [[ "$run_succeeded" == true && "$KEEP_RAW" == false ]]; then
|
||||
rm -rf "$raw_dir"
|
||||
else
|
||||
printf 'Private raw canary events retained at %s\n' "$raw_dir" >&2
|
||||
fi
|
||||
return "$status"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
trap 'exit 130' INT
|
||||
trap 'exit 143' TERM
|
||||
|
||||
common_arguments=(
|
||||
--service "$SERVICE_URL"
|
||||
--mediator "$MEDIATOR"
|
||||
--game "$GAME_ID"
|
||||
--environment "$ENVIRONMENT_ID"
|
||||
--region "$REGION"
|
||||
--protocol "$PROTOCOL_VERSION"
|
||||
--script
|
||||
--json
|
||||
--timeout-seconds "$TIMEOUT_SECONDS"
|
||||
)
|
||||
|
||||
exit_code=0
|
||||
if [[ "$ROLE" == host ]]; then
|
||||
dotnet run --project "$PROJECT" --configuration Release --no-build -- \
|
||||
host "${common_arguments[@]}" --exit-after-echo --run-seconds "$RUN_SECONDS" \
|
||||
>"$raw_log" 2>&1 &
|
||||
host_pid="$!"
|
||||
ready=false
|
||||
for ((iteration = 0; iteration < TIMEOUT_SECONDS * 4; iteration++)); do
|
||||
if jq -e 'select(.event == "host.ready" and .status == "ready")' "$raw_log" \
|
||||
>/dev/null 2>&1; then
|
||||
ready=true
|
||||
break
|
||||
fi
|
||||
if ! kill -0 "$host_pid" 2>/dev/null; then
|
||||
break
|
||||
fi
|
||||
sleep 0.25
|
||||
done
|
||||
if [[ "$ready" != true ]]; then
|
||||
printf 'The canary host did not become ready within the bounded startup window.\n' >&2
|
||||
kill -TERM "$host_pid" 2>/dev/null || true
|
||||
wait "$host_pid" 2>/dev/null || true
|
||||
exit 1
|
||||
fi
|
||||
observed_listing="$(jq -r 'select(.event == "host.registered") | .listingId' "$raw_log" | tail -n 1)"
|
||||
if [[ ! "$observed_listing" =~ $UUID_PATTERN ]]; then
|
||||
printf 'The canary host did not produce a valid coordination identifier.\n' >&2
|
||||
kill -TERM "$host_pid" 2>/dev/null || true
|
||||
wait "$host_pid" 2>/dev/null || true
|
||||
exit 1
|
||||
fi
|
||||
coordination_parent="$(dirname "$COORDINATION_FILE")"
|
||||
mkdir -p "$coordination_parent"
|
||||
coordination_temp="$(mktemp "$COORDINATION_FILE.tmp.XXXXXXXX")"
|
||||
printf '%s\n' "$observed_listing" >"$coordination_temp"
|
||||
mv "$coordination_temp" "$COORDINATION_FILE"
|
||||
printf 'Host ready; securely transfer the private coordination file to the client operator.\n'
|
||||
set +e
|
||||
wait "$host_pid"
|
||||
exit_code="$?"
|
||||
set -e
|
||||
elif [[ "$ROLE" == client-success ]]; then
|
||||
set +e
|
||||
dotnet run --project "$PROJECT" --configuration Release --no-build -- \
|
||||
join "${common_arguments[@]}" --listing "$LISTING_ID" >"$raw_log" 2>&1
|
||||
exit_code="$?"
|
||||
set -e
|
||||
else
|
||||
set +e
|
||||
dotnet run --project "$PROJECT" --configuration Release --no-build -- \
|
||||
join "${common_arguments[@]}" --listing "$LISTING_ID" >"$raw_log" 2>&1
|
||||
exit_code="$?"
|
||||
set -e
|
||||
fi
|
||||
|
||||
checks='{}'
|
||||
if [[ "$ROLE" == host ]]; then
|
||||
[[ "$exit_code" -eq 0 ]]
|
||||
jq -e --arg family "$ADDRESS_FAMILY" 'select(.event == "host.direct-traffic" and .status == "verified" and .addressFamily == $family)' "$raw_log" >/dev/null
|
||||
jq -e 'select(.event == "host.deregistered" and .status == "complete")' "$raw_log" >/dev/null
|
||||
checks='{"authenticatedDirectTraffic":true,"deregistered":true}'
|
||||
elif [[ "$ROLE" == client-success ]]; then
|
||||
[[ "$exit_code" -eq 0 ]]
|
||||
jq -e --arg family "$ADDRESS_FAMILY" 'select(.event == "join.connected" and .status == "connected" and .addressFamily == $family)' "$raw_log" >/dev/null
|
||||
jq -e --arg family "$ADDRESS_FAMILY" 'select(.event == "join.direct-traffic" and .status == "verified" and .addressFamily == $family)' "$raw_log" >/dev/null
|
||||
jq -e 'select(.event == "join.outcome-report" and .status == "accepted")' "$raw_log" >/dev/null
|
||||
checks='{"authenticatedDirectTraffic":true,"typedOutcomeReported":true}'
|
||||
else
|
||||
[[ "$exit_code" -eq 12 ]]
|
||||
jq -e 'select((.event == "join.traversal" or .event == "join.authorization") and .status == "failed" and (.outcome | type == "string") and (.outcome | length > 0))' "$raw_log" >/dev/null
|
||||
jq -e 'select(.event == "join.fallback" and (.status == "available" or .status == "unavailable") and (.outcome | type == "string") and (.outcome | length > 0))' "$raw_log" >/dev/null
|
||||
checks='{"boundedTypedFailure":true,"fallbackPolicyReported":true}'
|
||||
fi
|
||||
|
||||
mkdir -p "$(dirname "$OUTPUT")"
|
||||
raw_retention=deleted-after-success
|
||||
if [[ "$KEEP_RAW" == true ]]; then
|
||||
raw_retention=retained-private-on-request
|
||||
fi
|
||||
jq -n \
|
||||
--arg commit "$commit" \
|
||||
--arg treeState "$tree_state" \
|
||||
--arg timestampUtc "$(date -u +%Y-%m-%dT%H:%M:%SZ)" \
|
||||
--arg role "$ROLE" \
|
||||
--arg topology "$TOPOLOGY" \
|
||||
--arg addressFamily "$ADDRESS_FAMILY" \
|
||||
--arg rawEvents "$raw_retention" \
|
||||
--argjson checks "$checks" \
|
||||
'{schemaVersion:1,kind:"rendezvous-real-network-canary",commit:$commit,treeState:$treeState,timestampUtc:$timestampUtc,role:$role,topology:$topology,addressFamily:$addressFamily,result:"pass",checks:$checks,dataRetention:{rawEvents:$rawEvents,identifiers:"not-in-summary",networkEndpoints:"not-in-summary"}}' \
|
||||
>"$OUTPUT"
|
||||
|
||||
run_succeeded=true
|
||||
printf 'Real-network canary passed; sanitized evidence: %s\n' "$OUTPUT"
|
||||
@@ -47,6 +47,8 @@ for ((index = 0; index < count; index++)); do
|
||||
cat >"$targets" <<EOF
|
||||
<Project>
|
||||
<ItemGroup Condition="'\$(MSBuildProjectFullPath)' == '$project'">
|
||||
<PackageReference Remove="FinalFactory.Rendezvous.Client" />
|
||||
<PackageReference Remove="FinalFactory.Rendezvous.Contracts" />
|
||||
<PackageReference Include="FinalFactory.Rendezvous.Client" Version="[$version]" />
|
||||
<PackageReference Include="FinalFactory.Rendezvous.Contracts" Version="[$version]" />
|
||||
</ItemGroup>
|
||||
|
||||
@@ -114,11 +114,12 @@ internal sealed class RendezvousCommandRunner : ITestClientCommandRunner
|
||||
listingId: session.ListingId.ToString(),
|
||||
displayName: options.DisplayName);
|
||||
echo = new DirectEchoProtocol(events.GameplayEvents, host: true);
|
||||
echo.ExchangeCompleted += _ => output.Write(
|
||||
echo.ExchangeCompleted += peer => output.Write(
|
||||
"host.direct-traffic",
|
||||
"verified",
|
||||
phase: "direct-traffic",
|
||||
endpointType: "peer-to-peer");
|
||||
endpointType: "peer-to-peer",
|
||||
addressFamily: AddressFamilyName(peer.Address));
|
||||
coordinator = new RendezvousHostCoordinator(
|
||||
manager,
|
||||
events,
|
||||
@@ -485,6 +486,7 @@ internal sealed class RendezvousCommandRunner : ITestClientCommandRunner
|
||||
"connected",
|
||||
phase: "direct-connection",
|
||||
endpointType: endpointType,
|
||||
addressFamily: AddressFamilyName(peer.Address),
|
||||
elapsedMilliseconds: ToMilliseconds(outcome.Elapsed));
|
||||
await ReportOutcomeAsync(coordinator, joins, output, cancellationToken).ConfigureAwait(false);
|
||||
echo.BeginJoin(peer);
|
||||
@@ -507,7 +509,8 @@ internal sealed class RendezvousCommandRunner : ITestClientCommandRunner
|
||||
"join.direct-traffic",
|
||||
"verified",
|
||||
phase: "direct-traffic",
|
||||
endpointType: endpointType);
|
||||
endpointType: endpointType,
|
||||
addressFamily: AddressFamilyName(peer.Address));
|
||||
peer.Disconnect();
|
||||
manager.PollEvents();
|
||||
return TestClientExitCode.Success;
|
||||
@@ -765,6 +768,9 @@ internal sealed class RendezvousCommandRunner : ITestClientCommandRunner
|
||||
return privateAddress ? "private" : "public";
|
||||
}
|
||||
|
||||
private static string AddressFamilyName(IPAddress address) =>
|
||||
address.AddressFamily == AddressFamily.InterNetworkV6 ? "ipv6" : "ipv4";
|
||||
|
||||
private static long ToMilliseconds(TimeSpan elapsed) =>
|
||||
(long)Math.Min(long.MaxValue, Math.Max(0, elapsed.TotalMilliseconds));
|
||||
|
||||
|
||||
@@ -24,6 +24,7 @@ internal sealed class TestClientOutput(TextWriter standardOutput, TextWriter sta
|
||||
string? displayName = null,
|
||||
string? outcome = null,
|
||||
string? endpointType = null,
|
||||
string? addressFamily = null,
|
||||
int? count = null,
|
||||
long? elapsedMilliseconds = null,
|
||||
string? message = null) => WriteCore(
|
||||
@@ -37,6 +38,7 @@ internal sealed class TestClientOutput(TextWriter standardOutput, TextWriter sta
|
||||
DisplayName = SafeText(displayName),
|
||||
Outcome = SafeToken(outcome),
|
||||
EndpointType = SafeToken(endpointType),
|
||||
AddressFamily = SafeToken(addressFamily),
|
||||
Count = count,
|
||||
ElapsedMilliseconds = elapsedMilliseconds,
|
||||
Message = SafeText(message),
|
||||
@@ -92,6 +94,7 @@ internal sealed class TestClientOutput(TextWriter standardOutput, TextWriter sta
|
||||
Append(line, "name", item.DisplayName, quote: true);
|
||||
Append(line, "outcome", item.Outcome);
|
||||
Append(line, "endpoint", item.EndpointType);
|
||||
Append(line, "addressFamily", item.AddressFamily);
|
||||
if (item.Count.HasValue)
|
||||
{
|
||||
Append(line, "count", item.Count.Value.ToString(System.Globalization.CultureInfo.InvariantCulture));
|
||||
@@ -174,6 +177,7 @@ internal sealed class TestClientOutput(TextWriter standardOutput, TextWriter sta
|
||||
public string? DisplayName { get; init; }
|
||||
public string? Outcome { get; init; }
|
||||
public string? EndpointType { get; init; }
|
||||
public string? AddressFamily { get; init; }
|
||||
public int? Count { get; init; }
|
||||
public long? ElapsedMilliseconds { get; init; }
|
||||
public string? Message { get; init; }
|
||||
|
||||
@@ -238,6 +238,10 @@ public sealed class ProductionProcessTests
|
||||
"--Rendezvous:Provisioning:SigningKeys:0:NotBefore", now.AddHours(-1).ToString("O"),
|
||||
"--Rendezvous:Provisioning:SigningKeys:0:SignUntil", now.AddHours(1).ToString("O"),
|
||||
"--Rendezvous:Provisioning:SigningKeys:0:VerifyUntil", now.AddHours(2).ToString("O"),
|
||||
"--Rendezvous:Provisioning:SigningKeys:1:SecretReference", $"file:{secretPath}",
|
||||
"--Rendezvous:Provisioning:SigningKeys:1:NotBefore", now.AddHours(-1).ToString("O"),
|
||||
"--Rendezvous:Provisioning:SigningKeys:1:SignUntil", now.AddHours(1).ToString("O"),
|
||||
"--Rendezvous:Provisioning:SigningKeys:1:VerifyUntil", now.AddHours(2).ToString("O"),
|
||||
"--Rendezvous:Udp:Port", udpPort.ToString(System.Globalization.CultureInfo.InvariantCulture),
|
||||
"--Rendezvous:Deployment:PublicUdpPort", udpPort.ToString(System.Globalization.CultureInfo.InvariantCulture),
|
||||
},
|
||||
|
||||
@@ -40,14 +40,19 @@ public sealed partial class DocumentationContractTests
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public void LocalCredentialHelperIsFixedScopeAndSmokeDelegatesToIt()
|
||||
public void LocalCredentialHelperWhitelistsProvisionedGameScopesAndSmokeDelegatesToIt()
|
||||
{
|
||||
string root = FindRepositoryRoot();
|
||||
string helper = File.ReadAllText(Path.Combine(root, "scripts", "mint-local-publisher-credential.sh"));
|
||||
string smoke = File.ReadAllText(Path.Combine(root, "scripts", "smoke-deployment.sh"));
|
||||
|
||||
Assert.Contains("if (( $# != 0 ));", helper, StringComparison.Ordinal);
|
||||
Assert.Contains("\"gameId\": \"space-game\"", helper, StringComparison.Ordinal);
|
||||
Assert.Contains("space-game)", helper, StringComparison.Ordinal);
|
||||
Assert.Contains("unscouted)", helper, StringComparison.Ordinal);
|
||||
Assert.Contains("KEY_ID=\"local-smoke-1\"", helper, StringComparison.Ordinal);
|
||||
Assert.Contains("KEY_ID=\"local-smoke-unscouted-1\"", helper, StringComparison.Ordinal);
|
||||
Assert.Contains("RENDEZVOUS_LOCAL_CREDENTIAL_GAME_ID must be space-game or unscouted", helper, StringComparison.Ordinal);
|
||||
Assert.Contains("\"gameId\": game_id", helper, StringComparison.Ordinal);
|
||||
Assert.Contains("\"environmentId\": \"smoke\"", helper, StringComparison.Ordinal);
|
||||
Assert.Contains("\"regions\": [\"local\"]", helper, StringComparison.Ordinal);
|
||||
Assert.Contains("now + 600", helper, StringComparison.Ordinal);
|
||||
@@ -60,6 +65,32 @@ public sealed partial class DocumentationContractTests
|
||||
Assert.DoesNotContain("openssl dgst", smoke, StringComparison.Ordinal);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public void UnscoutedComposeTenantIsGameScopedAndMetadataBounded()
|
||||
{
|
||||
string root = FindRepositoryRoot();
|
||||
using JsonDocument settings = JsonDocument.Parse(File.ReadAllText(
|
||||
Path.Combine(root, "deploy", "compose", "appsettings.Production.json")));
|
||||
JsonElement provisioning = settings.RootElement.GetProperty("Rendezvous").GetProperty("Provisioning");
|
||||
JsonElement game = provisioning.GetProperty("Games").EnumerateArray().Single(
|
||||
static item => item.GetProperty("GameId").GetString() == "unscouted");
|
||||
JsonElement key = provisioning.GetProperty("SigningKeys").EnumerateArray().Single(
|
||||
static item => item.GetProperty("KeyId").GetString() == "local-smoke-unscouted-1");
|
||||
|
||||
Assert.Equal("smoke", game.GetProperty("EnvironmentId").GetString());
|
||||
Assert.Equal([1], game.GetProperty("ProtocolVersions").EnumerateArray().Select(static value => value.GetInt32()));
|
||||
Assert.Equal(["mode", "mods", "world"], game.GetProperty("MetadataValueMaxBytes")
|
||||
.EnumerateObject().Select(static property => property.Name).Order(StringComparer.Ordinal));
|
||||
Assert.Equal(["mode", "mods", "world"], game.GetProperty("RequiredMetadataKeys")
|
||||
.EnumerateArray().Select(static value => value.GetString()).Order(StringComparer.Ordinal));
|
||||
Assert.Equal(3, game.GetProperty("MetadataMaxKeys").GetInt32());
|
||||
Assert.Equal("DedicatedEndpointAllowed", game.GetProperty("FallbackPolicy").GetString());
|
||||
Assert.Equal("unscouted", key.GetProperty("GameId").GetString());
|
||||
Assert.Equal("smoke", key.GetProperty("EnvironmentId").GetString());
|
||||
Assert.Equal(["DedicatedPublisher"], key.GetProperty("CredentialKinds")
|
||||
.EnumerateArray().Select(static value => value.GetString()));
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public void EveryIncidentRunbookHasDetectContainRecoverAndVerifyGates()
|
||||
{
|
||||
@@ -228,6 +259,37 @@ public sealed partial class DocumentationContractTests
|
||||
Assert.DoesNotMatch(ReusableCredential(), guide);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public void UnscoutedPilotEvidenceProvesAnIndependentGameBoundaryAndKeepsExternalGatesOpen()
|
||||
{
|
||||
string root = FindRepositoryRoot();
|
||||
string guide = File.ReadAllText(Path.Combine(root, "docs", "integration", "unscouted-pilot.md"));
|
||||
using JsonDocument evidence = JsonDocument.Parse(File.ReadAllText(
|
||||
Path.Combine(root, "docs", "evidence", "consumers", "unscouted.json")));
|
||||
JsonElement record = evidence.RootElement;
|
||||
JsonElement run = record.GetProperty("godotRun");
|
||||
JsonElement negative = record.GetProperty("negativePaths");
|
||||
|
||||
Assert.Equal("checkpoint-pass-with-external-gates", record.GetProperty("result").GetString());
|
||||
Assert.Equal("unscouted", record.GetProperty("configuration").GetProperty("gameId").GetString());
|
||||
Assert.Equal(["mode", "world", "mods"], record.GetProperty("configuration").GetProperty("metadataKeys")
|
||||
.EnumerateArray().Select(static value => value.GetString()));
|
||||
Assert.Equal("none", run.GetProperty("rendezvousGameplayPayloadPath").GetString());
|
||||
Assert.Equal("unscouted-litenetlib", run.GetProperty("gameplayTransport").GetString());
|
||||
Assert.True(run.GetProperty("directGameplay").GetBoolean());
|
||||
Assert.True(run.GetProperty("fallbackGameplay").GetBoolean());
|
||||
Assert.Equal(2, run.GetProperty("authenticatedSessions").GetInt32());
|
||||
Assert.Equal("proven-exact-NotFound", negative.GetProperty("wrongGame").GetString());
|
||||
Assert.Equal("proven-exact-NotFound", negative.GetProperty("wrongEnvironment").GetString());
|
||||
Assert.Equal(3310, record.GetProperty("verification").GetProperty("consumerDebugTests").GetProperty("passed").GetInt32());
|
||||
Assert.Equal(360, record.GetProperty("verification").GetProperty("consumerGdUnitTests").GetProperty("passed").GetInt32());
|
||||
Assert.Contains("public-package-restore", record.GetProperty("openGates").EnumerateArray().Select(static gate => gate.GetString()));
|
||||
Assert.Contains("representative-external-nat", record.GetProperty("openGates").EnumerateArray().Select(static gate => gate.GetString()));
|
||||
Assert.Contains("Do not mark #22 passed", guide, StringComparison.Ordinal);
|
||||
Assert.Contains("not an Unscouted branch", guide, StringComparison.Ordinal);
|
||||
Assert.DoesNotMatch(ReusableCredential(), guide);
|
||||
}
|
||||
|
||||
[GeneratedRegex(@"rv1\.[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+", RegexOptions.CultureInvariant)]
|
||||
private static partial Regex ReusableCredential();
|
||||
|
||||
|
||||
@@ -143,6 +143,10 @@ public sealed class ReleaseCompatibilityTests
|
||||
pinnedConsumers.Select(static item => item.GetProperty("name").GetString()!).ToArray());
|
||||
Assert.All(pinnedConsumers, static item =>
|
||||
Assert.Matches("^[0-9a-f]{40}$", item.GetProperty("revision").GetString()));
|
||||
|
||||
string realConsumerGate = File.ReadAllText(Path.Combine(root, "scripts", "verify-real-consumers.sh"));
|
||||
Assert.Contains("<PackageReference Remove=\"FinalFactory.Rendezvous.Client\" />", realConsumerGate, StringComparison.Ordinal);
|
||||
Assert.Contains("<PackageReference Remove=\"FinalFactory.Rendezvous.Contracts\" />", realConsumerGate, StringComparison.Ordinal);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
@@ -164,6 +168,52 @@ public sealed class ReleaseCompatibilityTests
|
||||
Assert.Equal(actual, declared);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public void ProductionReadinessRecordIsFailClosedAndCanaryEvidenceIsRedacted()
|
||||
{
|
||||
string root = FindRepositoryRoot();
|
||||
using JsonDocument readiness = JsonDocument.Parse(File.ReadAllText(Path.Combine(
|
||||
root,
|
||||
"docs/evidence/production-readiness-v1.json")));
|
||||
JsonElement document = readiness.RootElement;
|
||||
Assert.Equal(1, document.GetProperty("schemaVersion").GetInt32());
|
||||
Assert.Equal("rendezvous-production-readiness", document.GetProperty("kind").GetString());
|
||||
Assert.Matches("^[0-9a-f]{40}$", document.GetProperty("evaluatedCommit").GetString());
|
||||
|
||||
JsonElement[] local = document.GetProperty("localGates").EnumerateArray().ToArray();
|
||||
JsonElement[] external = document.GetProperty("externalGates").EnumerateArray().ToArray();
|
||||
Assert.Equal(6, local.Length);
|
||||
Assert.Equal(13, external.Length);
|
||||
JsonElement[] gates = local.Concat(external).ToArray();
|
||||
Assert.Equal(gates.Length, gates.Select(static gate => gate.GetProperty("id").GetString()).Distinct().Count());
|
||||
Assert.All(gates, static gate =>
|
||||
{
|
||||
Assert.True(gate.GetProperty("status").GetString() is "pass" or "pending" or "fail");
|
||||
string evidence = Assert.IsType<string>(gate.GetProperty("evidenceRef").GetString());
|
||||
Assert.False(Path.IsPathRooted(evidence));
|
||||
Assert.DoesNotContain("..", evidence, StringComparison.Ordinal);
|
||||
Assert.True(gate.GetProperty("note").GetString()!.Length <= 240);
|
||||
});
|
||||
bool allPass = gates.All(static gate => gate.GetProperty("status").GetString() == "pass");
|
||||
Assert.Equal(allPass ? "ready" : "not-ready", document.GetProperty("decision").GetString());
|
||||
|
||||
string canary = File.ReadAllText(Path.Combine(root, "scripts/run-real-network-canary.sh"));
|
||||
Assert.Contains("umask 077", canary, StringComparison.Ordinal);
|
||||
Assert.Contains("client-expected-failure", canary, StringComparison.Ordinal);
|
||||
Assert.Contains("exit_code\" -eq 12", canary, StringComparison.Ordinal);
|
||||
Assert.Contains(".addressFamily == $family", canary, StringComparison.Ordinal);
|
||||
Assert.Contains("identifiers:\"not-in-summary\"", canary, StringComparison.Ordinal);
|
||||
Assert.DoesNotContain("jq -c . \"$raw_log\"", canary, StringComparison.Ordinal);
|
||||
|
||||
string checker = File.ReadAllText(Path.Combine(root, "eng/check_production_readiness.py"));
|
||||
Assert.Contains("return 3", checker, StringComparison.Ordinal);
|
||||
Assert.Contains("FORBIDDEN_KEY_PARTS", checker, StringComparison.Ordinal);
|
||||
Assert.Contains("decision must be", checker, StringComparison.Ordinal);
|
||||
Assert.Contains("candidate capacity evidence", checker, StringComparison.Ordinal);
|
||||
Assert.Contains("rendezvous-external-gate-attestation", checker, StringComparison.Ordinal);
|
||||
Assert.Contains("does not resolve to a repository evidence file", checker, StringComparison.Ordinal);
|
||||
}
|
||||
|
||||
private static string Property(XDocument document, string name) =>
|
||||
document.Descendants(name).Single().Value;
|
||||
|
||||
|
||||
@@ -178,12 +178,17 @@ public sealed class TestClientProcessIntegrationTests
|
||||
Assert.Contains(
|
||||
join.JsonEvents(),
|
||||
item => item.GetProperty("event").GetString() == "join.connected"
|
||||
&& item.GetProperty("endpointType").GetString() is "loopback" or "private");
|
||||
&& item.GetProperty("endpointType").GetString() is "loopback" or "private"
|
||||
&& item.GetProperty("addressFamily").GetString() == "ipv4");
|
||||
Assert.True(join.HasEvent("join.punch", "started"), join.DiagnosticText());
|
||||
Assert.True(join.HasEvent("join.direct-connect", "started"), join.DiagnosticText());
|
||||
Assert.True(join.HasEvent("join.direct-traffic", "verified"), join.DiagnosticText());
|
||||
Assert.True(join.HasEvent("join.outcome-report", "accepted"), join.DiagnosticText());
|
||||
Assert.True(host.HasEvent("host.direct-traffic", "verified"), host.DiagnosticText());
|
||||
Assert.Contains(
|
||||
host.JsonEvents(),
|
||||
item => item.GetProperty("event").GetString() == "host.direct-traffic"
|
||||
&& item.GetProperty("addressFamily").GetString() == "ipv4");
|
||||
Assert.True(host.HasEvent("host.punch", "started"), host.DiagnosticText());
|
||||
Assert.True(host.HasEvent("host.direct-connect", "connected"), host.DiagnosticText());
|
||||
Assert.True(host.HasEvent("host.deregistered", "complete"), host.DiagnosticText());
|
||||
|
||||
Reference in New Issue
Block a user