refactor(runtime-host): share verified deployment identity - #3766

Merged
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity
Aug 25, 2026
Merged

refactor(runtime-host): share verified deployment identity#3766
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity

Conversation

@me2seeks

@me2seeksme2seeks commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Define the exact Runtime Host deployment identity that Maka can currently verify: an npm registry version plus SHA-512 integrity.
  • Make registry update candidates carry that shared identity from discovery through package acquisition.
  • Revalidate the complete identity at the package boundary while keeping the existing service-management wire frame unchanged.

This is the first, behavior-preserving layer of the local deployment-owner work. It deliberately adds no owner record, transfer authority, Desktop evidence format, remote deployment authority, or lifecycle behavior.

Refs #3231
Design context: #3709

中文摘要
  • 定义 Maka 当前能够验证的精确 Runtime Host 部署身份:npm registry 版本号与 SHA-512 integrity。
  • 让 registry 更新候选从发现到包获取都携带同一份共享身份。
  • 在包边界重新验证完整身份,同时保持现有 service-management wire frame 不变。

这是本地部署 owner 工作的第一层、行为不变的基础 PR。它不新增 owner 记录、转移权限、Desktop 证据格式、remote 部署权限或生命周期行为。

Verification

  • npm --workspace @maka/runtime-host run build
  • npm --workspace maka-agent run build
  • Focused Runtime Host update tests: 17 passed.
  • Full CLI suite: 450 passed.
  • Scoped Biome lint and git diff --check passed.

AI use

Select exactly one:

  • No generative tool made a substantive contribution
  • Generative tooling made a substantive contribution

Tool(s) and scope: Codex helped design and implement the shared deployment-identity contract, propagation, validation, and tests under user direction. The affected commit includes a Generated-by: Codex trailer.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head. No Spec blocking issues, but hard Standards breaches block approval.

[P3] Standards — missing commit trailer and incomplete PR template

  • Commit 286bf417 with AI-assisted changes lacks required Generated-by: Codex trailer (per CONTRIBUTING.md:30-34).
  • PR body does not include the template's AI-use selection/scope, checklist, or behavior yes/no (per :79-81). Needs completed template.

Spec is GO — identity {version, integrity} correctly modeled and verified through discovery/selection/acquisition, with SHA-512 re-hash and compatibility separate.

Checks on 286bf41710 are test: success, but standards gate is not met.

简体中文存在提交信息与模板两项标准不合规。

@me2seeks
me2seeksforce-pushed the feat/runtime-host-deployment-identity branch from 286bf41 to 21f195dCompareAugust 25, 2026 07:09
@me2seeks

Copy link
Copy Markdown
ContributorAuthor

Addressed the standards findings on new exact head 21f195d82:

The old and new tree objects are identical for all three rewritten commits; this update changes attribution/history only, not source or test content. CI is running again on each new head.

简体中文

已在新 head 21f195d82 修复两项标准问题:commit 补充 Generated-by: Codex trailer,PR body 恢复完整 AI-use、checklist 与 behavior 选择。依赖的 #3767/#3769 已按顺序 rebase;同时主动修复了 #3767 的相同标准问题。三个 commit 改写前后的 tree 完全一致,只改变 attribution/history,不改变源码或测试内容;CI 正在重新运行。

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head and found no blocking issues.

The deployment identity is now cleanly modeled as {kind, version, integrity} with verification at discovery, selection, and package acquisition — correctly distinguishing same-version-different-content artifacts. No new authority, state, or lifecycle is added.

No P0-P3.

简体中文该头未发现阻断。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE — 21f195d, no P0-P3, identity correctly scoped.

@Astro-Han
Astro-Han merged commit ef71012 into apache:mainAug 25, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@me2seeks@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

refactor(runtime-host): share verified deployment identity - #3766

Merged
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity
Aug 25, 2026
Merged

refactor(runtime-host): share verified deployment identity#3766
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity

Conversation

@me2seeks

@me2seeksme2seeks commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Define the exact Runtime Host deployment identity that Maka can currently verify: an npm registry version plus SHA-512 integrity.
  • Make registry update candidates carry that shared identity from discovery through package acquisition.
  • Revalidate the complete identity at the package boundary while keeping the existing service-management wire frame unchanged.

This is the first, behavior-preserving layer of the local deployment-owner work. It deliberately adds no owner record, transfer authority, Desktop evidence format, remote deployment authority, or lifecycle behavior.

Refs #3231
Design context: #3709

中文摘要
  • 定义 Maka 当前能够验证的精确 Runtime Host 部署身份:npm registry 版本号与 SHA-512 integrity。
  • 让 registry 更新候选从发现到包获取都携带同一份共享身份。
  • 在包边界重新验证完整身份,同时保持现有 service-management wire frame 不变。

这是本地部署 owner 工作的第一层、行为不变的基础 PR。它不新增 owner 记录、转移权限、Desktop 证据格式、remote 部署权限或生命周期行为。

Verification

  • npm --workspace @maka/runtime-host run build
  • npm --workspace maka-agent run build
  • Focused Runtime Host update tests: 17 passed.
  • Full CLI suite: 450 passed.
  • Scoped Biome lint and git diff --check passed.

AI use

Select exactly one:

  • No generative tool made a substantive contribution
  • Generative tooling made a substantive contribution

Tool(s) and scope: Codex helped design and implement the shared deployment-identity contract, propagation, validation, and tests under user direction. The affected commit includes a Generated-by: Codex trailer.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head. No Spec blocking issues, but hard Standards breaches block approval.

[P3] Standards — missing commit trailer and incomplete PR template

  • Commit 286bf417 with AI-assisted changes lacks required Generated-by: Codex trailer (per CONTRIBUTING.md:30-34).
  • PR body does not include the template's AI-use selection/scope, checklist, or behavior yes/no (per :79-81). Needs completed template.

Spec is GO — identity {version, integrity} correctly modeled and verified through discovery/selection/acquisition, with SHA-512 re-hash and compatibility separate.

Checks on 286bf41710 are test: success, but standards gate is not met.

简体中文存在提交信息与模板两项标准不合规。

@me2seeks
me2seeksforce-pushed the feat/runtime-host-deployment-identity branch from 286bf41 to 21f195dCompareAugust 25, 2026 07:09
@me2seeks

Copy link
Copy Markdown
ContributorAuthor

Addressed the standards findings on new exact head 21f195d82:

The old and new tree objects are identical for all three rewritten commits; this update changes attribution/history only, not source or test content. CI is running again on each new head.

简体中文

已在新 head 21f195d82 修复两项标准问题:commit 补充 Generated-by: Codex trailer,PR body 恢复完整 AI-use、checklist 与 behavior 选择。依赖的 #3767/#3769 已按顺序 rebase;同时主动修复了 #3767 的相同标准问题。三个 commit 改写前后的 tree 完全一致,只改变 attribution/history,不改变源码或测试内容;CI 正在重新运行。

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head and found no blocking issues.

The deployment identity is now cleanly modeled as {kind, version, integrity} with verification at discovery, selection, and package acquisition — correctly distinguishing same-version-different-content artifacts. No new authority, state, or lifecycle is added.

No P0-P3.

简体中文该头未发现阻断。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE — 21f195d, no P0-P3, identity correctly scoped.

@Astro-Han
Astro-Han merged commit ef71012 into apache:mainAug 25, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@me2seeks@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

refactor(runtime-host): share verified deployment identity - #3766

Merged
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity
Aug 25, 2026
Merged

refactor(runtime-host): share verified deployment identity#3766
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity

Conversation

@me2seeks

@me2seeksme2seeks commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Define the exact Runtime Host deployment identity that Maka can currently verify: an npm registry version plus SHA-512 integrity.
  • Make registry update candidates carry that shared identity from discovery through package acquisition.
  • Revalidate the complete identity at the package boundary while keeping the existing service-management wire frame unchanged.

This is the first, behavior-preserving layer of the local deployment-owner work. It deliberately adds no owner record, transfer authority, Desktop evidence format, remote deployment authority, or lifecycle behavior.

Refs #3231
Design context: #3709

中文摘要
  • 定义 Maka 当前能够验证的精确 Runtime Host 部署身份:npm registry 版本号与 SHA-512 integrity。
  • 让 registry 更新候选从发现到包获取都携带同一份共享身份。
  • 在包边界重新验证完整身份,同时保持现有 service-management wire frame 不变。

这是本地部署 owner 工作的第一层、行为不变的基础 PR。它不新增 owner 记录、转移权限、Desktop 证据格式、remote 部署权限或生命周期行为。

Verification

  • npm --workspace @maka/runtime-host run build
  • npm --workspace maka-agent run build
  • Focused Runtime Host update tests: 17 passed.
  • Full CLI suite: 450 passed.
  • Scoped Biome lint and git diff --check passed.

AI use

Select exactly one:

  • No generative tool made a substantive contribution
  • Generative tooling made a substantive contribution

Tool(s) and scope: Codex helped design and implement the shared deployment-identity contract, propagation, validation, and tests under user direction. The affected commit includes a Generated-by: Codex trailer.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head. No Spec blocking issues, but hard Standards breaches block approval.

[P3] Standards — missing commit trailer and incomplete PR template

  • Commit 286bf417 with AI-assisted changes lacks required Generated-by: Codex trailer (per CONTRIBUTING.md:30-34).
  • PR body does not include the template's AI-use selection/scope, checklist, or behavior yes/no (per :79-81). Needs completed template.

Spec is GO — identity {version, integrity} correctly modeled and verified through discovery/selection/acquisition, with SHA-512 re-hash and compatibility separate.

Checks on 286bf41710 are test: success, but standards gate is not met.

简体中文存在提交信息与模板两项标准不合规。

@me2seeks
me2seeksforce-pushed the feat/runtime-host-deployment-identity branch from 286bf41 to 21f195dCompareAugust 25, 2026 07:09
@me2seeks

Copy link
Copy Markdown
ContributorAuthor

Addressed the standards findings on new exact head 21f195d82:

The old and new tree objects are identical for all three rewritten commits; this update changes attribution/history only, not source or test content. CI is running again on each new head.

简体中文

已在新 head 21f195d82 修复两项标准问题:commit 补充 Generated-by: Codex trailer,PR body 恢复完整 AI-use、checklist 与 behavior 选择。依赖的 #3767/#3769 已按顺序 rebase;同时主动修复了 #3767 的相同标准问题。三个 commit 改写前后的 tree 完全一致,只改变 attribution/history,不改变源码或测试内容;CI 正在重新运行。

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head and found no blocking issues.

The deployment identity is now cleanly modeled as {kind, version, integrity} with verification at discovery, selection, and package acquisition — correctly distinguishing same-version-different-content artifacts. No new authority, state, or lifecycle is added.

No P0-P3.

简体中文该头未发现阻断。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE — 21f195d, no P0-P3, identity correctly scoped.

@Astro-Han
Astro-Han merged commit ef71012 into apache:mainAug 25, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@me2seeks@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

refactor(runtime-host): share verified deployment identity - #3766

Merged
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity
Aug 25, 2026
Merged

refactor(runtime-host): share verified deployment identity#3766
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity

Conversation

@me2seeks

@me2seeksme2seeks commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Define the exact Runtime Host deployment identity that Maka can currently verify: an npm registry version plus SHA-512 integrity.
  • Make registry update candidates carry that shared identity from discovery through package acquisition.
  • Revalidate the complete identity at the package boundary while keeping the existing service-management wire frame unchanged.

This is the first, behavior-preserving layer of the local deployment-owner work. It deliberately adds no owner record, transfer authority, Desktop evidence format, remote deployment authority, or lifecycle behavior.

Refs #3231
Design context: #3709

中文摘要
  • 定义 Maka 当前能够验证的精确 Runtime Host 部署身份:npm registry 版本号与 SHA-512 integrity。
  • 让 registry 更新候选从发现到包获取都携带同一份共享身份。
  • 在包边界重新验证完整身份,同时保持现有 service-management wire frame 不变。

这是本地部署 owner 工作的第一层、行为不变的基础 PR。它不新增 owner 记录、转移权限、Desktop 证据格式、remote 部署权限或生命周期行为。

Verification

  • npm --workspace @maka/runtime-host run build
  • npm --workspace maka-agent run build
  • Focused Runtime Host update tests: 17 passed.
  • Full CLI suite: 450 passed.
  • Scoped Biome lint and git diff --check passed.

AI use

Select exactly one:

  • No generative tool made a substantive contribution
  • Generative tooling made a substantive contribution

Tool(s) and scope: Codex helped design and implement the shared deployment-identity contract, propagation, validation, and tests under user direction. The affected commit includes a Generated-by: Codex trailer.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head. No Spec blocking issues, but hard Standards breaches block approval.

[P3] Standards — missing commit trailer and incomplete PR template

  • Commit 286bf417 with AI-assisted changes lacks required Generated-by: Codex trailer (per CONTRIBUTING.md:30-34).
  • PR body does not include the template's AI-use selection/scope, checklist, or behavior yes/no (per :79-81). Needs completed template.

Spec is GO — identity {version, integrity} correctly modeled and verified through discovery/selection/acquisition, with SHA-512 re-hash and compatibility separate.

Checks on 286bf41710 are test: success, but standards gate is not met.

简体中文存在提交信息与模板两项标准不合规。

@me2seeks
me2seeksforce-pushed the feat/runtime-host-deployment-identity branch from 286bf41 to 21f195dCompareAugust 25, 2026 07:09
@me2seeks

Copy link
Copy Markdown
ContributorAuthor

Addressed the standards findings on new exact head 21f195d82:

The old and new tree objects are identical for all three rewritten commits; this update changes attribution/history only, not source or test content. CI is running again on each new head.

简体中文

已在新 head 21f195d82 修复两项标准问题:commit 补充 Generated-by: Codex trailer,PR body 恢复完整 AI-use、checklist 与 behavior 选择。依赖的 #3767/#3769 已按顺序 rebase;同时主动修复了 #3767 的相同标准问题。三个 commit 改写前后的 tree 完全一致,只改变 attribution/history,不改变源码或测试内容;CI 正在重新运行。

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head and found no blocking issues.

The deployment identity is now cleanly modeled as {kind, version, integrity} with verification at discovery, selection, and package acquisition — correctly distinguishing same-version-different-content artifacts. No new authority, state, or lifecycle is added.

No P0-P3.

简体中文该头未发现阻断。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE — 21f195d, no P0-P3, identity correctly scoped.

@Astro-Han
Astro-Han merged commit ef71012 into apache:mainAug 25, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@me2seeks@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

refactor(runtime-host): share verified deployment identity - #3766

Merged
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity
Aug 25, 2026
Merged

refactor(runtime-host): share verified deployment identity#3766
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity

Conversation

@me2seeks

@me2seeksme2seeks commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Define the exact Runtime Host deployment identity that Maka can currently verify: an npm registry version plus SHA-512 integrity.
  • Make registry update candidates carry that shared identity from discovery through package acquisition.
  • Revalidate the complete identity at the package boundary while keeping the existing service-management wire frame unchanged.

This is the first, behavior-preserving layer of the local deployment-owner work. It deliberately adds no owner record, transfer authority, Desktop evidence format, remote deployment authority, or lifecycle behavior.

Refs #3231
Design context: #3709

中文摘要
  • 定义 Maka 当前能够验证的精确 Runtime Host 部署身份:npm registry 版本号与 SHA-512 integrity。
  • 让 registry 更新候选从发现到包获取都携带同一份共享身份。
  • 在包边界重新验证完整身份,同时保持现有 service-management wire frame 不变。

这是本地部署 owner 工作的第一层、行为不变的基础 PR。它不新增 owner 记录、转移权限、Desktop 证据格式、remote 部署权限或生命周期行为。

Verification

  • npm --workspace @maka/runtime-host run build
  • npm --workspace maka-agent run build
  • Focused Runtime Host update tests: 17 passed.
  • Full CLI suite: 450 passed.
  • Scoped Biome lint and git diff --check passed.

AI use

Select exactly one:

  • No generative tool made a substantive contribution
  • Generative tooling made a substantive contribution

Tool(s) and scope: Codex helped design and implement the shared deployment-identity contract, propagation, validation, and tests under user direction. The affected commit includes a Generated-by: Codex trailer.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head. No Spec blocking issues, but hard Standards breaches block approval.

[P3] Standards — missing commit trailer and incomplete PR template

  • Commit 286bf417 with AI-assisted changes lacks required Generated-by: Codex trailer (per CONTRIBUTING.md:30-34).
  • PR body does not include the template's AI-use selection/scope, checklist, or behavior yes/no (per :79-81). Needs completed template.

Spec is GO — identity {version, integrity} correctly modeled and verified through discovery/selection/acquisition, with SHA-512 re-hash and compatibility separate.

Checks on 286bf41710 are test: success, but standards gate is not met.

简体中文存在提交信息与模板两项标准不合规。

@me2seeks
me2seeksforce-pushed the feat/runtime-host-deployment-identity branch from 286bf41 to 21f195dCompareAugust 25, 2026 07:09
@me2seeks

Copy link
Copy Markdown
ContributorAuthor

Addressed the standards findings on new exact head 21f195d82:

The old and new tree objects are identical for all three rewritten commits; this update changes attribution/history only, not source or test content. CI is running again on each new head.

简体中文

已在新 head 21f195d82 修复两项标准问题:commit 补充 Generated-by: Codex trailer,PR body 恢复完整 AI-use、checklist 与 behavior 选择。依赖的 #3767/#3769 已按顺序 rebase;同时主动修复了 #3767 的相同标准问题。三个 commit 改写前后的 tree 完全一致,只改变 attribution/history,不改变源码或测试内容;CI 正在重新运行。

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head and found no blocking issues.

The deployment identity is now cleanly modeled as {kind, version, integrity} with verification at discovery, selection, and package acquisition — correctly distinguishing same-version-different-content artifacts. No new authority, state, or lifecycle is added.

No P0-P3.

简体中文该头未发现阻断。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE — 21f195d, no P0-P3, identity correctly scoped.

@Astro-Han
Astro-Han merged commit ef71012 into apache:mainAug 25, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@me2seeks@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

refactor(runtime-host): share verified deployment identity - #3766

Merged
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity
Aug 25, 2026
Merged

refactor(runtime-host): share verified deployment identity#3766
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity

Conversation

@me2seeks

@me2seeksme2seeks commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Define the exact Runtime Host deployment identity that Maka can currently verify: an npm registry version plus SHA-512 integrity.
  • Make registry update candidates carry that shared identity from discovery through package acquisition.
  • Revalidate the complete identity at the package boundary while keeping the existing service-management wire frame unchanged.

This is the first, behavior-preserving layer of the local deployment-owner work. It deliberately adds no owner record, transfer authority, Desktop evidence format, remote deployment authority, or lifecycle behavior.

Refs #3231
Design context: #3709

中文摘要
  • 定义 Maka 当前能够验证的精确 Runtime Host 部署身份:npm registry 版本号与 SHA-512 integrity。
  • 让 registry 更新候选从发现到包获取都携带同一份共享身份。
  • 在包边界重新验证完整身份,同时保持现有 service-management wire frame 不变。

这是本地部署 owner 工作的第一层、行为不变的基础 PR。它不新增 owner 记录、转移权限、Desktop 证据格式、remote 部署权限或生命周期行为。

Verification

  • npm --workspace @maka/runtime-host run build
  • npm --workspace maka-agent run build
  • Focused Runtime Host update tests: 17 passed.
  • Full CLI suite: 450 passed.
  • Scoped Biome lint and git diff --check passed.

AI use

Select exactly one:

  • No generative tool made a substantive contribution
  • Generative tooling made a substantive contribution

Tool(s) and scope: Codex helped design and implement the shared deployment-identity contract, propagation, validation, and tests under user direction. The affected commit includes a Generated-by: Codex trailer.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head. No Spec blocking issues, but hard Standards breaches block approval.

[P3] Standards — missing commit trailer and incomplete PR template

  • Commit 286bf417 with AI-assisted changes lacks required Generated-by: Codex trailer (per CONTRIBUTING.md:30-34).
  • PR body does not include the template's AI-use selection/scope, checklist, or behavior yes/no (per :79-81). Needs completed template.

Spec is GO — identity {version, integrity} correctly modeled and verified through discovery/selection/acquisition, with SHA-512 re-hash and compatibility separate.

Checks on 286bf41710 are test: success, but standards gate is not met.

简体中文存在提交信息与模板两项标准不合规。

@me2seeks
me2seeksforce-pushed the feat/runtime-host-deployment-identity branch from 286bf41 to 21f195dCompareAugust 25, 2026 07:09
@me2seeks

Copy link
Copy Markdown
ContributorAuthor

Addressed the standards findings on new exact head 21f195d82:

The old and new tree objects are identical for all three rewritten commits; this update changes attribution/history only, not source or test content. CI is running again on each new head.

简体中文

已在新 head 21f195d82 修复两项标准问题:commit 补充 Generated-by: Codex trailer,PR body 恢复完整 AI-use、checklist 与 behavior 选择。依赖的 #3767/#3769 已按顺序 rebase;同时主动修复了 #3767 的相同标准问题。三个 commit 改写前后的 tree 完全一致,只改变 attribution/history,不改变源码或测试内容;CI 正在重新运行。

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head and found no blocking issues.

The deployment identity is now cleanly modeled as {kind, version, integrity} with verification at discovery, selection, and package acquisition — correctly distinguishing same-version-different-content artifacts. No new authority, state, or lifecycle is added.

No P0-P3.

简体中文该头未发现阻断。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE — 21f195d, no P0-P3, identity correctly scoped.

@Astro-Han
Astro-Han merged commit ef71012 into apache:mainAug 25, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@me2seeks@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

refactor(runtime-host): share verified deployment identity - #3766

Merged
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity
Aug 25, 2026
Merged

refactor(runtime-host): share verified deployment identity#3766
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity

Conversation

@me2seeks

@me2seeksme2seeks commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Define the exact Runtime Host deployment identity that Maka can currently verify: an npm registry version plus SHA-512 integrity.
  • Make registry update candidates carry that shared identity from discovery through package acquisition.
  • Revalidate the complete identity at the package boundary while keeping the existing service-management wire frame unchanged.

This is the first, behavior-preserving layer of the local deployment-owner work. It deliberately adds no owner record, transfer authority, Desktop evidence format, remote deployment authority, or lifecycle behavior.

Refs #3231
Design context: #3709

中文摘要
  • 定义 Maka 当前能够验证的精确 Runtime Host 部署身份:npm registry 版本号与 SHA-512 integrity。
  • 让 registry 更新候选从发现到包获取都携带同一份共享身份。
  • 在包边界重新验证完整身份,同时保持现有 service-management wire frame 不变。

这是本地部署 owner 工作的第一层、行为不变的基础 PR。它不新增 owner 记录、转移权限、Desktop 证据格式、remote 部署权限或生命周期行为。

Verification

  • npm --workspace @maka/runtime-host run build
  • npm --workspace maka-agent run build
  • Focused Runtime Host update tests: 17 passed.
  • Full CLI suite: 450 passed.
  • Scoped Biome lint and git diff --check passed.

AI use

Select exactly one:

  • No generative tool made a substantive contribution
  • Generative tooling made a substantive contribution

Tool(s) and scope: Codex helped design and implement the shared deployment-identity contract, propagation, validation, and tests under user direction. The affected commit includes a Generated-by: Codex trailer.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head. No Spec blocking issues, but hard Standards breaches block approval.

[P3] Standards — missing commit trailer and incomplete PR template

  • Commit 286bf417 with AI-assisted changes lacks required Generated-by: Codex trailer (per CONTRIBUTING.md:30-34).
  • PR body does not include the template's AI-use selection/scope, checklist, or behavior yes/no (per :79-81). Needs completed template.

Spec is GO — identity {version, integrity} correctly modeled and verified through discovery/selection/acquisition, with SHA-512 re-hash and compatibility separate.

Checks on 286bf41710 are test: success, but standards gate is not met.

简体中文存在提交信息与模板两项标准不合规。

@me2seeks
me2seeksforce-pushed the feat/runtime-host-deployment-identity branch from 286bf41 to 21f195dCompareAugust 25, 2026 07:09
@me2seeks

Copy link
Copy Markdown
ContributorAuthor

Addressed the standards findings on new exact head 21f195d82:

The old and new tree objects are identical for all three rewritten commits; this update changes attribution/history only, not source or test content. CI is running again on each new head.

简体中文

已在新 head 21f195d82 修复两项标准问题:commit 补充 Generated-by: Codex trailer,PR body 恢复完整 AI-use、checklist 与 behavior 选择。依赖的 #3767/#3769 已按顺序 rebase;同时主动修复了 #3767 的相同标准问题。三个 commit 改写前后的 tree 完全一致,只改变 attribution/history,不改变源码或测试内容;CI 正在重新运行。

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head and found no blocking issues.

The deployment identity is now cleanly modeled as {kind, version, integrity} with verification at discovery, selection, and package acquisition — correctly distinguishing same-version-different-content artifacts. No new authority, state, or lifecycle is added.

No P0-P3.

简体中文该头未发现阻断。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE — 21f195d, no P0-P3, identity correctly scoped.

@Astro-Han
Astro-Han merged commit ef71012 into apache:mainAug 25, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@me2seeks@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

refactor(runtime-host): share verified deployment identity - #3766

Merged
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity
Aug 25, 2026
Merged

refactor(runtime-host): share verified deployment identity#3766
Astro-Han merged 1 commit into
apache:mainfrom
me2seeks:feat/runtime-host-deployment-identity

Conversation

@me2seeks

@me2seeksme2seeks commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Define the exact Runtime Host deployment identity that Maka can currently verify: an npm registry version plus SHA-512 integrity.
  • Make registry update candidates carry that shared identity from discovery through package acquisition.
  • Revalidate the complete identity at the package boundary while keeping the existing service-management wire frame unchanged.

This is the first, behavior-preserving layer of the local deployment-owner work. It deliberately adds no owner record, transfer authority, Desktop evidence format, remote deployment authority, or lifecycle behavior.

Refs #3231
Design context: #3709

中文摘要
  • 定义 Maka 当前能够验证的精确 Runtime Host 部署身份:npm registry 版本号与 SHA-512 integrity。
  • 让 registry 更新候选从发现到包获取都携带同一份共享身份。
  • 在包边界重新验证完整身份,同时保持现有 service-management wire frame 不变。

这是本地部署 owner 工作的第一层、行为不变的基础 PR。它不新增 owner 记录、转移权限、Desktop 证据格式、remote 部署权限或生命周期行为。

Verification

  • npm --workspace @maka/runtime-host run build
  • npm --workspace maka-agent run build
  • Focused Runtime Host update tests: 17 passed.
  • Full CLI suite: 450 passed.
  • Scoped Biome lint and git diff --check passed.

AI use

Select exactly one:

  • No generative tool made a substantive contribution
  • Generative tooling made a substantive contribution

Tool(s) and scope: Codex helped design and implement the shared deployment-identity contract, propagation, validation, and tests under user direction. The affected commit includes a Generated-by: Codex trailer.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head. No Spec blocking issues, but hard Standards breaches block approval.

[P3] Standards — missing commit trailer and incomplete PR template

  • Commit 286bf417 with AI-assisted changes lacks required Generated-by: Codex trailer (per CONTRIBUTING.md:30-34).
  • PR body does not include the template's AI-use selection/scope, checklist, or behavior yes/no (per :79-81). Needs completed template.

Spec is GO — identity {version, integrity} correctly modeled and verified through discovery/selection/acquisition, with SHA-512 re-hash and compatibility separate.

Checks on 286bf41710 are test: success, but standards gate is not met.

简体中文存在提交信息与模板两项标准不合规。

@me2seeks
me2seeksforce-pushed the feat/runtime-host-deployment-identity branch from 286bf41 to 21f195dCompareAugust 25, 2026 07:09
@me2seeks

Copy link
Copy Markdown
ContributorAuthor

Addressed the standards findings on new exact head 21f195d82:

The old and new tree objects are identical for all three rewritten commits; this update changes attribution/history only, not source or test content. CI is running again on each new head.

简体中文

已在新 head 21f195d82 修复两项标准问题:commit 补充 Generated-by: Codex trailer,PR body 恢复完整 AI-use、checklist 与 behavior 选择。依赖的 #3767/#3769 已按顺序 rebase;同时主动修复了 #3767 的相同标准问题。三个 commit 改写前后的 tree 完全一致,只改变 attribution/history,不改变源码或测试内容;CI 正在重新运行。

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this head and found no blocking issues.

The deployment identity is now cleanly modeled as {kind, version, integrity} with verification at discovery, selection, and package acquisition — correctly distinguishing same-version-different-content artifacts. No new authority, state, or lifecycle is added.

No P0-P3.

简体中文该头未发现阻断。

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE — 21f195d, no P0-P3, identity correctly scoped.

@Astro-Han
Astro-Han merged commit ef71012 into apache:mainAug 25, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@me2seeks@Astro-Han