R2D2-MERIDIAN/crates
Joshua Belke a9b30ea276
Some checks failed
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Meridian Harness / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Meridian Harness / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Meridian Harness / Publish rolling release (push) Has been cancelled
Meridian Harness / Publish tagged release (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
control plane / chart (push) Has been cancelled
control plane / test (push) Has been cancelled
control plane / browser-e2e (push) Has been cancelled
control plane / Build control plane image (linux/amd64) (push) Has been cancelled
control plane / Build control plane image (linux/arm64) (push) Has been cancelled
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Isolated DB Gate (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Admin Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Server Cross-Compile (push) Has been cancelled
CI / Server Cross-Compile-1 (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
control plane / Publish signed control plane image (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
test(relay): prove the bus tenancy binding ACCEPTS, not just that it refuses
`meridian-f43l` closed a cross-tenant injection path by making a below-floor
bus event's tenancy come from its row in the system of record rather than from
the publisher-chosen key expression. Every refusal on that path was covered
without infrastructure; `CommunityBinding::Bound` was covered by code
inspection only, because the row it asks for cannot exist without Postgres.

That is the wrong way round for a security control: a binding that refused
everything would have passed the entire existing suite. Three tests, in the
crate's `--lib` module because `fan_out_pubsub_event_with` — the only entry
point that reaches the `Reverify` arm without a Zenoh session — is
`pub(crate)`, and gated `#[ignore = "requires Postgres"]` so
`just test-relay-db-run` (CI's "Relay DB/Redis gate") runs them and the
infra-free suite stays infra-free:

- `reverify_delivers_the_community_whose_row_binds_the_event_and_no_other`.
  One event, one signature, one channel UUID, two real communities. Under A,
  where the event's row exists carrying the routed channel scope, it is
  re-verified and delivered. Under B — a real community holding a real *open*
  channel with the same UUID and a subscriber on it, which is the shape an
  attacker gets for free from caller-chosen channel ids and a
  `(community_id, id)` primary key — the identical bytes on the identical
  topic are refused. Without the delivered half, "refused" would be equally
  consistent with a binding that refuses everything.
- `a_relay_derived_channel_kind_is_bound_by_its_row_scope_and_nothing_else`.
  `bind_scope` answers `Silent` for reactions, deletions, gift wraps, 9007 and
  44100/44101, so for those kinds the routed channel is checked in exactly one
  place: `stored.channel_id == routed_channel`. The stream-message pair cannot
  reach that arm — its refusal is decided before any lookup and its acceptance
  has tag and row agreeing — so this test is the one that fails when the
  comparison is deleted. Verified: with it deleted the pair still passes and
  this test fails.
- `unknown_tenancy_refuses_and_withdraws_the_replay_id_that_unbound_spends`.
  A database error refuses rather than accepts, and is told apart from a
  decided `Unbound` by the replay set: `Unbound` spends the id, `Unknown`
  withdraws it so one Postgres blip is not a ten-minute hole. Needs no live
  database — `Unbound` is reached by an ephemeral kind and `Unknown` by a pool
  pinned at an address nothing listens on, so it runs in the default suite.
  The seen-set assertion is also what proves the refusal came from the tenancy
  check rather than from the visibility gate failing closed one step later.

Mutation-verified in both directions: forcing `Bound` fails the paired refusal
and the `Unknown` test; forcing `Unbound` fails the acceptance.

The `--lib` pool is untouched. `test_state` still resolves through
`test_config` and connects lazily; `postgres_state` is a sibling builder that
resolves `meridian_test_db::disposable_url()` and connects eagerly, failing
loudly rather than skipping, the same repair `api::operator` got in
meridian-wxqw. Redis stays unconnectable for all three — the cross-node
*receive* path publishes nothing, and a live one would pull these into
meridian-h0tg's non-exiting test binary. The seeded rows are removed on the
way out, because that gate's database is shared and nothing resets it.

Refs: meridian-f43l
Signed-off-by: Joshua Belke <joshua@innovationhub-act.org>
2026-08-21 04:47:22 -04:00
..
git-credential-nostr feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
git-sign-nostr feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
meridian-acp docs(readme): overhaul the README for the program, and relicense to MIT 2026-08-05 14:47:03 -04:00
meridian-admin feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
meridian-agent docs(zenoh): record what postcard cannot encode, and stop the Q2 express cell reading as permission 2026-08-19 16:03:43 -04:00
meridian-audit feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
meridian-auth feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
meridian-cli fix(workflows): stop the UI and its mock from claiming runs that never happened 2026-08-08 21:33:42 -04:00
meridian-conformance feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
meridian-control-plane fix(paths): point the parent tree's tooling at the relocated client trees 2026-08-19 14:01:44 -04:00
meridian-core docs(zenoh): fold the Phase 1 and Phase 4 findings back into the charter 2026-08-19 14:40:16 -04:00
meridian-db fix(workflow): snapshot definition on run for approval resume 2026-08-19 14:01:38 -04:00
meridian-dev-mcp feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
meridian-harness feat(rebrand): finish the conversion — sprig, sprout, and a lost-identity bug 2026-08-04 23:50:47 -04:00
meridian-media refactor: move clients under REMAPPING deployable grammar 2026-08-19 14:01:39 -04:00
meridian-openapi feat(brand): put every Meridian surface on one dark ramp 2026-08-07 08:35:17 -04:00
meridian-pair-relay feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
meridian-pairing-cli feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
meridian-persona docs(readme): overhaul the README for the program, and relicense to MIT 2026-08-05 14:47:03 -04:00
meridian-pubsub perf(bus): measure the posture the relay ships, and prove it took 2026-08-21 00:48:59 -04:00
meridian-push-gateway fix(apps): finish the detail-panel rhythm — the symbol block was left behind 2026-08-07 18:25:26 -04:00
meridian-relay test(relay): prove the bus tenancy binding ACCEPTS, not just that it refuses 2026-08-21 04:47:22 -04:00
meridian-relay-mesh fix(audio): hold the huddle-control read across roster deltas (F083/meridian-ydnx) 2026-08-08 13:29:38 -04:00
meridian-sdk feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
meridian-search fix(apps): finish the detail-panel rhythm — the symbol block was left behind 2026-08-07 18:25:26 -04:00
meridian-test-client fix(canvas): resolve same-second ties the way the relay already does 2026-08-08 05:01:50 -04:00
meridian-test-db fix(apps): finish the detail-panel rhythm — the symbol block was left behind 2026-08-07 18:25:26 -04:00
meridian-workflow fix(workflow): snapshot definition on run for approval resume 2026-08-19 14:01:38 -04:00
meridian-ws-client feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
AGENTS.md docs(stellar): record the bus readiness contract and mark non-negotiable 2 unmet 2026-08-19 16:53:50 -04:00