Skip to content

Phase/8 operational hardening - #10

Merged
Mujhtech merged 35 commits into
developmentfrom
phase/8-operational-hardening
Jul 31, 2026
Merged

Phase/8 operational hardening#10
Mujhtech merged 35 commits into
developmentfrom
phase/8-operational-hardening

Conversation

@Mujhtech

Copy link
Copy Markdown
Owner

No description provided.

@gitguardian

gitguardian Bot commented Jul 31, 2026

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secret in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
35177584 Triggered Generic Password 2b49cfd compose.yaml View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@Mujhtech
Mujhtech force-pushed the phase/8-operational-hardening branch from dbf2113 to fd549ab Compare July 31, 2026 09:35
@Mujhtech
Mujhtech force-pushed the phase/8-operational-hardening branch from fd549ab to 9c2faca Compare July 31, 2026 09:36
@Mujhtech
Mujhtech force-pushed the phase/8-operational-hardening branch from 9c2faca to 96884a1 Compare July 31, 2026 09:36
@Mujhtech
Mujhtech force-pushed the phase/8-operational-hardening branch from 96884a1 to 4008fe9 Compare July 31, 2026 09:37
@Mujhtech
Mujhtech force-pushed the phase/8-operational-hardening branch from 4008fe9 to 834bb79 Compare July 31, 2026 09:37
@Mujhtech
Mujhtech force-pushed the phase/8-operational-hardening branch from 834bb79 to 32406bd Compare July 31, 2026 09:37
@Mujhtech
Mujhtech force-pushed the phase/8-operational-hardening branch from 32406bd to bf5d95a Compare July 31, 2026 09:38
Base automatically changed from phase/7-experiments to development July 31, 2026 09:38
Mujhtech added 14 commits July 31, 2026 10:38
Organization switcher rewrite, route guards and sign-out, error
classification and degraded states, app-wide field accessibility,
error boundaries, pending states, focus management, browser matrix,
runtime config injection, diagnostics panel, version stamping,
dashboard Dockerfile and operations documentation.
Embedded protocol schemas with drift test, version-stamped images,
migration preflight with advisory locking and refuse-on-affected-data
downs, experiment schedule lease recovery, analytics ingestion
minimization enforcement, trusted-proxy rate limiting, observability
metrics and spans, dependency-aware readiness and draining shutdown,
production config guards, backup/restore/keyring tooling, upgrade
workflow, and stdlib load-generation harness. Migrations 00019-00021.
Explicit tree codecs replace reflective Gson for cached configuration
and experiment assignment records (R8-safe persistence), corrected
consumer rules, minified example release build as regression guard,
file-backed bounded no-backup Google Play delivery store off the main
dispatcher, scroll-indicator recomposition fix, analytics registry
flag reconciliation, RevenueCat publication parity, version 0.1.0-dev.7
with reconciled wire constant, canonical assignment-vector test binding,
R8 and installation documentation, known-limitations register.
Storage failures can no longer escape public APIs (dispose, lifecycle
flush, identity persistence with poisoning fix), decidePlacement
degrades to sealed unavailable, v2 analytics acknowledgements are now
accepted (exposure-loss fix), rollout tuple emitted atomically,
per-event v2 correlation/attribution allow-lists in the decoder,
version reconciled to 0.2.0-dev.11 with matching wire constant,
floor raised to Flutter 3.22/Dart 3.4, canonical v1 invalid and v2
fixture sweeps, honest installation docs, docs/sdk rewrite.
…n android

Correlation allow-lists for every schema version, attribution ownership
extended to v1, ingestion responses retain and require the echoed
contract version so v1 responses cannot acknowledge v2 experiment
batches, rollout tuple all-or-none by construction, six canonical
invalid fixtures consumed directly in tests.
…at contract level (stage 3)

Manifest lifecycle widened (retired status, deprecation metadata) before
the one-way approval flip of all 13 contracts, Delivery v3 readerPolicy
fallback keys, Local Preview 0.2 manifest wired into validation,
generator-enforced per-event correlation/attribution allow-lists and
dependent-required tuples in canonical analytics schemas, rejection-layer
metadata for invalid fixtures, corrected export-name documentation,
compatibility/deprecation/breaking-change/fixture-lifecycle/release
policies and per-contract migration guides.
Verified conversion events already emit on v2 with the complete tuple
under an active assignment (blocker non-reproduction, evidence-backed);
locked the three previously untested mechanisms with emitter and
canonical-fixture tests including tuple event-scope boundaries.
iOS 15 floor restored (monotonic clock replaces ContinuousClock) with a
deployment-target typecheck guard, privacy manifest with SystemBootTime
declaration, version reconciliation to 0.1.0-dev.6 across podspecs and
wire constants, trap paths converted to safe errors, configure degrades
to in-memory persistence with bundled fallback instead of throwing,
packaged bundled fallback made loadable (digest and delivery-version
bugs), acknowledgement contract-version pairing enforced, canonical
assignment-vector test binding, pinned swift-format config, honest
installation and validation docs.
…s tuple-free

Journey batch now exercises the exposure-to-conversion join; normative
rule that conversions on fallback presentations must omit the experiment
tuple (denominator displacement / category 12), with detection signal;
three unsatisfiable guardrail metrics identified against the approved
contract.
Conversion events carry the immutable all-or-none experiment tuple on
schema v2 only for exposed original-variant presentations; fallback and
QA-override presentations emit tuple-free; v2 lane batching keeps
versions unmixed; attributed canonical fixtures round-trip; version-
dependent context validation fixed.
Mujhtech added 21 commits July 31, 2026 10:38
…ndled fallback

Conversion tuple attaches only when the presentation was an exposed
original variant (excludes fallback and QA-override presentations,
matching the exposure-emission condition exactly); packaged bundled
fallback pinned with renderability and byte-equality tests through R8.
Conversion attribution attaches only when the presentation was not a
fallback (non-vacuity-proven regression test); stale v0.1-era golden
removed and redundant test consolidated; baseline re-recorded on
Xcode 26.5/iOS 26.5 with documented visual review; simulator suite
12/12 and deterministic across runs.
README rewritten for v1 reality, SECURITY/CONTRIBUTING/CODE_OF_CONDUCT,
draft v1.0.0 release notes, support policy, ten grounded user guides,
TEST.md credential file removed (rotation remains an owner action),
accidentally truncated known-limitations sections restored.
Experiment publishing worked against PostgreSQL for the first time:
wrong assets column name and semicolon-joined parameterized statements
fixed in experimentpostgres; email validation no longer performs live
MX lookups (isolated installs could not create an administrator);
placement/alias/attribute keys validated against the schema pattern
instead of 500ing; 5xx causes now logged with request correlation;
drill evidence for D1, D7, D8, D14 recorded including non-zero
experiment conversion verification.
Compose volume isolation and env passthrough (59 vars), script project
overrides, truthful readiness during dependency failure, named 406
capability details, worker job log identity, experiment schedule insert
schema drift (and three sibling writer/schema drifts), deliberate 5xx
statuses no longer collapsed to internal_error, audit history readable
after experiment actions, diagnosable 422s, migrate down-to parsing,
secret redaction in error-cause logging, loadgen capability headers,
embedded schema re-sync; drills D2-D6, D9, D10, D12-D14 evidence,
full integration suite green, both triage items resolved, first
performance measurements recorded.
QA-override presentations leaked the tuple with no exposure row behind
it; tuple attachment and exposure emission now share one predicate
(recordsStatisticalExposure) so they cannot drift, verified across six
presentation shapes with a non-vacuity-proven biconditional test.
Installation, upgrade, backup/restore, and troubleshooting guides
grounded in executed drill commands; 21 operator runbooks with index;
README documentation index updated; non-drill-validated steps labelled
explicitly.
…tes, asset 404, drift sweep

Configurable readiness drain delay before shutdown (D6 pass), experiment
publishes carry a usable v1 representation forward so v1-only SDKs keep
receiving configuration, explicit experiment_placement_decision_required
code, missing asset object is a 404 with operator-log integrity detail
while storage failure stays 503, writer/schema drift sweep script clean
across 88 tables with two additional defect classes audited.
Backend (format/vet/build/full integration tests against postgres and
minio, writer-schema drift sweep, govulncheck, Go SBOM), protocol
(tests, contract validation, generation drift gate, audit), dashboard
(full check including relay, audit, npm SBOM), Flutter, Android with
minified example R8 gate, iOS with the iOS 15 deployment-target
typecheck, compose readiness smoke, and secret scanning.
Server/platform and dashboard known-limitation sections, BUGS.md item
registered and file removed, experiments guide prerequisites and
emergency-stop accuracy, publishing/placements trap propagation,
troubleshooting updated to post-fix behavior, release notes dashboard
section and deliberate D8 deviation, README matrix alignment,
installation guide dashboard configuration and first-screen accuracy.
…otiation guarantees

Eleven changelog entries carry the approved-at-GA status line, the
release-approval checklist now requires it, the every-release-carries-
every-approved-version production guarantee and the 406 details wire
shape with its closed reason vocabulary are documented, remaining
unconsumed fixture coverage recorded.
Opt-in integration harness proves fetch, cache-served outage survival,
bundled fallback with empty cache, and 304 recovery against a live
compose stack; evidence and suite/toolchain record appended; fragile
fixture path in placement_test routed through repositoryFile.
…ions

Code-to-copy-and-recovery mapping ahead of the status fallback with
details rendering (blockers, fields, reason, capability), diagnostics
moved outside the auth guard, studio back control targets /workspace,
raw server messages routed through the mapper, rule-set archive uses a
focus-managed sheet without internal phase vocabulary, Access naming
reconciled, api version rows in diagnostics, unrepresentable empty-copy
states, fast-uri audit fix, node base image bump, relay as an explicit
check gate, dashboard docs contradiction fixed.
…te limiters, structured otel errors

Binary-mode govulncheck clean on 1.26.5 (8 called stdlib vulns on
1.26.2), X-Forwarded-For walked right-to-left past trusted hops with
forged-prefix tests, pinned edge address with a /32 trust default,
upload and export limiter families, otel errors through zerolog,
drill-evidence corrections with inline validator output, health
envelope spec widened, cross-surface verification record closing the
relay owner condition.
Toolchain directive so CI builds on 1.26.5, CI MinIO pinned to the
compose version via run steps with bucket creation, obsolete rate-limit
register entry removed, stale audit row corrected, 406 capability
details test case added, and the Phase 8 review document recording
Ready with documented limitations.
@Mujhtech
Mujhtech force-pushed the phase/8-operational-hardening branch from bf5d95a to ba1fffe Compare July 31, 2026 09:39
@Mujhtech
Mujhtech marked this pull request as ready for review July 31, 2026 09:39
@Mujhtech
Mujhtech merged commit cac9802 into development Jul 31, 2026
14 of 25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant