Skip to content

Remove governed envelopes; keep frame types 8 and 9 reserved - #46

Merged
TeoSlayer merged 1 commit into
mainfrom
remove-governed-envelopes
Oct 1, 2026
Merged

TeoSlayer merged 1 commit into
mainfrom
remove-governed-envelopes

Conversation

@TeoSlayer

Copy link
Copy Markdown
Contributor

Why

Governed delivery verified decisions signed by the hosted control plane. That control plane has been retired, and the daemon stopped configuring the governed receiver gates in v1.14.0 (pilotprotocol main has no reference to any Governed* name, RequireGoverned or SendGoverned*). The code could no longer be reached, and it was this module's only use of github.com/pilot-protocol/common/decision, which blocks removing that package from common.

Removed

  • governed.go, governed_stream.go, governed_replay.go, retention.go and their tests (governed_test.go, zz_governed_replay_test.go, retention_test.go).
  • ServiceConfig fields RequireGoverned, GovernedVerifier, GovernedStreamVerifier, RequireGovernedReceipts, GovernedReceiptRecorder, GovernedContentInspector, RequireGovernedContentInspection, GovernedTransferQuota, GovernedRetentionPolicies, RetentionStateDir, RetentionSweepInterval, in both service.go and the no_dataexchange stub.
  • The governed branches of handleConn (decode/verify, quota admission, content inspection, receipts, stream binding) and the config validation in Start.
  • Client.SendGoverned, SendGovernedWithDisclosure, SendGovernedFileStream* and the two authorizer types.
  • BuildStreamInitPayload in filestream.go (it only existed to bind a governed stream intent).
  • The retention manager. It was reachable only through GovernedRetentionPolicies plus a governed delivery carrying a disclosure binding, so it goes with the rest.

This is an exported-API removal; these names shipped in v0.2.3.

Kept for wire compatibility

TypeGoverned = 8 and TypeGovernedFileStream = 9 keep their constants and their TypeName entries and are documented as reserved, so the numbers are not handed to a new frame type while older senders can still emit them.

A receiver now refuses both through the existing unsupported-type path in handleConn: nothing is written to the inbox or the received directory, no event is published, the frame is not remembered by duplicate suppression, the sender gets ERR GOVERNED save failed: unsupported frame type 8 (or ERR GOVERNED_FILESTREAM save failed: unsupported frame type 9), and the connection stays open for further frames. A receiver with no verifier configured already refused both on main (... no verifier is configured); only the reason text changes.

TestService_ReservedGovernedTypesAreRefused covers this for plain, tagged and malformed frames of both types, sent twice each, followed by an ordinary text frame on the same connection. TestReservedGovernedTypesKeepTheirNames pins the numbers and names.

Not changed

Text, JSON, binary, file, trace and file-stream handling, duplicate suppression, inbox budget, ACK text and events. Two things are left in place on purpose to keep this a removal only:

  • persistedDelivery keeps its prepare/commit split and rollback; the service no longer calls rollback (a test still does).
  • The StreamReceiver prepare/commit hooks and NewStreamReceiverWithQuotaAndCommit / ...AndPrepareAndCommit stay exported; the service now uses NewStreamReceiverWithQuota.

Other test changes: TestService_TaggedGovernedFrameKeepsCorrelation is deleted, and TestSend_NewReceiverRejectionIsNotRetried now provokes the rejection with the inbox byte cap instead of RequireGoverned. The emulation of old deployed receivers (including ones that ran with RequireGoverned) in zz_correlation_test.go is kept, since Client.Send still has to recognise their answers.

What was run

In a fresh clone, on this branch:

  • GOWORK=off go build ./... and GOWORK=off go build -tags no_dataexchange ./...: pass
  • GOWORK=off go vet ./... (both tag sets): clean
  • GOWORK=off go test -race -count=1 ./...: pass, coverage 84.0% (main: 78.3%)
  • gofmt -l .: no output
  • GOWORK=off go mod tidy: no change to go.mod / go.sum; go directive still 1.25.13
  • no .go file imports common/decision or common/actionhook
  • the new refusal test fails against main's code, as expected
  • pilotprotocol main (4e5b1fe) with replace github.com/pilot-protocol/dataexchange => <this clone>: GOWORK=off GOFLAGS=-mod=mod go build ./... passes, and go vet ./cmd/... ./pkg/... ./internal/... is clean. Its ./tests suite was not run.

Not done here: no tag, and no end-to-end run on a live overlay.

🤖 Generated with Claude Code

The governed-delivery code verified decisions signed by the hosted control
plane. That control plane has been retired, and the daemon stopped
configuring the governed receiver gates in v1.14.0, so none of this could
be reached any more. It was also this module's only use of
github.com/pilot-protocol/common/decision.

Removed: governed.go, governed_stream.go, governed_replay.go and
retention.go with their tests; the Governed*/RequireGoverned*/Retention*
fields of ServiceConfig (and of the no_dataexchange stub); the governed
branches of handleConn; Client.SendGoverned*; BuildStreamInitPayload.
The retention manager goes too: it only ran for a governed delivery that
carried a disclosure binding.

Wire compatibility: TypeGoverned (8) and TypeGovernedFileStream (9) keep
their constants and TypeName entries and are documented as reserved. A
receiver refuses them through the existing unsupported-type path: nothing
is stored, no event is published, the reply is
"ERR GOVERNED save failed: unsupported frame type 8" (or
GOVERNED_FILESTREAM / 9), and the connection stays open. A receiver with
no verifier configured already refused both; only the reason text changes.

Ordinary text, JSON, binary, file, trace and file-stream handling is
unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@TeoSlayer
TeoSlayer merged commit e6728da into main Oct 1, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant