Remove governed envelopes; keep frame types 8 and 9 reserved - #46
Merged
Merged
Conversation
The governed-delivery code verified decisions signed by the hosted control plane. That control plane has been retired, and the daemon stopped configuring the governed receiver gates in v1.14.0, so none of this could be reached any more. It was also this module's only use of github.com/pilot-protocol/common/decision. Removed: governed.go, governed_stream.go, governed_replay.go and retention.go with their tests; the Governed*/RequireGoverned*/Retention* fields of ServiceConfig (and of the no_dataexchange stub); the governed branches of handleConn; Client.SendGoverned*; BuildStreamInitPayload. The retention manager goes too: it only ran for a governed delivery that carried a disclosure binding. Wire compatibility: TypeGoverned (8) and TypeGovernedFileStream (9) keep their constants and TypeName entries and are documented as reserved. A receiver refuses them through the existing unsupported-type path: nothing is stored, no event is published, the reply is "ERR GOVERNED save failed: unsupported frame type 8" (or GOVERNED_FILESTREAM / 9), and the connection stays open. A receiver with no verifier configured already refused both; only the reason text changes. Ordinary text, JSON, binary, file, trace and file-stream handling is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Governed delivery verified decisions signed by the hosted control plane. That control plane has been retired, and the daemon stopped configuring the governed receiver gates in v1.14.0 (
pilotprotocolmain has no reference to anyGoverned*name,RequireGovernedorSendGoverned*). The code could no longer be reached, and it was this module's only use ofgithub.com/pilot-protocol/common/decision, which blocks removing that package fromcommon.Removed
governed.go,governed_stream.go,governed_replay.go,retention.goand their tests (governed_test.go,zz_governed_replay_test.go,retention_test.go).ServiceConfigfieldsRequireGoverned,GovernedVerifier,GovernedStreamVerifier,RequireGovernedReceipts,GovernedReceiptRecorder,GovernedContentInspector,RequireGovernedContentInspection,GovernedTransferQuota,GovernedRetentionPolicies,RetentionStateDir,RetentionSweepInterval, in bothservice.goand theno_dataexchangestub.handleConn(decode/verify, quota admission, content inspection, receipts, stream binding) and the config validation inStart.Client.SendGoverned,SendGovernedWithDisclosure,SendGovernedFileStream*and the two authorizer types.BuildStreamInitPayloadinfilestream.go(it only existed to bind a governed stream intent).GovernedRetentionPoliciesplus a governed delivery carrying a disclosure binding, so it goes with the rest.This is an exported-API removal; these names shipped in v0.2.3.
Kept for wire compatibility
TypeGoverned = 8andTypeGovernedFileStream = 9keep their constants and theirTypeNameentries and are documented as reserved, so the numbers are not handed to a new frame type while older senders can still emit them.A receiver now refuses both through the existing unsupported-type path in
handleConn: nothing is written to the inbox or the received directory, no event is published, the frame is not remembered by duplicate suppression, the sender getsERR GOVERNED save failed: unsupported frame type 8(orERR GOVERNED_FILESTREAM save failed: unsupported frame type 9), and the connection stays open for further frames. A receiver with no verifier configured already refused both on main (... no verifier is configured); only the reason text changes.TestService_ReservedGovernedTypesAreRefusedcovers this for plain, tagged and malformed frames of both types, sent twice each, followed by an ordinary text frame on the same connection.TestReservedGovernedTypesKeepTheirNamespins the numbers and names.Not changed
Text, JSON, binary, file, trace and file-stream handling, duplicate suppression, inbox budget, ACK text and events. Two things are left in place on purpose to keep this a removal only:
persistedDeliverykeeps its prepare/commit split androllback; the service no longer callsrollback(a test still does).StreamReceiverprepare/commit hooks andNewStreamReceiverWithQuotaAndCommit/...AndPrepareAndCommitstay exported; the service now usesNewStreamReceiverWithQuota.Other test changes:
TestService_TaggedGovernedFrameKeepsCorrelationis deleted, andTestSend_NewReceiverRejectionIsNotRetriednow provokes the rejection with the inbox byte cap instead ofRequireGoverned. The emulation of old deployed receivers (including ones that ran withRequireGoverned) inzz_correlation_test.gois kept, sinceClient.Sendstill has to recognise their answers.What was run
In a fresh clone, on this branch:
GOWORK=off go build ./...andGOWORK=off go build -tags no_dataexchange ./...: passGOWORK=off go vet ./...(both tag sets): cleanGOWORK=off go test -race -count=1 ./...: pass, coverage 84.0% (main: 78.3%)gofmt -l .: no outputGOWORK=off go mod tidy: no change togo.mod/go.sum;godirective still 1.25.13.gofile importscommon/decisionorcommon/actionhookpilotprotocolmain (4e5b1fe) withreplace github.com/pilot-protocol/dataexchange => <this clone>:GOWORK=off GOFLAGS=-mod=mod go build ./...passes, andgo vet ./cmd/... ./pkg/... ./internal/...is clean. Its./testssuite was not run.Not done here: no tag, and no end-to-end run on a live overlay.
🤖 Generated with Claude Code