ticket: close backend resource fetch work

This commit is contained in:
Keisuke Hirata 2026-07-08 20:55:03 +09:00
parent 01f94b7591
commit a645ee5b79
No known key found for this signature in database
3 changed files with 116 additions and 2 deletions

View File

@ -1,8 +1,8 @@
--- ---
title: 'Add Runtime-to-Backend resource fetch REST API' title: 'Add Runtime-to-Backend resource fetch REST API'
state: 'inprogress' state: 'closed'
created_at: '2026-07-08T09:12:33Z' created_at: '2026-07-08T09:12:33Z'
updated_at: '2026-07-08T11:53:02Z' updated_at: '2026-07-08T11:54:55Z'
assignee: null assignee: null
queued_by: 'workspace-panel' queued_by: 'workspace-panel'
queued_at: '2026-07-08T10:04:10Z' queued_at: '2026-07-08T10:04:10Z'

View File

@ -0,0 +1,36 @@
完了。
実装内容:
- Runtime-to-Backend resource fetch contract を追加した。
- Backend-issued typed resource handle と `BackendResourceBroker` を実装した。
- v0 resource kind `profile_source_archive` を fetch / verify / cache できるようにした。
- embedded direct Runtime path と remote Runtime HTTP path が同じ typed resource contract を使うようにした。
- Runtime は handle に基づき archive を fetch し、digest / max bytes / content type / expiry / binding を検証してから cache/reuse するようにした。
- Backend broker は stored issued handle を authority として扱い、Runtime-provided mutable handle fields による expiry / max_bytes / policy tampering を fail closed するようにした。
- Runtime cache は Backend authorization / expiry / binding を bypass しないようにした。
- Decodal ProfileSourceArchive / config bundle path を resource fetch boundary に接続し、Runtime filesystem discovery を再導入しない形にした。
- Browser-facing summaries は internal resource handle / endpoint / raw path / archive content/digest/store path / token 等を出さないようにした。
- Focused worker-runtime / workspace-server tests を追加した。
主な commit / merge:
- implementation: `57e96d3b feat: add backend resource fetch api`
- review fix: `e716ae44 fix: harden backend resource handles`
- merge into orchestration: `01f94b75 merge: backend resource fetch api`
Review:
- 初回 external review は request_changes。
- follow-up external review は approve。merge-blocking issue なし。
Final validation in Orchestrator worktree:
- `git diff --check`: pass
- `cargo test -p worker-runtime --features ws-server,fs-store`: pass45 lib tests + 5 main tests + doc tests
- `cargo test -p yoi-workspace-server`: pass77 lib tests + 2 main tests
- `cargo check -p yoi`: pass
- `cd web/workspace && deno task check`: pass0 errors / 0 warnings
- `cd web/workspace && deno task test`: pass17 tests
- `yoi ticket doctor`: ok
- `nix build .#yoi --no-link`: pass
補足:
- Reviewer の non-blocking follow-up: stored `audit_correlation_id` echo と Runtime-side response `resource_id` check、remote HTTP response-size limiting のさらなる強化余地。
- queued `00001KX0DSMPT` については、resource-fetch API shape が確定したため再 routing 可能。

View File

@ -317,3 +317,81 @@ Effect on queued `00001KX0DSMPT`:
- blocking concern なし。profile/archive details は redacted summaries behind boundary に留まっており、future settings UI/API が profile metadata を consume しても handles を露出しない設計と互換。 - blocking concern なし。profile/archive details は redacted summaries behind boundary に留まっており、future settings UI/API が profile metadata を consume しても handles を露出しない設計と互換。
--- ---
<!-- event: state_changed author: orchestrator at: 2026-07-08T11:54:39Z from: inprogress to: done reason: merged_validated_review_approved field: state -->
## State changed
Merge/validation acceptance:
- Follow-up external review approved the implementation after blocker fix。
- Implementation branch `work/00001KX0G06VA-resource-fetch-api` was merged into the orchestration branch with merge commit `01f94b75 merge: backend resource fetch api`
- Final validation in Orchestrator worktree passed:
- `git diff --check`: pass
- `cargo test -p worker-runtime --features ws-server,fs-store`: pass45 lib tests + 5 main tests + doc tests
- `cargo test -p yoi-workspace-server`: pass77 lib tests + 2 main tests
- `cargo check -p yoi`: pass
- `cd web/workspace && deno task check`: pass0 errors / 0 warnings
- `cd web/workspace && deno task test`: pass17 tests
- `yoi ticket doctor`: ok
- `nix build .#yoi --no-link`: pass
Implementation commits:
- `57e96d3b feat: add backend resource fetch api`
- `e716ae44 fix: harden backend resource handles`
No merge-blocking issues remain. Reviewer noted no blocking concern for queued `00001KX0DSMPT`; the resource-fetch API shape is now stable enough for that follow-up to be re-routed.
---
<!-- event: state_changed author: hare at: 2026-07-08T11:54:54Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-07-08T11:54:55Z status: closed -->
## 完了
完了。
実装内容:
- Runtime-to-Backend resource fetch contract を追加した。
- Backend-issued typed resource handle と `BackendResourceBroker` を実装した。
- v0 resource kind `profile_source_archive` を fetch / verify / cache できるようにした。
- embedded direct Runtime path と remote Runtime HTTP path が同じ typed resource contract を使うようにした。
- Runtime は handle に基づき archive を fetch し、digest / max bytes / content type / expiry / binding を検証してから cache/reuse するようにした。
- Backend broker は stored issued handle を authority として扱い、Runtime-provided mutable handle fields による expiry / max_bytes / policy tampering を fail closed するようにした。
- Runtime cache は Backend authorization / expiry / binding を bypass しないようにした。
- Decodal ProfileSourceArchive / config bundle path を resource fetch boundary に接続し、Runtime filesystem discovery を再導入しない形にした。
- Browser-facing summaries は internal resource handle / endpoint / raw path / archive content/digest/store path / token 等を出さないようにした。
- Focused worker-runtime / workspace-server tests を追加した。
主な commit / merge:
- implementation: `57e96d3b feat: add backend resource fetch api`
- review fix: `e716ae44 fix: harden backend resource handles`
- merge into orchestration: `01f94b75 merge: backend resource fetch api`
Review:
- 初回 external review は request_changes。
- follow-up external review は approve。merge-blocking issue なし。
Final validation in Orchestrator worktree:
- `git diff --check`: pass
- `cargo test -p worker-runtime --features ws-server,fs-store`: pass45 lib tests + 5 main tests + doc tests
- `cargo test -p yoi-workspace-server`: pass77 lib tests + 2 main tests
- `cargo check -p yoi`: pass
- `cd web/workspace && deno task check`: pass0 errors / 0 warnings
- `cd web/workspace && deno task test`: pass17 tests
- `yoi ticket doctor`: ok
- `nix build .#yoi --no-link`: pass
補足:
- Reviewer の non-blocking follow-up: stored `audit_correlation_id` echo と Runtime-side response `resource_id` check、remote HTTP response-size limiting のさらなる強化余地。
- queued `00001KX0DSMPT` については、resource-fetch API shape が確定したため再 routing 可能。
---