Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
90 commits
Select commit Hold shift + click to select a range
c4a2162
docs: establish v1.13.11 closure correction baseline
franchoy Jul 20, 2026
40a9462
chore: activate v1.13.11 release identity
franchoy Jul 20, 2026
f748675
docs: classify v1.13.11 backend compatibility claims
franchoy Jul 20, 2026
7259b9d
test: add reusable dual-backend harness
franchoy Jul 20, 2026
0147851
ci: execute PostgreSQL internal package contracts
franchoy Jul 20, 2026
6e1a067
docs: record phase 4 PostgreSQL CI evidence
franchoy Jul 20, 2026
2b603b7
test: prove schema bootstrap and migration contracts
franchoy Jul 21, 2026
bfe4917
test: capture G6 packed-block rebuild diagnostics
franchoy Jul 21, 2026
54ecd84
fix: refuse partial rebuild of shared packed blocks
franchoy Jul 21, 2026
460ff67
docs: close phase 5 schema and G6 CI evidence
franchoy Jul 23, 2026
c03c42b
test: prove implemented catalog contracts across backends
franchoy Jul 23, 2026
db12c3d
fix: make snapshot listing order deterministic
franchoy Jul 23, 2026
5051752
docs: record phase 6 catalog parity CI evidence
franchoy Jul 23, 2026
3e8c98d
test: prove engine read contracts across backends
franchoy Jul 23, 2026
313d006
fix: release deep-verify rows before block queries
franchoy Jul 23, 2026
ab8accb
docs: record phase 7 engine read parity CI evidence
franchoy Jul 23, 2026
bcae357
test: close snapshot selector determinism contracts
franchoy Jul 24, 2026
8a7b998
docs: record phase 8 selector parity CI evidence
franchoy Jul 24, 2026
848e579
test: prove engine mutation outcomes across backends
franchoy Jul 24, 2026
e4c7760
docs: record phase 9 mutation parity CI evidence
franchoy Jul 24, 2026
ad82c95
test: prove backend transaction and row-lock semantics
franchoy Jul 25, 2026
81dd0da
docs: record phase 10 transaction semantics CI evidence
franchoy Jul 25, 2026
84d4ce7
feat: define repository coordination contract
franchoy Jul 25, 2026
7b26241
test: add benchmark gate calibration harness
franchoy Jul 25, 2026
68cf839
ci: launch Phase 11 benchmark calibration
Jul 25, 2026
19e7df1
ci: remove temporary benchmark calibration launcher
Jul 25, 2026
a4bf7d4
test: add benchmark final-state diagnostics
Jul 26, 2026
c5dd3d5
test: classify benchmark gate invariants
Jul 26, 2026
06b4a81
test: make SQL driver fixture repeat-safe
Jul 26, 2026
d9cbdec
ci: launch corrected-contract benchmark calibration
Jul 26, 2026
e797fc1
ci: remove corrected-contract calibration launcher
Jul 26, 2026
f6ce216
test: correct benchmark final-state model
Jul 26, 2026
67e1826
ci: launch diagnostic-v2 benchmark calibration
franchoy Jul 27, 2026
835208a
ci: remove diagnostic-v2 calibration launcher
franchoy Jul 27, 2026
747e5c3
docs: define paired benchmark gate contract
franchoy Jul 27, 2026
e25b825
test: add paired benchmark gate harness
franchoy Jul 27, 2026
4ce5bfa
test: enable paired diagnostic qualification decision
Aug 1, 2026
0e63396
ci: launch paired benchmark qualification
Aug 1, 2026
7dcfdc7
ci: remove paired benchmark qualification launcher
Aug 1, 2026
95d54f7
benchmark: add bounded paired v2 diagnostic fixtures
Aug 1, 2026
eeb913a
ci: harden paired diagnostic evidence lifecycle
Aug 1, 2026
afd375e
docs: record rejected qualification and bounded remediation
Aug 1, 2026
d05d32c
ci: launch bounded paired v2 qualification
Aug 1, 2026
741e992
ci: remove bounded paired v2 qualification launcher
Aug 1, 2026
0e47602
ci: enforce paired launcher output ownership
Aug 1, 2026
15bd01b
ci: launch bounded paired v2 qualification
Aug 1, 2026
12fc63a
ci: remove bounded paired v2 qualification launcher
Aug 1, 2026
01f1ea6
benchmark: separate integrity from hosted timing advice
Aug 1, 2026
8ef9c89
ci: require benchmark integrity and preserve timing warnings
Aug 1, 2026
3a6e000
docs: adopt Phase 11 hosted timing advisory policy
Aug 1, 2026
b08da99
benchmark: align hosted advisory with small report contract
Aug 8, 2026
d871ad5
docs: close Phase 11 repository coordination contract
Aug 8, 2026
b63bd34
coordination: prepare repository control namespace
Aug 8, 2026
e13db33
coordination: add owner metadata and process reservation
Aug 8, 2026
ac1a6bb
coordination: add unix native repository locking
Aug 8, 2026
bbe2e18
coordination: add windows native repository locking
Aug 8, 2026
5b8f749
cli: acquire repository lease before recovery and database work
Aug 8, 2026
9934bc9
coordination: stabilize errors and direct caller contract
Aug 8, 2026
6a36804
ci: run native coordination tests across platforms
Aug 8, 2026
cf75530
test: align adversarial stores with repository coordination
Aug 8, 2026
eba01b2
docs: record Phase 12G and 13A CI evidence
Aug 8, 2026
c1b5e4d
docs: close Phase 12 repository coordination runtime
Aug 9, 2026
5bdaa44
test: prove repository lease release after holder death
Aug 9, 2026
4aa2e75
test: satisfy killed-holder staticcheck
Aug 9, 2026
7018432
docs: record Phase 13B killed-holder evidence
Aug 9, 2026
da78614
fix: pin GC advisory lock to one PostgreSQL session
Aug 9, 2026
54b1a04
test: prove live GC cross-process repository barrier
Aug 9, 2026
d4b9cae
docs: record Phase 13C live GC coordination evidence
Aug 9, 2026
aa0a9df
docs: close Phase 13 multi-process coordination
Aug 9, 2026
fc88a4e
fix: validate container ranges and header size consistency
Aug 9, 2026
314e2ad
fix: preserve container maximum during recovery
Aug 9, 2026
2cc39c1
test: preserve recovery maximum assertions
Aug 9, 2026
a576b19
fix: retain orphan recovery size marker semantics
Aug 9, 2026
a5ab52d
docs: close Phase 14 container hardening
Aug 9, 2026
4213f3c
fix: bound decompression output before allocation
Aug 9, 2026
15b7e26
docs: close Phase 15 bounded decompression
Aug 9, 2026
5dcf004
fix: preserve exact integers in JSON output
Aug 9, 2026
eff7ae5
docs: close Phase 16 JSON integer fidelity
Aug 9, 2026
0c50113
fix: fail closed on SQL mutation cardinality
Aug 15, 2026
de741d5
docs: close Phase 17 SQL mutation audit
Aug 15, 2026
975453d
ci: require backend and coordination contracts
Aug 15, 2026
eaa5896
ci: preserve audit status patterns
Aug 15, 2026
9c1fa52
docs: close Phase 18 required CI gate
Aug 15, 2026
39526e3
docs: close Phase 19 validation reconciliation
Aug 18, 2026
0565b02
docs: prepare v1.13.11 exact-head release candidate
Aug 18, 2026
22b2ea7
ci: harden benchmark calibration trust boundary
Aug 18, 2026
d18c3e5
fix(ci): harden benchmark tooling checks
Aug 18, 2026
632d2e1
refactor: reduce production Codacy complexity
Aug 18, 2026
5fd0fe6
refactor: reduce test tooling Codacy complexity
Aug 18, 2026
a2b903a
fix(ci): close remaining Codacy findings
Aug 18, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
206 changes: 206 additions & 0 deletions .github/workflows/benchmark-baseline.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,206 @@
name: Benchmark Gate Calibration and Baseline Capture

on:
workflow_dispatch:
inputs:
mode:
description: Calibration uses two ten-sample replicas; capture uses one five-sample profile.
required: true
type: choice
options:
- calibration
- capture
source_sha:
description: Confirm the exact protected-main dispatch SHA to build and measure.
required: true
type: string

permissions:
contents: read

env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
COLDKEEP_AES_GCM_FIXTURE_HEX: ${{ format('{0}{1}{0}{1}{0}{1}{0}{1}', '01234567', '89abcdef') }}
POSTGRES_IMAGE_DIGEST: sha256:33f923b05f64ca54ac4401c01126a6b92afe839a0aa0a52bc5aeb5cc958e5f20

jobs:
authorize:
runs-on: ubuntu-24.04
timeout-minutes: 5
steps:
- name: Validate trusted benchmark source
env:
SOURCE_SHA: ${{ inputs.source_sha }}
TRUSTED_REF: ${{ github.ref }}
TRUSTED_SHA: ${{ github.sha }}
run: |
set -euo pipefail
if [[ "${TRUSTED_REF}" != "refs/heads/main" ]]; then
echo "benchmark calibration must be dispatched from refs/heads/main" >&2
exit 2
fi
if ! [[ "${SOURCE_SHA}" =~ ^[0-9a-f]{40}$ ]]; then
echo "source_sha must be a full lowercase commit SHA" >&2
exit 2
fi
if [[ "${SOURCE_SHA}" != "${TRUSTED_SHA}" ]]; then
echo "source_sha must equal the trusted workflow dispatch SHA" >&2
exit 2
fi

sample:
needs: authorize
runs-on: ubuntu-24.04
timeout-minutes: 30
services:
postgres:
image: postgres:16@sha256:33f923b05f64ca54ac4401c01126a6b92afe839a0aa0a52bc5aeb5cc958e5f20
env:
POSTGRES_USER: coldkeep
POSTGRES_PASSWORD: coldkeep
POSTGRES_DB: coldkeep
ports:
- 5432:5432
options: >-
--health-cmd "pg_isready -U coldkeep -d coldkeep"
--health-interval 10s
--health-timeout 5s
--health-retries 5
strategy:
fail-fast: false
matrix:
compression: [none, zstd]
workers: [1, 4]
replicate: [1, 2]

steps:
- name: Checkout trusted source
if: ${{ inputs.mode == 'calibration' || matrix.replicate == 1 }}
uses: actions/checkout@v6
with:
ref: ${{ github.sha }}
fetch-depth: 0
persist-credentials: false

- name: Verify trusted checkout
if: ${{ inputs.mode == 'calibration' || matrix.replicate == 1 }}
env:
TRUSTED_SHA: ${{ github.sha }}
run: |
test "$(git rev-parse HEAD)" = "${TRUSTED_SHA}"

- name: Setup exact Go toolchain
if: ${{ inputs.mode == 'calibration' || matrix.replicate == 1 }}
uses: actions/setup-go@v6
with:
go-version: '1.25.12'
cache: false

- name: Build benchmark binary once
if: ${{ inputs.mode == 'calibration' || matrix.replicate == 1 }}
run: go build -o coldkeep ./cmd/coldkeep

- name: Capture fixed benchmark samples
if: ${{ inputs.mode == 'calibration' || matrix.replicate == 1 }}
env:
SOURCE_SHA: ${{ github.sha }}
CAPTURE_MODE: ${{ inputs.mode }}
COLDKEEP_DB_AUTO_BOOTSTRAP: true
COLDKEEP_CODEC: aes-gcm
COLDKEEP_COMPRESSION: ${{ matrix.compression }}
COLDKEEP_KEY: ${{ env.COLDKEEP_AES_GCM_FIXTURE_HEX }}
COLDKEEP_CONTAINER_LOCK_RETRY_ATTEMPTS: 12
COLDKEEP_CONTAINER_LOCK_RETRY_BASE_WAIT_MS: 15
COLDKEEP_CONTAINER_LOCK_RETRY_MAX_WAIT_MS: 900
DB_HOST: 127.0.0.1
DB_PORT: 5432
DB_USER: coldkeep
DB_PASSWORD: coldkeep
DB_NAME: coldkeep
DB_SSLMODE: disable
run: |
sample_count=10
if [ "${CAPTURE_MODE}" = "capture" ]; then
sample_count=5
fi
profile="${{ matrix.compression }}-w${{ matrix.workers }}-r${{ matrix.replicate }}"
postgres_version="$(docker exec '${{ job.services.postgres.id }}' postgres --version)"
python3 scripts/benchmark_gate.py sample \
--binary ./coldkeep \
--output-dir "evidence/${profile}" \
--compression '${{ matrix.compression }}' \
--workers '${{ matrix.workers }}' \
--dataset ci-stable-v1 \
--warmups 1 \
--samples "${sample_count}" \
--source-commit "${SOURCE_SHA}" \
--go-version "$(go version)" \
--postgres-version "${postgres_version}" \
--database-image-digest "${POSTGRES_IMAGE_DIGEST}"

- name: Upload immutable sample evidence
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
if: ${{ always() && (inputs.mode == 'calibration' || matrix.replicate == 1) }}
uses: actions/upload-artifact@v7
with:
name: benchmark-${{ inputs.mode }}-${{ matrix.compression }}-w${{ matrix.workers }}-r${{ matrix.replicate }}
path: evidence/${{ matrix.compression }}-w${{ matrix.workers }}-r${{ matrix.replicate }}
if-no-files-found: error

calibration:
if: ${{ inputs.mode == 'calibration' }}
runs-on: ubuntu-24.04
needs: sample
timeout-minutes: 10
steps:
- name: Checkout calibration harness
uses: actions/checkout@v6
with:
ref: ${{ github.sha }}
persist-credentials: false

- name: Download calibration evidence
uses: actions/download-artifact@v8
with:
pattern: benchmark-calibration-*
path: ${{ runner.temp }}/benchmark-calibration-input

- name: Evaluate the fixed calibration matrix
run: |
mapfile -t aggregates < <(
find "${RUNNER_TEMP}/benchmark-calibration-input" \
-mindepth 2 -maxdepth 2 -name aggregate.json -print | sort
)
args=()
for aggregate in "${aggregates[@]}"; do
artifact="$(basename "$(dirname "${aggregate}")")"
profile="${artifact#benchmark-calibration-}"
args+=(--aggregate "${profile}=${aggregate}")
done
python3 - "${GITHUB_SHA}" "${aggregates[@]}" <<'PY'
import json
import pathlib
import sys

expected = sys.argv[1]
for raw_path in sys.argv[2:]:
path = pathlib.Path(raw_path)
with path.open(encoding="utf-8") as handle:
report = json.load(handle)
actual = report.get("provenance", {}).get("source_commit")
if actual != expected:
raise SystemExit(
f"{path}: source_commit {actual!r} does not match trusted SHA {expected}"
)
PY
python3 scripts/benchmark_gate.py calibrate \
"${args[@]}" \
--thresholds benchmarks/v1.9/regression-thresholds.yaml \
--output calibration-report.json

- name: Upload calibration decision
if: always()
uses: actions/upload-artifact@v7
with:
name: benchmark-calibration-decision
path: calibration-report.json
if-no-files-found: error
Loading