mirror of
https://github.com/ruvnet/RuView.git
synced 2026-08-31 04:25:54 +00:00
feat: implement ADR-292/293/294/295/296 — provenance, UDP hardening, multi-node, model gates, CSI policy
ADR-292 (sensing-server): SourceState enum + pure transition (provenance.rs); auth-error/unknown can never resolve to LiveVerified; synthetic exports watermarked. Pose-fusion simulator starts SYNTHETIC and only shows LIVE on a real decoded frame (#1557); sensing client no longer labels an unauthorized status endpoint as live (#1526). ADR-294 (sensing-server): NodeInference distinct from RoomInference (inference.rs); deterministic freshness-weighted fuse_room; RateLimiter re-keyed to (NodeId,EntityKind) so nodes do not starve each other (#1541); stale nodes go unavailable not frozen-online (#1555). ADR-293 (sensing-server): --udp-bind (default 127.0.0.1) + --udp-allow allowlist + fail-closed refusal of routable bind without allowlist unless --udp-insecure-lan (udp_bind.rs); crate SECURITY.md documents the threat model and the deferred per-device-auth step two. ADR-295 (train): model_gates.rs — constant-output, unreachable-boundary (the issue-1521 degenerate presence head), class-balance, baseline, and metric-name-provenance gates. ADR-296 (ci): scripts/csi-data-policy-check.sh (+ allowlist) and a workflow that fails on tracked CSI-format/oversized-JSONL files; 6/6 self-tests pass. Per-crate suites reported green by the swarm; CSI policy self-test 6/6 and JS syntax verified here. Full workspace re-verification deferred until the concurrent phase-1 spine build frees the target dir (disk pressure). Co-Authored-By: claude-flow <ruv@ruv.net> Claude-Session: https://claude.ai/code/session_015TcKegTS7QqhWPC2L2SzaS
This commit is contained in:
14
scripts/csi-data-policy.allow
Normal file
14
scripts/csi-data-policy.allow
Normal file
@@ -0,0 +1,14 @@
|
||||
# csi-data-policy.allow — ADR-296 synthetic-fixture allowlist.
|
||||
#
|
||||
# One shell glob per line (repo-relative paths). `#` starts a comment; blank
|
||||
# lines are ignored. A tracked/staged file whose path matches any pattern here
|
||||
# is exempt from the CSI data-policy check (scripts/csi-data-policy-check.sh).
|
||||
#
|
||||
# ONLY synthetic or expressly-consented minimal fixtures belong here (ADR-296).
|
||||
# Never allowlist a real capture to silence the guard — real CSI is person data.
|
||||
# The CSI_POLICY_ALLOW env var appends extra patterns (colon-separated) for
|
||||
# one-off/local use.
|
||||
#
|
||||
# Conventional location for synthetic CSI test fixtures generated by tests:
|
||||
scripts/tests/fixtures/csi-policy/*.csi.jsonl
|
||||
scripts/tests/fixtures/csi-policy/*.csi.meta.json
|
||||
Reference in New Issue
Block a user