feat(wake): W3 — cumulative-state digest renderer + non-circular HMAC signer (#904)
All checks were successful
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/ci Pipeline was successful

Co-authored-by: jason.woltje <jason@diversecanvas.com>
Co-committed-by: jason.woltje <jason@diversecanvas.com>
This commit was merged in pull request #904.
This commit is contained in:
2026-07-26 00:32:12 +00:00
committed by Mos
parent dc45eb7c30
commit 10d957d095
5 changed files with 1042 additions and 9 deletions

View File

@@ -1,6 +1,6 @@
# Mosaic wake component — VERSION metadata manifest (Gate B).
#
# EPIC #892, W2 of the wake/heartbeat canon.
# EPIC #892, W2 + W3 of the wake/heartbeat canon.
#
# SCOPE — THIS FILE IS VERSION METADATA ONLY. It declares the wake component's
# semantic version and the RANGE of watch-list schema versions it supports. It
@@ -10,9 +10,11 @@
#
# Format: KEY=VALUE, one per line. '#' and blank lines ignored.
# Component identity + semantic version (the store+drain lib + ack-wrapper).
# Component identity + semantic version.
# 0.1.0 W2 — store+drain lib + ack-wrapper.
# 0.2.0 W3 — cumulative-state digest renderer + non-circular HMAC signer.
component=wake
version=0.1.0
version=0.2.0
# Watch-list schema this component consumes, and the INCLUSIVE range of
# schema_version values it supports. A wake-watch-list.json whose schema_version
@@ -22,8 +24,12 @@ schema=wake-watch-list
schema_min=1
schema_max=1
# W2 pieces shipped by this component version (informational):
# store.sh A2 — three-cursor durable store + drain lib.
# ack.sh A4 — RECEIVED/CONSUMED ack-wrapper (local-write + async ship).
# Out of W2 scope (later waves): detector (W4), digest renderer/HMAC (W3),
# FN-oracle/reconciler (W5), beacon (W6), installer (W7).
# Pieces shipped by this component version (informational):
# store.sh A2 — three-cursor durable store + drain lib. (W2)
# ack.sh A4 — RECEIVED/CONSUMED ack-wrapper (local-write + ship). (W2)
# digest.sh A3 — cumulative-state digest renderer (hard locators,
# two-tier trust, injection/secret scrub). (W3)
# sign.sh A5 — non-circular HMAC signer (independent wake_id,
# load_credentials by-name; fills the hmac placeholder). (W3)
# Out of scope (later waves): detector (W4), FN-oracle/reconciler (W5),
# beacon (W6), installer (W7).