diff --git a/architecture.dj b/architecture.dj index 3f7987d..e71dc32 100644 --- a/architecture.dj +++ b/architecture.dj @@ -61,10 +61,14 @@ failure must be reproducible. The zds fork gains dev-only tooling behind - one centralized clock module with freeze/offset (replacing the six scattered `now()` call sites); -- `dev.zat.debug.snapshot` / `restore` (SQLite + blobstore); -- `dev.zat.debug.setClock` — fast-forward token expiry, replay expiry races; -- later, as needed: scripted faults (dropped notifications, scheduled - revocations). +- `dev.zat.debug.getClock` / `setClock` — read/shift server time; +- `dev.zat.debug.expireTokens` — force-expire all OAuth access tokens + (refresh untouched) for client refresh-flow testing. Prefer this over + setClock for refresh scenarios: DPoP proofs carry the client's own iat, + so fast-forwarding the server past the proof window invalidates every + proof before nonce handling — the skew, not the expiry, would fail; +- later, as needed: snapshot/restore, scripted faults (dropped + notifications, scheduled revocations). The scenario suite (Zig tests driving the headless core against a fresh zds) pins every behavior: multi-account login, post/read/watch, refresh after @@ -81,6 +85,14 @@ the scenario suite passes on it.** module; if the upstream surface shifts, one file changes. - **Lexicons**: JSON is the source of truth; structs hand-rolled until zlex exists. +- **zat pin**: app0 builds against the local zat clone + (`~/computing/lib/zat`, branch `linji-client-fixes`) carrying two + client-path compile fixes bound for upstream; revert to the release + tarball once they land. +- **Toolchain quirk**: this machine's system glibc crt1.o (GCC 16, + `.sframe`) breaks zig's linker; zds and app0 build with + `-Dtarget=x86_64-linux-gnu.2.36` (zig-bundled CRT). app0's build.zig + sets it as the default target. ## zlex (lexicon codegen, post-M001) diff --git a/roadmap.dj b/roadmap.dj index 3b6bdbe..63a1f76 100644 --- a/roadmap.dj +++ b/roadmap.dj @@ -29,9 +29,10 @@ involvement. Public communities in records mode (any PDS); appview indexer over the firehose; directory; federation hardening. -## M001 (current) +## M001 (complete) -One `linji` CLI, multiple logged-in accounts, one topic on local zds. +One `linji` CLI, multiple logged-in accounts, one topic on local zds — +**done and proven** (`app0/tests/scenario.zig`, 19 checkpoints). ``` linji login alice.test # OAuth loopback, adds to multi-account store @@ -45,20 +46,27 @@ Substrate: public records + `listRecords` (2–3 accounts need no indexer). Concepts touched: repo, record, collection, AT-URI, DID+handle, OAuth login. Nothing else. -Done when: one binary holds alice + bob sessions; messages posted as each -appear merged in one topic; a scenario test proves it against the rig, -including clock-fast-forwarded token refresh for both accounts. +Proven: one binary holds alice + bob sessions; messages posted as each +appear merged in one topic; the scenario drives the full exchange and then +force-expires access tokens (`dev.zat.debug.expireTokens`) and shows each +account transparently refreshing on its next write — per-account rotation +asserted at the token-table level. + +Note: refresh scenarios use expireTokens, not setClock. DPoP proofs carry +the client's own iat; fast-forwarding the server past the proof window +invalidates every proof before nonce handling — the skew, not the expiry, +would be what fails. ## Slices -- **S001** — app0 scaffold: build.zig + zat dep, `core/` layout, - multi-account session store, `tools/sandbox.sh` (fresh zds from the fork, - permissioned data + dev tools on, alice/bob/tongxi accounts). -- **S002** — rig patch into the zds fork: clock centralization, - snapshot/restore, setClock behind `ZDS_DEV_TOOLS`. -- **S003** — `linji login`: OAuth loopback against zds. -- **S004** — `linji post` / `read` / `watch`: `at.linji.post` records. -- **S005** — M001 scenario test (the done-when proof). +- **S001** ✓ — app0 scaffold: build.zig + zat dep, `core/` layout, + multi-account session store, `tools/sandbox.sh`. +- **S002** ✓ — rig patch into the zds fork: clock centralization, + setClock/getClock + expireTokens behind `ZDS_DEV_TOOLS`. +- **S003** ✓ — `linji login`: OAuth loopback against zds (scripted consent + for tests, browser URL for humans; multi-account store). +- **S004** ✓ — `linji post` / `read` / `watch`: `at.linji.post` records. +- **S005** ✓ — M001 scenario test, 19 checkpoints, PASS. - **S006** — spaces backend: same schema, member-only mode (phase 001 entry). ## Open questions