/** * Sanitized reference implementation of a fail-closed release gate. * * This module contains no customer source, secrets, signing keys, proprietary * schemas, or production endpoints. I/O and cryptographic verification belong * in adapters. The gate consumes their evidence and makes one deterministic * decision: a candidate is ready, or it is rejected with explicit reasons. */ export type ReleaseStatus = "ready" | "rejected"; export type CheckCode = | "candidate_identity" | "target_region" | "artifact_signature" | "artifact_hash" | "content_schema" | "content_age" | "runtime_proof" | "dependency_budget" | "smoke_tests" | "rollback_target"; export type ReleaseManifest = { revision: string; buildId: string; region: string; schemaVersion: number; createdAt: string; runtimeProofs: readonly string[]; dependencyBytes: number; }; export type VerificationEvidence = { candidateRevision: string; signatureValid: boolean; hashMatches: boolean; smokeTests: readonly { name: string; passed: boolean; }[]; rollbackTargetAvailable: boolean; }; export type ReleasePolicy = { expectedRegion: string; allowedSchemaVersions: readonly number[]; maxContentAgeMs: number; requiredRuntime: string; dependencyBudgetBytes: number; requireRollbackTarget: boolean; }; export type ReleaseCheck = { code: CheckCode; label: string; passed: boolean; detail: string; }; export type ReleaseDecision = { status: ReleaseStatus; checks: readonly ReleaseCheck[]; failedCodes: readonly CheckCode[]; evaluatedAt: string; }; function check( code: CheckCode, label: string, passed: boolean, detail: string, ): ReleaseCheck { return { code, label, passed, detail }; } function formatBytes(bytes: number): string { return `${(bytes / 1024 / 1024).toFixed(1)} MB`; } export function evaluateRelease( manifest: ReleaseManifest, evidence: VerificationEvidence, policy: ReleasePolicy, nowMs: number, ): ReleaseDecision { const createdAtMs = Date.parse(manifest.createdAt); const contentAgeMs = nowMs - createdAtMs; const hasValidTimestamp = Number.isFinite(createdAtMs); const contentAgeIsValid = hasValidTimestamp && contentAgeMs >= 0 && contentAgeMs <= policy.maxContentAgeMs; const allSmokeTestsPass = evidence.smokeTests.length > 0 && evidence.smokeTests.every((test) => test.passed); const checks: readonly ReleaseCheck[] = [ check( "candidate_identity", "Candidate identity", manifest.revision.length > 0 && manifest.buildId.length > 0 && manifest.revision === evidence.candidateRevision, `manifest ${manifest.revision || "missing"} / evidence ${ evidence.candidateRevision || "missing" }`, ), check( "target_region", "Target region", manifest.region === policy.expectedRegion, `${manifest.region} must equal ${policy.expectedRegion}`, ), check( "artifact_signature", "Artifact signature", evidence.signatureValid, evidence.signatureValid ? "cryptographic adapter reported a valid signature" : "signature evidence is missing or invalid", ), check( "artifact_hash", "Artifact hash", evidence.hashMatches, evidence.hashMatches ? "candidate bytes match the signed manifest" : "candidate bytes do not match the signed manifest", ), check( "content_schema", "Content schema", policy.allowedSchemaVersions.includes(manifest.schemaVersion), `schema v${manifest.schemaVersion}; allowed: ${policy.allowedSchemaVersions.join( ", ", )}`, ), check( "content_age", "Content age", contentAgeIsValid, hasValidTimestamp ? `${Math.max(0, Math.round(contentAgeMs / 60_000))} minutes old; limit ${Math.round( policy.maxContentAgeMs / 60_000, )}` : "manifest timestamp is invalid", ), check( "runtime_proof", "Runtime proof", manifest.runtimeProofs.includes(policy.requiredRuntime), `${policy.requiredRuntime} proof must be present`, ), check( "dependency_budget", "Dependency budget", manifest.dependencyBytes <= policy.dependencyBudgetBytes, `${formatBytes(manifest.dependencyBytes)} / ${formatBytes( policy.dependencyBudgetBytes, )}`, ), check( "smoke_tests", "Candidate smoke tests", allSmokeTestsPass, `${evidence.smokeTests.filter((test) => test.passed).length}/${ evidence.smokeTests.length } checks passed`, ), check( "rollback_target", "Rollback target", !policy.requireRollbackTarget || evidence.rollbackTargetAvailable, evidence.rollbackTargetAvailable ? "previous verified artifact is available" : "no verified rollback target is available", ), ]; const failedCodes = checks .filter((item) => !item.passed) .map((item) => item.code); return { status: failedCodes.length === 0 ? "ready" : "rejected", checks, failedCodes, evaluatedAt: new Date(nowMs).toISOString(), }; }