Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
101 commits
Select commit Hold shift + click to select a range
a02dfce
security: harden repository and begin ABI split
bedipritpal Sep 22, 2026
792874e
build: fetch mbedTLS framework submodule
bedipritpal Sep 23, 2026
9030bc0
ci: fetch full history so git describe finds tags
bedipritpal Sep 23, 2026
3be72aa
ci: add apply-patch workflow
bedipritpal Sep 23, 2026
03ee675
Merge pull request #1 from bedipritpal/remediation/v1.09.69-hardening
bedipritpal Sep 23, 2026
b465884
Update ci.yml
bedipritpal Sep 23, 2026
b9df38c
trace: log every wire round trip and table-park decisions (wire_trace…
Sep 23, 2026
b539684
perf: answer empty-table GO 0, post-bottom keycount, table type, reco…
Sep 23, 2026
36b5070
fix: session-pool MT races (locked remote-table store, conn_for_table…
Sep 23, 2026
3a9eeaf
Create release-notes-test-p1-mtfix-1.md
bedipritpal Sep 23, 2026
7666126
fix: store DBF logical byte T/F on remote writes (contributor patch) …
Sep 23, 2026
fd63f6a
Create release-notes-1.09.68-mtfix2.md
bedipritpal Sep 24, 2026
0c7ebfc
perf: 1.5s still-empty window for Seek/GO on server-certified empty t…
Sep 24, 2026
bfa796b
Create release-notes-1.09.68-mtfix3.md
bedipritpal Sep 24, 2026
8054cfb
fix: remote Reindex rebuilds bags bound on the server ABI twin + remo…
Sep 24, 2026
18eff36
Create release-notes-1.09.68-mtfix4.md
bedipritpal Sep 24, 2026
96b0e0f
fix(mt): release s.mu across the remote OpenTable round-trip (in-proc…
Sep 24, 2026
3249b56
Create release-notes-1.09.68-mtfix5.md
bedipritpal Sep 24, 2026
3786552
test: remote REINDEX, Vouch shape (multi-tag .Z01 bag, no order, shar…
Sep 24, 2026
2379a0e
perf: single-attempt lock default + alias/path lane pinning (mtfix6)
Sep 25, 2026
bcf21f5
Create release-notes-1.09.68-mtfix6.md
bedipritpal Sep 25, 2026
ade150c
diag: named timed client wire trace for voucher save
Sep 25, 2026
b3bd4e7
Create release-notes-1.09.68-mtfix7-diag.md
bedipritpal Sep 25, 2026
cd0bba8
mtfix8: slim commit flush path, park previously-locked tables, cache …
Sep 25, 2026
9c6d1e8
Create release-notes-1.09.68-mtfix8.md
bedipritpal Sep 25, 2026
f4079be
mtfix9: keep nav stamp across CloseAll/OpenIndex park-unpark (skip re…
Sep 25, 2026
cdbe631
Create release-notes-1.09.68-mtfix9.md
bedipritpal Sep 25, 2026
327b68f
mtfix10: AdsGetNumLocks ledger fast path + open-table FileExists shor…
Sep 25, 2026
2c3f618
Create release-notes-1.09.68-mtfix10.md
bedipritpal Sep 25, 2026
44ff960
mtfix11: AdsIsRecordLocked probes other connections' locks at OS leve…
Sep 25, 2026
c39e3d8
mtfix11: enforce ADS_EXCLUSIVE opens across wire sessions - server re…
Sep 25, 2026
feb4e41
Create release-notes-1.09.68-mtfix11.md
bedipritpal Sep 25, 2026
717e1c0
release: add ubuntu:20.04 container leg (glibc 2.31 asset)
bedipritpal Sep 25, 2026
9e4c9a3
release: build glibc231 leg with g++-10 (focal clang-10 rejects P1825…
bedipritpal Sep 26, 2026
f40ceef
release: export Harbour SDK paths on linux cache hit (provision early…
bedipritpal Sep 26, 2026
2f8c059
mtfix12: nav fusion - boundary-pair certification, self-GotoRecord su…
bedipritpal Sep 26, 2026
e8645f6
mtfix12: nav fusion - boundary-pair serve + self-GotoRecord + GetReco…
bedipritpal Sep 26, 2026
513e699
mtfix12: boundary-pair unit tests + nav expectation updates for fusio…
bedipritpal Sep 26, 2026
3fe8f3a
mtfix12: register network_boundary_pair_test
bedipritpal Sep 26, 2026
8e41fa3
release notes v1.09.68-mtfix12
bedipritpal Sep 26, 2026
d907e30
glibc231 leg: fix lost version stamp (fetch tags + explicit OPENADS_V…
bedipritpal Sep 26, 2026
41049f3
version stamp: honor explicit OPENADS_VERSION_FORCE from the pipeline
bedipritpal Sep 26, 2026
381f043
Create release-notes-1.09.68-mtfix12.md
bedipritpal Sep 26, 2026
a120c7a
Delete 11-release-notes-1.09.68-mtfix12.md
bedipritpal Sep 26, 2026
c40f016
ci: make tag resolvable in glibc231 container (safe.directory + fetch…
bedipritpal Sep 26, 2026
a6cf639
mtfix12: nav fusion - boundary-pair certification, self-GotoRecord su…
Sep 26, 2026
92d4628
mtfix12: nav fusion (ABI layer) + OPENADS_VERSION_FORCE stamp support…
Sep 26, 2026
3c8eee4
Delete 2-CMakeLists.txt
bedipritpal Sep 26, 2026
9aaac65
Delete src/network/1-wire.h
bedipritpal Sep 26, 2026
5f3dc7d
Delete src/network/2-client.h
bedipritpal Sep 26, 2026
c9bd203
Delete src/network/3-client.cpp
bedipritpal Sep 26, 2026
bfa4525
Delete src/network/4-session.h
bedipritpal Sep 26, 2026
64b510f
Delete src/network/5-session.cpp
bedipritpal Sep 26, 2026
fb5f47f
Delete src/abi/6-ace_exports.cpp
bedipritpal Sep 26, 2026
88dc36c
Delete tests/unit/7-network_nav_batch_test.cpp
bedipritpal Sep 26, 2026
bc73eb5
Delete tests/unit/8-network_use_budget_test.cpp
bedipritpal Sep 26, 2026
614c595
Delete tests/unit/9-network_boundary_pair_test.cpp
bedipritpal Sep 26, 2026
0c40429
Delete tests/10-CMakeLists.txt
bedipritpal Sep 26, 2026
9586a41
Delete .github/workflows/1-release.yml
bedipritpal Sep 26, 2026
b0c3b0c
Add opt-in client CreateIndex ABI diagnostic probe
Sep 26, 2026
6e92812
Create release-notes-1.09.68-diag-createindex.md
bedipritpal Sep 26, 2026
8813986
Fix false index-bag existence from open DBF
Sep 26, 2026
90a3830
Create release-notes-1.09.68-mtfix13.md
bedipritpal Sep 26, 2026
3c915da
Diagnostic: disable boundary-pair navigation for mtfix14 A/B
Sep 26, 2026
ea3d995
Create release-notes-1.09.68-mtfix14.md
bedipritpal Sep 27, 2026
beab98a
mtfix15: restore boundary pairs without eager scoped key counting
Sep 27, 2026
9093184
Create release-notes-1.09.68-mtfix15.md
bedipritpal Sep 27, 2026
03181eb
mtfix16: opt-in create, open and append diagnostics
Sep 27, 2026
69e722a
mtfix16: make Windows memo-failure test deterministic
Sep 27, 2026
0324e10
docs: add mtfix16 diagnostic test-build notes
bedipritpal Sep 27, 2026
5eb8838
mtfix17: recheck remote directories after external changes
Sep 27, 2026
18a3f46
docs: add mtfix17 fresh-org test-build notes
bedipritpal Sep 27, 2026
3de8d12
mtfix18: always recheck file and directory existence
Sep 27, 2026
f34e9dd
docs: add mtfix18 fresh-org test-build notes
bedipritpal Sep 27, 2026
33bf8db
fix(oads): use shared connection for no-handle Harbour helpers (mtfix19)
Sep 28, 2026
6209037
fix(lock): make repeat RLOCK idempotent and DBRI_LOCKED owner-scoped …
Sep 29, 2026
807f069
docs(release): mtfix20 lock-contract test build notes (Pritpal Bedi)
bedipritpal Sep 29, 2026
510e362
Sync upstream main 54e237b1 into test branch; preserve mtfix20 and re…
github-actions[bot] Sep 30, 2026
adf8aa5
docs(release): mtfix21 upstream-sync test build notes (Pritpal Bedi)
bedipritpal Sep 30, 2026
08f37bd
fix(packaging): include public headers in test kits (Pritpal Bedi)
bedipritpal Sep 30, 2026
1bfe9ea
fix(abi): mtfix22 tag case and stock RDD natural focus
Oct 1, 2026
de3c80e
Create release-notes-1.09.70-mtfix22.md
bedipritpal Oct 1, 2026
c3d1f40
Update release-notes-1.09.70-mtfix22.md
bedipritpal Oct 1, 2026
fa0bf40
ci: stage mtfix drafts as prerelease and not latest
bedipritpal Oct 1, 2026
a5fa4f6
ci: stage test packages from source SHA before publishing tag
bedipritpal Oct 1, 2026
7e940f6
ci: verify final archive members and version before draft release
bedipritpal Oct 1, 2026
4ace98f
Update release-notes-1.09.70-mtfix22.md
bedipritpal Oct 1, 2026
37ceaf5
Merge upstream v1.09.71 into test branch; preserve fork lock/index fi…
bedipritpal Oct 1, 2026
cc5b792
ci(release): keep reviewed public mtfix archives immutable
bedipritpal Oct 1, 2026
0637e5a
docs(release): mtfix23 upstream sync test-build notes for Pritpal Bedi
bedipritpal Oct 1, 2026
63302b7
ci(release): skip glibc231 rebuild on mtfix tag publication
bedipritpal Oct 1, 2026
764150d
fix(cdx): make lock diagnostics opt-in through OPENADS_LOCK_DIAG
bedipritpal Oct 1, 2026
dec4f83
docs(release): document shipped ace.h and opt-in lock diagnostics
bedipritpal Oct 1, 2026
0401939
Refactor apply-patch workflow for clarity and functionality
FiveTechSoft Oct 1, 2026
10708d2
restore our ci.yml workflow (keep fork workflows out of the mtfix23 s…
FiveTechSoft Oct 1, 2026
890347c
restore our release.yml workflow (keep fork workflows out of the mtfi…
FiveTechSoft Oct 1, 2026
fb2ee6b
remove fork secret-scan workflow (not part of the mtfix23 sync)
FiveTechSoft Oct 1, 2026
dae69d7
Merge pull request #179 from FiveTechSoft/main
FiveTechSoft Oct 1, 2026
55029be
platform: process-scoped byte locks on macOS (OFD made the engine wai…
FiveTechSoft Oct 1, 2026
07027e4
ci: macos-diag also runs on push to mtfix23-sync (temporary)
FiveTechSoft Oct 1, 2026
edfd5f1
platform: log errno/getlk details on byte lock timeout (diagnostic)
FiveTechSoft Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .github/workflows/macos-diag.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,8 @@ name: macos-diag
# per-assertion output and, if they stall, dumps thread stacks.
on:
workflow_dispatch:
push:
branches: [mtfix23-sync]

jobs:
diag:
Expand Down
4 changes: 4 additions & 0 deletions .gitleaks.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
title = "OpenADS Gitleaks configuration"

[extend]
useDefault = true
4 changes: 4 additions & 0 deletions .gitleaksignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
src/session/connection.cpp:generic-api-key:525
src/session/connection.cpp:generic-api-key:1457
tests/unit/aes_test.cpp:generic-api-key:41
third_party/tinyaes/aes.c:generic-api-key:18
35 changes: 22 additions & 13 deletions CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,14 @@ project(OpenADS
# a .git tree falls back to ${PROJECT_VERSION} from project() above.
# The previous hard-coded "1.0.0-rc1" string drifted six releases
# behind reality and surprised users running rc12.
# A pipeline that knows the release tag passes it explicitly: the tag
# is the source of truth for a release build's stamp, not the local
# clone's git state (shallow/container checkouts may not resolve
# `git describe` - the glibc231 container leg shipped a plain
# "1.09.68" banner for exactly that reason).
if(OPENADS_VERSION_FORCE)
set(OPENADS_VERSION_STR "${OPENADS_VERSION_FORCE}")
else()
set(OPENADS_VERSION_STR "${PROJECT_VERSION}")
find_package(Git QUIET)
if(GIT_FOUND AND EXISTS "${CMAKE_SOURCE_DIR}/.git")
Expand All @@ -29,6 +37,7 @@ if(GIT_FOUND AND EXISTS "${CMAKE_SOURCE_DIR}/.git")
string(REGEX REPLACE "-dirty$" "" OPENADS_VERSION_STR "${OPENADS_VERSION_STR}")
endif()
endif()
endif()
message(STATUS "OpenADS version: ${OPENADS_VERSION_STR}")
# Deliver the version through a generated header instead of a global
# compile definition: a new commit used to change the command line of
Expand Down Expand Up @@ -219,9 +228,11 @@ if(OPENADS_WITH_TLS)
set(MBEDTLS_INSTALL OFF CACHE BOOL "" FORCE)
FetchContent_Declare(
mbedtls
GIT_REPOSITORY https://github.com/Mbed-TLS/mbedtls.git
GIT_TAG v3.6.2
GIT_SHALLOW TRUE
GIT_REPOSITORY https://github.com/Mbed-TLS/mbedtls.git
GIT_TAG v3.6.2
GIT_SHALLOW TRUE
GIT_SUBMODULES framework
GIT_SUBMODULES_RECURSE TRUE
)
FetchContent_MakeAvailable(mbedtls)
message(STATUS "OpenADS: TLS enabled via vendored mbedtls 3.6.2 (statically linked)")
Expand All @@ -246,15 +257,13 @@ if(OPENADS_WITH_HTTP)
set(JSON_Install OFF CACHE BOOL "" FORCE)
FetchContent_Declare(
cpp_httplib
GIT_REPOSITORY https://github.com/yhirose/cpp-httplib.git
GIT_TAG v0.18.5
GIT_SHALLOW TRUE
URL https://github.com/yhirose/cpp-httplib/archive/refs/tags/v0.18.5.tar.gz
URL_HASH SHA256=731190e97acd63edce57cc3dacd496f57e7743bfc7933da7137cb3e93ec6c9a0
)
FetchContent_Declare(
nlohmann_json
GIT_REPOSITORY https://github.com/nlohmann/json.git
GIT_TAG v3.11.3
GIT_SHALLOW TRUE
URL https://github.com/nlohmann/json/archive/refs/tags/v3.11.3.tar.gz
URL_HASH SHA256=0d8ef5af7f9794e3263480193c491549b2ba6cc74bb018906202ada498a79406
)
set(JSON_BuildTests OFF CACHE INTERNAL "")
FetchContent_MakeAvailable(cpp_httplib nlohmann_json)
Expand All @@ -278,8 +287,8 @@ if(NOT EXISTS "${_openads_zlib_dir}/zlib.h")
include(FetchContent)
FetchContent_Declare(
zlib_src
URL https://github.com/madler/zlib/releases/download/v1.3.1/zlib-1.3.1.tar.gz
DOWNLOAD_EXTRACT_TIMESTAMP TRUE
URL https://github.com/madler/zlib/releases/download/v1.3.1/zlib-1.3.1.tar.gz
URL_HASH SHA256=9a93b2b7dfdac77ceba5a558a580e74667dd6fede4585b91eefb60f03b72df23
)
set(BUILD_SHARED_LIBS OFF CACHE BOOL "" FORCE)
set(SKIP_INSTALL_ALL ON CACHE BOOL "" FORCE)
Expand Down Expand Up @@ -334,8 +343,8 @@ if(OPENADS_WITH_SQLITE)
include(FetchContent)
FetchContent_Declare(
sqlite_amalgamation
URL https://www.sqlite.org/2024/sqlite-amalgamation-3460100.zip
DOWNLOAD_EXTRACT_TIMESTAMP TRUE
URL https://www.sqlite.org/2024/sqlite-amalgamation-3460100.zip
URL_HASH SHA256=77823cb110929c2bcb0f5d48e4833b5c59a8a6e40cdea3936b99e199dbbe5784
)
FetchContent_MakeAvailable(sqlite_amalgamation)
set(_openads_sqlite_src "${sqlite_amalgamation_SOURCE_DIR}/sqlite3.c")
Expand Down
21 changes: 11 additions & 10 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -103,13 +103,13 @@ generated baseline; OpenADS clears every line of the regenerated
ADS-flavoured baseline. The session that closed the last gap is
recorded across 28 incremental commits ending at `28be1be`.

**Current release: [v1.8.4](https://github.com/FiveTechSoft/OpenADS/releases/tag/v1.8.4) (2026-07-09).**
Harbour `rddads` + FiveWin `TDataBase` / `xBrowse` over `tcp://` is
production-ready: remote scope (`OrdScope`), index navigation, key counts,
date fields, and field I/O by ordinal all work end-to-end. Full Data
Dictionary enforcement, Studio web console, SAP DD import, SQL backends
(PostgreSQL / MariaDB / MSSQL / ODBC / SQLite), and CDX bulk-load index
build are in production. `openads_serverd` serves the OpenADS wire
**Current release: [v1.09.68](https://github.com/FiveTechSoft/OpenADS/releases/tag/v1.09.68) (2026-09-20).**
OpenADS has broad compatibility coverage, but support varies by API and
backend. Before production deployment, review [`TODO.parity.md`](TODO.parity.md)
and [`docs/known-issues.md`](docs/known-issues.md), test the exact workload,
and apply normal database security and backup controls. In particular,
documented Data Dictionary and access-control parity gaps make untrusted or
multi-user deployments experimental until those gaps are closed. `openads_serverd` serves the OpenADS wire
protocol; clients connect with
`AdsConnect60("tcp://host:port/path.add", ...)` and no application code
changes. Docs:
Expand All @@ -120,9 +120,10 @@ including [migrating from ADS](https://fivetechsoft.github.io/OpenADS/en/migrati
(CDX rollback / error 7017 caveat). `docs/wire-protocol.md` is the
formal spec for non-C++ clients (Python, Go, Rust, Harbour AEP).

Cross-platform CI is **green on all three runners**
(`ubuntu-24.04 / ninja-clang`, `macos-14 / default`,
`windows-2022 / msvc-x64`).
Cross-platform CI runs on Ubuntu, macOS, and Windows. Check the current
[Actions results](https://github.com/FiveTechSoft/OpenADS/actions/workflows/ci.yml)
before relying on a branch or release; this document does not claim that the
latest run is green.

Release timeline:

Expand Down
21 changes: 21 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# Security Policy

## Supported versions

Security fixes are applied to the latest published release and the default branch. Older releases may not receive fixes.

## Reporting a vulnerability

Do not open a public issue for a vulnerability or suspected credential exposure. Use GitHub's private vulnerability reporting for this repository:

1. Open the repository's **Security** tab.
2. Select **Advisories** and **Report a vulnerability**.
3. Include affected versions, reproduction steps, impact, and any suggested mitigation.

If private vulnerability reporting is unavailable, contact a repository maintainer privately and ask for a secure reporting channel. Do not include secrets or exploit details in ordinary email, discussions, issues, pull requests, or chat.

You should receive an acknowledgement within 7 days. A maintainer will coordinate validation, remediation, disclosure, and any CVE request. Please allow time for a fix before public disclosure.

## Credential exposure

Treat a committed credential as compromised even after the file is deleted. Rotate or revoke it first, then remove it from the current tree and purge it from Git history. Avoid copying the credential into issues, pull requests, commit messages, or logs.
Loading
Loading