September release candidate (DO NOT MERGE) - #1112
Draft
ChristianPavilonis wants to merge 714 commits into
Draft
ChristianPavilonis wants to merge 714 commits into
ChristianPavilonis wants to merge 714 commits into
Conversation
…spec/auction-timeline-offsets
# Conflicts: # crates/trusted-server-cli/src/commands/audit/mod.rs # crates/trusted-server-cli/src/commands/config/init.rs # crates/trusted-server-core/src/config.rs # crates/trusted-server-core/src/integrations/js_asset_proxy.rs # crates/trusted-server-core/src/integrations/mod.rs # crates/trusted-server-core/src/platform/test_support.rs # docs/guide/getting-started.md # docs/superpowers/specs/2026-04-01-js-asset-proxy-design.md # docs/superpowers/specs/2026-06-22-ts-audit-js-asset-proxy-config-design.md # trusted-server.example.toml
Preserve JavaScript asset proxy candidate generation in the relocated audit generator while retaining ad-template slot discovery.
Chrome opens several sockets per navigation: the document request, socket pool preconnects that close without sending anything, and speculative /favicon.ico, /robots.txt and /sitemap.xml fetches. The GPT fixture served exactly one accepted connection and panicked on a connection that carried no request, so whenever a preconnect won the accept race the listener was gone before the navigation landed and the collector failed with net::ERR_CONNECTION_REFUSED. Replace the one-shot fixture with a server that accepts until the returned guard is dropped, answers each connection on its own thread so a silent socket cannot stall the document request, and treats a request-less socket as normal. Cover both failure modes with tests that need no browser.
The set-tester endpoint minted the ts-tester cookie without Max-Age or Expires, making it a session cookie. Safari deletes session cookies when the browser quits, so Safari testers silently fell back to the baseline arm on every restart. Add a 30-day Max-Age; /_ts/clear-tester already expires the cookie explicitly and is unchanged.
Return empty 404 responses for speculative fixture requests and wake the blocking acceptor on shutdown. Pin routing with real speculative paths. Share the generation settle budget across initial, post-scroll, and GPT waits while retaining a snapshot after exhaustion. Document the shared budget and the two-empty-poll shortcut, with Chrome regression coverage.
Conflicts: publisher.rs (origin span now wraps the early-dispatch pending-origin wait as well as the direct send, still dropping before the abandonment-telemetry branch), main.rs (EdgeZero env parameter threaded through the AppBuild span block and the finalize signature gaining both mut ec_state and timings), app.rs (both sides' test-module additions kept). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…rface
Review round 3, the blocking route finding plus the config items:
- Publisher route templates now come from an operator allowlist
(observability.route_sections, default empty): a first segment that
matches an entry and has further depth emits the lowercased allowlist
entry as /{section}/*; everything else emits /other/*. The shape
heuristics (charset, length, digit bounds) are gone because they
could not bound identity: depth-2 first segments are usernames under
/{username}/posts shapes and single-segment paths are documents. The
emitted value set is now fixed by configuration, so no
request-derived byte reaches the row.
- Integration-proxy responses carry the registered route pattern
verbatim (bounded, integration-defined) instead of a classifier
output; the registry stores the pattern at registration.
- auction_enabled serializes only when false, so a pushed config
cannot silently re-enable auction telemetry on rollback; with a
serialization test alongside the observability one.
- The secret-store validator is renamed to validate_secret_store_key_name
with a key_name parameter: it validates an identifier, never a
credential, and the old name tainted the key name as a secret value
in CodeQL, lighting up eleven pre-existing log sites.
- Docs: the tinybird table gains its three missing rows,
max_body_bytes states the 1024 floor the code enforces, the rollback
guidance now describes the real compatibility boundary (push a
compat config first: drop [observability], access_enabled = false,
and enabled = false for access-only deployments), and the fixture
uses the example-domain convention.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- The access sink streams the Tinybird response (the body is never consumed; buffered conversion materializes chunked bodies before the limit check) and newline-terminates rows to match the auction sink's NDJSON framing, with the recording client now asserting both. - Poisoned RequestTimings locks recover via into_inner instead of silently dropping every subsequent sample: the guarded data are plain counters, so one panic cannot blank the header and row for the rest of the request. Module and spec docs updated to stop conflating poisoning with contention. - The geo write-back skips 401 responses through a shared helper: resolve_geo_for_response short-circuits on 401 before consulting the carried state, so the old unconditional write downgraded a carried Resolved to Attempted and cost the row its country. - TimedKvStore forwards exists, so decorating a store with a cheap metadata probe (Spin) no longer downgrades it to the get-and-discard default body; with a contradiction-stub delegation test. - Post-send ordering is owned by run_post_send_steps, which both production sites route through, and the instrumented sequence test drives the real seam: elapsed stamped by send, then pull-sync, then telemetry. - Axum: dev_server_service remains the standard path; new tests pin flag-off suppression and the extension round trip (a phase recorded in the handler must surface as ts-filter in the header); the outer-wrapper rationale is reworded to the terminal-freeze-point argument; the configuration guide notes the flag is read once at startup. - The no-Cache-Control fail-closed case is pinned by a test, and t0's boundary (constructed after the adapter prologue) is documented. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
# Conflicts: # crates/trusted-server-adapter-axum/Cargo.toml # crates/trusted-server-adapter-axum/src/app.rs # docs/.vitepress/config.mts # docs/guide/api-reference.md # docs/guide/configuration.md
# Conflicts: # crates/trusted-server-js/lib/test/prebid-artifact-integration.test.mjs
# Conflicts: # crates/trusted-server-core/src/publisher.rs # crates/trusted-server-js/lib/src/integrations/gpt_diagnostics/overlay.ts # crates/trusted-server-js/lib/test/integrations/gpt_diagnostics/overlay.test.ts # docs/guide/integrations/gpt-diagnostics.md
# Conflicts: # crates/trusted-server-integration-tests/fixtures/configs/viceroy-template.toml # docs/guide/fastly.md
# Conflicts: # crates/trusted-server-adapter-fastly/src/platform.rs # crates/trusted-server-core/src/publisher.rs
This reverts commit fb2d6d8.
EdgeZero PR 381's store-selector work made a runtime EDGEZERO__STORES__CONFIG__<ID>__KEY override move the CLI's config push destination on its own, with no --key flag. Under v0.0.8 it did not, which is what this test asserted when PR #879 was written. Record the pinned runtime's behavior so the release candidate is green, and flag the change for upstream review rather than leaving the suite red.
# Conflicts: # crates/trusted-server-adapter-cloudflare/src/app.rs # crates/trusted-server-adapter-fastly/src/app.rs # crates/trusted-server-adapter-fastly/src/main.rs # crates/trusted-server-adapter-fastly/src/platform.rs # crates/trusted-server-cli/tests/config_store_defaults.rs # crates/trusted-server-core/build.rs # crates/trusted-server-core/src/ec/prebid_eids.rs # crates/trusted-server-core/src/publisher.rs # crates/trusted-server-integration-tests/fixtures/configs/viceroy-template.toml # docs/guide/configuration.md
dhruv8sh
added this pull request to stack #1218
September 29, 2026 11:40
dhruv8sh
removed this pull request from stack #1218
September 29, 2026 11:51
Signed-off-by: dhruv8sh <dhruv8sh@proton.me>
Signed-off-by: dhruv8sh <dhruv8sh@proton.me>
Signed-off-by: dhruv8sh <dhruv8sh@proton.me>
Signed-off-by: dhruv8sh <dhruv8sh@proton.me>
Signed-off-by: dhruv8sh <dhruv8sh@proton.me>
Signed-off-by: dhruv8sh <dhruv8sh@proton.me>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
September release candidate.
This PR is an integration branch for release-candidate validation. Do not merge it into
main.RC head
6c87bfb8f.mainis fully contained (0 commits behind).Merged PRs (milestone 202609)
Eighteen milestone PRs are already merged into
mainand inherited here. All are verifiedpresent in this branch.
Contents
Milestone
202609has 17 open PRs. Sixteen are integrated here; #1179 is not.That accounts for all 35 PRs carrying the
202609milestone: the 18 merged throughmainlisted above, 16 integrated here from open branches, and #1179 excluded.Exclusions and caveats
#1179 pins a diverged EdgeZero revision. Its
c4841b60is 7 commits ahead of the RC's12c3215cbut 62 behind. Those 62 contain the whole Fastly store-selector series that#1175 depends on, including
fix(fastly): apply canonical store selectors at deployandfeat(fastly): load runtime config by service version. Merging it would roll thedependency back and revert #1175 at the dependency level. It needs rebasing onto the
current pin.
#879 is included, with one of its tests changed. Its
config_push_does_not_use_the_runtime_key_override_without_the_key_flagasserted that aruntime
EDGEZERO__STORES__CONFIG__<ID>__KEYoverride must not move wherets config pushwrites, and that only an explicit
--keyflag should. That holds under EdgeZerov0.0.8,which #879 was written against, and the test passes on its own branch. It does not hold
under
12c3215c, the pin this RC carries: with the env var set and no--keyflag, thepush writes to
active_configinstead of the default blob key. Verified by instrumentingthe assertion to print the keys actually written.
config pushis entirelyedgezero_cli, so this behavior cannot be changed from thisrepository. The test was renamed to
config_push_follows_the_runtime_key_override_without_the_key_flagand now asserts whatthe pinned runtime does, with a comment recording that this is a behavior change from
v0.0.8rather than the intended contract. This is worth upstream review on EdgeZeroPR 381 before the pin moves to a release tag: an operator exporting that variable for
runtime reasons now also redirects their config pushes.
Conflict resolution
Conflicts were resolved as three-way merges. Each conflicted file was audited by commit
subject to establish which side carried work the other had never seen, because several
RC-side features postdate the branches. Resolutions worth reviewing:
gpt/index.tskept both sides. The RC'sdelete ts.firstImpression(first-impressionarbitration, Prevent competing GPT first impressions and resize PUC shells #1079 / Harden PR 1079 first-impression arbitration #1083 / Resolve the GPT bootstrap test fixture without assuming a platform #1162) and the branch's
ts.auctionDiagnostics = undefinedare independent cleanups on the same reset path. Taking the branch alone reverted Prevent competing GPT first impressions and resize PUC shells #1079
and broke 24 tests.
publisher.rskept the RC'sdispatch_auction/collect_dispatched_auctionsplitand
legacy_provider_map(Add configuration-driven OpenRTB auction providers #1016), layering the branch's no-argumentmark_auction_dispatched,auction_wait_placement_wirehelper and two-phaseBrowserAuctionDiagnosticsconstruction on top.prebid/index.tskept the RC's first-impression token reconciliation and took thebranch's removal of the
hb_curcurrency field, which a later review commit on thatbranch had deliberately dropped.
app.rsrestoredis_publisher_navigation = ec.is_real_browser && is_navigationfrom the merge base. The RC side had dropped the
is_real_browserterm, wideningset_recovery_eligibleto non-browser navigations.docs/.vitepress/config.mtstook main's flat alphabetical integration nav from theAdd full-surface documentation refresh spec #1049 refresh, then re-added
gam,gpt-diagnostics-dictionaryandkargo, three pagesthat exist on disk but were absent from main's list and would otherwise be unreachable.
feature set. The guard exists to catch a Prebid value-import multiplying the bundle, and
its Prebid-free assertions still pass.
Semantic conflicts that auto-merged without markers
Four breakages merged cleanly at the text level and were caught only by compiling and
running the suites:
AuctionCollectDepsgainedtimingsandplacementon the RC side while main's newparser-seam streaming tests constructed it without them (E0063). Both sites now pass
RequestTimings::new()andAuctionWaitPlacement::InStream.platform/timed_kv.rsoverrode onlycount_keys_with_prefixafter theEcKvStoretrait made
list_keys_with_prefixrequired and the former a provided default (E0046).settings.rskept both sides' copies of the same two consent-store tests (E0428).NamedRoutefor/_ts/admin/cache/purgewithout theroute_classfieldthe RC's access telemetry requires. It is
RouteClass::Other, since unlike the siblingadmin routes it does not operate on Edge Cookie state.
A fix was also pushed to #1157's own branch (
bd0b83a98): its rebase ontomainleft theEidConflictEcKvtest double missinglist_keys_with_prefix, failingtrusted-server-coreunder
cfg(test)and takingcargo fmtdown as a cascade.Verification
Run locally against the merged branch before each push:
cargo fmt --all -- --checkcargo test-fastlycargo test-axum/test-cloudflare/test-spinnpx vitest run