Skip to content

Commit b9d9a0b

Browse files
committed
docs: record green 7.14.2 hermeticity handoff
1 parent 407fff2 commit b9d9a0b

1 file changed

Lines changed: 31 additions & 3 deletions

File tree

‎docs/handoff-python-test-hermeticity.md‎

Lines changed: 31 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,26 @@ exactly on b93f95c5698328a391487ecb97a3d3f6ea74159a. Its fixture-manifest
2222
SHA-256 is ae9f78b4cf934d501edcddc38ca671c0e095f9c7761845dade49fa07ac92837b.
2323
Use this branch, rather than merging alpha/develop, for the isolated 7.14.2 PR.
2424

25+
The reviewed fork head is
26+
407fff2be0771f4f1fca9aa7dcfdd6096fefe5e8. It is a two-commit linear port:
27+
28+
1. 8b479c58adf484194595a4e1f687d595c4b547aa — hermetic fixture and test
29+
implementation, whose parent is the exact release head b93f95c.
30+
2. 407fff2be0771f4f1fca9aa7dcfdd6096fefe5e8 — CI egress denial corrected to
31+
permit only the exact local emulator container while rejecting every other
32+
new non-loopback connection.
33+
34+
Fork CI run 32951356211 is green at that exact head:
35+
https://github.com/BitHighlander/python-keepkey/actions/runs/32951356211
36+
37+
- Fixture verification and Python syntax checks passed.
38+
- Emulator integration collected 456 tests: 322 passed, 134 skipped, and zero
39+
failed. Existing firmware/version skips remain itemized in JUnit; none is an
40+
explorer, RPC, network, or missing-fixture skip.
41+
- Both network-denial controls passed, the JUnit artifact was uploaded, and the
42+
fail-closed result step passed.
43+
- The CI log independently printed the expected fixture-manifest SHA-256 above.
44+
2545
The implementation is intentionally isolated from the 7.14.2 Solana/TON
2646
disclosure and PDF-report branches. Reconcile those branches only after this
2747
one is reviewed, then repin firmware to the durable Python merge commit.
@@ -78,9 +98,11 @@ the manifest from the 26 transaction fixtures that release tests actually use.
7898

7999
## Required upstream migration
80100

81-
1. Port the fork commits without weakening the fail-closed behavior.
82-
For 7.14.2, start from b93f95c and use fix/7142-hermetic-tests; do not merge
83-
the alpha/develop report catalog into the active PDF remediation branch.
101+
1. Create the upstream work branch from exact b93f95c. Cherry-pick 8b479c58 and
102+
407fff2b in that order, or reproduce their changes exactly after review. Do
103+
not merge the alpha/develop report catalog into the active PDF remediation
104+
branch, and do not weaken the fail-closed behavior while resolving later
105+
branch conflicts.
84106
2. Preserve public live TxApi clients for non-test callers, but ensure
85107
authoritative tests enable offline-only mode before constructing clients.
86108
3. Run python tests/tx_fixture_manifest.py --check as an early CI gate.
@@ -95,6 +117,12 @@ the manifest from the 26 transaction fixtures that release tests actually use.
95117
cannot satisfy or influence a required release check. Store them outside
96118
tests/ and obtain endpoints and credentials from the workflow environment;
97119
never commit either value.
120+
8. After upstream review, rebase onto the then-current Python #219 head, rerun
121+
the complete offline Python gate, merge #219, and record its durable master
122+
merge commit. Repin firmware #458 to that durable commit, rerun the complete
123+
firmware PR-event gate, and regenerate release evidence with the exact
124+
Python SHA and fixture-manifest digest. Do not sign or tag before those
125+
exact-head gates and approvals are green.
98126

99127
## Acceptance criteria
100128

0 commit comments

Comments
 (0)