feat(distribution): unified in-tree registry and Forgejo distribution for binaries and plugin packages #269
Labels
No labels
code-review
correctness
dos
performance
security
severity/high
severity/low
severity/medium
tech-debt
Kind/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
h-dv/code-index#269
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Unified In-Tree Registry and Forgejo Distribution for Binaries and Plugin Packages
1. Problem Statement & Motivation
Today,
code-indexhas two decoupled distribution channels that share the same release runner and Forgejo forge (git.h-dv.de/h-dv/code-index):code-index-${TAG}-${slug}.tar.gz) and managed byinstall.shusing GitHub/Forgejo release API lookups..cipcontainers and.cipsdetached signature sidecars, configured manually viacode-index plugin add <url> --sha256 <hex>or copied to.code-index/plugins/.The Friction for Operators and AI Agents
When an operator or AI agent opens a project containing unindexed source files (e.g.
.svelte,.xaml):project_overviewcorrectly measures and reportssymbol_blind_extensions: [".svelte"].Store::installed),activation_availablehas no offer because the store is local-only..svelte?[update."<package_id>"]in.code-index.tomlcurrently requires manually pasting raw release URLs that may rot across tag rotations.By bringing a unified distribution catalog directly in-tree and leveraging Forgejo's built-in Releases and Generic Package Registry,
code-indexcan publish, discover, install, and update both core binaries and plugin packages in one cohesive, cryptographically verified mechanism.2. Technical Architecture
2.1 In-Tree Registry Catalog Schema (
distribution/registry.v1.json)A versioned, machine-readable catalog generated and signed during the CI release workflow and published to Forgejo:
3. Forgejo CI/CD Release Pipeline Integration (
.forgejo/workflows/release.yml)The existing
release.ymlworkflow already builds all target binary archives and packages/signs in-tree plugins. The workflow will be extended in the finalreleasejob:shipped/code-index-${TAG}-*.tar.gz.sha256).*.cip.digest.txt).distribution-manifest.jsonfor the specific release tag and update the cumulativeregistry.json.registry.jsonusingCODE_INDEX_PUBLISHER_KEYto produceregistry.json.sig(Ed25519 detached signature).registry.jsonandregistry.json.sigto the Forgejo Release assets.https://git.h-dv.de/api/packages/h-dv/generic/code-index-distribution/latest/registry.jsondistribution/registry.jsonback tomaster(or publish via Forgejo Pages).4. Tooling & Client Integration
4.1 Enhanced
install.shregistry.jsondirectly from the release or Forgejo generic package endpoint.registry.json.sigagainst the compiled-in first-party public key.4.2 CLI
code-index pluginEnhancementscode-index plugin add de.h-dv.xamlqueries the registry catalog, automatically resolves the URL, sha256, and detached signature, and proceeds through standard verification and operator elicitation.In
.code-index.toml:plugin updateautomatically resolves the newest release from the registry, enforcing all 7 safety gates (strict semver ordering #255, subset grants, unchanged extraction identity).4.3 Agent & MCP Server Integration
cosi://registry/pluginsto allow AI agents to browse available plugins.project_overviewdetectssymbol_blind_extensions: [".xaml"], it checks the cached registry and includes:plugin_addto acceptpackage: "<id>", fetching the.cipand.cipsfrom the registry and prompting the human operator via MCP elicitation.5. Security & Threat Model Compliance
_prdoc/guides/80-threat-model.md, HTTP carries no trust.C_{\text{new}} \subseteq C_{\text{in\_force}}).install.sh --base-url <url|path>andcode-index --registry-url <url|path>allow air-gapped environments or local disk mirrors to function identically without external network access.6. Required Quality Gates & Tests
Per IXT V2 and
code-indexstandards:installer_targets.rsextension: Grade that all published binary targets in.forgejo/workflows/release.ymlappear inregistry.json.registry_schema_gate.rs: Validatedistribution/registry.v1.jsonagainst its JSON schema.plugin_registry_e2e.rs: End-to-end integration test over loopback mock HTTP server testing registry resolution, signature checking, tampered catalog rejection, and unattended update.readofpkg.digestbinds a same-named pub field in another crate, and localising the receiver does not move it #270File::create+write!+ chmod), andplugin-host/tests/kill_cost.rsis a live member #271