Conversation
added 3 commits
July 19, 2026 22:05
Makes provider errors actionable and adds the concurrency guard the spec's error
model and concurrency sections call for — both on the shared actuateSigned core.
- ociError(status, body): parses OCI's {code, message} response and maps the HTTP
status to a CIC-canonical class (400→validation, 401/403→permission, 404→
not-found, 409/412→conflict, 429→transport+retryable, 5xx→provider+retryable),
preserving the native provider_code for evidence. execute/observe/destroy/
invoke/poll now return the mapped error instead of a bare "HTTP N"; execution
steps carry error_class + provider_code.
- If-Match: execBinding.revision (the observed etag) is sent as an unsigned
If-Match header on mutations (execute/destroy/invoke), so a concurrent change
yields 412 → conflict, never a silent overwrite. GET ops (observe/poll) send
none. actuateSigned gained the ifMatch arg.
- destroy now also surfaces async Work Requests (accepted + work_request_id).
TestExecuteErrorAndIfMatch covers 409→conflict/IncorrectState and the If-Match
header. Full local CI green (golang.quality, wasm.build/integrity/test full suite,
check, verify-release, manifest, pytest).
---
[signing-metadata]
key = cic-my-sign-key
signature = vault:v1:MEQCIC6gmifyvg7N9N/CATFeTL2vDGis+DBr+MZw13zyb6rfAiAGKAPRa9fYy4XtckQJ6d8mpNg2kVewagedIJUd7wSsdQ==
hash-algorithm = sha256
digest = 4JiAp43EAMeycbJtvE+0SM+Fmt5WwVTCWLFFVXhgrUc=
[certificate]
-----BEGIN CERTIFICATE-----
MIICBjCCAaygAwIBAgIUSnRMR6RPnEbg296XWPOqq/u5PCwwCgYIKoZIzj0EAwIw
QzELMAkGA1UEBhMCSFUxGTAXBgNVBAoMEENlbnRyYWxJbmZyYUNvcmUxGTAXBgNV
BAMMEENJQyBEZXZlbG9wZXIgQ0EwHhcNMjYwMzIwMTMyMjU5WhcNMjYxMjMxMTMy
MjU5WjBFMQswCQYDVQQGEwJIVTEZMBcGA1UECgwQQ2VudHJhbEluZnJhQ29yZTEb
MBkGA1UEAwwSR2Fib3IgWm9sdGFuIFNpbmtvMFkwEwYHKoZIzj0CAQYIKoZIzj0D
AQcDQgAEIG2CVmTfmLB9pLLclj7YmP2eedAjklpy4LGrU2ijoiy6Xqpuybv7OgJe
i+ez31s65NEV8+X/ByeX1cstR988z6N8MHowCQYDVR0TBAIwADAdBgNVHQ4EFgQU
yZN6AIX/TNnIJ9GwAa/NRN3ujHAwHwYDVR0jBBgwFoAUXn6CHYzPUqU4JVP8g+OS
WeDYjhcwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEF
BQcDBDAKBggqhkjOPQQDAgNIADBFAiEA+bFzXRoJ4PCQbhAAtpkcMjt0vNj5rEW0
lOMBGDNyaWkCIB1vmM7PcZzv/c9bIrxF5kqv6QXomouhByUfeNUTbpKW
-----END CERTIFICATE-----
…ve/validate/plan Adds manual_real_oci_test.go, gated behind a manual_real_oci build tag plus a REAL_OCI_TEST=1 runtime opt-in, so it never runs in a plain `go test ./...` or `make golang.test`. It calls the module's own handler functions against a real OCI tenancy using the real API-key signing scheme, to cover what the existing mock-host tests (relay_integration_test.go, module_loadtest_test.go) cannot: whether the request/response logic actually works against live OCI. Documents current coverage and known gaps (poll needs a live work-request; execute/invoke/destroy are mutating and out of scope for this harness) in docs/design/manual-verification.md, including a capability-manifest/realm mismatch found via describe() (egress_hosts declares *.oraclecloud.com only; this tenancy's real host is the EU Sovereign realm's oraclecloud.eu). --- [signing-metadata] key = cic-my-sign-key signature = vault:v1:MEQCICjWxcWKF1io8wtKpL50iMCRJR84M/WJBKxaFcz+hDqyAiA/6eL2/sCZQsNUqwez/ceZctydinxdxe9KaYfMRi142Q== hash-algorithm = sha256 digest = Ivzn5N8QEdyxivv1s42gSjy8++NNm8ngVnb9uMCt1jk= [certificate] -----BEGIN CERTIFICATE----- MIICBjCCAaygAwIBAgIUSnRMR6RPnEbg296XWPOqq/u5PCwwCgYIKoZIzj0EAwIw QzELMAkGA1UEBhMCSFUxGTAXBgNVBAoMEENlbnRyYWxJbmZyYUNvcmUxGTAXBgNV BAMMEENJQyBEZXZlbG9wZXIgQ0EwHhcNMjYwMzIwMTMyMjU5WhcNMjYxMjMxMTMy MjU5WjBFMQswCQYDVQQGEwJIVTEZMBcGA1UECgwQQ2VudHJhbEluZnJhQ29yZTEb MBkGA1UEAwwSR2Fib3IgWm9sdGFuIFNpbmtvMFkwEwYHKoZIzj0CAQYIKoZIzj0D AQcDQgAEIG2CVmTfmLB9pLLclj7YmP2eedAjklpy4LGrU2ijoiy6Xqpuybv7OgJe i+ez31s65NEV8+X/ByeX1cstR988z6N8MHowCQYDVR0TBAIwADAdBgNVHQ4EFgQU yZN6AIX/TNnIJ9GwAa/NRN3ujHAwHwYDVR0jBBgwFoAUXn6CHYzPUqU4JVP8g+OS WeDYjhcwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEF BQcDBDAKBggqhkjOPQQDAgNIADBFAiEA+bFzXRoJ4PCQbhAAtpkcMjt0vNj5rEW0 lOMBGDNyaWkCIB1vmM7PcZzv/c9bIrxF5kqv6QXomouhByUfeNUTbpKW -----END CERTIFICATE-----
Missed in the previous commit — CI's manifest-verify step caught it. --- [signing-metadata] key = cic-my-sign-key signature = vault:v1:MEUCIDptg4k9W3It7Ku1btZ2X3y6JpchqL8aCwmMBN5/AQJSAiEAv5duRUitGffpL3L4mbKnuL81A/NiTH5wN0UGRh88yV8= hash-algorithm = sha256 digest = jSpHVe1UcYHMuqY13EF2P5FgLQJIWcSJ3rhXKyp02Hk= [certificate] -----BEGIN CERTIFICATE----- MIICBjCCAaygAwIBAgIUSnRMR6RPnEbg296XWPOqq/u5PCwwCgYIKoZIzj0EAwIw QzELMAkGA1UEBhMCSFUxGTAXBgNVBAoMEENlbnRyYWxJbmZyYUNvcmUxGTAXBgNV BAMMEENJQyBEZXZlbG9wZXIgQ0EwHhcNMjYwMzIwMTMyMjU5WhcNMjYxMjMxMTMy MjU5WjBFMQswCQYDVQQGEwJIVTEZMBcGA1UECgwQQ2VudHJhbEluZnJhQ29yZTEb MBkGA1UEAwwSR2Fib3IgWm9sdGFuIFNpbmtvMFkwEwYHKoZIzj0CAQYIKoZIzj0D AQcDQgAEIG2CVmTfmLB9pLLclj7YmP2eedAjklpy4LGrU2ijoiy6Xqpuybv7OgJe i+ez31s65NEV8+X/ByeX1cstR988z6N8MHowCQYDVR0TBAIwADAdBgNVHQ4EFgQU yZN6AIX/TNnIJ9GwAa/NRN3ujHAwHwYDVR0jBBgwFoAUXn6CHYzPUqU4JVP8g+OS WeDYjhcwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEF BQcDBDAKBggqhkjOPQQDAgNIADBFAiEA+bFzXRoJ4PCQbhAAtpkcMjt0vNj5rEW0 lOMBGDNyaWkCIB1vmM7PcZzv/c9bIrxF5kqv6QXomouhByUfeNUTbpKW -----END CERTIFICATE-----
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
module/manual_real_oci_test.go: calls the module's own handler functions (Describe/Observe/Validate/Plan) against a real OCI tenancy, using the real API-key signing scheme — covers what the existing mock-host tests (relay_integration_test.go,module_loadtest_test.go) cannot: whether the request/response logic actually works against live OCI.manual_real_ocibuild tag, and skips withoutREAL_OCI_TEST=1even when built with the tag.docs/design/manual-verification.md: coverage table (describe/observe/validate/plan verified; poll blocked on no live work-request found; execute/invoke/destroy out of scope, mutating), plus a concrete finding —describe()'srequired_capabilities.egress_hostsis*.oraclecloud.comonly, but this was verified against an EU Sovereign realm tenancy whose real host isoraclecloud.eu.golang.test.manual-real-ociMakefile target mirroring the existinggolang.testdocker pattern (not verified in this environment — no docker available here; flagged in the target's own output thatOCI_KEY_PATHneeds to be reachable inside the builder container, which the currentdocker-compose.ymldoesn't mount).MANIFEST.sha256.Test plan
go vet ./...(no tags) — file invisible, unaffectedgo test -tags manual_real_oci ./...withoutREAL_OCI_TEST— all gated tests SKIP cleanlygo test -tags manual_real_oci -run TestManualRealOCI -v ./...with real OCI credentials — Describe/Observe (Vcn + Subnet)/Validate/Plan (noop + update) all PASS against a live tenancydevel(lint_and_test, including the WASM build/host-load steps, unaffected by the new file)