Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
15 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 16 additions & 1 deletion .ai-context/overview.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,11 @@
# base-demo Overview

Disposable trust scenarios live in `tests/scenarios/trust.py` and
`docs/trust-scenarios.md`. The stable v1.9 lane does not claim full historical
revocation or static runtime inspection; those assertions use a separately
pinned v1.10 candidate. Fixture homes and IDE delegate spies prevent learner
state mutation. Scenario success does not certify host readiness.

The release BOM gate reuses Base's governed contract and requires both platform
jobs plus source-provider evidence at the exact release commit. Static pins and
historical release:// records are not passing compatibility proof; see
Expand All @@ -19,7 +25,7 @@ binds both to the annotated tag target, checks their SHA-256 manifests, and
publishes those exact verified assets after the read-only validation job passes.

It includes the Base project shape plus a reduced-scale representative
environment: a `base_manifest.yaml` that declares every current Base contract,
environment: a `base_manifest.yaml` that declares a curated representative subset of Base contracts,
runnable commands, a Python CLI that uses `base_cli.App`, an interactive demo
script, validation tests, multiple language services, common build tools, one
Dockerized service, one React/Vite UI, local databases and cache through
Expand Down Expand Up @@ -119,6 +125,15 @@ change stream, and its three existing validation job IDs remain stable.

## Quick Loop

`tests/scenarios/workspace.py` is the isolated multi-peer consumer fixture.
Stable 1.9 covers reports; exact-candidate 1.10 covers selection, aggregate
failure/skip, aliases, undeclared inventory and checkout-bound next actions.
Start at `docs/first-success.md`: evaluator, adopting-project maintainer and
demo contributor have separate prerequisites, completion criteria and handoff
artifacts. The full README command map is a reference, not an unattended setup
script. Current source uses `.release/supported-dependencies.json`; the interim
public bootstrap still consumes historical Base 1.8/demo 0.1 releases.

```bash
basectl setup base-demo
basectl activate base-demo
Expand Down
82 changes: 82 additions & 0 deletions .github/workflows/scenarios.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,82 @@
name: Isolated Base scenarios

on:
pull_request:
push:
branches: [main]
workflow_dispatch:

permissions:
contents: read

concurrency:
group: scenarios-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
trust:
name: Trust and workspace scenarios (${{ matrix.lane }})
runs-on: macos-14
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
include:
- lane: stable-v1.9
base: ac8d294421e1bfc14afa8c6a2a12f1affb5268ee
options: ""
- lane: advisory-v1.10-candidate
base: 5f316aeddc3680b92bd209fcfe652eac020d02d0
options: --candidate
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5
with:
repository: basefoundry/base
ref: ${{ matrix.base }}
path: .dependencies/base
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5
with:
repository: basefoundry/base-cli
ref: 8a93d22156ba75a99965f7c355f867acba630069
path: .dependencies/base-cli
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5
with:
repository: basefoundry/base-bash-libs
ref: 36fec50c446dcea8c521a1ba3e7fee2394f169c0
path: .dependencies/base-bash-libs
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065
with:
python-version: '3.13'
- name: Install fixture interpreter dependencies
# Match both exact Base revisions' lib/base/default_manifest.yaml.
run: python -m pip install ./.dependencies/base-cli click==8.4.1 PyYAML==6.0.3 tomli==2.4.1
- name: Install supported Bash for Base
run: brew install bash
- name: Verify isolated trust and consent contracts
env:
BASE_SCENARIO_COMMIT: ${{ matrix.base }}
BASE_SCENARIO_OPTIONS: ${{ matrix.options }}
run: |
python tests/scenarios/trust.py \
--base .dependencies/base --base-commit "$BASE_SCENARIO_COMMIT" \
--base-cli .dependencies/base-cli --bash-libs .dependencies/base-bash-libs \
--python "$(command -v python)" $BASE_SCENARIO_OPTIONS
- name: Verify isolated workspace contracts
env:
BASE_SCENARIO_COMMIT: ${{ matrix.base }}
BASE_SCENARIO_OPTIONS: ${{ matrix.options }}
run: |
python tests/scenarios/workspace.py \
--base .dependencies/base --base-commit "$BASE_SCENARIO_COMMIT" \
--base-cli .dependencies/base-cli --bash-libs .dependencies/base-bash-libs \
--python "$(command -v python)" $BASE_SCENARIO_OPTIONS
- name: Rehearse evaluator first success
env:
BASE_SCENARIO_COMMIT: ${{ matrix.base }}
BASE_SCENARIO_OPTIONS: ${{ matrix.options }}
run: |
python tests/scenarios/journeys.py \
--base .dependencies/base --base-commit "$BASE_SCENARIO_COMMIT" \
--base-cli .dependencies/base-cli --bash-libs .dependencies/base-bash-libs \
--python "$(command -v python)" $BASE_SCENARIO_OPTIONS
6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,12 @@ promotes this section into a dated version heading before tagging.
- Aligned current source with the supported Base 1.9.0, base-cli 0.4.3 and
base-bash-libs 2.1.0 input contract, with exact macOS/Ubuntu CI revisions and
live final-candidate evidence binding outside the tracked tree.
- Added disposable workspace selection, failure/skip, fail-fast and targeted
recovery scenarios, with separate stable and exact-candidate boundaries.

- Added isolated stable/candidate trust scenarios for denial, invalidation,
revocation, runtime verification and independent IDE consent, with explicit
Base v1.9 historical-revocation limitations.

- Made release BOM publication fail closed on incomplete participants, stale
pins, inconsistent platforms, and missing exact-commit hosted evidence.
Expand Down
25 changes: 25 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,18 @@

Reference Base-managed project and representative demo environment.

## Start with your goal

- **Evaluate Base:** [inspect, run one command, and export a handoff](docs/first-success.md#evaluate-base).
- **Adopt Base in your project:** [map one real validation command](docs/first-success.md#adopt-base-in-a-project).
- **Contribute to this demo:** [validate an issue-backed change](docs/first-success.md#contribute-to-base-demo).

Each path states prerequisites, a completion check, and one safe recovery.
This demo is a **curated representative subset**, not every Base contract.
Current-source paths use the [supported inputs](.release/supported-dependencies.json);
the historical-release Quick Start below installs older versions until v0.2.0
publication. Neither path implies native Windows or a full Linux demo.

This repository is the public reference project for Base-managed repositories.
It demonstrates Base on a compact but credible project shape: small enough to
inspect in one sitting, but substantial enough to represent the tools and
Expand All @@ -29,6 +41,13 @@ blocked Base capabilities is maintained in the [Base capability and evidence
matrix](docs/base-capability-matrix.md). Use it during Base release reviews and
when deciding whether a new base-demo scenario has executable evidence.

The [workspace scenarios](docs/workspace-scenarios.md) prove selected execution,
failure aggregation and checkout-bound recovery in disposable peers.
The [isolated trust and consent scenarios](docs/trust-scenarios.md) demonstrate
denial, approval, invalidation and revocation without changing your trust store
or IDE settings. They explicitly separate Base v1.9 behavior from the stronger
implemented v1.10 candidate contracts.

The external tooling direction is tracked in
[Tooling Test Bed](docs/tooling-testbed.md). That matrix separates active
baseline tools from optional wrappers, reference-only examples, and future Base
Expand Down Expand Up @@ -152,6 +171,12 @@ toolchain is unavailable, and requires live HTTP execution markers for all four
API services. That smoke lane uses loopback listeners and does not require
Docker Compose.

## Complete command reference

Use this inventory after a [first-success path](docs/first-success.md), not as
an unattended script. Review the manifest before the explicit trust command;
setup, approval and command execution can change local state.

```bash
basectl projects list
basectl setup base-demo # macOS only
Expand Down
4 changes: 2 additions & 2 deletions docs/base-capability-matrix.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,8 +23,8 @@ useful for development, but does not by itself establish released compatibility.
| Representative build, test, service, environment, and non-interactive demo loop | `1.9.0` | The manifest targets in [`base_manifest.yaml`](../base_manifest.yaml), baseline gate in [`tests/validate.sh`](../tests/validate.sh), and focused suites in [`tests/services_test.bats`](../tests/services_test.bats), [`tests/environments_test.bats`](../tests/environments_test.bats), and [`tests/demo_test.bats`](../tests/demo_test.bats) | Full project loop is macOS; Ubuntu/Debian validates Base setup and project health only | Demonstrated | base-demo | Add executable evidence before calling a new service or command demonstrated. |
| Linux and WSL2 read-only support boundary | `1.9.0` | The supported commands and explicit native-Windows boundary are in [`README.md`](../README.md) and [`docs/contracts.md`](contracts.md); CI's Ubuntu path is in [`.github/workflows/tests.yml`](../.github/workflows/tests.yml) | Ubuntu/Debian and WSL2 use setup, dev-profile, check, and doctor/read-only paths; native Windows is excluded | Demonstrated | Base + base-demo | Keep platform claims tied to a hosted or repository-local check. |
| Base `1.9.0` released-compatibility pin and full Go/live-HTTP evidence | `1.9.0` | Structured pins in [supported inputs](../.release/supported-dependencies.json), verified by `bin/base-demo-dependencies`; full-language and live-HTTP gates run in [`.github/workflows/tests.yml`](../.github/workflows/tests.yml) | Exact macOS 14 full demo and Ubuntu 24.04 setup/read-only scope; no Linux full-demo claim | Demonstrated | Base + base-demo | Bind final-candidate runs during #303; later dependency changes require fresh proof. |
| Workspace scenarios planned for the Base `1.10.0` train | `1.10.0` (planned) | The workspace manifest and current boundary are [`workspace.yaml.example`](../workspace.yaml.example) and [`README.md`](../README.md); the new scenario evidence is tracked by [base-demo#297](https://github.com/basefoundry/base-demo/issues/297) | Planned release work; no `1.10.0` claim is made by the current `main` branch | Blocked upstream | Base + base-demo | Implement #297 after the Base `1.10.0` workspace contract is fixed. |
| Trust and consent scenarios planned for the Base `1.10.0` train | `1.10.0` (planned) | Current trust documentation and CI ordering are in [`README.md`](../README.md), [`docs/contracts.md`](contracts.md), and [`.github/workflows/tests.yml`](../.github/workflows/tests.yml); the additional scenario is tracked by [base-demo#298](https://github.com/basefoundry/base-demo/issues/298) | Planned release work; current evidence remains the `1.9.0` boundary | Blocked upstream | Base + base-demo | Implement #298 after the Base trust/consent contract is stable. |
| Workspace inventory, selected tests and targeted recovery | `1.9.0` reports; exact `1.10.0` candidate | `tests/scenarios/workspace.py` and [workspace scenario guide](workspace-scenarios.md), run by isolated scenario CI | macOS fixture lane; selection and expanded recovery require the exact candidate | Demonstrated | Base + base-demo | Refresh candidate evidence before release; do not claim stable 1.10 support. |
| Trust lifecycle and separate runtime/IDE consent | `1.9.0` baseline; exact `1.10.0` candidate | `tests/scenarios/trust.py` and [trust scenario guide](trust-scenarios.md), executed by [isolated scenario CI](../.github/workflows/scenarios.yml) | macOS fixture lane; full historical revocation and runtime inspection require the pinned candidate | Demonstrated | Base + base-demo | Refresh exact candidate evidence before release; do not attribute candidate-only guarantees to v1.9.0. |
| Optional `test.requirements` and uninstall guidance | `1.9.0` | The manifest test entry and contributor setup guidance are [`base_manifest.yaml`](../base_manifest.yaml) and [`README.md`](../README.md) | Optional metadata is not required for the baseline demo contract | Intentionally omitted | base-demo | Revisit when Base publishes a stable user-facing contract and a concrete scenario. |
| Native Windows support | `1.11.0` (planned) | The current non-goal is recorded in [`README.md`](../README.md); the staged Base work is tracked by [base-demo#302](https://github.com/basefoundry/base-demo/issues/302) and Base [#2215](https://github.com/basefoundry/base/issues/2215) | Native Windows is not shipped; Git Bash and WSL2 do not count as native Windows evidence | Blocked upstream | Base + base-demo | Wait for the PowerShell-first Base contract and hosted Windows evidence. |
| First-class Base Docker-service contract | Future | The existing Compose fixture is documented in [`docs/tooling-testbed.md`](tooling-testbed.md) and [`infra/compose.yaml`](../infra/compose.yaml); adoption remains tracked by [base-demo#163](https://github.com/basefoundry/base-demo/issues/163) and Base [#124](https://github.com/basefoundry/base/issues/124) | Compose is a repository fixture; it does not establish a Base Docker-service contract | Blocked upstream | Base + base-demo | Do not make the future Base command a required demo dependency before Base publishes it. |
Expand Down
Loading
Loading