Skip to program ledger

Living Program Ledger

Frauthy/Project Management

v37 · 2026-07-28

Repository dossier

sandbox

The standing e2e suite — Amalga · Quill · Lens · Rust worker

On track
Branch
master
Commit
4fb332561d52c002b2750d2902e8e17f5175981a
Worktree
Clean
SDK
@frauthy/sandbox-ui 1.0.0-next.0 source, published, and Brand-admitted

stack

TS · Go · Python · Rust

ci

green (exact-head Integration run 29448176119)

deploy

not applicable (integration suite)

coverage

live conformance evidence 9/9 and 100/100

What it is. The standing end-to-end integration suite disguised as a product: Amalga (TS social-feed aggregator) merging Quill (Go microblog: follower graph, user:*, block exclusion) and Lens (Python photos: nested groups, album inheritance) — all resolving through Frauthy on both backends, with a Rust merge worker enforcing independently through sdk/rust.

What’s proven. Live-verified: 9/9 conformance cells (each component identical on SpiceDB and Keto) and 100/100 integration assertions (per-persona unified feeds exact-match on all-SpiceDB, all-Keto, and mixed backends, plus 404-not-403 hiding and connection gating). A planted-regression test proves the harness catches breakage.

Where it falls short. Its CI is a silent no-op: even the offline job is gated on the human-gated FRAUTHY_CI_TOKEN because of the file:../../sdk dependency — the weekly cron skips green forever. POST /v1/boards writes no authz tuple, so dynamically-created boards are unenforced. The APM assertion checks only “at least one trace exists” against a spec that demands per-hop attributes. And the cloud APM still boots on legacy port 8080.

The plan. sandbox/specs/05-GAP-CLOSURE-2026-07-12.md (SBX-1 … SBX-7): a vendored SDK tarball makes the offline job tokenless, board tuple writes + an F3 sweep table of every mutating handler, per-hop observability assertions, the worker wired behind AMALGA_RUST_WORKER_URL, and the port migration.

full spec: sandbox/specs/05-GAP-CLOSURE-2026-07-12.md · port :41020