Skip to content

Conversation

@Bownairo
Copy link
Contributor

@Bownairo Bownairo commented Dec 18, 2025

This came out of the now closed #7456. I've moved the check to the "stronger" invariants so that it protects any changes made to replica versions.

frankdavid
frankdavid approved these changes Dec 19, 2025
if r.guest_launch_measurements
.is_some_and(|measurements| measurements.guest_launch_measurements.is_empty())
{
panic!("guest_launch_measurements must not be an empty vector");
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we also validate the contents of the GuestLaunchMeasurements struct using

pub fn validate(&self) -> Result<(), Vec<String>> {
?

@Bownairo Bownairo force-pushed the eero/measurement-followups branch from e2993b1 to 5418b0b Compare December 30, 2025 19:12
@Bownairo Bownairo marked this pull request as ready for review December 30, 2025 19:17
@Bownairo Bownairo requested a review from a team as a code owner December 30, 2025 19:17
Copy link
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pull request changes code owned by the Governance team. Therefore, make sure that
you have considered the following (for Governance-owned code):

  1. Update unreleased_changelog.md (if there are behavior changes, even if they are
    non-breaking).

  2. Are there BREAKING changes?

  3. Is a data migration needed?

  4. Security review?

How to Satisfy This Automatic Review

  1. Go to the bottom of the pull request page.

  2. Look for where it says this bot is requesting changes.

  3. Click the three dots to the right.

  4. Select "Dismiss review".

  5. In the text entry box, respond to each of the numbered items in the previous
    section, declare one of the following:

  • Done.

  • $REASON_WHY_NO_NEED. E.g. for unreleased_changelog.md, "No
    canister behavior changes.", or for item 2, "Existing APIs
    behave as before.".

Brief Guide to "Externally Visible" Changes

"Externally visible behavior change" is very often due to some NEW canister API.

Changes to EXISTING APIs are more likely to be "breaking".

If these changes are breaking, make sure that clients know how to migrate, how to
maintain their continuity of operations.

If your changes are behind a feature flag, then, do NOT add entrie(s) to
unreleased_changelog.md in this PR! But rather, add entrie(s) later, in the PR
that enables these changes in production.

Reference(s)

For a more comprehensive checklist, see here.

GOVERNANCE_CHECKLIST_REMINDER_DEDUP

@Bownairo
Copy link
Contributor Author

@dfinity/governance-team I can't seem to find if these invariants are checked during an upgrade. If not already, maybe they should be?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants