0.6 prerelease checklist: stabilize guest-agent API and SDKs
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 5/5
- Tempo estimado
- Mais de uma semana
- Facilidade para iniciantes
- 42/100
- Tipo de issue
- Funcionalidade
- Clareza
- Razoavelmente clara
- Status de atividade
- Ativa
- Stack de tecnologia
- go, javascript, python, rust, typescript
- Domínio
- api, backend, documentation
Direção de pesquisa
Comece pelos itens não marcados do SDK e da API versionada nesta checklist e, em seguida, leia docs/guest-api-v1.md, docs/guest-api-v0.md e o trabalho aberto em #1124. Revise as tarefas restantes de release do SDK e de documentação por SDK, os nomes opacos dos campos JSON e as representações de bytes do protobuf. Considera-se concluído quando os SDKs alterados forem lançados como 0.6.0, o schema v1 estiver corrigido e a documentação de referência tiver sido regenerada.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Objective
Ship dstack 0.6 with a stable, versioned guest-agent API and consistent Go, JavaScript/TypeScript, Python, and Rust SDKs. Existing 0.5.x clients must continue to work against a 0.6 agent.
Compatibility
- Keep the unversioned API fully compatible with 0.5.x, verified with v0.5.10 generated clients and SDKs. — #1121 runs the released SDK suites against the current agent in CI. The pinned tags are v0.5.8 and v0.5.11, not v0.5.10:
v0.5.10:sdkandv0.5.11:sdkare the same tree object, so running both bought nothing. Note the limit — old JSON clients ignore unknown keys, so this job catches breaking changes to the frozen surface but not additive ones; the shape freeze infrozen_surfaceis what covers additions. - Keep
GetQuoteunchanged: the v0.5 response fields and semantics remain the complete contract. Cross-platform attestation is exposed throughAttest, notGetQuote. - Keep
GetKeywire- and behavior-compatible. Publish a normative specification for path, purpose, supported algorithms, defaults, output encoding, and signature-chain verification. — spec in #1123 (docs/guest-api-v0.md), byte-level: HKDF salt, what enters the KDF vs only the claim, both chain-link preimages, all three signing modes, and the hazard thatalgorithmdoes not domain-separate. - Make
EmitEventreturn 404 with informative error message (deprecated method) - Unknown algorithms must be rejected.
Attestation
- Make
Attestthe single API for platform and GPU attestation
SDKs
- Release all changed SDKs as 0.6.0 and apply semantic versioning consistently.
- Expose the same
TlsKeyOptionsfields and defaults in every SDK.usage_server_authdefaults totrue; remove the unusedpathoption. — #1120 - Represent the TLS private key as PEM and provide an explicit
toPkcs8Der()conversion. Remove ambiguous byte-conversion APIs. — resolved differently, deliberately. The ambiguous accessor is gone from v1 (#1120) and notoPkcs8Der()replaced it: v1 returns PEM and nothing else. The accessor existed to feed the key into the blockchain adapters, v1 has no chain-flavored surface, and DER is one standard-library call away for anyone who wants it. v0 keeps the accessor, because the adapters are v0-typed and that surface is frozen. Reopen this if a v1 caller turns up who needs DER from the SDK itself. - Represent protobuf byte fields as bytes in Rust, not hex strings. — #1124 (open), and in every SDK rather than Rust alone: eleven response fields plus
report_data, with thedecode_*helpers deleted. The JSON wire is unchanged. - Make all SDKs report non-2xx responses consistently, including the server error and HTTP status. — #1120, pinned by tests in #1120 that assert the exact status an image without nvattest answers.
- Regenerate and review the protobuf, HTTP, and SDK reference documentation. — v1 and v0 both have written specs now (
docs/guest-api-v1.md,docs/guest-api-v0.md) andsdk/curl/api.mdwas corrected, but the per-SDK reference docs have not been regenerated.
Versioned API (future)
- Introduce the long-term API under a versioned URL/service namespace such as
/prpc/v1/...and protobuf packagedstack.guest.v1. API selection must not depend on request headers. — #1116; selection is by URL path alone. - Use
*Requestand*Responseconsistently for new messages. Keep the method nameAttest. - Give opaque JSON fields explicit
*_jsonnames in v1, or use typed messages where the schema is stable. — not done.InfoResponsestill carriesapp_compose,vm_configandkey_provider_infoas barestringfields whose comments say they are JSON documents passed through unparsed. v1 is unreleased, so this is still cheap to change.
Signing (future)
- Provide
Signwith an explicit key specification containing path, purpose, and algorithm. — v1 has noSign; the frozen v0Signis now specified indocs/guest-api-v0.md. - Add
GetSigningKeyto return the corresponding public key and certification chain without signing a message. — v1GetKeyreturnspublic_keyandsignature_chainalongside the key, which covers the use case but not as a separate method. - Provide signature verification as SDK functionality rather than an agent RPC. — #1110. v0's
VerifyRPC is still served for 0.5.x clients and is documented as frozen. - Specify the exact Ed25519 and secp256k1 message and prehashed modes. — done for the frozen v0 surface in #1123, including
secp256k1_prehashedrequiring the caller to supply the digest. v1 has no signing surface to specify.
- Linguagem predominante
- Rust
- Estrelas
- 551
- Forks
- 97
- Merge médio
- 1d 3h
- PRs com merge (30d)
- 199
Preparar o ambiente
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de Dstack-TEE/dstack
-
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 35/100
Dstack-TEE/dstack#1384 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 30/100
Dstack-TEE/dstack#1301 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 55/100
Dstack-TEE/dstack#1300 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 48/100
Dstack-TEE/dstack#1299 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 48/100
Dstack-TEE/dstack#1298 ·
Mantenedores costumam responder em até 1 dia
Todas as issues de Dstack-TEE/dstack
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
vercel-labs/agent-browser#2017 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
tursodatabase/turso#9405 ·
Mantenedores costumam responder em até 1 dia
-
bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
PolyMeilex/Neothesia#447 ·
Mantenedores costumam responder em até 1 dia
-
backend::vllm diffusion multimodal
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
trezor/trezor-firmware#7985 ·
Mantenedores costumam responder em até 2 dias