feat(authority): establish autonomous permit foundation - #44
feat(authority): establish autonomous permit foundation#44mindburnlabs wants to merge 50 commits into
Conversation
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
|
Strix is installed on this repository, but we couldn't run this PR security review because this workspace's trial has ended. Add a card to resume code reviews here. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4d54d56175
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "package.json": "cedddab487eef9361782ee578ace4482c9c994bf6b0d2d855797fe8873142abc" | ||
| } | ||
| }, | ||
| "Mindburn-Labs/contracts-autonomous-release-lab": { |
There was a problem hiding this comment.
Add the canary repo to the org manifest
This adds a source-owned gate profile for Mindburn-Labs/contracts-autonomous-release-lab, and the promotion workflow also depends on that repository for the canary PR, but repo-manifest.yaml has no entry for it (rg "contracts-autonomous-release-lab" repo-manifest.yaml returns nothing). Since AGENTS.md defines repo-manifest.yaml as the current machine-readable GitHub org inventory, consumers of the manifest will get an incomplete inventory for a repository that is now required by the release-authority path.
Useful? React with 👍 / 👎.
| owner: ml-platform | ||
| expires: 2027-06-30 | ||
| tempora: | ||
| reason: product checkout lives at /Users/ivan/Code/Tempora outside the Mindburn-Labs workspace root |
There was a problem hiding this comment.
Remove Ivan's hard-coded checkout path
The local policy now embeds /Users/ivan/Code/Tempora as the explanation for tempora, but the repo instruction in AGENTS.md says to use $MINDBURN_WORKSPACE_ROOT for workspace references and not hardcode Ivan's local paths as platform invariants. Please rephrase this in terms of $MINDBURN_WORKSPACE_ROOT or a repo-relative/local alias so the machine-readable policy does not encode one developer's absolute filesystem layout.
Useful? React with 👍 / 👎.
|
Exact-head authority result: run 29511827667 completed at head 1253aae under governing workflow 52a1ef4. Both provider transports succeeded; Anthropic returned ALLOW with five P3 advisories, while OpenAI returned DENY with two P2 blockers: PROMOTION_WORKFLOW_BOOTSTRAP_DEADLOCK at promote-authority.yml:4 and PINNED_AUTHORITY_SHA_MISMATCH at line 78. The reducer correctly emitted DENY permit sha256:ad009c9c7d8fcd5a96a9549c6f8eafff04c2b2ff65937f89ad558cbb067d790f. This is authenticated source-review evidence, not authorization. No rerun, merge, ruleset repin, environment/App mutation, or promotion was performed; this exact head remains on hold. |
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
|
Closing as superseded, per the approved HELM-350 disposition (operator decision 2026-07-23). ... |
|
Completing the closing reason above: the autonomous permit foundation stack in this branch has diverged from the live immutable permit estate — ruleset 18924515 pins the enforcement content at c585fc5, and PR #64 is the content-adoption record for that pinned truth. This branch is not a merge path anymore. Branch intentionally not deleted. |
Stack 1 of 6. Bounded release permit, source-owned gates, generation-two authority base, and review-transport hardening. Followed by #41, #45, #42, #43, and #36.