Skip to content

feat(authority): establish autonomous permit foundation - #44

Closed
mindburnlabs wants to merge 50 commits into
mainfrom
codex/autonomous-release-permit-foundation
Closed

feat(authority): establish autonomous permit foundation#44
mindburnlabs wants to merge 50 commits into
mainfrom
codex/autonomous-release-permit-foundation

Conversation

@mindburnlabs

Copy link
Copy Markdown
Contributor

Stack 1 of 6. Bounded release permit, source-owned gates, generation-two authority base, and review-transport hardening. Followed by #41, #45, #42, #43, and #36.

Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
@mindburnlabs
mindburnlabs requested a review from a team as a code owner July 16, 2026 14:37
@strix-security

Copy link
Copy Markdown

Strix is installed on this repository, but we couldn't run this PR security review because this workspace's trial has ended. Add a card to resume code reviews here.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4d54d56175

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

"package.json": "cedddab487eef9361782ee578ace4482c9c994bf6b0d2d855797fe8873142abc"
}
},
"Mindburn-Labs/contracts-autonomous-release-lab": {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Add the canary repo to the org manifest

This adds a source-owned gate profile for Mindburn-Labs/contracts-autonomous-release-lab, and the promotion workflow also depends on that repository for the canary PR, but repo-manifest.yaml has no entry for it (rg "contracts-autonomous-release-lab" repo-manifest.yaml returns nothing). Since AGENTS.md defines repo-manifest.yaml as the current machine-readable GitHub org inventory, consumers of the manifest will get an incomplete inventory for a repository that is now required by the release-authority path.

Useful? React with 👍 / 👎.

owner: ml-platform
expires: 2027-06-30
tempora:
reason: product checkout lives at /Users/ivan/Code/Tempora outside the Mindburn-Labs workspace root

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Remove Ivan's hard-coded checkout path

The local policy now embeds /Users/ivan/Code/Tempora as the explanation for tempora, but the repo instruction in AGENTS.md says to use $MINDBURN_WORKSPACE_ROOT for workspace references and not hardcode Ivan's local paths as platform invariants. Please rephrase this in terms of $MINDBURN_WORKSPACE_ROOT or a repo-relative/local alias so the machine-readable policy does not encode one developer's absolute filesystem layout.

Useful? React with 👍 / 👎.

@mindburnlabs

Copy link
Copy Markdown
Contributor Author

Exact-head authority result: run 29511827667 completed at head 1253aae under governing workflow 52a1ef4. Both provider transports succeeded; Anthropic returned ALLOW with five P3 advisories, while OpenAI returned DENY with two P2 blockers: PROMOTION_WORKFLOW_BOOTSTRAP_DEADLOCK at promote-authority.yml:4 and PINNED_AUTHORITY_SHA_MISMATCH at line 78. The reducer correctly emitted DENY permit sha256:ad009c9c7d8fcd5a96a9549c6f8eafff04c2b2ff65937f89ad558cbb067d790f. This is authenticated source-review evidence, not authorization. No rerun, merge, ruleset repin, environment/App mutation, or promotion was performed; this exact head remains on hold.

Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
@SergeyAP

Copy link
Copy Markdown
Contributor

Closing as superseded, per the approved HELM-350 disposition (operator decision 2026-07-23). ...

@SergeyAP

Copy link
Copy Markdown
Contributor

Completing the closing reason above: the autonomous permit foundation stack in this branch has diverged from the live immutable permit estate — ruleset 18924515 pins the enforcement content at c585fc5, and PR #64 is the content-adoption record for that pinned truth. This branch is not a merge path anymore. Branch intentionally not deleted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants