You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
add an authority-free JCS promotion input that binds production, the release manifest ref/generation/hash/status (production_candidate or canonical production_released), platform and apps overlay refs/hashes, protected environment, and explicit apps-empty intent
add a strict offline verifier for the existing ApprovalGrant -> ApprovalGrantConsumption -> ApprovalDispatchAdmission -> LaunchEffectAuthorizationEnvelope chain and DEPLOY_PRODUCTION_ACTIVATE effect
preflight signed authority without consuming a permit or crossing the dispatch seam, then fail closed on current fence and connector-release drift
wire the verifier tests into the repository-native Go gates
Trust and production boundary
--verification-context supplies verification keys, policy constraints, the current fence, and connector-release state. That context is intentionally not self-authenticating: this verifier validates artifacts against the supplied context, while an integration must load it from a base-owned trust source. That source and its provenance are outside this slice and remain a required production gate.
This is a source verifier slice for HELM-473. It creates no signer, approval, connector authority, deployment, or production mutation. Production Alpha remains NO-GO and undeployed until a base-owned trust source, source-owned apply connector, GitOps inputs, and an actual human promotion exist.
Validation
make quality-pr
focused go test and go vet for ./core/pkg/promotionpermit and ./core/cmd/promotion-permit-verify
git diff --check
Checklist
The change stays within the kernel scope in README.md and docs/KERNEL_SCOPE.md.
Public docs, SDKs, schemas, or examples are unchanged because this is an internal offline verifier surface.
Launchpad live local-container conformance is not affected.
HELM-473 is linked here; no contributor onboarding path changes.
Release version surfaces are untouched; version-drift passed.
Security-sensitive material is not included in the PR.
No public interface is broken.
No advisory quality warning remains for the changed paths.
Review boundary
Independent authority/security review is required before merge. Leave this PR open after CI; do not merge from this task.
Strix is installed on this repository, but we couldn't run this PR security review because this workspace's trial has ended. Add a card to resume code reviews here.
Closing as an unconsumed source experiment, not as completed production authority. Exact head b4c1d36a92d126b42c41026e515cbd6bb32bcd88 is 32 commits behind current main, conflicts, has no workspace caller or release packaging, accepts a caller-supplied non-self-authenticating trust snapshot, and lacks a full positive command proof. Local current-head quality gates passed, but the capability is not deliverable and must not enter the release train as dead authority code. HELM-473 remains open/Active and blocked by HELM-198 and HELM-33; its durable compiler, real consumer, deployment and runtime acceptance are not claimed. The closed PR preserves the eight-commit experiment for any future source-backed redesign.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
production_candidateor canonicalproduction_released), platform and apps overlay refs/hashes, protected environment, and explicit apps-empty intentDEPLOY_PRODUCTION_ACTIVATEeffectTrust and production boundary
--verification-contextsupplies verification keys, policy constraints, the current fence, and connector-release state. That context is intentionally not self-authenticating: this verifier validates artifacts against the supplied context, while an integration must load it from a base-owned trust source. That source and its provenance are outside this slice and remain a required production gate.This is a source verifier slice for HELM-473. It creates no signer, approval, connector authority, deployment, or production mutation. Production Alpha remains NO-GO and undeployed until a base-owned trust source, source-owned apply connector, GitOps inputs, and an actual human promotion exist.
Validation
make quality-prgo testandgo vetfor./core/pkg/promotionpermitand./core/cmd/promotion-permit-verifygit diff --checkChecklist
Review boundary
Independent authority/security review is required before merge. Leave this PR open after CI; do not merge from this task.