feat(ci): add strict admission and anchored revocation ledger - #2869
Conversation
Recompute protected decisions, reject incomplete/stale execution and require an independent fresh-provenance verifier. Add bounded single-host append/CAS reference ledger, revocation/circuit recovery and full-baseline age/merge-exposure checks. No canonical gate or reuse activation. Refs #2327, #2336, #2339
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7a7c07ad65
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Independent review and single fix-round checkpoint Reviewed this slice with an independent Terra reader, then reviewed only the blocking fix diff. Current head: e1c8116. The integrated final tree is byte-identical to independently reviewed 636a17329e5a480d702fcf1a9585cf279bbf60fb after preserving each original stack branch and propagating fixes with merge commits. Blocking changes: prohibit Git lazy fetch/protocol execution in immutable readers; use independently trusted self-contained export verification; repair Windows CRLF and privilege-free symlink fixtures. Slice-specific changes remain visible in this PR diff. No result-reuse activation or settings changes. Validation: cumulative Windows control command node --test scripts/ci/smart-ci/*.test.mjs passed 509/509, no failures/skips/cancellations. Independent fix checks: core/repository 110/110; export/workflow 11/11. node scripts/check-doc-links.mjs passed, 683 Markdown files and zero broken relative links. These are additive; hosted CI at the current head/base is still required. Nonblocking findings are tracked once on #2336: #2336 (comment) . Review budget: one original pass and one scoped fix verification, complete. Original E2E/nightly-map findings were already corrected in the previous authored heads and remain covered by the green control tests. The maintainer's current local request explicitly includes finishing and merging this CI work. Parent-first merge order remains #2863, #2864, #2865, #2867, #2868, #2869, #2871; children are retargeted only after parents land, with moved-base requalification. No branch deletion while it is a stack base. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e1c8116a3e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Parent #2868 merged as f0d4ebf at 05:37:52 UTC after exact-head required CI run 34439637559 succeeded, with no pending/failed checks or unresolved review threads. This PR now targets main, confirmed through the API. Updating the branch refreshed its head to 73c98e8. A complete tree comparison against reviewed head e1c8116 found no source changes. The code review remains applicable; fresh full hosted qualification is running before merge. Admission still has no production required-check authority. |
|
Base changed before merge The required run 34441867071 passed at head 73c98e8, but pre-merge validation found main had advanced through product PR #2866 to 384d8df. No merge was attempted on stale qualification. The branch is refreshed to cb7ae41. Comparing the complete old-base/old-head and new-base/new-head diffs shows the five-file admission PR patch is byte-identical. A bounded independent integration check is reviewing the changed-base boundary; fresh full hosted qualification is running. The product changes are preserved. |
|
Second concurrent base refresh Product PR #2886 advanced main to f00cf1d while the prior refresh was qualifying. Updated admission head is now 3c76464. The complete five-file PR patch still matches the original byte-for-byte, and the new main delta contains no CI-control paths. The independent integration check confirmed unchanged imported contract blobs and no new interaction or blocker. The earlier pending run is superseded by this branch update. Only the latest head/current-base full CI can qualify the merge. No product changes were removed or overwritten. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3c764640be
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Third base refresh after the product wave Product PR #2892 advanced main to 93eab34. The product wave has no remaining open PRs at this checkpoint. Admission is refreshed to 10c27c3. The full five-file admission patch remains byte-identical to the reviewed patch. The latest base delta changes no .github, ci, or scripts/ci files, so the independently reviewed CI dependency boundary remains unchanged. The latest complete hosted run is still required before merge. Earlier pending heads were superseded by these base updates; no stale-base merge was attempted. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 10c27c3e27
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Stack and authority
Depends on #2868. Merge parents first, then retarget and requalify. R4: park for maintainer plus independent fresh-context review under SC-10; no auto-merge.
Adds auxiliary admission that recomputes the entire protected plan, accounts for each task exactly once and rejects missing/duplicate/unknown, failed/skipped/cancelled, wrong-SHA/tree/policy, empty or retry-erased execution. Input-based omission additionally requires explicit qualified selection and a reviewed contract. A protected
verifyFreshcallback is mandatory for fresh execution; default denies. REST metadata flags cannot substitute for provenance. Output hasauthority:none; no canonical gate/schema/status or Taskdeck reuse activation is changed.Adds a bounded single-host JSONL ledger with canonical hash chaining, exclusive writer lock, expected-anchor CAS, file fsync, semantic validation before append, irreversible input revocations, task circuits and explicit recovery from a newer complete covering baseline. Full qualification decisions include both baseline age and landed-merge exposure.
Hash chains are not authentication. An external protected anchor/store is required. This does not provision keys, storage, a multi-host database, an event broker or production GitHub execution-provenance verification. Unanchored crash tails/stale locks fail closed and require reconciliation; no auto-truncation or expiry-based lock breaking.
Validation
Local combined continuation + placement suite: 352 passed, 0 failed/skipped/cancelled, Node 22.16.0/Linux. New cases exercise recomputation, stale/incomplete outcomes, absent verifier and exception redaction, unqualified omission, contention, corruption/rollback/partial writes, backward clocks, invalid recovery/duplicate baselines and age/exposure circuits.
Fixture callbacks simulate a trusted verifier; they do not prove production provenance. Hosted configured-Node/full CI and independent review remain required. No product-suite or distributed-durability claim.
Documentation / rollback / outstanding
docs/ci/continuation/ADMISSION_AND_LEDGER.mddescribes the protocol, APIs, trust boundaries, crash/CAS recovery, activation requirements and explicit remaining integrations. Taskdeck's existing policy stays shadow, every adapter contract unreviewed, and human settings/runner/signing decisions unchanged. No permissive placeholder is wired into the canonical gate.Rollback auxiliary code without deleting any independently stored historical revocations. Existing umbrella issues stay open.
Refs #2327, #2336, #2339.