Skip to content

L04-07: reconstruct governed publication audit and refuse stale sign-off (#39) - #217

Merged
mberrys merged 4 commits into
l04-06-published-bytesfrom
l04-07-provenance-signoff
Oct 5, 2026
Merged

mberrys merged 4 commits into
l04-06-published-bytesfrom
l04-07-provenance-signoff

Conversation

@mberrys

@mberrys mberrys commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

L04-07 (#39), slice 7 of the L04 Governed Operation Engine stack (refs #5). One authoritative chain now answers "who approved what output": a verify()-gated Core reader reconstructs plan, approval, execution, artifacts, validation, and sign-off for one published output; a stored sign-off round-trips and is refused when the bytes it binds changed; the evidence bundle refuses to export a sign-off whose artifact was never seen instead of synthesizing an output identity.

Stack position

Slice 7 of 8. Base: l04-06-published-bytes (#216). Children stack on this branch; land bottom-up.

Per-criterion: already satisfied vs built here

Acceptance criterion State Proof
Every event binds exact identities gateway (#37) already binds plan/approval/artifact identities for repair + action-list; holes closed here running/failed FixApplied events now bind effectiveProfileDigest (fixed once in the gateway); the legacy add-bleed approval gains evidenceSha256 + decisionReference (targeted identity fix, not convergence)
A reader can reconstruct who approved what output built here PDFGovernedPublicationAudit + reconstructGovernedPublicationAudit (store): reads every link from the chain, nothing synthesized; refuses chain-compromised / chain-unavailable / no-accepted-publication; new PDFOperationHistoryStore::execution(QUuid) getter
Failure: a second history store is rejected already satisfied the existing provenance guard (check_source_integrity.py) stays; PageMaster's manifest is documented as a reference, not an authority
Failure: stale sign-off after output changes is rejected built here PDFGovernedExecutionSignOff::fromJson + verifyGovernedSignOffAgainstArtifact re-read and re-hash the published bytes (invalid-document-changed); the evidence bundle refuses a sign-off with no artifact supplied instead of synthesizing one

Required proof

  • python scripts/agent/check-change.py --base cf015d5e --head 1a092d68 --head-branch l04-07-provenance-signoff --build-dir <loop-build-l04> -> status: pass, 102/102 checks (LoopLibCore/PdfTool/loop-pdf-worker builds, mapped suites, clang-tidy, format, changelog, architecture contracts).
  • Provenance: the proof was recorded at the pre-rebase head 6e93c692. The stack rebase left this slice's own diff unchanged (patch-id verified) and the only later edit is a documentation-only fragment correction, so the proof carries for the code; CI re-runs the mapped lanes on the head above.
  • Focused: UnitTestsGovernedExecution (47/47) / UnitTestsOperationHistory / UnitTestsPdfToolContract / UnitTestsPreflightVerdict -> 4/4; UnitTestsActionList built + run separately 31/31.
  • New coverage: audit reconstruction over a real chain, close/reopen persistence, tamper (UPDATE/DELETE) refusal, stale sign-off (unchanged passes / changed rejected / round-trip), identity completeness.
  • Architecture: check-architecture.py, test_architecture_contracts.py -> green.
  • Pre-existing flake UnitTestsPdfWorkerIsolation supervisorFaults(cpu) is a razor-margin race against the 135s client timeout #211 can redden a mapped run; CI agent-fast is authoritative.

Notes

  • Closes #39.
  • Recon correction applied: repair and action-list append their chain events through the L04-05 — Centralize approved Core execution #37 gateway now, so the profile-digest identity hole was fixed once in pdfgovernedexecution.cpp rather than at each producer (the recon's line references were stale).
  • Deferred, stated: a CLI entry point for the audit reader (Core API + tests land here); PageMaster and the Editor worker still have no store in scope, recorded in docs.
  • Breaking-change: no.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@mberrys
mberrys force-pushed the l04-07-provenance-signoff branch from a1ca101 to 1a092d6 Compare October 5, 2026 14:04
# Conflicts:
#	UnitTests/tst_governedexecutiontest.cpp
#	UnitTests/tst_operationhistorytest.cpp
@mberrys
mberrys added this pull request to stack #220 October 5, 2026 21:52
@mberrys
mberrys merged commit bef8e06 into l04-02-save-impact-policy Oct 5, 2026
3 of 5 checks passed
@mberrys
mberrys deleted the l04-07-provenance-signoff branch October 5, 2026 22:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant