Repository navigation
L04-07: reconstruct governed publication audit and refuse stale sign-off (#39) - #217
Merged
Merged
Conversation
mberrys
force-pushed
the
l04-07-provenance-signoff
branch
from
October 5, 2026 12:54
6e93c69 to
0864e0b
Compare
mberrys
force-pushed
the
l04-07-provenance-signoff
branch
from
October 5, 2026 12:59
0864e0b to
a1ca101
Compare
mberrys
force-pushed
the
l04-07-provenance-signoff
branch
from
October 5, 2026 14:04
a1ca101 to
1a092d6
Compare
# Conflicts: # UnitTests/tst_governedexecutiontest.cpp # UnitTests/tst_operationhistorytest.cpp
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
L04-07 (#39), slice 7 of the L04 Governed Operation Engine stack (refs #5). One authoritative chain now answers "who approved what output": a
verify()-gated Core reader reconstructs plan, approval, execution, artifacts, validation, and sign-off for one published output; a stored sign-off round-trips and is refused when the bytes it binds changed; the evidence bundle refuses to export a sign-off whose artifact was never seen instead of synthesizing an output identity.Stack position
Slice 7 of 8. Base:
l04-06-published-bytes(#216). Children stack on this branch; land bottom-up.Per-criterion: already satisfied vs built here
FixAppliedevents now bindeffectiveProfileDigest(fixed once in the gateway); the legacy add-bleed approval gainsevidenceSha256+decisionReference(targeted identity fix, not convergence)PDFGovernedPublicationAudit+reconstructGovernedPublicationAudit(store): reads every link from the chain, nothing synthesized; refuseschain-compromised/chain-unavailable/no-accepted-publication; newPDFOperationHistoryStore::execution(QUuid)gettercheck_source_integrity.py) stays; PageMaster's manifest is documented as a reference, not an authorityPDFGovernedExecutionSignOff::fromJson+verifyGovernedSignOffAgainstArtifactre-read and re-hash the published bytes (invalid-document-changed); the evidence bundle refuses a sign-off with no artifact supplied instead of synthesizing oneRequired proof
python scripts/agent/check-change.py --base cf015d5e --head 1a092d68 --head-branch l04-07-provenance-signoff --build-dir <loop-build-l04>-> status: pass, 102/102 checks (LoopLibCore/PdfTool/loop-pdf-worker builds, mapped suites, clang-tidy, format, changelog, architecture contracts).6e93c692. The stack rebase left this slice's own diff unchanged (patch-id verified) and the only later edit is a documentation-only fragment correction, so the proof carries for the code; CI re-runs the mapped lanes on the head above.agent-fastis authoritative.Notes
Closes #39.pdfgovernedexecution.cpprather than at each producer (the recon's line references were stale).Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.