Repository navigation
Align push checkpoint proof bases and GitHub SSH origins - #59
Merged
Merged
Conversation
hudsonaikins
temporarily deployed
to
tabellio-checkpoint-proof
October 2, 2026 03:29 — with
GitHub Actions
Inactive
Entire-Checkpoint: 2255ff4e2b75
hudsonaikins
force-pushed
the
codex/tabellio-readiness
branch
from
October 2, 2026 15:06
7fc7870 to
000d01b
Compare
hudsonaikins
temporarily deployed
to
tabellio-checkpoint-proof
October 2, 2026 15:06 — with
GitHub Actions
Inactive
hudsonaikins
marked this pull request as ready for review
October 2, 2026 15:12
This branch was previously deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Push checkpoint proof previously compared its base with the advanced origin/main, rejecting a normal proof bound to the parent validated by the gate. The loader now uses HEAD^ for push events and preserves merge-base binding for PRs. Buildkite derives GitHub repository identity with the existing shared parser, including canonical ssh:// origins.
Regression coverage exercises the real loader with a filtered synthetic native bundle: advanced-main prior-base acceptance, wrong-base/repository/candidate rejection, and multi-commit PR merge-base enforcement. The actual registered Buildkite extraction command accepts HTTPS, SCP SSH and canonical SSH, and rejects foreign hosts and malformed repositories. Existing digest, native identity, excluded-transcript and cleanup assertions remain. Independent review passed.
This is a draft follow-up to #58. No merge, new private proof upload, security-setting change or paid Buildkite build is authorized. Configured Entire Git hooks ran but produced no checkpoint for this delegated session; no checkpoint was fabricated. Required product validation needs genuine new-head capture and separately scoped private evidence approval.
Validation at exact head
7fc7870301f3d4b0ef9b9f233ede57be410addd1: all 493 tests and repository checks passed; 10 focused regressions passed; dead-code zero issues; required changed-code coverage/audit zero issues in four files (real PostgreSQL 138 + 16 cases and recovery demo); package dry-run contract passed, 275 entries. Owned package output archived and removed.Hosted results on that same head: Quality run36960416594 passed Tests, Fallow changed-code and Package dry-run. Product run36960416645 failed at the missing approved checkpoint proof loader; validation was not executed, runner cleanup passed. No proof was uploaded. The workflow-created empty environment was removed after completion; original environments and branch protection were verified identical. No Buildkite job was triggered.