Skip to content

Validate descendant provenance across conformance consumers - #295

Merged
BunsDev merged 2 commits into
mainfrom
fix/descendant-provenance-source
Sep 20, 2026
Merged

BunsDev merged 2 commits into
mainfrom
fix/descendant-provenance-source

Conversation

@BunsDev

@BunsDev BunsDev commented Sep 19, 2026 •

Copy link
Copy Markdown
Member

A protected conformance run may start at a descendant of the reviewed producer revision. Previously the lock accepted that shape, but the authority schema, evidence collectors, and run identity checks could not validate it.

This change carries actual Git ancestry through both collectors, verifies the reviewed workflow at the producer and dispatch source, and binds run, job, deployment, artifact, and certificate identities to the dispatch source. The platform harness remains bound to the reviewed producer revision. It also validates Chat's producer-revision resolver as an exact protected workflow graph, including its successful resolver job.

Absent or empty descent preserves tip-only behavior. The current frozen lock remains tip-only; exercising descendant dispatch requires a fresh reviewed binding with the resolver present at both revisions. Publication remains disabled, and real three-platform conformance is still tracked in #38.

Validation on 9615b56:

  • Full corepack pnpm@10.34.0 verify: 80 files, 2,696 passed, 2 skipped; coverage, contracts, packed consumers, stress tests, type checking, and lint passed.
  • Focused authority/local Git regression run: 132 passed, 1 skipped.
  • End-to-end fixture uses distinct producer and dispatch commits, with refusal cases for ancestry, workflow mutations, missing resolver success, and mismatched evidence identities.
  • Independent review found no remaining P1/P2 issues.

These are conformance tooling changes; the public package API is unchanged.

GitHub's provenance names the commit a workflow run started from. When a
protected run is dispatched against a named merged revision, that is the
ref tip rather than the revision, so signerDigest and sourceDigest could
never equal the frozen producer commit and the binding refused every
non-tip producer.

The lock now carries the descent from the attested source down to the
producer commit, and the binding proves each link against real Git
parents exactly as it already does for the authority path. An absent
descent still means the two must be equal, so existing tip-only locks
and the frozen review fixtures validate unchanged.

Descent alone would be a weakening. The run that signs the attestation
executes the workflow as it exists at the attested source, not at the
producer commit, and only the producer commit's copy was ever verified
against the reviewed digest. The evidence path now verifies the workflow
bytes at the attested source too, so a descendant cannot attest evidence
produced by an unreviewed workflow.

Refs OpenCoven/chat#314
Copilot AI lite review requested due to automatic review settings September 19, 2026 02:50

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Descent schema, type declarations, caller wiring, and source workflow graph support remain incomplete.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 High severity

Open (2)
What changed in this PR

Adds provenance source-descent support for validating protected runs against named merged revisions while preserving tip-only compatibility.

Changes:

  • Validates source descent and Git parent lineage.
  • Verifies workflow content at the attested source revision.
  • Updates types, fixtures, locks, and tests.
File Reviewed changes
tests/​conformance-gaps.spec.ts Updates producer fixtures for source-descent behavior.
tests/​conformance-contract.spec.ts Adds descent parsing coverage; parent-walk edge coverage remains incomplete.
scripts/​github-conformance-evidence.mjs Adds source workflow verification, but descent wiring and producer-revision graph support remain incomplete.
scripts/​conformance-contract.mjs Adds descent validation, though its authority schema does not yet accept the descent records.
scripts/​conformance-contract.d.mts Updates declarations but is missing the descent property on the authority parameter.
conformance/​client-v1-cross-repository-lock.json Records the empty tip-only descent for compatibility.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread scripts/conformance-contract.mjs
Comment thread scripts/github-conformance-evidence.mjs
@BunsDev BunsDev changed the title Accept a provenance source that descends from the producer commit Validate descendant provenance across conformance consumers Sep 20, 2026
@BunsDev BunsDev self-assigned this Sep 20, 2026
@BunsDev
BunsDev merged commit 8883580 into main Sep 20, 2026
8 checks passed
@BunsDev
BunsDev deleted the fix/descendant-provenance-source branch September 20, 2026 06:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants