Skip to content

Bind the Chat main dispatch revision by its descent to the producer - #318

Merged
BunsDev merged 1 commit into
mainfrom
fix/bind-chat-379-descent
Sep 25, 2026
Merged

BunsDev merged 1 commit into
mainfrom
fix/bind-chat-379-descent

Conversation

@BunsDev

@BunsDev BunsDev commented Sep 25, 2026

Copy link
Copy Markdown
Member

Part of #40.

Protected Chat run 36097764194 dispatched from Chat main at cab1cace, not the bound producer b1091054. The GitHub evidence verifier requires every run, job, deployment, artifact and certificate to name workflow.sourceDigest, so that run's artifacts cannot lift the aggregate block. Because each platform record embeds the frozen lock's digest, the descent has to be bound before the dispatch, not added afterwards.

This binds the current Chat main tip f4fbb423 through the sourceDescent mechanism from #295:

f4fbb423 (#380) → 813ddde5 (#379) → e1d9c643 (#378) → cab1cace (#377) → dbe11775 (#376) → b1091054 (producer)

Each link is a first-parent merge. git diff b1091054 f4fbb423 -- .github/ scripts/ phase1-conformance.lock.json is empty, so the workflow bytes and governed harness files match the producer. The producer, harness authority, workflow digests and validator scripts are unchanged.

  • tests/conformance-contract.spec.ts: the current-lock authority fixture now carries the real descent commits, read from Git. The tip-only refusal test uses the current lock with the descent removed.
  • tests/conformance-gaps.spec.ts: the pinned workflow literal is updated.
  • The workflow doc names the dispatch revision.

Validation: full pnpm verify passes locally (before the one-link extension to f4fbb423). The conformance and release specs pass after it (327 passed).

Next: rotate both validator scopes to the merge, then dispatch at f4fbb423 straight away. If Chat main moves first, the descent needs one more link.

🤖 Generated with Claude Code

Protected run 36097764194 dispatched from Chat main at cab1cace, a
descendant of the bound producer b1091054, so its artifacts cannot satisfy
a tip-only lock. Bind the current Chat main tip f4fbb423 with its explicit
parent walk to the producer. None of the five descent commits changes the
workflow or a governed harness file; the producer, harness authority and
workflow bytes are unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 25, 2026 06:46

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Provenance and ancestry binding require final human validation.

Review effort: Lite
Findings: None

What changed in this PR

Binds Chat main at f4fbb423 to the reviewed producer through a verified Git descent.

Changes:

  • Updates the conformance lock and workflow fixtures.
  • Adds descent ancestry authority and regression coverage.
  • Documents the bound dispatch revision.
File Description
tests/​conformance-gaps.spec.ts Updates the expected workflow binding.
tests/​conformance-contract.spec.ts Adds descent authority fixtures and tip-only testing.
docs/​workflows/​client-v1-cross-repository-conformance.md Documents the bound dispatch revision.
conformance/​client-v1-cross-repository-lock.json Records the dispatch digest and ancestry chain.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants