Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
82 commits
Select commit Hold shift + click to select a range
4a0416c
feat(gateway): redacted support bundle
bordumb Oct 5, 2026
7b31fb1
merge: bring merged qualification execution into operator polish
bordumb Oct 6, 2026
f02d100
feat(gateway): check readiness, stop through outages and guard restor…
bordumb Oct 6, 2026
86356d6
build(gateway): package the operator handoff and exercise emergency s…
bordumb Oct 6, 2026
73694cc
fix(gateway): persist credential cleanup and check runtime readiness …
bordumb Oct 6, 2026
94fc4fc
test(gateway): rehearse physical restore and preserve operator refusa…
bordumb Oct 6, 2026
7b83fd8
fix(gateway): decode closed readiness codes and exercise extracted op…
bordumb Oct 6, 2026
b786d9d
fix(gateway): reject arbitrary diagnostic text in support archives
bordumb Oct 6, 2026
ad6bc48
fix(gateway): split operator credential reads and writes by workload …
bordumb Oct 6, 2026
2906cab
build(gateway): bind operator archives to the exact pull request cand…
bordumb Oct 6, 2026
7b80638
fix(gateway): bound outage support collection and refuse damaged rest…
bordumb Oct 6, 2026
33e6952
fix(ci): assign gateway deployment verification phases
bordumb Oct 6, 2026
90357c0
docs(gateway): make qualification runbook commands executable
bordumb Oct 6, 2026
10111b9
fix(gateway): expire stale clock synchronization samples
bordumb Oct 6, 2026
d84311f
docs(gateway): order reconciliation around enabled leases
bordumb Oct 6, 2026
631f44c
docs(program): record GitHub SDK candidate handoff
bordumb Oct 6, 2026
4ab303b
fix(gateway): satisfy operator preflight lint checks
bordumb Oct 6, 2026
d24db30
fix(formal): refresh credential-store proof coverage measurement
bordumb Oct 6, 2026
8c98ecf
test(gateway): follow durable emergency-stop cleanup contract
bordumb Oct 6, 2026
71a85bf
fix(gateway): use the test host directory without underscore access
bordumb Oct 6, 2026
5aa0916
chore(formal): regenerate qualification artifacts
github-actions[bot] Oct 6, 2026
f1f92c3
chore(release): synchronize frozen assurance evidence
bordumb Oct 6, 2026
7bb3dcb
docs(gateway): record hosted evidence and diagnostic limits
bordumb Oct 6, 2026
8900553
feat(gateway): rehearse packaged operator commands without source che…
bordumb Oct 6, 2026
6667ced
fix(gateway): drain development hosts for operator file rotation
bordumb Oct 6, 2026
0f91af2
fix(gateway): declare synthetic qualification tuple in rehearsal
bordumb Oct 6, 2026
393edc5
docs(gateway): record passing Docker operator rehearsal
bordumb Oct 6, 2026
9d25e30
feat(release): derive stable launch readiness from signed evidence
bordumb Oct 6, 2026
88dad6b
fix(release): use the semantic closure decoder bound
bordumb Oct 6, 2026
00206fb
chore(formal): regenerate qualification artifacts
github-actions[bot] Oct 6, 2026
4f26b32
fix(release): bind the launch projection into the final manifest
bordumb Oct 6, 2026
7190901
fix(release): require and revalidate the computed launch projection
bordumb Oct 6, 2026
338453d
docs(qualification): define the proposed provider claims and bootstra…
bordumb Oct 6, 2026
fa9ca49
test(qualification): verify the published evidence closure
bordumb Oct 6, 2026
35d6995
docs(spec): align the launch evidence scenario and remaining gates
bordumb Oct 6, 2026
aff7e62
test(qualification): discard proposals before release consumption
bordumb Oct 6, 2026
de20ccc
docs(program): close the simulated Epic 4 operator deliverable
bordumb Oct 6, 2026
6806dcd
Fix launch fixture identifier references reported by CI
bordumb Oct 6, 2026
3ab35fc
Rehearse disposable qualification bootstrap and two provider lifecycles
bordumb Oct 6, 2026
e035f6d
Merge remote-tracking branch 'origin/main' into codex/recipe-qualific…
bordumb Oct 6, 2026
90a63ae
Package source-free qualification rehearsal and measure recovery races
bordumb Oct 6, 2026
926ceca
Support the operator host Python when hashing rehearsal binaries
bordumb Oct 6, 2026
9a0eb4c
Resolve checkout paths only for source builds in the portable runner
bordumb Oct 6, 2026
bc18c39
Measure read-back leases in qualification races and fix preflight lints
bordumb Oct 6, 2026
20837b5
Sign measured provider simulation reports and verify published bytes
bordumb Oct 6, 2026
a4d70ba
Keep protected production-readiness probe out of intermediate issuanc…
bordumb Oct 7, 2026
43f59bd
Format intermediate issuance scenario filter
bordumb Oct 7, 2026
8b6f96e
Rehearse real Airtable from installed SDK with isolated custody and s…
bordumb Oct 7, 2026
3e9704b
Qualify platform-only Stripe test refunds without Connect onboarding
bordumb Oct 7, 2026
bd5b87f
Refresh gateway closure and document public metadata scan findings
bordumb Oct 7, 2026
ec75deb
Specify bounded commissioning authority for first qualification
bordumb Oct 7, 2026
37b8796
Add purpose-bound qualification commissioning artifacts
bordumb Oct 7, 2026
8b2accd
Persist lifetime commissioning lease budgets on PostgreSQL
bordumb Oct 7, 2026
267a37a
Add private operator commissioning sessions with retained lease floors
bordumb Oct 7, 2026
c92531a
Pin offline qualification root and expose purpose-bound commissioning…
bordumb Oct 7, 2026
4d1aa4e
Derive offline production identity and independently review finite co…
bordumb Oct 7, 2026
d22e4ec
Separate first-run commissioning from ordinary qualified client evidence
bordumb Oct 7, 2026
f36d9e9
Measure actual custody and transport execution at private operator bo…
bordumb Oct 7, 2026
3f65fdf
Bind fresh qualification witnesses to reviewed subjects and retain me…
bordumb Oct 7, 2026
872ddc5
Journal disposable provider setup and verify ownership before cleanup
bordumb Oct 7, 2026
632e279
Validate Stripe test mode through its documented payment and charge o…
bordumb Oct 7, 2026
af34eb6
Retain shipping candidates and the actual disposable resource lifecyc…
bordumb Oct 7, 2026
bbd9b5d
Keep offline differential verification credential-free and update mea…
bordumb Oct 7, 2026
0e5ad33
Fix strict lint in qualification witness regressions
bordumb Oct 7, 2026
d6c3cd7
Keep installed qualification author isolated and refresh exact bounde…
bordumb Oct 7, 2026
47dfc3c
Scan the complete qualification publication tree before retaining evi…
bordumb Oct 7, 2026
84eb5e3
chore(formal): regenerate qualification artifacts
github-actions[bot] Oct 7, 2026
77ec9c2
Version the regenerated formal assurance inventory
bordumb Oct 7, 2026
d149ba4
Retain disposable resources across the complete protected journey
bordumb Oct 7, 2026
56e2c42
Keep the installed qualification author isolated across runner steps
bordumb Oct 7, 2026
9d66eda
Bound author sessions with monotonic deadlines
bordumb Oct 7, 2026
1ba1595
Confine qualification artifact waits to the exact protected run
bordumb Oct 7, 2026
3871a56
Support the operator Python baseline for artifact verification
bordumb Oct 7, 2026
4d0f151
Bind finite commissioning contexts to one shared lifetime budget
bordumb Oct 7, 2026
4a5c9b5
Author finite fresh-challenge replay packets with the installed SDK
bordumb Oct 7, 2026
7050874
Stream private commissioning counters without cancelling entered atte…
bordumb Oct 7, 2026
c7d837b
Bind qualification packet pools and measured provider observations
bordumb Oct 7, 2026
9739f15
Reconstruct qualification record resource names from owned ledgers
bordumb Oct 7, 2026
7525ad3
Scan and close final qualification proposals before publication
bordumb Oct 7, 2026
25b43de
Add transparent TLS faults and exercise complete proposal closure
bordumb Oct 7, 2026
85bdb01
Reconstruct commissioning authority from reviewed signer source
bordumb Oct 7, 2026
5428ca5
Plan finite count and sum qualification boundary experiments
bordumb Oct 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
277 changes: 212 additions & 65 deletions .github/workflows/recipe-qualification.yml

Large diffs are not rendered by default.

10 changes: 10 additions & 0 deletions .gitleaksignore
Original file line number Diff line number Diff line change
Expand Up @@ -72,3 +72,13 @@ af4791caed6a8cb6fc37313f9cacfe52bc0e2394:product/integrations/auths-stripe/fixtu
# generator now names the key "commit" and writes digests as "sha256:<hex>".
d92064d919b7c2498ce62588ff48a82284f0bcd7:formal/proof-coverage-v1.json:generic-api-key:9
d92064d919b7c2498ce62588ff48a82284f0bcd7:formal/proof-coverage-v1.json:generic-api-key:84

# Public metadata in signed development-rehearsal evidence (7 October 2026).
# key_sha256 is hex::encode(AttemptKey), the SHA-256 of public attempt identity;
# support.rs never exports provider credentials. Preserve the exact signed-run
# support bytes; these exceptions cover only the named historical fingerprints.
8b6f96e7e43dacf5b7f237cfc015f84a513a2bd1:qualification/simulation/evidence/airtable-live-2026-10-07/support-bundle.json:generic-api-key:1
3e9704b5d4d12bc654fc48de9b03ab6adb9fcb41:qualification/simulation/evidence/stripe-platform-live-2026-10-07/support-bundle.json:generic-api-key:1
# Ordinary progress prose triggered the generic key rule. The current prose
# avoids the ambiguous wording; no credential occurred in the historical line.
3e9704b5d4d12bc654fc48de9b03ab6adb9fcb41:docs/PROGRAM_BOARD.md:generic-api-key:477
2 changes: 2 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions architecture/dependency-graph.dot
Original file line number Diff line number Diff line change
Expand Up @@ -763,6 +763,7 @@ digraph auths_architecture {
"xtask" -> "auths-did-key" [label="normal"];
"xtask" -> "auths-did-web" [label="normal"];
"xtask" -> "auths-errors" [label="normal"];
"xtask" -> "auths-gateway" [label="normal"];
"xtask" -> "auths-github" [label="normal"];
"xtask" -> "auths-hsm-attested" [label="normal"];
"xtask" -> "auths-kubernetes" [label="normal"];
Expand All @@ -777,6 +778,7 @@ digraph auths_architecture {
"xtask" -> "auths-radicle" [label="normal"];
"xtask" -> "auths-raw-key" [label="normal"];
"xtask" -> "auths-receipts" [label="normal"];
"xtask" -> "auths-recipe-qualification" [label="normal"];
"xtask" -> "auths-records-api" [label="normal"];
"xtask" -> "auths-registries" [label="normal"];
"xtask" -> "auths-signature" [label="normal"];
Expand Down
24 changes: 24 additions & 0 deletions architecture/dependency-graph.json
Original file line number Diff line number Diff line change
Expand Up @@ -16991,6 +16991,18 @@
"std"
]
},
{
"source": "xtask",
"source_layer": "tooling",
"target": "auths-gateway",
"target_layer": "product",
"scope": "internal",
"kind": "normal",
"target_condition": null,
"optional": false,
"default_features": true,
"features": []
},
{
"source": "xtask",
"source_layer": "tooling",
Expand Down Expand Up @@ -17169,6 +17181,18 @@
"default_features": true,
"features": []
},
{
"source": "xtask",
"source_layer": "tooling",
"target": "auths-recipe-qualification",
"target_layer": "product",
"scope": "internal",
"kind": "normal",
"target_condition": null,
"optional": false,
"default_features": true,
"features": []
},
{
"source": "xtask",
"source_layer": "tooling",
Expand Down
104 changes: 104 additions & 0 deletions bindings/fixtures/gateway/production-codes.json
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,110 @@
"id": "lease-never-precedes-claim"
}
},
{
"code": "gateway.commissioning.binding-mismatch",
"owner": "commissioning-budget",
"stage": "before-custody",
"status": "implemented",
"epic": 5,
"case": null
},
{
"code": "gateway.commissioning.clock-untrusted",
"owner": "commissioning-budget",
"stage": "before-custody",
"status": "implemented",
"epic": 5,
"case": null
},
{
"code": "gateway.commissioning.contention",
"owner": "commissioning-budget",
"stage": "before-custody",
"status": "implemented",
"epic": 5,
"case": null
},
{
"code": "gateway.commissioning.exhausted",
"owner": "commissioning-budget",
"stage": "before-custody",
"status": "implemented",
"epic": 5,
"case": null
},
{
"code": "gateway.commissioning.expired",
"owner": "commissioning-budget",
"stage": "before-custody",
"status": "implemented",
"epic": 5,
"case": null
},
{
"code": "gateway.commissioning.registration-missing",
"owner": "commissioning-budget",
"stage": "before-custody",
"status": "implemented",
"epic": 5,
"case": null
},
{
"code": "gateway.commissioning.restore-rollback",
"owner": "commissioning-budget",
"stage": "before-custody",
"status": "implemented",
"epic": 5,
"case": null
},
{
"code": "gateway.commissioning.revocation-rollback",
"owner": "commissioning-budget",
"stage": "before-custody",
"status": "implemented",
"epic": 5,
"case": null
},
{
"code": "gateway.commissioning.revocation-stale",
"owner": "commissioning-budget",
"stage": "before-custody",
"status": "implemented",
"epic": 5,
"case": null
},
{
"code": "gateway.commissioning.revoked",
"owner": "commissioning-budget",
"stage": "before-custody",
"status": "implemented",
"epic": 5,
"case": null
},
{
"code": "gateway.commissioning.state-corrupt",
"owner": "commissioning-budget",
"stage": "before-custody",
"status": "implemented",
"epic": 5,
"case": null
},
{
"code": "gateway.commissioning.store-unavailable",
"owner": "commissioning-budget",
"stage": "before-custody",
"status": "implemented",
"epic": 5,
"case": null
},
{
"code": "gateway.commissioning.unavailable",
"owner": "commissioning-budget",
"stage": "before-custody",
"status": "implemented",
"epic": 5,
"case": null
},
{
"code": "gateway.connection.credential-generation-missing",
"owner": "engine",
Expand Down
18 changes: 18 additions & 0 deletions bindings/fixtures/qualification/commissioning-v2.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
{
"schema": "auths.qualification-commissioning-vectors/2",
"synthetic": true,
"trust_root": "{\"public_key_b64\":\"0EqyMnQrtKs6E2i9RhXk5tAiSrcaAWuvhSCjMsl3hzc\",\"root_id\":\"test-root\",\"schema\":\"auths.qualification-trust-root/1\",\"signature_suite\":\"ed25519-v1\"}",
"signer_certificate": "{\"root_signature_b64\":\"CbNmJUTovHK87FHlPhOC2TtvjfxmR5FHDvg4EAsNSjLR5bjqqG4zBOhDwbwXlNN97La1kMEVU57h3ApQVI_MCg\",\"statement\":{\"issued_at\":1789913600,\"not_after\":1790086400,\"not_before\":1789913600,\"permitted_artifact_kinds\":[\"qualification-commissioning-permit\"],\"public_key_b64\":\"oJql9HpnWYAv-VX43C0qFKXJnSO-l_hkEn_5ODRVpPA\",\"root_id\":\"test-root\",\"schema\":\"auths.qualification-signer-certificate/1\",\"signature_suite\":\"ed25519-v1\",\"signer_id\":\"test-commissioner\",\"signer_kind\":\"protected-software-release-key-v1\"}}",
"revocation_list": "{\"root_signature_b64\":\"sAtYxcGQsy05npek7vQrBcpqiHKWqcEV-g4EowFJhxs4guxt73ual7FEngULuO3H15qIZLIy4HrbJdyISzJVAA\",\"statement\":{\"issued_at\":1789996400,\"next_update\":1790086400,\"revoked_qualifications\":[],\"revoked_signers\":[],\"root_id\":\"test-root\",\"schema\":\"auths.qualification-revocation-list/1\",\"sequence\":1}}",
"permit": "{\"signature_b64\":\"0nrpp-Hm34Xnj5fGodRMJJDp6ifsNFCvFJ4M3j7aS9Jz73Y7HkXjYi1GfhzQWLTh6tRTP-VhzSHoukbmeTN6Bg\",\"statement\":{\"binding\":{\"allowed_actions\":[\"6363636363636363636363636363636363636363636363636363636363636363\",\"6464646464646464646464646464646464646464646464646464646464646464\"],\"maximum_credential_leases\":32,\"offline_evidence\":{\"conformance_sha256\":\"8749fb03dc89fe583529f59c613c78319e893898118092c61344812be78d1b5c\",\"differential_sha256\":\"5f22f2e011050cbabf1f58bdf92a2912fa489353309b594b4db327865e82cd7f\"},\"principal_sha256\":\"6060606060606060606060606060606060606060606060606060606060606060\",\"protected_run\":\"github.com/auths-dev/auths-proof/actions/runs/1/attempts/1\",\"provider_environment_class\":\"provider-test-mode\",\"resources_sha256\":\"6262626262626262626262626262626262626262626262626262626262626262\",\"source_commit\":\"0123456789abcdef0123456789abcdef01234567\",\"trusted_contexts_sha256\":[\"6161616161616161616161616161616161616161616161616161616161616161\",\"6565656565656565656565656565656565656565656565656565656565656565\"],\"tuple\":{\"compiled_recipe_sha256\":\"1111111111111111111111111111111111111111111111111111111111111111\",\"gateway_semantic_closure_sha256\":\"4444444444444444444444444444444444444444444444444444444444444444\",\"profile_lock_sha256\":\"2222222222222222222222222222222222222222222222222222222222222222\",\"provider_contract_id\":\"3333333333333333333333333333333333333333333333333333333333333333\",\"recipe_family\":\"example-refund-v1\",\"target\":{\"arch\":\"x86_64\",\"credential_store_kind\":\"aws-secrets-manager-v1\",\"gateway_build_sha256\":\"5555555555555555555555555555555555555555555555555555555555555555\",\"gateway_package\":\"auths-gateway\",\"gateway_version\":\"1.0.0-rc.1\",\"os\":\"linux\",\"store_kind\":\"postgresql-v1\",\"store_schema\":\"auths.gateway-store/1\"}}},\"issued_at\":1790000000,\"not_after\":1790007200,\"not_before\":1790000000,\"schema\":\"auths.qualification-commissioning-permit/2\",\"signature_suite\":\"ed25519-v1\",\"signer_id\":\"test-commissioner\"}}",
"permit_digest": "6023cdfdc1af437745f506196bfb853dc10e9d9e53be86337d230a8934a44480",
"budget_scope_sha256": "01640eb7b447d8b909e6955a186f95e3c7bc6765174ee23d8b3dbd0db1c845e5",
"budget_binding_sha256": "d6782163617e1f1aa54cd272fb776fc70426a90fade59718b24306cbfe2275c0",
"limits": {
"actions": 256,
"contexts": 4,
"leases": 1024,
"seconds": 7200,
"bytes": 32768
}
}
Loading
Loading