Skip to content

fix: enforce server-owned audit authority admission - #4427

Merged
Trecek merged 24 commits into
developfrom
impl-rectify-audit-authority-20260729-205238
Jul 31, 2026
Merged

fix: enforce server-owned audit authority admission#4427
Trecek merged 24 commits into
developfrom
impl-rectify-audit-authority-20260729-205238

Conversation

@Trecek

@Trecek Trecek commented Jul 30, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • move audit authority identity ownership from child-authored artifacts to the server admission boundary
  • add durable installation, attempt, publication, finalization, replay, and disposition fencing
  • isolate standalone audit evidence and normalize audit outcome routing across recipe families
  • preserve server-authored response fields, including kill_reason, through replay and response budgeting
  • add production-seam, state-machine, fault-injection, retention, security, and architectural regression coverage

Verification

  • pre-commit run --all-files
  • task test-all — 34,230 passed, 631 skipped, 27 xfailed
  • AUTOSKILLIT_TEST_FILTER=conservative AUTOSKILLIT_TEST_BASE_REF=develop task test-check — 32,756 passed, 570 skipped, 27 xfailed
  • independent implementation re-audit: GO

Fixes #4419

@Trecek Trecek left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AutoSkillit PR Review — Verdict: approved_with_comments

Comment thread docs/execution/architecture.md Outdated
Comment thread src/autoskillit/recipe/_contracts_manifest.py
Comment thread src/autoskillit/core/types/_type_audit_admission.py
Comment thread src/autoskillit/core/types/_type_audit_admission.py
Comment thread src/autoskillit/server/_audit_authority_materializer.py
Comment thread src/autoskillit/core/types/_type_audit_admission.py

@Trecek Trecek left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AutoSkillit PR Review — Verdict: approved_with_comments

Comment thread src/autoskillit/server/tools/tools_execution.py
Comment thread tests/conftest.py
Comment thread tests/server/test_audit_cycle_delivery_integration.py

@Trecek Trecek left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AutoSkillit PR Review — completion of bisected batch (2 findings). Verdict: approved_with_comments.

Comment thread src/autoskillit/server/tools/tools_audit_artifacts.py
Comment thread src/autoskillit/server/_audit_authority_materializer.py

@Trecek Trecek left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AutoSkillit PR Review — completion of bisected batch (2 findings). Verdict: approved_with_comments.

Comment thread src/autoskillit/server/tools/tools_audit_artifacts.py
Comment thread src/autoskillit/server/_audit_authority_materializer.py
@Trecek
Trecek force-pushed the impl-rectify-audit-authority-20260729-205238 branch from 6ceea49 to a4ff444 Compare July 31, 2026 07:16
@Trecek
Trecek added this pull request to the merge queue Jul 31, 2026
Merged via the queue into develop with commit 817086f Jul 31, 2026
3 checks passed
@Trecek
Trecek deleted the impl-rectify-audit-authority-20260729-205238 branch July 31, 2026 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant