Skip to content

Land v1.3.0-rc.1 adoption-surface program (OVK-PR1–PR9) - #18

Open
fraware wants to merge 19 commits into
mainfrom
adoption-surface-v1.3.0-rc.1
Open

Land v1.3.0-rc.1 adoption-surface program (OVK-PR1–PR9)#18
fraware wants to merge 19 commits into
mainfrom
adoption-surface-v1.3.0-rc.1

Conversation

@fraware

@fraware fraware commented Jul 25, 2026

Copy link
Copy Markdown
Owner

Summary

  • Split the in-repo v1.3.0-rc.1 adoption-surface program into reviewable commits covering OVK-PR1 through OVK-PR9: normative capability/template registry and multi-OS repro baseline, DecisionState lattice, evidence integrity envelope, adapter conformance (including lane adapters), FormalPR-Bench provenance/partitions/holdout, Action SHA pinning and hardening scenarios, private-alpha GitHub App, three advisory pilot reports, and RC prep (TCB, install/DoD gates, attributable publication docs).
  • Includes follow-up correctness fixes for trusted-policy path matching, non-positive worker budget rejection, and control-plane cache-regime isolation so the landed suite stays coherent with the lattice and integrity work.
  • Tree content matches the previously squashed local landing; history is expanded for merge review without rewriting main.

Test plan

  • CI green on this branch (unit/integration, conformance, FormalPR provenance checks)
  • Spot-check scripts/verify_rc_dod.py / scripts/verify_rc_install.py and capability/conformance validators
  • Confirm Action pin path and GitHub App alpha docs still describe advisory-first adoption
  • Merge when ready; cut attributable v1.3.0-rc.1 tag/Sigstore only after gates pass

fraware added 19 commits July 25, 2026 11:08
Record a machine-checkable reproducibility baseline so release candidates can prove adapter and control-plane behavior across platforms before attributable publication.
Tighten the capability schema and publish a template registry so stable backends declare enforceable limits, versions, and eligibility instead of prose-only claims.
Replace ad-hoc merge recommendations with a normative decision lattice, wire aggregation and CLI exit codes through decision_state, and lock behavior with exhaustive truth-table tests.
Define a typed integrity envelope for evidence artifacts so digests, assumptions, and provenance cannot drift between execution, bundle assembly, and attestation checks.
Require every stable adapter to ship machine-readable conformance claims so registry stability implies tested timeout, unavailable, and malformed behavior.
Publish capability and conformance packages for authorization, CI-secrets, deployment, infrastructure, and self-protection lanes so deterministic runners share the same failure taxonomy as native backends.
Add timeout, unavailable, and malformed example payloads so local demos and conformance generators share the same edge-case corpus.
…R5).

Version the benchmark manifest with attributable provenance, mutation partitions, adversarial cases, and held-out variants so leaderboard claims stay reproducible.
Wire provenance generation, holdout runners, and scoring updates so benchmark publications validate against the versioned manifest rather than ad-hoc file lists.
Pin third-party Action dependencies by SHA and add adversarial scenario coverage for fork PRs, malicious paths, and workflow-dispatch edges before consumers widen adoption.
Introduce a signature-verified webhook service with isolation, replay protection, redaction, and check-run emission so App installs stay narrower than the composite Action surface.
Land express-actions, fastapi-terraform, and infra-terraform-k8s pilot reports with check-case evidence so adoption guidance is backed by attributable advisory runs.
Advance release metadata and preflight report shape so install pins and consumer checklists target the in-repo release candidate explicitly.
Document the trusted computing base and add machine-checkable RC definition-of-done plus install verification so attributable publication cannot proceed on incomplete gates.
Match verification-policy changes against the canonical repository path as well as absolute test roots so policy-touching PRs are not silently treated as trusted.
Treat a zero or negative budget as a configuration error rather than a timed-out process so isolation tests and control-plane fallbacks observe the correct failure cause.
Extend cache binding and MCP regression tests so decision-state-aware control-plane replay cannot cross regime boundaries after the lattice landing.
Share digest and manifest helpers used by provenance generation so scoring and holdout tooling stay aligned with the versioned corpus.
Update roadmap, schema index, and root docs for v1.3.0-rc.1, and extend CI so conformance and RC gates run with the rest of the suite.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant