Skip to content

[Governance] Remove or independently authorize PR #43 MV3 workflow mutation #212

Description

@seonghobae

Verified current authority defect

Protected main is now exact b05d5acca82b9d916ada2c8e82f59f92a89817e1. PR #43 (test/mv3-downloads) remains open and Ready at exact contributor head ed15185a550ba28dddb05bff6a1736f9acb117e0, but its recorded PR base snapshot is predecessor main 0841d2ab3d8b5e60a03c0a8e818cf438e2716829, and GitHub now reports the PR non-mergeable after protected main moved.

A fresh changed-file inventory still includes .github/workflows/mv3-compatibility.yml among #43's 19 changed files. That workflow delta adds privileged Chrome sandbox setup (sudo chown root:root .../chrome_sandbox, sudo chmod 4755 .../chrome_sandbox) and exports CHROME_DEVEL_SANDBOX.

Protected-main AGENTS.md says scheduled agents may not alter workflows. This remains a governance-owned defect; the scheduled OriginWeave writer is not authorized to adopt, revert, rewrite, self-approve, or otherwise mutate that workflow delta.

Evidence truth after main movement

The native/scanner evidence recorded on exact head ed15185a550ba28dddb05bff6a1736f9acb117e0 was generated while the PR's recorded base snapshot was 0841d2ab3d8b5e60a03c0a8e818cf438e2716829. It remains useful branch-history evidence only and must not be promoted to live-base merge evidence now that protected main is b05d5acca82b9d916ada2c8e82f59f92a89817e1 and GitHub reports #43 non-mergeable.

No local product-code workaround may hide the workflow-authority defect or manufacture a mergeable stack.

Required owner action

Use an explicitly authorized manual/governance path against the then-current exact #43 head and protected main to:

  1. inspect the full intervening protected-main delta and deliberately reconstruct/revalidate test(mv3): prove real downloads compatibility #43 against the live base without force-push, destructive rebase, or predecessor-evidence transfer; and
  2. either remove the workflow mutation while preserving the product/test changes, or independently review and authorize the workflow hardening as a governance change, including the setuid sandbox implications and least-privilege rationale.

After the owner action, rerun all applicable exact-head CI, Manifest V3 browser evidence, SAST, Security Scan, coverage/repository contracts, and current review/approval gates. Resolve review threads only after their underlying defect is actually addressed.

No scheduled-agent merge, workflow edit, gate weakening, synthetic approval, credential change, tag, or publish action is authorized by this issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions