From 91c7de4bd15a92cd757d878e4866e0c5e8d13bdf Mon Sep 17 00:00:00 2001 From: eimyroot Date: Sun, 6 Sep 2026 13:50:22 +0200 Subject: [PATCH 01/17] docs(governance): record fresh exact-main G0 verification --- CURRENT_PRODUCT_STATE.md | 71 ++++++++++++++++++++++++++-------------- 1 file changed, 46 insertions(+), 25 deletions(-) diff --git a/CURRENT_PRODUCT_STATE.md b/CURRENT_PRODUCT_STATE.md index 2129744a..4e559d75 100644 --- a/CURRENT_PRODUCT_STATE.md +++ b/CURRENT_PRODUCT_STATE.md @@ -56,7 +56,7 @@ RELEASED / DEPLOYED = separately governed states | Restart-safe durable resume | **IMPLEMENTED / MERGED via PR #140** | | Runtime resume wiring | **IMPLEMENTED / MERGED via PR #140** | | G7 post-merge verification | **VERIFIED on `main@60bc9c268...` by CI #1015, D4 #202, E3 #193, E4B #189** | -| GitHub G0 governance | **UNKNOWN / fresh post-rename exact-main verification required** | +| GitHub G0 governance | **VERIFIED / PASS on `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c` via run `34031128405`** | | Default provider runtime pack | **DISABLED / FAIL-CLOSED** | | Real canonical HTTP READ E2E using default G8 pack | **BLOCKED / NOT YET VERIFIED** | | Provider WRITE activation | **BLOCKED** | @@ -69,12 +69,35 @@ RELEASED / DEPLOYED = separately governed states ## G0 GitHub governance — current vs historical evidence -Current canonical repository identity is `eimyroot/Voodoo-One`. No fresh post-rename G0 run is yet -retained for the exact current `main` SHA, so current G0 state is deliberately `UNKNOWN` and the -release-candidate governance gate remains fail-closed until fresh live evidence exists. +Current canonical repository identity is `eimyroot/Voodoo-One`. Fresh post-rename G0 evidence is now +retained for the exact repaired `main` SHA and independently verifies the current repository identity, +required-check provenance and live ruleset controls: -The following retained artifact remains valid historical evidence for the repository identity and -source SHA that existed when it ran: +```text +workflow = g0-governance-verify +run = 34031128405 +event = workflow_dispatch +branch = main +source_sha = a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +branch_head_sha = a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +verifier_source_sha = a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +required_check = verify +required_workflow = ci +required_workflow_path = .github/workflows/ci.yml +artifact = g0-governance-evidence-34031128405-1 +artifact_id = 9988632821 +artifact_digest = sha256:be646405590ac07f6293eaeb94a72c77ecf8ea02c16a31b31ccf93ef4ec92a2c +checksum_validation = PASS +verdict = VERIFIED +verified_at = 2026-09-06T11:45:16.520493Z +``` + +The live verifier observed PR-only main, required `verify` from GitHub Actions workflow `ci`, latest-head +strict checks, force-push disabled, branch deletion disabled, conversation resolution, no ordinary +admin/ruleset bypass, active rulesets and exact verifier-source binding. All required G0 checks were true. + +The earlier retained artifact remains valid historical evidence for the repository identity and source +SHA that existed when it ran: ```text workflow = g0-governance-verify @@ -89,27 +112,24 @@ evidence_json_checksum = 11a99765485b63b70186037011d31c105dea8dd75b689e0036a8766 historical_verdict = VERIFIED ``` -That historical evidence verified PR-only main, required `verify` from workflow `ci`, latest-head -strict checks, force-push disabled, branch deletion disabled, conversation resolution, no ordinary -admin/ruleset bypass, active rulesets, and verifier source binding for its exact evidence scope. It -must not be reused as proof for the renamed current repository identity. +Historical evidence stays historical; the current PASS is supported only by the fresh exact-main run +above. ```text -REPO_ENFORCEMENT_CONTRACT = IMPLEMENTED -GITHUB_SETTINGS_ENFORCED = UNKNOWN -MAIN_PR_ONLY = UNKNOWN_CURRENT_G0 -REQUIRED_CI = UNKNOWN_CURRENT_G0 -FORCE_PUSH_DISABLED = UNKNOWN_CURRENT_G0 -BRANCH_DELETE_DISABLED = UNKNOWN_CURRENT_G0 -CONVERSATION_RESOLUTION = UNKNOWN_CURRENT_G0 -ORDINARY_ADMIN_BYPASS_DISABLED = UNKNOWN_CURRENT_G0 -P0_GITHUB_GOVERNANCE = BLOCKED_PENDING_FRESH_G0 -G0 = UNKNOWN +REPO_ENFORCEMENT_CONTRACT = VERIFIED +GITHUB_SETTINGS_ENFORCED = VERIFIED +MAIN_PR_ONLY = VERIFIED +REQUIRED_CI = VERIFIED +FORCE_PUSH_DISABLED = VERIFIED +BRANCH_DELETE_DISABLED = VERIFIED +CONVERSATION_RESOLUTION = VERIFIED +ORDINARY_ADMIN_BYPASS_DISABLED = VERIFIED +P0_GITHUB_GOVERNANCE = PASS +G0 = PASS ``` -A fresh G0 PASS on the exact post-repair `main` SHA may promote these current governance fields back to -`VERIFIED`; documentation, CI success, or the historical artifact cannot do so by inference. G0 PASS -does not authorize release or deployment. +G0 PASS closes the current repository-governance blocker only. It does not authorize provider runtime, +release, deployment or production effects. ## Canonical shared authority/execution prefix @@ -305,13 +325,14 @@ This historical evidence does not authorize or prove any new provider mutation. - Historical PR #125 technical merge/post-state is VERIFIED; separate pre-merge merge-authorization provenance remains **NOT VERIFIED** and is not rewritten. - ADR-0018 records the R2 terminal-profile correction instead of silently rewriting older history. - PR #128 reconciliation remains historical provenance; later G7 evidence does not rewrite it. -- Historical G0 run `32553113424` remains retained evidence for its original repository identity and exact source SHA; it is not current post-rename proof. +- Historical G0 run `32553113424` remains retained evidence for its original repository identity and exact source SHA. +- Current G0 run `34031128405` VERIFIED the renamed canonical repository at exact `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c`. ## Current release truth ```text VOODOO_ALLOW_PRODUCTION_EFFECTS=false -G0_GITHUB_GOVERNANCE=UNKNOWN +G0_GITHUB_GOVERNANCE=PASS G7_CANONICAL_READ_API=MERGED G7_RESTART_SAFE_RESUME=MERGED G8_DEFAULT_READ_RUNTIME=OFF From 6a563395381fcb76cd7b1dc86ba7b611c31d1d2c Mon Sep 17 00:00:00 2001 From: eimyroot Date: Sun, 6 Sep 2026 13:51:02 +0200 Subject: [PATCH 02/17] docs(governance): promote current G0 after fresh verification --- docs/product/CURRENT_CAPABILITIES.md | 44 +++++++++++++++++++--------- 1 file changed, 30 insertions(+), 14 deletions(-) diff --git a/docs/product/CURRENT_CAPABILITIES.md b/docs/product/CURRENT_CAPABILITIES.md index e9aa9ca1..ed3f175b 100644 --- a/docs/product/CURRENT_CAPABILITIES.md +++ b/docs/product/CURRENT_CAPABILITIES.md @@ -85,19 +85,19 @@ Is it released/deployed? | OperationProof/v2 | VERIFIED | current contract/tests + historical F6b digest | mutation-only post-verification lineage | | OperationCell/v1 | VERIFIED | current contract/tests + historical F6b digest | mutation-only stable operation atom | | Unified authority→profile runtime composition | IMPLEMENTED | ProductComposition + canonical runtime tests + PR #140 | public READ API merged; default provider pack still off | -| Receipt/audit hash-chain integrity | VERIFIED | ledger verification tests | chain integrity != independent provider verification | +| Receipt/audit hash-chain integrity | VERIFIED | ledger verification tests | chain integrity != independent verification | | SQLite migrations | VERIFIED | migrations 0001–0014 + integrity tests | single-node backend | | PostgreSQL backend | BLOCKED | fail-closed startup contract | adapter/concurrency/operations gates not released | | OIDC identity provider | BLOCKED | fail-closed configuration tests | no released external identity runtime | | Security Intelligence R-SI1.1 | IMPLEMENTED | metadata + tests | intelligence-only; no execution/proof authority | | Security Intelligence R-SI1.2 normalization | IMPLEMENTED | merged PR #135 | descriptive/context-only; no authority/runtime/effect widening | | CyberCore integration | BLOCKED | product/release-governance hardening | cannot bypass V-One gates | -| Main GitHub governance policy | UNKNOWN | historical G0 run `32553113424` remains VERIFIED for its original evidence scope | fresh exact-main G0 is required for current `eimyroot/Voodoo-One` identity | -| Main required latest-head enforcement | UNKNOWN | historical G0 verified PR-only main, required `verify`, latest-head strict checks and no ordinary bypass for its then-current repository identity | current post-rename enforcement must be re-verified live | +| Main GitHub governance policy | VERIFIED | fresh G0 run `34031128405` on exact `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c`; artifact digest `sha256:be646405590ac07f6293eaeb94a72c77ecf8ea02c16a31b31ccf93ef4ec92a2c` | release/deploy remain separate gates | +| Main required latest-head enforcement | VERIFIED | fresh G0 verified PR-only main, required `verify` from `ci`, latest-head strict checks, no ordinary bypass, force-push/deletion disabled | later repository/ruleset changes require fresh live evidence for their own exact scope | | G8 default READ provider runtime | BLOCKED | G8 gate defined; no default runtime activation yet | must be READ-only, explicit, separate Runner/Verifier credentials, fail-closed | | Real canonical HTTP READ E2E + restart resume | BLOCKED | G7 components merged; G8 runtime not yet active | must prove HTTP→Runner→independent `VerificationResult/v1` plus no duplicate authority/effect after restart | | Provider WRITE activation | BLOCKED | ADR-0019 safety decision is under governed adoption | not eligible before verified repeated READ E2E + restart-safe continuity | -| Release-candidate build | VERIFIED | fail-closed workflow + historical image/SBOM checks | build candidate != deployment; current RC construction is additionally blocked until fresh current G0 succeeds | +| Release-candidate build | VERIFIED | fail-closed workflow + historical image/SBOM checks; current G0 blocker closed by fresh exact-main evidence | build candidate != deployment; remaining release-candidate gates still apply | | Unrestricted production release | BLOCKED | production effects default disabled | G8 + real READ E2E + security/legal/ops/release gates remain | | Public commercial distribution | BLOCKED | no distribution authorization | licensing/EULA/privacy/support and production gates remain separate | @@ -177,11 +177,29 @@ membership is a scope check, not activation of the separately PROPOSED Solo/Team ## G0 governance evidence — current vs historical -Current canonical repository identity is `eimyroot/Voodoo-One`. A fresh post-rename G0 observation on -the exact current `main` SHA has not yet been retained, so current GitHub governance status is -`UNKNOWN` and must fail closed for release-candidate promotion. +Current canonical repository identity is `eimyroot/Voodoo-One`. Fresh post-rename G0 evidence is +retained for the exact repaired `main` SHA: -The following retained artifact remains VERIFIED historical evidence for the exact repository identity +```text +workflow = g0-governance-verify +run = 34031128405 +event = workflow_dispatch +source_sha = a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +branch_head_sha = a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +verifier_source_sha = a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +artifact = g0-governance-evidence-34031128405-1 +artifact_id = 9988632821 +artifact_digest = sha256:be646405590ac07f6293eaeb94a72c77ecf8ea02c16a31b31ccf93ef4ec92a2c +checksum_validation = PASS +verdict = VERIFIED +verified_at = 2026-09-06T11:45:16.520493Z +``` + +The fresh evidence verifies PR-only main, required `verify` from GitHub Actions workflow `ci`, exact +workflow path `.github/workflows/ci.yml`, latest-head strict checks, force-push and deletion disabled, +conversation resolution, no ordinary bypass, active rulesets and exact source binding. + +The earlier retained artifact remains VERIFIED historical evidence for the exact repository identity and source SHA that existed when it ran: ```text @@ -196,11 +214,9 @@ evidence_json_checksum = 11a99765485b63b70186037011d31c105dea8dd75b689e0036a8766 historical_verdict = VERIFIED ``` -That historical evidence verified PR-only main, required `verify` from workflow `ci`, latest-head -strict checks, force-push and deletion disabled, conversation resolution, no ordinary bypass, active -rulesets, and source binding for its exact evidence scope. It is not current post-rename proof. A fresh -G0 PASS on the exact repaired `main` may promote current GitHub governance back to `VERIFIED`; G0 never -authorizes release/deploy by itself. +Historical evidence stays historical. Current G0 is VERIFIED only because the fresh exact-main run +independently proved the renamed repository and live controls. G0 never authorizes release/deploy by +itself. ## Verified historical complete operation atom @@ -232,7 +248,7 @@ This is historical evidence for one real atom. It does not execute or authorize VOODOO_ALLOW_PRODUCTION_EFFECTS=false NEW_G7_PROVIDER_WRITE=NO NEW_A09_PROVIDER_MUTATION=NO -G0_LIVE_ENFORCEMENT_VERIFIED=UNKNOWN_CURRENT +G0_LIVE_ENFORCEMENT_VERIFIED=YES G8_DEFAULT_PROVIDER_RUNTIME=OFF REAL_CANONICAL_READ_E2E_VERIFIED=NO WRITE_RUNTIME_GATE=BLOCKED From 048101ccd3159f4c7c90a6f1c49bcf7f7a0ba0b6 Mon Sep 17 00:00:00 2001 From: eimyroot Date: Sun, 6 Sep 2026 13:51:38 +0200 Subject: [PATCH 03/17] docs(governance): surface verified current G0 evidence --- README.md | 35 +++++++++++++++++++++++++---------- 1 file changed, 25 insertions(+), 10 deletions(-) diff --git a/README.md b/README.md index 5d486cc5..e4754d27 100644 --- a/README.md +++ b/README.md @@ -69,7 +69,7 @@ OperationProof != OperationCell | Canonical FastAPI ProductComposition runtime seam | IMPLEMENTED / MERGED; explicit runtime factory required, default provider pack disabled | | Canonical public READ operation API | IMPLEMENTED / MERGED via PR #137; reconciled with resume/runtime via PR #140 | | Restart-safe durable READ resume | IMPLEMENTED / MERGED via PR #140 | -| GitHub main governance enforcement | UNKNOWN / fresh post-rename G0 required; historical VERIFIED evidence retained | +| GitHub main governance enforcement | VERIFIED / G0 PASS on exact `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c`; historical evidence retained separately | | Default provider runtime pack | BLOCKED / disabled until G8 | | Real canonical HTTP READ E2E through default G8 pack | BLOCKED / not yet verified | | Provider WRITE activation | BLOCKED pending repeated READ E2E + restart-safe verification gate | @@ -157,8 +157,25 @@ deployment, or release. ## G0 governance evidence -The repository retains historical live G0 evidence for the repository identity that was current when -the run executed: +Fresh current live G0 evidence is retained for the renamed canonical repository and exact repaired +`main` SHA: + +```text +workflow = g0-governance-verify +run = 34031128405 +source_sha = a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +artifact = g0-governance-evidence-34031128405-1 +artifact_id = 9988632821 +artifact_digest = sha256:be646405590ac07f6293eaeb94a72c77ecf8ea02c16a31b31ccf93ef4ec92a2c +checksum_validation = PASS +verdict = VERIFIED +``` + +The fresh run verified the current `eimyroot/Voodoo-One` identity, exact main/verifier source binding, +PR-only main, required `verify` from workflow `ci`, latest-head strict checks, force-push and deletion +disabled, conversation resolution, active rulesets and no ordinary bypass. + +The repository also retains the earlier G0 artifact for its original evidence scope: ```text workflow = g0-governance-verify @@ -166,14 +183,12 @@ run = 32553113424 source_sha = 76d74d2ed62b6e78f027728c456c22da0b4a95bd artifact = g0-governance-evidence-32553113424-1 artifact_digest = sha256:6e63caee23a57613471df66ef0279c0261ed8d375e4c929accdf50eff7dc4f5f -verdict = VERIFIED +historical_verdict = VERIFIED ``` -That artifact remains valid historical evidence only. The canonical repository is now -`eimyroot/Voodoo-One`; current G0 governance is therefore `UNKNOWN` until a fresh -`g0-governance-verify` run executes on the exact post-repair `main` SHA and independently verifies the -current repository identity and live ruleset. Historical G0 PASS never authorizes provider runtime, -release, or deployment. +Historical evidence stays historical. Current G0 is PASS only because the fresh exact-main verifier +independently proved the renamed repository and live ruleset. G0 PASS never authorizes provider runtime, +release or deployment. ## READ before WRITE @@ -221,7 +236,7 @@ a new provider mutation is authorized. - default G8 provider runtime and real product HTTP READ E2E remain blocked/unverified; - provider WRITE remains blocked behind READ-before-WRITE evidence and separate effect authorization; - no release/deployment inferred from CI, merge, Proof or Cell; -- historical G0 VERIFIED evidence is retained, while current post-rename GitHub governance remains UNKNOWN until fresh exact-main verification. +- current post-rename GitHub governance has fresh exact-main G0 VERIFIED evidence; historical G0 evidence remains separately scoped. ## Documentation From 640435fe465573d4adb59c9c5158b81bf6140472 Mon Sep 17 00:00:00 2001 From: eimyroot Date: Sun, 6 Sep 2026 13:52:11 +0200 Subject: [PATCH 04/17] docs(governance): record current G0 baseline verification --- .../GITHUB_MAIN_GOVERNANCE_BASELINE_V1.md | 34 +++++++++++++++++-- 1 file changed, 31 insertions(+), 3 deletions(-) diff --git a/docs/governance/GITHUB_MAIN_GOVERNANCE_BASELINE_V1.md b/docs/governance/GITHUB_MAIN_GOVERNANCE_BASELINE_V1.md index 7fdd60bd..ad4e7a25 100644 --- a/docs/governance/GITHUB_MAIN_GOVERNANCE_BASELINE_V1.md +++ b/docs/governance/GITHUB_MAIN_GOVERNANCE_BASELINE_V1.md @@ -1,12 +1,12 @@ # GitHub Main Governance Baseline v1 -Status: PREPARED — repository-side contract repaired for `eimyroot/Voodoo-One`; fresh live G0 verification required +Status: VERIFIED — fresh exact-main G0 evidence retained for `eimyroot/Voodoo-One` ## Purpose Define the minimum GitHub repository enforcement required before higher-impact V-One authority, Grant Issuer, Runner, release, or production-capable work may rely on GitHub as a governance boundary. -This document does not claim that GitHub Settings are already enforced. Remote enforcement must be verified independently against the live repository configuration. +Current live enforcement is VERIFIED only for the exact evidence scope recorded below. Remote enforcement must be re-verified independently after repository-identity, ruleset or required-check changes. ## Canonical protected branch @@ -75,6 +75,34 @@ source = GitHub live repository settings/API A repository document, CI pass, issue, PR description or previous observation is not sufficient evidence of GitHub-side enforcement. A repository rename or transfer changes the identity being verified: a historical G0 PASS for a different repository identity remains historical evidence and is not reusable as current G0 proof. +## Current retained G0 evidence + +The current exact-main verification is: + +```text +workflow = g0-governance-verify +run = 34031128405 +repository = eimyroot/Voodoo-One +branch = main +branch_head_sha = a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +verifier_source_sha = a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +required_status_check = verify +observed_required_workflow = ci +observed_required_workflow_path = .github/workflows/ci.yml +artifact = g0-governance-evidence-34031128405-1 +artifact_id = 9988632821 +artifact_digest = sha256:be646405590ac07f6293eaeb94a72c77ecf8ea02c16a31b31ccf93ef4ec92a2c +checksum_validation = PASS +verdict = VERIFIED +verified_at = 2026-09-06T11:45:16.520493Z +``` + +The evidence reported every required G0 check as true, including PR-only main, strict/latest-head +required checks, GitHub Actions provider/workflow identity, force-push and branch deletion disabled, +conversation resolution, complete bypass evidence with no ordinary bypass actor, active rulesets and +exact verifier-source binding. This evidence is current only for its exact scope; later relevant +GitHub/repository changes require fresh live G0 verification. + ## Machine verification Canonical local/manual verification can read live settings without claiming checkout freshness: @@ -207,4 +235,4 @@ ORDINARY_ADMIN_BYPASS_DISABLED = VERIFIED P0_GITHUB_GOVERNANCE = PASS ``` -Until all fields are proven, authority/Runner work may be designed or prepared but must not treat GitHub enforcement as a trusted completed boundary. +Current fresh evidence satisfies the exit gate for exact `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c`. Later relevant repository or GitHub-governance changes require a new exact-main G0 observation rather than inference from this artifact. From ef1a10573b2361e9ea36b4745e51dc1c99dcad71 Mon Sep 17 00:00:00 2001 From: eimyroot Date: Sun, 6 Sep 2026 13:52:35 +0200 Subject: [PATCH 05/17] test(governance): bind current truth to fresh G0 evidence --- .../test_pr01_repository_identity_truth.py | 41 +++++++++++++------ 1 file changed, 29 insertions(+), 12 deletions(-) diff --git a/tests/system/test_pr01_repository_identity_truth.py b/tests/system/test_pr01_repository_identity_truth.py index aff71f02..9b382b11 100644 --- a/tests/system/test_pr01_repository_identity_truth.py +++ b/tests/system/test_pr01_repository_identity_truth.py @@ -29,6 +29,11 @@ def _load_script(relative: str, module_name: str): CANONICAL_REPOSITORY = "eimyroot/Voodoo-One" CANONICAL_REPOSITORY_URL = "https://github.com/eimyroot/Voodoo-One.git" +CURRENT_G0_SOURCE_SHA = "a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c" +CURRENT_G0_RUN = "34031128405" +CURRENT_G0_ARTIFACT_DIGEST = ( + "sha256:be646405590ac07f6293eaeb94a72c77ecf8ea02c16a31b31ccf93ef4ec92a2c" +) LEGACY_FETCH_ALIASES = frozenset( { "https://github.com/eimyroot/V-One.git", @@ -99,7 +104,10 @@ def test_governance_and_publication_docs_bind_current_repository_identity() -> N assert "repository = eimyroot/Voodoo-One" in governance assert "repository = nulleimy/V-One" not in governance - assert "fresh live G0 verification required" in governance + assert "Status: VERIFIED" in governance + assert CURRENT_G0_RUN in governance + assert CURRENT_G0_SOURCE_SHA in governance + assert CURRENT_G0_ARTIFACT_DIGEST in governance assert CANONICAL_REPOSITORY_URL in publication assert "fetch-only legacy alias" in publication @@ -119,24 +127,33 @@ def test_operations_runbook_uses_current_repo_and_artifact_derived_schema_truth( assert "current expected schema is 14" in runbook -def test_current_truth_does_not_promote_historical_g0_after_rename() -> None: +def test_current_truth_uses_fresh_exact_main_g0_and_preserves_history() -> None: state = _read("CURRENT_PRODUCT_STATE.md") capabilities = _read("docs/product/CURRENT_CAPABILITIES.md") readme = _read("README.md") assert "CANONICAL_REPOSITORY: eimyroot/Voodoo-One" in state - assert "G0_GITHUB_GOVERNANCE=UNKNOWN" in state - assert "G0 = UNKNOWN" in state + assert "G0_GITHUB_GOVERNANCE=PASS" in state + assert "G0 = PASS" in state + assert CURRENT_G0_RUN in state + assert CURRENT_G0_SOURCE_SHA in state + assert CURRENT_G0_ARTIFACT_DIGEST in state assert "historical_verdict = VERIFIED" in state assert "| Canonical repository | `eimyroot/Voodoo-One` |" in capabilities - assert "| Main GitHub governance policy | UNKNOWN |" in capabilities - assert "G0_LIVE_ENFORCEMENT_VERIFIED=UNKNOWN_CURRENT" in capabilities + assert "| Main GitHub governance policy | VERIFIED |" in capabilities + assert "G0_LIVE_ENFORCEMENT_VERIFIED=YES" in capabilities + assert CURRENT_G0_RUN in capabilities + assert CURRENT_G0_SOURCE_SHA in capabilities + assert CURRENT_G0_ARTIFACT_DIGEST in capabilities assert "historical_verdict = VERIFIED" in capabilities - assert ( - "| GitHub main governance enforcement | UNKNOWN / fresh post-rename G0 required; " - "historical VERIFIED evidence retained |" - ) in readme - assert "current G0 governance is therefore `UNKNOWN`" in readme - assert "historical G0 VERIFIED evidence is retained" in readme + assert "| GitHub main governance enforcement | VERIFIED / G0 PASS" in readme + assert CURRENT_G0_RUN in readme + assert CURRENT_G0_SOURCE_SHA in readme + assert CURRENT_G0_ARTIFACT_DIGEST in readme + assert "historical_verdict = VERIFIED" in readme + + assert "G0_GITHUB_GOVERNANCE=UNKNOWN" not in state + assert "G0_LIVE_ENFORCEMENT_VERIFIED=UNKNOWN_CURRENT" not in capabilities + assert "current G0 governance is therefore `UNKNOWN`" not in readme From 551b268b7d58f36964aca9b5cbc4c5a8ad21ad6a Mon Sep 17 00:00:00 2001 From: eimyroot Date: Sun, 6 Sep 2026 14:15:26 +0200 Subject: [PATCH 06/17] test(governance): enforce non-self-invalidating G0 truth --- .../test_pr01_repository_identity_truth.py | 67 ++++++++++++------- 1 file changed, 42 insertions(+), 25 deletions(-) diff --git a/tests/system/test_pr01_repository_identity_truth.py b/tests/system/test_pr01_repository_identity_truth.py index 9b382b11..fb95f6b7 100644 --- a/tests/system/test_pr01_repository_identity_truth.py +++ b/tests/system/test_pr01_repository_identity_truth.py @@ -29,9 +29,9 @@ def _load_script(relative: str, module_name: str): CANONICAL_REPOSITORY = "eimyroot/Voodoo-One" CANONICAL_REPOSITORY_URL = "https://github.com/eimyroot/Voodoo-One.git" -CURRENT_G0_SOURCE_SHA = "a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c" -CURRENT_G0_RUN = "34031128405" -CURRENT_G0_ARTIFACT_DIGEST = ( +LATEST_RETAINED_G0_SOURCE_SHA = "a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c" +LATEST_RETAINED_G0_RUN = "34031128405" +LATEST_RETAINED_G0_ARTIFACT_DIGEST = ( "sha256:be646405590ac07f6293eaeb94a72c77ecf8ea02c16a31b31ccf93ef4ec92a2c" ) LEGACY_FETCH_ALIASES = frozenset( @@ -104,10 +104,11 @@ def test_governance_and_publication_docs_bind_current_repository_identity() -> N assert "repository = eimyroot/Voodoo-One" in governance assert "repository = nulleimy/V-One" not in governance - assert "Status: VERIFIED" in governance - assert CURRENT_G0_RUN in governance - assert CURRENT_G0_SOURCE_SHA in governance - assert CURRENT_G0_ARTIFACT_DIGEST in governance + assert "latest retained G0 evidence" in governance.lower() + assert "CURRENT_LIVE_G0 = DERIVED / QUERY_ONLY" in governance + assert LATEST_RETAINED_G0_RUN in governance + assert LATEST_RETAINED_G0_SOURCE_SHA in governance + assert LATEST_RETAINED_G0_ARTIFACT_DIGEST in governance assert CANONICAL_REPOSITORY_URL in publication assert "fetch-only legacy alias" in publication @@ -127,33 +128,49 @@ def test_operations_runbook_uses_current_repo_and_artifact_derived_schema_truth( assert "current expected schema is 14" in runbook -def test_current_truth_uses_fresh_exact_main_g0_and_preserves_history() -> None: +def test_versioned_truth_uses_retained_g0_evidence_without_self_invalidating_current_pass() -> None: state = _read("CURRENT_PRODUCT_STATE.md") capabilities = _read("docs/product/CURRENT_CAPABILITIES.md") readme = _read("README.md") assert "CANONICAL_REPOSITORY: eimyroot/Voodoo-One" in state - assert "G0_GITHUB_GOVERNANCE=PASS" in state - assert "G0 = PASS" in state - assert CURRENT_G0_RUN in state - assert CURRENT_G0_SOURCE_SHA in state - assert CURRENT_G0_ARTIFACT_DIGEST in state + assert "LATEST_RETAINED_G0_VERDICT=VERIFIED" in state + assert "CURRENT_LIVE_G0=DERIVED_QUERY_ONLY" in state + assert LATEST_RETAINED_G0_RUN in state + assert LATEST_RETAINED_G0_SOURCE_SHA in state + assert LATEST_RETAINED_G0_ARTIFACT_DIGEST in state assert "historical_verdict = VERIFIED" in state assert "| Canonical repository | `eimyroot/Voodoo-One` |" in capabilities - assert "| Main GitHub governance policy | VERIFIED |" in capabilities - assert "G0_LIVE_ENFORCEMENT_VERIFIED=YES" in capabilities - assert CURRENT_G0_RUN in capabilities - assert CURRENT_G0_SOURCE_SHA in capabilities - assert CURRENT_G0_ARTIFACT_DIGEST in capabilities + assert "LATEST_RETAINED_G0_VERDICT=VERIFIED" in capabilities + assert "CURRENT_LIVE_G0=DERIVED_QUERY_ONLY" in capabilities + assert LATEST_RETAINED_G0_RUN in capabilities + assert LATEST_RETAINED_G0_SOURCE_SHA in capabilities + assert LATEST_RETAINED_G0_ARTIFACT_DIGEST in capabilities assert "historical_verdict = VERIFIED" in capabilities - assert "| GitHub main governance enforcement | VERIFIED / G0 PASS" in readme - assert CURRENT_G0_RUN in readme - assert CURRENT_G0_SOURCE_SHA in readme - assert CURRENT_G0_ARTIFACT_DIGEST in readme + assert "latest retained G0 evidence" in readme.lower() + assert "CURRENT_LIVE_G0=DERIVED_QUERY_ONLY" in readme + assert LATEST_RETAINED_G0_RUN in readme + assert LATEST_RETAINED_G0_SOURCE_SHA in readme + assert LATEST_RETAINED_G0_ARTIFACT_DIGEST in readme assert "historical_verdict = VERIFIED" in readme - assert "G0_GITHUB_GOVERNANCE=UNKNOWN" not in state - assert "G0_LIVE_ENFORCEMENT_VERIFIED=UNKNOWN_CURRENT" not in capabilities - assert "current G0 governance is therefore `UNKNOWN`" not in readme + forbidden_current_pass_claims = ( + "G0_GITHUB_GOVERNANCE=PASS", + "G0_LIVE_ENFORCEMENT_VERIFIED=YES", + "G0 = PASS", + "current G0 is PASS", + "Current G0 is VERIFIED", + ) + for claim in forbidden_current_pass_claims: + assert claim not in state + assert claim not in capabilities + assert claim not in readme + + +def test_release_candidate_requires_fresh_exact_checkout_g0() -> None: + workflow = _read(".github/workflows/release-candidate.yml") + assert "verify_github_main_governance.py" in workflow + assert "--expected-source-sha" in workflow + assert '"${GITHUB_SHA}"' in workflow From 4920e1f2a936ac3091dc95a7d57b850bd1a4c041 Mon Sep 17 00:00:00 2001 From: eimyroot Date: Sun, 6 Sep 2026 14:16:15 +0200 Subject: [PATCH 07/17] docs(governance): make G0 truth non-self-invalidating --- CURRENT_PRODUCT_STATE.md | 52 +++++++++++++++++++++------------------- 1 file changed, 28 insertions(+), 24 deletions(-) diff --git a/CURRENT_PRODUCT_STATE.md b/CURRENT_PRODUCT_STATE.md index 4e559d75..f3cc99d7 100644 --- a/CURRENT_PRODUCT_STATE.md +++ b/CURRENT_PRODUCT_STATE.md @@ -56,7 +56,7 @@ RELEASED / DEPLOYED = separately governed states | Restart-safe durable resume | **IMPLEMENTED / MERGED via PR #140** | | Runtime resume wiring | **IMPLEMENTED / MERGED via PR #140** | | G7 post-merge verification | **VERIFIED on `main@60bc9c268...` by CI #1015, D4 #202, E3 #193, E4B #189** | -| GitHub G0 governance | **VERIFIED / PASS on `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c` via run `34031128405`** | +| Latest retained GitHub G0 evidence | **VERIFIED for exact `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c` via run `34031128405`; current live G0 is query-only** | | Default provider runtime pack | **DISABLED / FAIL-CLOSED** | | Real canonical HTTP READ E2E using default G8 pack | **BLOCKED / NOT YET VERIFIED** | | Provider WRITE activation | **BLOCKED** | @@ -67,11 +67,12 @@ RELEASED / DEPLOYED = separately governed states | Deployment | **NOT PERFORMED** | | CyberCore | **BLOCKED pending product/release-governance hardening** | -## G0 GitHub governance — current vs historical evidence +## G0 GitHub governance — retained evidence vs live-derived truth -Current canonical repository identity is `eimyroot/Voodoo-One`. Fresh post-rename G0 evidence is now -retained for the exact repaired `main` SHA and independently verifies the current repository identity, -required-check provenance and live ruleset controls: +Current canonical repository identity is `eimyroot/Voodoo-One`. The latest retained post-rename G0 +evidence independently verified repository identity, required-check provenance and live ruleset controls +for exactly the SHA that it observed. This versioned document records that immutable evidence scope; it +does not promote the repository's moving current `main` to PASS by self-reference. ```text workflow = g0-governance-verify @@ -88,13 +89,19 @@ artifact = g0-governance-evidence-34031128405-1 artifact_id = 9988632821 artifact_digest = sha256:be646405590ac07f6293eaeb94a72c77ecf8ea02c16a31b31ccf93ef4ec92a2c checksum_validation = PASS -verdict = VERIFIED +retained_verdict = VERIFIED verified_at = 2026-09-06T11:45:16.520493Z ``` -The live verifier observed PR-only main, required `verify` from GitHub Actions workflow `ci`, latest-head +The verifier observed PR-only main, required `verify` from GitHub Actions workflow `ci`, latest-head strict checks, force-push disabled, branch deletion disabled, conversation resolution, no ordinary -admin/ruleset bypass, active rulesets and exact verifier-source binding. All required G0 checks were true. +admin/ruleset bypass, active rulesets and exact verifier-source binding. All required G0 checks were +true for that exact evidence scope. + +Current live G0 is deliberately not stored as a mutable-looking PASS/FAIL field in Git. It is derived +at decision time by comparing live `main` and live settings with fresh verifier evidence. Release-candidate +construction must run G0 against its exact checked-out `${GITHUB_SHA}` rather than reuse this retained +artifact as current authorization. The earlier retained artifact remains valid historical evidence for the repository identity and source SHA that existed when it ran: @@ -112,24 +119,18 @@ evidence_json_checksum = 11a99765485b63b70186037011d31c105dea8dd75b689e0036a8766 historical_verdict = VERIFIED ``` -Historical evidence stays historical; the current PASS is supported only by the fresh exact-main run -above. +Historical evidence stays historical. Neither retained run is silently promoted to proof for a later +`main` SHA. ```text -REPO_ENFORCEMENT_CONTRACT = VERIFIED -GITHUB_SETTINGS_ENFORCED = VERIFIED -MAIN_PR_ONLY = VERIFIED -REQUIRED_CI = VERIFIED -FORCE_PUSH_DISABLED = VERIFIED -BRANCH_DELETE_DISABLED = VERIFIED -CONVERSATION_RESOLUTION = VERIFIED -ORDINARY_ADMIN_BYPASS_DISABLED = VERIFIED -P0_GITHUB_GOVERNANCE = PASS -G0 = PASS +REPO_ENFORCEMENT_CONTRACT = IMPLEMENTED +LATEST_RETAINED_G0_VERDICT = VERIFIED +LATEST_RETAINED_G0_SOURCE_SHA = a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +CURRENT_LIVE_G0 = DERIVED_QUERY_ONLY +P0_GITHUB_GOVERNANCE = QUERY_LIVE_FOR_DECISION ``` -G0 PASS closes the current repository-governance blocker only. It does not authorize provider runtime, -release, deployment or production effects. +G0 evidence does not authorize provider runtime, release, deployment or production effects. ## Canonical shared authority/execution prefix @@ -326,13 +327,16 @@ This historical evidence does not authorize or prove any new provider mutation. - ADR-0018 records the R2 terminal-profile correction instead of silently rewriting older history. - PR #128 reconciliation remains historical provenance; later G7 evidence does not rewrite it. - Historical G0 run `32553113424` remains retained evidence for its original repository identity and exact source SHA. -- Current G0 run `34031128405` VERIFIED the renamed canonical repository at exact `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c`. +- Latest retained G0 run `34031128405` VERIFIED the renamed canonical repository at exact `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c`; current live G0 remains derived/query-only. ## Current release truth ```text VOODOO_ALLOW_PRODUCTION_EFFECTS=false -G0_GITHUB_GOVERNANCE=PASS +LATEST_RETAINED_G0_VERDICT=VERIFIED +LATEST_RETAINED_G0_SOURCE_SHA=a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +CURRENT_LIVE_G0=DERIVED_QUERY_ONLY +RELEASE_CANDIDATE_G0=FRESH_EXACT_CHECKOUT_REQUIRED G7_CANONICAL_READ_API=MERGED G7_RESTART_SAFE_RESUME=MERGED G8_DEFAULT_READ_RUNTIME=OFF From 89162495ecf8b1f507b84d42516db28ec1050ec0 Mon Sep 17 00:00:00 2001 From: eimyroot Date: Sun, 6 Sep 2026 14:17:00 +0200 Subject: [PATCH 08/17] docs(governance): describe G0 as retained evidence --- README.md | 30 ++++++++++++++++++++---------- 1 file changed, 20 insertions(+), 10 deletions(-) diff --git a/README.md b/README.md index e4754d27..cfbb2040 100644 --- a/README.md +++ b/README.md @@ -69,7 +69,7 @@ OperationProof != OperationCell | Canonical FastAPI ProductComposition runtime seam | IMPLEMENTED / MERGED; explicit runtime factory required, default provider pack disabled | | Canonical public READ operation API | IMPLEMENTED / MERGED via PR #137; reconciled with resume/runtime via PR #140 | | Restart-safe durable READ resume | IMPLEMENTED / MERGED via PR #140 | -| GitHub main governance enforcement | VERIFIED / G0 PASS on exact `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c`; historical evidence retained separately | +| GitHub governance evidence | latest retained G0 evidence VERIFIED for exact `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c`; current live G0 is derived/query-only | | Default provider runtime pack | BLOCKED / disabled until G8 | | Real canonical HTTP READ E2E through default G8 pack | BLOCKED / not yet verified | | Provider WRITE activation | BLOCKED pending repeated READ E2E + restart-safe verification gate | @@ -157,8 +157,8 @@ deployment, or release. ## G0 governance evidence -Fresh current live G0 evidence is retained for the renamed canonical repository and exact repaired -`main` SHA: +The repository records immutable G0 evidence scopes, not a self-updating `current main = PASS` claim. +The latest retained G0 evidence is: ```text workflow = g0-governance-verify @@ -168,12 +168,23 @@ artifact = g0-governance-evidence-34031128405-1 artifact_id = 9988632821 artifact_digest = sha256:be646405590ac07f6293eaeb94a72c77ecf8ea02c16a31b31ccf93ef4ec92a2c checksum_validation = PASS -verdict = VERIFIED +retained_verdict = VERIFIED ``` -The fresh run verified the current `eimyroot/Voodoo-One` identity, exact main/verifier source binding, +That run independently verified the renamed `eimyroot/Voodoo-One` repository, exact source binding, PR-only main, required `verify` from workflow `ci`, latest-head strict checks, force-push and deletion -disabled, conversation resolution, active rulesets and no ordinary bypass. +disabled, conversation resolution, active rulesets and no ordinary bypass for that exact SHA. + +```text +LATEST_RETAINED_G0_VERDICT=VERIFIED +LATEST_RETAINED_G0_SOURCE_SHA=a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +CURRENT_LIVE_G0=DERIVED_QUERY_ONLY +RELEASE_CANDIDATE_G0=FRESH_EXACT_CHECKOUT_REQUIRED +``` + +`CURRENT_LIVE_G0` must be derived from live GitHub state at decision time. A later commit changes +`main`, so this retained artifact cannot be reused as exact-current proof. The release-candidate +workflow therefore performs fresh G0 verification against its exact checked-out `${GITHUB_SHA}`. The repository also retains the earlier G0 artifact for its original evidence scope: @@ -186,9 +197,8 @@ artifact_digest = sha256:6e63caee23a57613471df66ef0279c0261ed8d375e4c929accdf50e historical_verdict = VERIFIED ``` -Historical evidence stays historical. Current G0 is PASS only because the fresh exact-main verifier -independently proved the renamed repository and live ruleset. G0 PASS never authorizes provider runtime, -release or deployment. +Historical evidence stays historical. G0 evidence never authorizes provider runtime, release or +deployment by itself. ## READ before WRITE @@ -236,7 +246,7 @@ a new provider mutation is authorized. - default G8 provider runtime and real product HTTP READ E2E remain blocked/unverified; - provider WRITE remains blocked behind READ-before-WRITE evidence and separate effect authorization; - no release/deployment inferred from CI, merge, Proof or Cell; -- current post-rename GitHub governance has fresh exact-main G0 VERIFIED evidence; historical G0 evidence remains separately scoped. +- latest retained G0 evidence is exact-SHA scoped; current live GitHub governance is queried/derived rather than versioned as PASS. ## Documentation From a4a3cbb44155ae065f9374f79b1c35767585fd96 Mon Sep 17 00:00:00 2001 From: eimyroot Date: Sun, 6 Sep 2026 14:17:47 +0200 Subject: [PATCH 09/17] docs(governance): separate retained G0 evidence from live truth --- .../GITHUB_MAIN_GOVERNANCE_BASELINE_V1.md | 37 ++++++++++++------- 1 file changed, 24 insertions(+), 13 deletions(-) diff --git a/docs/governance/GITHUB_MAIN_GOVERNANCE_BASELINE_V1.md b/docs/governance/GITHUB_MAIN_GOVERNANCE_BASELINE_V1.md index ad4e7a25..5bc8d41d 100644 --- a/docs/governance/GITHUB_MAIN_GOVERNANCE_BASELINE_V1.md +++ b/docs/governance/GITHUB_MAIN_GOVERNANCE_BASELINE_V1.md @@ -1,12 +1,12 @@ # GitHub Main Governance Baseline v1 -Status: VERIFIED — fresh exact-main G0 evidence retained for `eimyroot/Voodoo-One` +Status: ACTIVE CONTRACT — latest retained exact-main G0 evidence is recorded separately from current live truth ## Purpose Define the minimum GitHub repository enforcement required before higher-impact V-One authority, Grant Issuer, Runner, release, or production-capable work may rely on GitHub as a governance boundary. -Current live enforcement is VERIFIED only for the exact evidence scope recorded below. Remote enforcement must be re-verified independently after repository-identity, ruleset or required-check changes. +This document defines the contract and records immutable evidence scopes. It does not store a self-updating claim that the moving current `main` is VERIFIED. Current live G0 is derived by querying live GitHub state at decision time. ## Canonical protected branch @@ -47,7 +47,7 @@ Product/runtime rule `no requester self-approval` remains a separate V-One autho ## Required verification evidence -P0 is complete only when live GitHub configuration evidence proves the desired state. Acceptable evidence must include: +P0 is complete for a decision scope only when live GitHub configuration evidence proves the desired state on the exact SHA being evaluated. Acceptable evidence must include: ```text repository = eimyroot/Voodoo-One @@ -73,11 +73,11 @@ verified_at = source = GitHub live repository settings/API ``` -A repository document, CI pass, issue, PR description or previous observation is not sufficient evidence of GitHub-side enforcement. A repository rename or transfer changes the identity being verified: a historical G0 PASS for a different repository identity remains historical evidence and is not reusable as current G0 proof. +A repository document, CI pass, issue, PR description or previous observation is not sufficient evidence of GitHub-side enforcement. A repository rename, transfer, new commit, ruleset change or required-check change can make older evidence non-current without invalidating its historical scope. -## Current retained G0 evidence +## Latest retained G0 evidence -The current exact-main verification is: +The latest retained G0 evidence is immutable evidence for exactly the SHA it observed: ```text workflow = g0-governance-verify @@ -93,15 +93,24 @@ artifact = g0-governance-evidence-34031128405-1 artifact_id = 9988632821 artifact_digest = sha256:be646405590ac07f6293eaeb94a72c77ecf8ea02c16a31b31ccf93ef4ec92a2c checksum_validation = PASS -verdict = VERIFIED +retained_verdict = VERIFIED verified_at = 2026-09-06T11:45:16.520493Z ``` The evidence reported every required G0 check as true, including PR-only main, strict/latest-head required checks, GitHub Actions provider/workflow identity, force-push and branch deletion disabled, conversation resolution, complete bypass evidence with no ordinary bypass actor, active rulesets and -exact verifier-source binding. This evidence is current only for its exact scope; later relevant -GitHub/repository changes require fresh live G0 verification. +exact verifier-source binding for that exact SHA. + +This is intentionally **not** serialized as `current main = PASS` because committing such a statement +would change `main` and immediately make its own exact-SHA proof stale. + +```text +LATEST_RETAINED_G0_VERDICT = VERIFIED +LATEST_RETAINED_G0_SOURCE_SHA = a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +CURRENT_LIVE_G0 = DERIVED / QUERY_ONLY +RELEASE_CANDIDATE_G0 = FRESH_EXACT_CHECKOUT_REQUIRED +``` ## Machine verification @@ -180,7 +189,7 @@ Examples that are `BLOCKED` when evidence is otherwise complete: - PR-only flow, force-push blocking, deletion blocking or thread resolution is absent; - any bypass actor is configured. -Only `VERIFIED` exits successfully. `BLOCKED` and `UNKNOWN` fail closed. A historical PASS is not reusable proof after GitHub ruleset/settings configuration changes or repository-identity changes. +Only `VERIFIED` exits successfully. `BLOCKED` and `UNKNOWN` fail closed. A retained or historical PASS is not reusable proof for a different exact SHA or changed governance state. ## Credential boundary @@ -192,7 +201,7 @@ The dedicated token exists only because GitHub may omit sensitive `bypass_actors A release-candidate workflow is not allowed to produce an RC artifact unless the exact checked-out `main` SHA first produces G0 `VERIFIED`. The resulting `g0-governance-evidence.json` is included in the RC artifact and covered by `SHA256SUMS.txt` alongside the source archive and SBOM. -This gate does not itself authorize release or deployment. It only prevents release-candidate artifact construction from bypassing repository-governance evidence. +This gate does not reuse `LATEST_RETAINED_G0_VERDICT` as current authorization. It performs fresh exact-checkout verification. The gate does not itself authorize release or deployment. ## Failure semantics @@ -210,7 +219,7 @@ GITHUB_SETTINGS_ENFORCED = BLOCKED P0 = BLOCKED ``` -Never convert `UNKNOWN` or `BLOCKED` into `PASS` from documentation intent, CI success or branch metadata alone. +Never convert `UNKNOWN` or `BLOCKED` into `PASS` from documentation intent, CI success, retained evidence or branch metadata alone. ## Change path @@ -218,6 +227,8 @@ Changes to this baseline use a PR and must not reduce the controls above without ## Exit gate +For any specific evaluated SHA, a fresh G0 `VERIFIED` result requires: + ```text REPO_ENFORCEMENT_CONTRACT = VERIFIED GITHUB_SETTINGS_ENFORCED = VERIFIED @@ -235,4 +246,4 @@ ORDINARY_ADMIN_BYPASS_DISABLED = VERIFIED P0_GITHUB_GOVERNANCE = PASS ``` -Current fresh evidence satisfies the exit gate for exact `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c`. Later relevant repository or GitHub-governance changes require a new exact-main G0 observation rather than inference from this artifact. +The latest retained evidence satisfies that exit gate for exact `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c`. Whether a later current `main` satisfies it is a live-derived question and requires fresh exact-SHA evidence. From 13ca40c89c00fa54f48714abddc1a160e1c41937 Mon Sep 17 00:00:00 2001 From: eimyroot Date: Sun, 6 Sep 2026 14:18:48 +0200 Subject: [PATCH 10/17] docs(product): scope G0 evidence to exact SHA --- docs/product/CURRENT_CAPABILITIES.md | 39 ++++++++++++++++++---------- 1 file changed, 26 insertions(+), 13 deletions(-) diff --git a/docs/product/CURRENT_CAPABILITIES.md b/docs/product/CURRENT_CAPABILITIES.md index ed3f175b..7180eb73 100644 --- a/docs/product/CURRENT_CAPABILITIES.md +++ b/docs/product/CURRENT_CAPABILITIES.md @@ -92,12 +92,12 @@ Is it released/deployed? | Security Intelligence R-SI1.1 | IMPLEMENTED | metadata + tests | intelligence-only; no execution/proof authority | | Security Intelligence R-SI1.2 normalization | IMPLEMENTED | merged PR #135 | descriptive/context-only; no authority/runtime/effect widening | | CyberCore integration | BLOCKED | product/release-governance hardening | cannot bypass V-One gates | -| Main GitHub governance policy | VERIFIED | fresh G0 run `34031128405` on exact `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c`; artifact digest `sha256:be646405590ac07f6293eaeb94a72c77ecf8ea02c16a31b31ccf93ef4ec92a2c` | release/deploy remain separate gates | -| Main required latest-head enforcement | VERIFIED | fresh G0 verified PR-only main, required `verify` from `ci`, latest-head strict checks, no ordinary bypass, force-push/deletion disabled | later repository/ruleset changes require fresh live evidence for their own exact scope | +| Main GitHub governance evidence | VERIFIED | latest retained G0 run `34031128405` for exact `main@a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c`; artifact digest `sha256:be646405590ac07f6293eaeb94a72c77ecf8ea02c16a31b31ccf93ef4ec92a2c` | evidence is exact-SHA scoped; current live G0 is derived/query-only | +| Main required latest-head enforcement evidence | VERIFIED | retained G0 observed PR-only main, required `verify` from `ci`, latest-head strict checks, no ordinary bypass, force-push/deletion disabled | later `main` or governance changes require fresh live exact-SHA verification | | G8 default READ provider runtime | BLOCKED | G8 gate defined; no default runtime activation yet | must be READ-only, explicit, separate Runner/Verifier credentials, fail-closed | | Real canonical HTTP READ E2E + restart resume | BLOCKED | G7 components merged; G8 runtime not yet active | must prove HTTP→Runner→independent `VerificationResult/v1` plus no duplicate authority/effect after restart | | Provider WRITE activation | BLOCKED | ADR-0019 safety decision is under governed adoption | not eligible before verified repeated READ E2E + restart-safe continuity | -| Release-candidate build | VERIFIED | fail-closed workflow + historical image/SBOM checks; current G0 blocker closed by fresh exact-main evidence | build candidate != deployment; remaining release-candidate gates still apply | +| Release-candidate build | VERIFIED | fail-closed workflow + historical image/SBOM checks | every RC attempt must perform fresh G0 against its exact checked-out `${GITHUB_SHA}`; build candidate != deployment | | Unrestricted production release | BLOCKED | production effects default disabled | G8 + real READ E2E + security/legal/ops/release gates remain | | Public commercial distribution | BLOCKED | no distribution authorization | licensing/EULA/privacy/support and production gates remain separate | @@ -175,10 +175,11 @@ The runtime factory must share the exact ProductService database and permission- Without an explicit provider/runtime pack the default composition remains fail-closed. Workspace membership is a scope check, not activation of the separately PROPOSED Solo/Team/Regulated policy. -## G0 governance evidence — current vs historical +## G0 governance evidence — retained vs live-derived -Current canonical repository identity is `eimyroot/Voodoo-One`. Fresh post-rename G0 evidence is -retained for the exact repaired `main` SHA: +Current canonical repository identity is `eimyroot/Voodoo-One`. The repository records retained G0 +evidence only for the exact SHA that was observed; it does not serialize a moving `current main = PASS` +claim. ```text workflow = g0-governance-verify @@ -191,13 +192,24 @@ artifact = g0-governance-evidence-34031128405-1 artifact_id = 9988632821 artifact_digest = sha256:be646405590ac07f6293eaeb94a72c77ecf8ea02c16a31b31ccf93ef4ec92a2c checksum_validation = PASS -verdict = VERIFIED +retained_verdict = VERIFIED verified_at = 2026-09-06T11:45:16.520493Z ``` -The fresh evidence verifies PR-only main, required `verify` from GitHub Actions workflow `ci`, exact +The retained evidence verifies PR-only main, required `verify` from GitHub Actions workflow `ci`, exact workflow path `.github/workflows/ci.yml`, latest-head strict checks, force-push and deletion disabled, -conversation resolution, no ordinary bypass, active rulesets and exact source binding. +conversation resolution, no ordinary bypass, active rulesets and exact source binding for that SHA. + +```text +LATEST_RETAINED_G0_VERDICT=VERIFIED +LATEST_RETAINED_G0_SOURCE_SHA=a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +CURRENT_LIVE_G0=DERIVED_QUERY_ONLY +RELEASE_CANDIDATE_G0=FRESH_EXACT_CHECKOUT_REQUIRED +``` + +A later commit changes the exact current `main` identity. Therefore current G0 is derived from live +GitHub state at decision time, and release-candidate construction must run fresh G0 against its exact +checkout rather than infer current PASS from retained evidence. The earlier retained artifact remains VERIFIED historical evidence for the exact repository identity and source SHA that existed when it ran: @@ -214,9 +226,7 @@ evidence_json_checksum = 11a99765485b63b70186037011d31c105dea8dd75b689e0036a8766 historical_verdict = VERIFIED ``` -Historical evidence stays historical. Current G0 is VERIFIED only because the fresh exact-main run -independently proved the renamed repository and live controls. G0 never authorizes release/deploy by -itself. +Historical evidence stays historical. G0 never authorizes release/deploy by itself. ## Verified historical complete operation atom @@ -248,7 +258,10 @@ This is historical evidence for one real atom. It does not execute or authorize VOODOO_ALLOW_PRODUCTION_EFFECTS=false NEW_G7_PROVIDER_WRITE=NO NEW_A09_PROVIDER_MUTATION=NO -G0_LIVE_ENFORCEMENT_VERIFIED=YES +LATEST_RETAINED_G0_VERDICT=VERIFIED +LATEST_RETAINED_G0_SOURCE_SHA=a7e7c075dc44d61d4f7e8870cc3c0580ff290c2c +CURRENT_LIVE_G0=DERIVED_QUERY_ONLY +RELEASE_CANDIDATE_G0=FRESH_EXACT_CHECKOUT_REQUIRED G8_DEFAULT_PROVIDER_RUNTIME=OFF REAL_CANONICAL_READ_E2E_VERIFIED=NO WRITE_RUNTIME_GATE=BLOCKED From 387649f7749d40b93e2bbbab16f565ff4276e49c Mon Sep 17 00:00:00 2001 From: eimyroot Date: Sun, 6 Sep 2026 14:21:56 +0200 Subject: [PATCH 11/17] test(governance): fix retained-evidence assertions --- tests/system/test_pr01_repository_identity_truth.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/tests/system/test_pr01_repository_identity_truth.py b/tests/system/test_pr01_repository_identity_truth.py index fb95f6b7..5dd31c3d 100644 --- a/tests/system/test_pr01_repository_identity_truth.py +++ b/tests/system/test_pr01_repository_identity_truth.py @@ -104,7 +104,7 @@ def test_governance_and_publication_docs_bind_current_repository_identity() -> N assert "repository = eimyroot/Voodoo-One" in governance assert "repository = nulleimy/V-One" not in governance - assert "latest retained G0 evidence" in governance.lower() + assert "latest retained g0 evidence" in governance.lower() assert "CURRENT_LIVE_G0 = DERIVED / QUERY_ONLY" in governance assert LATEST_RETAINED_G0_RUN in governance assert LATEST_RETAINED_G0_SOURCE_SHA in governance @@ -149,7 +149,7 @@ def test_versioned_truth_uses_retained_g0_evidence_without_self_invalidating_cur assert LATEST_RETAINED_G0_ARTIFACT_DIGEST in capabilities assert "historical_verdict = VERIFIED" in capabilities - assert "latest retained G0 evidence" in readme.lower() + assert "latest retained g0 evidence" in readme.lower() assert "CURRENT_LIVE_G0=DERIVED_QUERY_ONLY" in readme assert LATEST_RETAINED_G0_RUN in readme assert LATEST_RETAINED_G0_SOURCE_SHA in readme From d352fd6f9be8008b440266803f044cff94ed7313 Mon Sep 17 00:00:00 2001 From: eimyroot Date: Sun, 6 Sep 2026 15:10:47 +0200 Subject: [PATCH 12/17] ci: trigger exact-head verification From a5cc549e1d89a2e6f0b54496ab87934eb7d6ceeb Mon Sep 17 00:00:00 2001 From: eimyroot Date: Sun, 6 Sep 2026 15:34:03 +0200 Subject: [PATCH 13/17] ci: trigger exact-head verification (user-authenticated) From 6e0aa5fd6923fa65ee1c2fb14d14e1962ac01491 Mon Sep 17 00:00:00 2001 From: Eimy Herrer <321177660+eimyroot@users.noreply.github.com> Date: Sun, 6 Sep 2026 15:43:59 +0200 Subject: [PATCH 14/17] ci: trigger exact-head verification From ce30329624640285c0359956820bec766bacb675 Mon Sep 17 00:00:00 2001 From: Eimy Herrer <321177660+eimyroot@users.noreply.github.com> Date: Sun, 6 Sep 2026 16:02:21 +0200 Subject: [PATCH 15/17] ci: exercise PR event dispatch --- README.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/README.md b/README.md index cfbb2040..e677bd82 100644 --- a/README.md +++ b/README.md @@ -338,3 +338,5 @@ Console: `http://127.0.0.1:8000/console` See [`SECURITY.md`](SECURITY.md), [`CONTRIBUTING.md`](CONTRIBUTING.md), and [`COMMERCIAL_READINESS.md`](docs/product/COMMERCIAL_READINESS.md). + + From c48608eccb9b22062649a01f74b460e0c6b95b91 Mon Sep 17 00:00:00 2001 From: Eimy Herrer <321177660+eimyroot@users.noreply.github.com> Date: Sun, 6 Sep 2026 16:02:50 +0200 Subject: [PATCH 16/17] Revert "ci: exercise PR event dispatch" This reverts commit ce30329624640285c0359956820bec766bacb675. --- README.md | 2 -- 1 file changed, 2 deletions(-) diff --git a/README.md b/README.md index e677bd82..cfbb2040 100644 --- a/README.md +++ b/README.md @@ -338,5 +338,3 @@ Console: `http://127.0.0.1:8000/console` See [`SECURITY.md`](SECURITY.md), [`CONTRIBUTING.md`](CONTRIBUTING.md), and [`COMMERCIAL_READINESS.md`](docs/product/COMMERCIAL_READINESS.md). - - From d108675dd41110f234bc4536c7eac92425c1d72d Mon Sep 17 00:00:00 2001 From: eimyroot Date: Fri, 11 Sep 2026 06:00:51 +0200 Subject: [PATCH 17/17] ci: retrigger canonical verification after Actions restore