Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 10 additions & 9 deletions RELEASING.md
Original file line number Diff line number Diff line change
Expand Up @@ -213,20 +213,21 @@ passing evidence record for each target.

The frozen Chat production source
`0da8c4749f57e63601b29d66032f80c9bbac1cb5` is selected by merged
Chat #240 producer `8d17c173aa00310755fe912c66d4d3ba088296c4`, pinning executable
harness `4ca05443866131c655169dea088158095f2df9f2` and merged Cave
Chat #239 producer `43e821689cc22e58b424c59b90981379fb16a6a8`, pinning executable
harness `87ce946b0d9c7f05ccad2e23b2e1a7b18e9682f2` and merged Cave
OpenCoven/coven-cave#5378 at
`cb3d22d1f403dd3b94b02668a599a2bf94999e8b`. Exact-head Chat CI run
`34707682406` passed its applicable checks. The merge retains the immutable
`34710284258` passed all checks. The merge retains the immutable
harness source ancestry.

The conformance-only token-profile safety probe reports fixed follow-up
categories after an initial unsafe discovery response. Owner-only and
combined owner/ACL failures remain distinct. Follow-up observations do not
capture the original read and never authorize launch. Existing discovery
trust, quota, assertion and dependency policies remain unchanged. This is a
diagnostic-only rebind; native protected validation and release acceptance
remain outstanding.
categories after an initial unsafe discovery response and never authorizes
launch. The Windows reader now accepts the OS-managed profile root when its
owner is the restricted user, LocalSystem, or builtin Administrators and only
those trusted principals can write it. Application-owned discovery paths
still require restricted-user ownership. Reparse, identity, replacement,
size, process, quota, assertion, and dependency checks remain fail closed.
Fresh protected validation and release acceptance remain outstanding.

The Windows reader retains the validated isolated token for synchronous quota
scans, including terminal accounting after account disablement. Private ACLs
Expand Down
8 changes: 4 additions & 4 deletions conformance/client-v1-cross-repository-lock.json
Original file line number Diff line number Diff line change
Expand Up @@ -165,8 +165,8 @@
"evidenceProducer": {
"status": "compatible",
"repository": "OpenCoven/chat",
"commit": "8d17c173aa00310755fe912c66d4d3ba088296c4",
"tree": "6c77f90769f77c5f3477956b9c0d380bbad17692",
"commit": "43e821689cc22e58b424c59b90981379fb16a6a8",
"tree": "a7cd7ba6a784ded8afb34d68780475dbdcd928ec",
"packageManifest": {
"path": "package.json",
"size": 4044,
Expand Down Expand Up @@ -249,8 +249,8 @@
]
},
"signerWorkflow": "OpenCoven/chat/.github/workflows/client-v1-conformance.yml",
"signerDigest": "8d17c173aa00310755fe912c66d4d3ba088296c4",
"sourceDigest": "8d17c173aa00310755fe912c66d4d3ba088296c4",
"signerDigest": "43e821689cc22e58b424c59b90981379fb16a6a8",
"sourceDigest": "43e821689cc22e58b424c59b90981379fb16a6a8",
"predicateType": "https://slsa.dev/provenance/v1",
"denySelfHostedRunners": true
}
Expand Down
21 changes: 11 additions & 10 deletions docs/workflows/client-v1-cross-repository-conformance.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,20 +27,21 @@ publication primitives needed to support the aggregator safely on Windows.
There is no passing aggregate in this repository yet. The SDK candidate remains
`1597835325cf3762b51408ff0a565037eeb25f64`, with frozen Chat production
`0da8c4749f57e63601b29d66032f80c9bbac1cb5` and its reviewed native deltas.
This binding selects merged Chat #240 producer `8d17c173aa00310755fe912c66d4d3ba088296c4`, pinning executable
harness `4ca05443866131c655169dea088158095f2df9f2` and merged Cave
This binding selects merged Chat #239 producer `43e821689cc22e58b424c59b90981379fb16a6a8`, pinning executable
harness `87ce946b0d9c7f05ccad2e23b2e1a7b18e9682f2` and merged Cave
OpenCoven/coven-cave#5378 at
`cb3d22d1f403dd3b94b02668a599a2bf94999e8b`. Exact-head Chat CI run
`34707682406` passed its applicable checks. The merge retains the immutable
`34710284258` passed all checks. The merge retains the immutable
harness source ancestry.

The conformance-only token-profile safety probe reports fixed follow-up
categories after an initial unsafe discovery response. Owner-only and
combined owner/ACL failures remain distinct. Follow-up observations do not
capture the original read and never authorize launch. Existing discovery
trust, quota, assertion and dependency policies remain unchanged. This is a
diagnostic-only rebind; native protected validation and release acceptance
remain outstanding.
categories after an initial unsafe discovery response and never authorizes
launch. The Windows reader now accepts the OS-managed profile root when its
owner is the restricted user, LocalSystem, or builtin Administrators and only
those trusted principals can write it. Application-owned discovery paths
still require restricted-user ownership. Reparse, identity, replacement,
size, process, quota, assertion, and dependency checks remain fail closed.
Fresh protected validation and release acceptance remain outstanding.

The validator must merge and both protected scopes must be rotated before a
fresh protected run.
Expand Down Expand Up @@ -404,7 +405,7 @@ aggregation job has no permissions and can only confirm successful completion
of the protected matrix; it cannot generate, upload, attest, or replace a
platform record. This structural template is exercised synthetically in tests
only. The committed lock marks the reachable Chat producer at
`8d17c173aa00310755fe912c66d4d3ba088296c4` compatible with the reviewed
`43e821689cc22e58b424c59b90981379fb16a6a8` compatible with the reviewed
schema-v2 workflow bytes. Release readiness remains blocked until this SDK
validator merges, `CLIENT_V1_CONFORMANCE_VALIDATOR_REVISION` is rotated to the
merged revision, and all three protected platform records and their GitHub
Expand Down
4 changes: 2 additions & 2 deletions tests/conformance-contract.spec.ts
Original file line number Diff line number Diff line change
Expand Up @@ -215,7 +215,7 @@ describe('cross-repository conformance contract entrypoints', () => {
'utf8',
);
expect(workflowDocument).toContain(
'8d17c173aa00310755fe912c66d4d3ba088296c4',
'43e821689cc22e58b424c59b90981379fb16a6a8',
);
expect(workflowDocument).not.toContain(
'f6eba8af1f71d4251583cf39d4e5fb5b4797d209',
Expand All @@ -230,7 +230,7 @@ describe('cross-repository conformance contract entrypoints', () => {
'9f073f05241c2d3241b23ed9d73b26c6cd55ce7e',
);
expect(workflowDocument).toContain(
'4ca05443866131c655169dea088158095f2df9f2',
'87ce946b0d9c7f05ccad2e23b2e1a7b18e9682f2',
);
expect(workflowDocument).toContain('validator_revision');
expect(workflowDocument).toContain('20863036831');
Expand Down
8 changes: 4 additions & 4 deletions tests/conformance-gaps.spec.ts
Original file line number Diff line number Diff line change
Expand Up @@ -1770,8 +1770,8 @@ describe('unresolved SDK #38 conformance gaps', () => {
expect(lock.evidenceProducer).toEqual({
status: 'compatible',
repository: 'OpenCoven/chat',
commit: '8d17c173aa00310755fe912c66d4d3ba088296c4',
tree: '6c77f90769f77c5f3477956b9c0d380bbad17692',
commit: '43e821689cc22e58b424c59b90981379fb16a6a8',
tree: 'a7cd7ba6a784ded8afb34d68780475dbdcd928ec',
packageManifest: {
path: 'package.json',
size: 4_044,
Expand Down Expand Up @@ -1848,8 +1848,8 @@ describe('unresolved SDK #38 conformance gaps', () => {
},
signerWorkflow:
'OpenCoven/chat/.github/workflows/client-v1-conformance.yml',
signerDigest: '8d17c173aa00310755fe912c66d4d3ba088296c4',
sourceDigest: '8d17c173aa00310755fe912c66d4d3ba088296c4',
signerDigest: '43e821689cc22e58b424c59b90981379fb16a6a8',
sourceDigest: '43e821689cc22e58b424c59b90981379fb16a6a8',
predicateType: 'https://slsa.dev/provenance/v1',
denySelfHostedRunners: true,
},
Expand Down