Repository navigation
fix: bind staged portfolio truth to manifest receipt identity - #276
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
New portfolio generation publication checks the security receipt ID and content SHA in the staged truth artifact against the admitted manifest binding before making the release visible.
Why
A valid receipt pair could replace A with B before publisher admission. The publisher then accepted and selected a bundle whose truth named A while its manifest named B, even though every artifact hash matched. The new check refuses that disagreement, missing or malformed identities, and incompatible truth contracts.
Review Of What Was Built
The gate validates the bytes in the staged generation. Correct publication is exercised with the actual upstream truth builder and strict canonical validator. Companion digest files are explicitly synthetic opaque artifacts; decision-digest semantics remain in their own tests. The CLI tests cover unchanged A, B before admission, B after admission, and a mismatched receipt/terminal pair. Existing history remains readable through new publication, rollback, and roll-forward.
Cleanup Review
The manifest and pointer schemas, historical verifier, public function signatures, and later live receipt guard remain unchanged. This is a publication identity repair; full truth validation stays with the upstream producer.
Verification Summary
Shipped Summary
A new generation cannot be selected with truth and manifest disagreeing on the admitted security receipt identity. Correct identity remains publishable. These are source and offline fixture results; scheduled runtime activation is not part of this change.
Next Phase
Controlled activation under the operator release contract is a separate deployment task. It should preserve existing receipt and generation history and verify the activated producer revision before any scheduled-run claim.
Remaining Roadmap
No additional implementation is required for this bounded repair.