Repository navigation
Add GitHub self‑governance docs, workflows, agent manifests, and Trust Authority updates - #15
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 81689e1b13
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if [ "$DECISION" != "PERMIT" ]; then | ||
| echo "Fail-closed: decision=$DECISION receipt=$RECEIPT" | ||
| exit 1 |
There was a problem hiding this comment.
Keep step-up job runnable when decision is non-PERMIT
The gate step exits with exit 1 for STEP_UP/ESCALATE, but both follow-on jobs use needs: [protected-action-gate]; in GitHub Actions, a failed needed job causes dependents to be skipped unless they use an always() status check. As written, the environment-backed step-up-approval path never runs when it is actually required, so protected changes are hard-failed instead of entering the intended human approval flow.
Useful? React with 👍 / 👎.
| -d @request.json > decision.json | ||
|
|
||
| DECISION=$(jq -r '.decision' decision.json) | ||
| RECEIPT=$(jq -r '.receiptId' decision.json) |
There was a problem hiding this comment.
Extract receipt ID using the documented response shape
This workflow reads receiptId from the authorization response, but the repository’s runtime contract documents the receipt identifier at receipt.receipt_id (runtime/api/re-authorize.contract.md). When wired to a contract-compliant authority, jq -r '.receiptId' yields null, and the downstream receipt-required check can still pass because "null" is non-empty, effectively bypassing receipt-presence enforcement.
Useful? React with 👍 / 👎.
| } | ||
|
|
||
| if (req.method === "POST" && url.pathname === "/re/authorize") { | ||
| const body = await parseBody(req) as AuthorizeRequest |
There was a problem hiding this comment.
Handle JSON parse failures in /re/authorize
The handler awaits parseBody(req) without a try/catch, so malformed JSON causes a rejected promise that is never converted into an HTTP error response. In Node’s default unhandled-rejection mode this can terminate the process, making a single invalid request to /re/authorize a denial-of-service for the authority service.
Useful? React with 👍 / 👎.
Motivation
ExecutionReceipt.Description
docs/github-self-governance-reference-architecture.md,runtime/api/re-authorize.contract.md,spec/extensions/execution-receipt-v2.schema.json, and related policy files underpolicy/andreceipts/to capture decision semantics and receipt schema.agents/*) and apolicy/github-self-governance-policy.yamlplus protected-action definitions to model machine identities and allowed/forbidden actions.ttp-protected-gate.yml(protected PR gate),ttp-governed-pr-action.yml(slash-command governed action), and a CI jobci.ymlto build/test the Trust Authority reference.aggregation.test.ts,jest.config.cjs,package.jsondeps/devDeps,tsconfig.jsonadjustments,crypto.tssha512 usage fix, new admin endpointGET /v1/admin/agents, store methods (listAgents,getAgentReceiptsAcrossDomains), and small runtime/admin utilities to support the new governance flow.CONTRIBUTING.md,SECURITY.md,docs/*,examples/*,rfcs/0001-*) and aCODEOWNERSfile to require reviews for critical paths.Testing
reference-implementations/trust-authority/src/aggregation.test.tsand run vianpm test(Jest) in the Trust Authority package, and they passed..github/workflows/ci.yml) is included to runnpm install,npm run build, andnpm testfor the reference Trust Authority on PRs and pushes.Codex Task