Skip to content

Add GitHub self‑governance docs, workflows, agent manifests, and Trust Authority updates - #15

Merged
blocksifrdev merged 3 commits into
mainfrom
codex/revise-ttp-integration-plan-for-agt-alfao1
Apr 18, 2026
Merged

blocksifrdev merged 3 commits into
mainfrom
codex/revise-ttp-integration-plan-for-agt-alfao1

Conversation

@blocksifrdev

Copy link
Copy Markdown
Collaborator

Motivation

  • Introduce a reference architecture to apply TTP runtime authority gating to repository operations so non-human role-agents can be governed with explicit decisions and auditable receipts.
  • Define protected actions/paths and policies so high-risk edits (workflows, policy, core runtime code) require step-up/escalation or a signed ExecutionReceipt.
  • Seed operational readiness for a public release by adding CODEOWNERS, CI, onboarding docs, and operator/runbook material.

Description

  • Add GitHub self-governance design and reference implementation artifacts, including docs/github-self-governance-reference-architecture.md, runtime/api/re-authorize.contract.md, spec/extensions/execution-receipt-v2.schema.json, and related policy files under policy/ and receipts/ to capture decision semantics and receipt schema.
  • Add role-agent manifests and agent manifests (agents/*) and a policy/github-self-governance-policy.yaml plus protected-action definitions to model machine identities and allowed/forbidden actions.
  • Add GitHub Actions workflow skeletons: ttp-protected-gate.yml (protected PR gate), ttp-governed-pr-action.yml (slash-command governed action), and a CI job ci.yml to build/test the Trust Authority reference.
  • Extend the Trust Authority reference implementation with tests and runtime changes: added unit tests aggregation.test.ts, jest.config.cjs, package.json deps/devDeps, tsconfig.json adjustments, crypto.ts sha512 usage fix, new admin endpoint GET /v1/admin/agents, store methods (listAgents, getAgentReceiptsAcrossDomains), and small runtime/admin utilities to support the new governance flow.
  • Add multiple onboarding and governance docs (README updates, CONTRIBUTING.md, SECURITY.md, docs/*, examples/*, rfcs/0001-*) and a CODEOWNERS file to require reviews for critical paths.

Testing

  • Unit tests were added under reference-implementations/trust-authority/src/aggregation.test.ts and run via npm test (Jest) in the Trust Authority package, and they passed.
  • A CI workflow (.github/workflows/ci.yml) is included to run npm install, npm run build, and npm test for the reference Trust Authority on PRs and pushes.

Codex Task

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 81689e1b13

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +65 to +67
if [ "$DECISION" != "PERMIT" ]; then
echo "Fail-closed: decision=$DECISION receipt=$RECEIPT"
exit 1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Keep step-up job runnable when decision is non-PERMIT

The gate step exits with exit 1 for STEP_UP/ESCALATE, but both follow-on jobs use needs: [protected-action-gate]; in GitHub Actions, a failed needed job causes dependents to be skipped unless they use an always() status check. As written, the environment-backed step-up-approval path never runs when it is actually required, so protected changes are hard-failed instead of entering the intended human approval flow.

Useful? React with 👍 / 👎.

-d @request.json > decision.json

DECISION=$(jq -r '.decision' decision.json)
RECEIPT=$(jq -r '.receiptId' decision.json)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Extract receipt ID using the documented response shape

This workflow reads receiptId from the authorization response, but the repository’s runtime contract documents the receipt identifier at receipt.receipt_id (runtime/api/re-authorize.contract.md). When wired to a contract-compliant authority, jq -r '.receiptId' yields null, and the downstream receipt-required check can still pass because "null" is non-empty, effectively bypassing receipt-presence enforcement.

Useful? React with 👍 / 👎.

}

if (req.method === "POST" && url.pathname === "/re/authorize") {
const body = await parseBody(req) as AuthorizeRequest

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Handle JSON parse failures in /re/authorize

The handler awaits parseBody(req) without a try/catch, so malformed JSON causes a rejected promise that is never converted into an HTTP error response. In Node’s default unhandled-rejection mode this can terminate the process, making a single invalid request to /re/authorize a denial-of-service for the authority service.

Useful? React with 👍 / 👎.

@blocksifrdev
blocksifrdev merged commit 968ab09 into main Apr 18, 2026
2 of 3 checks passed
@blocksifrdev
blocksifrdev deleted the codex/revise-ttp-integration-plan-for-agt-alfao1 branch April 18, 2026 20:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant