Introduce GitHub self‑governance (TTP governing TTP): docs, policies, workflows, agents, and TA updates - #16
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0ce58d9962
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| } | ||
|
|
||
| if (req.method === "POST" && url.pathname === "/re/authorize") { | ||
| const body = await parseBody(req) as AuthorizeRequest |
There was a problem hiding this comment.
Catch JSON parse errors in /re/authorize handler
parseBody rejects on invalid JSON, but the /re/authorize route awaits it without a try/catch, so a malformed request triggers an unhandled exception in the async HTTP handler and can terminate the process instead of returning a 4xx error. Any client sending invalid JSON can take down this authority service instance.
Useful? React with 👍 / 👎.
| } | ||
|
|
||
| function decide(req: AuthorizeRequest, protectedPaths: string[]): { decision: Decision; reason: string; context: DecisionContext } { | ||
| const protectedAction = req.pathsTouched.some(p => isProtectedPath(p, protectedPaths)) |
There was a problem hiding this comment.
Validate
pathsTouched before calling .some
The request body is cast to AuthorizeRequest with no runtime validation, so if pathsTouched is missing or not an array, this .some(...) call throws a TypeError; in the current async server callback that exception is uncaught and can crash the service. Invalid/malformed caller payloads should be handled as a normal deny/400 path instead of process-fatal errors.
Useful? React with 👍 / 👎.
| if [ "$DECISION" != "PERMIT" ]; then | ||
| echo "Fail-closed: decision=$DECISION receipt=$RECEIPT" | ||
| exit 1 |
There was a problem hiding this comment.
Keep gate job successful for STEP_UP/ESCALATE outcomes
Failing protected-action-gate for every non-PERMIT decision prevents the downstream step-up-approval job from running because it depends on this job via needs, so manual approval/escalation paths are effectively unreachable. This makes STEP_UP/ESCALATE behave like hard-deny instead of entering the intended approval flow.
Useful? React with 👍 / 👎.
|
@copilot resolve the merge conflicts in this pull request |
Motivation
Description
docs/github-self-governance-reference-architecture.md,docs/github-self-governance.md,runtime/api/re-authorize.contract.md, RFCrfcs/0001-github-self-governance-role-agents.md, and supporting docs (docs/*,spec/extensions/*,docs/open-source-boundary.md,docs/public-readiness.md,docs/repo-access-control.md,docs/getting-started.md,docs/operator-guide.md, etc.).policy/*.yaml,policy/protected-actions.yaml,policy/trust-thresholds.yaml, andreceipts/schemas/execution-receipt.v1.jsonplusspec/extensions/execution-receipt-v2.schema.jsonto define execution receipts and protected paths.agents/to describe workload identities and allowed actions for AI role‑agents (e.g.agents/manifests/role-agents.yaml,agents/*/manifest.json)./.github/CODEOWNERS,/.github/workflows/ci.yml,/.github/workflows/ttp-protected-gate.yml, and/.github/workflows/ttp-governed-pr-action.ymlto show how to call a Runtime Authority (POST /re/authorize) and enforce decisions in workflows.services/authority/including a simplePOST /re/authorizeimplementation, receipt signing/chain hashing, policy loader, and schemas to exercise the reference model.jest.config.cjs), an aggregation unit test (src/aggregation.test.ts), package updates (package.json), TS config tweaks, store/router changes exposingGET /v1/admin/agentsand metrics, helpersgetAgentReceiptsAcrossDomains, and small fixes to@noble/ed25519SHA-512 usage incrypto.ts,index.ts, and keygen script.Testing
reference-implementations/trust-authority/src/aggregation.test.tsand executednpm testin thereference-implementations/trust-authoritypackage which passed locally.CI -> trust-authority(.github/workflows/ci.yml) configured to runnpm install,npm run build, andnpm testfor the trust authority; the workflow template is included to run these checks onpushandpull_requestevents.services/authorityexercisedPOST /re/authorizeflows and receipt generation during development (prototype behavior exercised successfully).Codex Task