Skip to content

Add GitHub self‑governance/workflow gates, agent manifests, docs, CODEOWNERS, and trust‑authority tests - #17

Merged
blocksifrdev merged 2 commits into
mainfrom
codex/revise-ttp-integration-plan-for-agt-fdggdd
Apr 18, 2026
Merged

blocksifrdev merged 2 commits into
mainfrom
codex/revise-ttp-integration-plan-for-agt-fdggdd

Conversation

@blocksifrdev

Copy link
Copy Markdown
Collaborator

Motivation

  • Establish a self‑governance reference for applying TTP to GitHub actions by gating meaningful non‑human actions through a Runtime Authority (POST /re/authorize) and requiring auditable receipts.
  • Provide secure repo access and review controls for protocol/security‑critical paths via CODEOWNERS and related repo access guidance.
  • Seed operator and integration documentation, policies, and role‑agent manifests to enable safe rollout and adoption.
  • Harden and test the reference Trust Authority implementation with unit tests and CI to improve release readiness.

Description

  • Add GitHub governance artifacts: a global CODEOWNERS, two workflow skeletons (.github/workflows/ttp-protected-gate.yml, .github/workflows/ttp-governed-pr-action.yml) and a CI job (.github/workflows/ci.yml) that builds and tests the trust‑authority reference.
  • Add a comprehensive set of docs and policies under docs/, policy/, spec/extensions/, receipts/schemas/ and new README/CONTRIBUTING/SECURITY updates to document self‑governance, operator guides, open‑source boundary, and public‑readiness.
  • Introduce role/agent manifests and agent descriptors under agents/ (multiple manifest.json and role-agents.yaml) to model workload identities and allowed actions for AI role‑agents.
  • Add a starter Authority service (services/authority/) that implements POST /re/authorize, receipt signing/chain hashing, policy loader, and example decision logic and schemas.
  • Update the reference Trust Authority: add tests (src/aggregation.test.ts), jest config, package.json dev deps, tsconfig adjustments, API extension GET /v1/admin/agents, in‑memory store helpers (listAgents, getAgentReceiptsAcrossDomains), and multiple small crypto/sha512 sync fixes.
  • Provide example workflows, acceptance tests and RFCs for the GitHub self‑governance model and a trimmed, implemented version of the ttp-language docs to match repository semantics.

Testing

  • Added unit tests: reference-implementations/trust-authority/src/aggregation.test.ts which exercise aggregateTrustScore behavior (windowing, issuer weight cap, metadata outputs).
  • Configured CI job CI (.github/workflows/ci.yml) to run npm install, npm run build, and npm test in reference-implementations/trust-authority; the job is wired to run on push/pull_request.
  • The new aggregation unit tests were executed (npm test / jest) as part of validation and passed (aggregation behavior and cap logic succeeded).

Codex Task

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: eb0ff11c05

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +136 to +138
if (req.method === "POST" && url.pathname === "/re/authorize") {
const body = await parseBody(req) as AuthorizeRequest
const { decision, reason, context } = decide(body, protectedPaths)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Enforce bearer auth before processing authorization requests

The /re/authorize handler processes and signs decisions without checking the Authorization header, so any caller that can reach this service can obtain valid receipts (including PERMIT for non-critical actions) and pollute the receipt chain. This is a security boundary issue because the workflows already assume token-gated access via RUNTIME_AUTH_TOKEN, but the service currently ignores that trust boundary entirely.

Useful? React with 👍 / 👎.

Comment on lines +84 to +88
if (!(prior.decision === "STEP_UP" || prior.decision === "ESCALATE")) {
return { decision: "DENY", reason: "prior_decision_not_reauthorizable", context }
}
if (!req.approval?.approved || !req.approval.approvedBy) {
return { decision: "DENY", reason: "step_up_approval_missing", context }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Validate reauth targets match the prior receipt context

Reauthorization only checks that the prior receipt exists and had STEP_UP/ESCALATE, then permits on generic approval/freshness checks; it never verifies that the new request matches the prior receipt’s repo/resource/commit/action scope. This allows reusing a step-up receipt from one change to authorize a different change, which breaks the intended step-up security model.

Useful? React with 👍 / 👎.

}

if (req.method === "POST" && url.pathname === "/re/authorize") {
const body = await parseBody(req) as AuthorizeRequest

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Handle JSON parse failures in /re/authorize requests

The route awaits parseBody(req) without a try/catch, but parseBody rejects on malformed JSON; in that case the request never gets a structured error response and can surface as an unhandled rejection. A single malformed client payload can therefore cause request hangs and potentially destabilize the process depending on runtime unhandled-rejection settings.

Useful? React with 👍 / 👎.

@blocksifrdev
blocksifrdev merged commit 0352f9b into main Apr 18, 2026
2 of 3 checks passed
@blocksifrdev
blocksifrdev deleted the codex/revise-ttp-integration-plan-for-agt-fdggdd branch April 18, 2026 14:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant