Skip to content

Add GitHub self-governance: runtime authority, protected PR gates, docs, agents and TA updates - #18

Merged
blocksifrdev merged 2 commits into
mainfrom
codex/revise-ttp-integration-plan-for-agt-44i2le
Apr 18, 2026
Merged

blocksifrdev merged 2 commits into
mainfrom
codex/revise-ttp-integration-plan-for-agt-44i2le

Conversation

@blocksifrdev

Copy link
Copy Markdown
Collaborator

Motivation

  • Implement a starter reference for applying TTP to its own GitHub workflows so non-human role-agents are governed by a runtime authority before executing protected repo actions.
  • Provide operator and governance artifacts (policies, manifests, protected-path rules, CODEOWNERS) to define which paths and actions require step-up or escalation.
  • Ship a minimal local authority runtime and workflow skeletons to exercise /re/authorize flows in CI for protected PR merges.

Description

  • Add a lightweight runtime authority service and helper: services/authority/*, including receiptSigner, policyLoader, schemas, and an HTTP POST /re/authorize implementation that emits signed ExecutionReceipts.
  • Add a local authorizer script ./.github/scripts/ttp-local-authorize.mjs and GitHub Actions workflow skeletons ttp-protected-gate.yml and ttp-governed-pr-action.yml which call the local authority and enforce decisions (PERMIT|STEP_UP|ESCALATE|DENY).
  • Add governance/policy and agent manifests: policy/*.yaml, agents/* manifests and agents/manifests/role-agents.yaml to declare role-agents, protected paths, thresholds, and escalation rules.
  • Expand docs and onboarding: many new docs under docs/ (self-governance architecture, operator guide, getting-started, protected-action model, repo access control, public-readiness, roadmap, ecosystem integrations) and README/CONTRIBUTING/SECURITY updates to reflect repository self-governance and release controls.
  • Update reference trust authority: add unit tests aggregation.test.ts, enhancements to store.ts and routes.ts (admin GET /v1/admin/agents, metrics), crypto fixes for @noble/hashes usage, jest config, package.json deps, and TS config tweaks.
  • Add receipt schemas and execution-receipt v1/v2 schema extensions under receipts/schemas and spec/extensions and example/supporting files (runtime/api/re-authorize.contract.md, rfcs/0001-*).
  • Introduce CODEOWNERS entries for maintainers and protocol/security owners and an examples/acceptance test doc for protected workflow edits.

Testing

  • Added unit tests in reference-implementations/trust-authority/src/aggregation.test.ts exercising aggregateTrustScore and ran npm test in reference-implementations/trust-authority, and the test suite completed successfully.
  • CI job skeleton /.github/workflows/ci.yml is provided to run npm install, npm run build, and npm test for the Trust Authority package on PRs and pushes.
  • The new GitHub workflow skeletons were exercised locally in integration by invoking node .github/scripts/ttp-local-authorize.mjs from workflow steps in the repository examples (used in the protected gate and governed PR action steps).

Codex Task

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3f9faba4ab

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +260 to +264
"workflowRunId": "${{ github.run_id }}",
"attestationRef": "att-pr-${{ github.run_id }}-reauth",
"authorityGrantRef": "grant-pr-${{ github.run_id }}",
"priorReceiptId": "${{ needs.protected-action-gate.outputs.receipt_id }}",
"approval": {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Include freshnessSeconds in reauthorization request

The reauthorization payload never sets freshnessSeconds, but .github/scripts/ttp-local-authorize.mjs defaults missing freshness to 9999 and returns ESCALATE for merge request reauthorize when freshness is over 900. In protected-path PRs this means step-up-approval can succeed but reauthorize-after-step-up still cannot produce PERMIT, so merge-authority consistently blocks merges.

Useful? React with 👍 / 👎.

Comment on lines +136 to +137
if (req.method === "POST" && url.pathname === "/re/authorize") {
const body = await parseBody(req) as AuthorizeRequest

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Catch JSON parse errors on /re/authorize

parseBody(req) is awaited without a try/catch, so malformed JSON causes a rejected promise inside the HTTP request handler instead of a controlled 4xx response. In Node HTTP servers this can leave the request unresolved and surface as an unhandled rejection, which is an availability issue for a public authorization endpoint.

Useful? React with 👍 / 👎.

}

function decide(req: AuthorizeRequest, protectedPaths: string[]): { decision: Decision; reason: string; context: DecisionContext } {
const protectedAction = req.pathsTouched.some(p => isProtectedPath(p, protectedPaths))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Validate pathsTouched before using .some()

The decision path calls req.pathsTouched.some(...) before any runtime validation of request shape. A syntactically valid request with pathsTouched omitted or non-array will throw TypeError, bypassing policy evaluation and returning no proper authorization decision, which can crash or destabilize this handler under malformed input.

Useful? React with 👍 / 👎.

@blocksifrdev
blocksifrdev merged commit cdba2c7 into main Apr 18, 2026
2 of 3 checks passed
@blocksifrdev
blocksifrdev deleted the codex/revise-ttp-integration-plan-for-agt-44i2le branch April 18, 2026 19:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant