Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 12 additions & 5 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
# catch-all.

#
# WHY THESE PATHS NAME TWO OWNERS AND NOT ONE.
# WHY THESE PATHS NAME TWO ACCOUNTS AND NOT ONE.
#
# They named only @0j0bit until 2026-09-12. That deadlocks: GitHub does not let
# anyone approve their own pull request, and the branch ruleset grants no
Expand All @@ -18,10 +18,17 @@
# change to hit it would have been the one recording rows 27 and 37, which
# touches /governance/ and /releases/.
#
# Both named accounts have write access, which a code owner must have to count.
# These lines currently resolve to the same two people as the catch-all, so
# their present effect is documentary: they record which paths are authorities.
# If the catch-all ever widens, they narrow again on their own.
# @0j0bit and @sed-boi are two GitHub accounts controlled by the SAME project
# owner. Either account may satisfy the code-owner review requirement for a
# change it did not author -- in practice, changes proposed by the
# mcl-release-governor App and reviewed as @0j0bit. This is account redundancy,
# NOT independent two-person review, and nothing here claims separation of
# duties.
#
# Both accounts have write access, which a code owner must have to count. The
# path lines below name the same accounts as the catch-all, so their present
# effect is documentary: they record which paths are authorities. If the
# catch-all ever widens, they narrow again on their own.

* @0j0bit @sed-boi

Expand Down
16 changes: 16 additions & 0 deletions conformance/independent/20260913-public-candidate/HEADS.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
{
"release_repositories_at_public_qualification": {
"mcl-core": "66c838b7dbf6a4c7c92ab006b53366f22667d955",
"mcl-wire": "415f110e55ed00ddd9c7e4c2c6a241dcdfb17a6e",
"mcl-link": "59214bc1c65295a1cbd0940af3ba223cef4f1b7c",
"mcl-sdk": "3fd3b931d66ab9f3d487091b8fb60b8df4155f54",
"mcl-ap": "686908093cc4f0ca04a295492e81b9c8d5c2945e",
"mcl-ip": "adbe2e64db7ffb7c0b7419ea77cc552d8154913c",
"mcl-ble": "9d35ff05e3ffa83292f71e59f22cd45214ae93fd",
"mcl-uwb": "4ddd18bcf39f1e6778f76ea4572ef53c3e30fe3c"
},
"organization_infrastructure": {
".github": "4d35d0cdd372"
},
"note": "These are the heads public CI and the audit qualified. They are NOT the frozen Public Candidate: mcl-core moves when this closure merges, and the Candidate is sealed later on the final heads. .github is recorded for operations only and is never part of the release manifest."
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
## repositories (anonymous)
repo visib page actions release tags license contrib/security
mcl-core public 200 200 0 0 200 contributing-from=none security-policy-page=200
mcl-wire public 200 200 0 0 200 contributing-from=none security-policy-page=200
mcl-link public 200 200 0 0 200 contributing-from=none security-policy-page=200
mcl-sdk public 200 200 0 0 200 contributing-from=none security-policy-page=200
mcl-ap public 200 200 0 0 200 contributing-from=none security-policy-page=200
mcl-ip public 200 200 0 0 200 contributing-from=none security-policy-page=200
mcl-ble public 200 200 0 0 200 contributing-from=none security-policy-page=200
mcl-uwb public 200 200 0 0 200 contributing-from=none security-policy-page=200
.github public 200 200 0 0 404 contributing-from=none security-policy-page=200

## organization profile (anonymous)
org page http=200 profile-README-rendered=1

## cross-repo links in READMEs on main (anonymous)
checked 14 unique links, broken=0

## evidence index claim paths on main (anonymous)
checked 7 claim paths, missing=0

## tracked content: credentials and local identity (all 9 repos at main)
mcl-core credential-shaped=0 local-paths(non-evidence)=0 local-paths(retained records)=6
mcl-wire credential-shaped=0 local-paths(non-evidence)=0 local-paths(retained records)=0
mcl-link credential-shaped=0 local-paths(non-evidence)=0 local-paths(retained records)=0
mcl-sdk credential-shaped=0 local-paths(non-evidence)=0 local-paths(retained records)=10
mcl-ap credential-shaped=0 local-paths(non-evidence)=0 local-paths(retained records)=0
mcl-ip credential-shaped=0 local-paths(non-evidence)=0 local-paths(retained records)=0
mcl-ble credential-shaped=0 local-paths(non-evidence)=0 local-paths(retained records)=0
mcl-uwb credential-shaped=0 local-paths(non-evidence)=0 local-paths(retained records)=0
org-profile credential-shaped=0 local-paths(non-evidence)=0 local-paths(retained records)=0

## default community-health files (anonymous)
community profile mcl-wire: contributing -> https://github.com/machine-contact-layer/.github/blob/main/CONTRIBUTING.md
community profile mcl-core: contributing -> https://github.com/machine-contact-layer/mcl-core/blob/main/CONTRIBUTING.md
mcl-wire security policy page: shows the organization-wide default policy
mcl-ble security policy page: shows the organization-wide default policy
mcl-core security policy page: shows the mcl-core policy (Release gate item 23)
mcl-wire community page links CONTRIBUTING from .github
mcl-uwb community page links CONTRIBUTING from .github

.github has no LICENSE: it is organization infrastructure and carries no MCL release content.
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
{
"receipt": "20260913-public-candidate",
"event": "workflow_dispatch on main, after mcl-ap #1 and mcl-core #1 merged",
"ci": {
"mcl-core": {
"run": 34732269868,
"head": "66c838b7dbf6",
"build (gcc)": "success",
"build (clang)": "success"
},
"mcl-wire": {
"run": 34732271489,
"head": "415f110e55ed",
"build (gcc)": "success",
"build (clang)": "success"
},
"mcl-link": {
"run": 34732273058,
"head": "59214bc1c652",
"build (gcc)": "success",
"build (clang)": "success"
},
"mcl-sdk": {
"run": 34732274496,
"head": "3fd3b931d66a",
"build (gcc)": "success",
"build (clang)": "success"
},
"mcl-ap": {
"run": 34732275914,
"head": "686908093cc4",
"build (gcc)": "success",
"build (clang)": "success"
},
"mcl-ip": {
"run": 34732277584,
"head": "adbe2e64db7f",
"build (gcc)": "success",
"build (clang)": "success"
},
"mcl-ble": {
"run": 34732279462,
"head": "9d35ff05e3ff",
"build (gcc)": "success",
"build (clang)": "success"
},
"mcl-uwb": {
"run": 34732281385,
"head": "4ddd18bcf39f",
"build (gcc)": "success",
"build (clang)": "success"
}
},
"release-gates": {
"repository": "mcl-core",
"run": 34732282757,
"head": "66c838b7dbf6",
"posix-gates": "success",
"cross_repository_checkout": "all eight release repositories, public"
},
"superseded_failure": {
"release-gates run": 34708065754,
"conclusion": "failure",
"cause": "two mcl-ap/experiments/011 run.log digests recorded over Windows CRLF working-tree bytes; corrected by mcl-ap #1, gate hardened by mcl-core #1"
},
"local_exact_head": {
"posix_rehearsal_checks_passed": 22,
"msvc_test_targets_passed": 44
}
}
46 changes: 46 additions & 0 deletions conformance/independent/20260913-public-candidate/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
# Public Candidate operations receipt

Receipts for release gate rows 27 and 37, taken on 2026-09-13 after all nine
repositories were made public.

| file | what it records |
| --- | --- |
| `PUBLIC_AUDIT.txt` | the logged-out audit, run with no token and no credential helper |
| `PUBLIC_CI.json` | the qualifying public `ci` and `release-gates` runs, by run id |
| `HEADS.json` | the heads those runs qualified, and `.github` separately |
| `releases/v1.0.0/GOVERNANCE_RECEIPT.json` | the live read-back of every ruleset |

## What the audit found

All eight release repositories and `.github` are anonymously readable. The
organization profile renders. Every release repository serves its LICENSE, a
security policy and a contributing guide: `mcl-core` its own, the other seven
through the default community-health files in `.github`, verified from the
community profile and security-policy pages rather than assumed. The 14 unique
cross-repository links in the READMEs and the 7 evidence-index claim paths all
resolve. No credential-shaped string exists in any tracked file. Absolute user
paths appear only in retained evidence records, which
`check-publication-readiness.sh` lists as disclosure decisions rather than
defects. There are zero tags and zero GitHub Releases.

## What public qualification found first

The first public `release-gates` run failed, and it was right to. Two digests
under `mcl-ap/experiments/011-bootstrap-over-air` had been recorded over a
Windows working tree still holding CRLF bytes, while Git stores LF; a Windows
sweep reported them passing because it read the wrong bytes. `mcl-ap` #1
corrected the two records without touching the measurements, and `mcl-core` #1
made the digest gate compare the working tree against the committed blob. Both
were merged before the qualifying runs recorded in `PUBLIC_CI.json`.

## Review, stated accurately

`@0j0bit` and `@sed-boi` are two GitHub accounts controlled by the same project
owner. The code-owner requirement is satisfied by the owner reviewing changes
proposed by the `mcl-release-governor` App. That is account redundancy, not
independent two-person review.

## What this does not establish

These receipts record operations. They are not review: row 36, public external
review, remains open, and no Stable tag or GitHub Release exists or is implied.
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
bfbedaa4418a41b072cd738a5f850b92b990377fd6917d17864fc685297a36a1 HEADS.json
bbec7b9f8ea785fd7de9954457ef8d32049cb46363f9a886346bfb835fab45d9 PUBLIC_AUDIT.txt
8269525e439b547ba282c50f296ee6b81eec7849f11616622e723847657d02cc PUBLIC_CI.json
ddab2de6b1fc7cc886881d3ffa9314c1942db7e76b870c259f619fac4b7f5fe7 README.md
4 changes: 2 additions & 2 deletions governance/RELEASE_GATE_V1.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,7 @@ and non-overclaiming* is itself the requirement.
| 24 | Legal / IPR / contribution closure | `DONE` | `LICENSING.md`, `CONTRIBUTING.md`, `NOTICE` in all eight. |
| 25 | Licensing / provenance audit | `DONE` | `check-provenance.sh`, 101 binaries accounted for, in the gates. |
| 26 | Governance operationalization | `DONE` | `governance/GOVERNANCE.md`. |
| 27 | Public Candidate operations | `EXTERNAL` | Everything a repository can carry is present and checked: `check-publication-readiness.sh` (front doors, absolute paths, secrets, claim boundary, CI policy) and `governance/PUBLISHING.md` (the order, and the evidence-disclosure decisions the owner takes). **This row used to say the remaining act was one step -- making the eight repositories readable. That was wrong, and preparing the GitHub organisation is what showed it.** Readability is one act in a sequence, and the acts after it decide whether a public repository is governed at all: `tracked readiness -> evidence/disclosure decisions -> CI-qualified frozen heads -> visibility public -> per-repository rulesets and branch/tag protection applied -> governance receipt verified -> logged-out front-door audit -> Public Candidate`. The protections cannot be applied before the flip, and that is a platform constraint rather than an oversight: on GitHub Free both branch protection and repository rulesets answer `403 Upgrade to GitHub Pro or make this repository public` while a repository is private -- measured, not assumed. The interval between flip and rulesets is therefore real. It is small in severity, because becoming public grants no outsider write access, and it is bounded by applying all eight through the release-governor App in one scripted operation rather than a manual settings session. **Organisation-wide rulesets are deliberately NOT part of this row**: they require GitHub Team, visibility does not unlock them, and eight repositories are manageable per-repository. Row 37 carries the receipt. |
| 27 | Public Candidate operations | `DONE` | Closed 2026-09-13, in the order this row used to prescribe: tracked readiness and the evidence-disclosure decisions; CI-qualified heads; all eight release repositories and the `.github` organization-infrastructure repository made public in one pass and read back `private=false`; per-repository rulesets applied immediately and verified (row 37); and a logged-out audit with no token and no credential helper. The audit: all nine anonymously readable; the organization profile rendering; LICENSE, a security policy and a contributing guide served by every release repository -- `mcl-core` its own, the other seven through the default community-health files in `.github`, confirmed from the community-profile and security-policy pages; the 14 cross-repository README links and the 7 evidence-index claim paths resolving; no credential-shaped string in any tracked file; absolute user paths only in retained evidence records that `check-publication-readiness.sh` lists as disclosure decisions; zero tags and zero GitHub Releases. Public qualification on the merged heads: `ci` green with both `build (gcc)` and `build (clang)` on all eight, and `release-gates` completing its cross-repository checkout and passing. **The first public `release-gates` run failed, and was right to**: two `mcl-ap` digests had been recorded over a Windows working tree's CRLF bytes rather than the committed LF blobs. `mcl-ap` #1 corrected the records without touching the measurements and `mcl-core` #1 hardened the gate to compare against committed bytes; both merged before the qualifying runs. Receipts in `conformance/independent/20260913-public-candidate/`. This row records operations, not review: row 36 remains open. |
| 28 | Interoperability gate | `DONE` | `V1_SCOPE.md` §5.9 defines what v1.0 requires, in three mandatory parts, and all three are met: (a) two implementations independent of each other's code cross-decoding, C4 803 + C5 108; (b) over-air between distinct devices on IP, BLE and acoustic; (c) the stack compiled by a different toolchain for a different architecture, running on an ESP32-S3 and interoperating over air — `mcl-ap/experiments/008-embedded-node/`. **See the note below: this row was narrowed by an explicit scope decision, and what it no longer covers is stated in the release.** |
| 29 | Errata and defect-report process | `DONE` | `REPORTING.md` (what a useful report is, and what happens to it) and `errata/README.md` (the list, empty at v1.0.0 by design, with the format and the never-silently-rewrite rule). `GOVERNANCE.md` §6 defines the process; these make it usable by someone who has just found a defect. |
| 30 | Final release bundle | `DONE` | Frozen developer archive built from the eight revisions in `releases/v1.0.0/commits.txt`; the artifact inventory is the source of truth. Release-candidate only until public review and Stable promotion. Final audit metadata is sealed after execution without rebuilding the SDK archive. |
Expand All @@ -69,7 +69,7 @@ and non-overclaiming* is itself the requirement.
| 34a | Android peer verification | `DONE` | `mcl-ip/evidence/e4-android-udp-20260904/` — an iQOO 9 on Android 14 (arm64-v8a) as a third IP peer over its own 2.4 GHz SoftAP. Four cells (both directions × both majors), 142 checks, 0 failed, 400 sustained frames, 0 lost, 0 retries. The Stable path — major-1 Link frames carrying major-1 `PRESENCE` and `TRANSPORT_OFFER` on profile 1 — was exercised in both directions, including refusal of reserved `profile_id` 0, reserved `transport_id` 0, and a Candidate object at the Stable major. Harness in `mcl-ip/hardware/android-udp-peer/`. |
| 35 | Builder-interoperability floor | `DONE` | Original `V1_SCOPE.md` section 5.10, restored by owner review on 2026-09-10. Both-role zero-prior DFR/Android migration and physical three-party AP contention session `E0585224` are verified by `conformance/independent/20260910-private-rc/verify_row35.py`. All three transmit and receive; both devices receive Windows; the first selected session survives a competing ACCEPT and migrates with explicit policy. Windows is an AP contention participant only. Later stress cells remain informative, including the failed 120-second recheck. Candidate-profile caveats and public review remain separate. |
| 36 | Charter-required public review | `EXTERNAL` | `ARCHITECTURE_CHARTER.md` §6 requires **public review** for a Stable Specification, in addition to interoperability and operational evidence. This row exists because that requirement was being satisfied nowhere: row 27 makes the repositories readable, and readability is not review. **The external act is people outside this project reading the specifications and reporting on them**, after row 27. No fixed waiting period is recorded, because the charter names review, not a timer — the evidence is the reports and what was done about them, tracked as errata. Two consequences while this row is open: no profile is promoted to Stable on private evidence alone, and **AP's Standards Action profile identifier is not assigned** — `AP-BOOTSTRAP-1` and `BLE-ACTIVATE-1` stop at Interoperability Candidate, and profile 192 stays Experimental forever. |
| 37 | GitHub governance receipt | `EXTERNAL` | After row 27's flip, each of the eight repositories carries: protected `main` with pull-request-only merges, at least one approving review, required status checks from `ci`, required conversation resolution, no force push and no deletion; code-owner review on the authority paths named in that repository's `.github/CODEOWNERS`; and a tag rule protecting the `v*` namespace from deletion and mutation, because a release tag that can be moved is not a release tag. **The evidence for this row is machine-readable, not a screenshot.** Every setting is read back through the API after it is written and recorded as a receipt, for the same reason every other number in this ledger is generated rather than typed: a governance setting nobody re-read is a governance setting nobody has. Prerequisite for row 36 -- external reviewers should be reading repositories whose history cannot be quietly rewritten underneath them. |
| 37 | GitHub governance receipt | `DONE` | Closed 2026-09-13. `releases/v1.0.0/GOVERNANCE_RECEIPT.json` is the read-back of live API state, not the write: every asserted parameter recorded as GitHub returned it. **Release class, all eight:** `main` pull-request-only, at least one approving review, code-owner review, conversation resolution, stale reviews dismissed on push, strict required status checks `build (gcc)` and `build (clang)`, no deletion and no force push; a tag ruleset on `refs/tags/v*` blocking deletion, force-update and update. **Infrastructure class, `.github`:** the same review protections and no deletion or force push, with required status checks and a tag ruleset asserted *absent*, because a required context no workflow reports would make every pull request unmergeable. 9/9 verified, 0 skipped, 0 failed, and an independent read-back found **zero bypass actors** on every ruleset. Exercised, not only configured: a direct push to the protected `main` of `.github` by an App holding administrator rights was refused with `GH013`, and the two release-integrity fixes merged only through code-owner review. **What that review means, stated accurately:** `@0j0bit` and `@sed-boi` are two GitHub accounts controlled by the same project owner. Naming both in CODEOWNERS is account redundancy, not separation of duties; MCL has one human project authority, and changes proposed by the `mcl-release-governor` App are reviewed by that owner, not by an independent second person. Organisation-wide rulesets remain out of scope: they require GitHub Team. |

## Row 28: what was narrowed, and what was not

Expand Down
Loading
Loading