Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
154 commits
Select commit Hold shift + click to select a range
469dfa3
feat: add DGAF v1 governance envelope
ndrorchestration Aug 29, 2026
75697aa
feat: add deterministic v1 state identity
ndrorchestration Aug 29, 2026
b69c2b2
feat: add v1 resource and concurrency ledger
ndrorchestration Aug 29, 2026
2f1a529
feat: add v1 branch provenance registry
ndrorchestration Aug 29, 2026
0e41bae
feat: add explicit v1 commit authorization gate
ndrorchestration Aug 29, 2026
c958275
feat: add v1 deterministic control-plane lifecycle
ndrorchestration Aug 29, 2026
7f2e107
docs: map canonical DGAF agents to v1 control-plane roles
ndrorchestration Aug 29, 2026
c28b789
test: add deterministic DGAF v1 control-plane contracts
ndrorchestration Aug 29, 2026
8f5967a
test: add DGAF v1 TGL lifecycle integration contracts
ndrorchestration Aug 29, 2026
5ec710a
ci: add deterministic DGAF v1 control-plane validation lane
ndrorchestration Aug 29, 2026
99cf0e5
feat: export DGAF v1 control-plane contracts
ndrorchestration Aug 29, 2026
342c3be
docs: add canonical DGAF v1 control-plane architecture
ndrorchestration Aug 29, 2026
4626b66
docs: add DGAF v1 file-tree ownership plan
ndrorchestration Aug 29, 2026
089014f
docs: reconcile current state with v1 finalization and latest Notion …
ndrorchestration Aug 29, 2026
878f1ad
docs: add DGAF v1 finalization gate record
ndrorchestration Aug 29, 2026
9f4c7f5
docs: add DGAF v1 execution readiness criteria
ndrorchestration Aug 29, 2026
24f9174
ci: include adversarial v1 contracts in control-plane lane
ndrorchestration Aug 29, 2026
04551a9
test: add DGAF v1 adversarial control-plane contracts
ndrorchestration Aug 29, 2026
e3ce2fc
fix: release active control-plane resources on escalation
ndrorchestration Aug 29, 2026
f96383a
test: enforce immediate resource release on escalation
ndrorchestration Aug 29, 2026
5445ac1
docs: record Notion GitHub reconciliation for v1
ndrorchestration Aug 29, 2026
554e852
docs: add PR139 review packet
ndrorchestration Aug 29, 2026
4bce22a
docs: record PR139 status snapshot
ndrorchestration Aug 29, 2026
ea5ccf1
docs: record PR139 hardening closure notes
ndrorchestration Aug 29, 2026
9dea8b0
docs: add exact-head CI execution record for PR139
ndrorchestration Aug 29, 2026
2ceca4f
test: add branch registry count contract
ndrorchestration Aug 29, 2026
0b9e314
test: align TGL fixture with established hook contract
ndrorchestration Aug 29, 2026
b606aa3
test: align adversarial TGL fixture contract
ndrorchestration Aug 29, 2026
9b0d0dd
fix: seal commit request payloads and prevent commit replay
ndrorchestration Aug 29, 2026
b554d67
fix: seal branch metadata against mutation
ndrorchestration Aug 29, 2026
3e12938
fix: contain TGL runner exceptions and preserve resource release
ndrorchestration Aug 29, 2026
5d91cce
test: harden commit replay and evidence immutability contracts
ndrorchestration Aug 29, 2026
52a5fed
docs: repair PR139 current-state lint
ndrorchestration Aug 29, 2026
d6ec490
fix: account expansion as consumed resources
ndrorchestration Aug 29, 2026
2bff873
test: lock expansion resource accounting semantics
ndrorchestration Aug 29, 2026
89e63f0
docs: repair PR139 reconciliation lint
ndrorchestration Aug 29, 2026
ea434e0
docs: bind PR139 CI record to current candidate
ndrorchestration Aug 29, 2026
86a7857
docs: repair PR139 hardening notes lint
ndrorchestration Aug 29, 2026
6ee4f89
docs: repair PR139 review packet lint
ndrorchestration Aug 29, 2026
2c79d86
docs: clarify PR139 exact-head readiness binding
ndrorchestration Aug 29, 2026
ece6863
fix: enforce reserved plus consumed budget ceiling
ndrorchestration Aug 29, 2026
ffe1ad9
test: enforce reservation-consumption interaction safety
ndrorchestration Aug 29, 2026
ad879bb
test: distinguish historical aliases from active agent seats
ndrorchestration Aug 29, 2026
13ac656
ci: move Doc Lint workflow to Node 24
ndrorchestration Aug 29, 2026
22fd65a
fix: validate expansion transition before side effects
ndrorchestration Aug 29, 2026
e291897
test: ensure illegal expansion transition has no side effects
ndrorchestration Aug 29, 2026
47ec32d
ci: add numpy to pinned test dependencies
ndrorchestration Aug 29, 2026
567e59f
test: cover illegal expansion side-effect invariant
ndrorchestration Aug 29, 2026
91ca892
ci: replace yanked pytest-timeout pin
ndrorchestration Aug 29, 2026
792bb83
fix(tgl): close fail-closed status and audit-seal integrity gaps
ndrorchestration Aug 29, 2026
f7a2ccf
test(tgl): enforce fail-closed reduction and complete audit sealing
ndrorchestration Aug 29, 2026
7ac6f63
docs: consolidate current TGL and v1 engineering state
ndrorchestration Aug 29, 2026
010a054
docs: consolidate public current-state and canonical engineering lane
ndrorchestration Aug 29, 2026
7ac734c
docs: reconcile v1 finalization gate with TGL hardening
ndrorchestration Aug 29, 2026
37987bf
docs: reconcile public-surface canonical state
ndrorchestration Aug 29, 2026
54fe565
docs: align v1 finalization gate with current TGL remediation
ndrorchestration Aug 29, 2026
ac81182
docs: reconcile adapter boundary audit with hardened TGL lane
ndrorchestration Aug 29, 2026
a114b0b
docs: align v1 finalization gate with current TGL remediation
ndrorchestration Aug 29, 2026
ce312af
docs: align v1 finalization gate with current TGL remediation
ndrorchestration Aug 29, 2026
bafb137
docs: align v1 file ownership with hardened TGL boundary
ndrorchestration Aug 29, 2026
ca8bd81
docs: reconcile v1 role map with canonical authority boundary
ndrorchestration Aug 29, 2026
87b201a
docs: reconcile current state with canonical TGL remediation lane
ndrorchestration Aug 29, 2026
2636da8
docs: reconcile v1 finalization gate status
ndrorchestration Aug 29, 2026
f19adcb
docs: record canonical v1 finalization lane
ndrorchestration Aug 29, 2026
411bcfe
docs: reconcile v1 finalization gate
ndrorchestration Aug 29, 2026
ba9232f
docs: maintain canonical v1 finalization record
ndrorchestration Aug 29, 2026
a475e36
docs: consolidate current TGL and v1 engineering state
ndrorchestration Aug 29, 2026
9c83407
docs: designate PR139 canonical v1 finalization lane
ndrorchestration Aug 29, 2026
be5dd3d
docs: reinforce canonical v1 finalization boundary
ndrorchestration Aug 29, 2026
b75e286
docs: align v1 architecture with hardened TGL boundary
ndrorchestration Aug 29, 2026
f2da1aa
docs: finalize canonical v1 role boundary
ndrorchestration Aug 29, 2026
bffd95f
docs: finalize canonical v1 role mapping
ndrorchestration Aug 29, 2026
26de6f2
docs: mark v1 finalization lane canonical
ndrorchestration Aug 29, 2026
b9cf839
docs: finalize current-state canonical engineering lane
ndrorchestration Aug 29, 2026
0da6d32
docs: reconcile v1 finalization gate with current canonical lane
ndrorchestration Aug 29, 2026
352d432
docs: maintain canonical v1 finalization boundary
ndrorchestration Aug 29, 2026
abfa254
docs: reconcile v1 finalization gate with canonical lane
ndrorchestration Aug 29, 2026
152c70a
docs: finalize canonical v1 ownership and boundary map
ndrorchestration Aug 29, 2026
e16c159
docs: retain canonical v1 finalization boundary
ndrorchestration Aug 29, 2026
2d011ab
docs: keep canonical v1 finalization boundary
ndrorchestration Aug 29, 2026
99028a4
docs: retain canonical v1 finalization boundary
ndrorchestration Aug 29, 2026
23e0bd0
docs: finalize canonical engineering-lane consolidation
ndrorchestration Aug 29, 2026
cef98b0
docs: finalize v1 gate canonical status
ndrorchestration Aug 29, 2026
39d8a0c
docs: finalize v1 architecture boundary
ndrorchestration Aug 29, 2026
6af38c3
docs: finalize v1 ownership boundary
ndrorchestration Aug 29, 2026
eff0709
docs: consolidate README current engineering and experimental state
ndrorchestration Aug 29, 2026
577fd64
docs: consolidate v1 finalization status
ndrorchestration Aug 29, 2026
a7a950f
docs: consolidate v1 finalization status
ndrorchestration Aug 29, 2026
aeda76d
docs: consolidate v1 finalization status
ndrorchestration Aug 29, 2026
c3734da
docs: retain canonical v1 finalization boundary
ndrorchestration Aug 29, 2026
bda619e
fix: require successful TGL evaluation before merge readiness
ndrorchestration Aug 29, 2026
d60f24c
test: enforce TGL evidence before merge readiness
ndrorchestration Aug 29, 2026
d65986e
test: reconcile TGL terminal semantics and final seal
ndrorchestration Aug 29, 2026
d0f94ca
fix: preserve all branch identities for shared state IDs
ndrorchestration Aug 29, 2026
973f253
test: preserve branch identity for shared states
ndrorchestration Aug 29, 2026
f08d6d3
fix: reject resource consumption after terminal lifecycle states
ndrorchestration Aug 29, 2026
5a2780b
test: enforce terminal resource immutability
ndrorchestration Aug 29, 2026
9c8a191
test: harden child creation transaction ordering
ndrorchestration Aug 29, 2026
f1bc2e7
harden TGL evidence binding and transactional child registration
ndrorchestration Aug 29, 2026
86fa203
test: bind merge readiness to sealed TGL evidence
ndrorchestration Aug 29, 2026
d2bc18a
fix: freeze branch provenance collections
ndrorchestration Aug 29, 2026
c85c5f2
harden task identity mutability and sealed TGL provenance
ndrorchestration Aug 29, 2026
2d54a2b
test: close identity and provenance mutation gaps
ndrorchestration Aug 29, 2026
f8c70e6
fix: make child metadata and side-effect authority monotonic
ndrorchestration Aug 29, 2026
91f893d
test: enforce monotonic governance envelope inheritance
ndrorchestration Aug 29, 2026
86857f9
docs: reconcile PDMAL control state with canonical PR139 lane
ndrorchestration Aug 29, 2026
36e1874
security: make control-task runtime state controller-managed
ndrorchestration Aug 29, 2026
6146e08
test: enforce controller-managed runtime state and monotonic inheritance
ndrorchestration Aug 29, 2026
e741f52
security: isolate control-plane capabilities behind read-only views
ndrorchestration Aug 29, 2026
111ad92
security: bind TGL runner and require canonical audit evidence
ndrorchestration Aug 29, 2026
361ee81
security: require sealed TGL evidence while preserving test seams
ndrorchestration Aug 29, 2026
7ea2cd2
fix: record exact post-transition child state identity
ndrorchestration Aug 29, 2026
236e58a
test: add v1 capability and child-state boundaries
ndrorchestration Aug 29, 2026
8a7ce4d
fix: permit deterministic fail-closed task termination
ndrorchestration Aug 29, 2026
ce93394
fix: align control-plane regression expectations with fail-closed lif…
ndrorchestration Aug 29, 2026
a365b17
reconcile project status to consolidated PR #139 engineering lane
ndrorchestration Aug 29, 2026
ba11ff8
reconcile PR139 status with adversarial findings and exact head
ndrorchestration Aug 29, 2026
c5e4fe4
update PR139 hardening audit with resolved capability and lifecycle f…
ndrorchestration Aug 29, 2026
228cf8d
expand DGAF v1 finalization record with closed control-plane invariants
ndrorchestration Aug 29, 2026
b65312d
reconcile adapter-boundary audit with current PR139 hardening and evi…
ndrorchestration Aug 29, 2026
23dc2b3
reconcile PR139 CI record with exact-head findings and Vercel blocker
ndrorchestration Aug 29, 2026
5da79a4
refresh PR139 status to current engineering head and verification bou…
ndrorchestration Aug 29, 2026
72563ae
refresh PR139 reviewer packet with current head and hardened controls
ndrorchestration Aug 29, 2026
3183e95
reconcile Notion-GitHub record to current PR139 head and Vercel blocker
ndrorchestration Aug 29, 2026
9bcd2fa
refresh current-state record with current PR139 head and Vercel blocker
ndrorchestration Aug 29, 2026
b9b6773
expand DGAF v1 execution-readiness acceptance criteria for hardened c…
ndrorchestration Aug 29, 2026
fe0d4ac
reconcile P8 lock with current PR139 engineering authority
ndrorchestration Aug 29, 2026
077cf76
harden control-plane CI with exact-head checkout and pinned dependencies
ndrorchestration Aug 29, 2026
2df8c06
reconcile PDMAL evidence index to current PR139 engineering authority
ndrorchestration Aug 29, 2026
88a9069
refresh PR139 hardening notes to authoritative current head
ndrorchestration Aug 29, 2026
aa070f3
align adapter-boundary audit to authoritative PR139 head
ndrorchestration Aug 29, 2026
eb17f06
refresh PR139 CI record to confirmed exact head and evidence status
ndrorchestration Aug 29, 2026
f0d424a
align PR139 status with confirmed branch head 2df8c060
ndrorchestration Aug 29, 2026
3a706ca
ensure v1 control-plane contracts run on every candidate branch push
ndrorchestration Aug 29, 2026
eb3f1cc
fix: enforce monotonic child side-effect authority
ndrorchestration Aug 29, 2026
7807d95
fix: make side-effect widening regression test exercise actual escala…
ndrorchestration Aug 29, 2026
250de1c
docs: reconcile current state to verified PR139 head
ndrorchestration Aug 29, 2026
d07013c
docs: reconcile current state to latest PR139 head and exact evidence…
ndrorchestration Aug 29, 2026
d51915e
merge: reconcile PR #139 with current main
ndrorchestration Aug 29, 2026
541cddb
fix: reduce final TGL status after Herald
ndrorchestration Aug 29, 2026
a728ce3
test: enforce Herald status reduction
ndrorchestration Aug 29, 2026
d5b4b9b
docs: reconcile current state to integrated PR139 head
ndrorchestration Aug 29, 2026
2855e65
docs: fix markdown list spacing
ndrorchestration Aug 29, 2026
d24f6e7
docs: lint v1 finalization record
ndrorchestration Aug 29, 2026
b7d1fe4
docs: lint Notion GitHub reconciliation
ndrorchestration Aug 29, 2026
be32038
docs: lint PR139 CI execution record
ndrorchestration Aug 29, 2026
d2c2405
docs: reconcile PR139 hardening notes
ndrorchestration Aug 29, 2026
6ecfdf0
docs: reconcile PR139 review packet
ndrorchestration Aug 29, 2026
febe823
docs: reconcile PR139 status
ndrorchestration Aug 29, 2026
9947adf
docs: fix project status markdown newline
ndrorchestration Aug 29, 2026
15efb74
docs: finalize current candidate identity
ndrorchestration Aug 29, 2026
49b53f4
ci: move PR doc lint to Node 24
ndrorchestration Aug 29, 2026
46c556c
ci: attest exact Vercel deployment source SHA
ndrorchestration Aug 29, 2026
dad96fc
ci: require production deployment target
ndrorchestration Aug 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
73 changes: 73 additions & 0 deletions .github/workflows/control-plane-contract.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
name: DGAF v1 Control-Plane Contract

permissions:
contents: read

on:
pull_request:
branches: [main]
paths:
- "pptl/governance_envelope.py"
- "pptl/state_identity.py"
- "pptl/budget_ledger.py"
- "pptl/branch_registry.py"
- "pptl/control_plane.py"
- "pptl/commit_gate.py"
- "pptl/triadic_governance_loop.py"
- "pptl/tests/test_v1_control_plane.py"
- "pptl/tests/test_v1_tgl_integration.py"
- "pptl/tests/test_v1_adversarial_contract.py"
- "pptl/tests/test_v1_capability_boundaries.py"
- "docs/architecture/DGAF_V1_AGENT_ROLE_MAPPING.md"
- "docs/governance/DGAF_V1_FINALIZATION_GATE.md"
- "docs/architecture/DGAF_V1_EXECUTION_READINESS.md"
- "requirements-ci.txt"
- ".github/workflows/control-plane-contract.yml"
push:
branches:
- "feat/dgaf-v1-control-plane-finalize-20260829"
paths:
- "pptl/governance_envelope.py"
- "pptl/state_identity.py"
- "pptl/budget_ledger.py"
- "pptl/branch_registry.py"
- "pptl/control_plane.py"
- "pptl/commit_gate.py"
- "pptl/triadic_governance_loop.py"
- "pptl/tests/test_v1_control_plane.py"
- "pptl/tests/test_v1_tgl_integration.py"
- "pptl/tests/test_v1_adversarial_contract.py"
- "pptl/tests/test_v1_capability_boundaries.py"
- "requirements-ci.txt"
- ".github/workflows/control-plane-contract.yml"
workflow_dispatch:

jobs:
contracts:
name: V1 Control-Plane Contracts
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
fetch-depth: 1
- name: Assert exact candidate checkout
shell: bash
env:
EXPECTED_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
run: |
set -euo pipefail
ACTUAL_SHA="$(git rev-parse HEAD)"
test "$ACTUAL_SHA" = "$EXPECTED_SHA"
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Install pinned CI dependencies
run: python -m pip install -r requirements-ci.txt pandas==3.0.5
- name: Run deterministic contracts
run: >-
python -m pytest -q
pptl/tests/test_v1_control_plane.py
pptl/tests/test_v1_tgl_integration.py
pptl/tests/test_v1_adversarial_contract.py
pptl/tests/test_v1_capability_boundaries.py
59 changes: 51 additions & 8 deletions .github/workflows/deploy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,8 @@ jobs:
runs-on: ubuntu-latest
outputs:
deployment_url: ${{ steps.deploy.outputs.deployment_url }}
deployment_id: ${{ steps.provenance.outputs.deployment_id }}
source_sha: ${{ steps.provenance.outputs.source_sha }}
env:
VERCEL_TOKEN: ${{ secrets.VERCEL_TOKEN }}
VERCEL_ORG_ID: ${{ secrets.VERCEL_ORG_ID }}
Expand All @@ -95,25 +97,66 @@ jobs:
--token="$VERCEL_TOKEN")
echo "deployment_url=$URL" >> "$GITHUB_OUTPUT"
echo "Deployed to: $URL"
export DEPLOYMENT_URL="$URL"

- name: Verify exact Vercel deployment identity
id: provenance
shell: bash
env:
DEPLOYMENT_URL: ${{ steps.deploy.outputs.deployment_url }}
run: |
set -euo pipefail
mkdir -p artifacts
HOST="${DEPLOYMENT_URL#https://}"
HOST="${HOST#http://}"
RESPONSE=$(curl -fsS --get \
--data-urlencode "teamId=$VERCEL_ORG_ID" \
--data-urlencode "withGitRepoInfo=true" \
"https://api.vercel.com/v13/deployments/$HOST" \
-H "Authorization: Bearer $VERCEL_TOKEN")

echo "$RESPONSE" > artifacts/deployment_metadata.json
READY_STATE=$(echo "$RESPONSE" | jq -r '.readyState // empty')
TARGET=$(echo "$RESPONSE" | jq -r '.target // empty')
DEPLOYMENT_ID=$(echo "$RESPONSE" | jq -r '.id // empty')
META_SHA=$(echo "$RESPONSE" | jq -r '.meta.githubCommitSha // empty')
GIT_SHA=$(echo "$RESPONSE" | jq -r '.gitSource.sha // empty')
SOURCE_SHA="${META_SHA:-$GIT_SHA}"

[ -n "$DEPLOYMENT_ID" ] || { echo 'x deployment id missing'; exit 1; }
[ "$READY_STATE" = "READY" ] || { echo "x deployment state=$READY_STATE"; exit 1; }
[ "$TARGET" = "production" ] || { echo "x deployment target=$TARGET; expected production"; exit 1; }
[ -n "$SOURCE_SHA" ] || { echo 'x Vercel Git source SHA missing'; exit 1; }
[ "$SOURCE_SHA" = "$GITHUB_SHA" ] || {
echo "x source SHA mismatch: Vercel=$SOURCE_SHA GitHub=$GITHUB_SHA"
exit 1
}

python - <<'PY'
import json
import os
from pathlib import Path

raw = json.loads(Path('artifacts/deployment_metadata.json').read_text(encoding='utf-8'))
source_sha = raw.get('meta', {}).get('githubCommitSha') or raw.get('gitSource', {}).get('sha')
payload = {
'evidence_class': 'DEPLOYMENT_ATTESTATION',
'evidence_class': 'DEPLOYMENT_EXACT_SOURCE_ATTESTATION',
'source_commit': os.environ['GITHUB_SHA'],
'vercel_source_commit': source_sha,
'workflow_run_id': os.environ['GITHUB_RUN_ID'],
'deployment_id': raw.get('id'),
'deployment_url': os.environ['DEPLOYMENT_URL'],
'command': 'vercel deploy --prod --yes --token=<redacted>',
'result': 'DEPLOYMENT_RETURNED_URL',
'scope': 'Vercel deployment command result only',
'limitations': ['Deployment return does not establish application health or end-to-end runtime behavior.'],
'ready_state': raw.get('readyState'),
'target': raw.get('target'),
'git_ref': raw.get('meta', {}).get('githubCommitRef') or raw.get('gitSource', {}).get('ref'),
'repository': raw.get('meta', {}).get('githubRepo'),
'exact_source_match': source_sha == os.environ['GITHUB_SHA'],
}
Path('artifacts/deployment_provenance.json').write_text(json.dumps(payload, indent=2) + '\n', encoding='utf-8')
PY

echo "deployment_id=$DEPLOYMENT_ID" >> "$GITHUB_OUTPUT"
echo "source_sha=$SOURCE_SHA" >> "$GITHUB_OUTPUT"

- name: Set env vars
run: |
echo "1.8.0" | vercel env add ENSEMBLE_VERSION production \
Expand Down Expand Up @@ -208,9 +251,9 @@ jobs:
'source_commit': os.environ['GITHUB_SHA'],
'workflow_run_id': os.environ['GITHUB_RUN_ID'],
'deployment_url': os.environ['DGAF_URL'],
'scope': 'health preflight, 30-turn live regression, and audit turn-count check',
'scope': 'exact-source production deployment identity, health preflight, 30-turn live regression, and audit turn-count check',
'result': 'PASS',
'limitations': ['Runtime verification applies to the exercised deployment and protocol; it does not establish broad real-world efficacy.'],
'limitations': ['Runtime verification applies to the exercised exact-source production deployment and protocol; it does not establish broad real-world efficacy.'],
}
Path('artifacts/runtime_verification.json').write_text(json.dumps(payload, indent=2) + '\n', encoding='utf-8')
PY
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/doc-lint-pr-scope.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ jobs:
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '20'
node-version: '24'

- name: Install markdownlint-cli
run: npm install -g markdownlint-cli@0.39.0
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/doc-lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ jobs:
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '20'
node-version: '24'

- name: Install markdownlint-cli
run: npm install -g markdownlint-cli@0.39.0
Expand Down
Loading
Loading