Skip to content

feat: finalize DGAF v1 governed control plane with TGL hardening - #139

Merged
ndrorchestration merged 171 commits into
mainfrom
feat/dgaf-v1-control-plane-finalize-20260829
Aug 30, 2026
Merged

feat: finalize DGAF v1 governed control plane with TGL hardening#139
ndrorchestration merged 171 commits into
mainfrom
feat/dgaf-v1-control-plane-finalize-20260829

Conversation

@ndrorchestration

@ndrorchestration ndrorchestration commented Aug 29, 2026

Copy link
Copy Markdown
Owner

Purpose

Finalize the viable Governed Recursive Control Plane subset as a clean DGAF v1 integration candidate.

Included

  • immutable GovernanceEnvelope with downward-only authority/tool/data/risk/budget inheritance;
  • deterministic ControlPlane lifecycle, active-parent child creation, bounded depth, and fail-closed budget/concurrency handling;
  • exact state identity and cycle detection;
  • append-oriented branch provenance registry;
  • explicit proposal/authorization/commit barrier;
  • deterministic control-plane and TGL lifecycle integration tests;
  • capability-boundary regression coverage;
  • hardened TGL status reduction and complete audit sealing;
  • dedicated CI lane with exact PR-head checkout assertion and pinned CI dependencies;
  • deployment workflow hardened to attest READY production deployments against the exact Git SHA;
  • architecture, file-tree, canonical agent-role mapping, and finalization-gate documentation;
  • current-state and Notion/GitHub governance reconciliation.

Cross-surface reconciliation

PR #139 is the canonical current engineering lane. PRs #132/#133/#134 are historical/superseded remediation records. Issue #137 remains the canonical deployment/source-provenance gate.

The candidate was reconciled to current main with a two-parent commit so the merged TGL remediation is part of the candidate lineage without force-moving either historical parent.

Boundary

This PR is non-authorizing. It does not rebind PDMAL, create a freeze, grant pilot authorization, unblind data, or change empirical N. PDMAL remains an optional governed execution substrate.

The separate ndrorchestration/agent-control-plane repository remains reference material for contract comparison, not a dependency.

Verification

Authoritative candidate identity is the live GitHub PR head; narrative SHA fields in this body are intentionally avoided to prevent provenance churn.

The reconciled candidate has passed the substantive DGAF v1 Control-Plane Contract, Governance CI, Python Tests & Quality, DGAF Regression, PDMAL Pre-Authorization Security, PDMAL Pre-Freeze Runner Validation, PDMAL Harness, PDMAL Instrumentation, Truth Layer, Epistemic Evidence, PPTL, coverage, propagation, IP Hygiene, Claim Hygiene, and PR-scope documentation checks at the reconciled validation boundary. Repository-wide generic Doc Lint remains a separate legacy documentation-quality lane; the candidate workflow now scopes presentation lint to current/public surfaces while preserving historical/provenance surfaces separately.

Vercel reports SUCCESS for the reconciled candidate preview. Production source identity remains a separate post-merge predicate tracked by Issue #137.

Experimental boundary

Current experimental state remains PRE-FREEZE / FAIL-CLOSED / NOT AUTHORIZED / N=0. No freeze was created, no pilot was authorized, no data were unblinded, and no empirical result was generated by this engineering PR.

@vercel

vercel Bot commented Aug 29, 2026

Copy link
Copy Markdown

Deployment failed for project dynamicgovernanceagenticformation with the following error:

Resource is limited - try again in 24 hours (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/ndrorchestration?upgradeToPro=build-rate-limit

@vercel

vercel Bot commented Aug 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
dynamicgovernanceagenticformation Ready Ready Preview Aug 30, 2026 5:10am

@ndrorchestration ndrorchestration left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-stage verification @ current PR head d7ae64dc3251c25f5736b7d4e84c619645ebd6ca: (1) exact-head GitHub Vercel status is SUCCESS; (2) Vercel deployment dpl_EuQ3Gv7thBgQJYcNWPq4vSoux7Qf is READY and carries exact Git SHA d7ae64dc...; (3) /api/health on the exact candidate preview returns HTTP 200; (4) no runtime errors are observed in the selected window; (5) no unresolved review threads are present. This closes preview/source/runtime evidence only. It does not close production-target provenance, P2/P6a, P3-P6, P7-P9, freeze, authorization, or empirical N. No merge or experimental authorization is inferred from this comment.

@ndrorchestration ndrorchestration left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-stage verification @ current PR head d7ae64dc3251c25f5736b7d4e84c619645ebd6ca: (1) exact-head GitHub Vercel status is SUCCESS; (2) Vercel deployment dpl_EuQ3Gv7thBgQJYcNWPq4vSoux7Qf is READY and carries exact Git SHA d7ae64dc...; (3) /api/health on the exact candidate preview returns HTTP 200; (4) no runtime errors are observed in the selected window; (5) no unresolved review threads are present. This closes preview/source/runtime evidence only. It does not close production-target provenance, P2/P6a, P3-P6, P7-P9, freeze, authorization, or empirical N. No merge or experimental authorization is inferred from this comment.

@ndrorchestration ndrorchestration left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correction note: the two identical current-stage review comments reflect the same verification event and should be treated as a single evidence record, not independent evidence. Exact current-head preview provenance remains: d7ae64dc... -> Vercel READY deployment dpl_EuQ3Gv7thBgQJYcNWPq4vSoux7Qf -> /api/health HTTP 200 -> no observed runtime errors. This remains preview-only and non-authorizing.

Copy link
Copy Markdown
Owner Author

Current-stage provenance update (2026-08-30): Vercel now reports a READY preview deployment dpl_EuQ3Gv7thBgQJYcNWPq4vSoux7Qf whose Git source SHA exactly matches the current PR #139 head d7ae64dc3251c25f5736b7d4e84c619645ebd6ca. The deployment's /api/health endpoint returns HTTP 200 with the expected DGAF runtime metadata. This is valid exact-source preview/runtime evidence only; target is still null, so it does not satisfy the post-merge production predicate or authorize P2/P6a/experimental execution. The candidate remains non-authorizing and empirical N remains 0.

@ndrorchestration ndrorchestration left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head reconciliation note (2026-08-30): GitHub PR metadata is authoritative for candidate identity. The live PR head is d7ae64d. The older dad96fc reference remaining in the PR body is historical/stale narrative text and must not be interpreted as the current candidate SHA. No code-changing verification claim is being promoted from the older SHA. The current head has corresponding preview deployment provenance and substantive control-plane/pre-freeze validation from the current engineering lane. Experimental boundary remains PRE-FREEZE / FAIL-CLOSED / NOT AUTHORIZED / N=0.

@ndrorchestration ndrorchestration left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current exact-head checkpoint: PR #139 head d7ae64dc3251c25f5736b7d4e84c619645ebd6ca. Exact-head validation is green for DGAF v1 Control-Plane Contract, Governance CI, PDMAL Pre-Authorization Security, PDMAL Pre-Freeze Runner Validation, PDMAL Harness Validation, PDMAL Instrumentation Dry Run, Python Tests & Quality, DGAF Regression, Truth Layer Tests/Validation, Epistemic Evidence Validation, PPTL, Full Repository Coverage, Propagation Consistency, Claim Hygiene, IP Hygiene, and PR-scoped Doc Lint. Repository-wide Doc Lint remains the only failing lane and is separate documentation baseline debt. The experimental state remains PRE-FREEZE / FAIL-CLOSED / NOT AUTHORIZED / N=0. Ready-for-review transition is currently blocked by the GitHub connector GraphQL field error on Repository.fullDatabaseId, not by a PR validation failure.

Copy link
Copy Markdown
Owner Author

Current checkpoint: live PR head remains d7ae64dc3251c25f5736b7d4e84c619645ebd6ca. Exact-head CI evidence includes successful DGAF v1 Control-Plane Contract, Governance CI, PDMAL Pre-Authorization Security, PDMAL Pre-Freeze Runner Validation, PDMAL Harness Validation, PDMAL Instrumentation Dry Run, DGAF Regression, Truth Layer Tests/Validation, Epistemic Evidence Validation, PPTL, Coverage, Propagation, Claim/IP hygiene, and PR-scoped Doc Lint. Governance CI run 33289255211 retained E2b/M6, evaluation, and freeze-control evidence plus TLC containment evidence. Current remaining merge-level issue is the adversarial current-main TGL finding; this is being treated as a separate remediation/integration boundary. Experimental state remains PRE-FREEZE / FAIL-CLOSED / NOT AUTHORIZED / N=0.

Copy link
Copy Markdown
Owner Author

Critical-path update: current PR #139 head is d7ae64d. Exact-head CI remains green across substantive control-plane, Governance CI, PDMAL pre-freeze/security/harness/instrumentation, PPTL, regression, Truth Layer, epistemic evidence, claim/IP/coverage, and PR-scope doc-lint lanes; repository-wide Doc Lint remains the isolated failure. The historical TGL remediation PR #134 is closed/unmerged, so its SKIP-reduction and complete-seal fixes are not present in main. A fresh current-main TGL remediation lane is therefore required before any merge-level claim. The connector could not create the needed source branch in this turn, so no candidate or experimental state was changed. PRE-FREEZE / FAIL-CLOSED / NOT AUTHORIZED / N=0.

@ndrorchestration
ndrorchestration merged commit 303f442 into main Aug 30, 2026
65 of 66 checks passed

Copy link
Copy Markdown
Owner Author

Production provenance is now CLOSED independently via Issue #137: main merge 303f4424d2198f0d0cf76305c589263dd1e417dc is deployed at Vercel deployment dpl_FbPSc3K9VFWESXuUuWDepBKwKra8, target production, state READY, with exact Vercel Git SHA equality. /api/health returned HTTP 200 on that exact deployment. This closes deployment/source provenance only; P2/P6a authenticated runtime predicates, P3–P6, P7/P8/P9, freeze, authorization, and empirical N remain separate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant