diff --git a/specs/015-af-01-trusted-development-baseline/closeout.md b/specs/015-af-01-trusted-development-baseline/closeout.md new file mode 100644 index 00000000..0c110fb1 --- /dev/null +++ b/specs/015-af-01-trusted-development-baseline/closeout.md @@ -0,0 +1,241 @@ +# AF-01 Canonical Closeout — Trusted Development Baseline + +Status: CLOSEOUT_CANDIDATE + +This document records the final AF-01 closure evidence after the convergence implementation and convergence record became canonical. It changes no product source, workflow, dependency, ruleset intent, oracle identity, frozen corpus, or runtime behavior. + +This closeout is not canonical merely because this file exists on a branch. AF-01 may be classified as `CLOSED_CANONICAL` only if this exact docs-only closeout head receives its own required exact-head qualification and merges to `main` without content-changing substitution. + +Temporal exact-head workflow, check-run, artifact, and reviewer identifiers are created only after a commit exists. They are therefore retained in the pull-request conversation as an exact-head qualification checkpoint rather than injected into the same commit: committing those future identifiers would create a new SHA and immediately invalidate them. The checked-in closeout defines the gate and retains completed prerequisite evidence; GitHub's immutable association of the temporal checkpoint with the exact candidate head is the authoritative non-circular T056 record. + +## Canonical entry state + +AF-01 convergence PR #51 merged from exact qualified head: + +```text +convergence head: ae8967a933832c4331d895f6389a9e086c23e661 +convergence tree: 6b98c5582f40681ac9049451025486bbdd1de4fa +PR: #51 +merge commit: 652207aaed1d9a28f3a326ca92e8fd93229fd028 +canonical main tree: 6b98c5582f40681ac9049451025486bbdd1de4fa +``` + +GitHub reports PR #51 as merged and closed, and canonical `main` resolves to the merge commit above. + +## T054 — exact convergence-head qualification + +T054 is complete by exact-head temporal evidence for unchanged convergence head `ae8967a933832c4331d895f6389a9e086c23e661`. + +Retained PR checkpoint: + +```text +PR #51 comment: 5440100797 +``` + +All five path-applicable workflows on that exact head completed successfully: + +```text +ci: 33078356963 +cf06-oracle: 33078357039 +af01-security: 33078357105 +af01-scorecard: 33078357068 +af01-assurance-proof: 33078356986 +``` + +Required-context exact-head uniqueness and provenance were independently verified: + +```text +rust + check-run/job: 98538482919 + head_sha: ae8967a933832c4331d895f6389a9e086c23e661 + conclusion: success + GitHub Actions integration: 15368 + +assurance-proof + check-run/job: 98538483445 + head_sha: ae8967a933832c4331d895f6389a9e086c23e661 + conclusion: success + GitHub Actions integration: 15368 + +scorecard + check-run/job: 98538483749 + head_sha: ae8967a933832c4331d895f6389a9e086c23e661 + conclusion: success + GitHub Actions integration: 15368 +``` + +Retained exact-head artifacts: + +```text +af01-assurance-proof + run: 33078356986 + artifact: 9648998743 + GitHub digest: sha256:7dddbedac56331200dd3432241c92ba9cf488f7bb393d4bff0a106fb5dc92d8c + AF01_ASSURANCE_SHA256: 2902f14e249e61fb9d002f20be5ea37fefe6489d9932f656c0148dc5bbafd08d + +af01-scorecard + run: 33078357068 + artifact: 9648908018 + GitHub digest: sha256:69fda3598bce3cf1f0228733adedff327995a480c30749ad74e8e9aa76175431 +``` + +The convergence delta from canonical Stack C main `a683dfaba7feb607145400eaa75d771e5df3c608` to the exact convergence head changed only: + +```text +A specs/015-af-01-trusted-development-baseline/convergence.md +M specs/015-af-01-trusted-development-baseline/tasks.md +``` + +Fresh reviewer truth on the unchanged exact head was retained in PR #51: + +- Qodo comment `5440158934` accepted the non-circular temporal-evidence model and stated that T054 would be satisfied once a clean unchanged-head CodeRabbit result was linked. +- CodeRabbit comment `5440191060` independently re-verified the exact head/tree, workflow results, required-context uniqueness, active rulesets, artifact bindings, semantic-freeze compare, and review-thread state and concluded: `I found no remaining substantive issue.` +- The prior CodeRabbit auditability thread was resolved after the requested exact Stack C mapping was added. +- unresolved substantive review threads: `0`. + +Therefore: + +```text +T054=COMPLETE +``` + +## T055 — convergence merge and post-merge canonical verification + +PR #51 was merged with an exact expected-head guard from `ae8967a933832c4331d895f6389a9e086c23e661`. + +GitHub merge result: + +```text +merged: true +merge commit: 652207aaed1d9a28f3a326ca92e8fd93229fd028 +``` + +Canonical `main` post-merge: + +```text +main: 652207aaed1d9a28f3a326ca92e8fd93229fd028 +tree: 6b98c5582f40681ac9049451025486bbdd1de4fa +parent 1: a683dfaba7feb607145400eaa75d771e5df3c608 +parent 2: ae8967a933832c4331d895f6389a9e086c23e661 +``` + +The canonical merge tree exactly equals the qualified convergence head tree. + +### Post-merge assurance proof + +The dedicated assurance workflow ran from the canonical merge SHA by `push` and completed successfully: + +```text +workflow: af01-assurance-proof +run: 33079909197 +job/check: 98543959538 +source SHA: 652207aaed1d9a28f3a326ca92e8fd93229fd028 +result: success +artifact: 9649667139 +GitHub digest: sha256:cba692521ac4f99d09cee0ed3d72cb7089eb7efd68c2e08b61619287bb23af98 +AF01_ASSURANCE_SHA256: e1359325c5be4bd93cd4833d9cc51bdde6ecb1d5f440b2c30ef68b248ce833e1 +``` + +The retained `assurance-summary.json` recomputes exactly to the recorded `AF01_ASSURANCE_SHA256` and binds: + +```text +source.sha: 652207aaed1d9a28f3a326ca92e8fd93229fd028 +source.tree: 6b98c5582f40681ac9049451025486bbdd1de4fa +source status: clean +``` + +Every substantive assurance step completed successfully, including workflow-trust counterexamples, exact workflow-trust evidence, deterministic dependency evidence, cargo-deny, cargo-audit/RustSec, zizmor, deterministic summary construction, and retained artifact publication. + +### Post-merge Scorecard evidence + +```text +workflow: af01-scorecard +run: 33079909183 +job/check: 98543959583 +source SHA: 652207aaed1d9a28f3a326ca92e8fd93229fd028 +result: success +artifact: 9649563302 +GitHub digest: sha256:bf61b2301f7e360d56132560cb7931d62098f8c369d5602562a51a333f7461f0 +``` + +Scorecard remains supplemental posture evidence and is not commandF correctness authority. + +### Live source-control policy after merge + +An owner-authorized GitHub ruleset read-back after the convergence merge remains active and applies to `refs/heads/main`. This owner-authorized detailed ruleset endpoint is the authority for repository-administration fields such as bypass actors. GitHub Apps with narrower administration visibility may receive a redacted or `null` `bypass_actors` field; such a permission-scoped omission is not evidence that an owner-visible configured bypass actor is absent. + +Assurance ruleset: + +```text +id: 21652953 +name: commandF main assurance +enforcement: active +bypass actors: none +current user bypass: never +rules: + deletion blocked + non-fast-forward blocked + strict required status checks: + rust integration 15368 + assurance-proof integration 15368 + scorecard integration 15368 +``` + +Review-governance ruleset, owner-authorized live read-back: + +```text +id: 21652974 +name: commandF main review governance +enforcement: active +main only: true +allowed merge methods: merge +required approvals: 1 +require code-owner review: true +require latest-push approval: true +dismiss stale approvals: true +require review-thread resolution: true +bypass: + RepositoryRole actor 5 + mode: pull_request only +current user bypass: pull_requests_only +``` + +The review-only bypass cannot bypass the separate assurance ruleset, whose owner-authorized live bypass list remains empty. + +Therefore: + +```text +T055=COMPLETE +``` + +## Product-semantic closure boundary + +The AF-01 convergence and closeout work after canonical Stack C is documentation/task-state only. No product source, workflow, Cargo manifest, dependency lock, ruleset intent, security policy, oracle identity, or frozen corpus is changed by this closeout candidate. + +AF-01 still does not claim completion of AF-02, AF-03, or AF-04. Those assurance units retain their separate planning/authorization requirements. + +Post-Stack-C dependency updates remain separately qualified work and are not folded into AF-01 closure. + +## T056 — canonical closeout gate + +T055 evidence is complete. T056 is represented by this docs-only closeout candidate under the same canonical-closeout pattern used by prior commandF slices: + +1. this exact closeout head/tree must be identified in authoritative GitHub PR/commit metadata and retained in a PR qualification checkpoint; +2. every path-applicable mandatory workflow on this exact closeout head must be terminal and successful; +3. fresh Qodo and CodeRabbit truth must be obtained when available; +4. every substantive returned finding must be dispositioned; +5. unresolved substantive review threads must be `0`; +6. merge must use an exact expected-head guard and merge method `merge`; +7. canonical post-merge `main` SHA/tree and live rulesets must be re-read. + +The temporal evidence produced after this commit exists — workflow run IDs, check-run IDs, artifact IDs/digests, exact reviewer outcomes, and the final live-policy re-read — belongs in the PR qualification checkpoint. It must not be committed back into this same candidate merely to make the candidate describe its own future evidence, because that would create a new SHA and invalidate the evidence being recorded. + +Until those steps complete, this branch remains `CLOSEOUT_CANDIDATE` and no canonical closure claim is made. + +If and only if this exact docs-only closeout qualifies and merges unchanged, canonical repository truth may classify: + +```text +AF-01=CLOSED_CANONICAL +``` + +At that point AF-01 no longer blocks the next repository-authorized product implementation. AF-02/AF-03/AF-04 remain retained, separately planned assurance units rather than implied completions. diff --git a/specs/015-af-01-trusted-development-baseline/tasks.md b/specs/015-af-01-trusted-development-baseline/tasks.md index 2a7408f5..41191f63 100644 --- a/specs/015-af-01-trusted-development-baseline/tasks.md +++ b/specs/015-af-01-trusted-development-baseline/tasks.md @@ -1,6 +1,6 @@ # AF-01 Tasks — Trusted Development Baseline -Status: CONVERGENCE_CANDIDATE +Status: CLOSEOUT_CANDIDATE ## Task-state rules @@ -10,6 +10,7 @@ Status: CONVERGENCE_CANDIDATE - No implementation task begins until T005 is canonical. - AF-01 cannot close while the live `main` ruleset/branch-policy requirement remains unproven. - Phase 4 entered from canonical `main=a683dfaba7feb607145400eaa75d771e5df3c608`, tree `623a5b20eba83c618d4da288677c1cd3d2826f61`, with T043 `CLOSED_CANONICAL`. +- T054 and T055 are now evidence-complete through convergence PR #51 and its post-merge canonical verification; T056 remains open until this docs-only closeout candidate itself qualifies and merges to canonical `main`. ## Phase 0 — planning and authority @@ -76,9 +77,20 @@ Depends on T043. - [x] **T051** Create `convergence.md` recording planning/Stack A/B/C identities, workflow run/job/artifact/digest evidence, dependency/security tool identities, reviewer dispositions, live ruleset evidence, required-check topology, limits, and deferrals. - [x] **T052** Confirm product-semantic diff from pre-AF-01 canonical base contains no unauthorized CF semantic change; any incidental product source mutation requires separate task/justification and full semantic qualification. - [x] **T053** Record remaining assurance work under AF-02/AF-03/AF-04 rather than falsely claiming fuzz/mutation/portability/release/performance completion. -- [ ] **T054** Exact convergence head receives path-applicable CI/review truth with zero unresolved substantive findings. -- [ ] **T055** Merge convergence PR and verify canonical post-merge main/tree plus live source-control policy and universally terminal required checks. +- [x] **T054** Exact convergence head receives path-applicable CI/review truth with zero unresolved substantive findings. + - exact convergence head `ae8967a933832c4331d895f6389a9e086c23e661` passed all five path-applicable workflows; + - Qodo accepted the retained non-circular temporal evidence model on the unchanged head; + - CodeRabbit independently re-verified the exact head and reported no remaining substantive issue or false-PASS concern; + - unresolved substantive review threads = `0`. +- [x] **T055** Merge convergence PR and verify canonical post-merge main/tree plus live source-control policy and universally terminal required checks. + - PR #51 merged from exact qualified head using an expected-head guard; + - canonical post-merge `main=652207aaed1d9a28f3a326ca92e8fd93229fd028`, tree `6b98c5582f40681ac9049451025486bbdd1de4fa`; + - post-merge `af01-assurance-proof` run `33079909197` and `af01-scorecard` run `33079909183` succeeded on that exact merge SHA; + - retained assurance artifact `9649667139` binds the exact merge source/tree, recomputes `AF01_ASSURANCE_SHA256=e1359325c5be4bd93cd4833d9cc51bdde6ecb1d5f440b2c30ef68b248ce833e1`, and records clean source status; + - live assurance ruleset `21652953` and review-governance ruleset `21652974` remain active on `refs/heads/main` with the reviewed semantics. - [ ] **T056** Mark `AF-01=CLOSED_CANONICAL` only after T055 evidence is complete. + - T055 evidence is complete and retained in `closeout.md`; + - this task remains open until the exact docs-only closeout candidate itself qualifies and merges to canonical `main` without content-changing substitution. ## AF-02 handoff retained, not authorized by AF-01 implementation