Skip to content

test(provenance): verify landed-main identity reference - #59

Merged
zoeyrose merged 1 commit into
mainfrom
test/approved-main-provenance-386
Aug 13, 2026
Merged

test(provenance): verify landed-main identity reference#59
zoeyrose merged 1 commit into
mainfrom
test/approved-main-provenance-386

Conversation

@zoeyrose

@zoeyrose zoeyrose commented Aug 13, 2026

Copy link
Copy Markdown
Member

Summary

  • replace the pre-merge provenance audit with a newly signed synthetic record pinned to the #381 squash commit on coordinator main
  • bind local shape validation to the exact landed revision and synthetic-only reviewer authority
  • add a negative regression for the obsolete intermediate branch commit
  • document the default authoritative offline workflow and privacy boundary

Supports atrinik/atrinik#386.

Prerequisite atrinik/atrinik#388 merged as coordinator commit 254595b3e958471a73e2ca4c635992a34abe9cb6.

Coordinates

  • base: main at 9d94970c7787aafaefb5953b2df765f4575f1c61
  • head: test/approved-main-provenance-386 at f2f14d6295305550c7d518d0366daa639f787ebd
  • worktree: /workspaces/atrinik/workspace/worktrees/client/issue-386-approved-main
  • commit: f2f14d6295305550c7d518d0366daa639f787ebd test(provenance): verify landed-main identity reference

Trust boundary

The record remains visibly synthetic and cannot authorize real material. It copies no registry, reviewer roster, identity alias, contact data, or restricted evidence. Its signature selects the synthetic-only authority added by atrinik/atrinik#388.

Validation

  • Rust formatting, strict Clippy, 56 unit/integration tests, and doc tests — passed through tools/validate.sh
  • tools/test-provenance-identity-reference.sh — passed
  • tools/check-foundations.sh — passed
  • version, headless, and dummy-window smoke modes — passed
  • shellcheck tools/check-provenance-identity-reference.sh tools/test-provenance-identity-reference.sh
  • git diff --check
  • canonical coordinator main validation of this record with no trusted-ref or audit override — valid (2 records, 1 references)
  • canonical coordinator main aggregate validation with the client and server records — valid (2 records, 2 references)

The local aggregate then stopped at unavailable cargo-deny; a manual packaging repeat stopped at unavailable cargo-auditable. Latest-head CI owns those installed-tool gates and packaging proof.

Verification

Replacement wrapper runtime adapters remain unavailable under atrinik/atrinik#266, #269, and #270. Classic is not a substitute, and no profile, topology, service, state, scenario, or credentials are needed for this offline trust record.

Repeat from this worktree with a current coordinator checkout:

ATRINIK_COORDINATOR=/path/to/atrinik \
tools/check-provenance-identity-reference.sh

Expected result: valid (2 records, 1 references) with no ATRINIK_COORDINATOR_TRUSTED_REF and no audit flag. The command is read-only and safely repeatable; no shutdown or cleanup is required.

@zoeyrose
zoeyrose marked this pull request as ready for review August 13, 2026 13:42
@zoeyrose
zoeyrose merged commit 700cfec into main Aug 13, 2026
10 checks passed
@zoeyrose
zoeyrose deleted the test/approved-main-provenance-386 branch August 13, 2026 13:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant