feat: add PoCI organizational-independence gate - #202
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Validation completeFinal head: Passed:
Live governance result:
Evidence artifact:
This is an intentionally successful readiness evaluation, not an organizational-independence claim. |
Exact-head validation refreshThe branch head moved to Exact-head checks all passed again:
The live governance result remains the intentional |
What changed
Adds the tenth PoCI slice: a fail-closed governance gate that distinguishes technical federation from organizational independence.
The current ProofPath + Ibex federation has separate repositories, commits, workflows, runners, artifacts, recomputation paths, and Sigstore identities, but both repositories are controlled by the same GitHub owner. This PR therefore intentionally evaluates the live configuration as
HOLD, notACCEPT.The implementation adds:
CHALLENGE > BLOCK > HOLD > ACCEPTdecision precedence;Live expected result
The workflow succeeds only when the live evidence remains an honest
HOLDwith all missing-independence reason codes preserved.Admission rule
ACCEPTrequires:safal207;External operator handoff
A
HOLDemitsproofpath.poci.external-operator-challenge.v0.1, containing the pinned consensus, admission thresholds, required response fields, and independent recomputation steps. The challenge grants no repository, merge, or execution authority.Stacked PR
Base:
agent/poci-cross-repo-federation-v0.1/ #201No merge is performed by this PR.