Skip to content

test(provenance): verify landed-main identity reference - #86

Merged
zoeyrose merged 1 commit into
mainfrom
test/approved-main-provenance-386
Aug 13, 2026
Merged

test(provenance): verify landed-main identity reference#86
zoeyrose merged 1 commit into
mainfrom
test/approved-main-provenance-386

Conversation

@zoeyrose

@zoeyrose zoeyrose commented Aug 13, 2026

Copy link
Copy Markdown
Member

Summary

  • replace the pre-merge provenance audit with a newly signed synthetic record pinned to the #381 squash commit on coordinator main
  • bind local shape validation to the exact landed revision and synthetic-only reviewer authority
  • add a negative regression for the obsolete intermediate branch commit
  • document the default authoritative offline workflow and privacy boundary

Supports atrinik/atrinik#386.

Prerequisite atrinik/atrinik#388 merged as coordinator commit 254595b3e958471a73e2ca4c635992a34abe9cb6.

Coordinates

  • base: main at 95c8421c25b8175d684830a8e2e1d5861e317dd9
  • head: test/approved-main-provenance-386 at 7e828ce308d96a2f2416b97a58df0dd87e41d3e9
  • worktree: /workspaces/atrinik/workspace/worktrees/server/issue-386-approved-main
  • commit: 7e828ce308d96a2f2416b97a58df0dd87e41d3e9 test(provenance): verify landed-main identity reference

Trust boundary

The record remains visibly synthetic and cannot authorize real material. It copies no registry, reviewer roster, identity alias, contact data, or restricted evidence. Its signature selects the synthetic-only authority added by atrinik/atrinik#388.

Validation

  • go mod verify, go vet ./..., go test ./..., and go test -race ./... — passed
  • observability fuzz smoke and kernel benchmarks — passed
  • tools/test-provenance-identity-reference.sh and tools/check-foundations.sh — passed
  • shellcheck tools/check-provenance-identity-reference.sh tools/test-provenance-identity-reference.sh
  • git diff --check
  • canonical coordinator main validation of this record with no trusted-ref or audit override — valid (2 records, 1 references)
  • canonical coordinator main aggregate validation with the client and server records — valid (2 records, 2 references)

The local aggregate prerequisites staticcheck, govulncheck, and go-licenses are unavailable; latest-head CI owns those installed-tool gates and package dependency proof.

Verification

Replacement wrapper runtime adapters remain unavailable under atrinik/atrinik#266, #269, and #270. Classic is not a substitute, and no profile, topology, service, state, scenario, or credentials are needed for this offline trust record.

Repeat from this worktree with a current coordinator checkout:

ATRINIK_COORDINATOR=/path/to/atrinik \
tools/check-provenance-identity-reference.sh

Expected result: valid (2 records, 1 references) with no ATRINIK_COORDINATOR_TRUSTED_REF and no audit flag. The command is read-only and safely repeatable; no shutdown or cleanup is required.

@zoeyrose
zoeyrose marked this pull request as ready for review August 13, 2026 13:42
@zoeyrose
zoeyrose merged commit 7d7a154 into main Aug 13, 2026
10 checks passed
@zoeyrose
zoeyrose deleted the test/approved-main-provenance-386 branch August 13, 2026 13:45
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 1.1.4 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant