ci: add PoCI conformance gate and runnable evidence demo - #196
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Validation completeBoth workflows passed on head
Uploaded artifact:
The Python/Rust PoCI golden-root comparison remains outside this PR and waits for #186. |
What changed
Adds the fourth PoCI v0.1 slice:
PoCIGitHub Actions workflow;test_poci*.pyconformance tests as a CI gate;ACCEPT, then detects result-digest substitution asCHALLENGE;Reviewer command
Expected decisions:
valid-action.accept.json->ACCEPTresult-digest-mismatch.challenge.json->CHALLENGE / RESULT_DIGEST_MISMATCHCI contract
The workflow fails when:
Successful runs upload
poci-conformance-<run_id>for 14 days.Security boundary
The demo proves deterministic evidence evaluation and tamper detection in the committed mock scenario. It does not prove model truthfulness, real hardware identity, TEE or zkML correctness, witness independence, or objective real-world truth.
Stacked PR
Base:
agent/poci-python-verifier-v0.1/ #195Review and merge after #195, then retarget to
mainif GitHub does not do so automatically.Backlog
Epic: #180
Advances:
Next: