Skip to content

Axiom v0.8.20

Choose a tag to compare

@wheakerd wheakerd released this 29 Aug 03:26
Immutable release. Only release title and notes can be modified.
6581813

Version 0.8.20 is the release-tag controller hardening for Issue #90. It replaces the repository's manually assembled tag-creation step with one fail-closed controller contract and gives each release evidence boundary a distinct check name.

Closed Pre-Creation Decision

Create protected release tag is manual-only on refs/heads/main. Before mutation it binds the requested stable numeric version and exact matching tag, live protected-main commit and tree, both manifest versions, the two required main checks, Verify signed main history, REST and GraphQL GitHub-made signature evidence, tag and Release absence, the release App installation and repository scope, and all three live rulesets.

The controller reads that complete state twice and rejects any difference. It then attempts one exact POST /git/refs and immediately reads the ref back. It has no tag-update, tag-delete, Release-publication, or ruleset-write operation. An uncertain response is read back once and reported as a failure without retry; a later rerun rejects the existing ref with zero mutation.

Dedicated Identity Boundary

The workflow's ordinary GITHUB_TOKEN has only contents: read and checks: read. A pinned actions/create-github-app-token step explicitly targets the current owner and repository and requests only administration: read and contents: write. Its app-slug and installation-id outputs are bound into the controller, while the installation token is checked through GitHub's supported /installation/repositories endpoint. The App private key is consumed only in the release-tag-creation environment after non-secret inputs pass. No pull-request, push, release, or schedule trigger can reach it.

The controller requires the creation-only ruleset to bypass exactly the configured App Integration and rejects the current owner-user bypass. It separately requires the signature, required-check, deletion, and non-fast-forward ruleset to have no bypass actor. A break-glass operation remains a separately authorized and audited ruleset change rather than a permanent interactive-user bypass.

GitHub intentionally omits the bypass_actors property for a caller without ruleset write access. The controller keeps administration: read, binds all three ruleset IDs and normalized server update instants to the administrator-verified migration snapshot, and requires the App's effective bypass states to remain never, never, and always for main, tag integrity, and tag creation. Any ruleset edit therefore fails before mutation without granting the workflow ruleset-write authority.

Distinct Evidence Contexts

Release signature guard now emits Verify signed main history, Verify release candidate, Verify created release tag, or Observe published immutable release according to the exact event and manual phase. A manual candidate accepts only release/v<version> and remains read-only. The creation controller accepts only current protected main and its main-history result, so candidate evidence cannot authorize a production tag.

Created-tag verification still rejects movement, deletion, forced updates, malformed versions, manifest mismatch, non-main history, or a non-GitHub-made signature. Published-release observation additionally requires the live Release to be final, non-prerelease, immutable, and bound to the exact tag commit.

Regression Contract

The offline controller fixtures cover the valid single-creation path and supported installation endpoint; invalid Action identity outputs; ruleset snapshot and visibility drift; version/tag and manifest mismatch; a descendant that is not current main; candidate-context substitution; required checks from another SHA; main drift between reads; pre-existing tag or Release; an App bypass on the integrity ruleset; the superseded shared context; and an uncertain mutation response followed by a zero-mutation rerun.

A disposable bare-Git integration executes the same controller decision, creates one exact lightweight tag, verifies its target, then proves a completed or interrupted rerun cannot create a second effect. Static workflow validation also fixes the manual-only trigger, protected-main job gate, environment, token permissions, action pins, step order, and absence of tag update or deletion commands.

Live Migration Boundary

The separately authorized migration registered GitHub App ID 4756785 with slug axiom-release-tag-controller, installed it only on wheakerd/axiom as installation 157389529, and configured the release-tag-creation environment variables and private-key secret name. The secret value was not read back.

Continuous creation protection was preserved while the App was added and the owner-user bypass was removed. The administrator-visible final read-back shows only that App as the creation bypass, no bypass actor in the integrity or main ruleset, and only Verify signed main history as the integrity required context. The controller's read-only App view independently reports exact App identity and repository scope plus effective bypass states never, never, and always.

Local Static Validation

The complete standard-library suite passes 151 tests in a disposable release copy, with one expected skip for the real-Windows-only command-shell boundary. The aggregate publication validator passes with 87 required files, 105 Markdown files, 73 routing cases, 30 fixed benchmark memberships, 11 historical host records, 55 release-provenance fixtures, and 13 immutable external Action or image pins. The release-controller fixtures and disposable bare-Git integration pass.

Claude Code 2.1.220 strict offline validation passes for both the plugin manifest and marketplace manifest. Both plugin manifests, both marketplace descriptors, and both declared hook files parse as JSON. The English-only documentation scan, Markdown links, release facts, context budget, action graph, distribution drift, and publication contracts pass.

The bundled local Codex plugin-creator validator retains its documented stale-schema conflict and rejects only the unchanged supported hooks, interface.brandColorDark, and interface.supportURL fields. That result remains a non-pass and is not used to remove supported metadata. actionlint and shellcheck were unavailable and are NOT-RUN; repository-owned canonical YAML checks and exact Node execution cover the changed workflow contracts.

Installed Codex host and lifecycle observation is NOT-RUN; authenticated Claude Code installed-host and lifecycle observation is UNAVAILABLE / NOT-RUN. The change affects repository release policy and validation only; installed Skills, hooks, routes, action authority, benchmarks, and runtime dependencies are unchanged.

Exact Draft Evidence Validation

The immutable-publication path still requires one fresh content-addressed 17-case Codex routing observation bound to the exact GitHub-signed main commit, tree, stable 0.8.20 version, and v0.8.20 tag. The Release must remain non-prerelease, its tag must satisfy the production grammar, and the final evidence and attestation subjects must identify that exact version and tag.

No v0.8.20 tag, final-commit routing observation, draft Release, publication workflow, immutable Release, GitHub Latest transition, post-publication observation, Issue closure, or branch cleanup is claimed by this candidate. Earlier fail-closed controller attempts created no tag and are not rewritten as successful evidence. The immutable v0.8.19 Release and every earlier record remain separate history.

Routing Context Facts

The v0.8.20 routing-context record uses the immutable v0.7.9 using-axiom gate as its cumulative baseline. The baseline has 5,899 UTF-8 bytes, 757 whitespace-delimited words, 107 logical lines, 1 direct reference, and an estimated 1,475 tokens. The candidate has 6,960 UTF-8 bytes, 894 whitespace-delimited words, 124 logical lines, 1 direct reference, and an estimated 1,740 tokens. Its cumulative deltas are +1,061 bytes, +137 words, +17 lines, 0 references, and +265 estimated tokens. The record marks the absolute threshold reached, the relative threshold reached, and review status reviewed. The exact static counts are context proxies, and each ceil(UTF-8 bytes / 4) figure is only an estimate for the same English Markdown surface, not an exact token or credit count. Codex host and lifecycle observation remains NOT-RUN; authenticated Claude Code remains UNAVAILABLE / NOT-RUN. No host observation is inferred from these static values.