Skip to content

Authorize CK-07R1 consuming boundary - #445

Merged
douglasmonsky merged 3 commits into
mainfrom
docs/ck07r1-consuming-boundary-authority
Aug 19, 2026
Merged

Authorize CK-07R1 consuming boundary#445
douglasmonsky merged 3 commits into
mainfrom
docs/ck07r1-consuming-boundary-authority

Conversation

@douglasmonsky

Copy link
Copy Markdown
Owner

What changed

  • add repository standing authorization for roadmap-scoped work while preserving fail-closed and safety exclusions
  • add a versioned CK-07R1 consuming-boundary authority/schema for exactly one synthetic qualification launch after hosted-green merge and exact-main verification
  • bind worker ownership normatively to the exact existing Codex task and repository evidence without claiming runtime or cryptographic per-task authentication
  • enforce exact authority/cohort/cwd/argv/environment/interpreter/process/output/token/receipt/capacity gates at the launcher-imported verifier
  • require a non-destructive post-merge fast-forward from the prequalification base to exact merged main while preserving and recomputing the exact three dirty candidate bytes
  • keep implementation/runtime acceptance, PR CK-07R1: correct lifecycle preparation scale #394, live data, and downstream readiness unchanged

Why

The existing exact cohort is prequalified but intentionally blocked at the consuming boundary. Repository policy now explicitly defines worker identity as coordinator/orchestration ownership rather than a runtime credential. This PR encodes that policy and the narrow exactly-once transition without launching or creating runtime artifacts.

Validation

  • 180 authority-consumer tests passed
  • 67 focused lifecycle tests passed
  • 269 publication/storage/oracle tests passed
  • 9 privacy tests passed
  • exact combined preflight passed against the retained dirty three-path candidate
  • physical temporary-Git fast-forward test preserves the exact dirty cohort
  • just vp, just v, and just vc passed (1479 passed, 1 skipped; 13/13 invariants)
  • ruff, mypy, compileall, diff, scope, secrets, build, release, and package checks passed
  • Python 3.14.6 passed locally; Python 3.10 was unavailable locally and remains covered by hosted CI

Non-consuming state

No child or benchmark was launched. matching_processes=[]; output, ledger, stdout, and stderr paths remain absent; token status remains unspent_unavailable with token_consumed=false.

@douglasmonsky
douglasmonsky merged commit 213b5d2 into main Aug 19, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant