Skip to content

Commit dedf07f

Browse files
committed
Add commercial evidence execution verification plan
1 parent 88a34b1 commit dedf07f

7 files changed

Lines changed: 178 additions & 4 deletions

File tree

README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -72,7 +72,7 @@ The first production milestone is M3UA over a transport abstraction. SCCP, TCAP,
7272
| Supply-chain release execution | Phase 34 foundation-complete: final versioned SBOM, trusted timestamped package signing, provenance attestation, public API diff, artifact upload, ordered command-plan, release promotion gate, concrete workflow execution, status reporting, and final validation are available; retained release-run artifacts and commercial evidence are still required |
7373
| RC publish and commercial gate | Phase 35 complete: dry-run release rehearsal, gated NuGet prerelease publication, retained release notes, retained migration notes, final commercial readiness reporting, RC/stable decisioning, RC publication evidence manifest, release workflow channel wiring, status reporting, and final commercial gate report are available; stable publication remains blocked until commercial evidence is complete |
7474
| Commercial evidence readiness lockdown | Phase 36 foundation-complete: release target locking, protected secret readiness, evidence retention mapping, commercial evidence checklist, release preflight, protected release environments, dossier handoff, go/no-go gating, status reporting, and final validation are available; RC and stable publication remain blocked until retained commercial release evidence is complete |
75-
| Commercial evidence execution orchestration | Phase 37 in progress: evidence execution run identity, stage catalog, operator command plan, execution environment contract, and artifact collection manifest are available; verification, blocker handling, retry/resume, and status reporting are still being implemented |
75+
| Commercial evidence execution orchestration | Phase 37 in progress: evidence execution run identity, stage catalog, operator command plan, execution environment contract, artifact collection manifest, and digest/redaction verification are available; blocker handling, retry/resume, and status reporting are still being implemented |
7676

7777
## Requirements
7878

docs/PHASE37_COMMERCIAL_EVIDENCE_EXECUTION_ORCHESTRATION.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -66,6 +66,16 @@ The contract validates run identity values, reports missing or mismatched variab
6666

6767
The manifest validates checklist coverage, known stage ownership, unique paths, and stage-scoped artifact roots.
6868

69+
## Unit 6 - Digest And Redaction Verification Plan
70+
71+
`SigtranCommercialEvidenceExecutionVerifications` defines review requirements for each retained artifact:
72+
73+
- Every artifact requires digest verification.
74+
- Packet captures, logs, SDK traces, configurations, comparison reports, and benchmark reports require redaction review.
75+
- Every verification item must map back to an artifact manifest path.
76+
77+
This plan keeps evidence review auditable and prevents sensitive telecom traces from entering the public dossier without redaction review.
78+
6979
## Validation
7080

7181
Each unit in this phase is validated with:

docs/PHASE37_SUMMARY.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,8 @@ Phase 37 prepares the SDK to execute real commercial evidence runs after readine
99
- Operator command plan that maps each stage to an ordered run-id-aware command with approval flags for sensitive execution.
1010
- Execution environment contract that binds run identity, lab inputs, and protected secrets without storing secret values.
1111
- Artifact collection manifest that maps checklist artifacts to known stage roots and retained output paths.
12+
- Digest and redaction verification plan for every retained execution artifact.
1213

1314
## Readiness Position
1415

15-
The phase is in progress. Execution orchestration still requires digest/redaction verification, blocker classification, retry/resume policy, status reporting, and final validation.
16+
The phase is in progress. Execution orchestration still requires blocker classification, retry/resume policy, status reporting, and final validation.

docs/PHASE_INDEX.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ This index is the complete phase map for Sigtran.NET. It links each phase to the
4141
| 34 | Supply-chain release execution | [Phase 34 Supply Chain Release Execution](PHASE34_SUPPLY_CHAIN_RELEASE_EXECUTION.md), [Phase 34 Summary](PHASE34_SUMMARY.md) | Foundation complete; retained release run pending |
4242
| 35 | RC publish and commercial gate | [Phase 35 RC Publish And Commercial Gate](PHASE35_RC_PUBLISH_COMMERCIAL_GATE.md), [Phase 35 Summary](PHASE35_SUMMARY.md), [Phase 35 Commercial Gate Report](PHASE35_COMMERCIAL_GATE_REPORT.md) | RC gate foundation complete; stable publication blocked |
4343
| 36 | Commercial evidence readiness lockdown | [Phase 36 Commercial Evidence Readiness Lockdown](PHASE36_COMMERCIAL_EVIDENCE_READINESS_LOCKDOWN.md), [Phase 36 Summary](PHASE36_SUMMARY.md) | Foundation complete; real commercial evidence still required |
44-
| 37 | Commercial evidence execution orchestration | [Phase 37 Commercial Evidence Execution Orchestration](PHASE37_COMMERCIAL_EVIDENCE_EXECUTION_ORCHESTRATION.md), [Phase 37 Summary](PHASE37_SUMMARY.md) | In progress; artifact collection complete |
44+
| 37 | Commercial evidence execution orchestration | [Phase 37 Commercial Evidence Execution Orchestration](PHASE37_COMMERCIAL_EVIDENCE_EXECUTION_ORCHESTRATION.md), [Phase 37 Summary](PHASE37_SUMMARY.md) | In progress; verification plan complete |
4545

4646
## Current Commercial Gate
4747

docs/SDK_ROADMAP.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -331,7 +331,7 @@ Status: Phase 36 is foundation-complete. The release target lock binds an RC ver
331331
- Define execution stages, operator commands, environment contracts, artifact collection, digest and redaction verification, blocker handling, retry/resume behavior, and execution status.
332332
- Keep the phase separate from real passing evidence: orchestration can prepare a run, but publication remains blocked until retained artifacts prove execution success.
333333

334-
Status: Phase 37 is in progress. Evidence execution run identity now binds a locked release target to a stable run id, operator identity, UTC start time, and run-scoped artifact root. The stage catalog now covers readiness preflight, native SCTP lab, external peer interoperability, protocol validation, performance benchmark, supply-chain evidence, release workflow dry-run, and dossier assembly with run-scoped artifact roots. The operator command plan now maps every stage to an ordered run-id-aware command and requires protected approval for supply-chain, workflow, and dossier assembly execution. The environment contract now binds run identity, lab inputs, and protected secrets while preventing fixed secret values from being stored. Artifact collection now maps all checklist artifacts to known stage roots and retained output paths. Verification, blocker handling, retry/resume, status reporting, and final validation remain in progress.
334+
Status: Phase 37 is in progress. Evidence execution run identity now binds a locked release target to a stable run id, operator identity, UTC start time, and run-scoped artifact root. The stage catalog now covers readiness preflight, native SCTP lab, external peer interoperability, protocol validation, performance benchmark, supply-chain evidence, release workflow dry-run, and dossier assembly with run-scoped artifact roots. The operator command plan now maps every stage to an ordered run-id-aware command and requires protected approval for supply-chain, workflow, and dossier assembly execution. The environment contract now binds run identity, lab inputs, and protected secrets while preventing fixed secret values from being stored. Artifact collection now maps all checklist artifacts to known stage roots and retained output paths. Digest and redaction verification now requires digest coverage for every artifact and redaction review for trace-bearing evidence. Blocker handling, retry/resume, status reporting, and final validation remain in progress.
335335

336336
## Recommended First Deliverable
337337

src/Sigtran.NET.Tests/Program.cs

Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -283,6 +283,7 @@
283283
Run("SIGTRAN commercial evidence execution command plan covers stage work", SigtranCommercialEvidenceExecutionCommandPlanCoversStageWork);
284284
Run("SIGTRAN commercial evidence execution environment contract protects run inputs", SigtranCommercialEvidenceExecutionEnvironmentContractProtectsRunInputs);
285285
Run("SIGTRAN commercial evidence execution artifact manifest covers retained outputs", SigtranCommercialEvidenceExecutionArtifactManifestCoversRetainedOutputs);
286+
Run("SIGTRAN commercial evidence execution verification requires digests and redaction", SigtranCommercialEvidenceExecutionVerificationRequiresDigestsAndRedaction);
286287
Run("SIGTRAN status capabilities use domain documentation labels", SigtranStatusCapabilitiesUseDomainDocumentationLabels);
287288
Run("Native SCTP platform probe reports socket creation capability", NativeSctpPlatformProbeReportsSocketCreationCapability);
288289
Run("Native SCTP socket factory creates or reports unsupported platform", NativeSctpSocketFactoryCreatesOrReportsUnsupportedPlatform);
@@ -4674,6 +4675,42 @@ static void SigtranCommercialEvidenceExecutionArtifactManifestCoversRetainedOutp
46744675
Assert(!floatingArtifact.UsesStageArtifactRoots, "floating artifact paths should be rejected");
46754676
}
46764677

4678+
static void SigtranCommercialEvidenceExecutionVerificationRequiresDigestsAndRedaction()
4679+
{
4680+
SigtranCommercialEvidenceExecutionRun run = SigtranCommercialEvidenceExecutionRuns.CreateReleaseCandidateRun(
4681+
"1.0.0-rc.1",
4682+
"abcdef123456",
4683+
"run-20260622-001",
4684+
"release-automation",
4685+
DateTimeOffset.UtcNow);
4686+
SigtranCommercialEvidenceExecutionStageCatalog catalog = SigtranCommercialEvidenceExecutionStages.CreateDefault(run);
4687+
SigtranCommercialEvidenceExecutionArtifactManifest manifest = SigtranCommercialEvidenceExecutionArtifacts.CreateDefault(catalog);
4688+
SigtranCommercialEvidenceExecutionVerificationPlan plan = SigtranCommercialEvidenceExecutionVerifications.CreateDefault(manifest);
4689+
SigtranCommercialEvidenceExecutionVerificationPlan missingDigest = new(
4690+
manifest,
4691+
plan.Items
4692+
.Select(item => item.Kind == SigtranCommercialEvidenceChecklistKind.Sbom
4693+
? new SigtranCommercialEvidenceExecutionVerificationItem(item.ArtifactPath, item.Kind, requiresDigest: false, item.RequiresRedactionReview)
4694+
: item)
4695+
.ToArray());
4696+
SigtranCommercialEvidenceExecutionVerificationPlan missingRedaction = new(
4697+
manifest,
4698+
plan.Items
4699+
.Select(item => item.Kind == SigtranCommercialEvidenceChecklistKind.PacketCapture
4700+
? new SigtranCommercialEvidenceExecutionVerificationItem(item.ArtifactPath, item.Kind, item.RequiresDigest, requiresRedactionReview: false)
4701+
: item)
4702+
.ToArray());
4703+
4704+
Assert(plan.IsReady, plan.Describe());
4705+
Assert(plan.CoversArtifacts, "verification plan should cover all artifacts");
4706+
Assert(plan.RequiresDigestForAllArtifacts, "verification plan should require digests for all artifacts");
4707+
Assert(plan.RequiresRedactionForTraceArtifacts, "verification plan should require redaction for trace-bearing artifacts");
4708+
Assert(!missingDigest.IsReady, missingDigest.Describe());
4709+
Assert(!missingDigest.RequiresDigestForAllArtifacts, "missing digest requirement should block verification");
4710+
Assert(!missingRedaction.IsReady, missingRedaction.Describe());
4711+
Assert(!missingRedaction.RequiresRedactionForTraceArtifacts, "missing redaction review should block trace evidence");
4712+
}
4713+
46774714
static void SigtranStatusCapabilitiesUseDomainDocumentationLabels()
46784715
{
46794716
IReadOnlyList<string>[] statusCapabilities =
Lines changed: 126 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,126 @@
1+
namespace Sigtran.NET.Core.Utilities;
2+
3+
/// <summary>
4+
/// Describes verification required for one commercial evidence execution artifact.
5+
/// </summary>
6+
public sealed class SigtranCommercialEvidenceExecutionVerificationItem
7+
{
8+
/// <summary>Creates a commercial evidence execution verification item.</summary>
9+
/// <param name="artifactPath">The retained artifact path.</param>
10+
/// <param name="kind">The checklist artifact kind.</param>
11+
/// <param name="requiresDigest">Whether digest verification is required.</param>
12+
/// <param name="requiresRedactionReview">Whether redaction review is required.</param>
13+
public SigtranCommercialEvidenceExecutionVerificationItem(
14+
string artifactPath,
15+
SigtranCommercialEvidenceChecklistKind kind,
16+
bool requiresDigest,
17+
bool requiresRedactionReview)
18+
{
19+
ArtifactPath = string.IsNullOrWhiteSpace(artifactPath) ? throw new ArgumentException("Artifact path is required.", nameof(artifactPath)) : artifactPath;
20+
Kind = kind;
21+
RequiresDigest = requiresDigest;
22+
RequiresRedactionReview = requiresRedactionReview;
23+
}
24+
25+
/// <summary>The retained artifact path.</summary>
26+
public string ArtifactPath { get; }
27+
28+
/// <summary>The checklist artifact kind.</summary>
29+
public SigtranCommercialEvidenceChecklistKind Kind { get; }
30+
31+
/// <summary>Whether digest verification is required.</summary>
32+
public bool RequiresDigest { get; }
33+
34+
/// <summary>Whether redaction review is required.</summary>
35+
public bool RequiresRedactionReview { get; }
36+
37+
/// <summary>Whether this item satisfies verification requirements for its artifact kind.</summary>
38+
public bool IsReady => RequiresDigest
39+
&& (!IsTraceBearingKind(Kind) || RequiresRedactionReview);
40+
41+
/// <summary>Checks whether an artifact kind carries traffic, logs, or configuration.</summary>
42+
/// <param name="kind">The artifact kind.</param>
43+
/// <returns><c>true</c> when redaction review is required for the kind; otherwise, <c>false</c>.</returns>
44+
public static bool IsTraceBearingKind(SigtranCommercialEvidenceChecklistKind kind)
45+
{
46+
return kind is SigtranCommercialEvidenceChecklistKind.PacketCapture
47+
or SigtranCommercialEvidenceChecklistKind.PeerLog
48+
or SigtranCommercialEvidenceChecklistKind.SdkTrace
49+
or SigtranCommercialEvidenceChecklistKind.Configuration
50+
or SigtranCommercialEvidenceChecklistKind.ComparisonReport
51+
or SigtranCommercialEvidenceChecklistKind.BenchmarkReport;
52+
}
53+
}
54+
55+
/// <summary>
56+
/// Describes the commercial evidence execution digest and redaction verification plan.
57+
/// </summary>
58+
public sealed class SigtranCommercialEvidenceExecutionVerificationPlan
59+
{
60+
/// <summary>Creates a commercial evidence execution verification plan.</summary>
61+
/// <param name="manifest">The artifact manifest.</param>
62+
/// <param name="items">The verification items.</param>
63+
public SigtranCommercialEvidenceExecutionVerificationPlan(
64+
SigtranCommercialEvidenceExecutionArtifactManifest manifest,
65+
IReadOnlyList<SigtranCommercialEvidenceExecutionVerificationItem> items)
66+
{
67+
Manifest = manifest ?? throw new ArgumentNullException(nameof(manifest));
68+
ArgumentNullException.ThrowIfNull(items);
69+
Items = items.Count == 0 ? throw new ArgumentException("At least one verification item is required.", nameof(items)) : items.ToArray();
70+
}
71+
72+
/// <summary>The artifact manifest.</summary>
73+
public SigtranCommercialEvidenceExecutionArtifactManifest Manifest { get; }
74+
75+
/// <summary>The verification items.</summary>
76+
public IReadOnlyList<SigtranCommercialEvidenceExecutionVerificationItem> Items { get; }
77+
78+
/// <summary>Whether every artifact has a verification item.</summary>
79+
public bool CoversArtifacts => Manifest.Artifacts.All(artifact => Items.Any(item => item.ArtifactPath == artifact.Path));
80+
81+
/// <summary>Whether every artifact requires digest verification.</summary>
82+
public bool RequiresDigestForAllArtifacts => Items.All(static item => item.RequiresDigest);
83+
84+
/// <summary>Whether trace-bearing artifacts require redaction review.</summary>
85+
public bool RequiresRedactionForTraceArtifacts => Items
86+
.Where(static item => SigtranCommercialEvidenceExecutionVerificationItem.IsTraceBearingKind(item.Kind))
87+
.All(static item => item.RequiresRedactionReview);
88+
89+
/// <summary>Whether the verification plan is ready for evidence review.</summary>
90+
public bool IsReady => Manifest.IsReady
91+
&& CoversArtifacts
92+
&& RequiresDigestForAllArtifacts
93+
&& RequiresRedactionForTraceArtifacts
94+
&& Items.All(static item => item.IsReady);
95+
96+
/// <summary>Formats a compact verification plan summary.</summary>
97+
/// <returns>The verification plan summary.</returns>
98+
public string Describe()
99+
{
100+
return $"commercialEvidenceVerificationReady={IsReady} items={Items.Count}";
101+
}
102+
}
103+
104+
/// <summary>
105+
/// Provides commercial evidence execution verification plan helpers.
106+
/// </summary>
107+
public static class SigtranCommercialEvidenceExecutionVerifications
108+
{
109+
/// <summary>Creates the default digest and redaction verification plan.</summary>
110+
/// <param name="manifest">The artifact manifest.</param>
111+
/// <returns>The default verification plan.</returns>
112+
public static SigtranCommercialEvidenceExecutionVerificationPlan CreateDefault(SigtranCommercialEvidenceExecutionArtifactManifest manifest)
113+
{
114+
ArgumentNullException.ThrowIfNull(manifest);
115+
116+
return new(
117+
manifest,
118+
manifest.Artifacts
119+
.Select(static artifact => new SigtranCommercialEvidenceExecutionVerificationItem(
120+
artifact.Path,
121+
artifact.Kind,
122+
requiresDigest: true,
123+
requiresRedactionReview: SigtranCommercialEvidenceExecutionVerificationItem.IsTraceBearingKind(artifact.Kind)))
124+
.ToArray());
125+
}
126+
}

0 commit comments

Comments
 (0)