diff --git a/.adversarial-review/20260827T190803Z-iar/report.md b/.adversarial-review/20260827T190803Z-iar/report.md new file mode 100644 index 0000000..1f03bc9 --- /dev/null +++ b/.adversarial-review/20260827T190803Z-iar/report.md @@ -0,0 +1,57 @@ +# Internal Adversarial Review + +- Gate: IAR +- Repository: transpara-ai/agent +- Draft PR: #34 +- Exact reviewed head: `f3eabbdc502963244743331b0d0b2f409dee127c` +- Author family: Codex/OpenAI +- Result: pass +- BLOCKER_COUNT: 0 +- Live-head equality: local, pushed branch and draft PR head matched at review time +- Base: authenticated PR base on `main` +- Design: `TLC51-CIVILIZATION-GATE-GOVERNANCE-DESIGN@0.4.0`, Git blob `14cc032d3252855d264d28b7fbd7cb57048fc82b` +- Factory Order: Git blob `e9f75ca5a273c22e281d9a6a05a7844fe0fca878` + +## Scope and changed files + +- `.tlc/tlc51-migration.blocked.json` + +The exact diff was checked for design/Factory Order mismatch, path-boundary drift, authority leaks, stale generated artifacts, weak validation, runtime/protected-action drift, reviewer-family assumptions and closure overclaims. The PR remained draft. The later commit containing this report is mechanical review evidence only; the implementation head above is the exact IAR subject. + +## Validation + +- `make verify`: pass. Repository suite passed; the only change is the fail-closed migration stop. + +## Findings and dispositions + +- No findings. + +## Residual risks retained + +- TLC51-RR-ORG-CONTROLS +- TLC51-RR-MUTABLE-PROVIDER-RECORDS +- TLC51-RR-APP-ENVIRONMENT-CAPABILITY +- TLC51-RR-DUAL-PROTOCOL-RUNTIME +- TLC51-RR-FACTORY-BINARY-SOURCE +- TLC51-RR-NONATOMIC-MULTIREPO-CUTOVER +- TLC51-RR-NONATOMIC-SETTINGS-API +- TLC51-RR-UNTRUSTED-GITHUB-CONTROLLER +- TLC51-RR-TLC-REPOSITORY-CONTROLS + +These are implementation-verification obligations and fail-closed future stops. They are not satisfied or closed states. + +## Non-authorizations + +- PR readiness +- merge +- release or tag +- installation or distribution +- pilot or adoption +- workflow activation or settings enforcement +- runtime or deployment +- canary or rollout +- rollback or retirement +- deletion, archival, or issue closure +- any other protected effect + +IAR is same-family evidence. It does not satisfy CFAR, create PR readiness, or authorize any protected effect. diff --git a/.adversarial-review/20260827T190803Z-iar/result.json b/.adversarial-review/20260827T190803Z-iar/result.json new file mode 100644 index 0000000..1263a18 --- /dev/null +++ b/.adversarial-review/20260827T190803Z-iar/result.json @@ -0,0 +1,42 @@ +{ + "gate": "IAR", + "repo": "transpara-ai/agent", + "pr_number": 34, + "head_sha": "f3eabbdc502963244743331b0d0b2f409dee127c", + "author_family": "Codex/OpenAI", + "result": "pass", + "blocker_count": 0, + "validation": [ + { + "command": "make verify", + "outcome": "pass", + "evidence": "Repository suite passed; the only change is the fail-closed migration stop." + } + ], + "findings": [], + "residual_risks": [ + "TLC51-RR-ORG-CONTROLS", + "TLC51-RR-MUTABLE-PROVIDER-RECORDS", + "TLC51-RR-APP-ENVIRONMENT-CAPABILITY", + "TLC51-RR-DUAL-PROTOCOL-RUNTIME", + "TLC51-RR-FACTORY-BINARY-SOURCE", + "TLC51-RR-NONATOMIC-MULTIREPO-CUTOVER", + "TLC51-RR-NONATOMIC-SETTINGS-API", + "TLC51-RR-UNTRUSTED-GITHUB-CONTROLLER", + "TLC51-RR-TLC-REPOSITORY-CONTROLS" + ], + "pr_visible_evidence_url": "https://github.com/transpara-ai/agent/pull/34", + "non_authorizations": [ + "PR readiness", + "merge", + "release or tag", + "installation or distribution", + "pilot or adoption", + "workflow activation or settings enforcement", + "runtime or deployment", + "canary or rollout", + "rollback or retirement", + "deletion, archival, or issue closure", + "any other protected effect" + ] +} diff --git a/.tlc/tlc51-migration.blocked.json b/.tlc/tlc51-migration.blocked.json new file mode 100644 index 0000000..6a9d0cd --- /dev/null +++ b/.tlc/tlc51-migration.blocked.json @@ -0,0 +1,16 @@ +{ + "schema_version": "tlc51-consumer-migration-blocked/v2", + "status": "BLOCKED", + "repository": "transpara-ai/agent", + "design_git_blob": "14cc032d3252855d264d28b7fbd7cb57048fc82b", + "current_adoption": {"path": ".tlc/adoption.json", "git_blob": "cf43a4b824b1311ac2a8c26a226bb468b69a3bd6", "version": "5.0.0", "requested_mode": "report_only", "adapter": "none"}, + "retained_predecessor_workflow": {"path": ".github/workflows/tlc-4.5.yml", "git_blob": "2c9ba13f29b5c4e722cd0db36f7e87eb06614938", "mode": "audit"}, + "required_check_observation": {"authenticated": true, "actor": "github:MichaelSaucier", "provider_origin": "https://api.github.com/repos/transpara-ai/agent/branches/main/protection/required_status_checks", "observed_at": "2026-08-27T19:46:55Z", "provider_etag": "W/\"c942902127f4e1b6d877ac77016d22003683221a1b2c9e468ed36e9f55fe886b\"", "provider_request_id": "B6DC:29732F:37A9402:359B074:6A90942F", "scope": "required_status_checks_only", "strict": true, "complete_governed_field_readback": false, "checks": [{"context": "Build & Test", "app_id": 15368}, {"context": "cross-family-adversarial-review", "app_id": null}]}, + "new_tlc_check": {"context": "TLC 5.1 / gate", "identity_status": "PENDING_POSITIVE_NUMERIC_APP_ID", "required": false}, + "reserved_paths": {"adoption": ".tlc/adoption.json", "wrapper": ".github/workflows/tlc-5.1.yml", "settings_subject": ".tlc/tlc51-settings.json", "rollback_subject": ".tlc/tlc51-settings-rollback.json"}, + "required_before_wrapper_or_adoption": ["accepted annotated TLC v5.1.0 tag, binding commit, manifest and package digests", "protected exact controller head and package digest with authenticated bootstrap read-back", "resolved positive numeric TLC Check App ID", "repository-owned exact review and Human adoption decision"], + "required_before_settings_subject": ["fresh authenticated complete governed-field read-back", "every predecessor check tuple preserved exactly with provider-returned numeric or null app_id", "new TLC 5.1 / gate tuple with resolved positive numeric app_id", "separately reviewed predecessor-first rollback document"], + "preservation": {"active_tlc45_workflow_unchanged": true, "active_tlc50_adoption_unchanged": true, "provider_returned_check_tuples_recorded_exactly": true, "unknown_app_id_is_not_null": true, "new_tlc_check_not_required": true, "observation_is_not_settings_authority": true}, + "authority_granted": [], + "protected_effects_invoked": [] +}