Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
57 changes: 57 additions & 0 deletions .adversarial-review/20260827T190803Z-iar/report.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
# Internal Adversarial Review

- Gate: IAR
- Repository: transpara-ai/agent
- Draft PR: #34
- Exact reviewed head: `f3eabbdc502963244743331b0d0b2f409dee127c`
- Author family: Codex/OpenAI
- Result: pass
- BLOCKER_COUNT: 0
- Live-head equality: local, pushed branch and draft PR head matched at review time
- Base: authenticated PR base on `main`
- Design: `TLC51-CIVILIZATION-GATE-GOVERNANCE-DESIGN@0.4.0`, Git blob `14cc032d3252855d264d28b7fbd7cb57048fc82b`
- Factory Order: Git blob `e9f75ca5a273c22e281d9a6a05a7844fe0fca878`

## Scope and changed files

- `.tlc/tlc51-migration.blocked.json`

The exact diff was checked for design/Factory Order mismatch, path-boundary drift, authority leaks, stale generated artifacts, weak validation, runtime/protected-action drift, reviewer-family assumptions and closure overclaims. The PR remained draft. The later commit containing this report is mechanical review evidence only; the implementation head above is the exact IAR subject.

## Validation

- `make verify`: pass. Repository suite passed; the only change is the fail-closed migration stop.

## Findings and dispositions

- No findings.

## Residual risks retained

- TLC51-RR-ORG-CONTROLS
- TLC51-RR-MUTABLE-PROVIDER-RECORDS
- TLC51-RR-APP-ENVIRONMENT-CAPABILITY
- TLC51-RR-DUAL-PROTOCOL-RUNTIME
- TLC51-RR-FACTORY-BINARY-SOURCE
- TLC51-RR-NONATOMIC-MULTIREPO-CUTOVER
- TLC51-RR-NONATOMIC-SETTINGS-API
- TLC51-RR-UNTRUSTED-GITHUB-CONTROLLER
- TLC51-RR-TLC-REPOSITORY-CONTROLS

These are implementation-verification obligations and fail-closed future stops. They are not satisfied or closed states.

## Non-authorizations

- PR readiness
- merge
- release or tag
- installation or distribution
- pilot or adoption
- workflow activation or settings enforcement
- runtime or deployment
- canary or rollout
- rollback or retirement
- deletion, archival, or issue closure
- any other protected effect

IAR is same-family evidence. It does not satisfy CFAR, create PR readiness, or authorize any protected effect.
42 changes: 42 additions & 0 deletions .adversarial-review/20260827T190803Z-iar/result.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
{
"gate": "IAR",
"repo": "transpara-ai/agent",
"pr_number": 34,
"head_sha": "f3eabbdc502963244743331b0d0b2f409dee127c",
"author_family": "Codex/OpenAI",
"result": "pass",
"blocker_count": 0,
"validation": [
{
"command": "make verify",
"outcome": "pass",
"evidence": "Repository suite passed; the only change is the fail-closed migration stop."
}
],
"findings": [],
"residual_risks": [
"TLC51-RR-ORG-CONTROLS",
"TLC51-RR-MUTABLE-PROVIDER-RECORDS",
"TLC51-RR-APP-ENVIRONMENT-CAPABILITY",
"TLC51-RR-DUAL-PROTOCOL-RUNTIME",
"TLC51-RR-FACTORY-BINARY-SOURCE",
"TLC51-RR-NONATOMIC-MULTIREPO-CUTOVER",
"TLC51-RR-NONATOMIC-SETTINGS-API",
"TLC51-RR-UNTRUSTED-GITHUB-CONTROLLER",
"TLC51-RR-TLC-REPOSITORY-CONTROLS"
],
"pr_visible_evidence_url": "https://github.com/transpara-ai/agent/pull/34",
"non_authorizations": [
"PR readiness",
"merge",
"release or tag",
"installation or distribution",
"pilot or adoption",
"workflow activation or settings enforcement",
"runtime or deployment",
"canary or rollout",
"rollback or retirement",
"deletion, archival, or issue closure",
"any other protected effect"
]
}
16 changes: 16 additions & 0 deletions .tlc/tlc51-migration.blocked.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
{
"schema_version": "tlc51-consumer-migration-blocked/v2",
"status": "BLOCKED",
"repository": "transpara-ai/agent",
"design_git_blob": "14cc032d3252855d264d28b7fbd7cb57048fc82b",
"current_adoption": {"path": ".tlc/adoption.json", "git_blob": "cf43a4b824b1311ac2a8c26a226bb468b69a3bd6", "version": "5.0.0", "requested_mode": "report_only", "adapter": "none"},
"retained_predecessor_workflow": {"path": ".github/workflows/tlc-4.5.yml", "git_blob": "2c9ba13f29b5c4e722cd0db36f7e87eb06614938", "mode": "audit"},
"required_check_observation": {"authenticated": true, "actor": "github:MichaelSaucier", "provider_origin": "https://api.github.com/repos/transpara-ai/agent/branches/main/protection/required_status_checks", "observed_at": "2026-08-27T19:46:55Z", "provider_etag": "W/\"c942902127f4e1b6d877ac77016d22003683221a1b2c9e468ed36e9f55fe886b\"", "provider_request_id": "B6DC:29732F:37A9402:359B074:6A90942F", "scope": "required_status_checks_only", "strict": true, "complete_governed_field_readback": false, "checks": [{"context": "Build & Test", "app_id": 15368}, {"context": "cross-family-adversarial-review", "app_id": null}]},
"new_tlc_check": {"context": "TLC 5.1 / gate", "identity_status": "PENDING_POSITIVE_NUMERIC_APP_ID", "required": false},
"reserved_paths": {"adoption": ".tlc/adoption.json", "wrapper": ".github/workflows/tlc-5.1.yml", "settings_subject": ".tlc/tlc51-settings.json", "rollback_subject": ".tlc/tlc51-settings-rollback.json"},
"required_before_wrapper_or_adoption": ["accepted annotated TLC v5.1.0 tag, binding commit, manifest and package digests", "protected exact controller head and package digest with authenticated bootstrap read-back", "resolved positive numeric TLC Check App ID", "repository-owned exact review and Human adoption decision"],
"required_before_settings_subject": ["fresh authenticated complete governed-field read-back", "every predecessor check tuple preserved exactly with provider-returned numeric or null app_id", "new TLC 5.1 / gate tuple with resolved positive numeric app_id", "separately reviewed predecessor-first rollback document"],
"preservation": {"active_tlc45_workflow_unchanged": true, "active_tlc50_adoption_unchanged": true, "provider_returned_check_tuples_recorded_exactly": true, "unknown_app_id_is_not_null": true, "new_tlc_check_not_required": true, "observation_is_not_settings_authority": true},
"authority_granted": [],
"protected_effects_invoked": []
}
Loading