PRVSR Phase 1: repair Release Trust credential split (#471) - #473
Conversation
Exact-head independent review packet — PRVSR credential repairReview target is frozen at exact head:
tree:
base recorded by PR:
The PR is review-ready and mergeable. The active Independent technical review of the three-file patch finds no blocking code or authority defect:
No unresolved review threads are present. Operational limitation is explicit rather than waived: because the trusted Review recommendation: ADMIT exact head Any head movement invalidates this packet and requires fresh exact-head CI and review. |
|
HUMAN_STEWARD_DISPOSITION — PRVSR-PHASE1-CREDENTIAL-REPAIR-001 I, Human Steward, approve protected admission and merge of PR #473 at exact head: tree: 1345700c4aaea947ddebe9d70c6a52dddae7cf6a against protected base: I find the exact-head validation complete and the independent exact-head review approved. This disposition admits only the bounded PRVSR Phase 1 credential repair represented by this exact head: separation of ordinary source reads, live-ruleset administration authority, and publication authority; the zero-credential public-read fallback; and the accompanying regression protections. No GitHub App permission expansion, new required check, new merge gate, cross-repository propagation, target-PR code execution, authoritative visual status, or human-performance claim is authorized. The failed pre-repair run 31599387292 remains retained historical evidence and is not reclassified as successful. This disposition authorizes an expected-head protected merge of PR #473 only. Protected-main readback, terminal post-merge census, and a successful repaired bounded PRVSR replay on PR #465 remain mandatory before issue #471 may be closed. Any movement from exact head 6269d20 voids this disposition and requires fresh exact-head validation and review. PRVSR_PHASE1_CREDENTIAL_REPAIR_ADMITTED__POST_MERGE_REPLAY_REQUIRED |
Refs #471, #462, #459.
Trigger
Manual
Advisory PR visual statusdispatch failed in run31599387292, job94122702489, before collection atMint bounded PRVSR publisher tokenwith GitHub 422The permissions requested are not granted to this installation.The failed workflow requested one Release Trust installation token containing source-read, live-ruleset, and publisher permissions, including
actions: readandchecks: read.Repair
This candidate preserves the established Release Trust credential separation while narrowing ordinary source-read authority:
GITHUB_TOKENis job-scoped with onlycontents: read; ordinary governed reads use it when authorized and otherwise may fall back only to unauthenticated public GETs against this public repository;administration: readfor live rulesets;contents: writeandissues: writefor durable archive and advisory comment publication;ci/pr_visual_status_operational_split.pyroutes ruleset GETs only to the administration token, ordinary source reads first toGITHUB_TOKENand then, only on source 403/404, to a zero-credential public-read client, and all mutations to the publisher token;The public-read fallback carries no mutation authority and does not widen GitHub App or installation permissions.
Authority boundary
No GitHub App permission expansion is requested. No target PR code is executed. PRVSR remains derived/advisory, MATH-PROGRAMME-only, non-authoritative, and non-blocking. No required check, merge gate, cross-repository propagation, or human-performance claim is created.
Admission
This PR is review-ready. Fresh exact-head validation and independent exact-head review are required before any Human Steward merge disposition.
The failed run
31599387292remains retained evidence and is not rewritten as successful.