Skip to content

PRVSR Phase 1: repair PR conversation publisher authority (#471) - #488

Merged
fyremael merged 2 commits into
mainfrom
feature/prvsr-phase1-comment-publisher-authority-002
Aug 12, 2026
Merged

PRVSR Phase 1: repair PR conversation publisher authority (#471)#488
fyremael merged 2 commits into
mainfrom
feature/prvsr-phase1-comment-publisher-authority-002

Conversation

@fyremael

Copy link
Copy Markdown
Contributor

Scope

This is the minimal successor repair for the characterized post-merge PRVSR replay blocker recorded under #471.

The protected-main replay of #465 proved that the Phase 1 credential split itself is operational through both bounded token mints, protected implementation checkout, target resolution, and collector execution, but publication of the advisory PR conversation comment failed with GitHub 403 Resource not accessible by integration at POST /repos/grandchallenge/MATH-PROGRAMME/issues/465/comments.

Change

  • add permission-pull-requests: write to the existing bounded PRVSR publisher token;
  • retain publisher contents: write and issues: write;
  • retain the distinct administration token at exactly administration: read;
  • retain the ordinary source job token at contents: read;
  • strengthen regression coverage so the publisher permission set is exactly {contents: write, issues: write, pull-requests: write} and the administration set is exactly {administration: read}.

pull-requests: write is already granted and governed for the same Release Trust App in the protected administrative-maintenance runtime; this candidate does not expand GitHub App installation permissions.

Nonclaims

This change does not alter collector semantics, target-code execution policy, repository scope, required checks, merge gates, rulesets, mathematical claim authority, cross-repository propagation, or any Human Steward authority.

The prior replay run 31645161006 remains retained evidence: its outer workflow conclusion was success because reporting is advisory/continue-on-error, while the collector publication itself failed at the PR comment POST boundary. It must not be reclassified as a successful PRVSR replay.

Admission boundary

minimal publisher authority wiring + regression → exact-head CI → independent exact-head review → Human Steward exact-head disposition → expected-head protected merge → protected-main readback → successful bounded #465 replay → close #471

Candidate disposition, if fully admitted:

PRVSR_PHASE1_PR_COMMENT_PUBLISHER_AUTHORITY_REPAIRED__POST_MERGE_REPLAY_REQUIRED

@fyremael
fyremael marked this pull request as ready for review August 12, 2026 22:43
@fyremael
fyremael requested review from a team as code owners August 12, 2026 22:43

Copy link
Copy Markdown
Contributor Author

Exact-head independent review packet — PRVSR Phase 1 publisher authority repair

Review target is frozen at exact head:

582eeddfcb7973b9af56ea94e9ea6813bc44c65b

tree:

cc00e29f86650d5138d81a281ef9250ac712b0f0

protected base:

2d4751c3c83f4cdaa07dfa5a21e3064ff5da3a9d

Exact candidate delta is limited to two files:

  • .github/workflows/pr-visual-status-advisory.yml: add only permission-pull-requests: write to the existing bounded publisher token;
  • tests/test_pr_visual_status_credential_split.py: require the publisher permission set to be exactly {contents: write, issues: write, pull-requests: write} and the administration set to remain exactly {administration: read}.

No collector implementation code changed.

Exact-head protected validation is terminal green:

  • validate-json — SUCCESS, Programme policy run 31647474699, aggregate job 94286120328;
  • Replay LOG-GCD-001 in Lean — SUCCESS, job 94284426331;
  • Replay PC-WP04 bounded certificate — SUCCESS, job 94284426292;
  • Replay pinned Union-Closed MATHCERT evidence — SUCCESS, job 94284426422;
  • policy / policy — SUCCESS, check 94284287622;
  • security / action-policy — SUCCESS, check 94284287775.

The contracts shard 94284426626 is SUCCESS and executed the governed full python -m unittest discover -s tests -p test_*.py suite, which includes the strengthened PRVSR credential regression.

Supporting exact-head lanes are also green, including GCL conformance, administrative dispatcher, CM1, CM2, CM3, CM4, P2, P2-D, P2-E, P3, NAT concordance, C05, V0, and Euclid bridge.

Authority audit:

  • source/job token remains contents: read;
  • administration token remains exactly administration: read;
  • publisher token becomes exactly contents: write, issues: write, pull-requests: write;
  • the same Release Trust App already uses pull-requests: write in the protected administrative-maintenance runtime, so this is wiring of already-governed installation authority, not a GitHub App permission expansion;
  • active main ruleset remains Programme profile - main (17137629) with the same six strict required contexts and no review/gate drift.

Retained evidence / nonclaims:

  • replay run 31645161006 remains a collector publication failure at POST /repos/grandchallenge/MATH-PROGRAMME/issues/465/comments; its outer workflow success must not be reclassified as a successful PRVSR replay;
  • original combined-token failure run 31599387292 remains retained historical evidence;
  • this candidate does not alter collector semantics, required checks, merge gates, target-PR code execution, repository scope, rulesets, mathematical claim authority, cross-repository propagation, or Human Steward authority;
  • candidate CI cannot prove the repaired trusted workflow will publish successfully because PRVSR executes protected-main workflow code. Protected-main readback and a fresh bounded replay on CMDG-CONDENSED-CM4-P3-E-001: certify canonical finite-limit reduction #465 remain mandatory after merge.

Candidate bounded disposition:

PRVSR_PHASE1_PR_COMMENT_PUBLISHER_AUTHORITY_REPAIRED__POST_MERGE_REPLAY_REQUIRED

Independent review must bind specifically to head 582eeddfcb7973b9af56ea94e9ea6813bc44c65b and the bounded authority/nonclaim set above. Any subsequent head movement invalidates this packet and requires fresh exact-head validation and review.

@fyremael
fyremael requested a review from jimsteeg August 12, 2026 22:43
@gcl-release-trust

gcl-release-trust Bot commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

Advisory visual status report — PRVSR-LIVE-PR488-582eeddfcb79-20260812230017

  • operative state: AUTHORIZED_FOR_PROTECTED_MERGE
  • freshness: CURRENT
  • exact PR head: 582eeddfcb7973b9af56ea94e9ea6813bc44c65b
  • source snapshot SHA-256: 5ba06bcd6113024c5dd1f8d21638b4a3ccc7eba1e08926ec80ed5ad8c34e9ce9
  • durable archive: governance/pr_visual_status_archive/grandchallenge/MATH-PROGRAMME/pr-488/PRVSR-LIVE-PR488-582eeddfcb79-20260812230017/

This is a deterministic, derived, advisory presentation of governed source state. It does not create review, authorization, merge, certification, or propagation authority. The target PR head was not modified by archive or transport generation.

Phase 1 archive branch: prvsr-advisory-archive/pr-488
Archive path: governance/pr_visual_status_archive/grandchallenge/MATH-PROGRAMME/pr-488/PRVSR-LIVE-PR488-582eeddfcb79-20260812230017/
Report generation or archive failure remains advisory and non-blocking.

@fyremael

Copy link
Copy Markdown
Contributor Author

HUMAN_STEWARD_DISPOSITION — PRVSR-PHASE1-PR-COMMENT-PUBLISHER-AUTHORITY-002

I, Human Steward, approve protected admission and merge of PR #488 at exact head:

582eedd

tree:

cc00e29f86650d5138d81a281ef9250ac712b0f0

against protected base:

2d4751c

I acknowledge the independent exact-head review by jimsteeg:

review REST ID:
4921824889

review GraphQL ID:
PRR_kwDOSuWV7M8AAAABJV0WeQ

state:
APPROVED

submitted:
2026-08-12T22:57:35Z

commit_id:
582eedd

I further acknowledge that exact-head CI is terminal green, including the protected required contexts:

  • validate-json
  • Replay LOG-GCD-001 in Lean
  • Replay PC-WP04 bounded certificate
  • Replay pinned Union-Closed MATHCERT evidence
  • policy / policy
  • security / action-policy

This admission is narrowly limited to the characterized PRVSR publication-authority repair:

  • add pull-requests: write to the existing bounded PRVSR publisher token;
  • retain publisher contents: write and issues: write;
  • retain the separate administration token at exactly administration: read;
  • retain the ordinary source job token at contents: read;
  • bind the publisher authority set by regression as exactly
    {contents: write, issues: write, pull-requests: write}.

This disposition does not authorize any expansion of source-token authority, administration-token authority, repository scope, collector semantics, target-code execution, protected required checks, merge gates, mathematical claim authority, cross-repository propagation, or Human Steward authority.

The prior bounded replay run 31645161006 remains historical evidence of the characterized publication failure. Its advisory outer workflow conclusion must not be reclassified as a successful PRVSR replay.

Expected-head protected merge only.

Any movement of the candidate head, candidate tree, or protected base before merge voids this disposition and requires renewed exact-state review.

After protected merge, protected-main readback and a fresh successful bounded PRVSR replay against PR #465 are mandatory. That replay must establish successful bounded credential minting, collector execution, PR-conversation publication, and corresponding publication/readback evidence before issue #471 may close.

PRVSR_PHASE1_PR_COMMENT_PUBLISHER_AUTHORITY_REPAIRED__POST_MERGE_REPLAY_REQUIRED

@fyremael
fyremael merged commit 4f99b64 into main Aug 12, 2026
47 of 50 checks passed
@fyremael
fyremael deleted the feature/prvsr-phase1-comment-publisher-authority-002 branch August 12, 2026 23:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants