Skip to content

MP-ADMIN-ADMINISTRATIVE-0813-EXECUTION-TRIGGER-001: deterministic protected-main self-kick - #563

Open
fyremael wants to merge 3 commits into
mainfrom
control/mp-admin-0813-execution-trigger-001
Open

MP-ADMIN-ADMINISTRATIVE-0813-EXECUTION-TRIGGER-001: deterministic protected-main self-kick#563
fyremael wants to merge 3 commits into
mainfrom
control/mp-admin-0813-execution-trigger-001

Conversation

@fyremael

Copy link
Copy Markdown
Contributor

Control

Successor execution-liveness repair under issue #554 / MP-ADMIN-ADMINISTRATIVE-0813-RECEIPT-RECOVERY-001.

Protected construction base: 8bbc24421c1b5b37110f608b90c95d57f19af0b2.

Exact problem

PR #562 protected the exact Aug13 closure preflight, but the candidate runtime remains dependent on GitHub scheduled-event delivery. The protected completion ledger still has administrative_review through 2026-08-10T01:21:00Z, receipt count 3; the exact Aug13 receipt has not materialized.

Bounded correction

This PR does not broaden the candidate workflow trigger contract. Instead it uses the already-governed protected-main push trigger on .github/workflows/administrative-autonomy-activation.yml, whose path allowlist already includes that workflow file itself.

The activation workflow now:

  • mints the same bounded evidence/observability token used by the candidate runtime;
  • runs ci/administrative_autonomy_0813_closure_preflight.py --apply before the activation canary;
  • skips the unrelated activation canary only when the exact Aug13 recovery reports recovered=true;
  • otherwise falls through to the existing activation canary unchanged;
  • preserves Candidate / Referee / Administration identity separation and existing protected receipt mechanics.

Because this PR changes the activation workflow itself, protected merge of this exact repair deterministically generates the required protected-main push event. No manual workflow dispatch is required.

Exact target unchanged

Validation

The mandatory tests.test_administrative_autonomy_0813_executor_binding lane now asserts:

  • the activation workflow self-path remains in the protected-main push allowlist;
  • the exact Aug13 preflight runs before the activation canary;
  • evidence/observability credentials are present;
  • successful recovery suppresses only the unrelated activation canary;
  • no-target behavior falls through.

Exclusions

No direct completion-ledger edit; no fabricated receipt branch; no #476 re-execution/re-merge; no stale #558 mutation/merge; no generalized candidate push trigger; no cadence reset; no bypass/direct protected push; no Human Steward impersonation; no mathematical/source/certification/publication/deployment/product/novelty/priority/patentability/commercial authority.

Protected admission requires exact-head machine gates, fresh independent non-author approval, streamlined Human Steward disposition, expected-head protected merge, and protected-main readback.

@fyremael
fyremael requested review from a team as code owners August 18, 2026 12:20
@fyremael
fyremael deployed to release-trust August 18, 2026 12:20 — with GitHub Actions Active
@fyremael
fyremael requested a review from jimsteeg August 18, 2026 12:20
@gcl-release-trust

gcl-release-trust Bot commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

Advisory visual status report — PRVSR-LIVE-PR563-1ef290a4c36d-20260818122602

  • operative state: UNKNOWN
  • freshness: CURRENT
  • exact PR head: 1ef290a4c36d1d47d23b56484dccbd95d153e73c
  • source snapshot SHA-256: f5b90f845a5319586140be7f87bd46d2b7bbd9916528846da04c1321e0fe3423
  • durable archive: governance/pr_visual_status_archive/grandchallenge/MATH-PROGRAMME/pr-563/PRVSR-LIVE-PR563-1ef290a4c36d-20260818122602/

This is a deterministic, derived, advisory presentation of governed source state. It does not create review, authorization, merge, certification, or propagation authority. The target PR head was not modified by archive or transport generation.

Phase 1 archive branch: prvsr-advisory-archive/pr-563
Archive path: governance/pr_visual_status_archive/grandchallenge/MATH-PROGRAMME/pr-563/PRVSR-LIVE-PR563-1ef290a4c36d-20260818122602/
Report generation or archive failure remains advisory and non-blocking.

Copy link
Copy Markdown
Contributor Author

Exact-head review packet — MP-ADMIN-ADMINISTRATIVE-0813-EXECUTION-TRIGGER-001

Review-ready and frozen.

  • exact head: 1ef290a4c36d1d47d23b56484dccbd95d153e73c;
  • protected base: 8bbc24421c1b5b37110f608b90c95d57f19af0b2;
  • exact-head workflows: 16/16 terminal SUCCESS;
  • administrative automation validation: run 32136297699SUCCESS;
  • Programme policy checks: run 32136297582SUCCESS;
  • GCL conformance: run 32136298540SUCCESS;
  • final P3 exact-tree replay: run 32136297680SUCCESS.

Changed surface is exactly three files:

  1. .github/workflows/administrative-autonomy-activation.yml — invokes the already-protected exact Aug13 closure preflight from the workflow's existing protected-main self-path push trigger; successful exact recovery skips only the unrelated activation canary; no-target falls through unchanged.
  2. tests/test_administrative_autonomy_0813_executor_binding.py — mandatory regression binds self-kick ordering, evidence credentials, recovery skip, and no-target fallthrough.
  3. governance/administrative_review_0813_execution_trigger_note.md — bounded control record.

No candidate-workflow trigger broadening; no completion-ledger edit; no fabricated receipt; no #476 re-execution/re-merge; no stale #558 mutation/merge; no bypass/direct protected push; no Human Steward impersonation; no substantive claim authority.

Fresh independent non-author APPROVED review is requested from @jimsteeg and must bind this exact unchanged head. Under the standing streamlined policy, once that review is present the delegated Human Steward disposition, expected-head protected merge, protected readback, and bounded Aug13 receipt continuation may proceed without another intermediate prompt.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant