Defect
Protected TEPP main still contains the historical hourly LLM path that performs model/provider admission outside the canonical released contextual-orchestrator boundary. The surviving consumer repair is PR #480; it must not regress to TEPP-owned provider discovery, price ranking, mutable contextual-orchestrator source bootstrap, or provider credentials.
Active TEPP repair
PR #480 is the independently landable TEPP governance repair. Current exact head: 4475542750eda01afad0cf9ea8d563f508f63fd3.
The current branch removes the repository-local scripts/run_contextual_orchestrator.py bootstrap and provider credential/discovery/ranking authority from the scheduled model-backed workflow. AGENTS.md now requires every semantic LLM/model-backed Actions path to consume a released/versioned contextual-orchestrator contract, use only orchestrator/free plus the gateway credential, prohibit TEPP-side provider/model/group/paid-fallback selection, and distinguish administrative job limits from model-call elapsed-time termination. The workflow requires a non-draft, non-prerelease, immutable CONTEXTUAL_ORCHESTRATOR_RELEASE, an HTTPS gateway, authenticated health/model-catalog checks, and orchestrator/free; otherwise it fails closed.
The earlier redirect findings have been repaired and must not be reported as current blockers. RED 6d756d02409d0eb11a35146b9abfe41369efd2ad → repair f1da3f29ee1c9d3de6923a52d6cf26b71b96d257 constrains authenticated gateway redirects to HTTPS. RED 1f0d2ddfb3ac5d8e6c8e1c1c5c40d47c46a017c9 → current repair 4475542750eda01afad0cf9ea8d563f508f63fd3 applies the same HTTPS-only redirect policy to the checksum-pinned OpenCode archive download.
Current owner-contract blockers
Three exact-current #480 review threads remain unresolved. Two distinct findings describe the same canonical owner prerequisite, and the third is the related authentication boundary:
- A valid immutable GitHub release and a gateway that exposes
orchestrator/free are currently verified independently. The running gateway must expose authenticated release/schema/artifact provenance that can be compared to the selected immutable release; otherwise a mismatched deployment must fail closed.
- The model-controlled OpenCode process receives a reusable gateway bearer. The released contextual-orchestrator Actions contract needs scoped/ephemeral or brokered authentication so arbitrary model-controlled shell/tool execution cannot read and reuse a long-lived credential.
These are tracked in ContextualWisdomLab/contextual-orchestrator#1023. They are not justification for TEPP to recreate provider routing, invent deployment provenance, or weaken authentication. TEPP #480 should remain alive and fail closed until the owner publishes a compatible immutable contract, then add consumer REDs for missing/mismatched deployment identity and unsafe credential exposure before adopting it.
Released-contract state
Fresh contextual-orchestrator protected main is 464da4715b495b5eaaa593eba3796e2d976ee0c9; GitHub releases remain zero. A mutable owner main/open PR/checksum-pinned source archive is not production dependency authority.
Exact-head evidence
For #480 exact head 4475542750eda01afad0cf9ea8d563f508f63fd3, CodeQL PR 33631459335 ended in startup_failure; Documentation Quality 33631457327, Security Scan 33631457254, Rust Foundation CI 33631457441, Scorecard 33631457604, and OSV 33631458030 are queued; SAST Semgrep 33631457329 is pending. There is no qualifying independent current-head APPROVED review. Queued/pending/startup-failed evidence is non-passing and does not authorize bypass.
Acceptance
- TEPP contains no provider/model/group/free-price routing authority in the scheduled model-backed lane.
- Actions request only the released
orchestrator/free contract through the documented contextual-orchestrator authentication boundary; provider credentials remain owner-side.
- A compatible immutable contextual-orchestrator release exists and the running gateway proves authenticated identity/provenance bound to that release/schema/artifact.
- The model-controlled process does not receive a reusable long-lived gateway bearer; the owner contract supplies a scoped/ephemeral or brokered equivalent.
- HTTPS redirect restrictions remain enforced for authenticated gateway probes and external tool archives.
- Exact-current required workflows, current review-thread resolution, and the live ruleset's qualifying independent approval pass on the surviving TEPP head.
- Protected main receives the repair by normal merge; issue closure is not based on an unmerged branch.
Keep this issue open until those conditions reach protected main.
Defect
Protected TEPP
mainstill contains the historical hourly LLM path that performs model/provider admission outside the canonical releasedcontextual-orchestratorboundary. The surviving consumer repair is PR #480; it must not regress to TEPP-owned provider discovery, price ranking, mutable contextual-orchestrator source bootstrap, or provider credentials.Active TEPP repair
PR #480 is the independently landable TEPP governance repair. Current exact head:
4475542750eda01afad0cf9ea8d563f508f63fd3.The current branch removes the repository-local
scripts/run_contextual_orchestrator.pybootstrap and provider credential/discovery/ranking authority from the scheduled model-backed workflow.AGENTS.mdnow requires every semantic LLM/model-backed Actions path to consume a released/versioned contextual-orchestrator contract, use onlyorchestrator/freeplus the gateway credential, prohibit TEPP-side provider/model/group/paid-fallback selection, and distinguish administrative job limits from model-call elapsed-time termination. The workflow requires a non-draft, non-prerelease, immutableCONTEXTUAL_ORCHESTRATOR_RELEASE, an HTTPS gateway, authenticated health/model-catalog checks, andorchestrator/free; otherwise it fails closed.The earlier redirect findings have been repaired and must not be reported as current blockers. RED
6d756d02409d0eb11a35146b9abfe41369efd2ad→ repairf1da3f29ee1c9d3de6923a52d6cf26b71b96d257constrains authenticated gateway redirects to HTTPS. RED1f0d2ddfb3ac5d8e6c8e1c1c5c40d47c46a017c9→ current repair4475542750eda01afad0cf9ea8d563f508f63fd3applies the same HTTPS-only redirect policy to the checksum-pinned OpenCode archive download.Current owner-contract blockers
Three exact-current #480 review threads remain unresolved. Two distinct findings describe the same canonical owner prerequisite, and the third is the related authentication boundary:
orchestrator/freeare currently verified independently. The running gateway must expose authenticated release/schema/artifact provenance that can be compared to the selected immutable release; otherwise a mismatched deployment must fail closed.These are tracked in
ContextualWisdomLab/contextual-orchestrator#1023. They are not justification for TEPP to recreate provider routing, invent deployment provenance, or weaken authentication. TEPP #480 should remain alive and fail closed until the owner publishes a compatible immutable contract, then add consumer REDs for missing/mismatched deployment identity and unsafe credential exposure before adopting it.Released-contract state
Fresh contextual-orchestrator protected
mainis464da4715b495b5eaaa593eba3796e2d976ee0c9; GitHub releases remain zero. A mutable owner main/open PR/checksum-pinned source archive is not production dependency authority.Exact-head evidence
For #480 exact head
4475542750eda01afad0cf9ea8d563f508f63fd3, CodeQL PR33631459335ended instartup_failure; Documentation Quality33631457327, Security Scan33631457254, Rust Foundation CI33631457441, Scorecard33631457604, and OSV33631458030are queued; SAST Semgrep33631457329is pending. There is no qualifying independent current-headAPPROVEDreview. Queued/pending/startup-failed evidence is non-passing and does not authorize bypass.Acceptance
orchestrator/freecontract through the documented contextual-orchestrator authentication boundary; provider credentials remain owner-side.Keep this issue open until those conditions reach protected main.