Skip to content

feat(stage2): make trusted runtime composition target-aware - #90

Merged
Robinlee0929 merged 1 commit into
mainfrom
codex/stage2-s2-ro-10-lab2-target-aware-composition
Sep 14, 2026
Merged

Robinlee0929 merged 1 commit into
mainfrom
codex/stage2-s2-ro-10-lab2-target-aware-composition

Conversation

@Robinlee0929

Copy link
Copy Markdown
Owner

Summary

Extends the existing S2-RO-10 trusted runtime composition from its historical
Lab1-only selection path to the already accepted target-aware Lab1/Lab2
contracts.

This is a bounded composition change only.

Changes

  • preserve the complete fixed target registry;
  • resolve credentials through the target-aware S2-RO-03 API;
  • acquire credentials through the target-aware S2-RO-04 API;
  • preserve exact request target ↔ endpoint ↔ credential ↔ known-host binding.

Safety invariants preserved

  • same public S2-RO-10 API;
  • same failure enum;
  • same S2-RO-01 evidence schema;
  • Owner verification still precedes replay;
  • replay remains consumed before downstream acquisition/transport;
  • downstream failure leaves authorization spent;
  • one credential read;
  • one transport invocation;
  • zero retry;
  • no Lab2→Lab1 fallback;
  • S2-RO-09 unchanged;
  • S2-RO-11 unchanged.

Validation

Focused S2-RO-10:
287 passed / 0 failed / 0 skipped

Stage 2:
1890 passed / 2 accepted safety skips / 0 failed

Full pytest:
4015 passed / 3 accepted safety skips / 0 failed

Report-index:
accepted WARN
13 optional missing
0 mandatory missing
0 failed
0 unknown

Independent security review:
PASS
0 material findings
1 accepted non-material documentation nuance

Scope

Exactly three files:

  • validation_framework/stage2_trusted_runtime_composition.py
  • tests/stage2/test_trusted_runtime_composition.py
  • docs/automation_readiness/stage2_vrrp_readonly_s2_ro_10_trusted_runtime_composition.md

Live boundary

This PR proves offline/synthetic Lab2 composition only.

OFFLINE_IMPLEMENTATION_AUTHORITY != LIVE_EXECUTION_AUTHORITY

No live Lab2 S2-RO-10 execution is authorized by this PR.

@Robinlee0929
Robinlee0929 merged commit 1eca857 into main Sep 14, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant