Skip to content

v1.5.1: bind audit publication seals to exact reviewer lanes #1032

Description

@jeffhuber

Follow-up to #1023, #1025 and #1028. This is reliability work for v1.5.1.

Verified failure mode

Single-lane publication works: #1052 source run 35496105953 produced one eligible Claude reviewer seal, the default-branch publisher resolved it, posted an exact-head PASS as github-actions, emitted a receipt, transitioned labels, and satisfied the authoritative gate.

A multi-lane source run remains ambiguous: #1051 run 35494919199 completed and sealed the Claude review, but submit-staged refused with SOURCE_REVIEWER_SEAL_MISSING_OR_AMBIGUOUS while another audit lane was active in the same matrix run.

The prior hosted INTERNAL_ERROR diagnosis is retained as historical evidence, but the current reproducible problem is reviewer-seal selection across multiple lanes or seal-producing jobs.

Scope

  • Bind source-seal lookup to the requested reviewer lane and exact source job/attempt identity.
  • Preserve workflow name/path/event/default-ref/run-attempt/SHA, exact PR head, contributor exclusion, replay ledger, reservation, receipt, and cleanup checks.
  • Emit fixed non-sensitive stage/status codes for unexpected API/response/runtime failures.
  • Keep single-lane behavior unchanged.

Acceptance

  • Single-lane exact-head audit publishes, receipts, transitions labels, and gates.
  • Two active independent audit lanes publish their own exact seals without ambiguity or cross-lane substitution.
  • A missing, duplicate within the same lane, forged, stale-head, wrong-job, or wrong-attempt seal fails closed.
  • Unexpected API/response/runtime failures expose only bounded safe codes.
  • Adversarial privacy and forge-resistance tests, CI, and code-mower/gate pass.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions