Skip to content

#100: Pin validation-authority provenance - #158

Draft
justsml wants to merge 5 commits into
dan/issue-87-execution-profilefrom
dan/issue-100-validation-authority
Draft

#100: Pin validation-authority provenance#158
justsml wants to merge 5 commits into
dan/issue-87-execution-profilefrom
dan/issue-100-validation-authority

Conversation

@justsml

@justsml justsml commented Aug 27, 2026

Copy link
Copy Markdown
Owner

Split from the Wayfinder mega PR #137.

Refs #100

Scope

  • Make validation authority explicit across execution profiles, security actions, and persisted provenance.

Review notes

This PR is intentionally ticket-scoped. It does not close the referenced issue unless the issue is already complete; CI provides the final integration check.

@justsml justsml mentioned this pull request Aug 27, 2026
19 tasks
@justsml

justsml commented Aug 27, 2026

Copy link
Copy Markdown
Owner Author

Council of Dans review: repair/defer. Highest-priority gate: Critical blocker: production-capable yolo/caller approvals bypass durable server authority. Keep self/yolo synthetic-eval-only and require server authorization for every real executor. Feature flags are not a substitute for authority, evidence-integrity, or durability fixes; use typed modes only where they provide a real rollout boundary.

@justsml
justsml marked this pull request as draft August 30, 2026 23:26
@justsml

justsml commented Aug 30, 2026

Copy link
Copy Markdown
Owner Author

Council triage update: this PR is now draft and dependency-blocked on #157/#87. One full review loop found that the child delta is not yet connected to production authority paths.

P1 blockers in #100 itself:

  • no real server-owned authority resolver for strict/auto/self in the public validation tool;
  • self mode has no public model decision seam;
  • strict/auto can accept unverified model-authored evidence strings;
  • provenance is derived from mode rather than actual actor;
  • Tool Runs default to strict instead of the pinned run mode;
  • legacy permissive plans/runs are silently tightened rather than classified as yolo;
  • required UI visibility is absent.

The branch is also behind the repaired #87 parent and #87 remains draft with its own P1 blockers. Focused tests/typecheck pass, but they inject abstractions and do not exercise the missing production resolver. Per the roadmap stop rule, work is parked until #87 is release-ready and the production authority/evidence design is resolved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant