Skip to content

Fix live rollback Manager evidence routing - #4

Merged
WilliamClifton-dev merged 1 commit into
mainfrom
codex/fix-live-rollback-manager
Aug 5, 2026
Merged

WilliamClifton-dev merged 1 commit into
mainfrom
codex/fix-live-rollback-manager

Conversation

@WilliamClifton-dev

Copy link
Copy Markdown
Owner

Summary

  • route paid rollback workflows through the real AgentTeams Manager room
  • collect strict role-owned events from the verified Manager and Team rooms
  • allow one Manager room plus one Team room in host-side evidence validation
  • keep sender, event ID, timestamp ordering, and binding hash checks strict

Verification

  • 171 tests passed
  • Ruff passed
  • mypy passed
  • all PowerShell scripts parsed
  • local environment dependency audit found no known vulnerabilities

Live E2E status

The workflow reached the real Manager, but DashScope returned HTTP 503 for qwen3.7-plus on all four built-in retries. No role markers or success evidence were produced, and the failed run is not represented as successful.

Route the workflow through the Manager room and collect role-owned evidence only from the Manager and Team rooms.
@WilliamClifton-dev
WilliamClifton-dev merged commit 0258d49 into main Aug 5, 2026
1 check passed
@WilliamClifton-dev
WilliamClifton-dev deleted the codex/fix-live-rollback-manager branch August 5, 2026 07:27
WilliamClifton-dev added a commit that referenced this pull request Aug 22, 2026
…A-256

The P3 follow-up originally wrapped sigstore cosign (commit b30c303).
On design review against docs/architecture/agentloom-architecture.md
the cosign path was rejected. The architecture commits to a trust
model of "evidence + self-attested digest + reproducible replay"
(sections 6.1 #4, 12.1, 12.4, ADR-005); cosign is not in that
model, and the project already publishes the submission SHA-256 in
the GitHub release body — GitHub Releases with a published digest
is the same trust model that PyPI and crates.io use, and it is the
existing third-party anchor.

This commit:

- Rewrites docs/security/signing-submission.md to lead with the
  GitHub-Releases-plus-SHA-256 verification flow, with a four-step
  curl + shasum recipe and the cross-checks for a fresh-clone
  Lite gate. Records the three reasons cosign was rejected
  (architecture trust model, evidence-schema digest redundancy,
  GitHub-Releases already is a third-party anchor).
- Adds deploy/signing/DEPRECATED.md explaining why
  sign-submission-package.ps1 is kept as an opt-in helper for
  operators with an internal sigstore requirement, and why it
  must not be wired into the public-main CI.
- Patches deploy/signing/sign-submission-package.ps1 with a
  Write-Warning at the top so a future operator who reaches for it
  sees the deprecation notice before the script runs.

The script itself is unchanged in behaviour. test-results.txt
is byte-stable; ruff / mypy / pip-audit / pytest (376 passed / 3
skipped / 0 failed) all remain green.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant