Skip to content

Commit e4a4183

Browse files
committed
phase2: enforce standalone product boundary
1 parent a73fe75 commit e4a4183

9 files changed

Lines changed: 75 additions & 27 deletions

‎CHANGELOG.md‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -42,4 +42,11 @@ Nothing in this section has shipped as a tagged release.
4242
and hosted CI checks for Linux, containers, supply chain, and static
4343
analysis.
4444

45+
### Changed
46+
47+
- Clarified the standalone product boundary: consumer repositories and
48+
development-time collaboration or review tools are optional integrations,
49+
never Portable GHAR build, test, release, deployment, or runtime
50+
dependencies.
51+
4552
[Unreleased]: https://github.com/sumitake/portable-ghar/compare/main...HEAD

‎README.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,16 @@ does not operate a shared control plane on anyone's behalf. Isolation is
4343
isolation; see [Trust boundaries](#trust-boundaries) for the full,
4444
explicit non-claims list.
4545

46+
### Standalone boundary
47+
48+
Portable GHAR's source, build, tests, release artifacts, deployment tools,
49+
and runtime are self-contained in this repository plus its declared public
50+
dependencies. No consumer repository, collaboration broker, reviewer plugin,
51+
or developer workspace is a required component. External review tools are
52+
replaceable development aids, and consumer repositories are optional workload
53+
integrations selected from a deployment's live inventory; neither is part of
54+
the Portable GHAR product or a prerequisite for Phase 2 source completeness.
55+
4656
## Architecture
4757

4858
```mermaid

‎docs/superpowers/plans/2026-07-11-portable-ghar-program.md‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -340,12 +340,19 @@ unsupported browser/container jobs on `ubuntu-latest`.
340340

341341
Canary order:
342342

343-
1. the smallest public read-only, secretless build;
344-
2. workspace unit-test chain;
345-
3. workspace governance aggregate;
346-
4. application core and aggregate tests;
343+
1. the project-owned dedicated secretless recovery canary;
344+
2. one low-complexity, read-only consumer build or unit-test workload;
345+
3. one read-only multi-job aggregate workload, when eligible;
346+
4. one representative application core or aggregate workload;
347347
5. any write-capable deployment recorder only after separate review.
348348

349+
No named consumer repository or workflow is mandatory. Portable GHAR source,
350+
build, test, release, and deployment gates never clone, import, or execute a
351+
consumer repository as an implementation dependency. Deployment canaries are
352+
selected at cutover time from authenticated live inventory according to the
353+
capability and risk classes above; an unavailable or ineligible consumer is
354+
skipped rather than becoming a Portable GHAR blocker.
355+
349356
Fresh inventory immediately before migration is authoritative. A repository
350357
with no workflow that can route self-hosted is excluded from the private fleet
351358
configuration, receives no scale set or idle capacity, and is not retained as a

‎docs/superpowers/plans/2026-07-29-task11-implementation.md‎

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1783,7 +1783,7 @@ git status --short
17831783

17841784
Expected: all source tests/vet pass; only Task 11 planned files differ.
17851785

1786-
### Task 9: Obtain exact xAI/Grok review and create a signed source checkpoint
1786+
### Task 9: Obtain exact distinct-family review and create a signed source checkpoint
17871787

17881788
#### Step 1: Seal the exact review artifact
17891789

@@ -1797,9 +1797,11 @@ Include:
17971797
- exact list of pending target proofs; and
17981798
- statement that no host action or numeric choice occurred.
17991799

1800-
Run a synchronous read-only xAI/Grok exact-artifact governance review. Accept
1801-
only a substantive matching-digest result. If findings materially change the
1802-
plan, return to the plan cross-check before implementation changes.
1800+
Run a synchronous read-only distinct-family exact-artifact governance review
1801+
through any eligible reviewer route. Accept only a substantive matching-digest
1802+
result. The provider and transport are replaceable development tooling. If
1803+
findings materially change the plan, return to the plan cross-check before
1804+
implementation changes.
18031805

18041806
#### Step 2: Verify after review
18051807

@@ -1918,8 +1920,8 @@ The Task 11 source checkpoint is complete when:
19181920
- all Linux effect code is opt-in and closed;
19191921
- synthetic and actual evidence cannot substitute for each other;
19201922
- cleanup is mandatory, bounded, positively verified, and precedence-safe;
1921-
- the exact source artifact receives matching-digest substantive xAI/Grok
1922-
review; and
1923+
- the exact source artifact receives matching-digest substantive
1924+
distinct-family review through an eligible read-only route; and
19231925
- the signed commit contains only planned source/test/plan files.
19241926

19251927
Task 11's operational gate is complete only when a separately approved

‎docs/superpowers/plans/2026-07-29-task14-implementation.md‎

Lines changed: 11 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -669,9 +669,9 @@ gates.
669669
- Every implementation change is TDD: observe a targeted RED failure, make the
670670
smallest implementation change, rerun focused tests, then run the full local
671671
source gate.
672-
- Direct distinct-family review uses xAI/Grok before Anthropic/Claude. The
673-
broker is bypassed only for this session as explicitly authorized; no broker
674-
lifecycle state is read or changed.
672+
- Direct distinct-family review uses any eligible read-only route. Reviewer
673+
provider and transport are replaceable development tooling; no collaboration
674+
runtime lifecycle state is read or changed.
675675

676676
## Threat Model and Adversarial Classes
677677

@@ -1053,13 +1053,14 @@ or unregistered file may remain.
10531053
Expected on this macOS host: nonzero typed prerequisite failure. Record this
10541054
as the still-open Linux/Docker gate, not a skip/pass.
10551055

1056-
## Task 14.7: Exact Direct xAI/Grok Review and Signed Checkpoint
1056+
## Task 14.7: Exact Distinct-Family Review and Signed Checkpoint
10571057

10581058
- [ ] Seal the complete Task 14 diff plus this plan into one exact UTF-8
10591059
artifact and record byte length/SHA-256.
1060-
- [ ] Use the directly authenticated xAI/Grok CLI in read-only mode for an
1061-
exact-artifact code review. Require a substantive matching-digest verdict.
1062-
Do not use or mutate the managed broker.
1060+
- [ ] Use any eligible direct, read-only distinct-family route for an exact-
1061+
artifact code review. Require a substantive matching-digest verdict. The
1062+
provider and transport are replaceable development tooling and must not
1063+
mutate product or runtime state.
10631064
- [ ] Adjudicate every finding against exact source/tests. Material changes
10641065
require a changed-artifact confirmation review. No matching approval means
10651066
no checkpoint commit.
@@ -1088,9 +1089,9 @@ or unregistered file may remain.
10881089
release-settings GitHub App variable/secret/installation are still
10891090
operator configuration gates; and
10901091
- no deployment or host mutation occurred.
1091-
- [ ] Obtain exact-head distinct-family review with xAI/Grok before
1092-
Anthropic/Claude, satisfy required checks/compliance, resolve every review
1093-
thread, and merge without admin bypass.
1092+
- [ ] Obtain exact-head distinct-family review through an eligible read-only
1093+
route, satisfy required checks/compliance, resolve every review thread, and
1094+
merge without admin bypass.
10941095
- [ ] Read back the merge commit and `origin/main`.
10951096
- [ ] Do not label the merge as **Phase 2 fully verified**.
10961097

‎docs/superpowers/plans/2026-07-30-pr15-final-review-repair.md‎

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,9 @@ name, and HTTPS deadline contracts. This plan incorporates those constraints.
4545
phase authority returns a typed failure before effects.
4646
5. Phase 2 source completion is mergeable only when all local and hosted gates
4747
pass at one signed head, every PR review thread is resolved with evidence,
48-
and a distinct-family Grok exact-diff review reports no material defect.
48+
and an eligible read-only distinct-family exact-diff review reports no
49+
material defect. Reviewer provider and transport are replaceable development
50+
tooling, not Portable GHAR dependencies.
4951
6. After the normal PR merge and exact merge-commit readback, stop. Do not
5052
begin Phase 3, deployment, activation, or the deferred evidence PR.
5153

@@ -751,8 +753,9 @@ python3 scripts/sanitize_public.py --tracked
751753
- Create deliberate signed crash-safe commits, push, and wait for all hosted
752754
checks at the exact head.
753755
- Seal the final base-to-head artifact (byte count + SHA-256), obtain a direct
754-
xAI/Grok high-effort exact-diff review before Anthropic/Claude, and count only
755-
a matching-digest substantive approval.
756+
high-effort distinct-family exact-diff review through any eligible read-only
757+
route, and count only a matching-digest substantive approval. The provider
758+
and transport remain replaceable development tooling.
756759
- Merge PR #15 normally, never with admin bypass. Read back the PR merge commit,
757760
signature, `origin/main`, and all required checks.
758761
- Report the merged Phase 2 source checkpoint and the deferred Linux/Docker,

‎docs/superpowers/plans/2026-08-01-pr15-lifecycle-completion.md‎

Lines changed: 9 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -35,6 +35,10 @@ not fabricate those deferred external proofs.
3535
closed commands.
3636
- Preserve the approved Grafana/InfluxDB activation contract as documentation
3737
only.
38+
- Do not add an unrelated repository, collaboration broker, reviewer plugin,
39+
or developer workspace as a source, build, test, release, deployment, or
40+
runtime dependency. Review transport remains replaceable development
41+
tooling; its availability does not change Portable GHAR's product boundary.
3842

3943
## Threat and failure model
4044

@@ -344,9 +348,11 @@ the declared trusted-root boundary rather than adding cosmetic copies.
344348
Debian snapshot, sanitizer, and controller aggregate checks.
345349
7. Re-run all source/container gates available on macOS. Record Linux/Docker
346350
skips as deferred, never as passes.
347-
8. Seal the exact base-to-head diff and obtain a direct high-effort xAI/Grok
348-
exact-artifact adversarial review. Integrate any valid finding, rehash, and
349-
obtain a matching-digest approval.
351+
8. Seal the exact base-to-head diff and obtain a direct high-effort
352+
distinct-family exact-artifact adversarial review through any eligible
353+
read-only reviewer route. Review provider and transport are replaceable
354+
development tooling, not product dependencies. Integrate any valid finding,
355+
rehash, and obtain a matching-digest approval.
350356
9. Create a signed crash-safe commit, push, reply to and resolve exact-head PR
351357
threads with focused evidence, pass hosted checks, and merge normally.
352358

‎docs/superpowers/specs/2026-07-10-portable-ghar-platform-design.md‎

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,17 @@ The first implementation will:
2626

2727
This project is not an official GitHub project. Its scale-set integration depends on a public-preview upstream interface and must be presented as experimental until the compatibility and migration gates in this document pass.
2828

29+
### 1.1 Standalone dependency boundary
30+
31+
Portable GHAR source, builds, tests, release artifacts, deployment tools, and
32+
runtime depend only on this repository and its declared public dependencies.
33+
No consumer repository, collaboration broker, reviewer plugin, or developer
34+
workspace is a product dependency. Independent review tooling is replaceable
35+
development infrastructure, and deployment-time consumer workflows remain
36+
external integrations chosen from authenticated live inventory. Failure or
37+
absence of either cannot create a new Portable GHAR build, test, release, or
38+
runtime prerequisite.
39+
2940
## 2. Goals
3041

3142
1. Replace fixed, always-online runner slots with on-demand ephemeral runners.
@@ -40,6 +51,7 @@ This project is not an official GitHub project. Its scale-set integration depend
4051
10. Produce reproducible binaries and images with checksums, SBOMs, provenance, and third-party license notices.
4152
11. Survive GitHub-forced runner version bumps without manual intervention or loss of the GitHub-hosted execution path.
4253
12. Reclaim every job-scoped cgroup, tmpfs, process, namespace, and workspace by whole-container destruction, with bounded steady-state host memory and no persistent runner work area.
54+
13. Keep every mandatory source and operational contract consumer-neutral so the platform can be built, tested, deployed, and operated without any unrelated repository or development tool.
4355

4456
## 3. Non-goals
4557

‎internal/productionruntime/lifecycle_authority_test.go‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -277,7 +277,7 @@ func writeHostedHoldEvidenceFixture(
277277
FenceGeneration: 9,
278278
Route: "hosted",
279279
HoldActive: true,
280-
Repositories: []string{"keicrew", "workspace"},
280+
Repositories: []string{"example-readonly", "example-service"},
281281
NotBefore: now.Add(-time.Minute),
282282
NotAfter: now.Add(time.Minute),
283283
ProofDigest: strings.Repeat("a", 64),

0 commit comments

Comments
 (0)