Skip to content

[EPIC] MCP S6 release proof and external-controller finalization #181

Description

@Joncallim

Execution mode: tracking
Parent: #172
Canonical architecture: docs/architecture/issue-181-e2e-admission-regression.md
Historical review/rationale: docs/architecture/issue-181-review-amendments.md

Issue Type

Release / regression Epic. Do not dispatch this Epic as one coding task.

Context

Most repository-side S6 architecture/test scaffolding is already on main. The current integrated S6 topology is intentionally:

  • separate signed host preflight;
  • five manifest partitions: contract, postgres, operator-desktop, operator-mobile, host-boundary;
  • four S6 suite commands: test:mcp:contract, test:mcp:postgres, e2e:mcp-operator, test:mcp:host-boundary.

A standalone test:mcp:issuance S6 suite is not missing. Integrated review moved packet-issuance proof back to #179/S4 because issuance is owned/proven there; duplicating it in S6 violated test ownership.

The repository-side S6 controller remains fail-closed (externalControllerRequired, live activation/ingress/issuance disabled by default). The major remaining gate is the independently controlled external trust lane and live signed release evidence.

Desired Outcome

S6 proves that the already-delivered S1-S5 MCP admission/context/grant/recovery behavior remains connected across real routes, PostgreSQL, operator UI and the supported hostile host boundary, and final Epic-172 readiness is enabled only with exact externally signed controller/App/host/build evidence.

S6 owns proof/integration. It does not silently redefine S1-S5 production policy.

Tasks

Acceptance Criteria

  • Repository-side S6 suites remain green and their manifest topology matches the current canonical five-partition/four-command ownership model.
  • Packet issuance remains proved by [FEATURE] S4 — Specialist prompt and bounded context packet assembly with run evidence #179/S4 and is not duplicated as an S6 policy suite.
  • Required release rules cannot be satisfied by an untrusted same-name Actions check or moving branch/tag.
  • External controller/root harness/App identity and signed evidence cannot be forged/replaced by repository checkout code.
  • Final supported-host proof is bound to exact reviewed SHA/build/image/App/check/epoch and has first-attempt/no-skip/no-retry evidence.
  • Preflight, suite, output quarantine, teardown/quiescence and destruction/reimage evidence are independently signed/verified according to the canonical contract.
  • Wrong/stale/replayed evidence, controller/lease loss, unsupported host or failed suite prevents activation/final readiness without lowering/corrupting durable evidence state.
  • Final readiness consumes the exact required receipts atomically while the provisional window/lease is still valid.
  • [OTHER][RELEASE] Complete S6 external-controller trust binding and live release evidence #357 closes with an operator/release record containing only approved sanitized/path-free evidence metadata.

Out of Scope

  • Reimplementing S1-S5.
  • Adding a new issuance suite merely because older issue text mentioned five commands.
  • Letting ordinary checkout/Actions code own external controller secrets/root authority.
  • Treating beta CI success alone as enabled-production release evidence.

Technical Notes

Issue history contains many rounds of architecture detail; the checked-in primary architecture + amendments are now the source of truth. Future implementation should work from current main and #357 rather than reconstructing the old stacked PR branches.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requesttracking-onlyREADINESS PROJECTION — Issue is a tracking/umbrella issue and is not implementation-dispatchable.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions