Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions docs/OPERATIONS.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,10 @@ identity/E2E mismatch is a normal `NOT_READY` result, never a bypass.
6. Promote atomically, health-check production, and roll back on any mismatch.
7. Publish immutable machine certificates and the repository certificate graphic.

The Echo GitHub Autonomy production collector must use profile
`echo-github-autonomy-remote-mcp-v2` and exactly the three governed accounts.
Profile v1 and evidence containing the retired `Bmcbob76` identity fail closed.

## Incident triage

Capture the run ID, target SHA, environment digest, policy version, service health, dispatcher state,
Expand Down
13 changes: 8 additions & 5 deletions docs/PROJECT_CONTRACT.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,8 +52,11 @@ acceptance. Source checks, local journeys, HTTP 200, unsigned status fields, and
target-authored evidence cannot satisfy this gate. Missing, expired, untrusted,
partially passing, or identity-mismatched attestations remain `NOT_READY`.

For Echo GitHub Autonomy the target-specific profile additionally requires the
canonical MCP and OAuth surface, 30-tool schema, repeated discovery plus
invocation without registry loss, reconciled public/private inventory and
read/write/certify authority for all four exact GitHub account IDs, and matching
private-repository fingerprints from ChatGPT, Claude, Codex, and Grok.
For Echo GitHub Autonomy, target-specific profile
`echo-github-autonomy-remote-mcp-v2` additionally requires the canonical MCP
and OAuth surface, 30-tool schema, repeated discovery plus invocation without
registry loss, reconciled public/private inventory and read/write/certify
authority for exactly the three governed GitHub account IDs (`echoomegaprime`,
`ECHO-OMEGA-PRIME`, and `bobmcwilliams4`), and matching private-repository
fingerprints from ChatGPT, Claude, Codex, and Grok. The retired `Bmcbob76`
identity is invalid evidence for this profile.
5 changes: 2 additions & 3 deletions src/echo_certification_forge/production_e2e.py
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@
RULE_ID = "production_e2e"
SCHEMA_VERSION = "certforge.production-e2e.v1"
GENERIC_PROFILE = "generic-production-v1"
ECHO_GITHUB_AUTONOMY_PROFILE = "echo-github-autonomy-remote-mcp-v1"
ECHO_GITHUB_AUTONOMY_PROFILE = "echo-github-autonomy-remote-mcp-v2"
ECHO_GITHUB_AUTONOMY_REPOSITORY = "echoomegaprime/echo-github-autonomy"
ECHO_GITHUB_AUTONOMY_CANONICAL_MCP = "https://echo-ghub.grok.me/api/plugin/mcp"

Expand All @@ -44,7 +44,7 @@
"tool_schema",
"repeated_tool_invocation",
"registry_persistence",
"four_account_reconciliation",
"three_account_reconciliation",
"private_public_visibility",
"read_write_certify",
"cross_client_consistency",
Expand All @@ -53,7 +53,6 @@
ECHO_GITHUB_ACCOUNTS = {
"echoomegaprime": 314902331,
"ECHO-OMEGA-PRIME": 264607697,
"Bmcbob76": 203470412,
"bobmcwilliams4": 235318155,
}
ECHO_CLIENTS = frozenset({"chatgpt", "claude", "codex", "grok"})
Expand Down
31 changes: 27 additions & 4 deletions tests/test_production_e2e.py
Original file line number Diff line number Diff line change
Expand Up @@ -118,27 +118,29 @@ def test_echo_github_autonomy_requires_complete_exact_cross_client_e2e() -> None
(lambda value: value.__setitem__("deployment_sha", "6" * 40), "production_e2e_deployment_sha_mismatch"),
(lambda value: value.__setitem__("tool_count", 27), "production_e2e_tool_count_mismatch"),
(
lambda value: value["accounts"]["Bmcbob76"].__setitem__("private_count", 0),
lambda value: value["accounts"]["bobmcwilliams4"].__setitem__(
"private_count", 0
),
"production_e2e_account_reconciliation_failed",
),
(
lambda value: value["clients"]["grok"].__setitem__("accepted", False),
"production_e2e_client_not_accepted",
),
(
lambda value: value["accounts"]["Bmcbob76"].__setitem__(
lambda value: value["accounts"]["bobmcwilliams4"].__setitem__(
"credential_source", "model_config_pat"
),
"production_e2e_credential_source_invalid",
),
(
lambda value: value["accounts"]["Bmcbob76"].__setitem__(
lambda value: value["accounts"]["bobmcwilliams4"].__setitem__(
"secret_exposed", True
),
"production_e2e_secret_boundary_failed",
),
(
lambda value: value["sample_private_repositories"]["Bmcbob76"].__setitem__(
lambda value: value["sample_private_repositories"]["bobmcwilliams4"].__setitem__(
"repository_id", True
),
"production_e2e_sample_repository_id_invalid",
Expand All @@ -163,6 +165,27 @@ def test_stale_e2e_attestation_fails_closed() -> None:
assert reason == "production_e2e_attestation_not_current"


def test_retired_account_and_v1_profile_are_rejected() -> None:
retired_account = _payload()
retired_account["accounts"]["Bmcbob76"] = {
**retired_account["accounts"]["bobmcwilliams4"],
"account_id": 203470412,
}
valid, reason = validate_production_e2e(
retired_account, _target(), _environment(), now=NOW + timedelta(minutes=1)
)
assert not valid
assert reason == "production_e2e_accounts_incomplete"

retired_profile = _payload()
retired_profile["profile"] = "echo-github-autonomy-remote-mcp-v1"
valid, reason = validate_production_e2e(
retired_profile, _target(), _environment(), now=NOW + timedelta(minutes=1)
)
assert not valid
assert reason == "production_e2e_profile_mismatch"


def test_attestation_loader_requires_a_pinned_collector_key(tmp_path) -> None:
signer = Ed25519VerdictSigner.generate()
payload = _payload(signing_key_id=signer.key_id)
Expand Down
Loading