Skip to content

Load exact production E2E attestations in subscriber dispatcher - #20

Draft
echo-fleet-builder[bot] wants to merge 13 commits into
mainfrom
agent/popup-monitor-production-e2e
Draft

echo-fleet-builder[bot] wants to merge 13 commits into
mainfrom
agent/popup-monitor-production-e2e

Conversation

@echo-fleet-builder

Copy link
Copy Markdown

Summary

Restore the production subscriber-dispatcher path for independently signed, exact-identity production E2E attestations.

Scope

  • Add a root-selected directory provider keyed by exact target and environment identity digests.
  • Verify every envelope against independently pinned Ed25519 public keys.
  • Wire the provider into the durable dispatcher and immutable FORGE deployment.
  • Keep missing, malformed, untrusted, stale, and mismatched evidence fail-closed as NOT_READY.
  • Document atomic collector-envelope installation and private-key separation.

Validation

  • python -m pytest -q --durations=10: 648 passed, 3 skipped.
  • python scripts/p1_acceptance.py: passed, including default-block, source-only-blocks, and tamper-blocks.
  • git diff --check: passed.
  • Remote branch readback equals 3db2b984d8b102656662d5bd25c71ec21c9122f3.

Risks and rollback

The dispatcher loads only root-owned exact-name envelopes and never reads a collector private key. A missing or invalid envelope cannot promote a run. Rollback is the repository deploy script's captured prior release and atomic current-link restoration.

Certification state

Local verification is green. Hosted checks, exact-SHA CertForge/GitHub App evidence, and Commander acceptance remain separate gates; this PR remains draft until those readbacks are complete.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant