feat: certify Station v1 publication and recovery - #1
Open
joshuajbouw wants to merge 6 commits into
Open
Conversation
Certify the exact adversarially reviewed Station v2 interface tree as a coherent signed successor. Signed-off-by: Joshua J. Bouw <jjb@unicity-labs.com> AI-Disclosure: Codex | implemented Station v2 protocol, recovery, client, CLI, and integration changes; human reviewed and verified the independently tested exact-tree evidence
Certify the exact adversarially reviewed recovery protocol, tooling, and ceremony tree. Signed-off-by: Joshua J. Bouw <jjb@unicity-labs.com> AI-Disclosure: Codex | implemented Station v2 protocol, recovery, client, CLI, and integration changes; human reviewed and verified the independently tested exact-tree evidence
Create security-sensitive CLI test scratch directories beneath the canonicalized platform temp root so Linux and macOS exercise the same output-path invariant. AI-Disclosure: Codex | implemented cross-platform Station CLI test scratch paths; human reviewed and verified the full workspace tests and clippy evidence Signed-off-by: Joshua J. Bouw <jjb@unicity-labs.com>
Keep the Station client fixture compatible with current Clippy while preserving the generated mirror URL. AI-Disclosure: Codex | implemented the inline format-argument cleanup; human reviewed and verified the client suite and workspace clippy Signed-off-by: Joshua J. Bouw <jjb@unicity-labs.com>
joshuajbouw
marked this pull request as ready for review
August 26, 2026 12:37
Emit all authenticated identity shards, require exact admission binding before exposing publication records, and let the production async CLI sign Pages output without constructing a nested runtime. AI-Disclosure: Codex | implemented the production E2E fixes and regressions; Joshua reviewed the requirements and verified the tests and strict Clippy before signing and publication Signed-off-by: Joshua J. Bouw <jjb@unicity-labs.com>
joshuajbouw
force-pushed
the
codex/station-v2-certified-recovery
branch
2 times, most recently
from
August 26, 2026 14:39
8b44398 to
6815f6a
Compare
Reject publication lifecycle and mirror events that precede the exact authenticated admission during repository generation. Add a mutation-falsifiable ordering regression and an in-tree generator-to-signer-to-production-client replay and resolution test. AI-Disclosure: Codex implemented the cure and tests. Joshua J. Bouw reviewed the security invariant and verified the full workspace tests, strict Clippy, formatting, and diff checks. Signed-off-by: Joshua J. Bouw <jjb@unicity-labs.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #2
Parent campaign: astrid-runtime/astrid#1563
Summary
Internal
v2.rs,prepare-v2, schema, report, binary, and domain identifiers describe implementation formats; Station is product v1.Evidence
2cbeaf49b3029b1201671bf3ee3a3c23917a3254, tree5ba2c8a0d05d4b90654c39a536a6beb8a17549e7astrid-qualityexact-head review ACCEPTED the current tip with no P0/P10bf775f2and recovery tree972ba81dretain their prior independent ACCEPT evidenceGitHub CI and required human review remain merge gates.
Boundaries
This PR does not change the deployed Station pin, publish production keys or TUF metadata, mutate live homes, merge itself, or activate Station. Pin movement remains a separate post-merge decision.
The separate isolated Astrid lifecycle exercise found a Core consumer provenance defect: a Station-installed capsule is currently persisted as daemon-owned, so
astrid capsule updateis a no-op. That Core fix is tracked in astrid-runtime/astrid#1682 and does not weaken this repository-generation cure.AI / Tool Assistance
Assisted-by: Codex: GPT-5
Codex implemented and tested the changes. Joshua J. Bouw authorized the signed publication and reviewed the security invariants; independent exact-head review remains separate from authorship.