Skip to content

feat: add governed continuity, authenticated RLS, and recovery runtime - #1

Closed
jstar0 wants to merge 377 commits into
mainfrom
agent/grok-cli-runtime
Closed

feat: add governed continuity, authenticated RLS, and recovery runtime#1
jstar0 wants to merge 377 commits into
mainfrom
agent/grok-cli-runtime

Conversation

@jstar0

@jstar0 jstar0 commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Scope

This Draft PR carries the complete Vermory implementation and evidence history
from the independent jstar0/Vermory repository into the canonical
samekind/Vermory organization repository.

It includes PostgreSQL-authoritative workspace and conversation continuity,
thin Global Defaults, governed bridges, MCP/Web Chat/OpenClaw/Hermes clients,
formation and review loops, RLS/authentication, retrieval projections,
operations/recovery profiles, reality cases, benchmark evidence, release
packaging, GitHub OIDC keyless artifact signing, and repository collaboration
governance.

Product Boundary

  • PostgreSQL remains the only native semantic authority.
  • Models may propose but cannot silently govern.
  • Workspace-backed continuity, conversation-backed continuity, and thin Global
    Defaults remain isolated by default.
  • Cross-continuity movement remains explicit.
  • Providers and clients are compatibility targets, not a ranking exercise.
  • Gemini CLI is retired; cursor-agent is a distinct real-client target.

Migration Provenance

  • Original repository: https://github.com/jstar0/Vermory
  • Original Draft PR: https://github.com/jstar0/Vermory/pull/1
  • Source head: 3eb0c2af900d71d96963c0f5264ce9ed8c502549
  • Base head: 2fe75531c7d8e85b6d7fadf39e2b42dd70ebaac7
  • Git histories and branch SHAs match the original repository exactly.
  • The new repository is independent and is not a GitHub fork.

The original PR body exceeds GitHub's current 65,536-character creation limit.
Its complete 83,911-byte body is retained below as ordered migration comments.
Repository evidence documents remain the authoritative detailed records.

Current Delivery

The latest source head previously passed protected test and sign-snapshot
checks in the original repository. The new organization PR must pass those
checks again under the samekind/Vermory workflow identity before merge.

This PR remains draft. It requires a non-author review under the organization
repository's protected-branch policy.

jstar0 added 30 commits July 14, 2026 17:49
@jstar0

jstar0 commented Jul 22, 2026

Copy link
Copy Markdown
Contributor Author

W35 authenticated remote Web Chat qualification

Repository evidence is now committed at head e656601604ee8fc245af91b3555beaf22c345dd0.

Protected delivery

  • CI run: 29948009188, success
  • test: 89018308588, success
  • Linux service lifecycle: 89018308724, success
  • Linux service lifecycle ARM64: 89018308668, success
  • Native DEB/RPM matrix: 4/4 success
  • sign-snapshot: 89019243721, success
  • Signed artifact: 8541086171
  • Artifact ZIP SHA-256: 62fafdb6263f27cc7ba2c8e35c9ec38763863f5bc61834680cb10024b169f82a
  • Darwin ARM64 archive SHA-256: 461c2c308feb6fa4be1bf560520085ff4424fff61f8615586bb2eb805176b9c8
  • Darwin ARM64 binary SHA-256: e6c1867be8d34c6f15dc151d7f588662bbc9d308c239642a21df7c0f35d2bca9
  • Release manifest, checksums, and Sigstore pull-request workflow identity: verified

Exact-head deployment recheck

  • Mac mini user-level LaunchAgent reports revision e656601604ee8fc245af91b3555beaf22c345dd0
  • Installed binary hash matches the signed Darwin ARM64 payload
  • Public root: 200
  • Anonymous protected session: 401
  • Authenticated browser session: 200
  • Chrome 150 no-cache load: 7/7 same-origin HTTPS requests returned 200
  • Console errors, warnings, and issues: 0
  • Current source-conversation memory count after cleanup: 0
  • Cross-tenant inspection: 404, no tenant-A marker in tenant-B response

The full W35 trajectory remains 26/26 PASS in docs/evidence/2026-07-23-authenticated-remote-webchat.md and its JSON snapshot. The provider is deterministic for deployment and authority qualification; this does not create a model-quality, multi-browser, Internet-scale SLA, or general identity-product claim.

@jstar0

jstar0 commented Jul 22, 2026

Copy link
Copy Markdown
Contributor Author

I08 Linux package repository qualification is complete and retained as public evidence.

  • Accepted qualification run: https://github.com/samekind/Vermory/actions/runs/29953896649 at 858e5afc05b8136fd81d46a88164f799f2925197
  • Evidence commit: 78a6cbc87b45f32f10b43eb252f75aeac253d2bb
  • Current-head revalidation run: https://github.com/samekind/Vermory/actions/runs/29955270548, all checks successful
  • APT/DNF x AMD64/ARM64: 18/18 hard gates per leg
  • Exact I06 package bytes consumed through native package managers from file://
  • Repository metadata signatures enforced; tampered metadata rejected by APT/DNF
  • Four exact repository bundles included in the verified 16-entry OIDC/Cosign release manifest
  • Six failed implementation runs remain documented rather than erased

Evidence:

Boundary: this qualifies ephemeral CI repository signing and exact local repository bundles. It does not claim a stable production signing key, public hosted repository, mirrors, retention, cross-version lifecycle, tagged publication, or RPM payload signatures.

@jstar0

jstar0 commented Jul 22, 2026

Copy link
Copy Markdown
Contributor Author

Current PR head revalidation is complete.

  • Head: 2ba918fb75a0b9b1ec8aed971ca2be287403e9d9
  • Protected CI: https://github.com/samekind/Vermory/actions/runs/29955829716
  • Result: all checks successful, including APT/DNF x AMD64/ARM64 and OIDC sign-snapshot
  • README, required-check policy, current open boundaries, capability matrix, evaluation matrix, public evidence, and machine-readable snapshot now agree on the I08 qualification boundary.

@jstar0

jstar0 commented Jul 22, 2026

Copy link
Copy Markdown
Contributor Author

I09 Linux repository lifecycle qualification

The cross-version repository lifecycle is now evidence-closed on the implementation head and requalified on the final documentation head.

  • Accepted implementation evidence: run 29959050993 at b2076981351f3e4f2f31c86a1abcd22c04cd71ec. The six I09 artifacts and signed snapshot were independently downloaded, their GitHub ZIP digests matched, all four lifecycle reports passed 26/26, all bundle/report hashes matched, and Cosign positive, modified-manifest, and wrong-identity controls were independently rerun.
  • Final PR head: 040d4b905a4a0c00fb82bd701398ce6b94e27f16; run 29960454929 completed successfully after the evidence and matrix commit.
  • Final-head APT AMD64: job 89061158963, artifact 8545891431, 26/26.
  • Final-head APT ARM64: job 89061159023, artifact 8545896855, 26/26.
  • Final-head DNF AMD64: job 89061159001, artifact 8545898245, 26/26.
  • Final-head DNF ARM64: job 89061158960, artifact 8545893668, 26/26.
  • Final-head protected gates: test 89059936038 and sign-snapshot 89061633227 both passed.

Retained failure history remains visible in run 29958102641: attempt 1 was cancelled during the published GitHub hosted-runner delay incident; attempt 2 exposed the set -e dormant-service check defect on all four lifecycle legs. Commit b207698 replaced the bare probes with explicit conditions and added a regression test.

Evidence:

Claim boundary: this qualifies one frozen DEB/APT and RPM/DNF base-to-candidate lifecycle on native AMD64/ARM64: normal upgrade, no implicit downgrade, explicit rollback, normal re-upgrade, removal, source binding, state preservation, service dormancy, metadata-signature enforcement, and credential-free evidence. It does not qualify a stable production repository key, public hosted repository, mirrors or retention SLA, unattended updates, release tags or public version promises, database migration/rollback, RPM payload signatures, or the complete platform. I09 bundles gate signing but are not presented as release payloads; the signed release manifest remains 16 entries.

@jstar0

jstar0 commented Jul 22, 2026

Copy link
Copy Markdown
Contributor Author

I10 external withheld-evaluation protocol qualification is complete.

  • Accepted implementation head: bb3c919efbd298f47f61fb781d6e6924480a44a4
  • Implementation CI: https://github.com/samekind/Vermory/actions/runs/29962727959
  • Main test job: 89067294746
  • Protected sign-snapshot job: 89068059759
  • Signed artifact: 8546725792, ZIP SHA-256 7c42b067ec2776d0a45f31d9ae11d947634464ceffb35f10b519fdc672ed7b5f
  • 16-entry release manifest SHA-256: d4831976f1a5bb8eea80b5b838c4a4d85433fe6d364ca10c882ef8f96570f8cb
  • Sigstore bundle SHA-256: 24e5671d4a70896fe623cc008245402457c1cb2075cd5adb58765aa4bf5da737
  • Independent Cosign positive verification, modified-manifest rejection, and wrong-workflow-identity rejection all passed.
  • Final evidence/documentation head: 989bea77eeab56ee8ef87ccf9034269958897231
  • Final exact-head CI: https://github.com/samekind/Vermory/actions/runs/29963278116
  • Final main test job: 89069061061
  • Final protected sign-snapshot job: 89069740310

The repository now has strict submission v1, submission-bound attestation v2, CLI create/verify surfaces, public schemas, positive and negative controls, the frozen I10 case, and machine-checked evidence. The status is deliberately protocol-qualified only: no independent evaluator private-suite run is claimed, external_run_recorded=false, and sealed_qualified=false.

@jstar0

jstar0 commented Jul 23, 2026

Copy link
Copy Markdown
Contributor Author

I11 macOS authenticated service lifecycle qualification

Implementation source e8d2bd34ee63e4cb923287baaed1275061ef5e8b is now runtime-qualified on the ARM64 Mac mini.

  • Protected implementation CI: https://github.com/samekind/Vermory/actions/runs/29967482446
  • Mac mini run: i11-20260723-e8d2bd3-v6
  • Frozen base: 989bea77eeab56ee8ef87ccf9034269958897231
  • Signed candidate binary SHA-256: 6fbe9057986a36ef989ad0804c2f7f673af2d185cfe6bfb1b471a50c0489478d
  • Runtime report SHA-256: 6927f71866e416665a6a1e0b5fdb38fe4f505e9e3f3d70d3d7945ebb7d171e7e
  • Hard gates: 20/20
  • OpenClaw backend probe: pass
  • Hermes backend probe: pass
  • Security: environment mode 0600, protected environment files 2, plist credential matches 0, non-secret runtime credential matches 0
  • Post-run cleanup: LaunchAgent plist absent, service unloaded, database absent, runtime role absent, runtime root absent, port listener absent

The preceding 3cc50b9 v5 report was rejected as final evidence because independent post-run inspection found an unloaded LaunchAgent plist residue. e8d2bd3 added the regression assertion and cleanup fix; v6 proved zero residue.

Evidence is committed at head 2d6f06e0c5ed1881c3cd50b049a6962f49711dfd:

Final evidence-head delivery:

  • Protected CI: https://github.com/samekind/Vermory/actions/runs/29968252477
  • Test job: 89084344729
  • Sign job: 89084881517
  • Signed snapshot artifact: 8548719511
  • Artifact name: vermory-pr-snapshot-2d6f06e0c5ed1881c3cd50b049a6962f49711dfd
  • GitHub artifact digest: sha256:0af2b51ee2d5d42ee970727dc9fdb10c7e3b566c757ecb117cd61e4a41ef59dc
  • Release manifest entries: 16
  • Release manifest file SHA-256: c6ac3c4369c283639865528e352299e82fcdea5e7c8b68b2306b7072a679552a
  • Sigstore bundle SHA-256: 22ca7a3142ca403f507f09bcb2fea93143709f20995116bf96dad9193fa42856
  • Cosign PR workflow identity and GitHub OIDC issuer verification: pass
  • Darwin ARM64 binary revision: 2d6f06e0c5ed1881c3cd50b049a6962f49711dfd

Claim boundary remains narrow: no database down migration, arbitrary historical rollback, zero-downtime or long-duration SLA, model-quality claim, public exposure, notarization, system-wide installation, or new real-client qualification from the backend probes.

@jstar0

jstar0 commented Jul 23, 2026

Copy link
Copy Markdown
Contributor Author

Closing stale delivery PR pinned to 2d6f06e. The branch now contains the exact W36 commits through bc0eb0e; a fresh PR will be opened against the current remote head.

@jstar0 jstar0 closed this Jul 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant