Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
91 commits
Select commit Hold shift + click to select a range
3f21f90
chore(manifest): refresh cognitive-state anchors
github-actions[bot] Jul 20, 2026
40ef577
feat(sol): define governed cross-platform control plane
Jul 20, 2026
0858def
feat(sol): add canonical execution request schema
Jul 20, 2026
642cfab
feat(sol): add canonical execution result schema
Jul 20, 2026
8640e3e
feat(sol): register governed platform capabilities
Jul 20, 2026
73e07b3
feat(sol): add fail-closed oGemma verdict adapter
Jul 20, 2026
1d8efae
test(sol): cover oGemma adapter fail-closed behavior
Jul 20, 2026
4d68e48
fix(sol): load adapter without shadowing Python platform module
Jul 20, 2026
088d7ef
ci(sol): validate cross-platform contracts and oGemma adapter
Jul 20, 2026
c2af059
docs(sol): define OpenAI agent runtime contract
Jul 20, 2026
b05e3bd
docs(sol): define Cloudflare remote MCP deployment contract
Jul 20, 2026
5a8fba9
docs(sol): define iOS operator and App Intents contract
Jul 20, 2026
ee89e25
docs(sol): define web operator console architecture
Jul 20, 2026
c1d35fa
docs(sol): define SharePoint knowledge publishing policy
Jul 20, 2026
e8a7e1d
docs(sol): add control-plane implementation map
Jul 20, 2026
a2e433b
chore(admission): add exact-parent SOL integration plan
Jul 20, 2026
dcbbbe2
fix(admission): bind SOL operator approval record hash
Jul 20, 2026
4f1c06f
feat(sol): add pinned Cloudflare MCP Worker package
Jul 20, 2026
c1c82bf
feat(sol): add strict Worker TypeScript configuration
Jul 20, 2026
dad2699
feat(sol): configure staging Cloudflare MCP Worker
Jul 20, 2026
a186bc8
chore(sol): ignore generated Worker state and secrets
Jul 20, 2026
5000cee
feat(sol): add fail-closed Cloudflare Access guards
Jul 20, 2026
eaaaf8d
feat(sol): implement governed Streamable HTTP MCP edge
Jul 20, 2026
ccd9d1f
test(sol): cover Cloudflare MCP edge guards
Jul 20, 2026
aeaf10f
ci(sol): validate Cloudflare MCP edge package
Jul 20, 2026
e09e96a
feat(sol): normalize immutable cross-provider evidence
Jul 20, 2026
d7de7ab
test(sol): enforce provider evidence immutability
Jul 20, 2026
42dd345
feat(sol): add provider evidence schema
Jul 20, 2026
528a2f9
feat(sol): add deterministic mathematical verifier
Jul 20, 2026
f238e3f
test(sol): verify quorum notation and attention monotonicity
Jul 20, 2026
e6acc79
docs(sol): record Wolfram audit of holon mathematics
Jul 20, 2026
b2d65ef
fix(admission): bind SOL protocol parent-state root
Jul 20, 2026
4cd41a7
feat(sol): add governed oGemma Hub release manifest
Jul 20, 2026
562e4e2
docs(sol): add corrected oGemma model card
Jul 20, 2026
01b6d93
feat(sol): add oGemma release preflight
Jul 20, 2026
73b5876
test(sol): enforce governed Hugging Face release preflight
Jul 20, 2026
f88edc3
feat(metacognition): add fail-closed self-regulation controller
Jul 20, 2026
9950dcd
test(metacognition): cover governed self-regulation states
Jul 20, 2026
bf82894
feat(automaton3): close governed adaptation outcomes
tarikskalic33 Jul 28, 2026
2d52aea
feat: persist authenticated outcome evidence
tarikskalic33 Jul 28, 2026
c572405
feat(provenance): verify authoritative receipts across runtimes
tarikskalic33 Jul 28, 2026
2de5fe9
feat(projection): compile receipt-backed holonngram feedback
tarikskalic33 Jul 28, 2026
d072d03
fix(authority): canonicalize workspace observation remote
Aug 1, 2026
0b87cff
chore(manifest): refresh cognitive-state anchors
github-actions[bot] Aug 1, 2026
8e22395
fix(edge): patch audited transitive dependencies
Aug 1, 2026
faaacb5
ci(sol): regenerate and verify edge lockfile
Aug 1, 2026
f620e97
ci(sol): allow explicit PR revalidation trigger
Aug 1, 2026
3452ea2
chore(replay): align cognitive manifest with current main
Aug 1, 2026
277136c
Merge 0bdffe75b56e5cd27c0632e1ba166620da327494 into 3452ea2d62beb7c4c…
Aug 1, 2026
4f8f6cc
chore(manifest): refresh cognitive-state anchors
github-actions[bot] Aug 1, 2026
27f190c
ci(sol): regenerate audited edge lockfile
Aug 1, 2026
b12ca41
fix(edge): regenerate audited dependency lockfile
Aug 1, 2026
05bb721
chore(ci): remove temporary lockfile repair workflow
Aug 1, 2026
3a88ff8
chore(ci): remove residual lockfile write workflow
Aug 1, 2026
4fa19c2
feat(governance): declare workflow write-capability allowlist
Aug 1, 2026
2e08689
feat(governance): add fail-closed workflow capability audit
Aug 1, 2026
12e2c88
ci(governance): enforce workflow write-capability gate
Aug 1, 2026
80dbc35
fix(admission): rebind PR 225 to canonical parent
tarikskalic33 Aug 15, 2026
595c2d0
fix(admission): rebind PR 225 to current canonical main
tarikskalic33 Aug 15, 2026
26aea79
fix(domain): carry canonical Cloudflare binding guard into PR 225
tarikskalic33 Aug 15, 2026
cd92037
merge(main): align PR 225 with canonical parent
tarikskalic33 Aug 15, 2026
a8ecfa4
test(organism): define persistent company-loop contract
tarikskalic33 Aug 19, 2026
8d6dc2f
feat(organism): add durable governed company loop
tarikskalic33 Aug 19, 2026
fe847d3
test(organism): define provider contribution contract
tarikskalic33 Aug 19, 2026
983dde2
feat(organism): record cross-provider contributions
tarikskalic33 Aug 19, 2026
24757bc
feat(mcp): add durable organism contribution client
tarikskalic33 Aug 19, 2026
4dd061c
feat(mcp): expose organism status and provider contributions
tarikskalic33 Aug 19, 2026
f0f00bc
test(mcp): verify provider contribution client
tarikskalic33 Aug 19, 2026
6541644
test(mcp): add organism contribution integration script
tarikskalic33 Aug 19, 2026
cb8cafc
feat(organism): persist content-addressed provider artifacts
tarikskalic33 Aug 19, 2026
f97b2a8
test(organism): cover content-addressed cross-provider work
tarikskalic33 Aug 19, 2026
7a748b7
feat(mcp): add next-work and text contribution client
tarikskalic33 Aug 19, 2026
01d6fd8
feat(authority): map organism MCP capabilities
tarikskalic33 Aug 19, 2026
5a70a1a
feat(organism): bind contributions to prepared pre-state
tarikskalic33 Aug 19, 2026
c52f85e
test(organism): cover contribution pre-state fencing
tarikskalic33 Aug 19, 2026
c72c275
feat(mcp): expose prepared contribution pre-state
tarikskalic33 Aug 19, 2026
3fc4ec8
feat(authority): bootstrap provider-bound execution identity
tarikskalic33 Aug 19, 2026
c7dde44
feat(authority): add provider session bootstrap CLI
tarikskalic33 Aug 19, 2026
0d14693
test(authority): verify provider session bootstrap bindings
tarikskalic33 Aug 19, 2026
66d74aa
feat(mcp): bootstrap provider session from live repository state
tarikskalic33 Aug 19, 2026
5e9ae26
feat(mcp): bind provider sessions to durable organism contributions
tarikskalic33 Aug 19, 2026
74b3b01
test(mcp): verify durable provider artifact workflow
tarikskalic33 Aug 19, 2026
344c386
fix(mcp): narrow local denial type
tarikskalic33 Aug 19, 2026
dff5c14
test(mcp): add provider-session organism E2E
tarikskalic33 Aug 19, 2026
6617730
test(mcp): wire provider organism E2E
tarikskalic33 Aug 19, 2026
1f9be70
fix(sol): patch vulnerable edge dependency chain
tarikskalic33 Aug 19, 2026
cbfd43d
fix(admission): rebind PR 225 to canonical main
tarikskalic33 Aug 19, 2026
0da74da
fix(governance): remove unleased Automaton-2 branch writes
tarikskalic33 Aug 19, 2026
1b2c2c5
fix(governance): make cognitive refresh mutation-free
tarikskalic33 Aug 19, 2026
f61eb2c
fix(governance): reconcile workflow write capability allowlist
tarikskalic33 Aug 19, 2026
476c236
ci(sol): expose and enforce resolved lockfile
tarikskalic33 Aug 19, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
85 changes: 85 additions & 0 deletions .aegis/experiments/pr-225-sol-cross-platform-control-plane-v1.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,85 @@
{
"schema_version": "0.1.0",
"experiment_id": "pr-225-sol-cross-platform-control-plane-v1",
"title": "Admit the non-production SOL governed cross-platform control-plane foundation",
"repository": "Aegis-Omega/AEGIS-OMEGA",
"execution_class": "EXPERIMENT",
"evidence_tier": "T1",
"expected_parent_sha": "32b7eb6a37fb69d19dd80189390b6641c5004ef1",
"expected_parent_state_root": "7ae848d409f35b2804fbcb009a43df1d9da0a5fbd348564b81d771863223e253",
"constitution": {
"path": "CONSTITUTIONAL_DECLARATION.md",
"blob_id": "d0c210443e03313113e43da46c4d98269494baeb"
},
"policy": {
"path": "platform/sol/SPEC.md",
"blob_id": "621e549e9cfa047f5f0d56b31597b1854bea4bb9"
},
"sovereignty_contracts": {
"path": "sovereign-omega-v2/src/sovereignty/contracts.ts",
"blob_id": "d53860f1340293cf08955ebb8729a853432551eb"
},
"admission_executable": {
"path": "sovereign-omega-v2/scripts/validate-experiment-plan.ts",
"blob_id": "b9c998ddc85b9beeefec30121e88e828b15a8405"
},
"admission_workflow": {
"path": ".github/workflows/experiment-admission.yml",
"blob_id": "01a59d129b0431c9ccb92b1227a0e46992b1562f"
},
"integration_ledger_generator": {
"path": "scripts/integration_ledger.py",
"blob_id": "28823ae5b630be273b78210f0addf9c0a86aad05"
},
"claims_ledger": {
"path": ".aegis/claims-ledger.json",
"root": "495a01d7a942d5f90b39f2d2b178b074aee60c5e6460e1622f1917982ac59652"
},
"budget": {
"max_cost_microunits": 0,
"max_duration_seconds": 3600,
"max_mutations": 0
},
"observability": {
"provider": "github-actions",
"durable_execution_required": true,
"heartbeat_max_seconds": 300,
"cancellation_mechanism": "github-actions-cancel-run",
"emergency_stop_reference": "github-actions:cancel-run"
},
"operator_approval": {
"required": true,
"state": "APPROVED",
"operator_actor_id": "tarikskalic",
"operator_session_id": "chatgpt-session-2026-07-20-sol-control-plane",
"authorization_basis": "user-explicit-sol-cross-platform-control-plane",
"decided_at": "2026-07-20T18:20:00Z",
"approval_record_hash": "dbe281ec13d2ac473ed9ecb44677d6d3e4450c1924db1d55f3dee81bf196ab73",
"signature_mode": "GITHUB_OIDC_ATTESTATION"
},
"requested_authority_domains": [
"github:artifact-metadata-write",
"github:attestation-write",
"github:workflow-artifact-write"
],
"termination_conditions": [
"budget_exhausted",
"observability_expired",
"operator_emergency_stop"
],
"expected_outputs": [
"ADMISSION_RECEIPT.json",
"EVIDENCE_MANIFEST.json",
"EXPERIMENT_PLAN.json",
"INTEGRATION_LEDGER.json",
"INTEGRATION_LEDGER.md",
"SHA256SUMS"
],
"replay_package": {
"required": true,
"include_plan": true,
"include_admission_receipt": true,
"include_evidence_manifest": true,
"include_integration_ledger": true
}
}
6 changes: 3 additions & 3 deletions .claude.json
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,8 @@
"provenance": {
"generator": "scripts/build-cognitive-manifest.py",
"repository": "Aegis-Omega/AEGIS-OMEGA",
"source_ref": "claude/blissful-rubin-mt9jS",
"parent_state_hash": "410bcd49c721e65050382ae759db7af2f41fa9f572e625174252c72a8748ea93",
"source_ref": "feat/sol-cross-platform-control-plane",
"parent_state_hash": "e9f0ec153b0b320a1e791092f73209442ec43a982e503203d9c101ec40949cba",
"signature_mode": "GITHUB_OIDC_ATTESTATION"
},
"hashing": {
Expand Down Expand Up @@ -488,5 +488,5 @@
"on_success": "broadcast-attested-verified-event-stream"
}
},
"state_hash": "e9f0ec153b0b320a1e791092f73209442ec43a982e503203d9c101ec40949cba"
"state_hash": "1726a5ac63348cbb6e5175588cd98de01ecaa2867556aa8f5086bb77cc6675fe"
}
19 changes: 4 additions & 15 deletions .github/workflows/automaton-2.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ on:
branches: [main]

permissions:
contents: write
contents: read
id-token: write
attestations: write
artifact-metadata: write
Expand Down Expand Up @@ -76,23 +76,12 @@ jobs:
if-no-files-found: error
retention-days: 90

- name: Promote anchors on same-repository PR
if: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository }}
- name: Verify committed anchors match governed candidate
shell: bash
run: |
set -euo pipefail
if cmp -s "$RUNNER_TEMP/cognitive-anchors/.claude.json" .claude.json 2>/dev/null && \
cmp -s "$RUNNER_TEMP/cognitive-anchors/skill-hashes.sha256" skill-hashes.sha256 2>/dev/null; then
echo "Committed anchors already current."
exit 0
fi
cp "$RUNNER_TEMP/cognitive-anchors/.claude.json" .claude.json
cp "$RUNNER_TEMP/cognitive-anchors/skill-hashes.sha256" skill-hashes.sha256
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add .claude.json skill-hashes.sha256
git commit -m "chore(manifest): promote governed cognitive anchors"
git push origin "HEAD:${{ github.event.pull_request.head.ref }}"
cmp "$RUNNER_TEMP/cognitive-anchors/.claude.json" .claude.json
cmp "$RUNNER_TEMP/cognitive-anchors/skill-hashes.sha256" skill-hashes.sha256

- name: Run Automaton-2 negative and determinism tests
run: python sovereign-omega-v2/python/tests/test_automaton2.py
Expand Down
22 changes: 18 additions & 4 deletions .github/workflows/automaton-3.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,10 +47,12 @@ jobs:
with:
node-version: '20'
cache: npm
cache-dependency-path: sovereign-omega-v2/mcp-server/package-lock.json
cache-dependency-path: |
sovereign-omega-v2/package-lock.json
sovereign-omega-v2/mcp-server/package-lock.json

- name: Install exact schema validator
run: pip install jsonschema==4.23.0
- name: Install exact schema and signature validators
run: pip install --requirement harness/requirements-automaton3.txt

- name: Validate JSON schemas
shell: bash
Expand All @@ -60,7 +62,7 @@ jobs:
import json
from pathlib import Path
from jsonschema.validators import validator_for
for path in sorted(Path('schemas').glob('*-envelope.v1.schema.json')) + sorted(Path('schemas').glob('*-receipt.v1.schema.json')) + [Path('schemas/writer-lease.v1.schema.json')]:
for path in sorted(Path('schemas').glob('*-envelope.v1.schema.json')) + sorted(Path('schemas').glob('*-receipt.v1.schema.json')) + [Path('schemas/writer-lease.v1.schema.json'), Path('schemas/receipt-trust-registry.v1.schema.json')]:
schema = json.loads(path.read_text(encoding='utf-8'))
validator_for(schema).check_schema(schema)
print(f'SCHEMA_OK {path}')
Expand All @@ -81,6 +83,16 @@ jobs:
npm run test:resources
npm run test:automaton3 | tee "$RUNNER_TEMP/AUTOMATON3_MCP.log"

- name: Verify cross-runtime authoritative receipt provenance
working-directory: sovereign-omega-v2
shell: bash
run: |
set -euo pipefail
npm ci
npm run typecheck
npm test -- --reporter=dot
npm run build

- name: Validate claims and constitutional anchors
shell: bash
run: |
Expand Down Expand Up @@ -157,3 +169,5 @@ jobs:
harness/policies/capability-map.v1.json
schemas/execution-identity-envelope.v1.schema.json
schemas/mutation-receipt.v1.schema.json
schemas/cross-runtime-receipt-envelope.v1.schema.json
schemas/receipt-trust-registry.v1.schema.json
34 changes: 17 additions & 17 deletions .github/workflows/cognitive-manifest-refresh.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ on:
workflow_dispatch:

permissions:
contents: write
contents: read

concurrency:
group: cognitive-manifest-refresh-${{ github.ref }}
Expand Down Expand Up @@ -40,26 +40,26 @@ jobs:
fi
echo "state_hash=$parent_hash" >> "$GITHUB_OUTPUT"

- name: Generate deterministic anchors
- name: Generate deterministic anchors without mutating branch
shell: bash
run: |
set -euo pipefail
out="$RUNNER_TEMP/cognitive-anchors"
python scripts/build-cognitive-manifest.py \
--ref "$GITHUB_REF_NAME" \
--parent-state-hash "${{ steps.parent.outputs.state_hash }}"
--parent-state-hash "${{ steps.parent.outputs.state_hash }}" \
--output-dir "$out"
python scripts/build-cognitive-manifest.py \
--check \
--ref "$GITHUB_REF_NAME" \
--parent-state-hash "${{ steps.parent.outputs.state_hash }}"
--parent-state-hash "${{ steps.parent.outputs.state_hash }}" \
--output-dir "$out"

- name: Commit refreshed anchors
shell: bash
run: |
set -euo pipefail
if git diff --quiet -- .claude.json skill-hashes.sha256; then
echo "Manifest already current."
exit 0
fi
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add .claude.json skill-hashes.sha256
git commit -m "chore(manifest): refresh cognitive-state anchors"
git push origin "HEAD:${GITHUB_REF_NAME}"
- name: Upload proposed anchors for governed admission
uses: actions/upload-artifact@v4
with:
name: aegis-cognitive-anchor-candidate-${{ github.sha }}
path: ${{ runner.temp }}/cognitive-anchors
include-hidden-files: true
if-no-files-found: error
retention-days: 90
101 changes: 101 additions & 0 deletions .github/workflows/sol-integration.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,101 @@
name: SOL Cross-Platform Integration

on:
pull_request:
branches: [main]
paths:
- 'platform/sol/**'
- '.github/workflows/sol-integration.yml'
merge_group:
branches: [main]
push:
branches: [main]
paths:
- 'platform/sol/**'
- '.github/workflows/sol-integration.yml'

permissions:
contents: read

jobs:
contracts:
name: aegis / sol-contracts
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Checkout exact candidate
uses: actions/checkout@v4

- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: '3.12'

- name: Install pinned schema validator
run: python -m pip install jsonschema==4.23.0

- name: Validate JSON and schemas
shell: bash
run: |
set -euo pipefail
python - <<'PY'
import json
from pathlib import Path
from jsonschema.validators import validator_for

root = Path('platform/sol')
for path in sorted(root.rglob('*.json')):
data = json.loads(path.read_text(encoding='utf-8'))
if path.name.endswith('.schema.json'):
validator_for(data).check_schema(data)
print(f'JSON_OK {path}')
PY

- name: Run fail-closed oGemma adapter tests
run: python -m unittest discover -s platform/sol/tests -p 'test_*.py' -v

- name: Verify no production credentials or mutable state are committed
shell: bash
run: |
set -euo pipefail
! grep -RInE '(hf_[A-Za-z0-9]{20,}|sk-[A-Za-z0-9_-]{20,}|BEGIN (RSA|OPENSSH|EC) PRIVATE KEY)' platform/sol
! find platform/sol -type f \( -name '*.sqlite' -o -name '*.db' -o -name '*.pem' -o -name '.env' \) -print -quit | grep .

edge-mcp:
name: aegis / sol-edge-mcp
runs-on: ubuntu-latest
timeout-minutes: 15
defaults:
run:
working-directory: platform/sol/cloudflare/worker
steps:
- name: Checkout exact candidate
uses: actions/checkout@v4

- name: Set up Node
uses: actions/setup-node@v4
with:
node-version: '24.11.0'

- name: Install pinned dependencies without lifecycle scripts
run: npm install --ignore-scripts

- name: Generate Worker bindings and typecheck
run: npm run typecheck

- name: Run fail-closed edge tests
run: npm test

- name: Audit installed dependency graph
run: npm audit --audit-level=high

- name: Upload resolved lockfile for reconciliation
uses: actions/upload-artifact@v4
with:
name: sol-edge-resolved-lock-${{ github.event.pull_request.head.sha || github.sha }}
path: platform/sol/cloudflare/worker/package-lock.json
if-no-files-found: error
retention-days: 7

- name: Require resolved lockfile to be committed
run: git diff --exit-code -- package-lock.json
37 changes: 37 additions & 0 deletions .github/workflows/write-capability-gate.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
name: Workflow Write Capability Gate

on:
pull_request:
branches:
- main
paths:
- '.github/workflows/**'
- '.github/write-capability-allowlist.yml'
- 'scripts/audit-workflow-write-capabilities.py'
push:
branches:
- feat/sol-cross-platform-control-plane
paths:
- '.github/workflows/**'
- '.github/write-capability-allowlist.yml'
- 'scripts/audit-workflow-write-capabilities.py'
workflow_dispatch:

permissions:
contents: read

jobs:
audit-workflow-write-capabilities:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Checkout exact candidate
uses: actions/checkout@v4

- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: '3.13'

- name: Audit privileged workflows and branch writers
run: python scripts/audit-workflow-write-capabilities.py
Loading
Loading