Skip to content

evidence(p3): bind reproducible build hash manifest to Git - #260

Draft
Deleted user (ghost) wants to merge 2 commits into
mainfrom
agent/p3-reproducible-build-binding-v1
Draft

evidence(p3): bind reproducible build hash manifest to Git#260
Deleted user (ghost) wants to merge 2 commits into
mainfrom
agent/p3-reproducible-build-binding-v1

Conversation

@ghost

@ghost ghost commented Aug 5, 2026

Copy link
Copy Markdown

Scope

This draft records the local P3 reproducible-build lineage in Git without overstating source or distributed admission.

Added

  • .aegis/evidence/p3-reproducible-build-v1/SHA256SUMS
  • .aegis/evidence/p3-reproducible-build-v1/COMMIT_BINDING_RECEIPT_v1.6.1.json

Established

  • HASH_MANIFEST_COMMIT_BOUND = ESTABLISHED
  • authoritative bundle SHA-256 is commit-bound by reference:
    d73509bf215ff14bf91cc0232fe69a1b80cbf9a68edd305aa0a0c09ea59c3a5d
  • base binding: main@0bdffe75b56e5cd27c0632e1ba166620da327494

Deliberately not claimed

  • FULL_REPRODUCIBLE_BUILD_BINDING: pending repository presence of the exact source bytes for package_deterministic_bundle.py, target_deployment.json, and the declared build inputs.
  • DISTRIBUTED_TARGET_ADMISSION: pending independent reconstruction on a second physical host/target.
  • clean working-tree attestation: unavailable through the remote Git API.

Current commit lineage

  • SHA256SUMS commit: b47dae266a0e3cec8a95c90939aff1510c87bbe0
  • binding receipt commit: 2b72bc832430d38dda86599600d710d2d4f7658a

Keep draft until exact source bytes are committed and independently rebuilt.

@cloudflare-workers-and-pages

Copy link
Copy Markdown
Contributor

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
aegisomega 2b72bc8 Commit Preview URL

Branch Preview URL
Aug 05 2026, 04:40 AM

@vercel

vercel Bot commented Aug 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
hook-generator Ready Ready Preview Aug 5, 2026 4:44am
hub Ready Ready Preview Aug 5, 2026 4:44am
platform-picker Ready Ready Preview Aug 5, 2026 4:44am

ghost commented Aug 6, 2026

Copy link
Copy Markdown
Author

Phase 25 — corrected Antigravity local target admission handoff (v1.6.3)

This supersedes the previous v1.6.2 handoff and its evidence-package digest.

Reported execution result

  • EXECUTION_SURFACE = ANTIGRAVITY_CLI
  • LOCAL_GIT_HEAD_AND_TREE = NOT_ESTABLISHED
  • LOCAL_GIT_REPOSITORY = ABSENT
  • DIRTY_STATE = NOT_APPLICABLE
  • VERIFIED_FILE_COUNT = 9
  • AUTHORITATIVE_BUNDLE_SHA256 = d73509bf215ff14bf91cc0232fe69a1b80cbf9a68edd305aa0a0c09ea59c3a5d
  • DETERMINISTIC_REBUILD = PASSED
  • INDEPENDENT_EXECUTION_1 = PASSED
  • INDEPENDENT_EXECUTION_2 = PASSED
  • INDEPENDENT_VERIFIER = PASSED
  • FINAL_VERDICT = LOCAL_TARGET_ADMISSION_PASSED

Corrected evidence package

  • artifact: AEGIS_PHASE25_ANTIGRAVITY_ADMISSION_EVIDENCE_v1.6.3.tar.gz
  • reported SHA-256: e2da38267b0386ceb6ed0f1a601980580bc3f09b830a1d57ffd0571c8798c504
  • corrected semantics: dirty_state = null; dirty_state_applicability = NOT_APPLICABLE
  • verifier policy: reject dirty_state = false when no local Git repository exists

The previous v1.6.2 package digest 756c23d87780b1696a4b9430940a96945c02e23df14114990c7c3df8375b053a is superseded and must not be used as authority for the corrected handoff.

Authoritative source identities

  • checkpoint.py2c724562f5656c12d61faaf8e0fd79a5da496a5e46a3c7840768db517fddb279
  • deploy_verify.py6b4f8aa7c772351412f565437b44729cd8c073bf5929ed2e75f65e8667e522c6
  • package_deterministic_bundle.pyba303acbd8e944126ed0bbeaee5c49016736285e8e41eb46a39721c9e168754e
  • phase23_manifest.json04697bfa709707ae398951fee577def79357a8399551f5bb2b4292f1d87dafc2
  • runner.py4e66901570f48d4c05fbe2dd25efa7c4999bf8b0d12c5cb0fc474f2231b318f4
  • state.py73892cbfaaa849d5f6c9ddfa2b03109d72a71706cb83be6628070f65b7834166
  • target_deployment.jsonf26ec6829ea0683dcfea6ff22ec7ac2320be14b8e80f06708713761f7e2b12e6
  • telemetry.pyd370a64514c17df365872b58d2476a7a8927c8a127ecf44bd12fc7a09305a9b8
  • target_reproducible_bundle.tar.gzd73509bf215ff14bf91cc0232fe69a1b80cbf9a68edd305aa0a0c09ea59c3a5d

Not established

  • GIT_COMMIT_BINDING
  • CI_ADMISSION
  • SECOND_HOST_VERIFICATION
  • DISTRIBUTED_TARGET_ADMISSION
  • FULL_PRODUCTION_ADMISSION
  • COMMIT_BOUND_REPRODUCIBLE_BUILD

Transport boundary

This comment records the Antigravity CLI result and corrected digest. The v1.6.3 package bytes and exact textual source bytes are not yet present in this PR, so the reported package digest has not been independently recomputed from repository content here.

Keep PR #260 draft until exact source bytes are committed, Git blob/commit/tree identities are recorded, and the evidence package is published as a Release or CI artifact bound to the resulting commit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants