Skip to content

fix: bind Azure receipts to exact review evidence - #325

Merged
ruby-dlee merged 1 commit into
mainfrom
codex/azure-receipt-fix
Aug 24, 2026
Merged

fix: bind Azure receipts to exact review evidence#325
ruby-dlee merged 1 commit into
mainfrom
codex/azure-receipt-fix

Conversation

@ruby-dlee

Copy link
Copy Markdown
Owner

Intent

Get the regular GLM 5.2 Azure Crosscheck lane up and working reliably for Firstmate without overbuilding day-one enterprise machinery. Preserve exact-head review evidence, model-family independence, credential isolation, fail-closed cloud cleanup, and the trusted host and Azure VM identity bindings. Fix the live failure where a credentialless Azure evidence VM was required to echo private paths belonging to the separate model VM, even though those paths were already independently host-bound and copying them into a receipt proved nothing. Keep the remote receipt bound to its distinctive marker and exact base and head SHAs, leave local reviewer receipts unchanged, add behavioral regression coverage and concise operator documentation, use no Bugbot, and ship through green CI. Focused Crosscheck tests, the full Azure contract suite, and the complete repository lint already passed before this run, so duplicate local test and lint stages are intentionally skipped while CI remains required.

What Changed

  • Limit Azure evidence receipts to their distinctive marker and exact base/head SHAs, while preserving local reviewer identity-path receipt checks.
  • Clarify the credentialless Azure tool/verifier boundary in reviewer prompts and operator documentation.
  • Add regression coverage ensuring remote receipts do not impersonate the credentialed model environment.

Risk Assessment

✅ Low: The change is narrowly scoped and preserves local receipt identity checks while making Azure receipts bind only the distinctive marker and exact base/head SHAs; model identity, credential isolation, exact-head evidence, and fail-closed cleanup remain independently enforced.

Testing

  • ⏭️ Test - skipped

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

✅ **Review** - passed

✅ No issues found.

⏭️ **Test** - skipped

Step was skipped.

✅ **Document** - passed

✅ No issues found.

⏭️ **Lint** - skipped

Step was skipped.

✅ **Push** - passed

✅ No issues found.

@ruby-dlee
ruby-dlee merged commit c70044e into main Aug 24, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant