Skip to content

Make runtime-binding blocker explicit and mechanically checked - #6

Draft
Riverbraid wants to merge 3 commits into
mainfrom
agent/runtime-binding-blocked-state
Draft

Riverbraid wants to merge 3 commits into
mainfrom
agent/runtime-binding-blocked-state

Conversation

@Riverbraid

@Riverbraid Riverbraid commented Jul 27, 2026 •

Copy link
Copy Markdown
Owner

What changed

  • Replaces the no-op integrity workflow message with the actual repository-local npm test verifier.
  • Pins the workflow to Ubuntu 24.04, Node 24.11.1, and exact checkout/setup-node action commits.
  • Adds RUNTIME_BINDING_STATUS.json with the observed source-bound blockers:
    • missing bin/verify-swarm.cjs;
    • missing riverbraid-shield.js;
    • CommonJS syntax in both .js runtime-binding entrypoints while the package declares type: module.
  • Adds tests/runtime-binding-status.mjs to ensure those blockers remain visibly classified and that GPG execution evidence remains NOT_ASSESSED while the source contract is not executable.

Exact-head validation

Current head:

e054407becc9d995b023042a24eaf0c7cae5e0b7

Two GitHub Actions workflows completed successfully:

  1. Repaired Riverbraid Verification Gate: run 30289790880, job 90056469679.
    • repository-local verifier passed;
    • runtime-binding source status validator passed.
  2. Existing repository verify workflow: run 30289790890, job 90056470184.
    • legacy vector verification passed.

The bounded status marker is:

RUNTIME_BINDING_BLOCKED_STATE_CONFIRMED

What this establishes

For the exact draft head:

  • the repository-local stationary verifier executes under the observed environment;
  • the runtime-binding blockers are mechanically consistent with the observed source tree;
  • GPG execution is not being mislabeled as verified.

Required future repair

Direct GPG verification remains blocked until an attributable repair:

  1. restores or implements the exact verify-swarm dependency;
  2. restores or implements the exact shield dependency;
  3. reconciles the runtime-binding module format with declared consumers;
  4. adds valid, invalid, missing-input, and CI=true GPG tests using an isolated keyring;
  5. executes those tests on an exact source identity.

Boundary

This PR does not invent the missing implementations, verify GPG behavior, close the runtime-binding fault, alter protocol authority, change registry state, or claim production readiness, security hardening, certification, external audit, independent reproduction, or absence of defects.

The PR remains draft and unmerged; the main branch remains blocked for the runtime-binding claim.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant