Skip to content

feat: add signed Commons trust path - #66

Merged
SignalLayerLabs merged 4 commits into
mainfrom
codex/signed-commons-packs
Aug 21, 2026
Merged

SignalLayerLabs merged 4 commits into
mainfrom
codex/signed-commons-packs

Conversation

@SignalLayerLabs

@SignalLayerLabs SignalLayerLabs commented Aug 21, 2026 •

Copy link
Copy Markdown
Owner

Summary

Adds a cryptographically authenticated release path for MARGINAL Commons.

Commons remains a non-authoritative, model-specific prior. It cannot enable enforcement, promote Autopilot, change thresholds, override local evidence, or grant authority.

What changed

  • replace the hardcoded source_commit trust pin with signed Commons releases
  • add an offline Ed25519 root trust anchor
  • add a root-authorized release-key certificate
  • verify signatures over the exact downloaded Commons pack bytes
  • add strict stdlib-only Ed25519 verification at runtime
  • keep zero mandatory production dependencies
  • download pack + detached signature from fixed endpoints
  • store the signed pack atomically
  • reject rollback and same-revision equivocation
  • ignore legacy unsigned cache as trusted input
  • preserve the previous valid cache after rejected refreshes
  • keep Contributor submission fail-open when Commons refresh fails
  • add trusted immutable-Git release builder
  • treat Marginal-Commons as untrusted structured data
  • reject symlinks, malformed JSON, duplicate keys, registry drift, invalid lifecycle data and poisoned inputs
  • derive Commons revision from actual release-input history
  • add signed production release workflow for Cloudflare Pages
  • pin GitHub Actions and release dependencies
  • package only the public root trust anchor into the runtime
  • rebuild Codex runtime and provenance
  • add release/security operations documentation

Security model

Release chain:

offline root -> certified release key -> exact Commons pack bytes

The root private key remains offline.

The production release key belongs only in the protected commons-production GitHub Environment.

Marginal-Commons contains data only and is never imported or executed by the trusted release process.

Runtime consumption remains fail-open. Publication is fail-closed after signed bootstrap.

Verification

Host verification:

  • pytest -q: 997 passed
  • ruff format --check .: passed
  • ruff check .: passed
  • mypy src/marginal: passed
  • Codex plugin build/check: passed
  • python -m build: passed
  • twine check dist/*: passed
  • git diff --check: passed
  • zero mandatory production dependencies
  • old hardcoded Commons trust pin removed
  • private signing material excluded from repository

Runtime SHA-256:

650e6eee439a2e1ad5999ded2c019964713eb0d166a40d179f5f470be7cb1842

Sprint backup SHA-256:

a147fb6751cc4f544aae0231151f679f6278b68712205c4a01b3e4d3078f5a77

Operational follow-up after merge

  • configure protected commons-production GitHub Environment
  • add COMMONS_RELEASE_PRIVATE_KEY_B64URL
  • add CLOUDFLARE_API_TOKEN
  • add CLOUDFLARE_ACCOUNT_ID
  • perform the initial unsigned -> signed Commons bootstrap
  • verify production pack + detached signature
  • run Contributor -> Commons -> next SessionStart production E2E

@SignalLayerLabs
SignalLayerLabs merged commit 4f9fb1b into main Aug 21, 2026
8 checks passed
@SignalLayerLabs
SignalLayerLabs deleted the codex/signed-commons-packs branch August 21, 2026 07:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants