Skip to content

Add inactive Control foundation policy roll-up - #215

Merged
yihanzhu merged 2 commits into
mainfrom
codex/control-foundation-rollup-v1
Sep 2, 2026
Merged

Add inactive Control foundation policy roll-up#215
yihanzhu merged 2 commits into
mainfrom
codex/control-foundation-rollup-v1

Conversation

@yihanzhu

@yihanzhu yihanzhu commented Sep 2, 2026

Copy link
Copy Markdown
Owner

Roadmap item: 2 — Control foundation.

What changed

  • Ship one canonical control_policy_set v1 artifact in the required six-section order.
  • Bind the exact current policy and decision files to the selected core v2 generation and package closure.
  • Add one focused closure test plus restore and manifest notes.
  • Add the canonical set's one exact path to the existing closed v2 generation-ID allowlist and its ordered expected-hit list. The grep, rejecting fallback, and every other allowed path stay unchanged.

Exact identity

  • Base: 81cdf84f0cad6e2b93411a3adceb06c47b2f1dc2
  • Head: ebc8d215dc480fb8da648e7aac7db3ef728fbaab
  • Branch: codex/control-foundation-rollup-v1
  • Scope: exactly six paths.

Proof on the exact head

  • bash scripts/test/control-foundation-rollup.test.sh — 23 focused checks passed.
  • bash scripts/test/portable-core-schema.test.sh — zero failures: 47/47 owned rules, 141/141 direct cases, 13/13 private route probes, 8/8 registry cases, 39/39 activation guards, 8/8 numeric boundaries, 8/8 review findings, and 44/44 legacy assertions.
  • bash -n on both changed test scripts — passed.
  • ShellCheck 0.11.0 with -x -S style on both changed test scripts — passed.
  • Exact six-path diff, append-only manifest, required-file structure, diff check, and rename gate — passed.

The focused roll-up test independently hashes all 12 referenced policy and decision files and recomputes the selected core package closure. It rejects mutations to every ref, the core identity, generation, package, order, uniqueness, activation, and fail mode. The six evaluator suites were not run locally; required CI will run the full repository suite.

Inactive boundary

This is a static, repo-only identity bundle. It stays inactive and fails closed. It adds no aggregator runtime and claims no enforcement, qualification, approval, authority, activation, credential access, candidate execution, network access, publish, deploy, or external effect.

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying ystack with  Cloudflare Pages  Cloudflare Pages

Latest commit: ebc8d21
Status: ✅  Deploy successful!
Preview URL: https://2dfe2c0b.fabrica-6yx.pages.dev
Branch Preview URL: https://codex-control-foundation-rol.fabrica-6yx.pages.dev

View logs

yihanzhu commented Sep 2, 2026

Copy link
Copy Markdown
Owner Author

Codex reviewer (cross-vendor, read-only)

Reviewed-head: ebc8d21
Reviewed-base: 81cdf84
reviewer: review_control_rollup_215 @ high

CLEAN — zero unresolved Important findings.

Bugs

  • The canonical policy set passes the existing validator.
  • All six sections are in the required order, and all 12 policy and decision refs match the current file bytes, content IDs, and media types.
  • The selected core generation and recomputed package closure match the shipped set.
  • Focused mutations reject changed refs, core identity, order, duplicates, activation, and fail-open state.

Security

  • The addition is static canonical JSON plus focused proof; no aggregator or executable product runtime was added.
  • No untrusted value reaches command selection, shell evaluation, credentials, candidate execution, publishing, deployment, or an external write.
  • The schema test adds only the exact canonical-set path to the closed predicate and ordered hit list. No glob, prefix, fallback, or catch-all was added.

Compliance

  • Exactly six briefed paths changed; the restore manifest is append-only.
  • ROADMAP, NORTH_STAR, mode, and ruleset identities match; no forbidden path changed.
  • The package remains inactive, closed, repo-only, and authority-free.
  • Required CI run 33617686021, check 100207222717, completed successfully from app 15368.
  • Focused roll-up proof passed 23/23; policy-set proof passed 61/61; portable-core schema groups, including 39/39 activation guards, passed.

@yihanzhu
yihanzhu merged commit 022c786 into main Sep 2, 2026
2 checks passed
@yihanzhu
yihanzhu deleted the codex/control-foundation-rollup-v1 branch September 2, 2026 10:42

yihanzhu commented Sep 2, 2026

Copy link
Copy Markdown
Owner Author

Construction publish receipt

  • reviewed head/base: ebc8d21 / 81cdf84
  • required CI: app 15368, check 100207222717, success
  • independent review: comment 5508289713, zero unresolved Important
  • squash merge/main: 022c786
  • reviewed/merged tree: 14b9d6933a35f5e2e83eb8062e0044280f41fcc3
  • canonical receipt SHA-256: a7515c2efd00f4fb50c2483e73f468fe577088b2b4e9bea34c1548980d8ffaa8
  • local main: clean and fast-forwarded
  • Roadmap item 2: implementation-complete

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant