Skip to content

feat: add protected Chongqing admission verifier workflow - #101

Merged
zhouning merged 1 commit into
mainfrom
feat/ar2-protected-admission-workflow
Aug 17, 2026
Merged

feat: add protected Chongqing admission verifier workflow#101
zhouning merged 1 commit into
mainfrom
feat/ar2-protected-admission-workflow

Conversation

@zhouning

Copy link
Copy Markdown
Owner

Summary

  • add a main-only protected chongqing-admission verifier workflow on the dedicated gda-admission runner
  • bind metadata-only external attestations to the exact M3-31 fingerprints and enforce the M3-32 evaluate/verify no-authority boundary
  • attest and retain the input/report evidence while keeping all content, Landing, ResourceVersion, PlatformRun, scheduler, provider, and production claims false
  • add static contract coverage, required CI/staging parity, ADR-080, roadmap, and system-of-record updates

Verification

  • python -m pytest data_agent/test_chongqing_protected_admission.py data_agent/test_chongqing_protected_admission_workflow.py -q (8 passed)
  • Required Platform Tests (728 passed)
  • python -m ruff check data_agent/test_chongqing_protected_admission_workflow.py
  • git diff --check

Boundary

This PR establishes the M3-33 workflow contract only. It does not provision the protected environment/runner, consume real Chongqing payloads, create Landing or ingestion authority, or make AR-2 production-ready. The next accepted evidence remains environment/runner/reviewer/rotation provisioning plus all 15 real external attestations and the first protected verifier run.

@zhouning
zhouning merged commit 8e1a7e8 into main Aug 17, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant