Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
61 commits
Select commit Hold shift + click to select a range
c78ab54
docs(trust-001): grant bounded Authorization A
bateau84 Oct 5, 2026
3c73513
feat(trust001): add bounded protocol package
bateau84 Oct 5, 2026
873ff6e
feat(trust001): add strict split-channel protocol
bateau84 Oct 5, 2026
556757f
feat(trust001): add request and seal state machines
bateau84 Oct 5, 2026
fe36d04
feat(trust001): add one-shot unix channel primitive
bateau84 Oct 5, 2026
954a173
test(trust001): cover split protocol and lifecycle
bateau84 Oct 5, 2026
3599660
test(trust001): cover one-shot unix endpoint
bateau84 Oct 5, 2026
f453053
build(trust001): pin stock OpenCode 2.0.23
bateau84 Oct 5, 2026
029b0d7
feat(trust001): build immutable bridge source closure
bateau84 Oct 5, 2026
7e1483c
test(trust001): cover bridge source closure
bateau84 Oct 5, 2026
abb1cdd
ci(trust001): add provider-free construction preflight
bateau84 Oct 5, 2026
e7feb12
fix(trust001): separate host and callback request classes
bateau84 Oct 5, 2026
408f547
test(trust001): enforce request-class separation
bateau84 Oct 5, 2026
9b3acfe
fix(trust001): split cancellation request classes
bateau84 Oct 5, 2026
5aafb6b
feat(trust001): add directional capability router
bateau84 Oct 5, 2026
15c7071
test(trust001): cover directional broker authority
bateau84 Oct 5, 2026
8017101
test(trust001): update stock OpenCode pin assertion
bateau84 Oct 5, 2026
986f79c
refactor(trust001): use dependency-free bridge module
bateau84 Oct 5, 2026
c9277f6
test(trust001): follow bridge module format
bateau84 Oct 5, 2026
017324b
feat(trust001): add framed socket relay
bateau84 Oct 5, 2026
77e8cef
feat(trust001): add stock OpenCode bridge handshake
bateau84 Oct 5, 2026
272f8c9
test(trust001): cover real framed socket relay
bateau84 Oct 5, 2026
9b287dd
feat(trust001): create separated channel set
bateau84 Oct 5, 2026
bb06828
test(trust001): verify endpoint role separation
bateau84 Oct 5, 2026
cc5c2bf
test(trust001): add synthetic isolated peer
bateau84 Oct 5, 2026
73ba187
test(trust001): exercise stock bridge activation without inference
bateau84 Oct 5, 2026
fa0ffe9
ci(trust001): run stock bridge provider-free preflight
bateau84 Oct 5, 2026
643eb29
fix(trust001): verify stock OpenCode version format
bateau84 Oct 5, 2026
e23dc9a
ci(trust001): match stock version output
bateau84 Oct 5, 2026
193ea14
fix(trust001): keep normal OpenCode default pin unchanged
bateau84 Oct 5, 2026
76bf413
fix(trust001): restore existing default pin test
bateau84 Oct 5, 2026
85aa18b
ci(trust001): cancel superseded preflights
bateau84 Oct 5, 2026
8b923ed
test(trust001): configure provider-free preflight model reference
bateau84 Oct 5, 2026
662503d
docs(trust001): authorize stock 2.0.23 default pin
bateau84 Oct 5, 2026
fa00ad8
build(trust001): move stock OpenCode default to 2.0.23
bateau84 Oct 5, 2026
b9a3853
test(trust001): assert stock OpenCode 2.0.23 default
bateau84 Oct 5, 2026
b19265d
fix(trust001): preserve Loom plugin storage namespace
bateau84 Oct 5, 2026
1521534
fix(trust001): bind bridge to Loom plugin namespace
bateau84 Oct 5, 2026
7e95f7a
test(trust001): assert Loom namespace bridge closure
bateau84 Oct 5, 2026
f17d869
test(trust001): verify Loom-id bridge activation
bateau84 Oct 5, 2026
0029502
feat(trust001): admit immutable location capability
bateau84 Oct 5, 2026
1c0e215
feat(trust001): implement bounded stock host bridge
bateau84 Oct 5, 2026
b9ebdb7
feat(trust001): add bounded isolated Loom host
bateau84 Oct 5, 2026
d21205d
feat(trust001): serve capability directions concurrently
bateau84 Oct 5, 2026
5e0d3ad
fix(trust001): classify clean capability shutdown
bateau84 Oct 5, 2026
cd00f28
fix(trust001): accept clean isolated-host shutdown
bateau84 Oct 5, 2026
c8fea92
test(trust001): add bounded remote-context fixture
bateau84 Oct 5, 2026
5fe13bf
test(trust001): exercise bounded remote context provider-free
bateau84 Oct 5, 2026
947a104
ci(trust001): run bounded remote-context preflight
bateau84 Oct 5, 2026
d6111f4
fix(trust001): fence isolated generation after seal
bateau84 Oct 5, 2026
8f4125d
feat(trust001): add trusted evidence close request
bateau84 Oct 5, 2026
ab40b70
feat(trust001): let collector request trusted close
bateau84 Oct 5, 2026
83cd6b3
fix(trust001): seal only after trusted evidence close
bateau84 Oct 5, 2026
edf3387
test(trust001): close stock bridge through trusted channel
bateau84 Oct 5, 2026
7692fd2
test(trust001): hold runtime through trusted close and seal
bateau84 Oct 5, 2026
8cfcc64
fix(trust001): materialize bridge in stock-discoverable js form
bateau84 Oct 5, 2026
f6f5ba9
test(trust001): assert stock-discoverable bridge path
bateau84 Oct 5, 2026
53f2787
ci(trust001): separate bridge and remote-context preflights
bateau84 Oct 5, 2026
19c1d92
test(trust001): add fixed remote setup stage markers
bateau84 Oct 5, 2026
9b5dc43
test(trust001): report fixed remote setup stage on failure
bateau84 Oct 5, 2026
cd871b4
fix(trust001): preserve tool identity through effective registry id
bateau84 Oct 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
77 changes: 77 additions & 0 deletions .github/workflows/trust001-preflight.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,77 @@
name: TRUST-001 provider-free preflight

on:
pull_request:
paths:
- "Containerfile"
- "runner/trust001/**"
- "container/trust001/**"
- "trust001/**"
- "tests/test_trust001_*.py"
- "tests/trust001/**"
- ".github/workflows/trust001-preflight.yml"
- "docs/experiments/trust-001/checkpoints/**"

concurrency:
group: trust001-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
unit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262

- name: Verify forbidden OpenCode patch tree absent
run: |
test ! -e runtime-patches
test ! -e opencode-patches

- name: Compile TRUST-001 Python
run: |
python3 -m py_compile runner/trust001/*.py

- name: Run provider-free TRUST-001 unit tests
run: |
python3 -m unittest discover -s tests -p 'test_trust001_*.py'

- name: Check dependency-free bridge scripts
run: |
node --check trust001/bridge.mjs
node --check trust001/isolated-host.mjs
node --check trust001/synthetic-loom-peer.mjs
node --check trust001/synthetic-remote-plugin.mjs
python3 -m py_compile tests/trust001/run_stock_bridge_preflight.py
python3 -m py_compile tests/trust001/run_remote_context_preflight.py

stock-opencode:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262

- name: Build stock OpenCode candidate image
run: |
docker build -f Containerfile --target opencode --build-arg OPENCODE_VERSION=2.0.23 -t trust001-stock-opencode:preflight .

- name: Verify exact stock version and labels
run: |
test "$(docker run --rm --entrypoint opencode trust001-stock-opencode:preflight --version)" = "opencode v2.0.23"
test "$(docker image inspect trust001-stock-opencode:preflight --format '{{ index .Config.Labels "io.opencode-eval.stock-opencode-version" }}')" = "2.0.23"
test "$(docker image inspect trust001-stock-opencode:preflight --format '{{ index .Config.Labels "io.opencode-eval.stock-opencode-package" }}')" = "@opencode/cli"

- name: Exercise stock bridge handshake without inference
run: |
python3 tests/trust001/run_stock_bridge_preflight.py \
--image trust001-stock-opencode:preflight

- name: Exercise bounded remote context without inference
run: |
python3 tests/trust001/run_remote_context_preflight.py \
--image trust001-stock-opencode:preflight

- name: Record provider-free image identity
run: |
docker image inspect trust001-stock-opencode:preflight --format 'image={{.Id}} config={{.Config.Image}} version={{ index .Config.Labels "io.opencode-eval.stock-opencode-version" }}'
7 changes: 5 additions & 2 deletions Containerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
FROM node:24-bookworm-slim@sha256:0e0ff40c39bc087845bfb27465a0df4ea419520094bc35842ff83dd8cbe6f9b6 AS opencode-builder
ARG OPENCODE_VERSION=2.0.18
ARG OPENCODE_VERSION=2.0.23
RUN npm install --global "@opencode/cli@${OPENCODE_VERSION}" \
&& resolved="$(readlink -f "$(command -v opencode)")" \
&& test -x "$resolved" \
Expand Down Expand Up @@ -53,8 +53,11 @@ ENTRYPOINT ["python3", "/opt/opencode-eval-runner/container/invoke.py"]
USER 1000:1000

FROM runtime-base AS opencode
ARG OPENCODE_VERSION=2.0.23
LABEL io.opencode-eval.stock-opencode-version="${OPENCODE_VERSION}" \
io.opencode-eval.stock-opencode-package="@opencode/cli"
COPY --from=opencode-builder /opencode /usr/local/bin/opencode
RUN opencode --version
RUN test "$(opencode --version)" = "opencode v${OPENCODE_VERSION}"

FROM runtime-base AS copilot
COPY --from=copilot-builder /opt/copilot/bin/copilot /usr/local/bin/copilot
Expand Down
Loading
Loading