Skip to content

ci: isolate Flow PRs and pin trusted runner execution - #35

Merged
pheidon merged 2 commits into
mainfrom
pheidon/flow-trusted-isolation
Sep 15, 2026
Merged

pheidon merged 2 commits into
mainfrom
pheidon/flow-trusted-isolation

Conversation

@pheidon

@pheidon pheidon commented Sep 15, 2026

Copy link
Copy Markdown
Member

Summary

  • Keep all pull-request code on hosted runners; move trusted Flow checks into a full-SHA-pinned input-free callee with a pre-assignment repository/ref/event boundary.
  • Preserve fast checks, actionlint v1.7.7, extended release-contract checks and existing check names; aggregate gates reject skipped/cancelled/failed execution.
  • Coordinate narrowing Flow's runner access to one restricted group and one EXISTING slot, preserving other repositories and all limits. Deployment/policy proof is tracked separately from this source PR.

Governing Issue

Refs #34

Validation

  • All 88 local tests, extended offline policy-release verification, and actionlint v1.7.7 pass.
  • Mutation controls reject event/ref widening, mutable selector, secrets inheritance, hosted-to-selfhost changes and misleading comment decoys.
  • Hosted PR CI, independent exact-head review, policy application, native bootstrap and merged-main proof pending.
  • Bootstrap dispatch checks fixed trusted base; it is not head-test evidence. Hosted CI separately tests this head.

Bootstrap Governance

Flow Contract

  • Owner lane: Pheidon / authorized organization recovery
  • Repair owner: Pheidon
  • Autonomy class: authorized bounded CI migration
  • Risk class: material runner trust boundary

Flow Merge Readiness

  • Independent non-author review and eligible code-owner approval pending.
  • Required CI Gate and native evidence pending; no bypass permitted.

Merge Automation

  • Auto-merge withheld until reviewed policy and actual native proof are complete; normal squash merge only.

Notes

Immutable callee source ref pheidon/flow-trusted-source must be retained after merge. No spending, new worker count, releases, or host admission expansion.

@pheidon
pheidon requested a review from a team as a code owner September 15, 2026 17:35

@athena-omt athena-omt left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent cross-model review published by Athena automation, separately from source author under common control.

APPROVE exact head7970371ceb2c46d6e459f268d44497a30da07689 base165ff16e2cb3cbc176a107eb1c1f99f4f925438d.

Actual reviewer: official Claude Pro CLI Sonnet4.6 with Anthropic Haiku helper, no OpenAI fallback. Source authored by OpenAI. One bounded fresh review; remaining subscription quota unknown.

Full effective source diff plus proposed narrowing/controller scripts reviewed. Focused tests3/3, seven bypass-relevant mutation cases, aggregate failure/cancel/skip controls, full-file digest matching and actionlint pass independently. Parent88test/extended evidence and actual hosted/native runs recorded separately. No blocking findings. Entire trusted callee and caller digest-bound; PR execution hosted; only immutable callee reachable through restricted group. Callee's own predicate and server group restrictions enforce boundary, not mutable caller conditions alone.

Independent review seals REVIEW.md and review.json under reports/claude-review-flow35-20260915/. Actual provider receipt, executed tool evidence, reviewed policy script hashes and live isolation verification under reports/flow-isolation-20260915/. Runtime proof and normal required CI/codeowner gates remain parent-owned. No real fork trial is claimed by a same-repository negative-ref control.

@pheidon
pheidon merged commit ea30a74 into main Sep 15, 2026
17 checks passed
@pheidon
pheidon deleted the pheidon/flow-trusted-isolation branch September 15, 2026 17:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants