From d9793944dde9fdada1cf3041bc01bf1160504796 Mon Sep 17 00:00:00 2001 From: WPEssential Date: Thu, 8 Oct 2026 19:00:48 +0500 Subject: [PATCH 1/2] docs(m14): add release-trust subtask progress table --- README.md | 28 +++++++++++++++++++++++----- 1 file changed, 23 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index 4538c93b..f13a0b0d 100644 --- a/README.md +++ b/README.md @@ -6,15 +6,15 @@ WorkIntel is a single Laravel 13 + React/TypeScript workforce operations platfor ## AI Development Progress - **Repo:** `Vertex-Systems-Network/workforce-intelligence` -- **Current Work:** PR #144 governance fix is under exact-head certification; third-party Windows trust-signing provider work is deferred by owner and does not block safe repository maintenance. +- **Current Work:** M14 gate-by-gate status is tracked below; provider-based Windows signing and Apple signing are deferred, while external release-policy and real-target evidence remain open. - **Current Module:** M14 — Production Release Trust & Real-Target Readiness - **Module Progress:** [███████░░░] **70%** - **Overall Progress:** [██████████] **100%** — active release-scope modular maturity - **Active Issue:** #62 -- **Active PR:** #144 -- **Active Branch:** `governance/no-recursive-state-sync` -- **Last Completed:** PR #145 merged to protected main at dfb4fc7ec9536a304b7df582027968dc60f3e53a after all six exact-head checks passed on dab1ad7af440334d6ed7a7847665659216fedb69; zero unresolved review threads. -- **Next Action:** Finish PR #144 exact-head certification and merge only if all required checks pass at the unchanged head. Defer third-party Windows trust-signing provider qualification/integration until future owner authorization; it is not a blocker for safe repository maintenance. Continue the next safe authorized repository lane without buying/configuring signing material or claiming trusted signatures. M14 remains 70% until external evidence gates actually pass; do not deploy, restore, publish or run Runner tasks without separate authority. Issue #70 remains evidence-gated and Apple remains deferred under Issue #123. +- **Active PR:** none +- **Active Branch:** `main` +- **Last Completed:** PR #144 merged to protected main as `33411a06b2585705880181f056d7b42d3bdf7458`; all six required PR-head checks were green on `989ededc74ce6bc72191ca740ae313aae64babde`. +- **Next Action:** Track each M14 evidence gate in the subtask table below and update its status only when repository or external evidence changes. Keep provider-based Windows signing deferred until future owner authorization; Apple remains deferred under Issue #123. Do not claim trusted signatures/publication or run production, restore, target, or unauthorized Runner work. > Apple/macOS release trust is deferred to future Issue #123 and is not represented as complete. Overall progress is scoped to active release-scope modular maturity. @@ -89,6 +89,24 @@ The table below is the repository-level roadmap view. `Progress` represents acce | M13 | Agent Lifecycle Reliability — Batches 1–6 | Complete | `██████████` 100% | 2026-08-22 | 2026-08-24 | Managed update, deterministic packaging, immutability, transactional publication, browser version authority and runtime-bound deployment accepted | | M14 | Production Release Trust & Real-Target Readiness | **VERIFYING / PARTIALLY COMPLETE** | `███████░░░` **70%** | 2026-08-31 | **Active** | GitHub release-control and real-target/recovery evidence remain separate gates. Third-party Windows signing and Apple/macOS trust are deferred; no trusted signature or publication is claimed | +### M14 subtask progress + +The bars below show closure of each stated subtask against its own acceptance evidence; they are **not averaged** to calculate the roadmap's M14 70%. A source implementation can be complete while real signing, publication, or target evidence is still not verified. + +| M14 subtask | Status | Progress | Evidence / remaining work | +|---|---|---|---| +| Trusted-release workflow source: protected-main source binding, fail-closed trust jobs, receipts, and publication safeguards | Implemented | `[██████████]` **100%** | Source contract and CI coverage are merged. This does not claim an actual trusted release. | +| Linux checksum/provenance candidate evidence | Not run | `[░░░░░░░░░░]` **0%** | Run an authorized release-candidate workflow and retain its exact-source digest/provenance receipt. | +| `agent-v*` tag update/deletion protection and separate creation-authority attestation (Gate A/A2) | Verified | `[██████████]` **100%** | Live ruleset 23938765 and the VERIFIED attestation match; zero bypass actors and update/deletion restrictions are recorded. | +| `production-release` environment protection and least-privilege policy-read token (Gate B) | Not Verified | `[░░░░░░░░░░]` **0%** | Requires administrator-visible environment protection and secret-scope evidence. | +| GitHub immutable-release policy and protected read-back (Gate C) | Not Verified | `[░░░░░░░░░░]` **0%** | Connector cannot read the required admin setting; no enablement is assumed. | +| Windows approved signer material, signer fingerprint, and actual Authenticode/timestamp evidence | Deferred | `[░░░░░░░░░░]` **0%** | Owner deferred third-party provider qualification/integration to future authorization; no trusted Windows signature is claimed. | +| Apple Developer ID signing and accepted notarization | Deferred | `[░░░░░░░░░░]` **0%** | Parked under Issue #123 pending owner authorization and required subscription/tooling. | +| Trusted release publication and immutable asset-integrity postcondition | Not run | `[░░░░░░░░░░]` **0%** | Requires the applicable release-policy and signer gates plus separately authorized publication; no release is claimed. | +| Real-target readiness evidence (revision, health, database, queue, scheduler, storage, download, auth/workspace smoke) | Not Verified | `[░░░░░░░░░░]` **0%** | Requires an approved target and captured target-specific evidence; no target run is claimed. | +| Isolated/disposable backup-to-restore verification | Not run | `[░░░░░░░░░░]` **0%** | Requires separate recovery/target authority and actual restore evidence. | + + \* The canonical M0–M12 maturity record stores per-phase completion state but not precise per-phase start/end timestamps. M0–M11 therefore use the repository's initial implementation/certification evidence window instead of inventing unsupported day-level precision. M12, M13 and M14 dates are tied to explicit repository/PR authority and closure records. **Current roadmap state:** M0–M13 are accepted complete. M14 is the active authorized phase and must not be labeled `DONE` or `PRODUCTION_VERIFIED` until its owner-authorized AI-only review gate and external evidence gates are actually satisfied. See `docs/architecture/MODULAR_MATURITY_STATUS.md`, `docs/architecture/M13_AGENT_LIFECYCLE_RELIABILITY.md`, `docs/architecture/M14_RELEASE_TRUST_READINESS.md`, and `docs/status/AI_CHECKPOINT.md`. From c2ad9c6cd4a309e9daefc3717bfaf26a98b2cb8b Mon Sep 17 00:00:00 2001 From: WPEssential Date: Thu, 8 Oct 2026 19:21:00 +0500 Subject: [PATCH 2/2] docs(ai): sync M14 progress state and README --- README.md | 10 +++++----- docs/ai-state/COORDINATION-QUEUE.yaml | 15 ++++++++++++--- docs/ai-state/CURRENT-STATE.yaml | 19 ++++++++++--------- docs/ai-state/LAST-CHECKPOINT.md | 10 +++++----- 4 files changed, 32 insertions(+), 22 deletions(-) diff --git a/README.md b/README.md index f13a0b0d..3a068d9a 100644 --- a/README.md +++ b/README.md @@ -6,15 +6,15 @@ WorkIntel is a single Laravel 13 + React/TypeScript workforce operations platfor ## AI Development Progress - **Repo:** `Vertex-Systems-Network/workforce-intelligence` -- **Current Work:** M14 gate-by-gate status is tracked below; provider-based Windows signing and Apple signing are deferred, while external release-policy and real-target evidence remain open. +- **Current Work:** PR #146 README M14 subtask table is open; exact-head CI and Windows Certification exposed a failing README/compact-state synchronization contract, and the docs/state repair is in progress. - **Current Module:** M14 — Production Release Trust & Real-Target Readiness - **Module Progress:** [███████░░░] **70%** - **Overall Progress:** [██████████] **100%** — active release-scope modular maturity - **Active Issue:** #62 -- **Active PR:** none -- **Active Branch:** `main` -- **Last Completed:** PR #144 merged to protected main as `33411a06b2585705880181f056d7b42d3bdf7458`; all six required PR-head checks were green on `989ededc74ce6bc72191ca740ae313aae64babde`. -- **Next Action:** Track each M14 evidence gate in the subtask table below and update its status only when repository or external evidence changes. Keep provider-based Windows signing deferred until future owner authorization; Apple remains deferred under Issue #123. Do not claim trusted signatures/publication or run production, restore, target, or unauthorized Runner work. +- **Active PR:** #146 +- **Active Branch:** `docs/m14-readme-subtask-progress-20261008` +- **Last Completed:** PR #144 merged to protected main as 33411a06b2585705880181f056d7b42d3bdf7458 after all six required PR-head checks passed on 989ededc74ce6bc72191ca740ae313aae64babde. +- **Next Action:** Synchronize the README AI progress block with compact state in PR #146, then require exact-head CI, Code Quality and Windows Certification to pass before merge. Keep M14 at 70%; external release-policy, signing, publication, real-target and restore evidence remain unverified, deferred or not run. > Apple/macOS release trust is deferred to future Issue #123 and is not represented as complete. Overall progress is scoped to active release-scope modular maturity. diff --git a/docs/ai-state/COORDINATION-QUEUE.yaml b/docs/ai-state/COORDINATION-QUEUE.yaml index 372103b0..b9701fc6 100644 --- a/docs/ai-state/COORDINATION-QUEUE.yaml +++ b/docs/ai-state/COORDINATION-QUEUE.yaml @@ -2,7 +2,7 @@ "schema_version": 1, "non_authoritative_resume_index": true, "repository": "Vertex-Systems-Network/workforce-intelligence", - "observed_main_sha": "dfb4fc7ec9536a304b7df582027968dc60f3e53a", + "observed_main_sha": "33411a06b2585705880181f056d7b42d3bdf7458", "reconciled_at": "2026-10-08", "issues": [ { @@ -25,13 +25,22 @@ } ], "pull_requests": [ + { + "number": 146, + "title": "docs(m14): track release-trust subtasks in README", + "state": "open", + "draft": false, + "head_ref": "docs/m14-readme-subtask-progress-20261008", + "head_sha": "d9793944dde9fdada1cf3041bc01bf1160504796", + "action": "repair-readme-compact-state-sync-before-recertification" + }, { "number": 144, "title": "governance: prevent recursive state-only reconciliation loops", - "state": "open", + "state": "merged", "draft": false, "head_ref": "governance/no-recursive-state-sync", - "action": "owner-defers-provider-signing; exact-head-certification-pending" + "action": "merged-as-33411a06b2585705880181f056d7b42d3bdf7458" }, { "number": 145, diff --git a/docs/ai-state/CURRENT-STATE.yaml b/docs/ai-state/CURRENT-STATE.yaml index 90a23b58..89adae62 100644 --- a/docs/ai-state/CURRENT-STATE.yaml +++ b/docs/ai-state/CURRENT-STATE.yaml @@ -2,14 +2,14 @@ "schema_version": 1, "compact_state_path": "docs/ai-state", "repository": "Vertex-Systems-Network/workforce-intelligence", - "observed_main_sha": "dfb4fc7ec9536a304b7df582027968dc60f3e53a", + "observed_main_sha": "33411a06b2585705880181f056d7b42d3bdf7458", "active_issue": 62, - "active_pr": 144, - "active_branch": "governance/no-recursive-state-sync", + "active_pr": 146, + "active_branch": "docs/m14-readme-subtask-progress-20261008", "current_milestone": "M14 Windows/Linux release trust — provider-based signing deferred; real-target evidence remains separate", - "milestone_status": "WAITING_EXTERNAL", - "last_completed_milestone": "PR #145 merged to protected main at dfb4fc7ec9536a304b7df582027968dc60f3e53a after all six exact-head checks passed on dab1ad7af440334d6ed7a7847665659216fedb69; zero unresolved review threads.", - "exact_next_safe_action": "Finish PR #144 exact-head certification and merge only if all required checks pass at the unchanged head. Defer third-party Windows trust-signing provider qualification/integration until future owner authorization; it is not a blocker for safe repository maintenance. Continue the next safe authorized repository lane without buying/configuring signing material or claiming trusted signatures. M14 remains 70% until external evidence gates actually pass; do not deploy, restore, publish or run Runner tasks without separate authority. Issue #70 remains evidence-gated and Apple remains deferred under Issue #123.", + "milestone_status": "VERIFYING", + "last_completed_milestone": "PR #144 merged to protected main as 33411a06b2585705880181f056d7b42d3bdf7458 after all six required PR-head checks passed on 989ededc74ce6bc72191ca740ae313aae64babde.", + "exact_next_safe_action": "Synchronize the README AI progress block with compact state in PR #146, then require exact-head CI, Code Quality and Windows Certification to pass before merge. Keep M14 at 70%; external release-policy, signing, publication, real-target and restore evidence remain unverified, deferred or not run.", "pending_runner_ids": [ "RB-001", "RB-002", @@ -28,7 +28,8 @@ "Public-trust Windows private signing keys must not be treated as portable GitHub PFX secrets; existing PFX secrets remain unset for the public-trust path.", "Live GitHub readback on 2026-10-08 confirms active main branch ruleset 21176050 with zero bypass actors and active `agent-v-release-tags` ruleset 23938765 for `refs/tags/agent-v*` with zero bypass actors plus update/deletion restrictions; the VERIFIED attestation matches updated_at `2026-09-24T17:49:27.650+05:00`. `production-release` environment protection, token placement/least privilege, and immutable-releases setting remain Not Verified because the connector cannot read those admin endpoints.", "Issue #70 remains open; RB-005 remains not-authorized/blocked.", - "Apple/macOS signing and notarization are intentionally deferred to future Issue #123 and are not an active M14 execution blocker; do not claim Apple completion." + "Apple/macOS signing and notarization are intentionally deferred to future Issue #123 and are not an active M14 execution blocker; do not claim Apple completion.", + "PR #146 exact-head Code Quality passed, but WorkIntel CI and Windows Certification failed because README AI progress fields did not match docs/ai-state/CURRENT-STATE.yaml. Repair the synchronized source files before another exact-head certification." ], "timeout_control": { "max_consolidated_status_refreshes_per_milestone": 1, @@ -47,11 +48,11 @@ "last_reconciled_at": "2026-10-08", "response_status": { "repository_name": "Vertex-Systems-Network/workforce-intelligence", - "current_work": "PR #144 governance fix is under exact-head certification; third-party Windows trust-signing provider work is deferred by owner and does not block safe repository maintenance.", + "current_work": "PR #146 README M14 subtask table is open; exact-head CI and Windows Certification exposed a failing README/compact-state synchronization contract, and the docs/state repair is in progress.", "current_module": "M14 — Production Release Trust & Real-Target Readiness", "module_progress": { "percent": 70, - "basis": "Third-party provider-based trusted signing is deferred by owner for future scope. No provider, signing, publication or real-target evidence is claimed; M14 remains 70% until its authorized evidence gates pass." + "basis": "Provider-based trusted signing is deferred by owner; Gate A/A2 is verified, while release-policy, trusted-artifact and real-target evidence remain open. M14 remains 70% until its authorized external evidence gates pass." }, "overall_progress": { "percent": 100, diff --git a/docs/ai-state/LAST-CHECKPOINT.md b/docs/ai-state/LAST-CHECKPOINT.md index 2999de72..1c7b815a 100644 --- a/docs/ai-state/LAST-CHECKPOINT.md +++ b/docs/ai-state/LAST-CHECKPOINT.md @@ -1,13 +1,13 @@ # Last AI Engineering Supervisor Checkpoint **Repository:** `Vertex-Systems-Network/workforce-intelligence` -**Observed protected main:** `dfb4fc7ec9536a304b7df582027968dc60f3e53a` +**Observed protected main:** `33411a06b2585705880181f056d7b42d3bdf7458` **Active Issue:** #62 **Deferred Future Issue:** #123 — Apple signing, notarization and macOS release trust -**Active PR:** #144 — governance/no-recursive-state-sync -**Active branch:** `governance/no-recursive-state-sync` +**Active PR:** #146 — M14 README subtask progress +**Active branch:** `docs/m14-readme-subtask-progress-20261008` **Milestone:** M14 Windows/Linux release trust — provider-based signing deferred; real-target evidence remains separate -**Status:** PR #144 exact-head certification pending; provider-based Windows trust signing deferred by owner; M14 remains 70%. +**Status:** PR #146 is being repaired after exact-head checks found README/compact-state drift; provider-based Windows signing is deferred; M14 remains 70%. ## Completed @@ -38,4 +38,4 @@ ## Next Action -Finish PR #144 exact-head certification and merge only if all required checks pass at the unchanged head. Defer third-party Windows trust-signing provider qualification/integration until future owner authorization; continue safe authorized repository work independently. Keep M14 at 70% until real external evidence gates pass. Do not deploy, restore, publish, sign or run Runner tasks without separate authority. +Synchronize the README AI progress block with compact state in PR #146, then require exact-head CI, Code Quality and Windows Certification to pass before merge. Keep M14 at 70%; external release-policy, signing, publication, real-target and restore evidence remain unverified, deferred or not run. Do not deploy, restore, publish, sign or run Runner tasks without separate authority.