idkmesh

Evolution control-plane independent audit — 2026-08-29

Scope and independence

This audit answers issue #151. A read-only Codex audit agent, separate from the implementation agent and instructed not to modify repository or GitHub state, inspected the current-main workflows, implementation, tests, live run metadata, and retained artifacts. This is AI-assisted independent review; it does not claim human or organizational independence.

The initial audit was performed against origin/main at 566bee13. The fixes below were then implemented on a clean branch and must receive a second exact-head review and green required checks before integration.

Initial verdict

The control plane preserved its read-only authority and hard non-compensation rules, but was not ready to close #151. Five concrete blockers and one documentation defect were found.

Severity Finding Resolution
High Branch-name-only lookup could admit an ordinary PR artifact from a fork branch named main. Selectors now allowlist trusted event types, use a new v2 trust epoch, require one exact unexpired run-bound artifact, and bind API run/head/event provenance in a verified manifest.
Medium State and ledger were only JSON-parsed; unsupported versions and inconsistent counters were accepted. Strict semantic validation now rejects unsupported versions, non-finite/out-of-range beliefs, inconsistent fitness/counters, authority-policy changes, malformed ledgers, and state/ledger lineage mismatch.
Medium Selected artifact/API/download failures could silently reset history to the repository seed. API errors, duplicate artifacts, download errors, missing files, manifest mismatch, and semantic invalidity now fail the run. Seed is used only when no eligible checkpoint is selected.
Medium Stale, dismissed, and comment-only reviews could clear the review-coverage guard. Review evidence is tied to the exact current head, collapsed to the latest state per eligible reviewer, excludes author/bots/comment-only/dismissed records, and separates approval count.
Medium pull_request_review directly launched the checkpoint-producing observer. The privileged trigger was removed; trusted PR lifecycle observation remains on pull_request_target, with scheduled refresh for review changes.
Low Portfolio documentation claimed retention of a raw snapshot that the workflow excludes. Documentation now consistently describes ephemeral raw text and retained derived evidence only.

Trust-boundary result

Persistence and concurrency result

Mathematical and governance result

Artifact minimization result

The portfolio checkpoint retains derived state, ranked features, report, policy, and integrity provenance. It does not retain the raw repository snapshot or raw issue/PR bodies. Exact historical replay therefore requires reacquisition or a separately governed evidence-retention contract.

Verification required for closure

The implementation branch adds regression coverage for fork-head branch-name collisions, exact artifacts, fail-closed restoration, manifest tampering, unsupported/forged state, ledger mismatch, current-head review evidence, and raw snapshot exclusion. Issue #151 is closable only after the PR’s exact head is independently reviewed, its current-main diff is inspected, and required checks are green for that same SHA.