mirror of
https://github.com/microsoft/BCQuality.git
synced 2026-10-05 22:56:55 +01:00
Fix all 6 confirmed findings from today's gap audit
Implements every confirmed finding from the workflow-based audit of CURABIS Standard's agent model (7 finders + adversarial verification, 8 confirmed / 5 refuted): 1. Roemer/Florence phantom wiring - roemer.agent.md claimed Florence's heartbeat "may summon me when a ward smells of drift" with nothing in florence.agent.md or HEARTBEAT.md implementing it. Fixed by adding an explicit "Kald Roemer" instruction to HEARTBEAT.md ward 6 (agent visibility, his actual domain), mirroring ward 8's existing "Kald Weber" pattern, and correcting roemer.agent.md's own claim to match. 2. m365.agent.md's "Florence's morning brief pattern" was a one-way orphaned reference - a full 4-step pattern with nothing in florence.agent.md implementing it. Added it to florence.agent.md as an explicit on-demand capability, separate from the timestamp-gated Round protocol. 3. An Ergasterion "PROCEED WITH CHANGES" ruling had no way to be checked against the eventual diff - al-review's checklists never referenced it. Added ERGASTERION_RULING to the [CURABIS-STATE] vocabulary, wired Ergasterion to write it, and added a BLOCKing checklist item to al-review's Titus checklist that verifies required changes were actually implemented. 4. curabis-task-state-check.yml was headered "Deterministic enforcement (not LLM diligence)" but only checks checkbox order, only blocks anything if a human separately enabled branch protection (never verified anywhere), and doesn't exist at all for the PTE track. Corrected the header's claims and added Roemer station 14 to verify branch protection is actually configured. 5. Mode C's only safeguard against a support user reaching Curabis/QualityHub was a single manual eyeball check with no re-check ever. Strengthened Step 2 to cover team-inherited and org-default access paths, added an append-only support-user registry, and added Roemer station 15 to periodically re-verify every registered user against it. 6. Columbo's persona was presented as genuine autobiography with no disclosure of its fictional TV origin (Levinson & Link, Peter Falk), unlike Smiley which discloses explicitly. Added a reader-facing editorial note - never something Columbo says aloud, since unlike Smiley he actually performs the persona to customers.
This commit is contained in:
parent
44546d4fe0
commit
9e5273443f
11 changed files with 181 additions and 18 deletions
|
|
@ -875,7 +875,20 @@ Guide administratoren gennem:
|
|||
|
||||
1. Invitér brugeren til organisationen som **member**
|
||||
2. Giv **Read**-rolle på de valgte repos — aldrig Write/Maintain/Admin
|
||||
3. Verificér at brugeren IKKE har adgang til `Curabis/QualityHub`
|
||||
3. Verificér at brugeren IKKE har adgang til `Curabis/QualityHub` — og tjek
|
||||
BÅDE vejene dertil, ikke kun den ene: (a) ingen direkte collaborator-
|
||||
invitation til QualityHub, OG (b) brugeren er ikke medlem af et team der
|
||||
selv har adgang til QualityHub (team-nedarvet adgang omgår en ren
|
||||
per-repo-check), OG (c) organisationens "Base permissions" (Org Settings →
|
||||
Member privileges) ikke er sat bredere end "No permission"/"Read" på en
|
||||
måde der stiltiende dækker private repos. 2026-08-03: et tidligere audit
|
||||
fandt at trin 3 kun tjekkede (a) — en bruger kunne i praksis få adgang via
|
||||
(b) eller (c) uden at noget fangede det.
|
||||
4. **Registrér onboardingen** i `custom/setup/support-users-onboarded.md`
|
||||
(denne fil, append-only) — navn, GitHub-brugernavn, dato, tildelte repos.
|
||||
Uden dette har intet senere trin (station 15 i Rømers runde) noget at
|
||||
tjekke imod, og en glemt/forkert adgang forbliver usynlig for altid, ikke
|
||||
kun til næste inspektion.
|
||||
|
||||
### Step 3 — Claude-miljø (browser, ikke VS Code)
|
||||
|
||||
|
|
|
|||
14
custom/setup/support-users-onboarded.md
Normal file
14
custom/setup/support-users-onboarded.md
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
# Support users onboarded via Mode C
|
||||
|
||||
Append-only registry of every Mode C (support-profile) onboarding — see
|
||||
`curabis-standard.agent.md`'s MODE C section, Step 2.4. Never delete or edit
|
||||
a row after the fact; if a user's access is later revoked or their profile
|
||||
changes (e.g. promoted to full developer access), add a new row noting the
|
||||
change rather than removing the original entry. This is what Rømer's
|
||||
inspection round station 15 reads to periodically re-verify that every
|
||||
support user still has no `Curabis/QualityHub` access and no Write+ role
|
||||
anywhere — a registry with silently edited history defeats that check the
|
||||
same way an edited `[CURABIS-STATE]` comment would.
|
||||
|
||||
| Name | GitHub-brugernavn | Dato | Tildelte repos | Status |
|
||||
|---|---|---|---|---|
|
||||
|
|
@ -70,11 +70,15 @@ Tjek branches ældre end 14 dage uden åben PR.
|
|||
|
||||
### 6. Agent-synlighed i CLAUDE.md
|
||||
Sammenlign filer i `.github/.agents/` med referencer i `CLAUDE.md`.
|
||||
Kald Rømer (`roemer.agent.md`) hvis 1+ agent i mappen ikke er nævnt i
|
||||
CLAUDE.md — det er præcis hans station 8 (agent visibility), og han kan
|
||||
afgøre om det er drift eller en legitim lokal afvigelse der skal videre
|
||||
til Ferencz.
|
||||
|
||||
| Klassifikation | Kriterium |
|
||||
|---|---|
|
||||
| Routine | Alle agenter er nævnt i CLAUDE.md |
|
||||
| Concerning | 1+ agent i mappen er ikke nævnt i CLAUDE.md |
|
||||
| Concerning | 1+ agent i mappen er ikke nævnt i CLAUDE.md — Rømer kaldt |
|
||||
|
||||
---
|
||||
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
---
|
||||
kind: action-skill
|
||||
id: curabis-al-review
|
||||
version: 3
|
||||
version: 4
|
||||
title: CURABIS AL independent review (Torvalds & Winters)
|
||||
description: Independent per-change code reviewer. Runs after the TDD green gate and before merge — the fourth checkpoint, separate from the implementer and from portfolio-level rule governance (Rømer/Immanuel/Court, who ask "is the ruleset healthy", not "is THIS change good"). Two lenses - Linus Torvalds (BC/AL domain-technical correctness, backward compatibility, performance, security) and Titus Winters (general software-engineering maintainability, architecture, complexity over time).
|
||||
inputs: [diff, task-description]
|
||||
|
|
@ -111,6 +111,18 @@ remember to request. See `smiley.agent.md`.
|
|||
`[[task-state-lives-in-the-mandatory-artifact]]`. This is a BLOCKing
|
||||
finding, not a note — the fix is trivial (go check what actually happened
|
||||
and record it truthfully), so there's no reason to let it slide.
|
||||
- **Did the diff honor a prior Ergasterion ruling?** (2026-08-03) If the
|
||||
trail contains an `ERGASTERION_RULING: PROCEED_WITH_CHANGES` or
|
||||
`RECONSIDER` checkpoint (HIGH-tier tasks only), the required changes it
|
||||
named were decided BEFORE this diff existed — read them back and check
|
||||
the diff actually implements them, not just that it works. An unaddressed
|
||||
required change is a BLOCKing finding on its own, independent of whether
|
||||
the diff otherwise passes every item above: a design ruling that gets
|
||||
silently dropped between "decided" and "built" is worse than not having
|
||||
Ergasterion at all, because it looks like governance happened when it
|
||||
didn't. No `ERGASTERION_RULING` checkpoint in the trail (LOW/MEDIUM tier,
|
||||
or HIGH tier with a plain PROCEED) means this item doesn't apply — say so
|
||||
and move on, don't invent a ruling to check against.
|
||||
|
||||
## Protocol
|
||||
|
||||
|
|
|
|||
|
|
@ -1,11 +1,37 @@
|
|||
name: CURABIS task-state check
|
||||
|
||||
# Deterministic enforcement (not LLM diligence) for the AppSource state-trail
|
||||
# format from task-state-lives-in-the-mandatory-artifact.md. Parses the PR
|
||||
# body for a "## CURABIS Task State" checklist and fails if any checked box
|
||||
# appears AFTER an unchecked one - i.e. a later stage claimed without an
|
||||
# earlier one. Silently passes (does nothing) if the section is absent -
|
||||
# this check only applies to PRs that actually opted into the state trail;
|
||||
# 2026-08-03 - scope correction after an audit found the header overstated
|
||||
# this check's actual guarantee.
|
||||
#
|
||||
# What this DOES enforce deterministically: checklist ORDER in the PR body
|
||||
# ("## CURABIS Task State") - a later stage cannot be checked while an
|
||||
# earlier one isn't. It runs on every push/edit, needs no AI session to
|
||||
# execute, and cannot be talked out of failing.
|
||||
#
|
||||
# What this does NOT enforce, and never has: that a checked box corresponds
|
||||
# to a real event (a red test that actually ran, a review that actually
|
||||
# happened). A session or a rushed developer can check every box in perfect
|
||||
# order having done none of the underlying work, and this Action passes.
|
||||
# The order check catches a narrower, still-real failure mode (a later
|
||||
# stage claimed before an earlier one) - it is not proof the trail is true.
|
||||
#
|
||||
# This ALSO does not enforce anything by itself unless a human has
|
||||
# separately added it as a required status check in the repo's branch
|
||||
# protection settings (curabis-standard.agent.md documents this as a
|
||||
# one-time manual step - it cannot be automated by file deployment). Absent
|
||||
# that, a failing run just shows as a red X someone can ignore and merge
|
||||
# past. Rømer's inspection round has a station that checks whether branch
|
||||
# protection is actually configured this way - see roemer.agent.md station 14.
|
||||
#
|
||||
# This check ONLY covers the AppSource track (PR body checklists). The PTE
|
||||
# track (BC task comments) has NO equivalent deterministic backstop - only
|
||||
# Smiley's Close-gate self-verification and al-review's "state trail
|
||||
# complete?" checklist item, both of which are an AI session re-reading its
|
||||
# own/BC's history, not an independent script. That is a known, accepted
|
||||
# gap, not an oversight - see task-state-lives-in-the-mandatory-artifact.md.
|
||||
#
|
||||
# Silently passes (does nothing) if the "## CURABIS Task State" section is
|
||||
# absent - this check only applies to PRs that opted into the state trail;
|
||||
# it must never block an unrelated PR (docs fix, infra change, etc.).
|
||||
|
||||
on:
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue