Skip to content

fix(retirement): reconcile invalid nested SHA in committed E03 decision #402

Description

@Fancy0uth

Parent #400. Paired E03 validation found the committed historical packet is internally inconsistent: orchestration/retirements/e03-provider-preflight/gate-out/compatibility-retirement-decision.json replacement.atomEvidence.sha256 is 8b05ce9a2cd43c97ffc040c2e5d1dfe6ea69a53f392ac960e499fd6ed54369e7, while evidence/replacement-atom.json hashes to 513f1487459138c3588364ae9b1902dfabeffbc14a1177e4945a3b3cdaaa7746 (verified Get-FileHash). The decision field is an artifact ref copied from the E00 approval subject, not projected metadata. The existing PowerShell verifier misses that nested ref; a strict native verifier must reject the tracked packet, so we cannot call historical-packet cutover proven.

Resolve in a separate reviewed change: investigate the original E00 generation/provenance, produce a corrected valid active packet or re-attestation with exact cascading SHA refs and preserve the original bytes as rollback evidence. Add a regression proving every nested ref binds its actual artifact; run old/new verifier where applicable, native E03 and retirement CI gates. Do not hard-code the bad digest, waive the mismatch, reserialize unrelated historical attestations, reset Sentrux baseline, or silently rewrite the old record.

Branch main; approach is forensic audit then separately reviewed packet correction. Fancy0uth lacks claimed-label permission (REST 403); maintainer please add claimed before edits.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    claimedIssue claimed by an active session (DR-0004): read the claim comment before touching it

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions