Skip to content
This repository was archived by the owner on Sep 20, 2026. It is now read-only.
This repository was archived by the owner on Sep 20, 2026. It is now read-only.

Define signed Every Code agent provenance and verifier vectors #442

Description

@shiny-code-bot

Goal

Implement the signed Every Code agent-run provenance wire contract, signing/verifying library, key material, replay/role-conflict ledger, and deterministic cross-language test vector required by parent #441.

Scope

  • Add a new Every Code-owned Rust crate for provenance claims, challenge binding, Ed25519 compact JWS signing/verifying, runtime-controlled model-family derivation, transcript digesting, and issuance ledger behavior.
  • Bind audience, nonce, canonical challenge digest, repository, PR when available, head/tree SHA, run role, root/session/thread/turn identity, runtime model/family/provider, task identity, issue/expiry times, and evidence digest.
  • Keep policy decisions outside Every Code.
  • Generate a deterministic golden token/JWKS/negative-vector fixture that Launchplane can verify independently.
  • Do not add the final code exec or CLI export surface in this issue.

Acceptance Criteria

  • Signature, issuer, audience, expiry, nonce, challenge, repo/PR/head, role, run identity, and model-family tampering fail verification.
  • One run cannot be issued under both implementer and reviewer roles or replayed as a second run.
  • Model identity comes from observed runtime metadata, never challenge or caller text.
  • Raw remote URLs and transcript contents are never emitted.
  • The golden vector is deterministic and suitable for a PyJWT Launchplane verifier test.
  • ./build-fast.sh passes with no warnings.

Finish Line

Every Code has a tested signed provenance library and stable cross-language verifier vector.

Next Action

Add the crate and fixed-clock golden vector around existing Ed25519 and agent/session identity primitives.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    planDurable planning issueplan:donePlan completed or superseded

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions