Skip to content

HAC-324: the authoritative filmed run, captured while it happened - #34

Merged
qmarcelle merged 1 commit into
mainfrom
hac/324-authoritative-filmed-run
Aug 24, 2026
Merged

HAC-324: the authoritative filmed run, captured while it happened#34
qmarcelle merged 1 commit into
mainfrom
hac/324-authoritative-filmed-run

Conversation

@qmarcelle

Copy link
Copy Markdown
Contributor

Run ilk-hac340-cloud-1787536029323 on disposable project interlock-film-260823, executed from a worktree at the approved runtime source ae6d0d3 and captured through the hardened Studio path as it ran.

Five provenance-bound frames

scene source sha256
agent-traversal the live traversal, captured while executing 102cafb35c0c02f9
gemini-adk-attribution live Cloud Run config: gemini-3.5-flash, interlock-adk:ae6d0d3 ee007e9c29c5fea3
cloud-run-topology the three services and revisions ae6bd02c7f4ebf0d
cloud-logging-correlation Cloud Logging filtered to this run's id ccd916391f6a8f38
receipt-mutation-observation receipt, EXECUTED, OBSERVED from the packet scene 1 emitted 381c629fa64bbafe

All five clear the HAC-313 artifact floor (467–523 distinct colours, σ 18.7–34.2).

The first frame is the execution, not a retelling of it. The command ran inside the capture, and its stdout — correlation id, ALLOW, receipt digest, 403/401/403 — is what the frame shows.

Parity — all material fields PASS

Runtime source SHA exactly, gemini-3.5-flash, ADK 1.35.1, region, Vertex location, ALLOW, EXECUTED, identical before/after revision digests, identical observed state, and all three fail-closed controls. Cloud Logging correlates to this run, and the proxy log shows the agent service account calling the proxy — internal trust boundary unchanged.

Two discrepancies recorded, not smoothed over

1. resources.observerPrincipal says user:qwynn@marcellelabs.io. That is the provision-time caller. The traversal authenticated by impersonating the dedicated keyless observer SA, because gcloud 580 refuses audience-scoped ID tokens for user accounts. The packet was not edited — evidence is recorded as emitted — and the correction lives in capture-package.json. Adjudicated NON_MATERIAL, and the condition held: controls came back identical.

2. Raw preflight gcloud --format=json dumps are excluded. Cloud Run service descriptions embed INTERLOCK_SIGNING_KEY_PEM — the proxy's Ed25519 private key — verbatim in the service env, and those dumps were taken with plain gcloud before the redaction adapter existed. They were removed rather than committed. Every frame here went through the hardened path, whose redaction covers private-key blocks, and none contains key material. The project is deleted, so the key is dead regardless. This is a direct argument for the adapter's redaction existing at all.

Verification and teardown

  • HAC-340 packet verifier: verified, all 19 assertions including teardown.
  • Teardown completed 2026-08-24T01:50:43Z; project DELETE_REQUESTED; services and service accounts deleted.
  • Frozen HAC-340 / HAC-342 packets untouched. This is new evidence for a new run, labelled as such.

Gates

pnpm run check exit 0 · 645 tests · typecheck · build — all clean.

Run ilk-hac340-cloud-1787536029323 on disposable project interlock-film-260823,
executed from a worktree at the approved runtime source ae6d0d3 and captured
through the hardened Studio path as it ran.

Five provenance-bound frames, each carrying its own sha256 and each clearing the
HAC-313 artifact floor:

  agent-traversal                the live traversal, captured while executing
  gemini-adk-attribution         live Cloud Run config: gemini-3.5-flash and
                                 the interlock-adk:ae6d0d3 image
  cloud-run-topology             the three services and revisions
  cloud-logging-correlation      Cloud Logging filtered to this run's id
  receipt-mutation-observation   receipt, EXECUTED and OBSERVED from the packet
                                 scene 1's traversal emitted

The first frame is the execution, not a retelling of it: the command ran inside
the capture, and its stdout — correlation id, ALLOW, receipt digest, 403/401/403
— is what the frame shows.

Every material parity field matches the frozen HAC-340 packet: runtime source
SHA exactly, gemini-3.5-flash, ADK 1.35.1, region, Vertex location, ALLOW,
EXECUTED, identical before/after revision digests, identical observed state, and
all three fail-closed controls. Cloud Logging correlates to this run, and the
proxy log shows the agent service account calling the proxy, so the internal
trust boundary is unchanged.

Two discrepancies are recorded rather than smoothed over.

resources.observerPrincipal in the packet says user:qwynn@marcellelabs.io.
That is the provision-time caller; the traversal authenticated by impersonating
the dedicated keyless observer SA, because gcloud 580 refuses audience-scoped
ID tokens for user accounts. The packet was not edited — evidence is recorded as
emitted — and the correction lives in the capture package. Adjudicated
NON_MATERIAL, and the condition held: controls came back identical.

The raw `gcloud --format=json` dumps taken during preflight are excluded. Cloud
Run service descriptions embed INTERLOCK_SIGNING_KEY_PEM, the proxy's Ed25519
private key, verbatim in the env — and those dumps were taken with plain gcloud
before the redaction adapter existed. They were removed, not committed. Every
frame here went through the hardened path, whose redaction covers private-key
blocks, and none contains key material. The project is deleted, so the key is
dead regardless.

HAC-340 packet verifier: verified, all 19 assertions including teardown.
Teardown completed 2026-08-24T01:50:43Z; project DELETE_REQUESTED.

The frozen HAC-340 and HAC-342 packets are untouched. This is new evidence for a
new run and is labelled as such.

pnpm run check exit 0, 645 tests, typecheck and build clean.
Copilot AI lite review requested due to automatic review settings August 24, 2026 01:55

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@vercel

vercel Bot commented Aug 24, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
interlock Ready Ready Preview Aug 24, 2026 1:55am

@sonarqubecloud

Copy link
Copy Markdown

@codecov

codecov Bot commented Aug 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@qmarcelle
qmarcelle merged commit 738c4b8 into main Aug 24, 2026
24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants