feat(engine): TAG-SIGNED — a tag that names a signer, not just write access

The check sat parked as "blocked on an operator decision" on the strength of
0 of 18 repos signing. That zero was never evidence against it: it is what a
practice nobody has adopted yet looks like, and reasoning from it makes the
gate ratify the status quo it exists to move. The rule that settled it asks
something else — would a public AAA+ repository do this? Yes, and unlike the
two conventions that killed VERSION-DRIFT, there is no second convention under
which release tags are better left unattributable.

The measurement then decided the SCOPE, not the yes. Across 20 clones: 158 v*
tags, 144 annotated, 14 lightweight, 0 signed, and not one dated after
2026-08-12. A boolean "this org signs" would have failed 20 correct
repositories on day one with force-moving 144 published refs as its only
remedy — the mechanism that gets gates switched off. So the policy is a DATE in
the register (never in the engine, the rule that keeps the org-profile
exemption a flag): nothing fires today, teeth at each repo's next release.

Verified both directions, because a sweep returning zero proves nothing on its
own — a dead check returns zero too. 21 repos: 18 PREPOLICY + 3 NONE, 0 ERROR,
0 WARN; then against real git objects an unsigned post-policy newest tag does
fire ERROR.

Two exclusions keep one defect from being counted twice: a lightweight tag has
no object to carry a signature (byDesign skip naming TAG-ANNOTATED as owner),
and a pre-policy tag was correct when cut (OK, said out loud, never silence).
It answers "is it signed", never "does the forge vouch for it".

The README row ships in this commit, not after it, and the stale test count in
CLAUDE.md (230 → 241) is corrected here rather than left for the next reader.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XsPsVsvhrSaejK3cLPmnN2
This commit is contained in:
Kjell Tore Guttormsen 2026-08-13 10:51:36 +02:00
commit e6cd8983ca
9 changed files with 415 additions and 17 deletions

View file

@ -214,6 +214,31 @@
"llm-ingestion-pipeline-security": ["v0.3.0"]
},
"$comment_tags_signed_from": [
"The date the org's tag-signing policy takes effect. Operator decision",
"2026-08-13, on the rule that decides these: would a public AAA+ repository",
"do this? Yes — a signed tag ties a released ref to a signer rather than to",
"whoever could write to the forge, and the catalog pins plugins by tag.",
"",
"It lives HERE and not in the engine for the reason the org-profile",
"exemption is a flag rather than `if (klass === 'org-profile')`: the engine",
"holds no org decision of its own. Remove the key and TAG-SIGNED goes back",
"to a notRun SKIP — the gate never assumes a policy nobody recorded.",
"",
"A DATE, not a boolean, and that is the whole reason the check is shippable.",
"MEASURED across 20 clones 2026-08-13: 158 `v*` tags, 144 annotated, 14",
"lightweight, 0 signed, and NOT ONE tag dated after 2026-08-12. A boolean",
"would have failed 20 correct repositories the day it landed — the mechanism",
"that gets gates switched off — and its only remedy would have been force-",
"moving 144 published refs. The date fires nothing today and acquires teeth",
"at each repo's next release, which is how signing is adopted in public.",
"",
"Do NOT backdate this to 'catch up' history. Every tag below it was correct",
"when it was cut, and the check says so out loud (TAG-SIGNED-PREPOLICY, OK)",
"rather than going silent about it."
],
"tags_signed_from": "2026-08-13",
"description_max_codepoints": 180,
"$comment_length": [
"180 codepoints, not bytes and not UTF-16 units. The same string measures 248",