Fix rotation review evidence and reconcile blocked S1 workplans
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e3b9-b19e-7ba1-9eb4-4faea76af3ea
This commit is contained in:
parent
41f25fe42d
commit
9886567b40
10 changed files with 255 additions and 18 deletions
|
|
@ -117,6 +117,7 @@ def _load_approval(path: Path, plan: list[dict[str, Any]]) -> None:
|
|||
expected = [
|
||||
{
|
||||
"path": item["path"],
|
||||
"sha256": item["sha256"],
|
||||
"before_recipients": item["before_recipients"],
|
||||
"after_recipients": item["after_recipients"],
|
||||
}
|
||||
|
|
@ -202,9 +203,13 @@ def main() -> int:
|
|||
raise RotationError("--apply requires at least one recipient change")
|
||||
_load_approval(args.approval_file, plan)
|
||||
_apply(plan)
|
||||
plan = rotation_plan()
|
||||
if any(item["changed"] for item in plan):
|
||||
after_plan = rotation_plan()
|
||||
if any(item["changed"] for item in after_plan):
|
||||
raise RotationError("recipient drift remains after rotation")
|
||||
if [item["path"] for item in after_plan] != [item["path"] for item in plan]:
|
||||
raise RotationError("protected file inventory changed during rotation")
|
||||
for before, after in zip(plan, after_plan):
|
||||
before["after_sha256"] = after["sha256"]
|
||||
verified = _verify_decryption(protected_files()) if args.verify_decryption or args.apply else False
|
||||
receipt = build_receipt(plan, verified, args.apply)
|
||||
if args.receipt:
|
||||
|
|
@ -219,6 +224,7 @@ def main() -> int:
|
|||
"changes": sum(1 for item in plan if item["changed"]),
|
||||
"decryption_verified": verified,
|
||||
"applied": args.apply,
|
||||
"plan": plan,
|
||||
},
|
||||
sort_keys=True,
|
||||
)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue