From a3a6e817619af3214fd05731c7c6bb97437ed560 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 22 Jun 2026 17:25:56 -0400 Subject: [PATCH] =?UTF-8?q?docs(agent-team):=20close=20B1=20ordering=20?= =?UTF-8?q?=E2=80=94=20admin-bypass=20disabled=20before=20any=20flip=20via?= =?UTF-8?q?=20the=20B4=20precondition?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Round-4 confirmatory re-review noted (c) admin-bypass-disable sits in Phase 2 while the gate is framed Phase-1. Clarify there is no ordering window: the flip (Phase 3) is gated on Phase 2 completion (B4), so branch protection incl. admin-bypass-disable is necessarily in place before any flip. The check's implementation being a Phase-1 build task (not yet physically built) is expected for a pre-build plan; it is non-optional and flip-blocking, enforced at the Phase-1 hard stop. Stopping the plan-review cycle here per the project's '3 cycles, residual is build-time' rule. --- docs/provisioning/P3-LIVE-FLIP-PLAN.md | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/docs/provisioning/P3-LIVE-FLIP-PLAN.md b/docs/provisioning/P3-LIVE-FLIP-PLAN.md index 177be37..9f5c68e 100644 --- a/docs/provisioning/P3-LIVE-FLIP-PLAN.md +++ b/docs/provisioning/P3-LIVE-FLIP-PLAN.md @@ -163,9 +163,14 @@ workflow (Phase 3), not only the inert version** (see Phase 3). un-mergeable until the box has run it. - (c) branch-protection set so the required checks **cannot be bypassed by admins** ("do not allow bypassing the above settings" / include-administrators) — **no `--admin` merge of the - privileged flip** (NIT). This setting is applied in Phase 2 with the rest of the env/protection. + privileged flip**. Applied in Phase 2; **no ordering window** because the flip (Phase 3) is + gated on Phase 2 completion (the B4 precondition), so admin-bypass is already disabled before + any flip is possible. The Phase-1 required-status-check (a/b) and the Phase-2 branch-protection + (c) together are the gate; the flip cannot happen until BOTH are in place. This is the gate; until it is built+green, the flip is blocked. (Owner: 🤖 build; verified in - the Phase-1 `/sh-security-review` + cross-review hard stop.) + the Phase-1 `/sh-security-review` + cross-review hard stop. The check's implementation is itself + a Phase-1 build task — that it is not yet physically built is expected for a pre-build plan; what + matters is it is non-optional and flip-blocking, enforced at the Phase-1 hard stop.) - [ ] **Concrete "no write token on the box" audit (B-QUESTION → a real check):** a test/script asserting the box env + coordinator config hold no `pull-requests:write` / contents-write token (grep the live env names + assert the App token is only an Actions