The same gate that just approved your change governs the code that runs
AMOS — one level down. Two altitudes, one system: every change to the product
itself is proof-carrying and gated before it ships.
This is a recent shipped gate result. Its counts and diff identity are
read from the Plumbline receipt embedded in this build — not copied into the page.
Reviewed
Inline Approval V1
▸
This change touched AMOS's own approval boundary. Plumbline classified it as self-modifying, so the evidence had to pass and a human had to sign off before merge.
- ✓Formatting — no diff (cargo fmt applied)
- ✓Lint + type checks — Finished, 0 warnings
- ✓Focused tests — test result: ok. 18 passed; 0 failed (incl. approval_refuses_machine_principal_even_when_owner, approval_allows_only_session_owner_or_admin, park_output_carries_deep_link_and_summary)
- ✓Integration tests — test result: ok. 148 passed; 0 failed (real Postgres, isolated DB, single-threaded, ~118s). Includes the 4 approval-decision tests migrated to the human-session path: test_company_gate_escalate_park_approve, test_company_gate_deny_does_not_execute, test_company_gate_cross_tenant_isolation, test_sites_lifecycle_draft_preview_gated_publish_serve — each now asserts bearer/MCP approve|deny → 403 (op stays parked) AND approves|denies via the amos_session login cookie.
- ✓Integration tests — CI (authoritative record for the merged #211): the 'Integration Tests' job — conclusion=success — of the CI/CD Pipeline run on this PR's head commit e5d2be7f9a9c63f54b36ecc20ea917db5f26a549 (branch feat/inline-approval-208): https://github.com/amos-labs/amos-managed-platform/actions/runs/29515972172/job/87681006706 (run https://github.com/amos-labs/amos-managed-platform/actions/runs/29515972172, conclusion=success). Local re-verification on origin/main: PASS — 'test result: ok. 1 passed; 0 failed' (real Postgres, single-threaded, finished in 120.77s). NOTE: this test drives many sequential MCP calls and runs right at the ~120s tower request-timeout boundary, so it is slow and observed flaky under local contention (one run in isolation failed at the same 120.77s wall before passing on re-run); CI, which corroborated it green, is the definitive record. Follow-up: consider raising/scoping the timeout for this test or trimming its call count (tracked separately; not part of #211's security fix). [evidence added by follow-up chore/complete-211-receipt — this step was declared in the plan but missing from the merged receipt's evidence.]
- ✓Integration tests — CI (authoritative record for the merged #211): the same 'Integration Tests' job — conclusion=success — of the CI/CD Pipeline run on head commit e5d2be7f9a9c63f54b36ecc20ea917db5f26a549: https://github.com/amos-labs/amos-managed-platform/actions/runs/29515972172/job/87681006706. Corroborated by the 'Lint & Unit Tests' job (conclusion=success): https://github.com/amos-labs/amos-managed-platform/actions/runs/29515972172/job/87681006752. Local re-verification on origin/main: PASS — 'test result: ok. 1 passed; 0 failed' (finished in 0.35s; deterministic, fast). [evidence added by follow-up chore/complete-211-receipt — this step was declared in the plan but missing from the merged receipt's evidence.]
Receipt inline-approval-v1 · diff bound by hash
sha256 b0e173592ba31d50b3395b6dded26d6c7184a3acb5dc11a8e1bcb1a34c3b4fc3