Skip to content

Releases: Judgment-Pack/judgment-pack-desk

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 07 Oct 03:30
f144b4b

Desk v0.7.0

A desk's decision record can now be handed to someone outside, and Desk holds the record to what was handed over. Jobs runs are signed with a key of Runner's own, their chain of runs can be handed over the same way, and a Jobs record beside the decision record checks that chain with the runtime's own verifier over Desk's private copy. The pinned Runtime, Runner and Gateway are unchanged from v0.6.0.

Updating from v0.6.0 needs no backup step: nothing here changes a desk's jpack.json, a Jobs store or a lock. Updating from v0.5.x or earlier: see v0.6.0's notes and back up every desk's Jobs store first.

What changes for you

  • Hand-over (Admin → Project → Decision record). You add holders by a label and a channel in your own words. For each holder, Download checkpoints saves the runtime's checkpoint lines after that holder's cursor, as the exact bytes the runtime printed; Confirm records that the file went to the holder, and only then does the cursor move. The decision record then holds the trail to what was handed over, and its coverage says which records a held checkpoint witnesses.
  • Jobs runs are signed. Each desk's Runner is started with a signing key of its own, kept by Desk outside the project. Help & About → Gates shows Runner's public key, or why runs are not signed. A run's version-5 export carries its signature; jpack-runner verify-run --public-key <key> --require-signed checks it.
  • The Jobs chain in hand-over. Where a desk has a Runner, each holder has a second row, "Jobs runs", with its own cursor: the checkpoints of Runner's chain of runs, from Desk's private copy of it.
  • Jobs record (Admin → Project, after the decision record). On request, Desk takes a fresh private copy of Runner's chain of runs and runs jpack audit verify --trail <copy> with the Jobs checkpoints it holds for each holder. It shows the runtime's status, coverage, findings and sentences verbatim, Runner's key state, and offers the chain for download. It never runs on a timer.
  • Key rotation follow-ups. The list of public keys is checked again immediately before the next key is put in place; a rotation the runtime did not write now says Desk kept the current key; a failure inside a rotation leaves the key lock released.

What a hand-over establishes, and what it does not

  • A held checkpoint, kept by a holder the operator does not control: the records up to it are the ones that existed when it was handed over. It establishes nothing after it, and nothing about a holder who did not keep every checkpoint, or about when it was made.
  • Desk's record of hand-overs: nothing to anyone but you. You keep it and can change it. The decision record says so beside the list: "This is Desk's own record. You keep it, and you can change it, so it proves nothing to a holder or to anyone else. Only the holder's own copy counts."
  • A Jobs run's signature: a holder of Runner's key signed that record. It binds nothing against the operator, who holds the key. The chain of runs itself carries no signature; the Jobs record passes no key, and says that each run's signature is checked by verify-run on that run's export.
  • Desk's verification, decision record and Jobs record alike: what your own copies show, with the keys and checkpoints you keep. It is not evidence to anyone who does not trust you.

Hand-over by download or copy (#241, ADR-0010 PR 5)

  • Holders and Desk's record live in <project>/.desk-private/handover/, owner-only, refused by the file API, in no backup, like the trail.
  • GET /api/audit/checkpoints?holder=<id> runs jpack audit checkpoint --since <cursor> --limit 300 in the human form, batch after batch, and answers the concatenated standard output as application/jsonl, never re-encoded; a download cuts at the record the first call read, so every byte is the runtime's.
  • A confirmation regenerates the same bytes and compares digests: records added since, a rewrite, another trail identity or a replayed confirmation are refused as stale, and nothing is written.
  • Each holder's held file is read whole and held to the holder's record (complete lines, the record's trail, increasing sequences, the last sequence and the digest) before it is passed to --expect; one that does not match is named and passed to nothing. An unreadable record is said as such, never as "no holders".
  • Desk's lists are written within the 64 KiB they are read with; a holder past that bound is refused in plain words.

Runner's signing key (#232, ADR-0010 row 11)

  • <Desk configuration folder>/secrets/signing/runner/<name>.seed, under the same custody as the desks' keys, made at Runner's start where none is kept, under the one signing lock. A key is named to Runner only where, under the lock, no creation marker is left, the seed and its list agree, and the runtime reads the seed under its own rules.
  • A key the runtime or Runner refuses, or a lock that is held, never refuses or fails a run: Runner is started again without the key, the run is recorded unsigned, and Gates says why.

The Jobs chain, and the Jobs record (#254, ADR-0010 rows 8b and 12)

  • Desk's private copy of GET /v1/run-chain is held whole within Desk's bound and replaced on each use; a transfer that ends early is an error, never a report over a shorter chain.
  • The Jobs cursor, held files and record are kept apart from the decision record's, by chain.
  • The Jobs record's sentence: "Desk ran this over its own copy of the runner's chain of runs, with the checkpoints it keeps. It shows what a holder would see. It is not evidence to anyone who does not trust this installation."

Also in this release

  • The web suite holds under machine load (#242); the mutation harness ends a hung suite's whole process tree at its bound (#245).

Verification

CI ran frontend behaviour, all twelve locale catalogues, the Go chassis tests, the Jobs companion against the pinned Runner and Runtime, the local Gateway checks and the native archive builds.

  • Review: each change to keys, hand-over or verification had one cross-vendor round, recorded on its pull request with a disposition for every finding.
    • #232 (on its predecessor #229): two HIGH findings on the key's custody lock, fixed before merge.
    • #241: one HIGH (a held file passed on its metadata alone) and two MEDIUM, all fixed before merge.
    • #244: two MEDIUM, fixed before merge.
    • #254: one HIGH (the check after a confirmation of the chain joined a check already in flight, so the panel could show the earlier report) and two MEDIUM, all in the page, fixed before merge.
  • Mutation checks: every safeguard has a row in scripts/mutation-check.sh. #232: 29 rows caught before merge, 212 of 214 after (the two others hang or panic the suite rather than fail, #252). #241: 83 new rows and 198 of 199 existing rows caught before merge, 29 of 29 of the review round's. #244: 65 Go and 36 web. #254: 69 new rows (34 Go, 35 web) and 17 existing rows in changed lines, all caught before merge; the 163 other rows in touched files run after merge.

Not exercised: macOS and Windows for key custody and hand-over; two Desk processes on one project at once; a holder who does not keep the file; the page in a real browser beyond jsdom; a native speaker's reading of the new messages.

See installation and updates and release verification.

Component Pin
Runtime v0.27.1
Runner and source worker v0.6.0
Gateway and required Desk adapters v0.9.1

Platforms

This release contains complete Linux/amd64, macOS Apple Silicon (arm64), and
macOS Intel (amd64) archives. All three archives were built and smoke-tested on
native GitHub-hosted runners before publication; neither macOS archive is merely
cross-compiled. Component versions come from the same release lock.

macOS executables are not Developer ID signed or notarized. Gatekeeper may block
downloaded executables; verify the release and checksums, then use Apple's
Privacy & Security → Open Anyway procedure
for the blocked executable. Native CI does not exercise these dialogs. The Codex
subscription subprocess bridge remains Linux-only.

No Windows archive is published. Windows execution is untested, and the managed
installer supports only Linux and macOS.

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 05 Oct 23:59
ac20edd

Desk v0.6.0

New desks are signed. Desk keeps a signing key for each desk it makes, starts new desks at configVersion "6" with that key, and its decision record checks the trail's signatures with the desk's public keys. You can rotate a desk's key, and Desk finishes or undoes a rotation that a stop cut short. Desk moves to Runtime v0.27.1, Runner v0.6.0 and Gateway v0.9.1, and each job's Activity tab now reads Runner's journal.

Before you update: back up every desk's Jobs store. Runner v0.6.0 migrates each store to its schema "2" on its first start, and the Runner that earlier Desks bundle (v0.5.0) then refuses that store. Desk's updater does not copy the store, and a rollback selects the earlier Desk, not the earlier data: after a rollback, Jobs cannot open a migrated store until a copy from before the update is put back. Stop Desk, copy each Jobs workspace folder, then update (installation and updates).

What changes for you

  • A desk you make now is signed. Where the runtime reads configVersion "6", Desk keeps an Ed25519 key for the desk in its own configuration folder, writes the desk's jpack.json at "6" naming that key, and locks it. Each deciding run's record is then signed by the runtime. Desks made earlier, and the project Desk was started on, are not changed.
  • The decision record (Admin → Project) checks signatures with the desk's public keys, shows those keys for you to hand to a holder, and shows the runtime's own check of the key.
  • Rotate a desk's key from the decision record, on your confirmation.
  • The Activity tab reads Runner's journal of job activity.
  • The Runs table and run page say "Not recorded" for a run time Runner did not store or that cannot be read, instead of failing.

Signed desks: key custody (#219, ADR-0010 PR 3a)

  • Where the key is. One seed per desk at <Desk configuration folder>/secrets/signing/<desk id>.seed, 0600, in a folder that is 0700 and held to Desk's custody checks: real folders, not links, writable by the user alone. The runtime writes the seed (jpack audit key generate) and never over a file; Desk never reads its bytes. The desk's public keys are kept beside it, in <desk id>.keys.jsonl.

  • New desks at "6".

    The runtime reads Desk can keep a key The new desk
    "6" yes "6", signed
    "6" no "5", unsigned, and the creation says why
    "5", not "6" (not asked) "5", unsigned, and the creation says so

    A creation that fails at any step leaves no key behind. A creation stopped by a crash is finished or cleared at the next start, and a key whose desk was published is never removed because a file could not be read for a moment.

  • The decision record passes the desk's public keys to jpack audit verify only where the key list's key in force is the seed's own (jpack audit key public); otherwise it passes none, and says why. It shows the runtime's packs validate check of the key in the runtime's words.

  • No path is shown. Every sentence the panel passes on has the key's location, the configuration folder and the home folder replaced, in every spelling the runtime prints.

  • What a signature binds. A holder of the key signed these exact bytes. It binds nothing against the owner, who holds the key, or against a program running as the owner's user, which can read it. A Jobs run is not signed by this release.

Rotating a desk's key (#231, ADR-0010 PR 3b)

  • Your action, never scheduled. The decision record offers "Rotate signing key" behind a confirmation. Desk makes the next key, has the runtime hand signing over to it (jpack audit key rotate), adds it to the desk's list of public keys, and puts it in the current key's place.
  • Whether the runtime handed signing over is read from the trail's signature sidecar, not from its answer alone. A rotation it refused is undone. A rotation that a stop cut short is finished or undone at the next start, or, where Desk cannot tell which, left as it is, and the decision record says so.
  • What a rotation does not do:
    • it revokes nothing: whoever holds the old key can still sign as it;
    • a holder needs the new public key, and to be told about the old one;
    • a record written during the rotation may be unsigned;
    • the old seed's name is removed, but its bytes may remain on the disk;
    • a lost key cannot be rotated away from.
  • The decision record passes every key, in order, and checks that the list agrees with the trail's own rotations.
  • A desk keeps at most 64 keys, and Desk offers no rotation past that.
  • The project Desk was started on has no key in this release, so it has none to rotate.

One lock for every change to keys (#230)

Two Desk processes can share one configuration folder, for example Desk started on two projects. One's start-up cleanup could remove the other's new desk key. Now:

  • What takes the lock: a key's creation, the start-up cleanup, a rotation and its recovery each hold one exclusive lock on Desk's signing folder.
  • Cleanup and recovery that find the lock taken change nothing, and leave it for the next start.
  • A creation or rotation waits up to ten seconds, then refuses with a plain message.

The Activity tab reads Runner's journal (#228, closes #218)

  • It shows Runner's own log of job activity, in Runner's order. Each row is marked as a journal entry or a record, and no row names a person as the actor.
  • It reads the journal forward, one page at a time, and shows no entry until it has read to the end. It renders the newest 500, with a control for earlier ones, and keeps at most 20,000.
  • A runner that serves no journal leaves the record rows as before, with one line saying so.
  • The journal is neither chained nor signed, and the tab says so.
  • A change in the Jobs proxy: /api/operations/ now refuses any Jobs path that contains a percent-encoding, on every forwarded route. The page never sends one.

"Not recorded" for a missing run time (#226, closes #223)

The Runs table, the run page and the Jobs index show "Not recorded" for a run time Runner did not store or that cannot be read, where they threw before.

Component updates (#227)

  • Runtime v0.27.1. It refuses a signing key kept where another user could remove or replace it, which Desk's custody already meets. Every audit verify report now also says, among what it does not establish, that the trail records decisions, not refused or failed attempts (runtime ADR-0048); the decision record shows that sentence as the runtime writes it.
  • Runner v0.6.0. A journal of job activity, which the Activity tab reads; exports of a run whose job has no mapping v2 (version 3 or later, with "inputs":"not-mapped"), which the verification download names by version as before; and the store migration above. Desk's limits on what it reads from Runner are unchanged: Runner v0.6.0's export and chain limits are those of v0.5.0.
  • Gateway v0.9.1. It seals a session that only a discarded registry line names; Desk's managed gateway is unaffected on the paths Desk uses.

Existing job releases keep their frozen Runtime. Desk's release stays at state epoch 1: the storage change is Runner's store, and the backup above is the explicit step.

Verification

CI ran frontend behaviour, all twelve locale catalogues, the Go chassis tests, the Jobs companion against the pinned Runner and Runtime, the local Gateway checks and the native archive builds.

  • Review: each change to key handling had a cross-vendor round, recorded on its pull request with a disposition for every finding.
    • #219 had three rounds. The last high-severity finding, a read error at start that could remove a published desk's key, was fixed before merge.
    • #231 had one round. Its one finding that could leave a desk without a usable key, rotation past the key list's bound, was fixed before merge. Four others are filed as #239.
  • Mutation checks: every safeguard of #219 and #231 has a row in scripts/mutation-check.sh. The rows that each fix added or changed were run and caught before its merge. The full set for #219 is being run after merge.

Not exercised: macOS and Windows for key custody (custody is Unix-only, and keeps no key on a build that cannot establish ownership); a key owned by another user (faked through a test seam); a rotation stopped at every moment by a real crash (tests stop it at each step through a seam); two real Desk processes on one configuration folder (tested with a second lock holder in one process); a native speaker's reading of the new messages.

See installation and updates and release verification.

Component Pin
Runtime v0.27.1
Runner and source worker v0.6.0
Gateway and required Desk adapters v0.9.1

Platforms

This release contains complete Linux/amd64, macOS Apple Silicon (arm64), and
macOS Intel (amd64) archives. All three archives were built and smoke-tested on
native GitHub-hosted runners before publication; neither macOS archive is merely
cross-compiled. Component versions come from the same release lock.

macOS executables are not Developer ID signed or notarized. Gatekeeper may block
downloaded executables; verify the release and checksums, then use Apple's
Privacy & Security → Open Anyway procedure
for the blocked executable. Native CI does not exercise these dialogs. The Codex
subscription subprocess bridge remains Linux-only.

No Windows archive is published. Windows execution is untested, and the managed
installer supports only Linux and macOS.

v0.5.2

Choose a tag to compare

@github-actions github-actions released this 05 Oct 13:47
7b19cf8

Desk v0.5.2

Each job gains an Activity tab, the verification download asks Runner for its newest export and names what it answers, the runner's chain of runs can be downloaded as exact bytes, and the Tests workspace says which kind of invalid expectation the runtime found. Desk stays on Runtime v0.26.0, Runner v0.5.0 and Gateway v0.9.0.

What changes for you

  • Activity, a fourth tab on each job. One row per record Runner serves: runs, occurrences and preparations, newest first by the time Runner first recorded each, with what it says, who initiated it (this installation, or a trigger by name and revision), the release, and what the run's record holds. Rows open the right pane; a run row links to the run page.
  • The run page shows when the run started, who requested it, the release's pack and runtime digests, and whether the exact record bytes and a signature sidecar are retained. Each of those is shown as present or absent, never as checked.
  • The verification download asks for export version 5 and names the version Runner answers, with one sentence per version; a version-4 or 5 export shows the run's chain entry as "chain entry N, not checked".
  • Download the runner's chain of runs, beside Jobs | Runs: the whole chain, byte for byte as the runner sent it, unverified here.
  • The Tests workspace says which kind of invalid expectation the runtime found: a §8.3 defect as the runtime words it, a limit as input the runtime did not admit, and an expectation no pack can produce as the expectation to change, not the draft.
  • Admin → Project → Decision record now says that Jobs runs are recorded by the runner, not in that trail.

An Activity tab on each job (#222, closes #213)

The tab is built only from records Runner already serves. Nothing is synthesised: a record without the time that orders it gets no row, a missing later time is left out rather than filled in, and no row is shown until every list the filter reads has answered. An interrupted run's finish is labelled as the time the runner recorded the interruption, since Runner sets it at restart. No sentence says "verified", "valid", "witnessed" or "audit trail": nothing on this tab is checked against held material.

Export version 5, and the chain of runs as exact bytes (#220, closes #214)

This is the first half of ADR-0010's delivery PR 8, split out so it ships before hand-over, which it does not need. Runner v0.5.0 has served export versions 2 to 5 and GET /v1/run-chain since its release; Desk refused versions above 3 in two places and had no route for the chain.

  • The proxy accepts versions 2 to 5, asked once; the page asks for 5 and names the version the body carries, since Runner answers the highest version a run's material allows: a run with no chain entry is answered at 3 or 2, an unsigned run at 4.
  • A new GET-only route passes the chain through untouched as application/jsonl, under a bound of 67,174,400 bytes that fails the download rather than truncating it; a transfer that ends early is an error on every route, never a shorter answer.
  • One cross-vendor round: no HIGH or MEDIUM; one LOW (the bound's wording in the documents) fixed, and the bound test strengthened to show the proxy stops reading near the bound.

What it establishes: the saved export and the saved chain are the runner's bytes. What it does not: nothing here checks them; Runner's verify-run does, with the material a holder keeps.

The Tests workspace names the kind of invalid expectation (#211, closes #208)

The workspace showed the runtime's bare message for any invalid expectation. It now words each kind the way the research feature does, through catalogue templates in all twelve locales. Harness rows for this and for #207 (#210, #212) now hold the branches.

ADR-0010 amended (#224, closes #217)

A dated amendment that reverses no decision: the status lines say what has shipped (PRs 1 and 2 in v0.5.1; PR 8a here), the checkpoint hand-over command gains --limit 300, the delivery table splits PR 8 and adds rows for a Runner signing key and a Jobs record panel, and §4, §5 and §8 carry verification of a chain copy with audit verify --trail. Section 5 says that Runner signs each run's record, not its chain entries, which the Jobs record panel's design must account for.

Component updates

None. The pins are unchanged, and newer releases exist upstream:

  • Runtime v0.27.0 and v0.27.1 refuse a signing key kept where another user could remove or replace it, and say in every audit verify report that the trail is silent about refused and rehearsed evaluations. Desk's key custody (ADR-0010 PR 3, in progress) places keys where that rule accepts them and shows that report; the pin moves with that work.
  • Runner v0.6.0 keeps a journal of job activity, exports runs of jobs with no mapping or a v1 mapping without lineage, and serves a failed run's diagnostics. A store it opens is migrated to its schema "2" and is then refused by Runner v0.5.0, so the pin moves only with a release note that says so and with the Activity tab reading the journal (#218). Do not replace the Runner this Desk bundles with v0.6.0 by hand: a store that Runner opens cannot be read by this Desk's Runner afterwards, and Desk's updater keeps the pinned one.
  • Gateway v0.9.1 seals a session that only a discarded registry line names; Desk's managed gateway is unaffected on the paths Desk uses.

Existing job releases keep their frozen Runtime. State epoch remains 1.

Verification

CI ran frontend behaviour, all twelve locale catalogues, the Go chassis tests, the Jobs companion against the pinned Runner and Runtime, the local Gateway checks and the native archive builds.

  • Mutation checks: #220 added Go and web rows to scripts/mutation-check.sh for the version handling, the chain route, its bound and an early-ended transfer; #222 added 24 rows for the Activity tab; #210 and #212 added the rows for #207 and #211. Every row was run and caught by a named test.
  • Review: #220, whose proxy change is not frontend, had one cross-vendor round recorded on its pull request. #222 and #211 are frontend and had the in-house checks. #224 is documentation.

Not exercised: the Activity tab against a live Runner (its screenshots and tests use recorded fixtures); the chain download against a live Runner; a native speaker's reading of the new messages in the eleven catalogues other than English.

See installation and updates and release verification.

Component Pin
Runtime v0.26.0
Runner and source worker v0.5.0
Gateway and required Desk adapters v0.9.0

Platforms

This release contains complete Linux/amd64, macOS Apple Silicon (arm64), and
macOS Intel (amd64) archives. All three archives were built and smoke-tested on
native GitHub-hosted runners before publication; neither macOS archive is merely
cross-compiled. Component versions come from the same release lock.

macOS executables are not Developer ID signed or notarized. Gatekeeper may block
downloaded executables; verify the release and checksums, then use Apple's
Privacy & Security → Open Anyway procedure
for the blocked executable. Native CI does not exercise these dialogs. The Codex
subscription subprocess bridge remains Linux-only.

No Windows archive is published. Windows execution is untested, and the managed
installer supports only Linux and macOS.

v0.5.1

Choose a tag to compare

@github-actions github-actions released this 05 Oct 01:50
362e6b3

Desk v0.5.1

Two fixes and no new capability. Desk stays on Runtime v0.26.0, Runner v0.5.0 and Gateway v0.9.0.

What changes for you

  • Research: an expectation no pack can produce is shown as the expectation's defect, not as something to repair in the draft. The runtime's sentence that names the rule is shown with it, and no repair round starts on it.
  • Nothing else visible. The other change is in how a release archive is built.

An unreachable expectation is the expectation's defect, not the candidate's (#207, closes #137)

The pinned runtime answers JPS-EXPECTATION-UNREACHABLE for an expectation no conforming pack can reach: an unresolved result retaining not-applicable, no-match beside any other reason, or an outcome id outside the identifier grammar. Desk read that row as an admitted §8.3 defect, worded it that way, and every caller presented it as something to repair in the candidate.

  • JPS-EXPECTATION-UNREACHABLE is its own case, apart from a §8.3 defect and a limit. The person reads: "This expectation names a disposition no pack can produce, so the expectation must change, not the draft:" followed by the runtime's message, which names the rule.
  • The issue list, the proposal check, the approval check and the reopened-draft recheck all present it as an expectation to change, and start no repair round on it. They already stopped before a repair round on any invalid finding; the change is the wording, and tests now hold each of them.
  • The fixture holds the runtime's live answers for the three unreachable shapes, byte for byte, from Runtime v0.26.0.

The Tests workspace still shows the runtime's bare message for an invalid expectation (#208).

Release archives retry a component download (#206, closes #203)

The release-archives job, and check-release.py at release time, fetch the published components with gh release download. The download failed intermittently, twice in about four runs, and the log held only Python's CalledProcessError without what gh had printed.

  • The download is retried, at most three attempts, with waits of 2 and 4 seconds. Before a retry the download directory is emptied, because gh refuses to overwrite a partial file.
  • The checksum check and gh attestation verify are never retried; they fail at once, as before.
  • Every command's standard error is kept. A failure names the command and repeats what gh said; a command that printed nothing says so.

Nothing in the app changes. The archives this release carries were fetched through the new code.

Component updates

None. Runtime v0.27.0 refuses a signing key kept in a directory anyone else could write or that another user owns; Desk does not pin it yet. Desk's own key custody (ADR-0010, in progress) places keys where that rule accepts them, and the pin moves with that work.

Existing job releases keep their frozen Runtime. State epoch remains 1.

Verification

CI ran frontend behaviour, all twelve locale catalogues, the Go chassis tests, the Jobs companion against the pinned Runner and Runtime, the local Gateway checks and the native archive builds.

  • Mutation checks: #207's six branches were each broken by hand and caught by a named test; their rows for scripts/mutation-check.sh follow in a change of their own. #206's eleven variants are in its pull request; the harness runs no Python rows.
  • Review: #206, which is not frontend, had one cross-vendor round, recorded on its pull request: no HIGH or MEDIUM, one LOW accepted without change. #207 is frontend and had the in-house checks.

Not exercised: the retry recovering from a real transient failure in CI, which only the stand-in gh showed.

See installation and updates and release verification.

Component Pin
Runtime v0.26.0
Runner and source worker v0.5.0
Gateway and required Desk adapters v0.9.0

Platforms

This release contains complete Linux/amd64, macOS Apple Silicon (arm64), and
macOS Intel (amd64) archives. All three archives were built and smoke-tested on
native GitHub-hosted runners before publication; neither macOS archive is merely
cross-compiled. Component versions come from the same release lock.

macOS executables are not Developer ID signed or notarized. Gatekeeper may block
downloaded executables; verify the release and checksums, then use Apple's
Privacy & Security → Open Anyway procedure
for the blocked executable. Native CI does not exercise these dialogs. The Codex
subscription subprocess bridge remains Linux-only.

No Windows archive is published. Windows execution is untested, and the managed
installer supports only Linux and macOS.

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 03 Oct 12:23
7707252

Desk v0.5.0

This update turns the gates on by default (ADR-0009):

  • new desks start under a reviewed set, with an audit trail;
  • the project Desk was started on, and older desks, are offered the same, and nothing is changed until the owner confirms;
  • Jobs refuse a release whose saved tests did not run and pass.

It also moves Desk to Runtime v0.26.0, Runner v0.5.0 and Gateway v0.9.0.

What changes for you

  • Create job refuses an untested release. Runner answers 409 release_untested, and Desk shows it. Existing jobs keep running. To allow untested releases again, restart Desk with --runner-require-tested-releases=false.
  • A new desk is gated. A deciding run of a pack that is not in the reviewed set is refused. Rehearsals and tests still answer, and every evaluation Desk itself makes is a rehearsal, with one exception the README names. requireComparableFacts refuses any evaluation, rehearsals included, that reads a fact of a type no comparison in the pack can match.
  • Your existing projects are not changed. Packs shows a note offering the gates, and Admin → Project has a Gates card. Before you confirm, read what the offer lists. If the project already keeps a lock, the upgrade writes a new one with the new jpack.json: commit both files together, or a CI step that runs packs verify fails on config-drift.
  • An inherited JPACK_SIGNING_KEY now has an effect. Runtime v0.26.0 signs audit records where a key is set. A JPACK_SIGNING_KEY set where Desk was started reaches every runtime Desk starts, for every desk, and the runtime can sign their records with it. ADR-0010 removes it for desks Desk made; that is not built yet.

Gates on by default (ADR-0009, #190)

  • New desks (#193). POST /api/desks writes jpack.json at configVersion "5", with requireReviewed, requireComparableFacts and the audit directory .desk-private/audit, made owner-only. The runtime then locks the empty project, in jpack.lock.json, before the desk exists.

    • With a runtime that reads "4" but not "5", the desk is made without requireComparableFacts, and the creation says so.
    • With an older runtime, or if the lock fails, no desk is made.
    • A JPACK_CONFIG set where Desk was started no longer applies to a desk Desk made.
  • Review and lock (#195). On Packs, Review and lock shows what the runtime's packs verify finds, file by file, in plain words. Each pack's finding is also shown beside its name.

    • A diff is shown only where Desk kept a copy of exactly the bytes the lock names, in .desk-private/reviewed/.
    • One confirmation locks the whole set, through the runtime's packs lock. Desk locks exactly the files it showed, or nothing.
    • Locking records that you confirmed these exact files as the project's reviewed set. It is not a second person's approval, and it records no name.
  • Tested releases by default (#194). --runner-require-tested-releases now defaults to on. Every desk's Runner boot line states the policy, true or false, and the page says which applies.

  • Jobs: is a release in the reviewed set? (#196) Review this release compares the SHA-256 of the release's exact pack bytes with what the project's lock pins for its decision id. It shows the runtime's findings beside that, and refuses nothing. "In the reviewed set" means the lock pins these exact bytes. It does not mean the pack is right, or say who reviewed it.

  • The offer for existing desks (#197). It lists each change with what it writes and why:

    • jpack.json: the gate members, changed by its bytes, so that every other member, its order and its spelling are kept;
    • .desk-private/ as the last line of .gitignore, where the project is in a Git work tree;
    • the first lock;
    • requireComparableFacts, as an item of its own that can be declined.

    The configuration and the lock go together: if the lock fails, every file is put back as it was. Desk offers no configuration version the runtime cannot read.

  • The README and in-app help (#199) say what each gate holds, what is recorded, and whom requireReviewed binds. They also say how to give an outside agent the project's tools under the gate.

Defensible decision records: decided, not built (ADR-0010, #198)

ADR-0010 is accepted. It decides how Desk will keep a desk's record defensible on top of Runtime ADR-0047:

  • key custody;
  • handing over checkpoints;
  • stamping;
  • a verification panel;
  • Runner's chain of runs.

None of it is in this release. The runtime this release pins chains each desk's audit trail by default. But Desk takes, shows and hands over no checkpoint, so the chain shows nothing yet to someone who does not trust the desk's owner.

Component updates

  • Runtime v0.26.0:
    • A project's audit trail is chained over its exact bytes, by default (ADR-0047).
    • New jpack audit verify, checkpoint, repair, key and stamp commands; Desk runs none of them yet.
    • Records are signed where a signing key is set.
  • Runner v0.5.0:
    • A chain of the installation's runs, and signed audit records.
    • Verification export versions 4 and 5.
    • Desk still asks for version 3, does not pass GET /v1/run-chain through, and gives Runner no signing key.
    • A run's answer now also carries its signature sidecar, so Desk reads a run and its verification export up to Runner v0.5.0's export limit, 19,596,893 bytes (#200).
  • Gateway v0.9.0:
    • A decision policy can require a signed record. Desk sends no writes through /act.
    • The engine refuses to start where another user could replace an adapter it launches, its decision-record directory, or a link to its seed or credentials. The bundle's adapters, owned by the user who runs Desk, pass.

Existing job releases keep their frozen Runtime. Records made with earlier bundles, development builds or explicit Runtime overrides still need their original binary for replay. State epoch remains 1.

Verification

CI ran frontend behaviour, all twelve locale catalogues, the Go chassis tests, the Jobs companion against the pinned Runner and Runtime, the local Gateway checks and the native archive builds.

  • Mutation checks: each change to a safeguard added rows to scripts/mutation-check.sh, and each row was run against the tests it targets and caught. A row that did not compile was not counted as caught.

  • Review: each change but #199, which is documentation and help, had cross-vendor review, recorded on its pull request with a disposition of every finding.

    • #193: two rounds; the first found two HIGH, both fixed.
    • #194: one round; one MEDIUM, a test gap, fixed.
    • #195: three rounds; the first found three HIGH, the second one more, all fixed.
    • #196: two rounds; the first found one HIGH, fixed.
    • #197: two rounds; the first found three HIGH, all fixed.

    #200, the pin update, raised one read bound by 23,457 bytes to match the pinned Runner, and took none.

Not exercised:

  • the reviewed-set comparison in a browser on an origin that is not a secure context, where it says "Not known";
  • a native speaker's reading of the new messages in the eleven catalogues other than English.

See installation and updates and release verification.

Component Pin
Runtime v0.26.0
Runner and source worker v0.5.0
Gateway and required Desk adapters v0.9.0

Platforms

This release contains complete Linux/amd64, macOS Apple Silicon (arm64), and
macOS Intel (amd64) archives. All three archives were built and smoke-tested on
native GitHub-hosted runners before publication; neither macOS archive is merely
cross-compiled. Component versions come from the same release lock.

macOS executables are not Developer ID signed or notarized. Gatekeeper may block
downloaded executables; verify the release and checksums, then use Apple's
Privacy & Security → Open Anyway procedure
for the blocked executable. Native CI does not exercise these dialogs. The Codex
subscription subprocess bridge remains Linux-only.

No Windows archive is published. Windows execution is untested, and the managed
installer supports only Linux and macOS.

v0.4.2

Choose a tag to compare

@github-actions github-actions released this 02 Oct 19:28
0a0aa88

Desk v0.4.2

This update moves Desk to Runtime v0.25.0, Runner v0.4.0 and Gateway v0.8.1. The verification download now saves Runner's export version 3, which carries the audit record's exact bytes.

Verification download

Download verification record on a run now asks Runner for verification export version 3. That version carries the run's audit record exactly as the Runtime wrote it, so its digest can be compared with a gateway receipt's decision.recordDigest.

  • Runner answers with version 2 for a run that holds no such bytes, such as one recorded before Runner v0.4.0. The saved file is named for the version it holds, <run>-verification-v3.json or -v2.json, read from the export itself. A line beside the button says which version was saved.
  • The file is saved byte for byte as Runner sent it.
  • Desk forwards a version only on the verification route, and only when it is asked once for 2 or 3. It refuses anything else itself.
  • The verification and run routes now read up to Runner's export limit, about 18.7 MiB. Every other route stays at 16 MiB.

A version-3 file shows that the bytes are consistent with the exported record. Only a digest held independently, such as a gateway receipt's, shows they are the bytes the Runtime wrote, and verify-run does not make that comparison.

Component updates

  • Runtime v0.25.0:
    • Audit records also carry unknownCauses and typeMismatches.
    • A project may opt in to requireComparableFacts under configVersion "5". Desk does not write it.
    • experimental compare warns when two packs are different decisions or no input resolved.
  • Runner v0.4.0:
    • verify-run reports which inputs were asserted and which rule parameters no signed request commits. --require-sourced refuses such a run.
    • Runs keep the audit record's exact bytes, and export version 3 carries them.
  • Gateway v0.8.1: no program changes. Its notes explain what a decision policy with reviewed but no packs admits.

Existing job releases keep their frozen Runtime. Records made with earlier bundles, development builds or explicit Runtime overrides still need their original binary for replay. State epoch remains 1.

Verification

CI ran frontend behaviour, all twelve locale catalogues, the Go proxy tests, the Jobs companion against the pinned Runner, the local Gateway checks and the native archive builds.

  • Mutation checks: seventeen deliberate mutations of the new forwarding, bounds and download rules were caught by the new tests.
  • Review: the change had one cross-vendor review round. It found two test gaps, both fixed, and no defect in the code.

Not exercised: a real Runner serving a version-3 export through Desk (the proxy tests use a fake Runner), and a download near the 18.7 MiB limit in a browser.

See installation and updates and release verification.

Component Pin
Runtime v0.25.0
Runner and source worker v0.4.0
Gateway and required Desk adapters v0.8.1

Platforms

This release contains complete Linux/amd64, macOS Apple Silicon (arm64), and
macOS Intel (amd64) archives. All three archives were built and smoke-tested on
native GitHub-hosted runners before publication; neither macOS archive is merely
cross-compiled. Component versions come from the same release lock.

macOS executables are not Developer ID signed or notarized. Gatekeeper may block
downloaded executables; verify the release and checksums, then use Apple's
Privacy & Security → Open Anyway procedure
for the blocked executable. Native CI does not exercise these dialogs. The Codex
subscription subprocess bridge remains Linux-only.

No Windows archive is published. Windows execution is untested, and the managed
installer supports only Linux and macOS.

v0.4.1

Choose a tag to compare

@github-actions github-actions released this 02 Oct 11:54
e6a7169

Desk v0.4.1

This patch improves independent test-case authoring, explains evaluation findings, and bundles the exact published companion executables. Component versions remain Runtime v0.24.0, Runner v0.3.0 and Gateway v0.8.0.

Independent case authoring

The v0.3.0 claim that both chat modes ask for test cases without sight of draft rules did not hold when a pack chat or “Ask Assistant about this” appended rule context. Those routes now keep Desk context separate from the person’s message and supplied files; the case writer receives only the latter. The main assistant still receives the full context.

Older augmented turns are not used for case grounding because their authored material cannot reliably be separated from draft context; send the requirements again to ground new cases. Plain saved messages remain usable. Published release notes are unchanged; this note corrects the earlier claim.

Clearer results and labels

  • Evaluation traces explain type mismatches, unknown facts or evidence, and unmet evidence requirements reported by Runtime v0.24.0. These messages are translated into all twelve supported languages.
  • Rule citation references are distinguished from evidence gates. The independent-case count excludes saved Tests-tab rows.
  • Documentation clarifies that release snapshots remain fixed through Desk’s API, while a filesystem owner can still alter stored files.

Published companion executables

Desk release bundles now copy Runtime, Runner, the source worker, Gateway and the required adapters from their published platform archives. Packaging checks archive checksums and GitHub build attestations against the locked repository, workflow, tag and commit. Archive checks independently compare bundled files with those upstream bytes. A missing or invalid artifact stops the release.

New job releases made with this bundle identify the published Runtime executable. Existing job releases and records retain their original executable digest: keep the original binary for their replay, including records made with earlier Desk bundles, development builds or explicit Runtime overrides. Updating Desk does not migrate those records.

State epoch remains 1. See installation and updates and release verification.

Component Pin
Runtime v0.24.0
Runner and source worker v0.3.0
Gateway and required Desk adapters v0.8.0

Platforms

This release contains complete Linux/amd64, macOS Apple Silicon (arm64), and
macOS Intel (amd64) archives. All three archives were built and smoke-tested on
native GitHub-hosted runners before publication; neither macOS archive is merely
cross-compiled. Component versions come from the same release lock.

macOS executables are not Developer ID signed or notarized. Gatekeeper may block
downloaded executables; verify the release and checksums, then use Apple's
Privacy & Security → Open Anyway procedure
for the blocked executable. Native CI does not exercise these dialogs. The Codex
subscription subprocess bridge remains Linux-only.

No Windows archive is published. Windows execution is untested, and the managed
installer supports only Linux and macOS.

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 20:50
ab58de5

Desk v0.4.0

Jobs can now identify calculated values, show how their inputs were bound, and explain why a calculator returned no value. The bundle advances Runner and its source worker to v0.3.0; Runtime remains v0.24.0 and Gateway remains v0.8.0.

Calculated job inputs

  • The integration picker identifies a calculator by its name and pinned version. The mapping review shows its input-to-parameter bindings and each reference table's maximum age in localized words.
  • Run input lineage shows whether a value was calculated, an input was missing, or the calculator could not compute it. Each reported input names its parameter, its case or earlier-source origin, and the corresponding pointer. Reference tables show localized as-of dates and times.
  • A calculated source skipped because a dependency was unavailable has no invented calculation details. Ordinary source and lineage displays retain their existing behavior.
  • Choosing a calculator profile adds the required empty calculation binding. Replacing it with an ordinary source removes that binding; switching calculators resets it. Source details explain how to fill it in using Advanced mapping → Edit mapping.

What an owner must configure

A calculator must already be declared in an installation's trusted input profile. Desk does not install one or infer its input bindings. Bind each reported input to a source parameter and give each table a maximum age in the mapping JSON. Empty bindings reject answers that report inputs or tables.

Runner checks the signed answer against the pinned calculator, the supplied case parameters, and the mapping's limits. It does not establish that the calculator is deterministic, that its arithmetic is correct, or that its reported as-of times are true. No new binding editor is included.

Existing job releases retain their frozen mappings and Runtime. To use a new calculator mapping, preview it and create a new job release. State epoch remains 1; updating the executable bundle does not migrate stored data.

Other changes since v0.3.0

  • Component versions in Updates compares the running companions with the commits this Desk pins. Missing metadata remains Unknown; a different or modified build is not reported as a match.
  • Component release freshness reports newer unadopted releases without modifying the lock. The development launcher starts Desk with its locked companions.
  • Test case table wrapping and review dialog spacing are improved. The Triggers screen describes reading an occurrence's result.

Verification

Frontend behavior, all twelve locale catalogues, component integration, and native archive checks pass in CI. Twenty-four deliberate frontend mutations were caught by the new tests. A separate check used the real Runner v0.3.0 HTTP planner and preparation endpoints with Desk-generated mappings and signed synthetic responses, covering all calculation statuses, unbound inputs/tables, and case and earlier-source lineage.

The calculator check did not exercise a live Gateway acquisition, external calculator, or scheduled job evaluation. It makes no claim about an external calculator's correctness.

Component Pin
Runtime v0.24.0
Runner and source worker v0.3.0
Gateway and required Desk adapters v0.8.0

See installation and updates.

Platforms

This release contains complete Linux/amd64, macOS Apple Silicon (arm64), and
macOS Intel (amd64) archives. All three archives were built and smoke-tested on
native GitHub-hosted runners before publication; neither macOS archive is merely
cross-compiled. Component versions come from the same release lock.

macOS executables are not Developer ID signed or notarized. Gatekeeper may block
downloaded executables; verify the release and checksums, then use Apple's
Privacy & Security → Open Anyway procedure
for the blocked executable. Native CI does not exercise these dialogs. The Codex
subscription subprocess bridge remains Linux-only.

No Windows archive is published. Windows execution is untested, and the managed
installer supports only Linux and macOS.

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 12:00
a2cda0c

Desk v0.3.0

Desk now holds a chat draft to what it rests on before it becomes a pack, searches the whole of a Google Drive, runs natively on macOS, and moves to Runtime v0.24.0, Gateway v0.8.0 and Runner's first stable release.

What an owner must do

  • Reconnect Google Drive. A Drive connection made by an earlier Desk asked for drive.file. This release asks for the whole of the person's Drive, so the first request of an old connection is answered reconnect-required while its status still says connected. Connect again from Admin.
  • Update your Google Cloud project if you registered your own Drive client. Enable the Google Drive API only; the Google Picker API is no longer used. In the consent screen's Data access, add https://www.googleapis.com/auth/drive in place of drive.file. Google restricts this scope: an owner using their own registration, within their organization or as a named test user, needs no verification by Google; a registration offered to the public would. The setup guide in Admin says the same.
  • Nothing else is required. Saved chats, packs and jobs carry over. This release keeps state epoch 1, so rolling back changes which programs run and not your data.

Pack authoring

  • A chat draft is ready only when what it rests on holds. Every citation must trace to a document kept in the chat:
    • the page it names is one of that document's selected pages;
    • the document verifies under the gateway pin;
    • the quoted text is on that page;
    • for a web page, the address is the one in the signed record.
  • The citation rules per mode. A web-research draft needs at least one traced citation. A draft that cites nothing says so in words: "This pack cites no source. It rests on what you told the assistant." Reopened drafts re-check their citations before anything reads them.
  • Test cases written without the draft's rules. In both chat modes Desk asks for test cases written without sight of the draft's rules. Each rests on a traced citation's quote or on one of your own messages, never on the assistant's turns. A disagreement between the draft and those cases comes to you; Desk does not repair the draft on its own. A saved draft without cases offers a button to write them. The created pack carries its cases.
  • The creation dialog states, beside the button, how many citations are traced and how many cases agree.
  • New packs declare the version the evaluator admits, taken from the runtime itself. Examples are served in that version, and a draft declaring another is corrected before it is finalized.
  • The test case editor states the expected handoff target and keeps it through an edit (absent, null, or a kind and a name), and says when a change of expected result removes it.

Connections

  • Google Drive is searched and selected in Desk in place of Google's chooser. Search results are not model context until you select them. A grant now says that Desk asked to read a file; your choice is held in Desk's own interface.

Jobs

  • An installation can refuse jobs from untested releases. Started with --runner-require-tested-releases, Runner refuses to create a job from a release whose tests never ran. Desk keeps its warning and shows Runner's refusal in place of a created job, for both creation paths. Off by default.
  • A trigger's caller can read its own result. GET /api/job-events/{trigger}/occurrences/{occurrence} with the trigger's token answers that occurrence's state and, once its run completes, its disposition and handoff target, and nothing else. It refuses browser requests, any query or body, and any shape but the one route. Runner's 401 and 404 answers pass through unchanged, so nothing tells whether an occurrence exists. The Triggers screen does not describe the read yet.

Releases and repository

  • Native macOS archives for Apple Silicon and Intel, each built and run on a native runner before publication, beside Linux. The managed installer selects your platform and refuses another's archive.
  • Component pins are proposed by Renovate, and package and action updates by Dependabot. A security policy names the private route for vulnerability reports. The README describes the pages the routes actually serve.
Component Pin
Runtime v0.24.0
Runner and source worker v0.2.0
Gateway and required Desk adapters v0.8.0

See installation and updates.

Platforms

This release contains complete Linux/amd64, macOS Apple Silicon (arm64), and
macOS Intel (amd64) archives. All three archives were built and smoke-tested on
native GitHub-hosted runners before publication; neither macOS archive is merely
cross-compiled. Component versions come from the same release lock.

macOS executables are not Developer ID signed or notarized. Gatekeeper may block
downloaded executables; verify the release and checksums, then use Apple's
Privacy & Security → Open Anyway procedure
for the blocked executable. Native CI does not exercise these dialogs. The Codex
subscription subprocess bridge remains Linux-only.

No Windows archive is published. Windows execution is untested, and the managed
installer supports only Linux and macOS.

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 19:11
ce7e23f

Desk v0.2.0

Desk can discover web sources through configurable search connections, show decision paths more clearly, and prepare verified application updates for the next launch.

Research and source discovery

  • Configure named Tavily or Google Cloud Search grounding connections in Admin, independently of the assistant model. Gateway holds provider credentials.
  • Chat can choose available research tools when the request needs them. Research mode uses those tools directly and no longer requires the legacy source-led research configuration to enable Send.
  • Search receipts and retained result digests are verified before returned links can be read or explored. Search records stay with their response through reload and backup.
  • Provided-sources-only settings remain available. Search requires a configured provider account; configuration alone makes no paid search request. No live provider account was used in release testing.

Logic maps and local development

  • Configure decision colors and symbols without guessing their meaning from outcome names.
  • Highlight related nodes and edges across branching and converging paths. Auto-arrange restores a readable layout; dragging avoids unnecessary layout work.
  • VS Code tasks and a local lifecycle helper start, stop, restart, and report the development servers.

Releases and updates

  • Help & About shows update status and links to release downloads.
  • Managed installations can verify and prepare a complete bundle, cancel a prepared update, or opt into updates before the next launch. Automatic installation is off by default. Running work is not restarted automatically.
  • The updater retains the previous bundle for explicit rollback. Development checkouts and existing job release snapshots are preserved.
  • CI and packaging use one component lock. Daily component-update PR automation requires the repository's COMPONENT_UPDATE_TOKEN bot credential; it is separate from installation updates.
Component Pin
Runtime v0.23.1
Runner and source worker v0.1.0-rc.1 (preview)
Gateway and required Desk adapters v0.5.0

The downloadable Desk bundle is Linux/amd64. The managed launcher requires Python 3.8 or later. It verifies archive checksums and every file in the release manifest. This release preserves state epoch 1; rollback changes executable selection, not user data.

See installation and updates and web search configuration.