Repository navigation
Coven v0.4.7
Coven v0.4.7
Coven brings the Automations command surface to the published v1 contract,
locks automation authority to the owner, and lands the verifying half of
Runtime Authority while keeping unattended identity-bound execution disabled.
npm install -g @opencoven/cli@0.4.7
coven doctorAutomations
- Commands follow the spec. The
coven.automations.command.v1control action
accepts the spec command envelope. A tested command matrix marks each of the
19 v1 commands as implemented (14), compatibility-only (1), or refused with a
typedCAPABILITY_UNSUPPORTED(4). New commands:- versioned activate and pause;
definition.health.v1;run.get.v1;run.history.v1;occurrence.history.v1, with keyset paging;legacy.import.v1, which imports intodraft.
- Rich
coven.automations.v1definitions are persisted with their JCS
integrity. Every revision stays recoverable, and envelope create and revise
accept them. - Occurrence, run and attempt transitions are published atomically with the
state they describe, on a gapless event feed. - Mutations require owner-local IPC. Prompt- and log-bearing reads are
owner-only over loopback TCP, and the gate is exercised over the Windows
named pipe.
Upgrade and rollback
- Stores written by the v0.4.3 and v0.4.6 daemons upgrade with every status
kept and imports kept paused. History edited after it ran stays
unverifiable rather than being reattributed. - Rolling back to v0.4.6 is supported. If v0.4.6 revises a rich definition,
this release drops the stale rich body on its next start instead of serving
it as the new revision.
Runtime Authority (still disabled)
- Ed25519 verification of authority and runtime terminal evidence against
out-of-band trusted keys, checked against the published vectors' real
signatures. - Reconciliation can settle a launched run from complete, verified terminal
evidence and commit its receipt atomically. Production supplies no adapter
and no keys, so these runs are still held for recovery exactly as before.
Daemon, security and tooling
- JSON API responses support conditional GET (
ETag/304). - The store no longer fsyncs every commit or checkpoints on every request.
- Origins must match exactly.
- Store and memory archive permissions are hardened.
- Managed hooks no longer execute worktree scripts.
- External adapter manifests reject interpreter executables.
coven doctornames each install's origin and the copy npm will upgrade.- Ordinary-chat context intents are refused at one fail-closed daemon
boundary. - Enrolled devices gain a reversible suspended state.
- The
opencoven-coven-clientcrate is packaged. - The restricted runtime gains a macOS Seatbelt backend with guardian and
kernel conformance evidence. - The native audit inventory grows to 21 suites with portable
command-envelope vectors. - The release stress harness compiles each selection before timing it, so
its bound measures the test rather than a cold build.
Coven remains an early MVP. The Automations manifests remain proposed with
productionReady:false. A trusted Runtime Authority adapter still waits on
these open decisions:
- principal authentication;
- familiar binding issuance;
- Threads decision signing;
- terminal observation production (#857, OpenCoven/coven-runtimes#48).
Exact source: c93a8a936f9b7f1bd070a1cbb608d38d4e13c92a.
-----BEGIN SSH SIGNATURE-----
U1NIU0lHAAAAAQAAADMAAAALc3NoLWVkMjU1MTkAAAAguzqcpSw/45XOhNc1hxn3wh4+l3
iP5p67B5VL9yjNXwMAAAADZ2l0AAAAAAAAAAZzaGE1MTIAAABTAAAAC3NzaC1lZDI1NTE5
AAAAQMpcudVxOffsGhVmtaV5RzA2eQr9t21rPtsu0jhfWPGfdqAe/5spJox4bHR2hiYFWs
Qju01DK3wepfu2SYJ/Tgg=
-----END SSH SIGNATURE-----