Skip to content

Releases: OtohaCo/SwiftAgent

SwiftAgent 1.0.0-rc.5

SwiftAgent 1.0.0-rc.5 Pre-release
Pre-release

Choose a tag to compare

@baryon baryon released this 29 Sep 08:23
24447b8

SwiftAgent 1.0.0-rc.5 is an SDK pre-release. It is not stable 1.0, and it is not approval for any production Host or store cutover.

  • Bounded pre-admission replanning. Opt-in and off by default (.disabled).
    • With .evidenceRejection(toolNames:), a single prepared call that the runtime's own Evidence check rejects before authorization, intent or admission sends one correlated error result to the model.
    • The correction happens inside the original Run and its remaining turn, tool-call and deadline budgets. No second Run starts, and nothing is reset.
    • The denial is not a Receipt, Evidence, authorization or execution.
  • Tools defined at runtime. New AgentTool.definition and RuntimeAgentTool.
    • Registration, validation, capability bindings and mutation admission use the instance definition.
    • A capability binding keeps the definition it read when it was created.
  • Fixes.
    • Route continuation state goes back only to the candidate that produced it.
    • Undelivered steering is committed before a Run ends.
    • Follow-up enqueue and withdrawal are refused once close() begins.
    • The Session adopts a checkpoint committed as its Run ends.
    • Rotation and maintenance are bounded: an uncertain CURRENT poisons the handle, a failing rotation applies backpressure within maxWorkBytes, and opening with a budget below the retained data fails with maintenanceBudgetTooSmall.
    • The writer lock is opened close-on-exec. Before this, a posix_spawn child kept a closed store locked; this was reproduced on hosted macOS and Linux.

Upgrade notes.

  • Journal formats.
    • New stores are schema 3 by default. RC4 can still open, append to and maintain them.
    • Only stores created with supportsAdmissionRejections: true are schema 4. RC4 refuses them at open.
    • RC5 opens RC4 schema-3 stores. A Run that opts in to replanning on schema 3 fails before any Provider request.
    • Stores are never migrated, upgraded or downgraded, and a new store does not inherit an old store's operation-deduplication facts.
  • New public enum cases (affect exhaustive switches):
    • AgentEvent.toolAdmissionRejected
    • AgentJournalEvent.toolAdmissionRejected
    • AgentSessionError.admissionRejectionJournalRequired
    • ModelProviderFallbackPolicyError.invalidCandidateIdentity
    • AgentJournalError.maintenanceBudgetTooSmall
    • AgentFailure.modelBinding / .capability / .contextPipeline / .contextProjection
  • Behavior changes.
    • Route: continuation state the Route cannot attribute to a current candidate fails with fallbackBlocked before any candidate is contacted. That includes state saved by RC4 through a Route, and state from candidates without declared IDs after a restart. Use ModelProviderRoute.Candidate(id:provider:).
    • Steering: a failed steering commit is reported by the Run.
    • Maintenance policy: JournalMaintenancePolicy rejects a work budget below the largest segment rotation can seal, and a failed rotation applies maintenanceRequired backpressure.

Exact artifact. Annotated tag object 2a3d3d1a4462616e6d4663eef3e75bde0ce1e4c4 resolves to main commit 24447b8298ccea84f9f8056374857c5c47d8f64c (tree f3fbd3297f5b776cbe0ad22681d89ebd2469d3bf), the merge of #48.

SDK verification. Each gate below ran once; none was rerun.

A fresh public clone, detached at that commit, passed:

  • bash Scripts/ci-macos.sh and bash Scripts/ci-concurrency-seal.sh;
  • the strict BoundedReplanningProbe (exit 0; T1 and T2 PASS);
  • RuntimeToolPublicAPITests (3/3);
  • five runs of WriterLockLifetimeTests, FollowUpProcessTests and the rotation backpressure test. Both launch paths reported not held with reopen status 0.
  • the RC4-reader matrix (verify-pr27-compatibility.sh against 3f01599). RC4 reads, appends to and maintains RC5 default stores. It refuses schema 4 with unsupportedFormat and leaves the store untouched.

Hosted runs:

  • Main push CI: macOS, Linux and Apple passed on attempt 1. Each job's checkout was verified as the exact commit and tree.
  • Tag-triggered CI: macOS, Linux and Apple passed on attempt 1. All three jobs checked out refs/tags/1.0.0-rc.5 at the same commit and tree.

A no-credential, empty-cache SwiftPM consumer resolved, built and ran against the fixed revision and against exact: "1.0.0-rc.5". Package.resolved recorded the same commit. The consumer queued, reopened and queried a follow-up on a schema-3 store, created a schema-4 store, and confirmed that replanning defaults to .disabled.

Known issues. None is claimed as fixed.

  • CI flakes:
    • The hosted macOS job sometimes reaches its 30-minute limit. This is unattributed (#45).
    • One Linux segfault could not be reproduced (#46).
    • RC5 bounds the follow-up process test's waits and keeps CI logs and crash evidence as artifacts. A green rerun is not a fix.
  • Brief storeInUse: a reopen right after close() can briefly get storeInUse while the same process is spawning a child (#47). The refusal is fail-closed.
  • Tracked design and performance items: #39–#44.
  • Real-model evaluation: the real-model replanning evaluation was not run.

Live evidence, exactly as run. One local check was run on 2026-09-29: the ProviderQualification local provider against an LM Studio OpenAI-compatible endpoint that reported qwen/qwen3.8-27b, on main 5ddb19b.

  • All 6 cases passed: text, tool, restart, structured, usage and cancel.
  • The run made 10 requests.

This qualifies nothing beyond those cases. No paid live Provider request was made. RC5 does not claim a production Host dependency update, user-store migration or cutover, OS sandbox qualification, or power-loss testing.

Complete RC5 release note · Acceptance record · Versioning · Journal guide

SwiftAgent 1.0.0-rc.4

SwiftAgent 1.0.0-rc.4 Pre-release
Pre-release

Choose a tag to compare

@baryon baryon released this 27 Sep 17:44
3f01599

SwiftAgent 1.0.0-rc.4 is an SDK pre-release, not stable 1.0 or a production Host/store cutover.

  • Segmented Journal: incremental local commits, indexed Session and operation recovery, atomic trusted Receipt/output/conversation settlement, one store writer and automatic bounded packing.
  • Context Pipeline: sourced, deterministic, budgeted request projection with Host-provided derived summaries/excerpts that do not replace formal history or grant Evidence.
  • Scoped Capability Binding: immutable Run tool/backend/resource snapshot, revocation of new execution admission, and separately owned physical drain.
  • Durable Follow-up Queue: stable input identity, FIFO reception and atomic Run/formal-input admission with fresh Host bindings. Reopen remains paused and uncertain admitted work is not automatically replayed.

Breaking upgrade: the durable directory format is schema 3 while its transaction payload is BatchV2. Schema 1, the unreleased schema-2 candidate and the old framed format are rejected intact. There is no automatic migration or fallback to memory. A new empty store does not inherit an old task's mutation deduplication ledger. Stop old writers, inspect uncertain operations and adopt the new public Journal/Session/Context/Capability/Follow-up APIs deliberately. A slow queued-Run event observer may lose intermediate progress; trusted Receipt and replayable output remain in the Journal. Input and mutation identities are retained without a default TTL, so disk use can grow with real retained facts.

Exact artifact: annotated tag object ff7ab55033857a0b0fe7c03dc6fb41c558c141d8 resolves to main commit 3f01599ef3d0923659226025a7d34d4144ed1800 (tree 9aa6e6828e01aa4d7b1b6ac3689fa89ac6a26989).

SDK verification: a clean detached checkout of that main commit passed bash Scripts/ci-macos.sh and bash Scripts/ci-concurrency-seal.sh. Hosted main push CI passed macOS, Linux and Apple jobs on the exact commit; logs include Journal/queue/process recovery, Context, Capability, ModelBinding, mutation recovery, Provider mapping, ExternalClient and the public FollowUpQueueFixture. A separate no-credential, empty-cache SwiftPM consumer resolved, built and ran against both the fixed public revision and exact: 1.0.0-rc.4; Package.resolved records the same commit, and the client created/reopened a disposable schema-3 store. Tag-triggered CI also passed macOS, Linux and Apple after all three jobs actually checked out refs/tags/1.0.0-rc.4 at the same commit.

Fixture and SIGKILL evidence covers a disposable file and process termination; it is not a physical power-loss test or arbitrary external-system exactly-once guarantee. Paid live Provider calls, a real production Host, OS sandbox qualification and any user-store migration/cutover were not run and are not claimed by this SDK prerelease. Production adopters must verify their own Host resources and credentials.

Complete RC4 release note · Journal guide · Follow-up guide

SwiftAgent 1.0.0-rc.3

SwiftAgent 1.0.0-rc.3 Pre-release
Pre-release

Choose a tag to compare

@baryon baryon released this 21 Sep 13:49
d5383a2

SwiftAgent 1.0.0-rc.3

Release type: prerelease candidate

Release scope: focused RC2 compatibility and execution-reporting hotfix

SwiftAgent 1.0.0-rc.3 fixes Anthropic model discovery for the current Models
API capability metadata shape. It is an additive bugfix prerelease and does not
change the AgentCore execution contract.

RC2 to RC3

  • Decode Anthropic effort capability levels and thinking.types when the API
    returns object maps instead of string arrays.
  • Preserve the legacy string-array catalog fixtures used by RC2.
  • Keep supported, unsupported, and unknown metadata distinct. An object-map
    entry is accepted only when its nested value explicitly says
    supported: true; missing, null, malformed, or incomplete metadata is not
    promoted to support.
  • Preserve open Anthropic effort raw values when they use the existing
    output_config.effort wire parameter. Unknown thinking modes remain
    discoverable but require an adapter upgrade until the encoder understands
    them.
  • Keep unknown catalog capability keys out of the current capability model
    without invalidating the complete model page.

Execution reporting and Host integration

  • Preserve an observed mutation Receipt when the later Provider response is
    malformed or fails, while keeping the Runtime termination failed.
  • Validate the Journal-backed recovery example with a new Session/Journal and
    new tool call ID. A settled replay returns the original operation result,
    does not re-enter the executor, and does not change the file or write count.
  • Keep executorEntered unknown when the public event stream only proves a
    tool result or settled replay; toolCompleted and Receipt observations are
    not executor-entry evidence.
  • Bind example reports to the actual AgentRun.sessionID, reject event bodies
    before the expected runStarted identity is bound, and diagnose mismatched
    lifecycle sources.
  • Keep the AppleChatApp and HeadlessExecutionHost consumers in example/support
    packages. They do not add a new root SDK product or change AgentCore's
    execution, cancellation, Journal, Receipt, or authorization contracts.

Compatibility

  • No new Provider, routing architecture, tools, Memory feature, Apple PCC
    feature, or AgentCore execution behavior is included.
  • Existing Agent, Session, Run, Journal, Evidence, Receipt, mutation safety,
    and continuation contracts remain unchanged.
  • 1.0.0-rc.1 and 1.0.0-rc.2 are immutable anchors. RC3 is a new annotated
    tag based on the final verified main commit.

Verification boundary

The release is fixture-first for the Anthropic catalog contract. It does not
claim live model-generation qualification, and creating RC3 does not require a
live generation request or an Anthropic API key.

SwiftAgent 1.0.0-rc.2

SwiftAgent 1.0.0-rc.2 Pre-release
Pre-release

Choose a tag to compare

@baryon baryon released this 21 Sep 03:39
a1e77d2

SwiftAgent 1.0.0-rc.2

Release type: prerelease candidate

Release scope verified: 2026-09-21

SwiftAgent 1.0.0-rc.2 is a provider-neutral Swift Agent runtime release
candidate. It contains the RC2 reliability, provider, durability, usage,
catalog, decision, and example work accumulated after the immutable
1.0.0-rc.1 anchor.

Included scope

  • Agent, Session, and Run lifecycle with logical completion and physical drain.
  • Durable Journal recovery, mutation intent/Receipt settlement, Evidence
    boundaries, cancellation, and absolute preflight deadlines.
  • OpenAI Responses, DeepSeek Responses, and Anthropic provider adapters with
    typed streaming, tool calls, continuation validation, structured-output
    handling where tested, usage, and fail-closed terminal validation.
  • Local/self-hosted OpenAI-compatible Responses support with canonical-history
    replay and no dependency on previous_response_id.
  • Optional AgentCatalog model discovery, immutable Run-level model bindings,
    request-only context projection, and the Host-owned DynamicModelRouting
    example.
  • AgentUsage response/Run/Session-window aggregation with explicit unknown and
    partial accounting states.
  • AgentDecisions and the TypeSafe Jev adapter. Decisions remain advice and
    cannot authorize or execute tools.
  • Apple on-device Foundation Models support at the recorded opt-in scope.
  • Swift 6.4 package validation on macOS and Linux, Apple adapter fixtures,
    iOS cross-build, ExternalClient, ProviderQualification fixtures, and the
    concurrency seal.

Qualification boundaries

Provider qualification is scoped evidence, not a claim that every model,
endpoint, deployment, or platform has been tested. The RC2 record covers the
OpenAI official matrix, the DeepSeek official matrix, the configured Anthropic
gateway/service matrix, the typed Jev decision matrix, and the recorded Apple
on-device cases.

Apple Private Cloud Compute remains:

EXPERIMENTAL / NOT LIVE-QUALIFIED FOR RC2

The adapter, fixtures, and compile path exist. A signed Otoha Host proved that
PCC service access is available, but RC2 does not claim the complete
SwiftAgent Core flow of:

Agent -> Session -> Run -> Tool -> second PCC turn -> terminal

PCC durable restart is also not qualified. A normal SwiftPM test bundle does
not carry com.apple.developer.private-cloud-compute; availability depends on
Apple platform, account, region, entitlement, and service state. See the
Apple provider guide.

Tingting/Otoha product CI, media closed-loop assertions, AppleChatApp visual
live UI, and unexecuted iOS simulator/device live UI are downstream or
platform-specific evidence. They are not SwiftAgent RC2 release gates.

Compatibility and safety

The immutable 1.0.0-rc.1 tag remains the compatibility anchor. RC2 adds
public products and provider adapters without removing the recorded rc.1
identifiers. Mutation safety, Evidence, Receipt, Journal settlement, and
provider continuation boundaries remain enforced by Core; provider or
decision output cannot grant authorization.

Verification

The final release gate requires the exact candidate to pass the repository's
macOS, Linux, Apple provider, ExternalClient, example, and concurrency checks,
followed by runner-backed SwiftAgent hosted CI. Live credentials are not
required for the normal CI gate, and no live provider request is implied by a
green fixture or compile test.

RC2 is a prerelease candidate. It is not a stable 1.0.0 release.

SwiftAgent 1.0.0-rc.1

SwiftAgent 1.0.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 19 Sep 01:38
d2347f1

SwiftAgent 1.0.0-rc.1 Release Notes

Status: Published as GitHub Pre-release 1.0.0-rc.1.
Last verified: 2026-09-19

Highlights

  • Provider-neutral ModelProvider contract and normalized model event stream.
  • Typed AgentTool API with schema validation and controlled type erasure.
  • Multi-Run AgentSession conversation continuity.
  • Durable AgentJournal checkpoints and crash-safe recovery.
  • Evidence prerequisites, independent host authorization, and Receipt-backed
    mutation settlement.
  • Stable mutation idempotency across Host retries, Sessions, restart, compaction,
    and provider fallback.
  • Recoverable, model-visible failures for explicitly opted-in read-only tools.
  • Provider routing and fallback without replaying mutation side effects.
  • macOS, iOS, and Linux Core support plus an optional Apple Foundation Models adapter.

Frozen Contracts

  • wait() resolves at logical Run termination.
  • waitForDrain() waits for provider/tool physical drain and Session identity release.
  • Crash recovery never automatically replays an uncertain mutation.
  • Cross-Run mutation retry safety requires a stable non-nil operationID, the
    same tool, canonical semantic arguments, and a shared durable AgentJournal.
  • Conversation memory is not Evidence. Model output is not authorization.
  • An executor return is not durable mutation completion until Receipt validation
    and journal settlement succeed.
  • A recoverable read error is not a runtime or safety error; mutation,
    authorization, Evidence, receipt, journal, timeout, and cancellation failures
    remain fail-closed.

Known Limitations

  • A first-class queued follow-up while another Run is active is not included.
    Hosts can await the active Run and submit the next turn explicitly (SAI-045).
  • Settled and aborted mutation tombstones are retained indefinitely by default.
    A future explicit retention policy may trade storage for deduplication horizon
    without changing the current correctness-first default (SAI-046).
  • Immutable v1/v2 journal byte fixtures produced by the original historical
    encoders are not checked in. Current migration regressions cover the accepted
    legacy vocabulary; immutable provenance fixtures remain a P3 follow-up (SAI-050).

Verification Scope

The RC gate requires clean-clone macOS, Linux, Apple adapter, ExternalClient,
architecture, journal migration, mutation, concurrency, and hosted CI evidence.
The public release seal also requires a credential-isolated anonymous HTTPS
clone and a no-cache SwiftPM consumer build from the documented repository URL.
Live cloud and Apple model calls remain operator opt-ins and are not required
for ordinary CI.

Published as annotated tag and GitHub Pre-release 1.0.0-rc.1.