Releases: OtohaCo/SwiftAgent
Release list
SwiftAgent 1.0.0-rc.5
SwiftAgent 1.0.0-rc.5 is an SDK pre-release. It is not stable 1.0, and it is not approval for any production Host or store cutover.
- Bounded pre-admission replanning. Opt-in and off by default (
.disabled).- With
.evidenceRejection(toolNames:), a single prepared call that the runtime's own Evidence check rejects before authorization, intent or admission sends one correlated error result to the model. - The correction happens inside the original Run and its remaining turn, tool-call and deadline budgets. No second Run starts, and nothing is reset.
- The denial is not a Receipt, Evidence, authorization or execution.
- With
- Tools defined at runtime. New
AgentTool.definitionandRuntimeAgentTool.- Registration, validation, capability bindings and mutation admission use the instance definition.
- A capability binding keeps the definition it read when it was created.
- Fixes.
- Route continuation state goes back only to the candidate that produced it.
- Undelivered steering is committed before a Run ends.
- Follow-up enqueue and withdrawal are refused once
close()begins. - The Session adopts a checkpoint committed as its Run ends.
- Rotation and maintenance are bounded: an uncertain
CURRENTpoisons the handle, a failing rotation applies backpressure withinmaxWorkBytes, and opening with a budget below the retained data fails withmaintenanceBudgetTooSmall. - The writer lock is opened close-on-exec. Before this, a
posix_spawnchild kept a closed store locked; this was reproduced on hosted macOS and Linux.
Upgrade notes.
- Journal formats.
- New stores are schema 3 by default. RC4 can still open, append to and maintain them.
- Only stores created with
supportsAdmissionRejections: trueare schema 4. RC4 refuses them at open. - RC5 opens RC4 schema-3 stores. A Run that opts in to replanning on schema 3 fails before any Provider request.
- Stores are never migrated, upgraded or downgraded, and a new store does not inherit an old store's operation-deduplication facts.
- New public enum cases (affect exhaustive switches):
AgentEvent.toolAdmissionRejectedAgentJournalEvent.toolAdmissionRejectedAgentSessionError.admissionRejectionJournalRequiredModelProviderFallbackPolicyError.invalidCandidateIdentityAgentJournalError.maintenanceBudgetTooSmallAgentFailure.modelBinding/.capability/.contextPipeline/.contextProjection
- Behavior changes.
- Route: continuation state the Route cannot attribute to a current candidate fails with
fallbackBlockedbefore any candidate is contacted. That includes state saved by RC4 through a Route, and state from candidates without declared IDs after a restart. UseModelProviderRoute.Candidate(id:provider:). - Steering: a failed steering commit is reported by the Run.
- Maintenance policy:
JournalMaintenancePolicyrejects a work budget below the largest segment rotation can seal, and a failed rotation appliesmaintenanceRequiredbackpressure.
- Route: continuation state the Route cannot attribute to a current candidate fails with
Exact artifact. Annotated tag object 2a3d3d1a4462616e6d4663eef3e75bde0ce1e4c4 resolves to main commit 24447b8298ccea84f9f8056374857c5c47d8f64c (tree f3fbd3297f5b776cbe0ad22681d89ebd2469d3bf), the merge of #48.
SDK verification. Each gate below ran once; none was rerun.
A fresh public clone, detached at that commit, passed:
bash Scripts/ci-macos.shandbash Scripts/ci-concurrency-seal.sh;- the strict
BoundedReplanningProbe(exit 0; T1 and T2 PASS); RuntimeToolPublicAPITests(3/3);- five runs of
WriterLockLifetimeTests,FollowUpProcessTestsand the rotation backpressure test. Both launch paths reportednot heldwith reopen status 0. - the RC4-reader matrix (
verify-pr27-compatibility.shagainst3f01599). RC4 reads, appends to and maintains RC5 default stores. It refuses schema 4 withunsupportedFormatand leaves the store untouched.
Hosted runs:
- Main push CI: macOS, Linux and Apple passed on attempt 1. Each job's checkout was verified as the exact commit and tree.
- Tag-triggered CI: macOS, Linux and Apple passed on attempt 1. All three jobs checked out
refs/tags/1.0.0-rc.5at the same commit and tree.
A no-credential, empty-cache SwiftPM consumer resolved, built and ran against the fixed revision and against exact: "1.0.0-rc.5". Package.resolved recorded the same commit. The consumer queued, reopened and queried a follow-up on a schema-3 store, created a schema-4 store, and confirmed that replanning defaults to .disabled.
Known issues. None is claimed as fixed.
- CI flakes:
- Brief
storeInUse: a reopen right afterclose()can briefly getstoreInUsewhile the same process is spawning a child (#47). The refusal is fail-closed. - Tracked design and performance items: #39–#44.
- Real-model evaluation: the real-model replanning evaluation was not run.
Live evidence, exactly as run. One local check was run on 2026-09-29: the ProviderQualification local provider against an LM Studio OpenAI-compatible endpoint that reported qwen/qwen3.8-27b, on main 5ddb19b.
- All 6 cases passed: text, tool, restart, structured, usage and cancel.
- The run made 10 requests.
This qualifies nothing beyond those cases. No paid live Provider request was made. RC5 does not claim a production Host dependency update, user-store migration or cutover, OS sandbox qualification, or power-loss testing.
Complete RC5 release note · Acceptance record · Versioning · Journal guide
SwiftAgent 1.0.0-rc.4
SwiftAgent 1.0.0-rc.4 is an SDK pre-release, not stable 1.0 or a production Host/store cutover.
- Segmented Journal: incremental local commits, indexed Session and operation recovery, atomic trusted Receipt/output/conversation settlement, one store writer and automatic bounded packing.
- Context Pipeline: sourced, deterministic, budgeted request projection with Host-provided derived summaries/excerpts that do not replace formal history or grant Evidence.
- Scoped Capability Binding: immutable Run tool/backend/resource snapshot, revocation of new execution admission, and separately owned physical drain.
- Durable Follow-up Queue: stable input identity, FIFO reception and atomic Run/formal-input admission with fresh Host bindings. Reopen remains paused and uncertain admitted work is not automatically replayed.
Breaking upgrade: the durable directory format is schema 3 while its transaction payload is BatchV2. Schema 1, the unreleased schema-2 candidate and the old framed format are rejected intact. There is no automatic migration or fallback to memory. A new empty store does not inherit an old task's mutation deduplication ledger. Stop old writers, inspect uncertain operations and adopt the new public Journal/Session/Context/Capability/Follow-up APIs deliberately. A slow queued-Run event observer may lose intermediate progress; trusted Receipt and replayable output remain in the Journal. Input and mutation identities are retained without a default TTL, so disk use can grow with real retained facts.
Exact artifact: annotated tag object ff7ab55033857a0b0fe7c03dc6fb41c558c141d8 resolves to main commit 3f01599ef3d0923659226025a7d34d4144ed1800 (tree 9aa6e6828e01aa4d7b1b6ac3689fa89ac6a26989).
SDK verification: a clean detached checkout of that main commit passed bash Scripts/ci-macos.sh and bash Scripts/ci-concurrency-seal.sh. Hosted main push CI passed macOS, Linux and Apple jobs on the exact commit; logs include Journal/queue/process recovery, Context, Capability, ModelBinding, mutation recovery, Provider mapping, ExternalClient and the public FollowUpQueueFixture. A separate no-credential, empty-cache SwiftPM consumer resolved, built and ran against both the fixed public revision and exact: 1.0.0-rc.4; Package.resolved records the same commit, and the client created/reopened a disposable schema-3 store. Tag-triggered CI also passed macOS, Linux and Apple after all three jobs actually checked out refs/tags/1.0.0-rc.4 at the same commit.
Fixture and SIGKILL evidence covers a disposable file and process termination; it is not a physical power-loss test or arbitrary external-system exactly-once guarantee. Paid live Provider calls, a real production Host, OS sandbox qualification and any user-store migration/cutover were not run and are not claimed by this SDK prerelease. Production adopters must verify their own Host resources and credentials.
SwiftAgent 1.0.0-rc.3
SwiftAgent 1.0.0-rc.3
Release type: prerelease candidate
Release scope: focused RC2 compatibility and execution-reporting hotfix
SwiftAgent 1.0.0-rc.3 fixes Anthropic model discovery for the current Models
API capability metadata shape. It is an additive bugfix prerelease and does not
change the AgentCore execution contract.
RC2 to RC3
- Decode Anthropic
effortcapability levels andthinking.typeswhen the API
returns object maps instead of string arrays. - Preserve the legacy string-array catalog fixtures used by RC2.
- Keep supported, unsupported, and unknown metadata distinct. An object-map
entry is accepted only when its nested value explicitly says
supported: true; missing, null, malformed, or incomplete metadata is not
promoted to support. - Preserve open Anthropic effort raw values when they use the existing
output_config.effortwire parameter. Unknown thinking modes remain
discoverable but require an adapter upgrade until the encoder understands
them. - Keep unknown catalog capability keys out of the current capability model
without invalidating the complete model page.
Execution reporting and Host integration
- Preserve an observed mutation Receipt when the later Provider response is
malformed or fails, while keeping the Runtime termination failed. - Validate the Journal-backed recovery example with a new Session/Journal and
new tool call ID. A settled replay returns the original operation result,
does not re-enter the executor, and does not change the file or write count. - Keep
executorEnteredunknown when the public event stream only proves a
tool result or settled replay;toolCompletedand Receipt observations are
not executor-entry evidence. - Bind example reports to the actual
AgentRun.sessionID, reject event bodies
before the expectedrunStartedidentity is bound, and diagnose mismatched
lifecycle sources. - Keep the AppleChatApp and HeadlessExecutionHost consumers in example/support
packages. They do not add a new root SDK product or change AgentCore's
execution, cancellation, Journal, Receipt, or authorization contracts.
Compatibility
- No new Provider, routing architecture, tools, Memory feature, Apple PCC
feature, or AgentCore execution behavior is included. - Existing Agent, Session, Run, Journal, Evidence, Receipt, mutation safety,
and continuation contracts remain unchanged. 1.0.0-rc.1and1.0.0-rc.2are immutable anchors. RC3 is a new annotated
tag based on the final verifiedmaincommit.
Verification boundary
The release is fixture-first for the Anthropic catalog contract. It does not
claim live model-generation qualification, and creating RC3 does not require a
live generation request or an Anthropic API key.
SwiftAgent 1.0.0-rc.2
SwiftAgent 1.0.0-rc.2
Release type: prerelease candidate
Release scope verified: 2026-09-21
SwiftAgent 1.0.0-rc.2 is a provider-neutral Swift Agent runtime release
candidate. It contains the RC2 reliability, provider, durability, usage,
catalog, decision, and example work accumulated after the immutable
1.0.0-rc.1 anchor.
Included scope
- Agent, Session, and Run lifecycle with logical completion and physical drain.
- Durable Journal recovery, mutation intent/Receipt settlement, Evidence
boundaries, cancellation, and absolute preflight deadlines. - OpenAI Responses, DeepSeek Responses, and Anthropic provider adapters with
typed streaming, tool calls, continuation validation, structured-output
handling where tested, usage, and fail-closed terminal validation. - Local/self-hosted OpenAI-compatible Responses support with canonical-history
replay and no dependency onprevious_response_id. - Optional AgentCatalog model discovery, immutable Run-level model bindings,
request-only context projection, and the Host-owned DynamicModelRouting
example. - AgentUsage response/Run/Session-window aggregation with explicit unknown and
partial accounting states. - AgentDecisions and the TypeSafe Jev adapter. Decisions remain advice and
cannot authorize or execute tools. - Apple on-device Foundation Models support at the recorded opt-in scope.
- Swift 6.4 package validation on macOS and Linux, Apple adapter fixtures,
iOS cross-build, ExternalClient, ProviderQualification fixtures, and the
concurrency seal.
Qualification boundaries
Provider qualification is scoped evidence, not a claim that every model,
endpoint, deployment, or platform has been tested. The RC2 record covers the
OpenAI official matrix, the DeepSeek official matrix, the configured Anthropic
gateway/service matrix, the typed Jev decision matrix, and the recorded Apple
on-device cases.
Apple Private Cloud Compute remains:
EXPERIMENTAL / NOT LIVE-QUALIFIED FOR RC2
The adapter, fixtures, and compile path exist. A signed Otoha Host proved that
PCC service access is available, but RC2 does not claim the complete
SwiftAgent Core flow of:
Agent -> Session -> Run -> Tool -> second PCC turn -> terminal
PCC durable restart is also not qualified. A normal SwiftPM test bundle does
not carry com.apple.developer.private-cloud-compute; availability depends on
Apple platform, account, region, entitlement, and service state. See the
Apple provider guide.
Tingting/Otoha product CI, media closed-loop assertions, AppleChatApp visual
live UI, and unexecuted iOS simulator/device live UI are downstream or
platform-specific evidence. They are not SwiftAgent RC2 release gates.
Compatibility and safety
The immutable 1.0.0-rc.1 tag remains the compatibility anchor. RC2 adds
public products and provider adapters without removing the recorded rc.1
identifiers. Mutation safety, Evidence, Receipt, Journal settlement, and
provider continuation boundaries remain enforced by Core; provider or
decision output cannot grant authorization.
Verification
The final release gate requires the exact candidate to pass the repository's
macOS, Linux, Apple provider, ExternalClient, example, and concurrency checks,
followed by runner-backed SwiftAgent hosted CI. Live credentials are not
required for the normal CI gate, and no live provider request is implied by a
green fixture or compile test.
RC2 is a prerelease candidate. It is not a stable 1.0.0 release.
SwiftAgent 1.0.0-rc.1
SwiftAgent 1.0.0-rc.1 Release Notes
Status: Published as GitHub Pre-release
1.0.0-rc.1.
Last verified: 2026-09-19
Highlights
- Provider-neutral
ModelProvidercontract and normalized model event stream. - Typed
AgentToolAPI with schema validation and controlled type erasure. - Multi-Run
AgentSessionconversation continuity. - Durable
AgentJournalcheckpoints and crash-safe recovery. - Evidence prerequisites, independent host authorization, and Receipt-backed
mutation settlement. - Stable mutation idempotency across Host retries, Sessions, restart, compaction,
and provider fallback. - Recoverable, model-visible failures for explicitly opted-in read-only tools.
- Provider routing and fallback without replaying mutation side effects.
- macOS, iOS, and Linux Core support plus an optional Apple Foundation Models adapter.
Frozen Contracts
wait()resolves at logical Run termination.waitForDrain()waits for provider/tool physical drain and Session identity release.- Crash recovery never automatically replays an uncertain mutation.
- Cross-Run mutation retry safety requires a stable non-nil
operationID, the
same tool, canonical semantic arguments, and a shared durableAgentJournal. - Conversation memory is not Evidence. Model output is not authorization.
- An executor return is not durable mutation completion until Receipt validation
and journal settlement succeed. - A recoverable read error is not a runtime or safety error; mutation,
authorization, Evidence, receipt, journal, timeout, and cancellation failures
remain fail-closed.
Known Limitations
- A first-class queued follow-up while another Run is active is not included.
Hosts can await the active Run and submit the next turn explicitly (SAI-045). - Settled and aborted mutation tombstones are retained indefinitely by default.
A future explicit retention policy may trade storage for deduplication horizon
without changing the current correctness-first default (SAI-046). - Immutable v1/v2 journal byte fixtures produced by the original historical
encoders are not checked in. Current migration regressions cover the accepted
legacy vocabulary; immutable provenance fixtures remain a P3 follow-up (SAI-050).
Verification Scope
The RC gate requires clean-clone macOS, Linux, Apple adapter, ExternalClient,
architecture, journal migration, mutation, concurrency, and hosted CI evidence.
The public release seal also requires a credential-isolated anonymous HTTPS
clone and a no-cache SwiftPM consumer build from the documented repository URL.
Live cloud and Apple model calls remain operator opt-ins and are not required
for ordinary CI.
Published as annotated tag and GitHub Pre-release 1.0.0-rc.1.