Skip to content

Releases: Ranopha/dungeonq-amazon

DungeonQ v0.11.1 — Follow the diversion

Choose a tag to compare

@Ranopha Ranopha released this 18 Sep 04:17

DungeonQ is a defensive deception runtime. This presentation release restores the product story: follow a designated session into a persistent synthetic world, use a world-only ticket, inspect its activity and bounded adaptation, then check the independent artificial origin.

  • New judge route and six recorded checkpoints; the original v0.11.0 reference evidence retains its source and date.
  • Updated English README, submission and OSS review materials. Original model studies, negative results and historical videos remain intact.
  • Corrected CI artifact retention for the detailed runtime report. No runtime implementation or production capability changed.
  • Local clean distribution: 460/460 tests, three deterministic scenarios, audit, typecheck, build and source-manifest verification passed. Exact-candidate remote CI passed on Ubuntu, macOS and the dedicated container/runtime job.

Follow the recorded diversion. The website reads saved observations; self-hosting runs the reference. Automatic attack classification, real production acceptance and general deception efficacy remain unassessed. Required branch protection is a separate gate.

Use the attached full source archive and SHA256SUMS.txt. The source archive includes its manifest, license/notices and SBOM, and excludes private Git history and installation data. Earlier WebMCP competition materials remain frozen.

The attached editable flow diagram illustrates the owned artificial reference; it is not a live attack screenshot.

DungeonQ 0.11.0 — Persistent Deception Runtime

Choose a tag to compare

@Ranopha Ranopha released this 18 Sep 03:30

DungeonQ now ships the persistent Deception Runtime alongside its retained assistant and research profiles. Five bounded real local adapters (HTTP, MCP, SSH, PostgreSQL profile and managed-workload broker), JavaScript/Python SDKs, scoped synthetic tickets, independent artificial-origin evidence and operator-approved finite mutation share one canonical state.

Install the source archive with Node24.15+ and npm ci --ignore-scripts, then npm run runtime. Read docs/RUNTIME.md and docs/RUNTIME_ACCEPTANCE.md before interpreting results.

Validation: 460/460 tests, three deterministic scenarios, source audit, typecheck, build and manifest verification passed locally. Exact-source CI passed Ubuntu24.04, macOS14 and the dedicated Linux container/runtime acceptance job. Source: 1ce468368b2e54699e59f734171bf5c43eb511dc. Runtime evidence is retained in that run's runtime-reference-evidence artifact.

This release measures an owned artificial reference. It does not claim production protection, arbitrary SSH/SQL support, general attack detection, broad deception efficacy or enforced branch protection. Historical model results and videos remain unchanged; the new runtime is not a new live Astra/ Alexa-service experiment. WebMCP's frozen submission is untouched.

The archive includes source inventory, SBOM, Apache-2.0 license and notices; no private Git history or installation credentials. Checksums establish integrity, not independent authorship attestation.

Documentation note: the immutable archive's Runtime contract contains an outdated sentence about inactive CI. Public CI was active and passed at this release commit. The corrected contract on main and validation history clarify this; source assets and tags are preserved unchanged.

v0.10.0 — Administrator-bound notifications

Choose a tag to compare

@Ranopha Ranopha released this 17 Sep 08:18

v0.10.0 — Administrator-bound notifications

  • Verified Owner email binding and login alias; a durable encrypted alert outbox with versioned recipients, bounded retries and no blind retry after an unknown outcome.
  • Optional Google / GitHub sign-in adapters link an existing Owner to a verified provider email. Registration and credentials remain deployment-owner configuration; Apple is unavailable in the local profile.
  • A private simulated mailbox works without a provider or paid call. Optional TLS-verified SMTP is separate from sign-in. Server acceptance is not inbox delivery.
  • Nine reproducible scripted HTTPS/restart checks: npm run email:proof. Both clean distributions passed 386 tests, three goldens, audit, typecheck, build and source verification locally.

Run npm run defense:workspace for the full local synthetic lab; read docs/EMAIL_NOTIFICATIONS.md. The static site is a recorded-evidence viewer, not a public mail, OAuth or defense server. There is no live-provider login or commercial inbox acceptance claim.

Orders Workspace, separate Owner approval, actual synthetic rotation/readbacks and all earlier positive/negative model records are retained. This is not a new model-efficacy result, a live attack or production security software. Original video provenance and the Astra API proof remain unchanged.

Archives contain clean Apache-2.0 source, tests, documentation, synthetic evidence, SBOM and a source manifest. No private history, installation state or credentials are included. SHA-256 checks establish file integrity, not an independent trust root.

v0.9.0 — Orders Workspace and bounded model evidence

Choose a tag to compare

@Ranopha Ranopha released this 17 Sep 05:32

Orders Workspace v0.9 adds persistent synthetic snapshot/index/reconciliation records, shared HTTP/MCP projection, an English Actor desk and the retained separate Owner alert/approval/rotation boundary. Old installations remain pinned and unchanged.

All 296 tests, three goldens, audit, typecheck and build passed in both local clean distributions. Raw records include both new Codex sessions and the prior 0/3 negative pilot. The new sessions accepted decoy values but explicitly qualified their scope: this is not proof of sustained origin misbelief, a new Astra API run or production defensive efficacy. See docs/WORKSPACE_LAB.md for exact results and limitations.

No private history or installation credentials are included. Original videos, live Astra evidence and WebMCP submissions remain unchanged. Source and checksum attachments are provided.

v0.8.0 — One incident. Two worlds.

Choose a tag to compare

@Ranopha Ranopha released this 17 Sep 04:08

v0.8.0 — One incident. Two worlds.

The defense reference now connects a bounded synthetic Dungeon and a separate protected-origin authorization service through the same durable incident. It does not rely on a success message alone.

What works

  • Seeded B/C/D topology, persistent local progress, bounded actions and a locally useful world artifact. The artifact is rejected by A's actual authorization endpoint.
  • One decoy-contact incident, a received durable local notification, and a fixed-scope rotation proposal. Contact is not proof of AI identity or an A compromise.
  • Separate Owner sign-in and fresh digest-bound approval; no Actor or MCP approval tool. Approval, claims, expiry, generations and replay protection are enforced outside model output.
  • Real loopback TLS rotation and four separate readbacks: old key denied, new key business request succeeds, old consumer denied, world artifact denied by A. The Dungeon remains available after rotation.
  • Unknown outcomes are reconciled by receipt lookup and readback, never by blindly repeating rotation. Restart preserves state.

Reproduce and inspect

Use Node.js 24.15.0 or later and OpenSSL. After extracting the source archive, run npm ci --ignore-scripts, npm run doctor, npm run check, and npm run defense:proof. For the interactive Actor, administrator and official MCP interfaces, follow docs/DEFENSE_LAB.md. A private lab directory must not be published.

Both clean public distributions passed 292 local tests, three golden scenarios, audit, typecheck, build and source-manifest verification. The bundled evidence/defense-v1/ contains a 13-check engineering record with linked world and governance evidence. Public Ubuntu/macOS CI is reported separately in Actions.

The source archive excludes private Git history, keys and installation databases. Its manifest binds files to the public source commit; SHA-256 checks establish integrity, not independent provenance.

Honest boundaries

The new record is a scripted synthetic engineering fixture, with zero model calls and zero external-target requests. Automated use of the Owner fixture does not prove human presence. The public website is a recorded evidence viewer, not a hosted live defense server. Same-host processes are not production infrastructure isolation; the notification is a local sink, not email. The reference supports one fixed protected asset and one transition per installation. Issued permits retain a bounded validity window.

Earlier Astra API evidence and all v1/v2 pilot records remain unchanged. The v2 pilot observed ordered route following in 2/2 treatment sessions versus 0/2 controls, but 0/4 unsupported completion claims. This release does not claim general LLM deception efficacy, transparent traffic interception, enterprise deployment, live attacks or Alexa-service integration.

v0.7.0 — Persistent synthetic world and complete pilot record

Choose a tag to compare

@Ranopha Ranopha released this 17 Sep 02:55

v0.7.0 — Persistent publishing world and complete pilot record

An original six-desk synthetic workflow with durable local successes, fixed-consumer delivery/read/decision/write lineage, bounded HTTP and official MCP, and a separate-process replaying Observer. The earlier governed assistant and v1 study remain available.

What the pilot actually showed

Four predeclared Codex sessions, all retained: both procedural-memo sessions followed the complete three-step local branch (2/2), while neither early-explanation control did (0/2). False completion claims: 0/4. Every participant eventually verified the actual catalogue goal. Continued route following is not evidence of a false causal belief; cognitive induction remains unverified. Exact model identities were not independently attested. Earlier v1 results are retained separately.

Reproduce

Use Node.js 24.15.0 or later. Install with npm ci --ignore-scripts, run npm run check, then npm run topology. Read docs/TOPOLOGY_LAB.md for Actor, Observer and bounded MCP access. npm run topology:proof runs the deterministic engineering proof. docs/TOPOLOGY_RESULTS.md links every original pilot record and offline replay commands.

Both clean public distributions passed 256 local tests, three golden scenarios, audit, typecheck, build, the 12-check topology proof and source-manifest verification. Public CI is separately visible in Actions.

The source archive contains no private Git history, installation credentials or local databases. Its RELEASE_MANIFEST.json binds files to the public source commit. A checksum establishes byte integrity, not independent provenance attestation.

Synthetic evaluation only. No live attacks, exploitable vulnerabilities, production effects or claimed Alexa-service integration. The recorded pilot viewer is not a hosted live lab or a new live Astra API run.

v0.6.0 — World and causal study lab

Choose a tag to compare

@Ranopha Ranopha released this 17 Sep 01:12

DungeonQ 0.6.0 — finite worlds and replayable causal studies

The governed assistant remains intact. This release adds persistent synthetic worlds, a consent-based predict → act → reflect study, separate-process Observer storage, bounded MCP parity and offline causal replay. No API key is required for the new experiences.

  • Read docs/STUDY_LAB.md, docs/WORLD_LAB.md and docs/STUDY_RESULTS.md in the source archive.
  • 214 tests, three goldens, audit, typecheck and build passed in each clean distribution; both public Ubuntu/macOS CI jobs passed.
  • World and study engineering proofs each passed 12 checks. The transparent learner matrix contains 48 condition units, not subjects.
  • Both planned Codex pilots are retained: 0/2 wrong-high-confidence induction. Exact pilot model identity was not independently attested. No general human/LLM efficacy claim is made.
  • Static pages and gallery captures show recorded evidence; the independent Observer requires self-hosting. Study UI is currently Traditional Chinese with English documentation.

The archive is built from this distribution's public commit, without private history, installations, databases or credentials. It contains a source manifest, SBOM and third-party notices. SHA-256 proves file integrity, not independent provenance. Apache-2.0; SYNTHETIC_ONLY; not production security software.

The Astra edition retains its separate earlier recorded live API proof. Publishing this source does not advance its Product Hunt launch: September 18, 2026 at 00:01 PDT / 15:01 Taiwan.

DungeonQ 0.4.0 — Bring your own proof

Choose a tag to compare

@Ranopha Ranopha released this 16 Sep 01:42

DungeonQ 0.4.0 — bring your own proof

This release makes the synthetic governance lab independently testable and maintainable: bring a Scenario Pack, connect a separate MCP client, inspect public CI, and rebuild a source distribution without a private repository.

What changed

  • demo:proof --scenario FILE: complete fresh-lab proof with input, decision and proposal digests. Correctly authored inputs can reach APPROVED_EFFECT_VERIFIED; modeled budget exhaustion reaches POLICY_BLOCKED; unsupported rotation reaches UNSUPPORTED_MAPPING_REJECTED. Rejection proofs do not fabricate receipts.
  • Separate-process SDK client: real MCP 2025-11-25 Streamable HTTP, worker token only, loopback/no-redirect guards, no approval command. Optional Codex configuration is documented; it is not a claimed live-model acceptance run.
  • Public CI: pinned actions, read-only permissions, Ubuntu 24.04 and macOS 14, no secrets, deployment or model calls.
  • release:prepare: clean public-checkout source, new SBOM and verified file inventory, no private Git history or lab state. Private and public development entry points are now explicitly distinguished.

Verified

  • 122 source tests and three deterministic engine goldens passed locally.
  • Both platforms passed the public acceptance run, including full checks, three shipped proofs and public-only release rebuilding.
  • Approved-effect proof: 7 checks including HTTPS/CSRF, pre-approval rejection, exact fixture-role approval/read-back, pinned signature/tamper, replay and full-stack restart.
  • Budget and unsupported-mapping proofs: 3 checks each, unchanged assets/observations/requests, no effect receipt.
  • Source inventory: 118 files; original receipt accepted and tampered receipt rejected. Source commit for the final package: 75d508c4253232ff5a45d8cdd94e4c75ad664198.

The final documentation/inventory commit has its own acceptance run. Consult its actual status; prior green checks are not a substitute for an unrelated revision.

Run

Follow the README with Node 24.15.0+ and OpenSSL. Start npm run amazon for the human UI, or run the browser-free proof. Use a new output directory and synthetic inputs only.

Source and proof archives plus SHA256SUMS are attached. The proof archive contains synthetic evidence and a public key, never the disposable lab. Verify the receipt using an independently trusted key: a bundled key alone proves no trusted origin. SHA-256 inventories/checksums are not author signatures or external attestations.

Honest boundaries

SYNTHETIC_ONLY, local-host profile. Real transport/authentication/database/signatures; artificial incidents and effects. The automated proof controls both fixture roles and does not prove human presence. Native Windows, live LLM/Alexa/Echo acceptance, production identity/isolation/recovery and remote hosting remain outside this release. SQLite v5 and the six-tool human-approval boundary are unchanged. The existing public video still depicts the unchanged 0.2.0 interactive workflow. Earlier WebMCP submission/deployment is untouched.

v0.3.0 — Reproducible Governance Proofs

Choose a tag to compare

@Ranopha Ranopha released this 15 Sep 04:37

DungeonQ v0.3.0 — Reproducible Governance Proofs

Let it investigate. Decide before it acts.

DungeonQ is an Apache-2.0, locally runnable reference lab for testing the boundary between an assistant's request and a human-authorized effect. This release makes that value easier to inspect, install and reproduce without requiring a cloud account, API key or real enterprise environment.

What changed

  • A reviewer-first README, complete installation/restart/troubleshooting guide, named scenarios and a five-minute human-approval walkthrough.
  • npm run doctor: checks the Node.js, crypto, SQLite, OpenSSL, MCP SDK and loopback-port prerequisites without changing your environment.
  • npm run demo:proof: creates a fresh disposable lab, runs seven end-to-end governance checks through real HTTPS and Streamable HTTP, exports inspectable evidence and removes its own private fixture. Existing output directories and existing labs cannot be supplied or overwritten.
  • npm run verify:source: checks the distribution's complete source inventory against its SHA-256 manifest.
  • Governance/control/test mapping, security-reporting guidance, contribution instructions, validation record, changelog and release policy.

The existing assistant UI, MCP tools, approval rules and SQLite schema are unchanged. The public 2:35 video records the preceding 0.2.0 interactive workflow, which remains applicable. The original public baseline is preserved at b3ec2e22cd53e7c16c7334c39ad9942d890b9c95; no historical release tag has been invented or moved.

Reproduce locally

Reference platform: macOS, Node.js 24.15.0+, npm and OpenSSL with req -addext. Other operating systems are not yet release-accepted.

git clone --branch v0.3.0 --depth 1 https://github.com/Ranopha/dungeonq-amazon.git
cd dungeonq-amazon
npm ci --ignore-scripts
npm run doctor
npm run demo:proof -- --out ../dungeonq-proof-030

Expect seven PASS checks and Result: PASS. To experience the separate human approval interface, run npm run amazon and follow the reviewer guide. Inspect the local self-signed certificate warning yourself; do not install system trust or disable certificate validation.

Validation recorded for this release

  • 115 tests passed, with zero failures.
  • Three fixed-seed golden scenarios passed: honey-credential replay, compound PEP failure and false-positive recovery.
  • Seven proof checks passed: authenticated HTTPS/real MCP; scenario analysis; unapproved effect and assistant-approval rejection; exact reauthenticated approval and readback; pinned-signature/tamper detection; idempotent replay; full-stack restart persistence.
  • Type checking, build and source-pattern audit passed. All 108 source files matched the distribution manifest.
  • A fresh dependency installation reported zero known vulnerabilities at validation time. This is not a guarantee against unknown vulnerabilities.
  • The actual interactive launcher served the assistant page over certificate-pinned HTTPS and shut down cleanly. No new browser visual or human-presence validation is claimed for this release; the UI is unchanged.
  • The build retains a documented Vinext route-classification warning. See the validation record for scope and limitations.

Downloads and trust boundaries

  • dungeonq-v0.3.0-source.tar.gz: exact source tree from commit 06c4c145ba26a7b5323967a17bda0c54e4815161, including manifest, SBOM and license notices; no private repository history, dependencies or lab credentials.
  • dungeonq-v0.3.0-proof.tar.gz: one actual run's report.json, evidence.json, deliberately altered tampered-evidence.json and a public verification key. Run the proof yourself for an independently generated result.
  • SHA256SUMS.txt: checksums for the two named archives. These establish file integrity relative to this release, not an independently signed author identity or trusted timestamp.

After downloading the three assets into one directory, use shasum -a 256 -c SHA256SUMS.txt. The source archive can be extracted and checked with npm run verify:source before installing dependencies.

The proof driver controls both automated fixture roles, so it does not prove human presence. The runtime assistant still has no approval tool. The runner pins the lab's public key before exporting evidence; a key included with third-party evidence does not independently establish a trusted origin. The receipt signature does not authenticate the whole export envelope.

Scope

SYNTHETIC_ONLY. Authentication, transport, signatures and local persistence are real; identities, incidents and effects are synthetic. DungeonQ is not the Alexa service, an Echo integration, an LLM agent or production security software. Execution is limited to one synthetic session-containment mapping. The 127 failure combinations are modeled capability checks, not 127 infrastructure attacks. No live targets, cloud deployment, real enterprise credentials or physical effects are involved.

This release supports review of the Amazon Alexa+ / Open Source Mini entry and the public open-source project. It does not claim contest acceptance, OpenAI endorsement, independent security certification or production readiness. The older WebMCP entry is separate and unchanged.