Skip to content

contract: integrated agent-native stack (per-app modification + accessibility + security seams + purple-team) - #262

Merged
mdheller merged 3 commits into
mainfrom
feat/integrated-agent-native-stack
Aug 3, 2026
Merged

contract: integrated agent-native stack (per-app modification + accessibility + security seams + purple-team)#262
mdheller merged 3 commits into
mainfrom
feat/integrated-agent-native-stack

Conversation

@mdheller

@mdheller mdheller commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

What

The contract that makes the whole SourceOS stack work like Apple's — one integrated system — but agent-native and owned. Ties the desktop, launcher, apps, accessibility, and security into one coherent spec.

  • Per-app feature-modification matrix — every app in the macOS-replacement set is a modified first-class citizen (wired to the owned shell + consent-plane + receipts + mesh + governed model plane), not a stock binary. Launcher + lampstand = Albert-class parity wired to sherlock-search / holmes / NewHope / slashtags; messaging = our own mesh/Matrix capability (no WhatsApp/Telegram/Element); browser/files/terminal/mail/media/assistant/search each carry their agent-native modifications.
  • Accessibility as a first-class default — AT-SPI/Orca/high-contrast/keyboard-only/WCAG 2.2 AA on by default, plus an opt-in agent-native assistive layer (the local agent + speech + Agent-S can describe and operate the UI, under consent + receipts).
  • Six named security seams — consent · space · surface · supply-chain · mesh · identity — where policy is enforced fail-closed + receipted.
  • Mandatory purple-team tests per seam (red probe + the blue detection it must trigger, proven to fire, fail-closed) as each seam's acceptance gate.

Depends on isolation-spaces-and-taits, consent-plane/001, the enhancement program (E1–E12), and the owned shell (sourceos-shell). Enforcement code stays in the owning repos; this is the governing contract.

…+ seams + purple-team)

Makes the whole SourceOS stack work like Apple's — ONE integrated system — but
agent-native and owned. Specifies:
- Per-app FEATURE-MODIFICATION matrix: launcher(+lampstand, Albert-parity wired to
  sherlock/holmes/NewHope/slashtags)/browser/files/terminal/mail/media/messaging
  (own capability, not WhatsApp/Telegram)/assistant/search — each integrated to the
  owned shell + consent-plane + receipts + mesh + governed model plane, not stock.
- ACCESSIBILITY as a FIRST-CLASS DEFAULT (AT-SPI/Orca/high-contrast/keyboard/WCAG
  2.2 AA on by default) + opt-in agent-native assistive layer (agent describes/
  operates the UI, under consent + receipts).
- The 6 named SECURITY SEAMS (consent/space/surface/supply-chain/mesh/identity) —
  where policy is enforced fail-closed + receipted.
- Mandatory PURPLE-TEAM TESTS per seam (red probe + blue detection, must fire,
  fail-closed) as the acceptance gate. Registered in the contract index.
… Apple Intelligence

Because the whole intelligence stack is native (Noetica reasoning + labs +
governed model plane + local agent cell), the Noetica voice concierge REPLACES
and EXTENDS Siri + Apple Intelligence rather than copying them: every Apple-
Intelligence feature (summarize/rewrite/generate/prioritize/transcribe/translate/
describe) is a native governed-model-plane capability (local-default, swappable,
auditable); reasoning-backed + agentic (governed multi-step action across the
integrated apps, consent-gated + receipted); one intelligence powering concierge +
launcher + accessibility. New native capabilities land in all surfaces at once.
…/action-ontology)

The stack's purposes/intents/actions/profiles/accessibility roles MUST be
ontologically grounded, not ad-hoc: bound to the KKO upper set (KBpedia RCs),
the Action Ontology (agent-plane/001 action+trace+receipt), the Semantic
Coordinate Algebra (procyber/semantic), and the intent grid (23x6). Mandates
proper OWL+SHACL ontologies authored in ontogenesis and PROJECTED into runtime
(closing E10's not-projected gap): OS-layer ontology (spaces/surfaces/seams),
accessibility-binding ontology, per-app intent+profile ontology, consent-purpose
ontology — SHACL-validated in CI, consumed fail-closed by the gate/receipt path
(a purpose/intent absent from the ontology is refused).
@mdheller
mdheller merged commit b52af1f into main Aug 3, 2026
7 checks passed
mdheller added a commit that referenced this pull request Aug 3, 2026
…s-zero census) (#266)

* spec(macos): app-by-app replacement & enhancement matrix (feature-gaps-zero census)

Closes the biggest spec gap: the contract (#262) says HOW to build agent-native
apps, but the app-by-app macOS→SourceOS census never existed. This is it — 24
stock-macOS apps/subsystems mapped to their SourceOS replacement, owning repo,
the SociOS superiority (why it's a superset not a clone), the E1-E12 IDs it draws
on, third-party deps vs stock macOS, and an honest status (spec/partial/built/gap/hw).

Plus a hardware-gap register: the four places Apple silicon wins (Neural Engine,
Secure Enclave, HW codecs, display pipeline) that spec cannot close on Asahi —
stated honestly so nothing is over-promised.

The census makes the feature-gaps-zero campaign tractable: every gap/partial row
is a work item; a row is 'built' only when agent-native + accessible-by-default +
its seam's purple-team test passes.

* spec(macos): complete the long tail (Contacts/Reminders/Maps/Weather/Passwords/ScreenTime/Disk/FaceTime/AirPlay/…) — ~37 surfaces total

* spec(E11): consent & receipts UX design (campaign gap #2) + clickable prototype; cross-link census

* spec(E3): personal mesh transport (Continuity/Handoff/AirDrop/AirPlay parity, campaign gap #3); fix census owner attribution

* docs(surfaces): canonical truthful surfaces + doctrine (diagram-is-a-witness)

Replaces garbled DALL-E renders with reproducible HTML/SVG: holography+ghostspace
framework poster (Tier 1), B11 life-mirror automaton + E11 consent/receipts (Tier 2).
Adds the surfaces doctrine (3 tiers; instruments must not lie).

* docs(surfaces): lampstand semantic launcher + turn-witness (Godel/consistency/conclusions); canonical sourceos.tokens.css from source

Validates surface style against the OS: tokens extracted from source-os/website +
GNOME workstation-v0 (Cantarell, color-scheme honored). Turn-witness proves
well-formed != admissible via real BigInt Godel numbering + teeth'd consistency checks.

* docs(surfaces): Tier-1 genesis braid + install + flywheel diagrams (first theme); set house theme in tokens

Completes Tier-1 architecture set in the chosen first-theme (B11 instrument) palette.
Correct equations. tokens.css now documents OS base + first-theme house layer.

* docs(surfaces): reflow holography/turn-witness/e11 onto the first theme (house style)

lampstand kept faithful-light to match the real SociOS Albert launcher screenshot.

---------

Co-authored-by: Michael Heller <mdheller314@icloud.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant