Repository navigation
The fourth release, and the one where nothing new is offered. No closed set opens, no artefact gains a
key, and no Run behaves differently once it has started. What moves is three checks that decline where
they used to pass, one Journal member that was specified and never written, and one marker reaching
the surface that ranges over the Journal.
go install github.com/TheLoomLabs/hyper/cmd/hyper@v0.0.4-alphaUpgrading from v0.0.3-alpha
Install the new binary, run hyper project, read the diff. project rewrites the version pin and the
release digest, both land in a file you review, and nothing else on the machine changes. Until you do,
every command Refuses version-pin-mismatch at exit 77 — the gate compares the pinned version
against the binary's for exact equality, and that is working as intended.
Read the three breaking changes below before you upgrade a repository that runs. All three are
static, and a Run re-runs check in full at its start (§6) — so an artefact that checked clean under
v0.0.3-alpha and now does not is a Refusal at exit 77 before Step 1 rather than a surprise
mid-Run. None of them changes what a Run does once it passes.
hyper project also rewrites AGENTS.md, and the orientation an agent reads gained two sentences.
They are under Added.
Breaking
- A request's
method:is a literal. Anhttp:block'smethod:admits no template hole. A hole
there ishole-illegalat the position rather than at the source — the name inside it is never read
— which putsmethod:beside an Auth scheme's parameters as the second of §12's two positions where
a hole is refused outright. It follows thatmethod:reaches no Operation input, so an input named
only in a hole there is nowmanifest-inconsistentlike any other input nothing reaches: a
Manifest that declared an input and spent it on the verb draws two rows where it used to draw none.
(#279, ADR-0155) - A
method:that is not an HTTP token is refused where it is written. It is one HTTPtoken—
RFC 9110's1*tchar— and a literal that is not one ismanifest-inconsistentat
<op>.http.method. The grammar is the line and the registry is not: a verb no registry names,
and a verb written in lower case, both still check clean. What fails is a value with a space, a
slash, a newline or an empty string in it — the shapes that would have gone out on the wire as
something other than a method. (#285, ADR-0156) - A Bound is a positive count. A
bound:below1is refused where it is written:
bound-not-positive, reported atsteps[N].boundon every Step whose Kind admits a Bound at all.
The zero and the negatives are one code.1is the strictest Bound there is, and what this buys is
that a Journal entry's absent Bound now means this Step declared none and nothing else — it
could previously have meant a declared zero. (#287,
ADR-0158)
error_code goes from fifty-three members to fifty-four, gaining bound-not-positive. The set is
closed and a consumer matches on it, so the count is stated here rather than left to be discovered.
Added
runssays which rows were rehearsals. Every row carriesdry_run, read off the Journal entry
the row is, written always — the barefalseincluded. That is §7's one exception to the absence
rule, and it is here because this is the one surface where the entry cannot be missing, so a boolean
is a fact rather than a silence. On the page it is aREHEARSALcolumn carryingyeswhere there is
something to say and nothing where there is not, which isshow's reading of the same marker and
records'. For a consumer:dry_runis a new required member of everyrunsrow, and §9's
enumeration of what a row carries stays at seven facts — the marker rides on the row as the contest
does.--outcomestill selects a rehearsal on the outcome it has.
(#289, ADR-0160)- The orientation says a
destroyis how a record is closed, and a404is not a reason to withhold
it. The sentence an agent read named the exception and stopped — an effectful Operation completes
on2xxand halts on everything else, adestroycompleting on404besides — which is true and
reads as a leniency. A sealed session read it exactly that way: it checked a ref, met the404, and
narrowed itsdestroyaway from that Asset, handing back a Store whose Head read alive for a
resource the world no longer held. AdestroyStep writes the Tombstone and nothing else does, so
there is no second route. The clause now states what the rule is for — retire against what the
record says you hold, not only against what the world still answers for — and that a check the
operator has already made is no reason to withhold the Step, the check and the call being two calls
with nothing holding the world still between them. Nothing about the product changed; this is text.
(#290, ADR-0161)
Fixed
- A Step records the Bound its Expansion was counted against. §7 says a Disposition carries one,
§7's worked Step file shows"bound": 5, §9 lists it among whatshow --expansioncarries,
internal/storedeclared the member — and no Run had ever written one, because the only place a
Step's selector is built used two of the type's three members.showrendered aBOUNDline it had
been handed a zero for, every time. The guardrail was never affected: the Expansion was counted
andbound-exceededRefused exactly as specified, andcheckread the authored list's length
offline. What was missing was the record — an entry read after the artefact had moved could not say
what that Run's Expansion had been held to. The fix reads the Bound with the same reading the
guardrail uses, two readings of onebound:being able to disagree about what a Step declared. On
the wire the member's schema moves fromminimum: 0tominimum: 1, which is the breaking change
above seen from the Journal's side. Abound:on a Step with noover:still records nothing:
§7 attaches what was counted to what it was counted over, and a guardrail with no Expansion beneath
it was counted against nothing. (#286)
Documentation
- The process by which the closed sets grow is no longer undecided. ADR-0004 closed the Capability
set at two and left the process by which the closed set grows without becoming an open one by
attrition unowned; §12 and §13 both advertised the hole. ADR-0157
owns it with an admission sentence — a Capability is an effecthyperperforms with a credential
it already has a position for — five criteria as its application, and four candidates assessed as
its first use.fileis recorded as kept on file rather than refused forever.
(#281) - A cluster is authorable today, and now the corpus says so.
docs/research/worked-example-immutable-cluster.md
provisions one end to end with no new Capability, no new artefact key and no code — provisioned
configured rather than configured after provisioning — and is frozen at the commit it was written
against. (#282,
#283) - §13 states what a machine's inside costs, and
CONTEXT.md'sAssetstops overclaiming: what an
Opaque Operation's effect reached is the command and nothing past it, so the accountability is for
the processhyperran and never for the service it started.
(#284) - The acceptance seal covers
/tmp. Two sealed runs of 2026-09-09 could reach a secondhyperat
the pinned version and ten kilobytes ofdocs/spec/under the scratchpad directory an attended
session is handed. Neither read any of it, and no transcript is in doubt; what was false was the
claim the harness made about itself./tmpis a tmpfs in the seal now, with nothing bound back, and
the assertion was widened with the cover.
(#292, ADR-0163) That is about how this project
measures itself and changes nothing you install. docs/adr/holds 163 records.
What is in the release
Four archives — x86_64-linux, aarch64-linux, x86_64-darwin, aarch64-darwin — each holding one
file, hyper, plus checksums.txt, which is sha256sum's own output over all four. There is no
Windows build.
Nobody signed or notarised the macOS archives. Run the binary from a shell and it runs; a copy
downloaded in a browser carries the quarantine attribute the browser set, and Finder will refuse to
open it and offer Move to Trash. That is the attribute, not a verdict on the bytes.
hyper is alpha. It has one built-in Provider, shell, it never updates itself, and the
specification in docs/spec/ is the
authority where the code disagrees with it.