Skip to content

Releases: WSattazahn/caveat-lang

CAVEAT Language 0.1.0-rc.17

Pre-release

Choose a tag to compare

@github-actions github-actions released this 11 Oct 05:25
304a16d

CAVEAT Language 0.1.0-rc.17 — View 0.2, source digests in saves, and the integration starter

npm publication verified on 2026-10-11 UTC. The owner approved the merge and publication. The exact CI-tested main package was published through trusted publishing with provenance; registry bytes, signatures and a fresh installation passed verification. The scope is track A of Path to 1.0 (A1 to A5), with the starter (B1) and the pilot package (B2).

View 0.2 and its delta

A host can ask for View 0.2 beside View 0.1, which is unchanged byte for byte (PR #190, PR #192). It changes three things:

  • session.view({ schema: '0.2' }) lists each decision's grounds evidence in the order it was first observed. That order is fixed when the decision is made. Caveats stay sorted.
  • A commitment says reopened where View 0.1 says open, with the same meaning.
  • session.dispatchViewDelta(event, payload) runs the same transaction as dispatch and returns only what the event changed. Applied to the 0.2 view the host holds, the delta gives the next one. A refusal is dispatch's, with no delta.

Saves gain an additive evidence_order field, written only where the order differs from name order. It keeps the order after a journal window retires the entry that gave it. A save without the field takes the order from its retained journal entry, and otherwise name order.

The delta gate runs in CI over every tracked program. It drives each one with seeded events, applies each delta to the held view and compares the result with the full view. The applier is written from the specification, not from the runtime's builder. On the merged revision, the gate checked 147 programs and 77,302 accepted events with no mismatch. It also detected all 123,212 deliberately corrupted deltas. Thirty tracked programs are skipped, each named: they do not load as reactive programs or declare no events. See View 0.2.

Saves record their source's SHA-256

A save now carries source_sha256, the SHA-256 of the exact source text (PR #189). explain prints made under source sha256:… under its decisions. Its JSON, and each dependents decision change, carry the digest. A save made before this restores as before, and its decisions show their source as not recorded; later events record it. Restore under other source is refused as before, and a save whose digest is not its source's is now refused too. The digest identifies the source; it does not authenticate a save or its history. See Save 0.1, "Source digest".

A save made by rc.17 does not restore in rc.16 or earlier, which refuse fields they do not know. Saves from earlier releases restore in rc.17. The save schema stays caveat-reactive-save/0.1.

The integration starter

caveat-lang/starter, with a Node store in caveat-lang/starter/node, is a host for Node and browsers. It keeps a checkpoint and the departure archive, and resumes after a restart (PR #183). The packed examples/readiness example runs a release approval through it, including a restart, a refused event, a failed storage write and the archive. The engineering readiness pilot package is in docs/pilot (PR #188). See the starter guide.

Specifications and the compatibility promise

  • Withdrawal Collection 0.1 specifies rc.16's collector, which shipped as an accepted experiment (PR #185). Runtime behavior is unchanged.
  • docs/COMPATIBILITY.md states what 1.0 keeps stable through 1.x and what it does not (PR #187). Prereleases, this one included, may still change anything until 1.0.0.

Documentation and the site

  • The front door leads with "a decision ledger for agents" and shows what is checked (PR #182). A related-work note and a discovery-study design were added (PR #186).
  • The rc.16 distribution closeout is recorded (PR #191).
  • The game draws Mr. Caveat from his character sheet (PR #184). It deploys with the site, not with npm.

Completed publication gates

The tagged main revision passed all 18 checks of PR #194 and Runtime run 38095375998 on main. That run's kit-package-candidate artifact is the tested tarball above.

The owner pushed the annotated tag at 02:33 UTC and approved npm-publish at 02:34 UTC in publish-npm run 38105537131. The candidate check and the publish passed on attempt 1; npm lists the version at 2026-10-11T02:35:20.971Z. The first verification job failed because npm install caveat-lang@0.1.0-rc.17 returned ETARGET about 12 seconds after publication, before the registry served the new version. Re-running only that job passed at 02:41:12 UTC: registry SHA-256/SHA-512 integrity, provenance identity, npm signature and attestation verification, and ten successful fresh-cache installation and CLI commands. A separate registry download on 2026-10-11 matched the tested tarball's bytes, SHA-256 and SHA-512, and the SHA-512 equals the provenance statement's subject. The publication record holds the artifact and receipt hashes. GitHub prerelease creation uses these same public package bytes through the separate workflow described in the release procedure.

Distribution closeout

Recorded on 2026-10-11 under the distribution closeout procedure. These steps move channels and listings. They do not move the tag or change the published package bytes.

npm next. The owner ran npm dist-tag add caveat-lang@0.1.0-rc.17 next at about 04:29 UTC. npm then listed latest and next as 0.1.0-rc.17.

MCP Registry. The owner published server.json from the v0.1.0-rc.17 tag with mcp-publisher (validate, login github, publish). The registry lists io.github.WSattazahn/caveat-lang 0.1.0-rc.17 as active and latest, published at 2026-10-11T04:30:21Z. It installs caveat-lang@0.1.0-rc.17 from npm with npx and the mcp argument over stdio. The rc.14, rc.15 and rc.16 entries remain active and are no longer latest.

Check. node scripts/check-distribution.mjs --version 0.1.0-rc.17 passed every row at 2026-10-11T04:31:46Z, with no lag recorded. Its complete output, including the raw npm and registry responses, is v0.1.0-rc.17-distribution.json.

Install path. Started the way the registry launches it, npx -y caveat-lang@0.1.0-rc.17 mcp answered initialize as caveat-lang 0.1.0-rc.17 and tools/list with caveat_validate, caveat_check, caveat_test, caveat_explain and caveat_dependents, at 2026-10-11T04:32:03Z on Linux. This shows that the listed package starts and offers those tools. It does not test the tools' results.

Socket. On the owner's screenshots of Socket's versions and alerts pages, taken 2026-10-11 at about 04:32 UTC, rc.17 (next, latest) scores Supply Chain Security 83, Vulnerability 100, Quality 100, Maintenance 94 and License 100, the same as rc.16. The page shows rc.17 published by GitHub Actions through OIDC. Compared with rc.16, the versions page reports 11 files added, 47 modified, 603 lines added and 273 removed, 4 metrics improved, and one new alert, "Filesystem access". Its one decreased metric is supplyChainRiskIssueLow, from 20 to 24. The screenshots do not name the file behind the alert. It is most likely the starter's new Node store, kit/lib/starter-node.mjs, which imports node:fs to keep the checkpoint and archive; that attribution is inferred, not shown by Socket. The package's alerts page for 0.1.0-rc.17 showed "No alerts" under Package Alerts, and 0 dependencies. Socket's scores are recorded as a signal, not a release gate.

These checks do not authenticate supplied evidence or saved history.

CAVEAT Language 0.1.0-rc.16

Pre-release

Choose a tag to compare

@github-actions github-actions released this 09 Oct 01:12
3cc7b0f

CAVEAT 0.1.0-rc.16 — history departure and archive-backed explanations

npm publication verified on 2026-10-08 Pacific (2026-10-09 UTC).
The owner approved the narrowed release scope and publication. The exact
CI-tested main package was published through trusted publishing with provenance;
registry bytes, signatures and a fresh installation passed verification.

At verification, latest named rc.16 and next still named rc.15. Install the
exact version to avoid depending on a moving channel:

npm install caveat-lang@0.1.0-rc.16
npx caveat-lang doctor
npx caveat-lang demo agent

Version and review lineage

The machine-readable lineage separates the published
rc.15 source, merged specifications, preserved review heads and later local
work. The review branches are cumulative: integration preserves original
commits and evidence, without squash or rewritten source identities.

Stage Exact revision Role in the preserved lineage
Published rc.15 source 3a88ba0f80d563b4493840dc7bd7e195329b8302 Published predecessor; see its separate verification record
Main specification baseline 9a2d1dd391b29385ee34ce24242d3b15a44856f4 Merged specifications
Departure / PR #174 f5ec8294efe2be24705f234ef75e5f5459aa5e89 Preserved baseline
Repaired collector / PR #175 3d77aa27bcffa16f39818b2684e9afb3b102ed17 Accepted experimental baseline
Index compaction / PR #176 c1d8fea1164e9d89edc8ff33af5a3bb608bc37d3 Reviewed representation improvement
Withdrawal batch extraction / PR #177 055e2af0b411d8385941dd8522201e5afc73cb34 Reviewed representation improvement
Renewal profiling / scanner portability 677ad1365398fe37bb24ff8fb6cfbae82d3ef5b5 Profiling and diagnostic work
Event-phase profiling 11c2a6a741609d3b640f27224ab6c9943b07f72c Profiling; early-boxing comparison baseline
Early archive boxing 590fae59aa4295ac5209f930a1e58ac152bd4603 Measured candidate before release closeout
rc.16 integration / PR #178 3cc7b0f66a5b7dafe3d5a166bd20953fa74ce5f4 Merged, annotated and published; all earlier stage commits remain ancestors

High-degree confirmation and adversarial receipts identify the unchanged
590fae5 runtime. Documentation/regression integration has its own source
revision and gates; it does not inherit a claim that the original experiments
measured later code. The published revision and package hashes above are fixed. Later publication
records and site documentation do not move that tag or rebuild the package.
GitHub automatically marked #174 merged through the integration. At the
owner's request, the superseded #175–#177 review pages were then closed with
integration comments; their branches, original commits, evidence and review
history remain preserved. Their code is included. The separate mobile layout
fix in #179 remains open and is outside this release.

Approved scope

rc.16 carries the reviewed history-management and collector work through
590fae59aa4295ac5209f930a1e58ac152bd4603, plus its release documentation and
retained regressions:

  • Departure and lineage compaction for the implemented renewable-evidence,
    reading-stream and journal windows. Exact own grounds remain live retention
    requirements; compactable inherited provenance uses departure markers.
  • Host-drained archive records and provenance nodes for exact departed
    membership reconstruction when the matching archive is complete, including
    copying, merging, overlap and replacement.
  • Reachability-based collection of otherwise-departable withdrawal groups that
    have no required external dependency. Required reasons and conservative
    transfer protections remain.
  • Archive-aware explanation and dependent reports, session drain/count APIs,
    serve operations, and transactional restore/rollback checks.
  • Compact derived collector indexes, batched withdrawal extraction and early
    archive boxing. These target representation, copying and allocation costs;
    they do not shorten required reason chains.

The original development plan remains the historical
record. Its View 0.2 inclusion is explicitly superseded for this release:
View 0.2, series windows and remaining unimplemented feature work are deferred
to the next cycle
. The adapter scaffold and broader dispatch work remain
future direction. There is no new delta-view API in this release. No further
optional optimization is part of this closeout.

Compatibility and evidence contracts

The history integration guide, departure
specification
and accepted experimental
collector contract
describe the API
and its limits.

  1. Current snapshots are current retained state. An eligible departed
    record may disappear from later snapshots. Historical payloads and withdrawal
    relationships belong in the host archive. Current decisions, necessary
    reasons, qualifications and permissions remain obligations of the runtime;
    snapshot inventory equality with rc.15 is not the compatibility criterion
    for programs that use windows.
  2. Exact membership needs the matching proof. Markers alone are
    conservative ranges, not exact lists. Missing or conflicting required
    archive data must remain visibly unavailable. Copies and merges require the
    accumulated provenance nodes as well as the departed record entries.
  3. Historical completeness has a stated scope. Machine-readable reports
    say scope: "provided records and their referenced closure" and
    authenticated: false. A complete result establishes consistency of that
    supplied referenced closure. It does not establish an exhaustive session,
    all incoming relationships, authenticated payloads or guaranteed
    distinction between same-source branches.
  4. Capacity can become available after collection. A later event may
    succeed because an earlier accepted event freed records. The existing
    65,536 held-record threshold, admission timing and other refusal conditions
    remain; collection cannot rescue an event already refused by admission.
  5. Save and archive are separate. Keep saves with the exact program source
    and store drained archive chunks separately. Restore starts with an empty
    pending archive and does not collect on load. Valid rc.15 saves are covered
    by migration/continuation regressions; the next accepted event can collect
    eligible history, while rejection must leave the save and pending archive
    intact. This is not a promise that rc.15 can consume rc.16 saves.
  6. No-window behavior remains a release gate. The measured compatibility
    corpus and its explicit skips are reported separately; finite tests do not
    establish equivalence for arbitrary programs.

Performance decision and workload limits

Recommendation: retain early boxing in rc.16 with the measured
successful-release tradeoff.
The completed high-degree confirmation is the
requested closeout, not an outstanding experiment:
report.
Eight alternating-order pairs at degree 16 and 1,000 cycles measured a median
paired successful-release increase of 6.67115% / 15.45 microseconds.
Six of eight pairs exceeded the separately fixed 5% review trigger. Growth
(+0.82%) and rejected release (+2.76%) did not cross it. Order effects limit
causal attribution; they do not erase the successful-release finding.

This accepts a scoped prerelease improvement, not a claim of meeting a
workload's <=5% successful-release degradation budget. No such claim is made.
The high-degree requested-heap peaks fell from 269,972 to 242,900 bytes for
growth, 114,024 to 103,456 for successful release, and 114,237 to 98,596 for
rejection in every pair. The finite save/archive/rollback projections matched.

The bulk early-boxing experiment
measured an approximately 20.485% lower additional requested heap at
3,000 mutual cycles: successful release 27,403,251 -> 21,789,689 bytes and
rejection 27,403,464 -> 21,789,902 bytes. Successful candidate releases ranged
54.98–59.90 ms. This fixture does not fit a 16.7 ms synchronous frame
budget. A host must select and test its own resource budget; neither
"experimental" nor "human-paced" supplies one.

Window sizes do not bound the complete save. Required reason chains,
conservative retention and retained allocation capacity can grow. The
3,000-cycle required-chain control retained 7,811,422 requested heap bytes,
saved 1,238,709 bytes and reached an 8,574,441-byte additional growth peak.
The registered C3 gate's 2,646-byte adapter saves at both 30 and 60 cycles
remain a fixture-specific result, not a universal bound.

Keep live retained memory, additional dispatch peaks, save bytes a...

Read more

CAVEAT Language 0.1.0-rc.15

Pre-release

Choose a tag to compare

@github-actions github-actions released this 05 Oct 15:47
3a88ba0

CAVEAT Language 0.1.0-rc.15 — integer clocks, history windows and a checked caveat test

Published and verified on npm, with provenance. The v0.1.0-rc.15 tag identifies source 3a88ba0f80d563b4493840dc7bd7e195329b8302 (PR #166). Registry verification finished at 2026-10-05T15:13:00.656Z.

rc.15 is the fourth version published through publish-npm.yml: the workflow published the exact tarball that Runtime tested for the tagged revision, authenticated by npm trusted publishing, with an npm provenance attestation. The scope is described in the rc.15 development record.

Integer clocks

A program can declare its clock integer: clock step every 16 integer; counts dt and elapsed() in whole units, such as milliseconds, so time no longer drifts as binary64 seconds do (PR #157, PR #158). The step and the dt bounds must be whole numbers, and a tick clock cannot be integer. The input bounds are checked first: a dt outside them is input/bound_exceeded, and a fractional dt inside them is input/payload_invalid. A reading that would leave ±(2^53 − 1) is evaluation/bound_exceeded. A computed delay outside whole 0..2^53 − 1 is evaluation/expression, and a literal after outside that range fails at load. Restore refuses fractional or out-of-range clock times. The clock metadata adds "integer": true only when declared. No refusal code is added.

A program without integer is unchanged. A seeded sweep over the 103 repository programs that load as reactive programs hashed 123,600 saves, and the digests were identical before and after the change. Round 7's four Glowcap programs, converted to milliseconds, each fade a taste on the exact step at which 60,000 ms have passed. See Elapsed 0.1.

History windows and retirement

A reading stream, a renewable evidence or the decision journal can declare a window: readings STREAM from TEMPLATE window N;, renewable EVIDENCE window N; or journal window N; (PR #160, PR #163). When the window is full, the history's oldest live record retires inside the event's transaction. The retirement is reported as a retire effect before the effect that adds the new record. A retired record is no longer observed, and history reads and folds see live records only. The snapshot and the save gain retired, and the snapshot gains windows. Restore checks that each windowed history keeps exactly its newest records live and that no later reopening names a retired record. explain and dependents show retired records, and validate prints the window.

Retirement keeps records in the session; it does not yet remove them from the save. Departure, which would, moves to rc.16. Measured on round 7's C3 program over 60 cycles, a save with windows still grows linearly, because a state's lineage holds every occurrence it has read. Decision series have no window in this release, for the same reason. rc.16's first specification is the revision-lineage rule that both wait on. The measurement is in the development record.

A program without window is unchanged. The save schema stays caveat-reactive-save/0.1, and old saves restore unchanged. A seeded sweep over the 113 repository programs that load as reactive programs hashed 135,600 saves, and the digests were identical before and after the change. See Windows 0.1.

caveat test checks first, and C006

caveat test now runs check on every program before its first scenario (PR #161). It prints any warnings with the run and stops with exit code 2 on an error-severity diagnostic. The JSON report and the MCP caveat_test result carry each file's check.

A new advisory, C006 citation-unreachable, reports a bind whose because names something its value and its when condition never read. Such a binding is refused at dispatch as evaluation/ungrounded_citation whenever it supplies the shown value, which can be long after the program loads. Round 7's C2 and C3 first runs each report it at the binding that was refused as evaluation/ungrounded_citation, and their passing versions do not. No repository program reports it.

Proofs

Lean now models reopening (PR #165). Its 17 new laws cover these behaviours:

  • A reopening keeps every caveat the commitment retained, and the earlier journal.
  • It marks the commitment and records its cause with that evidence's caveats.
  • A repeated cause or a false guard changes nothing.
  • An uncommitted name is refused with evaluation/not_committed, and unobserved evidence with evaluation/unobserved_evidence.

The inventory is 97 authored laws and 250 theorems. A caveat-reopening/0.1 conformance runner compares the model with native and WebAssembly on 9 programs, with 11 accepted and 3 rejected reopening steps. Two compiled mutants of the runtime are caught: one that drops retained caveats on reopen, and one that drops the cause's caveats from the journal. Commitment creation and scheduled qualification are still not modeled, and the proofs README says so.

Release checks

scripts/kit-docs.mjs --check and the kit's tests refuse an mcpName or server.json name other than io.github.WSattazahn/caveat-lang, the GitHub login's exact case. They also refuse a server.json version that differs from the kit's (PR #152). rc.13's lowercase name, the cause of rc.14, can no longer reach a tag.

Documentation and examples

  • The authoring guide gains "What the language refuses to do for you", "What grows the save", and the one-series-per-exclusive-choice pattern. The kit gains two examples, reviewer-decision and boss-stance, each with events and scenarios (PR #159).
  • View 0.1 and the kit's Commitment type now say that open: true means reopened and awaiting a decision (PR #159). A design note for View 0.2 proposes ordered grounds, reopened in place of open, and a delta view (PR #164). None of it is implemented, and View 0.1 is unchanged.
  • A stray token was removed from Glowcap's Rule B verdict, and the verdict and its numbers are unchanged (PR #162).

Verified artifact

Runtime 37283790548 passed on this revision and produced the kit-package-candidate tarball caveat-lang-0.1.0-rc.15.tgz (904,066 bytes), SHA256 789b40ddf5bd1f24f4bcd9eb319dbd453e00e9d1519a2282dcf3a93e6e88805f. The publish workflow selected that run itself, re-checked the bytes, version and build, and published only that file.

Verified npm publication

publish-npm.yml run 37327425339 was dispatched from the tag with latest. Its publish job waited in the npm-publish environment until the owner approved it, then published with npm publish --provenance, authenticated by npm trusted publishing, on its first attempt. The registry records the version at 14:58:40 UTC.

The first attempt of its verify-publication job failed: the registry returned 404 for caveat-lang/0.1.0-rc.15 shortly after the publish. Only that job was re-run, and the second attempt passed. The publish was not repeated.

The compact publication record is copied from the second attempt's npm-publication-verification artifact. Its verify-publication job checked that the registry bytes and SHA512 integrity match the tested tarball (npm shasum a0a39628a8a8a423cc40f7106793ae334d5cbf6d); that the registry records an SLSA provenance attestation naming these bytes, this repository, .github/workflows/publish-npm.yml, refs/tags/v0.1.0-rc.15 and revision 3a88ba0; that npm audit signatures verified the registry signature and the attestation; and that a fresh exact-version install with a new npm cache and disabled lifecycle scripts passed both CLI identities, doctor, the agent demo, the umbrella scenarios and explanation. All 10 verification commands exited successfully. The package has no npm runtime dependencies.

latest names 0.1.0-rc.15 from the publish. The workflow sets one dist-tag, so the owner then moved next to it by hand; the verification ran before that and records next as 0.1.0-rc.14. Both now name rc.15. Install the exact candidate with:

npm install caveat-lang@0.1.0-rc.15

MCP Registry

The owner then published server.json to the MCP Registry with mcp-publisher. The first attempt failed at login (GitHub's device flow answered incorrect_device_code) and published nothing; the second logged in and published. The registry lists io.github.WSattazahn/caveat-lang version 0.1.0-rc.15 as active and latest, published 2026-10-05T15:24:08Z, installing caveat-lang@0.1.0-rc.15 from npm with npx and the mcp argument over stdio. rc.14's entry remains active and is no longer latest. This is the first listing update since rc.14's name co...

Read more

CAVEAT Language 0.1.0-rc.14

Pre-release

Choose a tag to compare

@github-actions github-actions released this 05 Oct 02:36
51590b4

CAVEAT Language 0.1.0-rc.14 — the MCP server name the registry accepts

Published and verified on npm, with provenance. The v0.1.0-rc.14 tag identifies source 51590b4c3cd9ee09ee3603abaa147ee61df87d95 (PR #150). Registry verification finished at 2026-10-05T02:17:29.240Z.

rc.14 is the third version published through publish-npm.yml: the workflow published the exact tarball that Runtime tested for the tagged revision, authenticated by npm trusted publishing, with an npm provenance attestation. The scope is described in the rc.14 development record.

The MCP server name

rc.14 changes one thing in the package: its package.json declares mcpName io.github.WSattazahn/caveat-lang, and server.json names the server the same way. rc.13 declared io.github.wsattazahn/caveat-lang, all lowercase. The MCP Registry grants a GitHub login the namespace io.github. followed by the login exactly as GitHub spells it, and checks that the published package's mcpName equals the server name exactly, so the registry refused rc.13 and cannot list it. Published npm versions do not change, so the correction needs a new version.

The runtime, the language, the kit library, the CLI and the specifications are unchanged from rc.13. A program, save or event history that works with rc.13 works the same way with rc.14. See the rc.13 release record for what rc.13 changed.

Repository changes since rc.13, not in the package

  • The Caveatist skill is listed as caveat in Anthropic's plugin directory, from plugins/caveat (PR #143, PR #144, PR #146). Each of its habits is marked [TESTED] or [PROPOSED] (PR #148), and the Caveatist philosophy is no longer called fictional (PR #147). The same folder carries a manifest for OpenAI's plugin directory, where it is not listed yet (PR #149). These change nothing the runtime does.

Verified artifact

Runtime 37252199187 passed on this revision and produced the kit-package-candidate tarball caveat-lang-0.1.0-rc.14.tgz (876,784 bytes), SHA256 9aab7b811666e5b43b6f7c96ad5116235241b08fbed395698476cc035bfd57bf. The publish workflow selected that run itself, re-checked the bytes, version and build, and published only that file.

Verified npm publication

publish-npm.yml run 37254432886 was dispatched from the tag with latest. Its publish job waited in the npm-publish environment until the owner approved it, then published with npm publish --provenance, authenticated by npm trusted publishing, on its first attempt. The registry records the version at 02:15:20 UTC.

The first attempt of its verify-publication job failed: npm audit signatures got 404 from the registry's attestations endpoint about 45 seconds after the publish. The endpoint returned the attestations shortly afterwards, and only that job was re-run; the second attempt passed. The publish was not repeated.

The compact publication record is copied from the second attempt's npm-publication-verification artifact. Its verify-publication job checked that the registry bytes and SHA512 integrity match the tested tarball (npm shasum 779a54725c68a7733c7f5c63fb609f5a87bc2836); that the registry records an SLSA provenance attestation naming these bytes, this repository, .github/workflows/publish-npm.yml, refs/tags/v0.1.0-rc.14 and revision 51590b4; that npm audit signatures verified the registry signature and the attestation; and that a fresh exact-version install with a new npm cache and disabled lifecycle scripts passed both CLI identities, doctor, the agent demo, the umbrella scenarios and explanation. All 10 verification commands exited successfully. doctor on the installed package reports runtime build 51590b4, and the published package.json carries mcpName io.github.WSattazahn/caveat-lang. The package has no npm runtime dependencies.

latest names 0.1.0-rc.14 from the publish. The workflow sets one dist-tag, so the owner then moved next to it by hand; the verification ran before that and records next as 0.1.0-rc.13. Both now name rc.14. Install the exact candidate with:

npm install caveat-lang@0.1.0-rc.14

MCP Registry

The owner then published server.json to the MCP Registry with mcp-publisher. The registry lists io.github.WSattazahn/caveat-lang version 0.1.0-rc.14 as active and latest, published 2026-10-05T02:23:16Z, installing caveat-lang@0.1.0-rc.14 from npm with npx and the mcp argument over stdio.

Later documentation updates do not move the tag or rebuild the published package. Existing Lean verification remains limited to its documented fragment; this release introduces no broader proof or adoption claim. These checks do not authenticate supplied evidence or saved history.

CAVEAT Language 0.1.0-rc.13

Pre-release

Choose a tag to compare

@github-actions github-actions released this 04 Oct 23:17
8f4e700

CAVEAT Language 0.1.0-rc.13 — program interfaces, typed hosts and narrower restore

Published and verified on npm, with provenance. The v0.1.0-rc.13 tag identifies source 8f4e7007ddac3d28d46be03a755e34f2b7230377 (PR #137, merged after the release notes in PR #134). Registry verification finished at 2026-10-04T22:40:38.191Z.

rc.13 is the second version published through publish-npm.yml: the workflow published the exact tarball that Runtime tested for the tagged revision, authenticated by npm trusted publishing, with an npm provenance attestation. The scope is described in the rc.13 development record.

A program's interface, and TypeScript declarations from it

  • caveat-interface/0.1 (PR #130). WebReactiveSession.interface(source), the kit's runtime.interface(source), caveat-lang types --json PROGRAM and the native CLI's caveat --interface PROGRAM return a loaded program's interface as JSON: its events with typed payload fields, states with bounds, bindings with value types and whether every view shows them, cues, decision series, reading streams, and declared evidence, caveat and claim names. These are load-time facts only; nothing is evaluated, and the view and snapshot are unchanged. A program that does not load returns its load error. The output is byte-identical from native and both WebAssembly builds for every repository program that loads. See Program interface 0.1.
  • caveat types PROGRAM (PR #133) writes TypeScript declarations from that interface: a payload map per event, the binding map (a property shown only under a when is optional), name unions for states, cues, decisions, readings, evidence, caveats and claims, and Session and View types for typed(session) from caveat-lang/types. A JavaScript or TypeScript host can type-check its event names, payload fields and displayed values against the program.

What the types catch was measured, not assumed. On Glowcap round 7's four Caveat adapters, checked with // @ts-check and tsc --checkJs, adding the declarations took 11 or 12 lines per adapter and checked 15 to 21 names and fields in each. It found no mismatch with any program and caught all 16 misspelling controls except the decision series name. Forwarded event names and computed names stay unchecked, and none of the round's recorded failures would have been caught at type-check time. The measurement is in experiments/glowcap/round7/types/.

Restore refuses more of what the source could never leave

Restore narrows what it accepts in two more places, under the same conservative boundary as rc.11 and rc.12: a record is refused only when no mechanism of the loaded source can produce it, and accepted when that is uncertain.

  • A caveat the source cannot attach (PR #131, findings F330, F333, F335–F337). A saved provenance is refused when it carries a caveat that no mechanism of the loaded source can attach to it, either through its evidence or, as examined(...) and a commitment's retaining caveats do, without evidence. This applies to lineages, grounds, bases, guards, qualification records, readings and journal entries. Before, rc.12 accepted any declared caveat there, so a forged one reached using reads and the examined(), reopened() and committed() guards. A caveat the program could have attached still restores, without proof that it was.
  • A membership without its record (PR #135, findings F317–F322). A save is refused when it says evidence was observed, a caveat examined or a commitment reopened but holds no matching observation, examination or reopening record. Before, such a save restored and nothing reported the mismatch. A record removed together with its membership still restores, as a save the program could have written, and evidence and attention a declaration sets when the program loads need no record.

Saves the runtime writes are unaffected. 79,855 genuine saves from 151 reactive programs (the repository's programs, the runtime tests' program sources, Glowcap round 7's four Caveat programs and the caveatism canon), driven with seeded events, restore with none refused, and so do the saves published rc.3 to rc.12 write from the same event traces. Restoring a save still does not authenticate its history: a record the source could have produced restores as before, whether or not it really occurred. See the save contract and the restore trust boundary.

Upgrade note: a refused save throws CaveatError with kind: "restore" and a message beginning cannot restore save:, as in rc.12; caveat serve answers a restore request with an error carrying the same message.

id_text of a non-handle refuses the event (F309–F312, F338–F339)

id_text(h) with a number other than 0 that is not a handle the session holds used to end the session as a fatal unclassified failure (PR #129). It is now a domain failure where it occurs: the event is refused as evaluation/expression with the same message, rolls back, and the session accepts the next event. This holds in guards, rule bodies, bindings and if branches, on native and WebAssembly and through caveat serve. id_text(0) is still the empty string, require around it still reports evaluation/requirement_failed, and a type error in an expression stays fatal. One more fatal becomes a refusal; no accepted event changes. See the dispatch contract.

Proofs

Lean now proves that a later qualification leaves every commitment's basis and grounds unchanged (Late Qualification §3; PR #127). It adds 12 laws, and a conformance runner for caveat-late-qualification/0.1 runs 9 programs, with 14 qualification events, on native and WebAssembly against the model. Commitment creation, reopening, the journal and scheduled qualification are not modeled, and the proofs README says so.

Documentation

  • The package README's links now open the documentation on GitHub, so they resolve on npm and Socket instead of 404ing; the copies that shipped with this version remain in the package's own docs/ and examples/. A kit test refuses a relative README link or a link to a file the repository does not track (PR #126).
  • Glowcap round 7 is a row in the README's benchmark table, with its work list and its own sentence that no claim of Caveat being better than TypeScript rests on it (PR #124). The README's first-screen claim is unchanged.
  • Design notes for a save that forgets what the program forgot and for integer tick time, each ending with the owner's decision (PR #125, PR #132). Neither is implemented in this release.
  • The identifiers spec no longer says id_text of a non-handle is fatal "as 1 / 0 is" (F261).

The Caveatist skill, installable where agents look

The Caveatist skill installs with npx skills add WSattazahn/caveat-lang and as the Claude Code plugin caveat from the repository's one-entry marketplace caveat-lang. CI keeps the installable copy at skills/caveatist/SKILL.md byte-identical to the canonical caveatism/skills/caveatist/SKILL.md. llms.txt gives documentation-reading agents a map of the repository, and server.json describes the package's MCP server as io.github.wsattazahn/caveat-lang; the package's package.json now carries the matching mcpName (PR #136). The skill is a practice an agent may adopt, not a contract of the language, and it changes nothing the runtime does. Listing in the MCP Registry and agent directories is a separate step after publication.

Other changes

  • Member symbols remain a draft specification. The search for a second program that a member reference would simplify found none outside Before the Rain, so the specification's own merge gate (§11.6) is unmet and nothing is implemented.

Verified artifact

Runtime 37236869595 passed on this revision and produced the kit-package-candidate tarball caveat-lang-0.1.0-rc.13.tgz (876,794 bytes), SHA256 f7f980d401cd53f338fc2dd4021364af53f52bc06bba613a3ffcb2e58351e9ed. A later push to main cancelled that run before it finished; it was re-run, and its one failing job, Light the Way in WebKit timing out on its first page load, passed when re-run (PR #141 gives that load more time). The publish workflow selected that run itself, re-checked the bytes, version and build, and published only that file.

Verified npm publication

publish-npm.yml run 37240443563 was dispatched from the tag with latest. Its publish job waited in the npm-publish environment until the owne...

Read more

CAVEAT Language 0.1.0-rc.12

Pre-release

Choose a tag to compare

@github-actions github-actions released this 04 Oct 15:51
9e360af

CAVEAT Language 0.1.0-rc.12 — restore trust, parameter grounds and MCP 2026-07-28

Published and verified on npm, with provenance. The v0.1.0-rc.12 tag identifies source 9e360afab3ff8ff0a92dd31af62cefda3cb102b5 (PR #119). Registry verification finished at 2026-10-04T15:19:29.961Z.

rc.12 is the first version published through publish-npm.yml: the workflow published the exact tarball that Runtime tested for the tagged revision, authenticated by npm trusted publishing, with an npm provenance attestation. The scope is described in the rc.12 development record.

Restore refuses more of what the source could never leave

Restore narrows what it accepts in two more places. The policy is the same conservative boundary rc.11 introduced: a record is refused only when no mechanism of the loaded source can produce it, and accepted when that is uncertain.

  • A caveat's attention (PR #110, findings 123, 188–191). A reactive save is refused when it holds deferred or examining attention, marks a caveat examined without an attention budget or on a caveat no examine of the source reaches, or marks examined caveats whose least costs exceed what the budget spent. An explicit unexamined entry, which claims no examination, is still accepted.
  • The keys the tables trust and the withdrawal event (PR #118, findings 86, 89, 96, 118–120). A save is refused when it holds an observation record of evidence that is neither observed nor a renewed occurrence, an examination record of a caveat it leaves unexamined, a reopening record of a commitment no reopens relation names, a predicate guard on a name of the wrong kind, or a withdrawal whose event reaches no withdraw of that evidence for that reason.

Saves the runtime writes are unaffected: each check was run against genuine saves from the repository's programs, and none was newly refused. Restoring a save still does not authenticate its history. A record the source could have produced restores as before, whether or not it really occurred, and a record whose source is uncertain is accepted. Restore does not verify saves or detect forgery in general. See the save contract and the restore trust boundary.

Upgrade note: a refused save throws CaveatError with kind: "restore" and a message beginning cannot restore save:, as in rc.11; caveat serve answers a restore request with an error carrying the same message. It is not an event refusal with an outcome code.

A procedure parameter carries its argument's grounds (F268)

A numeric proc parameter used to supply its argument's whole lineage as grounds, so evidence that only guarded a reveal appeared among a value's grounds when the value went through a procedure (PR #115). Now call store(qualified(7, w)) grounds slot on [w], as set slot = qualified(7, w) does, and the guard stays in lineage. The call's guard and its eagerly frozen arguments still take full lineage.

Values and commitments passed through numeric proc parameters may report narrower grounds, and rests_on_withdrawn no longer holds for a withdrawal of evidence that only gated an argument. Lineage, outcomes and values are unchanged. Saves written by rc.11 restore with their wider grounds kept. Re-running the repository corpus and Glowcap round 7's Caveat programs before and after the fix changed no outcome, snapshot or grounds. See Explanations 0.2.

MCP 2026-07-28

caveat-lang mcp speaks the MCP 2026-07-28 revision and keeps 2025-11-25 through its deprecation window (PR #111). A client may call server/discover, then tools/list and tools/call with io.modelcontextprotocol/protocolVersion and io.modelcontextprotocol/clientCapabilities in _meta and no initialize. Those results carry resultType: "complete" and io.modelcontextprotocol/serverInfo, and an unsupported version returns -32022. 2025-11-25 responses are unchanged, and so is the bridge's boundary: no sessions, no file paths, one call at a time, 10 seconds per call. No official 2026-07-28 client is on npm yet, so the new path is checked by the package gate's own probe. See MCP setup and limits.

Documentation

  • The agent quickstart and the agent-evidence example say that a caveat serve session lasts as long as its process, that each MCP tool call is a fresh subprocess with no session handle, and that one MCP connection accepts 4,096 request IDs. The authoring guide lists the rc.11 outcome codes evaluation/bound_exceeded and limit/scheduled_limit (PR #112).
  • The renewal and elapsed specs state when a scheduled qualification is due: on the first clock event at which the clock reading minus the reading stored at scheduling reaches the delay, in binary64. Rounding can make that an event later or earlier than exact arithmetic over the supplied dt values would (Version Lab finding F267). The authoring guide advises clock steps that are powers of two for timing exact to the event. No program's behaviour changes (PR #114).

Other changes

  • caveatism/ holds the culture around Mr. Caveat: the Caveatist Archive and Atlas, an optional practice for agents, and the artwork. It is fiction outside the language's contracts. Its canon is a Caveat program with 7 scenarios, run in CI. The package's README shows Mr. Caveat by URL; nothing else from it enters the package (PR #116).
  • The release ledger, experiments/agent-ledger/release.cav, records release gates as evidence (PR #109). It is not part of the package.
  • Glowcap round 7 compared seven fresh authors on rc.11 against TypeScript. TypeScript won, and Caveat met neither decision rule (PR #113, results). No claim that Caveat is better than TypeScript is made on the strength of it.
  • Member symbols remain a draft specification for this release; they are not implemented.

Verified artifact

Runtime 37185306547 passed on this revision and produced the kit-package-candidate tarball caveat-lang-0.1.0-rc.12.tgz (840,905 bytes), SHA256 2a22cc7a711418ed32f508a23de6c19aed66f1bd52c2c61548a79183eab20d15. The publish workflow selected that run itself, re-checked the bytes, version and build, and published only that file.

Verified npm publication

publish-npm.yml run 37211390333 was dispatched from the tag with latest. Its publish job waited in the npm-publish environment until the owner approved it, then published with npm publish --provenance, authenticated by npm trusted publishing. The first attempt was refused by npm (ENEEDAUTH) because the trusted publisher was not yet configured, and nothing was published; after the owner configured it, the re-run published the version at 15:18:16 UTC.

The compact publication record is copied from that run's npm-publication-verification artifact. Its verify-publication job checked that the registry bytes and SHA512 integrity match the tested tarball (npm shasum 4e8f16f44f63a384a1022a64b3926c1b405fd1e1); that the registry records an SLSA provenance attestation naming these bytes, this repository, .github/workflows/publish-npm.yml, refs/tags/v0.1.0-rc.12 and revision 9e360af; that npm audit signatures verified the registry signature and the attestation; and that a fresh exact-version install with a new npm cache and disabled lifecycle scripts passed both CLI identities, doctor (runtime revision 9e360af), the agent demo, the umbrella scenarios and explanation. All 10 verification commands exited successfully. The package has no npm runtime dependencies.

latest names 0.1.0-rc.12 from the publish. The workflow sets one dist-tag, so the owner then moved next to it by hand; the verification ran before that and records next as 0.1.0-rc.11. Both now name rc.12. Install the exact candidate with:

npm install caveat-lang@0.1.0-rc.12

Later documentation updates do not move the tag or rebuild the published package. These checks do not authenticate supplied evidence or saved history. Existing Lean verification remains limited to its documented fragment; this release introduces no broader proof or adoption claim.

CAVEAT Language 0.1.0-rc.11

Pre-release

Choose a tag to compare

@github-actions github-actions released this 04 Oct 03:06
8e7805a

CAVEAT Language 0.1.0-rc.11 — classified refusals and stricter restore

Published and verified on npm, without provenance. The v0.1.0-rc.11 tag identifies source 8e7805a57269c2084224df487fe186f0c6f6a4a9 (PR #103). Registry verification finished at 2026-10-04T02:34:05.146Z.

The owner published the CI-tested tarball by hand from a local terminal, without npm provenance. The provenance-attested route added in this cycle (publish-npm.yml) was not used for rc.11, so the registry holds no provenance attestation for this version, and no provenance, attestation or signature check is claimed below. The scope is described in the rc.11 development plan.

Classified refusals

More evaluation failures that depend on what a session has seen now refuse the event, with a documented code, instead of failing fatally (PR #96):

  • evaluation/unobserved_evidence: a late qualify, a withdraw, a reopen … because or a qualified() read on evidence that was never observed, or on a stream with no reading. The reopen diagnostic now names the reopen site instead of "cannot qualify a value with unobserved evidence".
  • evaluation/not_committed: reopening an action that has no commitment.
  • evaluation/expression: division by zero, a history index out of range, a nonfinite result, a negative sqrt, latest of an empty stream or series, and a decision read whose current commitment has no numeric using value, in rule effects and bindings.
  • evaluation/requirement_failed: require(COND, VALUE) with a false condition, including the built-in clamp and wrap.
  • limit/scheduled_limit: the 4,097th pending qualify … after.
  • evaluation/bound_exceeded: a clock event whose sum would make elapsed nonfinite (PR #101). No supported path reaches it; it guards an addition that was unchecked.

Whole-event rollback is unchanged: a refused event leaves no history, sequence number, cue, journal entry, schedule or partial change. Program-shape errors that the load-time checks own stay fatal; the dispatch spec's still-fatal example is a type error in an expression. See the dispatch contract.

Host migration: these codes are new values of the refusal code. A host that treated these failures as fatal must now inspect the returned outcome; a rejected operation did not complete.

Stricter restore

Restore now refuses save contents the loaded source could never produce (PR #99, PR #104):

  • a cue the saved last event cannot emit, and an effect whose kind, names or relation do not match a rule the last event reaches;
  • a field the schema lacks in any nested save record, not only at the top level;
  • a restored qualifies edge or pending scheduled qualification that no source mechanism can create. The policy is conservative: a pair is refused only when no mechanism can create it, and accepted when that is uncertain.

Genuine saves written by every published rc from rc.3 to rc.10 (18,437 saves) still restore, and the 49 scenario files with a resume step give the same results as rc.10. These checks narrow what restore accepts; they do not authenticate saved history. See the save contract.

Upgrade note: restore refuses qualifications the source could never produce (A3: F95, F260). rc.10 restored a qualifies relation such as ["phantom", "qualifies", "sensor"], or a pending scheduled qualification, whenever its two ends had the right kinds, even when no mechanism of the source could make that pair. rc.11 refuses such a save at restore. The refusal is not an event refusal with an outcome code: runtime.restore throws CaveatError with kind: "restore" and a message beginning cannot restore save:. For a relation, the message continues relation phantom qualifies sensor: no rule, declaration, reading, renewal or withdrawal of this program qualifies sensor with phantom. For a schedule, it continues scheduled qualification of EVIDENCE with CAVEAT: no qualify ... after of this program schedules it. caveat serve answers a restore request with an error carrying the same message. An integration test that expects rc.10 to accept such a qualification must expect this refusal before upgrading.

Restoring a save still does not authenticate its history. A qualification the source could have produced restores as before, whether or not it really occurred, and under the conservative policy a pair whose source is uncertain is accepted. Restore does not verify saves or detect forgery in general; saves the runtime itself wrote are unaffected.

Other changes

  • A reactive program may declare 128 functions of its own; the standard library no longer counts against that limit (PR #100).
  • Spec corrections: the scenarios spec's size example uses initial and every JSON example in that spec is now validated; the save spec says a journal entry records its commitment's frozen grounds exactly; the elapsed spec says the clock stays finite and loses precision near the binary64 limit (PR #102, PR #101).
  • Before the Rain joins the repository as a hand-written corpus program; its 12 scenarios pass (PR #103). It is not part of the npm package.
  • A draft specification for member symbols records the design that supersedes $Q. It is not implemented (PR #97).
  • Release engineering (PR #98): a provenance-attested publish workflow for future candidates, and a declared-capabilities table in package security with a test that scans the packed tarball against it.

Verified artifact

Runtime 37169499765 passed on this revision and produced the kit-package-candidate tarball caveat-lang-0.1.0-rc.11.tgz (832,498 bytes), SHA256 13fd6e298731c46e024f10788e1f68834a1c02625fd74bb4715730b4a4887a8e. The owner checked that SHA256 on the downloaded artifact before publishing it.

Verified npm publication

The compact publication record records the registry identity, the installed-package checks and how the version was published.

The registry tarball's SHA256 and SHA512 integrity match the tested artifact, and npm's shasum is 72ce8e1fefc9f56a43dafc953ebd8508e72416ec. A fresh exact-version install with a new npm cache and disabled lifecycle scripts passed both CLI identities, doctor (which reports runtime revision 8e7805a), the agent demo, the two umbrella scenarios, strict checking and explanation. The packed files match the declared capabilities. All 10 verification commands exited successfully. The package has no npm runtime dependencies.

The record was regenerated by re-running the checks of scripts/verify-npm-publication.mjs locally against the public registry, except its provenance, attestation and npm audit signatures steps: the version has no provenance, and Sigstore was unreachable from the verifying environment. Registry signatures were therefore not verified for this record.

latest and next both name 0.1.0-rc.11. Install the exact candidate with:

npm install caveat-lang@0.1.0-rc.11

Later documentation updates do not move the tag or rebuild the published package. These checks do not authenticate supplied evidence or saved history. Existing Lean verification remains limited to its documented fragment; this release introduces no broader proof or adoption claim.

CAVEAT Language 0.1.0-rc.9

Pre-release

Choose a tag to compare

@WSattazahn WSattazahn released this 03 Oct 01:30
7ff92b1

CAVEAT Language 0.1.0-rc.9 — package consistency, worker hardening, and branch verification

rc.9 makes the package's installation instructions agree with its own version,
reduces the environment passed to authoring workers, and extends the checked
Lean/native Rust/WebAssembly comparison to selected conditional branches. The
kit has zero npm runtime dependencies. Lean remains a pinned,
development-only verification tool using its bundled libraries.

Implemented in PR #92, merged
as 7ff92b145ac9ce6f55588911c52ddc780b122916.

Changes

Keep bundled instructions consistent with the package

The rc.8 tarball retained earlier installation and publication wording. rc.9
now generates package identity and exact-version installation blocks from
kit/package.json. A consistency gate rejects stale package pins, moving
installation tags, and publication dates, channels or receipts in the immutable
kit guides. Genuine feature history is preserved.

The installed-package gate follows the bundled README from a fresh directory
using the same retained tarball: version, doctor, agent demo, starter creation,
two umbrella scenarios and explanation. It also checks the getting-started and
worked-example guides. Publication status stays in external release records;
the bundled guides describe the package version that contains them.

Stop forwarding application environment variables to authoring workers

The MCP bridge now supplies an empty environment option instead of copying the
parent application's environment into every child. It retains the fixed Node
executable, first-party worker path, shell: false, process limits and Windows
window handling. A real-child regression checks that a synthetic unrelated
secret and Node preload/path settings are absent before executing the actual
authoring worker. Launch-failure recovery joins the existing timeout,
cancellation, output-limit, crash and subsequent-call checks. The worker suite
passes on Linux and Windows.

On Windows, Node/libuv may supply ordinary process-support variables despite
that empty option. This is a reduction in inherited application configuration,
not an operating-system sandbox. The host still controls the server startup
environment and any runtime override.

The scoped capability review
records what was actually visible in the supplied Socket history and public
views. Exact scanner finding locations and the sixth historical label remain
unattributed. No Socket rescan or clearance is claimed.

Compare selected branches using the proved Lean definitions

The bounded bridge now accepts one nonnested conditional between two eager
state sums. It executes the existing proved Tracked.select definition. Both
selections have exact value, lineage and grounds equations and successful
nonempty evidence/caveat witnesses. The condition and chosen branch contribute
their dependencies; the untaken branch contributes none. Separate witnesses
preserve the distinction between an expression condition and an external
statement guard.

The pinned Lean 4.34.1 verification gate checks 68 authored laws and an
inventory of 147 public theorems, audits transitive axioms, replays all five
project modules through Lean's kernel, and requires the incomplete-proof and
indirect custom-axiom controls to fail for their intended reasons.

The executable comparison runs 72 deterministic cases through the proved
Lean definitions and the production native Rust and WebAssembly entrypoints:
122 accepted and 26 rejected modeled steps. It compares exact values and
both dependency channels, preserves observation/effect ordering, checks complete
native/WASM captures and rejection rollback, continues one event from every
restored prefix, and checks a final save roundtrip.

33 decoder refusal controls enforce the registered input boundary, including
conditional object shapes, duplicate keys after escape decoding, the old schema,
and bounded input loading. 15 semantic mutation executions across eight
families
detect lost condition or selected-branch dependencies and injected
untaken dependencies, alongside the existing eager-flow, guard, citation and
ordering controls. Five compilation entries cover four distinct mutations of
the production expression evaluator and run seven witnesses; four source
translation controls run through native and WASM for the other eight executions. The dependency-loss mutations remove metadata from both
lineage and grounds while preserving the numeric answer, so subset inclusion
alone cannot make them pass. Crashes, malformed traces and unrelated failures
never count as successful mutation detection.

See the verification contract
and Lean guide
for the registered fragment, trust boundary and exact commands.

Final-main verification

Release source: 7ff92b145ac9ce6f55588911c52ddc780b122916.

  • Runtime CI: 1,474 Rust tests across full and reactive-only configurations, both lint configurations, 245 kit tests, Linux/Windows worker checks, affected browser suites, independent WebAssembly reproducibility and all 15 installed-package groups passed.

  • Lean audit: 68 authored laws, 147 inventoried theorems, transitive axiom audit, kernel replay and both negative controls passed. The Runtime workflow also passed 72 comparison cases, 33 decoder controls and 15 mutation executions.

  • Same-tarball dependency-security checks passed seven scopes. Five npm scopes reported zero advisories; the Rust build-lockfile scan reported zero vulnerabilities or warnings. These dated dependency checks do not establish Socket clearance.

  • Formatting and Pages/live checks passed. Conditional Legacy Door jobs were scope-skipped.

  • The deployed build metadata and all four full/reactive JavaScript and WASM hashes match the retained final-main distribution. A fresh install of the retained package passed both aliases, doctor, demo and seven restore checks.

  • Additional live Beacon and rescue desktop/mobile checks passed; fresh representative mobile screenshots were inspected.

  • The registered compatibility replays passed: five saved cases (16,011 events and 13 resumes), plus 4,000 seeded sequences covering 14,443,471 events with zero reported divergences. Historical study files remained unchanged.

  • Before publication, the retained package also passed 13 exact branch checks, all five authoring tools with refusal recovery, and 11 package guide checks.

Scope

This release changes package instructions, worker environment handling and
verification coverage. The production Rust semantics source is unchanged from
rc.8. The restore boundary checks remain covered by the runtime suite and the
seven exact-package restore checks; this is test evidence, not a claim that all
language behavior is proved.

The executable comparison covers bounded exact integers, eager state sums,
one nonnested conditional body, statement guards and state citations. It does
not cover arbitrary or nested expressions, general floating-point arithmetic,
dynamic observation/qualification, readings, withdrawal, commitments or
historical journals. The fixed neutral-observation seed is a fixture. The
fragment has no fatal-producing operation; Fatal disposal has separate runtime
boundary coverage. A compiled rejected-state-leak mutation remains outside the
registered comparison gate.

The Lean theorems prove properties of the stated model. Sampled runtime
agreement is not a Rust refinement proof, and the parser, adapters, generated
machine code and save validation are not formally proved. Native Rust and WASM
share the production interpreter. Supplied evidence is not authenticated by
these checks. No adoption study or historical benchmark is reinterpreted here.

Artifact and publication status

The release archives the exact tested Linux package: caveat-lang-0.1.0-rc.9.tgz (812,345 bytes).

SHA256: ed75568c267a2c8ef3692571e1796b0d856471acbe5e4f99b56650a451108d24

Npm integrity: sha512-hDR7n3rG2VoEAjcLVzm95Gon4B6im0FwtkIQnDM07Mm70vamJtw8Z1fmQdwr7OSQgraLVNaXs5g5TC0d7J90Uw==

The annotated tag names 7ff92b145ac9ce6f55588911c52ddc780b122916. Official npm publication was verified at 2026-10-03T01:34:46.441Z. The registry tarball matches the archived tested package. The next channel points to rc.9; latest remains at rc.5. All 14 fresh-install verification commands passed, including both aliases, doctor/demo/starter, seven restore boundaries, 13 branch cases, all five authoring tools with refusal recovery, and 11 bundled guides.

Install the verified publication:

npm install caveat-lang@0.1.0-rc.9

Only kit/package.json owns the kit candidate version. Historical release artifacts and registered study evidence remain intact.

Public evidence: registry/install verification and command receipts.

Final-main verification passed at 1ce7969: Runtime and Pages/live QA, along with Lean, formatting and the historical helper: 26 required jobs passed, with two expected Legacy Door skips. Fresh desktop/mobile About checks pass...

Read more

CAVEAT Language 0.1.0-rc.10

Pre-release

Choose a tag to compare

@WSattazahn WSattazahn released this 03 Oct 16:18
03955da

CAVEAT Language 0.1.0-rc.10 — recoverable refusals and visible withdrawals

Published and verified on npm. The v0.1.0-rc.10 tag identifies source 03955daf6ed64914d3c21835d8779b286f856042 (PR #94). Registry verification finished at 2026-10-03T16:23:37.934Z.

CAVEAT now returns recoverable refusals for two specific evaluation failures and makes evidence withdrawals visible in dependency reports. It also documents existing restore boundaries and provides an executable example for preserving save text.

Recoverable refusals

Exhausted examination attention returns limit/attention_limit; an empty caveated() witness selection returns evaluation/empty_caveated_selection. Outcome clients receive outcome: "rejected" and can continue using the session.

Whole-event rollback already existed and remains intact: rejected work does not advance history, sequence numbers or cues, retain partial changes, or manufacture evidence or attention. A later valid event and save/restore remain available. Other fatal errors retain their existing classification. See the dispatch contract.

Host migration: inspect the returned outcome from dispatch and dispatchView. A rejected operation did not complete, even though the session remains usable. Hosts that previously relied on these two failures throwing a fatal error must explicitly handle the refusal before recording success or continuing dependent work.

Visible withdrawals

dependents JSON and text now identify query-matched withdrawn observations, their reasons, events and sequence numbers. Reports include a top-level withdrawals array and per-item withdrawn arrays.

A withdrawal does not itself reopen a decision or rewrite frozen grounds. Decision status still reflects authored history. Matching covers evidence, streams, templates, caveats, permissions and revisions. The formatter accepts older report objects without the new arrays; newly produced reports include them. The schema remains caveat-dependents/0.1. See the report contract.

Save and restore boundaries

This candidate changes no restore validator or save schema. The clarified contract distinguishes malformed required fields from omitted sparse state entries: omitting a state entry restores its source initial value, while earlier commitments can retain their frozen history.

A well-formed injected qualification edge can pass existing validation. Restore checks do not establish that every accepted graph or state arose through the source program, or authenticate saved history. origin: "live" identifies the current graph, not trusted provenance. See the save contract and trust-boundary design review.

Hosts should preserve the exact returned save string. JavaScript parsing and re-serialization can normalize negative zero and change a later decision. The shipped file-storage example demonstrates intact text storage. Restore-equivalence claims apply to intact runtime-produced text under the same source/runtime contract.

Other corrections

Documentation now distinguishes checked dependency references from evidence truth or explanation accuracy. View documentation includes decision_journal. The Door page declares UTF-8. A process-liveness test checker race is fixed; production process shutdown is unchanged.

Verified artifacts

Runtime 37133978605 and Pages 37135044751 passed on this revision: 746 full Rust, 734 reactive-only Rust, 262 kit and 29 supplemental tests. Package/install and dependency advisory checks passed. The retained and live full/reactive JavaScript and WASM bytes match the clean Linux build.

Additional live Beacon, Door and all four Rescue routes passed; selected screenshots were reviewed. Chromium mobile Rescue used native touch; WebKit mobile used mouse input at a mobile viewport. The owner retains final interactive visual judgment.

The attached npm tarball is caveat-lang-0.1.0-rc.10.tgz (820,299 bytes), SHA256 19f82b19c6eed94f9191cc45611d61917e8d1d52e1b834b41e5230aaa751378f. SHA256SUMS covers the original candidate assets; npm-publication-SHA256SUMS covers the later npm verification and receipt archive. verification-manifest.json links source, workflows, runtime hashes and preserved contracts. The runtime archive includes both runtimes, metadata, license and notices. The verification archive preserves selected security inputs, all 56 command streams and compact integration receipts. Known dependency advisory checks do not establish absence of unknown vulnerabilities.

Verified npm publication

The official registry tarball SHA256 and SHA512 integrity match the exact tested artifact. A fresh exact-version install with a new npm cache and disabled lifecycle scripts passed both CLI identities, doctor and agent demo, two umbrella scenarios, strict checking and explanation. Both new recovery cases passed through dispatch, dispatchView, restore/continuation, serve and CLI. The save-text example retained signed zero; all five restore-boundary and eight withdrawal tests passed against the installed package. All 18 verification commands exited successfully.

next names 0.1.0-rc.10; latest remains 0.1.0-rc.5. Install the exact candidate with:

npm install caveat-lang@0.1.0-rc.10

The original attached candidate manifest and release-notes asset are retained as the snapshot taken before npm publication. The npm verification above records the completed publication. Later documentation updates do not move the tag or rebuild the published package.

Documentation closeout

PR #95 records the verified publication in the README, agent guidance, release records and live About page. Its documentation merge is 00be10da2bdbf631e1a2c6a3a240c8c0cc2a6c0e.

Final-main Runtime and Pages deployment with live checks passed. A separate public-site check confirmed the new documentation revision, exact About source, unchanged full/reactive JavaScript and WASM hashes, and unchanged npm channels. Desktop and mobile Chromium About checks passed; all four screenshots were inspected. The release tag and npm package remain pinned to 03955daf6ed64914d3c21835d8779b286f856042.

documentation-deployment-SHA256SUMS covers these two later documentation assets. Their public downloads were verified against the locally staged hashes.

These checks do not authenticate supplied evidence or saved history. Existing Lean verification remains limited to its documented fragment; this release introduces no broader proof or adoption claim.

CAVEAT Language 0.1.0-rc.8

Pre-release

Choose a tag to compare

@WSattazahn WSattazahn released this 02 Oct 21:26
5ebe574

CAVEAT Language 0.1.0-rc.8

This prerelease strengthens saved-state validation and adds development-only Lean verification with a bounded comparison against the production runtime.

  • Restore rejects state grounds outside saved lineage and commitment grounds outside their frozen basis, while preserving valid narrowed or omitted grounds and historical commitment bases.
  • 58 authored Lean laws and a 128-theorem inventory cover exact dependency flow, guarded assignments, citations, and separate Accepted, Rejected, and Fatal outcomes. Transitive axiom audit, kernel replay and both proof controls pass.
  • 53 deterministic cases compare the proved definitions with native Rust and production WASM. Eighteen decoder controls and nine semantic mutation executions pass, including dependency loss from both lineage and grounds.
  • Four WASM overflow cases check Fatal disposal and refusal to reuse the session.
  • No npm runtime dependencies are added. Lean is a pinned development tool.

This is bounded executable conformance, not a proof that the entire Rust implementation refines Lean. See the verification contract and scope.

Verified revision: 5ebe5743cae50cb17767b00f86188646b5946d31.

Final Runtime CI and Pages/live CI passed. Retained package, security and proof receipts bind the exact tested Linux artifact. A fresh local install passed both CLI aliases, doctor, demo and seven restore cases; additional live Beacon and ferry tests passed. The deployed full/reactive runtime hashes match the tested build.

Package: caveat-lang-0.1.0-rc.8.tgz
SHA256: 75dab1f97a95774e4791303e38b484651379bfe922ede7805fa8dcf07828d021

Official npm publication of caveat-lang@0.1.0-rc.8 is verified. Registry SHA256, SHA512 integrity and downloaded bytes match the retained tested tarball. A fresh exact-version install passed both CLI aliases, doctor, demo, two umbrella scenarios, strict authoring checks, explanation checks and all seven restore cases. next names rc.8; latest remains rc.5.

npm install caveat-lang@0.1.0-rc.8

Publication verification and complete command receipts record the registry and fresh-install checks.

The immutable tarball retains documentation written during candidate preparation, including the earlier rc.7 installation notice. This dated publication record and current repository documentation describe rc.8 availability; the tested package was not rebuilt or repacked.