Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
86 commits
Select commit Hold shift + click to select a range
323dd50
add v4.3 public MCP evidence path
codex Jul 27, 2026
80b0da0
docs: define staged AgentPool autonomy goal
codex Jul 27, 2026
710d320
feat: add staged v4.3.5 autonomy
codex Jul 27, 2026
c25fbd8
feat: verify zero-context Qwen MCP discovery
codex Jul 27, 2026
2a97818
docs: publish Qwen MCP discovery evidence
codex Jul 27, 2026
a89f903
Publish v4.3.5 staged autonomy alpha
codex Jul 28, 2026
563ab0b
Add resilient Base Sepolia RPC fallback
codex Jul 28, 2026
55dbff5
Add autonomous AgentPool runner and buyer inbox
codex Jul 28, 2026
c276166
Harden autonomous runner onboarding and retries
codex Jul 28, 2026
3162adb
Add multi-role autonomous AgentPool runner
codex Jul 28, 2026
9c80497
Allow autonomous relay events through MCP
codex Jul 28, 2026
751dffb
Run AgentPool autonomously with Codex
codex Jul 28, 2026
f9f5d11
Fix Windows Codex login detection
codex Jul 28, 2026
b058948
Version public AgentPool runner downloads
codex Jul 28, 2026
d0680ba
Add finite self-bootstrap improvement market
codex Jul 28, 2026
63c0e4b
Fix unreserved bootstrap balance reporting
codex Jul 28, 2026
d1e2920
Harden MCP transaction gas estimation
codex Jul 28, 2026
25858d9
Add autonomous v4.3.7 validation harness
codex Jul 28, 2026
b37f7d6
Add automatic testnet gas onboarding
codex Jul 29, 2026
666f576
Harden gas onboarding RPC fallback
codex Jul 29, 2026
88d7578
Rank autonomous work by expected net profit
codex Jul 29, 2026
d363672
Harden autonomous improvements and prepare v4.4 mainnet candidate
codex Jul 29, 2026
2be6dca
Add reproducible v4.4 release evidence and stateful invariants
codex Jul 29, 2026
d63bb4b
Protect innocent parallel worker bonds
codex Jul 29, 2026
cf76f9a
Make Solidity artifacts cross-platform reproducible
codex Jul 29, 2026
36bb974
Decouple mainnet gate approvals from source hash
codex Jul 29, 2026
ea451dd
Base awards on verified capability outcomes
codex Jul 29, 2026
11628a9
feat: close autonomous improvement reward loop
codex Jul 29, 2026
63a3566
fix: bind candidate artifacts to their signer
codex Jul 29, 2026
cf18b5d
fix: deduplicate runner cycle observations
codex Jul 29, 2026
c0a5a2a
Separate external performance from Work Power
codex Jul 29, 2026
38a672b
Harden v4.4 mainnet deployment and release proofs
codex Jul 29, 2026
5d8c873
Add v4.4 adversarial review packet
codex Jul 29, 2026
e623952
Enforce v4.4 Slither baseline in CI
codex Jul 29, 2026
eaf100b
Expand v4.4 stateful fund invariants
codex Jul 29, 2026
54a160d
Harden v4.4 mainnet finance and governance
codex Jul 29, 2026
2697463
Harden v4.4 mainnet candidate gates
codex Jul 29, 2026
b535be6
Raise v4.4 testnet deployment gas floor
codex Jul 29, 2026
a57a64a
Record v4.4 Base Sepolia deployment
codex Jul 30, 2026
eb8f25c
Expose v4.4 read-only alpha
codex Jul 30, 2026
1d8fc90
Bind v4.4 autonomy evidence
codex Jul 30, 2026
e52ff1f
Harden v4.4 participant supply chain
codex Jul 30, 2026
042c17a
Publish v4.4 read-only participation path
codex Jul 30, 2026
3ba771c
Harden v4.4 public autonomy evidence
codex Jul 31, 2026
4a93685
Clarify versioned MCP endpoints
codex Jul 31, 2026
87a2794
Make v4.4 verification cross-platform
codex Jul 31, 2026
321467a
Use portable installer hashing
codex Jul 31, 2026
dbfad05
Pin participant bundle bytes across platforms
codex Jul 31, 2026
a072230
Harden v4.4 autonomy evidence and public provenance
codex Jul 31, 2026
e6ff97c
Allow provenance hashing of large Git blobs
codex Jul 31, 2026
3ea01a5
Record the v4.4 build toolchain in provenance
codex Aug 1, 2026
15b6210
fix: avoid recursive public MCP fetches
codex Aug 1, 2026
3b0bfda
fix: bind autonomy evidence to deployed events
codex Aug 1, 2026
48ccba1
docs: clarify split deployment provenance
codex Aug 1, 2026
8e5040e
Bind v4.4 reliability evidence to finalized chain state
codex Aug 1, 2026
0cc31ff
Fetch historical contract commit in protocol CI
codex Aug 1, 2026
5bced80
Resolve development dependency audit warning
codex Aug 1, 2026
04f9671
Separate historical testnet source evidence
codex Aug 1, 2026
37b0181
Document explorer provenance publication
codex Aug 1, 2026
60df87b
Harden v4.4 autonomy evidence gates
codex Aug 3, 2026
14c1827
Sync minimatch security override lockfile
codex Aug 3, 2026
d139639
Close v4.4 maturity evidence gaps
codex Aug 3, 2026
29fd6a6
Scope v4.4 exposure limits per deployment
codex Aug 3, 2026
0e31208
Regenerate task market artifact
codex Aug 3, 2026
a36340a
Track policy anchor in static analysis test
codex Aug 3, 2026
2cdee4e
fix: harden v4.4 maturity evidence
codex Aug 3, 2026
6a6bd93
chore: patch fast-uri advisory
codex Aug 3, 2026
2511b19
Harden v4.4 activation and maturity evidence
codex Aug 3, 2026
fedafe5
Scope static analysis to project contracts
codex Aug 3, 2026
6e61a21
Refresh threshold authority artifact
codex Aug 3, 2026
0be5f25
Close final v4.4 maturity evidence gaps
codex Aug 3, 2026
0ea51a3
Publish audited tree with exact Sites provenance
codex Aug 3, 2026
0bb9727
feat: add same-operator two-runner staging gate
codex Aug 4, 2026
bb2dc92
chore: publish verified two-runner evidence
codex Aug 4, 2026
688a08a
fix: pin published build provenance
codex Aug 4, 2026
fb89994
feat: isolate v44 testnet campaigns
codex Aug 4, 2026
1a65919
feat: bind real v44 bootstrap verification tasks
codex Aug 4, 2026
25eb57c
fix: derive testnet deploy reserve from receipts
codex Aug 4, 2026
3b311dc
chore: record isolated v44 testnet campaign
codex Aug 4, 2026
67fa2e4
feat: add v44 testnet participant bridge
codex Aug 4, 2026
0ce7c85
test: remove live RPC dependency from MCP surface check
codex Aug 4, 2026
2281d56
fix: align v44 testnet balance floor
codex Aug 4, 2026
6959d3a
fix: require valid v44 threshold owners
codex Aug 4, 2026
a93c641
chore: publish v44 candidate deployment
codex Aug 4, 2026
40aebd2
feat: publish current v44 testnet candidate
codex Aug 4, 2026
2f67eb5
feat: add bounded v44 autonomous worker
codex Aug 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
11 changes: 11 additions & 0 deletions .agents/mcp_config.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
{
"mcpServers": {
"agentpool": {
"command": "node",
"args": [
"public/agentpool-mcp.mjs"
],
"cwd": "."
}
}
}
5 changes: 5 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,10 @@ AGENTPOOL_WALLET_PROFILE=
AGENTPOOL_CHAIN_ID=84532
AGENTPOOL_RPC_URL=https://sepolia.base.org
DEPLOYER_PRIVATE_KEY=
# Hosted Base Sepolia-only gas sponsor. Store only as a Sites secret.
# It may send tiny capped test-ETH grants only after a device-signed
# GAS_REQUEST. Never use a mainnet-funded key.
AGENTPOOL_V43_GAS_SPONSOR_PRIVATE_KEY=
# Optional override; defaults to 0.001 test ETH in wei.
MIN_DEPLOYER_BALANCE_WEI=

Expand Down Expand Up @@ -59,6 +63,7 @@ V43_GENESIS_TIMESTAMP=
V431_GENESIS_TIMESTAMP=
V433_GENESIS_TIMESTAMP=
V434_GENESIS_TIMESTAMP=
V435_GENESIS_TIMESTAMP=
MIN_V43_DEPLOYER_BALANCE_WEI=100000000000000

# Hosted secret used to derive private capability exercises. Store only as a
Expand Down
61 changes: 61 additions & 0 deletions .env.v44.mainnet.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
# AgentPool v4.4 Base mainnet release candidate.
# Copy to .env.v44.mainnet.local only after every evidence gate is approved.
# Never commit the local file and never paste DEPLOYER_PRIVATE_KEY into chat.

AGENTPOOL_MAINNET_RPC_URL=https://your-base-mainnet-rpc.example
AGENTPOOL_V44_TESTNET_RPC_URL=https://sepolia.base.org
AGENTPOOL_V44_TESTNET_RPC_URL_2=https://base-sepolia-rpc.publicnode.com
# Exact immutable Base Sepolia campaign whose report clears the reliability gate.
V44_TESTNET_CAMPAIGN_ID=mainnet-candidate-1
DEPLOYER_PRIVATE_KEY=0xREPLACE_LOCALLY
MIN_V44_DEPLOYER_BALANCE_WEI=10000000000000000

# Exact clean Git commit containing the audited source and compiled settings.
V44_SOURCE_COMMIT=0000000000000000000000000000000000000000

# Immutable threshold authority deployed as part of the exact contract graph.
# Owners must be distinct sorted signer addresses; no owner is an admin.
V44_THRESHOLD_AUTHORITY_OWNERS=0x0000000000000000000000000000000000000001,0x0000000000000000000000000000000000000002,0x0000000000000000000000000000000000000003
V44_THRESHOLD_AUTHORITY_THRESHOLD=2

# Ignored local copy of mainnet-v44-gates.json containing evidence approvals.
# Keeping approvals outside the tracked source avoids a circular source hash.
V44_GATES_FILE=.mainnet-v44-gates.local.json

# Unix timestamp 72 hours to 30 days after deployment.
V44_GENESIS_TIMESTAMP=0

# The deployment EOA, proposer, and all validators must be different addresses.
V44_BOOTSTRAP_PROPOSER=0x0000000000000000000000000000000000000000
V44_VALIDATOR_1=0x0000000000000000000000000000000000000000
V44_VALIDATOR_2=0x0000000000000000000000000000000000000000
V44_VALIDATOR_3=0x0000000000000000000000000000000000000000

# Public, non-zero bytes32 identifiers backed by validator-independence evidence.
V44_VALIDATOR_1_GROUP_ID=0x0000000000000000000000000000000000000000000000000000000000000000
V44_VALIDATOR_2_GROUP_ID=0x0000000000000000000000000000000000000000000000000000000000000000
V44_VALIDATOR_3_GROUP_ID=0x0000000000000000000000000000000000000000000000000000000000000000

# Evidence-addressed bootstrap system-improvement catalog. It must contain
# 24-32 distinct objective tasks. Twenty successful settlements open the
# ownerless transition; at least four additional tasks provide bounded
# non-minting redundancy when a worker declines, expires, or fails.
V44_BOOTSTRAP_ISSUE_ID=0x0000000000000000000000000000000000000000000000000000000000000000
V44_BOOTSTRAP_OBJECTIVES_FILE=.mainnet-v44-bootstrap-objectives.local.json
V44_BOOTSTRAP_OBJECTIVES_SHA256=0000000000000000000000000000000000000000000000000000000000000000
V44_BOOTSTRAP_CATALOG_ID=base-mainnet-release-1
V44_BOOTSTRAP_OBJECTIVE_MODE=reliability
V44_BOOTSTRAP_PUBLIC_SPECIFICATIONS_FILE=outputs/v44-bootstrap-specifications.base-mainnet-release-1.json
V44_BOOTSTRAP_PUBLIC_SPECIFICATIONS_SHA256=0000000000000000000000000000000000000000000000000000000000000000
V44_GENESIS_MODULE_HASH=0x0000000000000000000000000000000000000000000000000000000000000000
V44_GENESIS_MANIFEST_HASH=0x0000000000000000000000000000000000000000000000000000000000000000

# These must equal the whole-file SHA-256 of each non-empty evidenceFile
# referenced by the approved V44_GATES_FILE. Zero placeholders are rejected.
V44_GATE_FINAL_SOURCE_REPRODUCIBILITY_SHA256=0000000000000000000000000000000000000000000000000000000000000000
V44_GATE_INDEPENDENT_SECURITY_REVIEW_SHA256=0000000000000000000000000000000000000000000000000000000000000000
V44_GATE_PUBLIC_TESTNET_RELIABILITY_SHA256=0000000000000000000000000000000000000000000000000000000000000000
V44_GATE_VALIDATOR_INDEPENDENCE_SHA256=0000000000000000000000000000000000000000000000000000000000000000
V44_GATE_ECONOMIC_INVARIANT_REVIEW_SHA256=0000000000000000000000000000000000000000000000000000000000000000
V44_GATE_DEPLOYER_LEGAL_ASSESSMENT_SHA256=0000000000000000000000000000000000000000000000000000000000000000
V44_GATE_NAME_AND_SYMBOL_CLEARANCE_SHA256=0000000000000000000000000000000000000000000000000000000000000000
56 changes: 56 additions & 0 deletions .env.v44.testnet.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
# AgentPool v4.4 Base Sepolia campaign deployment.
# Copy to .env.v44.testnet.local. Never commit private keys.

V44_TESTNET_ONLY_ACK=I_UNDERSTAND_THIS_IS_VALUELESS_BASE_SEPOLIA
# Unique lowercase deployment slot. Existing campaign manifests are never overwritten.
V44_TESTNET_CAMPAIGN_ID=mainnet-candidate-1
AGENTPOOL_V44_TESTNET_RPC_URL=https://sepolia.base.org
AGENTPOOL_V44_TESTNET_RPC_URL_2=https://base-sepolia-rpc.publicnode.com
DEPLOYER_PRIVATE_KEY=0xREPLACE_LOCALLY
# Operator floor. Preflight also enforces the greater of 0.0005 test ETH or
# five times the RPC-verified cost of the tracked prior v4.4 deployment.
MIN_V44_TESTNET_DEPLOYER_BALANCE_WEI=1

# Exact clean Git commit and its generated source evidence.
V44_SOURCE_COMMIT=0000000000000000000000000000000000000000
V44_SOURCE_EVIDENCE_FILE=outputs/v44-source-reproducibility.json
V44_THRESHOLD_AUTHORITY_OWNERS=0x0000000000000000000000000000000000000001,0x0000000000000000000000000000000000000002,0x0000000000000000000000000000000000000003
V44_THRESHOLD_AUTHORITY_THRESHOLD=2

# Unix timestamp 72 hours to 30 days after deployment.
V44_GENESIS_TIMESTAMP=0

# The deployer, proposer, and validators must be five distinct addresses.
V44_BOOTSTRAP_PROPOSER=0x0000000000000000000000000000000000000000
# Worker signs through its own device-local wallet; the coordinator never stores
# or receives this private key.
V44_BOOTSTRAP_WORKER=0x0000000000000000000000000000000000000000
V44_VALIDATOR_1=0x0000000000000000000000000000000000000000
V44_VALIDATOR_2=0x0000000000000000000000000000000000000000
V44_VALIDATOR_3=0x0000000000000000000000000000000000000000
V44_VALIDATOR_1_GROUP_ID=0x0000000000000000000000000000000000000000000000000000000000000000
V44_VALIDATOR_2_GROUP_ID=0x0000000000000000000000000000000000000000000000000000000000000000
V44_VALIDATOR_3_GROUP_ID=0x0000000000000000000000000000000000000000000000000000000000000000

V44_BOOTSTRAP_ISSUE_ID=0x0000000000000000000000000000000000000000000000000000000000000000
V44_BOOTSTRAP_OBJECTIVES_FILE=.testnet-v44-bootstrap-objectives.local.json
V44_BOOTSTRAP_OBJECTIVES_SHA256=0000000000000000000000000000000000000000000000000000000000000000
# Real campaign deployments require a generated public verification specification
# file bound to the private challenge catalog. Use mechanics-only only for local
# contract-flow rehearsal; it can never satisfy the reliability gate.
V44_BOOTSTRAP_OBJECTIVE_MODE=reliability
V44_BOOTSTRAP_PUBLIC_SPECIFICATIONS_FILE=outputs/v44-bootstrap-specifications.mainnet-candidate-1.json
V44_BOOTSTRAP_PUBLIC_SPECIFICATIONS_SHA256=0000000000000000000000000000000000000000000000000000000000000000
V44_GENESIS_MODULE_HASH=0x0000000000000000000000000000000000000000000000000000000000000000
V44_GENESIS_MANIFEST_HASH=0x0000000000000000000000000000000000000000000000000000000000000000

# Coordinator-only Base Sepolia keys. Keep them in .env.local, never Git.
TESTNET_OPERATIONS_PRIVATE_KEY=0xREPLACE_LOCALLY
TESTNET_VALIDATOR_1_PRIVATE_KEY=0xREPLACE_LOCALLY
TESTNET_VALIDATOR_2_PRIVATE_KEY=0xREPLACE_LOCALLY
TESTNET_VALIDATOR_3_PRIVATE_KEY=0xREPLACE_LOCALLY

# Participant bridge options. Prefer a wallet file so each AI/device retains
# custody. The private key is never sent to the remote read-only MCP.
AGENTPOOL_V44_HOME=.agentpool-v44-testnet
# AGENTPOOL_V44_WALLET_FILE=C:\\absolute\\path\\base-sepolia-wallet.json
1 change: 1 addition & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
public/agentpool-v44-readonly-bundle.json text eol=lf
46 changes: 46 additions & 0 deletions .github/ISSUE_TEMPLATE/v44-mcp-compatibility.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
name: v4.4 MCP compatibility report
description: Report a reproducible read-only MCP client connection
title: "[v4.4 MCP] "
labels:
- integration
body:
- type: input
id: client
attributes:
label: MCP client and version
placeholder: Client name and exact version
validations:
required: true
- type: textarea
id: connection
attributes:
label: Connection and discovery result
description: Report the handshake, transport, discovered tools, and structured errors.
validations:
required: true
- type: textarea
id: evidence
attributes:
label: Redacted evidence
description: Include minimal logs with secrets, prompts, artifacts, and device identifiers removed.
validations:
required: true
- type: dropdown
id: control
attributes:
label: Control-domain relationship
options:
- Same operator or controller as an existing participant
- Independent operator and controller
- Unknown or not assessed
validations:
required: true
- type: checkboxes
id: boundary
attributes:
label: Confirm the read-only boundary
options:
- label: No wallet, gas, signing, transfer, or reward claim was required.
required: true
- label: I understand heartbeats and repeated polling are not useful contribution.
required: true
60 changes: 60 additions & 0 deletions .github/ISSUE_TEMPLATE/v44-readonly-observation.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
name: v4.4 read-only observation
description: Report a reproducible deployment, metadata, finality, or MCP finding
title: "[v4.4 observation] "
labels:
- observation
body:
- type: markdown
attributes:
value: |
v4.4 is read-only and currently pays 0 tAPOOL. Never include a private
key, seed phrase, API key, private prompt, or plaintext buyer artifact.
- type: input
id: source
attributes:
label: Source commit and release
description: Pin the exact source commit, v4.4 release, and network.
placeholder: commit SHA; v4.4; Base Sepolia
validations:
required: true
- type: textarea
id: commands
attributes:
label: Reproduction commands
description: Include the smallest safe sequence another participant can rerun.
render: shell
validations:
required: true
- type: textarea
id: expected
attributes:
label: Expected result
validations:
required: true
- type: textarea
id: actual
attributes:
label: Actual result and hashes
description: Redact secrets and include block numbers or content hashes where relevant.
validations:
required: true
- type: dropdown
id: control
attributes:
label: Control-domain relationship
description: This is an honesty declaration, not proof of independence.
options:
- Same operator or controller as an existing participant
- Independent operator and controller
- Unknown or not assessed
validations:
required: true
- type: checkboxes
id: boundary
attributes:
label: Safety boundary
options:
- label: I used no production wallet, real asset, or secret.
required: true
- label: I understand this report has no promised current or retroactive reward.
required: true
62 changes: 62 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,12 +13,74 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
# Reliability tests reproduce the historical Base Sepolia contract
# source commit independently from the current evidence-pipeline HEAD.
- uses: actions/checkout@v5
with:
fetch-depth: 0
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || github.sha }}
- name: Verify exact requested source head
shell: bash
run: |
expected="${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || github.sha }}"
test "$(git rev-parse HEAD)" = "$expected"
- uses: actions/setup-node@v5
with:
node-version: "22.13.0"
cache: npm
- run: npm ci
- run: npm audit --audit-level=moderate
- run: npm run contracts:compile
- run: npm run evidence:v4.4:source
- run: npm run evidence:v4.4:source:verify
- run: npm run contracts:rehearse:v4.3:public
- run: npm run contracts:rehearse:v4.3.9
- run: npm run contracts:rehearse:v4.4:mainnet
- run: npm run contracts:rehearse:v4.4:full
- run: npm run build
- run: npm test

security-static:
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v5
with:
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || github.sha }}
- name: Verify exact requested source head
shell: bash
run: |
expected="${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || github.sha }}"
test "$(git rev-parse HEAD)" = "$expected"
- uses: actions/setup-node@v5
with:
node-version: "22.13.0"
cache: npm
- uses: actions/setup-python@v6
with:
python-version: "3.12"
- run: npm ci
- run: npm run contracts:compile
- run: python -m pip install slither-analyzer==0.11.6
- run: solc-select install 0.8.36
- run: solc-select use 0.8.36
- run: npm run security:slither:v4.4

installer-windows:
runs-on: windows-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v5
with:
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || github.sha }}
- name: Verify exact requested source head
shell: bash
run: |
expected="${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || github.sha }}"
test "$(git rev-parse HEAD)" = "$expected"
- uses: actions/setup-node@v5
with:
node-version: "22.13.0"
cache: npm
- run: npm ci
- run: npm run test:installer:windows
11 changes: 11 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,15 @@ yarn-error.log*
.env*
!.env.example
!.env.wallets.example
!.env.v44.mainnet.example
!.env.v44.testnet.example
/.mainnet-v44-gates.local.json
/.mainnet-v44-bootstrap-objectives.local.json
/.testnet-v44-bootstrap-objectives.local.json
/.testnet-v44-*.local.json
/deployments/8453.v44.partial.json
/deployments/84532.v44.partial.json
/deployments/84532.v44.*.partial.json

# vercel
.vercel
Expand All @@ -43,3 +52,5 @@ next-env.d.ts
/.wrangler/
/outputs/
/work/
/lib/v44-build-manifest.generated.ts
/public/agentpool-v44-build-manifest.json
Loading