Skip to content

Releases: amanayayatu-tech/loop-skill

LoopSkill v5.0.0

Choose a tag to compare

@amanayayatu-tech amanayayatu-tech released this 04 Aug 05:04
6e5cee7

LoopSkill v5.0.0 release notes

Publication is established only by the public annotated v5.0.0 tag, its peeled merged-main commit, green main/tag CI, the matching latest non-prerelease GitHub Release, and final public readback. This file or a branch alone is not a release claim.

What is new

  • A natural-language Codex Skill that prepares long local, single-user tasks before one explicit START.
  • Proactive investigation and concrete recommendations that extend the unattended span.
  • A 12-item human Launch Contract covering the real result, authority, acceptance, recovery, business Gates, emergency stops, timing, and external effects.
  • Host-native task/thread continuation and bounded heartbeat reentry for natural waits, with one minimal effect fact rather than a LoopSkill-owned control plane.
  • Business-first reporting that distinguishes artifacts, test results, fixture approvals, Owner decisions, and public publication.

Distribution identity

The v5 product consists of exactly:

  • loopskill5/SKILL.md
  • loopskill5/agents/openai.yaml

Install those files with the system Codex Skill Installer from the exact loopskill5 path at tag v5.0.0. The installer refuses to overwrite an existing install. Uninstallation moves only the exact loopskill5 directory recoverably outside skills.

The root VERSION=4.2.0, scripts/install.sh, loopskill4, old tags/Releases, and old data remain the independent v4 runtime identity. v5 does not import, migrate, repair, revive, or dual-write v3/v4 data.

Deliberate non-features

v5.0.0 does not add a LoopSkill-owned Controller, state machine, schema, database, daemon, queue, router, general Host adapter, general retry system, compatibility layer, or migration path. Development-only test harnesses are not release artifacts.

Claim limits

  • Local, single-user Codex Host is the first-release surface.
  • The verified release claim is limited to a scheduled exit in the same Codex task, at least two Host-native same-thread reentries, and safe continuation in each formal pre-merge and merged-main journey of at least 60 minutes.
  • Before START, the bounded or automatically expiring heartbeat must be persisted and read back with enough recurrence capacity for the eligible reentries, final readback, and measured scheduling jitter. Terminal acceptance requires accurate business facts, no repeated effect, next_run_at=NULL, and observation past expiry with no future delivery; physical identity deletion is best-effort housekeeping rather than a business PASS Gate.
  • Multiday endurance remains post-release validation and is not claimed by v5.0.0.
  • Sleep and operating-system shutdown recovery are not promised.
  • Fixture approvals do not represent Owner endorsement of public content.
  • No cross-system exactly-once, multi-host, arbitrary task-crash recovery, provider-wide publication, or automatic secret/permission expansion is claimed.
  • Private run paths, task/thread/session identities, raw transcripts, secrets, and private evidence are not release artifacts.

LoopSkill v4.2.0

Choose a tag to compare

@amanayayatu-tech amanayayatu-tech released this 02 Aug 00:54
476f6ba

LoopSkill 4.2.0 release notes

Status: publication is established only by the public v4.2.0 tag and GitHub
Release readback.

LoopSkill 4.2.0 turns the v4.1 bounded single-Attempt path into a recoverable
long-horizon Build Loop while retaining the explicit
INTAKE → PREPARE → CONFIRM → START boundary and v4-only hard break.

What changed

  • PlanDocument and PlanIndex v2 declare requirements, worker profile,
    capabilities, independent verifiers, human/time gates, optional Goals,
    failure policy, replay safety, recovery policy, and at most three Attempts.
  • loopskill4 list, status --loop, run, continue, pause, and the
    WAITING_BUDGET-only budget-extend make
    multiple per-Loop Stores discoverable without creating a second state writer.
  • A foreground run continues across Goals until completion or an actual human,
    time, budget, repeated-failure, or unsafe-replay waiting boundary.
  • Attempt timeout configuration has one source and permits 1–30000 seconds.
    Plan v2 sessions are non-ephemeral; owner-only evidence binds input, PID,
    session, JSONL, result controls, elapsed time, and terminal result.
  • A restart reads back a completed Attempt. An interrupted replay-safe session
    may consume one recorded codex exec resume; a live process is never resent.
    PID plus process-start identity prevents PID reuse from impersonating it, and
    the macOS token is locale/timezone independent. Initial and resumed deadlines
    survive controller restart, and interrupted resume compute remains charged.
  • Independent verification now supports exact argv commands, loopback HTTP
    routes, file existence/change/SHA-256, human approval, real-time gates, and
    optional capability skip-with-evidence.
  • Repairable failures stay in the same Loop. Attempt counts and repeated
    failure fingerprints are scoped per Goal; a repeated fingerprint waits with
    a concrete recovery action instead of terminalizing the PRD.
  • Plan v2 supports 1–128 Goals and a 512 KiB canonical Plan while sending only
    the current Goal and referenced requirements to Host.
  • Receipt-valid v4.1.1 installs upgrade transactionally to v4.2.0. The installer
    preserves config, Store data, old receipts, and exact rollback bytes until
    the new active pointer commits.
  • Public discovery and status projections open Stores read-only. Human and time
    waits require an exact Goal-bound gate digest; generic resume cannot bypass
    those gates.
  • Command verifier output is bounded while being read. Loopback HTTP verification
    rejects a preoccupied port, disables ambient proxies, and cannot block on an
    undrained server-output pipe.

Safety boundary

LoopSkill still does not register MCP, does not require an App restart, does
not require a Codex App restart, and does not import v3
state, expose credential values, or authorize automatic publication. Remote
cross-system actions are not claimed exactly-once. Unknown external outcomes
remain visible and are never converted into success. This release does not
support multiple Hosts.

The Codex Host subprocess receives only the minimal runtime environment needed
to locate its executable, configured Codex home, user home, locale, timezone,
and temporary directory. Ambient project variables and credential values are
not inherited.

The independent v3 fallback remains
v3.3.8.

The release Gate includes Linux/macOS × Python 3.11–3.14, coverage at least
80%, real v4.1.1 upgrade and rollback boundaries, long-horizon state-machine
regressions, three disposable canary layers, and exact merged-SHA/tag/release
readback. These checks prove the bound scenarios; they do not prove arbitrary
patch-success, long-horizon superiority, or a fault-free Host.

LoopSkill 4.1.1

Choose a tag to compare

@amanayayatu-tech amanayayatu-tech released this 31 Jul 17:04
2d031d4

LoopSkill 4.1.1 release notes

Status: LoopSkill 4.1.1 is the current public v4 release.

LoopSkill 4.1 helps turn work that can outlive one chat into a bounded process:
state the goal, inspect the scope, confirm once, and check the result against
machine evidence. The visible flow remains
INTAKE → PREPARE → CONFIRM → START; it does not silently start a Host task.

Patch fix

  • When the current working directory carries a v3 .codex-loop marker, v4.1.1
    stops before PREPARE, START, or status --refresh. It creates no prepared
    artifacts, Store, or Host task, and returns the existing
    USER_UNSUPPORTED_LEGACY_VERSION boundary.

User-visible changes

  • Start from one sentence, pasted PRD text, or one explicitly authorized UTF-8
    text/Markdown file. Ordinary users do not write JSON.
  • Conversational intake retains confirmed answers for the current session and
    asks at most three questions that truly block preparation.
  • PREPARE shows the confirmed boundary, plan summary, and capacity report.
    START THIS LOOP remains an exact, independent user confirmation.
  • One confirmed plan may contain 1–32 Goals. Only the current Goal is activated;
    subsequent Goals reuse the existing atomic AdvanceGoal transition.

Capacity and compatibility

  • Canonical PlanDocument: at most 128 KiB.
  • Explicit UTF-8 text/Markdown source: at most 256 KiB.
  • CreateLoop release target: 8 KiB / 64 members; hard limit remains 16 KiB /
    128 members.
  • Materialized Host prompt target: 24 KiB; hard limit remains 32 KiB. Overflow
    is rejected before Host execution and is never truncated.
  • New Loops use CONTENT_ADDRESSED_V1. Existing EAGER_V4_0 stores support
    status, export, and original-reducer continuation only. There is no migration,
    rewrite, or dual write.
  • LoopSkill 4 is a v4-only hard break. It does not open, import, repair, or
    automatically migrate v3 data. Users who need the historical v3 line can use
    LoopSkill v3.3.8.

Safety boundary

LoopSkill still uses one canonical Store writer, at-most-one automatic Attempt
per activation, bounded foreground Codex execution, and honest UNKNOWN /
UNVERIFIABLE outcomes. It does not register MCP, edit Codex configuration,
require an App restart, start a daemon, restore v3 runtime, promise cross-system
exactly-once, support multiple Hosts, or claim patch-success or proven
long-horizon superiority.

The original v4.1.0 release used deterministic matrices plus fresh 2-Goal and
8-Goal real Host canaries. For this scoped v4.1.1 boundary hotfix, the author
explicitly replaced a new Host canary with the direct v3-cwd zero-write
regression, the complete deterministic suite, isolated distribution tests, and
exact-SHA pull-request/main/tag CI. A superseded candidate's two semantic Goals
passed before its shared Host config integrity check failed; that failure is
preserved, is not a v4.1.1 release receipt, and no fresh Host canary is claimed.

LoopSkill 4.1.0

Choose a tag to compare

@amanayayatu-tech amanayayatu-tech released this 31 Jul 07:35
81d4f35

LoopSkill 4.1.0 release notes

Status: LoopSkill 4.1.0 is the current public v4 release.

LoopSkill 4.1 helps turn work that can outlive one chat into a bounded process:
state the goal, inspect the scope, confirm once, and check the result against
machine evidence. The visible flow remains
INTAKE → PREPARE → CONFIRM → START; it does not silently start a Host task.

User-visible changes

  • Start from one sentence, pasted PRD text, or one explicitly authorized UTF-8
    text/Markdown file. Ordinary users do not write JSON.
  • Conversational intake retains confirmed answers for the current session and
    asks at most three questions that truly block preparation.
  • PREPARE shows the confirmed boundary, plan summary, and capacity report.
    START THIS LOOP remains an exact, independent user confirmation.
  • One confirmed plan may contain 1–32 Goals. Only the current Goal is activated;
    subsequent Goals reuse the existing atomic AdvanceGoal transition.

Capacity and compatibility

  • Canonical PlanDocument: at most 128 KiB.
  • Explicit UTF-8 text/Markdown source: at most 256 KiB.
  • CreateLoop release target: 8 KiB / 64 members; hard limit remains 16 KiB /
    128 members.
  • Materialized Host prompt target: 24 KiB; hard limit remains 32 KiB. Overflow
    is rejected before Host execution and is never truncated.
  • New Loops use CONTENT_ADDRESSED_V1. Existing EAGER_V4_0 stores support
    status, export, and original-reducer continuation only. There is no migration,
    rewrite, or dual write.
  • LoopSkill 4 is a v4-only hard break. It does not open, import, repair, or
    automatically migrate v3 data. Users who need the historical v3 line can use
    LoopSkill v3.3.8.

Safety boundary

LoopSkill still uses one canonical Store writer, at-most-one automatic Attempt
per activation, bounded foreground Codex execution, and honest UNKNOWN /
UNVERIFIABLE outcomes. It does not register MCP, edit Codex configuration,
require an App restart, start a daemon, restore v3 runtime, promise cross-system
exactly-once, support multiple Hosts, or claim patch-success or proven
long-horizon superiority.

Release validation used deterministic matrices plus a fresh 2-Goal and, only
after it passed, a fresh 8-Goal real Host canary on the same exact clean
candidate. Those 10 invocations are product validation, not research evidence.

LoopSkill 4.0.0

Choose a tag to compare

@amanayayatu-tech amanayayatu-tech released this 28 Jul 10:09
f7b62cb

LoopSkill 4.0.0 release notes

These are the release notes for LoopSkill 4.0.0. Public-release identity is
established only after exact-SHA local gates, v4 PR/main/tag CI, annotated tag
v4.0.0, and GitHub Release readback all pass.

LoopSkill 4 is a v4-only breaking release. It replaces the v3 protocol,
persistence model, control identity transport, Pack/MCP execution path, and
Codex boundary with a small deterministic Kernel, one typed wire authority,
one SQLite state authority, capability libraries, and one Codex Host Adapter.
The production Adapter now consumes one foreground official
codex exec --json --output-schema --output-last-message invocation instead of owning the experimental external
app-server thread/turn lifecycle.

User experience

  • One goal or goal file enters INTAKE → PREPARE → CONFIRM → START.
  • Confirmation remains a mandatory human authorization boundary before real
    external effects; “one entry” never means silent permission.
  • Users no longer copy thread/task/route/effect IDs, SHA values, receipts,
    Pack identity, Gateway schema, MCP/App enum, heartbeat, readback, or retry
    parameters.
  • Normal status shows objective, progress, result, limitations, and next
    action. Internal identities appear only in diagnostics.
  • UNKNOWN and UNVERIFIABLE are visible honest outcomes and never cause a
    blind automatic resend.
  • Standard and Adaptive remain optional policy; a minimal task needs no policy
    pack.

Hard break from v3

LoopSkill 4 cannot open, import, repair, run, or automatically migrate v3
loops, Controller Packs, state, MCP data, or old CLI surfaces. It performs zero
writes and returns USER_UNSUPPORTED_LEGACY_VERSION. LoopSkill
v3.3.8
remains independently available and unchanged.

The LoopSkill 4 installer and uninstaller do not register MCP, edit Codex
config.toml, or require a Codex App restart. During the first real invocation
in a fresh workspace, the official Codex Host may append one exact workspace
trust record with trust_level = "trusted"; this Host-owned effect is measured
separately and is not attributed to installation. LoopSkill installs under a
distinct v4 identity and does not overwrite an existing v3 installation.

Safety preserved and redesigned

  • per-loop CAS, local operation idempotency, one writer, durable outbox, exact
    Attempt identity, honest lost-evidence classification, and no blind resend;
  • machine-owned Actor/Grant/handle/version/receipt/digest/Host identity;
  • immutable content digests, path confinement, existing-Git/non-Git/new-Git
    capture, exact artifact/report/review/finalization bindings;
  • bounded repair, immutable terminal evidence, honest limitations, and
    successor history that cannot rewrite its predecessor;
  • rebuildable audit/archive/privacy/metrics projections that never become a
    second state authority.
  • one bounded foreground Codex process group, strict lifecycle-only JSONL validation,
    a typed-manifest-derived closed outcome/summary schema, one official
    output-last-message result file with no agent-message/prose-marker fallback,
    same-process result/schema digest binding, bounded diagnostic stderr, and UNKNOWN without
    resend when process, stream, schema, or terminal evidence is lost.

Honest claim boundary

4.0 supports only the Codex Host Adapter. A host-neutral Kernel is not a
multi-host claim. The release does not promise cross-system exactly-once,
empirical patch-success superiority, long-horizon efficacy, or Host memory
isolation beyond what the Host can actually attest.
It does not promise Desktop-visible saved projects/tasks, provider
idempotency, cross-process lifecycle readback, or automatic exec resume.

No binary asset is required for installation. Reproducible source from the
annotated tag is the release artifact unless the final release packet lists a
reviewed additional asset with SHA-256.

LoopSkill v3.3.12 paper treatment source snapshot

Choose a tag to compare

LoopSkill v3.3.12 paper treatment source snapshot

Tag: paper-treatment-v3.3.12

Exact commit: 54442e22c3ce483823c911dfa8d03a52c85922e6

This archival prerelease preserves the exact source snapshot used as the
LoopSkill B3 treatment in the paper evaluation. The experiment froze this
source locally before public archival; this release was created afterward and
does not imply that a public release existed during execution.

Identity boundary

  • The tag must point permanently to the exact commit above.
  • The source must not be modified to satisfy later CI or release conventions.
  • This is not the latest stable product release and must not be marked latest.
  • A later maintained product release must use a different version and commit.
  • The archive is MIT licensed under the repository's existing license.

Informational local validation

  • skill validator: PASS;
  • recovery registry check: PASS, 727 entries;
  • focused protocol/release regression suite: 107 tests PASS;
  • source worktree remained clean at the exact commit.

These checks document the snapshot. They do not redefine the evaluated
treatment, and CI status must not move or replace the tag.

LoopSkill v3.3.8

Choose a tag to compare

@amanayayatu-tech amanayayatu-tech released this 22 Jul 23:43

v3.3.8

This patch fixes the Adaptive schema-v3 Gateway Controller Pack heartbeat renderer so generated Packs contain one concrete, digest-addressed heartbeat prompt body, and generation/check-only/skill validation reject missing or mismatched bodies. Legacy State-Writer Pack bytes remain unchanged.

Local evidence completed

  • Exact commit: 843945d9d34e7f065b65d9172ea4a2df66c0f2e3
  • Full local suite: 795 tests PASS
  • Generator fuzz: 5,000 cases PASS
  • State fuzz: 5,000 cases PASS
  • Canonical branch coverage: 770 tests, 80.380090% PASS
  • Isolated installation, managed rollback contracts, install-manifest validation, MCP registration readback, source/install zero drift, secret/risky-artifact scan, and independent code review: PASS

Explicit expedited-release waiver

The complete four-fixture pre-release App candidate canary did not PASS and was explicitly waived by the user because of time constraints. This waiver is authorization to publish; it is not a canary PASS, FINALIZATION_ACKED receipt, normal release-acceptance proof, product-effect evidence, or scientific evidence. Existing candidate canary FAIL/BLOCKED receipts, roots, tasks, and logs are preserved without deletion or relabeling.

GitHub Compatibility CI continues after publication. CI is compatibility evidence only and is not local release acceptance. A CI failure must block subsequent experimental execution until resolved.

This Release is not the LoopSkill paper experiment, long-run acceptance, a 90-cell pilot result, or a scientific validity/effectiveness conclusion. Experimental activation canary, R5, serial six-run shakedown, independent review, and the conditional 90-cell pilot remain separate mandatory gates.

LoopSkill v3.3.7 — Trustworthy long loops with explicit graph semantics

Choose a tag to compare

@amanayayatu-tech amanayayatu-tech released this 22 Jul 07:20
c12e761

Summary

LoopSkill v3.3.7 consolidates the P0-P2 improvements completed after v3.3.3. No v3.3.4, v3.3.5, or v3.3.6 tag or GitHub Release was published.

LoopSkill remains a governed, evidence-bound execution and completion control plane with explicit state-machine and graph semantics. It is not a general-purpose Graph workflow engine, arbitrary DAG scheduler, LangGraph replacement, or Temporal replacement.

P0: trustworthy long-running Loops

  • startup doctor, manifest compiler, and disposable canary gate
  • complete recovery registry and hash-chained rejection journal
  • opt-in strict model/reasoning identity with fail-closed host boundaries
  • Git closeout saga, generic policy migration, completion classes, and host lifecycle readback

P1: efficiency and governance

  • defect-family routes, Reviewer sibling disclosure, and third-return escalation
  • recoverable route orchestration, heartbeat registry, and Supervisor capability envelopes
  • metrics with explicit UNMETERED values and privacy-safe aggregate export
  • complete Goal-registry startup rules and machine-checked recovery coverage

P2: operability and historical governance

  • SHA-256 content-addressed projection, report, and staging storage
  • audit index, per-Goal summaries, business timeline, and business/control-plane accounting
  • recovery-derived next-operation templates and privacy-aware risky-artifact scanning
  • consistent CLI envelopes, active/history separation, archive-manifest-v2, CI telemetry, and shadow replay

Loop, state-machine, and Graph semantics

The bilingual README now explains the mapping between Goal registries, typed runtime operations, guards, leases, outboxes, reports, recovery edges, and explicit finalization. It also distinguishes the Adaptive schema-v3 MCP State Gateway from the constrained single-State-Writer path retained by Standard and legacy Adaptive Packs. Derived Markdown views remain observation surfaces, never a second canonical authority.

Evidence boundary

P0 includes a real disposable Codex App canary that reached canonical FINALIZATION_ACKED. P1 and P2 are supported by repository tests, isolated installation evidence, and GitHub Compatibility CI; these are not presented as one combined App canary. The release candidate passed four canonical shards, all-shipped branch coverage, both 5000-case fuzz lanes, Linux/macOS isolated installation, protected-main CI, exact tag identity, and the tag Final gate.

This release adds no new App restart requirement. Exact model/reasoning identity remains opt-in; default Loops use UNSPECIFIED / NOT_APPLICABLE without implying verification.

LoopSkill v3.3.3

Choose a tag to compare

@amanayayatu-tech amanayayatu-tech released this 19 Jul 06:51
4a46ae9

LoopSkill v3.3.3

This patch release adds schema-v3 Decision Gateway operations for registering a bounded user decision and recording the user's explicit response. Decision responses are normalized and hashed at the MCP boundary, bound to the current Controller turn and exact goal/dispatch/artifact/surface context, and fail closed on stale or mismatched identity. Explicit loopback preview URLs may differ only by port when scheme, host, and path remain identical.

It also makes canonical coverage runs remove stale generated coverage artifacts before measurement, preventing local result inflation.

Release evidence

  • Protected-main exact SHA and annotated tag target: 4a46ae95120dad44a1b2e10f42da4293fbaf4c08
  • Same-SHA macOS install receipt: LoopSkill 3.3.3, zero source/install drift, MCP configuration readback successful
  • Frozen local gate: 657 tests PASS; branch coverage 80.324457%; generator fuzz 5,000 PASS; state fuzz 5,000 PASS; Skill/SPEC/schema/installer/risk/secret checks PASS
  • Independent Reviewer: P0/P1/P2 = 0/0/0
  • Compatibility CI on the exact candidate tree: 632 canonical tests PASS; branch coverage 80.091827%; both 5,000-case fuzz lanes PASS; Linux/macOS install and Final gate PASS
  • Real authorized Life Blueprint path on the exact installed build: bounded visual decision REGISTERED and APPLIED, FINAL_AUDIT PASS, heartbeat PAUSED with readback, and canonical FINALIZATION_ACKED / LOOP_COMPLETE

Evidence boundary

Disposable decision fixtures A and B remain individually recorded as FAIL because of harness input errors (Controller attestation mismatch and logical-time regression). Both were rejected with zero canonical side effects. They are preserved as fail-closed negative evidence and are not described as passing canaries. The required positive capability evidence comes from the authorized exact-main Life Blueprint execution above.

The Life Blueprint product remained local-only: no product commit, push, pull request, merge, deployment, or external write was performed.

LoopSkill v3.3.2

Choose a tag to compare

@amanayayatu-tech amanayayatu-tech released this 18 Jul 19:22
7749b29

LoopSkill v3.3.2

This patch closes the schema-v3 transport-recovery dead end discovered while resuming a real long-running successor.

What changed

  • Adds the State Gateway operation ACK_TRANSPORT_RECOVERY.
  • Requires a real host-cooperative heartbeat ACTIVE update and readback before routing can resume.
  • Resumes only after the retained route/outbox has already been ACKed or recovered with a durable formal report.
  • Restores transport_recovery.status=HEALTHY and run_control.status=RUNNING atomically.
  • Preserves the historical failure count and does not create a product dispatch, repair attempt, PASS projection, or terminal projection.
  • Rejects unresolved, mismatched, and replayed acknowledgements with zero canonical side effects.
  • Adds post-state reconciliation guidance so an ambiguous response cannot incorrectly pause an already recovered loop.
  • Updates README, English README, SPEC, ADR, invariants, scaffold, examples, and App canary receipt schema v6.

Release authority and evidence

  • Protected main / tag target: 7749b292e421d291c3a7c96f39b7ee5d3dd62520
  • Tree: 6d29c7741e0db80d5e106d8f2b2f10a31ab73830
  • Independent Reviewer: P0/P1/P2 = 0/0/0
  • Full unittest: 655 PASS
  • Branch coverage: 80.12% (threshold unchanged at 80%)
  • Generator fuzz: 5,000 PASS
  • State fuzz: 5,000 PASS
  • Skill/SPEC/public schema/installer/rollback/config-readback/source-install-zero-drift/risk/secret checks: PASS
  • Exact-main macOS installation receipt: /Users/peachy/.codex/install-receipts/codex-loop-prompt-architect/20260719031640-51856.json
  • Installed version: 3.3.2; exact repo commit readback; source/install drift empty; MCP config readback true
  • Exact-main real Codex App transport-recovery canary: PASS on the real schema-v3 successor. The existing heartbeat was updated and read back as ACTIVE; ACK_TRANSPORT_RECOVERY advanced canonical v10 to v11 with transport_recovery.status=HEALTHY, run_control.status=RUNNING, and heartbeat ACTIVE. Historical failure_count=2 was preserved. Product dispatch count and G06 attempt count did not increase, and the retained recovered outbox remained the authority.

GitHub Compatibility CI is a compatibility mirror for this release and is not the formal release authority. The release authority is the exact-main local gate, independent review, same-SHA installation readback, and real Codex App recovery canary. This note does not claim a CI conclusion that was not used as the release gate.

Known boundary

The public MCP parameters field remains a generic object instead of a per-operation strict oneOf. The exact public field set is documented and tested; improving schema ergonomics remains follow-up work and does not weaken the state-transition checks in this patch.