LoopSkill v3.3.7 — Trustworthy long loops with explicit graph semantics
Summary
LoopSkill v3.3.7 consolidates the P0-P2 improvements completed after v3.3.3. No v3.3.4, v3.3.5, or v3.3.6 tag or GitHub Release was published.
LoopSkill remains a governed, evidence-bound execution and completion control plane with explicit state-machine and graph semantics. It is not a general-purpose Graph workflow engine, arbitrary DAG scheduler, LangGraph replacement, or Temporal replacement.
P0: trustworthy long-running Loops
- startup doctor, manifest compiler, and disposable canary gate
- complete recovery registry and hash-chained rejection journal
- opt-in strict model/reasoning identity with fail-closed host boundaries
- Git closeout saga, generic policy migration, completion classes, and host lifecycle readback
P1: efficiency and governance
- defect-family routes, Reviewer sibling disclosure, and third-return escalation
- recoverable route orchestration, heartbeat registry, and Supervisor capability envelopes
- metrics with explicit
UNMETEREDvalues and privacy-safe aggregate export - complete Goal-registry startup rules and machine-checked recovery coverage
P2: operability and historical governance
- SHA-256 content-addressed projection, report, and staging storage
- audit index, per-Goal summaries, business timeline, and business/control-plane accounting
- recovery-derived next-operation templates and privacy-aware risky-artifact scanning
- consistent CLI envelopes, active/history separation,
archive-manifest-v2, CI telemetry, and shadow replay
Loop, state-machine, and Graph semantics
The bilingual README now explains the mapping between Goal registries, typed runtime operations, guards, leases, outboxes, reports, recovery edges, and explicit finalization. It also distinguishes the Adaptive schema-v3 MCP State Gateway from the constrained single-State-Writer path retained by Standard and legacy Adaptive Packs. Derived Markdown views remain observation surfaces, never a second canonical authority.
Evidence boundary
P0 includes a real disposable Codex App canary that reached canonical FINALIZATION_ACKED. P1 and P2 are supported by repository tests, isolated installation evidence, and GitHub Compatibility CI; these are not presented as one combined App canary. The release candidate passed four canonical shards, all-shipped branch coverage, both 5000-case fuzz lanes, Linux/macOS isolated installation, protected-main CI, exact tag identity, and the tag Final gate.
This release adds no new App restart requirement. Exact model/reasoning identity remains opt-in; default Loops use UNSPECIFIED / NOT_APPLICABLE without implying verification.