CMI v0.10.0
This release candidate contains the reviewed Phase 1–3 work after v0.9.2. It is prepared for release review; publication remains separately authorized.
Added
- Added bounded portable project-evidence bundles with deterministic manifests, SHA-256 artifact verification, path-independent identity, exact/relocated/Git-checkout/content-only compatibility outcomes, explicit restore and rebind operations, destination-conflict protection, and recorded rebind provenance.
- Added executable provenance for the actual runtime/script, package root and version, source-checkout revision and cleanliness where available, install kind, observable candidates, and genuine multi-install ambiguity, with CLI/MCP parity.
- Added actionable uninitialized-project recovery and configuration/evidence health diagnostics across status, doctor, search/context, prepare, and impact; human and JSON trust-critical outcomes now share blocked semantics.
- Added persistence compatibility evidence for the audited
v0.5.0config/memory/index/graph floor,v0.7.0changes,v0.8.0sessions,v0.9.0findings, andv0.9.1evaluations, including no-rewrite checks and the exact boundedv0.8.0fallback exception. - Added fail-closed handling for future or corrupt durable/config/generated formats, preserving bytes and refusing ordinary downgrade or overwrite paths.
- Added regression coverage for portable evidence, executable provenance, operational diagnostics, MCP gating, persistence compatibility, future-format protection, and adversarial filesystem cases.
- Added maintainer/evaluator-side empirical study ledger and harness support for reproducible paired plain-vs-CMI study bookkeeping. The harness is not an agent-facing CMI command and does not establish productivity, time-savings, or general product-value evidence.
Changed
- Repository-baseline summaries now omit only untracked local
.codex-memory/state; tracked, staged, renamed, and ordinary project changes remain visible. - Portable evidence now binds the bounded scan, ignore, resolver, and workspace inputs needed to reproduce source boundaries after relocation.
- Durable compatibility is read-only/no-rewrite for the audited historical floor; generated state may be rebuilt only when its format is obsolete and supported, while unsupported state remains blocked.
- The release candidate keeps MCP mutation tools hidden or rejected by default; explicit write mode is required for portable-evidence and durable mutations.
Compatibility
- The audited historical floor is bounded and representative, not a promise to support every pre-v1 commit or every future schema. No explicit migration command is required for the audited fixtures.
- Future memory metadata, configuration, graph, and index formats fail closed without ordinary scan/refresh mutation or byte overwrite.
Evidence limits
- Static parsing and impact output remain heuristic/advisory rather than compiler-grade or complete runtime analysis.
- Portable bundles provide integrity checking, not authentication, backup authenticity, or source-authorship proof.
- Executable provenance reports observable runtime/install evidence; it does not prove source authorship and preserves ambiguity when multiple installs are visible.
- Evaluation and empirical records remain observational/caller-attested where documented. This release does not independently prove productivity, time savings, or general product value.
- Study 001 remains incomplete and Study 003 remains unreconciled; no new empirical study was run. This release does not claim v1 readiness.