Skip to content

Releases: lozknowles/agent-control

Agent Control 4.3.0

Choose a tag to compare

@lozknowles lozknowles released this 09 Sep 20:27
c389a7a

Agent Control 4.3.0 integrates the qualified Transport Context integrity boundary and Cache-Aware Expert Delegation with the complete 4.1 runtime.

Qualified product commit: 27bc4c5
Release commit: c389a7a
Evidence commit: 9038a6e

Fresh physical A-F qualification passed. Cold execution reused 0 and processed 1,328 prompt tokens; warm execution reused 1,327 and processed 1, with a measured 66.39x prompt-processing improvement. Governed warm-route selection, incompatible-context rejection, material invalidation, backend-restart isolation, and independent verification passed. Monetary saving is unavailable because the qualified local backend provides no authoritative billing data.

Final validation: TypeScript, bootstrap syntax, dashboard syntax, infrastructure neutrality, implementation status, and 1,119/1,119 tests passed.

Evidence hashes:

  • machine record: eff527f21b6a3a84ba18d44f6be74e24ae96841c3ee6891a63ec9cd923291d5d
  • report: 94adc82e33439e80b360acee3be0be841c36f5e6e11b623d4e34298f0e79d6e4
  • transcript: 5fe743c6d219d6dc543e87fa7123cce1104537d1a4e3e4f6116bf92988cf0897
  • dashboard screenshot: 92307b32f6cff5625c0b688b9ab0df33b5252a9bdc07774681c2674dc3860902
  • 1920x1080 recording: 321db46fe76ecfb0e781d9037e802bdd52ca354c343e8c86288e9fd3cca8931c

Reproduce validation:

  1. git clone https://github.com/lozknowles/agent-control.git
  2. git checkout --detach v4.3.0
  3. npm install
  4. npm run check

Upgrade and rollback: https://github.com/lozknowles/agent-control/blob/v4.3.0/docs/DEPLOYMENT.md
Release manifest: https://github.com/lozknowles/agent-control/blob/v4.3.0/docs/evidence/agent-control-4.3-release-manifest.json
Qualification: https://github.com/lozknowles/agent-control/blob/v4.3.0/docs/evidence/agent-control-4.3-integrated-qualification-20260909.md
Complete transcript: https://github.com/lozknowles/agent-control/blob/v4.3.0/docs/evidence/agent-control-4.3-integrated-transcript-20260909.md

Agent Control 4.1.0

Choose a tag to compare

@lozknowles lozknowles released this 09 Sep 05:26
3c906bd

Agent Control 4.1.0

The qualified product and edited 6:12 tour were accepted for release using the
existing evidence. Exact revisions, review methods and limitations are tracked
in the qualification record.

POE is a compact floating conversational operator and part-time tour guide. The
original moustached, waistcoated SVG companion speaks through the configured
original male OmniVoice voice and explains the dashboard feature currently
highlighted. Tour progression waits for actual browser audio to finish. Typing,
microphone input, full captions and speech interruption share the existing
authenticated conversation boundary.

Answers combine approved, versioned documentation with actual jobs, schedules,
model routes, Work Parcels and verification records. Explicit object links now
resolve the selected object. Unknown readiness, usage and cost stay unavailable.
The initial qualified route uses the existing Codex/ChatGPT integration with
gpt-5.6-luna; alternative routes remain subject to separate qualification.

POE can propose permitted jobs and frozen experiments, but execution requires
explicit approval of the sealed request through existing governance. Crew
handovers and receipts are narrated from real runtime events. Completion waits
for the relevant jobs and verification to reconcile. Speech interruption stops
playback and does not cancel executing jobs.

The final product checkpoint passed 1,083 tests with zero failures or skips,
isolated installation/authentication checks and responsive/reduced-motion checks.
Physical Windows evidence includes microphone input, real barge-in, a full spoken
tour and two explicitly approved read-only observation parcels with four verified
jobs and two sealed baton receipts. Exact commits, hashes, findings and limits
are preserved in the qualification record.

The public overview retains the redacted Windows dashboard footage and now uses revised narration in one consistent synthetic male voice, as requested after publication. The guide introduces himself once. Captions and the public transcript match the revised soundtrack; the original raw qualification and natural conversation remain private. This media revision does not change the product tag.

Installation and upgrade

Use the 4.1 installation/deployment runbook.
Keep configuration, state and credential references outside an immutable release
checkout. Back up mutable state with its controller stopped and preserve the
previous supervisor command before changing the scoped installation. No new
credential, public dashboard binding or automatic provider routing is required.

Limits

  • The selected voice adapter completes synthesis and validation before playback;
    it does not stream TTS. CPU speech preparation can be slow.
  • Read-only remote registry discovery does not grant remote execution authority.
  • The recorded Facebook discovery failure was a missing device transport; the
    tour did not publish Facebook events.
  • Crew characters present accountable runtime roles rather than additional model
    agents. The harmless observation job did not invoke a model.
  • Export privacy was reviewed across the full timeline using sampled frames;
    full human listening was not separately attested. The operator accepted the
    existing qualification evidence for release.
  • Configuration evidence for private tailnet access is distinct from an
    independent off-tailnet connectivity test.

See architecture, dashboard operation
and POE state/animation provenance.

Deployed product commit: 3c906bd3ec55b97815dd79cc79661bed4a255b33. The deployment verification records rollout, public playback, media hashes, navigation and retained limitations.

Agent Control 4.0.0

Choose a tag to compare

@lozknowles lozknowles released this 08 Sep 05:56

Agent Control 4.0.0

Agent Control 4.0.0 delivers the governed adaptive Crew lifecycle: authenticated work enters a canonical Work Parcel, capability and authority policy select the route and workflow, Crew/lane execution streams from canonical state, and retry or quality failure can produce a sealed-baton handoff followed by independent verification and durable evidence.

Highlights:

  • evidence-driven Model and Workflow Leagues with conservative sparse-evidence routing;
  • explicit retry → baton → governed fallback, preserving source recovery and route identity;
  • semantic protected-resource governance enforced before typed Git actions;
  • operational Crew roles and event-backed WOPR indicators across Jobs, Lanes, Models, tools, nodes, batons and verification;
  • governed Live Shell attachment to real owned sessions, with protected actions forced to WATCH_ONLY;
  • authenticated Pixel WhatsApp/OpenWA ingress through the normal adaptive Work Parcel path;
  • idempotent social decision repair across replay/restart boundaries;
  • complete human-readable transcripts and independent verification;
  • additive provider/account/model token accounting across handoffs.

Physical qualification proved a local-Qwen review, independent quality rejection, sealed baton, Codex/Controller Account A/Luna continuation, successful verification and terminal handset delivery. Usage reconciled exactly: 1,421 + 8,980 = 10,401 tokens. Current-context occupancy and monetary cost were unavailable on both routes and remain explicitly unavailable.

Release integrity:

  • release commit: ff7ed114c08b71583e2a2d67b40d081f0b0a4c33;
  • tested product checkpoint: a08ccac5ced3cd399755bd084ff30fe224ab7860;
  • evidence/tooling checkpoint: 8ad56c031b92454b6364f7b502159e69242921e7;
  • deterministic gate: 1,014/1,014 tests;
  • source package SHA-256: 27166bec036be1ce11889b02a62506803e628211fe5a065aacf201892008fa81;
  • accepted evidence archive SHA-256: 9be4555f7eb0465637239c6ace283055eee46fb08ffd94ad52dae5ee2c174647;
  • release manifest SHA-256: a11293c6c7ffc201c174c69cd0157bba01d9fef11b4761fc117ad3a734a3725e.

See release notes, qualification, Pixel continuation and migration guide.

No production deployment or automatic feature enablement is part of this release. OpenWA/Social & Voice remains a private pilot; NVIDIA routes remain disabled; unsupported provider cost/context telemetry remains unavailable rather than inferred.

Agent Control 3.9.0

Choose a tag to compare

@lozknowles lozknowles released this 05 Sep 14:07
4966c97

Agent Control 3.9.0

Agent Control 3.9.0 adds a qualified, cross-platform resilient execution lifecycle for governed Work Parcels.

Highlights

  • Persistent Work Parcel execution context with immutable goals, durable events, bounded baton views, and governed retrieval.
  • Resilient execution and recovery with controller-restart reconciliation that does not unsafely replay external work.
  • Bounded retry/backoff, cancellation, cleanup verification, and durable terminal-state handling.
  • Qualified Linux execution plus the tested production Windows cancellation and timeout path.
  • Qualified Android wireless-ADB lifecycle on the tested Pixel, including service-identity and intended-target verification, direct DNS-SD fallback, and bounded reconnect handling.
  • Dashboard and runtime resilience improvements with authoritative execution, recovery, and telemetry projections.
  • Sanitized artifact contracts for cross-node qualification and recovery evidence.
  • Independent cache outcome-quality verification across matched experiment arms.

Qualification boundary

  • Windows qualification applies to the tested production Windows execution path.
  • Android qualification applies to the tested Pixel wireless-ADB lifecycle. Other Android/ADB builds and unsupported execution or recovery substrates require their own qualification.
  • Cache outcome quality was demonstrated: both matched arms passed independent verification and scored 6/6.
  • No cache token, latency, or economic saving was demonstrated or claimed; the cache candidate used more tokens and took longer in the matched experiment.
  • Explicit Responses cache controls remain disabled and deferred.

Release integrity

  • Release commit: 4966c97505d05e5be3a2f8cae092113ad44d636e
  • Qualified candidate: 9e7696fd223a1eb80f5f83c94935b5b5ba8ef20e
  • Qualified package SHA-256: 51861afe80bdf2bd0ba1c184ca4eecde9b9d4f40b5e721ea07bf9e9ad0bf1d5d
  • Published package SHA-256: 4203e083d7c633f68febecdbc3d03470ac7517e6569ace8cfa7bdec2595ca3cb
  • Published package size: 20,536,323 bytes
  • Final validation: 829/829 tests; 3/3 neutrality checks; 45/45 implementation-status entries; 610 local Markdown links across 127 files.
  • Clean package installation reports agent-control 3.9.0; production dependency audit reports zero known vulnerabilities.

The published package differs from the qualified package in exactly three non-runtime files: two documentation examples now use the repository-supported no-lock install command, and one test supplies a fixed timestamp so its determinism assertion cannot race the wall clock. No runtime implementation file differs.

See the tracked Agent Control 3.9 qualification report. The attached evidence archive and manifest preserve the accepted sanitized cross-platform qualification set.

Install and verify

npm install --no-package-lock --ignore-scripts
npm run check
npm pack --dry-run
agent-control --version

No deployment is performed by this release publication.

Agent Control 3.8.2

Choose a tag to compare

@lozknowles lozknowles released this 04 Sep 21:47

Agent Control 3.8.2

Agent Control 3.8.2 aligns the repository-review provider-facing structured-output schema with the stricter application validation contract exposed by the 3.8.1 video qualification. The historical providers returned completed, transport-valid JSON; Agent Control then rejected values admitted by its looser wire schema. This release declares the same literals, enums, non-empty values, line constraints and confidence range at both boundaries while retaining independent fail-closed application validation.

New failures retain bounded safe constraint paths such as $.findings[0].category:enum. Rejected values and raw provider responses remain ephemeral and are not added to evidence merely for diagnostics.

The dashboard adds human-readable Execution history for Saved Job Runs and Lanes. This bounded redacted projection derives from existing durable Job Run, associated Work Parcel, token-governor, baton and verification records. It distinguishes operator, system, provider, tool/action, governor, baton and error activity and keeps current context separate from cumulative token/cost accounting with authoritative, estimated and unavailable labels. It is not a raw transcript store and does not expose hidden reasoning.

Handoff semantics remain evidence-based. A threshold can produce HANDOFF_RECOMMENDED without a transfer; baton creation is not destination acceptance or execution; only a durable successful BATON_AND_HANDOFF outcome is shown as completed. This release does not claim that its 3.8.2 physical qualification performed an actual baton transfer.

The HTTP redaction boundary now permits the safe numeric contextTokens and contextLimitTokens fields while continuing to redact credential-like token fields. Clean package installations can report their exact source release with agent-control --version without contacting a controller.

Physical qualification used the normal Controller Account A Saved Job path. Run a0d646b0-77ae-41b3-85ed-a02a86f4880e and Work Parcel parcel-bccb41f1-c1b1-4ff2-8f1d-b3d8c61c2c07 returned a schema-valid PASS, passed independent verification, exposed 21 correctly associated history entries and reconciled 13,092 input plus 194 output tokens to 13,286 total at calculated USD 0.026960.

Provenance and integrity

  • Release commit: b51623dae1b764a31198424e8fc6ea9076d04089
  • Qualified RC evidence checkpoint: fa112f3f9e470041d22a0e91b93543ba946cbd62
  • Qualified implementation commit: 9be253fb06f97ae0c010d2c26f0f74a263338ee4
  • Package SHA-256: d4c755aed3c73def1eb60275f58ae84b9ec26796e7bb744da4be901a74d362ef
  • Package SHA-512: 08c790a52791bd067756f09444599c61b09ab548d5a512f4a6bf516aa845f994f4d8d16b555ba8aba5a470b2b3eadf13a975ea070ed2281b0eb92fb5e8ab1395
  • History qualification video SHA-256: bb885f3b3a427c2ac49d50e7fd7143f6862a9987ccd4c44298da51d318421e2e
  • Candidate identity video SHA-256: e02fb8790242642b76597212e4db4c094d6b61ea0470bc3e3348d491936ed93a
  • Full release regression: 718/718 passed
  • Markdown links: 120 files, zero broken local links

Upgrade

git fetch --tags
git checkout v3.8.2
npm install --no-package-lock --ignore-scripts
npm run check
agent-control --version

Installing this source package starts no service, changes no live configuration, authenticates no provider and enables neither Spark nor a Saved Job. The immutable v3.8.1 tag remains the previous source rollback point; restore the operator's pre-upgrade state backup before running the older version.

Agent Control 3.8.1

Choose a tag to compare

@lozknowles lozknowles released this 04 Sep 10:47

Agent Control 3.8.1 separates workload locality, provider execution locality, and credential residency while preserving governed route, baton, telemetry, recovery, and ledger identity.

Highlights

  • Independently governed Codex account profiles with opaque credential references.
  • Physical Account A to sealed baton to Account B continuation and governed fallback qualification.
  • Immutable cross-node repository transfer and fixed-purpose Windows execution.
  • File-backed OpenRouter credential resolution without exposing resolved paths or provider bodies.
  • Repository-review retry and thread identity integrity across restart.
  • Complete non-ignored Git mutation containment for the opt-in Spark lane.
  • Owner-only foundational state and telemetry files, durable evidence sanitization, and reconciled dashboard telemetry.

Provenance

  • Release commit: 4da1d36
  • Annotated tag object: 91fa7b34bffd1d71144ab0cd8ceb62491556e575
  • Qualified implementation and evidence checkpoint: 93ce5ab
  • Reviewed implementation commit: 967181f
  • Metadata-only promotion commit: c695263

Qualification

  • Exact release commit: 711/711 complete deterministic tests passed.
  • Focused remediation set: 90/90 passed.
  • Production lifecycle: 9/9 passed.
  • State permissions: 3/3 passed.
  • TypeScript, bootstrap, dashboard syntax, neutrality, and 32 implementation-status claims passed.
  • 115 Markdown files and 452 repository-local links passed.
  • Evidence JSON parsing and git diff integrity passed.
  • Packed artifact installed successfully; installed package version is 3.8.1 and its CLI entrypoint executed.
  • Resolved production dependency audit: 0 known vulnerabilities.

Physical evidence

  • Final governed GLM run: run-1c151e3a-19ad-41e5-8f58-3075eb1460c1
  • Route: openrouter / z-ai/glm-5.3-flash
  • Usage: 847,422 input + 28,628 output = 876,050 total tokens; 23,130 reasoning tokens.
  • Calculated cost: USD 0.07071365.
  • Both independent verifier gates passed.
  • Final review: 0 Critical, 0 High, 1 Medium, 6 Low, 3 Informational.
  • Dashboard telemetry was reconciled programmatically. No interactive dashboard video exists or is claimed.

Artifact

  • File: agent-control-3.8.1.tgz
  • Size: 1,166,295 bytes
  • SHA-256: 792ccba24f146a430c262fecd211bd0a0e72d1aa987732a5372bb53f2016b76e
  • SHA-512: 6eb9000460e624381ed02f78b502c6d42fca5422a61afc41d229e62ee635bf731a175513927ba4a16d64155551e81b2b505cdb1cfdcfbcaabe9aa0c86ee45b72
  • npm integrity: sha512-brkABGDmJDge0C94tQLG1C/KVCKmGvxB0inmLuY1v3MaF1UTknukoW1kFVVR6BsrUFzbHP3PvKq+mqDIbuRbcg==

Accepted limitation
One Medium hardening item remains explicitly deferred: intentionally ignored and .git-internal Spark writes are outside the mutation ledger. Spark remains disabled by default, single-attempt, disposable-worktree-only, and independently verified. This release does not represent that limitation as fixed.

Upgrade

  1. git fetch --tags
  2. git checkout v3.8.1
  3. npm install --no-package-lock --ignore-scripts
  4. npm run check

This source release performs no live deployment, provider authentication, or service enablement.

Agent Control 3.8.0

Choose a tag to compare

@lozknowles lozknowles released this 03 Sep 19:09

Agent Control 3.8.0 — Governed Retrieval and Context Intelligence.

Release commit: 09ac94a
Accepted RC commit: 7534b6c
Final feature commit: b4b6047
Package: agent-control-3.8.0.tgz
Package SHA-256: d458a46dbe3268a69b30ed817ef4fd33635df0097c459022a423d19062f34a1f
Package SHA-512 integrity: sha512-o3sadkfxyxanRPk039KRlhEDK0Czt8WQId6JMv1eoV7/GYcVCNmTvd4H3maYkLyyHBcq1/fc1IUxgUKqOsGetQ==

Final release gates passed 690/690 tests, TypeScript, bootstrap and dashboard syntax, provider neutrality, implementation-status consistency, 416/416 documentation links, exact package install and CLI execution, and a resolved-artifact audit with zero vulnerabilities. The increase from the accepted RC count of 688 is exactly two fail-closed integrity tests added after final review found that persisted packet hashes were not recomputed and post-capture symlink replacement was not rejected.

The frozen Qwen2.5 Coder 3B mutation comparison independently verified 2/12 outcomes in every lane. Processed tokens per verified outcome were 95,101 conventional, 76,189 built-in, and 88,039.5 zg: reductions of 19.9% and 7.4%. This proves context efficiency, not an expanded model task class; all lanes still failed 10/12.

The physical Qwen2.5 Instruct to Qwen2.5 Coder lifecycle proved retrieval, sealed Evidence Packet references, destination rehydration, independent verification, restart recovery, stale-source invalidation and SSE reconciliation. Full baton storage was 2,297 bytes versus 1,327 bytes conventional and was not smaller. The measured saving is the 291-byte reference transfer and 690-byte destination rehydration path, a 78.1% reference-transfer reduction.

Both endpoints used the OpenAI-compatible adapter, so materially different adapter portability remains unqualified. Provider-unreported context occupancy, monetary cost and electricity cost remain estimated or unavailable. Retrieval is disabled by default, zg is optional, and index mutation retains separate authority.

Upgrade: git fetch --tags; git checkout v3.8.0; npm install --no-package-lock --ignore-scripts; npm run check. Installing source starts no service, changes no live configuration and enables no retrieval route. Full details are in docs/release-notes-3.8.0.md, docs/migration-3.8.md and docs/evidence/agent-control-3.8.0-release-qualification.md.

Agent Control 3.7.0

Choose a tag to compare

@lozknowles lozknowles released this 03 Sep 10:39

Agent Control 3.7.0 — Token-Aware Baton Routing with real-time dashboard telemetry.

Release commit: 41ae59c
Feature evidence commit: e7fe5c0
Package: agent-control-3.7.0.tgz
Package SHA-256: 7c2883902379b5b9bb70c08e05a16fb0af7e621d232d4210b31253d41ae61451
Package SHA-512 integrity: sha512-SZsdcM+cOvmM2vvVZCI7r30Gc3d8McP8dO2jmeZXODdjMUjgI0UuSl2SFWtHQ6KV+pp8TA9JC1R2+g7kvEY0IQ==

Physical lifecycle: source local-qwen-instruct/qwen-instruct-local produced 186 tokens; destination local-qwen-coder/qwen-coder-local continued from sealed baton fc0de100074b3b25c421f4b39b198df47f29eadb8fdc644b4423cb3230d0cb7d with 510 tokens; Work Parcel total reconciled to 696 tokens and independent verification passed. A separate destination-refusal run recovered the original source thread and passed verification without invented destination usage. Dashboard SSE reconciled with durable evidence.

Current-context occupancy is estimated for these ephemeral local provider calls; source and aggregate monetary cost remain unavailable. The proof does not claim a Codex or GLM workload leg and does not enable the separate automatic capability-routing benchmark.

Upgrade: git fetch --tags; git checkout v3.7.0; npm install --no-package-lock --ignore-scripts; npm run check. Installing source starts no service or automatic route. Recovery remains available through immutable v3.5.0 plus the operator state backup. Full reproduction, migration, security and evidence details are in docs/release-notes-3.7.0.md, docs/migration-3.7.md and docs/evidence/agent-control-3.7-physical-qualification-20260902.md.

Agent Control 3.5.0

Choose a tag to compare

@lozknowles lozknowles released this 01 Sep 20:26

Agent Control 3.5.0

Agent Control 3.5 adds durable identity, sessions and bounded delegation; governed ACP v1 session/control mapping; context-deterioration measurement; and a conservative, default-disabled Spark fast-execution class.

Provenance

  • Release commit: a12957e69d4db82fda751ffcf830333137f2cf87
  • Merge commit: 26d5c051e5341af2f00cb41211bfa1e1fca6c744
  • Qualified feature commit: 2aa19ce2a56ce7ded11d36b6cf96b02543e2ab17
  • Base release: v3.4.0 / 4b04f3942201d65748c6c68bf9669cdea1841d19
  • Package: agent-control-3.5.0.tgz
  • Package SHA-256: a678499fd6f02c86b696e4d914c35537581be3d051d31bb59272a5faa87e61dd

Qualification

Verdict: PASS_WITH_LIMITATIONS

  • Exact release commit: 587 tests passed, zero failed.
  • TypeScript, bootstrap syntax, dashboard syntax, infrastructure-neutrality and 23-entry implementation-status gates passed.
  • All 86 repository-local Markdown documents passed local-link validation.
  • Package dry run included 528 files; the actual tarball installed successfully and reported version 3.5.0.
  • npm reported zero known vulnerabilities; source/evidence secret and machine-path scans passed.
  • Spark classifier: 10/10, zero false positives and zero false negatives.
  • Spark: 7/7 independently verified, 14.464-second median.
  • gpt-5.6-luna comparison: 6/7 independently verified, 27.100-second median.
  • Provider monetary cost was unavailable and remains unknown.

Limitations are explicit: ACP 3.5 provides governed session/control mapping but not stdio/WebSocket packaging or external-client conformance; the physical Luna → local LLM → GLM-5.3-Flash → Luna chain did not run; broader Spark cost/corpus evidence and automatic production Job adoption remain unqualified. Spark remains disabled by default. No live service was deployed or reconfigured.

Reproduce and upgrade

git fetch --tags
git checkout v3.5.0
npm install
npm run check

Existing 3.4 state remains compatible. Installing the release starts no service, enables no Saved Job/Schedule and changes no live configuration.

Recovery

The previous known-good source boundary remains immutable at v3.4.0:

git checkout v3.4.0
npm install
npm run check

Full release evidence: docs/evidence/agent-control-3.5.0-release-qualification.md.

Agent Control 3.4.0

Choose a tag to compare

@lozknowles lozknowles released this 01 Sep 10:29

Agent Control 3.4.0

Agent Control 3.4 establishes Job Definition + Parameters + Schedule + Model Route + Governed Run + Persistent Result as a first-class platform boundary.

The built-in Repository Code Review freezes a Git SHA in a read-only snapshot, builds deterministic bounded context with exhaustive omission reporting, routes review.default to a qualified model, invokes its provider directly without Codex, creates attributable Work Parcels, validates structured findings, records provider/configured-price cost, and advances only a successful delta baseline.

Qualification

  • Release commit: 4b04f3942201d65748c6c68bf9669cdea1841d19
  • Full gate: 550 tests passed, zero failed; typecheck, bootstrap/dashboard syntax, infrastructure-neutrality and implementation-status checks passed.
  • Real LocalWalks Run: a25479c7-d969-464f-846e-943092c3122d, SUCCEEDED_WITH_FINDINGS, frozen SHA 7f99b664a90c887fdf7c310ce465de1ee94f1bcc, one Work Parcel, eight validated findings.
  • Real route: review.defaultglm-5.3-flash → OpenRouter z-ai/glm-5.3-flash; no fallback and no Codex dependency.
  • Usage: 4,776 input / 12,802 output / 17,578 total tokens; effective provider cost USD 0.00711668826.
  • Delta proof: exact 821560d64a52b9e7956ed75ec5a291fd77cf4348cfd5168f5710d18c8d32cfe1a1e1f9d8647e5a3d, with only src/value.test.ts selected as changed context and successful baseline advancement.
  • Scheduled proof: deterministic one-time occurrence 2026-09-01T10:12:42.815Z, actual start 10:12:42.828Z, completion 10:14:03.264Z; temporary Saved Job disabled afterward.
  • Package SHA-256: c97b9d93691ac81d82f3c71b879023c2dcb97e72415ccd5c8d8223b0f63b3726.

Full sanitized evidence: docs/evidence/agent-control-3.4.0-release-qualification.md.

Upgrade and migration

git fetch --tags
git checkout v3.4.0
npm install
npm run check

Existing 3.3 internal Job manifests, Run ledger, Work Parcels, model registry, systems and lanes remain intact. Parameterised Job state is created beneath AGENT_CONTROL_STATE_DIR/parameterized-jobs only when used. Installing this release enables no Saved Job or Schedule.

Before creating Repository Review Saved Jobs, configure jobs.repositoryRoots, an execution resource and a qualified review.default model. Remote Git checkout remains disabled unless jobs.repositoryRemotes explicitly permits it.