factory 0.3.5
·
25 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Compared against 0.3.0 (289cac5). Released channel stable points at v0.3.5.
- Retain independently accepted worker handoffs outside worktrees (#88): exact-head provenance and integrity, 90-day content/365-day metadata, 256 KiB artifact/1 MiB bundle/256 MiB repository limits, explicit incomplete/privacy/expiry states, and fail-closed cleanup when retention fails. Add local paged
kind: resultevidence reads and console/briefing consumption without widening context budgets, transcript ingestion, or execution authority. (PR #113) - External pull-request review lane (#5–#9): discover open, non-draft PRs opted in by
needs-reviewor a review request, preserve that opt-in after viability verdicts, publish cited reviews bound to the recorded head, re-review changed heads within bounded rounds, record fail-closed required-CI readiness, and surface the six-state Ops queue plus actionable Inbox rows. The lane never edits or pushes contributor branches and never merges their PRs. Viability replay remains keyed to the label-add event, not the PR head. - Bundle Cyberpunk, GPUFlo, District, Factory, ROCm, Porcelain, Sandstone, Slate and Forest dashboard themes with a persistent browser-local picker, preserving configured repository CSS as the default. Keep the title/status row above the consistent navigation row in a shared sticky header. Open Ops at the root without automatic FM briefing requests; explicit Inbox and existing deep links remain available. (PR #110)
- Add dashboard Settings for exactly five repository controls: concurrent tickets, time limit per ticket, worker/gate attempts, reviewer revision rounds, and Factory Manager model. Show effective values and sources, require an explicit reviewed save, reject stale writes, preserve unrelated TOML comments, and keep changes local and uncommitted. TOMLKit is the sole required Python dependency on current
main; it is loaded only by settings write helpers. (PR #111) - Shared roadmap and owner attention (#58): dashboard and read-only FM consume the same initiative/routing/drift producers. Owner/team filters select questions without changing canonical plans or granting authority; source failures, unknown ownership, missing baselines and assigned-but-non-runnable human takeover stay explicit. C1 adds roadmap, initiative and retained-drift reads with citations; declared stage and implementation closure never prove owner-confirmed delivery. Complete-content revision identity and historical accepted evidence remain intact. No publication, intake release, deployment or live two-human acceptance is implied.
- Immutable initiative bindings (#57): linked tickets carry a schema-1 baseline of the complete initiative's normalized Outcome, Boundaries, Plan, and Success evidence; admission pins the full human-approved ticket snapshot for every retry and fails closed on malformed, changed, incomplete, or unavailable sources while legacy unlinked tickets remain unchanged. Read-only
factory plan baselineandfactory plan driftexpose proposals and accepted-versus-live drift without mutation or inferred attribution. ManagerREWRITEpreserves the exact accepted binding, andSPLITpreflights the live source and every child before creating intake-ready work; models cannot rebaseline. - Correct routed-handoff integration (#56): neutralize incidental mentions in explanations while preserving validated destinations; journal manager
CLOSEcomment receipts on the correct PR/issue timeline; attempt terminal handoffs even when an earlier manager phase fails without hiding that error or allowing new scheduling. Refresh the architecture atlas with the handoff phase and current manager/dispatch citations. - Preserve human takeover after a failed escalation comment: without the current escalation's recorded comment, the manager fails closed and leaves routing to the human handoff pass. Later handoff receipts cannot authorize recovery or hide human unassignments. (#56)
- Routed human handoffs (#56): once automatic recovery for an escalation is terminal (manager
HUMAN, manager command failure as an explicit unable-to-diagnose,manager.roundsexhausted, no manager, or an escalation the loop can never act on again: unapplied decision, missing packet, unreceipted escalation comment),factory managepublishes one public-safe request per escalation generation with the question, bounded evidence links, proposed next step and thefactory plan routeowner/candidates and rationale; mentions only on the initial handoff and on an actual owner change, never assigning anyone. Intent and comment id are journaled (handoff,commentrows); a crash or failedghbetween them is reconciled from the timeline before any retry, a failed lookup posts nothing, and--dry-runjournals nothing. Human-takeover checks now trust only recorded comment ids (escalation, manager and handoff comments), never text prefixes; an edited recorded comment is human activity. Upgrade note: the first pass publishes a request for every openready-for-humanticket whose escalation is already terminal, including pre-#56 escalations (their comments carry no receipt, so the manager no longer runs on them). - Manager PR frontier (#15):
factory manageobserves every factory-ownedagent/<n>PR through the schema-1 feedback producer (#79) and escalates once on red CI, undelivered current-head feedback, ormanager.stale_daysinactivity; late feedback is delivered at most once per(evidence_id, source_revision)and never from partial coverage or unverified ownership. New managerCLOSEdecision closes the PR and proposeswontfix-proposalon a human issue (closes a factory-created child);wontfix-proposalis now a provisioned label.manager.review = "all"is implemented: thefactory-approvedlabel waits for a managerAPPROVEbound to the exact head, never re-bound across a refresh.pr-openedjournal rows carry the PR number;SPLITrecordsissue-created. - The
initiativelabel is now an unconditional execution guard, read fresh at each owning boundary: triage refuses before any model call,factory dispatch(including--ticket) refuses to claim, the manager refuses viability and escalation handling, and the merge stage refuses anagent/<n>PR whose ticket is an initiative. Refusals are logged, visible in--dry-run, and mutate nothing. Ordinary tickets are unchanged. (#55) - Initiative issue template (
.github/ISSUE_TEMPLATE/initiative.md, labelinitiativeonly) installed byfactory init; theinitiativelabel is provisioned with the others. Read-onlyfactory plan list/factory plan inspect Nemit schema 1 JSON: declared status/owner, sections, implementation links and linked-issue state, with partial/malformed results explicit. Reading an initiative grants no execution authority; #55 now enforces the initiative execution guard at every owning boundary. (#53) factory plan route N --reason <requirements|implementation|ci|unknown> [--path P]... --jsonand the optional[collaboration]section (fallback,reasons.<reason>,components."<exact path prefix>") resolve the human decision owner of a ticket read-only, with status (selected/candidates/unassigned/invalid), source revision and step-by-step provenance. A**Decision owner**ticket section is a human override;@org/teamis rejected on user-owned repositories; no section means unchanged behaviour. (#54)- Distinguish missing optional routing owners from invalid declarations, bound overrides to their own sections, retain rejected mixed-destination provenance without selecting a survivor, and reject dead reason mappings and duplicate normalized component prefixes. Preserve coverage notices on invalid invocations. (#54)
- Add
factory chat: a supported, read-only Factory Manager console over the pinned upstream Pi runtime (console/app) and the schema-1 evidence interface. Seven bounded evidence tools, no shell/edit/write/dispatch, isolated console-owned settings and provider auth, and an explicit provider/model disclosure gate before any inference. Every start and--continueresume reobserves fresh evidence rather than trusting stale conversation. Node/Pi stays an optional console dependency (npm ci --ignore-scripts --prefix console/app); ordinary Factory execution never needs it. (#86) - Add dashboard
/chat: the selected three-column Factory Manager layout with live repository-wide/case/run evidence, citation inspection, truthful request activity, Motion-powered reflowing context panels, and browser-local conversation history. The page remains read-only and uses the existing bounded/api/asktransport. - Add schema-1 source-versioned PR feedback at full dashboard
tickets[].pr.feedback, shared by Review, Inbox and briefing. Retain simultaneous native review/thread/check evidence and provenance-backed Factory reviews with deterministic identities, explicit unknown/partial coverage, fixed 100-item/two-page/20 KB-body/32-error/30-second bounds, and head-race handling. Reviews carry the provider's ownupdatedAt, so an edited review revises its source revision. Detail reads run only for open PRs; closed and merged PRs keep the schema-1 envelope withnot_collectedsources, which is unknown rather than empty or unsupported. Read-only: no feedback delivery, readiness or merge authority; runtime JSON is unchanged. (#79) - Add optional Codebase history: stable commit-timeline maps, baseline comparisons, confidence-aware relationships, pinned source citations, and bounded background refresh through
factory[atlas]. (#67) - Add opt-in direction viability to
factory manage:needs-reviewPRs beforeneeds-viabilityissues, evidence-cited BUILD/DONT_BUILD/DEFER comments, and label-event replay protection. Only issue BUILD entersneeds-triage; PRs remain recommendation-only, with no review or handoff mechanics. - Fix manager prompt transport to use files, including
factory learn; validate manager commands in doctor, bound nonzero-exit diagnostics, and count manager failures separately from escalation totals and rounds without overriding human takeover. (#62) - Recognize District's
[defaults.engine]snapshot metadata infactory doctorwithout loading it as pipeline configuration; keep warnings for unknown and misplaced host tables. - Keep generated services on the installed Factory snapshot even when their repository working directory contains a shadowing
factorypackage. (#70) - Add optional, host-owned
[install].pythonselection for every generated service command (unset usessys.executable), preserving symlink identity and-P. Pre-mutation validation reads and parsessystemctl --user show-environment, applies the unit PATH and overlays[install].env, reports the loaded version, and checks all service module origins with selectedpurelib/platlibcontext for lexical checkout shadows outside selected package roots. Render the interpreter as one literal systemd argument, rejecting control characters and escaping backslash, quote,$and%. No environment provisioning or version matching;--printremains rendering-only. (#1) - Preserve package-less manifest inventory when Graphify labels valid empty output as a failed source; retain fatal parse errors and last-good history. (#72)
- Bind gate, reviewer, durable approval, CI, and merge eligibility to one immutable PR head; fail closed on reviewer process/verdict errors and raced heads or vetoes, re-review refreshed branches, and pin merges with
--match-head-commit. Legacy unbound approvals are withdrawn for re-earning through manager FIX. - Create PRs against the configured integration branch explicitly and reject approval/merge eligibility for missing, wrong, or changed targets. Existing wrong-target PRs are not retargeted. Document explicit
@stableand@maininstallation channels now that the GitHub default ismain.