Skip to content

v1.6.27

Latest

Choose a tag to compare

@github-actions github-actions released this 01 Sep 11:43
· 1 commit to main since this release
Immutable release. Only release title and notes can be modified.
918578d
  • Closed V12 after independent reconciliation of its implementation, formal bounded
    real-repository pressure, and explicit proof limits. Plausible and Outline retain exact
    selected-closure refusal evidence and bounded witnesses for every applicable database, provider,
    worktree, service, hook, and selected-child mutation path. V12.1 remains planned and inactive.

  • ota up --dry-run --json now derives selected typed-effect admission before rendering a
    workflow preview. A typed refusal is BLOCKED without setup or other workflow work, and retains
    the admitted non-secret plan.effect_application_plans plus active
    plan.effect_policy_decision; untyped closures and missing policy decisions omit those fields
    rather than fabricating effect evidence.

  • Recorded immutable Linux/x64 and macOS pressure for typed ota up --dry-run admission in
    run 33382559640 against exact Core
    a5aae10f5ce33e0d0927dbb913a685505933145b. Both retained artifacts report one admitted plan,
    an explicit typed deny, BLOCKED, execution_started: false, and only the refusal action.
    The selected fixture's setup sentinel, rendered environment artifact, proof artifact, durable-log
    path, and dependency command sentinel were absent immediately after preview. Core-owned
    plan-to-executor and sandbox-admission continuity controls also passed. This is internal,
    provider-disabled evidence only; it does not prove provider contact or mutation, arbitrary
    child-process absence, repository-wide immutability, database correctness, positive assurance,
    or archive export safety.

  • Added the Core-owned pressure-evidence registry at
    docs/pressure/evidence-manifest.json and a generated Site discovery projection. Each retained
    case records exact repository and Ota revisions, hosted matrices, exercised surfaces, proven
    facts, explicit not_proved boundaries, and engineering-note status. This is evidence
    accounting, not repository certification, maintainer endorsement, or a green-badge scorecard.

  • Added ota contract effect-refusal-candidate as the first review-only bridge from verified
    private refusal evidence back to contract authoring. It accepts one verified workflow archive
    with exactly one eligible explicit typed denial, captures ota.yaml once through a retained
    no-follow descriptor, re-derives current contract, workflow, effect, attachment, migration-plan,
    and realization truth, rechecks the exact contract bytes before completion, and durably publishes
    a schema-v5 effect_assurance
    candidate proposing one agent.effect_refusal_canaries addition as unknown. The candidate has
    no application projection and apply-candidate returns candidate_read_only; an exact existing
    declaration is a successful non-publishing no-op, while stale or conflicting truth refuses.
    Both success branches carry one versioned reconciliation identity plus the archive, contract,
    effect, attachment, realization, workflow, and canary identities that produced the result.
    This does not infer effect definitions, policy, grants, provider authority, execution approval,
    or positive assurance from archive or incident evidence.

  • Recorded immutable Linux/x64 and macOS pressure for ota contract effect-refusal-candidate in
    run 33323426885 against exact Core
    9b2ff4bd0ed760a506d35539477441b3899e924f. Both retained artifacts publish the bounded
    archive-derived candidate, reject its --write --carrier git application as
    candidate_read_only, report exact-existing declaration as a reconciliation-bound no-op, and
    refuse migration drift and a symlinked ota.yaml without publication. The carrier also runs the
    Core regression rejecting a rehashed substituted proposal. This is internal, provider-disabled
    evidence; it does not prove provider contact or mutation, arbitrary child-process absence,
    repository-wide immutability, positive assurance, or export safety.

  • Recorded the same archive, assurance, review-only candidate, and bounded selected-path controls against forked
    Plausible and Outline repositories on Linux/x64 and macOS in
    run 33391482073 and
    run 33391486538. Both retained
    artifacts bind clean source-built Core e96cad13db9e4289c0985fca2ce6d8353a896da4, verify one
    private workflow archive, promote only its exact workflow claim to supported, return it to
    unknown after retained-context stripping, and exercise durable projection-free candidate,
    read-only write refusal, reconciliation no-op, migration drift, and contract-alias refusal. Task
    and workflow canaries retain absence of their selected provider/database precursor,
    worktree/child-command, and outcome-hook sentinels; workflow canaries additionally retain
    setup-sentinel absence, while captured closure evidence records no selected service. This is
    selected-lane, provider-disabled evidence only; it does not prove repository-wide readiness,
    actual provider/database behavior, database correctness, arbitrary child-process absence,
    complete repository immutability, positive assurance, or export safety.

  • Recorded immutable Linux/x64 and macOS pressure for private archive-backed workflow refusal
    assurance in run 33309358828
    against exact Core 81c25e09c833559312e9cd43ce04a1c63f27d6fa. Both retained artifacts promote
    one exact workflow challenge to supported only after reconciliation of the current contract,
    workflow closure, typed realization, explicit deny, and private archive. Tampering the archive
    returns that claim to unknown. This remains internal, provider-disabled negative evidence: it
    does not prove provider contact, mutation, positive assurance, or export safety.

  • ota doctor --json now consumes the existing verified private workflow refusal archive for
    additive effect_refusal_assurance claim records. It promotes only an exact current-contract
    workflow challenge with matching eligible effect attachment, realization, explicit typed deny,
    and pre-execution evidence; task-only, stale, invalid, ambiguous duplicate, or mismatched
    archives remain unknown. Any invalid sibling in the private archive set also prevents support.
    Known unchallenged equal-effect paths and opaque shell/provider paths remain explicit
    not_proved boundaries. A declared or ephemeral passing canary is not positive assurance.

  • Hardened detector-led starter and CI inference. GitHub Actions verification commands now retain
    repository-relative job or step working directories as structured task commands; dynamic,
    noncanonical, or escaping working directories are not promoted. Named multiline verification
    steps retain their complete ordered body and remain unresolved rather than selecting one line as
    task truth. Newly authored starters declare metadata.ota.minimum_version for the running Ota
    version, while heuristic agent-boundary output is explicitly Partially inferred unless both
    writable and protected paths came from an explicit boundary source. These are review inputs, not
    inferred agent-safe authority or runtime/provider evidence.

  • Non-dry-run ota up --json now retains receipt.typed_effect_policy_refusal when an explicit
    typed rule denies the selected closure. The additive schema-v1 record binds the exact
    command-scoped effect-policy decision and execution_started: false; it is absent for typed
    allow/warn provider-disabled refusal and policy unavailability. Operators may explicitly add
    --workflow <name> --archive-effect-refusal to create a durable negative receipt with immutable
    contract and private policy snapshots. Receipt history re-derives the selected closure,
    application plans, policy snapshot, and decision before accepting the archive. This does not
    contact a provider, prove a mutation, establish positive assurance, or create a public export.
    If atomic publication succeeds but directory synchronization fails, JSON reports
    effect_refusal_archive_durability_uncertain, published: true, and the exact recovery path
    instead of misreporting an ordinary pre-publication failure. Policy or contract snapshot sync
    uncertainty uses effect_refusal_snapshot_durability_uncertain, names the published artifact,
    and states receipt_published: false.
    Post-publication verification or receipt-retention failures now preserve the published receipt
    outcome as effect_refusal_archive_post_publication_failed with confirmed durability and its
    exact archive path.

  • Recorded immutable Linux/x64 and macOS pressure for the command-scoped typed effect-policy,
    capability, and sandbox-admission boundary in
    run 33199213628 against exact Core
    1339476f1806a14278028de95020afd7e9ef5098. Both retained artifacts record typed run, up,
    and inherited-proof refusal with execution_attempted: false; absent workflow setup,
    environment-rendering, proof-artifact, and durable-log paths; stale-input and symlink refusal;
    task/workflow canary results; and the Core-owned delivery-continuity control. This remains
    execution-disabled internal-fixture evidence, not arbitrary child-process absence, provider
    contact or mutation, complete repository immutability, positive receipt/archive, assurance,
    independently administered policy authority, or independent real-repository pressure.

  • Bound V12 typed effect-policy truth into task and workflow harness capabilities plus live sandbox
    admission. Capability JSON distinguishes untyped, evaluated, and unavailable policy posture and
    keeps every typed lane provider-disabled and schema-bound to refused preflight. Only untyped
    not_applicable lanes can appear under callable capability collections, while typed deny,
    allow/warn, and unavailable posture each bind their exact refusal reason. Sandbox evaluation
    consumes the exact command admission instead of re-planning with a second origin or reloading
    policy truth; malformed policy does not contaminate untyped lanes. Missing policy or aggregate
    denial refuses before canonical sandbox policy construction or provider capability evaluation.
    This does not enable typed provider execution, positive receipts or archives, or positive
    assurance.

  • Extended provider-neutral CI projection with identity-bound typed effect-policy decisions. The
    generated provider workflow re-evaluates that decision against its checkout before setup or
    selected execution; explicit typed denial returns inspectable effect_policy_denied. This does
    not enable provider mutation, positive receipts or archives, or positive assurance. Immutable Linux/x64
    and macOS pressure in
    run 33173733814 binds exact Core
    39d2f3964aec84a6e5ff5b0fdb19fa94ce27c8eb, retains schema-valid warn and deny projections,
    and proves checkout policy drift changes projection identity before provider setup or execution.

  • Rejected database_schema_mutation under workflows.<name>.prepare.action. Typed mutations
    must use a named task with effects.declared, so the shared typed-effect admission boundary can
    bind the canonical attachment before workflow preparation begins.

  • Extended V12 typed-effect admission to ota proof runtime and ota proof lifecycle. Both now
    evaluate the complete selected proof closure before replay-input evaluation, crossing or sandbox
    admission, proof artifact creation, service work, or child startup. A typed deny returns
    OTA_EFFECT_POLICY_DENIED with execution_started: false; provider execution, positive proof
    positive receipts, archives, and assurance remain disabled.
    Immutable Linux/x64 and macOS pressure in
    run 33166914327 proves that boundary
    before proof artifacts, setup, workflow environment rendering, durable logs, or child startup.

  • Added contract-owned V12 effect-refusal canaries for exact task and workflow lanes.
    agent.effect_refusal_canaries binds a local locator to one typed effect and mandatory origin.
    ota run --agent --expect-effect-refusal <id> --json <task> and the matching workflow ota up
    form exit 0 only when one eligible realization is denied by an explicit matching typed rule
    before execution starts. Fallback-only and generic refusals cannot false-green the canary;
    unknown IDs, caller overrides, missing origins, and non-denial retain distinct non-passing
    statuses. The result is negative-control evidence only, not provider mutation, a positive
    receipt/archive, or positive assurance.
    The bounded internal Linux/x64 and macOS carrier is green in
    run 33098093213 against exact Core
    dc368fbb2fc298490bfce6de86ea4ed79b493beb: it proves task/workflow canary passes, strict
    fallback and unknown-ID non-passing results, icon-free plain output, and no setup, environment,
    or durable-log side effect. It does not substitute for independent real-repository pressure.

  • Added the shared V12 typed effect-policy evaluator. Policy packs can declare canonical
    policies.effects.typed.rules with exact, namespace-pattern, or provider-wide PostgreSQL
    resource selectors. One command-scoped decision binds policy/source authority, selected
    invocation and execution graph, effect and realization sets, every matching rule, coarse effect
    components, and deny > warn > allow precedence. Explicit typed denial, strict fallback, or a
    coarser deny now causes a distinct pre-side-effect refusal in repo-level ota run and non-dry-run
    ota up; dry-run exposes the non-secret decision. Provider mutation, positive effect receipts,
    archives, and assurance remain disabled.

  • Include canonical discriminated action bounds in V12 effect application plans so an executor can
    receive apply, rollback, reset-empty, or reset-with-migrations semantics without rereading the
    contract. Preview schemas enforce the same canonical migration-root and action-specific manifest
    cardinality rules. The internal continuity control proves exact ordered delivery and binds its
    acknowledgement to the plan and executor input; callback behavior and provider mutation remain
    unproved. Immutable Linux/x64 and macOS internal-fixture pressure is green in
    run 33032683375 against exact Core
    32e3395f92e1114ce209dc620d14ecc82330856f.

  • Validate that a released agent.bootstrap.ota.source.version is not below
    metadata.ota.minimum_version. CI can consume that single checked source through
    ota-run/setup@v1 or ota-run/action@v1 with source: contract, instead of maintaining a
    separate workflow-owned version declaration.

  • Added the execution-disabled V12 action.kind: database_schema_mutation adapter. It requires
    one matching declared effect, captures bounded migration input by opening every effective-cwd and
    migration-root component through retained no-follow handles on Unix, refuses execution on
    non-Unix, and derives one exact selected-task-bound domain-separated application-plan identity
    that also binds the contract invocation origin and repository-relative effective working
    directory. ota run --dry-run --json publishes the non-secret
    plan, while repo-level ota run and non-dry-run repo-level ota up admit and verify every typed
    action in the selected closure before command-scoped
    replay-input policy loading, agent/crossing/sandbox admission, workflow-environment artifact
    rendering, durable-log preparation, task conditions, required services, dependencies, or provider
    execution. Validation rejects mode or OS-variant execution-body overrides that could replace the
    typed action after preview. It does not run a shell migration
    command, contact PostgreSQL, authorize execution, mark work agent-safe, or claim a successful
    mutation.

  • Began the V12 effect-bound assurance foundation with strict provider-neutral resource bindings,
    typed database schema-mutation definitions, task-local effect attachments, and separate
    domain-separated identities for consequence, attachment origin, resource evidence, and
    realization posture. Validation rejects ambiguous namespaces, unknown or duplicate references,
    noncanonical paths and identities, and action/bounds substitution. Resource namespace components
    use a versioned ASCII profile, and migration roots refuse every path alias instead of normalizing
    authored values. This is declaration and
    identity infrastructure only: it does not alter execution admission, verify migration bytes,
    evaluate policy, contact a provider, or produce positive effect-refusal assurance.

  • added /learn as a first-class site surface with 25 versioned lessons across foundations,
    contract authoring, execution, evidence, governance, operations, and hands-on labs. Every lesson
    carries substantive teaching content, canonical terminology, bounded claims, knowledge checks,
    and exact reference links. Learn is indexed through llms.txt, the sitemap, and a
    machine-readable /learn/index.json curriculum, while curriculum, module, lesson, and breadcrumb
    JSON-LD make the rendered pages discoverable without presenting the material as a credential

  • Closed the bounded V11.22 OSS authoring slice after independent review of its source-bound
    candidate model, fail-closed closure classification, create-new and Git write carriers,
    registered lossless upgrade, schemas, first-party propagation, and immutable Caddy, GitButler,
    BAML, Atuin, Buzz, and Flowise pressure evidence. Closure does not approve candidate changes,
    infer agent-safe authority, execute pressure-repository tasks, or claim repo-global governance.

  • Fixed source-bound candidate reapplication when a retained execution closure references evidence
    for a field that became unchanged after the first contract write. Candidate manifests now derive
    from every retained direct and nested closure reference, so an unchanged reviewed application
    remains a semantic no-op without weakening source-drift detection. Projected contracts now pass
    through the canonical parser, preserving registered compatibility normalization during a
    lossless legacy upgrade.

  • Clarified the V11.22 safety boundary: detection candidates classify execution closure but never
    infer agent-safe authority. Maintainer-authored declarations remain canonical; positive inferred
    safety is deferred until the planned typed effect and realization evaluator can prove every
    material effect rather than relying on verifier names or command shape.

  • Source-bound candidates now preserve distinct CI verifier lanes instead of flattening every
    Cargo test into one generic task. Exact Cargo +toolchain and Nextest commands retain
    job-scoped task identity, while unresolved CI closures carry observed runner platform,
    repository-selected Rust toolchain, service, and environment requirements as explicitly
    non-authoritative review evidence. CI evidence still cannot authorize agent-safe execution.

  • Fixed source-bound candidate inventory on case-insensitive filesystems so registered detector
    paths must match every repository path component exactly. Lowercase aliases such as
    claude.md and case-folded names such as makefile can no longer be reinterpreted as distinct
    CLAUDE.md or Makefile evidence and change candidate identity across Linux and macOS.

  • Fixed candidate application compilation and refusal posture on Windows and other unsupported
    writer platforms. apply-candidate --write --carrier git now returns the typed
    candidate_write_unsupported_platform refusal before candidate loading, repository locking,
    Git invocation, or mutation, while dry-run candidate review remains available.

  • ota init --dry-run --json now exposes the complete source-bound
    init_starter_preview_v1 candidate and resulting contract identity for the exact starter
    preview; the additive preview carrier grants no write authority.

  • Removed repo-level ota detect --merge, --apply, --apply-all, --rewrite, and --yes as
    parallel contract writers. Hidden parser tombstones return detect_legacy_mutation_removed
    before repository access and point to source-bound candidate review; rewrite/removal has no
    misleading replacement until candidates can represent those operations. The temporary
    first-contract-only ota detect --write alias now builds the schema-v3
    detect_conservative_first_contract_v1 profile and publishes its verified projection through
    the same locked, atomic create-new carrier as ota contract apply-candidate --write; successful
    text and JSON output now disclose that exact applied candidate identity and profile.

  • Added ota contract upgrade --candidate-out <path> as the first versioned, lossless contract
    migration review surface. It recognizes legacy flat toolchain fulfillment, emits a schema-v2
    source-bound upgrade candidate with before/after semantic and resulting-content evidence, and
    never changes ota.yaml. ota contract apply-candidate independently re-derives the migration
    for dry-run admission; explicit --write --carrier git now commits a reviewed existing-contract
    update through expected-HEAD branch compare-and-swap and verifies the resulting worktree. It
    scrubs caller Git routing state and preserves prior/resulting commit and branch identities if
    branch advancement succeeds but worktree reconciliation fails.
    Default --write remains create-new-only. Detection and upgrade candidate JSON distinguish
    candidate_published/candidate_publication from contract mutation: durable publication is
    explicit, while a post-publication sync failure reports durability_uncertain without
    incorrectly claiming that the candidate was absent.

  • Added ota contract apply-candidate as the dry-run admission surface for reviewed
    source-bound detection candidates. It verifies self-identity, detector compatibility, current
    contract/sources/evidence, exact re-derivation, and an identity-bound application projection
    before reporting a typed result. Candidates without a complete valid projection cannot enter
    application admission; unrelated unknown or unsupported findings remain visible review
    state unless --require-complete is used. Metadata for a newly detected task now inherits that
    task execution's fail-closed disposition, so an unresolved wrapper cannot leave orphaned
    applicable metadata that blocks projection of unrelated contract truth.

  • Added explicit ota contract apply-candidate --write for reviewed detection candidates. It
    takes an exclusive no-follow repository lock, re-derives and validates current source evidence
    under that lock, and atomically creates a previously absent ota.yaml from the shared
    evaluator's Contract. Default --write never overwrites an existing contract; a repeated
    matching result is a semantic no-op, and a post-publication directory-sync failure is reported
    as durability uncertainty rather than as an unwritten failure.

  • Added ota detect --candidate-out <path> for a durable, source-bound contract-candidate review
    artifact. It derives from a command-owned immutable source snapshot, uses canonical create-new
    atomic no-replace publication on Linux and macOS, refuses contract/evidence collisions and
    output aliases, and never modifies ota.yaml. Discovery inventory entries carry required
    content identities, every selected
    evidence tuple is retained, and each change binds a structured contract path plus a canonical
    semantic value. Equivalent existing truth is omitted, including typed commands equivalent to a
    detected package-script invocation, schema-default command fields, and indexed environment-source
    fields; disagreements are emitted as conflict. Candidate application is dry-run by default,
    with an explicit create-new-only writer for a previously absent contract.

  • Tighten ota detect agent-safety inference. Detected task names, package/task-runner wrappers,
    opaque shell scripts, and CI run: fragments no longer emit safe_for_agent: true merely
    because they resemble verification. Shell-variable and GitHub-expression CI commands remain
    outside command-truth inference; shell markers contribute toolchain presence only. Detected
    tasks remain reviewable runnable candidates under the V11.22 closure classifier until a
    maintainer explicitly applies a reviewed contract change.

  • Strengthen runtime-proof negative-control evidence for downstream consumers. A validated
    dependency-level projection now names its canonical negative_control_id; it is emitted only
    with same-obligation, expected-missing-effect, and failure-attestation evidence. Consumers can
    reconcile that ID, the parent dependency/obligation, and exact digest with the canonical
    top-level negative-control record. Core performs that semantic reconciliation before emission
    and when loading runtime-proof archives; archive readers re-derive the selected control from
    the archived contract and scope, requiring exactly one canonical record and projection. Invalid
    and unrun projections cannot carry the canonical ID or attestation digest.