-
Closed V12 after independent reconciliation of its implementation, formal bounded
real-repository pressure, and explicit proof limits. Plausible and Outline retain exact
selected-closure refusal evidence and bounded witnesses for every applicable database, provider,
worktree, service, hook, and selected-child mutation path. V12.1 remains planned and inactive. -
ota up --dry-run --jsonnow derives selected typed-effect admission before rendering a
workflow preview. A typed refusal isBLOCKEDwithout setup or other workflow work, and retains
the admitted non-secretplan.effect_application_plansplus active
plan.effect_policy_decision; untyped closures and missing policy decisions omit those fields
rather than fabricating effect evidence. -
Recorded immutable Linux/x64 and macOS pressure for typed
ota up --dry-runadmission in
run 33382559640 against exact Core
a5aae10f5ce33e0d0927dbb913a685505933145b. Both retained artifacts report one admitted plan,
an explicit typed deny,BLOCKED,execution_started: false, and only the refusal action.
The selected fixture's setup sentinel, rendered environment artifact, proof artifact, durable-log
path, and dependency command sentinel were absent immediately after preview. Core-owned
plan-to-executor and sandbox-admission continuity controls also passed. This is internal,
provider-disabled evidence only; it does not prove provider contact or mutation, arbitrary
child-process absence, repository-wide immutability, database correctness, positive assurance,
or archive export safety. -
Added the Core-owned pressure-evidence registry at
docs/pressure/evidence-manifest.jsonand a generated Site discovery projection. Each retained
case records exact repository and Ota revisions, hosted matrices, exercised surfaces, proven
facts, explicitnot_provedboundaries, and engineering-note status. This is evidence
accounting, not repository certification, maintainer endorsement, or a green-badge scorecard. -
Added
ota contract effect-refusal-candidateas the first review-only bridge from verified
private refusal evidence back to contract authoring. It accepts one verified workflow archive
with exactly one eligible explicit typed denial, capturesota.yamlonce through a retained
no-follow descriptor, re-derives current contract, workflow, effect, attachment, migration-plan,
and realization truth, rechecks the exact contract bytes before completion, and durably publishes
a schema-v5effect_assurance
candidate proposing oneagent.effect_refusal_canariesaddition asunknown. The candidate has
no application projection andapply-candidatereturnscandidate_read_only; an exact existing
declaration is a successful non-publishing no-op, while stale or conflicting truth refuses.
Both success branches carry one versioned reconciliation identity plus the archive, contract,
effect, attachment, realization, workflow, and canary identities that produced the result.
This does not infer effect definitions, policy, grants, provider authority, execution approval,
or positive assurance from archive or incident evidence. -
Recorded immutable Linux/x64 and macOS pressure for
ota contract effect-refusal-candidatein
run 33323426885 against exact Core
9b2ff4bd0ed760a506d35539477441b3899e924f. Both retained artifacts publish the bounded
archive-derived candidate, reject its--write --carrier gitapplication as
candidate_read_only, report exact-existing declaration as a reconciliation-bound no-op, and
refuse migration drift and a symlinkedota.yamlwithout publication. The carrier also runs the
Core regression rejecting a rehashed substituted proposal. This is internal, provider-disabled
evidence; it does not prove provider contact or mutation, arbitrary child-process absence,
repository-wide immutability, positive assurance, or export safety. -
Recorded the same archive, assurance, review-only candidate, and bounded selected-path controls against forked
Plausible and Outline repositories on Linux/x64 and macOS in
run 33391482073 and
run 33391486538. Both retained
artifacts bind clean source-built Coree96cad13db9e4289c0985fca2ce6d8353a896da4, verify one
private workflow archive, promote only its exact workflow claim tosupported, return it to
unknownafter retained-context stripping, and exercise durable projection-free candidate,
read-only write refusal, reconciliation no-op, migration drift, and contract-alias refusal. Task
and workflow canaries retain absence of their selected provider/database precursor,
worktree/child-command, and outcome-hook sentinels; workflow canaries additionally retain
setup-sentinel absence, while captured closure evidence records no selected service. This is
selected-lane, provider-disabled evidence only; it does not prove repository-wide readiness,
actual provider/database behavior, database correctness, arbitrary child-process absence,
complete repository immutability, positive assurance, or export safety. -
Recorded immutable Linux/x64 and macOS pressure for private archive-backed workflow refusal
assurance in run 33309358828
against exact Core81c25e09c833559312e9cd43ce04a1c63f27d6fa. Both retained artifacts promote
one exact workflow challenge tosupportedonly after reconciliation of the current contract,
workflow closure, typed realization, explicit deny, and private archive. Tampering the archive
returns that claim tounknown. This remains internal, provider-disabled negative evidence: it
does not prove provider contact, mutation, positive assurance, or export safety. -
ota doctor --jsonnow consumes the existing verified private workflow refusal archive for
additiveeffect_refusal_assuranceclaim records. It promotes only an exact current-contract
workflow challenge with matching eligible effect attachment, realization, explicit typed deny,
and pre-execution evidence; task-only, stale, invalid, ambiguous duplicate, or mismatched
archives remainunknown. Any invalid sibling in the private archive set also prevents support.
Known unchallenged equal-effect paths and opaque shell/provider paths remain explicit
not_provedboundaries. A declared or ephemeral passing canary is not positive assurance. -
Hardened detector-led starter and CI inference. GitHub Actions verification commands now retain
repository-relative job or step working directories as structured task commands; dynamic,
noncanonical, or escaping working directories are not promoted. Named multiline verification
steps retain their complete ordered body and remain unresolved rather than selecting one line as
task truth. Newly authored starters declaremetadata.ota.minimum_versionfor the running Ota
version, while heuristic agent-boundary output is explicitlyPartially inferredunless both
writable and protected paths came from an explicit boundary source. These are review inputs, not
inferred agent-safe authority or runtime/provider evidence. -
Non-dry-run
ota up --jsonnow retainsreceipt.typed_effect_policy_refusalwhen an explicit
typed rule denies the selected closure. The additive schema-v1 record binds the exact
command-scoped effect-policy decision andexecution_started: false; it is absent for typed
allow/warn provider-disabled refusal and policy unavailability. Operators may explicitly add
--workflow <name> --archive-effect-refusalto create a durable negative receipt with immutable
contract and private policy snapshots. Receipt history re-derives the selected closure,
application plans, policy snapshot, and decision before accepting the archive. This does not
contact a provider, prove a mutation, establish positive assurance, or create a public export.
If atomic publication succeeds but directory synchronization fails, JSON reports
effect_refusal_archive_durability_uncertain,published: true, and the exact recovery path
instead of misreporting an ordinary pre-publication failure. Policy or contract snapshot sync
uncertainty useseffect_refusal_snapshot_durability_uncertain, names the published artifact,
and statesreceipt_published: false.
Post-publication verification or receipt-retention failures now preserve the published receipt
outcome aseffect_refusal_archive_post_publication_failedwith confirmed durability and its
exact archive path. -
Recorded immutable Linux/x64 and macOS pressure for the command-scoped typed effect-policy,
capability, and sandbox-admission boundary in
run 33199213628 against exact Core
1339476f1806a14278028de95020afd7e9ef5098. Both retained artifacts record typedrun,up,
and inherited-proof refusal withexecution_attempted: false; absent workflow setup,
environment-rendering, proof-artifact, and durable-log paths; stale-input and symlink refusal;
task/workflow canary results; and the Core-owned delivery-continuity control. This remains
execution-disabled internal-fixture evidence, not arbitrary child-process absence, provider
contact or mutation, complete repository immutability, positive receipt/archive, assurance,
independently administered policy authority, or independent real-repository pressure. -
Bound V12 typed effect-policy truth into task and workflow harness capabilities plus live sandbox
admission. Capability JSON distinguishes untyped, evaluated, and unavailable policy posture and
keeps every typed lane provider-disabled and schema-bound to refused preflight. Only untyped
not_applicablelanes can appear under callable capability collections, while typed deny,
allow/warn, and unavailable posture each bind their exact refusal reason. Sandbox evaluation
consumes the exact command admission instead of re-planning with a second origin or reloading
policy truth; malformed policy does not contaminate untyped lanes. Missing policy or aggregate
denial refuses before canonical sandbox policy construction or provider capability evaluation.
This does not enable typed provider execution, positive receipts or archives, or positive
assurance. -
Extended provider-neutral CI projection with identity-bound typed effect-policy decisions. The
generated provider workflow re-evaluates that decision against its checkout before setup or
selected execution; explicit typed denial returns inspectableeffect_policy_denied. This does
not enable provider mutation, positive receipts or archives, or positive assurance. Immutable Linux/x64
and macOS pressure in
run 33173733814 binds exact Core
39d2f3964aec84a6e5ff5b0fdb19fa94ce27c8eb, retains schema-valid warn and deny projections,
and proves checkout policy drift changes projection identity before provider setup or execution. -
Rejected
database_schema_mutationunderworkflows.<name>.prepare.action. Typed mutations
must use a named task witheffects.declared, so the shared typed-effect admission boundary can
bind the canonical attachment before workflow preparation begins. -
Extended V12 typed-effect admission to
ota proof runtimeandota proof lifecycle. Both now
evaluate the complete selected proof closure before replay-input evaluation, crossing or sandbox
admission, proof artifact creation, service work, or child startup. A typed deny returns
OTA_EFFECT_POLICY_DENIEDwithexecution_started: false; provider execution, positive proof
positive receipts, archives, and assurance remain disabled.
Immutable Linux/x64 and macOS pressure in
run 33166914327 proves that boundary
before proof artifacts, setup, workflow environment rendering, durable logs, or child startup. -
Added contract-owned V12 effect-refusal canaries for exact task and workflow lanes.
agent.effect_refusal_canariesbinds a local locator to one typed effect and mandatory origin.
ota run --agent --expect-effect-refusal <id> --json <task>and the matching workflowota up
form exit0only when one eligible realization is denied by an explicit matching typed rule
before execution starts. Fallback-only and generic refusals cannot false-green the canary;
unknown IDs, caller overrides, missing origins, and non-denial retain distinct non-passing
statuses. The result is negative-control evidence only, not provider mutation, a positive
receipt/archive, or positive assurance.
The bounded internal Linux/x64 and macOS carrier is green in
run 33098093213 against exact Core
dc368fbb2fc298490bfce6de86ea4ed79b493beb: it proves task/workflow canary passes, strict
fallback and unknown-ID non-passing results, icon-free plain output, and no setup, environment,
or durable-log side effect. It does not substitute for independent real-repository pressure. -
Added the shared V12 typed effect-policy evaluator. Policy packs can declare canonical
policies.effects.typed.ruleswith exact, namespace-pattern, or provider-wide PostgreSQL
resource selectors. One command-scoped decision binds policy/source authority, selected
invocation and execution graph, effect and realization sets, every matching rule, coarse effect
components, anddeny > warn > allowprecedence. Explicit typed denial, strict fallback, or a
coarser deny now causes a distinct pre-side-effect refusal in repo-levelota runand non-dry-run
ota up; dry-run exposes the non-secret decision. Provider mutation, positive effect receipts,
archives, and assurance remain disabled. -
Include canonical discriminated action bounds in V12 effect application plans so an executor can
receive apply, rollback, reset-empty, or reset-with-migrations semantics without rereading the
contract. Preview schemas enforce the same canonical migration-root and action-specific manifest
cardinality rules. The internal continuity control proves exact ordered delivery and binds its
acknowledgement to the plan and executor input; callback behavior and provider mutation remain
unproved. Immutable Linux/x64 and macOS internal-fixture pressure is green in
run 33032683375 against exact Core
32e3395f92e1114ce209dc620d14ecc82330856f. -
Validate that a released
agent.bootstrap.ota.source.versionis not below
metadata.ota.minimum_version. CI can consume that single checked source through
ota-run/setup@v1orota-run/action@v1withsource: contract, instead of maintaining a
separate workflow-owned version declaration. -
Added the execution-disabled V12
action.kind: database_schema_mutationadapter. It requires
one matching declared effect, captures bounded migration input by opening every effective-cwd and
migration-root component through retained no-follow handles on Unix, refuses execution on
non-Unix, and derives one exact selected-task-bound domain-separated application-plan identity
that also binds the contract invocation origin and repository-relative effective working
directory.ota run --dry-run --jsonpublishes the non-secret
plan, while repo-levelota runand non-dry-run repo-levelota upadmit and verify every typed
action in the selected closure before command-scoped
replay-input policy loading, agent/crossing/sandbox admission, workflow-environment artifact
rendering, durable-log preparation, task conditions, required services, dependencies, or provider
execution. Validation rejects mode or OS-variant execution-body overrides that could replace the
typed action after preview. It does not run a shell migration
command, contact PostgreSQL, authorize execution, mark work agent-safe, or claim a successful
mutation. -
Began the V12 effect-bound assurance foundation with strict provider-neutral resource bindings,
typed database schema-mutation definitions, task-local effect attachments, and separate
domain-separated identities for consequence, attachment origin, resource evidence, and
realization posture. Validation rejects ambiguous namespaces, unknown or duplicate references,
noncanonical paths and identities, and action/bounds substitution. Resource namespace components
use a versioned ASCII profile, and migration roots refuse every path alias instead of normalizing
authored values. This is declaration and
identity infrastructure only: it does not alter execution admission, verify migration bytes,
evaluate policy, contact a provider, or produce positive effect-refusal assurance. -
added
/learnas a first-class site surface with 25 versioned lessons across foundations,
contract authoring, execution, evidence, governance, operations, and hands-on labs. Every lesson
carries substantive teaching content, canonical terminology, bounded claims, knowledge checks,
and exact reference links. Learn is indexed throughllms.txt, the sitemap, and a
machine-readable/learn/index.jsoncurriculum, while curriculum, module, lesson, and breadcrumb
JSON-LD make the rendered pages discoverable without presenting the material as a credential -
Closed the bounded V11.22 OSS authoring slice after independent review of its source-bound
candidate model, fail-closed closure classification, create-new and Git write carriers,
registered lossless upgrade, schemas, first-party propagation, and immutable Caddy, GitButler,
BAML, Atuin, Buzz, and Flowise pressure evidence. Closure does not approve candidate changes,
infer agent-safe authority, execute pressure-repository tasks, or claim repo-global governance. -
Fixed source-bound candidate reapplication when a retained execution closure references evidence
for a field that became unchanged after the first contract write. Candidate manifests now derive
from every retained direct and nested closure reference, so an unchanged reviewed application
remains a semantic no-op without weakening source-drift detection. Projected contracts now pass
through the canonical parser, preserving registered compatibility normalization during a
lossless legacy upgrade. -
Clarified the V11.22 safety boundary: detection candidates classify execution closure but never
infer agent-safe authority. Maintainer-authored declarations remain canonical; positive inferred
safety is deferred until the planned typed effect and realization evaluator can prove every
material effect rather than relying on verifier names or command shape. -
Source-bound candidates now preserve distinct CI verifier lanes instead of flattening every
Cargo test into one generic task. Exact Cargo+toolchainand Nextest commands retain
job-scoped task identity, while unresolved CI closures carry observed runner platform,
repository-selected Rust toolchain, service, and environment requirements as explicitly
non-authoritative review evidence. CI evidence still cannot authorize agent-safe execution. -
Fixed source-bound candidate inventory on case-insensitive filesystems so registered detector
paths must match every repository path component exactly. Lowercase aliases such as
claude.mdand case-folded names such asmakefilecan no longer be reinterpreted as distinct
CLAUDE.mdorMakefileevidence and change candidate identity across Linux and macOS. -
Fixed candidate application compilation and refusal posture on Windows and other unsupported
writer platforms.apply-candidate --write --carrier gitnow returns the typed
candidate_write_unsupported_platformrefusal before candidate loading, repository locking,
Git invocation, or mutation, while dry-run candidate review remains available. -
ota init --dry-run --jsonnow exposes the complete source-bound
init_starter_preview_v1candidate and resulting contract identity for the exact starter
preview; the additive preview carrier grants no write authority. -
Removed repo-level
ota detect --merge,--apply,--apply-all,--rewrite, and--yesas
parallel contract writers. Hidden parser tombstones returndetect_legacy_mutation_removed
before repository access and point to source-bound candidate review; rewrite/removal has no
misleading replacement until candidates can represent those operations. The temporary
first-contract-onlyota detect --writealias now builds the schema-v3
detect_conservative_first_contract_v1profile and publishes its verified projection through
the same locked, atomic create-new carrier asota contract apply-candidate --write; successful
text and JSON output now disclose that exact applied candidate identity and profile. -
Added
ota contract upgrade --candidate-out <path>as the first versioned, lossless contract
migration review surface. It recognizes legacy flat toolchain fulfillment, emits a schema-v2
source-bound upgrade candidate with before/after semantic and resulting-content evidence, and
never changesota.yaml.ota contract apply-candidateindependently re-derives the migration
for dry-run admission; explicit--write --carrier gitnow commits a reviewed existing-contract
update through expected-HEAD branch compare-and-swap and verifies the resulting worktree. It
scrubs caller Git routing state and preserves prior/resulting commit and branch identities if
branch advancement succeeds but worktree reconciliation fails.
Default--writeremains create-new-only. Detection and upgrade candidate JSON distinguish
candidate_published/candidate_publicationfrom contract mutation: durable publication is
explicit, while a post-publication sync failure reportsdurability_uncertainwithout
incorrectly claiming that the candidate was absent. -
Added
ota contract apply-candidateas the dry-run admission surface for reviewed
source-bound detection candidates. It verifies self-identity, detector compatibility, current
contract/sources/evidence, exact re-derivation, and an identity-bound application projection
before reporting a typed result. Candidates without a complete valid projection cannot enter
application admission; unrelatedunknownorunsupportedfindings remain visible review
state unless--require-completeis used. Metadata for a newly detected task now inherits that
task execution's fail-closed disposition, so an unresolved wrapper cannot leave orphaned
applicable metadata that blocks projection of unrelated contract truth. -
Added explicit
ota contract apply-candidate --writefor reviewed detection candidates. It
takes an exclusive no-follow repository lock, re-derives and validates current source evidence
under that lock, and atomically creates a previously absentota.yamlfrom the shared
evaluator'sContract. Default--writenever overwrites an existing contract; a repeated
matching result is a semantic no-op, and a post-publication directory-sync failure is reported
as durability uncertainty rather than as an unwritten failure. -
Added
ota detect --candidate-out <path>for a durable, source-bound contract-candidate review
artifact. It derives from a command-owned immutable source snapshot, uses canonical create-new
atomic no-replace publication on Linux and macOS, refuses contract/evidence collisions and
output aliases, and never modifiesota.yaml. Discovery inventory entries carry required
content identities, every selected
evidence tuple is retained, and each change binds a structured contract path plus a canonical
semantic value. Equivalent existing truth is omitted, including typed commands equivalent to a
detected package-script invocation, schema-default command fields, and indexed environment-source
fields; disagreements are emitted asconflict. Candidate application is dry-run by default,
with an explicit create-new-only writer for a previously absent contract. -
Tighten
ota detectagent-safety inference. Detected task names, package/task-runner wrappers,
opaque shell scripts, and CIrun:fragments no longer emitsafe_for_agent: truemerely
because they resemble verification. Shell-variable and GitHub-expression CI commands remain
outside command-truth inference; shell markers contribute toolchain presence only. Detected
tasks remain reviewable runnable candidates under the V11.22 closure classifier until a
maintainer explicitly applies a reviewed contract change. -
Strengthen runtime-proof negative-control evidence for downstream consumers. A validated
dependency-level projection now names its canonicalnegative_control_id; it is emitted only
with same-obligation, expected-missing-effect, and failure-attestation evidence. Consumers can
reconcile that ID, the parent dependency/obligation, and exact digest with the canonical
top-level negative-control record. Core performs that semantic reconciliation before emission
and when loading runtime-proof archives; archive readers re-derive the selected control from
the archived contract and scope, requiring exactly one canonical record and projection. Invalid
and unrun projections cannot carry the canonical ID or attestation digest.