Skip to content

Releases: rrrrrredy/execution-fidelity-guard

Execution Fidelity Guard 0.2.2

Choose a tag to compare

@rrrrrredy rrrrrredy released this 31 Aug 10:46

Execution Fidelity Guard 0.2.2

Correctness and evidence-integrity patch for the Codex preview.

This release closes common package-manager option and shell-wrapper bypasses,
including nested env, sudo, command, nohup, nice, timeout, exec,
and time forms. It distinguishes read-only Git branch inspection from
mutation and prevents named-tool heuristics from overriding parsed commands.
It also covers common dependency-changing manager verbs, core PowerShell and
POSIX file writers, mutating HTTP calls, and explicit local or remote deletion
forms without treating nearby read-only commands as mutations.

Automatic test evidence now excludes help, version, list, collection-only,
--if-present, and compile-without-running forms. Generic release commands no
longer create release evidence because the contract cannot bind an expected
repository and tag.

Mode behavior is explicit: off emits no Hook policy/context output; shadow
keeps pending-tool conflicts non-blocking and records completion gaps without
steering; balanced enforces structured rules and may request at most two
verification passes.

Shadow-pilot summary schema 1.1 counts only sessions with consistent exported
guard_mode=shadow provenance. Off, balanced, and legacy mode-unbound exports
remain diagnostic and cannot satisfy the 100-session gate.

Release verification

  • 98 of 98 automated tests passed on the local Windows candidate.
  • The release validator passed 295 checks with zero runtime dependencies.
  • The npm tarball surface contains 82 files. A fresh extraction passed 293
    internal checks and returned deny for the prohibited-install simulation;
    the verifier confirms it did not install the plugin.
  • The exact release commit is required to pass public Windows, Ubuntu, and
    macOS CI before the tag and Release are published.

The release remains an Apache-2.0 guardrail, not a sandbox or authorization
boundary. The exact 0.2.2 Windows source Hook path measured 134.57 ms p95 over
100 runs against a provisional 100 ms target. Installed-client UX, a real 100-task shadow cohort,
the 800-task controlled comparison, and real-world efficacy remain unverified.

A separate unofficial DeepSeek Harness adapter is available at
https://github.com/rrrrrredy/dsh-execution-fidelity-guard and is pinned to
Harness 0.1.2-alpha.2.

Execution Fidelity Guard 0.2.1

Choose a tag to compare

@rrrrrredy rrrrrredy released this 31 Aug 07:08

Execution Fidelity Guard 0.2.1

Execution Fidelity Guard is an Apache-2.0 open-source Codex plugin that checks
explicit task boundaries before tool execution and checks contract-bound
evidence when an Agent claims completion.

What changed

  • Added a dependency-free command that freezes and aggregates pseudonymous
    receipt exports while collecting a real 100-session shadow pilot.
  • Rejects duplicate sessions, events, one-event-to-many-receipt mappings,
    unknown reason codes, symlinked inputs, oversized bundles, and accidental
    output overwrite.
  • Lazy-loads persistence and event-specific modules so the ordinary
    no-persistence continue path does less work.
  • Preserves exact SessionEnd deletion when persistence is off and accepts
    verified non-link Windows 8.3 path aliases without relaxing junction checks.
  • Adds an empty-Node process-floor diagnostic to make Windows cold-start cost
    visible without subtracting it from Guard latency.
  • Pins CI actions to exact reviewed v7 commits and reports the actual Hook event
    when benchmarking a custom fixture.

Release evidence

  • 85 of 85 automated tests passed on the local Windows release candidate.
  • The source release validator passed 295 checks with zero runtime dependencies.
  • A real npm tarball was created, extracted, passed 293 internal validation
    checks, and returned deny for the prohibited-install simulation without
    installing the plugin.
  • Ten rounds of 20 simultaneous stale-lock contenders remained linearized:
    one transition at a time, complete results 1 through 20, and final state 20.
  • The final Windows x64 and Node.js 20.19.1 source benchmark measured 184.76 ms
    p50 and 296.05 ms p95 with persistence disabled. The same run's empty-Node
    process floor measured 189.73 ms p95.

Honest limits

  • The provisional 100 ms continue-path p95 target is not met.
  • The shadow summarizer enables auditable collection; it does not mean the 100
    real shadow tasks or 800-task controlled comparison have been completed.
  • Installed-client behavior remains intentionally untested on the maintainer's
    machine because this release process forbids local installation.
  • Product efficacy, false-positive rate, rework reduction, and outcome
    improvement are not yet established by controlled real-world use.
  • Live Intent Loop, Continuity, DeepSeek Harness, and other Host adapters are
    not implemented.

Execution Fidelity Guard v0.2.0

Choose a tag to compare

@rrrrrredy rrrrrredy released this 31 Aug 05:05

Execution Fidelity Guard 0.2.0

Execution Fidelity Guard is an Apache-2.0 open-source Codex plugin that checks
explicit task boundaries before tool execution and checks contract-bound
evidence when an Agent claims completion.

What is ready

  • Source-only doctor, demo, contract initialization, validation, explanation,
    status, evidence, and receipt workflows.
  • Deterministic action gates for local installation, workspace writes,
    destructive operations, publishing, network activity, and external changes.
  • SessionStart, SubagentStart, PreToolUse, PermissionRequest, PostToolUse,
    Stop, SubagentStop, and SessionEnd coverage.
  • Pseudonymous identifiers, local-only storage, bounded records, exact-session
    deletion, and owner-token Stop locking.
  • Apache-2.0 licensing, security and privacy policies, contribution guide,
    three-OS CI, package inventory verification, and real tarball execution.

Release evidence

  • 80 of 80 automated tests passed on the final local candidate.
  • The source release validator passed 287 checks with zero runtime dependencies.
  • A real npm tarball was created, extracted, and ran 285 internal validation
    checks plus a prohibited-install simulation that returned deny.
  • The final Windows x64 and Node.js 20.19.1 source benchmark measured
    146.54 ms p50 and 172.02 ms p95 with persistence disabled.

Honest limits

  • The 100 ms provisional p95 target is not met.
  • Installed-client behavior is intentionally untested on the maintainer
    machine because this release process forbids local installation.
  • Product efficacy, false-positive rate, and outcome improvement are not yet
    established by controlled real-world use.
  • Live Intent Loop and Continuity adapters are not implemented.
  • DeepSeek Harness is a strong next adapter target, but this package is not
    currently a DeepSeek Harness plugin.

Execution Fidelity Guard v0.1.0 - Public Preview

Choose a tag to compare

@rrrrrredy rrrrrredy released this 28 Aug 12:27

Execution Fidelity Guard v0.1.0 is an Apache-2.0 public preview of a local-first Codex plugin for explicit task-action gates, minimal decision receipts, and evidence-aware completion checks.

Highlights

  • Self-hosted Git marketplace packaging with zero runtime dependencies.
  • Shadow, balanced, and off modes; safe shadow default.
  • Deterministic install, publish, external-side-effect, destructive, and workspace-write classifiers with positive and negative regressions.
  • Strict provider-envelope and seven-field TaskContractLite validation with canonical SHA-256 binding.
  • Content-minimized receipts, caller-attested manual evidence, bounded Stop checks, retention, and exact-session deletion.
  • Frozen Intent Loop, Continuity, Guard, and Host ownership contract.

Validation

  • 55/55 local tests passed.
  • 257 release checks passed; 25 plugin files; 0 runtime dependencies.
  • GitHub Actions passed on Windows and Ubuntu with Node 20 and 22.
  • Adversarial and hands-on user reviews both returned GO after blocker remediation.
  • The de-identified 41-failure/40-success inventory proves coverage only, not runtime efficacy or outcome improvement.

Known limits

  • This is defense in depth, not a sandbox, authorization service, or complete shell interpreter.
  • Live Intent Loop and Continuity bridges, installed-client discovery, and end-to-end installed Hook delivery were not verified.
  • Hosted and specialized tool interception is incomplete; indirect scripts and wrappers can hide behavior.
  • Hook exceptions fail open, manual CLI evidence is caller-attested, and concurrent Stop processes can race.
  • The final Windows source benchmark measured 140.41 ms p95 with persistence disabled, above the provisional 100 ms target; installed-client, macOS, and Linux latency are unmeasured.

Install after reviewing the Hook commands:

codex plugin marketplace add rrrrrredy/execution-fidelity-guard --ref v0.1.0
codex plugin add execution-fidelity-guard@execution-fidelity-guard