Releases: rrrrrredy/execution-fidelity-guard
Release list
Execution Fidelity Guard 0.2.2
Execution Fidelity Guard 0.2.2
Correctness and evidence-integrity patch for the Codex preview.
This release closes common package-manager option and shell-wrapper bypasses,
including nested env, sudo, command, nohup, nice, timeout, exec,
and time forms. It distinguishes read-only Git branch inspection from
mutation and prevents named-tool heuristics from overriding parsed commands.
It also covers common dependency-changing manager verbs, core PowerShell and
POSIX file writers, mutating HTTP calls, and explicit local or remote deletion
forms without treating nearby read-only commands as mutations.
Automatic test evidence now excludes help, version, list, collection-only,
--if-present, and compile-without-running forms. Generic release commands no
longer create release evidence because the contract cannot bind an expected
repository and tag.
Mode behavior is explicit: off emits no Hook policy/context output; shadow
keeps pending-tool conflicts non-blocking and records completion gaps without
steering; balanced enforces structured rules and may request at most two
verification passes.
Shadow-pilot summary schema 1.1 counts only sessions with consistent exported
guard_mode=shadow provenance. Off, balanced, and legacy mode-unbound exports
remain diagnostic and cannot satisfy the 100-session gate.
Release verification
- 98 of 98 automated tests passed on the local Windows candidate.
- The release validator passed 295 checks with zero runtime dependencies.
- The npm tarball surface contains 82 files. A fresh extraction passed 293
internal checks and returned deny for the prohibited-install simulation;
the verifier confirms it did not install the plugin. - The exact release commit is required to pass public Windows, Ubuntu, and
macOS CI before the tag and Release are published.
The release remains an Apache-2.0 guardrail, not a sandbox or authorization
boundary. The exact 0.2.2 Windows source Hook path measured 134.57 ms p95 over
100 runs against a provisional 100 ms target. Installed-client UX, a real 100-task shadow cohort,
the 800-task controlled comparison, and real-world efficacy remain unverified.
A separate unofficial DeepSeek Harness adapter is available at
https://github.com/rrrrrredy/dsh-execution-fidelity-guard and is pinned to
Harness 0.1.2-alpha.2.
Execution Fidelity Guard 0.2.1
Execution Fidelity Guard 0.2.1
Execution Fidelity Guard is an Apache-2.0 open-source Codex plugin that checks
explicit task boundaries before tool execution and checks contract-bound
evidence when an Agent claims completion.
What changed
- Added a dependency-free command that freezes and aggregates pseudonymous
receipt exports while collecting a real 100-session shadow pilot. - Rejects duplicate sessions, events, one-event-to-many-receipt mappings,
unknown reason codes, symlinked inputs, oversized bundles, and accidental
output overwrite. - Lazy-loads persistence and event-specific modules so the ordinary
no-persistence continue path does less work. - Preserves exact SessionEnd deletion when persistence is off and accepts
verified non-link Windows 8.3 path aliases without relaxing junction checks. - Adds an empty-Node process-floor diagnostic to make Windows cold-start cost
visible without subtracting it from Guard latency. - Pins CI actions to exact reviewed v7 commits and reports the actual Hook event
when benchmarking a custom fixture.
Release evidence
- 85 of 85 automated tests passed on the local Windows release candidate.
- The source release validator passed 295 checks with zero runtime dependencies.
- A real npm tarball was created, extracted, passed 293 internal validation
checks, and returned deny for the prohibited-install simulation without
installing the plugin. - Ten rounds of 20 simultaneous stale-lock contenders remained linearized:
one transition at a time, complete results 1 through 20, and final state 20. - The final Windows x64 and Node.js 20.19.1 source benchmark measured 184.76 ms
p50 and 296.05 ms p95 with persistence disabled. The same run's empty-Node
process floor measured 189.73 ms p95.
Honest limits
- The provisional 100 ms continue-path p95 target is not met.
- The shadow summarizer enables auditable collection; it does not mean the 100
real shadow tasks or 800-task controlled comparison have been completed. - Installed-client behavior remains intentionally untested on the maintainer's
machine because this release process forbids local installation. - Product efficacy, false-positive rate, rework reduction, and outcome
improvement are not yet established by controlled real-world use. - Live Intent Loop, Continuity, DeepSeek Harness, and other Host adapters are
not implemented.
Execution Fidelity Guard v0.2.0
Execution Fidelity Guard 0.2.0
Execution Fidelity Guard is an Apache-2.0 open-source Codex plugin that checks
explicit task boundaries before tool execution and checks contract-bound
evidence when an Agent claims completion.
What is ready
- Source-only doctor, demo, contract initialization, validation, explanation,
status, evidence, and receipt workflows. - Deterministic action gates for local installation, workspace writes,
destructive operations, publishing, network activity, and external changes. - SessionStart, SubagentStart, PreToolUse, PermissionRequest, PostToolUse,
Stop, SubagentStop, and SessionEnd coverage. - Pseudonymous identifiers, local-only storage, bounded records, exact-session
deletion, and owner-token Stop locking. - Apache-2.0 licensing, security and privacy policies, contribution guide,
three-OS CI, package inventory verification, and real tarball execution.
Release evidence
- 80 of 80 automated tests passed on the final local candidate.
- The source release validator passed 287 checks with zero runtime dependencies.
- A real npm tarball was created, extracted, and ran 285 internal validation
checks plus a prohibited-install simulation that returned deny. - The final Windows x64 and Node.js 20.19.1 source benchmark measured
146.54 ms p50 and 172.02 ms p95 with persistence disabled.
Honest limits
- The 100 ms provisional p95 target is not met.
- Installed-client behavior is intentionally untested on the maintainer
machine because this release process forbids local installation. - Product efficacy, false-positive rate, and outcome improvement are not yet
established by controlled real-world use. - Live Intent Loop and Continuity adapters are not implemented.
- DeepSeek Harness is a strong next adapter target, but this package is not
currently a DeepSeek Harness plugin.
Execution Fidelity Guard v0.1.0 - Public Preview
Execution Fidelity Guard v0.1.0 is an Apache-2.0 public preview of a local-first Codex plugin for explicit task-action gates, minimal decision receipts, and evidence-aware completion checks.
Highlights
- Self-hosted Git marketplace packaging with zero runtime dependencies.
- Shadow, balanced, and off modes; safe shadow default.
- Deterministic install, publish, external-side-effect, destructive, and workspace-write classifiers with positive and negative regressions.
- Strict provider-envelope and seven-field TaskContractLite validation with canonical SHA-256 binding.
- Content-minimized receipts, caller-attested manual evidence, bounded Stop checks, retention, and exact-session deletion.
- Frozen Intent Loop, Continuity, Guard, and Host ownership contract.
Validation
- 55/55 local tests passed.
- 257 release checks passed; 25 plugin files; 0 runtime dependencies.
- GitHub Actions passed on Windows and Ubuntu with Node 20 and 22.
- Adversarial and hands-on user reviews both returned GO after blocker remediation.
- The de-identified 41-failure/40-success inventory proves coverage only, not runtime efficacy or outcome improvement.
Known limits
- This is defense in depth, not a sandbox, authorization service, or complete shell interpreter.
- Live Intent Loop and Continuity bridges, installed-client discovery, and end-to-end installed Hook delivery were not verified.
- Hosted and specialized tool interception is incomplete; indirect scripts and wrappers can hide behavior.
- Hook exceptions fail open, manual CLI evidence is caller-attested, and concurrent Stop processes can race.
- The final Windows source benchmark measured 140.41 ms p95 with persistence disabled, above the provisional 100 ms target; installed-client, macOS, and Linux latency are unmeasured.
Install after reviewing the Hook commands:
codex plugin marketplace add rrrrrredy/execution-fidelity-guard --ref v0.1.0
codex plugin add execution-fidelity-guard@execution-fidelity-guard