Releases: rschlaefli/devrouter
Release list
0.1.3
Fixed
stop --deletesettles a primary checkout whose Devsy registration is already
gone. The absent-registration proof accepted only ledger-owned linked
checkouts, so the mutation ran and the command still failed with "Absent stop
requires a linked workspace", leaving the journal instopping, where
settlement reported already-settled and every laterensurewas refused. A
primary checkout now proves the retained baseline by exact path and provider
identity instead.- A managed environment whose ignored generated profile was removed by an
interrupted or rolled-back transition restores that exact artifact from
retained state before a provider mutation, instead of refusing everystop
andensurewithdevcontainer path ... does not exist. A missing or
unreadable record, or a changed source, still leaves the environment
untouched. stop --deleteagainst a managed population that changed outside devrouter
withdraws the stop intent it recorded when its worker refuses before touching
anything, so the journal returns to its pre-stop state and the nextensure
proceeds instead of being blocked by an abandonedstoppingphase. A refusal
after the mutation boundary keeps the fail-closed intent.- The Docker network inventory template closes the JSON object it opens, so the
daemon's records parse again instead of every capacity read reporting unknown
inventory; a partial record is now named as malformed evidence, and the
template's scaffolding has a regression test. status,doctor,ensureand their JSON forms read a managed container's
mount table only when a configured mount actually nests, because a container
that configures no nested mount reportsnot-applicableeither way; the
unconditional read also failed the synthetic-provider qualification
harnesses.
Enhanced
- Lifecycle actions no longer start each provider CLI twice per registry read: a
missing CLI is classified from the registry read's ownENOENT, and every
other failure still records that registry as unavailable. On the retained
qualification fixture a cold or retainedensuredrops from 26 to 18 provider
invocations andstop --deletefrom 22 to 16, with the same ownership proofs
and the same provider Docker work. statusanddoctorreport a configured mount that the host runtime unwound,
as a bounded non-blocking observation.
Added
- Qualification harnesses for stopped-resume and fault-recovery cohorts
(pnpm qualify:cohorts), process-preparation reuse (pnpm qualify:preparation) and profile changes with host/container alternation
(pnpm qualify:profiles), plus a host-suspend observation harness and two
browser cells in the harness journey. - The ordinary
checkjob runs the installed synthetic lifecycle qualification
(pnpm qualify:lifecycle).
Agent Adaptation Prompt
Agent adaptation prompt: ./upgrade-prompts/0.1.3.md
v0.1.2
Patch release carrying the post-release reliability review corrections.
- Recovery guidance for a refused managed start now emits the supported
devrouter doctor --repo <checkout>form (single-quoted when the path needs it), so the suggested diagnostic inspects the intended checkout from any working directory. - The harness gate recognizes its own lifecycle commands as direct executables and through the
npx,pnpm exec,npm execandyarnlaunchers, includingenvand assignment prefixes, sostatus,stopandensurereach their own bounded checks during a transition. The gate also spends the full wait budget and observes once more at the deadline, and hook decisions no longer report a settled environment for passthrough, unmanaged, invalid-payload or unavailable evidence. devrouter doctornames the bounded cause and the offending journal entry when capacity-history enumeration is unprovable, and the network-capacity check names the missing evidence inputs.- Capacity snapshot replacement is fenced by content digest, so a reused inode cannot let a stale snapshot pass the presence check.
- Added:
pnpm qualify:killed-runtimefor container-local SIGKILL/OOM recovery, and an opt-inharness-journeyCI job that retains a sanitized run summary with the source revision, bundle hash and harness versions.
Fail-closed refusals for live workers, unknown ownership and surviving resources are unchanged.
Adaptation guidance: upgrade-prompts/0.1.2.md
v0.1.1
Patch release for one way a managed environment could sit blocked without saying so.
- A managed
ensurethat admission refuses on a fixed published host-port claim stays visible after the command exits.devrouter statusnow reports astart-refusedattention reason naming the read-onlydevrouter doctorcheck and the consumer-side fix; an explicitstopreleases the intent and the reason, and a later admitted ensure clears it. Before this release the journal recordeddesired: runningwhile no runtime existed, so status reported a stable, drift-free environment that could not progress, and nothing named a supported next step. - Carried from the merged Q06 qualification:
pnpm qualify:slow-dependencyproduces the four dependency-recovery outcomes the reliability roadmap's Q06 row names — a slow dependency waited for instead of failed early, a bounded failure naming an unhealthy dependency, no recreation of an unchanged one and exactly one start of an exited one.
The refusal itself is unchanged and still fail-closed: live-worker, unknown-ownership and surviving-resource checks refuse exactly as before.
Adaptation guidance: upgrade-prompts/0.1.1.md
v0.1.0
First stable cut of the reliability program: the managed lifecycle is driven by durable intent, capacity admission refuses instead of guessing, and the harness gate serves two agent harnesses.
devrouter harness gateserves the Codex CLI as well as Claude Code, answering in the envelope each harness accepts. An allowed Codex call returns the guidance asadditionalContextbecause Codex reports anallowdecision as unsupported hook output, and a re-delivered call is refused by itstool_use_idinstead of waiting twice. Both harnesses pass the same three-scenario journey.- The consumer contract is qualified against a runtime with no Node toolchain:
pnpm qualify:non-nodedrives a synthetic Python consumer with a routed host application and a routed Postgres dependency, and records a cold/warm baseline (cold median 6827ms, warm median 2291ms, consumer peak RSS 22.3MB) with its readiness, memory and dependency-reuse measurements. - The Q01-Q36 acceptance matrix is dispositioned with the layer that produced each result. Open and partially-not-applicable rows are recorded as open rather than approximated: Q06 has no slow-recovery run, Q20 has no real host-suspend observation, Q26 has no quarantine path to qualify, Q30's live cancellation stays unobservable in the qualified harness, and the two OOM-labelled rows are not applicable because no OOM classifier exists.
- Carried from 0.0.80: Devsy release-range support,
capacity reconcile --yesfor a provably absent ledger, a stop that settles when its cessation is already proven, router-held port remediation, worktree-owned upstream acceptance and theglobal.cli-pathdiagnostic.
Adaptation guidance: upgrade-prompts/0.1.0.md
v0.0.80
Verified Devsy release range and lifecycle hardening.
- Devrouter supports installed Devsy releases in the
>=1.16.2 <2.0.0range:devrouter setup --yes --workspace-runtime devsyverifies the official Linux agent for the installed release against the SHA-256 digest GitHub publishes, records the manifest and injects it, whiledoctorandensurestay network-free. An in-range release without a recorded manifest is accepted with a drift warning and nothing injected, so a Devsy update no longer blocks a managed start. devrouter harness gatedefers one agent tool call while a checkout's lifecycle phase settles; the wait budget now measures only the actual wait, and a re-delivered call is refused by itstool_use_idinstead of waiting twice.devrouter capacity reconcile --yesreplaces a provably absent capacity ledger, and a stop whose cessation is already proven against that absence settles instead of staying instopping.ensureaccepts devnet upstreams served by any Compose project owned by the exact worktree, host-port conflicts name the shareddevrouter-traefikholder, anddoctorreportsglobal.cli-pathwhen several installs exist.
Adaptation guidance: upgrade-prompts/0.0.80.md
v0.0.79
Managed-session reliability hardening.
- A managed stop whose Docker population was pruned or externally removed settles as proven-absent instead of refusing forever; a surviving container, an adopted replacement, a changed registration or unreadable evidence keeps the refusal and the retained baseline.
- Automatic recovery is bounded by the declared policy: per-process and per-service restart limits and the incident window are enforced against the exact declared resource, with the aggregate corrective-action cap unchanged.
- Durable consumer state survives controller restarts: version-2 snapshots, operator pins, retained-consumer release, exact reconnect and continuous pressure evidence.
- A host Devsy CLI newer than the verified pin no longer blocks managed starts; doctor reports the drift as a non-blocking warning.
devrouter statusexplains the durable lifecycle intent of a managed checkout, and ensure/stop report bounded stage progress on stderr.
Adaptation guidance: upgrade-prompts/0.0.79.md
v0.0.78
Provider queue diagnostics now distinguish the first waiter from the observed lock holder, show held duration and remaining acquisition time, and explain that acquisition timeout does not stop the holder. Unknown or changing evidence stays unknown. Lock acquisition, ownership, cancellation and runtime behavior are unchanged.
Source fix: #95. Release metadata: #99.
Validation: source and release PR CI passed, including full tests, build, isolated package proof and controller/capacity qualification. Local release checks included42 focused lock/upgrade/prompt tests. No consumer runtime operation was performed for this diagnostic-only patch. Historical configuration drift still requires its existing proof; this release does not claim recovery of affected legacy workspaces.
v0.0.77
Ordinary managed ensure now prepares TLS certificate coverage for resolved proxy hostnames before provider startup and repository hooks. Existing certificate names, shared locking, admission refusals, and retained-runtime repair behavior are preserved.
Source fix: #97. Release artifacts: #98.
Validation: 2,260 source tests passed, including managed ensure regressions and additive TLS coverage tests. Local release documentation, build, and isolated package checks passed. Live trusted TLS verification passed for six consumer hostnames; the consumer subsequently stopped successfully. Application readiness remains unproven because its authenticated fixture startup failed.
Agent adaptation: upgrade prompt.
v0.0.76
Fixes canonical stop for historical combined profile selections and preserves captured generated configuration during failed first-transition rollback.
Ownership, live-worker, configuration and surviving-resource checks remain fail-closed. Historical generated-file mismatches are not automatically adopted. Live dogfood passed the profile check but remained refused at a changed Compose configuration; this release does not claim consumer recovery.
See PR #96 and agent adaptation prompt.
v0.0.75
Fixes canonical stop after interrupted initial managed Devsy startup with a non-default profile.
Stop now uses the exact drained ensure's recorded profile and validates every selected container's Compose hash, full population, provider ownership and pinned Docker daemon around each stop. Unknown ownership, live workers, missing or changed evidence, and surviving or restarted resources remain refusals. No command or configuration migration is required.
See PR #94 and the adaptation prompt.
Validation: 173 focused regression tests; 2242 tests plus Linux process, build/package and controller/capacity checks in CI. The initial release-commit CI attempt hit an unchanged synthetic process ownership refusal; its retry passed. Consumer dogfooding is tracked separately by the affected checkout's runtime owner.