Once SDK 0.1.19
·
161 commits
to main
since this release
Once SDK 0.1.19
Phase 16G cold-user-driven usability release.
Highlights
- Adds candidate-specific, review-only
protectLocalfallback guidance after safe automatic refusal. - Uses the existing
.once/protect-plan.jsondecision rather than introducing a parallel eligibility engine. - Surfaces observed local inputs as source observations without claiming they define logical identity or complete effect-bearing payload.
- Generated
idandpayloadcallbacks deliberately remain non-runnable until reviewed. - Adds a controlled verification recipe covering duplicate replay/suppression, payload conflict, ambiguous UNKNOWN handling, reconciliation, and durable same-machine state.
- Pins the CU#5-style HTTP_WRITE local-function experience in regression coverage.
Safety boundaries unchanged
- No transformer widening.
- No new auto-apply eligibility.
- No inferred provider mapping.
- No inferred business identity.
- No automatic payload-semantic inference.
- No source mutation from manual guidance.
- No UNKNOWN -> execute behavior.
- No Authorization preservation into protected actions.
- No universal exactly-once claim.
Release source:
6b30fa3fde08e937cc906d37353bc3ce55b1c304