Once SDK 0.1.20
·
135 commits
to main
since this release
Phase 17 — reviewed semantics to runnable protection
This release shortens the path from a detected consequential local operation to a developer-reviewed, runnable protected integration.
Highlights
- candidate-specific Doctor/manual fallback hands off to
once review-local - durable reviewed-semantics artifact separates observations from developer-approved semantics
- stable logical identity remains an explicit developer decision
- complete effect-bearing payload remains an explicit developer decision
- deterministic preview of the reviewed
.mjsprotection companion - explicit write-once materialization under
.once/generated - stale source/review state fails closed
- generated companion uses existing
protectLocalexecution semantics - permanent Node 24.15 CI proof exercises the materialized companion across fresh processes
Proven behavior
- first logical execution performs one effect
- same identity + same payload replays without another effect
- same identity + changed effect-bearing payload returns
CONFLICT - response loss after commit becomes
UNKNOWN - retry of UNKNOWN does not blindly redispatch
Safety boundaries unchanged
- no inferred business identity
- no inferred complete effect-bearing payload semantics
- no UNKNOWN -> execute
- no unresolved-claim bypass
- no Authorization preservation
- no silent application source/call-site rewrite
- same-machine Node 24.15+ durability boundary remains explicit
- no universal exactly-once claim
Release source: