Skip to content

srstack v0.3.0

Latest

Choose a tag to compare

@tomismeta tomismeta released this 27 Sep 21:09
· 1 commit to main since this release

Host-native research and history-first projections

srstack v0.3.0 moves Standard Reserve research into the agent's existing host-authorized tools. Reviewed knowledge and optional offline calculations replace the bundled protocol clients; questions drive the work, not a fixed command catalog.

What changes

  • Retire the bundled snapshot, price, history and diagnostic clients. No RPC transport, active-deployment router, wallet connector or background service is installed.
  • Add question-oriented contract/capability guides and reviewed interface inventories: 19 dated contract bindings, 15 interfaces, 905 ABI entries and 25 scoped capabilities. Dated identities are discovery leads, not current routing authority or deployed-behavior certification.
  • Bundle optional standard-library calculation helpers, a thin offline JSON CLI, research/round schemas and explicitly fictional worked examples. Agents may use, adapt or ignore them; no particular language, helper or data format is required for an answer.
  • Start next-round close projections from relevant curated history. Report both an exact last-sold linear trend and a structural estimate with a descriptive ±1 sample-standard-deviation band. Keep policy opening, executable inventory-conditional quote, observed close and floor distinct; future floor remains unknown.
  • Add six runnable projection recipes, durable external round-dataset guidance, partial-evidence handling and the zero-inventory phantom-price guard. A decaying getter is not purchasable inventory and does not itself advance the round.
  • Make selected-interface authentication, bounded recovery/checkpoint plans, canonical event coverage, earned-origin attribution and claim-level uncertainty explicit without imposing a research wizard or tool allowlist.
  • Fix compact scientific-notation inputs exhausting calculator resources before magnitude rejection. Keep the Hermes description within 60 characters and install only the complete reviewed runtime export.

Boundaries retained

No wallet signing, signature requests or transaction submission/broadcast. Explicit unsigned-artifact preparation remains separately authorized; a buying question does not authorize preparation or execution. Host permissions, access controls, credential protection, private-data consent, untrusted-source handling and evidence integrity remain mandatory.

No live deployment, price, balance, funding origin or complete historical dataset is supplied as a package default. ABI coverage is not source/bytecode correspondence. Conditional calculations and forecasts require explicit evidence and assumptions; missing facts cannot become zero or verified outcomes. No new runtime third-party dependency or network/wallet authority is introduced.

Install or update

Use srstack-0.3.0.zip and verify its entry in SHA256SUMS. Only the complete runtime belongs in the skill directory; do not install the audit ZIP or GitHub's automatic source archive. Cleanly replace the complete runtime rather than overlaying files, retain rollback, and refresh discovery/start a fresh host conversation. Keep curated live research outside the installed tree.

The tagged README installation workflow covers review, committed export, staging, verification and recovery. Pin this exact full commit:

8501397e6ca196d424ccad5090826ce7ae078718

Verification now runs from the reviewed source checkout outside discovery using maintenance/package.py; the retired scripts/verify.py is not part of this release. The documented workflow resolves the explicit release tag or supplied full commit and compares installed membership/bytes with that commit. Python 3.10+ is needed only for repository maintenance or optional calculation helpers, not skill loading. Integrity is not authenticity or sandbox certification.

Verification and limits

Release commit: 8501397. Runtime: 72 files. Committed release export and runtime ZIP members match byte-for-byte; CI verifies deterministic packaging.

  • 76 regression tests passed per CI job: 20 packaging, 14 inventory and 42 research checks on Ubuntu Python 3.10/3.14 and macOS Python 3.14. Integrated-main CI.
  • All six documented calculation recipes executed from the final standalone committed export. Tag-selection smoke verified annotated-tag peeling and failure when the tag is absent, even with a same-named branch.
  • Historical fresh-session acceptance exposed three failures that were corrected and re-exercised; three new projection cases passed separately. These scoped runs are not a fresh all-scenarios model/live pass on the release pin.
  • User-reported dogfooding migrated 19 rounds, checked 10/19 rounds with 44 archive/header checks, checked a six-round forecasting cohort with 42 further checks, and passed fresh projection questions. These reports were not independently rerun here. Archive/header observations do not establish complete interior event ordering or exact first/last purchase-event coverage; the 50-to-40 capacity transition remains a comparability caveat.
  • The owner approved a bounded 0.3.0 release based on the accumulated dogfooding and review. Outstanding deployed accrual/lazy-roll/reset correspondence, attributable earned-only funding, refund/flow attribution and complete canonical history remain disclosed evidence gaps, not passed gates. Host loading and calculation checks do not establish universal safety or live-provider capability.

Scanner results — findings retained

The complete prior ten-check local security/native-host checklist was repeated on the hardened candidate. This is not an all-clear security verdict:

  • Cisco AI Defense 2.1.0 strict/behavioral: is_safe=true, with one low file-count finding and one medium recursive-reference-depth finding retained. The trace records 18 depth cutoffs and 170 reference occurrences; 17 unique existing references were not yet visited at their cutoff observations. This is not exhaustive semantic coverage.
  • Hermes current reviewed source: native parser/loader/default-preprocessing/quarantine/install checks passed with exact resource bytes; guard accepted the skill with four medium heuristics retained. Native AST audit found no findings across both runtime Python files.
  • AgentSkills valid; pinned OpenClaw loader, official validator and packaging passed; pinned local ClawHub static moderation clean. These pinned offline implementations are not current hosted registry approval.
  • Gitleaks found no leaks in the hardened runtime, then-reachable Git history or retained audit evidence. Bandit found no runtime issues and retained 14 low maintenance/test subprocess warnings. Final audited maintenance/reference-validator and Cisco environments had no known dependency vulnerabilities; srstack runtime has no third-party Python dependencies.
  • Manual review reproduced and fixed the compact-exponent resource-exhaustion issue. Before/after CLI evidence and the bounded regression are retained. No unresolved high/critical finding was reported by the executed scans; that does not prove absence of vulnerabilities.

Final changes since the full scanner/native review are limited to README release/scope wording, installation tag selection and the manifest. Executable files, entrypoint and all other runtime resources are byte-identical. The full scanner/native suite is not represented as freshly rerun on that final documentation delta. See the audit bundle for exact candidate identities, toolchain pins, raw findings, dispositions, CI and coverage limits.

Release assets

  • srstack-0.3.0.zip — complete installable runtime.
  • srstack-audit-0.3.0.zip — separate security/native-host/toolchain/verification evidence; not installable. Historical HOLD and prepublication labels retain their original meaning; subsequent scope/publication approvals are recorded separately.
  • SHA256SUMS — hashes of both ZIPs.

Runtime content SHA-256: 288c8dcde2204336b3a15a5f79ea00e98d2c4618d4c590dfb77fde43ebaa53c5.

Prior releases and their assets remain unchanged. MIT is unchanged. ClawHub publication and hosted review are deferred; no registry submission, terms acceptance or hosted scanner upload accompanies this GitHub release.