Skip to content

Papertiger 0.18.0

Choose a tag to compare

@github-actions github-actions released this 23 Sep 13:26
· 25 commits to 1185f6604880b49cf99d92be08eea1ea6d505520 since this release

This release renames planner storage, commands, flags and JSON identifiers with no compatibility aliases.
To upgrade an authority, run papertiger --db <authority> backup --output <new-path> with the new binary, then papertiger init to migrate it from schema v12 to v13.
Until then commands that open the authority, other than init and backup, refuse it and name that command.
A Mise authority likewise needs papertiger-mise --db <database> init (schema v10).
Then update scripts for the renames below and rerun setup-project from the verified release binary so the project skill and reference match.

Changed

  • Release archives carry papertiger.release_manifest.v3 (was papertiger.release-manifest.v2); update scripts that check the manifest schema.

  • Blockers record a condition: blocker add <task> <name> --condition <text> replaces --reason, and JSON, dumps and the database column use condition.

  • Gates use the blockers' vocabulary: gate resolve replaces gate close, and status resolved with resolved_at replaces closed and closed_at.
    The migration converts stored gates.
    Stored history keeps its original event kinds, so gate resolutions recorded before the upgrade still read closed in log.

  • Exports are papertiger.dump.v10.
    import also accepts papertiger.dump.v9 and converts it; older dumps still need their matching release to migrate and re-export.

  • A raw SQLite writer now fails with papertiger_write_requires_public_api (was papertiger_write_requires_executable).
    The migration reinstalls every guard.

  • list --all-plans pages with one opaque --after-cursor taken from the previous page's next_cursor or continuation_command; --after-seq and --snapshot are removed.
    A cursor from different --status/--tag filters or from a changed authority is refused with the restart command.

  • Renamed flags and commands: focus --include-blocked (was --all), evidence verify --classification (was --outcome), and papertiger mise record (was papertiger mise project).

  • search --compact and show --no-history print JSON without --json; both are JSON-only projections and previously refused the command.

  • search --compact returns 5 results by default (full search keeps 20) and includes a continuation_command when more results match.

  • JSON ids are snake_case, with their version raised where the id or shape changed: papertiger.task_context.v8, papertiger.task_current.v3, papertiger.task_inventory.v2 (next_cursor and continuation_command replace snapshot and next_after_seq), papertiger.search_compact.v2, papertiger.evidence_verification.v3 (projection.classification replaces projection.outcome), papertiger.history_inspection.v2, papertiger.history_quarantine.v2, papertiger.mise_planner_projection.v2 and papertiger.project_install_result.v6 (was papertiger.project_setup.v5).
    Quarantine envelopes and Mise projections recorded before this release keep their original ids and stay readable, exportable and importable; papertiger mise record refuses a new projection with the retired id and names the command that regenerates it.

  • Help text names task arguments "Task number (N or #N)", no longer claims that reject prevents re-litigation (reopen accepts rejected tasks), states that export carries events and Mise projections, and documents the reference, history and personal setup arguments.

  • The project skill and reference are shorter.
    commit add omits --repo unless the commit belongs to a nested or external repository.

  • Mise commands are renamed without aliases; the old spellings are refused.
    paired run-next, show-run and list-runs become execute-next, show-execution and list-executions; improvement verify <FILE> becomes verify-registry; improvement brief-verify becomes verify-brief; promotion inspect becomes promotion rederive; projection inspect becomes projection export.
    Update scripts and agent instructions that call them.

  • Mise rationale flags are --why <TEXT> or --why-file <PATH|-> (stdin with -) instead of --reason on budget release, candidate abandon-materialization, trial cancel, trial abandon and paired cancel.
    Cancellation requests report the rationale as why, and their JSON target for a paired execution is paired_execution.

  • Mise authority schema v10 renames the recorded cancellation rationale to why and the recorded Papertiger gate time to papertiger_gate_resolved_at; promotion proofs and successor admissions report it as resolved_at.
    Run papertiger-mise --db <database> init once after upgrading; read commands refuse a v9 authority and name that command.

  • Every Mise schema, protocol and domain-separation id is papertiger-mise.<snake_case_name>.v<N> with its version advanced, and the improvement formats move from the papertiger. prefix to papertiger-mise..
    Operator-authored inputs must be reissued under the new ids: campaign manifests papertiger-mise.campaign.v4 (measurement contracts measurement_contract.v2), adapter bindings paired_adapter_binding.v2 and domain_shadow_adapter_binding.v2, fixture bundles fixture_bundle.v2 (regenerate with campaign fixture-bundle), briefs project_improvement_brief.v3, approvals project_improvement_brief_approval.v2 and registries improvement_paradigm_registry.v2.
    Deterministic evaluators must read deterministic_evaluator_request.v3 and emit deterministic_evaluator_output.v3; paired adapters receive paired_trial_request.v4.
    Rerun campaign source-binding, because the repository identity digest changed with its domain-separation id.
    The complete retired-to-current table is papertiger_mise::schema_ids::RETIRED_SCHEMA_IDS.

  • Mise containment policies are ContainmentPolicy with schema papertiger-mise.containment_policy.v3 and protocol papertiger-mise.ed25519_sealed.v3, replacing TrustedContainmentPolicy and papertiger-mise.trusted-containment-policy.v2.
    Reissue existing policy files; a retired policy is refused with that instruction.
    Promotion proofs and sealed attestations name the policy digest containment_policy_sha256.

  • Mise refuses campaigns, receipts and shadow evidence recorded before this release instead of reading them.
    Each refusal names the replacement id; reopen frozen evidence with a 0.17.x papertiger-mise, or admit a new campaign.

  • Mise --papertiger-db defaults to state/papertiger.sqlite, resolved from --project-root, for campaign admit-successor, promotion verify-parent and promotion verify.
    promotion verify previously required it.

  • Mise promotion derive and promotion verify help states that both always refuse until sealed confirmation attestation lands.

  • Planner Mise projections require candidate material papertiger-mise.candidate_material.v2; export them with this release's papertiger-mise projection export.

Removed

  • inspect-project-guidance and the project_guidance field of the setup result.
    Papertiger no longer recommends trigger text for a project's AGENTS.md or CLAUDE.md; installed skills route agents by their own descriptions.
    Delete any Papertiger trigger text you added for it.

Fixed

  • A trigger added by direct SQLite access is write-guard drift.
    Previously it passed audit and repair-guards --dry-run, then ran inside the next Papertiger mutation and could change planning data without an event.
    Writes now refuse and name it; repair-guards --why <reason> removes it and records its SQL.
    The Mise projection immutability triggers are also checked and restored.
    An authority that already contains such a trigger refuses writes after upgrading until repair-guards runs; reads, export and backup continue.
  • repair-guards --json reports each entry's state as missing, altered or foreign.

Prebuilt archives are attached for Windows x64, Linux x64, Intel macOS, and Apple Silicon macOS.
Merge .agents, .claude, and tools into the project root. Skills are ready to discover; executables, documentation, licenses and the source manifest live under tools/papertiger.
Verify the adjacent SHA-256 asset before extraction.