SEMAPRAX v0.5.0
Pre-releaseSEMAPRAX v0.5.0 is pre-alpha research software.
Changes
-
Bind effect-free retained source job handlers to persisted deployment
descriptors before claim, using the existing durable job runtime and
checked interpreter; refuse stale roots and handler substitutions (#192). -
Complete the ten-row feature-composition inventory, exact ownership-profile
refusal regression, and provisioned strict differential campaign route
with explicit CI selections and nonzero-case enforcement (#103). -
Add exact SDK-envelope byte reservations to durable retries with frozen V2
journal preservation, canonical V3 recovery, and post-poll cancellation
checks (#179). Tighten provider conformance around request admission,
completion, final bytes, and usage regressions with corpus V2 (#181). -
Add a checked two-call offline repair loop and private CLI demo with
bounded candidate edits, diagnostic feedback, read-only review evidence,
and terminal journal replay (#116). Extend imported owned cursor failure
composition with exact Wasm cleanup-order and sticky-status controls (#103). -
Account compact workspace validation clones before allocation and schedule
the final uncached graph phase by temporary HIR overhead without raising
its cap (#124). Add decoded ID bounds and allocation-free token equality
to the catalog helper application with cross-backend oracle checks. -
Add generic durable retry/failover with acknowledged attempt journals,
exact retained execution/schema/model bindings, non-widening source and
deployment limits, request-seed checks, and conservative recovery (#179).
This is local host composition; checkpoints do not prove provider identity
or billing. -
Add V6 durable source-model quote accounting with nonrefundable observed and
unknown usage, absolute deadlines, cumulative migration carry, and optional
request/response byte ceilings (#113). Retain observed quote overages in
ordinary source-model admission as well. -
Retain exact generic model request/response reservations in the additive
priced I/O envelope, cross-bind successor carry, and reject noncanonical
recovery requests (#113). Add store-backed typed source-model execution with
acknowledged intents, exact raw settlements, and no uncertain redispatch
(#177). Release full sequential workspace HIR after compact validation facts
and selected output carriers are extracted (#124). -
Pair generic live work reservations with durable monetary accounting (#113),
and enforce opt-in source-model ceilings before adapter construction (#177,
#179). Add a final uncached graph retry that charges retained output vectors
while preserving earlier successful budget receipts (#124). -
Bind typed live model operations to deployment selection and commit their
redacted attempt evidence in an additive execution root (#177). Propagate
remaining host deadlines and distinguish reserved, observed and unknown
provider charges in a separate Runtime v1 receipt (#113). -
Add counterbalanced pilot scheduling, isolated MCP tools for both comparison
lanes, retained candidate source bytes and exact transport archives (#105).
Trial capture remains separate from eligible observations and review. -
Preserve pre-dispatch OpenCode cancellation as a zero-call cancellation
failure (#113). A changed journal or claimed dispatch without a receipt
remains a model failure; unresolved attempts cannot become clean refusals. -
Add direct owned String variant payloads (#216), with canonical String
lifecycle replay, own/borrow matching and backend cleanup. Scalar-match guard
and arm temporaries settle through exact cleanup regions. Generic String
substitutions and nested owned-record variant payloads remain restricted. -
Add explicit Rust-host Argon2id password hashing, authenticated sessions and
signup/login/logout composition (#191). Persist job cancellation and recurring
schedule advancement with checked arithmetic and replay evidence (#192). -
Add checked-source HTTPS POST across explicit provider, native C11 and
Core-Wasm/npm fixture paths (#193), with bounded body/response bytes, explicit
destination authorization and no automatic retry or redirect for POST. -
Add an explicit native HTTPS transport for provider adapters (#181), with
injected credentials, bounded buffered responses and conservative dispatch
uncertainty. Extend compact task context with ordered seeds, revision binding
and selectable token accounting (#197). Add a host-driven single-job
checkpoint runtime and evidence-based recovery (#192). -
Drive bounded retries and ordered failover through injected provider adapters
(#179), preserving charged attempts and stopping on uncertain outcomes.
Add host-transport protocol adapters for Responses and Messages (#181).
Recheck cancellation and deadlines when streaming settlement returns.
Add an eighth cross-language task family exercising owned byte mapping and
hidden-oracle rejection in Rust, TypeScript and SEMAPRAX (#106). -
Import bounded provider invoice evidence through explicit verifiers and retain
reconciliation results (#180). Enforce source usage consistency and complete
audit-view disclosure, payload association and truthful privacy claims; add
canonical audit replay and direct receipt emission from live run evidence. -
Decode canonical model receipts with strict bounds and enrich actual generic
and source attempt journals using retained root, request and host metadata (#180).
Join explicit adapter observations and provider usage without inventing
missing measurements; preserve failure and unresolved lifecycle evidence. -
Capture ordered provider adapter attempts and replay retained chunks against
actual generic/source runtime schemas (#178/#180). Bind generic settlements
to validated journal requests and responses; compare provider token and cost
observations independently during invoice reconciliation. -
Validate streamed nested Proposal fields, variant cases, exact scalars and
text/byte bounds from compiled type tables before final decode (#178).
Expose read-only grammar states and bounded work counters; extend the
generated TypeScript/Python/Rust client harness with adversarial chunking. -
Add versioned selective-dictionary model-text projections to CLI, retained
service and compatibility negotiation (#201). Connect streaming proposals to
Direct Runtime v2 typed effects and reject mismatched compiled schema envelopes
while streaming (#178); nested semantic admission remains in the full decoder. -
Expose compact projections through CLI replay and retained service/MCP routes,
with explicit format/profile negotiation and offline model-token measurement
tooling (#201). Introduce Rust embedding API v2 for mandatory analysis/execution input caps, add
cooperative request cancellation, and verify opaque session release (#203). -
Add authoritative task-context, Project API, candidate-diff, and Agent graph
compact profiles with regeneration-bound replay (#201). Extend Rust embedding
negotiation, cancellation, and the external consumer (#203). Connect the
source Proposal grammar to incremental decoding and an explicit per-attempt
provider adapter factory with bounded iterative context (#178). -
Connect the streaming Proposal decoder to the provider adapter and generic
live-kernel seams (#178), and compose token/cost/call policy with the live
work-budget hook (#179). Extend the embedding facade with opaque in-memory
Project sessions, atomic refresh, semantic query, and candidate replay (#203). -
Add journal-derived model-call receipts (#180) for generic live runs and
authenticated source checkpoints, including exact replay and Audit Capsule
object references. Unrecorded timing and billing stay unknown. Harden enriched
receipt replay against contradictory response states and decode refusals.
Extend the Rust source embedding facade (#203) with bounded context v1/v2
queries and explicitly authorized, cancellable, fuel-bounded interpretation. -
Implement additive Project Assurance Manifest v1 (#214): a canonical,
integrity-bound envelope bound to one retained Project, workspace
revision, ProgramRoot, and complete ordered source inventory. The profile
deduplicates shared entry/public/test HIR obligations, records explicit
unselected coverage, and admits only heldforbid_reachesarchitecture laws;
the existing single-file Assurance Manifest v1 bytes remain unchanged. -
Add additive source-journal I/O v5 accounting and private CLI config/receipt
v3 (#113). Authenticated attempt rows reserve exact prompt bytes and bounded
response capacity cumulatively; recovery and compatible migration retain
reservations without profile conversion. Legacy source journal and CLI
profiles remain unchanged. Add #103's result-allocation rejection case with
ordered input release in interpreter/Wasm and status/resource parity in
native C11 O0/O2, including a wrong-order oracle control. -
Extend #113's priced adapter regressions with exact retained retry I/O,
invalid quote preflight, and deadlines reached at journal acknowledgements.
Add #103's importedstd.bytesview-composition oracle across the Project
interpreter, native C11 O0/O2, and Core Wasm, including temporary cleanup. -
Add an explicit priced source-journal v4 route and private CLI config/receipt
v2 (#113). Integer currency-bound reservations remain separate from work
quotas and provider observations; replay retains unknown exposure and refuses
quote drift. Add the private CLI's one-hop priced-to-priced migration carry,
preserving cumulative reservations, observations, overage, and global money
ordinals under a non-widening compatible quote. Legacy source profiles remain
unchanged; unsupported profile conversion is refused. -
Construct ordinary imported function stubs from signatures without cloning
discarded bodies (#124). Preserve fitting graph receipts and add an uncached
fallback charging retained HIR plus the peak of sequential synthetic ASTs,
within the existing builder limit; cached frontends retain summed charges. -
Add opt-in, bounded current-thread workflow stage observations and an offline
campaign runner; compare exact cold/warm frontend products and prepared
traced/untraced products before timing. Measurements remain local evidence,
separate from canonical artifacts and authority (Refs #85). -
Pin cumulative durable source reservation boundaries at zero, exact, and
one-unit-over ceilings; terminal recovery retains accounting with zero
new proposal, model, or effect dispatches (Refs #113). -
Exercise eight borrowed byte-view call compositions across interpreter,
C11 O0/O2 and Core Wasm, including offset-sensitive forwarded views,
comparator rejection and the stable escaping-view diagnostic (Refs #103). -
Validate bounded Descriptor-v1 frames and versions in generated calling
consumers before exact pairing and provider admission; exercise canonical
shared mutations and byte-identical malformed configured descriptors in
Rust, C11, C++17, and TypeScript/Wasm (Refs #173). -
Add independent sensor-conjunction and stable three-job ordering benchmark
families with candidate-preserving hidden overlays and three-port negative
controls (Refs #106). -
Add private
semaprax-full source-live run|resume|migratecommands
(#113/#116), with held-directory checkpoints, exclusive writers, bounded
explicit task/read inputs and retained-Project bindings. A migration carries
the predecessor clock floor and nonrefundable work into one claimed
destination. Recorded-provider tests cover run, recovery and checked migration;
monetary pricing and the actual source repair workflow remain separate. -
Extend the catalog-normalizer source application with bounded JSONL record
counting and line/body limits (#124). Seven application cases execute on
the interpreter, C11 at both optimization levels and Core Wasm; a terminal
newline counting mutation is rejected. Full record normalization remains. -
Reduce the last-resort workspace graph construction estimate (#124) by
charging the largest sequential temporary import clone once. Imported
stubs release their discarded contract-vector buffers. Earlier accepted
receipts and the 18 MiB cap are preserved; core retries stay bounded. -
Add a fifth held-out cross-language benchmark family for half-open booking
conflicts (#106). Rust, TypeScript and SEMAPRAX share candidates across
public and hidden runs; an inclusive-end mutation passes public cases and
fails hidden adjacency cases on each port. Actual coding-agent trials remain. -
Migrate suspended source-mode agents through checked retained-Project A→B→C
handoffs (#115), preserving schema provenance and cumulative charged work.
Acknowledged migration results resume at Observe; initialization and completed
effects do not repeat. Lost acknowledgements, cancellation, deadline drift,
and malformed recovered State fail closed under explicit host-store freshness. -
Add private filesystem v3 checked atomic writes (#228), with inspectable
Published, NotPublished, and Uncertain outcomes and an exhaustive std.fs
variant wrapper. Interpreter, native C11 and Core Wasm preserve the separate
callback failure channel and legacy v2 behavior. Graph v46 binds the new
operation; compact conformance fixtures keep the existing construction limit. -
Add a fourth cross-language benchmark family for a multi-module invoice
calculation (#106). Candidate-preserving hidden entry modules distinguish
whole-subtotal rounding from per-item rounding in Rust, TypeScript, and
SEMAPRAX Project execution. This adds corpus coverage, not coding-agent trials. -
Separate native public-generic allocation accounting from the 16 MiB
logical carrier limit (#250), allowing metadata and overlapping full input
and result payloads. Exercise exact-byte boundaries across local native,
interpreter, and Wasm fixtures, with bounded allocation failure and cleanup. -
Pin Cargo, rustc, and rustdoc in the generated Rust consumer's MSRV gate
(#226). Selecting Cargo alone had allowed the ambient newer compiler to
satisfy the check. Native allocator capacity remains tracked in #250. -
Cover drop-free nested variant payloads through interaction-schema derivation,
canonical decoding, and hostile nested-field refusal (#216). Correct the
proposed checked-write taxonomy to distinguish proven non-publication from
phase-ambiguous legacy I/O errors (#228); missing-parent provider regressions
preserve the current fail-stop operation. -
Add a separate structured-envelope validation task to the cross-language
corpus (#106), with candidate-preserving hidden tests and a negative control
for wrong error precedence and removed visible assertions. The additive
SEMAPRAX Project adapter leaves the original pilot and task routes intact. -
Connect source checkpoint execution to the checked iterative driver (#113).
Journal v2 reserves fresh fuel on replay, shares one model-budget ledger,
persists optional usage and terminal evidence, refuses uncertain redispatch,
and retains partial failure evidence. The OpenCode durable source borrows
that ledger; source migration and a durable CLI remain pending. -
Exercise lazy boolean operands containing checked division failure through
the differential corpus (#103), including interpreter, native O0/O2, and
Core-Wasm observations with explicit lane results. -
Derive Assurance Manifest result-ownership and resource-cleanup obligations
from independently revalidated HIR (#214), and keep candidate summaries
aligned. Architecture-law derivation and workspace binding remain pending. -
Complete the documented-limit decision for compiler capacity (#241): name
the distinct checked-cache ceiling in SPX-G256, pin its inclusive boundary,
and state graph/replay limits and the source-versus-runtime byte-copy guard. -
Run TypeScript/Wasm consumer Node entry points with relative fixture paths
to avoid Windows extended-path main-module resolution failures. Complete
private OpenCode/source-journal documentation metadata and catalog entries. -
Include Cargo example targets in the CI unit shard, preserving exhaustive
workspace inventory and refusal of unknown target kinds. -
Add an explicit OpenCode proposal-attempt checkpoint boundary over the same
source journal and accounting ledger (#113). It validates bound context and
phase before charging, acknowledges intent before transport, and persists
the outcome before exposing response text. Full source replay remains pending. -
Add bounded source checkpoint primitives with strict causal validation,
poisoned writes after acknowledgement loss, and restoration through the
existing charge/deadline ledger (#113). Source runtime replay, provider
receipt persistence and migration integration remain pending. -
Derive cached Project Agent interaction facts from retained authenticated
source programs, fixing false SPX-G564 failures without reparsing (#85).
Repair the embedding-example index and Clippy CI blockers, and provision
pinned Clippy for the public-generic consumer job. -
Provision pinned TypeScript 5.8.3 for the public-generic hosted job and
fail closed on missing consumer tools; record platform/toolchain identities
with separate Unix and Windows preflights (#163). Fresh hosted evidence
remains pending. -
Check the OpenCode source route's shared deadline around deterministic stages,
proposal admission, effect dispatch and result publication (#113), preserving
earlier selected failures. Durable source failure evidence remains pending. -
Require explicit cumulative reservations for OpenCode source attempts and
retain their bounded usage observations across malformed retries and failures
(#113). Check the shared absolute deadline at settlement and later kernel
boundaries; source recovery and migration accounting remain separate work. -
Connect one explicitly configured free OpenCode provider to the existing
source-feedback driver, preserving canonical proposal admission (#112).
Bound Unix process output/cancellation, bind real CLI receipts, preserve
reported usage and redact provider error categories. The fixed local live
smoke reached Complete; broader hosted/provider support remains separate. -
Reuse exact retained source ASTs during cached Project finalization and
prelude-bound revision replay (#85). Remove nine hidden public parser calls
from unchanged calculator builds in both cache modes, preserving revision
hashes and admission checks; no timing improvement is claimed. -
Add explicit untraced prepared Project execution with unchanged traced
behavior, fuel, cancellation and revision replacement. Add matching cold
and prepared benchmark products and truthful platform-specific memory
observations (#85); no new performance measurements are claimed. -
Persist migrated live-kernel handoffs, state and destination journals in one
bounded canonical checkpoint before dispatch, with recovery and store-failure
regressions (#115). Checked source migration and cumulative-chain integration
remain open. -
Add a non-editing OpenCode availability smoke and bind archived event streams
to the matching exported session and frozen prompt (#105/#112). This is
provider availability evidence, not a coding-agent trial or live-driver adapter. -
Correct the Workspace Semantic Graph and Context/Impact/Review workspace
limit projections to report the enforced 18 MiB builder ceiling from one
renderer (#248). The 16 MiB analysis/cache ceilings remain separate. Re-pin
exact artifact hashes after verifying that restoring only the old limit
and dependent digests reproduces every previous known answer. -
Repair standard-library conformance registration for guarded logging and
std.metrics, and synchronize the generated auth/TOML catalogs (#102). -
Exercise frozen execution evidence around a live fixture invocation and
clarify that terminal journal replay preserves its case and carrier digest,
not the original carrier payload (#108). -
Add a standalone Rust consumer for the public check/format/graph embedding
facade, with its own offline lockfile and explicit checkout-only scope (#203). -
Rewrite the
SPX-H006cleanup-replay path-budget diagnostic's message to
name the actual cost driver instead of only the budget it exceeded. The
previous wording ("cleanup replay path bound exceeds the global path
budget") told an author nothing about why: the real driver is
combinatorial multiplication of independently-combined branch outcomes
within one function (2^N terminal paths for N such branches), not raw
branch count, so the natural fix an author reaches for on reading the old
message - splitting into helper functions - does not help unless it breaks
the combination. The new message states the measured path count and budget,
names the combinatorial driver, and names an actionable remedy (make the
branches mutually exclusive, or combine their results across separate
calls). The diagnostic code is unchanged; per issue #241, neither
SPX-G171's workspace-graph byte budget norSPX-H006's path budget was
raised, because no session has evidence that a higher value keeps the
workspace graph or the semantic cache finite - both remain documented,
regression-pinned limits in the completion matrix rather than raised
ceilings. A boundary fixture pinning the exact measured terminal-path count
at the crossover (98,300 paths for 15 independent branch terms, not the
naive2^15 = 32,768estimate the previous fixture comment assumed without
checking) replaces the earlier code-only assertion, plus a dedicated
regression that fails if the message regresses to the old cause-free
wording. -
Freeze the Public Generic Boundary Profile, Descriptor and Carrier v1, and
add a reference codec for the descriptor and carrier wire formats. The same
callable generic boundary had been described three times by three
overlapping issue packs, with a real scope conflict between a minimal
one-owned-Bytesslice and a contract admitting nested finite records. One
admission profile now settles it with an explicit in, deferred and excluded
table, so downstream implementation work has a single contract to build
against rather than three. Two classifications - owned generic variants and
public generic templates - are recorded as contested and awaiting review
rather than silently decided. -
Specify and implement the Live Invocation Contract v1: invocation identity
that survives retry, resume and recovery, a causal journal with
table-driven validation, and a provider-independentmodel.invokeeffect
with an explicit capability requirement, a closed failure domain and
cancellation checkpoints. Replay makes zero dispatches, and an unrecorded
result can never be reconstructed by hashing because the journal carries
response bytes rather than only a digest. Fixture transport only: no
provider binding, no deployment wiring and no live model call. -
Introduce Assurance Manifest v1, a deterministic per-obligation manifest
bound to exact source bytes that fails closed on drift. Obligation identity
keys to a declaration's persistent stable id rather than a byte offset, so
it survives a pure formatting change, and the assurance lattice is a
genuine partial order rather than a single ranking - compiler-proved,
SMT-proved and model-checked are deliberately incomparable. External
records let later formal-method backends contribute without this module
changing, so a simple candidate summary never waits on formal proof. -
Freeze the catalog-normalizer acceptance application and an independent
oracle: 25 requirement ids, 51 known-answer cases split into published and
hidden, and six runnable negative controls that each provably diverge from
the correct output. The hidden-case boundary is a review policy rather than
cryptographic isolation, and the specification says so plainly instead of
implying a guarantee the repository cannot enforce. -
Preserve comments and unrelated bytes in the v2
ReplaceExpressionroute.
The transaction previously rejected any workspace containing a comment
before it even selected an expression, because the shared candidate rebuild
always reprinted through the comment-oblivious canonical formatter. The
edited file may now carry comments, preserved by a span-scoped splice that
is independently reparsed and required to match byte for byte; a comment
overlapping the edited span is refused rather than silently relocated.
Every other source keeps the exact comment-free requirement. -
Resolve
core.optionin theuseful-text-consumer.v1linker, which never
seeded the compiler prelude its Useful Data sibling relies on, so any
match byte_get(...)in a Project-linked text package failed validation.
The profile's public signature restrictions are unchanged and pinned by a
test. -
Bind release publication to the exact-tag gate explicitly, and add a
reconciliation check for release claims. This caught a live defect: the
README claimed v0.4.1 was the published tag while citing v0.4.0's date,
commit and anchor. -
Connect an external coding-agent runner to the existing comparison ledger,
reusing its plan, trial, ledger, observation and audit schemas unmodified.
A candidate cannot escape its sandbox, write the finalized ledger, or claim
its own acceptance: a backend that reports every criterion passed while
leaving the work undone is still scored as failed. Offline fixture backend
only; the paid paired pilot needs an approved model budget. -
Correct a stale claim in the doctor provisioner specification, which stated
the provisioned gate had never executed when nine real runs exist, the most
recent of which failed. -
Give the MSRV shards the same time budget as the identical
verify-tests
command. Both runscripts/ci-msrv.py --shard, but the MSRV job had 40
minutes against that job's 90 while compiling the same workspace on an
older toolchain. Theintegration-1shard was cut off mid-test on two
runs while finishing in about 35 minutes on others, so its result reported
the runner's speed rather than the shard's outcome - and a cancelled
blocker fails the release gate exactly like a real failure. The coverage
guarantees are unchanged: the contract still forbidscontinue-on-error,
--no-fail-fast,--exclude,--skipand caching, and still requires
the full check and every shard.
These unsigned archives are not notarized and make no cross-host reproducible-build claim.
SHA-256 checksums are integrity facts, not signatures.