Skip to content

SEMAPRAX v0.5.0

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 16 Sep 09:43
· 389 commits to main since this release

SEMAPRAX v0.5.0 is pre-alpha research software.

Changes

  • Bind effect-free retained source job handlers to persisted deployment
    descriptors before claim, using the existing durable job runtime and
    checked interpreter; refuse stale roots and handler substitutions (#192).

  • Complete the ten-row feature-composition inventory, exact ownership-profile
    refusal regression, and provisioned strict differential campaign route
    with explicit CI selections and nonzero-case enforcement (#103).

  • Add exact SDK-envelope byte reservations to durable retries with frozen V2
    journal preservation, canonical V3 recovery, and post-poll cancellation
    checks (#179). Tighten provider conformance around request admission,
    completion, final bytes, and usage regressions with corpus V2 (#181).

  • Add a checked two-call offline repair loop and private CLI demo with
    bounded candidate edits, diagnostic feedback, read-only review evidence,
    and terminal journal replay (#116). Extend imported owned cursor failure
    composition with exact Wasm cleanup-order and sticky-status controls (#103).

  • Account compact workspace validation clones before allocation and schedule
    the final uncached graph phase by temporary HIR overhead without raising
    its cap (#124). Add decoded ID bounds and allocation-free token equality
    to the catalog helper application with cross-backend oracle checks.

  • Add generic durable retry/failover with acknowledged attempt journals,
    exact retained execution/schema/model bindings, non-widening source and
    deployment limits, request-seed checks, and conservative recovery (#179).
    This is local host composition; checkpoints do not prove provider identity
    or billing.

  • Add V6 durable source-model quote accounting with nonrefundable observed and
    unknown usage, absolute deadlines, cumulative migration carry, and optional
    request/response byte ceilings (#113). Retain observed quote overages in
    ordinary source-model admission as well.

  • Retain exact generic model request/response reservations in the additive
    priced I/O envelope, cross-bind successor carry, and reject noncanonical
    recovery requests (#113). Add store-backed typed source-model execution with
    acknowledged intents, exact raw settlements, and no uncertain redispatch
    (#177). Release full sequential workspace HIR after compact validation facts
    and selected output carriers are extracted (#124).

  • Pair generic live work reservations with durable monetary accounting (#113),
    and enforce opt-in source-model ceilings before adapter construction (#177,
    #179). Add a final uncached graph retry that charges retained output vectors
    while preserving earlier successful budget receipts (#124).

  • Bind typed live model operations to deployment selection and commit their
    redacted attempt evidence in an additive execution root (#177). Propagate
    remaining host deadlines and distinguish reserved, observed and unknown
    provider charges in a separate Runtime v1 receipt (#113).

  • Add counterbalanced pilot scheduling, isolated MCP tools for both comparison
    lanes, retained candidate source bytes and exact transport archives (#105).
    Trial capture remains separate from eligible observations and review.

  • Preserve pre-dispatch OpenCode cancellation as a zero-call cancellation
    failure (#113). A changed journal or claimed dispatch without a receipt
    remains a model failure; unresolved attempts cannot become clean refusals.

  • Add direct owned String variant payloads (#216), with canonical String
    lifecycle replay, own/borrow matching and backend cleanup. Scalar-match guard
    and arm temporaries settle through exact cleanup regions. Generic String
    substitutions and nested owned-record variant payloads remain restricted.

  • Add explicit Rust-host Argon2id password hashing, authenticated sessions and
    signup/login/logout composition (#191). Persist job cancellation and recurring
    schedule advancement with checked arithmetic and replay evidence (#192).

  • Add checked-source HTTPS POST across explicit provider, native C11 and
    Core-Wasm/npm fixture paths (#193), with bounded body/response bytes, explicit
    destination authorization and no automatic retry or redirect for POST.

  • Add an explicit native HTTPS transport for provider adapters (#181), with
    injected credentials, bounded buffered responses and conservative dispatch
    uncertainty. Extend compact task context with ordered seeds, revision binding
    and selectable token accounting (#197). Add a host-driven single-job
    checkpoint runtime and evidence-based recovery (#192).

  • Drive bounded retries and ordered failover through injected provider adapters
    (#179), preserving charged attempts and stopping on uncertain outcomes.
    Add host-transport protocol adapters for Responses and Messages (#181).
    Recheck cancellation and deadlines when streaming settlement returns.
    Add an eighth cross-language task family exercising owned byte mapping and
    hidden-oracle rejection in Rust, TypeScript and SEMAPRAX (#106).

  • Import bounded provider invoice evidence through explicit verifiers and retain
    reconciliation results (#180). Enforce source usage consistency and complete
    audit-view disclosure, payload association and truthful privacy claims; add
    canonical audit replay and direct receipt emission from live run evidence.

  • Decode canonical model receipts with strict bounds and enrich actual generic
    and source attempt journals using retained root, request and host metadata (#180).
    Join explicit adapter observations and provider usage without inventing
    missing measurements; preserve failure and unresolved lifecycle evidence.

  • Capture ordered provider adapter attempts and replay retained chunks against
    actual generic/source runtime schemas (#178/#180). Bind generic settlements
    to validated journal requests and responses; compare provider token and cost
    observations independently during invoice reconciliation.

  • Validate streamed nested Proposal fields, variant cases, exact scalars and
    text/byte bounds from compiled type tables before final decode (#178).
    Expose read-only grammar states and bounded work counters; extend the
    generated TypeScript/Python/Rust client harness with adversarial chunking.

  • Add versioned selective-dictionary model-text projections to CLI, retained
    service and compatibility negotiation (#201). Connect streaming proposals to
    Direct Runtime v2 typed effects and reject mismatched compiled schema envelopes
    while streaming (#178); nested semantic admission remains in the full decoder.

  • Expose compact projections through CLI replay and retained service/MCP routes,
    with explicit format/profile negotiation and offline model-token measurement
    tooling (#201). Introduce Rust embedding API v2 for mandatory analysis/execution input caps, add
    cooperative request cancellation, and verify opaque session release (#203).

  • Add authoritative task-context, Project API, candidate-diff, and Agent graph
    compact profiles with regeneration-bound replay (#201). Extend Rust embedding
    negotiation, cancellation, and the external consumer (#203). Connect the
    source Proposal grammar to incremental decoding and an explicit per-attempt
    provider adapter factory with bounded iterative context (#178).

  • Connect the streaming Proposal decoder to the provider adapter and generic
    live-kernel seams (#178), and compose token/cost/call policy with the live
    work-budget hook (#179). Extend the embedding facade with opaque in-memory
    Project sessions, atomic refresh, semantic query, and candidate replay (#203).

  • Add journal-derived model-call receipts (#180) for generic live runs and
    authenticated source checkpoints, including exact replay and Audit Capsule
    object references. Unrecorded timing and billing stay unknown. Harden enriched
    receipt replay against contradictory response states and decode refusals.
    Extend the Rust source embedding facade (#203) with bounded context v1/v2
    queries and explicitly authorized, cancellable, fuel-bounded interpretation.

  • Implement additive Project Assurance Manifest v1 (#214): a canonical,
    integrity-bound envelope bound to one retained Project, workspace
    revision, ProgramRoot, and complete ordered source inventory. The profile
    deduplicates shared entry/public/test HIR obligations, records explicit
    unselected coverage, and admits only held forbid_reaches architecture laws;
    the existing single-file Assurance Manifest v1 bytes remain unchanged.

  • Add additive source-journal I/O v5 accounting and private CLI config/receipt
    v3 (#113). Authenticated attempt rows reserve exact prompt bytes and bounded
    response capacity cumulatively; recovery and compatible migration retain
    reservations without profile conversion. Legacy source journal and CLI
    profiles remain unchanged. Add #103's result-allocation rejection case with
    ordered input release in interpreter/Wasm and status/resource parity in
    native C11 O0/O2, including a wrong-order oracle control.

  • Extend #113's priced adapter regressions with exact retained retry I/O,
    invalid quote preflight, and deadlines reached at journal acknowledgements.
    Add #103's imported std.bytes view-composition oracle across the Project
    interpreter, native C11 O0/O2, and Core Wasm, including temporary cleanup.

  • Add an explicit priced source-journal v4 route and private CLI config/receipt
    v2 (#113). Integer currency-bound reservations remain separate from work
    quotas and provider observations; replay retains unknown exposure and refuses
    quote drift. Add the private CLI's one-hop priced-to-priced migration carry,
    preserving cumulative reservations, observations, overage, and global money
    ordinals under a non-widening compatible quote. Legacy source profiles remain
    unchanged; unsupported profile conversion is refused.

  • Construct ordinary imported function stubs from signatures without cloning
    discarded bodies (#124). Preserve fitting graph receipts and add an uncached
    fallback charging retained HIR plus the peak of sequential synthetic ASTs,
    within the existing builder limit; cached frontends retain summed charges.

  • Add opt-in, bounded current-thread workflow stage observations and an offline
    campaign runner; compare exact cold/warm frontend products and prepared
    traced/untraced products before timing. Measurements remain local evidence,
    separate from canonical artifacts and authority (Refs #85).

  • Pin cumulative durable source reservation boundaries at zero, exact, and
    one-unit-over ceilings; terminal recovery retains accounting with zero
    new proposal, model, or effect dispatches (Refs #113).

  • Exercise eight borrowed byte-view call compositions across interpreter,
    C11 O0/O2 and Core Wasm, including offset-sensitive forwarded views,
    comparator rejection and the stable escaping-view diagnostic (Refs #103).

  • Validate bounded Descriptor-v1 frames and versions in generated calling
    consumers before exact pairing and provider admission; exercise canonical
    shared mutations and byte-identical malformed configured descriptors in
    Rust, C11, C++17, and TypeScript/Wasm (Refs #173).

  • Add independent sensor-conjunction and stable three-job ordering benchmark
    families with candidate-preserving hidden overlays and three-port negative
    controls (Refs #106).

  • Add private semaprax-full source-live run|resume|migrate commands
    (#113/#116), with held-directory checkpoints, exclusive writers, bounded
    explicit task/read inputs and retained-Project bindings. A migration carries
    the predecessor clock floor and nonrefundable work into one claimed
    destination. Recorded-provider tests cover run, recovery and checked migration;
    monetary pricing and the actual source repair workflow remain separate.

  • Extend the catalog-normalizer source application with bounded JSONL record
    counting and line/body limits (#124). Seven application cases execute on
    the interpreter, C11 at both optimization levels and Core Wasm; a terminal
    newline counting mutation is rejected. Full record normalization remains.

  • Reduce the last-resort workspace graph construction estimate (#124) by
    charging the largest sequential temporary import clone once. Imported
    stubs release their discarded contract-vector buffers. Earlier accepted
    receipts and the 18 MiB cap are preserved; core retries stay bounded.

  • Add a fifth held-out cross-language benchmark family for half-open booking
    conflicts (#106). Rust, TypeScript and SEMAPRAX share candidates across
    public and hidden runs; an inclusive-end mutation passes public cases and
    fails hidden adjacency cases on each port. Actual coding-agent trials remain.

  • Migrate suspended source-mode agents through checked retained-Project A→B→C
    handoffs (#115), preserving schema provenance and cumulative charged work.
    Acknowledged migration results resume at Observe; initialization and completed
    effects do not repeat. Lost acknowledgements, cancellation, deadline drift,
    and malformed recovered State fail closed under explicit host-store freshness.

  • Add private filesystem v3 checked atomic writes (#228), with inspectable
    Published, NotPublished, and Uncertain outcomes and an exhaustive std.fs
    variant wrapper. Interpreter, native C11 and Core Wasm preserve the separate
    callback failure channel and legacy v2 behavior. Graph v46 binds the new
    operation; compact conformance fixtures keep the existing construction limit.

  • Add a fourth cross-language benchmark family for a multi-module invoice
    calculation (#106). Candidate-preserving hidden entry modules distinguish
    whole-subtotal rounding from per-item rounding in Rust, TypeScript, and
    SEMAPRAX Project execution. This adds corpus coverage, not coding-agent trials.

  • Separate native public-generic allocation accounting from the 16 MiB
    logical carrier limit (#250), allowing metadata and overlapping full input
    and result payloads. Exercise exact-byte boundaries across local native,
    interpreter, and Wasm fixtures, with bounded allocation failure and cleanup.

  • Pin Cargo, rustc, and rustdoc in the generated Rust consumer's MSRV gate
    (#226). Selecting Cargo alone had allowed the ambient newer compiler to
    satisfy the check. Native allocator capacity remains tracked in #250.

  • Cover drop-free nested variant payloads through interaction-schema derivation,
    canonical decoding, and hostile nested-field refusal (#216). Correct the
    proposed checked-write taxonomy to distinguish proven non-publication from
    phase-ambiguous legacy I/O errors (#228); missing-parent provider regressions
    preserve the current fail-stop operation.

  • Add a separate structured-envelope validation task to the cross-language
    corpus (#106), with candidate-preserving hidden tests and a negative control
    for wrong error precedence and removed visible assertions. The additive
    SEMAPRAX Project adapter leaves the original pilot and task routes intact.

  • Connect source checkpoint execution to the checked iterative driver (#113).
    Journal v2 reserves fresh fuel on replay, shares one model-budget ledger,
    persists optional usage and terminal evidence, refuses uncertain redispatch,
    and retains partial failure evidence. The OpenCode durable source borrows
    that ledger; source migration and a durable CLI remain pending.

  • Exercise lazy boolean operands containing checked division failure through
    the differential corpus (#103), including interpreter, native O0/O2, and
    Core-Wasm observations with explicit lane results.

  • Derive Assurance Manifest result-ownership and resource-cleanup obligations
    from independently revalidated HIR (#214), and keep candidate summaries
    aligned. Architecture-law derivation and workspace binding remain pending.

  • Complete the documented-limit decision for compiler capacity (#241): name
    the distinct checked-cache ceiling in SPX-G256, pin its inclusive boundary,
    and state graph/replay limits and the source-versus-runtime byte-copy guard.

  • Run TypeScript/Wasm consumer Node entry points with relative fixture paths
    to avoid Windows extended-path main-module resolution failures. Complete
    private OpenCode/source-journal documentation metadata and catalog entries.

  • Include Cargo example targets in the CI unit shard, preserving exhaustive
    workspace inventory and refusal of unknown target kinds.

  • Add an explicit OpenCode proposal-attempt checkpoint boundary over the same
    source journal and accounting ledger (#113). It validates bound context and
    phase before charging, acknowledges intent before transport, and persists
    the outcome before exposing response text. Full source replay remains pending.

  • Add bounded source checkpoint primitives with strict causal validation,
    poisoned writes after acknowledgement loss, and restoration through the
    existing charge/deadline ledger (#113). Source runtime replay, provider
    receipt persistence and migration integration remain pending.

  • Derive cached Project Agent interaction facts from retained authenticated
    source programs, fixing false SPX-G564 failures without reparsing (#85).
    Repair the embedding-example index and Clippy CI blockers, and provision
    pinned Clippy for the public-generic consumer job.

  • Provision pinned TypeScript 5.8.3 for the public-generic hosted job and
    fail closed on missing consumer tools; record platform/toolchain identities
    with separate Unix and Windows preflights (#163). Fresh hosted evidence
    remains pending.

  • Check the OpenCode source route's shared deadline around deterministic stages,
    proposal admission, effect dispatch and result publication (#113), preserving
    earlier selected failures. Durable source failure evidence remains pending.

  • Require explicit cumulative reservations for OpenCode source attempts and
    retain their bounded usage observations across malformed retries and failures
    (#113). Check the shared absolute deadline at settlement and later kernel
    boundaries; source recovery and migration accounting remain separate work.

  • Connect one explicitly configured free OpenCode provider to the existing
    source-feedback driver, preserving canonical proposal admission (#112).
    Bound Unix process output/cancellation, bind real CLI receipts, preserve
    reported usage and redact provider error categories. The fixed local live
    smoke reached Complete; broader hosted/provider support remains separate.

  • Reuse exact retained source ASTs during cached Project finalization and
    prelude-bound revision replay (#85). Remove nine hidden public parser calls
    from unchanged calculator builds in both cache modes, preserving revision
    hashes and admission checks; no timing improvement is claimed.

  • Add explicit untraced prepared Project execution with unchanged traced
    behavior, fuel, cancellation and revision replacement. Add matching cold
    and prepared benchmark products and truthful platform-specific memory
    observations (#85); no new performance measurements are claimed.

  • Persist migrated live-kernel handoffs, state and destination journals in one
    bounded canonical checkpoint before dispatch, with recovery and store-failure
    regressions (#115). Checked source migration and cumulative-chain integration
    remain open.

  • Add a non-editing OpenCode availability smoke and bind archived event streams
    to the matching exported session and frozen prompt (#105/#112). This is
    provider availability evidence, not a coding-agent trial or live-driver adapter.

  • Correct the Workspace Semantic Graph and Context/Impact/Review workspace
    limit projections to report the enforced 18 MiB builder ceiling from one
    renderer (#248). The 16 MiB analysis/cache ceilings remain separate. Re-pin
    exact artifact hashes after verifying that restoring only the old limit
    and dependent digests reproduces every previous known answer.

  • Repair standard-library conformance registration for guarded logging and
    std.metrics, and synchronize the generated auth/TOML catalogs (#102).

  • Exercise frozen execution evidence around a live fixture invocation and
    clarify that terminal journal replay preserves its case and carrier digest,
    not the original carrier payload (#108).

  • Add a standalone Rust consumer for the public check/format/graph embedding
    facade, with its own offline lockfile and explicit checkout-only scope (#203).

  • Rewrite the SPX-H006 cleanup-replay path-budget diagnostic's message to
    name the actual cost driver instead of only the budget it exceeded. The
    previous wording ("cleanup replay path bound exceeds the global path
    budget") told an author nothing about why: the real driver is
    combinatorial multiplication of independently-combined branch outcomes
    within one function (2^N terminal paths for N such branches), not raw
    branch count, so the natural fix an author reaches for on reading the old
    message - splitting into helper functions - does not help unless it breaks
    the combination. The new message states the measured path count and budget,
    names the combinatorial driver, and names an actionable remedy (make the
    branches mutually exclusive, or combine their results across separate
    calls). The diagnostic code is unchanged; per issue #241, neither
    SPX-G171's workspace-graph byte budget nor SPX-H006's path budget was
    raised, because no session has evidence that a higher value keeps the
    workspace graph or the semantic cache finite - both remain documented,
    regression-pinned limits in the completion matrix rather than raised
    ceilings. A boundary fixture pinning the exact measured terminal-path count
    at the crossover (98,300 paths for 15 independent branch terms, not the
    naive 2^15 = 32,768 estimate the previous fixture comment assumed without
    checking) replaces the earlier code-only assertion, plus a dedicated
    regression that fails if the message regresses to the old cause-free
    wording.

  • Freeze the Public Generic Boundary Profile, Descriptor and Carrier v1, and
    add a reference codec for the descriptor and carrier wire formats. The same
    callable generic boundary had been described three times by three
    overlapping issue packs, with a real scope conflict between a minimal
    one-owned-Bytes slice and a contract admitting nested finite records. One
    admission profile now settles it with an explicit in, deferred and excluded
    table, so downstream implementation work has a single contract to build
    against rather than three. Two classifications - owned generic variants and
    public generic templates - are recorded as contested and awaiting review
    rather than silently decided.

  • Specify and implement the Live Invocation Contract v1: invocation identity
    that survives retry, resume and recovery, a causal journal with
    table-driven validation, and a provider-independent model.invoke effect
    with an explicit capability requirement, a closed failure domain and
    cancellation checkpoints. Replay makes zero dispatches, and an unrecorded
    result can never be reconstructed by hashing because the journal carries
    response bytes rather than only a digest. Fixture transport only: no
    provider binding, no deployment wiring and no live model call.

  • Introduce Assurance Manifest v1, a deterministic per-obligation manifest
    bound to exact source bytes that fails closed on drift. Obligation identity
    keys to a declaration's persistent stable id rather than a byte offset, so
    it survives a pure formatting change, and the assurance lattice is a
    genuine partial order rather than a single ranking - compiler-proved,
    SMT-proved and model-checked are deliberately incomparable. External
    records let later formal-method backends contribute without this module
    changing, so a simple candidate summary never waits on formal proof.

  • Freeze the catalog-normalizer acceptance application and an independent
    oracle: 25 requirement ids, 51 known-answer cases split into published and
    hidden, and six runnable negative controls that each provably diverge from
    the correct output. The hidden-case boundary is a review policy rather than
    cryptographic isolation, and the specification says so plainly instead of
    implying a guarantee the repository cannot enforce.

  • Preserve comments and unrelated bytes in the v2 ReplaceExpression route.
    The transaction previously rejected any workspace containing a comment
    before it even selected an expression, because the shared candidate rebuild
    always reprinted through the comment-oblivious canonical formatter. The
    edited file may now carry comments, preserved by a span-scoped splice that
    is independently reparsed and required to match byte for byte; a comment
    overlapping the edited span is refused rather than silently relocated.
    Every other source keeps the exact comment-free requirement.

  • Resolve core.option in the useful-text-consumer.v1 linker, which never
    seeded the compiler prelude its Useful Data sibling relies on, so any
    match byte_get(...) in a Project-linked text package failed validation.
    The profile's public signature restrictions are unchanged and pinned by a
    test.

  • Bind release publication to the exact-tag gate explicitly, and add a
    reconciliation check for release claims. This caught a live defect: the
    README claimed v0.4.1 was the published tag while citing v0.4.0's date,
    commit and anchor.

  • Connect an external coding-agent runner to the existing comparison ledger,
    reusing its plan, trial, ledger, observation and audit schemas unmodified.
    A candidate cannot escape its sandbox, write the finalized ledger, or claim
    its own acceptance: a backend that reports every criterion passed while
    leaving the work undone is still scored as failed. Offline fixture backend
    only; the paid paired pilot needs an approved model budget.

  • Correct a stale claim in the doctor provisioner specification, which stated
    the provisioned gate had never executed when nine real runs exist, the most
    recent of which failed.

  • Give the MSRV shards the same time budget as the identical verify-tests
    command. Both run scripts/ci-msrv.py --shard, but the MSRV job had 40
    minutes against that job's 90 while compiling the same workspace on an
    older toolchain. The integration-1 shard was cut off mid-test on two
    runs while finishing in about 35 minutes on others, so its result reported
    the runner's speed rather than the shard's outcome - and a cancelled
    blocker fails the release gate exactly like a real failure. The coverage
    guarantees are unchanged: the contract still forbids continue-on-error,
    --no-fail-fast, --exclude, --skip and caching, and still requires
    the full check and every shard.

These unsigned archives are not notarized and make no cross-host reproducible-build claim.
SHA-256 checksums are integrity facts, not signatures.