Skip to content

SEMAPRAX v0.6.0

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 30 Sep 18:08
· 1931 commits to main since this release

SEMAPRAX v0.6.0 is alpha research software.

Changes

  • Keep the frozen private Component v7 WIT identity at 0.5.0 while the crate
    advances to 0.6.0, and repin the version-bound public-generic Component
    known answers against independently emitted success and contract-failure
    fixtures. The four exact Component CI contract tests pass locally; hosted
    release evidence remains pending.

  • Pin the Wavect GmbH release verifier to GitHub's immutable owner/repository
    OIDC subject and require matching subject and ID extensions in the verified
    Fulcio certificate. This is local offline verification, not hosted signature
    evidence until the authorized v0.6.0 tag gate publishes immutable assets.

  • Observe Core Wasm record-Bytes copy-out only after the generated Node
    facade returns owned bytes from its settled JS arena, with strict transport
    refusal controls. Physical Wasm free, instruction-fuel parity and hosted
    target acceptance remain open.

  • Project a frozen malformed-result carrier recipe through generated TypeScript
    against the compiler-produced checked Wasm provider, alongside exact
    descriptor/binding and once-only result-release controls. This is local
    compiled-provider evidence, not the full hostile or hosted R06 matrix.

  • Bridge explicit held signed root/leaf generations into the existing resolver
    subject cache after fresh lock-bound artifact reads. CLI lock-bound fetch and
    the bridge share the extracted held cache writer; copied subjects carry no
    persistent signature/freshness authority and failures retain uncertain prefixes.

  • Add explicit offline artifact reads from a held signed Registry-v3 generation,
    bound to exact Lock-v3 and independently admitted manifests. Reads replay
    trusted-time freshness and recheck ACTIVE before returning immutable bytes;
    no reusable bearer token, ambient path read or execution authority is added.

  • Add an explicit local Registry-v3 generation store coordinating signed trust,
    full root/leaf Lock-v3 selection and exact core artifacts, with one-way v1
    migration and exact interrupted-commit recovery. Receipts remain evidence;
    no fetch/read/execution capability or hosted registry support is added.

  • Add pure offline signed metadata-v2 verification for producer-backed
    Registry-v3 linked roots and leaves, exact lock/artifact checks, and a one-way
    Checkpoint-v2 protocol floor preserving prior version/digest high-water marks.
    Candidates remain non-authoritative; managed-host/fetch integration is separate.

  • Add independently verified dependency-free Build-v1 leaf manifests and an
    additive producer-backed Registry-v3. A real linked root/leaf catalog now
    reproduces Lock-v3 bytes and checks exact source/report/dependency closure;
    focused tamper, yank, missing-leaf and API-claim controls pass locally.
    Existing profiles remain unchanged; trusted v3 distribution is separate.

  • Add a separate private authenticated-native-allocating.v1 handoff for a
    closed checked Bytes body/callee subset. An explicit-context reservation,
    canonical lease settlement and all-leaf result preflight preserve sticky
    failure through generated C11/C++17 callers. Focused controls cover real
    allocating callees, reservation/body/postcondition refusals, oversized
    results and missing-drop/dispatch controls; the actual legacy runtime
    emitter retains its frozen bytes. General-body, cross-backend, hosted and
    public acceptance remain open.

  • Add a separate private authenticated-native-moves.v1 handoff that executes
    checked flat-Bytes record movement bodies through generated C11/C++17
    callers. Focused physical controls cover both branches, malformed/legacy
    refusals, identity-body omission, and postcondition-failure settlement;
    allocating/status-producing bodies and public acceptance remain open.

  • Add an explicit local registry trust host with held owner-private storage,
    independently pinned bootstrap, immutable signed-evidence/checkpoint and
    selected-artifact generations, one durable ACTIVE pivot, and exact
    fail-stop recovery. Focused local crash-point and hostile-state tests pass;
    this adds no fetch/network authority or physical power-loss claim.

  • Correct catalog-normalizer JSON control escapes at \\u0010–\\u001f
    and exercise ten oracle-frozen controls across interpreter, native C and
    Core Wasm. The maximal 65,536-byte response still exhausts the unchanged
    100M-step fuel bound, so the catalog acceptance milestone remains open.

  • Add a TUF-style local registry verifier with independently installed roots,
    namespace-delegated Ed25519 thresholds, dual-threshold root rotation, exact
    registry/manifest bindings, freshness, rollback and yank checks. Results are
    non-authoritative checkpoint candidates; the managed durable host above is
    separate, and trusted distribution remains open.

  • Compact catalog-normalizer scalar projection helpers and avoid a repeated
    label walk when summing accepted record quantities. The 18-case focused
    interpreter/native C O0/O2/Core Wasm oracle selector passes, but the exact
    65,536-byte/256-record plain response still exhausts 100M fuel; enriched
    maximal output and the full owning gate remain unverified (#286 open).

  • Add a dispatch-only Windows confinement runtime gate that requires nonzero
    execution of restricted-token child launch, job limit/membership, scratch
    DACL, descendant refusal and test-owned descendant timeout, normal/nonzero
    settlement, timeout cancellation, and filesystem-stage refusal with
    handle-count cleanup. The gate uses
    test-key-signed capsule fixture bytes (not a release trust anchor), requires
    successful taskkill /T and direct Cargo PID absence on
    timeout, and checks exact marker/scratch cleanup. Descendant quiescence is
    not independently enumerated. The original two-test slice passed on exact
    checkout c6bf9902; the historical five-test selector passed in hosted
    Windows run 35988348061 at 3d4220b6. Current source uses the shared
    signed-capsule verifier and capsule-v1 architecture codes 3/4 for Windows,
    with a historical nine-test selector (six runtime cases plus three admission refusals).
    That selector passed on exact checkout c608b8d8 in hosted Windows Server
    2025 run 35992373373 (9 passed, 0 failed, 0 ignored). Artifact-byte binding and production
    support remain unverified. A tenth selected Windows case now exercises a
    real inheritable broad ACE on a private parent and requires the created
    scratch DACL to stay protected with only its intended explicit ACE; the
    expanded selector passed at f4d3291f in hosted Windows Server 2025 run
    35993882814 (10 passed, 0 failed, 0 ignored).

  • Harden additive lock-bound offline fetch with held-directory authority,
    bounded retained inputs, private staging and no-replace cache publication.
    Failures retain stages or a published prefix for explicit reconciliation,
    without pathname rollback or a misleading success receipt; unsupported
    hosts refuse before cache effects.

  • Re-pin exact Semantic Workspace Change and Operations artifact/evidence/receipt
    KATs to the expanded Project graph and serialized limits while retaining
    domain, reference, API/CLI parity, tamper, replay, budget, and stale/no-write
    assertions.

  • Keep the standalone compiler archive independent of unpublished crates by
    moving the private OCI emitter and all hostile tests into one internal
    compiler module. Preserve the typed input boundary, exact artifact bytes,
    credential refusal, and unchanged no-signing/no-registry-publication scope.

  • Keep the private public-generic Component runtime inside its ambient-authority
    source contract: acquire a checked-in canonical project explicitly, replay
    against pinned identities, and authenticate exact Component bytes before
    typed execution. This does not widen public Component support.

  • Generate canonical descriptor-bound TypeScript/Wasm carrier frames and run
    the generated package against the compiler-owned provider lifecycle. Add the
    private semaprax.authenticated-native-identity.v1 C profile, which rejects
    malformed or drifted frame metadata before physical work and invokes one
    compiler-checked flat owned-Bytes identity endpoint across C, C++, and Rust.
    These are local, unpublished profiles; broader shapes, shared-corpus and
    hosted acceptance remain open.

  • Settle borrowed arguments and returned Bytes at the native Agent stage
    boundary, retaining sticky failure and strict post-drop receipts. Local
    controls cover success, contract failure, cancellation, omitted drops,
    malformed receipts, and duplicate calls; native instruction fuel, complete
    finalizer accounting, compound cleanup failures, and Wasm parity remain open.

  • Emit the internal public-generic-wasm-provider.v1 endpoint as a
    deterministic zero-import Core Wasm module with exact descriptor/binding
    replay, normalized artifact binding, canonical carrier SHA-256 validation,
    module-owned scratch and opaque lifecycle handles, checked HIR invocation,
    two-pass result export, and explicit release/close operations. The generated
    TypeScript runtime now delegates provider lifecycle to those exports. The
    subsequent canonical carrier migration makes that package interoperable;
    #229 and the broader #162 matrix remain open for their larger acceptance
    scope.

  • Add the internal public-generic-wasm-provider.v1 Project profile as the
    first compiler-owned target foundation for #229. Package Manifest v1 now
    selects exactly one concrete checked generic owned-record endpoint, derives
    its Public Generic Descriptor v1, independently replays it against the exact
    linked program and project revision, and binds the verified digest into
    Project Lock v1. Web, npm, native, and Agent Transport artifact routes remain
    fail-closed until the Core Wasm provider emitter exists. The #162 native
    generated-caller settlement gate now shares this compiler-derived descriptor,
    binding, instance, cleanup, and leaf identity across C, C++, Rust, and the
    executed reference provider; the endpoint body remains the explicit reversal
    fixture, so neither issue is closed by this phase.

  • Make the push-driven CI and Docs workflows latest-ref only: a newer run now
    cancels its in-progress predecessor instead of spending hosted runner minutes
    completing already-superseded matrices or documentation builds.

  • Extend the bounded resumable-effect source profile from one site to one to
    eight direct sequential Copy-scalar yield sites. The deterministic plan now
    carries ordered per-site states and yield-free resume projections; the public
    interpreter uses an opaque in-memory request/answer history, while private
    native -O0/-O2 and Core Wasm runners replay the same projections. Every
    historical request is checked, and bindings commit exact arguments plus
    prior answer bits. This remains pure replay, not live-frame/liveness
    lowering: control-dependent yields, owned state, durability, scheduling and
    public target ABIs remain open. Distinct request/response assignment sites
    fail closed with SPX-T299; let and tail sites retain distinct types
    (#204). The original one-site ResumablePlan, exhaustive ResumableStep
    and start/resume functions remain source-compatible; sequential lowering and
    execution use additive plan, step and start/resume surfaces.

  • Add the initial deterministic compiler-owned three-state HIR plan for the
    single-top-level, Copy-scalar yield slice (subsequently widened above).
    Resume state now binds the exact
    checked program, yield site, and bit-exact original arguments. Closed
    projections now isolate disconnected yielding functions while retaining the
    selected and authored-entrypoint direct-call closures; retained non-scalar,
    effectful, owned-cleanup, generic and function-reference surfaces, all
    authored nominal/authority surfaces, reachable yielding callees, retained
    incoming callers, forged projections,
    and stale bindings fail closed. The interpreter consumes the plan identities,
    while cfg(test)-only
    native -O0/-O2 and Core Wasm runners execute independently validated
    yield-free projections, preserving exact normalized prefix/suffix arithmetic
    and pre/postcondition failures. Ordinary native/Wasm emitters still refuse
    yields; arbitrary NaN-payload preservation across the JavaScript Wasm test
    adapter, public continuation ABI, external-await runtime seam, durable source
    checkpoint, Agent migration, and general live-frame/control-dependent yield
    lowering are not claimed. The reference v1 journal additionally completes
    an already-observed partial turn without redispatch and never repeats cleanup for an in-memory
    replayed terminal; its unchanged wire has no durable append or cleanup
    settlement, so decoded terminal cleanup and crash recovery remain ambiguous
    and unclaimed (#204).

  • Add a deterministic, non-executing cross-language benchmark reproduction
    capsule that binds exact task and adapter inventories, equivalence files,
    public and hidden trees (including empty directories), and per-language
    adapter policy. Stable descriptor-backed reads reject path swaps, and a
    matching capsule says only that scoring inputs match, never that a model or
    toolchain ran (#211).

  • Compose the task-service reference application and generated service
    scaffold with std.tracing's pure trace-context and secret-classification
    policy now that reachability pruning admits the dependency closure. Valid,
    malformed, and caller-classified-secret cases join the existing backend
    parity gate; no logging, span emission/export, or host authority is added
    (#194).

  • Record the first hosted Windows compilation evidence for the production
    provisioner confinement module. The successful Windows Server 2025 job
    compiled the cfg(windows) code at the exact recorded revision but selected
    no confinement test function, so runtime confinement evidence remains open
    (#236).

  • Add an offline, unavailable-only admission gate for future external coding-
    agent baselines. It binds the owner-pinned task inventory bytes and Zero
    source revision to closed toolchain, interface, model, and reviewed-port
    provenance without running a model or treating provenance as execution
    evidence (#107).

  • Carry exact empty Bytes arguments through source-native Core Wasm Agent
    stages using the existing named slice/range/copy ownership path, with
    interpreter, native -O0/-O2, and Core Wasm parity plus a retained
    malformed-carrier refusal (#143).

  • Harden generated package preview verification around a flat physical-file
    inventory and private verified snapshots before optional npm or Cargo dry-
    runs. Package publication, signing, registry credentials, and support-policy
    promotion remain outside this tool (#145).

  • Harden the paired-agent pilot's stale-recovery metric so only an exact,
    well-formed conditional write to the drifted source can count as recovery,
    and only the gateway's exact stale-precondition refusal can count as a
    rejected stale write. Reads, unrelated paths, malformed commands, and other
    failures now fail closed instead of producing optimistic evidence. Fresh
    cohorts now have a digest-bound reviewer packet and exact 18-tuple audit:
    direct treatment labels are withheld, task content remains visible, and
    hostile or drifted evidence fails closed without backfilling the historical
    cohort (#105).

  • Preserve i64::MIN when source-native Agent stage arguments are synthesized
    for Core Wasm and native C11 execution. A four-leg regression now exercises
    the value through the interpreter, native -O0, native -O2, and Core Wasm,
    while empty byte literals retain their stable refusal (#182).

  • Add a binding-first Lean-kernel certificate recheck that re-derives the
    source, exact obligation selector, Lean document, and Wasm artifact before
    consulting caller-supplied kernel authority, then requires exact recorded
    axiom results. Kernel-confirmed evidence can now be associated with one exact
    retained Project ProgramRoot and appended to its assurance manifest through
    an opaque verified token; sibling projects, altered source, subset
    certificates, and replayed revisions fail before attachment. No process,
    filesystem, network, or tool-discovery authority is added to the compiler
    (#186).

  • Preserve every failing real-distribution role in the provisioned Linux
    doctor diagnostics instead of stopping at Node's first failure. Hosted run
    35472257722 remains red (12/13 in both suites): Clang passed, Node received
    SIGSEGV, and Rust's exact termination awaits the next instrumented run;
    confinement policy and WP-05 status are unchanged (#61).

  • Track AArch64 Linux doctor confinement separately with a dispatch-only native
    Arm runner and an exact 24-case plan. The committed evidence is limited to a
    historical local Docker Desktop Arm VM run (24/26); the two real-distribution
    fixtures remain excluded for missing selector/bundle preconditions, and no
    hosted, current-head, or physical-device support claim is made (#279).

  • Compose std.tracing trace-context field admission with the existing
    std.log.redact six-flag caller classification, preserving
    malformed-context refusal and left-to-right lazy evaluation. It does not
    inspect bytes or tracestate and remains a pure policy layer with no span
    generator, exporter, sink, or transport authority (#193).

  • Version and digest the public-generic hostile corpus, pinning 17 shared case
    outcomes plus exact bytes for 9 structured-descriptor and 6
    malformed-trusted cases in one deterministic manifest while correcting
    stale evidence counts. Persistent compiled source mutants now prove that
    five previously untested descriptor-envelope refusals are individually live
    in the generated Rust, shared C11/C++17, and TypeScript consumers, and that
    weakening each branch reaches the provider before clean settlement.
    Exact-current-head hosted evidence, carrier-side consumer hostility, and real
    generated endpoints remain outstanding (#173).

  • Drive the private frozen iterative Agent loop through the existing sealed
    interpreter, native C11 -O0/-O2, and Core Wasm stage backends. The local
    parity gate covers proposal admission, fresh consumed grants, injected binary
    reads, continued and terminal reductions, cancellation, malformed proposals,
    lifecycle ceilings, and semantic evidence settlement while leaving production
    wrappers interpreter-only. It also fixes canonical lexical selection of ten-
    plus synthesized Wasm projection exports without reordering driver, decode, or
    cleanup plans. Native/Wasm interpreter-fuel and hosted evidence remain open
    (#182).

  • Extend the source-live repair preview with an explicitly selected OpenCode
    Provider-Adapter route, durable V2 receipts, a restart-stable absolute
    deadline, and checkpoint identity bound to the chosen executable and
    scratch path. Terminal recovery now replays recorded provider bytes without
    pre-deriving fixture diagnostics or redispatching, binds corrective turns to
    the actual canonical prior effect, and rejects tampered settled responses.
    A public embedding seam can now inject one opaque, host-selected,
    fixed-buffer candidate-test observer: its canonical result is bound to the
    exact candidate/base/source/capability, settled as typed feedback for a later
    provider turn, and replayed without redispatch. Executable bytes and metadata
    are bound, run/export scratch state is cleaned before reuse, and foreign or
    tainted observations fail closed. The ordinary CLI still grants no test or
    publication authority; the scripted V1 seam stays frozen for offline
    regression coverage (#116).

  • Add whole-line UTF-8 validation and checked nonnegative i64 total helpers
    to the catalog-normalizer example, with malformed-scalar, boundary-total,
    backend-parity, and mutation-control regressions. This is a
    bounded foundation tranche; the complete record parser, canonical writer,
    duplicate handling, and independent oracle remain open (#124).

  • Have tag release jobs produce pinned GitHub build-provenance attestations
    for each platform archive and keylessly sign the final aggregate provenance
    with pinned cosign tooling. Release publication now carries those bundles
    beside the manifest and provenance, while policy and tests distinguish the
    GitHub OIDC sub claim from the Fulcio workflow-URL certificate identity.
    A bounded offline verifier now closes the Sigstore v0.3 framing, GitHub
    workflow-v1 predicate structure, exact archive inventory, and aggregate
    manifest/provenance/claim bindings before invoking an explicit verifier
    capability. SigstoreOfflineVerifier supplies the standalone CLI's default
    pure implementation, checking certificate-chain and pinned identity,
    DSSE/message signatures, signed time, and transparency-log evidence against
    exact caller-supplied historical trusted-root bytes. An embedding host can
    still inject another capability. Verification performs no network or root
    refresh and does not establish current revocation state, publication,
    reproducibility, or support. No signed hosted release is claimed yet (#168).

  • Stop Universal Semantic Transaction v1 from refusing every project with a
    commented bundled dependency (#274). ProjectCandidate::apply's
    materialize step re-derived every source in the revision through the
    comment-dropping canonical formatter, so the comment-free precondition had
    to span the complete workspace -- including compiler-bundled dependency
    source (std.auth carries 253 comment lines, std.jobs 34) that no project
    can edit, making SPX-G525 unsatisfiable by construction rather than by
    authoring. materialize now preserves an untouched program's exact base
    bytes, and the new src/project/semantic_transaction/canonical_sources.rs
    enforces comment-free canonical source differentially, of exactly the
    sources a transaction rewrites or drops. A comment in a rewritten source is
    still refused with SPX-G525, and the SPX-G525 regression that proves it
    is unchanged.

  • Run a real Lean kernel against the proof_export obligation export for the
    first time (#186). The module shipped with no LeanKernel implementation and
    no evidence Lean accepts its generated proofs -- every test replayed
    synthesized output. scripts/lean-export-gate.py is that implementation,
    deliberately outside the crate so the compiler gains no ambient process
    authority: it confirms the host runs the pinned leanprover/lean4:v4.34.0
    (the same pin proofs/kernel0-lean uses), checks the committed golden
    document plus two seeded variants, and compares each result byte-for-byte
    against transcripts committed under src/proof_export/testdata/, so recorded
    evidence cannot silently go stale. Results: omega discharges both the
    checked-range obligation and the postcondition, axiom-clean and
    byte-reproducible across runs; a seeded sorry is refused; and a vacuously
    weakened conclusion is accepted by the kernel with an axiom set cleaner
    than the honest proof's -- recorded as data, because it is precisely why a
    certificate binds lean_source_sha256 and verify_certificate_against_source
    re-renders the document from source instead of trusting the embedded bytes.
    Fixes one real fail-open the real kernel exposed: Lean 4.34.0 prints
    declaration uses `sorry` with backticks, so both single-quoted spellings
    kernel_report::parse was written against (from synthesized fixtures) were
    dead against the very toolchain the module pins, leaving only the sorryAx
    clause load-bearing; quoting is now normalized. All kernel evidence is
    local-host only -- hosted CI provisions no Lean toolchain, the gate is not
    in scripts/quality.sh and not in release-gate's blocker set, and every
    certificate now carries that as an explicit nonclaim.

  • Narrow ProjectFrontendCache's AST-level invalidation (src/project/incremental.rs):
    a provider module's own changed/added/removed source still invalidates its
    frontend cache entry, but an unrelated consumer that only imports from that
    provider no longer loses its entry through the old transitive reverse-import
    closure. Parsing and canonicalizing one file is a pure function of that
    file's own bytes, so a reused entry is bit-identical to a fresh reparse
    regardless of what any provider did, and every cross-module check (import
    stub validation, the checked-HIR cache's own exact synthetic-equality
    gate) still reruns unconditionally against the current build's sources, so
    a provider's exported-surface change is still caught -- narrowing this set
    only decides which unaffected files skip a redundant reparse. On
    examples/calculator-project, a provider body edit went from 0 modules
    cloned / all 3 reparsed (80 AST nodes) to 2 modules cloned / 1 reparsed
    (32 AST nodes), matching the existing local-body-edit case instead of being
    its expensive opposite (#130, #131).

  • Add scripts/generated-package-release.py (prepare/check), a
    release-preparation and dry-run-only layer around the existing Project v8
    owned-data-api.v1 generated npm/Rust packages: closed-inventory,
    secret/local-path, and no-private-dependency admission; deterministic
    README/LICENSE/checksum-manifest wrapping; and a check step that only
    ever runs npm pack --dry-run/cargo publish --dry-run (never
    --publish, never near a live registry credential). Prepares (but does not
    make) the maintainer publication decision drafted in
    docs/GENERATED-PACKAGE-PUBLICATION-DECISION-DRAFT-V1.md; nothing is
    published by this change (#145).

  • Refuse a bundled dependency member that names an authored type at the Useful
    Data workspace linker boundary, by name, rather than admitting it into a
    declaration set that deliberately holds no authored type and letting it
    surface much later as inline-array slot references an unknown type inside
    inline-array capacity analysis. Drop such a member from the retained
    dependency inventory when nothing reaches it, so a bundled package may still
    declare a generic record. This restores semaprax new --template service,
    which the record Secret<T> added to the bundled std.auth had broken for
    every scaffolded project (#268).

  • Execute the unchanged native reference provider inside freestanding Core Wasm
    at O0/O2 under both V8 tiers, with in-module allocation, ownership registries,
    multi-call copy-in/export/release and no host imports. Add a bounded private
    transport, exact native/corpus comparison, allocator self-tests, hostile-range
    and lifecycle tests, deterministic artifacts, canonical replay, and compiled
    semantic mutation controls for #162. This is a C11-reference fixture, not a
    Semaprax-generated generic endpoint, public Wasm ABI, PG-7 completion or hosted
    promotion. Actual Rust-renderer equality remains a separately selected gate.

  • Enforce single-owner, non-reentrant native reference-provider admission with
    one atomic owner/entry word; retain ownership until the last provider closes,
    and isolate failure injection, traces and sticky diagnostics per caller thread.
    Reject misuse without touching caller output/owning aliases or reporting false
    zero-resource counters. Extend #162 with deterministic pthread misuse/handoff,
    exact/+1 thread-identity admission, sanitizer, replay and mutation gates. This
    enforces the existing synchronous restriction, not concurrent execution,
    compiled generic-provider support, PG-7 completion or hosted promotion.

  • Harden the host-owned TypeScript/Wasm reference caller: authenticate immutable
    module-byte snapshots, reject unverifiable precompiled modules, isolate private
    descriptor/binding authority, enforce one in-flight owner and exact framed
    payload bounds, preflight complete result frames, and propagate primary plus
    secondary cleanup failures. Extend #162 with 108 settlement cases, 32 host
    regression groups, 13 authenticated module subjects, two V8 Wasm execution
    tiers, fresh C/C++ semantic comparison, strict replay and twelve type-checked
    behavioral mutants. Add actual-generator byte-equality gates without claiming
    those Rust gates have run, compiled-provider support, PG-7 completion or hosted
    promotion. No existing native ABI or public rejection profile is widened.

  • Propagate explicit native release failures through C11/C++17 calling consumers
    without exposing a decoded success or overwriting earlier failures. Add
    checked close with retained ownership, reverse caller rollback, bounded
    encoding/export/decode, and per-invocation injection isolation. Implement
    corresponding Rust settlement and fallible codecs, with separate Cargo
    regressions. Extend #162 by 112 shared consumer cases, independent caller
    counters, replay evidence and eleven compiled semantic negative controls;
    actual generator/Rust execution remains a distinct gate, and full PG-7,
    compiled Wasm and hosted promotion are not claimed.

  • Return real native input/result release failures without overwriting an earlier
    call's settlement. Extend #162 with actual per-leaf result allocation/copy and
    export preflight failures, pre-rollback byte checks, exact 16 MiB success,
    compound reverse cleanup, and 72 pinned physical-phase cases with a third
    independently replayed evidence artifact. Legacy logical trace bytes and
    public ABI declarations remain unchanged; full PG-7 and generated-consumer
    failure propagation are not claimed.

  • Prevent stale native public-generic handles from reviving when heap addresses
    are reused; validate provider identities before access/close and pin bounded,
    non-recycled identities plus exact/+1 live-resource admission. Isolate
    settlement between sibling prepared inputs so an earlier success cannot mask
    a later failure as success-without-result. Extend #162 with lifecycle/recreation,
    identity-exhaustion, 8,192-call stress and paired replay evidence; public ABI
    signatures and unsupported/unpublished status remain unchanged.

  • Share one bounded, digest-pinned public-generic settlement manifest across the
    existing model/native harnesses; preserve primary failures before cleanup and
    reverse every native result rollback. Add per-case native observations, real
    allocation/compound-failure regressions, retained trace expectations, and
    portable sanitizer/replay evidence. This advances the fixture subset of #162;
    it does not close PG-7 or widen public ownership support.

These unsigned archives are not notarized and make no cross-host reproducible-build claim.
SHA-256 checksums are integrity facts, not signatures.