Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .agnir/decisions.md
Original file line number Diff line number Diff line change
Expand Up @@ -207,3 +207,13 @@
- Final repair CI run `35317245771` passed all product-check jobs; final acceptance-checkpoint run `35317410100` also passed all product-check jobs.
- Continuity-only commits after `f9026f7e3db4db8956cfc88ba1990daf0757a011` may advance authoritative `main` without changing the accepted Plugin tree. External submission evidence MUST identify the exact submitted Plugin subject, not merely a moving branch.
- The immutable released Repository Preview `v0.2.0-preview.1` remains a different historical subject and is not rewritten.


## 2026-09-20 — Release-quality hardening before local acceptance

- The Principal authorized implementing existing Svif functionality to release-quality standards, while public Platform publication remains paused.
- `CapabilityPolicy` is trusted Provider/operation metadata, not result-selected authority. Missing policy fails closed; optional requested authority can only strengthen it.
- `OperationRequest` owns required verification/check IDs. The default requires exact-subject success; non-applicability needs an explicit trusted reason. Failed checks never justify completion. Integrations authenticate actual receipts rather than treating JSON as proof.
- The founding filesystem adapter uses cooperating-reader locks, revision checks, full preflight and a recoverable multi-file journal without changing Agnir identity/lineage/locators. Conflicting outside edits stop recovery.
- Completion sessions are single-use. Uncertain external attempts survive restart and cannot be blindly replayed; independently observed effects require trusted reconciliation. This is not a live Cloudflare implementation or authorization.
- Native install/discovery and actual task/bootstrap/idempotency/fresh-session effectiveness remain separately observed gates on the same Plugin subject. Local test success is not release authorization; no new tag or public publication occurs here.
31 changes: 31 additions & 0 deletions .agnir/evidence/2026-09-20-functional-hardening.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# Functional hardening candidate — 2026-09-20

Status: locally verified implementation candidate; native effectiveness/release sign-off remains pending. OpenAI publication stays paused. No live Cloudflare transport or protected credentials were used.

## Source and changes

Captured authoritative source: `960526544da308ea8b0eb1d325b26609487ab856`. The earlier source `fe7788bd53d3a240f663860133b741799d0470e3` is the reproduced-defect subject. Preparation branch `fix/local-readiness` is temporary, not a continuity authority. A pinned source artifact was materialized by workflow `35502924625` (artifact `10602459592`) for isolated local implementation; Git objects retain the exact captured source identity.

Implemented F1: trusted `CapabilityPolicy` comes from the registered provider's operation metadata. Missing metadata fails closed. Omitted/null/empty/weaker result authority never removes mandatory `protected-delivery`. Extra requested classes only strengthen it. The real provider policy is tested against its descriptor.

Implemented F4: trusted `OperationRequest` declares required verification/check IDs (default verification required). Failed/blocked/unknown, missing or wrong-subject checks reject completion before effects/checkpoint. Explicit non-applicability requires a reason and cannot excuse a failed check. Parsing model JSON does not authenticate verifier receipts; the trusted integration retains that responsibility.

Implemented F2: all text values and required destinations are preflighted before any memory writes. The filesystem adapter serializes cooperating readers/writers, rejects stale snapshots before effects, and journals the complete State/Next/Decisions/Evidence write set. Prepared transactions roll back after interruption; committed transactions complete recovery. Conflicting outside edits require reconciliation. Six actual child-process exit boundaries exercise prepared/partial/committed states on Core/profile 0.1, 0.2 and 1.0. Ordinary I/O faults exercise rollback without partial publication.

Implemented F3: each actual read/write is confined, including discovery, evidence children, lock, receipt and temporary paths. POSIX opens walk directory descriptors with no-follow flags. Symlinks, junctions and multi-linked regular targets are rejected; uniquely created temporary files replace predictable paths. Windows uses no-link/reparse checks and OS locking but does not claim protection against hostile concurrent parent-directory replacement by equally privileged processes.

Additional safety: exact Orchestrator sessions are single-use; duplicate persisted operation receipts cannot be overwritten; uncertain external attempts leave a persistent marker across restart. Reconciliation of an independently confirmed effect requires matching observation and trusted `effect-reconciliation` authority; it never replays delivery. Provider delivery/observation errors preserve their own failure classes rather than being called continuity I/O failures.

The shared Skill now carries the same operational guards without bundling or duplicating the Python kernel. Both READMEs, architecture, applicable contract/integration notes, Project artifact registration and repository tree are updated. Native install/discovery is tested separately by `checks/check_native_install.py`; actual task/bootstrap/idempotency/fresh-session acceptance is specified in `LOCAL_ACCEPTANCE.md`. `RELEASE_READINESS.md` maps existing requirements to implementation and evidence boundaries.

## Local observed verification

The complete repository was materialized from the pinned Git bundle, not reconstructed from excerpts. Baseline: 87 tests passed. After changes: 109 tests passed on Python 3.13.5; repository integrity and portable contracts passed; source/check/test compilation passed. All external providers in these tests are injected fakes. The new test methods include parameterized cases and 18 actual process-death trials (six points on each of three compatibility lines).

The local sandbox has no Codex binary. The native harness correctly emitted `native_install=not-observed`, `native_discovery=not-observed`, `native_task_and_fresh_session=not-observed`, `release_ready=false`, and exit 2. This is blocker reporting, NOT native-host acceptance. Connected plugin discovery did not expose a suitable authorized local-host execution capability.

Remote candidate CI/native installation observations, if obtained, must be appended with exact candidate and Plugin identities. Passing those still does not replace a real authenticated native task and fresh LLM-session receipt.

## Preserved boundaries

Core/profile and Project identity/lineage/selector/locators are unchanged. The repository still self-hosts Agnir Core/profile 1.0 and preserves historical 0.1/0.2 support; the founding Skill bootstrap is still 0.1. The old Preview tag is immutable. Old ZIP/package-only receipts remain historical; changes to the Skill create a NEW Plugin tree that must be independently identified. No new release tag, GitHub Release, OpenAI submission or production delivery is authorized by this candidate.
14 changes: 7 additions & 7 deletions .agnir/next-actions.md
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
# Svif Next Actions

## Active priority: local effectiveness and functional completion
## Active priority: finish same-revision local acceptance

The Principal has paused OpenAI Platform publication. Confirm local installation/effectiveness and complete Svif's existing functionality before returning to distribution paperwork. Current `0.2.0` is not signed off as locally effective or feature-complete. Do not repeat the superseded conclusion that only publisher prerequisites remain.
The Principal authorized functional implementation to release-quality standards, while OpenAI Platform publication remains paused. The F1-F4 hardening candidate is implemented and passed 109 local tests; this is not a claim of native-task effectiveness or blanket feature completion.

1. **Repair the reproduced authority and continuity blockers.** At audited source `fe7788bd53d3a240f663860133b741799d0470e3`, omitted/null/empty model-supplied authority classes bypassed protected delivery in the real Orchestrator + ChatGPT bridge + Cloudflare provider using fake transport; invalid Decisions updates partially changed State/Next Actions before checkpoint failure; evidence-child symlinks loaded a dummy outside-root file. Repair using trusted provider/operation authority policy, full checkpoint preflight/coherent publication and recovery, and resolved-path containment for every read/write. Add executable regression tests across Agnir `0.1`, `0.2`, and `1.0`, not just Skill-text markers.
2. **Close the verification-completion gap and finish the requirement-to-test audit.** A failed non-effectful verification result could still checkpoint a completion State/Next update. Define required verification from trusted operation context, preserve legitimate not-applicable cases, and prevent failed required verification from being recorded as successful completion. Check current CORE, Project Binding, Evidence, Capability Adapter, software-delivery and Skill commitments against implementation and positive/negative tests. The current findings are a targeted audit, not an exhaustive defect list. Do not add MCP merely to manufacture a completion gate.
3. **Run same-revision native local installation/effectiveness acceptance.** Freeze a reviewed local candidate without moving released tags. Use an isolated Codex CLI home or a real ChatGPT desktop/Codex local Project, record host/version and exact installed package revision, and verify installed + enabled + actual Skill discovery. Start from an ordinary Project without Agnir; perform a concrete file task, verify its exact content, checkpoint, then use a genuinely new session without prior transcript to recover the result and next action. Re-run on an existing Project to prove identity/instruction preservation and idempotency. Exercise broken discovery, another Continuity Provider, failed verification, missing authority and unavailable observation as negative cases. Archive registration, ZIP extraction, Python-provider tests and old Preview receipts cannot substitute for this evidence.
4. **Keep both acceptance conclusions explicit.** Record (a) local host installation and actual effect, and (b) completion of the bounded Skill-first MVP and applicable runtime commitments. Clearly separate optional future integrations from defects in already-promised behavior. Do not mark either gate passed without its own evidence. The current executor could retrieve the ZIP and execute blob-verified Python modules, but had no installed Codex binary and no access to the Principal's local host; current-version native installation remains unobserved.
1. **Accept the exact hardening candidate through remote checks and native install/discovery.** Preserve the captured source `960526544da308ea8b0eb1d325b26609487ab856`, compare the staged code/tree against the locally tested candidate, run repository integrity, portable contracts and the full regression suite. Exercise real native Codex installation and new-process Skill discovery with `checks/check_native_install.py`; record actual host/version, installed/enabled state and byte-exact Plugin identity. Never convert an unavailable host into a passing result.
2. **Run actual native local work and fresh-session acceptance on the same Plugin tree.** Follow `LOCAL_ACCEPTANCE.md`: ordinary Project without Agnir -> installed Skill -> real file task -> exact verification -> checkpoint -> genuinely new session without old transcript. Recheck existing-Project identity/instruction preservation, idempotency and the negative fixtures. Native package discovery alone is not functional effectiveness.
3. **Close the bounded release-readiness matrix.** Review `RELEASE_READINESS.md`, CI and native receipts. Keep trust assumptions and unsupported boundaries explicit. Do not add MCP merely to create a completion gate; do not silently narrow Windows, production or cross-provider claims. Release readiness stays unaccepted until its distinct evidence gates are satisfied.
4. **Preserve failure/recovery semantics.** Required authority comes from trusted Provider/operation metadata. Required checks come from trusted operation context; model JSON cannot authenticate its own receipts. Pending filesystem transactions must be recovered before normal continuation; conflicting outside edits require reconciliation. Unconfirmed external effects must not be blindly retried after restart; explicit independent observation and trusted reconciliation are required.

Reproduction details and observed results: `.agnir/evidence/2026-09-18-public-submission-candidate-audit.md`, 2026-09-20 local-readiness audit. All newly reported gaps are open; this checkpoint changes continuity only, not product code.
Implementation and local observations: `.agnir/evidence/2026-09-20-functional-hardening.md`. Historical defect reproductions remain in `.agnir/evidence/2026-09-18-public-submission-candidate-audit.md`. Preparation branch `fix/local-readiness` is temporary and must not become canonical continuity; integrate only after fresh stale-base and verification checks, then archive/retire it.

## Deferred public/personal ChatGPT path

Expand Down
Loading
Loading