Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
86 changes: 85 additions & 1 deletion .agnir/evidence/2026-09-20-bootstrap-version-selection.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Svif first-use Agnir version-selection repair — 2026-09-20

Status: implementation candidate on `fix/bootstrap-agnir-version-selection`; OpenAI Platform publication remains paused.
Status: version-selection implementation plus executable checker and native installation gates accepted for the PR #13 candidate; authenticated model behavior and whole-release sign-off remain pending. OpenAI Platform publication remains paused.

Principal correction: Svif must not pin all new/current Projects to Agnir Core/profile `0.1`. Existing Project truth wins. A valid existing Agnir Project keeps the Core/profile it declares; adding Svif creates/validates a matching continuity binding and does not authorize compatibility migration. Partial or contradictory Agnir artifacts remain repair cases.

Expand All @@ -9,3 +9,87 @@ Only a genuinely uninitialized Project resolves the canonical latest published s
Current external observation on 2026-09-20: `iorLab/agnir` latest published stable is repository release `v1.0.2` at revision `b5626394ec40a5cb7a28c01892acde07cc0adc8e`; that release still declares Core `1.0` and `repository-filesystem/1.0`. This receipt is evidence of today's resolved stable, not a hard-coded future bootstrap constant. Future first-use operations must resolve latest stable again.

The immutable Svif `v0.2.0-preview.1` release is not modified. It remains historical evidence with its original `0.1` bootstrap behavior. The current unpublished `0.2.0` Skill is the first Svif line to supersede that rule.

## Completed acceptance implementation

The initial selection rule reached main at `9501fd7ed0843f46882ee63ed9c19cd2759a7cb2`
(run `35519581944`, success). Follow-up inspection found that the native exercise still
prohibited model network lookup and only compared Project identity after bootstrap;
it did not verify that the new Project matched an independently resolved latest stable.
The actual Agnir adapter already supports 0.1/0.2/1.0; no runtime default change was needed.

The completed candidate is `08f2c7c7581edb8845cea161b971a0c4dca2de4d` on temporary
`fix/bootstrap-acceptance`, PR #13. Exact tree:
`3c053b2371f0fe916379ac7ea2f74ce1eb4bad3f`.
Exact Plugin tree: `77953ba954b2c0f3ff7dcc6f9c7814df5fa05e12`.

`checks/check_local_install.py` now resolves latest stable only for a new-Project model
exercise, verifies release/tag/commit and each source file's Git blob hash, obtains the
matching installer/Core/profile/schema/activation files and provides the model a fresh
same-operation source snapshot outside the still-uninitialized Project. It does not
relax the model sandbox or copy the source repository's Project identity/memory. The
independent result checker enforces Agnir/Svif identity and compatibility/profile,
applied package/source/revision provenance and selected-release activation locator.
The no-auth install path performs no Agnir lookup. Existing-Project validation is
read-only, supports 0.1/0.2/1.0 and does not require optional historical package provenance.
Unavailable or unsupported latest stops; it is never replaced with an older release.

The shared Skill, bilingual first-use diagrams, repository map and acceptance matrix
agree with these rules. This repository's existing Agnir activation, compatibility,
identity, lineage, selector, memory locators and applied v1.0.0 provenance are preserved.

## Verification receipts and boundaries

- Local full suite: 141 tests, success. Repository integrity, portable contracts and
diff checks pass. New executable fixtures cover stable/package version separation,
old-Project preservation, binding/provenance mismatches, RC/unpublished targets,
unsupported compatibility, corrupt source and unavailable latest. Fixtures are
checker regression evidence, not native-model behavior.
- PR run `35520792408`: all eight jobs succeeded for the candidate, including runtime
on Linux (Python 3.12/3.13), macOS (3.12) and Windows (3.12), plus repository integrity,
portable contracts and native Codex installation/discovery on Linux/macOS.
- Native synthetic merge checkout: `ddbc9b1d51a8701f51ee83c9cde6152d0e559384`.
Linux artifact `10608285647`, outer digest
`5102d99af3518ce903092aaf5ff4f6da428dd6ac1582a5dd49b7f2351919dea1`;
macOS artifact `10607959357`, outer digest
`024b0ac82e0df4416b608c55ee347af145460fac557c9d46d1e0cc0efe4b8efc`.
Both were downloaded and compared to ALL candidate Plugin source file hashes.
- Actual host: Codex CLI 0.155.1 on Linux and macOS. Installation, enabled state and
installed Skill discovery passed. Package-file-map SHA-256:
`4e6ccce8405606f260d010d058622b1f32eeafdb59501658ea75d971a621ed81`.
Both reports retain `model_exercise: not-run`, `complete_release_acceptance: false`.
- Exact generated inner `svif-0.2.0.zip` SHA-256:
`08ad8bb13657c359d799d66c9adafcd552f8d6afdd27ed1ad96d4e34e093911b`.
Its regular-file map was independently compared byte-for-byte to this Plugin tree.

## Actual upstream observation and auxiliary workflow failures

One-shot validation run `35520533567` passed 141 tests and both structural checks,
resolved actual canonical Agnir v1.0.2, built the exact ZIP and materialized the tested
Git tree. Its final summary command incorrectly used `git rev-parse :plugin` and failed.
The run as a whole is a failure, NOT a green pipeline claim. Artifact `10607369559`
retains the real tests, live-resolution receipt, ZIP and checksum. Outer artifact digest:
`35970da37830902b13034c56060ba3bd4af62eaa91df78bd9e7e33d9c8f83857`.

The live resolver observed at `2026-09-20T15:44:51.613206+00:00`:
release `v1.0.2`, publication `2026-09-18T14:14:18Z`, release ID `391529372`, exact commit
`b5626394ec40a5cb7a28c01892acde07cc0adc8e`, Core `1.0`,
profile `repository-filesystem/1.0`, activation `AGNIR.md`. Eight source files were
retrieved from that exact commit and verified. This is today's source observation,
not a pinned future default and not proof of a model executing the installer.

After correcting the summary command, run `35520615978` passed tests but encountered
GitHub public API HTTP 403 rate limiting at latest lookup. It stopped as designed,
without fallback or target initialization. This auxiliary run also remains a failure.
The completed tree was independently read back through the authorized GitHub connector
and validated by the separate fully green PR suite. The one-shot transfer/verification
workflow is absent from the accepted product tree; it is not a new runtime dependency.

## Outstanding release gate

Authenticated positive/negative native behavior on this exact changed Skill still
needs actual observations. Existing-Project versions must remain unchanged in those
exercises; new Projects must match stable resolved in that operation. Passing source,
checker, archive or no-auth install tests cannot replace these observations.
No v0.2.0 tag, public Release, Platform submission/Publish or live Cloudflare effect is
created or authorized. Released Preview history remains immutable.
41 changes: 27 additions & 14 deletions .agnir/next-actions.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,24 +7,37 @@ and native install/discovery now have passing evidence; do not repeat the old cl
that the four audit findings are unrepaired or that publisher prerequisites are the P0.
Full current-version Skill effectiveness and whole-release sign-off remain open.

1. **Accept the new bootstrap-version-selection Plugin subject before authenticated behavior.** The current Skill now preserves an existing Project's declared Agnir Core/profile and resolves latest published stable Agnir only for a genuinely uninitialized Project. This changes Plugin bytes, so tree `7cc90517013306181a4df2238f849b85cf716665` / run `35509417968` remains historical for the prior candidate. Run full CI and `checks/check_local_install.py --output <isolated-directory>` on the exact new candidate; require installed+enabled status, exact installed bytes and native Skill discovery on supported hosts before using `--exercise`. Then use the operator's authorized Codex login in the isolated CODEX_HOME and perform ordinary-Project bootstrap/task/checkpoint, fresh process + new conversation recovery, and unchanged existing-Project reuse. Do not copy, request or commit secret token values.
1. **Complete authenticated native behavior on the accepted current candidate.**
Use a fixed reviewed checkout whose Plugin tree is
`77953ba954b2c0f3ff7dcc6f9c7814df5fa05e12`. PR #13 candidate
`08f2c7c7581edb8845cea161b971a0c4dca2de4d` passed all eight checks in
`35520792408`; downloaded Linux/macOS Codex 0.155.1 reports confirm exact installed
bytes, enabled state and Skill discovery. This new no-auth gate is no longer pending.
With the operator's authorized login in isolated CODEX_HOME, run
`checks/check_local_install.py --output <isolated-directory> --exercise`.
New-Project testing resolves the latest published stable Agnir in that operation,
stages verified installer/contracts outside the Project, and independently checks
matching Core/profile, Svif binding and operational provenance. No preinitialized
continuity, cached fallback or relaxed model sandbox is allowed. Existing Projects
keep their actual version and valid activation; normal resume needs no latest lookup.
Exercise first-use task/checkpoint, fresh process + new conversation recovery and
unchanged reuse; also exercise existing 0.1/0.2/1.0 Projects independently.
Do not copy, request or commit secret token values.
2. **Exercise all same-candidate negative host scenarios.** Follow
`conformance/RELEASE_READINESS.md`: broken discovery, other Continuity Provider,
identity/version mismatch, failing required checks, absent authority, missing
observation and interrupted write markers. Record prompts, actual tool behavior,
initial/resulting file hashes, host/version and classification. Kernel tests do not
substitute for installed-Skill adherence. Repair any observed failure before sign-off.
3. **Preserve the integrated engineering baseline and release limits.** PR #11 was
squash-merged to authoritative `main` as `9e8f602b3c9a9d4a1a3c674979fcbc6f5483f27a`.
The merge tree is `3b6d026b8d3b6b8281b9cc9f7d8e62fefc741361`, exactly the reviewed
candidate tree. Final PR run `35509842215` and authoritative-main run `35509894716`
passed all eight checks. The latter includes native Codex installation/discovery on
Linux and macOS, plus runtime checks on Linux/macOS/Windows. Plugin tree remains
`7cc90517013306181a4df2238f849b85cf716665`. Integration verification is complete;
the remaining P0 is real authenticated native positive/negative behavior, not merging
the already-integrated repair. Keep `spec/RUNTIME_SAFETY.md` limitations explicit.
Implementation evidence: `.agnir/evidence/2026-09-20-runtime-readiness-repair.md`.
Full release acceptance must stay unpassed until the remaining native gates close.
initial/resulting file hashes, host/version and classification. The 141 passing tests
include version-checker regressions, not fabricated model observations. Kernel tests
and native installation cannot substitute for installed-Skill adherence.
3. **Preserve current evidence and integration identity.** The bootstrap correction
and native receipts are in `.agnir/evidence/2026-09-20-bootstrap-version-selection.md`.
Candidate tree `3c053b2371f0fe916379ac7ea2f74ce1eb4bad3f` contains no temporary
workflow. Require the continuity-only PR checkpoint CI before integration and read
back authoritative main afterward. Keep `spec/RUNTIME_SAFETY.md` limitations explicit.
PR #11's older integrated runtime and Plugin receipt remain historical; they must not
replace the current Plugin identity. Full release acceptance stays unpassed until
authenticated positive and negative native behavior gates close.

## Deferred public/personal ChatGPT path

Expand Down
52 changes: 32 additions & 20 deletions .agnir/state.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,29 +9,41 @@ Agnir continuity on `main` remains canonical; staging is not a second authority.
The Principal requested release-standard functional repair and local effectiveness;
OpenAI Platform submission/Publish remains paused until an explicit new instruction.

**The four reproduced runtime blockers are repaired and cross-platform regression
checks pass. A new first-use version-selection repair is now under validation: existing
Agnir Projects preserve their declared Core/profile, while genuinely uninitialized
Projects resolve the canonical latest published stable Agnir. Because this changes Skill
bytes, the prior native install/discovery receipt remains historical for the preceding
candidate and must be rerun for the new candidate before model-driven release acceptance.**
**The four reproduced runtime blockers remain repaired. Project-aware bootstrap selection
and its executable acceptance checks now pass: existing Agnir Projects preserve their
own version; only genuinely uninitialized Projects resolve the latest published stable.
The changed Plugin has fresh Linux/macOS native installation/discovery receipts.
Authenticated model-driven effectiveness and whole-product release sign-off remain open.**

## Verified repair subject
## Verified current candidate

- Product/package version: unpublished `0.2.0`; product and portable contracts remain `0.2`.
- Baseline: `960526544da308ea8b0eb1d325b26609487ab856`, retaining audited product code
`fe7788bd53d3a240f663860133b741799d0470e3`.
- Reviewed repair source: `225e535e32a18bf8db2bfc7d76efe6bed9378e97`, tree
`12542123c9ab47e5e938f8db8fd8a7d36f28a513`, PR #11.
- Prior repaired Plugin tree `7cc90517013306181a4df2238f849b85cf716665` passed native install/discovery and remains historical evidence. The bootstrap-version-selection change creates a new Plugin subject that requires its own exact tree and native receipt before acceptance.
- Local full suite: 128 tests pass on Linux/Python 3.13.5; repository integrity and
portable contracts pass. Tests execute real code, including process termination.
- PR candidate run `35509417968`: all eight jobs pass, including runtime on Linux
(Python 3.12/3.13), macOS (3.12), Windows (3.12), and native installation on Linux/macOS.
- Native Codex 0.155.1 reports installed+enabled and discovers `svif:svif` at the exact
installed cache path. All installed package file hashes equal the selected source.
- Native no-auth receipts remain distinct from model execution. No current-version
real model task/checkpoint/fresh-LLM-session or desktop GUI acceptance is claimed.
- Initial version-selection implementation reached main at
`9501fd7ed0843f46882ee63ed9c19cd2759a7cb2`; run `35519581944` passed.
- Completed checker/Skill candidate: `08f2c7c7581edb8845cea161b971a0c4dca2de4d`,
tree `3c053b2371f0fe916379ac7ea2f74ce1eb4bad3f`, PR #13.
- Exact current Plugin tree: `77953ba954b2c0f3ff7dcc6f9c7814df5fa05e12`.
- Local complete suite: 141 tests pass; repository integrity and portable contracts pass.
- PR run `35520792408` passed all eight checks: Linux Python 3.12/3.13, macOS 3.12,
Windows 3.12, repository integrity, portable contracts, native installation on Linux/macOS.
- Downloaded native reports from artifacts `10608285647` and `10607959357` confirm
Codex 0.155.1 installation, enabled state and exact installed Skill discovery. Every
installed file equals the candidate source; package-file-map SHA-256 is
`4e6ccce8405606f260d010d058622b1f32eeafdb59501658ea75d971a621ed81`.
- Native reports explicitly retain `model_exercise: not-run` and
`complete_release_acceptance: false`. No authenticated current-version task,
checkpoint/fresh-model-session, negative-host or desktop GUI acceptance is claimed.
- Actual stable lookup observed Agnir `v1.0.2` at
`b5626394ec40a5cb7a28c01892acde07cc0adc8e`, Core/profile `1.0`, on 2026-09-20.
This is a dated receipt, never a hard-coded future default. A subsequent HTTP 403
lookup stopped safely; no old-version fallback was used.
- The one-shot transfer/verification workflow is absent from the product candidate.

The earlier runtime repair was integrated by PR #11 at
`9e8f602b3c9a9d4a1a3c674979fcbc6f5483f27a`, with authoritative run `35509894716`.
Its Plugin tree `7cc90517013306181a4df2238f849b85cf716665` and 128-test/native receipts
remain historical and are not the identity of this changed candidate. Runtime code and
its safety contract were not changed by the bootstrap acceptance work.

## Implemented behavior

Expand Down
8 changes: 6 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,8 @@ If an activation locator, identity, required memory locator, or compatibility ch

## What Svif Adds to a Project

The following is the current unpublished `0.2.0` behavior. The immutable `v0.2.0-preview.1` package retains its historical onboarding procedure.

On first use, Svif first checks whether the Project already has Agnir. If it does, Svif preserves that Project's declared Agnir Core/profile compatibility exactly and creates/validates the Svif binding against the same line; installing Svif is not permission to migrate Agnir. Only a genuinely uninitialized repository/filesystem Project resolves the canonical **latest published stable Agnir** and initializes using the Core/profile and activation contract declared by that stable release. **Svif does not take over existing Project files.** Existing activation/documentation surfaces receive only the entry required by the selected Agnir contract, while unrelated content is preserved.

```text
Expand Down Expand Up @@ -87,10 +89,12 @@ flowchart TB

subgraph T["Target Project surface — first use"]
G["AGENTS.md<br/>EDIT: add activation locator only"]
H["README.md<br/>EDIT: add Agnir instructions only"]
H["README.md<br/>EDIT: add compatibility locator only"]
A0["AGNIR.md<br/>ADD: activation procedure when selected release requires it"]
Q["AGNIR.yaml + .agnir/<br/>ADD: founding continuity"]
B["SVIF.yaml<br/>ADD: Project binding"]
G --> H --> Q --> B
G --> A0 --> Q --> B
H --> A0
end

D -. "non-destructive first-use setup" .-> G
Expand Down
8 changes: 6 additions & 2 deletions README.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,8 @@ Install and enable Svif for this Project: https://github.com/iorLab/svif

## Svif 会给 Project 增加什么

以下描述当前尚未发布的 `0.2.0` 行为;不可变的 `v0.2.0-preview.1` 包仍保留其历史初始化流程。

首次使用时,Svif 会先判断 Project 是否已经使用 Agnir。若已经存在 Agnir,就原样保留该 Project 声明的 Agnir Core/profile compatibility,并让 Svif binding 与这一条兼容线保持一致;安装 Svif 不等于获得迁移 Agnir 的授权。只有真正没有 Agnir / 其他 continuity binding 的 repository/filesystem Project,才解析 canonical **最新已发布 stable Agnir**,并按该 stable release 声明的 Core/profile 与 activation contract 初始化。**Svif 不会接管已有 Project 文件。** 已有 activation / 文档表面只增加所选 Agnir contract 需要的入口,并保留无关内容。

```text
Expand Down Expand Up @@ -87,10 +89,12 @@ flowchart TB

subgraph T["目标 Project surface — 首次使用"]
G["AGENTS.md<br/>编辑:仅添加 activation locator"]
H["README.md<br/>编辑:仅添加 Agnir instructions"]
H["README.md<br/>编辑:仅添加兼容入口"]
A0["AGNIR.md<br/>新增:所选版本要求的项目激活流程"]
Q["AGNIR.yaml + .agnir/<br/>新增:founding continuity"]
B["SVIF.yaml<br/>新增:Project binding"]
G --> H --> Q --> B
G --> A0 --> Q --> B
H --> A0
end

D -. "非破坏性 first-use setup" .-> G
Expand Down
Loading
Loading