AOI v0.4 implementation and migration plan¶
Status: active implementation contract, evidence checkpoint 2026-07-23
- Title: Complete, publish, and install AOI v0.4
- Owner: /root
- Objective: Complete integrity-v2, the optional one-shot Codex App Server transport bridge, and destination-aware protection for user-designated local files; qualify one exact clean v0.4 successor, publish it to GitHub and PyPI, then install only that released version in ARISE.
- Completion boundary: A clean containing successor of rejected exact commit
054d1b6cf877fda8d24372318508614be28efe98must retain all accepted Bridge,local_files, WSL-hook, CAS, exact-model-list, clock-fixture, and integrity-v2 contracts. Everymodel/reroutednotification must synchronously bind its exact bounded wire bytes to controller-owned task-local CAS before payload classification and then fail closed with a typed fault. Aturn/completedobservation-derived terminal append requires a natural zero-exit/full-reader-drain stream seal; forced cleanup, nonzero exit, partial output, reader/CAS timeout, or a live reader may never authorizecompleted. That exact successor must pass Bridge/confidentiality falsification, pinned runtime/schema checks, full Windows and local fresh-ext4 WSL suites, typing/compile/docs, exact-wheel package/install, a newly issued read-only then writable live canary, verified Git mutation, profile-aware doctor, fresh independent review, integrity-v2 seal, and an encrypted local bundle.local_filesis selective: an empty protected-rule set permits normal AOI publication,home_remote_onlypermits only the exact named home remote and destination, andlocal_onlyforbids all external destinations absent an exact consumed Chief one-shot export permit. This same active task must push the exact sealed final commit after an exact pre-push check. Canonical GitHubtestLinux/Windows jobs and the main-onlydocsworkflow must then pass for the exact peeledmainpush commit. Their authenticated exact-CI receipt must be copied into task CAS before an unused annotated release tag is created. A second CAS receipt must bind that exact CI record, current plan/head, tag object/peeled commit, destination, remote absence, and confidentiality preflight before tag push; authenticated post-push tag-object/peeled-commit readback is a third distinct receipt. A tag test is supplementary and cannot replace the main-push observations. The publish workflow must independently fail closed on those exact runs before its first GitHub Release mutation. It must publish and read back the immutable tag, GitHub Release assets, and exact wheel/sdist through GitHub OIDC Trusted Publishing, then verify PyPI metadata, hashes, download, install, import, and entry points. Only after the current Chief binds those public observations throughrelease-promotemay ARISE consume the resulting exact promotion bundle and canonical bundle SHA, install the released version side-by-side, and prove Windows-to-WSL hook reachability. ARISE source, Git, RTL, artifacts, and EDA remain outside publication and execution scope.
AOI v0.4 makes semantic state, dispatch authority, transport observations, and releases content-addressed. It also reduces routine operator ceremony after those contracts are stable. This is a schema and trust-semantics release; it is not a claim that AOI is a hard sandbox or that multi-agent work is inherently better. The optional Codex Transport Bridge can launch one governed local App Server turn; the dependency-free AOI core remains usable without that adapter.
2026-07-23 selective publication closure repair¶
2026-07-23 remote publication update: v0.4.0a1 and v0.4.0a2 were
pushed to GitHub for remote-final-SHA validation and superseded before
Release/PyPI because the remote matrix exposed CI portability defects: Python
3.11 test-collection failures from backslashes inside f-string expressions,
and a Windows package-smoke failure where PYTHONPATH=src was evaluated after
entering the downloaded artifact directory. No GitHub Release, PyPI upload, or
ARISE install may use v0.4.0a1 or v0.4.0a2. The publication candidate is
retargeted to 0.4.0a3; branch CI must pass before the v0.4.0a3 tag is
created.
Two fresh read-only reviews rejected the first selective-policy repair. They proved that a never-tracked protected origin could be copied, deleted, and then escape the current-byte identity scan; that delivery doctor reinterpreted old receipts through the current config; that an unreceipted descendant remote tip could borrow an older delivery receipt; and that the actual Actions artifact and PyPI workflow never invoked the advertised subject gate. They also found the remaining empty-rule storage error, which contradicted the user's clarified requirement that AOI itself remain updateable. Those findings supersede all earlier policy-review GO/PASS language.
The active dirty repair now fails closed when a configured protected origin is missing, persists a self-digested delivery-time policy binding beside the task-local CAS receipt, and validates historical delivery evidence against that binding rather than a later config. Once the same protected-policy digest has governed a remote/ref, repository-wide doctor coverage requires its current tip to have an exact persisted preflight delivery. Empty rules no longer turn a sync/network storage finding into an error.
A new stdlib-only publication inventory expands regular wheel/ZIP and gzip-tar
members under bounded type/link/traversal/count/byte checks. The new
confidentiality-publication-preflight receipt binds exact container hashes,
member-manifest digest, destination, config/policy, and matched subjects. The
release workflow calls it before all six Actions artifact uploads and carries a
PyPI receipt whose exact two container rows are revalidated against the producer
inventory before OIDC publication. Current dirty-byte diagnostics after the
subsequent runtime-pin, archive-bound, annotated-tag, GitHub-Release/PyPI
continuity, and empty-rule regression repairs are: 164 focused
publication/confidentiality/release/runtime/workflow
tests plus two subtests passed, with the one clean-tracked-checkout contract
deliberately deferred until the candidate is committed; strict mypy passed the
six changed publication/runtime/verifier modules; compileall, policy byte
equality, diff-check, and task-scoped doctor passed with no doctor errors.
Checkpoint, integrity seal, fresh whole-diff review, exact-commit Windows/WSL
suites, package workflow, live canaries, remote CI, publication, and
installation all remain required; no GitHub/PyPI or ARISE completion is
claimed here.
Whole-diff review v119 then rejected the candidate because its GitHub Release
job published an empty prerelease before uploading assets, so an ordinary crash
could leave an externally visible partial official release. The current dirty
repair discovers draft and published Releases through an authenticated fully
paginated API listing, distinguishes discovery failure from absence, and binds
an exact draft marker to the repository, annotated tag object, peeled commit,
three asset names/sizes/hashes, publication policy, preflights, and sealed
content. The nondeterministic Actions archive digest remains run-local
provenance and is not part of cross-run draft identity. It resumes only that exact non-public draft, uses its Release
ID for bounded starter cleanup, upload, download, and final publication, and
rechecks the tag/Release contract before every mutation. A published incomplete
Release fails closed. Only after a stable full download/hash verification does
the workflow set draft=false; it then performs another published readback
before the independent read-only job and PyPI OIDC job may proceed. Workflow
YAML parsing, extracted Bash syntax/ShellCheck, and 16 scoped contract tests
pass on the dirty bytes; fresh whole-diff review and all exact-commit gates are
still required.
2026-07-23 exact release-CI and Python 3.11 environment closure¶
Exact commit 054d1b6cf877fda8d24372318508614be28efe98 remains rejected and
supplies no transferable acceptance evidence. GitHub docs run 29987095149
completed successfully at that SHA. Test run 29987095165 did not: its Ubuntu
Python 3.11 job reported two failures because a standard venv seeded
Setuptools' executable distutils-precedence.pth, while the remaining matrix
and coverage jobs were cancelled when the prior 45-minute timeout expired.
The executable-.pth rejection is intentional and is not weakened by an
allowlist. AOI install/provenance evidence instead uses a dedicated venv
without --system-site-packages, uninstalls Setuptools before installing AOI,
and rejects an executable .pth added before or after the provenance receipt.
The dirty successor adds a stdlib-only exact-CI verifier and a read-only
publication job that queries the canonical test.yml and docs.yml runs for
the exact peeled commit, repository, main branch, push event, workflow path,
completed state, and successful conclusion. Ambiguous, truncated, duplicate,
wrong-repository, wrong-workflow, wrong-event, wrong-SHA, incomplete, or failed
responses stop publication. The first GitHub Release writer now depends on
that job; PyPI remains transitively blocked behind verified GitHub Release
publication. Unit and coverage timeouts are raised to 90 and 120 minutes so a
slow matrix is not mislabeled as a test failure, without removing any job or
test. GitHub-hosted Linux/Windows and main-only docs are remote pushed-SHA
evidence; WSL acceptance remains a separate local fresh-ext4 full-suite gate.
A tag-push test is supplementary because docs.yml intentionally does not run
on tag pushes. No new review PASS, integrity seal, GitHub Release, PyPI
publication, Chief promotion, or ARISE installation is claimed at this
checkpoint.
2026-07-23 v126 content-addressed release-tag handoff¶
The final-promotion boundary now includes a mechanical local handoff between
exact remote-main CI and tag delivery. scripts/verify_release_ci.py emits one
portable canonical UTF-8/LF receipt for the authenticated successful
test.yml and docs.yml main-push observations. The Chief records those bytes
as a current passing delivery_check artifact in task CAS. Only then may an
operator create an annotated tag. release-tag-push-preflight is a read-only
consumer that requires that exact CAS record, current approved plan and HEAD,
one local annotated tag object peeling to the same commit, an absent remote tag,
an unchanged effective destination and raw push transport, and a fresh
destination-aware confidentiality preflight. Its composite receipt is itself
recorded in CAS before the push. Mutation-adjacent recheck mode must reopen
that current passing verification and CAS artifact, repeat the live checks,
and reproduce byte-identical receipt bytes. The operator then pushes the
receipt-bound tag object OID directly to the receipt-bound raw transport with a
create-only empty lease; a mutable tag ref, canonicalized identity, or remote
name is not an authorized source. Both preflight remote state and delivery
readback use that effective push transport, never a distinct fetch URL.
release-tag-push-verify reopens both CAS edges, rejects superseded
or malformed verification records, revalidates actual plan/config/head/tag/
policy bytes before and after network observation, and requires authenticated
remote readback of the same annotated tag object and peeled commit. Its
delivery receipt separately binds the exact preflight verification index,
verification-record SHA-256, artifact SHA-256, and receipt SHA-256.
This is deliberately not folded into set-delivery: the task's existing branch
delivery remains the exact refs/heads/main delivery, while the tag has a
separate content-addressed preflight/readback chain. The two tag commands hold
no reusable Chief credential and do not mutate AOI state. add-verification
remains Chief-fenced. A request sent with an unknown Git push outcome is not
declared successful and must be reconciled by readback before any retry. These
receipts prove the named cooperative Git handoff only; they do not establish GitHub
Release/PyPI publication, integrity seal, or the task completion boundary.
Current source/tests/docs are still dirty successor bytes and require fresh
exact-candidate gates.
2026-07-23 v128-v130 release-tag falsification successors¶
The v127 independent dirty-byte review rejected promotion with three P1 and two P2 findings: fetch URL readback could be confused with a distinct push URL; the Chief-free handlers did not reload locked configuration or hash the actual approved plan; the runbook pushed a mutable tag ref without immediate mechanical revalidation; the delivery receipt omitted the exact preflight task-CAS edge; and its public validator trusted an unvalidated preflight mapping. The v128 successor addresses those findings without broadening the cooperative boundary. Preflight remote-state inspection and delivery readback now use the exact effective push transport, config/plan/task/HEAD/tag/evidence are reloaded around network observations, an exact object/create-only-lease procedure replaces mutable-ref push, and delivery validation requires the exact preflight verification index, record SHA-256, artifact SHA-256, receipt SHA-256, and fully revalidated exact-CI-bound preflight.
A pre-formal v128 audit then found two remaining P1s and one P2 test gap: the runbook did not fail explicitly when reproduced preflight bytes or their CAS artifact SHA differed; local and workflow tag checks accepted a tag whose embedded name differed from its ref or whose direct target was another tag; and verify-side config/plan/tag drift lacked fault injection. The v129 successor rehashes both receipts and fails before push on any mismatch, extracts the exact push inputs only from the verified recheck, requires the local and workflow tag header to directly name the expected commit/ref, independently checks the GitHub tag object's name/direct commit before every publication boundary, and adds verify-side drift tests.
The v129 successor then passed a targeted 87 passed, 2 subtests and an
expanded 195 passed, 8 skipped, 2 subtests, plus native/win32 strict mypy on
six changed source modules, compileall, and diff-check. A new pre-formal audit
still rejected those bytes: the receipt kept only a canonical destination
while the remote checks used a distinct raw transport, and the mutation-
adjacent recheck compared local files without reopening the recorded task-CAS
preflight before the push. Those results are therefore diagnostic only. The
v130 successor binds the credential-free raw transport end to end and makes
the second preflight invocation consume the exact recorded verification index
and artifact SHA, revalidate its current passing CAS bytes, and require byte
equality with the freshly rebuilt receipt before exposing exact push inputs.
v130 requires fresh focused tests and formal independent review. None of these
generations is yet a clean candidate, integrity-v2 seal, remote CI observation,
GitHub/PyPI publication, or ARISE installation.
2026-07-23 v131 release-tag fail-closed successor¶
The v131 successor narrows three release-route authority gaps without changing
the cooperative/publication boundary. First, the exact release-tag route rejects
any configured Git URL insteadOf or pushInsteadOf rewrite before either
preflight/verify command performs remote observation or the operator pushes;
this applies even with no protected confidentiality subjects. An operator must
stop, review/remove the rewrite, and rerun the complete preflight rather than
reinterpret an effective endpoint. Second, both exact-CI and recorded preflight
artifacts are release authority only when they are canonical task-CAS snapshots;
legacy live references remain compatibility/history surfaces and cannot enter
the route. Third, the public release-tag receipt validator strictly validates
the embedded confidentiality-preflight schema and canonical self-digest as well
as the enclosing receipt digest, so a copied or merely syntactically shaped
inner mapping cannot become evidence.
The v130 focused 205 passed, 8 skipped, 2 subtests result is superseded
diagnostic evidence, not v131 acceptance. Fresh v131 dirty-byte tests then
passed: the targeted release-tag matrix reported 105 passed, 2 subtests
(fb6ef50bd576edbeefa9185c0d56cbf7f2b85e7a922c45fbf9310a33fc45b6ab),
and the expanded focused matrix reported
215 passed, 8 skipped, 2 subtests
(4b494e02df7306d819a69efb7690c624be7afc4a231569d571be95ac97a98018).
Native and emulated-win32 mypy passed the six changed source modules;
compileall and diff-check also passed. These results cover the implementation
and documentation bytes immediately before this evidence-only paragraph was
recorded; the containing documentation contract is rerun separately.
At that checkpoint, formal independent review was still required and none of
the clean-candidate, integrity-v2 seal, remote CI, tag delivery, GitHub/PyPI
publication, promotion-bundle, or ARISE-installation claims had been earned.
That formal review subsequently rejected result SHA
14e2f9db8ce9506068bad456ce901bcec86d34a1403043de49e4ccfb81835e89 with
P0=0/P1=1/P2=0. The P1 is a release-route race: a Git URL rewrite can be added
after v131's last rewrite audit and before the first ls-remote subprocess,
which lets Git reinterpret that network transport. Therefore the v131
215 passed, 8 skipped, 2 subtests matrix remains superseded diagnostic
evidence, not formal acceptance or a transferable release claim.
2026-07-23 v132 release-tag rewrite-race successor¶
v132 narrows that one P1 without claiming an impossible atomic lock over Git
configuration. Its required design puts the final rewrite guard immediately
next to every Git network-helper subprocess launch, generates an unguessable
full transport alias, and maps that alias once to the exact raw transport in a
temporary system-scope config entry that is read before all mutable later
scopes. This corrects the rejected command-scope prototype: Git keeps the first
equal-length match, so a command-scope identity rule could lose to an exact
repository rewrite. If an ambient rewrite is observed before the boundary, the
route fails before network access. If an equal-length rewrite appears in the
remaining post-guard race, the earlier system-scope alias pin keeps the
already-started subprocess on the exact endpoint; the post-call recheck must
nevertheless reject the receipt on detected drift. This is a bounded endpoint
guarantee plus fail-closed evidence reconciliation, not an assertion that AOI
atomically locks global, system, or repository Git configuration.
Fresh v132 dirty-byte evidence now passes:
- targeted release-tag matrix:
109 passed, 2 subtests passed, artifact SHA-256931ef80a342310e298f7f3fe2d3f3b48e94a943ae7d5e62b05ffe304149bcfbe; - expanded focused matrix:
220 passed, 8 skipped, 2 subtests passed, artifact SHA-25631c1230cb449fb248114d910ab56791917805655b1ae865fe6c6d28dd5637ae2; - strict native and Win32 mypy for the six release-route source modules,
compileall, and
git diff --check: pass.
The source, test, workflow, runbook, and documentation bytes immediately before this evidence paragraph are what those two pytest artifacts cover; the containing evidence-only documentation update requires its separate contract rerun. These remain focused dirty-byte evidence. Formal AOI packet review, full Windows/fresh-ext4 WSL qualification, clean candidate, integrity-v2 seal, tag delivery, remote CI, GitHub/PyPI publication, promotion bundle, and ARISE installation are still pending.
Formal v132 review subsequently rejected result SHA
cacfc7726af7680888f26bec4ef8deb76d30456cf3c416e5d37fae824ad18a2f
with P0=0/P1=0/P2=1. The endpoint pin prevents redirection, but the rewrite
guard and network subprocess did not enumerate the same Git config authority:
ambient GIT_CONFIG_NOSYSTEM=1 could hide a system rewrite from the guard,
while the isolated network helper scrubbed that selector and included the
discovered system config. The v132 matrices therefore remain superseded
diagnostic evidence, not acceptance.
2026-07-23 v133 normalized transport-config authority successor¶
v133 keeps the endpoint pin and closes the P2 by making the rewrite guard enter
the exact isolated transport config context used by the network helper. The
shared authority scrubs ambient command-count, parameter, no-system, and
system-file selectors; includes the discovered ordinary system config; lists
the bounded effective config; and removes exactly the first occurrence of each
of its two synthetic unguessable endpoint pins. Any identical real entry later
in config traversal remains visible. The release guard therefore cannot be
narrowed by GIT_CONFIG_NOSYSTEM=1, and its rewrite decision describes the
same config universe that the subsequent ls-remote observes.
The minimum regression proves that an ambient no-system selector hides a
configured system rewrite from ordinary git config --list but not from the
v133 guard. A second regression proves that synthetic-pin filtering removes
only the two injected records and preserves identical real records.
Fresh v133 dirty-byte evidence passes:
- targeted release-tag matrix:
112 passed, 2 subtests passed, artifact SHA-256d5cbcb2de77484ff99195fbc45fbea928939af394be631a4cec7fad58868c113; - expanded focused matrix:
224 passed, 8 skipped, 2 subtests passed, artifact SHA-2566f0c2b28efbd2ab938e2e21ee895aca676a6f1403266aa634d0a682d9c091eab; - native and emulated-win32 mypy: no issues in seven release/publication
source files; compileall and
git diff --check: pass.
These results cover the source, tests, workflow, runbook, and documentation
bytes immediately before this evidence-only paragraph. The containing
documentation contract passed separately. Independent formal review accepted
result SHA
f148f8733dd6a2ec95d03619e38b8d2af3bab1c8cbdb174fe9e3824d61b05655
with P0=0/P1=0/P2=0 and explicitly permits full Windows plus fresh-ext4 WSL
qualification. That read-only verdict covers the v133 source/test/runbook
bytes and the preceding evidence paragraph; this formal-result paragraph is
an evidence-only successor that remains subject to its own documentation
contract and later exact-candidate review. No candidate, seal, tag,
publication, promotion, or installation claim has been earned.
2026-07-23 v134 full-qualification fixture/contract repair¶
The first v133 full-qualification attempt did not pass and cannot be reused.
The WSL run on source tree
f34310fc98b42bda0ad6924f68a4ea5b9db84843 reported
1899 passed, 29 skipped, 401 subtests passed, 5 failed; its log SHA-256 is
a8b1d723389e8965f290f27eee2f158fb6289c2238eda3baeb6f2e48d734a022.
The parallel Windows process ended with code -1 after partial progress and no
pytest failure summary; its partial-log SHA-256 is
2ebcbe1e41704abcd2713ea34bc61ac0906266542c1f5612703cb95046d14b08.
That is an interrupted runner, not a Windows PASS or test-failure verdict.
Five WSL failures exposed qualification-fixture or test-contract defects:
- the reconstructed fresh tree had no
HEAD, so a test that archivesHEADcorrectly failed; - pytest was borrowed from a venv outside the fresh checkout, violating the new dedicated-runtime provenance contract and invalidating three hook/ onboarding fixtures;
- the ordinary workflow contract still required the superseded 45-minute unit timeout even though the canonical plan, changelog, workflow, and release contract require 90 minutes (coverage remains 120).
v134 creates a committed fresh ext4 checkout and its own isolated venv, updates
the strict local-provenance fixture with pyvenv.cfg, sys.exec_prefix, and
the sole site-package root, makes the two onboarding doctor tests explicitly
mock their out-of-scope runtime-provenance prerequisite in-process, and aligns
the stale workflow assertion to 90 minutes. Production behavior is unchanged.
The four formerly failing source-level regressions pass on Windows. The
expanded affected-module matrix passes
96 passed, 1 skipped, 57 subtests passed, artifact SHA-256
d7b686ef301280ed0971e99970c9ab51774bf9a2403857d2a563a2e2a910db7e.
This is dirty-byte focused evidence; its containing documentation contract,
independent review, a new exact source-tree identity, and complete sequential
Windows/WSL qualification were still required at that checkpoint. No v133
full-suite evidence transfers. The v136 entry below records the later,
separately reconstructed successor qualification.
Formal v134 review rejected result SHA
716bbc1af8c08168a595c30ccaa2504b1db843c3683a5017df0c829de4e20fe7
with P0=0/P1=0/P2=2. It found the incorrect four-versus-five sentence above
and an over-summarized verification command that did not bind the interpreter,
four exact module selectors, flags, and separate containing-doc invocation.
v135 corrects the sentence and adds a supplemental task-CAS verification that
binds those exact two commands to the existing immutable artifacts; it does
not rewrite or replace the earlier record. The reviewer otherwise found the
production diff unchanged, the dedicated-venv fixture meaningful, the two
doctor mocks properly scoped, and the 90/120 workflow contract consistent.
Fresh containing-documentation evidence and a successor formal review remain
required before sequential full qualification starts. That successor review
accepted result SHA
a311e27d47b7ddcf60df70e92b49415fd68c1476e0b956494225dfa793009794
with P0=0/P1=0/P2=0 and permits sequential full Windows followed by a newly
reconstructed, committed fresh-ext4 WSL checkout with its own isolated venv.
This formal-result paragraph is evidence-only and requires its containing
documentation contract; it does not itself establish full-suite acceptance.
2026-07-23 v136 sequential Windows/WSL qualification¶
The sequential local full-suite qualification froze exact source tree
620810f9e75cdf6df70ea5e1ea1fb3f91d2483c0. Windows ran
C:\Users\ryan529\AppData\Local\Programs\Python\Python314\python.exe -m pytest -q tests --tb=short
with PYTHONPATH=src and PYTHONDONTWRITEBYTECODE=1. It exited zero with
1913 passed, 22 skipped, 401 subtests passed in 2021.60s; the complete log
SHA-256 is
fbba27af8ccc15ad29731125165e05c475dc3600defb3b6b9f41575c0c385e0d.
A post-run temporary-index readback reproduced the same source-tree identity.
WSL was reconstructed from the same frozen base archive, dirty patch, and
untracked-file set into fresh ext4 scratch
/tmp/aoi-v135-full-20260723T140010Z. It produced clean synthetic commit
6c43b991ca8056895097946a1dd111bb49b5d89b whose tree is exactly
620810f9e75cdf6df70ea5e1ea1fb3f91d2483c0, then built a checkout-local
.venv from requirements/release-tools.lock using both
pip download --require-hashes and offline
pip install --no-index --require-hashes. The adopted native test command was
env NO_COLOR=1 CODEX_HOME=/tmp/aoi-v135-full-20260723T140010Z-evidence/codex-home-clean PYTHONPATH=/tmp/aoi-v135-full-20260723T140010Z/src PYTHONDONTWRITEBYTECODE=1 /tmp/aoi-v135-full-20260723T140010Z/.venv/bin/python -m pytest -q tests --tb=short.
The first WSL pytest child also exited zero with
1906 passed, 29 skipped in 1493.03s; its log SHA-256 is
2d0b10f3951328693b003a51cb17d8c8f9289caa24cf97ac3b5e7ed2974b2adc.
That attempt is retained only as diagnostic evidence because the stdin driver
later parsed exit 0\r and failed its outer wrapper. The LF-safe native rerun
then recorded WSL_CLEAN_DRIVER_EXIT=0, wrote exact exit bytes 0\n, and
reported 1906 passed, 29 skipped in 1426.14s; its complete log SHA-256 is
95308a8eb4855d2afe07aaab1bbbfb1ce7a17cb67f25f9bdd1dac622fdb65563.
The Codex nested-cell wrapper surfaced status 1 after that completed stdout,
so a separate direct wsl.exe native readback was required; it returned zero
and revalidated the exit file, summary, clean worktree, HEAD, and exact tree.
The nested-cell discrepancy remains a transport diagnostic and is not erased
or represented as a clean Codex-wrapper result. It does not alter the
reconciled native WSL runtime verdict.
These results establish local Windows and native WSL runtime qualification for the frozen dirty source tree only. They do not establish independent review, integrity-v2 sealing, package/install acceptance, remote CI, tag creation, publication, promotion, or ARISE installation. The containing documentation contract, task-CAS evidence records, and later exact clean-candidate gates remain required.
The first clean ext4 WSL matrix rejected exact commit 87bcd6b4d4c7b4757e6169f8b7f1502b4c6648b3:
its case-variant protected-path regression passed on Windows' case-insensitive
filesystem but the current-byte lookup treated the configured spelling as
missing on case-sensitive POSIX, even though Git exposure matching already used
a case-folded identity. The successor resolves each protected component under
that same bounded case-folded contract; applies it to current bytes, historical
blob lineage, Git index/tree paths, generic publication, and doctor; and rejects
component or protected-tree descendant collisions instead of choosing one.
The shared identity is specifically ASCII-case-insensitive and non-ASCII-exact;
exact CJK paths remain supported, while Python-only multi-codepoint folds such
as Straße/STRASSE cannot diverge from Git history discovery.
Because git ls-tree does not implement icase, AOI reads a bounded full tree,
caches it by commit, filters actual strict paths itself, and counts the
unfiltered entries against one aggregate history/outgoing budget. The governed
Git child also scrubs all ambient literal/glob/noglob/icase pathspec modes.
Windows and WSL ext4 regressions cover hostile pathspec environments, historical
copy lineage, doctor tracking, collision denial, aggregate overflow, and cache
deduplication. The standalone tracked snapshot builder and publication gate use
the same resolver, overlap admission, content correlation, and rule identity;
their regressions cover ASCII case variants, non-adjacent overlaps,
Straße/STRASSE separation, and exact CJK paths. Current dirty-byte scoped
evidence is Windows 81 passed/2 skipped and WSL ext4 82 passed/1 skipped for
confidentiality/publication subjects/snapshots, plus Windows 36 passed/1 skipped
with three subtests and WSL 37 passed for snapshot/config admission. Five changed
source modules pass mypy and compileall; diff-check, managed/package/doc policy
byte equality, and task doctor pass. All PASS evidence for 87bcd6b remains
diagnostic only; the successor still requires fresh exact-commit Windows/WSL,
package, review, integrity, CI, and publication gates.
2026-07-23 durable process-evidence replay repair¶
A current whole-diff transport review found one P2 evidence contradiction:
after a launch already had a terminal receipt, a later run replay returned
process_start_evidence=not_started without reading the persisted journal.
The bridge now derives the same not_started, process_start_pending_only, or
process_started_observed value from the complete journal for initial runs,
crash reconciliation, and terminal replay. This does not claim an unpersisted
physical Popen and does not authorize a resend. Focused exact-byte tests and a
new independent review are required before commit; predecessor PASS evidence
does not qualify this repair.
2026-07-23 process-start Chief fence checkpoint¶
Fresh independent review v94 rejected frozen read-only canary v18 with P0/P1/P2 = 0/2/0. The canary was never prepared or run, and its five evidence roots remained absent. One finding showed that the wrapper's inactive predicate incorrectly expected the released session at the authority record's top level, although canonical Chief release clears that field. The second showed that an empty fixed credential home did not prove that no different current Chief existed through another credential root or later epoch. Frozen v13-v18 assets and all predecessor PASS/seal evidence are historical only and may not be run or transferred to a successor.
The v98 repair moves the decisive check into production at the durable
process_start_pending callback while the AOI state lock is held. The runtime
rereads the immutable issuance marker, binds it to the exact
task/launch/intent/permit/authority/reservation, then requires the canonical
Chief record to be inactive at that marker's exact issuing epoch with the
latest non-forced release event naming the exact issuing session and epoch.
Still-active issuance, alternate-home epoch 2 acquisition, epoch 2 release,
wrong release audit identity, missing authority, and malformed marker issuer
all fail before pending publication and process start. A durable pending
milestone remains the authorization cut: later Chief changes do not
retroactively revoke it, and an ambiguous post-pending crash remains
launch_unknown without automatic restart. Windows focused source tests pass;
fresh WSL/full/package/review/canary evidence remains required before this
checkpoint can become an accepted candidate.
2026-07-23 selective protected-files and publication route decision¶
The user clarified that AOI itself must remain updateable. local_files applies
only to user-designated paths and their allowed destinations; it is not a
whole-repository publication ban. The canonical implementation plan is
aoi-v04-selective-protected-files-plan.md with SHA-256
5ccf1f340b8eec8eaf9309940e2e6e21e9c28836173ca433aede6dded54122d3.
It supersedes the rejected two-task/profile-migration route.
The active AOI development config has no protected rules, so this same task can
own local qualification, exact pre-push inspection, final-SHA GitHub CI,
immutable tag/Release readback, exact wheel/sdist Trusted Publishing and PyPI
readback, the Chief-fenced release-promote bundle, and released ARISE
installation. No config migration or replacement publication task is required.
PyPI tokens and other reusable publication credentials are forbidden; the
supported path is GitHub Actions OIDC Trusted Publishing followed by local
Chief promotion. Older statements below that describe local_files as
globally forbidding push/remote CI/publication are superseded historical
rationale and are not the current contract.
The clean-runner policy handoff is content-addressed. Local
confidentiality-policy-snapshot reads ignored aoi.toml and exact protected
origins, then emits canonical tracked release/publication-policy.json. Git
preflight and local release promotion reject a stale tracked snapshot. Remote
GitHub runners consume that snapshot only with the workflow's independent
expected-digest pin; they do not require ignored/local-only origins and never
upload raw aoi.toml. File/archive receipts are generated outside their payload
subject, copied as sidecars, temporarily removed for receiver recomputation, and
then restored. The standalone gate cannot authorize Git:
home_remote_only remains behind exact outgoing-commit preflight.
2026-07-23 resource/startup causal-clock repair¶
The first fresh-ext4 WSL full non-CLI run failed one session-registration fixture after 1,515 passes: a second resource apply, executed after a persisted startup observation, received a wall-clock timestamp 27.8 ms earlier than that startup. The prior clamp considered resource transitions and completed registrations but not unregistered startup receipts. Resource writers now scan and validate the bounded startup-receipt store under the same state lock and serialize a transition one microsecond after the latest transition, registration, or startup observation when clock rollback is within five seconds; larger rollback still fails before mutation. Focused Windows session/resource regression passed 123 tests plus 14 subtests. The failed WSL whole-suite attempt remains non-acceptance evidence; a fresh exact-diff WSL rerun is required.
2026-07-20 Codex Transport Bridge checkpoint¶
This is the independent local_files final-task implementation checkpoint, not
promotion. Exact documentation candidate 1fcce28a77b80b9833ecb725bcc4ae6650c1d821
(3dd5482233cd5f69ae3a288298a84e426c2ed95c) received a fresh P0/P1/P2=0
documentation review. It passed Windows non-CLI 1,382/33 plus 294 subtests
and Windows CLI 172/8 plus 70 subtests. Its fresh ext4 WSL run reached
1,565 passed, 29 skipped but failed one synthetic legacy-verification edge
because two sequential fixture timestamps compared backwards after a host/WSL
clock step. Ten isolated reruns passed, which diagnoses but does not replace
the failed whole-suite result.
The later ARISE installation preflight found that 1fcce28 could not route a
Windows Codex hook into canonical WSL state. Successive repairs added a single
no-shell Windows-to-WSL grammar, exact platform-pair validation, partial-signal
and WSL-UNC denial, fail-closed current-pair rotation, pair-before-receipt
publication, and deterministic ordering inside only the synthetic timestamp
fixture. Those bytes were committed as exact candidate
02e23c59bddacd641d4bb645d39b9c9298f4990a, tree
96fdfb9e9633d124673adb037c030f591bcec4d0.
The fresh exact-candidate review rejected 02e23c5 with P0/P1/P2=0/1/1.
Its P1 demonstrated that an unclosed quote and
cmd.exe /c aoi-codex-^hook.exe --hook-version 6 could be preserved as
foreign even though the latter executes the AOI hook after CMD caret removal.
The P2 was this checkpoint's stale dirty/pre-commit wording. Full suites on
the rejected bytes passed Windows non-CLI 1,392 passed, 33 skipped, 317
subtests, Windows CLI 172 passed, 8 skipped, 70 subtests, and fresh ext4 WSL
1,576 passed, 29 skipped. Those results are diagnostic evidence for a known
defective candidate, not exact promotion acceptance.
The bounded repair was first reviewed on dirty bytes and then committed as
388d075dbab8ab2eccb3d893b10b2fbc1dbbd286, tree
f32aa98ae09462ba799b91554f9d5b8e108dae30. It adds a fail-closed signature
check for tokenizer quote failure and CMD caret normalization while preserving
a well-formed foreign command that merely prints aoi-codex-hook. Before that
commit, focused onboarding/offboard tests passed Windows 68 passed, 4
skipped, 49 subtests and WSL 69 passed, 3 skipped; Linux/Win32 typing over
87 production files, compileall, strict MkDocs, packaged-policy byte equality,
and diff-check also passed. A read-only dirty-byte reviewer accepted those
bytes with P0/P1/P2=0/0/0 for a local commit only. Its routing remains
manual_unverified because the collaboration platform exposes no consumable
SubagentStart receipt. These are historical pre-commit checks, not exact
package, canary, or promotion evidence.
A fresh exact review of clean 388d075 then returned P0/P1/P2=0/0/1.
It independently confirmed the two bypasses closed, the benign control
preserved, focused exact Windows tests 68 passed, 4 skipped, 49 subtests, all
ten changed blobs equal to HEAD, a clean worktree, and packaged-policy byte
equality. Its P2 was this file's stale use of "current dirty", "dirty-byte
pre-commit", and "eventual successor" for an already clean exact candidate.
Package/install and the first read-only App Server canary were therefore
NO-GO. Full suites started only as diagnostic evidence and were intentionally
terminated after that verdict; they are not acceptance evidence.
This tracked plan names completed or rejected parent identities but does not embed the containing successor's own commit OID: changing this file would change that OID recursively. The canonical AOI task plan/state must instead bind the exact clean completion identity before fresh review and execution. The detector remains a bounded direct-token/known-shell guardrail, not a general shell-equivalence engine or DLP. No older seal, doctor PASS, package, test result, or canary authorization qualifies the containing successor. No successful live Codex turn, final integrity seal, encrypted local bundle, downstream installation, or ARISE workload is claimed here. At this historical checkpoint the route treated remote CI/publication as forbidden; the 2026-07-23 selective protected-files decision supersedes that interpretation.
The later clean candidate 76b6aefe2015d5e6db77af49112fb3b7aab1d5f0,
tree f0c115a4b32dd68fca38dd6ca2dfdc09b5a6ba75, passed its exact Windows and
fresh-ext4 WSL suites, static gates, package/isolated-install review, and
disposable WSL/Windows hook-routing smoke. Before any App Server process was
started, v14 rejected the first fresh read-only canary plan with P0/P1/P2
0/2/1: the driver lacked exact installed-source/config assertions and the
core bridge preserved/rechecked a Git endpoint only for workspaceWrite, so a
readOnly checkout or config could drift after intent capture. The attempted
v1 preparation was abandoned before packet-arm-prepare; authenticated
inspection showed launches=[], its Chief credential was released and removed,
and it is negative evidence only. Therefore every 76b6aefe PASS, wheel,
bundle, review, and canary authorization is historical diagnostic evidence and
cannot qualify the containing repair successor.
The first dirty repair then made both sandbox modes preserve and recheck that
endpoint, but v15 rejected it with P0/P1/P2 0/1/1. Mutation-path claim
coverage is intentionally empty for a clean checkout, so adding, removing, or
changing a still-live task claim did not change the endpoint at any of the
three freshness gates. The P2 was missing direct regression coverage for a
readable historical readOnly issuance marker whose endpoint CAS field is
null. The containing repair therefore keeps mutation-path coverage for its
original purpose and adds a separate, content-addressed full live task-claim
authority record. It binds every reserving claim's token, owner, observed
status, exact worktree, and canonical lock scope even when Git status is clean.
Historical null-CAS or v1 endpoints remain inspectable as history but cannot
reserve or cross the process-start boundary. No v15 result is promotion or
live-runtime evidence.
That repair was committed as e39e287d06c60efb40b27c7d9905b71ddab593c8;
the documentation-only successor a85932a715c0a8142be4641a24180c4309cd6358,
tree ba48017221ebc3cc1f8b821f362c3b7741318826, received an exact clean
P0/P1/P2=0/0/0 review. Its exact Windows suites and static gates passed, but
two fresh-ext4 WSL full-suite attempts produced three failures that each passed
when isolated. Reviewer v20 accepted P0/P1/P2=0/1/0: all three failures are
synthetic test fixtures that assumed monotonic wall clocks across subprocesses.
The bounded successor canonicalizes only causal fixture ordering, uses a fixed
far-past expired-arm window, and derives permit fixture arm time solely from the
subprocess-recorded registration time. Production arm, permit, and expiry
checks remain strict and unchanged. Every a85932a PASS is diagnostic and
non-transferable; the containing clean successor must regenerate all gates.
Exact candidate 91ffb4ec02d0971cf5989ed1da104dfffabf6970, tree
83ccaa691aab99066514cffc66e0d0fc2e195a98, then passed exact Windows,
static, package/install, and structural canary-driver gates. Its fresh-ext4 WSL
full suite nevertheless failed one positive permit-issuance fixture after
1,593 passed, 29 skipped; the named test passed only on an isolated rerun.
The persisted Chief-planned timestamp had been causally clamped ahead of the
next child process's wall clock. Sleep-based attempts remained nondeterministic
under WSL clock steps and are rejected. The containing test-only repair runs
successful issuance and consumption through a tests/-only subprocess driver
and the full CLI composition root with an exact post-plan time. Production
source does not read the test clock variable. A direct runtime regression proves
pre-plan issuance fails before publication; production validation and negative
CLI paths are unchanged.
On the rejected v42 dirty bytes, the original failing node passed ten
consecutive runs on both Windows and a fresh ext4 WSL copy. The complete permit
CLI/runtime focus then passed Windows 32 passed, 2 subtests and WSL 32
passed; native and emulated-win32 mypy each passed 87 production files,
compileall, strict MkDocs, and diff-check also passed. Those are historical
bounded pre-commit contract results, not clean-candidate promotion evidence.
Reviewer v42 nevertheless rejected those bytes with P0/P1/P2=0/1/2: the
consumer environment retained AOI_CHIEF_CREDENTIAL_HOME, and an independent
child recovered the live token; one negative resource-drift path contradicted
the direct-path documentation; and the focused logs did not bind commands to
source identity. The v43 successor removes every AOI_CHIEF_* and
AOI_CREDENTIAL_* locator plus the test-only backup root, makes the child
driver reject any such consumer input, adds a fresh-child credential-resolution
negative regression, restores the resource-drift negative to the ordinary CLI,
and regenerates self-identifying Windows/WSL evidence before re-review. The
original failing node passed ten consecutive runs per platform; the complete
permit CLI/runtime/reachability focus passed Windows 35 passed, 2 subtests and
fresh-ext4 WSL 35 passed, including an injected credential-locator rejection
before CLI entry with zero ledger mutation. Both logs bind base HEAD/tree, exact command, Python
executable/version/SHA, pre/post SHA-256 and sizes for all six dirty paths,
porcelain status, and diff-check; every pre/post source identity is equal. This
remains dirty-byte contract evidence pending a fresh independent review.
All 91ffb4e PASS, package, review, and driver evidence is superseded and a
fresh exact successor must regenerate every promotion gate.
Exact baseline be46e89b427b35d48e8813880a684b9333354506, tree
250b4fa3de08513493b95aa5d8362e4892700087, subsequently passed its complete
local Windows, fresh WSL, typing, compile, docs, package, and isolated-install
gates. Read-only live attempt v12 then durably reached
thread_start_send_pending but rejected the correlated response and
terminalized launch_unknown; it was never retried and never reached
turn/start. Runtime stderr also proved that the unsupported requested name
gpt-5.6 was silently replaced and that default apps/remote-plugin/
remote-control surfaces were active. Independent v49 review therefore returned
P0/P1/P2=0/3/0 and rejected every fresh live launch until all three P1s are
repaired. Its exact report is external evidence SHA-256
f782f6154929befc164136d3b0260910c8ba75ac9b0a29c60e53116438d32350.
Clean exact commit ff8fd223073ed800f8d9cdc454c4855be8c9e71d, tree
c578a4ee526e0ec458a3610c720cc70382c14ac2, contains the v49 production
repair. Production
App Server argv now supplies --strict-config plus exact overrides disabling
web search, apps, remote plugins, and multi-agent loading; thread/start
repeats those controls as defense in depth. Under local_files, the adapter
requires an absolute non-linked CODEX_HOME whose initial inventory is exactly
auth.json, config.toml, and managed_config.toml; it parses the two policy
files against closed tables, binds their paths/digests and the safe inventory
into the process journal, and rechecks them after the version probe immediately
before Popen. managed_config.toml fixes allow_remote_control=false, pins the
three disabled feature flags, and uses allowed_web_search_modes=[] so only
the implicit disabled mode is permitted.
After initialize, a content-addressed model/list pending/observed pair now
requires exactly one visible model == requested_model, a supported requested
effort, and no unconsumed pagination before thread/start. The bounded intent
model set uses current visible stable slugs such as gpt-5.6-terra; legacy
gpt-5.6 is rejected at intent sealing and cannot fall back silently. A lost
read-only model-list response is a known failed pre-thread outcome, whereas
uncertain process/thread/turn starts retain their prior non-retryable unknown
semantics.
Finally, correlated success bytes rejected by generated schema, sealed policy,
or model-catalog policy are synchronously written to the task-local non-Git CAS
and read back before the typed fault is raised. Only their exact digest/size
enter the transport journal; they cannot become a response observation. A
schema-valid App Server error envelope now takes that same rejected-evidence
path and cannot call the success-response observer or fabricate an initialized,
thread-started, or turn-started milestone. At the pre-commit checkpoint,
targeted evidence was diagnostic on dirty bytes:
adapter/contract/controller
plus CLI now pass 124 tests with 1 platform skip. The nine additional
adapter/authority/mutation/projection/reachability/runtime/semantic fixture
files pass 115 tests, 4 platform skips, and 10 subtests. Native and
emulated-win32 mypy each pass all 87 production files; compileall and strict
MkDocs also pass. These are dirty-byte contract/static/documentation evidence,
not promotion evidence. The containing ff8fd223 bytes then passed the exact
Windows full gate: non-CLI 1,434 passed, 33 skipped, 323 subtests plus CLI
172 passed, 8 skipped, 70 subtests, totaling 1,606 passed, 41 skipped, 393
subtests. Its fresh-ext4 WSL full gate is nevertheless a promotion-blocking
FAIL: 1 failed, 1,617 passed, 29 skipped, log SHA-256
9d9b9eaf416c4011dc817df86af90a5e33e6246e871d3c114c405ced87ed3800.
The failed reachability node passed an isolated 6.50-second rerun, which rules
out ordinary five-minute test duration but does not replace the full failure or
directly measure the inferred host/WSL clock step.
The only authorized containing repair derives arm time from the later of the
persisted migrated semantic head and resource-session registration, runs permit
issue/consume through the existing tests-only fixed-clock driver, and runs
Codex transport issue through a new
tests-only driver that patches the already-existing _now seam to a canonical
UTC instant inside the original 3/4/5-minute windows. Missing, malformed,
timezone-less, noncanonical, or non-issue driver input fails before CLI work.
No production source, expiry window, comparison, tolerance, prior FAIL, canary,
or promotion claim changes. A clean successor must rerun every exact-byte gate
before any fresh canary.
That tests-only clock successor was committed as exact 68c9c18d63cc3ed857fe1d9be0973c44a49c97b7,
tree ef25ad6403a8b5c7fb049563ee2a552c30734f1c. Its diagnostic Windows full
gate passed 1,608 passed, 41 skipped, 397 subtests, and its fresh-ext4 WSL
full gate passed 1,620 passed, 29 skipped. Independent exact-source review
v55 nevertheless rejected it with P0/P1/P2=0/1/0: the adapter accepted
model/rerouted as auxiliary, validated only correlation, and the controller
dropped it, so a later turn/completed could produce a completed receipt even
after the runtime left the sealed exact model. Those full-suite PASS results,
all packages built from that commit, and every earlier seal are rejected-
candidate diagnostics only.
Read-only design review v58 accepted the smallest sound repair: adapter
persist-before-parse typed rejection, a controller-owned exact-wire CAS sink,
controller observation pre-scan as defense in depth, and explicit transport
contract wire/fault kinds. The active v59 implementation uses a fixed redacted
ModelReroutedViolation; missing fields, wrong from/thread/turn, arbitrary
destination, and complete pinned-schema reroutes all take the same failed
terminal path. A queued completion cannot enter the journal. Current dirty-byte
focused evidence is 15 passed for the new reroute falsification subset and
139 passed, 1 skipped for the core adapter/controller/contracts/CLI matrix.
The expanded twelve-file Bridge/confidentiality matrix then passed Windows
224 passed, 4 skipped, 4 subtests and fresh-ext4 WSL 227 passed, 1 skipped;
both logs bind the same base HEAD/tree and identical pre/post dirty paths.
Native and emulated-win32 mypy each passed 87 production files, compileall and
strict MkDocs passed, and tracked/packaged policy bytes remain identical. This
is implementation evidence only: no clean successor, App Server canary,
package qualification, promotion, installation, or ARISE execution is claimed
yet.
Fresh dirty-diff review v60 rejected that first implementation with
P0/P1/P2=0/1/0. Although the method was already known to be
model/rerouted, the adapter still required params to be an object before
the CAS callback, could synthesize an evidence reference when the callback was
absent, and the controller parsed raw/test-double consistency before its CAS
sink. A bounded non-object payload therefore produced a generic pre-CAS fault.
The corrected slice introduces a raw-only method/wire/digest carrier, requires
the controller callback, and recomputes/persists the exact raw digest before
any adapter payload classification or controller raw/parsed comparison.
Missing or throwing callbacks remain fixed redacted fail-closed errors without
fabricated evidence. The expanded reroute subset now passes 19 tests,
including non-object params, missing/throwing callback, and raw/parsed mismatch;
the next twelve-file matrices passed Windows 228 passed, 4 skipped, 4
subtests and fresh-ext4 WSL 231 passed, 1 skipped, with static gates green.
Those results still did not authorize a commit: fresh dirty review v62 rejected
the bytes with P0/P1/P2=0/1/0. Persistence was deferred from reader
recognition to consumer dequeue, so an earlier queued completion, a later
reader error, a full main queue, or duplicate ordering could leave recognized
reroute bytes unpersisted and could still permit completed.
The active follow-up therefore moves the mandatory exact raw CAS callback to
the stdout reader's method-recognition boundary, before enqueue or reading a
later line. Every recognized duplicate is persisted independently; successful
recognition retains a typed reroute fault that outranks later generic
reader/backpressure errors and preempts an already queued completion. Consumer
classification can use only the verified evidence digest/size, while the
controller raw/test-double defense remains. New completion-order, later-error,
queue-full, duplicate, field-type, CAS divergence, and controller sink-failure
regressions pass as a 30 passed reroute subset. The complete current dirty
twelve-file matrix passes Windows 239 passed, 4 skipped, 4 subtests and a
fresh ext4 WSL clone 242 passed, 1 skipped; the WSL receipt records every
exact test path. Native and win32 mypy over 87 production files, compileall,
strict MkDocs, tracked/packaged policy identity, and diff-check also pass.
These are v63 pre-review implementation checks only: the plan evidence wording
change creates new bytes that must rerun exact gates and then receive a fresh
independent dirty review. All v61 PASS logs remain pre-v62-repair diagnostics.
Fresh exact dirty review v65 then rejected v64 with P0/P1/P2=0/1/0. The
reader called CAS at recognition, but did not publish its typed fault until the
callback returned. A threaded probe held that callback in flight while a prior
queued completion passed both instantaneous reader-error checks; the adapter
returned terminal and the controller published completed before the callback
released. The active repair now increments a condition-protected in-flight
barrier before callback invocation and publishes the verified typed or fixed
callback fault before decrement/notification. Queue consumption, terminal-turn
return, and controller pre-completion defense all wait on that bounded barrier.
Threaded success/raise/diverge regressions and an actual stdout-loop
duplicate-with-full-queue regression pass in a 34 passed reroute/boundary
subset. The complete v66 dirty matrix passes Windows 244 passed, 4 skipped, 4
subtests and a fresh ext4 WSL clone 247 passed, 1 skipped; native/win32
mypy, compileall, strict MkDocs, policy identity, and diff-check also pass.
These are implementation checks only. Recording those counts changes this plan,
so the resulting exact bytes still require a v67 rerun and another independent
review; every v64 PASS remains pre-v65-repair diagnostic only.
The exact v67 rerun preserved the same bytes across Windows 244 passed, 4
skipped, 4 subtests, fresh-ext4 WSL 247 passed, 1 skipped, and all static
gates, but fresh dirty review v68 still rejected it with P0/P1/P2=0/1/0.
After the controller's last instantaneous wait returned and before terminal
journal persistence, the reader could newly recognize a reroute and block in
the CAS callback while the controller committed immutable completed; success,
callback raise, and divergent-reference probes all reproduced the bypass.
Accepted read-only architecture packet v69 therefore replaces the
pre-completion check with a terminal stream seal. turn/completed is only a
candidate until the one-shot controller closes stdin, the pinned process exits
naturally with status zero, stdout and stderr are fully drained and joined, and
the reader condition proves both done/zero-inflight/no-fault. Only then may that
observation-derived terminal journal row be appended. Forced terminate/kill,
nonzero exit, partial output, live reader, or callback/join timeout permanently
aborts the clean seal and cannot produce completed. Exact-CAS reroutes may
instead append typed failed, and other owned faults may append
runtime_unknown, without claiming clean stream quiescence; bounded cleanup
then follows. This keeps the strong exact-model contract without
pretending App Server exposes a flush watermark that it does not. The current
implementation and regressions are pre-review bytes; all v67 PASS and v68
review evidence remain rejection/diagnostic history and cannot authorize a
commit.
Fresh implementation review v71 rejected exact v70 with P0/P1/P2=0/1/0.
Although _join_readers_until() waited for both reader threads to stop,
_stderr_reader() did not retain exceptions or publish a done-success state;
an OSError therefore killed the stderr thread, satisfied join, and allowed a
natural-zero process with clean stdout to seal and publish completed. The
active repair gives stderr the same condition-protected completion/fault
boundary as stdout, requires both done flags in the seal, and adds an actual
controller plus production reader/seal regression for stderr failure. No v70
test or review evidence authorizes full qualification or commit.
Fresh review v73 then rejected exact v72 with P0/P1/P2=0/1/0: a native
OSError from process wait(), or from poll() after stdin close failed,
escaped the adapter as a non-transport exception. The controller's typed catch
did not terminalize it, leaving the durable journal at turn_started with no
terminal receipt. The active repair normalizes every owned stdin/poll/wait
boundary to fixed RuntimeDisconnected, marks the stream ABORTED, performs
bounded no-throw cleanup, and adds actual-controller regressions for both
sequences. It deliberately does not catch arbitrary durable-sink OSError at
the controller level, because such a failure can make the persistence result
ambiguous and must not be retried as though it were a known process fault.
Fresh review v75 rejected exact v74 with P0/P1/P2=0/2/0. First, stdin close
failure followed by a normal poll()==0 was still treated as a clean process
exit and could seal completed; policy requires every stdin close failure to
abort. Second, an exact-CAS ModelReroutedViolation already retained by the
reader could be replaced at the controller boundary by a later process-wait
RuntimeDisconnected, incorrectly degrading known failed/model-rerouted to
runtime_unknown. The active repair removes the poll-based recovery from
stdin close failure and routes every seal failure through the reader's retained
fault precedence before constructing a later generic process fault. New
actual-controller modes cover close-error with exit zero, unavailable stdin,
and typed-reroute plus wait-error ordering. No v74 evidence authorizes full
qualification or commit.
Fresh exact-artifact review v77 rejected v76 patch
4711b7117eb30f6281369a741019343eeb5817ccf3e0d2d1b5028b1e7a16c392
(108704 bytes) with P1/P2/P3=2/1/0. A poll() fault skipped every later
terminate/kill step and unconditionally erased the still-live process handle;
a terminate plus wait fault had the same result. Separately, reader join()
handled only RuntimeError, so an owned OSError escaped through controller
cleanup, left the journal at turn_started, and prevented terminal receipt
publication. The liveness post-check also covered stdout but not stderr. The
active repair separates poll/terminate/wait/kill into independent bounded
attempts, keeps an unconfirmed-live child handle, normalizes owned join and
liveness exceptions, and accounts for both readers. Failure paths also settle
an already in-flight reroute callback within their original absolute deadline,
so a retained exact-CAS reroute still outranks a later join/process fault.
Actual-controller regressions cover poll failure with terminate fallback,
terminate/wait failure with kill fallback, fully unconfirmed exit with retained
handle, raw join failure, typed-reroute plus join failure, and stderr-only live
reader. The resulting diagnostic matrix passes 15 modes; both complete
transport files pass 118 passed, 1 skipped, strict typing passes, and
diff-check is clean. These are mutable implementation checks only. The repaired
bytes still require a fresh immutable artifact, exact independent review, and
all full qualification gates; no v76/v77 evidence authorizes commit.
Exact v78 review v79 returned P1/P2/P3=0/0/0 and admitted the subject to full
qualification. Its v81 Windows run passed non-CLI 1492 passed, 33 skipped, 327
subtests plus CLI 172 passed, 8 skipped, 70 subtests; native/win32 mypy over
87 source files, compileall, strict MkDocs, policy identity, pinned resources,
and diff-check also passed. The fresh ext4 WSL full run nevertheless failed all
15 parameter instances of the new production-adapter cleanup matrix before
behavior execution: the test passed the venv symlink Path(sys.executable) to
the deliberately strict production constructor, which rejects linked
executables. The active test-only repair resolves that synthetic placeholder to
its real regular executable while retaining the production symlink denial and
its dedicated negative tests. WSL reported 15 failed, 1661 passed, 29 skipped;
all v78/v79/v81 PASS and review evidence is now superseded for acceptance. The
containing bytes require a fresh exact artifact/review and complete Windows/WSL
rerun.
The v82 portability focus bound the repair to diff SHA-256
208bc877d8e5d0401568aaa66b505d4479ae82da6d092ec9a57b2146a85831a3
(118885 bytes). All 15 production-stream-seal parameter instances passed on
native Windows and in a fresh WSL ext4 clone, and both runners reproduced the
same pre/post diff digest and size. The Windows evidence log is SHA-256
4ce5566b9f417977bb3128bab06bb3cbbd43d952f0cc6f42531583a2e80177f5;
the WSL log is SHA-256
561b57d785fbeaa4a154e2bf038e54c34e6e6a49eca6db8b7f1cdaf32c2817c3.
This is focused portability evidence, not a replacement for exact containing
source review or the complete Windows/WSL qualification matrix.
The exact v83 subject subsequently passed v84 Windows non-CLI 1492 passed, 33
skipped, 327 subtests, Windows CLI 172 passed, 8 skipped, 70 subtests, fresh
ext4 WSL 1676 passed, 29 skipped, and the native/win32 typing, compile, strict
docs, policy/pin identity, and diff gates. Whole-diff review v85 nevertheless
returned P1/P2/P3=0/1/0 and rejected commit because this plan, policy, and
changelog incorrectly described a successful clean stream seal as authority for
every fault-derived terminal row. The active text repair limits that seal claim
to observation-derived terminal rows, preserves exact-CAS failed and owned
runtime_unknown fault terminals without a false quiescence claim, and adds an
early-reroute controller regression proving exact CAS, never-completed,
no-successful-seal, and bounded cleanup. All v84 PASS evidence is diagnostic for
the superseded bytes; the containing subject requires a fresh exact review and
proportionate rerun before commit.
- The optional
aoi-codex-bridgeentry point exposes finiteissue,run,inspect, andverify-mutationcommands. Onlyissueaccepts a Chief credential.runreceives one exact permit SHA and issuance marker; it cannot receive or retain reusable Chief authority. - Repository onboarding now treats a hook as one platform pair, not two
independent command strings. Native Windows and non-WSL POSIX retain the
exact direct provenance-bound launcher. A canonical WSL session is detected
only when the non-Windows host, Microsoft kernel release,
WSL_DISTRO_NAME, absoluteWSL_INTEROP, POSIX launcher/root, and current passwd user all agree. It then writes the direct Linuxcommandand this fixed no-shellcommandWindowsgrammar:
wsl.exe --distribution "<distro>" --user "<user>" --cd "<root>" --exec "<absolute-hook>" --hook-version 6 --project-root "<same-root>" --provenance-sha256 "<digest>"
Quoting/order, distro, user, cwd/root equality, absolute inner launcher, and
digest are canonical. Spaced distro and POSIX path values remain one quoted
argument; POSIX backslashes are rejected because they make Windows command
line quote boundaries ambiguous. Partial WSL signals, native-Windows WSL UNC roots,
shell wrappers, arbitrary prefixes, PATH-resolved inner hooks, duplicate or
reordered flags, and pair drift fail before onboarding publication or block
doctor/offboard. A proof-changing reinstall may rotate one current pair only
when the existing handler byte-matches the pair reconstructed from the
currently persisted validated provenance receipt; AOI archives that receipt
and rejects partial old/new or cross-bound pairs. It writes the desired hook
pair before replacing the receipt, making a receipt-publication crash
fail-closed and resumable rather than stranding the prior pair. The older
tolerant WSL parser remains legacy ownership recognition only; it cannot
establish current trust.
Onboarding/offboarding also conservatively recognize direct tokens and one
bounded known-shell operand; tokenizer quote failures carrying an AOI hook
signature and CMD caret-normalized AOI signatures fail closed. This does not
claim exhaustive shell parsing, DLP, or protection from an ungoverned
same-user process.
wsl.exe itself and the Codex /hooks trust decision remain cooperative
host/user boundaries.
- Semantic-v2 packet activation is now reachable without a legacy task write.
packet-arm-prepare derives a schema-v3 transaction from one canonical
ready packet, routing arm, decision, one-shot permit, and exact semantic
head. Chief issuance reuses the complete core packet, parent/root-session,
canonical resource event/receipt/registration, topology, envelope, and skill
gate; first unreserved consumption without Chief credentials repeats that
gate and commits routing authority, permit projection, and canonical
ready -> armed packet state in one semantic compare-and-append. Before
initial issuance/consumption, a terminal task, stale/tampered authority,
absent packet delta, old schema, or changed head fails closed. An exact
already-committed replay is historical event/projection recovery and does not
re-authorize a packet or launch; it returns before mutable external packet
files are rechecked, while every new downstream Bridge transition applies its
own canonical authority gate. Cohort schema v2 remains separate and is not
silently upgraded to the standalone packet-owning transaction.
- Permit consumption is one semantic CAS: the exact active packet arm becomes
transport_reserved, the packet becomes bridge-owned dispatched, and a
sealed ownership object binds task/packet/arm/launch/intent/permit/
reservation/routing bytes. It does not fabricate SubagentStart, an agent
id, thread id, turn id, or runtime observation. Transport ownership upgrades
the task and packet dispatch generation to v2; dropping either marker or
routing the packet through an ordinary core dispatch path fails closed.
- One Chief-created, per-launch OS file lock serializes the complete
controller lifetime. This proves cooperative at-most-one controller-owned
start sequence for the same AOI platform lock domain, not adversarial
same-user protection and not cross-Windows/WSL mutual exclusion. Two
different launch ids for one arm are instead arbitrated by the exact
semantic head and packet ownership CAS, so only one can reserve.
- The exact stable runtime remains Codex 0.145.0: App Server SHA-256
5163c75ed88d460b35b03c8d8f4ef190b3bdd09971d7ac2bd90b48c435f1cf14,
273-file schema-manifest SHA-256
6b8bfa74e475c6c9b46926c46f287f47873d188b13ab3df8db4633602db73262,
and combined v2 schema SHA-256
6253fd70273c2f33c42d0b6090eac771580c994b3c6eed4277598de08a5e69ec.
Executable bytes/size, schema, prompt, cwd, approval, sandbox, and correlation
drift fail before the runtime-process boundary. Version output is checked by
a bounded exact-binary probe after that boundary and before the App Server.
- The pinned 0.145.0 generated protocol uses line-delimited RPC objects without
a jsonrpc member. A real raw initialize response was the exact shape
{id,result}; the old fake peer incorrectly emitted JSON-RPC 2.0 envelopes,
so the old adapter rejected the live response before initialization. The
current repair emits schema-matching {id,method,params} requests and the
exact method-only initialized notification, rejects tagged/malformed
envelopes, and hashes exact inbound wire bytes. Response-derived semantic
milestones retain their actual request methods (initialize, model/list,
thread/start, turn/start) instead of claiming the similarly named
notification methods. A correlated success result is validated against the
pinned 0.145.0 required shape before the response journal callback;
initialize must report the exact isolated Codex home, and model/list must
expose exactly one visible requested model with the requested effort and no
remaining page before any thread can start. The bounded intent rejects
unsupported aliases, so the runtime cannot silently substitute a fallback.
thread/start additionally rebinds cwd, model, approval, sandbox/network,
ephemeral state, and model provider to the sealed intent. The supported
lifecycle notification subset checks pinned Thread/Turn/item required fields
and timestamps. An invalid thread/turn success response remains a
non-idempotent launch_unknown and is never resent. Exact rejected-response
bytes are synchronously preserved and read back from task-local non-Git CAS,
then become fault evidence only; a schema-valid App Server error response is
also barred from the success observer and uses this fault path. Other
synthetic faults hash a finite,
redacted reason code. A fault may not populate response_sha256 or
wire_event_sha256; malformed error envelopes fail before response
observation. Historical commit 0201799 passed the eleven-file Bridge/
confidentiality/export matrix as 149 passed, 4 skipped (68/1 adapter/
controller/contracts plus 81/3 CLI/runtime/authority/reachability/
projection/mutation/confidentiality/export). Its WSL full-suite diagnostic
later reached 1,561 passed, 29 skipped but exposed two wall-clock-order
fixture failures. Its successor c73c0ca makes the event factory consume
the contract's single wire-method table and derives arm time strictly after
the persisted registration. Exact c73c0ca then passed the complete local
Windows/WSL suites listed above. All predecessor results remain historical
evidence; exact containing-commit reruns and review are mandatory.
- Reservation, every process/request/response milestone, terminal receipt,
and mutation elevation use deterministic semantic command identities.
Exact publication-response-loss retries reconstruct the previous ledger
head. The reservation's authenticated pending binding is the durable
binding-to-event crash witness: only that exact marker-bound binding may
resume the same still-terminal semantic command after permit expiry; no
binding, a different pending binding, or head drift remains a fresh launch
and fails closed. Ambiguous process/thread/turn starts never resend. turn/interrupt
response is nonterminal observation, and only turn/completed establishes
the runtime terminal state. A completed, failed, or interrupted
terminal journal/receipt is invalid while any item remains started;
runtime_unknown deliberately preserves an outstanding item as incomplete
evidence rather than fabricating completion.
- The durable process_start_pending callback is the runtime-process
authorization boundary. Immediately before committing it, AOI revalidates
the earlier of permit/arm expiry, the complete live packet ownership object,
packet/task dispatch generation v2, fresh reserved namespace row,
local_files storage preflight, and—for both readOnly and
workspaceWrite—the exact pre-Git/tree/status/claim endpoint.
It authorizes the exact-binary --version probe and subsequent App Server
Popen; no child executes before it. After pending is durable, a crash is
ambiguous and must reconcile without automatic restart. CLI process-start
output is derived only from journal evidence: not_started,
process_start_pending_only, or process_started_observed. The boolean is
named
app_server_start_durably_observed; it never claims a physical Popen that
occurred but could not be persisted.
- Every readOnly and workspaceWrite issuance must validate an exact pre-turn
Git endpoint against AOI claims, preserve it in task CAS, and bind that CAS
SHA into the immutable issuance marker. The endpoint binds both
mutation-path coverage and a separate complete live task-claim authority
digest, so a clean worktree cannot erase claim add/remove/owner/status/
worktree/lock drift. verified_mutation remains a
workspaceWrite-only, separate semantic
projection/binding over pre/post Git snapshots, trees, claim endpoints, and
the original runtime receipt. It does not overwrite
codex_runtime_observed and never infers task completion.
The preserved endpoint is recaptured again after issue/before semantic
reservation and again at process pending, so Git or full claim-authority drift cannot be
attributed to the turn merely because the task semantic head stayed fixed.
- Under local_files, issue, reserve, and process-pending preflight the AOI
artifact/CAS root and writable cwd. A confirmed network or common sync root
is denied before publication or Popen. Windows drive-letter paths are checked
with GetDriveTypeW plus DOS-device alias inspection: mapped network drives
are confirmed-danger, while missing roots, metadata failures, SUBST aliases,
and link/reparse traversal are explicitly unverified and also fail the
confirmed-local launch/storage gate. The caller-visible lexical drive is
classified before the resolved target, so resolution cannot erase a SUBST/
DOS-device alias. file: URI paths are strictly percent-
decoded before classification, and every Windows
FILE_ATTRIBUTE_REPARSE_POINT tag is covered rather than only symlink/
junction helpers. The child receives
networkAccess=false and a scrubbed
environment. Before process pending, the adapter also requires an isolated
exact-inventory CODEX_HOME, parses and hashes closed config.toml and
managed_config.toml policies, binds them into the process journal, and
revalidates them after the exact-binary version probe before Popen. Production
argv and thread/start.config independently disable web search, apps,
remote plugins, and multi-agent loading; the managed policy denies remote
control. The child environment contains no known reusable publish
credentials. Credential matching
is finite and cannot prove an unlisted secret absent. This is still not DLP
or an offline-model guarantee.
- Contract tests: the historical packet-owning closure slice passed 55
tests, 9 subtests across dispatch protocol, standalone/cohort permit runtime
and CLI,
plus a real task-composition test covering legacy migration through canonical
arm and Bridge issuance. Exact parent c73c0ca later passed a two-shard
Windows partition: non-CLI 1,382 passed, 33 skipped, 294 subtests and CLI
172 passed, 8 skipped, 70 subtests, for 1,554 passed, 41 skipped, 364
subtests total. Its fresh ext4 WSL clone passed 1,566 passed, 29 skipped
plus compileall. Those broad runs establish only the exact parent; the
documentation-only containing commit receives its own final evidence. The
covered surfaces include bridge contracts, canonical
authority, projection/runtime/controller, fake stdio lifecycle, Git mutation
evidence, CLI, confidentiality/export, packet generation/downgrade,
semantic objects, transition permits, and distribution metadata. New
falsification includes two concurrent runs with one fake process owner, two
independent OS processes contending on the launch lock, lock sentinel/
hardlink tamper, same-arm different-launch CAS, issue-to-run Git drift,
expiry crossing before pending, executable substitution, sync-root/mapped-
drive/unverified-volume storage, outstanding terminal items,
generic packet cancellation, packet/ownership/generation drift, and exact
retry. This remains contract/fake-runtime evidence.
- Independent bridge review: an earlier review rejected promotion on
canonical route binding, stale Git pre-image, auxiliary correlation,
distribution coverage, duplicate process ownership, non-atomic arm
consumption, and consume-time expiry. The current source implements each
requested correction plus the later confidentiality/process-start hardening.
A 2026-07-20 fresh read-only review of the then-uncommitted bytes found no P0 but
rejected canary on three P1s: terminal runtime/packet status mismatch, the
current task's truthful standard binding versus the planned local_files
final route, and Chief credentials surviving in the controller process. It
also found version-probe boundary, finite credential detection, and malformed
Markdown-heading P2s. The source implements all six corrections. A following
v4 read-only review found no P0/P1 and one P2: the CLI output boolean could
be read as proof that physical Popen occurred when it represented only a
durable journal observation. It is now named
app_server_start_durably_observed and has a response-publication-loss
regression. Those review dispatches are truthfully recorded as
manual_unverified because the collaboration spawn did not emit an
AOI-consumable SubagentStart; neither rejected review is approval. The v5
review then found no transport P0/P1, but rejected canary and promotion on
two local-install P1s: the installed provenance omitted the Bridge
entry-point/launcher/module receipt, and the local wheel fixture still
emitted only three console scripts. The repair now binds the fourth Bridge
entry point through the local contract, installed runtime/RECORD checks,
generated-script checks, and schema-v2 receipt. Its eight-file consumer
matrix passed on that exact repair as 142 passed, 12 skipped, 32 subtests on
Windows and 149 passed, 5 skipped on WSL; all three review dispatches remain
manual_unverified. Pre-v6 package rehearsal then exposed another real-repo
P1: the source-manifest path grammar rejected tracked dotfiles such as
.gitignore and .github/workflows/test.yml. The grammar now accepts safe
leading-dot relative paths while still rejecting ./.., absolute,
normalized, backslash, and traversal paths; the fixture tracks both dotfile
forms and passes on Windows/WSL. The following v6 review found P0=0/P1=2/P2=0:
Windows mapped drive letters were not classified by volume type, and a
terminal journal could leave an item started. Its arm expired before the
reviewer returned, so AOI records it as a procedural-expiry advisory, not an
authorized review attestation. Both source defects and their negative tests
were implemented. The valid-arm v7 review accepted outstanding-item closure
but found one remaining locality P1: percent-encoded drive colons in file:
URIs and generic non-junction reparse attributes could bypass classification.
Strict URI decoding, generic reparse-bit inspection, doctor/Bridge negative
tests, and missing-leaf ancestor traversal are now implemented. A fresh v8
review closed those direct gaps but rejected one alias-ordering P1 and one
malformed-URL P2: resolving before drive inspection could erase the SUBST
identity, and malformed IPv6 file hosts could escape as raw ValueError.
Lexical-drive-first plus resolved-target classification and safe invalid URL/
port redaction are now implemented with regressions. v9 found one remaining
reporting-only P2 for malformed URI kind/redaction consistency; that was
repaired, and v10 independently returned P0=0/P1=0. v10 authorized managed
policy refresh and a bounded read-only scratch canary. Its sole P2 was this
paragraph's stale reference to v9; this documentation-only repair still
requires fresh review before final promotion closure. A later reachability/
CAS review rejected the new packet-owning slice on two P1s: terminal tasks
could still reach the pure arm transition, and semantic issuance did not
invoke the complete core packet authority gate. Both defects now have source
and negative-test repairs. The following v2 review found one further P1: the
detached arm was internally self-consistent but its parent/root-session and
resource event/receipt/registration authority were not rebound to canonical
task state. It also found two P2s covering exact committed-replay wording and
missing direct slot-collision tests. The current repair extends the core
composition callback at both issue and first unreserved consume, upgrades the
CLI fixture to a real registration/migration path, adds parent/resource/
registration and exact/wildcard collision falsification, and narrows the
replay claim. The fresh v3 exact-diff review returned P0=0/P1=0/P2=0 and
accepted those then-uncommitted bytes for a clean local commit. It independently ran six
targeted closure regressions plus the reverse exact-to-wildcard probe and
retained the boundary that reachability is composition evidence, not a live
App Server canary. The dispatch is recorded as manual_unverified because
collaboration still emitted no AOI-consumable SubagentStart; its technical
outcome is accepted, but exact committed bytes still require the remaining
profile-aware doctor, full-suite, canary, integrity, and installation gates.
The first exact-commit Windows run then exposed one architecture-boundary
failure: semantic command handlers lazily reverse-imported cli.py to obtain
the gate. The repair makes the CLI composition root inject the validator and
makes a missing injection fail closed. The affected architecture, permit CLI,
and real reachability tests pass as 16 passed, 2 subtests. A later
read-only protocol review (bridge-live-protocol-review, truthfully
manual_unverified) found no P0, one P1 for synthetic fault bytes mislabeled
as response/wire evidence, and one P2 for unvalidated error-envelope shape.
Both source defects received contract and negative-test repairs and required
a fresh clean-commit review. Exact review of clean commit
8a4aaab then returned P0=0/P1=2/P2=2 and rejected a fresh canary: response
bytes were mislabeled as notification evidence and method-specific success
schemas were not enforced before milestone publication. Its two P2s covered
low-discrimination synthetic fault digests and stale checkpoint wording.
Exact review of its successor 0201799 returned P0=0/P1=0/P2=2 and accepted
only a bounded read-only canary. Its two advisories were this file's stale
candidate wording and the unused duplicate runtime wire-method map. The
c73c0ca addressed both before canary execution; its fresh review returned
P0=0/P1=0/P2=1, with only the five stale evidence labels corrected by the
containing documentation-only commit. Review evidence for each newer exact
commit belongs in AOI state/local evidence and is never inherited from these
historical reviews.
- v38 pre-canary rejection: exact candidate
4f6d0b3df4e10769e47bef36efc8dd7aaec99a07, tree
dc7efa07aa685371c693f9c458d54ed800a5e0eb, had already passed local
Windows/WSL, package/install, and driver probes, but no new App Server process
was started. The independent v38 review rejected launch with P0/P1/P2
1/1/0: the external driver authenticated installed RECORD rows without
rejecting extra unrecorded import members, and production reservation retry
could not recover after a crash between pending-binding publication and the
semantic event once the permit expired. The production repair now treats
only the exact authenticated marker-bound pending binding as a recovery
witness and adds absent/wrong-witness falsification. The driver must next
enumerate the complete installed package/dist-info namespace before any AOI
import. A first dirty-byte source review accepted local commit with
P0/P1/P2 0/0/1; its advisory requested direct fresh-authority-revalidation
and pending-binding-plus-nonplanned-head regressions, both now present. The
v9 driver template now rejects unrecorded package files, top-level extension
shadows, extra dist-info files, and directory-closure drift before AOI import
on the historical isolated install. It remains structural/template evidence,
not authorization for a successor wheel or canary. The follow-up v40
cross-review returned P0/P1/P2 0/0/0, accepting the production bytes for a
local commit and the v9 closure structurally while explicitly withholding
canary and promotion authorization. Because the production bytes changed, every prior PASS, wheel,
install receipt, driver digest, and promotion checkpoint is historical only;
the containing successor requires fresh exact-byte evidence.
- Live App Server canary: attempted, not passed. The first disposable setup
stopped before Popen because its private Codex home was inside the governed
Git worktree. A fresh task then consumed one permit and durably observed the
exact pinned App Server process, but terminalized failed at initialize
because AOI required a jsonrpc member that the pinned runtime/schema omit.
The request was not retried, neither attempt mutated project Git, and private
Codex/Chief credential directories were deleted. The failed canary is
diagnostic evidence only. A wholly new task/packet/permit on the exact
reviewed containing candidate must run the read-only canary; only a pass may
unlock a separate writable scratch canary.
- Git mutation verification: fake-runtime + real disposable Git filesystem
tests prove separate runtime-versus-mutation evidence, pending binding/event
recovery, exact retry after later drift, and task_completion=not_inferred.
This is not a live Codex mutation canary.
- Promotion environment (superseded checkpoint): this checkpoint assumed
that local_files globally forbade push and remote CI. The 2026-07-23
selective protected-files decision rejects that assumption. Exact local
Windows/WSL evidence, independent review, integrity-v2 seal,
package/install smoke, and an encrypted local bundle remain prerequisites,
but final-SHA GitHub CI/publication now follow them. For a WSL-governed
downstream project that Windows Codex opens, package/install smoke also
requires a disposable exact-wheel codex-init, seven-event pair inspection,
doctor/offboard exercise, and a bounded Windows invocation of the exact
commandWindows into the same WSL state tree. A structural JSON or doctor
result alone is not runtime hook delivery. Historical GitHub PASS or failed
clean-checkout runs remain historical only.
- Complete Windows suite: exact commit ed91f12 passed a two-shard
partition: non-CLI 1,365 passed, 33 skipped, 294 subtests; CLI 172 passed,
8 skipped, 70 subtests; total 1,537 passed, 41 skipped, 364 subtests.
Native and emulated-win32 mypy each passed 87 source files; compileall and
strict MkDocs passed. Clean commit 8a4aaab later passed a diagnostic
two-shard Windows run: non-CLI 1,371 passed, 33 skipped, 294 subtests and
CLI 172 passed, 8 skipped, 70 subtests. Historical 0201799 was started as an
exact Windows/WSL rerun; its WSL full suite exposed the two deterministic-time
fixture failures described above. Exact parent c73c0ca subsequently passed
non-CLI 1,382/33/294 and CLI 172/8/70. These results establish the parent,
not later commits. Exact 1fcce28 independently passed non-CLI
1,382/33/294 and CLI 172/8/70, but its WSL and installation gates failed;
final successor evidence is recorded separately by AOI. Exact a85932a
later passed non-CLI 1,406 passed, 33 skipped, 323 subtests and CLI 172
passed, 8 skipped, 70 subtests; those Windows results do not transfer across
the fixture-only successor bytes.
- Complete WSL suite: exact ed91f12 was cloned to fresh ext4, all 259
tracked files were byte-equal to Git blobs, and passed non-CLI 1,369/29
plus CLI 180/0, total 1,549 passed, 29 skipped; compileall also passed.
A later fresh-ext4 8a4aaab attempt selected /usr/bin/python3 without
pytest and therefore produced no test evidence. Exact 0201799 used the
verified Python 3.12 environment and reached 1,561 passed, 29 skipped plus
two permit-fixture failures before this clock-order repair. Exact parent
c73c0ca then passed 1,566/29 plus compileall in a fresh ext4 clone. All
predecessor evidence remains nonqualifying. Exact 1fcce28 later reached
1,565 passed, 29 skipped, 1 failed; the isolated failing node then passed
ten times, which is diagnostic only. The synthetic fixture now clamps its
replacement record strictly after its source before hashing; a fresh exact
successor full suite is still required. Exact a85932a then failed two
fresh-ext4 full attempts: 1 failed, 1,589 passed, 29 skipped followed by 2
failed, 1,588 passed, 29 skipped. All three named failures passed in
isolation. The containing repair normalizes causal ordering in those three
fixtures only; focused PASS cannot replace a fresh full-suite PASS. Exact
91ffb4e subsequently reached 1 failed, 1,593 passed, 29 skipped because a
successful permit helper launched its child process before a bounded
Chief-planned timestamp was visible to that child; its isolated rerun passed
and is nonqualifying. Two subsequent wait-based dirty experiments were also
rejected after full-file WSL failures. The successor freezes only the
positive test-driver subprocess observation and separately proves the
unchanged runtime future-time rejection; it must earn a new fresh-ext4
whole-suite PASS.
- Package/install diagnostic: exact ed91f12 used locked WSL build 1.5.0
/ hatchling 1.27.0 and produced wheel/sdist SHA-256
4e86fdbf3ff71b36e7e559e38cb3ea8eaa77815b031b5a6aefcb33e4e26842bf
and 4681bcaea596cf5128566f73709992e9cb04c126ef8c2a8f98fb3d0c32df9127.
verify_dist.py accepted both the original wheel and sdist-derived wheel;
no index/download was used. An isolated Windows
install loaded version 0.4.0a1, all four console entry points, and the three
then-pinned 0.144.6 resources, and all four installed launchers returned
success. That exact commit predates the 0.145.0 refresh and is not evidence
for the current runtime resources.
This is superseded package evidence after the live defect repair, not a
final artifact, successful canary, promotion seal, or downstream install.
- The first integrity-v2 independent review rejected promotion on two P1s:
inline migration downgrade and non-atomic finding review. The accepted fix
makes persisted migration CAS-only and review+findings one atomic tail;
root reruns passed 29 focused tests plus 13 subtests and five targeted
CLI migration/seal/CAS tests. Those are historical slice results. Integrity
or promotion evidence is accepted only when the containing candidate has a
current checkpoint, integrity snapshot/review/seal, global doctor, exact
Windows/WSL suites, package/install smoke, and local bundle evidence; no prior
doctor PASS or seal applies.
2026-07-20 ic-local / local_files confidentiality scope¶
local_files implements model context allowed, user-designated files
destination-restricted. It is not an air-gap promise: Codex may receive prompt
and project context through its model service. A fully offline or self-hosted
model profile is a separate future capability.
The strict profile contract is:
[confidentiality]
mode = "local_files"
model_context = "allowed"
git_push = "deny"
remote_ci = "deny"
artifact_upload = "deny"
external_export = "permit_required"
local_cas = true
protected = [
{ path = "private/design.bin", kind = "file", policy = "home_remote_only", home_remote = "origin", home_destination = "https://github.com/example/chip.git" },
{ path = "eda/private", kind = "tree", policy = "local_only" },
]
The closed scalar values are defaults for protected subjects. With omitted or
empty protected, no file is classified and normal repository push, remote CI,
release, and package publication remain available. home_remote_only permits
the exact protected path/content only to its named remote and credential-free
home destination; other repositories are denied. local_only denies every
external destination. Its only governed exception is a Chief-issued one-shot
permit bound to one exact destination, content SHA-256/size, purpose, expiry,
task, and exact task-state digest. The consuming controller receives no reusable
Chief credential. AOI persists consumption before returning
fresh_consumption=true; an exact response-loss retry returns
fresh_consumption=false and cannot resend. AOI does not perform the upload,
and publication_observed=false is not remote receipt evidence.
AOI-managed Git push must preflight the exact config, remote/destination, complete ref update set, and read-only observed remote pre-state OIDs. It scans every outgoing commit, protected path history, and matching blob/content identity so delete-at-tip and copy/rename cases do not erase protection. Protected links/submodules, matching LFS routes, destination rewrite ambiguity, missing scope, duplicate/wrong correlation, and rule drift fail closed. Generic artifact, attachment, connector, release, and package gates require an exact file/content manifest whenever protected rules exist.
Doctor reports the rules, Git fetch/effective push URLs, rewrites, LFS endpoints, workflow presence, local/synchronized artifact roots, Windows mapped drives/aliases, known sync roots, known credential names/helpers without values, and authenticated push/export receipts. External publication capability alone is inventory or warning; an exact protected-rule/home-destination contradiction, violating receipt, or unsafe AOI local CAS/state is an error. Detection is finite and cannot prove that an unlisted credential is absent. Unverified volume, alias, or link/reparse locality remains labelled uncertainty but fails the confirmed-local Bridge/state gate.
The AOI v0.4 promotion loop, whose current config has no protected rules, is:
local Git commit -> Windows + local fresh-ext4 WSL tests -> independent Codex review -> integrity-v2 seal -> exact pre-push receipt -> exact-main-push GitHub Linux/Windows test + main-only docs -> immutable GitHub Release -> PyPI Trusted Publishing/readback -> Chief release-promote bundle -> released ARISE install
EDA is applicable only when the governed project's completion boundary names an EDA workload. It is not required to promote the AOI Python package, and this task must not launch ARISE RTL/EDA. This is a bounded governance/enforcement slice, not comprehensive DLP; explicit same-user shell bypasses outside AOI remain outside the guarantee.
Implementation checkpoint (2026-07-20): strict profile parsing, the first
AOI-managed publication denies, redacted doctor inspection, and the local-only
external-export intent/permit/issuance/consumption store are implemented.
The Bridge now reuses the profile at issue, pre-reserve, and process-pending
boundaries; it denies confirmed sync/network artifact roots before AOI writes,
and confirmed sync/network writable cwd before Popen. It also denies mapped
Windows drive roots and any drive/reparse locality it cannot confirm. The
integrated Bridge/confidentiality focus is the dual-platform 16-file result
above. Independent v9 review returned P0=0/P1=0/P2=1: it closed the mapped-drive
ordering, malformed-IPv6 exception, and terminal outstanding-item findings, but
found inconsistent classification/redaction for malformed file URIs and invalid
ports. Those cases now consistently become invalid / <invalid> and have
doctor-level negative tests. v10 accepted the confidentiality/transport bytes,
and the later packet-owning-arm v3 review accepted its clean exact diff with
P0=0/P1=0/P2=0. Export falsification covers wrong destination/purpose/content,
task-state drift, expiry, export-ID single assignment, exact replay,
Chief-credential absence, and doctor redaction. Earlier exact-commit package/
install rehearsals and local bundles are historical diagnostic evidence, not
an external upload, live App Server, containing-commit package, accepted
latest-byte independent review, seal, or promotion result.
Subject-aware promotion gates¶
The final gate selector is part of the evidence contract:
standard, orlocal_fileswith no protected rules: exact final-SHA remote-main CI and the selected publication gates are available normally.local_fileswithhome_remote_only: the protected subjects may reach only the exact named home remote/destination after an exact outgoing-commit preflight. Other repositories fail closed.local_fileswithlocal_only: those exact subjects remain outside all external CI/release/package/artifact manifests unless a separate exact one-shot export permit is consumed. Unclassified subjects are not globally blocked.- A remote PASS from another SHA, destination, or subject manifest is historical context and never substitutes for the selected exact gate.
Evidence categories for O9/O10¶
- Contract tests: historical exact
be46e89evidence passed its complete Windows and fresh WSL collections, typing, compile, docs, package, and install gates. Exactff8fd223passed Windows but failed the fresh-ext4 WSL whole suite at one cross-process reachability fixture; its isolated rerun is diagnostic only. No result transfers to the containing test-only successor; that clean commit must rerun every local gate. - Live App Server canary: v12 on exact
be46e89started the pinned process and initialized, then rejected a correlatedthread/startresponse and terminalized non-retryablelaunch_unknown. It also exposed unsupported model fallback and default app/plugin/remote-control surfaces. v12 is a diagnostic NO-GO and cannot be resent. Fresh v13 remains forbidden until a clean repair successor passes independent review and receives a new task/packet/permit identity. - Git mutation verification: fake runtime plus disposable real Git filesystem tests prove the separate evidence transition, but no live Codex writable mutation is claimed. A writable live canary remains locked behind a fresh read-only live pass on the accepted successor.
- Remote CI: required after the sealed exact commit is pushed for this AOI
release because its protected-rule set is empty. Authenticated exact-main
test.yml/docs.ymlobservations must pass the offline validator and be recorded in task CAS before the release-tag composite preflight. The publish workflow independently repeats the exact correlation before its first GitHub Release mutation. Historical runs, a tag-only test, or a receipt from another commit/destination do not qualify the containing candidate.
2026-07-19 evidence checkpoint¶
This checkpoint retains historical local v1 verification evidence. It does not
claim required-v2 post-commit review/seal, GitHub Actions acceptance, local
bundle or installed-package validation, PyPI publication/readback, live Codex
/hooks trust, or downstream installation/execution.
- Complete WSL pytest collection: all 83 test files were partitioned into
mutually exclusive cache-disabled shards;
1,312passed and28were platform-skipped, with zero failures or errors. The largetest_cli.pysurface was separately proven complete by collecting and running all 12 test classes (161cases). - Windows runtime coverage: the CI-equivalent
unittest discoversuite ran1,102tests with28platform skips and zero failures/errors. The final provenance/hook/workflow pytest focus passed32tests with6POSIX-only skips and5subtests; the host-native onboarding file passed42tests with4skips and22subtests. This focused pytest evidence closes the free-function gap inunittest discover. At that checkpoint a pushed GitHub matrix was the planned acceptance authority. The later whole-repo local-only interpretation was superseded; the final candidate requires both a fresh complete local collection and exact-final-SHA GitHub acceptance. - Static/review gates: native and emulated-win32 mypy each passed all 74
published source files after the shared agent-identity follow-up; compileall
and diff checks passed. Exact commit
6e7e1a32156828f11b644573112efc56b1ec0eccwas explicitly rejected rather than promoted after independent review found thatreview_integrity.pyhad been omitted from the shared identity contract. The corrected latest-byte focus passed 217 tests with 1 Windows-only skip and 101 subtests on Windows, and all 218 tests on WSL. Two independent final whole-diff reviews reported P0/P1/P2 = 0. At that checkpoint, the next committed bytes still required an exact review. The final selective-policy candidate additionally requires a pushed exact-final-SHA GitHub matrix after seal. -
Rejected promotion attempts remain evidence, not acceptance: the GitHub
testworkflow for6e7e1a32156828f11b644573112efc56b1ec0eccfailed becausetests/test_commands_offboard.pyread the repository-localaoi.toml, which is intentionally ignored and absent from a clean checkout. The successor candidate at that checkpoint built the fixture with the packageddefault_config_text()contract instead; the three directly affected test modules pass on Windows and WSL with the ignored root config removed. Exact review of888fd2969dc843b883c0faadbd2d9147879bc865also rejected its pre-commit integrity seal and found two remaining malformed top-level collection exceptions. Its successor returned deterministic array errors for those verification and incident inputs. That historical promotion attempt still required a fresh post-commit snapshot, independent review, seal, and profile-selected final environment evidence. -
O1: semantic event, object, and persistence acceptance coverage is in
tests/test_semantic_events.py,tests/test_semantic_objects.py, andtests/test_semantic_persistence.py. - O2: byte-preserving migration and rollback coverage is in
tests/test_semantic_migration.py. - O3: dispatch integrity and startup/hook receipt coverage is in
tests/test_packet_integrity.py,tests/test_codex_hook_receipts_v2.py, andtests/test_codex_hook_v2.py. - O4/O5: permit, cohort, and manual-wave contracts are exercised through the semantic-object and packet-integrity focused coverage. Their receipts do not assert a transport launch.
- O6: adapter contract, tool-path, install-provenance, and hook-receipt
focused coverage is in
tests/test_codex_adapter_contracts.py,tests/test_codex_tool_paths.py,tests/test_codex_install_provenance.py, andtests/test_codex_hook_receipts_v2.py. The localcodex-cli 0.144.0canary proved livePreToolUsesynchronous denial for Bash and that the denied command did not execute. This is not proof of complete tool-handler coverage, a collaboration pre-spawn gate, runtime trust beyond that canary, or a user trust decision; spawn remains arm plusSubagentStartgoverned. Any internalPreToolUsefault is fail-closed deny; non-PreToolUselifecycle adapters remain fail-open. - Local install proof:
tests/test_local_install_proof.pyand the v2 provenance/onboarding coverage exercise the separatereviewed_local_install_bundlecontract. Itsproof_scope=exact_local_wheel_install_onlybinds caller-approved bundle bytes, external store, clean source, inventory/rehearsal, exact wheel, PEP 610 archive evidence, installedRECORD, runtime bytes, and all four shipped console scripts including the optionalaoi-codex-bridge. The local schema-v2 receipt separately binds and rechecks the Bridge launcher, generated script when present, andcodex_transport_cli.pymodule. It is not a release or promotion, and a manual reviewer is only a cooperative assertion. The clean source is review context, not an independently attested source-to-wheel derivation or builder/test execution receipt. - O7: exact artifact, release CLI/runtime, inventory, local rehearsal, and
manifest contract coverage is in
tests/test_release_*.py. PyPI attestation evidence is presence-only; it is not an installed-byte or publication claim. - O8 v2 implementation candidate; promotion gates remain: the historical
v1 integrity coverage remains context, but it is not acceptance evidence for
required_v2. Exact post-commit independent review and seal, profile-selected final environment evidence, local bundle, and installed-package validation are pending. No promotion, release, or downstream installation/execution result is claimed. A manual reviewer identity is a cooperative assertion, and an unavailable MCP registry is explicitly uncovered rather than inferred as trusted. The final shared agent-identity follow-up makes new integrity producer/reviewer, packet, hook receipt, cohort, incident, skill-release, and Steward-brief records use the same bounded canonical/root/...identities as dispatch and routing. Current writers validate identity and all other caller-controlled fields before immutable CAS, artifact, receipt, mapping, or snapshot publication. Existing v1 receipts, review records, packets, and Steward briefs retain their original read and byte-exact replay semantics; legacy values cannot be elevated into new authority without replacement by a canonical identity. Malformed JSON collection, enum, identity, and replay inputs now return deterministic integrity errors instead of raw Python type exceptions. Persisted task state is rejected earlier byload_taskandload_all_tasks; direct in-memory gate/projection helpers are also guarded. The exact review of commit63c2babrejected promotion because close, cancel, doctor, and status-derived consumers still iterated malformedverificationorsubagent_incidentsvalues after their pure readers had diagnosed them. The follow-up keeps the canonical reader error, skips unsafe semantic derivation, and makes status summary/projection fail closed with aHarnessError. The focused integrity/dispatch/routing suites passed on Windows and WSL; the follow-up regression and final full matrix remain pending until the final candidate is committed. The old local-only route was superseded; the final matrix includes local Windows/fresh-ext4 WSL and pushed exact-final-SHA GitHub Linux/Windows plus docs gates. The required-v2 integrity work is a new candidate and must independently clear the pending post-commit review/seal, profile-selected environment, local bundle, and installed-package gates. Because adoption is one-way, it first checks that the current task owner, reserving claim owners, and completed mutation agents use this bounded principal syntax; canonical Codex paths and email-style operator IDs are accepted, while display names containing spaces must be replaced by a stable slug or email identity before adoption. The v1-to-v2 migration candidate now stores the immutable v1 prefix in the task-local CAS and persists only a compact native v2 tail. The migration source is bounded by the actual 16 MiB managed-state limit, while the logical 6,144-record cap remains independent; the resulting semantic delta is explicitly bounded below 1 MiB. A runtime-valid source larger than 1 MiB has passed focused upgrade, CAS materialization, and doctor tests. This remains a local implementation candidate until independent review and the final full suites pass. - O9 Transport Bridge is now a v0.4 release blocker: the user expanded the
v0.4 scope on 2026-07-19. The prior final-promotion boundary was retargeted and
its canonical task plan was atomically replaced through the AOI CLI and
re-approved at plan SHA-256
f26273ea0c5153fe90e8bd94f63c7441bcff2a79bad44b67f0e46dc0f134b16d; no older PASS, review, or seal applies to the new bytes. The installed Desktop CLI0.144.0was found stale. The current stable upstream release is0.145.0; a separate Windows App Server executable was fetched from the official release asset and verified as SHA-2565163c75ed88d460b35b03c8d8f4ef190b3bdd09971d7ac2bd90b48c435f1cf14. The same release's exact CLI generated 273 stable schema files; their canonical sorted manifest digest is6b8bfa74e475c6c9b46926c46f287f47873d188b13ab3df8db4633602db73262and the combined v2 schema digest is6253fd70273c2f33c42d0b6090eac771580c994b3c6eed4277598de08a5e69ec. The later 2026-07-20 checkpoint supersedes this paragraph for implementation status. Permit consumption, semantic persistence, recovery, finite CLI, and materialized Git mutation verification now have local fake-runtime evidence. Both live scratch canaries, exact independent transport review, full suites, packaging/install evidence, final seal, and the subject-selected final environment remain pending. The final AOI candidate has no protected rules, so remote final-SHA CI is required after seal. Source presence or a mock-server test is not live launch evidence.
The implementation order is mandatory. Query/UX work may not create a second state model, and automation may not receive a reusable Chief credential.
Verified starting point¶
The pre-change local suite collected 740 tests. Four cache-disabled partitions completed with 724 passed and 16 skipped, with no failures. The current Codex runtime supports native parallel agents and exposes SubagentStart, SubagentStop, PreToolUse, and PostToolUse hooks. Those hooks do not provide a provider routing receipt or the actual sandbox/profile configuration.
The baseline has four material gaps:
- packet routing truth can be recomputed from a later resource configuration;
state.jsonis mutable authority rather than a replayable projection;- an external controller cannot progress lifecycle state without a reusable Chief credential; and
baseline-freezedoes not identify or promote an exact release artifact set.
The initial hardening slice identifies compatibility boundaries without establishing that the remaining v0.4 architecture is already implemented.
Current implementation receipts¶
The following slices are implemented on the active v0.4 branch as of 2026-07-19. This section is a status receipt, not a relaxation of the later promotion gates.
- Foundation hardening is limited to shared compatibility boundaries and compact Windows atomic temporary recovery; the later v0.4 stages remain subject to their stated promotion gates.
- The pure semantic event contract is implemented and independently accepted. Its focused suite passes 16 tests plus 30 adversarial subtests, including canonical hashing, bounded deltas, replay, retry, tamper, legacy raw-snapshot binding, alias rejection, and size/node limits.
- The opt-in Stage 1 filesystem slice is implemented and independently
accepted after an initial review found four P1 defects. New
init-task --semantic-v2tasks publish genesis before projection, replay a missing/behind projection, recover an exact empty-directory or interrupted file publication, reject divergent/residual state, and block all unported legacy mutation paths before cross-file side effects. Exact retries bind all caller-effective genesis fields and require their plan/checkpoint artifacts. - Post-fix evidence is 34 semantic persistence/contract tests with 30 subtests, three real process-kill boundaries, and the complete CLI suite at 148 passed, 7 skipped, and 47 subtests passed.
- The pure Codex dispatch-v6 contract is implemented and independently accepted. It separates the SessionStart startup receipt, Chief registration, compact arm-time resource authority, hook observation, one-arm CAS slot, stored outcome, legacy v5 snapshot, and capacity row. The accepted review ran 55 focused tests plus 37 subtests and 21 adversarial in-memory probes. This is Stage-0 schema evidence only: no filesystem outcome CAS, hook/CLI integration, or provider/profile/sandbox runtime verification is claimed.
- The task-independent startup-receipt store base was independently accepted
after its first review found two P1 defects. First writes now bind
the exact current project root, raw
aoi.tomlSHA-256, and canonical in-root CWD before creating the store. Windows contents use CurrentUser DPAPI while reporting ACL evidence honestly aswindows-acl-unverified; POSIX requires current-user ownership and private group/other mode. Canonical sealing, bounded scans, replay/create separation, tamper/link rejection, real 512 KiB envelope expansion, and state-lock/recovery serialization were exercised on native Windows and WSL. The material schema-v2 observation extension was independently accepted after adversarial re-review. It additionally seals the SHA-256 identities of the project.codex/config.tomland managed agent TOMLs observed under that same state lock. This proves the filesystem observation and store only, not that Codex loaded those bytes. Previously published schema-v1 members remain exact-canonical and hash validated historical records, but cannot register or be rewritten as v2 because they lack file observations. A v1 member does not block unrelated v2 creation; reuse of its same session id fails as an explicit schema conflict. - The Codex
SessionStartsubprocess integration is implemented and independently accepted after review found one P1 type-confusion defect. Session, prompt, and stop routing now reject non-string session identifiers without coercion. Only an exact startup source with exact string session and CWD inputs attempts a receipt; timestamps, current root/config bindings, and managed project-file observations are produced locally. Failures preserve normal hook context behind one fixed warning, and requested model/provider/profile/permission/sandbox fields do not become authority. This is subprocess evidence only: live Codex hook delivery/trust remains a separate gate. - The Chief-fenced fresh-session registration v2 slice is implemented and
independently accepted. A read-only receipt command exposes the
exact sealed startup SHA needed for compare-and-register without exposing
Chief material.
Registration binds the persisted startup receipt, the event's immutable
applied snapshot, exact receipt/plan/config/profile-manifest hashes, task
plan/worktree, and the registering Chief session/epoch. Every reviewed
after-image must occur in the sealed startup byte observation, and the event
must remain effective-current with exact live after-bytes when registration
occurs. The receipt therefore proves byte-state equivalence, not that startup
followed the selected event when two events produce identical bytes. This
avoids treating independent Windows/WSL wall clocks as causal authority.
Same-epoch Chief renewal replays byte-identically; takeover,
non-LIFO or non-monotonic history, corrupt unrelated registrations,
applicability/selection tamper, and publication ambiguity fail closed. The
strongest result remains
registered_byte_state_equivalent_only, while config loading, provider route, runtime profile, and sandbox stayunavailable. Current-byte Windows and WSL focused suites each passed 32 tests; the reviewer found no remaining reproducible P0-P2. The complete local suite then passed 840 tests with 17 platform skips and 212 subtests.
The independently reviewed semantic-v2 slice extends Stage 1 with internal expected-head compare-and-append support for typed lifecycle writers, event-before-projection recovery, exact command retry, byte-preserving legacy migration, pre-first-transition migration rollback, semantic close, and doctor/close receipt checks. The store API is not a public generic full-state mutation command: ordinary legacy mutation handlers still fail closed for v2 tasks until their typed event-first ports exist. The focused semantic suites pass 62 tests and 46 subtests, the complete CLI suite passes 148 tests and 48 subtests with 7 platform skips, and the final adversarial review found no reproducible P0-P2.
The deterministic permit/cohort manual-runner slice is implemented. A pure
projection module defines the one-way permit namespace and the exact
cohort.advance consumption receipt. Schema-v2 detached transactions bind one
sealed cohort, one exact deterministic wave selection, all and only its routing
authority objects and slots, one semantic binding, and one planned event. The
runtime re-derives that exact after-image from the authenticated ledger at
prepare, issuance, consumption, retry, inspection, and recovery boundaries.
Chief issuance uses a separate immutable permit-issuances-v2 store while
global permit, consumption, replay, binding, event, transaction, and issuance
identities remain unique across v1 and v2. The v1 transaction bytes, marker
bytes, marker digest, and permit-issuances-v1 path have permanent golden
vectors.
The manual CLI now supports cohort-round-preview, canonical detached
cohort-round-prepare, permit-issue, no-Chief permit-consume, and
event-derived cohort-show. Preview/prepare/show do not launch or cancel a
transport; their receipts explicitly keep transport_launch_claimed=false and
launch_actor=unavailable. A reviewer-reproduced request/permit wave mismatch
was fixed to fail closed. Recovery tests cover object-only state, reserved
bindings after expiry, committed-event projection repair, marker tamper,
missing objects, unexpected store residue, exact retry, and cross-version
replay collision in both issuance orders. The combined O4/O5 focused suite
passes 170 tests with 1 platform skip and 2 adversarial subtests.
The focused evidence checkpoint above supersedes the older pending-slice note. Remaining promotion gates are intentionally unchanged.
Non-negotiable evidence boundaries¶
- A hook-observed model slug is not a provider routing receipt.
- Requested profile/model/sandbox, hook-observed fields, and independently verified runtime facts are separate fields.
- SubagentStart is observation after creation. A response with
continue=falsedoes not establish containment. - PreToolUse can deny supported cooperative tool paths. It is not an OS sandbox and does not cover every built-in action or sub-agent launch path.
- Local hash chaining is cooperative tamper evidence, not an external append-only witness.
- A planned/armed cohort is not running until starts are observed.
- A baseline is not a release. Only a promoted manifest names a consumable release.
- Process-kill recovery is not power-loss durability, especially on Windows where Python cannot portably fsync a parent directory.
- A registration's Chief record hash is an opaque command-time attestation. Same-epoch renewal changes the current Chief record, so permanent historical-exact reconstruction requires a future append-only Chief attestation ledger; current state proves the sealed session/epoch/timeline, not the old secret-bearing record preimage.
- A startup byte observation proves two identical bounded reads plus stable descriptor/path metadata under the cooperative AOI lock. It does not prove Codex loaded those bytes, it is not an OS-atomic snapshot against a hostile same-account writer, and byte-identical events cannot be distinguished by filesystem evidence alone.
- App Server
thread/starthas no client idempotency key in the pinned protocol. A connection loss after request send but before a durable response islaunch_unknown, not a safe retry and not exactly-once evidence. item/completedandturn/completedarecodex_runtime_observed. They do not prove an AOI task completion boundary or a verified source mutation. Only exact before/after Git snapshots, current claim coverage, and source/tree bindings can elevate a mutation.- The bridge receives one exact launch/transition permit. It never receives, reads, or persists a reusable Chief credential.
Outcome O1 — semantic commit v2 is the single task authority¶
New opt-in v2 tasks use an immutable event ledger as authority. state.json is
only the latest projection. An event contains:
- schema version, sequence, event type, command id, and recorded time;
- previous event SHA-256;
- deterministic payload and payload SHA-256;
- base and result projection SHA-256;
- a non-secret authority reference; and
- the canonical event SHA-256.
The first event is a genesis snapshot. Later events carry deterministic JSON operations. Event publication happens before projection publication. A writer uses expected-head compare-and-append; an exact retry that already produced the same result is idempotent. A reader may replay a valid ledger tail in memory when projection publication was interrupted. The next writer republishes the projection before adding new semantics.
Acceptance:
- complete replay produces the canonical projection byte-equivalent domain state and matching head;
- corrupt filenames, sequence gaps, hash mismatches, invalid operations, divergent projections, duplicate command ids with different results, and multiple valid heads fail closed;
- process termination at each append/fsync/replace boundary recovers at most one semantic head;
- v2 mutation cannot bypass the ledger through the legacy
write_taskpath; - doctor and close validate the ledger, projection, and migration receipt; and
- events are bounded records rather than repeated full-state snapshots after genesis.
Outcome O2 — legacy migration preserves history without inventing it¶
Migration requires task quiescence: no live arms, running packets/jobs, open
state writer, or unresolved temporary residue. The exact legacy state.json
bytes are copied to an immutable snapshot, and a legacy_genesis event binds
its SHA-256. A migration receipt binds input bytes, output head, tool version,
configuration, time, and the explicit operator authority.
Acceptance:
- migration is idempotent and never rewrites the legacy snapshot;
- legacy routing claims are preserved as legacy claims, never silently upgraded to verified runtime facts;
- corrupt input, a live v5 arm, an unknown hook event, or a non-quiescent task blocks migration without semantic mutation;
- the only pre-cutover rollback is a compare-and-swap restoration to the named snapshot; once a v2 event is accepted, rollback means read-only v2 or a new compensating event, never deletion of history; and
- v1 readers remain available for unmigrated tasks while v2 writers reject legacy state.
Outcome O3 — dispatch v6 binds immutable routing authority¶
Packet schema v6 is distinct from hook protocol v6. A v6 arm validates the exact resource-config receipt bytes once, then snapshots a compact reviewed plan and digest preimage: event/receipt identity, source SHA-256, resolved role-to-profile mapping, requested model/reasoning, resource envelope, applicability, restart requirement, apply time, fresh-session registration, and packet/plan authority. Backup bytes are not copied into every arm. Later config changes cannot change the arm's historical verdict.
Fresh-session evidence is split into two independently hashed objects. The
SessionStart hook may create a startup receipt only for source=startup;
resume, clear, and compact are not fresh. A later Chief registration binds
that receipt to the current resource event, aoi.toml, .codex/config.toml, and
post-apply profile-file manifest. The schema-v2 receipt records the exact
managed file identities observed during SessionStart. Registration accepts an
event only when every planned after-image is present in that sealed observation
and the event remains effective-current with the same live bytes. The wall-clock
timestamp is ordering metadata, not proof that one host/process caused another.
Its strongest statement is registered_byte_state_equivalent_only;
config_loaded_verified remains unavailable.
The resource lifecycle uses one strict replay shared by writers, readers, and doctor: timezone-aware transition instants are unique, applies follow append order, and each rollback pops the current stack top. Bounded cross-process clock jitter is serialized one microsecond after the latest causal transition; larger rollback fails before file mutation. Thus A apply, byte-changing B apply, startup under B, then rollback B cannot register the session to A because A's planned after-images were not observed. If two events produce identical managed bytes, startup evidence cannot and does not distinguish their event ids; the registration explicitly records byte-state equivalence while the current event/plan/Chief authority is selected at registration. It never claims that startup occurred after that exact event. Doctor, close, and later registration attempts revalidate the strict history, sealed startup store, receipt/event applicability and selection, rollback-stable registration snapshots, and current live after-bytes.
Routing output uses explicit fields and verdicts:
requested_*: arm-time requested authority;active_model_slug_observed: hook observation, when available;observed_model_slug_match: only the active slug comparison (match,mismatch, orunavailable), never a full config/provider binding;config_loaded_verified:unavailablewithout an independent load receipt;provider_route_verified:unavailableunless an independent provider receipt exists;runtime_profile_verified:unavailableunless independently observed;runtime_sandbox_profile_verified:unavailableunless independently observed; and- verdict:
observed_model_slug_match,observed_model_slug_mismatch,actual_model_unobserved,legacy_actual_model_unobserved, ormanual_unverified.
All terminal claims for one arm share one deterministic
outcome_slot_sha256; the persistence layer must publish that slot with an
atomic compare-and-swap. A pure schema supplies the collision identity but
does not itself make a write one-shot. Reuse of one raw observation across two
packet authorities is rejected when stored outcomes are assembled.
Ready v5 packets may be migrated before arm. Armed or dispatched v5 packets must drain, expire, or terminalize under v5; they are never rewritten in place. After cutover, v5 is replay-only and cannot create new mutation.
Acceptance:
- config A arm followed by config B apply, rollback, wrong-profile same-model, not-applicable config, or restart-required config leaves the A verdict unchanged;
- no observation is never converted into an observed match;
- capacity datasets consume stored immutable verdicts, not a new derivation from current config;
- capacity preserves every terminal row, while only explicit
accepted/rejectedtechnical outcomes with a stored slug match enter the model-quality denominator; - same-type parallel execution is documented as arm A, observe A, arm B while A runs; simultaneous pre-arm remains unsupported until the transport returns a packet nonce; and
- doctor reports every live packet by packet/dispatch schema and blocks release while an active v5 arm remains.
Outcome O4 — one-shot permits enable automation without Chief leakage¶
A technical agent emits a content-addressed decision. The Chief may authorize one exact lifecycle transition using a permit bound to:
- task and expected semantic head;
- decision SHA-256 and permitted action;
- exact target identifiers and parameters;
- expiry and random nonce;
- Chief session/epoch authority; and
- permit SHA-256.
The controller/Registrar receives only the permit. It can atomically consume that exact transition; it cannot retarget, edit technical payload, mint a new permit, or obtain the Chief credential.
Acceptance:
- replay, expiry, head drift, decision mutation, target mutation, and parameter widening all fail with zero semantic transition;
- concurrent consumers produce exactly one accepted event;
- the controller process environment and persisted receipt contain no reusable Chief token or credential path; and
- a failed transition records no false success and leaves the permit either unconsumed or explicitly terminal according to the failure class.
Outcome O5 — cohorts describe deterministic waves without overstating launch¶
A cohort binds ordered packet references, dependency DAG, waves, bounded
concurrency, transport slots, failure/cancel policy, and expected v6 authority.
Its projection distinguishes planned, armed, start_observed, terminal,
and cancelled. Completion order cannot change the deterministic next-wave
decision.
Acceptance:
- cycles, unknown packets, duplicate slots, incompatible schema versions, and over-capacity waves are rejected;
- no packet is
runningwithout an observed start; - identical terminal outcomes in different arrival orders yield the same cohort projection; and
- cohort machinery does not claim that AOI itself launched a transport unless a transport-specific launcher and receipt are implemented.
Outcome O6 — the Codex adapter produces bounded, honest receipts¶
- Install absolute resolved hook executables and bind package version plus installed-manifest digest. An update changes the hook definition and requires a new trust decision.
- Wire SubagentStop and correlate agent id, stop time, transcript path, and last
assistant message. A stop receipt improves accounting but does not prove
no_material_workwithout trace evidence. - Use PreToolUse as a cooperative claim gate only for supported, parseable apply-patch/shell/MCP paths. Unsupported or ambiguous paths are reported as uncovered, never described as contained.
- Use PostToolUse for mutation receipts, not prevention or rollback.
- Record active model slug and permission mode exactly as observations. Actual sandbox/profile remain unavailable absent a stronger platform receipt.
The already-landed Claude compatibility hardening remains covered by regression tests, but v0.4 adds no new Claude-specific hook, onboarding, provenance, or parity work. Shared schemas must continue to read existing Claude/v5 evidence without upgrading its strength.
Outcome O7 — releases are exact promoted manifests¶
release-manifest-v1.json is generated from the exact tested artifact bytes
before publication. It binds tag, commit/tree, package version, build
environment, workflow/run identity, artifact names/sizes/SHA-256, producer
packets/results, interface and schema versions, dependency release SHAs,
verification receipts, SBOM/attestation locations, and manifest SHA-256.
Promotion is a separate semantic event and receipt. Downstream consumers bind the promoted manifest SHA, installed metadata, console executable, and hook protocol. Rollback promotes a new compensating release or prior manifest; it does not rewrite publication history.
Acceptance:
- artifact replacement, tag/tree mismatch, missing Windows/Linux matrix gate, rebuild-after-test, PyPI readback mismatch, unpromoted dependency, and wrong installed executable all block promotion;
- the publish job uploads only bytes already named and verified by the manifest; and
- a clean second build either reproduces exact bytes or records a scoped, reviewed non-reproducibility explanation before promotion.
The release toolchain is itself an input to this evidence: the canonical
requirements/release-tools.lock is
hash-pinned, downloaded into a verified wheelhouse, and installed offline with
--require-hashes. The producer receipt records that lock digest and the exact
name, version, and artifact hash of all eleven locked distributions. Build the
wheel/sdist with that isolated toolchain, install the exact inventory-selected
wheel, then run the O7 tests with -I; do not let an ambient tool or rebuilt
wheel stand in for the tested bytes. The workflow/run, PyPI, tag, and GitHub
Release portions remain required future evidence, not facts asserted by this
checkpoint.
Separate reviewed local-install route¶
reviewed_local_install_bundle is deliberately not a shortcut release record.
It has proof_scope=exact_local_wheel_install_only and binds an exact local
wheel installation to a caller-supplied expected bundle SHA and canonical
external store. It additionally cross-checks clean commit/tree and the full
tracked source manifest, exact inventory and rehearsal, wheel path/SHA, PEP
610 direct_url archive path/SHA, installed RECORD, and runtime bytes.
codex-init accepts it only through the complete local proof pair; it rejects
half-pairs, both local and public pairs, and no pair before mutation. A manual
reviewer is cooperative, not authenticated; the expected bundle SHA is the
caller trust anchor and names the canonical bundle_sha256 field, not the raw
JSON file hash. The clean source identity is review context: this route does not
independently attest source-to-wheel derivation, the builder toolchain, or
execution of the caller-supplied test summary.
This local-install contract itself makes no tag, GitHub Release, PyPI, or live
Codex /hooks trust claim. That evidence boundary does not prohibit the
separate final-SHA release route; live-client and remote publication evidence
must each be independently recorded.
Outcome O8 — integrity v2 and adoption surfaces use the stable projection¶
After O1–O7 are stable:
- close/doctor capture NUL-safe Git mutation snapshots, including untracked, rename, case-only, and deletion states, and compare them with live claims;
- independent reviewer identity must differ from every producer identity;
- a finding-to-fix chain binds finding, change/result, and independent verification;
- bare
aoi statusbecomes concise human output, while--jsonremains the machine contract and--sincereads semantic cursors; - mini defaults reduce boilerplate without weakening explicit evidence;
- quickstart pins one exact version and demonstrates install, one mini task, and offboarding; and
- offboarding removes only AOI-owned hook definitions, leaves state as an inert archive by default, and never silently deletes project evidence.
New integrity-adopt creates required_v2 with an exact baseline head.
required_v1 is historical and frozen: its validator, candidate-only seal
semantics, and sealed contracts remain byte-compatible and read-only. Any valid
unsealed v1 contract, including a valid empty record set, may make the explicit
integrity-upgrade-v2 transition, supplying the expected canonical v1-contract
SHA. Its receipt stores the canonical v1 CAS artifact and carries every v1
finding obligation forward; the original v1 reader continues to validate it. No
task may silently reinterpret v1 history.
required_v2 uses one ordered record ledger. integrity_seq is continuous and
every record SHA is unique. A snapshot content SHA represents observed Git bytes
and may repeat; its record SHA is the unique attempt identity. All graph edges
therefore bind record SHA: review uses --snapshot-record-sha256, fix uses
--post-fix-snapshot-record-sha256, and verification uses
--verification-snapshot-record-sha256.
The operating order is deliberate. While task claims are live, capture a
candidate attempt and review it. Each review with findings extends the graph;
fixes and PASS verification may require further post-fix attempts even where
Git bytes are unchanged. The terminal snapshot must have one final clean review
whose exact basis lists, for every prior finding, the current PASS
reverification of that finding's latest fix on that same snapshot attempt. Seal
binds that terminal snapshot-record SHA, clean-review SHA, and exact live claim
scope; a fresh close observation must match. Retries are exact semantic replays,
not fresh record or artifact publication. Reviewer IDs remain cooperative
assertions, not authenticated independence or an OS access-control boundary.
Live dogfooding findings (P1). The v1 candidate → post-fix flow reached a
real dead-end: identical post-fix Git bytes could not be captured again because
v1 treated content snapshot_sha256 as globally unique. The prior v1 validator
also used a leaked loop variable when checking a verification snapshot, so its
result could depend on the tail snapshot rather than the verification's bound
record. v2 record identity and integrity_seq address the first issue. The v1
reader remains frozen, including that historical acceptance behavior; migration
must not silently reinterpret it. Neither finding is evidence of a completed
promotion.
Outcome O9 — the optional Codex Transport Bridge launches one governed turn¶
The v0.4 MVP is a finite stdio controller, not a daemon. Under one exclusive controller lock it executes one bounded exact-binary version probe, then starts one local Codex App Server for one packet, one thread, and one turn. AOI core has no new runtime dependency; the transport entry point is optional and uses the Python standard library plus an externally installed, explicitly pinned Codex executable.
The immutable launch intent and one-shot permit bind task, packet, optional cohort/wave, expected semantic head, permit SHA, prompt SHA, absolute cwd, requested model/reasoning, sandbox/approval, executable path/hash/version, and the generated stable JSON-schema bundle digest. Runtime receipts bind request and notification identities, thread id, turn id, item ids, terminal state, and the content-addressed event transcript. Version, executable, schema, permit, head, prompt, cwd, or target drift fails before the runtime-process boundary; the version probe occurs after that durable boundary and before App Server Popen.
The Bridge launch first requires a canonical packet arm. For a migrated
semantic-v2 task, packet-arm-prepare emits standalone transaction schema v3.
Chief issuance applies the same packet-contract, open-task, approved-plan,
topology, resource-envelope, and skill-canary authority gate as legacy
packet-arm; no-Chief consumption then commits routing authority, permit
projection, and the canonical packet's ready -> armed transition in one
semantic CAS. The transaction must include all three delta roots and cannot be
substituted by the separate cohort schema v2 contract.
Launch-permit consumption is then the Bridge packet-ownership transaction.
Under the same state lock and semantic CAS, the active arm becomes
transport_reserved, the packet becomes bridge-owned dispatched, and a
sealed object binds the full packet/arm/launch/intent/permit/reservation/routing
tuple. It uses dispatch generation v2 so an older v1 writer or a partial marker
downgrade fails closed. No SubagentStart, agent id, thread id, or turn id is
invented.
One Chief-created per-launch OS lock covers reserve/load through terminal
publication. It proves cooperative at-most-one process in one platform lock
domain. The durable process_start_pending callback revalidates the earlier
permit/arm expiry, exact live ownership/generation, fresh namespace,
confidentiality storage, and the exact Git/tree/status/full-claim endpoint
for both readOnly and workspaceWrite. It authorizes both the bounded
version probe and App Server Popen; no child executes before it, and a crash
after it reconciles without restart.
The ordered milestone/state machine is:
reserved -> initialize -> model/list -> thread_started -> turn_started -> completed|failed|interrupted
Initialize and model/list retain semantic state reserved. The catalog step
is read-only and must prove one visible exact model/effort before
thread/start; catalog loss or rejection is a known pre-thread failed
outcome. Process, thread-start, or turn-start ambiguity retains the stronger
unknown semantics below.
launch_unknown is a separate terminal reconciliation state. It is mandatory
when thread/start may have been sent but no durable correlated response exists;
automatic resend is forbidden. Duplicate events are idempotent only when their
canonical bytes and correlation identity match. Wrong thread/turn/item ids,
unsupported item/notification types, malformed JSONL, schema drift, and
out-of-order terminal evidence fail closed. turn/interrupt is allowed only for
the exact persisted thread/turn pair. A known thread/turn whose stream becomes
unobservable uses runtime_unknown; it is not mislabeled as a known failure.
Acceptance is deliberately split into four evidence classes:
- Contract tests: deterministic schema/hash vectors, permit replay/expiry and head drift, process/request/response crash boundaries, duplicate and wrong-correlation events, interrupt, unsupported item, and receipt publication recovery against a scripted fake App Server.
- Live App Server canary: exact pinned executable/schema, first in a read-only scratch repository and then in a disposable writable scratch repository. This proves only the observed local transport lifecycle.
- Git mutation verification: AOI before/after snapshots, exact endpoint
claim coverage, source/tree binding, and a separately recorded elevation from
codex_runtime_observedtoverified_mutation. Endpoint coverage is not a claim of continuously held authority without a claim-history receipt. - Promotion environment: exact final-SHA GitHub Linux/Windows test and main-only docs gates are available when no protected rule is exposed, or when every exposed subject is allowed at its exact home repository. Local fresh-ext4 WSL is separate required WSL evidence. This AOI release has no protected rules and requires those remote gates after exact local test/docs/package/review/seal evidence. Earlier runs remain historical.
The MVP fixes approvalPolicy=never; a server request for approval, user input,
or elicitation interrupts and fails closed. It accepts only readOnly or one
explicitly bounded workspaceWrite root, never dangerFullAccess. The child
environment removes all reusable AOI Chief authority variables before process
creation. Under local_files, an exact isolated Codex-home inventory plus
closed config/managed-policy hashes is process-journal evidence; strict process
argv and thread config disable web search, apps, remote plugins, multi-agent
loading, and remote control while the turn sandbox also sets
networkAccess=false. Raw prompt, assistant text, command output, and secrets
stay out of the semantic ledger. Exact correlated response bytes rejected by
schema or policy are retained only in task-local non-Git CAS and represented in
the ledger by verified digest/size.
Token budgets, thread/fork lineage, detached review, approval brokering, multi-wave autonomous cohorts, WebSocket/daemon transport, and remote EDA launch remain later gated v0.4 slices. None may block proving the single-turn MVP, and the first writable canary must not target ARISE or any RTL/EDA workload.
Implementation sequence and promotion gates¶
- Foundation hardening — compact Windows atomic temporaries with v1 recovery and exact adversarial tests.
- Stage 0 contracts — pure event, routing, permit, cohort, and release schemas with canonical hash vectors and tamper tests; no runtime mutation.
- Semantic commit v2 — opt-in new tasks, replay/projection/recovery, doctor/close checks, then explicit legacy migrator.
- Dispatch v6 — immutable arm authority, v5 drain inventory, adapter observations, capacity export migration.
- Permits and cohorts — deterministic manual round runner before any daemon or autonomous controller.
- Release manifests — observe-only generation, then promotion and one exact downstream dependency enforcement.
- Codex adapter provenance and mutation receipts — absolute hook definitions, stop/trace receipts, cooperative claim gates, fresh-session canaries.
- Integrity and adoption — mutation/reviewer/fix-chain gates, status, mini defaults, quickstart, version pins, and offboard.
- Codex Transport Bridge MVP — pin stable executable/schema, prove pure contracts and stdio crash semantics, then read-only and disposable writable live canaries plus exact Git mutation elevation.
- Selective local-files confidentiality — strict protected path/tree parsing, destination-aware Git preflight, subject manifests, local state/CAS enforcement, subject-aware doctor/promotion gates, exact one-shot export permits, and negative publication tests.
- Release rehearsal and exact remote gate — full local fresh-ext4-WSL/Windows matrix, wheel/sdist installed smoke, independent rebuild, encrypted local manifest/bundle, exact pre-push receipt, then exact-main-push GitHub Linux/Windows test plus main-only docs. A tag test is supplementary; the publication workflow independently verifies the required main-push observations before its first Release mutation.
- Downstream installation boundary — no installation or execution claim until the exact candidate has an independent post-commit review and seal, profile-required final environment evidence, immutable GitHub/PyPI readback, a Chief-created content-addressed promotion bundle, and installed-package evidence.
No stage is promoted by source presence alone. Its tests, doctor checks, migration receipts, and independent review must all pass.
Falsification matrix¶
| Contract | Required adversarial cases |
|---|---|
| Semantic ledger | truncated event, renamed event, sequence gap, wrong previous hash, payload tamper, projection behind/ahead, kill before/after append and replace, exact retry |
| Legacy migration | clean, live arm, expired arm, running job, corrupt snapshot, unknown event, repeated migration, pre-cutover rollback |
| Dispatch v6 | config after arm, rollback, wrong profile/same model, not applicable, restart required, missing observed model, old hook after cutover |
| Permit | replay, expiry, expected-head race, decision/target/parameter mutation, concurrent consume, credential-leak scan |
| Cohort | cycle, duplicate slot, capacity overflow, unobserved start, out-of-order completion, cancellation race |
| Codex adapter | executable/manifest drift, unsupported or ambiguous tool path, missing model, duplicate/replayed start, missing or mismatched stop receipt, PostToolUse mutation ambiguity |
| Codex Transport Bridge | permit replay/expiry/head drift, reservation binding-to-event crash crossing expiry with exact/absent/wrong witness, executable/version/schema drift, two-run and two-process lock contention, same-arm different-launch CAS, lock missing/link/hardlink/sentinel replacement, arm/permit expiry crossing version probe, packet status/contract/ownership/generation drift before pending, generic SubagentStart/cancel/re-dispatch conflict, process start before/after, thread request/response ambiguity, turn start before/after, mid-stream loss, terminal publication crash, duplicate/wrong-correlation event, unsupported item, interrupt race, issue-to-run and Git after-image/claim mismatch |
| Local-files confidentiality | permissive config mutation, empty-rule non-blocking route, untracked copy then origin deletion, missing protected tree, external push/rewrite/LFS endpoint, package/archive member copy or path match, transformed non-match boundary, every Actions artifact gate, PyPI container/receipt mismatch, historical config evolution, unreceipted descendant tip, sync/network artifact root, wrong export destination/file/purpose, expiry, task-state drift, duplicate consume, response loss, credential leak, malformed export receipt |
| Release | artifact/tag/tree/PyPI mismatch, missing matrix receipt, rebuild substitution, unpromoted dependency, wrong installed console script |
| Mutation gate | untracked, delete, rename, case-only rename, symlink/junction, Bash write, out-of-claim write, same-agent review |
Explicit non-goals¶
- a same-user or hostile-process security boundary;
- a claim that hook installation proves runtime trust;
- handing reusable Chief authority to a daemon, Registrar, or technical agent;
- fabricating model, sandbox, provider, or containment evidence absent a receipt;
- in-place reinterpretation of active legacy packets;
- new Claude-specific adapter or onboarding parity in this implementation;
- WebSocket transport, a resident daemon, automatic retry from
launch_unknown, or reusable Chief authority in the bridge MVP; - calling a planned cohort parallel execution without observed overlap; or
- claiming downstream installation or execution before its evidence boundary.
Decision log¶
- The release line is v0.4 because task authority, dispatch schema, release promotion, and migration behavior change materially.
- Semantic events are authority; a sidecar audit log beside independently writable state would preserve the current split-brain risk.
- Packet schema v6 and hook protocol v6 are separate contracts even if their numeric versions coincide.
- Provider route and actual sandbox/profile stay
unavailableuntil the platform exposes stronger receipts. - A deterministic manual round runner precedes a daemon because permit and cohort invariants must be proven before unattended lifecycle mutation.
- The user explicitly moved the finite local Codex App Server transport bridge into v0.4. A one-packet/one-thread/one-turn stdio MVP therefore precedes v0.4 promotion; daemon, WebSocket, and multi-wave autonomy remain separately gated.
- The user selected destination-aware
local_filesprotection for IC-local work: model context is allowed,home_remote_onlypaths may reach only their exact home repository, andlocal_onlypaths may not be externally published absent an exact one-shot permit. Empty rules leave AOI update, GitHub CI/Release, and PyPI publication enabled. This does not claim provider-side context isolation; offline/self-hosted is a distinct future profile. baseline-freezeremains useful input to a release manifest but is not itself promotion.