Skip to content

AOI v0.4 implementation and migration plan

Status: active implementation contract, evidence checkpoint 2026-07-23

  • Title: Complete, publish, and install AOI v0.4
  • Owner: /root
  • Objective: Complete integrity-v2, the optional one-shot Codex App Server transport bridge, and destination-aware protection for user-designated local files; qualify one exact clean v0.4 successor, publish it to GitHub and PyPI, then install only that released version in ARISE.
  • Completion boundary: A clean containing successor of rejected exact commit 054d1b6cf877fda8d24372318508614be28efe98 must retain all accepted Bridge, local_files, WSL-hook, CAS, exact-model-list, clock-fixture, and integrity-v2 contracts. Every model/rerouted notification must synchronously bind its exact bounded wire bytes to controller-owned task-local CAS before payload classification and then fail closed with a typed fault. A turn/completed observation-derived terminal append requires a natural zero-exit/full-reader-drain stream seal; forced cleanup, nonzero exit, partial output, reader/CAS timeout, or a live reader may never authorize completed. That exact successor must pass Bridge/confidentiality falsification, pinned runtime/schema checks, full Windows and local fresh-ext4 WSL suites, typing/compile/docs, exact-wheel package/install, a newly issued read-only then writable live canary, verified Git mutation, profile-aware doctor, fresh independent review, integrity-v2 seal, and an encrypted local bundle. local_files is selective: an empty protected-rule set permits normal AOI publication, home_remote_only permits only the exact named home remote and destination, and local_only forbids all external destinations absent an exact consumed Chief one-shot export permit. This same active task must push the exact sealed final commit after an exact pre-push check. Canonical GitHub test Linux/Windows jobs and the main-only docs workflow must then pass for the exact peeled main push commit. Their authenticated exact-CI receipt must be copied into task CAS before an unused annotated release tag is created. A second CAS receipt must bind that exact CI record, current plan/head, tag object/peeled commit, destination, remote absence, and confidentiality preflight before tag push; authenticated post-push tag-object/peeled-commit readback is a third distinct receipt. A tag test is supplementary and cannot replace the main-push observations. The publish workflow must independently fail closed on those exact runs before its first GitHub Release mutation. It must publish and read back the immutable tag, GitHub Release assets, and exact wheel/sdist through GitHub OIDC Trusted Publishing, then verify PyPI metadata, hashes, download, install, import, and entry points. Only after the current Chief binds those public observations through release-promote may ARISE consume the resulting exact promotion bundle and canonical bundle SHA, install the released version side-by-side, and prove Windows-to-WSL hook reachability. ARISE source, Git, RTL, artifacts, and EDA remain outside publication and execution scope.

AOI v0.4 makes semantic state, dispatch authority, transport observations, and releases content-addressed. It also reduces routine operator ceremony after those contracts are stable. This is a schema and trust-semantics release; it is not a claim that AOI is a hard sandbox or that multi-agent work is inherently better. The optional Codex Transport Bridge can launch one governed local App Server turn; the dependency-free AOI core remains usable without that adapter.

2026-07-23 selective publication closure repair

2026-07-23 remote publication update: v0.4.0a1 and v0.4.0a2 were pushed to GitHub for remote-final-SHA validation and superseded before Release/PyPI because the remote matrix exposed CI portability defects: Python 3.11 test-collection failures from backslashes inside f-string expressions, and a Windows package-smoke failure where PYTHONPATH=src was evaluated after entering the downloaded artifact directory. No GitHub Release, PyPI upload, or ARISE install may use v0.4.0a1 or v0.4.0a2. The publication candidate is retargeted to 0.4.0a3; branch CI must pass before the v0.4.0a3 tag is created.

Two fresh read-only reviews rejected the first selective-policy repair. They proved that a never-tracked protected origin could be copied, deleted, and then escape the current-byte identity scan; that delivery doctor reinterpreted old receipts through the current config; that an unreceipted descendant remote tip could borrow an older delivery receipt; and that the actual Actions artifact and PyPI workflow never invoked the advertised subject gate. They also found the remaining empty-rule storage error, which contradicted the user's clarified requirement that AOI itself remain updateable. Those findings supersede all earlier policy-review GO/PASS language.

The active dirty repair now fails closed when a configured protected origin is missing, persists a self-digested delivery-time policy binding beside the task-local CAS receipt, and validates historical delivery evidence against that binding rather than a later config. Once the same protected-policy digest has governed a remote/ref, repository-wide doctor coverage requires its current tip to have an exact persisted preflight delivery. Empty rules no longer turn a sync/network storage finding into an error.

A new stdlib-only publication inventory expands regular wheel/ZIP and gzip-tar members under bounded type/link/traversal/count/byte checks. The new confidentiality-publication-preflight receipt binds exact container hashes, member-manifest digest, destination, config/policy, and matched subjects. The release workflow calls it before all six Actions artifact uploads and carries a PyPI receipt whose exact two container rows are revalidated against the producer inventory before OIDC publication. Current dirty-byte diagnostics after the subsequent runtime-pin, archive-bound, annotated-tag, GitHub-Release/PyPI continuity, and empty-rule regression repairs are: 164 focused publication/confidentiality/release/runtime/workflow tests plus two subtests passed, with the one clean-tracked-checkout contract deliberately deferred until the candidate is committed; strict mypy passed the six changed publication/runtime/verifier modules; compileall, policy byte equality, diff-check, and task-scoped doctor passed with no doctor errors. Checkpoint, integrity seal, fresh whole-diff review, exact-commit Windows/WSL suites, package workflow, live canaries, remote CI, publication, and installation all remain required; no GitHub/PyPI or ARISE completion is claimed here.

Whole-diff review v119 then rejected the candidate because its GitHub Release job published an empty prerelease before uploading assets, so an ordinary crash could leave an externally visible partial official release. The current dirty repair discovers draft and published Releases through an authenticated fully paginated API listing, distinguishes discovery failure from absence, and binds an exact draft marker to the repository, annotated tag object, peeled commit, three asset names/sizes/hashes, publication policy, preflights, and sealed content. The nondeterministic Actions archive digest remains run-local provenance and is not part of cross-run draft identity. It resumes only that exact non-public draft, uses its Release ID for bounded starter cleanup, upload, download, and final publication, and rechecks the tag/Release contract before every mutation. A published incomplete Release fails closed. Only after a stable full download/hash verification does the workflow set draft=false; it then performs another published readback before the independent read-only job and PyPI OIDC job may proceed. Workflow YAML parsing, extracted Bash syntax/ShellCheck, and 16 scoped contract tests pass on the dirty bytes; fresh whole-diff review and all exact-commit gates are still required.

2026-07-23 exact release-CI and Python 3.11 environment closure

Exact commit 054d1b6cf877fda8d24372318508614be28efe98 remains rejected and supplies no transferable acceptance evidence. GitHub docs run 29987095149 completed successfully at that SHA. Test run 29987095165 did not: its Ubuntu Python 3.11 job reported two failures because a standard venv seeded Setuptools' executable distutils-precedence.pth, while the remaining matrix and coverage jobs were cancelled when the prior 45-minute timeout expired. The executable-.pth rejection is intentional and is not weakened by an allowlist. AOI install/provenance evidence instead uses a dedicated venv without --system-site-packages, uninstalls Setuptools before installing AOI, and rejects an executable .pth added before or after the provenance receipt.

The dirty successor adds a stdlib-only exact-CI verifier and a read-only publication job that queries the canonical test.yml and docs.yml runs for the exact peeled commit, repository, main branch, push event, workflow path, completed state, and successful conclusion. Ambiguous, truncated, duplicate, wrong-repository, wrong-workflow, wrong-event, wrong-SHA, incomplete, or failed responses stop publication. The first GitHub Release writer now depends on that job; PyPI remains transitively blocked behind verified GitHub Release publication. Unit and coverage timeouts are raised to 90 and 120 minutes so a slow matrix is not mislabeled as a test failure, without removing any job or test. GitHub-hosted Linux/Windows and main-only docs are remote pushed-SHA evidence; WSL acceptance remains a separate local fresh-ext4 full-suite gate. A tag-push test is supplementary because docs.yml intentionally does not run on tag pushes. No new review PASS, integrity seal, GitHub Release, PyPI publication, Chief promotion, or ARISE installation is claimed at this checkpoint.

2026-07-23 v126 content-addressed release-tag handoff

The final-promotion boundary now includes a mechanical local handoff between exact remote-main CI and tag delivery. scripts/verify_release_ci.py emits one portable canonical UTF-8/LF receipt for the authenticated successful test.yml and docs.yml main-push observations. The Chief records those bytes as a current passing delivery_check artifact in task CAS. Only then may an operator create an annotated tag. release-tag-push-preflight is a read-only consumer that requires that exact CAS record, current approved plan and HEAD, one local annotated tag object peeling to the same commit, an absent remote tag, an unchanged effective destination and raw push transport, and a fresh destination-aware confidentiality preflight. Its composite receipt is itself recorded in CAS before the push. Mutation-adjacent recheck mode must reopen that current passing verification and CAS artifact, repeat the live checks, and reproduce byte-identical receipt bytes. The operator then pushes the receipt-bound tag object OID directly to the receipt-bound raw transport with a create-only empty lease; a mutable tag ref, canonicalized identity, or remote name is not an authorized source. Both preflight remote state and delivery readback use that effective push transport, never a distinct fetch URL. release-tag-push-verify reopens both CAS edges, rejects superseded or malformed verification records, revalidates actual plan/config/head/tag/ policy bytes before and after network observation, and requires authenticated remote readback of the same annotated tag object and peeled commit. Its delivery receipt separately binds the exact preflight verification index, verification-record SHA-256, artifact SHA-256, and receipt SHA-256.

This is deliberately not folded into set-delivery: the task's existing branch delivery remains the exact refs/heads/main delivery, while the tag has a separate content-addressed preflight/readback chain. The two tag commands hold no reusable Chief credential and do not mutate AOI state. add-verification remains Chief-fenced. A request sent with an unknown Git push outcome is not declared successful and must be reconciled by readback before any retry. These receipts prove the named cooperative Git handoff only; they do not establish GitHub Release/PyPI publication, integrity seal, or the task completion boundary. Current source/tests/docs are still dirty successor bytes and require fresh exact-candidate gates.

2026-07-23 v128-v130 release-tag falsification successors

The v127 independent dirty-byte review rejected promotion with three P1 and two P2 findings: fetch URL readback could be confused with a distinct push URL; the Chief-free handlers did not reload locked configuration or hash the actual approved plan; the runbook pushed a mutable tag ref without immediate mechanical revalidation; the delivery receipt omitted the exact preflight task-CAS edge; and its public validator trusted an unvalidated preflight mapping. The v128 successor addresses those findings without broadening the cooperative boundary. Preflight remote-state inspection and delivery readback now use the exact effective push transport, config/plan/task/HEAD/tag/evidence are reloaded around network observations, an exact object/create-only-lease procedure replaces mutable-ref push, and delivery validation requires the exact preflight verification index, record SHA-256, artifact SHA-256, receipt SHA-256, and fully revalidated exact-CI-bound preflight.

A pre-formal v128 audit then found two remaining P1s and one P2 test gap: the runbook did not fail explicitly when reproduced preflight bytes or their CAS artifact SHA differed; local and workflow tag checks accepted a tag whose embedded name differed from its ref or whose direct target was another tag; and verify-side config/plan/tag drift lacked fault injection. The v129 successor rehashes both receipts and fails before push on any mismatch, extracts the exact push inputs only from the verified recheck, requires the local and workflow tag header to directly name the expected commit/ref, independently checks the GitHub tag object's name/direct commit before every publication boundary, and adds verify-side drift tests.

The v129 successor then passed a targeted 87 passed, 2 subtests and an expanded 195 passed, 8 skipped, 2 subtests, plus native/win32 strict mypy on six changed source modules, compileall, and diff-check. A new pre-formal audit still rejected those bytes: the receipt kept only a canonical destination while the remote checks used a distinct raw transport, and the mutation- adjacent recheck compared local files without reopening the recorded task-CAS preflight before the push. Those results are therefore diagnostic only. The v130 successor binds the credential-free raw transport end to end and makes the second preflight invocation consume the exact recorded verification index and artifact SHA, revalidate its current passing CAS bytes, and require byte equality with the freshly rebuilt receipt before exposing exact push inputs. v130 requires fresh focused tests and formal independent review. None of these generations is yet a clean candidate, integrity-v2 seal, remote CI observation, GitHub/PyPI publication, or ARISE installation.

2026-07-23 v131 release-tag fail-closed successor

The v131 successor narrows three release-route authority gaps without changing the cooperative/publication boundary. First, the exact release-tag route rejects any configured Git URL insteadOf or pushInsteadOf rewrite before either preflight/verify command performs remote observation or the operator pushes; this applies even with no protected confidentiality subjects. An operator must stop, review/remove the rewrite, and rerun the complete preflight rather than reinterpret an effective endpoint. Second, both exact-CI and recorded preflight artifacts are release authority only when they are canonical task-CAS snapshots; legacy live references remain compatibility/history surfaces and cannot enter the route. Third, the public release-tag receipt validator strictly validates the embedded confidentiality-preflight schema and canonical self-digest as well as the enclosing receipt digest, so a copied or merely syntactically shaped inner mapping cannot become evidence.

The v130 focused 205 passed, 8 skipped, 2 subtests result is superseded diagnostic evidence, not v131 acceptance. Fresh v131 dirty-byte tests then passed: the targeted release-tag matrix reported 105 passed, 2 subtests (fb6ef50bd576edbeefa9185c0d56cbf7f2b85e7a922c45fbf9310a33fc45b6ab), and the expanded focused matrix reported 215 passed, 8 skipped, 2 subtests (4b494e02df7306d819a69efb7690c624be7afc4a231569d571be95ac97a98018). Native and emulated-win32 mypy passed the six changed source modules; compileall and diff-check also passed. These results cover the implementation and documentation bytes immediately before this evidence-only paragraph was recorded; the containing documentation contract is rerun separately. At that checkpoint, formal independent review was still required and none of the clean-candidate, integrity-v2 seal, remote CI, tag delivery, GitHub/PyPI publication, promotion-bundle, or ARISE-installation claims had been earned.

That formal review subsequently rejected result SHA 14e2f9db8ce9506068bad456ce901bcec86d34a1403043de49e4ccfb81835e89 with P0=0/P1=1/P2=0. The P1 is a release-route race: a Git URL rewrite can be added after v131's last rewrite audit and before the first ls-remote subprocess, which lets Git reinterpret that network transport. Therefore the v131 215 passed, 8 skipped, 2 subtests matrix remains superseded diagnostic evidence, not formal acceptance or a transferable release claim.

2026-07-23 v132 release-tag rewrite-race successor

v132 narrows that one P1 without claiming an impossible atomic lock over Git configuration. Its required design puts the final rewrite guard immediately next to every Git network-helper subprocess launch, generates an unguessable full transport alias, and maps that alias once to the exact raw transport in a temporary system-scope config entry that is read before all mutable later scopes. This corrects the rejected command-scope prototype: Git keeps the first equal-length match, so a command-scope identity rule could lose to an exact repository rewrite. If an ambient rewrite is observed before the boundary, the route fails before network access. If an equal-length rewrite appears in the remaining post-guard race, the earlier system-scope alias pin keeps the already-started subprocess on the exact endpoint; the post-call recheck must nevertheless reject the receipt on detected drift. This is a bounded endpoint guarantee plus fail-closed evidence reconciliation, not an assertion that AOI atomically locks global, system, or repository Git configuration.

Fresh v132 dirty-byte evidence now passes:

  • targeted release-tag matrix: 109 passed, 2 subtests passed, artifact SHA-256 931ef80a342310e298f7f3fe2d3f3b48e94a943ae7d5e62b05ffe304149bcfbe;
  • expanded focused matrix: 220 passed, 8 skipped, 2 subtests passed, artifact SHA-256 31c1230cb449fb248114d910ab56791917805655b1ae865fe6c6d28dd5637ae2;
  • strict native and Win32 mypy for the six release-route source modules, compileall, and git diff --check: pass.

The source, test, workflow, runbook, and documentation bytes immediately before this evidence paragraph are what those two pytest artifacts cover; the containing evidence-only documentation update requires its separate contract rerun. These remain focused dirty-byte evidence. Formal AOI packet review, full Windows/fresh-ext4 WSL qualification, clean candidate, integrity-v2 seal, tag delivery, remote CI, GitHub/PyPI publication, promotion bundle, and ARISE installation are still pending.

Formal v132 review subsequently rejected result SHA cacfc7726af7680888f26bec4ef8deb76d30456cf3c416e5d37fae824ad18a2f with P0=0/P1=0/P2=1. The endpoint pin prevents redirection, but the rewrite guard and network subprocess did not enumerate the same Git config authority: ambient GIT_CONFIG_NOSYSTEM=1 could hide a system rewrite from the guard, while the isolated network helper scrubbed that selector and included the discovered system config. The v132 matrices therefore remain superseded diagnostic evidence, not acceptance.

2026-07-23 v133 normalized transport-config authority successor

v133 keeps the endpoint pin and closes the P2 by making the rewrite guard enter the exact isolated transport config context used by the network helper. The shared authority scrubs ambient command-count, parameter, no-system, and system-file selectors; includes the discovered ordinary system config; lists the bounded effective config; and removes exactly the first occurrence of each of its two synthetic unguessable endpoint pins. Any identical real entry later in config traversal remains visible. The release guard therefore cannot be narrowed by GIT_CONFIG_NOSYSTEM=1, and its rewrite decision describes the same config universe that the subsequent ls-remote observes.

The minimum regression proves that an ambient no-system selector hides a configured system rewrite from ordinary git config --list but not from the v133 guard. A second regression proves that synthetic-pin filtering removes only the two injected records and preserves identical real records.

Fresh v133 dirty-byte evidence passes:

  • targeted release-tag matrix: 112 passed, 2 subtests passed, artifact SHA-256 d5cbcb2de77484ff99195fbc45fbea928939af394be631a4cec7fad58868c113;
  • expanded focused matrix: 224 passed, 8 skipped, 2 subtests passed, artifact SHA-256 6f0c2b28efbd2ab938e2e21ee895aca676a6f1403266aa634d0a682d9c091eab;
  • native and emulated-win32 mypy: no issues in seven release/publication source files; compileall and git diff --check: pass.

These results cover the source, tests, workflow, runbook, and documentation bytes immediately before this evidence-only paragraph. The containing documentation contract passed separately. Independent formal review accepted result SHA f148f8733dd6a2ec95d03619e38b8d2af3bab1c8cbdb174fe9e3824d61b05655 with P0=0/P1=0/P2=0 and explicitly permits full Windows plus fresh-ext4 WSL qualification. That read-only verdict covers the v133 source/test/runbook bytes and the preceding evidence paragraph; this formal-result paragraph is an evidence-only successor that remains subject to its own documentation contract and later exact-candidate review. No candidate, seal, tag, publication, promotion, or installation claim has been earned.

2026-07-23 v134 full-qualification fixture/contract repair

The first v133 full-qualification attempt did not pass and cannot be reused. The WSL run on source tree f34310fc98b42bda0ad6924f68a4ea5b9db84843 reported 1899 passed, 29 skipped, 401 subtests passed, 5 failed; its log SHA-256 is a8b1d723389e8965f290f27eee2f158fb6289c2238eda3baeb6f2e48d734a022. The parallel Windows process ended with code -1 after partial progress and no pytest failure summary; its partial-log SHA-256 is 2ebcbe1e41704abcd2713ea34bc61ac0906266542c1f5612703cb95046d14b08. That is an interrupted runner, not a Windows PASS or test-failure verdict.

Five WSL failures exposed qualification-fixture or test-contract defects:

  • the reconstructed fresh tree had no HEAD, so a test that archives HEAD correctly failed;
  • pytest was borrowed from a venv outside the fresh checkout, violating the new dedicated-runtime provenance contract and invalidating three hook/ onboarding fixtures;
  • the ordinary workflow contract still required the superseded 45-minute unit timeout even though the canonical plan, changelog, workflow, and release contract require 90 minutes (coverage remains 120).

v134 creates a committed fresh ext4 checkout and its own isolated venv, updates the strict local-provenance fixture with pyvenv.cfg, sys.exec_prefix, and the sole site-package root, makes the two onboarding doctor tests explicitly mock their out-of-scope runtime-provenance prerequisite in-process, and aligns the stale workflow assertion to 90 minutes. Production behavior is unchanged. The four formerly failing source-level regressions pass on Windows. The expanded affected-module matrix passes 96 passed, 1 skipped, 57 subtests passed, artifact SHA-256 d7b686ef301280ed0971e99970c9ab51774bf9a2403857d2a563a2e2a910db7e. This is dirty-byte focused evidence; its containing documentation contract, independent review, a new exact source-tree identity, and complete sequential Windows/WSL qualification were still required at that checkpoint. No v133 full-suite evidence transfers. The v136 entry below records the later, separately reconstructed successor qualification.

Formal v134 review rejected result SHA 716bbc1af8c08168a595c30ccaa2504b1db843c3683a5017df0c829de4e20fe7 with P0=0/P1=0/P2=2. It found the incorrect four-versus-five sentence above and an over-summarized verification command that did not bind the interpreter, four exact module selectors, flags, and separate containing-doc invocation. v135 corrects the sentence and adds a supplemental task-CAS verification that binds those exact two commands to the existing immutable artifacts; it does not rewrite or replace the earlier record. The reviewer otherwise found the production diff unchanged, the dedicated-venv fixture meaningful, the two doctor mocks properly scoped, and the 90/120 workflow contract consistent. Fresh containing-documentation evidence and a successor formal review remain required before sequential full qualification starts. That successor review accepted result SHA a311e27d47b7ddcf60df70e92b49415fd68c1476e0b956494225dfa793009794 with P0=0/P1=0/P2=0 and permits sequential full Windows followed by a newly reconstructed, committed fresh-ext4 WSL checkout with its own isolated venv. This formal-result paragraph is evidence-only and requires its containing documentation contract; it does not itself establish full-suite acceptance.

2026-07-23 v136 sequential Windows/WSL qualification

The sequential local full-suite qualification froze exact source tree 620810f9e75cdf6df70ea5e1ea1fb3f91d2483c0. Windows ran C:\Users\ryan529\AppData\Local\Programs\Python\Python314\python.exe -m pytest -q tests --tb=short with PYTHONPATH=src and PYTHONDONTWRITEBYTECODE=1. It exited zero with 1913 passed, 22 skipped, 401 subtests passed in 2021.60s; the complete log SHA-256 is fbba27af8ccc15ad29731125165e05c475dc3600defb3b6b9f41575c0c385e0d. A post-run temporary-index readback reproduced the same source-tree identity.

WSL was reconstructed from the same frozen base archive, dirty patch, and untracked-file set into fresh ext4 scratch /tmp/aoi-v135-full-20260723T140010Z. It produced clean synthetic commit 6c43b991ca8056895097946a1dd111bb49b5d89b whose tree is exactly 620810f9e75cdf6df70ea5e1ea1fb3f91d2483c0, then built a checkout-local .venv from requirements/release-tools.lock using both pip download --require-hashes and offline pip install --no-index --require-hashes. The adopted native test command was env NO_COLOR=1 CODEX_HOME=/tmp/aoi-v135-full-20260723T140010Z-evidence/codex-home-clean PYTHONPATH=/tmp/aoi-v135-full-20260723T140010Z/src PYTHONDONTWRITEBYTECODE=1 /tmp/aoi-v135-full-20260723T140010Z/.venv/bin/python -m pytest -q tests --tb=short.

The first WSL pytest child also exited zero with 1906 passed, 29 skipped in 1493.03s; its log SHA-256 is 2d0b10f3951328693b003a51cb17d8c8f9289caa24cf97ac3b5e7ed2974b2adc. That attempt is retained only as diagnostic evidence because the stdin driver later parsed exit 0\r and failed its outer wrapper. The LF-safe native rerun then recorded WSL_CLEAN_DRIVER_EXIT=0, wrote exact exit bytes 0\n, and reported 1906 passed, 29 skipped in 1426.14s; its complete log SHA-256 is 95308a8eb4855d2afe07aaab1bbbfb1ce7a17cb67f25f9bdd1dac622fdb65563. The Codex nested-cell wrapper surfaced status 1 after that completed stdout, so a separate direct wsl.exe native readback was required; it returned zero and revalidated the exit file, summary, clean worktree, HEAD, and exact tree. The nested-cell discrepancy remains a transport diagnostic and is not erased or represented as a clean Codex-wrapper result. It does not alter the reconciled native WSL runtime verdict.

These results establish local Windows and native WSL runtime qualification for the frozen dirty source tree only. They do not establish independent review, integrity-v2 sealing, package/install acceptance, remote CI, tag creation, publication, promotion, or ARISE installation. The containing documentation contract, task-CAS evidence records, and later exact clean-candidate gates remain required.

The first clean ext4 WSL matrix rejected exact commit 87bcd6b4d4c7b4757e6169f8b7f1502b4c6648b3: its case-variant protected-path regression passed on Windows' case-insensitive filesystem but the current-byte lookup treated the configured spelling as missing on case-sensitive POSIX, even though Git exposure matching already used a case-folded identity. The successor resolves each protected component under that same bounded case-folded contract; applies it to current bytes, historical blob lineage, Git index/tree paths, generic publication, and doctor; and rejects component or protected-tree descendant collisions instead of choosing one. The shared identity is specifically ASCII-case-insensitive and non-ASCII-exact; exact CJK paths remain supported, while Python-only multi-codepoint folds such as Straße/STRASSE cannot diverge from Git history discovery. Because git ls-tree does not implement icase, AOI reads a bounded full tree, caches it by commit, filters actual strict paths itself, and counts the unfiltered entries against one aggregate history/outgoing budget. The governed Git child also scrubs all ambient literal/glob/noglob/icase pathspec modes. Windows and WSL ext4 regressions cover hostile pathspec environments, historical copy lineage, doctor tracking, collision denial, aggregate overflow, and cache deduplication. The standalone tracked snapshot builder and publication gate use the same resolver, overlap admission, content correlation, and rule identity; their regressions cover ASCII case variants, non-adjacent overlaps, Straße/STRASSE separation, and exact CJK paths. Current dirty-byte scoped evidence is Windows 81 passed/2 skipped and WSL ext4 82 passed/1 skipped for confidentiality/publication subjects/snapshots, plus Windows 36 passed/1 skipped with three subtests and WSL 37 passed for snapshot/config admission. Five changed source modules pass mypy and compileall; diff-check, managed/package/doc policy byte equality, and task doctor pass. All PASS evidence for 87bcd6b remains diagnostic only; the successor still requires fresh exact-commit Windows/WSL, package, review, integrity, CI, and publication gates.

2026-07-23 durable process-evidence replay repair

A current whole-diff transport review found one P2 evidence contradiction: after a launch already had a terminal receipt, a later run replay returned process_start_evidence=not_started without reading the persisted journal. The bridge now derives the same not_started, process_start_pending_only, or process_started_observed value from the complete journal for initial runs, crash reconciliation, and terminal replay. This does not claim an unpersisted physical Popen and does not authorize a resend. Focused exact-byte tests and a new independent review are required before commit; predecessor PASS evidence does not qualify this repair.

2026-07-23 process-start Chief fence checkpoint

Fresh independent review v94 rejected frozen read-only canary v18 with P0/P1/P2 = 0/2/0. The canary was never prepared or run, and its five evidence roots remained absent. One finding showed that the wrapper's inactive predicate incorrectly expected the released session at the authority record's top level, although canonical Chief release clears that field. The second showed that an empty fixed credential home did not prove that no different current Chief existed through another credential root or later epoch. Frozen v13-v18 assets and all predecessor PASS/seal evidence are historical only and may not be run or transferred to a successor.

The v98 repair moves the decisive check into production at the durable process_start_pending callback while the AOI state lock is held. The runtime rereads the immutable issuance marker, binds it to the exact task/launch/intent/permit/authority/reservation, then requires the canonical Chief record to be inactive at that marker's exact issuing epoch with the latest non-forced release event naming the exact issuing session and epoch. Still-active issuance, alternate-home epoch 2 acquisition, epoch 2 release, wrong release audit identity, missing authority, and malformed marker issuer all fail before pending publication and process start. A durable pending milestone remains the authorization cut: later Chief changes do not retroactively revoke it, and an ambiguous post-pending crash remains launch_unknown without automatic restart. Windows focused source tests pass; fresh WSL/full/package/review/canary evidence remains required before this checkpoint can become an accepted candidate.

2026-07-23 selective protected-files and publication route decision

The user clarified that AOI itself must remain updateable. local_files applies only to user-designated paths and their allowed destinations; it is not a whole-repository publication ban. The canonical implementation plan is aoi-v04-selective-protected-files-plan.md with SHA-256 5ccf1f340b8eec8eaf9309940e2e6e21e9c28836173ca433aede6dded54122d3. It supersedes the rejected two-task/profile-migration route.

The active AOI development config has no protected rules, so this same task can own local qualification, exact pre-push inspection, final-SHA GitHub CI, immutable tag/Release readback, exact wheel/sdist Trusted Publishing and PyPI readback, the Chief-fenced release-promote bundle, and released ARISE installation. No config migration or replacement publication task is required. PyPI tokens and other reusable publication credentials are forbidden; the supported path is GitHub Actions OIDC Trusted Publishing followed by local Chief promotion. Older statements below that describe local_files as globally forbidding push/remote CI/publication are superseded historical rationale and are not the current contract.

The clean-runner policy handoff is content-addressed. Local confidentiality-policy-snapshot reads ignored aoi.toml and exact protected origins, then emits canonical tracked release/publication-policy.json. Git preflight and local release promotion reject a stale tracked snapshot. Remote GitHub runners consume that snapshot only with the workflow's independent expected-digest pin; they do not require ignored/local-only origins and never upload raw aoi.toml. File/archive receipts are generated outside their payload subject, copied as sidecars, temporarily removed for receiver recomputation, and then restored. The standalone gate cannot authorize Git: home_remote_only remains behind exact outgoing-commit preflight.

2026-07-23 resource/startup causal-clock repair

The first fresh-ext4 WSL full non-CLI run failed one session-registration fixture after 1,515 passes: a second resource apply, executed after a persisted startup observation, received a wall-clock timestamp 27.8 ms earlier than that startup. The prior clamp considered resource transitions and completed registrations but not unregistered startup receipts. Resource writers now scan and validate the bounded startup-receipt store under the same state lock and serialize a transition one microsecond after the latest transition, registration, or startup observation when clock rollback is within five seconds; larger rollback still fails before mutation. Focused Windows session/resource regression passed 123 tests plus 14 subtests. The failed WSL whole-suite attempt remains non-acceptance evidence; a fresh exact-diff WSL rerun is required.

2026-07-20 Codex Transport Bridge checkpoint

This is the independent local_files final-task implementation checkpoint, not promotion. Exact documentation candidate 1fcce28a77b80b9833ecb725bcc4ae6650c1d821 (3dd5482233cd5f69ae3a288298a84e426c2ed95c) received a fresh P0/P1/P2=0 documentation review. It passed Windows non-CLI 1,382/33 plus 294 subtests and Windows CLI 172/8 plus 70 subtests. Its fresh ext4 WSL run reached 1,565 passed, 29 skipped but failed one synthetic legacy-verification edge because two sequential fixture timestamps compared backwards after a host/WSL clock step. Ten isolated reruns passed, which diagnoses but does not replace the failed whole-suite result.

The later ARISE installation preflight found that 1fcce28 could not route a Windows Codex hook into canonical WSL state. Successive repairs added a single no-shell Windows-to-WSL grammar, exact platform-pair validation, partial-signal and WSL-UNC denial, fail-closed current-pair rotation, pair-before-receipt publication, and deterministic ordering inside only the synthetic timestamp fixture. Those bytes were committed as exact candidate 02e23c59bddacd641d4bb645d39b9c9298f4990a, tree 96fdfb9e9633d124673adb037c030f591bcec4d0.

The fresh exact-candidate review rejected 02e23c5 with P0/P1/P2=0/1/1. Its P1 demonstrated that an unclosed quote and cmd.exe /c aoi-codex-^hook.exe --hook-version 6 could be preserved as foreign even though the latter executes the AOI hook after CMD caret removal. The P2 was this checkpoint's stale dirty/pre-commit wording. Full suites on the rejected bytes passed Windows non-CLI 1,392 passed, 33 skipped, 317 subtests, Windows CLI 172 passed, 8 skipped, 70 subtests, and fresh ext4 WSL 1,576 passed, 29 skipped. Those results are diagnostic evidence for a known defective candidate, not exact promotion acceptance.

The bounded repair was first reviewed on dirty bytes and then committed as 388d075dbab8ab2eccb3d893b10b2fbc1dbbd286, tree f32aa98ae09462ba799b91554f9d5b8e108dae30. It adds a fail-closed signature check for tokenizer quote failure and CMD caret normalization while preserving a well-formed foreign command that merely prints aoi-codex-hook. Before that commit, focused onboarding/offboard tests passed Windows 68 passed, 4 skipped, 49 subtests and WSL 69 passed, 3 skipped; Linux/Win32 typing over 87 production files, compileall, strict MkDocs, packaged-policy byte equality, and diff-check also passed. A read-only dirty-byte reviewer accepted those bytes with P0/P1/P2=0/0/0 for a local commit only. Its routing remains manual_unverified because the collaboration platform exposes no consumable SubagentStart receipt. These are historical pre-commit checks, not exact package, canary, or promotion evidence.

A fresh exact review of clean 388d075 then returned P0/P1/P2=0/0/1. It independently confirmed the two bypasses closed, the benign control preserved, focused exact Windows tests 68 passed, 4 skipped, 49 subtests, all ten changed blobs equal to HEAD, a clean worktree, and packaged-policy byte equality. Its P2 was this file's stale use of "current dirty", "dirty-byte pre-commit", and "eventual successor" for an already clean exact candidate. Package/install and the first read-only App Server canary were therefore NO-GO. Full suites started only as diagnostic evidence and were intentionally terminated after that verdict; they are not acceptance evidence.

This tracked plan names completed or rejected parent identities but does not embed the containing successor's own commit OID: changing this file would change that OID recursively. The canonical AOI task plan/state must instead bind the exact clean completion identity before fresh review and execution. The detector remains a bounded direct-token/known-shell guardrail, not a general shell-equivalence engine or DLP. No older seal, doctor PASS, package, test result, or canary authorization qualifies the containing successor. No successful live Codex turn, final integrity seal, encrypted local bundle, downstream installation, or ARISE workload is claimed here. At this historical checkpoint the route treated remote CI/publication as forbidden; the 2026-07-23 selective protected-files decision supersedes that interpretation.

The later clean candidate 76b6aefe2015d5e6db77af49112fb3b7aab1d5f0, tree f0c115a4b32dd68fca38dd6ca2dfdc09b5a6ba75, passed its exact Windows and fresh-ext4 WSL suites, static gates, package/isolated-install review, and disposable WSL/Windows hook-routing smoke. Before any App Server process was started, v14 rejected the first fresh read-only canary plan with P0/P1/P2 0/2/1: the driver lacked exact installed-source/config assertions and the core bridge preserved/rechecked a Git endpoint only for workspaceWrite, so a readOnly checkout or config could drift after intent capture. The attempted v1 preparation was abandoned before packet-arm-prepare; authenticated inspection showed launches=[], its Chief credential was released and removed, and it is negative evidence only. Therefore every 76b6aefe PASS, wheel, bundle, review, and canary authorization is historical diagnostic evidence and cannot qualify the containing repair successor.

The first dirty repair then made both sandbox modes preserve and recheck that endpoint, but v15 rejected it with P0/P1/P2 0/1/1. Mutation-path claim coverage is intentionally empty for a clean checkout, so adding, removing, or changing a still-live task claim did not change the endpoint at any of the three freshness gates. The P2 was missing direct regression coverage for a readable historical readOnly issuance marker whose endpoint CAS field is null. The containing repair therefore keeps mutation-path coverage for its original purpose and adds a separate, content-addressed full live task-claim authority record. It binds every reserving claim's token, owner, observed status, exact worktree, and canonical lock scope even when Git status is clean. Historical null-CAS or v1 endpoints remain inspectable as history but cannot reserve or cross the process-start boundary. No v15 result is promotion or live-runtime evidence.

That repair was committed as e39e287d06c60efb40b27c7d9905b71ddab593c8; the documentation-only successor a85932a715c0a8142be4641a24180c4309cd6358, tree ba48017221ebc3cc1f8b821f362c3b7741318826, received an exact clean P0/P1/P2=0/0/0 review. Its exact Windows suites and static gates passed, but two fresh-ext4 WSL full-suite attempts produced three failures that each passed when isolated. Reviewer v20 accepted P0/P1/P2=0/1/0: all three failures are synthetic test fixtures that assumed monotonic wall clocks across subprocesses. The bounded successor canonicalizes only causal fixture ordering, uses a fixed far-past expired-arm window, and derives permit fixture arm time solely from the subprocess-recorded registration time. Production arm, permit, and expiry checks remain strict and unchanged. Every a85932a PASS is diagnostic and non-transferable; the containing clean successor must regenerate all gates.

Exact candidate 91ffb4ec02d0971cf5989ed1da104dfffabf6970, tree 83ccaa691aab99066514cffc66e0d0fc2e195a98, then passed exact Windows, static, package/install, and structural canary-driver gates. Its fresh-ext4 WSL full suite nevertheless failed one positive permit-issuance fixture after 1,593 passed, 29 skipped; the named test passed only on an isolated rerun. The persisted Chief-planned timestamp had been causally clamped ahead of the next child process's wall clock. Sleep-based attempts remained nondeterministic under WSL clock steps and are rejected. The containing test-only repair runs successful issuance and consumption through a tests/-only subprocess driver and the full CLI composition root with an exact post-plan time. Production source does not read the test clock variable. A direct runtime regression proves pre-plan issuance fails before publication; production validation and negative CLI paths are unchanged. On the rejected v42 dirty bytes, the original failing node passed ten consecutive runs on both Windows and a fresh ext4 WSL copy. The complete permit CLI/runtime focus then passed Windows 32 passed, 2 subtests and WSL 32 passed; native and emulated-win32 mypy each passed 87 production files, compileall, strict MkDocs, and diff-check also passed. Those are historical bounded pre-commit contract results, not clean-candidate promotion evidence. Reviewer v42 nevertheless rejected those bytes with P0/P1/P2=0/1/2: the consumer environment retained AOI_CHIEF_CREDENTIAL_HOME, and an independent child recovered the live token; one negative resource-drift path contradicted the direct-path documentation; and the focused logs did not bind commands to source identity. The v43 successor removes every AOI_CHIEF_* and AOI_CREDENTIAL_* locator plus the test-only backup root, makes the child driver reject any such consumer input, adds a fresh-child credential-resolution negative regression, restores the resource-drift negative to the ordinary CLI, and regenerates self-identifying Windows/WSL evidence before re-review. The original failing node passed ten consecutive runs per platform; the complete permit CLI/runtime/reachability focus passed Windows 35 passed, 2 subtests and fresh-ext4 WSL 35 passed, including an injected credential-locator rejection before CLI entry with zero ledger mutation. Both logs bind base HEAD/tree, exact command, Python executable/version/SHA, pre/post SHA-256 and sizes for all six dirty paths, porcelain status, and diff-check; every pre/post source identity is equal. This remains dirty-byte contract evidence pending a fresh independent review. All 91ffb4e PASS, package, review, and driver evidence is superseded and a fresh exact successor must regenerate every promotion gate.

Exact baseline be46e89b427b35d48e8813880a684b9333354506, tree 250b4fa3de08513493b95aa5d8362e4892700087, subsequently passed its complete local Windows, fresh WSL, typing, compile, docs, package, and isolated-install gates. Read-only live attempt v12 then durably reached thread_start_send_pending but rejected the correlated response and terminalized launch_unknown; it was never retried and never reached turn/start. Runtime stderr also proved that the unsupported requested name gpt-5.6 was silently replaced and that default apps/remote-plugin/ remote-control surfaces were active. Independent v49 review therefore returned P0/P1/P2=0/3/0 and rejected every fresh live launch until all three P1s are repaired. Its exact report is external evidence SHA-256 f782f6154929befc164136d3b0260910c8ba75ac9b0a29c60e53116438d32350.

Clean exact commit ff8fd223073ed800f8d9cdc454c4855be8c9e71d, tree c578a4ee526e0ec458a3610c720cc70382c14ac2, contains the v49 production repair. Production App Server argv now supplies --strict-config plus exact overrides disabling web search, apps, remote plugins, and multi-agent loading; thread/start repeats those controls as defense in depth. Under local_files, the adapter requires an absolute non-linked CODEX_HOME whose initial inventory is exactly auth.json, config.toml, and managed_config.toml; it parses the two policy files against closed tables, binds their paths/digests and the safe inventory into the process journal, and rechecks them after the version probe immediately before Popen. managed_config.toml fixes allow_remote_control=false, pins the three disabled feature flags, and uses allowed_web_search_modes=[] so only the implicit disabled mode is permitted.

After initialize, a content-addressed model/list pending/observed pair now requires exactly one visible model == requested_model, a supported requested effort, and no unconsumed pagination before thread/start. The bounded intent model set uses current visible stable slugs such as gpt-5.6-terra; legacy gpt-5.6 is rejected at intent sealing and cannot fall back silently. A lost read-only model-list response is a known failed pre-thread outcome, whereas uncertain process/thread/turn starts retain their prior non-retryable unknown semantics.

Finally, correlated success bytes rejected by generated schema, sealed policy, or model-catalog policy are synchronously written to the task-local non-Git CAS and read back before the typed fault is raised. Only their exact digest/size enter the transport journal; they cannot become a response observation. A schema-valid App Server error envelope now takes that same rejected-evidence path and cannot call the success-response observer or fabricate an initialized, thread-started, or turn-started milestone. At the pre-commit checkpoint, targeted evidence was diagnostic on dirty bytes: adapter/contract/controller plus CLI now pass 124 tests with 1 platform skip. The nine additional adapter/authority/mutation/projection/reachability/runtime/semantic fixture files pass 115 tests, 4 platform skips, and 10 subtests. Native and emulated-win32 mypy each pass all 87 production files; compileall and strict MkDocs also pass. These are dirty-byte contract/static/documentation evidence, not promotion evidence. The containing ff8fd223 bytes then passed the exact Windows full gate: non-CLI 1,434 passed, 33 skipped, 323 subtests plus CLI 172 passed, 8 skipped, 70 subtests, totaling 1,606 passed, 41 skipped, 393 subtests. Its fresh-ext4 WSL full gate is nevertheless a promotion-blocking FAIL: 1 failed, 1,617 passed, 29 skipped, log SHA-256 9d9b9eaf416c4011dc817df86af90a5e33e6246e871d3c114c405ced87ed3800. The failed reachability node passed an isolated 6.50-second rerun, which rules out ordinary five-minute test duration but does not replace the full failure or directly measure the inferred host/WSL clock step.

The only authorized containing repair derives arm time from the later of the persisted migrated semantic head and resource-session registration, runs permit issue/consume through the existing tests-only fixed-clock driver, and runs Codex transport issue through a new tests-only driver that patches the already-existing _now seam to a canonical UTC instant inside the original 3/4/5-minute windows. Missing, malformed, timezone-less, noncanonical, or non-issue driver input fails before CLI work. No production source, expiry window, comparison, tolerance, prior FAIL, canary, or promotion claim changes. A clean successor must rerun every exact-byte gate before any fresh canary.

That tests-only clock successor was committed as exact 68c9c18d63cc3ed857fe1d9be0973c44a49c97b7, tree ef25ad6403a8b5c7fb049563ee2a552c30734f1c. Its diagnostic Windows full gate passed 1,608 passed, 41 skipped, 397 subtests, and its fresh-ext4 WSL full gate passed 1,620 passed, 29 skipped. Independent exact-source review v55 nevertheless rejected it with P0/P1/P2=0/1/0: the adapter accepted model/rerouted as auxiliary, validated only correlation, and the controller dropped it, so a later turn/completed could produce a completed receipt even after the runtime left the sealed exact model. Those full-suite PASS results, all packages built from that commit, and every earlier seal are rejected- candidate diagnostics only.

Read-only design review v58 accepted the smallest sound repair: adapter persist-before-parse typed rejection, a controller-owned exact-wire CAS sink, controller observation pre-scan as defense in depth, and explicit transport contract wire/fault kinds. The active v59 implementation uses a fixed redacted ModelReroutedViolation; missing fields, wrong from/thread/turn, arbitrary destination, and complete pinned-schema reroutes all take the same failed terminal path. A queued completion cannot enter the journal. Current dirty-byte focused evidence is 15 passed for the new reroute falsification subset and 139 passed, 1 skipped for the core adapter/controller/contracts/CLI matrix. The expanded twelve-file Bridge/confidentiality matrix then passed Windows 224 passed, 4 skipped, 4 subtests and fresh-ext4 WSL 227 passed, 1 skipped; both logs bind the same base HEAD/tree and identical pre/post dirty paths. Native and emulated-win32 mypy each passed 87 production files, compileall and strict MkDocs passed, and tracked/packaged policy bytes remain identical. This is implementation evidence only: no clean successor, App Server canary, package qualification, promotion, installation, or ARISE execution is claimed yet.

Fresh dirty-diff review v60 rejected that first implementation with P0/P1/P2=0/1/0. Although the method was already known to be model/rerouted, the adapter still required params to be an object before the CAS callback, could synthesize an evidence reference when the callback was absent, and the controller parsed raw/test-double consistency before its CAS sink. A bounded non-object payload therefore produced a generic pre-CAS fault. The corrected slice introduces a raw-only method/wire/digest carrier, requires the controller callback, and recomputes/persists the exact raw digest before any adapter payload classification or controller raw/parsed comparison. Missing or throwing callbacks remain fixed redacted fail-closed errors without fabricated evidence. The expanded reroute subset now passes 19 tests, including non-object params, missing/throwing callback, and raw/parsed mismatch; the next twelve-file matrices passed Windows 228 passed, 4 skipped, 4 subtests and fresh-ext4 WSL 231 passed, 1 skipped, with static gates green. Those results still did not authorize a commit: fresh dirty review v62 rejected the bytes with P0/P1/P2=0/1/0. Persistence was deferred from reader recognition to consumer dequeue, so an earlier queued completion, a later reader error, a full main queue, or duplicate ordering could leave recognized reroute bytes unpersisted and could still permit completed.

The active follow-up therefore moves the mandatory exact raw CAS callback to the stdout reader's method-recognition boundary, before enqueue or reading a later line. Every recognized duplicate is persisted independently; successful recognition retains a typed reroute fault that outranks later generic reader/backpressure errors and preempts an already queued completion. Consumer classification can use only the verified evidence digest/size, while the controller raw/test-double defense remains. New completion-order, later-error, queue-full, duplicate, field-type, CAS divergence, and controller sink-failure regressions pass as a 30 passed reroute subset. The complete current dirty twelve-file matrix passes Windows 239 passed, 4 skipped, 4 subtests and a fresh ext4 WSL clone 242 passed, 1 skipped; the WSL receipt records every exact test path. Native and win32 mypy over 87 production files, compileall, strict MkDocs, tracked/packaged policy identity, and diff-check also pass. These are v63 pre-review implementation checks only: the plan evidence wording change creates new bytes that must rerun exact gates and then receive a fresh independent dirty review. All v61 PASS logs remain pre-v62-repair diagnostics.

Fresh exact dirty review v65 then rejected v64 with P0/P1/P2=0/1/0. The reader called CAS at recognition, but did not publish its typed fault until the callback returned. A threaded probe held that callback in flight while a prior queued completion passed both instantaneous reader-error checks; the adapter returned terminal and the controller published completed before the callback released. The active repair now increments a condition-protected in-flight barrier before callback invocation and publishes the verified typed or fixed callback fault before decrement/notification. Queue consumption, terminal-turn return, and controller pre-completion defense all wait on that bounded barrier. Threaded success/raise/diverge regressions and an actual stdout-loop duplicate-with-full-queue regression pass in a 34 passed reroute/boundary subset. The complete v66 dirty matrix passes Windows 244 passed, 4 skipped, 4 subtests and a fresh ext4 WSL clone 247 passed, 1 skipped; native/win32 mypy, compileall, strict MkDocs, policy identity, and diff-check also pass. These are implementation checks only. Recording those counts changes this plan, so the resulting exact bytes still require a v67 rerun and another independent review; every v64 PASS remains pre-v65-repair diagnostic only.

The exact v67 rerun preserved the same bytes across Windows 244 passed, 4 skipped, 4 subtests, fresh-ext4 WSL 247 passed, 1 skipped, and all static gates, but fresh dirty review v68 still rejected it with P0/P1/P2=0/1/0. After the controller's last instantaneous wait returned and before terminal journal persistence, the reader could newly recognize a reroute and block in the CAS callback while the controller committed immutable completed; success, callback raise, and divergent-reference probes all reproduced the bypass. Accepted read-only architecture packet v69 therefore replaces the pre-completion check with a terminal stream seal. turn/completed is only a candidate until the one-shot controller closes stdin, the pinned process exits naturally with status zero, stdout and stderr are fully drained and joined, and the reader condition proves both done/zero-inflight/no-fault. Only then may that observation-derived terminal journal row be appended. Forced terminate/kill, nonzero exit, partial output, live reader, or callback/join timeout permanently aborts the clean seal and cannot produce completed. Exact-CAS reroutes may instead append typed failed, and other owned faults may append runtime_unknown, without claiming clean stream quiescence; bounded cleanup then follows. This keeps the strong exact-model contract without pretending App Server exposes a flush watermark that it does not. The current implementation and regressions are pre-review bytes; all v67 PASS and v68 review evidence remain rejection/diagnostic history and cannot authorize a commit.

Fresh implementation review v71 rejected exact v70 with P0/P1/P2=0/1/0. Although _join_readers_until() waited for both reader threads to stop, _stderr_reader() did not retain exceptions or publish a done-success state; an OSError therefore killed the stderr thread, satisfied join, and allowed a natural-zero process with clean stdout to seal and publish completed. The active repair gives stderr the same condition-protected completion/fault boundary as stdout, requires both done flags in the seal, and adds an actual controller plus production reader/seal regression for stderr failure. No v70 test or review evidence authorizes full qualification or commit.

Fresh review v73 then rejected exact v72 with P0/P1/P2=0/1/0: a native OSError from process wait(), or from poll() after stdin close failed, escaped the adapter as a non-transport exception. The controller's typed catch did not terminalize it, leaving the durable journal at turn_started with no terminal receipt. The active repair normalizes every owned stdin/poll/wait boundary to fixed RuntimeDisconnected, marks the stream ABORTED, performs bounded no-throw cleanup, and adds actual-controller regressions for both sequences. It deliberately does not catch arbitrary durable-sink OSError at the controller level, because such a failure can make the persistence result ambiguous and must not be retried as though it were a known process fault.

Fresh review v75 rejected exact v74 with P0/P1/P2=0/2/0. First, stdin close failure followed by a normal poll()==0 was still treated as a clean process exit and could seal completed; policy requires every stdin close failure to abort. Second, an exact-CAS ModelReroutedViolation already retained by the reader could be replaced at the controller boundary by a later process-wait RuntimeDisconnected, incorrectly degrading known failed/model-rerouted to runtime_unknown. The active repair removes the poll-based recovery from stdin close failure and routes every seal failure through the reader's retained fault precedence before constructing a later generic process fault. New actual-controller modes cover close-error with exit zero, unavailable stdin, and typed-reroute plus wait-error ordering. No v74 evidence authorizes full qualification or commit.

Fresh exact-artifact review v77 rejected v76 patch 4711b7117eb30f6281369a741019343eeb5817ccf3e0d2d1b5028b1e7a16c392 (108704 bytes) with P1/P2/P3=2/1/0. A poll() fault skipped every later terminate/kill step and unconditionally erased the still-live process handle; a terminate plus wait fault had the same result. Separately, reader join() handled only RuntimeError, so an owned OSError escaped through controller cleanup, left the journal at turn_started, and prevented terminal receipt publication. The liveness post-check also covered stdout but not stderr. The active repair separates poll/terminate/wait/kill into independent bounded attempts, keeps an unconfirmed-live child handle, normalizes owned join and liveness exceptions, and accounts for both readers. Failure paths also settle an already in-flight reroute callback within their original absolute deadline, so a retained exact-CAS reroute still outranks a later join/process fault. Actual-controller regressions cover poll failure with terminate fallback, terminate/wait failure with kill fallback, fully unconfirmed exit with retained handle, raw join failure, typed-reroute plus join failure, and stderr-only live reader. The resulting diagnostic matrix passes 15 modes; both complete transport files pass 118 passed, 1 skipped, strict typing passes, and diff-check is clean. These are mutable implementation checks only. The repaired bytes still require a fresh immutable artifact, exact independent review, and all full qualification gates; no v76/v77 evidence authorizes commit.

Exact v78 review v79 returned P1/P2/P3=0/0/0 and admitted the subject to full qualification. Its v81 Windows run passed non-CLI 1492 passed, 33 skipped, 327 subtests plus CLI 172 passed, 8 skipped, 70 subtests; native/win32 mypy over 87 source files, compileall, strict MkDocs, policy identity, pinned resources, and diff-check also passed. The fresh ext4 WSL full run nevertheless failed all 15 parameter instances of the new production-adapter cleanup matrix before behavior execution: the test passed the venv symlink Path(sys.executable) to the deliberately strict production constructor, which rejects linked executables. The active test-only repair resolves that synthetic placeholder to its real regular executable while retaining the production symlink denial and its dedicated negative tests. WSL reported 15 failed, 1661 passed, 29 skipped; all v78/v79/v81 PASS and review evidence is now superseded for acceptance. The containing bytes require a fresh exact artifact/review and complete Windows/WSL rerun.

The v82 portability focus bound the repair to diff SHA-256 208bc877d8e5d0401568aaa66b505d4479ae82da6d092ec9a57b2146a85831a3 (118885 bytes). All 15 production-stream-seal parameter instances passed on native Windows and in a fresh WSL ext4 clone, and both runners reproduced the same pre/post diff digest and size. The Windows evidence log is SHA-256 4ce5566b9f417977bb3128bab06bb3cbbd43d952f0cc6f42531583a2e80177f5; the WSL log is SHA-256 561b57d785fbeaa4a154e2bf038e54c34e6e6a49eca6db8b7f1cdaf32c2817c3. This is focused portability evidence, not a replacement for exact containing source review or the complete Windows/WSL qualification matrix.

The exact v83 subject subsequently passed v84 Windows non-CLI 1492 passed, 33 skipped, 327 subtests, Windows CLI 172 passed, 8 skipped, 70 subtests, fresh ext4 WSL 1676 passed, 29 skipped, and the native/win32 typing, compile, strict docs, policy/pin identity, and diff gates. Whole-diff review v85 nevertheless returned P1/P2/P3=0/1/0 and rejected commit because this plan, policy, and changelog incorrectly described a successful clean stream seal as authority for every fault-derived terminal row. The active text repair limits that seal claim to observation-derived terminal rows, preserves exact-CAS failed and owned runtime_unknown fault terminals without a false quiescence claim, and adds an early-reroute controller regression proving exact CAS, never-completed, no-successful-seal, and bounded cleanup. All v84 PASS evidence is diagnostic for the superseded bytes; the containing subject requires a fresh exact review and proportionate rerun before commit.

  • The optional aoi-codex-bridge entry point exposes finite issue, run, inspect, and verify-mutation commands. Only issue accepts a Chief credential. run receives one exact permit SHA and issuance marker; it cannot receive or retain reusable Chief authority.
  • Repository onboarding now treats a hook as one platform pair, not two independent command strings. Native Windows and non-WSL POSIX retain the exact direct provenance-bound launcher. A canonical WSL session is detected only when the non-Windows host, Microsoft kernel release, WSL_DISTRO_NAME, absolute WSL_INTEROP, POSIX launcher/root, and current passwd user all agree. It then writes the direct Linux command and this fixed no-shell commandWindows grammar:

wsl.exe --distribution "<distro>" --user "<user>" --cd "<root>" --exec "<absolute-hook>" --hook-version 6 --project-root "<same-root>" --provenance-sha256 "<digest>"

Quoting/order, distro, user, cwd/root equality, absolute inner launcher, and digest are canonical. Spaced distro and POSIX path values remain one quoted argument; POSIX backslashes are rejected because they make Windows command line quote boundaries ambiguous. Partial WSL signals, native-Windows WSL UNC roots, shell wrappers, arbitrary prefixes, PATH-resolved inner hooks, duplicate or reordered flags, and pair drift fail before onboarding publication or block doctor/offboard. A proof-changing reinstall may rotate one current pair only when the existing handler byte-matches the pair reconstructed from the currently persisted validated provenance receipt; AOI archives that receipt and rejects partial old/new or cross-bound pairs. It writes the desired hook pair before replacing the receipt, making a receipt-publication crash fail-closed and resumable rather than stranding the prior pair. The older tolerant WSL parser remains legacy ownership recognition only; it cannot establish current trust. Onboarding/offboarding also conservatively recognize direct tokens and one bounded known-shell operand; tokenizer quote failures carrying an AOI hook signature and CMD caret-normalized AOI signatures fail closed. This does not claim exhaustive shell parsing, DLP, or protection from an ungoverned same-user process. wsl.exe itself and the Codex /hooks trust decision remain cooperative host/user boundaries. - Semantic-v2 packet activation is now reachable without a legacy task write. packet-arm-prepare derives a schema-v3 transaction from one canonical ready packet, routing arm, decision, one-shot permit, and exact semantic head. Chief issuance reuses the complete core packet, parent/root-session, canonical resource event/receipt/registration, topology, envelope, and skill gate; first unreserved consumption without Chief credentials repeats that gate and commits routing authority, permit projection, and canonical ready -> armed packet state in one semantic compare-and-append. Before initial issuance/consumption, a terminal task, stale/tampered authority, absent packet delta, old schema, or changed head fails closed. An exact already-committed replay is historical event/projection recovery and does not re-authorize a packet or launch; it returns before mutable external packet files are rechecked, while every new downstream Bridge transition applies its own canonical authority gate. Cohort schema v2 remains separate and is not silently upgraded to the standalone packet-owning transaction. - Permit consumption is one semantic CAS: the exact active packet arm becomes transport_reserved, the packet becomes bridge-owned dispatched, and a sealed ownership object binds task/packet/arm/launch/intent/permit/ reservation/routing bytes. It does not fabricate SubagentStart, an agent id, thread id, turn id, or runtime observation. Transport ownership upgrades the task and packet dispatch generation to v2; dropping either marker or routing the packet through an ordinary core dispatch path fails closed. - One Chief-created, per-launch OS file lock serializes the complete controller lifetime. This proves cooperative at-most-one controller-owned start sequence for the same AOI platform lock domain, not adversarial same-user protection and not cross-Windows/WSL mutual exclusion. Two different launch ids for one arm are instead arbitrated by the exact semantic head and packet ownership CAS, so only one can reserve. - The exact stable runtime remains Codex 0.145.0: App Server SHA-256 5163c75ed88d460b35b03c8d8f4ef190b3bdd09971d7ac2bd90b48c435f1cf14, 273-file schema-manifest SHA-256 6b8bfa74e475c6c9b46926c46f287f47873d188b13ab3df8db4633602db73262, and combined v2 schema SHA-256 6253fd70273c2f33c42d0b6090eac771580c994b3c6eed4277598de08a5e69ec. Executable bytes/size, schema, prompt, cwd, approval, sandbox, and correlation drift fail before the runtime-process boundary. Version output is checked by a bounded exact-binary probe after that boundary and before the App Server. - The pinned 0.145.0 generated protocol uses line-delimited RPC objects without a jsonrpc member. A real raw initialize response was the exact shape {id,result}; the old fake peer incorrectly emitted JSON-RPC 2.0 envelopes, so the old adapter rejected the live response before initialization. The current repair emits schema-matching {id,method,params} requests and the exact method-only initialized notification, rejects tagged/malformed envelopes, and hashes exact inbound wire bytes. Response-derived semantic milestones retain their actual request methods (initialize, model/list, thread/start, turn/start) instead of claiming the similarly named notification methods. A correlated success result is validated against the pinned 0.145.0 required shape before the response journal callback; initialize must report the exact isolated Codex home, and model/list must expose exactly one visible requested model with the requested effort and no remaining page before any thread can start. The bounded intent rejects unsupported aliases, so the runtime cannot silently substitute a fallback. thread/start additionally rebinds cwd, model, approval, sandbox/network, ephemeral state, and model provider to the sealed intent. The supported lifecycle notification subset checks pinned Thread/Turn/item required fields and timestamps. An invalid thread/turn success response remains a non-idempotent launch_unknown and is never resent. Exact rejected-response bytes are synchronously preserved and read back from task-local non-Git CAS, then become fault evidence only; a schema-valid App Server error response is also barred from the success observer and uses this fault path. Other synthetic faults hash a finite, redacted reason code. A fault may not populate response_sha256 or wire_event_sha256; malformed error envelopes fail before response observation. Historical commit 0201799 passed the eleven-file Bridge/ confidentiality/export matrix as 149 passed, 4 skipped (68/1 adapter/ controller/contracts plus 81/3 CLI/runtime/authority/reachability/ projection/mutation/confidentiality/export). Its WSL full-suite diagnostic later reached 1,561 passed, 29 skipped but exposed two wall-clock-order fixture failures. Its successor c73c0ca makes the event factory consume the contract's single wire-method table and derives arm time strictly after the persisted registration. Exact c73c0ca then passed the complete local Windows/WSL suites listed above. All predecessor results remain historical evidence; exact containing-commit reruns and review are mandatory. - Reservation, every process/request/response milestone, terminal receipt, and mutation elevation use deterministic semantic command identities. Exact publication-response-loss retries reconstruct the previous ledger head. The reservation's authenticated pending binding is the durable binding-to-event crash witness: only that exact marker-bound binding may resume the same still-terminal semantic command after permit expiry; no binding, a different pending binding, or head drift remains a fresh launch and fails closed. Ambiguous process/thread/turn starts never resend. turn/interrupt response is nonterminal observation, and only turn/completed establishes the runtime terminal state. A completed, failed, or interrupted terminal journal/receipt is invalid while any item remains started; runtime_unknown deliberately preserves an outstanding item as incomplete evidence rather than fabricating completion. - The durable process_start_pending callback is the runtime-process authorization boundary. Immediately before committing it, AOI revalidates the earlier of permit/arm expiry, the complete live packet ownership object, packet/task dispatch generation v2, fresh reserved namespace row, local_files storage preflight, and—for both readOnly and workspaceWrite—the exact pre-Git/tree/status/claim endpoint. It authorizes the exact-binary --version probe and subsequent App Server Popen; no child executes before it. After pending is durable, a crash is ambiguous and must reconcile without automatic restart. CLI process-start output is derived only from journal evidence: not_started, process_start_pending_only, or process_started_observed. The boolean is named app_server_start_durably_observed; it never claims a physical Popen that occurred but could not be persisted. - Every readOnly and workspaceWrite issuance must validate an exact pre-turn Git endpoint against AOI claims, preserve it in task CAS, and bind that CAS SHA into the immutable issuance marker. The endpoint binds both mutation-path coverage and a separate complete live task-claim authority digest, so a clean worktree cannot erase claim add/remove/owner/status/ worktree/lock drift. verified_mutation remains a workspaceWrite-only, separate semantic projection/binding over pre/post Git snapshots, trees, claim endpoints, and the original runtime receipt. It does not overwrite codex_runtime_observed and never infers task completion. The preserved endpoint is recaptured again after issue/before semantic reservation and again at process pending, so Git or full claim-authority drift cannot be attributed to the turn merely because the task semantic head stayed fixed. - Under local_files, issue, reserve, and process-pending preflight the AOI artifact/CAS root and writable cwd. A confirmed network or common sync root is denied before publication or Popen. Windows drive-letter paths are checked with GetDriveTypeW plus DOS-device alias inspection: mapped network drives are confirmed-danger, while missing roots, metadata failures, SUBST aliases, and link/reparse traversal are explicitly unverified and also fail the confirmed-local launch/storage gate. The caller-visible lexical drive is classified before the resolved target, so resolution cannot erase a SUBST/ DOS-device alias. file: URI paths are strictly percent- decoded before classification, and every Windows FILE_ATTRIBUTE_REPARSE_POINT tag is covered rather than only symlink/ junction helpers. The child receives networkAccess=false and a scrubbed environment. Before process pending, the adapter also requires an isolated exact-inventory CODEX_HOME, parses and hashes closed config.toml and managed_config.toml policies, binds them into the process journal, and revalidates them after the exact-binary version probe before Popen. Production argv and thread/start.config independently disable web search, apps, remote plugins, and multi-agent loading; the managed policy denies remote control. The child environment contains no known reusable publish credentials. Credential matching is finite and cannot prove an unlisted secret absent. This is still not DLP or an offline-model guarantee. - Contract tests: the historical packet-owning closure slice passed 55 tests, 9 subtests across dispatch protocol, standalone/cohort permit runtime and CLI, plus a real task-composition test covering legacy migration through canonical arm and Bridge issuance. Exact parent c73c0ca later passed a two-shard Windows partition: non-CLI 1,382 passed, 33 skipped, 294 subtests and CLI 172 passed, 8 skipped, 70 subtests, for 1,554 passed, 41 skipped, 364 subtests total. Its fresh ext4 WSL clone passed 1,566 passed, 29 skipped plus compileall. Those broad runs establish only the exact parent; the documentation-only containing commit receives its own final evidence. The covered surfaces include bridge contracts, canonical authority, projection/runtime/controller, fake stdio lifecycle, Git mutation evidence, CLI, confidentiality/export, packet generation/downgrade, semantic objects, transition permits, and distribution metadata. New falsification includes two concurrent runs with one fake process owner, two independent OS processes contending on the launch lock, lock sentinel/ hardlink tamper, same-arm different-launch CAS, issue-to-run Git drift, expiry crossing before pending, executable substitution, sync-root/mapped- drive/unverified-volume storage, outstanding terminal items, generic packet cancellation, packet/ownership/generation drift, and exact retry. This remains contract/fake-runtime evidence. - Independent bridge review: an earlier review rejected promotion on canonical route binding, stale Git pre-image, auxiliary correlation, distribution coverage, duplicate process ownership, non-atomic arm consumption, and consume-time expiry. The current source implements each requested correction plus the later confidentiality/process-start hardening. A 2026-07-20 fresh read-only review of the then-uncommitted bytes found no P0 but rejected canary on three P1s: terminal runtime/packet status mismatch, the current task's truthful standard binding versus the planned local_files final route, and Chief credentials surviving in the controller process. It also found version-probe boundary, finite credential detection, and malformed Markdown-heading P2s. The source implements all six corrections. A following v4 read-only review found no P0/P1 and one P2: the CLI output boolean could be read as proof that physical Popen occurred when it represented only a durable journal observation. It is now named app_server_start_durably_observed and has a response-publication-loss regression. Those review dispatches are truthfully recorded as manual_unverified because the collaboration spawn did not emit an AOI-consumable SubagentStart; neither rejected review is approval. The v5 review then found no transport P0/P1, but rejected canary and promotion on two local-install P1s: the installed provenance omitted the Bridge entry-point/launcher/module receipt, and the local wheel fixture still emitted only three console scripts. The repair now binds the fourth Bridge entry point through the local contract, installed runtime/RECORD checks, generated-script checks, and schema-v2 receipt. Its eight-file consumer matrix passed on that exact repair as 142 passed, 12 skipped, 32 subtests on Windows and 149 passed, 5 skipped on WSL; all three review dispatches remain manual_unverified. Pre-v6 package rehearsal then exposed another real-repo P1: the source-manifest path grammar rejected tracked dotfiles such as .gitignore and .github/workflows/test.yml. The grammar now accepts safe leading-dot relative paths while still rejecting ./.., absolute, normalized, backslash, and traversal paths; the fixture tracks both dotfile forms and passes on Windows/WSL. The following v6 review found P0=0/P1=2/P2=0: Windows mapped drive letters were not classified by volume type, and a terminal journal could leave an item started. Its arm expired before the reviewer returned, so AOI records it as a procedural-expiry advisory, not an authorized review attestation. Both source defects and their negative tests were implemented. The valid-arm v7 review accepted outstanding-item closure but found one remaining locality P1: percent-encoded drive colons in file: URIs and generic non-junction reparse attributes could bypass classification. Strict URI decoding, generic reparse-bit inspection, doctor/Bridge negative tests, and missing-leaf ancestor traversal are now implemented. A fresh v8 review closed those direct gaps but rejected one alias-ordering P1 and one malformed-URL P2: resolving before drive inspection could erase the SUBST identity, and malformed IPv6 file hosts could escape as raw ValueError. Lexical-drive-first plus resolved-target classification and safe invalid URL/ port redaction are now implemented with regressions. v9 found one remaining reporting-only P2 for malformed URI kind/redaction consistency; that was repaired, and v10 independently returned P0=0/P1=0. v10 authorized managed policy refresh and a bounded read-only scratch canary. Its sole P2 was this paragraph's stale reference to v9; this documentation-only repair still requires fresh review before final promotion closure. A later reachability/ CAS review rejected the new packet-owning slice on two P1s: terminal tasks could still reach the pure arm transition, and semantic issuance did not invoke the complete core packet authority gate. Both defects now have source and negative-test repairs. The following v2 review found one further P1: the detached arm was internally self-consistent but its parent/root-session and resource event/receipt/registration authority were not rebound to canonical task state. It also found two P2s covering exact committed-replay wording and missing direct slot-collision tests. The current repair extends the core composition callback at both issue and first unreserved consume, upgrades the CLI fixture to a real registration/migration path, adds parent/resource/ registration and exact/wildcard collision falsification, and narrows the replay claim. The fresh v3 exact-diff review returned P0=0/P1=0/P2=0 and accepted those then-uncommitted bytes for a clean local commit. It independently ran six targeted closure regressions plus the reverse exact-to-wildcard probe and retained the boundary that reachability is composition evidence, not a live App Server canary. The dispatch is recorded as manual_unverified because collaboration still emitted no AOI-consumable SubagentStart; its technical outcome is accepted, but exact committed bytes still require the remaining profile-aware doctor, full-suite, canary, integrity, and installation gates. The first exact-commit Windows run then exposed one architecture-boundary failure: semantic command handlers lazily reverse-imported cli.py to obtain the gate. The repair makes the CLI composition root inject the validator and makes a missing injection fail closed. The affected architecture, permit CLI, and real reachability tests pass as 16 passed, 2 subtests. A later read-only protocol review (bridge-live-protocol-review, truthfully manual_unverified) found no P0, one P1 for synthetic fault bytes mislabeled as response/wire evidence, and one P2 for unvalidated error-envelope shape. Both source defects received contract and negative-test repairs and required a fresh clean-commit review. Exact review of clean commit 8a4aaab then returned P0=0/P1=2/P2=2 and rejected a fresh canary: response bytes were mislabeled as notification evidence and method-specific success schemas were not enforced before milestone publication. Its two P2s covered low-discrimination synthetic fault digests and stale checkpoint wording. Exact review of its successor 0201799 returned P0=0/P1=0/P2=2 and accepted only a bounded read-only canary. Its two advisories were this file's stale candidate wording and the unused duplicate runtime wire-method map. The c73c0ca addressed both before canary execution; its fresh review returned P0=0/P1=0/P2=1, with only the five stale evidence labels corrected by the containing documentation-only commit. Review evidence for each newer exact commit belongs in AOI state/local evidence and is never inherited from these historical reviews. - v38 pre-canary rejection: exact candidate 4f6d0b3df4e10769e47bef36efc8dd7aaec99a07, tree dc7efa07aa685371c693f9c458d54ed800a5e0eb, had already passed local Windows/WSL, package/install, and driver probes, but no new App Server process was started. The independent v38 review rejected launch with P0/P1/P2 1/1/0: the external driver authenticated installed RECORD rows without rejecting extra unrecorded import members, and production reservation retry could not recover after a crash between pending-binding publication and the semantic event once the permit expired. The production repair now treats only the exact authenticated marker-bound pending binding as a recovery witness and adds absent/wrong-witness falsification. The driver must next enumerate the complete installed package/dist-info namespace before any AOI import. A first dirty-byte source review accepted local commit with P0/P1/P2 0/0/1; its advisory requested direct fresh-authority-revalidation and pending-binding-plus-nonplanned-head regressions, both now present. The v9 driver template now rejects unrecorded package files, top-level extension shadows, extra dist-info files, and directory-closure drift before AOI import on the historical isolated install. It remains structural/template evidence, not authorization for a successor wheel or canary. The follow-up v40 cross-review returned P0/P1/P2 0/0/0, accepting the production bytes for a local commit and the v9 closure structurally while explicitly withholding canary and promotion authorization. Because the production bytes changed, every prior PASS, wheel, install receipt, driver digest, and promotion checkpoint is historical only; the containing successor requires fresh exact-byte evidence. - Live App Server canary: attempted, not passed. The first disposable setup stopped before Popen because its private Codex home was inside the governed Git worktree. A fresh task then consumed one permit and durably observed the exact pinned App Server process, but terminalized failed at initialize because AOI required a jsonrpc member that the pinned runtime/schema omit. The request was not retried, neither attempt mutated project Git, and private Codex/Chief credential directories were deleted. The failed canary is diagnostic evidence only. A wholly new task/packet/permit on the exact reviewed containing candidate must run the read-only canary; only a pass may unlock a separate writable scratch canary. - Git mutation verification: fake-runtime + real disposable Git filesystem tests prove separate runtime-versus-mutation evidence, pending binding/event recovery, exact retry after later drift, and task_completion=not_inferred. This is not a live Codex mutation canary. - Promotion environment (superseded checkpoint): this checkpoint assumed that local_files globally forbade push and remote CI. The 2026-07-23 selective protected-files decision rejects that assumption. Exact local Windows/WSL evidence, independent review, integrity-v2 seal, package/install smoke, and an encrypted local bundle remain prerequisites, but final-SHA GitHub CI/publication now follow them. For a WSL-governed downstream project that Windows Codex opens, package/install smoke also requires a disposable exact-wheel codex-init, seven-event pair inspection, doctor/offboard exercise, and a bounded Windows invocation of the exact commandWindows into the same WSL state tree. A structural JSON or doctor result alone is not runtime hook delivery. Historical GitHub PASS or failed clean-checkout runs remain historical only. - Complete Windows suite: exact commit ed91f12 passed a two-shard partition: non-CLI 1,365 passed, 33 skipped, 294 subtests; CLI 172 passed, 8 skipped, 70 subtests; total 1,537 passed, 41 skipped, 364 subtests. Native and emulated-win32 mypy each passed 87 source files; compileall and strict MkDocs passed. Clean commit 8a4aaab later passed a diagnostic two-shard Windows run: non-CLI 1,371 passed, 33 skipped, 294 subtests and CLI 172 passed, 8 skipped, 70 subtests. Historical 0201799 was started as an exact Windows/WSL rerun; its WSL full suite exposed the two deterministic-time fixture failures described above. Exact parent c73c0ca subsequently passed non-CLI 1,382/33/294 and CLI 172/8/70. These results establish the parent, not later commits. Exact 1fcce28 independently passed non-CLI 1,382/33/294 and CLI 172/8/70, but its WSL and installation gates failed; final successor evidence is recorded separately by AOI. Exact a85932a later passed non-CLI 1,406 passed, 33 skipped, 323 subtests and CLI 172 passed, 8 skipped, 70 subtests; those Windows results do not transfer across the fixture-only successor bytes. - Complete WSL suite: exact ed91f12 was cloned to fresh ext4, all 259 tracked files were byte-equal to Git blobs, and passed non-CLI 1,369/29 plus CLI 180/0, total 1,549 passed, 29 skipped; compileall also passed. A later fresh-ext4 8a4aaab attempt selected /usr/bin/python3 without pytest and therefore produced no test evidence. Exact 0201799 used the verified Python 3.12 environment and reached 1,561 passed, 29 skipped plus two permit-fixture failures before this clock-order repair. Exact parent c73c0ca then passed 1,566/29 plus compileall in a fresh ext4 clone. All predecessor evidence remains nonqualifying. Exact 1fcce28 later reached 1,565 passed, 29 skipped, 1 failed; the isolated failing node then passed ten times, which is diagnostic only. The synthetic fixture now clamps its replacement record strictly after its source before hashing; a fresh exact successor full suite is still required. Exact a85932a then failed two fresh-ext4 full attempts: 1 failed, 1,589 passed, 29 skipped followed by 2 failed, 1,588 passed, 29 skipped. All three named failures passed in isolation. The containing repair normalizes causal ordering in those three fixtures only; focused PASS cannot replace a fresh full-suite PASS. Exact 91ffb4e subsequently reached 1 failed, 1,593 passed, 29 skipped because a successful permit helper launched its child process before a bounded Chief-planned timestamp was visible to that child; its isolated rerun passed and is nonqualifying. Two subsequent wait-based dirty experiments were also rejected after full-file WSL failures. The successor freezes only the positive test-driver subprocess observation and separately proves the unchanged runtime future-time rejection; it must earn a new fresh-ext4 whole-suite PASS. - Package/install diagnostic: exact ed91f12 used locked WSL build 1.5.0 / hatchling 1.27.0 and produced wheel/sdist SHA-256 4e86fdbf3ff71b36e7e559e38cb3ea8eaa77815b031b5a6aefcb33e4e26842bf and 4681bcaea596cf5128566f73709992e9cb04c126ef8c2a8f98fb3d0c32df9127. verify_dist.py accepted both the original wheel and sdist-derived wheel; no index/download was used. An isolated Windows install loaded version 0.4.0a1, all four console entry points, and the three then-pinned 0.144.6 resources, and all four installed launchers returned success. That exact commit predates the 0.145.0 refresh and is not evidence for the current runtime resources. This is superseded package evidence after the live defect repair, not a final artifact, successful canary, promotion seal, or downstream install. - The first integrity-v2 independent review rejected promotion on two P1s: inline migration downgrade and non-atomic finding review. The accepted fix makes persisted migration CAS-only and review+findings one atomic tail; root reruns passed 29 focused tests plus 13 subtests and five targeted CLI migration/seal/CAS tests. Those are historical slice results. Integrity or promotion evidence is accepted only when the containing candidate has a current checkpoint, integrity snapshot/review/seal, global doctor, exact Windows/WSL suites, package/install smoke, and local bundle evidence; no prior doctor PASS or seal applies.

2026-07-20 ic-local / local_files confidentiality scope

local_files implements model context allowed, user-designated files destination-restricted. It is not an air-gap promise: Codex may receive prompt and project context through its model service. A fully offline or self-hosted model profile is a separate future capability.

The strict profile contract is:

[confidentiality]
mode = "local_files"
model_context = "allowed"
git_push = "deny"
remote_ci = "deny"
artifact_upload = "deny"
external_export = "permit_required"
local_cas = true
protected = [
  { path = "private/design.bin", kind = "file", policy = "home_remote_only", home_remote = "origin", home_destination = "https://github.com/example/chip.git" },
  { path = "eda/private", kind = "tree", policy = "local_only" },
]

The closed scalar values are defaults for protected subjects. With omitted or empty protected, no file is classified and normal repository push, remote CI, release, and package publication remain available. home_remote_only permits the exact protected path/content only to its named remote and credential-free home destination; other repositories are denied. local_only denies every external destination. Its only governed exception is a Chief-issued one-shot permit bound to one exact destination, content SHA-256/size, purpose, expiry, task, and exact task-state digest. The consuming controller receives no reusable Chief credential. AOI persists consumption before returning fresh_consumption=true; an exact response-loss retry returns fresh_consumption=false and cannot resend. AOI does not perform the upload, and publication_observed=false is not remote receipt evidence.

AOI-managed Git push must preflight the exact config, remote/destination, complete ref update set, and read-only observed remote pre-state OIDs. It scans every outgoing commit, protected path history, and matching blob/content identity so delete-at-tip and copy/rename cases do not erase protection. Protected links/submodules, matching LFS routes, destination rewrite ambiguity, missing scope, duplicate/wrong correlation, and rule drift fail closed. Generic artifact, attachment, connector, release, and package gates require an exact file/content manifest whenever protected rules exist.

Doctor reports the rules, Git fetch/effective push URLs, rewrites, LFS endpoints, workflow presence, local/synchronized artifact roots, Windows mapped drives/aliases, known sync roots, known credential names/helpers without values, and authenticated push/export receipts. External publication capability alone is inventory or warning; an exact protected-rule/home-destination contradiction, violating receipt, or unsafe AOI local CAS/state is an error. Detection is finite and cannot prove that an unlisted credential is absent. Unverified volume, alias, or link/reparse locality remains labelled uncertainty but fails the confirmed-local Bridge/state gate.

The AOI v0.4 promotion loop, whose current config has no protected rules, is:

local Git commit -> Windows + local fresh-ext4 WSL tests -> independent Codex review -> integrity-v2 seal -> exact pre-push receipt -> exact-main-push GitHub Linux/Windows test + main-only docs -> immutable GitHub Release -> PyPI Trusted Publishing/readback -> Chief release-promote bundle -> released ARISE install

EDA is applicable only when the governed project's completion boundary names an EDA workload. It is not required to promote the AOI Python package, and this task must not launch ARISE RTL/EDA. This is a bounded governance/enforcement slice, not comprehensive DLP; explicit same-user shell bypasses outside AOI remain outside the guarantee.

Implementation checkpoint (2026-07-20): strict profile parsing, the first AOI-managed publication denies, redacted doctor inspection, and the local-only external-export intent/permit/issuance/consumption store are implemented. The Bridge now reuses the profile at issue, pre-reserve, and process-pending boundaries; it denies confirmed sync/network artifact roots before AOI writes, and confirmed sync/network writable cwd before Popen. It also denies mapped Windows drive roots and any drive/reparse locality it cannot confirm. The integrated Bridge/confidentiality focus is the dual-platform 16-file result above. Independent v9 review returned P0=0/P1=0/P2=1: it closed the mapped-drive ordering, malformed-IPv6 exception, and terminal outstanding-item findings, but found inconsistent classification/redaction for malformed file URIs and invalid ports. Those cases now consistently become invalid / <invalid> and have doctor-level negative tests. v10 accepted the confidentiality/transport bytes, and the later packet-owning-arm v3 review accepted its clean exact diff with P0=0/P1=0/P2=0. Export falsification covers wrong destination/purpose/content, task-state drift, expiry, export-ID single assignment, exact replay, Chief-credential absence, and doctor redaction. Earlier exact-commit package/ install rehearsals and local bundles are historical diagnostic evidence, not an external upload, live App Server, containing-commit package, accepted latest-byte independent review, seal, or promotion result.

Subject-aware promotion gates

The final gate selector is part of the evidence contract:

  • standard, or local_files with no protected rules: exact final-SHA remote-main CI and the selected publication gates are available normally.
  • local_files with home_remote_only: the protected subjects may reach only the exact named home remote/destination after an exact outgoing-commit preflight. Other repositories fail closed.
  • local_files with local_only: those exact subjects remain outside all external CI/release/package/artifact manifests unless a separate exact one-shot export permit is consumed. Unclassified subjects are not globally blocked.
  • A remote PASS from another SHA, destination, or subject manifest is historical context and never substitutes for the selected exact gate.

Evidence categories for O9/O10

  1. Contract tests: historical exact be46e89 evidence passed its complete Windows and fresh WSL collections, typing, compile, docs, package, and install gates. Exact ff8fd223 passed Windows but failed the fresh-ext4 WSL whole suite at one cross-process reachability fixture; its isolated rerun is diagnostic only. No result transfers to the containing test-only successor; that clean commit must rerun every local gate.
  2. Live App Server canary: v12 on exact be46e89 started the pinned process and initialized, then rejected a correlated thread/start response and terminalized non-retryable launch_unknown. It also exposed unsupported model fallback and default app/plugin/remote-control surfaces. v12 is a diagnostic NO-GO and cannot be resent. Fresh v13 remains forbidden until a clean repair successor passes independent review and receives a new task/packet/permit identity.
  3. Git mutation verification: fake runtime plus disposable real Git filesystem tests prove the separate evidence transition, but no live Codex writable mutation is claimed. A writable live canary remains locked behind a fresh read-only live pass on the accepted successor.
  4. Remote CI: required after the sealed exact commit is pushed for this AOI release because its protected-rule set is empty. Authenticated exact-main test.yml/docs.yml observations must pass the offline validator and be recorded in task CAS before the release-tag composite preflight. The publish workflow independently repeats the exact correlation before its first GitHub Release mutation. Historical runs, a tag-only test, or a receipt from another commit/destination do not qualify the containing candidate.

2026-07-19 evidence checkpoint

This checkpoint retains historical local v1 verification evidence. It does not claim required-v2 post-commit review/seal, GitHub Actions acceptance, local bundle or installed-package validation, PyPI publication/readback, live Codex /hooks trust, or downstream installation/execution.

  • Complete WSL pytest collection: all 83 test files were partitioned into mutually exclusive cache-disabled shards; 1,312 passed and 28 were platform-skipped, with zero failures or errors. The large test_cli.py surface was separately proven complete by collecting and running all 12 test classes (161 cases).
  • Windows runtime coverage: the CI-equivalent unittest discover suite ran 1,102 tests with 28 platform skips and zero failures/errors. The final provenance/hook/workflow pytest focus passed 32 tests with 6 POSIX-only skips and 5 subtests; the host-native onboarding file passed 42 tests with 4 skips and 22 subtests. This focused pytest evidence closes the free-function gap in unittest discover. At that checkpoint a pushed GitHub matrix was the planned acceptance authority. The later whole-repo local-only interpretation was superseded; the final candidate requires both a fresh complete local collection and exact-final-SHA GitHub acceptance.
  • Static/review gates: native and emulated-win32 mypy each passed all 74 published source files after the shared agent-identity follow-up; compileall and diff checks passed. Exact commit 6e7e1a32156828f11b644573112efc56b1ec0ecc was explicitly rejected rather than promoted after independent review found that review_integrity.py had been omitted from the shared identity contract. The corrected latest-byte focus passed 217 tests with 1 Windows-only skip and 101 subtests on Windows, and all 218 tests on WSL. Two independent final whole-diff reviews reported P0/P1/P2 = 0. At that checkpoint, the next committed bytes still required an exact review. The final selective-policy candidate additionally requires a pushed exact-final-SHA GitHub matrix after seal.
  • Rejected promotion attempts remain evidence, not acceptance: the GitHub test workflow for 6e7e1a32156828f11b644573112efc56b1ec0ecc failed because tests/test_commands_offboard.py read the repository-local aoi.toml, which is intentionally ignored and absent from a clean checkout. The successor candidate at that checkpoint built the fixture with the packaged default_config_text() contract instead; the three directly affected test modules pass on Windows and WSL with the ignored root config removed. Exact review of 888fd2969dc843b883c0faadbd2d9147879bc865 also rejected its pre-commit integrity seal and found two remaining malformed top-level collection exceptions. Its successor returned deterministic array errors for those verification and incident inputs. That historical promotion attempt still required a fresh post-commit snapshot, independent review, seal, and profile-selected final environment evidence.

  • O1: semantic event, object, and persistence acceptance coverage is in tests/test_semantic_events.py, tests/test_semantic_objects.py, and tests/test_semantic_persistence.py.

  • O2: byte-preserving migration and rollback coverage is in tests/test_semantic_migration.py.
  • O3: dispatch integrity and startup/hook receipt coverage is in tests/test_packet_integrity.py, tests/test_codex_hook_receipts_v2.py, and tests/test_codex_hook_v2.py.
  • O4/O5: permit, cohort, and manual-wave contracts are exercised through the semantic-object and packet-integrity focused coverage. Their receipts do not assert a transport launch.
  • O6: adapter contract, tool-path, install-provenance, and hook-receipt focused coverage is in tests/test_codex_adapter_contracts.py, tests/test_codex_tool_paths.py, tests/test_codex_install_provenance.py, and tests/test_codex_hook_receipts_v2.py. The local codex-cli 0.144.0 canary proved live PreToolUse synchronous denial for Bash and that the denied command did not execute. This is not proof of complete tool-handler coverage, a collaboration pre-spawn gate, runtime trust beyond that canary, or a user trust decision; spawn remains arm plus SubagentStart governed. Any internal PreToolUse fault is fail-closed deny; non-PreToolUse lifecycle adapters remain fail-open.
  • Local install proof: tests/test_local_install_proof.py and the v2 provenance/onboarding coverage exercise the separate reviewed_local_install_bundle contract. Its proof_scope=exact_local_wheel_install_only binds caller-approved bundle bytes, external store, clean source, inventory/rehearsal, exact wheel, PEP 610 archive evidence, installed RECORD, runtime bytes, and all four shipped console scripts including the optional aoi-codex-bridge. The local schema-v2 receipt separately binds and rechecks the Bridge launcher, generated script when present, and codex_transport_cli.py module. It is not a release or promotion, and a manual reviewer is only a cooperative assertion. The clean source is review context, not an independently attested source-to-wheel derivation or builder/test execution receipt.
  • O7: exact artifact, release CLI/runtime, inventory, local rehearsal, and manifest contract coverage is in tests/test_release_*.py. PyPI attestation evidence is presence-only; it is not an installed-byte or publication claim.
  • O8 v2 implementation candidate; promotion gates remain: the historical v1 integrity coverage remains context, but it is not acceptance evidence for required_v2. Exact post-commit independent review and seal, profile-selected final environment evidence, local bundle, and installed-package validation are pending. No promotion, release, or downstream installation/execution result is claimed. A manual reviewer identity is a cooperative assertion, and an unavailable MCP registry is explicitly uncovered rather than inferred as trusted. The final shared agent-identity follow-up makes new integrity producer/reviewer, packet, hook receipt, cohort, incident, skill-release, and Steward-brief records use the same bounded canonical /root/... identities as dispatch and routing. Current writers validate identity and all other caller-controlled fields before immutable CAS, artifact, receipt, mapping, or snapshot publication. Existing v1 receipts, review records, packets, and Steward briefs retain their original read and byte-exact replay semantics; legacy values cannot be elevated into new authority without replacement by a canonical identity. Malformed JSON collection, enum, identity, and replay inputs now return deterministic integrity errors instead of raw Python type exceptions. Persisted task state is rejected earlier by load_task and load_all_tasks; direct in-memory gate/projection helpers are also guarded. The exact review of commit 63c2bab rejected promotion because close, cancel, doctor, and status-derived consumers still iterated malformed verification or subagent_incidents values after their pure readers had diagnosed them. The follow-up keeps the canonical reader error, skips unsafe semantic derivation, and makes status summary/projection fail closed with a HarnessError. The focused integrity/dispatch/routing suites passed on Windows and WSL; the follow-up regression and final full matrix remain pending until the final candidate is committed. The old local-only route was superseded; the final matrix includes local Windows/fresh-ext4 WSL and pushed exact-final-SHA GitHub Linux/Windows plus docs gates. The required-v2 integrity work is a new candidate and must independently clear the pending post-commit review/seal, profile-selected environment, local bundle, and installed-package gates. Because adoption is one-way, it first checks that the current task owner, reserving claim owners, and completed mutation agents use this bounded principal syntax; canonical Codex paths and email-style operator IDs are accepted, while display names containing spaces must be replaced by a stable slug or email identity before adoption. The v1-to-v2 migration candidate now stores the immutable v1 prefix in the task-local CAS and persists only a compact native v2 tail. The migration source is bounded by the actual 16 MiB managed-state limit, while the logical 6,144-record cap remains independent; the resulting semantic delta is explicitly bounded below 1 MiB. A runtime-valid source larger than 1 MiB has passed focused upgrade, CAS materialization, and doctor tests. This remains a local implementation candidate until independent review and the final full suites pass.
  • O9 Transport Bridge is now a v0.4 release blocker: the user expanded the v0.4 scope on 2026-07-19. The prior final-promotion boundary was retargeted and its canonical task plan was atomically replaced through the AOI CLI and re-approved at plan SHA-256 f26273ea0c5153fe90e8bd94f63c7441bcff2a79bad44b67f0e46dc0f134b16d; no older PASS, review, or seal applies to the new bytes. The installed Desktop CLI 0.144.0 was found stale. The current stable upstream release is 0.145.0; a separate Windows App Server executable was fetched from the official release asset and verified as SHA-256 5163c75ed88d460b35b03c8d8f4ef190b3bdd09971d7ac2bd90b48c435f1cf14. The same release's exact CLI generated 273 stable schema files; their canonical sorted manifest digest is 6b8bfa74e475c6c9b46926c46f287f47873d188b13ab3df8db4633602db73262 and the combined v2 schema digest is 6253fd70273c2f33c42d0b6090eac771580c994b3c6eed4277598de08a5e69ec. The later 2026-07-20 checkpoint supersedes this paragraph for implementation status. Permit consumption, semantic persistence, recovery, finite CLI, and materialized Git mutation verification now have local fake-runtime evidence. Both live scratch canaries, exact independent transport review, full suites, packaging/install evidence, final seal, and the subject-selected final environment remain pending. The final AOI candidate has no protected rules, so remote final-SHA CI is required after seal. Source presence or a mock-server test is not live launch evidence.

The implementation order is mandatory. Query/UX work may not create a second state model, and automation may not receive a reusable Chief credential.

Verified starting point

The pre-change local suite collected 740 tests. Four cache-disabled partitions completed with 724 passed and 16 skipped, with no failures. The current Codex runtime supports native parallel agents and exposes SubagentStart, SubagentStop, PreToolUse, and PostToolUse hooks. Those hooks do not provide a provider routing receipt or the actual sandbox/profile configuration.

The baseline has four material gaps:

  • packet routing truth can be recomputed from a later resource configuration;
  • state.json is mutable authority rather than a replayable projection;
  • an external controller cannot progress lifecycle state without a reusable Chief credential; and
  • baseline-freeze does not identify or promote an exact release artifact set.

The initial hardening slice identifies compatibility boundaries without establishing that the remaining v0.4 architecture is already implemented.

Current implementation receipts

The following slices are implemented on the active v0.4 branch as of 2026-07-19. This section is a status receipt, not a relaxation of the later promotion gates.

  • Foundation hardening is limited to shared compatibility boundaries and compact Windows atomic temporary recovery; the later v0.4 stages remain subject to their stated promotion gates.
  • The pure semantic event contract is implemented and independently accepted. Its focused suite passes 16 tests plus 30 adversarial subtests, including canonical hashing, bounded deltas, replay, retry, tamper, legacy raw-snapshot binding, alias rejection, and size/node limits.
  • The opt-in Stage 1 filesystem slice is implemented and independently accepted after an initial review found four P1 defects. New init-task --semantic-v2 tasks publish genesis before projection, replay a missing/behind projection, recover an exact empty-directory or interrupted file publication, reject divergent/residual state, and block all unported legacy mutation paths before cross-file side effects. Exact retries bind all caller-effective genesis fields and require their plan/checkpoint artifacts.
  • Post-fix evidence is 34 semantic persistence/contract tests with 30 subtests, three real process-kill boundaries, and the complete CLI suite at 148 passed, 7 skipped, and 47 subtests passed.
  • The pure Codex dispatch-v6 contract is implemented and independently accepted. It separates the SessionStart startup receipt, Chief registration, compact arm-time resource authority, hook observation, one-arm CAS slot, stored outcome, legacy v5 snapshot, and capacity row. The accepted review ran 55 focused tests plus 37 subtests and 21 adversarial in-memory probes. This is Stage-0 schema evidence only: no filesystem outcome CAS, hook/CLI integration, or provider/profile/sandbox runtime verification is claimed.
  • The task-independent startup-receipt store base was independently accepted after its first review found two P1 defects. First writes now bind the exact current project root, raw aoi.toml SHA-256, and canonical in-root CWD before creating the store. Windows contents use CurrentUser DPAPI while reporting ACL evidence honestly as windows-acl-unverified; POSIX requires current-user ownership and private group/other mode. Canonical sealing, bounded scans, replay/create separation, tamper/link rejection, real 512 KiB envelope expansion, and state-lock/recovery serialization were exercised on native Windows and WSL. The material schema-v2 observation extension was independently accepted after adversarial re-review. It additionally seals the SHA-256 identities of the project .codex/config.toml and managed agent TOMLs observed under that same state lock. This proves the filesystem observation and store only, not that Codex loaded those bytes. Previously published schema-v1 members remain exact-canonical and hash validated historical records, but cannot register or be rewritten as v2 because they lack file observations. A v1 member does not block unrelated v2 creation; reuse of its same session id fails as an explicit schema conflict.
  • The Codex SessionStart subprocess integration is implemented and independently accepted after review found one P1 type-confusion defect. Session, prompt, and stop routing now reject non-string session identifiers without coercion. Only an exact startup source with exact string session and CWD inputs attempts a receipt; timestamps, current root/config bindings, and managed project-file observations are produced locally. Failures preserve normal hook context behind one fixed warning, and requested model/provider/profile/permission/sandbox fields do not become authority. This is subprocess evidence only: live Codex hook delivery/trust remains a separate gate.
  • The Chief-fenced fresh-session registration v2 slice is implemented and independently accepted. A read-only receipt command exposes the exact sealed startup SHA needed for compare-and-register without exposing Chief material. Registration binds the persisted startup receipt, the event's immutable applied snapshot, exact receipt/plan/config/profile-manifest hashes, task plan/worktree, and the registering Chief session/epoch. Every reviewed after-image must occur in the sealed startup byte observation, and the event must remain effective-current with exact live after-bytes when registration occurs. The receipt therefore proves byte-state equivalence, not that startup followed the selected event when two events produce identical bytes. This avoids treating independent Windows/WSL wall clocks as causal authority. Same-epoch Chief renewal replays byte-identically; takeover, non-LIFO or non-monotonic history, corrupt unrelated registrations, applicability/selection tamper, and publication ambiguity fail closed. The strongest result remains registered_byte_state_equivalent_only, while config loading, provider route, runtime profile, and sandbox stay unavailable. Current-byte Windows and WSL focused suites each passed 32 tests; the reviewer found no remaining reproducible P0-P2. The complete local suite then passed 840 tests with 17 platform skips and 212 subtests.

The independently reviewed semantic-v2 slice extends Stage 1 with internal expected-head compare-and-append support for typed lifecycle writers, event-before-projection recovery, exact command retry, byte-preserving legacy migration, pre-first-transition migration rollback, semantic close, and doctor/close receipt checks. The store API is not a public generic full-state mutation command: ordinary legacy mutation handlers still fail closed for v2 tasks until their typed event-first ports exist. The focused semantic suites pass 62 tests and 46 subtests, the complete CLI suite passes 148 tests and 48 subtests with 7 platform skips, and the final adversarial review found no reproducible P0-P2.

The deterministic permit/cohort manual-runner slice is implemented. A pure projection module defines the one-way permit namespace and the exact cohort.advance consumption receipt. Schema-v2 detached transactions bind one sealed cohort, one exact deterministic wave selection, all and only its routing authority objects and slots, one semantic binding, and one planned event. The runtime re-derives that exact after-image from the authenticated ledger at prepare, issuance, consumption, retry, inspection, and recovery boundaries. Chief issuance uses a separate immutable permit-issuances-v2 store while global permit, consumption, replay, binding, event, transaction, and issuance identities remain unique across v1 and v2. The v1 transaction bytes, marker bytes, marker digest, and permit-issuances-v1 path have permanent golden vectors.

The manual CLI now supports cohort-round-preview, canonical detached cohort-round-prepare, permit-issue, no-Chief permit-consume, and event-derived cohort-show. Preview/prepare/show do not launch or cancel a transport; their receipts explicitly keep transport_launch_claimed=false and launch_actor=unavailable. A reviewer-reproduced request/permit wave mismatch was fixed to fail closed. Recovery tests cover object-only state, reserved bindings after expiry, committed-event projection repair, marker tamper, missing objects, unexpected store residue, exact retry, and cross-version replay collision in both issuance orders. The combined O4/O5 focused suite passes 170 tests with 1 platform skip and 2 adversarial subtests.

The focused evidence checkpoint above supersedes the older pending-slice note. Remaining promotion gates are intentionally unchanged.

Non-negotiable evidence boundaries

  1. A hook-observed model slug is not a provider routing receipt.
  2. Requested profile/model/sandbox, hook-observed fields, and independently verified runtime facts are separate fields.
  3. SubagentStart is observation after creation. A response with continue=false does not establish containment.
  4. PreToolUse can deny supported cooperative tool paths. It is not an OS sandbox and does not cover every built-in action or sub-agent launch path.
  5. Local hash chaining is cooperative tamper evidence, not an external append-only witness.
  6. A planned/armed cohort is not running until starts are observed.
  7. A baseline is not a release. Only a promoted manifest names a consumable release.
  8. Process-kill recovery is not power-loss durability, especially on Windows where Python cannot portably fsync a parent directory.
  9. A registration's Chief record hash is an opaque command-time attestation. Same-epoch renewal changes the current Chief record, so permanent historical-exact reconstruction requires a future append-only Chief attestation ledger; current state proves the sealed session/epoch/timeline, not the old secret-bearing record preimage.
  10. A startup byte observation proves two identical bounded reads plus stable descriptor/path metadata under the cooperative AOI lock. It does not prove Codex loaded those bytes, it is not an OS-atomic snapshot against a hostile same-account writer, and byte-identical events cannot be distinguished by filesystem evidence alone.
  11. App Server thread/start has no client idempotency key in the pinned protocol. A connection loss after request send but before a durable response is launch_unknown, not a safe retry and not exactly-once evidence.
  12. item/completed and turn/completed are codex_runtime_observed. They do not prove an AOI task completion boundary or a verified source mutation. Only exact before/after Git snapshots, current claim coverage, and source/tree bindings can elevate a mutation.
  13. The bridge receives one exact launch/transition permit. It never receives, reads, or persists a reusable Chief credential.

Outcome O1 — semantic commit v2 is the single task authority

New opt-in v2 tasks use an immutable event ledger as authority. state.json is only the latest projection. An event contains:

  • schema version, sequence, event type, command id, and recorded time;
  • previous event SHA-256;
  • deterministic payload and payload SHA-256;
  • base and result projection SHA-256;
  • a non-secret authority reference; and
  • the canonical event SHA-256.

The first event is a genesis snapshot. Later events carry deterministic JSON operations. Event publication happens before projection publication. A writer uses expected-head compare-and-append; an exact retry that already produced the same result is idempotent. A reader may replay a valid ledger tail in memory when projection publication was interrupted. The next writer republishes the projection before adding new semantics.

Acceptance:

  • complete replay produces the canonical projection byte-equivalent domain state and matching head;
  • corrupt filenames, sequence gaps, hash mismatches, invalid operations, divergent projections, duplicate command ids with different results, and multiple valid heads fail closed;
  • process termination at each append/fsync/replace boundary recovers at most one semantic head;
  • v2 mutation cannot bypass the ledger through the legacy write_task path;
  • doctor and close validate the ledger, projection, and migration receipt; and
  • events are bounded records rather than repeated full-state snapshots after genesis.

Outcome O2 — legacy migration preserves history without inventing it

Migration requires task quiescence: no live arms, running packets/jobs, open state writer, or unresolved temporary residue. The exact legacy state.json bytes are copied to an immutable snapshot, and a legacy_genesis event binds its SHA-256. A migration receipt binds input bytes, output head, tool version, configuration, time, and the explicit operator authority.

Acceptance:

  • migration is idempotent and never rewrites the legacy snapshot;
  • legacy routing claims are preserved as legacy claims, never silently upgraded to verified runtime facts;
  • corrupt input, a live v5 arm, an unknown hook event, or a non-quiescent task blocks migration without semantic mutation;
  • the only pre-cutover rollback is a compare-and-swap restoration to the named snapshot; once a v2 event is accepted, rollback means read-only v2 or a new compensating event, never deletion of history; and
  • v1 readers remain available for unmigrated tasks while v2 writers reject legacy state.

Outcome O3 — dispatch v6 binds immutable routing authority

Packet schema v6 is distinct from hook protocol v6. A v6 arm validates the exact resource-config receipt bytes once, then snapshots a compact reviewed plan and digest preimage: event/receipt identity, source SHA-256, resolved role-to-profile mapping, requested model/reasoning, resource envelope, applicability, restart requirement, apply time, fresh-session registration, and packet/plan authority. Backup bytes are not copied into every arm. Later config changes cannot change the arm's historical verdict.

Fresh-session evidence is split into two independently hashed objects. The SessionStart hook may create a startup receipt only for source=startup; resume, clear, and compact are not fresh. A later Chief registration binds that receipt to the current resource event, aoi.toml, .codex/config.toml, and post-apply profile-file manifest. The schema-v2 receipt records the exact managed file identities observed during SessionStart. Registration accepts an event only when every planned after-image is present in that sealed observation and the event remains effective-current with the same live bytes. The wall-clock timestamp is ordering metadata, not proof that one host/process caused another. Its strongest statement is registered_byte_state_equivalent_only; config_loaded_verified remains unavailable.

The resource lifecycle uses one strict replay shared by writers, readers, and doctor: timezone-aware transition instants are unique, applies follow append order, and each rollback pops the current stack top. Bounded cross-process clock jitter is serialized one microsecond after the latest causal transition; larger rollback fails before file mutation. Thus A apply, byte-changing B apply, startup under B, then rollback B cannot register the session to A because A's planned after-images were not observed. If two events produce identical managed bytes, startup evidence cannot and does not distinguish their event ids; the registration explicitly records byte-state equivalence while the current event/plan/Chief authority is selected at registration. It never claims that startup occurred after that exact event. Doctor, close, and later registration attempts revalidate the strict history, sealed startup store, receipt/event applicability and selection, rollback-stable registration snapshots, and current live after-bytes.

Routing output uses explicit fields and verdicts:

  • requested_*: arm-time requested authority;
  • active_model_slug_observed: hook observation, when available;
  • observed_model_slug_match: only the active slug comparison (match, mismatch, or unavailable), never a full config/provider binding;
  • config_loaded_verified: unavailable without an independent load receipt;
  • provider_route_verified: unavailable unless an independent provider receipt exists;
  • runtime_profile_verified: unavailable unless independently observed;
  • runtime_sandbox_profile_verified: unavailable unless independently observed; and
  • verdict: observed_model_slug_match, observed_model_slug_mismatch, actual_model_unobserved, legacy_actual_model_unobserved, or manual_unverified.

All terminal claims for one arm share one deterministic outcome_slot_sha256; the persistence layer must publish that slot with an atomic compare-and-swap. A pure schema supplies the collision identity but does not itself make a write one-shot. Reuse of one raw observation across two packet authorities is rejected when stored outcomes are assembled.

Ready v5 packets may be migrated before arm. Armed or dispatched v5 packets must drain, expire, or terminalize under v5; they are never rewritten in place. After cutover, v5 is replay-only and cannot create new mutation.

Acceptance:

  • config A arm followed by config B apply, rollback, wrong-profile same-model, not-applicable config, or restart-required config leaves the A verdict unchanged;
  • no observation is never converted into an observed match;
  • capacity datasets consume stored immutable verdicts, not a new derivation from current config;
  • capacity preserves every terminal row, while only explicit accepted/rejected technical outcomes with a stored slug match enter the model-quality denominator;
  • same-type parallel execution is documented as arm A, observe A, arm B while A runs; simultaneous pre-arm remains unsupported until the transport returns a packet nonce; and
  • doctor reports every live packet by packet/dispatch schema and blocks release while an active v5 arm remains.

Outcome O4 — one-shot permits enable automation without Chief leakage

A technical agent emits a content-addressed decision. The Chief may authorize one exact lifecycle transition using a permit bound to:

  • task and expected semantic head;
  • decision SHA-256 and permitted action;
  • exact target identifiers and parameters;
  • expiry and random nonce;
  • Chief session/epoch authority; and
  • permit SHA-256.

The controller/Registrar receives only the permit. It can atomically consume that exact transition; it cannot retarget, edit technical payload, mint a new permit, or obtain the Chief credential.

Acceptance:

  • replay, expiry, head drift, decision mutation, target mutation, and parameter widening all fail with zero semantic transition;
  • concurrent consumers produce exactly one accepted event;
  • the controller process environment and persisted receipt contain no reusable Chief token or credential path; and
  • a failed transition records no false success and leaves the permit either unconsumed or explicitly terminal according to the failure class.

Outcome O5 — cohorts describe deterministic waves without overstating launch

A cohort binds ordered packet references, dependency DAG, waves, bounded concurrency, transport slots, failure/cancel policy, and expected v6 authority. Its projection distinguishes planned, armed, start_observed, terminal, and cancelled. Completion order cannot change the deterministic next-wave decision.

Acceptance:

  • cycles, unknown packets, duplicate slots, incompatible schema versions, and over-capacity waves are rejected;
  • no packet is running without an observed start;
  • identical terminal outcomes in different arrival orders yield the same cohort projection; and
  • cohort machinery does not claim that AOI itself launched a transport unless a transport-specific launcher and receipt are implemented.

Outcome O6 — the Codex adapter produces bounded, honest receipts

  • Install absolute resolved hook executables and bind package version plus installed-manifest digest. An update changes the hook definition and requires a new trust decision.
  • Wire SubagentStop and correlate agent id, stop time, transcript path, and last assistant message. A stop receipt improves accounting but does not prove no_material_work without trace evidence.
  • Use PreToolUse as a cooperative claim gate only for supported, parseable apply-patch/shell/MCP paths. Unsupported or ambiguous paths are reported as uncovered, never described as contained.
  • Use PostToolUse for mutation receipts, not prevention or rollback.
  • Record active model slug and permission mode exactly as observations. Actual sandbox/profile remain unavailable absent a stronger platform receipt.

The already-landed Claude compatibility hardening remains covered by regression tests, but v0.4 adds no new Claude-specific hook, onboarding, provenance, or parity work. Shared schemas must continue to read existing Claude/v5 evidence without upgrading its strength.

Outcome O7 — releases are exact promoted manifests

release-manifest-v1.json is generated from the exact tested artifact bytes before publication. It binds tag, commit/tree, package version, build environment, workflow/run identity, artifact names/sizes/SHA-256, producer packets/results, interface and schema versions, dependency release SHAs, verification receipts, SBOM/attestation locations, and manifest SHA-256.

Promotion is a separate semantic event and receipt. Downstream consumers bind the promoted manifest SHA, installed metadata, console executable, and hook protocol. Rollback promotes a new compensating release or prior manifest; it does not rewrite publication history.

Acceptance:

  • artifact replacement, tag/tree mismatch, missing Windows/Linux matrix gate, rebuild-after-test, PyPI readback mismatch, unpromoted dependency, and wrong installed executable all block promotion;
  • the publish job uploads only bytes already named and verified by the manifest; and
  • a clean second build either reproduces exact bytes or records a scoped, reviewed non-reproducibility explanation before promotion.

The release toolchain is itself an input to this evidence: the canonical requirements/release-tools.lock is hash-pinned, downloaded into a verified wheelhouse, and installed offline with --require-hashes. The producer receipt records that lock digest and the exact name, version, and artifact hash of all eleven locked distributions. Build the wheel/sdist with that isolated toolchain, install the exact inventory-selected wheel, then run the O7 tests with -I; do not let an ambient tool or rebuilt wheel stand in for the tested bytes. The workflow/run, PyPI, tag, and GitHub Release portions remain required future evidence, not facts asserted by this checkpoint.

Separate reviewed local-install route

reviewed_local_install_bundle is deliberately not a shortcut release record. It has proof_scope=exact_local_wheel_install_only and binds an exact local wheel installation to a caller-supplied expected bundle SHA and canonical external store. It additionally cross-checks clean commit/tree and the full tracked source manifest, exact inventory and rehearsal, wheel path/SHA, PEP 610 direct_url archive path/SHA, installed RECORD, and runtime bytes. codex-init accepts it only through the complete local proof pair; it rejects half-pairs, both local and public pairs, and no pair before mutation. A manual reviewer is cooperative, not authenticated; the expected bundle SHA is the caller trust anchor and names the canonical bundle_sha256 field, not the raw JSON file hash. The clean source identity is review context: this route does not independently attest source-to-wheel derivation, the builder toolchain, or execution of the caller-supplied test summary.

This local-install contract itself makes no tag, GitHub Release, PyPI, or live Codex /hooks trust claim. That evidence boundary does not prohibit the separate final-SHA release route; live-client and remote publication evidence must each be independently recorded.

Outcome O8 — integrity v2 and adoption surfaces use the stable projection

After O1–O7 are stable:

  • close/doctor capture NUL-safe Git mutation snapshots, including untracked, rename, case-only, and deletion states, and compare them with live claims;
  • independent reviewer identity must differ from every producer identity;
  • a finding-to-fix chain binds finding, change/result, and independent verification;
  • bare aoi status becomes concise human output, while --json remains the machine contract and --since reads semantic cursors;
  • mini defaults reduce boilerplate without weakening explicit evidence;
  • quickstart pins one exact version and demonstrates install, one mini task, and offboarding; and
  • offboarding removes only AOI-owned hook definitions, leaves state as an inert archive by default, and never silently deletes project evidence.

New integrity-adopt creates required_v2 with an exact baseline head. required_v1 is historical and frozen: its validator, candidate-only seal semantics, and sealed contracts remain byte-compatible and read-only. Any valid unsealed v1 contract, including a valid empty record set, may make the explicit integrity-upgrade-v2 transition, supplying the expected canonical v1-contract SHA. Its receipt stores the canonical v1 CAS artifact and carries every v1 finding obligation forward; the original v1 reader continues to validate it. No task may silently reinterpret v1 history.

required_v2 uses one ordered record ledger. integrity_seq is continuous and every record SHA is unique. A snapshot content SHA represents observed Git bytes and may repeat; its record SHA is the unique attempt identity. All graph edges therefore bind record SHA: review uses --snapshot-record-sha256, fix uses --post-fix-snapshot-record-sha256, and verification uses --verification-snapshot-record-sha256.

The operating order is deliberate. While task claims are live, capture a candidate attempt and review it. Each review with findings extends the graph; fixes and PASS verification may require further post-fix attempts even where Git bytes are unchanged. The terminal snapshot must have one final clean review whose exact basis lists, for every prior finding, the current PASS reverification of that finding's latest fix on that same snapshot attempt. Seal binds that terminal snapshot-record SHA, clean-review SHA, and exact live claim scope; a fresh close observation must match. Retries are exact semantic replays, not fresh record or artifact publication. Reviewer IDs remain cooperative assertions, not authenticated independence or an OS access-control boundary.

Live dogfooding findings (P1). The v1 candidate → post-fix flow reached a real dead-end: identical post-fix Git bytes could not be captured again because v1 treated content snapshot_sha256 as globally unique. The prior v1 validator also used a leaked loop variable when checking a verification snapshot, so its result could depend on the tail snapshot rather than the verification's bound record. v2 record identity and integrity_seq address the first issue. The v1 reader remains frozen, including that historical acceptance behavior; migration must not silently reinterpret it. Neither finding is evidence of a completed promotion.

Outcome O9 — the optional Codex Transport Bridge launches one governed turn

The v0.4 MVP is a finite stdio controller, not a daemon. Under one exclusive controller lock it executes one bounded exact-binary version probe, then starts one local Codex App Server for one packet, one thread, and one turn. AOI core has no new runtime dependency; the transport entry point is optional and uses the Python standard library plus an externally installed, explicitly pinned Codex executable.

The immutable launch intent and one-shot permit bind task, packet, optional cohort/wave, expected semantic head, permit SHA, prompt SHA, absolute cwd, requested model/reasoning, sandbox/approval, executable path/hash/version, and the generated stable JSON-schema bundle digest. Runtime receipts bind request and notification identities, thread id, turn id, item ids, terminal state, and the content-addressed event transcript. Version, executable, schema, permit, head, prompt, cwd, or target drift fails before the runtime-process boundary; the version probe occurs after that durable boundary and before App Server Popen.

The Bridge launch first requires a canonical packet arm. For a migrated semantic-v2 task, packet-arm-prepare emits standalone transaction schema v3. Chief issuance applies the same packet-contract, open-task, approved-plan, topology, resource-envelope, and skill-canary authority gate as legacy packet-arm; no-Chief consumption then commits routing authority, permit projection, and the canonical packet's ready -> armed transition in one semantic CAS. The transaction must include all three delta roots and cannot be substituted by the separate cohort schema v2 contract.

Launch-permit consumption is then the Bridge packet-ownership transaction. Under the same state lock and semantic CAS, the active arm becomes transport_reserved, the packet becomes bridge-owned dispatched, and a sealed object binds the full packet/arm/launch/intent/permit/reservation/routing tuple. It uses dispatch generation v2 so an older v1 writer or a partial marker downgrade fails closed. No SubagentStart, agent id, thread id, or turn id is invented.

One Chief-created per-launch OS lock covers reserve/load through terminal publication. It proves cooperative at-most-one process in one platform lock domain. The durable process_start_pending callback revalidates the earlier permit/arm expiry, exact live ownership/generation, fresh namespace, confidentiality storage, and the exact Git/tree/status/full-claim endpoint for both readOnly and workspaceWrite. It authorizes both the bounded version probe and App Server Popen; no child executes before it, and a crash after it reconciles without restart.

The ordered milestone/state machine is:

reserved -> initialize -> model/list -> thread_started -> turn_started -> completed|failed|interrupted

Initialize and model/list retain semantic state reserved. The catalog step is read-only and must prove one visible exact model/effort before thread/start; catalog loss or rejection is a known pre-thread failed outcome. Process, thread-start, or turn-start ambiguity retains the stronger unknown semantics below.

launch_unknown is a separate terminal reconciliation state. It is mandatory when thread/start may have been sent but no durable correlated response exists; automatic resend is forbidden. Duplicate events are idempotent only when their canonical bytes and correlation identity match. Wrong thread/turn/item ids, unsupported item/notification types, malformed JSONL, schema drift, and out-of-order terminal evidence fail closed. turn/interrupt is allowed only for the exact persisted thread/turn pair. A known thread/turn whose stream becomes unobservable uses runtime_unknown; it is not mislabeled as a known failure.

Acceptance is deliberately split into four evidence classes:

  1. Contract tests: deterministic schema/hash vectors, permit replay/expiry and head drift, process/request/response crash boundaries, duplicate and wrong-correlation events, interrupt, unsupported item, and receipt publication recovery against a scripted fake App Server.
  2. Live App Server canary: exact pinned executable/schema, first in a read-only scratch repository and then in a disposable writable scratch repository. This proves only the observed local transport lifecycle.
  3. Git mutation verification: AOI before/after snapshots, exact endpoint claim coverage, source/tree binding, and a separately recorded elevation from codex_runtime_observed to verified_mutation. Endpoint coverage is not a claim of continuously held authority without a claim-history receipt.
  4. Promotion environment: exact final-SHA GitHub Linux/Windows test and main-only docs gates are available when no protected rule is exposed, or when every exposed subject is allowed at its exact home repository. Local fresh-ext4 WSL is separate required WSL evidence. This AOI release has no protected rules and requires those remote gates after exact local test/docs/package/review/seal evidence. Earlier runs remain historical.

The MVP fixes approvalPolicy=never; a server request for approval, user input, or elicitation interrupts and fails closed. It accepts only readOnly or one explicitly bounded workspaceWrite root, never dangerFullAccess. The child environment removes all reusable AOI Chief authority variables before process creation. Under local_files, an exact isolated Codex-home inventory plus closed config/managed-policy hashes is process-journal evidence; strict process argv and thread config disable web search, apps, remote plugins, multi-agent loading, and remote control while the turn sandbox also sets networkAccess=false. Raw prompt, assistant text, command output, and secrets stay out of the semantic ledger. Exact correlated response bytes rejected by schema or policy are retained only in task-local non-Git CAS and represented in the ledger by verified digest/size.

Token budgets, thread/fork lineage, detached review, approval brokering, multi-wave autonomous cohorts, WebSocket/daemon transport, and remote EDA launch remain later gated v0.4 slices. None may block proving the single-turn MVP, and the first writable canary must not target ARISE or any RTL/EDA workload.

Implementation sequence and promotion gates

  1. Foundation hardening — compact Windows atomic temporaries with v1 recovery and exact adversarial tests.
  2. Stage 0 contracts — pure event, routing, permit, cohort, and release schemas with canonical hash vectors and tamper tests; no runtime mutation.
  3. Semantic commit v2 — opt-in new tasks, replay/projection/recovery, doctor/close checks, then explicit legacy migrator.
  4. Dispatch v6 — immutable arm authority, v5 drain inventory, adapter observations, capacity export migration.
  5. Permits and cohorts — deterministic manual round runner before any daemon or autonomous controller.
  6. Release manifests — observe-only generation, then promotion and one exact downstream dependency enforcement.
  7. Codex adapter provenance and mutation receipts — absolute hook definitions, stop/trace receipts, cooperative claim gates, fresh-session canaries.
  8. Integrity and adoption — mutation/reviewer/fix-chain gates, status, mini defaults, quickstart, version pins, and offboard.
  9. Codex Transport Bridge MVP — pin stable executable/schema, prove pure contracts and stdio crash semantics, then read-only and disposable writable live canaries plus exact Git mutation elevation.
  10. Selective local-files confidentiality — strict protected path/tree parsing, destination-aware Git preflight, subject manifests, local state/CAS enforcement, subject-aware doctor/promotion gates, exact one-shot export permits, and negative publication tests.
  11. Release rehearsal and exact remote gate — full local fresh-ext4-WSL/Windows matrix, wheel/sdist installed smoke, independent rebuild, encrypted local manifest/bundle, exact pre-push receipt, then exact-main-push GitHub Linux/Windows test plus main-only docs. A tag test is supplementary; the publication workflow independently verifies the required main-push observations before its first Release mutation.
  12. Downstream installation boundary — no installation or execution claim until the exact candidate has an independent post-commit review and seal, profile-required final environment evidence, immutable GitHub/PyPI readback, a Chief-created content-addressed promotion bundle, and installed-package evidence.

No stage is promoted by source presence alone. Its tests, doctor checks, migration receipts, and independent review must all pass.

Falsification matrix

Contract Required adversarial cases
Semantic ledger truncated event, renamed event, sequence gap, wrong previous hash, payload tamper, projection behind/ahead, kill before/after append and replace, exact retry
Legacy migration clean, live arm, expired arm, running job, corrupt snapshot, unknown event, repeated migration, pre-cutover rollback
Dispatch v6 config after arm, rollback, wrong profile/same model, not applicable, restart required, missing observed model, old hook after cutover
Permit replay, expiry, expected-head race, decision/target/parameter mutation, concurrent consume, credential-leak scan
Cohort cycle, duplicate slot, capacity overflow, unobserved start, out-of-order completion, cancellation race
Codex adapter executable/manifest drift, unsupported or ambiguous tool path, missing model, duplicate/replayed start, missing or mismatched stop receipt, PostToolUse mutation ambiguity
Codex Transport Bridge permit replay/expiry/head drift, reservation binding-to-event crash crossing expiry with exact/absent/wrong witness, executable/version/schema drift, two-run and two-process lock contention, same-arm different-launch CAS, lock missing/link/hardlink/sentinel replacement, arm/permit expiry crossing version probe, packet status/contract/ownership/generation drift before pending, generic SubagentStart/cancel/re-dispatch conflict, process start before/after, thread request/response ambiguity, turn start before/after, mid-stream loss, terminal publication crash, duplicate/wrong-correlation event, unsupported item, interrupt race, issue-to-run and Git after-image/claim mismatch
Local-files confidentiality permissive config mutation, empty-rule non-blocking route, untracked copy then origin deletion, missing protected tree, external push/rewrite/LFS endpoint, package/archive member copy or path match, transformed non-match boundary, every Actions artifact gate, PyPI container/receipt mismatch, historical config evolution, unreceipted descendant tip, sync/network artifact root, wrong export destination/file/purpose, expiry, task-state drift, duplicate consume, response loss, credential leak, malformed export receipt
Release artifact/tag/tree/PyPI mismatch, missing matrix receipt, rebuild substitution, unpromoted dependency, wrong installed console script
Mutation gate untracked, delete, rename, case-only rename, symlink/junction, Bash write, out-of-claim write, same-agent review

Explicit non-goals

  • a same-user or hostile-process security boundary;
  • a claim that hook installation proves runtime trust;
  • handing reusable Chief authority to a daemon, Registrar, or technical agent;
  • fabricating model, sandbox, provider, or containment evidence absent a receipt;
  • in-place reinterpretation of active legacy packets;
  • new Claude-specific adapter or onboarding parity in this implementation;
  • WebSocket transport, a resident daemon, automatic retry from launch_unknown, or reusable Chief authority in the bridge MVP;
  • calling a planned cohort parallel execution without observed overlap; or
  • claiming downstream installation or execution before its evidence boundary.

Decision log

  • The release line is v0.4 because task authority, dispatch schema, release promotion, and migration behavior change materially.
  • Semantic events are authority; a sidecar audit log beside independently writable state would preserve the current split-brain risk.
  • Packet schema v6 and hook protocol v6 are separate contracts even if their numeric versions coincide.
  • Provider route and actual sandbox/profile stay unavailable until the platform exposes stronger receipts.
  • A deterministic manual round runner precedes a daemon because permit and cohort invariants must be proven before unattended lifecycle mutation.
  • The user explicitly moved the finite local Codex App Server transport bridge into v0.4. A one-packet/one-thread/one-turn stdio MVP therefore precedes v0.4 promotion; daemon, WebSocket, and multi-wave autonomy remain separately gated.
  • The user selected destination-aware local_files protection for IC-local work: model context is allowed, home_remote_only paths may reach only their exact home repository, and local_only paths may not be externally published absent an exact one-shot permit. Empty rules leave AOI update, GitHub CI/Release, and PyPI publication enabled. This does not claim provider-side context isolation; offline/self-hosted is a distinct future profile.
  • baseline-freeze remains useful input to a release manifest but is not itself promotion.