From e46d986188d51b693f5b6d86f68a2be09c77937e Mon Sep 17 00:00:00 2001 From: dbarr5 Date: Sun, 27 Sep 2026 17:02:34 -0400 Subject: [PATCH 1/2] docs(release): record interactive chat qualification gates --- docs/releases/2026-09-27.md | 14 +++++ docs/releases/OPERATOR-PACKET-v0.4.0.md | 73 +++++++++++++++++++++++-- docs/releases/README.md | 5 ++ 3 files changed, 88 insertions(+), 4 deletions(-) create mode 100644 docs/releases/2026-09-27.md diff --git a/docs/releases/2026-09-27.md b/docs/releases/2026-09-27.md new file mode 100644 index 0000000..0ff06ce --- /dev/null +++ b/docs/releases/2026-09-27.md @@ -0,0 +1,14 @@ +# 2026-09-27 — v0.4.0 interactive chat qualification update + +This is a candidate and incident record, not a v0.4.0 release announcement. +At 20:58 UTC, npm `aether-agents` `latest` was 0.3.2 while the repository +manifest was 0.4.0. An installed 0.3.2 interactive chat from a broad Windows +home directory (`%USERPROFILE%`) was reported to accept a prompt without +answering; a one-shot chat from a small project directory returned an answer. +Reauthentication did not resolve the home-directory symptom. + +The source-candidate [operator packet](OPERATOR-PACKET-v0.4.0.md#2026-09-27-interactive-chat-incident-gate) +records the exact `main` head, merged packed-401 regression coverage, the +merged home-folder discovery and SSE integrity fixes, and the separate +installed-package and live-account gates. No v0.4.0 tag or publication is +established by this entry. diff --git a/docs/releases/OPERATOR-PACKET-v0.4.0.md b/docs/releases/OPERATOR-PACKET-v0.4.0.md index 47a7187..04a87fa 100644 --- a/docs/releases/OPERATOR-PACKET-v0.4.0.md +++ b/docs/releases/OPERATOR-PACKET-v0.4.0.md @@ -16,11 +16,11 @@ before evaluating release readiness. | Source custody | ATS owns the canonical source. The Agent copy must match its recorded upstream source and digest; it is not a separate implementation. | | Required Cloud companion | Cloud #1691 at `13a6ef5857d14d036d7275d123c521a889d804f2`: `/agent/managed`, verified `/identity`, typed ATS profile and additive inventory contract `/1.1`, restacked after Cloud #1687 without replacing its admission/runtime ownership. This client also reads legacy `/1` inventories; local setup requires the verified subject endpoint. | | Local prerequisites | The ATS Python engine and a reachable Agent Browser runtime are separate prerequisites. The npm context dependency is a launcher, not proof that Python memory is installed or verified. | -| Platform evidence | Audited `main` at `c0feb1970986cfaf166504ebe51b882aea608e4f` passed Linux and Windows tests plus Linux and Windows clean-install jobs in [CI 35358929047](https://github.com/AetherAI3/Aether-Agent/actions/runs/35358929047). Native headed Browser/noVNC remains Linux/POSIX-only and still needs its real-host release canary if browser availability is claimed. | -| Archive evidence | The production-package verifier passed on audited `main`; the immutable `v0.4.0` tag archive, checksum and publishing provenance remain pending and must be produced from the final verified tag commit. | -| Hosted checks | Audited `main` is green in [CI 35358929047](https://github.com/AetherAI3/Aether-Agent/actions/runs/35358929047), [CodeQL 35358929027](https://github.com/AetherAI3/Aether-Agent/actions/runs/35358929027) and its later [scheduled run 35601932145](https://github.com/AetherAI3/Aether-Agent/actions/runs/35601932145), plus [release truth 35358929055](https://github.com/AetherAI3/Aether-Agent/actions/runs/35358929055) and its later [scheduled run 35629835836](https://github.com/AetherAI3/Aether-Agent/actions/runs/35629835836). CI includes supply-chain, generated-documentation, production-package, clean-install and PyPI-launcher coverage. The final tag commit must rerun these gates. | +| Platform evidence | `main` at `b037891d361ab295cd1fcba7e7dae00b626ac4fd` passed Linux and Windows tests plus both clean-install jobs in [CI 36350635579](https://github.com/AetherAI3/Aether-Agent/actions/runs/36350635579). Native headed Browser/noVNC remains Linux/POSIX-only and still needs its real-host release canary if browser availability is claimed. | +| Archive evidence | The production-package verifier passed on the exact `main` head in CI; the immutable `v0.4.0` tag archive, checksum and publishing provenance remain pending and must be produced from the final verified tag commit. | +| Hosted checks | Exact `main` head `b037891d361ab295cd1fcba7e7dae00b626ac4fd` passed [CI 36350635579](https://github.com/AetherAI3/Aether-Agent/actions/runs/36350635579), [CodeQL 36350635637](https://github.com/AetherAI3/Aether-Agent/actions/runs/36350635637) and [release truth 36350635471](https://github.com/AetherAI3/Aether-Agent/actions/runs/36350635471). CI includes supply-chain, generated-documentation, production-package, clean-install and PyPI-launcher coverage. The final tag commit must rerun these gates. | | Live service evidence | Deployment of the Cloud adapter, actual web/terminal DM sync, model/UVT execution and broker connectivity are not established by local tests. | -| Publication evidence | No `v0.4.0` tag, GitHub Release, npm/PyPI publish, trusted-publishing provenance or registry dist-tag update is established by this packet. Published `latest` remains a separate registry fact until protected workflows complete. | +| Publication evidence | At the 2026-09-27 21:09 UTC registry observation, npm `aether-agents` `latest` resolved to 0.3.2. No `v0.4.0` tag, GitHub Release, npm/PyPI publish, trusted-publishing provenance or registry dist-tag update is established by this packet. Recheck the registry immediately before any release decision. | | PyPI launcher | Version synchronized with `node packages/sync-version.mjs`; still launches npm `latest` unless explicitly pinned. No Python runtime dependency added. | | License scope | The Agent and bundled ATS adapter are Apache-2.0. The paid ATS engine is a separate prerequisite and is not bundled into the CLI. | | Governance evidence | Qualified legal review of `ATS_ACCEPTABLE_USE_POLICY.md` is not yet recorded. ATS publication remains withheld until that review and the real-account release canaries are attached. | @@ -41,6 +41,71 @@ before evaluating release readiness. 5. Run the existing release-truth and supply-chain gates. Only the existing protected release workflows can establish publication and provenance. +### 2026-09-27 interactive chat incident gate + +This addendum is a source and CI snapshot at 21:14 UTC, not a release +approval. Repository `main` was +[`b037891d361ab295cd1fcba7e7dae00b626ac4fd`](https://github.com/AetherAI3/Aether-Agent/commit/b037891d361ab295cd1fcba7e7dae00b626ac4fd) +with `package.json` at 0.4.0; npm `latest` resolved to 0.3.2 in the 21:09 UTC +registry observation. The +incident class was an interactive `aether` turn started in a broad Windows +home directory (`%USERPROFILE%`) that accepted a prompt without visibly +responding, while one-shot chat from a small project directory returned. +Reauthentication did not resolve the reported home-directory symptom. These +are field observations, not a final-package live-account qualification. + +- [#180](https://github.com/AetherAI3/Aether-Agent/pull/180) is merged into + `main`. Its installed-tarball CI smoke drives the interactive raw-key + path with a synthetic loopback HTTP 401 whose response body never closes, + requiring a visible error and responsive `/exit` within eight seconds. + It ran in Linux and Windows clean-install CI and was added to the protected + npm release workflow. The harness emulates TTY input over pipes; it is not a + headed Windows console or real account test. +- [#182](https://github.com/AetherAI3/Aether-Agent/pull/182) merged at + `b037891d361ab295cd1fcba7e7dae00b626ac4fd`. Its investigation found a + synchronous nested `AGENTS.md` scan before the request, so a broad home + directory could appear to hang while the small project directory worked. + The PR bounds nested discovery and warns when it is incomplete; local tool + authority is refused if nested rules could be missing. Its branch exercised + a built 0.4.0 CLI from the home folder with a synthetic invalid key in about + 1.7 seconds, without a model call. One `readdirSync` operation itself cannot + be preempted by the budget. This fix is in `main`, not npm `latest` at this + snapshot. +- [#181](https://github.com/AetherAI3/Aether-Agent/pull/181) merged at + `67cb640b36841ea923c143ed859ac9df45742a17`. + It rejects an undelimited SSE `done` frame at EOF, so an interrupted turn + remains uncertain instead of appearing successful. It is a separate stream + integrity fix, not the demonstrated pre-request home-folder stall. +- The merged [#169](https://github.com/AetherAI3/Aether-Agent/pull/169) + credential-status diagnostics, [#170](https://github.com/AetherAI3/Aether-Agent/pull/170) + failed-stream termination and [#178](https://github.com/AetherAI3/Aether-Agent/pull/178) + Node TLS diagnostics are source fixes; none establishes that the installed + 0.3.2 binary contains them or that a live account 401 is solved. + +The merged #182 PR head `ab70e07cec9282eb5f0da711d4be557bfcc0ba8b` +passed Linux and Windows tests and clean installs, CodeQL, supply-chain and +PyPI launcher checks in [CI 36350196224](https://github.com/AetherAI3/Aether-Agent/actions/runs/36350196224) +and [CodeQL 36350196297](https://github.com/AetherAI3/Aether-Agent/actions/runs/36350196297). +The exact merged `main` head passed +[CI run 36350635579](https://github.com/AetherAI3/Aether-Agent/actions/runs/36350635579), +[CodeQL run 36350635637](https://github.com/AetherAI3/Aether-Agent/actions/runs/36350635637) +and [release truth 36350635471](https://github.com/AetherAI3/Aether-Agent/actions/runs/36350635471). +The main CI includes Linux and Windows tests and clean installs, +production-package verification, generated-documentation checks, +supply-chain and PyPI launcher checks. The packed interactive 401 smoke ran +in both clean-install jobs. This is exact source and packaged synthetic +evidence, not a real home-directory/account canary. + +Before qualifying a 0.4.0 publication, establish exact-final-head CI, +CodeQL, release truth, the production-package verifier and an +installed-tarball interactive smoke +from a broad Windows home directory. Follow that with a real headed Windows +console and authenticated account canary from the same directory, including +both interactive `aether` and `aether chat "just testing reply 1"`; preserve +the observed response or terminal error and the absence of a stall. A green +synthetic 401 fixture alone cannot satisfy the live account canary. The +existing Cloud/ATS/browser/legal gates in this packet still apply. + ## Product boundary Creating an agent saves a draft. It does not imply activation, UVT reservation, diff --git a/docs/releases/README.md b/docs/releases/README.md index 783d24a..259d0ad 100644 --- a/docs/releases/README.md +++ b/docs/releases/README.md @@ -13,6 +13,11 @@ as prerelease evidence while the registry and tag remain authoritative. ## Index +- [2026-09-27](2026-09-27.md) — **v0.4.0 interactive chat qualification + update** after an installed-package home-directory stall. This is a + candidate incident record, not a publication. The + [operator packet](OPERATOR-PACKET-v0.4.0.md#2026-09-27-interactive-chat-incident-gate) + tracks the exact-head and remaining release gates. - [2026-09-17](2026-09-17.md) — **v0.4.0 source candidate** for shared managed agents and ATS setup. No publication or live-service qualification is established by this entry. Packet: From dbc5eb206354b08e1f4a13ef2772670f6abfc283 Mon Sep 17 00:00:00 2001 From: dbarr5 Date: Sun, 27 Sep 2026 17:22:09 -0400 Subject: [PATCH 2/2] docs(release): preserve frozen packet assertions --- docs/releases/OPERATOR-PACKET-v0.4.0.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/releases/OPERATOR-PACKET-v0.4.0.md b/docs/releases/OPERATOR-PACKET-v0.4.0.md index 04a87fa..f1bad1c 100644 --- a/docs/releases/OPERATOR-PACKET-v0.4.0.md +++ b/docs/releases/OPERATOR-PACKET-v0.4.0.md @@ -17,10 +17,10 @@ before evaluating release readiness. | Required Cloud companion | Cloud #1691 at `13a6ef5857d14d036d7275d123c521a889d804f2`: `/agent/managed`, verified `/identity`, typed ATS profile and additive inventory contract `/1.1`, restacked after Cloud #1687 without replacing its admission/runtime ownership. This client also reads legacy `/1` inventories; local setup requires the verified subject endpoint. | | Local prerequisites | The ATS Python engine and a reachable Agent Browser runtime are separate prerequisites. The npm context dependency is a launcher, not proof that Python memory is installed or verified. | | Platform evidence | `main` at `b037891d361ab295cd1fcba7e7dae00b626ac4fd` passed Linux and Windows tests plus both clean-install jobs in [CI 36350635579](https://github.com/AetherAI3/Aether-Agent/actions/runs/36350635579). Native headed Browser/noVNC remains Linux/POSIX-only and still needs its real-host release canary if browser availability is claimed. | -| Archive evidence | The production-package verifier passed on the exact `main` head in CI; the immutable `v0.4.0` tag archive, checksum and publishing provenance remain pending and must be produced from the final verified tag commit. | -| Hosted checks | Exact `main` head `b037891d361ab295cd1fcba7e7dae00b626ac4fd` passed [CI 36350635579](https://github.com/AetherAI3/Aether-Agent/actions/runs/36350635579), [CodeQL 36350635637](https://github.com/AetherAI3/Aether-Agent/actions/runs/36350635637) and [release truth 36350635471](https://github.com/AetherAI3/Aether-Agent/actions/runs/36350635471). CI includes supply-chain, generated-documentation, production-package, clean-install and PyPI-launcher coverage. The final tag commit must rerun these gates. | +| Archive evidence | The production-package verifier passed on audited `main`; the immutable `v0.4.0` tag archive, checksum and publishing provenance remain pending and must be produced from the final verified tag commit. | +| Hosted checks | Audited `main` is green in [CI 35358929047](https://github.com/AetherAI3/Aether-Agent/actions/runs/35358929047), [CodeQL 35358929027](https://github.com/AetherAI3/Aether-Agent/actions/runs/35358929027) and its later [scheduled run 35601932145](https://github.com/AetherAI3/Aether-Agent/actions/runs/35601932145), plus [release truth 35358929055](https://github.com/AetherAI3/Aether-Agent/actions/runs/35358929055) and its later [scheduled run 35629835836](https://github.com/AetherAI3/Aether-Agent/actions/runs/35629835836). CI includes supply-chain, generated-documentation, production-package, clean-install and PyPI-launcher coverage. The final tag commit must rerun these gates. | | Live service evidence | Deployment of the Cloud adapter, actual web/terminal DM sync, model/UVT execution and broker connectivity are not established by local tests. | -| Publication evidence | At the 2026-09-27 21:09 UTC registry observation, npm `aether-agents` `latest` resolved to 0.3.2. No `v0.4.0` tag, GitHub Release, npm/PyPI publish, trusted-publishing provenance or registry dist-tag update is established by this packet. Recheck the registry immediately before any release decision. | +| Publication evidence | No `v0.4.0` tag, GitHub Release, npm/PyPI publish, trusted-publishing provenance or registry dist-tag update is established by this packet. Published `latest` remains a separate registry fact until protected workflows complete. | | PyPI launcher | Version synchronized with `node packages/sync-version.mjs`; still launches npm `latest` unless explicitly pinned. No Python runtime dependency added. | | License scope | The Agent and bundled ATS adapter are Apache-2.0. The paid ATS engine is a separate prerequisite and is not bundled into the CLI. | | Governance evidence | Qualified legal review of `ATS_ACCEPTABLE_USE_POLICY.md` is not yet recorded. ATS publication remains withheld until that review and the real-account release canaries are attached. |