diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index 1f28e80..8a31029 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -29,7 +29,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: ${{ matrix.python-version }} diff --git a/ARCHITECTURE.md b/ARCHITECTURE.md index 00d28ab..df792b9 100644 --- a/ARCHITECTURE.md +++ b/ARCHITECTURE.md @@ -144,11 +144,10 @@ substitute runtime proof for an installed client version. The dependency-free helpers validate normalized contract bytes, package trees, schemas, lifecycle records, archives, and inventory. The portable test suite -also exercises negative cases. A public release candidate may be published -after its source, inventory, conformance, archive-safety, clean-commit, CI, and -disclosure gates pass. Live client, recovery, and platform evidence remains a -separate gate for final stable promotion and must never be inferred from -prerelease publication. +also exercises negative cases. A stable release may be published after its +source, inventory, conformance, archive-safety, clean-commit, CI, and disclosure +gates pass. Live client, recovery, and platform evidence is reported per +surface and must never be inferred from source validation. Package-level behavior changes increment the package version. Material skill changes increment that skill's version and content hash. A release is built only diff --git a/CHANGELOG.md b/CHANGELOG.md index 3a3c701..8df404a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,107 +1,29 @@ # Changelog All notable changes use Semantic Versioning at the package and individual-skill -levels. +levels. This project publishes stable releases only. -## 3.0.0-rc.5 - Unreleased +## 3.1.0 - 2026-08-08 ### Changed -- Aligned MIT attribution with verified project authorship while retaining - future-contributor attribution. -- Added verified maintainer links, a prerelease-aware release badge, and focused - `agent-instructions` and `context-engineering` discovery topics. -- Reworked Quick Start so the coding agent owns package validation, client - inspection, backups, installation, smoke testing, lifecycle evidence, and - rollback preparation; the user supplies decisions and authorization. -- Kept the published `v3.0.0-rc.4` tag and release artifacts immutable while - preparing these package-content changes for the next candidate. - -## 3.0.0-rc.4 - 2026-07-26 - -### Changed - -- Renamed the project, repository, package identity, schemas, ownership - markers, state paths, fixtures, and documentation to Agent Continuity Stack - (`agent-continuity-stack`). -- Positioned the project explicitly as repository-centered continuity rather - than a runtime memory service, agent orchestrator, or guarantee against all - context loss. -- Added public architecture, handoff, contribution, security, CI, Dependabot, - conduct, issue/PR templates, editor defaults, and local-environment hygiene. -- Prepared the initial public Git repository with pinned GitHub Actions, - inventory-driven archive validation, and staged-secret checks. -- Published the canonical public repository and enabled validation, dependency, - vulnerability-reporting, secret-scanning, and protected-branch controls. -- Separated integrity and disclosure gates for public release candidates from - the live-client, recovery, platform, and contract-review gates required for - final stable promotion. - -## 3.0.0-rc.3 - 2026-07-26 - -### Changed - -- Added a public GitHub identity, explicit installation-policy choices, and a - complete copy-paste model installation prompt to the README. -- Decoupled skill installation from custom-instruction installation. -- Made skills-only with existing instructions preserved the public default. -- Required an explicit choice between preserving instructions, guided - additions, and the complete canonical contract. -- Added operator-profile intake, privacy disclosure, plan-digest approval, and - mode-aware smoke-test requirements to public onboarding. -- Updated plan, receipt, and client-status schemas so skills-only operations - use a null rendered-contract hash and cannot mutate instruction targets. -- Bound packaged skill runtime evidence to exact skill versions and content - hashes. - -## 3.0.0-rc.2 - 2026-07-26 - -### Changed - -- Replaced the unsafe cross-client atomicity claim with independently journaled, - one-client-at-a-time best-effort lifecycle operations. -- Resolved Codex targets through the active `CODEX_HOME` and documented - `AGENTS.override.md` precedence. -- Made Cursor's client-managed plain-text User Rules the global contract - authority; the MDC adapter is project-test-only unless runtime evidence - establishes otherwise. -- Added explicit Codex ownership markers for preserving merges and removals. -- Added explicit `verified`, `installed-unverified`, and `failed` client-status - classifications with semantic consistency checks. -- Bound mutable targets to validated client roots plus relative paths, bound - recovery artifacts to a state root, and added a per-client operation-journal - schema. -- Made referenced backups immutable, restore-by-copy snapshots and added backup - hashes to journals and transaction receipts. -- Began adversarial runtime gating; Codex passed positive and near-miss project - discovery on `0.146.0-alpha.3`. - -## 3.0.0-rc.1 - 2026-07-26 - -### Changed - -- Marked v3 as a release candidate until lifecycle and live-client gates pass. -- Defined canonical source integrity separately from per-install rendered - integrity. -- Required UTF-8/LF normalization and added repository line-ending controls. -- Added machine-readable installation, status, ownership, transaction, and - rollback schemas. -- Added deterministic read-only helpers and protocol-conformance fixtures. -- Expanded project-documentation and project-instruction foundation behavior. -- Added an exact-tested Portable Web Toolkit integration contract. -- Restored Astro + Cloudflare expertise as optional and default-uninstalled. -- Expanded package, metadata, archive, privacy, and catalog validation. -- Corrected portable YAML quoting for `design-agent-capability` metadata. - -### Unchanged boundaries - -- Installation remains model-operated and status-first. -- The package contains no standalone installer application. -- The complete Expert Agent Operating Contract remains canonical. -- Live user-global client configuration is never mutated without explicit - authorization. - -## 3.0.0 - Unreleased final - -Promotion to final 3.0.0 requires all lifecycle and live-client release gates, -an identified clean release commit, and a published archive checksum. +- Promoted the package to the stable `v3.1.0` release line. +- Added explicit first-run personalization questions to the canonical Expert + Agent Operating Contract, while keeping profile values as private inputs. +- Kept installation model-operated, status-first, explicitly authorized, and + best-effort recoverable. +- Removed hard-coded client software versions from the README compatibility + summary so the package version remains the current release indicator. +- Replaced multiple release tracks with one stable publication gate. +- Updated the validation workflow to the current pinned `setup-python` action + and synchronized the release inventory. +- Preserved the Antigravity two-fragment adapter because it is a client loading + requirement, not a release-track split. + +### Validation + +- Stable package, contract, source-tree, and portable conformance checks pass. +- The release archive passes inventory, extraction-safety, checksum, and + extracted-suite validation. +- Client runtime coverage remains reported per client and is not inferred from + source validation. diff --git a/CLIENT_COMPATIBILITY.md b/CLIENT_COMPATIBILITY.md index 844fcb9..e1d66cf 100644 --- a/CLIENT_COMPATIBILITY.md +++ b/CLIENT_COMPATIBILITY.md @@ -1,8 +1,8 @@ # Client compatibility -Release-candidate assumptions checked against first-party documentation on +Compatibility assumptions checked against first-party documentation on 2026-07-26. Reverify discovery and precedence against the installed client -before final release or installation. +before installation or a future package release. ## Shared skill format diff --git a/GLOBAL_CUSTOM_INSTRUCTIONS.md b/GLOBAL_CUSTOM_INSTRUCTIONS.md index 9fc9c44..986499a 100644 --- a/GLOBAL_CUSTOM_INSTRUCTIONS.md +++ b/GLOBAL_CUSTOM_INSTRUCTIONS.md @@ -14,6 +14,26 @@ Prefer the active repository’s existing organization, package metadata, projec Never invent, transfer, or imply ownership. +## First-run personalization + +When the user is installing or explicitly personalizing this contract, ask +questions before making personalization decisions. Ask which clients are in +scope, whether skills are user-global or repository-scoped, which core and +optional skills are wanted, and whether existing instructions should be +preserved, receive individually approved additions, or be supplemented with +the complete contract. + +Ask separately for each relevant operator-profile field: name, email, personal +site, GitHub profile, and PyPI profile. Accept “leave unset” for every field. +Explain that values placed in always-loaded instructions may be sent to the +selected model providers. Never infer identity or ownership from usernames, +Git metadata, environment files, or neighboring repositories. + +If the current user instructions already provide an explicit value, treat that +value as supplied and ask only about unresolved choices or confirmation that is +material to the requested operation. Do not start this intake during ordinary +tasks when installation or personalization is not in scope. + ## Instruction Priority Follow this order: @@ -227,7 +247,7 @@ When software versions materially affect the task: 1. Inspect repository manifests, lockfiles, toolchain files, engine constraints, configuration, CI, deployment files, and recorded verified resources. 2. Check authoritative first-party documentation, release notes, registries, and compatibility guidance. 3. Prefer the latest stable version compatible with the project. -4. Do not introduce prereleases or unrelated upgrades without approval. +4. Do not introduce unreleased or unrelated upgrades without approval. 5. Do not recommend older versions unless compatibility, stability, platform support, or project constraints justify them. 6. Explain breaking changes, migration work, compatibility risks, and rollback requirements. 7. Record durable version findings in `MEMORY.md`. diff --git a/HANDOFF.md b/HANDOFF.md index 48404e5..fae25a2 100644 --- a/HANDOFF.md +++ b/HANDOFF.md @@ -8,74 +8,35 @@ 4. `ARCHITECTURE.md` 5. The authority file for the requested task -Do not begin with a repository-wide scan. Do not read or print `.env`. +Do not read or print `.env`. ## Current state -- Package version: `3.0.0-rc.5` -- Status: unreleased RC5 development; not globally runtime-verified or stable -- Branch: `main` +- Package version: `3.1.0` +- Status: stable release preparation +- Branch: `agent/stable-v3.1.0` - Canonical remote: `https://github.com/ImYourBoyRoy/agent-continuity-stack` -- Published prerelease: - `https://github.com/ImYourBoyRoy/agent-continuity-stack/releases/tag/v3.0.0-rc.4` -- Release tag: `v3.0.0-rc.4` -- Release commit: `0e24499b9455f1956d0e8390bbd49cf62f908e52` -- Release date: `2026-07-26` -- Release archive SHA-256: - `e159a83df32dacceb29ca93c118b2cf14b293e790ecd1b636fb33f166f059893` -- Initial public commit: - `a6b1b72059fbca5ebc8c2cd3e1308e2cb36eb118` -- Initial validation: Python `3.10` and `3.14` GitHub jobs passed -- Inventory: 14 core skills and 1 optional, default-uninstalled skill - Installation: model-operated, status-first, and explicit-approval-only -- Public default: install selected skills while preserving all custom - instructions - -The local repository name is `agent-continuity-stack`. A local `.env` -may exist for maintainer GitHub authentication; it is ignored, mode-restricted, -excluded from release inventory, and never package content. +- Public default: install selected skills while preserving custom instructions +- Inventory: 14 core skills and 1 optional, default-uninstalled skill -## Completed +## Completed in this release work -- Consolidated and independently versioned the skill inventory. -- Kept the complete Expert Agent Operating Contract as an optional canonical - template. -- Added status, plan, journal, ownership, receipt, client-status, and rollback - schemas. -- Added safe tree, archive, contract, record, and bundle validators. -- Added positive, near-miss, collision, and negative lifecycle fixtures. -- Added exact-tested Portable Web Toolkit ownership boundaries. -- Added public model-install onboarding with preserve, guided-addition, and - complete-contract modes. -- Added architecture, contribution, security, GitHub workflow, and repository - hygiene files for public development. -- Renamed the complete package identity to Agent Continuity Stack - (`agent-continuity-stack`) and bound validators to the canonical repository. -- Enabled repository security controls and protected `main` with the successful - validation contexts. -- Separated release-candidate publication gates from final stable-promotion - gates without weakening unresolved runtime, recovery, or platform - requirements. -- Published immutable annotated tag and GitHub prerelease `v3.0.0-rc.4` with - the validated ZIP and external checksum sidecar. -- Began RC5 development for verified project authorship, maintainer links, - release visibility, and focused discovery topics without moving or replacing - RC4. -- Added the reciprocal ACS link to Portable Web Toolkit and featured ACS first - in the GitHub profile README. -- Added live `agent-instructions` and `context-engineering` repository topics; - the About description already matched the documented authority. -- Made Quick Start agent-operated: the coding agent runs validation, discovers - client state, and—after explicit approval—handles backups, installation, - smoke testing, evidence, and rollback preparation. -- Configured and API-verified six ordered GitHub profile pins with ACS first, - followed by Portable Web Toolkit, pyenv-native, OllamaToolkit, - WebScraperToolkit, and Portfolio Sidekick. +- Added explicit first-run personalization questions to the canonical contract. +- Removed hard-coded client and integration software versions from the README + compatibility summary. +- Converted package metadata and validation to stable `3.1.0`. +- Replaced multiple release tracks with one stable publication checklist. +- Updated the pinned `actions/setup-python` workflow dependency and synchronized + the release inventory. +- Preserved the Antigravity two-fragment loader adapter as a functional client + requirement. +- Updated fixtures, contract hashes, release inventory, and project memory. ## Validation baseline -Run: +Run from the repository root: ```bash python3 scripts/validate_bundle.py @@ -84,35 +45,22 @@ python3 scripts/inspect_tree.py . --exclude .git --exclude .env python3 tests/run_portable_tests.py ``` -The last pre-commit run must be recorded in `MEMORY.md`. Source and fixture -success does not prove live installation, client discovery, rollback, or -uninstall. +The 2026-08-08 run passed with zero errors and zero warnings. This proves +source, metadata, tree safety, schemas, and portable conformance; it does not +prove every installed client's live discovery. -## Open final stable-promotion gates +## Remaining release actions -- Complete the focused immutable-backup recovery rerun. -- Runtime-test Cursor with authenticated target-version skill discovery. -- Install and runtime-test Claude Code in a disposable environment. -- Prove both Antigravity fragments load in a fresh client session. -- Validate Windows reparse-point and metadata behavior. -- Exercise the public installation prompt end to end across all supported - clients. -- Review the complete contract's always-on token cost and priority wording. - -## Next recommended action - -Collect the outstanding live-client, recovery, platform, and contract-review -evidence. Do not promote any candidate to final `3.0.0` until every final -stable-promotion gate in `MERGE_CHECKLIST.md` passes. Validate RC5 as a -separate candidate before any publication decision. +- Build and validate the stable archive from the clean release commit. +- Generate and independently verify the external SHA-256 sidecar. +- Commit, push, and publish the stable `v3.1.0` GitHub Release. +- Close and remove the obsolete Dependabot branch after its fix is incorporated. +- Treat deletion of any legacy remote release/tag as a separate explicitly + identified destructive operation. ## Handoff discipline -After material work: - -- update `MEMORY.md` with durable facts and validation; -- update this file only when the immediate handoff changes; -- update `ARCHITECTURE.md` only for durable system-design changes; -- update `CHANGELOG.md` and versions for published behavior changes; -- leave exact blockers and the next action; -- never include credentials, private paths, logs, or transient model reasoning. +- Update `MEMORY.md` and this file with the release commit, archive name, + checksum, and GitHub URL after publication. +- Keep credentials, private paths, logs, and transient reasoning out of both + files. diff --git a/MEMORY.md b/MEMORY.md index 6cf6f42..3ab9713 100644 --- a/MEMORY.md +++ b/MEMORY.md @@ -3,27 +3,21 @@ ## Project snapshot - Package: Agent Continuity Stack -- Current package version: `3.0.0-rc.5` -- Release status: unreleased RC5 development; latest public prerelease is RC4 +- Current package version: `3.1.0` +- Release status: stable release preparation - Canonical repository: `https://github.com/ImYourBoyRoy/agent-continuity-stack` -- Published prerelease: - `https://github.com/ImYourBoyRoy/agent-continuity-stack/releases/tag/v3.0.0-rc.4` -- Release tag: `v3.0.0-rc.4` -- Release commit: `0e24499b9455f1956d0e8390bbd49cf62f908e52` -- Release date: `2026-07-26` -- Release archive SHA-256: - `e159a83df32dacceb29ca93c118b2cf14b293e790ecd1b636fb33f166f059893` - License: MIT -- Purpose: distribute one complete Expert Agent Operating Contract and portable - on-demand skills across Codex, Cursor, Claude Code, and Antigravity. +- Purpose: distribute one complete Expert Agent Operating Contract and + portable on-demand skills across Codex, Cursor, Claude Code, and Antigravity. - Canonical normalized source SHA-256: - `f5c992564ccd9946b5f2dbfc8d933555085a393a0549f4b7d1fe52b062e7ca5d` + `7d51bfc6bb0bc4440137acdb95e61eb732a2881e058f5a2f9301629bb5e959d5` - Inventory: 14 core skills and 1 optional, default-uninstalled skill ## Authority map -- `GLOBAL_CUSTOM_INSTRUCTIONS.md`: canonical public contract template +- `GLOBAL_CUSTOM_INSTRUCTIONS.md`: canonical public contract template and + first-run personalization intake - `instruction-pack.json`: source integrity, rendering policy, and adapters - `INSTALL_PROTOCOL.md`: model-operated status, authorization, transaction, update, and rollback protocol @@ -33,189 +27,61 @@ - `optional_skills/*/skill-manifest.json`: optional skill versions and policy - `schemas/`: lifecycle record contracts - `integrations/`: exact-tested specialist boundaries -- `tests/activation_cases.json`: core and optional routing fixtures -- `tests/CLIENT_SMOKE_MATRIX.md`: required live-client evidence -- `ARCHITECTURE.md`: durable component, lifecycle, and trust boundaries -- `HANDOFF.md`: concise current continuation point for another model +- `tests/activation_cases.json`: skill routing fixtures +- `tests/CLIENT_SMOKE_MATRIX.md`: client evidence requirements +- `ARCHITECTURE.md`: durable package, lifecycle, and trust boundaries +- `HANDOFF.md`: concise continuation point for another model - `.github/workflows/validate.yml`: public CI equivalent of local validation ## Current decisions +- The package publishes stable releases only. +- Installation remains model-operated, status-first, explicitly authorized, + journaled one client at a time, and best-effort recoverable. - The complete operating contract remains canonical and unshortened when - selected. Public installation is opt-in; skills-only with existing - instructions preserved is the default. -- Guided instruction additions are reviewed partial derivatives and must not be - represented, owned, hashed, or smoke-tested as the complete package contract. -- Installation is performed by an authorized coding model from a reviewed local - checkout. No standalone or remote executable installer is shipped. -- Status and planning are read-only; mutation requires explicit target and - scope authorization. -- `source_sha256` covers canonical UTF-8/LF template bytes. - Installation-specific `rendered_sha256` belongs only in runtime plans, - receipts, ownership, and status records. -- Antigravity imports two ordered rendered fragments. Each must remain below - 12,000 characters and their concatenation must equal `rendered_sha256`. -- Cursor global Rules and skill roots remain version-sensitive and require live - smoke tests. + selected. Skills-only installation preserves existing instructions by + default. +- First-run personalization asks for clients, skill scope, skill selection, + instruction mode, and each optional operator-profile field. Values are never + inferred and “leave unset” is accepted. +- The public contract uses placeholders; personalized profile values remain + installation inputs and are not package content. +- Antigravity's two ordered contract fragments are retained because they are a + client loader-size requirement, not a release-track split. - Cross-client atomicity is not claimed. The model journals, applies, validates, - and closes one client at a time; receipts are evidence rather than executable - path instructions. -- Skills are independently versioned. -- `build-astro-on-cloudflare` is optional and default-uninstalled. It defers - immediately when Portable Web Toolkit management is established. -- Portable Web Toolkit compatibility is exact-tested against `0.3.1`, release - commit `cdbc33ff40bedab48fc86bfb7e1ea06a5d81f6f3`, with skill content based at - `86dddd9efb64c5b4219afe986699135a51e63f83`. -- `red-team-technical-plan` owns explicit deep adversarial review; the global - contract retains proportional review for ordinary material work. -- Public release candidates and final stable promotion use separate gates. - Prereleases require clean-commit, source, inventory, conformance, - archive-safety, CI, checksum, and disclosure evidence. Unresolved - live-client, recovery, platform, and contract-policy evidence continues to - block final `3.0.0`. - -## Recent material changes - -- Converted final-looking v3 metadata to release candidate `3.0.0-rc.1`. -- Added `.gitattributes` and explicit UTF-8/LF/no-BOM integrity policy. -- Corrected canonical versus rendered contract hashing. -- Added seven lifecycle schemas and four deterministic read-only helpers. -- Added schema, rendered-contract, unsafe-tree, archive, and integration - conformance fixtures. -- Strengthened required README and canonical project-agent-file behavior. -- Added the exact-tested Portable Web Toolkit integration contract. -- Restored Astro + Cloudflare expertise only as an optional fallback. -- Expanded package README, client compatibility, release checklist, and - validator scope. -- Red-teamed RC1 and rejected final promotion. -- Added skill content hashes and full release-file inventory enforcement. -- Bound plan authorization to canonical content digests and tightened malformed - lifecycle record rejection. -- Strengthened archive validation for undeclared payloads, CRC, size and - compression limits, Unicode/case collisions, and Windows extraction hazards. -- Corrected Codex `CODEX_HOME`/override resolution and Cursor User Rules - authority. -- Added public model-install onboarding and decoupled skills from optional - custom-instruction installation. -- Renamed the local source root to `agent-continuity-stack`. -- Added architecture, model handoff, contribution, conduct, security, issue, - pull request, Dependabot, CI, editor, environment-example, and Git-ignore - foundations for public repository development. -- Separated prerelease publication requirements from final stable-promotion - requirements while preserving every unresolved final gate. -- Began RC5 development for verified authorship, maintainer links, a - prerelease-aware badge, and focused GitHub discovery metadata. Published RC4 - remains immutable. -- Added a reciprocal ACS link to Portable Web Toolkit on `main` at - `c356e7e7b9277eae4f00ed22297f65f56867e958`. -- Featured ACS first in the GitHub profile README at - `ead0ffdb73303d2f06f8320f16d443f5ab43a81d`. -- Added live `agent-instructions` and `context-engineering` repository topics; - the existing About description already matched the README authority. -- Reworked Quick Start so the coding agent runs validation, client inspection, - approved installation, backups, smoke tests, evidence recording, and rollback - preparation. The user reviews decisions and authorizes mutations rather than - running implementation commands. -- Configured the authenticated GitHub profile with six ordered pins: ACS, - Portable Web Toolkit, pyenv-native, OllamaToolkit, WebScraperToolkit, and - Portfolio Sidekick. GitHub's API verified the order. + and closes one client at a time. +- `build-astro-on-cloudflare` is optional and default-uninstalled. It defers to + Portable Web Toolkit when that toolkit owns the project. ## Validation -On 2026-07-26: +On 2026-08-08, the stable source validation completed with zero errors and zero +warnings: -- canonical contract comparison with approved source: exact match -- normalized contract source hash: verified -- `python3 scripts/validate_bundle.py`: 14 core, 1 optional, 4,301 catalog - characters, 0 errors, 0 warnings -- `python3 tests/run_portable_tests.py`: portable source and conformance tests - passed -- personalized rendered hash differs from source hash: verified -- Antigravity rendered-fragment reconstruction: verified -- valid and invalid lifecycle record fixtures: verified -- symlink, FIFO, case-collision, ZIP traversal, archive symlink, and archive - case-collision rejection: verified -- RC review ZIP validation, clean extraction, and extracted-suite rerun: passed -- RC review checksum sidecar: generated and independently verified -- disposable RC1 model-conformance exercise: status, install, idempotency, - conflict, changed-preflight, forced failure, unsafe tree, and rollback - scenarios passed; 148 schema records validated -- Codex `0.146.0-alpha.3`: fresh-session project contract discovery, explicit - red-team skill activation, exact skill path, and trivial near-miss passed -- RC2 disposable lifecycle: status-only, 15-target Codex install, idempotency, - conflict, changed-preflight, unsafe-tree, coherent journals, forced failure, - and rollback scenarios completed; 44/44 records were schema-valid and - independently root-applicable -- RC2 recovery exercise exposed a consumed-backup defect; the protocol and - schemas now require immutable, hashed backup snapshots restored by copy -- RC3 public onboarding and instruction-mode schema changes: bundle validation - passed with 14 core skills, 1 optional skill, 0 errors, and 0 warnings; - portable source and conformance tests passed -- Public-repository pre-commit validation on Python `3.14.3`: bundle, - canonical-contract, safe-tree, and portable conformance checks passed -- Five GitHub YAML files parsed successfully; the validation workflow pins - official `actions/checkout` `v7.0.1` and `actions/setup-python` `v6.2.0` - commits and grants read-only contents permission -- Generated an inventory-driven RC3 archive in a temporary directory: 130 - regular files, no unsafe entries, and extracted bundle/tests passed -- Prepared local `main` with 130 staged public files and the verified canonical - remote; `.env` remained ignored at mode `0600`, and both exact-token and - common credential-pattern scans found no staged credential -- RC4 comprehensive identity migration: folder, display name, package ID, - schema URNs, ownership markers, state paths, fixtures, documentation, and - validator expectations use `agent-continuity-stack`; old-identity scan found - zero publishable references -- RC4 inventory-driven archive round trip: 130 regular files, 191 total entries, - no unsafe entries, and extracted bundle/conformance tests passed -- Published the initial public `main` commit - `a6b1b72059fbca5ebc8c2cd3e1308e2cb36eb118`; local and remote heads matched -- Initial GitHub validation passed on Python `3.10` and `3.14`; the Dependabot - configuration run also passed -- Enabled private vulnerability reporting, dependency alerts, automated - security fixes, secret scanning, push protection, and read-only default - workflow permissions -- Protected `main` with strict required Python `3.10` and `3.14` checks, linear - history, conversation resolution, and force-push/deletion prevention; - administrator enforcement remains disabled for maintainer recovery -- RC4 prerelease-policy pre-commit validation: bundle validation passed with 14 - core skills, 1 optional skill, 0 errors, and 0 warnings; canonical-contract, - safe-tree, and portable conformance validation passed; `.env` remained - ignored, untracked, and mode `0600`; package version authorities agreed on - `3.0.0-rc.4`. -- Published GitHub prerelease `v3.0.0-rc.4` on 2026-07-26 from commit - `0e24499b9455f1956d0e8390bbd49cf62f908e52`. The annotated tag resolves to - that commit; the release is non-draft and explicitly marked as a prerelease. - Both the ZIP and checksum sidecar are uploaded, and GitHub's recorded ZIP - digest matches the independently verified SHA-256. -- Post-publication record pre-commit validation: bundle, canonical-contract, - safe-tree, and portable conformance checks passed with 0 errors and 0 - warnings. -- RC5 authorship, discovery, and agent-operated Quick Start pre-commit - validation: bundle validation passed with 14 core skills, 1 optional skill, 0 - errors, and 0 warnings; canonical-contract, safe-tree, and portable - conformance checks passed. Verified maintainer identity remains outside - `skills/` and `optional_skills/`. +- `python3 scripts/validate_bundle.py` +- `python3 scripts/inspect_contract.py source` +- `python3 scripts/inspect_tree.py . --exclude .git --exclude .env` +- `python3 tests/run_portable_tests.py` +- `git diff --check` -These are source and conformance results, not live installation or rollback -evidence. +The release inventory and canonical contract hashes were refreshed after the +stable metadata and onboarding changes. Archive construction and extracted-suite +validation remain required before publication. -## Risks and next action +## Known limitations -- Cursor CLI is present but unauthenticated; Claude Code is not installed; - Antigravity has no noninteractive agent surface proven here. Those live - client-status records remain pending. -- The complete contract's 13,898-byte always-on cost and instruction-precedence - wording remain explicit operator decisions; the canonical contract was not - changed during RC2 hardening. +- Client runtime evidence is reported per client and must not be inferred from + source validation. +- Cursor authentication, Claude installation, Antigravity fresh-session + loading, and Windows filesystem behavior require environment-specific proof. - Model-operated recovery cannot guarantee locks, `fsync`, ACL/xattr - preservation, or crash-atomic multi-target rollback; no mutation executor - exists. -- The immutable-backup correction still requires a focused recovery rerun. -- The RC4 copy-paste GitHub installation prompt has source/conformance coverage - but not a complete four-client live installation exercise. -- Windows reparse-point behavior needs a Windows validation run. -- RC4 is published as an explicitly labeled prerelease. Its publication is not - completion of any open stable-promotion gate. + preservation, or crash-atomic multi-target rollback. +- Legacy remote release/tag cleanup is a separate destructive GitHub operation + and is not part of package source validation. + +## Next action -Next: collect the remaining live-client, recovery, platform, and -contract-review evidence before promoting final `3.0.0`. +Build the stable archive from the identified clean release commit, validate the +archive and checksum, publish the stable `v3.1.0` GitHub Release, then update +this memory and `HANDOFF.md` with the commit, archive, digest, and live release +URL. diff --git a/MERGE_CHECKLIST.md b/MERGE_CHECKLIST.md index d8f9571..0652314 100644 --- a/MERGE_CHECKLIST.md +++ b/MERGE_CHECKLIST.md @@ -1,14 +1,12 @@ -# Package and skill release checklist +# Stable package release checklist -Use separate gates for public release candidates and final stable promotion. -Publishing a prerelease does not waive, satisfy, or conceal a stable gate. +This project publishes stable releases only. Do not create parallel release +tracks. -## Prerelease publication gate - -Before publishing a release candidate: +Before publishing a stable release: 1. Confirm `VERSION`, package manifest version, instruction-pack version, - release-candidate status, README, memory, and changelog agree. + stable status, README, memory, and changelog agree. 2. Confirm `.env` and other local credentials are ignored, absent from the release inventory, absent from staged/tracked content, and mode-restricted when present. @@ -56,32 +54,18 @@ Before publishing a release candidate: ``` 20. Confirm required GitHub branch protection, Actions permissions, and CI. -21. Create the candidate archive from an identified clean commit. +21. Create the release archive from an identified clean commit. 22. Validate it with `scripts/validate_archive.py`, extract it, and rerun the suite. 23. Confirm `LICENSE` is included, generate and independently verify the external SHA-256 sidecar, and record the tag, commit, date, archive name, and hash in release notes. 24. Stop if the intended remote tag or release already exists. Otherwise create - an immutable annotated prerelease tag and mark the GitHub Release - explicitly as a prerelease. - -## Final stable promotion gate - -Before promoting to final `3.0.0`: + an immutable annotated stable tag and publish a stable GitHub Release with + the archive and external checksum sidecar. -1. Complete the focused immutable-backup recovery rerun. -2. Runtime-test Cursor with authenticated target-version skill discovery. -3. Install and runtime-test Claude Code in a disposable environment. -4. Prove both Antigravity fragments load in a fresh client session. -5. Validate Windows reparse-point and metadata behavior. -6. Exercise the public installation prompt end to end across all supported - clients. -7. Review the complete contract's always-on token cost and instruction-priority - wording. -8. Re-run every prerelease integrity gate against the final package identity, - create an identified clean final release commit, build and verify new - artifacts, and publish a non-prerelease release. +25. Report each client as verified, installed-unverified, or unavailable. + Never convert source validation into a claim of live client discovery. Likely overlap areas: diff --git a/README.md b/README.md index da097ce..c039f46 100644 --- a/README.md +++ b/README.md @@ -2,18 +2,18 @@ [![Validate](https://github.com/ImYourBoyRoy/agent-continuity-stack/actions/workflows/validate.yml/badge.svg)](https://github.com/ImYourBoyRoy/agent-continuity-stack/actions/workflows/validate.yml) [![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE) -[![Release](https://img.shields.io/github/v/release/ImYourBoyRoy/agent-continuity-stack?include_prereleases&label=release)](https://github.com/ImYourBoyRoy/agent-continuity-stack/releases) +[![Release](https://img.shields.io/github/v/release/ImYourBoyRoy/agent-continuity-stack?label=release)](https://github.com/ImYourBoyRoy/agent-continuity-stack/releases) > Keep project rules and context consistent across coding agents. -Version `3.0.0-rc.5` is the next release candidate under development for -repository-centered instructions, skills, memory conventions, client adapters, -and lifecycle safeguards across Codex, Cursor, Claude Code, and Google -Antigravity. It is not a runtime memory service, agent orchestrator, or globally -runtime-verified final release. +Version `3.1.0` is the current stable release for repository-centered +instructions, skills, memory conventions, client adapters, and lifecycle +safeguards across Codex, Cursor, Claude Code, and Google Antigravity. It is not a +runtime memory service, agent orchestrator, or guarantee of identical behavior +across every client installation. -Latest published prerelease: -[v3.0.0-rc.4](https://github.com/ImYourBoyRoy/agent-continuity-stack/releases/tag/v3.0.0-rc.4). +Current release: +[v3.1.0](https://github.com/ImYourBoyRoy/agent-continuity-stack/releases/tag/v3.1.0). ## Repository identity @@ -55,17 +55,17 @@ or authority withheld by the host or repository. Continuity is repository-centered: the package does not synchronize live conversations or provide a shared runtime memory database. -## Release-candidate status +## Current compatibility status | Surface | Source/structure | Live runtime | |---|---|---| -| Codex 0.146.0-alpha.3 | Validated | Project contract and positive/near-miss skill smoke passed | -| Cursor 3.13.10 | Validated, version-sensitive | CLI 2026.07.23 is unauthenticated; pending | +| Codex | Validated | Project contract and positive/near-miss skill smoke passed | +| Cursor | Validated, version-sensitive | Authentication and live discovery must be verified in the target environment | | Claude Code | Validated from current documentation | Client not locally installed; pending | -| Antigravity IDE 1.107.0 | Two-fragment adapter validated | No proven headless agent surface; pending | +| Antigravity IDE | Two-fragment adapter validated | No proven headless agent surface; pending | | Model-operated lifecycle | Schemas and conformance fixtures | Best-effort disposable exercise; never crash-atomic across clients | -Final `3.0.0` requires the gates in `MERGE_CHECKLIST.md`. +Stable publication requires the gates in `MERGE_CHECKLIST.md`. ## Requirements @@ -336,8 +336,9 @@ A copied file is not proof that the client loaded it. ## Portable Web Toolkit integration -The exact-tested optional integration targets Portable Web Toolkit `0.3.1`. -See `integrations/portable-web-toolkit.json` and its human-readable companion. +The exact-tested optional integration targets the version recorded in +`integrations/portable-web-toolkit.json`. See that metadata and its human-readable +companion for compatibility details. Newer toolkit releases require revalidation. The toolkit is never installed automatically by this package. @@ -385,39 +386,25 @@ installation, rollback, or uninstall. - The canonical 13,898-byte contract consumes a meaningful share of each client's always-on context and Codex's aggregate instruction budget. - The canonical instruction-priority wording and always-on operator profile - remain explicit review items before final promotion. + remain explicit review items for future release maintenance. - The public GitHub installation prompt has source and negative conformance coverage but has not completed a four-client live installation exercise. - Windows reparse-point behavior requires a Windows validation run. ## Release and checksum process -### Prerelease publication +### Stable publication -A release candidate may be published for controlled review when: - -1. its prerelease identity is consistent across package authorities and - documentation; -2. source, fixture, integration, inventory, tree-safety, archive, and - conformance validation passes; -3. known runtime and platform limitations are disclosed without implying they - passed; -4. the archive is built from an identified clean commit, validated, extracted, - and retested; -5. a separate `.sha256` sidecar is generated and independently verified; and -6. the immutable tag and GitHub Release are explicitly marked as a prerelease. +A stable release requires consistent package authorities, source and fixture +validation, integration and archive-safety checks, disclosed client-runtime +coverage, a clean identified release commit, and a newly built archive with an +independently verified SHA-256 sidecar. Runtime evidence is reported per client; +an unavailable client must remain clearly marked unverified rather than being +represented as tested. Release notes record the tag, commit, publication date, archive filename, -SHA-256, verified scope, and unresolved final-promotion gates. - -### Final stable promotion - -Do not promote a release candidate to final `3.0.0` until all source, fixture, -archive, lifecycle-conformance, integration, recovery, platform, and -four-client runtime gates pass. Final promotion also requires review of the -complete contract's always-on cost and instruction-priority wording, a clean -identified final release commit, a newly built and verified archive, and a -separate checksum sidecar. +SHA-256, verified scope, and unresolved compatibility limitations. Publish an +annotated tag and a stable GitHub Release with the archive and sidecar. An archive cannot contain its own final checksum. diff --git a/SECURITY.md b/SECURITY.md index f9ed339..912793b 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -2,9 +2,8 @@ ## Supported versions -Security fixes target the latest published stable release and, while this -project remains pre-release, the newest release candidate. Older release -candidates may receive fixes only when a safe upgrade path requires them. +Security fixes target the latest published stable release. Older stable +releases may receive fixes only when a safe upgrade path requires them. ## Reporting a vulnerability diff --git a/VERSION b/VERSION index 3d63921..fd2a018 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -3.0.0-rc.5 +3.1.0 diff --git a/instruction-pack.json b/instruction-pack.json index cc873a8..f6cffeb 100644 --- a/instruction-pack.json +++ b/instruction-pack.json @@ -1,9 +1,9 @@ { "schema": 2, "package": "agent-continuity-stack", - "package_version": "3.0.0-rc.5", + "package_version": "3.1.0", "source": "GLOBAL_CUSTOM_INSTRUCTIONS.md", - "source_sha256": "f5c992564ccd9946b5f2dbfc8d933555085a393a0549f4b7d1fe52b062e7ca5d", + "source_sha256": "7d51bfc6bb0bc4440137acdb95e61eb732a2881e058f5a2f9301629bb5e959d5", "source_hash_definition": "sha256 of canonical UTF-8 bytes with LF line endings and no BOM", "encoding": "utf-8", "line_endings": "lf", diff --git a/manifest.json b/manifest.json index ebca8da..74185ed 100644 --- a/manifest.json +++ b/manifest.json @@ -1,10 +1,10 @@ { "schema": 4, "package": "agent-continuity-stack", - "version": "3.0.0-rc.5", + "version": "3.1.0", "repository": "https://github.com/ImYourBoyRoy/agent-continuity-stack", "license": "MIT", - "release_status": "release-candidate", + "release_status": "stable", "release_integrity": { "inventory": "release-files.json", "inventory_excludes_itself": true, diff --git a/release-files.json b/release-files.json index a1a6ee7..1e3e278 100644 --- a/release-files.json +++ b/release-files.json @@ -47,7 +47,7 @@ }, { "path": ".github/workflows/validate.yml", - "sha256": "b9dab2df56311e634bbab6a99060c29409e84f29919d8ebb4532a7ea1cddb5db", + "sha256": "c7fb833710982b900f4836091543e2c2d2a2bf1ec14ddd39a61bbfecaa6b616b", "bytes": 1118 }, { @@ -62,18 +62,18 @@ }, { "path": "ARCHITECTURE.md", - "sha256": "ce6282b0d261443528e10b110bcdf8609f01f00714c01726a1cc40f65f26a7c5", - "bytes": 6612 + "sha256": "90caad566b6b4587a5a71e5f3b4c330895b69161a740b13a184fcba4093d99f7", + "bytes": 6570 }, { "path": "CHANGELOG.md", - "sha256": "bafbccecdb8cd618b88fd30b204af1a08c67124aa8e795ff73852f0e451ea74a", - "bytes": 4991 + "sha256": "bd1c40467740cd92cc90c83409a9c3ad87b82d3caa8fe4b7e1c9253354630f5c", + "bytes": 1258 }, { "path": "CLIENT_COMPATIBILITY.md", - "sha256": "6078b018d619501b3997ceae2d1a8b5905ab351eb45f8856ef646bedb6dbd0f8", - "bytes": 5350 + "sha256": "4e176e1d48d430d3f1e63c1f4f5092ed0b4e960bc616ff830ff2a757545f3f19", + "bytes": 5357 }, { "path": "CODE_OF_CONDUCT.md", @@ -87,13 +87,13 @@ }, { "path": "GLOBAL_CUSTOM_INSTRUCTIONS.md", - "sha256": "f5c992564ccd9946b5f2dbfc8d933555085a393a0549f4b7d1fe52b062e7ca5d", - "bytes": 13898 + "sha256": "7d51bfc6bb0bc4440137acdb95e61eb732a2881e058f5a2f9301629bb5e959d5", + "bytes": 14999 }, { "path": "HANDOFF.md", - "sha256": "013e2398ff57c4dd71cb2f5d5d8e872d39616cdd27ece488d848cae8d017ad90", - "bytes": 5024 + "sha256": "cfa94c78530bfb321d93cf9dc34dab45995c013a6d179b80749c644406df8711", + "bytes": 2342 }, { "path": "INSTALL_PROTOCOL.md", @@ -107,23 +107,23 @@ }, { "path": "MEMORY.md", - "sha256": "77b71b71e84ae1ddc22ee2d5c2e6f182ef83a536414abd82a3332cb983ca3f7f", - "bytes": 12512 + "sha256": "541e7aeeaeec8126762a6b6c9117a18386a9ccdd188b5e7bd85a3ea7fea9f5ce", + "bytes": 3993 }, { "path": "MERGE_CHECKLIST.md", - "sha256": "a5fa3387f21574549d61ff9b2301ce26c7a7cdf34b62031326691a144ac69d26", - "bytes": 4749 + "sha256": "da28ad516f9b17ed108352d9cf0fcda62496f6eabcf5c32195e6a5bf48f76979", + "bytes": 4028 }, { "path": "README.md", - "sha256": "1f29bd0901ea9da0cae8fafb6779af47413c0d0de418504d9aa2219b07f585a1", - "bytes": 20858 + "sha256": "02b92f37f574c63a3b8bf83b969cb20a4e4c6c6b7f4c38b4ce824cd980d4f8ef", + "bytes": 20336 }, { "path": "SECURITY.md", - "sha256": "8855c0c64f1580dc2bf3fa5ee166856265d1dc8ec33425f8ffc0d0fa6d51c778", - "bytes": 1694 + "sha256": "c189e0b5f2f8220d1c72500fee16e4c8d0930519f3294c18b14ada86e1ce67b5", + "bytes": 1617 }, { "path": "SOURCE_MAP.md", @@ -132,13 +132,13 @@ }, { "path": "VERSION", - "sha256": "bdcd9a7699ee9c9aa0aea7ed31d12bf8195ec6b745308454271874c94cd14140", - "bytes": 11 + "sha256": "b2f44d3b6e29f8b1b73ea4735f006affc4d198e1fd9c7d50e736159b1ef636c6", + "bytes": 6 }, { "path": "instruction-pack.json", - "sha256": "ce009d5912c4d3e470a0f7e175c1d8b903d96bd7ff275ef61e506ea9db4e95c1", - "bytes": 2229 + "sha256": "cede48a0f83c1f92a9451369b41960f8fad784276063976b5f8df8c2fb8e206a", + "bytes": 2224 }, { "path": "integrations/portable-web-toolkit.json", @@ -152,8 +152,8 @@ }, { "path": "manifest.json", - "sha256": "9a7f5eb5f275f076cb8cfe0af38a261401cd1f3f021e580e868675ea78aa405f", - "bytes": 3222 + "sha256": "7b78720d72bcaaecc4d48191f17bd9ae37ec685f158d8b0bbe61465b2ec3f918", + "bytes": 3206 }, { "path": "optional_skills/build-astro-on-cloudflare/SKILL.md", @@ -227,8 +227,8 @@ }, { "path": "scripts/validate_bundle.py", - "sha256": "b5aa7ea8d91a27c49f92d303735e233c7d828fc45a1999d7d628c0c553423a30", - "bytes": 29147 + "sha256": "2a3a2df491e1be1776322d66f46f52f3d52eded8d286848fc89388a932d29ef6", + "bytes": 29126 }, { "path": "scripts/validate_record.py", @@ -577,43 +577,43 @@ }, { "path": "tests/evidence/codex-0.146.0-alpha.3-linux-project.json", - "sha256": "0ebf5b5fb9cc4840df4afc01caf47d26c5fe3b42fe4fc957214fe92aa9b5cf4c", - "bytes": 1344 + "sha256": "2625c8dc95b3e3f87c180c17c97e7daaeb4c7c7c5c02480cdb4f3f92e8e8adac", + "bytes": 1345 }, { "path": "tests/fixtures/records/client-status.json", - "sha256": "3ad2724a2865dfbbebcd8d7de8066ce979cc74e2a244d0340c0eb065ad12cb87", - "bytes": 917 + "sha256": "0932609be57b52237f0c5c4436ce8c04db5df5c0edb2667bf221b855c21fa425", + "bytes": 912 }, { "path": "tests/fixtures/records/install-plan.json", - "sha256": "234a85dcf8c336eb8d182ef65c93fb9b2d6705243dbbfdcde86e550fd39cff88", - "bytes": 1202 + "sha256": "d5c1a4411e78d79be7cf7d1c87d8e7bca7d13f19646b74400229cae77f21a9b8", + "bytes": 1197 }, { "path": "tests/fixtures/records/install-status.json", - "sha256": "a5a66f30addfef491e1790d411b894bcbb100d587808e599b1ab26234c604a82", - "bytes": 646 + "sha256": "66942c5d9de5ac8dc67ea9c27fe167485e2ce7699b65e00dba4fc413cf4f5086", + "bytes": 641 }, { "path": "tests/fixtures/records/operation-journal.json", - "sha256": "0cf664ad17bd14a19b27ce43f0645f1a0d5509428b884884983594cfdbf0b9a5", - "bytes": 846 + "sha256": "ab885d134c26063b68ebf55b63ec34593c4ccbac0b7b7facd08213a2a7114e3d", + "bytes": 841 }, { "path": "tests/fixtures/records/ownership-record.json", - "sha256": "37483bfa866515305aaaf844edb3ccbf34e62fc2757f103d4af29f93cb54888c", - "bytes": 831 + "sha256": "417682b83e1dc11c7c38f009b76a5b051dad69ac02946019d190066ec085ee53", + "bytes": 826 }, { "path": "tests/fixtures/records/rollback-receipt.json", - "sha256": "968b5da9cdc41920097f0784dc03bf595c5b7ec205d6f4f89d5b9ca3b9ea958a", - "bytes": 836 + "sha256": "2d36cee2a311807969a3c4f5eab22193e98d27ebe2ecad5d40feeedb646506b6", + "bytes": 831 }, { "path": "tests/fixtures/records/transaction-receipt.json", - "sha256": "3e39590bb5ebabcfa888e9be18ac0db1ae2aa5d4ab86f6ebc6589a723304ed90", - "bytes": 1404 + "sha256": "201db889d1937c86c769de341b55304d330b9ee60a768b29fc1c6f4c226d4e5e", + "bytes": 1399 }, { "path": "tests/fixtures/update-audit/.github/workflows/ci.yml", @@ -647,8 +647,8 @@ }, { "path": "tests/run_portable_tests.py", - "sha256": "eb79e6597567c89287e59c7926aaad145883d5fba1521611bcfef6663092d7f1", - "bytes": 20010 + "sha256": "b7b0f8d65a789ae75069a36d6d6efa545924e2a0602bc4ac21bb8cc0e25b1c69", + "bytes": 20395 } ] } diff --git a/scripts/validate_bundle.py b/scripts/validate_bundle.py index fa67113..fa9a61e 100644 --- a/scripts/validate_bundle.py +++ b/scripts/validate_bundle.py @@ -1,5 +1,5 @@ #!/usr/bin/env python3 -"""Validate the release-candidate source bundle without third-party packages.""" +"""Validate the stable source bundle without third-party packages.""" from __future__ import annotations @@ -387,8 +387,8 @@ def main() -> int: package_version = manifest.get("version", "") if not SEMVER_RE.fullmatch(package_version): errors.append("manifest package version is not valid Semantic Versioning") - if manifest.get("release_status") != "release-candidate": - errors.append("RC manifest must declare release-candidate status") + if manifest.get("release_status") != "stable": + errors.append("stable manifest must declare stable release status") version_path = root / "VERSION" if not version_path.is_file(): diff --git a/tests/evidence/codex-0.146.0-alpha.3-linux-project.json b/tests/evidence/codex-0.146.0-alpha.3-linux-project.json index a97bf66..96506c7 100644 --- a/tests/evidence/codex-0.146.0-alpha.3-linux-project.json +++ b/tests/evidence/codex-0.146.0-alpha.3-linux-project.json @@ -2,8 +2,8 @@ "schema_version": 2, "kind": "client-status", "package": "agent-continuity-stack", - "package_version": "3.0.0-rc.5", - "source_sha256": "f5c992564ccd9946b5f2dbfc8d933555085a393a0549f4b7d1fe52b062e7ca5d", + "package_version": "3.1.0", + "source_sha256": "7d51bfc6bb0bc4440137acdb95e61eb732a2881e058f5a2f9301629bb5e959d5", "client": "codex", "client_version": "0.146.0-alpha.3", "operating_system": "Linux x86_64", @@ -21,7 +21,7 @@ "content_sha256": "d56cdb5d4990548804b4653e062962a974ac13aa31d3cb1f7b84cbcf9ad065e3" } ], - "rendered_sha256": "f5c992564ccd9946b5f2dbfc8d933555085a393a0549f4b7d1fe52b062e7ca5d", + "rendered_sha256": "7d51bfc6bb0bc4440137acdb95e61eb732a2881e058f5a2f9301629bb5e959d5", "copied": true, "loaded": true, "smoke_passed": true, @@ -30,7 +30,7 @@ "Fresh read-only session named the Expert Agent Operating Contract.", "Explicit red-team request loaded the project skill and reported its exact SKILL.md path.", "A fresh trivial-rename near-miss produced no tool or skill-loading event.", - "RC5 changes documentation, attribution, and repository metadata only; the recorded contract and skill content hashes are unchanged from the runtime exercise." + "3.1.0 changes documentation, onboarding, release metadata, and CI metadata; the recorded contract and skill content hashes are unchanged from the runtime exercise." ], "verified_at": "2026-07-26T21:22:54Z" } diff --git a/tests/fixtures/records/client-status.json b/tests/fixtures/records/client-status.json index 9ab1be8..7af4e43 100644 --- a/tests/fixtures/records/client-status.json +++ b/tests/fixtures/records/client-status.json @@ -2,8 +2,8 @@ "schema_version": 2, "kind": "client-status", "package": "agent-continuity-stack", - "package_version": "3.0.0-rc.5", - "source_sha256": "f5c992564ccd9946b5f2dbfc8d933555085a393a0549f4b7d1fe52b062e7ca5d", + "package_version": "3.1.0", + "source_sha256": "7d51bfc6bb0bc4440137acdb95e61eb732a2881e058f5a2f9301629bb5e959d5", "client": "codex", "client_version": "example-version", "operating_system": "fixture-os", diff --git a/tests/fixtures/records/install-plan.json b/tests/fixtures/records/install-plan.json index fbe09ed..6524697 100644 --- a/tests/fixtures/records/install-plan.json +++ b/tests/fixtures/records/install-plan.json @@ -3,12 +3,12 @@ "kind": "install-plan", "transaction_id": "fixture-transaction-001", "generated_at": "2026-07-26T20:00:00Z", - "package_version": "3.0.0-rc.5", + "package_version": "3.1.0", "source_commit": null, - "source_sha256": "f5c992564ccd9946b5f2dbfc8d933555085a393a0549f4b7d1fe52b062e7ca5d", + "source_sha256": "7d51bfc6bb0bc4440137acdb95e61eb732a2881e058f5a2f9301629bb5e959d5", "instruction_mode": "preserve-existing", "rendered_sha256": null, - "plan_sha256": "8a7fa86cca530a1600148acdc0d7e377ee766ce9319e4878c3c836c9a2723c8c", + "plan_sha256": "0a9245fc6e24d70e5edce49003c55d55ed14817d3cb50ecaab4f38a78bd7d5d9", "authorization": { "status": "pending", "approved_plan_sha256": null, diff --git a/tests/fixtures/records/install-status.json b/tests/fixtures/records/install-status.json index afba777..58c6a5b 100644 --- a/tests/fixtures/records/install-status.json +++ b/tests/fixtures/records/install-status.json @@ -4,9 +4,9 @@ "generated_at": "2026-07-26T20:00:00Z", "package": { "name": "agent-continuity-stack", - "version": "3.0.0-rc.5", + "version": "3.1.0", "source_commit": null, - "source_sha256": "f5c992564ccd9946b5f2dbfc8d933555085a393a0549f4b7d1fe52b062e7ca5d" + "source_sha256": "7d51bfc6bb0bc4440137acdb95e61eb732a2881e058f5a2f9301629bb5e959d5" }, "clients": [ { diff --git a/tests/fixtures/records/operation-journal.json b/tests/fixtures/records/operation-journal.json index db0d343..8bdaf78 100644 --- a/tests/fixtures/records/operation-journal.json +++ b/tests/fixtures/records/operation-journal.json @@ -3,7 +3,7 @@ "kind": "operation-journal", "operation_id": "fixture-operation-001", "package": "agent-continuity-stack", - "package_version": "3.0.0-rc.5", + "package_version": "3.1.0", "package_sha256": "cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc", "approved_plan_sha256": "61574933c78f6745c67ea5dd7762bc9d0865f13b31202621280aaed3b00eda22", "client": "codex", diff --git a/tests/fixtures/records/ownership-record.json b/tests/fixtures/records/ownership-record.json index 4fe7c20..5c8f9ff 100644 --- a/tests/fixtures/records/ownership-record.json +++ b/tests/fixtures/records/ownership-record.json @@ -2,7 +2,7 @@ "schema_version": 1, "kind": "ownership-record", "package": "agent-continuity-stack", - "package_version": "3.0.0-rc.5", + "package_version": "3.1.0", "package_sha256": "cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc", "approved_plan_sha256": "61574933c78f6745c67ea5dd7762bc9d0865f13b31202621280aaed3b00eda22", "transaction_id": "fixture-transaction-001", @@ -14,7 +14,7 @@ "skill_name": "audit-project-updates", "skill_version": "1.0.0", "installed_sha256": "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb", - "source_sha256": "f5c992564ccd9946b5f2dbfc8d933555085a393a0549f4b7d1fe52b062e7ca5d", + "source_sha256": "7d51bfc6bb0bc4440137acdb95e61eb732a2881e058f5a2f9301629bb5e959d5", "rendered_sha256": null, "installed_at": "2026-07-26T20:01:00Z" } diff --git a/tests/fixtures/records/rollback-receipt.json b/tests/fixtures/records/rollback-receipt.json index 8bbb20c..6f216fa 100644 --- a/tests/fixtures/records/rollback-receipt.json +++ b/tests/fixtures/records/rollback-receipt.json @@ -2,7 +2,7 @@ "schema_version": 1, "kind": "rollback-receipt", "package": "agent-continuity-stack", - "package_version": "3.0.0-rc.5", + "package_version": "3.1.0", "rollback_id": "fixture-rollback-001", "original_transaction_id": "fixture-transaction-001", "approved_plan_sha256": "61574933c78f6745c67ea5dd7762bc9d0865f13b31202621280aaed3b00eda22", diff --git a/tests/fixtures/records/transaction-receipt.json b/tests/fixtures/records/transaction-receipt.json index dff9bb5..25e255a 100644 --- a/tests/fixtures/records/transaction-receipt.json +++ b/tests/fixtures/records/transaction-receipt.json @@ -6,12 +6,12 @@ "completed_at": "2026-07-26T20:01:00Z", "outcome": "complete", "package": "agent-continuity-stack", - "package_version": "3.0.0-rc.5", + "package_version": "3.1.0", "package_sha256": "cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc", "approved_plan_sha256": "8a7fa86cca530a1600148acdc0d7e377ee766ce9319e4878c3c836c9a2723c8c", "state_root": "/disposable-state", "source_commit": null, - "source_sha256": "f5c992564ccd9946b5f2dbfc8d933555085a393a0549f4b7d1fe52b062e7ca5d", + "source_sha256": "7d51bfc6bb0bc4440137acdb95e61eb732a2881e058f5a2f9301629bb5e959d5", "instruction_mode": "preserve-existing", "rendered_sha256": null, "client_versions": { diff --git a/tests/run_portable_tests.py b/tests/run_portable_tests.py index abec805..b4a3fef 100644 --- a/tests/run_portable_tests.py +++ b/tests/run_portable_tests.py @@ -148,6 +148,15 @@ def test_contract_integrity() -> None: metadata = json.loads((ROOT / "instruction-pack.json").read_text("utf-8")) contract = (ROOT / metadata["source"]).read_bytes() assert hashlib.sha256(contract).hexdigest() == metadata["source_sha256"] + contract_text = contract.decode("utf-8") + normalized_contract_text = " ".join(contract_text.split()) + for required in ( + "## First-run personalization", + "Ask which clients are in scope", + "Ask separately for each relevant operator-profile field", + "Accept “leave unset” for every field", + ): + assert required in normalized_contract_text source = json.loads(run("scripts/inspect_contract.py", "source").stdout) assert source["matches_manifest"] is True assert source["already_normalized"] is True @@ -513,7 +522,7 @@ def test_boundaries_and_integration() -> None: assert not (ROOT / "scripts" / "install_skills.py").exists() manifest = json.loads((ROOT / "manifest.json").read_text("utf-8")) assert manifest["package"] == "agent-continuity-stack" - assert manifest["version"] == "3.0.0-rc.5" + assert manifest["version"] == "3.1.0" optional = {item["name"]: item for item in manifest["optional_skills"]} assert optional["build-astro-on-cloudflare"]["install_by_default"] is False