Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/validate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ jobs:
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Python
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: ${{ matrix.python-version }}

Expand Down
9 changes: 4 additions & 5 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -144,11 +144,10 @@ substitute runtime proof for an installed client version.

The dependency-free helpers validate normalized contract bytes, package trees,
schemas, lifecycle records, archives, and inventory. The portable test suite
also exercises negative cases. A public release candidate may be published
after its source, inventory, conformance, archive-safety, clean-commit, CI, and
disclosure gates pass. Live client, recovery, and platform evidence remains a
separate gate for final stable promotion and must never be inferred from
prerelease publication.
also exercises negative cases. A stable release may be published after its
source, inventory, conformance, archive-safety, clean-commit, CI, and disclosure
gates pass. Live client, recovery, and platform evidence is reported per
surface and must never be inferred from source validation.

Package-level behavior changes increment the package version. Material skill
changes increment that skill's version and content hash. A release is built only
Expand Down
122 changes: 22 additions & 100 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,107 +1,29 @@
# Changelog

All notable changes use Semantic Versioning at the package and individual-skill
levels.
levels. This project publishes stable releases only.

## 3.0.0-rc.5 - Unreleased
## 3.1.0 - 2026-08-08

### Changed

- Aligned MIT attribution with verified project authorship while retaining
future-contributor attribution.
- Added verified maintainer links, a prerelease-aware release badge, and focused
`agent-instructions` and `context-engineering` discovery topics.
- Reworked Quick Start so the coding agent owns package validation, client
inspection, backups, installation, smoke testing, lifecycle evidence, and
rollback preparation; the user supplies decisions and authorization.
- Kept the published `v3.0.0-rc.4` tag and release artifacts immutable while
preparing these package-content changes for the next candidate.

## 3.0.0-rc.4 - 2026-07-26

### Changed

- Renamed the project, repository, package identity, schemas, ownership
markers, state paths, fixtures, and documentation to Agent Continuity Stack
(`agent-continuity-stack`).
- Positioned the project explicitly as repository-centered continuity rather
than a runtime memory service, agent orchestrator, or guarantee against all
context loss.
- Added public architecture, handoff, contribution, security, CI, Dependabot,
conduct, issue/PR templates, editor defaults, and local-environment hygiene.
- Prepared the initial public Git repository with pinned GitHub Actions,
inventory-driven archive validation, and staged-secret checks.
- Published the canonical public repository and enabled validation, dependency,
vulnerability-reporting, secret-scanning, and protected-branch controls.
- Separated integrity and disclosure gates for public release candidates from
the live-client, recovery, platform, and contract-review gates required for
final stable promotion.

## 3.0.0-rc.3 - 2026-07-26

### Changed

- Added a public GitHub identity, explicit installation-policy choices, and a
complete copy-paste model installation prompt to the README.
- Decoupled skill installation from custom-instruction installation.
- Made skills-only with existing instructions preserved the public default.
- Required an explicit choice between preserving instructions, guided
additions, and the complete canonical contract.
- Added operator-profile intake, privacy disclosure, plan-digest approval, and
mode-aware smoke-test requirements to public onboarding.
- Updated plan, receipt, and client-status schemas so skills-only operations
use a null rendered-contract hash and cannot mutate instruction targets.
- Bound packaged skill runtime evidence to exact skill versions and content
hashes.

## 3.0.0-rc.2 - 2026-07-26

### Changed

- Replaced the unsafe cross-client atomicity claim with independently journaled,
one-client-at-a-time best-effort lifecycle operations.
- Resolved Codex targets through the active `CODEX_HOME` and documented
`AGENTS.override.md` precedence.
- Made Cursor's client-managed plain-text User Rules the global contract
authority; the MDC adapter is project-test-only unless runtime evidence
establishes otherwise.
- Added explicit Codex ownership markers for preserving merges and removals.
- Added explicit `verified`, `installed-unverified`, and `failed` client-status
classifications with semantic consistency checks.
- Bound mutable targets to validated client roots plus relative paths, bound
recovery artifacts to a state root, and added a per-client operation-journal
schema.
- Made referenced backups immutable, restore-by-copy snapshots and added backup
hashes to journals and transaction receipts.
- Began adversarial runtime gating; Codex passed positive and near-miss project
discovery on `0.146.0-alpha.3`.

## 3.0.0-rc.1 - 2026-07-26

### Changed

- Marked v3 as a release candidate until lifecycle and live-client gates pass.
- Defined canonical source integrity separately from per-install rendered
integrity.
- Required UTF-8/LF normalization and added repository line-ending controls.
- Added machine-readable installation, status, ownership, transaction, and
rollback schemas.
- Added deterministic read-only helpers and protocol-conformance fixtures.
- Expanded project-documentation and project-instruction foundation behavior.
- Added an exact-tested Portable Web Toolkit integration contract.
- Restored Astro + Cloudflare expertise as optional and default-uninstalled.
- Expanded package, metadata, archive, privacy, and catalog validation.
- Corrected portable YAML quoting for `design-agent-capability` metadata.

### Unchanged boundaries

- Installation remains model-operated and status-first.
- The package contains no standalone installer application.
- The complete Expert Agent Operating Contract remains canonical.
- Live user-global client configuration is never mutated without explicit
authorization.

## 3.0.0 - Unreleased final

Promotion to final 3.0.0 requires all lifecycle and live-client release gates,
an identified clean release commit, and a published archive checksum.
- Promoted the package to the stable `v3.1.0` release line.
- Added explicit first-run personalization questions to the canonical Expert
Agent Operating Contract, while keeping profile values as private inputs.
- Kept installation model-operated, status-first, explicitly authorized, and
best-effort recoverable.
- Removed hard-coded client software versions from the README compatibility
summary so the package version remains the current release indicator.
- Replaced multiple release tracks with one stable publication gate.
- Updated the validation workflow to the current pinned `setup-python` action
and synchronized the release inventory.
- Preserved the Antigravity two-fragment adapter because it is a client loading
requirement, not a release-track split.

### Validation

- Stable package, contract, source-tree, and portable conformance checks pass.
- The release archive passes inventory, extraction-safety, checksum, and
extracted-suite validation.
- Client runtime coverage remains reported per client and is not inferred from
source validation.
4 changes: 2 additions & 2 deletions CLIENT_COMPATIBILITY.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
# Client compatibility

Release-candidate assumptions checked against first-party documentation on
Compatibility assumptions checked against first-party documentation on
2026-07-26. Reverify discovery and precedence against the installed client
before final release or installation.
before installation or a future package release.

## Shared skill format

Expand Down
22 changes: 21 additions & 1 deletion GLOBAL_CUSTOM_INSTRUCTIONS.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,26 @@ Prefer the active repository’s existing organization, package metadata, projec

Never invent, transfer, or imply ownership.

## First-run personalization

When the user is installing or explicitly personalizing this contract, ask
questions before making personalization decisions. Ask which clients are in
scope, whether skills are user-global or repository-scoped, which core and
optional skills are wanted, and whether existing instructions should be
preserved, receive individually approved additions, or be supplemented with
the complete contract.

Ask separately for each relevant operator-profile field: name, email, personal
site, GitHub profile, and PyPI profile. Accept “leave unset” for every field.
Explain that values placed in always-loaded instructions may be sent to the
selected model providers. Never infer identity or ownership from usernames,
Git metadata, environment files, or neighboring repositories.

If the current user instructions already provide an explicit value, treat that
value as supplied and ask only about unresolved choices or confirmation that is
material to the requested operation. Do not start this intake during ordinary
tasks when installation or personalization is not in scope.

## Instruction Priority

Follow this order:
Expand Down Expand Up @@ -227,7 +247,7 @@ When software versions materially affect the task:
1. Inspect repository manifests, lockfiles, toolchain files, engine constraints, configuration, CI, deployment files, and recorded verified resources.
2. Check authoritative first-party documentation, release notes, registries, and compatibility guidance.
3. Prefer the latest stable version compatible with the project.
4. Do not introduce prereleases or unrelated upgrades without approval.
4. Do not introduce unreleased or unrelated upgrades without approval.
5. Do not recommend older versions unless compatibility, stability, platform support, or project constraints justify them.
6. Explain breaking changes, migration work, compatibility risks, and rollback requirements.
7. Record durable version findings in `MEMORY.md`.
Expand Down
116 changes: 32 additions & 84 deletions HANDOFF.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,74 +8,35 @@
4. `ARCHITECTURE.md`
5. The authority file for the requested task

Do not begin with a repository-wide scan. Do not read or print `.env`.
Do not read or print `.env`.

## Current state

- Package version: `3.0.0-rc.5`
- Status: unreleased RC5 development; not globally runtime-verified or stable
- Branch: `main`
- Package version: `3.1.0`
- Status: stable release preparation
- Branch: `agent/stable-v3.1.0`
- Canonical remote:
`https://github.com/ImYourBoyRoy/agent-continuity-stack`
- Published prerelease:
`https://github.com/ImYourBoyRoy/agent-continuity-stack/releases/tag/v3.0.0-rc.4`
- Release tag: `v3.0.0-rc.4`
- Release commit: `0e24499b9455f1956d0e8390bbd49cf62f908e52`
- Release date: `2026-07-26`
- Release archive SHA-256:
`e159a83df32dacceb29ca93c118b2cf14b293e790ecd1b636fb33f166f059893`
- Initial public commit:
`a6b1b72059fbca5ebc8c2cd3e1308e2cb36eb118`
- Initial validation: Python `3.10` and `3.14` GitHub jobs passed
- Inventory: 14 core skills and 1 optional, default-uninstalled skill
- Installation: model-operated, status-first, and explicit-approval-only
- Public default: install selected skills while preserving all custom
instructions

The local repository name is `agent-continuity-stack`. A local `.env`
may exist for maintainer GitHub authentication; it is ignored, mode-restricted,
excluded from release inventory, and never package content.
- Public default: install selected skills while preserving custom instructions
- Inventory: 14 core skills and 1 optional, default-uninstalled skill

## Completed
## Completed in this release work

- Consolidated and independently versioned the skill inventory.
- Kept the complete Expert Agent Operating Contract as an optional canonical
template.
- Added status, plan, journal, ownership, receipt, client-status, and rollback
schemas.
- Added safe tree, archive, contract, record, and bundle validators.
- Added positive, near-miss, collision, and negative lifecycle fixtures.
- Added exact-tested Portable Web Toolkit ownership boundaries.
- Added public model-install onboarding with preserve, guided-addition, and
complete-contract modes.
- Added architecture, contribution, security, GitHub workflow, and repository
hygiene files for public development.
- Renamed the complete package identity to Agent Continuity Stack
(`agent-continuity-stack`) and bound validators to the canonical repository.
- Enabled repository security controls and protected `main` with the successful
validation contexts.
- Separated release-candidate publication gates from final stable-promotion
gates without weakening unresolved runtime, recovery, or platform
requirements.
- Published immutable annotated tag and GitHub prerelease `v3.0.0-rc.4` with
the validated ZIP and external checksum sidecar.
- Began RC5 development for verified project authorship, maintainer links,
release visibility, and focused discovery topics without moving or replacing
RC4.
- Added the reciprocal ACS link to Portable Web Toolkit and featured ACS first
in the GitHub profile README.
- Added live `agent-instructions` and `context-engineering` repository topics;
the About description already matched the documented authority.
- Made Quick Start agent-operated: the coding agent runs validation, discovers
client state, and—after explicit approval—handles backups, installation,
smoke testing, evidence, and rollback preparation.
- Configured and API-verified six ordered GitHub profile pins with ACS first,
followed by Portable Web Toolkit, pyenv-native, OllamaToolkit,
WebScraperToolkit, and Portfolio Sidekick.
- Added explicit first-run personalization questions to the canonical contract.
- Removed hard-coded client and integration software versions from the README
compatibility summary.
- Converted package metadata and validation to stable `3.1.0`.
- Replaced multiple release tracks with one stable publication checklist.
- Updated the pinned `actions/setup-python` workflow dependency and synchronized
the release inventory.
- Preserved the Antigravity two-fragment loader adapter as a functional client
requirement.
- Updated fixtures, contract hashes, release inventory, and project memory.

## Validation baseline

Run:
Run from the repository root:

```bash
python3 scripts/validate_bundle.py
Expand All @@ -84,35 +45,22 @@ python3 scripts/inspect_tree.py . --exclude .git --exclude .env
python3 tests/run_portable_tests.py
```

The last pre-commit run must be recorded in `MEMORY.md`. Source and fixture
success does not prove live installation, client discovery, rollback, or
uninstall.
The 2026-08-08 run passed with zero errors and zero warnings. This proves
source, metadata, tree safety, schemas, and portable conformance; it does not
prove every installed client's live discovery.

## Open final stable-promotion gates
## Remaining release actions

- Complete the focused immutable-backup recovery rerun.
- Runtime-test Cursor with authenticated target-version skill discovery.
- Install and runtime-test Claude Code in a disposable environment.
- Prove both Antigravity fragments load in a fresh client session.
- Validate Windows reparse-point and metadata behavior.
- Exercise the public installation prompt end to end across all supported
clients.
- Review the complete contract's always-on token cost and priority wording.

## Next recommended action

Collect the outstanding live-client, recovery, platform, and contract-review
evidence. Do not promote any candidate to final `3.0.0` until every final
stable-promotion gate in `MERGE_CHECKLIST.md` passes. Validate RC5 as a
separate candidate before any publication decision.
- Build and validate the stable archive from the clean release commit.
- Generate and independently verify the external SHA-256 sidecar.
- Commit, push, and publish the stable `v3.1.0` GitHub Release.
- Close and remove the obsolete Dependabot branch after its fix is incorporated.
- Treat deletion of any legacy remote release/tag as a separate explicitly
identified destructive operation.

## Handoff discipline

After material work:

- update `MEMORY.md` with durable facts and validation;
- update this file only when the immediate handoff changes;
- update `ARCHITECTURE.md` only for durable system-design changes;
- update `CHANGELOG.md` and versions for published behavior changes;
- leave exact blockers and the next action;
- never include credentials, private paths, logs, or transient model reasoning.
- Update `MEMORY.md` and this file with the release commit, archive name,
checksum, and GitHub URL after publication.
- Keep credentials, private paths, logs, and transient reasoning out of both
files.
Loading