Skip to content
24 changes: 13 additions & 11 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -143,6 +143,7 @@ or a sandbox.
- [Process authority and isolation](docs/integrations/authority-isolation.md)
- [Artifact binding contract](docs/integrations/artifact-bindings.md)
- [Scenario fixture contract](docs/integrations/scenario-fixtures.md)
- [Hermetic provider kit](docs/integrations/hermetic-provider-kit.md)
- [Versioned contracts](contracts/README.md)
- [Roadmap](ROADMAP.md)

Expand All @@ -152,17 +153,18 @@ skills, agents, templates, and validators used to maintain these documents.
## Status

Flow is in the **executable contract seam** phase. Issues #23, #26, #28, #36,
#38, and #40 are merged through PRs #24, #27, #35, #37, #39, and #41. Issue
#42 / PR #43 adds the final bounded parent-#25 slice: real
`trusted-unconfined` direct launch and supervision through the existing
subject, authority, and transcript gates. Issue #44 begins the parent-#29
hermetic provider kit with an immutable package and deterministic accepted
inspection artifact. Issue #45 adds its bounded selection, lifecycle, and
protocol outcome matrix; #46 retains physical artifact adversaries, graph
fixtures, and the final parent evidence matrix. The process seam still does not
implement authenticity verification, operating-system sandbox enforcement,
authenticated host evidence, descriptor-bound launch, or process-tree
containment, and the scenario contract is not an executor.
#38, #40, #42, #44, and #45 are merged through PRs #24, #27, #35, #37, #39,
#41, #43, #47, and #48. PR #60 consolidates #46's four sequential checkpoints:
physical and evidence adversaries, deterministic single- and two-provider
compositions, exact package/executable content-identity correlation, a closed
behavior catalog, and the parent #29 evidence matrix. After that PR merges and
default-branch CI is green, #46 and #29 can close and #30 becomes the next
conformance-matrix checkpoint.
The synthetic providers are not the two real adapters required to finish
FLO-Q03. The process seam still does not implement authenticity verification,
operating-system sandbox enforcement, authenticated host evidence,
descriptor-bound launch, or process-tree containment, and the scenario contract
is not an executor.
Current descriptions of Aniflow, Optiflow, and Renderflow are grounded in their default
branches as inspected on 2026-08-13. The holons remain independently released
repositories; real provider adapters and the restore-and-assess workflow remain
Expand Down
75 changes: 52 additions & 23 deletions ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,12 +3,12 @@ schema: aether.architecture-document/v1
id: flow-roadmap
title: Flow Roadmap
kind: architecture-document
version: 1.0.0
version: 1.3.0
status: draft
owners:
- egohygiene
created: 2026-08-13
updated: 2026-09-22
updated: 2026-09-24
governed_by:
- architecture-roadmap
depends_on:
Expand All @@ -30,29 +30,31 @@ repository: egohygiene/flow
visibility: public
publication: central
route: /roadmap/flow/
updated: 2026-09-22
updated: 2026-09-24
-->
## 2026-09-21 execution snapshot
## 2026-09-24 execution snapshot

> [!IMPORTANT]
> **2026-09-22 live-sweep checkpoint**
> **2026-09-24 hermetic-kit closeout checkpoint**
>
> The current suite state and strict next-up queue are preserved in
> [the 2026-09-22 live-sweep checkpoint](docs/roadmaps/flow-suite-live-sweep-2026-09-22.md).
> It supersedes stale active-checkpoint and open-count claims in this snapshot while preserving
> the evidence below as history. Flow draft PR #47 is ready for maintainer review; stacked draft
> PR #48 follows it. The immediate Optiflow lane is #88 → #89 → #90 → #91 → #92 → #96 → #93,
> followed by #94 → #95 for lossless PNG replacement.
> Flow #42, #44, and #45 are merged. Draft PR #60 consolidates #46's four
> sequential checkpoints (#56–#59), including the final hermetic-kit package
> layout/finalization, behavior, and requirement evidence. Merge #60, require
> green default-branch CI, then close #46 and #29 and hand the executable
> conformance matrix to #30.
> [The 2026-09-22 live-sweep checkpoint](docs/roadmaps/flow-suite-live-sweep-2026-09-22.md)
> remains the historical suite-wide queue; this checkpoint supersedes only its
> older Flow PR state.


> This evidence-reconciled snapshot is the issue-generation and visual-roadmap handoff. The longer-horizon strategy below remains canonical context; generated HTML, JSON, progress, issue plans, and commit lists are projections.

**Lifecycle:** executable contract prototype

**Current gate:** Complete Flow #42, the final bounded child of Flow #25: launch
one exact authorized `trusted-unconfined` provider, enforce bounded transport
and direct-child lifecycle control, and preserve the existing subject,
authority, transcript, and artifact boundaries.
**Current gate:** Review and merge Flow PR #60, then require green
default-branch CI before closing #46 and #29. Flow #30 is the exact next
checkpoint for the broader executable compatibility, artifact, provider,
diagnostic, and privacy scenario matrix.

**North-star outcome:** Federated orchestration across holons with stable provider seams, resumable work, and explicit evidence.

Expand All @@ -62,8 +64,8 @@ authority, transcript, and artifact boundaries.
**Route:** `/roadmap/flow/`
**Current publication evidence:** Architecture, contract source, merged Flow
#23 / PR #24, #26 / PR #27, #28 / PR #35, #36 / PR #37, #38 / PR #39, #40 /
PR #41, and the candidate #42 / PR #43; no executable release or Pages
publication observed.
PR #41, #42 / PR #43, #44 / PR #47, and #45 / PR #48, plus candidate #46 /
PR #60; no executable release or Pages publication observed.

Publish the public-safe projection through egohygiene.io at /roadmap/flow/. This repository owns intent and acceptance evidence; it does not add a second site deployment.

Expand Down Expand Up @@ -138,7 +140,7 @@ same acceptance gate validates a deterministic external-process transcript.
id: FLO-Q03
status: active
depends_on: [FLO-Q02]
issues: [13, 25, 28, 36, 38, 40, 42]
issues: [13, 25, 28, 29, 30, 36, 38, 40, 42]
-->
#### FLO-Q03 — Freeze conformance fixtures and implement provider adapters

Expand Down Expand Up @@ -178,9 +180,20 @@ behavior through stable error and evidence contracts.
- Flow #40 / merged PR #41 supplies exact authority/isolation preflight with
green default-branch CI at
`5f411da6e7040e3494cbd275729de9a2ed8c67a3`.
- Flow #25 remains the active owner of process enforcement. Flow #42 / PR #43
is its final bounded child and adds direct launch/supervision without
pre-empting later sandbox, durable-state, or real-adapter work.
- Flow #25 is complete through #42 / merged PR #43, which adds bounded direct
launch and supervision without claiming sandbox, durable-state, or
real-adapter behavior.
- Flow #44 / merged PR #47 establishes the immutable hermetic package and
accepted success path. Flow #45 / merged PR #48 adds its closed lifecycle and
protocol matrix.
- Flow #46 / candidate PR #60 carries the evidence intended to complete the
remaining artifact adversaries, fixed single-provider and two-provider
compositions, exact package and executable-digest correlation and tamper
rejection, the closed behavior catalog, and every parent #29 requirement
mapping. Its evidence is indexed in
[the hermetic provider kit](docs/integrations/hermetic-provider-kit.md).
- The synthetic providers are conformance infrastructure, not real adapters.
FLO-Q03 remains active for #30 and the later released-provider adapter work.

<!-- roadmap-step
id: FLO-Q04
Expand Down Expand Up @@ -339,7 +352,10 @@ kinds, and portable locators beneath one caller-selected root. Recompute file
and deterministic recursive-directory identity with Flow-owned code. Keep
provider execution validation separate from artifact acceptance, and require a
complete result plus exact invocation, result, event, binding, and host
observation correlation.
observation correlation. Bind each opaque observation token to its exact
binding snapshot and host-local canonical root, then require equal final
root-confined evidence immediately before promotion. This freshness check does
not make either observation atomic.

**Delivered evidence:** Flow #36 / merged PR #37 adds
`flow.artifact-bindings/v1`, `flow.artifact-observations/v1`, opaque observed and
Expand All @@ -348,6 +364,19 @@ adversarial filesystem/correlation tests. It does not verify executables,
enforce provider authority, launch a process, or validate provider-native
artifact semantics.

Flow #57 hardens that acceptance boundary against changed evidence and stale
binding context without changing the portable artifact schemas or assigning
authoritative digest semantics to free-form provider provenance. Flow #58 adds
fixed two-stage single-provider and two-provider compositions that hand the
exact accepted inspection artifact into a transformation stage through public
Flow boundaries and produce equal normalized evidence and bytes across fresh
roots. It remains test-owned sequencing rather than a graph scheduler. Flow #59
adds candidate closeout evidence for the exact materialized package layouts,
correlated package and executable digests across the manifest, locks, and
observations, tamper rejection, redistribution terms, behavior-to-test catalog,
parent #29 requirement matrix, residual gaps, and #30 handoff. Parent closure
waits for PR #60 to merge and default-branch CI to pass.

### Verify locked package and executable subjects

Pin exactly one package directory and one regular executable file to the
Expand Down Expand Up @@ -395,7 +424,7 @@ authorized opaque handles; supervise stdin and independently bounded output;
enforce deadline and caller cancellation with grace and escalation; reap the
direct child; and retain transcript validation as the sole promotion path.

**Candidate evidence:** Flow #42 / PR #43 adds `LocalProcessRunner`,
**Delivered evidence:** Flow #42 / merged PR #43 adds `LocalProcessRunner`,
`CancellationSignal`, bounded stdio workers, Unix `SIGTERM` grace and forced
escalation, typed interruption, direct-child reap proof, and real-process
positive/adversarial tests. It does not provide a sandbox, descendant
Expand Down
2 changes: 1 addition & 1 deletion contracts/fixtures/scenarios/canonical-digests.v1.json
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@
},
{
"path": "fixtures/scenarios/multi-provider.v1.fixture.json",
"digest": "cbf8a6e6b436a20438661abb9f0b17206e720b08027f7efc1cd3c19b21493e2c"
"digest": "0f813edfe5492236ebd66f72e5861960afa9047b74e1a5cc8acf989f0fa64186"
},
{
"path": "fixtures/scenarios/observed-empty.v1.fixture.json",
Expand Down
29 changes: 16 additions & 13 deletions contracts/fixtures/scenarios/multi-provider.v1.fixture.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@
"schema_version": "flow.scenario-manifest/v1",
"scenario_id": "scenario:multi-provider-handoff",
"fixture_id": "fixture:multi-provider-handoff-v1",
"fixture_version": "1.0.0",
"fixture_version": "1.1.0",
"title": "Hermetic multi-provider handoff",
"description": "Describes an ordered inspect-then-render handoff through two independently identified synthetic providers.",
"description": "Describes an ordered inspect-then-transform handoff through two independently identified synthetic providers using only Flow-owned fake capabilities.",
"fixture_class": "valid",
"tags": ["clean-room", "multi-provider", "success"],
"inputs": [
Expand Down Expand Up @@ -52,7 +52,7 @@
"parameters_digest": "6161616161616161616161616161616161616161616161616161616161616161"
}
},
"required_capabilities": ["optiflow/inspect-artifact"]
"required_capabilities": ["flow/inspect-fixture"]
},
{
"provider_id": "org.egohygiene.synthetic-renderer",
Expand All @@ -75,33 +75,33 @@
"parameters_digest": "9191919191919191919191919191919191919191919191919191919191919191"
}
},
"required_capabilities": ["renderflow/render-synthetic-document"]
"required_capabilities": ["flow/transform-fixture"]
}
],
"stages": [
{
"stage_id": "inspect",
"provider_id": "org.egohygiene.synthetic-inspector",
"capability_id": "optiflow/inspect-artifact",
"capability_id": "flow/inspect-fixture",
"depends_on": [],
"consumes": ["source-document"],
"produces": ["inspection-evidence"],
"produces": ["inspection-report"],
"required": true
},
{
"stage_id": "render",
"stage_id": "transform",
"provider_id": "org.egohygiene.synthetic-renderer",
"capability_id": "renderflow/render-synthetic-document",
"capability_id": "flow/transform-fixture",
"depends_on": ["inspect"],
"consumes": ["inspection-evidence", "source-document"],
"produces": ["rendered-document"],
"consumes": ["inspection-report"],
"produces": ["transformation-report"],
"required": true
}
],
"expectation": {
"terminal_state": "complete",
"evidence_state": "complete",
"expected_artifacts": ["inspection-evidence", "rendered-document"],
"expected_artifacts": ["inspection-report", "transformation-report"],
"expected_diagnostics": [],
"evidence_refs": [
{
Expand Down Expand Up @@ -130,8 +130,11 @@
"covered_behaviors": [
"cross-provider immutable artifact handoff",
"deterministic topological stage order",
"two-provider capability references"
"two-provider Flow-owned fake capability references"
],
"known_gaps": ["Uses synthetic package references rather than released holon binaries."]
"known_gaps": [
"This manifest remains declarative; the hermetic provider kit separately executes its aligned two-stage composition without making the manifest a runtime plan.",
"Uses synthetic package references rather than released holon binaries."
]
}
}
43 changes: 30 additions & 13 deletions docs/architecture/foundation/ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,12 +3,12 @@ schema: aether.architecture-document/v1
id: flow-architecture
title: Flow Architecture
kind: architecture-document
version: 0.9.0
version: 0.11.0
status: draft
owners:
- egohygiene
created: 2026-08-13
updated: 2026-09-21
updated: 2026-09-24
governed_by:
- architecture-architecture
depends_on:
Expand Down Expand Up @@ -73,9 +73,13 @@ Artifact bindings remain separate from path-independent extension envelopes.
A Flow-owned binding set maps immutable input and candidate-output identities to
logical ports, media types, kinds, and portable root-relative locators for one
run. A Flow observer computes file or recursive directory identity beneath one
caller-selected root. Only the separate artifact-acceptance gate can correlate
those observations with resolved capability, invocation, event, and terminal
result evidence.
caller-selected root. Its opaque token privately retains the exact binding
snapshot and absolute canonical root while omitting that sensitive host context
from portable evidence and manual `Debug` output. Only the separate artifact-
acceptance gate can correlate those observations with resolved capability,
invocation, event, and terminal result evidence. Immediately before promotion,
the gate re-observes the retained root and requires the portable evidence to
remain equal.

Process execution subjects are a third, distinct boundary. A Flow-owned lock
pins one package directory and one regular executable file to an exact
Expand Down Expand Up @@ -231,13 +235,24 @@ required by both process seams. Issue #40 adds exact process authority and
isolation profiles, caller-attested enforcement evidence, and a second opaque
token required by both process seams. Issue #42 adds the bounded local
trusted-unconfined runner, direct transport workers, timeout/cancellation grace
and escalation, and direct-child reaping. Flow does not yet supply the public
CLI, real holon adapters, signature or transparency verification,
provider-native artifact validation, an operating-system sandbox or
authenticated enforcement evidence, descriptor-bound execution, process-tree
containment, durable run state, checkpoints, retry, or resume. Structural units
beyond these library seams remain constraints for later adapter and
orchestration work, not claims about current source layout.
and escalation, and direct-child reaping. Issue #57 binds an opaque artifact
observation to its exact binding snapshot and canonical root and requires an
equal final observation before acceptance, without changing portable artifact
schemas or free-form extension-result v1 provenance. Issue #58 adds a test-owned
fixed `inspect`-then-`transform` sequencer that runs both single-provider and
two-provider compositions through public resolution, subject observation,
authority, local-process execution, artifact observation, and acceptance. The
second stage consumes the exact accepted first-stage artifact in the same
workspace, and two fresh roots must produce equal portable evidence and output
bytes. This is conformance infrastructure, not a scenario-manifest executor or
production graph scheduler. Flow does not yet supply
the public CLI, real holon adapters, signature or transparency verification,
provider-native artifact validation, an atomic filesystem snapshot, an
operating-system sandbox or authenticated enforcement evidence,
descriptor-bound execution, process-tree containment, durable run state,
checkpoints, retry, or resume. Structural units beyond these library seams
remain constraints for later adapter and orchestration work, not claims about
current source layout.

## Open questions

Expand All @@ -263,4 +278,6 @@ authenticated sandbox conformance, descriptor-bound launch, process-tree
containment, provider-native artifact validation, and scenario execution remain
later gates for their corresponding runtime surfaces. Issue #42 adds real Unix
direct-child conformance for literal launch state, supervised transport,
overflow, interruption, grace, escalation, and reaping.
overflow, interruption, grace, escalation, and reaping. Issue #58 additionally
validates deterministic fixed-order composition without adding plan/run state,
retry, checkpoint, resume, or real holon algorithms.
Loading
Loading