Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,9 @@ product orchestrator, CLI, real provider adapter, operating-system sandbox,
general scenario executor, automatic recovery scheduler, or public resume CLI.
Prepared process execution now has [durable run state](docs/integrations/durable-state.md)
with immutable plans, atomic snapshots, verified checkpoints, status inspection,
and explicit recovery decisions.
explicit recovery decisions, and fresh dependency-graph assessment before
caller-selected downstream execution. Stale prerequisites invalidate their
descendants for reuse while unrelated valid branches retain their eligibility.

## Executable checkpoint

Expand Down
19 changes: 14 additions & 5 deletions ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,12 +3,12 @@ schema: aether.architecture-document/v1
id: flow-roadmap
title: Flow Roadmap
kind: architecture-document
version: 1.3.2
version: 1.3.3
status: draft
owners:
- egohygiene
created: 2026-08-13
updated: 2026-09-25
updated: 2026-09-26
governed_by:
- architecture-roadmap
depends_on:
Expand All @@ -23,7 +23,7 @@ supersedes: []

# Flow Roadmap

## 2026-09-25 live suite handoff
## 2026-09-26 live suite handoff

> [!IMPORTANT]
> This is the current near-term execution handoff for agents. It supersedes
Expand All @@ -36,10 +36,18 @@ supersedes: []
Its [acceptance matrix](docs/integrations/acceptance-scenarios.md) proves 81
scenarios twice on Rust 1.85 and stable.

The #49 review candidate adds [durable prepared execution](docs/integrations/durable-state.md):
#49 merged through [PR #63](https://github.com/egohygiene/flow/pull/63) at
`711fbe3c19c0e080ab6c67b74d7945cd29675a74`, with
[default-branch CI green](https://github.com/egohygiene/flow/actions/runs/36213631491).
It adds [durable prepared execution](docs/integrations/durable-state.md):
versioned plans and state, atomic immutable snapshots, workspace locking,
accepted checkpoints, fresh resume eligibility, and explicit recovery decisions.
After this candidate merges and the default-branch gate passes, #31 is next.
#31 is active through three dependency-ordered review checkpoints:
[#64](https://github.com/egohygiene/flow/issues/64) adds fresh graph assessment and
safe dependent execution; [#65](https://github.com/egohygiene/flow/issues/65) adds
the deterministic durable lifecycle corpus; [#66](https://github.com/egohygiene/flow/issues/66)
proves authority, duplicate-effect prevention, and recovery residuals. Land one
review PR and verify default-branch CI before starting the next checkpoint.
FLO-Q03 remains active until real released-provider adapters satisfy its
remaining exit criteria. [#62](https://github.com/egohygiene/flow/issues/62) is
later documentation visualization work and does not block this sequence.
Expand All @@ -53,6 +61,7 @@ later documentation visualization work and does not block this sequence.
recovery state.
3. [#31](https://github.com/egohygiene/flow/issues/31) — prove interruption,
retry, resume, invalidation, and authority transitions against durable state.
Ordered children: #64 → #65 → #66; the parent remains open until all pass.
4. After #49, integrate immutable provider releases as they become available:
[#50](https://github.com/egohygiene/flow/issues/50) for Optiflow,
[#52](https://github.com/egohygiene/flow/issues/52) for Renderflow, and
Expand Down
3 changes: 2 additions & 1 deletion contracts/README.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Flow contract set

This directory contains Flow-owned suite interchange contracts. The initial
contract set is version `0.7.0`, status `provisional`, in the v1 compatibility
contract set is version `0.8.0`, status `provisional`, in the v1 compatibility
family. Provisional means versioned and testable, not stable for production.

| Contract | Purpose |
Expand Down Expand Up @@ -30,6 +30,7 @@ family. Provisional means versioned and testable, not stable for production.
| `flow.run-validation/v1` | accepted evidence and validator implementation identities |
| `flow.run-recovery/v1` | explicit retry/abandon decision and uncertainty acknowledgement |
| `flow.run-snapshot/v1` | atomic-storage envelope with state integrity digest |
| `flow.run-assessment/v1` | read-only current graph eligibility correlated to exact saved state |

`contract-set.v1.json` is the machine-readable index. Schemas live in
`schemas/`; deterministic examples live in `examples/`; extension compatibility
Expand Down
10 changes: 9 additions & 1 deletion contracts/contract-set.v1.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"schema_version": "flow.contract-set/v1",
"contract_set_version": "0.7.0",
"contract_set_version": "0.8.0",
"status": "provisional",
"contracts": [
{
Expand Down Expand Up @@ -191,6 +191,14 @@
"invalid_examples": [
"fixtures/state/run-snapshot.v2.invalid.json"
]
},
{
"id": "flow.run-assessment/v1",
"schema": "schemas/run-assessment.v1.schema.json",
"example": "examples/run-assessment.v1.example.json",
"invalid_examples": [
"fixtures/state/run-assessment.v2.invalid.json"
]
}
]
}
15 changes: 15 additions & 0 deletions contracts/examples/run-assessment.v1.example.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
{
"schema_version": "flow.run-assessment/v1",
"plan_digest": "0e91d3a2af624fd222d6cf2aa1b005b8d9b3ad2f3e9951cde35b2e9e99b102d1",
"state_digest": "8796604491ccdbab553b73b319608fbbc824da503645927e810b7577a40442d3",
"sequence": 0,
"steps": [
{
"step_id": "step:inspect",
"recorded_status": "pending",
"eligibility": "ready",
"stale_boundary": null,
"blocked_by": []
}
]
}
15 changes: 15 additions & 0 deletions contracts/fixtures/state/run-assessment.v2.invalid.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
{
"schema_version": "flow.run-assessment/v2",
"plan_digest": "0e91d3a2af624fd222d6cf2aa1b005b8d9b3ad2f3e9951cde35b2e9e99b102d1",
"state_digest": "8796604491ccdbab553b73b319608fbbc824da503645927e810b7577a40442d3",
"sequence": 0,
"steps": [
{
"step_id": "step:inspect",
"recorded_status": "pending",
"eligibility": "ready",
"stale_boundary": null,
"blocked_by": []
}
]
}
106 changes: 106 additions & 0 deletions contracts/schemas/run-assessment.v1.schema.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,106 @@
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://egohygiene.github.io/flow/contracts/run-assessment.v1.schema.json",
"title": "Flow run assessment v1",
"type": "object",
"additionalProperties": false,
"required": [
"schema_version",
"plan_digest",
"state_digest",
"sequence",
"steps"
],
"properties": {
"schema_version": {
"const": "flow.run-assessment/v1"
},
"plan_digest": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"state_digest": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"sequence": {
"type": "integer",
"minimum": 0,
"maximum": 4095
},
"steps": {
"type": "array",
"minItems": 1,
"maxItems": 256,
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"step_id",
"recorded_status",
"eligibility",
"stale_boundary",
"blocked_by"
],
"properties": {
"step_id": {
"type": "string",
"maxLength": 160,
"pattern": "^step:[a-z0-9][a-z0-9._-]*$"
},
"recorded_status": {
"enum": [
"pending",
"running",
"succeeded",
"failed",
"cancelled",
"denied",
"abandoned"
]
},
"eligibility": {
"enum": [
"ready",
"reusable",
"invalidated",
"dependency-blocked",
"approval-required",
"abandoned"
]
},
"stale_boundary": {
"anyOf": [
{
"enum": [
"invocation",
"provider",
"capability",
"configuration",
"authority",
"bindings",
"inputs",
"artifacts",
"validation"
]
},
{
"type": "null"
}
]
},
"blocked_by": {
"type": "array",
"maxItems": 256,
"uniqueItems": true,
"items": {
"type": "string",
"maxLength": 160,
"pattern": "^step:[a-z0-9][a-z0-9._-]*$"
}
}
}
}
}
}
}
22 changes: 16 additions & 6 deletions docs/architecture/foundation/ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,12 +3,12 @@ schema: aether.architecture-document/v1
id: flow-architecture
title: Flow Architecture
kind: architecture-document
version: 0.12.0
version: 0.13.0
status: draft
owners:
- egohygiene
created: 2026-08-13
updated: 2026-09-25
updated: 2026-09-26
governed_by:
- architecture-architecture
depends_on:
Expand Down Expand Up @@ -121,9 +121,17 @@ State contains typed decisions, identities, relative artifact bindings, and
allowlisted validation evidence. Secret values, configuration values, raw process
streams, and provider-authored messages remain outside the store. The workspace
is trusted local state, not a cryptographically authenticated or sandboxed store.
ADR-0011 owns the persistence, migration, and recovery rationale. Graph scheduling,
automatic retry, provider-native checkpoints, and downstream invalidation policy
remain later orchestration work.
ADR-0011 owns the persistence, migration, and recovery rationale. ADR-0012 adds
read-only graph assessment: a complete current context inventory and the exact
saved plan are required before classifying every step in dependency order.
Completed prerequisites must be freshly reusable, not merely historically
succeeded. Stale evidence invalidates that step and every descendant for reuse;
unrelated branches retain their independently assessed eligibility. Pending or
unresolved prerequisites block their descendants. These assessments never rewrite
accepted history or grant execution authority. Dependent execution recomputes
the assessment, and single-step entry points refuse dependent steps. Automatic
scheduling, retry, cross-plan migration, and provider-native checkpoints remain
later orchestration work.

### External adapters

Expand Down Expand Up @@ -271,7 +279,9 @@ workspace, and two fresh roots must produce equal portable evidence and output
bytes. This is conformance infrastructure, not a scenario-manifest executor or
production graph scheduler. Issue #49 adds the versioned durable coordinator,
immutable prepared plans, atomic snapshots, accepted checkpoints, fresh reuse
assessment, and explicit recovery decisions described above. Flow does not yet supply
assessment, and explicit recovery decisions described above. Issue #64 requires
fresh prerequisite evidence for graph assessment and dependent execution without
adding a scheduler or rewriting accepted history. Flow does not yet supply
the public CLI, real holon adapters, signature or transparency verification,
provider-native artifact validation, an atomic filesystem snapshot, an
operating-system sandbox or authenticated enforcement evidence,
Expand Down
7 changes: 5 additions & 2 deletions docs/architecture/governance/DECISIONS.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,12 +3,12 @@ schema: aether.architecture-document/v1
id: flow-decisions
title: Flow Decisions
kind: architecture-document
version: 0.9.0
version: 0.10.0
status: draft
owners:
- egohygiene
created: 2026-08-13
updated: 2026-09-25
updated: 2026-09-26
governed_by:
- architecture-decisions
depends_on:
Expand Down Expand Up @@ -65,10 +65,13 @@ justifies separate ADRs.
| [ADR-0009](decisions/ADR-0009-process-authority-isolation.md) | Bind process authority to explicit isolation evidence | Accepted | 2026-09-21 | None | A real sandbox, authenticated host evidence, or new authority dimension changes the preflight boundary |
| [ADR-0010](decisions/ADR-0010-bounded-direct-process-supervision.md) | Bound direct provider launch and supervision | Accepted | 2026-09-21 | None | Sandbox enforcement, descriptor-bound launch, process-tree containment, or durable interruption changes the runner boundary |
| [ADR-0011](decisions/ADR-0011-durable-run-state.md) | Persist prepared intent and acceptance in immutable local snapshots | Proposed | Pending review | None | Migration, distributed writers, automatic recovery, authenticated state, or stronger durability changes the boundary |
| [ADR-0012](decisions/ADR-0012-fresh-graph-assessment.md) | Require fresh prerequisite evidence for durable graph execution | Proposed | Pending review | None | Scheduling, cross-plan reuse, or concurrent artifact mutation changes the assessment boundary |

## Active decisions

ADR-0011 is proposed with Flow #49 and remains subject to maintainer review.
Its implementation merged in PR #63. ADR-0012 is proposed with Flow #64, the
first bounded checkpoint under #31.

The indexed ADRs are authoritative. Summaries in other documents must link back
to them rather than recreate rationale.
Expand Down
Loading
Loading