Skip to content

Commit fe52830

Browse files
yjwyjw
authored andcommitted
release: ship aet v1.4.0 trace artifacts
1 parent ef275a7 commit fe52830

17 files changed

Lines changed: 361 additions & 31 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,4 +13,4 @@ jobs:
1313
- run: uv run --no-editable --reinstall-package agent-engineering-toolkit python -m unittest discover -s tests -v
1414
- run: uv run --no-editable aet audit . --strict --format json --output .aet/evidence/audit.json
1515
- run: uv build
16-
- run: uv run --isolated --with dist/agent_engineering_toolkit-1.3.0-py3-none-any.whl aet --version
16+
- run: uv run --isolated --with dist/agent_engineering_toolkit-1.4.0-py3-none-any.whl aet --version

‎CHANGELOG.md‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,24 @@
22

33
## Unreleased
44

5+
## 1.4.0 — 2026-07-12
6+
7+
- Added repeatable `aet trace --artifact <relative-path>` for explicitly
8+
declared UTF-8 reports generated by a traced command, including pytest JUnit
9+
XML. AET redacts report content before persisting it and embeds the redacted
10+
artifact plus SHA-256 in the portable Evidence Pack.
11+
- Trace rejects absolute/outside-workspace artifact declarations. A missing,
12+
non-regular, undecodable, or unredactable declared report is recorded as
13+
`UNKNOWN`; a successful command then returns a non-zero Trace exit without
14+
rewriting the child command's successful execution result. Such a Trace also
15+
cannot advance a Run to `PROVEN` or mark a bound proof as complete.
16+
- Added regression coverage for redacted report capture, portable-pack
17+
inclusion, missing artifacts, and outside-workspace rejection. This closes
18+
the evidence gap found while tracing Invest-Vault's pytest delivery proof.
19+
- Constrained optional pytest discovery to AET's first-party `tests/` directory
20+
so nested dogfood repositories are not accidentally collected into AET's
21+
own test report.
22+
523
## 1.3.0 — 2026-07-12
624

725
- Added an optional, deterministic **Context Manifest**: `aet context discover`

‎PROJECT_MEMORY.md‎

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -307,3 +307,24 @@ deterministic core.
307307
path, as well as direct supersession. The v1.3 release gate requires 27 unit
308308
tests, strict self-audit, reviewed intent, a proof-bound Trace/Evidence Pack,
309309
and an isolated wheel smoke test.
310+
311+
## v1.4.0 implementation and release candidate — 2026-07-12
312+
313+
- Invest-Vault dogfood confirmed that v1.3 Trace successfully ran its complete
314+
pytest process; the gap was report portability, not subprocess execution.
315+
Trace held stdout/stderr but not a test framework's generated report.
316+
- Added explicit `trace --artifact <relative-path>` capture. It is not a
317+
report-file guesser: only a declared regular UTF-8 file under the workspace
318+
is captured, redacted, hashed, and embedded into Trace plus Evidence Pack.
319+
- A missing, outside-root, non-regular, undecodable, or unredactable declared
320+
artifact is `UNKNOWN`. AET returns non-zero after an otherwise successful
321+
child command, while preserving the child's `execution: PASS` fact.
322+
- A real pytest dogfood trace initially exposed unrelated collection of nested
323+
`work/dogfood` repositories. `pyproject.toml` now limits optional pytest
324+
discovery to AET's own `tests/` directory.
325+
- This adopts the useful Harness Engineering idea of durable, inspectable
326+
filesystem artifacts and failure traces. It explicitly rejects the article's
327+
broader runtime, autonomous optimization, and generic-memory directions.
328+
- The v1.4 release gate requires 30 unit tests, a real pytest JUnit artifact
329+
dogfood trace/pack, strict self-audit, reviewed intent, a proof-bound release
330+
Evidence Pack, and an isolated wheel smoke test.

‎README.md‎

Lines changed: 27 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ what was declared, what was explicitly executed, and what remains unknown.
3939
| --- | --- | --- |
4040
| Can this agent safely follow the repository instructions and Skills? | `aet audit` | Markdown, JSON, or SARIF findings with locations and fixes. |
4141
| Is the diff inside the human-approved intent? | `aet review` | An intent-gate report for path budget, allowed paths, and declared proofs. |
42-
| Did the command run against the reviewed workspace? | `aet trace` + `aet evidence pack` | A redacted execution record plus proof and workspace-snapshot bindings. |
42+
| Did the command run against the reviewed workspace, and did it produce its declared test report? | `aet trace --artifact` + `aet evidence pack` | A redacted execution record, explicitly captured report, plus proof and workspace-snapshot bindings. |
4343
| What delivery stage is this evidence chain in, and did it become stale? | `aet run` | An optional append-only Run Manifest with explicit lifecycle states. |
4444
| Which local instructions/references were available, and what was only claimed as read? | `aet context` | A hash-bound Context Manifest; read declarations are explicit attestations. |
4545
| Which project decisions have local sources, and which records supersede them? | `aet decision` | A source-hash Decision Ledger with verification and supersession history. |
@@ -165,11 +165,11 @@ AET deliberately reports a status matrix rather than a synthetic “agent trust
165165
score.” Its only numeric model, `aet triage`, exposes its weights and is used
166166
only to order remediation work.
167167

168-
| Release check | v1.3.0 result | How to reproduce |
168+
| Release check | v1.4.0 result | How to reproduce |
169169
| --- | --- | --- |
170-
| Regression suite | 27 tests passed | `uv run --no-editable --reinstall-package agent-engineering-toolkit python -m unittest discover -s tests -v` |
170+
| Regression suite | 30 tests passed | `uv run --no-editable --reinstall-package agent-engineering-toolkit python -m unittest discover -s tests -v` |
171171
| Strict self-audit | 0 `FAIL`, 0 `UNKNOWN` in the configured production Skill scope | `uv run --no-editable aet audit . --strict` |
172-
| Intent review | Release diff must stay inside the reviewed contract | `uv run --no-editable aet review . --base v1.1.0 --intent aet.intent.json` |
172+
| Intent review | Release diff must stay inside the reviewed contract | `uv run --no-editable aet review . --base v1.3.0 --intent aet.intent.json` |
173173
| Distribution smoke | Wheel built and invoked in an isolated environment | `uv build` then install the wheel shown below |
174174
| Delivery automation | CI on `main`, plus tag-driven GitHub Release workflow | [Actions](https://github.com/AdvancingTitans/agent-engineering-toolkit/actions) |
175175

@@ -185,7 +185,7 @@ what AET does and does not claim.
185185
Install the published GitHub Release wheel with [uv](https://docs.astral.sh/uv/):
186186

187187
```bash
188-
uv tool install https://github.com/AdvancingTitans/agent-engineering-toolkit/releases/download/v1.3.0/agent_engineering_toolkit-1.3.0-py3-none-any.whl
188+
uv tool install https://github.com/AdvancingTitans/agent-engineering-toolkit/releases/download/v1.4.0/agent_engineering_toolkit-1.4.0-py3-none-any.whl
189189
aet --version
190190
```
191191

@@ -265,6 +265,28 @@ Trace is opt-in, requires `--`, records only the explicit command, and stores
265265
redacted excerpts plus hashes. The static viewer needs no server or external
266266
assets.
267267

268+
### Capture a declared pytest report
269+
270+
`trace` never guesses which files a command wrote. When a test report matters
271+
to the delivery claim, declare the workspace-relative path explicitly. AET
272+
captures the completed UTF-8 text report only after the command exits, redacts
273+
it before persistence, and embeds it in the portable Evidence Pack.
274+
275+
```bash
276+
aet trace --artifact reports/junit.xml --output .aet/evidence/pytest-trace.json -- \
277+
pytest --junitxml=reports/junit.xml
278+
aet evidence pack --trace .aet/evidence/pytest-trace.json \
279+
--output .aet/evidence/evidence-pack.json
280+
```
281+
282+
Absolute, outside-workspace, missing, non-regular, undecodable, or
283+
unredactable artifacts are `UNKNOWN`; if one was explicitly requested, Trace
284+
returns non-zero even when pytest itself exited zero. This preserves the two
285+
facts separately: the command ran, but its requested report was not safely
286+
captured. A bound proof with that artifact gap remains `UNKNOWN` and cannot
287+
advance a Run to `PROVEN`. Stdout and stderr remain excerpt-and-digest only; full report content
288+
enters a pack solely through this explicit opt-in.
289+
268290
### 4. Optionally record a delivery lifecycle
269291

270292
```bash

‎aet.intent.json‎

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
2-
"intent": "Release v1.3.0 with deterministic Context Manifests, explicit read-attestation boundaries, and source-backed Decision Ledgers without adding an Agent runtime or generic memory system.",
2+
"intent": "Release v1.4.0 with explicit, redacted capture of declared command-generated text reports so pytest evidence can travel in an Evidence Pack without adding an Agent runtime or guessing output files.",
33
"changed_path_budget": 20,
44
"allowed_paths": [
55
"aet.intent.json",
@@ -23,9 +23,8 @@
2323
"command": "uv run --no-editable --reinstall-package agent-engineering-toolkit python -m unittest discover -s tests -v",
2424
"evidence": [
2525
"README.md",
26-
"src/aet/context.py",
27-
"src/aet/decision.py",
28-
"tests/test_productization.py"
26+
"src/aet/evidence.py",
27+
"tests/test_audit.py"
2928
]
3029
}
3130
]

‎docs/README.zh-CN.md‎

Lines changed: 24 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ AET 是 Agent 工作与“已经就绪”这个结论之间的一层小而确定
3434
| --- | --- | --- |
3535
| 这个 Agent 能安全地遵循当前指令和 Skill 吗? | `aet audit` | 带位置和修复建议的 Markdown、JSON 或 SARIF。 |
3636
| 这次 diff 是否在人工批准的意图范围内? | `aet review` | 路径预算、允许路径和已声明 proof 的 Intent Gate 报告。 |
37-
| 这条命令是在已审查的工作区运行的吗? | `aet trace` + `aet evidence pack` | 脱敏执行记录,以及 proof / 工作区快照绑定。 |
37+
| 这条命令是否在已审查工作区运行,并生成了声明的测试报告? | `aet trace --artifact` + `aet evidence pack` | 脱敏执行记录、显式捕获的报告,以及 proof / 工作区快照绑定。 |
3838
| 这份交付证据正处于哪个阶段,是否已经过期? | `aet run` | 可选、append-only 的 Run Manifest 与明确生命周期状态。 |
3939
| 哪些本地指令/参考资料可用,哪些只是被声明为已读? | `aet context` | 哈希绑定的 Context Manifest;读取声明是显式 attestation。 |
4040
| 哪些项目决策有本地来源,哪条记录已替代它? | `aet decision` | 带来源哈希、验证和 supersession 历史的 Decision Ledger。 |
@@ -145,11 +145,11 @@ Decision Ledger 是给维护者使用的、带来源的轻量项目记忆,不
145145
AET 故意展示 status matrix,而不是“Agent 信任度总分”。唯一有权重的模型是
146146
`aet triage`,它会公开因素和版本,并且只用于修复排序。
147147

148-
| Release 检查 | v1.3.0 实测结果 | 复现方式 |
148+
| Release 检查 | v1.4.0 实测结果 | 复现方式 |
149149
| --- | --- | --- |
150-
| 回归测试 | 27 项测试通过 | `uv run --no-editable --reinstall-package agent-engineering-toolkit python -m unittest discover -s tests -v` |
150+
| 回归测试 | 30 项测试通过 | `uv run --no-editable --reinstall-package agent-engineering-toolkit python -m unittest discover -s tests -v` |
151151
| 严格自审 | 在配置的 production Skill 范围内为 0 `FAIL`、0 `UNKNOWN` | `uv run --no-editable aet audit . --strict` |
152-
| Intent Review | 发布 diff 必须在已审阅合同范围内 | `uv run --no-editable aet review . --base v1.1.0 --intent aet.intent.json` |
152+
| Intent Review | 发布 diff 必须在已审阅合同范围内 | `uv run --no-editable aet review . --base v1.3.0 --intent aet.intent.json` |
153153
| 分发冒烟 | 成功构建 wheel,并在隔离环境中调用 | `uv build` 后安装上方 wheel |
154154
| 自动交付 | `main` 上 CI,`v*` tag 触发 GitHub Release | [Actions](https://github.com/AdvancingTitans/agent-engineering-toolkit/actions) |
155155

@@ -163,7 +163,7 @@ AET 故意展示 status matrix,而不是“Agent 信任度总分”。唯一
163163
使用 [uv](https://docs.astral.sh/uv/) 安装 GitHub Release wheel:
164164

165165
```bash
166-
uv tool install https://github.com/AdvancingTitans/agent-engineering-toolkit/releases/download/v1.3.0/agent_engineering_toolkit-1.3.0-py3-none-any.whl
166+
uv tool install https://github.com/AdvancingTitans/agent-engineering-toolkit/releases/download/v1.4.0/agent_engineering_toolkit-1.4.0-py3-none-any.whl
167167
aet --version
168168
```
169169

@@ -240,6 +240,25 @@ aet evidence viewer --pack .aet/evidence/evidence-pack.json \
240240
Trace 是 opt-in,要求 `--`,只记录显式命令;保存的是脱敏片段和内容哈希。静态 viewer
241241
不需要服务器或外部资产。
242242

243+
### 捕获显式声明的 pytest 报告
244+
245+
`trace` 不会猜测命令写出了哪些文件。若测试报告属于交付结论,必须显式声明其相对于
246+
工作区的路径。命令结束后,AET 才读取完整 UTF-8 文本报告、先脱敏再持久化,并将其嵌入
247+
可携带的 Evidence Pack。
248+
249+
```bash
250+
aet trace --artifact reports/junit.xml --output .aet/evidence/pytest-trace.json -- \
251+
pytest --junitxml=reports/junit.xml
252+
aet evidence pack --trace .aet/evidence/pytest-trace.json \
253+
--output .aet/evidence/evidence-pack.json
254+
```
255+
256+
绝对路径、工作区外路径、缺失、非常规文件、无法解码或无法安全脱敏的产物均为
257+
`UNKNOWN`。只要显式请求的产物未被安全捕获,即使 pytest 本身返回 0,Trace 也会返回
258+
非零。这样能分别保留两个事实:命令确实执行过,但请求的报告并未被安全保留。stdout 与
259+
stderr 仍只保存片段和 hash;此时绑定 proof 仍为 `UNKNOWN`,Run 也不会推进到 `PROVEN`。
260+
完整报告仅在用户明确 opt-in 后才会进入 Pack。
261+
243262
### 4. 可选:记录交付生命周期
244263

245264
```bash

‎docs/productization-plan.md‎

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -482,3 +482,24 @@ Evidence IR。
482482
不采用 LangGraph、XState、工作流引擎、embedding、向量数据库、RAG、后台记忆 Agent 或
483483
宿主控制器。状态机文章提供的是白名单迁移和显式状态的表达法;这里以小型命令和 JSON
484484
ledger 吸收该思想,绝不将 AET 变成 Runtime。
485+
486+
## v1.4 决策:显式 Trace 产物捕获(2026-07-12)
487+
488+
Invest-Vault 的真实 dogfood 证明了一个缺口:`aet trace` 可以执行完整 pytest 子进程,
489+
但 v1.3 只带回 stdout/stderr,无法让 Evidence Pack 携带 pytest 生成的 JUnit、HTML 或
490+
JSON 报告。命令成功不等于报告已生成、仍在原路径、且可安全复核。
491+
492+
Harness Engineering 对 AET 的可取之处是“把长期运行的可检查产物保留在文件系统,并把
493+
失败轨迹也留为可读状态”;不应因此把 AET 改造成自我改进 Agent 或工作流调度器。于是采用
494+
最小、显式的 `aet trace --artifact <relative-path>`:命令结束后才读取声明的工作区内 UTF-8
495+
文本文件,先脱敏,再将完整脱敏文本与 SHA-256 嵌入 Trace 和 Pack。
496+
497+
| 情况 | Trace 中的事实 | CLI 退出码 |
498+
| --- | --- | --- |
499+
| 命令成功,声明报告安全捕获 | execution `PASS`,artifact `PASS` | 0 |
500+
| 命令成功,报告缺失/越界/非文件/无法安全读取 | execution `PASS`,artifact `UNKNOWN` | 非 0 |
501+
| 命令失败 | execution `FAIL` | 子进程的非 0 |
502+
503+
不自动猜测 pytest 输出文件、不解析具体测试框架格式、不捕获目录或二进制文件,也不把
504+
未经显式请求的完整 stdout/stderr 放入 Pack。这既提供端到端的报告证据,又维持 Trace 的
505+
副作用边界、最小采集和隐私默认值。

‎docs/security-and-retention.md‎

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,13 @@
22

33
- `audit`, `review`, `triage`, and local `evolve` are read-only.
44
- `trace` is the only generic command executor. It requires `--`, records the
5-
explicit argv, and writes redacted logs plus digests.
5+
explicit argv, and writes redacted logs plus digests. `--artifact` is a
6+
separate explicit opt-in for one workspace-relative UTF-8 text report; the
7+
report is redacted before it enters Trace or an Evidence Pack. stdout and
8+
stderr remain excerpt-and-digest only.
9+
- Artifact paths may not be absolute or resolve outside the workspace. Missing,
10+
non-regular, undecodable, and unredactable artifacts remain `UNKNOWN` and
11+
make an otherwise successful Trace invocation return non-zero.
612
- `evolve --remote github` is opt-in and records endpoint, retrieval time,
713
status, and payload hash in its source manifest. No network access occurs by
814
default.

0 commit comments

Comments
 (0)