Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 6 additions & 6 deletions .github/workflows/coordination.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,10 +30,10 @@ jobs:
group: daimon-coordination-mutations
cancel-in-progress: false
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
with:
ref: ${{ github.event.repository.default_branch }}
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
with:
python-version: "3.12"
cache: pip
Expand All @@ -60,10 +60,10 @@ jobs:
group: daimon-coordination-mutations
cancel-in-progress: false
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
with:
ref: ${{ github.event.repository.default_branch }}
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
with:
python-version: "3.12"
cache: pip
Expand All @@ -86,7 +86,7 @@ jobs:
issues: read
pull-requests: read
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
with:
ref: ${{ github.event.repository.default_branch }}
- name: Detect coordination baseline
Expand All @@ -96,7 +96,7 @@ jobs:
if [[ -f tools/github_coordination.py && -f coordination/principals.json ]];
then echo 'enabled=true' >> "$GITHUB_OUTPUT";
else echo 'enabled=false' >> "$GITHUB_OUTPUT"; fi
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
if: steps.coordination.outputs.enabled == 'true'
with:
python-version: "3.12"
Expand Down
78 changes: 56 additions & 22 deletions .github/workflows/tests.yml

Large diffs are not rendered by default.

9 changes: 9 additions & 0 deletions CONCURRENT-WORK-AUDIT.md
Original file line number Diff line number Diff line change
Expand Up @@ -114,6 +114,15 @@ credential patterns, and prevent revocation from deleting an untracked target.
Inbound collective knowledge is a separate attributed source/quarantine
direction and must use the supported API or an atomic snapshot boundary.

DM-036 resolves that pending boundary against the public MIT upstream commit
`3e3b39416917f8e3c2bc5ca69362b20296205938`, with closed schema SHA-256
`2aad43d1b309ee95108c855fc8dc682a854e5fdf3a1e799ecfca96d3ebf7c5d9`.
The exact repository/tree/blob/license inventory is
`provenance/collective-memory-exchange-v1.json`. No upstream source, database,
WAL, corpus or live state is imported or vendored. Matrix uses two independent
injected contracts: immutable export into quarantine and exact reviewed
publication with fresh effect-truth reconciliation.

### compaii-state and Wiki

Retain hash-pinned generations, staging, conflict checks, classified artifact
Expand Down
36 changes: 32 additions & 4 deletions CURRENT-STATE.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,33 @@
# Current state

## Active completion checkpoint — 2026-08-11

DM-083 is operationally accepted. Exact Matrix runtime `915c56c` and Cluster
runtime `94d80ba` run across the real Legion and daimonmatrix host embodiments of
one fresh being. Encrypted peer exchange, pending import, observer-local
adoption/reversal, ordinary exact retry, outage refusal, whole-pair rollback,
portable restore, checked off-host backup, scheduled quiesce/resume and one
separate Tribe v1 transport message were exercised. A signed authority epoch
advanced the Legion incarnation while preserving accepted history.

The real succession first exposed a safe historical-response rejection. The
repaired V2 client then replayed the preserved request byte-identically without
duplicating its event. Subsequent bounded live work left both host views at
nine known events and zero incomplete events. The final runtime also provisions
a distinct five-method read-only host status client. A cold daimonmatrix reboot
then recovered every service and container with unchanged audit/idempotency
hashes and reconcile findings; the private-bridge bind preflight completed once
with no crash or restart. Final service, Matrix integrity, Cluster audit-chain,
portable restore and encrypted backup/mirror checks passed. The next dependency
gates are cross-being native semantic delivery and fresh-host rebirth/recovery. The exact
sequence is in [`RESUME.md`](RESUME.md); the public audit is
[`reviews/DM-083.md`](reviews/DM-083.md).

PR #112 remains subject to independent review. Tribe Bridge remains only the
transitional human-message lane; its ACK cannot substitute for Matrix
authenticated intake or a signed semantic receipt. There is still no separately
identified `tribe-chat` repository in the recorded project set.

The canonical model permits multiple simultaneous embodiments of one being.
The previously documented identity-wide singleton lease is not part of the
supported architecture.
Expand Down Expand Up @@ -47,11 +75,11 @@ authority plus purpose-separated encrypted runtime secrets, journals exact RPC
responses, and survives retry across semantic-commit/response-write failures.
DM-025 adds the typed authenticated local client, installed `daimon` CLI and
closed MCP `2026-07-28` stdio adapter. Durable retry files preserve exact RPC
bytes, MCP exposes only the current forty-six closed methods and
bytes, the daemon exposes 83 closed methods, MCP advertises 66 closed tools and
`daimon:` resources, and legacy MCP and Matrix.org transports remain absent.
The merged Cluster host adapter supervises the process. DM-026 closes the local
release gate with a deterministic installed conformance report over the current
91-scenario closed registry; it exercises real process, AF_UNIX, filesystem and
97-scenario closed registry; it exercises real process, AF_UNIX, filesystem and
SQLite paths. DM-070 extends that gate with two isolated installed processes,
native encrypted peer exchange, partition/restart convergence, observer-local
adoption, authority-epoch succession and injected Cluster fence truth. Neither
Expand Down Expand Up @@ -133,8 +161,8 @@ external-reference promotion, retraction/reassertion and tombstone are exposed
through runtime bundle V5 and twelve typed daemon/CLI/MCP methods. The installed
two-being journey recovers at every durable boundary and the generated 84-row
Section 14 registry is release-blocking. It performs no live disclosure,
source fetch, memory admission, host mutation or Cluster effect. DM-082 owns
DM-082 now implements those relationship grants plus bilateral consent,
source fetch, memory admission, host mutation or Cluster effect. DM-082 now
implements the relationship grants plus bilateral consent,
founded-Tribe membership, founder succession and strict delegation. Runtime
bundle V6 feeds DM-054 from verified signed history, publishes fixed owner
daemon/CLI/MCP surfaces and retains forks without an arrival-order winner. Its
Expand Down
10 changes: 7 additions & 3 deletions PLAN.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,8 +33,9 @@ is explicitly outside the MVP.
6. Absorb Tribe Bridge's reusable implementation into Matrix: recipient
encryption, typed messages, cursors, routes, and `/me`/`/we`/`/tribe`
resolution; then remove the standalone runtime dependency (DM-050 through
DM-055). DM-055's native encrypted peer implementation is complete behind
bundle V3; its authorized two-host cutover remains an operational gate.
DM-055). DM-055's native encrypted peer implementation has passed the
same-being two-host DM-083 cutover. Cross-being authenticated intake and a
signed semantic receipt remain the replacement gate before Tribe removal.
7. Complete birth/species/source behavior and their synthetic acceptance
journeys. DM-060, DM-061 and DM-081 now implement those isolated journeys;
DM-082 relationship grants precede the DM-071 external source canary.
Expand All @@ -44,7 +45,10 @@ is explicitly outside the MVP.
still completion evidence rather than inferred from the synthetic adapter.
9. Run local, cross-host, recovery, revocation, and rebirth journeys with real
processes, cryptography, encrypted state, transport, Cluster bodies, and
separately authorized synthetic/live evidence.
separately authorized synthetic/live evidence. The same-being two-host
journey, authority-epoch succession, exact historical retry and checked
recovery passed. Cross-being delivery and fresh-host rebirth/recovery are
the active release gates.
10. Freeze, audit, publish, and independently reinstall the V0.1 release.

## Release invariants
Expand Down
20 changes: 16 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,8 @@ Matrix.org clients, homeservers and federation are intentionally outside the
MVP. To avoid ambiguity, documentation uses `daimon-matrix`, `Matrix.org`, and
“daimonmatrix host” for the software, external protocol, and VPS.

Start with [ONTOLOGY.md](ONTOLOGY.md), the
For a cold start after the current pause, read [RESUME.md](RESUME.md) first.
Then continue with [ONTOLOGY.md](ONTOLOGY.md), the
[operational stack contract](specs/operational-stack-contract.md), and the
[being-root contract](specs/identity-root-v1.md). Delivery order and acceptance
are in [PLAN.md](PLAN.md) and [ROADMAP.md](ROADMAP.md).
Expand All @@ -58,13 +59,15 @@ is deployed. DM-054 now provides exact `/me`, `/we`, `/we.diff`, per-origin
`/we.sync` plans, verified `/tribe` snapshots, and signed replay-safe partial
fan-out independent of any live carrier. DM-055 adds the optional bundle-V3
root-bound HPKE/Ed25519 peer transport and direct scope/sync HTTP carrier with
durable replay. DM-070 proves deterministic convergence between two isolated
installed processes through partition and restart; a fresh live two-host
durable replay. DM-083 adds the installed plural-being bootstrap, closed V7
peer targets and an authenticated configured peer-pull operation. DM-070 proves
deterministic convergence between two isolated installed processes through
partition and restart; a fresh live two-host
cutover remains human-authorized. Cluster remains its
lifecycle/state-volume host; frozen fixtures preserve the old canary as a
migration oracle rather than a second protocol. Tribe Bridge is not a Matrix
peer wire. The installed `daimon-conformance` gate binds the local
implementation and reproducible artifacts to a closed 91-scenario report; its
implementation and reproducible artifacts to a closed 97-scenario report; its
route, birth and multihost evidence is synthetic/isolated and does not yet
certify a fresh live remote delivery or rebirth. The merged Cluster adapter pins Matrix,
supervises one daemon per embodiment, preserves quiesced relocatable state and
Expand Down Expand Up @@ -119,6 +122,15 @@ adopts a shared target and Hermes locally rejects it. The published
`dm.local-we.validation/v1` receipt is deterministic and path-free; the card is
a synthetic single-host gate, not a Matrix.org, multihost Cluster or CompAII
rebirth claim.
DM-036 adds independent inbound and outbound `collective-memory` adapters over
the exact public exchange-v1 contract. Immutable generations enter only an
append-only source log plus `source.imported` quarantine evidence, with offline
catch-up and ledger/source-log rebuild. Publication requires exact current
Matrix source refs, recomputable checkpoints, subject consent, independent
human review, deterministic final-byte secret scanning and fresh upstream
effect truth. The directions have content-addressed DM-018 identities and no
shared credential, store, queue, receipt or authority; the real-I/O lane uses
only isolated synthetic corpus roots.
DM-060 adds the root-authorized birth V1 ceremony and installed
`daimon-synthetic-birth` acceptance. A parent can offer attributed context but
cannot precommit or retain the newborn root; the newborn independently accepts,
Expand Down
98 changes: 98 additions & 0 deletions RESUME.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,98 @@
# Project resume checkpoint

Status: autonomous V0 completion is active. The operator authorized reversible
local and SSH work on the named systems on 2026-08-10 and the final reboot on
2026-08-11. DM-083 same-being live dogfood is operationally accepted; its
host-qualified successor pair is exact Matrix runtime `915c56c` and Cluster
runtime `94d80ba`. The active dependency path is now consented cross-being
native delivery followed by fresh-host rebirth/recovery.

Last reconciled: 2026-08-11.

## Proven checkpoint

- Matrix runtime `915c56c8899fd53d683bd7c7c81c3465b600bed9` and Cluster
runtime `94d80baca05f468287b7d2bf99c577350d654a36` run on Legion and
daimonmatrix as two embodiments of one fresh being. Native encrypted peer
pull, pending intake, observer-local adoption/reversal, ordinary restart,
ambiguous peer outage and separate Tribe v1 transport evidence succeeded.
- Portable snapshots restored with exact manifests. Encrypted restic backups
were checked, mirrored off host and rerun through the corrected scheduled
quiesce/resume path.
- A signed authority epoch advanced Legion to one successor incarnation while
preserving accepted history on both hosts. Replaying an old exact request
did not duplicate its event, but the daemon closed the reply because the
service and client expected only the active server origin.
- The repaired V2 client returned the exact historical CLI output across the
succession without duplicating the event. A successor-lane event then
converged both hosts; later bounded live-canary work left both views at nine
known events and zero incomplete events. Portable
restores, fresh encrypted backups and final service/integrity checks passed.
- Matrix bootstrap now emits a separate owner-only status client with a
distinct key and exactly five read methods. Authenticated host status is
configured and healthy without giving Cluster mutation authority.
- The final daimonmatrix reboot changed boot ID and recovered every enabled
service and all three containers without intervention. Audit and idempotency
hashes were byte-identical, the five known reconcile findings were unchanged,
`clusterd` started once after its private-bridge preflight, and neither an
`EADDRNOTAVAIL` bind failure nor a service restart occurred.
- Restic snapshot `89d801b1` passed repository verification and its encrypted
repository mirror was pulled to Legion. The prior Cluster 4a release remains
preserved as an explicit whole-pair rollback.

## Repositories and authority

| Repository | Recorded state | Role and resume warning |
|---|---|---|
| `AlterMundi/daimon-matrix` | draft PR #112; deployed runtime code `915c56c` | Canonical identity, ledgers, scopes, relationship/grant authority, communication semantics and peer runtime. DM-083 plus the host-status/reboot qualification passed; PR #112 still requires independent review. Documentation-only successors do not change the exact deployed runtime pin. |
| `nicoechaniz/daimon-cluster` | PR #77; deployed runtime code `94d80ba`, exact Matrix pin `915c56c` | Hosts bodies/storage/lifecycle and resource fences. CI, deployment, repeated whole-pair rollback, backup/mirror and cold reboot passed. Cluster never gains social, grant or canonical-ledger authority. Documentation-only successors do not change the installed runtime code. |
| `nicoechaniz/tribe-bridge` | PR #61 at runtime-repair code `ecb51d8`; deployed service build `d49bf22` | V1 remains the transitional deployed human-message carrier at directory epoch 5. Keep ACK/dedup evidence separate from Matrix intake and semantic receipts, then retire it only after the native live message and explicit migration/archive gates. |

No repository named `tribe-chat` was found in the local project set or the
`nicoechaniz`/`AlterMundi` GitHub repositories at this checkpoint. If
“tribe-chat” means the current chat-facing Tribe runtime, its canonical source
is `nicoechaniz/tribe-bridge`; do not invent a fourth authority or migration
target without first recording the actual repository.

“Matrix” means `daimon-matrix`. Matrix.org remains excluded. “daimonmatrix
host” means the VPS, not a software component or being authority.

## Exact resume order

1. Read this file, `CURRENT-STATE.md`, `ROADMAP.md`, DM-083 issue #111, draft
PR #112, `reviews/DM-083.md` and `docs/dm083-two-host-dogfood.md`.
2. Preserve `915c56c` as the exact deployed Matrix runtime candidate and
`94d80ba` as its Cluster host pair; documentation-only successors do not
silently move that pin.
3. Complete the Project 9 consented cross-being canary using Matrix's native
authenticated intake and signed semantic receipt. Do not infer that result
from the already-proven Tribe ACK lane.
4. Complete fresh-host rebirth/recovery with a new root-authorized embodiment
credential, independent private custody and no copied writable database.
5. Complete remaining adapter, collective-memory and adversarial security
gates, then freeze the exact release candidate and independently reinstall
it.
6. Remove transitional compatibility and archive Tribe Bridge only after the
native replacement and explicit migration gates prove it is unnecessary.

## Stop conditions

Do not proceed from preparation to live effects if roots/manifests differ,
custody or writable state is shared, the Matrix/Cluster commits are not exact,
a route is implicit, rollback is incomplete, a backup is unverified, or a
secret/private endpoint would enter public evidence. Transport reachability,
Tribe directory membership, Cluster registry state, successful decryption and
ACKs never create relationship, grant, `/we`, adoption or semantic-delivery
authority.

## Local minimum rerun

From an installed current Matrix artifact:

```bash
state_dir="$(mktemp -d /tmp/daimon-relationship-demo-XXXXXX)"
daimon-synthetic-relationships --state-root "$state_dir" | python -m json.tool
```

Success requires every reported invariant to be true. This command remains
local and uses disposable state plus loopback networking.
Loading
Loading