From 14843f45c8ff5754a127726d9b1ce4f1c8c67d7f Mon Sep 17 00:00:00 2001 From: Deathcharge Date: Sun, 2 Aug 2026 04:02:33 -0400 Subject: [PATCH 1/2] docs: record consumer policy evidence --- CHANGELOG.md | 2 ++ README.md | 5 +++- ROADMAP.md | 11 +++++---- docs/ADOPTION.md | 52 +++++++++++++++++++++++------------------- docs/PRODUCTIZATION.md | 22 +++++++++--------- 5 files changed, 52 insertions(+), 40 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index ed45c44..5a18e33 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -46,6 +46,8 @@ This is a replacement alpha rather than a compatibility release. - independently packaged redaction evidence for experimental task creation, status, blocking result retrieval, related-task progress, bounded retention, cancellation, and private task state; +- independently packaged redaction evidence for the invocation-policy allow path and + safe denial of an out-of-contract tool before execution; - real behavioral tests, strict typing/linting, package smoke tests, and accurate docs; - a dependency-free JSON runtime microbenchmark for repeatable local comparisons. - a dependency-free MCP stdio microbenchmark covering parsing, dispatch, diff --git a/README.md b/README.md index c0fa9a9..be11e53 100644 --- a/README.md +++ b/README.md @@ -114,7 +114,7 @@ progress and logging, bounded task retention, admission limits, and security bou ## Proven external consumer [Samsarix Integration Examples](https://github.com/Deathcharge/samsarix-integration-examples) -version 0.2.7 pins Core commit `1558624ba294f47d59ea1713ac5609ef3122239e` +version 0.2.8 pins Core commit `33f2baa9c81d4437c0e4746355eda7b4d0df0cbd` and uses only the public API to expose a privacy-first, resumable redaction workflow over MCP. Its consumer-owned tests exercise initialization, discovery, stdio invocation, @@ -126,6 +126,9 @@ synchronous timeout/quiescence accounting, package installation, and CLI entry p It also proves the experimental task lifecycle on the real redaction workflow: immediate private task state, status polling, blocking result retrieval, related-task progress, safe cancellation, bounded retention, and unavailable unauthenticated listing. +Its fail-closed host policy also admits only the exact validated redaction contract and +denies an independently registered destructive, open-world tool before execution without +reflecting that tool's private argument. The preceding v0.2.6 contract was also discovered and invoked through official MCP Inspector 0.21.2; a portable VS Code workspace is configuration-discovered, with signed-in trust and tool approval still awaiting operator acceptance. diff --git a/ROADMAP.md b/ROADMAP.md index d255fc7..293bbdd 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -33,8 +33,8 @@ remain separate decisions. - Strict `TypedDict` input and output contracts now preserve named nested fields, descriptions, and required/optional key semantics in JSON Schema and runtime validation. -- External consumer: `samsarix-integration-examples` version 0.2.7 pins Core - commit `1558624ba294f47d59ea1713ac5609ef3122239e` and proves a confined, +- External consumer: `samsarix-integration-examples` version 0.2.8 pins Core + commit `33f2baa9c81d4437c0e4746355eda7b4d0df0cbd` and proves a confined, privacy-first redaction workflow, exact typed result discovery, and response-free asynchronous cancellation through the public MCP API. It also proves progress-token correlation, monotonic content-free updates, notification @@ -45,9 +45,10 @@ remain separate decisions. independently discovered and invoked through official MCP Inspector 0.21.2. The consumer now proves real redaction through task creation, status, blocking result retrieval, related-task progress, bounded private retention, and safe task cancellation. -- Next: prove the invocation-policy contract from the independent redaction consumer, - complete the signed-in Visual Studio Code trust/tool-approval journey, and rerun the - consumer matrix after GitHub Actions billing is restored. Use observed + It also proves the host-policy allow path and safe pre-execution denial of an + independently registered out-of-contract tool without private-input disclosure. +- Next: complete the signed-in Visual Studio Code trust/tool-approval journey and rerun + the consumer matrix after GitHub Actions billing is restored. Use observed demand and confirmed contract gaps—not framework parity—to prioritize broader schema support. - Review priority: Capture all 101 dirty/untracked paths. diff --git a/docs/ADOPTION.md b/docs/ADOPTION.md index 7b7ef50..05084e5 100644 --- a/docs/ADOPTION.md +++ b/docs/ADOPTION.md @@ -12,11 +12,11 @@ Repository: | Evidence | Value | | --- | --- | -| Core contract commit | `1558624ba294f47d59ea1713ac5609ef3122239e` | +| Core contract commit | `33f2baa9c81d4437c0e4746355eda7b4d0df0cbd` | | Core package version | `2.0.0a1` | -| Consumer merge commit | `51cc3fb3f1fb4bd484ebef58d2c9ab22acc24623` | -| Consumer pull request | [samsarix-integration-examples#10](https://github.com/Deathcharge/samsarix-integration-examples/pull/10) | -| Consumer package version | `0.2.7` | +| Consumer merge commit | `c59ed468fc126eecb0a61559423ab7854ddacb87` | +| Consumer pull request | [samsarix-integration-examples#11](https://github.com/Deathcharge/samsarix-integration-examples/pull/11) | +| Consumer package version | `0.2.8` | | Integration Guard provenance | [`samsarix-integration-guard`](https://github.com/Deathcharge/samsarix-integration-guard) `0.2.0` at `1aa711d89eaedcc396f0cd6eb416fb4253da3f5e` | | Orchestration provenance | [`samsarix-agent-orchestration`](https://github.com/Deathcharge/samsarix-agent-orchestration) `0.1.0` at `0dfc050cf9a4582c9fa8d34d74b1ca97d43c9005` | | Declared consumer Python | 3.11-3.13 | @@ -47,6 +47,15 @@ selects `info`. The accepted event contains only the public tool name, invocatio status, and duration; it follows both progress phases and precedes the response. A cancelled call emits no terminal log. +The production adapter now installs a fail-closed host policy through Core's public +`ToolPolicyContext` and `ToolPolicyDecision` API. It admits only the exact redaction +name, version, tags, task mode, safety annotations, and default-filled argument set. +The consumer independently registers a destructive, open-world test tool and proves +that an MCP call reaches status `denied` without executing the tool or reflecting its +private argument. Ordinary and task-augmented redaction journeys still succeed, proving +the policy receives Core's validated, default-filled contract. This is defense in depth, +not caller authentication or evidence of human approval. + The same consumer redaction tool advertises task support as optional, preserving the ordinary call and older-client contract. A task-aware MCP `2025-11-25` client receives an immediate `working` state with a random 128-bit identifier; that state contains no @@ -78,9 +87,9 @@ was signed out of Copilot, so no trust prompt or VS Code tool call was accepted. desktop configuration-discovery evidence, not a completed desktop-agent journey. The consumer's merged -[`pyproject.toml`](https://github.com/Deathcharge/samsarix-integration-examples/blob/51cc3fb3f1fb4bd484ebef58d2c9ab22acc24623/pyproject.toml) +[`pyproject.toml`](https://github.com/Deathcharge/samsarix-integration-examples/blob/c59ed468fc126eecb0a61559423ab7854ddacb87/pyproject.toml) is the dependency manifest. It declares -`samsarix-core @ git+https://github.com/Deathcharge/samsarix-core.git@1558624ba294f47d59ea1713ac5609ef3122239e`; +`samsarix-core @ git+https://github.com/Deathcharge/samsarix-core.git@33f2baa9c81d4437c0e4746355eda7b4d0df0cbd`; the installed public package reports Core version `2.0.0a1`. The same manifest records the Guard and Orchestration commits above, and the compatibility test asserts all three installed package versions. @@ -93,7 +102,7 @@ The installed-wheel consumer contract checks completed locally on Windows with P ```text python -m ruff check . -> passed python -m mypy -> passed, strict mode -python -m pytest -> 33 passed, 90.85% branch coverage from installed wheel +python -m pytest -> 34 passed, 91.00% branch coverage from installed wheel python -m bandit -q -r src -> passed ``` @@ -104,31 +113,28 @@ python -m build -> isolated wheel and sdist passed python -m twine check -> wheel and sdist passed ``` -A fresh virtual environment installed the consumer wheel with dependencies -resolved from their exact public Git commits. Import metadata resolved to `0.2.7` -and retained the exact Core commit requirement. Outside the source checkout, the -installed `samsarix-redaction-mcp` CLI completed a real task-augmented redaction over -stdio: initialize, discovery, immediate task creation, blocking result retrieval, and -terminal status. It published a sanitized artifact, emitted exactly two related-task -progress notifications, and exposed neither the three seeded secrets nor the resolved -workspace path in protocol output. Both installed CLIs also passed their help journeys. -The source-tree development run on Python 3.14.6 separately completed the same 33 tests -at 91.47% branch coverage. Python 3.12 and 3.13 remain declared consumer support, but -their hosted jobs did not execute in this record because the account billing gate stopped -the matrix before checkout. +A fresh virtual environment installed the consumer wheel with dependencies resolved +from their exact public Git commits. Import metadata resolved to `0.2.8`, and pip cloned +Core and resolved commit `33f2baa9c81d4437c0e4746355eda7b4d0df0cbd`. +Outside the source checkout, the installed consumer suite proved both the permitted real +redaction path and safe denial of the out-of-contract tool. Both installed CLIs also +passed their help journeys. The source-tree development run on Python 3.14.6 separately +completed the same 34 tests at 91.61% branch coverage. Python 3.12 and 3.13 remain +declared consumer support, but their hosted jobs did not execute in this record because +the account billing gate stopped the matrix before checkout. Final local artifacts were: | Artifact | Bytes | SHA-256 | | --- | ---: | --- | -| `samsarix_integration_examples-0.2.7-py3-none-any.whl` | 18,303 | `1c538ac89b2ea878b1ef0cd8ee0628cef6bcc4745efc39cb42927018d1770896` | -| `samsarix_integration_examples-0.2.7.tar.gz` | 36,469 | `807f33bd857ec7918e4b0a0747472638120a618ea977323c86d4808d3ffd4cf5` | +| `samsarix_integration_examples-0.2.8-py3-none-any.whl` | 18,628 | `576c0a9b1b896f6c3289e4b825d8ec13bee977ff196483ce1a5bb7c19072547f` | +| `samsarix_integration_examples-0.2.8.tar.gz` | 37,426 | `7b4390e3e0ddae78d6756762433d3c5426f127d915fe5cead10003a6fc1cb6c4` | CodeRabbit attached a green high-level status, but its free-plan notice says the pass provides only a summary and walkthrough; it is not counted as independent line-level review evidence. The consumer's -[pull-request](https://github.com/Deathcharge/samsarix-integration-examples/actions/runs/30736315532) -and [post-merge](https://github.com/Deathcharge/samsarix-integration-examples/actions/runs/30736368378) +[pull-request](https://github.com/Deathcharge/samsarix-integration-examples/actions/runs/30738779310) +and [post-merge](https://github.com/Deathcharge/samsarix-integration-examples/actions/runs/30738829352) GitHub Actions runs did not start their jobs: GitHub attached an account billing/spending-limit failure before checkout, leaving zero executed steps and diff --git a/docs/PRODUCTIZATION.md b/docs/PRODUCTIZATION.md index 8829c9a..018421f 100644 --- a/docs/PRODUCTIZATION.md +++ b/docs/PRODUCTIZATION.md @@ -270,10 +270,11 @@ All baseline commands were run on Windows with Python 3.11.9 at commit asynchronous cancellation, bounded content-free progress, and client-filtered operational logging, retained sync-worker capacity after timeout, and bounded shutdown quiescence, official MCP Inspector invocation, and Visual Studio Code - configuration discovery from `samsarix-integration-examples`; version 0.2.7 at merge - commit `51cc3fb3f1fb4bd484ebef58d2c9ab22acc24623` pins Core commit - `1558624ba294f47d59ea1713ac5609ef3122239e` and additionally proves the bounded - experimental task lifecycle on the real redaction workflow. + configuration discovery from `samsarix-integration-examples`; version 0.2.8 at merge + commit `c59ed468fc126eecb0a61559423ab7854ddacb87` pins Core commit + `33f2baa9c81d4437c0e4746355eda7b4d0df0cbd` and additionally proves the bounded + experimental task lifecycle plus the allow/deny invocation-policy contract on the + real redaction adapter. ## Deferred work and rationale @@ -282,13 +283,12 @@ isolation, and richer schema types remain deliberately deferred. Experimental MC tasks retain bounded results only inside one server process and do not satisfy durable persistence or restart recovery. Those features are not required for the first useful release. One independent repository now proves both the stable MCP boundary and the -experimental task lifecycle. Subsequent surface area should follow concrete consumer -demand. Core's own post-merge -[Python 3.10-3.14 hosted matrix](https://github.com/Deathcharge/samsarix-core/actions/runs/30735632274) -is green with 98 tests and 94.28% branch coverage. The consumer's separate Python -3.11-3.13 jobs could not start because GitHub reported an account -billing/spending-limit problem, so its local 33-test installed-wheel evidence is -recorded separately in `docs/ADOPTION.md`. +experimental task lifecycle and the bounded policy gate. Subsequent surface area should +follow concrete consumer demand. Core's policy post-merge +[Python 3.10-3.14 hosted matrix](https://github.com/Deathcharge/samsarix-core/actions/runs/30738258486) +is green. The consumer's separate Python 3.11-3.13 jobs could not start because GitHub +reported an account billing/spending-limit problem, so its local 34-test installed-wheel +evidence is recorded separately in `docs/ADOPTION.md`. ## Owner-, credential-, or production-blocked tasks From fd457619e001bbfe25a006079e94e92679afe530 Mon Sep 17 00:00:00 2001 From: Deathcharge Date: Sun, 2 Aug 2026 04:06:47 -0400 Subject: [PATCH 2/2] docs: avoid overstating consumer deployment --- docs/ADOPTION.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/ADOPTION.md b/docs/ADOPTION.md index 05084e5..02c60c9 100644 --- a/docs/ADOPTION.md +++ b/docs/ADOPTION.md @@ -47,7 +47,7 @@ selects `info`. The accepted event contains only the public tool name, invocatio status, and duration; it follows both progress phases and precedes the response. A cancelled call emits no terminal log. -The production adapter now installs a fail-closed host policy through Core's public +The consumer adapter now installs a fail-closed host policy through Core's public `ToolPolicyContext` and `ToolPolicyDecision` API. It admits only the exact redaction name, version, tags, task mode, safety annotations, and default-filled argument set. The consumer independently registers a destructive, open-world test tool and proves