Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .agentcortex/bin/deploy.sh
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ TARGET="${TARGET:-.}"
TARGET="${TARGET%/}"

MANIFEST_FILE="$TARGET/.agentcortex-manifest"
ACX_VERSION="1.8.25"
ACX_VERSION="1.8.26"

# --- Self-deploy guard ---
TARGET_ABS="$(cd "$TARGET" 2>/dev/null && pwd || echo "$TARGET")"
Expand Down
6 changes: 3 additions & 3 deletions .agentcortex/context/.guard_receipt.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"expected_sha": "dd77b4f39777466835988468b07814ca8bd22ef580b2673d37b21f96cfa27db6",
"expected_sha": "d2831acb1a5c1fa22528706524e6ed50479741d425b5bc81749efc7da8606484",
"mode": "replace",
"new_sha": "d2831acb1a5c1fa22528706524e6ed50479741d425b5bc81749efc7da8606484",
"new_sha": "d2622d215737951bb4edcca09cefc27d3391dce281f7b344ae5012b315c63d61",
"target": ".agentcortex/context/current_state.md",
"timestamp": 1788609072
"timestamp": 1788616412
}
1 change: 1 addition & 0 deletions .agentcortex/context/archive/INDEX.jsonl
Original file line number Diff line number Diff line change
Expand Up @@ -170,3 +170,4 @@
{"branch": "feat/skill-trigger-accuracy-eval-398", "classification": "feature", "decisions": ["D-5 supersedes D-4: runner is source-only", "AC-7 partially met, not rewritten", "premise refuted: intent_patterns has no runtime consumer"], "log": "feat-skill-trigger-accuracy-eval-398-20260901.md", "modules": [".agentcortex/eval/skills.yaml", ".agentcortex/tools/run_skill_eval.py", ".agentcortex/tests/test_skill_trigger_eval.py"], "patterns": ["eval-suite", "premise-refutation", "no-runtime-consumer", "roundtable-rejected-demolition"], "prev_sha": "7239221b", "shipped": "2026-09-01", "specs": ["docs/specs/skill-trigger-accuracy-eval.md"]}
{"branch": "docs/downstream-stability-audit-findings", "classification": "quick-win", "decisions": ["File only primary-agent-reproduced findings; carry unreproduced subagent reports as leads in #194", "Expose exactly one finding (#191) as public issue #430 per the issue-exposure policy", "Put the audit continuation in a committed backlog row, not a gitignored Work Log or a session-local resume handle"], "log": "docs-downstream-stability-audit-findings-20260905.md", "modules": ["docs/specs/_product-backlog.md"], "patterns": ["downstream-simulation", "evidence-before-adding", "ai-discoverable-handoff"], "prev_sha": "0b7a27be", "shipped": "2026-09-05", "specs": ["backlog #188-#194"]}
{"branch": "fix/precommit-credential-failopen", "classification": "hotfix", "decisions": ["Reject floor-first-always; keep probe + fallthrough", "The probe is justified on parity, not on security", "Classification stays hotfix above the rule minimum", "Fix the false positive at its source, not by re-scoping the floor"], "log": "fix-precommit-credential-failopen-20260905.md", "modules": [".githooks/pre-commit.guard-ssot.sample", ".agentcortex/tools/credential_floor.sh", ".agentcortex/tools/credential_floor.ps1", ".agentcortex/tools/scan_credentials.py"], "patterns": ["fail-open", "interpreter-startability", "advertised-but-unenforced", "paired-check-parity"], "prev_sha": "dc48eafa", "shipped": "2026-09-05", "specs": ["docs/specs/dev-flow-hardening.md#AC-8", "docs/specs/downstream-adaptability-optimization.md#AC-S4"]}
{"branch": "chore/release-v1.8.26", "classification": "quick-win", "decisions": [], "log": "chore-release-v1.8.26-20260905.md", "modules": [".agentcortex/bin/deploy.sh", "CITATION.cff", "CHANGELOG.md", "docs/AGENT_MODEL_GUIDE.md", ".agentcortex/docs/TESTING_PROTOCOL.md"], "patterns": ["release-cut", "adopter-delta-measured", "honest-subset-claim"], "prev_sha": "3a792eb8", "shipped": "2026-09-05", "specs": []}
150 changes: 150 additions & 0 deletions .agentcortex/context/archive/chore-release-v1.8.26-20260905.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,150 @@
# Work Log: chore/release-v1.8.26

## Header

- Branch: `chore/release-v1.8.26`
- Classification: `quick-win`
- Classified by: `claude-opus-5`
- Frozen: `2026-09-05`
- Created Date: `2026-09-05`
- Owner: `KbWen`
- Guardrails Mode: `Quick`
- Current Phase: `ship`
- Diff Base SHA: `0b08cb5`
- Checkpoint SHA: `none`
- Recommended Skills: `verification-before-completion, karpathy-principles`
- Primary Domain Snapshot: `release metadata`
- SSoT Sequence: `168`

---

## Session Info

- Agent: `claude-opus-5`
- Session: `2026-09-05 14:30 UTC`
- Platform: `claude-code`
- Files Read: `6`

---

## Task Description

Cut release v1.8.26. Bump the seven canonical version surfaces plus `CITATION.cff` `date-released`, and write the CHANGELOG entry for the three units merged since v1.8.25 (#183, #398, #433). No engine, gate, or configuration change.

---

## Phase Sequence

| Phase | Status | Entered | Notes |
|---|---|---|---|
| bootstrap | done | 2026-09-05 | quick-win, matching `chore/release-v1.8.23` precedent |
| plan | done | 2026-09-05 | 8 surfaces + CHANGELOG; downstream delta measured first |
| implement | done | 2026-09-05 | version bump + CHANGELOG entry |
| review | n/a | — | quick-win: optional, evidence inline |
| test | n/a | — | quick-win: optional, evidence inline |
| handoff | n/a | — | quick-win exempt |
| ship | pending | — | — |

---

## Phase Summary

**bootstrap/plan** — Classified `quick-win` on the `chore/release-v1.8.23` precedent (same shape, same archive header). The plan step that mattered was measuring the adopter delta **before** writing the notes rather than describing the release from its commit list: `git diff --name-only v1.8.25..HEAD` intersected with the deploy manifest golden gives **6 of 26** changed files actually reaching an adopter. That number, not the 14-commit log, is what the Downstream delta paragraph states.

**implement** — Seven version surfaces plus `CITATION.cff date-released` bumped 1.8.25 → 1.8.26 / 2026-08-27 → 2026-09-05, each by an asserted single-occurrence replace. CHANGELOG entry written in house format. The release notes lead with the one instruction an adopter must act on: **re-run the INSTALL copy**, because `.githooks/pre-commit` is a user-made copy `deploy.sh` never rewrites — without that line the release would claim a fix most existing adopters do not have, which is the same over-promise class this release fixes.

⚡ ACX

---

## Gate Evidence

- Gate: bootstrap | Verdict: PASS | Classification: quick-win | Timestamp: 2026-09-05T14:30:00Z
- Gate: plan | Verdict: PASS | Classification: quick-win | Timestamp: 2026-09-05T14:35:00Z
- Gate: implement | Verdict: PASS | Classification: quick-win | Timestamp: 2026-09-05T14:45:00Z

---

## External References

| Type | Path / URL | Notes |
|---|---|---|
| PR | https://github.com/KbWen/agentic-os/pull/433 | the security fix this release carries |
| Backlog | `#195` / `#196` / `#197` / `#194(b)-(h)` | named in the release notes as NOT done |
| Guard | `tests/ci/test_release_version_consistency.py` | pins all 8 surfaces to `deploy.sh` |

---

## Known Risk

- The hook fix does not reach an already-installed `.githooks/pre-commit`. Mitigated only by the release notes; the mechanical fix is filed as **#197**, not attempted here.
- Rollback: revert the version bump commit; no state migration. The tag/Release are the only non-git artifacts and are created after merge.

---

## Decisions

none

---

## Conflict Resolution

none

---

## Skill Notes

none

---

## Drift Log

none

---

## Review Feedback

none

---

## Red Team Findings

none

---

## Design Reference

none

---

## Observability

none

---

## Resume

none

---

## Test Gate Results

none

---

## Evidence

- **Adopter delta measured, not assumed**: `git diff --name-only v1.8.25..HEAD` = 26 files; intersected with `deploy_manifest_golden.txt` = **6** — `.githooks/pre-commit.guard-ssot.sample`, `credential_floor.sh`, `credential_floor.ps1`, `scan_credentials.py`, `repo-gotchas.md`, `current_state.md` (scaffold, adopter copy preserved). `run_skill_eval.py` and `eval/skills.yaml` are **not** in the deploy set (grep count 0), so #398's suite is upstream-only.
- Release guard `tests/ci/test_release_version_consistency.py`: **2 passed** after the bump.
- Version-sensitive subset run locally: `test_release_version_consistency.py` + `test_deploy_tiering.py` + `test_pre_commit_hook.py` -> **47 passed, 1 skipped** (9:41). This is a **subset, not CI-equivalent** - the full 947-test suite runs on CI's three Windows shards, which is the real environment for it; no local full-suite claim is made for this cut.
- Stale-version sweep after the bump: the only surviving `1.8.25` outside `CHANGELOG.md`/archive is inside the v1.8.25 Ship History entry, which `ship.md` forbids editing. Correct to leave.
8 changes: 8 additions & 0 deletions .agentcortex/context/archive/ship-history-2026.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,14 @@

Archived from `current_state.md ## Ship History` to stay within the 10-entry cap. Entries are rotated out verbatim (per ship.md §205 — never edited), newest-archived first.

### Ship-fix-agents-md-backlog-write-scope-178-2026-08-23
- Feature shipped: **backlog #178 — a precedence contradiction that fired on every non-`tiny-fix` bootstrap is gone.** `AGENTS.md` §Write Isolation scoped `_product-backlog.md` writes to spec-intake/ship, while `bootstrap.md §1` step 5 **mandates** a `Pending → In Progress` advance at bootstrap and calls it the only valid such transition. Under the documented precedence (AGENTS.md > workflows) the governance surface forbade the step the workflow required. **Reproduced live** during this session's #175 bootstrap before being fixed here. Resolved by **widening the enumeration, not by moving the advance**: the bootstrap step is the behaviour the repo wants, so the surface that failed to name it is the one that was wrong — moving it would have traded a text defect for a behaviour change, and later phases are not guaranteed to run for every classification, so a row could sit `Pending` while work proceeded.
- **The §13 trim is real, not a formality.** Deletion-First requires a change to an always-loaded surface to cite a deletion in the same change. That `AGENTS.md` line carried **two duplicate no-Python fallback clauses** — one parenthetical, one trailing sentence, both left by the 2026-05-26 compression pass `f3b3b81` — which are merged into one here. Net **0 lines**, **+56 characters**, recorded honestly in the Work Log rather than claimed as a wash. The directive-count ratchet held at **37/37**, and the green was mutation-verified before being trusted: appending one `MUST` to the file yields `count 38 exceeds baseline 37 (growth)`.
- **Sub-item reconciled, and its knock-on stated at true size.** `docs/specs/downstream-adaptability-optimization.md` frontmatter read `status: frozen` while the SSoT Spec Index had recorded `[Shipped 2026-06-14, PR #238]` since June; it is now `shipped`. The index entry was confirmed present **first**, because under ADR-010 the Spec-Index-completeness check *skips* `frozen` but *requires* `shipped` specs to be indexed — flipping an unindexed spec would have turned a skip into a FAIL. One stale word in `tests/ci/test_validator_absent_tool_signal.py:43` ("frozen" → "shipped") was corrected in the same change. **Backlog #177's premise was rewritten rather than left to rot**: its frozen-gate half is now gone, but **AC-S5's wording still blocks** collapsing the two `deploy.sh` sites — that needs a spec-freshness update, not an unfreeze.
- **The gate caught two of my own errors mid-implement, both from running it rather than reading it.** (1) Editing `AGENTS.md` stales `trigger-compact-index.json`; the first `validate.ps1` run came back `fail=2` (`metadata deep validation` + `compact index freshness`) until `generate_compact_index.py` was re-run in the same change. (2) A new backlog row was filed with `Labels: dx` — but `dx` is a **Kind** value, not an existing label, which violates `bootstrap.md §5`'s label-reuse rule and tripped `backlog label vocabulary: 16 distinct labels (>15)`. Corrected to the existing `tooling`; the vocabulary is back to 15.
- **Test-cost measured, and it is worse than the backlog says.** Real job times from the #417 CI run: `Pytest (Windows) (1)` **21m57s** against shards 2 and 3 at **3m19s** and **4m14s**, while Linux runs the *entire* 897-test suite in **3m29s**. The cost is Windows process-spawn tax, not test count, and the shards are badly unbalanced because `--splits 3 --group N` runs with **no committed `.test_durations`**, so pytest-split falls back to an even *count* split and clusters every subprocess-shelling deploy test onto one shard. Backlog **#88** already tracks this but records `7:14` — stale by ~3×. Balanced, the same ~29.5 minutes of work is ~10 min/shard: a >2× CI wall-clock cut from one committed file. Two paths are already closed and should not be re-proposed: `pytest-xdist` was **measured slower** here, and deselecting `slow` in CI is explicitly rejected in `pytest.ini` (subprocess fidelity is the point). New row **#181** files the macOS-coverage gap this measurement surfaced — filed on a *verified absence* (15 ubuntu + 2 windows + **0 macos**) rather than a suspected break, since a BSD-vs-GNU scan of both shipped shell scripts came back clean and `sha256sum` already carries a deliberate `shasum`/`openssl` fallback.
- Tests: `validate.ps1` **exit 0 · pass=118 warn=3 fail=0 skip=2** and `validate.sh` **exit 0 · pass=118 warn=4 fail=0 skip=2**, both printing an **unqualified** `Agentic OS integrity check passed`. The one-WARN delta is again this session's own `stale advisory work log locks` — the 60-minute `stale_timeout_minutes` elapsed during a 90-minute suite, i.e. the documented phase-granular limitation in `config.yaml §worklog_lock`, not twin divergence. Full CI-equivalent suite with **no `-m` filter**: **896 passed, 1 skipped, exit 0** in 1:30:03. Targeted first: `test_directive_count_ratchet.py` + `test_validator_absent_tool_signal.py` → 14 passed.

### Ship-fix-validator-twin-parity-176-175-2026-08-23
- Feature shipped: **backlog #175 — `validate.ps1` no longer mojibakes its own output on a non-UTF-8 Windows console.** The file's `§` and `—` were rendered through the console's code page; on a cp950/Big5 box they came out as `0xA1B1` / `0xA158`. `[Console]::OutputEncoding` is **process-global** and the validator runs in the caller's live session, so a set-and-leave would have mutated console state after exit: the fix saves it, sets UTF-8 (`New-Object System.Text.UTF8Encoding $false`), and restores it in a matching `finally` that wraps the whole script. **+15 lines, 0 deletions, no re-indentation of the 2840-line body** — a PowerShell `try` block creates no scope (measured: locals, `$script:` vars and functions all survive it), and `finally` runs on the script's `exit 1` while preserving the code (measured: `exitcode=1`).
- **The backlog row was wrong and measurement corrected it.** Row #175 recorded that the bug "does not reproduce on `pwsh` 7 (the invocation `README.md:38` documents)", which would have made this a 5.1-only curiosity. Measured on the redirected byte stream — the path CI and any log capture see — `powershell` 5.1 and `pwsh` 7 emit **identical** big5 bytes; after the fix both emit correct UTF-8 (`0xC2A7` / `0xE28094`) and `restored=big5` confirms the caller's console is handed back. The row is corrected in place rather than silently shipped around.
Expand Down
Loading