Skip to content

Commit 2b7c975

Browse files
committed
fix: recover canonical onboarding authority
1 parent 618dd52 commit 2b7c975

30 files changed

Lines changed: 1896 additions & 315 deletions

‎PUBLIC_RELEASE_STATUS.md‎

Lines changed: 23 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -11,32 +11,37 @@ requirements, gate ledgers, or accountable-owner evidence.
1111
Reads of the public npm registry and immutable Git tag returned:
1212

1313
- package: `@misunders2d/agentnet`
14-
- latest published version: `0.1.45`
15-
- published source commit: `e8a49671481767078551f677599f51af051c3d5a`
16-
- immutable tag: `v0.1.45`
17-
- registry shasum: `06f4775ecf63097068e1f3583fe84a2c66c64096`
14+
- latest published version: `0.1.50`
15+
- published source commit: `c7c5659055884b3a6fa4ad05f1e43b7e7e844436`
16+
- immutable tag: `v0.1.50`
17+
- registry shasum: `4875fd0e37b8a12689a6a50772b89e118931e7d7`
1818
- provenance: SLSA statement signed by the trusted GitHub Actions publisher and
1919
approved by the accountable npm owner
2020

21-
`0.1.45` is a **fresh-install-only** release. In-place upgrade from `0.1.44` is
22-
not a supported path: the packaged upgrade and rollback lane is preserved as
23-
non-green, so operators must install `0.1.45` on a clean host and re-enroll the
24-
server and each harness. Publication is gated on the ordinary-server
25-
clean-install lane, which is the exact path operators follow.
21+
`0.1.50` is the published setup-usability release. It supports the exact
22+
allowlisted schema-v7 five-unit upgrade paths documented by that immutable
23+
package. Publication does not prove installed-host convergence, production
24+
durability, or any must-not-ship gate.
2625

2726
Package availability does not authorize deployment and does not establish
2827
production readiness. No must-not-ship gate is promoted by publication.
2928

30-
## Setup-usability `0.1.50` candidate
29+
## Corrective `0.1.51` candidate
30+
31+
Candidate `0.1.51` retains the published `0.1.50` setup and laptop protocols
32+
and adds package-owned convergence for the exact ordinary-onboarding
33+
placeholder Approval owner and for a committed communication scope missing
34+
its schema-v7 collaboration projection. The target owner is derived from
35+
enrolled Core identity plus Approval's pinned OIDC binding; signer and Core
36+
policy cutover is journaled and resumable. New scope activation writes its
37+
projection atomically, and legacy repair derives it from the existing
38+
committed scope without replacing authority.
39+
40+
The candidate accepts only exact five-unit schema-v7 markers from v0.1.45
41+
through v0.1.50. Ambiguous, drifted, incomplete, or unsupported state fails
42+
closed. Package, installed-host, dedicated-PostgreSQL, and live two-machine
43+
validation remain pending; no production or gate claim is made.
3144

32-
Candidate `0.1.50` wraps the existing strict server and laptop protocols in
33-
one resumable command per machine. It adds authenticated discovery defaults,
34-
content-free named phases, bounded deadlines, exact blocker/recovery output,
35-
and direct allowlisted upgrades from exact v0.1.45–v0.1.49 schema-v7 five-unit
36-
markers. Packed-package verification requires an installed separate-process
37-
message/obligation roundtrip. Release artifacts, complete validation, fresh CI,
38-
and publication remain pending. This local implementation does not promote a
39-
requirement, production claim, or must-not-ship gate.
4045

4146
## Corrective `0.1.49` candidate
4247

‎README.md‎

Lines changed: 15 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -441,7 +441,7 @@ always-on deployment—see the [implementation guide](docs/implementation-guide.
441441
## Project status
442442

443443
AgentNet is an early public implementation; the latest published package is
444-
`0.1.45`. Its publication does not promote any requirement or gate.
444+
`0.1.50`. Its publication does not promote any requirement or gate.
445445
Published `0.1.29` repaired owner/enrollment OIDC callback parsing after real
446446
Google owner login exposed rejection of valid unique response extensions;
447447
published `0.1.30` repaired installed-verifier package custody; published
@@ -543,6 +543,20 @@ addition to the existing installed journey. These are local and CI evidence,
543543
not production certification, and no requirement or must-not-ship gate is
544544
promoted.
545545

546+
Candidate `0.1.51` adds the package-owned corrective recovery path for the
547+
exact ordinary-onboarding state where Approval still names the setup
548+
placeholder owner after Core enrolled the canonical human. Managed setup
549+
derives the target only from the enrolled Core identity and Approval's pinned
550+
OIDC binding, rotates current Approval signing authority to that principal,
551+
and journals resumable Core policy replacement. It rejects identity, domain,
552+
OIDC, signer, database, configuration, or journal ambiguity. New communication
553+
activation writes its complete schema-v7 collaboration projection in the same
554+
transaction; an already committed scope missing that projection is repaired
555+
from its immutable scope rows without replacing the scope or minting broader
556+
authority. Exact five-unit schema-v7 markers from v0.1.45 through published
557+
v0.1.50 may upgrade directly to v0.1.51.
558+
559+
546560
Git tag `v0.1.23` reached the staging workflow, but CI stopped before npm
547561
staging because one hermetic interruption test mocked `/usr/bin/useradd` on a
548562
runner where that path did not exist. No `0.1.23` package was staged or

‎RELEASE_MANIFEST.json‎

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -218,7 +218,7 @@
218218
"path": "uv.lock",
219219
"pyproject": {
220220
"path": "pyproject.toml",
221-
"sha256": "95c9effe37951f5ab012aa00743ecc52b44ca0ac0b62ab08eddafa3ab7559e7a"
221+
"sha256": "6aebcdea17d2715c3136c2b6b3179a424a3eed990f54d65a4cccbf67c715c5da"
222222
},
223223
"resolution": {
224224
"a2a-sdk": "1.1.0",
@@ -285,7 +285,7 @@
285285
"webauthn": "3.0.0"
286286
},
287287
"revision": 3,
288-
"sha256": "afffa3558290939ca4f3efae1b04559db3299084f4a62c0d93ccdd4ab66e69c8"
288+
"sha256": "c971fdea8d3782a9d7349b5723f4e036740d314f19f7c3553dc6ba1780c9f84d"
289289
},
290290
"external_release_evidence": {
291291
"installer_lifecycle": {
@@ -529,20 +529,20 @@
529529
"release": {
530530
"name": "agentnet",
531531
"production_ready": false,
532-
"profile": "setup_usability_candidate",
532+
"profile": "canonical_owner_recovery_candidate",
533533
"reason": "All 19 must-not-ship gates remain non-PASSED; local implementation evidence is partial and required external, privileged, production-topology, or owner evidence remains absent.",
534534
"ship_eligible": false,
535535
"status": "BLOCKED",
536-
"version": "0.1.50"
536+
"version": "0.1.51"
537537
},
538538
"release_inputs": {
539539
"README.md": {
540540
"path": "README.md",
541-
"sha256": "f6839282457daeeb8cad2b76621b384725cb6caac15e92ad3e09f72633fcbbe3"
541+
"sha256": "f594836e220538cac9c41da74a7a02dcaaebc05534a2fa0bae1302b19ee21a26"
542542
},
543543
"REQUIREMENTS_STATUS.md": {
544544
"path": "REQUIREMENTS_STATUS.md",
545-
"sha256": "59491a96c8697c41c47d29756144768f5b62da0df04c3d75c9579dc762dae0d8"
545+
"sha256": "18c34a4e0224e68ccc68e71a970b398fc1e1bc1547c4ce4b00a43554b6887340"
546546
},
547547
"deploy/Dockerfile": {
548548
"path": "deploy/Dockerfile",
@@ -562,11 +562,11 @@
562562
},
563563
"docs/GATE_EVIDENCE.md": {
564564
"path": "docs/GATE_EVIDENCE.md",
565-
"sha256": "1d690b65756169e1954c1a37c0436bc3dc053e903e61dd4a647a0a0f786be6e2"
565+
"sha256": "83e5178c205b2808f9155ff245469a6234abf616cefac36f604badabbaa4419f"
566566
},
567567
"docs/RELEASE_MANIFEST.md": {
568568
"path": "docs/RELEASE_MANIFEST.md",
569-
"sha256": "99fb7ad44dfb05766c59ac69c1decb1df9e951984c7196acb53c37179d2d99ad"
569+
"sha256": "5953a7a3d47c10f145243ba82db76457f09fb7326f1d4373175a29087e776cd5"
570570
},
571571
"evidence/gates/G01/2026-07-13-installed-harnesses/manifest.json": {
572572
"path": "evidence/gates/G01/2026-07-13-installed-harnesses/manifest.json",
@@ -602,13 +602,13 @@
602602
},
603603
"scripts/verify_release.py": {
604604
"path": "scripts/verify_release.py",
605-
"sha256": "b559a98eb5050f54a9d4d222ef83e2b6bda16af5c79860699d0eace2c1661d00"
605+
"sha256": "612baa0e73b836f7411cc8f76f5698d750bfd5a77cbad8f94c70d6ac9f59bb01"
606606
}
607607
},
608608
"release_source_tree": {
609609
"algorithm": "sha256(path NUL bytes NUL)",
610610
"path": "src",
611-
"sha256": "740adfb28e27641c3ec0bab470036c4690fde2c70a53ab0568fde644aecddb7e"
611+
"sha256": "0906475b88bb57673fa2ab4ea793803d9931fad36e97a00519d52f7bb39685ea"
612612
},
613613
"runtime": {
614614
"implementation": "CPython",
@@ -746,5 +746,5 @@
746746
},
747747
"version": "1.0"
748748
},
749-
"snapshot_date": "2026-08-07"
749+
"snapshot_date": "2026-08-09"
750750
}

‎REQUIREMENTS_STATUS.md‎

Lines changed: 26 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
# Requirements Status
22

3-
Snapshot: 2026-08-07. This is an implementation/evidence ledger, not a release
3+
Snapshot: 2026-08-09. This is an implementation/evidence ledger, not a release
44
certificate. It contains the exact 85 stable requirement IDs from the preserved
55
requirements reference. PD-001 through PD-011 are listed separately because
66
they are accountable policy decisions, not additional requirements.
@@ -428,6 +428,31 @@ published and historical release evidence:
428428
`UX-001`, `UX-002`, `SEC-003`, `SEC-005`, `OPS-003`, and `OPS-006`. No
429429
requirement or must-not-ship gate is promoted.
430430

431+
- Corrective v0.1.51 work replaces the manually demonstrated live recovery
432+
with a package-owned, bounded path for the exact ordinary-onboarding
433+
placeholder-owner state. Approval owner/passkey custody and current signer
434+
authority converge to the enrolled Core principal only when exact domain,
435+
OIDC, credential, row-shape, configuration, and journal evidence agrees.
436+
Setup journals the corresponding Core policy cutover and resumes exact
437+
partial writes; unsupported or ambiguous state fails closed. Communication
438+
activation now materializes the complete schema-v7 collaboration projection
439+
atomically with scope commitment, while a committed legacy scope is repaired
440+
idempotently from its server-held source rows without replacement or generic
441+
entitlement minting. The focused recovery lane reports **347 passed**; the
442+
broad releasable-source lane reports **2204 passed and 22 expected
443+
platform/dedicated-PostgreSQL skips**; and source plus two recursive packed
444+
generations each report **2231 passed and 22 expected skips**. Two independent
445+
builds are byte-identical, packaged local message/obligation processing
446+
reaches `recipient_committed`, and a fresh installed npm package passes exact
447+
endpoint routing with zero sibling reactions or residue. Dedicated
448+
PostgreSQL, installed-host setup/upgrade, same-commit CI, and live two-machine
449+
evidence remain pending. Affected IDs are `ID-001`, `ID-002`, `ID-005`,
450+
`ID-006`, `AUTH-001`, `AUTH-002`, `AUTH-003`, `AUTH-004`, `AUTH-005`,
451+
`COM-001`, `COM-002`, `COM-009`, `AVL-003`, `AVL-005`, `SEC-003`, `SEC-005`,
452+
`SEC-007`, `OPS-003`, and `OPS-006`. No requirement or must-not-ship gate is
453+
promoted.
454+
455+
431456

432457

433458
- S5/S6 directly exercise `ID-006`, `AUTH-001`, `AUTH-002`, `AUTH-003`,

‎docs/ARCHITECTURE.md‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -895,4 +895,24 @@ revalidated before commit. Packed-package verification additionally executes
895895
the separate-process local message/obligation roundtrip; it remains H/L local
896896
evidence and does not prove production durability.
897897

898+
The corrective v0.1.51 recovery remains inside this composition root. After an
899+
exact supported upgrade has established the enrolled Core identity, setup may
900+
classify only the known placeholder-owner, partial-repair, live-repair, or
901+
already-converged Approval shapes. A service-private command adopts the
902+
canonical owner and replacement P-256 receipt signer under Approval's OS
903+
identity. Setup then replaces the corresponding Core OIDC and approver policy
904+
through the existing root-owned upgrade journal. Exact journal phases make an
905+
interruption resumable; mismatched identity, OIDC subject, domain, signer,
906+
configuration, database shape, revision, or digest blocks startup.
907+
908+
Communication-scope completion and legacy-scope repair share one schema-v7
909+
single-scope materializer. Completion invokes it inside the transaction that
910+
commits the scope, entitlements, revoke powers, members, audit record, and
911+
idempotent result. Repair derives the same projection only from committed
912+
server-held scope rows. Existing exact rows are a no-op; partial, extra, or
913+
conflicting rows roll back. Thus no success can expose a terminal active scope
914+
without its canonical collaboration authority, and recovery never replaces
915+
the active scope or grants generic access.
916+
917+
898918
`agentnet server-agent reset` is destructive server-manager-only package recovery. It acquires the same permanent root-only setup lock before inventory, rejects state without pre-existing lock custody, stops/disables and proves all five managed units inactive, removes only allowlisted package deployment units/state, and preserves the lock/root so a concurrent or later setup cannot lock a different inode. It always reloads systemd, including exact response-loss retry, and retains PostgreSQL, runtimes, package installation, proxy/TLS/DNS/firewall inputs, and locked service identities. Reset is not a browser action, onboarding step, or secret-rotation path. Exact AgentNet database/role reinitialization is a separate destructive operator boundary requiring sanitized target inventory, explicit named approval, an explicit backup/rollback decision, and redacted audit evidence; unrelated/shared/valuable targets fail closed.

‎docs/GATE_EVIDENCE.md‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
# Must-Not-Ship Gate Evidence Ledger
22

3-
Current ledger update: 2026-08-07. Overall release posture: **blocked**. Older
3+
Current ledger update: 2026-08-09. Overall release posture: **blocked**. Older
44
rows retain their exact run dates and remain historical evidence. This ledger
55
separates checked-in historical release evidence from an explicitly labeled
66
uncommitted worktree candidate, records only commands actually run for the stated
@@ -84,6 +84,8 @@ Gate statuses used here:
8484
| Candidate npm `0.1.48` canonical post-C0 credential correction | Completed-C0 terminal credentials now resolve through the exact domain/principal-bound harness plus credential epoch; unknown or mismatched identity state remains fail-closed. Adds only the exact forward-only `0.1.47→0.1.48` five-unit marker edge and no database migration. | Focused lane: `547 passed, 5 skipped`; broad releasable-source lane: `2155 passed, 21 skipped`; recursive packed-package and installed-host upgrade evidence pending. | H-only correction evidence; no gate promotion. Affected IDs: `ID-006`, `ID-009`, `SEC-007`, `OPS-003`. |
8585
| Candidate npm `0.1.49` completed-C0 communication recovery | Permanent communication activation resolves the exact completed C0 pair; only the authenticated ordinary server harness may advance to its current active credential, while the C0 peer remains pinned to its enrolled credential absent separately verified succession. Terminal pre-commit retries converge without replacing committed authority. Signed message send, inbox, and acknowledgement requests bind the exact collaboration scope. Adds only the forward-only `0.1.48→0.1.49` five-unit marker edge and no database migration. | Focused lane: `645 passed, 5 skipped`; broad releasable-source lane: `2166 passed, 21 skipped`; recursive packed-package and installed-host upgrade evidence pending. | H-only correction evidence; no gate promotion. Affected IDs: `ID-001`, `ID-002`, `ID-004`, `ID-006`, `AUTH-001`, `AUTH-002`, `AUTH-003`, `AUTH-004`, `AUTH-007`, `AUTH-009`, `COM-001`, `COM-002`, `COM-003`, `COM-006`, `COM-009`, `COM-011`, `AVL-003`, `AVL-005`, `AVL-006`, `SEC-003`, `SEC-005`. |
8686
| Candidate npm `0.1.50` setup-usability, direct-upgrade, and communication-scope approval path | One guided server command over the strict request/plan/apply protocol; one server-origin-only guided laptop command with authenticated discovery defaults; content-free named phases; ten-minute server and five-minute laptop bounds; resumable blocker output; exact direct allowlist from v0.1.45–v0.1.49 schema-v7 five-unit markers; installed separate-process local communication/obligation roundtrip added to packed verification; explicit one-hour Approval request ceiling limited to `authorization.communication_scope.approve`, with all other approvals retaining the five-minute ceiling and short-lived WebAuthn challenges | Focused release lane: `681 passed, 5 skipped`; broad releasable-source lane: `2180 passed, 21 skipped`; source and two recursive packed generations: `2207 passed, 21 skipped` each; two byte-identical release builds; release manifest verifier passed; installed tarball journey passed from an unrelated prefix; installed-host, fresh-machine, and same-commit CI evidence pending | H/L-shaped local candidate evidence only. No production, owner-policy, external, privileged-host, or gate promotion. Affected IDs: `ID-006`, `AUTH-004`, `AUTH-007`, `COM-001`, `COM-002`, `COM-003`, `COM-006`, `COM-009`, `AVL-003`, `AVL-005`, `AVL-006`, `UX-001`, `UX-002`, `SEC-003`, `SEC-005`, `OPS-003`, `OPS-006`. |
87+
| Corrective v0.1.51 canonical-owner and schema-v7 scope-projection recovery | Exact enrolled-Core plus pinned-Approval-OIDC owner selection; transactional Approval owner/passkey adoption; current receipt-signer replacement; strict resumable signer/config journal; journaled Core OIDC/approver cutover; single-scope schema-v7 projection shared by atomic activation and idempotent legacy repair; ambiguity, tamper, drift, partial-row, and conflicting-row rejection | Focused recovery lane: `347 passed`; broad releasable-source lane: `2204 passed, 22 skipped`; source plus two recursively packed generations: `2231 passed, 22 skipped` each; two byte-identical builds; installed-byte local communication reached `recipient_committed`; fresh installed npm exact-endpoint routing proved zero sibling reactions and no process/capability residue | Current source/package H/L-shaped evidence only. Dedicated PostgreSQL, installed-host setup/upgrade, same-commit CI, and live server/laptop reliability evidence remain pending. No requirement or gate promotion. Affected IDs: `ID-001`, `ID-002`, `ID-005`, `ID-006`, `AUTH-001`, `AUTH-002`, `AUTH-003`, `AUTH-004`, `AUTH-005`, `COM-001`, `COM-002`, `COM-009`, `AVL-003`, `AVL-005`, `SEC-003`, `SEC-005`, `SEC-007`, `OPS-003`, `OPS-006`. |
88+
8789
| OIDC validated-address transport repair | `UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/identity/test_oidc_enrollment.py tests/operations/test_fail_closed_config.py tests/production/test_deployment_config.py` | 53 passed, 0 failed on 2026-07-15 | H only: includes the real `_PinnedHTTPSConnection` socket path under a validation-to-connect DNS-answer change, exact TCP address/SNI/Host assertions, proxy/tunnel and redirect denial, response bounds, unsafe address-class rejection, invalid resolver type handling, private IPv4/IPv6 pins, configuration, and deployment wiring. No real IdP/TLS service or independent approval boundary is claimed. |
8890
| Independent WebAuthn-UV approval component | `UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/approval`; approval-consumer lane; non-gate full regression below | 12 focused passed; 144 approval/consumer passed; included in 1049-pass broad lane on 2026-07-15 | H only: strict owner-only config/key custody, exact SQLite catalog/tamper rejection, UV-required maintained-library call contract, exact display/digest, bounded duplicate-rejecting HTTP, one-receipt response-loss retry, committed denial/expiry audits, rejection, credential revocation, loopback serving, and non-authorizing provisioning. WebAuthn verification is seam-controlled in hermetic tests; no real authenticator, independent host/device/operator, TLS proxy, rotation/recovery drill, or owner decision is claimed. |
8991
| Prior `0.1.8` candidate, unfiltered local run | `UV_CACHE_DIR=/tmp/uv-cache uv run --extra test pytest -q` | `1087 passed, 2 failed, 7 expected PostgreSQL skips` on 2026-07-16 | Both failures were preserved environmental G01 gates. This was not a passing unfiltered release run and is not current `0.1.9` evidence. |

0 commit comments

Comments
 (0)