|
1 | 1 | # Public Package Status |
2 | 2 |
|
3 | | -Snapshot: 2026-08-01 |
| 3 | +Snapshot: 2026-08-02 |
4 | 4 |
|
5 | 5 | This additive status note reconciles public package availability with AgentNet's |
6 | | -published `0.1.35` setup-recovery release and corrective `0.1.36` strict |
7 | | -identity-profile candidate. It does not replace requirements, gate ledgers, or |
| 6 | +published `0.1.35` setup-recovery release, immutable non-public `0.1.36` tag, |
| 7 | +and corrective `0.1.37` candidate. It does not replace requirements, gate ledgers, or |
8 | 8 | accountable-owner evidence. |
9 | 9 |
|
10 | 10 | ## Current public package |
@@ -128,25 +128,38 @@ canonical `VerifiedActor` identity profiles forbid and never serialize |
128 | 128 | private-key thumbprint. Five units remained inactive, authority stayed false, |
129 | 129 | and no enrollment or C0 message occurred. |
130 | 130 |
|
131 | | -Corrective candidate `0.1.36` rejects duplicate/non-finite JSON members, |
| 131 | +Immutable tagged candidate `0.1.36` rejects duplicate/non-finite JSON members, |
132 | 132 | strictly parses the canonical actor, verifies its domain/harness/credential |
133 | 133 | labels, retains exact profile shape and private P-256 key custody/readability |
134 | 134 | checks, and removes only the impossible duplicate `actor.key_id` test. Active |
135 | 135 | database credential-to-key binding remains proven by `server-agent activate`; |
136 | | -setup does not manufacture a second self-asserted binding. This candidate adds |
137 | | -only the exact released `0.1.33` five-unit marker migration to `0.1.36`, with |
138 | | -provenance-checked retained-journal recovery; `0.1.34`, `0.1.35`, and direct |
139 | | -legacy sources remain rejected. Because the current Hub committed a `0.1.35` |
140 | | -marker, selected Hub recovery remains package-owned AgentNet-only reset, |
141 | | -followed only under a separate exact destructive approval by clean AgentNet |
142 | | -database/role init after public package verification; that approval requires |
143 | | -sanitized exact target inventory, an explicit backup/rollback decision, and |
144 | | -redacted audit evidence. Prior AgentNet state is intentionally disposable. |
145 | | -Unrelated/shared/valuable database targets fail closed. No unrelated service, |
146 | | -database, toolchain, proxy, TLS, enrollment, authority, or C0 mutation is |
147 | | -authorized by this source change. Release requires external exact same-commit |
148 | | -terminal-green cross-platform, clean-setup, and upgrade workflow evidence; |
149 | | -post-push run IDs are not self-authored into candidate source. |
| 136 | +setup does not manufacture a second self-asserted binding. It admitted only the |
| 137 | +exact released `0.1.33` five-unit marker migration; `0.1.34`, `0.1.35`, and |
| 138 | +direct legacy sources remained rejected. Same-commit main-push cross-platform, |
| 139 | +clean-setup, and upgrade workflows passed. The immutable tag upgrade rerun then |
| 140 | +failed in the released `0.1.31` seed setup's post-start runtime sampling: |
| 141 | +`Type=simple` briefly exposed systemd's pre-exec shell as `MainPID` before Node |
| 142 | +replaced it. Cleanup passed, setup authority stayed false, and npm staging never |
| 143 | +ran. The tag remains immutable and non-public; no test waiver or tag rewrite is |
| 144 | +permitted. |
| 145 | + |
| 146 | +Corrective candidate `0.1.37` changes only that protected release gate and exact |
| 147 | +candidate migration edge. The upgrade E2E still performs one real released |
| 148 | +`0.1.31 --apply --start`; exact success evidence passes directly, while only |
| 149 | +exit 1 plus the exact `service_runtime` refusal and all three false safety flags |
| 150 | +may enter a bounded, non-mutating convergence probe. That probe imports the |
| 151 | +single root-owned released `0.1.31` private runtime and invokes its own exact |
| 152 | +Approval/Core systemd-runtime and loopback/public-health validators. It never |
| 153 | +restarts or reruns setup; malformed evidence, any other blocker, stable wrong |
| 154 | +runtime, health mismatch, module-provenance mismatch, or timeout fails closed. |
| 155 | +All command stderr is separately retained and included in synthetic-secret leak |
| 156 | +scanning. The candidate admits only exact `0.1.33` five-unit marker migration to |
| 157 | +`0.1.37`; `0.1.34`, `0.1.35`, `0.1.36`, and direct legacy sources are rejected. |
| 158 | +Local focused, source, recursive packed-package, direct-verifier, and |
| 159 | +byte-identical archive gates pass for this candidate. Exact same-commit CI, a |
| 160 | +new immutable tag, and trusted npm stage are still required. Hub recovery remains a separately approved action |
| 161 | +after exact public-package verification. No deployment, reset, database, |
| 162 | +enrollment, authority, C0, federation, production, or gate mutation is implied. |
150 | 163 |
|
151 | 164 | ## Release and gate posture |
152 | 165 |
|
|
0 commit comments