Skip to content

Commit 6649e13

Browse files
committed
fix(release): harden released upgrade probe
1 parent 753b2ef commit 6649e13

29 files changed

Lines changed: 708 additions & 127 deletions

‎PUBLIC_RELEASE_STATUS.md‎

Lines changed: 31 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
# Public Package Status
22

3-
Snapshot: 2026-08-01
3+
Snapshot: 2026-08-02
44

55
This additive status note reconciles public package availability with AgentNet's
6-
published `0.1.35` setup-recovery release and corrective `0.1.36` strict
7-
identity-profile candidate. It does not replace requirements, gate ledgers, or
6+
published `0.1.35` setup-recovery release, immutable non-public `0.1.36` tag,
7+
and corrective `0.1.37` candidate. It does not replace requirements, gate ledgers, or
88
accountable-owner evidence.
99

1010
## Current public package
@@ -128,25 +128,38 @@ canonical `VerifiedActor` identity profiles forbid and never serialize
128128
private-key thumbprint. Five units remained inactive, authority stayed false,
129129
and no enrollment or C0 message occurred.
130130

131-
Corrective candidate `0.1.36` rejects duplicate/non-finite JSON members,
131+
Immutable tagged candidate `0.1.36` rejects duplicate/non-finite JSON members,
132132
strictly parses the canonical actor, verifies its domain/harness/credential
133133
labels, retains exact profile shape and private P-256 key custody/readability
134134
checks, and removes only the impossible duplicate `actor.key_id` test. Active
135135
database credential-to-key binding remains proven by `server-agent activate`;
136-
setup does not manufacture a second self-asserted binding. This candidate adds
137-
only the exact released `0.1.33` five-unit marker migration to `0.1.36`, with
138-
provenance-checked retained-journal recovery; `0.1.34`, `0.1.35`, and direct
139-
legacy sources remain rejected. Because the current Hub committed a `0.1.35`
140-
marker, selected Hub recovery remains package-owned AgentNet-only reset,
141-
followed only under a separate exact destructive approval by clean AgentNet
142-
database/role init after public package verification; that approval requires
143-
sanitized exact target inventory, an explicit backup/rollback decision, and
144-
redacted audit evidence. Prior AgentNet state is intentionally disposable.
145-
Unrelated/shared/valuable database targets fail closed. No unrelated service,
146-
database, toolchain, proxy, TLS, enrollment, authority, or C0 mutation is
147-
authorized by this source change. Release requires external exact same-commit
148-
terminal-green cross-platform, clean-setup, and upgrade workflow evidence;
149-
post-push run IDs are not self-authored into candidate source.
136+
setup does not manufacture a second self-asserted binding. It admitted only the
137+
exact released `0.1.33` five-unit marker migration; `0.1.34`, `0.1.35`, and
138+
direct legacy sources remained rejected. Same-commit main-push cross-platform,
139+
clean-setup, and upgrade workflows passed. The immutable tag upgrade rerun then
140+
failed in the released `0.1.31` seed setup's post-start runtime sampling:
141+
`Type=simple` briefly exposed systemd's pre-exec shell as `MainPID` before Node
142+
replaced it. Cleanup passed, setup authority stayed false, and npm staging never
143+
ran. The tag remains immutable and non-public; no test waiver or tag rewrite is
144+
permitted.
145+
146+
Corrective candidate `0.1.37` changes only that protected release gate and exact
147+
candidate migration edge. The upgrade E2E still performs one real released
148+
`0.1.31 --apply --start`; exact success evidence passes directly, while only
149+
exit 1 plus the exact `service_runtime` refusal and all three false safety flags
150+
may enter a bounded, non-mutating convergence probe. That probe imports the
151+
single root-owned released `0.1.31` private runtime and invokes its own exact
152+
Approval/Core systemd-runtime and loopback/public-health validators. It never
153+
restarts or reruns setup; malformed evidence, any other blocker, stable wrong
154+
runtime, health mismatch, module-provenance mismatch, or timeout fails closed.
155+
All command stderr is separately retained and included in synthetic-secret leak
156+
scanning. The candidate admits only exact `0.1.33` five-unit marker migration to
157+
`0.1.37`; `0.1.34`, `0.1.35`, `0.1.36`, and direct legacy sources are rejected.
158+
Local focused, source, recursive packed-package, direct-verifier, and
159+
byte-identical archive gates pass for this candidate. Exact same-commit CI, a
160+
new immutable tag, and trusted npm stage are still required. Hub recovery remains a separately approved action
161+
after exact public-package verification. No deployment, reset, database,
162+
enrollment, authority, C0, federation, production, or gate mutation is implied.
150163

151164
## Release and gate posture
152165

‎README.md‎

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -162,7 +162,7 @@ controls.
162162
AgentNet package installation, local SQLite state, signed HTTP clients, and
163163
host-local binding adapters support Linux, macOS, and Windows. Node.js 22.19 or
164164
newer and [`uv`](https://docs.astral.sh/uv/) 0.11.28 or newer must be on `PATH`.
165-
Only non-EOL Node.js release lines are supported: current `0.1.36` coverage targets
165+
Only non-EOL Node.js release lines are supported: current `0.1.37` coverage targets
166166
Node.js 22 LTS, 24 LTS, and 26 Current; Node.js 23 and 25 are unsupported despite
167167
the broad npm engine floor. Minimum-floor CI uses Node.js 22.19.0 with its
168168
compatible npm 10.9.3; the deployed Hub compatibility target is reported
@@ -359,7 +359,7 @@ message path. Published `0.1.32` repairs the ceremony blockers. Published
359359
`0.1.33` adds the exact migration from the live `0.1.31` two-unit marker, but
360360
the Hub transition exposed a retained systemd failed latch after its
361361
forward-only boundary. Published `0.1.35` adds identity-preserving reconciliation
362-
for that exact state. Candidate `0.1.36` removes one unsatisfiable fresh-init
362+
for that exact state. Candidate `0.1.37` removes one unsatisfiable fresh-init
363363
identity-profile check. No release proves completed fresh-laptop enrollment, native
364364
cross-host message/ACK, production readiness, or ship eligibility. The earlier `0.1.24`
365365
release introduced product-owned ordinary Linux server setup: fixed
@@ -448,12 +448,12 @@ public `0.1.35` then reached marker and PostgreSQL migration on the Hub but
448448
failed because setup required `actor.key_id` even though strict canonical
449449
`VerifiedActor` profiles forbid and never serialize that field.
450450

451-
Candidate `0.1.36` strictly validates the canonical actor and its current
451+
Candidate `0.1.37` strictly validates the canonical actor and its current
452452
binding labels, retains exact profile shape plus P-256 private-key custody and
453453
readability checks, and removes only that impossible duplicate field test.
454454
`server-agent activate` remains the database-backed credential-to-key binding
455455
proof. It adds only the exact released `0.1.33` five-unit marker migration to
456-
`0.1.36`, including provenance-checked retained-journal recovery; `0.1.34`,
456+
`0.1.37`, including provenance-checked retained-journal recovery; `0.1.34`,
457457
`0.1.35`, and direct legacy sources remain rejected. Because the current Hub
458458
committed a `0.1.35` marker, its intended recovery remains a package-owned
459459
AgentNet-only clean reset, followed only under a separate exact destructive
@@ -463,7 +463,7 @@ inventory, an explicit backup/rollback decision, and redacted audit evidence;
463463
unrelated/shared/valuable database targets fail closed. Release still requires
464464
external exact same-commit terminal-green cross-platform, clean-setup, and
465465
upgrade workflow evidence; post-push run IDs are not self-authored into source.
466-
Required runtime proof remains exact public `0.1.36`, clean five-unit readiness,
466+
Required runtime proof remains exact public `0.1.37`, clean five-unit readiness,
467467
fresh enrollment, one native
468468
signed message, recipient `recipient_committed`, exact
469469
`COMPLETED_C0_ROUND_TRIP`, then five-power revocation and post-revocation refusal.

‎RELEASE_MANIFEST.json‎

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
{
22
"$schema": "https://agentnet.invalid/schemas/release-manifest-v1.json",
33
"manifest_version": "1.0",
4-
"snapshot_date": "2026-08-01",
4+
"snapshot_date": "2026-08-02",
55
"release": {
66
"name": "agentnet",
7-
"version": "0.1.36",
7+
"version": "0.1.37",
88
"profile": "strict_identity_profile_fresh_init_candidate",
99
"status": "BLOCKED",
1010
"production_ready": false,
@@ -32,12 +32,12 @@
3232
},
3333
"dependency_lock": {
3434
"path": "uv.lock",
35-
"sha256": "aeecba8a1b1ab7163347f9727ab08a87ada0f6b5ab73b39181d7170bea1b9e02",
35+
"sha256": "0d20da004cd1573020f366fef9b7a89f0955367cfb16e1720f546e3f62648f55",
3636
"format_version": 1,
3737
"revision": 3,
3838
"pyproject": {
3939
"path": "pyproject.toml",
40-
"sha256": "66072a5744f37124767b6d6350f9a55e5827fc07e54d8c440a6e220ce0bfbcfa"
40+
"sha256": "1c2c2b42543aa22d2b41a461173cd0945098ca1b6bf66194f65f6fbf34e9e1f6"
4141
},
4242
"direct_dependencies": {
4343
"build": {
@@ -193,11 +193,11 @@
193193
"release_inputs": {
194194
"README.md": {
195195
"path": "README.md",
196-
"sha256": "6fe9fefa3982d2e9feafbd18dc684a71fac42ee5c99fbb3aa4cb314ed1857e9e"
196+
"sha256": "2bc4d3064f5ceb35fb6f1b080308a8be4b5abffd71b66518c4044da59a223a22"
197197
},
198198
"REQUIREMENTS_STATUS.md": {
199199
"path": "REQUIREMENTS_STATUS.md",
200-
"sha256": "f5c51fa69fae8267e47f02579421a1a60602157352ebe0e4692e834f5bcba55a"
200+
"sha256": "427f3f7ca853d7ee35af16388dc52f635f5f0a4f3756212c1ffdd1d08949ddee"
201201
},
202202
"deploy/Dockerfile": {
203203
"path": "deploy/Dockerfile",
@@ -217,11 +217,11 @@
217217
},
218218
"docs/GATE_EVIDENCE.md": {
219219
"path": "docs/GATE_EVIDENCE.md",
220-
"sha256": "17224e8b8bf4b7b871b504ec3d720a38a9b3f590ebf0bab0eea632d6005f5ab6"
220+
"sha256": "ae96a0b1c930e300f3fe52daa801442286f956e81d246380655f398d3dfc3615"
221221
},
222222
"docs/RELEASE_MANIFEST.md": {
223223
"path": "docs/RELEASE_MANIFEST.md",
224-
"sha256": "61c99f67ec1902cd304c5ef399b87fa3864e30acbfc725e89160c292d3cd402f"
224+
"sha256": "af067b1b36cfec1341174dbbccd54113adffb76ccef252128bd0efdc4947730f"
225225
},
226226
"evidence/gates/G01/2026-07-13-installed-harnesses/manifest.json": {
227227
"path": "evidence/gates/G01/2026-07-13-installed-harnesses/manifest.json",
@@ -245,13 +245,13 @@
245245
},
246246
"scripts/verify_release.py": {
247247
"path": "scripts/verify_release.py",
248-
"sha256": "930b04d1660c101d031de152f047b1ddc3b4ffa6362831c01cee824f5f1ce5c4"
248+
"sha256": "7568703efe8b4d9c250287fdb0bc37d03dc2244c2fd445f4d272ada5a677ded3"
249249
}
250250
},
251251
"release_source_tree": {
252252
"path": "src",
253253
"algorithm": "sha256(path NUL bytes NUL)",
254-
"sha256": "a350849e5bc5e02fe486a5a5df6b1905b70030070093146fbd7c5011721f079a"
254+
"sha256": "b9150543f59b41830fc4bfd622398626608dc0bf6557c758909a18a9aa936a77"
255255
},
256256
"protocols": {
257257
"a2a": {
@@ -410,7 +410,7 @@
410410
},
411411
"supervisor_harness_lifecycle": {
412412
"status": "BUILD_OWN_INTEGRATION",
413-
"pin": "agentnet-0.1.36",
413+
"pin": "agentnet-0.1.37",
414414
"boundary": "Exact human plus harness binding and foreground isolation remain owned."
415415
},
416416
"a2a_gateway": {

‎REQUIREMENTS_STATUS.md‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
# Requirements Status
22

3-
Snapshot: 2026-08-01. This is an implementation/evidence ledger, not a release
3+
Snapshot: 2026-08-02. This is an implementation/evidence ledger, not a release
44
certificate. It contains the exact 85 stable requirement IDs from the preserved
55
requirements reference. PD-001 through PD-011 are listed separately because
66
they are accountable policy decisions, not additional requirements.
@@ -144,14 +144,14 @@ published and historical release evidence:
144144
canonical strict `VerifiedActor` profiles forbid and never serialize
145145
`actor.key_id`, while setup required that field. Units remained inactive,
146146
authority false, and no enrollment or C0 message occurred.
147-
- Candidate `0.1.36` affects `AUTH-007`, `SEC-007`, `OPS-003`, `OPS-006`,
147+
- Candidate `0.1.37` affects `AUTH-007`, `SEC-007`, `OPS-003`, `OPS-006`,
148148
`OPS-007`, and the same blocked first-message path. It rejects duplicate/non-finite managed
149149
profile JSON, strictly parses the canonical actor, verifies current
150150
domain/harness/credential labels, retains exact profile and P-256 private-key
151151
custody/readability checks, and removes only the impossible duplicate field
152152
test. Database-backed credential-to-key binding remains owned by
153153
`server-agent activate`. It adds only the exact released `0.1.33` five-unit
154-
marker migration to `0.1.36`, with provenance-checked retained-journal
154+
marker migration to `0.1.37`, with provenance-checked retained-journal
155155
recovery; `0.1.34`, `0.1.35`, and direct legacy sources remain rejected.
156156
Because the current Hub committed a `0.1.35` marker, selected Hub recovery
157157
remains package-owned AgentNet-only reset, followed only under separate exact

‎docs/ARCHITECTURE.md‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -620,16 +620,16 @@ After database gate, wrapper owns only locked Approval/Core/C0 service identitie
620620

621621
Exact reruns do not trust old marker as realized state. Apply reruns bootstrap, reloads and validates Core configuration, reloads and validates Approval trust, and writes exact unit bytes before marker commit. Request-v1 marker-v2 retains original request/package/config/unit provenance and same-request v1 migration semantics. Request-v2 marker-v3 additionally binds explicit artifact mode and rejects marker-v1/v2 as evidence. Both preserve monotonic revision, previous-marker digest, and exact prior-byte compare-and-swap under setup lock. A root-owned current-package attempt record is written before first product mutation and removed only after marker commit, allowing exact interruption recovery while rejecting unowned pre-existing state.
622622

623-
The `0.1.36` corrective migration boundary admits only the exact released
623+
The `0.1.37` corrective migration boundary admits only the exact released
624624
`0.1.33` five-unit marker. Earlier sources use the separately released 0.1.33
625-
boundary first; 0.1.36 does not add another direct legacy edge and does not
625+
boundary first; 0.1.37 does not add another direct legacy edge and does not
626626
accept 0.1.34 or 0.1.35 as source markers. Exact prior managed configs/units are
627627
journaled before writes. For this edge, the target marker is the forward-only
628628
boundary: successful or exactly reconciled marker commit disarms source-byte
629629
rollback; all five units are quiesced before Core bootstrap may migrate
630630
PostgreSQL; and the journal is retained until bootstrap succeeds. A retained
631631
journal whose exact committed target is 0.1.33 may be superseded only after its
632-
marker/config/unit provenance is revalidated; it remains durable until 0.1.36
632+
marker/config/unit provenance is revalidated; it remains durable until 0.1.37
633633
atomically replaces it with the separate new journal before changing managed
634634
bytes.
635635
Quiescence clears systemd's failed latch only after bounded stop/disable and
@@ -644,7 +644,7 @@ OIDC/WebAuthn, guided key-possession enrollment, and offline activation remain
644644
explicit ceremonies. Remote Managers may provide immutable package guidance
645645
and inspect sanitized evidence only; target coding agents own host execution.
646646

647-
Candidate `0.1.36` adds only the exact `0.1.33` five-unit corrective migration edge above.
647+
Candidate `0.1.37` adds only the exact `0.1.33` five-unit corrective migration edge above.
648648
Setup rejects duplicate/non-finite JSON members, strictly parses the managed
649649
identity actor with canonical `VerifiedActor`, checks current
650650
domain/harness/credential labels, and retains exact profile shape plus private

0 commit comments

Comments
 (0)