Skip to content

Commit a4a1f58

Browse files
committed
chore(release): prepare 0.1.43 candidate
1 parent a33b744 commit a4a1f58

19 files changed

Lines changed: 253 additions & 72 deletions

PUBLIC_RELEASE_STATUS.md

Lines changed: 26 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
# Public Package Status
22

3-
Snapshot: 2026-08-03
3+
Snapshot: 2026-08-04
44

55
This additive status note reconciles public package availability with AgentNet's
6-
published `0.1.38` release and corrective `0.1.39` candidate. It does not replace requirements, gate ledgers, or
7-
accountable-owner evidence.
6+
published `0.1.38` release and corrective `0.1.43` candidate. It does not replace
7+
requirements, gate ledgers, or accountable-owner evidence.
88

99
## Current public package
1010

@@ -200,6 +200,29 @@ public bytes, and fresh Hub setup remain pending separately approved actions. No
200200
Hub deployment, reset, database, enrollment, authority, native C0, federation,
201201
production, or gate mutation is implied.
202202

203+
Candidate `0.1.43` consolidates the unpublished corrective sequence and the
204+
narrow first-C0 evidence. A disposable ordinary server and separately stored
205+
laptop harness completed real Google workforce OIDC plus owner WebAuthn UV,
206+
remained identity-only before one fixed approved plan, then completed one native
207+
request/reply/ACK round trip and exact revocation of all five temporary
208+
communication entitlements. The retained historical deployment used source
209+
`d8884b6c03a0dd38baab03386982aae8ad11dd58`; it did not include the later
210+
credential-open correction.
211+
212+
The candidate accepts strict remote-browser bootstrap evidence without weakening
213+
local-browser evidence, preserves the systemd responder's P-256 private key as
214+
bytes, permits only its package-owned credential file, and opens that file with
215+
`O_NONBLOCK` before regular-file custody validation. A dedicated regression
216+
demonstrably failed before the nonblocking correction and the responder file
217+
then passed 23 tests. Local focused and broad-source gates passed. Fresh npm
218+
tarballs from both recursive generations repeated the broad source lane, and
219+
the retained-content generation completed the real installed-byte local
220+
communication journey with an empty workspace. The candidate evidence manifest
221+
records final release-manifest/direct-verifier and retained byte-identical
222+
archive outcomes. Same-commit CI, immutable tag, trusted npm stage,
223+
staged-package remote deployment, and publication remain required external
224+
actions; none is inferred from the historical `0.1.42` run.
225+
203226
## Release and gate posture
204227

205228
`RELEASE_MANIFEST.json` remains controlling for release eligibility:

README.md

Lines changed: 22 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -162,7 +162,7 @@ controls.
162162
AgentNet package installation, local SQLite state, signed HTTP clients, and
163163
host-local binding adapters support Linux, macOS, and Windows. Node.js 22.19 or
164164
newer and [`uv`](https://docs.astral.sh/uv/) 0.11.28 or newer must be on `PATH`.
165-
Only non-EOL Node.js release lines are supported: current `0.1.39` coverage targets
165+
Only non-EOL Node.js release lines are supported: current `0.1.43` coverage targets
166166
Node.js 22 LTS, 24 LTS, and 26 Current; Node.js 23 and 25 are unsupported despite
167167
the broad npm engine floor. Minimum-floor CI uses Node.js 22.19.0 with its
168168
compatible npm 10.9.3; the deployed Hub compatibility target is reported
@@ -377,15 +377,29 @@ for that exact state. Published `0.1.37` removes one unsatisfiable fresh-init
377377
identity-profile check. Published `0.1.38` extends only the bounded public
378378
post-restart health/readiness wait, but the remote Hub peer reported from bounded
379379
read-only preflight that its default `Python-urllib/*` request identity was
380-
rejected with HTTP 403 before origin routing. Candidate `0.1.39` sends an explicit
380+
rejected with HTTP 403 before origin routing. Unpublished `0.1.39` sent an explicit
381381
`AgentNet/0.1.39` User-Agent and JSON Accept header while preserving the same TLS,
382382
redirect, proxy, timeout, payload, and exact-identity checks. It also repairs the
383383
local-only signed lab path so intentional `deterministic_only` harnesses can use
384384
the existing narrow C0 allowlist without becoming production-active, and adds the
385385
installed-package multiprocess gate described above. It is a clean-state setup
386-
candidate and accepts no earlier release marker as migration input. No release proves completed
387-
fresh-laptop enrollment, native
388-
cross-host message/ACK, production readiness, or ship eligibility. The earlier `0.1.24`
386+
candidate and accepts no earlier release marker as migration input. No release
387+
proves completed fresh-laptop enrollment, native cross-host message/ACK,
388+
production readiness, or ship eligibility.
389+
390+
Candidate `0.1.43` carries the corrected first-C0 path proven narrowly by the
391+
unpublished `0.1.42` deployment: real workforce OIDC, owner-controlled WebAuthn
392+
UV, separately enrolled server and laptop harnesses, one fixed
393+
`BootstrapGrantPlan`, `COMPLETED_C0_ROUND_TRIP`, and exact five-power revocation.
394+
It additionally accepts only strict remote-browser bootstrap evidence, keeps
395+
the responder's P-256 private key as bytes instead of corrupting it through text
396+
decoding, permits only the package-owned systemd credential file, and opens that
397+
credential with `O_NONBLOCK` before regular-file custody validation so a FIFO or
398+
device fails closed without stalling startup. The historical live run remains
399+
bound to `d8884b6c03a0dd38baab03386982aae8ad11dd58`; candidate `0.1.43` requires
400+
fresh same-commit build, CI, staged-package, and remote deployment evidence.
401+
No requirement or must-not-ship gate is promoted by the narrow prior run. The
402+
earlier `0.1.24`
389403
release introduced product-owned ordinary Linux server setup: fixed
390404
plan/apply/start convergence, Approval/Core separation, scanner trust, exact
391405
public HTTPS health identity, interruption recovery, redacted evidence, and
@@ -490,14 +504,14 @@ and failure semantics are unchanged. The remote Hub peer reported from bounded
490504
read-only preflight that the stdlib default `Python-urllib/*` User-Agent received
491505
HTTP 403 on all three public routes, while an explicit AgentNet product User-Agent
492506
passed edge classification and reached the offline origin response. That report is
493-
corroboration only, not retained reproducible release proof. Candidate `0.1.39`
494-
changes request identity to explicit GET, `User-Agent: AgentNet/0.1.39`, and
507+
corroboration only, not retained reproducible release proof. Unpublished `0.1.39`
508+
changed request identity to explicit GET, `User-Agent: AgentNet/0.1.39`, and
495509
`Accept: application/json`; it also adds the bounded synthetic installed-package
496510
communication gate without weakening the production policy engine. It adds no
497511
migration edge and rejects existing release markers. Release still requires exact same-commit terminal-green
498512
cross-platform, clean-setup, and exact released-marker rejection workflow
499513
evidence; post-push run IDs are not
500-
self-authored into source. Required runtime proof remains exact public `0.1.39`, clean five-unit readiness,
514+
self-authored into source. Required runtime proof now targets exact staged `0.1.43`, clean five-unit readiness,
501515
fresh enrollment, one native
502516
signed message, recipient `recipient_committed`, exact
503517
`COMPLETED_C0_ROUND_TRIP`, then five-power revocation and post-revocation refusal.

RELEASE_MANIFEST.json

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
11
{
22
"$schema": "https://agentnet.invalid/schemas/release-manifest-v1.json",
33
"manifest_version": "1.0",
4-
"snapshot_date": "2026-08-03",
4+
"snapshot_date": "2026-08-04",
55
"release": {
66
"name": "agentnet",
7-
"version": "0.1.39",
8-
"profile": "public_health_and_packaged_local_communication_candidate",
7+
"version": "0.1.43",
8+
"profile": "corrected_first_c0_release_candidate",
99
"status": "BLOCKED",
1010
"production_ready": false,
1111
"ship_eligible": false,
@@ -32,12 +32,12 @@
3232
},
3333
"dependency_lock": {
3434
"path": "uv.lock",
35-
"sha256": "942a612badeff0d02349359bbdcd528fd09d4cc583c57f3c9fd92d05da796285",
35+
"sha256": "d961a710a41d71923ce5565ccdc6200d7720f121eda8c0c9623143d6cf140c1c",
3636
"format_version": 1,
3737
"revision": 3,
3838
"pyproject": {
3939
"path": "pyproject.toml",
40-
"sha256": "ed6bac592c242f59d1500d6d118bf7dc0118e7938c3ccc87e596c14b96d9375f"
40+
"sha256": "3402f8e836bed7c8a083777d0bb3a0a35361a525f5f05fce17a3bc7855a47402"
4141
},
4242
"direct_dependencies": {
4343
"build": {
@@ -193,11 +193,11 @@
193193
"release_inputs": {
194194
"README.md": {
195195
"path": "README.md",
196-
"sha256": "2af059607f85d9188f69508495f8b866e897565fd78e704e001c4a7aaf7eea70"
196+
"sha256": "4248526bed1ad4047ac9a43bd60bacf82445d6cb8a51dc51beee5fe375aa354e"
197197
},
198198
"REQUIREMENTS_STATUS.md": {
199199
"path": "REQUIREMENTS_STATUS.md",
200-
"sha256": "a3ea62531f9a4dc2d8f65e187e6e4c9c12703328418d57c94184c3980ceb983b"
200+
"sha256": "1337a8ad7faef9ba029f7ec477c046c055c59d5d55703d560a47e30a670e7a48"
201201
},
202202
"deploy/Dockerfile": {
203203
"path": "deploy/Dockerfile",
@@ -217,11 +217,11 @@
217217
},
218218
"docs/GATE_EVIDENCE.md": {
219219
"path": "docs/GATE_EVIDENCE.md",
220-
"sha256": "4a1678c7fefdfee1c6e1ee870b2ca417b2e2491031af69d276313efdedcac3ff"
220+
"sha256": "8e62cded8b925bd49d7a5e9643f8b0e23737b65758ce7b9e52791bca262b34b6"
221221
},
222222
"docs/RELEASE_MANIFEST.md": {
223223
"path": "docs/RELEASE_MANIFEST.md",
224-
"sha256": "c9eccf4898307b232bf168e71ca7cbfbc74885ed3afc78ca23f7bac95beec864"
224+
"sha256": "d62e17419c4197d6750b19c56a03747fe05cb4bfaf5f6587e2367851b458a71b"
225225
},
226226
"evidence/gates/G01/2026-07-13-installed-harnesses/manifest.json": {
227227
"path": "evidence/gates/G01/2026-07-13-installed-harnesses/manifest.json",
@@ -249,13 +249,13 @@
249249
},
250250
"scripts/verify_release.py": {
251251
"path": "scripts/verify_release.py",
252-
"sha256": "fafc39b1abd19b767d1f11c7e4c63572dbb6b4512fe46593deabaed1b9798ecc"
252+
"sha256": "22e9b7be75d12cc1b3db5638d1b3f371fb6d9dd1373d9c25052edf44ecb80da3"
253253
}
254254
},
255255
"release_source_tree": {
256256
"path": "src",
257257
"algorithm": "sha256(path NUL bytes NUL)",
258-
"sha256": "4d3961f7c871fc969828a5119cba02946e410e141f019b9a97f41aa0ca4c7016"
258+
"sha256": "667d9ebe8d4ba60d3ac931a321f9c9cb10749ed601c6047c3efdd58eaf6cdd67"
259259
},
260260
"protocols": {
261261
"a2a": {

REQUIREMENTS_STATUS.md

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -234,6 +234,26 @@ published and historical release evidence:
234234
candidate build and deployment evidence before any release handoff.
235235
Focused corrective evidence and review closure are retained at
236236
`evidence/local/2026-08-04-v0.1.42-post-live-corrective/manifest.json`.
237+
- Candidate `0.1.43` packages the corrected source for a fresh same-commit
238+
release path. It includes strict remote-browser bootstrap evidence,
239+
byte-preserving P-256 responder credential handling, package-owned systemd
240+
credential custody, and `O_NONBLOCK` before regular-file validation. Current
241+
local source verification reports **757 passed and 7 expected dedicated-
242+
PostgreSQL skips** in the affected lane and **1640 passed and 16 expected
243+
platform/dedicated-PostgreSQL skips** in the broad source lane. Fresh npm
244+
tarballs from both recursive generations each repeated that **1640 passed,
245+
16 expected skips** source lane; the retained-content second generation also
246+
completed the real loopback Core/separate-client local communication journey
247+
and left an empty workspace. The candidate evidence manifest records the
248+
final release-manifest/direct-verifier and retained byte-identical archive
249+
outcomes. Same-commit CI, immutable tag, npm stage, staged-package remote
250+
deployment, and publication remain external actions. The `0.1.42` live run
251+
remains historical evidence only and was not rerun after the descriptor-open
252+
correction. Affected IDs remain
253+
`ID-001`, `ID-002`, `ID-004`, `ID-006`, `AUTH-001`, `AUTH-002`, `AUTH-003`,
254+
`AUTH-004`, `AUTH-007`, `AUTH-009`, `COM-001`, `COM-002`, `COM-003`,
255+
`COM-006`, `COM-009`, `AVL-003`, `AVL-005`, `AVL-006`, `SEC-003`,
256+
`SEC-005`, `OPS-003`, and `OPS-006`. No requirement or gate is promoted.
237257

238258
- S5/S6 directly exercise `ID-006`, `AUTH-001`, `AUTH-002`, `AUTH-003`,
239259
`AUTH-004`, `AUTH-007`, `COM-001`, `COM-009`, `AVL-005`, `AVL-006`, `UX-001`,

docs/GATE_EVIDENCE.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -76,6 +76,7 @@ Gate statuses used here:
7676
| Corrective npm `0.1.39` request-identity plus packaged local-communication candidate | Explicit GET `urllib.request.Request`; `User-Agent: AgentNet/0.1.39`; JSON Accept; unchanged TLS/proxy/redirect/timeout/identity boundaries; local-policy-only deterministic lab revision, recipient-resolution, and custody-ACK composition; second recursive npm generation runs a real Core plus separate fresh-proof client processes over loopback from installed bytes; fresh clean-state setup only with no migration edge | Health regression passed (`2 passed`); setup/recovery (`224 passed`) and prior focused release (`645 passed, 7 expected PostgreSQL skips`) remain green. New focused synthetic-lane/HTTP/obligation regressions report `7 passed`. A fresh manually packed npm tarball installed into an unrelated prefix passed `accepted_local`, exact proof-derived request/reply attribution, offline recipient recovery after Core restart, stable request event/obligation and ACK receipt idempotency, `recipient_committed`, typed obligation `completed`, requester response custody after another restart, fresh authentication refusal after an explicitly non-approved lab credential fixture, closed listener, and removed state. Final metadata-bound recursive verification passed in both clean npm generations with `1642 passed, 16 expected skips` each; generation 2 additionally passed the installed-byte multiprocess lifecycle, package-tree equality, empty-workspace, listener-release, and no-residue checks. Peer-reported 403→502 comparison remains corroboration only. | `BLOCKED`; H/L-shaped synthetic local evidence only. The production policy engine still rejects deterministic lab harnesses. This is not bounded `COMPLETED_C0_ROUND_TRIP`, approved revocation or five-power cleanup, real enrollment, ordinary server-agent `COM-002`/`COM-003`, PostgreSQL durability, Hub installation, production, ship, requirement, or gate promotion. Exact same-commit cross-platform, clean-setup, public-0.1.38-marker rejection, packaged communication, tag, stage, public-byte, and fresh-setup evidence remain pending. |
7777
| Unpublished npm `0.1.42` narrow real C0 candidate | Explicit owner-approved reset of only disposable AgentNet state; fresh ordinary server setup; real workforce Google OIDC and owner-controlled WebAuthn UV for exact server and laptop harness enrollment; strict remote-browser challenge evidence; fixed one-hour `BootstrapGrantPlan`; package-owned systemd responder credential custody; native request/reply/ACK journey; authoritative PostgreSQL postcondition query | Narrow live path PASS: both harnesses ended identity-only before the fixed plan; plan commit returned `prepared_unusable`; `c0-pilot` progressed `waiting_owner` → `waiting_fresh` → `COMPLETED_C0_ROUND_TRIP`; retained parent-scoped postconditions are exactly one committed plan, its one revoked guard, its one `communication_revoked` attempt, 7 rows/7 distinct fact kinds for that attempt, 5/5 communication entitlements for that plan revoked, and 5 exact-revoke items for that plan. Broad run remains non-green: `1747 passed, 16 skipped, 3 failed`; `agentnet verify` reported `1665 passed, 16 skipped, 1 failed`; release verifier reported 15 manifest/source/package drift findings. | Narrow L/E-shaped real IdP/authenticator plus disposable single-node service evidence is retained at `evidence/local/2026-08-04-v0.1.42-c0-live/manifest.json`; its sanitized parent-scoped postcondition query/result is hash-bound as `postconditions.json` SHA-256 `518f030c0503f93bcc6e119581c1c4d88c16f6ec06b69addc2768a5c7be2681a`. Both artifacts remain historical evidence for deployed source `d8884b6c03a0dd38baab03386982aae8ad11dd58`; they do not prove the post-run nonblocking credential-open correction at `52b6941`. The run does not pass a gate, certify a release, prove independent approval hosting, production key custody, PostgreSQL HA/PITR, real four-harness semantics, cross-platform packaging, or owner decisions. Candidate is unpublished and release posture remains BLOCKED. |
7878
| Post-live `0.1.42` credential-open correction | `O_NONBLOCK` before descriptor metadata validation; dedicated regression; retained parent-scoped C0 SQL/result evidence | Regression failed before the correction; responder file passed `23 tests`; independent corrective review ended `NO_BLOCKING_FINDINGS` | H-shaped source-only evidence at `evidence/local/2026-08-04-v0.1.42-post-live-corrective/manifest.json`. Revision `52b6941` was not deployed for the historical live run. No package, live rerun, release, requirement, or gate promotion is claimed. |
79+
| Candidate npm `0.1.43` corrected first-C0 release path | Strict remote-browser bootstrap evidence; byte-preserving P-256 responder credential handling; package-owned systemd credential custody; `O_NONBLOCK` before regular-file validation; retained historical real OIDC/WebAuthn two-harness C0 and exact-revocation evidence | Focused affected lane `757 passed, 7 expected dedicated-PostgreSQL skips`; broad source lane and both fresh recursive npm generations each `1640 passed, 16 expected skips`; the retained-content generation completed the real loopback Core/separate-client local communication journey and left an empty workspace. The candidate manifest records final release-manifest/direct-verifier and byte-identical archive outcomes. Same-commit CI/stage and corrected-source remote evidence remain external actions. Historical narrow deployment passed only at source `d8884b6c03a0dd38baab03386982aae8ad11dd58`. | H/L-shaped candidate source, recursive-package, installed-byte, and retained-archive evidence at `evidence/local/2026-08-04-v0.1.43/manifest.json`. The historical live run predates the descriptor-open correction. No requirement, release, production, or gate promotion is claimed. |
7980
| OIDC validated-address transport repair | `UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/identity/test_oidc_enrollment.py tests/operations/test_fail_closed_config.py tests/production/test_deployment_config.py` | 53 passed, 0 failed on 2026-07-15 | H only: includes the real `_PinnedHTTPSConnection` socket path under a validation-to-connect DNS-answer change, exact TCP address/SNI/Host assertions, proxy/tunnel and redirect denial, response bounds, unsafe address-class rejection, invalid resolver type handling, private IPv4/IPv6 pins, configuration, and deployment wiring. No real IdP/TLS service or independent approval boundary is claimed. |
8081
| Independent WebAuthn-UV approval component | `UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/approval`; approval-consumer lane; non-gate full regression below | 12 focused passed; 144 approval/consumer passed; included in 1049-pass broad lane on 2026-07-15 | H only: strict owner-only config/key custody, exact SQLite catalog/tamper rejection, UV-required maintained-library call contract, exact display/digest, bounded duplicate-rejecting HTTP, one-receipt response-loss retry, committed denial/expiry audits, rejection, credential revocation, loopback serving, and non-authorizing provisioning. WebAuthn verification is seam-controlled in hermetic tests; no real authenticator, independent host/device/operator, TLS proxy, rotation/recovery drill, or owner decision is claimed. |
8182
| Prior `0.1.8` candidate, unfiltered local run | `UV_CACHE_DIR=/tmp/uv-cache uv run --extra test pytest -q` | `1087 passed, 2 failed, 7 expected PostgreSQL skips` on 2026-07-16 | Both failures were preserved environmental G01 gates. This was not a passing unfiltered release run and is not current `0.1.9` evidence. |

0 commit comments

Comments
 (0)