@@ -198,9 +198,13 @@ identity or authority source. You can also load it explicitly with
198198
199199### Product-owned ordinary Linux server setup
200200
201- After verifying system-wide root-owned AgentNet, Node.js, and ` uv ` executables, then
202- resolving approved PostgreSQL, OIDC, scanner trust, secret-file, and distinct
203- public HTTPS-route inputs, plan without writes:
201+ Follow the bundled canonical checklist in
202+ [ ` skills/agentnet-operator/references/ordinary-server-setup.md ` ] ( skills/agentnet-operator/references/ordinary-server-setup.md ) .
203+ First verify system-wide root-owned AgentNet, Node.js, and ` uv ` executables whose
204+ resolved paths are outside ` /root ` , ` /home ` , and ` /run/user ` . Prepare exact
205+ owner-only OIDC/scanner/environment inputs and the fixed local PostgreSQL peer
206+ contract (` agentnet ` OS user → ` agentnet ` role/database through
207+ ` /var/run/postgresql ` ). Then plan without privileged or managed-host writes (the npm launcher may materialize its caller-owned Python runtime):
204208
205209``` bash
206210< resolved-root-owned-agentnet-path> server-agent setup --request /home/operator/.config/agentnet-setup/server-setup.json
@@ -215,15 +219,26 @@ sudo -- <resolved-root-owned-agentnet-path> server-agent setup \
215219 --apply --start
216220```
217221
218- This fixed wrapper creates only AgentNet's two locked identities, private roots,
219- Approval/Core state, scanner trust, and two hardened systemd units. It starts
220- loopback Core and Approval, verifies operator-owned public HTTPS routes, emits
221- redacted resumable evidence, and rejects conflicting state without overwrite.
222- It never mutates DNS, TLS certificates, proxy or firewall policy, PostgreSQL
223- administration, identity, or authority. A remote Manager does not shell into
224- the target. Human OIDC/WebAuthn and offline activation remain explicit steps in
225- the bundled skill. Final setup status is ` operational ` with identity enrolled
226- and authority still false.
222+ Plan and apply bind exact Node/uv/launcher/` systemctl ` /` useradd ` paths and
223+ content hashes plus the canonical full AgentNet package-tree content hash to
224+ approval digest v2. Apply
225+ repeats preflight under an exclusive lock, may create the fixed Core OS identity
226+ plus root-owned setup runtime/lock, and then blocks before AgentNet
227+ environments/config/database writes
228+ unless a read-only canary succeeds as that identity and parsed PostgreSQL
229+ HBA/ident views plus config-load freshness prove the exact loaded unshadowed
230+ ` local agentnet agentnet peer ` rule. PostgreSQL
231+ role/database/HBA edits and reload remain a separate operator-owned approval;
232+ rerun the same AgentNet digest afterward.
233+
234+ The wrapper then owns only AgentNet's two locked identities, private roots,
235+ Approval/Core state, scanner trust, two hardened systemd units, bounded start,
236+ and exact loopback/public health. Retry reloads realized state and commits
237+ marker v2 only through same-request compare-and-swap; manual marker/unit surgery
238+ is unsupported. It never mutates DNS, TLS, proxy/firewall policy, PostgreSQL
239+ administration, identity, or authority. Human OIDC/WebAuthn and offline
240+ activation remain explicit. Final setup status is ` operational ` with identity
241+ enrolled and authority still false.
227242
228243For a real network, AgentNet's install-and-use contract is the exact capability
229244set in [ ` docs/requirements.md ` ] ( docs/requirements.md ) —no reduced messaging
@@ -291,7 +306,8 @@ always-on deployment—see the [implementation guide](docs/implementation-guide.
291306## Project status
292307
293308AgentNet is an early public implementation; latest published package is
294- ` 0.1.24 ` . That release contains the product-owned ordinary Linux server setup:
309+ ` 0.1.25 ` . The current unpublished ` 0.1.26 ` candidate corrects ordinary Linux
310+ server setup convergence. The earlier ` 0.1.24 ` release introduced product-owned ordinary Linux server setup:
295311fixed plan/apply/start convergence, Approval/Core separation, scanner trust,
296312exact public HTTPS health identity, interruption recovery, redacted evidence,
297313and bundled operator workflow. Setup grants neither identity nor authority.
@@ -302,7 +318,7 @@ runner where that path did not exist. No `0.1.23` package was staged or
302318published. Published ` 0.1.24 ` changed only that fixture to mock AgentNet's
303319validated host-tool resolver directly; runtime behavior was unchanged.
304320
305- Prepared ` 0.1.25 ` repairs two JSON-RPC interoperability defects exposed by the
321+ Published ` 0.1.25 ` repairs two JSON-RPC interoperability defects exposed by the
306322pinned official A2A TCK: ` /rpc ` and ` /rpc/ ` now use the same strict endpoint
307323without POST redirects, and a blank SDK request tenant is restored only from an
308324exact verified opaque route binding. Missing/spoofed bindings and tenant
@@ -313,10 +329,16 @@ release-manifest self-check reports `1386 passed, 15 expected host/PostgreSQL
313329skips` . The focused official JSON-RPC lane reports ` 3 passed`, while the full
314330MUST run remains non-green at ` 50 passed, 11 failed, 174 skipped ` ; G04 therefore
315331remains ` FAILED ` . Exact prepublication, retained-artifact, recursive packed, and
316- Pi-loader checks are recorded in the candidate evidence after they pass.
317- Privileged clean-host apply, cross-SDK/public-peer evidence, live
318- PostgreSQL/OIDC/WebAuthn/TLS ceremony, Sergey-only publication, and independent
319- public-artifact deployment remain pending or separately gated. Repository
332+ Pi-loader checks are recorded in its immutable evidence.
333+
334+ Unpublished ` 0.1.26 ` repairs runtime-bound setup approval, semantic broker
335+ preflight, exact PostgreSQL service-identity peer validation, safe same-digest
336+ resume, marker provenance/CAS, Windows CLI imports, and installer guidance.
337+ Local source/package evidence is recorded as working-candidate evidence only;
338+ clean Ubuntu 24.04/PostgreSQL 18 CI, cross-platform CI, retained-artifact refresh,
339+ Sergey-only publication, and independent public-artifact deployment remain
340+ pending. Cross-SDK/public-peer evidence and live OIDC/WebAuthn ceremony remain
341+ separately gated. Repository
320342evidence is not a completed live cross-host journey or production certification.
321343
322344Production adoption still requires deployment-specific evidence such as a real
0 commit comments