Skip to content

Commit e2a51b8

Browse files
committed
feat(bindings): launch OMP through Manager
1 parent 601dc6c commit e2a51b8

17 files changed

Lines changed: 199 additions & 141 deletions

README.md

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -399,10 +399,11 @@ Artifacts, effects, federation, public A2A, administration, data, tools,
399399
and secrets remain excluded.
400400

401401
On a supported Linux owner laptop, the enrolled harness launches an interactive
402-
agent through `agentnet manager-run --identity .agentnet/identity.json -- pi`.
403-
The launcher stages the exact packaged Pi extension inside the private session,
404-
disables extension discovery, and rejects caller-supplied extension or tool-
405-
selection flags before opening the identity. The child gets only a short-lived,
402+
Pi or OMP agent through the package-owned `agentnet manager-run` command ending
403+
in `-- pi` or `-- omp`. The launcher stages the exact packaged Manager extension
404+
inside the private session, disables extension discovery, and rejects
405+
caller-supplied extension or tool-selection flags before
406+
opening the identity. The child gets only a short-lived,
406407
exact-process local binding for canonical communication tools—not the laptop key
407408
or reusable remote credentials. The parent owns
408409
authentication, strict request parsing, and cleanup. Full commands and

RELEASE_MANIFEST.json

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -529,20 +529,20 @@
529529
"release": {
530530
"name": "agentnet",
531531
"production_ready": false,
532-
"profile": "expired_laptop_credential_reauthorization_candidate",
533-
"reason": "All 19 must-not-ship gates remain non-PASSED; local evidence proves the package-owned same-binding expired-laptop credential reauthorization contract, but fresh installed-host, live owner WebAuthn/Core recovery, and required external, privileged, production-topology, and owner evidence remain absent.",
532+
"profile": "expired_credential_reauthorization_and_omp_manager_activation_candidate",
533+
"reason": "All 19 must-not-ship gates remain non-PASSED; local evidence proves same-binding expired-laptop credential reauthorization and measured Linux Pi/OMP Manager activation, but live OMP AgentNet tool use, fresh installed-host recovery, live owner WebAuthn/Core recovery, and required external, privileged, production-topology, and owner evidence remain absent.",
534534
"ship_eligible": false,
535535
"status": "BLOCKED",
536536
"version": "0.1.51"
537537
},
538538
"release_inputs": {
539539
"README.md": {
540540
"path": "README.md",
541-
"sha256": "c98f3fa0cce833f8166fb938281e68f1a44134d2d305e97372b0a00968b1fae9"
541+
"sha256": "54aae716059b4149725374c00867f6f8f7a2ef50b09febf17c0c98cc3f1258b0"
542542
},
543543
"REQUIREMENTS_STATUS.md": {
544544
"path": "REQUIREMENTS_STATUS.md",
545-
"sha256": "c7a57046e2b352ca4296bc7753fd7b783a0d8dd0f253708d561c1e2c54ce663e"
545+
"sha256": "82a1aa1c88fbf8c0f46e902f4cfa8d45bffe304f3b4cf2d609cb6502b2828ac2"
546546
},
547547
"deploy/Dockerfile": {
548548
"path": "deploy/Dockerfile",
@@ -562,11 +562,11 @@
562562
},
563563
"docs/GATE_EVIDENCE.md": {
564564
"path": "docs/GATE_EVIDENCE.md",
565-
"sha256": "51695ac55e5cbd41be39809b568ac78051eb1a91ac5aafe1b380bffc6af3325c"
565+
"sha256": "2c2db8a6c34fd008dd0dbeb2db12980d1ee2da539a561311a21e8de6571eb701"
566566
},
567567
"docs/RELEASE_MANIFEST.md": {
568568
"path": "docs/RELEASE_MANIFEST.md",
569-
"sha256": "c091bd6ac72357c3d4b923638244913a5b63a1e59c64c9509161b3c4fba4d9dd"
569+
"sha256": "de6860173c4d66a51c492922582654dd03b6bee6f11a5be5544230834cbe587a"
570570
},
571571
"evidence/gates/G01/2026-07-13-installed-harnesses/manifest.json": {
572572
"path": "evidence/gates/G01/2026-07-13-installed-harnesses/manifest.json",
@@ -602,13 +602,13 @@
602602
},
603603
"scripts/verify_release.py": {
604604
"path": "scripts/verify_release.py",
605-
"sha256": "fd3a11fbb1473c5a32d970d8bc102028b211c5ac0ace67412dfb8eac8bfa60a4"
605+
"sha256": "ac3b15b328f9e3a4465da42e57cb7d659b212fb6c44748cd1faa45f23e875e37"
606606
}
607607
},
608608
"release_source_tree": {
609609
"algorithm": "sha256(path NUL bytes NUL)",
610610
"path": "src",
611-
"sha256": "a3c1e64482bb7e0751dcbb3fb1a05d831f1b9d425b6063eca0a4c2a92612901d"
611+
"sha256": "0733a06a1ec40180a148348ef8b9fff9b845bfc1a8fc31c9f1f67f17073c1172"
612612
},
613613
"runtime": {
614614
"implementation": "CPython",

REQUIREMENTS_STATUS.md

Lines changed: 28 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -429,27 +429,34 @@ published and historical release evidence:
429429
requirement or must-not-ship gate is promoted.
430430

431431
- Candidate `0.1.51` adds a dedicated, package-owned reauthorization workflow
432-
for an expired ordinary laptop credential. It preserves the exact
433-
domain/principal/harness binding, OS- or hardware-bound public key, authority,
434-
scopes, memberships, capabilities, and credential-supersession history;
435-
requires fresh independent WebAuthn user verification; rejects active,
436-
revoked, mismatched, non-laptop, stale, replayed, expired-transaction, and
437-
conflicting bindings before key use or mutation; and commits exactly one
438-
same-key successor epoch with idempotent response-loss recovery. It grants no
439-
authority and performs no enrollment, generic renewal, key replacement, or
440-
service restart. Current evidence is hermetic only: the focused lane reports
441-
**698 passed and 5 expected dedicated-PostgreSQL skips**, the broad
442-
releasable-source lane reports **2197 passed and 21 expected
443-
platform/dedicated-PostgreSQL skips**, two independent release builds are
444-
byte-identical, and source plus two recursive packed generations each report
445-
**2224 passed and 21 expected platform/dedicated-PostgreSQL skips**. The
446-
packaged exact-endpoint routing gate, packaged `0.1.45` user journey, and
447-
separate-process communication/obligation roundtrip pass. Fresh
448-
installed-host, live owner WebAuthn/Core recovery, same-commit CI, and
449-
production-topology evidence remain pending. Affected IDs are `ID-006`,
450-
`ID-007`, `ID-009`, `AUTH-001`, `AUTH-002`, `AUTH-004`, `AUTH-007`,
451-
`SEC-003`, `SEC-005`, `SEC-007`, `OPS-003`, and `OPS-006`. No requirement or
452-
must-not-ship gate is promoted.
432+
for an expired ordinary laptop credential and generalizes the package-owned
433+
measured Manager launcher from Pi to Pi/OMP. Reauthorization preserves the
434+
exact domain/principal/harness binding, OS- or hardware-bound public key,
435+
authority, scopes, memberships, capabilities, and credential-supersession
436+
history; requires fresh independent WebAuthn user verification; rejects
437+
active, revoked, mismatched, non-laptop, stale, replayed,
438+
expired-transaction, and conflicting bindings before key use or mutation;
439+
and commits exactly one same-key successor epoch with idempotent
440+
response-loss recovery. It grants no authority and performs no enrollment,
441+
generic renewal, key replacement, or service restart. The OMP path reuses
442+
the existing measured single-child Manager composition, stages the exact
443+
packaged Pi-compatible extension, rejects caller-selected extensions/tools,
444+
retains exact-process binding and the private PID namespace/procfs sandbox,
445+
and exposes only canonical AgentNet tools. Current evidence is local only:
446+
the focused lane reports **763 passed and 5 expected dedicated-PostgreSQL
447+
skips**, the broad releasable-source lane reports **2203 passed and 21
448+
expected platform/dedicated-PostgreSQL skips**, and source plus two recursive
449+
packed generations each report **2230 passed and 21 expected
450+
platform/dedicated-PostgreSQL skips**. Two independent release builds are
451+
byte-identical; the packaged exact-endpoint routing gate, packaged `0.1.45`
452+
user journey, separate-process communication/obligation roundtrip, and
453+
measured Linux OMP launcher smoke pass. Fresh installed-host, live owner
454+
WebAuthn/Core recovery, live OMP AgentNet tool use, same-commit CI, and
455+
production-topology evidence remain pending. Affected IDs are `ARC-001`,
456+
`ARC-002`, `ARC-004`, `ID-006`, `ID-007`, `ID-009`, `AUTH-001`, `AUTH-002`,
457+
`AUTH-004`, `AUTH-007`, `COM-001`, `COM-002`, `COM-003`, `UX-001`, `UX-002`,
458+
`SEC-003`, `SEC-005`, `SEC-007`, `OPS-002`, `OPS-003`, `OPS-006`, and
459+
`OPS-007`. No requirement or must-not-ship gate is promoted.
453460

454461

455462

docs/ARCHITECTURE.md

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -359,10 +359,11 @@ Normal current-credential renewal preserves the scope because authority is
359359
harness-bound; harness/principal/domain revocation stops it immediately.
360360

361361
`agentnet manager-run` is the laptop-side interactive composition. Before
362-
identity loading it accepts only a Pi command and rejects caller extension/tool
363-
selection overrides. It copies the exact packaged AgentNet extension into the
364-
private session, disables extension discovery, launches one Pi child without
365-
signing keys, exposes only the canonical AgentNet tool surface through a private
362+
identity loading it accepts only a Pi or OMP command and rejects caller
363+
extension/tool selection overrides. It copies the exact packaged AgentNet
364+
extension into the private session, disables extension discovery, launches one
365+
Pi or OMP child without signing keys, exposes only the canonical AgentNet tool
366+
surface through a private
366367
per-process Unix socket, and derives every remote signed request from the
367368
Manager's authenticated actor. A short-lived inherited
368369
capability binds the exact child PID/process measurement, credential epoch,

docs/GATE_EVIDENCE.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -84,7 +84,7 @@ Gate statuses used here:
8484
| Candidate npm `0.1.48` canonical post-C0 credential correction | Completed-C0 terminal credentials now resolve through the exact domain/principal-bound harness plus credential epoch; unknown or mismatched identity state remains fail-closed. Adds only the exact forward-only `0.1.47→0.1.48` five-unit marker edge and no database migration. | Focused lane: `547 passed, 5 skipped`; broad releasable-source lane: `2155 passed, 21 skipped`; recursive packed-package and installed-host upgrade evidence pending. | H-only correction evidence; no gate promotion. Affected IDs: `ID-006`, `ID-009`, `SEC-007`, `OPS-003`. |
8585
| Candidate npm `0.1.49` completed-C0 communication recovery | Permanent communication activation resolves the exact completed C0 pair; only the authenticated ordinary server harness may advance to its current active credential, while the C0 peer remains pinned to its enrolled credential absent separately verified succession. Terminal pre-commit retries converge without replacing committed authority. Signed message send, inbox, and acknowledgement requests bind the exact collaboration scope. Adds only the forward-only `0.1.48→0.1.49` five-unit marker edge and no database migration. | Focused lane: `645 passed, 5 skipped`; broad releasable-source lane: `2166 passed, 21 skipped`; recursive packed-package and installed-host upgrade evidence pending. | H-only correction evidence; no gate promotion. Affected IDs: `ID-001`, `ID-002`, `ID-004`, `ID-006`, `AUTH-001`, `AUTH-002`, `AUTH-003`, `AUTH-004`, `AUTH-007`, `AUTH-009`, `COM-001`, `COM-002`, `COM-003`, `COM-006`, `COM-009`, `COM-011`, `AVL-003`, `AVL-005`, `AVL-006`, `SEC-003`, `SEC-005`. |
8686
| Candidate npm `0.1.50` setup-usability, direct-upgrade, and communication-scope approval path | One guided server command over the strict request/plan/apply protocol; one server-origin-only guided laptop command with authenticated discovery defaults; content-free named phases; ten-minute server and five-minute laptop bounds; resumable blocker output; exact direct allowlist from v0.1.45–v0.1.49 schema-v7 five-unit markers; installed separate-process local communication/obligation roundtrip added to packed verification; explicit one-hour Approval request ceiling limited to `authorization.communication_scope.approve`, with all other approvals retaining the five-minute ceiling and short-lived WebAuthn challenges | Focused release lane: `681 passed, 5 skipped`; broad releasable-source lane: `2180 passed, 21 skipped`; source and two recursive packed generations: `2207 passed, 21 skipped` each; two byte-identical release builds; release manifest verifier passed; installed tarball journey passed from an unrelated prefix; installed-host, fresh-machine, and same-commit CI evidence pending | H/L-shaped local candidate evidence only. No production, owner-policy, external, privileged-host, or gate promotion. Affected IDs: `ID-006`, `AUTH-004`, `AUTH-007`, `COM-001`, `COM-002`, `COM-003`, `COM-006`, `COM-009`, `AVL-003`, `AVL-005`, `AVL-006`, `UX-001`, `UX-002`, `SEC-003`, `SEC-005`, `OPS-003`, `OPS-006`. |
87-
| Candidate npm `0.1.51` same-binding expired laptop credential reauthorization | Dedicated package-owned recovery for an expired ordinary laptop credential preserves the exact domain/principal/harness binding, OS- or hardware-bound public key, authority, scopes, memberships, capabilities, and supersession history. Fresh independent WebAuthn user verification is required; active, revoked, mismatched, non-laptop, stale, replayed, expired-transaction, and conflicting bindings fail before key use or mutation. One same-key successor epoch commits idempotently; no enrollment, generic renewal, key replacement, authority grant, or service restart occurs. | Focused lane: `698 passed, 5 skipped`; broad releasable-source lane: `2197 passed, 21 skipped`; source plus two recursive packed generations: `2224 passed, 21 skipped` each; two byte-identical release builds; packaged exact-endpoint routing, packaged `0.1.45` user journey, and separate-process communication/obligation roundtrip passed; fresh installed-host, live owner WebAuthn/Core recovery, same-commit CI, and production-topology evidence pending. | H/L-shaped local recovery and packaging evidence only; no gate promotion. Affected IDs: `ID-006`, `ID-007`, `ID-009`, `AUTH-001`, `AUTH-002`, `AUTH-004`, `AUTH-007`, `SEC-003`, `SEC-005`, `SEC-007`, `OPS-003`, `OPS-006`. |
87+
| Candidate npm `0.1.51` same-binding expired laptop credential reauthorization and measured Pi/OMP Manager activation | Dedicated package-owned recovery for an expired ordinary laptop credential preserves the exact domain/principal/harness binding, OS- or hardware-bound public key, authority, scopes, memberships, capabilities, and supersession history. Fresh independent WebAuthn user verification is required; active, revoked, mismatched, non-laptop, stale, replayed, expired-transaction, and conflicting bindings fail before key use or mutation. One same-key successor epoch commits idempotently; no enrollment, generic renewal, key replacement, authority grant, or service restart occurs. The existing single-child Manager launcher now accepts Pi or OMP, stages the exact packaged Pi-compatible extension, rejects caller-selected extension/tool flags, retains exact-process binding and a private PID namespace/procfs sandbox, and exposes only canonical AgentNet tools. | Focused lane: `763 passed, 5 skipped`; broad releasable-source lane: `2203 passed, 21 skipped`; source plus two recursive packed generations: `2230 passed, 21 skipped` each; two byte-identical release builds; release verifier, packaged exact-endpoint routing, packaged `0.1.45` user journey, separate-process communication/obligation roundtrip, and measured Linux OMP launcher smoke passed; fresh installed-host, live owner WebAuthn/Core recovery, live OMP AgentNet tool use, same-commit CI, and production-topology evidence pending. | H/L-shaped local recovery, Manager activation, and packaging evidence only; no gate promotion. Affected IDs: `ARC-001`, `ARC-002`, `ARC-004`, `ID-006`, `ID-007`, `ID-009`, `AUTH-001`, `AUTH-002`, `AUTH-004`, `AUTH-007`, `COM-001`, `COM-002`, `COM-003`, `UX-001`, `UX-002`, `SEC-003`, `SEC-005`, `SEC-007`, `OPS-002`, `OPS-003`, `OPS-006`, `OPS-007`. |
8888
| OIDC validated-address transport repair | `UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/identity/test_oidc_enrollment.py tests/operations/test_fail_closed_config.py tests/production/test_deployment_config.py` | 53 passed, 0 failed on 2026-07-15 | H only: includes the real `_PinnedHTTPSConnection` socket path under a validation-to-connect DNS-answer change, exact TCP address/SNI/Host assertions, proxy/tunnel and redirect denial, response bounds, unsafe address-class rejection, invalid resolver type handling, private IPv4/IPv6 pins, configuration, and deployment wiring. No real IdP/TLS service or independent approval boundary is claimed. |
8989
| Independent WebAuthn-UV approval component | `UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/approval`; approval-consumer lane; non-gate full regression below | 12 focused passed; 144 approval/consumer passed; included in 1049-pass broad lane on 2026-07-15 | H only: strict owner-only config/key custody, exact SQLite catalog/tamper rejection, UV-required maintained-library call contract, exact display/digest, bounded duplicate-rejecting HTTP, one-receipt response-loss retry, committed denial/expiry audits, rejection, credential revocation, loopback serving, and non-authorizing provisioning. WebAuthn verification is seam-controlled in hermetic tests; no real authenticator, independent host/device/operator, TLS proxy, rotation/recovery drill, or owner decision is claimed. |
9090
| Prior `0.1.8` candidate, unfiltered local run | `UV_CACHE_DIR=/tmp/uv-cache uv run --extra test pytest -q` | `1087 passed, 2 failed, 7 expected PostgreSQL skips` on 2026-07-16 | Both failures were preserved environmental G01 gates. This was not a passing unfiltered release run and is not current `0.1.9` evidence. |

docs/RELEASE_MANIFEST.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
Snapshot: 2026-08-14
44
Candidate: `agentnet 0.1.51`
55
Latest published package: `agentnet 0.1.50`
6-
Evidence profile: package-owned same-binding expired-laptop credential reauthorization with exact identity/key/authority preservation, old-key possession, fresh owner WebAuthn UV, atomic epoch+1 replacement, idempotent response-loss recovery, and direct allowlisted v0.1.45–v0.1.50 setup-marker upgrade compatibility
6+
Evidence profile: package-owned same-binding expired-laptop credential reauthorization plus measured Linux Pi/OMP Manager activation through one packaged extension, canonical tool allowlist, exact-process capability, private PID namespace/procfs, and direct allowlisted v0.1.45–v0.1.50 setup-marker upgrade compatibility
77

88
This is not a production release. It is the human projection of
99
`RELEASE_MANIFEST.json`; local evidence cannot promote external, privileged,
@@ -16,7 +16,7 @@ owner, installer, or production-topology gates.
1616
| Must-not-ship gate status | `BLOCKED` |
1717
| Production ready | `false` |
1818
| Ship eligible | `false` |
19-
| Reason | Every must-not-ship gate remains non-passed; hermetic recovery and packaging evidence does not substitute for fresh installed-host, live owner WebAuthn/Core recovery, or required P/E/O evidence. |
19+
| Reason | Every must-not-ship gate remains non-passed; local recovery, Manager-launcher, and packaging evidence does not substitute for live OMP AgentNet tool use, fresh installed-host recovery, live owner WebAuthn/Core recovery, or required P/E/O evidence. |
2020

2121
## Runtime and dependency lock
2222

docs/SCHEMAS_INTERFACES.md

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -83,10 +83,11 @@ locator and close the pin; retryable renewal preserves it. Runtime status and
8383
its content-free state expose a fixed `last_failure` code, never raw exception
8484
text. Platforms without that primitive fail the MCP binding closed. Windows uses
8585
protected named pipes with remote-client rejection and server-derived client
86-
PID. Pi capability bytes never enter argv or environment. Interactive
87-
`manager-run` stages the packaged Pi extension inside the private session and
88-
owns extension discovery/tool-selection flags; caller overrides fail before
89-
identity loading. Supervisor Pi capability delivery uses sealed memfd on Linux,
86+
PID. Manager capability bytes never enter argv or environment. Interactive
87+
`manager-run` stages the packaged Pi-compatible extension for a Pi or OMP child
88+
inside the private session and owns extension discovery/tool-selection flags;
89+
caller overrides fail before identity loading. Supervisor Pi capability
90+
delivery uses sealed memfd on Linux,
9091
a read-only inherited pipe on macOS, and a one-time exact-process pipe on
9192
Windows. Interactive `manager-run` is Linux-only until equivalent process-tree
9293
and filesystem containment exists elsewhere. Missing delivery acknowledgement

0 commit comments

Comments
 (0)