You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
"reason": "All 19 must-not-ship gates remain non-PASSED; local evidence proves the package-owned same-binding expired-laptop credential reauthorization contract, but fresh installed-host, live owner WebAuthn/Core recovery, and required external, privileged, production-topology, and owner evidence remain absent.",
"reason": "All 19 must-not-ship gates remain non-PASSED; local evidence proves same-binding expired-laptop credential reauthorization and measured Linux Pi/OMP Manager activation, but live OMP AgentNet tool use, fresh installed-host recovery, live owner WebAuthn/Core recovery, and required external, privileged, production-topology, and owner evidence remain absent.",
Copy file name to clipboardExpand all lines: docs/GATE_EVIDENCE.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -84,7 +84,7 @@ Gate statuses used here:
84
84
| Candidate npm `0.1.48` canonical post-C0 credential correction | Completed-C0 terminal credentials now resolve through the exact domain/principal-bound harness plus credential epoch; unknown or mismatched identity state remains fail-closed. Adds only the exact forward-only `0.1.47→0.1.48` five-unit marker edge and no database migration. | Focused lane: `547 passed, 5 skipped`; broad releasable-source lane: `2155 passed, 21 skipped`; recursive packed-package and installed-host upgrade evidence pending. | H-only correction evidence; no gate promotion. Affected IDs: `ID-006`, `ID-009`, `SEC-007`, `OPS-003`. |
85
85
| Candidate npm `0.1.49` completed-C0 communication recovery | Permanent communication activation resolves the exact completed C0 pair; only the authenticated ordinary server harness may advance to its current active credential, while the C0 peer remains pinned to its enrolled credential absent separately verified succession. Terminal pre-commit retries converge without replacing committed authority. Signed message send, inbox, and acknowledgement requests bind the exact collaboration scope. Adds only the forward-only `0.1.48→0.1.49` five-unit marker edge and no database migration. | Focused lane: `645 passed, 5 skipped`; broad releasable-source lane: `2166 passed, 21 skipped`; recursive packed-package and installed-host upgrade evidence pending. | H-only correction evidence; no gate promotion. Affected IDs: `ID-001`, `ID-002`, `ID-004`, `ID-006`, `AUTH-001`, `AUTH-002`, `AUTH-003`, `AUTH-004`, `AUTH-007`, `AUTH-009`, `COM-001`, `COM-002`, `COM-003`, `COM-006`, `COM-009`, `COM-011`, `AVL-003`, `AVL-005`, `AVL-006`, `SEC-003`, `SEC-005`. |
86
86
| Candidate npm `0.1.50` setup-usability, direct-upgrade, and communication-scope approval path | One guided server command over the strict request/plan/apply protocol; one server-origin-only guided laptop command with authenticated discovery defaults; content-free named phases; ten-minute server and five-minute laptop bounds; resumable blocker output; exact direct allowlist from v0.1.45–v0.1.49 schema-v7 five-unit markers; installed separate-process local communication/obligation roundtrip added to packed verification; explicit one-hour Approval request ceiling limited to `authorization.communication_scope.approve`, with all other approvals retaining the five-minute ceiling and short-lived WebAuthn challenges | Focused release lane: `681 passed, 5 skipped`; broad releasable-source lane: `2180 passed, 21 skipped`; source and two recursive packed generations: `2207 passed, 21 skipped` each; two byte-identical release builds; release manifest verifier passed; installed tarball journey passed from an unrelated prefix; installed-host, fresh-machine, and same-commit CI evidence pending | H/L-shaped local candidate evidence only. No production, owner-policy, external, privileged-host, or gate promotion. Affected IDs: `ID-006`, `AUTH-004`, `AUTH-007`, `COM-001`, `COM-002`, `COM-003`, `COM-006`, `COM-009`, `AVL-003`, `AVL-005`, `AVL-006`, `UX-001`, `UX-002`, `SEC-003`, `SEC-005`, `OPS-003`, `OPS-006`. |
87
-
| Candidate npm `0.1.51` same-binding expired laptop credential reauthorization | Dedicated package-owned recovery for an expired ordinary laptop credential preserves the exact domain/principal/harness binding, OS- or hardware-bound public key, authority, scopes, memberships, capabilities, and supersession history. Fresh independent WebAuthn user verification is required; active, revoked, mismatched, non-laptop, stale, replayed, expired-transaction, and conflicting bindings fail before key use or mutation. One same-key successor epoch commits idempotently; no enrollment, generic renewal, key replacement, authority grant, or service restart occurs. | Focused lane: `698 passed, 5 skipped`; broad releasable-source lane: `2197 passed, 21 skipped`; source plus two recursive packed generations: `2224 passed, 21 skipped` each; two byte-identical release builds; packaged exact-endpoint routing, packaged `0.1.45` user journey, and separate-process communication/obligation roundtrip passed; fresh installed-host, live owner WebAuthn/Core recovery, same-commit CI, and production-topology evidence pending. | H/L-shaped local recovery and packaging evidence only; no gate promotion. Affected IDs: `ID-006`, `ID-007`, `ID-009`, `AUTH-001`, `AUTH-002`, `AUTH-004`, `AUTH-007`, `SEC-003`, `SEC-005`, `SEC-007`, `OPS-003`, `OPS-006`. |
87
+
| Candidate npm `0.1.51` same-binding expired laptop credential reauthorization and measured Pi/OMP Manager activation | Dedicated package-owned recovery for an expired ordinary laptop credential preserves the exact domain/principal/harness binding, OS- or hardware-bound public key, authority, scopes, memberships, capabilities, and supersession history. Fresh independent WebAuthn user verification is required; active, revoked, mismatched, non-laptop, stale, replayed, expired-transaction, and conflicting bindings fail before key use or mutation. One same-key successor epoch commits idempotently; no enrollment, generic renewal, key replacement, authority grant, or service restart occurs. The existing single-child Manager launcher now accepts Pi or OMP, stages the exact packaged Pi-compatible extension, rejects caller-selected extension/tool flags, retains exact-process binding and a private PID namespace/procfs sandbox, and exposes only canonical AgentNet tools. | Focused lane: `763 passed, 5 skipped`; broad releasable-source lane: `2203 passed, 21 skipped`; source plus two recursive packed generations: `2230 passed, 21 skipped` each; two byte-identical release builds; release verifier, packaged exact-endpoint routing, packaged `0.1.45` user journey, separate-process communication/obligation roundtrip, and measured Linux OMP launcher smoke passed; fresh installed-host, live owner WebAuthn/Core recovery, live OMP AgentNet tool use, same-commit CI, and production-topology evidence pending. | H/L-shaped local recovery, Manager activation, and packaging evidence only; no gate promotion. Affected IDs: `ARC-001`, `ARC-002`, `ARC-004`, `ID-006`, `ID-007`, `ID-009`, `AUTH-001`, `AUTH-002`, `AUTH-004`, `AUTH-007`, `COM-001`, `COM-002`, `COM-003`, `UX-001`, `UX-002`, `SEC-003`, `SEC-005`, `SEC-007`, `OPS-002`, `OPS-003`, `OPS-006`, `OPS-007`. |
88
88
| OIDC validated-address transport repair |`UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/identity/test_oidc_enrollment.py tests/operations/test_fail_closed_config.py tests/production/test_deployment_config.py`| 53 passed, 0 failed on 2026-07-15 | H only: includes the real `_PinnedHTTPSConnection` socket path under a validation-to-connect DNS-answer change, exact TCP address/SNI/Host assertions, proxy/tunnel and redirect denial, response bounds, unsafe address-class rejection, invalid resolver type handling, private IPv4/IPv6 pins, configuration, and deployment wiring. No real IdP/TLS service or independent approval boundary is claimed. |
89
89
| Independent WebAuthn-UV approval component |`UV_CACHE_DIR=/tmp/uv-cache uv run pytest -q tests/approval`; approval-consumer lane; non-gate full regression below | 12 focused passed; 144 approval/consumer passed; included in 1049-pass broad lane on 2026-07-15 | H only: strict owner-only config/key custody, exact SQLite catalog/tamper rejection, UV-required maintained-library call contract, exact display/digest, bounded duplicate-rejecting HTTP, one-receipt response-loss retry, committed denial/expiry audits, rejection, credential revocation, loopback serving, and non-authorizing provisioning. WebAuthn verification is seam-controlled in hermetic tests; no real authenticator, independent host/device/operator, TLS proxy, rotation/recovery drill, or owner decision is claimed. |
90
90
| Prior `0.1.8` candidate, unfiltered local run |`UV_CACHE_DIR=/tmp/uv-cache uv run --extra test pytest -q`|`1087 passed, 2 failed, 7 expected PostgreSQL skips` on 2026-07-16 | Both failures were preserved environmental G01 gates. This was not a passing unfiltered release run and is not current `0.1.9` evidence. |
Copy file name to clipboardExpand all lines: docs/RELEASE_MANIFEST.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,7 +3,7 @@
3
3
Snapshot: 2026-08-14
4
4
Candidate: `agentnet 0.1.51`
5
5
Latest published package: `agentnet 0.1.50`
6
-
Evidence profile: package-owned same-binding expired-laptop credential reauthorization with exact identity/key/authority preservation, old-key possession, fresh owner WebAuthn UV, atomic epoch+1 replacement, idempotent response-loss recovery, and direct allowlisted v0.1.45–v0.1.50 setup-marker upgrade compatibility
6
+
Evidence profile: package-owned same-binding expired-laptop credential reauthorization plus measured Linux Pi/OMP Manager activation through one packaged extension, canonical tool allowlist, exact-process capability, private PID namespace/procfs, and direct allowlisted v0.1.45–v0.1.50 setup-marker upgrade compatibility
7
7
8
8
This is not a production release. It is the human projection of
9
9
`RELEASE_MANIFEST.json`; local evidence cannot promote external, privileged,
@@ -16,7 +16,7 @@ owner, installer, or production-topology gates.
16
16
| Must-not-ship gate status |`BLOCKED`|
17
17
| Production ready |`false`|
18
18
| Ship eligible |`false`|
19
-
| Reason | Every must-not-ship gate remains non-passed; hermetic recoveryand packaging evidence does not substitute for fresh installed-host, live owner WebAuthn/Core recovery, or required P/E/O evidence. |
19
+
| Reason | Every must-not-ship gate remains non-passed; local recovery, Manager-launcher, and packaging evidence does not substitute for live OMP AgentNet tool use, fresh installed-host recovery, live owner WebAuthn/Core recovery, or required P/E/O evidence. |
0 commit comments