Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
259 commits
Select commit Hold shift + click to select a range
9fc63fa
docs: track restacked browser evidence queue
seonghobae Aug 28, 2026
685cf81
docs: record completed restack checks
seonghobae Aug 28, 2026
f1d1afb
docs: record baseline PR exact head
seonghobae Aug 28, 2026
0b2f278
test: make baseline phrase scope explicit
seonghobae Aug 28, 2026
48af173
docs: correct full active stack SHAs
seonghobae Aug 28, 2026
b3a3eb6
docs: track current WARC PR evidence
seonghobae Aug 28, 2026
92467cc
docs: avoid self-referential PR head evidence
seonghobae Aug 28, 2026
14def76
docs: record missing required workflow identities
seonghobae Aug 28, 2026
4b5fa6f
docs: correct central workflow failure evidence
seonghobae Aug 28, 2026
9c877ad
docs: bind workflow status to exact failures
seonghobae Aug 28, 2026
a505b9f
docs: record exact review-tool rerun evidence
seonghobae Aug 28, 2026
6a39bbe
docs: mark superseded WARC head historical
seonghobae Aug 28, 2026
5181ef9
docs: refresh live delivery gap baseline
seonghobae Aug 28, 2026
0c14e33
test: align live gap snapshot contracts
seonghobae Aug 28, 2026
08ea760
docs: enforce MCP traceability evidence
seonghobae Aug 28, 2026
0cb11e1
docs: remove volatile self-head snapshot
seonghobae Aug 28, 2026
e4266b5
docs: refresh live gap baseline for pr46
seonghobae Aug 28, 2026
2c81990
docs: align current baseline changelog date
seonghobae Aug 28, 2026
b6f7dce
docs: bind warc gate failures to current head
seonghobae Aug 28, 2026
5bd7991
docs: record current WARC provider rerun
seonghobae Aug 28, 2026
b04830d
docs: record review dispatch authorization blockers
seonghobae Aug 28, 2026
ef2bd1f
docs: bound prior review dispatch observation
seonghobae Aug 28, 2026
d0b0d1e
docs: align current changelog snapshot date
seonghobae Aug 28, 2026
b691340
docs: refresh gap baseline after WARC stack merge
seonghobae Aug 28, 2026
40c217e
test: align gap queue contract with live snapshot
seonghobae Aug 28, 2026
ea9bf08
docs: refresh current WARC parent evidence
seonghobae Aug 28, 2026
693f91d
docs: refresh WARC current-head evidence
seonghobae Aug 28, 2026
1e0e49d
docs: record browser interruption stack merge
seonghobae Aug 28, 2026
6c092ce
test(docs): require distinct live delivery baseline
seonghobae Sep 1, 2026
8b24f63
docs(gap): add current live delivery state
seonghobae Sep 1, 2026
027abf5
test(docs): require current Chromium stack evidence
seonghobae Sep 1, 2026
421e58b
docs(gap): refresh current Chromium stack evidence
seonghobae Sep 1, 2026
1103103
test(docs): require current OriginWeave delivery evidence
seonghobae Sep 1, 2026
c077307
docs(gap): refresh live Chromium stack evidence
seonghobae Sep 1, 2026
f9846f9
docs: sync live delivery baseline
seonghobae Sep 2, 2026
ffc1b66
test: decouple live baseline checks from transient stack heads
seonghobae Sep 2, 2026
4decbc3
test(docs): fail on stale live delivery baseline
seonghobae Sep 2, 2026
5e4e45e
docs: refresh exact live delivery baseline
seonghobae Sep 2, 2026
00f3f51
test(docs): bind live baseline to current governance evidence
seonghobae Sep 2, 2026
6dfe38a
test(docs): keep live governance evidence ruleset-bound
seonghobae Sep 2, 2026
1d3d848
test(docs): bind live baseline to current evidence
seonghobae Sep 2, 2026
50b11c2
docs: refresh exact live delivery evidence
seonghobae Sep 2, 2026
c4e5d06
test(docs): align grouped root-gate evidence
seonghobae Sep 2, 2026
959ae47
test(docs): reject volatile queue count in buyer gap
seonghobae Sep 2, 2026
356a4b3
docs: remove stale volatile queue count from buyer gap
seonghobae Sep 2, 2026
09efb78
test(docs): require terminal coverage evidence
seonghobae Sep 2, 2026
817e241
docs(gap): refresh live release and browser evidence
seonghobae Sep 2, 2026
569aa71
chore(docs): adopt current protected-main CI trigger scope
seonghobae Sep 3, 2026
5b4d48a
chore(docs): adopt protected main #280 without rewriting history
seonghobae Sep 3, 2026
74be6f5
docs(gaps): refresh exact live delivery baseline
seonghobae Sep 3, 2026
53ab9fa
docs(gap): refresh Agent Task sandbox repair evidence
seonghobae Sep 3, 2026
c4655e6
test(docs): bind product gap contract to current live inventory
seonghobae Sep 3, 2026
1e58104
docs(changelog): refresh current OriginWeave delivery evidence
seonghobae Sep 3, 2026
75c2e4b
docs(gaps): refresh volatile OriginWeave delivery state
seonghobae Sep 3, 2026
ae095c5
test(gap): bind live baseline to 145 PR inventory
seonghobae Sep 3, 2026
5d58b98
docs(gap): refresh live queue inventory to 145 PRs
seonghobae Sep 3, 2026
38fe063
docs(gap): refresh volatile live delivery state
seonghobae Sep 3, 2026
e7ff628
test(gap): bind MV3 diagnostic child to canonical parent
seonghobae Sep 3, 2026
cebd879
chore(gap): keep live-head drift non-destructive
seonghobae Sep 3, 2026
31f70c3
docs: refresh live OriginWeave delivery state
seonghobae Sep 4, 2026
7d8406d
fix(docs): align live gap evidence contracts
seonghobae Sep 4, 2026
8802d61
fix(docs): bind baseline to active ruleset
seonghobae Sep 4, 2026
8096437
docs: record final live evidence timestamp
seonghobae Sep 4, 2026
5494542
docs: record required workflow correction
seonghobae Sep 4, 2026
8ce9ac5
fix(docs): make live inventory reproducible
seonghobae Sep 4, 2026
037dbbb
docs: correct MCP and historical head claims
seonghobae Sep 4, 2026
a030b81
docs: refresh documentation CI evidence heads
seonghobae Sep 4, 2026
1ff7436
docs: refresh required workflow inventory
seonghobae Sep 4, 2026
3f8a7a2
docs: refresh active pull request evidence
seonghobae Sep 4, 2026
5dc7e60
docs: close similarity evidence drift
seonghobae Sep 4, 2026
b743a9b
docs: follow current partition heads
seonghobae Sep 4, 2026
9fd2f87
chore(docs): adopt current protected main for gap evidence
seonghobae Sep 4, 2026
ee93248
docs(governance): record protected-main bypass evidence
seonghobae Sep 4, 2026
115de7a
docs(ci): refresh partition stack evidence
seonghobae Sep 4, 2026
f2e0df2
docs(queue): record post-merge repair slice
seonghobae Sep 4, 2026
f966528
docs(gaps): record current ready root heads
seonghobae Sep 4, 2026
e69ac3e
docs(gaps): follow current HTTP root head
seonghobae Sep 4, 2026
67dc4b9
docs(gap): refresh live delivery evidence
seonghobae Sep 4, 2026
3fa08db
docs(gaps): refresh current delivery inventory
seonghobae Sep 4, 2026
3494b1f
docs(gaps): record reduced active queue
seonghobae Sep 4, 2026
dc5b08e
docs(gaps): record latest queue reduction
seonghobae Sep 4, 2026
e884e79
docs(gaps): record cleanup queue reduction
seonghobae Sep 4, 2026
d84384e
Merge remote-tracking branch 'origin/main' into docs/refresh-live-gap…
seonghobae Sep 4, 2026
a08b366
docs: refresh ready-root exact heads
seonghobae Sep 4, 2026
742d206
docs: record baseline review readiness
seonghobae Sep 4, 2026
31749f2
docs: refresh exact live delivery state
seonghobae Sep 4, 2026
6907975
docs: record enterprise approval review readiness
seonghobae Sep 4, 2026
b284246
docs: record JSON envelope review readiness
seonghobae Sep 4, 2026
674cb07
docs: record denial error review readiness
seonghobae Sep 4, 2026
e8565d3
docs: record denial error review readiness
seonghobae Sep 4, 2026
8c56de3
Merge remote-tracking branch 'origin/docs/refresh-live-gap-baseline-2…
seonghobae Sep 4, 2026
21d8a36
docs: record governance repair readiness
seonghobae Sep 4, 2026
126dc8f
docs: record presentation kernel readiness
seonghobae Sep 4, 2026
864679c
docs: refresh PR 287 exact-head evidence
seonghobae Sep 5, 2026
ca4c46e
docs: record Agent Task successor evidence
seonghobae Sep 5, 2026
f48957a
docs: refresh public surface head evidence
seonghobae Sep 5, 2026
e69a3c2
docs: correct MCP and merge evidence
seonghobae Sep 5, 2026
f82e2c9
docs(gaps): record http reset-content repair
seonghobae Sep 5, 2026
6ffaa7b
docs(gaps): record ready workflow gap
seonghobae Sep 5, 2026
f41eead
docs(gaps): remove moving self reference
seonghobae Sep 5, 2026
e93c627
docs(gaps): record PR 288 contract repair
seonghobae Sep 5, 2026
bd70a3d
docs(gaps): record corrected 205 framing head
seonghobae Sep 5, 2026
501c223
docs(product): record text observation boundary
seonghobae Sep 5, 2026
31b5a54
docs(product): record observation transport sync
seonghobae Sep 5, 2026
fee81e8
docs(product): record postcondition response sync
seonghobae Sep 5, 2026
524a13a
docs(product): record repaired BiDi lineage
seonghobae Sep 5, 2026
ded8b87
docs(product): record HTTP persistence repair
seonghobae Sep 5, 2026
650db22
docs: refresh semantic action stack evidence
seonghobae Sep 5, 2026
064d2d8
docs: extend semantic stack baseline
seonghobae Sep 5, 2026
3bc6bb0
docs: record current semantic dispatch head
seonghobae Sep 5, 2026
b8d1dd8
docs: record session status coverage repair
seonghobae Sep 5, 2026
3a1f184
docs: refresh WebDriver BiDi stack evidence
seonghobae Sep 5, 2026
4405727
docs: record session lifecycle stack heads
seonghobae Sep 5, 2026
ce6bed5
docs: extend session lifecycle stack evidence
seonghobae Sep 5, 2026
dfb36a1
docs: extend teardown stack evidence
seonghobae Sep 5, 2026
50a127b
docs: record pointer click stack heads
seonghobae Sep 5, 2026
cdd1adf
docs: refresh concurrent delivery evidence
seonghobae Sep 5, 2026
04ce6a5
docs: bind latest correlation head
seonghobae Sep 5, 2026
f281ffb
docs: record navigation stack restacks
seonghobae Sep 5, 2026
0136613
docs: record session stack restacks
seonghobae Sep 5, 2026
a3697c5
docs: record completed pointer restack
seonghobae Sep 5, 2026
574213b
docs: record downstream stack repair
seonghobae Sep 5, 2026
fdbe548
docs: bind latest HTTP persistence head
seonghobae Sep 5, 2026
fdb2516
docs: record formal review blockers
seonghobae Sep 5, 2026
23e7aa1
docs: correct baseline observation time
seonghobae Sep 5, 2026
208d77a
docs: record runner admission backlog
seonghobae Sep 5, 2026
ec9c3d7
test(docs): reject non-convergent baseline self-SHA
seonghobae Sep 5, 2026
ce74ab2
docs: record exact HTTP formatting repair
seonghobae Sep 5, 2026
4ecd2e3
docs: record origin-bound socket repair
seonghobae Sep 5, 2026
bf88ff2
docs: record teardown evidence gap
seonghobae Sep 5, 2026
6fef50a
docs: mark stale classifier parent
seonghobae Sep 5, 2026
6ddae59
docs: correct current queue lineage
seonghobae Sep 5, 2026
87b423b
test: align live queue contracts
seonghobae Sep 5, 2026
f32ecb1
test(docs): bind live queue after workflow draft repair
seonghobae Sep 5, 2026
bb2f185
docs: record workflow draft repair in live queue
seonghobae Sep 5, 2026
09c841a
docs: refresh workflow-owner queue evidence
seonghobae Sep 5, 2026
cb3ac4a
test(docs): align current workflow queue evidence
seonghobae Sep 5, 2026
9be7b98
docs: record BiDi connection evidence review
seonghobae Sep 5, 2026
fab93ac
docs: record fresh connection review correction
seonghobae Sep 5, 2026
a3e70b0
docs: distinguish active teardown repair from prior verification
seonghobae Sep 5, 2026
a13a0b9
docs: record received-response provenance and CI retry evidence
seonghobae Sep 5, 2026
9a36ee4
docs: correct PR 285 native CI and replay evidence
seonghobae Sep 5, 2026
a08b014
docs: record connection repair and fixture integration evidence
seonghobae Sep 5, 2026
7070d86
docs: record verified message parent and cleanup review
seonghobae Sep 5, 2026
af0d8e6
docs: record correlation discovery repair and current stack
seonghobae Sep 5, 2026
2d7e31d
docs(product): refresh integration and cleanup review evidence
seonghobae Sep 5, 2026
b76dc39
docs(product): record status integration and CodeQL handoff
seonghobae Sep 5, 2026
b09de47
docs: record cleanup evidence repairs and review outcomes
seonghobae Sep 5, 2026
6154c87
docs: distinguish owner repair and instrumentation limits
seonghobae Sep 5, 2026
907c71a
docs: track active non-lossy stack repair inventory
seonghobae Sep 5, 2026
eac47f1
docs: record session end integration and remaining teardown red
seonghobae Sep 5, 2026
6a2ff08
docs: preserve teardown red to green and response integration
seonghobae Sep 5, 2026
b40e33b
docs: record teardown parent integration limits
seonghobae Sep 5, 2026
6be4771
docs: record cleanup verification and scan failure evidence
seonghobae Sep 5, 2026
858071f
docs: bind freshness review evidence to current head
seonghobae Sep 5, 2026
6f80f3a
docs: record verified navigation dependency integrations
seonghobae Sep 5, 2026
a2600ee
docs: separate current queue from prior verification cuts
seonghobae Sep 6, 2026
70d9c97
docs: record current sandbox and subscription identity evidence
seonghobae Sep 6, 2026
38e5eb4
docs: separate hosted browser failure from private repair evidence
seonghobae Sep 6, 2026
7ca86a2
docs: distinguish remote quality failures from private repair proof
seonghobae Sep 6, 2026
545551f
test(docs): require integrated subscription publication evidence
seonghobae Sep 6, 2026
70b9a98
docs: bind subscription integration proof to published revision
seonghobae Sep 6, 2026
b447b63
test(docs): require current registry ownership repair evidence
seonghobae Sep 6, 2026
8e6284f
docs: record exact original-registry repair and audit boundaries
seonghobae Sep 6, 2026
f114a26
test(docs): distinguish dispatch repair from predecessor check success
seonghobae Sep 6, 2026
31a7d4c
docs: refresh dispatch freshness and exact hosted evidence
seonghobae Sep 6, 2026
81e334a
docs: retain the full-inventory freshness contract
seonghobae Sep 6, 2026
cbd6c40
test(docs): require current subscription teardown evidence
seonghobae Sep 6, 2026
88447b7
docs: record subscription teardown proof and visual inspection gap
seonghobae Sep 6, 2026
5d8ffb1
test(docs): require pointer integration evidence boundaries
seonghobae Sep 6, 2026
f29244e
test(docs): require current delivery checkpoint evidence
seonghobae Sep 6, 2026
ad1a7a8
docs: record current OriginWeave delivery checkpoint
seonghobae Sep 6, 2026
e933fd9
docs: refresh pointer integration and visual evidence
seonghobae Sep 6, 2026
e5cfddc
docs: preserve concurrent delivery checkpoint contribution
seonghobae Sep 6, 2026
bbe0bd0
test(docs): scope recovered visual evidence to current checkpoint
seonghobae Sep 6, 2026
112ba13
docs: reconcile released checkpoint and recovered visual evidence
seonghobae Sep 6, 2026
8d3b20b
test(docs): require executed session-adoption evidence
seonghobae Sep 6, 2026
ca8f847
docs: record verified session repair and child adoption
seonghobae Sep 6, 2026
6fe2af6
test(docs): expose historical evidence masking current state
seonghobae Sep 6, 2026
65ff436
fix(docs): isolate current inventory from historical evidence
seonghobae Sep 6, 2026
63bd50c
docs: keep one canonical current delivery inventory
seonghobae Sep 6, 2026
0d9278f
test(docs): require latest roots and lineage without historical fallback
seonghobae Sep 6, 2026
fcb4982
fix(docs): bind active queue and lineage to latest verified evidence
seonghobae Sep 6, 2026
1488fb4
test(docs): prove historical prose cannot mask latest evidence removal
seonghobae Sep 6, 2026
1016bcb
test(docs): require current text receipt provenance evidence
seonghobae Sep 6, 2026
6abe400
docs: refresh connection-bound text repair baseline
seonghobae Sep 6, 2026
bb5900e
fix(docs): bind inventory validation to the newest checkpoint
seonghobae Sep 6, 2026
e7b0f61
test(docs): require current pointer receipt evidence
seonghobae Sep 6, 2026
e4a4d47
docs: record published pointer receipt repair and remaining gaps
seonghobae Sep 6, 2026
efe39b8
test(docs): propagate pointer checkpoint mutation failures
seonghobae Sep 6, 2026
591ca38
test(docs): require current receipt descendant checkpoint
seonghobae Sep 6, 2026
8f56594
docs: record verified receipt descendant adoptions
seonghobae Sep 6, 2026
347e0db
test(docs): require bounded subscription repair evidence
seonghobae Sep 6, 2026
d9e49c0
docs(product): record subscription reply provenance checkpoint
seonghobae Sep 6, 2026
82b7511
test(docs): bind descendant evidence to current published rows
seonghobae Sep 6, 2026
fb8de50
docs: refresh published descendant and visual evidence
seonghobae Sep 6, 2026
e7f541d
test(docs): require compact linked checkpoint heads
seonghobae Sep 6, 2026
e57e930
docs: keep checkpoint coverage visible beside linked revisions
seonghobae Sep 6, 2026
3ceec7e
test(docs): require current published input evidence
seonghobae Sep 7, 2026
9e83af1
docs: record published input stack verification
seonghobae Sep 7, 2026
1a90686
test(docs): bind published response and observation evidence
seonghobae Sep 7, 2026
8d96328
docs: record published response and observation checkpoint
seonghobae Sep 7, 2026
0ea2aaf
fix(docs): validate newest inventory instead of historical counts
seonghobae Sep 7, 2026
30bc34b
test(docs): require ready roster in newest checkpoint
seonghobae Sep 7, 2026
4ac4830
docs: reaffirm current ready roster without historical fallback
seonghobae Sep 7, 2026
0751ea1
test(docs): require published observation safeguard evidence
seonghobae Sep 7, 2026
e81bd58
docs: record published observation safeguards and recovery
seonghobae Sep 7, 2026
cb1d7f2
test(docs): require verified maintenance lessons
seonghobae Sep 7, 2026
de06d65
docs: retain verified maintenance and publishing lessons
seonghobae Sep 7, 2026
4a71692
test(docs): require current action adoption checkpoint
seonghobae Sep 7, 2026
c73fdbd
docs: record published semantic action adoption evidence
seonghobae Sep 7, 2026
1160196
test(docs): require published status repair evidence and coverage gui…
seonghobae Sep 7, 2026
665e981
docs: record published status repair and coverage lessons
seonghobae Sep 7, 2026
7dafc8e
test(docs): require published end-reply evidence and recovery limits
seonghobae Sep 7, 2026
2ce9b62
docs: record published end-reply binding and recovery limits
seonghobae Sep 7, 2026
fb0c9dd
test(docs): reject per-owner publication evidence loss
seonghobae Sep 7, 2026
8741f16
fix(docs): bind checkpoint evidence to each owning pull request
seonghobae Sep 7, 2026
0d4cd6e
docs: refresh closure verification checkpoint
seonghobae Sep 8, 2026
37b0819
docs: refresh verified closure repair checkpoint
seonghobae Sep 8, 2026
847f453
docs: record repeated control verification checkpoint
seonghobae Sep 8, 2026
74f7590
docs: record verified intent acknowledgment repair
seonghobae Sep 8, 2026
6a4bd33
docs: record server Close role repair
seonghobae Sep 8, 2026
8c11b90
docs: record hosted intent verification
seonghobae Sep 8, 2026
8e0bab6
docs: refresh BiDi capability evidence
seonghobae Sep 8, 2026
fb705d2
docs: record Edge capability inspection
seonghobae Sep 8, 2026
2127c0a
docs: record typed BiDi command planning
seonghobae Sep 8, 2026
27b33c6
docs: refresh bidi gap evidence
seonghobae Sep 8, 2026
f4ac8da
test(docs): fail closed on live evidence provenance
seonghobae Sep 8, 2026
bab8719
fix(docs): bind merge evidence to current authority
seonghobae Sep 8, 2026
ac7e4b8
test(docs): bind queue contract to September 8 cut
seonghobae Sep 8, 2026
60374c6
test(docs): separate executable evidence contract
seonghobae Sep 8, 2026
3e7e488
test(docs): validate evidence collector syntax and stability
seonghobae Sep 8, 2026
257f2ed
experiment: align live evidence contracts (#296)
seonghobae Sep 9, 2026
45aaaed
test(docs): fail closed on unstable live evidence generations
seonghobae Sep 9, 2026
67151a6
fix(docs): bind live evidence to final PR state
seonghobae Sep 9, 2026
1cf9f56
test(docs): require collector executable mode
seonghobae Sep 9, 2026
f18e799
fix(docs): make live evidence collector executable
seonghobae Sep 9, 2026
6c04808
docs(traceability): bind live merge evidence to stable PR state
seonghobae Sep 9, 2026
ceecca9
test(docs): require whole-generation inventory closure
seonghobae Sep 9, 2026
b98c258
fix(docs): close live evidence over the full inventory
seonghobae Sep 9, 2026
a2ddb53
docs(traceability): close the complete evidence generation
seonghobae Sep 9, 2026
d2684f3
docs(evidence): link canonical merge collector
seonghobae Sep 9, 2026
c320788
Merge pull request #302 from ContextualWisdomLab/codex/baseline-evide…
seonghobae Sep 9, 2026
4c2ce60
docs: refresh live product gap baseline
seonghobae Sep 9, 2026
20e8573
docs: refresh live inventory after publication
seonghobae Sep 9, 2026
fb9acab
docs: distinguish harness from runtime acceptance
seonghobae Sep 9, 2026
cc6e1c7
docs(gaps): record repaired BiDi successor contract
seonghobae Sep 9, 2026
01d87b8
test(docs): preserve dated checkpoint verification
seonghobae Sep 9, 2026
43acca1
merge(docs): adopt current baseline evidence parent
seonghobae Sep 9, 2026
16098a0
Merge pull request #307 from ContextualWisdomLab/codex/refresh-gap-ba…
seonghobae Sep 9, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Agent Development Contract

When a follow-up closes a documented gap, add a bounded current checkpoint and label the predecessor as historical. Pin new local metrics and hosted run separately; do not leave an earlier pending implementation claim as the current next action.

This file is authoritative for humans and automated contributors working in OriginWeave.

## Product objective
Expand Down Expand Up @@ -97,6 +99,7 @@ A skipped security, GPU, browser, TLS, or statistical test is not passing eviden
## Documentation and research

- Update `docs/doctoring.md` when a standard or research claim affects design.
- Refreshing the volatile product-gap baseline requires paginated live PR and issue counts, full exact heads, and the matching `CHANGELOG.md` inventory line; run its documentation contracts before publication. A local browser policy that blocks loopback or file rendering is not visual evidence—inspect the GitHub-rendered exact head after push instead.
- Use primary specifications, official documentation, or peer-reviewed/primary papers.
- Format references in APA 7th style.
- Update an ADR for binding architectural changes.
Expand All @@ -116,3 +119,26 @@ A skipped security, GPU, browser, TLS, or statistical test is not passing eviden
## Release contract

A release requires all current-head checks, complete coverage and docs, updated `CHANGELOG.md`, SBOM and provenance, reproducible artifacts, compatibility evidence, security review, and an explicit version decision. Pre-alpha commits are not releases.

## Package Manager

- Use the pinned Rust toolchain and Cargo workspace with the checked-in `Cargo.lock`; use `--locked` for release verification.

## Commit Attribution

- AI-assisted commits include `Co-Authored-By` with the actual agent identity; never attribute work to an agent that did not contribute.

## Verified maintenance lessons

- When updating a delivery checkpoint, separate a verified predecessor from a newer pending head. A passing coverage summary does not validate a fixture that ignores peer errors; preserve the failing reproduction and the repaired wire-level assertions in the evidence trail.
- A live-inventory contract must update its dated baseline, `CHANGELOG.md`, and full exact SHA together. Use `scripts/ci/collect_live_merge_evidence.sh` for reusable head/base evidence; do not infer current state from an abbreviated SHA or a historical inventory line.
- A regression that verifies a dated baseline cut must select that named cut, not assume it remains the latest heading after a newer live cut is added; run the full Python repository contract suite after changing cut markers.
- Keep the delivery baseline decision-sized: GitHub truncates large Markdown code blocks. Link the canonical executable evidence collector instead of copying it into the rendered baseline, and keep its contract test pointed at that executable source.

- Add concise, reproducible lessons here as work establishes them. Keep transient heads, job IDs and incident snapshots in PR evidence, not permanent instructions; never record secret values.
- Retained receipt recovery is not live-stream recovery. State whether a fixture keeps the original connection open and uses the same endpoint; claim live recovery only when a synchronized test reads and completes the original request after rejecting the replacement reply.
- For coverage repairs, inspect uncovered regions in each linked crate instance and prefer the existing public integration path. Reuse shared validation before adding test-only authority accessors; keep validation before state consumption. Do not weaken coverage exclusions or production lint gates to hide uncovered fixture or production paths.
- Resume the existing process after a tool observation timeout; inspect its terminal status and logs before starting another copy. A timeout waiting for output is not a failed test.
- For rustdoc visual inspection, use `RUSTDOCFLAGS='-D warnings' cargo doc --workspace` when `--no-deps` leaves cross-crate references unlinked. Inspect the actual rendered page and open the link destinations before claiming success; do not patch valid source links to hide a build artifact.
- In parent adoption, preserve the child's behavior and tests, and compare inherited security boundaries against the exact parent. A rejected replacement reply must preserve pending work and prove that the original connection can still complete its own request.
- Secret availability is not release readiness. Verify the intended package, registry, version, protected revision and release evidence before publishing. Inspect only secret metadata; an empty repository list does not prove organization or environment secrets are absent. Do not remove `publish = false` merely to make a publish command succeed.
109 changes: 103 additions & 6 deletions CHANGELOG.md

Large diffs are not rendered by default.

4 changes: 4 additions & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,3 +12,7 @@ Additional constraints:
- Do not add hostname reconnect, proxy-environment inheritance, dangerous certificate-verifier hooks, Common Name fallback, TLS 0-RTT, key logging, or secret extraction to a production TLS path.
- Keep changes bounded to one product gap and preserve modular crate boundaries.
- Never claim a test, benchmark, browser integration, TLS identity, GPU execution, release, or merge succeeded without current exact-head evidence.
- For volatile gap-baseline refreshes, bind the dated inventory, full PR heads, and `CHANGELOG.md` line to the same live observation; if local rendering is blocked, visually inspect the GitHub-rendered exact head after push.
- When refreshing live delivery evidence, update the dated baseline, `CHANGELOG.md`, and full exact SHA atomically; use `scripts/ci/collect_live_merge_evidence.sh` rather than an abbreviated SHA or historical count.
- Date-bound baseline tests must locate their named checkpoint rather than assuming it remains the newest cut; run the complete Python contract suite after changing checkpoint markers.
- Keep rendered delivery evidence concise: link the canonical collector rather than embedding its long shell body, because GitHub truncates oversized code blocks.
8 changes: 4 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

OriginWeave is a Chromium-compatible, Rust-first control plane for governed AI agents on the web. It is designed to let an agent observe, extract, and act without turning untrusted page content into authority, exposing secrets to a model, connecting to an unapproved network destination, accepting an unauthenticated web service, or losing the evidence required to explain what happened.

> Project status: pre-alpha. The current protected repository contains independently reusable safety, resolved-destination, direct TCP peer-binding, authenticated TLS service-identity, and bounded MCP `2026-07-28` stateless `tools/call` routing/policy foundations. Chromium, WebDriver BiDi, CDP, complete MCP, HTTP, proxy, WARC, and persistent provenance adapters are planned but not yet shipped. Active PR #170 implements only conservative `tools/list` discovery metadata on top of the protected-main MCP catalog; it remains non-shipped active-PR evidence and does not make the complete MCP adapter available.
> Project status: pre-alpha. The current protected repository contains independently reusable safety, resolved-destination, direct TCP peer-binding, authenticated TLS service-identity, and bounded MCP `2026-07-28` stateless `tools/call` routing/policy and `tools/list` discovery foundations. Chromium, WebDriver BiDi, CDP, complete MCP, HTTP, proxy, WARC, and persistent provenance adapters are planned but not yet shipped. The merged `tools/list` contract does not make the complete MCP adapter available.

## Why OriginWeave

Expand Down Expand Up @@ -40,7 +40,7 @@ The repository is organized as independently consumable Rust crates:
- `originweave-resource`: task-level RAM, VRAM, thread, and frame-time budgets with cumulative mitigation plans.
- `originweave-evidence`: universally value-redacted network evidence and source-bound provenance records.

Protected main additionally contains an `originweave-core` MCP routing registry and `originweave-policy` binding for the MCP `2026-07-28` `tools/call` boundary. That shipped foundation validates and maps an explicit tool name to an existing typed action while preserving normal OriginWeave policy. Active PR #170 adds non-shipped conservative `tools/list` discovery metadata derived from the same reviewed catalog. Neither boundary implements transport parsing, OAuth, browser control, secret materialization, persistence, or ambient authority.
Protected main additionally contains an `originweave-core` MCP routing registry and `originweave-policy` binding for the MCP `2026-07-28` `tools/call` boundary, plus the `originweave-core` `tools/list` discovery contract merged through PR #170. Those shipped foundations validate explicit call routing and conservative discovery metadata without granting discovery any policy authority. Neither boundary implements transport parsing, OAuth, browser control, secret materialization, persistence, or ambient authority.

See [ARCHITECTURE.md](ARCHITECTURE.md) and the [architecture decision records](docs/adr/) for binding design decisions.

Expand Down Expand Up @@ -99,7 +99,7 @@ isolated Chromium session
→ redacted provenance bundle
```

Subsequent work connects the live Chromium network service, adds explicit proxy and download policy, WARC/PROV persistence, completes the MCP and Browser Agent Protocol adapters beyond the protected-main `tools/call` foundation and active `tools/list` refinement, expands extension compatibility testing, adds GPU/RAM telemetry and prompt-injection benchmarks, and builds an accessible approval interface. See [docs/product-roadmap.md](docs/product-roadmap.md).
Subsequent work connects the live Chromium network service, adds explicit proxy and download policy, WARC/PROV persistence, completes the MCP and Browser Agent Protocol adapters beyond the protected-main `tools/call` and `tools/list` foundations, expands extension compatibility testing, adds GPU/RAM telemetry and prompt-injection benchmarks, and builds an accessible approval interface. See [docs/product-roadmap.md](docs/product-roadmap.md).

## Hourly product-development loop

Expand All @@ -111,4 +111,4 @@ Read [AGENTS.md](AGENTS.md), [CONTRIBUTING.md](CONTRIBUTING.md), and [SECURITY.m

## License

Apache License 2.0. See [LICENSE](LICENSE).
Apache License 2.0. See [LICENSE](LICENSE).
8 changes: 4 additions & 4 deletions docs/adr/0107-browser-protocol-adapter-strategy.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,11 +38,11 @@ MCP version negotiation is independent of the OriginWeave Protocol version. As o

The complete MCP adapter remains **Planned**. Protected main now contains the narrower bounded Rust `tools/call` routing/action-policy foundation merged through PR #168. That protected-main foundation validates the `2026-07-28` stateless `tools/call` routing envelope presented to this boundary, bounds and syntax-checks both untrusted method fields and both untrusted tool-name fields before cross-field correlation, derives one of the existing typed `ActionKind` values from a deterministic reviewed registry, exposes discovery metadata from that same registry, and requires the resulting action to pass the ordinary OriginWeave policy evaluator. The method boundary accepts only nonempty ASCII method names up to 64 bytes using the reviewed routing alphabet, while the tool-name boundary accepts only nonempty ASCII names up to 128 bytes using its narrower reviewed alphabet. The catalog and validated route grant no capability, approval, origin, secret, browser, persistence, or evidence authority by themselves.

Active PR #170 is a separate non-shipped refinement on top of that protected-main catalog. It adds one conservative typed `tools/list` request/result contract: both protocol-version fields are required and bounded before comparison, client-capability metadata must be present without becoming authority, both routing/body methods are syntax-bounded before correlation, only exact `tools/list` is admitted, and every caller-supplied cursor is rejected because the current fixed catalog issues none. The result is one complete page with zero freshness, private cache scope, and no continuation cursor.
The merged PR #170 is a protected-main refinement on top of that catalog. It adds one conservative typed `tools/list` request/result contract: both protocol-version fields are required and bounded before comparison, client-capability metadata must be present without becoming authority, both routing/body methods are syntax-bounded before correlation, only exact `tools/list` is admitted, and every caller-supplied cursor is rejected because the current fixed catalog issues none. The result is one complete page with zero freshness, private cache scope, and no continuation cursor.

Neither protected main nor PR #170 implements Streamable HTTP transport parsing, JSON-RPC/HTTP serialization, OAuth, browser I/O, WebMCP/BiDi/CDP translation, secret delivery, persistence, general pagination/subscription state, or a complete OriginWeave Protocol adapter. Those remain separate adapter/runtime work. Protected `main` may therefore describe only the bounded merged `tools/call` foundation as implemented; the full MCP adapter remains planned, and the `tools/list` refinement remains active-PR evidence until separately integrated.
Neither protected main nor PR #170 implements Streamable HTTP transport parsing, JSON-RPC/HTTP serialization, OAuth, browser I/O, WebMCP/BiDi/CDP translation, secret delivery, persistence, general pagination/subscription state, or a complete OriginWeave Protocol adapter. Those remain separate adapter/runtime work. Protected `main` may therefore describe only the bounded merged `tools/call` and `tools/list` foundations as implemented; the full MCP adapter remains planned.

The version boundary is explicit: the protected-main routing foundation and active discovery refinement accept only MCP `2026-07-28`; neither infers compatibility with later protocol generations. OriginWeave Protocol versioning remains independent and cannot be changed by MCP metadata.
The version boundary is explicit: the protected-main routing foundation and merged discovery refinement accept only MCP `2026-07-28`; neither infers compatibility with later protocol generations. OriginWeave Protocol versioning remains independent and cannot be changed by MCP metadata.

## Consequences

Expand All @@ -60,7 +60,7 @@ Protocol validation occurs before messages influence policy. Tool/page-provided

Require version-negotiation tests, schema/property tests, malformed-message tests, BiDi/CDP semantic parity tests for shared capabilities, WebMCP prompt-injection tests, MCP authority-separation and version-change tests, browser-version compatibility matrices, and end-to-end proof that unsupported capabilities fail without side effects.

For the protected-main `tools/call` foundation, acceptance includes deterministic method and tool-name bounds/syntax, exact header/body method and tool-name correlation only after both sides are bounded, explicit invalid-method/invalid-tool-name/unknown-tool rejection, one unambiguous tool-to-action registry, independent capability/risk expectations, route/action mismatch denial before ordinary policy evaluation, exact 100% owned-production coverage, and integrated review evidence from PR #168. For active PR #170, exact-current acceptance additionally requires bounded protocol metadata before cross-field comparison, required client-capabilities presence, bounded `tools/list` method correlation, rejection of unissued cursors, deterministic result/cache semantics, exact 100% owned-production coverage, and unchanged-head CI/security/review evidence. These checks do not substitute for complete transport or adapter conformance.
For the protected-main `tools/call` foundation, acceptance includes deterministic method and tool-name bounds/syntax, exact header/body method and tool-name correlation only after both sides are bounded, explicit invalid-method/invalid-tool-name/unknown-tool rejection, one unambiguous tool-to-action registry, independent capability/risk expectations, route/action mismatch denial before ordinary policy evaluation, exact 100% owned-production coverage, and integrated review evidence from PR #168. The merged PR #170 discovery contract additionally requires bounded protocol metadata before cross-field comparison, required client-capabilities presence, bounded `tools/list` method correlation, rejection of unissued cursors, deterministic result/cache semantics, exact 100% owned-production coverage, and current-head acceptance evidence recorded at merge. These checks do not substitute for complete transport or adapter conformance.

## Migration and rollback

Expand Down
Loading
Loading