Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
21 commits
Select commit Hold shift + click to select a range
48f9905
fix: defer managed implementation PR publication
pcvantol Sep 9, 2026
6528989
fix: bind implementation publication to local validation
pcvantol Sep 9, 2026
7a3512d
fix: verify draft publication identity
pcvantol Sep 9, 2026
0a2250c
test: bind publication fixtures to verified draft
pcvantol Sep 9, 2026
dfd5ae7
test: model verified publication in qualification fixture
pcvantol Sep 9, 2026
7a320d4
docs: distinguish historical and candidate version evidence
pcvantol Sep 9, 2026
583d5a4
fix: reconcile recovered draft publication
pcvantol Sep 9, 2026
9dc6f78
test: retain publication negative fixture assertion
pcvantol Sep 9, 2026
46d998c
fix: distinguish recovered publication results
pcvantol Sep 9, 2026
fa53346
fix: reconcile recovered publication acknowledgement
pcvantol Sep 9, 2026
9916a0b
fix: reconcile uncertain draft publication
pcvantol Sep 9, 2026
4b54b41
docs: align managed publication contract
pcvantol Sep 9, 2026
805ab3e
fix: adopt managed candidate through lifecycle
pcvantol Sep 10, 2026
eea489f
fix: preserve adopted repair lineage
pcvantol Sep 10, 2026
771c657
fix: block replay before publication readback
pcvantol Sep 10, 2026
fcdf996
fix: bind publication to durable validation evidence
pcvantol Sep 10, 2026
98b61da
fix: preserve installed assurance evidence
pcvantol Sep 10, 2026
0bd4db7
fix: build qualification wheels from committed source
pcvantol Sep 10, 2026
a7b2661
test: cover fail-closed phase policy
pcvantol Sep 10, 2026
56c3b91
fix: fail closed on publication readback
pcvantol Sep 10, 2026
9ac3bd2
docs: record paused publication qualification
pcvantol Sep 10, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 36 additions & 4 deletions docs/development/ENGINEERING_PLATFORM_ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,12 @@

Repository evidence recorded on 2026-09-09 reads `origin/main` as
`0a98d0ca2395bd3b6b50deffd3139206b75c16e5` at this roadmap update. PyPI
holds immutable 2.3.1 wheel and sdist bytes; protected-main reconciliation
moved the canonical source projections forward to 2.3.2 without rewriting that
published identity. The observed Mac has one 2.3.1 server process/data root and
holds immutable 2.3.1 wheel and sdist bytes; the historical protected-main
reconciliation receipt records the earlier 2.3.2 source preparation without
rewriting that published identity. The current bounded engineering candidate
uses the EP product version helper to project 2.3.3; it is source-prepared
only and has no publication or release-closure claim. The observed Mac has one
2.3.1 server process/data root and
a distinct 2.3.0 PlatformIO PATH candidate. This is explicit-path investigation
evidence, not proof of Mac-wide uniqueness and not authorization to remove or
cut over either installation. CENTRAL schema 56, engineering-storage schema 41
Expand All @@ -15,7 +18,7 @@ and repository-attachment schema 1.0 remain separate contracts.
| Increment | Owning repository | Bounded result | Dependencies / acceptance |
| --- | --- | --- | --- |
| RL-1 | engineering-platform | Durable EP release-operation record, product-wide exclusive operation lock, exact wheel/sdist identities and separate `PUBLISHED`/`RELEASE_COMPLETE` states | SOURCE_FIXED through #153 `6919898`; the current parity increment also hardens owner-locked transitions, immutable policy identity, JSON recovery validation and `CLEANUP_PENDING` resume. No new release operation has been executed. |
| RL-2 | engineering-platform | Protected-main release workflow, exact-main qualification, registry readback, immutable `PUBLISHED` evidence, separate `RELEASE_COMPLETE` closure, receipt and scoped cleanup | The current parity increment retains `QUALIFIED` in a draft GitHub Release before PyPI, rejects unproven existing publications, reads back both exact distributions and completes cleanup before terminalization. 2.3.2 remains source-prepared only; no PyPI publication or release closure is claimed. |
| RL-2 | engineering-platform | Protected-main release workflow, exact-main qualification, registry readback, immutable `PUBLISHED` evidence, separate `RELEASE_COMPLETE` closure, receipt and scoped cleanup | The current parity increment retains `QUALIFIED` in a draft GitHub Release before PyPI, rejects unproven existing publications, reads back both exact distributions and completes cleanup before terminalization. The historical 2.3.2 receipt remains evidence for that earlier reconciliation; the current 2.3.3 engineering candidate is source-prepared only. No PyPI publication or release closure is claimed. |
| RL-3 | engineering-platform | Durable first-failure `CLEANUP_PENDING` evidence and controlled retry of release cleanup | SOURCE_FIXED: #165 `0a98d0c`. It canonicalizes and atomically hydrates a matching remote PENDING receipt, retains it on repeated cleanup failure, and detects dangling symlinks or post-delete residuals. No release operation has been dispatched. |
| OI-1 | engineering-platform | Read-only operational-installation resolver/diagnostic | SOURCE_FIXED: #111, #114 `9ef29bb`, #116 `71779d5`, #118 `f29006c`, #131 `28293b0`, #132 `d7efd67`, #133 `98e70e9`, #135 `99cbd4f`, #157 `f28fc84`, #161 `3161a4e`. The selected venv launcher and the actual server response remain separate from PATH/source observations. Explicit-path inventory only; no installation is verified. |
| OI-2 | engineering-platform | One EP-owned install/update/repair record and crash-resumable lifecycle | PARTIAL_SOURCE_FIXED: #113 `38b222a`, #121 `1bfe729`, #122 `a6f6c10`, #123 `2c4b081`, #127 `b77a638`, #128 `73c9729`, #129 `aadb3a5`, #130 `5073ee1`, #137 `a517ce3`, #144 `2848c52`, #158 `62eb6c4`. The executor serializes, journals and resumes explicit inventory/quiesce/backup/migrate/activate/verify actions; it atomically replaces only the exact registered record and performs operation-scoped cleanup. A product-specific runtime/service/migration adapter, a real update, and operational cleanup have not run. |
Expand Down Expand Up @@ -65,6 +68,35 @@ receipts remain product-specific. A production publication or an actual Mac
installation/update remains outside this source order until separately
authorized.

## Managed post-assurance publication closure — paused candidate qualification

`EP_MANAGED_POST_ASSURANCE_PUBLICATION_CLOSURE_V1` remains a bounded EP-owned
repair, separate from the release and operational-installation lanes above.
Its historical candidate is `7c347f887ddd01b15f70234a324c2de2fd9844a2`; the
source lineage retains its patch-equivalent contract update and the local
repair branch `codex/ep-managed-post-assurance-publication-closure-v1` had
last committed candidate `56c3b912cda7d0a9fc911c5b3a298083e44b3fa9` at this
pause checkpoint. The branch must be made stable and its exact final SHA must
be explicitly re-authorized before any execution resumes.

The source candidate contains the typed Managed-adoption route, current
validation binding, separate Quality/Security assurance, and fail-closed
publication readback handling. That is source evidence only: no isolated
candidate-wheel qualification run, durable owner-authority record, current
validation PASS, independent Quality/Security PASS, remote repair branch, or
draft implementation PR is claimed here. The observed primary EP runtime is
2.3.1 and is not the execution route for this repair; it must not be changed
by this work.

The next permitted continuation is one separately authorized, isolated
candidate-wheel qualification after the final SHA is frozen. It must use the
product-owned DEVELOPMENT route and a separate data root, execute one Managed
adopted-candidate run with zero corrective rounds, and stop immediately after
one GitHub-readback-verified draft PR. It must not merge, release, install,
change the primary runtime/CENTRAL, or activate a later roadmap increment.
This pause record is documentary context, not lifecycle authority or
qualification evidence.

## Subagent orchestration and efficiency — retained audit and planned lane

`EP_SUBAGENT_ORCHESTRATION_AND_EFFICIENCY_V1` records the
Expand Down
13 changes: 12 additions & 1 deletion docs/development/SUBAGENT_ORCHESTRATION_V1_DAG.json
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,18 @@
"depends_on": [],
"owning_work": "EP_MANAGED_POST_ASSURANCE_PUBLICATION_CLOSURE_V1",
"requirement": "Read back qualification of the existing post-assurance publication contract for the exact source/artifact before SA-PUB activation; this documentary graph does not implement or close that work.",
"evidence": []
"evidence": [
{
"kind": "SOURCE_PAUSE_CHECKPOINT",
"observed_at": "2026-09-10",
"status": "NOT_QUALIFIED",
"historical_candidate": "7c347f887ddd01b15f70234a324c2de2fd9844a2",
"branch": "codex/ep-managed-post-assurance-publication-closure-v1",
"last_committed_candidate": "56c3b912cda7d0a9fc911c5b3a298083e44b3fa9",
"summary": "The local source continuation is paused pending a stable, explicitly re-authorized final SHA and one isolated candidate-wheel Managed qualification. No owner-authority record, current validation/Quality/Security PASS, remote repair branch, draft PR, source delivery, or installed-runtime qualification is evidenced by this record.",
"continuation_boundary": "Use only the separately authorized isolated DEVELOPMENT route; preserve the primary runtime/CENTRAL and stop after one GitHub-readback-verified draft PR."
}
]
}
],
"nodes": [
Expand Down
35 changes: 35 additions & 0 deletions docs/engineering/EXECUTION_HOST_ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,41 @@ hosted checks and finalization; a new SHA, phase, resume or PR does not reset
it. The Console projects the same stored review identities and repair rounds
for live and historical runs.

For a new Managed implementation, the first draft implementation PR is a
separate, post-assurance dispatch: bounded implementation -> local validation
-> independent Quality and Security reviews for the same candidate/profile ->
host publication gate -> draft PR. `EXECUTE_AGENT` is used for both the
implementation and that publication dispatch, so prompt authority is selected
from trusted transaction kind, phase, next action, checkpointed PR lineage and
current assurance evidence together. An action string or objective text alone
never grants PR creation. Pre-publication repair normally has no PR and returns
to validation and both reviews; repair of a known PR preserves its exact
lineage. A recovered implementation result is not a publication result.

The local-validation decision is not inferred from provider prose. The host
loads the persisted validation profile and requires a successful terminal
command receipt for every required control at the current repair ordinal. The
selected tier, version, registry reference, required-control set and launcher
bindings form a digest that is embedded in the assurance profile. A missing
receipt, non-zero exit, unavailable/skipped result, older repair ordinal or
different profile therefore cannot authorize publication.

The host rejects an early provider-reported PR with
`implementation_pr_before_assurance`, and verifies candidate/branch identity
before and after publication. This is host sequencing and result detection, not
a universal technical proof that an arbitrary provider could not use every
possible external HTTP or absolute-path route to create a remote PR. The local
validation provider is read-only sandboxed; existing product boundaries do not
claim a general remote-write broker or network proxy for all implementation
provider routes.

Before a first-publication provider turn, including after restart, the host
reads GitHub for the checkpointed branch. It accepts only one open draft whose
base and exact head SHA match the reviewed candidate. A mismatching result
blocks; an exact match is reconciled without replaying PR creation. An
interrupted publication turn likewise cannot enter the generic provider retry
loop before that exact readback.

The immutable profile lists repository, remote, upstream, clean-worktree,
branch, workspace authorization, host and capability qualification, providers,
datastore, active-lease and Producer Contract requirements. Facts are observed
Expand Down
10 changes: 6 additions & 4 deletions docs/engineering/EXECUTION_HOST_CONTRACT.md
Original file line number Diff line number Diff line change
Expand Up @@ -77,10 +77,12 @@ The Execution Host acquires the exclusive run lease, performs admission and
synchronizes the repository before it invokes the implementation agent. A
managed, owner-authorized transaction then runs in the Codex CLI's
`danger-full-access` sandbox profile so that the already-authorized bounded
transaction can create its branch, stage its own scoped changes, commit and
open its draft pull request. This is not an unrestricted lifecycle authority:
the supplied transaction scope, branch and pull-request rules still apply. The
runner may mark a pull request ready for review, but its merge remains
transaction can create its branch, stage its own scoped changes and commit.
The first draft pull request is a separate host-owned publication dispatch,
permitted only after current read-only local validation and independent Quality
and Security assurance for that exact candidate. This is not an unrestricted
lifecycle authority: the supplied transaction scope, branch and pull-request
rules still apply. The runner may mark a pull request ready for review, but its merge remains
operator-owned. A green, open pull request is persisted as
`WAIT_FOR_OPERATOR_MERGE`; it is not a failed execution and it must keep its
Inbox position until the operator merges it or explicitly aborts the hand-off.
Expand Down
31 changes: 25 additions & 6 deletions docs/engineering/EXECUTION_HOST_OPERATIONS.md
Original file line number Diff line number Diff line change
Expand Up @@ -223,16 +223,35 @@ documentation tier.
For a Managed implementation, the Execution Host first creates and pushes the
bounded branch without creating a pull request. The visible **Local repository
validation** step discovers and runs the target repository's canonical required
local validation. It may make scoped production-code and test corrections on
that same branch and retries at most three times. Each attempt records its safe
problem, corrective action, result and commit evidence. Only a passing attempt
may create the draft implementation pull request. Remote GitHub check repair
remains a separate, later bounded gate.
local validation as a read-only measurement. It cannot modify files, index,
commits, branches, remotes, pull requests, or other remote state; it neither
requires nor creates a PR. A failing measurement does not authorize a local
repair itself. The host may spend the one existing run-wide repair budget on a
bounded repair of the same candidate, then returns that candidate through
local validation and both independent Quality and Security reviews. Only after
current validation and both reviews bind to the same clean candidate/profile
does the separate host-owned first-publication gate create the draft
implementation PR. Remote GitHub check repair remains a separate, later
bounded gate and preserves an already-known PR lineage.

For publication eligibility, a textual validation summary is reporting only.
The canonical decision requires an exit-code-zero terminal receipt for every
control in the persisted profile at the current run-wide repair ordinal. The
assurance profile binds the digest of that selected profile and its immutable
control launchers. Missing, failed, unavailable, skipped, stale or differently
profiled evidence blocks before publication and cannot be replaced by passing
Quality/Security records.

If the host restarts at the first-publication checkpoint, it does not
synchronize back to `main` or rerun implementation. It verifies the clean
checkpointed branch and candidate, then performs exact GitHub readback before
any create attempt. One matching open draft is resumed; a mismatch blocks and
does not trigger a second PR.

Both bounded gates preserve the same immutable per-attempt shape: iteration,
observation time, observed problem, proposed action, safe agent summary,
commit evidence and outcome. Local validation uses `validated`,
`validation_failed` or `agent_failed`; PR repair uses
`validation_failed` or `agent_failed`; repair uses
`submitted_for_recheck`, `agent_failed` or `agent_timed_out`. The latter is a
host-owned deadline outcome, not an invitation to start another repair: the
run is blocked with its evidence intact and requires a new explicit recovery
Expand Down
4 changes: 2 additions & 2 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "engineering-platform-browser-validation",
"private": true,
"version": "2.3.2",
"version": "2.3.3",
"scripts": {
"test:engineering-dashboard": "PYTHONPATH=src python3 -m engineering_platform.dashboard_browser_validation",
"test:engineering-dashboard-logic": "node --test tests/engineering/dashboard_status_store.test.mjs tests/engineering/ui_localization_contract.test.mjs",
Expand Down
2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta"

[project]
name = "engineering-platform"
version = "2.3.2"
version = "2.3.3"
description = "Local-first Engineering Platform execution operations runtime"
readme = "README.md"
requires-python = ">=3.11"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
"platform": {
"id": "engineering-platform",
"name": "Engineering Platform",
"version": "2.3.2",
"version": "2.3.3",
"generation": 2,
"documentation_namespace": "engineering-platform",
"capability_registry_version": 1
Expand Down
8 changes: 4 additions & 4 deletions src/engineering_platform/ENGINEERING_PLATFORM_VERSION.json
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
{
"bootstrap_contract": "2026.12",
"checkpoint_format": 1,
"dashboard_version": "2.3.2",
"dashboard_version": "2.3.3",
"handoff_protocol": 1,
"memory_format": 2,
"minimum_codex_cli": "0.146.0",
"inbox_protocol": 1,
"platform_version": "2.3.2",
"platform_version": "2.3.3",
"report_format": 2,
"runner_version": "2.3.2",
"runner_version": "2.3.3",
"status_model": 1,
"storage_schema": 41,
"watcher_version": "2.3.2"
"watcher_version": "2.3.3"
}
2 changes: 1 addition & 1 deletion src/engineering_platform/ENGINEERING_QUALIFICATION.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ registry and writes local, git-ignored reports under `.engineering/qualification
| --- | --- | --- | --- | --- |
| Repository Initialization | Clean and dirty checkout | Reconcile or `BLOCKED` with diagnostics | local qualification report | Registered |
| Checkpoint Resume | Interrupted transaction | Resume without duplicate PR | local qualification report | Registered |
| Implementation Lifecycle, Validation Loop, Repair Loop | bounded PR and failing validation | repair remains bounded and lifecycle continues | local qualification report | Registered |
| Implementation Lifecycle, Validation Loop, Repair Loop | adopted or newly implemented candidate, terminal validation controls, interrupted first publication and failing validation | every required current control and both independent reviews precede one exact draft PR; restart reconciles by branch/base/SHA without duplicate creation; repair remains bounded | local qualification report | Registered |
| Owner Authorization, Ready For Review, Automatic Merge | authorized green PR | only runner-controlled progression | local qualification report | Registered |
| Repository Reconciliation, Finalization, Repository Cleanup | merged and squash-merged transaction | evidence-driven reconciliation and `WORKSPACE_READY` | local qualification report | Registered |
| Engineering Memory, Progress Reporting, Engineering Reports | repeated transaction | bounded advisory memory and explainable output | local qualification report | Registered |
Expand Down
11 changes: 10 additions & 1 deletion src/engineering_platform/agent_state.py
Original file line number Diff line number Diff line change
Expand Up @@ -379,12 +379,21 @@ def from_dict(cls, raw: object) -> "TransactionState":
raise StateError("checkpoint quality evidence is invalid or unsafe")
profile_fields = {"version", "digest", "candidate_sha"}
current_profile_fields = profile_fields | {"criteria_digest"}
candidate_bound_profile_fields = current_profile_fields | {"validation_profile_digest"}
if state.assurance_profile is not None and (
not isinstance(state.assurance_profile, dict)
or set(state.assurance_profile) not in (profile_fields, current_profile_fields)
or set(state.assurance_profile) not in (
profile_fields, current_profile_fields, candidate_bound_profile_fields,
)
or not all(isinstance(value, str) and value for value in state.assurance_profile.values())
or not re.fullmatch(r"sha256:[0-9a-f]{64}", state.assurance_profile["digest"])
or not re.fullmatch(r"[0-9a-f]{40}", state.assurance_profile["candidate_sha"])
or (
"validation_profile_digest" in state.assurance_profile
and not re.fullmatch(
r"sha256:[0-9a-f]{64}", state.assurance_profile["validation_profile_digest"],
)
)
):
raise StateError("checkpoint assurance profile is invalid")
review_fields = {"reviewer", "status", "candidate_sha", "profile_digest", "invocation_id", "findings"}
Expand Down
7 changes: 4 additions & 3 deletions src/engineering_platform/execution_executor.py
Original file line number Diff line number Diff line change
Expand Up @@ -291,10 +291,11 @@ def load_validation_failure_diagnostic(
_format_cli_failure = format_cli_failure

# A managed Engineering transaction has already passed host-owned admission,
# repository synchronization and an exclusive execution lease. It must be
# able to create its bounded branch, commit, and draft PR; `workspace-write`
# repository synchronization and an exclusive execution lease. It must be able
# to create its bounded branch and commit; the later, separately host-gated
# publication dispatch may create the first draft PR. `workspace-write`
# deliberately rejects Git index writes and therefore cannot complete that
# contract. Review-only invocations remain read-only below.
# contract. Review-only invocations remain read-only below.
MANAGED_EXECUTION_SANDBOX = "danger-full-access"

class CodexCliClient:
Expand Down
Loading
Loading