Skip to content

release: harden v0.1.0 around reproducible acceptance evidence - #148

Merged
avaargsh merged 35 commits into
mainfrom
release/v0.1.0-hardening
Oct 4, 2026
Merged

avaargsh merged 35 commits into
mainfrom
release/v0.1.0-hardening

Conversation

@avaargsh

@avaargsh avaargsh commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Goal

Cut v0.1.0 from existing hard evidence rather than adding product features.

This PR freezes and makes executable the release contract around the real Kubernetes Deployment 20 -> 30 Golden Slice.

Product boundary

v0.1 is positioned as a provable execution control plane for AI-initiated state transitions.

The core user-facing questions are:

  • Was this exact change authorized?
  • Did this exact operation own the provider side effect?
  • Can an independent verifier prove the resulting state afterwards?

The README no longer presents AgentRelease / Binding DAG / EvalGate / Decision Lab / AI Factory as the primary product architecture. Those remain secondary, compatibility, or integration surfaces. The normative core is:

ObservationSnapshot
  -> TransitionPlan
  -> PlanAuthorizationBinding
  -> PlanExecutionFence
  -> durable PREPARED ExecutionAttempt
  -> provider side effect
  -> COMMITTED | ABORTED | UNKNOWN
  -> reconciliation
  -> fresh independent ObservationSnapshot
  -> VerificationReport
  -> IndependentExecutionProof

This keeps v0.1 distinct from Agent frameworks, MCP gateways, runtime guardrails, durable workflow engines, IAM products, sandbox runtimes, and model-serving platforms.

Release contract

  • adds a machine-readable Acceptance Artifact Contract and human documentation;
  • makes IndependentExecutionProof/v1 the normative completed-execution release artifact;
  • retains ExecutionAttestation/v2 only as a compatibility artifact;
  • freezes the ownership marker inputs and statement-hash algorithm;
  • adds a complete artifact-set verifier;
  • records source commit + SHA-256 of every required artifact as release-evidence.json.

Public compatibility

  • snapshots console scripts and CLI command names;
  • snapshots top-level package exports and exported authority dataclass fields;
  • snapshots manifest kind -> schema mapping;
  • freezes IndependentExecutionProof predicate/statement identity and field names;
  • executes the compatibility verifier before package release verification.

Existing authority/eval/context commands remain in the v0.1 compatibility snapshot, but they do not define the primary product boundary.

Fresh-clone rehearsal

The Kubernetes CI path now:

  1. creates the kind cluster;
  2. clones the exact candidate commit into a clean temporary checkout;
  3. installs from that clone;
  4. runs the real Deployment 20 -> 30 transition;
  5. verifies the serialized proof in a new Python process;
  6. validates the complete Acceptance Artifact Contract;
  7. uploads the artifact set plus release-evidence.json.

The Makefile live target no longer relies on pipe/tee exit-code behavior.

Documentation cleanup

  • README centered on exact StateTransition authorization, execution fencing, reconciliation, ownership-aware verification, and IndependentExecutionProof;
  • secondary AgentRelease / Eval / AI Factory / context integrations explicitly separated from the v0.1 core;
  • old ExecutionAttestation-as-final-proof narrative moved to compatibility status;
  • release notes/readiness/freeze/release verification/development docs aligned;
  • synthetic GPU XID demo explicitly labeled as composition/replay fixture;
  • stale pre-v0.1 future-state wording removed from stack documentation.

Non-goals

No new runtime, CRD, lifecycle phase, policy product, provider authority model, Agent framework abstraction, MCP gateway, IAM system, or signing service is added.

Tag gate

Do not create v0.1.0 until:

  • package/public compatibility gate is green;
  • full-history audit is green;
  • fresh-clone kind Acceptance Artifact gate is green;
  • no open P0 correctness issue remains;
  • release notes and known limitations are aligned.

At the latest repository check there are no other open PRs and no open P0-labeled issues; the release checklist leaves v0.1.0 tag/release creation as the final explicit unchecked item.

@avaargsh
avaargsh merged commit 62da9f3 into main Oct 4, 2026
8 checks passed
@avaargsh
avaargsh deleted the release/v0.1.0-hardening branch October 4, 2026 03:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant