Changelog
September 22, 2026 · View on GitHub
Project log follows a compact Keep a Changelog
format: Unreleased then release buckets, grouped by impact.
For full historical detail of every entry, refer to docs/CHANGELOG-ARCHIVE.md.
Unreleased
-
Add the internal
public-generic-wasm-provider.v1Project profile as the first compiler-owned target foundation for #229. Package Manifest v1 now selects exactly one concrete checked generic owned-record endpoint, derives its Public Generic Descriptor v1, independently replays it against the exact linked program and project revision, and binds the verified digest into Project Lock v1. Web, npm, native, and Agent Transport artifact routes remain fail-closed until the Core Wasm provider emitter exists. The #162 native generated-caller settlement gate now shares this compiler-derived descriptor, binding, instance, cleanup, and leaf identity across C, C++, Rust, and the executed reference provider; the endpoint body remains the explicit reversal fixture, so neither issue is closed by this phase. -
Make the push-driven CI and Docs workflows latest-ref only: a newer run now cancels its in-progress predecessor instead of spending hosted runner minutes completing already-superseded matrices or documentation builds.
-
Extend the bounded resumable-effect source profile from one site to one to eight direct sequential Copy-scalar
yieldsites. The deterministic plan now carries ordered per-site states and yield-free resume projections; the public interpreter uses an opaque in-memory request/answer history, while private native-O0/-O2and Core Wasm runners replay the same projections. Every historical request is checked, and bindings commit exact arguments plus prior answer bits. This remains pure replay, not live-frame/liveness lowering: control-dependent yields, owned state, durability, scheduling and public target ABIs remain open. Distinct request/response assignment sites fail closed withSPX-T299;letand tail sites retain distinct types (#204). The original one-siteResumablePlan, exhaustiveResumableStepand start/resume functions remain source-compatible; sequential lowering and execution use additive plan, step and start/resume surfaces. -
Add the initial deterministic compiler-owned three-state HIR plan for the single-top-level, Copy-scalar
yieldslice (subsequently widened above). Resume state now binds the exact checked program, yield site, and bit-exact original arguments. Closed projections now isolate disconnected yielding functions while retaining the selected and authored-entrypoint direct-call closures; retained non-scalar, effectful, owned-cleanup, generic and function-reference surfaces, all authored nominal/authority surfaces, reachable yielding callees, retained incoming callers, forged projections, and stale bindings fail closed. The interpreter consumes the plan identities, whilecfg(test)-only native-O0/-O2and Core Wasm runners execute independently validated yield-free projections, preserving exact normalized prefix/suffix arithmetic and pre/postcondition failures. Ordinary native/Wasm emitters still refuseyields; arbitrary NaN-payload preservation across the JavaScript Wasm test adapter, public continuation ABI, external-await runtime seam, durable source checkpoint, Agent migration, and general live-frame/control-dependent yield lowering are not claimed. The reference v1 journal additionally completes an already-observed partial turn without redispatch and never repeats cleanup for an in-memory replayed terminal; its unchanged wire has no durable append or cleanup settlement, so decoded terminal cleanup and crash recovery remain ambiguous and unclaimed (#204). -
Add a deterministic, non-executing cross-language benchmark reproduction capsule that binds exact task and adapter inventories, equivalence files, public and hidden trees (including empty directories), and per-language adapter policy. Stable descriptor-backed reads reject path swaps, and a matching capsule says only that scoring inputs match, never that a model or toolchain ran (#211).
-
Compose the task-service reference application and generated service scaffold with
std.tracing's pure trace-context and secret-classification policy now that reachability pruning admits the dependency closure. Valid, malformed, and caller-classified-secret cases join the existing backend parity gate; no logging, span emission/export, or host authority is added (#194). -
Record the first hosted Windows compilation evidence for the production provisioner confinement module. The successful Windows Server 2025 job compiled the
cfg(windows)code at the exact recorded revision but selected no confinement test function, so runtime confinement evidence remains open (#236). -
Add an offline, unavailable-only admission gate for future external coding- agent baselines. It binds the owner-pinned task inventory bytes and Zero source revision to closed toolchain, interface, model, and reviewed-port provenance without running a model or treating provenance as execution evidence (#107).
-
Carry exact empty
Bytesarguments through source-native Core Wasm Agent stages using the existing named slice/range/copy ownership path, with interpreter, native-O0/-O2, and Core Wasm parity plus a retained malformed-carrier refusal (#143). -
Harden generated package preview verification around a flat physical-file inventory and private verified snapshots before optional npm or Cargo dry- runs. Package publication, signing, registry credentials, and support-policy promotion remain outside this tool (#145).
-
Harden the paired-agent pilot's stale-recovery metric so only an exact, well-formed conditional write to the drifted source can count as recovery, and only the gateway's exact stale-precondition refusal can count as a rejected stale write. Reads, unrelated paths, malformed commands, and other failures now fail closed instead of producing optimistic evidence. Fresh cohorts now have a digest-bound reviewer packet and exact 18-tuple audit: direct treatment labels are withheld, task content remains visible, and hostile or drifted evidence fails closed without backfilling the historical cohort (#105).
-
Preserve
i64::MINwhen source-native Agent stage arguments are synthesized for Core Wasm and native C11 execution. A four-leg regression now exercises the value through the interpreter, native-O0, native-O2, and Core Wasm, while empty byte literals retain their stable refusal (#182). -
Add a binding-first Lean-kernel certificate recheck that re-derives the source, exact obligation selector, Lean document, and Wasm artifact before consulting caller-supplied kernel authority, then requires exact recorded axiom results. Kernel-confirmed evidence can now be associated with one exact retained Project
ProgramRootand appended to its assurance manifest through an opaque verified token; sibling projects, altered source, subset certificates, and replayed revisions fail before attachment. No process, filesystem, network, or tool-discovery authority is added to the compiler (#186). -
Preserve every failing real-distribution role in the provisioned Linux doctor diagnostics instead of stopping at Node's first failure. Hosted run 35472257722 remains red (12/13 in both suites): Clang passed, Node received
SIGSEGV, and Rust's exact termination awaits the next instrumented run; confinement policy and WP-05 status are unchanged (#61). -
Track AArch64 Linux doctor confinement separately with a dispatch-only native Arm runner and an exact 24-case plan. The committed evidence is limited to a historical local Docker Desktop Arm VM run (24/26); the two real-distribution fixtures remain excluded for missing selector/bundle preconditions, and no hosted, current-head, or physical-device support claim is made (#279).
-
Compose
std.tracingtrace-context field admission with the existingstd.log.redactsix-flag caller classification, preserving malformed-context refusal and left-to-right lazy evaluation. It does not inspect bytes or tracestate and remains a pure policy layer with no span generator, exporter, sink, or transport authority (#193). -
Version and digest the public-generic hostile corpus, pinning 17 shared case outcomes plus exact bytes for 9 structured-descriptor and 6 malformed-trusted cases in one deterministic manifest while correcting stale evidence counts. Persistent compiled source mutants now prove that five previously untested descriptor-envelope refusals are individually live in the generated Rust, shared C11/C++17, and TypeScript consumers, and that weakening each branch reaches the provider before clean settlement. Exact-current-head hosted evidence, carrier-side consumer hostility, and real generated endpoints remain outstanding (#173).
-
Drive the private frozen iterative Agent loop through the existing sealed interpreter, native C11
-O0/-O2, and Core Wasm stage backends. The local parity gate covers proposal admission, fresh consumed grants, injected binary reads, continued and terminal reductions, cancellation, malformed proposals, lifecycle ceilings, and semantic evidence settlement while leaving production wrappers interpreter-only. It also fixes canonical lexical selection of ten- plus synthesized Wasm projection exports without reordering driver, decode, or cleanup plans. Native/Wasm interpreter-fuel and hosted evidence remain open (#182). -
Extend the source-live repair preview with an explicitly selected OpenCode Provider-Adapter route, durable V2 receipts, a restart-stable absolute deadline, and checkpoint identity bound to the chosen executable and scratch path. Terminal recovery now replays recorded provider bytes without pre-deriving fixture diagnostics or redispatching, binds corrective turns to the actual canonical prior effect, and rejects tampered settled responses. A public embedding seam can now inject one opaque, host-selected, fixed-buffer candidate-test observer: its canonical result is bound to the exact candidate/base/source/capability, settled as typed feedback for a later provider turn, and replayed without redispatch. Executable bytes and metadata are bound, run/export scratch state is cleaned before reuse, and foreign or tainted observations fail closed. The ordinary CLI still grants no test or publication authority; the scripted V1 seam stays frozen for offline regression coverage (#116).
-
Add whole-line UTF-8 validation and checked nonnegative
i64total helpers to the catalog-normalizer example, with malformed-scalar, boundary-total, backend-parity, and mutation-control regressions. This is a bounded foundation tranche; the complete record parser, canonical writer, duplicate handling, and independent oracle remain open (#124). -
Have tag release jobs produce pinned GitHub build-provenance attestations for each platform archive and keylessly sign the final aggregate provenance with pinned cosign tooling. Release publication now carries those bundles beside the manifest and provenance, while policy and tests distinguish the GitHub OIDC
subclaim from the Fulcio workflow-URL certificate identity. A bounded offline verifier now closes the Sigstore v0.3 framing, GitHub workflow-v1 predicate structure, exact archive inventory, and aggregate manifest/provenance/claim bindings before invoking an explicit verifier capability.SigstoreOfflineVerifiersupplies the standalone CLI's default pure implementation, checking certificate-chain and pinned identity, DSSE/message signatures, signed time, and transparency-log evidence against exact caller-supplied historical trusted-root bytes. An embedding host can still inject another capability. Verification performs no network or root refresh and does not establish current revocation state, publication, reproducibility, or support. No signed hosted release is claimed yet (#168). -
Stop Universal Semantic Transaction v1 from refusing every project with a commented bundled dependency (#274).
ProjectCandidate::apply'smaterializestep re-derived every source in the revision through the comment-dropping canonical formatter, so the comment-free precondition had to span the complete workspace -- including compiler-bundled dependency source (std.authcarries 253 comment lines,std.jobs34) that no project can edit, makingSPX-G525unsatisfiable by construction rather than by authoring.materializenow preserves an untouched program's exact base bytes, and the newsrc/project/semantic_transaction/canonical_sources.rsenforces comment-free canonical source differentially, of exactly the sources a transaction rewrites or drops. A comment in a rewritten source is still refused withSPX-G525, and theSPX-G525regression that proves it is unchanged. -
Run a real Lean kernel against the
proof_exportobligation export for the first time (#186). The module shipped with noLeanKernelimplementation and no evidence Lean accepts its generated proofs -- every test replayed synthesized output.scripts/lean-export-gate.pyis that implementation, deliberately outside the crate so the compiler gains no ambient process authority: it confirms the host runs the pinnedleanprover/lean4:v4.34.0(the same pinproofs/kernel0-leanuses), checks the committed golden document plus two seeded variants, and compares each result byte-for-byte against transcripts committed undersrc/proof_export/testdata/, so recorded evidence cannot silently go stale. Results:omegadischarges both the checked-range obligation and the postcondition, axiom-clean and byte-reproducible across runs; a seededsorryis refused; and a vacuously weakened conclusion is accepted by the kernel with an axiom set cleaner than the honest proof's -- recorded as data, because it is precisely why a certificate bindslean_source_sha256andverify_certificate_against_sourcere-renders the document from source instead of trusting the embedded bytes. Fixes one real fail-open the real kernel exposed: Lean 4.34.0 printsdeclaration uses `sorry`with backticks, so both single-quoted spellingskernel_report::parsewas written against (from synthesized fixtures) were dead against the very toolchain the module pins, leaving only thesorryAxclause load-bearing; quoting is now normalized. All kernel evidence is local-host only -- hosted CI provisions no Lean toolchain, the gate is not inscripts/quality.shand not inrelease-gate's blocker set, and every certificate now carries that as an explicit nonclaim. -
Narrow
ProjectFrontendCache's AST-level invalidation (src/project/incremental.rs): a provider module's own changed/added/removed source still invalidates its frontend cache entry, but an unrelated consumer that only imports from that provider no longer loses its entry through the old transitive reverse-import closure. Parsing and canonicalizing one file is a pure function of that file's own bytes, so a reused entry is bit-identical to a fresh reparse regardless of what any provider did, and every cross-module check (import stub validation, the checked-HIR cache's own exactsynthetic-equality gate) still reruns unconditionally against the current build's sources, so a provider's exported-surface change is still caught -- narrowing this set only decides which unaffected files skip a redundant reparse. Onexamples/calculator-project, a provider body edit went from 0 modules cloned / all 3 reparsed (80 AST nodes) to 2 modules cloned / 1 reparsed (32 AST nodes), matching the existing local-body-edit case instead of being its expensive opposite (#130, #131). -
Add
scripts/generated-package-release.py(prepare/check), a release-preparation and dry-run-only layer around the existing Project v8owned-data-api.v1generated npm/Rust packages: closed-inventory, secret/local-path, and no-private-dependency admission; deterministic README/LICENSE/checksum-manifest wrapping; and acheckstep that only ever runsnpm pack --dry-run/cargo publish --dry-run(never--publish, never near a live registry credential). Prepares (but does not make) the maintainer publication decision drafted indocs/GENERATED-PACKAGE-PUBLICATION-DECISION-DRAFT-V1.md; nothing is published by this change (#145). -
Refuse a bundled dependency member that names an authored type at the Useful Data workspace linker boundary, by name, rather than admitting it into a declaration set that deliberately holds no authored type and letting it surface much later as
inline-array slot references an unknown typeinside inline-array capacity analysis. Drop such a member from the retained dependency inventory when nothing reaches it, so a bundled package may still declare a generic record. This restoressemaprax new --template service, which therecord Secret<T>added to the bundledstd.authhad broken for every scaffolded project (#268). -
Execute the unchanged native reference provider inside freestanding Core Wasm at O0/O2 under both V8 tiers, with in-module allocation, ownership registries, multi-call copy-in/export/release and no host imports. Add a bounded private transport, exact native/corpus comparison, allocator self-tests, hostile-range and lifecycle tests, deterministic artifacts, canonical replay, and compiled semantic mutation controls for #162. This is a C11-reference fixture, not a Semaprax-generated generic endpoint, public Wasm ABI, PG-7 completion or hosted promotion. Actual Rust-renderer equality remains a separately selected gate.
-
Enforce single-owner, non-reentrant native reference-provider admission with one atomic owner/entry word; retain ownership until the last provider closes, and isolate failure injection, traces and sticky diagnostics per caller thread. Reject misuse without touching caller output/owning aliases or reporting false zero-resource counters. Extend #162 with deterministic pthread misuse/handoff, exact/+1 thread-identity admission, sanitizer, replay and mutation gates. This enforces the existing synchronous restriction, not concurrent execution, compiled generic-provider support, PG-7 completion or hosted promotion.
-
Harden the host-owned TypeScript/Wasm reference caller: authenticate immutable module-byte snapshots, reject unverifiable precompiled modules, isolate private descriptor/binding authority, enforce one in-flight owner and exact framed payload bounds, preflight complete result frames, and propagate primary plus secondary cleanup failures. Extend #162 with 108 settlement cases, 32 host regression groups, 13 authenticated module subjects, two V8 Wasm execution tiers, fresh C/C++ semantic comparison, strict replay and twelve type-checked behavioral mutants. Add actual-generator byte-equality gates without claiming those Rust gates have run, compiled-provider support, PG-7 completion or hosted promotion. No existing native ABI or public rejection profile is widened.
-
Propagate explicit native release failures through C11/C++17 calling consumers without exposing a decoded success or overwriting earlier failures. Add checked close with retained ownership, reverse caller rollback, bounded encoding/export/decode, and per-invocation injection isolation. Implement corresponding Rust settlement and fallible codecs, with separate Cargo regressions. Extend #162 by 112 shared consumer cases, independent caller counters, replay evidence and eleven compiled semantic negative controls; actual generator/Rust execution remains a distinct gate, and full PG-7, compiled Wasm and hosted promotion are not claimed.
-
Return real native input/result release failures without overwriting an earlier call's settlement. Extend #162 with actual per-leaf result allocation/copy and export preflight failures, pre-rollback byte checks, exact 16 MiB success, compound reverse cleanup, and 72 pinned physical-phase cases with a third independently replayed evidence artifact. Legacy logical trace bytes and public ABI declarations remain unchanged; full PG-7 and generated-consumer failure propagation are not claimed.
-
Prevent stale native public-generic handles from reviving when heap addresses are reused; validate provider identities before access/close and pin bounded, non-recycled identities plus exact/+1 live-resource admission. Isolate settlement between sibling prepared inputs so an earlier success cannot mask a later failure as success-without-result. Extend #162 with lifecycle/recreation, identity-exhaustion, 8,192-call stress and paired replay evidence; public ABI signatures and unsupported/unpublished status remain unchanged.
-
Share one bounded, digest-pinned public-generic settlement manifest across the existing model/native harnesses; preserve primary failures before cleanup and reverse every native result rollback. Add per-case native observations, real allocation/compound-failure regressions, retained trace expectations, and portable sanitizer/replay evidence. This advances the fixture subset of #162; it does not close PG-7 or widen public ownership support.
0.5.0 — 2026-09-14
-
Bind effect-free retained source job handlers to persisted deployment descriptors before claim, using the existing durable job runtime and checked interpreter; refuse stale roots and handler substitutions (#192).
-
Complete the ten-row feature-composition inventory, exact ownership-profile refusal regression, and provisioned strict differential campaign route with explicit CI selections and nonzero-case enforcement (#103).
-
Add exact SDK-envelope byte reservations to durable retries with frozen V2 journal preservation, canonical V3 recovery, and post-poll cancellation checks (#179). Tighten provider conformance around request admission, completion, final bytes, and usage regressions with corpus V2 (#181).
-
Add a checked two-call offline repair loop and private CLI demo with bounded candidate edits, diagnostic feedback, read-only review evidence, and terminal journal replay (#116). Extend imported owned cursor failure composition with exact Wasm cleanup-order and sticky-status controls (#103).
-
Account compact workspace validation clones before allocation and schedule the final uncached graph phase by temporary HIR overhead without raising its cap (#124). Add decoded ID bounds and allocation-free token equality to the catalog helper application with cross-backend oracle checks.
-
Add generic durable retry/failover with acknowledged attempt journals, exact retained execution/schema/model bindings, non-widening source and deployment limits, request-seed checks, and conservative recovery (#179). This is local host composition; checkpoints do not prove provider identity or billing.
-
Add V6 durable source-model quote accounting with nonrefundable observed and unknown usage, absolute deadlines, cumulative migration carry, and optional request/response byte ceilings (#113). Retain observed quote overages in ordinary source-model admission as well.
-
Retain exact generic model request/response reservations in the additive priced I/O envelope, cross-bind successor carry, and reject noncanonical recovery requests (#113). Add store-backed typed source-model execution with acknowledged intents, exact raw settlements, and no uncertain redispatch (#177). Release full sequential workspace HIR after compact validation facts and selected output carriers are extracted (#124).
-
Pair generic live work reservations with durable monetary accounting (#113), and enforce opt-in source-model ceilings before adapter construction (#177, #179). Add a final uncached graph retry that charges retained output vectors while preserving earlier successful budget receipts (#124).
-
Bind typed live model operations to deployment selection and commit their redacted attempt evidence in an additive execution root (#177). Propagate remaining host deadlines and distinguish reserved, observed and unknown provider charges in a separate Runtime v1 receipt (#113).
-
Add counterbalanced pilot scheduling, isolated MCP tools for both comparison lanes, retained candidate source bytes and exact transport archives (#105). Trial capture remains separate from eligible observations and review.
-
Preserve pre-dispatch OpenCode cancellation as a zero-call cancellation failure (#113). A changed journal or claimed dispatch without a receipt remains a model failure; unresolved attempts cannot become clean refusals.
-
Add direct owned String variant payloads (#216), with canonical String lifecycle replay, own/borrow matching and backend cleanup. Scalar-match guard and arm temporaries settle through exact cleanup regions. Generic String substitutions and nested owned-record variant payloads remain restricted.
-
Add explicit Rust-host Argon2id password hashing, authenticated sessions and signup/login/logout composition (#191). Persist job cancellation and recurring schedule advancement with checked arithmetic and replay evidence (#192).
-
Add checked-source HTTPS POST across explicit provider, native C11 and Core-Wasm/npm fixture paths (#193), with bounded body/response bytes, explicit destination authorization and no automatic retry or redirect for POST.
-
Add an explicit native HTTPS transport for provider adapters (#181), with injected credentials, bounded buffered responses and conservative dispatch uncertainty. Extend compact task context with ordered seeds, revision binding and selectable token accounting (#197). Add a host-driven single-job checkpoint runtime and evidence-based recovery (#192).
-
Drive bounded retries and ordered failover through injected provider adapters (#179), preserving charged attempts and stopping on uncertain outcomes. Add host-transport protocol adapters for Responses and Messages (#181). Recheck cancellation and deadlines when streaming settlement returns. Add an eighth cross-language task family exercising owned byte mapping and hidden-oracle rejection in Rust, TypeScript and SEMAPRAX (#106).
-
Import bounded provider invoice evidence through explicit verifiers and retain reconciliation results (#180). Enforce source usage consistency and complete audit-view disclosure, payload association and truthful privacy claims; add canonical audit replay and direct receipt emission from live run evidence.
-
Decode canonical model receipts with strict bounds and enrich actual generic and source attempt journals using retained root, request and host metadata (#180). Join explicit adapter observations and provider usage without inventing missing measurements; preserve failure and unresolved lifecycle evidence.
-
Capture ordered provider adapter attempts and replay retained chunks against actual generic/source runtime schemas (#178/#180). Bind generic settlements to validated journal requests and responses; compare provider token and cost observations independently during invoice reconciliation.
-
Validate streamed nested Proposal fields, variant cases, exact scalars and text/byte bounds from compiled type tables before final decode (#178). Expose read-only grammar states and bounded work counters; extend the generated TypeScript/Python/Rust client harness with adversarial chunking.
-
Add versioned selective-dictionary model-text projections to CLI, retained service and compatibility negotiation (#201). Connect streaming proposals to Direct Runtime v2 typed effects and reject mismatched compiled schema envelopes while streaming (#178); nested semantic admission remains in the full decoder.
-
Expose compact projections through CLI replay and retained service/MCP routes, with explicit format/profile negotiation and offline model-token measurement tooling (#201). Introduce Rust embedding API v2 for mandatory analysis/execution input caps, add cooperative request cancellation, and verify opaque session release (#203).
-
Add authoritative task-context, Project API, candidate-diff, and Agent graph compact profiles with regeneration-bound replay (#201). Extend Rust embedding negotiation, cancellation, and the external consumer (#203). Connect the source Proposal grammar to incremental decoding and an explicit per-attempt provider adapter factory with bounded iterative context (#178).
-
Connect the streaming Proposal decoder to the provider adapter and generic live-kernel seams (#178), and compose token/cost/call policy with the live work-budget hook (#179). Extend the embedding facade with opaque in-memory Project sessions, atomic refresh, semantic query, and candidate replay (#203).
-
Add journal-derived model-call receipts (#180) for generic live runs and authenticated source checkpoints, including exact replay and Audit Capsule object references. Unrecorded timing and billing stay unknown. Harden enriched receipt replay against contradictory response states and decode refusals. Extend the Rust source embedding facade (#203) with bounded context v1/v2 queries and explicitly authorized, cancellable, fuel-bounded interpretation.
-
Implement additive Project Assurance Manifest v1 (#214): a canonical, integrity-bound envelope bound to one retained Project, workspace revision, ProgramRoot, and complete ordered source inventory. The profile deduplicates shared entry/public/test HIR obligations, records explicit unselected coverage, and admits only held
forbid_reachesarchitecture laws; the existing single-file Assurance Manifest v1 bytes remain unchanged. -
Add additive source-journal I/O v5 accounting and private CLI config/receipt v3 (#113). Authenticated attempt rows reserve exact prompt bytes and bounded response capacity cumulatively; recovery and compatible migration retain reservations without profile conversion. Legacy source journal and CLI profiles remain unchanged. Add #103's result-allocation rejection case with ordered input release in interpreter/Wasm and status/resource parity in native C11 O0/O2, including a wrong-order oracle control.
-
Extend #113's priced adapter regressions with exact retained retry I/O, invalid quote preflight, and deadlines reached at journal acknowledgements. Add #103's imported
std.bytesview-composition oracle across the Project interpreter, native C11 O0/O2, and Core Wasm, including temporary cleanup. -
Add an explicit priced source-journal v4 route and private CLI config/receipt v2 (#113). Integer currency-bound reservations remain separate from work quotas and provider observations; replay retains unknown exposure and refuses quote drift. Add the private CLI's one-hop priced-to-priced migration carry, preserving cumulative reservations, observations, overage, and global money ordinals under a non-widening compatible quote. Legacy source profiles remain unchanged; unsupported profile conversion is refused.
-
Construct ordinary imported function stubs from signatures without cloning discarded bodies (#124). Preserve fitting graph receipts and add an uncached fallback charging retained HIR plus the peak of sequential synthetic ASTs, within the existing builder limit; cached frontends retain summed charges.
-
Add opt-in, bounded current-thread workflow stage observations and an offline campaign runner; compare exact cold/warm frontend products and prepared traced/untraced products before timing. Measurements remain local evidence, separate from canonical artifacts and authority (Refs #85).
-
Pin cumulative durable source reservation boundaries at zero, exact, and one-unit-over ceilings; terminal recovery retains accounting with zero new proposal, model, or effect dispatches (Refs #113).
-
Exercise eight borrowed byte-view call compositions across interpreter, C11 O0/O2 and Core Wasm, including offset-sensitive forwarded views, comparator rejection and the stable escaping-view diagnostic (Refs #103).
-
Validate bounded Descriptor-v1 frames and versions in generated calling consumers before exact pairing and provider admission; exercise canonical shared mutations and byte-identical malformed configured descriptors in Rust, C11, C++17, and TypeScript/Wasm (Refs #173).
-
Add independent sensor-conjunction and stable three-job ordering benchmark families with candidate-preserving hidden overlays and three-port negative controls (Refs #106).
-
Add private
semaprax-full source-live run|resume|migratecommands (#113/#116), with held-directory checkpoints, exclusive writers, bounded explicit task/read inputs and retained-Project bindings. A migration carries the predecessor clock floor and nonrefundable work into one claimed destination. Recorded-provider tests cover run, recovery and checked migration; monetary pricing and the actual source repair workflow remain separate. -
Extend the catalog-normalizer source application with bounded JSONL record counting and line/body limits (#124). Seven application cases execute on the interpreter, C11 at both optimization levels and Core Wasm; a terminal newline counting mutation is rejected. Full record normalization remains.
-
Reduce the last-resort workspace graph construction estimate (#124) by charging the largest sequential temporary import clone once. Imported stubs release their discarded contract-vector buffers. Earlier accepted receipts and the 18 MiB cap are preserved; core retries stay bounded.
-
Add a fifth held-out cross-language benchmark family for half-open booking conflicts (#106). Rust, TypeScript and SEMAPRAX share candidates across public and hidden runs; an inclusive-end mutation passes public cases and fails hidden adjacency cases on each port. Actual coding-agent trials remain.
-
Migrate suspended source-mode agents through checked retained-Project A→B→C handoffs (#115), preserving schema provenance and cumulative charged work. Acknowledged migration results resume at Observe; initialization and completed effects do not repeat. Lost acknowledgements, cancellation, deadline drift, and malformed recovered State fail closed under explicit host-store freshness.
-
Add private filesystem v3 checked atomic writes (#228), with inspectable Published, NotPublished, and Uncertain outcomes and an exhaustive std.fs variant wrapper. Interpreter, native C11 and Core Wasm preserve the separate callback failure channel and legacy v2 behavior. Graph v46 binds the new operation; compact conformance fixtures keep the existing construction limit.
-
Add a fourth cross-language benchmark family for a multi-module invoice calculation (#106). Candidate-preserving hidden entry modules distinguish whole-subtotal rounding from per-item rounding in Rust, TypeScript, and SEMAPRAX Project execution. This adds corpus coverage, not coding-agent trials.
-
Separate native public-generic allocation accounting from the 16 MiB logical carrier limit (#250), allowing metadata and overlapping full input and result payloads. Exercise exact-byte boundaries across local native, interpreter, and Wasm fixtures, with bounded allocation failure and cleanup.
-
Pin Cargo, rustc, and rustdoc in the generated Rust consumer's MSRV gate (#226). Selecting Cargo alone had allowed the ambient newer compiler to satisfy the check. Native allocator capacity remains tracked in #250.
-
Cover drop-free nested variant payloads through interaction-schema derivation, canonical decoding, and hostile nested-field refusal (#216). Correct the proposed checked-write taxonomy to distinguish proven non-publication from phase-ambiguous legacy I/O errors (#228); missing-parent provider regressions preserve the current fail-stop operation.
-
Add a separate structured-envelope validation task to the cross-language corpus (#106), with candidate-preserving hidden tests and a negative control for wrong error precedence and removed visible assertions. The additive SEMAPRAX Project adapter leaves the original pilot and task routes intact.
-
Connect source checkpoint execution to the checked iterative driver (#113). Journal v2 reserves fresh fuel on replay, shares one model-budget ledger, persists optional usage and terminal evidence, refuses uncertain redispatch, and retains partial failure evidence. The OpenCode durable source borrows that ledger; source migration and a durable CLI remain pending.
-
Exercise lazy boolean operands containing checked division failure through the differential corpus (#103), including interpreter, native O0/O2, and Core-Wasm observations with explicit lane results.
-
Derive Assurance Manifest result-ownership and resource-cleanup obligations from independently revalidated HIR (#214), and keep candidate summaries aligned. Architecture-law derivation and workspace binding remain pending.
-
Complete the documented-limit decision for compiler capacity (#241): name the distinct checked-cache ceiling in SPX-G256, pin its inclusive boundary, and state graph/replay limits and the source-versus-runtime byte-copy guard.
-
Run TypeScript/Wasm consumer Node entry points with relative fixture paths to avoid Windows extended-path main-module resolution failures. Complete private OpenCode/source-journal documentation metadata and catalog entries.
-
Include Cargo example targets in the CI unit shard, preserving exhaustive workspace inventory and refusal of unknown target kinds.
-
Add an explicit OpenCode proposal-attempt checkpoint boundary over the same source journal and accounting ledger (#113). It validates bound context and phase before charging, acknowledges intent before transport, and persists the outcome before exposing response text. Full source replay remains pending.
-
Add bounded source checkpoint primitives with strict causal validation, poisoned writes after acknowledgement loss, and restoration through the existing charge/deadline ledger (#113). Source runtime replay, provider receipt persistence and migration integration remain pending.
-
Derive cached Project Agent interaction facts from retained authenticated source programs, fixing false SPX-G564 failures without reparsing (#85). Repair the embedding-example index and Clippy CI blockers, and provision pinned Clippy for the public-generic consumer job.
-
Provision pinned TypeScript 5.8.3 for the public-generic hosted job and fail closed on missing consumer tools; record platform/toolchain identities with separate Unix and Windows preflights (#163). Fresh hosted evidence remains pending.
-
Check the OpenCode source route's shared deadline around deterministic stages, proposal admission, effect dispatch and result publication (#113), preserving earlier selected failures. Durable source failure evidence remains pending.
-
Require explicit cumulative reservations for OpenCode source attempts and retain their bounded usage observations across malformed retries and failures (#113). Check the shared absolute deadline at settlement and later kernel boundaries; source recovery and migration accounting remain separate work.
-
Connect one explicitly configured free OpenCode provider to the existing source-feedback driver, preserving canonical proposal admission (#112). Bound Unix process output/cancellation, bind real CLI receipts, preserve reported usage and redact provider error categories. The fixed local live smoke reached Complete; broader hosted/provider support remains separate.
-
Reuse exact retained source ASTs during cached Project finalization and prelude-bound revision replay (#85). Remove nine hidden public parser calls from unchanged calculator builds in both cache modes, preserving revision hashes and admission checks; no timing improvement is claimed.
-
Add explicit untraced prepared Project execution with unchanged traced behavior, fuel, cancellation and revision replacement. Add matching cold and prepared benchmark products and truthful platform-specific memory observations (#85); no new performance measurements are claimed.
-
Persist migrated live-kernel handoffs, state and destination journals in one bounded canonical checkpoint before dispatch, with recovery and store-failure regressions (#115). Checked source migration and cumulative-chain integration remain open.
-
Add a non-editing OpenCode availability smoke and bind archived event streams to the matching exported session and frozen prompt (#105/#112). This is provider availability evidence, not a coding-agent trial or live-driver adapter.
-
Correct the Workspace Semantic Graph and Context/Impact/Review workspace limit projections to report the enforced 18 MiB builder ceiling from one renderer (#248). The 16 MiB analysis/cache ceilings remain separate. Re-pin exact artifact hashes after verifying that restoring only the old limit and dependent digests reproduces every previous known answer.
-
Repair standard-library conformance registration for guarded logging and
std.metrics, and synchronize the generated auth/TOML catalogs (#102). -
Exercise frozen execution evidence around a live fixture invocation and clarify that terminal journal replay preserves its case and carrier digest, not the original carrier payload (#108).
-
Add a standalone Rust consumer for the public check/format/graph embedding facade, with its own offline lockfile and explicit checkout-only scope (#203).
-
Rewrite the
SPX-H006cleanup-replay path-budget diagnostic's message to name the actual cost driver instead of only the budget it exceeded. The previous wording ("cleanup replay path bound exceeds the global path budget") told an author nothing about why: the real driver is combinatorial multiplication of independently-combined branch outcomes within one function (2^N terminal paths for N such branches), not raw branch count, so the natural fix an author reaches for on reading the old message - splitting into helper functions - does not help unless it breaks the combination. The new message states the measured path count and budget, names the combinatorial driver, and names an actionable remedy (make the branches mutually exclusive, or combine their results across separate calls). The diagnostic code is unchanged; per issue #241, neitherSPX-G171's workspace-graph byte budget norSPX-H006's path budget was raised, because no session has evidence that a higher value keeps the workspace graph or the semantic cache finite - both remain documented, regression-pinned limits in the completion matrix rather than raised ceilings. A boundary fixture pinning the exact measured terminal-path count at the crossover (98,300 paths for 15 independent branch terms, not the naive2^15 = 32,768estimate the previous fixture comment assumed without checking) replaces the earlier code-only assertion, plus a dedicated regression that fails if the message regresses to the old cause-free wording. -
Freeze the Public Generic Boundary Profile, Descriptor and Carrier v1, and add a reference codec for the descriptor and carrier wire formats. The same callable generic boundary had been described three times by three overlapping issue packs, with a real scope conflict between a minimal one-owned-
Bytesslice and a contract admitting nested finite records. One admission profile now settles it with an explicit in, deferred and excluded table, so downstream implementation work has a single contract to build against rather than three. Two classifications - owned generic variants and public generic templates - are recorded as contested and awaiting review rather than silently decided. -
Specify and implement the Live Invocation Contract v1: invocation identity that survives retry, resume and recovery, a causal journal with table-driven validation, and a provider-independent
model.invokeeffect with an explicit capability requirement, a closed failure domain and cancellation checkpoints. Replay makes zero dispatches, and an unrecorded result can never be reconstructed by hashing because the journal carries response bytes rather than only a digest. Fixture transport only: no provider binding, no deployment wiring and no live model call. -
Introduce Assurance Manifest v1, a deterministic per-obligation manifest bound to exact source bytes that fails closed on drift. Obligation identity keys to a declaration's persistent stable id rather than a byte offset, so it survives a pure formatting change, and the assurance lattice is a genuine partial order rather than a single ranking - compiler-proved, SMT-proved and model-checked are deliberately incomparable. External records let later formal-method backends contribute without this module changing, so a simple candidate summary never waits on formal proof.
-
Freeze the catalog-normalizer acceptance application and an independent oracle: 25 requirement ids, 51 known-answer cases split into published and hidden, and six runnable negative controls that each provably diverge from the correct output. The hidden-case boundary is a review policy rather than cryptographic isolation, and the specification says so plainly instead of implying a guarantee the repository cannot enforce.
-
Preserve comments and unrelated bytes in the v2
ReplaceExpressionroute. The transaction previously rejected any workspace containing a comment before it even selected an expression, because the shared candidate rebuild always reprinted through the comment-oblivious canonical formatter. The edited file may now carry comments, preserved by a span-scoped splice that is independently reparsed and required to match byte for byte; a comment overlapping the edited span is refused rather than silently relocated. Every other source keeps the exact comment-free requirement. -
Resolve
core.optionin theuseful-text-consumer.v1linker, which never seeded the compiler prelude its Useful Data sibling relies on, so anymatch byte_get(...)in a Project-linked text package failed validation. The profile's public signature restrictions are unchanged and pinned by a test. -
Bind release publication to the exact-tag gate explicitly, and add a reconciliation check for release claims. This caught a live defect: the README claimed v0.4.1 was the published tag while citing v0.4.0's date, commit and anchor.
-
Connect an external coding-agent runner to the existing comparison ledger, reusing its plan, trial, ledger, observation and audit schemas unmodified. A candidate cannot escape its sandbox, write the finalized ledger, or claim its own acceptance: a backend that reports every criterion passed while leaving the work undone is still scored as failed. Offline fixture backend only; the paid paired pilot needs an approved model budget.
-
Correct a stale claim in the doctor provisioner specification, which stated the provisioned gate had never executed when nine real runs exist, the most recent of which failed.
-
Give the MSRV shards the same time budget as the identical
verify-testscommand. Both runscripts/ci-msrv.py --shard, but the MSRV job had 40 minutes against that job's 90 while compiling the same workspace on an older toolchain. Theintegration-1shard was cut off mid-test on two runs while finishing in about 35 minutes on others, so its result reported the runner's speed rather than the shard's outcome - and a cancelled blocker fails the release gate exactly like a real failure. The coverage guarantees are unchanged: the contract still forbidscontinue-on-error,--no-fail-fast,--exclude,--skipand caching, and still requires the full check and every shard.
0.4.1 — 2026-09-11
-
Record cross-platform hosted evidence for the public generic ownership milestone. The
public-generic-ownership-milestonejob is green onubuntu-latest,macos-latestandwindows-latestfor implementation commit2ef043ba1b989f49b256e456f71fb6e89068bf33in run 34594793245, with each leg's log showing all four consumer toolchains exercised rather than skipped. Gate PG-8 and the four gates whose corpus that job runs - the type grammar, template and ordered argument identities, the compatibility rules and the candidate delta - move toHosted green. PG-5, PG-6 and PG-7 stay open because the corpus contains none of what they ask for, and PG-9, the support and publication decision, stays open: public generic ownership remains unsupported and unpublished. -
Fix a temporary-path collision between two copies of the same owned-data native test helper.
owned_vec_bytes_runtime/native.rsis#[path]-included by two modules of one test binary, so it is compiled twice and each copy owns a separate case counter starting at zero - while both named their scratch files from the process id and that counter alone. Two tests in the same process therefore shared a.cpath and a binary path, which is exactly what the hosted shard reported twice: one run could not execute a binary a concurrentclangstill held open (ETXTBSY), the next could not read a.cfile the other copy's cleanup had already removed. The name now includes the module path, so the two copies cannot collide. The generated public generic consumer gate, which also compiles and then executes, retries a launch refused withETXTBSYrather than adding another way for a foreign fork to redden an unrelated shard. -
Make the generated C and C++ public generic consumers build on Windows. The hosted leg found two things a Unix-only run could not: the UCRT marks the standard
fopendeprecated in favour of its ownfopen_s, which a-Werrorbuild turns into an error, and a compiled consumer needs the host's executable name because Windows resolves a bareconsumerby looking forconsumer.exe. The generated sources now opt out of that deprecation, and the gate names the executable per host. The C++ consumer also dropsstd::span, which it used only to carry a pointer and a length together: a pointer and a size are the same information, so the generated artifact no longer needs a C++20 library header and builds under C++17. The compile check now fails on a warning or an error in the toolchain's output rather than on any output at all, because "compiles warning-free" is the claim; a linker note about something else is not evidence about the generated code. -
Make generated public generic consumers independent of the checkout that produced them. The fixed part of each consumer is an included template, and a Windows checkout delivers
.txtwith CRLF, so every placeholder whose match included its newline silently stopped substituting: the generated files kept their literal placeholders and lost both their type declarations and their embedded metadata. Templates are now normalized at generation time,.gitattributespins.txtto LF like every other embedded text asset, and the generator itself asserts that no generated file carries a carriage return or a surviving placeholder — so this class fails where it happens rather than as a downstream expectation on one platform. A generator that only worked because of a checkout setting was not the deterministic generator the milestone claims. -
Guard the Windows checkout of the public generic ownership milestone job. Its first hosted run failed on
windows-latestbefore any gate executed: the checkout itself cannot write this repository's retained evidence paths withoutcore.longpaths, which every other Windows job already sets. The cross-platform leg was therefore reporting a checkout limit, not a milestone result. -
Add Public Generic Candidate Delta v1, milestone gate PG-4: a candidate-bound delta that describes the selected exports of an immutable Project candidate's base and final revisions over the public generic grammar, classifies the pair with the PG-3 rules, and binds the candidate digest, both Project and workspace revisions, both graph digests and a domain-separated facts digest. Inclusion is grammar-strict, so an entry in the delta is exactly a candidate public generic signature: no admitted export has one today, which makes the generic fixture all-excluded with the closed reason
borrowed_byte_view- and the gate asserts its rendered bytes carry no template identity, instance term, record identity, or even the grammar's instance sigil. The substantive evidence rides on a Project v9 record-returning export, where a realadd_record_fieldchange isbreakingwith the finding on the record that changed and ordered arguments, substituted fields and owned leaves retained across mutation, recovery-capsule restoration and byte-exact independent replay (SPX-PG301-SPX-PG303). The grammar now also exposesRejection::ALLandRejection::of, so a consumer recovers a typed reason from the owning artifact instead of re-spelling its message, and the compatibility report exposes its digest. -
Add Public Generic Settlement Obligations v1: for one owned admitted instance parameter, which owned leaves a boundary is accountable for, in which order, how each is discharged, and what is released when a transfer fails part way - each fact bound to the compiler's own cleanup facts rather than derived beside them. The grammar's owned-leaf paths must equal the inventory's structural leaf order; each obligation is paired with its liveness flag in flag order and carries that flag's checked drop lifecycle, because an obligation whose flag does not match it has no stated way to be discharged; and the transfer unit is the cleanup plan's single whole live owned place, since reading leaves out of the plan would invent a per-leaf transfer the compiler never performs. Release order is the exact reverse of the canonical order, and every disagreement is a refusal (
SPX-PG501,SPX-PG502) rather than a sort or a repair. This is the specification half of milestone gate PG-7, which stays open: nothing here allocates, transfers, releases or observes a runtime, and there is no public generic boundary to exercise on any engine. -
Wire the public generic ownership milestone corpus into CI as the
public-generic-ownership-milestonejob onubuntu-latest,macos-latestandwindows-latest, and declare it a release blocker so it cannot be satisfied vacuously. It runs the grammar, template-identity, compatibility and metadata-consumer projections, the separation gate, the frozen Project v9/v11 descriptor refusals of a selected generic result, and the four-language consumer gate, and it resolves and prints the consumer toolchains each host actually has - a language whose toolchain is absent is skipped, which is a narrower run rather than a pass. Milestone gate PG-8 stays open: the harness exists, the hosted evidence does not, and the gate moves only when the owning document records a run and job for an exact implementation commit. -
Add Public Generic Metadata Consumers v1: a Rust, TypeScript/Wasm, C11 and C++ consumer generated from a candidate public generic surface, plus the length-framed canonical metadata format they read. Before a foreign toolchain can call a public generic export, several of them have to agree on what its types are and refuse everything else - and that is falsifiable without a calling convention. All four consumers are compiled warning-free and run for real against nine hostile documents, and each must report the same closed refusal (
malformed,term,mismatch) as the others and as the Rust reference reader; the gate fails when no toolchain was available rather than passing silently. Identifiers come from term bytes rather than display names, nested instances are declared before their holders so C and C++ never see an incomplete type, and regeneration is byte-identical. This closes the grammar half of milestone gates PG-5 and PG-6; both stay open for their descriptor half, because no public generic descriptor, carrier or calling convention exists. No generated consumer receives a SEMAPRAX value, allocates one, frees one, or links against anything, and every generated file says so in its own banner. -
Add Public Generic Compatibility v1, gate PG-3 of the public generic ownership milestone: candidate surfaces over the type grammar, and a closed thirteen-reason classification of one ordered pair of them. The rules are deliberately stricter than source compatibility, because a foreign consumer reads the whole substituted field tree and owned-leaf shape of what it receives: adding a Copy field to a nested reachable record is breaking even though no canonical term, parameter position or owned-leaf path moves, and it is reported once on the record that changed rather than on every position mentioning it. Presentation is never compatibility - renaming records, type parameters, fields, exports and parameters yields
unchangedwith an identical surface digest - and a parameter's value identity is excluded for the same reason the repository excludes it elsewhere: a revision-scoped fact must not move a verdict. A signature position that is not a data type gets its own closedview:vocabulary instead of widening the grammar. Both artifacts are canonical JSON with directional byte-exact replay (SPX-PG201-SPX-PG204), and both record that no semantic-version, support, publication or runtime conclusion follows from a verdict. A candidate surface is a description, not an admission: no public generic signature is admitted, and local evidence is the only evidence. -
Add Public Generic Type Grammar v1, gates PG-1 and PG-2 of the public generic ownership milestone: a versioned, target-neutral term for the types a public generic surface could name, plus the explicit template and ordered argument identities derived from it. Identities are length-prefixed in bytes, so an identity holding the grammar's own punctuation still round trips and two distinct types can never render alike; digests are computed over persistent identities, declared arity and ordered parameter positions, so a record, parameter or field display rename changes nothing while argument permutation, duplication or substitution changes the instance identity and omission is an
arity_mismatchrefusal. The vocabulary is closed to the eight Copy scalars, directBytesand fully concrete authored records; the other twelve reasons reject, bounds refuse instead of truncating, and replay is byte-exact against an independent recomputation. It is deliberately not the compiler's internal, unversionedidentity_keyspelling. Local evidence only: no hosted run, no descriptor, carrier, package or consumer selects the grammar, and public generic ownership remains unsupported and unpublished. -
Make public generic ownership a separate milestone instead of a side effect of the internal generic closure. The new Public Generic Ownership milestone owns nine prerequisite gates - a versioned target-neutral type grammar, explicit template and ordered argument identities, semantic compatibility rules, candidate ABI-delta evidence, generated Rust/TypeScript-Wasm/C/C++ consumers, hostile metadata replay, owned allocation and failure settlement, cross-platform hosted evidence, and the explicit support and publication decision - plus separation invariants and an executable separation gate. The gate selects a generic template, a concrete generic-instance result and an owned generic parameter through the canonical ABI report, C header emission and the public scalar Wasm export edge, and pins each closed refusal, so an internal admission that starts producing a public generic surface reddens the build rather than becoming a silent public claim. Public generic ownership remains unsupported and unpublished; no grammar, descriptor, carrier or consumer is added here.
-
Add effect-free listing cursors to
std.fs, so the canonical immediate-name listinglistalready returns can be walked without a provider or any further authority: entry counting, per-entry span offsets, and an entry-name validity predicate rejecting an empty name, an embedded separator or NUL byte, and the two traversal names. No function gained an effect and the module's capability list is unchanged; recursive traversal, streaming and richer metadata remain Missing. -
Add the bundled
std.env.policypackage: a portable environment-variable name predicate, a value predicate, and aNAME=VALUEassignment cursor, all effect-free offset computations over borrowed bytes. It is a sibling package rather than more ofstd.envbecause the completion gate requires everystd.envfunction to declareprocess.environment.read, and these functions read no environment - declaring that effect to satisfy a gate would claim a capability they never exercise. -
Add effect-free settlement and argument policy to
std.process: classification of an existing settlement value as a normal exit or a signal termination - the only two kinds the termination encoding defines, per thelow2-kind-0-exit-u32-or-1-signalgraph fact - exit-code extraction defined only where the process exited normally, and argument-vector admissibility over borrowed bytes. A deadline expiry is deliberately not a settlement class: it is a call-level failure that prevents an output from existing, so classifying an unused bit pattern as one would invent a value no provider emits. Onlystd.process.runstill carriesprocess.execute; the new functions perform nothing and grant nothing, and broader physical-provider and general process support remain open. -
Add a checked lifecycle policy to
std.agent: an admitted stage-transition predicate total over the lifecycle vocabulary, a terminality predicate consistent with it, and a deterministic bounded retry policy whose backoff is a pure function of the attempt count. These describe checked meaning only: no clock is read, no stage is executed, and the package gains no capability, effect or permit. Native and Wasm execution of these ordinary library functions still does not execute Agent stages. -
Add quoted-key validation and value cursors to
std.data.toml, closing the key half of its recorded gap.basic_quoted_key_endadmits the TOML basic-string escapes and rejects an unterminated string, a raw control byte and any other escape;literal_quoted_key_endadmits'...'with no escapes;key_enddispatches the bare, basic-quoted and literal-quoted forms; andvalue_start,value_content_endandvalue_endbound a value quote-aware, so a#inside quotes does not open a comment and trailing spaces and tabs are excluded. Every scanner is an allocation-free offset computation and reports failure through thebyte_len + 1 + offsetsentinel thestd.data.jsonfamily already uses for arbitrary-start scanners. Values stay uninterpreted bytes; tables, decoding, typed values and encoding remain Missing. Bare-key admission walks bytes directly instead of testing a growingbyte_rangesub-slice: that shape is admitted by the checker and executes on the interpreter and native C11, but emits a corrupt slice carrier on the Core Wasm lane, filed as issue #100 with a single-variable reproduction. -
Add
decoded_token_eqtostd.data.json.dec: two JSON string tokens in one input compared by their decoded bytes through the existing pull surface, with no buffer, so"a\u0062"and"ab"are equal keys and"\n"equals"\u000a". Tokens of different decoded length are unequal without decoding either fully. Duplicate-key detection over a whole document still needs the object walk instd.data.json.docand remains Missing. -
Add the bundled
std.encoding.base64package, Base64 v1: pull-based padded standard Base64 encoding over a borrowed byte view.lengives the padded output length andbytegives its byte at one index, both computed from the input alone with no buffer, so a caller writes the digits into capacity it already owns. It is a sibling package becausestd.encodingsits on the default Project v1 route, which admits only Copy scalar boundaries and rejects a borrowed view. Decoding of padded input, streaming, and URL-safe or unpadded alphabets remain Missing. -
Add
wrapping_multostd.num.overflow, closing the wrapping-multiplication gap its own required scope recorded as Missing. The result is exact two's-complement wrapping for every operand pair, includingi64::MIN * -1,i64::MIN * i64::MINandi64::MAX * 2, and it never evaluates an overflowing intermediate under the language's checked arithmetic. -
Add a failure-mask discipline to
std.test, so a nonzero test result names the failing check instead of merely being nonzero:bit_foris the bit an indexed case owns,bit_is_setreports membership,record_failureaccumulates one case's verdict, andfirst_failureandfailure_countreport the lowest failing index and the number of failures. Indexes run 0 to 62,record_failurerefuses a bit another case already claimed, and the accumulated mask is monotonic, so two cases cannot silently share a bit and hide one another. The package's own conformance and examples modules now use the discipline they document. -
Add quote-aware field cursors to
std.data.csv:field_endstops at the first comma outside quotes,field_startopens the next field,field_is_quotedreports the quoted form, andcontent_startandcontent_endbound a field's content excluding its surrounding quotes. A""inside a quoted field is one escaped quote that never ends the field and stays in the content bytes, so decoding remains the caller's step. Empty records, empty quoted fields and consecutive commas yield exact offsets, and a walk terminates because the last field'sfield_startis the record length. The offsets compose with thestd.io.linesrecord content and thestd.bytestrimming offsets, and the package conformance adds acursorsbit to its failure mask on the interpreter, native C11-O0/-O2and Core Wasm. Typed fields, decoded content, dialects, streaming and writing remain Missing. -
Add explicit level filtering to
std.logunder the existing Log Writer v1 contract:level_enabledcompares a level against a threshold on the existing 0-5 scale,event_admittedis the borrowed observer that is true only when the event both passes the threshold and fits the writer's live capacity,discard_eventis the named drop path that consumes the event and returns the Writer untouched, andappend_event_ifwrites a passing event exactly asappend_eventdoes. Capacity is required only for an event that is actually written, so a small buffer with a high threshold is a valid composition rather than a contract failure, and a filtered event releases its name and message bytes through ordinary lexical cleanup instead of being buffered. Three named cases join the logger corpus as individual bounded projects on the interpreter, native C11-O0/-O2and repeated Core Wasm. No sink, queue, timestamp source, redaction or concurrency is added. -
Add span cursors to
std.bytes:is_space,trim_start,trim_endandis_blankfor ASCII whitespace, andfield_end,field_startandfield_countfor delimiter-separated fields. Field walking preserves empty fields, soa,,bis three fields and a trailing delimiter opens one final empty field, and every operation is a borrowed-view offset computation with no allocation and no copy. The offsets compose directly with thestd.io.linesline content, so a bounded caller can walk a delimited record and trim each field without a buffer. Whitespace is exactly space, tab, carriage return and line feed; no Unicode whitespace class, quoting or escaping policy is implied. -
Add field padding to
std.formatunder the existing Format Writer v1 contract:pad_lenis the field width actually written (never narrower than the content),append_fillwrites one repeated byte,append_str_leftwrites left-aligned text andappend_usize_rightright-aligned decimals. Each padded operation preflights the whole field rather than only its content, so a buffer that could hold the content but not its padding fails before any byte is written, and content longer than the field is written in full rather than truncated. Five named cases join the existing corpus as individual bounded projects on the interpreter, native C11-O0/-O2and repeated Core Wasm, and four further short or forged-output cases reject padded writes with the exactrequires-false status. Alignment is byte alignment and the fill byte carries no character or locale policy; general format strings, arbitrary alignment modes, grouping separators and floating-point rendering remain Missing. -
Add the bundled
std.path.normalizepackage, Path Normalization v1: lexical normalization of the typedPathvaluesstd.path.valueowns.normalized_lenandnormalized_bytegive the exact normalized length and each byte of a borrowed view with no buffer, andinto(borrow Path, own Bytes) -> Pathwrites the normalized form into caller-supplied capacity after an exact preflight while preserving the borrowed input. A separator run collapses,.vanishes,..cancels the nearest retained segment, an uncancelled..is kept for a relative path and dropped at an absolute root, a trailing separator is removed, and an empty result is.or/, so a normalized Path is never zero bytes. Retention is decided without a stack, as the clamped maximum prefix sum of a forward walk that scores..as+1and an ordinary segment as-1. Ten named cases run as individual bounded projects on the interpreter, native C11-O0/-O2and repeated Core Wasm, with hostile cases rejecting a short buffer, a forged Path and out-of-range offsets, and a graph check replaying the projection and its per-shape cleanup-schema selection. No public export, descriptor, platform conversion or filesystem authority is added, andstd.path.valuestays byte-identical. -
Add the bundled
std.io.linespackage, IO Lines v1: bounded line processing over the unchangedstd.ioReader and Writer cursors.line_end,line_terminatedandline_content_lenobserve a borrowed byte view;reader_line_lenandreader_line_completeobserve a borrowed Reader;reader_line_intocopies one line's content into caller-supplied Writer capacity after an exact preflight;reader_next_lineis the consuming transition past the line and its terminator. One line feed terminates a line, whose content excludes that byte and one immediately preceding carriage return, so LF and CRLF inputs yield identical content and a bare carriage return stays content. Eight named cases run as individual bounded projects on the interpreter, native C11-O0/-O2and repeated Core Wasm, and nine hostile cases reject short capacity, forged cursors and out-of-range view offsets with the exactrequires-false status. A graph check pins the selected cleanup schema per shape: v5 for the copy and the record observers, v2 for the pure view helpers, with the caller's Writer as the copy's one owned parameter. No public export, descriptor, stream, standard stream or host authority is added, and existing cursor signatures, contracts and identities are unchanged. -
Add the private owned iterator payload profile for
Iter<Bytes>andIterStep<Bytes>. Prelude v8, Graph v45, and CleanupPlan v13 bind the exact detached-prefix item/rest transfer and preserve prior scalar iterator, vector, and cache bytes. Focused library, interpreter/native C11-O0/-O2, workspace, and Core Wasm checks pass, including graph/Prelude and cache replay, exact failure settlement, and malformed-provider output rejection. Hosted promotion, public generic iterator ABI, and broader iterator scope remain pending. Also close the omitted Graph v44 process-profile rejection in frozen evidence admission without changing serialized graph bytes. -
Extend
std.test.byteswith reusable named snapshot fixtures and Copy comparison results containing equality, lengths, and the relative first difference. Borrowed fixtures and Reader cursors remain unchanged, with no new allocation or filesystem authority. Focused source-package and bundled consumer cases pass locally across the interpreter, C11 O0/O2, and repeated Core Wasm, including invalid-cursor cleanup. -
Add authenticated Project-linked State migration and workspace typed binding. A single declared or explicitly imported migration function extends the checked role closure; additive migration root v3 binds its exact source association while legacy root v1/v2 bytes remain unchanged. Durable recovery reconstructs the closure without evaluating migration again, preserves cumulative usage, and skips destination initialization. Focused local linked migration, selection refusal, recovery, and workspace currentness cases pass.
-
Add the private
std.agentsource package and the linked Project lifecycle boundary. Task, Context, Observation, and Outcome records plus checked lifecycle and outcome helpers compose as ordinary source data; the linked path derives the Proposal schema from the retained Project closure and binds it to the additive typed iterative runtime while preserving the existing scalar/public package bytes and direct Runtime v2 binder. All six linked-role cases pass locally, and the four standard-library testing cases pass across interpreter, native C11-O0/-O2, and Core Wasm, including epoch boundary cases and the byte-assertion regression. Linked migration, native/Wasm Agent-stage execution, live providers, hosted support, and fullstd.agentcompletion remain open. -
Add the sibling private
std.test.bytesassertion package while preserving the existing scalarstd.testfacade and public descriptor. Exact slice and Reader-suffix comparisons, cursor validation, unchanged Reader positions, and failure-bit wrappers use the privateuseful-data.v2profile with no exports and exactstd.ioplusstd.testdependencies. Execution and invalid-cursor gates pass locally; richer fixtures, property tests, fuzzing, and snapshots remain open. -
Record the private
std.processbounded process slice. Example, conformance, and bundled-consumer commands pass locally on the interpreter, native C11-O0/-O2, and Core Wasm. Five focused physical Darwin provider cases also pass, covering the registered local provider path. Linux physical-provider, hosted, public, and broader process support remain open; this does not promote the full process profile. -
Record the nested record-match entry/result phase ownership fix. The named
nested_record_match_entry_and_result_phases_settle_across_enginesgate now passes interpreter, native, and Core Wasm success and postcondition-failure cases while preserving canonical cleanup vectors. -
Add the private
std.envenvironment snapshot package and Projectenvironment-io.v1composition. The bounded operation vocabulary, immutable UTF-8 snapshot constructor, capability checks, graph facts, package metadata, catalogs, and source links are in place. Four focused carrier cases cover empty, success, failure, and malformed Wasm paths; fourteen selected library checks cover the snapshot and environment admission surfaces, including the provider constructor on Node. The named gatesenvironment_manifest_is_canonical_and_authority_is_closedandenvironment_package_executes_all_functions_with_injected_snapshotpass: the two Project commands pass on the interpreter, native C11, and repeated Core Wasm, including the bundled consumer; five focused useful-data environment checks also pass. The package is local/private evidence only, with no hosted CI or public ABI claim. -
Add the private
std.logstructured JSON-lines Writer. Its ownedEventcarries level, sequence, name, and message fields; append preflights level, UTF-8, and complete caller-owned Writer capacity before emitting one exact line. It composes bundled JSON UTF-8, JSON writing, and IO helpers without hidden allocation or ambient effects. The canonical package and fifteen expanded fixtures pass on interpreter, C11-O0/-O2, and repeated Core Wasm with exact zero-to-three live Bytes bounds. Nine invalid-event/output cases pass twice with exact contract status. A direct ASCII validation path keeps the 300-byte message within unchanged interpreter fuel; the existing UTF-8 package conformance passes on all three backends. Catalog, metadata, formatting, links, and module-size checks pass. Broader Everyday logging remains Partial; no public ABI or hosted support is promoted. -
Add the private
std.formatWriter append slice:append_str,append_i64,append_usize, andappend_boolpreflight exact caller-ownedstd.io.Writercapacity and return the advanced writer. Checked digit, decimal-byte, and length helpers supply deterministic output without hidden allocation or effects under the privateuseful-data.v2profile; the package has no public exports. Local verification now passes seven owned-function-import unit tests, including borrowed-strand ordinary owned-byte-record positives plus non-byte-record refusal; eight individually runnable named SPX tests pass on the interpreter, native C11-O0/-O2, and repeated Core Wasm with a strict two-entry byte arena (the pure helper case uses zero allocation). Five short/forged-output preflight cases pass twice with exactrequires-false status through the bundledstd.formatconsumer and transitivestd.io; metadata and catalog regeneration pass. Named tests run individually because the per-function static allocation limit is unchanged. General format strings and floating-point rendering remain outside this slice, with no hosted or production claim. -
Add allocation-free JSON cursor adapters:
decode_intoandquoted_intoconsume an ownedWriterafter exact capacity preflight while borrowing aReader, andcount_intorenders ausizevalue into that writer. The additive Project v16useful-data.v2profile keeps private owned cursor composition separate from the frozen Useful Data v1 byte-export boundary. Legacy byte-only consumers retain their public boundary while unused newer dependency members stay outside the linked program. The standalone decoder/writer corpus passes on the interpreter, native C11-O0/-O2, and repeated Core Wasm, including a 300-byte decoded input; six malformed-input, insufficient-capacity, and forged-cursor contract-rejection cases pass. The named Project v16 gateprofile_admission::project_v16_json_cursor_public_facade_replays_and_executespasses deterministic npm reconstruction, replay, and Node execution. The named cross-package gateprivate_json_cursor_roundtrip_executes_across_project_backendspasses the local interpreter entry and repeated test, native C11-O0/-O2, and repeated Core Wasm with a strict two-entry arena under the unchanged 16 MiB budget. These are local observations and do not claim hosted or public support. -
Refine workspace build-memory prebounds using bounded dependency identities and proven AST storage facts. Earlier successful budget receipts and fixed limits remain unchanged; a refused production build may retry once with the tighter bound after discarding its partial core and staged cache entries. Explicit smaller limits and nested budgets keep their original single-attempt behavior. JSON conformance scratch directories now remain distinct when decoder and writer checks run concurrently.
-
Extend private
std.fswith typed metadata, canonical immediate directory listing, directory creation/removal, and atomic file replacement through explicit providers. Project v15 and Graph v42 preserve the v1 profiles. Typed commands run on the interpreter, C11 O0/O2 and Core Wasm; malformed directory results fail before owned publication. Unix providers retain a directory descriptor and use same-parent rename for atomic replacement, without a durability claim. Private owned-input calls can return checked Copy-only records such as FileInfo; public ABI boundaries stay unchanged. -
Add bounded filesystem reads and create-new writes through explicit providers, with source-authored
std.fscomposition of Path, Reader and Writer, bundled dependencies, Graph v41 replay, and the private Project v14 execution profile. Interpreter, C11 O0/O2 and Core Wasm cover typed operations, byte/operation limits, failure priority, repeated calls and owned-result cleanup. The Unix provider retains a directory descriptor and rejects symlink traversal; writes never overwrite and do not promise rollback of physical effects. Broader filesystem facilities and cross-platform promotion remain open. -
Add the source-authored
std.path.valueowned Path library with checked logical prefixes, lexical queries, consuming parent traversal and joins into caller-supplied buffers. Bundled dependency composition preserves the originalstd.pathbyte helpers and adds no filesystem authority or public nominal ABI. Shared-loan replay now authenticates completion of synchronous borrowed calls used directly as contract roots, preserving previously accepted plan bytes. -
Add source-authored
std.ioReader/Writer cursors over caller-owned Bytes, checked bounds, consuming transitions and bundled dependency use. Internal Project calls now compose explicit owned-record signatures, and empty-export owned-data libraries run in both manifest layouts without a public descriptor. Independent cleanup replay and interpreter/native/Wasm lanes retain result transfers before arm cleanup. Focused tests cover binary roundtrips, contract failures, borrowed-owner escape, forged identities and missing transfers; generated catalogs now include the record declarations. -
Preserve both immutable workspace generations through typed Agent migration, durable recovery and chained migration using additive provenance receipts. Recovery rechecks compiler-owned bindings and exact receipts; current-run paths refuse stale destinations before host or store work. Focused local tests cover recovered A→B→C chains, forged receipts, stale destinations and preserved terminal failures after checkpoint acknowledgement loss.
-
Bind acyclic, iterative, and typed Agent runtimes to exact immutable semantic service generations through additive workspace execution receipts. Replaying a receipt reselects compiler-owned state; current execution rejects drift before host calls while historical bindings retain their original generation. Join only actual producer evidence and preserve typed durable checkpoint replay. Twelve focused execution-root tests pass locally, including the new V1/V2/V3, forgery, refresh, and zero-host replay cases.
-
Complete private native-builder cleanup test visitors for the additive iterator renewal transitions; the private test target compiles locally.
-
Add private one/two-parameter generic iterator operations with ordered Copy substitutions, explicit argument permutation, and authored map/filter/fold. Conditional same-owner Vec updates inside consuming loops use additive CleanupPlan v12 reservation/renewal facts and Graph v40; ordinary loops keep v11/v39 semantics. Replay rejects missing renewal facts and schema downgrades. Native layout discovery now includes retained concrete function bodies. Focused local runtime and projection evidence is recorded in Generic Iterator Operations v1; public generic ABI and hosted promotion remain separate.
-
Separate cross-platform Rust build validation from focused runtime evidence in CI, retaining both as release blockers. Run the complete MSRV check once across its four test shards and remove two identical generic-lane test repetitions. Cache the pinned mdBook tool and upload the book only for Pages deployment. Hosted timing and platform validation remain pending.
-
Add private consuming
for owntraversal over scalar iterators, including generic callbacks and same-owner vector accumulation. The hidden Step protocol preserves exact loop ownership with additive CleanupPlan v11 and Graph v39. Fix native conditional owner materialization and Wasm borrowed remainder/aliased-move handling. Focused interpreter, C11 O0/O2, Core-Wasm, graph and ProgramRoot replay checks pass locally; hosted promotion is pending. -
Compose private generic iterator helpers with scalar callbacks and step reconstruction. Source and HIR retain scoped
Iter<T>/IterStep<T>ownership; existing Prelude v7, CleanupPlan v10, and Graph v38 remain authoritative. The eight-scalar runtime corpus passes interpreter, C11 O0/O2, and Core Wasm, including callback contract failure and repeated settlement. Graph and ProgramRoot reject forged instance/scoped identities and changed source. Public iterator ABI and consuming loops remain separate work. -
Repair the prior head's CI failures by consolidating Closure test visitors, keeping production iterator/prelude helpers before test modules, and completing closure/iterator documentation metadata and catalog entries.
-
Repair local-only iterator step construction across prelude selection, graph classification, cleanup case-state replay, backend runtime activation, and canonical owning matches. Add repeated cross-engine regressions for bound and direct
Doneconstructors; preserve legacy graph and prelude selection. Retain complete iterator declaration and cleanup facts in both workspace linkers, restore Box's frozen prelude slice, and verify ProgramRoot replay. -
Add the private Owning Iterators v1 implementation tranche for scalar
Iter<T>/IterStep<T>and consumingvec_into_iter/iter_next, with Prelude v7, CleanupPlan v10, Graph v38, and ProgramRoot binding. Local interpreter and C11 O0/O2 observations cover all eight scalar types, order, empty/exhaustion, early drop,Done/Yieldreconstruction, contracts, private returns, and forged native cursors. The same corpus passes Core Wasm with exact scope settlement; hosted promotion and the broader iterator, owning-payload, lazy-adapter, and public-ABI work remain pending. -
Repair Closure exhaustiveness in projection and semantic test traversals and native-builder mutable AST traversal, plus narrowly mechanical
-D warningshygiene exposed by the cancelled CI run. Hosted revalidation remains pending. -
Add scalar closure construction inside generic collection functions and bounded loops, with concrete instance identity remapping, independent scoped HIR validation, and source-only template body facts in Graph v37/ProgramRoot. Preserve per-iteration snapshots and collection settlement across interpreter, native C11, and Core Wasm; extend native Rust builder accounting while keeping its public callable boundary closed.
-
Add private scalar snapshot Closures v1: exact AST/HIR cache carriers, Graph v37 and SemanticProgram v5/ProgramRoot replay, and local interpreter, C11 O0/O2, and Core-Wasm evidence for snapshot timing and captured generic Vec map/filter/fold composition. Owning captures, public callable ABI, and hosted promotion remain pending.
-
Add private noncapturing Function Values v1 with checked declaration-identity references and indirect invocation, Graph v36 projection, and retained SemanticProgram v3 callable closures. Public ABI and hosted promotion remain outside this additive profile.
-
Add the private generic-collection callback profile for Function Values v2; focused collection execution and ownership checks remain pending.
-
Extend argument inference through nested omitted calls and generic callers, retaining scoped symbolic forwarding identities, independent bounded evidence, exact graph/root replay and ordinary evaluation-once ownership settlement.
-
Extend private generic argument inference to complete ordered vectors and bounded expression type evidence, with independent source/HIR derivation and unchanged concrete instance, ownership and cleanup admission.
-
Add durable Agent migration handoffs, trusted-store destination recovery and repeated revision chains with cumulative call, byte, stage and fuel accounting; preserve frozen operation checkpoint v2 bytes and bind additive migrated evidence to the handoff.
-
Add private
Vec<Bytes>push, replacement, reserve, clear and lexical cleanup across checked source/HIR, interpreter, C11 and Core Wasm. Mutations stage vector and payload owners together and fail before transfer; successful replacement drops the old payload once. Prelude v6 and explicit v2 host imports bind the new meaning, including graph and ProgramRoot replay. Scalar storage and prior prelude contracts remain frozen; focused local evidence is separate from hosted and public promotion. -
Add private owned
Box<Bytes>allocation and consuming extraction across source/HIR, interpreter, native C11 and Core Wasm. Prelude v5 binds the additive contract; v2 Wasm imports prevent a legacy scalar host from silently leaking the payload. Allocation refusal keeps the staged Bytes owner live until ordinary cleanup, independently replayed before lowering. Focused local probes cover success, contract failure, allocation refusal, repeated settlement and frozen scalar compatibility; hosted and public promotion remain pending. -
Added exact argument-directed generic inference at monomorphic call sites, preserving explicit concrete HIR instances and ownership transfer boundaries. Seven language checks, private ProgramRoot replay and all-eight-scalar runtime success/failure settlement pass locally.
-
Added consuming State migration from actual durable Suspend evidence into a differently rooted retained Agent, through a pure checked function replayed twice. Destination execution skips initialize, binds fresh authorizations and retains prior call, byte, stage and fuel charges, including failed migration fuel reservations. Focused unit and joined-runtime checks pass locally.
-
Fixed YAML interpretation of unquoted Rust test-prefix selectors in CI run steps; GitHub had rejected the workflow before creating jobs. Added focused inference and migration selectors. Hosted execution remains unobserved.
-
Added trusted-store checkpoints around each typed iterative effect, with persisted stage fuel reservations, intent/observation/transition generations, exact call and byte accounting, fresh-authorized recovery, and fail-closed uncertain delivery. Terminal failure survives a lost final store acknowledgement. Four execution and eight hostile decoder checks pass locally.
-
Added private authored generic variants with one owned Bytes case and all eight Copy substitutions, including owning match/branch/call composition. Native selected-case destructuring now precedes arm construction, with outgoing ownership transferred only after the result exists. The 18-profile runtime corpus passes on interpreter, native O0/O2 and Core Wasm. Exact private variant/collection signatures now survive HIR linking; attempted public owning results reach the unchanged Scalar Export Profile and reject with its SPX-W115 diagnostic instead of the earlier private-linker SPX-H006.
-
Added a deployed typed scalar operation registry with exact argument/result contracts, per-turn authorization, and call/byte ceilings. Direct Runtime v2 compiles retained Agent source into this iterative product and joins its actual execution to deployment, instance and evidence roots. Five registry checks and the three-turn/two-operation Runtime integration pass locally.
-
Added private generic Box/Vec functions over all eight Copy scalars, with exact source/HIR materialization, graph and ProgramRoot replay, and runtime success/failure settlement on interpreter, native O0/O2 and Core Wasm. Native intrinsic arguments now stage through the canonical transfer boundary; owned collection parameters reference their live cleanup slots. Interpreter report replay recognizes only the finite existing Box/Vec status tables.
-
Added bounded iterative Agent Step execution with fresh per-turn authorization, cancellation and budget ceilings, exact source-Agent binding, and immutable invocation-bound evidence. Joined roots associate retained ProgramRoot v1-v3, deployment, invocation and actual one-pass or iterative execution. Iterative execution obeys both deployed turn and call ceilings. Copy-only Observation results use a narrow retained-call extension. Focused local checks pass; typed multi-effect checkpoints and migration remain follow-on work.
-
Made the generated Proposal-client execution gate portable across Linux, macOS and Windows with exact UTF-8/LF output and provisioned TypeScript JS execution through Node. All three clients compile and execute locally on macOS; the added blocking CI matrix awaits exact-head hosted evidence.
-
Added structural nested generic record composition and multiple owning parameters, with explicit reconstruction into different nominal result types. Source and HIR validate substituted fields, recursive patterns and complete ownership; nested update construction and replay select cleanup v9 after concrete substitution. Native owning branches now emit their canonical join and staged-call transfers. Focused all-eight-scalar runtime corpora pass on interpreter, C11 O0/O2 and Core Wasm, including both branches, nested owner replacement, contract and second-argument failure, repeated execution, allocation settlement and no additional aggregate memory.copy.
-
Added explicit generic argument permutations, repetition and concrete substitutions with independent source/HIR proof, cycle rejection and the existing 256-instance closure bound. Additive Graph v35 binds symbolic caller-parameter/concrete mappings by authenticated expression paths; identity-only programs retain v34 bytes. ProgramRoot and bounded context expose the same mappings. Focused source, hostile graph, workspace replay and interpreter/native O0/O2/Core-Wasm checks pass.
-
Extended generic Result propagation to
Result<T, Bytes>for all eight Copy success types. Cleanup consumes the conditional owner without inventing a success cleanup slot; interpreter, native and Wasm preserve scalar Ok values and owned Err settlement. Forty focused cross-engine success/failure profiles pass, with forged empty-case flags and missing residual transitions rejected. -
Added generic
Result<Bytes, E>relay, explicit forwarding and postfix?for every Copy error scalar plusBytes. Independent HIR proofs validate unused substitutions without requiring a discovered call instance. Existing conditional cleanup handles empty scalar-error ownership paths; native residual return now preserves those scalar values before publishing the tag. Graph v34 and ProgramRoot bind concrete variant and residual facts across private function boundaries. Focused local runtime evidence covers 45 success/failure profiles on interpreter, C O0/O2 and Core-Wasm; public generic descriptors remain closed. This begins GEN-06, not the end of the full goal. -
Completed Graph-v34 type facts for concrete generic instance signatures and bodies, including template-only context selection. Frozen legacy graph collection remains unchanged. Added focused hosted compatibility selectors for existing Component byte known answers and closed public mappings.
-
Added Graph v34 concrete generic-instance ownership, revision-bound semantic identities, forwarding facts and exact source replay, with independently selected cleanup schemas preserving existing CleanupPlan bytes. An additive SemanticProgram v2 node binds linked generic closures into ProgramRoot; frozen graph consumers and public ABI descriptors retain their prior contracts. The independent
GEN-05B generic instance semantic closureLinux job combines the eight-scalar flat and nested corpus, graph/schema hostility, expression composition and scalar cross-package execution. Focused graph and workspace replay checks pass; the bounded GEN-05B/GEN-05C Linux tranche passed for implementation commitc27d06f0cf74749804237a43cc71c248b319cfe0in CI run 34058787739, job 101555489228. This documentation-only successor records that implementation result and does not claim a new test run, full-CI passage, or a public generic ABI. Semantic instance identities survive comment-only edits while ProgramRoot still binds exact source. Preserved existing workspace known answers and ownership/range diagnostics. -
Added a source-native Agent-to-Lifecycle v1 bridge and executable generated Proposal-client evidence. One checked
.spxAgent is selected by stable identity, lowered through the frozen AgentDefinition-v1 compiler, and bound to the existing one-pass lifecycle; replay now requires both exact lifecycle bytes and the semantic source revision, so role-body drift fails closed. Focused regressions cover completion, refusal, injected-effect failure, missing-Agent/incompatible-role cases, stale source, and fail-first oversized or malformed replay selectors. A named Linux step also materializes generated record and variant clients in isolated temporary projects, strict-compiles TypeScript 5.8.3, byte-compiles Python, builds Rust offline with a private target, executes all three, and submits their exact integer/UTF-8/case output through the canonical decoder. This changes no frozen Agent or Runtime wire and adds no provider, tool, filesystem, publication, or ambient authority. -
Extended Exact Program Context v2 with candidate-safe ProgramRoot-v3 refresh. A host-authenticated successor context is independently replayed against a separately compiler-admitted candidate Project; successor external facts are freshly supplied and replayed rather than implicitly copied from the current generation. The persistent service selects the active workspace/v3 root first, stages the complete candidate generation, cache, indexes, unchanged refresh-v1 receipt, and history entry, then adopts them together. Stale selectors, cross-paired facts, invalid source, or replay failure preserve the active generation and history; old snapshots remain exact. This adds no wire, filesystem acquisition, execution, commit, or publication authority.
0.4.0 — 2026-09-06
-
Added Universal Semantic Transaction v2 for one exact, authority-free
ReplaceExpressionover an authenticated revision-scoped body-expression identity, including explicit monomorphicmain. Validation rebuilds the complete Project Candidate, preserves exact source bytes outside the selected span, and emits deterministic separately versioned result/evidence. The persistent service adds ordinary and ProgramRoot-v2/v3 validation/replay, with exact selection before parsing/history and no replay history append;change preview ... replace-expressionreturns exact core output or the Candidate structural diff without writes. V1 transaction and CLI bytes are unchanged; contract/implicit/generic/synthetic/imported editing, composition, commit, publication, and authority remain unavailable. -
Added the product/package contract for Owned Bounded Box v1 and the alloc-tier
std.mempackage. Compiler-ownedBox<T>is limited to the eight explicit Copy scalars withnew, synchronousget, consuminginto_inner, one unique non-Copy owner, a 4,096-live-allocation bound, and sticky allocation refusal. Additive prelude v4 is Box-selected while v1-v3 and authored inlinerecord Box<T>programs remain frozen.std.memcontains exactly three authenticated aliases, explicit 3-by-8 conformance, scalar-only example/test results, and no public exports. Focused local package, catalog, interpreter, native C11, Core-Wasm, cleanup-replay, and hostile-carrier evidence passes; contract-failure cleanup, owned payloads, allocator interfaces, public generic ABI, regions, arenas, ARC/shared ownership, Iterator integration, hosted evidence, and production support remain open. -
Specified Owned Bounded Vec For Traversal v1: the source form
for item in values { body }accepts one simple immutableVec<T>binding over the existing eight Copy scalars, snapshots its length once, visits indices in ascending order, freezes the source, and discards each body result. Resolver lowering reuses the existing len/get/while HIR, so this adds no stable identity, schema, prelude or backend operation, standard-library declaration, or public ABI. Focused local language and all-engine runtime selectors pass; hosted evidence remains required before promotion. The lowering has no origin marker, so ordinary HIR-node validation applies instead of a traversal-specific canonical-shape rule. This is not Iterator support: objects,next, adapters, closures, associated types, lifetime inference, consuming traversal, owned elements, andstd.iterremain open. -
Added bounded acyclic generic-to-generic forwarding between already-admitted templates. A direct call must pass the callee exactly the caller-owned type- parameter vector in declaration order; each concrete caller instance derives the deterministic transitive callee-instance closure, bounded at 256 entries. The existing direct-scalar and one-owner-identical-result relay profiles, Graph v14, and CleanupPlan v2/v5/v7 remain the limits. Focused evidence covers chained source/HIR identities in authored FIFO order, interpreter/native C11
-O0/-O2/Core-Wasm settlement, concrete non-identity/permutation/cycle rejection, and missing/reordered/forged HIR instance rejection. This adds no inference, constraints, construction, projection, variants, resources, effects, package signature, or public generic ABI. -
Added the exact flat generic owned-record expression-composition tranche. One owning parameter returns the identical record while all eight explicit Copy substitutions exercise Copy-field projection, top-level immutable update,
match borrowreturning a bound Copy field, andmatch ownreconstructing the same owner. Focused local evidence covers update and reconstruction failure settlement, hostile HIR/backend mutation replay, repeated interpreter, native C11-O0/-O2, and Core-Wasm execution, and no added aggregatememory.copyagainst the direct-relay baseline. Generic variants, nested expression-result composition, standalone constructors, consuming projections, public generic ABI, and Graph/schema widening remain closed or unclaimed. -
Added a dedicated Linux CI step for the additive nested generic-owned relay and identity-forwarding tranche. It names the exact source/HIR boundary, transitive-instance hostility, all-engine settlement, and scalar-only Project dependency selectors, and removes their duplicate invocations from the adjacent generic-owned step. New locally passing hostility regressions cover all eight Copy scalars through a three-template nested relay, forged HIR carrier and cleanup vectors, source vector changes and cycles, and the exact 256/+1 instance-closure bound. The named step is hosted green in CI run 34048713967, Ubuntu job 101528399406; the older run 34031917437 remains the evidence for the pre-nested-relay corpus.
-
Re-derived the offline doctor carrier ceiling from measured distributions.
DOCTOR_OFFLINE_INPUT_MAX_BYTESwas 536,870,912 bytes, and on a hostedubuntu-24.04runner the loader closures of Node v22.23.2 and Rust 1.88.0 alone encode to 462,424,370 of them, 86% of the ceiling, leaving 74,446,542 bytes for a whole Clang role. No official LLVM release that runs on 24.04 is that small: clang 9.0.1 reaches a 568,339,434-byte carrier, 14.0.0 reaches 618,411,514 and 17.0.6 reaches 652,142,493, and Ubuntu's own clang-18 closure is about 713,000,000. Sincerender_rowsadmits only Node 22 or newer and Rust 1.88 or newer, the two non-Clang roles cannot shrink, so the two real-distribution lifecycle fixtures could not be satisfied by any current real distribution set. The ceiling is now 1,073,741,824 bytes: 1.65 times the measured clang-17 three-role carrier, 1.51 times Ubuntu's clang-18 closure, and still 6.25% of a hosted runner's 16 GB. It stays a hard bound and remains a resource bound rather than an authority boundary, since seals, digests, the release signature, the ELF contract and the closed inventory decide admission and none of them depend on size. The delegated cgroup-v2 scope'smemory.maxmoves with it, from 2 GiB to 4 GiB, and is now derived rather than coincidental: an admitted carrier of N bytes costs 2N of unswappable residency inside that scope -- the worker's whole-carrier snapshot, which the root plan borrows and so cannot release before the tool children run, plus the page-rounded tmpfs root written out of it -- whilememory.swap.maxis 0 andmemory.oom.groupis 1, so an overshoot kills the whole scope instead of refusing cleanly. The signed capsule'sMAX_ARTIFACT_BYTES, the release directory'sMAX_ARTIFACT_BYTESand the signed store'sMAX_FILE_BYTESare held equal to the new ceiling because they bound the same bundle and request bytes and the smallest of them is always the effective limit. The derivation is recorded beside the constant and in Doctor Sealed Input v1. -
Fixed the offline doctor collector retaining its whole-carrier snapshot across the blocking collect. Every fact the collector keeps is already an owned copy by that point, and the launcher and provisioner both release theirs before creating a child, so the omission left three whole carriers resident in the confined scope at once instead of two.
-
Fixed the provisioned Linux doctor gate failing before any lifecycle fixture ran, with
input permissions or link count are unsafe. Cargo uplifts each binary out ofdeps/as a hard link, so the artifact in the target root has link count 2, andsemaprax-doctor-releaserefuses an input a second name can still reach. The workflow now copies the four images to private single-link files and asserts the link count; the packager's check is unchanged. The gate also carries all three real roles again, which the re-derived ceiling admits. -
Added
std.data.json.dec, the seventh JSON sibling package, which expands JSON string escapes. All eight simple escapes,\uXXXX, and surrogate pairs decode to their exact UTF-8 bytes; a lone or unpaired surrogate, an unknown escape letter, a raw control byte, and an unterminated string are rejected at the offset of the backslash or byte that opened them, in the family'susizeresult encoding.decoded_len/decoded_sizesize the output,token_end/emit_len/emit_atstream the decoded bytes with no allocation, anddecoded_eqfills one owned bounded byte buffer of a fixed 256-byte capacity through the loop-carried same-owner replacement and compares it to a caller-supplied view. The conformance module runs on the interpreter, clang C11-O0/-O2, and Core Wasm, where the standard-library closure now supplies theenv.spx_bytes_zeroed/env.spx_bytes_sethost-arena imports and asserts that the package's module reaches them, that the arena holds at most one live entry, and that it is empty after each of four re-entries. Three admission facts were measured rather than assumed and are recorded in the specifications:owned-data-api.v1is the only project profile that admits both a borrowed byte view and the buffer, the buffer must stay out of the entry program because a public web build containing it isSPX-W115, and aBytesvalue does not cross a module boundary (SPX-G172), so a caller-provided output buffer is not expressible. The package is committed at 17,620 B against a measured 18,480 B admitted / 18,653 B firstSPX-G171;decoded_atanddecoded_samewere written, measured over that bound, and cut. -
Added the bounded ScalarV1 internal flat generic-owned body path. Admission is based on the exact reachable ResolvedProgram rather than source or dependency provenance; callable and selected-public signatures remain value-scalar. One exact project-local Subject-v3 dependency provides cross-package evidence by retaining the concrete generic owned-byte record composition internally while exposing exactly one no-argument
i64function. Focused local evidence covers exact Report-v2/Subject-v3 resolution, linked-HIR identity and cleanup, Project check and repeated entry/test, native C11-O0/-O2, Core-Wasm, the unchanged scalar Web build,SPX-W115public-selection escape andSPX-J123dependency tamper. This evidence is unhosted. Manifest, report, Project, public descriptor, Wasm and package-evidence schemas remain frozen; no generic record, owner or aggregate signature crosses a call, package or public boundary, and no acquisition, publication or production support follows. -
Extended the bounded concrete generic owned-record relay from its flat carrier to any acyclic authored-record template tree within the existing 64-level, 256-owned-leaf, and 4,096-field work limits. Each template has one
ownparameter and an identical return type, requires explicit Copy-scalar arguments, and preserves exact template/instance identity and recursive ownership through source verification and independent HIR validation. Focused local evidence exercisesBox<Pair<Bytes, T>>andPair<Box<Bytes>, T>across all eight scalars in source/HIR, including representative source and forged-HIR rejection. The representativebool/i64runtime instances cover success plus requires/ensures/staged-call failure settlement on the interpreter, native C11-O0/-O2, and Core-Wasm. Graph v14 and CleanupPlan v7 remain unchanged. The pre-nested-relay generic-owned corpus is hosted green in CI run 34031917437, Ubuntu job 101482963175; this additive nested-relay evidence remains local until its own pushed run. Nested-nonflat multiple-owner or non-identical-return composition, Project/package/public ABI exposure, and production support remain closed; the legacy flat generic-function admission is unchanged. -
Admitted the loop-carried owned byte buffer fill.
bytes_setgains one same-owner replacement shape,buffer = bytes_set(buffer, index, value), whose assignment target and buffer operand are the samelet mutbinding: the call moves the single owner out and the assignment publishes the returned owner back, so exactly one generation is live at every point. It is the onlybytes_seta boundedwhilebody admits, so a loop can fill a buffer it did not allocate;bytes_zeroedstays outside the loop and is still rejected there by both the byte-family rule (SPX-T252) and the owned byte allocation rule (SPX-T267). Every other named buffer operand remainsSPX-T271, a borrowed view live across the replacement remainsSPX-T265, and independent HIR validation re-derives the same fact so hostile HIR that swaps two replacements' targets fails closed withSPX-H006. The fill and a store one element past the capacity execute on the reference interpreter, native C11, and Core Wasm under Node against a one-entry owned-byte arena across four re-entries with no linear-memory copy or growth, and the out-of-range store selects the identicalsemaprax.byte-buffer.v1code 1 status on all three engines before the owner transfer commits. Capacity growth stays out of scope: the allocation capacity is still a literal. -
Added the bounded AGENT-04 generated Proposal-to-Runtime v1 compatibility adapter. One exact checked Proposal record or Copy-scalar variant now passes the existing decoder before its complete canonical bytes, including the terminal LF, become the escaped message of the frozen Runtime v1 final action. The adapter performs no case or field translation, reaches no host, and cannot select a Runtime tool;
SPX-G578rejects cross-pair and complete escaped-action-bound failures while ProposalSPX-G550/SPX-G551remain unchanged. AgentDefinition, AgentGraph, Proposal Schema, and every Runtime v1 schema, API, digest and known answer remain frozen. Direct provider Proposal input, Runtime tool-action/schema generation, broader Proposal, public ABI, and Runtime v2 support remain open. -
Added authority-free Exact Program Context v2, which independently replays exact context v1, Contracts and Tests Facts v1, and ProgramRoot v3 before requiring the enriched workspace and v3-root selectors across typed query, transaction, service, and history paths. The same appended facts descriptor is retained in memory; query/result, transaction/evidence, history, service receipt, exact-context-v1, and ProgramRoot wires remain unchanged. Exact transaction history keeps the authenticated default base workspace identity, selector and replay failures append nothing, and exact service refresh plus candidate ProgramRoot v3 remain unavailable.
-
Added the authority-free Contracts and Tests Facts v1 association and ProgramRoot v3. The standalone fact bundle binds one admitted Project, semantic Graph, and legacy workspace revision to stable-ID-sorted function and function-template rows with ordered checked
requires/ensuresfacts, plus only the declared testmainand ordinary executable named tests. Its closed document explicitly denies coverage, execution, result, and source authority claims. ProgramRoot v3 freshly retains all eleven ProgramRoot-v2 descriptors and three unbound relationships, then appends only the fact schema/digest/byte-count descriptor. Canonical Semantic Workspace v1 and ProgramRoot v1/v2 identities and bytes remain unchanged. This is inventory and association only: contract proof, coverage, test execution, runtime roots and authority remain absent; the separate Exact Program Context v2 entry above records the later typed selector integration. -
Extended the additive Exact Program Context v1 lifecycle through exact query replay, transaction replay, and persistent-service history selection. Every exact route requires both the enriched workspace revision and ProgramRoot-v2 digest, retains the selected
ProgramRootV2only on typed in-memory results, and fails closed on stale, reminted, cross-paired, or mutated inputs. Exact transaction history records the authenticated default Project-derived base workspace identity; read-only replay appends no entry. Universal Semantic Query v1, Universal Semantic Transaction v1, service-history v1, receipt, ProgramRoot v1/v2, canonical-workspace v1, and other legacy wire bytes remain unchanged. Candidate ProgramRoot-v2 derivation and exact refresh remain unavailable pending candidate-safe Project Lock replay. -
Corrected the cleanup-plan storage ownership rule so the Owned Bounded Vec v1 loop-carried fill is reachable from source, and added
examples/vector-stats-project, the first example that accumulates a variable number of scalar values and filters them. A storage now belongs to the cleanup region that first introduced it. It was previously re-homed into whichever region asked for it second, sovalues = vec_push<T>(values, value)inside a boundedwhilemoved the enclosing binding's slot into the loop body's own region: the body's scope exit finalized the vector on every iteration, one linearized body pass no longer preserved owned liveness, and every such program fail-closed withSPX-H006even though source verification, HIR validation and independent cleanup replay all admitted it. The example initializes oneVec<i64>outside a bounded loop whose body pushes a computed number of readings, then walks it back throughvec_lenandvec_getsumming only the readings over a threshold. Its gate drives the accumulating function at seven element counts and three thresholds and runs both the entry and the conformance module on the interpreter, native C11 at-O0and-O2, and Core Wasm under Node against a one-generation host arena; the owned-data harness carries the same shape as a focused language regression. -
Admitted a computed
usizeelement index for the Owned Bounded Byte Buffer v1bytes_setstore, so a value can be written at an offset a scan discovers. The allocation capacity is still one literal at thebytes_zeroedsite (SPX-T271), and a literal index at or above that capacity, or any index into an empty buffer, staysSPX-T272; only what the compiler cannot decide moved to run time.bytes_settherefore became the first fallible compiler-owned byte operation: it carries an ordinaryPropagatedCallstatus source whose failure is selected before the owner transfer commits, so an out-of-range store writes nothing, is not a backend accident, and leaves the buffer in the canonical call-argument slot that the exit's singlecore.bytes.dropfinalizer already owns. Independent replay re-derives the same ordering. The reference interpreter, native C11 through the newspx_bytes_set_check_v1, and internal Core-Wasm through a generated comparison against the carrier's byte length all select the identicalsemaprax.byte-buffer.v1code 1 adapter status; the Web wrapper reserves internal value 16 for it. The deferred-owner-commit decision the bounded Vec lane introduced forvec_pushnow lives in onecleanup_plan::deferred_commitmodule that both operations share. The Core-Wasm host import keeps its own gate, now unreachable from admitted source. Local focused evidence covers a computed in-range fill and a computed out-of-range store on all three engines, including a one-entry Core-Wasm arena that still balances across four failing invocations. Elements wider than one byte, a loop-driven fill, a computed capacity, and a public FFI layout stay open and unclaimed. -
Restored the cross-platform CI gates after the owned algebra expansion by refreshing the checked Core-Wasm, component, artifact-DAG, browser project graph, and macOS provider symbol KATs; aligning Project admission regressions with the newly supported generic and byte-bearing shapes; and keeping the POSIX native network fixtures Unix-only. The TCP deadline regression now constrains the client send buffer so it cannot spuriously complete before the peer-side timeout is exercised, and newly enabled strict Clippy lints are clean.
-
Executed the VS Code Extension Host execution evidence v2 gate for the first time, on exact subject
3fccd30b861d48c9d404eb2698fa2eff510569afin a locally provisioned Visual Studio Code 1.136.1 on Darwin arm64 with Node v24.3.0. The 97 standalone controller cases and the single Extension Host scenario passed, producing bundle29660fc88dac4d3bd11098f7facfe1bd05fda23b378d519d9590f028a3fdc7dd, whose envelope and four artifacts are archived underdocs/evidence/. The run found two defects the mock-backed suites could not:runCandidateTestsandsuggestHoleFillawaited non-modal notifications that resolve only when a human dismisses the toast, hanging the command and holding the busy latch; and the host assertion for a cleared diagnostic expectedundefinedfromDiagnosticCollection.get, which the real host never returns for an absent URI. Those commands now fire the notices without awaiting, and absence is observed throughhas. This is one local product on one platform; VSIX or Marketplace packaging, manual UI, accessibility, minimum-version, remote, hosted and cross-platform evidence remain open, and the run covers its exact subject rather than any later head. -
Added internal Owned Bounded Vec v1 across source, HIR, Graph, cleanup-plan replay, the interpreter, native C11, and Core Wasm.
Vec<T>and eight explicit generic intrinsics admit exactly the eight Copy scalars, anyusizecapacity expression with a hard runtime maximum of 8192 and sticky code 3 on dynamic overflow/allocation failure, consuming push, deterministic exact reserve, indexed set, capacity-retaining clear, borrowed length/capacity/get, exact same-owner reopening, and deterministic settlement on all three engines. Reserve usesmax(old_capacity, len + additional), set reuses bounds status code 2, and all three new mutators consume and return the one owner. Additive compiler prelude v3 is selected only when one of those operations is used; frozen prelude v1/v2 contract bytes remain unchanged, and collision-free legacy Vec programs keep selecting their prior bindings. The three new intrinsic names and core identities are now reserved language vocabulary. The alloc-tierstd.collectionspackage now authors the exact eight authenticated aliases, an explicit eight-scalar conformance module, bundled dependency metadata, generated catalogs, focused local Project/package evidence, and no public exports. Owned/aggregate elements, inference, iterators, public generic ABI, hosted support, and broader collections remain closed. -
Admitted the exact internal Owned Bounded Byte Buffer v1 write-once profile on Core-Wasm. The frozen host-arena imports allocate a literal-bounded zeroed
Bytesvalue and mutate the same opaque token at literal indices; focused local Node evidence covers deterministic valid modules, three writes and reads, repeated success and contract-failure settlement/re-entry at one live arena entry, and absence ofmemory.copyandmemory.grow. Source/HIR and cleanup hostiles preserve exact capacity, callee, transfer and call-commit authority. The public byte adapter remains rejected withSPX-W115; this adds no loops, growth, wider elements, Project/public ABI,std.*, browser, hosted, or cross-platform support. -
Added one exact cross-file Project product gate for an internal concrete generic owned record. The retained Project keeps
Pair<Bytes, bool>inside its linked closure while its frozen v8 descriptor remains scalar-only; the gate repeatedly executes Project entry and test functions, generated native C11 at-O0/-O2, and an external Node consumer calling the generated npm/Core-Wasm scalar API for empty and nonempty inputs. This does not expose a generic record, widen v8/v9/v11, or add a public generic ABI or Project v14. -
Added
agent_lifecycle::durable, the Agent Checkpoint v1 revision-bound durable slice over Agent Lifecycle v1.bind_durable_agentanchors one checked module, one AgentDeployment v1 bound product and one caller-supplied policy epoch, and every checkpoint generation binds nine recomputed facts - the policy epoch, the semantic definition, deployment and bound-product digests, the State role identity, the proposal-grammar digest, the lifecycle digest, the exact module source digest and the caller's task digest - so definition, deployment, source or state-schema drift and a revoked epoch each reject a stale checkpoint by its own reason, re-running no stage and writing no generation. A durable run splits the lifecycle at its single external boundary: it commits an intent before crossing it and a settled observation after it, so a crash between the two leaves delivery uncertain. An uncertain operation is never retried automatically - it ends in a terminalunknownstate, or the host reconciles it with a settled observation or an abandonment - and a read that reports failure is treated as uncertain too, because a reported failure is not evidence of non-occurrence. Neither budget ledger is refunded: the effect grant is consumed at the intent whatever the operation's fate, and re-executing the deterministic prefix on a resume spends interpreter fuel from the same remaining total. -
A resumed run cannot forge an authorization. A checkpoint carries no
Authorized, no grant seal and no state carrier, only digests, and there is no decoder from checkpoint bytes back to a retained value; a resume recomputes the state from the caller's task and mints a fresh grant through the crate's single mint site before comparing the derived operation identity against the journal. Checkpoint bytes are self-verifying - closed key set, strictly advancing journal ranks, recomputed chain link, program counter agreeing with the journal, and exact canonical re-rendering - so a partially written generation fails closed withSPX-G573rather than being adopted, and atomicity itself stays the caller'sCheckpointStorecontract. Caller inputs are retained as digests only; the settled observation is the sole retained external datum, andRetention::ObservationDigestOnlyredacts that too. The checkpoint is deliberately unauthenticated and republishes that dependence in its own nonclaims, alongside the standing provider-billing and external-exactly-once nonclaims. Theagent_runtime_v1harness gainsagent_checkpoint_v1covering crash injection at all five boundaries with their recoveries and total boundary-crossing counts, the drift and caller-input rejections, seven malformed-document rejections, the redaction sentinels, and an atomic write-and-rename store against a contract-violating torn one; the crate-internal gate additionally proves that an internally consistent rechained journal forgery still mints nothing. No CLI surface was added:semaprax agentstill refusesresumeandreconcile. -
Added
agent_lifecycle, the Agent Lifecycle v1 compiler and runner: it binds an AgentDefinition's four deterministic operation identities -initialize,observe,authorize,reduce- to actual verified.spxfunctions in the same HIR ordinary execution uses, and executes one acyclic lifecycle over them throughinterpreter::retained_call. Binding validates each stage's parameter count, parameter ownership modes against the AgentGraph v1 relationships, declared effects, role types, the derived two-case grant/refusal decision variant, and the acyclic and uniquely ordered stage graph, and it rejects an unresolved identity, an incompatible signature, an incorrect ownership mode, a declared effect on a deterministic stage, an unadmitted proposal field representation, and an unadmitted decision shape with anSPX-G570diagnostic naming the exact failing field - all before any host work is reachable. The authorizing transition mintsAuthorized, an opaque one-use value bound to the exact lifecycle policy digest, the identity-keyed encoding of the state carrier, the exact proposal document bytes, the grant case identity, and the seal the program itself constructed. Its fields are private to one module, it derives nothing and has no public constructor, it is consumed by move at the effect boundary, and the crate's single mint site is reachable only from the function that runs the validated authorize stage - which requires anAuthorizeStageonly the stage binder builds, requires the retained product to name that exact validated function, and mints only on the validated grant case. A proposal, an observation and a reduction therefore have no route to one. Spending an authorization independently recomputes its binding from the state and proposal presented, so a substituted state or proposal isSPX-G571before the injected read operation is called.proposeis a scripted offline document admitted only through Proposal Schema v1, andexecuteis one explicitly injectedAgentReadOperationand nothing else. The six terminal conditions -completed,rejected,model_failed,effect_failed,cancelled,budget_exhausted- each produce a canonicalsemaprax.agent-lifecycle-evidence.v1document carrying identities, outcomes and cleanup-event counts but no payload bytes, byte-identical on replay. Stage values stay inside the retained seam's closed vocabulary, sostringcannot cross a stage boundary and the Proposal role crosses as its exact ordered scalar projection instead. The frozen AgentDefinition, AgentGraph and Runtime v1 profile digests are re-asserted unchanged;AgentDefinitiongains two additive read-only accessors and no other change. IterativeAgentStepexecution, typed language effects beyond the injected read, durable checkpoint/resume, and a CLI surface remain Missing. -
Re-derived the
SPX-G171identity term. The builder pre-bound charged every declaration identity slot the longest identity in scope times 64, a factor whose enumeration of retained resolver structures overlapped the occurrences the slot count already enumerates, so each slot was billed for the whole resolver twice. Measured with a counting global allocator around the core build, lengthening every identity in a package by one byte raises the heap that build retains by 0.87 to 1.11 bytes per identity slot (std.test460 over 416 slots,std.core1,378 over 1,385,std.bytes2,080 over 2,378,std.data.json.token2,409 over 2,755), so the factor is now 16: eight retained structures, each able to hold the identity as a map key and as a value. The structural factor stays 24 against a measured 3.8, because the sixteen it is built from is a compile-time bundle assertion rather than an estimate, and the string factor stays 64 because that term is 1.2% to 2.5% of the estimate. Padding the sixstd.data.json.*packages untilSPX-G171fires now admits 19.7 KB to 22.1 KB of total package source where the same measurement gave 12.3 KB to 14.2 KB, sostd.data.json.dochas headroom again. Nothing about the retained-memory bound is relaxed: the pre-bound and the structures the core build actually retains are reserved against the same 16 MiB budget and either overflow is stillSPX-G171. Whole-document KATs that embedused_builder_byteswere re-pinned; rendering the same workspace document under both factors and diffing it field by field showsused_builder_bytesand the digest over it as the only changes. Standard Library v1 also records two limits that were written down nowhere:matchis not admitted in awhilebody (SPX-T252) outside a two-armOptionmatch onbyte_get, and replay path counts multiply across sequential statements while only summing acrossmatcharms, so packing small tables into one function can tripSPX-H006where splitting them does not. -
Added
interpreter::retained_call, the retained multi-argument call seam Reference Interpreter v1 was missing:prepare_resolved_zero_arg_i64is zero-argument and additionally requiresentry_id == program.entrypoint, so it can run onlymain;interpretre-reads and re-verifies source on every call;ArgumentValueis scalar-only; andevaluate_resolved_owned_datais restricted to a borrowedSlice<u8>entry with bytes-shaped results.prepare_retained_calladmits ONE explicitly identified function - the entrypoint or any other - through the interpreter's own admitted-function map and closure scan, restricts its signature to a closed value vocabulary, and retains the authority-free dispatch index;evaluate_retained_callthen invokes that product repeatedly, reading no source, re-resolving nothing, and re-running neitherhir::validatenor the closure scan, re-checking only that the retained vector positions still name the same identities and that the admitted signature is unchanged. Arguments and results are the monomorphic scalar record/variant subset of Agent Proposal Schema v1 the interpreter actually executes:bool,i32,i64,u8,usize, ownedBytes, and bounded acyclic records, classes, and owned-byte variants over exactly those leaves;string,char,f32,f64, borrowed carriers, and generic shapes fail closed with a locatedSPX-F102diagnostic in the existing closed reason vocabulary rather than widening the cleanup shape the shared machinery and the native and Wasm backends own. Execution enters through the same evaluator call frame, a staged ownedBytesargument is charged against the same verified byte-data capacity abytes_copyconsumes, a Copy carrier is harvested by reference while an owned one must be uniquely held, and result leaves settle in declared field order without being sorted or repaired. The frozen zero-argument entrypoint product keeps its exact admission and known answers; both products now share one owner for the retained dispatch index.stringfields, admitted by the proposal schema but by no interpreter record or variant classifier, remain Missing here. -
Added
std.data.json.doc, the structural document layer of the bounded JSON slice: the object and array grammar driven by six modes over a base-2 container stack held in onei64, an explicitdepth_limitclamped to 32 open containers and rejected at the offset of the container that exceeds it, a closer that does not match the innermost container rejected at its own offset, and trailing-byte rejection that reports the first trailing non-whitespace byte.document_endscans one value,whole_endrequires only whitespace after it, andis_documentis the whole-input form; the RFC 8259 number grammar, the exacttrue/false/nullwords, and string framing that rejects raw0x00-0x1Fand an unterminated string are scanned in the same pass, allocation-free, returning only scalars in the family's end-offset/rejection encoding. Escape-character and surrogate validity stay withstd.data.json, raw UTF-8 withstd.data.json.utf8, and duplicate keys are accepted rather than rejected - all three stated in Bounded JSON Scanner v1 rather than left to inference, because theSPX-G171pre-bound admits 12,216 B of this package's source and rejects 12,292 B. The package deliberately depends on nothing: a[dependencies]edge onstd.data.jsonalone puts it over that bound, since vendored dependency source is charged in full against the consumer. -
Extended the bounded JSON slice from one package to five sibling packages, because the Workspace Semantic Graph pre-bound is charged against a whole package - library, examples, and conformance modules - and no single library module can hold the slice.
std.data.json.tokenadds the RFC 8259 number grammar as composable integer, fraction, and exponent scanners,true,false, andnullrecognition, and exacti64decoding that refuses overflow and refuses a fraction or exponent rather than rounding it, so-9223372036854775808decodes exactly and no value passes through anf64.std.data.json.utf8adds raw-byte UTF-8 validation that rejects invalid lead bytes, missing or malformed continuations, overlong encodings, raw surrogates, and scalars aboveU+10FFFF.std.data.json.writeandstd.data.json.digitsadd a pull-based, buffer-free writer: the exact length and each byte of a quoted JSON string, and the exact decimal bytes of anyi64plus the literal words. All four carry the existing scanner'susizeend-offset/rejection encoding and pass interpreter, native C11 at O0 and O2, and Core Wasm conformance. Two new gate cases link the siblings from one consumer. Structural document validation - nesting limit, trailing-byte rejection, and duplicate-key policy - decoded strings, an owned document tree, and an output buffer remain Missing. -
Extended concrete generic owned-
Bytesrecords across the complete direct Copy-scalar set:i64,i32,u8,usize,char,f32,f64, andbool. Source verification, resolved HIR, cleanup inventory/replay, Native64/Wasm32 layout and native/Core-Wasm lowering retain the exact owner-and-index substitution. Concrete generic immutable updates now retain unchanged fields, replace owned fields left to right, and settle both partial construction and partial update failures without replacing the selected status. Focused local interpreter, Clang O0/O2 and Node/Core-Wasm evidence covers borrow-then-own execution, update execution, both partial failures, repeated entry, one-live-owner capacity, and hostile plan mutation. Explicitly instantiated generic functions can now consume and return the admitted flat owned-record template, with exact instance dispatch and failure settlement in the interpreter, native C11, and Core-Wasm. Real cross-file Project linking, semantic-recipe replay, candidate rename/recovery, and ABI-delta replay retain the internal generic identity while frozen public descriptors stay closed. Bounded acyclic concrete nesting now composes those records asBox<Pair<Bytes, bool>>,Pair<Box<Bytes>, i64>, and a two-owned-leaf instance. One global worklist authenticates depth, owned-leaf, and field-work limits; recursive cleanup retains complete stable field paths; Native64 and Wasm32 layouts independently replay complete concrete identities; and local interpreter, native C11, and Core-Wasm evidence covers whole moves, exact owner capacity, partial-prefix settlement, and repeated recovery. Generic variants, classes, resources, general nested storage, public generic ABIs, and hosted execution remain unchanged or unclaimed; the required Linux steps are authored but have not yet produced hosted evidence. -
Added a bounded authored generic owned-variant path for exact
Either<Bytes, i64>andEither<i64, Bytes>-equivalent instances. Source, HIR, conditional cleanup, layout, interpreter, native C11, and Core-Wasm retain owner/index substitution and one authenticated owned case. Local evidence covers opposite live-case vectors, inactive cases, borrow then own, partial construction, owned-arm failure, exact semantic status, repeated recovery, zero native leaks, and rejection of shallow native/Wasm copies. A partial-construction fix now stores each completed Wasm field before evaluating the next initializer and still publishes the tag last. Hostile index/type layout drift is rejected. The compiler-owned two-sidedResultis handled by a separate exact profile; nested/resource variants, public ABIs, and hosted promotion remain closed or unclaimed. -
Proved an exact authored two-owned-branch generic variant shape with two parameters,
[Bytes, Bytes]arguments, and two owned cases. Existing conditional cleanup represents both case-qualified owners without a schema change. Local interpreter, C11-O0/-O2, and Core-Wasm evidence covers both constructors, borrow/own matching, dynamic parameter/result/call transfer, branch-specific partial construction and arm failure, precondition settlement, repeated recovery, tight capacity, zero native leaks, invalid carriers/tags, and native/Wasm shallow-copy rejection. Hostile replay changes inactive liveness, case authentication, and guarded finalizers in both directions. Compiler-ownedResult<Bytes, Bytes>is admitted separately below; broader multi-case generic sums, Project/public ABIs, and hosted promotion remain closed or unclaimed. -
Admitted the exact compiler-owned
Result<Bytes, Bytes>instance for ordinary internal construction, explicit own/borrow matching, parameters, results, and calls. Its authenticated prelude identities reuse the proven conditional two-branch cleanup machinery. Focused local interpreter, native C11-O0/-O2, and Core-Wasm evidence covers both active branches, dynamic forwarding, staged-call and arm-failure settlement, capacity-one execution, hostile cleanup-plan mutation, invalid tags, tag-last result publication, and native/Wasm shallow-copy rejection. The same exact internal instance now supportsResult<Bytes, Bytes> -> Result<Bytes, Bytes>postfix?: the operand evaluates once, Ok moves its selected payload, Err transfers the complete residual, and ownership-only replay joins preserve shared postconditions, sticky failure, and both guarded finalizers. Focused local interpreter, native C11-O0/-O2, and Core-Wasm evidence covers both branches and re-entry. Mixed/general/nested and generic-function owned propagation, Project/public ABIs, and hosted promotion remain closed or unclaimed. -
Bounded native C11 name resolution by the same aggregate operation deadline as the rest of the operation. A numeric endpoint is answered under
AI_NUMERICHOSTwith no name service, no budget and no worker; a name is resolved on a POSIX-thread worker the emitted translation unit owns, waits only for what is left of the deadline, and leaves an abandoned worker registered, joined and freed by the next reap or by settlement rather than detached — the same model as the RustSystemResolver, and the same non-claim: this bounds waiting, notgetaddrinfo, which POSIX cannot cancel. A host may now select a shorter native deadline by definingSPX_NETWORK_OPERATION_DEADLINE_MILLIS_V1, clamped to the fixed maximum. Four executed native gates drive an injected 300 ms name service, a spent budget, an always-EINTRread and an interrupted-then-successful read through the emitted text in milliseconds, over loopback and anAF_UNIXsocket pair with no outbound traffic; an always-interrupted whole program still selectssemaprax.network.v1code 5 under a 250 ms deadline. The_WIN32branch is now cross-compiled where a Windows toolchain exists and keeps the inline resolver; Windows execution is explicitly scoped out rather than claimed. -
Added deterministic grammar-driven differential compiler tests with shrinking as a module of the existing
scalar_status_backend_equivalenceharness. A seed names one module in the admitted scalar subset — nested operands, parameterized helper calls, branches, bounded loops, mutation, contracts, checked failure and lazy evaluation — and every lane answers in one closed vocabulary: canonical parse-format-parse stability, graph identity, verifier/HIR agreement, the reference interpreter, native C11 at O0 and O2, and Core-Wasm on Node. Sixteen fixed seeds run in PR CI; a larger bounded campaign runs separately. A disagreement is classified, minimized by a structure-preserving shrinker, and rendered with the seed, source, compiler commit, toolchain identities, exact commands, expected and observed outcomes and the minimized module. Unsupported profiles and absent provisioned tools are explicitUnavailableoutcomes, never parity passes, and failure injection proves the checker notices a wrong backend value, an incorrect failure selection and an abort. Generated modules declare no effects and nounsafe, so no fuzzer-generated file executes with ambient network, filesystem, process or signing authority. Owned cleanup and task schedules remain out of this first tranche. -
Added the bounded AGENT-04 interaction-contract slice. Source-owned Agents now derive exact Proposal and Observation grammars from checked same-module record or variant declarations, including closed bounded decoders and a deterministic provider-neutral JSON Schema/TypeScript/Python/Rust Proposal client bundle. Project revisions retain independently replayed contract facts and expose them through the existing AgentDefinitions node, ProgramRoot, typed query, and semantic service without changing closed transport schemas or legacy agent-free and explicit-association bytes. Generated client source is structurally verified but is not claimed as compiled, packaged, or run; cross-module role resolution remains follow-up work.
-
Fixed
semaprax runrefusing bounded Copy record construction thatcheckverifies and that the native C11 and Core-Wasm backends execute (#75). The single-file interpreter route was the only route askingrecord_construction_is_admittedfor the narrower owned-byte answer, so readingp.xwas admitted while building thepit reads from was not. The admission predicate is now the single bounded acyclic classifier every route already shared, and the parameter that split them is gone. Field Mutation v1 stores now replace one direct scalar field instead of the whole binding — the previous store left a later projected read failing closed onSPX-F105— and a shared Copy carrier is copied before the store, so a sibling binding keeps the value the other two backends give it. Record shapes still outside the profile keep their exact closed reason at admission: a record-typed callee signature isunsupported_callee, andwithover a Copy record isrecord_update. -
Added the bounded AGENT-03 language-native source Agent slice. A closed
.spxdeclaration with explicit identities and fixed deterministic/model/ effect roles now parses, round-trips canonically, lowers through the unchanged AgentDefinition v1 compiler, and retains byte-identical AgentDefinition, AgentGraph, and Runtime Profile products on the admitted Project revision. Default canonical workspace derivation populates its existing AgentDefinitions segment, with the same node selected through ProgramRoot, exact context, a typed in-memory query, and the persistent service. The three focused compatibility/hostile/integration cases pass locally; role execution, provider authority, opaque authorization, and durability remain absent. -
Fixed the Workspace Semantic Graph
builder_bytespre-bound charging every imported function's contract and body as resolved structure in the importing module. The synthetic projection retains an import as a stub — rewritten signature, no contract, default body — so a conformance module that imports everything its library exports was costing a second complete copy of that library, expanded by the structural factor. Imports are now charged as the stub they become, plus the largest single transient provider clone at the raw AST rate.SPX-G171still refuses before mutation and the estimate remains an upper bound of resolver memory. Documented the practical authoring limits, including theSPX-H006cleanup-replay path budget, in Standard Library v1. -
Added ProgramRoot v2 and Exact Program Context v1. The versioned root retains the enriched canonical workspace's nine v1 segments, appends exact interface/ artifact and Project Lock association descriptors, and explicitly binds the distinct default Project root. Additive service, query, transaction, and structural-diff entry points select the same dual-keyed v2 root in memory without changing legacy wire bytes. Exact candidate-root derivation and refresh remain fail-closed pending candidate-safe lock replay.
-
Added locally exercised SEG-02 input bundles for exact source-interface and pathless generated-artifact facts plus exact Project Lock v1 association. Both freshly replay their existing owning compiler artifacts, retain bounded content identities without authority, and preserve ProgramRoot v1 and every legacy Project/Image/Graph/lock byte. Versioned exact-root integration remains explicit follow-up work.
-
Added the provisioned Linux offline doctor lifecycle gate: one dispatch-only workflow,
scripts/doctor-provisioned-linux-gate.py, and Provisioned Linux gate v1. The gate asserts host, kernel, delegated cgroup-v2, held-image, release and trust-anchor preconditions before any test runs, selects the twenty-six existing ignored lifecycle fixtures exactly and serially, binds commit, platform, tools, fixture identity, bounded capture and final cgroup emptiness into one evidence document, and keeps failure selection sticky over cleanup. Absent provisioning is a failure, never a skip: unmet or unobservable preconditions, still-ignored tests, an unmatched filter and a narrowed selection are each rejected, and--self-testdrives that logic with synthetic inputs on any host. The gate itself has never been executed; no provisioned Linux x86-64 host exists, no completion row moves, and the private provisioner stays out of every ordinary CLI route. -
Added the SEG-02 explicit AgentDefinition association bridge. A bounded, stable-ID-ordered set of exact compiler-admitted definition/graph/profile bundles can populate the existing Canonical Workspace AgentDefinitions node for one exact Project revision and flows into ProgramRoot automatically. Default empty derivation remains byte-compatible; the new route explicitly does not claim
.spxAgent syntax, intrinsic Project ownership, execution, or authority. Its three focused Workspace-harness cases pass locally. -
Added the SEG-02 ProgramRoot v1 foundation as a small segmented, content-addressed projection of Canonical Semantic Workspace Revision v1. Nine independently digested descriptors bind the existing typed node bytes, while DeploymentRoot, InstanceRoot, and EvidenceRoot remain typed unbound placeholders. Existing canonical workspace, Project, Image, and Graph bytes and identities are unchanged. The 33-case combined focused gate and strict all-target clippy pass locally.
-
Added the Project-v13 native C11 HTTPS lane. Generated commands link through a narrow libcurl route, embed a pinned 146-certificate Mozilla trust bundle, require hostname/certificate validation with TLS 1.2 or 1.3, negotiate HTTP/2 with HTTP/1.1 fallback, bound redirects/connections/headers/body and time, suppress ambient proxies, canonicalize the complete response, and settle before publication. A real encrypted loopback gate and an opt-in public-PKI smoke exercise the generated executable.
-
Added a locked Project-v13 HTTPS browser fixture and provisioned Chromium CI gate. It executes the real generated npm/Wasm package, verifies exact fixture-v3 output, one-shot invocation and tampered-Wasm rejection, and proves every browser request stays on the loopback harness origin.
-
Added a descriptor-derived safe C++17 adapter for Project-v9 flat owned records. Its thread-bound noncopyable client preflights borrowed inputs, authenticates private carrier values, copies and settles the sole byte handle, closes the provider context, and only then returns a value-only C++ record. A real separately compiled C11 provider and C++17 consumer execute at O0/O2. The C header now preserves its C11 static-array minimum while using C++-legal syntax when included from C++.
-
Added
std.data.json, the first JSON facility a SEMAPRAX program can call. Bounded JSON Scanner v1 specifies a pure, allocation-free JSON string-token scanner overborrow Slice<u8>: whitespace skipping, escape classification,\uXXXXcode-unit decoding, strict surrogate-pair rules that reject a lone or unpaired surrogate, RFC 8259 control-byte rejection, and the byte offset of the first rejection carried in the sameusizeresult. Number and literal tokens, structural document validation, UTF-8 validation, decoded strings, an owned document tree, and a writer stay Missing: theSPX-G171workspace-graph pre-bound admits roughly 4.7 KiB of library source for a package of this density, and rejects a consumer that links two such packages, so the remaining scope needs that bound raised rather than more library code. -
Added invocation-owned HTTPS work to the bounded structured-task runtime. Providers now settle exactly once across success, HTTP failure, cancellation, panic, deadline expiry, and registration rejection; results publish only after settlement, while started blocking I/O drains and late responses are discarded.
-
Added authored Universal Semantic Query v1 checked-fact projections for one expression's ownership/loan facts and for direct retained-HIR declaration consumers. Both are exact revision-bound canonical requests with replay, paging/walk/output bounds, and explicit static-analysis and export-visibility nonclaims; the focused evidence passes locally.
-
Extended Universal Semantic Transaction v1 with typed
AddDeclaration. It authenticates the exact anchor-module path, source digest, and ordered declaration identities, rejects Project-wide identity reuse, delegates the closed function/record/variant constructor to Project Candidate, and proves one source insertion with unrelated bytes preserved. The read-onlychange preview add-declarationadapter and focused regression evidence pass locally. -
Added the Project-v13 HTTPS Core-Wasm and npm lanes. The new replayable
semaprax.project-npm-build.v12package authenticates onespx_https_get_v1import, a distinct HTTP status marker, owned response carriers, fixture-v3 authority, and success-only output; the generated package executes the committed HTTPS project under Node without sockets. -
Added frozen Project Manifest v13 with the exact
https-command-io.v1profile andnetwork.httpauthority. Its authenticatednetwork-runroute replays fixture v3, while Project v12 and all prior manifest bytes remain unchanged. -
Repaired the VS Code Extension Host inventory and widened its scenario. The host test asserted exactly 28 contributed commands while the manifest contributes 37, so a provisioned run failed before its workflow. The assertion is now the exact 37-command inventory in manifest order, every contributed command must be registered, no registered
semaprax.command may be undeclared, and the forbidden authority-bearing list is checked against both contribution and registration. The scenario additionally covers check-on-save positions past a supplementary character, retention of previous diagnostics across an unclassifiable run, project-routed navigation across all three calculator sources, and the dirty-buffer and project-rename refusals. The provisioned runner's node-controller inventory, recorded inputs, and command count were updated to match. The Extension Host gate itself was not run for this change: no Visual Studio Code product is installed here. -
Routed VS Code declaration navigation, callers, code lenses, and ownership through the project that owns the saved file, resolved exactly as check-on-save resolves its subject. A module with
useimports has no standalone meaning (SPX-G172), so those commands previously failed on every importing file, including the shipped calculator project. Thesemaprax.project-query.v1result is parsed with its per-matchpathandsource_revision, matches outside the project root are dropped, and a selection opens the authenticated file the match was found in. Safe rename reports that a project-owned file belongs to the saved-source session's replay-checked typed intent rather than to a standalone patch, and the module-onlydocandgraphroutes name their boundary. -
Made VS Code MCP frame assembly linear in received bytes. The receive path concatenated the whole retained response with every incoming chunk and rescanned it from byte zero, so a legal response fragmented into 1 KiB pieces copied about 2.1 GB for 2 MiB received. Retained fragments are now counted for the cap check and copied once into the frame they complete. The byte cap, strict UTF-8, CR rejection, response-identity validation, serial request semantics and terminal failure are unchanged.
-
Fixed VS Code editor ranges mixing three coordinate systems. The compiler's UTF-8 byte spans are now translated against the exact saved source into zero-based UTF-16 positions that may cross lines, through one mapper (
editors/vscode/positions.js) shared by diagnostics, declaration navigation, and code lenses. Torn, reversed, and out-of-range offsets fall back to the reported line and column instead of underlining the wrong text, and a document changed while the compiler ran receives no positions at all. -
Fixed the VS Code check-on-save adapter reporting a clean project from output it could not read.
check --jsonoutput is now classified into diagnostics, the verified record, and malformed lines, and the exit status is validated against them; a killed child, a foreign status, an unparsed line, an error with status 0, or a verified record with status 1 is a check failure that retains the previously published diagnostics instead of clearing them. -
Made the
Release gateCI aggregate fail closed. It ran underif: ${{ success() }}, which skips the job whenever a blocker did not succeed, and GitHub scores a skipped check run as a satisfied required status check. It now always runs and asserts everyneedsresult throughscripts/ci-required-checks.py, rejecting failed, skipped, cancelled, malformed, vacuously empty, and foreign-commit inputs; a local test drives those cases and a second derives the blocker inventory from the workflow so a new job cannot escape the aggregate. Added Required CI checks v1 recording the observed unprotectedmain, the branch-scope, bypass and recovery policy, and the exact ruleset request. The ruleset is a proposal: no repository setting, ruleset, membership, credential or branch permission was changed, and no required check is in force. -
Added Persistent Semantic Workspace Service MCP v1 through
semaprax service <project> --mcp. Its closed seven-tool MCP catalogue exposes protocol/status, universal, retained-index, and bounded history queries, transaction validation, and caller-owned refresh through one process-retained service generation. Startup is the only host-path boundary; MCP tools add no authority and frozen Project Agent Transport v5 bytes and MCP catalogue remain unchanged. -
Added Persistent Semantic Workspace Service Transport v1 and the
semaprax service <project>adapter. One authenticated Project and one incremental semantic service remain alive across bounded JSON-RPC-lines universal-query, retained-index-query, transaction-validation, and caller-owned refresh requests; failed or stale refresh rolls back before the in-memory generation/cache/index CAS. Four focused Workspace-harness cases pass locally. This is a single-client local stdio process, not MCP/LSP, a socket, daemon, durable/shared state, source writer, execution service, or authority broker; frozen Project Agent Transport v5 remains separate and unchanged. -
Extended Universal Semantic Transaction v1 with typed whole-function
ReplaceBlock. It binds an exact old source block, delegates the replacement expression to complete ProjectCandidate validation, proves byte-identical source outside the selected span, and exact-replays the ordinary transaction artifacts without commit authority. The focused transaction/composition selection passes 10 cases locally; nested expression replacement, multi-operation transactions, and ReplaceBlock composition remain open. -
Added refresh-atomic retained semantic-service indexes for tests covering a stable declaration and functions that can reach a named effect. Canonical, revision-bound query/results are bounded, deterministic, replayable, and available through both the service core and
workspace/index-query. Persistent-core focused evidence passes five cases locally. -
Extended
semaprax reviewwith the closed Project formreview <project> <transaction.json> [--evidence]. Default output is the exact concise semantic review; evidence is displayed only when requested. The existing source-patch form remains unchanged, no files are written, and the focused three-case CLI gate passes locally. -
Fixed the macOS held-Git process boundary to preseed CoreFoundation's user-text-encoding key with the process UID and fixed encoding fields. This prevents CoreFoundation from reading the user-home encoding file or rewriting the child environment, while the exact environment assertion remains closed.
-
Added Signed Minimum Literals v1:
-9223372036854775808and-2147483648i32are ordinary literals in expressions and match patterns, so boundary constants no longer need a-MAX - 1workaround. The magnitude survives tokenization as its own token and is claimed only by a directly applied unary-, so tokenization stays context-free and subtraction is unchanged; the bare magnitude, a parenthesized one, andMIN - 1all keep the stable locatedSPX-P003rejection.-MINandMIN / -1still select checked arithmetic failures, and the native C11 backend now spells both signed minimums as a negated maximum less one so no C literal names an unrepresentable magnitude. -
Fixed
run <file> --jsonpublishing human diagnostics on stderr when its preliminary load or verification failed. Parse errors, unreadable inputs, and type/effect/ownership failures now emit the same diagnostic records on stdout thatcheck --jsondoes, including for the bounded stdout profile. Human mode and every execution envelope are unchanged. -
Added
semaprax.network-fixture.v3as an ordered, bounded HTTPS request/response replay carrier. V1 and v2 reject the new member, URL or response mismatches do not consume queue entries, and hostedhttps_getconformance now uses the serialized carrier shared with generated lanes. -
Added Installed Fix Plan v1.
semaprax fix --planreturns the exact bounded, version-bound one-operation installed catalog, whilesemaprax fix <file> assign-function-id <automatic-function-id> --planwraps the existing source-authenticatedSPX-S103Diagnostic Repair discovery in a canonical, replayable plan. Five focused semantic-harness cases pass locally. Planning does not select a persistent ID, instantiate or apply a patch, write source, rank repairs, or grant host/publication authority; existingrepairs,repair, and Diagnostic Repair bytes remain unchanged. -
Admitted a bounded internal concrete generic owned-byte record slice. Exact authored instances such as
Pair<Bytes, bool>now substitute fields through source verification, HIR facts, cleanup inventory and replay, interpreter, Native64 C11, and Wasm32 lowering. Focused local evidence covers borrow then own, repeated success, and failure after owner creation across interpreter, C11-O0/-O2, and Node/Core-Wasm; stable diagnostics keep nested generic, class, variant, and non-Copy record shapes closed. This record slice does not authorize prelude carriers; exactResult<Bytes, Bytes>support was added later under the owned-variant contract. It does not expose a Project, C, Rust, WIT, Component, or package ABI. -
Named the exact
Option<Bytes>andResult<Bytes, i64>tags in the public Project-v8 C11 header. A separately compiled C consumer now executes all four cases at O0/O2, proves inactive cases grant no handle authority, and copies, drops, and stale-rejects each active byte handle before context closure. -
Exposed the shared descriptor-derived C11 provider header for Project-v10 owned UTF-8. A separately compiled consumer links against the actual provider at O0/O2 and copies, drops, and closes an exact-length result containing both embedded NUL and multibyte UTF-8, without exposing native String layout.
-
Added Installed Diagnostics v1: an offline build-time scan embeds the exact static
SPX-*token inventory from compiler and workspace-member Rust sources while separately reporting unresolved dynamic diagnostic constructor sites. Authority-free library constructors expose bounded, canonical, compiler-version-bound catalogue and per-code explanation artifacts with exact replay;semaprax explainprints the exact concise or JSON explanation. Five focused projections-harness cases pass locally. Static presence is not runtime reachability, message or repair inference, binary attestation, or a stable cross-version registry, and legacy diagnostic bytes remain unchanged. -
Added a descriptor-derived C11 header for the Project-v11 nested owned-record provider. Its fixed-width leaf carrier preserves full descriptor occurrence order without exposing native record layout. A separate C consumer links and runs at O0/O2, copies and settles two distinct byte owners, rejects both duplicate drops, and closes their shared context.
-
Added a descriptor-derived low-level C11 header for the Project-v9 flat owned-record provider. It publishes fixed-width carrier field counts, ordinals and kinds without exposing native record layout. A separate C consumer compiles, links and runs with the actual provider at O0/O2 while checking poison preservation, scalar decoding, byte copy/drop, stale-handle rejection, and context closure.
-
Added source-level
https_getthrough an explicitnetwork.httpcapability, a closedsemaprax.http.v1status domain, canonical bytes consumable bystd.http, and a reusable authenticated HTTP/1.1/2 host provider; addednet_tls_acceptfor source-controlled server-side TLS without changing the existing network status domains or prior HIR cache tags. -
Added a pure C11 consumer gate for the authenticated Project-v8 owned-data package. The generated provider and a translation unit using only the public C header compile separately, link, and execute at O0/O2 while checking invalid-bool output poison, owned-byte copy/drop, stale-handle rejection, and context closure. This establishes a local linkable C ABI slice without promoting Objective-C, cross-platform support, distribution, or compatibility.
-
Added the locally exercised Universal Semantic Transaction Composition v1 core. It derives a bounded canonical workspace structural diff, rebases one validated display rename onto an exact independently admitted revision, and merges two distinct-target sibling renames in an explicit order through the existing Project Candidate conflict and replay machinery. The five focused integration cases pass locally. Four focused Workspace-harness cases also prove that the read-only CLI forms print the exact core structural-diff, rebase, and merge reports; no general multi-operation transaction, behavioral equivalence, source commit, transport, or authority is claimed, and all Semantic Transaction v1 bytes remain unchanged.
-
Added Installed Agent Guidance v1: six deterministic, version-matched, authority-free skill documents are available through
skills get, andquery --capabilitiesreports the exact installed five-operation Universal Semantic Query catalogue with no host grants. Core and CLI return identical canonical, bounded, digest-bound artifacts assembled only from embedded compiler resources. The focused projections integration gate passes 5/5; no binary attestation, live discovery, skill execution, host authority, registry, network, MCP/LSP, or legacy-query change is claimed. -
Added exact
semaprax help diagnostic <SPX-code>lookup and the boundedsemaprax help diagnostic codesinventory. A generated JSON companion keeps the CLI response identical in meaning to the compiler-checked quick reference's correction table, and the documentation gate now requires every marked failing example to have indexed help. The guardedSPX-T208answer is 111 bytes and 32 lexical units versus 2,513 bytes and 916 units for the complete diagnostic index. -
Added the locally exercised Universal Semantic Workflow CLI v1 read-only adapter. Five Project-only
querysubcommands print exact Universal Semantic Query results, whilechange preview rename-display-nameprints the exact Universal Semantic Transaction result or evidence. Each one-shot invocation retains and finally rechecks one authenticated Project; no source write, commit, persistent transport, or MCP/LSP route is added, and frozen Project Agent Transport v5 remains unchanged. The five focused integration cases pass locally. -
Added the authority-free, transport-neutral Universal Semantic Query v1 core. Five exact canonical, workspace-revision-bound operations cover bounded declaration paging, symbol, context, impact, and truthful transaction eligibility; results bind Project, image, canonical component, payload, and request identities and support fresh exact replay. The six focused integration regressions pass locally. No wire, CLI, MCP, LSP, mutation, publication, or frozen Project Agent Transport v5 change is claimed.
-
Added exact
semaprax help language <topic>lookup and the boundedsemaprax help language topicsselector list. An installed compiler can now return one compiler-checked section of the agent quick reference without transferring the whole card; every topic is guarded at more than five times smaller in both bytes and repository lexical units. Thescalarsresult is 793 bytes and 296 units versus 26,140 bytes and 7,418 units for the full card. -
Added a hosted Network Services v1 extension with Rustls-authenticated TLS clients, explicit listener/accept lifecycle, deterministic fixture v2, five effect-gated source operations, and a bounded real structured-task runtime.
-
Restored the frozen legacy Project-v3 Wasm byte projection by keeping the data-export profile's unused
spx_contract_failimport at its historical void signature. Data exports continue to publish typed arithmetic, contract, and byte-range failures through status globals; the ordinary entry wrapper retains its status-carrying failure import. The byte-capacity unit module now names its test submodule path explicitly so both its library owner and the consolidated cleanup harness remain resolvable bycargo fmt --all. -
Added an explicit reusable native-host HTTPS client with bounded redirects, keep-alive pooling, HTTP/1.1 and HTTP/2 negotiation, stable typed responses, body limits, and an opt-in public-PKI smoke; the TCP provider can now accept server-side TLS with caller-installed Rustls certificate policy.
-
Added the developer-preview
network-command-io.v1Project v12 profile, native and deterministic fixture-only npm/Web build lanes, the boundedsemaprax network-run --fixturecommand, and a committed HTTP Project fixture. Browser and npm packages receive no ambient or real socket authority. -
Added Graph v32/v33 for exact composition of owned-variant conditional cleanup with unprojected or stable-field-projected Shared Loan Plan facts. Semantic Workspace now preserves those source schemas, unknown spellings and evidence flows remain closed, and the formerly ignored checked-HIR cache regression executes cold/warm Graph v32 accounting and replay.
-
Added scoped
semaprax help shapes <kind|stable-id|path#stable-id>backed by a generated JSON companion to the unchanged Markdown catalog. Exact IDs can be source-disambiguated, and a kind returns its smallest canonical exemplar instead of every declaration. The guardedcalculator.addresult is 114 bytes and 33 lexical units versus 22,888 bytes and 7,571 units for the full catalog, while every kind exemplar stays within 512 bytes and 128 units. -
Added the authority-free, transport-neutral Persistent Incremental Semantic Workspace Service v1 core. A process can retain one immutable Project, Canonical Semantic Workspace Revision, Semantic Workspace Image, and semantic cache generation; serve revision-bound bounded snapshot queries; stage a complete source-exact incremental successor; and install it through one expected-current in-memory generation/cache compare-and-swap. Transaction validation returns Universal Semantic Transaction artifacts without adopting their candidate. The three focused lifecycle regressions pass locally; no wire, CLI, MCP, LSP, disk persistence, build, execution, commit, publication, or broad operation-algebra claim is added.
-
Corrected the pathless public C-artifact projection after entry and public target closures were separated: native inspection now emits the independently admitted entry-plus-export program, so unsupported owned exports remain explicit header exclusions instead of failing because they are absent from the executable entry-only closure. Native useful-data, language-I/O, and line-I/O command products likewise emit that public closure so the manifest-selected command and its exact permits remain present. Entry execution semantics remain unchanged.
-
Admitted explicit nongeneric resource-free record and variant type imports containing owned
Bytesin owned Project profiles. Stable-ID HIR and cleanup plans now survive that module boundary, and an owning nominal function can move with one exact type import; imported callables exposing owned nominal arguments, borrowed storage, resources, generics, cycles, runtime execution, and public carrier widening remain closed. Promoted the focused cleanup dependency image/transport corpus into the ordinary suite. -
Promoted the focused nominal record/variant rename regressions into the ordinary candidate suite after correcting an invalid shadowed pattern fixture; the corpus now executes owning and generic nominal renames, stable member identities, immutable rejection, recovery, conservative rebase, and the existing transport surface; runtime and hosted gates remain unrun.
-
Hardened
std.http.status_codeso an HTTP/1.x status code is accepted only when the required space before the reason phrase is present; truncated lines such asHTTP/1.1 299now return-1consistently on the interpreter, native C11, and Core Wasm lanes. -
Added
semaprax help shapes, which prints a generated language shapes catalog: every declaration of every committed example with its@idand canonical header, rendered through thesemaprax docmodel and pinned by the projections harness, so the bundled reference of admitted shapes is derived from the graph rather than hand-written. -
The VS Code adapter adds
Safe Rename by Stable ID(authors the semantic rename patch, showsimpact, applies through the replay-checkedpatchroute),Show Cleanup Plan(the module graph's canonical cleanup plan for a function), andRun Agent Transcript(trace, evidence, or receipt of a scriptedagent run), all bounded like check-on-save. -
semaprax doctoris now admitted by the standalone compiler: the pure offline-profile admission and version-policy module moved from the private toolchain into the root crate (src/doctor.rs), so both binaries print the same report and the guided help pages are identical; only the settled provisioner-observation renderer remains in the toolchain, and onlybuild --target ruststill needs the private host. -
Added exact offline
semaprax help library <module|name|stable-id>lookup, returning only the generated dependency row, required profile, signature, effects, and contracts while preserving the full catalog bytes. The guardedstd.core.comparelookup stays within 512 bytes and 128 lexical units and is more than 50 times smaller than the 22,076-byte, 6,662-unit catalog in both measures. -
The VS Code adapter adds
Show Ownership, Contracts, and Effects(the compiler's boundedcontextfacets for a chosen callable) andInspect Agent Definition(agent inspectover the saved AgentDefinition v1 file), both bounded like check-on-save and covered bytest/navigation.test.js. -
Added
semaprax agent run <definition.json> <task.json> <transcript.json> [--evidence|--trace]andsemaprax agent replay ... <evidence.json>: a scripted transcript of provider responses and tool results drives the bounded Agent Runtime v1 through the definition's derived profile with no transport, clock, or tool authority, so runs are deterministic and a replay proves an evidence capsule byte for byte (SPX-V221malformed transcript,SPX-V222replay mismatch).resumeandreconcilestay unadmitted. -
Added the bounded, authority-free Universal Semantic Transaction v1 kernel over Canonical Semantic Workspace Revision v1, with one typed
RenameDisplayNameoperation, exact base/old-name preconditions, deterministic intent/impact/review/result/evidence, fresh exact replay, and a locally passed focused Project-candidate gate. The additive slice does not alter legacy Project, workspace, Image, Semantic Change, or Candidate bytes. -
The bundled standard-library catalog (
semaprax help library,std/catalog.json) is now rendered from thesemaprax docdocumentation model, with every signature cross-checked against the source text and each declaration's leading comments carried as its description. -
Added
semaprax add <dir>|semaprax.toml <package> <range>, which appends one byte-sorted[dependencies]row to a Package Manifest v1 table manifest and rewrites it canonically only after the result re-parses (SPX-J127for frozen layouts and duplicates), andsemaprax fetch <cache-dir> <subject.json>..., which replays Subject-v3 envelopes and files them into the resolver's content-addressed cache by digest with one receipt line (SPX-J128on tampering or collisions), with no registry or network access. -
The VS Code adapter navigates by meaning:
Go to Declaration by Stable ID,Show Callers of a Declaration, andShow Module Documentationrun the selected compiler's read-onlyquery --jsonanddocover the saved active file, and code lenses show each declaration's@id, effects, and contract counts (semaprax.codeLens). ThedocandqueryJSON projections now carry each declaration's and member'slocation. -
Fixed Project owned-API target preparation to retain a distinct, already-admitted entry-plus-export HIR closure without changing entry-only execution or cleanup semantics, and updated both typed-expression schema gates for the two newly admitted numeric-to-String operation alternatives.
-
Updated cleanup and protocol regression fixtures for aggregate-equality rejection, stable-ID native contract details, and the precise scalar-profile signature diagnostic while preserving owned-result and lazy-temporary cleanup coverage.
-
Kept the freestanding C profile libc-free after native contract details gained argument rendering by replacing hosted formatting with a bounded byte copy and eliding per-call formatting, refreshed the affected native known answers, and made the depth-512 HIR oracle independent of the parser's depth-128 source admission boundary.
-
Added the locally exercised Canonical Semantic Workspace Revision v1 foundation: one immutable authority-free object derived from an admitted Project, with nine typed node projections, distinct semantic, source projection, manifest, and dependency-closure digests, one composite revision, and exact fresh replay. Existing Project, managed Workspace, and Semantic Workspace Image v1 schemas, bytes, and revision identities remain unchanged; universal transactions, full semantic coverage, persistent service,
.spxagent syntax, and publication authority remain separate work. -
Added Bounded Language Network I/O v1: six compiler-owned, effect-gated TCP client operations (
net_connect,net_send, ownednet_recv, transcript-streamingnet_stream_stdout, bounded-readinessnet_wait,net_close) with the closedsemaprax.network.v1status domain, aNetworkV1operation profile, invocation-scoped handles, a deterministicsemaprax.network-fixture.v1provider, a realTcpNetworkProviderfor the hosted interpreter seam, native C11 POSIX/Winsock lowering, and Core Wasm closedenvimports with fixture injection; plus purestd.net,std.http, andstd.asynchelper packages and thenet_http_getexample. -
Fixed the native C11 borrowed-view context extension: the
call_depthfield added tospx_contexthad silently detached the text anchors that splice inborrowed_str_depth, so every native program with aborrow Slice<u8>orborrow strparameter failed to compile; the anchors now target the current struct and the emitter asserts that they matched. -
Added
semaprax query <file|project> [filters] [--json], a read-only declaration search over a checked module or every authenticated Project source with--kind,--name,--id,--effect,--calls, and--called-byfilters. Project results name owning paths and exact revisions, and use the retained semantic graph for cross-file call predicates; unknown kinds or identities fail closed withSPX-V211/SPX-V212. -
semaprax context <file|project> <stable-id>now accepts a Project directory or manifest and renders a compact authenticated, bounded cross-file context without requiring agents to discover and reopen one source. The calculator gate caps it at 2 KiB, 600 lexical units, and one sixth of the full graph. -
Added the
semaprax package report|lock|resolvenamespace, each subcommand exactly its long-form offline package route. -
Split CLI option parsing and single-file execution/reporting out of the command dispatcher, bringing
src/cli_driver.rsbelow the module-size limit while retaining the moved surfaces in the source-locked doctor contract. -
Added
semaprax verify, one verb for every independent evidence verifier: the capsule'sschemaselects the owning route (semantic patch evidence v1/v2, workspace patch evidence, semantic workspace change, structural change, and operations evidence, agent graph bundles, and project images) and the receipt is that route's own bytes; unrecognized or unreadable capsules fail closed withSPX-V201/SPX-V202before any verifier runs. -
Added
semaprax agent inspect <definition.json> [--profile], which compiles a canonical AgentDefinition v1 and prints its AgentGraph v1 or its Agent Runtime Profile v1 projection; the other lifecycle verbs stay unadmitted. The guided help gains anAgentsgroup and listsverifyunderChange by meaning, with shapes shortened to hold the 2048-byte bound. -
Added
semaprax doc <file> [--json], the documentation projection of one checked module: a Markdown page or onesemaprax.doc.v1document of every declaration's identity, canonical signature, ownership modes, effects, contracts, members, and leading//comments, bound to the graph revision. The projections harness proves the page andsemaprax graphname the same declarations at the same revision on every committed example. The guided help lists it underInspect meaning; several guide summaries were shortened to keep both capability pages under the 2048-byte bound. -
The canonical graph-operational agent workflow now uses compact candidate source-review, function-summary, and impact-summary projections while full candidate and semantic-delta replay stays inside the verifier. Its regression rejects the older full-report routes and enforces aggregate protocol and review-material byte/lexical-unit ceilings, preventing silent context-cost regressions in the fixed twelve-step application change. Immutable review data is transferred once and reused across the expected conflict; recovery replay proves the candidate and source review stayed exact without two duplicate protocol responses.
-
Project-link diagnostics now name and locate the exact entry, test, or provider module responsible for missing or invalid
maindeclarations and distinguish capability exclusions from declaration-shape exclusions. -
CLI and parser diagnostic gaps now retain stable codes and actionable source anchors: missing
fmtinputs useSPX-I001/SPX-J102, unknowncontextsymbols useSPX-G404, bare identifier statements point at their token, UTF-8 BOMs name their removal, and semantic-review patch decoding shares the ordinarySPX-I202wording. -
Improved newcomer diagnostics: statement-position
iffailures now name the mandatoryelseand discard form, immutable parameters show the mutable-copy repair, and unknown bundled standard-library functions name their manifest dependency and offline catalog route. -
Added reserved
string_from_i64andstring_from_usizeoperations with canonical decimal spelling across the interpreter, native C11, and Core Wasm lanes, allowing computed integers to be printed without handwritten digit tables. -
Malformed three-token help requests now identify the unexpected extra operand instead of misreporting
helpas an unknown command. CLI report and analysis option parsers also live in a bounded driver submodule, keeping the shared dispatcher comfortably below its recorded module-size cap. -
Build target errors now use input- and toolchain-specific catalogs; scoped help and the CLI guide document the Web-compatible
wasmalias,-o/--output, target and destination defaults, and structuredbuild --jsonresults. Profile Web collisions report Web-specificSPX-I307, concurrent project native builds have one create-new winner, and command-profilerunoutput explains that it executes the entry while built adapters invoke the manifest command. -
Single-file native and Web/Wasm builds now require fresh destinations. Native output is reserved before compiler invocation and Web output uses an atomic create-new directory, so existing sources/artifacts and concurrent winners are never overwritten or merged; invalid parents report
SPX-I301and existing destinations reportSPX-I307. -
Native contract-failure stderr now includes the canonical clause, persistent function identity, and declaration-ordered observed arguments, matching the interpreter's human repair detail while preserving the normalized status and exit code.
-
Reference-interpreter frames now use indexed binding slots instead of reverse linear scans. Interned
ValueIdhandles also make executedletbinding insertion allocation-free after HIR construction; scalar reads keep their existing by-value copy path. The runtime loop is retained in the Criterion interpreter benchmark as a regression gate. -
Single-file
semaprax runnow executesapp.mainthrough the bounded reference interpreter, accepts--json,--max-steps, and--max-bytes, and automatically admits the exact bounded stdout-transcript profile. The former generated C11 behavior remains available explicitly as--native. -
Generated native executables now guard the same 256-frame call-depth bound used by the reference interpreter. Deep and mutual recursion return the deterministic
semaprax.runtime.v1/1capacity outcome with visible stderr and exit 73 instead of terminating through an empty-stderr stack signal. -
Web packages now preserve semantic status domains for byte-range failures and checked i32, u8, and usize arithmetic. Generated JavaScript exposes the same frozen
{schema, domain_id, code}observation for these failures as the interpreter and native lanes instead of mislabeling or bare trapping. -
Native builds now accept legal scalar self-comparisons such as
x == xunder the generated C warning policy, including the idiomatic floating-point NaN test shape, while retaining-Werrorfor actionable generator warnings. -
Fixed right-nested i32 arithmetic in the scalar Core-Wasm emitter by keeping the outer widened operand on the Wasm value stack until the nested operand finishes. Nested literal and function-call expressions now match native and interpreter results at multiple depths.
-
Fixed the scalar Core-Wasm local layout so i32, u8, and usize arithmetic scratch locals follow function parameters instead of aliasing parameters or user
letbindings. Parameterized narrow-integer programs now validate and agree with the reference interpreter. -
The CLI now rejects single-file semantic-patch no-ops and read-only sources before staging, admits Context byte budgets only from the viable 2048-byte envelope floor, and refuses
fmtsource, manifest, or project-directory symlink/reparse aliases withSPX-J102. -
Cleanup replay now validates long scalar checked-status sequences through bounded status-source/edge/exit summaries instead of cloning every failed path's successful prefix, eliminating quadratic replay memory and preflight rejection for large straight-line functions.
-
Cleanup replay now recognizes decision-only CFGs with no cleanup state and validates them structurally without enumerating every lazy-boolean outcome, so ordinary long
&&/||chains no longer hit the path budget. -
Source verification now skips lazy-branch snapshots for ordinary binary operators, tracks whether a scope has local borrows before liveness work, and indexes declared record fields once, removing quadratic rescans from wide scalar blocks and record literals.
-
Formatter capacity accounting now measures all expression-subtree lengths during one canonical traversal instead of re-rendering every subtree, making revision hashing linear in expression size while preserving exact bytes.
-
Cleanup replay's preflight now accounts for every constructor-field continuation, so wide record and variant literals no longer exhaust an underestimated per-function skeleton budget.
-
Corrected the installed language card:
whilerepetition is controlled by the re-evaluated condition, while the required body tail is discarded; the card now names the Copy-scalar and aggregate restrictions behindSPX-T252. -
Misspelled variant constructors and patterns now suggest the nearest unique case and preserve the nominal type after a bad constructor, suppressing the downstream unknown-binding and incompatible-match cascade.
-
String ordering now emits only
SPX-T250, without a duplicate numericSPX-T208; aggregate equality in contracts now fails at the clause with locatedSPX-T207and scalar-field/match guidance before backend lowering. -
Nominal aggregate-valued
matcharms now fail during source verification with a locatedSPX-T258and anif/scalar-extraction remedy.check, native, and Wasm agree before unsupported record/variant lowering begins. -
Added a deterministic 128-level source-nesting limit. Deep balanced or truncated delimiters, unary chains, and expression trees now fail with a located
SPX-P207and extraction help instead of overflowing the Rust runtime stack in front-end commands. -
Empty function identities now fail at source verification with located
SPX-S102suffix guidance, and the 4,096-function byte-data capacity limit uses locatedSPX-T270with the bound and a module-splitting remedy instead of an unlocated internal replay diagnostic. -
semaprax checknow resolves and validates HIR, cleanup plans, and replay budgets after source verification, matching the verdict used bygraph,run, and both build targets instead of accepting backend-invalid source. -
Agent Context v2 now projects
whilestatements in modern byte-data function bodies, so every declaration inexamples/text_analytics.spxis available through the bounded context route when the full graph succeeds. -
Pinned source-verifier rejection of unsuffixed
i64literals mixed withusize,u8, ori32arithmetic.SPX-T208now has explicit regression coverage for the suffix help before HIR or a backend can observe the input. -
Rejected a trailing semicolon after a block's value with the existing
SPX-P106expression-statement diagnostic. Canonical formatting no longer accepts and silently removes that source token. -
Offline language/library help now shows the compiler-bundled dependency route and each
std.*package's required consumer profile.semaprax newwrites the extensible table scaffold and the calculator demonstrates a stable-ID import fromsrc/core.spx. Table-manifest structural diagnostics report independent failures together and point to both scaffold routes. -
Project command operands now accept shell-natural
.and..spellings, including--manifest-path, consistently across check, run, test, lock, build, and new-project verification. Manifest-declared source paths retain their strict no-alias rule. -
Scalar Project v1 now retains module-local record declarations through HIR replay, while aggregate function boundaries fail at their declaration with actionable
SPX-G174guidance. The language card and generated project agent guide now state that boundary explicitly. -
Workspace declaration replay now retains classes as
Classrather thanRecord, includes their owned methods in the independent fact map, and names the first differing stable identity in genuineSPX-G173disagreements. Class-bearing projects can therefore reach their ordinary execution lanes. -
Source byte-data capacity verification borrows the ordinary-function index instead of cloning its full
BTreeMaponce per function, and rejects the 4,096-function bound at the start of declaration verification with the first excess declaration's source span. -
Canonical formatting now emits comment hooks for variant cases, variant payload fields, resource lifecycle items, and their closing braces. Comments in those bodies survive exactly once and formatting is a fixed point.
-
semaprax patchrejects every surplus positional argument or unknown option with usage status 2 before reading or rewriting the source, matching the strictimpactandreviewcommand grammars. -
fmt --checkreports the first differing line and documents compact single-linematchprojection;resolvevalidates its target before dependency availability, andnew .now explains that an explicit project name is required. -
CLI success and usage surfaces are now consistent for automation: successful
check --jsonemits a verified envelope,fmt --checkaccepts flag-first order,lock/resolveprint one recovery hint, and bare native-callable output names resolve against the current directory. -
testtreats missing operands as domain failures rather than usage errors,--max-stepsuses one closed usage-error range, and failed project summaries distinguishmainfrom their consistently counted named cases. -
Added a replayable Agent Payment Graph and unified injected-host harness that compiles one AgentDefinition into Runtime v1, binds an independently admitted Economic Agent Policy, and carries a completed canonical Payment Intent into the existing approval/custody/broadcast/reconciliation state machine. The graph binds all three semantic digests and grants no model, wallet, signing, network, journal, approval, custody, or publication authority.
-
Added exact project dependency inputs: scalar Package Manifest projects can replay and link a complete project-local Subject-v3 SEMAPRAX closure across check, test, run, analysis, and build routes, while generated Native Rust SDK packages carry exact Cargo versions/features and deterministic crate re-exports. An offline executable consumer now proves that a non-allowlisted crate can implement a typed
import rust fnadapter and return its result through a SEMAPRAX export. Both routes remain bounded, authenticated, and free of implicit registry or network authority. -
Deepened four existing standard-library packages without widening ambient authority:
std.timerounds durations upward and measures elapsed milliseconds,std.pathexposes parent and extension boundaries,std.data.csvvalidates quote placement in complete records, andstd.data.tomllocates assignment delimiters outside simple quoted keys and comments. Each addition is covered by the package examples and conformance cases on every standard-library backend. -
Added
std.data.tomlas the fourth executableportable-tier package, with allocation-free bare-key validation, blank/comment line recognition, and first assignment-delimiter location over borrowed bytes. Full keys, values, tables, decoding, validation, and encoding remain Missing. -
Added
std.pathas the third executableportable-tier package, with allocation-free inspection of canonical slash-separated path bytes for absoluteness, trailing separators, nonempty segment counts, and filename position. Typed values, normalization, traversal policy, safe joining, and host-platform conversion remain Missing. -
Added the second executable
portable-tier package,std.url, with ASCII scheme and unreserved-byte classification plus percent-triplet validation and decoding. The package depends onstd.encoding; a consumer that names onlystd.urlreceives both bundled sources through deterministic transitive closure, with no acquisition authority. -
Added the first executable
test-tier package,std.test, with scalar equality predicates and deterministic 0/1 or caller-selected failure status helpers for the current Project return-code test model. It is portable and compiler-bundled; rich diagnostics, fixtures, property tests, fuzzing, and snapshots remain Missing. -
Added the first executable
portable-tier data-format package,std.data.csv, with allocation-free single-record field counting that respects quoted commas and escaped quotes, plus balanced-quote validation. It runs on every standard-library backend and is available through the closed compiler-bundled dependency inventory; streaming, typed fields, dialects, and writing remain Missing. -
Added the eighth executable
core-tier package,std.time, with nonnegative millisecond conversion and decomposition, deadline comparison, remaining-duration calculation, and saturating addition. The package is effect-free and portable; clock reads, sleeps, timers, and other authority-bearing time operations remain explicitly Missing. -
Added the seventh executable
core-tier package,std.random, with a pure Park–Miller generator, total seed normalization, bounded deterministic advancement, and range sampling. Secure randomness remains unavailable without a future explicit capability boundary; the deterministic package runs on the interpreter, native C11, and Core Wasm lanes and is included in the closed compiler-bundled dependency inventory. -
semaprax testnames atest_-prefixed function that is not a case (it takes parameters, does not returni64, or has no explicit@id) with anote:line on stderr instead of skipping it silently; the JSON envelope is unchanged. The generatedAGENTS.mdnow explains the test module and named cases, so the scaffold capsule digests change. -
semaprax project-scaffold --layout tablesemits a new project whosesemaprax.tomluses the extensiblesemaprax.manifest.v1table layout, under a new additive capsule schemasemaprax.project-scaffold.v3(Public Project Scaffold Capsule v3). The default (--layout frozen) is byte-for-byte the shipped v2 capsule with the frozensemaprax.project.v1manifest, so no existing scaffold byte or digest moves. The calculator's table layout adds a separate core module and imports its exported function by stable identity; both layouts lower to the same Project v1 contract.tests/project.rs::scaffoldand::scaffold_clipin it. -
Added the sixth executable
core-tier package,std.encoding, with bounded ASCII-byte classification, hexadecimal value conversion, byte-pair decoding, lowercase/uppercase hex digit encoding, standard Base64 digit conversion, and unpadded four-digit decoding to a 24-bit value. Its contracted examples and conformance suite run on the interpreter, native C11, and Core Wasm lanes, and package manifests can import the compiler-bundled module at version0.1.0without acquisition authority. -
Extended
std.byteswith length-aware suffix matching over borrowed byte slices, including empty, exact, proper-suffix, prefix-only, and longer-suffix conformance cases on every listed backend. -
Extended
std.textwith exact, length-aware borrowed UTF-8 equality and direct empty, Unicode, embedded-NUL, equal, and unequal interpreter, native-C11, and Core-Wasm assertions. -
Project manifests can now link the closed compiler-bundled
std.*inventory at version0.1.0without cache, network, or acquisition authority. Exact, tilde, and caret ranges are checked, transitive standard dependencies are expanded deterministically, and one Project can link multiple packages by stable identity; ordinary resolved-package builds remain open. -
The Useful Text workspace boundary now links exact non-escaping
borrow strproviders across files, enabling the new partialstd.textpackage with byte-length, emptiness, prefix, and substring operations across interpreter, native C11, and Core Wasm conformance lanes. -
The full toolchain's held-parent
newauthority now admits the exact six-file library scaffold as well as the calculator, preserving fixed inventories, create-new writes, no-replace publication, and post-publication authentication. -
semaprax lockandsemaprax resolveaccept[<dir>|semaprax.toml], resolving directory arguments to<dir>/semaprax.tomland defaulting to./semaprax.tomlwhen omitted, matchingcheck,fmt,run,test, andbuild. Outside a project without arguments, both commands attach the standard missing-manifest guidance hint.tests/project.rs::project_lock_v1andtests/project.rs::dependency_resolution_v1pin the ergonomics. -
Canonical project comments now remain valid inputs to Project semantic-graph construction and persisted frontend-cache replay, while the parsed semantic program remains comment-free. Project-format and install-guide fixtures use native path spelling on every host and explicitly create the required lock before executing a freshly formatted project.
-
semaprax lockgains--emit-interfaceand--compare-interface <baseline.json>: a fine-grained per-export compatibility for Project v1 scalar packages.--emit-interfaceprints the scalar WIT interface descriptor to store as a baseline;--compare-interfacediffs the current project against it and names exactly which export was added or removed, or had its parameter or result type change, exiting nonzero on a breaking change. It is purely additive and does not touch thesemaprax.lockformat; the coarse--comparestays.tests/project.rs::project_lock_v1and thescalar_wit_compareunit tests pin it. -
The
useful-data.v1byte-data profile admitsrequiresandensurescontracts throughout its function inventory. The Core-Wasm data emitter walks contracts with bodies and lets a false contract publish status 9 or 10 through the data status global, the generated facade already maps those toSemapraxDataErrorin thesemaprax.contract.v1domain, and the npm semantic recipe renders contract lines so replay binds them byte for byte. Functions with effects are still rejected.std.bytesships on the profile with byte conversion, guarded indexing, search, counting, ASCII classification, equality and prefix tests, and endian reads, all contracted and run on every lane; the catalogs are regenerated. -
semaprax testruns everyfn test_<name>() -> i64of the manifest-declared test module as a named case aftermain, each with its own step budget, and names each failing case with its outcome (failed calculator.tests.test_add: returned 2) followed byproject tests failed: K of N in <module>and ahelpline; a failingmainis reported the same way instead of the bareproject tests failed with result N. Thesemaprax.project-execution.v1test envelope gains an always-present additivecasesarray under the unchanged schema string and payload-digest domain, andproject::verify_execution_envelopeverifies it. Entry envelopes and the passing-test line without cases are unchanged. Project Test Cases v1 owns the rule andtests/project.rs::developer_looppins it. -
A violated
requiresorensuresundersemaprax runorsemaprax testnow names the failing function's stable id, the clause kind and source text, and the call's argument values, both as two indented lines after the unchanged language-status line and as an additivefailuremember of thelanguage_failureoutcome. The interpreter records the detail at the failing frame (src/interpreter/failure_detail.rs); the status object, cleanup, and exit status are untouched, and the native path is unchanged. The legacy resolved-entry evaluator moved verbatim intosrc/interpreter/resolved_case.rsso a named function can be evaluated without being the entrypoint. -
semaprax checkon a project whoseusenames a module no listed source declares keepsSPX-G172and its message and adds ahelpline: it names the unlisted.spxfile that declares the module and thesourceskey insemaprax.toml, or says that no listed file declares the module. The hint is added by the project loader insrc/project/source_hint.rs, so human and JSON diagnostics agree; Project Manifest v1 owns the rule andtests/project_cli_v1.rspins it. -
scripts/quality.sh changedroutes CLI and editor changes narrowly. Paths undersrc/cli/andsrc/bin/, plussrc/cli_driver.rsandsrc/main.rs, classify ascli-surfaceand append atest-cligate that runs the CLI harnesses of the standalone package and the full toolchain; paths undereditors/classify aseditor-adapterand appendtest-editor, which runs the extension'snode --testsuite and the documentation harness. Both follow the fixedchangedgates in one order, and the executor rejects a repeated or reordered surface gate. Other paths route as before,full's gate list is unchanged, and the plan schema stayssemaprax.quality-route.v2;tests/quality_routing.rspins the routes and the executor's dispatch. -
AGENTS.mdforbids pointing a worktree's Cargotarget-dirat another worktree or at any path a different checkout's tests depend on, and the development guide gives the privateCARGO_TARGET_DIR,CARGO_INCREMENTAL=0, andCARGO_PROFILE_TEST_DEBUG=0setup with the disk a full gate needs. -
The VS Code extension checks on save. Saving a
.spxfile orsemaprax.tomlruns the user-selectedsemaprax.compilerPathbinary ascheck <nearest semaprax.toml or file> --json, maps each JSON diagnostic to an editor diagnostic (code: messageplus the help on a new line, range from the reported line and column), and clears entries the re-check no longer reports.SEMAPRAX: Check Projectruns the same check explicitly and names the setting to fill when none is set; the machine settingsemaprax.checkOnSave(defaulttrue) turns the save trigger off. The child is spawned without a shell, capped at 4 MiB of output and 30 seconds, and writes nothing. Activation addsonLanguage:semapraxand the new command;editors/vscode/diagnostics.jsholds the pure logic andtest/diagnostics.test.jscovers it. -
The
SPX-J121build rejection for a manifest with[dependencies]now points atsemaprax resolve --writeto resolve and pin the dependency graph, instead of claiming no resolution route exists; only a build that links resolved dependencies is still unimplemented. The agent quick reference gains a short locking-and-dependencies note coveringlockandresolve. -
semaprax resolvegains--writeand--verify:--writepins the resolution evidence tosemaprax.resolution-<target>.jsonbeside the manifest, and--verifyre-resolves and confirms that pin still holds byte for byte, failing closed withSPX-J126when the cache no longer produces the recorded selection. Because resolution is deterministic the pin is a stable per-target dependency lockfile a CI job can check.tests/project.rs::dependency_resolution_v1pins it. -
semaprax lock <manifest> --compare <baseline.lock>classifies a project's current interface against a baselinesemaprax.lockand prints asemaprax.project-lock-compatibility.v1verdict, exiting nonzero on a breaking change so a CI gate fails. A removed export, a widened required capability, a removed target, a changed package name or contract, or a changed interface descriptor digest with the same export set are breaking; an added export, a narrowed capability, an added target are not; a pure display rename or a version-only change is not. It is a coarse project-level counterpart to the offline Compatibility Evidence;tests/project.rs::project_lock_v1pins it. -
semaprax resolve <manifest> --target <native64|wasm32> --cache <dir>resolves a project's[dependencies]against a local content-addressed cache of Subject-v3 envelopes and prints the offline resolver's evidence (Project Dependency Resolution v1). It selects one version per package that satisfies the manifest ranges and their transitive requirements, deterministically and per target, reading the cache as an explicit effect with no registry, acquisition, or build. Cache files are named by their subject digest, so a misfiled subject is rejected;SPX-J126covers missing dependencies, a target outside the matrix, and cache faults. Manifest dependency names are now dotted lowercase package identities matching the resolver, soexamples.meaningis admitted;tests/project.rs::dependency_resolution_v1is the gate. -
Cross-platform CI now preserves the exact verifier hint while accepting native line endings in CLI help, and deep standalone-String Wasm planning uses narrow recursive walkers so the contracted nesting depth fits the default macOS test stack. Supply-chain command dispatch also moved into its audited submodule to restore the CLI driver's source-size budget.
-
The help catalog test's dispatcher inventory lists the
lockcommand that landed with the deterministicsemaprax.lock, so the catalog and dispatcher closure check passes again in both executables. -
semaprax help libraryprints the generated standard-library catalog, the fourthhelpshape besidehelp language, so an installed compiler lists everystd.*function and contract offline. -
Project-shape rejections now carry their fix: a Project v1 manifest whose six lines are missing, extra, or unterminated lists the exact lines in order, an
entrythat names a module withoutmainexplains theentrykey, and an unknown function with no near name shows theuse function @id(…) from module as name;import line.tests/project/manifest_hints.rspins the manifest and CLI cases. -
semaprax fmtaccepts a project directory orsemaprax.toml, likecheck,run,test, andbuild: it formats everysourcesentry in manifest order through the comment-preserving projection, parses every file before writing any, and with--checkprints one<path> is not canonically formattedline per drifting file. Previouslyfmt .failed withcannot read .: Is a directory.tests/projections/fmt_comments.rsandtests/project_cli_v1.rspin it. -
semaprax new --template librarycreates the scaffold's library template in the standalone compiler; the success line is nowcreated <template> project <destination>, and an unknown template is rejected withexpected calculator or library. The full toolchain'snewstill publishes only the calculator inventory and refuseslibrarywith a message naming the standalone route.tests/project/new_cli.rspins the library project's bytes and that it checks, tests, runs, and is canonical. -
semaprax patch,patch-with-evidence, andpatch-with-evidence-v2keep the file's//comments: the patched candidate is parsed with its comments and rendered through the same projection asfmt, so a comment above a renamed function stays above it and the patched file passesfmt --check. Graph revisions and evidence digests are unchanged. Canonical comments v1 lists the preserved routes;tests/semantic/patch.rspins the regression. -
semaprax lock <manifest>renders the deterministicsemaprax.lockbeside a project (Project Lock v1): the canonical manifest and its contract, the project revision as the program root, every source file's revision and digest, the retained interface descriptor digest, the declared target matrix, required capabilities, the compiler, and the resolution policy.--writepersists it atomically and--verifyre-renders and compares bytes, failing closed withSPX-J123when a source, manifest, or compiler drifts and naming the drifted fields. Like every package operation the lock is explicit and never touched bycheck;tests/project.rs::project_lock_v1is the gate. -
semaprax fmtkeeps//comments. The lexer records each comment's position, and the canonical formatter prints it above the item it preceded or right after the item it followed, at that item's depth; formatting is idempotent and a comment-free file formats to the same bytes as before. Onlyfmtrestores comments;patchand other rewriting transactions still emit comment-free text. Canonical comments v1 owns the placement rules,src/format/comments.rsandtests/projections/fmt_comments.rspin them, and the formatter's capacity accounting moved verbatim intosrc/format/capacity.rs. -
Every generated project now carries an
AGENTS.md: the commands to check, test, run, format, and build it, and the rules that differ from other languages, written for coding agents and people alike. The scaffold capsule becomessemaprax.project-scaffold.v2with five files and a new digest domain, the generatedREADME.mdpoints atAGENTS.mdand uses directory operands, and bothnewroutes publish the same five files. The library template gains the same file. The_v1API names are unchanged; the schema string and digest domain are v2. Public Project Scaffold Capsule v2 owns the contract. -
semaprax new <destination>now works on the standalone compiler. It derives the same calculator template as the full toolchain, refuses anything but a fresh destination under an existing real directory, writes every file with create-new semantics, reads the files back, authenticates the project, and prints the same success line. The full toolchain keeps its held-parent staged publication; Standalone project creation v1 owns the bounded route and its non-claims,tests/project/new_cli.rspins it, and the install guide, quickstart, and README no longer require the full toolchain to create a project. -
semaprax.tomlgains one extensible table layout,semaprax.manifest.v1(Package Manifest v1):[package],[modules],[exports],[command],[capabilities],[dependencies], and[targets]tables lower onto the frozen Project v1-v11 profile contracts, so every project route, descriptor, and generated artifact is unchanged and only the manifest bytes differ. Reserved and unknown tables or keys reject withSPX-J120, a declared dependency fails every build closed withSPX-J121, a build target outside[targets] matrixrejects withSPX-J122, and a non-canonical manifest names its first differing line. The frozen layouts remain admitted byte-for-byte;tests/project.rs::package_manifest_v1is the gate. -
The standard-library contract and the agent quick reference explain how a Project consumes a
std.*module today, by vendoring its library file and importing by@id; the gate vendors every package into a fresh project and runs its examples and conformance there. -
std.numgains checkedpow,isqrt,digit_count,is_power_of_two,log2_floor, andlog10_floor, each with contracts and conformance checks on every lane; the catalogs are regenerated. -
semaprax project-scaffold --template libraryprints a library package in the standard-library shape:src/lib.spxwith one contracted function,src/examples.spxas the entry, andsrc/tests.spxas the conformance suite, all checked and tested at derivation and replayable only as the library template. The calculator capsule bytes are unchanged, and the privatenewstill admits only the calculator inventory. -
Added the standard-library contract, Standard Library v1, and its first
core-tier packages understd/:std.core(ordering as-1/0/1, extrema, clamping, range membership,boolconversions and connectives),std.num(sign, absolute value, parity, Euclidean division and remainder, greatest common divisor), andstd.num.overflow(overflow predicates and wrapping and saturating arithmetic). Each package is a Project whose entry is its examples module and whose test module is its conformance suite;tests/project.rs::standard_libraryruns both on the interpreter, native C11 at O0/O2, and Core Wasm under Node, checks identities and conformance coverage, and generates the human catalog andstd/catalog.json. -
The Workspace Semantic Graph builder pre-bound now charges structural bytes, string contents, and per-shape identity slots separately instead of the
Tryand string rates for every node. The 16 MiB budget and every reported field are unchanged, butused_builder_bytesvalues move, so the frozen known-answer digests in the workspace change, operations, structural-change, and analysis tests, the workspace CLI harness, and the browser fixture'sproject_graph_digestanswers were re-pinned. Before the split a 4.9 KiB module of twenty scalar functions was rejected withSPX-G171; thestd/packages are the regression. -
The workspace CLI tests that assert exact command usages now read them from
semaprax help all, the exhaustive catalog, instead of the guided one-screen--helppage that replaced it. -
check,run,test, andbuildinvoked with no input outside a project now attach a hint to the unchangedSPX-J102missing-manifest diagnostic naming the three admitted inputs: a.spxfile, a project directory, or running from inside a project. An explicitly named manifest is unchanged. -
semaprax help languageprints the compiler-checked agent quick reference byte for byte from the installed binary, so an agent or developer without the source checkout can read the admitted shapes, the diagnostics foreign habits trigger, and their fixes offline. Both help harnesses pin the bytes and the guided page lists the form. -
The VS Code extension now contributes the
.spxlanguage declaratively: a TextMate grammar and language configuration give highlighting,//comment toggling, bracket matching, and auto-closing pairs without starting a session or running code. The documentation gate checks that the grammar names every keyword the parser recognises and every literal suffix. -
Checking one module of a multi-file project on its own now explains the next step:
SPX-G172(the module imports other modules) andSPX-T105(the module has nomain) keep their codes and messages and gain a hint namingsemaprax check <project-dir>. -
check,run,test, andbuildaccept a project directory as their positional operand and select thesemaprax.tomlinside it, sosemaprax check examples/calculator-projectandsemaprax run .work without naming the manifest. Inert.components are removed before the manifest is authenticated;--manifest-pathis still taken literally, and a directory without a manifest reports the ordinarySPX-J102for that path instead of an unreadable directory. Scoped help and the catalog show<dir>. -
A source file that does not start with its
moduleline now carries a fix hint under the unchangedSPX-P104expected `module`diagnostic, naming themodule dotted.name;header a pasted or truncated file is missing. -
semaprax --help,help,-h, and the empty invocation now print a guided one-screen overview: the commands for writing, checking, running, inspecting, and changing programs, grouped by task with a one-line purpose each, bounded to 2048 bytes and filtered by the executable's capability class. The former 7 KB exhaustive page moved to the newsemaprax help allform with its bytes otherwise unchanged; scoped help, typo guidance, and recovery hints are unchanged. Guided CLI Help v4 owns the contract and the standalone and full-toolchain help harnesses pin it. -
A borrowed view taken directly from a string literal, an array literal, or a call result (
str_as_bytes("hi"),array_as_slice([1u8])) now names theletbinding step in itsSPX-T266help, and the README routes coding agents to the agent quick reference. -
More first-attempt habits now carry their fix:
struct/enum/pub/constdeclarations, a missing trailing,after the last field or match arm,x += 1, a missing->result type or a()unit type, an uninitialisedlet,=in anifcondition,a[0]indexing,Some(1)/Noneshorthand, a method call on astring, byte, record, or variant value, and foreign type names such asString,int,double,boolean, orVec. Codes and messages are unchanged;tests/language/foreign_syntax_hints.rsandtests/language/verifier_hints.rspin each case. Type syntax parsing moved verbatim intosrc/parser/types.rsto keep the grammar root under budget. -
An owned
stringor byte value passed to a user function'sborrow strorborrow Slice<u8>parameter now names the view conversion in itsSPX-T205help, the parser's expression-statement hint shows the admittedlet _ = …;discard, and the agent quick reference explains that a failing project test reports only its return value. -
Verifier diagnostics now carry fix hints for the type-level habits an agent brings from other languages: an unknown function names the nearest declared or compiler-owned function (
did you meanstring_len?) or, for the print family, the one admitted output route; a generic call or generic type without explicit type arguments shows theid<i64>(…)andOption<i64>::Some { value: … }shapes; an unsuffixed integer literal against ausize,i32, oru8operand names the suffix to write; and an ownedstringhanded tostr_as_bytes, a byte operation, orstdout_writenames thestring_as_str/str_as_bytesconversion. Codes, messages, and spans are unchanged, and the iterative verifier and the test-only oracle share the helpers insrc/source_verify/hints.rs;tests/language/verifier_hints.rspins each case and the no-hint baselines. -
Fixed the stale descendant expectation in
tests/language/generic_records.rs. Admitting concrete generic owned variants madeMaybe<Bytes>a legal standalone owned value, so the descendant ofown Box<Maybe<Bytes>>stopped reportingSPX-T268on its own. The shape itself stayed closed throughout - the record carrier reportsSPX-T223in source verification and resolved-HIR classification returnsOutsideProfile, matching the identical case already pinned intests/owned_data/nested_generic_owned_record_frontend_hir.rs- so no admission changed. The test now asserts carrier closure, pins the standalone variant admission that explains the descendant's silence, and adds two descendant cases that must still reportSPX-T268: a variant without a persistent@idunder the same carrier, and an admitted owned variant stored as a declared record field.
0.3.5 — 2026-09-04
-
Fixed the owning
add_record_fieldBytes lane, which emittedbytes_copy(array_as_slice([...]))and was rejected by its own admission: the indexed byte-data contract never lets a view borrow an array temporary. A migrated constructor now materializes its owner as{ let spx_field_bytes_0 = [..]; bytes_copy(array_as_slice(spx_field_bytes_0)) }, a block that occupies exactly the appended initializer position, binds a reserved name proven absent from every retained canonical source, and adds no statement to the enclosing body. The record-field, variant-case, and ownership-delta candidate cases for owned Bytes and String fields now execute and pass; three of them also corrected assertions that contradicted canonical@idformatting, the checkedbytestype identity key, and theSPX-S113reservation of compiler-owned function spellings. -
The Project owned-data workspace linker now links generics exactly. It walks the entry and public-root closure over
(callee, type arguments)call sites, selects the one authenticated instance a generic call derives, continues through that instance body's callees, and carries the retained templates and instances into the linked program with their Phase-A facts and canonical type-parameter metadata. An unreferenced template or instance is still not linked, a call with no authenticated instance fails closed, and an instance reachable only from another instance body is rejected. The public API descriptor admits a template as an interior closure member under the same effect-, contract-, and import-free obligations, and private Wasm lowering emits instance bodies under their generic execution identity while charging a generic call edge the largest retained instance frame. This is compiler admission; no runtime execution of a retained instance is claimed. -
Added a Unix-only signed doctor generation store with lifetime-held root authority, exact signed-byte replay, no-adoption installation, settled generation publication, cooperative expected-current activation/rollback, and fail-closed authenticated inert-stage recovery. Focused fault and race evidence covers substitution, pre/post-pivot uncertainty, unsafe inventory, and foreign-byte preservation; it does not claim a kernel CAS against an uncooperative same-principal writer, Windows support, CLI activation, or production promotion.
-
Added automatic host-library composition of immutable candidate/draft archive storage and the semantic-retention registry. Exact held-root replay can resume an archive orphaned before checkpointing, distinguish an already retained subject without advancing again, and reject cross-kind or reminted selectors. Canonical replay receipts and closed recovery outcomes carry no source, Git, approval, GC, warm-HIR, or publication authority.
-
Added an authority-free Project v8 promotion receipt model. Its canonical, bounded replay binds one exact commit, baseline and display-rename subjects, eight artifact digests, and a closed pass-only fifteen-gate platform/tool inventory. The receipt records caller-owned observations only; it neither executes gates nor establishes hosted success, provenance, support, package publication, or WP-15 completion.
-
Parser diagnostics now carry fix hints for habits carried over from other languages:
return,for/loop,else if, an expression statement, a missingelse, a tuple literal, aSome(x)pattern, and awhilebody,ifbranch, or function body that ends without a value. Every hinted diagnostic keeps the stable code the grammar already produced and no hint admits new syntax;tests/language/foreign_syntax_hints.rspins each case. Match-pattern parsing moved verbatim intosrc/parser/patterns.rsso the grammar root shrinks under its recorded module-size budget. -
Added the compiler-checked agent quick reference: one page of admitted language shapes, the compiler-owned function table, the diagnostics that habits from other languages trigger with their fixes, and measured guidance on when
graph,context, or the source itself is the cheapest representation.tests/documentation.rschecks every SEMAPRAX block on the page: unmarked blocks must verify cleanly and already be canonical, and marked blocks must produce exactly the named diagnostic code.AGENTS.mdand the documentation index route agents to it before the tour. -
Added an authority-free Project-v8 C++ owned-data package derived from the exact replayed public descriptor and existing native provider. Its bounded C11 boundary and thread-bound, noncopyable C++17 wrapper enforce cumulative borrowed-input and owned-output limits, poison preservation, copy-before- drop ordering, certain close before exceptions, and fail-stop cleanup uncertainty. Focused local C11/C++17 O0/O2 consumers cover exact/+1 bounds, recovery, hostile handles/tags and injected copy/drop/close failures; target activation, MSVC/cross-platform ABI, distribution and support remain open.
-
Executed the generated Project Agent Transport v6 Python, Rust and provisioned Node/TypeScript codecs against retained Project v8-v11 sessions. The Rust codec is byte-pinned and compiled into the owning harness rather than trusting ambient Cargo state; process-backed codecs run with a closed environment and bounded direct-child settlement. Exact profile/schema/ subject/build binding and the full cross-profile hostile matrix remain local evidence, not a packaged, registry, hosted or general process-authority claim.
-
Hardened signed Linux doctor distribution construction. Archive and release utilities now run through a closed deterministic environment, hostile archive/loader variables cannot change bytes, and independent unpack replay uses the explicitly admitted gzip and tar tools. The script now states its trusted-shell and immutable absolute-tool ancestry precondition; it does not claim held-tool execution or concurrent tool-path mutation resistance. The provisioned child also detaches from the old root into an authenticated, empty, read-only 64-KiB tmpfs before its held launcher executes.
-
Added project-route evidence for the Bounded Language Command I/O v1 borrowed-
strargument root. The existing regressions reassembled the committed v7 sources into one module by hand, so nothing pinned the routecheck,run, andtestactually take: all four committed spxgrep manifests now admit and execute through the manifest route, and a mutable command-argument local still fails closed there. Removing the command-argument arm from checked-HIR validation fails all three cases, so the gate is load-bearing. The examples index no longer records the argument root's rejection as expected behavior. -
Added the authority-free C++ scalar package v1 projection. An explicit stable-ID selection now produces a bounded canonical envelope containing a C++17 header and separately linkable C11 provider over the existing Copy- scalar native ABI. Verification treats hashes only as transport integrity: it replays embedded canonical source through parsing, verification, admission and native emission, then requires exact reconstructed Shim, header and provider bytes, rejecting self-consistent remints and appended code. The local owning gate compiles separate translation units and executes success plus failure-slot preservation; aggregate/resource/string ownership, exceptions, maintained packaging, cross-platform conformance and support promotion remain open.
-
Fixed the combined current-main regression batch: command UTF-8 results now retain authenticated borrowed-string provenance through immutable locals, nested owned-record backends distinguish records that actually contain owned bytes from other resource-free records, and Project cache/signature regressions track the current compiler-owned function and borrowed-view contracts. Oversized implementation and test roots were split into audited sibling modules without raising any module-size budget.
-
Added a getting-started layer over the existing references: a language tour whose every code block is a gated verbatim excerpt of a committed example, an examples index recording what each example demonstrates and which command was observed to succeed on it, an install guide owning the two-CLI routes and a reproduced first-failure table, and a first-contribution walkthrough sequencing one change through the existing read order, harness conventions, and quality profiles. Each document is bound to executable gates in
tests/, and the observed evidence is local to one host and one build. -
The README browser-package walkthrough built an exported-scalar package and handed it to
scripts/verify-web.mjs, which callssemaprax_main; that package has noapp.mainentry, so the documented sequence failed. The README now names the six-export build and the scalar-export verifier that accepts it, and a gate parses the documented commands out of the README and runs them. -
Added a candidate-bound ABI delta that compares manifest-selected callable signatures, reachable concrete record/variant shapes, checked type facts and already-retained native/Wasm structural projections. Exact verification replays the candidate; compatibility, runtime, deployment and external consumers remain explicitly unassessed. Regressions are authored and unrun.
-
Extended ownership deltas with explicit source-nominal rows, ordered member identities, resolved types and available checked Copy/drop/resource/layout facts. Generic and unsupported/incomplete type closures remain explicitly unavailable rather than receiving inferred facts. Regressions are authored and unrun.
-
Extended the package-consumer migration proposal with one exact authenticated
own Bytestoborrow Slice<u8>provider and caller transition. Calls stage the original bare owner before deriving its view, preserve ordinary cleanup, and require complete candidate-era package replay; discovery, writes and compatibility remain outside the artifact. Regressions are authored and unrun. -
Added bounded
add_variant_casefor one appended owningBytescase on an eligible originally Copy variant. Exact old member prefixes and checked Copy-to-needs-drop facts survive replay and conservative rebase; String variants, handler synthesis and ABI compatibility remain unsupported. Regressions are authored and unrun. -
Known commands that reject invalid arguments now point directly to their scoped
--helpusage. Recovery hints respect the standalone/full-toolchain capability boundary and leave unknown-command diagnostics unchanged. -
Human compiler diagnostics now include terminal-safe
path:line:columnlocations when source paths and spans are available. Pathless rendering and machine-readable JSON remain unchanged. -
Added the bounded Language-Native Agent Object v1 compiler slice. Canonical AgentDefinition documents assign stable IDs to the six agent types and six harness operations; compilation emits a deterministic digest-bound AgentGraph and derives a canonical Agent Runtime Profile v1 from structured model, tool, policy, and limit material. The fixture projection is byte-identical to the frozen Runtime v1 known answer and executes through the unchanged
Agent<H>kernel. AgentGraph exposes model, context, proposal, capability, effect, limit, terminal, and evidence contracts; represents the opaque single-use authorization andAgentStepboundaries; and supports exact definition/profile/graph bundle replay. This adds no.spxsyntax, generated proposal grammar, transition execution, effects, durability, provider transport, or authority. -
Added bounded, deterministic typo guidance for unknown CLI commands. The nearest unique command within edit distance one or two is suggested only from the executable's capability-visible static catalog; unrelated, ambiguous, non-ASCII, and over-limit names retain the prior diagnostic.
-
Extended
extract_functionwith one exact whole body-local owningBytes/Stringcapture. The compiler authenticates source, retained HIR and cleanup facts before mutation, transfers the owner once at its original expression position through an owning helper parameter, and admits an already-supported whole owned result. Conditional, projected, borrowed, shared, repeated, contract, entrypoint, export and external-consumer cases fail closed. Regressions are authored and unrun. -
Added an authority-free package-consumer migration proposal for one exact Copy-scalar signature append. It authenticates the caller-supplied baseline corpus, rebuilds canonical migrated sources and candidate-era provider evidence, and requires independent package replay before returning the proposal. It performs no discovery, write, installation, compatibility inference or publication. Regressions are authored and unrun.
-
Extended
add_record_fieldwith bounded owningstringandBytesdefaults for originally Copy, drop-free, sized resource-free records. Every authenticated constructor receives a fresh appended owner, Bytes defaults use compiler-owned copy operations, target record patterns fail closed, and independent replay requires the exact Copy-to-needs-drop transition. Regressions are authored and unrun. -
Added v5
draft/archive-storeover the startup-held immutable archive store. The host independently replays the exact image and retained draft before storage and may checkpoint the successful receipt through the distinct retention registry; registry failures never erase or deny the stored draft. The route grants no restore, completion, source, approval, publication, deletion or garbage-collection authority. Regressions are authored and unrun. -
Closed the
graph <file>command grammar. Unknown options and extra operands now reject with status 2 before the compiler reads or verifies the source. -
Closed the
fmt <file> [--check]command grammar. Unknown options, duplicate--check, misplaced flags, and extra operands now reject with status 2 before the formatter reads or rewrites the source file. -
Added candidate generic-template display renames with exact retained-instance preservation. The compiler authenticates the source template and bounded concrete instance inventory before mutation, migrates stable-ID-bound local typed calls, preserves imported aliases, and requires normalized checked HIR, exact type arguments, ownership, cleanup and loan plans to survive full Project replay. This is not generic signature evolution or runtime evidence. Regressions are authored and unrun.
-
Added a bounded owning-result signature lane that wraps an exact whole
BytesorStringresult in an existing visible one-field owning record. Provider construction happens once at result commit and every authenticated local body caller projects and moves the sole field after ordinary left-to-right argument staging. Contracts, entrypoints, manifest exports, zero-caller cases and external/package migration remain excluded. Regressions are authored and unrun. -
Extended static interface implementation across Project modules. An explicit destination may import the exact receiver, protocol and implementation functions through stable IDs and deterministic aliases; the new protocol import kind remains static-conformance-only and is excluded from runtime HIR, Graph and operation sidecars. Generic/owned receivers, runtime witnesses and dynamic dispatch remain unsupported. Regressions are authored and unrun.
-
Added an opt-in v5
candidate/archive-storeoperation backed by a private startup-held immutable archive store. Requests select only an already retained complete candidate; the host independently prepares/replays it, stores it, and automatically checkpoints the successful typed receipt through an optional distinct retention lifecycle. Registry stale, failed, uncertain or poisoned outcomes remain accountability data and never roll back storage. There is no restore/current/source/approval/publication/delete/GC authority. Regressions are authored and unrun. -
Added an exact candidate-bound function-reference rebind. It independently derives the immutable base and final images, resolves the canonical base reference through the ordinary exact-image path, and delegates conservative stable-ID selection to the existing image rebind before returning a fresh destination reference that still requires normal replay. It grants no migration, compatibility, source, execution or publication authority. Regressions are authored and unrun.
-
Added a paired candidate analysis-coverage change report. Optional exact base/final boundary bundles are independently authenticated through their existing deployment, generated-file and external-API declaration owners, enabling real categorical advances, regressions and same-status unknowns in those three areas. Runtime and external-consumer rows remain explicit source-only invariants; completeness and compatibility stay
not_assessed, and every observation flag remains false. Regressions are authored and unrun. -
Attached the retention lifecycle coordinator to v5 embedding sessions under a once-only startup host selection. The session holds the authenticated registry root for its lifetime and records exact outcomes for typed receipts supplied after separate immutable stores succeed. V5 owns no subject-store operation, so request frames cannot select a root or trigger a checkpoint; wire-owned automatic storage remains open. Regressions are authored and unrun.
-
Added an authority-free task-economics normalizer over exact caller-supplied paired observation bytes. It authenticates the existing observation-v1 envelopes, complete metric and evidence-reference inventories and paired bindings, then emits only descriptive deltas for matching outcomes with
superiority: not_assessed. The v1 manifest's external-unrun Zero lane is rejected and remains explicitly unassessed. V5 exposes a smaller envelope-safe query through generated clients and MCP without invoking a model, tool, validator, artifact reader or publication path. Regressions are authored and unrun. -
Added a startup-selected retention lifecycle coordinator for successful typed image, candidate and draft store receipts. It holds the authenticated private registry root and metadata directory for its lifetime, advances the exact CAS cursor, and reports stale, failed, uncertain and poisoned states without ever denying or rolling back prior immutable-store success. It grants no subject restore, deletion, GC, source, approval or publication authority. Regressions are authored and unrun.
-
Added bounded top-level immutable reconstruction for the existing acyclic monomorphic owned-
Bytesrecord profile. Independent source/HIR admission, CleanupPlan v9, Graph v30/v31, interpreter, native C11 and Core Wasm retain exact stable field paths, left-to-right replacement completion, unchanged descendant transfers, replaced-old settlement and one atomic result commit. Dotted mutation, variants, generics, resources and public aggregate ABIs remain closed, and affected completion rows remain Partial pending the full promotion corpus. -
Added one candidate environment-consumer review that joins the complete source/environment review to an explicitly host-attached, authenticated candidate-era package graph. Exact Project, Workspace, graph, provider, source and target bindings advance only the external-consumer area to
partial; compatibility remainsnot_assessed. V5 exposes bounded chunks through generated clients and MCP input discovery without ambient consumer, runtime, registry or deployment observation. Regressions are authored and unrun. -
Added the rooted
string_as_str/core.string.as-strview over an exact unprojected owning String, with source/HIR/graph/cache loan provenance, interpreter, native and general Wasm lowering, and fail-closed standalone internal-String exclusion. Ordered signature evolution now converts a mixed set of one to eight exact owning Bytes/String parameters toborrow Slice<u8>orborrow str: complete source/HIR uses authenticate before mutation, all old caller arguments stage left to right, views derive in mapped order, and owners retain ordinary caller cleanup. Projected/temporary/escaping views, automatic package migration and compatibility remain excluded. Regressions are authored and unrun. -
Added a durable authority-neutral retention registry over successful typed image/candidate/draft store receipts. An explicit private Unix root chains immutable checkpoint/plan pairs through a canonical CAS
CURRENTcursor, authenticates exact interrupted stages, and recovers through held-directory descriptors. It performs no subject discovery, deletion, GC execution, source restoration, approval or publication. Regressions are authored and unrun. -
Added bounded exact recursive
match ownandmatch borrowfor the existing acyclic monomorphic owned-Bytesrecord profile. Independent source/HIR admission, canonical byte-slice provenance, CleanupPlan v8, Graph v28/v29, interpreter, native C11 and Core Wasm retain complete stable field-ID paths; owned destructuring preflights and commits every descendant together while borrowed patterns mint no owner or cleanup action. Variants, mutation, generics, resources, escaping loans and public aggregate ABIs remain closed, and the completion rows remain Partial pending the complete promotion corpus. -
Added one environment-aware candidate review that independently regenerates the complete source review and the three-declaration analysis-boundary bundle, validates their exact candidate/source/Project/Workspace/graph joins, and nests both bounded reports with exact revisions and byte hashes. V5 exposes bounded chunks through closed schemas, generated TypeScript/Python/Rust clients and MCP discovery. It carries no observation or authority and marks semantic compatibility
not_assessed. Regressions are authored and unrun. -
Added a descriptive external-API contract delta over exact retained base and candidate declarations. Canonical rows distinguish declared-inventory additions, removals and operation/schema digest changes while binding both Project, Workspace and graph revisions. V5 exposes bounded chunks through closed schemas, generated clients and MCP discovery. Provider/runtime/API compatibility remains
not_assessed; regressions are authored and unrun. -
Added a retention declaration-inventory command whose closed rows contain only visible subject identities and logical stored bytes. The compiler derives subject digests, imposes planner order internally, and emits the raw observation inventory accepted by the existing retention planner. It adds no store discovery, freshness, persistence, GC execution or authority. The implementation is authored and unrun.
-
Added exact candidate declarations for generated-file provenance and external API contracts. Canonical declaration bytes join retained source identities or explicit manifest exports to caller-declared digests and advance only the matching analysis blind spot to partial. V5 exposes bounded chunks through closed schemas, generated TypeScript/Python/Rust clients and MCP discovery. A transport-safe canonical bundle independently replays these declarations with the deployment contract and composes exactly the three owned coverage rows. No generator, filesystem, network, provider, runtime or conformance evidence is inferred. Regressions are authored and unrun.
-
Exposed immutable retention checkpoint/plan persistence and exact restoration through explicit CLI commands. The caller supplies an existing private root, bounded metadata files and every selector. A separate planner accepts a canonical sorted image/candidate/draft observation inventory and exact prior checkpoint tuple, then emits canonical checkpoint/plan bytes without storing or applying them. The commands add no discovery, freshness choice, overwrite, deletion, GC execution, subject restoration, protocol, approval or publication authority. Regressions are authored and unrun.
-
Added typed event-ledger derivation to the paired agent-task benchmark. Exact plan/task/lane/model bindings, authenticated stream evidence and closed per-event token/context/tool/failure/stale/timing/intervention records produce the existing observation schema and authenticate the ledger itself. A bounded incremental audit validates one observation and every referenced artifact before the complete matrix exists. Zero streams still require evidence; no agent trial, lane comparison or productivity result is claimed.
-
Added an explicit immutable retention metadata store that publishes one already authenticated checkpoint/GC-plan pair through a single no-replace Unix pivot. Exact selector-bound load repeats ordinary checkpoint and plan restoration under held private roots/files. The store cannot discover or delete retained subjects, infer freshness, apply GC, restore source, or grant approval/publication authority. Regressions are authored and unrun.
-
Extended exact caller-owned target reuse to pathless npm carriers. Hits invoke no generator and replay the carrier's closed schema, semantic recipe, ordered files/bytes/digests and private trusted binding against the exact manifest, source, Project, Workspace and graph key. No package manager, installation, runtime, materialization, persistence or publication authority is added. Regressions are authored and unrun.
-
Exposed exact candidate deployment-contract declarations through the v5 candidate protocol, discovery, generated TypeScript/Python/Rust clients and MCP catalogue. The candidate-read method regenerates the report and returns bounded UTF-8 chunks; it remains outside parallel reads and grants no filesystem, environment, secret, network or deployment authority. Regressions are authored and unrun.
-
Added a complete canonical benchmark execution matrix over every available task, lane and repetition. Each ordered row binds the exact repository plan and SHA-256 digest of its independently generated trial contract. Matrix generation invokes no agent or validator; observations, comparative results and the pinned external Zero lane remain unrun.
-
Connected successful Semantic Workspace Image store receipts to the shared authority-neutral retention contract. One bounded heterogeneous inventory can now plan deterministic image/candidate/draft retention using exact typed identities and logical byte accounting. It performs no store discovery, checkpoint persistence or deletion and recovers no freshness or authority. Regressions are authored and unrun.
-
Added conservative cross-revision rebinding for exact function references. Both already admitted images and the original selector are authenticated; one unique explicit stable identity and exact source/module provenance are required before exporting a fresh destination reference. Reports distinguish unchanged, changed and moved source provenance without claiming ancestry, signature/contract/body equivalence, compatibility or authority. Regressions are authored and unrun.
-
Added a closed caller-declared deployment-configuration contract attachment for exact candidates. Canonical declaration bytes bind the candidate, the complete uniquely authenticated manifest export inventory, and sorted key/type/required shapes while structurally excluding values, secrets, paths, URLs and locators. It changes only deployment coverage to partial and is not environment observation, artifact/runtime/API verification, deployment execution or authority. Regressions are authored and unrun.
-
Extended caller-owned target reuse with a separate exact pathless native-C11 carrier. Hits invoke no emitter and replay canonical payload, revision, manifest, source, export, artifact and embedded C-header bindings before returning. The lane remains in-memory and grants no materialization, compilation, linking, runtime, persistence or publication authority. Regressions are authored and unrun.
-
Added the bounded internal acyclic nested owned-
Bytesrecord profile across independent source/HIR admission, CleanupPlan v7, Graph v26/v27, the interpreter, native C11 and Core Wasm. Complete stable field-ID paths govern whole-value moves, partial cleanup and synchronous shared loans; exact depth/leaf/field limits, nested mutation/pattern closure, native-import schema conflicts and legacy variant publication fail closed. Public Project, FFI and Component aggregate ABIs remain unchanged, and the completion rows remain Partial pending the full promotion corpus. -
Added the unpromoted Project v11 public nested owned-record tranche with a separate canonical stable-path descriptor, retained Project admission, bounded Core-Wasm/npm multi-owner settlement, and a replayed native provider/safe-Rust package. V8-v10 identities and public aggregate ABIs stay unchanged; complete current-tree and hosted promotion evidence remains open.
-
Added executable Project v11 conformance through generated Node/npm and an offline external safe-Rust consumer, including exact cumulative output, plus-one rejection and successful reuse. Corrected Wasm cleanup lowering so a nested record with two-segment owned paths cannot be misclassified as a conditional variant.
-
Added opt-in read-only Project Agent Transport v6 for exact Project v8-v11 public descriptors and npm carriers. The manifest selects the closed profile; every carrier is independently replayed and compared with its retained typed descriptor, response budgets include the complete discriminated wrapper, and v2-v5 behavior remains unchanged. Focused local evidence covers all four profiles without granting write, build-process, execution, or publication authority.
-
Added canonical per-trial contracts to the agent-task comparison harness. Each contract binds the exact plan, repository head, task, prompt, fixtures, drift, lane, workspace state, acceptance rubric and metric inventory for one available tuple. Generation performs no agent run or validation and rejects the explicitly external, unrun Zero lane; observations and comparative results remain absent.
-
Connected successful candidate and draft archive-store receipts to the pure semantic-retention policy. Receipts now retain exact stored-byte accounting and can form one bounded deterministic mixed checkpoint/GC plan without carrying a path or store handle. The adapter performs no discovery, persistence or deletion and grants no source, approval or publication authority. Regressions are authored and unrun.
-
Added a conservative package signature-consumer conflict report over one explicitly supplied authenticated baseline package corpus. Exact retained base/candidate scalar signatures determine changed facets; known imports and static calls are marked for separate candidate-era replay. This is neither installed-consumer discovery nor migration, acceptance, runtime, ABI or behavioral compatibility evidence. Regressions are authored and unrun.
-
Extended ordered signature evolution with fresh parameters derived from an authenticated original
borrow strorborrow Slice<u8>view. The source view must remain exactly once, its compiler-derived type/root is reused from the original left-to-right staged argument, and complete Project replay still owns admission. Owner-to-view conversion, new roots/lifetimes,borrow Bytes, nominal/storage/shared/mutable borrowing and external migration remain excluded. Regressions are authored and unrun. -
Added a caller-owned exact scalar-Web target cache for already admitted immutable Project revisions. The key binds canonical manifest, Project, workspace and graph identities, entry/exports, compiler compatibility and the byte limit; every hit independently verifies and rebinds the carrier. Failed or incompatible work leaves the prior entry intact. This authored lane grants no persistence, filesystem, execution or publication authority and does not cover npm, Native, non-scalar or cross-revision targets.
-
Added a fixed source-bound blind-spot ledger to image and candidate analysis coverage. It records absent deployment-configuration, generated-file provenance and external-API/deployed-runtime evidence against the exact retained Project revision while explicitly refusing to infer that the underlying contract is absent. Closed v5 schemas and discovery guidance carry the same boundary; no external system is scanned, fetched, or verified.
-
Added an ownership-sensitive third task to the paired graph-operational and source-first agent benchmark corpus. It reorders two
Bytesowners and one borrowed slice view, requiring exact-once retention, left-to-right caller migration, rebuilt loan/cleanup admission, authority separation and explicit runtime/deployment/generated/API/consumer blind spots. The canonical fixture is admitted, but no agent observations or comparative result exist yet. -
Added bounded filled-hole lineage and branch ancestry to additive v2 draft, rebase, merge and recovery schemas. Every successful fill binds the exact checked intention and history ordinal; rebase and merge retain exact parent draft identities and remap event ordinals to the actual merged history. Recovery and closed v5 transport validate canonical v1 and v2 capsules; filled events are checked against replayed intentions while ancestry remains content-bound metadata rather than parent-content provenance. Lineage never supplies source meaning, approval, publication authority, or implicit completion of a sibling branch's pending hole. Regressions are authored and unrun.
-
Extended the authored Phase 0 v3 aggregate to authenticate the complete three-language supported product workflow and the installed TypeScript SDK's pinned-MCP review/separate-publication gate alongside the earlier selected children. The aggregate validates the exact child subjects, tool identities, ten hostile workflow cases and recursively bound artifact rows. V3 remains authored and unrun, so it adds no execution or completion claim.
-
Added bounded exact monomorphic free-function HIR reuse inside a changed Project module. Reuse requires complete equality of the non-body module environment, every function signature/contract/span, and the selected function AST. Source verification, HIR validation, cross-file checks, linking, profile admission and graph replay remain mandatory; persistent snapshots do not restore function-cost evidence. Authored regressions cover sibling reuse and conservative contract invalidation and were not run.
-
Added pure authority-neutral semantic retention checkpoints and digest-bound GC plans for exact images, candidates and drafts. Canonical chained checkpoints bind deterministic bounded recency/protection decisions; recovery rejects stale predecessors, rollback, tampering and protected-capacity overflow. The API grants no filesystem, deletion, freshness, approval or publication authority. Authored regressions were not run.
-
Made candidate rebase and merge treat an imported callable's contracts and effects as dependency facts alongside its signature. Concurrent provider contract/effect drift now fails with
SPX-G235before replay, while a provider body-only change can still merge through complete canonical source and semantic-graph replay. The cross-module regressions are authored and unrun; cross-manifest and external-package merging remain unsupported. -
Extended ordered signature evolution to retain and reorder existing exact
borrow strandborrow Slice<u8>parameters once each while rebuilding callers with left-to-right staging and complete Project replay. New borrowed parameters, borrowed Bytes/nominal/storage migration, and external consumers remain outside this authored, unrun slice. -
Added an authored Linux production offline-doctor provisioner around the existing launcher/worker/collector chain. A strict build-time Ed25519 trust anchor verifies one canonical capsule binding the exact sealed request, bundle and static role images; the dedicated supervisor authenticates its fixed pipes/procfs/cgroup2 descriptors, creates private user/mount/network/ IPC/UTS namespaces, atomically places the child under fixed cgroup limits, and withholds bounded report bytes until exact reap and whole-cgroup
populated 0. Worker seccomp admission is now selected by exact authenticated Clang/Node/Rust role with a shared deny floor and no union fallback. Portable checks and Linux cross-compilation passed locally, but real packaged tools, hostile kernel/settlement evidence, ordinary CLI activation and macOS/Windows routes remain unrun or unavailable; WP-05 is not promoted. -
Added an authored Phase 0 aggregate evidence v3 contract. It upgrades the real VS Code child to the closed task-control v2 schema and bundle domain and records current-head, exact-tag, provisioned, default-ignored, and authored/unrun evidence as separate classes. The v3 aggregate has not run; historical v1/v2 bundles retain only their exact-subject claims.
-
Added an evidence-honest comparative agent-task benchmark framework for the graph-operational and source-first Semaprax lanes. Three exact cold-state tasks bind common fixture, prompt, drift, acceptance and review protocols; the bounded summarizer authenticates external artifacts and requires observed model tokens, bytes, tool calls, failures, stale recovery, validation time, review time and intervention counts before emitting descriptive paired differences. The pinned Zero lane is explicitly external and unrun. No observations, productivity result, ranking or programme completion is claimed.
-
Added deterministic persistent semantic-cache lifecycle telemetry. The new
semantic-cache-lifecyclecommand binds cold source admission, authenticated store restoration, unchanged refresh, exact eviction and cold reconstruction into one bounded authority-neutral receipt, including required cold/warm HIR work facts and payload/envelope byte counts. It preserves canonical source and semantic identity and explicitly makes no elapsed-time, RSS, cross-process, crash-recovery, execution or publication claim. Its focused executable evidence is authored but was not run. -
Extended authenticated nested-block function extraction with one checked resource-free owned result. Copy-only captures remain unchanged; String, Bytes, or monomorphic owned record/variant results cross the new helper call exactly once through the rebuilt whole provisional-result publication. Exact HIR correspondence and cleanup validation reject borrowed/shared results, projections, resources, owned captures, and scalar/owned commit mismatches. Authored regressions are unrun and do not claim backend runtime conformance.
-
Added a zero-authority pinned MCP transport to the packaged TypeScript workflow SDK. It initializes MCP 2025-11-25, sends the initialized notification, routes the generated v5 request through the exact selected
tools/call, validates the one-text-item inner response, and restores codec correlation without changing grants. The installed-package review and separately approved Git publication gate now targets realserve-workspace-mcp; that additive form is authored but unrun, while the earlier raw-v5 package gate remains the only passed claim. -
Added exact, authority-neutral persistent semantic-cache eviction. A host can remove one digest-selected derived entry under the authenticated store's held-root and exclusive-lock discipline, receive a bounded machine-readable receipt, and rebuild the identical warm entry from unchanged canonical source. Absence and digest drift fail before unlink; failures after unlink remain explicit uncertainty. Automatic retention, eviction policy, GC, and measured cold/warm performance remain open.
-
Carried a real Rust import selection through the authenticated Project Native Rust SDK route, and taught the
ScalarV1workspace linker to retain the interfaces that declare those callbacks. The Project subject'simportsandcapabilitiesarrays are now the sorted native Rust imports declared by the authenticated entry program and the sorted union of their effects; both render as[]when empty, so an import-free Project's subject bytes are unchanged. Phase A independently re-derives the reached import set and still rejects any disagreement.The scalar linker previously dropped every interface and rejected every effectful function, so a Project could not express a callback at all. It now retains interfaces whose imports are all native Rust, admits a function whose declared effects are covered by those imports' declared effects, and rejects an ordinary non-native import that has no scalar calling convention. With no retained interfaces the linked program is identical to before.
Project v1 admission no longer forces a callback program through the WebAssembly emitter. A
ScalarV1linked entry program that declares a native Rust callback now takes a separate route that derives no target bytes and no scalar WIT descriptor. It proves instead, under the newSPX-J117, that every selected export names an explicitly identified monomorphic function, that the selected identities are in canonical manifest order without duplicates, that each has at most eight value-modei64/boolparameters and ani64/boolresult, and that every declared effect is granted by a declared callback. A program with no callback keeps the previous WebAssembly scalar-export path and its exact bytes.The no-Web-target boundary is retained rather than widened. WebAssembly still rejects native Rust imports (
SPX-W114), the ordinary native backend still cannot lower a callback call site, and the public scalar WIT accessor still fails closed withSPX-J105because no descriptor exists. The only consumer of such a Project is the generated C and safe Rust bridge that the SDK builder renders from linked HIR; regressions pin both the admission and the still-closed Wasm target.With that route in place the authenticated Project SDK is bidirectional end to end:
semaprax-native-rust-sdk projecton a Project declaring a callback publishes a package whose generated facade carries both the selected SEMAPRAX export and the Rust callback trait method, and a Rust consumer built against it completed the round trip Rust caller →callback.apply→ SEMAPRAX → Rust callback → scalar result, with a declared-status failure surfacing its exact domain. That evidence is local, single-host, current-head only, on one macOSaarch64-apple-darwinmachine. It promotes nothing, there is no hosted three-host run for it, and the builder crate and generated packages remain unpublished. -
Added one host-selected, session-scoped candidate-test task with deterministic queued start, cooperative evaluator cancellation, sticky terminal outcomes, bounded report paging, exact source/candidate binding, drift/refresh/finish invalidation, ordinary MCP tools, and VS Code Run/Cancel control. Build and publication remain non-cancellable and no MCP Tasks capability is claimed. The packaged TypeScript workflow SDK now exposes closed failure variants and immutable per-call transcripts carrying validated grants, effects, authority, blind spots, and permitted runtime updates. The overall graph-operational programme remains Partial pending real Extension Host task execution, hosted/cross-platform evidence, broader workflows, and representative gates.
-
Hardened candidate Git publication around a held-process authority. Linux launches now use the already authenticated executable image and repository directory rather than reopening their pathnames; macOS launches suspended and fails closed unless its executable vnode and held cwd attest before resume. Both use a fixed safety environment, close every non-protocol descriptor, bound synchronous pipe traffic under the one adapter deadline, and return only after leader reap and owned process-group quiescence, with a separate bounded fail-stop settlement allowance after an operation deadline. Hostile regressions cover same-byte executable replacement, ancestor and repository substitution, descriptor/environment isolation, output and deadline failure, and descendant settlement. This closes the namespace check/use gap without claiming safety against a same-UID writer who can mutate the held repository's contents.
-
Recorded the public Wasm export surface per profile instead of per backend.
tests/backend_type_parity.rshad onewasm exportcolumn measured only against the Copy-scalar profile, sousize,str, andSlice<u8>read as having no export path when in fact each reaches a boundary through the profile built for its ABI. The row set now pins scalar, borrowed-text, and useful-data admission separately, one exact probe shape per row, and records that position matters as much as type:borrow stris admitted by the borrowed-text profile returning a scalar and refused returningusize. Public Wasm Scalar Exports v1 now names what each excluded type uses instead. No admission behavior changed. -
Added
semaprax.graph.v25so a program declaring animport rust fncallback has a semantic projection. Every Graph-derived route previously rejected such a program withSPX-G218, which closed the callback direction of Native Rust interoperability out of the agent-facing interface and out of Semantic Workspaces and Projects entirely. The schema is selected exactly when a native Rust import is declared, and the predicate reads declarations rather than call sites so a declared but uncalled import still selects the schema that can represent its result type. No earlier schema can represent such a declaration, so every program without one keeps the schema it already selected and its previously emitted bytes; the golden snapshots and every frozen digest are unchanged.The module Graph projects the declaration with its real result type and a
native_rustmarker, and projects the call as anative_rust_import_callnode mirroring the existinghost_command_callshape.ResolvedType::Unitgains a projection because a unit-result import can now reach it. The workspace graph gate is lifted, so a Project source may declare a callback.The projections that omit import nodes by construction stay closed and now say so in the diagnostic: agent context, review, impact, and target evidence would drop authenticated meaning rather than represent it. Graph v25 is outside the evidence flow's admission, like every schema above v14.
-
Extended the
example-checksandexample-fmtquality gates to the bidirectional Native Rust interoperability exampleexamples/calculator-rust/callback.spx, which declares animport rust fncallback and the export that calls it. That source was previously outside both loops, so its verification and canonical formatting were ungated. Documented the already emittedSPX-B112SDK admission andSPX-I233SDK publication diagnostics in Native Rust Interoperability v1, whose owned-diagnostic list had omitted both. No admitted source form, type, ABI, descriptor, manifest, or generated-artifact byte changed. -
Added the zero-authority
@semaprax/agent-workflowTypeScript package for the frozen scalar signature workflow. Generated clients now expose a domain-separatedCLIENT_CONTRACT_REVISIONthat binds their selected wire contract. The package fail-closes reference, validation, coverage, test, review, handoff, approval, commit-status, receipt, and host-inspection transitions; reports typed application failures with an explicitly empty compiler-repair catalogue and the non-executing typed new-review transition; and never retries publication. Its explicitly provisioned local Unix gate strict-compiles the generated codecs and consumer, packs and installs the checked artifact offline by package name, executes the real thirteen-step review and separate nine-step approved publication against a local bare SHA-256 Git repository, and rejects malformed, structured-failure, and duplicate-publication cases. This does not establish registry publication, OS network isolation, hosted or cross-platform support, cancellation, MCP/editor control, automatic repair, broader workflows, full quality, or programme completion. -
Added closed v5 application-error diagnostic data while preserving ordinary JSON-RPC code/message and generic grammar/overflow failures. Generated TypeScript, Python, and Rust clients now retain structured compiler failures through typed decoders and reject malformed or foreign data without parsing diagnostic codes from prose. The supported workflow now binds every ordered response to a closed grant/effect/authority/blind-spot contract and an exact selected-profile revision. This is typed accountability metadata and codec support, not a packaged workflow driver, automatic repair, cancellation, later-head execution evidence, or programme completion.
-
Executed
function_signature_review_publish_v1at clean exact local subject3c605fe3055539a9a5f2bf83e98c8c2a521ff741. Bundle8e18e9dea2050844c554a826e9485394ef44381c24915602ff52952448862cfaauthenticates 18 artifacts covering three isolated generated-client success workflows (Python, Rust, and explicitly provisioned TypeScript), three source-backed handoffs, three exact success transcripts and real local Unix bare SHA-256 publications, plus ten closed hostile transitions including result loss after a real ref update. Raw Project source remained unchanged per language. This qualifies only the frozen scalar fixture and profile; MCP/editor transport, native/Wasm/deployed runtime, hosted/cross-platform, network isolation, packaged SDK, full quality, economics, completion-matrix promotion, and programme completion remain unclaimed. -
Widened the Public Scalar Export Profile v1 from
i64/boolto the full Copy-scalar surface —i64,i32,u8,char,f32,f64,bool— matching the surface the reference interpreter,semaprax.abi-report.v1,semaprax.c-header.v1,semaprax.cxx-shim.v1, and the schema projections already admit.usizestays excluded, as in those widenings, and every other shape still needs the owned-data memory ABI. The widening reaches the export admission gate, the workspace scalar linker that feeds Project v1 and package builds, the generated JavaScript/TypeScript facade, the scalar-ABI manifest, and thesemaprax.project.scalar-wit-interface.v1projection, which now spellss32,u8,char,f32, andf64.An exported adapter's Core-Wasm signature is exactly its monomorphic callee's interned type, so nothing is converted at the boundary. Where the Wasm lane is wider than the SEMAPRAX type the adapter traps instead of truncating: a non-canonical
bool, au8outside0..=255, and acharthat is not a Unicode scalar value — above0x10FFFF, negative, or a UTF-16 surrogate — reachunreachablebefore the verified body runs, and results are checked the same way. The generated facade mirrors those ranges exactly and requiresMath.fround(v) === vforf32, so a narrowing is written at the call site rather than happening silently.Five independent gates guarded that surface and all five moved together: the export admission gate, the workspace scalar linker (
link_scalar_workspace, which feeds both Project v1 and package builds), the Project-profile parameter/return gate in the Workspace Semantic Graph, the package-source module gate, and thesemaprax.semantic-package-report.v2interface vocabulary.link_useful_text_workspaceand the Useful Text Consumer profile keep their narrowi64/boolsurface, which is unrelated to this ABI. One sharedhir::COPY_SCALAR_NAMESlist now owns the wire vocabulary, with a regression asserting the backend's ABI spellings equal it.The change is additive. Guards and mapping rows are rendered only for the scalars a package actually projects, so every program the profile already admitted still produces byte-identical Wasm, JavaScript, TypeScript, manifest, WIT, and digests. Evidence:
tests/language/wasm_scalar_export_widen.rs,scripts/verify-wasm-scalar-widening.mjs, two new cases intests/project/scalar_wit_interface.rs, and widened-lane cases in the effect-free and linked offline package harnesses. Hosted browser execution of the widened scalars is not claimed; the Chromium job covers the unchangedi64/boolcalculator fixtures. -
Executed the Phase 0 graph-operational v2 closure runner at exact local subject
4e6751f92525ed8e4bb5e859233616df7adc86d1. Aggregate bundle76b2e7fab8a5c90fac6ed9c06fff8debe6c97bef015ff26ac53daf8b6ae0eeffrecursively authenticates 86 passing rows: four canonical-Git workflows including deterministic result loss after a real Git ref update, four managed-publication boundary regressions, and the integrated managed-generation workflow. Managed fixtures now authenticate the semanticACTIVEschema through the public graph snapshot and corroborate every candidate source in the immutable generation without rewriting raw source. The VS Code product identity check now retains bounded launcher diagnostics separately from the final three canonical identity lines, accommodating the selected macOS product without weakening package-version comparison. The completion row remains Partial: hosted/cross-platform, target runtime, full MCP certification, full quality, later-head and programme completion are unclaimed. -
Executed the selected Phase 0 graph-operational evidence set freshly at one exact local subject,
d85566f0682df0d236f7df3023479dc0ea50d450. Aggregate bundle77773f4655620b36f9a43f462e128de195345f1b58290823551ebceb908b0f18recursively authenticates three canonical-Git passes, 25 generated-client and authored-MCP passes, 50 standalone editor-controller passes, one real Visual Studio Code Extension Host scenario, and one independent Python MCP SDK 1.27.0 interoperability flow. Python, offline compiled Rust and provisioned TypeScript all submitted exact typed requests to compiler admission. The report separately records two default-ignored TypeScript cases as explicitly provisioned passes and the managedACTIVEworkflow as not selected. Exact-tag, remote/later-head, full MCP certification, hosted/cross-platform, target runtime, full quality and programme completion remain unclaimed. -
Executed the saved-source adapter in a selected local Visual Studio Code 1.135.0 Extension Host at exact subject
2888f84f123b7caa44aa6807388d98f851d4beaf. The archived machine-readable bundle records 50 standalone controller passes and one real compiler-backed host scenario covering 26 command registrations, stable-ID selection, a typed declaration rename, verified read-only virtual source diff, dirty-buffer invalidation, and unchanged saved source. VSIX/Marketplace, manual UI/accessibility, typed-hole and diagnostic-repair host paths, minimum-version, hosted/cross-platform, full quality, and programme completion remain unclaimed. -
Executed generated-client and MCP evidence at exact local subject
c69600e853a5ecc0df0b23e1329770914ba06e99. All 23 explicitly selected tests passed, including three Python consumer paths, one offline compiled Rust consumer, one provisioned strict TypeScript 5.8.3/Node consumer, eight MCP adapter cases and five MCP CLI tests. One CLI test interactively launches the actualserve-workspace-mcpstdio process. The archived envelope binds the four Cargo logs and recorded tools. Independent MCP SDK conformance, VS Code, HTTP/cancellation, generated-client Git publication, hosted/cross-platform, target runtime, full quality and programme completion remain unclaimed. -
Added and executed a focused exact-commit evidence contract for the existing twelve-step canonical-Git workflow. Subject
474c481bf3c3561c144e077f0000460f61af55f2passed all three locked/offline local SHA-1/SHA-256/stale-ref tests, and the archived machine-readable envelope authenticates both exportedsemaprax.agent-task-economics.v1reports. The ignored managed workflow, hosted CI, generated clients, MCP, native/Wasm runtime, later-head validation, benchmark results and programme completion remain explicitly independent and unclaimed. -
Added exact-revision semantic-image function references. A compact canonical carrier binds one retained function, optional facet, image/Project/Workspace revisions, graph digest and source provenance; resolving it against an independently rebuilt identical image freshly derives the function summary and facet handle. Two closed v5 read methods, generated clients, MCP and authenticated read batches expose the same zero-authority contract. Evidence is authored and unrun; references do not migrate across revisions or retain program meaning, cursors, execution, source or publication authority.
-
Added library-only candidate runtime-boundary evidence that composes exact candidate coverage with a freshly replayed, policy-bounded reference- interpreter test closure. Only
runtime_environmentbecomes partial; native/Wasm and deployed execution, path coverage, host-environment observation, external services, compatibility and publication remain open. Evidence is authored and unrun. -
Recorded the published
v0.2.0prerelease at exact commit5f6fb9655fdec92c57ab71615cfd7bfa8cc76051: all 45 jobs in the tag-triggered release workflow passed, all three host-built archives passed unpacked smoke checks, and the release published the closed archive inventory plusSHA256SUMS. Package versions remain0.2.0; pre-alpha, unsigned, not-notarized, non-reproducible-build, and feature-specific nonclaims remain.
0.2.0 — 2026-09-02
-
Gave Windows release ZIP extraction sole ownership of creating its previously verified-absent smoke root. Literal-path .NET extraction no longer follows a redundant PowerShell
New-Item, avoiding hosted Windows' false/duplicate existing-directory failure without permitting stale output. -
Rejected Windows owned-npm parent traversal and inadmissible final-leaf spellings from the raw requested path before
Pathor Win32 component normalization. Reserved names, alternate streams, separators, trailing dot/space, non-ASCII leaves, and missing parents remain pre-staging failures. -
Made the isolated public scalar WIT consumer's exact
wit-parser 0.252.0lock assertion independent of LF versus Windows CRLF checkout newlines. The dependency version, default-feature isolation, and locked/offline contract remain unchanged. -
Closed two Windows owned-npm publication fixture gaps: the private host now enforces its ASCII, non-device output-leaf grammar directly before acquiring parent or stage authority, and the ancestor-displacement regression accepts Windows' stronger access-denied result from retained descendant handles while still requiring fail-stop publication and exact retained bytes.
-
Corrected Windows release ZIP creation to use the literal .NET filesystem paths already admitted by the packager. This avoids
Compress-Archive's hosted PowerShell path-binding failure for bracketed or short-form paths while retaining the package root, optimal compression, and unpacked smoke validation. -
Corrected Windows offline Wasm package publication to settle staged file handles before the no-replace directory rename, then reopen and authenticate the exact three-file inventory through the renamed held directory against retained identity-and-digest proof. Existing-output, publication-race, and visible post-publication diagnostics retain their distinct fail-stop states.
-
Disabled matrix fail-fast cancellation for both the current-toolchain and Rust 1.88 four-way test shards. Every Linux, macOS, and Windows shard now reports its own result after a peer fails; coverage, per-job failure status, time limits, and release blocking remain unchanged.
-
Bound explicit Project v8-v10 Native Rust output leaves to the canonical spelling of their already-admitted parent on Windows. Relative package outputs now reach held publication without a DOS-versus-verbatim path mismatch; fail-fast settlement, tool authority, and process limits are unchanged.
-
Corrected the current Rust integration fixtures so scalar provider modules retain the existing G172 boundary and package-consumer tamper probes mutate the canonical source they authenticate. Resource-lifecycle cleanup inventory, planning, and replay now consistently exclude inline-owned
Stringleaves through nested records and variants while preserving cleanup forBytesand declared resources. The exact integration-0 and integration-2 shards and strict workspace Clippy pass locally. -
Corrected generated Project v8-v10 Native Rust provider guards so borrowed input accounting and carrier construction begin on distinct C statements. Strict compilers can no longer reject the authenticated provider for misleading guard indentation; validation order, byte limits, optimization, process deadlines, and publication authority remain unchanged. Bounded publication diagnostics now distinguish provider compilation and archive failures without exposing tool output or weakening fail-stop settlement.
-
Added candidate-bound compact function summaries and paged access to all nine existing HIR facets for changed and introduced functions. Handles and cursors bind the exact final candidate; pure reads support detached parallel batches without granting source, execution, retention or publication authority. Evidence is authored and unrun.
-
Added a host-selected v5 compact inventory of live retained candidates, drafts and rejected attempts. It exposes bounded registry-local handles, associations and detail/discard routes without granting validity, execution, source or publication authority. Evidence is authored and unrun.
-
Added the authority-free Public Project Scaffold Capsule v1. It derives and independently replays the built-in calculator's exact ordered four-file Project-v1 bytes under per-file and canonical artifact digests. The public
project-scaffoldCLI writes only the exact canonical capsule to stdout; privatenewbytes and its held-parent no-replace publication remain unchanged. The capsule grants no filesystem or publication authority, and its focused library, CLI, private-byte-preservation, and quickstart evidence passes locally; required-host and release-artifact gates remain open. -
Added a public authority-free WIT interface artifact for exact retained Project-v1 scalar exports. Injective stable-ID hexadecimal function names, ordinal arguments, and
result<i64|bool, status>signatures are bound into a bounded canonical descriptor with independent manifest/HIR/revision/graph replay. Display renames preserve WIT bytes while the subject-bound descriptor correctly changes. This emits no Component or target bytes, performs no I/O, and does not expose or promote the default-off private Component harness. -
Serialized the two test-local Project v10 Native Rust publication lifetimes. Windows no longer overlaps their real compiler and archiver authorities; generated SDK execution, semantic-failure recovery, and all package checks remain unchanged, while independent CI shards still run in parallel.
-
Added library-only candidate analysis artifact evidence that composes exact candidate coverage with one independently replayed Web, npm, OpenAPI or C artifact delta. Only
generated_artifactsbecomes partial for the selected pathless carrier; generated-file provenance, deployment, runtime, external behavior and consumers remain uninspected. Evidence is authored and unrun. The selected v5 build grant also exposes the exact composite through bounded candidate/kind-bound chunks with full-report SHA256; it remains outside parallel reads and grants no materialization, execution or publication. -
Bound the Windows doctor descendant-settlement regression to an exact exclusive lease held by the authored child. Parallel process churn can no longer turn a terminating or reused numeric PID into a false failure; the job termination, fail-stop paths, deadlines, and physical authority check remain unchanged.
-
Added library-only candidate analysis evidence that composes exact candidate coverage with one explicit authenticated candidate-era package-consumer replay. Only
external_consumersbecomes partial for that corpus; the other seven boundaries, exact nested rows/digests and strict no-discovery, compatibility, execution, retention and authority claims remain unchanged. Evidence is authored and unrun. -
Keep Windows owned-data SDK publication within the existing fail-fast tool process bound by compiling its already O0/O2-validated provider at O1. The bounded middle mode avoids both O2 compilation exhaustion and O0's larger COFF/archive path; Unix packages remain O2 and no timeout, retry, or test boundary changes.
-
Added library-only candidate package-consumer replay from an explicit, independently verified candidate-era provider report, source and package capsule. Exact source identity binds known coordinate-qualified imports and static call sites while retaining import-only consumers and strict nonclaims for installed discovery, completeness, compatibility, execution, retention and authority. Evidence is authored and unrun.
-
Added candidate-bound compact semantic-impact summaries and paged
affected,dependency_edgesandfrontiernavigation over the exact final candidate artifact. Handles bind candidate, target, query, artifact and view; pages preserve compiler order and existing truncation without adding impact facts, completeness, runtime, compatibility, retention or publication claims. Library and transport evidence is authored and unrun. -
Preserved exact synchronous
borrow Bytessemantics for monomorphic source-defined calls over named owners and one direct field of an owned flat byte record. Resolver/HIR now retain the borrow instead of normalizing it into a transfer, and Shared Loan Plan replay binds owned origins while forwarded borrowed roots reuse their enclosing provenance; source and hostile-HIR checks reject generic, temporary, borrowed-root, deep, identity-drifted, and overlapping-transfer shapes. The interpreter aliases the existing logical allocation, native C11 passes aconst spx_bytes_v1 *, and Core Wasm forwards the existing token without a call epoch or extra drop. Public ABI, Graph and cleanup schemas, owned-call commit semantics, and broader escaping or aggregate borrowing remain unchanged. -
Partitioned the current Rust toolchain's Linux, macOS, and Windows workspace target inventory into parallel lib/bin and three integration-test shards, while retaining separate blocking quality, documentation, release, example, sanitizer, and physical-platform jobs. The shared router rejects unknown targets and Windows package exclusions, every matrix remains release-gated, and commands remain fail-fast.
-
Serialized the two test-local Project v8 Native Rust publication lifetimes. Windows no longer overlaps their real compiler, SDK, and archiver authority; all package bytes, replay, no-clobber, and stable-ID assertions are unchanged.
-
Corrected the semantic-cache CLI fixture to finish and close a create-new staged compiler copy before atomically installing it, and to serialize each test-local install/mutate/execute lifetime. This removes Linux
ETXTBSYraces without retries, sleeps, or weaker executable identity, hard-link, permission, and cache-binding assertions. -
Added candidate-bound analysis coverage over the exact fully admitted final candidate revision. The report reuses the retained image inventory and its eight explicit blind-spot rows while adding exact candidate/base bindings and false retention/publication authority. Generated-looking source remains only checked source, local provider lookalikes do not satisfy declared external contracts, and Native Rust imports remain rejected by
SPX-G218. Library and transport regressions are authored, unrun; no external evidence is ingested. -
Added candidate-bound compact dependency summaries and paged sites/callers/calls/members navigation over the exact admitted candidate revision. Handles and cursors isolate candidate histories while reusing the existing immutable dependency collector; v5 discovery, generated clients, MCP and authenticated parallel reads select the queries only with candidate preparation. Evidence is authored and unrun, with no source, execution, retention, publication or measured context-economics claim.
-
Corrected the held Windows C compiler environment to expose the already bounded, caller-selected MSVC/SDK include directory set through both
CPATH(for the GNU-compatibleclang.exedriver used by CI and the product) andINCLUDE(for clang-cl compatibility). The environment remains closed,LIBis unchanged, and missing headers still fail before archive or package publication. -
Strengthened the integrated twelve-step Git workflow with ordered parameter rename/reordering, exact default insertion, scope-aware body/contract updates and three staged local/cross-file caller migrations. An additive task-economics observation records exact semantic protocol/review traffic and asserted workflow criteria while leaving model tokens, external tool calls, timing and human review explicitly unobserved. Evidence is authored and unrun; no productivity, target-execution or completion claim is made.
-
Completed typed scalar literal construction with exact Unicode scalar and finite IEEE-754 bit encodings for
char,f32andf64. Signed floats lower through canonical unary negation, including negative zero. Recursive expressions and both signature-default forms now cover all eight built-in Copy scalars; record defaults, diagnostic retagging, computed argument type selectors and target profiles remain unchanged. Regressions are authored and unrun; no compiler, client, backend or completion claim is made. -
Exposed the seven existing String operations through typed builtin calls, preserving their borrowed-read, consuming and copied-character signatures. Closed discovery and semantic rebase use compiler-owned descriptors; eligible declaration movement authenticates the same operation identities. Existing byte descriptors, source/type/import restrictions and target profiles remain unchanged. Regressions are authored, unrun, with no execution or completion claim.
-
Added bounded typed string and explicit byte-array literal constructors, with closed schemas and catalogue/hole discovery. Existing canonical source replay owns type, ownership, view provenance and target admission. The later scalar extension is separately specified. Regression cases are authored, unrun; no runtime, generated-client size or completion promotion is claimed.
-
Added read-only navigation from source generic-function templates to retained concrete instances and their facets. Exact instance caller and closure joins distinguish template IDs from concrete identities; existing plan renderers preserve their vectors. V5 discovery and read batches share the bounded handlers. Regression cases are authored, unrun; no new instantiation, generic-import admission or target execution is claimed.
-
Extended function extraction to nested blocks containing internal resource-free owners while retaining Copy captures and results. A helper wrapper preserves the nested cleanup boundary; source/HIR correspondence rejects owner crossings and root-body relocation. Discovery and regressions describe the bounded lane; cases are authored, unrun, with no runtime or completion promotion.
-
Connected checked hole-fill suggestions to an explicit editor selection that seeds a scratch document for the current draft and hole. Closed report checks and asynchronous stale-state fences precede scratch binding; previews are never adopted and ordinary Fill remains separate. Editor digest validation now rejects trailing-newline aliases. Mock controller cases are authored, unrun; no editor-host or compiler execution is claimed.
-
Added bounded typed-hole fill suggestions derived from exact context types, effects and lexical bindings. Every returned proposal passes ordinary source fill replay; previews are discarded and publication remains separate. Typed v5 discovery and parallel reads share the pure query. Regressions are authored, unrun; suggestions do not prove intended behavior or runtime contracts.
-
Added explicit startup-selected parallel read batches to v5 NDJSON and MCP, reusing the immutable read allowlist and held-source authentication with unchanged aggregate wire limits. Closed host-policy v7 and generated client discovery carry the selection; no request can select workers or gain mutation authority. Corrected stale record-field and retained-read instructions. Regression cases are authored, unrun locally.
-
Extended inert scalar record-field additions to existing checked sized resource-free records with owned storage beyond flat Bytes. Compiler type facts and full candidate replay govern eligibility; defaults, source profiles, borrowing, matching, imports and publication authority are unchanged. Broader target regressions are authored, unrun.
-
Added read-only candidate merge preview through actual merge replay in both orders. Reports bind exact parents, directional admission or bounded diagnostics, and accepted canonical source equality without retaining or publishing a candidate. V5 discovery and parallel retained reads share the same handler. Regressions are authored, unrun locally.
-
Connected typed data creation to local owning function declarations. New helpers can accept and return checked resource-free nominal owners or bare String values, with requested modes bound to rebuilt HIR and ordinary type facts. Copy, borrow, extraction, import and target restrictions remain in force. Composition and rejection regressions are authored, unrun locally.
-
Extended typed record and variant creation to direct data scalars, owned String/Bytes and existing stable-ID nominal fields. Full source replay and bounded checked type facts govern admission, including unused declarations; function-signature, import and target profiles remain unchanged. Discovery, schemas and ownership/rebase regressions are updated, authored and unrun.
-
Added optional editor diagnostic attempts, exact-byte diagnostic inspection and explicit compiler repair selection. Repairs remain bound to the retained predecessor and submit selectors only; ordinary Apply remains fail-fast. Stale views and uncertain handle retirement invalidate the editor session. No policy elevation or publication route was added. Controller regressions are authored with mock responses, unrun locally.
-
Extended declaration-move planning to resource-free owned values, String signatures and scalar helpers with internal byte operations. Builtin identities and lexical bindings are authenticated; exact source and checked place/type replay preserve the original body without adding staging. Existing owning import, resource, borrowed-signature and audit restrictions remain in force. Regression additions are authored, unrun locally.
-
Corrected three native Project fixtures to construct Windows executable paths from the dot-free platform extension instead of treating the already dotted executable suffix as an extension. This removes the test-only
..exelookup; native output naming, create-new publication and runtime behavior are unchanged. -
Corrected Unix Git-publication lease release: the owning guard now explicitly unlocks on drop, rejected admission and unwinding instead of relying on the final descriptor close under concurrent process creation. Added deterministic duplicate-descriptor and real-Git contention/recovery regressions. Lock files, nonblocking exclusion, publication checks, CI fail-fast and limits are unchanged.
-
Corrected the MSRV router's test-only stdout bridge to preserve exact bytes on Windows. Its original byte assertion and Cargo failure checks remain unchanged. The routing and typed-client Python fixtures now force CRLF text translation even on Unix while emitting their asserted bytes through binary stdout; the router's ordinary human-readable logging is unchanged.
-
Partitioned the Rust 1.88 CI target inventory into four fail-fast jobs with unchanged workspace feature selection, checks, coverage and 20-minute limits. Routing regressions require exact once-only coverage and reject unknown target kinds. Corrected the actual Python typed-request consumer to write UTF-8 frame bytes directly; forced CRLF text translation now guards against regression without relaxing the protocol's carriage-return rejection.
-
Reduced recursive generated Rust typed-client stack use through separate branch converters, one shared dispatch callsite and borrowed JSON conversion without explicit subtree cloning. Existing limits remain unchanged. The correction follows a Windows consumer overflow; validation is pending.
-
Reduced generated Rust client source duplication by sharing literal serde implementations through macros and omitting redundant field-rename attributes. Public types, literal checks and recursive conversion budgets remain unchanged. Added a regression against the serialized discovery payload size, including JSON escaping, without raising its existing cap. Corrected recursive-client fixtures to use admitted let-bound byte views. All three focused recursive client tests pass locally, including actual Python and offline Rust consumers; full-profile and current-head hosted validation remain pending.
-
Added a retained-Project reference evaluator for the closed Project-v10 owned-UTF8 profile. Exact descriptor/HIR replay precedes an authority-free invocation over all seven result shapes. The v10-only runtime removes implicit value cloning and precharges every interpreter-owned String materialization against fixed cumulative 65,536-byte and 4,096-allocation limits; borrowed snapshots and host copy-out retain their separate bounds. Distinct Bytes/UTF8 settlement events, closed quota outcomes, automatic-ID helper replay, mixed arities, hostile selection and exact boundaries are covered by focused evidence. This does not widen v10 closure admission, change v8/v9 behavior, execute a target, or promote/publicize the profile.
-
Added retained-Project reference evaluation for the closed Project-v9 flat owned-record profile. The evaluator replays the exact descriptor, validates the complete declaration-ordered record inventory before consumption, copies and settles its sole
Bytesowner exactly once, and only then publishes identity-bound scalar members. Focused local coverage includes byte-first and byte-last records, 65,536-byte output, scalar extrema, pre/post-allocation failures, hostile selection/arguments and fuel. No aggregate layout, target authority, cleanup schema, or v8/v10 behavior is exposed or changed. -
Made CLI help reflect the authority already present in its host: standalone
semapraxno longer advertises privatedoctor,new, or Rust-package build routes, whilesemaprax-fulldocuments those existing routes. A typed closed catalog now drives byte-identical global help, exhaustive command dispatch, and inerthelp <command>,<command> --help, and<command> -hviews; misplaced help flags fail before command effects. Ordinary command parsing, availability, and private-host hooks are unchanged; standalone and full catalog/alias/no-activity tests pass locally. -
Added a retained-Project reference evaluator for the complete closed Project v8 public signature surface: zero through eight ordered
i64,bool, borrowed UTF-8 and borrowed byte-slice arguments, plus all six v8 result shapes. Independent descriptor replay and exact export membership precede evaluation; borrowed carriers are snapshotted under one cumulative byte cap, and active owned outputs reuse authenticated copy-out and settlement. The focused hostile suite passes locally, including boundary, wrong-shape, unselected-entry, failure and cleanup cases. This adds no process, filesystem, publication, backend or v9/v10 authority and does not promote v8 support. -
Added an explicit compiler-free frame-product handoff: the current Linux compiler authenticates baseline and renamed Project packages, then retains exactly two seven-file SDKs and four unchanged consumers. All four consumers pass locked/offline under Linux AArch64 Rust/Cargo 1.85.1 with a read-only 30-file handoff, no checkout or network, fresh build state, empty stderr and exact post-run bytes. Publication authority remains unchanged; this is local consumer evidence, not compiler MSRV, Windows, hosted or support promotion.
-
Added generated owned-SDK fail-stop regressions combining active Rust unwind with owner-drop or context-close failure. Exact flushed phase traces and independent broken-finalizer controls reject ordinary return and later provider effects. Existing successful unwind and failure cases remain; all 50 lower-package tests pass on Linux/macOS and with fresh generated consumers in Rust 1.85.1. This is ABI-double protocol evidence, not real provider or hosted promotion; production code, ABI, schemas and generated artifacts are unchanged.
-
Extended real owned-data browser fixtures with independent direct-Bytes and staged Option/Result packages, exact twelve-artifact request admission, fixed offset controls, calibrated resizable-buffer rejection and retained variant copies. Preserved the original Project and closed Graph/import boundaries. Both compiler fixtures pass on Linux/macOS; actual publications pass a local non-pinned Chromium-only run. Pinned three-engine execution remains unrun; runtime, dependencies, hosted workflows and support status are unchanged.
-
Extended the real initialized-Bytes inactive-result fixture across native O0/O2 and a published Rust SDK. Native counters require allocation release before successful
None/Errreturns and no deferred context-close cleanup; safe consumers retain independent outputs after input and SDK disposal. Shared the exact Project fixture and package oracle while preserving the existing npm observations. Test-only evidence, without ABI or support promotion. -
Generate private owned-SDK helpers from validated result shapes instead of emitting unused ownership code. Scalar-only selections retain checked context closure; flat records retain discard whenever any result Bool requires it. Added warning-denied generated-SDK consumers and later-export Bool coverage. Fresh real v8/v9 packages pass Rust 1.85.1 strict offline consumers; compared provider archives and every v8 package byte remain unchanged. Only affected private FFI and manifest bindings change; no ABI, admission or support promotion.
-
Added external compile-negative
Send/Syncguards for four generated owned-data SDK variants, with healthy metadata consumers and exact compiler diagnostic checks. The gate passes on Linux/macOS, as do real v8/v9 native tuple providers at O0/O2, locked/offline published Rust consumers, and generated owner/context-close failure oracles. Documented host tool prerequisites and scoped evidence; no production, unsafe, dependency, artifact, schema or support-status change. -
Strengthened owned-data evidence with 33 genuine export declarations and 24 freshly digested fixed-limit mutations across v8/v10. A separate real v8 npm fixture observes initialized owners dropping before successful
None/Err, versus active result consumption, across 96 calls including maximum byte values. All 27 selected descriptor/lifecycle tests and two documentation checks pass on Linux/macOS; strict scoped macOS Clippy passes. Documented the distinction between oversized input, forged output carriers and source-reachable results. No production, schema or support-status change. -
Strengthened standalone String Web package evidence without changing production behavior: real source/descriptor boundary publication, private manifest-inclusive package accounting, and browser cancellation before oversized-response EOF. Publication hostility now includes a mandatory Windows junction branch, authored but unrun locally. Linux/macOS boundary, CLI/Node and legacy-admission gates pass, as do provisioned macOS TypeScript/Chromium consumers. The owning evidence record retains required-host, broader-browser and hosted-release gaps.
-
Corrected standalone String literal-pool admission and complete cleanup-work accounting without raising limits or leaking legacy diagnostics. Independent cleanup replay now reserves every charged block continuation and owned transfer. Split recursive parser atoms and Wasm dispatch from inactive large frames after reproducing default-stack overflows on valid nested source; grammar, canonical cleanup order and tested artifact bytes are preserved. Added exact-boundary, hostile carrier/quota and nested compilation regressions. Focused local Linux units, parity/preservation and native sanitizer gates, macOS nesting and strict Clippy pass; the versioned String evidence record separates these results from full-quality, hosted and support promotion.
-
Extended ordered signature intentions to retain and reorder admitted String and resource-free owned record/variant parameters using checked ownership and TypeFacts. Bare String parameters count as owners and cannot be omitted; original argument order, full candidate replay and ordinary cleanup admission remain mandatory. New owning defaults, resources and borrowing migrations remain excluded. Five focused local regressions pass, including two callers per target, replay/recovery and unchanged G172 import/H006 branch exclusions. String declarations are checked outside the mixed-aggregate executable closure; this is not physical or hosted String execution evidence.
-
Corrected cleanup-inventory traversal after assignment, while and audited unsafe statements, restoring discovery of later owned storage without changing admission or cleanup order. Corrected shared native Bytes argument, conditional and temporary-record projection lowering to use exact canonical transfer identities once. Affected native artifacts intentionally change. Added ordered inventory/hostile regressions, an eight-shape physical allocation corpus and a generated Rust fail-stop-oracle calibration. Owned-result matches retain mandatory H006 rejection. Original String and new Bytes allocation and sanitizer gates pass locally on Linux, as does the generated String SDK's locked/offline consumer with tmpfs publication; Docker Desktop bind-mount publication remains an undiagnosed filesystem-dependent limit. No full-quality, profile or hosted promotion is implied.
-
Batched CI repairs: update the isolated private Wasmtime runner to 47.0.4, resolve strict Clippy errors, restore component/consumer checks, and correct constructor fixtures without widening source/import admission. Core Wasm now allocates byte-range scratch independently of CleanupPlan v4/v5/v6 selection. Independent cleanup replay preserves declaration-ordered match transfers and partial-construction history through late Copy initializer failures. Focused local regressions pass; full-profile and current-head hosted promotion remain pending.
-
Added guarded recursive response types and complete repair-catalogue schemas to generated v5 clients. Response-reachable local definitions retain their document scope and asserted constraints, while alias-only cycles and unknown assertions fail closed. Shared runtime validation budgets include failed alternatives. Generated clients remain I/O-free and grant no authority; regression evidence is authored, unrun.
-
Added compiler-guided repair for rejected byte-field views staged through value projections. An actual
SPX-T266rejection and full candidate admission are required before offering direct field storage with unchanged stable field and lexical root selectors. Repair selection retains exact predecessor and replay bindings; source loan rules and publication authority are unchanged. Discovery, schema and regression additions are authored, unrun. -
Broadened semantic record-field changes to checked Copy and existing flat owned-byte records, with inert i64/bool/i32/u8/usize defaults. Migrations preserve old initializer order, owning pattern bindings and stable field identities, then rebuild ownership, loans, cleanup and target facts. Schema, catalogue and regression updates are authored, unrun.
-
Restored the resolved-interface slice in the borrowed operation-sidecar view for both workspace and retained-Project constructors. This fixes the refactor's compile error while preserving the existing authenticated interface-parameter type occurrence join. The focused interface type-rename regression passes; native-import graph admission remains unchanged.
-
Added real generated npm owned-result finalization fault coverage for copy allocation, owner deletion, scratch cleanup and frozen result construction, with exact first-error preservation and poisoned-reuse checks. The two-test, seven-package gate passes locally on macOS/Rust 1.98/Node 24.3 without runtime changes. Nine selected native provider/target tests pass on Linux AArch64/ Rust 1.88/Clang 14, including hostile handles and issuer boundaries; the nested offline Cargo consumer is excluded. No hosted or full-profile promotion.
-
Corrected analysis-coverage evidence after integration exposed an invalid Native Rust import fixture. The native case now explicitly preserves Graph admission rejection
SPX-G218; a separate non-native resource-import case covers partial declaration facts. Reports expose that admission limit. The correction is authored and unrun here, without widening native support. -
Added an authenticated package semantic graph with coordinate-qualified consumer queries, separate import/call facts, and explicit host-selected v5 reads. The graph reuses complete package source-capsule replay and never infers a Project dependency from matching IDs. Regression sources are authored, unrun; package acquisition and publication remain separate.
-
Fixed new-project failed-publication cleanup authority: return the rename error before reopening
src, so a replacement directory cannot become owned merely because it contains the original tracked files. Failed rename retains inert staging and its primary diagnostic; successful publication, templates, schemas and platform rename behavior remain unchanged. The destructive regression fails before and passes after the fix on macOS and Linux; all nine publication tests and 16 calculator-and-library CLI cases pass on both. The full lower package's 46 tests and package Clippy pass on macOS. No hosted or Windows promotion is implied. -
Corrected a doctor report test oracle that omitted a byte after partial writes; added exact accepted-byte conservation across short writes, repeated
EAGAINand 8 KiB chunk boundaries without changing production delivery. All 52 selected Linux AArch64/Rust 1.88 doctor wire, guard, capture, collector and launcher unit tests pass locally. Added an explicitly provisioned real-distribution gate through the production launcher, worker and collector with independent expected tool details and retained sealed-input checks; its Linux harness compiles and both resource-free report-oracle tests pass. Physical execution remains unrun; ordinary doctor acquisition and WP-05 status are unchanged. -
Added a graph-facing analysis-coverage query exposing exact retained source facts and explicit deployment, generated-file, external API, runtime and consumer blind spots. Read-only v5 discovery and closed schemas carry the same limits without external I/O or authority. Regressions are authored, unrun; missing edges never prove absent external dependencies.
-
Added authenticated nominal/member occurrence normalization to candidate and draft rebase comparisons. Pure display renames preserve compatible regions; identity, owner-shape, field-type, ordering and real expression changes remain conflicts. Private markers cannot enter source or impersonate authored names. Candidate/draft/transport regressions are authored, unrun.
-
Added direct typed field-place selection with authenticated nominal roots and stable member identities, without value-staging temporaries. Catalogue, hole and schema discovery share the constructor; ordinary source replay still owns borrowing, moves and cleanup. Regression coverage is authored, unrun, with no completion or target-execution promotion.
-
Added explicit unpacked-release product gates for calculator/Web onboarding, revision-bound read-only daemon queries and unchanged Node/Rust frame consumers. Shared source-bound artifact replay with the original frame suite; retained exact inventories, hostile admission/capture controls and bounded direct-child cleanup without recursive cache deletion after uncertain descendant settlement. Both archive lanes pass locally on macOS against the real archive built from
177fccf; the release guide records its digest and separates archive identity from the newer test driver. Updated affected programme rows to scoped local evidence, without hosted, release or production promotion. -
Added draft-bound body and contract expression catalogues over the current private last-valid state, with typed v5 discovery and shared immutable reads. The editor can plan additional holes after fills without reusing stale original-candidate selectors or exposing unfinished drafts as valid source. Library, transport and editor regression evidence is authored, unrun.
-
Added saved-source editor controls for body, expression and contract holes, compact context navigation, revision-bound fill scratches and explicit draft completion. Superseded in-memory draft handles are released without source writes; unfinished drafts cannot be previewed as valid candidates. Regression evidence is authored, unrun; no editor-host or completion claim is added.
-
Added an explicitly selected frame-product ASan/UBSan gate with calibrated failure controls, reusing the unchanged nine-case and 72-case corpora for isolated and retained baseline/display-renamed Projects at O0/O2. It passes locally on Linux arm64/Rust 1.88/Clang 14 and macOS arm64/Rust 1.98/Clang 21. Ordinary frame, strict TypeScript, offline npm installation, generated Rust, Chromium and version/new-project/quickstart gates also have local macOS passes. No production emitter, schema, corpus, hosted workflow or promotion changes.
-
Added typed
builtin_callexpressions for the seven compiler-owned byte operations, with owner-derived schemas and discovery, collision checks, and semantic rebase dependencies. Ordinary source replay still owns type, loan, cleanup, capacity and target admission. Regression coverage is authored, unrun; no completion or performance claim is added. -
Corrected doctor encoder test-module routing and the mixed-arity fixture's borrowed-view provenance: result bytes now come from named fixed-array storage, without relaxing compiler admission. Local macOS arm64 validation passes the 15 descriptor tests, mixed-arity native O0/O2/npm and generated Rust SDK gates, result-extrema interpreter/native/npm and Rust SDK gates, owned multiplication gate, and 40 doctor unit tests. Local Linux arm64 Rust 1.88 passes 32 sealed-input/factory/handoff tests and 25 bundle/ELF tests in a container with all capabilities dropped. Provisioned worker/collector execution and hosted gates are not implied.
-
Added compact typed-hole summaries and revision-bound pages for lexical scope, accessible calls, obligations and constructor choices. V5 discovery, generated clients and parallel reads describe the new closed reports; full contexts and unresolved-draft authority remain unchanged. Regression evidence is authored, unrun; no token or latency improvement is claimed.
-
Added recursive typed request parameters and additive builders to generated TypeScript, Python and Rust workspace clients. Types derive from selected compiler-owned schemas; legacy builders and compiler admission remain unchanged. Model, emitter and integration evidence is authored, unrun.
-
Added shared-source mixed v8 parameter-boundary regressions: all arities zero through eight, exact ninth-parameter rejection, native O0/O2 and generated npm/Rust consumers with independent argument literals and recovery controls. Descriptor and published-package bindings remain explicit. These fixtures now have focused local macOS evidence; no production, schema, artifact or promotion change is made.
-
Added production creation of sealed executable doctor images from explicit native ELF bytes, sharing bounded writes and one-shot failure cleanup with non-executable input creation. Added authored, unrun factory regressions and actual-file launcher handoff coverage; hostile images still use independent fixtures. No provenance, loader-closure, ordinary CLI or support promotion is inferred from executable storage.
-
Added closed, independently replayed candidate source-review reports and a saved-source VS Code adapter with explicit MCP startup, typed-intention submission and read-only virtual diffs. Candidate-owned review bytes are shared across chunks; source authentication and separate publication remain unchanged. Compiler, transport and editor regressions are authored, unrun.
-
Added a private provisioner-owned doctor launcher: sealed input and executable preflight, fixed-descriptor worker creation, parent-death protection and pidfd-owned collector handoff with bounded failure settlement. Added authored, unrun admission, lifecycle and actual launcher fixtures. No namespace bootstrap, service installation, ordinary CLI activation or support promotion is claimed; executable/loader provenance remains provisioner-owned.
-
Added typed response payloads and additive decoders to the host-selected v5 TypeScript, Python and Rust clients. A shared model uses already bundled schemas; existing runtime validation and generic APIs remain in place. Opaque compiler reports stay opaque. Regression evidence is authored, unrun.
-
Added anonymous non-executable sealed doctor carrier creation from explicit bytes, returning an owned file and a snapshot verified through existing acquisition. Mandatory sealing has no weaker fallback, writes are bounded, and failure cleanup is one-shot. Added authored, unrun storage and direct worker/collector handoff regressions. Ordinary CLI admission, host configuration and production-support claims remain unchanged.
-
Added an optional MCP stdio adapter over the host-selected v5 workspace, with a pinned lifecycle, derived tool schemas and exact semantic responses. The CLI reuses existing startup policy and separate Git approval; response storage is reserved before tool execution to preserve complete outcomes. Integration evidence is authored, unrun; no client-conformance claim is made.
-
Extended host-selected parallel reads to immutable candidate, draft and diagnostic review. Workers receive only selected subjects and share the sequential query implementations; source authentication still surrounds the complete batch. Mutations, runtime tests, builds and publication stay excluded. Regression evidence is authored, unrun; no throughput claim is made.
-
Added canonical offline doctor bundle and worker-request preparation from explicit borrowed content and retained sealed-input bindings. The APIs return bounded transport bytes only, reuse existing validators and preserve native admission. Added independent literal, hostile-input and provisioned handoff regressions, all authored and unrun. No ordinary CLI activation, provisioning authority or production-support promotion is claimed.
-
Added semantic merging of unfinished sibling drafts: one checked-history merge, independently rebound pending selections and a bounded hole union. Opposing writes, including no-op fills, cannot silently complete a pending hole. V5 retains only the resulting draft; regression evidence is authored, unrun.
-
Shared the provisioned doctor collector's ownership and report-delivery state machines with resource-free hostile scripts, preserving fixed descriptor ownership, fail-stop uncertainty, write bounds and deadlines. Added authored, unrun physical all-role, tool-failure, nonchild and interrupted-delivery regressions. Fixed full Rust signal-set initialization before libc's partial initialization. Ordinary CLI admission and production-support claims remain unchanged.
-
Added typed-draft semantic rebase for checked history and pending body, expression and contract holes. V5 returns a newly bound draft and report after conflict checks and source-origin remapping, without completing holes or granting source authority. Regression evidence is authored, unrun.
-
Added explicit durable typed-draft storage and host CLI recovery through the existing immutable archive store. Host-policy v6 selects historical drafts before requests and Git-provider startup, preserving pending holes and separate source approval. Storage and CLI regression evidence is authored, unrun.
-
Connected provisioner-owned offline worker collection to the shared doctor report policy through a separate unpublished collector entry. Only exact request/bundle/reply binding, complete capture and successful owned-worker reap can produce an opaque observation; malformed or uncertain handoffs fail-stop. Added authored, unrun lifecycle/report fixtures. Ordinary CLI discovery, service installation and support promotion remain unchanged.
-
Added self-contained typed-draft archives that rebuild canonical original source, valid history and pending holes after checkout loss. V5 separates current-base RPC recovery from startup-only historical host recovery; no approvals or publication authority are restored. Evidence is authored, unrun.
-
Added offline-worker hostile native programs and external post-exec capability/parent-death observations without widening the syscall policy. Factored capture/settlement control flow for scripted sticky-failure and fail-stop regressions alongside native owned operations. All new fixtures remain unrun; physical injection, real-tool compatibility and live CLI admission remain separate pending gates.
-
Added source-replayed C image artifacts and candidate comparisons, binding actual linked C11 output to exact header prototypes or explicit exclusions. V5 discovery and generated clients include the
cbuild kind. Static linkage and publication authority are unchanged; regression evidence is authored, unrun. -
Added source-bound OpenAPI image artifacts and candidate artifact deltas, using the existing scalar document renderer and complete canonical Project replay. V5 build discovery and generated clients include the additive kind; no files are published and regression evidence remains authored, unrun.
-
Connected the private Linux offline doctor worker from sealed request/bundle framing through per-tool PID namespaces, detached roots, capability removal, syscall filtering and bounded capture/reap. Added synthetic and real-bundle provisioned execution fixtures, all unrun. Deployment requires an external trusted provisioner; no service installation, ordinary CLI activation, macOS/Windows support or completion promotion is claimed.
-
Added source-bound image and candidate cleanup dependency queries for types, cases and fields, using retained inventory, cleanup and loan plan facts with exact coordinates. V5 provides permission-separated report chunks; candidate verification replays source history. Evidence is authored, unrun, with no runtime, source-publication or completion claim.
-
Removed silent Node prerequisite skips and a swallowed resizable-buffer rejection assertion from owned-data npm evidence. Shared v8/v9/v10 fixtures now require real hostile buffer capabilities and exact adapter rejection, retaining healthy-call controls. Tests remain unrun; production runtime, generated artifacts, schemas and support claims are unchanged.
-
Added candidate display renames for explicit record fields, variant cases and payload fields through shared authenticated cross-file reference planning and exact source replay. Discovery, conservative member conflicts and static test relevance use the existing candidate protocol. Regression evidence is authored, unrun; public Operations grammar and publication authority are unchanged.
-
Removed silent Windows hostile-path fixture omissions from the new-project and quickstart checks. A shared test helper requires an actual Unix symlink or Windows junction, authenticates the fixture target, and exercises rejection with unchanged foreign bytes. Regression evidence remains unrun; production path rules, generated projects and support claims are unchanged.
-
Added candidate record/variant display renames through the shared authenticated Operations reference collector and exact source replay, preserving stable IDs and consumer import aliases. Added nominal conflict checks, conservative test relevance and discovery; public Operations proposal bounds stay unchanged. Implementation and regression evidence are authored, unrun.
-
Moved the offline doctor inventory parser into its existing sys quarantine, preserving one validator and safe facade while correcting retained file-view lifetimes. Added authored, unrun bounded detached tmpfs materialization with exact page/inode accounting and read-only closure. This internal component requires an already controlled child; general-host bootstrap, tool execution and production profile admission remain unwired. No support promotion.
-
Added typed contract-expression changes and ephemeral pre/postcondition holes, with exact source replay, type/ownership preservation, conservative semantic rebase and selector-only draft recovery. V5 adds candidate-granted discovery and hole opening; existing body-expression behavior is unchanged. Regression cases are authored, unrun; no logical contract or runtime guarantee is claimed.
-
Added candidate artifact deltas over actual independently replayed Web/npm carriers, comparing file content, stable export identities and source/carrier bindings. V5 requires the existing build grant; no package installation, target execution or artifact publication is added. Regression cases are authored, unrun.
-
Added an authored, unrun offline doctor bundle parser over sealed input: exact selector/platform binding, bounded canonical file/tool inventory, zero-copy views, minimum ELF headers and in-inventory interpreter checks. Hostile structural and source-included sealed-handoff fixtures preserve the unavailable CLI route. This is not provenance, complete library closure, executable isolation or a production-readiness promotion.
-
Added whole-candidate ownership comparisons over checked signatures, complete structural inventories and ordered loan/cleanup plans, including retained generic instances. Exact replay verifies report bytes; v5 exposes bounded candidate-granted chunks. No plan mutation or execution authority is added. Regression evidence is authored, unrun.
-
Added whole-candidate contract comparisons with ordered checked predicates, source provenance and static callable-dependency facts. Exact candidate replay verifies report bytes; v5 exposes the read only under candidate preparation. No target execution, logical contract proof or publication authority is added. Regression evidence is authored, unrun.
-
Authored a bounded borrowed-file doctor input primitive in the existing OS quarantine and unsafe-free facade. Linux checks immutable memory-file seals before metadata/read access and never duplicates or closes an untrusted descriptor; exact positional reads return only complete immutable bytes. Hostile input/failure regressions are unrun. This supplies no profile format, provenance or execution authority; real doctor profiles remain unavailable.
-
Replaced real doctor ambient PATH/home discovery with explicit bounded offline-profile selection and one scoped admission per report. Production admission is not yet implemented: missing/unavailable profiles fail required checks without tool access or fallback. Authored selector, identity, canonical report and no-execution regressions are unrun. The required
profilereport row is additive; this is not full no-network enforcement or WP-05 promotion. -
Extended function movement to checked Copy record/variant values with stable-ID type bindings, destination type imports and rewritten aggregate syntax. Exact source replay and rebuilt semantic identities remain required; ownership, export-origin, generic-import and unsafe boundaries stay closed. Alias, replay and rejection regressions are authored, unrun.
-
Extended function extraction to checked Copy nominal values and immutable whole-root field captures. Body-value type facts share the existing bounded signature inventory; generated helper signatures and canonical source replay remain mandatory. Owned/borrowed captures and unsafe relocation stay closed. Charged retention can change graph budget bytes and derived image digests. Regression cases are authored, unrun; no source authority changes.
-
Corrected the Linux doctor guard's rejection of Rust's fork/exec handshake: only anonymous Unix stream/seqpacket pairs with exact scalar arguments and known flags are admitted, while named socket operations are now denied. Authored bit-boundary, real pair-exchange and forced Rust fallback regressions remain unrun. Existing settlement checks stay required; this is compatibility within partial isolation, not full cross-platform no-network enforcement.
-
Added stable-ID nominal types for computed signature arguments. Provider and caller annotations resolve their own existing type bindings; rebuilt HIR checks exact nominal identity and Sized Copy eligibility even without calls. Literal/append mappings, source authority and type-fact limits are unchanged. Migration, rejection, replay and discovery regressions are authored, unrun.
-
Added authored, unrun same-source
Result::Errzero/minimum/maximum gates across the reference interpreter, native O0/O2, actual npm/Wasm and an external locked/offline safe-Rust SDK consumer. Exact payload bits, successful language errors versus invocation failure, owned cleanup and recovery are observed without changing production code, package formats or status claims. -
Added an authored, unrun v8 installed npm consumer gate for baseline and renamed frame projects: real offline pack/locked install, independently checked tarball integrity, exact installed bytes, package-name Node imports, both existing corpora, and strict TypeScript positive/negative consumers. No production artifact, schema, dependency, or completion status changes.
-
Added explicit computed scalar arguments to ordered signature migration. Original arguments retain their staging order; typed computed locals follow, using original parameter references and existing caller bindings. Literal and append routes stay unchanged. Schema/discovery, scope, ownership, replay and rebase regressions are authored, unrun; no publication authority changes.
-
Added immutable scoped
letexpressions to typed candidate constructors, with initializer-before-body lowering, lexical isolation, hygienic names and unchanged compiler admission. Schemas and hole/change discovery expose the form. Scope, ownership, replay, hole and rebase regressions are authored, unrun; no source syntax or publication authority changes. -
Bound v9 native-package descriptor framing before hashing, reusing the existing replay guard. Invalid framing now consistently reports a descriptor error after provider validation, including when the digest is also wrong; accepted artifacts and other profile routes are unchanged. Authored boundary, digest-work and failure-precedence regressions remain unrun.
-
Added compact declaration-dependency summaries and revision-bound detail pages over the existing immutable image index, with read-only v5 discovery, client builders and host parallel reads. References bind selection and page options; no source authority or runtime coverage is inferred. Regression cases are authored, unrun; full dependency reports and earlier profiles are unchanged.
-
Corrected both Wasm
usizemultiplication lowerings: the overflow division now executes only for a nonzero multiplier. Zero products retain ordinary success, while genuine overflow still reaches aggregate cleanup with status 3. Authored regressions cover both routes, boundary products, operand-failure precedence and staged Bytes across interpreter/native O0/O2/npm. Affected Wasm and derived integrity bytes intentionally change, including earlier profiles; source semantics, schemas, descriptors and native code do not. Tests remain unrun and no known-answer values were replaced. -
Added a lazy immutable-image declaration dependency index shared with candidate semantic deltas, plus read-only v5 dependency chunks and host parallel reads. Source-bound field/type/case sites and reverse callers remain structural facts, with no execution, coverage or source authority. Regression evidence is authored, unrun; image identity and earlier protocol profiles are unchanged.
-
Added real generated npm facade regressions for malformed result carriers, Option/Result tags, inactive storage, bools, unsettled owners and corrupted semantic-failure output across the existing seven v8/v9/v10 packages. Scoped read/consume observations and same-arena stale tokens complement the preserved lower-level fixtures; no production runtime or package bytes change. Evidence is authored, unrun. Frame-product/browser instructions now explicitly select the full toolchain required for Windows owned npm publication, with command assertions in the existing product fixture.
-
Added typed-hole draft recovery capsules and host-selected v5 export/restore methods. Recovery independently replays prior valid history, re-creates every pending selector and checks exact draft identity; unresolved holes still block completion. Schema/client discovery and restart, partial-fill, stale-source and hostile-capsule regressions are authored, unrun. Existing protocol profiles, source publication and approval authority are unchanged.
-
Added explicit-ID record and variant creation through
add_declaration, with closed scalar fields, complete owner/member identity inventories and exact source reconstruction. Discovery and schemas expose the new forms; semantic rebase rejects nested identity collisions and supports record creation followed by field evolution and nominal use. Regressions are authored, unrun. Generic type creation, owned fields and source/publication authority remain unchanged. -
Added a private doctor pre-exec Linux seccomp/no-new-privileges layer on native64 little-endian x86-64/AArch64. Socket creation, including local socket pairs, and six related asynchronous-I/O/descriptor/process syscalls fail closed; unsupported ABIs and setup failures never retry unfiltered. Authored policy, inheritance, unfiltered-host and failed-install regressions are unrun. This is partial isolation with explicit tool-compatibility limits, not full no-network enforcement; discovery/filesystem/brokers and macOS/Windows remain open. No dependency, root unsafe code, or authenticated build-runner change.
-
Added stable-ID named Copy parameter and return types to function declaration intentions, including fresh local generic instances, monomorphic aliases and authenticated Option/Result. Discovery exposes provisional templates; every addition passes an exact checked-signature gate after rebuilding. Return-only facts retain existing table/byte limits, and rebase binds complete selected type inventories. Regressions are authored, unrun; source/publication authority and general declaration-kind support are unchanged.
-
Moved Windows Project v8–v10 npm/Web publication to the private full toolchain with compiler-prepared six-file plans and existing held-handle filesystem authority. Standalone publication rejects before output effects; the private route requires an existing parent and never rolls back after settlement. Source rechecks, exact bytes, no-clobber and post-rename authentication remain mandatory. Regressions are authored, unrun; generated artifacts, Unix behavior, dependencies and unsafe-code boundaries are unchanged.
-
Added stable-ID record update intentions with exact nominal base staging, subset field replacement and preserved base-first/requested evaluation order. Catalogue and hole discovery expose checked record inventories; semantic rebase binds untouched fields as well as selected replacements. Regression fixtures are authored, unrun. Runtime evidence, backend admission and source/publication authority are unchanged.
-
Added stable-ID exhaustive variant match intentions for source variants and authenticated Option/Result, with exact nominal scrutinee staging and scoped payload bindings. Discovery and recursive schemas expose complete case/field inventories; semantic rebase binds those inventories before replay. Tests are authored, unrun. General patterns, owned/borrowed match modes, runtime evidence and source/publication authority remain outside this change.
-
Added stable-ID record field value projection with an exact-owner typed temporary, single base evaluation, deterministic scope hygiene, and ordinary ownership/cleanup admission. Catalogue and hole discovery describe eligible fields; semantic rebase binds each selected field and its complete owner shape. Regressions are authored, unrun. Variant/class projections, borrowed field views, runtime evidence and source/publication authority are unchanged.
-
Extended stable-ID aggregate constructors to explicit direct-scalar generic arguments and authenticated compiler-owned Option/Result cases. Discovery reports checked templates and prelude provenance; concrete admission remains the ordinary full-source replay. Generic parameter inventories now bind semantic rebase dependencies, including phantom parameters. Regression cases are authored, unrun; no nested generic arguments, inference, runtime evidence or source/publication authority is added.
-
Added typed record and variant expression constructors selected through stable type/case/field identities, with checked local/import bindings and exact member coverage. Initializers retain requested evaluation order; complete source replay remains the admission gate. Discovery and recursive schemas describe the new forms, and semantic rebase rejects concurrent aggregate shape changes. Regression cases are authored, unrun; generic construction, projection/update/match synthesis and runtime evidence remain outside this change.
-
Added authentic descriptor cross-replay regressions for v8/v10 and v9: separately checked programs produce valid, correctly digested descriptors that self-replay but reject against the other retained HIR. Explicit signature/record-field deltas and body/function-name invariance controls distinguish semantic binding from mere hash rejection. The new tests are authored and unrun; production code, schemas and golden outputs are unchanged.
-
Extended ordered signature evolution to admitted concrete Copy records and variants using retained checked HIR identities and TypeFacts. Discovery uses the same eligibility gate; original argument staging, exact type/mode and complete source replay remain mandatory. Rebase fingerprints now distinguish nominal identities even when type spellings are unchanged. Named aggregate, catalogue and concurrent-identity regressions are authored, unrun; no new aggregate defaults, type conversion, borrow/resource migration or runtime equivalence claim is introduced.
-
Replaced the direct-Bytes browser placeholder with a fixed Project-v8 subject and real generated-package boundary tests for all three existing browser projects. The authored cases cover capacity, hostile buffers and getters, copy independence, pre-instantiation Wasm authentication and genuine pre/post-staging failure recovery; missing prerequisites fail rather than skip. No tests were run and no runtime, schema, dependency, workflow or support-status change is claimed.
-
Added independently replayable whole-candidate static interface deltas with complete affected-member inventories and bound-function dependency facts. Added v5 symbol-diagnostic queries linking exact retained rejected attempts to their predecessor/intent target and actually admitted repair classes. Report-bound continuations reject changed diagnostic inventories. Existing selected-delta bytes, v1–v4 profiles and source/publication authority remain unchanged. Focused regressions are authored, unrun; runtime dispatch, behavioral proof, general repairs and full-programme completion remain open.
-
Corrected Unix npm publication success binding: canonical path equality is now followed by a held/reopened parent identity comparison. Same-path parent or ancestor replacement reports failure while preserving the original artifacts and foreign bytes. Test hooks are thread-local so parallel publishers cannot steal each other's substitutions. Real-carrier and hook regressions are authored but unrun; artifact bytes, Windows routes and the existing non-atomic publication contract remain unchanged.
-
Fixed the shared full-toolchain test launcher to use Cargo's uniquely reported, manifest-bound executable instead of guessing
target/debug. Configured target output can no longer silently select a stale CLI at the guessed path. Locked/offline builds and valid cached artifacts remain unchanged. Literal-message and pathname regressions are authored but unrun; compiler behavior, generated packages and hosted workflows do not change. -
Added host-selected authenticated persistence of complete checked-module HIR, synthetic inputs and graph projections, with a private bounded binary codec. MAC verification and compiler-file binding precede decoding; restored source is reparsed and the ordinary warm Project pipeline checks exact synthetic inputs and graph equality. Added explicit cache CLI commands and startup host-policy v5 selection while cold stores remain unchanged. This relies on protected host key custody and an immutable static compiler installation; it is not compiler attestation or protection against a compromised host. Cross-process and hostile regressions are authored, unrun; no performance or full-programme completion claim follows.
-
Reject non-string owned npm export identities without formatting or invoking caller conversion hooks. This fixes Symbol error classification and prevents invalid-ID rejection from causing reentry and poisoning an idle instance. Existing poison/busy precedence and unknown-string errors are preserved. Only v8/v9/v10 runtime JavaScript and dependent integrity bindings change; the seven-package regression matrix and historical-byte controls are unrun.
-
Exclude exact/ASCII-case-equivalent calculator staging/destination names before creation, retaining the existing attempt limit and output-exists precedence. A requested destination matching a generated staging name can still succeed through another candidate, without exposing partial template files there. Physical publication/failure regressions are authored but unrun; templates and schemas stay unchanged, with no general Unicode filesystem alias-equivalence claim.
-
Added a separate 72-case frame-format conformance supplement while retaining the original nine-case product corpus and native/raw-Wasm checkpoints. Baseline and renamed Project subjects share the extra length-bit, truncation, valid-size and error-precedence cases across interpreter, native O0/O2, raw Wasm, existing npm/Rust consumers, and the provisioned Chromium fixture. Native executables and published packages are reused; no source semantics, generated artifacts, or schemas change. All new checks remain unrun.
-
Added explicitly selected checked-module HIR reuse for exact synthetic AST inputs, with conservative reverse-import invalidation and transactional adoption after complete Project admission. ImageWorkspace and authenticated v5 sessions can select it; closed host-policy v4 retains startup authority boundaries. Separate semantic work schemas preserve AST-only reports and expose actual resolver/reuse counts. Regression cases are authored, unrun; persistent cross-process HIR and measured performance remain outstanding.
-
Closed Cargo instruction injection through CR/LF-bearing owned-data SDK package paths. V8/v9/v10 now share a private build-script renderer that validates the path before stdout while preserving target-error precedence and valid instruction bytes. Generated
build.rsand manifest bindings intentionally change; descriptors, providers, safe APIs, FFI, and scalar SDK artifacts do not. Generated-script regressions are authored but unrun. -
Added a separate allocator-observed native O0/O2 lane for the frame-payload product, preserving its plain-provider runs and exact nine-case corpus. Per-call pointer and allocator accounting checks actual payload release, empty ownership, inactive branches, and stale drops across the baseline and display-renamed Project subjects. Production generators remain unchanged; the regression fixtures are authored but unrun and promote no status.
-
Added source-backed candidate archives and an explicitly selected immutable Unix store, allowing complete histories to be independently rebuilt after original source files change or disappear. Added CLI persist/load and strict startup host-policy v3 archive selection; recovered candidates remain historical until explicit rebase and gain no approval or publication authority. The store preserves failed stages and reports post-pivot uncertainty without adoption, overwrite or automatic cleanup. Tests and compiler execution remain unrun; no warm HIR, complete session recovery or durability promotion is claimed.
-
Replaced predictable native C/executable temporary paths with exclusively created scratch directories, create-new C files, and identity/inventory-checked nonrecursive cleanup. Source
runchecks and emits before reserving scratch; failures retain partial work instead of deleting a pre-existing pathname. Added hostile-path and ordering regressions without changing emitted code, compiler flags, or package schemas. Tests remain unrun; this is not process sandboxing or hosted promotion. -
Connected opt-in frontend AST reuse to authenticated v5 live refresh without a preliminary cold parse, retaining full semantic/link/profile rebuilding and staged cache rollback. Added strict host-policy v2 selection while v1 remains closed/cold, plus bounded embedding-host parallel image reads with ordered results and whole-batch source rechecks. Expanded concrete candidate response schemas and fail-closed generated client validation. Authored an integrated signature-review-to-real-bare-Git workflow for SHA1/SHA256 and stale-ref rejection. Tests, compiler/client execution and benchmarks remain unrun; warm persistent HIR and full-programme completion are not claimed.
-
Added real v8/v9 npm mixed-borrow consumers and raw native admission fixtures alongside the published Rust corpus. npm checks exact six-file publication and calibrated selected-Wasm-export entry counts; the native fixture observes post-validation invocation, allocator calls, output preservation, and recovery on the same physical context. Generators remain unchanged. All new execution gates are authored but unrun; no completion or hosted status is promoted.
-
Added an explicit host-policy Image Agent Protocol v5 and
serve-workspaceCLI with independently selected candidate, diagnostic, interpreter-test, pathless-build and optional startup-approved Git source-commit grants. Cold live refresh retains candidate handles and clears drafts/attempts on success. Actual target emission and replayed Web/npm carriers produce bounded source, export and artifact reports. Catalogue-driven typed clients/schema bundles retain explicit opaque payload gaps. Git publication uses fixed authority, consumes separate exact approval and preserves terminal uncertainty; review and commit use separate sessions rather than later RPC approval. No raw checkout or artifact filesystem publication is added. Tests, compiler/client execution and benchmarks are unrun; the full programme remains Partial. -
Authored real published v8/v9 Rust consumers for mixed UTF-8 and two-slice borrowed tuples at the cumulative 65,536-byte boundary, including unused inputs, inactive v8 variants, maximum
Some/Okoutputs, rejection/reuse, and independent retained copies. The gate reopens exact seven-file packages and uses locked/offline external consumers. Generators remain unchanged; tests are unrun and do not establish allocation or invocation-entry evidence. -
Made lower owned-data SDK package publication one-way: preparation failures can discard their exact inventory, but settlement, rename and post-publication failures cannot regain cleanup authority. This prevents deletion of an authenticated published tree moved back to its former stage name. Added held-filesystem preservation and real no-clobber regressions; tests remain unrun and no hosted or isolation claim is promoted.
-
Centralized native SDK current-target selection around complete compiled ABI facts instead of OS/CPU alone, rejecting musl/GNU-Windows and mismatched vendor, pointer-width, endianness or ABI without relabeling them. Preserved the five public package targets and six private Phase-A targets, existing diagnostic ordering, and supported-target artifact bytes. Pure selector and caller-policy regressions are authored but unrun; no platform support or completion status is promoted.
-
Preserved uncertain archive settlement in the lower native owned-data package builder instead of discarding that state and attempting cleanup. Uncertain failures now retain the inert stage and stop before rechecks or publication; settled cleanup and sticky primary errors remain unchanged. Authored shared-boundary and held-inventory regressions, including foreign bytes. Tests remain unrun; injected failures are not physical archiver or quiescence evidence, and no completion status is promoted.
-
Authored actual npm and native Rust SDK consumers for 65,535- and 65,536-byte owned String results, sharing one minimal Project fixture with independent BOM/NUL/Unicode byte oracles. Added the separate capacity-plus-one Project admission regression and reused the native manifest consistency helper. Generators, schemas and literal limits remain unchanged. Tests/builds are unrun; these fixtures do not establish allocation or production evidence.
-
Corrected admission/routing defects: native SDK descriptor digest discovery now enforces the existing byte bound before JSON parsing;
checkretains its parsed source path when--jsonprecedes it; and extensionless Windows Project-native outputs receive.exe, not..exe. Provider-binding validation no longer copies unbounded caller digest text. Added bounded descriptor, CLI shadow-file and output-name regressions while preserving existing schemas, valid generated bytes and help output. Tests and builds remain unrun; no hosted or production status is promoted. -
Authored a real Project-v10 native Rust publication and external-consumer gate over the same multi-module UTF-8 fixture as npm: exact seven-file descriptor/provider/manifest bindings, stable-ID helper rename, no-clobber preservation, safe owned output, raw byte bounds and failure recovery. The provisioned locked/offline gate remains unrun, and does not replace physical allocation or maximum-String-output evidence. Integrated upstream candidate commands while retaining every historical help snapshot control. No generated package bytes, public APIs or completion status are changed.
-
Bound Unix and Windows release packaging to an explicit fresh Cargo build directory instead of copying potentially stale default-target binaries. Preserved fresh output-root creation, tightened path-collision preflight, corrected Windows current-location and commit-length handling, and retained Unix host-query/smoke command failures despite matching stdout. Added fake-tool packaging regressions and clarified CLI-only commit embedding and trusted-workspace limitations. Tests and builds remain unrun; no release or production evidence is promoted.
-
Aligned native v8/v10 descriptor replay with the compiler's per-export parameter-identity uniqueness rule, rejecting correctly rehashed duplicate identities without changing canonical output or schemas. Added matching root/lower regressions and a real multi-module v10 npm publication consumer covering imported String helpers, control-bearing IDs, exact UTF-8 contents, raw bytes, failure/reuse and display rename. Native evidence stops at a rejecting publisher handoff. Tests/builds are unrun; nothing is promoted.
-
Authored published Project-v9 npm and native Rust consumer gates over one shared multi-module source fixture: colliding record display names, control and empty identities, opposite byte-field ordinals, checked failure and recovery, binary/capacity cases, output independence, exact package bindings, and display-only rename preservation. Native consumption uses the real private host and an isolated locked/offline Cargo workspace. Production generators and existing compatibility pins are unchanged; new tests remain unrun.
-
Corrected owned-data package semantic replay for distinct linked types with identical display names and for retained control-bearing identities. A private collision-only alias projection preserves original descriptor names and rebuilds checked HIR; source annotations now use SEMAPRAX string escaping. Added real Project/npm and rejecting-native-handoff regressions plus hostile recipe checks. Previously replayable recipe bytes and descriptor schemas stay unchanged. Tests and builds are unrun; no publication or promotion is claimed.
-
Aligned the additive v9 native descriptor reader with the compiler's retained identities and presentation names, including exact control-character JSON escapes. Preserved exported-method restrictions and same-identity consistency, restored the complete 256-function inventory bound, and added conservative pre-clone content charging plus shared root/lower canonical regressions. Existing accepted bytes and v8/v10 serialization remain unchanged; all new executable evidence is authored and unrun.
-
Strengthened frame-payload evidence around actual baseline/renamed Project subjects: exact npm/Rust descriptor and manifest bindings, retained-HIR interpreter/native corpus checks, and a raw-Wasm consumer observing the production arena. Corrected the private Rust build command and external consumer working directory, documented both quickstart CLI installations, and preserved historical help pins while accounting for upstream image commands. Tests and builds remain unrun; no release or production promotion.
-
Corrected authored native String fixtures to establish checked binary stdout through one shared test-only helper, including the native sides of internal interpreter/Wasm parity. Exact byte assertions, allocation counters, and generated runtimes remain unchanged. Strengthened the generic NUL corpus with an independent byte-length assertion. All affected tests remain unrun; this is no platform or production promotion.
-
Authored standalone owned-data provider String settlement and exact-content correction: reuse the existing per-function owner ledger and length-header helpers without changing public admission or Bytes ABI. String-bearing full provider translation units and dependent artifact bindings intentionally change, including unselected functions; String-free output, v10, commands, and private callable selection remain unchanged. Real-provider allocation and external-consumer evidence is authored but unrun; no promotion.
-
Authored publication corrections without changing generated package bytes: the shared Windows rename fallback explicitly clears legacy replacement authority, and calculator generation verifies final held-parent/output and original requested-parent bindings before reporting success. Once renamed, failure preserves the published tree and foreign replacements rather than attempting rollback. Added forced-fallback, substitution and residue evidence; new executable gates remain unrun and no support claim is promoted.
-
Authored an explicit source-only internal-String Web package selector with bounded source snapshots, pre-publication drift checks, exact compiler/runtime artifacts, a separate integrity manifest and a local scalar-call console. Reused the existing fresh-output publisher without widening its authority. Legacy Web builds now reject unsupplied String imports before output creation, including String use in materialized generic bodies; raw emission and successful String-free legacy output remain unchanged. Consumer, boundary and preservation fixtures are authored but unrun; no support promotion.
-
Authored a shared v8/v9/v10 npm invocation failure state: guarded preflight, exact checked-error identity, sticky falsy failures, absorbing reentry/host uncertainty, and settlement before publication. UTF-8 validation separates malformed text from host faults; output decoding preserves leading BOM data. Only runtime JavaScript and dependent integrity bindings change. Added real-package fault and preservation fixtures and corrected old quota probes to forbid post-poison reuse. Independent review also corrected standalone String admission to consume canonical owned HIR. All new executable evidence remains unrun; no support or production-readiness promotion is claimed.
-
Authored an explicit standalone Wasm internal-String compiler/runtime profile: compiler-directed scope/call/failure cleanup, checked allocation-capacity outcomes, fixed memory, bounded UTF-8 ownership and exact module binding. Added independent raw-arena, generated-host, native O0/O2 and interpreter regression fixtures. Existing target and package paths remain separate. Adversarial review also corrected earlier unrun loop fixtures to respect unchanged source/v10 admission. Tests/builds remain unrun; no ordinary-Wasm settlement or production promotion is claimed.
-
Added conservative semantic rebase and same-root merge for source-owned static protocol implementation intentions. Replay binds exact compiler-owned receiver, protocol, method and selected-function conformance facts and rejects occupied receiver/protocol pairs or implementation identities before full candidate admission. Named signature and receiver-field types bind retained checked-HIR identities, and protocol method order remains exact. Function bodies and postconditions remain outside the conformance fingerprint; behavioral equivalence, runtime witnesses and dynamic dispatch are not claimed. Focused evidence is authored and unrun.
-
Added source-owned static protocol implementation mappings, compiler-derived member discovery, the bounded
implement_interfaceintention, and additive v4 conformance/interface-catalogue queries over source-bound sidecar facts. Runtime Graph contracts and earlier protocol method sets stay unchanged; no runtime interface witnesses or dynamic dispatch are introduced. All eleven requested graph-operational operation classes now have bounded authored slices, not general implementations or verified completion. Extended the separate Unix bare-Git publication route to ordinary SHA1 alongside SHA256, with exact SHA1 staged-object readback and a SHA256 content binding; SHA1 is compatibility only, without collision-detection claims. Tests/compiler gates were not run for this batch, and no current-head status is promoted. -
Added an opt-in source-exact frontend cache with real parse/format reuse, disjoint expression holes with selector remapping, parameter renaming and conservative owning-Bytes signature migration. Added a replayable diagnostic repair intention and separate canonical Git-tree publication through an explicitly selected Unix bare-SHA256 host adapter and CLI. Raw checkouts stay unchanged; broader Git formats/hosts, general interfaces, warm HIR reuse and benchmark evidence remain open. Regressions are authored, unrun by request.
-
Added source-backed semantic image persistence and explicit refresh reports, candidate semantic delta replay, and diagnostic protocol v4 with optional host-selected tests. Added explicit store/load and diagnostic CLI commands plus an integrated signature/merge/managed-publication scenario. These remain authored and unrun; no warm HIR cache, raw Git-source publication or full graph-operational completion is claimed.
-
Added candidate-bound static test relevance and explicitly host-selected interpreter-test execution with fixed limits and replay-bound reports. Rejected attempts now retain bounded diagnostics and can offer one fully admitted integer literal repair. Added a separate candidate publication bridge through existing locked managed Workspace evidence and
ACTIVEauthority; original Git files remain unchanged. Test-enabled protocol v3 grants no source/build/native/Wasm authority. All new regressions are authored, unrun by request; the full graph-operational programme remains incomplete. -
Added typed cross-file scalar function moves and Copy record-field additions, including stable-ID import/call migration, constructor/pattern migration, exact identity allowances, source replay, discovery and semantic conflict checks. Added bounded data-access and unsafe-boundary HIR facet projections; current Project admission still excludes unsafe-bearing sources. Tests are authored, unrun by request. These additions grant no source publication or runtime authority and do not complete the graph-operational programme.
-
Added typed function declaration creation and bounded Copy-expression extraction, with exact new-identity inventories, namespace/effect checks, authenticated captures, unsafe-boundary rejection and source replay. Complete candidate histories can now be exported and restored through disposable recovery capsules, CLI commands and candidate-only protocol methods. Recovery revalidates the admitted source base and grants no source authority; incomplete drafts and persistent HIR remain outside this slice. Focused regression cases are authored but unrun by request.
-
Added typed body-expression replacement through current HIR identities, additive pre/postconditions, conservative stable-ID candidate rebase/merge, candidate protocol reconciliation and expression discovery, and closed constructor JSON Schemas. Candidates still re-enter complete canonical source admission; reconciliation reports carry no publication authority. Regression cases are authored but unrun by request. General operations, incremental/persistent reuse, complete schemas and source-commit integration remain incomplete.
-
Added ephemeral typed body-hole drafts, ordered built-in Copy signature mapping with hygienic left-to-right argument staging, and an opt-in candidate-only image protocol with bounded registries, replay validation, hole lifecycle, constructor discovery and report chunks. Unresolved drafts cannot expose materializable source. No source, test or runtime authority is added. Regression cases are authored, unrun by request; general changes, semantic merge, persistence and separate source commit remain incomplete.
-
Added immutable Project candidate overlays with a closed Semantic Change IR, stable-ID function rename, scalar parameter append/caller migration, and typed body construction. Previews materialize canonical source in memory, reparse and replay complete Project admission, retain diffs and structural impact, and bind emitted native/Wasm facts without source or runtime authority. Added HIR-backed image facets with bounded references and pagination, plus a separate self-describing read-only image protocol and generated client helpers. Tests are authored but unrun by request; the full graph-operational programme, runtime gates, incremental reuse, general holes, merge, and source commit remain incomplete.
-
Authored the first Semantic Workspace Image v1 foundation: a bounded, deterministic projection over retained Project revisions, complete graph and typed indexes, exact fresh replay, and digest-bound symbol/context/impact queries. Added explicit read-only image/replay/symbol CLI routes and an ignore convention for caller-persisted images. Canonical source remains authoritative; there is no trusted HIR deserialization, implicit cache, incremental compiler, or new commit authority. Regression evidence is authored, unrun at the user's request; no local, hosted, or completion status is promoted.
-
Kept owned-data generated-consumer build outputs in fresh short Cargo target directories, including frame-payload, standalone SDK, and v10 UTF-8 consumers. Added exact Windows UTF-16 object-path budget and isolation regressions; no consumer, corpus, or fail-fast gate was removed. Preserved the legacy help known answer while explicitly binding the three additive semantic-image command lines from the concurrent main update.
-
Integrated Dependabot PRs #13 and #14: pinned Android emulator runner 2.38.0 and wasmparser 0.258.0, including standalone Rust and Component lockfiles and exact CI pin contracts. Target Evidence now names the actual validator; current report/capsule/receipt known answers retain explicit old-binding preservation and
SPX-G132rejection before staging. Regenerate Evidence v2 capsules after upgrading; emitted target bytes and Evidence v1 are unchanged. Local workspace checking, strict workspace Clippy, and 53 focused tests passed (the target suite ran serially after a disk-space failure). All four affected lockfiles resolve offline with--locked. Fullscripts/quality.shcould not complete because the linker ran out of disk space; no hosted or completion status is promoted. -
Pinned embedded JavaScript to LF on every Git checkout. Windows CRLF conversion changed the owned-data runtime's authenticated bytes; the existing known-answer digest remains unchanged and a checkout regression guards it.
-
Kept the strict wildcard dependency ban while moving private-host CLI tests into the unpublished toolchain and pinning its local dependencies. Restricted a now-Unix-only publication helper accordingly and reduced Windows dev/test debug-artifact I/O without removing assertions or test gates. Bounded raw injected Windows replay carriers before parsing and refreshed exact CLI-help and pinned macOS desktop import-order snapshots without widening either gate.
-
Split private-host operations into the unpublished
semaprax-toolchainpackage andsemaprax-fullCLI. The standalone registry compiler rejectsnew,doctor, Native Rust package publication, and Windows revision-store host operations. Compiler replay and held-host authority boundaries remain explicit; tag archives select the full CLI. Added package-boundary regressions and repaired Darwin zombie-only doctor settlement and Windows-only lints. Hosted promotion remains gated on the complete exact-head CI result. -
Authored explicit expected-revision replacement for the prepared Project interpreter. Both candidate closures and source origins are admitted before one same-worker handoff; stale or ordinary preparation failures preserve prior execution, while panic or lost acknowledgement closes the worker. Existing trace schemas, evaluation, cancellation, and worker ceilings stay unchanged. Regression evidence is unrun; this is not incremental compilation or a production-promotion claim.
-
Authored opt-in
interpret-stringsand a distinct internal-String report schema/domain. The shared interpreter evaluates String helpers behind the unchanged external scalar/borrowed boundary; ordinary and Project routes retain their prior admission. Added bounded canonical replay, profile and source binding, hostile-wire and call/failure conformance fixtures. Tests are unrun; fuel limits are not heap-memory limits, and no target settlement or production promotion is claimed. -
Authored ordinary/stdout native String contents correction: construction, clone, equality, length, concatenation, prefix/substring operations, scalar count, and drop now share the existing length-header runtime. Embedded NUL is data throughout; no escaping workaround or source rejection is added. Frozen providers/commands and String-free output remain unchanged. Added exact-content and allocation evidence with cross-backend value cases and updated current-compiler target bindings. Tests/sanitizers remain unrun; ordinary Wasm settlement and production promotion remain open.
-
Authored ordinary/stdout native String failure settlement using the existing per-function owner ledger, plus runtime-helper discovery in materialized generic instances. Only String-bearing ordinary functions change; frozen command/provider outputs and String-free emission/budget paths are retained. Added physical allocation/status/poison regressions and current-compiler target-evidence binding coverage. All new tests and sanitizers remain unrun. Ordinary embedded-NUL semantics and Wasm String settlement remain separate open defects; no hosted, cross-backend, or production promotion is claimed.
-
Authored v10 native-provider inline String ownership settlement: initialized function-lifetime cells, explicit binding/branch/call/result transfers, normal scope cleanup, and sticky failure cleanup before result publication. Added physical allocation-accounting and consumer regressions; these are authored but unrun. Only v10 native C and dependent integrity bindings intentionally change. Ordinary native and earlier provider bytes, public admission, ABI/schema identities, and resource CleanupPlan semantics remain unchanged; their separate String failure-cleanup limitation remains open. No tests/builds or hosted workflows were run or changed, and no promotion is claimed.
-
Authored bounded doctor subprocess lifetime in the existing OS quarantine: fixed lexical
--version, restricted environment, combined output bounds, execution/settlement deadlines, and Unix-group/Windows-job fail-stop cleanup. The root CLI remains safe and report schemas are unchanged. Physical hostile fixtures are authored but unrun; no-network enforcement remains an open requirement, not a claim made by environment filtering. -
Corrected v10 Wasm inline String ownership for admitted direct-call argument expressions and owned parameters: cloned place reads, cleared temporary and call transfers, scope/failure cleanup, and a checked selected-call-path arena bound. Earlier profile bytes and the existing String admission remain frozen. V10 Wasm/JavaScript integrity bindings intentionally change. Native inline String failure cleanup remains a separate known gap; new regressions are authored but unrun and no support/promotion is claimed.
-
Added real offline linked-publication/reopened-replay fixtures, an explicitly provisioned Node consumer of the published package, and semantic-lock snapshot component mutation/cross-pair evidence using only reopened files. No production API/schema/artifact changes or hosted workflow edits accompany these acceptance fixtures. Tests/builds were not run.
-
Extended the existing bounded JavaScript input admission explicitly to v9/v10 while preserving v8 helper/rendered bytes. Added a shared generated Rust invocation guard that proves whole-context settlement before returning any owned/scalar/variant result or recoverable error, and prevents malformed discriminants from authorizing inactive-payload operations. Authored hostile provider and real-package input regressions. Added a committed standalone frame-payload consumer lock,
--locked --offlineexecution, strict provisioned TypeScript positive/negative fixtures, and a shared Node/Chromium corpus runner with a separate explicitly provisioned browser gate. No tests/builds were run and no hosted workflow changed. V9/v10 JavaScript and v8-v10 safe/private Rust bytes and integrity bindings intentionally change; public signatures, descriptors, provider C/ABI, and older profiles remain unchanged. All affected completion rows remain authored/unrun, unpublished, and unpromoted. -
Authored developer-preview boundary corrections: doctor preserves multicall executable names, skips non-executable Unix PATH shadows, and checks complete version tokens; v8 JavaScript admits complete bounded input tuples before payload snapshots and avoids constructor/species hooks; native opaque handles use all 4,096 slots with nonreused serials across live contexts and storage reincarnation; raw owned-data Wasm excludes complete selected helper-frame extents from result storage. Fixed the TypeScript consumer to pass explicit fetched bytes. Independent static review and regression fixtures accompany the changes; tests/builds were not run and no hosted/support status is promoted. Owned v8-v10 native/Wasm artifacts intentionally change; older public profiles and descriptor/signature schemas remain unchanged. V9/v10 JavaScript input hardening and doctor subprocess bounds remain open.
-
Authored Offline Published Semantic Lock Snapshot v1: an authority-free exact Resolver-v1 input capsule plus unchanged resolution-evidence and Lock-v2 bytes, with independent full replay and checked cumulative bounds. The safe lower publisher adds only a sealed fixed three-file create-new inventory and reuses the existing held/no-replace authority state machine, including a second replay immediately before publication and exact staged/published byte authentication. Hostile replay, raw-subject, bound, race, settlement, and build-v1/v2 preservation evidence is authored but unrun. No updateable lock, registry/cache, provenance, build, sandbox, target execution, support, completion, or promotion claim is made.
-
Authored additive Semantic Package Subject/Lock v3 and Offline Deterministic Package Resolver v2 with authenticated exact/tilde/caret dependency ranges, deterministic bounded backtracking, exact Lock-v3 replay, and hostile-input evidence. The evidence is locally unrun, unpublished, and unpromoted; all package v1/v2 bytes, APIs, diagnostics, and CLI routes remain unchanged.
-
Added an authored, unrun Windows-entry-v1 authority for Project Revision Store via explicit
identify_windows,persist_windows, andload_windowsAPIs. A new unpublished unsafe quarantine admits only drive-absolute fixed local NTFS roots with exact effective-SID/protected-DACL, reparse/ADS/8.3/link and stable-identity checks, a validated root-identity mutex, create-new held staging, and one no-replace non-POSIX handle-relative rename. A distinct Windows schema/domain preserves every ordinary Unix-v1 entry byte and digest; profiles cannot be silently adopted or migrated. Evidence is unrun; no hosted, cross-platform, public-cache, recovery, or production claim is made. -
Added the authored, unrun Prepared Project Interpreter and Source Trace v1: one cached exact entry/test closure admission, one sequential long-lived fixed-stack worker, bounded cancellation-aware expression origins, canonical trace replay, and retained revision source-origin verification. Existing Interpreter, Project execution, and Agent Transport v1-v5 wires remain unchanged.
-
Authored Linked Scalar Core-Wasm Package Build v2 as the first consumer of the exact Multi-Package Source Capsule replay seam. The authority-free build moves retained linked HIR into the unchanged scalar Wasm emitter, binds the selected closure, root-owned exports, capsule/source-set/link facts, and distinct canonical v2 manifest/evidence under cumulative bounds. The safe
publish_linkedfacade reuses the v1 exact three-file, two-replay, no-replace, settlement, and post-publication authority state machine. Real two-package, cross-pair/mutation, provider-export, boundary/fixed-point, and publication failure evidence is authored but unrun; v1 bytes/order remain preservation owners and no publication, target-conformance, provenance, or hermetic-sandbox claim is promoted. -
Hardened the authored Project Revision Store v1 without changing published entry bytes: every created-file replay is bounded to expected length plus one, exact Unix modes include special permission bits, one inert stage may be quarantined by top identity for unrelated loads while persistence remains blocked, and a pure locator permits post-pivot ambiguity to be resolved only by ordinary full replay. Added authored v1-v10 profile round trips and hostile residue, identity, and permission evidence; no local or hosted execution, cleanup, adoption, Windows support, cache, or promotion is claimed.
-
Authored Offline Multi-Package Source Capsule v1 above exact Resolver-v1, Subject/Lock-v2, and Report-v2 replay. The authority-free library admits two through four caller-owned effect-free scalar implementation sources, requires their source-derived direct import graph to exactly equal selected dependency metadata, exact-compares typed interfaces while omitting display/parameter names, binds an explicit root and only its explicit exports, and retains the ordinary linked HIR behind a crate-private future-build seam. Canonical wire, source/import/output bounds, root-only export, and hostile association evidence is authored but unrun; existing package bytes and APIs are preserved and no completion or promotion claim is made. This adds no build, publication, acquisition, registry/network/cache, provenance, execution, runtime enforcement, dynamic linking, or hermetic sandbox authority.
-
Authored Offline Effect-Free Scalar Core-Wasm Package Build v1 above exact Resolver-v1 and Lock-v2 replay. The authority-free compiler slice admits one dependency-free selected Subject v2, independently rebuilds its embedded canonical source, reuses the unchanged Public Scalar Export Profile v1, validates the exact seven-function runtime import and selected-export inventory, and exact-replays canonical manifest/evidence and Wasm bytes under cumulative bounds. A separate safe unpublished crate stages an exact three-file create-new inventory and performs no-replace local publication only after independent replay and held-byte comparison. Hostile canonical wire, root/subject association, dependency/capability/profile rejection, artifact cross-pairing, fixed-point bound, and publication evidence is authored but unrun; no local-green, hosted, support, release, or completion claim is made. This adds no acquisition, registry/network/cache, build scripts or external tools, multi-package source linking, target execution, runtime capability enforcement, trusted provenance, or hermetic OS sandbox.
-
Authored Offline Deterministic Package Resolver v1 and its focused public evidence above exact source-replayed Semantic Package Subject v2 inputs. The authority-free core fixes strict semantic-version ranges, deterministic transactional first-feasible backtracking, target and declared-capability admission, cumulative bounds, one final unchanged Lock-v2 generation/replay, and an exact independently replayable evidence wrapper. Report v1/v2, Subject/Lock v2, Lock v1, Compatibility v1, Graph, Project, and legacy CLI behavior remain preservation owners; root help gains only the additive command line. Evidence is intentionally unrun and no completion or hosted promotion is claimed. This adds no discovery, registry, network fetch, build-script or target execution, cache, publication, signature/trusted provenance, or runtime capability/build authority.
-
Authored additive source-authenticated Offline Semantic Package Lock v2 and stable-ID-only Compatibility Evidence v1. Unknown closure or authenticated lock-context drift is indeterminate. V1/V2 report, Lock-v1, and Graph bytes remain unchanged. Evidence is unrun; no completion or promotion is claimed.
-
Authored the closed Projected Owned-Byte Field Shared Borrow v1 tranche: exact direct stable-ID field provenance through aliases/ranges, additive Graph v24 with unchanged unprojected v23 schema/fields, prefix-overlap move safety, and interpreter/native/Core-Wasm lowering for
bytes_as_sliceon a named flat owned-byte record. Evidence is intentionally unrun and completion remains Partial. -
Authored additive Semantic Package Report v2 as a self-contained canonical source subject whose verifier reruns ordinary source verification, rebuilds validated HIR facts, regenerates the complete envelope, and exact-compares it. The unpromoted schema carries stable-ID type trees, ownership, effects, revision-independent structural contract facts, reachable nominal closure, and closed available/unavailable/unproven target evidence under separate projection, cumulative render-String, cardinality, and output bounds. V1 code, API, and bytes remain unchanged; its documentation now narrows re-mint claims to exact bytes and closed structural derivations. Focused evidence is authored but unrun; no compatibility, authority, local-green, hosted, or completion claim is made.
-
Added authored exact-boundary evidence for Shared Loan Plan v1. Deterministic typed-HIR fixtures now drive the canonical production planner and independent replay at exactly 4,096 program points, 4,096 CFG edges, and 1,000,000 checked work units, with isolated first-overflow diagnostics and hostile carrier reorder rejection. The work fixture derives its padding from exact production-counter deltas and reaches the production constant rather than a weakened test-only ceiling. The counter refactor preserves the schema, admission, cleanup meaning, backend bytes, diagnostics, and public ABI. The focused evidence was authored but not run in this audit, so no local-green or hosted promotion is claimed.
-
Authored Offline Package Lock v1 as an additive, read-only, independently replayable package graph above exact Interface Package Report v1 envelopes. The authority-free library and stdout-only CLI authenticate explicit finite subject bytes, stable module/version coordinates, dependency-first topology, report target intersection, transitive declared-capability closure, and only caller-supplied integrity-bound license/provenance claims under strict count/depth/byte/work limits. Cycle, diamond, duplicate, foreign dependency, version, schema, target, digest re-mint, legacy-report, helper-level limit, JSON-depth/output, and held-file alias evidence is authored but unexecuted; full production-builder exact/+1 fixtures for every frozen limit remain pending. This adds no resolver, registry, fetch, scripts, target execution, sandbox enforcement, source mutation, lockfile publication, trusted provenance, or completion-status promotion.
-
Added the explicitly injected, Unix-only Project Revision Store v1 for exact already-authenticated Project inputs. A closed content-addressed entry binds canonical manifest and sources, Workspace manifest/revision, Project revision, and graph digest; loading independently replays the complete recursive inventory and rebuilds ordinary Phase-A/HIR meaning. Unrelated retained entries receive one bounded, invocation-cached content-addressed metadata and structural authentication rather than an unbounded eager semantic rebuild. Publication requires a current-euid-owned exact-
0700held absolute root plus a host guarantee excluding uncooperative same-principal mutation; its advisory lock only serializes cooperating callers. Handle-relative create-new staging retains every created parent for later effects, settles files/directories, and uses same-root no-replace rename. Under that trusted-root contract, foreign, partial, colliding, drifted, or substituted structures are preserved and rejected; complete selected entries also reject truncated or foreign bytes. The receipt has no reusable authority; Transport v2-v5 and Project v1-v10 bytes remain unchanged; no daemon, ambient cache, build, recovery, eviction, GC, Windows-support, local-green, hosted, or promotion claim is added. A focused evidence subset is authored but was not run; complete profile and hostile coverage is not claimed. -
Added the unpromoted Project v9
flat-owned-record-api.v1implementation as the first additive follow-on to Project v8. Its distinct descriptor admits one direct owned-byte field with direct Copy-scalar siblings, while npm/Wasm and native-provider/safe-Rust adapters keep target aggregate layouts private and settle the sole opaque handle before host-object publication. The root compiler alone authenticates provider semantics; the unpublished lower package authenticates descriptor, byte-integrity, held-tool, and retained- stage publication facts. Evidence is authored but was not run, the generated packages are unpublished, and neither local nor hosted promotion is claimed. -
Added the authority-neutral Project Profile Admission v1 kernel and removed the obsolete blanket Project-v9 Phase-A rejection. Retained Project snapshots now expose separate replay-checked v9 flat-record and v10 owned-UTF8 descriptor accessors, while the existing v8 accessor and Transport v5 remain strictly v8-only. Project-v9 npm and Rust success messages now identify the selected profile truthfully. The implementation and preservation evidence are authored but unrun; no package publication or profile promotion is claimed.
-
Added the unpromoted Project v10
owned-utf8-api.v1implementation above the Project v9 physical adapters. Its distinct canonical descriptor admits mixed scalar, owned-byte, and length-delimited UTF-8 results. Wasm/npm copy and consume an opaque owned carrier before fatal decoding; the native provider validates exact bytes before publishing a handle; and generated safe Rust settles the handle beforeString::from_utf8, including hostile invalid-UTF-8 conversion. The lower package independently selects the exact v10 digest domain and rejects unknown schemas. Project v1-v9 identities and carrier numbering remain additive preservation requirements. Evidence is authored but was not run, and no hosted or publication claim follows. -
Recorded the upstream baseline blocking matrix at exact commit
4cc03820c86e70527cb65c4b10ee3841c7af167d: all 23 jobs are green in run 33259787886, and the matching mdBook is green in Docs run 33259787881. Command-I/O and the line-filter now pin their real Shared Loan Plan composition as Graph v23 while retaining the v19/v20 facts; the lexical transfer negative control keeps its view live after transfer; and the Native Rust builder's exact capacity envelopes include every retained loan plan. The shared Windows job replaces the duplicate all-target/all-feature interop diagnostic with the focusedwindows_library evidence under a five-minute cap; that diagnostic completed in 77 seconds and the formerly starved desktop, UI, documentation, release, example, and package tail all passed. The generated Rust builder remains unpublished, and no registry, general aggregate/resource ABI, or multi-engine browser claim follows. This run predates the later WP-01–WP-15, Project v8, Agent Transport v5, Project v9, and Project v10 source work; it does not execute or promote any of those additions. WP-04 tagged artifact/release promotion and WP-15 Project v8 hosted promotion remain pending. -
Added the authored exact additive Project Manifest v8
owned-data-api.v1implementation behind its closed profile. One canonical, domain-separated public API descriptor now derives from authenticated linked HIR and is independently replayed before driving directBytes,Option<Bytes>, andResult<Bytes, i64>npm/Wasm bindings or the safe Rust package. The Rust route keeps semantic/provider emission in the root compiler and delegates held compiler/archive tools, deterministic package rendering, no-clobber publication, and verification through retained stage authority to the dependency-invertedsemaprax-native-rust-owned-data-packagecrate. Generated safe Rust forbids unsafe code; opaque provider-handle FFI remains private, and no allocator transfer is introduced. Project v1–v7 preservation evidence is authored. These gates were not executed by this documentation audit, the packages are unpublished, and exact-head hosted promotion remains pending. -
Added the frame-payload Project v8 validation product with one committed binary-frame corpus shared by the reference interpreter, native C11 O0/O2, Core Wasm/Node, generated npm, and generated Rust consumer lanes. Authored evidence compares exact branches, bytes, language errors, semantic status, cleanup/settlement facts, and stable API identity before and after a display-only rename. The product is repository evidence, not a hosted-green, browser-breadth, registry, stable-ABI, or release claim.
-
Added opt-in read-only Project Agent Transport v5 with exactly
project/api-describeandproject/npm-build-inlineabove the preserved v2 inspection method set. Responses bind exact retained Project/workspace revisions, canonical descriptor bytes/digest, an independently replayed npm carrier, and an exact typed descriptor subject under the complete response budget. The profile adds no filesystem write, process, target selection, publication, mutation, persistence, or reusable authority. Focused hostile and preservation evidence is authored but was not executed by this documentation audit; local and hosted promotion remain open. -
Added the WP-01–WP-15 developer-preview implementation audit to the completion matrix. CI decomposition, deterministic versioning, release packaging,
doctor,new, the executable quickstart, and Project v8 WP-08–WP-14 are distinguished as authored-but-unrun implementation/evidence. WP-04 v0.2 promotion and WP-15 Project v8 promotion remain explicitly pending, no long-term row moves to Implemented, and no exact-head hosted result is claimed. -
Added the locally evidenced Shared Loan Plan v1 proof layer for bounded synchronous immutable borrowing rooted in
ownstorage. Dense resolved-function-local loan identities, exact owner-place and parent-reborrow provenance, multiple shared loans, path-sensitive CFG-edge last-use endpoints including distinct normal/residual?successors, independent replay, and checked limits of 256 loans, 4,096 program points, 4,096 edges, and 1,000,000 work units select Graph v23 while preserving legacy Graph and cleanup bytes when no plan is required. This is the foundation for, not admission of, nested owned aggregate borrowing; it adds no runtime loan object, public borrowed ABI, or hosted promotion claim. Semantic Workspace v1 fails closed rather than allowing Graph v23 to mask a simultaneous owned-variant Graph v22 base contract. -
Added the locally evidenced Owned Byte Variant Algebra v1 tranche: flat monomorphic authored variants with direct
Bytesplus Copy scalars, and the exactOption<Bytes>,Result<Bytes, i64|bool>, andResult<i64|bool, Bytes>instances. Cleanup Inventory v2, independently replayed CleanupPlan v6, and Graph v22 encode case-qualified conditional ownership. Focused interpreter, native C11-O0/-O2, and Core-Wasm/Node gates cover borrow/own matching, dynamic calls/results, payload-free cases, exact settlement, and hostile carriers that terminate or trap before cleanup or publication. Nested/generic non-Copy variants, non-Copy postfix?, and public aggregate ABIs remain closed; hosted promotion is not claimed. -
Reorganized documentation by audience without moving established specification paths. The README and
docs/index.mdnow form the public entry path;docs/DEVELOPMENT.mdowns contributor navigation; the mdBook separates public references from internal, private, and proof-only contracts. Architecture, quality gates, and roadmap now each have one clear responsibility. The completion matrix replaces the ambiguous mixed “56-row” dashboard with a fixed 49-requirement product contract and a separate v0.2 release-exit audit; historical milestone narration remains in this changelog. Every book document now states its status and audience near the title, and the documentation test enforces metadata plus exhaustiveSUMMARY.mdcatalog coverage. -
Added the locally evidenced Owned Byte Record Algebra v1 tranche: flat monomorphic records with direct
Bytesplus direct Copy scalars, explicitmatch own/match borrow, propagated drop-aware type facts, exact projected cleanup inventory, independently replayed CleanupPlan v5, and Graph v21. The interpreter, native C11-O0/-O2, and Node/Core-Wasm lanes move rather than shallow-copy each owned field and cover multiple leaves, borrowing, repeated entry, hostile plan drift, and success/failure settlement. Legacy Value-match Graph bytes remain pinned. Nested/generic/class/variant/resource shapes and every public aggregate ABI remain closed; hosted promotion and completion-status changes are not claimed. -
Added the locally evidenced Project Manifest v7
line-command-io.v1product tranche: explicit falliblebyte_rangewith the exact two-codesemaprax.byte-range.v1domain, Graph v20, CleanupPlan v4, cumulative stdout/stderr append under one 65,536-byte atomic semantic settlement bound, authenticated invocation-local Wasm descriptors, and independently replayed npm carrier schema v6. The committed multi-modulespxgrep-linesfixture is exercised through interpreter, native, and Core-Wasm/Node paths; real-browser and multi-engine execution remain open. Cross-module borrowing widens only to monomorphicborrow Slice<u8>parameters returning a non-borrowing scalar. Hosted promotion, general I/O/borrowing, Windows-safe npm publication, registry/release publication, and broad v0.2 completion remain open. -
Added a private plain-C dynamic consumer lane for the callable-v3 provider ABI, the first non-Rust consumer of the same generated corpus providers. The new
private-c-consumer-v1-fixturebin emits the discard-two, requires-false, and identity-max directions as provider sources with exact SPXNABI3 descriptors and manifests, and a hand-written strict C11 consumer dlopens each compiled provider at O0/O2 on the local Linux/macOS host to drive the descriptor getter, execute, and settle wire sequence directly: descriptor-driven argument packing for[Owned(u64)]and[Owned, Bool]shapes only (fail-closed otherwise), its own SHA-256 for request/frame digests, a replicated fixed 172-byte settlement-decision layout with static size asserts, exact outcome-line matching (scalar0with finalizers1:13then0:11; the selected failure ordinal inside the emitted trace; owned publication of ordinal0with payloadu64::MAX), byte-identical idempotent re-settlement, and stale re-execution rejection. The executable gate lives incrates/semaprax-native-host/tests/runtime_c_consumer_lane.rsand is pinned as one Linux step of the sharedverifyCI job; no hosted device, simulator, public-admission, orSPX-B104claim follows. -
Added a strict unpublished Project Rust SDK workspace binary that delegates once to the authenticated builder and emits one canonical
semaprax.project-native-rust-sdk-result.v1result. Expanded the local calculator browser proof to exact direct, baseline Project, and known-answer display-renamed Project fixtures: the same committed shell executes all three, while the six-function ABI and all six non-manifest generated artifacts remain byte-identical across the rename. Project/workspace HIR linkage now lives insrc/hir/workspace_link.rswithout semantic or authority changes. This is local evidence only and adds no hosted promotion, root/installed/public CLI, registry, general SDK/browser support, or completion-status change. -
Promoted the focused calculator Product Acceptance and Public Native Rust SDK matrices to blocking Ubuntu, macOS, and Windows configuration while keeping hosted promotion pending until the resulting exact-head run passes. The Windows SDK's archive, live-descendant denial, and minimal inventory gates passed at
d27ba9c, but its masked final consumer exposed Node 22's upstream failure to resolve a canonical\\?\entrypoint. The real Wasm execution now preserves the canonical fixture authority as its working directory and gives Node the single relativecalculator.mjsleaf; command inspection and source contracts prohibit reintroducing the incompatible absolute entrypoint. The unrelated private A+B Windows lane remains diagnostic and no broader interop or package claim follows. -
Hardened Public Native Rust SDK Phase C at the archive and nested-Cargo boundaries without claiming hosted promotion. Darwin archive execution now returns a closed failure phase plus
Settled/Uncertainevidence. A successfulmkdiratfollowed by a failed scratch reopen is explicitly uncertain, every failure after archiver process entry is absorbing, known process output is rejected before cleanup or rechecks, and no uncertain path performs speculative pathname deletion, stage discard, outer construction, later tool work, or publication. Table-driven macOS evidence exercises every post-process phase and preserves inert archive/foreign bytes; the local platform-sys suite is 35/35. Linux and Windows archive errors remain conservatively uncertain at the safe facade because their legacy sys result carries no settlement proof. On Windows, every nested external Cargo command validates and binds the absolute x64 MSVC target linker and removes the ambientLINK/_LINK_option channels before build-script linking while preservingLIBandINCLUDE. Windows C object compilation now also fixes-mno-incremental-linker-compatible, which zeroes the COFFTimeDateStampthatlib.exe /BREPROcannot normalize inside a member; the real archive gate compiles twice and requires exact object equality before admission. Hosted inventory mismatches now report only bounded per-file lengths, SHA-256 digests, and first differing offsets instead of formatting binary archives. The linker binding is bounded pathname configuration, not held-linker-image, ancestor-reparse, or same-path-race authority. The actual hosted macOS success-path predicate, Windows deterministic package confirmation, and the full exact-head promotion matrix remain pending. -
Closed the local v0.2 calculator-product evidence gaps without widening the admitted scalar profile. The committed browser calculator now consumes both a direct
semaprax.web.v4package and the multi-modulesemaprax.web-project.v1package through the same four interactive arithmetic operations; its dual-fixture preflight authenticates both schemas and all six stable-ID exports, strict TypeScript checks all six calls in both generated consumers, and one serial Chromium lane exercises the four UI operations against both packages. Public Native Rust SDK Phase C now has an explicit one-way settled publication state: after the final exact inventory replay it releases all nine leaf handles, closes both child-directory authorities, and retains only the authenticated root for the no-clobber rename required by Windows. Failure after settlement preserves exact inert residue. CI now fetches the root lockfile before offline product execution, invokes the intentionally unsettled Windows negative control explicitly, and keeps the new settled nested-publication regression blocking. These changes are locally evidenced; exact-head hosted promotion, registry publication, and general SDK/browser claims remain pending. -
Closed the ordinary Project v6 native product path. Semantic Workspace now admits current Graph v19 source facts; the Project linker keeps pure
mainand effectful command roots distinct, then retains both while binding the manifest-selected stable command identity explicitly.semaprax build semaprax.toml --target nativenow proves binary match/miss/usage, exact cumulative input capacity and plus-one failure, pre-existing destination preservation under the documented trusted precheck, and display-rename stability. Project meaning is also split into authority-neutral immutableProjectRevisionstate and liveProjectSnapshotfilesystem/publication authority; this adds no persistence or recovery claim. -
Added the locally evidenced Bounded Language Command I/O v1, additive Graph v19, and Project Manifest v6. Checked code gains four compiler-owned operations for argument count, UTF-8 argument views, one owned binary-stdin read, and bounded stderr, under exact declared effects and a closed four-code failure domain. One immutable invocation snapshot excludes
argv[0], permits at most 16 strict UTF-8/NUL-free arguments, admits one CommandArguments plus one Stdin source, rejects a duplicate of either, and charges their bytes once against a cumulative 65,536-byte budget. Distinct stdout/stderr transcripts allow at most one write per channel and path, share one 65,536-byte output bound, and publish together only after the bool result and cleanup settle. HIR uses a distinct host-command call; canonical CleanupPlan v2/v3 builder/replay authenticates borrowed argument provenance and success-only owned-stdin initialization. Interpreter, native C11 O0/O2, and Core-Wasm/Node execute the same contract; Wasm privately stages tagged owned stdin bytes while live instead of treating arena tokens as memory addresses, accepts only exact 0/1/2 argument-provider statuses, authenticates zero-status stdin arena membership and recorded length before initialization, and zeroes private staging after successful publication. Project v6 selectslanguage-command-io.v1, emits and replays its semantic npm carrier, and preserves earlier manifest/package/carrier bytes. Windows publication remains fail-closed. Hosted promotion, safe Windows npm publication, registry/release promotion, files/environment/network/child processes, streaming or interactive I/O, physical cross-descriptor atomicity, and durable writes are not claimed; affected rows remain Partial and totals remain 56 Partial/0 Missing. -
Reorganized the native C11 compiler implementation along review boundaries:
src/codegen.rsretains its established entry/admission surface and runtime payloads,src/codegen/native_emit/mod.rsowns emission orchestration and function/layout projection, andsrc/codegen/native_emit/expression.rsowns expression and place lowering. Existing entry points, output profiles, validation order, and authority boundaries are preserved. This is source organization only: it adds no language, HIR, Graph, CleanupPlan, backend semantics, runtime authority, target support, hosted promotion, or completion-status change; totals remain 56 Partial/0 Missing. -
Added target-bound owned-resource corpus fixture emitters for the private mobile lanes:
emit_private_native_callable_v3_android_corpus_fixture(Android dynamic x86_64/arm64) andemit_private_native_callable_v3_ios_corpus_fixture(iOS static targets) derive one exact provider sealed around any canonical corpus case, including semantic-failure witnesses such asrequires-false, through the existingcorpus_witness_planmachinery already proven at O0/O2 on desktop. Pinned tests require byte-identical rebuilds per target and distinct descriptors across targets. This is compiler-emission groundwork only: the Android JNI and Apple Swift harnesses, instrumentation, and hosted jobs do not consume failure-direction fixtures yet, no device or simulator execution is claimed, and completion totals stay 56 Partial/ 0 Missing. -
Added locally evidenced Project Manifest v5 and the fixed
useful-data-command.v2adapter while preserving Project v1-v4 manifests, packages, carriers, and behavior. The exact manifest separates the SEMAPRAX closure's existingprocess.stdout.writeeffect from the adapter's closedprocess.args.read,process.stderr.write,process.stdin.read, andprocess.stdout.writeauthority. One UTF-8 argument plus binary stdin share a checked 65,536-byte bound; native Project builds invoke the authenticated command stable ID rather than legacymain, matching the existing Wasm/Node result, success-only transcript, and 0/1/2 exit policy. Windows useswmain, strict UTF-16-to-UTF-8 conversion, and binary stdio; Unix validates argument UTF-8 and treats broken stdout/SIGPIPE as adapter failure. The seven-file npm package is independently replayed undersemaprax.project-npm-build.v4withsemaprax.useful-data-command.v2metadata. Hosted CI, safe Windows npm publication, registry/release promotion, general I/O, atomic physical stdout, executable determinism, and a stable public native runner ABI are not claimed; completion rows remain Partial. -
Added locally evidenced Bounded Stdout Transcript v1 and Project Manifest v4. Compiler-owned
stdout_writehas exactprocess.stdout.writeauthority, a 65,536-byte success-published transcript, one-write-per-path analysis, and loop/cycle rejection. Interpreter, native O0/O2, and Core-Wasm/Node preserve exact bytes and discard every failed invocation; Wasm adds no stdout/WASI import. The additiveuseful-data-command.v1profile emits an independently replayed seven-file npm command package. Its compiler-freespxgrepfixture prebuffers a UTF-8 needle plus binary stdin under one bound, performs a real nested indexed-byte search, flushes once after semantic and arena settlement, and uses exact match/no-match/adapter-failure exits. Legacy Project v1-v3, Graph, cleanup, and Useful Data paths remain unchanged. Hosted promotion, safe Windows publication, registry publication, and general language I/O remain open, so completion totals and Partial status do not change. -
Added locally evidenced Indexed Byte Loop v2. Bounded loops may perform immutable
byte_len/byte_getreads and exhaustively match the exact compiler-ownedOption<u8>result with guard-freeSome/Nonearms. Source and hostile-HIR gates keep view construction, allocation, owned values, general aggregate matching, effects, and imports closed; the indexed match itself adds no cleanup slot, action, status source, or back-edge. The binary-frame fixture now traverses dynamic indices rather than checking fixed offsets, with interpreter, native O0/O2, and Core-Wasm/Node evidence. Useful Data and the completion matrix remain Partial pending their existing hosted and public promotion gates. -
Added the locally evidenced Project Manifest v3 / public Useful Data v1 adapter tranche. The closed
useful-data.v1profile links the authenticated entry, test, and disconnected stable-ID export closures without widening v1 or v2 manifest bytes; reconstructs exact byte-operation, provenance, capacity, and cleanup facts across Project linking; and admits source Graph v15-v17 only at Semantic Workspace/Project preflight boundaries. SelectedSlice<u8>inputs and scalar results lower to fixed-memory Core Wasm and a strict snapshotting JavaScript/TypeScriptUint8Arrayfacade. The exact six-filesemaprax.project-npm-build.v2package has independent carrier replay, tamper rejection, offline pack/install, and compiler-free installed consumer evidence in the multi-module binary-frame fixture. Unix publication uses handle-relative, create-new, no-clobber authority; Windows v2 publication deliberately remains fail-closed until an equivalent safe primitive exists. This remains Partial: exact-head hosted promotion, Windows v2 publication, npm registry publication, and release promotion are open, and completion totals are unchanged. -
Added the second local internal Portable Indexed Byte Data v1 tranche. Target-independent checked
usize, fixed[u8; N]syntax and size-N/align-1 layouts, uniquely owned immutableBytes, and non-escapingSlice<u8>now reach source/HIR/hostile validation, Graph v17, the interpreter, native C O0/O2, and internal Core-Wasm/Node execution. The closedbyte_len,byte_get,bytes_copy,bytes_as_slice,array_as_slice, andstr_as_bytesoperations preserve exact NUL/0xff/invalid-UTF-8 bytes. Independent capacity analysis enforces frame, active-call-path, allocation site, payload, and mixed text/slice external-root bounds. Conservative lexical borrowing protects named owners, andBytesmoves, call epochs, failures, guarded finalizers, and result publication consume canonical CleanupPlan state through onecore.bytes.dropleaf. The later Project Manifest v3 tranche supplies bounded public Project, npm, and typed-array adapter evidence; complete hosted promotion and registry publication remain open, so the full Useful Data goal remains Partial. -
Moved Economic Agent unit proof code from the production module into
economic_agent/tests.rswhile preserving every existing test path and behavior. -
Added the locally evidenced Useful Text Consumer v1 / Project Manifest v2 tranche. Source and hostile HIR now admit a non-escaping
borrow strinput view with compiler-owned byte-length, empty, prefix, and contains operations; cleanup remains inert, the interpreter preserves invocation-root provenance, native C checks null, length, and UTF-8 over host-provided readable storage, while Wasm/JavaScript additionally validates linear-memory ranges and uses validated UTF-8 with fixed scratch. Every invocation has an exact 65,536-byte cumulative borrowed-input ceiling; contains uses linear-time byte-KMP, with a fixed native table and a caller-visible reserved two-page Wasm table beside the one-page public scratch region. Native root admission charges each external view once, nested aliases do not recharge it, and text-profile call cycles reject before emission. Project v2 adds canonical package version/profile metadata, disconnected stable-ID export-root linking, generated JS/TS, a create-new exact six-file npm package, and the context-boundsemaprax.project-npm-build.v1pathless carrier. The opaque prepared build retains trusted Project facts for publish authorization; context-free envelope inspection proves compiler consistency only. Local evidence covers Unicode/embedded NUL, periodic worst-case KMP at the exact byte bound, native O0/O2, Wasm, stable-ID display rename, carrier tamper rejection, and offline pack/install/consumer execution while preserving Project-v1 and scalar Web bytes. Exact-head hosted promotion is pending. This text tranche does not claim arrays, owned byte buffers, iteration, general text processing, dependency resolution, or npm registry publication; the separate internal indexed-byte tranche remains non-public. -
Expanded the v0.2 product-acceptance runner to the complete six-operation multi-module calculator Project. It executes the authenticated entry and test closures through the interpreter, native C11 at O0/O2, and Core Wasm, the direct and daemon-returned Web package, and the complete Transport-v4 derive/preview/impact/review/apply/build cycle. The same runner optionally requires the pinned TypeScript 5.8.3 declaration consumer when
SEMAPRAX_REQUIRE_PROJECT_TYPESCRIPT=1and baseline plus post-rename Project Rust SDK consumers whenSEMAPRAX_REQUIRE_PROJECT_NATIVE_RUST_SDK=1, while preserving stable-ID Web and Rust behavior across changed Project/workspace/source/subject revisions. It compares semantic Web scalar ABI and exact Rust export facts instead of revision-bound whole manifests. A focused pinned CI lane requires the TypeScript and held-tool Rust paths on Ubuntu and macOS; Windows remains explicitly diagnostic-only, so full hosted promotion is still pending. -
Added locally evidenced Project Agent Workflow v1. The explicit
semapraxd --stdio --allow-project-workflowv4 profile preserves v2/v3 and adds server-derived rename intent, candidate-bound Project Impact and fixed-section Review, A0 apply, exact refreshed state, and a pathless Web-only inline build carrier with independent seven-artifact replay. Requests gain no path, source/patch, output, tool, process, environment, native, or Rust build authority. The real daemon gate materializes the verified carrier and runs the stable-ID Node calculator after the rename. General/multi-file change, hosted promotion, recovery, and exactly-once delivery remain open; totals remain 56 Partial/0 Missing. -
Added locally evidenced Project Native Rust SDK v1. The unpublished builder accepts one root-authenticated Project Manifest v1 subject, consumes its already linked and validated entry HIR without flattening or reparsing, and emits the existing exact nine-file dependency-free Rust package for the manifest's stable-ID Web-export set. Distinct target-neutral subject, target-specific descriptor/bundle, and outer SDK schemas bind canonical manifest bytes, Project/workspace/graph revisions, complete source facts, exact export origins, current-target ABI, and artifacts under separate digest domains. Local calculator evidence runs Web/Node and Rust consumers, applies the opt-in daemon display rename, shuts the daemon down, rebuilds, and proves stable-ID behavior across changed authenticated revisions. It does not assert whole-package byte equality. Hosted promotion, root CLI, registry, dependencies, and general Project/import/capability/aggregate/ resource support remain pending; completion statuses and totals are unchanged.
-
Added the ownership control-flow regression battery v1 (
tests/ownership_control_flow_v1.rs): fourteen pinned cases locking the exact move-safety behavior across lazy boolean operands, match scrutinees, refutable-match guards, branch-block joins, while-loop admission (SPX-T252), explicit-mutation boundaries (SPX-U105),?propagation with live resources (SPX-T218), and borrowed-parameter transfer (SPX-O102), alongside admitted conditional-move success cases. The audit behind it found no verifier soundness holes; the battery converts that audit into executable evidence for the "Unique ownership and move safety" row. Status stays Partial; totals remain 56 Partial/0 Missing. -
Added locally evidenced, opt-in Project Rename Transaction v1. Running
semapraxd --stdio --allow-project-renamereports Project Agent Transport v3 and admits one preview-digest-bound display rename of one explicit-ID scalar function selected by Projectweb_exports. Preview validates one complete candidate Project; apply overlaps held Project authentication with the unchanged single-file A0 lock/snapshot authority, preflights success before writing, consumes A0 once, reloads exact candidate state, and fail-stops withSPX-J110on post-boundary uncertainty. Default v2 remains byte-preserved and read-only. General/multi-file change, client patch/path authority, exactly-once delivery, and hosted promotion are not claimed; totals remain 56 Partial/0 Missing. -
Added the locally evidenced Project Agent Transport v2 and
semapraxd --stdio: one host-bound Project v1 session retains the single Phase-A graph, linked entry/test HIR, and typed context index; serves revision-bound snapshot/check/graph/context/test requests; and absorbs drift before cached meaning can escape. Build/change/network/disk-persistence authority remains open, so completion totals stay 56 Partial/0 Missing and hosted promotion is not claimed. -
Added Public Project Developer Loop v1:
semaprax runandsemaprax testnow evaluate the exact authenticated Project v1 entry or manifest-declared test closure in process, with bounded fuel/output, deterministic revision/stable-ID/outcome evidence, no discovery, and no artifact or child process. The implementation also splits project and CLI responsibilities into smaller modules without changing their authority boundaries. This is local evidence inside existing Partial rows; totals remain 56 Partial/0 Missing and no hosted promotion is claimed. -
Added batch-3 additive tranches:
- String operations breadth v2 — reserved intrinsics
string_starts_with,string_contains,string_len_chars,string_from_charfollowing the string-ops v1 architecture with a separate v2 gating group so v1-only programs keep byte-identical C/Wasm bytes; native+Wasm evidence intests/string_ops_v2.rs(examples/string_ops_v2.spx). - Property-test generation widening —
semaprax propertiesgenerates and evaluates the full Copy-scalar surface (suffixed ints, canonical chars, bit-pattern floats) including bounded while loops under fuel, with legacy reports replaying byte-identically; evidence intests/property_widen_v1.rs. - Refutable match v1 exists as an UNVERIFIED work-in-progress branch
(
feat/refutable-match-v1); it is not merged intomain.
- String operations breadth v2 — reserved intrinsics
-
Added the parallel batch-1/batch-2 language and projection tranches (isolated worktrees under
.agent-worktrees/, merged intomain):- String operations v1 — reserved
core.string.*intrinsic calls (string_len,string_concat,string_is_empty) admitted through the ordinary monomorphic call path with borrow/move ownership, native C11 O0/O2 + Node/Wasm + interpreter equivalence, gated C helpers/host imports, and pinned evidence intests/string_ops_v1.rs(examples/string_ops.spx,docs/STRING-OPS-V1.md). - Field mutation v1 — statement-only direct scalar Copy-field assignment
<binding>.<field> = <expr>;onlet mutrecord/class locals with diagnosticsSPX-U107-SPX-U112, additive graph"field"attribute, unchanged CleanupPlan shapes, and native+Wasm equivalence intests/field_mutation_v1.rs(examples/field_mutation.spx,docs/FIELD-MUTATION-V1.md). - Bounded while-loop v1 —
while <bool> { body }under a Copy-scalar admission profile with diagnosticsSPX-T251-SPX-T253/SPX-G410, program-level Graph v15 selected above v14, linearized cleanup-plan iteration with fail-closed liveness guards, native/Wasm loop lowering, fuel-accounted interpretation, andtests/while_loops_v1.rs(examples/while_loops.spx,docs/WHILE-LOOPS-V1.md). - Reference Interpreter scalar widening — admission widened to the full
Copy-scalar surface (
i64/i32/u8/bool/f32/f64/char) including suffixed/float/char argument parsing, with a 24-row cross-backend parity corpus intests/interpreter_scalar_widen_v1.rs. - Interop scalar widening —
semaprax abi-report,semaprax c-header, andsemaprax cxx-shimadmit the full Copy-scalar surface with verbatim native-line digests and byte-level Wasm cross-consistency intests/interop_scalar_widen_v1.rs. - Schema scalar widening —
semaprax openapi,semaprax package-report, andsemaprax ui-schemaadmit the full Copy-scalar surface with bound-aware compat classification, layout cross-consistency, and pinned widened KATs intests/schema_scalar_widen_v1.rs. - Class single inheritance v1 —
class Child : Parent { ... }with ancestor-prefix layouts, static nearest-first method resolution, exact- signature overrides,super.m(...)calls, typed-let upcasts (ResolvedExprKind::Upcast), diagnosticsSPX-T227-SPX-T234, and a cleanup-inert suffix rule keeping plan schemas unchanged; evidence intests/class_inheritance_v1.rs(examples/inheritance.spx,docs/CLASS-INHERITANCE-V1.md). - Frozen KAT digests and HIR capacity pins are re-pinned for honest AST/HIR builder-bytes growth from the new syntax; programs without the new constructs keep byte-identical projections.
- String operations v1 — reserved
-
Added the String + Object-Oriented Types large-implementation tranche (branch
feat/string-oo-types, worktree.agent-worktrees/string-oo):- Owned heap
stringvalue type end-to-end —"…"literals with canonical escaping,Type::String/ResolvedType::String(copy=false, needs_drop=true,owned:stringfacts), move/borrow ownership, cleanup plans, graph nodes, deterministic canonical round-trip, native C11 O0/O2, browser/Wasm, and interpreter equivalence with pinned KATs intests/string_scalars.rs(examples/strings.spx). String arithmetic and concatenation are rejected fail-closed until the allocation tranche. classdeclarations with fields, methods, construction, and static method dispatch end-to-end — canonical projection, additive graph nodes, Native64/Wasm32 sequential layouts, native+Wasm lowering, andtests/class_declarations_v1.rs(examples/classes.spx). Inheritance syntax is rejected fail-closed with a stable diagnostic until Badge 4.protocoldeclarations + read-only Protocol Projection v1 —semaprax protocol-check <file>emits one digest-authenticated canonical envelope; conformance stays explicitly empty; program-graph schema stays v10–v14 with protocol nodes explicitly deferred;tests/protocol_projection_v1.rs.- Frozen workspace/workspace-graph KAT digests are re-pinned for the honest builder-bytes growth caused by the new AST/HIR variants; all other bytes stay byte-identical for programs without the new syntax.
- Owned heap
-
Added the locally evidenced Region Structure Report v1 tranche, the first executable slice of the completion-matrix row "Regions/arenas", moving that row from Missing to Partial. The new read-only
semaprax region-report <file> [--max-bytes N]command andregion_reportlibrary API emit one deterministic digest-authenticated canonicalsemaprax.region-report.v1JSON envelope per verified module: a lifetime-structure report for every admitted explicit-ID monomorphic effect-free scalar function, derived entirely from facts the existing borrow/move checking already proves. Per function the report carries the binding lifetime partition (parameters,let/let mutlocals, and match pattern bindings with real resolved-HIR value ids, ownership modes, canonical type keys, definition offsets, effective live-range ends measured at innermost statement/tail granularity, and use counts), canonical region clusters under the rule that overlapping live ranges can never share one region (greedily clustered in canonical binding-id order), explicit escape facts naming ownership checkSPX-O104as the reason every borrow today is provably non-escaping, move facts recomputed from the resolved call graph (own-consumption sites plus derived moved bindings), and maximal bulk-release grouping candidates (sets of at least two bindings whose effective ends coincide); every non-admitted function is recorded with one of six closed exclusion reasons mirroring the shared scalar profile.verify_envelopeindependently replays bytes, counts, vocabularies, orderings, the full greedy clustering re-derivation from reported live ranges, escape/move derivations, and exact bulk-release groupings, so forged-but-re-signed mutations still fail closed;verify_envelope_against_sourcefails closed on drift. Diagnostics use the previously unusedSPX-L1xxfamily (SPX-L101options,SPX-L102fail-closed budget exhaustion without truncation,SPX-L103consistency).tests/region_report_v1.rspins golden KAT digests overexamples/calculator.spxandexamples/meaning.spx, proves determinism, exercises every exclusion reason, cross-checks every reported binding id against the real resolved-HIR inventory across four examples plus a match-pattern fixture, and covers per-field tamper rejection, budget exhaustion, drift binding, and CLI exit codes. This tranche implements no region inference, adds no region annotation syntax, introduces no arena runtime behavior, changes no destructor behavior, executes nothing, and changes no source. -
Added the locally evidenced Deterministic Scoped Task Model v1, a hidden target-neutral proof-data tranche (
src/scoped_tasks.rs) in the exactnative_settlementstyle that moves the completion-matrix row "Structured concurrency" from Missing to Partial. The model fixes, as executable evidence only: a bounded task DAG (4,096 tasks / 4,096 scopes / 65,536 edges / 1,000,000 work units) inside one strict scope tree where every non-root scope requires exactly one parent join and cross-branch dependencies are rejected at construction as escaping references; deterministic sequential scheduling in canonical stable-id order; sticky cancellation propagation in which cancelling a scope marks all descendants and materializes their cancellation before any sibling starts new work while already-started work drains to its scripted outcome; children-finalize-before-parents scope exit in exact reverse completion order; sticky first-failure selection with independent siblings draining and dependents of failed prerequisites abandoned; closed per-taskSendable/Shareableannotations recorded as declared intent only; and canonical JSON model/trace projections under two separately domain-separated SHA-256 fingerprints.tests/scoped_tasks_model_v1.rsplus seven focused module units pin four known-answer trace digests for join-all, mid-scope cancellation, failure drain with an abandoned dependent, and nested scopes; prove exact event sequences, cancel-during-drain, failure-beats-cancellation stickiness, hostile construction rejections (escape/double/orphan joins, cycles, duplicates, zero physical codes, bounds/work budget), hostile run operations, full input-permutation determinism, a byte-pinned trace projection, and JSON validity. It adds no language syntax, no parser/HIR/Graph/verifier/backend or CLI change, no runtime threads or scheduler integration, no real concurrent execution (task bodies are closed scripted outcomes), noSendablechecking of real programs, and no actors/reducers/synchronization claim. -
Added the locally evidenced Deterministic ARC Zone Model v1, a hidden target-neutral proof model that moves the completion-matrix row "Shared immutable ARC and opt-in managed zones" from Missing to Partial by fixing bounded proof data only — no runtime RC integration, no language syntax, no compiler or backend change, and no real allocation behavior. The new
arc_zoneslibrary module models shared-immutable reference counting inside explicit opt-in managed zones: a strict zone containment tree with balanced, parent-first enter/exit; accounted retain/release over base-reference, explicit-handle, and live-payload-link strong counts with fail-closed double releases that keep link-anchored objects alive; exact deterministic finalization order — reverse construction at zone exit, cascading through outgoing payload links in canonical target order depth-first; closed cycle-participation deferral under which retained cycles (strongly connected components plus self-loops) reject the zone exit with one canonical smallest-member witness diagnostic instead of leaking silently; escape demotion as a deterministic rewrite rule turning a proven zone-local shared handle (sole unreleased base reference, zero incoming links) into unique ownership whose later shared use fails closed; and closed concurrency annotations under which every zone declares its single executing thread and cross-zone or cross-thread sharing requires an explicitShareablemark on the shared object. Zones, objects, scripts, events, and traces are bounded (semaprax.arc-zones-model.v1,semaprax.arc-zones-trace.v1) with canonically ordered inventories, domain-separated SHA-256 model fingerprints and trace digests, byte-pinned canonical JSON, and sticky run rejection.tests/arc_zones_model_v1.rspins four canonical known-answer trace digests (shared fan-out release with canonical cascade order, cycle rejection with smallest-member witness, escape demotion, nested-zone children-before-parents drains), hostile rejections (foreign-zone handle release, unbalanced zone exit, double release beyond outstanding references, sharing withoutShareable, demoted-object shared reuse), structural construction hostility, determinism under inventory permutation and repeated execution, and JSON-validity plus domain-separation projections; seven focused module units cover the remaining state machine and error surface. -
Added the locally evidenced Portable SIMD Eligibility Report v1 tranche, the first executable slice of the completion-matrix row "SIMD and GPU". The new read-only
semaprax simd-report <file.spx> [--max-bytes N]command andsimd_reportlibrary API emit one deterministic canonical digest-authenticated JSON envelope (semaprax.simd-report.v1) per verified module: a static vectorization-eligibility analysis per admitted explicit-ID monomorphic effect-free scalar function, derived exclusively from the real resolved HIR nodes. Per function the report lists every maximal pure straight-line arithmetic sub-expression overi64/i32/u8/f32/f64(subtrees of+/-/*/unary-whose leaves are plain numeric literals or projection-free numeric places) with element type, operator and leaf counts, the closed portable lane-operation sequence in post-order evaluation order, a domain-separated per-region SHA-256 over the exact rendered root text, and the proposed portable lane width (2/4/8) selected by a documented deterministic largest-feasible-first rule under the fixed 128-bit lane model ceilingsi64/f64→2,i32/f32→4,u8→8; plus effect-freedom justification facts with exact call/assignment counts; plus an explicit closed ineligibility reason for EVERY non-covered expression —call,contract,division_remainder,bool_mixing,char_operation,mutation_target(assignment stores are recorded once and never descended),computed_operand,control_flow,aggregate_operation,scalar_leaf— and five closed function-admission exclusion reasons (automatic_identity,generic_function,declared_effects,unsupported_parameter_mode,non_scalar_signature; scalar signatures deliberately admiti32/u8/f32/f64/bool/charso their bodies are analyzed honestly).verify_envelopeindependently replays bytes, shapes, module counts, both closed vocabularies, the fixed lane model and portable operation table, strict stable-ID ordering, index continuity, per-region digests, lane-width feasibility, operator-count agreement, effect-freedom consistency, and fixed nonclaims. Diagnostics use the previously unusedSPX-V1xxfamily (optionsSPX-V101, fail-closed budget exhaustionSPX-V102, envelope/HIR consistencySPX-V103).tests/simd_report_v1.rsproves pinned golden KATs overexamples/calculator.spxandexamples/meaning.spx, byte-identical determinism, every function and expression reason exercised, lane-ceiling/tie-break coverage, tamper rejection per digest field including forged-but-re-signed envelopes caught by replay, source-drift binding, budget exhaustion, CLI exit codes, and cross-consistency proving reported region operators equal the real Add/Sub/Mul/Neg HIR nodes of the same program while division entries equal its real Div/Rem nodes. No SIMD codegen or intrinsics are emitted, no SPIR-V/WebGPU/GPU kernels exist, no autovectorization is claimed about any backend, no target is executed, and no source is changed. -
Added the locally evidenced Reference Interpreter v1 tranche, the first executable slice of the completion-matrix row "Fast development lane". The new
semaprax interpret <file> --function <name|stable-id> [--arg <i64|bool literal>]... [--max-bytes N]command andinterpreterlibrary API evaluate ONE explicitly selected explicit-ID monomorphic effect-free scalar function directly from verified HIR of one verified module — no backend toolchain, no code generation, no target execution — under a closed admission profile (explicit identity, monomorphic, effect-free, by-value directi64/boolboundary signature for the selected function and every reachable callee) covering the admitted scalar surface: Explicit Mutation v1let mut/assignment, blocks,if, lazy&&/||, strict left-to-right evaluation with sticky first-failure selection, checkedi64/i32/u8arithmetic reusing the compiler's exactruntime_statustable, total IEEE-754f32/f64, char/u8/i32 locals, requires/ensures contracts withresultbinding, and admitted calls including bounded recursion. The deterministic canonicalsemaprax.interpret.v1envelope reports the returned value or the exact normalized failure status plus fuel accounting (steps used versus budget; exhaustion is a fail-closed capacity outcome, never a language status), the fixed call-depth ceiling, argument echo, source digest, and fixed nonclaims;verify_envelopeindependently replays bytes, shapes, grammars, fuel invariants, closed vocabularies, and exact compiler-owned status reconstruction, andverify_envelope_against_sourcefails closed on drift. Diagnostics use the previously unusedSPX-F1xxfamily.tests/interpreter_v1.rsproves a 28-row corpus produces byte-identical result/status transcripts across the interpreter, native C11 O0/O2, and Node/Wasm (full scalar surface versus native; the whole-program web-profile subset versus all three), plus pinned golden/fuel KAT digests, determinism, every admission reason, argument diagnostics, per-field tamper rejection including re-signed forgeries, drift binding, and CLI exit codes. No JIT/AOT/Cranelift, incremental persistence, hot reload, debugger mapping, or target execution is claimed. -
Added Unsafe Boundary Mechanics v1, a bounded end-to-end language slice that moves the completion-matrix row "Restricted
unsafeand raw memory" from Missing to Partial by proving boundary mechanics ONLY: a new statement form@audit("<summary>") unsafe { .. }wraps ordinary safe checked statements plus one required final value expression - no raw pointers or memory operations exist in the language and none are added, and block contents are verified by exactly the same rules as safe code. Each unsafe block requires an audit summary attribute following the existing attribute syntax pattern, recorded verbatim, and the enclosing module must declare the capability through the unchanged module permit mechanism with the reserved nameunsafe(permit { unsafe }); without it compilation fails through the previously unusedSPX-N1xxdiagnostic family: missing capability declaration (SPX-N101), missing audit annotation (SPX-N102), empty or non-string audit summary (SPX-N103), non-scalar/non-Copy body results (SPX-N104, so discarding introduces no ownership or cleanup semantics), and boundaries inside contract expressions (SPX-N105). The canonical formatter renders multi-line and inline forms byte-stably; HIR carriesResolvedStatement::Unsafethrough both iterative and recursive resolution/validation paths without changing frame budgets; Graph JSON adds one explicit"kind":"unsafe"node per boundary carrying the verbatim audit string in full and compact serializers without touching schema selection (boundary-only programs stay at v10) or any pinned non-boundary bytes (the Explicit Mutation v1 digest still holds); CleanupPlan v2 output is structurally identical to the plain block-equivalent form; native C11 lowers the body transparently (scalar result discarded) verified at O0/O2 including checked-overflow failure statuses inside boundaries, and the Wasm core lane emits the body's instructions plusdropwith identical Node-executed results and overflow trapping. Evidence lives intests/unsafe_boundaries_v1.rs(13 tests). Non-claims: no raw pointers or memory operations, no lint/platform conformance coverage, no safety claims about block contents, and no capability machinery beyond the single compile-time gate. -
Added the locally evidenced Plugin Manifest Projection v1 tranche, the first executable slice of the completion-matrix row "Plugins". The new read-only
semaprax plugin-manifest <file> [--max-bytes N]command andplugin_manifestlibrary API project one verified module into one deterministic canonicalsemaprax.plugin-manifest.v1envelope describing a capability-limited plugin descriptor: a sorted provided-export inventory of explicit-ID monomorphic effect-free by-valuei64/boolfunctions, each with its persistent stable ID, interface parameter/result types, canonically rendered requires/ensures clauses, and the exact Native64 prototype line extracted verbatim from the production native C11 projection under a per-export domain-separated digest; every other function is recorded under one of six closed exclusion reasons mirroring Canonical ABI Report v1. Plugin identity fields follow the existing module metadata conventions — the module declaration name plus a build-hash-style version derived from the domain-separated stable source digest, because the language has no version metadata today. The required host capabilities section reuses the Build Capability Manifest v1 derivation and helpers over the same closed five-domain vocabulary (module permits plus declared function and interface-import effects; unconsumed interface permits stay checked-but-not-declared), failing closed withSPX-Q102on any out-of-vocabulary token. An explicit empty-by-default canonical resource-limits section, a closed five-entry unavailable-sections inventory, and fixed nonclaims state that the projection provides no Component Model runtime or packaging, no host loading or lifecycle management, no versioning negotiation, no resource-limit enforcement, and no hostile-plugin execution testing. Domain-separated SHA-256 digests authenticate the payload, source snapshot, identity, and every export signature;verify_envelopeindependently replays the exact bytes, counts, all closed sections, exclusion vocabulary, strict stable-id ordering, capability vocabulary, identity/version consistency, and every signature digest, so forged-but-re-signed mutations still fail closed. Options (SPX-Q101), out-of-vocabulary (SPX-Q102), budget (SPX-Q103), and consistency (SPX-Q104) diagnostics come from the previously unusedSPX-Q1xxfamily (renamed from a transientSPX-N1xxchoice that Unsafe Boundary Mechanics v1 already claimed).tests/plugin_manifest_v1.rspins golden envelope KATs over two examples, determinism, every exclusion reason, independent digest recomputation, per-field tamper rejection including re-signed forgeries, budget exhaustion, source-drift fail-closed behavior through both embedded digests, CLI exit codes, and cross-consistency provingrequired_capabilitiesequals whatsemaprax capability-manifestderives for the same program and that listed exports carry byte-equal native symbols/signatures to whatsemaprax abi-reportadmits. The Plugins row moves from Missing to Partial. -
Added the locally evidenced Interface Package Report v1 tranche, the first executable slice of the completion-matrix row "Interface-first packages and target matrices". The new read-only
semaprax package-report <file> [--max-bytes N]command andpackage_reportlibrary API project one verified module into one deterministic canonicalsemaprax.package-report.v1envelope: an interface-first package descriptor whose sorted admitted export inventory lists every explicit-ID monomorphic effect-free by-valuei64/boolfunction with its interface parameter/result types, canonically rendered requires/ensures clauses, declared effects, persistent stable ID, and the exact Native64 prototype line extracted verbatim from the production native C11 projection under a per-export domain-separated digest; every other function is recorded under one of six closed exclusion reasons mirroring Canonical ABI Report v1. A fixed target availability matrix marks exactlynative64andwasm32available for this profile, and an explicit closed ten-entry unavailable-capability inventory plus fixed nonclaims state that the report provides no resolver, lockfile, dependency model, package registry, version-compatibility engine, conformance tests, provenance, signatures, licenses, or SBOM. Domain-separated SHA-256 digests authenticate the payload and source snapshot;verify_envelopeindependently replays the exact bytes, package counts, both closed sections, exclusion vocabulary, strict stable-id ordering, and every export-signature digest, so forged-but-re-signed mutations still fail closed. Admission-profile, options (SPX-P301), budget (SPX-P302), and consistency (SPX-P303) diagnostics come from the previously unusedSPX-P3xxfamily.tests/package_report_v1.rspins golden envelope KATs over two examples, determinism, every exclusion reason, independent digest recomputation, per-field tamper rejection including re-signed forgeries, budget exhaustion, source-drift fail-closed behavior, CLI exit codes, and cross-consistency proving the listed exports equal whatsemaprax abi-reportadmits (with byte-equal native prototypes) and whatsemaprax openapipublishes for the same program. The Interface-first packages and target matrices row moves from Missing to Partial. -
Added the locally evidenced UI Dialect Schema Projection v1 tranche, the first executable slice of the completion-matrix row "First-class application/state/UI dialect". The new read-only
semaprax ui-schema <file> [--max-bytes N]command andui_schemalibrary API project one verified module into a deterministic canonicalsemaprax.ui-dialect-schema.v1envelope describing its typed application schema: every public non-generic scalar-field record becomes one state-shape descriptor whose field names,i64/booltypes, and offsets/sizes/alignments come exclusively from the checked Native64 compiler layouts, and every explicit-ID monomorphic by-value effect-free scalar function becomes one typed action descriptor with its parameter/result types under the exact Canonical ABI Report v1 admission profile. Records outside the profile are excluded with the closed reasonsautomatic_identity,generic_type,resource_type,variant_type, ormixed_field_types, and functions reuse the six shared abi-report reasons; an explicit empty-by-default controls/accessibility/ navigation section is always present as a reserved nonclaim field. Domain-separated SHA-256 digests authenticate the payload, source snapshot, every state-shape layout, and every action signature;verify_envelopereplays all of them independently by rebuilding the canonical bytes from parsed values, so even consistently re-minted forgeries fail closed (SPX-U101-SPX-U103). Pinned golden envelope KATs over three examples, checked-layout cross-consistency including the Point record's exact offsets and padded 24/8 shape, action cross-consistency against abi-report signatures for the same program, determinism double runs, every exclusion reason, budget exhaustion, per-digest-field tamper rejection, and CLI exit codes are green locally intests/ui_schema_v1.rs. The projection claims no rendering, runtime, DOM, typed update/view language constructs, semantic controls, accessibility, navigation, localization, assets, platform blocks, custom rendering, or target execution. The First-class application/state/UI dialect row moves from Missing to Partial. -
Added the locally evidenced Freestanding Object Profile v1 tranche, the first executable slice of the completion-matrix row "Embedded and real-time". The new read-only
semaprax freestanding-object <file> [--max-bytes N]command andfreestanding_objectlibrary API admit one verified effect-free scalar module (whole-module scalar gate, fail-closed) and emit one deterministic canonicalsemaprax.freestanding.v1envelope containing the complete freestanding C11 translation unit whose bytes start from the production native C11 projection with the host entry wrapper,<stdio.h>/<stdlib.h>includes, andspx_public_failurereporter excluded, plus two recorded substitutions: a closed failstop replacement for the hosted stderr/abort invariant reporter and external linkage for each module function so the relocatable object exports callable symbols. Four profile assertions — no-runtime, no-allocation, no-blocking, and no-libc-dependency — are computed by explicit deterministic textual checks, re-checked during independent envelope replay, and backed by a real toolchain gate intests/freestanding_object_v1.rs: the emitted bytes are compiled twice with-ffreestanding -nostdlib -cinto byte-identical relocatable objects whosenmsurface must stay inside the declared allowed set (memcpy,strcmp, each with documented justification) while every module symbol remains externally defined; compiler discovery follows the existing native lanes and skips with an explicit message when no toolchain exists. Domain-separated SHA-256 digests authenticate the payload, source snapshot, and embedded unit; pinned golden KATs cover the envelope and translation-unit bytes, per-digest-field tamper rejection including forged-but-re-signed payloads caught by assertion replay, determinism, budget exhaustion, every admission rejection reason, and CLI exit codes. Option (SPX-A101), module-admission (SPX-A102), budget (SPX-A103), and consistency (SPX-A104) diagnostics fail closed from the previously unusedSPX-A1xxfamily. The tranche claims no MMIO/volatile/atomics support, no linker-script control, no hardware/emulator execution, no interrupt or RTOS model, and no board targets; the artifact is a relocatable object for one effect-free scalar profile only, the command invokes no toolchain, and no completion beyond this bounded Partial slice is claimed. The Embedded and real-time row moves from Missing to Partial. -
Added Explicit Mutation v1, a bounded end-to-end language slice that moves the completion-matrix row "Immutable-by-default values and explicit mutation" from Missing to Partial. Local bindings may declare
let mut, and simple locals admit a new statement-only assignment form<binding> = <expr>;over checked Copy scalar values (i64,i32,u8,char,f32,f64,bool) with exact type matching: the assigned value evaluates fully — checked arithmetic failure statuses propagate exactly as from an initializer — before one atomic store into the binding's existing value identity, so no new value id exists and evaluation stays left-to-right. Immutable by default is enforced everywhere else through the previously unusedSPX-U1xxdiagnostic family: assignment to an immutable binding (SPX-U101), exact type mismatch (SPX-U102),mutoutside localletbindings such as parameters (SPX-U103), duplicatemutmodifiers (SPX-U104), non-scalar/non-Copy targets or values (SPX-U105), and assignments inside contract expressions (SPX-U106); unknown targets keep the established unknown-value diagnostics. The grammar admits no assignment expression and no compound operators, so(x = 2)and chainedx = y = zfail at parse time. The canonical formatter renders both forms with exact byte budgets and formats mutation-free programs byte-for-byte identically; HIR gainsResolvedStatement::Assigncarrying the reused target binding plus per-binding mutability in resolver/validator scopes with matching iterative and recursive oracle paths; Graph JSON adds"mutable":trueonly on mutable lets and an additive"kind":"assign"node without touching schema selection (v10-v14) or any pinned non-mutation graph bytes; cleanup lowering treats assignments as initializer-equivalent value steps so straight-line mutation produces structurally identical CleanupPlan v2 output (no slots, no finalizers); native C11 lowers to plain locals and plain C11 stores verified at O0/O2 including assigned-overflow failure statuses, and the Wasm core lane stores vialocal.setwith identical Node-executed results and i32 overflow trapping. Evidence lives intests/explicit_mutation_v1.rs(16 tests) andexamples/explicit_mutation.spxunder the example check/fmt gates. Non-claims: no field/aggregate mutation, no collection mutation, no reference/mutable-borrow semantics, no concurrency/memory-model rules, and no cross-task mutation. -
Added the locally evidenced Canonical ABI Report v1 tranche, the first executable slice of the completion-matrix row "Portable canonical ABI and native fast ABI". The new read-only
semaprax abi-report <file> --function ...command andabi_reportlibrary API emit one deterministic canonicalsemaprax.abi-report.v1envelope describing, per explicitly selected explicit-ID monomorphic by-valuei64/boolfunction, both the Native64 fast ABI — the exact prototype line extracted verbatim from the production native C11 projection, sizes and alignments taken from the checked compiler layouts (i648/8,bool1/1), by-value copy semantics, and the status/out-parameter contract — and the portable canonical mapping used by the Public Scalar Export Profile v1 Core-Wasm lane (Core-Wasmi64/i32signatures, injective raw export symbols, canonical bool boundary normalization identical to the emitted web-v4 adapters, and fixed copy-only behavior). Domain-separated SHA-256 digests authenticate the payload, source snapshot, every native prototype, and every rebuilt canonical object;verify_envelopereplays all of them independently. Admission mirrors C Header Emission v1 with the same six closed exclusion reasons; overflow (SPX-A203), selection (SPX-A202), option (SPX-A201), and envelope/backend consistency (SPX-A204) diagnostics fail closed from the previously unusedSPX-A2xxfamily. Pinned golden envelope KATs over two examples, byte-level cross-consistency against both real backend projections (native prototypes and wasmparser-decoded scalar-export module signatures), checked-layout agreement including the Native64/Wasm32 bool divergence, every exclusion reason, CLI exit codes, budget exhaustion, and per-digest-field tamper rejection are green locally intests/abi_report_v1.rs. The report claims no interface semantics beyond selected scalar exports, no borrowing (copy-only slice), no cross-language conformance suites, no target execution, and no hosted promotion. The Portable canonical ABI and native fast ABI row moves from Missing to Partial. -
Added the locally evidenced Build Capability Manifest v1 tranche, the first executable slice of the completion-matrix row "Sandboxed builds and dependencies". The new read-only
semaprax capability-manifest <file>command andcapability_manifestlibrary API project one verified module into a deterministic canonicalsemaprax.capability-manifest.v1envelope declaring its exact build capabilities: the sorted module permit inventory, every declared per-function effect set, every declared interface-import effect set, and an explicit empty-by-default ambient authority assertion over the closed five-domain vocabulary filesystem, home, network, process, and secrets. Every capability token anywhere in the module must sit inside that vocabulary or the command fails closed with the dedicatedSPX-K202; interface permits no import consumes are checked but do not by themselves mark a domain as declared. Envelopes bind source snapshot digest, graph revision, module accounting, and the ambient section behind domain-separated SHA-256 digests;verify_envelopeindependently replays shape, byte count, digest, vocabulary, and ambient derivation, andverify_envelope_against_sourcefails closed on source drift. Output-budget overflow (SPX-K203) and malformed options (SPX-K201) also fail closed without truncation. Pinned golden envelope KATs over the effect-free example (all five domains"none"), exact declared-effect inventories, determinism, undeclared-capability injection rejected through both digest authentication and a consistent re-mint replay, out-of-vocabulary forgery rejection, tamper rejection, drift detection, budget exhaustion, and CLI exit codes are green locally intests/capability_manifest_v1.rs. No sandbox is enforced at build time, no dependency resolution, lockfile, package registry, or network/home/secrets/filesystem/process enforcement machinery exists, and no target execution is claimed; enforcement against a declared manifest remains future work. The Sandboxed builds and dependencies row moves from Missing to Partial; current totals are 44 Partial/12 Missing. -
Added the locally evidenced C++ Shim Projection v1 tranche, the first executable slice of the completion-matrix row "C++". The new read-only
semaprax cxx-shim <file> --function ...command andcxx_shimlibrary API project explicitly selected explicit-ID monomorphic by-valuei64/boolfunctions of one verified module into a deterministic C++17-compatible header fragment: anextern "C"block whose declaration lines are extracted verbatim from the production native C11 projection, so shim declarations always match the emitted ABI and cannot be silently name- mangled; generated comments carry only typed stable-ID, canonical contract, effect, status-contract, and by-value ownership facts under a fail-closed hygiene guard (SPX-X104); include guards derive only from sorted admitted stable identities and stay byte-stable across formatting-only edits and display-name-only renames while changing on identity renames. Canonical compactsemaprax.cxx-shim.v1envelopes bind source snapshot digest, graph revision, selection/admission accounting, per-declaration digests, and the embedded fragment behind domain-separated SHA-256 digests with an independentverify_envelopereplay that separately rejects tampering of every digest field, including forged-but-re-signed envelopes only the inner fragment replay catches. The admission profile is exactly C Header Emission v1's closed exclusion-reason set; output-budget overflow fails closed without truncation (SPX-X103), unknown or duplicate selections are hard errors (SPX-X102), all-excluded selections still yield a valid emptyextern "C"block, and at least one admitted function requires the native lane to succeed. Pinned golden envelope/fragment KATs, native cross-consistency, byte-identical double runs, guard stability rules, and CLI exit codes are green locally intests/cxx_shim_projection_v1.rs; no C++ compiler runs, no hosted promotion exists, and no header import or parsing, C++ compilation or conformance claim, exception/lifetime policy beyond the bounded slice, string/buffer/aggregate/resource mapping, adapter generation, or execution claim is made. The C++ interoperability row moves from Missing to Partial (current totals 45 Partial/11 Missing). -
Moved the workspace minimum supported Rust from 1.85 to 1.88 so private crates can track current dependencies, and bumped the exact-pinned private
semaprax-native-loaderdependency fromlibloading 0.8.9to=0.9.0. The three dynamic settlement symbol lookups pass&[u8]slices because libloading 0.9 replaced its lookup bound withAsSymbolName. The manifest MSRV fields, the README badge and install floor, the mandatory CI minimum- version job (Rust 1.88 minimum), and the corresponding quality-gate text moved together. The two hostedReactiveCircus/android-emulator-runnerpins were also re-pinned to the currentv2.37.0tag commite89f39f1abbbd05b1113a29cf4db69e7540cae5aper the Dependabot GitHub Actions bump. The hosted Android Emulator, JNI/APK, iOS Simulator, and sanitizer jobs must re-green on this commit before any new physical-runtime claim is counted, and this adds no completion transition. -
Added the locally evidenced C Header Emission v1 tranche, the first executable slice of the completion-matrix row "C and Objective-C". The new read-only
semaprax c-header <file> --function ...command andc_headerlibrary API derive one deterministic C11 header for explicitly selected explicit-ID monomorphic by-valuei64/boolfunctions. Emitted declaration lines are extracted verbatim from the production native C11 projection, so header declarations always match the emitted ABI; generated comments carry only typed stable-ID, canonical contract, effect, status-contract, and by-value ownership facts under a fail-closed hygiene guard (SPX-D104); include guards derive only from sorted admitted stable identities and stay byte-stable across formatting-only edits and display-name-only renames while changing on identity renames. Canonical compactsemaprax.c-header.v1envelopes bind source snapshot digest, graph revision, selection/admission accounting, per-declaration digests, and the embedded header behind domain-separated SHA-256 digests with an independentverify_envelopereplay; output-budget overflow fails closed without truncation (SPX-D103), unknown or duplicate selections are hard errors (SPX-D102), all-excluded selections still yield a valid empty header, and at least one admitted function requires the native lane to succeed. Pinned golden envelope/header KATs, native cross-consistency, every exclusion reason, guard stability rules, tamper rejection, and CLI exit codes are green locally intests/c_header_emission_v1.rs; no C compiler runs, no hosted promotion exists yet, and no header import, raw binding import, safe wrapper, Objective-C mapping, string/buffer mapping, or execution claim is made. The C and Objective-C interoperability row moves from Missing to Partial; the shared completion-matrix dashboard totals lines stay untouched pending hosted promotion. -
Added the locally evidenced Typed Hygienic Generation v1 tranche. The new read-only
semaprax hygienic-gen <file>command andhygieniclibrary API synthesize default constructors and scalar field accessors for admitted non-generic scalar records as typed AST nodes whose tails are realConstructRecord/Projectexpressions, verify the combined program with the ordinary verifier, and project it through the real Graph module so every generated declaration has a resolved graph identity. Derived__gen_names are pure functions of the record's persistent stable ID (rename-with-same-id keeps them; movement changes nothing); collisions with existing symbols, prefix preemption (SPX-Y102/SPX-Y103), combined-program rejection (SPX-Y104), envelope floor exhaustion (SPX-Y105), and unresolved identities (SPX-Y106) all fail closed. Reports are canonical compactsemaprax.hygienic-gen.v1JSON with an authenticated outer digest, closed exclusion reasons, byte-budget prefix truncation with stable order, and fixed nonclaims. No textual rewriting, macro system, cross-file scope, persistence, or target execution is claimed. -
Reorganized the documentation around a published book without moving any document path. Added
book.tomlanddocs/SUMMARY.md(pinned mdBook 0.5.4), so the existing flatdocs/*.mdfiles render as one searchable site grouped into Foundations; Status and process; Agent interface; Semantic workspace; Targets and backends; and Platform adapters, with a newdocs/index.mdportal mapping every document to a one-line purpose plus role-based entry points. De-duplicated prose rather than deleting content: the repository module map now lives only indocs/ARCHITECTURE.md("Repository module map") withAGENTS.mdlinking to it and its conditional reads compressed into one topic table, and the README status section now points at the spec status headers that own the hosted-green evidence, which also fixes the garbled duplicated Agent Runtime sentence there. Added.github/workflows/docs.yml: it builds the book on every push and pull request with pinned mdBook and SHA-pinned official Pages actions, and deploys the HTML to GitHub Pages on main. This changes no language, protocol, backend, or completion-matrix claim;tests/documentation.rscontinues to require every local markdown link to resolve. -
Added the locally evidenced checked
i32scalar tranche:i32is now a Copy value type end-to-end. The change spans the lexer (explicit42i32suffix literals with stableSPX-P003range/suffix diagnostics; unsuffixed literals stayi64with no cross-width inference), parser, canonical formatter (the explicit suffix keeps the declared width round-trip stable), source verifier (+,-,*,/stayi32and are checked likei64;%stays restricted toi64via the existingSPX-T208), resolved HIR, Native64/Wasm32 aggregate and variant layouts (4/4 bytes), cleanup plans, Graph JSON ("kind":"int32"nodes carrying the exact value and"kind":"primitive","name":"i32"types), the strict native C11 backend (int32_trepresentation; arithmetic computes inint64_tand selects the sameSPX_STATUS_ARITHMETIC_*codes asi64, includingINT32_MINnegation and division overflow), and both Wasm core backends (i32valtype with signed ordering opcodes). The aggregate Wasm lane detects add/ sub/mul overflow branchlessly via sign bits or i64 widening and selects the aggregateSTATUS_*failure codes throughfail_if; the core lane lowers checked i32 arithmetic inline on widened operands without new host imports and traps on detected overflow because that lane has no status plumbing. Ordered comparison is signed scalar ordering; equality follows the existing same-type rule; mixed-width operands are rejected by the verifier (SPX-T208,SPX-T207). i32-bearing records, record update, projection, params, returns, locals, calls, branches, cleanup plans, conformance traces ({"kind":"int32","value":N}), and contracts execute identically through native C11 at-O0/-O2and Node/Wasm (tests/i32_scalars.rs,examples/integers_i32.spx; an overflow probe asserts a non-success status natively and a trap under Node rather than silent wrapping). Deliberately out of scope for this tranche: generic instantiation arguments and generic template signature slots remain directi64/boolonly, Public Scalar Export Profile v1 remains i64/bool-only, the native host callable corpus remains i64/bool/resource-only, the Native Rust interop boundary rejects i32 scalars, integer remainder staysi64-only, and no completion-matrix row status changes. -
Added the locally evidenced unsigned-byte
u8tranche:u8is now a checked-arithmetic Copy scalar end-to-end. The change spans the lexer (integer literals with an exactu8suffix; unsuffixed digit runs stayi64, and out-of-range or malformed suffixes select stableSPX-P003), parser, canonical formatter (the explicit suffix keeps the declared width stable across round trips), source verifier, resolved HIR, Native64/Wasm32 layouts (u8occupies one byte at Native64 and four bytes at Wasm32), cleanup plans, Graph JSON ("kind":"uint8"nodes with the exact value plus"layout_key":"scalar:u8"), conformance trace results ({"kind":"uint8","value":N}), the native C11 backend (uint8_trepresentation; checked arithmetic computes inint64_tand range-checks 0..=255 into the matchingSPX_STATUS_ARITHMETIC_*statuses), and both Wasm core backends (i32valtype with unsigned ordering opcodes; checked u8 arithmetic uses inline unsigned range checks without new host imports — aggregate-lane failures select the same status codes as i64 while legacy-lane failures trap).%stays i64-only and unary negation stays rejected for u8 (SPX-T208,SPX-T206). U8-bearing records, record update, projection, params, returns, locals, calls, branches, and contracts execute identically through native C11 at-O0/-O2and Node/Wasm over 4,096 re-entries (tests/u8_scalars.rs,examples/bytes_u8.spx). Deliberately out of scope: generic instantiation arguments and template signature slots remain directi64/boolonly, Public Scalar Export Profile v1 remains i64/bool-only, the native host callable corpus and the Rust-interop boundary reject u8 fail-closed, string/heap types remain unimplemented, and no completion-matrix row status changes. -
Added the locally evidenced Unicode scalar
chartranche:charis now a first-class Copy value type end-to-end. The change spans the lexer (single scalar char literals with\n,\r,\t,\0,\\,\', and\u{...}escapes plus stableSPX-P006/SPX-P007/SPX-P008diagnostics), parser, canonical formatter (printable ASCII projects directly, named escapes are preserved, every other scalar projects as a lowercase\u{...}escape so revisions round-trip exactly), source verifier, resolved HIR (SPX-H006fail-closed rejection of non-scalar literal payloads), Native64/Wasm32 aggregate and variant layouts (4/4 bytes), cleanup plans, Graph JSON ("kind":"char"nodes carrying the exact scalar value plus the canonical display form), the strict native C11 backend (uint32_trepresentation with unsigned comparison semantics), and both Wasm core backends (i32valtype with unsigned ordering opcodes). Ordered comparison (<,<=,>,>=) compares Unicode scalar values; equality follows the existing same-type rule; char arithmetic and negation remain rejected by the verifier (SPX-T208,SPX-T206). Char-bearing records, record update, projection, params, returns, locals, calls, branches, and contracts execute identically through native C11 at-O0/-O2and Node/Wasm over 4,096 re-entries (tests/character_scalars.rs,examples/chars.spx). Deliberately out of scope for this tranche: generic instantiation arguments and generic template signature slots remain directi64/boolonly, Public Scalar Export Profile v1 remains i64/bool-only, the native host callable corpus remains i64/bool/resource-only, string/ heap types remain unimplemented (no allocation model exists yet), and no completion-matrix row changes; totals remain 39 Partial/17 Missing. -
Added the locally evidenced OpenAPI Schema Generation v1 tranche. The new read-only
semaprax openapi <file> --function ...command andopenapilibrary API project admitted monomorphic scalar signatures of one verified module into a canonical OpenAPI 3.1 document wrapped in asemaprax.openapi.v1envelope with domain-separated source, document, and input-binding digests; per-operation request/result schemas preserve authored parameter order and the shared status component is emitted only when a signature can surface compiler-owned arithmetic or contract failure. The companionsemaprax openapi-compat <base.json> <candidate.json>command authenticates both envelopes exactly (schema, structure, payload digest, outer digest) before classifying their difference into closed breaking, non-breaking, and informational finding families with a deterministic verdict and migration note. Overflow of either output budget fails closed with no truncated bytes. New stable diagnostics: SPX-OA101 through SPX-OA105. Seedocs/OPENAPI-V1.mdfor the admission model, document shape, compatibility semantics, and explicit non-claims (no Protobuf/gRPC, GraphQL, or SQL projections, no schema import parsing, no live conformance fixtures, no registry/server hosting, no target execution). -
Added the locally evidenced Property-Test Generation v1 tranche. The new read-only
semaprax properties <file>command andpropertieslibrary API generate deterministic boundary-lattice plus seeded candidates from admitted monomorphic scalar signatures, filter them through authoredrequiresclauses, evaluate bodies and interprocedural admitted callees with checked arithmetic, lazy booleans, lexical bindings, and call-depth/step budgets, and report the first exactensurescounterexample (clause index, canonical text, full argument tuple, observed result) in canonical compactsemaprax.property-tests.v1JSON with fixed key order, domain-separated source digest binding, closed deferral/runtime/truncation reason sets, byte-budget prefix truncation, and fixed nonclaims. Unsupported shapes defer fail-closed with stable reasons instead of approximating. No target is executed, no symbolic or SMT discharge is claimed, and completion totals remain 39 Partial/17 Missing. -
Added the locally evidenced Graph Agent Transport v1:
semaprax serve <file>now runs a deterministic newline-delimited JSON-RPC 2.0 loop that binds exactly one checked program per session and answers a closedprotocol/graph/context/context_v2/ping/shutdownmethod set. Responses are canonical hand-rolled JSON;graph,context, andcontext_v2embed byte-identical payloads from the unchanged Graph and Agent Context serializers. The request grammar is closed (exact member set, unsigned-integer-or-bounded-string ids, object params only, batch arrays rejected), notifications never respond, oversized frames fail closed and stop the session, and the session gains no ambient read/write/process/network authority beyond its one host-named source. This is the first bounded slice of the roadmap "persistent graph daemon and JSON-RPC agent transport" item: persistent indexed revisions, incremental resolution, multi-source sessions, and network transports remain open, and no completion-matrix row changes; totals remain 39 Partial/17 Missing. -
Added the locally evidenced Public Project Native Publication v1 tranche.
semaprax build --target nativeover asemaprax.tomlproject now publishes the linked entry closure as one create-new executable through the unchanged shared Clang C11 lane and exactly the linked entry HIR that Web publication and internal lowering-equivalence evidence consume. Publication rechecks every held manifest/source input before and after the boundary, rejects an existing destination withSPX-I307, reports post-publication drift asSPX-J103while preserving the retained executable, keeps Web-package bytes and all single-file/Workspace/Patch evidence unchanged, and preserves published behavior across stable-ID display renames. Projectrun, a public project test command, hostile-window no-clobber native publication, cross-build executable byte determinism, and exact-head hosted promotion of the new lane remain held; completion totals remain 39 Partial/17 Missing. -
Added the locally evidenced IEEE-754 floating-point scalar tranche:
f32andf64are now first-class Copy value types end-to-end. The change spans the lexer (decimal float literals with an optionalf32suffix and deterministicSPX-P003diagnostics), parser, canonical formatter (shortest round-trip decimals; whole values keep.0; f32 keeps its explicit suffix so revisions are stable), source verifier, resolved HIR (exact bit-pattern literals, finite-value validation,SPX-H006fail-closed rejection of NaN/infinity before any backend), Native64/Wasm32 aggregate and variant layouts, cleanup plans, Graph JSON ("kind":"float32"/"float64"nodes with bit-exact hex payloads), the strict native C11 backend, and the Wasm core backends. Float arithmetic (+,-,*,/) is total IEEE-754: overflow, signed zero, and division by zero never select a failure status, unlike checked i64 arithmetic. Comparisons and equality producebool; unary negation is total;%on floats is a stableSPX-T208diagnostic. Float-bearing records, nested records, record update, projection, params, returns, locals, calls, branches, and contracts execute identically through native C11 at-O0/-O2and Node/Wasm over 4,096 re-entries (tests/floating_point_scalars.rs,examples/floats.spx). Deliberately out of scope for this tranche: generic instantiation arguments and generic template signature slots remain directi64/boolonly, Public Scalar Export Profile v1 remains i64/bool-only (SPX-W115), the native host callable corpus remains i64/bool/resource-only, string/heap types remain unimplemented (no allocation model exists yet), and no completion-matrix row changes; totals remain 39 Partial/17 Missing. -
Added the locally evidenced Public Native Rust SDK v1 Phase C. The still-unpublished builder now exposes a bounded API that invokes unchanged private A+B and publishes an exact dependency-free nine-file Cargo package with stable-ID-derived scalar export/import methods, a safe public facade, the existing private unsafe FFI quarantine, a canonical
semaprax.native-rust-sdk.v1manifest, and deterministic current-host static archive metadata. Archive creation uses one explicit held absolute tool, an 8 MiB pre-digest cap, a private nonce stage, closed platform member/header grammar, one byte-identical object, and create-new outer publication. The calculator and callback consumers compile and run locked/offline without a compiler dependency after generation. Aggregate/resource/string/pointer ABI, async/cross-thread use, registry/CLI publication, independent linker-index semantic reconstruction, Phase-C cumulative allocation proof, and exact-head hosted promotion remain held. Existing private A+B bytes and claims are unchanged; completion totals remain 39 Partial/17 Missing. -
Upgraded the pinned cryptographic and Wasm validation stack to
hmac 0.13.0,sha2 0.11.0, andwasmparser 0.256.0across the root workspace and isolated Component runner. SHA-256 rendering remains byte-exact and allocation-bounded; Target Evidence now reports the actual validator version, with regenerated v1/v2/v3 Target Evidence and Patch Evidence v2 known answers. No completion status changes. -
Added Project Manifest v1, a locally evidenced bounded multi-file pure-scalar build input. Its exact canonical
semaprax.tomlnames 2–16 source files, one entry, one test module, and 1–32 stable Web exports. One invocation holds the exact manifest/source inputs, reuses Semantic Workspace Phase-A once in memory without creating a managed workspace, and links real stable-ID provider bodies into entry/test HIR closures consumed by internal native equivalence evidence and Web lowering. The public Project CLI publishes only the Web package, with the separate digest-boundsemaprax.web-project.v1manifest. Types, interface declarations plus interface/native imports,use typeedges, permits/effects, generics, dependencies, registries, discovery, and capabilities are excluded; explicit stable-IDuse functionprovider edges remain the sole cross-file composition mechanism. Public native executable publication and project run/test commands are held. A post-publication final input drift reportsSPX-J103: its complete digest-bound package remains for caller reconciliation and is never deleted automatically. Its exact-head Ubuntu/macOS/Windows and Chromium/TypeScript matrix is green atd883ace579bfd86f723cdc6819224fde51f0677din run 32523952912. This makes no completion-matrix status change: totals remain 39 Partial/17 Missing. -
Reconciled Windows desktop packaging with serviced hosted-runner images by pinning the canonical Visual Studio 18 product line while retaining exact
vswhere, MSVC, linker, SDK, and import-library identity checks, including the hosted-observed servicedlink.exeidentity. -
Added Public Wasm Scalar Exports v1. Repeated
--export <stable-id>options select 1–32 explicit persistent monomorphici64/boolfunctions from a completely scalar, effect-free program. Under a caller-exclusive parent/new-tree publication contract, the path-based fresh no-clobber package rejects symlink/reparse parents and children, uses create-new for every fixed artifact, rebinds parent/output identities, and immediately replays its exact inventory/bytes before success. Cleanup reauthenticates both identities and removes only exact-byte expected files. It contains only stable-ID-derived Wasm adapters, a canonical digest-boundsemaprax.web.v4manifest, a digest-authenticating runtime, frozen JavaScript bindings, TypeScript declarations, and a calculator consumer. The facade performs exact BigInt/Boolean conversion and returns the closed eight-case arithmetic and pre/post-contract status results. Aggregate/resource/generic/import/effect shapes reject without fallback, and ordinary no-export web-v3 output remains the legacy lane. Local executable evidence covers bounded admission, deterministic artifacts, Node consumption, mutation rejection, and stable-ID rename preservation. A locked Chromium loopback calculator job is wired but awaits exact-head hosted-green evidence; exact TypeScript 5.8.3 compilation of the real generated declaration consumer is locally green and wired into that job. Components, npm publication, imports/capabilities, aggregates/resources, callbacks/async, multi-engine conformance, provenance, and production readiness. The JavaScript and TypeScript completion row moves from Missing to Partial; current totals are 39 Partial/17 Missing. -
Private Native Rust Interoperability v1 A+B design and implementation are exact-head hosted green at
50b96dccabe3b3dcbcdf38bab380f3eb8699184cin run 32402944574. The additiveimport rust fnscalar profile resolves an explicitly configured absolute Rust launcher only to discover one bounded sysroot, independently holds the direct compiler at that sysroot, requires a fixed-point sysroot check, and admits Rust artifacts only from that held direct image. Phase B uses one pre-effect 12-use process arena whose Windows attribute storage is queried, bounded, reserved, and materialized exactly, prepared filesystem inventories/names, one fixed-capacity no-growth store for the four authenticatedrustc -vVfields, allocation-free final comparison/publication, and fail-stop process/handle settlement. Private A now has named pre-HIR and post-HIR retained/scratch envelopes, iterative renderer/replayer traversal, exact persistent allocation transfers, and minimum-minus-one entry gates; prepared Phase-B target arguments admit current-host underscore components without opening other punctuation, and the Linux link plan freezes the target's native-static library tail. Windows now freezes a verified absolute MSVC linker into exact-fuse-ldarguments while keeping ambientPATHout of the isolated child environment. Local builder 100/100, platform-system 24/24, platform 10/10, source-contract 6/6, strict-Clippy, formatting, and security gates are green; Windows directory authority now excludes mutable directory length while retaining full file identity and reparse rejection. The run is green across Ubuntu, macOS, Windows, Rust 1.85, the Linux sanitizer lane, and Windows runtime/capacity settlement. This promotes only private A+B evidence. Public C remains held because the builder/types remain crate-private, all three crates remain unpublished, and the root package has no Native Rust Interoperability API or CLI. Compiler sysroot/dynamic-library descendant provenance, callable v2/v3, loader/host,SPX-B104, and existing wires/KATs are unchanged. -
Added Bounded Native Agent Runtime v1 A+B proof and the additive C1 injected- host Rust API: canonical Profile/Task/Action/Trace/Evidence, deterministic routing, injected fake-host streaming, registered read-only typed tools, capability/effect checks, cooperative cancellation, cumulative budgets, and independent replay. C1 exposes opaque Agent/run/sink types and no CLI, provider transport, ambient authority, language or backend semantics, durable memory, wallet, payment, or signing surface. Public Agent Runtime v1 is hosted GREEN at 8cf29aff8d1be3ccf74c36bc8c837f0c666ca067 (run 31591039261, 12/12 jobs, private and public deterministic fake-host gates on Ubuntu, macOS, and Windows). Private Economic Agent v1 A+B is exact-head hosted green at fe75c38d898b71e3ed5c57411fb46d0dbd4fc34b in run 31611748969, including both Economic gates on Ubuntu, macOS, and Windows. Public Economic Agent v1 C is exact-head hosted green at 03f1f2736de23d03b298f265f93409de89a6be95 in run 31616168124 (12/12 jobs), including the private, process-termination, and public Economic gates on Ubuntu, macOS, and Windows. Totals remain 38 Partial/18 Missing.
-
Added Semantic Workspace Operations v1, a bounded shared-lock read-only compiler for explicit stable-ID declaration and direct import-alias renames over existing managed paths. It consumes one retained base graph/AST-HIR sidecar, builds one candidate graph, and emits an exact existing Change-v1 replacements proposal plus canonical derivation wrapper. Digest KATs are
sha256:3c7bf340a5313907edcec41748063e8666793ee76b903bc4e691871a843544b5,sha256:5c7a67d42ef76b3a241c0dc98f3d8919a799d3745bb6ae54a1d0289a51ee3e86, andsha256:80df18fea48a663e25cca66e90c0842fa8146ed35ab2ee30f2659728509dd2b7. Added an outer canonical Operations Evidence wrapper, exact shared-lock verification receipt, and exclusive fresh-replay immutable publication route. Change-v1 bytes remain unchanged; a Change-v1 Evidence document alone binds only derived Change bytes, not Operations intent. The exactdfc04278c6ba9a7dd247d4cc4add3af91f55b936matrix is hosted green in run 31570834457; all 12 jobs passed, including the Operations process-termination gate on Ubuntu, macOS, and Windows. Totals remain 38 Partial/18 Missing. -
Added Semantic Workspace v1, Workspace Semantic Graph v1, Workspace Analysis v1, and Semantic Workspace Change v1. The additive initializer authenticates 2–16 existing sources and resolves explicit direct function/type imports in one managed generation. The public graph projects an entry-provider closure while its budget authenticates full managed-set work; Context, Impact, and Review add bounded read-only analysis over six typed edge families. Change C1/C2/C3 binds a 2–16-file replacements-only proposal to full-graph delta artifacts, exact verification and application receipts, and fresh replay-before-write under the exclusive lock. Candidate publication is no-clobber, two final checks precede the sole
ACTIVEpivot, and post-pivot uncertainty isSPX-I212. Receipts are not authorization tokens. Residue changes authenticated state, so old Evidence may failSPX-G187; regenerated Evidence may exact-reuse the candidate without a strategy claim. Change document KATs are Previewfbfba16e8c3a822b65e59b2a16e2f28393b6d9d9552bcc95fa1363e2599ff8fc, Context18a7990f5b3e1d6a7b06586930684f24787119b99c1e3981c83d92f46d2db117, Impact07c556a41f0ed1d6c25d48743f9550cb6a90eb6d1d8fe26c3ab274feac19284b, Review86ef97e76b6e4ae55d43995a3f537aa5f55b4326cf51a1cfe7fc4127d5054662, Evidence0c5393cb128adc8223a82b7181229cb2c18cb495d714949ccc2dfba07b4402b0, verification receipt564bdc6b50e475b68321787997aab2b4e96ad23397212e0efefe45b8895561c0, and application receipt2aeb79acfa7420fd57f82d8afa436658c265bf5c02808d13bd7b6acaa6957636. Local public C3 is 10/10 and private authority evidence is 11/11. Exact-head hosted Ubuntu/macOS/Windows, MSRV, Component, and dependency-policy evidence remains pending. Real process termination proves OS lock release and old/new managed state on tested filesystems only, not power-loss durability. No status changes: 38 Partial/18 Missing. -
Added Semantic Workspace Patch Evidence v1. The canonical outer capsule binds one exact Workspace Patch/preview and, for every sorted changed path, independently rebuilt source/Graph/Patch/Review/seven-assessment/ supporting-evidence facts plus a child Semantic Patch Evidence v1 digest.
verify-workspace-patch-evidenceemits an exact-replay receipt;workspace-apply-with-evidenceacquires the exclusive permanent lock first and requires exact typed and byte replay before candidate generation or staging, then enters the unchanged sealed Workspace publication core. The capsule and receipt grant no authority and aggregate neither Target Evidence nor Evidence v2. Raw capsule/receipt SHA-256 KAT pairs are v1d0f0ec9abde015cd84745d8d71b260736874b7cff8f172194d04e8ebe489c197/ee310a2f848dd034c20f727f011f30db46dfe478bbc1169467dec0d57c266ae1, v295b054e188a4721e03c08b94afe0963394fc0af16be42ef3bdec0990218eb9f6/da2440da67c87ec0ab873599c911fc78e816d02fcd12195532ce93817a15df0b, v33fc5dc57a01ce2a9d1110dfd66ec96e9def90b8bfd3e5d2328aa9d4a81da19e4/b05b0516508c7850b409b1b81dedfc51c708bfbe6e73c94db77a1aadce35f757, and mixed v1/v2/v3de764637af59c533feaba15dca373408cb50972f81afd3fde903f463550fde27/3538b97acc1626972b0242085c87059c51b64c2ba7412172bbc2c5118f2f63c1. Local public generation/verification is 6/6, apply 5/5, hostile 2/2, module units 8/8, shared Workspace core 39/39, Workspace integration 12/12, root library 496/496, and preservation 107/107; full local gates and security are green. The exactcda4892ee74100fd11c5161ad857d469ec5e5421corrective matrix is hosted green in run 31491573287, with all 12 jobs passing, including Dependency policy, Ubuntu, macOS, Windows, MSRV, and Component. The intermediate exact658b2f4dc6d69974cef553dbd4e6eaecafacdd63documentation/count head run 31490049153 was nonqualifying and cancelled: its macOS early-error precedence test observedSPX-I210instead of the expectedSPX-G150; Windows was concurrency-cancelled after that failure and reported no product failure. The exact3e41b3a0318730fec41e7d75438414e93dafa313predecessor run 31486578192 was nonqualifying at 10/12: its macOS test observedSPX-I210instead of the expected staleSPX-G152during snapshot-lock handoff, and its Windows lock-precedence fixture hit OS error 33 while reopening the lockedLOCKfile. The corrective head makes the owned-snapshot lock release explicit and avoids that fixture-only reopen; it changes no wire contract. This adds no completion transition: the dashboard remains 38 Partial/18 Missing, and unified cross-file semantics, repository analysis, target/test execution, provenance/approval, raw-tree materialization, recovery/GC, and durability remain open. -
Added Semantic Workspace Transaction v1 and ADR 0002. The opt-in protocol authenticates 2–16 canonical pre-existing sources, serializes cooperating readers and writers through one permanent lock, publishes a complete immutable candidate generation, and atomically pivots only
ACTIVE. It embeds unchanged admitted Patch v1/v2 and the sole canonical Patch v3 per file. Original source paths are never rewritten, so no raw-file, Git, editor, repository-Graph, cross-file semantic, recovery/GC, or power-loss durability claim follows. Exact initial-revision/snapshot/preview KATs aresha256:9a7368825342cee138d02a8037248e9a41ed0479d4f7c32a21c7ee7141cf280c,3646097c9fb8c47bced51cf2c404b886755f657c73c57afb18d25282574f0b80, anda4f1a9467d535aada97e7f253cf51c0d2168b5557a5a400d11692ac6966776b4; mixed-v1/v2/v3 snapshot/preview KATs aredfd35db518d0a8d94b83702dd1d2760ce9340b5875e0960ac573f84474c223b5and3cbd8d22bc26069387ac8ebce72ca590f095cbaa193b04bdef041e4c06beced1. Local integration 12/12, hostile 5/5, workspace units 37/37, library 482/482, full gates, preservation, and security are green. The exactafde3b3302e0f88fd8af3278efaf0ddd72e6dfe7matrix is hosted green in run 31472847068, including Ubuntu job 93719800613 and Windows job 93719800611; all 12 jobs passed. Earlier run 31471716036 on4daa407failed only Windows strict Clippy and is not green evidence. The completion matrix remains 38 Partial/18 Missing. -
Added Semantic Target Evidence v1 and Semantic Patch Evidence v2.
target-evidencereports exact base/candidate Graph JSON, typed zero capability delta, production C11 source, and structurally validated Wasm core digests/lengths without executing a target or discovering tests. Additive Evidence-v2 generation, verification, and lock-first A0 application bind that report while preserving Evidence v1 and ordinarypatch. Target is 9/9, target units 4/4, Evidence-v2 8/8, and library 439/439 locally. The exactfcdf3861d79faea27c526a8dc5105b92c6738213matrix is hosted green in run 31440359793, including Ubuntu job 93624123631; all 12 jobs passed. This changes none of the 38 Partial/18 Missing statuses, grants no authority, and does not implement or replace multi-file work. -
Added Semantic Patch Evidence v1. Fixed-arity
patch-evidenceandverify-patch-evidencecommands emit and independently replay exact bounded capsules for Patch v1/v2 and the sole canonical Patch v3 operation. The separatepatch-with-evidenceroute acquires the unchanged A0 lock first, requires exact replay before staging, then commits through unchanged A0; ordinarypatchremains unchanged. Exact capsule SHA-256 KATs are03befad24157620b56138e84d4495b1973d141275ee728493d5fbe4f0f6f09aa,23742f9b8a323003237106d7a800cc8fb98f53a68bd72f5e0961cf47c63f7bba, andd682e08b125451af3ed49dce03a0814e83ca5e665224fc3bc7ab7b314827f62c; receipt KATs are1f2733743aaf2f9d2b9ad6bf2709a6867f169f596be01a9d53e92daecb8730a1,6d8b13b3f54277e66a1ee501e1e71d6fe959a2ebcdbaa158a7ece20dde054e48, and13a99674a4c014d9f7f315d8108c3e5c870dcac2c5950ff3035ca1a1c155361b. A+B integration is 11/11 with 5/5 internal units; Phase C integration is 16/16 with 11/11 hook/limit units; library 420/420, doctest 37/37, full preservation, and security gates are locally green. The exact34a8ed82e9ae96277aa51e7994c19644331f5e78replacement matrix is hosted green in run 31431768632, including Ubuntu job 93596706949; all 12 jobs passed.e04c2c9was the failed Rust 1.97 lint predecessor, not green evidence. This moves only Proof-carrying patches from Missing to Partial: capsules are not signatures, authenticated provenance, approval, target/test execution, general proofs, reusable authorization, multi-file transactions, or new Graph/Cleanup/runtime semantics. -
Added Bounded Semantic Review v1, a fixed-arity read-only
review <file> <patch.spatch>command with canonicalsemaprax.semantic-review.v1JSON. Patch v1/v2 reports embed complete, nontruncated Semantic Impact v1 evidence under fixed limits; the sole canonical Patch v3assign-function-idreport instead embeds the exact shared Diagnostic Repair identity rebase and no Impact object. Every report carries the seven fixed sectionsbehavior,api_identity,security_authority,memory_ownership,target_artifact,migration, andunsafe, with one evidence-linked closed finding per authored operation. Exact Patch v1/v2/v3 whole-report SHA-256 KATs are054c12822e9984b3f9cab06056f311f35af3b06a438af7ade0b452a823443946,37fe056f519366fcaf6c13586e3b78afd64d51483490a1120e3e0fdc1b04c421, and081bcb20aca2e74f724f5bc0cd2cf03770a499e11aa090d92b59650209165544. Local Review integration is 10/10, hook/limit units are 4/4, and library 408/408, full workspace, release, doctest, rustdoc, strict Clippy, format, diff, preservation, and independent security gates are green. The exact2634011f3d205077d4533701e412bec8fdcff7c8full matrix is hosted green in run 31423743369 attempt 1, including Ubuntu job 93570423170; all 12 jobs passed. This is not Agent Context, target/test execution, a public verifier or proof artifact, authenticated patch provenance, human approval policy/UI, A0 apply/commit authority, repository/multi-file review, or general capability/security/unsafe/ABI analysis. Only the Semantic human review completion row moves from Missing to Partial. -
Added Bounded Diagnostic Repair v1 and Semantic Patch v3. Read-only
repairsdiscovery emits canonicalsemaprax.diagnostic-repair.v1JSON for one exactSPX-S103automatic-function target, and read-onlyrepairinstantiation emits canonicalsemaprax.diagnostic-repair-preview.v1JSON after independently proving the exact one-annotation HIR/normalized-Graph rebase. The operation is classifiedbreaking_identity_rebase. Its embeddedsemaprax.semantic-patch.v3is exactly one canonical LF-terminated three-lineassign-function-idoperation;patchrevalidates every selector, the closed scalar Graph-v10 repair domain, and the complete rebase before applying through unchanged A0. Impact v1 rejects every syntactically valid, canonical v3 asSPX-G110before semantic selector interpretation; malformed or noncanonical v3 remainsSPX-G101. Impact retains its v1/v2 bytes. Frozen query, preview, and independently authored candidate-Graph SHA-256 KATs areef689fed2c742dea6cedb0b8ec3d449e5facd8748dd00cb8a8f2e6115be82075,ae779749b252e5d9661172dfebcd3317211b97310eed57a0a6b7a692be1053e4, andd255c0e88ff497436ca0737ffd139cf47c2c142cf1b4f2da071514c0515ad2b3. Local Phase A integration is 13/13; the Phase B semantic integration corpus is 7/7; v3 A0 hook units are 4/4; aggregate v3 integration-plus-hook evidence is 9/9 (seven semantic cases plus two bounded-work integration hooks, not the separate 4/4 internal units); and the library suite is 404/404. Full preservation is green and security review is clean. The exactdae957afull matrix is hosted green in run 31418476217 attempt 1, including Ubuntu job 93553147265; all 12 jobs passed. Typed holes, other diagnostics and declaration kinds, repair ranking/composition/automatic application, other v3 operations, authenticated patch provenance, Graph or CleanupPlan schema/version/semantic-shape widening, Graph v11-v14 repair admission, backend/runtime semantic changes, and general or multi-file repair remain nonclaims. The admitted breaking operation does change Graph-v10 revision/identity/callee/derived-ID content and may rebase identity-bearing CleanupPlan content. Function and structural call-site bounds run on the parsed AST before HIR. After the patch parses as v3, its A0 initial source read and both final rechecks are capped at 16 MiB; initial oversize and concurrent greater-than- 16-MiB growth fail closed without replacing the source. V1/v2 reads are unchanged. -
Added
semaprax.semantic-impact.v1, a deterministic read-only preview for one Semantic Patch v1/v2 file. It reports exact operation/change provenance and source consumers, and computes a byte/node/depth-bounded reverse-call closure only for exact generic-call instance changes. Reports bind the source base/candidate revisions, Graph v10-v14 schema, patch schema, and a domain-separated digest of the exact processed patch bytes. Source identity/bytes/revision are rechecked before return; patch-path provenance remains trusted input. The canonical report SHA-256 KAT is94bbe5dcfe02f4b80b12ba5c8faf0889ddf11a96598072e539490c71a09518e9. Local focused integration and internal Impact/call-index suites are 12/12 and 4/4. This is single-file call impact, not repository-wide, non-call, repair, ranking, or commit authority. Impact itself emits no review sections; the separate Review v1 layer embeds its complete nontruncated report. The exact1b3731afull hosted matrix is green in run 31408654657 attempt 2, including Ubuntu job 93530141404. -
Added
semaprax.agent-context.v2as an explicit-direction extension of the byte/node-bounded context query. V1 remains the exact default when--directionis absent;forward,reverse, andbothselect deterministic breadth-first call traversal with global stable-ID ordering, minimum-depth direction provenance, and separate traversal and reference frontiers. Frozen SHA-256 KATs are forward922404133444942ab86607772362098e0f5656add6bea607a890be2bcfe5b7c9, reverse9a2ebfe569926e67f436379cf2b5c96d510daadd11d0a295ed54903cb612627b, and both4ec8a62a17551e87dc301d08f0a09c6159445757bca6dd9920a7db4e3790ce17. Local v2 and legacy-v1 gates are 8/8 and 8/8; the full hosted matrix is green in run 31397881268, including Ubuntu job 93485198327. V2 remains a call-graph query and does not claim general reverse semantic edges, impact analysis, ranking, repository indexing, persistence, or a graph daemon. -
Added bounded Semantic Patch v2 with an explicit schema line, atomic persistent record/case-member and variant-case renames, exact generic-call type-argument replacement, pattern-shorthand binding preservation, and a mandatory selective post-HIR semantic-delta gate. Schema-less v1 behavior is retained. Graph remains v14 and CleanupPlan selection is unchanged. The patch file itself remains trusted input; A0 authenticates source/staging, not concurrent patch-path replacement. The focused Patch v2 suite is 9/9, and the exact
f95d243full matrix is hosted green in run 31401200449 attempt 2, including Ubuntu job 93505622044. The isolated runtime lock repair is included in that exact green head; Patch v2 also remains covered by the green Wasmtime job 93505622110. -
Hardened single-file semantic patch commits against lost updates and leaf substitution. Patch application authenticates a canonical regular source leaf, serializes cooperating writers with a create-new sibling lock, uses bounded create-new staging candidates, preserves source permissions, syncs staged bytes, and rechecks exact source identity/bytes/revision plus staging path/handle identity/bytes at both final commit boundaries. Unix uses exact device/inode identity. Windows holds same-file handles and compares volume plus the available 64-bit file index; it does not claim identity uniqueness on ReFS 128-bit or other hostile non-unique-index environments. Identity- aware cleanup never removes a foreign replacement. Focused internal commit- race/failure/path-swap tests are 5/5 and integration patch tests are 17/17; the full matrix is hosted green in run 31396483313, including Windows job 93481068538. This remains a single-file cooperative protocol: predictable sibling names permit collision or stale-lock denial of service, crashes may leave locks, the containing directory remains trusted against non-cooperating mutation in the final portable path-based rename window, and parent-directory sync, power-loss durability, multi-file commits, and general typed repair/impact are not claimed.
-
Added default-off Private Source-Option Propagation Component v10 for WIT package
semaprax:private@0.8.0, interfaceoption-propagation, and worldsemaprax-private-v10. Its sole export maps the exact compiler-ownedOption<i64>through postfix?toOption<bool>asevaluate(input: option<s64>, divisor: s64) -> result<option<bool>, status>. Exact SHA-256 KATs are source revision98b8fc892c183499153142d5bbdb4162e31bda95ef145d34dbb1ff57c9b8fc72, Graph v1196083f90fab18c919a96cee48109e606e089159e109869a42bdf48831743d45d, prelude v1d37bad7e3911669bbf2c66b25c8b31d5c2e36eb181cc54fdc86c3a49a8fb9c5e,Option<i64>layout79194fc88011ac060877e60293d0a4272429dd9e2d720674d0d54e804562deda,Option<bool>layoutdec126293ece7ec0e48d3d85ccdb494f7c7cfe4c3d4a9b1a61b50f6f862ff038, CleanupPlan v3d07fa51fc6f192a43318140264fa0e5964933ed90bc065cc8c74708e258ff92f, generated core16d1d34024e3fad920d8d00a61d7cb3bd010335ca382f23615b3b3da4143aaec, profilef53a0c21638b5a360faa19ad4fdef68f6d861a5baffe39422847128686e82bef, raw componentf5770bdfdbc862ea39640b2c706c1d9ea171164c220d18366e25b3219443ad0d, and artifact DAG90ab80260c84abfe85d1edc666ab3750b81388e6e4cffd7ca21c301b9d0ee589. Typed and raw gates coverSome/None, contracts, checked arithmetic, sticky failure, status-first/tag-last publication, full poison, invalid input/output tags and booleans, unknown status, repeated and fresh instances, and out-of-band fuel exhaustion. Local core 5/5, component 4/4, CI-lock 4/4, full, hostile, and security gates are green; the zero-import pinned Rust 1.97.1/Wasmtime 47 v3-v10 runner is hosted green in run 31396483313, job 93481068502. V1-v9 bytes and KATs remain unchanged. This exact fixture does not establish general source selection/export, generalResult/Option/?or algebraic Component mapping, nested/resource/non-Copy carriers, imports/capabilities, callbacks/async, callable/FFI or public ABI, browser/multi-engine conformance, package negotiation, orSPX-B104/SPX-W111widening. -
Added bounded explicitly instantiated generic Copy functions. One or two owner/index-stable parameters may appear directly in by-value scalar signatures, concrete calls must supply ordered
i64/boolarguments, and templates remain effect-free and outside generic-to-generic call chains or recursion. Unused templates are verified over every direct-scalar substitution without being materialized; explicitly referenced instances receive exact domain-separated HIR identities, native symbols, and Wasm indices. Program-wide Graph v14 takes precedence over v13/v12/v11/v10 and serializes exact function-template, function-instance, and call-instance meaning. Corrected same-schema Graph v14 function-template serialization by adding the missing array delimiters aroundtype_parameters; two-parameter templates previously produced invalid JSON in module, Agent Context, and bounded-context projections. Its migrated frozen SHA-256 KATs are module7a61fa6229f2db7aca6a035fd961720e8a401c138cc66c9cd71c64d45bed5efd, Agent Context2841401e7ba85fa8e47b3c35a15ae401b4a271d2500d70bbf3627f1453869eb6, and bounded contextd7bda2be1fc366195ffb00a9e20b2b03204b4dd6f46e8019842dd84f70b54ab8. The corrected JSON parse regressions and KATs are locally green and hosted green in run 31390043736, Ubuntu job 93459346296. Separate strict C11 O0/O2 and 4,096-entry Node/Wasm execution evidence plus its independent security review are green locally and were hosted in run 31385406865, Ubuntu job 93445428338. CleanupPlan v2 remains byte/schema/meaning compatible and template-ID-only; HIR and Graph authenticate the exact instance before replay. Inference, constraints, aggregate/resource/non-Copy signatures, effects, generic entrypoints, callable/resource admission, general/public Component mapping, and stable public ABI remain closed; the exact private v9 profile below is separately gated. -
Added default-off Private Generic-Function Instance Component v9 for exact WIT package
semaprax:private@0.7.0, interfacegeneric-function-instances, and worldsemaprax-private-v9. The three phantom Copy templatespreserve<T>,invert<T>, andordered<T,U>materialize exactly six explicitly referenced Graph-v14 function instances in frozen export order, each with the same(marker: bool, control: s64) -> result<bool, status>WIT signature and no authored record or layout roots. Admission selects exactFunctionInstanceIds, one monomorphic materializer, andapp.main; it does not substitute declaration IDs or wrappers. Frozen SHA-256 KATs are source revision218085fb5ea1bcc090c04ac0acb3395912d0dad09027b9118d8817978b2fde0c, Graph v1462907c4b95495bb573b2b37de9f0b08c7a82218934154521e8c0c8396158cc6e, generated core9f178207a0406f740198ee8c71d5d008efdf4d995ff04e11e80ea73b79155d44, planedd11c98bbc902d9dbc9c942375477fcf1e6c3f1befbe3c4a9f260107104485e, profile365897ddb2770cc25a11690dddbfef5d232244ec5d328c79a24a1410e684615e, raw component3cf6c7d7d02e838fb374478a2b5b25077c7c612ad36e30deaffd15311a25a688, and artifact DAG2623ff9a7eda5526616a15befd4951de86874a59911dcba2a7d3bcc2d178a474. Local core 5/5, component 4/4, CI-lock 4/4, full gates, and independent security review are green, including rejection of all 15 same-signature swaps (eight behaviorally observable and seven identity-only). The isolated zero-import, empty-linker, no-WASI Rust 1.97.1/Wasmtime 47 typed runner is hosted green in run 31392541096, job 93467490492. V1-v8 bytes remain unchanged. This exact fixture opens no inference or constraints, general source selection/export, general generic-function Component mapping, aggregates/resources/non-Copy values, imports/capabilities, callbacks/async, callable/FFI or public ABI, browser/multi-engine conformance, package negotiation, orSPX-B104/SPX-W111gate. -
Added default-off Private Record-Pattern Projection Component v8 for exact WIT package
semaprax:private@0.6.0, interfacerecord-pattern-projections, worldsemaprax-private-v8, and four ordered monomorphic preserve/invert exports over the distinct same-layoutPhantom<i64>andPhantom<bool>instances. It binds exact source, generated core, two Wasm32 layouts, Graph v13, projection plan, profile, component, and artifact DAG. Primary KATs are source revisionsha256:2baac0c0920dbb153789767bf506a4a81713081586a81444d8e5f5a8f5a8516d, generated coreb6e1dbf9522dbb98df9b6fcd370b562a9a722fcc672d44488aed80f13b7ad39e, profile79d4bade38dd3fff9c7145b406bb0bb265ff3ef7cf084edac83384c84610bce2, component bytesd88590752ed7b08b0f0a32019ba8b4c5fc489d59f06b96986d7ad69e2554a10e, and artifact DAGe32fe0a15a3458f16aa4da59d87683013dbeba03754966f35e0cb63600e613a3. Local exact/upstream validation, all six identity-swap rejections, four behaviorally observable polarity swaps, generated-core Node behavior, poison/invalid-value closure, source locks, strict gates, and independent security review are green. The isolated pinned Rust 1.97.1/Wasmtime 47 typed runner is hosted green in run 31385406865, job 93445428268. V1-v7 bytes remain unchanged; v8 adds no generic-function component, general exporter, imports/capabilities/resources, public ABI, browser/multi-engine, package-negotiation, orSPX-B104/SPX-W111claim. -
Added bounded irrefutable Copy-record destructuring in
match. Exact named fields may recursively destructure records, bind scalar or whole Copy-record values with shorthand or renamed bindings, or ignore fields; one top-level wildcard remains binding-free. Source/HIR reject missing, duplicate, foreign, resource/non-Copy, multi-arm, and non-scalar-result forms. Explicit record patterns select program-wide Graph v13 above v12/v11/v10 when no generic function declaration selects v14, and serialize exact concrete instances, stable field IDs, and binding identities; wildcard-only record matches preserve the prior schema. CleanupPlan v2/v3 remains unchanged and straight-line. Native C11 O0/O2 and Node/Wasm 4,096-entry evidence covers one-evaluation, nested/generic and whole-record bindings, bool paths, failure precedence, postconditions, and poison. The Ubuntu gate is hosted green in run 31373317800, job 93406925130, and independent security review found no P0/P1. Refutable/literal/guard/or/rest/nested-variant patterns, non-Copy or resource matching, aggregate arm results, and public aggregate ABI admission remain closed. -
Added default-off Private Generic Record Component v7 for exact WIT package
semaprax:private@0.5.0, interfacegeneric-records, worldsemaprax-private-v7, and four exports overDuo<i64, bool>,Duo<bool, i64>,Phantom<i64>, andPhantom<bool>. The exact source, generated core, four concrete layouts, Graph-v12 and plan bindings, profile, component, ordered type arguments, and same-layout/distinct-instance Phantom mapping are authenticated. Local core/component hostility, upstream validation, Node core execution, default-consumer hiding, source locks, strict gates, and independent security review are green. The isolated pinned Rust 1.97.1/Wasmtime 47 typed runner is hosted green in run 31373317800, job 93406924922. V1-v6 bytes remain unchanged; this adds no general source selection/exporter, nested/resource/non-Copy records, imports/capabilities/callbacks/async, callable/FFI or public ABI, browser/ multi-engine conformance, package negotiation, orSPX-B104/SPX-W111widening. -
Added default-off Private Nested Record Component v6 for exact WIT package
semaprax:private@0.4.0, interfacenested-records, worldsemaprax-private-v6, and onetransformexport over fixed nestedinner/outerscalar records inside the unchanged physical-status result. Source, generated core, both Wasm32 layouts, profile, component, and complete DAG have frozen KATs; local exact-profile/upstream validation, hostile mutation/cross-version closure, core execution, default-consumer hiding, source locks, strict Clippy, and independent security review are green. The isolated pinned Rust 1.97.1/Wasmtime 47 typed runtime is hosted green in run 31365363898, job 93383304974. V1-v5 bytes stay unchanged; this adds no general/empty/generic/resource records, variants/algebraic nesting, imports/capabilities/async, public ABI, browser/multi-engine support, package negotiation, orSPX-B104/SPX-W111widening. -
Added bounded explicitly instantiated generic Copy records with one or more owner/index-stable parameters, direct scalar/own-parameter template fields, and direct
i64/boolconcrete arguments. Canonical source, source verification, resolved HIR, construction/projection/immutable update, concrete type facts, exact-instance Native64/Wasm32 layout caches and digests, native C symbols, and Wasm lowering now agree forBox<T>,Pair<T>, and orderedDuo<T, U>instances. Generic-record programs select program-wide Graph v12 above the existing v11 Option/v10 legacy lattice; legacy graph snapshots remain byte-identical. Strict C11 O0/O2 and Node/Wasm re-entry cover construction, update, pass/return, both bool arms, sticky failure order, and poisoned outputs and are hosted green in run 31365363898, Ubuntu job 93383304995. Generic-record inference and broader generic-function signatures, nested/resource/non-Copy arguments or fields, record patterns/matching, public aggregate/callable/FFI ABIs, and resource admission remain closed. -
Added default-off Private Scalar Algebraic Component v5 with six fixed WIT 0.3 exports for
Option<i64>,Option<bool>, and the complete direct-copyResult<T, E>matrix overi64/bool. Language carrier arms remain ordinary values nested inside the unchanged outer physical-status result. The exact capability-free source table/order, prelude layouts, stable-ID/core-index/WIT mapping, canonical memory, and source/core/profile/component DAG are authenticated without inferring identity from equal signatures or layouts. Core/component KATs, hostile mutation/reindexing/cross-version closure, upstream validation, invalid-value traps, default-consumer hiding, and the isolated pinned-Rust-1.97.1 typed Wasmtime matrix are hosted green in run 31360176398, job 93367728269. V1-v4 bytes remain unchanged; this adds no general exporter, resources/non-copy carriers, imports/capabilities, async, public API/ABI, callable/FFI mapping, orSPX-B104/SPX-W111widening. -
Added default-off Private Source-Result Component v4 for one exact effect-free source closure. It compiles ordinary compiler-owned
Result<i64, bool>plus postfix?intoResult<bool, bool>, then lifts the result as the distinct WIT 0.2 typeresult<result<bool, bool>, status>. SourceOk/Errremain the inner language result while recognized compiler status is the outer error; invalid internal tags and unknown statuses trap. The artifact binds the exact source revision, generated core, prelude, both layout-v2 digests, and v4 profile with independent parsing, upstream validation, canonical-byte mutation closure, and local generated-core Node execution. The isolated Wasmtime 47.0.3 runner and CI source locks cover ten typed outcomes, same/fresh-instance calls, zero imports, empty linker/no WASI, and out-of-band fuel failure. The v4 runner is hosted green in run 31356536123, job 93357169796. This does not alter v1-v3 artifacts, public component/aggregate ABI, resources, imports/capabilities, generalResult/Option/?, callable/FFI signatures, orSPX-B104. -
Added bounded postfix
?for ordinary compiler-owned direct-scalar CopyOption<T>intoOption<U>.Someextracts the exact source payload; payload-freeNonereconstructs the exact outer instance as a normal status-zero result, skips later body work, and still traverses shared postconditions before success-only publication. CleanupPlan v3 authenticates the Option source, members, and source/target instances; Graph v11 emitstry_option. Both schemas are feature-minimal: Result-only and propagation-free programs remain byte-compatible CleanupPlan v2/Graph v10, and agent context uses the program-wide graph schema even for a legacy root. Local strict C11 O0/O2 and Node/Wasm evidence coversi64tobool,booltoi64,Some,None, skipped failure, postcondition/physical-status separation, poison, invalid tags, and repeated Wasm entry. Hosted matrix evidence is pending. Nested/resource/non-copy arguments, residual conversion,?in contracts, public aggregate ABI, callable/component aggregate signatures, and public resource admission remain closed. -
Added bounded typed postfix
?for ordinary compiler-ownedResult<T, E>with directi64/boolarguments. Source and HIR authenticate the exact prelude members, source and outer instances, one operand evaluation, exactE, normal-resultErrstaging, and a shared postcondition/publication epilogue. CleanupPlan v2 makes body-versus-residual Copy-result staging explicit and independently replayable; Graph v10 exposes the same evaluation-once and shared-epilogue meaning. Native C11 O0/O2 and real Node/Wasm cover different source/outer layouts, later-expression skip, physical-status separation, postcondition failures, poison, invalid tags, and re-entry. The conformance-trace protocol remains closed to aggregate values. Resource/nested arguments, generic-function use of?, broader non-Copy generic records, non-copy propagation, residual conversion,?in contracts, public aggregate ABI, callable/component aggregate signatures, and public resource admission are unchanged nonclaims. -
Hosted run 31353051690 is fully green for the typed-
?tranche across Linux, macOS, Windows, MSRV, sanitizers, the isolated Wasmtime runner, and the private mobile/application jobs. The macOS provider export lock is bound to the Graph-v10-derived exact descriptor/execute/settle symbols and has a hostile source-lock regression. -
Hosted run 31347109201 supersedes the pending generic/prelude and component-runner notes below. It is fully green across the configured matrix; the isolated prelude-bound Wasmtime runner is green in job 93330959212.
-
Superseding the earlier configured/pending notes below, hosted run 31338834586 is green for Portable Result Component v3 (job 93309086213), the private macOS engine plus AppKit package/runtime (job 93309086230), the private Swift/iOS app plus XCFramework (job 93309086228), and the private Android JNI/Kotlin app (job 93309086206). A later full-matrix run 31343897595 is green, including the Windows engine and Win32 UI package/runtime (job 93322134480) and the bounded Copy Variants + Match v1 tests on Linux, macOS, and Windows.
-
Superseding the earlier non-generic/Graph-v8 boundary below, copy variants now admit explicitly instantiated nominal templates with direct
i64/boolarguments. Compiler-owned ordinaryOption<T>andResult<T, E>are the same versioned generic-variant mechanism, not backend intrinsics. Graph v9 authenticates owner/index-stable parameters, exact concrete arguments, andsemaprax.prelude.v1; graph revision v2 binds canonical source plus the prelude contract. Internal Native64/Wasm32 layout digest v2 and distinct concrete-instance symbols prevent instance confusion. Native C11 O0/O2 and real Node/Wasm execute the generic and prelude cases with deterministic layout, poison, invalid-tag, and repeated-call evidence. That earlier tranche did not include generic functions or records, nested/resource arguments, non-copy matching, stable public aggregate ABI, and callable/component aggregate admission remain closed. -
Added bounded executable copy variants and exhaustive
match: non-generic nominal unit/direct-i64/direct-boolcases, explicit construction, persistent case/payload identities, declaration-orderu32tags, checked Native64/Wasm32 internal layouts, stable diagnostics, CleanupPlan v1 variant-case replay, native C11 O0/O2 execution, and real Node/Wasm execution with selected-arm-only behavior, full poison, invalid-tag closure, and shadow-stack re-entry. Graph is nowsemaprax.graph.v8. Generic variants,Option,Result,?, resource-bearing payloads, non-copy ownership modes, stable public aggregate ABI, callable/component signatures, and public resource admission remain closed. The complete hosted matrix is green in run 31343897595. -
Graph v7 added canonical immutable record update across source, resolved HIR, Graph, and context traversal. Update meaning is base-first with replacement expressions in authored order; v6/v7 and v7/v8 schema confusion reject as documented in MIGRATIONS.md.
-
Added checked deterministic Native64/Wasm32 layouts for nested record fields in the admitted
i64/bool/direct-trivial-resource slice. Cleanup-plan construction and independent replay now cover partial initialization and immutable update, including untouched-field transfer and reverse exact-once cleanup of displaced live fields. Empty records are frozen to one byte with alignment one on both profiles. -
Added production-reachable native C11 O0/O2 and Node-executed browser Wasm lowering for nested scalar
i64/boolrecords, including construction, projection, immutable update, base-first/authored replacement order, status/out poison, internal aggregate pointer parameters, caller-owned results, and Wasm shadow-stack re-entry. A separate private test-only harness projects one direct-trivial-resource record scenario from the same cleanup plan into C and real Wasm, proving an exact common finalization trace and zero liveness. This does not establish a stable public aggregate ABI, public resource-record execution, callable/component aggregate signatures, or any change toSPX-B104/SPX-W111. -
Added deterministic offline agent context economics v1: four checked maintenance questions, exact context/economics goldens, UTF-8 byte and node counts, an explicitly non-model lexical unit, manifest/context digests, exact scored label IDs, reviewed relevance/evidence recall, mutation and hostile path/facet gates, plus exact-case/separator-normal/Windows-forbidden-and-reserved-safe paths and explicit-or-unique-target-merge-base plus dirty-Git fail-closed
quick/changed/fullquality routing with a profile-exact ordered executable gate plan. The small corpus honestly records context larger than source; Graphify adoption and model-token savings remain unclaimed. -
Added
semaprax.agent-context.v1: thecontextCLI now emits deterministic whole-JSON byte- and function-node-bounded facts, exact used/omitted/deferred accounting, closed truncation reasons, strict options, and query-bound stable-ID progress frontiers with non-dangling emitted calls and permanent oversize rejection. Compact Graph-v8 contracts, parameter/result ownership, effects, and reference-closed types are filterable; cleanup/lifecycle/import subgraphs are not claimed, and absent target/diagnostic/test graph facts are explicitly unavailable. This is not an exact model-token budget or repository-wide relevance/impact claim. -
Added the private native desktop application v1: a feature-gated headless macOS
APPLbundle and Windows portable PE application directory package one exact callable-v3 provider/descriptor with the existing loader and authenticated host. Local macOS execution proves two generation-rotating owned calls and exact replay. The Windows package/runtime path and hosted desktop executions remain configured and pending; UI, accessibility, lifecycle, installer/signing, public admission, andSPX-B104stay closed. -
Added private native desktop UI v1: exact AppKit and Win32 frontends compose the package-bound desktop engine with one visible native window/button, native accessibility-name query, delayed control event, event-loop close/termination, pre-launch SHA-256 engine-byte verification, bounded AppKit termination, exact Windows imports/no export directory, double-build artifact inspection, and closed packaging. Source locks and local AppKit compilation are green; hosted packaged macOS/Windows execution is configured and pending. This adds no SEMAPRAX UI syntax, SwiftUI/WinUI, general accessibility/lifecycle, distribution, public admission, or
SPX-B104claim. -
Added the private Apple Swift ownership adapter v1: a feature-gated same-thread Rust host, generation-tagged Swift wrapper, target-bound device/simulator providers, private XCFramework packager, and installed arm64-Simulator app gate. Local Rust/source-lock evidence and the bounded hosted Apple path are green in run 31333469714, job 93295293995. Public framework, device, UI/lifecycle, admission, and
SPX-B104claims stay closed. -
Added the private WIT boundary v1: deterministic
SPXWIT01WIT/schema/JavaScript bytes, a frozen digest, mutation rejection, exact status bounds, and Node adapter execution. A separate standards-valid scalar component binary now has a frozen digest, an independent exact-profile parser, hostile mutation coverage, default-surface closure, and private Node execution of its extracted core module. Checked component v2 additionally composes the exact SEMAPRAX-generated scalar core with a frozen checked runtime, exposes read-only artifact digests, passes pinned upstreamwasmparservalidation plus rehashed signature/body/cardinality/lift hostiles, and executes generated success, overflow, and contract failure through authenticated privateevaluate(). Portable Result Component v3 adds the exact privateresult<s64, status>lift, independent parser and upstream validation, poison/sticky-status evidence, and local typed Wasmtime execution of success, addition overflow, division by zero, precondition, and postcondition outcomes with zero imports, an empty linker, and no WASI. Its dependency/MSRV graph is isolated; hosted Wasmtime is configured and pending. Source-languageResult/Option, records/resources/imports/async, capabilities, multi-engine/browser conformance, public API, andSPX-B104remain closed. -
Added a mandatory private Android Emulator runtime gate. A hidden closed selector emits exact arm64 and x86_64-emulator dynamic descriptors and Bionic/ELF-guarded strict-C providers; the unpublished host now compiles for Android and connects the real dynamic loader to the unchanged receipt ledger. The pinned NDK/API-35 lane compiles both architectures and executes
token.discard-twoat O0/O2 in an x86_64 emulator with exact finalizers and zero measured Rust allocation across the irreversible interval. Run 31320436726, job 93262427248 is green. That standalone-process lane proves no JNI/Kotlin APK; public or general JNI, APK/AAR distribution, lifecycle/UI, device, general-corpus, public-admission, andSPX-B104claims remain closed. -
Added the separate private Android JNI ownership adapter v1 implementation and a dedicated hosted APK job. A feature-gated generator emits exact x86_64/arm64 provider and JNI shim sources; strict NDK compilation, exact
JNI_OnLoadexport/dependency inspection, and a plugin-free Gradle 9--offlinepackaging project produce one same-package, no-UI framework Instrumentation APK containing only the x86_64 JNI library and O0/O2 providers. The minSdk-28 Kotlin wrapper uses an owningHandlerThread, generation-taggedSPXAJH01handles, fixedSPXAJS01status words, and aPhantomReference/ReferenceQueuefallback.OwnedSession.consume()is the explicit evidence path;AutoCloseable.close()is non-throwing Cleaner-style dispatch. Tests invoke the identical registered cleanup action deterministically throughcleanForTest(), not by observing GC. Local Rust/C and source-lock evidence plus the exact API-35 x86_64 APK/Instrumentation path are green in run 31324497016, job 93272580149. This is no AAR, UI/lifecycle, device, arm64 runtime, general resource execution, public admission, orSPX-B104change. -
Added a mandatory private arm64 iOS Simulator runtime gate for one exact
token.discard-twocallable-v3 provider. The closed emitter produces the target-specific descriptor and strict-C provider; CI links it with the static-only loader/host, ad-hoc signs the standalone Mach-O, and requires exact O0/O2 finalizers, authenticated no-owned receipt/ledger transition, and zero measured Rust allocation across the irreversible interval. The first hosted Simulator job is green in run 31318280135, job 93257002836; device/app lifecycle, the remaining iOS corpus, Android, and public admission remain open. -
Added iOS-target cfg isolation plus a mandatory macOS CI cross-check for the unpublished static callable-v3 loader and receipt/ledger host across five distinct device, simulator, and Catalyst Rust targets. The gate requires zero resolved
libloading, dynamicopen_*, or desktop v1/v2 host surface there; linking, mobile runtime, Swift/XCFramework integration, and public admission remain open. -
Added resource declarations and explicit
own,borrow, andsharedboundaries. -
Added stable resource identities and atomic resource/type-boundary renames.
-
Added straight-line move analysis with use-after-move and illegal-transfer diagnostics.
-
Added lexical
letbindings, typedif/else, and conservative control-flow ownership joins. -
Distinguished definitely moved resources from resources moved on only some paths.
-
Exposed resource nodes and parameter ownership in the semantic graph.
-
Upgraded the graph to v2 with deterministic revision-scoped expression and binding nodes.
-
Added structured contract graphs and contract dependencies to bounded agent context.
-
Added a direct WebAssembly core backend and generated browser package.
-
Preserved checked
i64arithmetic through audited WebAssembly host imports. -
Added the authoritative full-goal completion matrix.
-
Verified the compiler, native executable, and WebAssembly package on macOS, Linux, and Windows CI runners.
-
Made native expression evaluation explicitly left-to-right instead of inheriting C's unspecified call-argument order.
-
Hardened public backends to reject unverified programs with diagnostics instead of panicking.
-
Added repository agent guidance, evidence rules, MSRV/package gates, and a documented Graphify adoption decision.
-
Added a fail-closed resolved HIR with persistent nominal/call identities, deterministic lexical place identities, and centralized type facts/layout keys.
-
Migrated native and Wasm semantic lowering to validated HIR and added malformed-HIR cross-backend rejection parity.
-
Upgraded the semantic graph to v3 backed by validated HIR, with resolved declaration/value/type identities, centralized type facts, explicit identity origin, fail-closed public APIs, and bounded-context frontier metadata.
-
Upgraded the semantic graph to v4 with persistent record and field nodes, resolved construction/projection references, recursive field-type context closure, and fail-closed graph integrity checks.
-
Replaced FNV revision tokens atomically across graphs, semantic patches, CLI output, and
semaprax.web.v2manifests with domain-separated SHA-256 content addresses. -
Split source verification behind a compatibility facade and additive HIR analysis API while freezing complete ordered diagnostic JSON behavior.
-
Added canonical record declarations, construction, projection, persistent field identities, deterministic field diagnostics, recursive facts/layout keys, and by-value recursion rejection.
-
Upgraded the semantic graph to v4 with record/field nodes and stable constructor/projection references; native and Wasm record builds fail closed pending aggregate cleanup and layout support.
-
Added prefix-aware ownership for resource-containing record fields, preserving disjoint siblings while rejecting definite and conditional partial-place reuse in both source verification and hostile-HIR replay.
-
Fixed canonical formatting of record constructors in contracts and
ifconditions so parse-format-parse remains valid. -
Hardened semantic resource renames so record initializer expressions cannot be mistaken for type annotations.
-
Published design-only RFC 0003 for exactly-once cleanup, logical resource imports, and a shared native/Wasm status-and-out ABI; executable cleanup remains gated on its conformance evidence.
-
Closed the pre-cleanup backend gap by rejecting bare resource modules with
SPX-B104/SPX-W111; record diagnostics retain precedence when both declaration kinds are present. -
Implemented RFC 0003 phase 1 with mandatory persistent trivial/imported resource lifecycles, declaration-only interface/import contracts, recursive lifecycle-effect authority checks, and hostile-HIR validation while retaining fail-closed resource execution.
-
Upgraded the semantic graph to v5 with resource-drop, interface, and logical-import nodes plus lifecycle-aware bounded context closure and exact snapshots.
-
Migrated legacy resource fixtures explicitly and extended atomic resource renames through import parameter types without rewriting lifecycle IDs or logical keys.
-
Added a mandatory, deterministic
CleanupInventoryto resolved functions, cataloging owned droppable storage and exact nested resource-leaf flags while independently rejecting hostile inventory mutations before backend gates. -
Corrected the proposed cleanup-plan schema to require atomic call commits, exact single-flag finalizer guards, explicit entry liveness, edge-based cleanup continuation, and sticky failure-status identities; executable cleanup remains unimplemented.
-
Implemented RFC 0003 phase 2 with a mandatory target-neutral cleanup CFG on every resolved function, covering all current HIR expressions, lexical exits, guarded reverse finalization, caller-owned argument epochs, atomic call commits, checked and contract failures, partial record construction, whole-value normalization, and scalar/owned result publication.
-
Added independent cleanup-plan reconstruction after core HIR and inventory validation, plus focused deterministic and hostile-HIR tests that preserve
SPX-H006precedence across native and Wasm consumers. -
Upgraded the semantic graph to v6 with complete tagged cleanup plans per selected function while retaining the canonical source revision algorithm.
-
Added public
semaprax.status.v1normalized-status types, exact compiler-owned contract/arithmetic mappings, and a bounded context-local immutable status arena; token zero remains success and no physical token is serialized. This is protocol/runtime groundwork, not a backend status ABI implementation. -
Added public
semaprax.conformance-trace.v1semantic event/result types and deterministic canonical JSON for ownership transitions, calls/imports, frame-local failure selection, infallible finalization, and result publication. -
Added independent attached-plan coverage and exhaustive current-CFG replay plus a scenario-driven single-frame reference executor with guarded cleanup, sticky normalized failure, exact trace emission, and explicit caller out-slot publication state. Recursive calls, callable imports, and native/Wasm instrumentation remain unimplemented, so no backend conformance is claimed.
-
Documented strict status/trace schema rejection, compatibility, cache-binding, event-order, and no-physical-data rules in Conformance trace v1.
-
Migrated native scalar calls to the RFC 0003 context/status/out convention: internal contract and checked-arithmetic failures now propagate exact normalized statuses without terminating a SEMAPRAX frame, nested calls retain the same token, and caller result storage is written only after successful postconditions.
-
Added an executable strict-Clang native ABI matrix covering scalar success, requires/ensures, all eight arithmetic status codes, left-to-right nested failure propagation, arena shape, and poisoned out-slot preservation while retaining the
SPX-B104resource gate. -
Fixed status-v1 domain identity at 1–255 UTF-8 bytes without NUL and enforced the same byte rule in public status construction, source/HIR validation, and native arena-owned domain storage.
-
Added gated native-resource ABI scaffolding with deterministic stable-ID-derived C wrapper and typed finalizer symbols; this does not enable resource execution.
-
Added a fail-closed first-slice cleanup-plan index for direct trivial resources and a checked max-path trace-capacity preflight. Records, imported lifecycles, projections, generics, and every nested call remain rejected behind
SPX-B104until their executable conformance evidence exists. -
Added an unreachable plan-driven native cleanup C scaffold with exact terminal liveness/status assertions, clear-before-trivial-finalization, owned-result publication checks, and a compiler-owned C binding namespace; executable resource lowering remains gated.
-
Added deterministic, strongly typed C wrappers for direct opaque resources and staged resource-aware native signatures while preserving the unconditional
SPX-B104execution gate. -
Extended the gated native cleanup scaffold to emit real root-frame
transfer,select_failure, trivial-finalization, andresult_commitevents from the classified function identity; strict C11 fixtures cover event order, hostile trigraph sequences, and exact UTF-8 identity bytes. -
Made every persistent semantic identity NUL-free at source and hostile-HIR boundaries, including type/expression/place references and attached cleanup inventory/plan metadata, so C and wire encodings cannot silently truncate or alias identities.
-
Added an exact test-only native cleanup conformance lane: a bounded versioned binary decoder and validated-HIR identity materializer compare typed traces and canonical JSON with the independent executor across zero/max opaque payloads, reverse finalization, contract/arithmetic failure, owned publication, failed owned postconditions, O0/O2, ASan, and UBSan. Production resource lowering remains gated.
-
Replaced injected native cleanup observations with a typed, cleanup-CFG-synchronized value planner that executes real Boolean contracts,
i64comparison, checked addition, scalar publication, and owned transfers inside the exact conformance lane. Added portablei64::MINC emission and independent resource-lifecycle/transfer-type coherence checks; the public resource host gate remains closed. -
Added the private host-ownership transaction v1 reference model: linked-runtime-unique non-clone registries, generation/provenance tokens, immutable function contracts, atomic multi-owner ingress, and must-complete typed execution scopes make rejection versus executed success/failure and owned-result publication executable without exposing raw pointers or weakening
SPX-B104. -
Split private native host contracts into deterministic authority-free templates and runtime binding. Resource preflight now derives and discards each template from its exact already-admitted cleanup/value evidence without replanning; complete ordered scalar/resource metadata, exact same-type owner results, lifecycle identity, module ABI and function-template fingerprints, mismatched-evidence rejection, binding-instance-distinct process-local authority, cross-ABI binding rejection, and internally observed thread affinity at binding and synchronous registry execution are unit-tested while public execution remains gated.
-
Corrected the native conformance probe to consume the value planner's exact owned-result parameter/owner ordinal instead of choosing the first same-typed input. The sanitizer-backed corpus now proves returning the second of two identical resource types with both distinct and identical opaque payloads, plus reverse cleanup and no result publication when its precondition fails.
-
Added a private descriptor-only physical native ABI stage derived solely from sealed admitted host templates. Its canonical pointer-free wire binds explicit schema, target, semantic/physical module, function, ordered scalar/resource/lifecycle, and exact result identities. A host-only provider compile-guards every encoded target property; strict separate C11/C++ translation units plus a real shared-library/export/dynamic-consumer test verify the deterministic getter as the sole export. Compiler preflight discards every staged artifact, exports no callable owner API, creates no runtime authority, and leaves the exact public
SPX-B104gate unchanged. -
Initially added the private native capability-token codec as a disconnected exact 64-byte canonical envelope with a full RustCrypto HMAC-SHA256 tag. Pinned audited crypto, a published RFC 4231 vector, independently reproduced owner/result full-token goldens, every-bit/arbitrary-byte/length/structure hostility, exact function-template result scoping, function-independent owner scoping, cross-context rejection, stale/max-generation checks, and explicit entropy/module-lifetime/linearity nonclaims established the mechanics later connected by the callable host.
-
Added a private OS-backed native capability authority without connecting it to compiler preflight or any export. Exactly pinned
getrandom0.4.3 supplies one fail-closed seed for the secret, nonzero random epoch, and opaque thread-binding nonce; kind-specific non-formatting credentials seal immutable module/resource context and reject every operation off the actually captured Rust thread. Test-only deterministic entropy, independently reproduced authority goldens, error/zero/context/thread hostility, MSRV, and desktop OS smoke preserve the publicSPX-B104gate while module retention, ledger integration, fork safety, and callable ownership remain blocked. -
Added a private fake-backed
NativeModuleLeasetopology and required the native capability authority plus every staged owner/result credential wrapper to retain the exact allocation instance. Tests cover equal-fingerprint instance separation, process-incarnation rejection, one-way draining, lease-derived fingerprints, cross-instance rejection despite equal bearer bytes, drop-order retention, concurrent final release, and absence of retention cycles. There remains no production constructor, platform loader handle, code-identity admission, physical pin/unload protocol, ledger integration, callable export, or change toSPX-B104. -
Added an unpublished
semaprax-native-loaderworkspace quarantine around the unavoidable trusted-library load, fixed-getter lookup, and bounded descriptor-read/compare unsafe edge. At this initial stage its same-thread opaque explicit-retain lease, exact-pinnedlibloading0.8.9, compile-fail trait checks, workspace-wide gates, and real Linux/macOS fixtures were isolated from the compiler and authority; later entries connect them privately while the public adapter remains gated. -
Added a blocking, immutable-action-pinned
cargo-denyCI gate for the complete native/mobile/Wasm dependency graph: RustSec advisories, unapproved licenses, duplicate or wildcard versions, Git dependencies, and registries outside crates.io fail the build with no advisory exceptions. -
Added a root-frame native trace-storage scaffold with exact compiler-status/event validation and a pre-ownership attachment handshake. Canonically zeroed one-shot contexts, buffers, and event slots use owner/generation checks to reject rebinding, aliasing, double attachment, and capacity underflow before execution.
-
Added the unpublished
semaprax-native-hostphysical ownership stage. It strictly decodes compiler-derived descriptors, retains the exact real loader instance through its same-thread OS-seeded authority and opaque owners, authenticates owner/result credentials, connects the private ownership ledger, preserves owners on precommit rejection, rotates owned results, and gates new work after draining. The later callable-v2 work below replaces its original trusted-closure execution fixture; compiler resource builds still retainSPX-B104. -
Added the first narrow public
semaprax.wasm-owned.v1Core Wasm execution path for one direct trivial-resource identity. Generated adapters consume replay-validated terminal cleanup order, stage owner handles atomically, normalize contract/arithmetic/adapter status records, preserve poisoned result storage on failure, rotate owned results, and reject excluded shapes withSPX-W111. The generated JavaScript keeps host imports private, binds calls to exact generated metadata and SHA-256-authenticated Wasm bytes, rejects non-canonical ABI arguments, checks result ranges before ownership commit, and uses one-shot trusted adoption tickets; Node tests cover the admitted slice. This is not WebAssembly Component resources or production native-host conformance. -
Added
semaprax.semantic-event-dictionary.v1, which assigns deterministic nonzero ordinals to exact semantic event shapes. Generated cleanup C and the real Wasm owned adapter emit those ordinals from their executed control flow; the host-side materializer rejects zero or unknown ordinals without inferring or repairing events. -
Unified the authoritative direct-trivial-resource conformance corpus at 14 named scenarios. Real compiler-generated native shared libraries at O0/O2 now execute through the exact loader/authority/ledger ownership host, while real Node/Wasm executes the same cases. Both materialize to the exact reference trace and normalized outcome for zero/max payloads, reverse cleanup, contract and checked failures, scalar publication, owned identity/selection, and failed owned publication; native also proves result rotation and final logical liveness.
-
Added private callable native descriptor v2, derived from the sealed compiler host template plus execution/cleanup, semantic-dictionary, and trace-path evidence. Its canonical pointer-free wire binds twelve fingerprints, exact symbols, request/response capacities, complete ordered signature, opaque-
u64owned payload kind, and result mapping. The unpublished host's independent strict parser accepts compiler output and rejects every single-byte mutation, truncation, and trailing byte. -
Extended the native loader quarantine with Unix
RTLD_NOW | RTLD_LOCAL, exact callable-v2 symbol admission, bounded preallocated one-shot byte calls, and exact-instance rejection, then connected that transport to the ownership host with strict request/response codecs and allocation-free postcommit decoding. -
Added
semaprax.trace-path-certificate.v1: the compiler deterministically compiles every admitted cleanup path into a canonical trie-DFA separately fingerprinted into descriptor v2, symbols, and call contracts. Host admission authenticates it and rejects omitted, duplicated, reordered, or wrong-outcome traces before semantic materialization. -
Added complete private callable-provider emission with exact physical result and outcome namespaces, owned-payload integrity checks, and compile-time architecture/OS/environment/object/pointer/endian guards. Exact MSVC/GNU source known answers and deliberate target/payload mismatch fixtures fail closed without touching the response.
-
Made formatting, Clippy, tests, docs, builds, and the Rust 1.85 gate run every workspace feature so staged production surfaces cannot escape CI.
SPX-B104remains closed for general physical/malformed-response fallback cleanup and quiescence, Android/iOS profiles, and public native execution/admission. -
Added a separate fail-closed Linux Rust-host ASan lane pinned to
nightly-2026-07-16: it rebuilds the target standard library, proves active Rust instrumentation with both an intentional fault and binary/compiler inspection, and runs the real callable host plus generated corpus. The exact lane passed in public run 31259216533, job 93107277065, alongside a fully green current hosted-CI matrix for Linux, macOS, Windows, MSRV, dependency policy, and provider sanitizers. This is not mobile or app- platform evidence. Rust-host UBSan is not claimed andSPX-B104remains closed. -
Recorded the green public Linux callable-host sanitizer job: all 14 authoritative O0/O2 cases executed from dynamically loaded ASan/UBSan-instrumented generated providers through the Rust host. The Rust host code itself was not sanitizer-instrumented. The dependency-policy job was also green, but unrelated Clippy/GCC failures stopped the platform jobs before runtime evidence and kept the overall workflow run red; no Windows runtime evidence is inferred from this job.
-
Added the hidden callable-v3 settlement foundation and proposed RFC 0004: a bounded target-neutral certificate/frame/receipt model with one all-live start, typed progress, exhaustive owner-state enumeration, exact accept/abort cleanup actions, idempotent quiescent receipts, deterministic fingerprints, and hostile mutations. A private compiler deriver now preserves exact HIR result-staging/finalization timing and binds terminal settlement to accepted semantic trace paths for the authoritative 14-case direct-trivial corpus. The model deliberately provides no invocation or module-instance reservation, physical finalizer authority, descriptor/provider, loader/host, public compiler, or backend runtime evidence;
SPX-B104remains closed. -
Added a private linear settlement transaction model with closed
Executing,DecisionLocked,ActionInProgress,ProviderSettled, modelReceiptCommitted, and absorbingQuarantinedphases. Its 29 focused tests cover phase-aware unwind, every-finalizer interruption without retry, exact candidate/committed replay, hostile mutation/cross-binding, and preserved evidence while keeping providerPublishedunauthoritative. The model allocates and grants no exact-instance reservation, host authentication, ledger publication, FFI/provider, or physical-finalizer authority; this changes no v2 bytes or public/runtime gate. -
Added private callable settlement-proof v1 without consuming the future v3 ABI version.
SPXNPRF1embeds the exact unchanged callable-v2 descriptor and a canonical pointer-free binary settlement graph under one 64 KiB ceiling. Separate compiler and host codecs bind the exact v2 call contract and trace certificate, reject rehashed cross-module/changed-trace substitutions and hostile graph structure, and reproduce a fixed known answer. The compiler enforces the cap while serializing; the v2 loader rejects proof magic before opening an image; default consumers cannot import the proof surface. This adds no provider, descriptor-v3, loader admission, host settlement execution, physical finalizer, public API, mobile evidence, orSPX-B104change. -
Froze the private callable ABI v3 descriptor/wire contract:
SPXNABI3fixes the descriptor, acyclic hash dependencies, recovery graph, capacity budget, dynamic and iOS-static linkage roles, six complete provider codecs, and the distinct host-only 524-byte committed-receipt codec. The six-argument execute ABI, payload-bearing frame cells, closed tags, request/response/decision/action/ frame/candidate digests, and separate receipt-key HMAC replace the former provisional identities and freeze changed private v3 known answers.CertifyOutcomeembeds the canonical ordinal/outcome witness and a nonzero trace-certificate-bound evidence digest independently recomputed by the host; this binds the witness only and is not host acceptance of the trace-path DFA certificate. Resealed witness or digest mutations are rejected. Independent compiler encoders and host parsers cover those seven complete transcripts. The emitter is bound to its build target and provides no Android/iOS/Windows cross-emission evidence. Both existing loader constructors now reject v3 magic before path canonicalization or image/symbol access, including malformed same-magic headers. The compiler/host codec tranche grants no provider, loading, settlement, finalizer, ledger, mobile, or public authority and leaves v2/proof bytes andSPX-B104unchanged. -
Added the first private callable-v3 physical components: two bounded generated strict-C11 providers execute scalar-discard and owned-identity settlement at
-O0/-O2; an exact dynamic-image loader verifies root provenance for the getter, execute, settle, and descriptor storage; and the host has a distinct OS-seeded receipt authority with a fixed-capacity atomic ledger/facade. These components are not yet connected by one host invocation and do not prove the full 14-case physical corpus, exhaustive failure injection, sanitizers, Windows v3 runtime, Android/iOS, quiescence, malicious-code containment, public admission, or anySPX-B104change. -
Connected one private callable-v3 path from compiler-generated strict C through exact dynamic-image admission into the authoritative host receipt ledger. Scalar discard-two and owned identity execute at
-O0/-O2with exact buffer handoff, independent host decoding, finalizer order, receipt replay, generation refresh, cross-instance rejection, and unload pinning. Separately, graph-derived providers now execute all 14 authoritative normal corpus scenarios at-O0/-O2, including mixed owned/scalar/bool inputs, exact trace/action digests, dispositions, and replay; a mandatory ASan+UBSan gate and explicit Windows gate are configured. Pending/pre-execute host unwind fails closed without effects because its canonical returned-response transcript is not yet frozen. The joint host still allocates during post-CallCommitevidence decoding/replay, and the full corpus has not yet run through loader plus host. Failure injection, public CI observation of this batch, mobile/static admission, quiescence, malicious-code containment, and publicSPX-B104admission remain open. -
Expanded the private callable-v3 joint path to all 14 authoritative scenarios at
-O0/-O2, with mixed scalar/bool/owned requests, exact graph-derived finalizer evidence, authenticated replay/publication, and unload pinning. A counting allocator observes zero Rust heap growth from immediately beforeCallCommitthroughReceiptCommit; injected reusable-decode reserve failure quarantines exact bytes, owners, and the image pin. Seven provider-side failure fixtures cover physical return, malformed response/frame/candidate, durable finalizer interruption, replay, and decision conflict at-O0/-O2and under ASan+UBSan. Pre-execute unwind, fatal allocator/process-crash recovery, hosted Windows confirmation, mobile/static admission, quiescence, malicious-code containment, public admission, andSPX-B104remain open. -
Added canonical pre-execute callable-v3 unwind: frame tag 3 and reserved
0xFFFF_FFFEbind exact zero-filled response storage, the loader never enters provider execute, certified abort finalizers settle, and the host commits an authenticated receipt without Rust heap growth. Expanded all seven physical- failure/interruption fixtures through exact loader and host at-O0/-O2, including quarantine boundaries and zero retry. Added a bounded process- lifetime iOS-static exact-address registry that shares the dynamic host's generation/draining/quarantine ledger without any path,dlopen, close, or unload surface. Non-Apple static-function evidence is green; representative iOS/Android execution, fatal allocator/process-crash recovery, quiescence, public admission, andSPX-B104remain open. Private v3 descriptor/frame KATs migrated; v1/v2/proof bytes remain unchanged. -
Added a mandatory Windows callable-v2 dependency-isolation fixture. It places a same-name dependency in both CWD and legacy
PATH, proves the root-image sibling wins for descriptor admission and invocation, then removes that sibling and requiresLibraryOpenrather than malicious fallback. CI names this fixture and the complete O0/O2 callable corpus explicitly. Both passed in run 31257545008, job 93103151756. -
Added a public build-only native-callable API and CLI for one explicitly selected direct-trivial owned function. It produces a deterministic hashed provider bundle and strict host shared library through safe staging and observed no-overwrite checks, while exposing no loading, invocation, adoption, or authority and retaining ordinary native
SPX-B104. -
Added a private bounded iOS-static callable-v3 registration alternative. It binds one exact descriptor-storage/getter/execute/settle address tuple to a process-lifetime logical instance, makes exact bootstrap re-registration idempotent, rejects target relabeling and partial address reuse, and feeds the same generation/draining/quarantine ledger as dynamic admission. Non-Apple fake-function evidence exercises physical-return quarantine and pin retention; there is no
dlopen, close, unload, device-runtime, public API, orSPX-B104claim. -
Migrated browser manifests from
semaprax.web.v2tosemaprax.web.v3. Version 3 retains module, graph revision, Wasm entry, and capabilities while adding the requiredowned_abiobject with schemasemaprax.wasm-owned.v1and a declaration-ordered function mapping; scalar-only packages use an empty function array. Version-2-only consumers must reject or explicitly migrate rather than inferring ownership ABI metadata.
0.3.5
This is the most recent published tag and the full historical changelog is archived in docs/CHANGELOG-ARCHIVE.md.
Added
- Expanded project CLI workflows for lock generation/verification, dependency resolution, and interface comparison.
- Added support for richer manifest and contract diagnostics, including repair guidance.
- Editor and quality-tooling updates for
check,fmt, andtestflows.
Changed
- CLI diagnostics now surface stable-id and argument context on
semaprax run/testfailures. - Changelog documentation is now centralized and compressed at the repository root.
Fixed
- Improved route selection and command discovery for CLI help/catalog behavior.
- Tightened evidence and diagnostics alignment across human and machine paths.