Last updated: 2026-09-10
Cloud Wave 3 (U0) consumes Use as the trusted package/Plugin Manager
boundary. Deliver digest-only apply and observation contracts. Do not add a
Use-owned scheduler, node channel, or Cloud desired-state store. See
agents portfolio roadmap
and
cloud-substrate-dependency-roadmap.md.
A3S Use is a development preview. The cognitive-package platform has not shipped a supported product release and is not production-ready.
This roadmap is deliberately release-oriented. Completed internal contracts or green unit tests are evidence of implementation progress, not a release claim. A product release requires the cross-repository, cross-platform, supply chain, recovery, and operational gates in this document.
A3S Use will be the AI Native Package Manager for arbitrary coding agents and A3S hosts on Linux, macOS, and Windows. It must install platform-native capabilities and versioned cognitive packages whose dependency graph can contribute:
- Tool Tasks and Services;
- standard MCP servers;
- OKF Knowledge bundles;
- A3S Flow workflows;
- Skills; and
- sandboxed UI assets.
One command resolves the complete SemVer closure, verifies every source and artifact, freezes exact locks, prepares dependencies before dependents, publishes one capability generation, and retires unused generations in reverse.
- The package is the lifecycle unit; the scoped installation is the consistency unit. A surface cannot be installed, upgraded, enabled, disabled, or removed independently of its owning package. A graph mutation commits one complete scoped installation generation, never a collection of independently authoritative root-package graphs.
- There is one current cognitive-package format. Manifest v3, catalog v3, receipt v6, Installation Snapshot v2, Extension Registry snapshot v3, capability snapshot v5, extension cursor v3, capability cursor v4, plan v4, host protocol v6, managed scope v2, manager toolset v5 (v4 migration contract retained), pending graph v4, pre-lock resolution attempt/diagnostic v1, pre-plan download attempt/diagnostic v1, enablement recovery projection v3, and enablement operation v3 are the only accepted baseline.
- No pre-release compatibility debt. Superseded schemas, receipts, metadata, APIs, and disk state are rejected. The user must clean the unsupported state and reinstall. No migration or fallback is inferred.
- Package-manager compatibility remains. SemVer dependencies,
requires_use, OS/target checks, and host/provider capability checks are required correctness rules, not legacy branches. - Registries are replaceable host input. URLs, trust roots, source state, and mirror selection are not compiled into packages or the resolver.
- Trust evidence is end-to-end. TUF
custom.a3scarries a complete catalog-v3 record; the exact verified record and provenance survive download, planning, lock creation, installation, and receipt loading. - Planning and mutation are separate. Install, upgrade, uninstall,
enable, and disable return an immutable reviewed plan before apply.
plugin_apply_planis the only package-state mutation tool; explicit pre-admission cancellation is a separate control-plane mutation. - There is one Flow lifecycle.
a3s-flowowns workflow compilation and execution.flow.jsonmay describe visual design/deployment but cannot create another package identity, receipt, or journal. - OKF is a Knowledge surface, not a process. Publication requires exact promoted Knowledge evidence. Only OKF v0.2 is accepted.
- Hosts own providers and UX. Runtime, Gateway, Flow, Knowledge, Code, Web, and OS inject their typed providers; Use never hides missing ownership with native or source-only fallback.
- Hardware adapters reuse MCP. The MHS research-preview profile adds no package surface or private protocol. Use owns package trust and exact publication evidence; the hardware control gateway and device safety layer own physical authorization, interlocks, and ambiguous-operation reconciliation.
- Artifacts are global; authority is scoped. Immutable content-addressed bytes may be deduplicated globally, but package selection, dependency ownership, enablement, Grants, provider bindings, and capability publication belong to an explicit User or Workspace installation.
- Agents consume capabilities, not host paths. The portable agent contract is standard MCP plus opaque invocation, artifact, and endpoint references. Local executable paths, package roots, credentials, and provider internals are never part of the external capability contract.
- Management and consumption are separate trust planes. The Package Manager MCP endpoint performs privileged reviewed lifecycle operations. The Capability MCP Gateway exposes only the capabilities authorized for a consumer and holds exact-generation leases on the consumer's behalf.
- Use-owned mutable authority is transactional. ACL remains the product configuration format and immutable artifacts remain files, but related installation, operation, Grant, enablement, and publication state commits through one transactional Control Store. Sagas remain only around external provider effects that cannot join that transaction.
- The official package feed is a Registry deployment. Its target name is
A3S-Lab/Use-Registry, with root submodule pathuse-registry/.a3s-useowns Registry formats and tooling; the Registry repository owns reviewed admission data, signed TUF metadata, and immutable published targets. Package source remains in each owning repository. - Domain packages stay outside the package manager.
a3s-use-scienceis not an A3S Use workspace member, runtime dependency, CI target, or release artifact. A future Science capability remains owned by its independent repository and may integrate only as a signed Registry-distributed package.
Status: release-critical, planned from the 2026-08-28 first-principles review.
The current implementation has strong artifact verification, reviewed plans,
immutable generations, drain, and crash-replay foundations. A0 gives every
accepted mutation one serial order inside its exact installation and rejects
stale publication generations. A1 now has one canonical InstallationId and
scopes filesystem state, receipts, Registry and capability snapshots, leases,
backup/restore, and maintenance/mutation locks by that identity. A0 and A1 are
qualified on the declared five-platform CI matrix. The implementation is still
not the target architecture: one InstallationSnapshot now owns the desired root set,
unified resolved graph, per-package enablement, and selected-surface
publication intent, but receipts, Grants, bindings, operation checkpoints, and
materialized publication state remain split across several stores, and a non-A3S agent
cannot consume an exact leased capability without learning local execution
details. A checked item elsewhere in this roadmap is implementation evidence;
it does not waive the convergence gates below.
| Boundary | Sole responsibility |
|---|---|
| Catalog Source | Locate TUF metadata and targets; a Git or GitHub address is transport shorthand, never trust authority. |
| Artifact Store | Retain verified immutable bytes by digest and deduplicate them globally; it owns no installation or activation authority. |
| Installation Snapshot | Atomically describe one scope generation: requested roots, resolved packages, dependency edges, selected artifacts, enablement, and publication intent. |
| Control Store | Serialize and transact Use-owned mutable authority, operation records, checkpoints, and materialized capability generations. |
| Provider Set | Apply typed Runtime, Gateway, Flow, Knowledge, UI, Web, and OS effects through explicit ports. |
| Capability Index | Materialize an immutable, scope-specific projection only after lifecycle cutover. |
| Capability MCP Gateway | Present portable discovery and invocation to arbitrary agents while the Use Host owns exact-generation leases. |
| Package Manager MCP | Present privileged planning, review, apply, observation, cancellation, and diagnostics to an authorized operator or host. |
Canonical authority keys are explicit:
- installation:
(scope_kind, scope_id); - installed package:
(installation, package_id, package_generation); - capability:
(installed_package, surface_kind, surface_id); and - invocation: an opaque, expiring host reference bound to the exact capability generation and consumer context.
Package, CatalogSource, ArtifactStore, Installation, CapabilityIndex,
and Provider are the preferred architecture terms. Plugin, Extension,
and Registry type names with older meanings are removed at the next contract
cutover instead of being preserved as parallel abstractions.
A0 mutation correctness -> A1 scoped installation -> A2 transactional control
| `-> A3 agent capability gateway
`--------------------------> A4 provider boundary cleanup
A0 mutation correctness ------------------------------> A5 official Registry
A3 agent gateway + A4 provider boundary + A5 Registry -> A6 MHS qualification
Work may proceed in parallel only where this graph permits it. In particular, new surfaces, package types, or host-specific integrations do not take priority over A0 through A3.
- Add a deterministic barrier-based regression for the shared-dependency
race: with
Y -> Dinstalled, one operation plans removingYandDwhile another plans installingX -> D; no interleaving may publishXwithDabsent. - Introduce one cross-process installation mutation lease keyed by
(scope_kind, scope_id). Install, upgrade, uninstall, enable, and disable are exclusive writers within that domain; another installation remains independently available. - Bind every reviewed mutation to the expected complete installation
generation and make lifecycle publication an exact compare-and-swap from
installation generation
GtoG + 1. - After acquiring the mutation lease, revalidate the complete requested root set, resolved closure, dependency ownership, selected artifacts, and expected publication generation. A stale plan fails without provider or filesystem effects.
- Validate live dependents in every retirement branch, including nodes previously classified as retained, before hiding a package binding or deleting bytes.
- Advertise exclusive managed-scope mutation in host capabilities only when the active coordinator actually enforces it.
- Add multi-process stress and crash-replay tests for different roots with
shared dependencies on Linux, macOS, and Windows. CI run
33158712152
passed the main release gate and native Linux x86_64/ARM64, macOS
x86_64/ARM64, and Windows x86_64 jobs from exact commit
5a78b32f1db1880fe456ced1b76a027981381b52.
Exit gate: every accepted graph operation has one serial order, and no stale plan can publish a graph whose dependency closure is incomplete.
Implementation evidence (2026-08-28):
- Each installation's
.installation-mutation.lockis a cross-process, non-Tokio-blocking writer fence held by install, upgrade, uninstall, enable, disable, and recovery from live-state inspection through terminal persistence. State backup recognizes it as excluded infrastructure rather than portable authority. - The admitted pending graph record or active enablement record is the durable mutation owner after process exit. Graph and enablement recovery reject each other until the exact owner reaches a terminal state; no second ownership file can drift from the operation record.
- Lifecycle publication binds reviewed install, upgrade, uninstall, enable,
and disable plans to Registry generation
Gand commits only an exactG -> G + 1cutover. Stale generation, root ownership, dependency closure, manifest, artifact, and dependent checks run before authorization or lifecycle effects. - Barrier-based, independent-process, stale-plan, root-adoption, dependent, cross-domain interruption, and Registry cutover regressions cover the A0 invariants. Existing process-exit lifecycle suites continue to cover exact replay after cutover and removal checkpoints.
- Define
InstallationSnapshotas the single installed-selection source of truth for one explicit User or Workspace scope and monotonically increasing generation. It contains the desired root set and one resolved graph, rather than one authoritative graph file per root package. - Move expanded package directories into a global content-addressed
Artifact Store while keeping selections, receipts, package bindings, enablement,
Grants, provider bindings, and capability publication under an
InstallationId. - Move verified archive, executable-planning, and presentation-media bytes behind a global sharded Blob tier. Keep canonical source observations and resumable partials in the Registry source datastore. Blob commit is digest-locked, no-clobber, handle-rehashed, and durable before observation publication; source prune never deletes global bytes.
- Introduce one global cross-source/cross-installation/cross-operation reference inventory before deleting any raw blob or expanded tree.
- Join global references with physical inventory in one guarded collection pass and expose checked usage plus bounded quota assessment.
- Enforce an optional durable hard quota with concurrency-safe cross-process admission. Policy-disabled publications share the storage boundary; policy-enabled publications serialize physical scan, exact projection, staging cleanup, and final commit so two writers cannot spend the same capacity.
- Add an explicit bounded global digest audit for raw Blobs and expanded packages. Reuse the admission fingerprint, hold the exact collection guard, report mismatches without mutation, and fail closed on unsafe or unstable physical state.
- Require an explicit confirmed garbage-collection policy before deletion.
- Add exact-plan logical corruption quarantine. Re-audit under the exact collection guard, require the reviewed canonical plan digest, atomically publish a bounded marker, preserve forensic content in place, and fail new ordinary Blob and expanded-package access closed.
- Add verified rehydration. Recovery must not silently replace bytes underneath an admitted generation and must never derive replacement authority from a quarantine marker alone.
- Bind enablement and capability-publication intent to the exact
InstallationSnapshotgeneration instead of reconciling separate mutable authorities. - Require scope in extension paths, receipts, package bindings, snapshots, and every
CapabilityRegistryconstructor. Remove implicitUser/currentprojection. - Bind Runtime, Flow, OKF binding/SQLite, and lifecycle journal stores to
one constructor-supplied
InstallationId. Reject a different or invalid identity before path derivation, lock acquisition, database creation, or evidence mutation. - Make the same package independently selectable at different versions in User and Workspace installations while safely sharing identical artifact bytes.
- Replace route strings as identity with the canonical keys above. The ACL
routeattribute is now an optional human alias only. Duplicate aliases are legal; explicit alias lookup fails as ambiguous instead of selecting an arbitrary package. Ownership, leases, cursors, and host surface names use scoped package/generation/surface identity. - Freeze the new contract versions together. Because Use is pre-release, reject superseded disk state with a documented clean-reinstall procedure instead of maintaining a second live authority model.
- Prove apply, restart, snapshot, leased invocation, upgrade, and uninstall for the same package in two scopes, including identical textual scope IDs with different scope kinds.
Exit gate: all lifecycle, authorization, and capability queries can be answered from one exact scoped installation generation plus immutable artifact evidence.
Implementation evidence (2026-08-30; exit gate passed):
InstallationId(kind, id)is the sole installation identity. Its validated kind and collision-resistant storage key partition every installation data and state root; equal textual IDs in User and Workspace installations do not alias.- Receipt v6, Extension Registry snapshot v3, capability snapshot v5, and the extension cursor v3/capability cursor v4 contracts carry the exact installation and reject cross-installation loading or lease acquisition. The CLI requires explicit scope kind and ID for every installation-scoped command.
- Registry source configuration, trust roots, TUF metadata, target observations and partials, global artifact blobs, and derivable Flow compilation artifacts remain installation-independent inputs. Receipts, package bindings, enablement, Grants, provider bindings, capability publication, backup/restore, and both maintenance and mutation locks are installation scoped. Installation backup rejects the global cache families.
- Provider and lifecycle evidence stores no longer accept a second scope as
storage authority beneath an already installation-scoped root. Their scope
fields and nested keys remain integrity evidence and must exactly match the
constructor-bound installation; cross-installation reads and writes fail
with
use.installation.identity_mismatchbefore filesystem effects. - Windows publication and SQLite/Flow access use a shared extended-length path primitive. Native regressions cover long scoped roots, atomic publication, same-text-ID scope-kind isolation, and independent installation locks.
a3s.use.installation-snapshot.v2is the only installed-selection and desired-activation authority. It binds the exactInstallationId, a monotonic installation generation, one resolution host, a sorted desired root set, and one unique package selection per ID. Each selection carries the immutable lock node, monotonic package state generation, desired enablement, and exact selected-surface closure. Root locks are derived; conflicting shared selections, disabled dependencies of enabled packages, and orphan nodes fail closed. Removing the final root retains an empty next generation so authority never resets.- Installed-selection persistence is one atomic
state/installation-snapshot.jsonfile. The former per-rootstate/package-graphs/<publisher>/<package>.jsonlayout is rejected rather than migrated, and backup/restore inventories accept only the new snapshot. - Expanded package content is stored once at
data/artifacts/expanded-packages/sha256/<prefix>/<digest>/content, guarded by a cross-process per-digest mutation lock. Two installation registries can commit the same digest concurrently and converge on that one complete tree, while their receipt, generation, visibility, and lease authority remain independent. - The authoritative per-installation
registry.jsonsnapshot has a bounded 4 MiB read/write boundary. Readers validate the complete configured state directory chain, open the final file without following links or reparse points, allocate only the measured bounded size, and recheck file identity and length after reading. Writers create missing directories one component at a time only inside the configured state root, flush and sync a bounded temporary file, then atomically replace the snapshot. Oversized, linked, redirected, or concurrently replaced authority fails closed before JSON decoding or publication. - Artifact reads validate the complete owned directory chain and exact digest
path before package integrity is rechecked. Link/reparse substitution fails
closed. Interrupted writes use bounded
.artifact-staging-*trees and are reclaimed only while holding the digest lock. - A global cross-process reachability boundary now separates shared reference admission from exclusive maintenance. Raw-target observations, lifecycle receipts, applying/rolling-back lifecycle journals, installation snapshots, and durable package-graph operations must acquire a store-bound shared admission before their subordinate lock and atomic publication. Incomplete network downloads release admission until the bounded blob-commit/observation transaction. This closes the collector TOCTOU prerequisite.
ArtifactStore::inspect_inventorynow uses the exact store-bound exclusive guard to enumerate both physical tiers deterministically. Its path-free v1 report distinguishes canonicalcontentfrom abandoned staging, accounts regular-file bytes and files, bounds the complete traversal, and rejects unknown layout, links/reparse points, and special files. This is physical evidence only: it neither infers reachability nor verifies path digests and grants no deletion authority.RegistrySourceStore::inspect_artifact_referencesnow derives the first reference-source inventory under that exact exclusive guard. Its path-free v1 evidence scans every preserved Registry datastore, including a source no longer selected by current config, and reports each canonical blob digest with its signed byte expectation. Unknown layouts, missing cache locks, links/reparse points, malformed observations, and traversal bounds fail closed. This inventory is one input to—not a replacement for—the global joined view and its still-open audit and deletion policy.ArtifactReachabilityInspector::inspect_referencesnow derives the path-freea3s.use.artifact-reference-inventory.v1view under the same exclusive global guard. It validates every installation storage key and identity, then aggregates Registry observations, installed selections, current and retained receipts, non-cancelled package-graph operations, applying/rolling-back lifecycle journals, and immutable Runtime plan payloads. Runtime plan artifacts are decoded under the installation maintenance and plan-store locks before their Blob references are emitted. Source locks are joined without nesting unrelated locks; unknown state, links/reparse points, malformed or unbounded records, and conflicting physical expectations fail closed. Missing physical content does not erase a durable reference. Whole-installation restore now enters global reference admission before its maintenance lock and publication, closing the restore-to-collector race.ArtifactReachabilityInspector::inspect_reachabilitynow joins logical and physical evidence while retaining the same exclusive guard. Its path-freea3s.use.artifact-reachability-inventory.v1output has one canonical row per(kind, digest), keeps reference owners separate from physical state, classifies only metadata expectation availability/match, and derives checked global storage usage. Reference retirement may leave conservative extra owners. A bounded quota assessment reports observed excess but deliberately provides no deletion authority.- The global Artifact Store owns optional canonical
data/artifacts/storage-quota.aclpolicy state. Revision compare-and-swap serializes operator changes with publications. Every Blob and expanded-tree writer takes reference admission, then the global storage boundary, then its digest mutation lock. Without a policy, the storage lock is shared. With a policy, one exclusive lock covers bounded physical inventory, exact logical-byte/container projection, same-digest staging reclamation, and final publication. Real subprocess competition proves that only one of two distinct writers can consume one remaining slot. Prepared expanded-package byte/file measurements and a bounded exact copy prevent source growth from creating unaccounted staging. Tightening below current usage stops growth but permits non-worsening replay or cleanup. This correctness-first protocol is serialized, not a parallel durable reservation ledger, and grants no deletion authority. ArtifactStore::audit_digestsnow emits deterministic, path-freea3s.use.artifact-store-digest-audit.v1evidence while the exact collection guard freezes admitted publication. It reuses raw SHA-256 for Blobs and the canonical admission fingerprint for expanded packages, hashes sequentially, reports complete mismatches instead of mutating them, retains incomplete staging evidence without hashing it, and repeats the bounded physical scan before returning. Package file opens do not follow the final link/reparse component and revalidate the opened measurement. The audit itself grants no quarantine, rehydration, or deletion authority.ArtifactStore::plan_quarantinenow derives one canonical path-free plan only from a fresh complete digest mismatch.apply_quarantinere-audits under the same exact collection guard, compares the reviewed plan digest, and atomically publishes a no-clobberquarantine.jsonrecord. Exact replay is idempotent; bounded interrupted publication can be retried without removing its fail-closed sentinel first. Inventory validates marker state without charging it as content or staging, while new Blob open/observe/commit and expanded-package validate/commit paths fail closed. Canonical content remains untouched as forensic evidence. The marker grants neither replacement nor deletion authority.ArtifactStoreMaintenancenow coordinates verified rehydration across the facade/extension boundary. Planning and apply keep the exact collection guard across a fresh global zero-reference proof and Artifact Store work. Candidates must resolve outside the store and match the expected raw or canonical expanded digest. Exact path-free v1 plans bind the quarantine record, corrupt measurement, replacement measurement, and required reference count. Apply reverifies all evidence, publishes canonical prepared/completed records, stages under the digest mutation lock, accounts for peak hard-quota bytes, and only then reopens access. Bounded interrupted preparation, retired-content, and completion states resume; moved or conflicting records fail closed. Matching terminal replay validates durable completion and the canonical replacement without reopening the external candidate or requiring later references to be retired again. The reviewed replacement consumes corrupt forensic content, so external evidence retention remains an operator decision rather than hidden Artifact Store GC.ArtifactStoreMaintenancenow owns explicit confirmed global garbage collection. A policy names 1..=1024 exact Blob or expanded-package digests; there is no implicit sweep. Plan and nonterminal apply retain one collection guard across the complete reference scan and physical work, require zero Registry, installation, receipt, snapshot, graph-operation, and lifecycle- operation owners, and bind canonical physical measurements plus ordinary, quarantined, or completed-rehydration lifecycle evidence. Apply requires the reviewed plan digest, durably publishes a global prepared fence before any deletion, atomically renames each container to a deterministic same-shard tombstone, rejects links/reparse points and unowned residual entries, and resumes bounded partial deletion after restart. While prepared or temporary state exists, new reference admission fails closed. Completion is durable and exact replay is read-only. Each new plan binds the previous completion digest, so an old confirmation cannot delete an identical digest recreated later.- Upgrade, rollback, and uninstall retire installation-scoped authority but do not delete global content. Installation backup excludes global artifacts. Unreferenced content remains retained unless an operator explicitly selects it and confirms the exact global garbage-collection plan.
- Enable and disable use package-state compare-and-swap inside the next Installation Snapshot generation. Receipts, Registry package bindings, and the v3 enablement file are applied evidence or crash-recovery projections; none can independently select desired state. The projection binds the exact installation generation and digest, and capability snapshot v5 plus cursor v4 expose the same binding before any selected surface can publish.
- Registry publication and accepted-call drain are keyed by
(InstallationId, package_id, lifecycle_generation, package_digest, manifest_digest). Physical locks live undergeneration-leases; capability surfaces add their canonical kind and ID. Human aliases are retained only in projections, never serve as cursor package keys, and cannot change Tool/MCP host names. The cursor revision still commits the complete projection so an alias-only projection change cannot evade snapshot consistency. same_package_two_scope_matrix_preserves_exact_authority_and_leased_invocationinstalls the same signed OKF package into concurrent User and Workspace installations with an identical textual ID and one shared Artifact Store. Both installations survive Host reconstruction, expose distinctInstallationSnapshotauthority, reject cross-scope snapshot and invocation leases, upgrade independently while the other installation's v1 or v2 lease remains callable, uninstall independently without advancing the other capability cursor, and replay both terminal removals after restart.
- Introduce a typed
ControlStoreinterface with an initial SQLite/WAL backend for Use-owned mutable metadata. Keep ACL configuration and immutable package, backup, and projection payloads outside the database. - Commit installation generations, reviewed-operation state, lifecycle checkpoints, Grants, enablement, provider-binding identity, and capability generation metadata in explicit transactions with foreign-key and generation constraints.
- Use an outbox/checkpoint boundary for provider effects. Never hold a database transaction across Runtime, Gateway, Flow, filesystem, network, or device I/O; retry owner-proven safe-no-effect deferrals automatically with the same key, and reconcile rejected or unknown outcomes explicitly.
- Derive backup/restore inventory from the Control Store schema and
registered external payload owners instead of maintaining a second manual
allowlist that can drift from the state model. Control-backed coordinated
backup now admits only the verified Control export leaf plus
ControlPayloadOwnerIdlive locations; unregistered layout families fail closed. Owner-native complete-set snapshot/restore remains the stronger portable archive path and continues to converge with restore wiring. - Provide deterministic export, offline verification, restore, corruption
diagnostics, and clean-state initialization tests for the new store.
Authority export/verify/tamper rejection and clean restore round-trips are
covered by Control aggregate tests (
authority_export_is_complete_and_semantically_verified_offline,clean_restore_stages_and_round_trips_the_exact_authority); payload-owner restore coordinators and crash-checkpoint suites exercise the broader installation restore path. - Keep async callers non-blocking through an async database driver or a
bounded dedicated store executor.
ControlStoreExecutorowns a dedicateda3s-use-control-storeworker thread with a bounded request queue; async callers only await oneshot replies and never run SQLite on the Tokio runtime. Concurrent multi-thread verify (bounded_executor_keeps_concurrent_async_callers_progressing) and acurrent_threadresponsiveness proof (bounded_executor_keeps_current_thread_runtime_responsive_during_store_work) cover the ADR-003 isolation claim.
Exit gate: a process failure cannot expose a combination of graph, Grant, enablement, operation, and capability metadata that never committed together.
Implementation order is fixed by ADR-003. In particular, the SQLite backend must not become a mirror beside the current JSON stores. The preparatory extraction of installation-snapshot persistence from shared package-graph file I/O gives the coordinated cutover an explicit replacement boundary; it does not complete an A2 checkbox by itself. Production activation must switch the complete mutable control aggregate and its reachability, diagnostic, backup, and restore readers together.
The checked-in coordinated cutover contract
now records production activation (production_authority = "control-store",
control_store_activation = "active", clean-state-only). Cognitive-package
install/upgrade/uninstall/enablement and Host observation open Control only;
legacy mutable leaves fail closed at installation open. Product CLI install,
enablement, and Host graph completion now read Control operation evidence and
Control-backed installed extensions (no legacy extensions/ receipts). Product
graph recovery and production activation now prove Control EffectsPending
survives process restart and resumes by exact operation identity without
generation inflation; legacy journal/pending/registry kill suites are obsolete
under Control. Archive extraction/staging kill recovery and uninstall artifact
retention are Control-native. Native-launcher Tool surfaces no longer require
Runtime plan publications. A2 Control Store checkboxes are closed on evidence
(typed SQLite authority, outbox effects, inventory derivation, export/verify/
restore suites, dedicated store executor). Production readers no longer open unused legacy mutable leaves
(package-enablement/, operations/plugins, operations/package-graphs,
installation-snapshot.json, grants/, extensions/ receipts) as
authority beside Control; capability projection is Control-only. Coordinated
backup inventory under Control is derived from the Control export plus the
registered external payload-owner live locations (not the legacy
installation_state_layout allowlist). Control-native Host Grant
recovery (install/upgrade/uninstall reopen + offline replay without
reauthorization) and EffectsPending kill/resume are proven; legacy
grants/.operations kill suites are obsolete under Control. Host pre-admission
cancel now uses Control observation + Host cancellation + retained diagnostic
history only (no operations/package-graphs write). Host lifecycle binding
composition uses Control-authority payload roots
(payloads/{runtime,knowledge,flow}-bindings) instead of legacy
bindings/{runtime,knowledge,flow} leaves. This
activation does
not close A3, Registry, or ops GA gates by itself.
The inactive src/control_store/ kernel now qualifies most of ADR-003 step 2
for a clean installation. Schema v11 binds one exact InstallationId and stores
contiguous installation generations, canonical complete reviewed Plan
envelopes, versioned authorization evidence, exact snapshots, full Workspace
Grants, provider bindings, capability candidates, lifecycle checkpoints, and an
idempotent effect outbox behind relational and compare-and-swap constraints.
Plan and authorization bytes are bounded canonical JSON; operation ID, both
digests, action, root package, installation scope, and generation cursors are
derived and revalidated against relational projections after restart, in
offline export verification, and during staged restore. Selected packages now
keep immutable lifecycle generation separate from installation generation and
desired-state generation. A pure projection derives the complete next
snapshot, per-package desired-state generations, and globally monotonic
lifecycle incarnations from the exact reviewed Plan, prior generation, and
bounded committed history. Database commit, offline export verification, and
staged restore all recompute it. Authorization evidence v2 persists only the
exact prior Grant snapshot, reviewed change set, and confirmation facts. The
same projection re-finalizes full target Grants and their independent receipt
revisions, retains unrelated active Grants, and rejects caller-selected Grant
bytes, digests, or revisions. The projection covers all five actions, User and
Workspace installations, multiple roots sharing a dependency, and removal
followed by reinstall without reusing a package identity; callers can no longer
select these fields.
The same projection now derives the complete dynamic provider selection for
every enabled Tool and MCP surface from canonical reviewed Plan evidence and
the exact prior generation. It preserves unrelated package selections, removes
disabled or removed surfaces, and stores canonical provider build, capability,
semantics, and enforcement evidence with a derived digest. Static Flow, OKF,
Skill, and UI host ownership is not fabricated as Runtime selection. The
candidate capability descriptor digest is independently derived from the exact
target snapshot, package lifecycle identities, Grant revisions, and provider
selections. It intentionally contains no endpoint, readiness, compiled
artifact, or Knowledge application claim; those facts can exist only as typed
post-commit observations.
The projection also derives the complete bounded external-effect inventory.
Only work that cannot join the local transaction enters the outbox:
surface-prepare, capability-cutover, calls-drain, surface-stop, and
surface-remove. Package selection, lifecycle identity, Grants, and reviewed
provider selection are transaction facts, not pseudo provider effects.
Installation and enablement prepare dependency surfaces before dependants and
then cut over. Upgrade prepares the candidate, cuts over, drains prior calls,
and removes prior surfaces in reverse dependency order. Disable and uninstall
cut over before drain and reverse-order retirement. Each intent binds a typed
Capability Index, invocation-lease, Runtime, Flow, Knowledge, Skill, or UI
owner; Runtime effects carry the exact reviewed provider selection. Optional
selected surface preparation may be rejected without blocking cutover, while
its required dependency closure and every teardown remain required. Sequence,
owner, policy, generation, and a domain-separated idempotency key are all
derived rather than accepted from callers. Payload bytes, digest, and relational
projection commit together and survive restart and offline verification. Claim
and completion rebind every payload to the committed generation and reject an
incomplete checkpoint/outbox inventory. Applied outcomes now retain a canonical
owner-specific application descriptor, not a caller-selected success digest.
It binds the exact effect identity to Capability Index or invocation-lease
receipts, the reviewed Runtime selection and portable Task/opaque gateway:
Service readiness evidence, or Flow artifact, Knowledge projection, and
Skill/UI content digests. Deferred, rejected, and unknown outcomes retain
diagnostic evidence only. Deferred is allowed only when the owner proves that
it accepted no effect; a bounded durable not-before time then permits automatic
same-key retry without reconciliation. An applied capability-cutover
observation atomically retires the prior publication, publishes the candidate,
and advances the capability cursor
before drain or teardown. A required failure after that boundary remains
effects-pending for explicit same-key reconciliation and cannot roll back the
published generation; terminal completion must follow every observation.
Typed commands prove atomic transition rollback, action/root-state semantics,
terminal replay, pre-cutover required-effect rejection, post-cutover
reconciliation, and explicit reconciliation of unknown or expired claims
across restart. Its bounded canonical export includes the complete aggregate,
is semantically verifiable without the live database, and supports clean-state
staged restore with exact authority round-trip. WAL/full durability, foreign
keys, exact-schema/integrity checks, linked-path rejection, and the 16-entry
bounded worker remain qualified.
The inactive post-commit dispatcher now retains one installation-wide shared
maintenance fence from claim through durable observation, claims one effect at
a time, and leaves both the SQLite transaction and bounded executor before
owner I/O. Seven
separate typed ports cover Capability Index, invocation leases, Runtime, Flow,
Knowledge, Skill, and UI; each can return only owner-shaped application evidence
or an explicit deferred/rejected/unknown failure. A deferred observation binds
a maximum-five-minute not-before time, blocks early claims, survives export and
clean restore, and automatically retries only the original key when due. A hard
provider timeout must leave a fixed observation budget inside the claim lease;
timeout is recorded as unknown rather than being misclassified as rejection.
Timeout and caller cancellation stop waiting but do not cancel the possibly
accepted owner future; that detached task retains the same shared maintenance
guard until it actually completes. Process exit after an accepted effect, an
expired claim, and an unknown outcome all require explicit replay with the
original committed idempotency key. Qualification tests prove
commit-before-effect, Store re-entry during provider I/O, all owner routes,
action/evidence compatibility, timeout bounding, task-panic classification,
exact-key recovery, and that a concurrent restore cannot acquire its exclusive
fence before observation or while a timed-out/cancelled effect remains in
flight. Every successful claim now also
projects its
owner-shaped authority inside the claim transaction. Package owners receive
only the exact committed package selection, lifecycle incarnation, host,
snapshot identity, and Grant; Runtime additionally receives the complete
reviewed provider selection. Capability Index receives the complete candidate
generation and one latest terminal preparation for every enabled selected
surface, including retained multi-root surfaces from earlier generations and
explicit optional degradation. Missing Grant coverage, a nonterminal latest
observation, teardown masquerading as preparation, or generation drift fails
closed before provider I/O. The multi-root qualification exposed and fixed an
immediate-foreign-key ordering defect: generation commit now writes the complete
package node set before dependency edges and surfaces in the same transaction.
The Artifact Store now supplies the corresponding non-cloneable verified read
lease. Acquisition holds both coordinated read locks and binds one complete
verified catalog record to the full package fingerprint, manifest digest,
exact byte/file counts, manifest surface graph, surface-file validation,
quarantine state, and incomplete-GC fence. The handle exposes no package root,
bounded manifest reads precede ACL parsing, missing locks are not created by a
read, and repeat verification detects uncoordinated tampering. The first real
post-commit adapter uses that lease for immutable Skill and UI surfaces. It
re-derives the typed owner and original idempotency key from committed portable
fields, validates the exact package/lifecycle/host/snapshot/Grant authority,
reads only the named surface, re-verifies the full package after the bounded
read, and emits a stable path-free content receipt independent of retry claim
metadata. Artifact lock or I/O contention becomes a safe durable deferral;
tampering, missing content, and authority substitution become terminal
proved-no-effect rejection; this read-only adapter has no unknown-acceptance
state. Static stop/remove receipts require no artifact path or bytes. This
is now joined by a real OKF Knowledge adapter. It revalidates the exact
committed Knowledge owner and idempotency key, reads first-use OKF content as a
path-free verified byte payload, stores staged receipt evidence before
promotion, stores promoted evidence before returning applied, and can replay a
retained promoted generation without Artifact access. Stage, promotion,
removal, or post-effect receipt ambiguity is durable unknown evidence;
pre-effect contention is a safe deferral; authority or immutable-byte drift is
rejected. Stop is path-independent and remove is driven only by the retained
receipt. A real SQLite composition test exercises committed claim, detached
dispatcher coordinator, Knowledge materialization, and durable Control
observation together. Artifact-only admission is now distinct from legacy
lifecycle publication: it is idempotent, revalidates prepared bytes, creates no
installation receipt, and requires its reference-admission guard to span the
separate authority commit. The third real post-commit adapter now implements
Capability Index and invocation leases as one Capability Plane boundary. It
accepts a host-owned pure Agent-catalog projector only after validating the
committed candidate and exact terminal surface evidence. It rejects projected
descriptors outside enabled, prepared package incarnations, durably publishes
the catalog, and materializes a canonical content-addressed Index document
that binds the publication. Control's applied cutover observation advances the
only mutable cursor with that catalog digest/generation/revision in one
transaction. Admission reopens and rehashes the exact catalog before reading
the cursor around shared locks for every package incarnation; drain requires
an unpublished prior incarnation and an exclusive lock, safely deferring until
accepted calls release it. Immutable publication is no-follow, no-replace, and
crash-replayable. The Index and lease files remain derived operational state;
the legacy coordinated inventory now registers and verifies the catalog and
descriptor-snapshot payloads. The owner-native restore boundary now also has a
ControlCapabilityPayloadRestoreCoordinator that binds both plans under one
exclusive fence, preflights both targets, and replays fixed-order activation.
A matching ControlCapabilityPayloadRetentionCoordinator now binds both
retention plans under one exclusive fence, preflights both inventories and
pending journals before the first unlink, and replays fixed-order deletion. A real
composition test joins Knowledge, Skill, catalog/Index publication, exact
payload admission, stale admission, and same-key drain retry. The
inactive ADR-003 step-3 qualification now also includes a committed-authority
Flow owner. It consumes a path-free verified source snapshot, durably publishes
a no-clobber content-addressed source in its own workspace, and invokes only
the typed a3s-flow Native TypeScript preflight. Compiler/cache paths are
operational host configuration, never package authority; source substitution
and failed preflight reject without a Control observation, while Artifact Store
contention remains a same-key deferral. Stop/remove are path-independent
receipts. The same inactive qualification now includes a committed-authority
Runtime owner for release-backed Tool Tasks, Tool Services, and Streamable HTTP
MCP. First prepare reads a verified, path-free Tool/MCP release payload and
requires the injected plan/provider semantics to match the exact committed
package and provider selection. Task preparation persists no Runtime unit;
Services advance a durable requested -> runtime-applied -> gateway-ready
record before committing the final binding. Exact final receipts replay without
Artifact access, the final-binding/provisioning overlap reconciles without a
second Runtime apply, and retirement verifies receipt-owned provider evidence
before Gateway drain and Runtime stop/remove. Pre-effect contention safely
defers; authority or immutable-byte drift rejects; every ambiguity after a
Runtime, Gateway, or receipt effect remains unknown. The Runtime boundary now
provides a bounded canonical plan payload and a restart-safe resolver that
reconstructs the full plan from its committed semantics digest and rechecks
exact provider evidence. The installation-scoped, host-owned
RuntimeSurfacePlanStore is also qualified as a canonical digest-addressed
payload source with bounded batch publication, no-clobber writes, restart-safe
reads, and fail-closed tamper checks. An inactive lifecycle admission seam now
accepts the canonical cognitive-package Plan envelope, authorization evidence,
and optional planned Grant transition. It derives both prior Control cursors
from the immutable Plan and accepts no caller-selected generation. Its combined
qualification entry point retains one installation-wide maintenance fence while
registering the exact reviewed operation, deriving the complete Control
transition, validating exact Runtime prepare coverage and reviewed Grant
proposal digests, publishing immutable plan bytes, and committing the projected
generation. Production still needs to route the live lifecycle through this
seam and complete the atomic dispatcher composition; a
process-local selection must never become production authority, and no adapter
may read legacy authority or treat a path as authority. This narrows the
production cutover boundary without activating the private kernel.
Production lifecycle code still does not construct this kernel, and the live
state layout, reachability, diagnostics, backup, and restore orchestration do
not accept it as production authority. A private path-free registry contract
now freezes all seven owner identities and their ACL backup policies. It excludes
the global Artifact Store and requires an exact canonical receipt set for the
remaining six owners, bound to one InstallationId, Control generation,
registry digest, owner snapshot schemas, manifest/inventory digests, and
bounded file/byte accounting. Deserialized evidence must pass the same
semantic validation before hashing. This removes the duplicated owner-ID and
policy list from the cutover test. A private snapshot session now binds the
canonical Control export digest, generation, installation, and owner-registry
digest under one exclusive maintenance fence, then releases the SQLite
transaction and bounded-executor permit before owner I/O. The Knowledge owner
now produces and offline-verifies a non-overwriting, size-bounded OKF
SQLite/FTS5 archive plus canonical binding/selection inventory evidence. A
missing Knowledge database is represented by a zero-file manifest without
mutating live state, and linked owner roots fail closed. Snapshot creation and
offline verification now also require the exact canonical Control export named
by the binding. Every retained Knowledge lifecycle incarnation must map to its
originating prepare intent and committed OKF bundle. Applied prepare evidence
must match the retained observation and capability projection; removed or
missing applied payload must have a same-incarnation remove effect. Deferred
outcomes prove no owner effect and remain scheduling evidence; claimed and
unknown outcomes remain explicit reconciliation evidence. None selects desired
state. This code remains inactive and does not replace the legacy path
scanner. An offline-verified Knowledge owner snapshot can now stage its exact
SQLite database into a caller-owned directory beneath the target state root,
re-audit the staged database and canonical binding/selection inventory, and
activate only into a clean target while the exact installation-wide exclusive
maintenance fence is held. Activation rejects linked paths, candidate drift,
unowned live-layout entries, unexpected absent-state bytes, an existing live
payload, and a guard for another root. It publishes by atomic rename and
replays an exact completed partial. While the staged attempt and exclusive
guard remain held, it also reconciles the post-publication/pre-result boundary
without creating a second binding authority; the canonical result is path-free
and snapshot-bound.
The planning-and-diagnostic observation owner now has the second concrete
snapshot and clean-target restore adapter. It uses the diagnostic-history,
resolution-attempt, and download-attempt owners' own decoders and invariants
instead of copying their schemas. Only terminal diagnostic histories and
terminal resolution attempts enter the bounded no-clobber archive. Active
resolution/download records and locks are excluded, while a canonical
path/digest inventory of active records is bound to the manifest. Secure
traversal, a second pre-publication scan, and offline verification reject links,
moved or foreign records, unknown layouts, duplicate identities, substitution,
trailing bytes, and registered bound violations. Receipts remain path-free and
bound to the exact Control export. An offline-verified archive can be staged
beneath the target state root without touching live owner paths. Activation
requires the exact exclusive maintenance guard and a clean record inventory,
atomically marks the archive as activating, and publishes each owner-validated
record without replacement. Digest-named deterministic partials recover
interrupted record writes; after activation starts, only an exact snapshot
subset may replay. The final path-free result is bound to the owner manifest and
inventory. This adapter is not connected to the legacy scanner.
The Host protocol projection is now the third concrete snapshot and
clean-target restore adapter. Its owner-native scanner treats immutable
request-to-plan records, optional terminal outcomes, and cancellations as the
only semantic archive sources. Operation lookup aliases and latest-enablement
diagnostic indexes are derived: the scanner validates them against their source
requests, rejects missing, stale, orphaned, linked, or unknown layouts, and
excludes them from the archive. Exact and legacy cancellation aliases normalize
to one canonical binding. A bounded no-clobber archive is published only after
a second live scan and after every Host plan, outcome, cancellation time,
completion result digest, package identity, desired state, selected surface,
package generation, and capability generation is reconciled with the exact
bound Control export. Receipt and observed-health evidence remain Host
observations and cannot choose Control desired state. The path-free manifest
and receipt support exact offline verification, explicit zero-file absence, and
no-change Host requests without inventing an operation. An offline-verified
snapshot can stage its archive and build a complete target-local Host owner
root from exact semantic source bytes plus newly derived canonical operation and
latest-enablement indexes. Legacy aliases and locks are excluded. Activation
requires the exact exclusive maintenance guard and no existing live owner root,
re-runs the owner-native semantic scan, persists a snapshot-bound activation
marker, and atomically publishes the whole directory without replacement.
Deterministic archive, record, and marker partial recovery covers every staged
transition, and the same attempt reconciles the post-publication/pre-result
boundary. Drift, links, rebinding, and preexisting state fail closed; absence
creates no owner root and the result is path-free. This adapter remains
inactive. The Restore Coordinator is now the fourth concrete snapshot and
restore owner. Its owner-native scanner accepts only
exact canonically encoded completed restore operations for the bound
installation. It excludes the active marker and its exact operation while
binding their bounded count and digest inventory, including marker-only
handoff. Orphaned nonterminal operations, pruning or temporary residue,
unknown entries, links, foreign installation history, and path/record rebinding
fail closed. Snapshot creation performs a second scan before no-clobber
publication; its path-free receipt and streaming offline verifier bind exact
terminal bytes to the Control export, while empty or active-only history emits
no archive. An offline-verified snapshot now builds an immutable target-local
candidate. Activation requires the exact exclusive maintenance guard and an
active whole-installation restore marker; it binds that stable marker identity
plus exact before/source/target inventories before changing live state. It
atomically retires only terminal directories, publishes the target without
replacement, and leaves the current active operation untouched even as its
status advances between replays. A marker-only handoff is valid. If a legacy
whole-installation marker accompanies a 64-record source, the adapter applies
the journal's native (completed_at_ms, started_at_ms, plan_digest) ordering
and omits exactly the oldest source record to reserve the active operation's
slot. The typed complete-set marker has no retained operation and preserves all
64 records. Any source collision with a retained active plan fails closed before
pruning. Candidate, activation, retired,
and deterministic publication-partial evidence make every local boundary
replayable and tamper-evident, and the result remains path-free and
snapshot-bound. This adapter is still qualification-only. The Runtime plan
payload owner is now the fifth snapshotted owner: it captures immutable,
installation-scoped plan envelopes, verifies complete key/plan binding, and
restores them before Host projection activation. Runtime plan artifact digests
are included in installation reachability scanning so cleanup cannot remove a
blob still required by a committed plan. The Capability payload owner is now
the sixth snapshotted owner: it captures the installation-scoped Gateway catalog
and descriptor-snapshot family under capability-gateway, restores after Runtime
plans and before Host projection, and keeps Index/leases excluded as operational
state. Seeded Archive (catalog + descriptor-snapshot) complete-set round-trip is
now tip-qualified alongside Absent; owner digests may be domain-separated from
plain archive sha256. Tip also proves Archive fail-closed offline verify
(trailing/truncated/rebound entry) and that planted capability-index /
generation-leases stay excluded from complete-set bytes and clean-target
restore. Production Control Store activation and backup/restore
wiring remain open. The private complete-set snapshot
coordinator now captures one canonical Control export and the Capability,
Host projection, Knowledge, planning/diagnostic observation, Restore Coordinator,
and Runtime plan snapshots under the same exclusive maintenance fence and timestamp. One
canonical path-free manifest binds the exact owner registry,
receipts, schemas, digests, and byte accounting. The coordinator streams a
single staged archive outside all Use data and state roots, reuses each
owner-native offline verifier, and publishes only the fully verified file with
no-clobber semantics. Explicitly absent owners add no payload bytes, and the
global Artifact Store remains excluded. This closes complete-set snapshot
assembly and offline verification. The same offline-verified aggregate can now
stage one deterministic clean-target restore attempt. A canonical path-free
descriptor first binds the exact complete snapshot, installation, owner
registry, Knowledge policy, and fixed seven-component set. One exclusive target
maintenance fence is then retained while the Control database and all six
owner-native candidates are built beneath the fixed
.control-installation-restore directory. Control is reconstructed from the
canonical export, checkpointed to one SQLite file, round-tripped semantically,
and bound by durable physical digest evidence. No live Control, Capability,
Host, Knowledge, observation, or restore-history path is changed. Exact retries and
interrupted Control staging recover deterministically; target contamination,
links, unknown entries, snapshot or policy rebinding, and completed-candidate
drift fail closed. The complete-set coordinator now qualifies full ordered
activation. Before durable intent, it revalidates every owner candidate and its
clean live boundary. The immutable attempt descriptor remains the restore
identity. A canonical activation.json journal binds that attempt to an
immutable operation; the typed global .maintenance.restore.json marker binds
the same identity and blocks ordinary shared access. The fixed owner order is
Control Store, Runtime plans, Capability payload, Host projection, Knowledge,
observations, then Restore Coordinator; every step follows journal, marker,
owner effect, checkpoint.
Each ordered checkpoint retains only the canonical path-free result length and
a domain-separated digest. The Restore Coordinator additionally binds the exact
complete marker bytes, length, and digest before history mutation. Reopening
reacquires the exact exclusive guard, rebinds the same verified snapshot,
attempt, owner registry, and Knowledge policy, and reconstructs or verifies
every owner at its precise candidate/live boundary. Journal and marker partials,
all seven post-effect/pre-checkpoint boundaries, the final checkpoint before
retirement, and exit immediately after marker deletion converge. A missing
marker is valid only beside the complete seven-checkpoint journal; out-of-order
live roots, ambiguous markers, snapshot rebinding, links, and evidence drift
fail closed. Exact completed replay performs no owner effect and can only resume
bounded fixed-order retirement of the seven link-free staging trees. A
real-child-process matrix qualifies 24 top-level durable exits, including each
retirement boundary. The surviving canonical attempt.json and complete
activation.json are the exact installation-bound terminal receipt. Legacy
backup and artifact reachability exclude only that receipt; incomplete,
extended, linked, or tampered evidence fails closed. Production Grant
conversion, Runtime/Flow dispatcher composition, production backup/restore
wiring, indivisible consumer cutover, and deletion of legacy mutable stores
remain open on the A3/ops path. A2 Control Store checkboxes are closed on
evidence (typed SQLite authority, outbox effects, inventory derivation,
export/verify/restore suites, dedicated store executor including a
current_thread non-blocking proof). Legacy mutable-store deletion and
indivisible consumer cutover remain cutover follow-ups, not open A2 gates.
Progress on prune-legacy: Host protocol store no longer dual-writes or
fallback-reads pre–plan-digest operation/cancellation indexes (exact
binding paths only); capability projection reads Control payload binding
roots via for_control_authority instead of legacy bindings/*.
The legacy CognitivePackageEnablementStore file writer under
package-enablement/ is deleted; enablement projection/operation types and
validators remain for Control diagnostics and recovery evidence only.
Knowledge CLI restore observes Grants from the committed Control generation
via ProductionControlLifecycle::observe_stored_workspace_grant on the
for_control_authority path (legacy grants/ stays absent).
Knowledge restore authority inventory and managed Knowledge lease acquisition
likewise pin exact generations from the Control installation snapshot
(validate_authority_inventory_control,
acquire_control_knowledge_generation_leases); published Registry lease paths
remain test-only. Fail-closed without Control:
control_restore_fails_closed_without_control_installation_snapshot,
control_knowledge_leases_fail_closed_without_control_snapshot.
Capability Gateway snapshot leases pin the same Control selections via
ExtensionRegistry::acquire_control_snapshot (packages projected from the
Control installation snapshot into CapabilityUpstreamEvidence). Empty Control
leases use acquire_empty_control_snapshot against
ExtensionRegistrySnapshot::empty — never acquire_published_snapshot /
registry.json. Projection fail-closes without Control
(use.capability.control_required). Evidence:
injected_registry_acquires_one_exact_use_snapshot_lease,
snapshot_lease_fails_closed_without_control_store.
Whole-installation restore validates live Control export authority under the
exclusive maintenance fence (validate_live_control_authority) and fails closed
without Control (use.state_restore_control_required); coordinated backup likewise
requires Control (use.state_backup_control_required) and never reads published
registry.json authority. Evidence:
coordinated_backup_requires_control_store,
control_state_restore_plans_against_control_export_authority.
Operation diagnostics project Registry generation/digest from Control
(control_registry_diagnostic_face); they do not read published_snapshot().
CLI Plugin Manager planning reads the same Control-owned Grant snapshot via
CognitivePackageManager::planned_grant_snapshot and must never open
WorkspaceGrantStore::from_extension_paths (that path's lock creates
grants/ and fail-closes Control open).
Production Grant commit evidence:
production_apply_commits_grants_without_legacy_grants_leaf.
PackageGraphAuthorization::lifecycle_unit (file-store Grant saga) is
#[cfg(test)] only — production never opens WorkspaceGrantStore beside
Control. CognitivePackageManager no longer stores an authority selector;
construction still fail-closes via select_installation_authority.
File-store WorkspaceGrantStore locks fail closed when control.sqlite3 is
present (use.plugin.grant_store.control_authority_required) so hosts cannot
materialize grants/ beside Control.
CognitivePackageManager::ensure_control shares one open path with
ensure_control_for_registry_lifecycle (default cached Registry trust when
sources exist). OnceCell records whether signed description trust was injected;
a later Registry/Gateway open that requires signed trust fail-closes with
use.control.signed_description_trust_unavailable instead of silently keeping
an unsigned projector.
OkfKnowledgeRecoveryManager::from_extension_paths and the legacy
bindings/{knowledge,runtime,flow} / operations/plugins store constructors
are #[cfg(test)] only; production builds expose
for_control_authority exclusively. InstallationSnapshotStore and
PendingPackageGraphStore (legacy installation-snapshot.json /
operations/package-graphs writers) are likewise compiled only for tests;
those leaves remain in LEGACY_AUTHORITY_PATHS and fail-close beside Control.
Production apply_reviewed_operation / pending-effect resume seed an empty
unsigned descriptor-proof snapshot for the committed capability identity only
when the published Gateway catalog has no descriptors (skill-only /
catalog-empty). Non-empty Tool/MCP catalogs leave the snapshot absent until
proofs are staged, so signed publish cannot conflict with an empty seed.
As a cutover prerequisite, lifecycle intent v4 and operation v3 now bind every
checkpoint key to the plan, installation kind and ID, package ID and
generation, action, sequence, kind, and surface. This removes collisions
between graph siblings before their effects enter one installation outbox.
- Ship two standard MCP service entry points: a privileged Package Manager
endpoint and a lower-authority Capability Gateway endpoint. Do not introduce
a private Use JSON-RPC protocol. The Gateway embedding also exposes standard
Streamable HTTP at
/mcpwith host-owned bearer, Origin, and bounded admission configuration. - Define portable
CapabilityDescriptorcontracts with opaqueInvocationRef,ArtifactRef,EndpointRef, andResourceRefvalues. Remove executable paths, package roots, provider release paths, and secrets from external JSON. - Let the Use Host resolve an invocation reference and retain the exact package-generation lease for the entire call, stream, or server connection; drain and retirement operate on those server-side leases.
- Define consumer profiles. Generic coding agents receive standard MCP Tools, Resources, and Prompts; the typed profile/negotiation contract keeps optional A3S extension labels explicit without changing the universal contract.
- Project negotiated Flow, UI, and Knowledge metadata for A3S consumers
without weakening the lower-authority boundary. Principal-scoped discovery
filtering remains a separate host policy seam. Path-free
CapabilityDescriptorKind::{Flow,Knowledge,Ui}variants carry digest-bound extension payloads; they require the matching consumer extension, appear inextension_metadata_descriptors()only after negotiation, and are never compiled into MCP Tool/Resource/Prompt routes (gateway_projects_flow_ui_knowledge_metadata_only_for_negotiated_extensions). - Propagate standard MCP request cancellation through the Capability
Gateway. rmcp
RequestContext.ctnow bounds Tool, Resource, and Prompt provider operations; cancellation drops in-flight provider futures and resolver/admission leases, with a typed secret-free boundary result when a response is still deliverable. Detached downstream work remains a host provider responsibility. - Require signed descriptions and JSON input/output schemas for every
agent-visible Tool. Legacy executable-only Tool Tasks remain host-only until
a schema-valid descriptor is bound to them. Grant Tool production cutover now
admits only schema-bearing Tools through
ControlCapabilityDescriptorProjection(Runtime attestation digests) and publishes signed v2 descriptor snapshots;ProductionControlHostDependencies::standalone_with_signed_catalogis the product constructor that re-verifies those envelopes on projection. Registry/TUF key-source binding is implemented:load_capability_description_trust_storereads the signed fixed targetcapability/description-trust-store-v1.json, registry-tools can assemble and verify it, andstandalone_with_signed_catalog_from_registry/open_control_lifecycle_with_signed_trustinject only aVerifiedCapabilityDescriptionTrustStore. Product CLI wiring is closed for Gateway serve:a3s-use mcp serve gateway --registry-name <name>(or the configured default) callsensure_control_for_registry, which loads the signed target throughload_signed_description_trust_for_controland opens Control viaopen_control_lifecycle_with_signed_trust(no fixture keys). Empty Registry configuration keeps the unsigned preview projector (signed_trust_load_stays_optional_without_registry_sources,gateway_mcp_entrypoint_accepts_registry_name_for_signed_trust,capability_description_trust_store_loads_from_signed_tuf_target). - Expose bounded, catalog-authorized MCP Resources and Prompts through the
standard
resources/list,resources/read,prompts/list, andprompts/getmethods. Resource URIs are opaque and exact-match checked; prompt arguments are closed against reviewed declarations; provider content is size-bounded, path-free, and held under the same generation lease as Tool calls. - Materialize one immutable Capability Index at lifecycle cutover and emit
generation-change notifications. Remove fixed-interval full filesystem
rescans and repeated asset hashing from the normal watch path. Control
durably publishes and transactionally binds exact catalog/Index identities;
reconcile_published_capability_gatewayswaps a live session after cutover and fans out standard MCPlist_changedto independent clients (control_cutover_reconcile_notifies_independent_client_list_changed). Hosts that retain a long-lived Gateway must still call reconcile after releasing prior-generation leases (Grant Tool upgrade lease fencing). - Add CLI/service wiring, fail-closed trusted confirmation for management
apply, bounded authentication, authorization, rate limits, and secret-free
diagnostics for both endpoints. Gateway HTTP bearer authentication,
optional exact Origin policy, duplicate-header rejection, bounded in-flight
and rolling-window admission, sanitized HTTP errors, an explicit
pre-invocation provider authorization hook, and typed propagation of the
host-authenticated transport/principal context are implemented; bounded
HTTP token-to-principal mapping is now also available. Manager serve uses
FailClosedPluginManagerConfirmationProviderso MCP never implies apply confirmation. Gateway serve loads Registry/TUF description trust via--registry-name/ default into Control open and reopens the published catalog withproduction_gateway_invocation_provider()(Control Grant + Runtime receipt join;production_invocation_factory_requires_committed_control_grant). A host can inject a bounded, fail-closedCapabilityGatewayDiscoveryPolicyso authenticated principals receive frozen per-context Tool/Resource/Prompt views; this metadata boundary remains separate from invocation authorization. Provider errors are sanitized at the agent boundary (adapter_sanitizes_provider_errors_at_the_agent_boundary). - Prove one-endpoint discovery and invocation from independent Rust, TypeScript, and Python clients, including a container or remote client with no shared package filesystem. Cover install, live upgrade, prior-generation drain, uninstall, restart, and denied cross-scope access.
Implementation notes (2026-09-03): PR #192
landed the portable descriptor and catalog contracts plus an embedding
CapabilityGatewayMcpServer that speaks standard MCP and dispatches through an
injected provider. PR #199 then added
an exact CapabilitySnapshotLease constructor path: the host acquires all
callable package-generation leases in canonical order, rechecks the cursor, and
retains the non-clone lease through Gateway clones and calls. PR
#200 corrected a first-principles
clock error in the catalog contract: catalog generation is the immutable
publication generation, while each descriptor generation is its owning
package lifecycle generation. A single publication may therefore contain
independently upgraded packages, but it cannot contain two lifecycle
incarnations of one package/surface identity. PR
#202 adds shared host-configured
in-flight and rolling-window admission to Gateway calls and Streamable HTTP.
PR #203 adds duplicate-header
rejection, native-client Origin compatibility, standard HTTP challenge/backoff
headers, and a real independent Rust client test. These are contract and
embedding increments only; the A3 exit gate remains open until live-host
reference resolution, authorization, CLI wiring, and the independent
client/recovery matrix are implemented. The HTTP transport remains
caller-TLS/loopback only; authentication and rate limiting are endpoint
safeguards, not a substitute for live reference authorization. The provider
boundary now requires a pre-invocation authorize hook; denials are sanitized
to use.plugin.capability_gateway_forbidden and never reach invoke, with no
implicit allow implementation. A host must bind its principal and policy
explicitly.
Implementation note (2026-09-23): Control composition exposes
gateway_invocation_provider /
ControlCapabilityGatewayInvocationResolver, which reopen the durable
published cursor, validate the exact descriptor against the immutable
catalog, and retain an external Control generation lease through
authorize+invoke (proven by Control capability-plane and drain-busy tests).
ProductionControlInvocationFactory joins the leased descriptor to a
committed Control Grant and installed package selection before provider
I/O; absence fails closed as use.plugin.capability_gateway_forbidden
(production_invocation_factory_requires_committed_control_grant). For
Tool/MCP it then discovers the durable Runtime plan key, reconnects the
committed provider, loads the exact binding receipt, and verifies the
receipt-owned provider lease before returning the handle. Missing
provider selection fails as use.control.capability_gateway_provider_missing;
missing plan/receipt fails as
use.control.capability_gateway_runtime_binding_missing. Tool Task invoke
uses the joined receipt; Tool/MCP Service invoke proves the provider is
still healthy, then dispatches through
ControlCapabilityGatewayEndpointRouter. Composition owns a shared
ControlGatewayEndpointRouteTable: bind readiness is wrapped by
RecordingControlRuntimeServiceReadiness, and
production_gateway_invocation_provider() injects
LiveControlCapabilityGatewayEndpointRouter, which resolves opaque
gateway: identities to the loopback Runtime endpoint recorded at bind
and forwards with the plugin native protocol (MCP Streamable HTTP
tools/call, or Tool Service POST of Gateway-validated JSON to
base_path). A missing route still fails closed as
use.control.capability_gateway_endpoint_route_unavailable
(live_router_fails_closed_without_route,
live_router_forwards_tool_service_http_to_recorded_endpoint).
FailClosedCapabilityGatewayEndpointRouter remains available for
tests and non-production factory construction. Non-Tool/MCP surfaces
remain Grant-only (use.control.capability_gateway_runtime_unavailable
on provider I/O). Invocation authorize requires an authenticated
principal (use.plugin.capability_gateway_forbidden when absent). Open
also requires the descriptor surface to appear in the committed Grant
permission ceiling. Product CLI wiring:
a3s-use mcp serve gateway --scope-kind … --scope-id … [--registry-name …]
loads the signed description trust store from the selected or default
TrustedRegistry (when configured), opens Control through
ensure_control_for_registry, and reopens the durable published Control catalog
through
ProductionControlLifecycle::serve_published_capability_gateway_stdio /
open_published_capability_gateway with
production_gateway_invocation_provider(). Optional
--streamable-http [--bind …] [--token …] [--principal …] serves the same
Control-backed session over loopback Streamable HTTP and prints endpoint
metadata on stderr. Standalone Control composition now projects catalogs from
the installation descriptor-snapshot store and mints opaque Gateway endpoint
identities at bind (live loopback recorded by the composition route table).
The A3 exit gate stays open until the independent
Rust/TypeScript/Python client recovery matrix lands against this product
endpoint. First evidence:
independent_rust_client_discovers_control_published_gateway_without_shared_package_fs
proves an independent Rust Streamable HTTP client can discover Control-published
catalog resources through production_gateway_invocation_provider without a
shared package filesystem;
independent_rust_client_is_denied_with_wrong_gateway_token proves bearer
auth fails closed for that same Control-backed endpoint;
independent_rust_client_invokes_tool_task_under_committed_control_grant
proves the same independent client can call_tool a Tool Task under a
committed Control Grant after production admit+drain publishes the exact
Runtime plan/receipt and Grant-scoped Tool catalog (FakeRuntime
test-runtime provider);
independent_rust_client_invokes_grant_tool_after_control_process_restart
proves the same call_tool path still succeeds after dropping the admitting
lifecycle and reopening ProductionControlLifecycle over the durable Control
root (process-restart stand-in);
independent_rust_client_grant_tool_denied_for_foreign_installation_scope
proves a peer Workspace installation with its own Control root cannot observe
or serve the Grant Tool publication, while the original scope remains
invokeable;
independent_rust_client_grant_tool_fails_closed_after_uninstall
proves Uninstall retires committed Grants and Grant Tool discovery (empty
tools list or no published Gateway);
independent_rust_client_invokes_grant_tool_after_live_upgrade
proves a real v2 package Replace under Grant + Runtime plan republication
advances the capability generation and keeps independent call_tool working;
independent_rust_client_grant_tool_prior_generation_drains_on_live_upgrade
proves the gen1 Gateway session must release package-generation leases
before Upgrade Remove/Prepare can drain, after which the replacement
publication key differs and independent invoke succeeds on the new catalog;
independent_typescript_client_invokes_tool_task_under_committed_control_grant
proves an official @modelcontextprotocol/sdk Node client can
list_tools/call_tool convert against the same Control-backed Streamable
HTTP endpoint with only URL + bearer token (no shared package FS);
independent_python_client_invokes_tool_task_under_committed_control_grant
proves the official Python mcp Streamable HTTP client can do the same.
Client scripts live under tests/independent_clients/{ts,python}/. The A3
independent-client discovery/invoke language matrix for Tool Task under Grant
is now closed for Rust, TypeScript, and Python. Grant Tool cutover now admits
agent-visible Tools only through ControlCapabilityDescriptorProjection
(schema digests + Runtime release-descriptor attestation), and publishes a
signed v2 descriptor snapshot whose envelopes reverify under the fixture trust
store (grant_tool_publishes_signed_schema_bearing_descriptor_snapshot,
strict/install/upgrade/uninstall/restart/cross-scope Grant Tool tests). Control
Index cutover now also proves independent-client list_changed after
reconcile_published_capability_gateway replaces a live session
(control_cutover_reconcile_notifies_independent_client_list_changed). Remaining
A3 checkboxes are non-client items (CLI/service authorization beyond the
Gateway HTTP safeguards and signed-Tool Grant production cutover against live
Code/managed hosts that inject real Runtime readiness). Registry/TUF
key-source binding, Flow/UI/Knowledge projection, the Gateway
--registry-name signed-trust Control open path, and product HTTP Gateway
reconcile+drain-on-shutdown are closed on evidence.
ProductionControlLifecycle::reconcile_published_capability_gateway exposes
the composition reconcile seam for long-lived hosts after cutover
(production_gateway_reconcile_is_unchanged_for_the_current_grant_tool_publication).
Hosts must still release prior-generation Gateway leases before Upgrade
Remove/Prepare can drain, then reconcile so clients observe list_changed.
Product face now exposes
ProductionControlLifecycle::gateway_cutover_activation and
drain_and_retain_published_capability_gateway so long-lived hosts attach the
composition cutover hook without reaching into the private composition module.
open_control_lifecycle_with_host_ports accepts an injected
ControlRuntimeServiceReadinessPort so managed hosts bind real Runtime Service
endpoints instead of opaque gateway: placeholders
(ProductionControlHostDependencies::with_injected_runtime_readiness).
ManagedCognitivePackageLifecycleFactory::with_control_runtime_readiness
carries that port into CognitivePackageManager::ensure_control; install /
upgrade / uninstall admit lifecycle.runtime_plan_publications() from the
managed RuntimeProviderSelection (empty for standalone/skill-only).
Product mcp serve gateway --streamable-http now uses
ProductionControlLifecycle::serve_published_capability_gateway_streamable_http,
which watches the durable published cursor, reconciles the retained session,
and drain+retains on shutdown
(production_retained_gateway_watch_reconciles_then_drains_on_shutdown).
Same-process graph hosts that retain a Gateway beside
PluginPackageGraphLifecycleCoordinator still attach
gateway_cutover_activation so reconcile runs before prior-generation drain.
The embedding-host face is now public:
ControlRuntimeServiceReadinessPort /
ControlRuntimeMcpReadiness re-exported from cognitive_package, plus
CognitivePackageManager::{ensure_control_for_registry,open_published_capability_gateway,gateway_cutover_activation,watch_and_reconcile_published_capability_gateway,drain_and_retain_published_capability_gateway,serve_published_capability_gateway_*}
(public_control_runtime_readiness_port_is_nameable_for_embedding_hosts,
public_cognitive_package_manager_gateway_face_after_grant_tool_install).
A3S CLI product join injects Control readiness when a private Gateway exists
(ControlGatewayReadinessPort,
code_factory_forwards_injected_control_runtime_readiness) and forwards the
managed RuntimeClientRegistry into Control open
(runtime_client_registry,
managed_factory_forwards_runtime_client_registry_to_control_open) so effect
drain reconnects host providers. Runtime Task invoke pins Control-selected
generations (RuntimeTaskDispatcher::invoke →
acquire_control_lifecycle_generation) and fail-closes legacy publication
authority. Published Capability Gateway hosts that retain
an MCP session beside publication still attach gateway_cutover_activation.
Engine fail-closes non-empty Runtime plan publications without Control
readiness (use.control_store.runtime_readiness_required,
managed_publications_without_control_readiness_fail_closed); opaque
gateway: minting remains skill/native-only. Plugin readiness is saga-only
documentation for the Control effect bind face.
Legacy RuntimeBindingStore / Knowledge / Flow ::new constructors that write
bindings/* compile only under #[cfg(test)].
The host can derive a Gateway catalog from one immutable
CapabilityRegistrySnapshot through
CapabilityRegistrySnapshot::capability_gateway_catalog. The bounded
projection rechecks the snapshot cursor and public projection revision,
package and manifest digests, reviewed publication-record evidence, selected
surfaces, and ready/enabled package binding before constructing the canonical
catalog. It accepts a consumer subset, but does not verify signatures or
resolve opaque references on behalf of the host.
CapabilityGatewayMcpServer::from_registry_snapshot acquires the
matching RAII snapshot lease only after that projection and returns no server
when the publication changes or is already draining. This closes the
snapshot-to-catalog composition gap without claiming the remaining live
resolver, receipt-owned provider, or multi-principal production wiring.
The verified live-host composition boundary is now explicit as well:
CapabilityGatewayMcpServer::from_verified_registry_snapshot_with_factory_and_options
observes one snapshot, consumes host-verified description proofs, captures the
same cursor in CapabilityGatewayRegistryResolver, acquires the exact server
lease, and retains consumer negotiation plus bounded admission policy. A
publication race returns no server. The injected factory still owns receipt,
Runtime, Grant, principal, and scope authorization, so the overall A3 exit gate
remains open.
Implementation note (2026-09-04): the typed
CapabilityConsumerProfile/CapabilityConsumerNegotiation contract now
distinguishes the default generic-mcp consumer from an explicit a3s
consumer. Extension requests are canonical, sorted, bounded, and digest-bound;
fail closed when the host cannot support the complete requested set. The
embedding Gateway retains the completed negotiation across its clones and
leased constructors; legacy constructors remain generic-MCP by default.
Descriptors can now carry a canonical requiredExtensions set, and every
Gateway constructor projects the immutable catalog against the completed
negotiation before compiling discovery or invocation routes. This closes the
generic-consumer information-leak path. Path-free
CapabilityDescriptorKind::{Flow,Knowledge,Ui} payloads are projected through
the same negotiation filter and exposed via
extension_metadata_descriptors() without becoming MCP Tool routes. A3
product CLI/service wiring and the signed-Tool Registry→Control open path are
closed on evidence (ensure_control_for_registry /
mcp serve gateway --registry-name, fail-closed Manager confirmation, and
production_gateway_invocation_provider Grant/Runtime join).
Implementation note (2026-09-04): the standard MCP projection now includes catalog-authorized Resources and Prompts in addition to Tools. Resource references are opaque, exact-match checked, and never interpreted as paths or URLs; prompt arguments are closed against the reviewed declaration; every standard discovery list is deterministic, bounded, and cursor-paginated; and provider output is validated before it crosses the agent boundary. This does not yet project A3S-specific Flow/UI/Knowledge metadata or principal-specific discovery policy.
Implementation note (2026-09-07): Gateway discovery cursors now bind the MCP
surface, negotiated catalog digest, frozen principal visibility indices, and
offset in an opaque bounded v2 token. A client that misses a standard
list_changed notification cannot apply an old offset to a replacement
catalog; the request receives a stale-cursor error and can restart discovery.
The session factory also treats a changed discovery-policy snapshot as a view
cutover and emits list_changed, ensuring initialized clients are prompted to
restart before they encounter that stale-cursor boundary.
Implementation note (2026-09-04): Gateway catalog projection now evaluates
descriptor requiredExtensions against the immutable consumer negotiation.
Unaccepted descriptors are removed before MCP route compilation, so they are
absent from both list responses and direct lookup. Tool discovery is explicitly
sorted because the underlying router uses a hash map; cursors therefore cannot
silently reorder or skip capabilities between pages.
Implementation note (2026-09-04): the Gateway now exposes an explicit
CapabilityGatewayDiscoveryPolicy seam for host-authenticated principal
filtering. Policy decisions are evaluated once per trusted context and cached
in a bounded OnceCell view shared by server clones, so tools/list,
resources/list, prompts/list, and direct Tool/Resource/Prompt requests use
the same stable visibility set. Denied routes behave like unpublished routes;
policy errors are sanitized and fail closed, while the provider's per-call
principal/Grant/generation authorization remains mandatory. Existing
constructors retain an allow-all compatibility default, so production
multi-principal hosts must opt in explicitly.
Implementation note (2026-09-04): the standard MCP adapter now consumes rmcp's
per-request cancellation token. Tool, Resource, and Prompt provider futures
are selected against RequestContext.ct; a cancellation drops the in-flight
future before the adapter can validate or publish a result, releasing the
short-lived admission permit and any resolver-owned invocation lease. The
adapter returns the bounded use.plugin.capability_gateway_cancelled result
when a response remains deliverable, while the server-wide snapshot lease is
left available to other requests. Integration tests exercise real rmcp
notifications/cancelled traffic for all three operation classes.
Implementation note (2026-09-05): Extension Registry watches now follow the
atomic registry.json publication through a bounded cross-platform filesystem
subscription instead of a fixed 50 ms read loop. Native notifications are
preferred, with a bounded target-metadata probe running alongside them to cover
platform backends that coalesce or omit an atomic replacement; an explicit
metadata-only polling backend is retained when the native backend cannot be
registered. Callback events are target-filtered and coalesced to one signal,
and every wake-up re-reads the validated publication.
CapabilityRegistry::wait_for_change no longer rebuilds, scans, and hashes the
complete capability projection every 100 ms; it projects at subscription
setup, after a real generation advance, and once at timeout to close the final
race. The Gateway now exposes a bounded host-owned notification hub that
registers initialized MCP peers, advertises all three standard
list_changed capabilities, coalesces exact publication keys while rejecting
older generations, and retires closed or back-pressured peers without
introducing a private wire method. The hub is
deliberately separate from catalog/session replacement: a host must durably
publish the new immutable catalog, route new sessions to it, and retain old
leases through drain. The roadmap item remains open until the complete
agent-facing catalog is materialized into the lifecycle Capability Index and
product hosts connect that cutover to the hub.
Implementation note (2026-09-05): CapabilityGatewayCatalogStore now gives
the embedding host a durable owner for the exact Agent-facing catalog payload.
It validates the installation scope and canonical bytes, stores bounded
SHA-256-addressed records behind a cross-process mutation lock, uses
no-follow checks plus deterministic staging and create-if-absent hard-link
publication, and supports exact generation/revision reads after restart.
Malformed top-level state, linked entries, tampered records, and over-bound
inventories fail closed; incomplete regular staging artifacts can be replayed
under the same digest. The store deliberately has no mutable current pointer,
so payload durability alone does not select a live generation. The inactive
Control composition now supplies the transactional binding described below
and a restart-safe path to seed or replace a live Gateway session from its
durable cursor; production activation, owner registration, lease drain, and
retention remain required before the A3 catalog gate can close.
Implementation note (2026-09-05): CapabilityGatewaySessionFactory now gives
an embedding host a bounded live-endpoint cutover seam. It serializes
replacement of immutable servers, rejects cross-installation and stale
publication generations, keeps consumer negotiation and lease mode stable, and
routes each MCP operation through a current-server snapshot. A replacement is
made visible before the shared standard list-change fan-out; old in-flight
operations retain their prior immutable server and lease, while subsequent
operations on the same endpoint observe the new catalog. This is an adapter
mechanism, not the lifecycle authority: production Control activation,
receipt-owned provider composition, lease retirement, and catalog-retention
coordination remain open.
Implementation note (2026-09-05): the session factory now also offers
from_published and replace_published. These paths read the exact
installation/generation/revision/digest from CapabilityGatewayCatalogStore,
re-project it for the server's completed consumer negotiation, and reject a
missing, forged, tampered, or unpersisted catalog before the in-memory swap.
The check covers the complete source catalog as well as its negotiated view,
and replacement uses a conditional source swap so a concurrent local cutover
cannot be overwritten after verification.
The unverified compatibility method remains available for hosts with another
persistence authority; selecting the Control-bound publication and retiring
payload leases remain lifecycle responsibilities.
Implementation note (2026-09-06): Gateway session identity now follows the complete immutable source publication retained before consumer negotiation. Optional descriptor filtering therefore changes only the visible MCP view; Control lease matching, reconciliation, and drain continue to bind the full published cursor. Control projection validation also requires every retained descriptor to equal an exact descriptor in that publication, rather than checking package digests alone.
Implementation note (2026-09-05): catalog payload retention now has an explicit plan/apply protocol. The lifecycle owner supplies the protected digest set; the store emits a canonical inventory partition, rechecks the exact plan under its mutation lock, verifies each regular record before removal, fsyncs the affected shard, and supports read-only terminal replay. The store refuses an empty protection set for a non-empty inventory and never infers liveness from a mutable pointer. Control cursor and session-lease coordination remain the authority that chooses the protected set.
Implementation note (2026-09-05): retention apply now persists a bounded,
canonical append-only recovery journal before each destructive unlink. It
repairs a torn final record, reconciles an in-flight unlink against the
immutable inventory after restart, blocks conflicting publication/planning,
and exposes CapabilityGatewayCatalogStore::recover_retention so a host can
resume from the journal's stored reviewed plan. This hardens the payload-owner
recovery boundary; it does not choose the protected generations or close the
session-lease lifecycle gate.
Implementation note (2026-09-05): inactive Control Store schema v11 now binds the immutable Agent-facing catalog to the actual capability publication transaction. A host-owned projection port receives only the committed candidate generation and terminal surface observations. The concrete Capability Plane rejects descriptors outside enabled, prepared package incarnations, durably publishes the catalog and canonical Capability Index, and returns their identities as one typed cutover application. Recording that applied observation stores the catalog digest/generation/revision and advances the published cursor in the same SQLite transaction. Admission reopens and rehashes the exact payload before taking package-generation leases; missing or tampered bytes fail closed. This closes the inactive-kernel cursor-binding mechanism, not production activation, complete receipt/Runtime/Grant-backed descriptor projection, production payload-owner restore/retention activation, or session drain coordination.
Implementation note (2026-09-05): the inactive Capability Plane now also has
an explicit descriptor-evidence projector. It accepts only host-verified
CapabilityDescriptionProof values and an immutable package-scoped signer
allowlist. Every supplied descriptor is checked against the committed enabled
package and lifecycle incarnation, exact catalog-record provenance, selected
surface dependency graph, terminal prepared owner receipt, active Grant
coverage, and reviewed Tool/MCP workload or transport before the projector
derives domain-separated opaque invocation, endpoint, artifact, and resource
references. Optional degraded surfaces and substituted owner evidence remain
unpublishable, and projection failures are safe deterministic rejections with
no payload write. This was a strict subset gate at the time of that projector
change; cryptographic key custody, a durable cryptographic snapshot, production
Runtime payload admission/receipt wiring, and production Control/Runtime/
receipt wiring remained open before the complete A3 catalog exit gate could
close.
Implementation note (2026-09-05): the descriptor evidence boundary now has an installation-owned durable snapshot store for crash and restart replay. It captures the exact normalized proof set and package-scoped signer policy under a key bound to the installation, installation generation, capability generation, and candidate Control descriptor digest. The record itself is content-addressed by its canonical bytes, with bounded no-follow staging, create-if-absent publication, cross-process locking, exact canonical/digest revalidation, and no mutable current pointer. A durable projector reads only the exact Control-bound key; absent evidence defers safely, while substitution, tampering, duplicate keys, and unknown layout fail closed. The coordinated state inventory now recognizes and semantically verifies its canonical descriptor-snapshot records alongside Gateway catalogs; locks, staging, and retention journals remain nonterminal. The store is still an inactive external payload owner: key custody, production owner-native restore/retention activation, and Control/Runtime/receipt wiring remain open. Runtime Tool release planning now carries a canonical input/output-schema attestation through plans, binding receipts, and Control evidence; verified artifact admission and strict descriptor projection compare the same descriptor and schema digests. The implementation is qualified in the inactive kernel, while production lifecycle activation remains open. The signed v2 admission path described below now makes the retained envelope, rather than the proof projection, the cryptographic replay authority.
Implementation note (2026-09-05): the signed-description trust boundary now
has a canonical SignedCapabilityDescription envelope in a3s-use-core and
an Ed25519 CapabilityDescriptionTrustStore in a3s-use-extension. The
envelope domain-separates the exact descriptor bytes, key/signer identities,
and bounded validity window. The verifier owns no private keys, rejects
identity, expiry, revocation, canonical-byte, and signature mismatches, and
returns a private replay wrapper that must be reverified after restart. Multiple
keys for one signer are supported for rotation, and schema-bearing Runtime
Tool descriptors are required. The root Gateway facade now has signed-
description constructors that verify envelopes before snapshot lease and
provider-resolver composition; the legacy proof constructors remain only for
explicit preview hosts. This qualifies the cryptographic mechanism and its
composition seam but does not mark the A3 checkbox: Registry/TUF key-source
binding and production Registry-to-Control lifecycle wiring remain open.
Implementation note (2026-09-05): the Control descriptor snapshot owner now
has a signed v2 admission path. publish_signed verifies every canonical
Ed25519 envelope before content-addressed publication and stores the exact
envelopes beside a derived proof projection. A signed projector re-verifies
those envelopes against the current trust store and clock on every replay;
expiry, revocation, substitution, and proof/envelope mismatch fail closed. The
legacy v1 proof-only snapshot remains an explicit compatibility path and is
not allowed to consume a signed v2 record. This closes the Control
proof-snapshot admission mechanism in the inactive kernel; official
Registry/TUF key-source binding, production owner-native restore activation,
and Registry-to-Control/Runtime/receipt wiring remain release gates. The
paired owner-retention coordinator is qualified below, but lifecycle-selected
retention policy is still a production authority gate.
Implementation note (2026-09-05): coordinated state backup now has an explicit
CapabilityPayloads family for the two immutable Capability Gateway owners.
The scanner admits only the catalog shard and descriptor-snapshot record
layouts, verifies installation binding, canonical bytes, and content-addressed
digests during inventory and archive verification, and rejects unknown paths,
staging residue, mutation locks, and retention journals. This is a qualified
legacy inventory/restore-plan boundary, not the A2 owner-registry cutover:
production clean-target activation, lifecycle owner retention policy, and
current Registry/TUF trust revalidation on signed replay remain required.
Implementation note (2026-09-05): Artifact Reachability now traverses the same Capability Gateway payload-owner tree instead of silently ignoring the new root. Catalog and descriptor-snapshot records are revalidated against their installation and content address; unknown nested paths, links, staging residue, and retention journals fail closed before a garbage-collection view is returned. The scanner intentionally emits no Artifact Store references for these opaque projections; lifecycle receipts remain the artifact authority.
Implementation note (2026-09-06): the Control descriptor-snapshot owner now
supports the same explicit retention contract as the Gateway catalog owner.
plan_retention names the protected digest set and the complete removal
complement; apply_retention binds the canonical plan digest, rechecks every
record under the owner lock, and persists one bounded checkpoint per unlink.
recover_retention resumes the embedded plan after a process interruption,
repairs only a torn journal tail, and blocks publication or inspection while
the journal is pending. The non-empty inventory invariant prevents an empty
protection set from deleting every snapshot. Production Control owner
registration, clean-target restore activation, and Registry/TUF policy wiring
remain separate gates. ControlCapabilityPayloadRetentionCoordinator now
joins this owner with the Gateway catalog: it binds both child plans to one
canonical digest, preflights both inventories and exact pending journals under
one exclusive maintenance fence, and resumes catalog-then-descriptor deletion
after an interruption. The coordinator is recoverable ordered deletion, not a
cross-directory atomic transaction; lifecycle retention policy and production
owner registration remain outside it.
The coordinator now also persists a bounded canonical
a3s.use.control-capability-payload-retention-journal.v1 before the first
unlink and checkpoints catalog completion before advancing to descriptor
snapshots. A restart can reopen the exact reviewed pair; ordinary owner
publication/reads, clean restore, state backup, and artifact reachability are
blocked until that journal is recovered and retired. This is durable ordered
convergence rather than a cross-directory atomic transaction, so lifecycle
retention policy and production owner registration remain release gates.
Implementation note (2026-09-06): CapabilityGatewayCatalogStore now also
exposes an owner-native clean-target restore boundary. A reviewed plan binds
the installation, canonical byte counts, and the complete digest-sorted
inventory; apply re-derives every supplied catalog, stages and rescans a full
candidate tree, persists a plan-bound activation marker, and publishes with a
no-clobber directory move. Existing owner state is never merged or replaced,
foreign staged plans are rejected, and a durable candidate/marker can be
replayed after interruption. This closes the catalog half of the restore
primitive, but descriptor-snapshot restore, Control owner registration,
signed replay policy, session drain, and production rollback coordination
remain release gates.
Implementation note (2026-09-06): the Control descriptor-snapshot owner now has a matching plan-bound clean-target restore adapter. The reviewed inventory binds snapshot and key digests, Control generation identity, canonical byte counts, and signed/proof-only mode. Apply re-derives every snapshot, requires current trust-store verification for signed v2 evidence, stages and rescans a complete candidate, persists a plan-bound activation marker, and publishes without clobbering an existing owner. Durable candidate/marker evidence is replayable after interruption, while foreign staged plans and retention journals fail closed. The remaining gate is production Gateway reconstruction from the reopened Control lease and Registry/TUF-to-owner authority, not another local payload writer.
Implementation note (2026-09-06): the two immutable Capability owners now have
one ControlCapabilityPayloadRestoreCoordinator. Its canonical plan binds the
catalog and descriptor child digests, validates both source sets (including
signed trust re-verification) and both clean targets before the first payload
publication,
and holds one installation-wide exclusive maintenance fence through fixed
catalog-then-descriptor activation. A stop between owner boundaries is
recoverable by replaying the same plan; the coordinator intentionally makes no
cross-directory atomicity claim. Live Gateway session reconstruction, lease
drain, lifecycle retention policy, and Registry/TUF authority binding remain
open.
Implementation note (2026-09-06): the inactive Control composition can now reopen its published Capability generation directly from durable Control authority after a restart. The caller supplies no cursor. The Capability Plane reads the committed cursor, verifies the exact immutable Index and catalog, acquires every bound package-generation lease in canonical order, then rereads the Control cursor so a concurrent cutover returns stale rather than exposing a mixed graph. The composition now uses that lease as an internal Gateway generation guard, so every cloned server retains it and the session factory cannot replace a leased endpoint with an unleased server. Production live Control activation, owner registration, lease drain, lifecycle retention policy, and Registry/TUF authority binding remain open.
Implementation note (2026-09-06): graph lifecycle now exposes the
replay-safe PluginGraphCapabilityCutoverActivation hook. It is invoked after
the durable capability publish (or its exact replay) and before any prior
generation drain. The inactive Control composition supplies a concrete
adapter that reopens the Control cursor, requires an external Control lease on
the live factory, rejects a newer in-memory endpoint, and treats an identical
catalog as an idempotent no-op. The inactive composition now also derives the
durable current catalog/descriptor protection set for retention and applies a
reviewed plan only after rechecking the cursor under an exclusive maintenance
fence. Production hosts still need to attach this adapter, add any
independently managed rollback identities, and retire payloads in one host
transition.
The adapter now binds the callback's opaque key to the reviewed operation that owns the published cursor (following that cursor's installation generation, not the merely current generation). Stale graph replays and callbacks against enablement-only publications therefore fail closed instead of activating an unrelated endpoint.
Implementation note (2026-09-06): the inactive Control composition now also provides a Control-backed opaque invocation resolver. Each operation reopens the durable published cursor, validates the complete descriptor against the immutable catalog before provider state is opened, and retains that exact Control generation lease through the returned invocation handle. A host-owned factory receives the lease for its principal/Grant/Runtime binding; forged or cross-generation descriptors fail before provider I/O. Production lifecycle wiring and legacy-authority deletion remain open as cutover follow-ups; the Control-backed invocation resolver and product Gateway join are closed.
Implementation note (2026-09-06): destructive Capability payload retention now
has one cursor-bound composition path. It always protects the catalog selected
by the durable Control cursor and, when descriptor snapshots are present, the
key-matched proof snapshot; a cursor change or plan that would remove either
payload is rejected before unlink. Both standalone owner apply_retention
entries also take the installation-wide exclusive maintenance fence, so a
live Control snapshot/Gateway lease cannot be bypassed. Hosts may add explicit
rollback or legacy endpoint digests, but liveness is never inferred from an
in-memory current pointer.
Implementation note (2026-09-06): CapabilityGatewaySessionFactory::drain
now provides an explicit endpoint-retirement boundary. It serializes with
replacement, closes admission for every live adapter clone, waits for already
admitted operations under a caller deadline, and detaches the source
generation lease only after the operation count reaches zero. A timed-out
attempt remains non-admitting and can be resumed; independent immutable server
clones retain their own leases until dropped. Lifecycle hosts can therefore
call drain before entering the exclusive Capability payload retention fence;
the inactive Control composition provides one helper that performs that
drain-and-retain sequence against its durable cursor.
Implementation note (2026-09-06): the Control composition now reads the published capability cursor and its owning operation from one SQLite snapshot, then reacquires the exact cursor before constructing or swapping a Gateway endpoint. Destructive drain-and-retain additionally requires the supplied session's catalog identity and Control-issued external lease to match that cursor; copied catalogs, unrelated leases, and cursor changes during drain fail closed before payload unlink. This closes the remaining in-process session identity/TOCTOU gap, while production host wiring and independent rollback authority remain release gates.
Implementation note (2026-09-06): the live session boundary now retains a one-shot, typed identity proof when a Control-bound endpoint finishes draining. An exact lifecycle retry can therefore repeat drain-and-retain after the source lease has been detached, while a directly drained or copied unleased server cannot manufacture that proof. Replacements built from a stale local snapshot also use a conditional source compare-and-swap; if another cutover wins, the attempt returns a retry signal instead of overwriting the newer same-generation projection. These are local convergence mechanisms; production Control publication and rollback authorities still have to coordinate the durable cross-process transition.
Implementation note (2026-09-04): Runtime Task publication and dispatch now cross-bind each durable receipt to the installed package's retained planning evidence and exact release descriptor digest. Registry-trusted packages must retain catalog-bound signed planning evidence; substituted descriptors, cross-generation bindings, and missing evidence are omitted or rejected before provider connection. Local explicit packages retain their host-owned qualification path. This closes a Runtime integrity gap but does not complete the broader A3 receipt/Runtime/Grant authorization or independent-client exit gate.
Implementation note (2026-09-03): PR #197
added a secret-free error projection at the Package Manager MCP boundary. The
adapter retains only validated use.* contract codes and a bounded public
message; paths, URLs, suggestions, details, provider-owned identifiers, and
package-authored diagnostics are omitted or collapsed to a generic code. This
is defense-in-depth for the existing adapter, not an A3 exit-gate claim. The
Gateway HTTP edge now adds endpoint bearer authentication and bounded
admission, and the injected provider exposes a sanitized pre-invocation
authorization seam; the HTTP for_principal/for_principals configuration now
carries the selected verified principal into both provider hooks without
exposing it to agents. PR #208 adds
the lease-scoped resolver and bounded multi-principal mapping. Production host
receipt/Runtime/Grant composition, product Gateway/Manager wiring, and the
independent-client recovery matrix are closed on the A3 evidence above; A5
Registry custody/publication and A4 provider inversion remain separate exit
gates.
The embedding seam is now explicit: PR #208
adds CapabilityGatewayInvocationResolver and
CapabilityGatewayResolvedProvider, which perform one resolution and
authorization for each call before invoking a private lease. The handle
implementation owns the exact package-generation guard and must retain it
until the invocation returns. The same PR adds a bounded 64-entry immutable
HTTP token-to-principal registry with duplicate-token rejection and complete
credential scans. Production composition now joins those host embedding
contracts to Control Grant + Runtime receipt authority through
production_gateway_invocation_provider(), product CLI Gateway serve, and the
independent Rust/TypeScript/Python client matrix under committed Control Grants.
Exit gate: an arbitrary MCP-capable coding agent can discover and invoke an authorized package without an A3S SDK, local package path, or duplicated lifecycle implementation. Closed on evidence (A3 checkboxes above, including independent-client discovery/invoke and product Gateway/Manager serve paths).
- Make the Use Engine own lifecycle coordination, journaling, retries, and
recovery. Factories inject a typed
ProviderSetor lifecycle ports; they do not construct and return concrete coordinators. Closed on evidence:LifecycleProviderSetcarries journal +PluginLifecycleHosts; factory methods are*_providersreturning that set;LifecycleProviderSet::into_coordinatoris the engine-owned construction path (factories_inject_provider_sets_without_constructing_coordinators,managed_factory_uses_the_embedding_hosts_ui_composition). - Negotiate the actual supported operations, surfaces, protocol versions,
concurrency guarantees, and provider readiness. Remove default trait methods
that make unsupported behavior appear supported. Closed on evidence:
CognitiveLifecycleSupportis required onCognitivePackageLifecycleFactory; planning/retirement/enablement andflow_compiler_binaryno longer have default bodies that fake support; Standalone vs Managed declare distinct surface sets (lifecycle_factories_declare_supported_surfaces_without_default_trait_fiction). - Treat Browser, OCR, Box, Runtime, Flow, and UI integrations as provider
components or ordinary first-party packages. A bundled profile may install
them for convenience, but the universal engine and capability projection do
not hardcode their domains. Closed on evidence:
CapabilityRegistry::snapshotonly projectsCapabilitySeedProviderseeds; bareCapabilityRegistry::newusesEmptyCapabilitySeedsand publishes nouse/browser|ocr|box(universal_engine_registry_projects_no_hardcoded_first_party_domains); standalone productfrom_envinjectsBundledFirstPartyCapabilitySeeds(bundled_product_profile_projects_browser_ocr_box_as_injected_seeds). Runtime/Flow/UI remain host-injected lifecycle ports. - Split the current all-purpose capability binding into consumer catalog,
invocation binding, and operation diagnostic views so management evidence
and local provider details cannot leak into agent discovery. Closed on
evidence: agent discovery uses
CapabilityGatewayCatalog/CapabilityGatewayMcpServer; invocation usesCapabilityGatewayInvocationProvider/CapabilityGatewayResolvedProviderwith generation leases; management diagnostics stay on Package Manager / Host observation paths with secret-free projection (adapter_sanitizes_provider_errors_at_the_agent_boundary, Package Manager MCP error sanitization). - Keep A3S Flow and UI as negotiated consumer extensions over the same
package generation; do not make A3S-specific surfaces mandatory for generic
agents. Closed on A3 evidence:
CapabilityDescriptorKind::{Flow,Knowledge,Ui}plusgateway_projects_flow_ui_knowledge_metadata_only_for_negotiated_extensions. - Refactor along the target boundaries before creating more repositories:
contracts, catalog/artifacts, control store, engine, host/gateway, and
provider adapters. Split oversized files when responsibility moves; do not
add forwarding facades or duplicate registries. Progress: first-party
Browser/OCR/Box projectors in
capability_registry/product_seeds.rs; Control-authority extension projection incapability_registry/extension_projection.rs; unit tests incapability_registry/registry_tests.rs. Facadecapability_registry.rsis under the ~1000-line split threshold with lease/mcp/runtime_tasks retained as sibling adapters (universal_engine_registry_projects_no_hardcoded_first_party_domains). Capability Gateway rootcapability_gateway.rsis now a thin public contract (~284 lines) withprotocol.rs,server/{mod,compose,handler}.rs, andsession_factory/{mod,live,helpers}.rssiblings (each under the ~800 line focus band); Control-native empty lease/composition/signed-admission tests are green (capability_gateway::53 passed). Control composition is nowcomposition/{mod,gateway}.rs(mod ~778 / gateway ~495;control_store::composition8 passed). Capability payload owner iscapability_payload/{mod,archive,filesystem,helpers}.rs(each under the hard 1000-line cap;payload_capability_payload5 passed). Runtime plan payload owner isruntime_plans/{mod,archive,filesystem,helpers}.rs(payload_runtime_plangreen). Control Store aggregate claim/observe/complete mutations live inaggregate/dispatch.rs(~446) with rootaggregate.rsunder the hard 1000-line cap (~855). Descriptor-snapshot store/restore are split via#[path]siblings (descriptor_snapshot_store.rs+descriptor_snapshot_store_io.rs; restore{helpers,layout,filesystem}.rs) — every non-test Control Store source file is now under the hard 1000-line cap (descriptor_snapshot12 passed). Cognitive-package production owners that were over the hard 1000-line cap are split without forwarding facades:plan_tests.rs/provider_plan_tests.rs/hosts_tests.rsvia#[path];host_store_io.rs,upgrade_apply.rs,diagnostic_queries.rs,diagnostic/validation_pending.rs, anddiagnostic/projection_lifecycle.rsviainclude!. The same hard cap is now held for every non-testcrates/use/src/**/*.rsproduction leaf by additional splits:plugin_runtime/plan_store_io.rs,plugin_lifecycle/{coordinator_execute, coordinator_helpers,graph_upgrade}.rs,okf_knowledge/recovery_validate.rs,capability_catalog_store/restore_prepare.rs, andcli_mcp.rs. Extension production leaves that were over the hard 1000-line cap are split the same way:registry_bindings.rs,remote_prepare.rs,surface_files_io.rs, andregistry/lifecycle_publish.rs(cargo check -p a3s-use-extension --libandcargo check -p a3s-use --libgreen). Evidence: no non-test production.rsundercrates/use/srcorcrates/use/crates/{core,extension}/srcexceeds 1000 lines (test modules such asregistry_tests/cognitive_lifecycle.rsremain). Remaining open A4 work: large test modules and crate-level boundary repository splits (contracts / catalog / engine / host-gateway / provider adapters as separate repos — not more file splits inside Use).
Exit gate: the core engine runs against deterministic in-memory providers, and each product host composes only the providers and consumer extensions it owns.
Decision: rename A3S-Lab/Use-Packages to A3S-Lab/Use-Registry before the
first production bootstrap root is created. The current repository already
contains admission material, registry/ TUF state, immutable targets, and
Registry verification; Use-Packages incorrectly suggests a package-source
monorepo. The pre-initialization rename avoids creating a second trusted source
identity later.
- Rename the GitHub repository and root submodule path to
use-registry/; update.gitmodules, remotes, documentation, tests, CI, and examples in one reviewed change. Do not compile the official URL into the resolver. Root evidence:.gitmodulespinsuse-registry→git@github.com:A3S-Lab/Use-Registry.git; monorepo README modules list Use Registry atuse-registry/. - Treat any preview configuration using the old address as an explicit
source replacement: re-add the renamed source with its pinned bootstrap-root
digest. Do not silently turn a GitHub redirect into trust authority.
Registry source identity remains name/URL/bootstrap-root digest; redirects
never become trust authority (
registry-cache-operations.md). - Keep package source, build logic, and releases out of
Use-Registry.Use-Registryaccepts reviewed admission records, immutable release artifacts, provenance, SBOMs, and signed TUF publication state. Enforced by README ownership boundary plusregistry-staging-gateownership-layoutrejectingpackages/,src/, andCargo.tomlin the Registry tree (docs/staging-ci.md). - Add package-authoring commands for lint, deterministic build/pack,
manifest and expanded-content digesting, permission review, provenance
verification, and isolated install tests. These formats and commands are
versioned by
a3s-use, not reimplemented by the Registry repository. Landed asa3s-use-registry-tools lint|pack|assemble|verifyovera3s_use_extension::lint_package_directory(ACL parse, README + surface file review, expanded fingerprint) plus deterministic pack and released- client verify (skill_package_lints_before_pack,lint_fails_closed_when_skill_file_is_missing). Isolated install against a live Control installation remains a product CLI/Host matrix item, not a second Registry-owned format. - Add Registry assembly and verification commands that preserve canonical
catalog metadata, validate the complete staged tree with a released client,
and produce a reviewable publication delta before signing. Landed as
crates/registry-tools(a3s-use-registry-toolskeygen/pack/assemble/verify) on Use main via #256. Threshold custody, rotation, expiry, mirrors, and withdrawal are exercised in-tree; official production bootstrap publication remains on the production channel checkbox. - Document and exercise offline threshold root custody, online
snapshot/timestamp custody, expiry monitoring, every-intermediate-root
rotation, emergency withdrawal, mirror replacement, and rollback recovery.
Operator documentation for keygen/assemble/verify custody, threshold root
ceremony (
--root-share-count/--root-threshold), offline recovery,rotate-root(retainmetadata/root.history/, require new bootstrap pin),check-expiry,compare-mirrors, andwithdraw-targetsis indocs/registry-key-custody.md. Exercised in registry-tools: single-operator offline assemble/verify + pin-stable recovery (offline_custody_recovery_rebuilds_the_same_bootstrap_pin); 2-of-3 threshold ceremony + under-threshold fail-closed (threshold_root_ceremony_assembles_and_verifies_with_two_of_three_shares,threshold_assemble_fails_closed_when_too_few_root_shares_are_present); every-intermediate-root rotation + mismatched-custody fail-closed (root_rotation_retains_the_previous_root_and_requires_a_new_bootstrap_pin,root_rotation_fails_closed_when_previous_keys_do_not_match_published_root); expiry monitoring (check-expiry) with near-expiry fail-closed (check_expiry_passes_for_a_freshly_assembled_registry,check_expiry_fails_closed_when_metadata_expires_inside_the_warn_window); mirror compare (compare-mirrors) with drift fail-closed (compare_mirrors_accepts_identical_trees_and_rejects_drift); emergency withdrawal (withdraw-targets) keeps the bootstrap pin, removes target bytes, and verifies an empty catalog (withdraw_targets_removes_a_package_while_keeping_the_bootstrap_pin). Multi-signer TUF targets-role delegation is deferred until Use-Registry admits independently signed package authorities; GA custody uses one online targets key outside the git tree. Production bootstrap publication and live mirror promotion remain on the production channel checkbox below. - Publish a staging channel through reviewed GitHub CI with no signing key
in the repository or package-manager client. Staging gate in Use-Registry
(
.github/workflows/registry-staging-gate.yml,docs/staging-ci.md) fail-closes on keys-in-tree / ownership bleed and, when admissions +REGISTRY_TOOLS_REF+REGISTRY_STAGING_KEYS_DIRare present, runs realassemble+verify+check-expirywith environment-injected keys (no trust-root push). - Publish the production channel through reviewed GitHub CI with no signing
key in the repository or package-manager client. Retain witness, provenance,
SBOM, and prior-generation recovery evidence outside the mutable delivery
boundary. Offline ceremony checklist:
Use-Registry
docs/production-bootstrap.md. Progress: Use-Registry now carriesregistry-production-gate.yml+docs/production-ci.mdthat fail-close keys-in-tree / package-source bleed / in-gitregistry/, and arm assemble+verify+expiry only foradmissions/production*.aclwith environment-injectedREGISTRY_PRODUCTION_KEYS_DIR(never pushes a trust root). Live signed publication, witness retention, and production mirror promotion remain open. - Keep MHS adapter source in an owning external repository (linked as
crates/mhsonly when that ownership exists) and publish only its signed package artifacts and admission records throughUse-Registry. Progress: research-preview contract fixture lives undercrates/extension/fixtures/packages/plugin-v3-mhs-bridgewith profiledocs/mhs-integration.md.crates/mhsis intentionally absent until an owning MHS adapter repository exists; do not invent a Use-owned hardware crate. Admission through Use-Registry remains blocked on that external ownership plus production Registry operation. - Express MHS through existing MCP, Flow, Skill, Knowledge, and optional UI
surfaces. Do not add a hardware-specific package surface or private protocol.
Closed on evidence: the research-preview fixture and catalog contracts reuse
only standard surfaces (
docs/mhs-integration.mdTest scope); extension-crate MHS profile tests are green (cargo test -p a3s-use-extension --lib mhs→ 2 passed). Full A6 lab qualification remains on the virtual-laboratory checkbox below. - Keep the virtual industrial laboratory in its own repository. Its
simulator connects through the same MHS control-gateway contract used by
physical adapters and is test infrastructure, not Use runtime code.
Exit criteria for that external lab are listed under
docs/mhs-integration.md(Enterprise GA / A6 exit). - Model read operations as safe observations and physical mutations as
explicitly authorized operations with idempotency evidence or an
unknown-outcomestate. Never retry an ambiguous device mutation implicitly. Progress: research-previewflows/monitor.tsschedules observation withretry: { max_attempts: 1 }and the fixture test asserts that contract (mhs_bridge_fixture_is_a_bounded_standard_surface_package). Physical mutation / unknown-outcome reconciliation still requires the external virtual laboratory. - Prove least-authority Grants, gateway health, dependency publication, exact-generation lease/drain, reconnect, and reconciliation against the virtual laboratory before enabling any physical adapter profile.
- Run the same signed package from a generic MCP client and A3S Code: install, discover, observe, invoke a simulated mutation, interrupt/reconcile, upgrade without mixed generations, uninstall, and verify no Registry bindings, Gateway routes, Grants, processes, or projections remain.
- Keep the adapter labeled research preview until the external MHS profile is stable and the package passes its published conformance and hardware safety-gateway requirements.
Exit gate: MHS demonstrates the complete Registry-to-agent capability path in the separate virtual laboratory without granting Use direct physical-device authority.
The protocol table below describes the currently implemented preview. A2 and A3 will intentionally supersede affected contracts in one coordinated cutover; version numbers are assigned only after their invariants and negative fixtures are frozen.
| Contract | Accepted version |
|---|---|
| Cognitive-package manifest | schema version 3 |
| Signed catalog record | a3s.use.plugin-catalog.v3 |
| Installed receipt | schema version 6 |
| Package lock | a3s.use.plugin-package-lock.v1 |
| Installation snapshot | a3s.use.installation-snapshot.v2 |
| Operation plan | a3s.use.plugin-operation-plan.v4 |
| Host capabilities | a3s.use.plugin-host-capabilities.v6, protocol 6 |
| Host managed scope | a3s.use.plugin-managed-scope.v2 |
| Host operation observation | a3s.use.plugin-host-operation-observation-request/result.v1 |
| Host operation watch | a3s.use.plugin-host-operation-watch-request.v1 |
| Host cancellation | a3s.use.plugin-host-cancel-request/result.v1 |
| Manager MCP toolset | a3s.use.plugin-manager-tools.v5 (v4 migration contract remains readable) |
| Pending package graph | a3s.use.pending-package-graph-operation.v4 |
| Pre-lock resolution attempt | a3s.use.plugin-resolution-attempt.v1 |
| Pre-plan download attempt | a3s.use.plugin-download-attempt.v1 |
| Lifecycle diagnostic | a3s.use.plugin-lifecycle-diagnostic.v1 |
| Operation diagnostic | a3s.use.plugin-operation-diagnostic.v1 |
| Operation history | a3s.use.plugin-operation-history.v1 / a3s.use.plugin-operation-history-diagnostic.v1 |
| Pre-lock resolution diagnostic | a3s.use.plugin-resolution-attempt-diagnostic.v1 |
| Pre-plan download diagnostic | a3s.use.plugin-download-attempt-diagnostic.v1 |
| Enablement recovery projection | a3s.use.cognitive-package-enablement-projection.v3 |
| Enablement operation | a3s.use.cognitive-package-enablement-operation.v3 |
| Runtime Task binding | a3s.use.runtime-task-binding.v4 |
| Runtime Service provisioning | a3s.use.runtime-service-provisioning.v1 |
| Runtime Service binding | a3s.use.runtime-service-binding.v3 |
| Extension Registry snapshot | schema version 3 |
| Capability snapshot | schema version 5 |
| Capability descriptor | a3s.use.capability-descriptor.v1 |
| Control descriptor evidence snapshot | a3s.use.control-capability-descriptor-snapshot.v1 (proof-only compatibility) / v2 (signed envelope) |
| Capability Gateway catalog | a3s.use.capability-gateway-catalog.v1 |
| Capability Gateway catalog restore plan | a3s.use.capability-gateway-catalog-restore-plan.v1 |
| Capability Gateway catalog restore result | a3s.use.capability-gateway-catalog-restore-result.v1 |
| Capability Gateway catalog retention plan | a3s.use.capability-gateway-catalog-retention-plan.v1 |
| Capability Gateway catalog retention result | a3s.use.capability-gateway-catalog-retention-result.v1 |
| Capability Gateway catalog retention journal | a3s.use.capability-gateway-catalog-retention-journal.v1 (internal) |
| Control descriptor snapshot retention plan | a3s.use.control-capability-descriptor-snapshot-retention-plan.v1 |
| Control descriptor snapshot retention result | a3s.use.control-capability-descriptor-snapshot-retention-result.v1 |
| Control descriptor snapshot retention journal | a3s.use.control-capability-descriptor-snapshot-retention-journal.v1 (internal) |
| Control descriptor snapshot restore plan | a3s.use.control-capability-descriptor-snapshot-restore-plan.v1 |
| Control descriptor snapshot restore result | a3s.use.control-capability-descriptor-snapshot-restore-result.v1 |
| Capability consumer profile | a3s.use.capability-consumer-profile.v1 |
| Capability consumer negotiation | a3s.use.capability-consumer-negotiation.v1 |
| Capability snapshot cursor | a3s.use.capability-snapshot-cursor.v4 |
| Extension snapshot cursor | a3s.use.extension-snapshot-cursor.v3 |
| Coordinated Use state backup | a3s.use.state-backup.v2 |
| Coordinated Use state backup retention plan | a3s.use.state-backup-retention-plan.v2 |
| Coordinated Use state backup retention result | a3s.use.state-backup-retention-result.v2 |
| Coordinated Use state restore plan | a3s.use.state-restore-plan.v1 |
| Coordinated Use state restore operation | a3s.use.state-restore-operation.v1 |
| Coordinated Use state restore result | a3s.use.state-restore-result.v1 |
| Coordinated Use state restore diagnostic | a3s.use.state-restore-diagnostic.v1 |
| OKF Knowledge backup | a3s.use.okf-knowledge-backup.v1 |
| OKF Knowledge backup retention plan | a3s.use.okf-knowledge-backup-retention-plan.v1 |
| OKF Knowledge backup retention result | a3s.use.okf-knowledge-backup-retention-result.v1 |
| OKF Knowledge restore plan | a3s.use.okf-knowledge-restore-plan.v2 |
| OKF Knowledge restore operation | a3s.use.okf-knowledge-restore-operation.v2 |
| OKF Knowledge restore result | a3s.use.okf-knowledge-restore-result.v2 |
| OKF Knowledge restore diagnostic | a3s.use.okf-knowledge-restore-diagnostic.v2 |
Negative fixtures for superseded inputs remain only to prove fail-closed rejection. They are not supported decode paths.
- ACL manifest v3 with named Tool, MCP, OKF, Flow, Skill, and UI surfaces.
- Required bounded UTF-8
README.md, package path validation, archive bounds, shared Unix symlink/Windows reparse-point rejection, and content fingerprinting. - Canonical catalog-v3 record with complete surface inventory, package and manifest digests, planning target, provider requirements, and permission ceiling.
- Complete current TUF metadata validation and cache verified archives and signed planning targets by SHA-256.
- Expose one state-free bootstrap-root evidence inspector and one bounded, digest-pinned, immutable admission API for managed hosts. They share the exact digest/version/size decoder and public size bound; admitted bytes still require the ordinary complete TUF refresh before catalog evidence is trusted. Standalone root imports share that same public size bound.
- Provide one strict public-Internet Registry transport policy for managed hosts: HTTPS only, per-request DNS validation and address pinning, no ambient proxy or automatic redirects, per-hop validation of bounded target redirects, and fail-closed denial of non-public address space across metadata, bootstrap-root, planning-target, and package-target downloads.
- Persist up to 64 named Registry sources in canonical ACL with one enabled default, revision-bound confirmed authority changes, managed digest-bound root import, and source-identity-isolated TUF/cache datastores. Install and upgrade consume that same enabled set for cross-Registry dependencies.
- Accept a typed GitHub
owner/repositoryRegistry address with bounded ref/path overrides while retaining the ordinary mandatory TUF bootstrap root; never clone or execute Git repository content on the client. - Support explicit zero-network install and upgrade from only unexpired, revalidated cached metadata and targets; reject missing or tampered evidence without implicit online-to-cache fallback.
- Registry/TUF receipts require the exact verified catalog record and source provenance.
- Bounded SemVer dependency resolution with deterministic install/removal order, cycle detection, host/target checks, and cross-source ambiguity rejection.
- Exact package locks bind every selected version, dependency edge, artifact digest, Registry identity, and TUF role version.
- Operation plan v4 binds complete impact, current state, confirmation, host/provider evidence, and package transitions.
- Upgrade binds both prior and candidate locks and classifies Add/Replace/Remove/Retain.
- Reviewed enablement planning returns either an exact plan-v4 envelope or
terminal
NoChange.
- Dependency-forward prepare and one atomic graph publication.
- Reverse uninstall and exact dependency garbage collection.
- Immutable N/N+1 package roots and receipt-owned retirement.
- Durable Registry cutover replay, lifecycle journals, operation locking, exact terminal result replay, and tamper rejection.
- Package-scoped latest/previous lifecycle checkpoint diagnostics with bounded status, digest, timing, failure-code, and rollback evidence; output excludes idempotency keys, credentials, tokens, secret values, and package-authored error text.
- Both applying and rolling-back journals retain exclusive operation ownership until terminal completion.
- Cutover-aware host traits only; no fallback publication API.
- Prior-generation retirement fails unless the graph package binding is already absent.
- Hosts can acquire an exact currently published lifecycle generation by package, manifest, and generation identity; the lease participates in the same accepted-call drain as alias dispatch.
- Hosts can derive a typed capability/Registry cursor and atomically lease every callable package generation in canonical order. Publication is rechecked after the complete batch is held; stale, hidden, mixed, digest-mismatched, contended, or non-lifecycle package bindings fail closed without a partial lease.
- Missing exact recovery evidence fails closed instead of reconstructing state heuristically.
- Typed lifecycle hosts for Tool, MCP, OKF, Flow, Skill, and UI.
- Standalone executable Task, stdio MCP, immutable Skill/UI, and SQLite/FTS5 OKF Knowledge composition.
- Scope-kind-isolated OKF storage policy with atomic receipt-accounted byte and projection quotas, per-surface generation bounds, global tombstone pruning, SQLite/WAL compaction, and exact-scope usage diagnostics.
- Scope-local OKF SQLite/receipt/FTS integrity audit, non-overwriting digest-bound database backup and offline verification, exact-scope bounded oldest-first rotation with canonical plan confirmation, plus repair limited to rebuilding the derived search index from validated documents. Authority-bound restore binds exact package/lifecycle/Registry/Grant authority, an exact-subset binding inventory, and live main/WAL/SHM evidence; it can restore missing binding files without overwriting conflicts, preserves prior files, and converges a durable six-state journal after interruption.
- Real
a3s-flowNative TypeScript preflight and exact-generation binding in injected hosts and the explicitly configured standalone CLI lifecycle. - Self-contained release-backed Runtime Task binding and exact-generation dispatch with receipt-owned provider reconnection, restart reconstruction, stale-generation rejection, bounded output cleanup, and Registry lease drain.
- Capability snapshot v5 projection for exact installation/package/generation matched release-backed Runtime Tool Task bindings.
- Capability snapshot v5 projection for every exact extension MCP surface, preserving canonical IDs, collision-resistant host names, activation, package/file identity, bounded package-local stdio launch evidence, and credential-free managed HTTP binding evidence.
- Research-preview MHS adapter profile and fixture using only MCP, Flow, Skill, and UI surfaces, with a canonical least-authority permission ceiling, fail-closed gateway/dependency publication, and explicit unknown-outcome semantics for physical mutations. This does not claim MHS conformance.
- Workspace Grant proposal/change/resolution/ceiling binding.
- Candidate Grant persistence before prepare, cutover checkpointing, drain-before-revoke, and joint pre-cutover rollback.
- Manager MCP toolset v5 with explicit install-time Registry selection, read-only planning, digest-bound operation observation/watch, one apply tool, and trusted explicit cancellation; the ten-tool v4 inventory remains a migration contract.
- Shared typed
PluginManagerServiceover the production Host Manager, with deterministic request replay, Registry-bound catalog cursors, stable installed-state pagination, exact/ranged SemVer selection, durable reviewed plan reopening, exact operation observation/watch, and all thirteen frozen operations. Its standard MCP adapter derives names, schemas, and annotations from toolset v5 and obtains apply/cancellation confirmation only from an injected trusted host provider. - Production
CognitivePackageHostManagerfor one exact managed-scope fence, with durable request/operation binding, selected-surface planning, digest-only graph and enablement apply, restart replay, provenance revalidation, zero-network install/upgrade apply from the exact planning cache, and expired-plan recovery only after Use-owned durable admission or completion evidence. Host protocol v6 binds an explicit User or Workspace scope kind, observes exact operations from durable Host, graph, enablement, and lifecycle evidence, long-polls a status revision, and persists explicit-user cancellation only before durable admission.
- Exact
a3s-flow1.0.0-rc.1candidate qualification for the extension facade through the complete all-feature workspace gate. - Canonical fixtures and digest goldens for the current contract line.
- Unit, integration, remote Registry, crash-replay, grant, Flow, OKF, and CLI tests in the Use workspace.
- Test-binary subprocess exit after a durable host effect and before receipt persistence at every canonical install, upgrade, enable, disable, and uninstall checkpoint, with exact-key recovery, one durable effect, and no host call on terminal replay.
- Test-binary subprocess exit after a grant-bearing install, upgrade, or
uninstall graph publish/hide effect but before package publication receipts
and Grant cutover evidence, with exact-key recovery, one graph effect,
completed package/Grant journals, and no publication on terminal replay.
Three externally killed managed-host processes also cover five-node install,
upgrade, and uninstall after Registry publish/hide but before one dependency
receipt and Grant cutover/retirement. Restart forbids reauthorization,
performs no network request, preserves the exact candidate Grant, retires
only the bound prior Grant, and completes without another Registry generation.
Five real
CognitivePackageHostManagerprotocol children also cover every reviewed mutation after the Registry is taken offline. Install, upgrade, and uninstall are killed at the five-node graph publish/hide boundaries; disable is killed after root hide and Grant cutover while accepted-call drain blocks; enable is killed after publication while its candidate Grant is still prepared. Digest-only apply reuses the durable reviewed plan and confirmation; install and upgrade also use only the planning cache. Recovery completes lifecycle/Grant journals, converges the exact candidate/prior Grants or enablement regrant/revocation without another Registry generation, and persists a replayable terminal Host outcome. - Test-binary subprocess exit after all 14 Grant Store durable checkpoints in the canonical two-candidate/two-retirement lifecycle across forward prepare, cutover/retirement, and pre-cutover rollback, with exact candidate/prior convergence and terminal journal replay.
- Real
a3s-useprocess exit after a nine-node install Registry publish cutover but before dependency journal and installation snapshot completion, followed by zero-network exact replay with one complete visible closure and no capability-generation inflation; and after an uninstall Registry hide cutover but before its package hide receipt, followed by exact-plan restart, an observed accepted-call drain, and physical removal. Missing generation state without the exact durable cutover is rejected without changing graph, pending-plan, or Registry evidence. - Signed standalone CLI Flow/OKF/Skill/UI install, process-restart
observation, exact upgrade, uninstall, failed-preflight non-publication, and
repaired exact replay coverage on Unix and Windows x86_64. The OKF fixture
also exercises audit, backup, offline verification, confirmed FTS repair, and
reviewed restore. Test subprocess exits cover the active-marker handoff,
every restore journal state, and partial main/WAL/SHM movement; replay works
from the durable candidate without the external backup and terminal replay
does not rewrite state. A path-free
restore-statusprojection reports the global active phase and bounded scope history/capacity at every exit window without changing restore or database evidence. - Linux CI, macOS workspace tests, and Windows preview compile/facade plus signed Registry, dependency-graph, Grant, Flow, OKF lifecycle, and killed-process cutover-replay gates.
- GitHub Pages documentation application and bilingual documentation.
Status: in progress
- Persist exact Service provisioning before Runtime apply, advance it monotonically through Runtime-applied and Gateway-ready evidence, reconcile the final-binding commit window, and remove interrupted candidates without creating duplicate Runtime effects.
- Exit real test subprocesses at all six nested Service provisioning windows for Tool and HTTP MCP, then prove exact-key recovery, one Runtime and Gateway effect, terminal replay, and drain/remove without residue.
- Qualify the inactive committed-authority Runtime owner for release-backed Tool Task/Service and Streamable HTTP MCP payloads, monotonic Service provisioning, exact final-receipt replay, typed Gateway readiness, and receipt-owned retirement without exposing Artifact Store paths.
- Define the canonical Runtime plan payload and restart-safe resolver boundary, with exact plan-time and provider-evidence validation.
- Qualify the installation-scoped host-owned Runtime plan store with canonical digest addressing, bounded batch publication, restart-safe reads, no-clobber immutability, and fail-closed tamper detection.
- Register Runtime plan payloads as the fifth snapshotted owner, include them in complete-set snapshot/staging/six-checkpoint activation, and retain referenced Runtime blobs through installation artifact reachability.
- Qualify a reviewed-operation-only Control composition that projects the complete transition, validates Runtime publication authority, and orders immutable plan publication before the generation commit under one shared maintenance fence. This remains an inactive cutover proof.
- Compose production Runtime Service providers in A3S Code and managed hosts with a durable host source and atomic dispatcher cutover, preserving exact plan-time and apply-time evidence.
- Consume the reviewed Runtime Task projection in Code CLI/TUI and agent
tool discovery, then route invocation through the leased Use dispatcher. A3S
CLI
maincommite77d318beba3cba7f193da8d83bb9ac5c46fc0f7extends the resident TUI projection to scoped Code Exec: the one-shot host freezes provider-qualified reviewed Tasks with exact count/digest evidence, retains the same trusted Plugin Manager through Session teardown, and invokes through the existing exact-generation dispatcher and Use lease. A missing named provider omits only its Task; MCP, Knowledge, Flow, and Plugin Manager presentation surfaces remain outside the scoped host. CI run 32797862154 passed the main all-target check, Linux release sandbox, Linux ARM64 local inference, and native macOS/Windows cross-platform jobs. - Compose HTTP/streamable MCP through Gateway with health, drain, and
exact-generation retirement. A3S CLI
maincommit563e7e139740e845369f9102a2d47026733797a8qualifies four real Linux Tool and MCP processes across retained N/N+1 routing, Gateway and lifecycle-host restart, stop/drain, exact receipt-owned removal, and zero residual routes, Runtime units, receipts, or PIDs. CI run 32739505482 passed the full Linux all-target suite, release sandbox, Linux ARM64 local inference, and macOS/Windows cross-platform jobs with the exact merged Box and Gateway revisions. - Complete bounded storage quota, projection retention, tombstone garbage collection, and physical compaction in the standalone Knowledge backend.
- Complete managed A3S Code Knowledge Workspace/session carriers and prove leased prior-generation query semantics through those hosts.
- Validate UI entry points and exact asset digests during package lifecycle changes, and clear receipt-owned UI state on true surface removal.
- Complete reviewed UI backend bindings and sandboxed rendering in supported hosts. Current CLI and TUI hosts remain static-integrity-only.
- Prove that every required surface remains unpublished when its owner or evidence is missing.
Exit gate: a six-surface signed package completes install, enable, upgrade, disable, and uninstall through the same reviewed plan/apply service in each supported managed host.
Status: in progress
- Converge the standalone CLI on the shared
PluginManagerServicewithout a second catalog, plan, confirmation, or mutation implementation. The exact manager-v5 read, planning, observation, watch, and cancellation inventory is available underplugin; apply and cancellation reopen a durable operation ID plus plan digest, require explicit trusted user authority (and CLI--yes), and use the verified cache without network access. Compatibility install, upgrade, and uninstall fields remain intact. - Migrate the A3S Code TUI to that service and compose the standard manager
MCP in Code. CLI, TUI
/packages, and the exact thirteen-tool manager-v5 MCP now reuse one host-owned service without a second plan, confirmation, or mutation path at A3S CLI commitce1240891d6926c132aed8212efabaf6c925f4db. - Verify TUI
/packagesand CLI output show the exact plan, package graph, source, permission ceiling, and confirmation boundary. A3S CLImaincommitbef7c913cbefba62638b37f91ce9263f4db2ffbbderives one deterministic, read-only human review from the immutable Manager envelope while preserving the standard machine JSON contracts. CLI and TUI show exact plan/lock, source, transition, permission, provider/impact/state, and confirmation evidence; the TUI scrolls every wrapped line before exact apply. CI run 32786647662 passed the main all-target check, Linux release sandbox, Linux ARM64 local inference, and macOS/Windows cross-platform jobs. - Prove install → invoke → exact-generation upgrade → invoke → uninstall → process restart for Tool, MCP, Flow, Skill, UI, and OKF. The complete signed six-surface Host Manager matrix now exercises native Tool and stdio MCP launchers, Flow preflight, Skill/UI integrity, and an exact OKF lease across install/replay, upgrade/replay, and uninstall/replay.
- Prove watcher resumption, no duplicate side effects, and path-free retained history after process restart. A real Host-protocol install now carries its pre-restart status revision across an externally killed apply and offline recovery process, observes exactly one completed revision, and then times out without changing the terminal revision. Recovery retains one Registry generation, exact apply replay performs no authorization or publication side effect, and scoped retained history excludes filesystem paths, Registry URLs, Host request IDs, and idempotency material.
- Run the same scenarios for User and Workspace scope and reject scope-kind substitution under the same textual ID. Permission-free Skill and permission-bearing Tool matrices cover the individual scope fences, and the complete six-surface Host Manager matrix now covers both User and Workspace install/restart, upgrade/restart, uninstall/restart, exact Tool/MCP/OKF observations, and plan/apply/operation-observation scope-fence rejection.
Exit gate: Code CLI/TUI and agent tools produce the same plan digest and terminal operation result for the same request.
Status: pending
- Bind package-owned Flow identity to distributed scheduling, resumption,
cancellation, and observation without a second
flow.jsonlifecycle. - Prove local Code and remote OS targets consume the same source/export, package generation, dependency edges, and authorization.
- Define and test failure/retry ownership across Use, Flow, Runtime, and remote target boundaries.
Exit gate: remote execution changes placement only; package receipts, locks, and lifecycle journals remain Use-owned and singular.
Status: in progress
- Run full workspace and real-process package lifecycle tests on Linux
x86_64/arm64 and macOS arm64/x86_64. Native CI run
32604181662
passed the then-current Use-owned workspace suite on all four targets from exact
maincommit40bc5593cbf58ca2da171d85ba578c2d6bd911c8while the matching Windows job and general release gates also passed. - Run signed Registry trust/lock, dependency-graph install/upgrade/uninstall,
Grant, standalone Flow preflight/lifecycle, and OKF cutover scenarios through
real
a3s-useprocesses on Windows x86_64, including killed-process replay of removed-dependency cleanup without capability-generation inflation. - Run the complete current Use-owned workspace suite on Windows x86_64
and reject directory junctions across package, Registry/cache, Grant,
lifecycle, Runtime, Flow, and Knowledge trust boundaries. Flow Runtime
qualification now also exercises exact-generation retention, artifact
substitution, tampered or moved binding records, same-text scope-kind
isolation, and directory-junction rejection on Windows. Shared native link
qualification also covers the maintenance lock, target-cache partials and
observations, retained lifecycle receipts, package graph and diagnostic
stores, enablement locks, Runtime and lifecycle records, whole-state backup
and restore paths, and OKF database, binding, backup, and restore paths with
real Windows directory junctions. Native Windows tests additionally prove
single-package and graph cutover-capacity rejection happens before lifecycle
receipt replacement, and that Box CLI delegation preserves arguments,
output, and exit status through a
.cmdcomponent. - Run the Runtime Service provisioning subprocess-exit matrix for Tool and HTTP MCP on the configured platform CI jobs. Real managed-provider and CLI process-kill qualification remains open.
- Expand the remaining Windows gate to the complete filesystem, Runtime,
MCP, watcher, failure-injection, and crash-recovery matrix. All production
temporary-file publications for Registry state/cache, Workspace Grants,
package and Host records, lifecycle, Runtime, Flow, Knowledge, enablement,
backup, restore, and diagnostics now share one bounded Windows retry for
transient access, sharing, and lock violations while preserving replace
versus no-clobber semantics. Restore journal evidence and Knowledge recovery
preserve their source after a bounded rename failure; whole-state restore
candidates preserve reviewed file attributes, and lifecycle-generation plus
restore-history directory moves use the same retry bound. A released
exclusive file or directory lock converges atomically, and a persistent
replacement lock leaves the old target intact. Resumable Registry partials
use one final-component no-follow handle from discovery through append,
checkpoint, verification, and copying into the global Blob tier. Commit
rehashes while copying, publishes without clobber under the digest lock,
reopens the final blob without following it, and retains that exact handle
through staging. The source observation is durable only after the blob, and
partial cleanup is last. A live Windows partial or blob handle permits readers
but denies external writes, removal, and replacement, while Unix commit and
staging remain bound to their held handles after path replacement.
Windows-native scanner tests prove a transient no-delete-share handle
converges within the two-second cleanup bound. If cleanup stays locked after
publication, the next transaction rehashes the durable blob and removes the
redundant complete partial without a network transfer. Invalid-partial
cleanup and source deletion of stale files, partials, and observations use the
same bounded blocking retry; source deletion never removes the global blob.
Native tests prove transient scanner release converges for each cleanup path;
a persistent selected-target lock stops at two seconds, preserves that entry,
and a later prune rescans and finishes after any earlier durable deletions.
Recursive cleanup of bounded abandoned
.artifact-staging-*trees plus lifecycle receipt deletion uses the same retry without blocking Tokio. Native tests prove transient receipt and nested-staging contention lets the same authority retirement or artifact commit finish. A persistent reader of a complete global artifact never delays uninstall because scoped retirement does not delete shared bytes. Native tests also hold the active artifact-staging directory at its atomic content rename: transient contention lets the same commit finish, while persistent contention fails before receipt or Registry-snapshot mutation, retains residual staging, and permits exact commit replay after release. Selected upgrade-receipt replacement has the same native scanner qualification. Transient contention completes the same upgrade; persistent contention stops at the bound, retains the valid global candidate artifact, removes its retained-receipt candidate, preserves the byte-exact prior receipt and published generation, leaves no temporary receipt, and permits exact replay after release. Reboot recovery, antivirus contention beyond these exact blob publication, source-cache removal, active package-commit, upgrade-receipt replacement, and lifecycle-removal boundaries, product-host contention, and the remaining platform scenarios stay open. - Test real-process uninstall interruption between durable Registry cutover and its package receipt, then hold the prior generation lease through restart to prove drain-before-removal and exact generation replay.
- Complete the interrupted download, archive extraction, graph/Grant
cutover, drain, removal, process crash, reboot, remaining antivirus contention
outside blob publication, source-cache removal, active package commit,
upgrade-receipt replacement, and lifecycle removal, and reparse-point
replacement matrix. A real
a3s-useprocess-kill test now proves digest-bound target download resume without partial publication. A second real-process test kills installation while a verified high-entry archive is being extracted, proves no receipt, installation snapshot, pending operation, or package root was published, and completes an exact zero-network retry from the verified cache. A third real-process test kills the following immutable package copy after its pending plan and applying journal are durable, then proves retry reclaims the actual bounded artifact-staging tree, publishes only the exact generation once, and removes the pending operation. Package commit also rejects staging or Artifact Store ancestor links/reparse points. A fourth integration test proves uninstall retires scoped receipt and package-binding authority without deleting or waiting on global artifact bytes. A fifth real-process test kills a nine-node install after the complete atomic graph is visible but before one dependency journal and the installation snapshot complete; offline replay uses the retained cutover, performs no network request, completes every journal, and keeps the original Registry generation. Sixth through eighth externally killed managed-host tests cover install, upgrade, and uninstall publish/hide boundaries with a permission-bearing root and four dependencies while the Grant journal is still prepared. Replay is rejected if it requests authorization again or performs a network request; otherwise it preserves the exact candidate Grant, retires only the bound prior Grant, and completes package and Grant journals without generation inflation. Ninth through thirteenth externally killedCognitivePackageHostManagerprotocol applies cover all five reviewed mutations after the Registry server is stopped. Install, upgrade, and uninstall use the five-node graph publish/hide boundaries; disable stops after root hide and Grant cutover while drain is blocked; enable stops after publication with its candidate Grant prepared. Recovery consumes the durable reviewed request and confirmation, uses only the exact planning cache for install/upgrade, converges the exact candidate/prior Grant or enablement regrant/revocation, completes drain, and persists the terminal Host outcome without reauthorization or generation inflation. Actual Code/Runtime product-host, platform, reboot, contention, and replacement-race qualification stays open. - Verify release archives install and run without repository-local paths.
Non-publishing qualification run
33651777660
scanned all five target archives for checkout paths and ran the installed
native executables with isolated homes and working directories from exact
maincommit4f6e4725205d06ab81f8ea98bfee85c7eb4b2bcd.
Exit gate: every supported target passes the same signed six-surface package and failure-injection scenarios.
Status: in progress
- Initialize and operate
A3S-Lab/Use-Registryas the documented official Registry with root rotation, expiry, mirror replacement, offline recovery, and incident procedures. Complete architecture track A5 before publishing its first production bootstrap root. Progress: Use-Registry checkout documents ownership boundary; staging CI gate (registry-staging-gate.yml/docs/staging-ci.md) fail-closes keys-in-tree and package-source bleed, and runs realassemble+verifywhen admissions and environment-injected keys are present. Registry-tools support threshold root ceremony, pin-stable offline recovery, under-threshold fail-closed, and every-intermediate-rootrotate-rootwith retainedroot.historyplus mandatory new bootstrap pin,check-expirywarn/fail-closed monitoring,compare-mirrorsdrift fail-closed, andwithdraw-targetsemergency withdrawal with pin-stable empty-catalog verify. Production bootstrap root publication and live incident procedures remain open; the offline ceremony checklist is in Use-Registrydocs/production-bootstrap.md. Production CI readiness gate (registry-production-gate.yml/docs/production-ci.md) fail-closes keys-in-tree and in-gitregistry/, and arms assemble+verify only with production admissions + environment-injected keys (no trust-root push). - Provide durable Registry source add/list/replace/default/enable/disable/ remove operations; preserve immutable receipts and identity-bound evidence across replacement and exact-provenance restoration.
- Persist verified archives and planning targets in a content-addressed cache and support explicit fail-closed offline install/upgrade.
- Enforce typed per-Registry byte/entry limits, minimum free-space admission, oldest-first retention, stale-write cleanup, zero-network usage, and confirmed garbage collection.
- Add bounded, integrity-preserving download resume with durable digest-bound partials, exact HTTP range validation, full-file verification, and cache-policy/GC accounting.
- Publish checksum-verifying Linux/macOS and Windows installers from the release workflow with HTTPS downgrade prevention, safe extraction, packaged OCR/Skill binding, versioned atomic activation, and tamper/conflict tests.
- Deterministically serialize multi-platform archives and publish one SPDX SBOM per platform, GitHub OIDC provenance/SBOM attestations, and a locally reverified keyless Sigstore bundle for complete checksum evidence from one workflow with pinned Actions and release tools.
- Make both platform installers require Cosign, authenticate the checksum manifest against the exact tag workflow identity and GitHub OIDC issuer before archive download, fail closed on invalid evidence, and retain the verified manifest and bundle with the installed version.
- Pass byte-for-byte independent rebuilds for every shipped native
executable on all five targets. The tagged
v0.3.2attempt exposed drift on four targets and did not publish a Release. The current non-publishing qualification run 33651777660 rebuilt every shipped native executable without a compiled-artifact cache, with one release codegen unit, and byte-matched all five primary archives from exactmaincommit4f6e4725205d06ab81f8ea98bfee85c7eb4b2bcd. - Publish the development-preview
v0.3.6GitHub Release after the exact tagged source, five verified platform archives, deterministic SBOM/reproducibility evidence, installers, and Use-owned typed crates passed the release workflow. Release workflow run 33675697857 passed all 13 jobs for exactmaincommit54758910f2f4ad9498137410e0a2207d412e99a1; the release publishesa3s-use-core 0.2.5,a3s-use-extension 0.3.6, anda3s-use 0.3.6. The cancelledv0.3.5attempt did not create a GitHub Release because the public core crate was stale; do not treat that tag as published evidence. This does not close the external-witness or product-readiness gates. - Publish the development-preview
v0.3.7GitHub Release after the exact tagged source, five verified platform archives, deterministic SBOM/reproducibility evidence, installers, and Use-owned typed crates passed the release workflow. Release workflow run 33687297386 passed all 13 jobs for exactmaincommit48a0b76f8a4a87a11d16627c7bd7567920852508; the release publishesa3s-use-core 0.2.6,a3s-use-extension 0.3.7, anda3s-use 0.3.7. The priorv0.3.6release remains historical evidence. This does not close the external-witness or product-readiness gates. - Publish the development-preview
v0.3.8GitHub Release after the exact tagged source, five verified platform archives, deterministic SBOM/reproducibility evidence, installers, and Use-owned typed crates passed the release workflow. Release workflow run 33720485826 passed all 13 jobs for exactmaincommit6d3a7baf32ce998a2e487c40fbf78b4a6cda2579; the release publishesa3s-use-core 0.2.7,a3s-use-extension 0.3.8, anda3s-use 0.3.8. The priorv0.3.6andv0.3.7releases remain historical evidence. This does not close the external-witness or product-readiness gates. - Publish the development-preview
v0.3.9GitHub Release after the exact tagged source, five verified platform archives, deterministic SBOM/reproducibility evidence, installers, and Use-owned typed crates passed the release workflow. Release workflow run 33756618837 passed all 13 jobs for exactmaincommita5f3cc40bfb0a1021ca150d2ce4295409b74d220; the release publishes 19 assets,a3s-use-core 0.2.7,a3s-use-extension 0.3.9, anda3s-use 0.3.9. The priorv0.3.6,v0.3.7, andv0.3.8releases remain historical evidence. This does not close the external-witness or product-readiness gates. - Publish the development-preview
v0.3.10GitHub Release after the exact tagged source, five verified platform archives, deterministic SBOM/reproducibility evidence, installers, and Use-owned typed crates passed the release workflow. Release workflow run 33791616307 passed all 13 jobs for exactmaincommitc4c80a223bfff3698ca4b4598e7175c6e3303239; the release publishes 19 assets,a3s-use-core 0.2.8,a3s-use-extension 0.3.10, anda3s-use 0.3.10. The priorv0.3.6,v0.3.7,v0.3.8, andv0.3.9releases remain historical evidence. This does not close the external-witness or product-readiness gates. - Publish the development-preview
v0.3.11GitHub Release after the exact tagged source, five verified platform archives, deterministic SBOM/reproducibility evidence, installers, and Use-owned typed crates passed the release workflow. Release workflow run 33830280138 passed the validation, five-target primary-build, typed-crate, and five-target independent-rebuild gates for exactmaincommitc25028ae0245ba1d28f7e2837e2a87f7e9f6fe40; the release publishes 19 assets,a3s-use-core 0.2.9,a3s-use-extension 0.3.11, anda3s-use 0.3.11. The priorv0.3.6,v0.3.7,v0.3.8,v0.3.9, andv0.3.10releases remain historical evidence. This does not close the external-witness or product-readiness gates. - Add an externally operated witness for the complete staged tree and final archive digest, and retain verification evidence outside the Release asset trust boundary.
- Define storage retention, quota, garbage collection, backup, and repair
procedures for packages, cutover evidence, Grants, Flow history, UI state,
and OKF projections. A deterministic
a3s.use.state-backup.v2exact-installation inventory now snapshots all allowlisted installation-owned families under its exclusive maintenance fence, binds the installation, Registry generation/snapshot, and installed receipt digests, excludes locks and global Registry/TUF/Flow caches, rejects nonterminal or unknown state, and verifies every payload offline without extraction. Signed-package real-process coverage proves path-free inventory and zero-network verification. Coordinated retention now verifies every managed whole-install archive under one external directory lock, returns a path-free oldest-first canonical plan, rejects stale plans or changed candidates, and removes nothing without the exact plan digest and explicit confirmation while retaining at least two recovery generations. Scope-local OKF database audit, verified backup and exact-plan rotation, derived-index repair, and authority-bound database plus missing-binding restore are also implemented. Binding recovery accepts only an exact subset of the verified backup inventory and independently retained Registry/package/lifecycle/Grant authority; conflicting or newer binding evidence fails closed. Reviewed same-version/OS/architecture whole-install restore is now implemented with a path-free Add/Replace/Remove/Retain plan, exact live Registry and Grant authority, a verified external rollback archive, link/reparse-safe staging, seven durable phases, 15 subprocess-exit recovery boundaries, terminal replay, read-only diagnostics, and bounded crash-recoverable history. Missing authority recovery, clean-machine disaster recovery, cross-platform drills, whole-product policy, and complete operational exercises remain open. - Expose bounded, secret-free latest/previous lifecycle checkpoint
diagnostics through
extension inspect --json. - Add broader telemetry and diagnostics for plan, download, provider
readiness, cutover, drain, rollback, and recovery without exposing secrets.
extension diagnose --jsonnow exposes bounded, path-free Registry/TUF, reviewed-plan, provider, Grant, cutover, lifecycle publication/drain/ rollback, and recovery evidence for one exact retained planned/admitted/ cancelled install, upgrade, or uninstall graph, active admitted enable/ disable operation, or newest Host-reviewed pre-admission enable/disable plan or cancellation. Standalone Knowledge recovery exposes bounded active/ history/capacity evidence. Retained install/upgrade graphs and durable pre-plan download attempts expose expected and retained archive and signed executable-planning-target bytes plus exact-target missing/partial/complete state from historical Registry provenance without network I/O, writes, cache-lock acquisition, or paths. Real killed-process tests prove active archive and planning-target partial observation, retained evidence, exact Range resume, and cleanup only after the reviewed graph is durable. Partials and complete observations are never planning/apply/recovery authority. Before an exact lock exists, a durable pre-lock resolution attempt records refreshed/cached access, requested version/channel, per-Registry pending/verifying/verified/failed state, path-free source/trust digests, TUF role versions, bounded failures, and terminal package-lock evidence. The diagnostic survives resolver failure or process exit and is deleted only after its download-attempt successor is durable. Real CLI tests cover a killed online resolution, terminal verification failure, and zero-network offline cache failure.extension diagnose --history --jsonnow retains the newest 16 exact completed or rolled-back operations and cancelled graph plans within 8 MiB per scope/package. Retention happens before recovery evidence is removed, exact replay is deduplicated by(operationId, planDigest), history survives uninstall, and malformed, linked, or oversized state fails closed without path or secret leakage. A real CLI install/uninstall/reinstall sequence proves zero-network newest-first history and legitimate textual operation-ID reuse; a Host graph cancellation proves zero-network cancelled outcome and replay deduplication; the managed Workspace Host kill/recovery path proves exact-scope history without a second entry. A digest-bound Host observation index selects the newest reviewed enablement plan by(plannedAtMs, requestId)while retaining its exact managed scope only for private request lookup. Real CLI assertions proveplanned/cancelledprojection, selected provider and awaiting-Grant state, exact zero-observed lifecycle counts, zero network/authorization/ admission, no Host/fence/path leakage, active Use-evidence precedence, and suppression after Use completion before the Host outcome is durable. - Complete threat model review, privilege boundaries, security response, upgrade policy, and support runbooks.
Exit gate: a release candidate can be installed, upgraded, recovered, audited, and removed by an operator using only published artifacts and documentation.
The first-principles capability and release-gate audit is recorded in docs/agent-package-manager-audit.md. It distinguishes qualified mechanisms from inactive Control proofs and from the production composition, trust, interoperability, and operations gates below.
The first supported product release is blocked until all of the following are green:
- A0 proves serializable graph mutation and stale-generation rejection across different roots with shared dependencies.
- A1 proves one authoritative installation generation for every explicit User and Workspace scope, including independent selection of the same package.
- A2 proves atomic Use-owned control state and deterministic recovery around every external provider-effect boundary.
- A3 lets an arbitrary MCP-capable agent discover and invoke capabilities through opaque references and server-owned exact-generation leases.
- One reviewed Package Manager serves CLI, TUI, and management MCP, with a distinct lower-authority Capability Gateway for agents.
- A4 composes all declared production providers without hardcoding A3S-specific domains into the universal engine.
- Exact graph and Grant recovery passes failure injection at every checkpoint.
- Linux, macOS, and Windows pass the declared real-process matrix.
- A5 Registry operations, signing, provenance, and release installation are
independently reproducible from
A3S-Lab/Use-Registry. - Storage retention, repair, observability, incident response, and support procedures are documented and exercised.
- A6 qualifies the signed MHS reference package against the separate virtual laboratory without claiming physical-device conformance.
- Website and README examples pass against the release candidate.
Until then, README and website copy must say development preview and must not advertise production readiness or a stable cognitive-package contract.
A3S Use is ready to publish only when a user can select a trusted Registry, review one exact scoped-installation plan, and atomically install a signed dependency graph; and when an arbitrary MCP-capable coding agent can discover and invoke its authorized capabilities without learning host paths or holding lifecycle authority. The system must recover from interruption without guessing, upgrade without exposing mixed generations, and uninstall without leaving routes, Grants, leases, processes, projections, or package-owned state behind.