Skip to content

Latest commit

 

History

History
2734 lines (2598 loc) · 178 KB

File metadata and controls

2734 lines (2598 loc) · 178 KB

A3S Use Roadmap

Last updated: 2026-09-10

A3S Cloud substrate obligations

Cloud Wave 3 (U0) consumes Use as the trusted package/Plugin Manager boundary. Deliver digest-only apply and observation contracts. Do not add a Use-owned scheduler, node channel, or Cloud desired-state store. See agents portfolio roadmap and cloud-substrate-dependency-roadmap.md.

Product status

A3S Use is a development preview. The cognitive-package platform has not shipped a supported product release and is not production-ready.

This roadmap is deliberately release-oriented. Completed internal contracts or green unit tests are evidence of implementation progress, not a release claim. A product release requires the cross-repository, cross-platform, supply chain, recovery, and operational gates in this document.

Product outcome

A3S Use will be the AI Native Package Manager for arbitrary coding agents and A3S hosts on Linux, macOS, and Windows. It must install platform-native capabilities and versioned cognitive packages whose dependency graph can contribute:

  • Tool Tasks and Services;
  • standard MCP servers;
  • OKF Knowledge bundles;
  • A3S Flow workflows;
  • Skills; and
  • sandboxed UI assets.

One command resolves the complete SemVer closure, verifies every source and artifact, freezes exact locks, prepares dependencies before dependents, publishes one capability generation, and retires unused generations in reverse.

Product decisions

  1. The package is the lifecycle unit; the scoped installation is the consistency unit. A surface cannot be installed, upgraded, enabled, disabled, or removed independently of its owning package. A graph mutation commits one complete scoped installation generation, never a collection of independently authoritative root-package graphs.
  2. There is one current cognitive-package format. Manifest v3, catalog v3, receipt v6, Installation Snapshot v2, Extension Registry snapshot v3, capability snapshot v5, extension cursor v3, capability cursor v4, plan v4, host protocol v6, managed scope v2, manager toolset v5 (v4 migration contract retained), pending graph v4, pre-lock resolution attempt/diagnostic v1, pre-plan download attempt/diagnostic v1, enablement recovery projection v3, and enablement operation v3 are the only accepted baseline.
  3. No pre-release compatibility debt. Superseded schemas, receipts, metadata, APIs, and disk state are rejected. The user must clean the unsupported state and reinstall. No migration or fallback is inferred.
  4. Package-manager compatibility remains. SemVer dependencies, requires_use, OS/target checks, and host/provider capability checks are required correctness rules, not legacy branches.
  5. Registries are replaceable host input. URLs, trust roots, source state, and mirror selection are not compiled into packages or the resolver.
  6. Trust evidence is end-to-end. TUF custom.a3s carries a complete catalog-v3 record; the exact verified record and provenance survive download, planning, lock creation, installation, and receipt loading.
  7. Planning and mutation are separate. Install, upgrade, uninstall, enable, and disable return an immutable reviewed plan before apply. plugin_apply_plan is the only package-state mutation tool; explicit pre-admission cancellation is a separate control-plane mutation.
  8. There is one Flow lifecycle. a3s-flow owns workflow compilation and execution. flow.json may describe visual design/deployment but cannot create another package identity, receipt, or journal.
  9. OKF is a Knowledge surface, not a process. Publication requires exact promoted Knowledge evidence. Only OKF v0.2 is accepted.
  10. Hosts own providers and UX. Runtime, Gateway, Flow, Knowledge, Code, Web, and OS inject their typed providers; Use never hides missing ownership with native or source-only fallback.
  11. Hardware adapters reuse MCP. The MHS research-preview profile adds no package surface or private protocol. Use owns package trust and exact publication evidence; the hardware control gateway and device safety layer own physical authorization, interlocks, and ambiguous-operation reconciliation.
  12. Artifacts are global; authority is scoped. Immutable content-addressed bytes may be deduplicated globally, but package selection, dependency ownership, enablement, Grants, provider bindings, and capability publication belong to an explicit User or Workspace installation.
  13. Agents consume capabilities, not host paths. The portable agent contract is standard MCP plus opaque invocation, artifact, and endpoint references. Local executable paths, package roots, credentials, and provider internals are never part of the external capability contract.
  14. Management and consumption are separate trust planes. The Package Manager MCP endpoint performs privileged reviewed lifecycle operations. The Capability MCP Gateway exposes only the capabilities authorized for a consumer and holds exact-generation leases on the consumer's behalf.
  15. Use-owned mutable authority is transactional. ACL remains the product configuration format and immutable artifacts remain files, but related installation, operation, Grant, enablement, and publication state commits through one transactional Control Store. Sagas remain only around external provider effects that cannot join that transaction.
  16. The official package feed is a Registry deployment. Its target name is A3S-Lab/Use-Registry, with root submodule path use-registry/. a3s-use owns Registry formats and tooling; the Registry repository owns reviewed admission data, signed TUF metadata, and immutable published targets. Package source remains in each owning repository.
  17. Domain packages stay outside the package manager. a3s-use-science is not an A3S Use workspace member, runtime dependency, CI target, or release artifact. A future Science capability remains owned by its independent repository and may integrate only as a signed Registry-distributed package.

Architecture convergence program

Status: release-critical, planned from the 2026-08-28 first-principles review.

The current implementation has strong artifact verification, reviewed plans, immutable generations, drain, and crash-replay foundations. A0 gives every accepted mutation one serial order inside its exact installation and rejects stale publication generations. A1 now has one canonical InstallationId and scopes filesystem state, receipts, Registry and capability snapshots, leases, backup/restore, and maintenance/mutation locks by that identity. A0 and A1 are qualified on the declared five-platform CI matrix. The implementation is still not the target architecture: one InstallationSnapshot now owns the desired root set, unified resolved graph, per-package enablement, and selected-surface publication intent, but receipts, Grants, bindings, operation checkpoints, and materialized publication state remain split across several stores, and a non-A3S agent cannot consume an exact leased capability without learning local execution details. A checked item elsewhere in this roadmap is implementation evidence; it does not waive the convergence gates below.

Target responsibility model

Boundary Sole responsibility
Catalog Source Locate TUF metadata and targets; a Git or GitHub address is transport shorthand, never trust authority.
Artifact Store Retain verified immutable bytes by digest and deduplicate them globally; it owns no installation or activation authority.
Installation Snapshot Atomically describe one scope generation: requested roots, resolved packages, dependency edges, selected artifacts, enablement, and publication intent.
Control Store Serialize and transact Use-owned mutable authority, operation records, checkpoints, and materialized capability generations.
Provider Set Apply typed Runtime, Gateway, Flow, Knowledge, UI, Web, and OS effects through explicit ports.
Capability Index Materialize an immutable, scope-specific projection only after lifecycle cutover.
Capability MCP Gateway Present portable discovery and invocation to arbitrary agents while the Use Host owns exact-generation leases.
Package Manager MCP Present privileged planning, review, apply, observation, cancellation, and diagnostics to an authorized operator or host.

Canonical authority keys are explicit:

  • installation: (scope_kind, scope_id);
  • installed package: (installation, package_id, package_generation);
  • capability: (installed_package, surface_kind, surface_id); and
  • invocation: an opaque, expiring host reference bound to the exact capability generation and consumer context.

Package, CatalogSource, ArtifactStore, Installation, CapabilityIndex, and Provider are the preferred architecture terms. Plugin, Extension, and Registry type names with older meanings are removed at the next contract cutover instead of being preserved as parallel abstractions.

Dependency order

A0 mutation correctness -> A1 scoped installation -> A2 transactional control
                             |                         `-> A3 agent capability gateway
                             `--------------------------> A4 provider boundary cleanup
A0 mutation correctness ------------------------------> A5 official Registry
A3 agent gateway + A4 provider boundary + A5 Registry -> A6 MHS qualification

Work may proceed in parallel only where this graph permits it. In particular, new surfaces, package types, or host-specific integrations do not take priority over A0 through A3.

A0 - Make graph mutation serializable

  • Add a deterministic barrier-based regression for the shared-dependency race: with Y -> D installed, one operation plans removing Y and D while another plans installing X -> D; no interleaving may publish X with D absent.
  • Introduce one cross-process installation mutation lease keyed by (scope_kind, scope_id). Install, upgrade, uninstall, enable, and disable are exclusive writers within that domain; another installation remains independently available.
  • Bind every reviewed mutation to the expected complete installation generation and make lifecycle publication an exact compare-and-swap from installation generation G to G + 1.
  • After acquiring the mutation lease, revalidate the complete requested root set, resolved closure, dependency ownership, selected artifacts, and expected publication generation. A stale plan fails without provider or filesystem effects.
  • Validate live dependents in every retirement branch, including nodes previously classified as retained, before hiding a package binding or deleting bytes.
  • Advertise exclusive managed-scope mutation in host capabilities only when the active coordinator actually enforces it.
  • Add multi-process stress and crash-replay tests for different roots with shared dependencies on Linux, macOS, and Windows. CI run 33158712152 passed the main release gate and native Linux x86_64/ARM64, macOS x86_64/ARM64, and Windows x86_64 jobs from exact commit 5a78b32f1db1880fe456ced1b76a027981381b52.

Exit gate: every accepted graph operation has one serial order, and no stale plan can publish a graph whose dependency closure is incomplete.

Implementation evidence (2026-08-28):

  • Each installation's .installation-mutation.lock is a cross-process, non-Tokio-blocking writer fence held by install, upgrade, uninstall, enable, disable, and recovery from live-state inspection through terminal persistence. State backup recognizes it as excluded infrastructure rather than portable authority.
  • The admitted pending graph record or active enablement record is the durable mutation owner after process exit. Graph and enablement recovery reject each other until the exact owner reaches a terminal state; no second ownership file can drift from the operation record.
  • Lifecycle publication binds reviewed install, upgrade, uninstall, enable, and disable plans to Registry generation G and commits only an exact G -> G + 1 cutover. Stale generation, root ownership, dependency closure, manifest, artifact, and dependent checks run before authorization or lifecycle effects.
  • Barrier-based, independent-process, stale-plan, root-adoption, dependent, cross-domain interruption, and Registry cutover regressions cover the A0 invariants. Existing process-exit lifecycle suites continue to cover exact replay after cutover and removal checkpoints.

A1 - Make the scoped installation the authority

  • Define InstallationSnapshot as the single installed-selection source of truth for one explicit User or Workspace scope and monotonically increasing generation. It contains the desired root set and one resolved graph, rather than one authoritative graph file per root package.
  • Move expanded package directories into a global content-addressed Artifact Store while keeping selections, receipts, package bindings, enablement, Grants, provider bindings, and capability publication under an InstallationId.
  • Move verified archive, executable-planning, and presentation-media bytes behind a global sharded Blob tier. Keep canonical source observations and resumable partials in the Registry source datastore. Blob commit is digest-locked, no-clobber, handle-rehashed, and durable before observation publication; source prune never deletes global bytes.
  • Introduce one global cross-source/cross-installation/cross-operation reference inventory before deleting any raw blob or expanded tree.
  • Join global references with physical inventory in one guarded collection pass and expose checked usage plus bounded quota assessment.
  • Enforce an optional durable hard quota with concurrency-safe cross-process admission. Policy-disabled publications share the storage boundary; policy-enabled publications serialize physical scan, exact projection, staging cleanup, and final commit so two writers cannot spend the same capacity.
  • Add an explicit bounded global digest audit for raw Blobs and expanded packages. Reuse the admission fingerprint, hold the exact collection guard, report mismatches without mutation, and fail closed on unsafe or unstable physical state.
  • Require an explicit confirmed garbage-collection policy before deletion.
  • Add exact-plan logical corruption quarantine. Re-audit under the exact collection guard, require the reviewed canonical plan digest, atomically publish a bounded marker, preserve forensic content in place, and fail new ordinary Blob and expanded-package access closed.
  • Add verified rehydration. Recovery must not silently replace bytes underneath an admitted generation and must never derive replacement authority from a quarantine marker alone.
  • Bind enablement and capability-publication intent to the exact InstallationSnapshot generation instead of reconciling separate mutable authorities.
  • Require scope in extension paths, receipts, package bindings, snapshots, and every CapabilityRegistry constructor. Remove implicit User/current projection.
  • Bind Runtime, Flow, OKF binding/SQLite, and lifecycle journal stores to one constructor-supplied InstallationId. Reject a different or invalid identity before path derivation, lock acquisition, database creation, or evidence mutation.
  • Make the same package independently selectable at different versions in User and Workspace installations while safely sharing identical artifact bytes.
  • Replace route strings as identity with the canonical keys above. The ACL route attribute is now an optional human alias only. Duplicate aliases are legal; explicit alias lookup fails as ambiguous instead of selecting an arbitrary package. Ownership, leases, cursors, and host surface names use scoped package/generation/surface identity.
  • Freeze the new contract versions together. Because Use is pre-release, reject superseded disk state with a documented clean-reinstall procedure instead of maintaining a second live authority model.
  • Prove apply, restart, snapshot, leased invocation, upgrade, and uninstall for the same package in two scopes, including identical textual scope IDs with different scope kinds.

Exit gate: all lifecycle, authorization, and capability queries can be answered from one exact scoped installation generation plus immutable artifact evidence.

Implementation evidence (2026-08-30; exit gate passed):

  • InstallationId(kind, id) is the sole installation identity. Its validated kind and collision-resistant storage key partition every installation data and state root; equal textual IDs in User and Workspace installations do not alias.
  • Receipt v6, Extension Registry snapshot v3, capability snapshot v5, and the extension cursor v3/capability cursor v4 contracts carry the exact installation and reject cross-installation loading or lease acquisition. The CLI requires explicit scope kind and ID for every installation-scoped command.
  • Registry source configuration, trust roots, TUF metadata, target observations and partials, global artifact blobs, and derivable Flow compilation artifacts remain installation-independent inputs. Receipts, package bindings, enablement, Grants, provider bindings, capability publication, backup/restore, and both maintenance and mutation locks are installation scoped. Installation backup rejects the global cache families.
  • Provider and lifecycle evidence stores no longer accept a second scope as storage authority beneath an already installation-scoped root. Their scope fields and nested keys remain integrity evidence and must exactly match the constructor-bound installation; cross-installation reads and writes fail with use.installation.identity_mismatch before filesystem effects.
  • Windows publication and SQLite/Flow access use a shared extended-length path primitive. Native regressions cover long scoped roots, atomic publication, same-text-ID scope-kind isolation, and independent installation locks.
  • a3s.use.installation-snapshot.v2 is the only installed-selection and desired-activation authority. It binds the exact InstallationId, a monotonic installation generation, one resolution host, a sorted desired root set, and one unique package selection per ID. Each selection carries the immutable lock node, monotonic package state generation, desired enablement, and exact selected-surface closure. Root locks are derived; conflicting shared selections, disabled dependencies of enabled packages, and orphan nodes fail closed. Removing the final root retains an empty next generation so authority never resets.
  • Installed-selection persistence is one atomic state/installation-snapshot.json file. The former per-root state/package-graphs/<publisher>/<package>.json layout is rejected rather than migrated, and backup/restore inventories accept only the new snapshot.
  • Expanded package content is stored once at data/artifacts/expanded-packages/sha256/<prefix>/<digest>/content, guarded by a cross-process per-digest mutation lock. Two installation registries can commit the same digest concurrently and converge on that one complete tree, while their receipt, generation, visibility, and lease authority remain independent.
  • The authoritative per-installation registry.json snapshot has a bounded 4 MiB read/write boundary. Readers validate the complete configured state directory chain, open the final file without following links or reparse points, allocate only the measured bounded size, and recheck file identity and length after reading. Writers create missing directories one component at a time only inside the configured state root, flush and sync a bounded temporary file, then atomically replace the snapshot. Oversized, linked, redirected, or concurrently replaced authority fails closed before JSON decoding or publication.
  • Artifact reads validate the complete owned directory chain and exact digest path before package integrity is rechecked. Link/reparse substitution fails closed. Interrupted writes use bounded .artifact-staging-* trees and are reclaimed only while holding the digest lock.
  • A global cross-process reachability boundary now separates shared reference admission from exclusive maintenance. Raw-target observations, lifecycle receipts, applying/rolling-back lifecycle journals, installation snapshots, and durable package-graph operations must acquire a store-bound shared admission before their subordinate lock and atomic publication. Incomplete network downloads release admission until the bounded blob-commit/observation transaction. This closes the collector TOCTOU prerequisite.
  • ArtifactStore::inspect_inventory now uses the exact store-bound exclusive guard to enumerate both physical tiers deterministically. Its path-free v1 report distinguishes canonical content from abandoned staging, accounts regular-file bytes and files, bounds the complete traversal, and rejects unknown layout, links/reparse points, and special files. This is physical evidence only: it neither infers reachability nor verifies path digests and grants no deletion authority.
  • RegistrySourceStore::inspect_artifact_references now derives the first reference-source inventory under that exact exclusive guard. Its path-free v1 evidence scans every preserved Registry datastore, including a source no longer selected by current config, and reports each canonical blob digest with its signed byte expectation. Unknown layouts, missing cache locks, links/reparse points, malformed observations, and traversal bounds fail closed. This inventory is one input to—not a replacement for—the global joined view and its still-open audit and deletion policy.
  • ArtifactReachabilityInspector::inspect_references now derives the path-free a3s.use.artifact-reference-inventory.v1 view under the same exclusive global guard. It validates every installation storage key and identity, then aggregates Registry observations, installed selections, current and retained receipts, non-cancelled package-graph operations, applying/rolling-back lifecycle journals, and immutable Runtime plan payloads. Runtime plan artifacts are decoded under the installation maintenance and plan-store locks before their Blob references are emitted. Source locks are joined without nesting unrelated locks; unknown state, links/reparse points, malformed or unbounded records, and conflicting physical expectations fail closed. Missing physical content does not erase a durable reference. Whole-installation restore now enters global reference admission before its maintenance lock and publication, closing the restore-to-collector race.
  • ArtifactReachabilityInspector::inspect_reachability now joins logical and physical evidence while retaining the same exclusive guard. Its path-free a3s.use.artifact-reachability-inventory.v1 output has one canonical row per (kind, digest), keeps reference owners separate from physical state, classifies only metadata expectation availability/match, and derives checked global storage usage. Reference retirement may leave conservative extra owners. A bounded quota assessment reports observed excess but deliberately provides no deletion authority.
  • The global Artifact Store owns optional canonical data/artifacts/storage-quota.acl policy state. Revision compare-and-swap serializes operator changes with publications. Every Blob and expanded-tree writer takes reference admission, then the global storage boundary, then its digest mutation lock. Without a policy, the storage lock is shared. With a policy, one exclusive lock covers bounded physical inventory, exact logical-byte/container projection, same-digest staging reclamation, and final publication. Real subprocess competition proves that only one of two distinct writers can consume one remaining slot. Prepared expanded-package byte/file measurements and a bounded exact copy prevent source growth from creating unaccounted staging. Tightening below current usage stops growth but permits non-worsening replay or cleanup. This correctness-first protocol is serialized, not a parallel durable reservation ledger, and grants no deletion authority.
  • ArtifactStore::audit_digests now emits deterministic, path-free a3s.use.artifact-store-digest-audit.v1 evidence while the exact collection guard freezes admitted publication. It reuses raw SHA-256 for Blobs and the canonical admission fingerprint for expanded packages, hashes sequentially, reports complete mismatches instead of mutating them, retains incomplete staging evidence without hashing it, and repeats the bounded physical scan before returning. Package file opens do not follow the final link/reparse component and revalidate the opened measurement. The audit itself grants no quarantine, rehydration, or deletion authority.
  • ArtifactStore::plan_quarantine now derives one canonical path-free plan only from a fresh complete digest mismatch. apply_quarantine re-audits under the same exact collection guard, compares the reviewed plan digest, and atomically publishes a no-clobber quarantine.json record. Exact replay is idempotent; bounded interrupted publication can be retried without removing its fail-closed sentinel first. Inventory validates marker state without charging it as content or staging, while new Blob open/observe/commit and expanded-package validate/commit paths fail closed. Canonical content remains untouched as forensic evidence. The marker grants neither replacement nor deletion authority.
  • ArtifactStoreMaintenance now coordinates verified rehydration across the facade/extension boundary. Planning and apply keep the exact collection guard across a fresh global zero-reference proof and Artifact Store work. Candidates must resolve outside the store and match the expected raw or canonical expanded digest. Exact path-free v1 plans bind the quarantine record, corrupt measurement, replacement measurement, and required reference count. Apply reverifies all evidence, publishes canonical prepared/completed records, stages under the digest mutation lock, accounts for peak hard-quota bytes, and only then reopens access. Bounded interrupted preparation, retired-content, and completion states resume; moved or conflicting records fail closed. Matching terminal replay validates durable completion and the canonical replacement without reopening the external candidate or requiring later references to be retired again. The reviewed replacement consumes corrupt forensic content, so external evidence retention remains an operator decision rather than hidden Artifact Store GC.
  • ArtifactStoreMaintenance now owns explicit confirmed global garbage collection. A policy names 1..=1024 exact Blob or expanded-package digests; there is no implicit sweep. Plan and nonterminal apply retain one collection guard across the complete reference scan and physical work, require zero Registry, installation, receipt, snapshot, graph-operation, and lifecycle- operation owners, and bind canonical physical measurements plus ordinary, quarantined, or completed-rehydration lifecycle evidence. Apply requires the reviewed plan digest, durably publishes a global prepared fence before any deletion, atomically renames each container to a deterministic same-shard tombstone, rejects links/reparse points and unowned residual entries, and resumes bounded partial deletion after restart. While prepared or temporary state exists, new reference admission fails closed. Completion is durable and exact replay is read-only. Each new plan binds the previous completion digest, so an old confirmation cannot delete an identical digest recreated later.
  • Upgrade, rollback, and uninstall retire installation-scoped authority but do not delete global content. Installation backup excludes global artifacts. Unreferenced content remains retained unless an operator explicitly selects it and confirms the exact global garbage-collection plan.
  • Enable and disable use package-state compare-and-swap inside the next Installation Snapshot generation. Receipts, Registry package bindings, and the v3 enablement file are applied evidence or crash-recovery projections; none can independently select desired state. The projection binds the exact installation generation and digest, and capability snapshot v5 plus cursor v4 expose the same binding before any selected surface can publish.
  • Registry publication and accepted-call drain are keyed by (InstallationId, package_id, lifecycle_generation, package_digest, manifest_digest). Physical locks live under generation-leases; capability surfaces add their canonical kind and ID. Human aliases are retained only in projections, never serve as cursor package keys, and cannot change Tool/MCP host names. The cursor revision still commits the complete projection so an alias-only projection change cannot evade snapshot consistency.
  • same_package_two_scope_matrix_preserves_exact_authority_and_leased_invocation installs the same signed OKF package into concurrent User and Workspace installations with an identical textual ID and one shared Artifact Store. Both installations survive Host reconstruction, expose distinct InstallationSnapshot authority, reject cross-scope snapshot and invocation leases, upgrade independently while the other installation's v1 or v2 lease remains callable, uninstall independently without advancing the other capability cursor, and replay both terminal removals after restart.

A2 - Consolidate mutable authority in a Control Store

  • Introduce a typed ControlStore interface with an initial SQLite/WAL backend for Use-owned mutable metadata. Keep ACL configuration and immutable package, backup, and projection payloads outside the database.
  • Commit installation generations, reviewed-operation state, lifecycle checkpoints, Grants, enablement, provider-binding identity, and capability generation metadata in explicit transactions with foreign-key and generation constraints.
  • Use an outbox/checkpoint boundary for provider effects. Never hold a database transaction across Runtime, Gateway, Flow, filesystem, network, or device I/O; retry owner-proven safe-no-effect deferrals automatically with the same key, and reconcile rejected or unknown outcomes explicitly.
  • Derive backup/restore inventory from the Control Store schema and registered external payload owners instead of maintaining a second manual allowlist that can drift from the state model. Control-backed coordinated backup now admits only the verified Control export leaf plus ControlPayloadOwnerId live locations; unregistered layout families fail closed. Owner-native complete-set snapshot/restore remains the stronger portable archive path and continues to converge with restore wiring.
  • Provide deterministic export, offline verification, restore, corruption diagnostics, and clean-state initialization tests for the new store. Authority export/verify/tamper rejection and clean restore round-trips are covered by Control aggregate tests (authority_export_is_complete_and_semantically_verified_offline, clean_restore_stages_and_round_trips_the_exact_authority); payload-owner restore coordinators and crash-checkpoint suites exercise the broader installation restore path.
  • Keep async callers non-blocking through an async database driver or a bounded dedicated store executor. ControlStoreExecutor owns a dedicated a3s-use-control-store worker thread with a bounded request queue; async callers only await oneshot replies and never run SQLite on the Tokio runtime. Concurrent multi-thread verify (bounded_executor_keeps_concurrent_async_callers_progressing) and a current_thread responsiveness proof (bounded_executor_keeps_current_thread_runtime_responsive_during_store_work) cover the ADR-003 isolation claim.

Exit gate: a process failure cannot expose a combination of graph, Grant, enablement, operation, and capability metadata that never committed together.

Implementation order is fixed by ADR-003. In particular, the SQLite backend must not become a mirror beside the current JSON stores. The preparatory extraction of installation-snapshot persistence from shared package-graph file I/O gives the coordinated cutover an explicit replacement boundary; it does not complete an A2 checkbox by itself. Production activation must switch the complete mutable control aggregate and its reachability, diagnostic, backup, and restore readers together.

The checked-in coordinated cutover contract now records production activation (production_authority = "control-store", control_store_activation = "active", clean-state-only). Cognitive-package install/upgrade/uninstall/enablement and Host observation open Control only; legacy mutable leaves fail closed at installation open. Product CLI install, enablement, and Host graph completion now read Control operation evidence and Control-backed installed extensions (no legacy extensions/ receipts). Product graph recovery and production activation now prove Control EffectsPending survives process restart and resumes by exact operation identity without generation inflation; legacy journal/pending/registry kill suites are obsolete under Control. Archive extraction/staging kill recovery and uninstall artifact retention are Control-native. Native-launcher Tool surfaces no longer require Runtime plan publications. A2 Control Store checkboxes are closed on evidence (typed SQLite authority, outbox effects, inventory derivation, export/verify/ restore suites, dedicated store executor). Production readers no longer open unused legacy mutable leaves (package-enablement/, operations/plugins, operations/package-graphs, installation-snapshot.json, grants/, extensions/ receipts) as authority beside Control; capability projection is Control-only. Coordinated backup inventory under Control is derived from the Control export plus the registered external payload-owner live locations (not the legacy installation_state_layout allowlist). Control-native Host Grant recovery (install/upgrade/uninstall reopen + offline replay without reauthorization) and EffectsPending kill/resume are proven; legacy grants/.operations kill suites are obsolete under Control. Host pre-admission cancel now uses Control observation + Host cancellation + retained diagnostic history only (no operations/package-graphs write). Host lifecycle binding composition uses Control-authority payload roots (payloads/{runtime,knowledge,flow}-bindings) instead of legacy bindings/{runtime,knowledge,flow} leaves. This activation does not close A3, Registry, or ops GA gates by itself.

The inactive src/control_store/ kernel now qualifies most of ADR-003 step 2 for a clean installation. Schema v11 binds one exact InstallationId and stores contiguous installation generations, canonical complete reviewed Plan envelopes, versioned authorization evidence, exact snapshots, full Workspace Grants, provider bindings, capability candidates, lifecycle checkpoints, and an idempotent effect outbox behind relational and compare-and-swap constraints. Plan and authorization bytes are bounded canonical JSON; operation ID, both digests, action, root package, installation scope, and generation cursors are derived and revalidated against relational projections after restart, in offline export verification, and during staged restore. Selected packages now keep immutable lifecycle generation separate from installation generation and desired-state generation. A pure projection derives the complete next snapshot, per-package desired-state generations, and globally monotonic lifecycle incarnations from the exact reviewed Plan, prior generation, and bounded committed history. Database commit, offline export verification, and staged restore all recompute it. Authorization evidence v2 persists only the exact prior Grant snapshot, reviewed change set, and confirmation facts. The same projection re-finalizes full target Grants and their independent receipt revisions, retains unrelated active Grants, and rejects caller-selected Grant bytes, digests, or revisions. The projection covers all five actions, User and Workspace installations, multiple roots sharing a dependency, and removal followed by reinstall without reusing a package identity; callers can no longer select these fields. The same projection now derives the complete dynamic provider selection for every enabled Tool and MCP surface from canonical reviewed Plan evidence and the exact prior generation. It preserves unrelated package selections, removes disabled or removed surfaces, and stores canonical provider build, capability, semantics, and enforcement evidence with a derived digest. Static Flow, OKF, Skill, and UI host ownership is not fabricated as Runtime selection. The candidate capability descriptor digest is independently derived from the exact target snapshot, package lifecycle identities, Grant revisions, and provider selections. It intentionally contains no endpoint, readiness, compiled artifact, or Knowledge application claim; those facts can exist only as typed post-commit observations. The projection also derives the complete bounded external-effect inventory. Only work that cannot join the local transaction enters the outbox: surface-prepare, capability-cutover, calls-drain, surface-stop, and surface-remove. Package selection, lifecycle identity, Grants, and reviewed provider selection are transaction facts, not pseudo provider effects. Installation and enablement prepare dependency surfaces before dependants and then cut over. Upgrade prepares the candidate, cuts over, drains prior calls, and removes prior surfaces in reverse dependency order. Disable and uninstall cut over before drain and reverse-order retirement. Each intent binds a typed Capability Index, invocation-lease, Runtime, Flow, Knowledge, Skill, or UI owner; Runtime effects carry the exact reviewed provider selection. Optional selected surface preparation may be rejected without blocking cutover, while its required dependency closure and every teardown remain required. Sequence, owner, policy, generation, and a domain-separated idempotency key are all derived rather than accepted from callers. Payload bytes, digest, and relational projection commit together and survive restart and offline verification. Claim and completion rebind every payload to the committed generation and reject an incomplete checkpoint/outbox inventory. Applied outcomes now retain a canonical owner-specific application descriptor, not a caller-selected success digest. It binds the exact effect identity to Capability Index or invocation-lease receipts, the reviewed Runtime selection and portable Task/opaque gateway: Service readiness evidence, or Flow artifact, Knowledge projection, and Skill/UI content digests. Deferred, rejected, and unknown outcomes retain diagnostic evidence only. Deferred is allowed only when the owner proves that it accepted no effect; a bounded durable not-before time then permits automatic same-key retry without reconciliation. An applied capability-cutover observation atomically retires the prior publication, publishes the candidate, and advances the capability cursor before drain or teardown. A required failure after that boundary remains effects-pending for explicit same-key reconciliation and cannot roll back the published generation; terminal completion must follow every observation. Typed commands prove atomic transition rollback, action/root-state semantics, terminal replay, pre-cutover required-effect rejection, post-cutover reconciliation, and explicit reconciliation of unknown or expired claims across restart. Its bounded canonical export includes the complete aggregate, is semantically verifiable without the live database, and supports clean-state staged restore with exact authority round-trip. WAL/full durability, foreign keys, exact-schema/integrity checks, linked-path rejection, and the 16-entry bounded worker remain qualified.

The inactive post-commit dispatcher now retains one installation-wide shared maintenance fence from claim through durable observation, claims one effect at a time, and leaves both the SQLite transaction and bounded executor before owner I/O. Seven separate typed ports cover Capability Index, invocation leases, Runtime, Flow, Knowledge, Skill, and UI; each can return only owner-shaped application evidence or an explicit deferred/rejected/unknown failure. A deferred observation binds a maximum-five-minute not-before time, blocks early claims, survives export and clean restore, and automatically retries only the original key when due. A hard provider timeout must leave a fixed observation budget inside the claim lease; timeout is recorded as unknown rather than being misclassified as rejection. Timeout and caller cancellation stop waiting but do not cancel the possibly accepted owner future; that detached task retains the same shared maintenance guard until it actually completes. Process exit after an accepted effect, an expired claim, and an unknown outcome all require explicit replay with the original committed idempotency key. Qualification tests prove commit-before-effect, Store re-entry during provider I/O, all owner routes, action/evidence compatibility, timeout bounding, task-panic classification, exact-key recovery, and that a concurrent restore cannot acquire its exclusive fence before observation or while a timed-out/cancelled effect remains in flight. Every successful claim now also projects its owner-shaped authority inside the claim transaction. Package owners receive only the exact committed package selection, lifecycle incarnation, host, snapshot identity, and Grant; Runtime additionally receives the complete reviewed provider selection. Capability Index receives the complete candidate generation and one latest terminal preparation for every enabled selected surface, including retained multi-root surfaces from earlier generations and explicit optional degradation. Missing Grant coverage, a nonterminal latest observation, teardown masquerading as preparation, or generation drift fails closed before provider I/O. The multi-root qualification exposed and fixed an immediate-foreign-key ordering defect: generation commit now writes the complete package node set before dependency edges and surfaces in the same transaction. The Artifact Store now supplies the corresponding non-cloneable verified read lease. Acquisition holds both coordinated read locks and binds one complete verified catalog record to the full package fingerprint, manifest digest, exact byte/file counts, manifest surface graph, surface-file validation, quarantine state, and incomplete-GC fence. The handle exposes no package root, bounded manifest reads precede ACL parsing, missing locks are not created by a read, and repeat verification detects uncoordinated tampering. The first real post-commit adapter uses that lease for immutable Skill and UI surfaces. It re-derives the typed owner and original idempotency key from committed portable fields, validates the exact package/lifecycle/host/snapshot/Grant authority, reads only the named surface, re-verifies the full package after the bounded read, and emits a stable path-free content receipt independent of retry claim metadata. Artifact lock or I/O contention becomes a safe durable deferral; tampering, missing content, and authority substitution become terminal proved-no-effect rejection; this read-only adapter has no unknown-acceptance state. Static stop/remove receipts require no artifact path or bytes. This is now joined by a real OKF Knowledge adapter. It revalidates the exact committed Knowledge owner and idempotency key, reads first-use OKF content as a path-free verified byte payload, stores staged receipt evidence before promotion, stores promoted evidence before returning applied, and can replay a retained promoted generation without Artifact access. Stage, promotion, removal, or post-effect receipt ambiguity is durable unknown evidence; pre-effect contention is a safe deferral; authority or immutable-byte drift is rejected. Stop is path-independent and remove is driven only by the retained receipt. A real SQLite composition test exercises committed claim, detached dispatcher coordinator, Knowledge materialization, and durable Control observation together. Artifact-only admission is now distinct from legacy lifecycle publication: it is idempotent, revalidates prepared bytes, creates no installation receipt, and requires its reference-admission guard to span the separate authority commit. The third real post-commit adapter now implements Capability Index and invocation leases as one Capability Plane boundary. It accepts a host-owned pure Agent-catalog projector only after validating the committed candidate and exact terminal surface evidence. It rejects projected descriptors outside enabled, prepared package incarnations, durably publishes the catalog, and materializes a canonical content-addressed Index document that binds the publication. Control's applied cutover observation advances the only mutable cursor with that catalog digest/generation/revision in one transaction. Admission reopens and rehashes the exact catalog before reading the cursor around shared locks for every package incarnation; drain requires an unpublished prior incarnation and an exclusive lock, safely deferring until accepted calls release it. Immutable publication is no-follow, no-replace, and crash-replayable. The Index and lease files remain derived operational state; the legacy coordinated inventory now registers and verifies the catalog and descriptor-snapshot payloads. The owner-native restore boundary now also has a ControlCapabilityPayloadRestoreCoordinator that binds both plans under one exclusive fence, preflights both targets, and replays fixed-order activation. A matching ControlCapabilityPayloadRetentionCoordinator now binds both retention plans under one exclusive fence, preflights both inventories and pending journals before the first unlink, and replays fixed-order deletion. A real composition test joins Knowledge, Skill, catalog/Index publication, exact payload admission, stale admission, and same-key drain retry. The inactive ADR-003 step-3 qualification now also includes a committed-authority Flow owner. It consumes a path-free verified source snapshot, durably publishes a no-clobber content-addressed source in its own workspace, and invokes only the typed a3s-flow Native TypeScript preflight. Compiler/cache paths are operational host configuration, never package authority; source substitution and failed preflight reject without a Control observation, while Artifact Store contention remains a same-key deferral. Stop/remove are path-independent receipts. The same inactive qualification now includes a committed-authority Runtime owner for release-backed Tool Tasks, Tool Services, and Streamable HTTP MCP. First prepare reads a verified, path-free Tool/MCP release payload and requires the injected plan/provider semantics to match the exact committed package and provider selection. Task preparation persists no Runtime unit; Services advance a durable requested -> runtime-applied -> gateway-ready record before committing the final binding. Exact final receipts replay without Artifact access, the final-binding/provisioning overlap reconciles without a second Runtime apply, and retirement verifies receipt-owned provider evidence before Gateway drain and Runtime stop/remove. Pre-effect contention safely defers; authority or immutable-byte drift rejects; every ambiguity after a Runtime, Gateway, or receipt effect remains unknown. The Runtime boundary now provides a bounded canonical plan payload and a restart-safe resolver that reconstructs the full plan from its committed semantics digest and rechecks exact provider evidence. The installation-scoped, host-owned RuntimeSurfacePlanStore is also qualified as a canonical digest-addressed payload source with bounded batch publication, no-clobber writes, restart-safe reads, and fail-closed tamper checks. An inactive lifecycle admission seam now accepts the canonical cognitive-package Plan envelope, authorization evidence, and optional planned Grant transition. It derives both prior Control cursors from the immutable Plan and accepts no caller-selected generation. Its combined qualification entry point retains one installation-wide maintenance fence while registering the exact reviewed operation, deriving the complete Control transition, validating exact Runtime prepare coverage and reviewed Grant proposal digests, publishing immutable plan bytes, and committing the projected generation. Production still needs to route the live lifecycle through this seam and complete the atomic dispatcher composition; a process-local selection must never become production authority, and no adapter may read legacy authority or treat a path as authority. This narrows the production cutover boundary without activating the private kernel.

Production lifecycle code still does not construct this kernel, and the live state layout, reachability, diagnostics, backup, and restore orchestration do not accept it as production authority. A private path-free registry contract now freezes all seven owner identities and their ACL backup policies. It excludes the global Artifact Store and requires an exact canonical receipt set for the remaining six owners, bound to one InstallationId, Control generation, registry digest, owner snapshot schemas, manifest/inventory digests, and bounded file/byte accounting. Deserialized evidence must pass the same semantic validation before hashing. This removes the duplicated owner-ID and policy list from the cutover test. A private snapshot session now binds the canonical Control export digest, generation, installation, and owner-registry digest under one exclusive maintenance fence, then releases the SQLite transaction and bounded-executor permit before owner I/O. The Knowledge owner now produces and offline-verifies a non-overwriting, size-bounded OKF SQLite/FTS5 archive plus canonical binding/selection inventory evidence. A missing Knowledge database is represented by a zero-file manifest without mutating live state, and linked owner roots fail closed. Snapshot creation and offline verification now also require the exact canonical Control export named by the binding. Every retained Knowledge lifecycle incarnation must map to its originating prepare intent and committed OKF bundle. Applied prepare evidence must match the retained observation and capability projection; removed or missing applied payload must have a same-incarnation remove effect. Deferred outcomes prove no owner effect and remain scheduling evidence; claimed and unknown outcomes remain explicit reconciliation evidence. None selects desired state. This code remains inactive and does not replace the legacy path scanner. An offline-verified Knowledge owner snapshot can now stage its exact SQLite database into a caller-owned directory beneath the target state root, re-audit the staged database and canonical binding/selection inventory, and activate only into a clean target while the exact installation-wide exclusive maintenance fence is held. Activation rejects linked paths, candidate drift, unowned live-layout entries, unexpected absent-state bytes, an existing live payload, and a guard for another root. It publishes by atomic rename and replays an exact completed partial. While the staged attempt and exclusive guard remain held, it also reconciles the post-publication/pre-result boundary without creating a second binding authority; the canonical result is path-free and snapshot-bound. The planning-and-diagnostic observation owner now has the second concrete snapshot and clean-target restore adapter. It uses the diagnostic-history, resolution-attempt, and download-attempt owners' own decoders and invariants instead of copying their schemas. Only terminal diagnostic histories and terminal resolution attempts enter the bounded no-clobber archive. Active resolution/download records and locks are excluded, while a canonical path/digest inventory of active records is bound to the manifest. Secure traversal, a second pre-publication scan, and offline verification reject links, moved or foreign records, unknown layouts, duplicate identities, substitution, trailing bytes, and registered bound violations. Receipts remain path-free and bound to the exact Control export. An offline-verified archive can be staged beneath the target state root without touching live owner paths. Activation requires the exact exclusive maintenance guard and a clean record inventory, atomically marks the archive as activating, and publishes each owner-validated record without replacement. Digest-named deterministic partials recover interrupted record writes; after activation starts, only an exact snapshot subset may replay. The final path-free result is bound to the owner manifest and inventory. This adapter is not connected to the legacy scanner. The Host protocol projection is now the third concrete snapshot and clean-target restore adapter. Its owner-native scanner treats immutable request-to-plan records, optional terminal outcomes, and cancellations as the only semantic archive sources. Operation lookup aliases and latest-enablement diagnostic indexes are derived: the scanner validates them against their source requests, rejects missing, stale, orphaned, linked, or unknown layouts, and excludes them from the archive. Exact and legacy cancellation aliases normalize to one canonical binding. A bounded no-clobber archive is published only after a second live scan and after every Host plan, outcome, cancellation time, completion result digest, package identity, desired state, selected surface, package generation, and capability generation is reconciled with the exact bound Control export. Receipt and observed-health evidence remain Host observations and cannot choose Control desired state. The path-free manifest and receipt support exact offline verification, explicit zero-file absence, and no-change Host requests without inventing an operation. An offline-verified snapshot can stage its archive and build a complete target-local Host owner root from exact semantic source bytes plus newly derived canonical operation and latest-enablement indexes. Legacy aliases and locks are excluded. Activation requires the exact exclusive maintenance guard and no existing live owner root, re-runs the owner-native semantic scan, persists a snapshot-bound activation marker, and atomically publishes the whole directory without replacement. Deterministic archive, record, and marker partial recovery covers every staged transition, and the same attempt reconciles the post-publication/pre-result boundary. Drift, links, rebinding, and preexisting state fail closed; absence creates no owner root and the result is path-free. This adapter remains inactive. The Restore Coordinator is now the fourth concrete snapshot and restore owner. Its owner-native scanner accepts only exact canonically encoded completed restore operations for the bound installation. It excludes the active marker and its exact operation while binding their bounded count and digest inventory, including marker-only handoff. Orphaned nonterminal operations, pruning or temporary residue, unknown entries, links, foreign installation history, and path/record rebinding fail closed. Snapshot creation performs a second scan before no-clobber publication; its path-free receipt and streaming offline verifier bind exact terminal bytes to the Control export, while empty or active-only history emits no archive. An offline-verified snapshot now builds an immutable target-local candidate. Activation requires the exact exclusive maintenance guard and an active whole-installation restore marker; it binds that stable marker identity plus exact before/source/target inventories before changing live state. It atomically retires only terminal directories, publishes the target without replacement, and leaves the current active operation untouched even as its status advances between replays. A marker-only handoff is valid. If a legacy whole-installation marker accompanies a 64-record source, the adapter applies the journal's native (completed_at_ms, started_at_ms, plan_digest) ordering and omits exactly the oldest source record to reserve the active operation's slot. The typed complete-set marker has no retained operation and preserves all 64 records. Any source collision with a retained active plan fails closed before pruning. Candidate, activation, retired, and deterministic publication-partial evidence make every local boundary replayable and tamper-evident, and the result remains path-free and snapshot-bound. This adapter is still qualification-only. The Runtime plan payload owner is now the fifth snapshotted owner: it captures immutable, installation-scoped plan envelopes, verifies complete key/plan binding, and restores them before Host projection activation. Runtime plan artifact digests are included in installation reachability scanning so cleanup cannot remove a blob still required by a committed plan. The Capability payload owner is now the sixth snapshotted owner: it captures the installation-scoped Gateway catalog and descriptor-snapshot family under capability-gateway, restores after Runtime plans and before Host projection, and keeps Index/leases excluded as operational state. Seeded Archive (catalog + descriptor-snapshot) complete-set round-trip is now tip-qualified alongside Absent; owner digests may be domain-separated from plain archive sha256. Tip also proves Archive fail-closed offline verify (trailing/truncated/rebound entry) and that planted capability-index / generation-leases stay excluded from complete-set bytes and clean-target restore. Production Control Store activation and backup/restore wiring remain open. The private complete-set snapshot coordinator now captures one canonical Control export and the Capability, Host projection, Knowledge, planning/diagnostic observation, Restore Coordinator, and Runtime plan snapshots under the same exclusive maintenance fence and timestamp. One canonical path-free manifest binds the exact owner registry, receipts, schemas, digests, and byte accounting. The coordinator streams a single staged archive outside all Use data and state roots, reuses each owner-native offline verifier, and publishes only the fully verified file with no-clobber semantics. Explicitly absent owners add no payload bytes, and the global Artifact Store remains excluded. This closes complete-set snapshot assembly and offline verification. The same offline-verified aggregate can now stage one deterministic clean-target restore attempt. A canonical path-free descriptor first binds the exact complete snapshot, installation, owner registry, Knowledge policy, and fixed seven-component set. One exclusive target maintenance fence is then retained while the Control database and all six owner-native candidates are built beneath the fixed .control-installation-restore directory. Control is reconstructed from the canonical export, checkpointed to one SQLite file, round-tripped semantically, and bound by durable physical digest evidence. No live Control, Capability, Host, Knowledge, observation, or restore-history path is changed. Exact retries and interrupted Control staging recover deterministically; target contamination, links, unknown entries, snapshot or policy rebinding, and completed-candidate drift fail closed. The complete-set coordinator now qualifies full ordered activation. Before durable intent, it revalidates every owner candidate and its clean live boundary. The immutable attempt descriptor remains the restore identity. A canonical activation.json journal binds that attempt to an immutable operation; the typed global .maintenance.restore.json marker binds the same identity and blocks ordinary shared access. The fixed owner order is Control Store, Runtime plans, Capability payload, Host projection, Knowledge, observations, then Restore Coordinator; every step follows journal, marker, owner effect, checkpoint. Each ordered checkpoint retains only the canonical path-free result length and a domain-separated digest. The Restore Coordinator additionally binds the exact complete marker bytes, length, and digest before history mutation. Reopening reacquires the exact exclusive guard, rebinds the same verified snapshot, attempt, owner registry, and Knowledge policy, and reconstructs or verifies every owner at its precise candidate/live boundary. Journal and marker partials, all seven post-effect/pre-checkpoint boundaries, the final checkpoint before retirement, and exit immediately after marker deletion converge. A missing marker is valid only beside the complete seven-checkpoint journal; out-of-order live roots, ambiguous markers, snapshot rebinding, links, and evidence drift fail closed. Exact completed replay performs no owner effect and can only resume bounded fixed-order retirement of the seven link-free staging trees. A real-child-process matrix qualifies 24 top-level durable exits, including each retirement boundary. The surviving canonical attempt.json and complete activation.json are the exact installation-bound terminal receipt. Legacy backup and artifact reachability exclude only that receipt; incomplete, extended, linked, or tampered evidence fails closed. Production Grant conversion, Runtime/Flow dispatcher composition, production backup/restore wiring, indivisible consumer cutover, and deletion of legacy mutable stores remain open on the A3/ops path. A2 Control Store checkboxes are closed on evidence (typed SQLite authority, outbox effects, inventory derivation, export/verify/restore suites, dedicated store executor including a current_thread non-blocking proof). Legacy mutable-store deletion and indivisible consumer cutover remain cutover follow-ups, not open A2 gates. Progress on prune-legacy: Host protocol store no longer dual-writes or fallback-reads pre–plan-digest operation/cancellation indexes (exact binding paths only); capability projection reads Control payload binding roots via for_control_authority instead of legacy bindings/*. The legacy CognitivePackageEnablementStore file writer under package-enablement/ is deleted; enablement projection/operation types and validators remain for Control diagnostics and recovery evidence only. Knowledge CLI restore observes Grants from the committed Control generation via ProductionControlLifecycle::observe_stored_workspace_grant on the for_control_authority path (legacy grants/ stays absent). Knowledge restore authority inventory and managed Knowledge lease acquisition likewise pin exact generations from the Control installation snapshot (validate_authority_inventory_control, acquire_control_knowledge_generation_leases); published Registry lease paths remain test-only. Fail-closed without Control: control_restore_fails_closed_without_control_installation_snapshot, control_knowledge_leases_fail_closed_without_control_snapshot. Capability Gateway snapshot leases pin the same Control selections via ExtensionRegistry::acquire_control_snapshot (packages projected from the Control installation snapshot into CapabilityUpstreamEvidence). Empty Control leases use acquire_empty_control_snapshot against ExtensionRegistrySnapshot::empty — never acquire_published_snapshot / registry.json. Projection fail-closes without Control (use.capability.control_required). Evidence: injected_registry_acquires_one_exact_use_snapshot_lease, snapshot_lease_fails_closed_without_control_store. Whole-installation restore validates live Control export authority under the exclusive maintenance fence (validate_live_control_authority) and fails closed without Control (use.state_restore_control_required); coordinated backup likewise requires Control (use.state_backup_control_required) and never reads published registry.json authority. Evidence: coordinated_backup_requires_control_store, control_state_restore_plans_against_control_export_authority. Operation diagnostics project Registry generation/digest from Control (control_registry_diagnostic_face); they do not read published_snapshot(). CLI Plugin Manager planning reads the same Control-owned Grant snapshot via CognitivePackageManager::planned_grant_snapshot and must never open WorkspaceGrantStore::from_extension_paths (that path's lock creates grants/ and fail-closes Control open). Production Grant commit evidence: production_apply_commits_grants_without_legacy_grants_leaf. PackageGraphAuthorization::lifecycle_unit (file-store Grant saga) is #[cfg(test)] only — production never opens WorkspaceGrantStore beside Control. CognitivePackageManager no longer stores an authority selector; construction still fail-closes via select_installation_authority. File-store WorkspaceGrantStore locks fail closed when control.sqlite3 is present (use.plugin.grant_store.control_authority_required) so hosts cannot materialize grants/ beside Control. CognitivePackageManager::ensure_control shares one open path with ensure_control_for_registry_lifecycle (default cached Registry trust when sources exist). OnceCell records whether signed description trust was injected; a later Registry/Gateway open that requires signed trust fail-closes with use.control.signed_description_trust_unavailable instead of silently keeping an unsigned projector. OkfKnowledgeRecoveryManager::from_extension_paths and the legacy bindings/{knowledge,runtime,flow} / operations/plugins store constructors are #[cfg(test)] only; production builds expose for_control_authority exclusively. InstallationSnapshotStore and PendingPackageGraphStore (legacy installation-snapshot.json / operations/package-graphs writers) are likewise compiled only for tests; those leaves remain in LEGACY_AUTHORITY_PATHS and fail-close beside Control. Production apply_reviewed_operation / pending-effect resume seed an empty unsigned descriptor-proof snapshot for the committed capability identity only when the published Gateway catalog has no descriptors (skill-only / catalog-empty). Non-empty Tool/MCP catalogs leave the snapshot absent until proofs are staged, so signed publish cannot conflict with an empty seed. As a cutover prerequisite, lifecycle intent v4 and operation v3 now bind every checkpoint key to the plan, installation kind and ID, package ID and generation, action, sequence, kind, and surface. This removes collisions between graph siblings before their effects enter one installation outbox.

A3 - Deliver the arbitrary-agent capability plane

  • Ship two standard MCP service entry points: a privileged Package Manager endpoint and a lower-authority Capability Gateway endpoint. Do not introduce a private Use JSON-RPC protocol. The Gateway embedding also exposes standard Streamable HTTP at /mcp with host-owned bearer, Origin, and bounded admission configuration.
  • Define portable CapabilityDescriptor contracts with opaque InvocationRef, ArtifactRef, EndpointRef, and ResourceRef values. Remove executable paths, package roots, provider release paths, and secrets from external JSON.
  • Let the Use Host resolve an invocation reference and retain the exact package-generation lease for the entire call, stream, or server connection; drain and retirement operate on those server-side leases.
  • Define consumer profiles. Generic coding agents receive standard MCP Tools, Resources, and Prompts; the typed profile/negotiation contract keeps optional A3S extension labels explicit without changing the universal contract.
  • Project negotiated Flow, UI, and Knowledge metadata for A3S consumers without weakening the lower-authority boundary. Principal-scoped discovery filtering remains a separate host policy seam. Path-free CapabilityDescriptorKind::{Flow,Knowledge,Ui} variants carry digest-bound extension payloads; they require the matching consumer extension, appear in extension_metadata_descriptors() only after negotiation, and are never compiled into MCP Tool/Resource/Prompt routes (gateway_projects_flow_ui_knowledge_metadata_only_for_negotiated_extensions).
  • Propagate standard MCP request cancellation through the Capability Gateway. rmcp RequestContext.ct now bounds Tool, Resource, and Prompt provider operations; cancellation drops in-flight provider futures and resolver/admission leases, with a typed secret-free boundary result when a response is still deliverable. Detached downstream work remains a host provider responsibility.
  • Require signed descriptions and JSON input/output schemas for every agent-visible Tool. Legacy executable-only Tool Tasks remain host-only until a schema-valid descriptor is bound to them. Grant Tool production cutover now admits only schema-bearing Tools through ControlCapabilityDescriptorProjection (Runtime attestation digests) and publishes signed v2 descriptor snapshots; ProductionControlHostDependencies::standalone_with_signed_catalog is the product constructor that re-verifies those envelopes on projection. Registry/TUF key-source binding is implemented: load_capability_description_trust_store reads the signed fixed target capability/description-trust-store-v1.json, registry-tools can assemble and verify it, and standalone_with_signed_catalog_from_registry / open_control_lifecycle_with_signed_trust inject only a VerifiedCapabilityDescriptionTrustStore. Product CLI wiring is closed for Gateway serve: a3s-use mcp serve gateway --registry-name <name> (or the configured default) calls ensure_control_for_registry, which loads the signed target through load_signed_description_trust_for_control and opens Control via open_control_lifecycle_with_signed_trust (no fixture keys). Empty Registry configuration keeps the unsigned preview projector (signed_trust_load_stays_optional_without_registry_sources, gateway_mcp_entrypoint_accepts_registry_name_for_signed_trust, capability_description_trust_store_loads_from_signed_tuf_target).
  • Expose bounded, catalog-authorized MCP Resources and Prompts through the standard resources/list, resources/read, prompts/list, and prompts/get methods. Resource URIs are opaque and exact-match checked; prompt arguments are closed against reviewed declarations; provider content is size-bounded, path-free, and held under the same generation lease as Tool calls.
  • Materialize one immutable Capability Index at lifecycle cutover and emit generation-change notifications. Remove fixed-interval full filesystem rescans and repeated asset hashing from the normal watch path. Control durably publishes and transactionally binds exact catalog/Index identities; reconcile_published_capability_gateway swaps a live session after cutover and fans out standard MCP list_changed to independent clients (control_cutover_reconcile_notifies_independent_client_list_changed). Hosts that retain a long-lived Gateway must still call reconcile after releasing prior-generation leases (Grant Tool upgrade lease fencing).
  • Add CLI/service wiring, fail-closed trusted confirmation for management apply, bounded authentication, authorization, rate limits, and secret-free diagnostics for both endpoints. Gateway HTTP bearer authentication, optional exact Origin policy, duplicate-header rejection, bounded in-flight and rolling-window admission, sanitized HTTP errors, an explicit pre-invocation provider authorization hook, and typed propagation of the host-authenticated transport/principal context are implemented; bounded HTTP token-to-principal mapping is now also available. Manager serve uses FailClosedPluginManagerConfirmationProvider so MCP never implies apply confirmation. Gateway serve loads Registry/TUF description trust via --registry-name / default into Control open and reopens the published catalog with production_gateway_invocation_provider() (Control Grant + Runtime receipt join; production_invocation_factory_requires_committed_control_grant). A host can inject a bounded, fail-closed CapabilityGatewayDiscoveryPolicy so authenticated principals receive frozen per-context Tool/Resource/Prompt views; this metadata boundary remains separate from invocation authorization. Provider errors are sanitized at the agent boundary (adapter_sanitizes_provider_errors_at_the_agent_boundary).
  • Prove one-endpoint discovery and invocation from independent Rust, TypeScript, and Python clients, including a container or remote client with no shared package filesystem. Cover install, live upgrade, prior-generation drain, uninstall, restart, and denied cross-scope access.

Implementation notes (2026-09-03): PR #192 landed the portable descriptor and catalog contracts plus an embedding CapabilityGatewayMcpServer that speaks standard MCP and dispatches through an injected provider. PR #199 then added an exact CapabilitySnapshotLease constructor path: the host acquires all callable package-generation leases in canonical order, rechecks the cursor, and retains the non-clone lease through Gateway clones and calls. PR #200 corrected a first-principles clock error in the catalog contract: catalog generation is the immutable publication generation, while each descriptor generation is its owning package lifecycle generation. A single publication may therefore contain independently upgraded packages, but it cannot contain two lifecycle incarnations of one package/surface identity. PR #202 adds shared host-configured in-flight and rolling-window admission to Gateway calls and Streamable HTTP. PR #203 adds duplicate-header rejection, native-client Origin compatibility, standard HTTP challenge/backoff headers, and a real independent Rust client test. These are contract and embedding increments only; the A3 exit gate remains open until live-host reference resolution, authorization, CLI wiring, and the independent client/recovery matrix are implemented. The HTTP transport remains caller-TLS/loopback only; authentication and rate limiting are endpoint safeguards, not a substitute for live reference authorization. The provider boundary now requires a pre-invocation authorize hook; denials are sanitized to use.plugin.capability_gateway_forbidden and never reach invoke, with no implicit allow implementation. A host must bind its principal and policy explicitly.

Implementation note (2026-09-23): Control composition exposes gateway_invocation_provider / ControlCapabilityGatewayInvocationResolver, which reopen the durable published cursor, validate the exact descriptor against the immutable catalog, and retain an external Control generation lease through authorize+invoke (proven by Control capability-plane and drain-busy tests). ProductionControlInvocationFactory joins the leased descriptor to a committed Control Grant and installed package selection before provider I/O; absence fails closed as use.plugin.capability_gateway_forbidden (production_invocation_factory_requires_committed_control_grant). For Tool/MCP it then discovers the durable Runtime plan key, reconnects the committed provider, loads the exact binding receipt, and verifies the receipt-owned provider lease before returning the handle. Missing provider selection fails as use.control.capability_gateway_provider_missing; missing plan/receipt fails as use.control.capability_gateway_runtime_binding_missing. Tool Task invoke uses the joined receipt; Tool/MCP Service invoke proves the provider is still healthy, then dispatches through ControlCapabilityGatewayEndpointRouter. Composition owns a shared ControlGatewayEndpointRouteTable: bind readiness is wrapped by RecordingControlRuntimeServiceReadiness, and production_gateway_invocation_provider() injects LiveControlCapabilityGatewayEndpointRouter, which resolves opaque gateway: identities to the loopback Runtime endpoint recorded at bind and forwards with the plugin native protocol (MCP Streamable HTTP tools/call, or Tool Service POST of Gateway-validated JSON to base_path). A missing route still fails closed as use.control.capability_gateway_endpoint_route_unavailable (live_router_fails_closed_without_route, live_router_forwards_tool_service_http_to_recorded_endpoint). FailClosedCapabilityGatewayEndpointRouter remains available for tests and non-production factory construction. Non-Tool/MCP surfaces remain Grant-only (use.control.capability_gateway_runtime_unavailable on provider I/O). Invocation authorize requires an authenticated principal (use.plugin.capability_gateway_forbidden when absent). Open also requires the descriptor surface to appear in the committed Grant permission ceiling. Product CLI wiring: a3s-use mcp serve gateway --scope-kind … --scope-id … [--registry-name …] loads the signed description trust store from the selected or default TrustedRegistry (when configured), opens Control through ensure_control_for_registry, and reopens the durable published Control catalog through ProductionControlLifecycle::serve_published_capability_gateway_stdio / open_published_capability_gateway with production_gateway_invocation_provider(). Optional --streamable-http [--bind …] [--token …] [--principal …] serves the same Control-backed session over loopback Streamable HTTP and prints endpoint metadata on stderr. Standalone Control composition now projects catalogs from the installation descriptor-snapshot store and mints opaque Gateway endpoint identities at bind (live loopback recorded by the composition route table). The A3 exit gate stays open until the independent Rust/TypeScript/Python client recovery matrix lands against this product endpoint. First evidence: independent_rust_client_discovers_control_published_gateway_without_shared_package_fs proves an independent Rust Streamable HTTP client can discover Control-published catalog resources through production_gateway_invocation_provider without a shared package filesystem; independent_rust_client_is_denied_with_wrong_gateway_token proves bearer auth fails closed for that same Control-backed endpoint; independent_rust_client_invokes_tool_task_under_committed_control_grant proves the same independent client can call_tool a Tool Task under a committed Control Grant after production admit+drain publishes the exact Runtime plan/receipt and Grant-scoped Tool catalog (FakeRuntime test-runtime provider); independent_rust_client_invokes_grant_tool_after_control_process_restart proves the same call_tool path still succeeds after dropping the admitting lifecycle and reopening ProductionControlLifecycle over the durable Control root (process-restart stand-in); independent_rust_client_grant_tool_denied_for_foreign_installation_scope proves a peer Workspace installation with its own Control root cannot observe or serve the Grant Tool publication, while the original scope remains invokeable; independent_rust_client_grant_tool_fails_closed_after_uninstall proves Uninstall retires committed Grants and Grant Tool discovery (empty tools list or no published Gateway); independent_rust_client_invokes_grant_tool_after_live_upgrade proves a real v2 package Replace under Grant + Runtime plan republication advances the capability generation and keeps independent call_tool working; independent_rust_client_grant_tool_prior_generation_drains_on_live_upgrade proves the gen1 Gateway session must release package-generation leases before Upgrade Remove/Prepare can drain, after which the replacement publication key differs and independent invoke succeeds on the new catalog; independent_typescript_client_invokes_tool_task_under_committed_control_grant proves an official @modelcontextprotocol/sdk Node client can list_tools/call_tool convert against the same Control-backed Streamable HTTP endpoint with only URL + bearer token (no shared package FS); independent_python_client_invokes_tool_task_under_committed_control_grant proves the official Python mcp Streamable HTTP client can do the same. Client scripts live under tests/independent_clients/{ts,python}/. The A3 independent-client discovery/invoke language matrix for Tool Task under Grant is now closed for Rust, TypeScript, and Python. Grant Tool cutover now admits agent-visible Tools only through ControlCapabilityDescriptorProjection (schema digests + Runtime release-descriptor attestation), and publishes a signed v2 descriptor snapshot whose envelopes reverify under the fixture trust store (grant_tool_publishes_signed_schema_bearing_descriptor_snapshot, strict/install/upgrade/uninstall/restart/cross-scope Grant Tool tests). Control Index cutover now also proves independent-client list_changed after reconcile_published_capability_gateway replaces a live session (control_cutover_reconcile_notifies_independent_client_list_changed). Remaining A3 checkboxes are non-client items (CLI/service authorization beyond the Gateway HTTP safeguards and signed-Tool Grant production cutover against live Code/managed hosts that inject real Runtime readiness). Registry/TUF key-source binding, Flow/UI/Knowledge projection, the Gateway --registry-name signed-trust Control open path, and product HTTP Gateway reconcile+drain-on-shutdown are closed on evidence. ProductionControlLifecycle::reconcile_published_capability_gateway exposes the composition reconcile seam for long-lived hosts after cutover (production_gateway_reconcile_is_unchanged_for_the_current_grant_tool_publication). Hosts must still release prior-generation Gateway leases before Upgrade Remove/Prepare can drain, then reconcile so clients observe list_changed. Product face now exposes ProductionControlLifecycle::gateway_cutover_activation and drain_and_retain_published_capability_gateway so long-lived hosts attach the composition cutover hook without reaching into the private composition module. open_control_lifecycle_with_host_ports accepts an injected ControlRuntimeServiceReadinessPort so managed hosts bind real Runtime Service endpoints instead of opaque gateway: placeholders (ProductionControlHostDependencies::with_injected_runtime_readiness). ManagedCognitivePackageLifecycleFactory::with_control_runtime_readiness carries that port into CognitivePackageManager::ensure_control; install / upgrade / uninstall admit lifecycle.runtime_plan_publications() from the managed RuntimeProviderSelection (empty for standalone/skill-only). Product mcp serve gateway --streamable-http now uses ProductionControlLifecycle::serve_published_capability_gateway_streamable_http, which watches the durable published cursor, reconciles the retained session, and drain+retains on shutdown (production_retained_gateway_watch_reconciles_then_drains_on_shutdown). Same-process graph hosts that retain a Gateway beside PluginPackageGraphLifecycleCoordinator still attach gateway_cutover_activation so reconcile runs before prior-generation drain. The embedding-host face is now public: ControlRuntimeServiceReadinessPort / ControlRuntimeMcpReadiness re-exported from cognitive_package, plus CognitivePackageManager::{ensure_control_for_registry,open_published_capability_gateway,gateway_cutover_activation,watch_and_reconcile_published_capability_gateway,drain_and_retain_published_capability_gateway,serve_published_capability_gateway_*} (public_control_runtime_readiness_port_is_nameable_for_embedding_hosts, public_cognitive_package_manager_gateway_face_after_grant_tool_install). A3S CLI product join injects Control readiness when a private Gateway exists (ControlGatewayReadinessPort, code_factory_forwards_injected_control_runtime_readiness) and forwards the managed RuntimeClientRegistry into Control open (runtime_client_registry, managed_factory_forwards_runtime_client_registry_to_control_open) so effect drain reconnects host providers. Runtime Task invoke pins Control-selected generations (RuntimeTaskDispatcher::invoke → acquire_control_lifecycle_generation) and fail-closes legacy publication authority. Published Capability Gateway hosts that retain an MCP session beside publication still attach gateway_cutover_activation. Engine fail-closes non-empty Runtime plan publications without Control readiness (use.control_store.runtime_readiness_required, managed_publications_without_control_readiness_fail_closed); opaque gateway: minting remains skill/native-only. Plugin readiness is saga-only documentation for the Control effect bind face. Legacy RuntimeBindingStore / Knowledge / Flow ::new constructors that write bindings/* compile only under #[cfg(test)].

The host can derive a Gateway catalog from one immutable CapabilityRegistrySnapshot through CapabilityRegistrySnapshot::capability_gateway_catalog. The bounded projection rechecks the snapshot cursor and public projection revision, package and manifest digests, reviewed publication-record evidence, selected surfaces, and ready/enabled package binding before constructing the canonical catalog. It accepts a consumer subset, but does not verify signatures or resolve opaque references on behalf of the host. CapabilityGatewayMcpServer::from_registry_snapshot acquires the matching RAII snapshot lease only after that projection and returns no server when the publication changes or is already draining. This closes the snapshot-to-catalog composition gap without claiming the remaining live resolver, receipt-owned provider, or multi-principal production wiring.

The verified live-host composition boundary is now explicit as well: CapabilityGatewayMcpServer::from_verified_registry_snapshot_with_factory_and_options observes one snapshot, consumes host-verified description proofs, captures the same cursor in CapabilityGatewayRegistryResolver, acquires the exact server lease, and retains consumer negotiation plus bounded admission policy. A publication race returns no server. The injected factory still owns receipt, Runtime, Grant, principal, and scope authorization, so the overall A3 exit gate remains open.

Implementation note (2026-09-04): the typed CapabilityConsumerProfile/CapabilityConsumerNegotiation contract now distinguishes the default generic-mcp consumer from an explicit a3s consumer. Extension requests are canonical, sorted, bounded, and digest-bound; fail closed when the host cannot support the complete requested set. The embedding Gateway retains the completed negotiation across its clones and leased constructors; legacy constructors remain generic-MCP by default. Descriptors can now carry a canonical requiredExtensions set, and every Gateway constructor projects the immutable catalog against the completed negotiation before compiling discovery or invocation routes. This closes the generic-consumer information-leak path. Path-free CapabilityDescriptorKind::{Flow,Knowledge,Ui} payloads are projected through the same negotiation filter and exposed via extension_metadata_descriptors() without becoming MCP Tool routes. A3 product CLI/service wiring and the signed-Tool Registry→Control open path are closed on evidence (ensure_control_for_registry / mcp serve gateway --registry-name, fail-closed Manager confirmation, and production_gateway_invocation_provider Grant/Runtime join).

Implementation note (2026-09-04): the standard MCP projection now includes catalog-authorized Resources and Prompts in addition to Tools. Resource references are opaque, exact-match checked, and never interpreted as paths or URLs; prompt arguments are closed against the reviewed declaration; every standard discovery list is deterministic, bounded, and cursor-paginated; and provider output is validated before it crosses the agent boundary. This does not yet project A3S-specific Flow/UI/Knowledge metadata or principal-specific discovery policy.

Implementation note (2026-09-07): Gateway discovery cursors now bind the MCP surface, negotiated catalog digest, frozen principal visibility indices, and offset in an opaque bounded v2 token. A client that misses a standard list_changed notification cannot apply an old offset to a replacement catalog; the request receives a stale-cursor error and can restart discovery. The session factory also treats a changed discovery-policy snapshot as a view cutover and emits list_changed, ensuring initialized clients are prompted to restart before they encounter that stale-cursor boundary.

Implementation note (2026-09-04): Gateway catalog projection now evaluates descriptor requiredExtensions against the immutable consumer negotiation. Unaccepted descriptors are removed before MCP route compilation, so they are absent from both list responses and direct lookup. Tool discovery is explicitly sorted because the underlying router uses a hash map; cursors therefore cannot silently reorder or skip capabilities between pages.

Implementation note (2026-09-04): the Gateway now exposes an explicit CapabilityGatewayDiscoveryPolicy seam for host-authenticated principal filtering. Policy decisions are evaluated once per trusted context and cached in a bounded OnceCell view shared by server clones, so tools/list, resources/list, prompts/list, and direct Tool/Resource/Prompt requests use the same stable visibility set. Denied routes behave like unpublished routes; policy errors are sanitized and fail closed, while the provider's per-call principal/Grant/generation authorization remains mandatory. Existing constructors retain an allow-all compatibility default, so production multi-principal hosts must opt in explicitly.

Implementation note (2026-09-04): the standard MCP adapter now consumes rmcp's per-request cancellation token. Tool, Resource, and Prompt provider futures are selected against RequestContext.ct; a cancellation drops the in-flight future before the adapter can validate or publish a result, releasing the short-lived admission permit and any resolver-owned invocation lease. The adapter returns the bounded use.plugin.capability_gateway_cancelled result when a response remains deliverable, while the server-wide snapshot lease is left available to other requests. Integration tests exercise real rmcp notifications/cancelled traffic for all three operation classes.

Implementation note (2026-09-05): Extension Registry watches now follow the atomic registry.json publication through a bounded cross-platform filesystem subscription instead of a fixed 50 ms read loop. Native notifications are preferred, with a bounded target-metadata probe running alongside them to cover platform backends that coalesce or omit an atomic replacement; an explicit metadata-only polling backend is retained when the native backend cannot be registered. Callback events are target-filtered and coalesced to one signal, and every wake-up re-reads the validated publication. CapabilityRegistry::wait_for_change no longer rebuilds, scans, and hashes the complete capability projection every 100 ms; it projects at subscription setup, after a real generation advance, and once at timeout to close the final race. The Gateway now exposes a bounded host-owned notification hub that registers initialized MCP peers, advertises all three standard list_changed capabilities, coalesces exact publication keys while rejecting older generations, and retires closed or back-pressured peers without introducing a private wire method. The hub is deliberately separate from catalog/session replacement: a host must durably publish the new immutable catalog, route new sessions to it, and retain old leases through drain. The roadmap item remains open until the complete agent-facing catalog is materialized into the lifecycle Capability Index and product hosts connect that cutover to the hub.

Implementation note (2026-09-05): CapabilityGatewayCatalogStore now gives the embedding host a durable owner for the exact Agent-facing catalog payload. It validates the installation scope and canonical bytes, stores bounded SHA-256-addressed records behind a cross-process mutation lock, uses no-follow checks plus deterministic staging and create-if-absent hard-link publication, and supports exact generation/revision reads after restart. Malformed top-level state, linked entries, tampered records, and over-bound inventories fail closed; incomplete regular staging artifacts can be replayed under the same digest. The store deliberately has no mutable current pointer, so payload durability alone does not select a live generation. The inactive Control composition now supplies the transactional binding described below and a restart-safe path to seed or replace a live Gateway session from its durable cursor; production activation, owner registration, lease drain, and retention remain required before the A3 catalog gate can close.

Implementation note (2026-09-05): CapabilityGatewaySessionFactory now gives an embedding host a bounded live-endpoint cutover seam. It serializes replacement of immutable servers, rejects cross-installation and stale publication generations, keeps consumer negotiation and lease mode stable, and routes each MCP operation through a current-server snapshot. A replacement is made visible before the shared standard list-change fan-out; old in-flight operations retain their prior immutable server and lease, while subsequent operations on the same endpoint observe the new catalog. This is an adapter mechanism, not the lifecycle authority: production Control activation, receipt-owned provider composition, lease retirement, and catalog-retention coordination remain open.

Implementation note (2026-09-05): the session factory now also offers from_published and replace_published. These paths read the exact installation/generation/revision/digest from CapabilityGatewayCatalogStore, re-project it for the server's completed consumer negotiation, and reject a missing, forged, tampered, or unpersisted catalog before the in-memory swap. The check covers the complete source catalog as well as its negotiated view, and replacement uses a conditional source swap so a concurrent local cutover cannot be overwritten after verification. The unverified compatibility method remains available for hosts with another persistence authority; selecting the Control-bound publication and retiring payload leases remain lifecycle responsibilities.

Implementation note (2026-09-06): Gateway session identity now follows the complete immutable source publication retained before consumer negotiation. Optional descriptor filtering therefore changes only the visible MCP view; Control lease matching, reconciliation, and drain continue to bind the full published cursor. Control projection validation also requires every retained descriptor to equal an exact descriptor in that publication, rather than checking package digests alone.

Implementation note (2026-09-05): catalog payload retention now has an explicit plan/apply protocol. The lifecycle owner supplies the protected digest set; the store emits a canonical inventory partition, rechecks the exact plan under its mutation lock, verifies each regular record before removal, fsyncs the affected shard, and supports read-only terminal replay. The store refuses an empty protection set for a non-empty inventory and never infers liveness from a mutable pointer. Control cursor and session-lease coordination remain the authority that chooses the protected set.

Implementation note (2026-09-05): retention apply now persists a bounded, canonical append-only recovery journal before each destructive unlink. It repairs a torn final record, reconciles an in-flight unlink against the immutable inventory after restart, blocks conflicting publication/planning, and exposes CapabilityGatewayCatalogStore::recover_retention so a host can resume from the journal's stored reviewed plan. This hardens the payload-owner recovery boundary; it does not choose the protected generations or close the session-lease lifecycle gate.

Implementation note (2026-09-05): inactive Control Store schema v11 now binds the immutable Agent-facing catalog to the actual capability publication transaction. A host-owned projection port receives only the committed candidate generation and terminal surface observations. The concrete Capability Plane rejects descriptors outside enabled, prepared package incarnations, durably publishes the catalog and canonical Capability Index, and returns their identities as one typed cutover application. Recording that applied observation stores the catalog digest/generation/revision and advances the published cursor in the same SQLite transaction. Admission reopens and rehashes the exact payload before taking package-generation leases; missing or tampered bytes fail closed. This closes the inactive-kernel cursor-binding mechanism, not production activation, complete receipt/Runtime/Grant-backed descriptor projection, production payload-owner restore/retention activation, or session drain coordination.

Implementation note (2026-09-05): the inactive Capability Plane now also has an explicit descriptor-evidence projector. It accepts only host-verified CapabilityDescriptionProof values and an immutable package-scoped signer allowlist. Every supplied descriptor is checked against the committed enabled package and lifecycle incarnation, exact catalog-record provenance, selected surface dependency graph, terminal prepared owner receipt, active Grant coverage, and reviewed Tool/MCP workload or transport before the projector derives domain-separated opaque invocation, endpoint, artifact, and resource references. Optional degraded surfaces and substituted owner evidence remain unpublishable, and projection failures are safe deterministic rejections with no payload write. This was a strict subset gate at the time of that projector change; cryptographic key custody, a durable cryptographic snapshot, production Runtime payload admission/receipt wiring, and production Control/Runtime/ receipt wiring remained open before the complete A3 catalog exit gate could close.

Implementation note (2026-09-05): the descriptor evidence boundary now has an installation-owned durable snapshot store for crash and restart replay. It captures the exact normalized proof set and package-scoped signer policy under a key bound to the installation, installation generation, capability generation, and candidate Control descriptor digest. The record itself is content-addressed by its canonical bytes, with bounded no-follow staging, create-if-absent publication, cross-process locking, exact canonical/digest revalidation, and no mutable current pointer. A durable projector reads only the exact Control-bound key; absent evidence defers safely, while substitution, tampering, duplicate keys, and unknown layout fail closed. The coordinated state inventory now recognizes and semantically verifies its canonical descriptor-snapshot records alongside Gateway catalogs; locks, staging, and retention journals remain nonterminal. The store is still an inactive external payload owner: key custody, production owner-native restore/retention activation, and Control/Runtime/receipt wiring remain open. Runtime Tool release planning now carries a canonical input/output-schema attestation through plans, binding receipts, and Control evidence; verified artifact admission and strict descriptor projection compare the same descriptor and schema digests. The implementation is qualified in the inactive kernel, while production lifecycle activation remains open. The signed v2 admission path described below now makes the retained envelope, rather than the proof projection, the cryptographic replay authority.

Implementation note (2026-09-05): the signed-description trust boundary now has a canonical SignedCapabilityDescription envelope in a3s-use-core and an Ed25519 CapabilityDescriptionTrustStore in a3s-use-extension. The envelope domain-separates the exact descriptor bytes, key/signer identities, and bounded validity window. The verifier owns no private keys, rejects identity, expiry, revocation, canonical-byte, and signature mismatches, and returns a private replay wrapper that must be reverified after restart. Multiple keys for one signer are supported for rotation, and schema-bearing Runtime Tool descriptors are required. The root Gateway facade now has signed- description constructors that verify envelopes before snapshot lease and provider-resolver composition; the legacy proof constructors remain only for explicit preview hosts. This qualifies the cryptographic mechanism and its composition seam but does not mark the A3 checkbox: Registry/TUF key-source binding and production Registry-to-Control lifecycle wiring remain open.

Implementation note (2026-09-05): the Control descriptor snapshot owner now has a signed v2 admission path. publish_signed verifies every canonical Ed25519 envelope before content-addressed publication and stores the exact envelopes beside a derived proof projection. A signed projector re-verifies those envelopes against the current trust store and clock on every replay; expiry, revocation, substitution, and proof/envelope mismatch fail closed. The legacy v1 proof-only snapshot remains an explicit compatibility path and is not allowed to consume a signed v2 record. This closes the Control proof-snapshot admission mechanism in the inactive kernel; official Registry/TUF key-source binding, production owner-native restore activation, and Registry-to-Control/Runtime/receipt wiring remain release gates. The paired owner-retention coordinator is qualified below, but lifecycle-selected retention policy is still a production authority gate.

Implementation note (2026-09-05): coordinated state backup now has an explicit CapabilityPayloads family for the two immutable Capability Gateway owners. The scanner admits only the catalog shard and descriptor-snapshot record layouts, verifies installation binding, canonical bytes, and content-addressed digests during inventory and archive verification, and rejects unknown paths, staging residue, mutation locks, and retention journals. This is a qualified legacy inventory/restore-plan boundary, not the A2 owner-registry cutover: production clean-target activation, lifecycle owner retention policy, and current Registry/TUF trust revalidation on signed replay remain required.

Implementation note (2026-09-05): Artifact Reachability now traverses the same Capability Gateway payload-owner tree instead of silently ignoring the new root. Catalog and descriptor-snapshot records are revalidated against their installation and content address; unknown nested paths, links, staging residue, and retention journals fail closed before a garbage-collection view is returned. The scanner intentionally emits no Artifact Store references for these opaque projections; lifecycle receipts remain the artifact authority.

Implementation note (2026-09-06): the Control descriptor-snapshot owner now supports the same explicit retention contract as the Gateway catalog owner. plan_retention names the protected digest set and the complete removal complement; apply_retention binds the canonical plan digest, rechecks every record under the owner lock, and persists one bounded checkpoint per unlink. recover_retention resumes the embedded plan after a process interruption, repairs only a torn journal tail, and blocks publication or inspection while the journal is pending. The non-empty inventory invariant prevents an empty protection set from deleting every snapshot. Production Control owner registration, clean-target restore activation, and Registry/TUF policy wiring remain separate gates. ControlCapabilityPayloadRetentionCoordinator now joins this owner with the Gateway catalog: it binds both child plans to one canonical digest, preflights both inventories and exact pending journals under one exclusive maintenance fence, and resumes catalog-then-descriptor deletion after an interruption. The coordinator is recoverable ordered deletion, not a cross-directory atomic transaction; lifecycle retention policy and production owner registration remain outside it.

The coordinator now also persists a bounded canonical a3s.use.control-capability-payload-retention-journal.v1 before the first unlink and checkpoints catalog completion before advancing to descriptor snapshots. A restart can reopen the exact reviewed pair; ordinary owner publication/reads, clean restore, state backup, and artifact reachability are blocked until that journal is recovered and retired. This is durable ordered convergence rather than a cross-directory atomic transaction, so lifecycle retention policy and production owner registration remain release gates.

Implementation note (2026-09-06): CapabilityGatewayCatalogStore now also exposes an owner-native clean-target restore boundary. A reviewed plan binds the installation, canonical byte counts, and the complete digest-sorted inventory; apply re-derives every supplied catalog, stages and rescans a full candidate tree, persists a plan-bound activation marker, and publishes with a no-clobber directory move. Existing owner state is never merged or replaced, foreign staged plans are rejected, and a durable candidate/marker can be replayed after interruption. This closes the catalog half of the restore primitive, but descriptor-snapshot restore, Control owner registration, signed replay policy, session drain, and production rollback coordination remain release gates.

Implementation note (2026-09-06): the Control descriptor-snapshot owner now has a matching plan-bound clean-target restore adapter. The reviewed inventory binds snapshot and key digests, Control generation identity, canonical byte counts, and signed/proof-only mode. Apply re-derives every snapshot, requires current trust-store verification for signed v2 evidence, stages and rescans a complete candidate, persists a plan-bound activation marker, and publishes without clobbering an existing owner. Durable candidate/marker evidence is replayable after interruption, while foreign staged plans and retention journals fail closed. The remaining gate is production Gateway reconstruction from the reopened Control lease and Registry/TUF-to-owner authority, not another local payload writer.

Implementation note (2026-09-06): the two immutable Capability owners now have one ControlCapabilityPayloadRestoreCoordinator. Its canonical plan binds the catalog and descriptor child digests, validates both source sets (including signed trust re-verification) and both clean targets before the first payload publication, and holds one installation-wide exclusive maintenance fence through fixed catalog-then-descriptor activation. A stop between owner boundaries is recoverable by replaying the same plan; the coordinator intentionally makes no cross-directory atomicity claim. Live Gateway session reconstruction, lease drain, lifecycle retention policy, and Registry/TUF authority binding remain open.

Implementation note (2026-09-06): the inactive Control composition can now reopen its published Capability generation directly from durable Control authority after a restart. The caller supplies no cursor. The Capability Plane reads the committed cursor, verifies the exact immutable Index and catalog, acquires every bound package-generation lease in canonical order, then rereads the Control cursor so a concurrent cutover returns stale rather than exposing a mixed graph. The composition now uses that lease as an internal Gateway generation guard, so every cloned server retains it and the session factory cannot replace a leased endpoint with an unleased server. Production live Control activation, owner registration, lease drain, lifecycle retention policy, and Registry/TUF authority binding remain open.

Implementation note (2026-09-06): graph lifecycle now exposes the replay-safe PluginGraphCapabilityCutoverActivation hook. It is invoked after the durable capability publish (or its exact replay) and before any prior generation drain. The inactive Control composition supplies a concrete adapter that reopens the Control cursor, requires an external Control lease on the live factory, rejects a newer in-memory endpoint, and treats an identical catalog as an idempotent no-op. The inactive composition now also derives the durable current catalog/descriptor protection set for retention and applies a reviewed plan only after rechecking the cursor under an exclusive maintenance fence. Production hosts still need to attach this adapter, add any independently managed rollback identities, and retire payloads in one host transition.

The adapter now binds the callback's opaque key to the reviewed operation that owns the published cursor (following that cursor's installation generation, not the merely current generation). Stale graph replays and callbacks against enablement-only publications therefore fail closed instead of activating an unrelated endpoint.

Implementation note (2026-09-06): the inactive Control composition now also provides a Control-backed opaque invocation resolver. Each operation reopens the durable published cursor, validates the complete descriptor against the immutable catalog before provider state is opened, and retains that exact Control generation lease through the returned invocation handle. A host-owned factory receives the lease for its principal/Grant/Runtime binding; forged or cross-generation descriptors fail before provider I/O. Production lifecycle wiring and legacy-authority deletion remain open as cutover follow-ups; the Control-backed invocation resolver and product Gateway join are closed.

Implementation note (2026-09-06): destructive Capability payload retention now has one cursor-bound composition path. It always protects the catalog selected by the durable Control cursor and, when descriptor snapshots are present, the key-matched proof snapshot; a cursor change or plan that would remove either payload is rejected before unlink. Both standalone owner apply_retention entries also take the installation-wide exclusive maintenance fence, so a live Control snapshot/Gateway lease cannot be bypassed. Hosts may add explicit rollback or legacy endpoint digests, but liveness is never inferred from an in-memory current pointer.

Implementation note (2026-09-06): CapabilityGatewaySessionFactory::drain now provides an explicit endpoint-retirement boundary. It serializes with replacement, closes admission for every live adapter clone, waits for already admitted operations under a caller deadline, and detaches the source generation lease only after the operation count reaches zero. A timed-out attempt remains non-admitting and can be resumed; independent immutable server clones retain their own leases until dropped. Lifecycle hosts can therefore call drain before entering the exclusive Capability payload retention fence; the inactive Control composition provides one helper that performs that drain-and-retain sequence against its durable cursor.

Implementation note (2026-09-06): the Control composition now reads the published capability cursor and its owning operation from one SQLite snapshot, then reacquires the exact cursor before constructing or swapping a Gateway endpoint. Destructive drain-and-retain additionally requires the supplied session's catalog identity and Control-issued external lease to match that cursor; copied catalogs, unrelated leases, and cursor changes during drain fail closed before payload unlink. This closes the remaining in-process session identity/TOCTOU gap, while production host wiring and independent rollback authority remain release gates.

Implementation note (2026-09-06): the live session boundary now retains a one-shot, typed identity proof when a Control-bound endpoint finishes draining. An exact lifecycle retry can therefore repeat drain-and-retain after the source lease has been detached, while a directly drained or copied unleased server cannot manufacture that proof. Replacements built from a stale local snapshot also use a conditional source compare-and-swap; if another cutover wins, the attempt returns a retry signal instead of overwriting the newer same-generation projection. These are local convergence mechanisms; production Control publication and rollback authorities still have to coordinate the durable cross-process transition.

Implementation note (2026-09-04): Runtime Task publication and dispatch now cross-bind each durable receipt to the installed package's retained planning evidence and exact release descriptor digest. Registry-trusted packages must retain catalog-bound signed planning evidence; substituted descriptors, cross-generation bindings, and missing evidence are omitted or rejected before provider connection. Local explicit packages retain their host-owned qualification path. This closes a Runtime integrity gap but does not complete the broader A3 receipt/Runtime/Grant authorization or independent-client exit gate.

Implementation note (2026-09-03): PR #197 added a secret-free error projection at the Package Manager MCP boundary. The adapter retains only validated use.* contract codes and a bounded public message; paths, URLs, suggestions, details, provider-owned identifiers, and package-authored diagnostics are omitted or collapsed to a generic code. This is defense-in-depth for the existing adapter, not an A3 exit-gate claim. The Gateway HTTP edge now adds endpoint bearer authentication and bounded admission, and the injected provider exposes a sanitized pre-invocation authorization seam; the HTTP for_principal/for_principals configuration now carries the selected verified principal into both provider hooks without exposing it to agents. PR #208 adds the lease-scoped resolver and bounded multi-principal mapping. Production host receipt/Runtime/Grant composition, product Gateway/Manager wiring, and the independent-client recovery matrix are closed on the A3 evidence above; A5 Registry custody/publication and A4 provider inversion remain separate exit gates.

The embedding seam is now explicit: PR #208 adds CapabilityGatewayInvocationResolver and CapabilityGatewayResolvedProvider, which perform one resolution and authorization for each call before invoking a private lease. The handle implementation owns the exact package-generation guard and must retain it until the invocation returns. The same PR adds a bounded 64-entry immutable HTTP token-to-principal registry with duplicate-token rejection and complete credential scans. Production composition now joins those host embedding contracts to Control Grant + Runtime receipt authority through production_gateway_invocation_provider(), product CLI Gateway serve, and the independent Rust/TypeScript/Python client matrix under committed Control Grants.

Exit gate: an arbitrary MCP-capable coding agent can discover and invoke an authorized package without an A3S SDK, local package path, or duplicated lifecycle implementation. Closed on evidence (A3 checkboxes above, including independent-client discovery/invoke and product Gateway/Manager serve paths).

A4 - Invert providers and reduce facade coupling

  • Make the Use Engine own lifecycle coordination, journaling, retries, and recovery. Factories inject a typed ProviderSet or lifecycle ports; they do not construct and return concrete coordinators. Closed on evidence: LifecycleProviderSet carries journal + PluginLifecycleHosts; factory methods are *_providers returning that set; LifecycleProviderSet::into_coordinator is the engine-owned construction path (factories_inject_provider_sets_without_constructing_coordinators, managed_factory_uses_the_embedding_hosts_ui_composition).
  • Negotiate the actual supported operations, surfaces, protocol versions, concurrency guarantees, and provider readiness. Remove default trait methods that make unsupported behavior appear supported. Closed on evidence: CognitiveLifecycleSupport is required on CognitivePackageLifecycleFactory; planning/retirement/enablement and flow_compiler_binary no longer have default bodies that fake support; Standalone vs Managed declare distinct surface sets (lifecycle_factories_declare_supported_surfaces_without_default_trait_fiction).
  • Treat Browser, OCR, Box, Runtime, Flow, and UI integrations as provider components or ordinary first-party packages. A bundled profile may install them for convenience, but the universal engine and capability projection do not hardcode their domains. Closed on evidence: CapabilityRegistry::snapshot only projects CapabilitySeedProvider seeds; bare CapabilityRegistry::new uses EmptyCapabilitySeeds and publishes no use/browser|ocr|box (universal_engine_registry_projects_no_hardcoded_first_party_domains); standalone product from_env injects BundledFirstPartyCapabilitySeeds (bundled_product_profile_projects_browser_ocr_box_as_injected_seeds). Runtime/Flow/UI remain host-injected lifecycle ports.
  • Split the current all-purpose capability binding into consumer catalog, invocation binding, and operation diagnostic views so management evidence and local provider details cannot leak into agent discovery. Closed on evidence: agent discovery uses CapabilityGatewayCatalog / CapabilityGatewayMcpServer; invocation uses CapabilityGatewayInvocationProvider / CapabilityGatewayResolvedProvider with generation leases; management diagnostics stay on Package Manager / Host observation paths with secret-free projection (adapter_sanitizes_provider_errors_at_the_agent_boundary, Package Manager MCP error sanitization).
  • Keep A3S Flow and UI as negotiated consumer extensions over the same package generation; do not make A3S-specific surfaces mandatory for generic agents. Closed on A3 evidence: CapabilityDescriptorKind::{Flow,Knowledge,Ui} plus gateway_projects_flow_ui_knowledge_metadata_only_for_negotiated_extensions.
  • Refactor along the target boundaries before creating more repositories: contracts, catalog/artifacts, control store, engine, host/gateway, and provider adapters. Split oversized files when responsibility moves; do not add forwarding facades or duplicate registries. Progress: first-party Browser/OCR/Box projectors in capability_registry/product_seeds.rs; Control-authority extension projection in capability_registry/extension_projection.rs; unit tests in capability_registry/registry_tests.rs. Facade capability_registry.rs is under the ~1000-line split threshold with lease/mcp/runtime_tasks retained as sibling adapters (universal_engine_registry_projects_no_hardcoded_first_party_domains). Capability Gateway root capability_gateway.rs is now a thin public contract (~284 lines) with protocol.rs, server/{mod,compose,handler}.rs, and session_factory/{mod,live,helpers}.rs siblings (each under the ~800 line focus band); Control-native empty lease/composition/signed-admission tests are green (capability_gateway:: 53 passed). Control composition is now composition/{mod,gateway}.rs (mod ~778 / gateway ~495; control_store::composition 8 passed). Capability payload owner is capability_payload/{mod,archive,filesystem,helpers}.rs (each under the hard 1000-line cap; payload_capability_payload 5 passed). Runtime plan payload owner is runtime_plans/{mod,archive,filesystem,helpers}.rs (payload_runtime_plan green). Control Store aggregate claim/observe/complete mutations live in aggregate/dispatch.rs (~446) with root aggregate.rs under the hard 1000-line cap (~855). Descriptor-snapshot store/restore are split via #[path] siblings (descriptor_snapshot_store.rs + descriptor_snapshot_store_io.rs; restore {helpers,layout,filesystem}.rs) — every non-test Control Store source file is now under the hard 1000-line cap (descriptor_snapshot 12 passed). Cognitive-package production owners that were over the hard 1000-line cap are split without forwarding facades: plan_tests.rs / provider_plan_tests.rs / hosts_tests.rs via #[path]; host_store_io.rs, upgrade_apply.rs, diagnostic_queries.rs, diagnostic/validation_pending.rs, and diagnostic/projection_lifecycle.rs via include!. The same hard cap is now held for every non-test crates/use/src/**/*.rs production leaf by additional splits: plugin_runtime/plan_store_io.rs, plugin_lifecycle/{coordinator_execute, coordinator_helpers,graph_upgrade}.rs, okf_knowledge/recovery_validate.rs, capability_catalog_store/restore_prepare.rs, and cli_mcp.rs. Extension production leaves that were over the hard 1000-line cap are split the same way: registry_bindings.rs, remote_prepare.rs, surface_files_io.rs, and registry/lifecycle_publish.rs (cargo check -p a3s-use-extension --lib and cargo check -p a3s-use --lib green). Evidence: no non-test production .rs under crates/use/src or crates/use/crates/{core,extension}/src exceeds 1000 lines (test modules such as registry_tests/cognitive_lifecycle.rs remain). Remaining open A4 work: large test modules and crate-level boundary repository splits (contracts / catalog / engine / host-gateway / provider adapters as separate repos — not more file splits inside Use).

Exit gate: the core engine runs against deterministic in-memory providers, and each product host composes only the providers and consumer extensions it owns.

A5 - Build and operate the official Registry

Decision: rename A3S-Lab/Use-Packages to A3S-Lab/Use-Registry before the first production bootstrap root is created. The current repository already contains admission material, registry/ TUF state, immutable targets, and Registry verification; Use-Packages incorrectly suggests a package-source monorepo. The pre-initialization rename avoids creating a second trusted source identity later.

  • Rename the GitHub repository and root submodule path to use-registry/; update .gitmodules, remotes, documentation, tests, CI, and examples in one reviewed change. Do not compile the official URL into the resolver. Root evidence: .gitmodules pins use-registry → git@github.com:A3S-Lab/Use-Registry.git; monorepo README modules list Use Registry at use-registry/.
  • Treat any preview configuration using the old address as an explicit source replacement: re-add the renamed source with its pinned bootstrap-root digest. Do not silently turn a GitHub redirect into trust authority. Registry source identity remains name/URL/bootstrap-root digest; redirects never become trust authority (registry-cache-operations.md).
  • Keep package source, build logic, and releases out of Use-Registry. Use-Registry accepts reviewed admission records, immutable release artifacts, provenance, SBOMs, and signed TUF publication state. Enforced by README ownership boundary plus registry-staging-gate ownership-layout rejecting packages/, src/, and Cargo.toml in the Registry tree (docs/staging-ci.md).
  • Add package-authoring commands for lint, deterministic build/pack, manifest and expanded-content digesting, permission review, provenance verification, and isolated install tests. These formats and commands are versioned by a3s-use, not reimplemented by the Registry repository. Landed as a3s-use-registry-tools lint|pack|assemble|verify over a3s_use_extension::lint_package_directory (ACL parse, README + surface file review, expanded fingerprint) plus deterministic pack and released- client verify (skill_package_lints_before_pack, lint_fails_closed_when_skill_file_is_missing). Isolated install against a live Control installation remains a product CLI/Host matrix item, not a second Registry-owned format.
  • Add Registry assembly and verification commands that preserve canonical catalog metadata, validate the complete staged tree with a released client, and produce a reviewable publication delta before signing. Landed as crates/registry-tools (a3s-use-registry-tools keygen/pack/assemble/verify) on Use main via #256. Threshold custody, rotation, expiry, mirrors, and withdrawal are exercised in-tree; official production bootstrap publication remains on the production channel checkbox.
  • Document and exercise offline threshold root custody, online snapshot/timestamp custody, expiry monitoring, every-intermediate-root rotation, emergency withdrawal, mirror replacement, and rollback recovery. Operator documentation for keygen/assemble/verify custody, threshold root ceremony (--root-share-count / --root-threshold), offline recovery, rotate-root (retain metadata/root.history/, require new bootstrap pin), check-expiry, compare-mirrors, and withdraw-targets is in docs/registry-key-custody.md. Exercised in registry-tools: single-operator offline assemble/verify + pin-stable recovery (offline_custody_recovery_rebuilds_the_same_bootstrap_pin); 2-of-3 threshold ceremony + under-threshold fail-closed (threshold_root_ceremony_assembles_and_verifies_with_two_of_three_shares, threshold_assemble_fails_closed_when_too_few_root_shares_are_present); every-intermediate-root rotation + mismatched-custody fail-closed (root_rotation_retains_the_previous_root_and_requires_a_new_bootstrap_pin, root_rotation_fails_closed_when_previous_keys_do_not_match_published_root); expiry monitoring (check-expiry) with near-expiry fail-closed (check_expiry_passes_for_a_freshly_assembled_registry, check_expiry_fails_closed_when_metadata_expires_inside_the_warn_window); mirror compare (compare-mirrors) with drift fail-closed (compare_mirrors_accepts_identical_trees_and_rejects_drift); emergency withdrawal (withdraw-targets) keeps the bootstrap pin, removes target bytes, and verifies an empty catalog (withdraw_targets_removes_a_package_while_keeping_the_bootstrap_pin). Multi-signer TUF targets-role delegation is deferred until Use-Registry admits independently signed package authorities; GA custody uses one online targets key outside the git tree. Production bootstrap publication and live mirror promotion remain on the production channel checkbox below.
  • Publish a staging channel through reviewed GitHub CI with no signing key in the repository or package-manager client. Staging gate in Use-Registry (.github/workflows/registry-staging-gate.yml, docs/staging-ci.md) fail-closes on keys-in-tree / ownership bleed and, when admissions + REGISTRY_TOOLS_REF + REGISTRY_STAGING_KEYS_DIR are present, runs real assemble + verify + check-expiry with environment-injected keys (no trust-root push).
  • Publish the production channel through reviewed GitHub CI with no signing key in the repository or package-manager client. Retain witness, provenance, SBOM, and prior-generation recovery evidence outside the mutable delivery boundary. Offline ceremony checklist: Use-Registry docs/production-bootstrap.md. Progress: Use-Registry now carries registry-production-gate.yml + docs/production-ci.md that fail-close keys-in-tree / package-source bleed / in-git registry/, and arm assemble+verify+expiry only for admissions/production*.acl with environment-injected REGISTRY_PRODUCTION_KEYS_DIR (never pushes a trust root). Live signed publication, witness retention, and production mirror promotion remain open.
  • Keep MHS adapter source in an owning external repository (linked as crates/mhs only when that ownership exists) and publish only its signed package artifacts and admission records through Use-Registry. Progress: research-preview contract fixture lives under crates/extension/fixtures/packages/plugin-v3-mhs-bridge with profile docs/mhs-integration.md. crates/mhs is intentionally absent until an owning MHS adapter repository exists; do not invent a Use-owned hardware crate. Admission through Use-Registry remains blocked on that external ownership plus production Registry operation.
  • Express MHS through existing MCP, Flow, Skill, Knowledge, and optional UI surfaces. Do not add a hardware-specific package surface or private protocol. Closed on evidence: the research-preview fixture and catalog contracts reuse only standard surfaces (docs/mhs-integration.md Test scope); extension-crate MHS profile tests are green (cargo test -p a3s-use-extension --lib mhs → 2 passed). Full A6 lab qualification remains on the virtual-laboratory checkbox below.
  • Keep the virtual industrial laboratory in its own repository. Its simulator connects through the same MHS control-gateway contract used by physical adapters and is test infrastructure, not Use runtime code. Exit criteria for that external lab are listed under docs/mhs-integration.md (Enterprise GA / A6 exit).
  • Model read operations as safe observations and physical mutations as explicitly authorized operations with idempotency evidence or an unknown-outcome state. Never retry an ambiguous device mutation implicitly. Progress: research-preview flows/monitor.ts schedules observation with retry: { max_attempts: 1 } and the fixture test asserts that contract (mhs_bridge_fixture_is_a_bounded_standard_surface_package). Physical mutation / unknown-outcome reconciliation still requires the external virtual laboratory.
  • Prove least-authority Grants, gateway health, dependency publication, exact-generation lease/drain, reconnect, and reconciliation against the virtual laboratory before enabling any physical adapter profile.
  • Run the same signed package from a generic MCP client and A3S Code: install, discover, observe, invoke a simulated mutation, interrupt/reconcile, upgrade without mixed generations, uninstall, and verify no Registry bindings, Gateway routes, Grants, processes, or projections remain.
  • Keep the adapter labeled research preview until the external MHS profile is stable and the package passes its published conformance and hardware safety-gateway requirements.

Exit gate: MHS demonstrates the complete Registry-to-agent capability path in the separate virtual laboratory without granting Use direct physical-device authority.

The protocol table below describes the currently implemented preview. A2 and A3 will intentionally supersede affected contracts in one coordinated cutover; version numbers are assigned only after their invariants and negative fixtures are frozen.

Current protocol baseline

Contract Accepted version
Cognitive-package manifest schema version 3
Signed catalog record a3s.use.plugin-catalog.v3
Installed receipt schema version 6
Package lock a3s.use.plugin-package-lock.v1
Installation snapshot a3s.use.installation-snapshot.v2
Operation plan a3s.use.plugin-operation-plan.v4
Host capabilities a3s.use.plugin-host-capabilities.v6, protocol 6
Host managed scope a3s.use.plugin-managed-scope.v2
Host operation observation a3s.use.plugin-host-operation-observation-request/result.v1
Host operation watch a3s.use.plugin-host-operation-watch-request.v1
Host cancellation a3s.use.plugin-host-cancel-request/result.v1
Manager MCP toolset a3s.use.plugin-manager-tools.v5 (v4 migration contract remains readable)
Pending package graph a3s.use.pending-package-graph-operation.v4
Pre-lock resolution attempt a3s.use.plugin-resolution-attempt.v1
Pre-plan download attempt a3s.use.plugin-download-attempt.v1
Lifecycle diagnostic a3s.use.plugin-lifecycle-diagnostic.v1
Operation diagnostic a3s.use.plugin-operation-diagnostic.v1
Operation history a3s.use.plugin-operation-history.v1 / a3s.use.plugin-operation-history-diagnostic.v1
Pre-lock resolution diagnostic a3s.use.plugin-resolution-attempt-diagnostic.v1
Pre-plan download diagnostic a3s.use.plugin-download-attempt-diagnostic.v1
Enablement recovery projection a3s.use.cognitive-package-enablement-projection.v3
Enablement operation a3s.use.cognitive-package-enablement-operation.v3
Runtime Task binding a3s.use.runtime-task-binding.v4
Runtime Service provisioning a3s.use.runtime-service-provisioning.v1
Runtime Service binding a3s.use.runtime-service-binding.v3
Extension Registry snapshot schema version 3
Capability snapshot schema version 5
Capability descriptor a3s.use.capability-descriptor.v1
Control descriptor evidence snapshot a3s.use.control-capability-descriptor-snapshot.v1 (proof-only compatibility) / v2 (signed envelope)
Capability Gateway catalog a3s.use.capability-gateway-catalog.v1
Capability Gateway catalog restore plan a3s.use.capability-gateway-catalog-restore-plan.v1
Capability Gateway catalog restore result a3s.use.capability-gateway-catalog-restore-result.v1
Capability Gateway catalog retention plan a3s.use.capability-gateway-catalog-retention-plan.v1
Capability Gateway catalog retention result a3s.use.capability-gateway-catalog-retention-result.v1
Capability Gateway catalog retention journal a3s.use.capability-gateway-catalog-retention-journal.v1 (internal)
Control descriptor snapshot retention plan a3s.use.control-capability-descriptor-snapshot-retention-plan.v1
Control descriptor snapshot retention result a3s.use.control-capability-descriptor-snapshot-retention-result.v1
Control descriptor snapshot retention journal a3s.use.control-capability-descriptor-snapshot-retention-journal.v1 (internal)
Control descriptor snapshot restore plan a3s.use.control-capability-descriptor-snapshot-restore-plan.v1
Control descriptor snapshot restore result a3s.use.control-capability-descriptor-snapshot-restore-result.v1
Capability consumer profile a3s.use.capability-consumer-profile.v1
Capability consumer negotiation a3s.use.capability-consumer-negotiation.v1
Capability snapshot cursor a3s.use.capability-snapshot-cursor.v4
Extension snapshot cursor a3s.use.extension-snapshot-cursor.v3
Coordinated Use state backup a3s.use.state-backup.v2
Coordinated Use state backup retention plan a3s.use.state-backup-retention-plan.v2
Coordinated Use state backup retention result a3s.use.state-backup-retention-result.v2
Coordinated Use state restore plan a3s.use.state-restore-plan.v1
Coordinated Use state restore operation a3s.use.state-restore-operation.v1
Coordinated Use state restore result a3s.use.state-restore-result.v1
Coordinated Use state restore diagnostic a3s.use.state-restore-diagnostic.v1
OKF Knowledge backup a3s.use.okf-knowledge-backup.v1
OKF Knowledge backup retention plan a3s.use.okf-knowledge-backup-retention-plan.v1
OKF Knowledge backup retention result a3s.use.okf-knowledge-backup-retention-result.v1
OKF Knowledge restore plan a3s.use.okf-knowledge-restore-plan.v2
OKF Knowledge restore operation a3s.use.okf-knowledge-restore-operation.v2
OKF Knowledge restore result a3s.use.okf-knowledge-restore-result.v2
OKF Knowledge restore diagnostic a3s.use.okf-knowledge-restore-diagnostic.v2

Negative fixtures for superseded inputs remain only to prove fail-closed rejection. They are not supported decode paths.

Implemented baseline

Package and catalog contracts

  • ACL manifest v3 with named Tool, MCP, OKF, Flow, Skill, and UI surfaces.
  • Required bounded UTF-8 README.md, package path validation, archive bounds, shared Unix symlink/Windows reparse-point rejection, and content fingerprinting.
  • Canonical catalog-v3 record with complete surface inventory, package and manifest digests, planning target, provider requirements, and permission ceiling.
  • Complete current TUF metadata validation and cache verified archives and signed planning targets by SHA-256.
  • Expose one state-free bootstrap-root evidence inspector and one bounded, digest-pinned, immutable admission API for managed hosts. They share the exact digest/version/size decoder and public size bound; admitted bytes still require the ordinary complete TUF refresh before catalog evidence is trusted. Standalone root imports share that same public size bound.
  • Provide one strict public-Internet Registry transport policy for managed hosts: HTTPS only, per-request DNS validation and address pinning, no ambient proxy or automatic redirects, per-hop validation of bounded target redirects, and fail-closed denial of non-public address space across metadata, bootstrap-root, planning-target, and package-target downloads.
  • Persist up to 64 named Registry sources in canonical ACL with one enabled default, revision-bound confirmed authority changes, managed digest-bound root import, and source-identity-isolated TUF/cache datastores. Install and upgrade consume that same enabled set for cross-Registry dependencies.
  • Accept a typed GitHub owner/repository Registry address with bounded ref/path overrides while retaining the ordinary mandatory TUF bootstrap root; never clone or execute Git repository content on the client.
  • Support explicit zero-network install and upgrade from only unexpired, revalidated cached metadata and targets; reject missing or tampered evidence without implicit online-to-cache fallback.
  • Registry/TUF receipts require the exact verified catalog record and source provenance.

Resolution and planning

  • Bounded SemVer dependency resolution with deterministic install/removal order, cycle detection, host/target checks, and cross-source ambiguity rejection.
  • Exact package locks bind every selected version, dependency edge, artifact digest, Registry identity, and TUF role version.
  • Operation plan v4 binds complete impact, current state, confirmation, host/provider evidence, and package transitions.
  • Upgrade binds both prior and candidate locks and classifies Add/Replace/Remove/Retain.
  • Reviewed enablement planning returns either an exact plan-v4 envelope or terminal NoChange.

Package lifecycle

  • Dependency-forward prepare and one atomic graph publication.
  • Reverse uninstall and exact dependency garbage collection.
  • Immutable N/N+1 package roots and receipt-owned retirement.
  • Durable Registry cutover replay, lifecycle journals, operation locking, exact terminal result replay, and tamper rejection.
  • Package-scoped latest/previous lifecycle checkpoint diagnostics with bounded status, digest, timing, failure-code, and rollback evidence; output excludes idempotency keys, credentials, tokens, secret values, and package-authored error text.
  • Both applying and rolling-back journals retain exclusive operation ownership until terminal completion.
  • Cutover-aware host traits only; no fallback publication API.
  • Prior-generation retirement fails unless the graph package binding is already absent.
  • Hosts can acquire an exact currently published lifecycle generation by package, manifest, and generation identity; the lease participates in the same accepted-call drain as alias dispatch.
  • Hosts can derive a typed capability/Registry cursor and atomically lease every callable package generation in canonical order. Publication is rechecked after the complete batch is held; stale, hidden, mixed, digest-mismatched, contended, or non-lifecycle package bindings fail closed without a partial lease.
  • Missing exact recovery evidence fails closed instead of reconstructing state heuristically.

Surfaces and authorization

  • Typed lifecycle hosts for Tool, MCP, OKF, Flow, Skill, and UI.
  • Standalone executable Task, stdio MCP, immutable Skill/UI, and SQLite/FTS5 OKF Knowledge composition.
  • Scope-kind-isolated OKF storage policy with atomic receipt-accounted byte and projection quotas, per-surface generation bounds, global tombstone pruning, SQLite/WAL compaction, and exact-scope usage diagnostics.
  • Scope-local OKF SQLite/receipt/FTS integrity audit, non-overwriting digest-bound database backup and offline verification, exact-scope bounded oldest-first rotation with canonical plan confirmation, plus repair limited to rebuilding the derived search index from validated documents. Authority-bound restore binds exact package/lifecycle/Registry/Grant authority, an exact-subset binding inventory, and live main/WAL/SHM evidence; it can restore missing binding files without overwriting conflicts, preserves prior files, and converges a durable six-state journal after interruption.
  • Real a3s-flow Native TypeScript preflight and exact-generation binding in injected hosts and the explicitly configured standalone CLI lifecycle.
  • Self-contained release-backed Runtime Task binding and exact-generation dispatch with receipt-owned provider reconnection, restart reconstruction, stale-generation rejection, bounded output cleanup, and Registry lease drain.
  • Capability snapshot v5 projection for exact installation/package/generation matched release-backed Runtime Tool Task bindings.
  • Capability snapshot v5 projection for every exact extension MCP surface, preserving canonical IDs, collision-resistant host names, activation, package/file identity, bounded package-local stdio launch evidence, and credential-free managed HTTP binding evidence.
  • Research-preview MHS adapter profile and fixture using only MCP, Flow, Skill, and UI surfaces, with a canonical least-authority permission ceiling, fail-closed gateway/dependency publication, and explicit unknown-outcome semantics for physical mutations. This does not claim MHS conformance.
  • Workspace Grant proposal/change/resolution/ceiling binding.
  • Candidate Grant persistence before prepare, cutover checkpointing, drain-before-revoke, and joint pre-cutover rollback.
  • Manager MCP toolset v5 with explicit install-time Registry selection, read-only planning, digest-bound operation observation/watch, one apply tool, and trusted explicit cancellation; the ten-tool v4 inventory remains a migration contract.
  • Shared typed PluginManagerService over the production Host Manager, with deterministic request replay, Registry-bound catalog cursors, stable installed-state pagination, exact/ranged SemVer selection, durable reviewed plan reopening, exact operation observation/watch, and all thirteen frozen operations. Its standard MCP adapter derives names, schemas, and annotations from toolset v5 and obtains apply/cancellation confirmation only from an injected trusted host provider.
  • Production CognitivePackageHostManager for one exact managed-scope fence, with durable request/operation binding, selected-surface planning, digest-only graph and enablement apply, restart replay, provenance revalidation, zero-network install/upgrade apply from the exact planning cache, and expired-plan recovery only after Use-owned durable admission or completion evidence. Host protocol v6 binds an explicit User or Workspace scope kind, observes exact operations from durable Host, graph, enablement, and lifecycle evidence, long-polls a status revision, and persists explicit-user cancellation only before durable admission.

Validation and documentation

  • Exact a3s-flow 1.0.0-rc.1 candidate qualification for the extension facade through the complete all-feature workspace gate.
  • Canonical fixtures and digest goldens for the current contract line.
  • Unit, integration, remote Registry, crash-replay, grant, Flow, OKF, and CLI tests in the Use workspace.
  • Test-binary subprocess exit after a durable host effect and before receipt persistence at every canonical install, upgrade, enable, disable, and uninstall checkpoint, with exact-key recovery, one durable effect, and no host call on terminal replay.
  • Test-binary subprocess exit after a grant-bearing install, upgrade, or uninstall graph publish/hide effect but before package publication receipts and Grant cutover evidence, with exact-key recovery, one graph effect, completed package/Grant journals, and no publication on terminal replay. Three externally killed managed-host processes also cover five-node install, upgrade, and uninstall after Registry publish/hide but before one dependency receipt and Grant cutover/retirement. Restart forbids reauthorization, performs no network request, preserves the exact candidate Grant, retires only the bound prior Grant, and completes without another Registry generation. Five real CognitivePackageHostManager protocol children also cover every reviewed mutation after the Registry is taken offline. Install, upgrade, and uninstall are killed at the five-node graph publish/hide boundaries; disable is killed after root hide and Grant cutover while accepted-call drain blocks; enable is killed after publication while its candidate Grant is still prepared. Digest-only apply reuses the durable reviewed plan and confirmation; install and upgrade also use only the planning cache. Recovery completes lifecycle/Grant journals, converges the exact candidate/prior Grants or enablement regrant/revocation without another Registry generation, and persists a replayable terminal Host outcome.
  • Test-binary subprocess exit after all 14 Grant Store durable checkpoints in the canonical two-candidate/two-retirement lifecycle across forward prepare, cutover/retirement, and pre-cutover rollback, with exact candidate/prior convergence and terminal journal replay.
  • Real a3s-use process exit after a nine-node install Registry publish cutover but before dependency journal and installation snapshot completion, followed by zero-network exact replay with one complete visible closure and no capability-generation inflation; and after an uninstall Registry hide cutover but before its package hide receipt, followed by exact-plan restart, an observed accepted-call drain, and physical removal. Missing generation state without the exact durable cutover is rejected without changing graph, pending-plan, or Registry evidence.
  • Signed standalone CLI Flow/OKF/Skill/UI install, process-restart observation, exact upgrade, uninstall, failed-preflight non-publication, and repaired exact replay coverage on Unix and Windows x86_64. The OKF fixture also exercises audit, backup, offline verification, confirmed FTS repair, and reviewed restore. Test subprocess exits cover the active-marker handoff, every restore journal state, and partial main/WAL/SHM movement; replay works from the durable candidate without the external backup and terminal replay does not rewrite state. A path-free restore-status projection reports the global active phase and bounded scope history/capacity at every exit window without changing restore or database evidence.
  • Linux CI, macOS workspace tests, and Windows preview compile/facade plus signed Registry, dependency-graph, Grant, Flow, OKF lifecycle, and killed-process cutover-replay gates.
  • GitHub Pages documentation application and bilingual documentation.

Remaining development plan

M1 — Complete managed-host provider composition

Status: in progress

  • Persist exact Service provisioning before Runtime apply, advance it monotonically through Runtime-applied and Gateway-ready evidence, reconcile the final-binding commit window, and remove interrupted candidates without creating duplicate Runtime effects.
  • Exit real test subprocesses at all six nested Service provisioning windows for Tool and HTTP MCP, then prove exact-key recovery, one Runtime and Gateway effect, terminal replay, and drain/remove without residue.
  • Qualify the inactive committed-authority Runtime owner for release-backed Tool Task/Service and Streamable HTTP MCP payloads, monotonic Service provisioning, exact final-receipt replay, typed Gateway readiness, and receipt-owned retirement without exposing Artifact Store paths.
  • Define the canonical Runtime plan payload and restart-safe resolver boundary, with exact plan-time and provider-evidence validation.
  • Qualify the installation-scoped host-owned Runtime plan store with canonical digest addressing, bounded batch publication, restart-safe reads, no-clobber immutability, and fail-closed tamper detection.
  • Register Runtime plan payloads as the fifth snapshotted owner, include them in complete-set snapshot/staging/six-checkpoint activation, and retain referenced Runtime blobs through installation artifact reachability.
  • Qualify a reviewed-operation-only Control composition that projects the complete transition, validates Runtime publication authority, and orders immutable plan publication before the generation commit under one shared maintenance fence. This remains an inactive cutover proof.
  • Compose production Runtime Service providers in A3S Code and managed hosts with a durable host source and atomic dispatcher cutover, preserving exact plan-time and apply-time evidence.
  • Consume the reviewed Runtime Task projection in Code CLI/TUI and agent tool discovery, then route invocation through the leased Use dispatcher. A3S CLI main commit e77d318beba3cba7f193da8d83bb9ac5c46fc0f7 extends the resident TUI projection to scoped Code Exec: the one-shot host freezes provider-qualified reviewed Tasks with exact count/digest evidence, retains the same trusted Plugin Manager through Session teardown, and invokes through the existing exact-generation dispatcher and Use lease. A missing named provider omits only its Task; MCP, Knowledge, Flow, and Plugin Manager presentation surfaces remain outside the scoped host. CI run 32797862154 passed the main all-target check, Linux release sandbox, Linux ARM64 local inference, and native macOS/Windows cross-platform jobs.
  • Compose HTTP/streamable MCP through Gateway with health, drain, and exact-generation retirement. A3S CLI main commit 563e7e139740e845369f9102a2d47026733797a8 qualifies four real Linux Tool and MCP processes across retained N/N+1 routing, Gateway and lifecycle-host restart, stop/drain, exact receipt-owned removal, and zero residual routes, Runtime units, receipts, or PIDs. CI run 32739505482 passed the full Linux all-target suite, release sandbox, Linux ARM64 local inference, and macOS/Windows cross-platform jobs with the exact merged Box and Gateway revisions.
  • Complete bounded storage quota, projection retention, tombstone garbage collection, and physical compaction in the standalone Knowledge backend.
  • Complete managed A3S Code Knowledge Workspace/session carriers and prove leased prior-generation query semantics through those hosts.
  • Validate UI entry points and exact asset digests during package lifecycle changes, and clear receipt-owned UI state on true surface removal.
  • Complete reviewed UI backend bindings and sandboxed rendering in supported hosts. Current CLI and TUI hosts remain static-integrity-only.
  • Prove that every required surface remains unpublished when its owner or evidence is missing.

Exit gate: a six-surface signed package completes install, enable, upgrade, disable, and uninstall through the same reviewed plan/apply service in each supported managed host.

M2 — Finish A3S Code TUI hot-plug qualification

Status: in progress

  • Converge the standalone CLI on the shared PluginManagerService without a second catalog, plan, confirmation, or mutation implementation. The exact manager-v5 read, planning, observation, watch, and cancellation inventory is available under plugin; apply and cancellation reopen a durable operation ID plus plan digest, require explicit trusted user authority (and CLI --yes), and use the verified cache without network access. Compatibility install, upgrade, and uninstall fields remain intact.
  • Migrate the A3S Code TUI to that service and compose the standard manager MCP in Code. CLI, TUI /packages, and the exact thirteen-tool manager-v5 MCP now reuse one host-owned service without a second plan, confirmation, or mutation path at A3S CLI commit ce1240891d6926c132aed8212efabaf6c925f4db.
  • Verify TUI /packages and CLI output show the exact plan, package graph, source, permission ceiling, and confirmation boundary. A3S CLI main commit bef7c913cbefba62638b37f91ce9263f4db2ffbb derives one deterministic, read-only human review from the immutable Manager envelope while preserving the standard machine JSON contracts. CLI and TUI show exact plan/lock, source, transition, permission, provider/impact/state, and confirmation evidence; the TUI scrolls every wrapped line before exact apply. CI run 32786647662 passed the main all-target check, Linux release sandbox, Linux ARM64 local inference, and macOS/Windows cross-platform jobs.
  • Prove install → invoke → exact-generation upgrade → invoke → uninstall → process restart for Tool, MCP, Flow, Skill, UI, and OKF. The complete signed six-surface Host Manager matrix now exercises native Tool and stdio MCP launchers, Flow preflight, Skill/UI integrity, and an exact OKF lease across install/replay, upgrade/replay, and uninstall/replay.
  • Prove watcher resumption, no duplicate side effects, and path-free retained history after process restart. A real Host-protocol install now carries its pre-restart status revision across an externally killed apply and offline recovery process, observes exactly one completed revision, and then times out without changing the terminal revision. Recovery retains one Registry generation, exact apply replay performs no authorization or publication side effect, and scoped retained history excludes filesystem paths, Registry URLs, Host request IDs, and idempotency material.
  • Run the same scenarios for User and Workspace scope and reject scope-kind substitution under the same textual ID. Permission-free Skill and permission-bearing Tool matrices cover the individual scope fences, and the complete six-surface Host Manager matrix now covers both User and Workspace install/restart, upgrade/restart, uninstall/restart, exact Tool/MCP/OKF observations, and plan/apply/operation-observation scope-fence rejection.

Exit gate: Code CLI/TUI and agent tools produce the same plan digest and terminal operation result for the same request.

M3 — Distributed Flow and OS integration

Status: pending

  • Bind package-owned Flow identity to distributed scheduling, resumption, cancellation, and observation without a second flow.json lifecycle.
  • Prove local Code and remote OS targets consume the same source/export, package generation, dependency edges, and authorization.
  • Define and test failure/retry ownership across Use, Flow, Runtime, and remote target boundaries.

Exit gate: remote execution changes placement only; package receipts, locks, and lifecycle journals remain Use-owned and singular.

M4 — Cross-platform real-process release matrix

Status: in progress

  • Run full workspace and real-process package lifecycle tests on Linux x86_64/arm64 and macOS arm64/x86_64. Native CI run 32604181662 passed the then-current Use-owned workspace suite on all four targets from exact main commit 40bc5593cbf58ca2da171d85ba578c2d6bd911c8 while the matching Windows job and general release gates also passed.
  • Run signed Registry trust/lock, dependency-graph install/upgrade/uninstall, Grant, standalone Flow preflight/lifecycle, and OKF cutover scenarios through real a3s-use processes on Windows x86_64, including killed-process replay of removed-dependency cleanup without capability-generation inflation.
  • Run the complete current Use-owned workspace suite on Windows x86_64 and reject directory junctions across package, Registry/cache, Grant, lifecycle, Runtime, Flow, and Knowledge trust boundaries. Flow Runtime qualification now also exercises exact-generation retention, artifact substitution, tampered or moved binding records, same-text scope-kind isolation, and directory-junction rejection on Windows. Shared native link qualification also covers the maintenance lock, target-cache partials and observations, retained lifecycle receipts, package graph and diagnostic stores, enablement locks, Runtime and lifecycle records, whole-state backup and restore paths, and OKF database, binding, backup, and restore paths with real Windows directory junctions. Native Windows tests additionally prove single-package and graph cutover-capacity rejection happens before lifecycle receipt replacement, and that Box CLI delegation preserves arguments, output, and exit status through a .cmd component.
  • Run the Runtime Service provisioning subprocess-exit matrix for Tool and HTTP MCP on the configured platform CI jobs. Real managed-provider and CLI process-kill qualification remains open.
  • Expand the remaining Windows gate to the complete filesystem, Runtime, MCP, watcher, failure-injection, and crash-recovery matrix. All production temporary-file publications for Registry state/cache, Workspace Grants, package and Host records, lifecycle, Runtime, Flow, Knowledge, enablement, backup, restore, and diagnostics now share one bounded Windows retry for transient access, sharing, and lock violations while preserving replace versus no-clobber semantics. Restore journal evidence and Knowledge recovery preserve their source after a bounded rename failure; whole-state restore candidates preserve reviewed file attributes, and lifecycle-generation plus restore-history directory moves use the same retry bound. A released exclusive file or directory lock converges atomically, and a persistent replacement lock leaves the old target intact. Resumable Registry partials use one final-component no-follow handle from discovery through append, checkpoint, verification, and copying into the global Blob tier. Commit rehashes while copying, publishes without clobber under the digest lock, reopens the final blob without following it, and retains that exact handle through staging. The source observation is durable only after the blob, and partial cleanup is last. A live Windows partial or blob handle permits readers but denies external writes, removal, and replacement, while Unix commit and staging remain bound to their held handles after path replacement. Windows-native scanner tests prove a transient no-delete-share handle converges within the two-second cleanup bound. If cleanup stays locked after publication, the next transaction rehashes the durable blob and removes the redundant complete partial without a network transfer. Invalid-partial cleanup and source deletion of stale files, partials, and observations use the same bounded blocking retry; source deletion never removes the global blob. Native tests prove transient scanner release converges for each cleanup path; a persistent selected-target lock stops at two seconds, preserves that entry, and a later prune rescans and finishes after any earlier durable deletions. Recursive cleanup of bounded abandoned .artifact-staging-* trees plus lifecycle receipt deletion uses the same retry without blocking Tokio. Native tests prove transient receipt and nested-staging contention lets the same authority retirement or artifact commit finish. A persistent reader of a complete global artifact never delays uninstall because scoped retirement does not delete shared bytes. Native tests also hold the active artifact-staging directory at its atomic content rename: transient contention lets the same commit finish, while persistent contention fails before receipt or Registry-snapshot mutation, retains residual staging, and permits exact commit replay after release. Selected upgrade-receipt replacement has the same native scanner qualification. Transient contention completes the same upgrade; persistent contention stops at the bound, retains the valid global candidate artifact, removes its retained-receipt candidate, preserves the byte-exact prior receipt and published generation, leaves no temporary receipt, and permits exact replay after release. Reboot recovery, antivirus contention beyond these exact blob publication, source-cache removal, active package-commit, upgrade-receipt replacement, and lifecycle-removal boundaries, product-host contention, and the remaining platform scenarios stay open.
  • Test real-process uninstall interruption between durable Registry cutover and its package receipt, then hold the prior generation lease through restart to prove drain-before-removal and exact generation replay.
  • Complete the interrupted download, archive extraction, graph/Grant cutover, drain, removal, process crash, reboot, remaining antivirus contention outside blob publication, source-cache removal, active package commit, upgrade-receipt replacement, and lifecycle removal, and reparse-point replacement matrix. A real a3s-use process-kill test now proves digest-bound target download resume without partial publication. A second real-process test kills installation while a verified high-entry archive is being extracted, proves no receipt, installation snapshot, pending operation, or package root was published, and completes an exact zero-network retry from the verified cache. A third real-process test kills the following immutable package copy after its pending plan and applying journal are durable, then proves retry reclaims the actual bounded artifact-staging tree, publishes only the exact generation once, and removes the pending operation. Package commit also rejects staging or Artifact Store ancestor links/reparse points. A fourth integration test proves uninstall retires scoped receipt and package-binding authority without deleting or waiting on global artifact bytes. A fifth real-process test kills a nine-node install after the complete atomic graph is visible but before one dependency journal and the installation snapshot complete; offline replay uses the retained cutover, performs no network request, completes every journal, and keeps the original Registry generation. Sixth through eighth externally killed managed-host tests cover install, upgrade, and uninstall publish/hide boundaries with a permission-bearing root and four dependencies while the Grant journal is still prepared. Replay is rejected if it requests authorization again or performs a network request; otherwise it preserves the exact candidate Grant, retires only the bound prior Grant, and completes package and Grant journals without generation inflation. Ninth through thirteenth externally killed CognitivePackageHostManager protocol applies cover all five reviewed mutations after the Registry server is stopped. Install, upgrade, and uninstall use the five-node graph publish/hide boundaries; disable stops after root hide and Grant cutover while drain is blocked; enable stops after publication with its candidate Grant prepared. Recovery consumes the durable reviewed request and confirmation, uses only the exact planning cache for install/upgrade, converges the exact candidate/prior Grant or enablement regrant/revocation, completes drain, and persists the terminal Host outcome without reauthorization or generation inflation. Actual Code/Runtime product-host, platform, reboot, contention, and replacement-race qualification stays open.
  • Verify release archives install and run without repository-local paths. Non-publishing qualification run 33651777660 scanned all five target archives for checkout paths and ran the installed native executables with isolated homes and working directories from exact main commit 4f6e4725205d06ab81f8ea98bfee85c7eb4b2bcd.

Exit gate: every supported target passes the same signed six-surface package and failure-injection scenarios.

M5 — Production supply chain and operations

Status: in progress

  • Initialize and operate A3S-Lab/Use-Registry as the documented official Registry with root rotation, expiry, mirror replacement, offline recovery, and incident procedures. Complete architecture track A5 before publishing its first production bootstrap root. Progress: Use-Registry checkout documents ownership boundary; staging CI gate (registry-staging-gate.yml / docs/staging-ci.md) fail-closes keys-in-tree and package-source bleed, and runs real assemble + verify when admissions and environment-injected keys are present. Registry-tools support threshold root ceremony, pin-stable offline recovery, under-threshold fail-closed, and every-intermediate-root rotate-root with retained root.history plus mandatory new bootstrap pin, check-expiry warn/fail-closed monitoring, compare-mirrors drift fail-closed, and withdraw-targets emergency withdrawal with pin-stable empty-catalog verify. Production bootstrap root publication and live incident procedures remain open; the offline ceremony checklist is in Use-Registry docs/production-bootstrap.md. Production CI readiness gate (registry-production-gate.yml / docs/production-ci.md) fail-closes keys-in-tree and in-git registry/, and arms assemble+verify only with production admissions + environment-injected keys (no trust-root push).
  • Provide durable Registry source add/list/replace/default/enable/disable/ remove operations; preserve immutable receipts and identity-bound evidence across replacement and exact-provenance restoration.
  • Persist verified archives and planning targets in a content-addressed cache and support explicit fail-closed offline install/upgrade.
  • Enforce typed per-Registry byte/entry limits, minimum free-space admission, oldest-first retention, stale-write cleanup, zero-network usage, and confirmed garbage collection.
  • Add bounded, integrity-preserving download resume with durable digest-bound partials, exact HTTP range validation, full-file verification, and cache-policy/GC accounting.
  • Publish checksum-verifying Linux/macOS and Windows installers from the release workflow with HTTPS downgrade prevention, safe extraction, packaged OCR/Skill binding, versioned atomic activation, and tamper/conflict tests.
  • Deterministically serialize multi-platform archives and publish one SPDX SBOM per platform, GitHub OIDC provenance/SBOM attestations, and a locally reverified keyless Sigstore bundle for complete checksum evidence from one workflow with pinned Actions and release tools.
  • Make both platform installers require Cosign, authenticate the checksum manifest against the exact tag workflow identity and GitHub OIDC issuer before archive download, fail closed on invalid evidence, and retain the verified manifest and bundle with the installed version.
  • Pass byte-for-byte independent rebuilds for every shipped native executable on all five targets. The tagged v0.3.2 attempt exposed drift on four targets and did not publish a Release. The current non-publishing qualification run 33651777660 rebuilt every shipped native executable without a compiled-artifact cache, with one release codegen unit, and byte-matched all five primary archives from exact main commit 4f6e4725205d06ab81f8ea98bfee85c7eb4b2bcd.
  • Publish the development-preview v0.3.6 GitHub Release after the exact tagged source, five verified platform archives, deterministic SBOM/reproducibility evidence, installers, and Use-owned typed crates passed the release workflow. Release workflow run 33675697857 passed all 13 jobs for exact main commit 54758910f2f4ad9498137410e0a2207d412e99a1; the release publishes a3s-use-core 0.2.5, a3s-use-extension 0.3.6, and a3s-use 0.3.6. The cancelled v0.3.5 attempt did not create a GitHub Release because the public core crate was stale; do not treat that tag as published evidence. This does not close the external-witness or product-readiness gates.
  • Publish the development-preview v0.3.7 GitHub Release after the exact tagged source, five verified platform archives, deterministic SBOM/reproducibility evidence, installers, and Use-owned typed crates passed the release workflow. Release workflow run 33687297386 passed all 13 jobs for exact main commit 48a0b76f8a4a87a11d16627c7bd7567920852508; the release publishes a3s-use-core 0.2.6, a3s-use-extension 0.3.7, and a3s-use 0.3.7. The prior v0.3.6 release remains historical evidence. This does not close the external-witness or product-readiness gates.
  • Publish the development-preview v0.3.8 GitHub Release after the exact tagged source, five verified platform archives, deterministic SBOM/reproducibility evidence, installers, and Use-owned typed crates passed the release workflow. Release workflow run 33720485826 passed all 13 jobs for exact main commit 6d3a7baf32ce998a2e487c40fbf78b4a6cda2579; the release publishes a3s-use-core 0.2.7, a3s-use-extension 0.3.8, and a3s-use 0.3.8. The prior v0.3.6 and v0.3.7 releases remain historical evidence. This does not close the external-witness or product-readiness gates.
  • Publish the development-preview v0.3.9 GitHub Release after the exact tagged source, five verified platform archives, deterministic SBOM/reproducibility evidence, installers, and Use-owned typed crates passed the release workflow. Release workflow run 33756618837 passed all 13 jobs for exact main commit a5f3cc40bfb0a1021ca150d2ce4295409b74d220; the release publishes 19 assets, a3s-use-core 0.2.7, a3s-use-extension 0.3.9, and a3s-use 0.3.9. The prior v0.3.6, v0.3.7, and v0.3.8 releases remain historical evidence. This does not close the external-witness or product-readiness gates.
  • Publish the development-preview v0.3.10 GitHub Release after the exact tagged source, five verified platform archives, deterministic SBOM/reproducibility evidence, installers, and Use-owned typed crates passed the release workflow. Release workflow run 33791616307 passed all 13 jobs for exact main commit c4c80a223bfff3698ca4b4598e7175c6e3303239; the release publishes 19 assets, a3s-use-core 0.2.8, a3s-use-extension 0.3.10, and a3s-use 0.3.10. The prior v0.3.6, v0.3.7, v0.3.8, and v0.3.9 releases remain historical evidence. This does not close the external-witness or product-readiness gates.
  • Publish the development-preview v0.3.11 GitHub Release after the exact tagged source, five verified platform archives, deterministic SBOM/reproducibility evidence, installers, and Use-owned typed crates passed the release workflow. Release workflow run 33830280138 passed the validation, five-target primary-build, typed-crate, and five-target independent-rebuild gates for exact main commit c25028ae0245ba1d28f7e2837e2a87f7e9f6fe40; the release publishes 19 assets, a3s-use-core 0.2.9, a3s-use-extension 0.3.11, and a3s-use 0.3.11. The prior v0.3.6, v0.3.7, v0.3.8, v0.3.9, and v0.3.10 releases remain historical evidence. This does not close the external-witness or product-readiness gates.
  • Add an externally operated witness for the complete staged tree and final archive digest, and retain verification evidence outside the Release asset trust boundary.
  • Define storage retention, quota, garbage collection, backup, and repair procedures for packages, cutover evidence, Grants, Flow history, UI state, and OKF projections. A deterministic a3s.use.state-backup.v2 exact-installation inventory now snapshots all allowlisted installation-owned families under its exclusive maintenance fence, binds the installation, Registry generation/snapshot, and installed receipt digests, excludes locks and global Registry/TUF/Flow caches, rejects nonterminal or unknown state, and verifies every payload offline without extraction. Signed-package real-process coverage proves path-free inventory and zero-network verification. Coordinated retention now verifies every managed whole-install archive under one external directory lock, returns a path-free oldest-first canonical plan, rejects stale plans or changed candidates, and removes nothing without the exact plan digest and explicit confirmation while retaining at least two recovery generations. Scope-local OKF database audit, verified backup and exact-plan rotation, derived-index repair, and authority-bound database plus missing-binding restore are also implemented. Binding recovery accepts only an exact subset of the verified backup inventory and independently retained Registry/package/lifecycle/Grant authority; conflicting or newer binding evidence fails closed. Reviewed same-version/OS/architecture whole-install restore is now implemented with a path-free Add/Replace/Remove/Retain plan, exact live Registry and Grant authority, a verified external rollback archive, link/reparse-safe staging, seven durable phases, 15 subprocess-exit recovery boundaries, terminal replay, read-only diagnostics, and bounded crash-recoverable history. Missing authority recovery, clean-machine disaster recovery, cross-platform drills, whole-product policy, and complete operational exercises remain open.
  • Expose bounded, secret-free latest/previous lifecycle checkpoint diagnostics through extension inspect --json.
  • Add broader telemetry and diagnostics for plan, download, provider readiness, cutover, drain, rollback, and recovery without exposing secrets. extension diagnose --json now exposes bounded, path-free Registry/TUF, reviewed-plan, provider, Grant, cutover, lifecycle publication/drain/ rollback, and recovery evidence for one exact retained planned/admitted/ cancelled install, upgrade, or uninstall graph, active admitted enable/ disable operation, or newest Host-reviewed pre-admission enable/disable plan or cancellation. Standalone Knowledge recovery exposes bounded active/ history/capacity evidence. Retained install/upgrade graphs and durable pre-plan download attempts expose expected and retained archive and signed executable-planning-target bytes plus exact-target missing/partial/complete state from historical Registry provenance without network I/O, writes, cache-lock acquisition, or paths. Real killed-process tests prove active archive and planning-target partial observation, retained evidence, exact Range resume, and cleanup only after the reviewed graph is durable. Partials and complete observations are never planning/apply/recovery authority. Before an exact lock exists, a durable pre-lock resolution attempt records refreshed/cached access, requested version/channel, per-Registry pending/verifying/verified/failed state, path-free source/trust digests, TUF role versions, bounded failures, and terminal package-lock evidence. The diagnostic survives resolver failure or process exit and is deleted only after its download-attempt successor is durable. Real CLI tests cover a killed online resolution, terminal verification failure, and zero-network offline cache failure. extension diagnose --history --json now retains the newest 16 exact completed or rolled-back operations and cancelled graph plans within 8 MiB per scope/package. Retention happens before recovery evidence is removed, exact replay is deduplicated by (operationId, planDigest), history survives uninstall, and malformed, linked, or oversized state fails closed without path or secret leakage. A real CLI install/uninstall/reinstall sequence proves zero-network newest-first history and legitimate textual operation-ID reuse; a Host graph cancellation proves zero-network cancelled outcome and replay deduplication; the managed Workspace Host kill/recovery path proves exact-scope history without a second entry. A digest-bound Host observation index selects the newest reviewed enablement plan by (plannedAtMs, requestId) while retaining its exact managed scope only for private request lookup. Real CLI assertions prove planned/cancelled projection, selected provider and awaiting-Grant state, exact zero-observed lifecycle counts, zero network/authorization/ admission, no Host/fence/path leakage, active Use-evidence precedence, and suppression after Use completion before the Host outcome is durable.
  • Complete threat model review, privilege boundaries, security response, upgrade policy, and support runbooks.

Exit gate: a release candidate can be installed, upgraded, recovered, audited, and removed by an operator using only published artifacts and documentation.

Release blockers

The first-principles capability and release-gate audit is recorded in docs/agent-package-manager-audit.md. It distinguishes qualified mechanisms from inactive Control proofs and from the production composition, trust, interoperability, and operations gates below.

The first supported product release is blocked until all of the following are green:

  1. A0 proves serializable graph mutation and stale-generation rejection across different roots with shared dependencies.
  2. A1 proves one authoritative installation generation for every explicit User and Workspace scope, including independent selection of the same package.
  3. A2 proves atomic Use-owned control state and deterministic recovery around every external provider-effect boundary.
  4. A3 lets an arbitrary MCP-capable agent discover and invoke capabilities through opaque references and server-owned exact-generation leases.
  5. One reviewed Package Manager serves CLI, TUI, and management MCP, with a distinct lower-authority Capability Gateway for agents.
  6. A4 composes all declared production providers without hardcoding A3S-specific domains into the universal engine.
  7. Exact graph and Grant recovery passes failure injection at every checkpoint.
  8. Linux, macOS, and Windows pass the declared real-process matrix.
  9. A5 Registry operations, signing, provenance, and release installation are independently reproducible from A3S-Lab/Use-Registry.
  10. Storage retention, repair, observability, incident response, and support procedures are documented and exercised.
  11. A6 qualifies the signed MHS reference package against the separate virtual laboratory without claiming physical-device conformance.
  12. Website and README examples pass against the release candidate.

Until then, README and website copy must say development preview and must not advertise production readiness or a stable cognitive-package contract.

Completion definition

A3S Use is ready to publish only when a user can select a trusted Registry, review one exact scoped-installation plan, and atomically install a signed dependency graph; and when an arbitrary MCP-capable coding agent can discover and invoke its authorized capabilities without learning host paths or holding lifecycle authority. The system must recover from interruption without guessing, upgrade without exposing mixed generations, and uninstall without leaving routes, Grants, leases, processes, projections, or package-owned state behind.