Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
280 changes: 280 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,286 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

## [1.1.0](https://github.com/RCSnyder/open-pincery/compare/v1.0.1...v1.1.0) - 2026-05-11

### Added

- *(build)* AC-91 pcy backup / pcy restore (v9.1 V91-S6)
- *(build)* AC-93 pcy provider β€” per-workspace LLM provider rows
- *(build)* AC-92 docs/onboarding.md β€” one-page first-run gate
- *(build)* AC-90 pcy doctor β€” 8-check self-diagnosis with table/json output
- *(build)* AC-89 pcy init β€” bootstrap .env with strong random secrets
- *(build)* AC-94 honesty pass β€” README five-row security table + DELIVERY v9.0
- *(build)* AC-82 G7f+G7g β€” status-write CAS lint + spec_coverage Inv_TerminalSuccession
- *(build)* AC-82 G7c+G7d β€” tool-loop transitions + terminal CAS chain
- *(build)* AC-82 G7b β€” wake-loop entry chain emits lifecycle_transition events
- *(build)* AC-82 G7a β€” fine-grained lifecycle CAS helpers + migration
- *(build)* AC-81 binding commitments β€” spec_coverage table + commit-msg hook + lint
- *(verify)* AC-80 closed β€” capability nonce admission gate verified
- *(build)* AC-80 G5b+G5c β€” wake_loop mints, dispatch_tool consumes
- *(build)* AC-80 G5a β€” capability_nonce module + migration + unit tests
- *(build)* AC-79 G4e per-wake tool-call rate limit + adversarial integration tests + CHANGELOG
- *(build)* AC-79 G4d jsonschema validation + retry cap + FailureAuditPending
- *(build)* AC-79 G4b+G4c canary emission + echo scan + injection termination
- *(build)* AC-79 G4a wake_system_prompt v3 + per-wake nonce/canary plumbing
- *(build)* G3d audit-chain startup gate refuses to boot on broken chain
- *(build)* G3c β€” pcy audit verify CLI + POST /api/audit/chain/verify
- *(build)* G3b AC-78 verifier + workspace pass + audit_chain events
- *(build)* G3a AC-78 event hash chain migration + Rust verifier scaffold
- *(build)* G3a AC-78 event-log hash chain migration + Rust verifier
- *(build)* AC-77 / Slices G2e+G2f - corpus-subset guard + CHANGELOG
- *(build)* AC-77 / Slice G2c - sandbox_syscall_denied event on SIGSYS
- *(build)* AC-77 / Slice G2b - default-deny allowlist + clone arg-filter
- *(build)* AC-77 / Slice G2a - empirical seccomp syscall corpus
- *(build)* G1d network-category escape payloads (AC-76 12/12)
- *(build)* G1c.x.2 wire memory.max probe into startup gate
- *(build)* AC-76 / Slice G1c.x - empirical memory.max enforcement probe
- *(build)* AC-76 / Slice G1c - resource payloads (fork-bomb, memory-balloon, pid-exhaustion)
- *(build)* AC-76 / Slice G1b β€” privesc payloads (setuid, CAP_SYS_ADMIN, user-ns)
- *(build)* AC-76 G1a sandbox escape suite β€” FS category
- *(build)* implement ac-88 landlock audit integration
- *(build)* enforce landlock IPC scopes
- *(build)* wire AC-84 startup preflight + exit-4 contract
- *(build)* G0b.1 kernel ABI floor preflight module (AC-84)
- *(build)* G0a.3h flip SandboxProfile::default to landlock=true
- *(build)* G0a.3g wire pincery-init into bwrap for landlock
- *(build)* JSON error channel on --error-fd for pincery-init (G0a.3f)
- *(build)* FullyEnforced verification inside pincery-init (G0a.3e)
- *(build)* install landlock inside pincery-init (G0a.3d)
- *(sandbox)* Slice G0a.3c -- seccomp filter install inside pincery-init (AC-83)
- *(sandbox)* Slice G0a.3b -- drop uid/gid inside pincery-init (AC-83)
- *(sandbox)* Slice G0a.3a -- prctl(NO_NEW_PRIVS) inside pincery-init (AC-83)
- *(sandbox)* Slice G0a.2 -- pincery-init binary skeleton (AC-83)
- *(sandbox)* Slice G0a.1 β€” SandboxInitPolicy IPC module (AC-83)
- *(build)* add landlock LSM filter (AC-53 layer 4 of 6, slice A2b.4c)
- *(sandbox)* Slice A2b.4b seccomp-bpf denylist (layer 3 of 6)
- *(sandbox)* Slice A2b.4a cgroup v2 resource caps (layer 2 of 6)
- *(scripts)* allow relocating cargo and devshell caches off system drive
- *(runtime)* AC-53 RealSandbox via bwrap + build_executor factory (Slice A2b.3)
- *(build)* AC-53 prep -- Linux sandbox crate gate (Slice A2b.1)
- *(build)* AC-73 sandbox mode config flag (Slice A2a)
- *(build)* AC-54 SECURITY.md threat model (Slice A1)
- *(build)* AC-75 cross-platform devshell (Slice A0)
- *(cli)* remove pcy bootstrap subcommand; login is sole auth verb (AC-45)
- *(build)* AC-52b v8.0 -- cli_naming_test + about docstrings
- *(build)* AC-51 v8.0 -- pcy completion via clap_complete
- *(build)* AC-47 v8.0 -- credential list honours --output
- *(build)* AC-45/AC-48 v8.0 -- idempotent pcy login + pcy whoami
- *(build)* AC-47 slice 2e-a -- root Cli --output/--no-color flags
- *(build)* AC-46/AC-48 slice 2d-i -- context noun
- *(build)* AC-48 slice 2c -- named contexts + v4 to v8 migration
- *(build)* AC-46 slice 2b -- name-or-UUID resolver
- *(build)* AC-47 slice 2a -- CLI output renderer foundation
- *(build)* AC-44 slice 1b -- full handler OpenAPI coverage
- *(build)* AC-44 slice 1a β€” OpenAPI 3.1 spec endpoint
- *(build)* AC-43 v7 slice 6 -- PLACEHOLDER credential resolution
- *(build)* AC-42 v7 slice 5 -- hardened wake_system_prompt v2
- *(build)* AC-41 v7 slice 4 -- list_credentials tool
- *(build)* AC-40 v7 slice 3 -- pcy credential CLI
- *(build)* AC-39 v7 slice 2 -- credentials REST API
- *(build)* AC-38 v7 slice 1 -- AES-256-GCM credential vault
- *(build)* AC-36 v6 slice 4 -- ToolExecutor trait + ProcessExecutor sandbox
- *(build)* AC-35 v6 slice 3 -- capability gate wired in front of dispatch_tool
- *(build)* AC-34 v6 slice 2 -- typed AgentStatus + TLA-aligned DB values
- *(build)* AC-37 v6 slice 1 -- zero-advisory cargo deny floor

### Fixed

- *(ci)* allowlist VAULT_KEY_BASE64 as INTERNAL_ONLY env var (AC-29 + AC-91)
- *(ci)* allowlist 'provider remove' for --yes flag (AC-93)
- *(ci)* clippy assertions_on_constants + AC-40 rpassword allowlist for pcy init
- *(review)* align onboarding doc + doctor docstring to 7 checks
- *(review)* amend AC-90 to 7 checks, add AC-93 resolver test
- *(build)* AC-91 review-fix β€” wire --include-vault-key into restore + 0o600 modes
- *(build)* AC-82 review-fixes (1 Critical + 3 Required + 1 Consider)
- *(build)* AC-82 G7a clippy doc_overindented_list_items
- *(build)* AC-81 clippy for_kv_map β€” iterate keys() in spec_coverage_lint
- *(build)* AC-80 REVIEW-fix-1 β€” concurrent test + AC-78 chain walk + schema shape + doc-comment
- *(build)* AC-80 G5d type alias for classify_rejection row tuple
- *(verify)* AC-79 verify-fix-1 β€” allowlist new env keys in AC-29 orphan check
- *(build)* AC-79 review-fix-1 β€” structured event payloads, OsRng, v3 active-template proof, 3 scope-verbatim adversarial tests
- *(build)* G3-review address REVIEW Required findings on AC-78
- *(build)* G3d add OPEN_PINCERY_AUDIT_CHAIN_FLOOR to .env.example
- *(test)* G3c β€” bootstrap returns 201 CREATED in audit_api_test
- *(build)* G3b verify-fix-2 β€” enforce monotonic created_at in chain trigger
- *(build)* G3b verify-fix-1 β€” advisory lock + payload arg-order
- *(verify)* accept Timeout as fork-bomb denial outcome (AC-77)
- *(verify)* relax AC-77 audit_mode test to negative-only assertion
- *(verify)* AC-77 escape-test scaffolding accepts SIGSYS denials
- *(verify)* add AC-77 Landlock syscalls (444/445/446) per kernel dmesg
- *(verify)* add AC-77 capget+capset (syscall 126) per kernel dmesg
- *(verify)* add AC-77 getresgid (syscall 120) per kernel dmesg evidence
- *(verify)* correct AC-77 syscall identification - 118=getresuid not setresgid
- *(verify)* allow setresgid in AC-77 seccomp filter (kernel-evidence)
- *(verify)* widen AC-77 allowlist for Rust runtime + glibc-2.39 residuals
- *(build)* AC-77 review re-fix - cfg-gate sigsys_event_test to linux + log G2c.2 review-deferreds
- *(build)* AC-77 review fixes - R1 SIGSYS event test, R2 audit-mode test, R3 fanotify negative control
- *(build)* AC-76 / Slice G1c cleanup - clippy + memory-balloon unconditional skip (BLOCKED)
- *(build)* AC-76 / Slice G1c round 3 - memory controller delegation probe
- *(build)* AC-76 / Slice G1c round 2 - dd buffer + SURVIVORS pattern
- *(build)* AC-76 / Slice G1c round 1 - reshape resource payloads after CI feedback
- *(build)* G1b round 1 - privesc test correctness (CI cb8521b failures)
- *(build)* G1b round 1 β€” privesc test correctness (CI cb8521b failures)
- *(sandbox)* per-path Landlock access mask; correct bwrap /etc guard test
- *(sandbox)* narrow /etc bind+landlock to public allowlist (closes G1a /etc/shadow escape)
- *(verify)* repair ac-88 linux ci failures
- *(sandbox)* block nested user namespaces
- *(sandbox)* keep AC-86 test helpers test-only
- *(sandbox)* drop bwrap uid and capabilities
- *(sandbox)* simplify landlock status validation
- *(sandbox)* avoid constructing landlock restriction status
- *(sandbox)* require full Landlock enforcement in production
- *(test)* locate server binary in AC-84 integration tests
- *(sandbox)* enforce AC-84 userns quota evidence
- *(test)* accept AC-84 event on stdout or stderr in CI
- *(build)* register OPEN_PINCERY_SANDBOX_FLOOR in env contract (AC-29)
- *(build)* set PINCERY_INIT_BIN_PATH in sandbox_real_smoke preflight
- *(build)* G0a.3g add /dev to default landlock rwx paths
- *(build)* G0a.3g populate policy.user_argv with sh -c <cmd>
- *(build)* make write_error_channel pub so main can call it (G0a.3f)
- *(build)* allowlist OPEN_PINCERY_INIT_FORCE_PARTIAL for AC-29
- *(build)* expand sample_policy landlock paths for G0a.3d enforcement
- *(build)* clippy doc_lazy_continuation in G0a.3d test docstring
- *(sandbox)* satisfy clippy::manual_is_multiple_of in apply_seccomp
- *(sandbox)* derive Debug on ParsedArgs (unwrap_err needs T: Debug)
- *(sandbox)* allow dead_code on ParsedArgs.user_argv (G0a.2 clippy fix)
- *(sandbox)* swap bincode -> serde_json in SandboxInitPolicy (deny failure fix)
- *(sandbox)* interim β€” disable landlock by default per AC-53 amendment
- *(sandbox)* add / to landlock rx allowlist so bwrap setup succeeds
- *(tla)* repair side-spec parse, include in CI, keep path filter
- *(build)* landlock must grant rwx on /proc for bwrap uid-map writes
- *(build)* remove unused CommandExt import (tokio's pre_exec is inherent)
- *(sandbox)* clippy doc-list-overindent + manual-c-str-literal in seccomp.rs
- *(sandbox)* clippy manual-range-contains in A2b.4a pids test
- *(devshell)* MSYS path + TTY auto-detect for Windows git-bash; log A2b.3 evidence closure
- *(ci)* close AC-53 evidence gate β€” patch rustls-webpki, allow unpriv userns, rotate deny.toml ignore
- *(build)* allowlist v8.0 env-var additions in env_example_test
- *(build)* clippy -- allow too_many_arguments on dispatch_tool and prefer flatten in leak scan
- *(build)* close v6 review R1/R2 β€” widen sudo check + add AppState.executor
- *(build)* AC-37 -- allow RUSTSEC-2023-0071 as a single documented exception

### Other

- *(deploy)* v9.1 onboarding gate delivery handoff
- *(verify)* align Doctor clap docstring to 7 checks
- *(reconcile)* v9.1 onboarding gate 7-axis drift sweep β€” REPAIRED
- *(analyze)* produce v9.1 readiness.md (AC-89..AC-94)
- *(iterate)* version scope to v9.1 β€” Onboarding Gate
- *(post_v9_audits)* add nwave convo + v9 audit
- *(readme)* v9.0 ship status update
- *(deploy)* DELIVERY.md AC-82 close + v9.0 ship-gate clear
- *(reconcile)* AC-82 7-axis drift sweep β€” REPAIRED
- *(build)* log G7c..G7g AC-82 BUILD-complete checkpoint
- *(build)* log AC-82 G7b checkpoint
- *(build)* log AC-82 G7a checkpoint
- *(analyze)* AC-82 readiness β€” Fire Reserved Lifecycle States READY
- *(deploy)* AC-81 closed β€” Binding Commitments delivered
- *(reconcile)* AC-81 7-axis drift sweep β€” REPAIRED
- *(analyze)* AC-81 readiness β€” Binding Commitments (spec_coverage + commit-msg hook) READY
- *(reconcile)* AC-80 7-axis drift sweep β€” REPAIRED
- *(review)* AC-80 REVIEW round 2 PASS
- *(build)* AC-80 G5e β€” CHANGELOG and DELIVERY entries for capability nonce gate
- *(build)* AC-80 G5d β€” capability nonce adversarial integration tests
- *(analyze)* AC-80 capability nonce/freshness β€” READY
- *(input)* tool-landscape audit 2026-05 β€” OpenShell, Sandcastle, pi-mono, Founder OS
- *(deploy)* AC-79 closed β€” Prompt-Injection Defense Floor delivered
- *(reconcile)* AC-79 7-axis drift sweep β€” REPAIRED
- *(review)* AC-79 REVIEW PASS @ 91ecfb8 β€” fix-cycle 1 closed all Critical/Required findings
- *(analyze)* AC-79 Prompt-Injection Defense Floor admission
- *(deliver)* document AC-78 event-log hash chain in DELIVERY.md
- *(reconcile)* AC-78 7-axis drift sweep β€” REPAIRED
- *(log)* G3-review entry; memory: AC-78 review-fix state @b412025
- *(build)* G3e log entry β€” AC-78 BUILD complete (G3a..G3e all green)
- *(build)* G3e AC-78 audit-chain recovery runbook + CHANGELOG
- *(build)* G3d log entry β€” audit-chain startup gate CI 25241912717 green
- *(build)* G3c CLOSED β€” log entry for pcy audit verify CLI + HTTP
- *(build)* log AC-78 G3b CLOSED at b961955
- *(build)* log AC-78 G3a PASS at bf9c6b5
- *(analyze)* readiness for AC-78 event-log hash chain
- *(design)* add v9 G3 AC-78 event-log hash chain design slice
- *(reconcile)* log AC-77 verify-fix-2 reconcile pass (REPAIRED)
- *(reconcile)* align AC-77 audit-mode coverage row with shipped test
- *(reconcile)* align design.md AC-77 allowlist counts with shipped state
- *(verify)* log AC-77 verify-fix-2 PASS entry
- *(sandbox-smoke)* capture kernel seccomp/audit log for AC-77 diagnosis
- *(verify)* log AC-77 verify-fix attempt 1 PARTIAL + BLOCKED post-mortem
- *(reconcile)* align design.md and audit doc counts with verify-fix
- *(reconcile)* align design.md and audit doc with AC-77 shipped state
- *(build)* log AC-77 / G2d+G2e+G2f PASS at 81571db / 5982ab3
- *(build)* AC-77 / Slice G2d - seccomp allowlist integration tests
- *(build)* log AC-77 / G2c PASS at a96499e
- *(build)* log AC-77 / G2b PASS at a89d4a5
- *(analyze)* log post-analyze PASS for AC-77
- *(analyze)* AC-77 readiness β€” seccomp default-deny allowlist
- *(verify)* G1d CI-green at 25197562247 - AC-76 closes 12/12
- *(ci)* install iputils-ping in sandbox-smoke runner
- *(scope)* document strategic security gaps + close G1c memory-balloon entry
- *(verify)* G1c.x.2 green on CI 25196202744
- *(verify)* G1c.x green on CI 25193943507
- *(verify)* G1b green on CI 25141721367 (8935fd7)
- *(verify)* G1a / AC-76 FS category green on CI dd10a8b
- *(sandbox)* include sandbox_escape_test in privileged smoke job
- *(analyze)* open AC-76 / Slice G1a sandbox escape suite readiness
- *(windows)* default local target dirs to repo-local paths
- *(verify)* record ac-88 ci evidence
- *(verify)* close AC-87 with CI evidence
- *(build)* pin landlock scope fallback event
- *(verify)* record AC-86 sandbox proof
- *(verify)* close AC-85 with CI evidence
- *(verify)* close AC-84 with CI evidence
- *(build)* log Slice G0a.1 SandboxInitPolicy
- *(analyze)* readiness addendum for Slice G0a (AC-83 pincery-init)
- *(expand)* v9 sandbox architecture rework β€” AC-83..AC-88, Phase G0
- *(sandbox)* --no-fail-fast so every real-bwrap binary runs
- *(sandbox)* accept dash 'Cannot fork' message as pids.max evidence
- *(sandbox)* run AC-53 real-bwrap tests inside --privileged container
- *(sandbox)* run smoke binary under sudo, skip in unprivileged test job
- *(sandbox)* grant bwrap cap_sys_admin+cap_sys_chroot file caps
- *(sandbox)* make / private before bwrap to unblock MS_SLAVE on hosted runners
- *(sandbox)* surface bwrap stderr in smoke test panics
- *(scope)* add AC-76..AC-82 as v9 release blockers from TLA+ + security audit
- *(ci)* remove extra lines
- *(tla)* add SANY parse + TLC simulation CI for canonical spec
- *(spec)* v3.3 TLC-driven correctness pass (B5-B10)
- *(log)* record Slice A2b.4b CI evidence (10/10 seccomp tests + 72 lib tests green on run 24801274092)
- *(log)* record Slice A2b.4a CI evidence (4/4 cgroup tests green on run 24799988428)
- *(log)* record Slice A2b.3 second-channel evidence (local devshell bwrap smoke 5/5)
- install bwrap userland + dedicated sandbox-smoke job (AC-53 evidence gate)
- *(build)* log Slice A2b.3 checkpoint
- *(build)* log Slice A2b.1 + A2b.2 checkpoint
- *(runtime)* split sandbox.rs into sandbox/ module (Slice A2b.2)
- *(clippy)* fix Rust 1.94 lints (derivable_impls, doc_lazy_continuation)
- *(build)* log Slice A2a PASS
- *(build)* verify AC-75 Linux parity + relax Docker floor
- *(build)* log Slice A1 PASS
- *(build)* log Slice A0 PASS
- *(audit)* fix post-audit plan inconsistencies
- *(audit)* v9 audit addendum β€” 3 new ACs (AC-73/74/75) + 15 in-slice hardening items
- *(design,analyze)* v9 trust-gate architecture + readiness map
- *(expand)* v9 scope revision β€” clarifications resolved; AC-53/65 upgraded; AC-71/72 added
- *(expand)* v9 scope -- solo-founder trust gate (AC-53..AC-70)
- *(build)* log v8.0 landing + DELIVERY.md v8.0 section
- *(build)* log AC-47 slice 2e-a -- root Cli output/no-color flags
- *(build)* log slice 2d-i -- context noun
- *(build)* log slice 2c -- named contexts + v4 to v8 migration
- *(build)* log BUILD v8 Slice 2 (partial - sub-slices 2a+2b)
- *(build)* log BUILD v8 Slice 1 (AC-44 OpenAPI coverage)
- *(analyze)* v8 readiness β€” READY
- *(scope)* normalize v8 stack table whitespace
- *(design)* v8 β€” Unified API Surface architecture
- *(v8-prep)* v8 exploration artifacts β€” CLI distribution + release matrix
- *(expand)* v8 scope β€” Unified API Surface (schema-driven CLI, MCP, distribution)
- *(v7)* RECONCILE + DEPLOY -- log and DELIVERY for v7
- *(design)* v7 design addendum + readiness READY
- *(expand)* scope v7 β€” credential vault & reasoner-secret refusal
- *(deploy)* v6 DELIVERY.md refresh + post-DEPLOY gate PASS
- *(verify)* v6 post-VERIFY gate PASS
- *(reconcile)* v6 seven-axis audit β€” align design.md + readiness.md with shipped code
- *(build)* v6 post-BUILD gate PASS + cargo audit observation
- *(analyze)* v6 readiness READY -- 4-slice build order starting with AC-37
- *(design)* v6 addendum β€” capability foundations & security baseline
- *(expand)* scope v6 β€” capability foundations & security baseline

### Security

- _(AC-81)_ **Binding commitments β€” spec coverage + commit-msg hook.** New `scaffolding/spec_coverage.md` is the single source of truth that maps every v9 acceptance criterion (AC-53..AC-88) to the canonical TLA+ action(s) in `docs/input/OpenPinceryCanonical.tla` `Next ==` it implements (or `β€”` for pure docs/UI/CLI surface) plus any invariant the AC makes real. New `tests/spec_coverage_lint.rs` mechanically validates the table: every cited action exists in the canonical `Next` disjunction, every AC-53..AC-88 row is present, no duplicates, no empty action cells. New `.github/hooks/commit-msg-spec-ref` is a path-conditional commit-msg hook that rejects any commit whose staged diff touches `src/runtime/**` or `src/api/**` unless the message body contains at least one `canonical_action=<Name>` trailer where `<Name>` appears in `scaffolding/spec_coverage.md`. Commits that touch neither path (scope edits, docs, CI, tooling) are accepted with no trailer requirement. `scripts/devshell.sh` installs the hook into `.git/hooks/commit-msg` idempotently β€” only when no hook is present, or when the present hook is the unmodified `commit-msg.sample`. User-customized hooks are never overwritten. `tests/spec_hook_test.rs` drives the hook end-to-end with synthetic `(message, staged-diff)` fixtures (5 cases: rejects runtime change without trailer, accepts runtime change with valid trailer, accepts docs-only commit, rejects unknown canonical action, devshell installer is idempotent and respects user customization). Closes the spec-drift loophole that let v9 ship runtime code without explicit traceability back to the canonical model.
Expand Down
2 changes: 1 addition & 1 deletion Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "open-pincery"
version = "1.0.1"
version = "1.1.0"
edition = "2021"
description = "Multi-agent platform for durable, event-driven AI agents"
license = "MIT OR Apache-2.0"
Expand Down
Loading