Skip to content

Harden CLI, integrations, browser and processor release contracts - #26

Merged
BitmapAsset merged 12 commits into
mainfrom
harden/release-20261010
Oct 11, 2026
Merged

BitmapAsset merged 12 commits into
mainfrom
harden/release-20261010

Conversation

@BitmapAsset

@BitmapAsset BitmapAsset commented Oct 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

Hardens the existing CLI, agent contracts, processor input boundaries, monitors, installers and browser module. Source candidate only: no version bump, release tag or published artifact update. Baseline 4b18679, candidate f24fb96.

Correctness and execution contracts

  • Reject invalid JSON grammar, non-finite weights, overflowing dimensions/counts and malformed pair tables before unsafe allocation/casts. Fix actual wasm32 precedence and weighted-capacity overflow reproductions.
  • Reject invalid anneal/polish starts even at zero work. Add independent exact oracles and pin RNG/fixed-work thread parity.
  • Preserve legacy candidate plan; add explicit plan_status and released_plan. Refused diagnostics are not authorization, and partial projections still require consistent completion of coupled assignments.
  • Validate stored strand structure/lifecycle before append. Full/fast verification and continuation agree on illegal checkpoints after controls, retirement or another checkpoint.
  • Require explicit synthetic-source authorization for source-restricted fuzz fixtures and replay exported fixtures strictly. Harden Python binary/input/error handling and MCP protocol boundaries.
  • Add a runnable local host-enforcement example: incident/history/repaired scenarios dispatch 2 → 3 → 2 calls, with replay and a scoped repaired-rule proof. No model, credentials or external actions.

CLI, monitor and installation

  • Consistent single-document persona --pretty, canonical state files, actionable JSONL/text exceptions and invalid-flag errors.
  • Explicit synthetic-demo/loop labels, legends, lifecycle/checkpoint status and an eight-event drives demo. Original tutor replay preserved. Real browser live-append and narrow-screen regressions included.
  • Correct ARM64/musl installer routing; user-local shell default; validate candidate before replacing existing shell/PowerShell installs; correct .NET null binding for PowerShell replacement.
  • Exact npm signal forwarding, bounded downloads and selector validation. npm 11/12 fixture tests compare installed candidate bytes and reject corrupt checksums, including lazy first-use installation.
  • Preserve the declared Rust 1.78 minimum with a compatible lockfile. CI includes full OS installation/integration checks, actual ARM64 Linux execution, Intel Mac/Rosetta and Windows static binaries, Node 18 and real browser/WASM checks.

Observed local validation

  • 287 Rust tests passed, 0 failed, 1 existing ignored (release workspace suite).
  • 44 Python/MCP tests passed, including host-enforcement regression; Node example preserves four documented exit codes.
  • 13 npm process/platform tests passed; clean-prefix shell/npm 11.17.0/npm 12.2.0 install scenarios pass on macOS ARM64.
  • 500 independent small models / 1,000 enumeration comparisons within the regression suite.
  • Actual WASM: 34 boundary calls / 11 native-parity cases; 60/60 historical persona stances and 12/12 puzzle branches retained.
  • Actual Chrome monitor/playground: controls, invalid-input recovery, partial-line/live append, loop restart, raw-document parity, checkpoint/pause display and 390px layout. Nine monitor screenshots; no browser exceptions.
  • Independent review found and rechecked two fixes: PowerShell replacement null binding and full-replay checkpoint eligibility. Final npm test scoping independently reviewed.

Final cross-platform CI: 11/11 jobs passed on candidate f24fb96: https://github.com/BitmapAsset/probbit/actions/runs/38093592161

  • Full native, Python/MCP, npm and clean-prefix installation checks passed on Ubuntu, macOS and Windows. Windows exercised both PowerShell 5.1 and 7; Linux also exercised npm 12.
  • Real Linux browser/WASM/live-monitor checks, Node 18 wrapper contracts and Rust 1.78 locked build passed.
  • x86 Linux musl, Intel Mac/Rosetta, actual ARM64 Linux and Windows static-CRT smoke runs passed, alongside the ARM64 cross-build.
  • Parent independently verified the successful run and exact head SHA. Ready for review; not merged or released.

Earlier runs exposed PowerShell replacement and npm 12 test-fidelity failures. The fixes are in this passing candidate; compilation was not treated as installation validation.

Compatibility and limits

  • No gate threshold, frozen stress corpus or RNG retuning; historical persona goldens retained.
  • Shell default changes to ~/.local/bin; PROBBIT_INSTALL_DIR still overrides it. Invalid JSON/oversized counts, damaged strands and malformed Python requests fail more strictly.
  • One-shot strand continuation now performs O(history) structural validation. Source labels are not authentication; checkpoint verification does not replace full replay or external anchoring.
  • One existing intentionally ignored gate-alone measurement remains documented. CI also skips an existing wall-clock-bound fallback path; the local suite exercises it.
  • Ordinary Clippy completes with inherited warnings; global rustfmt and -D warnings are not clean. No warnings suppressed or broad production reformat hidden in these repairs.
  • diagnostics_passed remains heuristic with published counterexamples. No universal application, every-CPU/OS, unlimited-resource, model-obedience or subjective-experience guarantee.

@BitmapAsset
BitmapAsset marked this pull request as ready for review October 10, 2026 23:21
@BitmapAsset
BitmapAsset merged commit da7e3a9 into main Oct 11, 2026
11 checks passed
@BitmapAsset
BitmapAsset deleted the harden/release-20261010 branch October 11, 2026 00:17
@BitmapAsset BitmapAsset mentioned this pull request Oct 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant