Roadmap
The repository's ROADMAP.md
is the source of truth. A3S Use has not shipped a supported product release and
is not production-ready. Completed contracts and tests are implementation
evidence, not a release claim.
Current protocol baseline
The current preview accepts one contract line only:
Before the first supported release, superseded preview schemas, APIs,
receipts, and disk state are deleted rather than maintained. Unsupported state
fails closed with cleanup and reinstall guidance. SemVer, requires_use,
host target, and provider capability checks remain mandatory correctness rules.
Domain packages remain outside the package manager itself. In the current
phase, a3s-use-science is not part of this repository, workspace, runtime,
CI, or release graph; a future integration must arrive as a signed Registry
package through the same public package contract as any other domain package.
Host protocol v6 binds an explicit User or Workspace scope kind and derives
operation phases and bounded checkpoint counts only from durable Host, graph,
enablement, and lifecycle evidence. Equal textual IDs in different kinds have
different fences and replay stores. A status revision binds the complete
projection, watch long-polls that revision for at most 30 seconds, and
explicit-user cancellation is accepted only before durable admission.
Multi-package progress never attributes a currentSurface to the wrong
package, and only a durable Host outcome reports Completed.
ROADMAP A2 is the next release-critical authority cutover. ADR-003 requires a per-installation SQLite/WAL Control Store, typed aggregate transactions, and an outbox for external provider effects. The database may be qualified before it is activated, but it must never mirror the current JSON authority; graph, operation, Grant, enablement, binding, capability, reachability, diagnostic, backup, and restore readers switch together.
The repository now carries a machine-checked coordinated cutover inventory. It accounts for every supported installation-state leaf exactly once and pins the consumer groups that must switch without dual writes or fallback reads. This freezes the implementation boundary only; production activation remains inactive and no A2 item is complete.
The checked-in Control Store kernel is deliberately inactive. Its clean-state
schema-v11 aggregate persists each canonical complete reviewed Plan envelope and
versioned authorization record. It derives operation identity, Plan and
authorization digests, action, root package, installation scope, and generation
cursors from that evidence and checks every relational projection after restart
and in offline export or restore. Installation, desired package-state, and
immutable package-lifecycle generations remain independent. The complete next
snapshot, both package generation axes, and complete target Grant inventory are
deterministically projected from the reviewed Plan, exact prior generation,
bounded committed history, and authorization-v2 prior snapshot/change-set/
confirmation evidence. Resolved Grant bytes, digests, and receipt revisions are
derived rather than caller-selected. Commit, offline export, and restore reject
divergence across all five actions, User and Workspace installations, shared
roots, and uninstall/reinstall. It also derives the exact reviewed Runtime
provider selection for every enabled Tool and MCP surface, retaining unrelated
selections and removing disabled or removed ones. The candidate capability
digest binds the target snapshot, package lifecycle identities, Grant
revisions, and provider selections without claiming applied endpoints,
readiness, compiled artifacts, or Knowledge observations. The same projection
derives the complete bounded inventory of work that cannot join the local
transaction: surface preparation, capability cutover, accepted-call drain, and
surface stop or removal. Dependency surfaces prepare first and retire in
reverse order. Every intent binds a typed Capability Index, invocation-lease,
Runtime, Flow, Knowledge, Skill, or UI owner; Tool and MCP effects retain the
exact reviewed provider selection. Package state, lifecycle identity, Grants,
and provider selection remain transaction facts rather than pseudo effects.
Payload bytes, a domain-separated idempotency key, digest, and relational
projection commit together; claim and completion rebind them to the committed
generation after restart and reject incomplete outbox inventory. Applied
outcomes now retain canonical owner-specific Capability Index plus its
immutable Agent-catalog binding, invocation lease, Runtime Task/opaque-Service
readiness, Flow artifact, Knowledge projection, or Skill/UI content evidence; deferred, rejected, and unknown
outcomes cannot carry applied state. Deferred proves that the owner accepted no
effect and persists a bounded not-before time for automatic same-key retry.
Recording the cutover application atomically advances publication and its
catalog identity before drain. A later required failure remains effects-pending for
same-key reconciliation instead of rolling back visible state, and completion
cannot predate provider observations. The kernel also qualifies snapshots,
full Grants, reviewed provider selections, capability history, explicit
unknown/expired-claim reconciliation, deterministic offline-verifiable export,
and clean staged restore. Its inactive one-effect dispatcher retains one
installation-wide shared maintenance fence from claim through durable observation, commits a claim,
releases the transaction and bounded executor before owner I/O, routes the exact
identity through separate Capability Index, invocation-lease, Runtime, Flow,
Knowledge, Skill, or UI ports, and records a later owner-shaped observation.
An owner-proven safe-no-effect deferral blocks claims until its durable
not-before time and then retries only the original key without reconciliation.
Provider timeout must leave a fixed observation budget inside the claim lease
and becomes unknown evidence. Timeout or caller cancellation detaches only the
wait; the possibly accepted owner task retains the same shared maintenance
guard until it actually completes. Process exit, expired claims, and ambiguity
require explicit same-key reconciliation. Tests cover Store re-entry during
provider I/O, all seven routes, hung-provider bounding, task panic, cancelled
waits, and exit after an unobserved effect. A concurrent whole-installation
restore cannot acquire its exclusive fence before the observation is durable
or while a detached in-process effect remains active. The same claim transaction now derives owner-shaped committed
context. Package ports receive only the exact selection, lifecycle, host,
snapshot identity, and Grant; Runtime also receives the complete reviewed
provider selection. Capability Index receives the candidate generation and the
latest terminal preparation for every enabled selected surface, including
retained multi-root history and optional degradation. Missing Grant coverage,
nonterminal or teardown state, and generation drift fail closed before owner
I/O. Multi-package generation commit now inserts the complete node set before
immediate-foreign-key dependency edges in the same transaction. The Artifact
Store now supplies a non-cloneable verified package lease that holds the global
reachability and per-artifact mutation locks, rejects quarantine or incomplete
GC, binds the complete package fingerprint, bounded manifest, exact
measurements, catalog surface graph, and declared files, and exposes no package
root. The first concrete post-commit adapter now uses that lease for immutable
Skill and UI preparation. It re-derives the typed owner and committed
idempotency key, reads only the named surface, re-verifies the complete package,
and emits a stable path-free receipt that excludes retry claim metadata.
Contention is a safe same-key deferral; tampering, absence, or authority
substitution is a proved-no-effect rejection; this read-only adapter cannot
produce unknown acceptance. Static stop/remove remain path-independent.
The OKF Knowledge adapter now uses the same boundary: verified path-free bytes
for first preparation, staged receipt persistence before promotion, promoted
evidence before applied, retained-receipt replay without Artifact access, and
unknown classification for every ambiguous external or post-effect write
boundary. A real SQLite composition test covers committed claim through durable
Control observation. Artifact-only admission is idempotent, revalidates the
prepared source, creates no lifecycle receipt, and retains reference admission
through the separate Control commit. Capability Index and invocation leases now
share a third concrete Capability Plane adapter. It writes canonical
content-addressed Index documents while the applied Control observation remains
the sole publication cursor. A Control cursor double-read around shared locks
for every exact package incarnation makes racing admission stale; exclusive
drain safely defers while an accepted call is active. Publication is no-follow,
no-replace, and crash-replayable. Index and lease files are derived operational
state excluded from backup and the Index must be rebuilt from restored Control
evidence. Coordinated legacy inventory now admits canonical catalog and
descriptor-snapshot records as the strict CapabilityPayloads family and
rejects owner staging/lock/journal residue; production owner-native restore,
retention, and Control registry cutover remain open. A real composition test covers Knowledge, Skill, cutover, stale
admission, and same-key drain retry. The strict descriptor projector now
consumes host-verified CapabilityDescriptionProof values under an explicit
package-scoped signer allowlist. It checks exact package/lifecycle/catalog
provenance, selected-surface dependencies, prepared owner receipts, active
Grant coverage, and reviewed Tool/MCP shape before deriving opaque route
references. This remains a deterministic subset gate: key custody remains
open. An installation-owned descriptor snapshot store now captures the exact
normalized proof set and signer policy under the Control candidate identity;
canonical bytes are content-addressed, bounded, no-follow, no-clobber, and
revalidated on restart. Missing evidence safely defers, while substitution,
duplicate keys, or tampering fails closed. Coordinated backup validates and
archives the canonical snapshot, while the store remains an inactive external
owner. Runtime Tool release planning now carries canonical input/output-schema
attestation through the inactive Runtime and Control path; production
Control/Runtime wiring, key custody, owner-native clean-target restore/retention
remain open. The core now defines a
domain-separated SignedCapabilityDescription envelope, and the extension
boundary verifies it with a bounded Ed25519 trust store that checks key
rotation, expiry, and revocation. The Gateway facade now verifies signed
envelopes before acquiring its Control snapshot lease or provider resolver.
This is a qualified mechanism/composition seam only: the Registry/TUF key
source, Control proof admission, and production lifecycle wiring remain open.
The inactive Flow owner now follows the
same boundary: it reads a path-free verified source payload, publishes a
durable no-clobber content-addressed owner copy, and delegates Native
TypeScript preflight only to a3s-flow. Package roots never cross the owner
boundary; source substitution and failed preflight reject without a Control
observation, while Artifact Store contention safely defers under the same key.
The inactive Runtime owner now follows the same committed boundary for
release-backed Tool Tasks, Tool Services, and Streamable HTTP MCP. First
prepare reads only a path-free verified release payload. Tasks persist no
Runtime unit; Services persist requested, exact Runtime observation, typed
Gateway readiness, and the final binding in monotonic order. Final receipts
replay without Artifact access, terminal provisioning overlap reconciles
without reapply, and retirement uses only exact receipt-owned evidence.
Pre-effect contention defers, authority or byte drift rejects, and every
post-effect ambiguity remains unknown. Runtime now exposes a bounded canonical
plan payload and restart-safe resolver that reconstructs the complete plan from
committed semantics-digest authority and rechecks exact provider evidence.
The installation-scoped, host-owned RuntimeSurfacePlanStore is now qualified
as the durable source, with canonical digest addressing, bounded batch
publication, no-clobber writes, restart-safe reads, and fail-closed tamper
checks. It owns payload bytes rather than desired state, so exact new records
must publish before the corresponding Control commit. The inactive lifecycle
admission seam accepts the canonical cognitive-package Plan, authorization
evidence, and optional planned Grant transition, derives both prior Control
cursors from the immutable Plan, and accepts no caller-selected generation. The
combined qualification entry point retains one shared fence while registering
the exact reviewed operation, deriving the complete Control transition,
verifying exact Runtime prepare coverage and reviewed Grant proposal digests,
and ordering immutable plan publication before the projected generation commit.
Production lifecycle still must route through this seam and construct the
dispatcher from committed authority rather
than use the process-local selection retained by this qualification. This
narrows the cutover boundary but does not activate the private kernel or accept
caller-selected transition fields.
The private path-free payload contract now freezes six external owner IDs and
their ACL backup policies. It excludes the global Artifact Store and requires
one complete canonical receipt set for the other five owners, bound to an exact
installation, Control generation, registry/owner schemas, digests, and bounded
accounting. A private session now freezes the exact canonical Control export
digest under one exclusive maintenance fence and releases the SQLite
transaction before owner I/O. The Knowledge owner can create and independently
verify a registered-size-bounded OKF SQLite/FTS5 archive and canonical
binding/selection inventory; absence is a zero-file manifest that creates no
live state. Snapshot creation and offline verification require the exact bound
Control export, join every retained incarnation to its prepare intent and
committed OKF bundle, compare applied observation/projection evidence, and
require a matching remove effect for removed or missing applied data. Deferred
outcomes remain safe-no-effect scheduling evidence; claimed and unknown outcomes
remain reconciliation evidence only. None selects desired state. It is not wired to
the legacy backup scanner. A verified Knowledge snapshot can now stage and
re-audit its exact database beneath a clean target state root, then publish it
by one atomic rename while the exact exclusive maintenance fence is held.
Post-rename retry is idempotent while that staged attempt and fence remain held.
Unowned, existing, ambiguous, linked, rebound, or policy-mismatched targets
fail closed, and absent state creates no payload. The
planning-and-diagnostic observation owner now has a concrete bounded snapshot
and clean-target restore boundary. It uses each cognitive store's own
validator, archives only terminal diagnostic histories and terminal resolution
attempts, and manifest-binds the count and canonical path/digest inventory of
excluded active resolution/download records. Locks never enter restore
authority. No-follow traversal, duplicate checks, a second scan, no-clobber
publication, and exact archive verification reject drift and substitution. An
offline-verified archive can be staged without touching live owner paths;
activation requires the exact exclusive maintenance fence, a clean initial
record inventory, an atomic activating marker, and digest-named deterministic
partials for exact-subset replay. The Host protocol projection now has a third
concrete snapshot, offline-verification, and clean-target restore boundary. It
archives only owner-validated request-to-plan, optional outcome, and canonical
cancellation records. Derived operation and latest-enablement indexes must be
complete and consistent but never enter the archive. A second bounded no-follow
scan and exact Control-export reconciliation precede no-clobber publication, so
the projection cannot choose desired state or package/capability generations.
No-change requests remain explicit without inventing operations. A verified
snapshot can build a complete target-local owner root from exact source bytes
and newly derived canonical indexes while excluding legacy aliases and locks.
Activation requires the exact exclusive maintenance fence and an absent live
root, writes a snapshot-bound marker, re-audits the exact physical and semantic
inventory, and atomically publishes the whole root without replacement.
Deterministic archive, record, and marker partials plus post-publication replay
cover the local crash boundaries. The Restore Coordinator is now the fourth
concrete snapshot and restore owner. Its owner-native journal
decoder archives only exact canonical completed operations for the bound
installation. The active marker and operation are excluded while their bounded
digest inventory remains manifest-bound, including marker-only handoff.
Orphaned nonterminal operations, pruning or temporary residue, unknown entries,
links, foreign history, and path rebinding fail closed. A second scan precedes
no-clobber publication, and streaming offline verification binds exact terminal
bytes and a path-free receipt to the Control export. Empty or active-only
history creates no archive. Its self-hosted restore adapter preserves the active
marker and any current operation while replayably replacing only terminal
history. Durable activation evidence binds exact before/source/target
inventories. A legacy whole-installation marker reserves one slot at the native
64-record limit; the typed complete-set marker has no retained operation and
preserves all 64 records. Marker-only handoff, status progress, and every local
partial are deterministic and tamper-evident. The Runtime plan owner is the
fifth snapshotted owner. It captures immutable installation-scoped plan
envelopes, validates complete key/plan binding, restores them before Host
projection activation, and contributes referenced Runtime blob digests to
installation reachability. The private complete-set snapshot coordinator now
captures one canonical Control export and all five registered owner snapshots
beneath one maintenance fence and timestamp. A path-free
canonical manifest binds the exact registry, receipts, schemas, digests, and
byte accounting. One fixed-order archive is streamed outside every Use data and
state root, fully audited through the owner-native offline verifiers, and
published without replacement. Absent owners add no payload, and the global
Artifact Store stays excluded. The verified aggregate can now stage one
deterministic clean-target attempt beneath .control-installation-restore.
One path-free descriptor binds the exact snapshot, installation, registry,
Knowledge policy, and six-component set before a retained exclusive fence
builds Control and every owner-native candidate. Control is checkpointed to one
SQLite file, export-round-tripped, and physically digest-bound; no live owner
path is changed. Exact retry and interrupted Control staging recover, while
target contamination, links, unknown entries, rebinding, and completed-candidate
drift fail closed. Complete activation now preflights every owner before durable
top-level intent. The immutable attempt remains authoritative,
activation.json is the sole mutable ordered journal, and the typed global
.maintenance.restore.json marker binds the same immutable operation while
blocking ordinary shared access. Control Store, Runtime plans, Host projection,
Knowledge, observations, and Restore Coordinator execute in fixed order; every
step follows journal, marker, owner effect, checkpoint. Each checkpoint binds its canonical
path-free result by byte count and a domain-separated digest, while the
coordinator owner additionally verifies the exact marker bytes, length, and
digest before mutation. Reopen reacquires the exact guard, rebinds the same
verified snapshot, attempt, registry, and policy, and reconstructs or verifies
every candidate/live boundary. Journal and marker partials, all six
post-effect/pre-checkpoint boundaries, the sixth checkpoint before retirement,
and exit after deletion converge. Marker absence is accepted only beside the
complete journal; out-of-order roots, ambiguous markers, links, rebinding, and
evidence drift fail closed. Completed replay performs no owner effect and can
only resume bounded fixed-order retirement of the six link-free staging trees.
A 21-boundary real-child-process matrix qualifies the top-level protocol,
including every retirement boundary. The canonical attempt.json and complete
activation.json then form the exact installation-bound terminal receipt.
Legacy backup and artifact reachability exclude only that receipt; incomplete,
extended, linked, or tampered evidence fails closed. Production Grant
conversion, Runtime/Flow dispatcher composition, backup/restore wiring, and
coordinated authority cutover remain open; no A2 roadmap item is complete yet.
Implemented baseline
- Manifest v3 and catalog v3 cover named Tool, MCP, OKF, Flow, Skill, and UI surfaces, package dependencies, permission ceilings, and exact provenance.
InstallationId(kind, id)now partitions mutable package state, receipts, Grants, bindings, capability publication, backup/restore, and locks. Global Registry/TUF inputs and the raw-blob/expanded-tree Artifact Store own no installation authority. Registry sources retain only observations and partials; source prune and scoped uninstall never delete global bytes. Guarded reachability, hard quota admission, and read-only digest audit cover both physical tiers. Exact-plan logical quarantine preserves mismatched bytes in place and blocks new ordinary access through a canonical marker. Verified rehydration now requires a candidate outside the store, exact reviewed evidence, a fresh zero-reference proof, and prepared/completed fail-closed recovery; completed exact replay is read-only and independent of the external candidate and later references. Confirmed GC now requires a bounded explicit target allowlist, fresh all-owner zero-reference proof, exact physical and lifecycle evidence, a durable fail-closed deletion fence, same-shard atomic retirement, and read-only terminal replay. The A1 two-installation gate now runs the same signed OKF package through apply, restart, exact snapshots, leased queries, upgrade, uninstall, and terminal replay in concurrent User and Workspace installations with the same textual ID. Each operation leaves the opposite installation cursor unchanged and its admitted lease callable.- The bounded resolver freezes one Registry/TUF package lock, prepares dependencies forward, publishes one graph snapshot, and retires unused packages in reverse.
- The standalone CLI persists a bounded enabled Registry set in canonical ACL, requires reviewed revisions for authority changes, isolates TUF/cache state by source identity, and restores exact prior evidence without receipt rewrites.
- Plan v4 separates review from mutation and binds operation identity, confirmation, scope, package transitions, impact, Grants, providers, and current-state evidence.
- The Use-owned typed
PluginManagerServicenow implements catalog search and inspection, stable installed-state pagination, status, all frozen planning operations, durable reviewed-plan reopening, and digest-only apply over the production Host Manager. Its standard MCP adapter derives the exact thirteen v5 tools from the frozen contract and obtains apply/cancellation confirmation only from an injected trusted host provider. - The path-free
CapabilityDescriptorand catalog contracts, opaque reference types, exact snapshot lease/generation binding, and embeddingCapabilityGatewayMcpServerare implemented and contract-tested. The adapter publishes only catalog-authorized Tools over standard MCP through an injected provider. Host-owned bounded in-flight and rolling-window admission, plus Streamable HTTP/mcpbearer/Origin enforcement, duplicate header rejection, sanitized HTTP errors, and an independent Rust client discovery/invocation check are also implemented. The provider now exposes an explicit pre-invocation authorization hook that fails closed and sanitizes denial results. The embedding now includes a bounded immutable 64-entry token-to-principal registry (complete credential scan, duplicate-token rejection) and a lease-scopedCapabilityGatewayInvocationResolver. Production receipt/Runtime/Grant composition, CLI wiring, TLS termination, and production-host recovery remain open. - A host can now project a consumer-specific Gateway catalog from one
immutable
CapabilityRegistrySnapshot. The projection rechecks exact package/manifest identity, reviewed publication evidence, selected surfaces, and ready bindings beforeCapabilityGatewayMcpServer::from_registry_snapshotacquires its RAII lease; signature verification and opaque-reference resolution remain host-owned. - The standalone
pluginCLI maps those same ten operations to the service. Planning is non-mutating; exact apply requires the durable operation ID, plan digest, and explicit--yes, while cached apply and replay are zero-network. - Lifecycle journals provide exact crash replay, cutover-aware publication, exact-generation drain, and fail-closed corruption handling.
extension inspect --jsonprojects bounded lifecycle history, whileextension diagnose --jsonreads one retained planned/admitted/cancelled install/upgrade/uninstall graph, active admitted enable/disable operation, or newest Host-reviewed pre-admission enable/disable plan/cancellation without network access or writes and correlates its reviewed plan, Registry/TUF, provider, Grant, cutover, drain, rollback, and recovery evidence.- Retained graphs and pre-plan attempts expose independent expected/retained
archive and signed executable-planning-target bytes plus exact
missing/partial/completestate. Real killed-process tests prove partial observation, exact Range resume, and gap-free handoff to the reviewed graph. - Pre-lock resolution attempts expose refreshed/cached per-Registry TUF progress, path-free source/trust digests, bounded failures, and terminal lock evidence across process exit before handing off durably to download state.
extension diagnose --history --jsonretains the newest 16 validated completed or rolled-back operations and cancelled graph plans within 8 MiB per scope/package, survives uninstall, and deduplicates exact crash replay.- Standalone composition exists for Tool Task, stdio MCP, Skill/UI projection,
SQLite/FTS5 OKF, and injected
a3s-flowNative TypeScript preflight. - The standalone Knowledge backend enforces whole-scope expanded-byte and projection quotas, per-surface generation limits, global tombstone pruning, SQLite/WAL compaction, exact-scope usage diagnostics, SQLite/receipt/FTS audit, non-overwriting verified database backup, canonical exact-plan oldest-first backup rotation, derived-index repair, and authority-bound database restore.
- GitHub Pages and bilingual product documentation exist, but they describe a development preview only.
Remaining release plan
1. Managed-host provider composition — in progress
- The host-owned
RuntimeSurfacePlanStoreis qualified for canonical, bounded, no-clobber plan publication; bind it to the Control commit before activating the production dispatcher. - Compose production Runtime Service and HTTP MCP/Gateway providers with the durable host source, restart-safe resolver, and atomic dispatcher cutover.
- Complete managed Knowledge Workspace/session carriers and leased prior- generation query qualification. Standalone OKF quota/retention/GC is implemented, but managed composition is not.
- Complete UI sandbox ownership, CSP, backend binding, drain, retention, and garbage collection.
- Prove required surfaces remain unpublished whenever ownership or exact readiness evidence is missing.
2. A3S Code TUI hot-plug qualification — in progress
- Migrate the A3S Code TUI and compose the manager MCP in Code on the implemented shared Plugin Manager service. The standalone CLI convergence is complete without replacing compatibility JSON fields; TUI and product presentation wiring must not introduce another plan or mutation path.
- Verify install, invoke, exact-generation upgrade, invoke, uninstall, and restart for all six surfaces and dependency-bearing graphs.
- Prove User/Workspace scope isolation, watcher resumption, terminal-result replay, and no duplicate side effects after crashes.
2a. Arbitrary-agent Capability Gateway — in progress
- PR #192 freezes the portable
descriptor/catalog schemas and adds an embedding standard-MCP adapter. PRs
#199 and
#200 add exact snapshot leases and
separate publication and package lifecycle generations. PR
#202 adds shared bounded admission
and Streamable HTTP
/mcp; PR #203 adds duplicate-header rejection and a real independent Rust client check. The HTTP embedding now also supports a bounded 64-entry token-to-principal registry with complete credential scans and duplicate-token rejection. - Complete live server-side invocation-reference resolution, CLI/service
wiring, TLS deployment, and production recovery. The embedding now exposes
CapabilityGatewayInvocationResolverandCapabilityGatewayResolvedProvider: one opaque reference is resolved to a private lease, checked against the catalog identity, authorized once, and held through invocation. Production receipt/Runtime/Grant composition remains open. CapabilityRegistrySnapshot::capability_gateway_catalogandCapabilityGatewayMcpServer::from_registry_snapshotclose the snapshot-to-catalog composition gap with a bounded, fail-closed projection; this is an embedding primitive, not the live resolver or production multi-principal registry.CapabilityConsumerProfileandCapabilityConsumerNegotiationnow bind an explicitgeneric-mcpora3sprofile to the Gateway. A3S extension labels are canonical and fail closed instead of being silently dropped. This is the typed negotiation boundary only; resources/prompts and production host projection remain open.- Qualify discovery and invocation from independent Rust, TypeScript, and Python clients without a shared package filesystem, including upgrade, restart, uninstall, and denied cross-scope access.
3. Distributed Flow and OS integration — pending
- Keep one package-owned
a3s-flowidentity while adding remote placement, scheduling, suspension, resumption, cancellation, and observation. - Prove remote execution changes placement only; Use still owns the single lock, receipt, and lifecycle journal.
4. Cross-platform real-process matrix — pending
- Windows x86_64 now runs signed Registry trust/lock, dependency-graph
install/upgrade/uninstall, Grant, standalone Flow preflight/lifecycle, and
OKF cutover scenarios through real
a3s-useprocesses. It also replays removed-dependency cleanup after killing an upgrade post-cutover, without inflating the capability generation. - The complete current workspace suite now runs on Windows x86_64.
A deterministic directory-junction regression proves package and durable
state trust boundaries reject Windows reparse points before traversal. Flow
Runtime coverage also retains exact generations, rejects artifact
substitution and tampered or moved bindings, isolates identical textual IDs
by scope kind, and rejects a linked scope directory on Windows. Shared native
link tests also cover Registry target-cache state, retained lifecycle
receipts, package graph and diagnostic stores, enablement locks, Runtime and
lifecycle records, whole-state backup/restore, and OKF database, binding,
backup, and restore paths with real Windows directory junctions. Native
Windows tests also prove single-package and graph cutover-capacity rejection
happens before lifecycle receipt replacement, and that Box CLI delegation
preserves arguments, output, and exit status through a
.cmdcomponent. - Every production temporary-file publication for Registry state/cache, Workspace Grants, package and Host records, lifecycle, Runtime, Flow, Knowledge, enablement, backup, restore, and diagnostics now uses bounded Windows retry primitives while retaining replace versus no-clobber semantics. Restore-journal/Knowledge recovery sources survive bounded rename failures, whole-state restore candidates preserve reviewed file attributes, and lifecycle/restore-history directory moves use the same retry bound. Released file or directory locks converge atomically; a persistent replacement lock stops at two seconds without changing the prior target. Resumable Registry partials now use one final-component no-follow handle through final verification and copying into the global Blob tier. Commit rehashes while copying, publishes without clobber under a digest lock, then reopens and retains the global blob through staging. Canonical source observation publication follows durable blob commit, and partial cleanup is last. Unix commit stays bound to the retained source handle, while Windows permits readers and denies external writes, removal, and replacement. Windows-native scanner tests prove transient no-delete-share contention converges within the two-second cleanup bound. If cleanup remains locked after publication, the durable blob and observation coexist with a redundant complete partial for a later zero-network cleanup retry. Invalid-partial cleanup and stale, partial, and source-observation deletion use the same bounded blocking retry and never delete global blobs. Native tests prove transient convergence and persistent selected-file preservation followed by a residual-inventory rescan. Bounded deletion of lifecycle receipts and abandoned artifact staging uses the same retry. Native tests prove transient receipt/nested-staging convergence. A persistent reader of a complete global artifact never delays scoped uninstall because shared bytes are retained. Native tests also bind active artifact-staging rename contention to the commit state machine: a transient lock lets the same commit finish, while a persistent lock leaves receipt and Registry snapshot untouched, preserves residual staging, and permits exact replay after release. Selected upgrade-receipt replacement now has the same native qualification. A transient lock completes the same upgrade; a persistent lock retains the valid global candidate artifact, removes its retained-receipt candidate state, preserves the exact prior receipt and published generation, leaves no temporary receipt, and permits exact replay after release. Reboot recovery and antivirus contention beyond these exact blob-publication, source-cache-removal, active package-commit, upgrade-receipt replacement, and lifecycle-removal boundaries remain open.
- Run equivalent signed six-surface lifecycle and failure-injection scenarios on declared Linux, macOS, and Windows targets.
- Real-process tests now cover resumable target-download interruption and termination during verified archive extraction. Both withhold all package publication; extraction recovery completes from the revalidated cache with explicit offline mode and no network request.
- A real-process package-copy interruption also proves the durable pending plan and applying journal replay the same generation, reclaim the physical artifact-staging residue, and publish only once without network access.
- Uninstall retires exact scoped lifecycle authority without deleting or waiting on global expanded-package bytes and without advancing the Registry generation again.
- A real-process nine-node install is now killed after its complete Registry graph and durable cutover are visible but before one dependency journal and the parent graph record complete. Explicit offline replay makes no network request, completes the exact graph, and does not advance the generation again.
- Externally killed managed-host processes now cover five-node permission- bearing install, upgrade, and uninstall at Registry publish/hide while the Grant operation is still prepared. Recovery disables reauthorization, makes no network request, preserves the exact candidate Grant, retires only the bound prior Grant, and does not inflate the Registry generation.
- Real Host protocol processes now cover all five reviewed mutations with the Registry server offline. Install, upgrade, and uninstall are killed after five-node graph publication/hide; disable is killed after root hide and Grant cutover while accepted-call drain is blocked; enable is killed after publication while its candidate Grant remains prepared. Restart consumes the durable reviewed plan and confirmation, uses only the verified planning cache for install/upgrade, completes drain and lifecycle/Grant journals, converges the exact candidate/prior Grant or enablement regrant/revocation, and persists replayable terminal Host outcomes without generation inflation.
- Cover interrupted download, archive extraction, cutover, drain, process crash, product-host Grant cutover, reboot, remaining antivirus contention outside blob publication, source-cache removal, and lifecycle removal, and reparse-point replacement races.
5. Supply chain and operations — in progress
- Operate a documented Registry with signing, root rotation, expiry, mirror replacement, offline recovery, and incident procedures.
- Durable Registry add/list/replace/default/enable/disable/remove and exact- identity evidence restoration are implemented; operating and exercising a real production Registry remains open.
- Deterministic archive serialization, cross-platform installers, per-platform SPDX SBOMs, GitHub OIDC provenance/SBOM attestations, and a verified keyless Sigstore checksum bundle now come from one workflow with pinned Actions and release tools.
- Both platform installers now require Cosign, verify the checksum manifest against the exact tag workflow identity before archive download, fail closed on invalid evidence, and retain the verified evidence with each version.
- Byte-for-byte cache-free rebuilds now pass for every shipped native
executable on all five release targets in non-publishing qualification run
33651777660,
from exact
maincommit4f6e4725205d06ab81f8ea98bfee85c7eb4b2bcdwith one release codegen unit; this run never publishes assets. Thev0.3.5publication attempt created no Release because the public core crate was stale. Release workflow 33675697857 passed all 13 jobs for tagv0.3.6at exactmaincommit54758910f2f4ad9498137410e0a2207d412e99a1and publishes the verified archives, installers, SBOM/reproducibility evidence, and typed Use crates in the v0.3.6 Release. Release workflow 33687297386 then passed all 13 jobs for tagv0.3.7at exactmaincommit48a0b76f8a4a87a11d16627c7bd7567920852508and published the current verified archives, installers, SBOM/reproducibility evidence, and typed Use crates in the v0.3.7 Release (a3s-use-core 0.2.6,a3s-use-extension 0.3.7,a3s-use 0.3.7). The independent witness and product gates remain open. - Release workflow
33720485826 then
passed all 13 jobs for tag
v0.3.8at exactmaincommit6d3a7baf32ce998a2e487c40fbf78b4a6cda2579and published the current verified archives, installers, SBOM/reproducibility evidence, and typed Use crates in the v0.3.8 Release (a3s-use-core 0.2.7,a3s-use-extension 0.3.8,a3s-use 0.3.8). The independent witness and product gates remain open. - Release workflow
33756618837 then
passed all 13 jobs for tag
v0.3.9at exactmaincommita5f3cc40bfb0a1021ca150d2ce4295409b74d220and published the current verified archives, installers, SBOM/reproducibility evidence, and typed Use crates in the v0.3.9 Release (a3s-use-core 0.2.7,a3s-use-extension 0.3.9,a3s-use 0.3.9). The independent witness and product gates remain open. - Release workflow
33791616307 then
passed all 13 jobs for tag
v0.3.10at exactmaincommitc4c80a223bfff3698ca4b4598e7175c6e3303239and published the current verified archives, installers, SBOM/reproducibility evidence, and typed Use crates in the v0.3.10 Release (a3s-use-core 0.2.8,a3s-use-extension 0.3.10,a3s-use 0.3.10). The independent witness and product gates remain open. - Release workflow
33830280138 then
passed the validation, five-target primary-build, typed-crate, and
five-target independent-rebuild gates for tag
v0.3.11at exactmaincommitc25028ae0245ba1d28f7e2837e2a87f7e9f6fe40and published the current verified archives, installers, SBOM/reproducibility evidence, and typed Use crates in the v0.3.11 Release (a3s-use-core 0.2.9,a3s-use-extension 0.3.11,a3s-use 0.3.11). The independent witness and product gates remain open. - Add an externally operated witness for the complete staged tree/final archive and retain verification evidence outside the Release asset trust boundary.
- Exercise missing Registry/package/lifecycle/Grant authority recovery,
clean-machine recovery, cross-platform restore/retention drills, whole-product storage
policy, telemetry, security response, and support runbooks. OKF scope
audit/backup/FTS repair and authority-bound database plus exact-subset
missing-binding restore are implemented and crash-tested; conflicting or
newer binding evidence fails closed. Deterministic whole-installation
inventory backup now covers every allowlisted Use-owned family under one
exclusive fence, binds Registry/receipt authority, rejects nonterminal or
unsafe state, and verifies all payloads offline without extraction. The
immutable Capability Gateway catalog and descriptor-snapshot records are
admitted as the strict
CapabilityPayloadsfamily with canonical and content-address checks; production owner-native restore/retention remains open. Reviewed same-version/OS/architecture whole-install restore is now implemented with an exact path-free action plan, unchanged live Registry and Grant authority, an external rollback archive, link/reparse-safe candidates, seven durable phases, 15 process-exit recovery boundaries, terminal replay, and read-only bounded status/history. The archive remains integrity evidence and cannot recreate missing authority. Whole-installation retention now fully verifies every managed archive under one external-directory lock, returns a path-free oldest-first canonical plan, requires exact digest confirmation, and preserves two recovery generations. Exact-plan oldest-first scope backup rotation and path-free active/history/ capacity diagnostics are also available. Retained planned, admitted, and cancelled install/upgrade/uninstall graphs and active admitted enable/disable operations now have a bounded cross-product diagnostic. Retained Registry-backed install/upgrade graphs and process-resilient pre-plan attempts expose zero-network expected/retained archive bytes and exact-target missing/partial/complete state. The same exact locks now expose independent planning-target byte progress. The newest Host-reviewed pre-admission enable/disable request is projected asplannedorcancelled; active/completed Use evidence takes precedence, and private Host request/fence identity is excluded. Retired operations now have bounded, zero-network, newest-first history with terminal outcome validation and fail-closed corruption handling. Real Host/CLI tests prove the pre-admission projection performs no network, authorization, admission, or lifecycle side effect and suppresses stale evidence during Host finalization.
Production-ready definition
A3S Use is ready to publish only when a user can choose a trusted Registry, review one exact plan, install a signed dependency graph, hot-use all six surface types in supported hosts, recover without guessing, upgrade without mixed generations, and uninstall without leaving routes, Grants, processes, projections, or package-owned state behind on every declared platform.