For AI agents: the complete documentation index is available at https://a3s-lab.github.io/Use/en/llms.txt, the full documentation bundle is available at https://a3s-lab.github.io/Use/en/llms-full.txt, and this page is available as Markdown at https://a3s-lab.github.io/Use/en/guide/roadmap.md.

Roadmap

The repository's ROADMAP.md is the source of truth. A3S Use has not shipped a supported product release and is not production-ready. Completed contracts and tests are implementation evidence, not a release claim.

Current protocol baseline

The current preview accepts one contract line only:

ContractCurrent value
Cognitive-package manifestschema 3
Signed cataloga3s.use.plugin-catalog.v3
Installed receiptschema 6
Extension Registry snapshotschema 3
Capability snapshotschema 5
Capability descriptora3s.use.capability-descriptor.v1
Capability Gateway cataloga3s.use.capability-gateway-catalog.v1
Capability consumer profilea3s.use.capability-consumer-profile.v1
Consumer negotiationa3s.use.capability-consumer-negotiation.v1
Snapshot cursorsa3s.use.extension-snapshot-cursor.v3 / a3s.use.capability-snapshot-cursor.v4
Operation plana3s.use.plugin-operation-plan.v4
Host capabilitiesa3s.use.plugin-host-capabilities.v6, protocol 6
Host managed scopea3s.use.plugin-managed-scope.v2
Host operation observationa3s.use.plugin-host-operation-observation-request/result.v1
Host operation watcha3s.use.plugin-host-operation-watch-request.v1
Host cancellationa3s.use.plugin-host-cancel-request/result.v1
Manager MCP toolsa3s.use.plugin-manager-tools.v5 (v4 migration contract remains readable)
Pending package grapha3s.use.pending-package-graph-operation.v4
Pre-lock resolution attempta3s.use.plugin-resolution-attempt.v1
Pre-plan download attempta3s.use.plugin-download-attempt.v1
Operation diagnostica3s.use.plugin-operation-diagnostic.v1
Operation historya3s.use.plugin-operation-history.v1 / a3s.use.plugin-operation-history-diagnostic.v1
Pre-lock resolution diagnostica3s.use.plugin-resolution-attempt-diagnostic.v1
Pre-plan download diagnostica3s.use.plugin-download-attempt-diagnostic.v1
Enablement state/operationv3
Coordinated state backupa3s.use.state-backup.v2
Coordinated state restore plana3s.use.state-restore-plan.v1
Coordinated restore operationa3s.use.state-restore-operation.v1
Coordinated restore resulta3s.use.state-restore-result.v1
Coordinated restore diagnostica3s.use.state-restore-diagnostic.v1
OKF contentv0.2 only

Before the first supported release, superseded preview schemas, APIs, receipts, and disk state are deleted rather than maintained. Unsupported state fails closed with cleanup and reinstall guidance. SemVer, requires_use, host target, and provider capability checks remain mandatory correctness rules.

Domain packages remain outside the package manager itself. In the current phase, a3s-use-science is not part of this repository, workspace, runtime, CI, or release graph; a future integration must arrive as a signed Registry package through the same public package contract as any other domain package.

Host protocol v6 binds an explicit User or Workspace scope kind and derives operation phases and bounded checkpoint counts only from durable Host, graph, enablement, and lifecycle evidence. Equal textual IDs in different kinds have different fences and replay stores. A status revision binds the complete projection, watch long-polls that revision for at most 30 seconds, and explicit-user cancellation is accepted only before durable admission. Multi-package progress never attributes a currentSurface to the wrong package, and only a durable Host outcome reports Completed.

ROADMAP A2 is the next release-critical authority cutover. ADR-003 requires a per-installation SQLite/WAL Control Store, typed aggregate transactions, and an outbox for external provider effects. The database may be qualified before it is activated, but it must never mirror the current JSON authority; graph, operation, Grant, enablement, binding, capability, reachability, diagnostic, backup, and restore readers switch together.

The repository now carries a machine-checked coordinated cutover inventory. It accounts for every supported installation-state leaf exactly once and pins the consumer groups that must switch without dual writes or fallback reads. This freezes the implementation boundary only; production activation remains inactive and no A2 item is complete.

The checked-in Control Store kernel is deliberately inactive. Its clean-state schema-v11 aggregate persists each canonical complete reviewed Plan envelope and versioned authorization record. It derives operation identity, Plan and authorization digests, action, root package, installation scope, and generation cursors from that evidence and checks every relational projection after restart and in offline export or restore. Installation, desired package-state, and immutable package-lifecycle generations remain independent. The complete next snapshot, both package generation axes, and complete target Grant inventory are deterministically projected from the reviewed Plan, exact prior generation, bounded committed history, and authorization-v2 prior snapshot/change-set/ confirmation evidence. Resolved Grant bytes, digests, and receipt revisions are derived rather than caller-selected. Commit, offline export, and restore reject divergence across all five actions, User and Workspace installations, shared roots, and uninstall/reinstall. It also derives the exact reviewed Runtime provider selection for every enabled Tool and MCP surface, retaining unrelated selections and removing disabled or removed ones. The candidate capability digest binds the target snapshot, package lifecycle identities, Grant revisions, and provider selections without claiming applied endpoints, readiness, compiled artifacts, or Knowledge observations. The same projection derives the complete bounded inventory of work that cannot join the local transaction: surface preparation, capability cutover, accepted-call drain, and surface stop or removal. Dependency surfaces prepare first and retire in reverse order. Every intent binds a typed Capability Index, invocation-lease, Runtime, Flow, Knowledge, Skill, or UI owner; Tool and MCP effects retain the exact reviewed provider selection. Package state, lifecycle identity, Grants, and provider selection remain transaction facts rather than pseudo effects. Payload bytes, a domain-separated idempotency key, digest, and relational projection commit together; claim and completion rebind them to the committed generation after restart and reject incomplete outbox inventory. Applied outcomes now retain canonical owner-specific Capability Index plus its immutable Agent-catalog binding, invocation lease, Runtime Task/opaque-Service readiness, Flow artifact, Knowledge projection, or Skill/UI content evidence; deferred, rejected, and unknown outcomes cannot carry applied state. Deferred proves that the owner accepted no effect and persists a bounded not-before time for automatic same-key retry. Recording the cutover application atomically advances publication and its catalog identity before drain. A later required failure remains effects-pending for same-key reconciliation instead of rolling back visible state, and completion cannot predate provider observations. The kernel also qualifies snapshots, full Grants, reviewed provider selections, capability history, explicit unknown/expired-claim reconciliation, deterministic offline-verifiable export, and clean staged restore. Its inactive one-effect dispatcher retains one installation-wide shared maintenance fence from claim through durable observation, commits a claim, releases the transaction and bounded executor before owner I/O, routes the exact identity through separate Capability Index, invocation-lease, Runtime, Flow, Knowledge, Skill, or UI ports, and records a later owner-shaped observation. An owner-proven safe-no-effect deferral blocks claims until its durable not-before time and then retries only the original key without reconciliation. Provider timeout must leave a fixed observation budget inside the claim lease and becomes unknown evidence. Timeout or caller cancellation detaches only the wait; the possibly accepted owner task retains the same shared maintenance guard until it actually completes. Process exit, expired claims, and ambiguity require explicit same-key reconciliation. Tests cover Store re-entry during provider I/O, all seven routes, hung-provider bounding, task panic, cancelled waits, and exit after an unobserved effect. A concurrent whole-installation restore cannot acquire its exclusive fence before the observation is durable or while a detached in-process effect remains active. The same claim transaction now derives owner-shaped committed context. Package ports receive only the exact selection, lifecycle, host, snapshot identity, and Grant; Runtime also receives the complete reviewed provider selection. Capability Index receives the candidate generation and the latest terminal preparation for every enabled selected surface, including retained multi-root history and optional degradation. Missing Grant coverage, nonterminal or teardown state, and generation drift fail closed before owner I/O. Multi-package generation commit now inserts the complete node set before immediate-foreign-key dependency edges in the same transaction. The Artifact Store now supplies a non-cloneable verified package lease that holds the global reachability and per-artifact mutation locks, rejects quarantine or incomplete GC, binds the complete package fingerprint, bounded manifest, exact measurements, catalog surface graph, and declared files, and exposes no package root. The first concrete post-commit adapter now uses that lease for immutable Skill and UI preparation. It re-derives the typed owner and committed idempotency key, reads only the named surface, re-verifies the complete package, and emits a stable path-free receipt that excludes retry claim metadata. Contention is a safe same-key deferral; tampering, absence, or authority substitution is a proved-no-effect rejection; this read-only adapter cannot produce unknown acceptance. Static stop/remove remain path-independent. The OKF Knowledge adapter now uses the same boundary: verified path-free bytes for first preparation, staged receipt persistence before promotion, promoted evidence before applied, retained-receipt replay without Artifact access, and unknown classification for every ambiguous external or post-effect write boundary. A real SQLite composition test covers committed claim through durable Control observation. Artifact-only admission is idempotent, revalidates the prepared source, creates no lifecycle receipt, and retains reference admission through the separate Control commit. Capability Index and invocation leases now share a third concrete Capability Plane adapter. It writes canonical content-addressed Index documents while the applied Control observation remains the sole publication cursor. A Control cursor double-read around shared locks for every exact package incarnation makes racing admission stale; exclusive drain safely defers while an accepted call is active. Publication is no-follow, no-replace, and crash-replayable. Index and lease files are derived operational state excluded from backup and the Index must be rebuilt from restored Control evidence. Coordinated legacy inventory now admits canonical catalog and descriptor-snapshot records as the strict CapabilityPayloads family and rejects owner staging/lock/journal residue; production owner-native restore, retention, and Control registry cutover remain open. A real composition test covers Knowledge, Skill, cutover, stale admission, and same-key drain retry. The strict descriptor projector now consumes host-verified CapabilityDescriptionProof values under an explicit package-scoped signer allowlist. It checks exact package/lifecycle/catalog provenance, selected-surface dependencies, prepared owner receipts, active Grant coverage, and reviewed Tool/MCP shape before deriving opaque route references. This remains a deterministic subset gate: key custody remains open. An installation-owned descriptor snapshot store now captures the exact normalized proof set and signer policy under the Control candidate identity; canonical bytes are content-addressed, bounded, no-follow, no-clobber, and revalidated on restart. Missing evidence safely defers, while substitution, duplicate keys, or tampering fails closed. Coordinated backup validates and archives the canonical snapshot, while the store remains an inactive external owner. Runtime Tool release planning now carries canonical input/output-schema attestation through the inactive Runtime and Control path; production Control/Runtime wiring, key custody, owner-native clean-target restore/retention remain open. The core now defines a domain-separated SignedCapabilityDescription envelope, and the extension boundary verifies it with a bounded Ed25519 trust store that checks key rotation, expiry, and revocation. The Gateway facade now verifies signed envelopes before acquiring its Control snapshot lease or provider resolver. This is a qualified mechanism/composition seam only: the Registry/TUF key source, Control proof admission, and production lifecycle wiring remain open. The inactive Flow owner now follows the same boundary: it reads a path-free verified source payload, publishes a durable no-clobber content-addressed owner copy, and delegates Native TypeScript preflight only to a3s-flow. Package roots never cross the owner boundary; source substitution and failed preflight reject without a Control observation, while Artifact Store contention safely defers under the same key. The inactive Runtime owner now follows the same committed boundary for release-backed Tool Tasks, Tool Services, and Streamable HTTP MCP. First prepare reads only a path-free verified release payload. Tasks persist no Runtime unit; Services persist requested, exact Runtime observation, typed Gateway readiness, and the final binding in monotonic order. Final receipts replay without Artifact access, terminal provisioning overlap reconciles without reapply, and retirement uses only exact receipt-owned evidence. Pre-effect contention defers, authority or byte drift rejects, and every post-effect ambiguity remains unknown. Runtime now exposes a bounded canonical plan payload and restart-safe resolver that reconstructs the complete plan from committed semantics-digest authority and rechecks exact provider evidence. The installation-scoped, host-owned RuntimeSurfacePlanStore is now qualified as the durable source, with canonical digest addressing, bounded batch publication, no-clobber writes, restart-safe reads, and fail-closed tamper checks. It owns payload bytes rather than desired state, so exact new records must publish before the corresponding Control commit. The inactive lifecycle admission seam accepts the canonical cognitive-package Plan, authorization evidence, and optional planned Grant transition, derives both prior Control cursors from the immutable Plan, and accepts no caller-selected generation. The combined qualification entry point retains one shared fence while registering the exact reviewed operation, deriving the complete Control transition, verifying exact Runtime prepare coverage and reviewed Grant proposal digests, and ordering immutable plan publication before the projected generation commit. Production lifecycle still must route through this seam and construct the dispatcher from committed authority rather than use the process-local selection retained by this qualification. This narrows the cutover boundary but does not activate the private kernel or accept caller-selected transition fields. The private path-free payload contract now freezes six external owner IDs and their ACL backup policies. It excludes the global Artifact Store and requires one complete canonical receipt set for the other five owners, bound to an exact installation, Control generation, registry/owner schemas, digests, and bounded accounting. A private session now freezes the exact canonical Control export digest under one exclusive maintenance fence and releases the SQLite transaction before owner I/O. The Knowledge owner can create and independently verify a registered-size-bounded OKF SQLite/FTS5 archive and canonical binding/selection inventory; absence is a zero-file manifest that creates no live state. Snapshot creation and offline verification require the exact bound Control export, join every retained incarnation to its prepare intent and committed OKF bundle, compare applied observation/projection evidence, and require a matching remove effect for removed or missing applied data. Deferred outcomes remain safe-no-effect scheduling evidence; claimed and unknown outcomes remain reconciliation evidence only. None selects desired state. It is not wired to the legacy backup scanner. A verified Knowledge snapshot can now stage and re-audit its exact database beneath a clean target state root, then publish it by one atomic rename while the exact exclusive maintenance fence is held. Post-rename retry is idempotent while that staged attempt and fence remain held. Unowned, existing, ambiguous, linked, rebound, or policy-mismatched targets fail closed, and absent state creates no payload. The planning-and-diagnostic observation owner now has a concrete bounded snapshot and clean-target restore boundary. It uses each cognitive store's own validator, archives only terminal diagnostic histories and terminal resolution attempts, and manifest-binds the count and canonical path/digest inventory of excluded active resolution/download records. Locks never enter restore authority. No-follow traversal, duplicate checks, a second scan, no-clobber publication, and exact archive verification reject drift and substitution. An offline-verified archive can be staged without touching live owner paths; activation requires the exact exclusive maintenance fence, a clean initial record inventory, an atomic activating marker, and digest-named deterministic partials for exact-subset replay. The Host protocol projection now has a third concrete snapshot, offline-verification, and clean-target restore boundary. It archives only owner-validated request-to-plan, optional outcome, and canonical cancellation records. Derived operation and latest-enablement indexes must be complete and consistent but never enter the archive. A second bounded no-follow scan and exact Control-export reconciliation precede no-clobber publication, so the projection cannot choose desired state or package/capability generations. No-change requests remain explicit without inventing operations. A verified snapshot can build a complete target-local owner root from exact source bytes and newly derived canonical indexes while excluding legacy aliases and locks. Activation requires the exact exclusive maintenance fence and an absent live root, writes a snapshot-bound marker, re-audits the exact physical and semantic inventory, and atomically publishes the whole root without replacement. Deterministic archive, record, and marker partials plus post-publication replay cover the local crash boundaries. The Restore Coordinator is now the fourth concrete snapshot and restore owner. Its owner-native journal decoder archives only exact canonical completed operations for the bound installation. The active marker and operation are excluded while their bounded digest inventory remains manifest-bound, including marker-only handoff. Orphaned nonterminal operations, pruning or temporary residue, unknown entries, links, foreign history, and path rebinding fail closed. A second scan precedes no-clobber publication, and streaming offline verification binds exact terminal bytes and a path-free receipt to the Control export. Empty or active-only history creates no archive. Its self-hosted restore adapter preserves the active marker and any current operation while replayably replacing only terminal history. Durable activation evidence binds exact before/source/target inventories. A legacy whole-installation marker reserves one slot at the native 64-record limit; the typed complete-set marker has no retained operation and preserves all 64 records. Marker-only handoff, status progress, and every local partial are deterministic and tamper-evident. The Runtime plan owner is the fifth snapshotted owner. It captures immutable installation-scoped plan envelopes, validates complete key/plan binding, restores them before Host projection activation, and contributes referenced Runtime blob digests to installation reachability. The private complete-set snapshot coordinator now captures one canonical Control export and all five registered owner snapshots beneath one maintenance fence and timestamp. A path-free canonical manifest binds the exact registry, receipts, schemas, digests, and byte accounting. One fixed-order archive is streamed outside every Use data and state root, fully audited through the owner-native offline verifiers, and published without replacement. Absent owners add no payload, and the global Artifact Store stays excluded. The verified aggregate can now stage one deterministic clean-target attempt beneath .control-installation-restore. One path-free descriptor binds the exact snapshot, installation, registry, Knowledge policy, and six-component set before a retained exclusive fence builds Control and every owner-native candidate. Control is checkpointed to one SQLite file, export-round-tripped, and physically digest-bound; no live owner path is changed. Exact retry and interrupted Control staging recover, while target contamination, links, unknown entries, rebinding, and completed-candidate drift fail closed. Complete activation now preflights every owner before durable top-level intent. The immutable attempt remains authoritative, activation.json is the sole mutable ordered journal, and the typed global .maintenance.restore.json marker binds the same immutable operation while blocking ordinary shared access. Control Store, Runtime plans, Host projection, Knowledge, observations, and Restore Coordinator execute in fixed order; every step follows journal, marker, owner effect, checkpoint. Each checkpoint binds its canonical path-free result by byte count and a domain-separated digest, while the coordinator owner additionally verifies the exact marker bytes, length, and digest before mutation. Reopen reacquires the exact guard, rebinds the same verified snapshot, attempt, registry, and policy, and reconstructs or verifies every candidate/live boundary. Journal and marker partials, all six post-effect/pre-checkpoint boundaries, the sixth checkpoint before retirement, and exit after deletion converge. Marker absence is accepted only beside the complete journal; out-of-order roots, ambiguous markers, links, rebinding, and evidence drift fail closed. Completed replay performs no owner effect and can only resume bounded fixed-order retirement of the six link-free staging trees. A 21-boundary real-child-process matrix qualifies the top-level protocol, including every retirement boundary. The canonical attempt.json and complete activation.json then form the exact installation-bound terminal receipt. Legacy backup and artifact reachability exclude only that receipt; incomplete, extended, linked, or tampered evidence fails closed. Production Grant conversion, Runtime/Flow dispatcher composition, backup/restore wiring, and coordinated authority cutover remain open; no A2 roadmap item is complete yet.

Implemented baseline

  • Manifest v3 and catalog v3 cover named Tool, MCP, OKF, Flow, Skill, and UI surfaces, package dependencies, permission ceilings, and exact provenance.
  • InstallationId(kind, id) now partitions mutable package state, receipts, Grants, bindings, capability publication, backup/restore, and locks. Global Registry/TUF inputs and the raw-blob/expanded-tree Artifact Store own no installation authority. Registry sources retain only observations and partials; source prune and scoped uninstall never delete global bytes. Guarded reachability, hard quota admission, and read-only digest audit cover both physical tiers. Exact-plan logical quarantine preserves mismatched bytes in place and blocks new ordinary access through a canonical marker. Verified rehydration now requires a candidate outside the store, exact reviewed evidence, a fresh zero-reference proof, and prepared/completed fail-closed recovery; completed exact replay is read-only and independent of the external candidate and later references. Confirmed GC now requires a bounded explicit target allowlist, fresh all-owner zero-reference proof, exact physical and lifecycle evidence, a durable fail-closed deletion fence, same-shard atomic retirement, and read-only terminal replay. The A1 two-installation gate now runs the same signed OKF package through apply, restart, exact snapshots, leased queries, upgrade, uninstall, and terminal replay in concurrent User and Workspace installations with the same textual ID. Each operation leaves the opposite installation cursor unchanged and its admitted lease callable.
  • The bounded resolver freezes one Registry/TUF package lock, prepares dependencies forward, publishes one graph snapshot, and retires unused packages in reverse.
  • The standalone CLI persists a bounded enabled Registry set in canonical ACL, requires reviewed revisions for authority changes, isolates TUF/cache state by source identity, and restores exact prior evidence without receipt rewrites.
  • Plan v4 separates review from mutation and binds operation identity, confirmation, scope, package transitions, impact, Grants, providers, and current-state evidence.
  • The Use-owned typed PluginManagerService now implements catalog search and inspection, stable installed-state pagination, status, all frozen planning operations, durable reviewed-plan reopening, and digest-only apply over the production Host Manager. Its standard MCP adapter derives the exact thirteen v5 tools from the frozen contract and obtains apply/cancellation confirmation only from an injected trusted host provider.
  • The path-free CapabilityDescriptor and catalog contracts, opaque reference types, exact snapshot lease/generation binding, and embedding CapabilityGatewayMcpServer are implemented and contract-tested. The adapter publishes only catalog-authorized Tools over standard MCP through an injected provider. Host-owned bounded in-flight and rolling-window admission, plus Streamable HTTP /mcp bearer/Origin enforcement, duplicate header rejection, sanitized HTTP errors, and an independent Rust client discovery/invocation check are also implemented. The provider now exposes an explicit pre-invocation authorization hook that fails closed and sanitizes denial results. The embedding now includes a bounded immutable 64-entry token-to-principal registry (complete credential scan, duplicate-token rejection) and a lease-scoped CapabilityGatewayInvocationResolver. Production receipt/Runtime/Grant composition, CLI wiring, TLS termination, and production-host recovery remain open.
  • A host can now project a consumer-specific Gateway catalog from one immutable CapabilityRegistrySnapshot. The projection rechecks exact package/manifest identity, reviewed publication evidence, selected surfaces, and ready bindings before CapabilityGatewayMcpServer::from_registry_snapshot acquires its RAII lease; signature verification and opaque-reference resolution remain host-owned.
  • The standalone plugin CLI maps those same ten operations to the service. Planning is non-mutating; exact apply requires the durable operation ID, plan digest, and explicit --yes, while cached apply and replay are zero-network.
  • Lifecycle journals provide exact crash replay, cutover-aware publication, exact-generation drain, and fail-closed corruption handling.
  • extension inspect --json projects bounded lifecycle history, while extension diagnose --json reads one retained planned/admitted/cancelled install/upgrade/uninstall graph, active admitted enable/disable operation, or newest Host-reviewed pre-admission enable/disable plan/cancellation without network access or writes and correlates its reviewed plan, Registry/TUF, provider, Grant, cutover, drain, rollback, and recovery evidence.
  • Retained graphs and pre-plan attempts expose independent expected/retained archive and signed executable-planning-target bytes plus exact missing/partial/complete state. Real killed-process tests prove partial observation, exact Range resume, and gap-free handoff to the reviewed graph.
  • Pre-lock resolution attempts expose refreshed/cached per-Registry TUF progress, path-free source/trust digests, bounded failures, and terminal lock evidence across process exit before handing off durably to download state.
  • extension diagnose --history --json retains the newest 16 validated completed or rolled-back operations and cancelled graph plans within 8 MiB per scope/package, survives uninstall, and deduplicates exact crash replay.
  • Standalone composition exists for Tool Task, stdio MCP, Skill/UI projection, SQLite/FTS5 OKF, and injected a3s-flow Native TypeScript preflight.
  • The standalone Knowledge backend enforces whole-scope expanded-byte and projection quotas, per-surface generation limits, global tombstone pruning, SQLite/WAL compaction, exact-scope usage diagnostics, SQLite/receipt/FTS audit, non-overwriting verified database backup, canonical exact-plan oldest-first backup rotation, derived-index repair, and authority-bound database restore.
  • GitHub Pages and bilingual product documentation exist, but they describe a development preview only.

Remaining release plan

1. Managed-host provider composition — in progress

  • The host-owned RuntimeSurfacePlanStore is qualified for canonical, bounded, no-clobber plan publication; bind it to the Control commit before activating the production dispatcher.
  • Compose production Runtime Service and HTTP MCP/Gateway providers with the durable host source, restart-safe resolver, and atomic dispatcher cutover.
  • Complete managed Knowledge Workspace/session carriers and leased prior- generation query qualification. Standalone OKF quota/retention/GC is implemented, but managed composition is not.
  • Complete UI sandbox ownership, CSP, backend binding, drain, retention, and garbage collection.
  • Prove required surfaces remain unpublished whenever ownership or exact readiness evidence is missing.

2. A3S Code TUI hot-plug qualification — in progress

  • Migrate the A3S Code TUI and compose the manager MCP in Code on the implemented shared Plugin Manager service. The standalone CLI convergence is complete without replacing compatibility JSON fields; TUI and product presentation wiring must not introduce another plan or mutation path.
  • Verify install, invoke, exact-generation upgrade, invoke, uninstall, and restart for all six surfaces and dependency-bearing graphs.
  • Prove User/Workspace scope isolation, watcher resumption, terminal-result replay, and no duplicate side effects after crashes.

2a. Arbitrary-agent Capability Gateway — in progress

  • PR #192 freezes the portable descriptor/catalog schemas and adds an embedding standard-MCP adapter. PRs #199 and #200 add exact snapshot leases and separate publication and package lifecycle generations. PR #202 adds shared bounded admission and Streamable HTTP /mcp; PR #203 adds duplicate-header rejection and a real independent Rust client check. The HTTP embedding now also supports a bounded 64-entry token-to-principal registry with complete credential scans and duplicate-token rejection.
  • Complete live server-side invocation-reference resolution, CLI/service wiring, TLS deployment, and production recovery. The embedding now exposes CapabilityGatewayInvocationResolver and CapabilityGatewayResolvedProvider: one opaque reference is resolved to a private lease, checked against the catalog identity, authorized once, and held through invocation. Production receipt/Runtime/Grant composition remains open.
  • CapabilityRegistrySnapshot::capability_gateway_catalog and CapabilityGatewayMcpServer::from_registry_snapshot close the snapshot-to-catalog composition gap with a bounded, fail-closed projection; this is an embedding primitive, not the live resolver or production multi-principal registry.
  • CapabilityConsumerProfile and CapabilityConsumerNegotiation now bind an explicit generic-mcp or a3s profile to the Gateway. A3S extension labels are canonical and fail closed instead of being silently dropped. This is the typed negotiation boundary only; resources/prompts and production host projection remain open.
  • Qualify discovery and invocation from independent Rust, TypeScript, and Python clients without a shared package filesystem, including upgrade, restart, uninstall, and denied cross-scope access.

3. Distributed Flow and OS integration — pending

  • Keep one package-owned a3s-flow identity while adding remote placement, scheduling, suspension, resumption, cancellation, and observation.
  • Prove remote execution changes placement only; Use still owns the single lock, receipt, and lifecycle journal.

4. Cross-platform real-process matrix — pending

  • Windows x86_64 now runs signed Registry trust/lock, dependency-graph install/upgrade/uninstall, Grant, standalone Flow preflight/lifecycle, and OKF cutover scenarios through real a3s-use processes. It also replays removed-dependency cleanup after killing an upgrade post-cutover, without inflating the capability generation.
  • The complete current workspace suite now runs on Windows x86_64. A deterministic directory-junction regression proves package and durable state trust boundaries reject Windows reparse points before traversal. Flow Runtime coverage also retains exact generations, rejects artifact substitution and tampered or moved bindings, isolates identical textual IDs by scope kind, and rejects a linked scope directory on Windows. Shared native link tests also cover Registry target-cache state, retained lifecycle receipts, package graph and diagnostic stores, enablement locks, Runtime and lifecycle records, whole-state backup/restore, and OKF database, binding, backup, and restore paths with real Windows directory junctions. Native Windows tests also prove single-package and graph cutover-capacity rejection happens before lifecycle receipt replacement, and that Box CLI delegation preserves arguments, output, and exit status through a .cmd component.
  • Every production temporary-file publication for Registry state/cache, Workspace Grants, package and Host records, lifecycle, Runtime, Flow, Knowledge, enablement, backup, restore, and diagnostics now uses bounded Windows retry primitives while retaining replace versus no-clobber semantics. Restore-journal/Knowledge recovery sources survive bounded rename failures, whole-state restore candidates preserve reviewed file attributes, and lifecycle/restore-history directory moves use the same retry bound. Released file or directory locks converge atomically; a persistent replacement lock stops at two seconds without changing the prior target. Resumable Registry partials now use one final-component no-follow handle through final verification and copying into the global Blob tier. Commit rehashes while copying, publishes without clobber under a digest lock, then reopens and retains the global blob through staging. Canonical source observation publication follows durable blob commit, and partial cleanup is last. Unix commit stays bound to the retained source handle, while Windows permits readers and denies external writes, removal, and replacement. Windows-native scanner tests prove transient no-delete-share contention converges within the two-second cleanup bound. If cleanup remains locked after publication, the durable blob and observation coexist with a redundant complete partial for a later zero-network cleanup retry. Invalid-partial cleanup and stale, partial, and source-observation deletion use the same bounded blocking retry and never delete global blobs. Native tests prove transient convergence and persistent selected-file preservation followed by a residual-inventory rescan. Bounded deletion of lifecycle receipts and abandoned artifact staging uses the same retry. Native tests prove transient receipt/nested-staging convergence. A persistent reader of a complete global artifact never delays scoped uninstall because shared bytes are retained. Native tests also bind active artifact-staging rename contention to the commit state machine: a transient lock lets the same commit finish, while a persistent lock leaves receipt and Registry snapshot untouched, preserves residual staging, and permits exact replay after release. Selected upgrade-receipt replacement now has the same native qualification. A transient lock completes the same upgrade; a persistent lock retains the valid global candidate artifact, removes its retained-receipt candidate state, preserves the exact prior receipt and published generation, leaves no temporary receipt, and permits exact replay after release. Reboot recovery and antivirus contention beyond these exact blob-publication, source-cache-removal, active package-commit, upgrade-receipt replacement, and lifecycle-removal boundaries remain open.
  • Run equivalent signed six-surface lifecycle and failure-injection scenarios on declared Linux, macOS, and Windows targets.
  • Real-process tests now cover resumable target-download interruption and termination during verified archive extraction. Both withhold all package publication; extraction recovery completes from the revalidated cache with explicit offline mode and no network request.
  • A real-process package-copy interruption also proves the durable pending plan and applying journal replay the same generation, reclaim the physical artifact-staging residue, and publish only once without network access.
  • Uninstall retires exact scoped lifecycle authority without deleting or waiting on global expanded-package bytes and without advancing the Registry generation again.
  • A real-process nine-node install is now killed after its complete Registry graph and durable cutover are visible but before one dependency journal and the parent graph record complete. Explicit offline replay makes no network request, completes the exact graph, and does not advance the generation again.
  • Externally killed managed-host processes now cover five-node permission- bearing install, upgrade, and uninstall at Registry publish/hide while the Grant operation is still prepared. Recovery disables reauthorization, makes no network request, preserves the exact candidate Grant, retires only the bound prior Grant, and does not inflate the Registry generation.
  • Real Host protocol processes now cover all five reviewed mutations with the Registry server offline. Install, upgrade, and uninstall are killed after five-node graph publication/hide; disable is killed after root hide and Grant cutover while accepted-call drain is blocked; enable is killed after publication while its candidate Grant remains prepared. Restart consumes the durable reviewed plan and confirmation, uses only the verified planning cache for install/upgrade, completes drain and lifecycle/Grant journals, converges the exact candidate/prior Grant or enablement regrant/revocation, and persists replayable terminal Host outcomes without generation inflation.
  • Cover interrupted download, archive extraction, cutover, drain, process crash, product-host Grant cutover, reboot, remaining antivirus contention outside blob publication, source-cache removal, and lifecycle removal, and reparse-point replacement races.

5. Supply chain and operations — in progress

  • Operate a documented Registry with signing, root rotation, expiry, mirror replacement, offline recovery, and incident procedures.
  • Durable Registry add/list/replace/default/enable/disable/remove and exact- identity evidence restoration are implemented; operating and exercising a real production Registry remains open.
  • Deterministic archive serialization, cross-platform installers, per-platform SPDX SBOMs, GitHub OIDC provenance/SBOM attestations, and a verified keyless Sigstore checksum bundle now come from one workflow with pinned Actions and release tools.
  • Both platform installers now require Cosign, verify the checksum manifest against the exact tag workflow identity before archive download, fail closed on invalid evidence, and retain the verified evidence with each version.
  • Byte-for-byte cache-free rebuilds now pass for every shipped native executable on all five release targets in non-publishing qualification run 33651777660, from exact main commit 4f6e4725205d06ab81f8ea98bfee85c7eb4b2bcd with one release codegen unit; this run never publishes assets. The v0.3.5 publication attempt created no Release because the public core crate was stale. Release workflow 33675697857 passed all 13 jobs for tag v0.3.6 at exact main commit 54758910f2f4ad9498137410e0a2207d412e99a1 and publishes the verified archives, installers, SBOM/reproducibility evidence, and typed Use crates in the v0.3.6 Release. Release workflow 33687297386 then passed all 13 jobs for tag v0.3.7 at exact main commit 48a0b76f8a4a87a11d16627c7bd7567920852508 and published the current verified archives, installers, SBOM/reproducibility evidence, and typed Use crates in the v0.3.7 Release (a3s-use-core 0.2.6, a3s-use-extension 0.3.7, a3s-use 0.3.7). The independent witness and product gates remain open.
  • Release workflow 33720485826 then passed all 13 jobs for tag v0.3.8 at exact main commit 6d3a7baf32ce998a2e487c40fbf78b4a6cda2579 and published the current verified archives, installers, SBOM/reproducibility evidence, and typed Use crates in the v0.3.8 Release (a3s-use-core 0.2.7, a3s-use-extension 0.3.8, a3s-use 0.3.8). The independent witness and product gates remain open.
  • Release workflow 33756618837 then passed all 13 jobs for tag v0.3.9 at exact main commit a5f3cc40bfb0a1021ca150d2ce4295409b74d220 and published the current verified archives, installers, SBOM/reproducibility evidence, and typed Use crates in the v0.3.9 Release (a3s-use-core 0.2.7, a3s-use-extension 0.3.9, a3s-use 0.3.9). The independent witness and product gates remain open.
  • Release workflow 33791616307 then passed all 13 jobs for tag v0.3.10 at exact main commit c4c80a223bfff3698ca4b4598e7175c6e3303239 and published the current verified archives, installers, SBOM/reproducibility evidence, and typed Use crates in the v0.3.10 Release (a3s-use-core 0.2.8, a3s-use-extension 0.3.10, a3s-use 0.3.10). The independent witness and product gates remain open.
  • Release workflow 33830280138 then passed the validation, five-target primary-build, typed-crate, and five-target independent-rebuild gates for tag v0.3.11 at exact main commit c25028ae0245ba1d28f7e2837e2a87f7e9f6fe40 and published the current verified archives, installers, SBOM/reproducibility evidence, and typed Use crates in the v0.3.11 Release (a3s-use-core 0.2.9, a3s-use-extension 0.3.11, a3s-use 0.3.11). The independent witness and product gates remain open.
  • Add an externally operated witness for the complete staged tree/final archive and retain verification evidence outside the Release asset trust boundary.
  • Exercise missing Registry/package/lifecycle/Grant authority recovery, clean-machine recovery, cross-platform restore/retention drills, whole-product storage policy, telemetry, security response, and support runbooks. OKF scope audit/backup/FTS repair and authority-bound database plus exact-subset missing-binding restore are implemented and crash-tested; conflicting or newer binding evidence fails closed. Deterministic whole-installation inventory backup now covers every allowlisted Use-owned family under one exclusive fence, binds Registry/receipt authority, rejects nonterminal or unsafe state, and verifies all payloads offline without extraction. The immutable Capability Gateway catalog and descriptor-snapshot records are admitted as the strict CapabilityPayloads family with canonical and content-address checks; production owner-native restore/retention remains open. Reviewed same-version/OS/architecture whole-install restore is now implemented with an exact path-free action plan, unchanged live Registry and Grant authority, an external rollback archive, link/reparse-safe candidates, seven durable phases, 15 process-exit recovery boundaries, terminal replay, and read-only bounded status/history. The archive remains integrity evidence and cannot recreate missing authority. Whole-installation retention now fully verifies every managed archive under one external-directory lock, returns a path-free oldest-first canonical plan, requires exact digest confirmation, and preserves two recovery generations. Exact-plan oldest-first scope backup rotation and path-free active/history/ capacity diagnostics are also available. Retained planned, admitted, and cancelled install/upgrade/uninstall graphs and active admitted enable/disable operations now have a bounded cross-product diagnostic. Retained Registry-backed install/upgrade graphs and process-resilient pre-plan attempts expose zero-network expected/retained archive bytes and exact-target missing/partial/complete state. The same exact locks now expose independent planning-target byte progress. The newest Host-reviewed pre-admission enable/disable request is projected as planned or cancelled; active/completed Use evidence takes precedence, and private Host request/fence identity is excluded. Retired operations now have bounded, zero-network, newest-first history with terminal outcome validation and fail-closed corruption handling. Real Host/CLI tests prove the pre-admission projection performs no network, authorization, admission, or lifecycle side effect and suppresses stale evidence during Host finalization.

Production-ready definition

A3S Use is ready to publish only when a user can choose a trusted Registry, review one exact plan, install a signed dependency graph, hot-use all six surface types in supported hosts, recover without guessing, upgrade without mixed generations, and uninstall without leaving routes, Grants, processes, projections, or package-owned state behind on every declared platform.