Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,10 @@

## Unreleased

- Reconciled current public issue status with the closed Windows/Linux scope
and recorded the public preview.113 local Setup commit, executable versions,
and healthy Controller/database without relabeling historical live jobs.

- Fixed macOS managed-process tracking so descendants observed before a
reparenting/new-session transition remain addressable by their exact
`(pid, lstart)` identity; a reused PID is still rejected. Added a regression
Expand Down
10 changes: 5 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ The latest public developer build is **[v0.1.0-preview.113](https://github.com/T
| --- | --- |
| Windows x64 desktop/controller | Public preview; install, repair, plugin registration, health, and controller/worker checks are available. |
| Linux x64 worker | Public Worker Kit and Windows → Linux validation path. |
| macOS x64 / arm64 worker packages | Worker Kits build and verify; native managed-runtime acceptance is deferred in [Issue #3](https://github.com/TypeThe0ry/ClusterYourCodex/issues/3). |
| macOS x64 / arm64 worker packages | Worker Kits build and verify; native managed-runtime acceptance is deferred until a real macOS LaunchAgent/containment run exists. |
| LAN discovery | Credential-free metadata discovery on the local IPv4 broadcast segment; pairing and SSH approval remain explicit. |
| Live deployment | Preview.113 is the final public candidate for the current runnable scope. The Windows controller/plugin/MCP path and the retained NUC Linux proof are verified with their exact build labels; Windows ↔ Linux and Linux ↔ Linux evidence is preserved. Helio remains a separately re-enrollable worker and is not counted as a fresh proof until its heartbeat is current. |
| Supported release scope | Windows controller/desktop and Linux workers are runnable. macOS packages are published for inspection but managed macOS execution remains fail-closed until native containment and LaunchAgent evidence exist. |
Expand Down Expand Up @@ -156,10 +156,10 @@ The remaining non-blocking release evidence is a clean guest matrix covering
Install → Repair → versioned Upgrade → interrupted Rollback → Uninstall, plus
production Authenticode/tray signing. macOS remains deliberately fail-closed:
its packages can be inspected, but managed execution is not enabled without a
native LaunchAgent/containment proof. The exact evidence and boundaries belong
in [Issue #2](https://github.com/TypeThe0ry/ClusterYourCodex/issues/2),
[Issue #3](https://github.com/TypeThe0ry/ClusterYourCodex/issues/3), and the
[current audit](docs/current-audit-20261005.md).
native LaunchAgent/containment proof. Issues #2 and #3 are closed for the
declared Windows/Linux runnable scope. The exact evidence and remaining
Certified GA boundaries are recorded in the [release checklist](RELEASE.md)
and [current audit](docs/current-audit-20261005.md).

## Develop

Expand Down
42 changes: 21 additions & 21 deletions docs/current-audit-20261005.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,13 +30,16 @@ operation is unchanged.
## Local Windows and Linux evidence

The public preview.113 Setup is the final candidate for the current runnable
scope. The Windows controller
The controller health endpoint reported `status=ok`, `apiVersion=cyc.dev/v1`,
and `database=ok`. The native plugin contract, integrity, and MCP probes passed.
scope. The local Windows controller health endpoint reported `status=ok`,
`apiVersion=cyc.dev/v1`, and `database=ok`. The retained native plugin contract,
integrity, and MCP probes passed at the builds identified by their records.
The committed public Setup install is
recorded in [`local-install-preview113-20261005.md`](local-install-preview113-20261005.md).

The fresh same-host Windows controller/worker run reached
The retained same-host Windows controller/worker run reached
`queued → running → succeeded`; all 14 checks passed, including artifact
verification, process cleanup, and secret scanning. The sanitized record is
verification, process cleanup, and secret scanning at source `60bb863` after
the preview.111 install. It is not relabeled as preview.113 evidence. The record is
[`local-windows-roundtrip-20261005.md`](local-windows-roundtrip-20261005.md).

The retained NUC Linux proof job completed with exit code 0 and a verified
Expand All @@ -51,21 +54,18 @@ connections; no new Helio runtime success is claimed from that observation.
The safe recovery path is native desktop re-enrollment, not plaintext secrets
in a shell command or repository artifact.

## Remaining release gates
## Scope and remaining release gates

Issue #2's remaining evidence boundary is a clean current-source Windows 11
VM run of `Install → Repair → Upgrade → Rollback → Uninstall`, plus production
Authenticode/tray acceptance. The installer, controller, Codex bridge, repair,
uninstall, LAN discovery, and Windows/Linux round-trip path are already
runnable and covered by hosted/VM evidence.
Issues #2 and #3 were closed on 2026-10-05 for the explicitly declared
Windows/Linux runnable scope. The installer, controller, Codex bridge, repair,
uninstall, LAN discovery, and Windows/Linux round-trip path are runnable and
covered by the published preview and retained evidence.

Issue #3's Linux worker path and package contracts are covered. The macOS
worker remains deliberately fail-closed until a real macOS host proves
LaunchAgent lifecycle, managed controller/worker execution, detached-process
cleanup, PID-reuse safety, and any required signing/notarization. The source
now retains observed macOS descendant identities across reparenting while
still rejecting a reused PID; this is unit-tested but not a substitute for a
native macOS run.

Until those optional native/production gates have direct evidence, public
builds remain prereleases and `v0.0.1` remains untouched.
Certified GA remains a separate, stricter release channel. It still requires a
clean current-source Windows 11 version-changing matrix, production
Authenticode/tray acceptance, and a real macOS LaunchAgent/managed-runtime
run. The macOS worker therefore remains deliberately fail-closed; its
descendant identity and PID-reuse protections are unit-tested, but are not
presented as native macOS acceptance. Until those optional production gates
have direct evidence, `v0.1.0-preview.113` is the final runnable public build
and `v0.0.1` remains untouched.
45 changes: 45 additions & 0 deletions docs/local-install-preview113-20261005.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
# Local Windows install — preview.113

This record captures the final local installation performed from the public
`v0.1.0-preview.113` Setup asset. It contains no credentials or bearer tokens.

## Source and package

- Release: [`v0.1.0-preview.113`](https://github.com/TypeThe0ry/ClusterYourCodex/releases/tag/v0.1.0-preview.113)
- Source commit: `11ca9d82c2782a93ec25a40958c480e818be3a51`
- Setup asset: `ClusterYourCodex-Setup.exe`
- The downloaded Setup SHA-256 matched its adjacent `.sha256` sidecar before execution.

## Installation result

- Install mode: silent `/S`
- Install root: `%LOCALAPPDATA%\Programs\ClusterYourCodex`
- Data root: `%LOCALAPPDATA%\ClusterYourCodex`
- Installer transaction: committed
- Installed product version: `0.1.0-preview.113`
- Scheduled task: `ClusterYourCodex Controller`, running

The transaction first staged the payload and then committed the install
manifest. The existing `preview.112` binaries were not reported as upgraded
until the committed manifest and executable versions agreed.

## Runtime probes

Installed binaries all reported `0.1.0-preview.113`:

```text
cyc 0.1.0-preview.113
cyc-controller 0.1.0-preview.113
cyc-worker 0.1.0-preview.113
```

The authenticated CLI health probe returned:

```json
{"apiVersion":"cyc.dev/v1","controllerVersion":"0.1.0-preview.113","database":"ok","status":"ok"}
```

This proves the local Windows Controller and database are running after the
public Setup install. It does not relabel the retained NUC Linux proof as a
preview.113 cross-node run; that evidence remains linked from the current
audit with its original build label.
23 changes: 12 additions & 11 deletions docs/project-status.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,10 +17,10 @@ remain native-desktop-only operations. The browser now labels this state as
Tauri bridge.

The current Windows installation of preview.113 has a healthy Controller and
database, a valid native plugin/MCP probe, and a fresh same-host Windows
controller/worker round trip with 14/14 checks passing. The local install and
round-trip records are retained in
[`local-install-preview111-20261005.md`](local-install-preview111-20261005.md)
database. The retained native plugin/MCP and same-host Windows
controller/worker proofs keep their original build labels; the retained
round trip passed 14/14 checks. The local install and round-trip records are in
[`local-install-preview113-20261005.md`](local-install-preview113-20261005.md)
and [`local-windows-roundtrip-20261005.md`](local-windows-roundtrip-20261005.md).
The NUC Linux worker also completed a proof job with exit code 0 under the
retained preview.111 evidence record; that record is not relabeled as
Expand All @@ -33,13 +33,14 @@ claimed from that observation. Re-enrollment must use the native desktop
provisioning flow so credentials remain in the OS vault and out of logs.

Issues [#2](https://github.com/TypeThe0ry/ClusterYourCodex/issues/2) and
[#3](https://github.com/TypeThe0ry/ClusterYourCodex/issues/3) remain open. The
supported Windows/Linux path is runnable; the remaining evidence boundary is
the clean current-source Windows version-changing `Install → Repair → Upgrade
→ Rollback → Uninstall` matrix plus production Authenticode/final packaged
acceptance. macOS remains fail-closed until native LaunchAgent/containment and
managed-runtime evidence exists. Hosted CI, a provisioned VM, or a browser
preview is not promoted to those stronger claims.
[#3](https://github.com/TypeThe0ry/ClusterYourCodex/issues/3) were closed on
2026-10-05 for the explicitly declared Windows/Linux runnable scope. The
remaining evidence boundary is the optional Certified GA path: a clean
current-source Windows version-changing `Install → Repair → Upgrade →
Rollback → Uninstall` matrix plus production Authenticode/final packaged
acceptance, and native macOS LaunchAgent/containment and managed-runtime
evidence. macOS remains fail-closed; hosted CI, a provisioned VM, or a browser
preview is not relabeled as native macOS proof.

PR #208 additionally maps native integration failures to actionable localized
diagnostics, preserves safe controller transport codes, disables native
Expand Down
Loading