release(r30): finalize adopted Agent OS registry, installer, and proof - #1529
Merged
vibeforge1111 merged 544 commits intoJul 28, 2026
Conversation
Carry the already-proven PR #346 descriptor/handle authority tests onto the cumulative CLI lane and preserve PR #71's sensitive-path finding as a stronger SPARK_HOME allowlist regression. Co-authored-by: driasim <driasim@users.noreply.github.com> Co-authored-by: onbtceth <onbtceth@users.noreply.github.com>
Port the proven Batch R secret-file carrier onto the cumulative CLI lane: SPARK_HOME-only, bounded regular files, descriptor-relative POSIX nofollow traversal, Windows final-handle containment, and nonreflecting failures.
Fully redact Telegram token identities before generic masking, cover structured named-secret values without broad auth matches, and reject invalid bot-token input with a short nonreflecting repair prompt.
Keep transport, profile, and change-detection fixtures synthetic while making them compatible with the fail-closed token parser. This carrier has no source-credit allocation.
Preserve PRs #77, #108, #348, and #1392 as exact evidence for read-only availability, target-operation authority, sanitized failure truth, and rejection of disconnected test-only claims. Co-authored-by: onbtceth <onbtceth@users.noreply.github.com> Co-authored-by: yppp66 <yppp66@users.noreply.github.com> Co-authored-by: driasim <driasim@users.noreply.github.com>
Keep the availability probe read-only, report only the backend error class, and leave fetch/delete authority with their actual target operations instead of destructive preflight probes.
Preserve PR #78's tuple-normalization finding while rejecting its unordered set/frozenset conversion and confirming that dictionary authority remains unchanged. Co-authored-by: onbtceth <onbtceth@users.noreply.github.com>
Normalize only tuples alongside native lists. Continue rejecting sets, frozensets, strings, mappings, and synthetic dict coercion so compiled evidence remains deterministic.
Preserve PR #79's two findings while proving that root-owned Spark state must not bypass the secrets file, sensitive home prefixes, or parent traversal. Co-authored-by: yppp66 <yppp66@users.noreply.github.com>
Allow root-owned Spark state only past the broad /root prefix, preserve exact secret and sensitive-prefix denials, and evaluate trusted SSH target values rather than dictionary keys.
Preserve CLI PR #80's failure-leak finding while requiring stable timeout, launch-error-class, and exit-code truth instead of child-controlled classification. Co-authored-by: giwaov <giwaov@users.noreply.github.com>
Report only the fixed timeout, launch error class, or child exit code. Never classify or relay Builder/Memory subprocess output, command arguments, local paths, principals, or tokens.
Co-authored-by: giwaov <giwaov@users.noreply.github.com>
Reconciles PR #95 with the established secure-prompt owner so PowerShell never receives an unquoted clipboard sentinel. Co-authored-by: giwaov <giwaov@users.noreply.github.com>
Co-authored-by: yppp66 <yppp66@users.noreply.github.com>
Retains the distinct runtime-health finding from PR #100 without duplicating its already-adopted URL boundary or semantics-neutral approval edit. Co-authored-by: yppp66 <yppp66@users.noreply.github.com>
Co-authored-by: yppp66 <yppp66@users.noreply.github.com>
Retains PR #105 local-address safety without its first-answer DNS lookup or validation-time network dependence. Co-authored-by: yppp66 <yppp66@users.noreply.github.com>
Co-authored-by: yppp66 <yppp66@users.noreply.github.com>
Retains PR #107 race-safety intent with OS-exclusive creation, fsync, atomic replacement, and executable-mode preservation. Co-authored-by: yppp66 <yppp66@users.noreply.github.com>
Uses direct exclusive creation so Windows behavior does not depend on temporary-path flavor selection.
Co-authored-by: yppp66 <yppp66@users.noreply.github.com>
Co-authored-by: giwaov <giwavictor9@gmail.com>
Co-authored-by: giwaov <giwaov@users.noreply.github.com>
Co-authored-by: giwaov <giwaov@users.noreply.github.com>
Preserve Aeyo and ifeoluwaaj regression coverage while adapting the useful Kubernetes, cloud, local-file, and immutable enforcement behavior to the canonical typed authority modules.\n\nProof: 55 focused tests and 117 subtests passed across enforcement, Kubernetes, cloud, local credential, and canonical authority suites.
Validate provider endpoint structure and every DNS answer, connect only to the validated address with TLS hostname verification, reject redirects, and bound responses. Preserve local Ollama loopback support.
Move response handling into the security owner module so the provider boundary shrinks cli.py instead of increasing the existing god-file debt.
Preserve the adopted Windows uninstall, live health, and required-secret regression coverage in focused files while restoring the fixed R21 god-file ceiling.
Record the sealed prior R30 CLI candidate as reconciled history while keeping the newer canonical tree. Useful release-gate and GPT-5.6 defaults are ported in follow-up commits; stale local registry pins and evidence snapshots remain superseded.
Selectively port source commit 5998ef7 onto the newer CLI lane while preserving the current prompted-secret onboarding flow. Co-authored-by: Codex <codex@openai.com>
Selectively port source commit af686175d1e469540496963350657e4d429bb6f1 onto the newer CLI lane. Preserve hosted-installer verification, remove a workstation-specific source path, and keep registry/evidence pins out of this batch. Co-authored-by: Codex <codex@openai.com>
Align the retained GPT-5.6 expectation, record the reviewed release-gate test baseline with a named extraction owner and bound, and keep the line-count ratchet green.
Pin all ten runtime and support modules to immutable R30 refs at their audited merged heads. Preserve Spawner supersession evidence without rewriting historical gate packets.\n\nVerification: 98 focused tests + 27 subtests; registry pin verifier green; diff check clean.\n\nAgent-Id: alchemistab
Record the ten canonical merged module heads, immutable refs, PRs, receipt hashes, the documented Spawner supersession, zero overlap, and the unchanged 24,409 point baseline.\n\nAgent-Id: alchemistab
Validate the final ten-module merged-source ledger and allow exact merged truth to supersede historical patch-era handoff blockers without deleting their raw evidence. Keep runtime, registry, installer, and hosted gates independent.\n\nVerification: 5 focused tests; compileall; merged-source validator 10/10; diff check clean.\n\nAgent-Id: alchemistab
Advance the R30 gate to the collision-free 2026-07-27 installer identifier while continuing to recognize the June provisional manifests as historical evidence.\n\nVerification: 74 focused tests; shell syntax and diff check clean.\n\nAgent-Id: alchemistab
Update shell and PowerShell defaults to the final R30 installer identifier and refresh normalized script hashes in the installer manifest.\n\nVerification: local installer verifier green.\n\nAgent-Id: alchemistab
Apply gate/evidence separation from the commit that introduced the gate instead of retroactively rejecting older R30 history. Move merged-source policy and focused tests out of existing god files so the R-21 ratchet shrinks.\n\nVerification: 7 focused tests; release-policy binding; separation across origin/master..HEAD; R-21; compileall; diff check.\n\nAgent-Id: alchemistab
Keep embedded private-key findings blocking by default, but recognize a synthetic marker declared in test data only when that same array flows into a named redaction/sanitization helper. This unblocks Telegram's credential-safety test without weakening runtime-source scanning.\n\nVerification: 7 focused tests; exact Telegram scan 0 blocking findings; R-21; compileall; diff check.\n\nAgent-Id: alchemistab
vibeforge1111
marked this pull request as ready for review
July 28, 2026 17:31
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
vibeforge1111
deleted the
agent/alchemistab/finalize-r30-registry-pins-verifier-truth-installer-and-release-proof
branch
July 28, 2026 17:42
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Finalizes the Spark CLI lane for the evidence-backed R30 adoption program. This branch preserves the reconciled contribution history and turns the adopted Agent OS components into one exact, locally proven release candidate.
spark-cli-public-installer-2026-07-27-r30User-visible impact
R30 installs and verifies one coherent Agent OS stack across Harness, Memory, Researcher, Character, Skill Graphs, QA Evidence, Builder, Voice, Spawner, and Telegram. Live verification now proves the exact installed sources, Access Level 5 behavior, one-poller Telegram supervision, registry pins, installer integrity, and release-lane cleanliness.
Exact source truth
69b444899595ce6c44845a6a58712fc45ddce80catrefs/tags/spark-r30-2026-07-27-spawner-level5b72cf5eafe0fddda124fed696e26d6739029b8f5atrefs/tags/spark-r30-2026-07-27Validation
spark verify --r30: 21/21 greenpip check, CLI help, and imports passed714b964e56320f5b752e33eb051201c226499e8bf23ee290327b0980f549df2037439ae42c98f0b4376d1ce8346de09615f7f275c8d9a7dca2433182d4e41fc5Release-gate boundary
The binding capture is green on 27/28 checks. The sole exception is
readiness_audit_strict, a historical private Daily Schedule Loop Engineering audit bound to retired local paths and missing an operator-sent canary. A narrow expiring per-check waiver records that this feature remains private, blocked, and excluded from R30 activation and public-readiness claims. No runtime, security, source, installer, points, or Telegram gate is waived.Rollback
Before publication, retain this branch head and the exact ten module refs. After merge, rollback is the prior Spark CLI release ref plus the prior registry/installer manifests; module rollback uses the recorded immutable per-module refs. Do not move existing tags. The final installer tag is created only after hosted CI is green and the merge commit is known.
Remaining publication sequence
spark-cli-public-installer-2026-07-27-r30Spark Compete production cutover remains a separate operational no-go until private manifest, database, and deployment access exist; this PR does not claim that cutover.