17 Commits

Author SHA1 Message Date
Jose Montes de Oca f7fa6770c4 chore: harden dependency installs and CI execution paths (#161)
Dependency installs and CI jobs both executed code this repo never
reviewed. This closes those paths without changing what anything
resolves to.

pnpm 9 ran every dependency's install lifecycle script and had no
allow-list model, so CI executed install hooks from the whole tree on
every PR. pnpm 10.34.5 blocks them by default and carries the fix for
the fail-open integrity check in CVE-2026-50021. minimumReleaseAge holds
freshly published versions out of resolution for 48 hours, the window in
which a registry compromise is typically caught and yanked.

The two `*` peer ranges in reactor-cli were the only place the workspace
opted out of range discipline: any future major satisfied them, including
a hijacked one. Both now carry carets on the versions already resolved,
and the README install lines are pinned to match, since a 0.x caret does
not cross the minor line.

Third-party actions take the commit SHA their movable tags resolved to,
with a monthly grouped Dependabot entry so those pins do not go stale.
GitHub-maintained actions stay on tags as a stated trust decision rather
than a claim that pinning them would buy nothing.

The benchmark jobs needed the most work, since they run an external
repository's code with five LLM provider keys in scope. Dispatch inputs
now travel through the step environment as quoted variables instead of
being interpolated into shell. The pi version is hardcoded rather than
dispatchable: npm accepts package sources after the `@` — an alias, a
repository, a tarball URL — so an input in that position chose a package
rather than a version. The remaining ref override is documented as an
operator escape hatch whose clone target is fixed.

The publish job holds a credential that can publish under our name and
installed npm at latest before using it. It now pins an exact version
above the floor OIDC trusted publishing requires, and fails at that step
if the pin does not take.

CI also fails on a tampered or unsigned tarball now, checked per
publishable package rather than once at the root where npm would only
see dev tooling. The advisory audit runs alongside it as a signal, not a
gate.

Nothing re-resolves: no version or integrity line in the lockfile moves.
2026-08-10 12:53:42 -04:00
Jose Montes de Oca aad1b43fd3 test: migrate the CI smoke suite to the current execution model (#152)
The smoke fixtures still exercised the retired pre-0.15 model: service
and system kinds, '### Ensures' contracts, and a harness that asked for
forme.manifest.json and checked every output under bindings/. The
execution docs now treat retired kinds as never-executable upgrade
input, which turned the kind-test case into a standing contradiction:
its subject resolved to a kind: service file the harness required to
execute. That contradiction fits kind-test's history as the suite's one
chronically flaky case.

Rewrite every fixture in current kinds while preserving what each case
smokes: functions for single render, caller input, execution block,
errors and strategies, and local pattern instantiation (standalone runs
publish '### Returns' under bindings/ via copy-on-return);
responsibility multi-node files for the wiring cases, with a deliberate
fan-in reconvergence replacing the retired '### Wiring' case; kind: test
now runs a function subject and asserts against its published bindings.

Align the harness with the current artifact layout: mounted runs
snapshot compiled-intent.json, publish node truth under world-model/,
and append receipts; a per-case outputRoot field selects world-model or
bindings for output checks. Give the test command a 40-turn budget,
since it reads the test file, resolves the subject, executes it, and
evaluates assertions in one session. Case ids and filenames are
unchanged, so required check names stay stable.
2026-07-22 10:38:44 -04:00
dan f12dcda4d8 Release: the OpenProse Reactor harness (engine + CLI + devtools) — 0.3.0 ideal API surface (#106)
Ships @openprose/reactor 0.3.0, @openprose/reactor-cli 0.2.0, @openprose/reactor-devtools 0.2.0: the Reactor harness (compile-once-intelligent then dumb reconciler, content-addressed receipts, cost scales with surprise) with the distilled ideal public API — curated front door, full @openai/agents passthrough, one typed handle, one Substrate, unified observe, branded ids, and additive forward seams for the fixpoint.
2026-06-02 14:06:56 -07:00
dan 52724edc11 chore: prepare reactor 0.1.0 release (#98) 2026-05-22 19:29:03 -07:00
dan a7b5d34920 fix: upgrade npm for reactor trusted publish
Install npm 11.5.1 in the Reactor package publish job before the provenance publish steps so npm Trusted Publishing can use the workflow OIDC token.
2026-05-22 17:52:38 -07:00
dan ecc230dd73 chore: cut reactor rc2 release
Prepare the Reactor packages for the interim 0.1.0-rc.2 release.

Narrow the package publish workflow to reactor-v* tags, bump Reactor and Cradle package versions, refresh the Cradle package pin for the rc.2 tarball, and update release-candidate evidence helpers and package docs.
2026-05-22 17:38:16 -07:00
dan 5cfbac8048 fix: harden reactor rc onboarding and edges
Implements the approved Reactor v0.1 rc hardening set: adoption contract docs, standalone flat-tokens install, runnable SDK snippet, quickstart prereqs/build fix, Cradle scenario export, stable synthetic payload hashes, concurrency-safe pressure writes, and dropped-route diagnostics.
2026-05-21 17:16:50 -07:00
irl-dan 5b4b42be8b Add the OpenProse Reactor harness (v0.1.0)
The Reactor is an evented reconciliation harness for AI-maintained
world state. Cost scales with surprise, not time.

This adds:
- @openprose/reactor — the runtime: content-addressed receipt
  kernel, memoization, dual-clock forecast scheduling, model-authored
  policy compile/recompile/rollback, composition with cycle
  detection, two adapter seams.
- @openprose/reactor-cradle — the deterministic evaluation harness.
- The prose CLI wired to the Reactor (prose compile / serve / status).
- Bundled examples that run end-to-end from a clean checkout.
- The OIDC trusted-publishing CI workflow.

Measured cost thesis (deterministic Cradle scenarios):
  static 24h world  — Reactor 46 fresh : 46 reused / 2 model calls
                      no-memo control  92 : 0
                      naive loop      256 : 0
  event-changing    — Reactor 74 : 74 / 2 model calls
                      no-memo control 148 : 0
                      naive loop      148 : 0

Spec: index/spec/02-ReactorHarness.md (openprose/index).
2026-05-20 22:03:48 -07:00
Raymond Weitekamp 9856ac5b12 feat(spec): declared ### Skills section with fail-closed compile resolution (#62)
* feat(spec): declared ### Skills section with fail-closed compile resolution

Implements the spec from issue #60. Components declare required harness
skills via a `### Skills` section (colon form, e.g. `document-skills:pdf`).
`prose compile` resolves declared skills against ./skills/, ~/.claude/skills/,
~/.codex/skills/, and ~/.agents/skills/, and fails closed with
`skill_unresolved` before forwarding to the agent harness when any are
missing.

- Spec: skills/open-prose/contract-markdown.md gains a ### Skills row in
  the Canonical Sections table and a ## Skills H2 covering colon naming,
  search order, the BYO-harness invariant, and fail-closed semantics.
- Implementation: tools/cli/src/skills/declared.ts (parser + resolver +
  directory walker + DeclaredSkillsUnresolvedError). Pure functions; no
  I/O beyond readFile / readdir / stat.
- Wiring: tools/cli/src/commands/compile.ts pre-checks declared skills
  before forwarding the compile prompt; fails closed with
  CompileValidationError when any are unresolved. Gated behind the
  existing skillPreflight option for test parity.
- Example: skills/open-prose/examples/declared-skills/ shows the
  document-skills:pdf canonical pattern.
- Tests: 19 new (18 in declared.test.ts covering parser/resolver/walker/
  error formatter; 1 in cli.test.ts asserting compile fails closed before
  the harness is invoked when a declared skill is missing).
- BYO harness: OpenProse never installs harness skills; resolution failure
  is the user's signal to install the named skill themselves.

Resolves #60.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(spec): move skill resolution into compiler program; trim spec per review

Address review feedback on #62:

- contract-markdown.md: drop the "not duplicated in frontmatter" clause —
  the rejected alternative shouldn't propagate into the spec.
- contract-markdown.md: fail-closed clause now mentions only `prose compile`;
  `prose run` enforcement is deferred per the PR description.
- compiler/index.prose.md: add a `skills_resolver` agent that owns the
  search-path order, scope aggregation, BYO invariant, and fail-closed
  semantics. Skill resolution is now a compiler/program-level
  responsibility, not a harness responsibility, so other harnesses running
  the compiler get the same behavior.
- skills/declared.ts: add a header comment pointing at the program-level
  spec; this module is the harness implementation of `skills_resolver`.
- examples/declared-skills/README.md: update wording to reference the
  compiler agent.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(ci): make smoke artifacts case-specific

* fix(ci): use deterministic audit policy

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-07 13:50:01 -04:00
dan b238fbb16e fix: clean up responsibility runtime playtest warts (#67) 2026-05-05 13:54:50 -04:00
dan d9aed223d2 fix responsibility runtime serve feedback (#65) 2026-05-04 22:20:39 -07:00
dan c20879fe06 chore: unify OpenProse release flow (#63) 2026-05-04 17:26:28 -04:00
dan 012650a201 [codex] Prepare OpenProse 0.12.0 responsibility runtime release (#57)
* Document native runtime skill semantics

* Rename native runtime to responsibility runtime

* Add responsibility runtime compiler skeleton

* Add responsibility compilation IR

* Compile Forme manifests into repository IR

* Serve static repository IR

* Tighten responsibility runtime review gaps

* Introduce OpenProse root model

* Harden OpenProse root resolution

* Add responsibility judge activation

* Add responsibility pressure fulfillment path

* Add repository status inspection

* Make triggers concrete gateway registrations

* Add live responsibility trigger adapters

* Refine responsibility runtime validation

* Harden responsibility runtime freshness

* Tighten responsibility runtime guardrails

* docs: replace skill examples with native repositories

* chore: release v0.12.0

* fix: tighten release review gaps
2026-05-04 09:26:26 -07:00
dan 624e75ad89 Refresh OpenProse skill conventions (#51)
* Refresh OpenProse skill conventions

* Align OpenProse skill with service system conventions

* Fix OpenProse PR review inconsistencies

* Clarify OpenProse state backend loading

* Enforce OpenProse smoke run state gate
2026-05-01 15:06:40 -04:00
Jose Montes de Oca 93e91325d7 feat: ship OpenProse as first-class Claude + Codex plugin (#46)
OpenProse already installed as a Claude Code plugin via
`npx skills add openprose/prose`, but the packaging surface was
uneven: missing manifest fields, no native Codex envelope, no
plugin-track release process, and a couple of doc/audience
inconsistencies. This commit closes those gaps without changing
skill behavior.

OpenProse now ships from the repo root as a dual-host plugin
envelope — `.claude-plugin/` for Claude Code, `.codex-plugin/`
plus `.agents/plugins/` for Codex — with `skills/open-prose/`
as the shared core and `prose ...` as the only user-facing
command surface.

Codex envelope:
- .codex-plugin/plugin.json with first-class catalog metadata
  (displayName, developer, descriptions, category, capabilities,
  defaultPrompt, privacy/terms URLs).
- .agents/plugins/marketplace.json local-source catalog, installable
  by anyone who clones this repo.

Claude Code manifest hygiene:
- Added license, homepage, and skills: ./skills so the plugin is
  self-describing.
- Added marketplace.json metadata.description, clearing the sole
  `claude plugin validate` warning.
- Deleted the stale .claude-plugin/README.md.

Skill metadata:
- Added license: MIT to skills/open-prose/SKILL.md frontmatter
  (no top-level version — Claude Code strips unrecognized top-level
  frontmatter keys; see anthropics/claude-code#13005).
- Fixed an inconsistent parse-table cell pair in
  skills/open-prose/deps.md.

Audience boundaries:
- AGENTS.md is now contributor-only per agents.md.
- Recommended consumer [agents] Codex config moved to README.md
  alongside the Quickstart.

Release process:
- scripts/bump-version.sh + .version-bump.json bump both manifests
  atomically, with a --check mode for CI. The Claude Code
  marketplace deduplicates by version, so a forgotten bump silently
  strands users on cached copies; this gate prevents that.
- scripts/extract-changelog.sh pulls a single `## [X.Y.Z]` block
  out of CHANGELOG.md.
- RELEASE.md documents the manual flow.
- .github/workflows/release.yml verifies declared versions match
  on `v*` tag push and publishes a GitHub Release.

CI:
- New plugin-manifest.yml: every-PR gate validating both plugin.json
  files, asserting declared skills paths resolve, and running
  bump-version.sh --check.
- cli-skills-smoke.yml: added `npx skills list openprose/prose`
  discoverability check alongside the existing install smoke.
- openprose-smoke/run.ts: removed a dead commands/prose-*.md regex.
2026-04-30 20:31:48 -07:00
Jose Montes de Oca 66446fb0f6 chore(ci): add a smoke CI gate for the OpenProse skill (#42)
Add a required smoke CI path for the `open-prose` skill.

- Add focused smoke fixtures for core OpenProse execution behavior.
- Add a TypeScript runner that installs the PR skill into isolated workspaces and validates `.prose/runs/` outputs.
- Add a GitHub Actions workflow with read-only permissions, fork safety, pinned tooling, artifact capture, and hardened Claude Code invocation.
- Validate the suite with both dry-run checks and a local live `9/9` smoke run.
2026-04-29 19:21:54 -07:00
irl-dan 18b3579ddc ci: add LongCoT benchmark workflow + pi-mono shim
workflow_dispatch action that runs the LongCoT benchmark using
pi-mono (@mariozechner/pi-coding-agent) as the inference harness.
Defaults (difficulty=longcot, thinking=high, no tools/scaffolding,
2 retries) mirror the paper for 1:1 result comparison; README
covers iteration with longcot-mini + slice inputs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-18 14:50:16 -07:00