Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
234 commits
Select commit Hold shift + click to select a range
3a73855
fix(runtime): published dynamic expansions are the lock-free authorit…
aviggiano Sep 28, 2026
d3ba05c
fix(runtime): a leftover expansion lock no longer refuses a dynamic s…
aviggiano Sep 28, 2026
eb5487f
fix(security): require eyJ header and payload segments in the JWT rule
aviggiano Sep 28, 2026
247c75a
fix(security): let the publication gate pass Anvil's public dev mnemo…
aviggiano Sep 28, 2026
6fffcf4
fix(runtime): restate whole-run accounting in runtime report presenta…
aviggiano Sep 28, 2026
b6a2a68
fix(runtime): stop the canonical report renderer rejecting its own ou…
aviggiano Sep 28, 2026
c51b310
docs: describe whole-run report summaries and literal prose links
aviggiano Sep 28, 2026
87c57d9
fix(runtime): resume keeps the run's agent auth config
aviggiano Sep 28, 2026
628f4c4
test(runtime): pin why prose escapes the parenthesis rather than the …
aviggiano Sep 28, 2026
336a2f8
fix(runtime): literal braces in prompt text no longer fail the workfl…
aviggiano Sep 28, 2026
c6f0060
fix(runtime): run the JSON validator preflight once per engine process
aviggiano Sep 28, 2026
9a92ecd
refactor(runtime): delete the unused smithersSnapshotUnverifiedDepend…
aviggiano Sep 28, 2026
da3653e
fix(runtime): name the runner error when a workflow fails with no fai…
aviggiano Sep 28, 2026
0da2113
fix(runtime): give agent retries a real wait and the whole planned chain
aviggiano Sep 28, 2026
0a71fe3
fix(runtime): cancel and pause work even when run control evidence ha…
aviggiano Sep 28, 2026
6c2020c
fix(runtime): leave paused runs out of the workflow deadline and warn…
aviggiano Sep 28, 2026
abf8146
fix(runtime): stop rewriting unchanged runs on observation and bound …
aviggiano Sep 28, 2026
4653c4b
fix(runtime): run one synchronization pass per run at a time and drop…
aviggiano Sep 28, 2026
aa3574a
fix(runtime): status reports the runner's health when its state refre…
aviggiano Sep 28, 2026
689e92e
docs: document the runner query timeout, synchronization contention a…
aviggiano Sep 28, 2026
7db436f
perf(runtime): write execution-snapshot files with their final mode a…
aviggiano Sep 28, 2026
c0f9625
fix(runtime): doctor requires only the agent CLIs a run can dispatch to
aviggiano Sep 28, 2026
332bdab
fix(runtime): keep refreshed controllers out of the governed target i…
aviggiano Sep 28, 2026
e7a5e50
fix(runtime): parse the control seal with an item limit that covers i…
aviggiano Sep 28, 2026
3d4a26e
docs: changelog entry for launch I/O and doctor fixes
aviggiano Sep 28, 2026
8741305
test(runtime): stop pinning adapter template bytes and sizes
aviggiano Sep 28, 2026
95ed8b3
fix(runtime): import path in the DeepSeek adapter and lint templates …
aviggiano Sep 28, 2026
ef3a8fa
fix(artifacts): the task-manifest gate no longer re-derives which inp…
aviggiano Sep 28, 2026
b139d3a
fix(runtime): record failed launches and report their original error
aviggiano Sep 28, 2026
f8d72a5
fix(runtime): build host aggregation sources from the sealed attempt …
aviggiano Sep 28, 2026
2192454
fix(runtime): accept the sealed closure dynamic lowering gives deeper…
aviggiano Sep 28, 2026
24b025e
fix(runtime): delete the host-only severity matrix gate
aviggiano Sep 28, 2026
84b4a79
fix(runtime): report unscoped coverage prose scores as warnings
aviggiano Sep 28, 2026
ff5ba1b
refactor(evals): delete the zero-reporter telemetry pump and reporter…
aviggiano Sep 28, 2026
aa12e72
refactor(evals): delete the automatic eval-history publication leftovers
aviggiano Sep 28, 2026
f49577a
refactor(evals,cli): delete `eval history --max-age-days`
aviggiano Sep 28, 2026
bf563a8
refactor(evals): stop rendering the six per-metric eval-history charts
aviggiano Sep 28, 2026
597f5aa
refactor(evals,evmbench): delete exports nothing calls
aviggiano Sep 28, 2026
846dcf3
docs(changelog): record the eval dead-code removals
aviggiano Sep 28, 2026
07575e2
refactor(runtime): delete the host re-implementation of campaign time…
aviggiano Sep 28, 2026
1db7f6d
refactor(runtime): delete host campaign partition joins the registry …
aviggiano Sep 28, 2026
386c244
refactor(runtime): delete invariant-ledger checks the ledger schema a…
aviggiano Sep 28, 2026
d4b1761
refactor(runtime): require the sealed attempt authority in the host a…
aviggiano Sep 28, 2026
e3b385b
refactor(runtime): read the resolved invariant priority settings with…
aviggiano Sep 28, 2026
7446394
docs(changelog): record the host artifact gate de-duplication
aviggiano Sep 28, 2026
5358806
refactor(prompts): delete the unused prompt rename feature and duplic…
aviggiano Sep 28, 2026
dd12e8b
refactor(config): delete the prompt-metadata layer and helpers with n…
aviggiano Sep 28, 2026
1785e1c
ci: delete benchmark CI scripts orphaned by #1131
aviggiano Sep 28, 2026
5ccd0a8
refactor(modal): delete unreferenced exports and move test-only helpe…
aviggiano Sep 28, 2026
9da1816
refactor(dashboard): drop the always-false command capabilities
aviggiano Sep 28, 2026
23359f7
chore(runtime): drop the unused run-tests selectors
aviggiano Sep 28, 2026
e6c395c
docs(changelog): record the dead-code deletions
aviggiano Sep 28, 2026
4c64f58
refactor(artifacts): delete the 48 semantic gates nothing dispatches
aviggiano Sep 28, 2026
6c3c69e
refactor(artifacts,security): delete code with no production caller
aviggiano Sep 28, 2026
5ae10be
fix(artifacts): event appends stop re-reading the journal and writing…
aviggiano Sep 28, 2026
eaa1ed5
refactor(artifacts): findings and property validators return the Ajv …
aviggiano Sep 28, 2026
15944d0
docs(changelog): note the artifacts dead-code and event-journal changes
aviggiano Sep 28, 2026
ebe5ef6
test(runtime): pin host aggregation attribution for model-fanout prod…
aviggiano Sep 28, 2026
d0091ab
docs(changelog): record the host artifact gate false-positive fixes
aviggiano Sep 28, 2026
a037bc9
fix(runtime): a no-op resume attach leaves run state alone and says so
aviggiano Sep 28, 2026
8298212
fix(runtime): resume warns instead of dropping the trusted launcher o…
aviggiano Sep 28, 2026
7643f7a
style(runtime): satisfy strict lint on the changed gate code
aviggiano Sep 28, 2026
3803dff
fix(config): accept smol-toml 1.9 tables when loading project config
aviggiano Sep 29, 2026
99d227e
fix(runtime): DeepSeek tasks no longer hang on Claude Code result lines
aviggiano Sep 28, 2026
45a708c
fix(runtime): Kimi and Pi telemetry parsing fails open instead of han…
aviggiano Sep 28, 2026
71c6007
fix(runtime): native continuations stop blanking adapter-owned paths …
aviggiano Sep 28, 2026
427cba9
fix(runtime): route digests cover only route-bearing input, with one …
aviggiano Sep 28, 2026
5093390
fix(runtime): plain init refreshes the stock adapter closure
aviggiano Sep 28, 2026
4dacfd7
docs(changelog): record the adapter fail-open and route digest changes
aviggiano Sep 28, 2026
d29d86b
docs: explain OpenRouter prompt-injection guardrail rejections
aviggiano Sep 29, 2026
9272688
ci: run every release validation lane on pull requests and never canc…
aviggiano Sep 29, 2026
4f5e977
ci: run the release validation lanes under eatmydata
aviggiano Sep 29, 2026
ca8b55f
ci: report unused exports without blocking the build
aviggiano Sep 29, 2026
5c8b53e
test: give vitest packages a 30 s default test timeout
aviggiano Sep 29, 2026
953f222
test(cli): remove each test's temporary project when the test ends
aviggiano Sep 29, 2026
5bd2a00
build(lint): enforce complexity and size budgets on all code against …
aviggiano Sep 29, 2026
87fa795
docs: disable only MD013 for the one-entry-per-line changelog
aviggiano Sep 29, 2026
638ff30
docs: exempt CHANGELOG.md from markdownlint's line-length rule
aviggiano Sep 29, 2026
2aa9d69
fix(runtime): a reused attempt number supersedes an unrecorded occurr…
aviggiano Sep 28, 2026
6100115
docs: record the CI, lint baseline and smol-toml changes in the chang…
aviggiano Sep 29, 2026
ff0d4ff
ci: stop super-linter failing every edit to CHANGELOG.md on line length
aviggiano Sep 29, 2026
0858237
test(modal): stop pinning the package test script to an exact string
aviggiano Sep 29, 2026
f120561
fix(runtime): record each Smithers attempt once and never let the led…
aviggiano Sep 28, 2026
4a44146
fix(runtime): rebuild run.json accounting from usage.jsonl on every pass
aviggiano Sep 29, 2026
b4a1923
fix(runtime): report a Smithers event stream that reaches the CLI eve…
aviggiano Sep 29, 2026
2b80ca7
docs: describe the attempt ledger and accounting cache semantics
aviggiano Sep 29, 2026
ef54525
test(cli): run one campaign end to end with a controller kill and resume
aviggiano Sep 29, 2026
f0b53bf
ci: require the end-to-end campaign lane on pull requests
aviggiano Sep 29, 2026
131ff3e
fix: record validator_build as provenance instead of comparing it
aviggiano Sep 29, 2026
7683771
docs: describe validator_build as provenance
aviggiano Sep 29, 2026
8239556
docs: note the Super-Linter line-length change in the changelog
aviggiano Sep 29, 2026
93b3419
docs: disable markdownlint line length for CHANGELOG.md
aviggiano Sep 29, 2026
bbe614a
docs(runtime): say what lock-free dynamic expansion relies on and wha…
aviggiano Sep 29, 2026
b822474
test(runtime): cover the identity check a published expansion now rel…
aviggiano Sep 29, 2026
de764c0
fix(runtime): stop Smithers persisting a TaskHeartbeat event per hear…
aviggiano Sep 29, 2026
82b008d
fix(runtime): stop Smithers fetching and rebasing task worktrees
aviggiano Sep 29, 2026
7d1600a
test(cli): check that temporaryRoot removes a sealed tree and its fak…
aviggiano Sep 29, 2026
8c832d8
fix(runtime): read the runner's clean summary and bound run-error red…
aviggiano Sep 29, 2026
e6ededb
fix(topology): restore the review group time budget
aviggiano Sep 28, 2026
7dd5ee6
chore(topology): drop the unused timeout on pinned reference nodes
aviggiano Sep 28, 2026
0ae8e2c
fix(prompts): stop inviting production interface edits the handoff re…
aviggiano Sep 28, 2026
5080b5a
fix(runtime): warn at validate time when a project prompt differs fro…
aviggiano Sep 28, 2026
0333333
docs: changelog for the review timeout and prompt/gate fixes
aviggiano Sep 28, 2026
6af84e4
docs: let CHANGELOG entries exceed the markdownlint line length
aviggiano Sep 29, 2026
93c5259
fix(security): end the BIP39 word run at Anvil's public mnemonic
aviggiano Sep 29, 2026
d101467
fix(security): constrain only the JWT header segment
aviggiano Sep 29, 2026
b964ae2
fix(runtime): restate run-summary tokens, spend and partial pricing t…
aviggiano Sep 29, 2026
dde848f
fix(runtime): drop the renderer's legacy prose rules and escape `](` …
aviggiano Sep 29, 2026
561a881
docs(changelog): file the terminal-publication relabel under breaking…
aviggiano Sep 29, 2026
75cb1fc
test(cli): poll the event log for the end of the resumed campaign
aviggiano Sep 29, 2026
f7a5fb7
refactor(prompts): leave getPrompt to the catalog work item
aviggiano Sep 29, 2026
d7704ae
docs(changelog): state the dead-code entry only as strongly as the ev…
aviggiano Sep 29, 2026
36b7067
docs(changelog): say the restated summary keeps values run.json lacks
aviggiano Sep 29, 2026
cd145af
fix(evals): re-read run state after the watch loop before classifying…
aviggiano Sep 29, 2026
2628525
docs(evals): stop describing eval runs as keeping telemetry
aviggiano Sep 29, 2026
6a17f72
fix(prompts): tell Vyper setup agents to declare interfaces in the te…
aviggiano Sep 29, 2026
ff229f9
fix(runtime): doctor no longer summarizes a validation with warnings …
aviggiano Sep 29, 2026
1193208
chore: move the prompt drift helper and state what the anchor test co…
aviggiano Sep 29, 2026
ba7bd6c
docs: record the review pin's precedence break and the topology refresh
aviggiano Sep 29, 2026
2b9ac05
fix(runtime): report a launch still publishing its snapshot as incomp…
aviggiano Sep 29, 2026
777a841
docs(runtime): say what pause and cancel still refuse, and when they …
aviggiano Sep 29, 2026
0df3af5
docs: keep the security CHANGELOG entry within the 400-character line…
aviggiano Sep 29, 2026
dde0c7b
fix(runtime): stop retrying deterministic admission failures and labe…
aviggiano Sep 28, 2026
52cf339
docs: correct the OpenCode profile claim and scope the guardrail advice
aviggiano Sep 29, 2026
af55c86
perf(runtime): cut per-process and per-render cost of the generated w…
aviggiano Sep 28, 2026
75c4f2b
docs: state what still ends the retry chain, and that text-only deadl…
aviggiano Sep 29, 2026
b03a83a
docs: changelog for render robustness and runtime footprint
aviggiano Sep 28, 2026
668ad91
ci: disable markdownlint MD013 for CHANGELOG.md
aviggiano Sep 29, 2026
c71b867
test(runtime): make the campaign join tests fail only for the rule th…
aviggiano Sep 29, 2026
b375f43
test(artifacts): share one campaign timeout evidence fixture
aviggiano Sep 29, 2026
e3ae145
refactor(artifacts): make the finding backend provenance parser modul…
aviggiano Sep 29, 2026
cf00e20
docs(changelog): scope the host gate de-duplication entry
aviggiano Sep 29, 2026
99c2f7c
fix(runtime): keep unscoped report prose advisory when no coverage pr…
aviggiano Sep 29, 2026
e5bf30c
fix(prompts): keep the coverage projection partial identical to its r…
aviggiano Sep 29, 2026
d0bdb3b
test(runtime): pin aggregation finalization and implicit-visibility g…
aviggiano Sep 29, 2026
266dafa
docs(changelog): correct the severity-matrix claim and scope the cove…
aviggiano Sep 29, 2026
4d6632b
docs: exempt CHANGELOG.md from the markdown line-length rule
aviggiano Sep 28, 2026
ca8a8d5
ci: stale lint suppressions no longer fail lint
aviggiano Sep 29, 2026
2e8404b
fix(runtime): the post-agent verify pass no longer preflights the val…
aviggiano Sep 29, 2026
21dbff1
docs: state where the TypeScript saving and the goal-plan brace rule …
aviggiano Sep 29, 2026
474f4f8
test(runtime): cover imported Object bindings in registry shadowing
aviggiano Sep 29, 2026
c180b94
test(runtime): say what the fixture attempt authority leaves out
aviggiano Sep 29, 2026
2143c44
fix(runtime): say what a kept trusted launcher can and cannot do on r…
aviggiano Sep 29, 2026
9029ff8
fix(cli): the no-op resume message also covers a controller that just…
aviggiano Sep 29, 2026
10ce4e5
test(runtime): let the pause-handoff guard's engines exit before dele…
aviggiano Sep 29, 2026
4997f01
fix(runtime): return prompt-snapshot failures from planning and check…
aviggiano Sep 29, 2026
e6c3e1a
docs: scope the launch-failure claims to what the launcher records an…
aviggiano Sep 29, 2026
7099d74
docs: exempt CHANGELOG.md from markdownlint's line-length rule
aviggiano Sep 29, 2026
b3c0f58
fix(runtime): resume --retry-failed reopens descendants skipped behin…
aviggiano Sep 28, 2026
232ddf3
fix(runtime): re-render after every skip, not only after a pass that …
aviggiano Sep 29, 2026
93638ee
fix(runtime): count only required commands in doctor's toolchain summary
aviggiano Sep 29, 2026
2fc375f
refactor(runtime): parse every runtime document with one 400,000-item…
aviggiano Sep 29, 2026
e90ef90
docs: use the changelog MD013 directive sibling PRs add
aviggiano Sep 29, 2026
d1cc424
test(runtime): make the snapshot tests exercise the phases they name
aviggiano Sep 29, 2026
1950b26
fix(runtime): a synchronization that cannot take its lock reports it …
aviggiano Sep 29, 2026
b3e89ef
fix(runtime): a retried status refresh reads the evidence again, and …
aviggiano Sep 29, 2026
26c97db
fix(runtime): keep a run ID that contains "smithers" intact in the or…
aviggiano Sep 29, 2026
8ae1ae2
test(runtime): stop the observation test pinning a finished run's act…
aviggiano Sep 29, 2026
cafe392
docs: qualify the synchronization lock claims and document its failur…
aviggiano Sep 29, 2026
a87aaa5
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
89bd8c5
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
c21db95
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
1343f65
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
2d9479d
Merge remote-tracking branch 'origin/main' into train/1165
aviggiano Sep 29, 2026
08d93ce
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
a129fff
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
519b16a
Merge remote-tracking branch 'origin/main' into train/1163
aviggiano Sep 29, 2026
4fcb053
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
4eed4c9
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
5373aab
fix(runtime): skip a terminal event stamped before its attempt started
aviggiano Sep 29, 2026
3a29a1f
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
8b6d5eb
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
8564e52
Merge remote-tracking branch 'origin/main' into train/1172
aviggiano Sep 29, 2026
ce761b1
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
f65fdbe
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
798f29a
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
998b33b
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
11c2854
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
d6677fa
fix(runtime): keep recorded provenance when a refresh rebinds output …
aviggiano Sep 29, 2026
223e827
test(runtime): cover the observer graph-semantics divergence and drop…
aviggiano Sep 29, 2026
ba6bb92
docs: scope the validator-build provenance claims to what the code does
aviggiano Sep 29, 2026
ba3be9f
test(runtime): stop asserting that plain init preserves a legacy regi…
aviggiano Sep 29, 2026
0b0557a
fix(runtime): plain init leaves an up-to-date adapter untouched
aviggiano Sep 29, 2026
584ec50
fix(runtime): Pi counts each response whole and reports no usage it d…
aviggiano Sep 29, 2026
9b2dbce
fix(runtime): Codex openai_base_url pins the route again, and Claude …
aviggiano Sep 29, 2026
e0fb561
refactor(runtime): adapters use the runtime's credential helpers and …
aviggiano Sep 29, 2026
37bf22d
docs: scope the route-ID and init claims to what was verified
aviggiano Sep 29, 2026
3b3757e
build(lint): lint:fix reuses lint's flags, so stale counts no longer …
aviggiano Sep 29, 2026
d22f8b9
docs: describe the lint ratchet as it behaves when a fix is not pruned
aviggiano Sep 29, 2026
f3b045b
ci: stop the unused-exports report annotating every run as failed
aviggiano Sep 29, 2026
ad6fc79
ci: install eatmydata only when the runner lacks it, and scope what i…
aviggiano Sep 29, 2026
471cb18
test(ci): catch step-level pull-request gating of release validation
aviggiano Sep 29, 2026
a7b984c
fix(runtime): keep a finalized node's retry count in step with later-…
aviggiano Sep 29, 2026
c39eb8d
fix(runtime): validate usage fields inside the accounting pass
aviggiano Sep 29, 2026
7f62c95
refactor(security): delete matchesRedactedText, orphaned by the attem…
aviggiano Sep 29, 2026
f58b79f
docs: state which superseded attempts the ledger records and what cou…
aviggiano Sep 29, 2026
d743f6b
integrate #1165 (claude/w05c-secret-gate-false-positives)
aviggiano Sep 29, 2026
ea97b3a
integrate #1163 (claude/w07-freeze-dynamic-membership)
aviggiano Sep 29, 2026
30df6a9
integrate #1166 (claude/w09-smithers-unused-behaviors)
aviggiano Sep 29, 2026
0c2419a
integrate #1169 (claude/w06-resume-reopens-skipped)
aviggiano Sep 29, 2026
1df61d7
integrate #1177 (claude/w01-resume-correctness)
aviggiano Sep 29, 2026
5e68e29
integrate #1170 (claude/w17-cancel-pause-always)
aviggiano Sep 29, 2026
82d634f
integrate #1176 (claude/w05a-gate-false-positives)
aviggiano Sep 29, 2026
dfab09d
integrate #1178 (claude/w05b-one-gate-implementation)
aviggiano Sep 29, 2026
59ab9cb
integrate #1181 (claude/w19-artifacts-dead-code)
aviggiano Sep 29, 2026
da09b76
integrate #1172 (claude/w15a-terminal-without-failed-node)
aviggiano Sep 29, 2026
cb9390b
integrate #1167 (claude/w11-report-accuracy)
aviggiano Sep 29, 2026
be41fa4
integrate #1164 (claude/w12-topology-prompt-fixes)
aviggiano Sep 29, 2026
861e6ab
integrate #1174 (claude/w20a-evals-dead-code)
aviggiano Sep 29, 2026
7534c54
integrate #1175 (claude/w20b-prompts-config-ci-dead-code)
aviggiano Sep 29, 2026
c2da49c
integrate #1182 (claude/w28-openrouter-guardrail-docs)
aviggiano Sep 29, 2026
dd45e92
test(runtime): pass the sealed attempt authority in the unscoped-pros…
aviggiano Sep 29, 2026
3e8ad3f
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
e8ceb12
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
2c35e93
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
bbd411a
integrate #1180 (claude/w03-sync-pump)
aviggiano Sep 29, 2026
98e4c01
integrate #1185 (claude/w10-launch-failures-durable)
aviggiano Sep 29, 2026
bf9d36c
test(cli): report e2e reruns and stub failures by name, and clean up …
aviggiano Sep 29, 2026
dce193d
docs: say the e2e CLI runs under Node and the workflow under Bun
aviggiano Sep 29, 2026
e6498fd
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
2e6df80
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
607d268
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
0e8e77b
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
ffbd622
integrate #1186 (claude/w02-ledgers-never-block-sync)
aviggiano Sep 29, 2026
51ba383
integrate #1171 (claude/w08-retry-policy)
aviggiano Sep 29, 2026
d01352b
integrate #1173 (claude/w13-adapters-fail-open)
aviggiano Sep 29, 2026
4a20b1c
integrate #1168 (claude/w15b-render-robustness)
aviggiano Sep 29, 2026
d097113
integrate #1179 (claude/w16-launch-io-hygiene)
aviggiano Sep 29, 2026
3f107b9
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
48fdcee
integrate #1187 (claude/w22-hermetic-e2e)
aviggiano Sep 29, 2026
010dfc5
build(lint): replace the suppression baseline with a global complexit…
aviggiano Sep 29, 2026
2dffb6a
chore: move the changelog entry to the consolidated release notes
aviggiano Sep 29, 2026
9494348
integrate #1188 (claude/w24-validator-build-provenance)
aviggiano Sep 29, 2026
a48ad9c
integrate #1184 (claude/w21-ci-quality)
aviggiano Sep 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions .github/linters/.markdown-lint.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# Super-Linter's default markdownlint rules (v8.7.0 TEMPLATES/.markdown-lint.yml)
# with MD013 line length off. Super-Linter lints each changed file in full, and
# CHANGELOG.md keeps each entry on one line while docs tables have rows past
# 400 characters, so any edit to those files failed on lines nobody touched.
MD004: false
MD007:
indent: 2
MD013: false
MD026:
punctuation: ".,;:!。,;:"
MD029: false
MD033: false
MD036: false
blank_lines: false
56 changes: 30 additions & 26 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,18 +16,18 @@ on:
permissions:
contents: read

# A new push to a pull request cancels that pull request's older run. Every
# other run gets its own group: a shared group would still cancel a queued run
# on main whenever another push arrived.
concurrency:
group: ci-${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
group: ci-${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}
cancel-in-progress: true

jobs:
draft-and-build-gates:
name: "${{ github.event_name == 'pull_request' && 'PR build and Node.js 24 runtime smoke' || 'Build gates' }}"
name: Build gates
runs-on: ubuntu-latest
# The PR path also runs the serial runtime and CLI contract smoke suites.
# Under runner contention they completed successfully just after the former
# 15-minute ceiling, so keep a bounded two-times completion budget.
timeout-minutes: 30
timeout-minutes: 15

steps:
- name: Check out repository
Expand Down Expand Up @@ -67,6 +67,13 @@ jobs:
- name: Find dead code and dependencies
run: pnpm -w knip

# Informational until the pending dead-code removals land; then these
# categories move into the blocking `pnpm -w knip` step above. Findings
# exit 0, so they do not add a failure annotation to every run.
- name: Report unused exports
continue-on-error: true
run: pnpm -w knip --include exports,types,duplicates --no-exit-code

- name: Build
run: pnpm -w build

Expand All @@ -84,14 +91,6 @@ jobs:
- name: Enforce production dependency advisory policy
run: pnpm -w security:dependency-advisories

- name: Run PR runtime smoke tests
if: github.event_name == 'pull_request'
run: pnpm --filter @ultrafuzz/runtime test:pr-smoke:prebuilt

- name: Run PR CLI status contract smoke tests
if: github.event_name == 'pull_request'
run: pnpm --filter @ultrafuzz/cli test:pr-smoke:prebuilt

external-static-analysis:
name: External static analysis
runs-on: ubuntu-latest
Expand Down Expand Up @@ -125,10 +124,10 @@ jobs:
VALIDATE_SHELL_SHFMT: true
VALIDATE_YAML: true

# The lane table lives in scripts/ci/release-validation-lanes.mjs so the
# pull-request policy is a tested artifact instead of an invisible `if:`.
# While this job was gated off pull requests, every runtime test reported
# `skipping` on a PR and resume-path regressions merged with all checks green.
# The lane table lives in scripts/ci/release-validation-lanes.mjs, whose test
# checks that it runs every gate scripts/validate-release.mjs defines. Every
# lane runs on pull requests too: while lanes were gated off pull requests,
# regressions in the skipped suites merged with all checks green.
release-validation-lanes:
name: Select release validation lanes
runs-on: ubuntu-latest
Expand All @@ -144,17 +143,14 @@ jobs:

- name: Select release validation lanes
id: select
env:
EVENT_NAME: ${{ github.event_name }}
run: |
echo "lanes=$(node scripts/ci/release-validation-lanes.mjs --event "$EVENT_NAME")" >> "$GITHUB_OUTPUT"
echo "lanes=$(node scripts/ci/release-validation-lanes.mjs)" >> "$GITHUB_OUTPUT"

# The lanes start without waiting for the build gates; release-gates still
# requires every job.
release-validation:
name: Full release validation (${{ matrix.description }})
needs:
- draft-and-build-gates
- external-static-analysis
- release-validation-lanes
needs: release-validation-lanes
runs-on: ubuntu-latest
timeout-minutes: ${{ matrix.timeout_minutes }}
strategy:
Expand All @@ -172,6 +168,14 @@ jobs:
sudo rm -rf /usr/local/lib/android
sudo rm -rf /usr/share/dotnet

# Every test that launches a run copies a sealed execution snapshot of
# thousands of files and fsyncs each one in the test process, where
# eatmydata makes fsync a no-op. The Smithers engine's environment is
# built from an allowlist without LD_PRELOAD, so engine processes still
# sync. An ephemeral runner has nothing to protect across a crash.
- name: Install eatmydata
run: command -v eatmydata || { sudo apt-get update && sudo apt-get install -y eatmydata; }

- name: Check out repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
Expand Down Expand Up @@ -214,7 +218,7 @@ jobs:

- name: Validate release lane
run: >-
pnpm -w validate:release --
eatmydata pnpm -w validate:release --
--gates "${{ matrix.gates }}"
--report ".ultrafuzz/release-validation/${{ matrix.lane }}.json"

Expand Down
4 changes: 2 additions & 2 deletions .ultrafuzz/evals/bug-finding.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ reporting: # policy only — provider selection/credentials live in ultrafuzz.to
node_telemetry: true
heartbeat_interval_seconds: 60
experiment_prefix: bug-finding
artifacts:
mode: manifest-only # forced default when target.sensitivity == private; opt in to "upload"
artifacts: # still validated, but no eval behaviour depends on it
mode: manifest-only
include: ["report.md", "report.json"]
max_file_bytes: 5000000
Original file line number Diff line number Diff line change
Expand Up @@ -37,5 +37,6 @@ Blockers:

Repeat blocker and evidence rows in artifact order. Runtime publication compares
this section with the typed handoff and rejects missing, duplicated, reordered,
or bare coverage scores. Raw `covg-eval` output is for iteration only and
defines neither published declaration-completeness view.
or contradicting scoped scores, and it warns about coverage scores that name no
exact scope. Raw `covg-eval` output is for iteration only and defines neither
published declaration-completeness view.
19 changes: 0 additions & 19 deletions .ultrafuzz/prompts/review/final-report.md
Original file line number Diff line number Diff line change
Expand Up @@ -385,25 +385,8 @@ Ultrafuzz is an automated smart-contract fuzzing campaign assistant. Issues belo
- Tokens used: `<token usage, or unavailable>`
- Estimated spend: `<cost estimate such as $123 or $123+ when pricing is partial, or unavailable>`
- Audit profile: `<effective audit profile, or unavailable>`

## Audit context

- Threat model: [THREAT_MODEL.md](<relative path to THREAT_MODEL.md>); [threat-model.json](<relative path to threat-model.json>)
- Goal plan: [goal-plan.json](<relative path to goal-plan.json>)
```

Render `## Audit context` with exactly this heading, bullet order, and link
text, immediately after `## Run summary`. Use repository-relative or
report-relative paths to the run's own `threat-model` and `goal-plan` artifacts;
never absolute paths or external URLs. Omit an individual link whose artifact
the run did not produce, omit the `Goal plan` bullet when there is no goal plan,
and omit the whole section when the run produced none of them. Do not invent a
different heading, ordering, or link text: `ultrafuzz report` regenerates this
exact section deterministically from the run's own artifacts and overwrites
anything else.
Keep detailed threat content in those dedicated artifacts; do not duplicate it
in `report.md`.

Each production issue entry must use exactly this Markdown section order. The
following example is structural only; replace the title, actor names, actions,
outcomes, explanations, code, variants, and strategy IDs with issue-specific
Expand Down Expand Up @@ -825,8 +808,6 @@ Before finishing, verify that:
- `report.md` contains `## Property provenance`, including every
property-derived finding and no invented property IDs for non-property
findings.
- `report.md` renders the fixed `## Audit context` section for every artifact
the run produced, without copying their detailed analysis.
- `report.md` contains `## Property implementation coverage` rendered from the
exact runtime-authoritative coverage object.
- `report.md` contains `## Goal search coverage` with counts recomputed from the
Expand Down
6 changes: 4 additions & 2 deletions .ultrafuzz/prompts/setup/discover-base-test.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,8 +39,10 @@ If the setup handoffs identify Vyper-only or mixed Solidity/Vyper production
contracts, make the reusable Foundry fixture Vyper-aware while keeping the tests
Solidity-based. Define Solidity interfaces for the Vyper contracts' ABI-visible
public/external functions and events, or reuse ABI-derived interfaces generated
by the target repository. Do not require Foundry to compile `.vy` files as
Solidity sources.
by the target repository. Declare any new interface in the test tree: the
workspace handoff rejects every change under the production source roots (by
default `src/` and `contracts/`). Do not require Foundry to compile `.vy` files
as Solidity sources.

For Vyper deployment helpers, prefer one reusable path that compiles creation
bytecode with the target project's pinned compiler/tooling from the project
Expand Down
4 changes: 3 additions & 1 deletion .ultrafuzz/prompts/setup/prepare-foundry-harness.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,9 @@ production contracts, keep Foundry as the test harness and do not ask Foundry to
compile `.vy` files as Solidity sources. Configure the harness so generated
`.t.sol` tests interact with Vyper contracts through Solidity interfaces that
match the contracts' public/external ABI, or through ABI-derived Solidity
interfaces when the target repository already generates them.
interfaces when the target repository already generates them. Declare any new
interface in the test tree: the workspace handoff rejects every change under the
production source roots (by default `src/` and `contracts/`).

Create only the minimal harness layout needed by later fuzzing agents.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -124,8 +124,10 @@ an unselected expected check is not implemented or fulfilled.
guard, or other precondition that prevents the backend from observing the
violating post-state. Preconditions may admit valid actions; they may not
assume the property under test.
- Do not edit production contracts except interfaces that are genuinely
required by the test harness.
- Do not edit production contracts, not even to add an interface: the
workspace handoff rejects every change under the production source roots
(by default `src/` and `contracts/`). Declare any interface the harness
needs in the test tree instead.
- Keep generated or changed invariant files in the test tree and include
every changed `*.t.sol` test/reproducer in `generated-tests.json`.
- Preserve Recon constructor deployment if property work changes `Setup`,
Expand Down
2 changes: 1 addition & 1 deletion .ultrafuzz/prompts/strategies/invariants/setup.md
Original file line number Diff line number Diff line change
Expand Up @@ -71,7 +71,7 @@ project's pinned revision.
Use these Recon/Chimera rules while making decisions:

- Read `AGENTS.md` and obey all repository-specific rules before editing.
- Do not edit production `src/` or `contracts/` except for interfaces if they are genuinely required by the harness.
- Do not edit production `src/` or `contracts/`, not even to add an interface: the workspace handoff rejects every change under the production source roots. Declare any interface the harness needs in the test tree instead.
- [Chimera](https://github.com/Recon-Fuzz/create-chimera-app) is the write-once, run-everywhere scaffold for Foundry, Echidna, Medusa, Halmos, and Kontrol style runs.
- The create-chimera-app layout under the repository's test root is:
`<test-root>/recon/Setup.sol`, `BeforeAfter.sol`, `Properties.sol`,
Expand Down
11 changes: 2 additions & 9 deletions .ultrafuzz/topology.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,8 @@ groups:
review:
label: Review
color: "#0f766e"
defaults:
timeout_seconds: 7200
nodes:
- id: __start__
kind: meta
Expand Down Expand Up @@ -198,7 +200,6 @@ nodes:
group: references
depends_on:
- __start__
timeout_seconds: 300
outputs:
- path: references/0kn0t.md
contract: ultrafuzz/nonempty-markdown@1
Expand All @@ -211,7 +212,6 @@ nodes:
group: references
depends_on:
- __start__
timeout_seconds: 300
outputs:
- path: references/certora-thinking.md
contract: ultrafuzz/nonempty-markdown@1
Expand All @@ -224,7 +224,6 @@ nodes:
group: references
depends_on:
- __start__
timeout_seconds: 300
outputs:
- path: references/certora-sanity.md
contract: ultrafuzz/nonempty-markdown@1
Expand All @@ -237,7 +236,6 @@ nodes:
group: references
depends_on:
- __start__
timeout_seconds: 300
outputs:
- path: references/aviggiano.md
contract: ultrafuzz/nonempty-markdown@1
Expand All @@ -250,7 +248,6 @@ nodes:
group: references
depends_on:
- __start__
timeout_seconds: 300
outputs:
- path: references/rounding.md
contract: ultrafuzz/nonempty-markdown@1
Expand All @@ -263,7 +260,6 @@ nodes:
group: references
depends_on:
- __start__
timeout_seconds: 300
outputs:
- path: references/crytic.md
contract: ultrafuzz/nonempty-markdown@1
Expand All @@ -276,7 +272,6 @@ nodes:
group: references
depends_on:
- __start__
timeout_seconds: 300
outputs:
- path: references/runtime-verification.md
contract: ultrafuzz/nonempty-markdown@1
Expand All @@ -289,7 +284,6 @@ nodes:
group: references
depends_on:
- __start__
timeout_seconds: 300
outputs:
- path: references/a16z-erc4626.md
contract: ultrafuzz/nonempty-markdown@1
Expand All @@ -302,7 +296,6 @@ nodes:
group: references
depends_on:
- __start__
timeout_seconds: 300
outputs:
- path: references/recon.md
contract: ultrafuzz/nonempty-markdown@1
Expand Down
19 changes: 13 additions & 6 deletions docs/SPECS.md
Original file line number Diff line number Diff line change
Expand Up @@ -243,8 +243,15 @@ Every planned JSON output MUST resolve through the checked-in schema registry.
The planned and expanded graph representations MUST persist the schema filename,
fragment-free schema ID, schema SHA-256, package schema-bundle SHA-256, and
validator build identity. Missing or partial bindings MUST fail planning or host
verification. Operators declare the versioned contract in topology; they MUST
NOT supply these trust identities manually in YAML.
verification. Host artifact gates and verified reads MUST validate against the
schema content a binding names, using the run's sealed schema snapshot when the
installed bundle differs. The recorded validator build and contract digest are
provenance: graph reads, host artifact gates, verified reads, task preparation,
dependency admission, and the validator preflight MUST NOT require them to equal
the reading build's own. Task preparation and the validator preflight MUST still
require the schema bundle they validate with to be the planned one. Operators
declare the versioned contract in topology; they MUST NOT supply these trust
identities manually in YAML.

## Prompts

Expand Down Expand Up @@ -447,9 +454,10 @@ every non-builtin module whose lexical or physical resolution escapes the
closure. Ordinary artifact and schema data reads remain outside this module
boundary. Modal MUST provide the equivalent root-owned,
read-only entrypoint. Both environments MUST run a real known-valid fixture and
verify the returned schema ID, schema digest, bundle digest, and validator build;
`command -v` alone is insufficient. A missing, tampered, or stale launcher or
closure is a setup failure for new model work. It MUST NOT turn historical
verify the returned schema ID, schema digest, and bundle digest; the returned
validator build is provenance and MUST NOT be compared. `command -v` alone is
insufficient. A missing, tampered, or stale launcher or closure is a setup
failure for new model work. It MUST NOT turn historical
seals or schema identities into resume authorization. A current-controller
continuation MAY select current validator packages while retaining historical
source and artifacts as provenance.
Expand All @@ -470,7 +478,6 @@ Before or at launch, each run MUST persist:
- immutable rendered prompt snapshots under `prompt-snapshots/`
- per-node artifacts under `artifacts/`
- review artifacts under `review/`
- event query indexes under `events.index/`
- workspace metadata under `workspaces/`

Reporting is agentic and lives in final-report artifacts.
Expand Down
Loading
Loading