Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
a835951
Add proposed acquisition and runtime adapter plans
MrScripty Sep 29, 2026
f4dd7ff
merge: restore coordinated acquisition and adapter plans
MrScripty Sep 29, 2026
ef74e84
docs(acquisition): admit Q1 and record starting evidence
MrScripty Sep 29, 2026
5010533
docs(acquisition): define durable handoff transitions
MrScripty Sep 29, 2026
8b96cab
feat(acquisition): route HF through shared HTTP protocol
MrScripty Sep 29, 2026
98c1991
feat(acquisition): resolve verified GitHub release assets
MrScripty Sep 30, 2026
096d180
refactor(acquisition): support multiple destination grants
MrScripty Sep 30, 2026
560cec7
fix(runtime): retain native installer effects through shutdown
MrScripty Sep 30, 2026
48ad1ba
Merge branch 'work/q1-native-custody' into work/acquisition-q1-http
MrScripty Sep 30, 2026
2193236
docs(acquisition): record q1 candidate evidence
MrScripty Sep 30, 2026
584b5f4
refactor(acquisition): scope shared task custody by consumer
MrScripty Sep 30, 2026
c305258
Merge branch 'agent/q1-hf-custody-scoping' into work/acquisition-q1-http
MrScripty Sep 30, 2026
efc4d20
docs(acquisition): record scoped custody candidate
MrScripty Sep 30, 2026
7129d51
docs(acquisition): admit shared store implementation slice
MrScripty Sep 30, 2026
5ef3e05
docs(acquisition): admit explicit schema migration boundary
MrScripty Sep 30, 2026
65274df
feat(acquisition): route HF through durable shared custody
MrScripty Sep 30, 2026
bc9e9da
Merge branch 'agent/q1-hf-acquisition' into work/acquisition-q1-http
MrScripty Sep 30, 2026
d0b71b5
fix(acquisition): reject conflicting durable custody
MrScripty Sep 30, 2026
8b6c5f7
fix(acquisition): guard in-place imports with exact custody proofs
MrScripty Sep 30, 2026
9719ecb
Merge branch 'agent/q1-import-custody-guard' into work/acquisition-q1…
MrScripty Sep 30, 2026
e46fc9a
feat(acquisition): complete shared consumer receipt handoff
MrScripty Sep 30, 2026
4c58197
docs(release): refresh Q1 attribution input
MrScripty Sep 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,8 @@ and remediation inputs, not current operating instructions.

## Active and Planned Work

- [Artifact acquisition](plans/artifact-acquisition/plan.md) — Q1 shared HTTP acquisition is active; AQ-HTTP is not ready
- [Runtime installations and model adapters](plans/runtime-installations-and-model-adapters/plan.md) — runtime implementation remains gated by acquisition evidence
- [2026-09-03 current-standards remediation program](plans/current-standards-remediation-2026-09-03/plan.md)
- [Local intent API and transport-independent domain language](plans/local-intent-api-2026-09-12/plan.md) — complete within the recorded local scope; native resolution, acquisition, durable declarations and existing IPC/RPC projections accepted; nodes/fleets/new networking deferred until after the next release

Expand Down
151 changes: 151 additions & 0 deletions docs/contracts/artifact-acquisition.md

Large diffs are not rendered by default.

171 changes: 171 additions & 0 deletions docs/plans/artifact-acquisition/execution-ledger.md

Large diffs are not rendered by default.

28 changes: 28 additions & 0 deletions docs/plans/artifact-acquisition/issues.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
# Acquisition issues and dispositions

Q1 is active; production repairs and acceptance claims remain pending until evidence is recorded. Evidence references [the source audit](reports/codebase-audit.md), [the canonical contract](../../contracts/artifact-acquisition.md), and its linked primary sources. Severity is consequence within this scope, not an asserted exploited vulnerability.

| ID | Severity / issue | Owner / disposition | Deciding evidence and revisit condition |
| --- | --- | --- | --- |
| AQ-I01 | High: model-specific destination authority cannot become the generic artifact root | Acquisition/core: fix in Q1 | AC01/AC04/AC09; re-plan if safe neutral capability extraction cannot preserve model custody |
| AQ-I02 | High: retained model/HF records and recovery transitions need explicit migration | Core/recovery: fix in Q1 | AC04–AC06; actual source/deployment inventory before mutation |
| AQ-I03 | High: cancellation/restart must retain worker and byte-use ownership | The local Q1 candidate closes the native pre-receipt cancellation gap: it durably revokes the exact attempt, drains/cleans its workspace under the native lock, and withdraws only the exact unchanged receipt-free `Using` lease. Cold reopen and same-tag retry are covered. Broader cancellation/crash-window acceptance remains pending. | AC05/AC06; retain exact-generation worker drainage and cleanup-failure/cold-reopen evidence; never equate caller cancellation with worker stop |
| AQ-I04 | High: acquisition/import/install completion and duplicate transfer owners | Current local Q1 candidate routes HF and llama.cpp through the shared transfer owner and gives both consumers exact completion receipts; composed source review found no remaining issue, while objective acceptance evidence remains pending | AC03/AC05/AC08/AC18; retain cold-reopen, cancellation, and no-duplicate-transfer proof; never infer import/install completion from path or metadata presence |
| AQ-I05 | High: cross-plan duplicate authority or prerequisite cycle | Integrator: fixed in plan design; implementation evidence pending | Gate graph and Q1/Q2 old-consumer evidence; review after any milestone dependency change |
| AQ-I06 | High: generic retrieval can be mistaken for package compatibility or executable trust | Runtime/package/security: Q2, with Q1 trust contract | AC07/AC11/AC12; keep origin and byte digest separate |
| AQ-I07 | Medium: new generic module could accidentally require inference or overclaim feature isolation | Core/composition: Q1/Q3/Q4 | AC09/AC15/AC17; no unsupported minimal-build claim |
| AQ-I08 | Medium: source roadmap can expand prerequisite beyond useful consumer result | Integrator: Q1 contract first; Q3 required S3 scope; future features deferred below | AC18 and gate-status record |
| AQ-I09 | Medium: hashless source comparison is not isolation from an uncooperative local writer that can modify a file in place and restore metadata before model import | Acquisition/import handoff: Q1 claim is explicitly limited; resolve through a same-owner handle/lifetime handoff or document and verify the supported local-writer threat model before any broader claim | AC05–AC07; revisit at shared durable handoff and final composed review |
| AQ-I10 | High, fixed in local Q1 candidate `d0b71b5`: acquisition-document validation accepted duplicate demands and overlapping active workspace custody, allowing `begin` to select around a retained `Using` record | Acquisition store: fixed by cross-record `AcquisitionDocument::validate`; independent exact-candidate review found no new issue | Three persisted-document fixtures cover duplicate demand, active-workspace collision, and terminal-history/successor coexistence; retain these invariants through schema-7 receipt work |
| AQ-I11 | High, fixed in local Q1 source tree `0c3e472c`: effectful in-place import and orphan adoption could act on a destination after an acquisition or hidden model admission retained custody | Model-library/importer: fixed by guard at the effect boundary with exact private partial/full HF stages; independent review found no P0–P3 issue | Worker reports focused real-store/filesystem/owner tests and cancellation/panic/replacement probes; reopened `Using` remains unresolved and AQ-HTTP is still not ready |
| AQ-I12 | High: metadata/index presence and package-facts cache freshness alone do not prove which `Using` lease completed import | Current local Q1 candidate implements the schema-7 HF receipt and exact cold reconciliation; composed source review found no remaining issue, while objective acceptance evidence remains pending. Never replay import after ambiguous publication. | AC05/AC08; retain proof that the receipt binds acquisition/use identity and deterministic output content, survives every writer/migration, and cold-reopens without importer invocation |
| AQ-D01 | Deferred: native Xet reconstruction | Acquisition/source owner | Revisit when a required HF source cannot use the supported existing file path or Xet transfer benefits are an admitted goal; evaluate maintained Rust implementation, no homemade protocol |
| AQ-D02 | Deferred: peers and concurrent multi-source failover | Acquisition/distribution owner | Revisit with actual node/authorization contract and content-equivalence proof; no cross-origin ETag comparison |
| AQ-D03 | Deferred: chunk CAS, reflink optimization and coalescing | Acquisition/storage owner | Revisit with measured duplication/network/storage need and explicit retention consumers; ordinary files and safe release are required now |
| AQ-D04 | Scoped retained dependency: package-resolver metadata and managed-Python-provider traffic | Package/runtime owner | Q2 inventories and accepts exact scope; migrate only through supported integration when it changes a meaningful transfer claim |
| AQ-D05 | Deferred: universal remote write/search/browsing or dynamic executable source plugins | Source owner | Revisit only for an explicit product/trust/API requirement; direct HTTP/S3 object acquisition is in scope now |
| AQ-E01 | Pending: required-real AWS/non-AWS/MinIO/native/desktop evidence | Assigned source/distribution integrator | AC14/AC17; missing environment blocks those claims, not fictional acceptance |

Pending cleanup replay and unrelated whole-runtime remediation are owned by the existing Rust/library plan. Preserve current refusal while migrating the selected transfer family. Do not mark those unrelated work items accepted from this plan's link/schema checks.

Q1 source preparation confirmed a public `DownloadManager` with no in-repository production caller, but did not establish its external compatibility population; removal or a compatibility disposition remains open. The supported download-store reader currently accepts schema 5 and upgrades schema 4, while deployment inventory and older-writer isolation are unavailable. Q1 must preserve both facts and keep live-root mutation blocked until that deployment evidence exists. The native llama.cpp cache currently uses size/filename admission and direct-final-directory extraction; these are admitted Q1 repair findings under AQ-I04/AQ-I07.
Loading