Skip to content

runtime: ship repaired v4.5.1 activation bundle - #65

Merged
sumitake merged 1 commit into
mainfrom
dev/codex/v451-runtime-release
Jul 26, 2026
Merged

runtime: ship repaired v4.5.1 activation bundle#65
sumitake merged 1 commit into
mainfrom
dev/codex/v451-runtime-release

Conversation

@sumitake

@sumitake sumitake commented Jul 26, 2026

Copy link
Copy Markdown
Owner

Summary

Ship the final repaired agent-collab v4.5.1 activation bundle built from workspace 1.0.823 commit d08b6382710d6d5910d64cf011bcac873a2e1c03 after the containment, canonical-HOME, lifecycle, timeout, zero-output, notarization, OpenCode Go, and continuity repairs converged.

The imported Darwin arm64 bundle is the exact sealed production handoff: SHA-256 2cea10cff2030d0238661667cf8d1b83cf9885dc6f4a03b0db4365e891b04f47, Apple notarization submission c6d29dec-5351-467d-883e-0b862734567d. No provider implementation source or signing credential enters this repository.

README and changelog surfaces now describe the co-packaged activation artifact and retain the merged v4.5.1 OpenCode Go, skill-pack, and structural-containment additions.

Boundary declaration

  • No provider executor source, raw provider command, credential, private absolute path, retired package tree, downloader, or post-install hook is included.
  • Native-runtime changes contain only the final signed artifact and reviewed public verification metadata; implementation and credentials remain private.
  • The change does not create a host-specific preset or provider-specific plugin.

Generated and release surfaces

  • Skill specs and generated SKILL.md files are in parity.
  • Claude and Codex marketplaces/manifests are in parity.
  • A unique changelog.d/ fragment is present; generated CHANGELOG.md is unchanged.
  • Version metadata already declares unreleased v4.5.1 and remains internally consistent.

Verification

  • python3 scripts/build_skills.py --check
  • python3 scripts/build_marketplace.py --check
  • python3 scripts/build-changelog.py --dry-run
  • python3 -m unittest discover -s tests -t . -v — 579/579
  • python3 -m unittest discover -s scripts -p test_*.py -v — 254/254
  • python3 scripts/check_release_consistency.py --against-ref origin/main
  • python3 scripts/secret_scan.py
  • python3 scripts/check-public-export-safety.py --active-tree
  • Fresh canonical GitHub clone: python3 scripts/check-public-export-safety.py --active-tree --history
  • python3 scripts/verify_runtime_release.py --git-sha 7e86d44f8c8a607de439f4eef2fde0dafa191975
  • Commit-bound build_plugin_archive.py --expected-commit 7e86d44f8c8a607de439f4eef2fde0dafa191975
  • Deterministic SPDX 2.3 evidence: 9 packages, 121 files, 130 relationships
  • git diff --check

The long-lived local clone retains private pre-consolidation refs and therefore intentionally fails an all-local-ref history scan. A fresh clone of the canonical GitHub repository contains 11 published refs and passes the exact active-tree plus history gate used by release CI.

Review and post-condition

Tier 3: release supply chain, signing, runtime verification, and containment behavior. A distinct-family exact-head review is in progress. After merge, compile the v4.5.1 changelog through a release PR, cut the signed annotated v4.5.1 tag, verify the published archive/evidence byte identities, then use the continuity-safe private lifecycle to replace only the inactive candidate while preserving serving lane 30.

author: codex (OpenAI GPT-5.6-sol, xhigh)
standing_directives: AGENTS.md source boundary, docs/public-governance.md Tier 3 review, signed runtime import, README/changelog parity, complete repository validation
tier: 3
cross_check: PROCEED - Google Gemini 3.1 Pro High exact-head Tier-3 review, confidence H, novel risk none, zero findings; durable PR comment 5084598017
post_condition: merge, compile v4.5.1 changelog, signed-tag release, verify published artifact and evidence, continuity-safe inactive-candidate replacement with lane 30 preserved, repaired watcher install, serial installed Gemini/Grok/OpenCode successes
mcp_coverage_gap: NONE
contributor_rights: OWNER-AUTHORED
operator_reserved: no

@sumitake

Copy link
Copy Markdown
Owner Author

Exact-head Tier-3 independent review — Google/Gemini

  • Reviewer family: Google (gemini-3.1-pro-high, direct CLI alternative explicitly authorized by the operator because the Claude quota reset was not practical)
  • Mode: read-only plan + sandbox; no repository, release, tag, install, selector, provider, watcher, or lifecycle mutation
  • Reviewed head: 7e86d44f8c8a607de439f4eef2fde0dafa191975
  • Reviewed base: b5ab1092f5e57253657a1d9472c26a1be9ddb7c7
  • Verdict: PROCEED
  • Confidence: H
  • Novel risk: none
  • Findings: none

Reviewer summary:

Tier-3 release supply-chain review verified clean ancestry and exact diff. Only the signed/notarized darwin-arm64 standalone bundle, closed manifest (matching whole-bundle digest 2cea10cff2030d0238661667cf8d1b83cf9885dc6f4a03b0db4365e891b04f47, Developer ID team 36UFP9KY4T, hardened runtime, secure timestamp, notarization requirements, and file permissions), and aligned documentation updates were introduced without private source or credential leakage. Release gates and activation continuity are fully satisfied.

This direct reviewer result is governance evidence for PR #65 only. It is not counted as an installed-coordinator canary; post-activation Gemini/Grok/OpenCode proofs remain mandatory.

@sumitake
sumitake marked this pull request as ready for review July 26, 2026 17:29
@sumitake
sumitake merged commit 3b10d38 into main Jul 26, 2026
17 checks passed
@sumitake
sumitake deleted the dev/codex/v451-runtime-release branch July 26, 2026 17:30
@sumitake sumitake mentioned this pull request Jul 26, 2026
11 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant