MVP Readiness Snapshot¶
Snapshot date: 2026-07-20.
This table is an estimated cross-document readiness snapshot for canonical Story, Proposal, and Solution documents.
Scope rules: localized duplicates (*.pl.md), indexes, backlog files, implementation notes, coding guides, and generated registries are excluded. Solution rows use the main NNN-*/NNN-*.md document for each component.
Estimation basis: node/docs/MVP.md defines the hard-MVP story set (story-000, story-002, story-005, story-006, story-008, story-010, story-011); doc/project/60-solutions/CAPABILITY-MATRIX.md provides coarse implementation status; each document text is used as fallback when no capability row exists. part of MVP tracks the hard-MVP story set plus explicitly promoted release-blocking proposals/contracts, and is treated as a release-blocker flag: a row with part of MVP = true must be ready before the hard-MVP release can be called closed. MVP ready may still be true for a post-hard-MVP document when its own MVP slice is implemented. readiness % is a document-level engineering estimate over contract clarity, implementation evidence, test coverage, and remaining risk; it is not computed mechanically from the number of capability rows and is not a release-signoff fact.
Hard-MVP release-blocking stories:
story-000story-002story-005story-006story-008story-010story-011
Hard-MVP release-blocking proposals/contracts:
proposal-048/ Sensorium OS action-class runtimeproposal-073/ node-local Agent organproposal-076/federation-root.v1proposal-081/ horizontal causal, replication, and scoped-nym-proof primitivesproposal-082/ Sensorium Interfacesproposal-083/ Sensorium Interactive Interfaces
Change basis: this refresh incorporates the current worktree state on 2026-07-21. It retains the previously recorded hard-MVP and federation-root slices and adds the latest P063/P064/P066 closure: live provider-backed image generation/edit, durable evaluation-gated train.adapt, bounded repair and output-rail diagnostics, egress-class limits, shared participant-id and monotonicity primitives, explicit local-model provisioning UX, typed communication-control admission including native adapter-envelope mapping, session-memory projection, locale framing, deterministic embedding cache, Inquiry Flow compilation, and their synchronized Node ledger, proposal trackers, and tests. It also includes the explicit Assistant Channel to Agent escalation, recovery, outcome-draft, and render-only acceptance slice tracked by Solution 045, plus the post-MVP Room-attested Corpus-chair binding, inert Corpus answer-draft acceptance, bounded node-local WSS deliberation with metadata-only authority observations and restart recovery, separately authorized signed Agent-chair answer publication, and registered local-policy evaluation of role assignments and policy-rendered instruction overlays through Inquirium host prompt assembly, with append-only delta recovery, tracked by P069/P073 and Solutions 036/038. P070 Phase 6A provides authority-signed member-visible relay epochs, outbound-only failover, host configuration and diagnostics, Agora plus Artifact Delivery endpoint recovery, and executable host-TLS deployment evidence. Phase 6B adds the non-member federation relay profile with signed pairwise sender-key distribution, authenticated encrypted delivery, join/leave/revoke rotation and fencing, metadata-only relay diagnostics and audit, strictly newer sealed-relay failover, and executable 21-check multiprocess host-TLS deployment evidence. P070 is therefore complete for both specified relay profiles; the hard-MVP verdict is unchanged because Phase 6B is post-MVP scope.
The 2026-07-20 P071 refresh freezes the process-isolated Sensorium Virt design
without counting documentation as runtime readiness. Backend selection is now
property-based and host-attested; VMM lifecycle and guest Workbench mechanics are
separate ports; vfkit on Apple Silicon is the first implementation slice; Cloud
Hypervisor is the first Linux deployment profile; and Firecracker is the subsequent
minimal-device profile. The contract freeze also covers closed semantic vocabularies,
plan-bound operational context and policy floors, digest-proven logical image
equivalence, and classified control-sequence-safe serial diagnostics. The five
backend-neutral contracts, closed host request envelope, pure Rust validator/
companion, and first host-broker slice now exist. Both host entry paths use the
Node schema-gate, the core covers research and live-hardware-VM recovery identity,
Workbench rejects backend substitution, and reconciliation diagnostics are
structured, opaque, and capped. The standalone companion is disabled by default,
requires explicit literal-boolean local development/conformance opt-in, and is
never an automatic fallback from supervised daemon admission; missing capability
dimensions refuse;
fixture-copy.v1 exercises their admission, recovery, quarantine, supersession,
projection, and teardown path. The daemon-owned vfkit-system.v1 host-lifecycle
slice now adds digest-pinned profile admission, private APFS-disk/EFI/socket
allocation, closed-argv process launch, exact PID/start-marker, socket-inode,
resource and CSPRNG boot-nonce identity, cooperative drain, teardown, recovery,
reconciliation, and quarantine. It now commits a durable launch intent before
process creation, fsyncs cloned boot artifacts, restricts disabled profiles to
teardown/reconcile, and uses a typed fixed vfkit API operation set. The socket
root is opened without following symlinks, pinned by descriptor identity, and
rechecked before use. A feature-gated 18-test
process harness covers process identity persisted before socket readiness,
interrupted-launch recovery, dead listeners, replay, dirty exit, missing storage,
fresh boot nonces, generation supersession, PID reuse, binary and socket
substitution, socket-root replacement, and orphan cleanup without claiming Apple
Virtualization Framework or guest evidence.
P071 and Solution 042 remain at 98%. The nonce/generation/plan/image-bound guest
agent and host channel have the explicit states protocol implemented and
real-binary local conformance proven: admission is typed, process output has one
total budget, PTY resize is ioctl-backed, patch staging is atomically durable and
content-bound, endpoint identity is rechecked, and deadline/boundary/disconnect
cases are covered. Deployment evidence pending remains distinct: a pinned
full-system vfkit image/deployment, platform resource evidence, and virtualized
Workbench PTY/file integration remain open.
The 2026-07-16 refresh additionally closes Proposal 082 and promotes Solution
046. Sensorium Interfaces now has the pure pull-batch core, eight schemas,
classification and Passport bindings, durable host lifecycle, Sensorium and
Workbench source adapters, signed direct-peer reads, loopback SSE, and the WSS
Room latest-state projection with current dual-authority checks. It is now a
hard-MVP release-blocking component whose own MVP slice is ready. Its promotion
therefore adds no unresolved P082 work. Subscription reads serialize only per lease,
Passport admission is atomic, direct-peer target binding is explicit, and active
Room projection pumps are capped at 64. The follow-up hardening rejects bare
grantee ids, intersects Room authority only by canonical stable subject key,
separates SSE and Room causal traces, distinguishes revoked Passport replay,
checks tier-vocabulary drift in CI, and adds a negative frame fixture.
The latest post-MVP extension replaces the closed source enum with a generic,
bounded adapter registry, migrates all existing Sensorium and Workbench sources,
adds an admitted Artifact Delivery pointer snapshot source, and exposes process-local
operator read metrics with bounded source/carrier/delivery-kind dimensions, flat
revoke-commit timing, and isolated source-registry, active-subscription,
metric-accumulator, and Room partial-failure reporting. Daemon startup now requires
all four built-in observation adapters, while the exact-name, fail-fast conformance
runner uses separate build/test timeouts and retains bounded host load, signed
direct-peer reads, SSE revocation, and Room projection revocation beside the new
actuation verticals.
These additions improve extensibility and evidence
collection without changing the component's 100 readiness estimate. P082 is now
listed as a hard-MVP blocker whose implementation gate is already satisfied.
The 2026-07-17 Agent review promotes Proposal 073 to Solution 047 and makes the node-local Agent organ an explicit hard-MVP release blocker. Its complete tracker, stratified core/host crates, durable recovery, bounded controller, effect-admission boundary, lease reconciliation, and dirty-restart process smokes satisfy that gate now. Cross-node or federated Agent execution remains a separate future proposal and does not weaken the node-local hard-MVP contract.
The 2026-07-19 Story 012 follow-up completes the composed acceptance profile
without changing the hard-MVP blocker set or the 100 readiness estimates for
P073, P082, and Solutions 046/047. agent-core owns
only a substrate-neutral observation need, static binding, and prompt-free
evidence contract. A positive dependency allowlist names pure inquirium-core
DTOs as the sole vertical exception and rejects Room, Corpus, Memarium,
Sensorium, Workbench, and other source/effect-domain coupling. Operator-authored
JSON-e Flow configuration imports the Agent-owned hard caps and may predeclare bounded
need-to-source wiring, while rendered data can only select or narrow it. After
caller-capability and ownership checks, binding admission resolves every exact
source/schema pair before persistence and refuses absent, incompatible, or
ambiguous registrations. Room
relays a resource-bound sensorium-interface-read-result.v1 containing one
inline cursor-free snapshot. The destination daemon resolves the opaque source
through its Room/Sensorium adapter, keeps a bounded process-local latest-state
inbox, exposes it to Interaction Broker only under a typed Agent-host principal
and exact resource
context, and admits one schema-, authority-, classification-, freshness-, and
byte-bounded observation into one Agent Inquirium passage. Durable Agent evidence
preserves the exact-schema/version-validated source P081 causal/context plus
generic source-version/resolution refs and is pinned to the enclosing Agent,
binding, and passage, while broker and Agent records retain no raw
observation payload. A conflicting digest at one relay epoch/sequence is refused
with a payload-free structured diagnostic without overwriting current state;
restart drops ephemeral content. The executable Story 012 runner reuses the
extracted Story 011 three-node federation/bootstrap lifecycle and proves a
failing chair terminal, distinct B/C observations and HIL deliberation, local
observer revocation and relay-audience convergence before repair, dirty restart
of recipient B, local repair, newer passing source-version and content-digest
evidence for B while C remains refused, and an unpublished Corpus draft. The
shared runner now binds A/B/C to distinct loopback addresses with exact peer TLS
IP identities. This is multi-address single-host evidence, not a claim of
multi-host deployment or public relay reachability, so readiness percentages do
not change. A separately selected single-address profile enables unattended
port-isolated smoke runs without privileged alias setup, but is recorded as
weaker evidence and likewise changes no readiness percentage. The closed
17-entry refusal matrix assigns every claim either to this composed process
runner or to its named P070/P082/P083 lower-stratum evidence suite. Story 012 is
therefore ready at 100%; P070 retains separate ownership of external host-TLS
relay deployment evidence.
The completed operational-impact extension does not change those hard-MVP scores.
P082-021 and P083-014 own the shared publication and interactive-resource contract,
including the 512-byte summary cap, source-generation/current-publication freshness
predicate, and audited immutable replacement; P071 pins it to exact Workbench
environments; P073 and P064 propagate only opaque evidence into a host-owned
pre-inference caution layer; and P069 adds the three-participant Story 012 proof.
The composed runner now verifies equal B/C source-owned qualifiers, an immutable
monotone test -> production replacement, refusal of the superseded static binding,
admission of the replacement under a new exact binding, continued C revocation, and
an unpublished draft. Lower-stratum tests cover generation drift,
malformed/oversized context, Workbench process generations, multi-feed caution
maxima, and non-droppable production/critical framing. These rows remain post-MVP
hardening and add no new authority or freshness TTL.
The 2026-07-18 operational hardening keeps that 100 readiness verdict and
strengthens its release evidence. The host now exposes an operator-only,
metadata-only paginated Agent list, fixed-cardinality diagnostics with stable
reason codes, and inspect-first maintenance whose cursor and batch bound policy
reconciliation, canonical expiry reaping, and terminal lease cleanup to one
exclusive Agent page. Its dry-run projects the same bounded plan that execute
applies, without mutating runtime state. A standalone acceptance pack drives
deterministic local Inquirium, HIL effect admission, terminal outcome, operator
projections, and SIGKILL recovery through authenticated HTTP. Deterministic
fact-bundle failpoints and a 1000-session restart soak additionally prove repair
and absence of live controller, effect-owner, HIL-routing, and pending-effect
index residue.
Proposal 083 is now a satisfied hard-MVP release blocker. P083-002 through P083-011
implement the shared directional resource, exact Passport scope, pure coordinator,
durable shared/exclusive state, adapters, direct-peer admission, and Workbench terminal
bridge. The Node also owns a bounded process-local Room collaboration registry and
strict manage actions. Collaborative status/control/
invoke derives the canonical caller and current actuate membership atomically from
one live Room transport snapshot, then reuses exact interface grants, grouped
methods, generation, lease, epoch, sequence, and host policy. Observation remains
separately authorized and raw terminal input is never Room content. The expanded
runner passes 19 exact Rust checks plus the
Workbench actuation and PTY story tests, including saturation, expiry/renewal,
handoff, stale epoch, restart, partial failure, observer-only denial, and two real PTY
controllers. P083-012 records the clean final authority and correctness review and
promotes this actuation boundary into Solution 046. P083 and Solution 046 are therefore
estimated at 100% and ready for hard MVP; completed post-MVP P083-013 relay work does
not reopen that verdict.
The Room collaboration boundary additionally mints 256-bit CSPRNG session bearers that never enter live frames, acknowledgements, fan-out, durable Room facts, shared Corpus observations, or collaboration-group state. Group withdrawal releases capacity immediately; closed or terminal Rooms are reaped at the next bounded group boundary, while one member-session disconnect correctly leaves the Room-scoped group available to other current members. This hardening changes no readiness percentage.
The same closure is now hardened with a uniform 32 MiB pre-read image-source
limit, a 96 MiB decoded adapted-model artifact cap, operation-kind/status-scoped
paged training recovery, recursive provider-usage aggregation, and full
classification no-broadening checks for crisis-candidate projection. These are
contract and recovery hardening changes; P063, P064, and P066 are now at 100
for their tracked implementation slices.
The P064 prompt-assembly policy slice remains tracked as done: support for a
future text-generative operation will receive a separate work item only when the
operation exists. Its previously additive communication-dialect, session-memory,
deterministic-cache, Flow-IR, and locale-policy slices now have bounded contracts
and host implementations, without moving plan execution or summary production
into Inquirium.
The Inquirium refresh in this snapshot additionally includes executable
classify/rerank verticals, provider-native structured output under host
validation, prompt-epoch promotion gating, baseline profile rendering,
host-derived context-grant binding, complete local context resolvers,
operator-question cancel/supersede, and transcript blob/projection/feedback
durability. The latest closure adds a live provider-backed image path, the
durable bounded train.adapt execution/evaluation/publication worker, bounded
structured-output repair and rail diagnostics, egress-class ceilings, shared
participant-id and monotonicity primitives, and explicit local-model
diagnosis/provisioning commands.
Post-MVP local-model productization now also has six accepted package/lifecycle
contracts, a dedicated content-addressed asset store, and an effectful host-side
package lifecycle. Control metadata stays
under data-dir; bulk bytes resolve from explicit configuration, then
ORBIPLEX_MODEL_ROOT, then the data-dir default. Marker/registry identity and
exclusive locking enforce one owner and writer. Managed authority is separated
from mutable engine/workspace interoperability, native files require verified
import, host-registered runtime layouts project only allowlisted child
environment, layout preparation checks containment before creating children,
launch materializations are re-verified, failed publication is rolled back or
discarded, and recovery detects same-size digest corruption. Journaled root
migration recovers both pre- and post-commit crashes without creating two active
roots and refuses symlinked provisional authority trees. Deterministic planning
still fixes effects/executed to false; a separate authority/lifecycle stratum
now verifies signed source trust and operator endorsement projections, streams
bounded local or HTTPS bytes into staging, journals and recovers installs, and
implements verified receipts, generation-guarded activation, rollback, status,
removal, and a baseline release gate enforced inside each journaled activation
or rollback transition. Competing workers are serialized by durable attempt
leases, one-shot source trust is committed only after the claim exists, rollback
binds the observed generation and exact target, and incomplete install/removal
cleanup remains visible and recoverable. A golden operator-endorsed reference
manifest pins a roughly 1.7 GB Bielik GGUF below the 5 GiB test ceiling without
silently downloading it; Python and Rust also share a Unicode/nested JCS parity
fixture. HTTPS package fetch requires exclusively public DNS results, pins the
resolved set per request against rebinding, and applies both total and rolling
transfer-progress bounds. Activation re-verifies referenced CAS bytes instead
of trusting receipt history alone. Daemon operator-question/signer wiring, real TLS
redirect acceptance, distributor-signed llama-server releases, package-to-
supervisor activation on macOS/Linux, and operator recovery rebind after
root/control-plane loss remain open. These items are explicitly outside the P066
hard-MVP denominator, so the Inquirium readiness percentages do not change.
The current Inquirium closure also adds archive-before-prune context-grant revocation and bounded scheduler maintenance, non-empty participant projection rebuild from validated Memarium facts, resolved retention admission, exact participant/feedback-bound revocable training grants, atomic baseline profile activation, registered notification widgets with server-side answer validation, host-owned mode/class escalation policy, complete assembled-prompt token accounting, and explicit fail-closed SQLite schema migration checks.
The latest P063/P064/P066 closure adds forward-only host-keyed assistant trace
references, automatic sustained-degradation and boundary-risk escalation,
metadata-only crisis candidates, provider-backed OpenAI embeddings, supervised
OpenAI/Anthropic lifecycle coverage, explicit remote model-acceptance and egress
acknowledgement, semantic transcript tags, canonical participant-bound
cross-device export/import, content-addressed training dataset manifests with
grant-rechecked local train.adapt admission, and complete bounded
summarize/transform/image contract verticals. Image output remains artifact-only;
the deterministic backend remains the conformance/smoke oracle, while the
supervised provider adapter now supplies a live image generation/edit path under
the same host verification and object-store boundary.
The P081 review closure additionally distinguishes non-canonical causation from
operation-id conflicts, unifies component-domain-separated receipt identifiers
across the four first consumers, strengthens durable nonce concurrency and Room
boundary tests, and bounds Agora proof clock skew. These are hardening changes;
P081 and Solution 043 remain at 100 for the hard-MVP slice, while Inquirium
adoption and signed revocation-snapshot admission remain explicit post-MVP
questions.
The Workbench refresh in this snapshot also includes native non-Workbench
broker providers, explicit artifact handoff, bounded argv-prefix consent and
operator UI, shared sidecar merge, the required Rust actuation bridge, the
managed fixture-copy.v1 Sensorium Virt executor, and host-verified
Agent/Corpus/Room tool-request lineage.
Recent component deltas:
- Proposal 081 / Solution 043 are hard-MVP ready. Canonical causal context and receipt contracts are consumed by Scheduler, Bounded Deferred Operations, Artifact Delivery, Sensorium, and redacted P074 trace adapters. Contact Catalog and Seed Directory consume the bounded replication core with domain-owned trust and merge policy. The durable scoped-claim runtime, Ed25519 nym-certificate adapter, and Agora/Room consumers are implemented with replay, expiry, candidate binding, and stale-revocation refusal. The repeatable 13-check acceptance runner passes and emits a metadata-only trace bundle. Stronger zero-knowledge suites, Agora cross-relay mesh, federated Memarium replication, and universal consumer migration remain explicitly post-MVP.
- Proposal 082 is an explicit hard-MVP release blocker whose observation implementation within Solution 046 is ready. The implementation has one carrier-neutral bounded read-next contract, exact local and Passport authority, revocation/restart coverage, direct-peer, SSE, and WSS Room adapters, and temperature plus collaborative Workbench acceptance tests. Canonical grantee refs prevent cross-kind Room identity collisions, carrier-specific traces preserve diagnostic provenance, and the bounded source registry now includes an admitted Artifact Delivery pointer adapter and fails startup when any built-in adapter is absent. Host-local aggregate read metrics separate delivery kinds, expose revoke transaction commit duration without mislabeling it as enforcement lag, isolate every unavailable operator section, reset explicitly on restart, and pair with the exact-name observation carrier checks in the extended conformance runner and separate build/test timeouts to provide the measurement boundary for future contract revisions. The former provider-push, descriptor-search, and split-management questions are resolved against the current baseline: bounded pull-batch, direct authority-scoped disclosure, and one source-local manage capability remain in force.
- Proposal 083 is an implemented and promoted hard-MVP release blocker.
P083-002 through P083-011 provide the separate
sensorium.interface.invokeauthority, per-method schemas, bounded shared/exclusive coordination, durable fencing and receipts, direct-peer and Workbench adapters, bounded operator/Room grouping with dual authority, and the load/restart/partial-failure/two-controller PTY conformance matrix. P083-012 records the clean final review and formal promotion into Solution 046; runtime readiness is true, and P083-013 now reuses the implemented P070 Phase 6A relay without moving authority into the carrier. - Communication Protocol Baseline is now hard-MVP ready as a historical baseline: Proposal 002 explicitly maps its implemented or superseded areas to the current runtime owners (P014/Solution 000 transport, P056/Solution 024 TLS trust, Seed Directory/Federation Root discovery trust, Capability Registry/Binding admission, AD/INAC payload transport, and Messaging/Room group semantics) and no longer carries independent hard-MVP implementation blockers.
- Proposal 048 / Sensorium OS Action Classes is now hard-MVP ready for the
minimal reference connector runtime:
sensorium-osnormalizes class-aware action catalog entries, reports per-action availability, executes script-backed C1/C2 entries, rejects allowlist-local sensitivity overrides, enforces exact and prefixresult_pointer_fields, blocks C3/C4/C5 under emergency posture without an explicit host-policy exception, and fails closed for unavailable C3-C7 classes until their enforcement envelopes exist. - Proposal 071 / Solution 042 now have the host-owned operator-consent
spine for exact and bounded-prefix Workbench terminal commands: typed request/decision schemas,
daemon persistence and submit/list/detail/revoke/projection APIs, P066-backed
operator questions and durable notifications, Workbench
sensorium-workbench.consent-descriptor.v1, matchingallow-onceadmission,remember-exact-argv, and workspace-boundremember-argv-prefixsidecar projection that refuses to loosen egress, credential, timeout, or output-byte caps. The latest hardening also makes operator-consent read/projection APIs reject module callers, replays duplicate consent requests by semantic request equality, validates Workbench consent descriptor and sidecar entry schemas, and refreshes Workbench sidecar profiles through a bounded TTL. It now also requires activenode-operator-binding.v1authority for consent answers and revocation, gates durable answers through host capability authorization policy, and filters expired entries, inactive operator-binding entries, and capabilities no longer durable-grantable by host policy from the effective sidecar withconsent-expired,consent-operator-binding-inactive, orconsent-capability-not-grantablediagnostics, which the Workbench connector now imports into operator-visible config diagnostics. The same host-owned consent spine now projects granted Sensorium OS action-catalog deltas intosensorium-os.action-catalog-sidecar.v1, materializes the sidecar into the Sensorium OS middleware config tree, publishes binding/delta/sidecar schemas, and the connector loads valid non-overriding deltas into its effective catalog with a bounded TTL/mtime cache. A shared append-only sidecar merge core now owns conflict/provenance semantics, node-ui exposes consent inspection/revocation, andfixture-copy.v1provides the first managed virtual executor without claiming process isolation. - Raw Signal Access is now hard-MVP complete as both proposal and solution:
hook-chain runtime and direct JSON-e-flow dispatch preserve raw context only
in memory, expose it only to declaring executors, strip it from final
envelopes, and now enforce declared raw-signal / component-trace byte limits
by replacing oversized exposures with
sha256:digest metadata. - Bounded Local Server Runtime is now hard-MVP complete: the shared Rust and
Python bounded-server primitives were already migrated across the production
local server surfaces, and the remaining daemon-context overload gap is closed
by a real health-endpoint integration test that forces
max_connections = 1and observes fast HTTP 503 rejection. - Host-Owned Module Store is now hard-MVP complete: the four module-store host capabilities have committed local schema-gate contracts, daemon routes validate raw request and response JSON before and after typed dispatch, and Story-009 verifies supervised module-store writes plus daemon restart/replay through real processes.
- Sealer, Capability Advertisement, and Pseudonym Vault / Key Roles are now
aligned with their component trackers as hard-MVP complete solution slices.
Sealer's hard-MVP
donestatus is backed by the daemon passport-aware dispatch gate, real revocation-view diagnostics, sealer master lifecycle, audit parity, and HTTP dispatch coverage. Capability Advertisement'sdonestatus reflects the registry-backed fail-closed advertisement path, while remaining per-passport ingress verification, lifecycle rebuilds, reusable schema retrieval, and Seed Directory reconciliation are post-MVP hardening. Pseudonym Vault / Key Roles was already markedhard-mvp-donein its solution tracker and caps sidecar; the snapshot now reflects that source of truth. - Proposal 003 and Proposal 011 are now hard-MVP ready for the selected-responder
procurement slice.
question-envelope.v1,procurement-offer.v1, andresponse-envelope.v1are schema-gated at daemon ingress; the host-owned service-order bridge derives full schema-valid question and offer artifacts; selected-responder executions persist transition facts, offers, contracts, responses, receipts, disputes, and settlement-aware closure. The full P003 NATS/JetStream plus Matrix collaborative-room transport remains post-MVP, and P011's broader collaborative/dispute lifecycle remains a later extension. - Proposal 072 is now implemented and promoted to Solution 037 for the hard-MVP scope:
capability-registry.v1is the machine source of truth, formal capability ids are checked for canonical grammar, status, wire-name uniqueness, derived surfaces, and use-specific eligibility, and capability advertisement, passport validation, host capability dispatch/routing, literal control-planePOST /v1/host/capabilities/*routes, and supervised middleware reports fail closed for unregistered or ineligible formal ids.capability-authorization-policy.v1adds the checked P071 Workbench/Interaction Broker authorization-policy sidecar for required grants, caller posture, approval mode, autonomy floor, and COI policy; daemon startup preflight validates both registry and policy, while runtime grant enforcement remains host-policy owned. Federation namespace governance remains a separate post-P072 proposal track. - Proposal 076 / Solution 041 /
federation-root.v1is hard-MVP ready while remaining a release blocker. The contract defines thedata-dir-scoped federation root used to selectfederation_id, bootstrap seed peers, Seed Directory endpoints/trust, sovereign subject refs, and official-service endorsement authority before the node enters the network. Node runtime now has the node-wide federation selector, startup schema-gated loading from explicit data-dir packs, Ed25519 signature verification, participant self-signature checks, org custody-policy evaluation forany-authorized/threshold, key-counted threshold semantics, same-federation data-dir state guards, rollback/digest-swap refusal, a fail-closed default when no explicit root pack exists, and a raw-digest-pinned bundledorbiplex-maindev/demo fixture behind explicitfederation.allow_bundled_fixture_root = true. The hard-MVP slice now also includesfederation-service-endorsement.v1as the sole official-service proof, participant/org verifier core, root-pack endorsement revocations, Seed Directory attach/read/revoke surfaces, own-node endorsement fetch/install cache, capability-advertisement endorsement projection with per-use re-verification, a thin participant-sovereign operator issuance API, offline MVP multisig ceremony tooling for root packs and endorsements, strict rejection of unauthorized excess endorsement signatures, productionorbiplex-mainceremony profile checks for manifest digest/threshold parity, explicit-roster root draft authoring, strict deterministic assembly, org-threshold shape, charter-versionpolicy_ref, at least a 2-of-3 unique signer-key threshold, and rejected signature refusal, optionalseed_directory_bootstrap[].tls_certificate_sha256projection into Seed Directory sources with HTTPS-only runtime enforcement and peer leaf certificate digest verification, and restart-only federation-root activation with specific first-activation/removal/change reload events. The hard-MVP acceptance harness seeders now write explicit signed local root packs and embed signed Seed Directory official-service endorsements for federation-endorsed bootstrap entries, so local Story-005, Story-009, Story-010, and Story-011 profiles exercise the same root-backed authority chain as runtime consumers. Story-011 now also proves the provider side of the projection: its managed smoke creates provider participants during first boot, inserts B/C participant attestation roots with matching self-signatures into the refreshed runtime root, restarts, asserts active/v1/seed-directorytrust for Node B, and only then issues/publishescorpus.providercapability passports. Concrete production roster/keys, final charter adoption and appeal body seating, consumer-specific alliance admission enforcement from Proposal 079, optional remote co-signing/FROST-style threshold protocols, and broader multi-federation matrix polish remain post-MVP governance/testnet follow-ups, not release blockers for the runtime contract. Room/Solution 036 now explicitly groundsfederation-local,cross-federation, andglobalexposure in the active P076federation_idinstead of letting any carrier define federation authority. - Proposal 078 now has its local post-hard-MVP intake spine implemented: the
canonical
weak-signal-finding.v1schema and fixtures are schema-gated at import/export, daemon exposes explicit operator import/list/detail/review endpoints, a dedicated SQLite Harvester review store owns review state, the first filesystem Markdown/text adapter is bounded under the node data-dir, and accepted findings can create local Whisper draft stubs without publishing. Directory-watch automation, network-capable harvesting, public gateway intake, and collector corroboration remain deferred profiles. - Proposal 018 / Solution 040 is no longer a low-coverage placeholder. Code review on
2026-06-22 confirmed schema-gated
participant-capability-limits.v1import/export, durable daemon replay, operator HTTP import/list/detail/clear, hard-block enforcement for the current procurement/response operation set, protected-floor behavior forsignal-marker/sendanddispute/file, procurement ranking penalties throughpriority-factor, and per-participant cooldown throughrate-limit-factor. Follow-up hardening added reasoned clear tombstones, dead/already-expired hard-block import rejection, stalerecorded-atoverwrite rejection, monotoniclast_cleared_atreplay so old records cannot reappear after clear, full participant-id validation on clear, schema-gated list/detail export, bounded local control bodies, runtime soft-factor andreason/refvalidation, and metadata-only operator SSE refresh events for import/clear. P018 is now hard-MVP complete; remaining questions are post-MVP scope expansion and registry/policy refinement. - Artifact Delivery moved from "MVP transport foundation" to hard-MVP complete: Memarium custody target-space policy, profiling counters, metadata-only observers, Matrix mailbox hardening, and
object-store-indirectfetch/rehydrate throughartifact-object-pointer.v1are now documented and implemented. Lower-level zero-copy and Matrix media variants remain post-MVP optimization layers. - Notifications now have a local durable MVP foundation promoted to Solution 039: schema-gated
notification.create, temporal SQLite event log, derived queue projection, JSONL audit mirror, SSE state ping, operator UI, legacynotify_emitadapter, first daemon-owned actions, profile-aware manifests, and destructive temporal compaction for local notification history. They remain partial because pod-user UX, OS notifications, and cross-node aggregation are later layers. - Node UI security readiness advanced: Solution 001 now documents and implements physically separate public/user/pod-user/operator router strata, participant-session enforcement for user-mode routes, header-first reflective CSRF without the legacy CSRF header alias, local user-action audit JSONL,
security-audit.v1.sqlitequery projection with 90-day retention,/admin/audit/user-actions, and optional best-effort Memariumuser-action.v1mirroring. Proposal 052 now carries the same audit/redaction/retention contract for the Tauri-hosted shell. Node UI remains partial because richer desktop settings writes, external preview isolation, pod-user auth, and native integration hardening are still later product/runtime layers. - Contact Catalog hard-MVP is tracker-complete: Proposal 058 and Solution 025 now report the implemented route-set
contact-claim.v1/contact-lookup-result.v1runtime, supervised service, local contact recovery, tombstone/revocation replay, PSI/blinded lookup, provider sync, provider trust controls, and contact-control-vs-identity wording as done for the hard-MVP slice. - Messaging hard-MVP is tracker-complete: Proposal 060 and Solution 027 now report supervised messaging runtime, daemon-mediated contactability provider discovery/challenge/redeem, Contact Catalog lookup/contact-request handoff, classification-bearing private-direct AD/INAC delivery,
messaging.flag.v1read/unread replay, recorded-message lineage plus best-effort encrypted Agora Vault storage, Node UI controls, user-mode wizard readiness for pseudonymous-only or public-handle-draft messaging setup, and Story 010 strictad-smokeas done for the hard-MVP slice. Latest hardening adds EML body/profile recovery, route-key normalization, mark-read routing fixes, readiness/routing retry gates, SSE mutation guards, and conversation diagnostics. Production privacy/federation expansion, receive-passport restoration matrices beyond the current sealed local recovery path, Maildir body encryption, richer per-recipient vault key wrapping, HTML rendering, group messaging, and live multi-device push remain post-MVP work. - Inquirium is now promoted to Solution 044 as an MVP-capable bounded-inquiry
organ rather than only a runtime substrate. The Assistant Channel is promoted
separately to Solution 045 as the human-facing interaction surface over that
organ, while Proposal 064 remains their shared implementation recommendations.
The solution has a first
generatevertical throughinquirium-core, daemoninquirium.generate, JSON-e Flow ingress/preflight, NSE runtime selection, deterministic stub runtime, classification-aware request validation, metadata-only trace records, direct embedding, report-backed conformance, and the direct data-plane lease/batch-embed pilot for lease-backed work.inquirium.classifyandinquirium.reranknow continue from bounded pair-validated contracts through inference-granted host capabilities, runtime/model-binding selection, deterministic and local HTTP/simulator execution, shared budgets, host-keyed metadata-only traces, and conformance fixtures. The same bounded host boundary now exposes summarize/transform through generate lowering and image generate/edit through explicit image candidates, operation-bound leases, verified artifact intents, a uniform 32 MiB source-media cap, and artifact-only responses. Proposal 064's core runtime-adapter foundation is implemented across model-runtime catalog v0.2, runtime-candidate routing, HTTP/stdio adapters, remote provider adapters, embedding contracts, durable lease APIs, deferredbatch.embed, verified artifact descriptors, signed adapter manifests, conformance report storage/runner, host-owned prompt assembly (PromptAssemblyPolicy, daemoninquirium.prompt_assemblyHostRoot/Organ/Operation sourcechain with default fixed non-empty host-root boundary plus coarse temporal context layer, real bounded hostcontent/refmaterialization, config-load validation for generate candidate sourcechains and base prompt refs, scoped adjustments for profile/model-binding/ adapter-instance, manifest-declared instruction roles, pure assembler,inquirium-hostadapter request planning, NFC-normalized canonical instruction hash, caller boundary count, content-source trace, fail-closed tests), and the first output-boundary foundation (output_contract.schema/ref, host-owned output schema registry with a narrow JSON Schema subset, structured JSON shape limits enforced without materializing oversized serialized buffers, at most two policy-admitted metadata-only repair attempts, adapter structured-I/O declarations,GenerateOutputEnvelopewith bounded params/control, typed unsafe output preserving usage/cost accountability, configurable deterministic host I/O rails, safety-critical effective budget diagnostics with typedbudget_exceeded, provider model snapshot/effective sampling trace, redacted output-projection traces carrying schema digest plus violation codes/counts, deterministic-stub/simulator structured happy paths, and host-capped assistant output, plus theinquirium-hoststratum for generate budget/prompt/adapter request planning, reusable Inquirium config types/defaults, output-schema normalization, embed admission predicates, bounded duplicate-free batch source lease refs, symlink-hardened file leases with capped metadata, assistant output/transcript-fact planning, table-driven daemon dispatch forinquirium.*host capabilities, typed returned-value effect intent DTOs, daemon effect-intent interpretation for trace, assistant transcript writes, durable generate/embed/assistant budget-charge records with idempotent replay protection, scoped per-principal/per-session/per-operation/per-agent budget preflight and final-charge enforcement, and shared daemon artifact-output intent execution). OpenAI and Anthropic adapters now compile the admitted schema subset into provider-native structured-output requests; native selection intersects adapter and selected runtime/model declarations, and host schema/rail checks still run. OpenAI direct embeddings use the same supervised adapter and runtime/model-binding policy boundary. Full schema ecosystem features such as dynamic refs/recursion/combinators/grammar artifact caching, richer optional evaluator critics, and provider packaging remain open. Deterministic embedding caching and pure CandidatePlan-to-Inquiry-Flow compilation are implemented; durable plan execution remains correctly owned by Agent and other effect strata. The current host boundary already has schema-owned string redaction, bounded multi-violation diagnostics, explicit egress-class limits, complete repair-attempt accounting, live image execution, and a durable evaluation-gated training worker. Solution 045 has a local-only assistant turn capability, host-capped assistant output, principal-scoped transcript fallback with local-control excision markers, Memarium-backed transcript fact attempts with local fallback/read-index, idempotent turn replay, metadata-only assistant trace/feed, direct local OpenAI-compatible baseline assistant target coverage with a validated operator override, profile-scoped baseline-assistant conformance/freshness gating with deployment-controlledhost-class/...scope, local-transport allowlisting, 16 KiB host-visible output-cap assertion, and schema-gated candidate-requirement diagnostics, hard-MVP readiness gating throughinquirium.baseline_assistant_required, operator-visibleinquirium.baseline-assistantstatus withregistry-errorand stable failure reason projection,run-conformancebootstrap paths, render-only Node UI affordance under/admin/inquirium/assistant, a durable participant/session/source-bound context grant registry, host-owned operator-inline/Relationship/Memarium/ Query/Messaging/Artifact/Dataset resolvers with classification ceilings and exact egress-ack binding, operator-question widget registry/projection contracts plus a bounded durable daemon registry withexpires/at, conservativedefault/on-timeout, lazy/recovery timeout sweeps, fail-closed late-answer handling, and notification/action expiry projection, source-component-scoped notification ids, and idempotent notification-store projection path, explicit cancel/supersede transitions with paired notification closure, digest/size-verified transcript object descriptors and replay hydration, participant-scoped text/tag projection with semantic tags, canonical participant-bound transcript bundle export/import, inquiry-feedback persistence, mode-keyed rigor policy, the shared ordered-axis resolver/monotonicity helper, and the canonical sharedparticipant:did:key:validator. The baseline profile renderer emits loopback Ollama or managed digest-pinnedllama-serveroperator config without an extra proxy and provides explicit doctor/pull/status/deactivate operations. Automatic sustained-loss/boundary-risk notification projection, metadata-only crisis candidates, remote model acceptance/egress acknowledgement, content-addressed training manifests, and grant-rechecked localtrain.adaptadmission and execution are implemented; training recovery is operation-kind/status scoped and paged, cancellation is compare-and-set, and decoded model artifacts are capped at 96 MiB. Solution 044's bounded organ, P064's tracked implementation recommendations, and Solution 045's assistant channel are MVP-ready. Richer schema/evaluator profiles, provider-binary packaging, optional scheduler-owned timeout surfacing, and Agent-owned effect governance remain additive later work rather than incomplete P064 tracker items. - Proposal 073, promoted to Solution 047, defines Agent as the bounded stateful orchestration organ above Inquirium. Its node-local FlowNode and Assistant Channel scopes are complete:
agent-coreowns substrate-free lifecycle, fork, step, memory, binding, outcome, Assistant escalation/acceptance, and effect contracts;agent-hostowns pure step decisions, operator-profile admission, and the closed table-driven Sensorium/Artifact Delivery effect-policy registry; and the daemon exposes lifecycle, proposal, binding, bounded controller-run, Assistant escalation/draft-acceptance, and contextual effect-dispatch capabilities. Local control is administrative authority, while module calls require explicit bounded JSON-e Flowagent_grants, Agent ownership, and target-capability allowlists. Memarium Personal facts remain the source of truth; startup performs bounded replay, partial-bundle and interrupted-outcome repair, immutable admission-snapshot recovery, current-policy quarantine cascading through descendants, and terminal/expired-owner lease reconciliation. Assistant approval is durably recorded before Agent/binding authority, uses the durable operator-question record as typed authority, rejects unapproved bindings during replay, and idempotently completes interrupted materialization. The binding's narrowed budget and wall-time deadline are effective across controller, Inquirium, lease, fork, reaper, and status paths. The general real HTTP process smoke covers spawn/status/binding/controller/suspend/resume/controller-mediated fork/stop plus durable recovery afterSIGKILL. A second process smoke covers Assistant turn, explicit escalation, pending-question restart, exact replay, approval, denial, timeout, bounded controller execution, content-addressedagent.outcome.v1, and render-only acceptance. Ambient Assistant binding is denied, generated content stays outside status and notifications before acceptance, and acceptance fixes publication authority to false. The active controller executes admitted Inquirium, inert effect-proposal, and child-spawn actions through their owning host strata; Inquirium remains constrained by classification, pinned profile, runtime allowlist, and grants. Effect dispatch consumes transport-independent host plans, persists bounded deferred/completed/failed execution outcomes, avoids target reinvocation on exact replay, and reconciles Deferred Operation Registry terminal state with lease release through a bounded scheduler job. Child reservations reconcile bottom-up, lease acquisition is charged, and old inactive lease details compact to restart-safe audit tombstones after the configurable 30-day default horizon. Summary-producer authority is the intersection of Capability Registry-eligible modules and the host allowlist. The post-MVP Corpus-chair extension is now implemented: signed and fresh Room evidence from the node-local round authority admits one exact query/room/participant binding, and Corpus durably accepts itsagent.outcome.v1as an inert answer draft without publication authority. Corpus room policy, signed invitations, typed control-plane failures, AD-owned transport idempotency, Corpus-owned semantic replay by signedinvite/id, configured remote trust-root verification, bounded live WSS join/readiness/messages, metadata-only authority observations, stable authority bind and subject-sequence recovery, controlled session rejoin, and recipient restart recovery are implemented. A separate local-control Corpus transition validates current quorum, room high-water, chair identity, evidence, output digest, and idempotency before signing and publishing the inert Agent draft; Agent authority remains non-publishing. Federated Room transport and remote Room-authority trust remain later work and do not change the node-local hard-MVP verdict. - The Agent boundary now also makes the horizontal/vertical split executable:
agent-coreowns only generic observation need/binding/evidence and effect proposal values; static JSON-e wiring may select or narrow operator-authored opaque source mappings; and the daemon composition root alone resolves those refs through Room/Sensorium, Workbench, Artifact Delivery, or later domain adapters while enforcing grants, schema, classification, leases, HIL, and quarantine. A positive dependency allowlist names pureinquirium-coreDTOs as the sole vertical exception and rejects Room, Corpus, Memarium, Sensorium, Workbench, and other source/effect-domain coupling inagent-core. JSON-e imports the Agent-owned hard observation caps, and successful observation resolution preserves the validated source P081causal/contextplus prompt-free source-version/ref and resolution/ref in the Agent trace. - The latest post-MVP Agent/Corpus profile is also implemented without changing
the hard-MVP verdict: Story-011 selects B while C remains a competing bidder,
admits B as a Room-attested
collaborative-participantAgent through the Corpus adapter, routes one inertcorpus-reasoning-turn-proposal.v1through HIL-gatedcorpus.room.turn, wakes A's chair Agent through an epoch-bound Interaction Brokerroom-eventwatch, and accepts the chair result only as an unpublished Corpus draft. Process coverage includes altered-evidence denial, metadata-only durable watch replay, dirty restart, stale cursor refusal, exact effect replay, exact Room-scoped module-watch authority, skew-tolerant turn expiry, schema fixtures, and absence of ambient publication. P069, P073, Solution 038, and Story-011 trackers carry the same evidence; readiness percentages remain unchanged because both documents were already at their completed node-local slices. - Story 005 remains hard-MVP complete, and its post-M4 productization tracker now lives in the Whisper implementation note instead of a workspace-root draft file. The closed slice has a CI-runnable Inquirium acceptance bridge: an opt-in supervised simulator adapter is routed only through model-runtime/Inquirium by
runtime/refand host-ownedmodel.binding/ref.whisper-corecarries the production-shaped policy primitives for routing failure mode, source class, outbound privacy resolution, correlation policy explanation, association-room proposal lifecycle, public-gossip promotion, and bounded trace integrity/privacy. The current Node worktree consumes those primitives in the publish path:whisper-intakeperforms outbound privacy preflight before public/private signal publication and now implementswhisper.trace.publishwith exact one-time operator consent for inline disclosure, transient byte validation, and metadata-only read models. Trace authoring atomically reserves idempotency keys, independently bounds inline bytes, extensions, and total JSON, and applies a 30-day default retention sweep to its local read model. Agora enforces public trace topic/disclosure admission and projects traces outside signal thresholding, while AD/INAC admits private traces through the existing signed-envelope carrier. Story-005 asserts the exactagora-publishandinac-directcarriers, proves that private traces stay absent from Agora projection, and retains its private-signal regression guard.agora-projectionsandagora-servicealso provide a minimal local association-room lifecycle seed plus public-gossip promotion drafts from accepted rooms, with authenticated actor binding, bounded lifecycle facts, FK-backed proposal refs, and bounded opaque lineage refs. These move Proposal 013 closer to post-M4 productization while preserving the readiness interpretation for unfinished product/runtime surfaces such as real Anon relay transport, production semantic correlation, full association-room case management on the accepted signed room-event log over Artifact Delivery with multi-Agora fanout/merge, bounded replica retention status, and per-thread predecessor digest links, final public-gossip publication runtime, live Monus/Sensorium source verification, richer room/curation UI, and remote model deployment. - Shared Offer Catalog is now hard-MVP complete. Proposal 067 and Solution 033 document the extracted shared Python offer-catalog runtime, Agora replay, fail-closed Agora/Seed Directory admission, Arca embedded-cache reuse, query parity, withdrawal active filtering, public/shared catalog deployment profile (
node/middleware-modules/offer-catalog/config/profiles/public-shared-catalog.json), automaticshared-offer-catalogpassport publication readiness with classified pending reasons, redacted Host Agora and Seed Directory admission diagnostics, and a local public-profile smoke runner (node/tools/acceptance/shared-offer-catalog-public-smoke.py) covering authorized replay, bad-signature refusal, unknown-provider refusal, withdrawn-offer inspection semantics, and the HTTP query surface. The remaining public-profile operating policy is now resolved and enforced where applicable: passport renewal is supervisor-driven by default, and non-loopback Agora URLs must use HTTPS/TLS with Node fail-closed replay validation. Remaining work is post-MVP production hardening such as broader monitoring matrices and eventual legacy peer-message retirement. - Proposal 080 is complete through P080-020. Bundled factory data now selects
channel_jsonorhttp_local_jsonexplicitly and records whether a product listener remains. Eligible host-only modules project to the shared channel without allocating per-module ports; intentional network and mixed product listeners remain explicit. Agora Verifier and Snooper use the shared Python channel adapter. Operator-installedhttp_local_jsonremains a visible explicit legacy compatibility path, while stale listener keys under channel-only module config fail closed. Story-005 proves host-ownedruntime/refand model-binding invocation over the channel plus stop/non-routable/restart; Story-009 and strict Story-010 also pass. - Corpus and Story 011 are tracked as hard-MVP blockers through Proposal 069 and Solution 038. Its MVP slice is
intentionally narrow: topic taxonomy/resolution, topic-scoped offer discovery,
question-envelope.v1-decorated query broadcast, bid-state aggregation, and a single-provider P011/P016 settlement path. The contract gate is implemented: canonical schemas and examples for topic taxonomy/resolution, query, bid and bid-state; theservice-offer.v1Corpus extension; node schema sync; schema-gate validation including query price-bracket and service-offer topic-subset constrainers; deterministic taxonomy digesting; topic resolution; topic-scoped offer indexing helpers; schema-valid ADcapability-manyquery envelope construction; bid-state projection; bid/query price validation; and single-provider settlement selection over the embeddedprocurement-offer.v1. The latest Node slice adds Dator Corpus offer projection, daemon-owned Corpus round persistence, query/bid registration APIs, provider-side bid acceptor runtime, unique provider-scoped bid ids, real node-identity Ed25519 signatures on generated local bids, exact-plus-parent topic matching, price-bracket rejection without silent offer-price mutation, the selected-offer bridge into the P011 procurement path, ADcapability-manyruntime fan-out over INAC with taxonomy-digest candidate filtering, opt-in provider-side Corpus AD query admission, admitted-bid signature verification bound tobidder/node-id, P057 notifications for bid readiness/requester-satisfied/settlement failure, operator-visiblesettlement-failedrecovery state for bridge failures after selection, operator visibility under/admin/corpus/rounds, and passing Story-011 acceptance coverage under full Seed Directorysovereign-policycapability lookup backed by a refreshed signed federation root. The current slice also addscorpus-reasoning-answer.v1as a validated, digest-bound final answer artifact that can be attached to the requester-owned round read model after provider-localinquirium.generatedrafting; answer admission now uses ordinary Artifact Delivery with an in-processcorpus.answeracceptor, tier-correct answer classification propagation, provider signature verification, selected-bid binding, policy-digest binding, and append-only federation metadata throughsupersedesplus optionalrevision/nowhile local snapshots remain latest read-models. The remaining hard-MVP closure is now covered as well: P069 specifies theorbiplex-canonical-json-jcs-v1profile for Corpus signatures/idempotency, and the Shared Offer Catalog exposes a path-first Corpus topic-index query surface with bounded pagination, HATEOAS-style navigation links, invalid-digest refusal, and partial-withdrawal supersession tests. P069 is now hard-MVP ready for the procurement slice. The post-MVP node-local live layer now connects admitted participants to a bounded WSS Room carrier, propagates metadata-only join/readiness/message observations to the authority, suppresses exact replay redelivery, and recovers stable authority binding plus subject/session sequence across authority and recipient restarts through fixed-high-water paged recovery and checkpoint validation at append and restore boundaries. The requester-appointed Agent-chair path also has a separate local-control transition that signs and publishes only after current quorum, room-high-water, chair, evidence, output-digest, and idempotency validation; the first profile is text-only and uses the dedicatedcorpus-reasoning-answer-signature.v1domain. Remaining post-MVP work includes remote Room-authority trust, arbiter election, multi-provider final answer composition, and N-way settlement. Matrix is an optional bridge profile rather than a Corpus or Room liveness dependency; Sensorium Interface views are already available over the Room relay slice. - Room primitive is now tracked explicitly through Proposal 070 and Solution 036. The current code
implements the durable Room skeleton, deterministic projection over Agora facts,
signer-backed short-lived membership attestations, explicit POST attestation request
contracts, no-disclosure request modes, per-exposure TTL caps, rate-limit/dedup,
metadata-only attestation audit, bounded Room contract validation, golden projection
vectors, authenticated Agora query surfaces, schema-gate import/export helpers,
room-scoped live authorization, host-owned Room lifecycle service, bounded WebSocket
pub/sub live carrier, Matrix live carrier with cleanup redaction, and compatibility
consolidation for answer-room/association-room projections. The latest hardening
makes the attestation endpoint skew-tolerant for authorization expiry, rejects
over-cap TTL instead of silently clamping it, scopes rate-limit buckets by room, and
records audit facts with
exposure,ttl/requested, andttl/grantedwhile schema tests reject raw payload and passport bodies. P070 is complete for its hard-MVP standalone Room foundation, including the node-local live plane required by Corpus. Phase 6A now closes the member-visible production federation delta: one authority-signed relocatable WSS endpoint per relay epoch, one ephemeral total order per epoch, failover through Agora/AD without cross-epoch merge, outbound-TLS operation, keepalive/reconnect, and relay-carried P082/P083 classes. The follow-up POSIX deployment-evidence profile now proves the host-owned TLS seam with separate relay, publisher, and observer processes, per-config crypto-provider binding, terminator-owned task cleanup, bounded cursor-expiry refresh, exact reconnect accounting, metadata-only dirty restart, graceful checkpoint persistence, newer-epoch failover, active revocation, payload-digest refusal, and session-bearer omission from relay deliveries and retained evidence. Phase 6B now closes the remaining specified relay profile with recipient-private signed sender-key packages, sender-authenticated encrypted frames, monotonic membership-high-water rotation, stale-ciphertext refusal, delayed receiver checkpoint commit, explicit member-visible versus sealed wire discriminators, schema-ref registry coherence, sealed reconnect, a bounded metadata-only relay audit, and a 21-check multiprocess host-TLS acceptance report with closed evidence shapes covering leave rotation and sealed-profile failover. P070 is therefore at100%and post-MVP ready for its declared Room scope. This changes neither the hard-MVP readiness verdict nor Matrix's status as an optional bridge profile. - Sensorium Workbench is now tracked through Proposal 071 and promoted to
Solution 042 as a post-MVP actuator foundation. The opt-in supervised Python
connector now has a complete local foundation: allowlisted workspaces,
bounded file and artifact operations, PTY lifecycle, artifact-backed patching,
waits/probes/watches, replay/recovery, metadata-only audit, and explicit
operator controls. Path and command-profile admission crosses the required
bounded
sensorium-actuation.bridge.{request,response}.v1companion-process boundary into the Rustsensorium-actuation-core; unavailable or malformed bridge behavior fails closed without a Python validation fallback. The daemon-owned Interaction Broker enforces grant-context admission, persistence, recovery, retention, provider health, Workbench file/terminal adapters, dynamic providers, and native Artifact Delivery, approval/consent, and Memarium-query adapters. Verified Workbench artifacts can be handed off explicitly to Artifact Delivery resolution and/or metadata-only Memarium provenance, with replay bound to the originalcorrelation/id. Consent supports allow-once, exact argv, and bounded workspace-bound argv prefixes through shared append-only sidecar merge; node-ui provides consent revoke and broker remediation screens. The managedfixture-copy.v1Sensorium Virt executor copies a bounded symlink-free tree, permits approved writes only in the copy, exports a bounded artifact, persists lifecycle, and tears down only its managed root while refusing PTY without process isolation. Agent, Corpus, and the current execution-derived answer-room tool requests now use a schema-backed host lineage wrapper aroundsensorium.directive.invoke, so no product receives direct Workbench connector authority. Proposal 071 remains outside hard MVP. Its process-isolated Phase 4 architecture is now frozen: suitability is matched from host-attested properties rather than backend names; VMM lifecycle and guest mechanics are separate ports; Rust and the daemon own validation and host launch/recovery authority; the Python connector owns bounded adapter mechanics;vfkit-system.v1onmacos-vz-arm64.v1is the first implementation slice; Cloud Hypervisor is the first Linux deployment profile; and Firecracker follows after the image manifest and guest protocol stabilize. The frozen contracts additionally require closed versioned capability values, a normalized-plan-bound P082 operational context with conservative network/host-share floors, digest-proven logical image equivalence, and classified control-sequence-safe serial diagnostics. The required capability/plan/image/ recovery/guest-frame contracts, closed host request envelope, pure validator, bounded companion, and first daemon host-broker fixture slice are implemented. Schema-gate covers the host boundary and all five contract families; Workbench refuses backend substitution and recovery diagnostics are structured and capped. The fixture path remains covered by a dirty-restart vertical smoke. Supervised Workbench uses the restricted non-passportablesensorium.virt.hostchannel capability; the companion is disabled by default, requires explicit literal-boolean local development/conformance opt-in, and is never a fallback when supervised daemon admission is unavailable. Daemon admission rechecks operator-configured source/context/limits, host mutations serialize across processes, and directory enumeration is capped before materialization. The daemon-owned vfkit host lifecycle, exact process/ socket/resource recovery identity, pre-spawn launch intent, fsync-backed boot artifacts, boot nonce, closed launch/API profile, disabled-profile terminal cleanup semantics, descriptor-pinned socket root, and feature-gated 18-case process-level crash/substitution harness are implemented. The nonce/generation/plan/image-bound Rust guest agent and host channel are nowprotocol implementedwith bounded process/PTY/file mechanics, a single aggregate process-output budget, ioctl-backed resize, atomic content-bound patch staging, endpoint identity checks, lifecycle inspect/ quiesce/shutdown, chunked transfers, and honest outcomes. The separateconformance provenstate comes from the real-binary local-transport harness, including admission, deadline, outcome/evidence, boundary, partial-transfer, and lost-receipt cases.Deployment evidence pendingremains explicit: a pinned full-system image, real vfkit deployment and platform-resource evidence, and virtualized Workbench integration are not implemented, so Proposal 071 and Solution 042 remain at98%. Richer command-BDO signal policy is also post-MVP hardening rather than a current blocker. Interaction Broker is implementation-complete for its current provider foundation; provider-pushed events and richer deferred-wait retry policy stay deferred, so the component is not yet marked post-MVP ready. - Local Relationship Layer is now hard-MVP complete for the Node-owned slice: Proposal 065 and Solution 032 have contracts, pure core, vault-first daemon storage, sealed rebuildable SQLite projection, local control/host capabilities, operator class/membership/predicate/decision audit UI, package trust queue with approval history, canonical Messaging consumption, dynamic Artifact Delivery group resolution, repeatable Story-010 relationship acceptance runner with a local CI wrapper, projection replay/privacy regression gates, verified
remote-disclosednode-operator-binding import through the identity control surface, durable revocation invalidation for imported binding evidence, registry-driven pairwise nym context-kind admission, and relationship-class retention profile inheritance. Public federated Local Relationship capability, richer multi-operator UX, hosted CI-provider wiring for the runner, and performance profiling under real relationship cardinalities remain post-MVP work. - Replay Scheduler M1 is now fully closed for the hard-MVP slice: the generic bounded scheduler, durable launch ledger, host-owned job-source merge, authority gate, cooperative shutdown, Agora projection replay action, and operator status/control surface are all documented as implemented. Richer Agora-domain panels and non-Agora maintenance jobs are post-M1 extensions.
- Agora gained a generic encrypted-artifact Vault surface:
agora-vault-entry.v1exposes only opaque artifact ids, kind, ciphertext, and cryptographic envelope metadata; supervised local routes are client-auth / daemon-dispatch gated, while remote provider deployments bind the same operations to the frozenagora-vault@v1passport profile. - Temporal Storage Convention is now hard-MVP complete: notification-store is the full-compaction-required adopter, while messaging outbox and Seed Directory accepted facts are converged bounded/no-op adopters with manifests, temporal status/feed/replay-check, and explicit
compaction.policy = "bounded-noop"diagnostics. - Bounded Deferred Operations were promoted from Proposal 055 to Solution 029 as a horizontal host control-plane component. The MVP slice is complete: shared wire contracts, host registry, poll/cancel surfaces, JSON-e Flow persisted continuation, Sensorium OS deferred state, operator visibility, and AD consumer integration.
- Sensorium has been promoted to Solution 030 as a constitutional organ. Its MVP slice is implemented for
sensorium-coreobservation admission/query, directive invocation, audit-only outcomes, internal connector dispatch, the supervised Sensorium OS reference connector, action-catalog sidecar authorization, and deferred Sensorium actions. Local Agora observation publication remains partial because runtime support currently exposes topic metadata and read surfaces rather than a complete local subscription bus. - Node Address Attestation Fallback is now counted as hard-MVP ready through the Seed Directory / TLS Trust path:
node-address-attestation.v1exists, Seed Directory can issue signed endpoint evidence, daemon consumers import usable evidence, peer supervisor enforces endpoint pins, and TLS leaf/SPKI plus advisory route-id checks are wired. Peer-relayed endpoint evidence over INAC remains a post-MVP fallback extension. - Classification is now counted as hard-MVP ready at proposal and solution level.
classification.v1andorbiplex-node-classificationprovide the common lattice, exact surface/topic/time derivation, revocation-bound declassification, durable one-shot consumption, quarantine vocabulary, and projection-aware bound-subject handling consumed by Memarium, Agora, Whisper, INAC/private Artifact Delivery, Interface, archival export, and adjacent host boundaries. Context-free reads retain source tier instead of leaking a boundary decision into every surface; missing authority fails closed. Whole-program IFC, per-field labels, complete historical backfill, provenance-aware enforcement for every open-world schema, and richer quarantine UI remain post-MVP work. - Proposal 025/Seed Directory capability catalog is now post-MVP complete for its current scope: official-service status rests on
federation-service-endorsement.v1, root-pack endorsement revocations are applied at startup, the unified/revocationsfeed carries{artifact_family, artifact}entries for passport and endorsement revocations, operator/AD endorsement install is scoped and conflict-aware with ingress-enforcedsourceplus optionalsource/detail, participant-sovereign operators can issue non-own official-service endorsements through the daemon API,federation-service-endorsement-revocation.v1has shared schemas/fixtures, andcapability-proof-presentation-batch.v1pluscapability-passport-present.v1can refresh local proof caches through AD with metadata-only presentation facts; outbound batch proof allows must carry explicitmax/bytescapped at 256 KiB. - Proposal 054 is hard-MVP complete:
seed-directory-query-attestation.v1is schema-gated, Seed Directory can attach opt-in signed response attestations, daemon can opt into trusted Agora replay foradv,cap, andrevocationslanes, replay follows paginated Agora result pages, replay cursors/status are persisted in the embedded store, projection equivalence tests include revocation effects, and daemon-owned Seed Directory discovery now applies one strict multi-directory policy (preferred-directory,quorum, orweighted-trust) across host queries, AD/capability routing, subject lookup, and Contact Catalog provider discovery, with cross-directory revocation suppression for revoked capability passports./v1/seed-directoryand Node UI expose safe trusted-directory diagnostics, local endorsement/reputation policy inputs, replay state, and skip reasons. - Memarium Proposal 036 and Solution 002 are implementation-complete for v1: neutral
MemariumObservationbridges post-chain and phase observers without daemon-private runtime dependencies; invalid observe rules fail startup; governed community forget verifies its governance fact; atomic fact idempotency and deterministic system keys make retries converge; the fully paginated scan path and validated SQLite sidecar remain replay-equivalent; quarantine and strict-mode transitions are authorization-first and durable; and archival backup/export applies exact revocation and one-shot authority before atomic bundle publication. Story-005 smoke covers the classification-bearing private AD/INAC boundary. Richer Node UI batch UX and measured sidecar connection/query optimization remain product/performance layers, not Proposal 036 blockers. - Story 000 is now hard-MVP complete: the minimal two-node operator acceptance pack under
node/tools/acceptance/story-000-operator/was hardened to keep all non-story middleware disabled by real module id and itsad-smokepath passes with two local WSS peer sessions, connected peer read models, running peer supervisors, and metadata-only daemon status. - Proposal 014 / Node Transport and Discovery is now counted as hard-MVP ready:
P014, Requirements 006, Solution 000,
node/docs/MVP.md, and the Node implementation ledger were reconciled against the currentprotocol,network,peer-runtime, daemon, and Story 000 acceptance implementation. Federated node-id succession publication/replay, richer federation-wide peer-governor policy, and additional transports remain post-MVP expansion rather than blockers for the transport seed. The local peer-governor slice is now seeded throughpeer-status.v1, daemon-configurable quality thresholds, and operator-visible peer scorecards. The local NT-018 node-succession lifecycle is implemented throughnode-succession.v1, host-derived operator import/accept/reject provenance, successor identity activation, and Story 000rotation-smoke; future successor routing eligibility remains a live local policy-registry resolution rather than a mutation of the accepted fact. The local client-instance recovery read model is now bounded and replay-idempotent, so evicted or unknown detachment references fail closed. - Key Delegation Passports are now hard-MVP complete at solution level: Seed Directory
/keypublication/query surfaces have focused signed-artifact coverage, daemon operator routes already expose proxy-key and delegation lifecycle management, and remaining multi-hop delegation plus richer Node UI screens are explicitly post-MVP/product-layer work. - Middleware is now counted as hard-MVP complete: Solution 019 already covers the implemented host-owned lifecycle, readiness, dispatch, claimed-route, host capability, observer/audit, raw-signal, and schema-presentation surfaces, while additional executor classes or product-specific module UX are future extension points owned by their specific proposals.
- Capability Binding is now counted as hard-MVP complete: the reference runtime uses the shared
capability-bindingorgan through daemon dispatch and Sealer integration, while solution-level service adapters and caches remain optional seams for alternate embeddings or profiled hot paths rather than MVP blockers. - Agora/P035 is now counted as hard-MVP complete: the reference runtime covers the public record relay, content addressing, signing/ingest, query/readback, SSE subscription, Matrix-backed federation, retention, subject indexing, Agora Vault, and Story-008 resource-opinion path. Remaining ingest-policy tightening and hot-path/status-product work stay post-MVP and are listed in Proposal 035's hardening queue.
Stories¶
Proposals¶
Solutions¶
| Document | part of MVP | MVP ready | post-MVP ready | readiness % |
|---|---|---|---|---|
| Orbiplex Node | true |
true |
false |
85 |
| Orbiplex Node UI | true |
false |
false |
88 |
| Orbiplex Memarium | true |
true |
true |
100 |
| Orbiplex Arca | true |
true |
false |
88 |
| Orbiplex Dator | true |
true |
false |
100 |
| Orbiplex Sealer | true |
true |
false |
100 |
| Orbiplex Capability Binding | true |
true |
true |
100 |
| Capability Advertisement | true |
true |
false |
100 |
| Orbiplex Agora | true |
true |
false |
100 |
| Orbiplex Monus | false |
false |
false |
15 |
| Orbiplex Anon | false |
false |
false |
10 |
| Orbiplex Whisper | true |
true |
false |
100 |
| Ferment | false |
false |
false |
15 |
| Raw Signal Access | true |
true |
false |
100 |
| Orbiplex Key Delegation Passports | true |
true |
false |
100 |
| Host-Owned Module Store | true |
true |
false |
100 |
| Bounded Local Server Runtime | true |
true |
false |
100 |
| Inter-Node Artifact Channel (INAC) | true |
true |
false |
88 |
| Classification | true |
true |
false |
100 |
| Middleware | true |
true |
false |
100 |
| Replay Scheduler | true |
true |
false |
100 |
| Agora Authority | false |
false |
false |
77 |
| Orbiplex Semantic Index | false |
false |
false |
15 |
| Artifact Delivery | true |
true |
false |
100 |
| TLS Trust Policy | true |
true |
false |
86 |
| Contact Catalog | true |
true |
false |
100 |
| Pseudonym Vault and Key Roles | true |
true |
false |
100 |
| Messaging Middleware | true |
true |
false |
100 |
| Temporal Storage Convention | false |
true |
false |
100 |
| Bounded Deferred Operations | true |
true |
false |
100 |
| Sensorium | true |
true |
false |
92 |
| Seed Directory | true |
true |
false |
100 |
| Local Relationship Layer | true |
true |
false |
100 |
| Shared Offer Catalog | true |
true |
false |
100 |
| API Surface Projection | false |
true |
true |
100 |
| Interaction Broker | false |
true |
false |
100 |
| Room | true |
true |
true |
100 |
| Capability Registry | true |
true |
false |
100 |
| Corpus | true |
true |
false |
100 |
| Notifications | true |
true |
false |
90 |
| Capability-Limited Restrictions | true |
true |
false |
100 |
| Federation Root and Network Selector | true |
true |
false |
92 |
| Sensorium Workbench | false |
false |
false |
98 |
| Horizontal Protocol Primitives | true |
true |
false |
100 |
| Inquirium | false |
true |
false |
100 |
| Inquirium Assistant Channel | false |
true |
false |
100 |
| Sensorium Interfaces | true |
true |
true |
100 |
| Agent | true |
true |
false |
100 |