From 1d73b294ae33c2d69223db90203e167f0d77521b Mon Sep 17 00:00:00 2001 From: Kevin Kern Date: Tue, 21 Jul 2026 21:15:36 +0200 Subject: [PATCH] docs: retain v0.3.0 release receipts --- docs/planr-hard-cut-handoff.md | 216 ++++++++++-------- docs/prepublish-certification-0.3.0.md | 204 +++++++++++++++++ .../release-ready-v0.3.0/candidate.json | 99 ++++++++ .../certification-report.json | 12 + .../certification-report.json | 94 ++++++++ .../workdir/codex-runtime-evidence.json | 183 +++++++++++++++ .../certification-report.json | 79 +++++++ .../workdir/dispatch-evidence.json | 28 +++ .../workdir/host-output.json | 1 + .../workdir/requested-invocation.json | 16 ++ .../certification-report.json | 79 +++++++ .../workdir/dispatch-evidence.json | 28 +++ .../workdir/host-output.json | 1 + .../workdir/requested-invocation.json | 16 ++ 14 files changed, 965 insertions(+), 91 deletions(-) create mode 100644 docs/prepublish-certification-0.3.0.md create mode 100644 retained-evidence/release-ready-v0.3.0/candidate.json create mode 100644 retained-evidence/release-ready-v0.3.0/live/claude-native/1784654534-22027-0/certification-report.json create mode 100644 retained-evidence/release-ready-v0.3.0/live/codex-openai/1784654270-96976-0/certification-report.json create mode 100644 retained-evidence/release-ready-v0.3.0/live/codex-openai/1784654270-96976-0/workdir/codex-runtime-evidence.json create mode 100644 retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/certification-report.json create mode 100644 retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/workdir/dispatch-evidence.json create mode 100644 retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/workdir/host-output.json create mode 100644 retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/workdir/requested-invocation.json create mode 100644 retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/certification-report.json create mode 100644 retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/workdir/dispatch-evidence.json create mode 100644 retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/workdir/host-output.json create mode 100644 retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/workdir/requested-invocation.json diff --git a/docs/planr-hard-cut-handoff.md b/docs/planr-hard-cut-handoff.md index dadc543..6175054 100644 --- a/docs/planr-hard-cut-handoff.md +++ b/docs/planr-hard-cut-handoff.md @@ -1,79 +1,79 @@ # Planr Hard-Cut Handoff Receipt -Date: 2026-07-19 +Date: 2026-07-21 -This receipt is the Goal A gate for starting the Planr Goal B hard cut. It -does not modify `/Users/kregenrek/projects/planr`; it records the independently +This receipt is the durable Goal A gate for starting the Planr Goal B hard cut. +It does not modify `/Users/kregenrek/projects/planr`; it records the independently published Switchloom release and the exact Planr routing responsibilities that now have a standalone owner or an explicit deletion action. ## Superseding Release Status -The public `v0.2.0` release had a native Codex discovery evidence gap: the -published package generated repository-local Codex role files, yet the accepted -receipt did not prove the checksum-identified installed candidate executed the -full status/uninstall lifecycle while preserving unmanaged repository content. - -The public superseding release is now `v0.2.1`. It replaces `v0.2.0` for the -final Goal A handoff. The canonical retained `0.2.1` candidate proof chain is: - -- `/private/tmp/model-routing-codex-standalone.COTXUA` proves exact `0.2.1` - package-byte execution, repository-local Codex role discovery, authentic Terra - High maker and Sol High reviewer spawns with `fork_turns = none`, and - unchanged global Codex config hash - `18cbbaee5e263f8bb011a174913721a8866a4d156d62c7fc74bc2d7103abcb3c`. -- The canonical `0.2.1` candidate crate hash in that receipt is - `e5c2eee164433f3433f8aef2aca46624d88a46c8b4db502aa63804017b83769e`, and - the installed binary hash is - `7e214789885a66e4788c778fd8d7681c1a67de0aed5f728735ff678c8965049f`. -- The same `0.2.1` installed binary ran `status` and `uninstall` only against - the generated temporary repository. It removed seven Switchloom-managed - artifacts, left `bundle_id: null` with no managed artifacts on post-status, - and preserved the unmanaged sentinel file byte-identically. -- `/private/tmp/model-routing-codex-standalone.yGExSi` remains a `0.2.0` - behavioral precursor only. It is useful for comparing the same proof shape, - but it is not the canonical `0.2.1` release-candidate proof because its crate - and installed binary are `0.2.0`. -- `/Users/kregenrek/projects/planr` remained at protected HEAD - `d7f0afae24643d4a1e475474426c37ca00e5dbe3` with - `git status --porcelain=v1 -z` SHA-256 - `45d1759e7ff4c3f45b15eaf3c331f82186173610427a5e0a38cdd945151d5f33`. - -Do not use the `v0.2.0` publication as the final Goal A handoff. The -superseding public `v0.2.1` bytes are the release gate for Goal B. +The current public hard-cut handoff release is `v0.3.0`. It supersedes the +earlier `v0.2.0`, `v0.2.1`, and `v0.2.2` receipts for Planr Goal B. + +The retained `v0.3.0` proof chain is: + +- PR `#19`, `https://github.com/instructa/switchloom/pull/19`, merged + `2026-07-21T18:25:24Z`. +- Candidate head commit `e936b90c81d8f944ba50657c10ef9a2a564c53c5`. +- Release commit and merge commit + `45c15fed09786c9dee1167744b1c43b87b47d505`. +- Annotated tag `v0.3.0`, tag object + `8306c2533be0cbeb9c6801651cb08d0d244d7678`, peeling to the release commit. +- Release workflow `29857502558` completed successfully for the release commit. +- Main CI after merge passed in run `29857146170`; main Secret Scan passed in + run `29857145475`. +- Public-byte certification retained fresh npm install, Homebrew install, live + website, status, apply, uninstall, and preservation receipts under + `/private/tmp/switchloom-public-v0.3.0-npm-fix.GMEH4n`, + `/private/tmp/switchloom-public-v0.3.0-brew-fix.sA9meG`, and + `/private/tmp/switchloom-public-v0.3.0-website-fix.Ou1eQ0`. +- The protected Planr repository remained at HEAD + `bbc877d40191b2cbb289ed26df5e6fee25e4326d` with + `git status --porcelain=v1 -uall` SHA-256 + `d6c56495c7e2a78aed2e641b0e928bc8a579bf31335db36456a9f05726827927`. +- The authenticated global Codex config hash remained + `eec8236cc13bd729a46376d65624eaf795a70bd48ccee8ac707d904f735aaedd`. + +Do not use earlier publications as the final Goal A handoff. The superseding +public `v0.3.0` bytes are the release gate for Goal B. ## Release Identity - Repository: `https://github.com/instructa/switchloom` - Production website: `https://switchloom.ai` -- Release: `https://github.com/instructa/switchloom/releases/tag/v0.2.1` -- Release workflow: `https://github.com/instructa/switchloom/actions/runs/29682448374` -- Tag: `v0.2.1` -- Commit: `56ce22ad33d7c8d2cf7ff1836639ee27ede36d67` -- Tagged commit subject: - `Merge pull request #11 from instructa/codex/non-destructive-release-0.2.1` -- npm package: `switchloom@0.2.1` -- npm tarball: `https://registry.npmjs.org/switchloom/-/switchloom-0.2.1.tgz` +- Release: `https://github.com/instructa/switchloom/releases/tag/v0.3.0` +- Release workflow: `https://github.com/instructa/switchloom/actions/runs/29857502558` +- Tag: `v0.3.0` +- Release commit: `45c15fed09786c9dee1167744b1c43b87b47d505` +- Candidate commit: `e936b90c81d8f944ba50657c10ef9a2a564c53c5` +- npm package: `switchloom@0.3.0` +- npm tarball: `https://registry.npmjs.org/switchloom/-/switchloom-0.3.0.tgz` - npm integrity: - `sha512-vUKHxYXHt7Sx7MkYQz5MRZ0Ll544iHoadHGCgvJPUYkpUzQWtzjt1o3xhyeQwExCA6tuLQ5vZnLPz+fO5uMiXg==` -- npm shasum: `e813283f54d0d64b5fd4835e17687aaaf3b0a6cb` -- Homebrew formula: `instructa/tap/switchloom`, version `0.2.1` + `sha512-NdEyH1zq+W6E5pZIHdG8oe2CQxVjtjVlvQlvdCMxDEwaroCLzXEMiUMvnd/kjgXGx5A/WYsFxWe/nU7eSNgjzw==` +- npm shasum: `7ccf5c8c693c33f5a83fad47529e630c46c8cf2c` +- npm file count: `20` +- npm unpacked size: `11898450` +- Homebrew formula: `instructa/tap/switchloom`, stable version `0.3.0` +- Homebrew tap HEAD: `2fdec6450d4444febc54fcf7ffe44e7072e59c74` ## Release Artifacts -GitHub release `v0.2.1` is public and non-draft. It contains aggregate -`SHA256SUMS` and four platform archives: +GitHub release `v0.3.0` is public, non-draft, and non-prerelease. It contains +aggregate `SHA256SUMS` and four platform archives: | Asset | SHA-256 | | --- | --- | -| `SHA256SUMS` | `3a72c5a6b4d3ceafda42593b0ceaa08ae36c5d2e908226eadfa2d82873567b7e` | -| `switchloom-darwin-arm64.tar.gz` | `2ec8344ecd38b41d4af47a77f6d5ff7882d4298ea73555d4c7cffa984dcdea0d` | -| `switchloom-darwin-x86_64.tar.gz` | `fc70d0b52c9b0e4932a505debba8d2aa75e0478189574f928fef6fdd312faf5b` | -| `switchloom-linux-arm64.tar.gz` | `561ebc772633f285326c08a3a9b9a8b2316bde0ea99f0d9a32def4a1838bf355` | -| `switchloom-linux-x86_64.tar.gz` | `0ba788c46404892f7bd7c1828eb9a52e9b92b6deba64bf71fed5eb3d39728deb` | +| `SHA256SUMS` | `a08021d57bd639244fab0a8ea575f3a2a5d77037fb6dbbae8e29d7db2bbc45ec` | +| `switchloom-darwin-arm64.tar.gz` | `e87d40f28553996b27313c82823f5f633e8e616197484d3b110bc1dc19ecb039` | +| `switchloom-darwin-x86_64.tar.gz` | `81485d39947f7e27a8693014b8eab346cfe7eaa72d3466420ac24068be12946e` | +| `switchloom-linux-arm64.tar.gz` | `09e063d95dc55a12108f75eacc1f3e7e04a4783d537244b4a94180cd2c34f678` | +| `switchloom-linux-x86_64.tar.gz` | `4636f564f884b6e710a1aa78a7429731995c69006603fab4ea663f6378d40ded` | -The Homebrew formula points at the same four `v0.2.1` release archives and -uses the matching platform checksums above. +The Homebrew formula points at the `v0.3.0` release archive for the current +stable macOS ARM formula URL and uses checksum +`e87d40f28553996b27313c82823f5f633e8e616197484d3b110bc1dc19ecb039`. ## Package Graph @@ -82,40 +82,75 @@ metadata or the Rust workspace metadata. | Command | Result | | --- | --- | -| `npm view switchloom@0.2.1 name version bin dependencies optionalDependencies peerDependencies --json` | Published package is `switchloom` version `0.2.1`, exposes bins `switchloom` and `model-routing` pointing to `npm/bin/model-routing.js`, and reports no runtime, optional, or peer dependency objects. | +| `npm view switchloom@0.3.0 name version bin dependencies optionalDependencies peerDependencies --json` | Published package is `switchloom` version `0.3.0`, exposes bins `switchloom` and `model-routing` through `npm/bin/model-routing.js`, and reports no runtime, optional, or peer dependency objects. | | `jq -r '.dependencies // {}, .peerDependencies // {}, .optionalDependencies // {}' package.json` | Local package metadata prints `{}` for each dependency graph. | -| `cargo metadata --format-version 1 --no-deps \| jq -r '.packages[] \| select(.name=="model-routing") \| {name,version,dependencies:[.dependencies[].name],targets:[.targets[] \| {name,kind}]}'` | Rust package is `model-routing` version `0.2.1`; dependencies are `anyhow`, `clap`, `ed25519-dalek`, `serde`, `serde_json`, `sha2`, and `toml`; targets are library `model_routing` plus binaries `model-routing` and `switchloom`. No dependency is named `planr`. | +| `cargo metadata --format-version 1 --no-deps \| jq -r '.packages[] \| select(.name=="model-routing") \| {name,version,dependencies:[.dependencies[].name],targets:[.targets[] \| {name,kind}]}'` | Rust package is `model-routing` version `0.3.0`; dependencies are `anyhow`, `clap`, `ed25519-dalek`, `serde`, `serde_json`, `sha2`, `thiserror`, and `toml`; targets are library `model_routing`, binaries `model-routing` and `switchloom`, and contract tests. No dependency is named `planr`. | | `sh scripts/check-migration-manifest.sh` | The checker scans local package metadata and fails on direct `planr` entries in `package.json`, `Cargo.toml`, or `Cargo.lock`. | ## Verification Receipts | Area | Evidence | | --- | --- | -| Release publication | Planr item `i-publish-and-smoke-test-the-super-b218` records public `v0.2.1` GitHub release, green Release workflow, npm Trusted Publisher package identity, Homebrew formula identity, production website deployment, and public-byte runtime receipt. | -| Release review chain | Initial independent review `i-review-publish-and-smoke-test-th-f424` closed not-complete with two documentation findings: the tagged commit subject needed correction, and this row needed a durable review-chain receipt. Fix item `i-fix-findings-for-review-publish-f3c2` is the remediation record for both findings, and its follow-up independent checker-2 gate is the final review closure path for the Goal A handoff. | -| Public GitHub check | `gh release view v0.2.1 --repo instructa/switchloom --json tagName,targetCommitish,url,publishedAt,isDraft,isPrerelease,assets` returned public non-draft `v0.2.1` with the five assets listed above. | -| Public workflow check | `gh run view 29682448374 --repo instructa/switchloom --json conclusion,status,url,createdAt,updatedAt,headSha,event,workflowName` returned `conclusion: success`, `status: completed`, `headSha: 56ce22ad33d7c8d2cf7ff1836639ee27ede36d67`. | -| Public npm check | `npm view switchloom@0.2.1 version dist.integrity dist.shasum dist.tarball --json` returned version `0.2.1` and the integrity/shasum/tarball listed above; `npm view switchloom@0.2.1 name version bin dependencies optionalDependencies peerDependencies --json` returned the bin contract and no dependency objects. | -| Public website check | Production deploy to `https://switchloom.ai` exited `0`; `/private/tmp/switchloom-public-0.2.1.MN008L/website-home.headers` and `/private/tmp/switchloom-public-0.2.1.MN008L/website-catalog.headers` record live HTTP `200`, and `/private/tmp/switchloom-public-0.2.1.MN008L/website-live.sha256` records exact catalog and bundle byte equality. | -| Public Homebrew check | `gh api repos/instructa/homebrew-tap/contents/Formula/switchloom.rb --jq '.content' \| base64 --decode` returned formula version `0.2.1`, release archive URLs, matching platform SHA-256 values, and `switchloom --version` formula test. | -| Public-byte runtime check | `/private/tmp/switchloom-public-0.2.1.MN008L` records the exact public npm proof. Fresh repository `/private/tmp/switchloom-public-0.2.1.MN008L/repository-retry-4` installed public `switchloom@0.2.1`; `/private/tmp/switchloom-public-0.2.1.MN008L/npm-tarball.sha1` matches npm shasum `e813283f54d0d64b5fd4835e17687aaaf3b0a6cb`, and `/private/tmp/switchloom-public-0.2.1.MN008L/npm-tarball.sha256` records tarball SHA-256 `028176063ce20b4981aa4e13199b25169b2f8296f648eeeec9291e6955e7549a`. `/private/tmp/switchloom-public-0.2.1.MN008L/retry-4-codex-runtime-evidence.json` validates complete parent `019f79dc-79cf-7342-90ae-f81ff1075e5a` runtime evidence: worker `model_routing_terra_high`, `fork_turns = none`, `gpt-5.6-terra` high; reviewer `model_routing_sol_high`, `fork_turns = none`, `gpt-5.6-sol` high; `/private/tmp/switchloom-public-0.2.1.MN008L/retry-4-validate-runtime-evidence.stdout` says `codex runtime evidence validation passed`. Global Codex config hashes in `retry-4-global-config-before.sha256` and `retry-4-global-config-after.sha256` are identical at `18cbbaee5e263f8bb011a174913721a8866a4d156d62c7fc74bc2d7103abcb3c`. Lifecycle cleanup is recorded by `retry-4-uninstall.json`, which removed only seven Switchloom-managed artifacts; `retry-4-status-after-uninstall.json` reports `bundle_id: null` and no artifacts; unmanaged `user-preserved.toml` survived with SHA-256 `ae9ae1bb9273d0b5f6641c430eb98efc1134a4c25bccf1a0dbf602bea29bd16b` in `retry-4-sentinel-after.sha256`; inventory after uninstall is `retry-4-inventory-after-uninstall.txt`. | -| Website/CLI parity | Planr item `i-prove-website-cli-standal-f9f5` and follow-up fixes record full `site:check`, Cloudflare verification, generated SetupSpec transport, desktop/mobile browser checks, CLI replay, and Planr recipe lifecycle evidence. | -| Authenticated Codex oracles | Planr item `i-pass-offline-safety-website-and-5aac` and follow-up logs record authenticated standalone and Planr-integrated Codex evidence for effective model, effort, role, non-`all` fork policy, Planr loop dispatch, and negative receipt checks. | +| Release PR and CI | PR `#19` was merged at `2026-07-21T18:25:24Z`; PR checks passed for Rust, four native builds, forbidden tracked paths, npm distribution, native-matrix package validation, TruffleHog verified secrets, and BetterLeaks. | +| Release review chain | Planr items in `switchloom-v0-3-0-reviewed-candidate-publication` were reviewed by `checker-release-revalidate` in independent mode. The exact review table below records the not-complete reviews, fix items, remediation reviews, and final follow-up verdicts. | +| Public GitHub check | `gh release view v0.3.0 --repo instructa/switchloom --json tagName,targetCommitish,url,publishedAt,isDraft,isPrerelease,assets` returned public non-draft `v0.3.0` with the five assets listed above. | +| Public workflow check | `gh run view 29857502558 --repo instructa/switchloom --json conclusion,status,url,createdAt,updatedAt,headSha,event,workflowName` returned `conclusion: success`, `status: completed`, and `headSha: 45c15fed09786c9dee1167744b1c43b87b47d505`. | +| Public npm check | `npm view switchloom@0.3.0 --json` returned version `0.3.0`, integrity and shasum listed above, tarball `https://registry.npmjs.org/switchloom/-/switchloom-0.3.0.tgz`, 20 files, unpacked size `11898450`, publish time `2026-07-21T18:34:48.188Z`, attestation URL `https://registry.npmjs.org/-/npm/v1/attestations/switchloom@0.3.0`, SLSA predicate `https://slsa.dev/provenance/v1`, and registry signature key `SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U`. | +| Public Homebrew check | `brew info --json=v2 instructa/tap/switchloom` returned stable version `0.3.0`, formula URL `https://github.com/instructa/switchloom/releases/download/v0.3.0/switchloom-darwin-arm64.tar.gz`, and the matching checksum. | +| Public asset checksum check | `tmpdir=$(mktemp -d /private/tmp/switchloom-release-v0.3.0-assets.XXXXXX); gh release download v0.3.0 --repo instructa/switchloom --pattern 'switchloom-*.tar.gz' --pattern SHA256SUMS --dir "$tmpdir"; cd "$tmpdir"; shasum -a 256 -c SHA256SUMS; cat SHA256SUMS` passed for all four public release archives and printed the archive hashes listed above. | +| Public npm provenance check | `root=$(mktemp -d /private/tmp/switchloom-public-v0.3.0-npm-tarball.XXXXXX); cd "$root"; npm pack switchloom@0.3.0 --json > pack.json; shasum switchloom-0.3.0.tgz; shasum -a 256 switchloom-0.3.0.tgz; tar -xzf switchloom-0.3.0.tgz package/npm/native/provenance.json package/package.json; node -e '...'` passed: tarball SHA-1 matched npm shasum `7ccf5c8c693c33f5a83fad47529e630c46c8cf2c`, tarball SHA-256 was `95ec712b3debab10e33f51652d644c531c5ea85fac4e90bb87369374514b68f5`, and `npm/native/provenance.json` recorded `package_version: 0.3.0`, git SHA `45c15fed09786c9dee1167744b1c43b87b47d505`, and four native targets. | +| Public npm runtime check | `/private/tmp/switchloom-public-v0.3.0-npm-fix.GMEH4n` records the complete fail-closed npm command in Planr item `i-fix-findings-for-review-certify-f413`, `log-c67dc0dd`: explicit `root`, `prefix`, `repo`, and `cache`; public `switchloom@0.3.0` install; version/help assertions; `compile`, `inspect`, `preview`, `apply`, `status`, `uninstall`; empty post-uninstall status; unchanged unmanaged sentinel SHA-256 `60ba63428d6029222a9d092142fcdc64d045d93650e0c25cb25cd7f319351fae`; unchanged authenticated Codex config SHA-256 `eec8236cc13bd729a46376d65624eaf795a70bd48ccee8ac707d904f735aaedd`. | +| Public Homebrew runtime check | `/private/tmp/switchloom-public-v0.3.0-brew-fix.sA9meG` records the complete fail-closed Homebrew command in Planr item `i-fix-findings-for-review-certify-f413`, `log-c67dc0dd`: formula `0.3.0` and checksum assertions, `brew reinstall instructa/tap/switchloom`, version/help assertions, `compile`, `inspect`, `preview`, `apply`, `status`, `uninstall`, empty post-uninstall status, and the same unchanged unmanaged sentinel and Codex config hashes. | +| Public website check | `pnpm exec alchemy deploy --stage prod` completed successfully and reported worker URL `https://model-routing-prod-catalog.office-35d.workers.dev`. `node scripts/verify-cloudflare-website.mjs https://switchloom.ai target/release/model-routing` passed with 28 catalog entries, 6 setup hosts, and `balanced-codex-openai` parity hash `3289f2d7231639a7084c4455c13448e89a1f596a2877672db5b1962d06f5f905`. `log-c67dc0dd` also records the complete fail-closed live guidance command that fetched the live index, catalog, and linked Generator JS and asserted npm/npx setup commands, lifecycle commands, Cursor advisory wording, and Claude unavailable/unverified wording. | +| Live guidance check | `/private/tmp/switchloom-public-v0.3.0-website-fix.Ou1eQ0` records `live website guidance fix passed: 28 compositions, 6 hosts, 1 Generator asset(s)`. | | Migration manifest | `sh scripts/check-migration-manifest.sh` verifies `docs/migration-manifest.tsv` covers the frozen Planr routing inventory, legacy command transfers, active Planr consumer/deletion mappings from a case-insensitive whole current Planr repo scan for routing lexical variants, unique type/source mappings, current generated artifact targets, and no direct Planr package dependency. | +| Protected Planr baseline | Before and after this receipt update, `/Users/kregenrek/projects/planr` remained at HEAD `bbc877d40191b2cbb289ed26df5e6fee25e4326d` and dirty-state SHA-256 `d6c56495c7e2a78aed2e641b0e928bc8a579bf31335db36456a9f05726827927`. | + +## Scoped Review Chain + +| Implementation or fix item | Review item | Reviewer | Mode | Verdict | Finding-to-fix or follow-up link | +| --- | --- | --- | --- | --- | --- | +| `i-revalidate-the-clean-candidate-a-9e76` | `i-review-revalidate-the-clean-cand-665d` (`log-a2def4d6`) | `checker-release-revalidate` | independent | not-complete | Required fail-closed candidate/receipt/hash assertions and darwin-arm64 native hash coverage; fixed by `i-fix-findings-for-review-revalida-f671`. | +| `i-fix-findings-for-review-revalida-f671` | `i-follow-up-review-for-review-reva-dc3f` (`log-d6f2175e`) | `checker-release-revalidate` | independent | complete | Follow-up review closed the revalidation finding. | +| `i-fix-findings-for-review-revalida-f671` | `i-review-fix-findings-for-review-r-71f5` (`log-da78edac`) | `checker-release-revalidate` | independent | complete | Remediation review also closed complete. | +| `i-push-the-candidate-branch-and-op-c4a1` | `i-review-push-the-candidate-branch-52ef` (`log-063de355`) | `checker-release-revalidate` | independent | complete | PR `#19` branch/opening evidence accepted. | +| `i-complete-independent-review-and-f551` | `i-review-complete-independent-revi-ca76` (`log-7955f3e5`) | `checker-release-revalidate` | independent | complete | CI and independent review state accepted. | +| `i-merge-the-reviewed-candidate-and-9502` | `i-review-merge-the-reviewed-candid-02fe` (`log-ba285da6`) | `checker-release-revalidate` | independent | complete | Merge commit and main checks accepted. | +| `i-tag-v0-3-0-and-publish-configure-1559` | `i-review-tag-v0-3-0-and-publish-co-6c7b` (`log-61a9b630`) | `checker-release-revalidate` | independent | complete | Tag, release workflow, npm, Homebrew, and website publication accepted. | +| `i-certify-public-bytes-and-fresh-i-e1fa` | `i-review-certify-public-bytes-and-fb9b` (`log-76c6ba7c`) | `checker-release-revalidate` | independent | not-complete | Initial public-byte certification lacked reproducible fresh npm/Homebrew/language guidance commands; fixed by `i-fix-findings-for-review-certify-f413`. | +| `i-fix-findings-for-review-certify-f413` | `i-follow-up-review-for-review-cert-ddc5` (`log-3f1d697e`) | `checker-release-revalidate` | independent | complete | Follow-up certification review accepted `log-c67dc0dd` and closed the finding. | +| `i-fix-findings-for-review-certify-f413` | `i-review-fix-findings-for-review-c-3c54` (`log-37c75656`) | `checker-release-revalidate` | independent | complete | Remediation review also closed complete. | +| `i-finalize-durable-release-and-pla-2dac` | `i-review-finalize-durable-release-a933` (`log-92b96893`) | `checker-release-revalidate` | independent | not-complete | Required this fix item, `i-fix-findings-for-review-finalize-884d`, to add exact review identities, tested-host evidence, and reproducible public-byte command identities. | + +## Tested Host Matrix + +| Host/profile | Version | Evidence identity | Result | +| --- | --- | --- | --- | +| Codex implementer `codex-terra-high` | `codex-cli 0.144.5` | `retained-evidence/release-ready-v0.3.0/live/codex-openai/1784654270-96976-0/workdir/codex-runtime-evidence.json` (`sha256:df08c39c2fc66c96e44b0a3620b48ec9a3ad271b4b936d56da3ffaf77f7933b8`) | Final-candidate live deterministic. Package digest `sha256:b4dd82486d85f5b7a171cbc7b25836a99ad6c59d0fa0490acbfc18703f729c39` matches `retained-evidence/release-ready-v0.3.0/candidate.json` `packages.darwin_arm64_native.sha256` and `model-routing 0.3.0`; `model_routing_terra_high`, task `standalone_implementer`, `fork_turns: none`, effective model `gpt-5.6-terra`, effective effort `high`, nonce `019f85af-1ba9-7080-b4fa-402fdce321b1:019f85af-49d0-7860-b948-44b5c34d6413:call_CPMYdb9RLRqdYSF9VmtNrZx2`. | +| Codex reviewer `codex-sol-high` | `codex-cli 0.144.5` | `retained-evidence/release-ready-v0.3.0/live/codex-openai/1784654270-96976-0/workdir/codex-runtime-evidence.json` (`sha256:df08c39c2fc66c96e44b0a3620b48ec9a3ad271b4b936d56da3ffaf77f7933b8`) | Final-candidate live deterministic. Package digest `sha256:b4dd82486d85f5b7a171cbc7b25836a99ad6c59d0fa0490acbfc18703f729c39` matches `retained-evidence/release-ready-v0.3.0/candidate.json`; `model_routing_sol_high`, task `standalone_reviewer`, `fork_turns: none`, effective model `gpt-5.6-sol`, effective effort `high`, nonce `019f85af-1ba9-7080-b4fa-402fdce321b1:019f85af-5594-7fa0-a9a3-ae6d27f399bc:call_lRdM1G8hGMLyVqqYJsIhHHjt`. | +| Cursor OpenAI `cursor-openai-worker` | `2026.07.17-3e2a980` | `retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/workdir/dispatch-evidence.json` (`sha256:8a774e60cdc3e3c9e29ad9603eedfa540c965635cb20715661e202e3f98dddaf`) | Final-candidate live nonce-correlated advisory. Package digest `sha256:b4dd82486d85f5b7a171cbc7b25836a99ad6c59d0fa0490acbfc18703f729c39` matches `retained-evidence/release-ready-v0.3.0/candidate.json`; requested model `gpt-5.4-mini`, role `model-routing-preset-worker`, nonce `cursor-ca900e62e38956c0534dbd4b4a22f4caef0be56da33acecae9df8afdf9f3e05f`; effective model and effort were not exposed by Cursor, so verdict remains `advisory`. | +| Cursor Fable/Grok `cursor-grok-worker` | `2026.07.17-3e2a980` | `retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/workdir/dispatch-evidence.json` (`sha256:0bdf08e18a5b4b99c600c4029928e76bb355d80341b2f54aed25db77b5e8d6cb`) | Final-candidate live nonce-correlated advisory. Package digest `sha256:b4dd82486d85f5b7a171cbc7b25836a99ad6c59d0fa0490acbfc18703f729c39` matches `retained-evidence/release-ready-v0.3.0/candidate.json`; requested model `cursor-grok-4.5-medium`, role `model-routing-preset-worker`, nonce `cursor-fc4820bb03cf0e4c29c70f8cc54a166d0f4f9175c086b4a076febc2497d27589`; effective model and effort were not exposed by Cursor, so verdict remains `advisory`. | +| Claude Code `claude-native` | `2.1.133 (Claude Code)` | `retained-evidence/release-ready-v0.3.0/live/claude-native/1784654534-22027-0/certification-report.json` (`sha256:fbcc3c7a027f1d9a8811189f5b66efed31386aabdf9eea7399d484d18df1dab8`) | Final-candidate skipped/unavailable/unverified. No live effective telemetry or certified dispatch receipt is claimed. | +| OpenCode `opencode-native` | Deterministic artifact coverage only | `reports/native-host-certification/opencode-native/certification-summary.json` | Unavailable/unverified as a live release gate. Static lifecycle and validator coverage pass, but no authentic nonce-bearing child receipt exists and deterministic upgrade is disallowed. | +| Pi `pi-external` | Deterministic artifact coverage only | `reports/native-host-certification/pi-external/certification-summary.json` | Unavailable/unverified as a live release gate. Static workflow and validator coverage pass, but provider authentication and nonce-only child evidence are absent and deterministic upgrade is disallowed. | + +Older `reports/native-host-certification/*` Codex and Cursor artifacts remain +historical pre-release evidence only. The final `v0.3.0` tested-host gate is the +durable `retained-evidence/release-ready-v0.3.0/live/*` evidence above. ## Migration Ownership The exhaustive mapping is `docs/migration-manifest.tsv`. -- `source-file` rows move or replace frozen `planr-routing/*` source, - website, fixture, policy, evaluation, and documentation ownership into this - standalone Switchloom repository. +- `source-file` rows move or replace frozen `planr-routing/*` source, website, + fixture, policy, evaluation, and documentation ownership into this standalone + Switchloom repository. - `generated-current` rows are deleted and regenerated from standalone Switchloom source; dependency install artifacts are never moved or published. - `cli-command` rows transfer old `planr-routing ...` commands to the standalone `model-routing`/`switchloom` command surface. -- `generated-artifact` rows transfer current Switchloom v0.2.1 outputs: optional - `.planr/agents.toml` and `.planr/policy.toml`; Codex +- `generated-artifact` rows transfer current Switchloom `v0.3.0` outputs: + optional `.planr/agents.toml` and `.planr/policy.toml`; Codex `.codex/agents/model-routing-luna-xhigh.toml`, `.codex/agents/model-routing-sol-high.toml`, `.codex/agents/model-routing-sol-medium.toml`, @@ -149,12 +184,11 @@ The active Planr files currently covered by `planr-consumer` rows include: `apps/docs/scripts/verify-shell.mjs`, and `plugins/planr/skills/planr-loop/SKILL.md`. The checker derives this list from the live `/Users/kregenrek/projects/planr` tree by scanning the whole repo -case-insensitively for `planr[- ]routing`, -`routing[_ -]bundles?`, and `routingbundle`, with explicit exclusions for -operational state, generated/dependency directories, and the legacy -`planr-routing/` producer subtree already covered by frozen `source-file` rows. -It fails if any discovered file lacks a manifest row or if any `(type, source)` -pair is duplicated. +case-insensitively for `planr[- ]routing`, `routing[_ -]bundles?`, and +`routingbundle`, with explicit exclusions for operational state, +generated/dependency directories, and the legacy `planr-routing/` producer +subtree already covered by frozen `source-file` rows. It fails if any discovered +file lacks a manifest row or if any `(type, source)` pair is duplicated. ## Remaining Planr Surface @@ -178,8 +212,8 @@ Goal B should run from `/Users/kregenrek/projects/planr` only after this item's review is complete. 1. Confirm the Switchloom release gate still holds: - `gh release view v0.2.1 --repo instructa/switchloom`, - `npm view switchloom@0.2.1 version`, and + `gh release view v0.3.0 --repo instructa/switchloom`, + `npm view switchloom@0.3.0 version`, and `gh api repos/instructa/homebrew-tap/contents/Formula/switchloom.rb`. 2. Delete or replace every `planr-consumer` row in `docs/migration-manifest.tsv` whose disposition is `keep-then-delete`, @@ -192,7 +226,7 @@ review is complete. 5. Remove legacy user-facing `planr routing bundle` command paths and any tests that require Planr to compile Switchloom-owned bundles internally. 6. Replace Planr bundle/route tests with fixtures produced by - `switchloom@0.2.1` and assertions that Planr consumes declarations, resolves + `switchloom@0.3.0` and assertions that Planr consumes declarations, resolves routes, and logs effective evidence. 7. Regenerate Planr CLI docs and generated fixtures so `docs/CLI_REFERENCE.md`, `docs/fixtures/mcp-contract.json`, @@ -206,19 +240,19 @@ review is complete. so current routing ownership points to released Switchloom instead of `planr-routing`. 10. Preserve `apps/docs/redirects.mjs` and - `docs/documentation/INFORMATION_ARCHITECTURE.md` only if they are historical - redirect inventory. Rewrite or delete them if they describe a current - routing-bundles feature surface. + `docs/documentation/INFORMATION_ARCHITECTURE.md` only if they are historical + redirect inventory. Rewrite or delete them if they describe a current + routing-bundles feature surface. 11. Run Planr's own format, lint, unit, integration, docs, and app-docs - verification commands, including the docs shell verifier that replaces the - legacy command assertions. + verification commands, including the docs shell verifier that replaces the + legacy command assertions. 12. Run negative ownership scans in the Planr repo for legacy compiler/catalog - ownership strings, including `planr-routing`, `routing bundle`, and - Switchloom model catalog/preset compiler code. + ownership strings, including `planr-routing`, `routing bundle`, and + Switchloom model catalog/preset compiler code. 13. Re-run this repo's checker from `/Users/kregenrek/projects/model-routing`: - `sh scripts/check-migration-manifest.sh`. It must either find no remaining - legacy Planr files or find only rows explicitly retained as Planr-owned - neutral orchestration. + `sh scripts/check-migration-manifest.sh`. It must either find no remaining + legacy Planr files or find only rows explicitly retained as Planr-owned + neutral orchestration. The hard cut is complete only when Planr can pass its tests using released Switchloom declarations or fixtures, with no Planr-side compiler/catalog source diff --git a/docs/prepublish-certification-0.3.0.md b/docs/prepublish-certification-0.3.0.md new file mode 100644 index 0000000..8b4fa1f --- /dev/null +++ b/docs/prepublish-certification-0.3.0.md @@ -0,0 +1,204 @@ +# Switchloom 0.3.0 Publish Certification + +Date: 2026-07-21 +Release Planr map: `switchloom-v0-3-0-reviewed-candidate-publication` +Final handoff Planr item: `i-finalize-durable-release-and-pla-2dac` + +## Candidate + +- Candidate version: `0.3.0` +- Candidate branch: `codex/switchloom-0.3.0-migration` +- Pull request: `https://github.com/instructa/switchloom/pull/19` +- Candidate commit: `e936b90c81d8f944ba50657c10ef9a2a564c53c5` +- Release and merge commit: `45c15fed09786c9dee1167744b1c43b87b47d505` +- Annotated tag: `v0.3.0` +- Tag object: `8306c2533be0cbeb9c6801651cb08d0d244d7678` +- Tag target: `45c15fed09786c9dee1167744b1c43b87b47d505` +- Protected Planr repository: + `/Users/kregenrek/projects/planr` +- Protected Planr HEAD: + `bbc877d40191b2cbb289ed26df5e6fee25e4326d` +- Protected Planr dirty-state hash: + `d6c56495c7e2a78aed2e641b0e928bc8a579bf31335db36456a9f05726827927` + +## Scoped Review Chain + +All scoped implementation, review, and remediation items for the +`switchloom-v0-3-0-reviewed-candidate-publication` map were independently +reviewed by `checker-release-revalidate` in independent mode before this final +handoff receipt was prepared. + +| Implementation or fix item | Review item | Reviewer | Mode | Verdict | Finding-to-fix or follow-up link | +| --- | --- | --- | --- | --- | --- | +| `i-revalidate-the-clean-candidate-a-9e76` | `i-review-revalidate-the-clean-cand-665d` (`log-a2def4d6`) | `checker-release-revalidate` | independent | not-complete | Required fail-closed candidate/receipt/hash assertions and darwin-arm64 native hash coverage; fixed by `i-fix-findings-for-review-revalida-f671`. | +| `i-fix-findings-for-review-revalida-f671` | `i-follow-up-review-for-review-reva-dc3f` (`log-d6f2175e`) | `checker-release-revalidate` | independent | complete | Follow-up review closed the revalidation finding. | +| `i-fix-findings-for-review-revalida-f671` | `i-review-fix-findings-for-review-r-71f5` (`log-da78edac`) | `checker-release-revalidate` | independent | complete | Remediation review also closed complete. | +| `i-push-the-candidate-branch-and-op-c4a1` | `i-review-push-the-candidate-branch-52ef` (`log-063de355`) | `checker-release-revalidate` | independent | complete | PR `#19` branch/opening evidence accepted. | +| `i-complete-independent-review-and-f551` | `i-review-complete-independent-revi-ca76` (`log-7955f3e5`) | `checker-release-revalidate` | independent | complete | CI and independent review state accepted. | +| `i-merge-the-reviewed-candidate-and-9502` | `i-review-merge-the-reviewed-candid-02fe` (`log-ba285da6`) | `checker-release-revalidate` | independent | complete | Merge commit and main checks accepted. | +| `i-tag-v0-3-0-and-publish-configure-1559` | `i-review-tag-v0-3-0-and-publish-co-6c7b` (`log-61a9b630`) | `checker-release-revalidate` | independent | complete | Tag, release workflow, npm, Homebrew, and website publication accepted. | +| `i-certify-public-bytes-and-fresh-i-e1fa` | `i-review-certify-public-bytes-and-fb9b` (`log-76c6ba7c`) | `checker-release-revalidate` | independent | not-complete | Initial public-byte certification lacked reproducible fresh npm/Homebrew/language guidance commands; fixed by `i-fix-findings-for-review-certify-f413`. | +| `i-fix-findings-for-review-certify-f413` | `i-follow-up-review-for-review-cert-ddc5` (`log-3f1d697e`) | `checker-release-revalidate` | independent | complete | Follow-up certification review accepted `log-c67dc0dd` and closed the finding. | +| `i-fix-findings-for-review-certify-f413` | `i-review-fix-findings-for-review-c-3c54` (`log-37c75656`) | `checker-release-revalidate` | independent | complete | Remediation review also closed complete. | +| `i-finalize-durable-release-and-pla-2dac` | `i-review-finalize-durable-release-a933` (`log-92b96893`) | `checker-release-revalidate` | independent | not-complete | Required this fix item, `i-fix-findings-for-review-finalize-884d`, to add exact review identities, tested-host evidence, and reproducible public-byte command identities. | + +## Passed Gates + +- `SWITCHLOOM_RC_RUN_ID=29856707722 RELEASE_DRY_RUN=1 scripts/release.sh 0.3.0 'Public CLI hard cut and deterministic setup lifecycle'` +- `SWITCHLOOM_RC_RUN_ID=29856707722 scripts/release.sh 0.3.0 'Public CLI hard cut and deterministic setup lifecycle'` +- `gh run view 29857502558 --repo instructa/switchloom --json conclusion,status,headSha,event,workflowName` +- `gh release view v0.3.0 --repo instructa/switchloom --json tagName,targetCommitish,url,publishedAt,isDraft,isPrerelease,assets` +- `npm view switchloom@0.3.0 version dist.integrity dist.shasum dist.tarball --json` +- `brew info --json=v2 instructa/tap/switchloom` +- `pnpm exec alchemy deploy --stage prod` +- `node scripts/verify-cloudflare-website.mjs https://switchloom.ai target/release/model-routing` +- `sh scripts/check-migration-manifest.sh` + +## Published Artifacts + +- GitHub release: + `https://github.com/instructa/switchloom/releases/tag/v0.3.0` +- GitHub release state: public, non-draft, non-prerelease. +- Release workflow run: `29857502558` +- Public npm package: `switchloom@0.3.0` +- Public npm tarball: + `https://registry.npmjs.org/switchloom/-/switchloom-0.3.0.tgz` +- Public npm shasum: `7ccf5c8c693c33f5a83fad47529e630c46c8cf2c` +- Public npm integrity: + `sha512-NdEyH1zq+W6E5pZIHdG8oe2CQxVjtjVlvQlvdCMxDEwaroCLzXEMiUMvnd/kjgXGx5A/WYsFxWe/nU7eSNgjzw==` +- Public npm file count: `20` +- Public npm unpacked size: `11898450` +- Public npm publish time: `2026-07-21T18:34:48.188Z` +- Public npm attestation URL: + `https://registry.npmjs.org/-/npm/v1/attestations/switchloom@0.3.0` +- Public npm attestation predicate: + `https://slsa.dev/provenance/v1` +- Public npm registry signature key: + `SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U` +- Public npm tarball SHA-256: + `95ec712b3debab10e33f51652d644c531c5ea85fac4e90bb87369374514b68f5` +- Homebrew stable version: `0.3.0` +- Homebrew formula URL: + `https://github.com/instructa/switchloom/releases/download/v0.3.0/switchloom-darwin-arm64.tar.gz` +- Homebrew formula checksum: + `e87d40f28553996b27313c82823f5f633e8e616197484d3b110bc1dc19ecb039` +- Homebrew tap HEAD: `2fdec6450d4444febc54fcf7ffe44e7072e59c74` +- Website worker URL: + `https://model-routing-prod-catalog.office-35d.workers.dev` + +GitHub release asset SHA-256 values: + +| Asset | SHA-256 | +| --- | --- | +| `SHA256SUMS` | `a08021d57bd639244fab0a8ea575f3a2a5d77037fb6dbbae8e29d7db2bbc45ec` | +| `switchloom-darwin-arm64.tar.gz` | `e87d40f28553996b27313c82823f5f633e8e616197484d3b110bc1dc19ecb039` | +| `switchloom-darwin-x86_64.tar.gz` | `81485d39947f7e27a8693014b8eab346cfe7eaa72d3466420ac24068be12946e` | +| `switchloom-linux-arm64.tar.gz` | `09e063d95dc55a12108f75eacc1f3e7e04a4783d537244b4a94180cd2c34f678` | +| `switchloom-linux-x86_64.tar.gz` | `4636f564f884b6e710a1aa78a7429731995c69006603fab4ea663f6378d40ded` | + +Public asset checksum command: + +- Command: `tmpdir=$(mktemp -d /private/tmp/switchloom-release-v0.3.0-assets.XXXXXX); gh release download v0.3.0 --repo instructa/switchloom --pattern 'switchloom-*.tar.gz' --pattern SHA256SUMS --dir "$tmpdir"; cd "$tmpdir"; shasum -a 256 -c SHA256SUMS; cat SHA256SUMS` +- Result: `shasum -a 256 -c SHA256SUMS` passed for all four public release + archives; `cat SHA256SUMS` returned the archive hashes listed above. + +Public npm provenance command: + +- Command: `root=$(mktemp -d /private/tmp/switchloom-public-v0.3.0-npm-tarball.XXXXXX); cd "$root"; npm pack switchloom@0.3.0 --json > pack.json; shasum switchloom-0.3.0.tgz; shasum -a 256 switchloom-0.3.0.tgz; tar -xzf switchloom-0.3.0.tgz package/npm/native/provenance.json package/package.json; node -e 'const fs=require("fs"); const p=JSON.parse(fs.readFileSync("package/npm/native/provenance.json","utf8")); if (p.git_sha !== "45c15fed09786c9dee1167744b1c43b87b47d505") throw new Error("unexpected git_sha"); if (p.package_version !== "0.3.0") throw new Error("unexpected package_version"); if (!Array.isArray(p.targets) || p.targets.length !== 4) throw new Error("expected four native targets"); for (const t of p.targets) { if (t.git_sha !== p.git_sha || t.version !== "model-routing 0.3.0") throw new Error(); }'` +- Result: public tarball SHA-1 matched npm shasum + `7ccf5c8c693c33f5a83fad47529e630c46c8cf2c`, public tarball SHA-256 was + `95ec712b3debab10e33f51652d644c531c5ea85fac4e90bb87369374514b68f5`, and + `npm/native/provenance.json` recorded `package_version: 0.3.0`, + `git_sha: 45c15fed09786c9dee1167744b1c43b87b47d505`, and four native + targets. + +## Tested Host Matrix + +| Host/profile | Version | Evidence identity | Result | +| --- | --- | --- | --- | +| Codex implementer `codex-terra-high` | `codex-cli 0.144.5` | `retained-evidence/release-ready-v0.3.0/live/codex-openai/1784654270-96976-0/workdir/codex-runtime-evidence.json` (`sha256:df08c39c2fc66c96e44b0a3620b48ec9a3ad271b4b936d56da3ffaf77f7933b8`) | Final-candidate live deterministic. Package digest `sha256:b4dd82486d85f5b7a171cbc7b25836a99ad6c59d0fa0490acbfc18703f729c39` matches `retained-evidence/release-ready-v0.3.0/candidate.json` `packages.darwin_arm64_native.sha256` and `model-routing 0.3.0`; `model_routing_terra_high`, task `standalone_implementer`, `fork_turns: none`, effective model `gpt-5.6-terra`, effective effort `high`, nonce `019f85af-1ba9-7080-b4fa-402fdce321b1:019f85af-49d0-7860-b948-44b5c34d6413:call_CPMYdb9RLRqdYSF9VmtNrZx2`. | +| Codex reviewer `codex-sol-high` | `codex-cli 0.144.5` | `retained-evidence/release-ready-v0.3.0/live/codex-openai/1784654270-96976-0/workdir/codex-runtime-evidence.json` (`sha256:df08c39c2fc66c96e44b0a3620b48ec9a3ad271b4b936d56da3ffaf77f7933b8`) | Final-candidate live deterministic. Package digest `sha256:b4dd82486d85f5b7a171cbc7b25836a99ad6c59d0fa0490acbfc18703f729c39` matches `retained-evidence/release-ready-v0.3.0/candidate.json`; `model_routing_sol_high`, task `standalone_reviewer`, `fork_turns: none`, effective model `gpt-5.6-sol`, effective effort `high`, nonce `019f85af-1ba9-7080-b4fa-402fdce321b1:019f85af-5594-7fa0-a9a3-ae6d27f399bc:call_lRdM1G8hGMLyVqqYJsIhHHjt`. | +| Cursor OpenAI `cursor-openai-worker` | `2026.07.17-3e2a980` | `retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/workdir/dispatch-evidence.json` (`sha256:8a774e60cdc3e3c9e29ad9603eedfa540c965635cb20715661e202e3f98dddaf`) | Final-candidate live nonce-correlated advisory. Package digest `sha256:b4dd82486d85f5b7a171cbc7b25836a99ad6c59d0fa0490acbfc18703f729c39` matches `retained-evidence/release-ready-v0.3.0/candidate.json`; requested model `gpt-5.4-mini`, role `model-routing-preset-worker`, nonce `cursor-ca900e62e38956c0534dbd4b4a22f4caef0be56da33acecae9df8afdf9f3e05f`; effective model and effort were not exposed by Cursor, so verdict remains `advisory`. | +| Cursor Fable/Grok `cursor-grok-worker` | `2026.07.17-3e2a980` | `retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/workdir/dispatch-evidence.json` (`sha256:0bdf08e18a5b4b99c600c4029928e76bb355d80341b2f54aed25db77b5e8d6cb`) | Final-candidate live nonce-correlated advisory. Package digest `sha256:b4dd82486d85f5b7a171cbc7b25836a99ad6c59d0fa0490acbfc18703f729c39` matches `retained-evidence/release-ready-v0.3.0/candidate.json`; requested model `cursor-grok-4.5-medium`, role `model-routing-preset-worker`, nonce `cursor-fc4820bb03cf0e4c29c70f8cc54a166d0f4f9175c086b4a076febc2497d27589`; effective model and effort were not exposed by Cursor, so verdict remains `advisory`. | +| Claude Code `claude-native` | `2.1.133 (Claude Code)` | `retained-evidence/release-ready-v0.3.0/live/claude-native/1784654534-22027-0/certification-report.json` (`sha256:fbcc3c7a027f1d9a8811189f5b66efed31386aabdf9eea7399d484d18df1dab8`) | Final-candidate skipped/unavailable/unverified. No live effective telemetry or certified dispatch receipt is claimed. | +| OpenCode `opencode-native` | Deterministic artifact coverage only | `reports/native-host-certification/opencode-native/certification-summary.json` | Unavailable/unverified as a live release gate. Static lifecycle and validator coverage pass, but no authentic nonce-bearing child receipt exists and deterministic upgrade is disallowed. | +| Pi `pi-external` | Deterministic artifact coverage only | `reports/native-host-certification/pi-external/certification-summary.json` | Unavailable/unverified as a live release gate. Static workflow and validator coverage pass, but provider authentication and nonce-only child evidence are absent and deterministic upgrade is disallowed. | + +Older `reports/native-host-certification/*` Codex and Cursor artifacts remain +historical pre-release evidence only. The final `v0.3.0` tested-host gate is the +durable `retained-evidence/release-ready-v0.3.0/live/*` evidence above. + +## Fresh Install Receipts + +Public npm receipt: + +- Root: `/private/tmp/switchloom-public-v0.3.0-npm-fix.GMEH4n` +- Install mode: fresh npm global-prefix install. +- Durable Planr evidence: `i-fix-findings-for-review-certify-f413`, + `log-c67dc0dd`. +- Reproducible command: complete `set -euo pipefail` npm command in + `log-c67dc0dd`, creating explicit `root`, `prefix`, `repo`, and `cache`, + installing public `switchloom@0.3.0`, and failing closed on each assertion. +- Commands covered: `--version`, `--help`, `compile`, `inspect`, `preview`, + `apply`, `status`, and `uninstall`; the help assertion also checked + `policy`, `update`, `rollback`, and `doctor`. +- Unmanaged sentinel hash before and after: + `60ba63428d6029222a9d092142fcdc64d045d93650e0c25cb25cd7f319351fae` +- Authenticated Codex config hash before and after: + `eec8236cc13bd729a46376d65624eaf795a70bd48ccee8ac707d904f735aaedd` +- Post-uninstall status: no managed artifacts. + +Public Homebrew receipt: + +- Root: `/private/tmp/switchloom-public-v0.3.0-brew-fix.sA9meG` +- Install mode: `brew reinstall instructa/tap/switchloom`. +- Durable Planr evidence: `i-fix-findings-for-review-certify-f413`, + `log-c67dc0dd`. +- Reproducible command: complete `set -euo pipefail` Homebrew command in + `log-c67dc0dd`, creating explicit `root` and `repo`, asserting formula + version `0.3.0` plus checksum + `e87d40f28553996b27313c82823f5f633e8e616197484d3b110bc1dc19ecb039`, + reinstalling `instructa/tap/switchloom`, and failing closed on each + lifecycle assertion. +- Commands covered: formula version and checksum assertion, `--version`, + `--help`, `compile`, `inspect`, `preview`, `apply`, `status`, and + `uninstall`. +- Unmanaged sentinel hash before and after: + `60ba63428d6029222a9d092142fcdc64d045d93650e0c25cb25cd7f319351fae` +- Authenticated Codex config hash before and after: + `eec8236cc13bd729a46376d65624eaf795a70bd48ccee8ac707d904f735aaedd` +- Post-uninstall status: no managed artifacts. + +Public website receipt: + +- Root: `/private/tmp/switchloom-public-v0.3.0-website-fix.Ou1eQ0` +- Durable Planr evidence: `i-fix-findings-for-review-certify-f413`, + `log-c67dc0dd`. +- Production verification: + `node scripts/verify-cloudflare-website.mjs https://switchloom.ai target/release/model-routing` +- Result: 28 catalog entries, 6 setup hosts, and + `balanced-codex-openai` parity hash + `3289f2d7231639a7084c4455c13448e89a1f596a2877672db5b1962d06f5f905`. +- Live guidance result: + `live website guidance fix passed: 28 compositions, 6 hosts, 1 Generator asset(s)`. +- Reproducible command: complete `set -euo pipefail` website command in + `log-c67dc0dd`, fetching the live index, catalog, and linked Generator JS, + then asserting `npm install -g switchloom@0.3.0`, + `npx switchloom@0.3.0 apply --recipe`, lifecycle commands, Cursor advisory + wording, and Claude unavailable/unverified wording. + +## Limitations + +- Claude Code is skipped/unavailable/unverified until live receipts exist; no + Claude effective model or effort telemetry is certified for this release. +- Cursor host checks remain advisory where the host returns the nonce but not + host-authenticated effective model or effort telemetry. +- This receipt updates only the Switchloom repository. The Planr repository is + intentionally unchanged until Goal B starts after review. + +## Handoff + +`docs/planr-hard-cut-handoff.md` is the durable Goal B oracle. Goal B should +consume released `switchloom@0.3.0` declarations or fixtures and remove Planr's +legacy routing compiler/catalog ownership without reintroducing a second source +of truth. diff --git a/retained-evidence/release-ready-v0.3.0/candidate.json b/retained-evidence/release-ready-v0.3.0/candidate.json new file mode 100644 index 0000000..1dfde7e --- /dev/null +++ b/retained-evidence/release-ready-v0.3.0/candidate.json @@ -0,0 +1,99 @@ +{ + "schema_version": 1, + "candidate_version": "0.3.0", + "source": { + "commit": "e936b90c81d8f944ba50657c10ef9a2a564c53c5", + "branch": "codex/switchloom-0.3.0-migration", + "dirty": false + }, + "packages": { + "cargo_crate": { + "path": "target/package/model-routing-0.3.0.crate", + "sha256": "e4b4c5975311478dfef345804c44c13a4b627d6beeb5f3be5d5f9099e5ed16eb", + "vcs_commit": "e936b90c81d8f944ba50657c10ef9a2a564c53c5", + "dirty": false + }, + "npm_tarball": { + "path": "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/switchloom-0.3.0.tgz", + "sha256": "23666bc68b3a1e892b0613733a9a843e789b4c3ae75c5106a706f17c5460f64d", + "shasum": "bba3978727825c17d18661b202c6c7abcb66c234", + "integrity": "sha512-uztvYnNlk5Pq/BghE1+Bp0AAztGi0zqvQvMj+h20T5N7tsqWw+r3rdzcUFfObH56srywloY/3yTc17MC40KHCg==" + }, + "darwin_arm64_native": { + "sha256": "b4dd82486d85f5b7a171cbc7b25836a99ad6c59d0fa0490acbfc18703f729c39", + "version_output": "model-routing 0.3.0" + }, + "darwin_arm64_archive": { + "path": "dist/switchloom-darwin-arm64.tar.gz", + "sha256": "d4fabca7b0f6abb96435462519bb6ddc1005d553bfa1801e56b2f7ab7f1e141f" + }, + "catalog_sha256": "eb405728b7a22436f3159774ce265ddbc604e12af7f59841a9e1a3dc26f630e0" + }, + "gates": { + "release_verify": "passed", + "cargo_inventory": "156 files; forbidden-path scan empty", + "npm_inventory": "16 files; forbidden-path scan empty", + "shellcheck": "passed", + "betterleaks": "passed; no leaks", + "trivy": "passed; zero Cargo vulnerabilities, secrets, or repository misconfigurations", + "standalone_lifecycle": "passed from freshly installed npm bytes", + "planr_mode_lifecycle": "passed from freshly installed npm bytes" + }, + "preservation": { + "standalone_unmanaged_sha256": "f6885ba9827675052bd56da1fcdcf82c8798444823583c461c84d8f0790ab696", + "planr_unmanaged_sha256": "f000713ad572d689efbce0c8b7257aa7d2e8d4b27405b228c2b1836c9837bad5", + "global_codex_config_sha256": "31d88604ab808d2bfec9264c379f4fd26e888eabc4a15cb2319d119c71e80606", + "protected_planr_commit": "bbc877d40191b2cbb289ed26df5e6fee25e4326d", + "protected_planr_status_sha256": "d6c56495c7e2a78aed2e641b0e928bc8a579bf31335db36456a9f05726827927" + }, + "supported_hosts": [ + "codex-openai", + "cursor-openai", + "cursor-fable-grok", + "claude-native", + "opencode-native", + "pi-external" + ], + "tested_hosts": [ + { + "host": "codex-openai", + "host_version": "codex-cli 0.144.5", + "result": "structured live receipt passed", + "receipt": "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/codex-openai/1784654270-96976-0" + }, + { + "host": "cursor-openai", + "host_version": "2026.07.17-3e2a980", + "result": "structured live receipt passed; requested routing is advisory", + "receipt": "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/cursor-openai/1784654493-22038-0" + }, + { + "host": "cursor-fable-grok", + "host_version": "2026.07.17-3e2a980", + "result": "structured live receipt passed; requested routing is advisory", + "receipt": "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/cursor-fable-grok/1784654511-23810-0" + } + ], + "skipped_hosts": [ + { + "host": "claude-native", + "host_version": "2.1.133 (Claude Code)", + "reason": "Claude effective model and effort telemetry is not treated as live verified", + "receipt": "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/claude-native/1784654534-22027-0" + }, + { + "host": "opencode-native", + "reason": "not required by this candidate's live-host gate; deterministic validator coverage passed" + }, + { + "host": "pi-external", + "reason": "not required by this candidate's live-host gate; deterministic validator coverage passed" + } + ], + "limitations": [ + "Only darwin-arm64 native/npm bytes were built locally; the four-platform native matrix remains CI-owned.", + "Cursor receipts prove nonce-correlated requested routing but the host exposes no authenticated effective model/effort telemetry.", + "Claude Code remains explicitly not live verified for effective model/effort telemetry.", + "No publication, tag, push, or deployment was performed." + ] +} diff --git a/retained-evidence/release-ready-v0.3.0/live/claude-native/1784654534-22027-0/certification-report.json b/retained-evidence/release-ready-v0.3.0/live/claude-native/1784654534-22027-0/certification-report.json new file mode 100644 index 0000000..17a3ace --- /dev/null +++ b/retained-evidence/release-ready-v0.3.0/live/claude-native/1784654534-22027-0/certification-report.json @@ -0,0 +1,12 @@ +{ + "schema_version": 1, + "host": "claude-native", + "success": true, + "live_verified": false, + "limitation": "Claude effective model/effort telemetry is not treated as live verified", + "restoration": { + "status": "not_required" + }, + "workdir": "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/claude-native/1784654534-22027-0/workdir", + "commands": [] +} diff --git a/retained-evidence/release-ready-v0.3.0/live/codex-openai/1784654270-96976-0/certification-report.json b/retained-evidence/release-ready-v0.3.0/live/codex-openai/1784654270-96976-0/certification-report.json new file mode 100644 index 0000000..0fec11d --- /dev/null +++ b/retained-evidence/release-ready-v0.3.0/live/codex-openai/1784654270-96976-0/certification-report.json @@ -0,0 +1,94 @@ +{ + "schema_version": 1, + "host": "codex-openai", + "success": true, + "live_verified": true, + "limitation": null, + "restoration": { + "status": "restored_explicitly" + }, + "workdir": "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/codex-openai/1784654270-96976-0/workdir", + "commands": [ + { + "label": "compile", + "argv": [ + "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/install/node_modules/switchloom/npm/native/darwin-arm64/model-routing", + "compile", + "balanced", + "--host", + "codex-openai", + "--output", + "bundle.json" + ], + "env_keys": [], + "stdout": "", + "stderr": "", + "status": 0, + "timed_out": false, + "elapsed_ms": 14 + }, + { + "label": "apply", + "argv": [ + "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/install/node_modules/switchloom/npm/native/darwin-arm64/model-routing", + "apply", + "bundle.json", + "--repository", + "." + ], + "env_keys": [], + "stdout": "{\n \"action\": \"apply\",\n \"bundle_id\": \"balanced-codex-openai@1.0.0+2.0.0\",\n \"repository\": \"/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/codex-openai/1784654270-96976-0/workdir\",\n \"artifacts\": [\n {\n \"path\": \".codex/agents/model-routing-luna-xhigh.toml\",\n \"mode\": \"create\",\n \"status\": \"create\",\n \"sha256\": \"c37a8a3419eab6a7769cdbafeebb09167ff1564ee713f52593ef4d4f7b97f1a5\"\n },\n {\n \"path\": \".codex/agents/model-routing-sol-high.toml\",\n \"mode\": \"create\",\n \"status\": \"create\",\n \"sha256\": \"b900c979282e69851720aa3f6c1ca1fd64cc9fc508d85b5c16f8017ede8d6752\"\n },\n {\n \"path\": \".codex/agents/model-routing-sol-medium.toml\",\n \"mode\": \"create\",\n \"status\": \"create\",\n \"sha256\": \"657975ea00e6363d52176969103234b2bfe119ee1fdc1d2a9c1332db7c3dbc35\"\n },\n {\n \"path\": \".codex/agents/model-routing-sol-ultra.toml\",\n \"mode\": \"create\",\n \"status\": \"create\",\n \"sha256\": \"92597594c9f31ab54fc7a6fe66bce9618bbe47d88a0a430532e6a402ede4602e\"\n },\n {\n \"path\": \".codex/agents/model-routing-terra-high.toml\",\n \"mode\": \"create\",\n \"status\": \"create\",\n \"sha256\": \"8a419febc4018ab64e840849f426c27d3cab268e9c579d5fa735e276e9e21c9d\"\n },\n {\n \"path\": \".codex/agents/model-routing-terra-medium.toml\",\n \"mode\": \"create\",\n \"status\": \"create\",\n \"sha256\": \"458cdc1750b5fabe2fa81c502c1decf0ba346644a595ecf75bcd3ac63d471464\"\n },\n {\n \"path\": \".codex/config.toml\",\n \"mode\": \"replace\",\n \"status\": \"create\",\n \"sha256\": \"38511fd94693a95ebcdb0d2ca65f414109b05835172729c35f91d70d20d3b60d\"\n }\n ]\n}\n", + "stderr": "", + "status": 0, + "timed_out": false, + "elapsed_ms": 157 + }, + { + "label": "codex-version", + "argv": [ + "codex", + "--version" + ], + "env_keys": [], + "stdout": "codex-cli 0.144.5\n", + "stderr": "", + "status": 0, + "timed_out": false, + "elapsed_ms": 583 + }, + { + "label": "codex-host", + "argv": [ + "codex", + "exec", + "--json", + "--ignore-user-config", + "-C", + "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/codex-openai/1784654270-96976-0/workdir", + "-s", + "workspace-write", + "-c", + "approval_policy=\"never\"", + "-c", + "projects.\"/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/codex-openai/1784654270-96976-0/workdir\".trust_level=\"trusted\"", + "-c", + "agents.model_routing_terra_high.config_file=\"/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/codex-openai/1784654270-96976-0/workdir/.codex/agents/model-routing-terra-high.toml\"", + "-c", + "agents.model_routing_sol_high.config_file=\"/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/codex-openai/1784654270-96976-0/workdir/.codex/agents/model-routing-sol-high.toml\"", + "-c", + "multi_agent_v2.hide_spawn_agent_metadata=false", + "-c", + "cli_auth_credentials_store=\"auto\"", + "-c", + "mcp_oauth_credentials_store=\"auto\"", + "Use the native collaboration spawn_agent tool exactly twice, then wait for both child agents to finish.\n\nYour first tool call must be spawn_agent with exactly these fields:\n- agent_type: model_routing_terra_high\n- task_name: standalone_implementer\n- fork_turns: none\n- message: Inspect the generated repository without editing files. End your final answer with SWITCHLOOM_STANDALONE_IMPLEMENTER_DONE.\n\nYour second tool call must be spawn_agent with exactly these fields:\n- agent_type: model_routing_sol_high\n- task_name: standalone_reviewer\n- fork_turns: none\n- message: Independently inspect the generated repository without editing files. End your final answer with SWITCHLOOM_STANDALONE_REVIEWER_DONE.\n\nDo not omit agent_type. Do not change either message. Do not pass model or reasoning_effort in either spawn call. Do not call wait_agent or answer before both spawn_agent calls have succeeded.\n\nAfter both children finish, return a short final answer containing:\nSWITCHLOOM_CODEX_RUNTIME_EVIDENCE_COMPLETE" + ], + "env_keys": [], + "stdout": "{\"type\":\"thread.started\",\"thread_id\":\"019f85af-1ba9-7080-b4fa-402fdce321b1\"}\n{\"type\":\"turn.started\"}\n{\"type\":\"item.started\",\"item\":{\"id\":\"item_0\",\"type\":\"collab_tool_call\",\"tool\":\"wait\",\"sender_thread_id\":\"019f85af-1ba9-7080-b4fa-402fdce321b1\",\"receiver_thread_ids\":[],\"prompt\":null,\"agents_states\":{},\"status\":\"in_progress\"}}\n{\"type\":\"item.completed\",\"item\":{\"id\":\"item_0\",\"type\":\"collab_tool_call\",\"tool\":\"wait\",\"sender_thread_id\":\"019f85af-1ba9-7080-b4fa-402fdce321b1\",\"receiver_thread_ids\":[],\"prompt\":null,\"agents_states\":{},\"status\":\"completed\"}}\n{\"type\":\"item.started\",\"item\":{\"id\":\"item_1\",\"type\":\"collab_tool_call\",\"tool\":\"wait\",\"sender_thread_id\":\"019f85af-1ba9-7080-b4fa-402fdce321b1\",\"receiver_thread_ids\":[],\"prompt\":null,\"agents_states\":{},\"status\":\"in_progress\"}}\n{\"type\":\"item.completed\",\"item\":{\"id\":\"item_1\",\"type\":\"collab_tool_call\",\"tool\":\"wait\",\"sender_thread_id\":\"019f85af-1ba9-7080-b4fa-402fdce321b1\",\"receiver_thread_ids\":[],\"prompt\":null,\"agents_states\":{},\"status\":\"completed\"}}\n{\"type\":\"item.completed\",\"item\":{\"id\":\"item_2\",\"type\":\"agent_message\",\"text\":\"SWITCHLOOM_CODEX_RUNTIME_EVIDENCE_COMPLETE\"}}\n{\"type\":\"turn.completed\",\"usage\":{\"input_tokens\":90823,\"cached_input_tokens\":73472,\"output_tokens\":279,\"reasoning_output_tokens\":80}}\n", + "stderr": "Reading additional input from stdin...\n2026-07-21T17:17:53.034251Z ERROR codex_models_manager::cache: failed to load models cache: missing field `supports_reasoning_summaries` at line 88 column 5\n2026-07-21T17:17:53.962500Z WARN codex_core_plugins::remote::remote_installed_plugin_sync: failed to download remote installed plugin bundle remote_plugin_id=plugin_asdk_app_6a0faef988b48191b843bac5cd170a9e plugin=convex marketplace=openai-curated-remote error=plugin.json name `app-6a0faef988b48191b843bac5cd170a9e` does not match marketplace plugin name `convex`\n2026-07-21T17:18:05.789452Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:08.171932Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:08.696455Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:10.941249Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:15.187483Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:17.153718Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:20.662374Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:25.214347Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:34.390975Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:40.528177Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:46.011241Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:49.100460Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:51.357552Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:55.282036Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:55.282259Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:55.614156Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:18:58.386311Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 86 column 5\n2026-07-21T17:19:02.258933Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 88 column 5\n2026-07-21T17:19:07.601408Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 88 column 5\n2026-07-21T17:19:19.665365Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 88 column 5\n2026-07-21T17:19:55.317589Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 88 column 5\n2026-07-21T17:20:18.935268Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 88 column 5\n2026-07-21T17:20:49.220088Z ERROR codex_models_manager::manager: failed to renew cache TTL: missing field `supports_reasoning_summaries` at line 88 column 5\n", + "status": 0, + "timed_out": false, + "elapsed_ms": 179007 + } + ] +} diff --git a/retained-evidence/release-ready-v0.3.0/live/codex-openai/1784654270-96976-0/workdir/codex-runtime-evidence.json b/retained-evidence/release-ready-v0.3.0/live/codex-openai/1784654270-96976-0/workdir/codex-runtime-evidence.json new file mode 100644 index 0000000..cbfce9e --- /dev/null +++ b/retained-evidence/release-ready-v0.3.0/live/codex-openai/1784654270-96976-0/workdir/codex-runtime-evidence.json @@ -0,0 +1,183 @@ +{ + "children": [ + { + "agent_type": "model_routing_terra_high", + "canonical_task": "/root/standalone_implementer", + "child_thread_id": "019f85af-49d0-7860-b948-44b5c34d6413", + "final_answer": { + "message_type": "FINAL_ANSWER" + }, + "input": { + "max_message_bytes": 512, + "message_bytes": 292, + "message_encoding": "codex-encrypted", + "message_plaintext_intent_sha256": "b37a696922196d76cb089319e9bb15ea6d183ab597876b5dc95978fe64abcc49", + "message_plaintext_verdict": "unsupported", + "message_sha256": "e87673cb95c6a1e06ff875a281d5889831a05f1979a4b2e1003764e9ef3abee2" + }, + "kind": "implementer", + "parent_thread_id": "019f85af-1ba9-7080-b4fa-402fdce321b1", + "profile": "codex-terra-high", + "session": { + "agent_path": "/root/standalone_implementer", + "agent_role": "model_routing_terra_high", + "parent_thread_id": "019f85af-1ba9-7080-b4fa-402fdce321b1", + "session_file": "rollout-2026-07-21T19-18-05-019f85af-49d0-7860-b948-44b5c34d6413.jsonl", + "thread_source": "subagent" + }, + "spawn": { + "agent_type": "model_routing_terra_high", + "call_id": "call_CPMYdb9RLRqdYSF9VmtNrZx2", + "fork_turns": "none", + "surface": "collaboration.spawn_agent", + "task_name": "standalone_implementer" + }, + "spawn_output": { + "agent_id": null, + "task_name": "/root/standalone_implementer" + }, + "state": { + "agent_path": "/root/standalone_implementer", + "agent_role": "model_routing_terra_high", + "cwd": "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/codex-openai/1784654270-96976-0/workdir", + "model": "gpt-5.6-terra", + "reasoning_effort": "high", + "thread_source": "subagent" + }, + "task_name": "standalone_implementer" + }, + { + "agent_type": "model_routing_sol_high", + "canonical_task": "/root/standalone_reviewer", + "child_thread_id": "019f85af-5594-7fa0-a9a3-ae6d27f399bc", + "final_answer": { + "message_type": "FINAL_ANSWER" + }, + "input": { + "max_message_bytes": 512, + "message_bytes": 292, + "message_encoding": "codex-encrypted", + "message_plaintext_intent_sha256": "1a6366f6f1f0a5a35c5a2b0849df9370bdebbddad073fe445a18ae47f8bf3834", + "message_plaintext_verdict": "unsupported", + "message_sha256": "98122c81d559df61a4c8f1da3c81d57536f4e49dbcc962668d4c47cb576a1b00" + }, + "kind": "reviewer", + "parent_thread_id": "019f85af-1ba9-7080-b4fa-402fdce321b1", + "profile": "codex-sol-high", + "session": { + "agent_path": "/root/standalone_reviewer", + "agent_role": "model_routing_sol_high", + "parent_thread_id": "019f85af-1ba9-7080-b4fa-402fdce321b1", + "session_file": "rollout-2026-07-21T19-18-08-019f85af-5594-7fa0-a9a3-ae6d27f399bc.jsonl", + "thread_source": "subagent" + }, + "spawn": { + "agent_type": "model_routing_sol_high", + "call_id": "call_lRdM1G8hGMLyVqqYJsIhHHjt", + "fork_turns": "none", + "surface": "collaboration.spawn_agent", + "task_name": "standalone_reviewer" + }, + "spawn_output": { + "agent_id": null, + "task_name": "/root/standalone_reviewer" + }, + "state": { + "agent_path": "/root/standalone_reviewer", + "agent_role": "model_routing_sol_high", + "cwd": "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/codex-openai/1784654270-96976-0/workdir", + "model": "gpt-5.6-sol", + "reasoning_effort": "high", + "thread_source": "subagent" + }, + "task_name": "standalone_reviewer" + } + ], + "dispatch_evidence": [ + { + "child_identity": { + "agent_role": "model_routing_terra_high", + "agent_type": "model_routing_terra_high", + "host": "codex", + "role": "implementer", + "task_name": "standalone_implementer" + }, + "effective_effort": "high", + "effective_model": "gpt-5.6-terra", + "host_version": "codex-cli 0.144.5", + "nonce": "019f85af-1ba9-7080-b4fa-402fdce321b1:019f85af-49d0-7860-b948-44b5c34d6413:call_CPMYdb9RLRqdYSF9VmtNrZx2", + "package_digest": "sha256:b4dd82486d85f5b7a171cbc7b25836a99ad6c59d0fa0490acbfc18703f729c39", + "raw_evidence_refs": [ + "codex-session:rollout-2026-07-21T19-17-53-019f85af-1ba9-7080-b4fa-402fdce321b1.jsonl", + "codex-session:rollout-2026-07-21T19-18-05-019f85af-49d0-7860-b948-44b5c34d6413.jsonl", + "state_5.sqlite:thread_spawn_edges:019f85af-1ba9-7080-b4fa-402fdce321b1:019f85af-49d0-7860-b948-44b5c34d6413", + "spawn_call:call_CPMYdb9RLRqdYSF9VmtNrZx2" + ], + "requested_dispatch": { + "agent_type": "model_routing_terra_high", + "effort": "high", + "fork_turns": { + "mode": "none" + }, + "max_message_bytes": 512, + "message_bytes": 292, + "message_encoding": "codex-encrypted", + "message_plaintext_intent_sha256": "b37a696922196d76cb089319e9bb15ea6d183ab597876b5dc95978fe64abcc49", + "message_plaintext_verdict": "unsupported", + "message_sha256": "e87673cb95c6a1e06ff875a281d5889831a05f1979a4b2e1003764e9ef3abee2", + "model": "gpt-5.6-terra", + "profile": "codex-terra-high", + "semantic_role": "implementer" + }, + "schema_version": 1, + "verdict": "deterministic" + }, + { + "child_identity": { + "agent_role": "model_routing_sol_high", + "agent_type": "model_routing_sol_high", + "host": "codex", + "role": "reviewer", + "task_name": "standalone_reviewer" + }, + "effective_effort": "high", + "effective_model": "gpt-5.6-sol", + "host_version": "codex-cli 0.144.5", + "nonce": "019f85af-1ba9-7080-b4fa-402fdce321b1:019f85af-5594-7fa0-a9a3-ae6d27f399bc:call_lRdM1G8hGMLyVqqYJsIhHHjt", + "package_digest": "sha256:b4dd82486d85f5b7a171cbc7b25836a99ad6c59d0fa0490acbfc18703f729c39", + "raw_evidence_refs": [ + "codex-session:rollout-2026-07-21T19-17-53-019f85af-1ba9-7080-b4fa-402fdce321b1.jsonl", + "codex-session:rollout-2026-07-21T19-18-08-019f85af-5594-7fa0-a9a3-ae6d27f399bc.jsonl", + "state_5.sqlite:thread_spawn_edges:019f85af-1ba9-7080-b4fa-402fdce321b1:019f85af-5594-7fa0-a9a3-ae6d27f399bc", + "spawn_call:call_lRdM1G8hGMLyVqqYJsIhHHjt" + ], + "requested_dispatch": { + "agent_type": "model_routing_sol_high", + "effort": "high", + "fork_turns": { + "mode": "none" + }, + "max_message_bytes": 512, + "message_bytes": 292, + "message_encoding": "codex-encrypted", + "message_plaintext_intent_sha256": "1a6366f6f1f0a5a35c5a2b0849df9370bdebbddad073fe445a18ae47f8bf3834", + "message_plaintext_verdict": "unsupported", + "message_sha256": "98122c81d559df61a4c8f1da3c81d57536f4e49dbcc962668d4c47cb576a1b00", + "model": "gpt-5.6-sol", + "profile": "codex-sol-high", + "semantic_role": "reviewer" + }, + "schema_version": 1, + "verdict": "deterministic" + } + ], + "run": { + "complete_marker": "SWITCHLOOM_CODEX_RUNTIME_EVIDENCE_COMPLETE", + "evidence_source": "codex_persisted_spawn_state", + "parent_session": "rollout-2026-07-21T19-17-53-019f85af-1ba9-7080-b4fa-402fdce321b1.jsonl", + "parent_thread_id": "019f85af-1ba9-7080-b4fa-402fdce321b1", + "status": "complete", + "workdir": "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/codex-openai/1784654270-96976-0/workdir" + }, + "schema_version": "switchloom.codex_runtime_evidence.v1" +} \ No newline at end of file diff --git a/retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/certification-report.json b/retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/certification-report.json new file mode 100644 index 0000000..4b956e0 --- /dev/null +++ b/retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/certification-report.json @@ -0,0 +1,79 @@ +{ + "schema_version": 1, + "host": "cursor-fable-grok", + "success": true, + "live_verified": true, + "limitation": "Cursor ran live but did not expose deterministic effective-model telemetry", + "restoration": { + "status": "not_required" + }, + "workdir": "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/cursor-fable-grok/1784654511-23810-0/workdir", + "commands": [ + { + "label": "compile", + "argv": [ + "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/install/node_modules/switchloom/npm/native/darwin-arm64/model-routing", + "compile", + "balanced", + "--host", + "cursor-fable-grok", + "--output", + "bundle.json" + ], + "env_keys": [], + "stdout": "", + "stderr": "", + "status": 0, + "timed_out": false, + "elapsed_ms": 56 + }, + { + "label": "apply", + "argv": [ + "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/install/node_modules/switchloom/npm/native/darwin-arm64/model-routing", + "apply", + "bundle.json", + "--repository", + "." + ], + "env_keys": [], + "stdout": "{\n \"action\": \"apply\",\n \"bundle_id\": \"balanced-cursor-fable-grok@1.0.0+1.0.0\",\n \"repository\": \"/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/cursor-fable-grok/1784654511-23810-0/workdir\",\n \"artifacts\": [\n {\n \"path\": \".cursor/agents/model-routing-preset-worker.md\",\n \"mode\": \"create\",\n \"status\": \"create\",\n \"sha256\": \"860be02449fecc58831944eec365caa1240bccc94366a02ec865c5178aea0d8c\"\n }\n ]\n}\n", + "stderr": "", + "status": 0, + "timed_out": false, + "elapsed_ms": 92 + }, + { + "label": "cursor-version", + "argv": [ + "cursor-agent", + "--version" + ], + "env_keys": [], + "stdout": "2026.07.17-3e2a980\n", + "stderr": "", + "status": 0, + "timed_out": false, + "elapsed_ms": 3523 + }, + { + "label": "cursor-host", + "argv": [ + "cursor-agent", + "--print", + "--output-format", + "json", + "--trust", + "--model", + "cursor-grok-4.5-medium", + "Return only this nonce and do not edit files: cursor-fc4820bb03cf0e4c29c70f8cc54a166d0f4f9175c086b4a076febc2497d27589" + ], + "env_keys": [], + "stdout": "{\"type\":\"result\",\"subtype\":\"success\",\"is_error\":false,\"duration_ms\":4151,\"duration_api_ms\":4151,\"result\":\"cursor-fc4820bb03cf0e4c29c70f8cc54a166d0f4f9175c086b4a076febc2497d27589\",\"session_id\":\"6e11c2e4-679d-488a-8b2e-806b9d619350\",\"request_id\":\"ffc46a6e-0d17-4da6-b317-48a537a92646\",\"usage\":{\"inputTokens\":13772,\"outputTokens\":72,\"cacheReadTokens\":5248,\"cacheWriteTokens\":0}}\n", + "stderr": "", + "status": 0, + "timed_out": false, + "elapsed_ms": 18248 + } + ] +} diff --git a/retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/workdir/dispatch-evidence.json b/retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/workdir/dispatch-evidence.json new file mode 100644 index 0000000..0289866 --- /dev/null +++ b/retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/workdir/dispatch-evidence.json @@ -0,0 +1,28 @@ +{ + "schema_version": 1, + "package_digest": "sha256:b4dd82486d85f5b7a171cbc7b25836a99ad6c59d0fa0490acbfc18703f729c39", + "host_version": "2026.07.17-3e2a980", + "requested_dispatch": { + "semantic_role": "worker", + "profile": "cursor-grok-worker", + "model": "cursor-grok-4.5-medium", + "agent_type": "model-routing-preset-worker", + "fork_turns": { + "mode": "none" + } + }, + "child_identity": { + "host": "cursor", + "role": "worker", + "agent_role": "model-routing-preset-worker", + "agent_type": "model-routing-preset-worker", + "task_name": "model-routing-preset-worker" + }, + "nonce": "cursor-fc4820bb03cf0e4c29c70f8cc54a166d0f4f9175c086b4a076febc2497d27589", + "raw_evidence_refs": [ + "requested-invocation:requested-invocation.json#argv", + "host-output:host-output.json", + "host-stderr:host-output.stderr" + ], + "verdict": "advisory" +} diff --git a/retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/workdir/host-output.json b/retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/workdir/host-output.json new file mode 100644 index 0000000..48b91b4 --- /dev/null +++ b/retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/workdir/host-output.json @@ -0,0 +1 @@ +{"type":"result","subtype":"success","is_error":false,"duration_ms":4151,"duration_api_ms":4151,"result":"cursor-fc4820bb03cf0e4c29c70f8cc54a166d0f4f9175c086b4a076febc2497d27589","session_id":"6e11c2e4-679d-488a-8b2e-806b9d619350","request_id":"ffc46a6e-0d17-4da6-b317-48a537a92646","usage":{"inputTokens":13772,"outputTokens":72,"cacheReadTokens":5248,"cacheWriteTokens":0}} diff --git a/retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/workdir/requested-invocation.json b/retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/workdir/requested-invocation.json new file mode 100644 index 0000000..49023b5 --- /dev/null +++ b/retained-evidence/release-ready-v0.3.0/live/cursor-fable-grok/1784654511-23810-0/workdir/requested-invocation.json @@ -0,0 +1,16 @@ +{ + "argv": [ + "cursor-agent", + "--print", + "--output-format", + "json", + "--trust", + "--model", + "cursor-grok-4.5-medium" + ], + "artifact_path": ".cursor/agents/model-routing-preset-worker.md", + "host": "cursor", + "mode": "live", + "nonce": "cursor-fc4820bb03cf0e4c29c70f8cc54a166d0f4f9175c086b4a076febc2497d27589", + "prompt": "Return only this nonce and do not edit files: cursor-fc4820bb03cf0e4c29c70f8cc54a166d0f4f9175c086b4a076febc2497d27589" +} diff --git a/retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/certification-report.json b/retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/certification-report.json new file mode 100644 index 0000000..c7ef0da --- /dev/null +++ b/retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/certification-report.json @@ -0,0 +1,79 @@ +{ + "schema_version": 1, + "host": "cursor-openai", + "success": true, + "live_verified": true, + "limitation": "Cursor ran live but did not expose deterministic effective-model telemetry", + "restoration": { + "status": "not_required" + }, + "workdir": "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/cursor-openai/1784654493-22038-0/workdir", + "commands": [ + { + "label": "compile", + "argv": [ + "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/install/node_modules/switchloom/npm/native/darwin-arm64/model-routing", + "compile", + "balanced", + "--host", + "cursor-openai", + "--output", + "bundle.json" + ], + "env_keys": [], + "stdout": "", + "stderr": "", + "status": 0, + "timed_out": false, + "elapsed_ms": 27 + }, + { + "label": "apply", + "argv": [ + "/private/tmp/switchloom-v0.3.0-candidate.hASKiy/install/node_modules/switchloom/npm/native/darwin-arm64/model-routing", + "apply", + "bundle.json", + "--repository", + "." + ], + "env_keys": [], + "stdout": "{\n \"action\": \"apply\",\n \"bundle_id\": \"balanced-cursor-openai@1.0.0+1.0.0\",\n \"repository\": \"/private/tmp/switchloom-v0.3.0-candidate.hASKiy/live/cursor-openai/1784654493-22038-0/workdir\",\n \"artifacts\": [\n {\n \"path\": \".cursor/agents/model-routing-preset-worker.md\",\n \"mode\": \"create\",\n \"status\": \"create\",\n \"sha256\": \"251cedbebfdaa13d3ce1a78fd4ca74e248b8a0822a1ad5684039881bb1e8eed9\"\n }\n ]\n}\n", + "stderr": "", + "status": 0, + "timed_out": false, + "elapsed_ms": 70 + }, + { + "label": "cursor-version", + "argv": [ + "cursor-agent", + "--version" + ], + "env_keys": [], + "stdout": "2026.07.17-3e2a980\n", + "stderr": "", + "status": 0, + "timed_out": false, + "elapsed_ms": 1922 + }, + { + "label": "cursor-host", + "argv": [ + "cursor-agent", + "--print", + "--output-format", + "json", + "--trust", + "--model", + "gpt-5.4-mini", + "Return only this nonce and do not edit files: cursor-ca900e62e38956c0534dbd4b4a22f4caef0be56da33acecae9df8afdf9f3e05f" + ], + "env_keys": [], + "stdout": "{\"type\":\"result\",\"subtype\":\"success\",\"is_error\":false,\"duration_ms\":4262,\"duration_api_ms\":4262,\"result\":\"cursor-ca900e62e38956c0534dbd4b4a22f4caef0be56da33acecae9df8afdf9f3e05f\",\"session_id\":\"ce45eb40-257f-42bc-b783-7949596cbb0e\",\"request_id\":\"9a41fbbf-23b6-414e-a773-d1d5723dfe3e\",\"usage\":{\"inputTokens\":20838,\"outputTokens\":63,\"cacheReadTokens\":0,\"cacheWriteTokens\":0}}\n", + "stderr": "", + "status": 0, + "timed_out": false, + "elapsed_ms": 14165 + } + ] +} diff --git a/retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/workdir/dispatch-evidence.json b/retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/workdir/dispatch-evidence.json new file mode 100644 index 0000000..e3e93b8 --- /dev/null +++ b/retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/workdir/dispatch-evidence.json @@ -0,0 +1,28 @@ +{ + "schema_version": 1, + "package_digest": "sha256:b4dd82486d85f5b7a171cbc7b25836a99ad6c59d0fa0490acbfc18703f729c39", + "host_version": "2026.07.17-3e2a980", + "requested_dispatch": { + "semantic_role": "worker", + "profile": "cursor-openai-worker", + "model": "gpt-5.4-mini", + "agent_type": "model-routing-preset-worker", + "fork_turns": { + "mode": "none" + } + }, + "child_identity": { + "host": "cursor", + "role": "worker", + "agent_role": "model-routing-preset-worker", + "agent_type": "model-routing-preset-worker", + "task_name": "model-routing-preset-worker" + }, + "nonce": "cursor-ca900e62e38956c0534dbd4b4a22f4caef0be56da33acecae9df8afdf9f3e05f", + "raw_evidence_refs": [ + "requested-invocation:requested-invocation.json#argv", + "host-output:host-output.json", + "host-stderr:host-output.stderr" + ], + "verdict": "advisory" +} diff --git a/retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/workdir/host-output.json b/retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/workdir/host-output.json new file mode 100644 index 0000000..64a03d1 --- /dev/null +++ b/retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/workdir/host-output.json @@ -0,0 +1 @@ +{"type":"result","subtype":"success","is_error":false,"duration_ms":4262,"duration_api_ms":4262,"result":"cursor-ca900e62e38956c0534dbd4b4a22f4caef0be56da33acecae9df8afdf9f3e05f","session_id":"ce45eb40-257f-42bc-b783-7949596cbb0e","request_id":"9a41fbbf-23b6-414e-a773-d1d5723dfe3e","usage":{"inputTokens":20838,"outputTokens":63,"cacheReadTokens":0,"cacheWriteTokens":0}} diff --git a/retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/workdir/requested-invocation.json b/retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/workdir/requested-invocation.json new file mode 100644 index 0000000..cf50688 --- /dev/null +++ b/retained-evidence/release-ready-v0.3.0/live/cursor-openai/1784654493-22038-0/workdir/requested-invocation.json @@ -0,0 +1,16 @@ +{ + "argv": [ + "cursor-agent", + "--print", + "--output-format", + "json", + "--trust", + "--model", + "gpt-5.4-mini" + ], + "artifact_path": ".cursor/agents/model-routing-preset-worker.md", + "host": "cursor", + "mode": "live", + "nonce": "cursor-ca900e62e38956c0534dbd4b4a22f4caef0be56da33acecae9df8afdf9f3e05f", + "prompt": "Return only this nonce and do not edit files: cursor-ca900e62e38956c0534dbd4b4a22f4caef0be56da33acecae9df8afdf9f3e05f" +}