release-candidate: complete Windows-first roadmap - #30
duc15052006-dotcom wants to merge 1174 commits into
Conversation
Verification checkpoint — 2026-09-18Current release-candidate head: Static/review work completed since the previous checkpoint:
Hosted verification is not green or verified:
Do not merge #30 until CI + Desktop + protected Windows signing/exact signed-installer acceptance provide actual workflow evidence. |
Actions blocker identifiedThe repository API confirms this repository is a public fork created 2026-09-17. GitHub Actions reports 0 workflow runs for GitHub's fork behavior explains this state: workflows in forked repositories do not run by default until Actions is enabled for the fork. This is now the primary external verification blocker. The release-candidate must remain unmerged until Actions is enabled and the final head receives real CI/Desktop results; protected |
Verification checkpoint updateCurrent head: Additional release blockers closed:
Current aggregate size: 328 commits, 119 changed files. Hosted verification remains blocked externally:
Keep #30 unmerged until a post-enable synchronize/push produces real CI + Desktop evidence and the protected Windows signing acceptance is exercised. |
Product checkpoint: local resource, browser, persistence, safety, and scheduled wakeKeep these requirements before final release:
User hardware target discussed for local-first acceptance: i5-12500H, RTX 3050 4GB, 16GB DDR4, 512GB SSD. Resource controls should make it practical to stop all Bots before gaming and resume later. |
|
Integrated teammate-orchestration improvements from PR #65 at What changed:
Security/runtime boundaries were not widened: shell policy, Computer sandboxing, quarantine/ClamAV, credentials and resource controls are unchanged. Verification on the integrated release-candidate SHA:
A duplicate Desktop #110 was still running when this note was posted; Desktop #111 is the equivalent complete successful run on the same SHA. |
Signing bootstrap advanced — 2026-09-27Current exact release head: Newly integrated:
Protected signing was explicitly triggered on this exact head:
This materially narrows the signing blocker: GitHub Environment variables and an Azure subscription id are no longer required. The remaining signing prerequisite is Azure/Entra-side trust: an authorized owner/administrator of the existing Entra application must add the credential defined in The Real Intelligence smoke still has no passing evidence recorded. Do not merge #30 into main yet. Remaining mandatory external gates:
|
…n-bootstrap-helper chore(signing): add safe Entra federation bootstrap helper
Entra federation bootstrap helper integrated — 2026-09-27Current exact release head: Newly integrated:
Verification:
The previous protected signing CopilotKit#243 already proved GitHub now emits the expected immutable OIDC subject and that the workflow reaches Do not re-trigger protected signing until that Azure federation credential is present. Once an authorized Entra app owner/admin runs the helper successfully, reapply Real Intelligence smoke still has no passing evidence recorded. Do not merge #30 into main yet. Remaining mandatory external gates:
|
Post-release roadmap note recorded: Agent EconomyA future architecture note has been stored separately from the release branch:
The design was cross-checked against This roadmap branch is not part of the current release candidate and must not be merged into #30 before the current release gates complete. GitHub Issues are disabled for this repository (the create-issue API returns 410), so this PR comment is only a discoverability pointer; it does not add a release requirement. |
Agent Economy roadmap completed through E7 — isolated from releaseThe post-release Merged roadmap PRs:
Current roadmap head: The final E7 PR #149 passed:
No Agent Economy feature PR remains open. The roadmap stays isolated and is not part of PR #30. Release PR #30 remains blocked only by its existing external mandatory gates:
Do not merge #30 into |
Agent Economy hardening update — 2026-09-28LIVE refresh confirmed the Agent Economy roadmap has advanced beyond the earlier E7 completion note.
PR #150 closes the transient Owner-confirmation gap by requiring persisted, append-only Owner approvals bound to the payment intent, Agent and policy version, with approval reloaded before prepare and again immediately before external execution. This remains isolated from
|
Agent Economy production hardening advanced — 2026-09-28The isolated Merged:
#151 turns persisted Owner approval into a real server-side boundary: Agent id, policy version and Owner identity are derived from durable database state; only intents that actually require Owner confirmation can be approved; retries are idempotent; cross-Owner access is hidden/fail-closed; and the authenticated API accepts no caller-supplied Agent/Owner/policy identity. This remains outside |
Agent Economy approval privacy + audit hardening merged — 2026-09-28The isolated Merged:
Security fix:
Audit hardening:
This remains isolated from PR #30 remains blocked only by the two external mandatory gates:
Do not merge #30 into |
Agent Economy execution + receipt durability hardening merged — 2026-09-28The isolated Merged #153 —
Merged #154 —
New roadmap head: This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy Circle finality hardening merged — 2026-09-28The isolated Merged:
Security change:
This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy receipt integrity hardening merged — 2026-09-28The isolated Merged:
Security/durability changes:
This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy deleted-Agent approval hardening merged — 2026-09-28The isolated Merged:
Security change:
This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy durable payment audit merged — 2026-09-28The isolated Merged:
Audit/durability changes:
This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy Owner payout accounting recovery merged — 2026-09-28The isolated Merged:
Durability/accounting changes:
This closes the crash window where external money movement could succeed while Owner payout/ledger history remained incomplete. This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy durable intent binding merged — 2026-09-28The isolated Merged:
Security changes:
This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy canonical payment intent creation merged — 2026-09-28The isolated Merged:
Integrity changes:
This complements #160: execution is now bound to durable intent state, and #161 provides the canonical server-authoritative path that creates that durable state. This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy server-owned payment policy snapshot hardening merged — 2026-09-28The isolated Merged:
Security/integrity changes:
This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy verified child funding persistence merged — 2026-09-28The isolated Merged:
E6 durability/safety changes:
This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy durable financial policy snapshot loader merged — 2026-09-28The isolated Merged:
Production-wiring changes:
This complements #161/#162: canonical payment-intent creation now has a real durable server-owned source for policy/balance/spend instead of requiring request-supplied state. This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy canonical Owner payment-intent route merged — 2026-09-28The isolated Merged:
Production wiring changes:
This closes the production-wiring gap between #161/#162/#164 and the live HTTP server. This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy live execution chain advanced through #166–#169 — 2026-09-29The isolated Merged sequence:
New roadmap head:
Production capability now includes:
This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy recovery-safe live child funding merged — 2026-09-29The isolated Merged:
E6 production changes:
This closes the previously documented reason CHILD_FUNDING was intentionally not live-executed. This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy payment reconciliation worker merged — 2026-09-29The isolated Merged sequence:
Reconciliation changes:
This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy reconciliation pagination hardening merged — 2026-09-29The isolated Merged:
Hardening changes:
This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Agent Economy cluster-safe payment reconciliation merged — 2026-09-29The isolated Merged:
Cluster/restart hardening:
This closes the duplicate-cluster execution and in-memory-cursor reset gaps left after #173/#174. This remains isolated from PR #30 release readiness is unchanged. Do not merge #30 until both external gates pass:
|
Purpose
This is the aggregate release-candidate PR from
verify/release-candidatetomain. It contains the complete stacked implementation so the repository can be reviewed and verified as one product change instead of requiring more than twenty dependent merges before CI can see the final tree.Included roadmap work
Verification lane
The head branch is under
verify/**, so push-triggered CI is enabled as a fallback when pull-request events are suppressed. This PR itself also gives the final combined tree a normalpull_requesttarget againstmain, which should trigger the standard CI and Desktop workflows.Merge guidance
Do not merge this release-candidate PR until the full CI/Desktop workflows are green and the protected Windows signing/release acceptance required by the release process has been exercised where applicable.
The earlier stacked PRs remain useful as review-sized slices, but this aggregate PR is the authoritative final-tree verification target.
Final release blockers
Exact verified release-candidate head:
3528ad9ea55987b6ea9939452807962113cbf1f0.Protected Windows signing — Azure federation remaining
azure/loginsuccessfully with the expected client/tenant/vault/certificate configuration.AADSTS700213: no matching federated identity record exists for this repository's immutablewindows-signingenvironment subject.desktop/signing/azure-federation.json.Real Intelligence smoke
docs/releasing.md/tests/smoke.Before the merge, also confirm
mainbranch protection requires aggregateverifyand keep an independent source backup/mirror.Do not merge this PR into
mainuntil both mandatory gates pass on the exact release head.