clockgrove/factory
Coordinate local coding agents to turn GitHub issues into tested pull requests, with dependency-aware scheduling, validation, and restart recovery.
Changelog
Notable changes to Factory. See GitHub issues for upcoming work.
Unreleased
The current 2.x package and plugin manifest versions identify development snapshots;
they do not by themselves indicate a published or fully qualified release. The historical
v1.0.0 and v1.0.1 Git tags predate this development line. Consult
GitHub Releases for published release notes
and artifacts, and record the commit SHA when installing from source.
Documentation
-
Replace historical run ledgers with release procedures and supported-behavior guidance; keep raw qualification output outside Git and retain sanitized summaries with releases.
-
Refresh the README, contributor guidance, issue forms, and package/plugin descriptions for a clearer first-use experience and consistent positioning. Clarify development versioning and keep detailed operator guidance available from the README.
Fixed
-
Reconnect interrupted foreground calls to the exact non-terminal run and honor its durable cancellation before another compiler, graph, Work Item, or worker admission. Cancelled terminal history and unresolved model invocations now require explicit successor recovery instead of an implicit new run, while preserving unknown usage and discovery identity. (#386)
-
Recover an unchanged Objective whose original, fully accounted compiler run stopped before graph or Work Item projection. An explicitly bounded auto-repair successor carries the prior failure, authenticates its new graph before deriving execute-only Work Item authority, and preserves the predecessor terminal and cumulative accounting. (#390)
-
Let Director resolve natural-language Factory requests through bounded, read-only discovery of labelled or canonically titled open Objectives. Users no longer need an Objective number or MCP command name when one complete repository scan identifies the existing work unambiguously. Document direct installation of Factory's public skills with
npx skills add clockgrove/factory. (#387) -
Stream bounded management prompts to Codex CLI stdin instead of placing them in the process argument vector, so documentation-rich compilation and repair inputs do not fail with Linux
E2BIG. (#392) -
Use a portable bare shell command in MCP manifests so Agent Plugins loaders accept the bundled server instead of exposing only Factory skills. Preserve the startup launcher and its missing-Node diagnostic.
-
Remove speculative minute/hour GitHub mutation quotas that could delay completion and cancellation without a GitHub refusal. Concurrent Objectives retain shared request admission, concurrency and server-directed backoff. (#373)
-
Wake local repository discovery, active Supervisor commands, capacity admission and backend completion observation after their producers make progress. Preserve authenticated reads, quota/backoff and bounded cross-host polling without increasing idle GitHub traffic. (#361)
-
Bind publication to the exact tested commit and prebuilt release manifest. Readiness checks and direct publication validate ignored evidence without rebuilding or repacking the tested artifact.
-
Discover open and recently changed closed Objectives through GitHub filters, with bounded scheduling summaries instead of lifetime comment history. Exact request and run locators retain outstanding obligations after closure or restart; labels still grant no execution authority. (#349)
-
Observe confirmed sibling ref writes with a bounded targeted PR check before ordinary integration backoff, retaining exact-head authority and the external-CI discovery grace. Record write, observation and next-action timing without treating observation hints as merge permission. (#347)
-
Remove Octokit's hidden fixed write/notification/GraphQL pacing; Factory remains the owner of admission and reactive retries. Preserve HTTP-200 GraphQL refusal and partial-effect handling, and distinguish client pretransport from fetch-response diagnostic time. (#341)
-
Reconstruct the built-in local validator with its original local capacity identity, avoiding foreground escalation during validation while preserving shared reservation checks. (#319)
-
Small foreground runs can use bounded mutation bursts before sustained smoothing, retaining rolling limits, lease priority and server backoff. Concurrent foreground/controller instances share credential quota and refusal state while shutdown remains owner-local. Validation and review JSON checkpoints create their blobs inline with their trees, saving one request each without changing their Git objects. Process-local phase diagnostics report elapsed time, requests and aggregate admission/fence time. (#333)
-
Preserve live sibling workers while an admitted child's execution-to-validation capacity receipt is still being published. Exact in-flight claims wait for progress and a fresh Objective observation; unrelated or abandoned claims retain bounded refusal. (#319)
-
Active-run cancellation checks now scan bounded history once and then read overlapping comment deltas. Credential-shared governor/quota entries and live transport observers are never silently evicted; exceeding 16 credentials or 1,024 simultaneous observers fails clearly before transport. (#320)
-
Refresh the complete Objective snapshot when the shared-capacity journal proves that an exact reconstructed claim was already released. Bounded visibility-lag handling preserves validation failures and successful completion without resurrecting capacity; changed identities still fail closed. Reconciliation retains original claim ownership across lease renewal and cleanup. (#306)
-
Installed controller units now skip startup when their pinned launcher disappears, preventing plugin-cache eviction from causing an unbounded Node restart loop. Launcher refresh refuses active, transitioning, or unknown service state; status gives the exact unit and settlement-first repair action. Existing units require explicit reinstallation before cache eviction. (#302)
Added
-
Ship a canonical GitHub issue form for human-authored Objectives and document the explicit, repository-scoped request for adding it. Global plugin installation remains repository-neutral and does not install templates or hooks into arbitrary checkouts. (#383)
-
Change-sensitive repository discovery now reconstructs authenticated history once, consumes bounded issue/comment deltas with a control-ref backstop, reserves credential-shared GitHub quota for lease and cleanup traffic, and exposes bounded request/cycle telemetry. The default unchanged poll interval is one minute. (#313)
-
A provider-neutral durable quota-gate contract, with narrow GitHub Copilot classification at the local Codex adapter boundary. Factory preserves exact or explicitly unknown usage, stops automatic retries, and exposes one redacted human-action result through status and explain. (#283)
-
Make authenticated Objective and attempt deadlines authoritative across management dispatch, provider creation and installed checkpoint qualification. App Server and artifact-transfer v2 arms now separate Objective-bound reach eligibility from the post-proof hold; reached v1 evidence stays readable while unreached v1 arms fail closed. Management invocations retain the explicit Run Policy Work Item timeout as their inner process-stall bound while never exceeding the Objective remainder. Vercel cleanup uses a separate bounded stop-confirmation window and preserves timed-out cleanup as an unresolved provider resource. (#309)
-
Opt-in obligation-first compiler judgment and bounded draft repair, with immutable revisions, independent full-coverage review, exact accepted projection and per-invocation accounting. Report-only runs never dispatch implementation. Read-only compiler evaluation JSON/Markdown retains historical failures, unknown attribution, automated-label provenance and honest comparative-evidence boundaries; model-backed calibration and savings are not yet qualified.
-
Unify Work Item ownership and attempt admission in an issue-scoped CAS ledger, preserving original recovery identities and unknown liabilities through a permanent legacy-writer bridge.
-
Opt-in installed two-Objective refill and failure/conflict qualification scenarios, with exact peer provenance, original-work accounting and safe closeout requirements. Their presence does not imply a live qualification pass or measured throughput savings.
-
Fair same-machine multi-Objective sharing and concurrent regular-PR execution, with immutable peer provenance and serialized, independently revalidated integration.
-
Durable explicit App Server preparation, dispatch, terminal usage and same-attempt artifact recovery, plus an installed checkpoint scenario that proves continuation without another turn.
-
Existing LFS detection and verified local hydration, binary/media manifests, bounded streamed source/artifact content and immutable content-addressed transfer recovery.
-
Supplied-snapshot replay, hierarchical Linux capacity observation, grounded compiler economics, runtime delivery/consumption reporting and executable compiler/chat evaluation cases.
-
Opt-in installed Linux qualification that joins fresh npm and Codex plugin installs with disposable service lifecycle, bounded resource pressure, cancellation, and restart observations. Sanitized artifact-bound reports retain explicit physical-host and published-distribution gaps.
-
Immutable recovery-plan and predecessor-chain verification contracts, with authenticated request bindings and explicit cumulative allowance increments. Read-only successor proposals and exact plan approval are exposed through MCP and CLI, with controller-discovered, dual-lease adoption.
-
Read-only recovery assessment through chat/MCP and CLI, with graph/PR identity checks and historical cumulative accounting. Successor execution and additional spending require separate explicit authority; ordinary activation, resume, and retry cannot revive terminal runs.
-
Linux execution/validation scope reservations bound to an owned launcher generation, with independently observed cleanup and controlled service retirement under its existing restart policy.
-
GitHub-only control protocol with immutable compiled graphs, compare-and-swap leases, deterministic attempts, and restart reconstruction.
-
Repository controller and explicit Linux
systemdlifecycle. -
Official Codex SDK local backend with Codex CLI as the supported portable fallback.
-
Cost-aware Objective compiler, native sub-issue dependencies, adaptive local scheduling, priority, bounded cloud burst, independent validation, replay, explanations, and economic evidence.
-
Regular and native stacked pull-request delivery with exact-head validation and recovery.
-
Repeated-successor accounting and delivery lineage, native source-PR restoration, and leased reconciliation of completed source merges before execution can resume.
-
Daytona execution adapter and provider-neutral managed-agent contract.
-
Optional Labs adapter for Vercel Sandbox.
-
Formal npm package contract for
@clockgrove/factoryalongside the Agent Plugin. -
Provider-reported input/output/cached-input token breakdowns in existing durable receipts, with explicit partial-coverage reporting and unchanged model-token budget totals.
Changed
-
Installed App Server checkpoint/restart qualification now validates complete reservation, session, and artifact Git objects transiently but persists only bounded verification receipts. Receipts retain exact authority refs/OIDs, session and artifact identities, and observation time without duplicating admission ledgers or checkpoint documents in the evidence envelope. (#322)
-
Installed local MCP manifests now enter through a packaged Linux launcher that reports an actionable Codex host
PATHdiagnostic when Node.js cannot be resolved, while preserving the same bundled server and 38-tool surface when Node.js 20 or later is available. (#262) -
Repository controllers now preserve typed fatal causes behind redacted diagnostic codes and artifact-keyed fingerprints. Installed systemd units bind the exact Factory artifact identity, keep transient failures and generation retirement restartable, stop deterministic discovery, durable-state, configuration, launcher, and invariant crash loops, and expose fuse/restart state with the next operator action through status and doctor. (#314)
-
Recheck mutable workflow safety inside the transport fence, after mutation-queue admission and final publication-authority validation, immediately before feature-ref and pull-request dispatch. Unsafe or unstable observed bases fail closed; GitHub's irreducible non-atomic administrator-mutation boundary remains explicit and tracked in #301.
-
Recovery successor verification now builds one bounded, immutable event observation per authenticated repository snapshot and shares its validated canonical/digest index across chain, accounting, evidence, outcome, publication, resource, and sibling-refresh proofs. Large histories are indexed in abortable batches without the former 512-entry reparse cliff; standalone trailers and later repository reads still receive full validation and cannot inherit snapshot authority. (#285)
-
An adopted successor that terminally stops after fully accounted management compilation but before authenticated graph projection can now be recovered again. The next immutable plan carries the exact Objective, legacy constraints, policy, allowance, history, and unknown-usage liability while moving compilation authority only to the explicitly requested successor. Any execution effect, unresolved invocation, changed Work Item, surviving graph/projection ref, or conflicting chain evidence still fails closed with a graph-bootstrap-specific diagnostic. (#287)
-
Immutable graphs now carry host-derived, adapter-qualified repository-capability generations for validation operations created by ancestor artifacts. The Supervisor waits for the exact provider integration, resolves every operation against the protected base before reservation, and binds dispatch to the base commit/tree, packet, provider, operation, authority paths and runtime. Graph recovery re-derives canonical bindings and reuses the persisted graph without another compiler invocation; independent ready work is not suppressed by one unavailable generation. Graphs retain only abstract managed-runtime contracts; after persistence, exact content-addressed Node/npm, Node/pnpm, Bun, or uv/CPython receipts are selected and bound through
AttemptReservedto every local or isolated consumer, then reverified with source/provider lineage immediately before launch. Integrated-base consumers inherit their provider generation's authenticated reservation receipt rather than the mutable active default, and provider/current authority drift fails before dispatch. Historical provider comments must reproduce the complete immutable reservation trailer digest, including its runtime activation. Historical graphs with an omitted top-level runtime retain their exact persisted identity while a read-only abstract execution view preserves compatibility; only an exact authenticated record may be copied by reusing its blob object for recovery, while fresh/issue-only persistence and selected graph data remain invalid. Issue-only inspection retains every packet field, and foreground completion reconstructs the exact activated invocation. Active-pointer changes cannot move a generation or reserved attempt, and missing or corrupt selected bytes fail readiness closed without recompilation. If that protected source advances after reservation but before launch, the attempt is durably deferred and replanned without spending an implementation retry or worker-session allowance. Reservations retain the full immutable origin receipt, and explicitfactory toolchains restore RECEIPT.jsonreacquires that historical bundle without selecting latest or changing the active pointer. Each adapter performs one frozen hook-free setup, validates root and later operation generations, and rejects partial authority, unsafe commands, lifecycle hooks, workspace/lock drift and hostile ambient runtimes. The npm adapter retains one full official Node LTS distribution and attests both its native Node entrypoint and embeddednpm-cli.js, which executes only through that exact Node interpreter. It accepts bounded Node 22/npm 10 and Node 24/npm 11 pairs, exactdevEnginespins, lockfile v3, exact workspace members, canonical public registry SHA-512 dependencies, and finitenpm runvalidations. Bun ZIP extraction is in-process and uv carries exact official CPython bytes; neither depends on an ambient archive, package-manager, Python, or self-download path. Existing observed npm recipes remain host-bound unless an explicitnode-npmcapability selects the managed adapter. Missing Cargo, Go, ambient Python, or uncatalogued recipes remain explicit unsupported future-authority gates. Safe protected-push-only workflow artifacts may be published only after a parsed credential/permission review; unsafe ones are durably held before a ref or PR, and every workflow, action, manifest, lock or registry change remains human-only at the exact Git-diff merge boundary. Unmanaged isolated validators stop at the first failed command while successful plans still run to completion. Concurrent execution settlements are now claimed exactly once by either the progress wake or synchronous scheduler fence, preventing a reconciled human hold from being reinterpreted as a second drain failure. The same hold arriving during terminal drain deterministically changes the proposal to escalation, while late cleanup/accounting/resource uncertainty vetoes it. (#284, #289, #293, #291, #294) -
Interrupted accepted compiler-evaluation graphs now authenticate their pre-receipt restart through exact immutable draft-selection and per-stage accounting evidence, while ordinary compilation retains its single-invocation checkpoint requirement. Changed Objective input still blocks before projection or repeated model work. (#280)
-
Terminal-recovery startup-race fixtures now explicitly model the lease assertion added by graph preflight, preserving their offline boundary and proving acquire/assert/release ordering without a live GitHub fallback. (#281)
-
Status now returns a mandatory machine-readable operator action that permits monitoring only while autonomous progress remains possible. Terminal, rejected, paused, and recovery-authority gates say that no Factory work is active, stop recurring monitors, preserve the exact reason or unknown usage digest, and identify one next action. The Director asks once at human gates instead of repeatedly polling immutable state. (#278)
-
Fresh Objective startup now classifies empty, authenticated, or strictly adoptable Work Item graph input under the acquired lease before
FactoryRunStarted.factory_doctorexposes the same read-only classification; malformed or mixed pre-existing Work Items produce an actionableActivationRejectedreceipt without delivery, model, graph-mutation, or worker effects. A full Supervisor regression protects ordinary same-issue adoption. (#277) -
A deterministic current-run graph ref no longer bypasses the compiler when
GraphCompiledis absent. Pre-receipt restart now requires the graph's atomic compilation record plus the exact management dispatch and actual-usage closure; a historical graph copy must not claim a new compilation. An authenticated staged projection can still finish its one-way immutable-ref publication after a lost response. (#275) -
A graphless terminal run may now recover an Objective whose bounded, human-authored Work Items already exist. The recovery plan authenticates the Objective prose plus their issue identities, six-section core, order, and native dependency topology before any model call; compilation may only enrich those exact items, and projection updates their bodies without creating issues or edges. Interrupted compiler dispatch remains unknown usage and blocks replay, while partial body and graph/projection writes resume idempotently under the same successor authority. (#274)
-
Pull-request branch-policy preflight now understands GitHub's current required-reviewer, dismissal-restriction, and unattributed-Copilot-approval fields. Optional review metadata and conversation resolution no longer invent a human-approval requirement when zero approvals are configured; positive global, code-owner, last-push, or path-specific approvals still fail closed. (#271)
-
Status, explanation, and recovery assessment now expose the authenticated concrete terminal reason for the selected run, including recovery successors, bound to its run, sequence, timestamp, and SHA-256 digest. Successor escalation explanations also provide a stable code, recovery gate, evidence, and required action. (#267)
-
Coordinated release verification now fails before broad coverage when Linux systemd 254+ or its user-manager transport is unavailable, with one actionable host diagnostic. Deterministic injected regressions cover unavailable and available transports while the real host-containment suite stays enabled. (#258)
-
Codex management preflight now proves that its durable isolated-home root is usable, and ordinary Objective compilation persists model-invocation intent only after local backend preparation at the final dispatch boundary. Known pre-dispatch failures no longer create an invocation marker; existing markers still require exact actual usage and remain unknown otherwise. (#256)
-
Cancellation preserves a failed known-usage receipt publication after owned cleanup, preventing both normal terminal cancellation and controller lease release from hiding unresolved accounting. Explicitly approved successor policy differences no longer incorrectly block issue admission; exact authority, complete accounting and resource reconciliation remain required. (#240, #241)
-
GitHub writes now classify immutable object preparation separately from authoritative publication. Blob, tree, and commit staging retain pacing, quota, cancellation, payload, scope, and secret controls without an Objective lease read per object; refs, comments, issues, and pull requests still capture authority before queueing and recheck it at dispatch. Fresh Director receipts bind a stable writer operation, holder, epoch, and policy to the current Objective lease observation while preserving older producer and accounting epochs. (#224)
-
Repository-controller election loss now retires discovery, activation/recovery dispatch and election-scoped configuration without aborting otherwise-current Objective execution. Retired controllers await Supervisor completion and cleanup under the Objective's own writer epoch; explicit shutdown and platform safety stops retain their existing propagation. (#225)
-
Two-Objective qualification now separates ordinary useful-throughput evidence from the controller-expiry fault scenario. The ordinary path injects no delay or failure, accepts either authenticated refill lane, uses incremental repository comment reads only as wake hints, safely filters issue and pull-request conversations by canonical issue target, and requires bounded topology/terminal convergence plus fresh complete observations for acceptance and actions. Supervisor waits now wake on queued local completion, shared-capacity changes, or the earliest applicable retry without losing pre-listener changes. Qualification records the exact requested/resolved model policy and observed execution backends while leaving provider-returned settings and non-attributable quota explicitly unavailable. (#218)
-
Shared-capacity journals now compact only explicit releases into exact, fixed-depth Git-tree tombstones published by the existing short CAS transaction. Active and unresolved claims remain in the bounded snapshot, retired identities cannot be replayed or changed, and actionable retention pressure is reported before the unchanged hard limit. (#220)
-
Installed large-file qualification Objectives now select the repository-observed
npm testrecipe, and fresh version-2 fixtures provide a matching Vitest test instead of an incompatiblenode:testsuite. This makes the scenarios compile-ready without weakening command grounding or claiming that installed execution passed. (#203) -
Installed checkpoint qualification now evaluates observed-stop model budgets at each linked dispatch marker using actual usage known at that sequence. It preserves the pre-resume remaining allowance fence while permitting an already-admitted final invocation to report in-flight overshoot, and still fails closed on post-threshold admission or incomplete accounting. (#202)
-
GitHub mutation telemetry now identifies its process-local scope and scheduler-lifetime window, remains separate from durable run economics, and reports absent historical run measurements as unavailable instead of attributing a new reader process's zero counters. Current response-header primary quota observations remain available. (#199)
-
Objective compilation now replaces model-invented platform, CPU, memory, artifact-storage and timeout sizing with pinned repository evidence, active run-policy values or named portable defaults, and records that provenance in each compiled Work Item.
-
GitHub primary quota is cached from authoritative response headers per credential/resource, while the unobservable secondary content limit uses separately reported adaptive pacing based on actual transports and 403/429 feedback. This removes the fixed 226-normal-write hourly cliff, preserves lease priority and circuit breaking, coalesces adjacent validation budget reconciliations, and reports mutation/pacing overhead with runtime economics.
-
Objective compilation now explicitly classifies each criterion's risk and assigns it to an evidence-grounded mechanical, semantic, visual, or deterministic-simulation tier. Exact and protected-risk gates are no longer mechanically duplicated into semantic acceptance, while genuinely dual-tier criteria retain both checks and compiled Work Items explain the selection. Partial, legacy, or ungrounded routing fails closed by retaining semantic review for every criterion without a valid deterministic binding.
-
An authenticated cancellation of an already-started activation can retire exactly owned resources after an external branch advance, without granting execution on the changed base. Known work and usage are retained; unknown resource termination still refuses terminal cleanup. Unavailable native validation duration can retain an explicitly conservative reserved charge, never measured usage.
-
Installed session qualification generates a self-consistent single-worker policy, preserves bounded operator refusal details, and settles model dispatch markers only through their exact actual-usage receipts. Activation request journals retain their distinct identity; refreshed PR delivery requires original publication provenance and exact candidate validation/review proof.
-
New token-budget policies must explicitly choose observed stopping; unsupported hard token caps are rejected before model work, and historical recorded policies keep their original digest and recovery semantics. Status distinguishes budget intent from observed usage and enforceable caps.
-
Model dispatch intent is durably recorded before supervised calls. Unresolved consumption blocks unsafe repeated calls after restart without turning an intent marker into zero usage; exact retained checkpoints repair actual accounting. Use matching controller/plugin artifacts, not an older controller that ignores these fences.
-
New default runs use a fixed two-worker ceiling with physical resource safety checks. Adaptive concurrency remains explicitly selectable until its default-enablement qualification passes.
-
Successor recovery refreshes retained Factory-owned regular PRs after authenticated trunk advances, preserving the original artifact and paid acceptance history while independently validating and reviewing the exact changed head. Provider-owned branches remain outside this refresh authority.
-
Adopted ordinary and native-sibling candidates retain required independent isolation, with explicitly authorized Daytona validation, successor-bound resource ownership, native budget reservations and durable completion reuse. Known rejected validation releases its proven-terminated resource and preserves usage without becoming accepted work. Unknown termination still blocks replacement.
-
Isolated candidate and rebase validations share configured Daytona concurrency ceilings with execution workers; their invocation-specific reservation and recovery identities remain distinct.
-
Unknown completion after dispatch cannot authorize a replacement worker, including failure of the first durable artifact-copy write. Exact retained output reuses original accounting and validation allowances; corrupt evidence still escalates. Conservative native-duration charges remain distinct from measured usage, and unsupported cold App Server repair turns remain refused.
-
Provider support is capability-specific. An unsupported managed-provider interface no longer blocks Factory globally, and final provider invoice settlement is not required for proven execution completion. User-owned billing, unknown costs and exact active-resource safeguards remain explicit; unavailable Codex managed execution is never advertised as a working adapter.
-
Recovery and Copilot diagnostics distinguish the supported successor flow from unsafe implicit restart, and unassignment from actual session termination. Provider-cost summaries deduplicate receipt replay and reject contradictory or non-finite totals.
-
Existing local fault qualifiers use bounded REST calls, default authentication and exact absence observations for all same-run execution/validation reservations. Checkpoint restart requires an explicit per-scenario model allowance. These source corrections do not imply new live evidence.
-
Recovery shares bounded exact-OID content reads without caching mutable authority or resource observations. Platform refusals retain their retry boundary through proof reconstruction.
-
The repository controller settles ownership before abortable in-process quota cooldown and fresh acquisition. Queued calls respect the same boundary; quota failures do not cause restart storms.
-
After a delayed restart, already finished local work can receive Objective completion only with exact on-time delivery, review, accounting and fresh cleanup proof. The deadline is not extended; new execution, validation, review, merging and missing-receipt repair remain prohibited.
-
Completed original-local foreground work can prove launcher closure from exact authenticated completion chains plus fresh producer/host and reserved-scope observations. Missing, partial or conflicting evidence still blocks recovery; no service identity or command output is invented.
-
Accepted successor recovery requests and exact retries repair Objective discovery without creating another activation or allowance. Read-only assessment directs users to the explicit proposal path instead of incorrectly reporting successor execution as unavailable.
-
Clean plugin verification requires the exact enabled Codex installation receipt and cache path; an available-only listing or staged source directory cannot satisfy installation evidence.
-
Native linear-stack Daytona execution uses immutable, independently sandboxed rebase validation and separate paid capacity/accounting before semantic review. Runtime qualification remains open.
-
Native-mode independent siblings retain parallel execution after another Work Item in the same run advances trunk. Factory refreshes the owned branch with an immutable two-parent commit and exact non-force update, then independently validates and reviews its changed head. Original publication evidence and budget history remain unchanged; external advances still escalate.
-
Sibling tree preparation uses raw Git objects and a private index without running repository hooks, filters, or commands. Installed native qualification independently verifies refresh lineage, changed-head evidence, integration, dependent joins, and resource accounting.
-
Recovery inspection distinguishes graph-derived native-stack units from independent sibling PRs.
-
Local Codex execution is the default; paid execution is always explicitly authorized and bounded.
-
The supported runtime is Linux on native Linux, Windows WSL2, or a Linux guest hosted by macOS.
-
Compiler navigation guidance now reaches local CLI/SDK workers without expanding edit scope.
-
Factory acceptance review remains mandatory; external Copilot PR review is an optional second opinion, not an installation dependency or a substitute for acceptance evidence.
Security
-
Validation and budget receipts cannot be written using another run's reservation under a current lease; same-run fenced takeover remains supported.
-
New activations reject predecessor execution that cannot yet be adopted safely, including reservation refs with missing comments and startup races. Existing PRs and accounting remain untouched; installed successor qualification and complete delivery-lineage coverage remain open.
-
Rejected management output retains observed token usage, with checkpoint-first recovery and failed-invocation replay protection.
-
Workers are treated as untrusted artifact producers without GitHub mutation, merge, budget, or Director authority.
-
Credentials are stripped or brokered by name, artifacts are independently validated, mutations are fenced, and sandbox/managed execution requires native-unit budget limits.
Release gates
- Publish and clean-install the synchronized npm and Agent Plugin artifacts.
- Complete the native Linux, Windows WSL2, and macOS-hosted Linux matrix.
- Complete live native-stack, Daytona, GitHub Copilot, OpenAI Codex, and adversarial Objective runs.