Skip to content

Release 0.18.0: complete listings, accountable writes and verifiable facts - #45

Merged
renezander030 merged 11 commits into
mainfrom
release/0.18.0
Oct 8, 2026
Merged

renezander030 merged 11 commits into
mainfrom
release/0.18.0

Conversation

@renezander030

Copy link
Copy Markdown
Owner

Release candidate for 0.18.0: complete listings, accountable writes and verifiable facts. One commit per item; the CHANGELOG stays under Unreleased.

Changes

  1. Complete completed-task listings. ats tasks completed [DAYS] pages through the completion window past the backend's per-call limit, deduplicates boundary entries and reports pages and complete. A listing that stops at its page budget warns and fails --require-complete. The positional day count sets the window start.
  2. Actor on every write. Ledger records carry actor: { id, kind, session? } (agent, human, unattributed). A global --agent NAME names the acting agent for one invocation; ATS_ACTOR_KIND and ATS_SESSION_ID are honored. ats ledger list filters by --actor-kind and --session; history revisions show the actor.
  3. Fact source verification. ats kg verify [FACT_ID...] rechecks each active fact's source against the system that holds it: task://P/T and --task references through the active adapter, files on disk (existence and modification after the fact was learned), URLs with --network. Results are verified, changed, stale or unverifiable; stale or changed sources exit 2, and --propose-retract stages reviewed retractions.
  4. Lossless body normalization. The Goal+Log normalizer keeps every word it receives. A body it cannot restructure without loss is written verbatim and reports skipped: content-loss with the affected words. Writes warn when a body arrives as one line of literal \n sequences.
  5. Review separation of duties. ats review approve refuses a decision from the identity that staged the item, by reviewer name or acting agent, with exit 4. ATS_REVIEW_REQUIRE_HUMAN=1 also requires a human approver. Items record stagedActor and decidedActor, and approve|reject accept --note. Rejecting one's own proposal stays possible.
  6. Provenance policy for facts. kg propose --require-source any|checkable, or ATS_KG_REQUIRE_SOURCE with optional ATS_KG_REQUIRE_SOURCE_DOMAINS, refuses unsourced proposals with verdict unsourced and exit 4. checkable accepts the references kg verify can recheck. Batch proposals apply it per line.
  7. Lossless frontmatter updates. Obsidian and OKF updates rewrite only the keys they change; block lists, nested maps, comments, key case and unknown keys stay byte for byte. Values are quoted where needed and missing keys are appended.
  8. Hash-chained action ledger. Every record carries prevHash, the SHA-256 of the previous line. ats ledger verify checks the chain, names each break by line and exits 2; it prints head, and --expect-head HASH compares it with a value kept elsewhere. Entries written before chaining stay valid at the start of the file.
  9. Ratification tiers. kg propose --tier source-fact|action-record|statement|belief (and tier per batch line) records the kind of claim. kg pending shows each proposal's tier, counts per tier and filters with --tier; ratified facts and exports keep it in provenance.

Maintenance: the lockfile resolves proxy-addr 2.0.8 (GHSA-jqcg-44mw-7w3h, transitive via Express); npm audit reports 0 findings.

Verification

  • npm test passes: lint, PII and claims checks, 516/516 unit tests (494 on the base commit, +22 new), and the intent, Taskmaster, synthetic Beads and progress proofs.
  • New tests: adapter-ticktick/test/completed-pages.test.js, core/test/action-actor.test.js, core/test/kg-verify.test.js, core/test/ledger-chain.test.js (including entries over 64 KB), cli/test/kg-governance.test.js (verify, separation, policy, ledger verify and tiers through the binary), and additions to the routing, update-modes, task-format, Obsidian and OKF tests.
  • Smoke-tested read-only against a live TickTick account: tasks completed 60 returned 519 completions over 3 pages, marked complete, where 0.17.0 returns 200. ledger verify accepted an existing 5,015-entry ledger as unchained legacy entries with no breaks. kg verify ran clean on an empty store.

Review notes

  • Base: d6768dc (main). No other open PRs.
  • Touched: core (action-ledger, review-queue, kg-store, new kg-verify, task-format), cli (bin, parser, reliability), adapter-ticktick (completed listing), adapter-obsidian, adapter-okf, docs, lockfile. packages/mcp is untouched; MCP review approvals inherit the separation check from core.
  • Behavior to check: an agent process that sets ATS_AGENT_ID can no longer approve items staged under that same identity. The kg CLI test harness now approves from a separate reviewer environment.
  • Additive formats: ledger records gain actor and prevHash; review items gain stagedActor/decidedActor; completed listings gain pages/complete; fact provenance gains tier when one was given. Existing readers keep working.
  • cli/test/ticktick-routing.test.js takes about 21 s on its own, on both the base commit and this branch, which is close to the 30 s per-file limit; one parallel run on a loaded machine timed out once, and every later run passed.
  • No version bump, tag or publish in this PR.

tasks completed walks the completion window page by page, deduplicates
boundary ties, and reports pages and complete. A listing that stops at
the page budget carries a warning and fails --require-complete. The
positional day count now sets the window start.
Ledger records carry actor { id, kind, session? }. A global --agent names
the acting agent for every write in one invocation; ATS_ACTOR_KIND and
ATS_SESSION_ID are honored. ledger list filters by --actor-kind and
--session, and history revisions show the actor.
ats kg verify rechecks every active fact's source: task references through
the active adapter, file paths by existence and modification after the
fact was learned, and URLs with --network. Results are verified, changed,
stale or unverifiable; any stale or changed source exits 2, and
--propose-retract stages a reviewed retraction for each stale fact.
The Goal+Log normalizer checks that every word of the input survives in
its output. A body it cannot restructure without loss is written verbatim
and the result reports skipped: content-loss with the affected words.
Writes warn when a body arrives as one line of literal \n sequences.
…item

review approve refuses a decision from the staging identity, by name or by
the acting agent, with exit 4. ATS_REVIEW_REQUIRE_HUMAN=1 also refuses
approvals from a process acting as an agent. Items record the staging and
deciding actor, and approve/reject accept --note.
kg propose --require-source any|checkable, or ATS_KG_REQUIRE_SOURCE with an
optional ATS_KG_REQUIRE_SOURCE_DOMAINS list, refuses a proposal without a
source with verdict unsourced and exit 4. checkable accepts the task, file
and URL references kg verify can recheck. Batch proposals apply the same
policy per line.
Note and concept updates rewrite only the keys they change. Block lists,
nested maps, comments, key case and unknown keys stay byte for byte;
values that need it are quoted, and missing keys are appended.
Every ledger record carries prevHash, the SHA-256 of the line before it.
ats ledger verify checks the chain, reports each break with its line and
exits 2; it prints head, the hash of the last entry, and --expect-head
compares it with a value kept elsewhere. Entries written before chaining
stay valid at the start of the file.
kg propose --tier source-fact|action-record|statement|belief (and a tier
field per batch line) records what kind of claim a proposal makes. kg
pending shows each proposal's tier, counts per tier and filters with
--tier; ratified facts keep the tier in their provenance and exports.
Refresh the transitive Express dependency to the patched release; npm
audit reports no findings.
Changelog entries, README examples and reliability notes for complete
completed listings, actors, ledger verification, fact source verification,
provenance policy, review separation, ratification tiers and lossless
normalization.
@renezander030
renezander030 merged commit e38f4d9 into main Oct 8, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant