Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
544 commits
Select commit Hold shift + click to select a range
edf1e2a
test(secrets): converge secret-file authority proof
Jul 16, 2026
0ee3273
fix(secrets): converge descriptor-bound file authority
Jul 16, 2026
19d6ea1
test(secrets): prove rendering and token validation authority
Jul 16, 2026
f677507
fix(secrets): close rendering and token validation gaps
Jul 16, 2026
a6ba482
test(telegram): use grammar-valid synthetic bot tokens
Jul 16, 2026
0092a8f
test(secrets): prove keychain health authority
Jul 16, 2026
67241ac
fix(secrets): expose sanitized keychain health failure
Jul 16, 2026
8c5bc23
test(system-map): prove ordered collection authority
Jul 16, 2026
dc55ebe
fix(system-map): preserve ordered tuple inputs
Jul 16, 2026
a5c53e0
test(authority): prove Spark-home and SSH target boundaries
Jul 16, 2026
6db38ba
fix(authority): separate Spark-home and SSH target trust
Jul 16, 2026
1885ef6
test(builder): prove memory smoke failure privacy
Jul 16, 2026
f2f1888
fix(builder): make memory smoke failures nonreflecting
Jul 16, 2026
aa2f211
test(cli): lock operator guidance safety
Jul 16, 2026
4200daa
fix(cli): make operator guidance production-safe
Jul 16, 2026
02c9799
fix(cli): keep Telegram token repair shell-safe
Jul 16, 2026
16a129c
test(cli): lock security-audit runtime truth
Jul 16, 2026
70c733d
fix(cli): report failed runtime audits truthfully
Jul 16, 2026
18fd755
test(ssh): lock remote target local-address boundary
Jul 16, 2026
c733c75
fix(ssh): reject local-only remote targets
Jul 16, 2026
9a8de94
test(cli): lock runtime-shim temp-file authority
Jul 16, 2026
84d1a24
fix(cli): create runtime shims through private temp files
Jul 16, 2026
d417881
fix(cli): keep exclusive shim writes path-native
Jul 16, 2026
e9d3a88
test(cli): preserve PR 112 private env intent
Jul 16, 2026
092ea49
fix(cli): write generated env files privately and atomically
Jul 16, 2026
c694f81
test(approval): preserve PR 119 inspection intent
Jul 16, 2026
d1e6280
fix(approval): parse read-only startup inspection actions
Jul 16, 2026
b8a4e85
test(approval): preserve outbound transfer donor intent
Jul 16, 2026
be46f2b
fix(approval): parse outbound transfer direction
Jul 16, 2026
7eaa221
test(approval): preserve publication family donor intent
Jul 16, 2026
6f66d1f
fix(approval): parse external publication actions
Jul 16, 2026
92aefc4
test(approval): preserve infrastructure publication intent
Jul 16, 2026
1822d40
fix(approval): cover infrastructure publication actions
Jul 16, 2026
868b58a
test(env): preserve normalization source intents
Jul 16, 2026
eb53bd2
test(security): preserve prompt scanner bypass intents
Jul 16, 2026
88a8ab7
fix(security): harden prompt override scanning
Jul 16, 2026
554931b
test(storage): preserve private JSON creation authority
Jul 16, 2026
fee4617
fix(storage): create JSON state through private writer
Jul 16, 2026
fbd50d9
test(sandbox): preserve Docker resource authority
Jul 16, 2026
67f650d
fix(sandbox): enforce bounded Docker resources
Jul 16, 2026
6365338
test(installer): preserve copyable Windows checks
Jul 16, 2026
e2b77ac
fix(installer): print path-independent Windows checks
Jul 16, 2026
dbfb281
test(git): preserve remote argument authority
Jul 16, 2026
e832802
fix(git): centralize remote argument authority
Jul 16, 2026
df796be
test: retain PR 171 raw approval bypass cases
Jul 16, 2026
7852a08
fix: parse raw approval text at the CLI boundary
Jul 16, 2026
dd9cb1d
test: retain PR 172 SSH authority finding
Jul 16, 2026
98eca7e
fix: classify typed SSH remote access
Jul 16, 2026
0bfdff5
test: retain PR 173 live failure truth
Jul 16, 2026
dd0c2c9
fix: preserve Spark Live startup failure truth
Jul 16, 2026
24b0c68
test: retain PR 175 structured redaction gaps
Jul 16, 2026
b680178
fix: close structured and bearer redaction gaps
Jul 16, 2026
fb71cdc
test: retain PR 180 unconfigured role truth
Jul 16, 2026
ea8f744
fix: expose typed unconfigured provider roles
Jul 16, 2026
e6a0198
test: retain PR 181 bounded log findings
Jul 16, 2026
cc8c03c
fix: bound process log retention and tail reads
Jul 16, 2026
3928bb2
test(cli): capture effective Spawner control env
Jul 16, 2026
04bff81
fix(cli): audit effective Spawner control env
Jul 16, 2026
3084240
test(cli): preserve repo directory identity
Jul 16, 2026
aa23e6e
test(cli): cover Character and Researcher owners
Jul 16, 2026
b783fc0
fix(cli): name Character and Researcher owners
Jul 16, 2026
5d0d839
test(installer): cover broken Windows Python alias
Jul 16, 2026
996c8f7
fix(installer): fall through broken Python aliases
Jul 16, 2026
5ef8543
chore(installer): refresh local PowerShell integrity
Jul 16, 2026
847d891
test(approval): cover setup credential authority
Jul 16, 2026
dfb21e9
fix(approval): gate setup credential authority
Jul 16, 2026
192a37a
test(init): require truthful agent contract scaffold
Jul 16, 2026
797925c
feat(init): scaffold truthful agent contracts
Jul 16, 2026
171bdc7
test(secrets): exercise machine-readable list output
driasim Jun 3, 2026
d8edfa6
feat(secrets): add value-free JSON listing
Jul 15, 2026
d3c6cb2
test(secrets): preserve PR 278 plain-list compatibility
Jul 16, 2026
24da4fb
test(secrets): preserve PR 289 JSON presence contract
Jul 16, 2026
085d5f9
feat(secrets): expose value-free JSON presence
Jul 16, 2026
03ae76c
test: preserve installed authority source coverage
Jul 16, 2026
a56988a
test(approval): preserve privileged shell severity
Jul 16, 2026
c2180c5
fix(approval): classify privileged shell launches
Jul 16, 2026
b88b338
test(cli): preserve guide and hosted installer routing
Jul 16, 2026
57e563c
fix(cli): route guide topics and hosted installer verification
Jul 16, 2026
c66570a
test(cli): align guide command reference
Jul 16, 2026
109a042
test(approval): preserve executable normalization
Jul 16, 2026
4dde192
test(approval): align normalized Spark credential policy
Jul 16, 2026
22e1947
fix(approval): normalize executable identity once
Jul 16, 2026
308ee98
test(approval): preserve deep verify enforcement
Jul 16, 2026
53979e6
fix(approval): enforce deep verification consent
Jul 16, 2026
91c599e
test(security): preserve revoke-all state authority
Jul 16, 2026
b6b6d5c
fix(security): constrain revoke-all state authority
Jul 16, 2026
e120c91
test(approval): preserve interpreter inline execution gate
Jul 16, 2026
679112f
fix(approval): gate inline shell execution
Jul 16, 2026
780220a
test(security): preserve private env creation authority
Jul 16, 2026
c9b6c63
fix(security): converge private env file writes
Jul 16, 2026
03ce833
merge: converge R30 with latest master
Jul 16, 2026
c271039
test(runtime): preserve Windows command paths and managed tools
Jul 16, 2026
7cf3f0c
fix(runtime): own Windows paths and managed Node
Jul 16, 2026
1a68463
test(approval): preserve wrapper command authority
Jul 16, 2026
c994abb
fix(approval): parse wrapper command authority
Jul 16, 2026
b0d95a8
test(os): preserve machine-readable command success
Jul 16, 2026
7315d94
fix(os): expose command success in JSON
Jul 16, 2026
cfa7bd4
refactor(os): hold command owners to line ratchet
Jul 16, 2026
686f5e7
test(json): preserve OS and support success contracts
Jul 16, 2026
b370401
fix(json): complete OS and support success contracts
Jul 16, 2026
b429639
test(status): preserve Telegram and autostart work truth
Jul 16, 2026
1ca2d64
fix(status): expose fresh Telegram and autostart truth
Jul 16, 2026
a81941a
test(cli): advertise Telegram status route
Jul 16, 2026
328e503
test(approval): preserve read-only CLI routes
Jul 16, 2026
d687dab
fix(approval): preserve read-only route authority
Jul 16, 2026
71eb864
test(config): preserve structured get semantics
Jul 16, 2026
e9134bf
fix(config): expose typed get truth
Jul 16, 2026
67eae36
test(providers): preserve JSON success routes
Jul 16, 2026
bcfd39c
test(secrets): preserve provider keys outside generated env
Jul 16, 2026
f4a4bc4
test(secrets): keep log repair truth scoped
Jul 16, 2026
704459d
fix(secrets): keep provider keys out of generated env
Jul 16, 2026
728f4c1
test(health): preserve actionable repair summaries
Jul 16, 2026
53b515e
fix(health): keep command summaries actionable
Jul 16, 2026
8f60c3d
test(health): keep failure details share-safe
Jul 16, 2026
755c7c0
fix(health): normalize private failure details
Jul 16, 2026
f6b04f8
test(paths): preserve governed output boundaries
Jul 16, 2026
b1d166f
fix(paths): govern explicit diagnostic outputs
Jul 16, 2026
d3dcda7
refactor(paths): keep system map at its ratchet
Jul 16, 2026
9d5e7a6
test(ci): lock CodeQL action provenance
Jul 16, 2026
0523f01
ci: update CodeQL action to v4.37.1
Jul 16, 2026
4ab579e
test(spawner): preserve mission provider credentials
Jul 16, 2026
e577653
fix(spawner): resolve mission credentials at runtime
Jul 16, 2026
6c733b0
test(telegram): preserve unverified health truth
Jul 16, 2026
f7d21e9
fix(telegram): keep declined health probes unverified
Jul 16, 2026
1e8effb
test(providers): separate configuration from live health
Jul 16, 2026
d58ea7d
fix(providers): separate configured from live readiness
Jul 16, 2026
8c37d44
test(approval): preserve host mutation authority
Jul 16, 2026
7d0bb46
fix(approval): classify host mutation authority
Jul 16, 2026
636f2aa
refactor(approval): hold host authority to ratchet
Jul 16, 2026
31e9ab2
test(installer): preserve Spark-home secret ref confinement
Jul 16, 2026
cb84920
test(secrets): preserve invalid-input authority reports
Jul 16, 2026
42565a7
fix(secrets): enforce typed input authority
Jul 16, 2026
51b9beb
refactor(secrets): isolate typed input authority
Jul 16, 2026
9944967
test(secrets): keep typed authority fixtures scoped
Jul 16, 2026
8d271bd
test(env): preserve configuration authority reports
Jul 16, 2026
38d9afd
fix(env): enforce single-line atomic file authority
Jul 16, 2026
5c8fc61
test(secrets): preserve plural listing source
Jul 16, 2026
db08fd1
test(cli): preserve machine output reports
Jul 16, 2026
00469f8
feat(cli): govern machine-readable output
Jul 16, 2026
d7ff281
test(sandbox): preserve structured redaction reports
Jul 16, 2026
37c85cc
fix(sandbox): redact structured secret surfaces
Jul 16, 2026
274da29
test(secrets): preserve insecure storage warning
Jul 16, 2026
942f6b8
fix(secrets): surface insecure storage once
Jul 16, 2026
47a3458
test(secrets): preserve backend index parity
Jul 16, 2026
5facc92
fix(secrets): retain index until full deletion
Jul 16, 2026
86b78ed
test(secrets): preserve clipboard decoding authority
Jul 16, 2026
27a7ac7
fix(secrets): decode clipboard helpers without corruption
Jul 16, 2026
238070e
test(git): require bounded subprocess authority
Jul 16, 2026
e3d250c
fix(git): bound module lifecycle operations
Jul 16, 2026
76cd7d6
test(logs): preserve redaction write authority
Jul 16, 2026
f29862d
fix(logs): gate and atomically redact inactive files
Jul 16, 2026
0566aa9
test(secrets): capture hardened file authority gaps
Jul 16, 2026
39e9a62
fix(secrets): enforce bounded file hardening truth
Jul 16, 2026
a2ef8bf
test(secrets): keep hardening coverage off god file
Jul 16, 2026
47e65f9
test(secrets): capture state directory hardening truth
Jul 16, 2026
bbe7994
fix(state): surface directory hardening failures safely
Jul 16, 2026
c6a906d
test(approval): capture Git authority gaps
Jul 16, 2026
28c860d
feat(approval): centralize Git authority decisions
Jul 16, 2026
7aa66c4
test(approval): capture credential authority gaps
Jul 16, 2026
8e8868d
feat(approval): centralize credential authority decisions
Jul 16, 2026
10de816
test(approval): capture network authority gaps
Jul 16, 2026
c6b503c
feat(approval): centralize network authority decisions
Jul 16, 2026
b9353c2
test(approval): capture container authority gaps
Jul 16, 2026
8857ef8
feat(approval): centralize container authority decisions
Jul 16, 2026
ada7ca6
test(approval): capture kubernetes authority gaps
Jul 16, 2026
fae0df9
test(approval): harden kubernetes credential boundaries
Jul 16, 2026
f8a0553
feat(approval): centralize kubernetes authority decisions
Jul 16, 2026
90b2ef3
test(approval): capture infrastructure authority gaps
Jul 16, 2026
31390e6
feat(approval): centralize infrastructure authority decisions
Jul 16, 2026
ca3e518
test(approval): capture aws control-plane authority gaps
Jul 16, 2026
54945c8
feat(approval): centralize aws control-plane authority
Jul 16, 2026
7e06f79
test(approval): ratchet aws donor compatibility
Jul 16, 2026
fe0da42
fix(approval): preserve aws cli donor grammar
Jul 16, 2026
9ea7e94
test(approval): capture extended aws authority gaps
Jul 16, 2026
d4f95f0
feat(approval): extend aws service authority
Jul 16, 2026
3f8cae4
test(approval): capture auth credential authority gaps
Jul 16, 2026
bf6e5be
feat(approval): own auth credential authority
Jul 16, 2026
1520286
test(approval): capture host execution authority gaps
Jul 16, 2026
3935269
feat(approval): own host execution authority
Jul 16, 2026
711e933
test(access): prove atomic persistence dispositions
Jul 16, 2026
41ac7c7
test(approval): capture residual authority gaps
Jul 16, 2026
b454fbd
feat(approval): close residual execution gaps
Jul 16, 2026
942b586
test(installer): characterize malformed checksum metadata
Jul 16, 2026
8689748
fix(installer): tolerate malformed checksum metadata
Jul 16, 2026
9654894
test(installer): isolate checksum metadata proof
Jul 16, 2026
3dd107b
test(ssh): characterize residual target boundaries
Jul 17, 2026
8cfdc4e
fix(ssh): validate persisted targets exactly
Jul 17, 2026
7e909fb
test(access): characterize empty Spark home authority
Jul 17, 2026
737572e
fix(access): keep empty Spark home on default root
Jul 17, 2026
8075d27
test(audit): characterize canonical field overrides
Jul 17, 2026
2064344
fix(audit): preserve canonical event authority
Jul 17, 2026
c753d19
test(sandbox): retain modular authority contracts
Jul 17, 2026
5d91acd
test(secrets): characterize truthful backend help
Jul 17, 2026
621e88b
fix(secrets): explain storage backend truthfully
Jul 17, 2026
0331a85
refactor(secrets): isolate help copy from CLI parser
Jul 17, 2026
79b56af
test(sandbox): characterize local home path privacy
Jul 17, 2026
81f65a9
fix(sandbox): redact local home roots from output
Jul 17, 2026
5dcd8b6
test(sandbox): characterize OS family authority
Jul 17, 2026
e1611bc
refactor(sandbox): centralize OS family authority
Jul 17, 2026
4824ece
test(sandbox): keep target errors non-reflective
Jul 17, 2026
21106c3
chore(r30): pin sealed local adoption heads
Jul 19, 2026
a024e24
docs(r30): seal reconciled candidate evidence
Jul 19, 2026
4373088
chore(r30): pin green Builder release baseline
Jul 20, 2026
3017281
chore(r30): pin final integrated candidate heads
Jul 24, 2026
dcc9e4e
docs(r30): attest final integrated gates
Jul 24, 2026
52c38de
test(r30): keep local candidate out of public bundle assertions
Jul 24, 2026
c907de2
ci(deps): prove browser-use extras across supported Python
Jul 15, 2026
d9ed6ed
chore(deps): update browser-use to 0.13.4
Jul 15, 2026
3f8cee9
fix(autostart): preserve uninstall failures
mayuulestasi-coder Jul 15, 2026
2c706de
test(autostart): prove Windows failure truth
Jul 15, 2026
40a20a3
fix(live): show unhealthy module count
mayuulestasi-coder Jul 15, 2026
93c9a14
test(live): prove safe unhealthy count route
Jul 15, 2026
7cabff2
fix(secrets): keep required default consistent
mayuulestasi-coder Jul 15, 2026
3392be9
test(secrets): prove order-independent required authority
Jul 15, 2026
54b945d
test(ssh): require private smoke probe directory
0xchukss May 22, 2026
3b560ab
fix(ssh): claim private smoke probe directory
Jul 15, 2026
94dfc1d
test(security): expose deferred purge interpolation
ifeoluwaaj Jul 15, 2026
b32c72a
fix(security): isolate deferred purge target
Jul 15, 2026
6e5244b
test(secrets): exercise list header pluralization
driasim Jun 3, 2026
7d5bcf6
test(security): expose mutable approval bypass
Jul 15, 2026
53baa7e
fix(security): remove mutable approval bypass
Jul 15, 2026
36d09cc
test(security): preserve secret reveal confirmation intent
ifeoluwaaj Jul 15, 2026
0c1f2f1
test(approval): cover kubernetes secret resource forms
Aeyod7 Jun 4, 2026
53048e1
test(approval): cover cloud secret read commands
Aeyod7 Jun 5, 2026
a19f415
test(approval): cover local secret-bearing file reads
Aeyod7 Jun 5, 2026
f819ca5
fix(approval): converge secret-read authority lanes
Jul 24, 2026
8ff3e74
test(security): cover LLM provider network boundary
ifeoluwaaj Jul 15, 2026
c552f19
fix(security): pin LLM provider connections
Jul 15, 2026
11c3256
test(security): prove bounded provider responses
Jul 15, 2026
8ddc928
refactor(security): keep provider transport out of CLI
Jul 15, 2026
8146c38
test(harness): extract adopted CLI regressions
Jul 24, 2026
4ecdc02
merge(r30): preserve prior CLI candidate lineage
Jul 24, 2026
d019f0d
feat(models): retain GPT-5.6 Sol setup defaults
Jul 24, 2026
222a9c6
feat(release): retain binding ship gate
Jul 24, 2026
471ede2
test(release): reconcile retained gate with R-21
Jul 24, 2026
3cdc8ad
chore(r30-cli-release): pin merged R30 modules
Jul 27, 2026
4161214
docs(r30-cli-release): seal merged source truth
Jul 27, 2026
863b07e
fix(r30-cli-release): trust merged adoption evidence
Jul 27, 2026
b4af971
fix(r30-cli-release): bind final installer identity
Jul 27, 2026
3b414c2
chore(r30-cli-release): refresh installer evidence
Jul 27, 2026
4895f8a
fix(r30-cli-release): bind post-gate history only
Jul 27, 2026
5a019f2
fix(r30-cli-release): classify sanitizer fixture flow
Jul 27, 2026
8aafb89
fix(r30): allow module-specific immutable follow-up refs
Jul 27, 2026
6cf8275
chore(r30): pin merged Spawner Level 5 follow-up
Jul 27, 2026
79eb1ea
fix(access): honor external Telegram ingress in Level 5 proof
Jul 27, 2026
9a61d61
fix(r30): scope OS compile gate to release lane
Jul 27, 2026
e5645ff
refactor(r30): keep release scoping outside CLI god file
Jul 27, 2026
d5d5591
fix(release): verify recorded installed source paths
Jul 28, 2026
fc991da
test(installer): isolate package manager repair hints
Jul 28, 2026
279c692
security(codeql): document value-free secret renderers
Jul 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
*.sh text eol=lf
scripts/*.sh text eol=lf
scripts/*.ps1 text eol=lf
docs/r30/patches/*.patch binary
32 changes: 32 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,32 @@ concurrency:
cancel-in-progress: true

jobs:
browser-use-dependency-compatibility:
name: browser-use-dependencies (Python ${{ matrix.python-version }})
runs-on: ubuntu-latest
timeout-minutes: 20
strategy:
fail-fast: false
matrix:
python-version: ["3.11", "3.12", "3.13"]
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false

- name: Set up Python
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6
with:
python-version: ${{ matrix.python-version }}

- name: Prove browser-use dependency compatibility
run: |
python -m pip install --upgrade pip
python -m pip install '.[browser-use]'
python -m pip check
python -c "import browser_use, litellm"

test-and-audit:
name: test-and-audit
runs-on: ubuntu-latest
Expand Down Expand Up @@ -59,6 +85,12 @@ jobs:
run: |
python -m spark_cli.cli verify --registry-pins --json | python -c "import json,sys; d=json.load(sys.stdin); n=int(d.get('unverified', 0)); assert n <= 3, f'unexpected unverified pins: {n}'; print('unverified:', n)"

- name: release_policy_binding_gate
run: python scripts/harness_checks/release_policy_binding_gate.py --root . --range "${{ github.event.pull_request.base.sha && format('{0}..{1}', github.event.pull_request.base.sha, github.sha) || 'HEAD' }}"

- name: gate_evidence_separation
run: python scripts/harness_checks/gate_evidence_separation.py --root . --range "${{ github.event.pull_request.base.sha && format('{0}..{1}', github.event.pull_request.base.sha, github.sha) || 'HEAD' }}"

secret-scan:
name: secret-scan
runs-on: ubuntu-latest
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,9 +36,9 @@ jobs:
persist-credentials: false

- name: Initialize CodeQL
uses: github/codeql-action/init@dc73d59c2d7bd4f8194098a91219eeee6d8a1719 # v4
uses: github/codeql-action/init@7188fc363630916deb702c7fdcf4e481b751f97a # v4.37.1
with:
languages: python

- name: Perform CodeQL analysis
uses: github/codeql-action/analyze@dc73d59c2d7bd4f8194098a91219eeee6d8a1719 # v4
uses: github/codeql-action/analyze@7188fc363630916deb702c7fdcf4e481b751f97a # v4.37.1
7 changes: 6 additions & 1 deletion .github/workflows/docker-optional.yml
Original file line number Diff line number Diff line change
Expand Up @@ -42,12 +42,17 @@ jobs:
- name: Run sandbox help with hardened flags
run: |
docker run --rm \
--user 1000:1000 \
--network none \
--read-only \
--cap-drop ALL \
--security-opt no-new-privileges \
--pids-limit 128 \
--memory 512m \
--memory-swap 512m \
--cpus 1.0 \
--tmpfs /tmp:rw,noexec,nosuid,size=256m \
--tmpfs /sandbox:rw,nosuid,uid=1000,gid=1000,size=512m \
--tmpfs /sandbox:rw,noexec,nosuid,uid=1000,gid=1000,size=512m \
spark-cli-sandbox:ci \
--help

Expand Down
1 change: 1 addition & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@ Use allowlisted serializers for read models. If a source payload contains unknow

## Authority and Route Rules

- **Before adding or changing any route / approval / fallback logic, read `docs/harness-discipline/` (start at `00_README.md`).** It is the harness-wide fix-discipline ruleset grounded in the 2026-06-24 audit. Non-negotiables that bite CLI work directly: no route-specific regex may own execution authority (`RL-01`); the approval gate must bind to the parsed/typed action, never a re-tokenized `argv` (`R-01`, fixes `approval.py`/`cli.py:17925`); `requires_approval` must mean *enforced* (`RL-05`); a security toggle must not be re-readable from mutable runtime (`RL-06`, fixes `SPARK_APPROVAL_ENFORCE`); and a failure must never return a success-shaped value (`RL-08`). New "for now" code needs a stopgap retirement owner (`R-15`).
- CLI may own operator diagnostics and local repair guidance, but Builder owns RouteConfidenceGateV1 and AOC route judgment.
- `spark fix` and `spark doctor` outputs should expose metadata-only route context and verification commands, not mutate high-risk surfaces without explicit gates.
- High-agency actions must fail closed unless authority, capability, freshness, consequence risk, confirmation, and privacy boundary are known.
Expand Down
4 changes: 4 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -458,6 +458,10 @@ Use `spark <cmd> --help` for full flags.
| `spark secrets list|set|get|delete` | Keychain-backed secret store |
| `spark config get|set|unset|list` | User config at `~/.spark/config/config.json` |

`spark doctor llm` rejects provider URLs containing credentials, query strings, fragments, unsafe schemes, or private/metadata targets. For direct provider calls it validates every DNS answer, pins the request to the validated address while preserving TLS hostname verification, and does not follow redirects.

`spark os compile` writes memory-movement and voice-surface read models with redacted `request_ref`/`trace_ref` compile metadata. Those refs prove compiled read-model lineage; they do not authorize memory movement, cleanup, promotion, voice transcription, speech synthesis, Telegram delivery, or execution.

`spark update` checks all selected installed-runtime clones for local edits before it stops services or runs install commands. Use `spark update --stash-local-runtime` for intentional local hotfix testing, `spark update --skip-dirty` to update only clean modules, and `spark update --continue` after manually fixing a preflight stop. If runtime processes were stopped and `SPARK_AUTOSTART=1`, update restarts Spark Live and prints a compact post-update health summary; use `--no-live-restart` to keep the stack manual.

## State Layout
Expand Down
145 changes: 145 additions & 0 deletions docs/ACCESS_LEVEL5_READ_ONLY_ELIMINATION_AUDIT_2026-06-28.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,145 @@
# Access Level 5 Read-Only Elimination Audit - 2026-06-28

Status: active proof, not just documentation.

## Invariant

When a trusted Telegram chat moves from Access level 1, 3, or 4 to Access level
5, Spark must not merely store the chat preference. The transition is valid only
when all of these are true:

1. `spark access status --level 5 --json` reports `effective_access_level=5`.
2. Level 5 service guardrails are active for Spawner and the active Telegram
service profile.
3. `level5.effective_codex_sandbox` is exactly `danger-full-access`.
4. The Telegram runner proves it can write a temporary state file before the chat
is marked operator.
5. Default Codex worker launchers use the persisted Level 5 service guardrails
even when the current parent process still has stale `read-only` or
`workspace-write` values.
6. `level5.full_permission_proof.ok` is `true`; when the proof object is
present, Telegram treats it as authoritative and does not fall back to older
green-looking fields.

If any one of those is false, Spark must say Level 5 is blocked or partial; it
must not claim full operator access.

## Current Live State

Fresh local audit on 2026-06-28, rechecked after Spawner access-action runner
hardening:

- Effective access level: `5`
- Level 5 activation state: `active_for_services`
- Service enabled: `true`
- Current shell process enabled: `false`
- Current shell Codex sandbox: `workspace-write`
- Service Codex sandbox: `danger-full-access`
- Effective Codex sandbox: `danger-full-access`
- Full permission proof: `ok=true`, `missing=[]`
- Spark workspace writable: `true`
- Service can operate whole computer: `true`
- Missing/stale services: none
- Skipped unstartable Telegram profiles: `sparkqa-bot`
- `spark live status --json`: `ok=true`, no unhealthy modules reported

The current shell not carrying Level 5 env is acceptable only because the worker
launchers read persisted module guardrails before launching Codex. A launcher that
uses stale process env directly is a release bug.

## Guardrail Coverage

- Spark CLI writes the Level 5 bundle into Spawner and every Telegram profile env:
`SPARK_ALLOW_HIGH_AGENCY_WORKERS=1`,
`SPARK_ALLOW_EXTERNAL_PROJECT_PATHS=1`, and
`SPARK_CODEX_SANDBOX=danger-full-access`.
- Spark CLI requires active service restart proof before reporting Level 5 as
effective for services.
- Telegram refuses to switch the chat to operator unless the CLI payload proves
effective full-access sandbox and the Telegram runner write probe passes.
- Telegram now consumes `level5.full_permission_proof` directly. If that proof
exists and is not green, the chat stays out of operator mode even if older
compatibility fields look green.
- Telegram natural language changes such as "change my access level from one to
five confirm" preserve the confirmation and still require fresh Level 5 proof.
- Spawner default Codex launch paths now have regression coverage proving stale
`read-only` process env is promoted from persisted Level 5 service guardrails.
- Spawner access execution actions now use the same persisted Level 5 env
promotion before launching `spark` actions, so access repair/setup commands do
not inherit stale `read-only` from the service parent process.

## Proof Commands

Fresh focused proof passed:

```bash
npm test -- --run \
src/lib/server/access-execution-actions.test.ts \
src/lib/server/high-agency-workers.test.ts \
src/lib/server/provider-clients/codex-cli-client.test.ts \
src/lib/services/spark-agent-bridge.test.ts \
src/routes/api/access/execution-lanes/access-execution-lanes.integration.test.ts
```

Result: 2026-06-28 Spawner proof passed with 44 tests, including the regression
that a stale `SPARK_CODEX_SANDBOX=read-only` service process still launches
access actions with persisted `danger-full-access` Level 5 env.

```bash
npm run build
```

Result: 2026-06-28 Spawner build passed.

```bash
npm run test:run -- \
src/lib/server/provider-clients/codex-cli-client.test.ts \
src/lib/services/spark-agent-bridge.test.ts
```

Result: 22 Spawner tests passed.

```bash
PYTHONPATH=src python3 -m pytest -q tests/test_access.py \
-k 'level5_transition or active_for_services or service_proof'
```

Result: 5 Spark CLI tests passed, 25 deselected, 6 subtests passed.

```bash
npm test -- --run \
tests/accessLevel5Natural.test.ts \
tests/level5RuntimeEnv.test.ts \
tests/accessActions.test.ts \
tests/accessPolicy.test.ts
```

Result: Telegram Access 5, stale-env promotion, and permission-proof tests passed.

```bash
npm test -- --run tests/accessPolicy.test.ts tests/accessActions.test.ts \
tests/profileEnv.test.ts tests/recursiveLevel5RuntimeEnv.test.ts
```

Result: 2026-06-28 focused Telegram proof passed, including CLI proof-object
adoption and stale read-only env promotion.

## Non-Bugs That Can Still Say Read-Only

- Historical mission result rows may still contain old read-only failure text.
They are evidence history, not current capability truth.
- Intentionally read-only creator missions and diagnostic routes must remain
read-only even under Access 5.
- A random Codex Desktop thread can still have a lower current-process sandbox.
Spark may only claim full access for work launched through the proven Level 5
service lane or a process that itself proves `danger-full-access`.

## Maintenance Rule

Any new Codex launch surface must add a test for this exact stale-env shape:

- persisted service env says Level 5 full access,
- current process env says `SPARK_CODEX_SANDBOX=read-only` or `workspace-write`,
- default Codex launch resolves to `--sandbox danger-full-access`,
- `level5.full_permission_proof.ok` is the authoritative full-access verdict,
- intentionally read-only commands remain intentionally read-only.
68 changes: 48 additions & 20 deletions docs/LAUNCH_RUNBOOK.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,21 @@ Run this from the exact branch or worktree intended for production. Do not push
installer changes until this gate passes and any paired Spark repo updates are
ready to ship together.

For the R30 installer batch, start from:

- [R30 documentation index](./R30_DOCUMENTATION_INDEX_2026-06-27.md)
- [R30 release plan](./R30_RELEASE_PLAN_2026-06-27.md)
- [R30 source owner audit](./R30_SOURCE_OWNER_AUDIT_2026-06-27.md)
- [R30 owner handoff packet](./R30_OWNER_HANDOFF_PACKET_2026-06-27.md)
- [R30 evidence packet](./R30_EVIDENCE_PACKET_2026-06-27.md)
- [R30 installer preparation checklist](./R30_INSTALLER_PREP_2026-06-27.md)
- [R30 Domain Chip Labs Telegram creator plan](./R30_DOMAIN_CHIP_LABS_TELEGRAM_CREATOR_PLAN_2026-06-28.md)
- [R30 Domain Chip Labs and Spawner readiness spec](./R30_DCL_SPAWNER_READINESS_SPEC_2026-06-28.md)
- [R30 Telegram live trace recapture](./R30_TELEGRAM_LIVE_TRACE_RECAPTURE_2026-06-28.md)
- [R30 stability, Domain Chip Labs, and Spawner goal prompt](./R30_STABILITY_DCL_SPAWNER_GOAL_PROMPT_2026-06-28.md)
- [R30 public release note draft](./R30_RELEASE_NOTE_DRAFT_2026-06-27.md)
- [R30 goal prompt](./R30_GOAL_PROMPT_2026-06-27.md)

```bash
python -m pytest
python -m spark_cli.cli verify --installers --json
Expand Down Expand Up @@ -82,18 +97,24 @@ bash ./install.sh
Both installers install the CLI, run the default starter setup, and write Spark
state under `~/.spark` unless `SPARK_HOME` is set.

## Non-interactive setup
## Identity Setup

Use a BotFather token and at least one Telegram admin id. Keep secrets in a
shell prompt, `@env:` references, or the Spark secret backend; do not paste them
into files that may be committed.

Use a BotFather token and at least one Telegram admin id. Keep secrets in
environment variables or a shell prompt; do not paste them into files that may be
committed.
Initial Telegram identity and operator-access setup is intentionally
interactive. A non-interactive command that includes `--bot-token` or
`--admin-telegram-ids` is a sensitive `identity_access_mutation` and must fail
closed before writing generated config or state. Use an interactive terminal for
the initial identity mutation:

```bash
spark setup --non-interactive \
--bot-token "$TELEGRAM_BOT_TOKEN" \
--admin-telegram-ids "$TELEGRAM_ADMIN_IDS" \
spark setup \
--bot-token "@env:TELEGRAM_BOT_TOKEN" \
--admin-telegram-ids "@env:TELEGRAM_ADMIN_IDS" \
--llm-provider zai \
--zai-api-key "$ZAI_API_KEY"
--zai-api-key "@env:ZAI_API_KEY"
```

Z.AI launch defaults:
Expand All @@ -103,7 +124,7 @@ Z.AI launch defaults:

OpenAI launch default:

- model: `gpt-5.5`
- model: `gpt-5.6-sol`

The installer stores cloud keys through the Spark secret backend. Generated
module env files should contain secret references and non-secret metadata, not
Expand Down Expand Up @@ -141,9 +162,11 @@ Then verify in Telegram:
- a normal message receives an LLM-backed response
- `/diagnose` reports Telegram, LLM, memory, and mission relay state

## Sandbox smoke
## Sandbox Smoke

Before launch, run at least one clean install with an isolated `SPARK_HOME`.
Before launch, run at least one guarded refusal smoke with an isolated
`SPARK_HOME`. This proves unattended identity mutation fails closed; it is not a
successful fresh install.

Windows PowerShell:

Expand All @@ -158,8 +181,7 @@ spark setup --non-interactive `
--no-autostart `
--no-start-now `
--skip-install-commands `
--skip-runtime-check
spark status --json
--skip-runtime-check; "exit=$LASTEXITCODE"
```

Linux or WSL:
Expand All @@ -175,11 +197,17 @@ spark setup --non-interactive \
--no-autostart \
--no-start-now \
--skip-install-commands \
--skip-runtime-check
spark status --json
--skip-runtime-check ; echo "exit=$?"
```

After the smoke, scan generated config, state, and logs for accidental secrets
Expected result:

- exit code `2`
- output says Spark blocked a sensitive `identity_access_mutation`
- no generated module env/state files contain the fake token, fake provider key,
old dashboard variables, or private-key material

After the smoke, scan generated config, state, and logs for accidental residue
or deferred dashboard configuration. Keep the scan focused on generated files;
installed source checkouts can contain redaction fixtures and runbook examples.

Expand All @@ -188,10 +216,10 @@ grep -R "fake-zai-key\|fake-token\|SPARK_API_URL\|SPARK_DASHBOARD_URL\|sscli_v1\
"$SPARK_HOME/config" "$SPARK_HOME/state" "$SPARK_HOME/logs" 2>/dev/null || true
```

The fake LLM key must not appear in generated module env files. Non-secret Z.AI
metadata such as provider, base URL, and model is expected. With a fake
Telegram token and `--no-start-now`, `spark status` may report the Telegram bot
or runtime processes as unhealthy; that is expected for this no-secret smoke.
The fake token and fake LLM key must not appear in generated module env files.
Do not use this guarded-refusal lane to claim runtime setup success; run the
interactive identity setup lane with a disposable test bot when release truth is
green enough for a full fresh-install smoke.

## Troubleshooting

Expand Down
Loading
Loading