dsh alpha.3 → master semantic disposition ledger

本页是 issue #186 建立的本轮唯一 semantic disposition ledger。它记录固定比较区间内的调用方可观察语义及其 owner,不是 README/AGENTS 的完成进度表;owner 是否完成仍只由 GitHub issue 与 milestone 状态裁决。

历史证据,不是当前 parity 声明。 本页保留 2026-09-04 的固定 tree 审计及 verifier;其中 main、owner 与架构描述均属于当时快照,不代表当前 HEAD 的实现或完成状态,也不替代 AGENTS/README 的复刻目标。当前范围与完成状态仍以 GitHub milestones/issues 为唯一 authority。

固定 authority

字段固定值
上游仓库deepseek-ai/deepseek-harness
Base(exclusive)dd6322d604e00eec1ba5e0c8541159906a21094a,dsh-v0.1.2-alpha.3
Target(inclusive)76fda729799fe9b3848dbe2c211d4b231032b81e
Comparedd6322d6...76fda729
区间规模404 commits、2682 files
First-parent authority32 条:31 个 merge,加直接落在 master 的 d921d4b357
Tether main evidence807dbf4c4cbfb50b184b5dfa5e919d90aafa5ed7,观察时间 2026-09-04T03:09:54Z
审计日期2026-09-04
机械清单dsh-alpha3-to-master.manifest.json
离线 verifiernode scripts/check-parity-ledger.mjs public/parity/dsh-alpha3-to-master.manifest.json
Git-backed verifiernode scripts/check-parity-ledger.mjs --git "$DSH_ROOT" public/parity/dsh-alpha3-to-master.manifest.json(DSH_ROOT 指向受信 deepseek-harness checkout;上表所有期望值——ancestry、HEAD、404/32/2682 计数、first-parent 序列与 kind、topic 区间 membership、target tree evidence paths——全部由真实 Git 计算派生)

离线自洽检查只是快速反馈;#186 的最终验收必须包含 Git-backed 运行(受信 checkout 的 HEAD 恰在 target 76fda729,历史不完整时直接失败,不静默跳过)。合成本本地 Git graph 负向测试(scripts/check-parity-ledger.graph.test.mjs)与真实 checkout 集成测试(scripts/check-parity-ledger.upstream.test.mjs,未设置 DSH_ROOT 时显式 skip——是未执行,不是通过)分开维护。

Tether evidence 纪律:“main 已等价实现”只能引用上表固定的 main SHA 及该 tree 中的测试。当前 feat/m13-issue-186 工作区或其他未合入分支只能证明审计正在进行,不能算 implemented。

审计方法与排除规则

  1. 从 base 到 target 执行 first-parent reverse walk,逐项读取相对第一父的实际 tree diff、merge 引入的 commits 与非文档 source/test paths;不按 PR title 猜语义。
  2. 对每个稳定主题在 target tree 再次定位 source 与 tests,确认它没有在后续 merge 中消失、变形或被 revert。
  3. 对照 Tether 固定 main tree、#173–#185、已有 v0.9/v0.10 owners 与历史 acceptance;发现没有 owner 的稳定语义时,新建 milestone 13 issue。本轮据此新增 #188。
  4. 合法 disposition 仅为:本 milestone owner、已有 v0.9/v0.10 issue、main 已等价实现、N/A、experimental FOLLOW/PARTIAL/NO-GO、reverted、intentional deviation。当前工作区不构成完成类别。
  5. 可排除纯 release/version、CI、issue-management、record-browser-gif、generated docs、style-only 与不改变 API 成本的 perf-only 噪声。若性能改变公开 publication cadence、identity、分页/重建成本或 backpressure,则必须入账;因此 1f694c88 不能整体排除。
  6. target-tree 交叉检查还覆盖本区间以前已存在但容易被大 merge 混入的 Webhook、Remote/Connection、turn outline/paging/rail、SQLite decision 与 experimental Inspector,避免重复立项或漏记最终边界。

32 个 first-parent 条目

下表中的主题 id 对应后文语义账本;“排除”也作为主题记录理由与重评条件,而不是从清单中消失。

#First-parent SHA实际条目主题
15dd876025dPR #2907;Session 点读/immutable snapshot,并夹带 restored empty model-policy 修复session-log-read-cost、subagent-restored-empty-model-policy
29d15938073PR #1148;CPython subprocess backend,最终移入 packages/experimentalcpython-runtime
3714bec1316PR #3367;删除 1400+ package 空 invariant companionsinvariant-companion-omission;并触发既有能力 target-tree 复核
452af48f808PR #3250;adjacent Agent delivery 统一到 Steeradjacent-agent-steer
568488c552aPR #3403;model discovery 复用并校验 profile headersmodel-discovery
6dead2b2324PR #3382;base/headless/SDK 默认暴露 WebFetchwebfetch-default-composition
74bc0b000f5PR #3411;superellipse/elevation CSSweb-style-smoothing
8876a3e0414PR #3346;全仓 Session seq/offset breaking brandssession-seq-offset-brands
93efd4b51e0PR #3415;turn rail preview stacking layerturn-preview-layer
10c3e5bd7daePR #3418;PTC note 外部名称/链接ptc-note-link
111f694c88abPR #3391;stable projections、三帧 stream cadence、resident history、reanchorweb-conversation-cost-contract
123c5b7097aePR #3425;PTC preset 禁用 workflow rowptc-single-composition-surface
134e84901e64PR #3427;0.1.2-alpha.4 workspace versionsrelease-versioning
148b799cd7acPR #3266;handle-based persistence 与 logical ZIP export 重写persistence-handle-contract、session-export-zip
15d3ab4ce53dPR #3401;Host pause abort 与 exact attempt refgoal-host-pause-fence
16d921d4b357直接提交 #3431;未知 storage version 禁止 legacy bootstrapstorage-version-salvage
17a631115597PR #2828;top-level/nested read_image card 与 nested-only fallbackread-image-card
18bbae7318f0PR #3424;empty/null tool-call delta identitytool-call-delta-identity
19be70505f9ePR #3417;GitHub issue Start dateissue-management-process
2066ca93c3dcPR #3441;恢复 Project date fieldsissue-management-process
210a1efddd40PR #3455;compatibleVersions、backup-and-skip、projection cache v6storage-version-salvage
22f7cee2c888PR #3333;Agent Teams Steer 与 cold mailbox orderagent-team-steer
2349a606bc5bPR #3456;0.1.2-alpha.5 versionsrelease-versioning
24c024c53d34PR #3458;record-browser-gif 使用 gh --attachrecord-browser-gif-docs
25f98bfbda85PR #3452;same-session message editsame-session-message-edit
269d3bbd46eePR #3459;完整 revert #3452same-session-message-edit
27a8e33b62e3PR #3434;pkg Python SDK runtime 的 child node 解析packaged-node-resolution
280e6a397464PR #3444;Project-local Priority/token policyissue-management-process
29427d210b5ePR #3451;DeepSeek/OpenRouter/Anthropic model listing shapesmodel-discovery
3048d84990a0PR #3471;0.1.2-rc.1 versionsrelease-versioning
317169660d33PR #3198;process-wide proxy、child policy、真实 egress testshttp-proxy-egress
3276fda72979PR #3481;proxy package rc.1 versionrelease-versioning

Semantic disposition ledger

每项都记录最终 target source/test、调用方语义、Tether 固定 main 证据、disposition 与 owner。完整 SHA 与机器字段见 manifest。

1. Session 与 persistence

主题上游 commit(s) 与最终 source/test调用方可观察语义Tether main evidenceDisposition / owner
session-log-read-cost5dd87602;5660f44d、bcfec8d1、47e6448e。Source: packages/core/session/src/{index,surface}.ts;tests: session.spec.ts、surface.spec.tseventAt O(1) 点读;append 前复用 immutable full snapshot identity,调用方无需为点读复制全日志。ISession.cs 仅公开全量 Events;InMemorySessionTests.cs 未固定点读/half-open/identity 成本。本 milestone owner #173
session-seq-offset-brands876a3e04 / 27bf1039。Source: core/session/src/types.ts、index.ts;tests: sequence-types.spec.ts、fork.spec.tsexisting event seq、prefix/gap offset 与 -1 cursor 编译期不可混用;尾后位置不是 event。SessionEvent.Seq、ISession.NextSequence、SessionHeader.SeedLength 仍为裸 long。本 milestone owner #173
persistence-handle-contract8b799cd7 / bec6805d。Source: session-persistence/src/{index,handle,revision}.ts;tests: contract.ts、live-write-contract.ts、storage-contract.spec.tscreate/open/stat/list、opaque revision、bounded read、append/flush freshness、single writer、close、合法 contiguous prefix。Coordinator 已独占 capture/write-behind/prepare/resume/final drain;ISessionEventStore 尚无 stat/list revision hint 或下推 bounded read。本 milestone owner #174;架构差异:Coordinator 保持唯一写权威,provider 不订阅 Session event。
session-export-zip同一 handle merge。Source: session-log-export/src/{archive,index}.ts;tests: archive.host.spec.ts、route.host.spec.tslogical canonical JSONL、descendants、media dedupe、live flush、streaming ZIP、bounded backpressure/cancel;不泄漏 physical raw artifact。SessionExportService.cs 依赖 IRawSessionLogSource;SessionExportStream.cs 输出物化后的 base64 NDJSON。本 milestone owner #175
storage-version-salvaged921d4b3、0a1efddd;fcd109d2、49df707c。Source: storage-domain/src/spec.ts、storage-json/src/per-record-unit.ts、session-projection-cache/src/spec.ts;相应 testsdeclared compatible old version 可读、写回 current;只有可重建 per-record 数据可 quarantine-and-skip;未知 version bootstrap 保持原物并 fail loud。StorageDomain.cs 对所有 mismatch fail loud;backend 无 exact-record quarantine capability。本 milestone owner #183
existing-v0.9-v0.10-capabilities 中的 SQLiteTarget 已删除 first-party SQLite Session provider,handle/export 又改变了抽象成本。上游删除后的取舍已由 owner 拍板(见右)。main 仍有 Tether.Session.Persistence.Sqlite 和 conformance lanes;决策与实现分离,移除未实施前 provider 与 conformance 必须保留并通过。已有 v0.10 decision #150,最终决策 comment 5541506234:FOLLOW,未来移除 first-party Session SQLite provider。Tether.Storage.Sqlite domain-KV、Session FTS、projection SQLite 与 Coordinator provider-neutral 不受影响;未来移除构建不打开/不迁移既有 .sqlite,升级前先 provider-neutral logical export。#150 刷新 review 正文(建议保留、称 pending)与该 explicit 最终 comment 存在叙述冲突;以 explicit comment 为准,除非被取代。

2. Subagent、Agent Teams 与 Goal

主题上游 commit(s) 与最终 source/test调用方可观察语义Tether main evidenceDisposition / owner
subagent-restored-empty-model-policy5dd87602 / 32d681f0。Source: tool-subagent/src/index.ts、model-selection-state.ts;test: model-selection-settings.spec.tsrestored Session 的显式空 seed/policy 保持 disabled;只对 fresh top-level Session 采样当前 Host allowlist。ProductSubagentProvider.cs、SubagentModel.cs、SubagentRegistryService.cs 有 route 基础,最终 restore-empty acceptance 尚未关闭。已有 v0.9 owner #105
adjacent-agent-steer52af48f8;ec493c2d、3091bdc2、43840d6e。Source: subagent/src/continuation.ts、tool-subagent/src/index.ts;tests: continuation.spec.ts、service.spec.tsexact live sender 仅 direct parent/child;running→最近 step,idle→新 turn,inactive child→cold resume;删除 quiet/wakeup 与独立 report tool。SubagentDeliveryMode 仍为 Quiet/NextStep,SubagentRegistryService 分离 Followup/Report。本 milestone owner #180;旧 #34/#145 acceptance 已加 note。
agent-team-steerf7cee2c8;040d7387、eeddd457。Source: experimental/agent-team/src/{mailbox,index}.ts、tool-agent-team/src/index.ts;tests: team.spec.ts、persistence.spec.ts、tool-team.spec.tsdurable enqueue/flush 后 Steer;cold recovery 按 mailbox 原序 dispatch-through;9-tool catalog;receipt 只为 accepted/queued。TeamMessage 仍含 DeliveryMode;AgentTeamsPlugin 4 tools;QueueMessageAsync 未 target delivery。experimental FOLLOW,#181(implementation child 已在 milestone 13,依赖 #180)。
goal-host-pause-fenced3ab4ce5;29ce8497、33fa98b3。Source: goal-round-driver/src/index.ts;test: goal-round-driver.spec.tsHost pause abort live turn;model 自己 pause 正常结束;旧 attempt 不能在 pause→resume 后重停新 revision。main 只有 durable Goal snapshot/projection,无 round driver 或 exact-turn abort fence。本 milestone owner #179

3. LLM、Web、工具与 preset

主题上游 commit(s) 与最终 source/test调用方可观察语义Tether main evidenceDisposition / owner
model-discovery68488c55、427d210b;5257c750、a6ed19b5、ccecf4db、8179d929。Source: llm-pi-ai/src/{discovery,catalog}.ts;tests: discovery.spec.ts、catalog.spec.tscatalog route 零 HTTP;动态 discovery 复用 validated profile headers;支持 OpenAI/DeepSeek/OpenRouter/Anthropic shape;Anthropic /v1 只影响 listing URL。MultiProviderClient.cs / MultiProviderPlugin.cs 是同步静态 directory,无 discovery seam。本 milestone owner #177(blocked by #176)。
tool-call-delta-identitybbae7318;a1271a49、e91c28d3、b03261ca。Source: llm-pi-ai/src/{stream,adapter}.ts;tests: adapter.spec.ts、adapter.e2e.tsmissing/null/"" identity 是“无更新”;later non-empty identity 可补齐;malformed final call 稳定失败。direct DeepSeek accumulator 已接受 non-empty;generic ChatCompletionsWire 只在首次 index fragment 捕获 identity。本 milestone owner #178
webfetch-default-compositiondead2b23;ca723d92、cf7b0bd5、0a0f9e59。Source: bundle/base/cordis.patch.yml、web-fetch-http/src/provider.ts;tests: base.spec.ts、keyless smokebase/headless/SDK 默认组合均有 web_fetch,不需要额外 patch。固定 main 的 base.yaml 已挂 web-http-fetch + web-tools;WebToolsTests.cs 固定 web_fetch catalog,WebHttpTests.cs 固定 bounded provider。main 已等价实现 at 807dbf4…;完整 SSRF/pinning 安全边界仍由 #111。
read-image-carda6311155;a4d44047、56ca8af0、666bd48e。Source: tool-fs/src/read-image.ts、ui-tool/.../image-card-model.ts、read-image-row.tsx;tests: read-image.spec.ts、image-card.client.spec.tsxtop-level/nested image cards 可 replay;path fallback 只用于 trusted nested call,普通 result 不可把任意 path 当图片。main 有 durable Attachment/image admission,无 read_image tool 与 replayable image card presenter。本 milestone owner #182,复用 #109/#113。
ptc-single-composition-surface3c5b7097 / 0cdcc9c3。Source: presets/ptc/agent.cordis.yml;test: shipped-root.spec.tsPTC 在注册/查找/呈现前禁用 general workflow tool,只保留 run_code;Host/Ralph infrastructure 不删。main base.yaml 同时挂 code runtime tools 与 workflow tools,没有 shipped PTC 差异。本 milestone owner #184
http-proxy-egress7169660d;545e2ad9、c62d6f3a、8470ddef。Source: util/http-proxy/src/{policy,install}.ts、profile-boot.ts;tests: proxy policy + LLM/Web/subprocess real egress单一 process-wide route authority、loopback/direct policy、home env、child/worker propagation、secret-safe diagnostics;所有 channels 真实走预期 route。main 各包自建 HttpClient/handler,通常继承 DefaultProxy,但无 launch-time policy、egress inventory、child trust split 与 real-proxy matrix。本 milestone owner #176;intentional implementation mapping 是 .NET 10 HttpClient.DefaultProxy,不复制 undici matcher。

4. Web client 成本与既有 v0.9/v0.10 能力

主题上游 commit(s) 与最终 source/test调用方可观察语义Tether main evidenceDisposition / owner
web-conversation-cost-contract1f694c88;81431381、c809098b→最终 59342011、2ab37e95、2e21d210、577f0cf7、0e90d47d、e32437d1。Source: ui-conversation/.../{conversation,assembly}.ts、ui-chat/ChatView.tsx、ui-trajectory/TrajectoryView.tsx;tests: conversation registry/assembler + trajectory viewshigh-frequency stream 在第三次 RAF coalesce 发布,immediate update 抢占;unchanged projections/keyed nodes 保持 identity;resident history bounded;window replacement 后 anchor 重绑。main 有 framework-free reconcile/perf tests,但没有 exact 三帧、resident-window 与 replacement-reanchor 完整 acceptance。原审计发现 orphan,已建 本 milestone owner #188。
turn-preview-layer3efd4b51 / 515eca7d。Source: TurnNavigator.module.css、turn-rail-items.ts;tests: chat scroll + rail itemsrail hover preview 不被 code banner stacking context 遮挡。main 已有 TurnOutline projection,但 final rail 尚未交付。已有 v0.10 #132 / #140;层级是 #140 assembled acceptance。
existing-v0.9-v0.10-capabilitiestarget tree 复核:packages/webhook、api/remotes、client/connection、session-turn-outline、turn-rail-items.ts 及 tests;本区间实际变动主要来自 invariant omission、seq brands 和 perf 收口signed webhook、typed Remote/Connection、whole-log outline、window paging/loadThrough/rail 继续存在;不因大 merge 重复立项。TurnOutline 已在 main;其余由既有 owners 推进。已有 v0.9/v0.10 issues:#101、#123、#132、#137、#138、#139、#140、#150。

5. Experimental / deviation / reverted

主题最终证据与调用方语义Tether evidenceDisposition
cpython-runtime9d159380 / c388169c,最终 source packages/experimental/code-runtime-python/src/{index,protocol}.ts,tests runtime.spec.ts、protocol.spec.ts。这是 private experimental CPython subprocess provider,强绑定 fd 3、POSIX signals、rlimit/process groups 与 Python runtime settlement。main 已有 provider-neutral IPtcRuntime(旧名 ICodeRuntime,#272 改名)、Roslyn/worker/process providers、ComputeLedger 与 protocol tests,但没有 shipped CPython provider。experimental NO-GO。 理由:上游仍未 shipped,具体机制不是稳定 C# parity,复制会建立第二本机 process/sandbox authority。**重评条件:**上游脱离 experimental 并进入 shipped preset;或 Tether 明确产品化本机 CPython sandbox provider且复用既有 Subprocess/Sandbox/IPtcRuntime authority。无需 implementation child。
agent-team-steer见上表;上游也仍在 packages/experimental,但 Tether 已有 experimental Teams runtime。main 的旧 surface 已存在,且最终差异明确、可在现有 seam 上收口。experimental FOLLOW,child owner 已是 milestone 13 的 #181。
same-session-message-editPR #3452 f98bfbda / ef88756f 随后被 PR #3459 9d3bbd46 / e974a655 完整反向;target grep 无 edit API/event。main 未实现。reverted;不建 owner。
inspector-cordis-consoletarget 的 packages/experimental/inspector 提供 JS CDP/debugger/runtime/network planes 与 Cordis tree tests。固定 main 已有 Cordis.Console、Tether.Web.CordisConsole、独立 /cordis、composition/fiber/service graph、patch preview/apply、SSE 与 HTTP/frontend tests。intentional deviation,仅限下表逐面矩阵中标注的替代面。“Console 替代 Inspector”不是 blanket 等价;CDP 其余 surface 已由 #103 逐面定为 NO-GO(2026-09-10 写回)。

Inspector/CDP 逐面处置(#103 口径)

#103 是 M9 decision owner,维持 decision-only。以下矩阵把原先“Inspector 由 Console 替代”的笼统表述细化到每个 surface。2026-09-10 逐面定案:Tether 运行时是本机 .NET 进程,没有可附着 CDP 的浏览器宿主,Inspector 的四个 CDP 面全部 NO-GO;替代观察面与重评条件逐行给出。

Surface上游(experimental Inspector)Tether 现状处置
Cordis tree / 状态观察CDP DOM tree 投影 + 事件流 ordered replayCordis Console 的 composition/fiber/service graph 观察(#194 可靠性增量)。**明确差异:**不是 CDP DOM tree 投影,没有 CDP 事件流 ordered replay 语义;观察对象是插件树/fiber/service 而非 DOM。NO-GO(CDP 形态);替代面 = Cordis Console(#194)+ EventTracer(#196)。 用户影响:浏览器 devtools 式 DOM 检视不可用;本机插件树检视可用。重评条件:Tether 出现浏览器宿主运行时(如 #114 webworker FOLLOW 被推翻)时重开。
CDP NetworkHost fetch 投影到 Network plane无对应面;出网由 egress authority 管控(WebFetchTransport pinned public transport,#111)。NO-GO。 理由:Network plane 是浏览器宿主的内省面;Tether 的等价管控是出网准入/DNS pinning/redirect 复核本身,不需要第二套网络内省权威。重评条件:需要按请求级审查模型出网行为时,作为自有扩展(非 CDP parity)立项。
CDP Runtime evaluation经 Worker execution realm 求值无对应面;动态执行走 Tether.PtcRuntime(旧名 Tether.CodeRuntime,#272 改名)/动态包 define/run/stop,是 Tether 自有执行入口,不是 CDP contract。NO-GO。 理由:Runtime evaluation 不是只读能力,按 Inspector 只读观察处置会绕过执行边界;上游自身仍在 experimental。重评条件:上游脱离 experimental 且 Tether 需要远端求值协议时,作为带威胁模型的独立能力评估。
Cross-realm identity / object routingCDP cross-realm 对象路由无对应面;单一 Cordis 进程树没有浏览器 realm;远端面用 exact generation identity(RemoteEventHub.TryAcquireExactGeneration)。NO-GO。 重评条件同上:出现多 realm 宿主时重开。
Caller abort / unload / security / performanceInspector 生命周期与边界契约#194/#196 已指明 Cordis Console 与 EventTracer 的能力边界;EventTracer/scope 是 #196 自有新增能力,不冒充上游 Inspector 功能边界由 #194/#196 持有

#103 不是 #194/#195 的硬前置;#196 不吞掉完整 CDP 实现。本 ledger 不实现 CDP。

6. N/A 与明确排除

主题上游证据排除理由重评条件
web-style-smoothing4bc0b000 只改 CSS modules、styling docs 与视觉 fixturesstyle-only;无 API、状态、持久化、成本或 accessibility contract delta视觉机制成为可配置 API、命中区域/可访问性或布局稳定性 contract 时重评
ptc-note-linkc3e5bd7d 只改 .agents/notes/...2026-06-15-ptc*generated/docs-only;不改 runtime/tool/preset名称进入 model-visible prompt/public API 时由 #100/#184 处理
release-versioning4e84901e、49a606bc、48d84990、76fda729 仅 workspace/package/lock version纯 release/versionversion 进入 wire capability negotiation 或 durable schema 时重评
issue-management-processbe70505f、66ca93c3、0e6a3974 只改 .github/issue-management Project date/Priority/token policy上游仓库流程,不是 harness runtime/APITether 自己采用同类流程时作为自有 infra issue,不冒充 parity
record-browser-gif-docsc024c53d / 2f091ee8 只更新 skill 中 gh --attach 用法issue 明确排除 record-browser-gif/generated docs仅在 Tether 自有贡献流程选择采用时处理
packaged-node-resolutiona8e33b62 / c732dedc 修改 @yao-pkg/pkg patch、Python SDK single-exe build/smokeTether 用 .NET global tool,不存在 pkg child node 劫持路径Tether 发布内嵌 Node/Python 单文件载体并重写 child executable resolution 时重评

Implementation owner graph

本图不是第二份完成勾选表;它只说明每个 semantic delta 的实现/决策 owner 与 acceptance。状态以 GitHub 为准。

Owner主题本轮 acceptance / supersession
#173Session seq/offset + read cost强类型 SessionSeq/SessionLogOffset/cursor;O(1) EventAt;immutable half-open snapshot;fork inherited cut。
#174persistence handle contractCoordinator 保持唯一 capture/write-behind/prepare/resume/final-drain authority;补 stat/list/revision/bounded read/freshness/flush/retire conformance。Blocked by #173。
#175streaming ZIP exportprovider-neutral logical JSONL、descendants/media、live flush、bounded streaming/cancel。Blocked by #174。
#176outbound egress/proxy.NET DefaultProxy 单一 authority、loopback/direct、child trust、real proxy channel tests。
#177model discoverycatalog short-circuit、profile headers、protocol URL/shape/bounds/errors。Blocked by #176。
#178tool-call delta identityper-index accumulator、non-empty identity acceptance、late identity、conflict/malformed policy、shared fixtures。
#179Goal pause/driverround driver、Host-vs-model pause、exact revision/attempt abort fence、race tests。
#180adjacent SendMessage + Steerdirect-edge authorization、running/idle/cold child、真实 sender provenance、FIFO settlement order。Supersedes #34 的 quiet/report acceptance。
#181experimental Agent Teams FOLLOWdurable enqueue/flush、Steer delivery、ordered dispatchThrough、dedupe/receipt、9-tool catalog。Blocked by #180;supersedes #60 旧 surface。
#182read_image cardsafe read/admission、bounded presentation metadata、top-level+nested replay、nested-only fallback。Blocked by #109/#113。
#183Storage compatibility/salvagecompatibleVersions、unknown bootstrap rejection、仅 rebuildable data 可 exact quarantine-and-skip。
#184PTC single surfaceshipped PTC 在 catalog/prompt/request 前移除 workflow;保留 Host infrastructure 与 standard/cordis 差异。Blocked by #100/#143/#144。
#185invariant omission删除空 companion 和 mandatory gate;真实 independent-observation invariants 保留 negative tests。
#188Web client observable cost三帧 coalescing、immediate preemption、stable keyed identity、resident-window bound、replacement reanchor、generation cancellation。审计新发现的 orphan owner,已加入 milestone 13。Host acquisition/budget 的候选计数器证据见下文跨 owner 一节——计数器而非 DOM 测试。
#105restored empty model policyfresh/restored exact allowlist 与 pre-spawn fail-closed;显式空 restore 不重新采样。
#109、#113、#139、#140conversation/image/paging/rail保持既有 folding/DOM identity、canonical image authority、bounded store paging、load-and-jump owner;#188 只补 exact cadence/cost/reanchor。
#101、#123、#132、#137、#138Remote/Connection/Webhook/outlinetarget tree 复核后仍由原 v0.9/v0.10 owners 持有,不重复立项。
#103Inspector/CDP 逐面决策(M9 decision owner)对 CDP DOM tree/ordered replay、Network、Runtime evaluation(非只读)、cross-realm identity 逐面给出 FOLLOW/PARTIAL/NO-GO;Cordis Console 替代仅限 composition/service-graph 观察面(逐面矩阵见上文)。未决项如实 pending,不因本 ledger 变绿。
#111、#176WebFetch 安全边界 / outbound egress#111:默认 WebFetch 的 SSRF/public-destination 边界与 untrusted-content boundary(仍 blocked)。#176:.NET DefaultProxy 单一 authority、child trust、real proxy channel tests。WebFetch route/destination 面的联合严格 deviation 记录为 webfetch-proxy-fail-closed(见下文)。
#150SQLite Session provider decision最终决策已记录(comment 5541506234):FOLLOW,未来移除 first-party SQLite Session provider。移除未实施;provider 与 conformance 保留;未来移除构建不打开/迁移旧库,升级前 logical export。#174/#175 保持 provider-neutral。

Supersession / decision notes

为保留历史正文且醒目标记最终 contract,本轮使用 comments 留痕:

  • #34 comment:quiet/next-step、独立 report、SubagentDeliveryMode 由 #180 supersede;continuable core 保留。
  • #60 comment:delivery mode、quiet、followup_task、旧 4-tool surface 由 #181 supersede;durable Team core 保留。
  • #106 comment:borrowable prepared source/persistence-owned cold cache 由 #174 的 revision-keyed observation 取代;其他 schema/range/torn-tail acceptance 保留。
  • #145 comment:图片 admission 保留,最终投递必须消费 #180,不再固化 FollowupAsync。
  • #150 comment(历史):handle/export refactor 不替 SQLite 去留 decision 拍板。
  • #150 最终决策 comment:FOLLOW,未来移除 first-party Session SQLite provider;决策与实现分离,移除未实施,provider 与 conformance 保留并必须通过。#150 刷新 review 正文与该 explicit comment 的 pending/retention 叙述冲突在此留痕,以 explicit comment 为准。

跨 owner 义务与继承前置

本节登记 #186 对其他 milestone owner 的精确处置;不移动、不关闭、不吸收它们的 ownership。机器可读结构见 manifest 的 crossOwnerDispositions / intentionalDeviations / integrationCandidateEvidence,由 verifier 强制。

严格 intentional deviation:webfetch-proxy-fail-closed(#111 × #176)

Tether WebFetch 仅执行同一 Boot HTTP authority 对当前 request/redirect hop 选择的 Direct route,且完整 nonempty DNS answer set 必须通过 public-only admission,实际连接 pin 到 admitted endpoint 并核对 native peer。Proxy-selected 或无法确定 route 的模型 fetch 在 destination DNS / proxy / origin connection 前 fail closed(WEB_ROUTE_REFUSED);绝不在 proxy 失败/拒绝后静默 direct retry。

这是相对 dsh 76fda729799fe9b3848dbe2c211d4b231032b81e 的有意更严格差异:上游 proxied hostname 由 proxy 解析、只过滤非 public literal。**本 ledger 不声称 upstream proxy DNS 行为已由本地检查证明。**影响:配置 proxy 且未由 authority 选择 Direct 的 public WebFetch 也不可用;operator Llm/WebSearch 等通道继续正常 proxy,合法 local LLM gateway 不受 public-only fetch 限制。重评条件:提供能验证 proxy-side origin admission / actual destination 的 safe proxy transport,并在同一 authority 下覆盖 HTTP/HTTPS、DNS/rebinding/redirect、凭据隔离与无 direct retry 的真实 transport 验收;不能用“本地 DNS 检查 + 普通 hostname proxy”替代。

继承前置(M15)与未行使项

Issue分类登记口径
#201supersededE2B execution world 已按 #271 决议从源码树移除(Tether.Sandbox.E2b 与其测试包删除):无 shipped profile 选中、无控制面、宿主机内存无界。本行保留为历史审计记录;远程世界改经 IWorldBound.WorldId seam + SANDBOX_SPLIT_WORLD fail-closed 保留,SSH 世界接入在 #271 登记为 DEFER。
#202inherited-bounded-acceptance继承前置(锚点 commit 6d12e3ab 在原始 rc.1 之前),不是本区间新 delta。bounded slice 见下方候选证据;#202 仍归 M15,未移动未关闭。
#203inherited-bounded-acceptance继承前置,不是本区间新 delta。bounded slice 见下方候选证据;#203 仍归 M15,未移动未关闭。
#204consume-not-implement本 ledger 与 task reports 只消费候选证据字段(full SHA、artifact hash、profile/patch/roster、OS/arch/RID、fixture/native 分类、实际执行计数、可取回输出);回执 infrastructure 仍由 #204 (M15) 持有,未实现未关闭。wrong-SHA、stale、skipped、zero-case、模拟冒充 native 的证据不可替代。

Integration candidate 证据(审计证据,不是完成)

以下指针引用 feat/m13-integration 分支上的真实提交与测试。按本 ledger 纪律,合入并验收前一律不算 completed;完成状态仍由 GitHub issue/milestone 裁决。这不是第二份完成勾选表。

  • #176 / #111(WebFetch route/destination):0e123902 → 36ae08a2。public-admitted/pinned Direct positive 走 production classifier/factory handler/ConnectCallback(DNS/socket 边界为 controlled fixture);proxy-selected fail-closed 有真实 loopback listener 8 组与不可达 proxy 拒绝;allow-all 变异证明 25 个 negative 失败。测试:WebFetchTransportTests / WebFetchBoundaryTests / WebFetchLifetimeTests / WebFetchCatalogTests。native public HTTPS positive 未执行(如实保留)。
  • #188(Host acquisition/budget 计数器):1ec55c9a → 7e487fae。计数器而非 DOM 测试:ReadOnlyColdRestoreTests(冷恢复 bounded suffix/全量读/append/repair 计数,SpyEventStore)、WebDownlinkBudgetTests(PeakPendingFrames/PeakPendingBytes)、前端 boot.test.js(opening 恰一次 HistoryAsync(from=cursor-window, toOffset=cursor),整窗一次 baseline)、kernel.test.js(live mirror 事件/字节淘汰与 overflowed/firstSeq 披露)。浏览器原生平台门禁未执行。
  • #202(普通 checkpoint policy,bounded):97f85940(RED)→ 04acc964。agent/pre-step、llm/stream、top-level tools/execute 三 seam 的 awaited durable flush;nested 复用外层持久化上下文;SessionCheckpointPolicyTests(16)与 SessionCheckpointHardKillTests(JSONL+SQLite 硬终止回执)。
  • #203(Schedule 投递运行时,bounded):056a1241 → 5da9f2c6 → ac2b75e3。durable schedule/change 事件、exact-live driver、idle-only admission(不 steer human turn)、dispatch barrier flush、冷恢复;ScheduleDomainTests + ScheduleRuntimeTests(Orchestration 52)。两处 disclosed 上游偏离(preflight flush 合并、durability 失败后停泊)。

审计结论

  • **First-parent coverage:**32 / 32;含唯一 direct commit d921d4b357。该序列、区间计数(404 commits / 2682 changed paths)与 target tree evidence 均可由 Git-backed verifier 从受信 checkout 重新计算。
  • **Semantic topics:**28;每项都有最终 target source/test evidence、observable semantics、Tether main evidence 与合法 disposition。
  • Implementation owners:#173–#185 全覆盖;新增 orphan owner #188 后无未认领稳定 semantic delta。跨 owner 义务(#103 逐面、#111/#176 deviation、#150 决策、#201–#204 继承前置)已登记且未决项如实 blocked/pending。
  • **CPython decision:**experimental NO-GO,无需 implementation child;理由和重评条件见上文。
  • **Current worktree:**只交付 ledger/verifier;任何 owner 的工作区实现均不在本页标作 completed。

CI 布线提案(未执行,不是完成声明)

现状(platform-execution-map 只读核查):仅有 .github/workflows/ci.yml——Ubuntu/Windows 测试矩阵 + owner-only ×2 + browser-layout,push main / PR 触发,无 macOS job、无 workflow_dispatch、无 TRX/results 上传。本提案只增加同候选执行/证据布线,不改动既有 gates,不实现 #204 的 receipt infrastructure:

  1. 新增 workflow_dispatch(含 candidate SHA 输入)+ macos-latest native gate job:dotnet test tests/Tether.LocalStorage.Tests -c Release(全量)+ tests/Tether.Terminal.Local.Tests 在 macOS 上的 early-return 分类如实上传。
  2. 全部 test job 统一 --logger trx;LogFileName=<job>.trx --results-directory <dir>,actions/upload-artifact@v4 按 runs-on + 实际 checkout SHA 命名,retention 90d;附 build/publish 产物 SHA-256。
  3. 每 job 末尾输出分类摘要(executed / platform-early-return / skipped-required),PR merge-ref 与 push SHA 分别记录;不在 merge-ref 上声称分支 SHA 的结果。
  4. 执行路线与授权:workflow_dispatch 只有当该 workflow 已存在于 default branch 后才可用;推送本分支不产生任何远程执行。实际触发需要 controller 在合入后手动 dispatch 或由 push 事件自然触发——本任务不 push、不 dispatch。
  5. Native Windows ConPTY acceptance(7 tests)与 macOS 专属 LocalStorage 用例(umask000/0777 双跑、privileged 需真实批准环境)在对应 OS job 内执行并上传;off-platform return 不计为 executed。

M20 implementation closeout ledger (2026-09-21)

本节记录 M20(GitHub milestone 20,v0.18)各 implementation owner 在 origin/main 上的可复核交付。GitHub issue/milestone 仍是完成状态权威。

Issue当前 disposition当前证据(origin/main)边界
#277implementation deliveredPR #305 已合入(c57191c8);bea538cb 按必需端点审计启动并输出私有失败诊断,768f8c0f 与其合并无
#278implementation delivered510c5f78/525f4520 退役 patchReload(reload 权威归 hmr 组合行);9286abbe 提供 reconcileProfilePatches 与共享队列仅依赖变化不触发组合重载的边界由 #277 语义覆盖
#279implementation deliveredb9c3cdc1 Remote 八方法 + 三事件;628b3db7 共享 PluginManager 服务 + plugin_manager agent 工具(每动作 danger-full-access);3d8884a0 install 快照恢复 + PackageResult.kind 失败分类;ba9a801e 跨进程 profile.yaml.lock + 诊断日志路径;17a0e374 具名验收矩阵;58520138 setBundleEnabled 写 bundles: 有序栈;0050a8c2 agent 工具 danger-full-access 门具名 e2e无
#280implementation delivered1b1ae58f parser、sanitize、owner-only atomic profile write无
#281host 侧 deliveredb539da92 Rebuilt/Invalidate/ArtifactBaseline/entry Rev;d13becbd /plugins/events 全图 SSE 首帧与变更推送;e0564df8 lazy chunk 路由;f640d32c scoped 包名按已知 entry id 匹配 + Rebuilt 保留注册级内容哈希,并补 HTTP 契约用例(exact rev、HEAD 不物化、stale/unknown 404、invalidate 同代际丢弃)浏览器 require.async 消费者 e2e 属 #256 重锚后的浏览器验证面;不在本 issue 伪造
#285implementation delivered278b5b60 /api/file 与启动 globals;46d9d761 host-only unknown-field 校验(按描述符拒绝未知 args)无
#123implementation deliveredb0a46eea provider-neutral runtime + GitHub HMAC adapter;0b682874 独立 ingress host(POST /github 202 fire-and-forget);2a4a91f2 Webhook inbox source/provenance + Workspace Session admission;a141501a webhook 组合行(默认 disabled);c7ebf07b provider 插件注册具名 rule → 签名 delivery → Session 的 e2edurable dedup/queue/retry 仍是明确的非目标
#104partial;余项归 v0.20e3ffd19f team/* durable 词汇与 runtime 解耦(default-off 冷启可读历史);九工具、projection、mailbox、invariant 已在 mainHost/Web 两个 shipped optional bundle(Host patch 换四个普通工具行、agentTeams.view/createTask/updateTask、ui-agent-team 行、四态验收)依赖 v0.20 bundle 框架 #307/#308,整体验收归 #309

平台修复(M20 验证前提):062665af 修正 Darwin 的 struct stat ABI——DllImport 拿到的是 INODE32 兼容符号(st_mode 在偏移 8),此前 macOS 上 owner-only 路径全线失败、本机几乎所有套件为红;改用 $INODE64 后 Tether.LocalStorage.Tests 163/164、Tether.Web.Client.Tests 688/688。GitHub CI 只跑 Linux/Windows,因此该缺陷长期未被门禁暴露。

M20 的稳定 owner(#277/#278/#279/#280/#281/#285/#123)已交付;#104 的余项与 #309/#310 的发布物验收同属 v0.20 阶段,必须在 #307/#308 之上完成后才能宣称 milestone 整体完成。

在 GitHub 上编辑此页