Skip to content

fix: publish v5 local CI, context, and desktop safeguards - #53

Draft
RecursiveIntell wants to merge 12 commits into
mainfrom
fix/arch-stabilization-v5-local-evidence
Draft

RecursiveIntell wants to merge 12 commits into
mainfrom
fix/arch-stabilization-v5-local-evidence

Conversation

@RecursiveIntell

@RecursiveIntell RecursiveIntell commented Sep 14, 2026

Copy link
Copy Markdown
Owner

Summary

This draft PR publishes the verified, candidate-local portions of the v5 architecture-stabilization work against the current Ares main base. It is intentionally limited to CI aggregation, Desktop busy-composer semantics, Context Governor lineage/restart handling, a Markdown property-fuzz timeout correction, and the reviewed httpx2 lock upgrade.

The historical Ares PRs #35 and #41 are not rewritten or closed by this branch.

Changes

  • Make the required-check aggregate expectation-aware and fail closed on missing, unknown, cancelled, or non-applicable job results.
  • Keep the deliberately disabled Desktop E2E lane explicit with literal if: false and checksum-pinned actionlint validation.
  • Make the Desktop composer expose truthful Stop, Steer, and Queue actions during busy/compaction states.
  • Preserve Context Governor derived-summary markers, host checkpoints, recursive lineage classification, and restart recovery bindings.
  • Bound the Markdown property-fuzz test so the existing test remains deterministic under the current runner.
  • Upgrade the httpx2/httpcore2 lock path from 2.7.0 to 2.12.0.
  • Refresh the locked h2, hpack, and tornado pins to 4.4.1, 4.2.0, and 6.5.8 respectively.
  • Prevent the ISO certification harness from inheriting the compute-host child marker and add a regression test for that boundary.

Local validation

  • Ares CI contract/evaluator tests: 22 passed.
  • Desktop composer controls/submit tests: 44 passed.
  • Context Governor restore suite: 60 passed, 4 deselected.
  • Markdown block tests: 6 passed.
  • Dependency metadata/lazy-dependency tests: 67 passed, 1 skipped.
  • Exact Desktop aggregate (typecheck, lint, UI, Electron platform tests, build): passed.
  • Focused Desktop busy/compression/compaction-queue E2E witnesses: passed.
  • Staged packet guard and detect-secrets scans: passed with empty findings.
  • Exact committed ISO harness seam suite: 3 passed; exact committed 600-second ISO-ON certification: passed with 17 heavy turns, zero serving stalls, REST p99 13.81 ms, and WebSocket p99 3.16 ms.

Known limitations / retained proof debt

  • These are controller-run local/source-level results. Hosted CI subsequently ran on this head and is not green: Review label gate and All required checks pass failed. Workflow dispatch was not separately dispatched.
  • The fresh full Desktop E2E run remains failed with 17 current failures. Focused action witnesses do not override that result.
  • The current candidate has a bounded high-load Context Governor witness passing, and candidate-bound restart witnesses CG-01.G02 and CG-04.G03 passing. These witnesses do not certify the original high-load workload or close full ARES qualification. The earlier candidate continuation run reported 9 passed, 1 failed on compute-host ownership; that result is retained as historical failure evidence and is not the current candidate status.
  • The canonical ARES-FULL attempt timed out, so full Ares qualification remains incomplete. The valid six-lane, 120-second ISO-OFF control remains failure evidence with 8 serving stalls. The earlier six-lane, 600-second ISO-ON receipt is retained but is invalid for isolation qualification because the controller inherited HERMES_COMPUTE_HOST_CHILD=1, which made the scratch dashboard disable dashboard.turn_isolation. Commit 5e5bdff6419404b038b5e28080d77170697e279c removes that child-only marker from the top-level certification dashboard environment; the exact committed 600-second ISO-ON rerun passed with 17 heavy turns, zero serving stalls, REST p99 13.81 ms, and WebSocket p99 3.16 ms. This is local source- and environment-specific certification evidence, not a universal performance, production-readiness, security, or overall completion claim.
  • The lock refresh now has a scoped locked third-party Python audit reporting 0 known vulnerabilities across 245 dependencies. Node audits remain non-clean; this is not a general security certification.
  • This PR does not implement the separately versioned native provider/tool protocol, an Ares native tool loop, activation, recurrence, live repair, or historical-goal transitions.

Boundary

No provider call, credential change, live migration, activation, ruleset change, merge, or historical identity transition is part of this PR. This draft must not be interpreted as fully validated, secure, production-ready, or release-ready.

@github-actions

github-actions Bot commented Sep 14, 2026

Copy link
Copy Markdown

૮ >ﻌ< ა ci review

ran on 5e5bdff — fix(iso): sanitize compute-host marker in certify harness

⚠️ Action required

CI-sensitive file review · View job

This PR changes CI-sensitive files (eslint config, workflow YAMLs, or composite actions). These influence what the js-autofix job executes and pushes to main.

Sensitive files changed:

How to fix:

Add the ci-reviewed label after verifying:

  • no new eslint rules with custom fix functions that write outside linted paths,
  • no workflow changes that widen permissions or remove guards,
  • no composite action changes that alter what gets executed.

package-lock.json · View job

Locked npm dependency versions changed.

package-lock.json

Package Before After
@electron/get 2.0.3 5.1.0
brace-expansion (nested under @eslint/config-array) 1.1.12 1.1.18
brace-expansion (nested under @eslint/eslintrc) 1.1.12 1.1.18
electron 40.10.2 40.10.6
brace-expansion (nested under eslint) 1.1.12 1.1.18
js-yaml 4.3.1 4.3.2
➕ @electron-internal/extract-zip 1.0.5
➕ env-paths (nested under @electron/get) 3.0.0
➕ undici (nested under @electron/get) 7.29.0
➖ semver (nested under @electron/get) 6.3.1
➖ @types/yauzl 2.10.3
➖ extract-zip 2.0.1
➖ fs-extra 8.1.0
➖ pend 1.2.0
➖ yauzl 3.4.0

scripts/whatsapp-bridge/package-lock.json

Package Before After
@emnapi/runtime 1.11.2 1.11.3
@img/sharp-darwin-arm64 0.35.3 0.35.4
@img/sharp-darwin-x64 0.35.3 0.35.4
@img/sharp-freebsd-wasm32 0.35.3 0.35.4
@img/sharp-libvips-darwin-arm64 1.3.2 1.3.3
@img/sharp-libvips-darwin-x64 1.3.2 1.3.3
@img/sharp-libvips-linux-arm 1.3.2 1.3.3
@img/sharp-libvips-linux-arm64 1.3.2 1.3.3
@img/sharp-libvips-linux-ppc64 1.3.2 1.3.3
@img/sharp-libvips-linux-riscv64 1.3.2 1.3.3
@img/sharp-libvips-linux-s390x 1.3.2 1.3.3
@img/sharp-libvips-linux-x64 1.3.2 1.3.3
@img/sharp-libvips-linuxmusl-arm64 1.3.2 1.3.3
@img/sharp-libvips-linuxmusl-x64 1.3.2 1.3.3
@img/sharp-linux-arm 0.35.3 0.35.4
@img/sharp-linux-arm64 0.35.3 0.35.4
@img/sharp-linux-ppc64 0.35.3 0.35.4
@img/sharp-linux-riscv64 0.35.3 0.35.4
@img/sharp-linux-s390x 0.35.3 0.35.4
@img/sharp-linux-x64 0.35.3 0.35.4
@img/sharp-linuxmusl-arm64 0.35.3 0.35.4
@img/sharp-linuxmusl-x64 0.35.3 0.35.4
@img/sharp-wasm32 0.35.3 0.35.4
@img/sharp-webcontainers-wasm32 0.35.3 0.35.4
@img/sharp-win32-arm64 0.35.3 0.35.4
@img/sharp-win32-ia32 0.35.3 0.35.4
@img/sharp-win32-x64 0.35.3 0.35.4
qs 6.15.3 6.16.0
sharp 0.35.3 0.35.4

website/package-lock.json

Package Before After
baseline-browser-mapping 2.10.43 2.11.20
browserslist 4.28.6 4.28.8
caniuse-lite 1.0.30001806 1.0.30001810
colord 2.9.3 2.9.4
electron-to-chromium 1.5.392 1.5.418
fast-uri 3.1.5 3.1.6
joi 17.13.4 17.13.6
js-yaml 4.3.1 4.3.2
node-releases 2.0.51 2.0.54
qs 6.15.3 6.16.0
svgo 3.3.4 3.3.5
update-browserslist-db 1.2.3 1.3.2
➕ nanoid 3.3.18
➖ nanoid (nested under postcss) 3.3.17

How to fix:

Add the ci-reviewed label after verifying the version changes are expected.


⚠️ Warnings

OSV vulnerability scan · View job

7 known vulnerabilities found in pinned dependencies.

How to fix:

Review the findings in the Security tab. Update the affected dependencies if a patched version is available.


debug info

CI timings

CI timings · View report · View job

Wall time 9m36s vs 9m31s (+0.9%). 26 job(s) slower, 14 faster, 4 unchanged.

  • JS & TS checks / apps/desktop / check:test:ui:shard-2of3: +65.0s
  • Python tests / Run tests slice 5/12: +59.0s
  • Python tests / Run tests slice 3/12: +55.0s
  • Python tests / Run tests slice 4/12: +48.0s
  • JS & TS checks / apps/desktop / check:test:desktop:platforms: +46.0s

@RecursiveIntell

Copy link
Copy Markdown
Owner Author

v5 publication checkpoint

Published candidate-local work at head 208cf07f1d9af6d250264d4ce758d7d687f3c7d1 from Ares main 370e3621bd90249e4492b4bac1d3e0046b828ae3.

Commits

  • d3bfd0da4 — fail-closed required-check aggregation and CI workflow contracts
  • afd007544 — truthful Desktop Stop/Steer/Queue composer actions
  • 54978924e — Context Governor lineage/restart marker preservation
  • 11b73562e — bounded Markdown property-fuzz test
  • 208cf07f1 — reviewed httpx2/httpcore2 lock upgrade

Verified locally

  • CI evaluator/workflow tests: 22 passed
  • Desktop composer controls/submit tests: 44 passed
  • Context Governor restore suite: 60 passed, 4 deselected
  • Markdown block tests: 6 passed
  • Dependency metadata/lazy-dependency tests: 67 passed, 1 skipped
  • Exact Desktop aggregate: passed (typecheck, lint, UI, Electron platform suite, build)
  • Focused busy/compression/compaction-queue E2E witnesses: passed
  • Final staged-diff packet guards and detect-secrets: passed with empty findings

Retained limitations

  • The new P09 continuation contract test was held back because its current run was 9 passed, 1 failed on compute-host ownership.
  • Full Desktop E2E remains failed with 17 current failures.
  • ARES-FULL and ISO sustained-load qualification remain incomplete.
  • The dependency upgrade reduces the locked Python audit to five findings in h2/tornado; this is not a clean security result. Existing Node findings remain visible.
  • Hosted CI, native provider/tool integration, provider calls, activation, live repair, recurrence, and historical-goal transitions were not performed.

This is a draft progress checkpoint, not a merge, release, security, production-readiness, or full-program-completion claim. Existing PRs #35 and #41 remain untouched.

@RecursiveIntell

Copy link
Copy Markdown
Owner Author

v5 hosted/publication reconciliation

Head verified: 208cf07f1d9af6d250264d4ce758d7d687f3c7d1; base: 370e3621bd90249e4492b4bac1d3e0046b828ae3.

This note corrects the earlier statement that hosted CI had not run. The PR remains a draft and is not merge-ready.

Hosted state at readback

Evidence boundary

The local test counts and focused Desktop witnesses in the PR description remain controller-run, source-level evidence. The fresh full Desktop E2E result remains 17 failures; ARES-FULL and ISO stress remain incomplete.

P13/P14 native provider/tool integration, external-provider calls, activation, live repair, recurrence, historical-goal transitions, merge, and release claims remain out of scope and unproven.

Historical Ares PRs #35 and #41 remain untouched.

@RecursiveIntell

Copy link
Copy Markdown
Owner Author

v5 security refresh

Head: 778a62e37bd76c6b93dd3ced20a14b8a621fc697. This commit is a lockfile-only security refresh; it does not alter runtime code or provider behavior.

Change

  • h2 4.3.0 → 4.4.1
  • hpack 4.1.0 → 4.2.0
  • tornado 6.5.7 → 6.5.8

Controller-run validation

  • uv lock --check: passed; 255 packages resolved.
  • Packaging/lazy-dependency tests: 90 passed, 2 skipped.
  • Scoped locked third-party Python audit: 0 known vulnerabilities across 245 dependencies.
  • git diff --check: passed; the commit contains only uv.lock.

Boundary

This is not a universal security guarantee: the Ares Node audits remain non-clean, and the broader v5 program still retains P09/P11/P12/P13–P16 proof debt. No production-readiness, merge-readiness, activation, provider-call, live-repair, or completion claim is intended.

@RecursiveIntell

Copy link
Copy Markdown
Owner Author

v5 current-gate reconciliation

Head: 778a62e37bd76c6b93dd3ced20a14b8a621fc697. This note updates the earlier progress checkpoint with current evidence; the PR remains a draft and is not merge-ready.

Current hosted/local state

  • All 12 hosted Ares Python test slices on this head completed successfully, but All required checks pass and Review label gate remain failed.
  • The canonical ARES-FULL attempt timed out; no full-suite green claim is made.
  • The valid six-lane, 120-second ISO-OFF control failed with 8 serving stalls.
  • The valid six-lane, 600-second ISO-ON run failed with 32 serving stalls. Isolation therefore remains an open failed gate, not a certification.
  • The current candidate’s bounded high-load Context Governor witness and CG-01.G02/CG-04.G03 restart witnesses pass. The earlier 9-pass/1-fail continuation result remains preserved historical failure evidence and is not erased.

Boundary

These are controller-run local/source-level and hosted-check observations. They do not establish full Ares qualification, sustained-load success, security certification, production readiness, native provider/tool integration, activation, live repair, recurrence, merge readiness, or full-program completion.

@RecursiveIntell

Copy link
Copy Markdown
Owner Author

v5 Desktop test-harness correction

Head intended for publication: a43d1179544b97ae62a5c14b0d8b5f179f007f86
Base published head: 778a62e37bd76c6b93dd3ced20a14b8a621fc697

This commit changes only apps/desktop/e2e/production-permit.spec.ts: it resolves the paired Recursive Agent source from the current sibling recursive-agent candidate instead of an obsolete historical worktree name.

Controller-run validation

  • Exact production-permit witness: 1 passed.

The fresh full Desktop E2E run remains failed with 17 current failures; this targeted correction does not override that result.

Boundary

No provider call, credential change, activation, merge, production-readiness, or full Desktop-E2E claim is intended.

@RecursiveIntell

Copy link
Copy Markdown
Owner Author

v5 Desktop test-harness correction — exact-head rerun

The exact committed head a43d1179544b97ae62a5c14b0d8b5f179f007f86 was rerun in the controller environment. The production-permit witness completed successfully: 1 passed. This confirms the one-line sibling-root correction on the committed source, beyond the earlier dirty-worktree result.

The fresh full Desktop E2E result remains failed with 17 current failures; this targeted witness does not override that gate. The PR remains a draft and this update does not claim production readiness, security certification, merge readiness, activation, provider execution, or full-program completion.

@RecursiveIntell

Copy link
Copy Markdown
Owner Author

v5 workflow-lint baseline correction

Head: 7e567e35ca8a8b788cdb83efb6d73b7957d28432
Base: 370e3621bd90249e4492b4bac1d3e0046b828ae3

This exact-scope follow-up changes seven existing workflow files. It quotes the merge-base expansion, removes a redundant cat pipeline, preserves the literal jq expression without shell expansion, and documents only the intentional SC2016 cases where Markdown backticks are embedded in JSON or CLI text. No broad actionlint or ShellCheck disable was added.

Controller-reported validation

  • Ares workflow contract tests: 22 passed.
  • Full local actionlint over current workflows: passed with the existing literal-false Desktop applicability exception.
  • git diff --check: passed.

The prior exact-head hosted All required checks pass failure was caused by baseline ShellCheck diagnostics in untouched workflow files; this commit is intended to address that lint baseline.

Boundary

A new hosted run is required before claiming the hosted lint gate or aggregate is passing. This PR remains a draft; the existing 17-failure full Desktop E2E result, neutral OSV result, and Review label gate remain visible. No production, security-certification, merge-readiness, activation, provider-execution, or full-program-completion claim is intended.

@RecursiveIntell

Copy link
Copy Markdown
Owner Author

v5 workflow-lint baseline correction

Head: 01d1cd6e39df59fc23bbb3907dc5c0e3fafd7a64
Base: 370e3621bd90249e4492b4bac1d3e0046b828ae3

This one-token follow-up replaces the unused polling-loop variable i with _ in .github/workflows/js-autofix.yml. It is a behavior-preserving ShellCheck cleanup intended to clear the remaining hosted actionlint SC2034 baseline warning.

Controller-reported validation

  • Ares workflow contract tests: 22 passed.
  • Full local actionlint: passed with the existing literal-false Desktop applicability exception.
  • git diff --check: passed.

Hosted boundary

The preceding hosted run at 7e567e35 reported the SC2034 warning and failed the aggregate; a new exact-head run is required. This PR remains a draft. Existing policy, OSV, full Desktop-E2E, P09/P10/P12, native-integration, activation, and completion boundaries remain unchanged and visible.

No production, security-certification, merge-readiness, provider-execution, or full-program-completion claim is intended.

@RecursiveIntell

Copy link
Copy Markdown
Owner Author

v5 scoped dependency/security refresh

Published commit: 811522d205633e565e368e0242068c019555f391
Base: 370e3621bd90249e4492b4bac1d3e0046b828ae3

This draft update refreshes selected dependency pins and lockfiles, and removes an invalid Liquid raw-block wrapper from the bundled arXiv skill documentation:

  • Ares root: brace-expansion 1.1.18 and js-yaml 4.3.2 overrides;
  • Desktop: Electron 40.10.240.10.6, including the build electron version;
  • Website: eligible patched overrides for Browserslist, baseline browser mapping, js-yaml, nanoid, qs, sharp, svgo, fast-uri, joi, and colord;
  • WhatsApp bridge: Express 4.22.2, qs 6.16.0, and sharp 0.35.4.

Exact-commit lockfile-only audits reported zero findings:

  • root: 0 / 1,515 dependencies;
  • Website: 0 / 1,389 dependencies;
  • WhatsApp bridge: 0 / 166 dependencies.

Additional recorded validation:

  • Desktop typecheck: passed;
  • Desktop lint: passed with 272 existing warnings and 0 errors;
  • Electron platform suite: 1,970 passed, 6 skipped;
  • Desktop build: passed;
  • Website build: passed with existing broken-link warnings;
  • WhatsApp bridge syntax check: passed.

Known limitations remain explicit:

  • Website typecheck still fails on existing JSX namespace errors and the generated userStories.json type-resolution path;
  • the post-refresh serial Desktop UI run timed out at 900 seconds;
  • full Desktop E2E remains separately failed;
  • Website broken-link warnings remain unresolved;
  • the scoped lockfile audits do not establish universal security, production readiness, merge readiness, or completion;
  • the unrelated untracked P09 test was excluded from the commit.

Receipts are preserved under P08/ and the commit/push receipt under P17/ares-push-security-mdx-811522d/. The PR remains a draft; hosted results for this new head must be read back separately.

@RecursiveIntell

Copy link
Copy Markdown
Owner Author

v5 hosted result for 811522d

The exact-head hosted Ares run completed:

  • Run: 34964301821
  • Head: 811522d205633e565e368e0242068c019555f391
  • Base: 370e3621bd90249e4492b4bac1d3e0046b828ae3

Observed:

  • substantive Python, Rust/bootstrap, JS/TS, desktop-platform, docs-site, Nix, package-lock semantic-diff, and supply-chain checks: passed;
  • Review label gate: failed;
  • All required checks pass: failed;
  • osv-scanner: neutral;
  • Desktop E2E: skipped by the workflow’s current affected-area policy.

This run is hosted evidence for the published commit only. It does not establish merge readiness, production readiness, universal security, or completion. No label/ruleset change was made; the PR remains draft.

@RecursiveIntell

Copy link
Copy Markdown
Owner Author

v5 Website typecheck/build follow-up

Published commit: 80141c48f129432dce0851d242cf13f452780376
Base: 811522d205633e565e368e0242068c019555f391

This follow-up:

  • sets website/tsconfig.json baseUrl to the project root and enables resolveJsonModule;
  • replaces global JSX.Element annotations with React.JSX.Element in the two affected components;
  • removes invalid Liquid raw-block tags from the Simplified Chinese arXiv guide, matching the earlier English correction.

Exact-commit validation:

  • Website typecheck: passed;
  • full npm run build: passed.

The full build still emits existing broken-link and broken-anchor warnings; those warnings remain open and are not being represented as a clean documentation gate. This update also does not establish universal security, production readiness, merge readiness, or completion of the broader stabilization handoff. The unrelated untracked P09 test remains excluded.

Receipts:

  • P08/npm-website-typecheck-exact-80141c48/receipts/2026-09-15-5acede2034054cf79b799feb09718d31.json;
  • P08/npm-website-build-exact-80141c48/receipts/2026-09-15-ac3c4f4fca8c4af193dc7d3378917cc5.json;
  • P17/ares-push-website-followup-80141c48/receipts/2026-09-15-3ab5f54e3617475c85663ee2c05737cc.json.

@RecursiveIntell

Copy link
Copy Markdown
Owner Author

v5 P09 ISO harness environment-boundary correction

Published commit: 5e5bdff6419404b038b5e28080d77170697e279c
Base: 80141c48f129432dce0851d242cf13f452780376

This two-file correction updates scripts/iso-certify.py and its seam test. The top-level scratch dashboard now removes only the inherited HERMES_COMPUTE_HOST_CHILD marker while preserving other environment values. Without this boundary, a controller launched inside a compute-host child caused the scratch dashboard to disable dashboard.turn_isolation, invalidating the ON measurement.

Controller-run validation

  • RED selector before the helper existed: failed with the expected missing-helper AttributeError; receipt retained.
  • Exact committed ISO seam suite: 3 passed.
  • Exact committed full ISO-ON run: passed over 600 seconds with 6 lanes, 17 valid heavy turns, zero serving stalls, REST p99 13.81 ms, and WebSocket p99 3.16 ms.
  • Retained scratch logs record compute host started; no provider call was used.

Corrected evidence boundary

  • The earlier 600-second ISO-ON receipt is retained but is invalid for isolation qualification because its controller environment inherited HERMES_COMPUTE_HOST_CHILD=1.
  • The valid 120-second ISO-OFF control remains failure evidence with 8 serving stalls.
  • The corrected ISO-ON result is local source- and environment-specific evidence. It does not establish universal performance, production readiness, merge readiness, security, or completion.
  • The broader ARES-FULL gate, Desktop E2E, P12, P13/P14, and remaining v5 gates are unchanged.

Receipts: P09/iso-env-exact-commit-tests/receipts/2026-09-15-da6b9430bcfc458fbff1bea5e0f1e78d.json, P09/iso-on-certification-v2/receipts/2026-09-15-25b3cc79215f4ff69f8b500359abbd3a.json.

RecursiveIntell added a commit that referenced this pull request Sep 16, 2026
Reuse scoped dependency work from Ares PR #53 commits
208cf07,
778a62e, and
811522d; retain only
dependency manifests, locks, and the matching lazy-install pin.

Add bounded current-advisory updates. This source checkpoint
does not claim merge, activation, or stabilization completion.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant