v37 · 2026-07-28
canonical Dagger remote-delivery foundation
Root, Protocol, Research, Market, Sandbox, Cloud, Admin, SDK, Site, and Infrastructure produced green hosted evidence during this migration. Brand's replacement canonical-action run remained non-terminal when polling stopped; no success is claimed for it.
This burst performed no Cloudflare, Neon, DNS, Terraform apply, package publication, GitHub environment mutation, or 1Password write. Site and Infrastructure production changes remain review- and evidence-gated.
v36 · 2026-07-20
Authenticated Admin and evidence-bound CI mesh
Protocol now calls the reviewed DevOps sender only after every mandatory terminal succeeds. The covered platform-init test retains all assertions and has a 30-second budget for its real cold Cargo-backed compile after the hosted 10-second default proved insufficient.
Every sibling caller is pinned to reviewed DevOps dispatch workflow commit `d39572723b2815bd1175546210325959883c3200`, waits for its real terminal CI DAG, and removes the legacy inline `FRAUTHY_CI_TOKEN` / `peter-evans` sender.
No secret was created, copied, printed, or persisted. No Cloudflare or Neon account was assumed to exist; no Terraform apply, DNS change, deployment, image publication, or SDK/UI package publication occurred.
All implementation used isolated worktrees. Active UI and product checkouts, including untracked Project Management UI work, were preserved.
v35 · 2026-07-20
Terraform-owned topology and Dagger master delivery
No Cloudflare or Neon account was assumed to exist. No Terraform apply, DNS mutation, Pages deployment, database creation, secret write, container publication, or SDK/UI package publication occurred.
Active product and UI worktrees were preserved. This program used isolated worktrees and exact-master ancestry checks so concurrent work was not overwritten.
v34 · 2026-07-19
Infrastructure-owned Site Pages contract
No live Cloudflare API mutation, Terraform apply, Pages deployment, GitHub secret write, DNS change, or cache pruning occurred in this version.
v33 · 2026-07-19
Authenticated workspace installs and gated Site delivery
Active Root, Site, and Project Management UI checkouts were preserved. The untracked `research/packages/ui/ui` tree and all product UI SDK surfaces were untouched.
v32 · 2026-07-16
Site typed content architecture
No public UI SDK package changed or was published. The active Site, Brand, and Research UI checkouts were not modified; implementation and ledger ingestion used isolated latest-master worktrees.
v31 · 2026-07-16
Site production quality gates and interactive GP.Family lab
No package was published, no production deployment occurred, and no active Brand or Research UI checkout was modified. Work was performed in isolated latest-master worktrees to preserve concurrent frontend changes.
v30 · 2026-07-16
Portal quality program assessment
No gaps are open. Status corrects from red to green based on exact-head CI and the absence of unresolved ledger work.
v29 · 2026-07-15
CI mesh completion and Market container contract
This burst stayed outside the concurrent frontend program's ownership: no Brand, Site UI, Admin web, Cloud web, Market web, DevOps Portal, Research UI, or product `packages/ui` implementation was changed.
v23 · 2026-07-15
Cloud runtime contract moved to Cloudflare
Runtime hosting decisions are now standardized on Cloudflare. Provider-specific deployment and persistence requirements should use Cloudflare primitives; prior Kubernetes/AWS/provider-selection placeholders are no longer authoritative.
v19 · 2026-07-14
Wave 14 Protocol platform and app initialization
Commit e270ec5 completes Level 2 platform initialization with interactive prompts and deterministic flags for name, slug, provider, store, domain proof method, and visibility; it generates the authorization schema, compiler target, domain-registration helper, typed configuration, package metadata, and a versioned workspace platform registry.
Level 3 app initialization resolves a named platform from an ancestor or explicit registry, generates only app-owned configuration and auth integration, and enforces access with session.can against the registered platform resource. Missing and unknown platforms fail closed without creating partial projects.
DNS and well-known ownership proofs are wired through the generated domain helper and persisted by the domains command. An end-to-end generated Keto platform schema compiles outside the Protocol checkout after correcting compiler schema-path resolution to the invoking project directory.
Sixty-five CLI tests with 272 assertions cover defaults, custom flags, registry preservation and resolution, generated-project compilation, DNS proof persistence, minimal app ownership, and fail-closed behavior. All workspace targets, strict Clippy, formatting, canonical type-contract tests, seven-crate packaging, coverage gates, and live backend suites pass.
Wave 14 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol CLI code, tests, documentation, its gap checklist, and this Research ledger event changed; no UI-owned surface, product packages/ui, Portal, registry publication, release tag, or concurrent UI branch was touched.
v18 · 2026-07-14
Wave 13 Protocol mapping completion
Commit 7332293 completes the mapping engine contract with DomainIn, Regex, IsTrue, and cloneable thread-safe Custom conditions; MappingRule idempotency and freshness controls; and MappingResult evaluation metadata.
Mapping freshness is operational through the lifecycle, not merely an evaluator flag: a recent successful idempotent rule skips both re-evaluation and the second Store write, while failed writes invalidate subject cache state and unverified claims never poison it.
Nineteen focused core tests and six lifecycle tests cover condition semantics, metadata counts, idempotent versus non-idempotent behavior, freshness hits, failed-write retry safety, and the zero-second-write guarantee. All workspace targets, strict Clippy, formatting, SDK type-contract tests, 51 CLI tests, seven-crate packaging, and live backend suites pass.
Wave 13 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol mapping/lifecycle code, tests, dependency metadata, its gap checklist, and this Research ledger event changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v17 · 2026-07-14
Frontend SDK federation prerelease gate
Frontend SDK Federation automated prerelease gate complete: seven Internal @frauthy/*-ui packages at 1.0.0-next.0, exact immutable tags and registry versions, seven verified Brand Portal libraries, 240 public components, and 634 catalog previews. Stable 1.0.0 promotion remains blocked only on the planned manual VoiceOver, NVDA, and TalkBack/touch-AT evidence.
v16 · 2026-07-14
Wave 12 Protocol LSP completion
Commit 334b7d7 completes scoped references and rename for entities, relations, permissions, relation type references, subject-set references, and traversal leaves. Same-named members in different entities remain isolated, and rename fails closed on invalid identifiers or same-scope collisions.
The LSP now advertises and handles textDocument/references, textDocument/rename, textDocument/codeAction, and textDocument/semanticTokens/full. Code actions create unresolved relations, add a first permission, and extract complex permission expressions; semantic tokens cover keywords, types, relations, permissions, backend values, and comments.
Twenty-eight focused LSP tests include capability registration, per-feature analysis coverage, and an in-memory JSON-RPC references round trip with declaration inclusion and exclusion. All workspace targets, strict Clippy, formatting, SDK type-contract tests, 51 CLI tests, and seven-crate packaging pass; remote Rust coverage rose to 74.42% and passed the 69.72% ratchet.
Wave 12 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol LSP code/tests/documentation and the Research ledger changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v15 · 2026-07-14
Wave 11 Protocol async contracts
Commits 15ce42f and 5461d23 complete the Send + Sync async Provider and Store contracts across frauthy-core, OIDC, SpiceDB, Keto, lifecycle callers, conformance fixtures, and observe tests. Public consistency, lookup, watch, discovery, verified-claim, and write-cursor types now have one canonical core contract.
SpiceDB writes preserve real ZedTokens, lookup flows through the Store trait, and watch uses the native gRPC WatchService with official protobuf wire shapes. Keto exposes opaque monotonic cursors and a paginated tuple-diff watch stream; neither adapter substitutes a fake in-process event queue.
Real SpiceDB and Keto permission, lifecycle, lookup, OIDC, Jaeger, and Keto watch suites pass. Native SpiceDB watch was separately proven against a watch-capable memory datastore because the registered PostgreSQL-backed development container reports WatchService unsupported.
All offline workspace targets, strict Clippy, formatting, the seven-crate packaging dry-run, CLI tests, and canonical type checks pass. Focused async edge-case tests raise Rust line coverage from the transient 69.47% result to 70.52%, above the unchanged 69.72% ratchet.
Wave 11 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol core/backend contracts, Protocol tests/documentation, and the Research ledger changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v14 · 2026-07-14
Wave 10 Protocol dev runner
Commit b1ba864 replaces the frauthy dev instruction printer with a supervised process runner. It discovers or accepts a schema, validates Cargo and cargo-watch, launches compiler hot reload, reports PIDs, and returns actionable usage or prerequisite failures.
frauthy dev --core additionally launches frauthy-lsp over stdio. SIGINT and SIGTERM stop every managed child, partial startup and child failures clean up siblings, and conventional exit codes propagate to the caller.
Nine deterministic lifecycle tests cover discovery, ambiguity, missing prerequisites, argv-safe paths, core launch, signal cleanup, failure cleanup, and process exit. A real polling watcher smoke test recompiled an edited schema and stopped cleanly with Ctrl+C.
The CLI now carries exact Bun and TypeScript development typings, a frozen Bun lockfile, and a protected typecheck in addition to its 51 passing tests. Docker-backed stores remain explicitly owned by DevOps.
Wave 10 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol CLI, Protocol documentation, and the Research ledger changed; no UI-owned, package publication, registry, or tag path was touched.
v13 · 2026-07-14
Wave 9 Protocol-SDK type contract
Commit a12565a makes seven shared public types a checked Protocol-owned manifest. The checker extracts structs, fields, enum variants, and source order directly from frauthy-core; a mutation test proves an unreflected Rust field rename fails CI.
Wave 9 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Protocol and core SDK are wholly Gap Closure-owned; no Brand, packages/ui, frontend composition, Portal, product UI, registry publication, or tag path changed.
v12 · 2026-07-14
Wave 8 Protocol release readiness
Commit 9e22cb1 adds strict formatting and warnings-as-errors Clippy to the protected Rust job, while retaining the existing LCOV producer and upward-only coverage gate.
Seven crates now inherit one workspace version and complete registry metadata. Exact versions accompany internal path dependencies, and all seven upload archives pass the non-publishing package gate; cargo publish --dry-run also reached the frauthy-core upload boundary and aborted as designed.
release-crates.yml accepts only crate-v<VERSION> tags at the current protected master commit, repeats format/Clippy/tests/package verification, and publishes in dependency order with index-propagation waits.
No crate or tag was published. Rust crates are a future public crates.io release gated on CARGO_REGISTRY_TOKEN; the npm CLI remains Internal on GitHub Packages.
Strict Clippy replaced the LSP document map's cache-bearing Uri keys with stable serialized strings rather than suppressing the mutable-key warning.
Wave 8 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Protocol is wholly Gap Closure-owned; no Brand, packages/ui, frontend composition, Portal, or product UI path changed.
v11 · 2026-07-14
Wave 7 branch protection
Wave 7 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, packages/ui, frontend composition, DevOps Portal, Research UI, or Sandbox UI path changed.
v10 · 2026-07-14
Wave 6 Protocol and SDK coverage gates
Actions run 29352211785 passed and retained both LCOV reports plus gate summaries. PROTO-11 remains open because its crates.io publication and strict Clippy acceptance are not complete.
Wave 6 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, packages/ui, frontend composition, DevOps Portal, Research UI, or Sandbox UI path changed.
GitHub Actions billing is restored; all Protocol, SDK, and DevOps master workflows in this wave received runners and completed successfully.
v9 · 2026-07-14
Wave 5 coverage producers verified
GitHub Packages authentication was verified through the local gh credential. Brand packages are available at 1.0.0-next.1 and all seven product UI packages at 1.0.0-next.0 with internal visibility.
Verification remained inside the ownership boundary in root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md; no Brand, packages/ui, web composition, Portal, Research UI, or Sandbox UI path changed.
v8 · 2026-07-14
Wave 5 Cloud and Market coverage producers
Local gates passed: Cloud 208 tests with 30 live-service tests gated, Market 176 tests with 29 live-service tests gated, and DevOps 132 tests; all three typechecks passed.
GitHub marked the DevOps, Cloud, and Market jobs failed without starting a runner because recent account payments failed or the spending limit must be increased. This is recorded as a human-gated infrastructure blocker, not as code verification.
Wave 5 remained inside the ownership boundary in root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md; no Brand, packages/ui, web composition, Portal, Research UI, or Sandbox UI path changed.
v7 · 2026-07-13
Wave 4 Rust telemetry and real CI enforcement
Wave 4 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, product packages/ui, web composition, DevOps Portal, Research UI, or Sandbox UI path was changed.
GitHub Packages publication and UI release coordination remain owned by the concurrent Frontend SDK Federation.
v6 · 2026-07-13
Wave 3 cross-backend verification and observability
Wave 3 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Brand, Site, product packages/ui, Cloud/Market web migration, Admin editor composition, DevOps Portal, Research UI, and Sandbox UI were intentionally untouched.
GitHub Packages publication remains blocked on a registry-compatible PAT in the concurrent federation session; no package publication is claimed here.
v5 · 2026-07-12
Wave 2 deconflicted backend and CI mesh
Live CI exposed and fixed SpiceDB subject-set wire encoding, Keto SubjectSet compiler output, and backend-neutral wildcard behavior. Stateful backend cases are isolated and Socket Firewall dependency bootstrap is retried without bypassing it.
Wave 2 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Brand, Site, product packages/ui, Cloud/Market web migration, Admin editor composition, DevOps Portal, Research UI, and Sandbox UI were intentionally untouched.
GitHub Packages publication remains blocked on a registry-compatible PAT in the concurrent federation session; no package publication is claimed here.
v4 · 2026-07-12
Wave 1 remote CI gate
Remote gate complete: SDK CI, infrastructure CI/image build, sandbox tokenless integration, and the manually-dispatched SDK staleness workflow are green.
v3 · 2026-07-12
Wave 1 deconflicted backend lanes
Domain registration now round-trips, eject is reversible, compiler diagnostics are expanded, BetterAuth and Hydra adapters are real, OIDC-connected proof verification works, lifecycle trace context is carried, and CI installs are Socket Firewall compliant.
PROTO-1 remains open; the async trait redesign was deliberately deferred instead of landing a partial contract migration.
Wave 1 was deconflicted from the concurrent Frontend SDK Federation. Brand, site, root, research UI, and all owned web/portal surfaces were intentionally untouched.
v1 · 2026-07-12
Baseline — workspace-wide gap audit
Seeded from the 2026-07-12 twelve-agent audit of all eleven repos plus the Cuitty capability catalog. Eleven gap-closure specs written; orchestration plan at root/specs/06-GAP-CLOSURE-ORCHESTRATION.md.