Project
Changelog
All user-visible changes follow the categories required by docs/releases.md. A published section maps to the canonical immutable signed Git tag with the same semantic version.
All user-visible changes follow the categories required by docs/releases.md. A published section maps to the canonical immutable signed Git tag with the same semantic version.
#0.2.0 — Unreleased
#Added
- Product contract, onboarding, operational, core, integration, example, testing, release, security, and support documentation.
- Authenticated guided setup that records completion only after the sealed runtime, enabled privileged backend, and a matching live kernel-gated agent session are all observed.
- Desktop build provenance and immutable release packaging contract.
- Public Tama CLI for catalog listing and validation with opt-in local install-drift checks, exact hook inspection, live session state, registry-declared provider coverage, Git dispatcher installation, repository scans and cleanup, adaptive recovery, MCP configuration, and the loopback desktop backend.
- Runnable
examples/shell commands with inline risk, required-input, side-effect, and rollback comments; CLI link installation is retry-safe, and prose runbooks plus the Markdown coverage matrix were removed. - Session destination that renders the capability a supervised session holds — lifetime, expiry, remaining uses and every tool grant — together with the register of semantic decisions that session published.
- Coverage destination for registry-declared provider coverage, and an Install plan destination that states each scope's target paths, the exact commands that write them, and the MCP server snippet.
- Settings destination for local enforcement — runtime installation, privileged backend registration and macOS approvals, and the confirmed deactivation of everything — plus the product and hook-release build identities.
- Documentation corpus: per-screen desktop reference under
docs/desktop/, concept pages underdocs/concepts/, two executed walkthroughs (release seal verification, runtime status), a runbook of exact refusal sentences, a scripts reference, and runnable read-only integrity examples underexamples/integrity/.
#Changed
- Runtime installation and macOS policy registration require explicit authenticated confirmation instead of running during model initialization.
- Session discovery is read-only when Tama has not been configured.
- Session monitoring starts only while the authenticated control surface is visible.
- Policy controls now require a current recognized Wisent organization role, and mutation-capable models enforce an explicit construction-time authorization boundary.
- Tama opens Wisent session restoration directly; the explicitly selected read-only inspector uses isolated bundled-catalog state, while incomplete authenticated setup resumes until its evidence is complete.
- In-flight repository scans and cleanup can be stopped; scan cancellation is read-only, while cleanup preserves partial edits and performs the final rescan.
- Runtime-drift CLI checks now resolve Claude and Codex adapter configuration from the current or explicitly selected user home instead of maintainer paths embedded in the signed catalog.
- Local setup and emergency commands now drain output concurrently, enforce bounded output and runtime, and terminate their process tree on timeout.
- Leaving the authenticated control surface cancels active repository scan or cleanup process trees and requires inspection plus a new read-only scan after partial cleanup.
- Product and hook-release identities are displayed separately.
- OMP session-control reload actions use the documented v2 identity, persist checksum-bound hook state, and schedule one native runtime reload after the active agent turn settles; the desktop waits for the matching authoritative response and distinguishes a scheduled reload from a stale or failed runtime.
- Per-session controls now expose only policy-permitted enable operations and wait for the live supervisor response; the desktop no longer offers or optimistically reports prohibited hook disablement.
- The interface is organized by operator decision rather than by data container: a grouped sidebar of eight destinations, a 44 pt context bar on every screen instead of a hero header, three-zone data screens with counted facet rails and inspectors, and the repository under repair selected once in the sidebar header.
- Disabling every managed hook, repairing violations with a headless agent, and deactivating local enforcement now open a decision dialog that quotes the exact effect, lists what it touches, and keeps the safe verb as the primary button.
- Mutations report the backend's own sentence in place on the screen that started them, instead of a modal alert that closes without a trace.
#Fixed
- OMP session records and overrides now use the documented v2
agentIdidentity, allowing the desktop to discover live sessions and exchange validated controls; a legacy-only v1 state now produces an actionable runtime-reinstall diagnostic instead of an unexplained empty session list. - Session-discovery failures remain visible instead of being represented as an empty successful result.
- Optional violation tooling no longer depends on a hard-coded maintainer directory.
- Nonzero cleanup-agent exits cannot be reported as successful cleanup even when partial edits remove the final violation.
- Hook registration now rejects invalid timeout and registry-path arguments before mutation, reports registry-load, registry-I/O, or mutator-launch failures without an unhandled stack trace, preserves registry permissions across atomic replacement, and retains the primary error if temporary-file cleanup also fails.
- Session control now labels hook-registry load failures explicitly and displays the runtime diagnostic instead of allowing a scheduled or required reload label to hide the error.
- Runtime prerequisites now consistently distinguish local Node.js execution, Python-based installation/restoration, and macOS backend approval across README, onboarding, core, and integration contracts.
- Build, CLI, and runtime installation now reject unsupported Node.js versions; installation validates Node before managed writes, canonicalizes its executable through symlinks, pins that path into installed hook commands and the supervisor launcher, preloads a sealed version guard before every installed target and supervised semantic dispatch, records path and validated version in release provenance, exposes them in Overview, and POSIX-quotes generated shell paths without expansion.
- Release packaging and publication now reject signed
vtags that are not strict Semantic Versioning, including leading-zero numeric identifiers; publication also verifies the sidecar against the artifact digest, byte size, signed embedded build/hook identities, source revision, dependency pins, channel, and canonical examples before upload. - Release packaging and publication rejection paths now return failure statuses instead of allowing automation to mistake a printed diagnostic for success.
- Prerelease and build metadata remain in Tama's exact embedded product identity while Apple bundle versions use the required numeric SemVer core; packaging and publication reject drift across the app, Network Extension, tag, manifest, or component build number.
- Channel promotion no longer implies relabeling prerelease bytes as stable: an exact preview remains preview, while a stable SemVer is a distinct signed candidate that must be qualified before one-time publication.
- Packaging and publication accept an explicit
TAMA_RELEASE_TAGto select one signed release identity when preview and stable candidates share a source commit, reject ambiguous implicit discovery, and reject a selected tag that does not resolve toHEAD. - Publication rejects duplicate ZIP member names, absolute or parent-traversing member paths, and any archive root other than
Tama.appor optional__MACOSXresource-fork metadata before upload. - Packaging and publication both require the app to pass signature, stapled-ticket, and Gatekeeper assessment; publication repeats those checks from the exact zip before upload.
- Publication now requires an immutable qualification sidecar bound to the exact candidate, complete coverage of each canonical example and required suite kind, repeated identity and cleanup evidence, passed/redacted records, and an asset link injected into release notes.
- Publication requires exactly one matching release-notes section and rejects missing, duplicate, reordered, or empty canonical categories before creating the immutable GitHub release.
- GitHub publication now requires the repository immutable-release policy, creates and retains one stable GitHub release ID, verifies the exact remote signed-tag object, stages exactly the four canonical assets in a private draft, rejects missing or foreign asset names, validates ID, title, tag, notes, draft state, and preview/stable classification, downloads and compares every uploaded byte, rechecks policy immediately before publishing that exact ID with an explicit stable-only
latestdecision, confirms the published metadata and immutable state, redownloads and rechecks the locked asset set, reports the stable ID after failure, and never automatically deletes a GitHub release where draft state cannot be an atomic deletion precondition. - Remote asset verification now paginates the retained release ID's complete asset collection and downloads every canonical byte stream by its unique release asset ID before and after publication.
- Canonical assets are now uploaded through URLs bound directly to the release ID returned by draft creation; upload and verification no longer resolve a mutable release tag.
- Release publication now classifies preview versus stable from the SemVer prerelease component only, so hyphens inside build metadata cannot suppress a stable release or mark it prerelease.
- App builds now read valid Keychain signing identities once and require an exact certificate-name or case-insensitive hash match, while also rejecting unsupported channel or code-signing timestamp modes and missing app or Network Filter provisioning-profile files before compilation. Build output and optional installation are assembled and signature-checked in private staging directories, then promoted with sibling backups and rollback instead of deleting the previous bundles before fallible work completes.
- Violations command output is retained within explicit bounds and output-limit failures remain visible.
- Cleanup rejects changed HEAD, checked-out branch, or local branch refs and states the remaining external-provider verification boundary.
- Backend status exposes partial installation, and deactivation attempts every privileged component while preserving aggregate failure and restart-required recovery.
- Backend unavailability is reported as a full-width panel carrying the backend's literal sentence and a reproducing command, rather than a dismissable alert or a swallowed read; the catalog, session control, provider coverage, install plan and repository scan each name their own command.
- The session capability document was decoded from every session record and displayed nowhere.
- A privileged backend that is merely not registered, a provider with no declared mapping, and a justification whose evidence is incomplete are no longer coloured as failures.
- A refresh that fails keeps the previous read on screen instead of replacing it with an empty state.
#Removed or deprecated
- Automatic service registration on application launch.
- Automatic session-controller installation on application launch.
- Supported-runtime dependence on
~/Documents/CodingProjects/Wisent/tama.
#Security
- Policy-changing setup is moved behind explicit user intent.
- Read-only catalog inspection remains available during Wisent Auth outages without exposing control actions.
- Distributed builds ignore development hook-root and Node executable overrides; unauthenticated inspection does not load local justification or policy state.
- Release artifacts record source provenance and carry independent SHA-256 verification.
#Configuration
- Developer-only source overrides remain unsupported for binary releases.
- Writable cleanup state is kept outside immutable release bytes.
#Data or state migrations
- Installed hook-release state and existing v2 session records remain readable. Legacy v1 session-control records and overrides are deliberately ignored because they lack the v2
agentIdidentity contract; reinstall the bundled runtime, then stop or resume affected sessions so the supervisor publishes fresh v2 records. - The former
tama.hasSeenWelcomeandtama.hasSeenTrustScreenpreferences are no longer read. Existing installations retain only independenttama.hasCompletedSetupstate without changing installed policy.
#Compatibility requirements
- Apple-silicon macOS 14 or newer.
- Python 3 and Node.js 20 or newer for installed runtime and violations workflows.
#Operator actions
- Review setup permissions and explicitly install/register components after upgrading.
- Confirm product build identity and loaded hook release before resuming supervised sessions.
#Known limitations
- No supported preview artifact has been published yet.
- Intel macOS, Linux, and Windows have no supported policy backend.
#Qualification evidence
- Packaging intentionally creates no qualification claim. Publication augments this source-level notice with a link to the completed immutable qualification sidecar for the exact candidate.