Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
33 commits
Select commit Hold shift + click to select a range
76fdabb
Implement Choice Core and frozen Mac flow
thesongzhu Jul 21, 2026
2631902
Add dedicated iMessage self-chat reply path
thesongzhu Jul 21, 2026
fbeba54
Add bounded memory and skill demo foundations
thesongzhu Jul 21, 2026
95c94a3
Add frozen memory and skill setup surfaces
thesongzhu Jul 21, 2026
0df2d12
Persist the one-skill demo lifecycle
thesongzhu Jul 21, 2026
906e72f
Wire the one-skill demo lifecycle
thesongzhu Jul 21, 2026
bdaf9ec
Show exact one-skill lifecycle state
thesongzhu Jul 21, 2026
99afcb2
Add durable one-import memory foundation
thesongzhu Jul 21, 2026
2f1563d
Bind B+ package inputs
thesongzhu Jul 21, 2026
3b18419
Bind DMG verification to B+ candidate
thesongzhu Jul 21, 2026
aec353b
Wire bounded Memory review UI
thesongzhu Jul 21, 2026
6bac482
Keep Memory review on frozen copy
thesongzhu Jul 21, 2026
ce908a1
Bind package to frozen Memory UI
thesongzhu Jul 21, 2026
bc5629c
Keep Skills feedback on frozen copy
thesongzhu Jul 21, 2026
0c8b67e
Bind package to final demo UI
thesongzhu Jul 21, 2026
070125b
Bind signed iMessage identity
thesongzhu Jul 21, 2026
0f844c9
Bind real Memory source processing
thesongzhu Jul 21, 2026
840ab5f
Fence Memory processing replay
thesongzhu Jul 21, 2026
e096b40
Wire frozen Memory source controls
thesongzhu Jul 21, 2026
cadb56c
Make correction polling test bounded
thesongzhu Jul 21, 2026
534ef09
Package the bounded Deep ZIP worker
thesongzhu Jul 21, 2026
a11f2ba
Refresh signed package identities
thesongzhu Jul 21, 2026
6fda99a
Add bounded Memory candidate contract
thesongzhu Jul 21, 2026
f46ddaf
Add bounded memory context scan
thesongzhu Jul 21, 2026
3c9128f
Bind B2 processing and readback
thesongzhu Jul 21, 2026
67ae855
Verify Finder-installed app copies
thesongzhu Jul 21, 2026
1246edc
Recover historical iMessage pairing state
thesongzhu Jul 21, 2026
9c99f4d
Run B2 candidates from verified context
thesongzhu Jul 21, 2026
7256826
Wire frozen B2 processing UI
thesongzhu Jul 21, 2026
6be6f67
Complete B2 Markdown publication and readback
thesongzhu Jul 21, 2026
42e4029
Recover failed B2 processing safely
thesongzhu Jul 21, 2026
6523937
Bind Decision Brief audit and close frozen UI gates
thesongzhu Jul 21, 2026
a7bba38
Bind packaging to current Demo binaries
thesongzhu Jul 21, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
99 changes: 93 additions & 6 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,12 +13,99 @@ approval semantics, evidence semantics, data policy, or release gates by
assumption. Low-risk implementation details may be recorded in its
Implementation Ledger when they preserve every fixed boundary.

Current Build Week work ends at `BUILD_WEEK_COMPETITION_READY` as defined by
the dated current competition contract at the top of the Master Plan. Older
`PRODUCT_READY_FOR_DEMO`, Slack, Hero B/C, notarization, and external-user
language is historical/post-competition roadmap context and cannot expand the
current handoff. Demo recording, editing, publishing, and Devpost submission
are separate work and are out of scope.
Current work follows the 2026-07-19 private-agent Choice Loop contract and the
Owner-approved 2026-07-20 ten-hour latest-safe B+ delivery route at the top of the
Master Plan and its same-fingerprint design/execution companions. The protected
Hero path is PR1 Choice Core+Mac, then PR2 iMessage same-account self-chat, then
the same-main Core+iMessage checkpoint App/DMG. The final B+ package additionally
contains one narrowly bounded B2 Memory flow and one narrowly bounded C2 Skill
flow, integrated in that order. The one
additional iMessage read-only source, Discord, broader Memory/Skill/channel
expansion, and product-wide presentation are post-B+. They may prepare only
inside isolated owned paths and may not block or redefine PR1/PR2. The former `BUILD_WEEK_COMPETITION_READY`,
`PRODUCT_READY_FOR_DEMO`, fixed-Sol/Auto, old Outcome/IntentSession, Passport/
ZIP/Skill critical-path, Slack, Hero B/C, notarization, and external-user
language is historical or support-lane context and cannot expand or redirect
the current handoff. First launch is English-only account scan → explicit model
and supported-effort selection → one question → dynamic A/B/C plus D; product UI
may not show a second language. Reactive replies use only the latest owner-
active connected channel; Mac never copies chat output across channels.
Persona, visual composition, and exact English copy remain Owner-open inside
those locked semantics.

The Owner also locked `OWNER-20260720-16H-FULL-FIRE`,
`OWNER-20260720-B2-DYNAMIC-CARDS-CONSENT`,
`OWNER-20260720-IMSG-ONE-READONLY`, and
`OWNER-20260720-DESIGN-AFTER-FUNCTION`. Their safety, lane-isolation, and
deferred-Owner rules remain locked; their earlier sixteen-hour/staged-integration
schedule is superseded by the ten-hour B+ route below. Safe READY work
continues after the target. B2 may use the supplied export only for an in-place, local, read-only,
no-network, no-retention diagnostic; semantic Memory cards require later exact
Owner consent before any bounded source excerpt reaches the selected OpenAI
model. The one additional iMessage source is read-only and has no outbound
authority. Real Discord credentials, public Skill lifecycle actions, provider
traffic, permissions, installation, Mission/Reminder effects, and release
remain action-time gates.

The Owner further locked `OWNER-20260720-REMINDER-SCHEDULE-BG`,
`OWNER-20260720-14H-DEMO-CORE-B2-C2`, and
`OWNER-20260720-14H-DEMO-IMSG-INCLUDE`; their exact Reminder, B2, C2, iMessage,
and UI bounds remain locked while their schedule and narrative are superseded
by `OWNER-20260720-10H-BPLUS-HERO`; its pacing is further locked by
`OWNER-20260720-10H-BPLUS-DEADLINE`. Reminder date/time/timezone proposals
must be visible and editable and may derive only from explicit user-provided
temporal information. If time is absent, Host requires a user selection; it
never inserts a fixed default or infers from the question timestamp. Exact
future date/time/timezone/list/count bind the confirmation digest, and every
edit creates a new revision and reconfirmation. Choice confirmation never
authorizes the separate real Reminder write. Ten hours is the latest-safe
delivery target and execution deadline, never authority to skip a gate. Any
external outage, normal-merge rejection, permission, or exact Owner action that
threatens the deadline is reported immediately rather than silently extending
the plan. The Hero
completion gate is the real Core Choice-to-Reminder-to-Evidence-to-Receipt-to-
Markdown-to-next-choice loop through PR2 same-account self-chat, with Off,
restart, and duplicate-effect proof. B+ B2 is exactly one
real import, at most three candidate cards, one Owner-selected card, and only
the Owner-confirmed Markdown diff. B+ C2 is exactly one public instruction-
only Skill through acquisition/audit/enablement and one no-external-effect use.
B+ UI polish is limited to the Core, B2, and C2 screens plus minimal iMessage
setup/status. iMessage inclusion is limited to PR2 same-account self-chat and
does not authorize Messages permission, chat selection, install, or send.

The Owner also locked `OWNER-20260720-24H-CLOSURE-QUEUE`; its queue discipline
remains active while its prior twenty-four-hour schedule is superseded. Every
not-yet-available Owner action is prepared as a non-sensitive, deduplicated
return-queue item. Reaching one such boundary freezes only that exact node and its
descendants; every unrelated READY item continues. Advanced UI/persona/final
copy is prepared as an explicit Owner decision packet after functional
structure exists and is completed with the Owner during the remaining closure
window. A task may report no-safe-READY only after the queue and every unrelated
READY path have been rechecked.

The Owner also locked `OWNER-20260720-CHOICE-BEGIN`: public Host RPC
`choice.begin` is the sole first-local-question intake/create route. Host
derives the authenticated Mac SourceEnvelope and sealed batch, atomically
creates the initial ChoiceSession/audit state, and accepts a first ChoiceSet
only through a private revision/generation/provenance-bound commit. It exposes
no raw snapshot writer and performs no external effect.

The Owner also locked `OWNER-20260720-CHOICE-D-SELECT`,
`OWNER-20260720-REFINEMENT-RESULT`, `OWNER-20260720-MARKDOWN-RENDER`, and
`OWNER-20260720-IDLE-STALE`. D is a bounded-text/idempotent-request variant of
command-owned `choice.select`; Host derives/seals its authenticated batch and
callers never mint batch identity. Post-selection output enters only through a
private Selection/operation/generation/revision/provenance/manifest-bound
single-transaction commit; first-question/D plaintext remains encrypted under
the existing Keychain-derived Store boundary and is deleted after cancel or
accepted typed-state render receipt. Markdown uses Store render intent,
descriptor-safe staged-file sync, atomic no-clobber creation or swap/CAS
replacement retaining the displaced base, parent-directory sync, final/base
digest verification, and only then an exact receipt, with typed ambiguous/
concurrent-edit recovery. Soft-idle/stale-review use
Host-owned persisted-deadline transitions with exact revision/generation;
timers themselves grant no model/effect authority, Host derives time/state, and
reboot/backward/ambiguous clock evidence blocks safely.

## Authority and task communication

Expand Down
49 changes: 48 additions & 1 deletion BUILD_WEEK.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,50 @@ come only from `docs/OPENOPEN_BUILD_WEEK_MASTER_PLAN.md`. This disclosure is a
chronological Build Week/provenance record and cannot authorize implementation
or override that canonical contract.

## Current private-agent direction — 2026-07-19

The Owner replaced the former competition critical path with the private-agent
Choice Loop: natural expression → bounded understanding → dynamic A/B/C plus D
→ refinement → one exact confirmation → Reminders → Evidence → Receipt →
bounded Markdown update → next choices.

The current UI is macOS-only. Mac is primary; the B+ Hero channel is the dedicated
same-account iMessage self-chat. A local personal Discord Bot DM and one
additional one-to-one iMessage read-only source are post-B+. The
account's compatible GPT/Codex
models are scanned and presented
for explicit model and supported-effort selection. First launch and all
product-owned visible copy are English-only: account scan → selection → one
simple question → first dynamic A/B/C plus D, with no model work before
selection. Reactive replies use only the latest owner-active connected channel;
Mac does not duplicate them across channels. Fixed Sol, Auto, silent fallback,
Connect Messages first, old Outcome/15-minute IntentSession UX, groups,
shared/cloud Discord Bot, offline replay, Claude/Anthropic, and Repair23 input
reuse are not current authority.

Repair24 source `ca26036…` merged as `c86e590…`, and CI `29707715009` passed.
That is source/CI identity only. The protected Hero route is PR1 Choice Core+Mac,
PR2 iMessage same-account self-chat, and a same-main Core+iMessage checkpoint
App/DMG proving one complete real outcome loop. Minimal B2 and minimal C2 then
land as narrow proof chapters in the final B+ App/DMG.
Host-owned `choice.begin` is the only public first-local-question
intake/create route and must commit the initial session/audit atomically before
model work. B+ B2 is one real import, at most three candidates, one Owner-
selected card, and one separately confirmed Markdown diff. B+ C2 is one
public instruction-only Skill and one no-external-effect use. Extra iMessage,
Discord, broader expansion, and advanced presentation are post-B+. Real install, providers,
permissions, Mission, Reminder, Evidence, Skill lifecycle, and release
boundaries remain unclaimed. The supplied real ChatGPT export is authorized
only for an isolated local, read-only, no-network, no-retention B2 diagnostic;
neither it nor derived metadata may enter repository evidence or a remote.
Sending bounded excerpts to the selected OpenAI model and committing selected
Memory cards require later exact Owner consent.

Reminder proposals use only explicit user temporal information. Missing time
requires user selection; fixed/question-time defaults are forbidden. Exact
future date/time/timezone/list/count bind confirmation and every edit
reconfirms, while the real write remains a separate action-time gate.

## Pre-existing before July 13, 2026

- Friday's general Mission, WorkItem, workflow, trust, storage, and Skill
Expand Down Expand Up @@ -134,7 +178,10 @@ or override that canonical contract.
The package remains unnotarized, and no provider, administrator/cross-UID,
`FRIDAY_ALPHA_READY`, or release proof is claimed.

## Current competition additions (not yet claimed)
## Superseded competition additions — historical only

This section records the former 2026-07-17 plan and does not define the current
Choice Loop critical path.

- The optional macOS voice entry route; Hero A currently uses explicit text
input.
Expand Down
Loading