Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .codex-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "codex-agy-worker",
"version": "0.18.0",
"version": "0.19.0",
"description": "Use Antigravity CLI for exploration, feature work, and project-scale implementation, with Codex independently verifying results.",
"author": {
"name": "cagdasyurekli",
Expand Down
20 changes: 17 additions & 3 deletions PRIVACY.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,10 +40,24 @@ with private HOME/TMP and never falls back to session mode. In native mode, the
reviewed Keychain service access; this is not a recipient allowlist. On macOS,
the listener rule also permits wildcard binds, so the agy image can expose a
listener to the local network. Outbound connections to local TCP services remain denied.
The exact `/usr/bin/security` helper shares the reviewed Keychain service access,
without additional network or filesystem access. This permission cannot be limited
The bound agy image can inspect metadata and existence of its executable's exact
parent directory for Core Foundation SSL initialization. This adds no directory
listing or sibling-file access and does not transfer to a different executed image.
The same image can read metadata for ancestors of its private HOME so SQLite can
resolve conversation database paths. This grants no ancestor listing or file data;
other executable images and self-verification receive no such exception.
Native preparation expresses the approved staged read/write scope in a generated
private AGY settings file. It copies no user settings and grants no commands,
URLs, MCP tools, or ambient paths; the native filesystem boundary remains in force.

The exact `/usr/bin/security` helper shares the reviewed Keychain service access
and can read the bound default Keychain file. This file rule grants no provider,
other-executable, directory, write, or additional network access. Before native
launch, the driver reads only the default Keychain locator and file identity, then
creates a minimal locator preference in the private provider HOME; it does not copy
owner preferences or credentials. The existing service permission cannot be limited
to one token or operation; disclose broader same-user Keychain read/change/delete
authority in the initial approval package.
authority and the helper's exact file access in the initial approval package.
The stage is writable, while reconciliation enforces its approved write subset.
Process-group cleanup and trusted-local-owner limits are described in
[Security and compatibility](skills/agy-worker/references/SECURITY_AND_COMPATIBILITY.md).
Expand Down
2 changes: 1 addition & 1 deletion benchmarks/v1/portable-source.json
Original file line number Diff line number Diff line change
@@ -1 +1 @@
{"files":[{"mode":"100755","path":"benchmark.sh","sha256":"7e0033f6bf3eec1e6007752ef67e8e33db8f39c7136790a5403d651b39eeab8d"},{"mode":"100755","path":"qa-gate.sh","sha256":"878cf09fbc982b70895f8bf1335892d7291a56616434f64b58334c91c8f87d3f"},{"mode":"100755","path":"verify-job.sh","sha256":"b719ebac651b83d27d6fe2af47a0d454a43a4ab649afe98093fcc13d9164073c"},{"mode":"100755","path":"scripts/benchmark.py","sha256":"a6e8527194b6394767d173d66610a6f57e427438765e955741a96239308d6c2e"},{"mode":"100755","path":"scripts/candidate_state.py","sha256":"de6c5c8006ac641a29b37bb2aaf17b4fe0d00d6844806ba382aa19ce6852efa7"},{"mode":"100755","path":"scripts/compatibility.py","sha256":"c7366f2b11864c6f6000bb0c274269e86e47b59a4d76ea06835863a5e222cd80"},{"mode":"100755","path":"scripts/evidence_receipt.py","sha256":"eaa1878355c541bdd7e5f3411002b6e4bb4860f7989f0397ba9237aaec76c3c6"},{"mode":"100755","path":"scripts/model_selection.py","sha256":"9e0be61a5a5900a2f11c7c9ca8799ba204e9e3d006638d3114407937cd7aedea"},{"mode":"100755","path":"scripts/recommendation_record.py","sha256":"2d8eb267535d7fd73c83185c1c8dc20f2639676371b9fc245f9b976bbd5437ba"},{"mode":"100755","path":"scripts/validate-envelope.py","sha256":"87799cbcc981ae38a5f96ab3191043047fd8de91d60ed98ee31e6666bf1091eb"},{"mode":"100644","path":"schemas/benchmark-plan.schema.json","sha256":"34c31fd50bee7e459f9be65bdd64c6af4673010c389763d7c59010065de662dc"},{"mode":"100644","path":"schemas/benchmark-result.schema.json","sha256":"f90ea7a9ff62f943e66349a6a48fef33b619e7191e2fbcbac97620cce1a376ad"},{"mode":"100644","path":"schemas/evidence-receipt.schema.json","sha256":"377e9161580cbf9b802074dcc09897b89b1e31e99f1f60a06bec30c12561f500"},{"mode":"100644","path":"schemas/worker-result.schema.json","sha256":"f2589ae5249b395dc90279af07600298b6b4354d1fbe0e2efe3fa72832e9a3b0"},{"mode":"100644","path":"schemas/worker-result.provider.schema.json","sha256":"d17bf6d47ddf89f57644ce94f154c370cb92f65f174255066c79e7cc233f6fdd"}],"kind":"agy-worker-benchmark-portable-source","schema_version":1,"source_revision":"offline-benchmark-v1"}
{"files":[{"mode":"100755","path":"benchmark.sh","sha256":"7e0033f6bf3eec1e6007752ef67e8e33db8f39c7136790a5403d651b39eeab8d"},{"mode":"100755","path":"qa-gate.sh","sha256":"878cf09fbc982b70895f8bf1335892d7291a56616434f64b58334c91c8f87d3f"},{"mode":"100755","path":"verify-job.sh","sha256":"b719ebac651b83d27d6fe2af47a0d454a43a4ab649afe98093fcc13d9164073c"},{"mode":"100755","path":"scripts/benchmark.py","sha256":"a6e8527194b6394767d173d66610a6f57e427438765e955741a96239308d6c2e"},{"mode":"100755","path":"scripts/candidate_state.py","sha256":"de6c5c8006ac641a29b37bb2aaf17b4fe0d00d6844806ba382aa19ce6852efa7"},{"mode":"100755","path":"scripts/compatibility.py","sha256":"b42cbb740aedfc3e2c183a5ea1bf5e43bf60e992987b38e36b7cc49f285bce5d"},{"mode":"100755","path":"scripts/evidence_receipt.py","sha256":"eaa1878355c541bdd7e5f3411002b6e4bb4860f7989f0397ba9237aaec76c3c6"},{"mode":"100755","path":"scripts/model_selection.py","sha256":"9e0be61a5a5900a2f11c7c9ca8799ba204e9e3d006638d3114407937cd7aedea"},{"mode":"100755","path":"scripts/recommendation_record.py","sha256":"2d8eb267535d7fd73c83185c1c8dc20f2639676371b9fc245f9b976bbd5437ba"},{"mode":"100755","path":"scripts/validate-envelope.py","sha256":"87799cbcc981ae38a5f96ab3191043047fd8de91d60ed98ee31e6666bf1091eb"},{"mode":"100644","path":"schemas/benchmark-plan.schema.json","sha256":"34c31fd50bee7e459f9be65bdd64c6af4673010c389763d7c59010065de662dc"},{"mode":"100644","path":"schemas/benchmark-result.schema.json","sha256":"f90ea7a9ff62f943e66349a6a48fef33b619e7191e2fbcbac97620cce1a376ad"},{"mode":"100644","path":"schemas/evidence-receipt.schema.json","sha256":"377e9161580cbf9b802074dcc09897b89b1e31e99f1f60a06bec30c12561f500"},{"mode":"100644","path":"schemas/worker-result.schema.json","sha256":"f2589ae5249b395dc90279af07600298b6b4354d1fbe0e2efe3fa72832e9a3b0"},{"mode":"100644","path":"schemas/worker-result.provider.schema.json","sha256":"d17bf6d47ddf89f57644ce94f154c370cb92f65f174255066c79e7cc233f6fdd"}],"kind":"agy-worker-benchmark-portable-source","schema_version":1,"source_revision":"offline-benchmark-v1"}
6 changes: 3 additions & 3 deletions compat/agy-distribution-manifest.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"version": "1.1.27",
"url": "https://storage.googleapis.com/antigravity-public/antigravity-cli/1.1.27-5211191891591168/darwin-arm/cli_mac_arm64.tar.gz",
"sha512": "cd627f798e059f84a88bfe21dbde54cc5262e2d93d1943f120eb4b386823f4a1f7c4a57d4d0f876557709b6061a4c02f1fc13157f0047c5df6f300afa471e411"
"version": "1.2.2",
"url": "https://storage.googleapis.com/antigravity-public/antigravity-cli/1.2.2-6061403484848128/darwin-arm/cli_mac_arm64.tar.gz",
"sha512": "8a3b5edea51e107a74413cea5eed1c5b02dede945ba21c7625b7c86f477c2c8ac423581de0ed84ff2f97c3bf6818c1fc24ca84cf9a76c2fb02a50e89d8a0d29a"
}
2 changes: 1 addition & 1 deletion compat/agy-last-reviewed.txt
Original file line number Diff line number Diff line change
@@ -1 +1 @@
2026-09-06
2026-09-13
4 changes: 2 additions & 2 deletions compat/agy-model-effort-matrix.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@
"schema_version": 1,
"resolution_status": "active",
"inventory": {
"agy_version": "1.1.27",
"reviewed_source_revision": "1ae9cb7b51667192c051b73a91099c71e816ca5f",
"agy_version": "1.2.2",
"reviewed_source_revision": "ba985e6b5de2ac8aa09860a154a102831eb7722b",
"evidence": [
"agy-models",
"official-release",
Expand Down
2 changes: 1 addition & 1 deletion compat/agy-model-effort-matrix.sha256
Original file line number Diff line number Diff line change
@@ -1 +1 @@
56ee4cefdf918184e8bae57c49f01c51c18e49b30ff0bd4b322d8801703dfaac
2c12abf09910489b681a01c88b43e8fbaf7df3a68fd715c7280c7f6fff6c89e4
10 changes: 5 additions & 5 deletions compat/agy-models-inventory-binding.json
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
{
"schema_version": 1,
"status": "accepted-current-inventory",
"agy_version": "1.1.27",
"reviewed_source_revision": "1ae9cb7b51667192c051b73a91099c71e816ca5f",
"source_sha256": "d583be1344ea9cfa0c45cff2c1342af7837f4833c4edb65e69bee84776a45caa",
"version_binding_sha256": "a1f8b651123f1e95ef7e744ae45e9066967b6ceb0a710ddfd685e54b14b0b0a6",
"capture_record_sha256": "ac8ddc28fcca90a20e05f6bd0678d32550db451a8e3402e4c287154eab289b33",
"agy_version": "1.2.2",
"reviewed_source_revision": "ba985e6b5de2ac8aa09860a154a102831eb7722b",
"source_sha256": "cabadc15a61944372bede1fdff186701c17467dd9d718e97dc79283055d3c101",
"version_binding_sha256": "cc3bd8bb44b31891e2bed4c4367ed90ae2334e0df29e9fba2e94bce7c3105bef",
"capture_record_sha256": "73d65488b618b721d70d85076cc1ca67c8ead62e0606588502aeb69e5230d032",
"capture_stdout_sha256": "d02970e6b6b4e0910461999afca8fb99d757e9094ab2874b557dad18fc75464a",
"capture_response_sha256": "b1cc011310435afa07b1e132a5b7f3e22297aa21427177461c858bcbd6a58794",
"inventory_normalized_sha256": "d5e58ab55e91ebd4a2cd23841c76cbe12b47d607c62cd8c834fc8f6b9f078ad7",
Expand Down
2 changes: 1 addition & 1 deletion compat/agy-models-inventory-binding.sha256
Original file line number Diff line number Diff line change
@@ -1 +1 @@
3a554f90922321700120e2c398f865a4894b2128087a4bac90968ddf2409762d
efcc59a983b0c9f60309a55047188d800f5e34d2dc42a38d9339cdc361e13802
2 changes: 1 addition & 1 deletion compat/agy-upstream-head.txt
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1ae9cb7b51667192c051b73a91099c71e816ca5f
ba985e6b5de2ac8aa09860a154a102831eb7722b
2 changes: 1 addition & 1 deletion compat/agy-verified-version.txt
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.1.27
1.2.2
55 changes: 52 additions & 3 deletions compat/agy-version-manifest.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,7 @@
"schema_version": 1,
"kind": "agy-version-manifest",
"versions": {
"1.1.27": {
"version": "1.1.27",
"support_tier": "current",
"1.2.2": {
"allowed_operations": [
"activation",
"capture",
Expand All @@ -13,6 +11,57 @@
"reprofile",
"version-evidence"
],
"capture_runner_source_sha256": "34fd925d3d66a8fa46d7308ec1f67e5a1578fb4f961197993f5bfb17b6ec8677",
"capture_snapshot_policy": "macos-readonly-mount",
"distribution_sha512": "8a3b5edea51e107a74413cea5eed1c5b02dede945ba21c7625b7c86f477c2c8ac423581de0ed84ff2f97c3bf6818c1fc24ca84cf9a76c2fb02a50e89d8a0d29a",
"distribution_url": "https://storage.googleapis.com/antigravity-public/antigravity-cli/1.2.2-6061403484848128/darwin-arm/cli_mac_arm64.tar.gz",
"expected_stdout": "1.2.2\n",
"output_profile_name": "models.capture.1.2.2.profile.json",
"prior_name": "agy-models-capture-1.2.2.version",
"recovery_binding_sha256": "cc3bd8bb44b31891e2bed4c4367ed90ae2334e0df29e9fba2e94bce7c3105bef",
"recovery_runner_bytes": 48402,
"recovery_runner_sha256": "16fe57ed938bd482aa8df99e5e42914984fdb0b9f22de59919a5ae64aa020f98",
"recovery_stdout": "1.2.2\n",
"recovery_summary_bytes": 260,
"release_commit": "ba985e6b5de2ac8aa09860a154a102831eb7722b",
"source_sha256": "cabadc15a61944372bede1fdff186701c17467dd9d718e97dc79283055d3c101",
"source_size": 180089984,
"support_tier": "current",
"version": "1.2.2",
"historical_recovery_binding_sha256": "a1f8b651123f1e95ef7e744ae45e9066967b6ceb0a710ddfd685e54b14b0b0a6",
"historical_recovery_source_sha256": "d583be1344ea9cfa0c45cff2c1342af7837f4833c4edb65e69bee84776a45caa",
"reprofile_output_name": "models.capture.1.2.2.reprofile.json",
"failure_ruleset_version": "agy-1.2.2-failure-rules-v1",
"capture_record_sha256": "73d65488b618b721d70d85076cc1ca67c8ead62e0606588502aeb69e5230d032",
"capture_stdout_sha256": "d02970e6b6b4e0910461999afca8fb99d757e9094ab2874b557dad18fc75464a",
"capture_response_sha256": "b1cc011310435afa07b1e132a5b7f3e22297aa21427177461c858bcbd6a58794",
"inventory_normalized_sha256": "d5e58ab55e91ebd4a2cd23841c76cbe12b47d607c62cd8c834fc8f6b9f078ad7",
"slug_count": 14,
"slugs": [
"claude-opus-4-6-thinking",
"claude-sonnet-4-6",
"gemini-3.1-pro-high",
"gemini-3.1-pro-low",
"gemini-3.6-flash-high",
"gemini-3.6-flash-low",
"gemini-3.6-flash-medium",
"gemini-3.7-flash-high",
"gemini-3.7-flash-low",
"gemini-3.7-flash-medium",
"gemini-3.8-flash-high",
"gemini-3.8-flash-low",
"gemini-3.8-flash-medium",
"gpt-oss-120b-medium"
]
},
"1.1.27": {
"version": "1.1.27",
"support_tier": "previous",
"allowed_operations": [
"capture",
"profile",
"version-evidence"
],
"expected_stdout": "1.1.27\n",
"source_sha256": "d583be1344ea9cfa0c45cff2c1342af7837f4833c4edb65e69bee84776a45caa",
"source_size": 177426912,
Expand Down
2 changes: 1 addition & 1 deletion compat/agy-version-manifest.sha256
Original file line number Diff line number Diff line change
@@ -1 +1 @@
898bc921c15aa342b9306600aa1e380bb2930e80de465c76a99b87ef34b0d6e0
5b28e6f05c6e63c2022b461cf2aac596f9f3a4f4a1aa72957b5a62a5c334428e
95 changes: 95 additions & 0 deletions compat/reviews/agy-1.2.2-activation.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,95 @@
# AGY 1.2.2 activation evidence

Reviewed: 2026-09-13

This record supports the accepted v0.19.0 implementation. Its stable candidate
passed all 44 offline CI stages and independent review. Publication and installation
remain separately verified delivery states.

The accepted version and single account inventory capture bind AGY **1.2.2**,
reviewed upstream revision `ba985e6b5de2ac8aa09860a154a102831eb7722b`, executable
SHA-256 `cabadc15a61944372bede1fdff186701c17467dd9d718e97dc79283055d3c101`, and
version binding `cc3bd8bb44b31891e2bed4c4367ed90ae2334e0df29e9fba2e94bce7c3105bef`.
The capture record is `73d65488b618b721d70d85076cc1ca67c8ead62e0606588502aeb69e5230d032`.
Its fourteen model slugs have normalized SHA-256
`d5e58ab55e91ebd4a2cd23841c76cbe12b47d607c62cd8c834fc8f6b9f078ad7`.
Mappings are unchanged from 1.1.27. Root and portable compatibility records bind
this version, source, inventory, matrix, and capture together. The separate
observational distribution snapshot was refreshed to the same accepted 1.2.2
URL/SHA-512 tuple after a fresh fixed-manifest read. This prevents a stale snapshot
from generating permanent drift warnings; it grants no activation or download
authority.

The official [1.2.2 changelog](https://github.com/google-antigravity/antigravity-cli/blob/1.2.2/CHANGELOG.md)
and bounded version/help inspection were reconciled with observable behavior. The
upstream repository does not expose the CLI implementation. Caller-selected model
and effort continue to resolve to one advertised compound slug, passed through
`--model`; the presence of `--effort` in help does not establish safe composition.

## Failure handling

A real refused-command canary exposed `denied_actions` but lacked structured output.
It remained `invalid_envelope`; no candidate was invented. For a valid envelope on
exact 1.1.27 or 1.2.2, offline fixtures verify that key presence produces
`permission_required`, preserves a valid candidate, and prevents automatic repair.
This policy does not assume a stable field payload schema.

A direct eight-second canary returned exit zero and terminal success with a partial
output warning. Its relative file request also caused an ambient account-home
configuration search, so this route was not repeated. Subsequent worker cases used
wrapper-controlled absolute stage paths. Offline controller scenarios verify that
the exact observed warning, bound to the job duration, yields `provider_timeout`
and preserves a valid candidate for independent review. Permission denial, invalid
reports, hard deadlines, cancellation, and binding failures keep their precedence.
The canary did not itself produce a valid worker candidate.

## Session and native qualification

One bounded campaign used only `gemini-3.8-flash-high`. Its initial ten-start cap was
explicitly raised to eleven; renewed user authority after the failed continuation
was bounded to two further repair starts. Thirteen actual starts were recorded.
There were no model substitutions, additional inventory reads, or Boost starts.

Session normal work and same-conversation repair passed driver-owned checks. The
repair deliberately began with a trim-only candidate; the second turn added
lowercasing and passed five checks. These cases qualify only the exercised workflow
and candidates; session mode does not confine host reads.

Native qualification required narrow, separately reviewed preparation fixes:
exact provider executable-parent metadata for local initialization, a private
default-Keychain locator with read access restricted to the security helper, and
minimal staged-path permissions in private job settings. Owner configuration was
not copied or changed. The normal native candidate then passed five driver checks
and independent review.

An earlier native continuation failed with `status_unavailable` at `binding_failure`.
The prior candidate remained on disk, but cleanup and result rebinding were not
established. Targeted diagnostics identified a failed conversation database open
before the continuation panic. An offline upstream SQLite differential reproduced
an ancestor `lstat` denial. Provider-image-only metadata access to private HOME's
ancestor chain restored database creation, WAL/SHM use, and close/reopen recovery;
it grants neither ancestor listing/data nor the same access to other images or
self-verification. No credential access or AGY invocation was used in that proof.

The two newly authorized native turns then completed in the same recorded
conversation in approximately 32 seconds total, within the original job budget.
The expected trim-only candidate was preserved, and the repaired candidate passed
five driver checks. Independent review accepted both native normal and repair
results. Historical failed attempts and their uncertain cleanup remain documented
in the [investigation record](agy-1.2.2-candidate.md); their outcomes are not rewritten.

## Activation and limits

Activation promotes 1.2.2 to current, retains 1.1.27 and 1.1.26 as previous, 1.1.22
as legacy, and 1.1.24, 1.1.16, and 1.1.12 as historical. Stable offline CI,
package parity, instruction audit, and independent repository acceptance passed
for the implementation candidate. The skill simplification preserves automatic discovery,
same-scope repair, candidate preservation, and driver-owned assurance labels; it
makes no measured speed or quality claim.

These bounded cases do not establish exhaustive compatibility, provider backend
identity, model quality, authentication or quota for other runs, billing, fallback,
effective routing, or live optional self-verification. Native tests establish the
exercised filesystem boundaries, not complete same-user tamper resistance. No new
Boost qualification is claimed. The closed-binary provider backend cannot be
independently attested by this evidence.
Loading
Loading