Amanuensis

Subsystem · B-08

Activation evidence and release-readiness harness

Survey record for Activation evidence and release-readiness harness: scope, reading path, concern review, findings, boundaries, vocabulary, and notes.

Branch  main Checked  adc4ce04aa57 As of  2026-08-29 04:56:43 No recorded stale entries Survey depth  Mapped

Status: Mapped Layer: delivery evidence

§Scope

dev/activation-evidence/, the dev/ activation and friction-free release harness scripts (run-/check-/test-/capture-/cleanup-/adopt-/render-), mcp-server/fixtures/activation/, the mcp-server activation and binding tests, dev/adr/0021, dev/friction-free-release-checklist.md, and dev/release-notes-v0.2.0-beta.1.md; the A19-A26 program that produced and gates the v0.2.0-beta.1 activation claim.

§Start here

dev/adr/0021-friction-free-codex-activation.md; dev/check-friction-free-release-readiness.mjs; dev/activation-evidence/a26-release-readiness.json

§Notes

Created during the 2026-08-27 full refresh. Distinct evidence corpus in the pattern of B-06 (design evidence) and B-07 (research evidence): captured host transcripts are generated witnesses, while the checkers, red-gate suites, and receipts are authored instruments. Runtime code it exercises lives in B-02 (codex-host.ts, project.ts) and B-05 (cli.ts) — claims about enforcement must cross to those subsystems.

§File ledger

a19-user-scoped-contract.json

Path
dev/activation-evidence/a19-user-scoped-contract.json
Review
candidate
Revision
5694080

Why this file is in scope

A19 receipt: user-scoped installation contract.

a20-activation-doctor.json

Path
dev/activation-evidence/a20-activation-doctor.json
Review
candidate
Revision
5694080

Why this file is in scope

A20 receipt: activation diagnosis output.

a21-immutable-workspace-binding.json

Path
dev/activation-evidence/a21-immutable-workspace-binding.json
Review
candidate
Revision
5694080

Why this file is in scope

A21 receipt: immutable workspace binding.

a22-codex-host.json

Path
dev/activation-evidence/a22-codex-host.json
Review
candidate
Revision
5694080

Why this file is in scope

A22 receipt: real Codex host activation evidence.

parent-cd-recovery.json

Path
dev/activation-evidence/a22-host-runs/parent-cd-recovery.json
Review
candidate
Revision
5694080

Why this file is in scope

A22 structured host-run summary for parent --cd recovery.

stale-process-cwd.sanitization.json

Path
dev/activation-evidence/a22-host-runs/stale-process-cwd.sanitization.json
Review
candidate
Revision
5694080

Why this file is in scope

A22 sanitization record for the stale-process-cwd transcript.

storage-readback.json

Path
dev/activation-evidence/a22-host-runs/storage-readback.json
Review
candidate
Revision
5694080

Why this file is in scope

A22 storage read-back witness for cross-repository containment.

a23-zero-touch-lifecycle.json

Path
dev/activation-evidence/a23-zero-touch-lifecycle.json
Review
candidate
Revision
5694080

Why this file is in scope

A23 receipt: lazy first-use lifecycle.

a24-package-parity.json

Path
dev/activation-evidence/a24-package-parity.json
Review
candidate
Revision
5694080

Why this file is in scope

A24 receipt: source vs package activation parity.

a25-activation-operating-envelope.json

Path
dev/activation-evidence/a25-activation-operating-envelope.json
Review
candidate
Revision
5694080

Why this file is in scope

A25 receipt: stratified activation operating envelope.

a26-candidate-suite.json

Path
dev/activation-evidence/a26-candidate-suite.json
Review
candidate
Revision
5694080

Why this file is in scope

A26 receipt: prepublication candidate suite.

a26-clean-replay.json

Path
dev/activation-evidence/a26-clean-replay.json
Review
candidate
Revision
5694080

Why this file is in scope

A26 receipt: clean-replay reproduction of the release gate.

a26-release-readiness-red-gates.json

Path
dev/activation-evidence/a26-release-readiness-red-gates.json
Review
candidate
Revision
5694080

Why this file is in scope

A26 receipt: red-gate proof that the readiness gate can fail.

adopt-codex-host-evidence.mjs

Path
dev/adopt-codex-host-evidence.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Authored adoption step promoting captured host runs into receipts.

capture-activation-launch.mjs

Path
dev/capture-activation-launch.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Authored launch-audit capture used by the envelope runner.

cleanup-activation-operating-trust.mjs

Path
dev/cleanup-activation-operating-trust.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Authored trust-state cleanup for A25 runs; portability of its temp root was changed in 3270cac.

cleanup-codex-host-trust.mjs

Path
dev/cleanup-codex-host-trust.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Authored trust-state cleanup for A22 host runs.

friction-free-release-checklist.md

Path
dev/friction-free-release-checklist.md
Review
candidate
Revision
5694080

Why this file is in scope

Authored human checklist for the friction-free release.

refresh-a22-evidence.mjs

Path
dev/refresh-a22-evidence.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Authored refresh path for A22 evidence.

release-notes-v0.2.0-beta.1.md

Path
dev/release-notes-v0.2.0-beta.1.md
Review
candidate
Revision
5694080

Why this file is in scope

Authored release notes for the beta candidate this program gates.

run-activation-operating-envelope.mjs

Path
dev/run-activation-operating-envelope.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Authored A25 stratified operating-envelope runner.

run-codex-parent-cd-evidence.mjs

Path
dev/run-codex-parent-cd-evidence.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Authored harness for the parent --cd recovery case.

run-friction-free-candidate-suite.mjs

Path
dev/run-friction-free-candidate-suite.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Authored A26 prepublication candidate suite runner.

test-activation-evidence.mjs

Path
dev/test-activation-evidence.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Authored test over activation evidence receipts.

codex-context-probe.mjs

Path
mcp-server/fixtures/activation/codex-context-probe.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Fixture probe used to observe Codex launch context.

codex-host-red-matrix.json

Path
mcp-server/fixtures/activation/codex-host-red-matrix.json
Review
candidate
Revision
5694080

Why this file is in scope

Negative-case matrix for the A22 checker.

conflicting-user-project.json

Path
mcp-server/fixtures/activation/conflicting-user-project.json
Review
candidate
Revision
5694080

Why this file is in scope

Fixture for conflicting user and project registrations.

first-use-interruption.json

Path
mcp-server/fixtures/activation/first-use-interruption.json
Review
candidate
Revision
5694080

Why this file is in scope

Fixture for interrupted first-use recovery.

first-use-worker.mjs

Path
mcp-server/fixtures/activation/first-use-worker.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Fixture worker exercising lazy first-use lifecycle.

hard-coded-global-project-local.json

Path
mcp-server/fixtures/activation/hard-coded-global-project-local.json
Review
candidate
Revision
5694080

Why this file is in scope

Fixture reproducing the hard-coded global registration defect ADR-0021 names.

operating-envelope-red-matrix.json

Path
mcp-server/fixtures/activation/operating-envelope-red-matrix.json
Review
candidate
Revision
5694080

Why this file is in scope

Negative-case matrix for the A25 envelope checker.

package-parity.json

Path
mcp-server/fixtures/activation/package-parity.json
Review
candidate
Revision
5694080

Why this file is in scope

Fixture for source vs package activation parity.

release-readiness-red-matrix.json

Path
mcp-server/fixtures/activation/release-readiness-red-matrix.json
Review
candidate
Revision
5694080

Why this file is in scope

Negative-case matrix for the A26 readiness gate.
Path
mcp-server/fixtures/activation/storage-symlink-escape.json
Review
candidate
Revision
5694080

Why this file is in scope

Fixture for storage containment against symlink escape.

test-activation-contract.mjs

Path
mcp-server/test-activation-contract.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Test of the activation registration contract.

test-activation-doctor.mjs

Path
mcp-server/test-activation-doctor.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Test of the A20 activation diagnosis path.

test-codex-parent-workspace.mjs

Path
mcp-server/test-codex-parent-workspace.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Test of codex-host.ts parent workspace resolution.

test-first-use-laziness.mjs

Path
mcp-server/test-first-use-laziness.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Test that no project state is created before first stateful use.

test-first-use-recovery.mjs

Path
mcp-server/test-first-use-recovery.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Test of interrupted first-use recovery.

test-nested-activation-binding.mjs

Path
mcp-server/test-nested-activation-binding.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Test of nested-repository binding resolution.

test-operating-envelope.mjs

Path
mcp-server/test-operating-envelope.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Test of the stratified operating envelope.

test-package-activation-parity.mjs

Path
mcp-server/test-package-activation-parity.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Test of source vs published-package activation parity.

test-release-rollback.mjs

Path
mcp-server/test-release-rollback.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Test of release rollback behavior.

test-workspace-binding.mjs

Path
mcp-server/test-workspace-binding.mjs
Review
candidate
Revision
5694080

Why this file is in scope

Test of immutable per-process workspace binding.

a26-release-readiness.json

Path
dev/activation-evidence/a26-release-readiness.json
Review
examined
Revision
5694080

Why this file is in scope

A26 receipt: release-readiness gate result with sha256 source custody.

0021-friction-free-codex-activation.md

Path
dev/adr/0021-friction-free-codex-activation.md
Review
examined
Revision
5694080

Why this file is in scope

Charter ADR defining the friction-free activation decision and acceptance boundary for A19-A26.

check-codex-host-evidence.mjs

Path
dev/check-codex-host-evidence.mjs
Review
examined
Revision
5694080

Why this file is in scope

Authored checker validating A22 host receipts.

check-friction-free-release-readiness.mjs

Path
dev/check-friction-free-release-readiness.mjs
Review
examined
Revision
5694080

Why this file is in scope

Authored checker gating the v0.2.0-beta.1 release-readiness claim.

run-codex-host-harness.mjs

Path
dev/run-codex-host-harness.mjs
Review
examined
Revision
5694080

Why this file is in scope

Authored harness that drives real Codex hosts and emits the A22 transcripts.

codex-config-healthy.toml

Path
mcp-server/fixtures/activation/codex-config-healthy.toml
Review
examined
Revision
aba6d04

Why this file is in scope

Control fixture: a healthy live Codex configuration that also carries an unrelated MCP server and an ordinary project trust entry, proving both are tolerated.

codex-config-residual-trust.toml

Path
mcp-server/fixtures/activation/codex-config-residual-trust.toml
Review
examined
Revision
aba6d04

Why this file is in scope

Negative fixture: harness trust surviving cleanup.

codex-config-shadowed.toml

Path
mcp-server/fixtures/activation/codex-config-shadowed.toml
Review
examined
Revision
aba6d04

Why this file is in scope

Negative fixture: duplicate Amanuensis registration.

codex-config-workspace-pinned.toml

Path
mcp-server/fixtures/activation/codex-config-workspace-pinned.toml
Review
examined
Revision
aba6d04

Why this file is in scope

Negative fixture: registration pinning a repository via --workspace.

test-startup-bounds.mjs

Path
mcp-server/test-startup-bounds.mjs
Review
examined
Revision
aba6d04

Why this file is in scope

Red gates proving no probe on the activation path runs unbounded; the B02-2 repair.

configuration-conflict.jsonl

Path
dev/activation-evidence/a22-host-runs/configuration-conflict.jsonl
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured Codex host transcript emitted by dev/run-codex-host-harness.mjs.

configuration-conflict.stderr.log

Path
dev/activation-evidence/a22-host-runs/configuration-conflict.stderr.log
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured host stderr stream.

interrupted-a.jsonl

Path
dev/activation-evidence/a22-host-runs/interrupted-a.jsonl
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured Codex host transcript.

interrupted-a.stderr.log

Path
dev/activation-evidence/a22-host-runs/interrupted-a.stderr.log
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured host stderr stream.

parent-cd-recovery.jsonl

Path
dev/activation-evidence/a22-host-runs/parent-cd-recovery.jsonl
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured Codex host transcript.

parent-cd-recovery.stderr.log

Path
dev/activation-evidence/a22-host-runs/parent-cd-recovery.stderr.log
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured host stderr stream.

repository-a-resume.jsonl

Path
dev/activation-evidence/a22-host-runs/repository-a-resume.jsonl
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured Codex host transcript.

repository-a-resume.stderr.log

Path
dev/activation-evidence/a22-host-runs/repository-a-resume.stderr.log
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured host stderr stream.

repository-a.jsonl

Path
dev/activation-evidence/a22-host-runs/repository-a.jsonl
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured Codex host transcript.

repository-a.stderr.log

Path
dev/activation-evidence/a22-host-runs/repository-a.stderr.log
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured host stderr stream.

repository-b.jsonl

Path
dev/activation-evidence/a22-host-runs/repository-b.jsonl
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured Codex host transcript.

repository-b.stderr.log

Path
dev/activation-evidence/a22-host-runs/repository-b.stderr.log
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured host stderr stream.

stale-process-cwd.jsonl

Path
dev/activation-evidence/a22-host-runs/stale-process-cwd.jsonl
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured Codex host transcript.

stale-process-cwd.stderr.log

Path
dev/activation-evidence/a22-host-runs/stale-process-cwd.stderr.log
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured host stderr stream.

worktree-a.jsonl

Path
dev/activation-evidence/a22-host-runs/worktree-a.jsonl
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured Codex host transcript.

worktree-a.stderr.log

Path
dev/activation-evidence/a22-host-runs/worktree-a.stderr.log
Review
generated-ignore
Revision
5694080

Why this file is in scope

Captured host stderr stream.

a25-2026-08-26T17-16-03-446Z-c435874d-negative-config.jsonl

Path
dev/activation-evidence/a25-host-runs/a25-2026-08-26T17-16-03-446Z-c435874d-negative-config.jsonl
Review
generated-ignore
Revision
5694080

Why this file is in scope

A25 captured host transcript emitted by dev/run-activation-operating-envelope.mjs.

a25-2026-08-28T22-52-43-706Z-e0b75e9d-repo-a-root.jsonl

Path
dev/activation-evidence/a25-host-runs/a25-2026-08-28T22-52-43-706Z-e0b75e9d-repo-a-root.jsonl
Review
generated-ignore
Revision
aba6d04

Why this file is in scope

Captured Codex host transcript from the 2026-08-28 A25 re-measurement.

a25-2026-08-28T22-52-43-706Z-e0b75e9d-repo-b-root.jsonl

Path
dev/activation-evidence/a25-host-runs/a25-2026-08-28T22-52-43-706Z-e0b75e9d-repo-b-root.jsonl
Review
generated-ignore
Revision
aba6d04

Why this file is in scope

Captured Codex host transcript from the 2026-08-28 A25 re-measurement.

a25-2026-08-28T22-52-43-706Z-e0b75e9d-repo-c-nested.jsonl

Path
dev/activation-evidence/a25-host-runs/a25-2026-08-28T22-52-43-706Z-e0b75e9d-repo-c-nested.jsonl
Review
generated-ignore
Revision
aba6d04

Why this file is in scope

Captured Codex host transcript from the 2026-08-28 A25 re-measurement.

a25-2026-08-28T22-52-43-706Z-e0b75e9d-repo-d-root.jsonl

Path
dev/activation-evidence/a25-host-runs/a25-2026-08-28T22-52-43-706Z-e0b75e9d-repo-d-root.jsonl
Review
generated-ignore
Revision
aba6d04

Why this file is in scope

Captured Codex host transcript from the 2026-08-28 A25 re-measurement.

§Concern review

SI-2

Verdict
Accepted behavior
Evidence
Code verified

Rationale

Receipts bind to an explicit baselineCommit and implementationCommit and carry sha256 digests for their declared source files, and the checker re-hashes those files off the working tree rather than trusting the recorded digest. Independently recomputed during this refresh: all six digests match at 5694080 and implementationCommit db00515 is an ancestor of HEAD. A receipt cannot silently be reused as current evidence after its sources change. Recording note: partly test-observed, recorded at the nearest permitted rung per finding B03-3.

TB-1

Verdict
Accepted behavior
Evidence
Code verified

Rationale

Both host-driving harnesses wrap their child processes in an explicit timer that is cleared on completion, so a stalled Codex host terminates with a recorded outcome rather than hanging the evidence run. This is the discipline TB-1 asks for. It also sharpens finding B02-2: the evidence apparatus bounds its subprocesses while the production activation path it certifies does not.

VG-1

Verdict
Ruled out
Evidence
Code verified

Rationale

Every gate in this subsystem was executed during the refresh and each showed a green control alongside a complete set of nonzero sabotage exits: A26 readiness 4/4, A22 Codex host evidence 4/4, A25 operating envelope 3/3, and A24 package parity halting on both packed-cwd and skill-version drift. The gates have non-zero denominators and turn red on demand — the direct contrast to B-03 and B-04, where this concern is a confirmed bug. Recording note: the attached evidence is test-observed, but set_disposition does not accept that value (finding B03-3), so it is recorded here at the nearest permitted rung.

§Findings

§B08-1 · Medium · fixed

Symptom: Release readiness depends on the byte state of the user's live ~/.codex/config.toml. Once that file changes for any reason, the A22 checker reports drift permanently, the A26 candidate suite fails, and no release can be cut until another real-host A22 campaign rebaselines the pin. Root cause: The A22 receipt records host.configSha256Before/After and configurationCustody.restoredConfigSha256 for the developer's own Codex configuration, and check-codex-host-evidence compares the live file against them. That file is user-level and mutable independently of this repository, so the pin is a snapshot of something the project does not own and cannot hold still. dev/refresh-a22-evidence.mjs rebaselines the fourteen source digests but not the config pin, leaving no cheap recovery.

Business context: This is what blocked v0.2.0-beta.2 after A25 had been successfully re-measured. The A25 campaign landed 6/6 real-host runs against the repaired startup path and left the configuration byte-identical, so the activation claim itself is sound; the release still could not proceed because an unrelated pin on a user-level file had drifted since 2026-08-26. The coupling also makes the gate weaker than it looks: it turns red for ordinary local activity while telling the reader that host evidence drifted, which is a different and more alarming claim. A developer on another machine could never satisfy it at all.

Primary files:

  • dev/activation-evidence/a22-codex-host.json:host.configSha256Before@8c779e1
  • dev/check-codex-host-evidence.mjs:live configuration check@8c779e1
  • dev/run-friction-free-candidate-suite.mjs:A22 gate@8c779e1

§Survey notes

Status: structural → concerns (2026-08-27 refresh) Anchored at: 5694080 Layer: delivery evidence

§What this subsystem is

The A19–A26 program that produced, and now gates, the v0.2.0-beta.1 activation claim. It is an evidence corpus plus the authored instruments that generate and verify it — not runtime production code. The runtime it exercises lives in B-02 (project.ts, codex-host.ts) and B-05 (cli.ts); claims about enforcement must cross to those subsystems.

Created during the 2026-08-27 full refresh. Before that refresh none of its 94 files carried a ledger row.

§Observed structure

Three tiers, deliberately separated in the file ledger:

observed structure
TierClassificationContents
Authored instrumentsexamined / candidatedev/run-*, dev/check-*, dev/test-*-red-gates, dev/cleanup-*, mcp-server/fixtures/activation/**
Receiptscandidate / examineddev/activation-evidence/a19..a26*.json
Captured witnessesgenerated-ignoredev/activation-evidence/a2{2,5}-host-runs/*.jsonl, *.stderr.log

dev/adr/0021-friction-free-codex-activation.md is the charter. Its acceptance boundary is explicit: after one user-scoped installation and one host restart, a fresh trusted repository must resolve its own Git root, create no project state until first use, and begin a workflow without another setup command — with two concurrent repositories retaining distinct storage and zero cross-repository writes. It also states that parsing generated TOML is necessary but insufficient, which is why the host-run corpus exists.

§Observed facts (verified at 5694080)

  • The gates are falsifiable. All four red-gate suites were executed during this refresh. Each reported a green control and a full set of nonzero sabotage exits: A26 readiness 4/4, A22 Codex host evidence 4/4, A25 operating envelope 3/3, A24 package parity halting on both packed-cwd and skill-version drift. (evidence 69)
  • The claim is content-bound and revision-bound. The A26 receipt carries a baselineCommit, an implementationCommit, and sha256 digests for six source files; check-friction-free-release-readiness.mjs re-hashes each file off the working tree and fails on drift. Recomputed independently here: all six match at 5694080, and implementationCommit db00515 is an ancestor of HEAD. The real receipt validates: "7/7 initiatives, 6 repository results". (evidence 70)
  • Subprocesses are bounded. Both host-driving harnesses wrap their children in an explicit timer cleared on completion. (evidence 71)

§Inference

The separation of generated witnesses from authored instruments is what makes the corpus auditable: a reader can tell which files are claims and which are transcripts. Combined with red-gate proofs and off-disk digest verification, this subsystem meets the falsifiability standard that B-03's staleness surface and B-04's freshness sentence do not (findings B03-2, B04-1).

§Tension worth recording

The harnesses bound their subprocesses; the production activation path they certify does not. Finding B02-2 records six unbounded git calls and one unbounded ps probe on the startup path. The evidence apparatus is more disciplined than the runtime it measures.

§Open questions

  • Whether dev/adr/** belongs to B-05 (documentation delivery) or should be split, with ADR-0021 following B-08. Recorded as a scope-judgment call; ADRs currently sit in B-05.