← 全部工具

OpenCoven/sdk

热度 70 更新于 开发与构建

Experimental TypeScript SDK and CLI for OpenCoven clients, transports, and shared protocol types. Not for production use.

githubauto-collected

安装

暂未验证可直接使用的安装命令,请查看项目官方文档或 Release。

OpenCoven TypeScript SDK

[!WARNING] Experimental — not ready for public consumption. This SDK is under active development, has not completed its first-release security review, and may change without notice. Do not use it for production workloads or with production credentials.

This workspace contains four experimental TypeScript SDK release packages and a private developer CLI workspace for OpenCoven Phase 1b clients, transports, compatibility contracts, runtime-only Cave discovery and pairing, explicit Coven daemon health, coordinated health reporting, and shared protocol infrastructure.

Release status

This source repository is public, but all workspace packages are explicitly marked private, are not published, and have standard publishing blocked. The 0.0.1 release inventory contains only @opencoven/sdk-core, @opencoven/cave-client, @opencoven/coven-client, and @opencoven/sdk. @opencoven/dev-cli remains private and is not packed, versioned with, or published beside that group. Standard publishing also requires OPENCOVENRELEASEAUTHORIZATION=publish; remove or change these gates only as part of an intentional release process. The 0.0.1 native Chat/real-authority conformance release matrix is separately frozen to darwin-arm64, linux-x64, and win32-x64; see SUPPORT.md for the distinction between Node runtime support and this release gate.

The four release manifests and initial changelogs are prepared at 0.0.1, with the merged Cave authority contract advertising a 0.0.1 client minimum. Strict version checks remain unchanged. The source lock now freezes the replacement private 0.0.1 candidate at cd10a3fa1d9900e0dbcb04bbb2477140854fba1d and its exact tarball bytes. The #40 re-review blocked the previous candidate 96804bc4 because it predates High-severity Cave fixes (see Second candidate source preparation); its aggregate and evidence remain historical, as do earlier 0.1.0 artifacts. This candidate includes the merged Coven Automations APIs and those fixes. Candidate77 records remain historical evidence. This binding selects the merged Chat #390 producer 399e1f199417e74db6a1b9096500d0e953fdfa6b, tree 76adbce55467a6bd276a040284d7004d88e452b8. Its reviewed head b7ceff48066a6649366fc27aa4ca41db064ad5ee has the same complete tree and has executable harness authority 2f72ecedd225759a11889ec4b7dd112b71361d56, tree 0a2e550bddbeaec405367d1dcb383c38fb10fb51 (Chat #389, which retries the Windows run-root rename through a transient access denial), as its sole parent. Its consumer is still dabcdd4 from Chat #383. The merge parents are that harness authority and the reviewed head. The validator checks the merge-to-reviewed-source edge, the source-to-harness edge, and complete reviewed/delivery tree equality. The intermediate source-authority path is empty again: this repin landed as a single commit.

This producer retains Chat #311's build-time home isolation, the exact Chat #314 producer-revision resolver, bounded Windows quota diagnostics, and Chat #327's pinned-main freshness guard, Chat #348's shortened isolated Windows bootstrap root, and the named report and Coven handshake diagnostics from Chat #361, #363 and #365. It adds Chat #370's two Windows repairs. First, the bootstrap selects a whole reviewed profile per runner image, because GitHub's gradual rollout of 20260922.246.2 serves it alongside 20260907.229.1 and the two differ in OS build, PowerShell and .NET as well as Visual Studio. Second, the Coven same-user identity scenario accepts exit code 1 from the daemon on Windows only, after the authenticated stop succeeds: coven daemon stop ends the verified daemon there with TerminateProcess(handle, 1), and requiring 0 had failed that assertion at its result stage on every Windows run. It also adds Chat #374: a Google Fonts download failure during the frozen Cave build, previously reported as compile.module-resolution, now reports compile.font-fetch, and only that failure retries the Cave build once. All 25 governed files and ten production deltas are bound to reviewed Git bytes. Token/profile ownership, native cleanup, resource limits, and operator isolation remain required. The SDK candidate and Chat consumer, Cave, and Coven revisions remain frozen.

SDK #316 delivered the preceding Chat #371 binding; that binding is historical and is not the one recorded above. Its protected runs 36033589858 and 36038079308 belong to it, and both completed every platform, validation, attestation and aggregation job with success. Earlier bindings, SDK #302's Chat #328 binding at 1c10e63a9ff87934397e8defc2d0b98f3932abe2 among them, are historical.

Protected run 35566636457 is historical and belongs to the preceding Chat #328 binding, not to the binding recorded above. Linux and macOS artifacts independently passed exact run/job and validator identities, ZIP digests, canonical schema, privacy/isolation checks, timing, and all 197 ordered assertions each (110 Cave, 46 SDK, 41 Chat). Windows failed at phase1.packaging.chat-native-build.build-script and produced no platform record. Validation, attestation, and aggregation were skipped. The earlier run 35500732205 failed at the same stage. That stage is now identified: the aws-lc-sys build script, whose deepest relative include exceeded MAXPATH beneath the previous isolated bootstrap root, which Chat #348 shortens.

Earlier run 35146928092 used Chat #311 / SDK #293 and produced independently verified Unix records with 197 assertions each. Its Windows checkout-quota failure is separate from the historical native-build failure and from run 35138402347's operator Cave-home isolation failure.

Historical run 35125287541 failed Windows execution-root cleanup before isolation validation. Run 35111662551 failed Windows isolation; run 35100084575 failed Windows secure-store preflight and deletion-purpose cleanup. Keep these failures distinct. Resolving the Windows evidence-assembly failure and obtaining a complete authenticated three-platform aggregate remain required. Chat consumer, candidate, Cave and Coven identities remain frozen.

Historical protected run 34977202052 used Chat producer 047e8ad7f4a2ca5a9009217de3c3f5f32fd98ba6 and SDK #284 validator e37b195c246d55a5929dc74f7e7d116b1fc6dfd0. Both validator scopes were read back at that SDK merge; the frozen workflow and supervisor artifact were authenticated before environment approval. Linux and macOS passed; their records independently passed exact identities, canonical schema, private scans, Cave timing and all 197 ordered assertions each (110 Cave, 46 SDK, 41 Chat). Windows failed at phase1.native-scenarios.native-preflight-installation-secure-store-unavailable and produced no record. Validation, attestation and aggregation were skipped.

That historical run exposed the native secure-store category without identifying the failing installation operation. Chat #297 subsequently landed profile ownership and cleanup repairs, bounded operation diagnostics, and a restricted native installation roundtrip. Its ordinary CI passed; SDK #290 landed and both scopes rotated for run 35111662551, which failed Windows isolation. Chat #305 adds bounded diagnostics for that new failure. SDK #38 acceptance remains open.

The following SDK #276 checkpoint is historical. On 2026-09-15, SDK #276 landed as 6b4e0d04e168c7ccd99df492a0494e223150e2ab with the verified Chat #293 binding. Both validator scopes were rotated and read back at that actual merge. Protected run 34951851914, attempt 1, was dispatched with Chat 6fa5dab5 and SDK #276. Its frozen workflow and supervisor artifact passed independent authentication before environment approval. Linux and macOS passed independent record identity, Cave timing, scan, and all 197 ordered assertion checks each. Windows failed at phase1.native-scenarios.native-preflight-installation-rpc, during appinstallationid and before the installation-ID assertion. It published no record; validation, attestation, and aggregation were skipped. This is terminal partial evidence, not aggregate acceptance or publication approval. The RPC's underlying failure remains unclassified; the stage does not prove a recurrence of the earlier quota-monitor cause.

The prior SDK #275 run 34945048615 is terminal failure: Linux and macOS records passed independent inspection, while Windows published no record and failed its bounded checkout directory quota monitor. Downstream attestation and aggregation were skipped. The #38 checkpoint tracks subsequent platform records and exact aggregate acceptance.

SDK #277 separately delivered per-client discovery v2 retention, concurrent current-credential preservation, and snapshots used to pin pairing authority. That development-source change is not included in frozen candidate 96804bc4 or validated by the SDK #276 run. SDK #299 and #301 subsequently delivered pairing guard regressions and managed HPKE iterator continuity; both blockers in #296 are closed. Native adapter adoption remains separate. Candidate and counterpart authorities stay frozen; a later candidate needs its own review and evidence. Complete protected #38 evidence and #40 authorization are still required; see the v0.0.1 preparation checklist for the remaining gates and required release sequence.

Bootstrap provenance preparation adds separately signed npm-compatible bundles without changing the original GitHub build attestation or enabling publication. The read-only verify:bootstrap-provenance command requires actual SHIP evidence; it neither publishes nor grants the separate manual-bootstrap approval. Genuine final SDK bundle qualification and registry acceptance remain pending. See First-publish bootstrap.

  • Roadmap
  • 0.1 read-only release design
  • 0.1 dependency-ordered delivery program
  • GitHub delivery program
  • Support policy
  • Compatibility and deprecation policy