|
| 1 | +# Switchloom 0.3.1 Public-Byte Certification |
| 2 | + |
| 3 | +Date: 2026-07-22 |
| 4 | +Release Planr map: `switchloom-v0-3-1-codex-0-145-native-v2-compatibility-and-published-byte-certification` |
| 5 | +Certification item: `i-certify-public-bytes-and-finaliz-ad43` |
| 6 | + |
| 7 | +This receipt supersedes the `v0.3.0` handoff as the current public-byte proof. |
| 8 | +The machine-readable source is |
| 9 | +`reports/release-ready-v0.3.1/public-byte-certification.json`. |
| 10 | + |
| 11 | +## Reviewed Release Identity |
| 12 | + |
| 13 | +- Candidate commit: `2f8ba006df06b88bb602d0698696c73e5963ff86` |
| 14 | +- Release and merge commit: `d7165627e33be2fb17f2e2f8f1b289cc1a40bf83` |
| 15 | +- Candidate and release tree: `2016988ee6ddf3514024ed93fdc810c41b388ce1` |
| 16 | +- Pull request: `https://github.com/instructa/switchloom/pull/21` |
| 17 | +- Annotated tag: `v0.3.1` |
| 18 | +- Tag object: `a30cc81d17410075dad33ad68c39e1149c1b2bec` |
| 19 | +- Release workflow: `29917032398`, successful for the release commit |
| 20 | +- GitHub release: `https://github.com/instructa/switchloom/releases/tag/v0.3.1` |
| 21 | +- npm package: `switchloom@0.3.1` |
| 22 | +- Homebrew formula: `instructa/tap/switchloom`, stable `0.3.1` |
| 23 | +- Website: `https://switchloom.ai` |
| 24 | + |
| 25 | +PR `#21` completed 10 required checks before merge. The candidate review |
| 26 | +`i-review-produce-and-independently-4f3b` closed complete in independent mode. |
| 27 | +Publication review `i-review-publish-switchloom-v0-3-1-209e` found a stale |
| 28 | +local-binary website parity claim. Fix item |
| 29 | +`i-fix-findings-for-review-publish-9562` replaced it with the checksum-verified |
| 30 | +public binary result, and both `i-review-fix-findings-for-review-p-f9ca` and |
| 31 | +`i-follow-up-review-for-review-publ-b8c0` closed complete. |
| 32 | + |
| 33 | +## Public Provenance |
| 34 | + |
| 35 | +The npm tarball SHA-256 is |
| 36 | +`52b8aa965ef81a3c9c8f94ffe4dfa62db1c92475bc6834f1366208ec72f52fba`, |
| 37 | +registry shasum is `4fb17ae575f9a77f5920524743f07b69da3c3ea4`, and |
| 38 | +integrity is |
| 39 | +`sha512-y+wz1NDEljOmXVGWkrjgy9QIXAnJ2w29d2rVntEmefDGyyR7D1q044pjHX3gdgrCIWFm/VJdwBRVSL/xytpPFA==`. |
| 40 | +Its native provenance hashes to |
| 41 | +`8f207afe26e609ca9ff1c9bc8a36595abaa0c92bfbd04409999b9eaff4a5ba44` |
| 42 | +and records release commit `d7165627e33be2fb17f2e2f8f1b289cc1a40bf83`. |
| 43 | + |
| 44 | +| Target | GitHub archive SHA-256 | Extracted native SHA-256 | |
| 45 | +| --- | --- | --- | |
| 46 | +| `darwin-arm64` | `1b5d022e6e9839ea16cdc51cd55283d3f116f7d52261f40a52b2b0c20d6797bf` | `5c0884da0dda7bdd87e8e3ce9530faa1cdea980acea49dadd0b8edd21367b5a4` | |
| 47 | +| `darwin-x86_64` | `e0a2e143d75b90651f714f144111c30e38cbfa3c8d407e0af45c70ea8fc519a4` | `2da9107175c73e24de7790f5219041550f29674c6af9a5adfb056afcde2cc08b` | |
| 48 | +| `linux-arm64` | `2116b8cf934d24a04973c0fd76cbf88d9f17eaab9b032446e87d445bc8bb3b73` | `1c3808749f941b9badb79c199025cac2c22678148a0b338220b1e7d12d65cd92` | |
| 49 | +| `linux-x86_64` | `836abf1689cc09e5254273cd379f285174be6886ce60932008e48732883af844` | `ee44f2df0e59063a5feb1e438644c3fccdacfd443746dea5e184686709cbbebd` | |
| 50 | + |
| 51 | +All four npm native hashes match binaries extracted from the four public |
| 52 | +GitHub archives. `SHA256SUMS` hashes to |
| 53 | +`c6443b222478f57d476867f35c36c6e15348d09424f0db40a079535e62471e9d`. |
| 54 | +The Homebrew formula at tap commit |
| 55 | +`e74da41afe58f76bb8d6aa2e115501679ae6a527` uses the same darwin-arm64 |
| 56 | +archive and checksum. |
| 57 | + |
| 58 | +## Fresh Install Lifecycles |
| 59 | + |
| 60 | +The npm run used an isolated global prefix and cache under |
| 61 | +`/private/tmp/switchloom-public-v0.3.1-npm.ncczr0`. The Homebrew run used |
| 62 | +`brew reinstall instructa/tap/switchloom` and an isolated repository under |
| 63 | +`/private/tmp/switchloom-public-v0.3.1-brew.4i8hYg`. |
| 64 | + |
| 65 | +Both public channels returned `model-routing 0.3.1`, exposed `policy`, |
| 66 | +`compile`, `inspect`, `preview`, `apply`, `update`, `status`, `uninstall`, |
| 67 | +`rollback`, and `doctor`, and executed this non-destructive lifecycle: |
| 68 | + |
| 69 | +1. Compile `balanced` and `low-usage` Codex bundles. |
| 70 | +2. Inspect and preview the bundle, then apply and inspect status. |
| 71 | +3. Update, roll back, and check status again. |
| 72 | +4. Delete one managed Terra role, observe missing-state repair guidance, and |
| 73 | + run update to restore it. |
| 74 | +5. Uninstall and assert that no managed artifacts remain. |
| 75 | +6. Apply against a compatible pre-existing unmanaged V2 setting and prove its |
| 76 | + bytes remain unchanged. |
| 77 | +7. Apply against a conflicting `multi_agent_v2 = false` setting and prove the |
| 78 | + command fails before partial managed state while preserving its bytes. |
| 79 | + |
| 80 | +The npm and Homebrew binaries both hash to the public darwin-arm64 native hash |
| 81 | +`5c0884da0dda7bdd87e8e3ce9530faa1cdea980acea49dadd0b8edd21367b5a4`. |
| 82 | +Across both runs, the unrelated sentinel, project Codex config, project role, |
| 83 | +and global Codex config remained byte-identical: |
| 84 | + |
| 85 | +| State | SHA-256 | |
| 86 | +| --- | --- | |
| 87 | +| Unmanaged sentinel | `60ba63428d6029222a9d092142fcdc64d045d93650e0c25cb25cd7f319351fae` | |
| 88 | +| Project `.codex/config.toml` | `205154e65c71a9da37e8e88334441d3873369a2da943d6f8875c0ca2d27aa8f1` | |
| 89 | +| Project local role | `dc41b95480f42e96893940ea9621c0b4d941f9a2385abcc2c0692c5da947a0ce` | |
| 90 | +| Compatible unmanaged V2 config | `6600e0b0294d38fc8f9ab0b0b82d99fea32cc39d4f18053d67925a5344928b36` | |
| 91 | +| Conflicting false config | `d4387757c44460f8fb3396a67c2d2298ef64e564cd88cb1c81930d73d50ca223` | |
| 92 | +| Global `~/.codex/config.toml` | `106482691dcada0fe1e862bffe7c59e771e804636a64b7495c5434995e378293` | |
| 93 | + |
| 94 | +## Exact Codex 0.145 Oracle |
| 95 | + |
| 96 | +The positive command used exact `@openai/codex@0.145.0`, an isolated |
| 97 | +authenticated Codex home, and the public npm darwin-arm64 binary: |
| 98 | + |
| 99 | +```sh |
| 100 | +SWITCHLOOM_CODEX_RUNTIME_HOME=<isolated-authenticated-home> cargo run --quiet -p xtask -- certify codex --routing-bin reports/release-ready-v0.3.1/public-npm/extracted/package/npm/native/darwin-arm64/model-routing --report-root retained-evidence/release-ready-v0.3.1/live --timeout-seconds 600 |
| 101 | +``` |
| 102 | + |
| 103 | +The report has `success: true` and `live_verified: true`. It correlates the |
| 104 | +parent thread, exact V2 spawn call arguments, custom `task_name`, registered |
| 105 | +`agent_type`, `fork_turns: none`, complete child sessions, effective model and |
| 106 | +effort, and dynamic nonce for: |
| 107 | + |
| 108 | +- Terra High maker: `model_routing_terra_high`, task `standalone_maker`, |
| 109 | + effective `gpt-5.6-terra` with `high`, nonce |
| 110 | + `019f89b8-8cb6-74b3-bd94-77fd07a11d5a:019f89b8-9d85-71d3-bed8-4cf9f73cfc1f:call_E8YJ5duz3iKw7eBUi0qs7Sm1`. |
| 111 | +- Sol High reviewer: `model_routing_sol_high`, task `standalone_reviewer`, |
| 112 | + effective `gpt-5.6-sol` with `high`, nonce |
| 113 | + `019f89b8-8cb6-74b3-bd94-77fd07a11d5a:019f89b8-a64a-70e2-a6ef-50d04eabd4f5:call_ZXL8ZbYOTMa43wAA35DHeNpj`. |
| 114 | + |
| 115 | +Positive evidence: |
| 116 | + |
| 117 | +- `retained-evidence/release-ready-v0.3.1/live/codex-openai/1784721995-22171-0/certification-report.json`, SHA-256 |
| 118 | + `6c2c45f552db1961545f0bcd4119417517978eb2310d004f27265201e90a694a`. |
| 119 | +- `retained-evidence/release-ready-v0.3.1/live/codex-openai/1784721995-22171-0/codex-runtime-evidence.json`, SHA-256 |
| 120 | + `30127910811f5a6906a09a1b08ba777c18d1f858821abe24d986c16b54d41f76`. |
| 121 | + |
| 122 | +The exact negative command added `--negative-fixture`. It succeeded only by |
| 123 | +failing closed with `parent must contain exactly 2 V2 spawn_agent calls`. |
| 124 | + |
| 125 | +- `retained-evidence/release-ready-v0.3.1/live/codex-openai-negative/1784722125-40469-0/certification-report.json`, SHA-256 |
| 126 | + `b291e1eab3535628c901576681bc14c5911a7b5c4a30170d539f4e2b2d212299`. |
| 127 | +- `retained-evidence/release-ready-v0.3.1/live/codex-openai-negative/1784722125-40469-0/codex-negative-fail-closed.txt`, SHA-256 |
| 128 | + `f9920edf6c71288ee3e266c3e884647bc7df17c512a5038b0f9eb7c5d7881ede`. |
| 129 | + |
| 130 | +The protected global-config snapshots match before and after both runs. The |
| 131 | +capability boundary remains frozen in `docs/codex-v2-runtime-evidence.json`: |
| 132 | +Codex owns effective backend selection and orchestration; Switchloom owns the |
| 133 | +repository-local role declarations and requested-versus-effective contract. |
| 134 | + |
| 135 | +## Live Website Guidance |
| 136 | + |
| 137 | +`node scripts/verify-cloudflare-website.mjs https://switchloom.ai <public-v0.3.1-binary>` |
| 138 | +passed with 28 compositions, 6 setup hosts, catalog SHA-256 |
| 139 | +`f879c6fdccca95abebcb65d521d9f115007165ec3c0e9fb1db47e81dae394026`, |
| 140 | +and balanced Codex download parity |
| 141 | +`da329ed10bbf9be4cc136173eb2702237662d6c13ad9e0f995e531535a0bc603`. |
| 142 | + |
| 143 | +A fresh headless browser rendered the live Commands tab and verified the |
| 144 | +`switchloom@0.3.1` install/lifecycle commands. Invoking the page's copy action |
| 145 | +returned an exact `npx switchloom@0.3.1 apply --recipe 'sw1_...' --repository .` |
| 146 | +command. Switching live host tabs verified exact Codex 0.145 Terra/Sol |
| 147 | +certification, Luna experimental/unverified, Cursor advisory, and Claude |
| 148 | +unavailable/unverified wording. |
| 149 | + |
| 150 | +## Protection And Limits |
| 151 | + |
| 152 | +- `/Users/kregenrek/projects/planr` remained at |
| 153 | + `bbc877d40191b2cbb289ed26df5e6fee25e4326d` with `-uall` status SHA-256 |
| 154 | + `d6c56495c7e2a78aed2e641b0e928bc8a579bf31335db36456a9f05726827927`. |
| 155 | +- The global Codex config remained SHA-256 |
| 156 | + `106482691dcada0fe1e862bffe7c59e771e804636a64b7495c5434995e378293`. |
| 157 | +- Fresh install execution covered darwin-arm64. Other platforms are correlated |
| 158 | + by CI provenance and public archive extraction, not executed on this host. |
| 159 | +- Terra High and Sol High are deterministic for exact Codex 0.145.0. Luna is |
| 160 | + experimental/unverified; Cursor stays advisory; Claude Code, OpenCode, and Pi |
| 161 | + stay unavailable/unverified without equivalent authentic receipts. |
| 162 | +- An initial isolated run without copied authentication returned HTTP 401 and |
| 163 | + is excluded. No auth file, session database, cache, or raw runtime workspace |
| 164 | + is committed; only the sanitized reports listed above are retained. |
| 165 | + |
| 166 | +After this item and its independent review close, `planr plan audit |
| 167 | +pln-45ebe887 --json` must report all clauses passing before Goal B starts. |
0 commit comments