Last updated: 2026-09-13 (the reference host re-cut on suite
2.1.6—187 / 0 / 0 / 44 / 0, 1606 assertions, all three claimed profiles certified, andcheck-cut-gates --host-bundleclears all ten predicate groups, 0 failed 0 blocked: the only fully-clean host bundle in this table. It had been the STALEST row here, measured on2.0.0-rc.61while the suite moved sixty-plus releases — accurate for the suite that ran it, which is all this table asks, but unable to answersuiteVersionCheck's question, "did this bundle run everything this corpus now requires of a host at its major". A stale row is not a neutral default, and the steward's own host should not be the last to act on that.) Previous, 2026-09-10 (v2 is the released major —v2.0.0tagged 2026-09-05, corpusv2.1.6tagged 2026-09-11 and suite2.1.4on npm; the v2 table below is no longer a release-candidate table. Rows are unchanged: each still carries the suite that measured it, and MyndHyve's2.0.8re-cut —136 / 0 / 90 / 0,openwop-discovery-corecertified,discovery.documentpresent — is that host's bundle to check in, not the steward's to transcribe.) Previous, 2026-09-05 (the reference host re-cut on suite2.0.0-rc.61and still certifies every profile it claims —openwop-host-v2-reference@2.0.0-rc.1atd029f8fe, 181 / 0 / 0 / 42, Identity through Front door PASS. The rc.59 bundle went stale the moment rc.60 landed: the Front door gate refused it because 1 of 72 major-2 scenario files had no row in it, so its totals said nothing aboutv2-run-fork-prefix— a bundle that never measured a scenario cannot speak for it. The two rows added since are that fork-boundary witness (this host is exclusive and passes it) and rc.61'skind: othernote assertion (vacuous here). Earlier: the first bundle from any host to clear all of §F, at48e26b72on suite2.0.0-rc.58; it replaced the rc.57 bundle checked in earlier that day, which measured a stale local process (disclosed in its row), and the clock anchor for this host stays on that commit by the mechanical rule. Earlier: every v2-table host now carries a non-vacuous major-2 bundle — the reference example re-cut on suite2.0.0-rc.57under the rotated keyv2-reference-2: witnessCount 3 / 8 / 4,certified: nonebecause the corpus moved past its own example between rc.16 and rc.57 (10 executed-fail rows, host fixes queued in openwop-examples); with all three hosts anchored the v1 end-of-support clock computes its first date. Earlier: both production hosts carry non-vacuous major-2 bundles — openwop-appopenwop-app-backend-00678-2sratf8e24beb7joins MyndHyve below: suite2.0.0-rc.56, signed and self-verified, cut at one worker through the Firebase Hosting + Cloud Run front door,openwop-discovery-corewitnessCount 3 → non-vacuous,certified: none(2v2-poll-cursor-v2fails = Gap C, seams surface not advertised = Gap A). Earlier the same day: first production major-2 bundle checked in — MyndHyveworkflow-runtime-00330-cjgat847d2425e, suite2.0.0-rc.56, signed and self-verified,openwop-discovery-corewitnessCount 3 → non-vacuous, so it anchors the v1 end-of-support clock (spec/v2/core/overview.md§v1 end-of-support; the anchor date is the merge commit that first carries the file, recorded byscripts/generate-v1-eos-clock.mjsin a follow-up commit). Not certified: its seams surface is not advertised, so the Coexistence rows stay blocked. Previous update, 2026-08-24: MyndHyve webhook delivery headers corrected and SERVING —workflow-runtime-00574-bawat 100%, replacing00572-noc:X-openwop-Signature: sha256={hex}andX-openwop-Webhook-Id, matchingwebhooks.md§"Delivery headers". The header shape is not live-witnessed — the host carries zero webhook subscriptions, so nothing observed a real delivery; the bytes are covered by unit and wire-level tests, red-before-green by sabotage. Rollback--to-revisions=workflow-runtime-00572-noc=100.) 2026-08-19 (MyndHyve bundle v2 #15, suite1.136.11). Per-bundle conformance history is in the Update log below; release-level changes are inCHANGELOG.md.A live record of OpenWOP-compatible hosts — their advertised compatibility profiles and the conformance evidence behind each claim. A row is a claim plus evidence: the claim is the host's advertised profile; the evidence is the conformance result published with the host (or under
conformance.md). Evidence vocabulary (RFC 0148 §A/§C, RFC 0155 §E): a claim is certified only when a bundle v2 shows every floor requirement of the profile in a certifiable disposition with a witnessed assertion count; rejected when a floor requirement returned unclassified (no row, or a zero-assertion pass); unprovable when the profile has no floor inPROFILE_FLOOR_SCENARIOS(RFC 0148 §C G6); and a self-declaration otherwise. Evidence tiers (steward / steward-affiliated sibling / independent-organization) followGOVERNANCE.md§"Acceptance evidence tiers"; no independent-organization row exists.openwop-discovery-coreis the canonical name of the discovery predicate;openwop-coreis its deprecated v1 alias and both derive together — an unqualified "OpenWOP conformant" statement meansopenwop-core-standard.openwop-node-packsis runtime-derived (profiles.md): from suite1.117.0a bundle claims it only when the host holds it (both floor scenarios witnessed passes); the1.116.0rows below that read rejected for it would read not held under1.117.0— same evidence, honest name.
v2 — the current major (corpus v2.1.7; suite 2.1.4 published)
The rows below were cut on release candidates and early 2.0.x patches — the suite version in each row is the one that measured it, and a row is never rewritten to a suite that did not run. v2.0.0 was tagged 2026-09-05; a host that has re-cut on a later suite replaces its own row with its own bundle (evidence/v2-host-bundles/<host>.json).
The charter's §F Witness and Front door predicates are measured on a host implemented from spec/v2/core/ rather than adapted from a v1 host — that is what the Front-door predicate asks, and building it is what found seven corpus and six suite defects before the cut. Neither the in-memory nor the SQLite reference host can reach the v2 floor (no fork substrate, no packs, no Subject), so they stay on the 1.x line through the overlap and appear only in the table below this one.
Verify a row with node scripts/check-cut-gates.mjs --host-bundle <bundle>.
| Host | Implemented from | Suite / artifacts | Advertised profiles | Discovery | pass / fail / blocked / inapplicable / skipped | Bundle | Evidence tier | Certified |
|---|---|---|---|---|---|---|---|---|
openwop-host-v2-reference@2.0.0-rc.1 (examples/hosts/v2-reference/, build commit:0db8e187) | spec/v2/core/ prose + the generated v2 documents — never from v1 host code; caught up with the rc.40–rc.53 prose retrospectives on 2026-09-05 (openwop/openwop-examples#32) | @openwop/openwop-conformance@2.1.5 / @openwop/spec-artifacts@2.1.5, --target-major 2 --require-behavior --max-workers 4, corpus stamp verified | openwop-discovery-core (witnessCount 3), openwop-core-standard (witnessCount 13), openwop-conformance-seams-v2 (witnessCount 4) — the spec/v2/profiles.json predicates its root satisfies | protocolVersions ["1.11","2.0"], preferredVersion 1.11 (the overlap rule, versioning.md §1.1), eventLogSchemaVersion 3 | 187 / 0 / 0 / 44 / 0 (231 ledger rows, 1606 assertions) | evidence/v2-host-bundles/openwop-host-v2-reference.json (= the example's bundle-v3.json), witness 180b49fd2f7f…, signed v2-reference-2 (rotated 2026-09-05; published in its discovery signingKeys[]); check-cut-gates.mjs --host-bundle against the 2.1.5 corpus: all ten predicate groups PASS, 0 failed 0 blocked — Identity, Registers, Closure, Deprecation, Paths, Codemods, Waiver, Witness, Coexistence, Front door — the first bundle from any host to clear all of §F. Disclosure: the rc.57 bundle this replaces (checked in by #1277, the commit the clock anchors this host on) measured a stale local process — the cut script had started the host on one port and pointed --certify at another, where a 2026-09-04 build was still listening; its 10 executed-fail rows were that process's. The anchor commit stands by the mechanical rule (the first commit at which the file was non-vacuous), fifteen minutes before this honest cut; the example's conformance.md keeps the superseded measurement | self | openwop-discovery-core, openwop-core-standard, openwop-conformance-seams-v2 — 0 executed-fail, 0 blocked, 0 skipped; the 44 inapplicable rows are optional families the host does not advertise (a2a, mcp, saml, scim, packs), each with its reason |
myndhyve@0dbdddf44 (MyndHyve workflow-runtime v1.0.0, steward-affiliated sibling host — see its v1 row below; build commit:0dbdddf44 as recorded in the bundle's host.build) | its v1 host code, migrated through the RFC 0167 program (docs/migration/v1-to-v2.md, docs/runbooks/V2-HOST-MIGRATION.md) — the first production host to reach a non-vacuous major-2 bundle | @openwop/openwop-conformance@2.0.4 / @openwop/spec-artifacts@2.0.4, --target-major 2 --max-workers 1, corpus stamp 8abb52df… verified | openwop-discovery-core — certified: true (witnessCount 3, tier self). The first certified major-2 profile claim from a production host. openwop-conformance-seams-v2 and openwop-core-standard remain unclaimed | protocolVersions ["1.0","2.0"], preferredVersion 1.0 (the overlap rule, versioning.md §1.1), eventLogSchemaVersion 3, sha256 c7a0b4c56b00c962cb5d772598b29e0467b5ef1c62556ac0e942fc23bdb8480f | 136 / 0 / 88 / 0 / 0 (1457 assertions, 224 rows, per-row counts equal the declared totals) — zero failures, zero blocked, across rc.56 … 2.0.4 | evidence/v2-host-bundles/myndhyve.json — bundleVersion 3, file sha256 b1814b027fc6…, witnessSha256 a84a0297c18e…, ed25519 signature under keyId myndhyve-bundle-2026-09 covering witnessSha256,host.build,suite.version,discovery.sha256 (so the witness cannot be transplanted onto another build, suite or discovery document), discovery bb48ab6188… at https://api.myndhyve.ai/.well-known/openwop. Self-consistency verified in-tree: 224 rows summing to assertionCount 1457, and the per-row dispositions re-tally to the declared totals exactly. Not verified here: the host reports it validated the keypair end-to-end against its published signingKeys[] before the cut, and a sidecar records generation at 02:36:23Z inside a credential window expiring 06:31:27Z — neither claim is carried by the bundle, whose discovery block records only url/sha256/protocolVersions/preferredVersion | self | Certified — with 3 of 20 floor rows partial witnesses, which the bundle self-identifies: results.requirements[].detail carries the partial-witness: prefix on 8 rows (1 blocked-flavoured, 7 inapplicable-flavoured), three of them floor rows — floor.v2-webhook-durable-delivery (blocked-flavoured: the retry WAS observed, the 204 was not, because the base backoff interval is not on the wire and the suite cannot derive how long to wait), floor.v2-interrupt-token-scheme (GET /interrupts/{token} unmounted) and floor.v2-v1-signed-webhook-accepted (seams profile unadvertised). A floor row can read executed-pass and still be half-unwitnessed — scenario-disposition.ts:109 returns executed-pass once assertions have passed and never consults a later soft-skip note, so the marker is the only signal and it is per-FILE, unable to say which leg produced it. A floor tally that ignores the prefix overstates readiness. Four suite releases on 2026-09-06 (2.0.1–2.0.4) cleared this host's path and NONE of them were host defects: a carrier read from the wrong field, a wait that outran its own harness, a disposition that convicted a host for the instrument's budget, and a fixture that required a host to violate RFC 0177 §D.1 in order to demonstrate §D.1 |
openwop-workflow-engine@0.1.0 (openwop-app, the tier-1 production host at app.openwop.dev — see its v1 row below; build commit:f7c631b9b, serving openwop-app-backend-00688-9bk at 100%; re-cut 2026-09-10, previously f8e24beb7 / 00678-2sr on rc.56) | its v1 host code, migrated through the RFC 0167 program (docs/migration/v1-to-v2.md, docs/runbooks/V2-HOST-MIGRATION.md); the Firebase Hosting + Cloud Run front door is part of the measured surface (%2F decoding, the http: link downgrade and the per-IP read budget were all found and fixed on the wire, 2026-09-05; the ADR 0646 shared-name content negotiation — /runs/<id> is JSON under OpenWOP-Version: 2 and the SPA shell to a headerless browser — landed 2026-09-10) | @openwop/openwop-conformance@2.0.11 / @openwop/spec-artifacts@2.0.11, --target-major 2, OPENWOP_MAX_WORKERS=2, corpus stamp 73ec5b7c… verified | openwop-discovery-core (witnessCount 3), openwop-core-standard (witnessCount 12) — the spec/v2/profiles.json predicates its major-2 root satisfies; openwop-conformance-seams-v2 is NOT advertised by the production revision (Gap A — the seams profile is a test-mode mount), so its rows are inapplicable, not blocked, on 2.0.10+ | protocolVersions ["1.1","2.0"], preferredVersion 1.1 (the overlap rule, versioning.md §1.1), eventLogSchemaVersion 3, sha256 8825f2c7baba50d0574f0f354d9544ecd6896298f3d80d196cd07316f51e1a01 | 137 / 0 / 3 / 87 / 0 (227 ledger rows, 1273 assertions) | evidence/v2-host-bundles/openwop-workflow-engine.json, witness c4499983b930…, signed openwop-app-self-2026-09-04 — the key is published in its discovery signingKeys[]; attribution and the tarball digest verified by check-cut-gates.mjs --host-bundle --network on 2026-09-10 (Identity, Registers, Closure, Deprecation, Paths, Codemods, Waiver, Witness, Front door PASS; Coexistence FAIL only on the seams-gated fork-a-v1-run / v1-signed-webhook-accepted legs and the manifest-ceiling-refused rows it does not advertise) | self | none — 0 executed-fail rows (the 2 v2-poll-cursor-v2 fails of the rc.56 cut are closed: ADR 0633, an omitted afterSequence starts at sequence 0), and 3 blocked rows, all the SSRF loopback receiver (lane-side: production correctly refuses to call back to a laptop; a public receiver URL is the only remaining precondition, runbook §"Why a remote certify blocks"); a bundle with blocked rows does not certify (RFC 0168 §E.1). Anchor-grade: discovery-core witnessCount ≥ 1; openwop.requirement.0170.id-grammar.bare-id (new on 2.0.11) executed-pass on the overlap branch |
How to read the reference row (rc.58 measurement). Zero executed-fail, zero blocked: the host caught up with the rc.40–rc.53 prose on 2026-09-05 (the example's conformance.md lists each rule), and the suite fixed v2-era-2-append-vocabulary in rc.58, which had read events off the response object and could never witness the writer rule on any host. The 42 inapplicable rows are optional families the host does not advertise (a2a, mcp, saml, scim, packs), recorded with their reasons, plus the corpus-ledger row (inapplicable since rc.57). The paragraph below describes the rc.16 measurement and is kept for the history of the row.
What the 16 blocked rows were (rc.16). Optional families the host does not implement and therefore does not advertise (a2a, mcp, saml, scim), a rate limit no run provoked, a windowed revocation lane, an alias family, and the corpus ledger the published tarball does not ship. Each row states its reason; none is a silent skip. The row claims self evidence tier: the steward built the host, so it is not independent evidence about anyone else's implementation, and it certifies nothing.
Hosts
| Host | Use case | Repo / Path | Compatibility profile claim | Scale claim | Production profile claim | Conformance link |
|---|---|---|---|---|---|---|
| In-memory (reference example) | Local development / fastest boot / no persistence | examples/hosts/in-memory/ | openwop-discovery-core (canonical, RFC 0155 §A; advertised as its deprecated alias openwop-core) · openwop-fixtures — RFC 0146 contractProvenance advertised 2026-08-13 (openwop-examples#13), derived from the installed package's CORPUS-STAMP.json rather than a constant, so the value cannot drift from the contract the host actually resolves. This is the advertising half of 0146's Accepted gate. — corrected 2026-08-13: openwop-stream-sse, openwop-stream-poll, and openwop-node-packs were withdrawn (openwop-examples#12) because the host's own committed bundle lists their floor scenarios in results.failed. Both retained claims are discovery-payload-only, so neither says anything about runtime behavior (RFC 0155 §A) — Measured 2026-08-16 — bundle v2, suite 1.130.0 (openwop-examples#15, certification-bundle-v2.json): executed-pass 206 / fail 30 / inapplicable 119 / blocked 111; certified: openwop-discovery-core (+alias), openwop-fixtures; not certified: openwop-stream-sse, openwop-stream-poll (floor rows executed-fail — consistent with the withdrawal); openwop-node-packs not held (runtime-derived since 1.117.0, dropped from claimedProfiles). 0 zero-assertion passes (the 1.116.0 run's 107 are now inapplicable/blocked rows with reasons). Prior: suite 1.116.0 (openwop-examples#14) 311/30/77/43. | minimal | Not claimed | conformance.md |
| SQLite (reference example) | Single-machine durability / process-restart-safe | examples/hosts/sqlite/ | openwop-discovery-core (canonical, RFC 0155 §A; advertised as its deprecated alias openwop-core) · openwop-stream-sse · openwop-stream-poll · openwop-audit-log-integrity · openwop-interrupt-quorum · openwop-interrupt-auth-required · openwop-interrupt-external-event · openwop-interrupt-cascade-cancel · openwop-auth-api-key-rotation · openwop-discovery-auth-scoped — Measured 2026-08-16 — bundle v2, suite 1.130.0 (openwop-examples#15, certification-bundle-v2.json): executed-pass 214 / fail 0 / inapplicable 144 / blocked 108; certified: openwop-discovery-core (+alias), openwop-stream-sse, openwop-stream-poll, openwop-secrets (floor landed at 1.120.0), openwop-fixtures; openwop-node-packs not held (runtime-derived). 0 zero-assertion passes. Prior: suite 1.116.0 (openwop-examples#14) 340/0/78/43. The openwop-audit-log-integrity / openwop-auth-* / openwop-discovery-auth-scoped claims are annex profiles with no floor in PROFILE_FLOOR_SCENARIOS — --certify cannot evaluate them; they remain the host's self-declaration backed by its conformance.md, not a certification. (openwop-interrupts gained a floor at suite 1.120.0 and is simply not among this host's claimed profiles.) | minimal | Not claimed | conformance.md |
| Python in-memory (reference example) | Cross-language portability — Python 3.11 stdlib-only port | examples/hosts/python/ | openwop-discovery-core (canonical, RFC 0155 §A; advertised as its deprecated alias openwop-core) · openwop-stream-sse · openwop-stream-poll — Measured 2026-08-16 — bundle v2, suite 1.130.0 (openwop-examples#15, certification-bundle-v2.json): executed-pass 181 / fail 0 / inapplicable 149 / blocked 136; certified: openwop-discovery-core (+alias), openwop-stream-sse, openwop-stream-poll, openwop-fixtures; openwop-node-packs not held (runtime-derived). 0 zero-assertion passes. Prior: suite 1.116.0 (openwop-examples#14) 321/0/78/62. | minimal | Not claimed | conformance.md |
| Postgres (reference example) | Multi-process durability + first production-profile host | examples/hosts/postgres/ | openwop-discovery-core (canonical, RFC 0155 §A; advertised as its deprecated alias openwop-core) · openwop-stream-poll · openwop-stream-sse · openwop-audit-log-integrity · openwop-interrupt-quorum · openwop-interrupt-auth-required · openwop-interrupt-external-event · openwop-interrupt-cascade-cancel · openwop-production · openwop-auth-oauth2-client-credentials · openwop-auth-oidc-user-bearer · openwop-auth-mtls · openwop-auth-api-key-rotation · openwop-discovery-auth-scoped (auth profiles conditional on env) — Measured 2026-08-16 — bundle v2, suite 1.130.0, pglite-backed local boot (openwop-examples#15, certification-bundle-v2.json): executed-pass 230 / fail 2 (webhook-signed-delivery — delivery omits X-openwop-Webhook-Id, a host gap; route-coverage — passes alone, timing under the full run) / inapplicable 138 / blocked 96; certified: openwop-discovery-core (+alias), openwop-stream-sse, openwop-stream-poll, openwop-provider-policy, openwop-memory (both floors landed at 1.120.0), openwop-fixtures; openwop-node-packs not held (runtime-derived). 0 zero-assertion passes. Prior: suite 1.116.0 (openwop-examples#14) 353/2/74/32. | minimal | Claimed (since 2026-05-11) | conformance-full.md |
MyndHyve workflow-runtime (steward-affiliated sibling host — separate deployment, same maintainer org; not an independent-organization host, per the GOVERNANCE.md §"Acceptance evidence tiers" taxonomy this is tier-2 evidence) | Production agent-platform deployment whose live advertisements drove the RFC 0078–0094 Active → Accepted graduations. Full per-bundle measurement history is in the Update log; the detailed conformance-evidence narrative is in MyndHyve conformance evidence below. | Closed source; live discovery: https://api.myndhyve.ai/.well-known/openwop | openwop-discovery-core (canonical, RFC 0155 §A; its live profiles[] advertises the deprecated alias openwop-core) · openwop-interrupts · openwop-stream-sse · plus the operational-annex claims openwop-core-standard (RFC 0088) and openwop-agent-platform full (RFC 0085) in its live profiles[] — Bundle v2 #11 measured 2026-08-17 later (suite 1.136.0, deployed rev workflow-runtime-00555-xih = main 94296615d, agrade/openwop-followups + 12 PRs): executed-pass 289 / executed-fail 6 / blocked 97; certifiable: openwop-discovery-core, core, interrupts, stream-sse, stream-poll, secrets, provider-policy, openwop-replay-fork (NEW — replay-llm-cache-key + -portable via one openwop-semantic-request-v2 writer, replayDeterminism + replay-fork-arbitrary with the SOURCE run's durationMs/metrics on the fork, replay-observable-sequence-determinism on the seeded core.conformance.nondet-tool, replay-side-effect-suppression with sideEffectSuppression: "recorded-outcome" — Nth attempt → Nth recorded outcome, replay_source_missing fail-closed; getting there surfaced two host bugs the suite's 1.136.0 delay change exposed and the host fixed: a cancelled run kept executing after run.cancelled, and core.control.delay ignored inputs.delayMs), fixtures, trigger-bridge, openwop-core-standard. Not: openwop-memory (suite S41 — the seedRun helpers sent a fabricated tenantId this tenant-enforcing host rightly 403'd; fixed at 1.136.3) and openwop-agent-platform (suite S42 — no floor entry existed, so it could never be evaluated; fixed at 1.136.3); five of the six executed-fails were suite S38 (always-on legs reading spec/ outside the npm package; fixed at 1.136.3). Host notes for other adopters: API-key auth (bcrypt work-12 + a lastUsedAt write per request) was the per-request bottleneck under load (GET /v1/runs/{id} p50 1.8 s → 60 ms after a positive-match cache + throttled write); Cloud Tasks at maxDispatchesPerSecond 10 delivered run dispatches at exactly 1/s until raised. Bundle v2 #3 measured 2026-08-17 (see the caveat column; host PR myndhyve#202, merged dd194d522, serving rev 00528-vip built from the identical tree): openwop-core-standard certifiable on the deployed origin at suite 1.135.1; the openwop-agent-platform claim in its profiles[] is measured NOT certifiable (memory/replay rows) and stays a claim, as the emitter reports. | Not published | Not claimed | Per-RFC graduation evidence in the Updated fields of RFCS/0078–0094 + the CHANGELOG.md 1.1.7/1.1.8 graduation entries (RFC 0093/0094: revision 00476-xuv, suite 1.22.0, 2026-06-11) (gated scenarios pass non-vacuously under OPENWOP_REQUIRE_BEHAVIOR=true; steward-curl-verified; the steward independently re-derived the profile predicates from the public discovery document); also drove the token-economy Active → Accepted graduations of RFC 0112 / 0113 / 0115 (2026-06-27, suite 1.43.0, tier-2 revs 00511-len / 00512-pej / 00510-jiv, steward-curl-verified) — RFC 0114 + 0116 honestly opted out (headless runtime emits no a2ui surface; durable path runs no provider prompt-caching) |
SAML ⟷ SCIM subject linking — key class + same-IdP trust root (RFC 0159 + 0163 — capabilities.auth.subjectLinking / subjectLinkKey)
RFC 0163 graduated Active → Accepted on 2026-09-02 on tier-1 single-witness evidence per GOVERNANCE.md §"Acceptance evidence tiers" — the steward's own reference host, under the bootstrap waiver, exactly as RFC 0159 did on 2026-09-01. RFC 0164 (the contract becomes mandatory for any host advertising both profiles; subjectLinking is derived) graduated the same way on 2026-09-02 — openwop-app #3620 (873efc466, ADR 0623). Not dual-witness, not independent-organization evidence.
The claim is narrow: a host that advertises both openwop-auth-saml and openwop-auth-scim and sets subjectLinking: true MUST also name the class it joins the two lanes on (subjectLinkKey ∈ {opaque-idp, configured-immutable}, schema-required by conditional), MUST join only on that class, and MUST NOT form a link unless the SAML assertion's signed <saml:Issuer> equals the IdP entityID bound to the SCIM connection. No production host advertises subjectLinking — openwop-app emits it only when both seams are configured, MyndHyve's live discovery carries no auth block — so this row records a seam-witnessed implementation, not a production advertisement.
| Host | Status | Evidence |
|---|---|---|
| openwop-app (tier-1 reference) | witnessed in-process — 2026-09-02, openwop-app #3614 (2f6ca969d), ADR 0620 | In-process witnesses on the reference host: test/auth-subject-link.test.ts (two synthetic IdPs with distinct signed issuers — advertisement subjectLinkKey === 'opaque-idp'; same-root provision + assertion authenticates as the positive control; cross-root collision refused 401 subject_link_trust_root_mismatch; the RFC 0159 legs — SCIM-deactivate ⇒ SAML denied, mutable-key hygiene — stay green), test/auth-saml-sso-trust-root.test.ts (production ACS: same-root mints a session, cross-root refuses with no cookie) and test/auth-saml.test.ts (signed <saml:Issuer> in the canonical + principal.issuer surfaced). npm run ci: backend 470 files / 3013 tests, 0 failed. The SSRF widening was sabotage-verified: with the trust-root refusal reverted the cross-root leg returns 200 authenticated:true and the assertion fails, so the refusal — not the 403 — is load-bearing. The class is opaque-idp (SCIM externalId == persistent SAML NameID), emitted from the same gate as subjectLinking so the two cannot drift. The same-trust-root compare runs before the link consult on both the validate seam and the production ACS. The seam's SSRF allowlist was widened to the second synthetic IdP first, so the cross-IdP negative is refused on trust root, not on origin — a 403 with no authenticated field would have satisfied the scenario's !== true for the wrong reason. Invariants subject-link-leaver-deny, subject-link-key-class-declared, subject-link-same-trust-root. RFC 0164 (2026-09-02, openwop-app #3620, 873efc466, ADR 0623): advertises both profiles only when its SAML/SCIM realms are aligned and a SCIM trust-root seat is configured, otherwise narrows to openwop-auth-saml; both advertised ⇒ subjectLinking: true + subjectLinkKey from one gate; an unbound record in a combined deployment is refused on the SAML lane. auth-subject-link-alignment.test.ts (5 legs: misaligned realms + seat ⇒ openwop-auth-scim dropped; aligned + no seat ⇒ dropped; aligned + seat ⇒ both profiles + subjectLinking: true + subjectLinkKey; aligned + seat + unbound ⇒ SAML 401 subject_link_unbound; single-profile + unbound ⇒ RFC 0159 deny-only survives) plus saml_assertion_unbound_refused in auth-subject-link.test.ts; two sabotage reverts confirmed load-bearing (revert the SCIM drop ⇒ alignment leg reds 1/4; revert the unbound refusal ⇒ fail-closed leg reds 1/14); tsc --noEmit clean, auth suites 25/25, npm run ci green (5034 tests, 0 failed); the witness was re-verified by the adopting session after the implementing agent stalled, not inherited |
MyndHyve workflow-runtime (tier-2 sibling) | openwop-auth-saml only (since myndhyve/myndhyve#238, 2026-09-03) | Erratum recorded 2026-09-03: the earlier "no auth block" reading of this row was wrong — the live discovery advertised BOTH openwop-auth-saml and openwop-auth-scim with no subjectLinking, the exact shape RFC 0164 forbids, from RFC 0050's graduation until the RFC 0165 leg (myndhyve/myndhyve#238, 8a972d193) narrowed it to SAML only (the host cannot link: no <saml:Issuer> parse, no SCIM trust root). RFC 0164 §Motivation + register G1 carry the correction. No second witness for RFC 0163/0164. |
RFC 0165 — v2 preparation wire shapes (protocolVersions[], owner.subject, OpenWOP-* dual emission, discovery ETag)
Graduated Active → Accepted on 2026-09-03 on tier-1 + tier-2 evidence (both steward-owned hosts; not independent-organization evidence). What each host does, and what the suite can witness against it:
| Host | Advertises / emits | Evidence |
|---|---|---|
| openwop-app (tier-1 reference) | protocolVersions: [protocolVersion]; owner.subject persisted at run creation for the SAML / SCIM / OIDC / API-key lanes and synthesized with issuer: "urn:openwop:legacy" for pre-subject runs; run.started echoes the owner block; :fork copies tenant + subject + principal; OpenWOP- headers beside X-openwop-; standard ETag + 304 on /.well-known/openwop | openwop-app #3631 (2578e025c), ADR 0625; suite 1.156.0 protocol-versions-array, owner-subject-shape, owner-subject-echo, identity-owner-shape, discovery ETag leg, webhook dual-emission legs |
MyndHyve workflow-runtime (tier-2 sibling) | protocolVersions: ["1.0"]; RunDoc.subject minted from the Firebase-OIDC / API-key / service lanes (subjectId is the same 16-hex projection as owner.principal, so §B.2 holds by construction), legacy synthesis on reads of older runs; run.started echoes the owner block; :fork copies initiatedBy + subject; OpenWOP-* headers; discovery ETag + 304; auth.profiles narrowed to openwop-auth-saml (RFC 0164 erratum remediation) | myndhyve/myndhyve#238 (8a972d193); suite pin 1.156.0; in-process witnesses discovery.test.ts, canonicalRunsRead.test.ts, forkConformance.test.ts, durableDelivery.conformance.test.ts |
Neither host mints keyClass on a run today (openwop-app only when both identity profiles are advertised under the RFC 0164 gate); neither emits actor. The §B.3 legacy-link negative remains blocked in the suite (RFC 0165 G4) until a host wires a seam that mints a legacy-issuer subject bound to a SCIM record. | In-memory / SQLite / Postgres / Python (reference examples) | Not applicable | None advertises openwop-auth-saml or openwop-auth-scim. |
Replay side-effect suppression (RFC 0140 — capabilities.replay.sideEffectSuppression)
RFC 0140 graduated Active → Accepted on 2026-08-08 on tier-1 single-witness evidence per GOVERNANCE.md §"Acceptance evidence tiers" — the steward's own reference host, under the bootstrap waiver. Not dual-witness, and not independent-organization evidence.
The claim being advertised is narrow and worth stating precisely: recorded-outcome says a mode: "replay" fork resolves a side-effecting node from the source run's recorded outcome or fails it closed with replay_source_missing — never a new effect — and that a default-deny guard sits at the host's effect seams behind the classifier. spec/v1/replay.md §"Determinism guarantees" caveat 1 binds every host regardless; hosts that omit the capability are not thereby permitted to re-fire, they simply do not expose a probeable mechanism.
| Host | Status | Evidence |
|---|---|---|
| openwop-app (tier-1 reference) | Advertises replay.sideEffectSuppression: "recorded-outcome" | a3531892 (ADR 0326 P3b + ADR 0341 classification, ADR 0531 run-scoped fail-closed guard, ADR 0533 seam widening). replay-side-effect-suppression.test.ts passes non-vacuously against suite 1.65.0 under OPENWOP_REQUIRE_BEHAVIOR=true: source effectCount: 1, replay effectCount: 0 reproducing the recorded output, cancelled-source replay node.failed replay_source_missing with effectCount: 0. Eight per-fix sabotages recorded in RFC 0140 §"Acceptance witness". 2026-08-18, deploy #7 (4c10c3a8eb42): the advertised value is none, and that is WITHHELD WITH A REASON rather than a capability gap. The host operator states it explicitly: H72 (the fan-out rule above) discharges "do not perform", while this advert asserts "resolve the recorded outcome" — a separate obligation. ADR 0572 P3 moved their undischarged-class ratchet 214 → 43, and those 43 classes can still throw where the advert would promise reproduction, so restoring the value on the strength of the ratchet number alone would be a false wire claim. Recorded here as the honest non-claim it is. |
MyndHyve workflow-runtime (tier-2 sibling) | Not advertised | No second witness. Carried forward — a tier-2 or tier-3 witness would strengthen this row but is not required under the bootstrap single-witness waiver. |
| In-memory / SQLite / Postgres / Python (reference examples) | Not advertised | These hosts implement no external side effects to suppress; omitting the capability is the honest advertisement. |
Host-initiated fan-out on a replay fork (replay.md §"Host-initiated fan-out is an external effect")
The rule landed 2026-08-18: a host that projects its event log outward — webhook delivery, outbound streams, analytics sinks — MUST NOT emit those deliveries for events a mode: "replay" fork re-emits as fixed history. It is unconditional and not gated on sideEffectSuppression, which describes what a host does with node effects. Replay-ness MUST be read from the run, never from the event type.
| Host | Status | Evidence |
|---|---|---|
| openwop-app (tier-1 reference) | SUITE-WITNESSED under an operator opt-in — 2026-08-19, replay-fanout-suppression.test.ts; deployed-wire 4c10c3a8eb42, deploy #7, 2026-08-18 | Suppression at the delivery boundary in routes/webhooks.ts, keyed on the RUN (run.forkMode === 'replay'), not on the event type — the property that keeps it a one-line predicate on a record the delivery path already loads, and stops an effect-type list rotting as kinds are added. Deliberately not routed through the effect guard: a throw inside a swallowed best-effort subscriber would suppress silently, the fail-open shape that module exists to remove (ADR 0533's second objection, which survived its first). Four legs including a positive control (the original run MUST still deliver) and a branch leg (branch is by design NOT suppressed). Before this deploy, production delivered webhooks to third parties asserting work a replay fork never performed. Now witnessed by the suite, in both directions: on a default host the scenario records blocked in 41 ms — the SSRF guard refuses the loopback receiver, which is correct — and with OPENWOP_WEBHOOK_ALLOW_PRIVATE=true it passes in 7.6 s, then goes red with expected [ Array(1) ] to deeply equal [] when the host's forkMode === 'replay' suppression is deleted. The third row is the one that makes the first two mean anything: a negative assertion that has never been shown to fail is not evidence. The 41 ms was itself the tell — the scenario carries a 1.5 s grace plus a 6 s quiet window, so a green under ~7.5 s is arithmetically impossible for a run that happened; where a scenario has a floor on its own runtime, wall-clock is a free vacuity check. The witness depends on an operator opt-in, disclosed in SECURITY/threat-model-replay.md §4 as a property of the evidence rather than a footnote. Narrowed 2026-08-25: more precisely, it depends on a particular layer-reading of that opt-in — this host honors OPENWOP_WEBHOOK_ALLOW_PRIVATE at both the registration and delivery layers, and only the registration half is what lets the loopback receiver be registered at all. A host honoring the same flag at delivery only cannot reach this scenario's assertions, and one was observed doing exactly that. So "witnessed under an operator opt-in" was true but wider than the evidence: the dependency is not that an opt-in exists, it is which layer it reaches. webhooks.md mandates the guard at both layers independently, so the both-layers reading is the one the contract implies (conformance/README.md §"Operator flags"); the narrowing is to the claim, not to the evidence, which is unchanged. |
MyndHyve workflow-runtime (tier-2 sibling) | Deployed 2026-08-18 (#224 on workflow-runtime-00572-noc) — blocked: unobservable, not unmet | Found the hole in its own tree first — onAppend fanning every appended event into the webhook dispatcher with no fork-awareness anywhere on the path — and reported that it generalizes to any host projecting its event log outward. That report is what made the rule normative. The fix now serves on the revision bundle v2 #15 was measured against, but no conformance scenario exists for this rule, so neither host's implementation is witnessed by the suite: both rows rest on the hosts' own tests. The scenario now exists (replay-fanout-suppression.test.ts, suite 1.137.0) and this host still cannot be its witness: its POST /v1/webhooks rejects the suite's loopback receiver on two independent grounds returning the same code — the SSRF predicate and a protocol !== 'https:' check, the second of which is a spec MUST no bypass should touch. The host measured this itself and declined the opt-in on the ground that it would not have produced the witness it was being traded for, which is a stronger reason than reluctance. It also corrected, in its own disfavour, a containment premise the steward had offered: conformance flags already serve at 100% on 00572-noc, so a tagged-revision promise would have been contradicted by every sibling flag. blocked here means unobservable, not unmet — see SECURITY/threat-model-replay.md §4. |
| In-memory / SQLite / Postgres / Python (reference examples) | Not applicable | No outbound fan-out to suppress. |
Why two hosts is the interesting number here. MyndHyve found it by inspection of its own delivery path; openwop-app then found the identical hole — as a written, reasoned exemption (ADR 0533 recorded the seam as a deliberate residual, on the stated ground that "a replay is a distinct run whose events are genuinely new", which the new section negates). A gap found in two trees is a coincidence; a gap found in a third where the question had been explicitly asked and answered wrong is the case for a normative rule.
What this row does not claim. The conformance scenario does not independently witness the seam guard — classification and the guard mask each other in the fixture, so disabling either alone leaves the scenario green (RFC 0140 gap G8); the guard's evidence is host-side. Three node-reachable effect paths remain unguarded in openwop-app (gap G9: webhook fan-out, s3Blob.put, openSearchSearch), the first deliberately, since it is host-level fan-out with no node to fail closed. Out-of-process pack execution is uncovered — AsyncLocalStorage does not cross a worker boundary. branch-mode forks re-fire effects by design (§D).
Poison work terminates within a bounded number of attempts (RFC 0158 §C.8 — durability/poison-exhaustion)
RFC 0158 is Draft. This row records evidence for one requirement, not a rung: the RFC's ladder mints no advertised capability (§E.10 — rung and recovery bound are published in the evidence bundle), so nothing here is a claim a host advertises. Of the RFC's six conformance rows this is the only one causable without terminating a process — the other five need a host seam, a supervisor, or ≥2 instances, and none exists yet. Seam-gated on the existing /v1/host/sample/test/runs/{runId}/events log seam and outside every profile floor.
| Host | Status | Evidence |
|---|---|---|
| openwop-app (tier-1 reference) | witnessed + sabotage-verified — 2026-08-19, suite 1.138.0 | PASS in 4030 ms on a clean host, and RED — expected 2 to be 1 — against a host patched to emit one attempt after run.failed. The red is the point: the stability leg fires on exactly the behaviour failure-path.test.ts cannot see, because a host that reports terminal and keeps re-dispatching also reports terminal. The host additionally checked the scenario's own blind spot and reported a clean negative rather than a reassurance: node.started has exactly one emission site, unconditional at the top of node execution with no served-from-log bypass, so on this host every re-dispatch is counted — "a fact about this host's structure, not about hosts", which is why the scenario keeps counting both event types. |
| Postgres / SQLite / In-memory / Python (reference examples) | blocked — unobservable, not unmet | The reference hosts advertise no conformance-failure fixture, so this scenario and failure-path.test.ts both skip against them in CI. The reference host cannot witness §C.8 at all — found by reading a CI log rather than by any failure. |
MyndHyve workflow-runtime (tier-2 sibling) | Not measured | Candidate: needs the fixture advertised and the event-log seam wired; no opt-in and no process kill required. |
Agent Platform profile (RFC 0085 — openwop-agent-platform)
The aggregate platform profile defined in spec/v1/agent-platform-profile.md (RFC 0085, Accepted 2026-06-01). A host populates the status column when it reaches partial/full. MyndHyve — the steward-affiliated sibling host whose graduation evidence accepted the RFC — derives full; no example reference host claims it yet (honest).
| Host | openwop-agent-platform status | Notes |
|---|---|---|
MyndHyve workflow-runtime | full | Advertises the profile in its live profiles[]; the steward independently re-derived isAgentPlatformFull from the public discovery doc (all 16 §B terms) and the aggregate-evidence scenario passes non-vacuously at tier full — see RFC 0085's Updated field. Steward-affiliated sibling host (same maintainer org). |
| In-memory | none | Advertises feedback + several floor constituents, not the full floor set. |
| SQLite | none | — |
| Python | none | — |
| Postgres | none (candidate) | Already production-profile-satisfying and advertises memory / authorization / httpClient — the natural first partial/full candidate. |
Connection packs (RFC 0095 — capabilities.connections.packsSupported)
The portable provider-definition pack kind defined in spec/v1/connection-packs.md (RFC 0095, Accepted 2026-06-12). A host populates the status column when it advertises connections.packsSupported: true and implements the §Manifest clause 6 resolution contract; verification is the two capability-gated behavioral scenarios (connection-provider-resolution + connection-pack-write-reconsent) run non-vacuously against the published suite.
| Host | connections.packsSupported status | Notes |
|---|---|---|
| openwop-app reference | live + strict-verified | §B.6 loader-path resolution (openwop-app#178) + §10 test seams (#194) deployed rev 00160-kjq; connections.packsSupported advertised live (steward curl-verified on the direct run.app URL; seams correctly 404 in production). All five 1.23.0 scenarios pass NON-VACUOUSLY (OPENWOP_REQUIRE_BEHAVIOR=true) against a seam-enabled instance at the deployed code. |
MyndHyve workflow-runtime | live + strict-verified | §B.6 publish-path resolution (myndhyve#167/#168) + §10 seams (#169) serving on api.myndhyve.ai (revision workflow-runtime-00268-x9l); connections.packsSupported advertised live (steward curl-verified). All five 1.23.0 scenarios pass NON-VACUOUSLY (OPENWOP_REQUIRE_BEHAVIOR=true) over the live seams — the RFC 0095 Active → Accepted non-steward evidence. |
| In-memory | none | — |
| SQLite | none | — |
| Python | none | — |
| Postgres | none | — |
Multi-party group conversation (RFC 0101 — capabilities.multiPartyConversation)
The shared-transcript / speaker-attribution surface defined in RFC 0101 (Accepted 2026-06-22). A host populates the status column when it advertises multiPartyConversation.supported: true, emits the optional participants: AgentRef[] on conversation.opened, stamps speakerId on role:'agent' turns, and rejects a turn from a non-participant. The always-on leg of multi-party-conversation-shape.test.ts verifies the schema shapes server-free; the capability-gated behavioral leg (isMultiPartyConversationSupported()) verifies live roster + attribution + non-participant rejection against an advertising host.
| Host | multiPartyConversation status | Notes |
|---|---|---|
| openwop-app reference | advertised live — steward-curl-verified (rev 00291-l8v) | First advertising host (Board of Advisors councils, ADR 0040 Phase 6). multiPartyConversation { supported:true, maxParticipants:8 } advertised on the live discovery doc — steward-curl-verified 2026-06-22 on the deployed Cloud Run revision openwop-app-backend-00291-l8v (curl https://app.openwop.dev/api/.well-known/openwop → supported:true, maxParticipants:8). Host emits the participants roster on conversation.opened, stamps the advisor-instance speakerId on every agent turn, and rejects a non-participant turn (422) — host-side enforcement covered by multi-party-conversation.test.ts (openwop-app#666); the always-on conformance shape leg passes. Remaining for full strict-verified: a non-vacuous behavioral conformance scenario — deferred at the suite level (a multi-party council is not a standard-wire-triggerable flow, so it can't be driven host-agnostically yet; the same Active → Accepted staging RFC 0086 used for its behavioral leg). |
MyndHyve workflow-runtime | none | — |
| In-memory | none | — |
| SQLite | none | — |
| Python | none | — |
| Postgres | none | — |
Localized content surface (RFC 0103 — capabilities.content.supported)
The capability-gated authored-content surface defined in spec/v1/localized-content.md (RFC 0103, Accepted 2026-06-17). A host populates the status column when it advertises content.supported: true (requires i18n.supported) and serves GET /v1/content/pages/{slug} with the §C resolveSection merge; the always-on legs of localized-content-delivery.test.ts verify the schemas + merge + capability coherence server-free, and the gated legs verify live delivery + tenant isolation.
| Host | content.supported status | Notes |
|---|---|---|
| openwop-app reference | live + non-vacuous | HOST-1 i18n.md annex (Accept-Language/Content-Language/capabilities.i18n) + HOST-2 content surface (content/resolve.ts resolveSection, /v1/content/*, SQLite/Postgres-backed, §F tenant-scoped); content { baseLocale:'en', supportedLocales:['es','pt-BR','fr'] } advertised on prod rev 00234-mg8 (app.openwop.dev, steward-curl-verified; main 999bfd0f, PR #412 / ADR 0064). Ran localized-content-delivery 18/18 NON-VACUOUSLY (incl. the live §A-coherence leg) — the second non-steward witness, closing the RFC 0103 content dual-witness bar. |
MyndHyve workflow-runtime | live + non-vacuous | Layer 1 (annex) + Layer 2 (content/resolveSection.ts + /v1/content/* over the Firestore CMS, credential-derived tenant per §F); content { baseLocale:'en', supportedLocales:['es','pt-BR','fr'] } advertised at doc root on prod rev 00273-6rf (api.myndhyve.ai, steward-curl-verified). Ran localized-content-delivery 18/18 NON-VACUOUSLY (incl. the live §A-coherence leg) + i18n-negotiation 4/4 — the Active → Accepted non-steward witness leg. |
| In-memory | none | — |
| SQLite | none | — |
| Python | none | — |
| Postgres | none | — |
Multi-turn conversation primitive (RFC 0005 — capabilities.conversationPrimitive)
The multi-turn conversation suspend variant defined in RFC 0005 (Accepted 2026-05-11), wiring the core.conversationGate typeId + the conversation.start / conversation.exchange / conversation.close suspend variants (normative surface in spec/v1/interrupt.md + spec/v1/capabilities.md). A host populates the status column when it advertises conversationPrimitive: true and takes the conversation path over the clarification.requested fallback; verification is the capability-gated conversationLifecycle / conversationReplayDeterminism / conversationVsLegacySuspend scenarios run non-vacuously, with conversationCapabilityNegotiation covering the negative refusal contract on hosts that do not advertise.
| Host | conversationPrimitive status | Notes |
|---|---|---|
| openwop-app reference | live + non-vacuous | ADR 0067 Phase-6 cutover: chat suspends ONLY via core.conversationGate (the per-turn fallback is retired). conversationPrimitive: true + the conversation.start/conversation.exchange/conversation.close interrupt kinds advertised at the discovery root on prod rev openwop-app-backend-00265-wtx (steward-curl-verified on the direct run.app URL; discovery-doc SHA-256 d098c9c4…c89f4c114). Ran the three positive scenarios — conversationLifecycle, conversationReplayDeterminism (incl. the §G replay/:fork byte-equal leg), conversationVsLegacySuspend — 3/3 NON-VACUOUSLY (OPENWOP_REQUIRE_BEHAVIOR=true) against suite 1.29.0 at the deployed code, 2026-06-21. conversationCapabilityNegotiation is correctly inapplicable here — it is the inverted gate, running only when the primitive is unadvertised. |
MyndHyve workflow-runtime | live + non-vacuous | conversationPrimitive: true advertised at the discovery root (+ a capabilities mirror) on prod rev workflow-runtime-00281-j8f (counter-reset by an unrelated stale-YAML rollback recovered same-day; serving code is current main) — api.myndhyve.ai, steward-curl-verified, discovery-doc SHA-256 d7d7ed32…18cd528. Ran the three positive scenarios — conversationLifecycle, conversationReplayDeterminism (the :fork returned 201, so the §G byte-equal leg ran), conversationVsLegacySuspend — 3/3 NON-VACUOUSLY (OPENWOP_REQUIRE_BEHAVIOR=true, serial) against suite 1.29.0, 2026-06-21; conversationCapabilityNegotiation correctly skipped (inverted gate). The conversation. suspend variants are proven on the wire by conversationVsLegacySuspend (emits conversation., zero clarification.*), not discovery-enumerated — MyndHyve ships no interrupts.kinds array. The second non-steward witness, closing the RFC 0005 dual-witness bar. |
| In-memory | none | — |
| SQLite | none | Wires only the negative refusal contract (GATED_TYPEID_MAP → core.conversationGate refused when referenced); deliberately does not advertise the primitive. |
| Python | none | Does not claim conversationPrimitive; the refusal contract is unwired (conformance.md). |
| Postgres | none | — |
Self-hosted / OpenAI-compatible provider class (RFC 0108 — aiProviders.selfHosted[])
The operator-/tenant-configured OpenAI-compatible endpoint class defined in spec/v1/capabilities.md §aiProviders.selfHosted (RFC 0108, Active 2026-06-24). A host populates the status column when it advertises aiProviders.selfHosted: string[] (a subset of supported[]) for a configured, reachable endpoint — honestly (§A.2, under OPENWOP_REQUIRE_BEHAVIOR), with an opaque non-URL id (§A.3), keeping the endpoint location off every wire surface (self-hosted-endpoint-no-disclosure). The always-on aiproviders-selfhosted-shape.test.ts verifies the §A field shape + the §A.1 subset / §A.3 no-URL rules server-free; the gated aiproviders-selfhosted-honesty.test.ts (lands at Active → Accepted) verifies a real dispatch against a selfHosted id with no endpoint-URL leak.
| Host | aiProviders.selfHosted status | Notes |
|---|---|---|
| openwop-app reference | harness-witnessed (non-vacuous) | ADR 0121 (PR #725 merged): compat dispatch case + per-connection base-URL Connection (ADR 0024) + modelCapabilityProbe (§B). Advertises aiProviders { supported:[…,"compat"], selfHosted:["compat"] } and passes aiproviders-selfhosted-shape + aiproviders-selfhosted-honesty non-vacuously under OPENWOP_REQUIRE_BEHAVIOR=true vs conformance 1.37.0 — the honesty leg dispatches against compat, reaches a real loopback OpenAI-compatible endpoint (HTTP 200, not capability_not_provided → §A.2 honest), the id is non-URL (§A.3), and the endpoint location leaks into no response/error payload (§D). Witness = the host's conformance harness (conformance/run.ts stands up the real mock + sets OPENWOP_TEST_COMPAT_ENDPOINT), production-dark (OPENWOP_COMPAT_PROVIDER_ENABLED unset ⇒ selfHosted:[]) — the appropriate evidence tier for an operator-private surface §D says MUST NOT be publicly exposed (mirrors the RFC 0035 harness-graduation precedent; no deployed public discovery doc by design). Steward-verified by code-inspecting the honesty-gated emission + the real-mock setup. The RFC 0108 Active → Accepted single-witness close under the bootstrap steward waiver (2026-06-24). |
MyndHyve workflow-runtime | none | — |
| In-memory | none | — |
| SQLite | none | — |
| Python | none | — |
| Postgres | none | — |
Parallel sub-workflow fan-out and join (RFC 0118 — capabilities.dispatch.fanOutSupported)
RFC 0118 graduated Active → Accepted on 2026-06-28. Both legs are now dual-witness and steward-verified (2026-06-28): the discovery/advertisement leg by /.well-known/openwop curl of each host, and the behavioral leg by a direct steward probe of each host's seam-enabled POST /v1/host/sample/dispatch/fanout returning a real, non-vacuous coordinator+fold. (At the original flip the behavioral leg was single-witness host-self-reported with a steward cross-check deferred; the deferred cross-check was subsequently run once both hosts stood up auth-exempt conf-fanout seam revisions — see the rows below. The full @openwop/openwop-conformance harness against openwop-app's tag URL tripped that host's per-IP 429 read budget during its multi-file discovery burst and soft-skipped the gated legs, so the direct seam probe is the steward behavioral artifact, alongside each host's own harness runs.) Per GOVERNANCE.md §"Acceptance evidence tiers" this remains a tier-2 (steward-affiliated sibling) + reference-host graduation — not independent-organization dual-witness.
| Host | Status | Evidence |
|---|---|---|
| openwop-app reference | discovery + behavioral both live + non-vacuous (steward-verified) | Discovery: prod app.openwop.dev/api advertises dispatch { supported:true, fanOutSupported:true, fanOutPolicies:["sequential","reject","parallel"], joinModes:["wait-all"], onChildFailureModes:["collect","absorb"], maxFanOut:16 } — steward-curl-verified 2026-06-28 (HTTP 200). Honest narrower advertisement: joinModes is ["wait-all"]-only and fail-fast is omitted from onChildFailureModes because the host cannot cancel in-flight siblings honestly (host/dispatchFanOut.ts, ENG-9). Behavioral: the /v1/host/sample/dispatch/fanout seam stays dark in prod by posture (OPENWOP_TEST_SEAM_ENABLED off, RFC 0117 parity), but the host stood up an auth-exempt seam-enabled tag revision 00355-zag (--no-traffic --tag conf-fanout, same image as prod 00348-mzh, code main@c2abc784 / #997). Steward direct probe 2026-06-28 (wait-all/collect ×3) → { joinOutcome:"satisfied", children:[3×completed], mergeOrder:[3], completedCount:3, failedCount:0, cancelledCount:0 } — real coordinator+fold, non-vacuous (no auth header). The always-on dispatch-fanout-parallel schema legs also pass server-free. |
MyndHyve workflow-runtime | discovery + behavioral both live + non-vacuous (steward-verified) | Tier-2 steward-affiliated sibling. Seam-enabled conformance revision 00513-qib (--no-traffic --tag conf-fanout from main@66fc108e with OPENWOP_CONFORMANCE_FIXTURES=1; prod traffic untouched on 00508-qis). Discovery: GET /.well-known/openwop advertises the full dispatch { fanOutSupported:true, fanOutPolicies:["sequential","reject","parallel"], joinModes:["wait-all","quorum","first","race"], onChildFailureModes:["collect","fail-fast","absorb"], maxFanOut:16 } — steward-curl-verified 2026-06-28 (HTTP 200). Behavioral: steward direct probe 2026-06-28 of the auth-exempt seam (wait-all/collect ×3) → { joinOutcome:"satisfied", children:[3×completed], mergeOrder:[3], completedCount:3, failedCount:0, cancelledCount:0 } — non-vacuous; corroborated by the host's own @openwop/openwop-conformance@1.45.0 … --filter dispatch-fanout → dispatch-fanout-parallel.test.ts 10/10 exit 0 (OPENWOP_REQUIRE_BEHAVIOR=true). |
| In-memory | none | — |
| SQLite | none | — |
| Python | none | — |
| Postgres | none | — |
The joinModes / onChildFailureModes divergence between the two witnesses (["wait-all"] + ["collect","absorb"] vs the full four-mode + three-mode sets) is the intended, discoverable outcome of the capability gating — a portable workflow pinning joinPolicy.mode:'quorum' or onChildFailure:'fail-fast' registers on MyndHyve and is honestly rejected at registration on openwop-app, and the author can see exactly that from each host's /.well-known/openwop at edit time (the gap RFC 0118's joinModes + openwop#789's onChildFailureModes descriptors close).
Subscription-reuse provider auth mode (RFC 0121 — aiProviders.authModes: "subscription")
The subscription auth mode defined in spec/v1/capabilities.md §aiProviders.authModes (RFC 0121, Active 2026-07-01; conformance 1.47.0). A host advertises subscription when it accepts a credential derived from reusing the caller's personal consumer subscription (Claude Pro/Max, ChatGPT Plus) — the mode is a BYOK path (§B.7, MUST be in byok), its credential MUST bind at host.credentials scope:"user" and MUST reject a tenant/workspace binding with credential_scope_forbidden (§B.8, the protocol-tier subscription-credential-user-scope-only invariant), and it MUST be advertised only when a real acquisition mechanism is configured (§B.9, truthful-advertisement). The always-on aiproviders-subscription-scope.test.ts verifies the enum shape server-free; the §B.7 leg is advertisement-gated; the §B.8 leg is bind-seam-gated (POST /v1/host/sample/credentials/bind, soft-skip on 404) so the user-scope safety rail is witnessable without a live subscription advertisement.
Partial graduation (2026-07-01): scope-safety rail only; 0121 stays Active. UQ1 (does any provider's consumer ToS permit third-party API-shaped reuse?) is UNRESOLVED — no citation exists; the steward issued an at-own-risk waiver (RFC 0121 Status history) of the acquisition-bearing gate. No host advertises subscription on a live discovery doc — the reference host is the scope-safety / reference-impl witness, not a full-advertisement witness. A full Active → Accepted graduation remains open, pending a deploy-model-compatible + UQ1-cleared advertising host (candidate: MyndHyve tier-2, per steward direction).
| Host | aiProviders.authModes: subscription status | Notes |
|---|---|---|
| openwop-app reference | §B.8 request-scope REJECTION rail steward-curl-verified on the wire; storage-resolvability half host-test-covered (openwop-app#1444); advertisement dark by design | Scope of the wire witness (precise): §B.8 has TWO clauses — (a) a subscription credential MUST bind at scope:"user", and (b) it MUST NOT be resolvable at tenant/workspace scope (a STORAGE property, not just the request field). The steward-curl-verified legs prove clause (a)'s request-scope rejection only. The bind seam is served under /api/** (POST /v1/host/openwop-app/credentials/bind, + /v1/host/sample/ alias; assertSubscriptionScopeAllowed in byok/subscriptionCredentialScope.ts, called unconditionally before any consent/acquisition). Steward-curl-verified 2026-07-07 on app.openwop.dev/api (unauthed): {provider,mode:"subscription",scope:"tenant"} → 403 credential_scope_forbidden; scope:"workspace" → 403 same; scope:"user" → 200 {bound:true,scope:"user"}; mode:"api_key" → 400 (seam binds subscription only, so the 403s aren't a blanket tenant block). Clause (b) — storage-resolvability — is black-box-invisible on the wire and was host-buggy until openwop-app#1444: the accepted scope:"user" credential was written at req.tenantId = the active* workspace (may be a shared ws: tenant, ADR 0015), so a user acting inside a shared workspace passed the request-scope rail yet had their personal token stored at a workspace-shared row → resolvable at workspace scope. Fixed in #1444 (store at the caller's own user:-scoped personal tenant personalTenantOf + fail-closed assertSubscriptionStorageTenant; host-test-covered: user:→ok, ws:→403, anon/default/undefined→403). Clause (b) is inherently host-test territory — see docs/KNOWN-LIMITS.md §"Behavior tests too coarse". Host unit tests subscriptionCredentialScope.test.ts (#1439) + the #1444 storage-tenant test + the pinned conformance aiproviders-subscription-scope.test.ts §B.8 request-scope leg. Discovery dark by default (no subscription authMode emitted — §B.9), acquisition mechanism-only (drift-guard test asserts no login code). Evidence tier = steward wire witness of the §B.8 request-scope rejection rail (advert UQ1-gated + dark; storage half host-test-covered). |
MyndHyve workflow-runtime | none | Candidate full-advertisement witness (tier-2) if/when an at-own-risk advertising path is stood up; not yet advertised. |
| In-memory | none | — |
| SQLite | none | — |
| Python | none | — |
| Postgres | none | — |
Anonymous-actor authorization (RFC 0132 — capabilities.anonymousActor)
The anonymous-actor model defined in spec/v1/capabilities.md §anonymousActor + spec/v1/auth.md §"Anonymous actors" (RFC 0132, Active 2026-07-22). A host advertises anonymousActor { supported:true, tiers, writeEgressControls?, failClosed:true } when it honors authorization for a caller on a public agent surface who authenticated no identity: an opaque, origin-bound, ephemeral, non-cross-linkable, non-PII principal (owner.principalKind:"anonymous") whose authority is a default-deny, explicit per-surface tool grant — never a role, never the ADR 0315-style default-on tool baseline. The read tier is tenant-scoped with no egress and no secret/BYOK reach; the bounded-write-egress tier is permitted only behind a mandatory HITL/approval (RFC 0051) or rate-limit + per-session cap, over the RFC 0076/0079 SSRF-guarded, audience-bound egress path. Every anon tool call audits via the existing RFC 0049 authorization.decided event (no new event type). The always-on anonymous-actor-shape.test.ts verifies the advert shape + the §B.2 conditional + owner.principalKind + the audit reuse server-free; the five gated behavioral scenarios (anonymous-actor-default-deny, -no-secret-reach, -egress-guarded, -write-gated, -audit-opaque) drive the POST /v1/host/sample/anon-surface/dispatch + GET /v1/host/sample/anon-surface/tools seam and soft-skip until a host wires a tool-enabled public surface.
Graduated Active → Accepted 2026-07-22 on the openwop-app tier-1 reference witness. The five SECURITY invariants landed at reference-impl tier at Active and GRADUATED to protocol tier at Active → Accepted once openwop-app wired the surface and passed all five behavioral scenarios non-vacuously under OPENWOP_REQUIRE_BEHAVIOR=true (RFC 0079 egress-credential-audience-bound precedent). The host ships the surface gated behind OPENWOP_ANON_ACTOR_ENABLED (default OFF) — honest-off, not advertised on the live production discovery doc until an operator opts in.
| Host | capabilities.anonymousActor status | Evidence |
|---|---|---|
| openwop-app reference | discovery + behavioral non-vacuous (tier-1 reference witness; gated OFF by default) | PR openwop-app#2403 merged, rev 03d06d1f2. host/anonymousActor.ts mints the opaque origin-bound anon principal + owner.principalKind:"anonymous", resolves a default-deny per-surface grant (never the ADR 0315 baseline; the anon run carries actingUserId:undefined so deliverable/secret tools fail closed by construction), gates write/egress via an RFC 0051 HITL interrupt over the RFC 0079 SSRF-guarded egress path, and emits opaque authorization.decided. Steward-verified 2026-07-22: booted the host in-memory with OPENWOP_ANON_ACTOR_ENABLED=true, /.well-known/openwop → anonymousActor {supported:true, tiers:["read","bounded-write-egress"], writeEgressControls:["hitl"], failClosed:true}, the /v1/host/sample/anon-surface/{tools,dispatch} seam served 200, and @openwop/openwop-conformance@1.55.1 anon-actor scenarios passed 10/10 non-vacuously under OPENWOP_REQUIRE_BEHAVIOR=true (default-deny anon-not-granted; planted BYOK canary never surfaced; cross-tenant attempt neutralized to the surface tenant; out-of-audience egress anon-egress-denied + credentialAttached:false; hitl write → approval interrupt before the durable write; uncontrolled surface → anon-write-ungated; opaque anon principal + no PII in the audit record). Host npm run ci green (2099 tests). Discovery dark by default (OPENWOP_ANON_ACTOR_ENABLED unset ⇒ block omitted + seam 404). |
MyndHyve workflow-runtime | none | Candidate tier-2 second witness; not yet advertised (single tier-1 witness sufficed to graduate, per the RFC 0129 precedent). |
| In-memory | none | — |
| SQLite | none | — |
| Python | none | — |
| Postgres | none | — |
Self-hosted runner (RFC 0122 — capabilities.selfHostedRunner)
The runner↔host channel defined in spec/v1/self-hosted-runner.md (RFC 0122, Accepted 2026-07-02; conformance 1.48.0). A host advertises selfHostedRunner { supported:true, dispatchKinds? } when it routes a run's per-step model/tool dispatch to a user-controlled runner that dials OUT (SSE receive + POST result, no inbound exposure) and holds local credentials the host cannot reach. The host stays the sole orchestration/persistence/replay authority; dispatch is per-step ({runId, stepId, seq, kind, provider?/model?/tool?, inputs}), results persist as normal step records (replay never re-dispatches), subject-first match rejects a cross-subject dispatch with a retriable runner_unavailable, and a redelivered {runId, stepId} is dropped at-most-once (deduped:true). The always-on self-hosted-runner.test.ts schema legs verify the frame/registration/capability shape server-free (the closed frames are the runner-credential-non-transit rail); the gated behavioral legs drive the POST /v1/host/sample/runner/{register,dispatch} seam (host-sample-test-seams.md §19) to assert subject-first runner_unavailable+retriable and at-most-once dedup non-vacuously. The runner_unavailable numeric HTTP status is host-chosen (any >= 400) — the witness asserts the envelope { error: { code, retriable:true } }, not a fixed status (mirrors run_forbidden / capability_required; registered in rest-endpoints.md §"Common error codes" per #815).
Graduated on dual-witness evidence vs suite 1.48.0 — per GOVERNANCE.md §"Acceptance evidence tiers" a tier-1 reference (openwop-app) + tier-2 (MyndHyve steward-affiliated sibling) graduation, not independent-organization dual-witness. Both invariants (runner-credential-non-transit, runner-output-untrusted-transport) are protocol-tier.
| Host | selfHostedRunner status | Evidence |
|---|---|---|
| openwop-app reference | discovery + behavioral live + non-vacuous (live-deployed, steward-verified) | PR openwop-app#1066 merged; live in prod app.openwop.dev, Cloud Run rev openwop-app-backend-00363-gtg @ 100% — steward-curl-verified 2026-07-02 (/.well-known/openwop → selfHostedRunner {supported:false, dispatchKinds:["model"]} honest-off; POST /v1/host/sample/runner/register → HTTP 400 route-live, not 404). (CI red = GitHub-Actions billing outage, 0-step fails; local npm run ci 3889 green authoritative per CLAUDE.md; admin-override merge.) host/selfHostedRunner.ts per-subject registry + subject-first match (no cross-subject fallback) + at-most-once {runId, stepId} dedup on a real DurableCollection; §19 seam via routes/runnerSeam.ts. Published @openwop/openwop-conformance@1.48.0 self-hosted-runner.test.ts 7/7 under OPENWOP_REQUIRE_BEHAVIOR=true — tier-3 seam RUNS (register → 200, not 404 soft-skip), subject-first runner_unavailable (409 + retriable:true), deduped:true on redelivered {runId, stepId} from persisted result; hard-assertion route test (no soft-skip escape). Both invariants honored (closed frames — token stays on runner; output fenced <UNTRUSTED>). Model-dispatch arm (ADR 0182 Phase 5); SSE outbound-dial deferred; no vendor-CLI spawn in backend/src. |
MyndHyve workflow-runtime | discovery + behavioral live + non-vacuous (live-deployed, steward-verified) | Tier-2 steward-affiliated sibling. PR myndhyve#192. Live-deployed witness rev workflow-runtime-00516-yuz (tag rfc0122, 0% traffic — prod serving untouched, RFC 0115 pattern) — steward-curl-verified 2026-07-02 (/.well-known/openwop → selfHostedRunner {supported:false, dispatchKinds:["model","tool"]} honest-off; register → route live, not 404). host/selfHostedRunner.ts SSOT: subject-first match keyed on the RFC 0048 Principal (subject-before-capability, no cross-subject fallback) + at-most-once {runId, stepId} dedup on a real persisted store (run_claims-pattern) + a loopback runner that really answers (non-vacuous dedup). Published @openwop/openwop-conformance@1.48.0 --filter self-hosted-runner 16/0 under OPENWOP_REQUIRE_BEHAVIOR=true (OPENWOP_OPTED_OUT_PROFILES=openwop-self-hosted-runner; tier-3 seam RUNS register → 200). Non-vacuity re-proven live via curl (fresh ids): subject-first → 503 {error:{code:"runner_unavailable",retriable:true}} no cross-subject fallback; deduped:false → deduped:true; result fenced <UNTRUSTED>…</UNTRUSTED> + contentTrust:"untrusted"; closed frames, no credential field. |
| In-memory | none | — |
| SQLite | none | — |
| Python | none | — |
| Postgres | none | — |
Data-parallel dispatch per-item input (RFC 0126 — capabilities.dispatch.perItemInput)
RFC 0126 graduated Active → Accepted on 2026-07-04 on a single-witness bootstrap steward waiver (0120/0121/0125 precedent); it is now dual-witness live (2026-07-05) — openwop-app (tier-1) + MyndHyve workflow-runtime (tier-2 steward-affiliated sibling), both advertising dispatch.perItemInput: true on live-deployed hosts, steward-curl-verified. The nextWorkerInputs[] array on NextWorkerDecision (orchestrator-decision.schema.json) lets a next-worker decision fan ONE childWorkflowId over N runtime items with distinct per-item inputs, projected over the RFC 0022 inputMapping (per-item wins on collision). A host advertises capabilities.dispatch.perItemInput: true (a prose descriptor in capabilities.md §dispatch, alongside the prose-only RFC 0118 dispatch.* family) when it honors per-index projection, the length-equality + fail-closed runtime validation_error gates, and the replay-freeze re-read of the recorded runOrchestrator.decided decision. The always-on dispatch-per-item-input.test.ts schema legs verify the nextWorkerInputs shape + the additionalProperties:false fail-closed rail server-free; the capability-gated behavioral legs (projection, merge-precedence, length-mismatch, replay-freeze, fail-closed) drive the POST /v1/host/sample/dispatch/per-item seam and soft-skip until a host wires it.
| Host | Status | Evidence |
|---|---|---|
| openwop-app reference | discovery + behavioral live + non-vacuous (live-deployed, steward-verified) | Witness #1, live. PR #1278: subWorkflowDispatcher.perItemInputs projected over the RFC 0022 mapping (per-item override); decision.nextWorkerInputs[idx] projected into each child on both the parallel fan-out and sequential-loop arms; the fail-closed gate (non-advertising host + length-mismatch each ⇒ validation_error, 0 children); replay-safe re-read of the recorded decision (CP-2). Witness dispatch-per-item-input-executor.test.ts 5/5 on a real core.dispatch node + real dispatcher; 64 existing dispatch/scheduler tests still green. PR #1283 flipped dispatch.perItemInput honest-ON + shipped the installable campaign-journeys.segment-winback chain (workflow-chain-segment-winback-execution.test.ts — a live 3-contact segment → 3 children each with its own contactId, ADR 0255). Corroborating consumer witness: #1279 (segment-winback supervisor node → real core.dispatch e2e). Discovery: app.openwop.dev/api/.well-known/openwop → dispatch.perItemInput: true — steward-curl-verified 2026-07-05. |
MyndHyve workflow-runtime | discovery + behavioral live + non-vacuous (live-deployed, steward-verified) | RFC 0126 dual-witness #2 — tier-2 steward-affiliated sibling (per the RFC 0122 precedent), a genuinely different code base from openwop-app. PR #194 (789480099) mirrors #1278 in dispatch.node.ts: decision.nextWorkerInputs[idx] projected over inputMapping/perWorkerInputMappings (per-item wins) on both the parallel + sequential arms, threaded on the TRUE dispatch index (duplicate nextWorkerIds safe); fail-closed rail (unadvertised + length-mismatch ⇒ validation_error, 0 children); replay-freeze on the recorded runOrchestrator.decided decision (CP-2, by construction — same anchor as nextWorkerIds); one-source honest-off→on gate (OPENWOP_DISPATCH_PER_ITEM_INPUT). Witness dispatch.node.test.ts 56/56 (the 5 + a parallel-arm duplicate-worker leg); root+engine tsc clean; engine core+protocol 960/960; no engine/event-version bump. Discovery: workflow-runtime-…run.app/.well-known/openwop → dispatch.perItemInput: true — steward-curl-verified 2026-07-05, serving rev workflow-runtime-00294-hcp (deployed under the Firestore deploy-lock + read-before-promote ritual). The published-suite POST /v1/host/sample/dispatch/per-item server-free seam (optional G5) is not wired here, so the published behavioral legs soft-skip against this host — a logged follow-up; the executor witness is the 56/56 unit suite + the live advertisement. |
| In-memory | none | — |
| SQLite | none | — |
| Python | none | — |
| Postgres | none | — |
Portable per-run parameter deferral (RFC 0124 — capabilities.workflowChainPacks.deferredParameters)
RFC 0124 graduated Active → Accepted on 2026-07-04 on a single-witness bootstrap steward waiver (0120/0121/0125/0126 precedent; the dual-witness path is a tracked follow-up per gap G6 — MyndHyve workflow-runtime and the in-memory host both lack a chain-expansion / PromptTemplate-compose path). Deferred mode materializes a workflow-chain pack's parameters into top-level variables[] and rewrites {{params.}} into spec'd runtime bindings (PromptTemplate {{varName}} source:"variable", or a variable-sourced PortValue), keeping parameters overridable per run via configurable while the persisted definition holds ZERO {{params.}} tokens. A host advertises workflowChainPacks.deferredParameters.supported: true when it implements this AND the §Security handling for x-openwop-sensitive params (materialize source:"secret", prompt-body-only, fail-closed sensitive_param_not_deferrable 422 elsewhere, per-run supply = credentialRef not plaintext). The always-on workflow-chain-deferred-parameters.test.ts legs verify deferred expansion + the §Security fail-closed/no-plaintext MUSTs server-free against the reference expandChainDeferred; the capability-gated host legs drive the POST /v1/host/sample/chain/deferred-expand seam (override / :fork replay / untrusted-fence / [REDACTED] compose) and soft-skip until a host wires it.
| Host | Status | Evidence |
|---|---|---|
| openwop-app reference | discovery + behavioral live + non-vacuous (live-deployed, steward-verified) | RFC 0124 witness #1, live end-to-end. Host stack #1245 (Path A) → #1252/#1262/#1265/#1270 (increments) → #1273 (durability: re-register metadata.mintedPromptTemplates at run-start) → #1281 (source:"secret" §Security) → #1289 (9361e646) advertise + pin @openwop/openwop-conformance@^1.51.0. Discovery: app.openwop.dev/api/.well-known/openwop advertises workflowChainPacks { supported: true, deferredParameters: { supported: true } } — steward-curl-verified 2026-07-05, Cloud Run rev openwop-app-backend-00404-6mw @ 100%. Behavioral: deferred expansion materializes → bare-param configurable override rebinds the value → :fork replays the same value → a x-openwop-sensitive param materializes source:"secret" (BYOK, [REDACTED:<credentialRef>]) with the plaintext appearing nowhere (body, RunSnapshot, at-rest, observability, override request); whole-value / non-prompt / no-secrets positions fail closed sensitive_param_not_deferrable (422); a plaintext sensitive configurable ⇒ validation_error. Green under OPENWOP_REQUIRE_BEHAVIOR=true — the published workflow-chain-* scenarios 56/0 against corpus b6ed2752 (#828); the always-on workflow-chain-deferred-parameters legs (materialization / fail-closed / credentialRef-string) + the host's own gated runpath vitest (workflow-chain-deferred-runpath.test.ts, plaintext-never-anywhere); backend discovery+chain 269/0. In-process harness witnesses (2026-07-05). The host now serves BOTH test-only seams (behind OPENWOP_TEST_SEAM_ENABLED, 404 in prod per the RFC 0117 posture, so prod discovery stays clean): /v1/host/sample/chain/deferred-expand (#1292) drives the workflow-chain-deferred-parameters gated legs non-vacuously (12/0) through the real deferred pipeline (materialize → bare-param override → :fork byte-stable replay → [REDACTED:<credentialRef>]), pinning the contentTrust:"untrusted" fence + plaintext-never-anywhere on the live compose fn; and /v1/host/sample/workflow-chain:expand (#1298) makes RFC 0013 host-expansion 6/6 (see the RFC 0013 host-expansion row). The former hostExpansionSeam opt-out is dropped — the flag is advertised only behind the seam gate. ADR 0250's plaintext-400 concern is now covered by the deferred-expand route test (#1292, chain-deferred-expand-seam.test.ts 3/3). |
MyndHyve workflow-runtime | ruled out (no chain-compose path) | — |
| In-memory | none | — |
| SQLite | none | — |
| Python | none | — |
| Postgres | none | — |
Streaming & CDC trigger sources (RFC 0127 — triggerBridge.sources: "stream" | "change")
RFC 0127 graduated Active → Accepted on 2026-07-06 on a single-witness bootstrap steward waiver (tier-1 reference host). It additively extends the RFC 0083/0099 trigger source enum with stream (a Kafka/Kinesis/Pub-Sub broker message) and change (a warehouse/DB CDC row; op insert|update|delete REQUIRED in the ChangeEvent sub-object). Both reuse the RFC 0099 TriggerEvent envelope, SSRF posture, SR-1 content-free trigger.* events, and the RFC 0083 ≥24h dedup floor unchanged. A host advertises stream/change in triggerBridge.sources[] + ingestion.externalSources[] only when it operates a real broker/CDC consumer (RFC 0099 honesty rule). The always-on trigger-stream-cdc-sources.test.ts schema legs verify the envelope shape (op-required negative, exactly-one rule, vocabulary pins) server-free; the capability-gated behavioral legs drive the POST /v1/host/sample/trigger-bridge/{ingest,deliver} seams.
| Host | Status | Evidence |
|---|---|---|
| openwop-app reference | behavioral live + non-vacuous (live-deployed, steward-verified); advert honest-off | Witness #1. PRs #1332 (ingest seam accepts stream/change on both /v1/host/openwop-app/… + /v1/host/sample/… paths; op REQUIRED; before/after CDC row images; dedup (topic,partition,offset)/(table,changelogId); SR-1 body never on the durable event) + a source-gate flag (OPENWOP_TRIGGER_STREAM_CDC_ENABLED). Cloud Run rev openwop-app-backend-00411-77q @ 100%. @openwop/openwop-conformance@1.53.1 trigger-stream-cdc-sources.test.ts non-vacuous for BOTH sources under OPENWOP_REQUIRE_BEHAVIOR=true. Steward-curl-verified 2026-07-06 on the *.run.app backend: stream + change ingest → 200 with schema-valid op/offset-carrying envelopes, body-canary absent from the durable delivery event; stream/change absent from advertised triggerBridge.sources[]/ingestion.externalSources[] (honest-off — no real broker/CDC consumer yet, gap G4).<br>Update 2026-07-06 (rev openwop-app-backend-00413-jcm) — G4 CLOSED, real consumer operating + steward-fired end-to-end. Advert FLIPPED ON: triggerBridge.sources[] + ingestion.externalSources[] now include stream/change (steward-curl-verified on /.well-known/openwop). Steward independently provisioned a real core.openwop.streams connection (conn:d0a76f77-…, source stream, BYOK HMAC) and fired the consumer boundary himself: valid signed push → 202 {accepted:true} → a REAL run (694cf46f-…, workflow openwop-app.agents.lead-routing) via trigger.delivery (ingestExternalEvent, NOT resolveAndResume); bad-signature → 401 no run (real HMAC, not the 404 of an unknown connection); a signature valid-for-a-stale-ts → 401 no run (real ±5min replay window); same-(topic,partition,offset) replay → 202 {deduped:true} no second run (effectively-once); exactly one run created across all legs. This is the "first host operating a real streaming/CDC consumer" — G4's second/real witness. |
MyndHyve workflow-runtime | ruled out (no broker/CDC consumer) — natural G4 second witness when one exists | — |
| In-memory / SQLite / Python / Postgres | none | — |
Purpose-propagation permitted-use labels (RFC 0128 — capabilities.purposePropagation)
RFC 0128 graduated Active → Accepted on 2026-07-06 on a single-witness bootstrap steward waiver + maintainer call. Gap G4 (a real onward label-carrying egress, steward-witnessed) — CLOSED 2026-07-06: tier-1 openwop-app built the openwop-app.cdp.sync-to-openwop-host reference workflow (prepare-onward node → the sanctioned core.openwop.http.fetch node → a steward capture bin) and fired the four onward legs local-on-origin/main; the steward independently read the bin and verified ⊆received / never-widen (marketing dropped on the real send) / []-drop with an unlabelled positive control. openwop-app is now the first host with a real onward label-carrying OpenWOP-envelope egress. An OPTIONAL permittedPurposes: string[] label (opaque purpose categories; absent = unlabelled, [] = no onward use) rides the A2A metadata.openwop.permittedPurposes extension + the top-level TriggerEvent.permittedPurposes field; a host advertising purposePropagation {supported, propagatesOnward} MUST re-emit the label on onward OpenWOP-envelope hops (MAY narrow, MUST NOT widen), a derived output MUST NOT carry a purpose absent from any contributing labelled input, and []-labelled data MUST NOT be forwarded onward. Non-OpenWOP destinations are a field-mapping SHOULD (untestable); internal use is §4 declared-intent (not gated). The always-on schema legs verify the label + family shape; the seam-gated purpose-propagation.test.ts behavioral legs drive the POST /v1/host/sample/purpose-propagation/forward two-hop seam.
| Host | Status | Evidence |
|---|---|---|
| openwop-app reference | discovery + behavioral live + non-vacuous (live-deployed, steward-verified) | Witness #1. PRs #1334 (the purposeLabels algebra + the /v1/host/sample/purpose-propagation/forward hop-B capture seam: forward→re-emit, merge→intersect, []→dropped/contagious, unlabelled→top element) + #1336 (advert behind OPENWOP_CDP_PURPOSE_PROPAGATION_ENABLED). Cloud Run rev openwop-app-backend-00411-77q advertises purposePropagation {supported:true, propagatesOnward:true}. @openwop/openwop-conformance@1.53.1 purpose-propagation.test.ts (seam-gated) — all four §3 legs non-vacuous under OPENWOP_REQUIRE_BEHAVIOR=true. Steward-curl-verified 2026-07-06 on the *.run.app backend: forward label ⊆ input; merge ⊆ intersection (marketing-email dropped when a contributing input lacked it); []-labelled blocked dropped while the unlabelled control twin forwarded (fail-closed positive control). G4 CLOSED 2026-07-06 (real onward egress, steward-witnessed): PR #1391 added the feature.destination-sync.nodes.prepare-onward node + reference workflow openwop-app.cdp.sync-to-openwop-host (prepare-onward → the sanctioned core.openwop.http.fetch node → the steward capture bin webhook.site/4c0267e7; feature never sends, SR-1 clean; ADR 0289), fired local-on-origin/main (run nonce mr9ovt8u). Steward independently read the bin (5 captures, L4-DROP absent): re-emit L1→["billing","support"]==received; narrow L2→["billing"]⊆received; never-widen L3→["billing"] only, marketing dropped on the real send (the falsifiable core); []-drop L4-DROP no egress while unlabelled twin L4-TWIN arrived (fail-closed, not a timeout). First host with a real onward label-carrying OpenWOP-envelope egress. |
MyndHyve workflow-runtime | honest opt-out (tier-2, gap G4) — architect-reviewed 2026-07-06 (repo @ 789480099): no genuine onward OpenWOP-envelope egress for the label (A2A ingress-only, no outbound client / no metadata field on task types; trigger delivery content-free in-run only). Declined to serve a fabricated-carrier seam (vacuous-witness trap). Natural tier-2 witness once it grows a real A2A-forward or connector-destination-sink boundary. | — |
| In-memory / SQLite / Python / Postgres | none | — |
Front-end plugin packs (RFC 0117 + 0119 — capabilities.uiPlugins)
RFC 0117 (+ 0119 isolation mechanism-neutrality) graduated Active → Accepted on 2026-07-06 on a single-witness bootstrap steward waiver + maintainer autonomy grant. A host advertising uiPlugins {supported:true, isolation} loads SIGNED, SANDBOXED kind:"frontend-plugin" packs in an origin/execution-isolated boundary and talks to them over the closed ui-plugin/1 host-RPC allowlist. Four protocol-tier SECURITY invariants: frontend-plugin-isolation / -egress / -rpc-allowlist / -no-byok. Witness ruling: isolation + egress are serve/apply-control MUSTs — the host MUST apply a sandboxed cross-origin iframe (no allow-same-origin) and serve the plugin under a deny-egress CSP; those controls are falsifiable by the steward on the wire + the reference host's FE unit tests, while the browser's runtime enforcement of correctly-applied controls is a platform guarantee (the §4-parallel unobservable-runtime split). rpc-allowlist + no-byok are wire-observable and steward-curl-verified.
| Host | Status | Evidence |
|---|---|---|
| openwop-app reference | discovery + serve-controls live + non-vacuous (steward-verified) | Witness #1. Host code merged openwop-app #1408 (400ef677, ADR 0300): FE iframe loader (PluginFrame, srcDoc sandbox="allow-scripts" no-same-origin + withPluginCsp deny-egress meta) + signed community.openwop.artifact-viewer kind:"frontend-plugin" pack + backend serve routes. Steward-curl-verified 2026-07-06 on app.openwop.dev/api: (1) /.well-known/openwop advertises uiPlugins {supported:true, isolation:"cross-origin-iframe", hostApi:[artifact.read,write,host.toast,navigate], maxEntryBytes:2097152}; (2) GET /ui-plugin/packs → isolation:"cross-origin-iframe", signed pack served with closed hostApi:["artifact.read"]; (3) the entry endpoint serves the self-witnessing plugin (window.origin==='null' / exfil-fetch→CSP-block / artifact.write→method_not_allowed); (4) POST /ui-plugin/rpc undeclared host.exec → {ok:false, error:{code:"method_not_allowed"}} (frontend-plugin-rpc-allowlist); (5) stale artifact.write → {artifact_conflict, currentVersion:"1"}, envelope carries no secret (frontend-plugin-no-byok). #1408 FE unit tests (green) assert PLUGIN_SANDBOX allow-scripts-without-allow-same-origin (frontend-plugin-isolation) + PLUGIN_CSP deny-egress + withPluginCsp injection (frontend-plugin-egress) + the allowlist bridge. Defense-in-depth: openwop-app's backend deny-egress CSP response header on the entry endpoint — initially a no-op (Firebase Hosting's global CSP overrode it on /api/), resolved 2026-07-06 (openwop-app#1414): a scoped firebase.json header rule now wins on the entry path. Steward-re-curl-verified** — the entry endpoint returns content-security-policy: default-src 'none'; … with NO connect-src, so a direct browser load of a plugin entry is deny-egress too. Real second layer end-to-end (in addition to the load-bearing frontend withPluginCsp srcDoc meta). |
| MyndHyve / In-memory / SQLite / Python / Postgres | none (tier-2 gap) | Tier-2 witness = a second host, or a non-iframe isolation mechanism (wasm/process/…) proving 0119's mechanism-neutrality on the wire. Carried forward as the named gap. |
Portable prompt-prefix cache (RFC 0116 — aiProviders.promptPrefixCache)
RFC 0116 graduated Active → Accepted on 2026-07-06 on a single-witness bootstrap steward waiver. A supporting host MAY route a stable, tenant-namespaced, secret-free cachePrefixId label to its provider's context cache; the outcome is cost-hint-only + replay-invariant (a hit/miss MUST NOT change the recorded envelope or inputTokens/outputTokens), witnessed by the cost-only provider.usage.cacheReadTokens/cacheWriteTokens. Protocol-tier invariant prompt-prefix-cache-cross-tenant-isolation mandates a (tenant, cachePrefixId) cache key.
| Host | Status | Evidence |
|---|---|---|
| openwop-app reference | discovery + behavioral live + non-vacuous (steward-verified) | Witness #1. Advert aiProviders.promptPrefixCache {supported:true, providers:["anthropic"]} live on app.openwop.dev/api. Steward-curl-verified 2026-07-06 via POST /v1/host/openwop-app/aiProviders/prefix-cache-probe (prod OPENWOP_TEST_SEAM_ENABLED): tenant-A prefix probe-prefix-1 → {cacheWriteTokens:1000, cacheHit:false} (write); tenant-A same prefix → {cacheReadTokens:1000, cacheHit:true} (hit); tenant-B same prefix → {cacheReadTokens:0, cacheHit:false} (MISS) = prompt-prefix-cache-cross-tenant-isolation proven ((tenant, cachePrefixId) keying, no cross-tenant leak). Anthropic call mocked → RFC 0108 production-dark tier (key-isolation real, provider routing dark). |
| MyndHyve / In-memory / SQLite / Python / Postgres | none (tier-2 gap) | Second host advertising promptPrefixCache — carried forward. |
A2UI surface deltas (RFC 0114 — a2uiSurface.deltaTransport)
RFC 0114 graduated Active → Accepted on 2026-07-06 on a single-witness bootstrap steward waiver. A host MAY deliver RFC 6902 (JSON-Patch) delta frames over the run event stream to subscribers that negotiate ?a2uiDelta=1; the RECORDED envelope stays the FULL ui.a2ui-surface (replay-pinned, unchanged) and the consumer re-validates the post-patch surface against the closed A2UI catalog fail-closed.
| Host | Status | Evidence |
|---|---|---|
| openwop-app reference | discovery + behavioral live + non-vacuous (steward-verified) | Witness #1. Advert a2uiSurface.deltaTransport:true live on app.openwop.dev/api; host code openwop-app#1416 (806fb747, host test a2uiSurfaceDelta.test.ts 5 passed). ① delta delivered + reconstructs: ?a2uiDelta=1 subscriber receives an RFC 6902 frame (op enum add/remove/replace, no test) that applyPatch-round-trips + re-validates (host test). ② recorded stays FULL (replay-pinned core): non-negotiating subscriber → {kind:'full'}, recorded event is the full envelope; steward-curl-verified 2026-07-06 valid emit → 201 {eventId, sequence:1, surfaceRef, catalogVersion:"0.9.1"}. ③ post-patch fail-closed: steward-curl-verified an out-of-catalog iframe → 422 a2ui_surface_invalid (#/anyOf closed catalog). |
| MyndHyve / In-memory / SQLite / Python / Postgres | none (tier-2 gap) | Second host advertising deltaTransport — carried forward. |
Connection-pack provider vendor grouping (RFC 0123 — provider.vendor)
RFC 0123 graduated Active → Accepted on 2026-07-06 on a single-witness bootstrap steward waiver — an OPTIONAL presentational vendor string on the RFC 0095 connection-pack provider object, so a host/registry groups pack-delivered connectors by commercial vendor. It gates no capability and carries no wire behavior, so the observable contract is the schema shape (accept string / accept-absent / reject non-string), witnessed by three conformance legs; the rendering MUSTs (SHOULD-group / MUST-fallback-to-displayName) are the 0128/0129 §4 unobservable-runtime class. Evidence UPGRADE 2026-07-07 (CARRIED-FORWARD → host-served real grouping): the flip was steward-only on the schema-shape witness, but a tier-1 host now serves pack-delivered vendor grouping on the wire — lifting the host row from "schema-shape witnessed" to "host-served real grouping witnessed." Tier-2 (a second host) is carried forward.
| Host | Status | Evidence |
|---|---|---|
| openwop-app reference | host-served real grouping (steward-verified) | Host code openwop-app#1430 (d3b29559, ADR 0303: connectionPackLoader.toProviderManifest reads provider.vendor → groups via the ADR 0185 catalog); deployed rev openwop-app-backend-00428-9st. Steward-authored wire witness 2026-07-07 on app.openwop.dev/api (both seams live under OPENWOP_TEST_SEAM_ENABLED): ① accept+honor — steward's own POST …/connection-packs/install of community.steward-witness.conn with provider.vendor:"Steward-Witness-Co" → {"installed":true}; ② served real grouping — GET …/providers then surfaces the steward's connector stwtns1 with vendor:"Steward-Witness-Co" on the wire (self-authored value, not a pre-seed); ③ fail-closed on type — a valid-named pack with provider.vendor:123 → {"installed":false, errors:[{code:"validation_error", "… /provider/vendor must be string"}]} (rejection only on vendor). |
| MyndHyve / In-memory / SQLite / Python / Postgres | none (tier-2 gap) | Second host serving pack-delivered provider.vendor grouping — carried forward. |
Agent-manifest role + the Skill profile (RFC 0131 — AgentManifest.role)
RFC 0131 graduated Draft → Accepted on 2026-07-07 via the bootstrap single-maintainer comment-window waiver (steward architect-reviewed). It adds an additive OPTIONAL AgentManifest.role ("skill" | "assistant") plus a schema-encoded Skill profile (if role==="skill" then {required:["handoff"], memoryShape.{conversation,longTerm} !== true}). Enforcement is universal JSON-Schema validation at publish/install — it introduces **no capabilities.* advertisement and no host runtime behavior — so, unlike a capability-gated surface, there is no per-host interop variance to track: every conformant validator rejects a stateful/handoff-less skill manifest identically, and an absent role (or role:"assistant") is unconstrained on every host. The witness is therefore the always-on, server-free** agent-manifest-role-profile.test.ts (validate skill/assistant/no-role; reject the stateful skill, the handoff-less skill, and a bad enum value) — no host-witness table applies. SECURITY invariant agent-skill-profile-stateless. Reference host: openwop-app ADR 0312 (Phase-0 marketplace "Skill" label; Phase-2 worker-memory normalization).
Conformance pass rates
Measured against @openwop/openwop-conformance@1.22.0 (the published suite has since advanced to 1.46.0 — 1.23.0 added the +5 RFC 0095 connection-pack scenarios, 1.24.0 the RFC 0096/0097/0098 scenarios, 1.25.0 the RFC 0099/0100 scenarios, 1.26.0 the RFC 0102 A2UI scenarios, 1.27.0 the RFC 0103 localized-content scenario, 1.28.0 the RFC 0104 approver-routing scenario, and 1.29.0–1.46.0 a further sequence of capability-gated scenarios (1.29.0 RFC 0105 speech-synthesis through 1.46.0 RFC 0120 connection-pack apiHosts egress allow-list); all are capability-gated and soft-skip on these reference hosts (which advertise none of those surfaces), so applicable rates are unchanged, and the table below re-measures on the next suite cycle) — all five hosts measured 2026-06-11, then re-measured the same day after the gap-closure fixes landed (openwop-examples#7 + openwop-app#164): the morning run's findings — the RFC 0093 §A3 webhook-tenant-isolation registration-gate gap on SQLite/Postgres/Python, the Python RFC 0058 runTimeoutMs gap, and the workflow-engine's 12 long-carried pre-existing failures — were all root-cause fixed and verified. Current posture: zero deterministic failures on the workflow-engine, Postgres, SQLite, and Python hosts; the in-memory host's 45 failures remain its documented honest-non-claim set (advertised-fixture surfaces the minimal host doesn't implement). Modes: in-memory/python/postgres default (Postgres via pglite), SQLite strict with honest profile/fixture opt-outs, workflow-engine in-process serial. Suite total 1963. Measurement basis: full 82-fixture catalog (fixture resolution now env-overridable + sibling-probing and loud on fallback — the silent degraded loading of pre-1.22.0 readings is fixed). Pass rate is passed/total.
Workflow-engine row re-measured 2026-06-21 at suite 1.29.0 (in-process, serial via --no-file-parallelism, full repo corpus via OPENWOP_CONFORMANCE_ROOT, OPENWOP_TEST_SEAM_ENABLED=true, memory://): 2059 / 0 / 89 / 2148, zero deterministic failures. The total rises 1963 → 2148 because the 1.23.0–1.29.0 scenarios now register (and the repo corpus carries the spec-corpus-validity prose/link/index cases the published package omits by design — so the repo-corpus total is the apples-to-apples basis the other reference rows are also measured on). The 89 skips are honest-non-claims: capability-gated families this host advertises none of (RFC 0104 approver-routing, RFC 0105 speech-synthesis, the unadvertised-profile families) soft-skip in default mode. The other four reference rows remain at the 1.22.0 basis pending their next re-measure cycle.
| Host | Passed | Failed | Skipped | Todo | Total | Pass rate (default) |
|---|---|---|---|---|---|---|
| Workflow-engine reference (in-process, 1.29.0) | 2059 | 0 | 89 | 0 | 2148 | 95.9% |
| Postgres reference | 1848 | 0 | 115 | 0 | 1963 | 94.1% |
| SQLite reference (strict) | 1826 | 0 | 137 | 0 | 1963 | 93.0% |
| In-memory reference | 1793 | 45 | 125 | 0 | 1963 | 91.3% |
| Python reference | 1786 | 0 | 177 | 0 | 1963 | 91.0% |
Composition partners — interop evidence
The conformance suite's MCP and A2A probes run against live reference implementations of the adjacent protocols. See A2A vs MCP vs OpenWOP for how the three layers compose.
| Partner | Reference impl | Sync round-trip | Async / durable (RFC 0100) |
|---|---|---|---|
| MCP | @modelcontextprotocol/sdk@1.29.0 (all three transports) | ✅ pass | — |
| A2A | @a2a-js/sdk@0.3.13 reference peer (echo skill, JSON-RPC) | ✅ 1/1 pass (a2a-task-roundtrip.test.ts) | ⏳ corpus landed (capabilities.a2a + A2ATaskState + durable-tasks/get/resubscribe/push subtests); reference-host durable-Task evidence at Active → Accepted |
Compensation and partial-failure profile (RFC 0151 + 0157 — capabilities.compensation)
The host-ordered, persisted, retried unwind of committed business effects (RFC 0151, Accepted 2026-08-12; spec/v1/compensation.md). A host populates the row when it advertises capabilities.compensation and the capability-gated witnesses execute non-vacuously — the base seams (compensation-behavior.test.ts: plan-before-effect, reverse-completion order, replay no-refire, content-free events, snapshot rollup ⇄ events) and the §21 recovery extension (compensation-recovery.test.ts: retry-stable identity, tenant-bound operator authority, recorded-facts replay).
| Host | compensation status | Evidence |
|---|---|---|
| openwop-app reference | DEPLOYED-WIRE (advert · §B · §D rollup ⇄ events · reverse-completion order · replay-no-refire) — app.openwop.dev main 756a9938d = Cloud Run rev openwop-app-backend-00646-2zb, deploy #2 2026-08-17; §C/§E/§F + RFC 0157 chain expansion = LOCAL-BOOT (d209d8009, strict, suite 1.134.0) | On the deployed origin (suite 1.135.x; credential-less by the steward + authenticated with the host's own scoped key by the host operator, rows posted verbatim): compensation-profile 19/19 (58) · compensation-behavior 5/6 — reverse-completion implemented ✓, descending forward-completion order ✓, replay re-fires nothing ✓, §D rollup on the snapshot agrees with the events ✓ (real routes), events carry no provider bodies/credentials ✓; the sixth (plan persisted before the first inverse action) drives the §21 unwind test seam, unmounted in production (OPENWOP_TEST_SEAM_ENABLED=false) → seamAbsent · compensation-recovery 0/3 seamAbsent for the same structural reason (see compensation.md G9) · contractProvenance absent (RFC 0146 unspecified, honest). On the local boot of merged main (d209d8009): compensation-profile 19/19 (58 asserts) · compensation-behavior 6/6 (25) · compensation-recovery 3/3 (25 — three attempts / one downstream key; cross-tenant 404 / same-tenant 403 audited / operator 200 audited; replayed ≡ source, refiredEffects: 0) · chain-compensation-expansion 11/11 (44) · workflow-chain-host-expansion 8/8 (the two RFC 0157 chains record blocked until the host's conformance pin reaches ≥ 1.133.0). Advert { supported: true, profileVersion: "1", orderingModels: ["reverse-completion"], manualIntervention: true }; compensationStatus on every RunSnapshot; UQ4 irreversible plan entry caps the rollup at partial. This is the first host to execute every RFC 0151 normative behavioral path in strict mode (RFC 0147 §A.5) — on a local boot of merged main — and, since deploy #2, the first to carry the advert, compensationStatus, the §D rollup and the ordering/replay behaviours on a deployed origin. §C/§E/§F stay local-boot t-recorded-facts-only) are witnessed here for the first time. Deploy #5 (83c1385ca, rev 00650-8rz, 2026-08-18) ships ADR 0554 P3 — the §E operator recovery family (start / retry / waive / substitute, separate permissions, SoD through the RFC 0051 approval gate, expectedState CAS) and the S36/S37 waiveRequiresApproval round-trip; the steward's credential-less strict re-drive at suite 1.136.4 holds compensation-profile` 20/20 (the S36 shape leg included). §E stays observable only through the §21 seams (G9), so the deployed-wire claim set is unchanged and the local-boot witness stands. |
MyndHyve workflow-runtime | none | — |
| In-memory / SQLite / Python / Postgres | none | reference hosts have no compensation surface (RFC 0151 acceptance: reference-host mid-unwind crash recovery is carried in openwop-examples) |
Memory profile (RFC 0080 §C — capabilities.memory, openwop-memory)
The agent-memory surface (RFC 0080 §C memoryDegraded / attribution / injection budget; floor = memory-attribution-emits-on-write + the agentMemory* scenarios, two-sided since S35 at suite 1.136.1). A host populates the row when it advertises capabilities.memory.supported: true and the profile evaluates under --certify bundle v2.
| Host | memory status | Evidence |
|---|---|---|
| openwop-app reference | DEPLOYED-WIRE advert — app.openwop.dev 83c1385ca = Cloud Run rev openwop-app-backend-00650-8rz, deploy #5 2026-08-18 (memory { supported: true, attribution { supported, emitsWriteEvents: true }, injectionBudget { supported, tokenCounter: "chars" } }; H49 memoryAction seam + H51 §C memoryDegraded flip) | Host operator's authenticated bundle-v2 certify lane on the deployed origin (posted on the bus 2026-08-18 00:46Z, verbatim): 11 profiles certified incl. openwop-memory, 468 requirement rows, evidence fa168b95d145; the installed suite in that lane was 1.136.1 (contractProvenance.suiteVersion), i.e. the S35 two-sided agentMemory* legs — the first host to certify openwop-memory on a deployed origin (the postgres reference host certified it first, on a local pglite boot — row below). Steward credential-less at 1.136.4: memory-capability-model-shape 8/8. The behavioural floor is authenticated and was NOT re-driven by the steward; the row rests on the operator's lane until the next steward-run bundle. |
MyndHyve workflow-runtime (tier-2) | certified — bundle v2 #13 at suite 1.136.7 on the deployed origin workflow-runtime-00566-vim (main 7898f2b12) | openwop.floor.memory-attribution-emits-on-write executed-pass (RFC 0057 session-end run-summary write) and agentMemoryTtlExpiry executed-pass with the S35 two-sided fixture. First certified at #12b (1.136.3) once S41 stopped the helpers fabricating a tenantId; #13 re-measures it on the promoted revision with executed-fail 0 across the whole run. |
| Postgres reference | certified — local (pglite) boot, bundle v2 at suite 1.130.0 (memory { supported, maxEntrySizeBytes: 65536, ttlSupported, attribution { supported, emitsWriteEvents } }) | openwop-examples#15 bundle: openwop-memory certifiable (both floors landed at 1.120.0); S35's two-sided agentMemory fixtures converged in openwop-examples#18 (4/4 at 1.136.1). A reference measurement, not a deployed origin — the row above is the first deployed* certification, this is the first certification anywhere. |
| In-memory / SQLite / Python | none | these reference hosts do not advertise capabilities.memory |
Versioned composition profiles — A2A 1.0, MCP 2026-07-28, workload identity (RFCs 0152 / 0153 / 0154)
Witnessed with the suite's dual-era fake peer / fake server (OPENWOP_A2A_FAKE_PEER=true, OPENWOP_MCP_FAKE_SERVER=true) under OPENWOP_REQUIRE_BEHAVIOR=true, suite 1.120.0–1.122.0, on local memory:// boots of openwop-app (tier-1). Real upstream peers in CI remain externally gated (RFC 0152/0153 acceptance).
Deployed origin, 2026-08-16 (suite 1.133.0, https://app.openwop.dev/api, deploy 1b2dd6fbb = Cloud Run rev openwop-app-backend-00644-njl, /api/readiness stamped: true): the credential-free legs of the A2A 1.0 and MCP 2026-07-28 families now hold on the wire, not only on a boot — a2a-card-runtime-consistency 5/5 (14 asserts, including the S18 header-less-GET-is-0.3 rule), a2a-1-0-agent-card 10/10 (52; the suite's peer, but the host's own card resolution), a2a-version-negotiation (§A advert + interop error envelope; the host-as-client legs need a peer reachable from Cloud Run and stay local-only), mcp-version-negotiation (same shape), versioned-composition-profiles 11/11, contract-provenance 6/6, protocol-version-grammar 20/20, replay-side-effect-suppression (none, as withdrawn 2026-08-15). The authenticated halves — MCP server mount (mcp-2026-07-28-discover, mcp-stateless-request, MRTR server half), multi-party behavioural — answer 401 to the suite's credential-less run and are witnessed on the local boots above only; auth.workloadIdentity, orgChart and triggerBridge are env-gated OFF in production (inapplicable on the wire), and compensation is not yet advertised (ADR 0554 flip pending). So: RFC 0152 §C is a deployed-wire claim; RFC 0153 §B/§D/§E and RFC 0154 remain local-boot claims until an authenticated production run or the toggles flip.
| Family (profile) | Host | Boot | Non-vacuous witness (file: passed / assertions) | Not yet |
|---|---|---|---|---|
a2a — a2a-1.0 (+ a2a-0.3-legacy) | openwop-app main 24b9e6c9b (ADR 0552 P2 merged); deployed 1b2dd6fbb for the credential-free legs (see above) | local, OPENWOP_WEBHOOK_ALLOW_PRIVATE=true (the egress guard otherwise refuses the loopback peer — RFC 0093 §A.1 working as designed) | a2a-1-0-agent-card 10/10 (52 — suite peer), a2a-card-runtime-consistency 4/4 (11), a2a-1-0-task-roundtrip 1/1 (14), a2a-peer-authority 1/1 (4), a2a-version-negotiation 4/4 (5) | ~~header-less card is served as 1.0~~ (H24 landed — 0.3 while legacy advertised, witnessed on the deployed origin 2026-08-16); ~~core.conformance.a2a-invoke not mapped~~ (H25 landed — a2a-1-0-task-roundtrip 1/1 on main 3653cd90d); durableTasks / pushNotifications not advertised; host-as-client legs local-only (no peer reachable from Cloud Run) |
mcp — mcp-2026-07-28 (+ mcp-2025-06-18-legacy) | openwop-app main df03c3476 (ADR 0553 P2 merged; re-driven at 3653cd90d, MRTR 2/2) — DEPLOYED-WIRE for §B/§D since 2026-08-17: app.openwop.dev 756a9938d rev 00646-2zb, host operator's authenticated strict pass at suite 1.135.2 (S25 legs reach serverUrls[0] = /v1/host/openwop-app/mcp): mcp-2026-07-28-discover 10/10 · mcp-stateless-request 2/2 · mcp-version-negotiation 4/4 · mcp-extension-opacity 2/2 · mcp-cache-tenant-scope 1/1; mcp-mrtr-roundtrip client half ✓ / server half local-boot (fixture tool is a conformance-boot registration); mcp-current-auth-boundary ✗ on 00646-2zb = a REAL host defect (H43: the cookie posture minted an anon:<sid> principal for a credential-less POST and the mount took "has a principal" for "authenticated"; the suite's bare probe caught it on the wire, and S30 adds a second probe that replays the host-minted anonymous session cookie) → ✓ 1/1 on deploy #3 3318d7062 rev 00648-pwz (host operator's authenticated re-run at 1.135.2; steward-verified credential-less: a bare POST /v1/host/openwop-app/mcp now answers 401 {"error":"unauthenticated",…,"details":{"reason":"anonymous_principal_refused"}} in the flat S22 envelope). Deploy #3 also carries contractProvenance.suiteVersion: "1.135.2" — the first honest non-absent RFC 0146 value on this host (H42), steward-verified — and the flat error envelope on every route (H27, 183 emit sites through one sendError; the S22 nested grace path is no longer exercised) Deploy #5 83c1385ca (rev 00650-8rz, 2026-08-18) ships ADR 0553 P3 (H53: downgrade floor, cache-confusion, token audience, cancellation, reconnect, audit — RFC 0153 §B/§D/§E)**; steward credential-less at suite 1.136.4: mcp-discoverability 2/2 and the bare anonymous POST to serverUrls[0] still refused (401, flat envelope); the authenticated §E positive control and the P3 behavioural legs are the host operator's authenticated lane (posted on the bus as certified, not re-driven by the steward). | local, OPENWOP_MCP_SERVER_ENABLED=true, second credential for the cache leg | 14/16 mcp- files, 37/39 tests — mcp-2026-07-28-discover (48), mcp-stateless-request (7 + the Mcp-Method/Mcp-Name half), mcp-mrtr-roundtrip client + server halves (11), mcp-extension-opacity (6), mcp-cache-tenant-scope (1, two credentials), mcp-current-auth-boundary (2), mcp-version-negotiation (9), all four mcp-server- round-trips + bridges | legacy host-mediated mcp-tool-roundtrip (no operator-configured server URL — H21); mcp-toolcall-redaction inapplicable (no mcpClient advert) |
auth.workloadIdentity — RFC 0154 | openwop-app main 8fbed15d4 (ADR 0556 P3 merged); H28 chain-bounds at 3653cd90d — workload-identity-chain-bounds 4/4 (12); env-gated OFF in production | local, trust roots + audience/issuer configured (run.ts recipe) | workload-identity-behavior 6/6 (12), workload-identity-profile 11/11 (18) — the delegation-tenant-audience-bound / delegation-chain-bounded invariants ride on the behaviour file | provenance≠authorization leg (named, unregistered); delegation-chain-acyclic + delegation-no-scope-amplification registered 2026-08-16 on the chain-bounds witness; no advertiser on the deployed wire (toggle off) |
Six RFC 0152/0153 invariants were registered on these witnesses (SECURITY/invariants.yaml, 2026-08-16): a2a-card-runtime-consistent, a2a-peer-no-authority-escalation, mcp-cache-tenant-scoped, mcp-extension-no-authority, mcp-peer-no-authority-escalation, mcp-header-body-consistent.
MyndHyve workflow-runtime — conformance evidence
Detailed evidence narrative for the MyndHyve row in the host table above (relocated from the table cell; newest measurement first). Per-bundle history is in the Update log.
Re-measured 2026-08-17 (M1–M6, bundle v2 #3, suite 1.135.1, deployed rev workflow-runtime-00528-vip, promoted 11:05Z; scoped 3h key on ws-openwop-conformance, revoked after the run; discovery sha256 ffde9549…60e26): the RFC 0149 UQ3 caveat is CLOSED — the live document now advertises protocolVersion: "1.0" (M1), the RFC 0155 canonical vocabulary (M3), root-first families with an identical capabilities mirror retained for external clients (M2), a2a { protocolVersions: ["0.3"], preferredVersion, profiles: ["a2a-0.3-legacy"] } (M6) and mcp { supported, protocolVersions: ["2024-11-05"], preferredVersion, serverUrls } — a version listed without its profile per mcp-integration.md §A (M5). Latest: bundle v2 #15 at suite 1.136.11 (2026-08-18, deployed revision workflow-runtime-00572-noc): executed-pass 304 / executed-fail 1 / skipped 0 / inapplicable 75 / blocked 89 across a 469-row ledger, all 14 profile lines certifiable (the 13 claimed + the openwop-core alias) — steward-re-derived from the published artifact (services/workflow-runtime/conformance/results/myndhyve-cloud-run-2026-08-18-bundle15-v2.json at ff0f8b7f4), not transcribed: all 36 floor rows sit in a certifiable disposition, 35 as executed-pass with a non-zero assertion count and one (prompt-list-and-fetch) as inapplicable with a stated reason, and the bundle contains zero zero-assertion passes. Discovery sha256 6ed605aa…45d4 — byte-identical to #13/#14, so the wire contract did not move. This is the first bundle in the programme measured against a reproducibly built image, which is what conformance-certification.md §"A bundle attributes to a BUILD" (gap G3) asks for: the Dockerfiles now npm ci under a pinned npm@11.6.2 (b9c1ddebc → ce44e7037 → 587c02bc7), so this revision's dependency closure is fixed by the lockfile and installed by the npm that wrote it. G3 exists because of this host — two builds of the identical commit 21db7e21d with byte-identical revision config scored 283/22 and 303/2, which falsified the corpus's own claim that v1 bundles are reproducible from a commit. The one failure, run-transport-economy (20 assertions, a wall-clock latency leg that passed in isolation against this same revision), is recorded as executed-fail and not re-run until green — a deliberate choice to publish what the run observed rather than the flattering score. Of four runs only the last is evidence, and both discarded modes are named on the record: attempt 1 (227/65) was discarded as invalid** because the API key expired ~6 minutes in — it would have read as a catastrophic regression caused by the build change shipped minutes earlier, a plausible story that was entirely wrong; attempt 2 (293/12) was cold-start latency on a scale-from-zero tag URL, made attributable by an isolation run rather than asserted.
Stated limitation, carried not solved: package-lock.json is still missing entries an npm < 11.5 expects, worked around by pinning the installer rather than regenerating the lock (declined for blast radius); the host's determinism guard asserts a pin exists and cannot assert it is the right one. Prior: #14 at suite 1.136.10 (2026-08-18, workflow-runtime-00566-vim): executed-pass 305 / executed-fail 0 / skipped 0 / inapplicable 75 / blocked 89, exit 0 — the same 13 claimed profiles certifiable, and memory-attribution-replay-stable now records assertionCount: 2, both halves of the recorded-fact rule. Under the pre-1.136.10 leg this host passed with its assertion loop running over zero events; it passes now because it re-emits, and the assertion count is what tells those two apart. Exactly one disposition moved from #13 — the new spec-section-citations records blocked in the published layout, where the package ships no spec/ by design (a missing dependency, RFC 0148 §A); it is in no profile floor, so no claim is affected. Prior: #13 at 1.136.7 (same revision; discovery sha256 6ed605aa…45d4; scoped key revoked after the run): executed-pass 305 / executed-fail 0 / skipped 0 / inapplicable 75 / blocked 88, exit 0 — and every one of the 13 claimed profiles is certifiable on its floor rows: discovery-core (+openwop-core alias) · core · interrupts · stream-sse · stream-poll · secrets · provider-policy · node-packs · replay-fork · fixtures · memory · trigger-bridge · core-standard · agent-platform. The BUNDLE still does not certify — blocked 88 are scenarios this host cannot witness (seams it does not mount, capabilities it does not advertise) — and the host records that rather than rounding it to "all green". Deltas from #12b, each with a real assertion count so none is a vacuous pass: eventOrdering 18 (host fix H1 — the terminal-status-before-terminal-event race, now stated in observability.md), pack-registry-publish 17 (suite S45), replay-observable-sequence-determinism 9 (host fix H2 — the replay fork re-emits the source's session-end memory events; on the RFC 0057 §D contradiction this host is on the re-emit side and therefore takes the assertion path), agentMemoryTtlExpiry 7 (suite S35), memory-attribution-emits-on-write 1, speech-synthesis-roundtrip 5 (a known external-TTS flake that passed this run, reported as a flake rather than as a fix). Both host fixes were verified on the wire before the suite was trusted — H1 by polling status to terminal then reading the log 3/3 runs, H2 by comparing source and fork sequences byte-for-byte. Prior: #12b at 1.136.3 (00564-lec) 299 / 5 / 89; #11 at 1.136.0 (00555-xih) 289 / 6 / 97, which added openwop-replay-fork. Bundle #3 detail follows. Emitter, unrounded: executed-pass 267 / executed-fail 23 / skipped 0 / inapplicable 76 / blocked 101 (exit 3 — blocked > 0 does not certify the BUNDLE); per profile: openwop-discovery-core ✓ (+openwop-core alias) · interrupts ✓ · stream-sse ✓ · stream-poll ✓ · secrets ✓ · provider-policy ✓ · fixtures ✓ · trigger-bridge ✓ · openwop-core-standard ✓ certifiable (all nine floor rows pass: auth 4, discovery 110, eventOrdering 14, failure-path 6, idempotency-key-determinism 1, idempotency 6, runs-lifecycle 7, webhook-negative 8, any.interrupt- 27) · openwop-node-packs not held (runtime-derived) · openwop-replay-fork NOT certifiable (replay-side-effect-suppression blocked — no sideEffectSuppression advertised; replayDeterminism executed-FAIL) · openwop-memory NOT (memory-attribution-emits-on-write blocked) · openwop-agent-platform NOT (inherits). Two of the four host fixes it took were the corpus's fault and are fixed at 1.135.1 (capabilities.mcp.serverUrls was scenario-required and schema-forbidden; webhook-negative read the wrapper only); the others were host defects (conformance-failure stripped from fixtures[] at boot; canonical POST/DELETE /v1/webhooks accepted user tokens only). The 23 executed-fail scenarios are the host's own follow-up queue, listed in the run record, and are NOT rounded here. This is the first tier-2 host to certify openwop-core-standard on a deployed origin under bundle v2.**
Update log
Per-bundle and per-deploy conformance history for the rows above (newest first). Release-level changes are recorded in CHANGELOG.md.
- 2026-08-19 (MyndHyve bundle v2 #15 at suite
1.136.11onworkflow-runtime-00572-noc: 304 / 1 / 0 / 75 / 89 over a 469-row ledger, all 14 profile lines certifiable, zero zero-assertion passes — the first bundle in the programme measured against a reproducibly built image, which is whatconformance-certification.mdgap G3 asks for; the oneexecuted-fail(run-transport-economy, a wall-clock leg) is published as failed rather than re-run until green, and the host's#224replay-fan-out fix ships on this revision — deployed but not suite-witnessed, because the rule still has no conformance scenario). - 2026-08-18 (openwop-app deploy #7 —
4c10c3a8eb42, both halves verified: first deployed-wire implementation ofreplay.md§"Host-initiated fan-out is an external effect" (H72 — production had been delivering webhooks asserting work a replay fork never performed);sideEffectSuppressionstaysnone, withheld with a stated reason rather than as a gap; pin still1.136.3). - 2026-08-18 (openwop-app deploy #6 —
d0b6b588acd8, Cloud Run revopenwop-app-backend-00651-mdh: 11 profiles certified in the host operator's bundle v2 (468 requirement rows, evidence38d3ff4430cd, digest matched),contractProvenance.suiteVersion1.136.3 — the pin is the host's installed package and is recorded as measured, not rounded up to the current 1.136.10, so this deploy's bundle contains neither the strengthened replay leg nor the citations gate). - 2026-08-18 (MyndHyve bundle v2 #14 at 1.136.10 on
workflow-runtime-00566-vim:executed-fail 0holds andmemory-attribution-replay-stableis witnessed non-vacuously atassertionCount: 2— both halves of the recorded-fact re-emission rule; one disposition moved, the new corpus-self-checkspec-section-citations,blockedin the published layout by construction and in no profile floor). - 2026-08-18 (MyndHyve bundle v2 #13 at 1.136.7 on
workflow-runtime-00566-vim: executed-fail 0 — 305 pass / 0 fail / 0 skipped / 75 inapplicable / 88 blocked, and every claimed profile certifiable (13 claimed, 14 lines with theopenwop-corealias) includingopenwop-core-standard,openwop-node-packs,openwop-memory,openwop-agent-platformandopenwop-replay-fork; the bundle itself does not certify becauseblocked > 0, which the host reports rather than rounds). - 2026-08-18 (MyndHyve bundle v2 #12b at 1.136.3 on
00564-lec:openwop-memory+openwop-agent-platformcertifiable — 12 profiles; core-standard held by one host race, fix pending deploy;pack-registry-publishred was suite S45). - 2026-08-18 (openwop-app deploy #5
83c1385carevopenwop-app-backend-00650-8rz:capabilities.memory.supported: trueon the wire (RFC 0080 §C, host H51) andopenwop-memorycertified in the host operator's authenticated bundle-v2 certify lane — the first host to certify that profile on a deployed origin (postgres reference certified it locally at 1.130.0); ADR 0553 P3 (H53) + ADR 0554 P3 operator recovery (H50) shipped; steward credential-less strict re-drive at suite1.136.486/86 across the nine credential-free files). - 2026-08-17 (MyndHyve bundle v2 #11 at 1.136.0 on
00555-xih:openwop-replay-forkcertifiable — 11 profiles; three suite defects it surfaced fixed at 1.136.3). - 2026-08-17 (openwop-app deploy #3
3318d7062rev00648-pwz: H43 auth-boundary ✓ on the wire,contractProvenance.suiteVersion 1.135.2first honest value, flat error envelope everywhere). - 2026-08-17 (RFC 0153 §B/§D DEPLOYED-WIRE on
app.openwop.dev756a9938d— host operator's authenticated pass;mcp-current-auth-boundaryred there = host defect H43 caught on the wire). - 2026-08-17 later (openwop-app deploy #2
756a9938d: RFC 0151 compensation advert + §B/§D/ordering/replay-no-refire DEPLOYED-WIRE, §C/§E/§F local-boot — compensation.md G9). - 2026-08-17 (MyndHyve tier-2 row re-measured as bundle v2 #3 at suite
1.135.1on the deployed origin —openwop-core-standardcertifiable, RFC 0149 UQ3 caveat closed; the same host surfaced three suite defects fixed at 1.135.1–1.135.3). - 2026-08-16 (the four reference-host rows re-measured as bundle v2 against suite
1.130.0,openwop-examples#15— zero zero-assertion passes on every host; earlier the same day the RFC 0147 criterion 11 sweep re-measured them at1.116.0and canonicalised profile names per RFC 0155 §A; MyndHyve row caveated per RFC 0149 UQ3).
Reading Rows
- Compatibility profile claim is derived from
/.well-known/openwopaccording tospec/v1/profiles.md. - Scale claim follows
spec/v1/scale-profiles.md. - Production profile claim follows
spec/v1/production-profile.mdand is recorded separately because durability, retention, backpressure, and observability are operational evidence, not discovery-payload predicates. - Conformance evidence should name the suite version, command used, target URL class, and pass/fail/skip counts. Do not include private deployment identifiers, secrets, or internal result paths.
Add A Host
1. Implement the openwop v1 wire contract. 2. Run @openwop/openwop-conformance against the host. 3. Publish a result file or Markdown summary in a public repository. 4. Add a row above with compatibility, scale, production-profile, and evidence claims.
See Also
conformance/README.md— how to run the suite.spec/v1/profiles.md— compatibility profile predicates.spec/v1/scale-profiles.md— scale tier definitions.spec/v1/production-profile.md— public-release operational profile.