diff --git a/.github/workflows/docs-live.yml b/.github/workflows/docs-live.yml index df66a5d..348f59a 100644 --- a/.github/workflows/docs-live.yml +++ b/.github/workflows/docs-live.yml @@ -24,7 +24,7 @@ jobs: timeout-minutes: 15 steps: - name: Check out repository - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: Install Node.js uses: actions/setup-node@v7 diff --git a/.github/workflows/docs-source-drift.yml b/.github/workflows/docs-source-drift.yml index 4aad884..813e669 100644 --- a/.github/workflows/docs-source-drift.yml +++ b/.github/workflows/docs-source-drift.yml @@ -20,7 +20,7 @@ jobs: timeout-minutes: 10 steps: - name: Check out repository - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: Install Node.js uses: actions/setup-node@v7 diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index 1406199..cc837a7 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -21,10 +21,10 @@ jobs: timeout-minutes: 10 steps: - name: Check out repository - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: Install Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: 22 @@ -58,7 +58,7 @@ jobs: NEXT_TELEMETRY_DISABLED: '1' steps: - name: Check out repository - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: fetch-depth: 0 @@ -111,10 +111,10 @@ jobs: timeout-minutes: 5 steps: - name: Check out repository - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: Install Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: 22 diff --git a/content/docs/cli/interactive.mdx b/content/docs/cli/interactive.mdx index 9490e31..44715b9 100644 --- a/content/docs/cli/interactive.mdx +++ b/content/docs/cli/interactive.mdx @@ -32,6 +32,19 @@ Set `COVEN_LEGACY_TUI=1` only when you temporarily need the older in-process sla Explicit subcommands such as `coven run`, `coven daemon`, and `coven sessions` are never redirected — only the interactive entry point hands off. See [Core concepts](/docs/guide/concepts) for the ownership boundary. +## Terminal appearance + +For explicit native CLI commands, `--theme auto|light|dark` selects the palette +for the terminal background. `auto` uses `COVEN_THEME`, then `COLORFGBG`, and +falls back to dark without querying the terminal: + +```bash +coven --theme light doctor +``` + +`--color` separately controls ANSI output. See the +[CLI color and palette rules](/docs/cli#configuration-paths-reset-and-color). + ## Terminal routing When stdin and stdout are both terminals, `coven` opens the managed interactive UI. When you pass a bare prompt, Coven routes the text as a Cast prompt instead of opening the interactive surface: diff --git a/content/docs/cli/repo-workflow.mdx b/content/docs/cli/repo-workflow.mdx index 9c19a87..2fc1df0 100644 --- a/content/docs/cli/repo-workflow.mdx +++ b/content/docs/cli/repo-workflow.mdx @@ -84,9 +84,17 @@ the drain exception. coven ward pending # staged proposals awaiting the principal coven ward pending # one proposal in full coven ward pending --json # exact daemon body +coven ward audit-census # bounded, read-only audit-history inventory +coven ward audit-census --json # machine-readable audit-only census coven ward migrate --fingerprint --apply # migrate v0.1 ward.toml to Phase-2 WardConfig ``` +`audit-census` reads an existing Coven store without repairing state, migrating +its schema, or granting authorization. It fails instead of truncating when the +relevant audit history exceeds `--max-audit-rows` (default 10,000; range +1–100,000) or the 32 MiB decoding budget. Pending artifacts are non-atomic, +unverified observations, not proof that a proposal can be applied. + `migrate` is a dry-run report unless `--apply` is passed; `--familiar ` limits it to one familiar. A familiar's *declared* Ward surface is read with `coven familiars ` — see [Observability commands](/docs/cli/observe). ## Adapters diff --git a/content/docs/reference/api.mdx b/content/docs/reference/api.mdx index b99144c..71bd02b 100644 --- a/content/docs/reference/api.mdx +++ b/content/docs/reference/api.mdx @@ -79,6 +79,21 @@ limits, and digest rules are in the A contract name in health establishes availability, not authorization. It is not an enforcement profile, identity proof, or grant. +## Ordinary-chat context admission + +Ordinary-chat context admission is not enabled. Owner-local +`POST /api/v1/sessions` and `POST /api/v1/sessions/{sessionId}/input` validate +an explicit `contextAdmission` intent and refuse execution while trusted +embodiment verification and native context-profile qualification are absent. +Valid unverified requests receive `503` with `accepted: false` and +`receiptIssued: false`; other mutations reject the member rather than dispatching +an unbound session. Requests without it keep their existing behavior. + +Do not remove a refused `contextAdmission` member and retry as an ordinary +launch or input. This intent is separate from session-policy admission, +`executionBinding`, and `requestAdoption`; it advertises no new capability. +See the [ordinary-chat context contract](https://github.com/OpenCoven/coven/blob/main/docs/API-CONTRACT.md#ordinary-chat-context-intent-not-enabled). + ## Action router The action router accepts a top-level `action` string plus optional `origin` and @@ -128,8 +143,10 @@ copying an implementation detail into an external integration. ## Version and privacy rules `GET /api/v1/health` advertises the named `coven.daemon.v1` contract. -Its `covenVersion` field identifies the daemon build; it is not the API -compatibility signal. +Its `covenVersion` field is an opaque daemon build identity. Source builds may +include a `git describe` distance, commit, or `-dirty` suffix; an unresolved +version is `unknown`. Negotiate compatibility using `apiVersion` and the +capabilities required for the operation. `GET /api/v1/api-version` is a legacy route-family diagnostic; its literal `v1` value is not sufficient proof that every named-contract capability exists. diff --git a/content/docs/reference/automations.mdx b/content/docs/reference/automations.mdx index e56c274..f245019 100644 --- a/content/docs/reference/automations.mdx +++ b/content/docs/reference/automations.mdx @@ -15,6 +15,11 @@ versioned `POST /api/v1/actions` router. Always call daemon. This page describes the current source contract; an older installed daemon advertises fewer actions. +The `coven.automations` capability may include an optional `variantNegotiation` +object describing supported, experimental, and refused contract variants. +This is negotiation metadata; it does not authorize a refused variant. See +[versioned definition commands](#versioned-definition-commands). + ## Owner-local access Send automation actions to the owner-local IPC endpoint: the Unix socket or diff --git a/docs/source-lock.json b/docs/source-lock.json index 0a149c5..fa157de 100644 --- a/docs/source-lock.json +++ b/docs/source-lock.json @@ -20,6 +20,7 @@ ], "paths": [ "crates/coven-cli/src/main.rs", + "crates/coven-cli/src/ward_audit_census.rs", "crates/coven-cli/src/api.rs", "crates/coven-cli/src/harness.rs", "crates/coven-cli/src/setup/mod.rs", diff --git a/openapi/coven.daemon.v1.yaml b/openapi/coven.daemon.v1.yaml index 9da0468..7c3f7df 100644 --- a/openapi/coven.daemon.v1.yaml +++ b/openapi/coven.daemon.v1.yaml @@ -871,6 +871,7 @@ components: executorDispatch: true eventCursor: sequence structuredErrors: true + sessionPolicyContracts: [coven.session-policy.v1] daemon: pid: 12345 startedAt: 2026-05-09T12:00:00Z @@ -907,6 +908,19 @@ components: type: boolean description: Whether errors use the `ErrorEnvelope` shape (always `true` in `coven.daemon.v1`). The separately negotiated session-policy contract has its own closed refusal shape. + sessionPolicyContracts: + type: array + description: | + Optional refusal-only admission contracts. Currently + `["coven.session-policy.v1"]` over owner-local IPC and `[]` over TCP. + Older daemons may omit this field; absence means unavailable. + This is not a supported enforcement profile, identity proof, or grant. + items: + type: string + examples: + - [coven.session-policy.v1] + - [] + HubHealth: type: object description: Hub control-plane summary embedded in the health response.