Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions .agent/context/20260909T-gate-p6-release-candidate.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# Gate P6 release candidate

- Branch: `milestone/gate-p6-release-candidate`
- Base: `7ae55c8d473ca1bc6ca146de0dfd375571fb517a`
- Scope: repeatable offline E2E demo, judge walkthrough, and plan scope update.
- Acceptance: demo proves 1.00 USDC evidence, zero-effect Privy denials, and
lost-response at-most-once recovery; Circle and video are not claimed.
- Checks: `pnpm demo:e2e`, `pnpm typecheck`, `pnpm lint`, `pnpm format:check`,
`pnpm --filter @oneshot/testkit-settlement evidence:b06` passed.
39 changes: 39 additions & 0 deletions docs/DEMO_SCRIPT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
# Gate P6 live demo script

This is the judge-facing 2–4 minute walkthrough. It is intentionally a written
script: no video artifact is included in this release candidate.

## Before the demo

Run `pnpm demo:e2e` from a clean checkout. The command builds the workspace,
runs all invariant scenarios, and verifies the sanitized B06/C06 evidence. It
does not send a transaction, change external chain history, or require secrets.

## Walkthrough (about three minutes)

1. **Create and settle (0:00–0:45).** Open the web console's Create/Replay
view and submit one Business Intent for `1.00 USDC` (`1000000` atomic
units). Show the durable intent ID, Privy authorization, Arc Testnet receipt,
and the final `COMMITTED` state.
2. **Replay and policy denial (0:45–1:30).** Submit the same intent again to
show the existing result. Then try an unauthorized recipient or an amount
above the configured cap. Privy rejects before broadcast: the audit view
shows zero broadcasts and zero settlements.
3. **Lost response and recovery (1:30–2:30).** Run the lost-response fixture.
The intent becomes `UNKNOWN`; the recovery view shows the pinned Subgraph
MCP candidate and Gemini recommendation. OneShot verifies the matching Arc
receipt and commits the existing settlement. Replacement submissions remain
zero.
4. **Safety and release posture (2:30–3:00).** Show `settlementPermission:
NEVER`, the disabled/fail-closed Arc Mainnet profile, and the safe-disable
runbook. Explain that Graph data is candidate discovery only; PostgreSQL and
Arc receipt verification retain financial authority.

## Claims shown

- Arc Testnet + USDC: working testnet evidence; no mainnet transaction is
claimed.
- Privy: authorization and spending policy boundary with zero-effect denials.
- The Graph: live Subgraph MCP + Gemini hashless recovery evidence, with
deterministic Arc verification.
- Circle Agent Stack: intentionally out of scope and not claimed.
1 change: 1 addition & 0 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@
"generate": "pnpm --filter @oneshot/contracts generate",
"lint": "eslint .",
"scenarios:invariants": "pnpm build && node scripts/run-invariant-scenarios.mjs",
"demo:e2e": "pnpm build && node scripts/demo-e2e.mjs",
"test": "pnpm build && vitest run --exclude apps/web/browser/**",
"test:browser": "pnpm --filter @oneshot/web test:browser",
"test:integration": "pnpm --filter @oneshot/storage-postgres test:integration && pnpm --filter @oneshot/api test:integration && pnpm --filter @oneshot/worker test:integration",
Expand Down
41 changes: 18 additions & 23 deletions plan.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# OneShot Product Delivery Plan

Status: working testnet MVP; Arc/Privy evidence live; Circle Agent Stack Arc qualification slice planned but not yet implemented; Graph Studio/MCP recovery proof qualified while the decentralized Explorer deployment remains unallocated; P4 PASS; P5 candidate composes A05/B05/C05 with live frozen-API recovery projection, APG tabs, and Playwright acceptance; P6 open
Status: Gate P6 release candidate; Arc/Privy testnet evidence live; The Graph Studio/MCP recovery proof qualified; Circle Agent Stack intentionally out of scope and not claimed; decentralized Explorer deployment remains unallocated; P4 and P5 PASS; video artifact not provided
Team: exactly three coders
Implementation base: the human-approved commit containing this plan
Research basis: `.agent/research/20260906-integration-decisions.md` and `.agent/research/20260907-subgraph-mcp-clarification.md`
Expand Down Expand Up @@ -47,10 +47,9 @@ not upgrade the Explorer deployment to indexed or allocated status. Sanitized ev
is recorded in `evidence/c06/graph-proof.json` and
`evidence/c06/sanitized-proof.json`, and Gate P4 is `PASS`.

Open work after the current base is the Arc/Circle qualification slice described in
section 5b. It is not implemented or sponsor-qualified merely because the plan names
it, and it must not change the OneShot settlement authority or the fail-closed
recovery defaults.
Open work after the current base is release packaging and human submission review.
Circle Agent Stack qualification is intentionally out of scope for this release
candidate and must not be implied by the architecture or sponsor claims.

## Global product vision

Expand Down Expand Up @@ -94,13 +93,11 @@ Business Intent contract.

## Sponsor and product configuration

The primary product configuration is **Privy + Arc + Circle Agent Stack + The Graph**:
The primary product configuration is **Privy + Arc + The Graph**:

- Privy authorizes and constrains the corporate wallet action.
- Circle Agent Stack is the planned agent-facing Circle surface: a Circle Agent
Wallet with explicit spending controls, connected to Arc/USDC through Circle's
CLI and Skills. It is a bounded service-payment lane for the hackathon demo, not
a replacement for the corporate Privy wallet.
- Circle Agent Stack is deliberately excluded from the active release scope; no
Circle wallet, CLI, Skills, or agent-payment lane is shipped or claimed.
- The Graph discovers candidate transfers when a successful submission lost its
transaction hash or provider response. The production path reaches the live
OneShot/Arc Subgraph through Subgraph MCP, not a direct application GraphQL client.
Expand All @@ -111,10 +108,9 @@ The primary product configuration is **Privy + Arc + Circle Agent Stack + The Gr

This is the final implementation direction for the current event window. The
Graph is load-bearing for automatic hashless discovery, but never becomes
settlement authority. Circle Agent Stack is load-bearing only for the planned
agentic-economy demo lane; the canonical OneShot obligation, policy decision,
durable state transition, and at-most-once settlement remain under OneShot,
PostgreSQL, Privy, and verified Arc evidence.
settlement authority. The canonical OneShot obligation, policy decision, durable
state transition, and at-most-once settlement remain under OneShot, PostgreSQL,
Privy, and verified Arc evidence.

The Graph submission targets the AI Tooling or AI Use Case track. One custom
Subgraph does not satisfy the Composable/Standardized track. One live Subgraph
Expand All @@ -135,7 +131,7 @@ name each claimed track explicitly.
| Privy | Best financial flow | The committed USDC transfer is a completed financial flow through a Privy wallet action |
| Arc | Launch on Arc Testnet & Push to Mainnet | Primary Arc claim: working testnet product plus the disabled Mainnet profile, deployment manifest, readiness probe, and rollback runbooks |
| Arc | Best DeFi / Onchain Finance Application | Secondary Arc claim: conditional, multi-step USDC settlement on Arc with programmable authorization |
| Arc | Best Agentic Economy Application with Circle Agent Stack | Planned Circle Agent Stack lane: an agent-controlled, capped Arc USDC service payment with a visible approval/denial path; `NOT VERIFIED` until Circle tools, live payment evidence, and the end-to-end intent trace exist |
| Arc | Best Agentic Economy Application with Circle Agent Stack | Not claimed; Circle Agent Stack is intentionally out of scope for this release candidate |

Not claimed, and the reason:

Expand Down Expand Up @@ -181,16 +177,12 @@ settlement contract; never weaken authorization to obtain a cleaner lookup.
| Execution worker | OneShot service | Acquire submission ownership and execute the approved settlement |
| Reconciliation service | Agent and operator | Resolve ambiguous outcomes without blindly paying again |
| Audit and recovery timeline | Company and supplier | Explain what happened, which evidence is authoritative, and what action is safe |
| Circle agent-service lane | Autonomous agent | Discover/pay a bounded Arc USDC service through Circle Agent Stack, while OneShot records the intent, cap decision, result, and evidence |

```mermaid
flowchart LR
Company[Company operator] -->|wallet policy and limits| Privy[Privy]
Agent[Autonomous agent] -->|stable business intent| API[OneShot API]
Agent -.->|requests paid work| SupplierAPI[Paid API or digital supplier]
Agent -->|agent-service profile| CircleStack[Circle Agent Stack]
CircleStack --> CircleWallet[Circle Agent Wallet with spend caps]
CircleWallet -->|bounded USDC service payment| Arc
API --> Core[OneShot domain]
Core --> DB[(PostgreSQL authority)]
DB --> Worker[Execution worker]
Expand Down Expand Up @@ -227,7 +219,7 @@ Privy rail or the explicitly scoped Circle service-payment rail, never both.

## 1. Mission and v1 release

Deliver a working application that accepts one approved Business Intent, survives retries, crashes, duplicate delivery, parallel workers, and ambiguous provider responses, and produces at most one committed USDC settlement on Arc Testnet through a Privy-controlled corporate wallet. The submission extension adds one bounded Circle Agent Stack service-payment lane for an agentic-economy demo; each demo intent selects exactly one payment rail and cannot double-charge. The same build must include a fail-closed Arc Mainnet profile, deployment and rollback procedure, and readiness evidence so official mainnet values can be enabled without redesigning the domain. Known-identity recovery uses OneShot, Privy, and direct Arc evidence; hashless automatic recovery uses The Graph for candidate discovery.
Deliver a working application that accepts one approved Business Intent, survives retries, crashes, duplicate delivery, parallel workers, and ambiguous provider responses, and produces at most one committed USDC settlement on Arc Testnet through a Privy-controlled corporate wallet. The same build includes a fail-closed Arc Mainnet profile, deployment and rollback procedure, and readiness evidence so official mainnet values can be enabled without redesigning the domain. Known-identity recovery uses OneShot, Privy, and direct Arc evidence; hashless automatic recovery uses The Graph for candidate discovery.

The release claim is:

Expand Down Expand Up @@ -393,7 +385,7 @@ evidence, so frontend work can start while B is still obtaining live proof.
Gate P4 remains the composition and live-proof gate. This rule changes only when
the contract is published, never what P4 must prove.

### Circle developer-tool surface
### Deferred: Circle developer-tool surface (not in this release)

The primary Circle implementation is **Circle Agent Stack**, using the Circle
CLI and Skills to provision/use an Agent Wallet with explicit spending controls.
Expand Down Expand Up @@ -425,7 +417,7 @@ not default scope: each requires a concrete user-facing Arc use case, a tested
adapter, and live evidence. No Circle product is added solely to widen the logo
surface.

### Circle acceptance checklist
### Deferred Circle acceptance checklist

The Circle/Arc slice is `NOT VERIFIED` until all of the following are recorded:

Expand Down Expand Up @@ -760,7 +752,10 @@ This is the frontend unlock gate.
### P6 — release candidate

- A06, B06, and C06 evidence bundles compose into one repeatable testnet demo.
- `pnpm demo:e2e` runs the invariant suite and verifies the sanitized 1.00 USDC,
Privy-denial, and lost-response evidence without secrets or external writes.
- The disabled Arc Mainnet profile passes configuration, deployment-manifest, readiness, safe-disable, and rollback checks without sending a mainnet transaction.
- Judge-facing walkthrough is documented in [`docs/DEMO_SCRIPT.md`](docs/DEMO_SCRIPT.md); no video artifact is included in this candidate.
- Sponsor qualification cites working code, tests, live evidence, network, and limitations.
- Safe-disable and recovery runbooks work without manual database surgery.
- Exact candidate tree passes repository checks and mandatory independent review gates before human merge.
Expand Down Expand Up @@ -1046,7 +1041,7 @@ Before Gate P6 can pass, confirm:
- UI has no direct/bypass/force-pay action and labels authority/freshness correctly.
- Demo/reset instructions require no unsafe database surgery or external-history rewrite.
- Evidence, repository, logs, screenshots, fixtures, source maps, and reviews contain no secrets.
- Claimed partner tracks match the sponsor claim mapping in section 5. Circle Agent Stack is a planned Arc claim and remains `NOT VERIFIED` until the acceptance checklist in section 5b is complete; Hedera remains out of scope.
- Claimed partner tracks match the sponsor claim mapping in section 5. Circle Agent Stack is intentionally out of scope and not claimed; Hedera remains out of scope.
- Every Arc requirement row in section 5b has a delivered artifact, including the README architecture diagram and the explicit track naming in the submission.
- Public README and submission text contain no statement that undermines a claimed dependency; justifications cite measured numbers.
- Privy and Arc claims use the qualification standard. The Graph claim requires live hashless discovery plus meaningful recovery-agent automation; otherwise it is `NOT VERIFIED` and removed from the submission.
Expand Down
50 changes: 20 additions & 30 deletions plan_missing_parts.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,37 +21,28 @@ exist.

### Sponsor-submission deliverables

- Record the required two-to-four-minute demo video/presentation.
- Prepare submission text that explicitly names the claimed Arc tracks and
links the public repository and evidence.
- Use [`docs/DEMO_SCRIPT.md`](docs/DEMO_SCRIPT.md) for the judge-facing walkthrough;
no recorded video artifact is included in this candidate.
- Do not include a The Graph qualification claim unless its live MCP and model
evidence is complete.

The repository contains demo runbooks and evidence templates, but not a
recorded submission artifact.
The repository contains demo runbooks, evidence, and a repeatable offline demo;
the recorded submission artifact remains intentionally absent.

### Arc/Circle Agent Stack qualification
### Circle Agent Stack (out of scope)

The current base has a real Arc/Privy settlement and a qualified live Graph
recovery path, but it does not yet contain a Circle Agent Stack integration.
The remaining Arc sponsor work is therefore an implementation and evidence
slice, not a documentation-only claim:
Circle Agent Stack is intentionally excluded from the Gate P6 release candidate.
No Circle wallet, CLI, Skills, or agent-payment claim is supported by this bundle.
Privy remains the canonical authorization rail; a future Circle lane must preserve
the OneShot policy/idempotency core and acquire its own evidence.

- add a provider-neutral agent-service payment port backed by Circle Agent
Stack/Agent Wallet and Circle CLI/Skills;
- configure explicit per-transaction and daily spending controls without
committing credentials or relying on an unbounded agent wallet;
- execute one real Arc Testnet USDC service payment or paid request, bind it to
a durable OneShot Business Intent, and verify the Arc receipt/response;
- prove over-cap/denied and lost-response behavior preserves zero duplicate
settlement and `UNKNOWN` reconciliation; and
- capture sanitized code, test, live transaction, architecture, and 2-4 minute
demo evidence before claiming the Arc Agentic Economy track.
Any future Circle implementation must add bounded spend controls, a live Arc
payment, and its own sanitized evidence before a Circle track can be claimed.

Privy remains the canonical corporate authorization rail. Circle must not bypass
the OneShot policy/idempotency core or gain authority over hashless recovery.
Hedera HTS and Hedera x402 work are intentionally not part of this submission
window.
Circle must not bypass the OneShot policy/idempotency core or gain authority over
hashless recovery. Hedera HTS and Hedera x402 remain out of scope.

## Completed in Gate P4

Expand Down Expand Up @@ -86,9 +77,9 @@ closed.
### Gate P6 release candidate

Release runbooks, safe-disable behavior, a disabled Mainnet profile, and
Privy/Arc/The Graph testnet evidence exist. P6 remains open until P5 completes, the
repeatable end-to-end demo is captured, selected sponsor claims are supported,
and the exact release candidate completes CI plus Gate A and Gate B review.
Privy/Arc/The Graph testnet evidence exist. `pnpm demo:e2e` and
`docs/DEMO_SCRIPT.md` provide the repeatable demo; video is intentionally absent.
P6 remains subject to CI, Gate A, Gate B, and human release review.

## Potential Dependencies and Blockers

Expand All @@ -99,12 +90,11 @@ and the exact release candidate completes CI plus Gate A and Gate B review.
| P5 live UI acceptance | RESOLVED in candidate: configured Cloud Run is reachable and frozen-API Playwright coverage exists | Await exact-tree review, CI, and human merge. |
| P6 release | P5 completion, CI, exact-tree reviews, and human demo/submission decisions | Keep release candidate and sponsor claims incomplete. |
| Arc Mainnet | Official published network values and explicit human authorization | Preserve the disabled, fail-closed profile. |
| Circle Agent Stack Arc lane | Agent Stack/Agent Wallet implementation, supported-chain confirmation, spend controls, live payment, and evidence | Keep the Circle Arc claim `NOT VERIFIED`; continue the proven Privy/Arc path until the complete acceptance checklist passes. |
| Circle Agent Stack Arc lane | Agent Stack/Agent Wallet implementation, supported-chain confirmation, spend controls, live payment, and evidence | Intentionally out of scope; do not claim the Circle track. |

## Immediate Priorities

1. Complete Gate A, CI, Gate B, and human review for the Gate P5 candidate.
2. Implement and test the bounded Circle Agent Stack Arc service-payment lane;
keep Privy as the canonical OneShot settlement authority.
3. After P5 and the Circle evidence pass, capture the demo/submission artifacts
and perform the P6 release-candidate CI and review sequence.
2. Prepare final submission text using checked-in evidence; keep Circle out of
the claimed scope.
3. Perform the P6 release-candidate CI and review sequence.
42 changes: 42 additions & 0 deletions scripts/demo-e2e.mjs
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
#!/usr/bin/env node
/** Gate P6 demo: deterministic, offline, and safe to rerun. */
import { readFileSync } from 'node:fs';
import { resolve } from 'node:path';
import { fileURLToPath } from 'node:url';
import { runAllInvariantScenarios } from '../apps/worker/dist/index.js';

const root = resolve(fileURLToPath(new URL('..', import.meta.url)));
const proof = JSON.parse(readFileSync(resolve(root, 'evidence/c06/sanitized-proof.json'), 'utf8'));

function fail(message) {
console.error(`DEMO FAIL: ${message}`);
process.exit(1);
}

const results = await runAllInvariantScenarios();
if (results.some((entry) => entry.status !== 'PASS' || !entry.atMostOneSettlementSatisfied)) {
fail('invariant scenarios did not pass');
}

if (proof.amount_atomic !== '1000000' || proof.settlement?.status !== 'CONFIRMED') {
fail('recorded 1.00 USDC settlement proof is invalid');
}
if (
!proof.denials?.length ||
proof.denials.some((entry) => entry.broadcast_count !== 0 || entry.settlement_count !== 0)
) {
fail('policy denial proof does not show zero external effects');
}
if (
proof.recovery?.lost_response_initial_state !== 'UNKNOWN' ||
proof.recovery?.external_recovery_submissions !== 0 ||
proof.recovery?.total_settlements_for_intent !== 1
) {
fail('lost-response recovery proof violates at-most-once settlement');
}

console.log('\nGate P6 demo PASS (testnet evidence + offline invariants)');
console.log('1.00 USDC: CONFIRMED on Arc Testnet (atomic amount 1000000)');
console.log('Privy policy denial: 0 broadcasts, 0 settlements');
console.log('Lost response: UNKNOWN -> reconciled existing payment, 0 replacement submissions');
console.log('No video artifact is included; use docs/DEMO_SCRIPT.md for the live walkthrough.');
Loading