Appearance
SDLX Project Progress — 2026-08-03 Detailed Snapshot
Updated: 2026-08-03
Status: Historical release snapshot. Current status is maintained in Current Progress; paths and counts below are preserved as evidence of this snapshot and may refer to documents that were subsequently archived.
Progress Scope
The forward design is docs/agent-first-system-design-prd.md. Phase A/P0 and Phase B/C are implemented and qualified at the software-contract level: routine lifecycle advancement is automatic, direct atomic control shares policy and Operation records, normal UI actions are backend-provided, Agent decisions are traceable/replayable, and the normal stack has four deployable boundaries.
The 2026-08-03 maintainability convergence baseline is implemented. Pinned static gates, strict Engineering Console diagnostic budgets, shared RunSpec and sandbox runtimes, canonical deployment topology, public Capability v2 compatibility checks and architecture regression tests are now in CI. The detailed change/evidence record is
docs/releases/2026-08-03-maintainability-convergence.md.Pre-PRISM Golden Loop software P0: approximately 90-93% complete.
Expanded PACE-PRISM-ASCEND closed-loop P0: 100% complete against its nine software release criteria.
ASCEND primary-interface and extensible-agent P0/P1: 100% complete against the nineteen criteria in
docs/ascend-primary-interface-prd.md.ASCEND hierarchical primary-interface P2 software scope is implemented and qualified, including Human Task, durable conversation, Take over, embedded reports, Home projection, and desktop/mobile primary-flow coverage.
ASCEND routine advancement now excludes paused and terminal Coordinations, stores bounded job-result summaries instead of complete mutable projections, and applies indexed, configurable high-volume retention pruning. This closes the SQLite growth failure that allowed periodic automation jobs to overwhelm the Control database and block the public surface on disk-page reads.
LabBridge now projects one versioned planar
sdlx.spatial-map/v1fromconfig/maps/<map-name>/map.yaml. Current Lab, Bridge Spatial, Rehearsal 2D, and Rehearsal 3D consume the same bounds/layout/device X/Y; new execution snapshots freeze the complete map for stable historical replay. DeviceModel YAML remains the authority for device appearance and behavior, while devices without an X/Y placement remain explicitly unplaced instead of receiving a renderer-invented position.Current Lab, LabBridge Spatial and Rehearsal Replay now render that contract through one
packages/ui-lab-mapimplementation. Current Lab and Bridge read live LabBridge state; each Rehearsal keeps its frozen execution-time map. All three surfaces support the same 2D/3D coordinate conversion, fitted 3D camera, fullscreen controls, generic fallback and responsive layout. A device package may optionally declareassets/model.glband/or a transparentassets/top.webp/top.png; LabBridge serves only validated package-local files. Visual files are display-only and do not participate in DeviceModel, evidence or experiment-version tracking.The shared map interaction layer now defaults to a light 2D/3D presentation and provides a persistent light/dark preference on all three surfaces. Map chrome, camera/view/theme/fullscreen controls, current-action context and the Rehearsal playback rail occupy separate document-flow regions instead of competing absolute overlays. The persistent 3D device roster has been removed; generic 2D markers, GLB models, declarative geometry and fallback models are directly hoverable/tappable/selectable and open one normalized device inspector. Shared renderer labels now come from the ASCEND and LabBridge English, Chinese and Spanish locale dictionaries. The spatial canvas has a visible keyboard focus state; arrow/Home/End traversal and Enter/Space/Escape provide the same inspection path without restoring a persistent device list. Non-fullscreen 2D canvases now derive their height from the frozen/live map's metric aspect ratio instead of a viewport-width minimum, including on mobile. Generic 2D device bodies fill the metric footprint calculated from each DeviceModel instead of collapsing to a fixed narrow grid item. Room titles render in a reserved top band after walls/obstacles with a contrast halo, so long zone names remain readable above utility spines. All 31 built-in DeviceModel YAML packages now declare a top-level metric
visualization.footprint_m; 2D rendering no longer reuses GLB-onlymodel_3d.fit_m. Existing default SimFleet profiles were version-upgraded in place, including the retainedamr1, without resetting device state or layout. ASCEND's sticky application bar owns a higher global stacking layer than map chrome, so the Console service menu cannot be covered by 2D/3D controls. Rehearsal environment revision, Agent activity, unplaced devices and playback controls remain visible outside the spatial plane. Checked-in Playwright image baselines cover Current Lab, Rehearsal Replay and LabBridge Spatial across 2D, 3D, light and dark desktop states plus Current Lab/Rehearsal mobile states. Both production builds pass, and the complete browser matrix finishes with 40 passed, 24 intentionally skipped and no failures. Desktop, tablet and Pixel 7 qualification also covers theme/view persistence, inspector interaction, fullscreen, replay and non-overlap.LabBridge Spatial now includes a visual calibrated planar map editor. It starts from the selected revision, edits metric bounds/origin/orientation, supports grid-snapped obstacle/restricted-zone handles, draggable station/device X/Y, two-point distance calibration, shared 2D/3D preview, and save-as-new-draft. Backend activation validates finite in-bounds geometry and atomically applies the revision's station/device layout without changing historical Rehearsal snapshots. Raw JSON remains read-only diagnostics rather than the main flow.
All 31 built-in DeviceModels now contain a package-local static GLB and adjacent source/license attribution. Exact or credible category-level public assets are used where available; close substitutes are explicitly marked as visual-only rather than physical, kinematic or metrology models. Optional YAML
fit_mnormalizes heterogeneous model dimensions while preserving package ownership and the declarative fallback. All GLBs pass format validation and the public same-origin asset proxy serves 31/31 without 4xx. Equipment remains static; the current Rehearsal action is indicated by a prominent game-style 3D arrow whose status treatment follows running/failed/completed.workspacea-map-r1is now a version-controlled, built-in and immutable complete laboratory baseline. It places all 31 virtual devices in four workflow-oriented zones—automation/logistics, preparation, measurement/testing and characterization—using the same X/Y projection consumed by Current Lab, LabBridge Spatial and future frozen Rehearsals. The console marks it as built-in, exposes no delete/overwrite action, and edits only by saving a new immutable map revision. Live public verification reports 31 placed and 31 modeled markers.Rehearsal Replay now makes device-to-device workflow progression visible in both map modes. Adjacent same-branch segments produce one deterministic handoff: 2D uses a curved directional path and information packets; 3D uses the same source/target X/Y as an elevated packet flow while retaining the current-device objective arrow. Shared labels are derived only from recorded output/input keys, with identifier-input or explicitly predicted-context fallback wording. The old arbitrary lower-left 2D origin line is removed. Generic 2D equipment no longer collapses under consumer button padding; it renders a sized footprint card with a derived short device mark such as XPS, AMR or AB.
Agent-first system design Phase A/P0: 100% complete against the seven-row qualification matrix in
docs/agent-first-system-design-prd.md.Agent-first system design Phase B/C: 100% complete against the eight-row qualification matrix in
docs/agent-first-system-design-prd.md.Agent-first system design Phase D/P2 maintainability and productization is 10/12 gates passed and 2 operationally blocked. Production and physical certification remain outside the software completion percentage.
Agent architecture convergence Phase E items 5-8 are complete: ordered multi-intent PlanRevision, Specialist AgentRun lineage, executable Runtime Profile constraints, and Composer model path migration. Prompt/profile quality thresholds remain open.
The CoN4Cl real-data autonomous study-design benchmark Phase F software P0 is implemented and live-stack qualified: sanitized XPS fixture conversion, a v2 one-click Research Goal preset, generic factorial decision context/validation, sibling material lineage, one-loop-per-arm Composer modules, a read-only LabBridge fixture controller, and an evidence-bound PRISM XPS Skill. The default ASCEND P2 Home now lists the direct-run preset in the normal new-goal workspace, shows its objective, success criteria, factor design, and fixed safety settings, and can either run it unchanged or create a copy with an edited title, goal, and success criteria. Data sources, round limits, automation policy, study design, and safety constraints cannot be changed through that copy form. Desktop and mobile browser tests cover both paths. A direct preset run completed three independent real-data import/analysis Iterations, created the evidence-bound fourth prospective Iteration, and saves it as a completed design without selecting equipment or creating a PACE furnace loop. Real execution is now a separate derived Experiment: its picker and backend accept only compatible, online, registered tube-furnace capabilities carrying explicit
execution + physical + physical_evidenceprovenance. Missing SOP facts belong to that physical Experiment. Physical furnace qualification remains open.Governed device recovery is implemented in software: stop-scope approval, an all-Experiment cancellation barrier, per-device automatic or Human Task reset, idempotency, verification-aware aggregate results, and a hard no-resume boundary. Physical safe-state qualification remains a hardware release gate.
Agent-native virtual-lab Phase 0 and the renderer-independent Phase 1 vertical slice are complete. LabBridge persists checksum-verifiable ExecutionSnapshots, clones isolated Rehearsal environments, runs deterministic capability-intent branches with optional fault profiles, supports immutable fork/reset and token-revoking cancel, records ordered branch events, and stores only hashes of environment-scoped capability tokens. A failed branch can now drive a new evidence-linked PlanRevision and a parent-linked recovery branch. ASCEND exposes a structured comparison of findings, failures, duration, conflicts and plan diffs; selects only a completed branch for the current revision; and revalidates current execution revision, typed capability bindings and Policy.
ALLOWautomatically creates a checksum-bound RunSpec and executes it;ASKcreates one typed Attention containing recommendation, alternatives, plan diff, findings and execution impact, then executes after approval without a second device prompt;DENYrejects without execution. Stale revisions cannot be promoted or applied. Direct atomic plans bind against the current LabBridge capability catalog; reusable workflows retain Composer ownership. Rehearsal output remainspredicted; PACE rejects it from committed result extraction. Current SimFleet remainsexecution + simulated + simulated_evidence, while unclassified legacy controllers remainunknown + unverified. SimFleet's 31 built-in device types now use uniformdevice_models/<type>/device.yaml + model.pypackages. The Surrogate runner and isolated Rehearsal branches reuse the same bounded input/state/output behavior; Rehearsal still creates only predicted output and no formal Operation.Agent-native virtual-lab Phase 2 and Phase 3 are complete. ASCEND now persists renderer-neutral scene identities and ordered events in schema migration v14, aggregates current LabBridge stations, device positions, carrier custody and active Operations, and exposes current-scene, snapshot and incremental-event read APIs through generated UI contracts. The Lab workspace presents the same stable-ID state in Web 2D and a browser-native React Three Fiber/Three.js renderer. Both views show Agent activity, Rehearsal/Execution provenance, branch failures, findings, Plan diffs, promotion/Attention and replay state. Device appearance is configured in each DeviceModel
device.yamland projected through LabBridge Capability -> ASCEND SceneProjection. The 3D frontend is a generic declarative geometry/optional glTF renderer with no device-name or device-category mapping, plus camera presets and responsive mobile layout. WebGL failure falls back to the same 2D reducer, and renderer interaction produces no virtual-lab write requests. Rendering runs on the client GPU; the remote SDLX server still does not need a GPU. Unreal remains optional Phase 3.5 showcase work. Rich calibrated physical DeviceModel dynamics and physical substitution remain Phase 4 work.The preset lifecycle gap found during UI qualification is closed. Automatic Composer-backed iterations now rehearse supported semantic capability steps against a frozen LabBridge snapshot before PACE Prepare/Start. The resulting session and ordered events are materialized immediately, so short synchronous runs remain replayable. Home exposes the latest active rehearsal as a compact status and replay entry; each experiment record lists retained rehearsal sessions and opens them in a read-only replay dialog. Lab is reserved for the current governed LabBridge execution map, current devices, camera and Take Over. Rehearsal remains predicted; it does not promote or duplicate the immutable Composer execution. Branch workers now persist bounded per-intent started/completed/failed events. ASCEND preserves them as ordered raw
rehearsal.action.*audit events and also projects deterministic replay segments that merge started/completed or started/failed byintent_id. Branch lifecycle, finding, revision, promotion and Attention events are not rendered as equipment frames. Legacy reconstruction from immutable plan revisions remains available for older recordings. The shared reducer drives both 2D and 3D device status, action labels, device highlighting, and visible Agent-to-device flow during playback instead of inheriting an always-idle execution snapshot. Legacy PlanRevision intent wrappers are unwrapped when reconstructing bindings, and rehearsal-referenced catalog devices without a spatial marker are retained as unpositioned scene entities so 3D action linkage does not silently disappear. Terminal legacy scene projections are deterministically repaired into lifecycle order, removing superseded unbound action frames; action effects now play between branch start and completion. The 3D camera remains under researcher control; transient flow and a single device halo follow the corresponding action segment. Replay controls now live inside the virtual viewport, advance by experiment action rather than raw event sequence, and support viewport fullscreen. Package-derived intent identities are allocated per PlanRevision, so two experiments rehearsing the same workflow cannot collide and leave automatic advancement retrying atREADY_TO_RUN.Added a direct
rehearsal_3d_multi_device_showcasepreset and deterministic Composer module for external demonstrations. Its seven registered semantic actions move across the mobile manipulator, analytical balance, electron microscope, and XPS spectrometer, producing real ordered Rehearsal events while leaving high-risk governed execution behind normal Policy review. Direct presets no longer require the factorial-study extension when their v1 contract supplies localized acceptance criteria and bounded constraints.Combined approved software P0: approximately 93-95% complete.
The percentages use different denominators and must not be merged. The latest release gate is the nine acceptance criteria in docs/pace-prism-ascend-closed-loop-prd.md; currently 9 of 9 are met. Physical integration and production deployment remain separate qualification work.
Working Foundations
- LabBridge provides the common Gateway boundary for MQTT/ESPHome nodes, controller devices, operations, artifacts, audit, MCP, and Admin Web.
- SimFleet provides 31 maintainable built-in device model packages, including AMR, AGV, fixed arm, and mobile manipulator contracts. Every type has the same
device.yaml + model.pylayout under its own directory. Import, grouping, enable, edit, YAML view, individual delete, and delete-all are implemented. - Robot simulation exposes carrier/custody state, route/station/service-port checks, fixed station modes, and deterministic failure injection.
- Composer runs on nanobot and owns deterministic skill/module selection, capability binding, package generation, validation, and package review.
- LabFlow has strict workflow YAML, preflight, DAG scheduling, parallel/join, locks, approvals, safe-stop, audit, artifacts, and run export.
- PACE owns immutable loop packages, runtime orchestration, result contracts, process-scoped experiment facts, evidence, incidents, and diagnostics.
- ESPHome node01/node02 firmware layouts, build/flash scripts, MQTT conventions, sensors, relay, and OLED support are present.
Completed In This Iteration
Unified the task logic of the three shared-map consumers. Rehearsal now opens at the first recorded action, focuses the participating devices by default, supports context reveal and playback speed, collapses nonessential branch audit, and settles completed handoffs. Current Lab adds device search, active/offline/unplaced filters, a live refresh timestamp and progressive disclosure for engineering controls. LabBridge moves its mode selector before the workspace, searches and prioritizes unplaced devices, supports drag source placement, uses explicit remove-from-map language, and removes the duplicate live canvas while editing a map revision. The shared inspector is now a stable overlay/mobile sheet, and the 3D camera adapts to portrait viewports.
Reworked Rehearsal playback around experiment actions. The API keeps the full append-only SceneEvent stream for audit and adds renderer-neutral
segmentsthat merge each intent's started/terminal pair. The experiment-record dialog now places restart/previous/play/next, seek and step summary inside the virtual scene, supports native fullscreen with a bounded embedded-browser fallback, and keeps desktop/mobile layouts responsive. Lifecycle, finding, Plan revision, promotion and Attention events remain visible in their proper record surfaces instead of becoming one-frame animation dots.Removed frontend device-name/category visual branching. Mobile manipulator, balance, electron microscope and XPS spectrometer now declare versioned generic geometry in their own
device_models/<type>/device.yaml; LabBridge validates and publishes it through Capability v2, and ASCEND carries it into scene entity details. The shared 3D renderer only understands generic box/cylinder/sphere or approved glTF config and uses one generic fallback for missing config. Profile version upgrades ensure existing default SimFleet devices receive the new YAML without resetting placement, scheduling or enabled state.Separated prospective study design from physical execution. The Co-Cl fourth Iteration now completes after the Agent saves its evidence-backed factor proposal; it no longer opens a furnace form or lets Composer bind the SimFleet furnace. A backend-provided action creates a separate physical Experiment only after the researcher chooses a compatible real furnace. LabBridge publishes explicit semantic and simulated-device provenance, Composer rejects simulated fallback, and both the preparation UI and backend reject device contracts that lack the heat-program fields used by the module.
Fixed value-entry
Needs youitems end to end. Producer-declared Attention actions can now include a JSON Schema form and declare which choice requires it; ASCEND renders and validates the form, records the submitted values without overwriting the scientific candidate, and returns them with the selected decision. The separate Co-Cl physical-execution record asks for the approved furnace method, risk assessment, and missing setup values only after compatible real equipment is selected. Composer and LabBridge use the same names and the furnace workflow now emits the registeredgas_flow_sccm,steps, andcooling_modecapability payload. Enum fields require an explicit human selection. Backend, module, LabBridge, generated API contract, and Playwright form-submission tests cover the path.Fixed repeated ASCEND intervention handling. If a researcher resumes a
Needs youitem and the retried Composer attempt still lacks the required local SOP inputs, ASCEND now keeps the resolved item as history and creates a new open Attention cycle. The Coordination and Home projections therefore no longer disagree about whether human input is pending.Added original-request disclosure to every ASCEND Experiments row without replacing the localized concise experiment name. Added on-demand English, Simplified Chinese, Spanish, Japanese, and Korean report translation through a no-tool
report-translator/v1shared-runtime profile. Translation requests use restart-safe durable jobs, persist source hashes, status, translated Markdown, AgentRun lineage, and remain independent of the current UI language. The Evidence page polls only while requested work is pending and enables a target language after completion. Each round can now download one ZIP containing the committed PRISM analysis archive, structured result JSON, original Markdown report, and all completed translations. SQLite migration v10, typed OpenAPI contracts, backend lifecycle/bundle tests, and the desktop Playwright journey cover the feature.Added durable multilingual experiment names. ASCEND Intake v3 and the interactive Scientist now compress a complete research request into equivalent short names in English, Simplified Chinese, and Spanish before creating the Coordination; the full goal remains unchanged. Presets reuse their reviewed localized titles, and clone/restart preserves the title map. Home, Experiments, experiment detail, round, evidence, and cleanup views select the saved name for the current interface language.
research-brief-review/v2makes all three names a bounded required model output. Needs-you projection now prefers the declared human-facing blocking reason, and Composer capability gaps are deduplicated instead of repeating a generic error.Moved the ASCEND Experiment page's round list directly below the experiment heading, ahead of the next-outcome, controls, conversation, and activity sections. Each round now shows its user-facing phase and exposes a direct result link when PRISM evidence is committed. Added round-specific evidence and report read routes so opening an earlier round cannot accidentally display the latest round's result. Experiment detail, round, and evidence headers now prefer the concise display title instead of rendering a full research goal as the page name. Backend projection tests and the desktop browser flow cover the ordering and round-bound result navigation.
Removed controller and SimFleet heartbeat churn from LabBridge's durable SQLite registry. Live online/freshness leases and repeated controller state values now use a process-shared per-user runtime directory, normally backed by tmpfs, so Admin and all MCP processes see one current status without competing with operation, artifact, registry, or audit writes. Unchanged controller registration no longer rewrites device, capability, or state rows. SQLite lock back-pressure is returned as retryable HTTP 503, and the XPS fixture controller retries transient registration, heartbeat, and poll failures instead of exiting. ASCEND now preserves Composer's concrete validation reason (including the offline device and capability), stops polling the same immutable blocked job, and creates a fresh Composer attempt only through the existing retry action; generic blocked work is no longer mislabeled as exhausted automatic recovery.
Fixed two recovery gaps found while replaying the live Co-Cl XPS preset. ASCEND stage retry now gives a user-requested Composer attempt a new idempotency reference instead of receiving the old immutable blocked job; transport retries within one attempt still retain their stable key. PRISM now gives an otherwise successful Analyst one bounded continuation when its first response leaves
report.mdoranalysis.jsonunwritten. The continuation must finish throughwrite_analysis_outputor explicitly commit a PARTIAL result; a second incomplete response still fails deterministic validation.Enabled outbound network access for the ASCEND Scientist, Composer Planner, and PRISM Analyst execution containers through Podman
bridgenetworking.execmay now useuv,pip,curl,wget, and other network clients; the effective Profile recordsnetwork_policy: unrestricted. The shared audited public-web access remains available for the interactive ASCEND Scientist, Composer Planner, and PRISM Analyst profiles through the shared read-onlyweb_searchandweb_fetchtools. Private/local targets remain blocked, fetched content is marked untrusted, and calls are retained in Agent trace. Profile/prompt versions, PRISM preflight, rendered nanobot configuration, role instructions, examples, and cross-module tests were updated together.Rewrote researcher-facing English and Chinese across the ASCEND primary workspace, preset details, progress states, Attention, experiment cleanup, About, Take over, and the adjacent Advanced explanations. Internal phrases such as factor-valid, immutable candidate, terminal outcome, deterministic execution, and common precursor lineage are replaced with direct descriptions of what the system is doing. The Co-Cl XPS preset now shows localized factor names and levels in English and Simplified Chinese while keeping stable execution IDs and values in the backend. Preset IDs, schema versions, scientific constraints, factor values, execution order, and deterministic guards remain unchanged.
Added the first real-data autonomous study-design benchmark from the supplied CoN4Cl/CoN4O/N-CSs XPS series. Three legacy workbooks are represented only by deterministic sanitized CSV/JSON derivatives with source SHA-256 and explicit energy-correction metadata; the thesis and original XLS files remain external. A direct-run, four-Iteration preset analyzes the three sibling historical arms through independent Composer/PACE/PRISM evidence boundaries, then asks ASCEND to select a legal non-duplicate prospective factor combination. The expected fourth arm is absent from the preset, Skill, and deterministic context. Candidate guards validate allowed levels, common precursor lineage, historical order, duplicates, full prior-analysis citations, and unknown local SOP fields without computing the answer. The generic prospective module contains a real approval/setup boundary before qualified 900 °C furnace execution, so the software cannot manufacture a physical fourth result. Qualification currently covers the default P2 Home one-click path on desktop/mobile, preset/API, study guards, Composer packages, fixture integrity, LabBridge controller contract, and PRISM analysis. Live-stack qualification now also covers Composer request idempotency, fixture heartbeat and terminal evidence, PACE artifact embedding, independent ASCEND decision retries, creation of the fourth Iteration, and the deterministic Composer-input
ASKprojection. The final prospective arm iscobalt_source=absentandnh4cl_treatment=present, cites all three committed analyses, preserves the common source, and has no PACE Loop. Physical device and furnace qualification remain to be performed.Added a responsive ASCEND About surface with a restrained institutional presentation, replaceable Tohoku University/AIMR logo slots, project design principles, and explicit project leader, supervisor, and main developer roles. The page is available from desktop and mobile primary navigation in English, Chinese, and Spanish. The hero and following sections now use a more compact vertical scale so the first card no longer dominates the viewport.
Added an explicit Self-aware mode to Goal conversation. Enabled turns build a content-addressed source snapshot from tracked and unignored source-like files, exclude local config/environment files, secrets, databases, object/runtime storage, caches, logs, binaries and build products, and mount only that snapshot read-only at
/workspace/sdlx-source. The repository root is never mounted, outbound network is available, while domain authority still flows through the existing typed tools. Chat migration v9 persists the mode and linked AgentRun; Scientist Profile v8/context v6/sandbox v3 records the exact snapshot hash, filter policy and full visible tool versions. Standard turns remove the source mount from the effective sandbox plan.Consolidated Experiment creation and history management. Home and Experiments no longer repeat a header-level New Experiment action; Home's New conversation context is the normal creation entry. Experiments now lists the complete active/terminal/archived history and offers deletion only for backend-declared deletable rows. Confirmation reconciles all record owners, previews the full indexed Coordination chain, and starts a durable
require_allcleanup in downstream-first order. Unavailable owners or active/protected related records reject the request; a later owner failure preserves the ASCEND root for a visible retry instead of leaving an undiscoverable partial chain.Added a confirmed experiment-record factory reset to Experiments. It verifies all six owners, stops active Agent replies and nonterminal Coordinations (including active Composer, PACE, and PRISM work), waits for terminal owner projections, and then runs one downstream-first durable cleanup. Failure to stop or reach an owner prevents deletion; a later owner failure retains ASCEND roots. Presets, settings, devices, Skills, and workflow definitions are preserved, so a clean Experiment can be started immediately. Terminal LabBridge Human Task/Operation pairs are now projected and removed as one dependency-ordered record chain instead of misclassifying their already succeeded operations as active and permanently blocking factory reset. A successful reset also clears ASCEND's Experiment-linked Attention/Inbox mirror, including orphaned late producer events; primary Home and Attention projections suppress any later replay whose Experiment root no longer exists while retaining unrelated platform and device-control audit entries. The reset entry remains available when no ASCEND Experiment roots exist, so orphaned downstream records such as Composer deliverables can still be reconciled and removed. ASCEND's API preset test now intercepts Composer creation locally and fails on every undeclared external request instead of writing test packages into a running Composer.
Qualified every engineering console through ASCEND's same-origin proxy. LabBridge now recognizes and preserves the proxy path prefix, so the embedded Lab map opens the map route instead of falling back to Overview. ASCEND now forwards LabFlow's server-sent event stream incrementally instead of buffering it until timeout. Composer and PRISM explicitly prebundle the Markdown stack used by the shared chat component, preventing their Vite development consoles from rendering blank on CommonJS dependencies. The six-case Playwright suite now covers Composer, LabBridge, the proxied LabBridge map, LabFlow, PACE, and PRISM and passes without page errors.
Closed the standalone New conversation lifecycle gap. New conversation now has a confirmed Discard action when idle; the backend deletes its durable ASCEND turns/session and its Agent runtime history, the browser replaces the session ID, and Experiment-bound conversation is rejected by this path. Empty sessions no longer probe Podman; persisted runtime history/sandbox cleanup is queued after the local deletion, so Discard returns immediately.
Added a real Stop reply control to ASCEND conversation. While a durable turn is queued or running, the send button becomes a stop button. Cancellation propagates through the ASCEND job to the session-scoped Agent runtime task, survives queue/worker races as a terminal
canceledturn, and cannot be overwritten by a late answer or failure. It deliberately does not stop the selected Coordination, Experiment, Operation, or device. Backend state/API, generated UI contracts, trilingual UI, and desktop browser coverage are in place.Added the governed Stop Experiments and Reset Devices operation. ASCEND freezes the exact Experiment/device scope, asks once when the request affects active Experiments, multiple devices, all devices, or high-risk reset support, and never lets the Agent self-approve it. After approval it cancels all target Coordinations through their existing PACE boundary; any stop failure blocks every device reset. LabBridge projects every enabled device as automatic or human-assisted reset support, persists reset idempotency, dispatches the semantic
reset_to_safe_statecapability where available, and otherwise creates the existing typed Human Task with required safe-state confirmation. Each device retains its Operation/Human Task/result/error independently and the aggregate reports completed, partial, failed, or an in-progress human boundary. MQTT dispatch stays unverified and cannot become reset success. Scientist Profile v5 adds only governed request/refresh tools; it receives no protocol details and reset has no route to resume PACE/LabFlow or restore experimental output. node01 turns its relay off and clears the OLED, node02 clears the OLED, and node99 stops/retracts/detaches its servo behind the common capability. ASCEND migration v7 and LabBridge reset records cover restart and idempotency behavior.Expanded ASCEND Plan/PlanRevision from one next intent to a deliberately bounded linear sequence without adding a Plan DSL or DAG engine. One immutable revision contains one to twelve stable intents, each with its own policy snapshot, execution state, result, error and trace correlation. The full proposal is rejected before side effects when any intent is already
DENY; otherwise allowed intents execute in order, later policy is rechecked at its execution boundary, andASKor failure stops the sequence at that intent. An approved DirectAction resumes the same revision without repeating completed work. The intent types continue to reuse blocked-stage retry, Composer recomposition and idempotent semantic DirectAction paths; no raw device protocol or workflow DAG enters ASCEND. Scientist Profile v4 and the revised tool contract expose the ordered form. SQLite migration v6 backfills v5 single-intent revisions and has a tested rollback.Replaced ASCEND Intake's process-local dictionary and fire-and-forget task with SQLite-backed Review state, per-round/per-attempt Revision records and the shared durable job lease/retry worker. Every Intake model attempt now records the exact projected context, prompt/context/profile versions, result or bounded failure, and a linked AgentRun. Queued work resumes after API restart, graceful shutdown returns an interrupted attempt to the queue, transient model failures retry with a new immutable attempt Revision, and committed Intake records remain traceable to the created Coordination instead of being deleted.
Closed the remaining Intake runtime split. Intake now executes as bounded
scientist-intake/v3through the sharedAgentRunner, with an empty tool/Skill registry, strictresearch-brief-review/v2validation, bounded retry/token/time budgets, and one persisted Specialist envelope per immutable attempt Revision. SQLite migration v8 stores the envelope and has a tested rollback. The model can only returnALLOW | ASK | DENY; deterministic ASCEND code remains responsible for applying the Review and creating a Coordination.Added task-level tool narrowing to the shared chat runtime. ASCEND automatic evidence decisions use the current
scientist/v12profile identity, while the actual request receives onlyascend_propose_decision; AgentRun metadata and trace now match that execution surface instead of reporting the old v2 identity. Composer Specialist records now carry declared Skill versions (or a content-addressed fallback) plus package hashes; PRISM records both version and hash using the same envelope contract.Started Agent architecture convergence from the accepted Agent-first PRD. Composer's durable ASCEND job now carries the orchestration context through the queue into the immutable Context Snapshot and exposes only an allowlisted coordination/iteration, hypothesis and acceptance-criteria projection to the production model. Its production role records a versioned system-prompt hash and context-policy version. Composer's stale unmarked
SDL Main Agentworkspace bootstrap is recognized and replaced without overwriting user-authored instructions. The Planner Profile is nowplanner/v8with a strict 16-tool allowlist, and model-callable package approve/reject tools were removed; package decisions continue only through the authenticated, idempotent ASCEND Attention endpoint. All 48 Composer tests pass.Completed the remaining Agent architecture convergence runtime work. The shared runtime now enforces role tool allowlists for discovered and manually registered tools, including
my, and applies Runtime Skill allowlists to the primary and subagent context. Scientist v11 exposes ASCEND coordination/Plan/decision plus isolated execution and public-web tools, Planner v8 exposes Composer planning plus isolated execution and public-web tools, and Analyst v6 exposes isolated execution, public-web lookup, and strict result writing; all three hide generic Runtime Skills. Publishedsdlx.specialist-task-envelope/v1andsdlx.agent-run/v1. Composer and PRISM now persist task source, lineage, input checksum, production-path identity, versions, budgets, status and result reference. ASCEND validates and propagates its parent AgentRun into Composer; Composer records the child ID in package provenance; PACE carries it in the results-ready event; PRISM records its own child AgentRun. Composer production drafting, brief review and health probing no longer use separate SDK/urllib calls and share the Planner provider, Runner, retry/budget and output-validation path. Runtime Profiles now enforce tool-error, provider retry and token ceilings, expose content hashes for actual prompts/tools/Skills/bootstrap/task snapshots, and fail closed on undeclared sandbox backends and network policy. Composer validates both draft schemas in the Runner; PRISM validates its result at service commit. Full related regressions pass: 12 shared-runtime, 102 ASCEND (1 skipped), 48 Composer, 72 PACE, 30 PRISM, and 5 contract tests.Added a backend-owned, per-round Experiment progress view above ASCEND Home's Conversation and
Needs youcolumns. The fixed-height view distinguishes the existing five user state categories from read-onlyASCEND -> Composer -> PACE -> LabFlow -> PRISMhandoffs, showing stage start times, live/final duration, current activity and bounded semantic device activity without exposing downstream IDs or adding lifecycle buttons. Stage details open in an accessible overlay, and mobile uses a horizontally scrollable track that centers the current stage. The additive typed workspace contract, generated OpenAPI declarations, backend projection tests and desktop/mobile Playwright geometry checks are synchronized.Added an on-demand Lab CCTV viewer with a small local looping demo asset. The collapsed card mounts no media element and consumes no video bandwidth; explicit viewing starts playback, while close or page hiding releases it. Browser coverage asserts this request boundary on desktop and mobile.
Replaced the ASCEND Settings destination with a compact Console menu beside language selection. It lists each configured service, opens its Engineering Console full-screen, changes Stop to Start when the service is offline, and provides confirmation-gated Restart. Runtime control now goes through an independent SDLX Supervisor with a standalone panel, fixed service and stack actions, health checks, one-operation locking and an append-only local action log. Root startup launches Supervisor first and starts services from LabBridge toward Control; shutdown keeps LabBridge until last. The Supervisor is operational infrastructure, not a fifth domain authority. Console windows no longer expose the configured third-level service domains or a separate-window action: fixed same-origin ASCEND proxy paths forward to the server-side loopback integrations. Live browser checks load Composer, PACE, LabFlow, LabBridge, and PRISM through those proxy paths without page or request failures. The full-screen window and its confirmation dialog are rendered at the document root so the sticky top bar cannot collapse the embedded console to its own 64 px containing block; public-browser geometry checks require the iframe to occupy the remaining viewport.
Reworked Lab around the LabBridge-owned spatial map. A read-only embedded map appears before Take Over, while map editing and device management open the corresponding LabBridge routes full-screen. The duplicate ASCEND device list was removed. Experiments now use a compact top-right icon for terminal-record deletion while retaining the governed cleanup dialog.
Consolidated normal interaction on ASCEND Home. A context-bound new-goal or Experiment conversation now sits beside the complete actionable Attention and Human Task list, so researchers can act without switching tabs. URL-owned context preserves direct links and browser history; old new-experiment and direct-Attention routes redirect into Home. Experiments and Attention history are read/query surfaces, primary navigation is Home/Experiments/Lab with the pending count on Home, and safety-relevant server-provided controls remain on their relevant Experiment and Lab surfaces. Shared Attention/Human Task components keep decision delivery and schema forms single-owned. Desktop Home uses a stable left column for conversation and Active Experiments plus a separately scrollable
Needs youcolumn. Conversation messages now scroll independently above a fixed auto-growing composer; New and active contexts use the same stableEXP-*display ID and concise Agent-authored title as the full-width single-column Active Experiments list. Compact Attention cards show a persisted one- or two-sentencebrief_summaryand explicit review button, then open complete decisions and Human Task forms in a responsive modal instead of expanding and reflowing the page. Legacy records receive deterministic bounded display fallbacks without an extra Home-time model dependency. Compact live indicators now show Conversation phase/Agent activity and pending Attention count. Needs-you summaries render producer-declared decision buttons directly for glance-and-approve use, while rejection, denial, Stop and Cancel retain confirmation and complex Human Tasks remain in the detail modal.Refined the ASCEND Home conversation surface. Every completed or active turn now has a default-collapsed Agent activity disclosure built from the durable session transcript and runtime checkpoint. It shows bounded phase and tool status only, not hidden reasoning or raw tool-result payloads. Conversation can enter a viewport-sized immersive mode and exit by button or Escape. Home now places Recent completions before Problems, and the journey card keeps its accessible region name without repeating the visible
Experiment progressheading. Production build plus the full desktop/mobile primary-workspace browser suite pass.Extended that Conversation disclosure with a user-invoked tool-call dialog showing bounded input, result and status; common credential fields are redacted before rendering. Researcher bubbles now align to the right edge in normal and immersive layouts, and the composer uses a compact square send action with a smaller placeholder. Experiment Activity shows the current round in one heading (
Current round: N). The ASCEND sandbox documentation now also states the actual boundary: no host/tmpmount, a writable container root, private/tmpand/cache, one persistent workspace bind, and no host/tmpmount.Aligned Scientist, Planner, and Analyst execution freedom. All three profiles now expose
exec,write_stdin, and exec-session inspection without role-specific command allowlists. Python and shell may write anywhere inside the isolated container; raw network stays disabled and role/domain effects remain behind typed tools. Shared package-cache volumes were removed so non-workspace state cannot leak into a new session. Sandbox plan-version audits recreate stale containers when mount, image, network, or sandbox policy changes.Closed decision-hold drift in ASCEND. An applied
request_humanorblockedAgent proposal is now a durable control boundary that cannot be overwritten by a refresh of an already-completed PACE loop. LegacyDECIDINGrecords with a terminal proposal are reconciled instead of repeatedly completing jobs aswaiting_decision; rejected/applied proposal history no longer prevents a fresh evidence-to-intent Agent cycle.request_humannow creates a typed, persistent ASCEND Attention item with the reason, concrete required actions, evidence, choice consequences, and Resume/Stop outcomes. Home, Needs you, Experiment and Advanced projections therefore explain what happened and what the researcher must address without a frontend lifecycle-state map.Simplified Legacy record-cleanup feedback. The Records workspace now shows only queued/running cleanup jobs and reports a terminal job once as transient feedback instead of pinning historical partial-result cards on every visit. ASCEND also separates lifecycle-protected records from actual owner-deletion failures in purge-job results, replacing the ambiguous combined
retainedcount with deleted/protected/failed outcomes in the UI.Hardened lifecycle cleanup across ASCEND and downstream record owners. Stop now completes idempotently when a specifically referenced PACE loop or PRISM analysis has already been removed, while retaining the missing-reference outcome in the immutable decision audit. Records cleanup protects every terminal downstream record still referenced by an active Coordination and revalidates that parent lifecycle immediately before owner deletion, so an engineering cleanup cannot strand a live Experiment.
Made PRISM Agent timeouts an enforced configuration contract with an 1800 s platform maximum. The configured task and LLM/provider timeouts now reach the shared Agent runtime instead of falling back to its hidden 300 s default. Timeout-only failures can automatically create immutable replay attempts; each failed attempt retains its
retry_oflineage, queued callbacks move ASCEND to the new attempt without an intermediate false blocking state, and Stop/Cancel terminates the retry chain. Retries are now always bounded:max_timeout_retries: 0means no replay, and the tracked production default permits three immutable timeout replays. Deterministic contract and evidence failures remain fail-closed.Closed stale LabFlow approval Actions end to end. Canceling an approval wait now closes the blocked step before the cancel response, emits an
approval.canceledAttention event correlated to the originalaction_id, and prevents a late decision from racing through. ASCEND treats LabFlow's terminal approval-conflict response asexpired, reconciles already-failed records on restart, and removes only those terminal Actions from Home while preserving genuinely retryable failures. LabFlow now also emits correlated Human Task completion/cancellation events, while ASCEND reconciles older pending cards against LabBridge's authoritative task status so accepted, canceled, and expired work no longer remains inNeeds you. Late producer decisions correlated to a deleted Coordination no longer terminate the global decision outbox; delivery remains audited in Inbox, unavailable Coordination projections are skipped, and the worker recovers from isolated dispatch exceptions.Closed the PACE parent-cancel/LabFlow child-start race that could leave an orphan Human Task in
Needs youafter its Coordination was stopped. PACE now publishes parent cancellation before forwarding child cancellation, makes child record/start atomic with respect to cancellation, and rechecks parent state before creating a child run. A cancellation can therefore either stop an already-started child or prevent it from starting, without being misclassified asWAITING_REVIEW.Made
Restart as newcarry the source lifecycle's first bounded hypothesis/candidate into a new Iteration with fresh identity and no copied execution references. Automated restart now reaches Composer instead of repeatedly completing advancement jobs aswaiting_for_bounded_iteration; sources without an Iteration retain the safe empty-DRAFT behavior.Added a shared
sdlx-schema-runtimewith contiguous version validation, drift detection, per-version savepoint atomicity, explicit compatibility floors and fail-closed downgrades. ASCEND, PACE and LabBridge now record their SQLite evolution through the same runner while retaining module-owned DDL and data transforms; migration, idempotency and immutable-lineage tests cover the new boundary.Split PRISM delivery preparation, output commitment and result/Agent-log projection out of the lifecycle service, reducing
service.pybelow nine hundred lines without moving analysis authority. PACE now also owns reusable console UI primitives outside its main application component.Extended TypeScript no-emit compilation plus ESLint syntax, undefined-variable, duplicate-key and React Hooks gates to Composer, LabBridge, LabFlow, PACE and PRISM. Composer, LabFlow, PACE and PRISM now enforce zero warnings; LabBridge's remaining Hook warnings retain an explicit non-increasing budget. The new lint gate also found and removed duplicate locale keys. Added five mocked-API Playwright boot journeys for the Engineering Consoles and wired all console builds/type checks/lints/journeys into CI.
Removed the ASCEND legacy workspace after replacing its remaining supported uses with native P2 routes: a read-only per-Experiment engineering trace and a governed Advanced Records catalog. Both now use generated OpenAPI types; legacy manual lifecycle controls, its dock layout, and its route were not carried forward.
Closed the post-audit ASCEND primary-interface gaps: the Experiments index now includes material
Problemrecords without duplication, Lab SSE events invalidate the actual overview query, and the Experiment timeline projects Agent decisions, execution, evidence, Attention, and human decisions. The next expected outcome prefers the recorded Agentexpected_effector current bounded-round hypothesis instead of a generic lifecycle sentence.Unified Take over
ASKhandling with the global durable Attention Inbox. Material direct actions now create a typed Attention event/action, use the standard durable decision outbox, and navigate the operator toNeeds you; terminal transport success without verification is explicitlycompleted_unverifiedrather than an indefinitely submitted operation.Added typed Human Task read/action responses to OpenAPI, generated frontend types, and rendered owner-provided UI schema ordering, textarea, full-width, placeholder, and read-only hints. Phase, activity, outcome, action, decision, risk, side-effect, task/action status, and timeline titles now use trilingual semantic presentation keys with backend text retained as fallback.
Previously made the Advanced compatibility workspace a lazy route and removed Composer's remaining 67-line Chat CSS clone in favor of
@sdlx/ui-chat. ASCEND primary features import the shared Chat owner directly, removing the mixed static/ dynamic duplicate-module build warning.Re-audited the three Agent-role dependency and sandbox declarations. Their common loop remains single-owned by
sdlx-agent-runtime, while ASCEND, Composer, and PRISM retain distinct entry points, mounts, write boundaries, and network policies. No further sandbox extraction was made because the superficially similar code enforces different domain isolation contracts.Closed the ASCEND P2 primary-flow acceptance gap: chat turns and their jobs are durable across API restart, session-correlated Agent-created Experiments navigate reliably, and existing Experiment workspaces retain conversation history with SSE invalidation and bounded active-turn fallback polling.
Added normal-route schema-driven Human Task execution with real artifact upload, semantic capability Take over through
ALLOW | ASK | DENY, Operation and evidence display, inline complete PRISM reports, and corrected Home problem/recent-completion projection.Expanded ASCEND qualification from route smoke coverage to desktop/mobile browser journeys for conversation reload, Human Task, Take over, reports, Home and Attention, with durable API/migration restart tests and strict generated TypeScript, ESLint, locale, and production-build gates.
Replaced the ASCEND engineering cockpit as the normal entry with a progressively disclosed P2 shell: Home, Experiments, conversation-first creation, stable Round/Evidence/Policy detail routes,
Needs you, Lab, and a role-separable Advanced/Engineering boundary. React Router, TanStack Query, SSE invalidation, strict TypeScript, generated projection clients and desktop/ mobile Playwright journeys now own the main path.Added typed Control projections for Home, Experiment workspace, Attention, Lab and report access. Attention producers now declare reason, evidence, consequences, recommendation and resume/stop outcomes; decision delivery and chat-turn contracts are typed end to end without moving downstream authority.
Centralized all ASCEND deployable-boundary URLs and runtime payload checks in typed clients, split workspace and chat routers from the API hotspot, and added Pyright enforcement for these seams alongside repository-wide Ruff.
Added explicit ASCEND schema migrations with reversible v1/v2 boundaries and a SQLAlchemy PostgreSQL lineage repository. Real PostgreSQL 17 qualification exercises v1 -> v2 -> v1 -> v2, preserves stable Coordination/Round/Decision/ analysis/trace digests and proves immutable Decision/trace mutation guards.
Split the PACE 2,280-line store into an 849-line stable facade and independent evidence, Attention/todo, result-delivery/outbox, codec and migration repositories. ASCEND Agent Control codecs and Iteration analysis ingestion now also have independent seams with compatibility facades.
Split ASCEND engineering Records reconciliation/purge into its own router and separated evidence-to-intent decision logic from deterministic Iteration lifecycle orchestration. The stable API, Iteration, PACE and Agent Control facades are now all below one thousand lines for reasons tied to ownership, not an arbitrary line cap.
Removed the duplicated LabFlow backend fallback tree (more than four thousand source lines) in favor of one
web/adminsource and generateddistoutput. ASCEND, Composer and PRISM now share one@sdlx/ui-chatcomponent owner; the identical ASCEND/PRISM chat CSS copy is gone.Pinned the shared Agent Runtime to the audited
HKUDS/nanobotv0.2.2 commit, recorded 45 modified and two SDLX-only paths, documented upgrade/rollback policy, added runtime-level tests, and made the three role suites mandatory.Added fail-closed production and physical qualification evidence validators. The current local deployment correctly fails them because PACE/PRISM object storage and external identity are unconfigured, no one-hour/backup evidence exists, and MQTT nodes are offline.
Added versioned JSON Schemas, fail-closed evidence templates and read-only production/physical draft collectors. CI now runs schema validation, isolated SIGKILL multi-process recovery and the MinIO identity/Object Lock integration; these are software prerequisites and cannot substitute for site evidence.
Added a shared immutable S3/MinIO adapter with deterministic conditional writes, SHA-256 verification, read/write prefix enforcement, workload-identity support, and no general runtime delete API. PACE now commits Result Bundles and delivery archives to
s3://before publishing its outbox event; PRISM verifies the PACE object on the worker host and commits its result/archive before the ASCEND callback. Localfile://remains an explicit development fallback.Added optional MinIO provisioning for separate artifact/archive buckets, versioning, Object Lock capability, configurable governance retention, and distinct least-privilege LabBridge/PACE/PRISM identities. The normal four SDLX deployment boundaries remain unchanged because object storage is external infrastructure.
Completed Agent-first Phase B/C. ASCEND, Composer, and PRISM now load Scientist, Planner, and Analyst profiles from one versioned runtime source; profiles declare prompt/context/Skill/output versions, budgets, tools, and sandbox policy without copying the generic loop.
Added deterministic Agent replay over recorded trace events. Replay verifies the source trace hash, reconstructs policy/tool/operation/evidence/decision state, and never invokes a model, Tool, LabBridge, or physical device.
Split the maintenance hotspots behind stable facades: ASCEND routes, contracts/projections/support, Composer routing/state/durable work, and LabBridge capability control are separate vertical change boundaries.
Added the shared SQLite durable-job runtime with idempotent enqueue, lease, heartbeat, retry, cancel, expired-worker recovery, and retention pruning. ASCEND routine advancement and Composer composition/brief review use it.
Migrated Composer from Next.js to Vite and made ASCEND the TypeScript primary SPA with React Router, TanStack Query, schema-driven device/Human Task forms, and the shared OpenAPI-generated
@sdlx/ui-contractsclient.Added deterministic source/output hashes to every Web build and verification commands so checked-in server assets cannot silently drift from their source.
Made
control,execution,labbridge, andanalysis-workerthe four root deployment defaults. Existing module scripts remain engineering compatibility adapters, while obsolete manual lifecycle HTTP routes were removed after the primary UI caller migrated.Completed Agent-first Phase A/P0. ASCEND now projects only
Working,Needs you,Paused,Completed, andProblem, returns typedavailable_actions, and automatically advances routine composition, preparation, execution polling, analysis, and continuation work when policy permits. The primary UI no longer presents Compose/Sync/Prepare/Start/Refresh as a required sequence.Added versioned
CapabilitySpec,PolicyDecision,AvailableAction,AgentDecision,AgentRun, andAgentTracerecords. Trace events correlate profile/prompt/context-policy versions, policy, tool calls, LabBridge Operations, PRISM evidence, Human Tasks, and decisions; bounded summaries are secret-redacted and do not store hidden chain-of-thought.Added schema-driven Take over and direct atomic control. Low-risk semantic capabilities can run without a Workflow/PACE package; material actions create typed Attention first; all calls are idempotent and preserve Operation/audit references. MQTT delivery records transport completion explicitly as
unverified, never as verified physical effect.Removed the last normal-operation deep-link requirements from ASCEND. Its Action Center now renders LabBridge-owned Human Tasks directly from immutable validation schemas and current controller presentation/default metadata, including typed values and artifact upload. Its Evidence view proxies and renders complete linked PRISM reports without exposing arbitrary analysis identifiers.
Added the shared
record-projection/v1contract and lifecycle-safe record catalogs for ASCEND, Composer, PACE, LabFlow, LabBridge, and PRISM. Every module console now uses checkbox-first selection, select-visible, selected count, bulk delete, confirmation, and retained skipped selections.Added ASCEND's on-demand Records view for cross-module health, search, filtering, selected deletion, and explicitly confirmed delete-all. The request is split by owner, active records are skipped by owner policy, and configuration assets are outside the purge contract.
Enforced allowlisted ASCEND Agent projections for Coordination, Iteration, and committed PRISM results. Removed PRISM Skill, presentation, workspace, archive, and callback internals from decision context; also removed local Skill/knowledge paths and LabBridge snapshot-source metadata from Composer's model context.
Removed unsafe semantic fallbacks: failed ASCEND intake stays blocked, unmatched Composer requests select no arbitrary Skill, and incomplete sample lineage is rejected rather than fabricated.
Completed module-owned record lifecycle controls. ASCEND deletes owned Inbox and chat state with a Coordination; Composer can cooperatively cancel active jobs before deletion; LabBridge only deletes terminal Human Tasks while retaining operations and artifacts; PRISM retains its terminal Analysis Run management.
Added PACE's durable incident Attention outbox and idempotent decision handler. Human-visible incidents now reach ASCEND, render declared resolve/dismiss actions, return to PACE, resolve linked TODOs, and publish a terminal event without exposing PACE internals to the ASCEND Agent.
Added a real-process PACE -> ASCEND -> PACE Attention qualification and corrected the existing restart suite to run PRISM's callback dispatcher as its own process and use only the current unified Attention endpoint.
Separated ASCEND Research Definition, Governance Policy, and immutable Iteration Candidate contracts. Coordinations can now be copied from any state into an editable derived lifecycle with explicit source lineage and no copied execution history.
Added a strict LabBridge Agent projection for capability calls, operations, cancellation, traces, usage, artifacts, leases, and custody. Device source, controller identity, runtime templates, and internal scenario provenance stay inside the LabBridge Engineering Console; upstream Agents receive the same real-device contract for every enabled device.
PRISM now verifies a source PACE archive first and then normalizes artifact references in the read-only Agent input projection. Historical replay keeps source checksums intact while hiding obsolete backing-store layout details.
Minimized the PRISM-to-ASCEND decision handoff to committed scientific claims and evidence references. PRISM Skills, presentation metadata, workspace paths, raw archives, and process-specific decision rules are excluded from ASCEND's Agent prompt.
Split ASCEND's historical Coordination surface into compact summaries, on-demand evidence/activity, and newest-first chat pages. Client request sequencing prevents stale responses from replacing a newly selected record; the live SSE channel removes high-frequency whole-page polling.
Added ASCEND's durable Attention decision outbox. Approval now returns after durable enqueue, displays a queued delivery state, retries producer delivery with the same idempotency key, survives restart, and publishes final state to the browser without blocking the conversation.
Rebuilt PRISM Results around process series rather than one global metric matrix. Results group by Coordination, process, and Analysis Skill profile; versioned Skill
presentationmetadata drives localized table columns, while generic and legacy read-only projections keep older results usable without rewriting committed archives.Removed PRISM's idle four-second polling and eager full-result/system fetches. Analysis Runs loads a compact list, live polling exists only while work is active, and Results loads its grouped projection independently.
Made ASCEND the deployment-configured normal user surface. Downstream links are secondary Engineering Console entries, Attention controls come from producer-declared decisions, and package approval provenance is attached server-side rather than copied by the operator. ASCEND no longer fabricates a Composer review event when the producer has not delivered one.
Removed shared-core scientific and laboratory fallbacks: Composer no longer injects a demo or placeholder sample; LabFlow protection and draft templates are YAML metadata; Composer/PRISM production core and ASCEND's frontend pass an audit for demo names and fixed public service URLs.
Established ASCEND as the primary SDLX user interface. Composer now preserves Coordination/Iteration lineage, publishes restart-safe package-review events from a durable outbox, and accepts idempotent ASCEND decisions. Guided reviews render in the ASCEND conversation; autonomous policy approvals use the same audited contract. Module-local Web applications remain diagnostic surfaces, with LabBridge Human Task upload as the device-specific input exception.
Added deterministic, checksummed PACE delivery archives containing objective, immutable Iteration, package, actual task timeline, decisions/approvals, Human Task references, device operations, artifacts, incidents, TODOs, and a complete file checksum index.
Added PACE's durable results-ready outbox, idempotent direct PRISM dispatch, retry/backoff, restart reconciliation, Analysis Run reference, APIs, and standalone dispatcher process.
Created the independent
prism/module with its own database, API, Web, configuration, model key, Analyst profile on the shared runtime, workspace, sessions, callbacks, and process lifecycle.Added PRISM-only versioned Analysis Skills, metadata matching, immutable Skill snapshots, per-run Podman sandboxes, read-only input/Skill mounts, writable output, explicit execution-container network policy, and a strict analysis-only tool allowlist. Audited public-web lookup remains available alongside raw container networking.
Installed the PRISM-only
xps-peak-fittingSkill for Co2p, N1s, C1s, O1s, and Cl2p high-resolution scans. It accepts native SDLX XPS fixture columns, records energy-correction and artifact provenance, emits JSON plus a fit plot, flags bound-hitting or weak fits, and preserves the boundary between candidate peak assignments and claims about valence, coordination, or mechanism. The sandbox image now carries pinned NumPy, SciPy, and Matplotlib versions.Added nanobot tool-call auditing, hidden-reasoning scrubbing, generated-file inventory, artifact checksum validation, strict
prism-analysis-result/v1commitment, deterministic analysis archives, and a durable ASCEND callback outbox.Replaced ASCEND's direct Result Bundle decision path with durable PRISM lifecycle ingestion and committed Analysis Result decisions. Added
ANALYSIS_QUEUED,ANALYZING,ANALYSIS_BLOCKED,DECIDING, andCOMPOSING_NEXT, policy-bound automatic continuation, duplicate-lineage protection, and PACE/PRISM cancellation propagation.Added explicit ASCEND Coordination lifecycle controls: safe-boundary pause/resume, terminal cancel semantics, restart-as-new with copied definition and policy, and immutable Composer/PACE/PRISM attempt lineage for blocked-stage retries. The trilingual Web exposes each action and its attempt history.
Added PRISM's trilingual operational Web for upload, observe, inspect, replay, compare, Skill inventory, result reports, collapsed tool calls, callbacks, and system checks. ASCEND now links directly to the selected Analysis Run and renders analysis quality, summary, metrics, artifacts, and iteration comparisons.
Added shared proxy identity plus internal PACE/PRISM/ASCEND service tokens. Added the compact English, Simplified Chinese, and Spanish localization contract and mobile/desktop browser verification for PRISM and ASCEND.
Added a three-Iteration cross-process qualification covering duplicate PACE dispatch, PRISM callback retry, service restarts, committed decisions, unique next-Iteration lineage, deterministic stop, and immutable analysis replay.
Added
human-task-controllerand the first operator-assisted device profile,manual_xrd0.upload_phase_analysis.Added
rde-cell-station0.prepare_rde_cellfor liquid electrochemistry setup.Added durable Human Task, immutable revision, artifact-role, and timeline storage in LabBridge.
Added Human Task create/list/detail/claim/upload/submit/review/reject/cancel APIs and a dedicated Admin Web Inbox.
Bound submissions to operation, sample, schema, artifact role/media type, checksum, revision, and idempotency key.
Linked accepted submissions to Gateway operation completion and linked run cancellation to Human Task cancellation.
Added LabFlow
completion.mode=operation_terminal, persistent operation waits, restart reconciliation, and differentiated blocking reasons.Added restricted
$fromdata binding forrun.parameters.*and completed step results.Added signed LabFlow run/step provenance to Gateway operation context.
Added
phase-analyzer0as a deterministic SimFleet decision device and a runnablepowder_heat_characterizePACE package covering weighing, heating, operator-assisted XRD, automatic evaluation, and archival.PACE now preserves LabFlow
WAITINGas an active state and exposes the blocking reason, operation IDs, and Human Task IDs while polling continues.Added an end-to-end regression proving the Human Task result and both XRD artifacts flow through LabFlow into the PACE result contract.
Removed second-person review as a product requirement. One operator can submit and, for
manual_accept, confirm the same immutable revision.Implemented shared LabBridge map revisions, stations, service ports, device placements, expiring resource leases, and revisioned carrier custody.
Added Spatial Admin CRUD and coordinate-free MCP station/status views. Agent context receives station IDs and mode/port constraints, not raw motion poses.
Added semantic Composer bindings by
semantic_id, required output fields, online state, and optional station. Package bindings do not encode a simulated/physical execution branch.Added the ORR RDE LSV module and PACE demo: operator cell setup followed by
electrochemical-workstation0.run_lsv, with literature evidence and local SOP parameters separated explicitly.Added the evidence-bound ZIF-8 Fe1/NC to secondary-sphere P-modified Fe1/NCP baseline: two Composer process modules and a dedicated Skill, a versioned Bridge-side ORR test fixture, reactive-furnace Human Task, parent-linked sample lineage, small-artifact delivery embedding, a PRISM ORR RDE Analysis Skill, and an ASCEND two-Iteration advance/stop qualification. Upstream modules use the same capability and evidence contract for every controller implementation; ORR is not treated as atomic-structure evidence.
Removed caller-asserted physical preconditions such as
*_confirmed: true, duplicate approval bypasses, device-specific editor defaults, and upstream simulation branches. Accepted Human Task operations now provide signed authorization provenance to their direct downstream device action.Promoted the nanobot ASCEND Agent from a prompt skeleton to a durable coordination coordinator. It stores coordination/decision records, links Composer, PACE, LabFlow, operation, Human Task, artifact, and incident IDs, requires an explicit approval reference before start, and aggregates blocking states.
Extracted that coordinator into the independent
ascend/module with a coordination dashboard, decision/reference detail, and persistent notifications.Added an ASCEND-owned nanobot runtime, chat-first Web UI, isolated tool plugins, Coordination Iterations, automation policy, decision proposals, and constrained automatic next-round handling. Composer and ASCEND no longer import each other.
Renamed the former HELM module to ASCEND end to end: directory, Python package, CLI, tool entry points, runtime variables, Web identity, documentation, and recovery contracts now use the new product name. Legacy environment names remain read-only deployment fallbacks.
Aligned ASCEND's model configuration with Composer by copying the same module-local YAML
llmschema and nanobot provider/config/model runtime sources. ASCEND keeps its own key, workspace, sessions, tools, and API process.Added Composer's formal
POST /api/composer/jobsboundary and changed ASCEND package handoff to API responses instead of reading Composer run directories.Added
pace-result-bundle/v1. Device controllers own native result processing, LabBridge validates capabilityoutput_schema, and PACE generically returns semantic parameters and object-store artifact URIs to ASCEND.Added optional trusted-proxy identity and viewer/operator/admin authorization to LabBridge, plus service-token access for internal controllers and schedulers.
Connected LabFlow steps to robot/station/port/carrier lease bundles, periodic renewal, source-custody checks, successful custody transfer, and unknown-state handling after uncertain failures.
Added
scripts/test-golden-loop-recovery.shfor rejection/resubmission, cancellation, durable external wait/restart reconciliation, spatial transfer, PACE cancellation forwarding, and ASCEND coordination regression contracts.Replaced periodic full SimFleet re-registration with one fleet heartbeat that refreshes enabled-device liveness. Live
/api/summarylatency dropped from multi-second/timeout behavior to about 4 ms after the initial registration pass.Added automatic MCP session reinitialization in LabFlow and PACE after a LabBridge restart, preventing stale
Session not foundpreflight failures.Fixed SQLite contention that regressed LabFlow's independent parallel waits.
Changed the Gateway summary contract to report all registered, enabled, disabled, online, and offline counts independently. The current live snapshot is 34 online enabled devices out of 39 registered devices, with 5 disabled.
Fixed malformed inline YAML descriptions in the AGV, AMR, fixed-arm, and mobile-manipulator profiles. SimFleet now rejects unknown template, profile, capability, and execution fields instead of silently accepting parser damage.
Added an isolated live-process recovery suite. It starts LabBridge Admin, both MCP transports, MQTT listener, SimFleet and Human Task workers, LabFlow, PACE, and ASCEND; writes durable records; sends
SIGKILL; restarts; and verifies the records through HTTP. A GitHub Actions workflow runs the same suite.Added the searchable VitePress SDLX documentation site on port 8112 with architecture, delivery, and operations navigation plus a locked CI build.
Added a live documentation status endpoint that aggregates LabBridge, LabFlow, PACE, ASCEND, and Composer health and current device counts. The public documentation route now serves the English site successfully.
Verification
Object storage: 4 immutable-write/checksum/prefix tests, 6 PACE delivery tests, 19 PRISM service/API tests, and 13 LabBridge artifact/config tests passed. The two-test real-process PACE -> PRISM -> ASCEND suite and documentation build also passed. MinIO compose/policy/static validation passed; live MinIO startup was not run because the current user cannot access the Docker socket without an interactive sudo password.
Composer: 48 tests passed; Admin Web production build and 313 trilingual locale keys passed.
LabBridge: 170 tests and 17 subtests passed; Admin Web production build and 388 trilingual locale keys passed.
LabFlow: 76 tests passed; Admin Web production build and 205 trilingual locale keys passed.
PACE: 69 tests passed; Admin Web production build and 164 trilingual locale keys passed.
PRISM: 31 tests passed; Admin Web production build, 135 trilingual locale keys, manual upload/replay, desktop/mobile layout, and zero-error Playwright checks passed.
ASCEND: 130 tests passed with one skip; Ruff and Pyright passed with zero errors, and the Admin Web production build, strict TypeScript/ESLint checks, generated contracts, and 818 trilingual locale keys passed. The updated Playwright suite passes all 21 applicable desktop/mobile journeys, with 11 project-specific skips and zero failures.
Agent-native virtual lab Phase 2/3 qualification: ASCEND agent-control, workspace, migration and virtual-lab schema suites passed; generated ASCEND OpenAPI TypeScript contracts passed; 999 trilingual locale keys, strict TypeScript/ESLint and the production build passed. Playwright verifies the complete branch-failure/revision/selection/Attention replay in 2D and 3D, intent-segment playback, YAML-driven generic device visualization, stable-ID parity, camera/fullscreen controls, zero renderer mutations, WebGL fallback and the mobile scene flow.
Shared job runtime: 4 lease/idempotency/retry/cancel/recovery/retention tests passed. Shared OpenAPI TypeScript generation, strict client type check, and the ASCEND primary SPA
tsc --noEmitcheck passed.All six Web production builds emitted and verified deterministic source/output manifests. The four deployment descriptors, executable wrappers, shell syntax, and aggregate live status path passed static qualification.
The current two-test PACE -> PRISM -> ASCEND real-process suite passed after the record ownership and proxy changes.
PACE -> PRISM -> ASCEND: three-Iteration cross-process recovery and replay qualification passed.
PACE -> ASCEND -> PACE: durable incident request, remote decision, and resolved lifecycle event qualification passed across real service processes.
Golden Loop recovery contracts passed for LabBridge (2), LabFlow (4), PACE (1), and ASCEND (65). The PACE -> PRISM -> ASCEND real-process suite passed 2 tests with the shared job runtime on its explicit integration path.
Live process
SIGKILLand restart recovery passed for the isolated stack; the fixture uses the protecteddemo_parallel_joinworkflow and verifies persisted LabBridge, LabFlow, PACE, and ASCEND records after restart.Documentation dependency audit reported zero vulnerabilities and its production build passed.
Online ORR RDE package preflight passed with no blocking checks against live LabBridge, LabFlow, and PACE services.
Current live measurements: ASCEND compact historical detail is 20,199 bytes versus 78,966 bytes for the full contract; PRISM compact run inventory is 7,929 bytes. An idle Results page issued no repeat API requests during the Playwright observation window.
The closed-loop suites cover 128 module tests across PACE, PRISM, and ASCEND plus the cross-process qualification. Existing Composer, LabBridge, LabFlow, firmware, documentation, and Golden Loop suites remain separate foundations.
Main Gaps
- The Phase D software slice, including hotspot decomposition and the PostgreSQL lineage path, is implemented and qualified. SQLite remains the development default; production must select and restore PostgreSQL through the separate operational qualification gate.
- The immutable object-store software path and MinIO prefix policies are implemented. Production deployment still needs real workload credentials, an approved retention duration, redundant storage/backup restoration, process supervision, and centralized secret rotation. Local development may continue using immutable
file://records behind the same URI contracts. - PRISM currently includes generic scientific-summary, tabular-measurement, ORR RDE, XPS composition, and XPS high-resolution peak-fitting Skills. Physical instruments still need versioned device-result Analysis Skills, fixtures, reference datasets, and scientific validation as their native data formats are integrated.
- Trusted-proxy authentication and role enforcement are implemented, but SDLX does not yet own an OIDC provider, account lifecycle, or organization policy.
- Spatial leases protect a running step, but interrupted physical robot work is not automatically resumed after a LabFlow process restart. Controller idempotency and physical custody reconciliation are required first.
- Spatial Admin includes a calibrated planar editor and immutable revision flow. Controller-driven calibration against surveyed physical reference points is still future work.
- ASCEND's current event broker is process-local. Horizontal API scaling will require a shared event fan-out transport; the durable Attention outbox already remains authoritative if a transient event is missed.
- ASCEND notifications are persistent and visible in its Web UI; outbound delivery such as email, webhook, or enterprise chat is not implemented.
- ASCEND and Composer model credentials are stored in separate ignored local YAML files. Deployment secret provisioning and rotation are not centralized.
- Physical AMR/AGV/arm controller adapters still need to implement the same tested contracts used by SimFleet.
- Firmware config validation is locally blocked until the ignored
firmware/packages/secrets.yamlis supplied; secrets must not be generated or overwritten automatically.
Recommended Order
- Provision the implemented object-storage prefixes with real service identities, approve the archive retention duration, verify backup restoration, and configure process supervision and centralized secret rotation.
- Add the first physical instrument's Analysis Skill, fixtures, processed artifact contract, and reference scientific dataset.
- Add long-duration closed-loop soak tests and deliberate Agent/container/ object-storage failure injection in the deployment environment.
- Add a shared ASCEND event fan-out transport only when a second API instance is introduced.
- Monitor the recovery and documentation workflows after their first remote GitHub Actions run.
- Integrate the trusted-header boundary with the deployment identity provider.
- Add physical-controller idempotency and custody reconciliation, then replace selected SimFleet profiles without changing workflow capability contracts.
- Validate and calibrate the first physical mobile-manipulator station modes.