Qualify the Windows OpenShell and MXC distribution authority
- Dominant language
- TypeScript
- Stars
- 22.5k
- Forks
- 3.1k
- Avg merge
- 1d 1h
- Merged PRs (30d)
- 715
Description
Part of #8178.
This task advances the dormant native Windows/OpenShell MXC candidate. It does not make MXC selectable, installable, activated, or supported.
## Outcome
NemoClaw can obtain one provider-owned authority for an immutable OpenShell Windows development qualification checkpoint and its compatible MXC/`wxc-exec.exe` identity. A later stable-release record can advance that authority from `qualification` to `accepted` only after OpenShell ownership, compatibility review, and physical regression evidence.
Authority must remain independent of files observed on the candidate host.
## Delivery state
Dormant two-stage distribution-authority gate.
## Dependencies
- #10582 is complete.
- The development checkpoint uses the exact OpenShell v0.0.24 package supplied by the OpenShell/MXC team and the separately identified MXC v0.7.0-rc1 identity.
- Stable-release acceptance requires the OpenShell team to publish or identify the final package, source revision, signing or integrity identity, and compatible MXC/`wxc-exec.exe` contract.
- The qualification authority unblocks the trusted physical-Windows executor slice without unblocking product activation.
## Deliverables
- Define the immutable development checkpoint: OpenShell source, version, revision, component digests, compatible MXC identity, and compatibility bounds.
- Mint a `qualification` attachment authority only from that checked-in provider-owned record.
- Keep MXC and `wxc-exec.exe` provenance separate when they are not part of the OpenShell distribution.
- Bind the qualification authority to the existing inactive attachment contract without deriving authority from host observation, caller-provided measurements, prototype files, or test constructors.
- Require a new immutable authority record and physical regression evidence for each replacement package.
- Reserve `accepted` authority for the stable OpenShell release.
- Keep production selection and activation absent.
## Acceptance evidence
- Allowed: the exact development checkpoint produces an opaque attachment authority with `acceptance: qualification`.
- Denied: caller-supplied hashes, local prototype measurements, unknown revisions, substituted components, copied capabilities, and test-only constructors cannot mint authority.
- Ambiguous: incomplete ownership, provenance, compatibility, or component identity remains blocked.
- Failure: authority creation fails before host observation or OpenShell mutation and reports no credential or sensitive path data.
- Stable release: a replacement package requires a new record, contract compatibility review, and physical regression evidence before it can produce `acceptance: accepted`.
## Security and authority boundaries
- Package qualification, stable-release acceptance, and host observation are separate trust decisions.
- Exact component identity must prevent artifact substitution and version drift.
- Test fixtures must not expose a production-callable authority constructor.
- No secret, token, certificate, or credential may enter the authority, receipt, logs, or test artifacts.
## Test plan
- Focused authority-source and attachment-contract tests.
- Negative tests for observation-derived authority, copied authority, test-constructor access, missing components, digest drift, version drift, and mixed OpenShell/MXC roots.
- Runtime-provider and architecture checks proving that MXC remains unregistered.
- Physical qualification against the exact development checkpoint before the trusted executor depends on it.
## Deferred scope
- Stable-release acceptance.
- Installation, normal onboarding, managed inference, protected E2E, and activation.
## Stop conditions
- Stop qualification if the exact development package or separate MXC provenance is incomplete or changes.
- Stop if the design can mint authority from local observation, prototype measurements, or test-only input.
- Stop stable-release acceptance and activation until OpenShell publishes the stable immutable distribution and compatible MXC identity.
- Stop if the design adds a central `mxc` switch.
## Completion evidence
- Link the implementation PR, exact merged commit, immutable development checkpoint, and focused validation.
- Keep this issue open or create a separate accepted-authority task until the stable-release record and physical qualification exist.
Contributor guide
Assessment
This issue has not been assessed yet.