nomos_flutter 0.63.61 copy "nomos_flutter: ^0.63.61" to clipboard
nomos_flutter: ^0.63.61 copied to clipboard

Drive the real Nomos GitHolon from a Flutter app — a local-first domain runtime. Apple runs the release-pinned native kernel; Android and web acquire and retain the release-pinned WASM runtime. Write [...]

0.63.61 #

  • Add the Android application runner used to produce and compose deterministic CycloneDX Pub, Gradle, and CocoaPods dependency evidence for the example app.
  • Keep the iOS kernel linker path symbolic so CocoaPods lockfile checksums are identical across clean checkout locations.

0.63.60 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.21; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Restaged with the current kernel candidate: a lower layer of the Dart release stack moved. Published pub.dev archives are immutable, so regenerated bytes ride their own version.

0.63.59 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.20; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Match application home birth certificates to the locally sealed parent offer's CAS-as-law verification verdict.
  • Consume nomos_client 0.64.35 for the corrected application birth ceremony.

0.63.58 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.19; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Keep typed birth evidence off the preliminary signer-enrolment offer so authenticated generated applications can complete first-device startup.
  • Consume nomos_client 0.64.34 for the corrected generated runner lifecycle.

0.63.57 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.18; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Open generated applications across arbitrary historical model backlogs while preserving a bounded, typed guard against a genuinely stuck lifecycle step.
  • Consume nomos_client 0.64.33 for progress-aware model convergence.

0.63.56 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.17; the pub.dev archive now carries the exact npm release stamp proved by this commit.

0.63.55 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.16; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Consume nomos_client 0.64.32 so Flutter applications prove durable device enrolment before generated writes become available.

0.63.54 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.15; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Consume nomos_client 0.64.31 so Flutter applications use the restaged, type-safe intent-offer gate and deterministic signer posture.

0.63.53 #

  • Consume nomos_client 0.64.30 so generated Flutter applications inherit deterministic signer-posture reads and authenticated replacement-device recovery.

0.63.52 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.14; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Restaged with the current kernel candidate: regenerated vendored assets (kernel release identity is baked into them). Published pub.dev archives are immutable, so regenerated bytes ride their own version.

0.63.51 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.13; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Restaged with the current kernel candidate: regenerated vendored assets (kernel release identity is baked into them). Published pub.dev archives are immutable, so regenerated bytes ride their own version.

0.63.50 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.12; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Consume nomos_client 0.64.27 so the Flutter package and its Dart runtime use nomos.cafe as the sole default cloud surface.

0.63.49 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.11; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Restaged with the current kernel candidate: regenerated vendored assets (kernel release identity is baked into them). Published pub.dev archives are immutable, so regenerated bytes ride their own version.

0.63.48 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.10; the pub.dev archive now carries the exact npm release stamp proved by this commit.

0.63.47 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.9; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Consume nomos_client 0.64.25 and rebuild the embedded runner, keeping the Flutter host on the same immutable runtime bytes as the generated Dart client.

0.63.46 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.8; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Publish the current package bytes under a new immutable version. The runtime behaviour is unchanged; the source now accurately documents CO2's existing, narrowly scoped platform-auth recovery compatibility lane instead of claiming that lawful recovery does not exist.
  • Move generated Flutter applications to this exact package floor so clean installs cannot resolve the stale 0.63.45 archive.

0.63.45 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.7; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Restaged with the current kernel candidate: regenerated vendored assets (kernel release identity is baked into them). Published pub.dev archives are immutable, so regenerated bytes ride their own version.

0.63.44 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.6; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Make the clean-checkout native release proof self-contained: the gate now hydrates the exact content-addressed Apple candidate when the ignored local build tree is absent, then verifies and links that candidate before exercising the CO2 custody handoff.

0.63.43 #

  • Restaged with the current kernel candidate: regenerated vendored assets (kernel release identity is baked into them). Published pub.dev archives are immutable, so regenerated bytes ride their own version.

0.63.42 #

  • Simulator builds link again. The kernel FFI retention pins now apply only to device archives, where stripping can otherwise remove the symbols. Simulator builds no longer force unresolved x86_64 symbols from the intentionally arm64-only simulator framework slice.
  • Consume nomos_client 0.64.23 and nomos_types 0.8.7, keeping the published Flutter package on the same generated-runner and JSON-value decoding fixes as the framework release.

0.63.41 #

  • THE FRAMEWORK OWNS TOKEN RENEWAL — tenant devs never write refresh code. Auth-provider tokens are short-lived by design (a Firebase ID token dies after an hour) and providers rotate signing keys underneath you. Every piece needed to survive that already existed and none were connected: the kernel classifies the refusal precisely (nomos.auth.token_expired, remedy reauth), the tenant already supplies a signIn callback that returns a FRESH token when called again, and the workspace scope already re-opens a session in place on a credential change. So an app open longer than one token lifetime simply began failing every write — observed on a real device 2026-08-09, "auth: token verification failed (Expired)" while creating assets.
  • NomosCredentialLifecycle renews AHEAD of exp (default 5min) so the user never reaches the edge, retries a stale-credential failure exactly ONCE, and coalesces concurrent expiries onto a single refresh. Only an AuthError whose remedy is reauth is retried — replaying a law or authz refusal would be wrong and on a write could double-author. A refresh that yields no token (genuine sign-out or a revoked key) surfaces the original typed refusal instead of looping.
  • FIXED with it: the device-bound token cache was unconditional, so once minted it was reused for the life of the process regardless of expiry. It now respects renewal.

0.63.40 #

  • THE STARTUP DEADLINE IS NOW A REAL STALL DETECTOR — fed by kernel activity, not phase names. Observed directly on a phone (2026-08-08): a first open doing >30s of genuine work — clone, genesis verification, birth-or-repeat, seating, enrolment, ALL inside the single openingCustody phase — was killed by the 30s budget on every attempt, forever, because the snapshot that makes the next open instant only persists AFTER a completed open. v2's re-arm-on-phase-transition could never help: there are no transitions inside that phase. Now the scope streams every bridge span (NomosScope.home onActivity) into NomosStartupStallDetector: progress at any layer resets the clock; a still-open span extends bounded patience through one long silent call (a hung call still fails at 3× the window); only genuine silence fails, typed, naming the phase. Slow first opens complete; completed opens persist the snapshot; subsequent opens take ~0.3s.

0.63.39 #

  • THE OWNER CAN NUKE LOCAL CUSTODY — an inoperable app is not an acceptable resting state. The startup failure surface now offers "Reset local data and retry": it QUARANTINES this device's snapshot cache (never deletes it) and re-opens, so custody is re-cloned from the cloud. Device authority is untouched and any un-synced local work stays on disk for recovery. This exists because a user staring at a screen that will not open needs a route back to a working application that is not "delete the app and reinstall", and because we cannot promise we will never ship a state the app cannot digest. FileSnapshotStore gains purgeAll(); the web store REFUSES loudly rather than silently purging nothing (quarantine there needs IndexedDB key enumeration, which is not built).

0.63.38 #

  • THE STARTUP DEADLINE MEASURES A STALL, NOT THE WHOLE CEREMONY. It was armed ONCE for all of startup, so a FIRST open — the one path that must do the expensive work — died on the clock while it was visibly progressing, and the retry restarted that same work from the top, so it never converged. A first open has no local custody: the device clones the ledger and verifies the chain from genesis (measured on an iPad 2026-08-07: restore_main 8.2s, of which 8.08s is chain replay across ~40 intents), then materialises genesis and enrols the device. Every subsequent open imports the checkpoint in ~0.3s. The deadline now re-arms on each phase transition — progress resets it — so a startup that stops advancing still fails loudly and typed, naming the phase it died in, while one that is genuinely working is left alone.

0.63.37 #

  • A FAILED BOOT REFUSES AS ITSELF — a transient fault can no longer destroy good local custody. 0.63.36 reclassified EVERY boot failure that happened while a restore snapshot was present as nomos.custody.snapshot_corrupt, whose recommended action is quarantine-and-reclone. Boot does network work, so a cold container or any transient fault threw the device's local custody away and forced a full re-clone — plus a foreign-source clone to satisfy the kernel's colocated reads — which is how a LOCAL-FIRST app came to hang 30s in openingCustody and repeat it on every retry. "Boot failed" is not evidence about the bytes on disk. Only the code that actually read those bytes may condemn them, and those sites now carry their own custody code and quarantine action.
  • Legacy (pre-envelope) and unstamped v2 snapshots restore normally; the workspace-mismatch guard fires only on a stamp that DISAGREES, never on an absent one.

0.63.36 #

  • AN ESTATE CAN BE OPENED AGAIN. Opening an estate failed with "generated application cannot identify the active 'estate' model it would supersede" — the application looking for the estate's own installed law and finding none. The law was never missing on the cloud; the estate's LOCAL custody had never been saved. A generated birth leaves the child resident in the shared kernel before application code ever acquires it, and host save-all was defined as "every connected session" — so a born-but-unopened estate was outside the definition and its custody was dropped on every close. Realm.snapshot(name) now exports mounted, parked, AND born-but-unopened residents, so the estate persists locally and reopens with its own law.
  • Durability is now acknowledged PER WORKSPACE HEAD rather than per session, so a realm holding many workspaces cannot mark one durable on the strength of another's save.
  • A local snapshot that is not this workspace's is refused, not interpreted. Snapshots now carry the workspace they belong to; restoring one into a different workspace is a typed, recoverable custody error (nomos.custody.snapshot_corrupt) that quarantines the bytes — never discards them — and performs one clean authenticated reconnect. A corrupt v2 envelope is likewise refused instead of being fed to the tree decoder as though it were legacy binary custody.
  • The kernel's colocated-read residency requirement is satisfied on the DEVICE, not just in the cloud. The rule is enforced by the kernel, so it fires identically on a phone; it had shipped with only the cloud taught to answer it, which left an estate whose history reads a catalogue unable to open on a device at all.
  • Restaged with the current kernel candidate: regenerated vendored assets (kernel release identity is baked into them). Published pub.dev archives are immutable, so regenerated bytes ride their own version.

0.63.35 #

  • THE SEATED BARRIER GATES WRITING, NOT OPENING. A device seating into an existing home had to prove its enrollment against cloud truth BEFORE the application would render. That proof is five attempts with 1+2+4+8s of backoff, four syncs and five remote reads — comfortably past any startup deadline when the serving container is cold, so a FRESH INSTALL reliably showed a terminal "could not open" screen over work that was still legitimately progressing. Authority gates writing; it must never gate opening. The barrier now runs in the background convergence tail: the home opens immediately, and the device still cannot author until the seat proves (typed, retryable, offers durably parked meanwhile).
  • This is the same defect class as 0.63.33 and it survived that fix because 0.63.33 was verified on a device that already had custody. The path that never worked is the first open on a new device.

0.63.34 #

  • Restaged with the current kernel candidate: regenerated vendored assets (kernel release identity is baked into them). Published pub.dev archives are immutable, so regenerated bytes ride their own version.

0.63.33 #

  • THE LOCAL-FIRST GATE — a cold, slow or absent cloud can no longer stop a home from opening. The home lifecycle used to hold the first frame until sync, a whole-chain replay verification and parent-authority repair had all completed. That is convergence work: it says how fresh and how provable this custody is, not whether it may be opened — and blocking on it made a local-first app unopenable in exactly the conditions it exists to survive. The gate now ends at seated (identity, custody, and the right to author); the tail runs in the background behind the new REQUIRED runConvergenceTail callback and reports as status, never as a gate.
  • Journal v2. HomeBootstrapStage.syncAttempted moved below seated, so a v1 cursor at that stage — which meant "synced but NOT seated", the opposite of what the new index implies — is read down to homeAvailable rather than trusted verbatim. Honouring it would let an upgrading device skip the seating barrier. Re-seating is an idempotent ensure, so the cost is one redundant check.

0.63.32 #

  • A late lawful open BEATS a stale startup deadline. The startup-timeout overlay paints over the still-mounted application scope; when the open then completed (physical-device first opens routinely outlast the deadline), the overlay was never cleared — a permanent "could not open" screen over a WORKING application. _startupComplete now clears the deadline error and rebuilds. Diagnosed live 2026-08-07 from device telemetry: synced sites and a live estate map underneath the failure surface.

0.63.31 #

  • THE SEATED BARRIER (architecture/seated_barrier_and_seal_obligation.md Part 3): a new REQUIRED seated stage in the home ceremony (HomeBootstrapStage.seated + proveSeated on resumeHomeBootstrap). A device seating into an EXISTING home must now PROVE — by reading the cloud's canonical state, never by trusting an ack — that its signer enrollment is durably on the judging chain before the app may author sync-dependent work. A fresh offline home birth is unaffected (enrollment rides the genesis; local truth suffices — offline-first preserved). An unproven seat fails typed + retryable (NomosSeatingPendingFailure, code nomos.client.seating_pending) and resumes at the barrier. This closes the 2026-08-06 class of loss where work signed by a not-yet-durably-enrolled key was doomed at the shared gate.

0.63.30 #

  • NomosHomeSetupFailure.toString() now includes the underlying technicalDetail instead of only a generic recommended-action sentence — a real error visible on screen, not a dead-end "try again" (diagnosed live 2026-08-06 against build 1178's smoke gate, which surfaced only the generic message for a genuine, specific failure).
  • Picks up @githolon/client's ensureParentSignerEnrollment routing fix (this same session): the existing-home device-recovery fallback added in 0.63.29 was itself blocked by a separate routing bug that failed before ever reaching the (already-handled) security refusal — verified live, the fallback now actually runs end-to-end.

0.63.29 #

  • Fix a genuine device-loss dead end: a founded receiving group whose one enrolled device is lost had NO lawful recovery lane (every enrolment door correctly refuses). Repeating birth is a side door the additional-device policy isn't wired to (a real gap — flagged for a proper kernel-level closure, see architecture/guardian_device_recovery.md) but is the only way a genuinely locked-out owner recovers today; seatDeviceInExistingHome now falls back to it, scoped to exactly the named receiving-group-additional-device-requires-current-device-or-guardian refusal so a healthy home's security posture is unaffected.

0.63.28 #

  • Restaged with the current kernel candidate: regenerated vendored assets (kernel release identity is baked into them). Published pub.dev archives are immutable, so regenerated bytes ride their own version.

0.63.27 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.1; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Raise the generated model-adoption retry budget from 4 to 12 governed steps. A long-lived workspace with several unresolved model-lifecycle generations backlogged could exhaust the fixed 4-attempt budget before every domain's adoption converged, even though each individual step was succeeding.

0.63.26 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.105.0; the pub.dev archive now carries the exact npm release stamp proved by this commit.

0.63.25 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.104.1; the pub.dev archive now carries the exact npm release stamp proved by this commit.

0.63.24 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.104.0; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Align the model-adoption host test with the generated accept callback, which now carries an optional dispositions map.

0.63.23 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.103.19; the pub.dev archive now carries the exact npm release stamp proved by this commit.

0.63.22 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.103.18; the pub.dev archive now carries the exact npm release stamp proved by this commit.

0.63.21 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.103.17; the pub.dev archive now carries the exact npm release stamp proved by this commit.

0.63.20 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.103.16; the pub.dev archive now carries the exact npm release stamp proved by this commit.

0.63.19 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.103.15; the pub.dev archive now carries the exact npm release stamp proved by this commit.

0.63.18 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.103.14; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • ApplicationModelApproval.package/.domain gain an optional dispositions field; ApplicationModelDecision.accept, DomainClientModelAdoptionRequired.accept and the generated NomosModelAdoption.accept all thread it through to the kernel's historyPreflight/promoteDomain — a tenant can now acknowledge a genuine field/aggregate removal ({"retired": [sid, ...]}) from model.adopt() instead of only via a raw adapter script.
  • Consumes @githolon/client's fix for a compiler bug where a shared enum's cosmetic export-binding name leaked into its field's business-value-contract hash, manufacturing false-positive evolve refusals.

0.63.17 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.103.13; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Rebuild and release the embedded runner assets from @githolon/client 0.103.13, resolving private framework routes from custodied law and governing installed-but-not-current application model adoption.
  • Consume nomos_client 0.64.14 with the matching generated application lifecycle.

0.63.16 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.103.12; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Ship the coherent 3c5ea6976ea135dfee7d2dbe41f43a715c78eeb69dacdf185ab85dbc392e49c3 kernel and runner, preserving semantic cross-workspace residency across independently resealed replicas.
  • Consume nomos_client 0.64.13 with the matching typed state-position protocol.

0.63.15 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.103.11; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Consume nomos_client 0.64.12, preserving clean resident unborn workspaces between genesis and their first durable push while keeping failed cold mounts retryable.

0.63.14 #

  • Ship the coherent 64114746f15783fc912d2af699a94ff2caccc187e56ccd644a23ea7357e61883 kernel and runner, preserving typed cross-workspace residency and single-replay cold adoption on native clients.
  • Consume nomos_client 0.64.11 with the matching generated runner custody.

0.63.13 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.103.10; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Persist every connected home, catalogue, data-profile and estate holon from the process-wide native plane, allowing the next launch to restore each opaque local custody snapshot instead of downloading and replaying its full cloud history. Ordinary projection metrics now inspect only their routed workspace.
  • Consume nomos_client 0.64.10 with the matching generated runner custody.

0.63.12 #

  • Rebuild the native and browser runner assets with the installed structural-interface cache, so generated application startup performs one compatibility projection read per unchanged workspace frontier.
  • Consume nomos_client 0.64.9 with the matching generated runner custody.

0.63.11 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.103.9; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Consume nomos_client 0.64.8 so periodic metrics refreshes do not fan out unchanged aggregate application status or rebuild tenant UI while preserving seeded status for newly attached listeners.

0.63.10 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.103.8; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Ship the bounded generated application lifecycle and typed custody failure surface with the coherent 171bd538ffccfbf248b2b25962d44676cf78466d5da2dfa32c8618ba5f38bf45 kernel.
  • Retain verified cold-start state, serve cloud cold packs from custody and wait for installed read readiness before presenting a generated application as ready.

0.63.9 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.103.7; the pub.dev archive now carries the exact npm release stamp proved by this commit.
  • Add an exact, fail-closed application model adoption policy for governed tenant law changes.

0.63.8 #

  • Rebuild and release the embedded runner assets from @githolon/client 0.103.6; the pub.dev archive now carries the exact npm release stamp proved by this commit.

0.63.7 #

  • Consume nomos_client 0.64.6, whose published archive now matches the generated application lifecycle and typed operation surface compiled by this release.
  • Fail coordinated publishing when an existing pub.dev archive differs from the package source instead of silently accepting the occupied version.

0.63.6 #

  • Consume nomos_types 0.8.3 throughout the coordinated Flutter release.
  • Ship the coordinated typed kernel candidate across native Apple, Web and cloud runtimes, with nominal protobuf operations and USDA custody replacing string-dispatched framework calls.
  • Preserve typed kernel refusals through application startup so missing governance law cannot be hidden by a compiled fallback or an indefinite loading state.

0.63.5 #

  • Bound generated application startup to 45 seconds across identity credentials, home custody and typed client binding. A stalled phase now reaches the tenant error surface as NomosApplicationStartupTimeout instead of leaving an immortal loading indicator.
  • Keep one process-wide native kernel plane across generated application scopes. Logout/login and widget reattachment now reuse live custody and compiled plans instead of racing multiple workers against the native singleton; a persisted snapshot seeds only a cold workspace and can never replace a resident one.
  • Expose stable authentication, custody-opening, application-binding and ready phases on generated Flutter applications, with an actionable loading surface and retry control supplied by default.

0.63.4 #

  • Coalesce identical home connection requests onto one in-flight open while serializing real credential changes on the same native kernel, preventing rebuilds from duplicating home ceremonies or engine boots.
  • Deliver native JavaScriptCore replies through the push channel instead of re-evaluating settled values, removing the post-offer crash on the production Apple path.

0.63.3 #

  • Cross the one-time USDA custody boundary without restoring pre-USDA local snapshots, while retaining the device identity and re-running the normal offer-gated home availability and birth ceremony.
  • Leave the old snapshot bytes untouched for forensic recovery; future cloud releases are separately blocked unless the candidate kernel can mount, replay and read every retained live workspace.

0.63.2 #

  • Ship the coherent USDA-native kernel candidate across Apple, web and test-mint runtimes, with immutable kernel identity checks and native typed offer/read boundaries.
  • Preserve lawful first-run workspace birth when the typed kernel reports that a birth certificate must be signed, while leaving every other typed refusal intact.

0.63.1 #

  • Run the generated application against the release-pinned external kernel while retaining that verified runtime for offline restart; a fresh-but-wrong local cache is replaced instead of silently reused.
  • Restore application-scale snapshots through the native bulk byte codec, avoiding multi-gigabyte temporary JavaScript allocations for large offline replicas.
  • Ship the coordinated Nomos client which understands complete OpenUSD application placement and framework-owned recovery of home and business-child workspaces.

0.63.0 #

  • Mount the generated domain application as the one Flutter application state. Product code supplies sign-in and business facts, then calls intent-shaped actions such as commissionAsset; framework runtime hosts, repositories and serialization helpers are no longer alternate public lanes.
  • Carry typed NomosRef<T> identities across WebView/WASM snapshots and the production Apple kernel, while Nomos privately seals owned fields and restores their custody after process restart.
  • Add a packed clean-room release gate covering blank-project generation, CO2 multi-record intent fanout, offline merge and replay, macOS native handoff, Flutter analysis/tests and the release web build.

0.62.3 #

  • Fetch the hash-pinned Apple framework during CocoaPods installation without embedding it in the pub package. Its libuv and uvwasi inputs are now source-pinned, every object targets macOS 11 or earlier, and macOS consumers are explicitly Apple Silicon until an equivalent Intel kernel exists.
  • Document the executable-free package boundary: Android and web fetch, verify and retain the immutable kernel on first use; Apple fetches the same release identity while assembling the application.

0.62.2 #

  • Keep the kernel executable out of the pub/npm-facing Flutter package. The runner carries only the production + dev-test release descriptors; Android/WebView and Flutter web acquire the exact immutable artifact by digest, verify it, and retain it in framework-owned custody for later offline process restarts.
  • Permit compatible old and new kernel digests during gradual rollout by checking the active law against both client and cloud capability sets; an incapable app fails before opening custody with an upgrade action.
  • Ship resumable home bootstrap/recovery and truthful automatic parent-first sync. A clean CO2 release build proves offline writes, process restart, generated conflict merge, reconnect convergence and cold replay.

0.62.1 #

  • Keep parent-before-child custody ordering inside Nomos: an offline-born child remains retryable framework work until its parent birth reaches custody, instead of exposing a transient lifecycle state as a business refusal or requiring application-driven sync.
  • Make sync status fail closed when the local frontier cannot be proved, and rebuild the bundled JavaScript runner so Flutter applications cannot report green before acknowledged work is remotely readable.

0.62.0 #

  • Release the full business-first model surface as one Flutter runtime: aggregate conflict policy, deterministic schema evolution, recursive organisation descriptions and generated business clients.
  • Rebuild the JavaScript runner and Apple native framework from the same current kernel as cloud/web. Release checks now require Dart versions, dependency floors, runner assets, native pins and kernel inputs to move together, closing the package-skew failure that exposed cryptographic internals to application developers.

0.61.3 #

  • Ship the exact verified-birth kernel now deployed by cloud and web (d8ee1a70fdaa…) in the Apple xcframework. Cloud deployment, the served wasm, native source identity and both podspec pins now agree; the published client cannot silently run the older pre-lineage kernel.

0.61.2 #

  • Ship the framework-owned birth-lineage ceremony used by the headless harness and the corrected kernel verifier for a root-signed, one-link platform parent. Application code remains one business birth; signer enrollment, delegation, attestation, warrant ordering and certificate retries stay internal.

0.61.1 #

  • Reject a malformed birth certificate chain at the parent admission gate before any birth record or child custody can land. The Apple framework is rebuilt from that exact kernel, keeping native replay identical to cloud and web admission.

0.61.0 #

  • Replace configurable home-birth profiles with one public application contract: NomosScope.home(cloud:, application:, authToken:, builder:). Nomos derives the canonical subject from the token, discovers the active framework/home laws, and owns routing, enrollment, provenance, recovery and persistence internally.
  • Make device bootstrap resumable: the application-scoped key is saved before any remote effect, reused after interruption, and storage failures stop setup instead of minting a replacement identity. Internal lifecycle failures surface as NomosHomeSetupFailure while retaining technical detail for support.
  • Ship the exact compound-key cloud/web kernel (ca687c59887…) in the Apple xcframework. Dart verifies the linked binary's full source-wasm identity at startup; CI, pub release and cloud deploy now refuse any JavaScript/native/cloud skew. There is no engine fallback for a broken package.

0.60.0 #

  • Bundle the one-call business birth runtime and require nomos_client 0.62.0, whose session-bound generated clients derive the verified principal automatically.

0.59.0 #

  • nomos_client floor ^0.61.0 (the era-0 release: signer-ready births — birthHome requires ownerKeyHash; the client auto-signs self-serve birth certs on the kernel's typed refusal; follow/acquireSession accept authorSecret for warranted locally-born children).

0.55.11 #

  • Runner assets carry the colocated attested-read fix: a generated directive's foreign read(q, {from}) now resolves from the mounted source session in-engine (signed envelope, zero HTTP) — the session-alias vs workspace-name keying bug that made it fall through to a 31s HTTP fetch on Flutter. Adds fast-fail SourceSessionNotMounted. Depends on nomos_client ^0.58.0.

0.55.9 #

  • Pin nomos_client: ^0.56.0 (was a wider range in 0.55.8) to match the generated-client pin convention (NOMOS_CLIENT_DEP) — nomos_client 0.56.0 and nomos_flutter move together.

0.55.8 #

  • Widen the nomos_client dependency to >=0.55.0 <0.57.0 so nomos_client 0.56.0 (NomosTestCloud, typed snapshot lifecycle, projectionReadFailed) resolves alongside nomos_flutter — the caret ^0.55.0 wrongly excluded 0.56.0, so the two could not coexist. Bundled JS runner assets are rebuilt from the compound-key-capable @githolon/client at publish.

0.55.7 #

  • Carry the @githolon/client fix: sync() now surfaces a typed pushError (endpoint, status, body) with pushFailed:true / stillAhead:true on a non-2xx/invalid direct offer, instead of a silent pushed:null that hangs the app waiting on custody that never advances. Runner bundle rebuilt. Patch bump — keeps the nomos_client: ^0.55.0 pin valid.

0.55.6 #

  • Export NomosRefAcquire (the ref.acquire(bridge) extension) from the barrel, carrying the nomos_client 0.55.2 session-state DX: explicit workspace state on listWorkspaces(), openable born/resident refs (await outcome.bornRefs.single.acquire(bridge)), and the NomosSession.isConnected/assertConnected() fail-at-bind guard.
  • Patch bump — keeps the nomos_client: ^0.55.0 pin valid.

0.55.5 #

  • Fix NomosScope snapshot persistence for multiple sessions: _exportAndSave now binds head()/export() to bridge.session(workspace) instead of the bare plane-level calls, which refuse "multiple sessions connected — pass session" once an estate/catalogue sibling session mounts — previously silently stopping home snapshot persistence.

0.55.4 #

  • Runner bundle rebuilt to carry issueDelegationCert (the public role-delegation cert lane) and the deriveWorkspaceName addressing helper reachable through the bridge. Native kernel unchanged (efff5199).

0.55.3 #

  • Native iOS/macOS kernel re-pinned to wasm efff5199 (delegated-authority offline births — the delegation-cert gate verifies a platform's grant to K_root on every lane; additive/era-ruled, so verify_chain over the selftest fixture is byte-identical to f4e05b47). Matches the live cloud. nomos_client: ^0.55.0 floor unchanged.

0.55.2 #

  • Native iOS/macOS kernel re-pinned to wasm f4e05b47 (the Surfaced read-collapse fix — replica as string for RFC-8785 canonicalization; byte-identity proven), matching the live cloud. 0.55.1's native path was one kernel behind. Also carries 0.55.1's nomos_client: ^0.55.0 floor.

0.55.1 #

  • Fix: the nomos_client dependency floor was ^0.54.2, not ^0.55.0 — 0.55.0 shipped with a stale floor (a release-process no-op), so a Flutter app using a client generated by @githolon/dsl 0.80.0+ (which pins nomos_client: ^0.55.0) could not pub get without an override. Floor corrected to ^0.55.0. (A pins tripwire now ties this floor to the generated-client floor so they can't diverge again.)

0.55.0 #

  • Bundled runner rebuilt with the adversarial-sweep client fixes (watch rebind, DLQ salvage, self-binding enrollSigner recovery lane). nomos_client floor -> ^0.55.0; bundle stamp 0.80.0.

0.54.1 #

  • Signer-recovery principal normalization fix (see nomos_client 0.54.1); home scope passes the canonical actor. Bundled runner rebuilt. Floors: nomos_client ^0.54.1, bundle >= 0.78.1.

0.54.0 #

  • NomosScope.home recovers parent authority: the born+keyed fast path now verifies the stored device signer is enrolled on the configured parent (one relation read per open) and lawfully repairs after a parent custody rebirth — sibling births no longer refuse with an opaque gate error on a reborn parent. Posture exposed via onParentAuthority / parentAuthorityOf; an unreachable parent records posture and never bricks offline use. Bundled runner rebuilt (enrollment + canAuthor ops, authz diagnosis classification).

0.53.7 #

  • Bundled JS runner rebuilt from @githolon/client 0.77.1 — carries the version stamp the new nomos_client 0.53.0 stale-bundle boot check expects. Upgrading BOTH and rebuilding with flutter clean yields a verified-fresh pair; a stale baked bundle now fails loudly at boot.

0.53.6 #

  • The fast kernel. Native + bundled kernel re-pinned to wasm c23d07b2 — the offer-latency arc: a pooled local offer on co2-scale (3MB) law drops from ~390ms to ~2.7ms on the reference machine (warm-law resident dispatch, gate-scan indexing, amortized fold-root; determinism proven by byte-identity suites + live-chain replay, which also got ~2× faster). Byte-identity proven for the native build; artifact live at the hash-pinned URL.
  • Bundled JS runner rebuilt: the idle intent-walk burn is gone (51.5% CPU → 0.0% under multi-MB law — head-cursored activity walks, size-gated decodes; rows for >192KB intents carry payloadOmitted: true).

0.53.5 #

  • Bundled JS runner rebuilt: offer ack decoupled from watch fan-out (watcher-count-independent ack; co2's grid-offer latency), offer span taxonomy, offerPlanned timing envelope. nomos_client floor → ^0.52.0.

0.53.4 #

  • Native kernel re-pinned to wasm 7cfe416a (Surfaced conflicts + captured-basis + ATTRIBUTED READS — opt-in per-field author provenance; byte-identity proven; artifact live at the hash-pinned URL).
  • Bundled JS runner rebuilt (DLQ session ops, sealing-refusal typed errors, staging lane).
  • nomos_client floor → ^0.51.0.

0.53.3 #

  • Bundled JS runner rebuilt: atomic session re-open (no routable stale record mid-replace) and identity-change re-mount (new credentials on an open session install instead of being silently ignored). nomos_client floor → ^0.50.0 (HarnessPhaseTimeout / phaseTimeout).

0.53.2 #

  • Bundled JS runner rebuilt: local-only sessions no longer register cloud sync machinery (the autoSync deadlock fix). nomos_client floor → ^0.49.0 (acquireSession).

0.53.1 #

  • iOS/macOS native kernel re-pinned to wasm 72604ff7 (the Surfaced/captured-basis kernel, byte-identity proven) — 0.53.0's podspecs still pinned the previous kernel, which would have put the native path one kernel behind the bundled JS runner. Artifact live at the hash-pinned runtime URL.

0.53.0 #

  • Bundled JS runtime rebuilt: the runner gains the interfaceOffer op (session-bound client preflight) and the pendingConflicts/watchPendingConflicts lanes (Surfaced conflicts).
  • nomos_client floor → ^0.48.0 (session-bound clients, Surfaced DX).

0.52.3 #

  • No code change — bumps the nomos_client dependency floor to ^0.47.0 (the release that actually carries the Dart-level createWorkspace(domain: ...) signature; 0.52.2 fixed the bundled JS runtime but the corresponding nomos_client publish was missed — see nomos_client 0.47.0's changelog).

0.52.2 #

  • Fix: createWorkspace hardcoded domain: "workspaces", so a tenant birthing through their OWN platform's custom law (e.g. a birthEstateWorkspace directive under a co2_platform domain) was refused by the kernel: the sealed intent always claimed domain: "workspaces" regardless of which law actually declared the directive. Added a domain parameter (default "workspaces", fully back-compatible) to NomosBridge.createWorkspace and the underlying @githolon/client createWorkspace/runner handler; call bridge.createWorkspace(domain: 'co2_platform', directiveId: 'birthEstateWorkspace', domainHash: ..., ...) to birth through a custom platform law. Regression added proving the parameter reaches the signer (a domain the workspace doesn't declare is correctly refused BY NAME, never silently dropped to "workspaces") and that the no-domain default is unchanged.

0.52.1 #

  • Fix: the 0.52.0 pub artifact embedded a STALE (pre-compact) native framework, defeating the kernel_sha pin — CocoaPods skipped the fetch because Frameworks/ already existed on disk (a build-hygiene bug: a local Frameworks/ dir was present at publish time; macos/Frameworks/ was missing from .pubignore while ios/Frameworks/ had it). Fixed the asymmetry, removed the stale local artifact, and HARDENED both podspecs: prepare_command now stamps the fetched kernel_sha and re-fetches whenever the stamp disagrees with the pin, instead of trusting bare directory presence. Added native/check_release_framework.sh — a release-gate script (no embedded Frameworks/ + the pinned runtime URL actually serves the expected compact-era parser marker) to run before every future dart pub publish.
  • Fix: createWorkspace/shareWith runner handlers forgot to await the (async) connected-holon lookup (need(a) is async; the handler used the unresolved Promise, so typeof h.createWorkspace was always the string for "undefined", failing every estate-creation call with "connected holon does not expose createWorkspace()" even on a correct kernel). Fixed at the source (cloud/web-client/src/webview-runner.mjs) and rebundled into both assets/nomos-native.js and assets/nomos-runner.js.

0.52.0 #

  • Native kernel resync (COMPACT-CAPABLE). The bundled NomosKernel.xcframework is rebuilt from kernel 7394d6fe (compact-native, 2026-07-07) — the SAME bytes the cloud runs. Fixes: the native macOS/iOS runtime could not open a workspace whose lineage (active OR superseded) contains a compact-era package — it rejected the then-current package encoding. The prior published native kernel (891bad48, 2026-07-04) predated compact support; the Dart wrapper had advanced without resyncing the AOT.
  • Guardrail (the improvement): stale-native is now self-diagnosing. A USDA-encoding parse failure is rewritten into an actionable error naming the on-device native kernel (kNativeKernelSha) + the fix (upgrade nomos_flutter / rebuild), with code nomos.native.stale-kernel — never a cryptic field name. Requires nomos_client >= 0.46.0. Rebuild your app so the podspec pulls the new xcframework.

0.51.0 #

  • NomosScope / NomosScope.home expose onCustodyBreak (a CustodyBreakPolicy) for the FIRST workspace mount — plug-and-play rebirth handling (co2 feedback). Threaded scope → home scope → bridge.connect; the barrel re-exports CustodyBreakPolicy/NomosCustodyBreak/NomosCustodyStatus/ NomosCustodyEvent so apps need no direct nomos_client import. Null keeps the fail-closed default (typed break, never silent adoption/loss). Requires nomos_client >= 0.46.0.

0.50.0 #

  • Bundles the current @githolon/client runner: bridge.attestedRead(from: <sibling>) now resolves IN-PLANE from a colocated local-only workspace (the explicit API shares the offer-path colocation resolver) — a cross-workspace local read no longer fails attested-read-unreachable/no active installed law declares that query. Pairs with nomos_client ≥0.41.0.

0.49.0 #

  • NATIVE REALM MIGRATION: the native (dart:ffi) path now runs the SAME shared runner + realm plane every other host runs (createWebviewRunner over openRealm with a native FFI engine plane) — the hand-rolled native ops table and session map are deleted, so the native op surface can no longer drift. This brings the native path: the 11 previously-missing ops (dead-letters, the crypto/E2E surface, checkCompat/compatHas, pull, manifests, …), per-session lawChanged forwarding (compat live-events now work natively), locally-born children opening IN-PLACE, in-plane colocated attested reads, and LRU park/remount (connect(maxMounted: …)), all conformance-tested on macOS. Pairs with @githolon/client 0.60.0 (the bundled runner).
  • FIX (per-session auth): the native transport no longer keeps a global last-connect-wins auth header map — one session's x-nomos-auth never rides another session's cloud traffic. The holon's own per-session headers are authoritative on fetches (parity with the WebView/web paths); the pack byte-shuttle and the doorbell WebSocket resolve THEIR session's credential. Conformance: test/native_multisession_auth_test.dart (a loopback fake cloud records auth per request; a tokenless session must not inherit a sibling's token).

0.48.0 #

  • FIX (native multi-session regression): the native (dart:ffi) transport now retains EVERY connected session. Previously a second bridge.connect(workspace:…, session:…) re-booted the single global kernel, replaced the JS engine, and overwrote the singleton workspace placement — listWorkspaces() showed only the latest session and earlier sessions failed session '…' is not connected. The engine now boots ONCE and keeps a per-session placement map (kernel calls, ws files, git tree, restore staging, pack apply, export all route by the session key native-entry stamps on every provider message), and connect forwards session to the runner.
  • FIX: a LOCAL-ONLY session (no cloud) works on the native path — the local:// sentinel never touches dart:io networking (the workspace-status probe answers unborn locally, parity with the node runner's offline lane), and connect no longer requires a cloud argument.
  • Native-path conformance test (test/native_multisession_test.dart, macOS): home connect → sibling connect → listWorkspaces contains both → home query + pre-existing watch still answer → child query/watch works. Runs under plain flutter test against the repo-built kernel slice via the new native/build_test_dylib.sh (the static macos-arm64 slice linked as a loadable test dylib).

0.42.0 #

  • Depend on nomos_client ^0.32.0 — spatial reads (NomosBbox, spatialWithin, watchSpatial) reach app clients; pairs with the ≥0.46 compiler wave (semantic enum names, analyzer-clean output, all-creates proofs with spatial membership).

0.41.0 #

  • Depend on nomos_client ^0.31.0 — pairs with the 0.42/0.43 compiler wave: the runtime aggregate-meta registry (NomosAggregateMeta/NomosFieldMeta incl. fromBirth), variant() sealed unions, unit() extension types, idOf() typed ids, fromBirth() non-nullable read models, and copyWith on generated VO/arm classes. Recompile domains with @githolon/dsl ≥0.43 tooling.

0.40.0 #

  • Depend on nomos_client ^0.29.0 — the headless test lane (NodeRunnerTransport + NomosTestHarness in package:nomos_client/nomos_headless.dart) and the law-minted-id offer surface (offerCreates/mintId) are available to app test suites; flutter test drives the real githolon with no plugins/WebView (proof: test/headless_transport_test.dart).

0.39.0 #

  • WEB SUPPORT: nomos_flutter now compiles and runs on Flutter web. The browser is itself a JS/wasm host, so web uses NO dart:ffi and NO WebView — a new dart:js_interop transport (web_transport.dart) loads the same @githolon/client browser runner (nomos-runner.js) in-page and drives it over the identical NomosBridge wire. Platform selection is via conditional imports (engine_host.dart), so dart:ffi/flutter_js/flutter_inappwebview never enter the web graph; native (iOS/macOS AOT) and Android (WebView) paths are unchanged. Web persistence (snapshots + device keys) is backed by IndexedDB (async, large-capacity) — NOT localStorage — so a durable save never blocks the main thread or hits the ~5MB cap. Proven end-to-end against the live cloud: connect, ledger clone, offline write → edge admission → main, undo/redo (kernel strike), history, and the profiler flame chart all run in-browser. (Known follow-up: on very large ledgers the runner runs on the single JS thread; a Web Worker host is future work.)

0.38.0 #

  • macOS NATIVE: macOS now runs the native-AOT kernel (the macos-arm64 slice of the same xcframework iOS uses) instead of the WebView engine — faster, no WKWebView memory cap, byte-identical. New macOS plugin (macos/nomos_flutter.podspec force-loads the macos-arm64 slice; macos/Classes/NomosFlutterPlugin.swift). _nativeEngine now covers iOS+macOS by default; set NOMOS_FORCE_WEBVIEW=1 to opt back to WebView on macOS. After upgrading: cd macos && pod install. Android stays on the WebView engine.

0.37.1 #

  • DX: clearer macOS error when the native path is FORCED (NOMOS_FORCE_NATIVE=1) without a linked macos-arm64 kernel slice — the loader now explains macOS uses the WebView engine by default + how to fix, instead of a cryptic "framework not loadable". (No behaviour change: macOS has always defaulted to WebView; _nativeEngine is iOS-only unless NOMOS_FORCE_NATIVE=1.)

0.37.0 #

  • TYPED SNAPSHOT RECOVERY: a corrupt local snapshot is no longer lose-it-or-keep-a-broken-app. Connect with recover: true (via the bridge) to recover IN-PLACE — salvage local-only writes + DLQ from the corrupt snapshot, refold fresh from cloud, re-offer the salvaged work. NomosClient.recovery{salvagedWrites, requeuedDeadLetters, unsalvageable} (unsalvageable = writes the current law refused — kept in the DLQ, never dropped). Quarantine-then-recover becomes one connect. Same kernel (the salvage verbs were already fallible — no deploy).

0.36.0 #

  • TIER-2 SYNC SIZE (aggregate-before-download): NomosClient.syncSize(){bytes, kind} via a HEAD on the serving pack (host answers Content-Length, no body, cached ~15s). Sum across your open workspaces to show "X MB to sync" BEFORE any download starts; per-workspace transferProgress (0.35) then fills the bar. Host endpoint live (HEAD /v2/workspaces/:ws/pack). Same kernel.

0.35.0 #

  • SYNC-STATE UI + REAL LOADING BARS (tier 1): NomosClient exposes syncStatus (truthful aggregated state), transferProgress (live pack byte-progress), currentStatus. The native pack shuttle streams the response + emits {received,total,kind} from the host Content-Length (the warm host packs then sends, so the real total is in the headers before the body) — real 0→100ars, never estimated. Drive a sync-state page off nomos.syncStatus. See co2-handover/SYNC_STATE.md (incl. the tier-2 HEAD /pack aggregate-size spec).

0.34.0 #

  • NATIVE LOCAL WORKSPACE CREATION FIXED: the iOS AOT kernel now uses uvwasi for its filesystem syscalls instead of the incomplete hand-rolled wasi shim. The multi-workspace kernel can init a fresh LOCAL workspace on device (the birthEstateWorkspace "Unreachable instruction" trap is gone) — estates/sites/assets all init locally, offline-first, then sync. Same canonical kernel wasm (07929c03); only the per-platform wasi provider changed. Determinism preserved: clock/random stay pinned to constants (the kernel takes time/entropy from captured ports), proven byte-identical (b6fea50e). REQUIRES re-fetching the kernel xcframework: rm -rf ios/Frameworks/NomosKernel.xcframework && pod install.

0.33.0 #

  • STRICT device-binding for keyless onboarding: NomosScope.home gains authTokenForDevice(devicePublicKey) => Future<String>. The ceremony mints the device key FIRST, then calls back for an IdP token whose nonce == sha256(pubkey) (e.g. a Firebase Cloud Function that mints a device-bound custom token). Overrides the static authToken (the relaxed lane). Needed when the parent AuthProvider sets requireDeviceBinding:true. Same kernel (07929c03). See co2-handover/STRICT_FIREBASE.md.

0.32.0 #

  • KEY-FREE GOVERNANCE: createWorkspace / shareWith (and NomosBridge) default authorSecret to the connection's signing key — the home device key NomosScope.home already loaded. A frontend dev never handles a key to make a workspace or share it. Same kernel (07929c03); Dart-only.

0.31.0 #

  • OFFLINE BIRTHS no longer trap on device: the native kernel folds the parent shallow-safe (resident frontier, never the panicking genesis walk) when running a .births() offer-effect locally (home/birthEstateWorkspace). A new estate births on-device + syncs to the edge. New kernel 07929c03 (byte-identical fold/verify). REQUIRES re-fetching the kernel xcframework.

0.30.0 #

  • RECOVERY / new-device on a BORN home: NomosScope.home now enrolls THIS device on an already-born home (via the admin-delegated enrollmentGate or keyless verifiedVia) instead of no-opping — so a lost/never-saved device key is recovered on reopen, keeping the homes data (no re-birth). Pairs with the 0.28 device-key store.

0.29.0 #

  • Re-exports nomos_client 0.23.0 (shareWith cross-custody sharing). Bumps the nomos_client floor to ^0.23.0.

0.28.0 #

  • Device key now PERSISTS: NomosDeviceKeyStore (authority credential, separate from the snapshot, file default + Keychain-swappable). NomosScope.home loads it on launch, saves the minted key on first birth, and reconnects SIGNED — a born home survives a device/session change. deviceKeyStore param. Requires nomos_client ^0.22.0.

0.27.1 #

  • Durability without the memory bomb: the durable-save-on-write now backs off adaptively (next save gated to ~4x the last save's cost) so the full-ledger re-serialize can never pile up faster than it completes — fixes an iOS jetsam crash on a large ledger where per-keystroke full-tree exports exhausted memory. The 45s periodic
    • lifecycle saves remain the backstops.

0.27.0 #

  • Local-first durability — a delete (or any write) now survives force-quit + reopen, and lands as a visible "saved" number. Three fixes: (1) the snapshot persists the converged fork point (syncedBase), so restore replays the un-synced local tail instead of resetting it to cloud main (the delete-resurrection bug); (2) the author is persisted durably OFF the author thread the instant a write seals, emitting a persist span — the new "saved" metric (NomosScope shows ready / saved / →main); (3) a thrown converge replay is dead-lettered, never silently dropped. NomosScope.dispose now tears down ordered (final save → bridge dispose) — no more bridge disposed race on app close. Kernel unchanged (1249458d…). Proven on the macOS native harness: delete → kill → reopen → still deleted.
  • Integrates the home-onboarding line (0.22.x): HomeBirth.enrollmentGate/HomeBirthEnrollmentEndpoint, the signed first-birth raw fallback, and allowUnborn home scopes — see the 0.22.x entries below.

0.26.0 #

  • Kernel pin → 1249458d… (the O(state) checkpoint-restore cloud kernel, deployed worker 5eaffe41): the #58 stable-id lineage check no longer discards a materialized projection. materialize_from_fold now STAMPS the projection's label_lineage (via stamp_materialized_lineage) at BOTH call sites — checkpoint_import (the container cold-mount) and canonicalize_projection (runs on EVERY client converge). Before, the materialized read model had label_lineage = None while the law derived a non-empty stable-id target, so the first read EVICTED + cold-refolded the whole chain from genesis (O(chain)) — the 60–158s client converge and the 24s container cold-mount. Now the restore is O(state): proven 132ms vs 2776ms (400 commits), flat 120/400/800 → 111/122/138ms. Era-safe — verify_chain is untouched (verdict b6fea50e… unchanged), so every live ledger replays byte-identically. Hash-pinned xcframework at /v1/runtime/ios/NomosKernel-1249458d….xcframework.zip.
  • A native client built before this is on a stale kernel — rm -rf ios/Frameworks/NomosKernel.xcframework then pod install to re-fetch.

0.25.0 #

  • Kernel pin → c8152e9d… (the GENERICISATION cloud kernel, deployed worker 15080fcf): the kernel names NO domain/directive/aggregate by ad-hoc literal — AuthProvider, the x5c rotation trigger, the birth-cert seed, and the genesis-install primitives are first-class (kernel-owned, the law compiles to them, drift-guarded); parent-attested birth reads its owner/cert locators from the law's declaration; the keyless arm reads its directive + payload fields from the law. Behaviour-identical + era-safe — every live ledger replays byte-green (verdict b6fea50e… unchanged), so this is a transparent superset of 0.24.0.
  • Supersedes the (never-published) 0.23.0/0.24.0 keyless line — this is the first pub.dev release carrying the keyless self-serve home birth AND the genericisation kernel. Hash-pinned xcframework uploaded to /v1/runtime/ios/NomosKernel-c8152e9d….xcframework.zip.
  • A native client built before this is on a stale kernel — rm -rf ios/Frameworks/NomosKernel.xcframework then pod install to re-fetch.

0.24.0 #

  • Keyless self-serve home birth — HomeBirth.keyless(...). A new user births their home with NO admin and NO server in the loop: pass their IdP token as NomosScope.home(authToken:) and birth: HomeBirth.keyless(parent:…, frameworkHash:…, lawHash:…, verifiedVia: <the parent's AuthProvider issuer>). The bundled @githolon/client ceremony mints the device key, bootstraps it on the parent via enrollFirstDevice (the on-chain device-bound IdP attestation the kernel re-verifies on every lane), then births the home — all in the embedded engine. Runner assets rebuilt with the ceremony.
  • NOTE: under the kernel's STRICT device-binding default the token must carry a nonce/cnf == sha256(the device pubkey). A plain IdP token works when the parent sets requireDeviceBinding:false (the bounded-window lane); full strict device-binding via a sign-in callback is the documented follow-up.

0.23.0 #

  • Kernel pin → 75014bd1… (the keyless verified-first-device cloud kernel — superset of the signer-schema kernel): a brand-new IdP-verified user can self-enroll its FIRST device-signer on a WARRANTED workspace from an on-chain, device-bound IdP attestation (enrollFirstDevice) — self-serve + peer-to-peer, no admin/server in the loop. Era-gated + inert unless a law composes the directive, so every existing chain replays byte-identically (verdict b6fea50e… unchanged). Hash-pinned xcframework uploaded to /v1/runtime/ios/NomosKernel-75014bd1….xcframework.zip.
  • A native client built before this is on a stale kernel — rm -rf ios/Frameworks/NomosKernel.xcframework then pod install to re-fetch.

0.22.9 #

  • Add HomeBirth.enrollmentGate and HomeBirthEnrollmentEndpoint so a tenant can run its live device enrollment gate before the signed home-birth offer. This keeps device secrets local while letting the tenant verify Firebase/AuthProvider identity and record the parent signer/delegation facts.
  • Rebuild the embedded runner assets with @githolon/client 0.24.10, including x-nomos-auth forwarding for the first-birth raw signed fallback.

0.22.8 #

  • Rebuild the embedded runner assets with the first-birth signed raw fallback. When the home bridge is still unborn/lawless and cannot locally seal home/birthHome, NomosScope.home now sends the parent birth payload with the minted device key for the kernel author door.

0.22.7 #

  • Rebuild the embedded runner assets with the signed-author home-birth fix. NomosScope.home now seals the parent home/birthHome offer locally with the minted device key and relays opaque intentBytes, so warranted platform workspaces no longer reject first-launch home birth for missing authorSecret.

0.22.6 #

  • Rebuild the embedded runner assets with the first-birth lawless-home enrollment fix. NomosScope.home no longer fails before the parent birthHome offer when the home has not yet installed its law.

0.22.5 #

  • Rebuild the embedded runner assets with allowUnborn forwarding in the native and WebView entrypoints. This is the patch that makes NomosScope.home's unborn-home first launch work through the published Flutter package.

0.22.4 #

  • Rebuild the embedded @githolon/client runner assets with the home-birth custody-head race fix. The birthHome ceremony now waits for the born home to have a ledger head before peer verification, and the ceremony's HTTP calls use the native injected transport.

0.22.3 #

  • NomosScope.home now passes the bridge's unborn-home opt-in before running the birth ceremony. This fixes the iOS/native first-launch failure where connect threw workspace '<home>' has no ledger main before birthHome could create and verify the home. Plain NomosScope remains strict.
  • Depends on nomos_client: ^0.20.2.

0.22.2 #

  • Structured Nomos runtime failures. NomosNativeTransport now preserves { error, errorInfo } from the shared runner/provider boundary instead of collapsing failures to strings, including provider, fetch, kernel-call, watch, and auto-sync paths.
  • The native iOS FFI facade now catches WABT wasm_rt_trap failures around nomos_call and returns nomos.native.wasm_trap as structured JSON instead of aborting the app process. The hash-pinned NomosKernel-04a04ef3....xcframework.zip runtime artifact has been rebuilt and uploaded.
  • Depends on nomos_client: ^0.20.1.

0.22.1 #

  • Native/WebView microtask shim. Bare JavaScriptCore in the iOS flutter_js path does not expose queueMicrotask, but the shared @githolon/client orchestration uses it for process.nextTick and post-offer warm queries. The generated nomos-native.js / nomos-runner.js bundles now install a standards-shaped queueMicrotask fallback before client code loads, so native estate/workspace offers do not fail with Can't find variable: queueMicrotask.

0.22.0 #

  • Publish the regenerated JS orchestration bundles from the @githolon/client 0.24.1 build. The generated nomos-runner.js / nomos-native.js assets are no longer tracked in Git; release tooling builds them from source and includes them in the pub package, so Flutter consumers get current bytes without CO2 carrying a local path override.

0.21.1 #

  • Native (iOS) text-codec shim — no tenant patch needed. Bare JavaScriptCore (the flutter_js engine) has no TextEncoder/TextDecoder; the client orchestration uses them, so the native path crashed at load and required a hand-patch. The bundled nomos-native.js now carries a pure-JS, WHATWG-correct TextEncoder/TextDecoder (byte-identical to the platform impl, parity-tested), so NomosScope boots on-device out of the box. The asset is now auto-synced from the build (no stale bundle). If you carried a local native_transport.dart polyfill, you can delete it.

0.21.0 #

  • Kernel pin → 04a04ef3… (the serve-path fold-root certification + warrant verify cloud kernel): the iOS native shell now runs the S1 serve-cert kernel and can verify its OWN warranted home locally (the warrant-flip is LAW-only, but the shell needs this kernel for the serve-cert + on-device home verify). Byte-identical to cloud/web — proven THREE ways on the pinned verifyChain fixture (verdict b6fea50e…): the wasm2c-native AOT build (the iOS kernel), Node's builtin node:wasi, and the @bjorn3/browser_wasi_shim the cloud edge + web peers run all produce the same 435-byte response. The hash-pinned xcframework (device+sim+macos) is rebuilt via wasm2c (--module-name holon, 8 outputs) and uploaded to the cloud runtime store (GET /v1/runtime/ios/NomosKernel-04a04ef3….xcframework.zip → 200).
  • A native client built before this is on a stale kernel — rm -rf ios/Frameworks/NomosKernel.xcframework then pod install to re-fetch (the prepare_command only re-fetches when the local framework is absent).

0.20.0 #

  • The native (iOS) path now runs the ONE @githolon/client orchestration (index.mjs) inside an embedded JS engine (flutter_js / JavaScriptCore) over an FFI kernel provider + a dart:io fetch — the Dart _Holon reimplementation of connect/offer/sync/the ceremony is DELETED. One orchestration on every peer; JS↔Dart drift is structurally impossible. THE RAM LAW: the ~1GB holon stays in NATIVE memory — the JS engine runs only the light control plane; packs/snapshots never enter the JS heap (proven: export keeps bytes native).
  • Authority: NomosScope.home(subject:) binds the actor onto generated clients automatically; gated directives throw MissingOfferAuthority before submit. nomos_client → ^0.20.0.
  • RESIDUAL: the native runtime is structurally + unit + crypto-parity (SHA-256 shim ↔ WebCrypto) proven but NOT yet validated on a physical iOS device — run a birthHome + sync on-device to confirm flutter_js boots.

0.19.0 #

  • Native home-birth parity (co2). The iOS native (dart:ffi) path now runs the full VA home-birth ceremony, matching the WebView engine. Two fixes:
    • NomosScope.home no longer dies when the home is unborn: native connect now TOLERATES an unborn workspace (boots an empty holon — the kernel crypto/ceremony ops need no chain state, parity with the WebView "unborn is fine"), so the birth ceremony in onConnected actually runs. After the birth the holon delta-pulls the full born chain. (Before: native connect threw "no ledger head" and the ceremony never fired.)
    • The five VA ceremony bridge ops are now wired on the native transport (they were declared on the bridge but only implemented on WebView): mintDeviceKey, signBirthCert (kernel cert_sign), enrollDevice (offers home/enrollSigner), verifyChain, and birthHome (the full ceremony — mint+enroll the device key → device-sign the home cert → offer the parent's birthHome → poll born → verify_chain). Exact parity with @githolon/client birthHome.
    • ONE native deviation: the post-birth peer-verify runs verify_chain on the connected holon (which connected empty to the home name and delta-pulls the born chain — a genuine fresh peer) rather than spinning up a second holon, because the native worker runs one process-singleton wasm module.
  • Pairs with the cloud fix (worker f7dd87a2) that persists offer-effect-born children to their own custody — so a native birthHome now lands a child with a real head (was head:null).

0.18.0 #

  • Kernel pin → 169d1fee… (the Verified Authority cloud deploy): VA core, the peer-sovereign birth-cert root-of-trust, offline-births enforced at the custody boundary, and the drift-proof cert_sign op. Byte-identical to cloud/web (prove_byte_identity.sh green — the self-test fixture replays identically); the hash-pinned xcframework is uploaded to the cloud runtime store.
  • nomos_client^0.18.0. NomosScope.home now runs the VA birth ceremony (mint + enroll the device signing key, device-sign the home cert via cert_sign, offer birthHome, poll + verify).
  • A native client built before this is on a stale kernel — rm -rf ios/Frameworks/NomosKernel.xcframework then pod install to re-fetch (the prepare_command only re-fetches when the local framework is absent).

0.17.0 #

  • FIX the invalid plugin spec that broke 0.16.2 on pub.dev: Android/macOS were declared with the legacy pluginClass: none, which current Flutter rejects. They are now correctly OMITTED from the plugin block (consumed as a plain Dart package on those platforms; iOS keeps the native-AOT kernel plugin). 0.16.2 cannot be overwritten, so this is the corrected republish — pin ^0.17.0 (not the broken 0.16.2).
  • Depend on nomos_client: ^0.17.0 (lockstep birth-primitive release).

0.16.2 #

  • Restore Android + macOS support (hidden-WebView engine); iOS keeps the native-AOT kernel.
  • Depend on the renamed nomos_client (was nomos_dsl).

0.1.0 #

  • Initial release. NomosScope boots the real Nomos GitHolon (the byte-identical wasm32-wasip1 artifact) inside a hidden, secure WebView host and hands your builder a connected NomosClient — drive it with the typed Dart client nomos compile generates.
  • Hosts the runner over a loopback http://127.0.0.1 origin (a secure context, so crypto.subtle + storage work) via flutter_inappwebview — the robust WKWebView/Android-WebView embedding. macOS/iOS/Android/web.
0
likes
0
points
4.18k
downloads

Publisher

unverified uploader

Weekly Downloads

Drive the real Nomos GitHolon from a Flutter app — a local-first domain runtime. Apple runs the release-pinned native kernel; Android and web acquire and retain the release-pinned WASM runtime. Write TypeScript domains, get a typesafe Dart client, build Flutter widgets.

Repository (GitHub)
View/report issues

License

unknown (license)

Dependencies

crypto, ffi, flutter, flutter_inappwebview, flutter_js, nomos_client, nomos_types, path_provider, web

More

Packages that depend on nomos_flutter

Packages that implement nomos_flutter