Ouroboros now delivers the Claudexor engine it integrates (PR #101 shipped
the integration without the runtime; a user upgrading in-app hit a dead
`claudexord_not_installed` Connect). This lands the owner-locked design:
- one exact pin (`ouroboros/claudexor_runtime_pin.json`, now bound to the
public Claudexor 3.3.7 bytes: build a4b004d7, sha256 fe07b839…, official
Node 24.16.0 for all five platforms) drives seed, download, verify and
next-spawn selection; a filled pin never degrades to a PATH binary;
- hybrid delivery: the release archive ships as an offline seed in new
DMG/tar/zip bundles and downloads foreground-only for upgraded old
installs, strictly inside an explicit user action (Connect, Repair or a
delegated/review start) with visible progress;
- one morphing Connect button (Install/Update/Fix & connect); updates stage
side-by-side and activate at the next natural daemon start or Ouroboros
restart, never hot-swapping a live daemon; a repair never replaces the
serving target of a live matching daemon;
- 3-OS CI gate and release-artifact smokes now exercise the real managed
chain (install → exact probe → owned daemon → delegated run →
identity-bound graceful stop) instead of `npm install -g claudexor@next`;
- Windows fail-fast helper for critical PowerShell 5.1 steps, utf-8-pinned
subprocess decoding, handshake reads the frozen `engine.sha` contract.
Review: triad (fable, sol scope, gemini) + adjudicated batch + confirmation
+ pin confirmation, all SAFE; suites on this base: Python 7775/1 skipped,
web 138/138, delivery tests 17/17, managed fixture smoke end-to-end.
Co-authored-by: Claudexor <noreply@claudexor.dev>
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>