proximo (0.40.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.40.0 (minor: doctor says where near-root exec lands.
    ct_exec and the node shell ride an ssh target or run on the box itself, never the
    API, so the machine the API reads and the machine a near-root command lands on can
    differ, and nothing said so. proximo doctor now reports exec_lands_on whenever a
    shell feature is on, resolves the ssh target through ssh's own config, counts every
    name and address this machine goes by as one host, and flags SPLIT TARGET with a
    remedy an operator can follow as written. Also in this release: the shadow-key flag
    compares every set-valued key the way its gate reads it, so a reordered allowlist is
    no longer a change while a mode keyword stays a single token; the TLS warning counts
    a pinned fingerprint as verification. 908 tools unchanged).

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Fri, 05 Sep 2026 04:10:00 +0000

proximo (0.39.1-1) UNRELEASED; urgency=medium

  * Track upstream 0.39.1 (patch: an allowlist refusal names the store that fed it.
    ct_exec and its siblings refused a CTID by naming a variable rather than a store,
    and that variable lives in two of them, the MCP client's env block and
    proximo.env, where the loader fills only keys the block has not set. An operator
    could edit a dead line and see the same refusal after a reconnect. Now the loader
    names every file key the process environment shadows with a different value (keys,
    never values), the config records where each allowlist came from, every refusal at
    the server and backend layers names that source for both launch shapes and says a
    restart or reconnect is required, and proximo doctor reports the source and flags a
    differing shadow. Also in this release: the base image moves to the python:3.13-slim
    tag head with both stages pinned together and a test that refuses a partial bump;
    the allow-all warning knows when the reach mirror is on and names the privilege; and
    the public release commit subject carries the changelog thesis instead of a bare
    version string. 908 tools unchanged).

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Fri, 04 Sep 2026 03:36:00 +0000

proximo (0.39.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.39.0 (minor: the junction gets its law. The reach mirror keys
    ct_exec/ct_psql on the served token's own PVE permission map, asked per guest path,
    fail-closed, dormant until PROXIMO_REACH_PRIVILEGE is set; the reach grant is
    witnessed in the PROVE ledger at serve start on every door, and while the mirror
    enforces, the witness derives the PVE-side per-guest reach too, so a pveum grant or
    revoke between starts lands as a delta; proximo reach-audit prints the privilege
    decision evidence live, semantics beside aliasing; proximo harden prints the
    operator recipe for every unerected pillar with --check teeth; pve_node_logs and
    pve_node_diagnose open the host's read half behind their own opt-in and the mirror
    at /nodes/<node>; an unknown CLI verb refuses instead of serving; docs/JUNCTION.md
    carries the design argument. 908 tools, up from 906).

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Mon, 31 Aug 2026 23:50:00 +0000

proximo (0.38.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.38.0 (minor: new capability. A new armgate leg gates the ssh ->
    pct exec path that the PVE token never touched, so a disarmed caller can no longer
    run in-container commands with every other gate satisfied. An adversarial pass then
    took the gate apart and four things around it were fixed: the gate now judges the
    box a command is aimed at rather than the process environment, with arm_source and
    readonly_source as per-target registry fields that are never inherited from the env,
    so one box's arm cannot authorize another and a target with exec enabled but no arm
    source of its own is refused; pointing the arm source at the served token is refused
    rather than read as armed forever; ct_diagnose joins ct_logs as available while
    disarmed, since a diagnostic that goes dark on disarm is the wrong shape, reached by
    a new keyed ExecBackend.probe that takes a probe name and never argv; failing probes
    now report why instead of a bare exception class; and the arm-before-lease gate order
    is pinned by a mutation-proved test. 906 tools unchanged).

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Mon, 24 Aug 2026 04:20:00 +0000

proximo (0.37.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.37.0 (minor: new capability. A journal anchor sink, the second
    write-only witness and the audit module's last named extension: heads are appended
    to systemd's journal over its native protocol, needing no collector and inheriting
    the journal's retention, rotation and FSS sealing (journalctl -t proximo-anchor).
    Its field-injection defence uses journald's length-prefixed binary form, so hostile
    values travel intact rather than being sanitized to a token. Separately, a pinned
    TLS bundle is now a trust anchor on every interpreter: Python 3.13 changed the
    defaults create_default_context applies, so one pinned file had been verifying on
    one Python and failing on the next; httpx_verify sets VERIFY_X509_PARTIAL_CHAIN and
    deliberately leaves VERIFY_X509_STRICT alone. Guidance now says pin the node
    certificate, not the cluster CA, which Proxmox issues without keyUsage. 906 tools
    unchanged).

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Sun, 23 Aug 2026 22:10:00 +0000

proximo (0.36.1-1) UNRELEASED; urgency=medium

  * Track upstream 0.36.1 (patch: the runtime image stops shipping its own
    installer. The runtime stage now uninstalls setuptools, wheel and pip once
    the hash-pinned install is done, and the python:3.13-slim base digest held
    back on 2026-08-17 is taken. Both HIGH findings that caused that hold live
    in one place, pip's vendored tree, so removing the installer removes their
    single source; the container also no longer carries a working package
    manager. Measured, not assumed: pip 26.1.2 and 26.2.1 vendor identical
    copies of the flagged packages, so the code was in the shipped image all
    along and only its detectability changed. No Python source change; the
    published wheel is unaffected. 906 tools unchanged).

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Sun, 23 Aug 2026 21:05:00 +0000

proximo (0.36.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.36.0 (minor: the external-report release. proximo_read
    joins the default lean facade — a read-only dispatch door whose
    readOnlyHint=true is enforced, not labeled: the verdict derives from the
    same READ-ONLY/MUTATION docstring marker that emits every hint, and a
    mutating, unmarked, or dispatcher tool refuses before dispatch. 33 read
    tools gained their missing READ-ONLY marker; the facade trio carries
    hints now. Two new PROVE anchor sinks: http (GET/PUT one pin resource on
    a remote receiver, TLS with no off switch, redirects refused) and syslog
    (write-only witness — appends every clean verify's head to a collector's
    trail; declares fetches_pins=false, UDP refused by design). audit_verify's
    unpinned nudge names the automated anchor. A daily pypi-smoke workflow
    fresh-resolves the published wheel on both mcp majors through the same
    verifier the release job runs. Doorway figures re-measured (default door
    ~1,740 tokens). 906 tools unchanged).

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Sat, 22 Aug 2026 08:00:00 +0000

proximo (0.35.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.35.0 (minor, BREAKING: pbs_tasks_list, pmg_tasks_list and
    pdm_tasks_list return the windowed envelope {returned, by_outcome, tasks}
    that pve_tasks_list got in 0.34.0, through the same server-side classifier.
    Each gains a "fields" escape hatch; the lean set is per plane because the
    column names differ (PBS and PDM say worker_type/worker_id where PVE and
    PMG say type/id, and asking for the wrong plane's names is refused with the
    available ones listed). Vocabulary live-probed per plane: a running PBS row
    omits both endtime and status;
    PDM upids are remote-qualified and its status carries raw error text; PMG
    never produced a failing or in-flight row, so its vocabulary is recorded
    as unobserved rather than known. Pinned bumps:
    codeql-action and setup-uv v10; the python base bump is NOT taken, it
    fails the blocking image scan on tooling that is not ours. 906 tools
    unchanged).

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Sun, 16 Aug 2026 22:13:09 +0000

proximo (0.34.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.34.0 (minor: pve_tasks_list returns a windowed outcome
    envelope {returned, by_outcome, tasks} — outcomes classified server-side
    from endtime + exitstatus text; deliberately no "total", PVE truncates
    before the server counts. One task classifier repo-wide (pve_diagnose
    adopts it). statusfilter descriptions teach the live vocabulary
    (ok/error/warning). Release gate regenerates lhm.plugin.json and fails
    on drift. 906 tools unchanged).

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Wed, 12 Aug 2026 22:35:00 +0000

proximo (0.33.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.33.0 (minor: the mcp dual-major port. One build runs
    the official MCP SDK's 1.x and 2.x (mcp>=1.24,<3) through the
    proximo._mcpcompat seam; the floor is measured (1.24 is the oldest
    release that imports and passes the suite; the declared 1.2.0 could
    not import). The packaged artifacts stay on mcp 1.x this release.
    No tool or wire shape changes; 906 tools unchanged).

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Tue, 12 Aug 2026 04:20:00 +0000

proximo (0.32.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.32.0 (minor, BREAKING response shapes - M4 Bucket 2:
    nine estate-scale list tools move from a bare list to a counted
    envelope; five inventory tools (pdm_resources_list, pdm_pve_resources,
    pdm_pve_qemu_list, pdm_pve_lxc_list, pve_ha_resources_list) envelope
    without a cap, four PMG per-correspondent statistics tools
    (sender/receiver/contact/detail) envelope with a default limit of 100;
    pbs_node_journal and pmg_node_journal default-bound to the last 100
    lines on a bare call; PyPI Homepage/Documentation URLs point at the
    project page).

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Tue, 11 Aug 2026 05:45:00 +0000

proximo (0.31.2-1) UNRELEASED; urgency=medium

  * Track upstream 0.31.2 (patch - security hardening from a full adversarial
    audit of 0.31.1: webhook secrets/headers redacted from the PROVE ledger,
    plan_config_set escalates host-crossing guest-config changes to HIGH,
    plan_create keys privilege on the real PVE unprivileged param, exec
    timeouts recorded as error:timeout with an honest may-still-be-running
    message, caller badges get a bounded 30d default expiry, consent approvers
    see the un-redacted command in the dry-run preview only, all four
    entrypoints print usage on --help instead of binding a socket, plus
    smaller hardening across audit_verify/webguard/hw_mappings/blast/pbs/
    receipt. No tool-surface change.)

proximo (0.31.1-1) UNRELEASED; urgency=high

  * Track upstream 0.31.1 (patch - security: GHSA-g6cj-pr64-35w5 (HIGH) affects
    cryptography >=44.0.0,<50.0.0; proximo's own published metadata capped the
    a2a/http/mcp-http extras at <50, holding adopters inside the affected range
    with no path to the patched 50.0.0, and the container shipped the vulnerable
    library. Both bounds now move to >=50.0.0,<51 - the floor, not just the cap,
    because widening the cap alone would still permit 49.0.0. Proximo does not
    call the vulnerable PKCS#7 surface. Adds a named test guarding the floor,
    which the existing bounds test could not see. Also carries the three deferred
    0.31.0 review findings and current GitHub Actions SHA pins.)

proximo (0.31.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.31.0 (minor - PROXIMO_SURFACES scopes planes, it no longer
    picks the doorway. Setting it silently kept the pre-0.30 catalog door: on a
    PVE+PBS box it served 569 resident tools where the facade serves 5. Surfaces
    now narrow the searchable catalog and leave the door at the default facade;
    PROXIMO_TOOLSETS=catalog or =all ask for the old doors by name. Nothing
    becomes unreachable. Also: doctor derives the facade size and the narrowing
    mechanism from the registry instead of the environment, a utility-only
    surface is served plainly rather than behind a search facade, a second
    scoping pass no longer collapses the searchable catalog, estate memory
    announces its file on every start, and the LobeHub manifest generator asks
    for a door instead of a scope.)

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Sun, 02 Aug 2026 02:50:00 +0000

proximo (0.30.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.30.0 (minor - the default flip: with nothing configured the
    server now serves the dynamic facade (~1,449 tokens, everything still callable
    through it) instead of the full catalog, and Tier-1 estate memory is on by
    default (PROXIMO_MEMORY=0 opts out). PROXIMO_TOOLSETS=catalog restores the
    previous default by name. Adds audit_entries residency, a negatively-stated
    map-limits pointer, and in-wheel lexical search improvements.)

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Sat, 01 Aug 2026 20:35:00 +0000

proximo (0.29.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.29.0 (minor - principal-in-ledger: who-asked on every PROVE
    entry, ES256 caller badges on the network faces, plus two defaults moved
    toward safety: command-body redaction on by default and a ~16% cheaper
    tools/list payload).

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Thu, 31 Jul 2026 22:00:00 +0000

proximo (0.28.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.28.0 (minor - one new opt-in capability plus a schema-honesty
    repair; no tool count change, 904). `proximo reap` gains an opt-in cleanup of
    dead sessions' token and lock files via PROXIMO_REAP_UNLINK_DAYS: restoring the
    read-only key was only half the job, and the files themselves accreted one pair
    per session forever. Only a file proven read-only, unheld by the kernel flock,
    and idle past the TTL is removed, under its own exclusive lock; unset or garbled
    disables it, because deletion is the destructive verb. Separately, the RRD tools
    stopped letting a model call a rolling window "today": the schema never said the
    windows roll and end at now, so a model asked for today answered from the last
    24 hours. Fixed across all five sites that shipped the wording, with the
    disclosure pinned by tests.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Thu, 30 Jul 2026 21:20:00 +0000

proximo (0.27.1-1) UNRELEASED; urgency=high

  * Track upstream 0.27.1 (patch - a packaging hotfix; no code, tool or interface
    change). The mcp dependency was declared without an upper bound, and the MCP
    SDK's 2.0.0 release on 2026-07-28 removed mcp.server.fastmcp, which
    proximo/server.py imports. Every fresh install off PyPI - of any version -
    therefore resolved mcp 2.0.0 and then could not import the package at all,
    including the `uvx proximo-proxmox` path the README leads with. mcp is now
    capped below 2, and every other runtime and adopter-facing requirement bounds
    its major. The repo's own lockfile held a working 1.x, which is why the suite
    stayed green throughout: a lockfile protects the build, only a bound in the
    published metadata protects an adopter. A new test reads that metadata and
    fails on any unbounded major.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Thu, 30 Jul 2026 09:20:00 +0000

proximo (0.27.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.27.0 (minor - two opt-in capabilities, plus honesty repairs;
    900 -> 904 tools, and a default install's served surface is unchanged because
    the four new tools are opt-in and auto-scoped away when their env var is
    unset). Tier-1 estate memory (PROXIMO_MEMORY=1) adds proximo_recall, an
    age-stamped local estate map, and proximo_baseline, per-guest cpu/mem rollups
    derived from rrddata. The wiki seam (PROXIMO_WIKI=1) adds proximo_wiki and
    proximo_wiki_read: BM25 search and one-section reads over a local docs index,
    joined by a file contract so proximo imports nothing from the index builder.
    Both refuse rather than return anything answer-shaped when unfed, because a 4B
    model answered "0" from a bare total field regardless of the note beside it.
    New CLI: proximo arm / proximo disarm swap the read-only token for a pre-minted
    write token and disclose whether that arm is a real boundary or merely
    advisory; proximo reap restores read-only for sessions that ended while armed,
    using a shared flock the kernel releases on exit, crash or kill. Fixes: a
    drifted autoscope guard could narrow the served registry from 904 tools to 5 on
    a box with an opt-in enabled and no detectable data plane; disarm could report
    DISARMED while installing write authority when the read-only source held the
    write token's bytes; the boundary check judged permission bits and ignored
    ownership, so a token owned by another uid, or sitting in a directory owned by
    another uid, reported as a real boundary; the REAL verdict printed a mode and an
    owner it had not checked; a refusal claimed live write authority when none was
    installed; four wiki refusals named a builder that does not ship, leaving public
    adopters a remedy they could not run (the index contract is now published in
    docs/SETUP.md); and a garbled PROXIMO_ARM_TTL printed "no auto-expiry" for an arm
    that LEASE already held expired.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Wed, 29 Jul 2026 22:30:00 +0000

proximo (0.26.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.26.0 (minor — the surface stops costing what it covers).
    Schema slimming drops the tools/list payload from ~348k to ~276k tokens with
    no capability change (84k of it was one repeated parameter description on 899
    of 900 tools; 24k was redundant pydantic titles). New scoping layers in the
    field-standard shape: PROXIMO_TOOLS (exact names), PROXIMO_TOOLSETS (23 domain
    groups), and PROXIMO_TOOLSETS=dynamic — a 3-tool search facade at ~555 tokens
    with the whole catalog still callable through the same governed dispatch.
    PROVE now records an "executing" entry before each mutation and a terminal
    entry after, sharing a derived intent id, so an operation killed mid-flight is
    visible instead of leaving no trace. pve_doctor reports the active scoping
    layer across all four.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Tue, 28 Jul 2026 22:30:00 +0000

proximo (0.25.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.25.0 (minor — the PMG plane closes, and a fourth transport
    arrives: 715 -> 900 tools). PMG node administration, mail-plane config (LDAP
    profiles, fetchmail, domains/transport/mynetworks, TLS policy + inbound TLS,
    DKIM signing, SpamAssassin custom scores, PBS-remote config + node-side PBS
    backup jobs, ACME accounts/plugins + node cert order/renew/revoke +
    custom-cert upload), PMG identity (auth realms, local users, TFA, the six
    appliance config singletons) + cluster bootstrap/join, and quarantine +
    statistics completion. Every one of PMG's 425 live API methods accounted for
    by an exit-code-gated whole-plane audit (351 in code + 74 documented
    dispositions, 0 undocumented). Plus a new optional [mcp-http] extra and
    proximo-mcp-http command: native MCP over Streamable HTTP, the first
    community-contributed transport (upstream FR #25), serving the same FastMCP
    instance over the same webguard perimeter — merged after a two-lens
    adversarial review. Schema-built (11,074 tests), not yet live-proven.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Sat, 18 Jul 2026 03:00:00 -0500

proximo (0.24.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.24.0 (minor — Ceph + SDN deep: 603 -> 715 tools). The full
    Ceph plane (OSD/mon/mgr/mds lifecycle, pools, CephFS; destroy plans quote
    Ceph's own cmd-safety verdict) and deep SDN (controllers, DNS, IPAMs,
    fabrics, vnet-scoped firewall, IP mappings, prefix-lists, route-maps; SDN
    dry-run in apply previews, global lock as a never-ledgered capability
    token, rollback as a real undo for staged config). Both planes closed by
    exit-code-gated audits (48/48 + 90/90 methods, 0 undocumented). Schema-
    built and mock-tested (9,182 tests), not yet live-proven — per-tool
    docstrings state which. mcp pinned 1.28.1.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Sat, 18 Jul 2026 00:45:00 -0500

proximo (0.23.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.23.0 (minor — the PBS plane closes: 493 -> 603 tools). Full
    PBS coverage proven by an exit-code-gated audit against the live schema
    (0 undocumented gaps; exclusions are wire-protocol/console/auth-handshake/
    node-power, each documented). Adds tape (hardware, media, encryption keys,
    operations, jobs, restore), S3 clients, client encryption keys, metrics
    servers, admin job views, node config/identity/report, pull/push, and
    datastore admin closers (group delete, whole-datastore prune, namespace
    move, mount/unmount). Fixes pbs_job_run outcome honesty and empty-delete-
    list transport drops; hardens proxy-URL and secret-read redaction.
    Packaging unchanged; not distributed — build-your-own from debian/.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Wed, 15 Jul 2026 22:30:00 +0000

proximo (0.22.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.22.0 (minor — the full-surface campaign opens: 365 -> 493 tools).
    APT/patching tools on all three planes (visibility + repo config; no upgrade
    execution exists upstream and the docstrings say so). PBS plane opened wide:
    identity/tokens/ACL, AD/LDAP/OpenID realms + TFA, node OS admin, disks,
    notifications, ACME — every tool built from the live upstream schema and
    adversarially reviewed. SETUP.md privsep fix (user AND token grants; dead-token
    happy path reported by first external production adopter). 64-finding coverage
    audit of the prior 365 tools closed (outcome honesty for bulk node ops, fail-closed
    resolver, an exact-payload confirm-sweep harness). pbs_acme_tos classified
    adversarial + https-only URL validation. Packaging unchanged; not distributed —
    build-your-own from debian/.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Wed, 15 Jul 2026 14:30:00 +0000

proximo (0.21.1-1) UNRELEASED; urgency=medium

  * Track upstream 0.21.1 (patch — the truth-audit release). Secret-file permission
    floor now covers every secret referenced by path (PBS/PDM tokens, PMG password,
    A2A/HTTP bearer-token files, A2A signing key — was PVE token + audit key only);
    a group/other-readable credential now refuses at load on every plane. All five
    pip installs in CI/release/image builds are hash-pinned against lockfiles
    exported from uv.lock; the container image build is two-stage (no build tooling
    or source tree in the final image). Doc truth ripple: THREAT_MODEL.md covers
    both network faces, VERIFY.md examples current, SECURITY.md support table
    de-versioned, README rebuilt (deduplicated + architecture diagram, tool picker,
    verify-in-60s receipts). No tool-count change (still 365). Packaging unchanged;
    not distributed — build-your-own from debian/.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Mon, 13 Jul 2026 19:08:37 +0000

proximo (0.21.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.21.0 (minor — the HTTP/OpenAPI face: a third transport beside MCP
    and A2A. Adds the optional [http] extra and the proximo-http command, serving the
    full 365-tool governed surface as plain HTTP + a generated /openapi.json for no-code /
    dashboard clients. It's a third transport over one shared dispatch chokepoint and
    fail-closed perimeter (A2A refactored onto the same shared surface too — widened from
    its old 16-skill slice to the full surface), so the guard can't drift. A same-day redteam found and fixed a loopback-CSRF hole and an audit gap
    before ship; config also now refuses a group/other-readable token or audit-key file.
    No tool-count change (still 365). New console script proximo-http and a new [http]
    extra; the base wheel is otherwise unchanged (same dh-virtualenv build, man page, and
    autopkgtest). Not distributed; build-your-own from debian/.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Mon, 13 Jul 2026 13:30:00 +0000

proximo (0.20.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.20.0 (minor — the receipts release: every safety claim is now
    paired with a command that proves it. No tool-count change (still 365). Adds
    VERIFY.md (each claim + its runnable check), THREAT_MODEL.md (assets/boundaries/
    adversaries/residuals), a CycloneDX SBOM for the published wheel attached to the
    GitHub release, an OpenSSF Scorecard badge, and scripts/mutation_smoke.py (4/4
    trust-core tamper-detection mutants killed). No packaging changes from 0.19.1-1 —
    same dh-virtualenv build, man page, and autopkgtest. Not distributed; build-your-own
    from debian/.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Fri, 10 Jul 2026 15:00:00 +0000

proximo (0.19.1-1) UNRELEASED; urgency=medium

  * Track upstream 0.19.1 (patch — self-audit release: 23 findings from a multi-agent
    audit of 0.19.0, all fixed, no tool-count change (still 365). Headline: _check_volid
    accepts PBS archive volids (RFC3339 snapshot times carry colons) so restore/prune
    from PBS work again; the freshness fence parses sub-daily schedules and degrades a
    stale verdict to unknown on an unreadable storage; pbs_realm_sync uses the hyphenated
    PBS field names; prune-job runs are rated HIGH; the PDM plane is honestly labeled
    reads + governed control. No packaging changes from 0.19.0-1 — same dh-virtualenv
    build, man page, and autopkgtest. Not distributed; build-your-own from debian/.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Fri, 10 Jul 2026 06:18:14 +0000

proximo (0.19.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.19.0 (minor — new tool pve_backup_freshness, the backup-freshness
    fence: walks actual backup archives per guest against what enabled jobs promise;
    task-OK is never treated as evidence a backup exists. Includes the token-sight guard
    (PVE hides backup volumes from tokens lacking VM.Backup + Datastore.AllocateSpace,
    200 + empty) and guests_visible population honesty (the guest list itself is
    permission-filtered). +1 tool -> 365. No packaging changes from 0.18.1-1 — same
    dh-virtualenv build, man page, and autopkgtest. Not distributed; build-your-own
    from debian/.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Thu, 09 Jul 2026 23:53:28 +0000

proximo (0.18.1-1) UNRELEASED; urgency=medium

  * Track upstream 0.18.1 (patch — the anonymous door is now a plain text box; one-click
    VS Code/Cursor install deeplinks that prompt for the token PATH, never the secret;
    field-hardened tool-description caveats for pve_tasks_list/pve_backup_list; copy-gate
    and Cursor-deeplink fixes). Docs + copy + tool-description only — no new tools, no API
    change. No packaging changes from 0.18.0-1 — same dh-virtualenv build, man page, and
    autopkgtest. Not distributed; build-your-own from debian/.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Thu, 09 Jul 2026 11:00:25 -0500

proximo (0.18.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.18.0 (the Open Door — AGENTS.md agent front door, the public Agent
    Guestbook, and the print-only `proximo hello` subcommand; no telemetry, invite-only,
    never receives). No packaging changes from 0.17.0-1 — same dh-virtualenv build, man
    page, and autopkgtest. Not distributed; build-your-own from debian/.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Tue, 07 Jul 2026 00:50:00 -0500

proximo (0.17.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.17.0 (PDM fleet control — governed guest lifecycle through the
    Datacenter Manager proxy, incl. live-proven cross-remote datacenter-to-datacenter
    migrate; the `proximo mint` onboarding-recipe subcommand; multi-target + typed-API
    fixes). No packaging changes from 0.16.0-1 — same dh-virtualenv build, man page, and
    autopkgtest. Not distributed; build-your-own from debian/.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Mon, 06 Jul 2026 15:51:04 -0500

proximo (0.16.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.16.0 (five safe-runbook MCP prompts; live-proven online
    live-migration + softdog HA fencing; storage 'shared' fix). No packaging
    changes from 0.15.0-1 — same dh-virtualenv build, man page, and autopkgtest.
    Not distributed; build-your-own from debian/.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Sun, 05 Jul 2026 17:02:08 -0500

proximo (0.15.0-1) UNRELEASED; urgency=medium

  * Track upstream 0.15.0 (cert-fingerprint pinning across all four Proxmox
    surfaces). No packaging changes from 0.14.1-1 — same dh-virtualenv build,
    man page, and autopkgtest. Not distributed; build-your-own from debian/.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Sat, 04 Jul 2026 14:29:06 -0500

proximo (0.14.1-1) UNRELEASED; urgency=medium

  * First working build: the dh-virtualenv step landed. debian/rules now
    drives `dh $@ --with python-virtualenv --buildsystem=pybuild` with an
    override_dh_virtualenv calling `dh_virtualenv --builtin-venv
    --python=/usr/bin/python3` -- this bundles a private venv at
    /opt/venvs/proximo (via `pip install .`, build-isolated so pip also
    fetches the hatchling backend) carrying the mcp and httpx runtime deps
    that Debian doesn't package. debian/control's Depends dropped the
    ${python3:Depends} substvar (no dh-python addon runs now) in favor of
    a plain `python3 (>= 3.12)` dependency, and gained
    Build-Depends: dh-virtualenv, python3-venv.
  * debian/proximo.links symlinks /usr/bin/proximo -> the venv's bundled
    `proximo` console script (the MCP stdio entry point).
  * Fixed two build-time gotchas specific to `--builtin-venv`, both
    verified by extracting the built .deb and grepping for leak shapes:
    dh-virtualenv's own fix_activate_path() only matches the classic
    `virtualenv` tool's activate-script format, so with `--builtin-venv`
    the build-tree's absolute path (pyvenv.cfg, bin/activate,
    direct_url.json, every .pyc's co_filename) silently leaked through
    unfixed; override_dh_virtualenv now sed-replaces it to the final
    /opt/venvs/proximo path and strips the .pyc caches (recompiled
    lazily, harmlessly, on first import) and direct_url.json by hand.
  * Architecture: all -> any. The venv bundles arch-specific compiled
    wheels (pydantic-core, rpds-py, cryptography, cffi); shipping them
    under Architecture: all silently skipped dh_strip/dh_shlibdeps
    (debhelper only runs those for arch-dependent packages), so the first
    `all` build had unstripped binaries and no libc6 dependency -- lintian
    caught both. `any` fixes both and gained ${shlibs:Depends} in Depends.
  * debian/proximo.postrm added: since we ship without .pyc caches,
    Python recompiles them at runtime into untracked __pycache__ dirs;
    without a cleanup hook `dpkg -r`/`apt remove` warned "directory not
    empty" and left /opt/venvs/proximo behind. Now unconditionally
    removed on remove/purge. Verified with a real install -> `proximo
    doctor` -> remove cycle: no leftover files, no dpkg record.
  * debian/proximo.lintian-overrides added for three tags that are
    expected on *any* dh-virtualenv package, not defects here: files
    under /opt, console-scripts shebanging to the venv's bare `python`,
    and two non-executable files vendored inside pip itself. Also
    dropped pip's own console-script wrappers (bin/pip, bin/pip3,
    bin/pip3.*) from the shipped venv -- nobody should be installing into
    this frozen production venv at runtime, and it silenced three
    wrong-path-for-interpreter tags. Full `lintian` pass is now clean
    except no-manual-page and three debug-file-with-no-debug-symbols
    warnings on the auto-generated -dbgsym package (the bundled
    manylinux wheels are pre-stripped, no DWARF info to extract) -- both
    documented in debian/README.Debian "still rough", neither a defect.
  * Version tracks upstream (0.14.1) now that the package actually builds
    and installs; still UNRELEASED/no real distribution/urgency is a
    placeholder -- this is a packaging milestone, not a Debian archive
    upload, and there's been no separate audit of this artifact for
    publication (see debian/README.Debian "still rough").
  * The A2A extra (a2a-sdk, uvicorn, starlette, cryptography) is
    deliberately NOT bundled into the venv -- matches upstream's opt-in
    design; only the base mcp+httpx surface ships. Anyone wanting
    proximo-a2a installs the extra by hand into the venv.
  * Kept the prior scaffold entry below verbatim for the historical record
    of what was blocking (now resolved) and what stays a permanent design
    decision (the on-demand stdio transport, not a blocker).

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Sat, 04 Jul 2026 00:00:00 +0000

proximo (0.1.0) UNRELEASED; urgency=medium

  * Initial packaging scaffold for the foundation release ("Spaniard").
  * Two backends (REST API + ssh->pct), full MCP tool surface, audit log,
    confirm-gated mutations, fail-closed CTID allowlist.
  * STATUS (still UNRELEASED, still a scaffold, not a working build): this
    entry is intentionally pinned at 0.1.0 while upstream proximo has moved
    on to 0.12.0+ on PyPI/GitHub/GHCR. The Debian package version tracks
    the packaging's own readiness, not upstream's release cadence -- it
    will be bumped (and a real distribution + urgency set) only once
    `dpkg-buildpackage` actually produces an installable .deb, not per
    upstream tag.
  * Two blockers tracked (see debian/README.Debian for the full writeup):
    - Python runtime deps (mcp, httpx) are not packaged for Debian.
      DECIDED direction: bundle a self-contained venv via dh-virtualenv
      (sovereign, no host clutter) so debian/control's Depends can stay
      stdlib+ssh-only. Not yet implemented -- debian/rules still drives
      plain dh/pybuild, which will fail to resolve those imports at build
      or run time until the dh-virtualenv step is written.
    - Transport is DECIDED (stdio, on-demand, no always-on daemon; see the
      optional packaging/optional-daemon-mode.service.example for anyone
      who wants a daemon anyway) -- this one is resolved, not a blocker.
  * Net: do not build/upload this package expecting a working .deb yet --
    it is scaffold-only until the dh-virtualenv bundling lands.

 -- John Broadway <271895126+john-broadway@users.noreply.github.com>  Wed, 01 Jul 2026 12:00:00 +0000
