Capability contract

Coverage without pretending.

A confirmed newer version and permission to install it are separate claims. This table states what Chronologix 1.0 can actually do.

Update All boundary

Every confirmed newer version remains visible. Update All contains all and only visible Install rows; Options rows are counted separately and never represented as installed.

Current source matrix

Source or itemCurrent capabilityWhat Chronologix doesWhat it does not claim
Installed macOS applicationsLocal inventoryReads approved application folders without following directory symlinks and normalizes identity, version, architecture, source evidence, and signing observations.Inventory alone does not prove a newer version or authorize replacement.
Firefox stable at the exact approved identity and pathInstallChecks fixed Mozilla metadata and checksums; after plan review it can verify, stage, replace, post-check, and retain a bounded recovery copy.No generic browser, vendor, channel, locale, bundle path, or third-party direct installer is authorized.
Eligible official Homebrew formulae and casksInstallChecks the exact official metadata and live receipt, then runs one fixed named package transaction inside Chronologix and verifies the resulting receipt version.No custom tap, HEAD build, rolling or self-updating cask, arbitrary argument, shell, sudo, Terminal, or universal rollback is authorized.
Mac App Store receipt-backed appsCoverage onlyRetains local receipt attribution for coverage accounting.No public consumer API lets Chronologix install another App Store app, so these items expose no update or external-open action.
Eligible signed application-owned feedsOptionsChecks a bounded HTTPS appcast against the installed signed identity and keeps a confirmed newer version visible for evidence review.Chronologix does not download the enclosure, open the app or updater, force installation, enter Update All, or claim success.
macOS Software UpdateCoverage onlyRetains the local macOS identity as a coverage anchor.The shipping app links no softwareupdate process or System Settings destination and exposes no update action for macOS.
Confirmed newer version without an executor or handoffOptionsKeeps the update visible with evidence review and Check Again.No arbitrary installer, generic force/reinstall, shell, sudo, Terminal, private API, or UI scripting is authorized.
Unmatched, stale, failed, or unsupported sourcesUnknownKeeps the limitation visible in coverage/history with its reason and last observed state.Missing evidence never becomes “up to date,” an update action, or safe by implication.

How a capability is earned

An adapter moves into Install only after identity, version, artifact origin, integrity, Apple signing continuity, platform compatibility, preflight, mutation, post-verification, interruption, cleanup, and recovery boundaries pass source-specific tests. Broader coverage does not inherit that authority.

Release accuracy

This page describes the exact signed Chronologix 1.0 release, verified on 5 August 2026. Products and upstream sources change; use the support route to report a correction.