<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Engineering notes on Harbor Self-Evolving</title><link>https://istarwyh.github.io/harbor-self-evolving/blog/</link><description>Recent content in Engineering notes on Harbor Self-Evolving</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sat, 19 Sep 2026 23:20:21 +0800</lastBuildDate><atom:link href="https://istarwyh.github.io/harbor-self-evolving/blog/index.xml" rel="self" type="application/rss+xml"/><item><title>Evidence before optimization</title><link>https://istarwyh.github.io/harbor-self-evolving/blog/evidence-before-optimization/</link><pubDate>Sat, 19 Sep 2026 00:00:00 +0000</pubDate><guid>https://istarwyh.github.io/harbor-self-evolving/blog/evidence-before-optimization/</guid><description>&lt;p&gt;The fastest way to make self-evolution untrustworthy is to let the same opaque loop choose cases, rewrite itself and declare victory.&lt;/p&gt;&#10;&lt;p&gt;Harbor reverses that order. First freeze what is being tested and how. Then inspect whether evidence is valid and how much of the population it covers. Only then propose one change and compare it against a baseline whose identities still match.&lt;/p&gt;&#10;&lt;p&gt;This is why the Optimizer and Gate are separate, why Historical Sessions are diagnosis rather than promotion, and why a raw reward never silently becomes a valid score.&lt;/p&gt;</description></item><item><title>Host first, with honest boundaries</title><link>https://istarwyh.github.io/harbor-self-evolving/blog/host-first-honest-boundaries/</link><pubDate>Sat, 19 Sep 2026 00:00:00 +0000</pubDate><guid>https://istarwyh.github.io/harbor-self-evolving/blog/host-first-honest-boundaries/</guid><description>&lt;p&gt;Requiring Docker before a user can diagnose an Agent creates friction. Pretending direct execution is isolated creates risk. Version 0.9.6 chooses Host as the default and names the boundary precisely.&lt;/p&gt;&#10;&lt;p&gt;Host mode runs with the current user&amp;rsquo;s permissions and environment. It supplies no container isolation, user switching, network policy or CPU/memory limits. Docker remains explicit opt-in when that boundary is required.&lt;/p&gt;&#10;&lt;p&gt;Execution environment becomes part of Context identity. A result produced on Host is not silently compared with Docker. Lower friction does not require weaker evidence—as long as the runtime difference remains visible.&lt;/p&gt;</description></item></channel></rss>