Skip to content
M31A
M31A — M31 AUTONOMOUS/v0.1.1

THE MODEL
PROPOSES.
THE RUNTIME
DECIDES.

M31A is a Rust-native autonomous software-engineering runtime that brings planning, execution, verification, and recovery to the terminal while keeping runtime authority outside the model.

FOUNDATIONRust 1.85+
QUALIFIEDLinux x86_64
DEPENDENCIESSingle Crate (Zero Foreign)
M31A RUNTIME ARCHITECTURE02 // DECISION CORE
THE MODELPROPOSESDECISION GATETHE RUNTIMEDECIDES & VERIFIES
THE CORE PRINCIPLE

INTELLIGENCE
IS NOT
AUTHORITY.

Large language models reason, decompose problems, and draft code. But granting a non-deterministic model direct shell access, ambient credentials, and write privileges inevitably produces runaway loops, destroyed workspaces, and security compromises.

M31A introduces a hard architectural boundary. The model proposes structured actions. The runtime evaluates policy, bounds memory and CPU time, executes tools inside sandboxes, and verifies evidence before any mission is admitted as complete.

PROPOSAL = Untrusted
RUNTIME = Authoritative
PRODUCT ARCHITECTURE

The Execution Lifecycle

Every autonomous mission follows a deterministic four-phase progression. No step is skipped; no completion is accepted without evidence.

01 //Acyclic DAG Decomposition

PLAN: Acyclic DAG Decomposition

Candidate intent is decomposed into a directed acyclic task graph backed by petgraph. The runtime performs topological scheduling and candidate validation before any task is admitted for execution.

  • Topological dependency resolution prevents circular blockages
  • Candidate plan validation rejects malformed task branches
  • Differential replanning preserves already verified nodes on recovery
Subsystem InvariantTaskGraph<PetGraph>

Authority is enforced outside the model context window.

THE RUNTIME SEPARATION

A model can reason.
A runtime can enforce.

By treating the LLM as an unprivileged component outside the trust boundary, M31A guarantees deterministic safety invariants that prompts alone cannot enforce.

THE MODEL (UPSTREAM)

Reasoning Engine

  • • Decomposes high-level intent
  • • Synthesizes candidate code diffs
  • • Proposes structured tool calls
  • • Evaluates compiler diagnostics
THE RUNTIME (AUTHORITY)

Deterministic Control

  • • 11-stage policy gate evaluation
  • • POSIX rlimits & cgroups confinement
  • • 10-dimensional resource budgeting
  • • Multi-tier test & lint verification
  • • Two-phase atomic SQLite commit
L0 TO L9 ARCHITECTURE

Ten Layers. One Direction: Down.

A single Rust crate organized with strict downward dependencies. Lower layers never import or depend on higher layers.

View Full Architecture Map
L1Layer Details
Strict downward dependency

Security & Policy Gate

Governance & Access Control

11-stage policy gate, NetworkDestinationPolicy (SSRF defense), fail-closed worktree isolation, approval coordinator.

Source Module:src/policy
Dependency Rule:Only layers below L1
Authority:Gate Enforcement
View Source on GitHub
SECURITY ARCHITECTURE

Security is Built into the Runtime.

Non-bypassable policy gates, process confinement, path containment, and automated secret redaction. Fail-closed by construction.

Read Full Security Model
Governance Architecture

11-Stage Non-Bypassable Policy Gate

Every side-effect passes through 11 sequential evaluation stages across a 10-tier authority stack. Layer 0 safety vetoes can never be weakened by user grants or prompt overrides.

Enforcement Mechanism

Monotonic non-weakening merger rules; higher authority always overrules.

Security Invariant

DENY is default. ASK converts to DENY in unattended mode.

EVIDENCE-BASED INTEGRITY

Completion Requires Evidence.

M31A does not trust a model's assertion that a problem has been solved. Tasks are committed only when automated verification pipelines produce matching cryptographic SHA-256 evidence digests.

Compiler & test suite execution in clean sandbox
Clippy static analysis and anti-fake-diff reviews
Strict git worktree attribution trailers
Cryptographic completion audit digests
Verification Pipeline Sequence
01EXECUTESandboxed Tool
02OBSERVESpool Output
03VERIFYTests + Linters
04CHECKPOINTAtomic SQLite
Completion Status:EVIDENCE REQUIRED [FAIL-CLOSED]
OPERATOR SURFACE

Terminal-Native Engineering.

Real CLI commands, real diagnostic probes, and a Ratatui TUI cockpit built as a pure projection of authoritative SQLite runtime state.

Explore All CLI Commands
$m31a doctor
[i] Probing host runtime environment and platform qualifications...
OK Architecture: x86_64-unknown-linux-gnu (Release Qualified)
OK Git Worktree: Isolation available, verified clean root
OK Process Limits: POSIX rlimits supported (max_memory, cpu_time)
OK Confinement: Linux cgroups v2 hierarchy available
OK Storage: SQLite 3.46+ with WAL mode enabled
OK Provider Trust: NVIDIA NIM API reachable (integrate.api.nvidia.com)
OK Secret Redaction: 5-tier filter pipeline verified active
--> All runtime prerequisites verified. Ready for mission execution.
INSTALLATION

Run M31A Locally.

Install the standalone binary via automated one-liner scripts or download prebuilt release archives directly.

Linux / macOS (One-Liner Install)

bash
curl -fsSL https://raw.githubusercontent.com/eshanized/M31A/master/scripts/install.sh | bash

Windows PowerShell (One-Liner Install)

powershell
irm https://raw.githubusercontent.com/eshanized/M31A/master/scripts/install.ps1 | iex

Platform Qualification

Linux (x86_64)x86_64-unknown-linux-gnu
SUPPORTED
macOS (Intel (x86_64))x86_64-apple-darwin
CONDITIONALLY SUPPORTED
Linux (ARM64 (aarch64))aarch64-unknown-linux-gnu
COMPILE-ONLY
View All Platform Releases

THE MODEL PROPOSES.
THE RUNTIME DECIDES.

M31A — M31 AUTONOMOUS

Download M31A