THE MODEL
PROPOSES.
THE RUNTIME
DECIDES.
M31A is a Rust-native autonomous software-engineering runtime that brings planning, execution, verification, and recovery to the terminal while keeping runtime authority outside the model.
INTELLIGENCE
IS NOT
AUTHORITY.
Large language models reason, decompose problems, and draft code. But granting a non-deterministic model direct shell access, ambient credentials, and write privileges inevitably produces runaway loops, destroyed workspaces, and security compromises.
M31A introduces a hard architectural boundary. The model proposes structured actions. The runtime evaluates policy, bounds memory and CPU time, executes tools inside sandboxes, and verifies evidence before any mission is admitted as complete.
The Execution Lifecycle
Every autonomous mission follows a deterministic four-phase progression. No step is skipped; no completion is accepted without evidence.
PLAN: Acyclic DAG Decomposition
Candidate intent is decomposed into a directed acyclic task graph backed by petgraph. The runtime performs topological scheduling and candidate validation before any task is admitted for execution.
- Topological dependency resolution prevents circular blockages
- Candidate plan validation rejects malformed task branches
- Differential replanning preserves already verified nodes on recovery
Authority is enforced outside the model context window.
A model can reason.
A runtime can enforce.
By treating the LLM as an unprivileged component outside the trust boundary, M31A guarantees deterministic safety invariants that prompts alone cannot enforce.
Reasoning Engine
- • Decomposes high-level intent
- • Synthesizes candidate code diffs
- • Proposes structured tool calls
- • Evaluates compiler diagnostics
Deterministic Control
- • 11-stage policy gate evaluation
- • POSIX rlimits & cgroups confinement
- • 10-dimensional resource budgeting
- • Multi-tier test & lint verification
- • Two-phase atomic SQLite commit
Ten Layers. One Direction: Down.
A single Rust crate organized with strict downward dependencies. Lower layers never import or depend on higher layers.
Security & Policy Gate
Governance & Access Control
11-stage policy gate, NetworkDestinationPolicy (SSRF defense), fail-closed worktree isolation, approval coordinator.
Security is Built into the Runtime.
Non-bypassable policy gates, process confinement, path containment, and automated secret redaction. Fail-closed by construction.
11-Stage Non-Bypassable Policy Gate
Every side-effect passes through 11 sequential evaluation stages across a 10-tier authority stack. Layer 0 safety vetoes can never be weakened by user grants or prompt overrides.
Monotonic non-weakening merger rules; higher authority always overrules.
DENY is default. ASK converts to DENY in unattended mode.
Completion Requires Evidence.
M31A does not trust a model's assertion that a problem has been solved. Tasks are committed only when automated verification pipelines produce matching cryptographic SHA-256 evidence digests.
Terminal-Native Engineering.
Real CLI commands, real diagnostic probes, and a Ratatui TUI cockpit built as a pure projection of authoritative SQLite runtime state.
Documentation & Specifications
Comprehensive technical manuals, subsystem documentation, and architectural invariants versioned directly with the runtime.
Getting Started
Installation guides, API key configuration, and executing your first autonomous coding mission.
Architecture & Invariants
Deep dives into the L0–L9 layered hierarchy, downward dependency rules, and persistence.
Security & ASVS L1
11 threat vectors, the 11-stage policy gate, and the NetworkDestinationPolicy SSRF defenses.
Run M31A Locally.
Install the standalone binary via automated one-liner scripts or download prebuilt release archives directly.
Linux / macOS (One-Liner Install)
curl -fsSL https://raw.githubusercontent.com/eshanized/M31A/master/scripts/install.sh | bashWindows PowerShell (One-Liner Install)
irm https://raw.githubusercontent.com/eshanized/M31A/master/scripts/install.ps1 | iex