Skip to content
M31A
RELEASE HISTORY

Changelog & Release Records.

Authoritative release notes for all published versions of the M31A runtime.

v0.1.1Released on 2026-10-02
Release Tag on GitHub

Deployment & Release Channels, Fail-Closed Worktree Isolation, Egress SSRF Hardening, and Output Security Contracts.

Deployment & Release Channels (DEVELOPMENT vs PRODUCTION)

  • One core runtime, two isolated deployment channels: production (m31a, default build) and development (m31a-dev, --features development). Channel is compile-time artifact identity.
  • New src/deployment/ subsystem: DeploymentChannel/UpdateChannel, immutable DeploymentContext, ReleaseArtifact model, versioned DeploymentManifest (schema v1), transactional Installer (stage → verify → atomic replace), channel-safe update discovery, and rollback seam.
  • CLI subcommands: m31a version [--verbose], m31a deployment [--verbose], m31a update --manifest <file> [--check], m31a rollback; channel-aware m31a --version.
  • PlatformPaths and persistence paths are channel-aware: development uses isolated m31a-dev global state; production paths are unchanged.

Security & Policy Hardening

  • Fail-Closed Worktree Isolation: default_execution_isolation() set to "required". Governed production runs fail closed if worktree creation cannot be verified.
  • Egress & SSRF Hardening: centralized NetworkDestinationPolicy blocking IPv4/IPv6 loopback, RFC 1918 private subnets, cloud metadata (169.254.169.254), link-local, and carrier NAT. Async DNS pre-validation and step-by-step redirect verification up to 5 hops.
  • XML TrustEnvelope Hardening: strict attribute escaping (&, <, >, ", ', control chars, newlines) preventing XML injection and tag breakouts.
  • Expanded Secret Redactor: added scrubbing for NVIDIA API keys, GitLab tokens, database URLs with passwords, basic/digest auth headers, and env credential pairs.
  • Structural Telemetry & Logging: runner step events, SSE parser logs, and pipeline diagnostics emit structural metadata only, strictly preventing raw model proposals or arbitrary command output from entering logs.
  • Stage 10 Output Security Contract: formalized PipelineOutputEvidence disambiguating raw execution output, model-visible projections, redacted diagnostic evidence, and SHA-256 cryptographic audit digests.
  • Process Environment & Shell Security: child processes strictly clear host environment variables (env_clear()) installing only trusted baselines.
v0.1.0Released on 2026-09-25
Release Tag on GitHub

Initial production foundation: single-crate runtime kernel, 11-stage policy gate, 28 core tools, and Ratatui cockpit.

Runtime Kernel (L0–L2)

  • Single-crate Rust-native autonomous runtime with zero foreign runtime dependencies (no Node.js, Python, or GPU required).
  • Domain-typed kernel IDs: MissionId, TaskId, SessionId, AgentId, CheckpointId, ArtifactId.
  • Immutable content-addressed artifact store with SHA-256 integrity verification.
  • SQLite-backed durable persistence with 19 incremental migration files and WAL mode.
  • Two-phase atomic checkpoints with CheckpointIntegrityValidator.
  • Startup crash scanner and automatic recovery classification.

Security & Policy Engine (L1)

  • 11-stage policy gate with ALLOW / DENY / ASK / ESCALATE decision matrix.
  • 10-tier precedence model for policy resolution with monotonic non-weakening merger rules.
  • SecretRedactor with multi-tier deterministic scrubbing pipeline (nvapi-*, ghp_*, sk-*, AKIA*, JWTs, RSA private keys).
  • TrustEnvelope::wrap_untrusted with SHA-256 integrity digest for prompt injection defense.
  • ApprovalCoordinator fail-closed ASK semantics in unattended mode.
  • Multi-tier process confinement: Linux cgroups v2, POSIX rlimits, process group isolation, and watchdog supervision.
  • ASVS L1 coverage across all 11 documented threat vectors.

Capabilities, Planning & Agent Swarm (L3–L5)

  • 28 core tools with typed parameter schemas and execution risk classifications.
  • 8 canonical agent roles: planner, researcher, architect, implementer, reviewer, verifier, diagnostician, integrator.
  • NVIDIA NIM provider integration with SSE streaming.
  • Directed acyclic task graph with petgraph-backed dependency resolution and differential DAG replanning.

CLI & TUI Cockpit (L9)

  • Ratatui 0.30 TUI cockpit with RAII TerminalGuard for raw-mode restoration.
  • Full clap-derive CLI with machine-readable --output json and stream-json modes.
  • Standardized UNIX exit codes: 0 (success), 1 (verification failure), 2 (policy violation), 3 (budget exhaustion), 4 (crash), 5 (config error).