v0.1.1Released on 2026-10-02
Release Tag on GitHubDeployment & Release Channels, Fail-Closed Worktree Isolation, Egress SSRF Hardening, and Output Security Contracts.
Deployment & Release Channels (DEVELOPMENT vs PRODUCTION)
- One core runtime, two isolated deployment channels: production (m31a, default build) and development (m31a-dev, --features development). Channel is compile-time artifact identity.
- New src/deployment/ subsystem: DeploymentChannel/UpdateChannel, immutable DeploymentContext, ReleaseArtifact model, versioned DeploymentManifest (schema v1), transactional Installer (stage → verify → atomic replace), channel-safe update discovery, and rollback seam.
- CLI subcommands: m31a version [--verbose], m31a deployment [--verbose], m31a update --manifest <file> [--check], m31a rollback; channel-aware m31a --version.
- PlatformPaths and persistence paths are channel-aware: development uses isolated m31a-dev global state; production paths are unchanged.
Security & Policy Hardening
- Fail-Closed Worktree Isolation: default_execution_isolation() set to "required". Governed production runs fail closed if worktree creation cannot be verified.
- Egress & SSRF Hardening: centralized NetworkDestinationPolicy blocking IPv4/IPv6 loopback, RFC 1918 private subnets, cloud metadata (169.254.169.254), link-local, and carrier NAT. Async DNS pre-validation and step-by-step redirect verification up to 5 hops.
- XML TrustEnvelope Hardening: strict attribute escaping (&, <, >, ", ', control chars, newlines) preventing XML injection and tag breakouts.
- Expanded Secret Redactor: added scrubbing for NVIDIA API keys, GitLab tokens, database URLs with passwords, basic/digest auth headers, and env credential pairs.
- Structural Telemetry & Logging: runner step events, SSE parser logs, and pipeline diagnostics emit structural metadata only, strictly preventing raw model proposals or arbitrary command output from entering logs.
- Stage 10 Output Security Contract: formalized PipelineOutputEvidence disambiguating raw execution output, model-visible projections, redacted diagnostic evidence, and SHA-256 cryptographic audit digests.
- Process Environment & Shell Security: child processes strictly clear host environment variables (env_clear()) installing only trusted baselines.