Skip to content
M31A

Introduction

What M31A is, architectural principles, and what it is not.


M31A (M31 Autonomous) is a single-crate, high-assurance, Rust-native autonomous software engineering runtime. It provides deterministic lifecycle control, strict multi-layer security policies, resource-bounded execution, continuous verification, crash-resilient checkpoints, and local observability for autonomous coding agents.

The Central Architectural Boundary

"The model proposes. The runtime decides."

Unlike ad-hoc agent scripts or loose orchestration frameworks that delegate execution authority to non-deterministic large language models, M31A treats the LLM as an untrusted reasoning component. The runtime strictly owns state, scheduling, file access, command execution, policies, verification, and completion criteria.

6 Architectural Pillars

1. Single Trusted Kernel

A single clean Rust crate without foreign runtime dependencies — zero Node.js, Python, or GPU required for core runtime execution.

2. Deterministic Governance

Every side effect passes through an 11-stage policy evaluation gate across a 10-tier authority stack.

3. Evidence-Based Completion

No mission or task is marked complete without deterministic, multi-tier verification evidence and cryptographic SHA-256 digests.

4. Resilient Recovery

Two-phase atomic checkpoints, startup crash recovery scanners, and differential DAG replanning preserve verified work.

5. Bounded Confinement

10-dimensional hard resource budgets and platform-aware confinement (Linux cgroups v2, POSIX rlimits) eliminate runaway executions.

6. Local Observability

SQLite compact event indexes, append-only NDJSON execution streams, and zero-leak secret redaction before durable storage.

What M31A Is Not

  • Not a generic chatbot or Copilot clone: It does not just suggest code completions; it plans, executes tools, and runs verifications in your local workspace.
  • Not a remote execution service: All execution happens on your local workstation or server under your direct terminal supervision.
  • Not an unconstrained prompt wrapper: The LLM has zero direct OS access; every action is mediated through sandboxed tools and non-bypassable policy gates.