Skip to content
M31A
FEATURES & CAPABILITIES

What the Runtime Owns.

Every feature below is implemented and governed by the Rust runtime. Subsystem boundaries are strictly enforced; authority never leaks to upstream models.

Runtime

(7 features)

Autonomous Execution Loop

Available

A 12-stage deterministic execution loop where the runtime owns state, scheduling, and completion criteria — not the model.

The LLM is treated as an untrusted reasoning component. The runtime strictly owns state, scheduling, file access, command execution, policies, verification, and completion criteria.

Source Modulesrc/agent/engine.rs

Continuous Verification

Available

Multi-tier quality gates verify each action against completion criteria before the runtime accepts the result.

Verification states, test outputs, linters, and cryptographic SHA-256 evidence digests are collected before any mission is allowed to complete.

Source Modulesrc/verification/gate.rs

28 Core Typed Tools

Available

A capability-bound tool registry across 15 capability families where each tool declares risk classes and JSON schema contracts.

Spans filesystem (7), repository intelligence (3), process management (5), Git (8), verification (3), and artifact storage (2).

Source Moduledocs/subsystems/TOOLS.md

Task DAG & Planning

Available

Decomposed tasks modeled as a petgraph-backed directed acyclic graph with topological scheduling and differential replanning.

Candidate plans are verified before admission. On crash recovery, differential DAG replanning preserves already verified tasks.

Source Modulesrc/agent/intent.rs

Deployment Channels

Available

Compile-time artifact identity separates production (m31a) from development (m31a-dev) with isolated state paths.

Channel is compile-time — no runtime switch can re-channel a binary. Features transactional installer with atomic rollback seam.

Source Modulesrc/deployment/channel.rs

10-Dimensional Budget Model

Available

Hard resource budget bounds across wall-clock time, memory, CPU, tokens, dollar cost, agent steps, and storage.

Two-phase reservation and settlement engine eliminates race conditions across concurrent agent steps.

Source Moduledocs/subsystems/AUTONOMY.md

8 Canonical Agent Roles

Available

Specialized role state machines for planner, researcher, architect, implementer, reviewer, verifier, diagnostician, and integrator.

Anti-fake-diff reviews detect todo!() and unimplemented!() placeholders. Premature-completion rejection prevents unverified completions.

Source Modulesrc/agent/registry.rs

Security

(4 features)

Non-Bypassable Policy Gates

Available

Every side effect passes through an 11-stage policy gate before execution. No action reaches the workspace without authorization.

File writes, process spawning, Git operations, and network requests all pass through 10 authority layers. Built-in Layer 0 safety vetoes can never be weakened.

Source Modulesrc/policy/matcher.rs

5-Tier Secret Redaction

Available

Deterministic scrubbing pipeline masking API keys (NVIDIA, AWS, GitHub, OpenAI), JWTs, passwords, and private keys.

Scrubbing applies before persistence, display buffers, or logs. Includes sanitize_error preventing stack traces from leaking secrets.

Source Modulesrc/policy/destination.rs

Multi-Tier Process Confinement

Available

Defense-in-depth confinement via Linux cgroups v2, POSIX rlimits, process group isolation, and watchdog supervision.

Deny-by-default environment contract: cmd.env_clear() strips all inherited host environment variables and secrets, blocking LD_PRELOAD.

Source Modulesrc/sandbox/limits.rs

Network Destination Policy (SSRF)

Available

Strict egress filtering blocking loopback, RFC 1918 private IPs, cloud metadata (169.254.169.254), and redirect SSRF.

Asynchronous DNS pre-validation before connection and step-by-step redirect checks up to 5 hops prevent DNS rebinding attacks.

Source Modulesrc/policy/destination.rs

Interface

(1 features)

Terminal-Native Cockpit

Available

A full terminal cockpit built with Ratatui 0.30 — conversation, live activity, task graphs, approvals, and telemetry in one unified surface.

The TUI is a pure projection of authoritative SQLite runtime state. Guaranteed terminal raw-mode restoration with RAII TerminalGuard.

Source Modulesrc/tui/app.rs

Workflow

(1 features)

Git-Aware Worktree Isolation

Available

Fail-closed worktree isolation and RFC-compliant commit trailers keep agent work separate and attributable.

In production, git.execution_isolation = "required" fails closed if worktree creation cannot be verified, preventing unisolated edits to primary branch.

Source Modulesrc/policy/effective.rs

Persistence

(1 features)

Crash-Resilient Checkpoints

Available

Two-phase atomic checkpoints and startup crash recovery scanners preserve verified work across system crashes.

External artifact staging followed by atomic SQLite transaction. Ambiguous and corrupt recovery states fail closed without blind auto-resume.

Source Moduledocs/subsystems/RECOVERY.md

Observability

(2 features)

Local Observability

Available

Compact SQLite event index and append-only NDJSON execution stream with zero-leak secret redaction.

Structured telemetry logs record proposal kinds, tool call counts, durations, and audit digests. Raw model output and arbitrary command text never enter traces.

Source Modulesrc/tui/surface/telemetry.rs

Replay & Post-Mortem

Available

Historical event timeline with read-only playback for inspecting past execution state and decisions.

Reconstruct past sessions step-by-step to inspect exact model proposals, policy decisions, tool invocations, and verification results.

Source Modulesrc/tui/surface/replay.rs

Models

(2 features)

Model Provider Abstraction

Available

Provider-neutral trait with SSE streaming; production runtime strictly and exclusively enforces NVIDIA NIM.

Retired provider IDs (openai, anthropic, gemini, ollama) are rejected deterministically. Invariant: no credential attached before endpoint trust is verified.

Source Modulesrc/model/provider/mod.rs

Extended Model Providers

Planned

Architectural support for additional model providers beyond NVIDIA NIM once qualification criteria are met.

Currently production is strictly NVIDIA NIM. Future provider support requires native endpoint trust and parity verification.

Source Moduledocs/architecture/ARCHITECTURE.md