What the Runtime Owns.
Every feature below is implemented and governed by the Rust runtime. Subsystem boundaries are strictly enforced; authority never leaks to upstream models.
Runtime
(7 features)Autonomous Execution Loop
AvailableA 12-stage deterministic execution loop where the runtime owns state, scheduling, and completion criteria — not the model.
The LLM is treated as an untrusted reasoning component. The runtime strictly owns state, scheduling, file access, command execution, policies, verification, and completion criteria.
Continuous Verification
AvailableMulti-tier quality gates verify each action against completion criteria before the runtime accepts the result.
Verification states, test outputs, linters, and cryptographic SHA-256 evidence digests are collected before any mission is allowed to complete.
28 Core Typed Tools
AvailableA capability-bound tool registry across 15 capability families where each tool declares risk classes and JSON schema contracts.
Spans filesystem (7), repository intelligence (3), process management (5), Git (8), verification (3), and artifact storage (2).
Task DAG & Planning
AvailableDecomposed tasks modeled as a petgraph-backed directed acyclic graph with topological scheduling and differential replanning.
Candidate plans are verified before admission. On crash recovery, differential DAG replanning preserves already verified tasks.
Deployment Channels
AvailableCompile-time artifact identity separates production (m31a) from development (m31a-dev) with isolated state paths.
Channel is compile-time — no runtime switch can re-channel a binary. Features transactional installer with atomic rollback seam.
10-Dimensional Budget Model
AvailableHard resource budget bounds across wall-clock time, memory, CPU, tokens, dollar cost, agent steps, and storage.
Two-phase reservation and settlement engine eliminates race conditions across concurrent agent steps.
8 Canonical Agent Roles
AvailableSpecialized role state machines for planner, researcher, architect, implementer, reviewer, verifier, diagnostician, and integrator.
Anti-fake-diff reviews detect todo!() and unimplemented!() placeholders. Premature-completion rejection prevents unverified completions.
Security
(4 features)Non-Bypassable Policy Gates
AvailableEvery side effect passes through an 11-stage policy gate before execution. No action reaches the workspace without authorization.
File writes, process spawning, Git operations, and network requests all pass through 10 authority layers. Built-in Layer 0 safety vetoes can never be weakened.
5-Tier Secret Redaction
AvailableDeterministic scrubbing pipeline masking API keys (NVIDIA, AWS, GitHub, OpenAI), JWTs, passwords, and private keys.
Scrubbing applies before persistence, display buffers, or logs. Includes sanitize_error preventing stack traces from leaking secrets.
Multi-Tier Process Confinement
AvailableDefense-in-depth confinement via Linux cgroups v2, POSIX rlimits, process group isolation, and watchdog supervision.
Deny-by-default environment contract: cmd.env_clear() strips all inherited host environment variables and secrets, blocking LD_PRELOAD.
Network Destination Policy (SSRF)
AvailableStrict egress filtering blocking loopback, RFC 1918 private IPs, cloud metadata (169.254.169.254), and redirect SSRF.
Asynchronous DNS pre-validation before connection and step-by-step redirect checks up to 5 hops prevent DNS rebinding attacks.
Interface
(1 features)Terminal-Native Cockpit
AvailableA full terminal cockpit built with Ratatui 0.30 — conversation, live activity, task graphs, approvals, and telemetry in one unified surface.
The TUI is a pure projection of authoritative SQLite runtime state. Guaranteed terminal raw-mode restoration with RAII TerminalGuard.
Workflow
(1 features)Git-Aware Worktree Isolation
AvailableFail-closed worktree isolation and RFC-compliant commit trailers keep agent work separate and attributable.
In production, git.execution_isolation = "required" fails closed if worktree creation cannot be verified, preventing unisolated edits to primary branch.
Persistence
(1 features)Crash-Resilient Checkpoints
AvailableTwo-phase atomic checkpoints and startup crash recovery scanners preserve verified work across system crashes.
External artifact staging followed by atomic SQLite transaction. Ambiguous and corrupt recovery states fail closed without blind auto-resume.
Observability
(2 features)Local Observability
AvailableCompact SQLite event index and append-only NDJSON execution stream with zero-leak secret redaction.
Structured telemetry logs record proposal kinds, tool call counts, durations, and audit digests. Raw model output and arbitrary command text never enter traces.
Replay & Post-Mortem
AvailableHistorical event timeline with read-only playback for inspecting past execution state and decisions.
Reconstruct past sessions step-by-step to inspect exact model proposals, policy decisions, tool invocations, and verification results.
Models
(2 features)Model Provider Abstraction
AvailableProvider-neutral trait with SSE streaming; production runtime strictly and exclusively enforces NVIDIA NIM.
Retired provider IDs (openai, anthropic, gemini, ollama) are rejected deterministically. Invariant: no credential attached before endpoint trust is verified.
Extended Model Providers
PlannedArchitectural support for additional model providers beyond NVIDIA NIM once qualification criteria are met.
Currently production is strictly NVIDIA NIM. Future provider support requires native endpoint trust and parity verification.