Skip to content

v0.7.0: proof-carrying execution - #11

Merged
renezander030 merged 2 commits into
masterfrom
feat/v0.7.0-proof-carrying-execution
Sep 17, 2026
Merged

renezander030 merged 2 commits into
masterfrom
feat/v0.7.0-proof-carrying-execution

Conversation

@renezander030

Copy link
Copy Markdown
Owner

Release: v0.7.0

This release makes every accepted action carry durable, inspectable proof from admission through execution.

What changed

  • Bind approvals to immutable action IDs, exact payloads, policy digests, and expiry windows.
  • Authenticate every tool-gate ask, poll, and consume route with the webhook bearer boundary; signed POST bodies follow webhook.require_signature.
  • Turn allowed tool decisions into atomic consume-once permits. Only the first valid consume response carries permit: execute.
  • Persist stable action IDs and idempotent terminal state in SQLite; matching retries return the existing result and drift gets 409.
  • Write webhook admission records before HTTP 202, return an admission ID, and expose authenticated status polling.
  • Add backward-compatible receipt schema v2 while preserving verification of existing v1 rows.
  • Add draftcat receipts list, show, and chronological JSONL export from the SQLite source of truth.
  • Add ordered model input/output policy rules with fail-closed deny and human review actions.
  • Add /healthz liveness and SQLite-backed /readyz readiness endpoints.

Compatibility

  • Existing v1 approval receipts continue to verify.
  • Existing tool-gate callers receive a generated action ID, but retry-safe clients should send and persist their own stable action_id.
  • An allow decision no longer authorizes execution by itself. Clients must consume the returned binding and execute only when the response contains permit: execute.

Validation

  • go test ./...
  • go test -race ./...
  • go test -short ./...
  • go vet ./...
  • golangci-lint run --new-from-rev=HEAD
  • go build .
  • draftcat validate --config config.yaml (0 errors)
  • v0.6-style SQLite migration regression test

@renezander030
renezander030 merged commit 8284656 into master Sep 17, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant