Skip to content

v0.9.0: durable budgets and tool execution lifecycle - #14

Merged
renezander030 merged 1 commit into
masterfrom
feat/v0.9.0-governance
Oct 3, 2026
Merged

renezander030 merged 1 commit into
masterfrom
feat/v0.9.0-governance

Conversation

@renezander030

@renezander030 renezander030 commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Concurrent pipelines previously shared run counters, daily spend disappeared on restart, and paid responses rejected by output policy could escape accounting. This release adds durable admission and settlement, fail-closed approval writes, and an explicit tool execution lifecycle.

Included improvements:

  1. Isolated per-run budgets and serialized model admission.
  2. Durable UTC daily usage, pending-call recovery, and budget status/reconcile.
  3. Central accounting for every engine model call, including classification, rewrites, and denied/reviewed output.
  4. Approval storage failures block release; tool decisions and consumption commit their receipts atomically.
  5. Immutable caller-attested execution outcomes bound to consumed actions.
  6. Consistent expiry/current-policy checks for live and recovered permits.
  7. Authenticated revocation of unconsumed tool actions, safe against consumption races and late approvals.
  8. Exact scalar output validation with startup schema checks and unambiguous JSON.
  9. Bounded provider responses and no automatic re-dispatch when billing is uncertain.

Cost limits remain thresholds checked between calls. Final provider usage can exceed an admitted token allowance; that usage is charged and output is withheld. Unresolved billing blocks further model calls until verified reconciliation. Completion reports attestations from the harness, rather than independent proof of a side effect.

Validation:

  • Lean and voice suites.
  • Race detector for engine/state concurrency.
  • Vet and lint against the base revision.
  • Native CLI version/config/budget-help smoke checks.
  • npm tests, package dry-run, and wrapper smoke check.

Prepares version 0.9.0 in Go and npm metadata, changelog, and operator/release guides. After review, the existing tag workflow can publish GitHub binaries/checksums, GHCR, and npm; the Go module uses the same tag. PyPI and MCP Registry do not apply to this CLI/service. npm authentication must be checked independently of successful native/container publishing. No release tag or publication is part of this PR.

@renezander030
renezander030 merged commit 482b7a5 into master Oct 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant