Skip to content

Releases: AETHERXGLOBAL/execsurface

ExecSurface v0.1.0-alpha.6

Pre-release

Choose a tag to compare

@github-actions github-actions released this 08 Oct 04:21
6d49b76

ExecSurface v0.1.0-alpha.6

Sixth public alpha of ExecSurface.

Alpha.6 supersedes Alpha.5 as the recommended public Alpha for the documented Linux x86_64 + native ptrace product boundary. Alpha.5 remains immutable and available for rollback, reproduction, and historical review.

What changed

Alpha.6 incorporates the Stage-2 semantic-remediation program and the post-R8 merge-authorization destruction round.

Runtime evidence correctness

  • Corrected stale FD destination identity after successful dup2/dup3-style replacement from an untracked source.
  • Unknown FD I/O no longer disappears while evidence remains marked complete; unresolved attribution fails closed.
  • Side-effectful open handling now distinguishes lexical intent from kernel-resolved object evidence within the qualified boundary.
  • Multiply-linked filesystem objects are treated conservatively where path-only attribution cannot prove unique object identity.

Baseline and policy custody

  • A verified baseline can be bound to an externally supplied expected semantic digest.
  • Policy bytes can be bound to an externally supplied SHA-256 identity.
  • Required-custody Action mode rejects missing, partial, malformed, duplicated, or unauthorized trust pins before target execution.

Policy schema v3

Alpha.6 adds opt-in policy schema v3 matchers for:

  • open intent;
  • path-resolution authority;
  • rename source.

Policy v1/v2 meanings are retained. v3-only fields under older schemas are rejected rather than ignored.

Verdict-output materialization

The post-R8 destruction round found and retained multiple fail-first counterexamples around report output ownership and pathname rebinding.

The corrected materialization guard covers, within the qualified boundary:

  • direct workload writes;
  • rename and chained-rename lineage;
  • parent-directory rename lineage;
  • create/truncate/ftruncate/delete final-state changes;
  • hardlink alias transitions;
  • preexisting and workload-created symlink outputs;
  • multiply-linked and non-regular output objects;
  • output-parent directory replacement;
  • output-parent symlink rebinding.

The final merge-authorization destruction corpus passed 17/17 cases on the qualified product source.

Compatibility boundary

Alpha.6 uses corrected normalization profile 4.

Alpha.5 baselines use profile 3 and are not silently migrated or reinterpreted. A profile-3 Alpha.5 baseline is explicitly incomparable with an Alpha.6 profile-4 candidate.

Migration: relearn the baseline with Alpha.6 under the same intended command/wrapper before using Alpha.6 check.

Alpha.5 remains available for exact historical reproduction and rollback.

Verdict contract

The existing verdict meanings remain:

  • PASS = 0
  • ERROR = 2
  • REVIEW = 10
  • BLOCK = 20

The wrapped target's native exit status remains report metadata rather than an automatic verdict input; this meaning is unchanged from Alpha.5.

Qualified public boundary

  • Linux x86_64
  • native ptrace reference observer
  • Alpha.6 is still a prerelease
  • experimental libbpf/eBPF paths are not promoted into the public PASS/learn/check authority boundary

ExecSurface is a runtime behavioral-verification / execution-semantics / semantic-evidence correctness system. This release does not classify the project as cybersecurity research and does not claim that PASS proves software safety.

Preserved history

This release does not delete or rewrite:

  • v0.1.0-alpha.5;
  • Alpha.5 release artifacts;
  • historical issues, PRs, comments, reviews, or external-engagement records;
  • retained RED/fail-first evidence from Stage-2.

The moving v0.1 Action channel is promoted to Alpha.6 only after the immutable Alpha.6 release and consumer gates pass.

Source commit: 6d49b76841cc5fbe752d992aa15017219b55b725

Build workflow: https://github.com/AETHERXGLOBAL/execsurface/actions/runs/37727017593

ExecSurface v0.1.0-alpha.5

Pre-release

Choose a tag to compare

@github-actions github-actions released this 01 Oct 18:58

ExecSurface v0.1.0-alpha.5

Fifth public alpha of ExecSurface, a runtime behavioral-integrity and verification layer for observed execution-surface drift.

What advances in Alpha.5

  • stronger semantics-preserving handling of the current evidence model, keeping ambiguous or incomplete evidence non-PASS-eligible;
  • stronger proposition and backend authority boundaries rather than treating a backend name as universal authority;
  • stronger legitimate-variance handling while retaining anti-poisoning constraints on accepted behavior;
  • stronger attestation, provenance, executable binding and release-artifact verification;
  • improved usability, packaging and reproducibility qualification;
  • portable release construction on Ubuntu 22.04 with a GLIBC compatibility ceiling, followed by public-artifact tests on Ubuntu 22.04 and Ubuntu 24.04.

Evidence boundary

Frozen product source: 5067200452c174da6bc8d9d7ecf6957ee379f0a2.

Internal destructive release-artifact qualification passed in run 36902486872. The earlier failed A7 run 36901600086, which exposed reproducibility and ABI-portability problems, remains retained evidence and was repaired before the accepted run.

P8 independent external validation was not closed before publication. Publication was explicitly authorized by the owner with P8 waived only as a pre-publication gate. This release does not claim independent external validation. P8 remains open for post-release reproduction, criticism, counterexamples, interoperability review and real-workload evidence.

Public support boundary

  • Linux x86_64 is the public support scope for this alpha.
  • Native ptrace remains the bounded public reference observer for the portable line.
  • ARM64 support is not claimed.
  • Observed behavior is not all possible behavior.
  • ExecSurface is not an antivirus, EDR, SIEM, sandbox, malware detector or proof of software safety.
  • Incomplete or ambiguous evidence cannot silently become PASS.

Distribution verification

The release pipeline checks source quality, deterministic dual builds, GLIBC compatibility, checksums, provenance attestation, archive safety and privacy, clean public consumption on Ubuntu 22.04 and 24.04, source-to-artifact byte equivalence, immutable-tag installation, Action PASS/REVIEW/BLOCK/ERROR semantics, tamper rejection, stable v0.1 promotion only after public proofs, and registry installation after publication.

Release source commit: 9e73b925d55557e33de1b0813995609aaefdc037
Frozen product source: 5067200452c174da6bc8d9d7ecf6957ee379f0a2

Build and attestation run: https://github.com/AETHERXGLOBAL/execsurface/actions/runs/36910725515

ExecSurface v0.1.0-alpha.4

Pre-release

Choose a tag to compare

@github-actions github-actions released this 28 Sep 19:47

ExecSurface v0.1.0-alpha.4

Fourth public alpha for the portable fail-closed hardening validated under M10–M12.

Reliability hardening

  • changes known clone-based fd-lifecycle ambiguity from potentially complete=true evidence to explicit incomplete / non-PASS-eligible evidence;
  • preserves the underlying shared-FD limitation rather than claiming exact attribution repair;
  • the portable ptrace guard may conservatively mark some clone/thread concurrency incomplete even when exact fd-table sharing is not proven; raw observation v2 does not retain enough CLONE_FILES detail to certify exact sharing, so this intentionally trades possible false incompleteness for preventing the known false-completeness class;
  • keeps event-budget loss and other known incomplete-evidence states fail-closed;
  • retains existing PASS / REVIEW / BLOCK / ERROR policy semantics and stable CLI exit-code behavior.

Evidence authority boundary

  • ptrace pathname observations remain pathname access-attempt metadata under the recorded observer; they are not represented as kernel-object identity;
  • adversarial PATH-TOCTOU and shared-FD counterexamples remain documented and reproduced in the M12 release review;
  • experimental/hybrid evidence capabilities remain explicit and proposition-scoped rather than silently treated as equivalent to the public ptrace path.

Compatibility and distribution

  • Linux x86_64 remains the public support scope;
  • native ptrace remains the public default/reference observer for the portable release line;
  • existing baseline-v2 serialization/digest semantics are unchanged and legacy schemas are not silently reinterpreted;
  • GitHub Release binary, crates.io package chain, and AETHERXGLOBAL/execsurface@v0.1 are the public distribution surfaces after their respective release gates complete.

Hybrid/BPF-LSM status

BPF-LSM / kernel-hook work remains managed/research-only and non-default. This alpha does not authorize automatic hybrid selection, new privilege requirements for the portable path, ptrace↔hybrid baseline interchangeability, or claims of end-to-end hybrid production readiness.

Performance scope

M12 paired hosted-CI benchmarks found no preregistered gate-blocking performance, RSS, binary-size, or event-shape regression in the tested Ubuntu 22.04 and 24.04 environments. This is engineering evidence for the release decision, not a universal performance-improvement or production-cost claim.

Product boundary

ExecSurface detects observed execution-surface drift under its recorded observer and explicit policy. It does not prove software safety, observed behavior is not all possible behavior, and incomplete evidence cannot silently become PASS.

Source commit: 48e0b9a0707553349e75e97a9dfa096d13f9ab5d

Build workflow: https://github.com/AETHERXGLOBAL/execsurface/actions/runs/36474542683

ExecSurface v0.1.0-alpha.3

Choose a tag to compare

@github-actions github-actions released this 27 Sep 00:13
79c4542

ExecSurface v0.1.0-alpha.3

Third public alpha, promoting the ptrace lifecycle hardening and the M9.1 external-workload evidence already merged to main.

Reliability and validation

  • incorporates the lifecycle-specific ptrace hardening closed under issue #55;
  • retains fail-closed completeness and existing PASS / REVIEW / BLOCK / ERROR authority semantics;
  • adds durable lifecycle regression coverage, including the pinned casey/just external workload;
  • carries M9.1 zero-contact external workload evidence for just, ripgrep, fzf, and fd;
  • preserves negative and PARTIAL evidence for unstable build/test surfaces rather than relabeling it as success.

Distribution

  • Linux x86_64 remains the public support scope;
  • native ptrace remains the public correctness-reference backend;
  • GitHub Release binary, crates.io package chain, and the stable AETHERXGLOBAL/execsurface@v0.1 Action channel remain the intended distribution surfaces;
  • this release does not authorize the experimental eBPF backend for PASS, learn/check, automatic backend selection, or baseline interchangeability.

Product boundary

ExecSurface detects observed runtime execution-surface drift. It does not prove software safety, and observed behavior is not all possible behavior.

Source commit: 79c4542730a1a4698db859d9f399cb39bf41ead3

Build workflow: https://github.com/AETHERXGLOBAL/execsurface/actions/runs/36281830689

ExecSurface v0.1.0-alpha.2

Pre-release

Choose a tag to compare

@github-actions github-actions released this 26 Sep 00:22
c6cabf1

ExecSurface v0.1.0-alpha.2

Second public alpha focused on Rust-native distribution without changing the execution-surface semantics established in M6.5/M7.

Distribution changes

  • public package identity simplified to execsurface;
  • workspace runtime crates made registry-ready with exact prerelease dependency versions;
  • internal benchmark probe remains non-publishable;
  • GitHub Release binary distribution remains supported;
  • stable GitHub Action channel remains AETHERXGLOBAL/execsurface@v0.1;
  • gated crates.io publication workflow added;
  • registry publication requires explicit maintainer credentials and an immutable release tag.

Product boundary

This release does not change:

  • evidence schema v2;
  • canonicalization semantics;
  • baseline/policy separation;
  • PASS / REVIEW / BLOCK / ERROR semantics;
  • Linux x86_64 support scope;
  • the ptrace reference-backend decision.

ExecSurface still detects observed runtime execution-surface drift. It does not prove software safety.

Source commit: c6cabf1b4d1399898b9643a7fce011664aac0918

Build workflow: https://github.com/AETHERXGLOBAL/execsurface/actions/runs/36204571334

ExecSurface v0.1.0-alpha.1

Pre-release

Choose a tag to compare

@github-actions github-actions released this 25 Sep 21:55
d6919e2

ExecSurface v0.1.0-alpha.1

First public alpha of AETHER X ExecSurface.

What this release is

ExecSurface detects observed runtime execution-surface drift between an accepted baseline and a later run.

Public alpha support is intentionally narrow:

  • Linux
  • x86_64
  • native ptrace reference observer
  • GitHub Actions integration

Included

  • metadata-only runtime observation;
  • descendant process execution effects;
  • fd-attributed file read/write evidence;
  • network destination evidence;
  • deterministic canonical surfaces;
  • content-addressed baseline lock;
  • deterministic diff;
  • independent policy layer;
  • PASS / REVIEW / BLOCK / ERROR;
  • GitHub composite Action;
  • execsurface doctor;
  • execsurface init;
  • v2 evidence contracts.

Security boundary

ExecSurface does not prove a program is safe.

Observed behavior is not all possible behavior.

No observed network activity is not proof that network access is impossible.

Observer completeness remains part of the evidence contract.

Install integrity

The GitHub Release publishes:

  • a Linux x86_64 archive;
  • a SHA-256 checksum;
  • GitHub build provenance attestation.

Attestation links an artifact to its build source/workflow. It is not a claim that the artifact is safe.

Source commit: d6919e2b3e23b196965bc7bba87598f09265599f

Build workflow: https://github.com/AETHERXGLOBAL/execsurface/actions/runs/36194046171

Release archive digest: sha256:e03a4e6852404992eb8d6d9347dd32f168c91528acad52b16ae328e629a30753