Skip to content

Context Guard 0.12.0

Choose a tag to compare

@GreenLv GreenLv released this 06 Sep 07:16
· 195 commits to main since this release

Context Guard 0.12.0

English

Context Guard 0.12.0 is the model- and agent-agnostic baseline for protecting
long-running tasks. It does not assume that the model or host already provides
reliable long-context recovery, completion protection, or release authority.

Highlights

  • Normal successful work is silent again: allowed tools and safe turn endings
    no longer emit persistent Hook status text or developer receipts.
  • Explicit work units keep completed or historical work from reopening as
    current debt after compaction or resume.
  • The position-aware classifier distinguishes commands that actually execute
    high-risk actions from quoted text, searches, examples, and dry runs.
  • standard, strict, release, observe, and off profiles separate
    ordinary completion protection from evidence and publication policy.
  • Protocol semantics are separated from the Codex Hook adapter so the baseline
    can be compared across models and agents.

Validation boundary

The candidate passes 684 current-behavior tests across 16 modules, the frozen
transition audit, repository and privacy checks, Hook self-test, lint, and
compilation. Native macOS and Windows acceptance independently bind the same
26-file runtime-tree SHA-256:
fa5928a3ce754120b4f7a5ce4d9907d04a80cc948780f72ffdfe96187924f4ae.
Exact CI, publication, and public readback are recorded as separate gates in
the local acceptance record.

Existing tasks may continue using the immutable Hook version they started
with. After upgrading, start a fresh task, review and trust all nine Hooks, then
start another fresh task so it loads 0.12.0. Normal user-runtime installation
is not implied by source, CI, native-candidate, or publication evidence.

简体中文

Context Guard 0.12.0 是面向通用模型与 Agent 的长任务保护基线。它不假定
模型或宿主已经具备可靠的长上下文恢复、完成保护或发布授权能力。

主要变化

  • 正常成功路径重新静默:允许的工具调用和安全结束不再显示常驻 Hook
    状态文案或 developer 回执。
  • 显式工作单元避免已完成或历史工作在 compact、resume 后重新变成当前债务。
  • 位置感知分类器只识别真正执行的高风险动作,不会把引用、搜索、示例或
    dry run 当成实际操作。
  • standard、strict、release、observe 与 off profile 把普通完成
    保护、严格证据和发布策略分开。
  • 协议语义与 Codex Hook adapter 分离,便于在不同模型和 Agent 上对照这套
    基线。

验证边界

候选版本通过 16 个模块的 684 项 current-behavior 测试、冻结 transition
审计、仓库与隐私检查、Hook 自检、lint 和编译。macOS 与 Windows 原生验收
分别绑定同一个 26 文件运行时树 SHA-256:
fa5928a3ce754120b4f7a5ce4d9907d04a80cc948780f72ffdfe96187924f4ae。
精确 CI、发布与公开读回作为独立门禁记录在本地验收文档。

已有任务可能继续使用启动时加载的不可变 Hook 版本。升级后请新建任务,
检查并信任全部九个 Hook,再新建一个任务以加载 0.12.0。源码、CI、原生
候选或发布证据均不代表正常用户运行时已经完成安装。