v0.6.1 — Hardening Release
Helm v0.6.1 — Hardening Release
Date: 2026-04-25
Helm 0.6.1 is a comprehensive hardening release that improves every module's type safety, immutability, thread safety, and test coverage. No new features are added — this release focuses entirely on correctness and robustness. 118 new tests bring the total to 298.
Hardening Highlights
Security (command_guard, run_with_profile)
- SemanticResult NamedTuple: Replaced stringly-typed
"approve."/"deny."prefix convention with a structuredSemanticResult(action, reason)return type - Recursive shell unwrapping:
_effective_argvloops up to depth 5 to catch nestedbash -c "bash -c '...'"patterns - dd read/write distinction:
if=device →require_approval,of=device →deny - shred/wipefs/blkdiscard: Added to semantic deny rules for device-targeting commands
- Subprocess timeout:
--timeoutflag (default 1800s) with properTimeoutExpiredhandling - Minimal environment:
_minimal_env()strips secrets from restricted profile subprocesses - --guard-json: Machine-readable guard decision output without executing the command
- Fail-closed tuples: All fallback guard decisions use immutable
tuple()instead of list literals
Immutability Enforcement
- Frozen dataclasses everywhere: All
list[str]fields →tuple[str, ...]acrossGuardDecision,CommandClassification,ProviderProbe,RuntimeFingerprint,HardwareProfile,RuntimeModelState - StrategyConfig: New frozen dataclass replaces the lone mutable
dict[str, object]field inDiscoverySnapshot - IntelligenceTier.available_tiers(): Returns
tuple[str, ...]instead oflist[str]
Thread Safety & Reliability
- ops_db:
_INITIALIZED_DBSprotected bythreading.Lock; schema versioning via_check_schema_version() - state_io: Windows sentinel-region lock (bytes 0–1);
threading.Eventfor lock warning; documented"ab"mode seek behavior - GPU detection:
@functools.lru_cache(maxsize=1)on_detect_gpu()— hardware doesn't change during process lifetime - Streaming JSONL:
verify_indexandread_jsonluse line-by-line reading (no OOM on large files) - Response body limit:
model_provider_probecaps HTTP response reads at 64KB
Code Quality
- JSONL consolidation: Duplicate
read_jsonl/append_jsonlremoved from 6 modules → single canonical source incommands/__init__.pyandstate_io.py - run_script consolidation: Removed from 6 command modules → single
commands/__init__.py - Lazy initialization:
reply_gateandrun_with_profiledefer workspace lookups - sys.executable: Replaces hardcoded
python3for Windows compatibility - Deep merge:
_deep_merge(base, overlay)for skill contract resolution - intelligence_tier: Complete rewrite from stub to snapshot-driven L0-L4 resolution
Tests
- 118 new tests (298 total, was 180)
- New test suites:
test_intelligence_tier.py(19),test_reply_gate.py(19),test_memory_capture.py(23) - Expanded:
test_command_guard.py(+35),test_run_with_profile_guard.py(+13)
Review Score Progression
| Cycle | Average | CRITICAL | IMPORTANT |
|---|---|---|---|
| 1st | 6.2/10 | 5 | 12 |
| 2nd | 7.7/10 | 0 | 12 |
| 3rd | 8.5/10 | 0 | 0 |
| 4th | 8.8/10 | 0 | 0 |