Skip to content

v0.99.16

Choose a tag to compare

@github-actions github-actions released this 29 Jul 03:08

Added

  • Add measurable first-use, core, adapters, governance, labs, and
    all views to synapse commands, including a versioned JSON contract for
    concept count, exact journey, package extras, implicit services, and explicit
    activation/deactivation boundaries while preserving the complete CLI surface.
  • Attach a container release manifest, SPDX image SBOM, checksums, and portable
    build-provenance/SBOM attestation bundles to each published release image.
  • Publish and continuously validate one machine-readable effective-policy
    contract across all nine externally reachable transport families without
    replacing the immutable hub configuration API.
  • Persist credential-free A2A push-delivery attempt evidence, expose it through
    authenticated task-scoped HTTP and JSON-RPC reads, and return typed success or
    terminal dead-letter results after a bounded 0.25/1-second retry schedule.
  • Narrow the multi-hub task board to an explicitly non-authoritative, non-causal
    display-only LWW contract. Text and JSON surfaces expose each displayed
    winner's (timestamp, hub_id, seq) provenance and state that synchronized
    clocks, including NTP, are not causal proof; local claim and namespace
    authority remain separate.
  • Give terminal pane bridges a distinct <identity>-pane-rx receiver while
    retaining <identity>-rx for durable mailbox arms. Shared identity parsing,
    doctor, and ready dispatch recognise both; mailbox arms now coexist with an
    active provider without receiver takeover, while redundant non-mailbox arms
    still yield.
  • Fail closed when an existing tmux session belongs to another Synapse seat.
    agent-tmux start, status, and wake now verify the live session's stable
    SYN_PROJECT and SYN_IDENTITY environment before accepting the pane or
    injecting a wake, preventing two project identities from sharing one target.
  • Bound pane-bridge truth to a live target. The bridge now uses a short wait
    interval as a liveness checkpoint, unregisters, and re-proves the tmux
    session, exact binding, and agent pane before advertising again; a vanished
    or inactive pane therefore closes the receiver without waiting for a message.
  • Correct the public multi-hub serving API contract: an absent serving policy
    refuses every peer, matching the handler's existing fail-closed behavior and
    regression tests; serving requires an explicit trusted peer grant.

Security

  • Fail Linux release preflight when its Python cannot exercise memfd/procfd and
    descriptor-sealing MCP launch protections; the runtime guard now also checks
    every required fcntl seal primitive before entering that path.
  • Prevent terminal wake bridges from approving provider modals. Pane delivery
    now requires provider-specific idle-composer evidence before and after one
    bracketed fixed-prompt paste; busy, modal, unknown, or ambiguous panes receive
    no submit key and retain a restart-safe pending wake for later delivery.
  • Build the container from hash-locked build frontend, backend, and runtime
    inputs; disable build isolation and live wheel dependency resolution; and
    attest the exact immutable GHCR digest plus its generated image SBOM.

Fixed

  • Load the latest tpm2-pytss against cryptography's canonical moved Camellia
    and CFB classes, removing the impending legacy-import failure and collection
    warnings without suppressing diagnostics or pinning an obsolete crypto stack.
  • Refuse commits and release builds whose generated capability inventory is
    stale, while retaining the lightweight pre-push drift check as a final
    operator guard.
  • Replace the divergent fastest-safe-trial sequences with one
    regression-bound, self-contained doctor → golden demo path that proves
    conflict refusal, handoff, and a verified receipt before any persistent hub,
    repository hook, MCP host, or optional A2A bridge is introduced.
  • Make agent-tmux wait start or verify its configured provider session and
    require an active agent pane before advertising pane_bridge, so a missing
    downstream tmux target fails closed instead of accepting unwakeable messages.
  • Resolve the arm service's machine identity through a hardened-namespace-safe
    relative XDG data path, so pinned receivers present their existing proof
    instead of degrading to unsigned reconnect loops.
  • Give deliberate arm disarms a dedicated successful exit status that systemd
    never restarts, covering active-provider yield, identity recovery, and name
    takeover while retaining Restart=always self-healing for unexpected exits.
  • Keep valid A2A task transitions independent from outbound webhook outcomes:
    expected network failures no longer vanish silently or rewrite task state,
    and every retry, success, or terminal dead letter is committed separately.

Artifact checksums (SHA-256)

cc3f5ba8951688a41ff3cc4de7d94cf9a950b97102e7ebca8f04890c2b75d038  synapse_channel-0.99.16-py3-none-any.whl
25a95be95c640f27493ce70075aa9a333f0a0cac6e364d47b1dbf7f78f3f000b  synapse_channel-0.99.16.tar.gz
2782c2a0f9dc4fa5f6ee34eed39f9475e2d949af048bb692620ca7906f9fb6e8  synapse-channel-v0.99.16-sbom.cdx.json