Skip to content

Releases: axonel/sentinel

Axonel v0.1.1

Choose a tag to compare

@roonakyadav roonakyadav released this 19 Sep 18:45

Axonel v0.1.1 — Audit Remediation & Safety Invariant Hardening Release

Overview

Axonel v0.1.1 is a corrective patch release addressing all 10 findings identified during the external audit of the v0.1.0 release. This release hardens core safety invariants, enforces isolated worktrees across all agent roles, eliminates concurrency test flakes, updates the Minimum Supported Rust Version (MSRV), and provides actionable diagnostics for external provider failures.


Key Improvements & Remediations

1. Main-Branch & Integration Safety

  • Direct Commit Prohibition: Removed the premature auto-merging Integrator role. Direct agent commits to the target main branch are strictly prohibited.
  • Transactional Integration Gate: Changes reach main strictly through transactional Git integration (POST /api/v1/missions/{id}/integrate) following explicit human review and acceptance (AwaitingAcceptance $\to$ Accepted).
  • Target Tree Hygiene: Integration strictly enforces status.is_clean and rejects dirty or stale target branches with HTTP 409 Conflict.

2. Isolated Worktree Enforcement & Staging Hygiene

  • Strict Worktree Isolation: All agent tasks execute exclusively within isolated Git worktrees (.plexis/worktrees/<task_id>), leaving the operator's active working tree and current branch completely untouched.
  • Untracked File Hygiene: Standardized agent Git staging with git add -A followed immediately by unstage rules (git reset -q --) for Cargo.lock, target/, SQLite databases (*.db*, plexis.db*, axonel.db*), environment files (*.env*), and sensitive credential/secret files.
  • Agent Author Identity: Configured author identity for agent commits as Axonel Agent <agent@axonel.local>.

3. Actionable Provider Failure Diagnostics

  • Immediate Escalation to NeedsHuman: Missing external agent CLI binaries or unrecoverable provider errors fail fast with clear, actionable diagnostics and immediately transition to NeedsHuman rather than looping into silent stagnation.
  • Process Telemetry: Child process execution logs command arguments, process group IDs, and termination statuses for complete operational auditability.

4. Concurrency Race Fix

  • Deterministic Lease Pairing: Implemented claim_command_by_id(&CommandId) in SQLite store to guarantee exact 1:1 command-to-lease pairing, eliminating multi-agent command lease race conditions under concurrent stress (verified 20/20 consecutive test passes).

5. Clean-Checkout Reproducibility & Toolchain

  • Rust 1.88+ MSRV: Formally established and documented Minimum Supported Rust Version as 1.88.0+ (rust-version = "1.88" in root Cargo.toml) for Rust 2024 edition compatibility.
  • Canonical Test Command: Documented canonical cargo test --workspace passing 100% across all workspace crates.
  • On-Demand Build Fallback: Multi-agent test harnesses compile plexis-fake-agent on demand if missing from target directories.

6. Google Gemini CLI & Browser E2E Validation

  • Real Gemini CLI Execution: Google Gemini CLI v0.60.0 (gemini_cli) validated with real OS process execution, streaming JSON, multi-turn tool calling, and isolated worktree commits using supported model gemini-3.1-flash-lite.
  • Browser E2E Lifecycle: Playwright Chromium browser E2E test passed 15/15 assertions (web/tests/e2e_release_candidate.mjs), validating the complete flow: workspace registration, mission dispatch, independent verification, human review/acceptance, through to transactional integration and physical disk verification.

Platform & Provider Limitations

  • Certified Platform: Linux x86_64 (x86_64-unknown-linux-gnu). Fully build-tested, quality-gated, and verified in continuous integration. (Linux aarch64 is planned but unverified on hardware).
  • Supported Agent Backend: Google Gemini CLI (gemini_cli) is currently the only external agent backend certified for autonomous execution in this release. Requires local Gemini CLI authentication (gemini auth login or GEMINI_API_KEY).
  • Internal Test Backend: Deterministic local mock agent (fake_agent) for offline testing and CI regression suites.
  • Experimental Scaffold Stubs: Interface stubs for claude_code, codex, and opencode are registered for post-v1 expansion but are not supported for live autonomous coding missions in v0.1.1.

Axonel v0.1.0

Choose a tag to compare

@roonakyadav roonakyadav released this 19 Sep 10:51

Axonel v0.1.0 — First Public Release

Axonel is a local-first autonomous engineering supervisor daemon designed to supervise external CLI coding agents (such as Google Gemini CLI) in isolated Git worktrees with out-of-band test verification and explicit human acceptance gates.

This is the first public release of Axonel (v0.1.0).


Key Capabilities & Guarantees

  • Isolated Git Worktree Execution: Executes tasks in dedicated Git worktrees (.plexis/worktrees/<task_id>), guaranteeing that your active workspace and branch remain untouched during background execution.
  • Independent Physical Verification: Rejects LLM self-reports of success. Axonel executes actual test toolchains (cargo test, npm test, pytest) out-of-band directly on the filesystem and requires a clean Git tree (working_tree_clean == true) and real Git commit before considering any deliverable.
  • Explicit Human Acceptance Gate: Autonomous execution strictly halts at AwaitingAcceptance. Direct unaccepted integration attempts return HTTP 409 Conflict. Code cannot reach your target branch without explicit human review and acceptance.
  • Structured Review Packages: Inspect complete deliverables via GET /api/v1/missions/{id}/review and the Web UI, including unified git diffs, changed files lists, verification logs, and HEAD freshness indicators.
  • Transactional Git Integration & Crash Recovery: Atomic Git merge execution with automatic rollback on merge conflict (git merge --abort). Startup reconciler uses Git ancestry (git merge-base --is-ancestor) to durably recover from abrupt SIGKILL or crashes without false reporting.
  • Autonomous Multi-Cycle Replanning: Automatically detects stagnation, failed tests, and compilation errors, driving bounded recovery attempts with structured error feedback.

Certified Platform & Proven Agent Integrations

  • Certified Supported Platform: Linux x86_64 (x86_64-unknown-linux-gnu). Build-tested, quality-gated, and verified in continuous integration.
  • Proven External Agent Backend: Google Gemini CLI v0.60.0 (gemini_cli). This is the only external agent integration currently proven end-to-end for production coding missions in v0.1.0. (Requires local authentication via gemini auth login or GEMINI_API_KEY).
  • Internal Test Provider: Deterministic local mock agent (fake_agent) used for automated regression test suites and CI.
  • Scaffold Stubs: Anthropic Claude Code (claude_code), OpenAI Codex (codex), and OpenCode (opencode) are registered interface stubs under development and are not certified for production execution in v0.1.0.

Security Model Defaults

  • Strict Loopback Default: The server binds strictly to 127.0.0.1:3000 by default.
  • Mandatory Authentication for External Binds: Binding to 0.0.0.0 or external network interfaces requires --auth-token or AXONEL_AUTH_TOKEN; startup fails immediately with exit code 1 if unauthenticated.
  • Automated Secret Redaction: Automated in-memory regex sanitization scrubs Bearer tokens, OpenAI/Anthropic API keys (sk-...), Google API keys (AIza...), and GitHub access tokens (ghp_...) from terminal buffers, logs, and events.
  • Path Confinement: Rejects directory traversal (..) attempts outside registered workspace boundaries.

Known Operational Boundaries & Limitations

As documented in docs/V1_LIMITATIONS.md:

  • Single-Repository Scope: Confined to single Git repositories; multi-repository coordination is not supported in v0.1.0.
  • Hardware Architecture Scope: Certified strictly on Linux x86_64. Linux aarch64 is architecturally supported but unverified on physical hardware. macOS is experimental; Windows is unsupported due to POSIX process-group containment requirements (setpgid/killpg).
  • Disk Footprint for Worktrees: Each concurrent mission provisions a separate Git worktree. Repositories with large untracked build artifacts (target/, node_modules/) require sufficient disk space.
  • No Automatic Merge Conflict Resolution: If target branch HEAD moves concurrently and causes a merge conflict, Axonel rolls back cleanly and returns HTTP 409 Conflict. Manual resolution is required.
  • No Distributed Execution: Axonel v0.1.0 operates as a single-node workstation daemon; cluster or distributed execution is out of scope.
  • Test Suite Ground Truth: Verification guarantees that your configured test commands ran and passed on disk; it does not prove correctness beyond the test suite's coverage.

Installation & First Run

From source on Linux x86_64:

# Clone the repository
git clone https://github.com/axonel/axonel.git
cd axonel

# Build the Web Dashboard SPA
cd web && npm ci && npm run build && cd ..

# Compile the release binary
cargo build --release -p plexis-server --bin axonel

# Start the Axonel supervisor daemon on loopback
./target/release/axonel server --host 127.0.0.1 --port 3000

Access the Web Dashboard at: http://127.0.0.1:3000