Axonel v0.1.1 — Audit Remediation & Safety Invariant Hardening Release
Overview
Axonel v0.1.1 is a corrective patch release addressing all 10 findings identified during the external audit of the v0.1.0 release. This release hardens core safety invariants, enforces isolated worktrees across all agent roles, eliminates concurrency test flakes, updates the Minimum Supported Rust Version (MSRV), and provides actionable diagnostics for external provider failures.
Key Improvements & Remediations
1. Main-Branch & Integration Safety
-
Direct Commit Prohibition: Removed the premature auto-merging
Integratorrole. Direct agent commits to the targetmainbranch are strictly prohibited. -
Transactional Integration Gate: Changes reach
mainstrictly through transactional Git integration (POST /api/v1/missions/{id}/integrate) following explicit human review and acceptance (AwaitingAcceptance$\to$ Accepted). -
Target Tree Hygiene: Integration strictly enforces
status.is_cleanand rejects dirty or stale target branches with HTTP 409 Conflict.
2. Isolated Worktree Enforcement & Staging Hygiene
- Strict Worktree Isolation: All agent tasks execute exclusively within isolated Git worktrees (
.plexis/worktrees/<task_id>), leaving the operator's active working tree and current branch completely untouched. - Untracked File Hygiene: Standardized agent Git staging with
git add -Afollowed immediately by unstage rules (git reset -q --) forCargo.lock,target/, SQLite databases (*.db*,plexis.db*,axonel.db*), environment files (*.env*), and sensitive credential/secret files. - Agent Author Identity: Configured author identity for agent commits as
Axonel Agent <agent@axonel.local>.
3. Actionable Provider Failure Diagnostics
- Immediate Escalation to NeedsHuman: Missing external agent CLI binaries or unrecoverable provider errors fail fast with clear, actionable diagnostics and immediately transition to
NeedsHumanrather than looping into silent stagnation. - Process Telemetry: Child process execution logs command arguments, process group IDs, and termination statuses for complete operational auditability.
4. Concurrency Race Fix
- Deterministic Lease Pairing: Implemented
claim_command_by_id(&CommandId)in SQLite store to guarantee exact 1:1 command-to-lease pairing, eliminating multi-agent command lease race conditions under concurrent stress (verified 20/20 consecutive test passes).
5. Clean-Checkout Reproducibility & Toolchain
- Rust 1.88+ MSRV: Formally established and documented Minimum Supported Rust Version as 1.88.0+ (
rust-version = "1.88"in rootCargo.toml) for Rust 2024 edition compatibility. - Canonical Test Command: Documented canonical
cargo test --workspacepassing 100% across all workspace crates. - On-Demand Build Fallback: Multi-agent test harnesses compile
plexis-fake-agenton demand if missing from target directories.
6. Google Gemini CLI & Browser E2E Validation
- Real Gemini CLI Execution: Google Gemini CLI v0.60.0 (
gemini_cli) validated with real OS process execution, streaming JSON, multi-turn tool calling, and isolated worktree commits using supported modelgemini-3.1-flash-lite. - Browser E2E Lifecycle: Playwright Chromium browser E2E test passed 15/15 assertions (
web/tests/e2e_release_candidate.mjs), validating the complete flow: workspace registration, mission dispatch, independent verification, human review/acceptance, through to transactional integration and physical disk verification.
Platform & Provider Limitations
- Certified Platform: Linux x86_64 (
x86_64-unknown-linux-gnu). Fully build-tested, quality-gated, and verified in continuous integration. (Linux aarch64 is planned but unverified on hardware). - Supported Agent Backend: Google Gemini CLI (
gemini_cli) is currently the only external agent backend certified for autonomous execution in this release. Requires local Gemini CLI authentication (gemini auth loginorGEMINI_API_KEY). - Internal Test Backend: Deterministic local mock agent (
fake_agent) for offline testing and CI regression suites. - Experimental Scaffold Stubs: Interface stubs for
claude_code,codex, andopencodeare registered for post-v1 expansion but are not supported for live autonomous coding missions in v0.1.1.