Repository navigation
bide v0.7.0
Proofs you can hand out, providers you can switch between.
v0.7.0 deepens the audit trail and broadens where bide runs. A proof now reveals only what it proves, every provider adapter speaks its API exactly, and the journal returns byte for byte what it recorded, on every store and across every process.
- Private, precise proofs. Every journal record and event carries its own salt, so a proof bundle discloses the record it proves and nothing about its neighbours. Signed tree heads commit to their tree's kind and run, evidence packages are sealed and checked field by field, and delegated grants attenuate strictly (issuer, expiry, and every scope key).
- Earned authority with a current-grant ledger.
VerifyCurrentGrantconfirms a grant is the latest one issued, against a ledger head the verifier has seen, so a demotion takes effect everywhere. - Exact replay. A resumed run sends the model the same bytes the live run did, on MemStore, SQLite, and Postgres alike.
agent/durabletestchecks any store against this contract. - Provider adapters, refined. Requests match each provider's API: grouped Gemini tool results and schemas, Gemini thought signatures and Anthropic redacted thinking carried round-trip, unique tool-call ids on every turn, and
max_completion_tokensfor OpenAI reasoning models. Quota exhaustion is reported asErrQuotaExhaustedrather than retried, and a turn ends only on the provider's own end-of-turn signal. - Durable governance at scale. Governed event logs append idempotently across Redis, SQLite, and Postgres, migrate safely under concurrent opens, and work on Redis Cluster. Each quorum has its own name, and a tie is never agreement.
- Sagas and sub-agents. Rollback reaches every call a saga started, including ones cut off mid-flight and those inside sub-agents. A pause inside a sub-agent names the root run to continue, a pause in one parallel tool lets its siblings finish, and
Recoverknows a finished rollback is done. - Sessions and flows. Sessions stay consistent across several workers, with each turn tied to its message.
planrejects graph shapes it cannot run as declared, and a run always resumes under the flow it started with. - Privacy by default. Traces and
ToolLogrecord an error's category unless content capture is on, URL credentials are redacted from tool errors before they are journaled (WithToolErrorRedactorscrubs more), and signers and adapters never print their keys. - Verification you can re-run. Fuzz targets for every parser and verifier run in CI alongside
govulncheck, a Benchmark workflow reproduces the published numbers on a standard runner, and How bide is verified describes the discipline behind each guarantee.
API changes:
- Audit formats move to
bide.audit.sth.v4with versioned, salted leaves; re-anchor heads made with earlier versions.RecordgainsSalt, andEventLog.ProvereturnsEventInclusion. VerifyRun,VerifyDelegationChain,SignAbsenceRoot, the absence proofs,EvidencePackage(Seal,WithConsistencyFrom), and earned authority (ProveCurrentGrant,VerifyCurrentGrant) have new signatures.govern.EventLog.Appendtakes an append id,govern.Quorumtakes a name, andbide-audit verify-quorumtakes-name.agent.MemWaker.Startreturns a channel that closes when it stops, and a model turn with a missing or reused tool-call id is an error.- Postgres keeps its journal in the
bide_stepstable.
Install:
go get github.com/bide-ai/bide@v0.7.0
Docs: https://bide-ai.com