Repository navigation
v0.10.0
Cayu adds provider-backed completion verification and independent completion
evaluations, improves crash recovery, and supports explicit Cloud storage
migration acknowledgements.
-
After recovery closes a tool call that started but never finished, the model now
sees that call's redacted arguments when the round resolved no invocation secrets
(no vault or credential proxy) and the tool permits argument publication. The
recovered result for anIDEMPOTENTtool explains that a safe retry must preserve
the same downstream idempotency identity; repeating arguments with a new runtime
idempotency key may duplicate the effect. Before, recovery
always showed the call with empty, unavailable arguments, so models reworded the
retry and applications that guard a write by its exact request body refused it.
Rounds that could resolve secrets and tools with private arguments keep their
arguments hidden. -
Continuation now recovers a session whose process died during a model call.
Whenrun,resumeor another continuation takes over an abandoned execution
and finds an ordinary dispatched assistant model call with no durable response,
it records the call's outcome as unknown, charges its budget reservations in
full, interrupts that interaction and continues the conversation. Before, this
raisedModelCompletionManualRecoveryRequireduntil the application called
recover_model_completion_stage(...). Resumable provider operations, context
compaction, auxiliary inference and contracted tasks keep their existing
recovery paths. -
cayu cloud deploy --acknowledge-breaking REVISION(repeatable) acknowledges a
breaking Cayu storage revision for Cayu Cloud's database migration, and
cayu cloud deployment retry RELEASE --application AGENT --acknowledge-breaking REVISIONadds the acknowledgement to an existing release. Values must be whole
numbers from 1 to 1,000,000 (at most 32) and fail locally withinvalid_input
otherwise. Without the flag, deploy requests and their idempotency keys are
unchanged. Rerunningdeploywith the flag for unchanged source adds the
acknowledgement to the release Cloud refused. See
breaking storage revisions. -
cayu cloud deployanddeployment waitreport Cloud's breaking-migration
publication failures (storage_breaking_acknowledgement_required,
storage_newer_than_release,storage_writers_not_stoppedand
storage_migration_state_unknown) aserror.codewith Cloud's message, detail
and hint, plus ready-to-run commands; the acknowledgement refusal includes the
exact--acknowledge-breakingretry.deployment waitno longer reports a
release whose publication failed as ready.cayu cloud rollback --waitwaits for
the service and reports a refused rollback across a storage boundary. -
cayu cloud deploy,deployment waitanddeployment logskeep a Cloud failure
whose phase or diagnostic stage this CLI doesn't know, with its code, message and
hint, instead of falling back to the genericdeployment_failedresult. The phase
and stage are shown as Cloud sent them, orunknownwhen missing, not a lowercase
identifier, or unsafe to print.smoke_testis a known stage for release smoke-test
failures. See the Cayu Cloud CLI guide. -
Provider-backed (model-judge) completion verifiers. Register a
ProviderCompletionVerifierwithCayuApp.register_completion_verifier(...)
for a work contract whose verifier reference has kindprovider. The runtime
calls the model through the registered provider with no tools, records every
provider attempt in a new verifier dispatch ledger before entering the
provider, settles its outcome, usage and latency afterwards, enforces a
per-proposal attempt and token budget across retries and recoveries, and
strictly decodes the response into a contract-complete decision. Provider,
transport, timeout and decoding failures raise typed verifier-execution errors
and never become a rejected candidate. A decoded provider outcome that already
committed is reused after a crash instead of judging again.
CayuApp.list_completion_verifier_dispatches(...)and
summarize_completion_verifier_dispatches(...)report verifier usage and cost
separately from the worker session. See
provider-backed completion verifiers. -
Independent completion evaluations. A work contract can declare an
evaluationpolicy naming an evaluator registered with
CayuApp.register_completion_evaluator(...), such as a benchmark run or test
suite that must not be triggered by the agent being judged. Cayu runs it once
per durable effect identity under the verification claim, persists the run
intent before the effect, reconciles an earlier owner's unfinished run through
CompletionEvaluator.reconcile(...), bounds runs per proposal, and gives the
verifier an immutableCompletionEvaluationReceiptas trusted evidence.
Evaluator failures and timeouts are typed execution failures, never rejected
candidates.CayuApp.list_completion_evaluation_runs(...)reports runs and
evaluator-reported usage separately. See
independent completion evaluations. -
Fix session deletion ordering for completion evaluations and verifier dispatches.
-
Report retained verified-worker ownership when asynchronous shutdown is cancelled.
The server contract remains 48. Upgrade the dashboard with the server.
Storage revision is 117 (previously 115). Revisions 116 and 117 are
additive: they add the cayu_completion_verifier_dispatches and
cayu_completion_evaluation_runs tables. Task stores now require revision 117,
so migrate storage before starting this version; older binaries keep working
against a migrated database.
Cloud-hosted Agents upgrading from v0.8.x
The v0.9.0 storage migration from revision 114 to 115 is breaking. For an Agent on
Cayu Cloud with an existing database, Cloud runs that migration when it publishes
the first release at 0.9.0 or later, and refuses publication until it is
acknowledged. Deploy with cayu cloud deploy --acknowledge-breaking 115. Cloud stops the previous release
during the migration, and 0.8.x releases can't be rolled back to afterwards. A new
Agent with an empty database needs no acknowledgement.