Repository navigation
v0.2.1
v0.2.1 gives durable Cayu sessions an explicit execution identity and hardens
the boundaries that carry model, tool, workspace, knowledge, and MCP work across
retries, restarts, and operator-directed changes.
Highlights
- Sessions persist a versioned execution profile covering their model target,
provider configuration, tools, approval policy, environment, context policy,
and other execution-critical inputs. Ordinary resume fails closed on drift;
applications can explicitly inspect and authorize a compatible profile
adoption at a safe boundary. - Model targets can change through an atomic durable transition rather than
mutating live agent configuration. The selected provider and model remain
attributable through pending work, recovery, forked sessions, and restart. - Every new session records immutable root-invocation provenance. Derived
sessions preserve the same root while recording their immediate execution
source, and the protected server derives authenticated provenance instead of
accepting client-authored identity claims. - Stdio and Streamable HTTP MCP transports now enforce validated per-message,
aggregate-response, idle-timeout, and absolute-deadline limits. Ambiguous
timeout, cancellation, and peer-failure paths fence or terminate uncertain
shared sessions before reuse. - Model-authored knowledge publication is operation-owned and receipt-backed
across the built-in stores. Acknowledgement loss reconciles against immutable
evidence instead of compensating by deleting a shared deterministic entry. - Active
SyncBindinggenerations reserve both source and target workspace
identities before provisioning, copy, and sync-back work. Bounded workspace
reads, runner listings, attachment limits, S3 deletion, provider cleanup,
reasoning-state replay, child-session identity, virtual-egress authority, and
internal event namespaces also fail closed at their public boundaries. cayu cloudvalidates application slugs, distinguishes local and production
contexts, reports bounded deployment diagnostics, and waits for Agent service
health before declaring a deployment ready.
Upgrade from v0.2.0
Python 3.11 or newer is required. Stop all v0.2.0 workers and take an
application-consistent backup of every configured SQLite or PostgreSQL store
before upgrading. Do not run mixed v0.2.0 and v0.2.1 processes against the
same stores.
The storage schema advances from revision 34 to revision 36. Revision 35 adds
operation-owned knowledge-publication receipts and is a mixed-writer boundary.
Revision 36 requires immutable invocation provenance on every session. Because
existing populated v0.2.0 session stores never recorded that provenance, Cayu
cannot truthfully infer it: archive any evidence that must be retained, then
recreate each database containing session rows. Do not edit the database or
fabricate invocation identities to bypass this guard. Empty databases and
databases without session rows migrate normally. Run cayu storage status and
cayu storage migrate against every explicitly configured session store,
budget ledger, eval store, task store, and knowledge store, then confirm
revision 36 with no pending migrations before starting v0.2.1 workers.
The server contract advances from version 9 to version 10. Upgrade independently
deployed servers, packaged dashboards, and generated clients together. Portable
trajectory documents advance from schema version 2 to version 3; regenerate
version-2 exports from their authoritative source rather than assigning invented
invocation provenance during loading.
Verification
Install cayu==0.2.1 in a clean environment and verify cayu version,
cayu cloud --help, and cayu check --json. Use fresh stores for a
current-contract smoke test, then exercise a durable session through restart,
an explicit model or execution-profile transition, durable knowledge
publication, one bounded MCP call, and the packaged /cayu/ dashboard.