Kranz 0.4.2 tightens approval authority and the evidence used to accept agent changes.
- Sgian credentials require an explicit trusted helper path and are unavailable to enforced workers. Existing Sgian users should review the updated setup guide.
- Approval screens display control characters visibly and refuse ambiguous requests. ACP deny rules cover argument arrays, all supplied paths and normalized traversal.
- External gates require committed, covered candidate source. Changed private or detected-secret inputs block acceptance, while ordinary web-framework and Unicode filenames are supported.
- Long ACP runs persist progress without waiting for a permission request; unanswered permissions prevent completion. Mount proofs are fresh, container starts use owned IDs, and evidence export verifies original bytes before redaction.
- Hosted missions heap-pin the feature execution future to prevent worker-thread stack overflow, with a bounded-stack lifecycle regression.
- The new kranz-acp library shares bounded ACP framing and session protocol. Released worker profiles continue to keep filesystem, terminal and resume capabilities disabled.
Container crash recovery/credential renewal and resource-budget qualification are scheduled before Sgian terminal rollout. This release does not add a provider qualification claim.
See the changelog and remediation review for the detailed changes and review dispositions. Verification completed on c95a6f833a01a4a077aa5d207fc43b7125a4788c:
- Remediation PR #91, main CI and main security checks passed. The tagged Linux suite passed 3,111 tests, with 0 failures and 9 ignored. The local workspace suite covering the production fixes passed 3,145 tests, with 0 failures and 10 ignored; final fixture corrections passed separately and in exact-source CI. The dashboard passed 264 tests. Changed ACP containment proofs use positive execution and owned-cleanup checks.
- Release rehearsal and its five native archive checks passed before tagging.
- Tagged builds and their five native archive checks passed on Linux x86-64, macOS Intel/Apple Silicon and Windows x86-64/ARM64. Published bytes match the tested artifacts; archive, checksum-manifest and SBOM attestations were verified.
- All five crates were dry-run, inspected and published in dependency order with matching versions, source commit and checksums. An isolated crates.io install on Apple Silicon verified version, help and licenses outside a checkout. The archive served its embedded dashboard and matching notices.
The first rehearsal stopped before packaging because two required container tests could not complete their bounded Docker availability probes. That failed attempt is retained; the same source and unchanged gates passed a fresh-runner retry before tagging. The root cause of that initial probe failure is not established.
Main CodeQL completed successfully; its existing alert inventory is not empty. Source triage classified 33 older findings as Windows API/test/workflow false positives and confirmed one issue in the manually started development mock server's configuration merge. That mock is excluded from released binaries and crates; its hardening remains tracked by CodeQL alert #2. Alert states and scanner rules were not changed. This triage was a self-review, not an independent security audit.
The original review's findings, fixes, scoped limits and self-review are in the remediation report. One unchanged local negative container subprobe remains inconclusive as denied-access evidence; a follow-up ticket requires explicit execution and denial receipts. No live provider calls or Keychain access were used for this release.