Session Kit v0.3.0
Pre-release
Pre-release
Session Kit v0.3.0 — public beta.
Highlights, from the changelog:
Fixed
- A stock Ubuntu machine installs: the group-writable provider-home refusal now accepts a provably single-member private group, refusals name the exact chmod, and
install.sh --checkcatches the condition before anything is written. Verified on clean and upgrade installs in VM proofs, with negative controls. - A delegated worker now receives its assignment (
commissionedduty delivery with on-disk receipts), and an undelivered intake notice is retried with backoff instead of abandoned. - The supervisor's MCP definition survives release activations.
shpool attachkeeps the shell's exit status (upstream race fixed in patch 0005; heartbeat ack hardened).
Added
- Projects as first-class: one canonical root identity, a committed
session-kit.tomlwith a strict single-implementation reader, trust-gated launch fields, and digest-pinned startup approval (surfaced, never executed). - Worktree isolation and run receipts for delegated work, with caps, verifier evidence, and tamper-detecting integrity digests.
- Quota-aware account selection from three evidence-labelled readers.
- Picker: peek-and-reply, live filter, jump-to-attention, grouping, compact rows, unified key help, and an opt-in attention notifier.
- Every command answers
--helpbefore requiring shpool; bash tab completion ships and installs with the release. tools/install-matrixproves the documented install on four distros; the public CI is fully self-contained.
Security
- Source authority verifies Codex sessions end to end, refuses harness machine text by stem, screens machine-originated wakes at capture, and reports an additive authority tier ladder via
session-kit doctor --authority— all observation, nothing gated.
Verification chain: see the attached .sha256, .provenance.json, and .chain.json. Source commit a4d58002f26cd018040897e8c047345187feba88.