Repository navigation
0.19.1
Changes
[0.19.1] - 2026-05-29
Fixed
- Kubernetes injection: handle named target ports in Service resources —
targetPortcan be a string (e.g."http") not only a number. Both
inject::k8s::runandinject::k8s::scenarionow fall back to
IntOrString::Stringwhen the numeric parse fails, instead of panicking on
unwrap().
[0.19.0] - 2026-05-28
Changed
- Agent vector database: replaced Qdrant (external server) with embedded LanceDB
- Removed
qdrant-clientcrate dependency; no Docker or network server needed - LanceDB stores data locally in
.fault/lancedb— tables created implicitly on first write - Sparse vector generation removed from retrieval (LanceDB uses Tantivy for FTS)
- Removed
create_index_if_not_exists()calls from all query pipelines - All batch sizes updated to
usizeliterals to match LanceDB builder API - Custom
OpIdRetrieverstruct insuggestion.rsreplaced withSimilaritySingleEmbedding<String>using LanceDB native filter syntax (operation_id = '{opid}') HybridSearch<Filter>replaced withSimilaritySingleEmbedding<String>across all query pipelines- All Qdrant builder calls replaced with LanceDB equivalents (
.uri(),.table_name())
- Removed
[0.18.0] - 2026-05-28
Added
- Agent: Anthropic/Claude LLM client support —
--llm-client claude(alias:claude,anthropic)- Uses Claude's native Messages API via the
async-anthropiccrate - Reads
ANTHROPIC_API_KEYfrom the environment - Embedding support via local FastEmbed (Anthropic doesn't provide native embeddings)
- Uses Claude's native Messages API via the
[0.17.1] - 2026-02-27
Fixed
- ci: set
aarch64-linux-gnu-gccas linker foraarch64-unknown-linux-gnucross-compilation to fix x86_64/aarch64 ELF incompatibility error
[0.17.0] - 2026-02-27
Added
-
eBPF stealth mode: new
--capture-pidflag to target a specific process by PID,
bypassing the/procname scan — essential when multiple instances of the same
process are running (e.g. multiple opencode sessions) -
eBPF stealth mode: match intercepted processes by TGID instead of thread comm, fixing
capture of multi-threaded runtimes (Bun/Node) where the HTTP thread has a different
comm than the process name (e.g.HTTP Clientvsopencode) -
eBPF stealth mode: skip interception of connections to
127.0.0.0/8(loopback IPC)
to avoid forwarding intra-process connections that would reset -
eBPF stealth mode: treat
ConnectionResetfrom client as a normal teardown (not an
error) — Happy Eyeballs causes the losing IP-family connection to be RST'd by the
client once the winning family completes -
eBPF stealth mode: IPv6 interception support via a new
cg_connect6cgroup program- Extended
ProxyConfigandSocketBPF maps to carry IPv6 addresses - Added dual-listener proxy (separate ports for IPv4/IPv6 to avoid dual-stack bind conflicts)
- BPF redirects IPv6 connections to the machine's global IPv6 address; retrieves the original destination via
getsockopt(SOL_IPV6, IP6T_SO_ORIGINAL_DST) - All aya crates (
aya,aya-log,aya-ebpf,aya-log-ebpf,aya-build) pinned to the same git rev (c42157f0) so the BPF log ring-buffer transport is consistent between kernel and userspace
- Extended
Fixed
- bpf-linker: set
LLVM_PREFIX=/usr/lib/llvm-21when installing to fix "could not find dynamic libLLVM" error - eBPF build: fixed memcpy symbol multiply defined error by aligning aya-ebpf version (using git version to match aya-log-ebpf)
- fault-ebpf-programs: fixed reference error in MAP_SOCKS.get() call
Changed
- Renamed
fault/llm/openai.rstofault/llm/inject.rsand updated types:
OpenAiSettings→LlmSettings,OpenAiInjector→LlmInjector— the
module already handles both OpenAI-compatible and Anthropic/Claude APIs so the
OpenAI-specific naming was misleading - Add proper DNS fault support
Full Changelog: 0.19.0...0.19.1