0.5.2 — 2026-08-17
Release Notes
Durable stores survive toolchain upgrades. Consuming 0.5.1 from GaugeDesk
surfaced that the replayed-open guard stranded every pre-existing instance
after a compiler-evolving upgrade: the recorded ir_hash could never match
what the new toolchain derives for the identical authored program.
Fixed
- A replayed instance open re-attests the IR under the current compiler
when the authored identity (source_hash) matches and only the compiled
identity (ir_hash) differs. The current compile is registered as a program
version, the instance is re-pointed, andinstance.program.reattestedis
appended naming both IRs — an auditable event, never a silent acceptance.
A differingsource_hashstays refused: different authored content under a
replayed request is the integrity breach the guard exists for
(spec/agent-harness.md"Program identity across toolchains").
Added
RuntimeStore::reattest_instance_program, implemented for the native
SqliteStoreand the durable-objectDoSqliteStore.
Install whipplescript 0.5.2
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/GaugeWright/whipplescript/releases/download/v0.5.2/whipplescript-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/GaugeWright/whipplescript/releases/download/v0.5.2/whipplescript-installer.ps1 | iex"Install prebuilt binaries via Homebrew
brew install GaugeWright/tap/whipplescriptDownload whipplescript 0.5.2
| File | Platform | Checksum |
|---|---|---|
| whipplescript-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| whipplescript-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| whipplescript-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| whipplescript-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| whipplescript-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |