Repository navigation
v3.35.0
Guard 3.35.0 is a stable release cut from 7202f09.
11 commits • 10 merged pull requests • 2 contributors since Guard 3.34.1.
Features
- guard: Prove Wrangler version, help and whoami reads benign (#3774)
- one of
--version,-v,--help,-h,whoami - one to three lowercase subcommand words followed by
--helpor-h(for examplewrangler d1 execute --help)
- one of
- gauntlet: Run the native Luna route at medium effort by default (#3767)
- The runner gives the adapter its effort through the adapter's private environment. The adapter uses that effort as the Oh My Pi thinking level, rejects any request with a different
reasoning_effort, and reports the… - Only
mediumandhighare accepted on this route. Any other value is rejected before anything starts. - Evidence records the effort in the provider identity:
openai-codex/gpt-5.6-luna/<effort> via pinned-omp-native-luna-stream-v2. The loopback request model name is nownative-luna.
- The runner gives the adapter its effort through the adapter's private environment. The adapter uses that effort as the Oh My Pi thinking level, rejects any request with a different
- gauntlet: Run catalog cases in parallel with --jobs (#3765)
--jobs 1keeps the existing in-process sequential path unchanged.- With
--jobsabove 1, each case runsrun_casein its own worker process. That process has a private Guard home, daemon and native resident, fixtures, loopback relay and collector, OMP process group, and evidence… summary.json,summary.mdand the hook-latency aggregate are built in catalog order whatever order the cases finish in.verifyandpackare unchanged. The only new summary field is an informationaljobs, and…
Fixes
- guard: Contain test runs wrapped in a workspace cd or output filter (#3775)
- a leading
cd <absolute dir inside the workspace> && - a single trailing
| tail -Nor| head -N(or-n N), with an optional2>&1on the producer bunx --cwd <relative dir inside the workspace>for vitest
- a leading
- guard: Stop asking approval for bounded waits and read-only probes (#3773)
- Waits:
sleepwas capped at 60 seconds, so loops likesleep 240 && echo doneneeded approval. Literal waits up to one hour are now proven inert. The total across chained sleeps is capped at one hour, with at… - Read-only probes:
uptime,pgrepwith listing and matching flags (-f -l -a -i -x -n -o -c) plus one pattern,node --version/-v,python3 --version/-V, andgit worktree list [--porcelain]are now…
- Waits:
- windows: Restore the native build and parallel Gauntlet workers (#3771)
-
hol-guard-runtimeno longer compiles for Windows.** The new resident diagnostics sink (#3701) passes its openFiletois_single_link_file, which takes a&Path:
-
- ci: Reuse native source compiler for shard wheel builds (#3701)
- gauntlet: Run the native Luna route on Windows (#3759)
Performance
- release: Compile in parallel and start Desktop signing sooner (
87a5329)
Tests
- gauntlet: Prove the deletion floor holds under an installed business policy (#3766)
Internal
- release: 3.35.0 (#3768)
Install
Install this release:
uv tool install "hol-guard[cisco]==3.35.0"Full changelog: v3.34.1...v3.35.0
Thanks @zerocodefast, ZCF!
Package publication and Desktop update availability are separate. Desktop updates are ready when the signed Core assets and update manifests appear below; macOS feed status shows signing and verification progress.