Skip to content

v3.35.0

Choose a tag to compare

@zerocodefast zerocodefast released this 08 Oct 21:06
7202f09

Guard 3.35.0 is a stable release cut from 7202f09.
11 commits • 10 merged pull requests • 2 contributors since Guard 3.34.1.

Features

  • guard: Prove Wrangler version, help and whoami reads benign (#3774)
    • one of --version, -v, --help, -h, whoami
    • one to three lowercase subcommand words followed by --help or -h (for example wrangler d1 execute --help)
  • gauntlet: Run the native Luna route at medium effort by default (#3767)
    • The runner gives the adapter its effort through the adapter's private environment. The adapter uses that effort as the Oh My Pi thinking level, rejects any request with a different reasoning_effort, and reports the…
    • Only medium and high are accepted on this route. Any other value is rejected before anything starts.
    • Evidence records the effort in the provider identity: openai-codex/gpt-5.6-luna/<effort> via pinned-omp-native-luna-stream-v2. The loopback request model name is now native-luna.
  • gauntlet: Run catalog cases in parallel with --jobs (#3765)
    • --jobs 1 keeps the existing in-process sequential path unchanged.
    • With --jobs above 1, each case runs run_case in its own worker process. That process has a private Guard home, daemon and native resident, fixtures, loopback relay and collector, OMP process group, and evidence…
    • summary.json, summary.md and the hook-latency aggregate are built in catalog order whatever order the cases finish in. verify and pack are unchanged. The only new summary field is an informational jobs, and…

Fixes

  • guard: Contain test runs wrapped in a workspace cd or output filter (#3775)
    • a leading cd <absolute dir inside the workspace> &&
    • a single trailing | tail -N or | head -N (or -n N), with an optional 2>&1 on the producer
    • bunx --cwd <relative dir inside the workspace> for vitest
  • guard: Stop asking approval for bounded waits and read-only probes (#3773)
    • Waits: sleep was capped at 60 seconds, so loops like sleep 240 && echo done needed approval. Literal waits up to one hour are now proven inert. The total across chained sleeps is capped at one hour, with at…
    • Read-only probes: uptime, pgrep with listing and matching flags (-f -l -a -i -x -n -o -c) plus one pattern, node --version / -v, python3 --version / -V, and git worktree list [--porcelain] are now…
  • windows: Restore the native build and parallel Gauntlet workers (#3771)
      1. hol-guard-runtime no longer compiles for Windows.** The new resident diagnostics sink (#3701) passes its open File to is_single_link_file, which takes a &Path:
  • ci: Reuse native source compiler for shard wheel builds (#3701)
  • gauntlet: Run the native Luna route on Windows (#3759)

Performance

  • release: Compile in parallel and start Desktop signing sooner (87a5329)

Tests

  • gauntlet: Prove the deletion floor holds under an installed business policy (#3766)

Internal

  • release: 3.35.0 (#3768)

Install

Install this release:

uv tool install "hol-guard[cisco]==3.35.0"

Full changelog: v3.34.1...v3.35.0

Thanks @zerocodefast, ZCF!

Package publication and Desktop update availability are separate. Desktop updates are ready when the signed Core assets and update manifests appear below; macOS feed status shows signing and verification progress.