A large release — 146 changes. This page is the short version: what breaks, and what is new. Every entry is in the CHANGELOG linked at the bottom.
Breaking changes at a glance
Everything here is a 0.x minor break, stated in full further down.
OKF4net (library)
IOkfClock.Nowis the required member andTodayderives from it. A
Today-only clock written against 0.5.0 no longer compiles.Lifecycle.StaleAfteris aDateTimeOffset?, andLifecycle.IsStale/
StalePolicy.Admitstake aDateTimeOffset. TheDateOnlyoverloads are
gone; render a date with the newLifecycle.StaleAfterDate.Sourcegained a seventh member, so positional deconstruction and
pattern-matching on it break at source level.Bundle.ReadResourceTextthrowsUnauthorizedAccessExceptionfor a path
outside the bundle root or one reached through a reparse point. It used to
read any path it was given.- The frontmatter fence is
---at column 0 (§4); an indented one no longer
closes the block. YAML anchors, aliases, tags, directives and document
markers are now rejected with a clear error, as the docs already claimed. - A bare
attester.resource/computationpath resolves from the bundle
root, not beside the concept (§6.2), andFrontmatterResourceKind.Relative
is renamedConceptRelative. A 0.5.0 bundle whose attester sits next to its
concept stops running —okf validatenow says where the file was found and
what to write. OkfCli.Runtakes aTextReader stdinparameter.
OKF4net.Attestation
- A declared but unresolvable
attester.resourceends the run with a
non-displayable outcome, and nothing executes.AttestationContexttakes a
sixth positional parameter.
OKF4net.Agents
RunComputationis[Obsolete]for one version; useRunComputationAsync.ComputationTimeoutcaps one run at two minutes by default;
Timeout.InfiniteTimeSpanrestores 0.5.0's unbounded wait.
okf-mcp
- A bundle is served read-only by default. Set
OKF_MCP_WRITABLE=1to
register the four write tools.
OKF4net.Attestation.Containers (unpublished)
- Containers run as uid 65534, with every capability dropped and
no-new-privileges. Isolation settings moved onto one shared
ContainerIsolationrecord. - Receipts and verdicts with duplicate JSON properties, or numbers that cannot
be represented exactly, now fail the stage instead of being silently resolved.
okfgen (producer, not published)
generatespawnsdotnet msbuildin the scanned tree, which executes that
repository's build logic. Only point it at a repository you would build.
--no-msbuildopts out.--updateprunes concepts under thecodeprefix that a complete run no
longer produces.
What is new
- §10 attested computation against real containers
(OKF4net.Attestation.Containers): a bundle's actual sanctioned script or
SQL, and its actual attester, run in Docker/Podman/nerdctl — never a C#
reimplementation. okf audit, a corpus-level query over a bundle's trust, lifecycle and
provenance, andokf verify, which records a dated §5.2 verification.okf-render, the static-site generator split out ofokfso the CI
validator stops carrying the viewer's JavaScript.- A C# code graph in
okfgen: one concept per namespace, type and member,
with resolved## Callslinks, plus--check,--roslyn-timeout,
--repo-url/--revand scope flags. - Diversified search (
ConceptSearch.TopDiversified), so one dominant
concept family stops crowding out the rest of a corpus. - A hardened agent surface: read-only-by-default MCP, tool modes, a
cancellable computation tool with a timeout, and neutralised model-facing
output.
The full list of changes (146 entries) is in the CHANGELOG.
dotnet add package OKF4net --version 0.6.0
dotnet tool install -g OKF4net.Mcp --version 0.6.0 # okf-mcpThe okf and okf-render binaries for Windows, Linux and macOS are attached below.