Releases
v0.227.0
Compare
Sorry, something went wrong.
No results found
[0.227.0] - 2026-08-16
Features
(engine) Make the user locus rung reachable, and shield what that exposes
(regions) Declare the credential dotfiles, then let home dotfiles be ordinary
(regions) Shield /etc/ssh, where the host private keys live
(regions) Classify raw devices and per-process /proc as what they are
(engine) Open local reads to the machine rung
(regions) Shield the decision log; correct the docs for the new read policy; v0.227.0
Bug Fixes
(engine) Check unpinnability BEFORE the sentinel is rewritten away
(engine) Correct the dotfile claim, and guard the sentinel fix that was untested
(engine) Close the last four ways an unknowable read reached the shield uncleared
(regions) Ten more credential dotfiles, and the measurement that questions the approach
(engine) Bind find/fd -exec through the same stand-in the pipe uses
(engine) Build dd's read from its path, so the shield is asked
(engine) Fold macOS firmlinks, so /private/etc/shadow is /etc/shadow
(engine) An unbounded read cannot be cleared by naming its root
(engine) A glob and a glued placeholder name nothing the shield can check
(engine) Two spellings that walked straight past the shield
(pathgate) An ambiguously glued value is a guess, not a path
(engine) One test for "the shield cannot clear this read", not two
(pathgate) Gate the recursive copiers — rsync, ditto, pax
(engine) Fold case on the firmlink prefix, for shields only
(cli) A raw device is not a login-policy file, and say so
(test) Two assertions that only held on macOS, caught by CI
Documentation
(design) Write up relocation, and the locus a thing came FROM
Testing
(engine) Restate the read invariant as "the shield cannot clear it", not "it is outside the workspace"
(policy) Enforce the path corpus, which named a guard that never existed
You can’t perform that action at this time.