v0.0.21
v0.0.21 strengthens Ultrafuzz's authenticated strategy and reporting chain while making cloud execution, recovery, and status reporting more resilient.
- Trustworthy strategy outputs. Strategy intake and report rows are now bound to sealed authorities, with clearer search roles and stricter lifecycle reconciliation.
- Safer cloud execution. Modal handoffs preserve committed inputs, lifecycle budgets leave room for setup and collection, and archive and download paths are bounded against stalls.
- More dependable recovery. Pending retries resume from terminal state, status remains useful around control drift, and Bun-backed adapter contracts honor conditional skips.
Improvements
- [runtime] [workflows] Adds a source-fingerprinted responsibility audit for shipped agent adapters, moves DeepSeek reasoning effort to the supported runtime option, and requires the boundary contracts in pull-request CI. Thanks @aviggiano! (#706)
Bug fixes
- [runtime] Lets read-only status reporting surface sealed control-file divergence as warnings while execution and lifecycle paths continue to fail closed. Thanks @aviggiano! (#681)
- [runtime] [cli] Recovers terminal runs with pending retry work, avoids duplicate active-workflow submissions, renews deadlines, and reports durable-state lifecycle divergence. Thanks @aviggiano! (#707)
- [config] [topology] Aligns audit-profile retry budgets across expanded agentic nodes, preserves explicit project and topology overrides, and removes the overlapping
thoroughprofile. Thanks @aviggiano! (#708) - [runtime] Makes conditional runtime tests use Bun-compatible skips and gives generated-adapter contracts stable selection and timeout behavior. Thanks @aviggiano! (#709)
- [modal] Preserves committed paths matched by
.gitignorein cloud handoff baselines while continuing to exclude untracked ignored files. Thanks @aviggiano! (#717) - [prompts] [artifacts] Binds strategy ancestor intake and published report rows to authenticated authorities, clarifies strategy search roles, and closes optional-prerequisite, recovery, archive, and report-lifecycle gaps. Thanks @aviggiano! (#621)
- [config] [modal] Preserves the configured inner agent timeout while reserving 30 minutes for the enclosing cloud lifecycle and rejects budgets beyond Modal's maximum. Thanks @aviggiano! (#723)
- [modal] [security] Bounds archive reads, writes, backpressure, and handle cleanup with a no-progress deadline so safe extraction cannot hang or finish partially. Thanks @aviggiano! (#729)
- [modal] Drains Modal result downloads concurrently with remote completion, preventing pipe backpressure deadlocks while preserving atomic publication and failure cleanup. Thanks @aviggiano! (#739)
Full changelog: v0.0.20...v0.0.21