v0.8.6
Guard 0.8.6 reports launch failures for approved commands as execution errors, with the observed failure stage when available and explicit start-state evidence. Genuine policy denials remain distinct.
Working-directory access uses the intended child identity, supplementary groups and capabilities. Child ownership extends through runtime registration and cleanup so an error after process creation retains accurate lifecycle reporting. Approval, rollback, audit and session history preserve execution outcomes, including unknown start state when evidence is unavailable.
The state database uses schema 15. Upgrade the daemon and all clients together. An older binary refuses the migrated database; rollback requires the matching pre-upgrade binary and consistent snapshot. Follow the upgrade and rollback contract.