Repository navigation
v0.3.3
Immutable
release. Only release title and notes can be modified.
v0.3.3: Exact Retry, Durable Interruption Markers, and Trust Coverage for Instructions
This release closes a set of Phase 0 gaps: exact turn retry now works end to end, interrupted turns leave a durable trace, AGENTS.md instruction sources are brought under workspace trust, credential redaction is broader, and a Windows cold-start Dolt activation bug is fixed alongside bounded Unix shell cleanup.
Added
kuru run --turn-id IDand the terminal/retrycommand let you safely retry the last local submission (#28, @replygirl). A completed turn is replayed from the durable journal with no new provider or tool call; a turn that may have dispatched external work refuses replay instead of duplicating it.kuru --resume SESSION_ID run "Continue from our last turn." --turn-id TURN_ID- Interrupted turns now store a fixed durable marker ("Turn interrupted; no completed answer was committed.") that remains visible after later turns and resume, while staying out of provider context (#28).
- JSON turn output adds
limit_reasons(tool-calls,peer-rounds,legacy-unspecified) andresponse_outcome(includingempty), replacing the old genericlimitedflag for diagnosis (#28). The TUI surfaces these as distinct labels instead of one generic "limited result" marker. --debugnow prints one JSON line naming the resolved per-project diagnostics ring directory on stderr, without changing command output (#28).- Workspace trust now reviews every ordered ancestor
AGENTS.mdsource, including the project root, before its bytes reach a prompt;trust statuslists the reviewed sources without printing their contents (#27).
Fixed
- A Windows cold-start activation failure is fixed: first-time Dolt provisioning now copies the fully verified engine to a private probe sibling, re-verifies it, and executes only that copy, instead of denying the checked move (#27).
- Warm Dolt cache opens now verify concurrently instead of serializing behind the install lock; the lock is reserved for missing-cache extraction and publication (#27).
- The private data-directory
0700remedy now applies to any rejected, real, current-user-owned unsafe directory, not only when legacy SQLite is present, and is never offered for a symlink or foreign-owned path (#27). - Retained Unix shell cleanup is now bounded process-wide (a fixed admission cap) with capped exponential backoff for unconfirmed observations, instead of growing unbounded worker/process ownership (#27).
- Unix and Windows shell failures now report the same fixed operational categories with bounded, redacted stderr, distinguishing a pending (incomplete) EOF from returned bytes; ordinary nonzero exits still return full structured output (#28).
- Automatic speaker selection now breaks activation ties using the framework's authored part order rather than raw ID order (#28).
Changed
- Credential redaction now also recognizes Slack and GitLab tokens, JWT-shaped values, URL userinfo credentials, and bare
token/secretfield names, in addition to existing OpenAI, GitHub, AWS, and PEM forms (#27). - The turn journal is documented as durable, no-expiry safety/idempotency history, separate from the bounded operational diagnostics ring (#28).
Full Changelog: https://github.com/replygirl/kuru/commits/v0.3.3