v0.108.0 #840
v0.108.0
#840
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What
The access layer arrives; the check stops trusting what it cannot
read. Three steps of the access ratification land (
accesspicks thepath,
model:picks the intelligence — resolver, pin, and the ACPharness class with its mock instrument), and the zero-authority scan now
refuses every
execspelling — the shell form included. Provenred-first, like everything on this train.
Added
Execution access · step 3 — the ACP harness class (D-2026-08-04-N1
· P3). The
nika-acpspec crate lands (ACP 2.0.0 = wire v1, verifiedagainst the published schema) with its mock agent in a quarantined
workspace — the instrument that proves the wire without a vendor in
the loop — and the kernel gains the
AgentBackendseam(
nika-kernel-ai· lane-agnostic): the harness access path plugs inwhere every other lane already does, behind a trait, never a special
case.
Execution access · step 2 — the deterministic resolver, the pin,
the narration (D-2026-08-04-N1 · steps P2.1–P2.8).
model:picksthe intelligence; access picks the path. The admission-time
resolver is a pure function with a strict sovereign order (
local < mock < harness < oauth < api, codepoint tie-break) — enumerationorder can never change the outcome (property-tested), and every drop
carries its witness (dimension · layer · teaching line).
--access <path>onrunandtrypins the path: judged at the launch gatesbefore the prologue (zero events · zero spend); unsatisfied refuses
with
NIKA-1800/1801/1802, never substitutes. Without a pin the RUNpath is byte-unchanged — the gate never fires; the audit surfaces do
grow (additive, the
models_catalog_warningsprecedent):check --jsongains the advisoryaccess_planrows,explaingains the « access (this machine) » section, the run header
announces an explicit pin, and
AccessPlanrecords the chosenpath's id. Run-start liveness stays the only runtime act: a dead
pinned path refuses, never falls back.
Fixed
the models rung pushed each
models_catalog_warningsrow two times;one block remains, with a test that proved red against the doubled
version first.
no longer teaches doors that refuse;
--recipe startersays whichhalf a pipe cannot deliver; the taught next step works on the machine
that just ran it;
explain's two golden-lane refusals teach insteadof misdirecting; the check strictness hint says close, not add.
exclusively — never adopts one — and the shared host tmp stops being
an ambient grant; exec-runner's scratch moved out of egress at the
file wall.
a silent seat swap refuses.
call. It asks about the call now.
the tails.
Changed
claude-sonnet-4-6. The catalog sattwo generations back (
claude-sonnet-4-20250514) while the spec'sexamples and conformance fixtures standardized on the 4.6 id — the
docs-spec coherence vector named the contradiction on the public site.
Six sites across the anthropic · openrouter (
anthropic/…) · bedrock(
anthropic.…-v1:0) entries follow each gateway's naming form. Parserand bench test strings keep the historical id on purpose (they are
inputs, not defaults).
Security
exec:with nopermits:block passednika checkgreen. The zero-authority scan (F-O8 · NEP-0003) refused the argv
spelling it can read (
command: ["rm", …]→NIKA-AUTH-006) anddeferred the shell spelling it cannot (
shell: "rm -rf …") to theruntime — the exact inversion of a security gate: the verifiable door
refused, the unverifiable one open. Law 1 puts the exec capability in
Requiredthe moment an exec task sits in the body, whatever thecommand form; law 3's runtime deferral owns dynamic VALUES, never the
category question, and the runtime refused both spellings all along.
The shell form and a computed argv head now refuse at check with
NIKA-AUTH-006— check ≡ run restored. Repair:nika check --infer-permitswrites the block (the shell form widensexectotruewith a note; rewrite to the array form for a programallowlist).
Install
Tarballs below: macOS arm64 / x64 · Linux x64 / arm64, plus
SHA256SUMS.Verify: three independent proofs
Provenance
Built from tag
v0.108.0byrelease.ymlon GitHub-hosted runners. Provenance is published twice: GitHub's native
build attestation (proof 2) and the SLSA generator's
multiple.intoto.jsonlrelease asset (proof 3). The release itself is a claim on the
machine-verified timeline: https://nika.sh/timeline
What's Changed
Full Changelog: v0.107.2...v0.108.0
This discussion was created from the release v0.108.0.
All reactions