Skip to content
CAI
Software that uses CAICheck a score

astrid-runtime/astrid

52.1

Adequate · 12 September 2026

331.8k

lines of production code

Rust

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

Astrid is a secure, multi-principal agent runtime that executes isolated WebAssembly capsules and external processes within strict sandbox boundaries. It provides a comprehensive security model featuring per-principal capability tokens, granular approval workflows, and content-addressed storage to enforce isolation and auditability. The system manages the full lifecycle of agent sessions and capsule installations through a robust kernel, CLI, and HTTP gateway, ensuring that all operations are cryptographically verified and traceable.

Features

Add macOS FSKit filesystem extension

Added the AstridFSKit Xcode project for macOS, which builds a hidden background app and an FSKit extension (AstridFSAppEx) to expose Astrid storage as a native macOS filesystem. The extension implements file read/write, directory listing, and metadata operations via a Unix socket RPC client, and requires a signed lease file to mount. This enables mounting Astrid storage on macOS through the standard \astrid storage\ CLI commands.

native · high confidence

Added example to print the OpenAPI specification

A new example script, print-openapi.rs, has been added to the astrid-gateway crate. This utility allows users to generate and print the API's OpenAPI documentation in pretty-printed JSON format to the standard output, facilitating easier inspection or export of the API schema.

crates/astrid-gateway/examples · high confidence

Added sandbox verification probe example

A new example program, sandbox\_probe, has been added to help verify the sandbox policy enforcement. This tool allows users to test how the system responds to different sandbox configurations by reading the ASTRID\_SANDBOX\_POLICY environment variable and reporting whether the sandbox is applied, bypassed, or refused.

crates/astrid-workspace/examples · high confidence

Admin API handlers for agent lifecycle, capability tokens, and distro provenance

The kernel's admin router now includes dedicated handlers for managing agent creation, deletion, and derivation, as well as issuing and revoking capability tokens and controlling distro provenance locks. Agent creation and derivation now support cloning profiles and inheriting capsule state, while deletion properly retires capabilities and reclaims resources. Capability tokens allow operators to pre-grant tool access to principals, and distro provenance handlers enable atomic, hash-verified locking of capsule sets with self-grant capabilities. These changes enhance the admin interface for managing agent lifecycles and access control.

_crates/astrid-kernel/src/kernel\router/admin · high confidence

Astrid CLI Mockup: Standalone TUI Design Prototype with Scripted Demos

The \astrid-cli-mockup\ crate provides a self-contained, zero-runtime-dependency ratatui prototype for designing the Astrid OS terminal interface, decoupled from the live kernel daemon. It features nine navigable views (Operate, Control, Monitor, Utility) and includes ten scripted demo scenarios—such as approval flows, error recovery, and multi-agent operations—that simulate agent streaming, tool execution, and user interactions. The mockup supports interactive mode, auto-playing demos via \--demo\, and non-interactive snapshot testing via \--snapshot\ to validate the UX at the speed of \cargo run\.

crates/astrid-cli-mockup · high confidence

Astrid MCP introduces secure, sandboxed server execution with capability-based authorization

The MCP subsystem now enforces security and isolation for external server processes. Untrusted servers are launched inside OS-level sandboxes (using bwrap on Linux) with configurable network and filesystem restrictions, and binary integrity is verified using BLAKE3 hashes instead of the previous SHA-256. A new \SecureMcpClient\ gates tool invocations on capability tokens and audit logging, while the \McpRegistry\ provides a unified interface that merges global and workspace tool layers. The crate has been renamed from \astralis-mcp\ to \astrid-mcp\, and the underlying \rmcp\ transport has been upgraded to support the MCP 2026 protocol with modern lifecycle negotiation and elicitation handling.

crates/astrid-mcp/src · high confidence

Astrid Runtime 2026.9.0 release and project rebrand

This entry covers the initial commit establishing the Astrid Runtime 2026.9.0 release. It introduces the project's new identity (renaming from Astralis) and adopts a calendar-based versioning scheme (2026.9.0). The release includes a comprehensive changelog detailing new features such as content-addressed durable storage, governed FSKit/FUSE mounts, signed Distro manifests, and native Linux musl targets. It also documents behavioral changes like the migration to per-principal isolation, MCP protocol 2026-07-28 support, and dependency upgrades including Wasmtime 48.0.1, Syn 3, and TOML 1.1. The repository structure is updated with new configuration files (.dockerignore, .gitattributes, rust-toolchain.toml) and documentation (CONTRIBUTING.md, SECURITY.md).

(repo-wide) · high confidence

Audit log now supports per-principal chain splitting and batched appends

The audit log now maintains separate, independently verifiable chains for each principal within a session, rather than a single monolithic log. This change introduces batched append operations that sign multiple entries against a single authoritative snapshot, improving throughput and consistency. It also includes a robust migration path to move legacy audit data into this new native structure, along with comprehensive tests to verify chain integrity and handle edge cases like storage capacity limits.

crates/astrid-audit/src · high confidence

Composite capsule execution engine with secure MCP host process support

The capsule runtime now supports a composite architecture where a single capsule can define multiple execution units, including WASM components and legacy MCP host processes. This change introduces the \McpHostEngine\ to securely spawn and manage external host commands (like \npx\ or \python\) via \SecureMcpClient\, enforcing strict capability checks to prevent command injection and path traversal attacks. It also adds robust lifecycle management for these processes, including automatic teardown and retry logic to ensure clean disconnection. Additionally, the system now resolves capsule environment variables from a host-only control store, supporting onboarding flows for missing secrets and configuration values.

crates/astrid-capsule/src/engine · high confidence

Dual-version process host API with read-only file injection and persistent process registry

The \astrid:process\ host interface now serves both \1.0.0\ and \1.1.0\ contract versions from a single implementation, ensuring backward compatibility with existing SDK-0.7.x capsules while introducing new capabilities in the \1.1.0\ tier. The \1.1.0\ API adds read-only file injection, allowing sandboxed spawns to securely expose host-verified, immutable files to child processes via \env-pointer\ or \fixed-path\ placement modes, complete with BLAKE3 integrity verification and strict size/count limits. Additionally, a persistent process registry has been implemented, enabling capsules to spawn, track, and manage long-lived background processes using ID-based operations like \status\, \read-logs\, \wait\, and \signal\, with all spawn and lifecycle events recorded on the signed audit chain for security observability.

crates/astrid-capsule/src/engine/wasm/host/process · high confidence

Extracted astrid-types crate with typed IPC topics and host-stamped message provenance

The \astrid-types\ crate has been extracted as a standalone, kernel-free library for shared data types, enabling capsule SDK consumption on \wasm32-unknown-unknown\ without pulling in the runtime. This introduces a \Topic\ newtype with typed constructors (e.g., \elicit\_response\, \approval\_request\) to prevent ad-hoc string formatting errors while maintaining wire compatibility. IPC messages now include a \MessageOrigin\ field (\LocalSocket\, \RemoteGateway\, or \System\) stamped by the host at ingress to distinguish local operator requests from remote API calls, defaulting to \System\ (fail-closed) for legacy or unattributed frames. Additionally, \IpcMessage\ deserialization now defaults the \timestamp\ and \signature\ fields when missing to ensure robust handling of legacy peers, and LLM types have been migrated into this crate with added serialization support and safe arithmetic for token usage.

crates/astrid-types/src · high confidence

Introduce astrid-build for capsule compilation and packaging

The new \astrid-build\ crate provides the tooling to compile Rust and legacy MCP/Gemini projects into \.capsule\ archives. It supports building Rust crates to WASM (including \wasm32-unknown-unknown\ and \wasm32-wasip2\), converting legacy \mcp.json\ or \gemini-extension.json\ manifests into \Capsule.toml\, and bundling opaque assets. The build process includes signing archives with the runtime identity, verifying provenance, and injecting WIT schemas for IPC topic resolution.

crates/astrid-build · high confidence

Introduce astrid-emit as an agent-agnostic stdio-to-bus pipe

Added the \astrid-emit\ crate and binary, which provides a generic mechanism for agent hook processes to publish raw stdin data to the kernel event bus. This tool reads from stdin, wraps the content in a fixed six-field JSON envelope (including hook name, payload, correlation ID, principal ID, session ID, and token), and publishes it to a specified topic. It ensures agents always receive a \{"continue":true}\ signal on stdout, while handling publish failures by exiting with code 1 rather than blocking or failing closed, effectively decoupling the transport layer from specific agent protocols.

crates/astrid-emit · high confidence

Introduce capability-based virtual file system with per-principal sandboxing

The VFS layer now enforces strict security boundaries and multi-tenant isolation. A new \IgnoreBoundary\ component enforces \.astridignore\ rules to prevent agents from accessing host secrets or local state. Filesystem operations are mediated through capability handles (\DirHandle\, \FileHandle\) rather than raw paths, and a new \OverlayVfs\ implementation provides copy-on-write isolation backed by temporary directories. Additionally, an \OverlayVfsRegistry\ ensures that each principal gets its own isolated overlay, preventing cross-principal data leakage while maintaining a bounded, LRU-cached registry.

crates/astrid-vfs/src · high confidence

The uplink module in astrid-core now provides a unified type system for components that send or receive messages on behalf of the runtime. This introduces UplinkId for unique identification, UplinkCapabilities to define supported features (such as sending, receiving, rich media, and buttons), and UplinkSource to distinguish between native, WASM, and bridge origins. The module also defines UplinkError for operation-specific failures and UplinkProfile to categorize behavioral modes like chat, interactive, notify, or bridge. This change establishes the foundational types and validation logic for the new uplink architecture.

crates/astrid-core/src/uplink · high confidence

Introduce granular, capsule-scoped allowance system for pre-approved actions

Users can now grant pre-approved access for specific action patterns, allowing repeated actions to bypass approval prompts. The new \AllowanceStore\ manages these allowances with strict multi-tenancy, ensuring that an allowance granted to one principal (e.g., an agent) cannot authorize actions for another. Allowances support various granular patterns, including exact tool calls, server-wide tool access, file access via glob patterns, and network access scoped to specific capsules. They can be configured as session-only (cleared when the session ends) or persistent, with optional expiration dates and use limits. This system provides a secure, fine-grained way to streamline workflows while maintaining strict isolation between different principals and capsules.

crates/astrid-approval/src/allowance · high confidence

Introduce persistent MCP gateway with authenticated Streamable HTTP transport

The CLI now runs a persistent per-user MCP gateway that manages a single authenticated uplink to the daemon, allowing multiple short-lived \mcp attach\ processes to share the connection without accumulating orphaned processes. This gateway supports a new authenticated Streamable HTTP transport (listening on loopback with Bearer token auth) alongside the existing stdio proxy, and enforces strict consent flows: it elicits binary grant-on-use consent for ungranted capsule tools and relays capability approval prompts to the MCP client, ensuring fail-secure behavior when consent is declined or unavailable.

crates/astrid-cli/src/commands/mcp · high confidence

Introduce signed, offline-installable distro bundles

The CLI now supports creating and installing curated distro bundles via a new \.shuttle\ archive format. Maintainers can use \astrid distro seal\ to package a \Distro.toml\ manifest, a resolved \Distro.lock\ (pinning exact capsule versions and BLAKE3 hashes), and an ed25519 signature into a deterministic, offline-installable archive. End users can install these bundles offline; the CLI verifies the signature, checks the manifest hash binding, and validates capsule integrity before installation, ensuring that only trusted, tamper-proof distro configurations are applied.

crates/astrid-cli/src/commands/distro · high confidence

Introduces astrid-runtime to enable WebAssembly (wasm32-unknown-unknown) support

A new \astrid-runtime\ crate has been added to provide a portable facade for task spawning and time management, allowing the application to run in web browsers. This crate uses compile-time configuration to select the underlying implementation: on native targets, it re-exports \tokio\ and \std\ types directly with zero overhead, while on the \wasm32-unknown-unknown\ target, it maps these operations to JavaScript equivalents (using \wasm-bindgen-futures\ for tasks and \wasmtimer\/\web-time\ for timing). This change enables the kernel to function in browser environments by abstracting away platform-specific runtime primitives.

crates/astrid-runtime · high confidence

Introduces native local transport with keypair authentication and connection management

The local uplink server now uses a new native transport implementation that supports keypair-based authentication for principals, ensuring that connections are verified against the user's device keys rather than relying solely on session tokens. This change includes a dedicated egress queue system to manage per-connection event delivery, preventing one principal's traffic from affecting another's, and implements a reserved lane for critical admin operations like status checks and shutdowns to ensure they are always processed even under high load. The transport also features cancellation-safe IPC framing to handle partial messages robustly and enforces strict limits on frame sizes and concurrent connections to maintain stability.

crates/astrid-uplink/src/native · high confidence

Introduces stable, durable identity and ownership models for users and fleets

The identity subsystem now distinguishes between mutable execution principals and stable, durable ownership identities. Users are identified by an \AstridUserId\ that maps platform-specific logins (Discord, Telegram, etc.) to a single canonical user via \FrontendLink\, with principals auto-derived from display names or explicitly set. For authority, the system introduces \UserUid\ and \FleetUid\ derived from immutable genesis records (\UserGenesis\, \PrincipalGenesis\) using Blake3 hashing, ensuring that identity records remain stable even if authentication keys or display names change. This change provides a robust foundation for user and fleet ownership that persists across platform links and key rotations.

crates/astrid-core/src/identity · high confidence

The kernel now includes a passive bus-activity monitor that tracks event publish rates over a 5-second window and logs a warning naming the hottest topics if a sustained rate exceeds 100 events/second, helping operators quickly identify runaway event loops. Additionally, the kernel implements a grant-on-first-use consent handler that intercepts ungranted capsule access attempts, publishes a \GrantRequired\ signal, and waits for an approval response to grant the capsule to the caller, replacing the previous behavior of silently dropping ungranted calls.

crates/astrid-kernel/src · high confidence

Linux FUSE storage provider implementation

The \astrid-storage-provider-fuse\ crate introduces a Linux FUSE filesystem provider that mounts storage volumes via a detached service. It implements the core filesystem operations (stat, read, write, create, remove, rename, sync) by communicating with an authenticated kernel callback client over a Unix socket, using version-2 protocol framing with bounded message sizes. The provider manages its own lifecycle through a private control socket, maintaining a registry of mount records for persistence and cleanup. It exposes volume metadata (name, capacity, timestamps) from the kernel and handles mountpoint preparation, validation, and lazy unmounting. The implementation includes comprehensive tests for the callback transport, control protocol, volume info parsing, and mountpoint handling.

crates/astrid-storage-provider-fuse · high confidence

MCP client capability handlers for sampling, roots, and elicitation

The MCP client now supports server-initiated capabilities defined in the MCP Nov 2025 spec. This includes sampling (allowing servers to request LLM completions), roots (allowing servers to query accessible directories/URIs), and elicitation (allowing servers to request user input, including URL-based flows for OAuth and payments). The implementation introduces dedicated handler traits and composite routing in \crates/astrid-mcp/src/capabilities\, along with conversion logic to bridge the \rmcp\ library's elicitation schema format with the application's canonical types.

crates/astrid-mcp/src/capabilities · high confidence

Manifest-backed security gate for capsule host function calls

Capsules now enforce file, network, and identity permissions based on their declared manifest capabilities. The new \ManifestSecurityGate\ validates HTTP requests against an allowlist, restricts file read/write access to specific paths or the workspace root (preventing traversal attacks), and gates identity operations (resolve, link, admin) by capability level. Test stubs (\AllowAllGate\, \DenyAllGate\) are provided for testing.

crates/astrid-capsule/src/security · high confidence

Migration of legacy principal homes and introduction of host-audit logging

The kernel now supports migrating legacy 'layout-1' principal home directories into the new authoritative storage format. This includes automatically minting durable identities for leftover, unbound principal directories that lack a profile (admitting them so their files import) and quarantining directories with invalid names. The migration process uses durable receipts to track progress, ensuring idempotency and preventing data loss if an alias is renamed or reused. Additionally, a new host-audit sink has been added to the kernel to record sensitive host calls (file, network, and process operations) from WASM capsules. This sink implements a bounded writer that coalesces events, caps guest-controlled string lengths to prevent amplification attacks, and produces a signed, hash-chained audit log.

_crates/astrid-kernel/src/principal\_home\migration · high confidence

New HTTP API endpoints for agent interaction, audit history, and system administration

The gateway now exposes several new HTTP routes to support dashboard and external client integration. Users can invoke the AI agent via \POST /api/agent/prompt\ (streaming responses via SSE) and handle agent follow-up requests through \POST /api/agent/elicit-response\. System administrators can query historical audit logs via \GET /api/sys/audit\ with pagination and filtering, manage principal capabilities via \POST/DELETE /api/sys/principals/{id}/caps\, and install capsules from GitHub sources via \POST /api/capsules\. Additionally, new endpoints \GET /api/distribution\ and \GET /api/distribution/onboarding\ allow clients to discover deployment branding and invite configuration without authentication.

crates/astrid-gateway/src/routes · high confidence

New HTTP gateway with bearer auth, in-process IPC, and Prometheus metrics

The \astrid-gateway\ crate introduces a new HTTP front-end for the Astrid admin API, replacing the previous socket-only CLI path for local management. It implements v2 ed25519-signed bearer tokens (including device-scoped variants) for authentication, with cryptographically bound revocation via \issued\_at\ timestamps. The gateway communicates with the kernel in-process via a shared \EventBus\ (using \BusAdminClient\ and \BusKernelClient\) to avoid socket-proxy bottlenecks, while preserving principal and device-scope context. It exposes a \/metrics\ endpoint with Prometheus-style counters, histograms, and build-info gauges, and supports native TLS termination via rustls. The default listen port is 2787, and configuration is loaded from \gateway-http.toml\.

crates/astrid-gateway/src · high confidence

New WIT interface definitions for capsule host capabilities

The \astrid-capsule/wit-staging\ directory now includes the formal WIT (WebAssembly Interface Types) definitions for the host interfaces that capsules can import. This adds the contract specifications for core capabilities including filesystem access (\astrid:fs\), HTTP client operations with SSRF protection (\astrid:http\), inter-process communication via an event bus (\astrid:ipc\), key-value storage (\astrid:kv\), networking primitives (\astrid:net\), and user interaction flows like human-in-the-loop approval (\astrid:approval\) and interactive input elicitation (\astrid:elicit\). It also defines the guest export contracts (\astrid:guest\) that the kernel uses to invoke capsule lifecycle hooks (install, upgrade, interceptor, background run). These files establish the API surface and data shapes for the capsule runtime environment.

crates/astrid-capsule/wit-staging · high confidence

New agent lifecycle commands with secure, ephemeral session spawning

The CLI now includes a comprehensive set of commands for managing agent identities, including \create\, \spawn\, \list\, \current\, \switch\, \show\, \delete\, \enable\, \disable\, \modify\, \link\, and \unlink\. The \agent create\ command supports provisioning agents with specific groups, egress rules, and resource limits, and introduces \--clone\ for full profile/state replication and \--inherit-from\ for selective state inheritance. A new \agent spawn\ command allows users to derive a restricted, throwaway principal with explicit capsule loads, allowed egress, and inherited state, execute a single bounded job, and automatically tear down the session. Remote agent features (discover, add, card, export, import, delegate) are present as stubs and currently rejected until future implementation.

crates/astrid-cli/src/commands/agent · high confidence

New capability grammar and content-addressed registry for management API policies

The system introduces a strict, colon-delimited grammar for static capability identifiers used in the management API, replacing the previous ad-hoc handling. This includes a new \capability\_grammar\ module that validates capability strings (enforcing ASCII-only, no double-globs, and specific wildcard rules) and defines core exemption capabilities like \system:resources:unbounded\, \net\_bind\, and \uplink\. Alongside this, a content-addressed capability registry (\capability\_registry\) has been added, featuring two schema revisions (v1 with 51 IDs, v2 adding \self:distro:grant\) that map capabilities to their scope, danger level, and target kinds. This registry serves as the authoritative source for kernel-enforced policy, ensuring that capability definitions are immutable per revision and cryptographically verifiable via BLAKE3 digests.

crates/astrid-core/src · high confidence

New capsule management subcommands and static validation

The CLI now includes a suite of new \astrid capsule\ subcommands to manage the capsule lifecycle and verify correctness. \astrid capsule build\ delegates compilation to a standalone companion binary. \astrid capsule check\ provides a static, CI-friendly linter that validates tool wiring (ensuring advertised tools are routed and handlers match) and mandatory publish patterns without requiring a running daemon. \astrid capsule config\ allows viewing and editing capsule environment variables via the daemon admin API. \astrid capsule deps\ visualizes the dependency graph of installed capsules, showing imports, exports, and unsatisfied dependencies. \astrid capsule install\ has been expanded to support GitHub sources, batch installation, and operator-consent authority checks for untrusted capsules, including live hot-loading of newly installed capsules into a running daemon.

crates/astrid-cli/src/commands/capsule · high confidence

New chunker evidence benchmarking tool

A new standalone Rust binary, \astrid-storage-chunker-evidence\, has been added to measure and report on content-addressed storage chunking algorithms. It evaluates FastCDC v2020, MinCDC, and MothCaterpillar against real and synthetic corpora, producing JSON reports that include throughput, edit stability, and bottom-k sketch evidence to help select optimal chunking profiles.

crates/astrid-storage-chunker-evidence · high confidence

New distro-neutral OCI container images for Linux amd64 and arm64

Astrid Runtime now provides official, distro-neutral OCI container images for both Linux amd64 and arm64 architectures. These images package the authenticated release archives into a minimal Ubuntu 24.04 base, running as an unprivileged user (UID/GID 65532) with a read-only root filesystem and all Linux capabilities dropped. The container entrypoint enforces strict security by requiring an operator-supplied SHA-256 pin for the signed distro, staging it in a private temporary directory to prevent symlink attacks, and rejecting unauthorized daemon arguments like ephemeral mode. Each architecture has its own dedicated build configuration and test suite to verify daemon readiness and runtime restrictions.

container · high confidence

New event bus with IPC rate limiting and per-principal routing

The \astrid-events\ crate now provides a new event bus that broadcasts events to async subscribers and notifies synchronous observers, while introducing IPC rate limiting and per-(capsule, topic, principal) routing. The bus uses a broadcast channel for async delivery and a subscriber registry for synchronous handlers, with a reentrant mutex ensuring ordered publication. IPC messages are stamped with a monotonic sequence number for ordered delivery. A new IPC rate limiter enforces per-principal throughput ceilings and a hard payload size cap to prevent DoS. The routing demux fans out events to per-principal FIFO queues with deficit round-robin fairness and byte-budget eviction to prevent starvation. Event types have been renamed from \AstralisEvent\ to \AstridEvent\, with new events for prompt building, message sending, context compaction, session reset, model resolving, agent loop completion, tool result persisting, and capsule lifecycle. The prelude has been updated to reflect these changes.

crates/astrid-events/src · high confidence

New filesystem host implementation with security gates and audit logging

The WASM capsule engine now includes a new \astrid:fs\ host implementation that routes file operations through workspace, home, and tmp VFS bundles. This change introduces strict security gates to prevent path-escape attacks and adds comprehensive audit logging for all file reads, writes, and deletions. While core operations like reading and writing files are now functional, file handle-based operations (such as positional I/O and synchronization) remain stubbed and will return errors until a follow-up port is completed.

crates/astrid-capsule/src/engine/wasm/host/fs · high confidence

New kernel management API surface for agent derivation, capsule lifecycle, and readiness probes

The kernel management API now exposes structured request and response types for the CLI and daemon to manage agents and capsules. Users can atomically derive restricted, throwaway agents from a source principal with explicit capsule and network controls via the new \AgentDeriveRequest\ and \AgentDeriveKernelRequest\ types. Capsule installation and lifecycle are governed by typed wire shapes including \InstalledCapsuleIdentity\, \CapsuleInstallResumeReceipt\, and \CapsuleInstallAuthority\ (Automatic, ExplicitApproval, OperatorDistribution), alongside environment staging via \CapsuleInstallEnv\. The API also introduces \AgentLoopReadiness\ and \AgentReadinessProbe\ to report whether the loaded capsule set can serve chat turns, and \CapsuleTopicProbe\ for gateway-level topic subscription checks. Additional admin capabilities include \PromoteWorkspace\ and \RollbackWorkspace\ for OS-level copy-on-write changes, projection-name diagnostics (\ProjectionNamePolicyPreset\), and audit/usage reporting types (\AuditStats\, \AuditPruneResult\, \AuditHealth\, \ResourceUsage\).

_crates/astrid-core/src/kernel\api · high confidence

A new \astrid-uplink\ crate introduces dedicated \AdminClient\ and \KernelClient\ wrappers for the local daemon socket, replacing ad-hoc IPC logic. The admin client handles high-level management requests (agents, quotas, groups, capabilities, invites, storage mounts) using a strict request/response correlation pattern with UUIDs. The kernel client manages capsule lifecycle and system status, featuring a robust timeout strategy that distinguishes between inactivity (no keepalive frames) and overall ceiling timeouts, mapping these to specific HTTP 504 errors for the gateway. Both clients enforce principal-based authentication via a signed handshake, ensuring that every outbound message is stamped with the correct identity for capability checks.

crates/astrid-uplink/src · high confidence

New macOS FSKit build, certification, and release infrastructure scripts

The scripts directory now includes a comprehensive set of tooling to build, sign, notarize, and certify the macOS FSKit application and release archives. build-macos-fskit.sh automates the Xcode build of the AstridFS app and extension, enforcing code signing with a specific team identifier, verifying bundle versions and architectures, and optionally submitting the app to Apple Notary. certify\_fskit\_local.py provides a supervised runtime verification of the installed app, ensuring the archive matches the installed binary and that mount, write, sync, and unmount operations function correctly. Additional scripts enforce release integrity: certify\_musl\_release\_archive.sh validates Linux musl archives for correct members and static linking; channel\_metadata.py and channel\_publication.py manage and validate signed release-channel pointers (stable, dev, nightly) with strict schema and lifetime checks; check-macos-fskit.sh validates the Swift source and Xcode project constraints for the FSKit extension; check-wasm-portability.sh ensures core crates compile for wasm32-unknown-unknown; check\_dco.py enforces Developer Certificate of Origin sign-offs; check\_glibc.py and check\_static\_elf.py validate binary compatibility and static linking for Linux releases; and ci/diff-gateway-openapi.sh detects unintended OpenAPI contract changes. ci/import\_macos\_signing.sh securely imports signing identities and notary credentials into the CI environment.

scripts · high confidence

New operator CLI commands for audit, capabilities, and capsule management

The CLI now exposes several new top-level subcommands for system administration and debugging. \astrid audit\ provides operator-only controls for audit accounting, including viewing stats and health, and pruning old segments. \astrid caps\ allows managing agent capabilities through grant, revoke, check, and token operations (mint, revoke, list). \astrid capsule\ enables dispatching CLI verbs contributed by capsules, supporting both auto-resolution of unique verbs and explicit provider selection. Additionally, \astrid doctor\ offers a system health check that verifies prerequisites, daemon status, and agent-loop readiness, while \astrid group\ provides CRUD operations for capability groups. A stub for \astrid budget\ is also registered for future budget management features.

crates/astrid-cli/src/commands · high confidence

New operator-configurable HTTP host with SSRF protection and versioned contracts

The WASM capsule engine now exposes the \astrid:http\ host interface, supporting both \@1.0.0\ and \@1.1.0\ contract versions. This implementation provides a secure HTTP client for capsules, featuring a shared backend that enforces strict SSRF (Server-Side Request Forgery) protections via a custom DNS resolver and airlock logic. The host blocks requests to private, loopback, and link-local IP addresses by default, while allowing operators to configure a local-egress allowlist for specific exempted hosts. The \@1.1.0\ interface introduces granular operator-configurable limits, including timeouts (connect, total, first-byte, between-bytes), redirect policies, maximum response and decompressed body sizes, HTTPS-only enforcement, and subresource integrity (SRI) verification. The \@1.0.0\ interface is maintained as a thin shim with default behaviors (e.g., redirect limit of 10, 30s timeout, 10 MB body cap) to ensure backward compatibility.

crates/astrid-capsule/src/engine/wasm/host/http · high confidence

Per-principal profile system with device-scoped authentication and resource quotas

A new per-principal profile system has been introduced, storing policy in \\~/.astrid/etc/profiles/{principal}.toml\ to ensure capsules cannot read or write their own policy. This system defines resource quotas (memory, CPU fuel, timeouts, IPC throughput, background processes) with strict validation and legacy zero-CPU-fuel coercion. Authentication is enhanced with per-device capability scoping: registered device keys now carry a \DeviceScope\ (either \Full\ or \Scoped\ with allow/deny patterns), allowing operators to restrict device capabilities beyond the principal's base permissions. The profile also manages group memberships, direct capability grants/revokes, capsule access lists, egress policies, and process allowlists, with atomic file saves on Unix and robust error handling for malformed or versioned profiles.

crates/astrid-core/src/profile · high confidence

Persistent group configuration with secure on-disk storage

Users can now define custom groups in \groups.toml\ that persist across restarts. The system introduces built-in groups (admin, agent, restricted) which are baked into the kernel and never serialized to disk, while only custom groups are written to the configuration file. To prevent privilege escalation, custom groups cannot grant the universal \\*\ capability unless they explicitly opt in via the \unsafe\_admin\ flag. The implementation ensures security by writing the configuration file atomically with restricted permissions (mode 0600 on Unix) and cleaning up temporary files on failure.

crates/astrid-core/src/groups · high confidence

Support for publishing astrid-capsule as a standalone crate

The astrid-capsule crate is now publishable to crates.io and usable via \cargo install astrid\. A new build script stages the required WIT (WebAssembly Interface Types) files from the workspace submodule into a committed \wit-staging\ directory, ensuring that consumers installing the crate do not need the git submodule or the full workspace source to compile. This change also adds a \.gitignore\ to manage the staging directory and updates the README to reflect the current architecture and MSRV of 1.94.

crates/astrid-capsule · high confidence

Unified prelude for Astrid secure agent runtime

A new \astrid-prelude\ crate has been introduced to provide a single import point for commonly used types across the Astrid ecosystem. Users can now access types from core, crypto, capabilities, audit, MCP, events, hooks, and workspace crates via \use astrid\prelude::\\, simplifying dependency management and reducing boilerplate in applications that need functionality from multiple subsystems.

crates/astrid-prelude/src · high confidence

Windows filesystem provider via WinFsp

A new \astrid-storage-provider-winfsp\ crate introduces a native Windows filesystem provider backed by WinFsp, enabling Astrid storage volumes to be mounted as standard Windows drives. The implementation includes a daemon and service mode for lifecycle management, a callback-based filesystem interface that translates Win32 I/O operations into Astrid's storage protocol, and a build script to link the WinFsp runtime. This allows Windows users to interact with Astrid storage using familiar file explorer operations.

crates/astrid-storage · high confidence

Workspace boundary enforcement and sandboxing architecture

The workspace crate now enforces strict operational boundaries for agent actions, introducing a configurable path-checking system that distinguishes between allowed, auto-allowed, and never-allowed paths based on workspace mode (Safe, Guided, or Autonomous) and escape policies. This includes new pre-defined profiles (safe, power\_user, autonomous, ci) to simplify configuration, and a dedicated sandbox module that generates host-level process sandboxes with read-only file injection capabilities. Additionally, agent sessions now utilize isolated Git worktrees to prevent cross-session interference, with automatic cleanup and WIP preservation upon session completion. The crate has also been renamed from 'astralis' to 'astrid' and internal modules have been restricted to crate-private visibility to enforce architectural boundaries.

crates/astrid-workspace/src · high confidence

macOS FSKit storage provider implementation

Added a new storage provider component for macOS that manages FSKit-based filesystem mounts. This includes the main service entry point handling mount, sync, status, and unmount operations via the storage provider protocol, along with specialized logic to classify and report native mount failures (such as missing or disabled FSKit extensions) and a hidden service mode for kernel-created broker interactions. This change introduces the specific macOS storage lifecycle companion without altering other platform providers.

crates/astrid-storage-provider-fskit · high confidence

Removals

Gateway daemon layer removed

The \astralis-gateway\ crate has been completely removed from the codebase. This eliminates the daemon-side runtime layer that previously handled configuration loading, multi-agent management, message routing, health checks, and IPC-based CLI communication (including approval/elicitation workflows). Users no longer interact with a persistent gateway daemon; the functionality provided by this crate is no longer available.

crates/astralis-gateway · high confidence

Removal of astralis-core crate

The \astralis-core\ crate, which previously provided the foundational types, traits, and utilities for the Astralis secure agent runtime SDK, has been removed. This deletion eliminates the core abstractions for security operations, identity management (\AstralisUserId\), the \Frontend\ trait for UI implementations, input classification (\TaggedMessage\), directory scaffolding, error types, and versioning utilities that other crates depended on.

crates/astralis-core, crates/astralis-mcp · high confidence

Removal of core Astralis runtime crates

The audit logging, capability token management, LLM provider abstraction, and storage engine crates have been removed from the repository. This eliminates the cryptographic audit trail, capability-based authorization tokens, LLM integration (Claude, OpenAI-compatible, Z.AI), and the underlying SurrealKV/TiKV storage layer from the product.

(repo-wide) · high confidence

Removal of initial Astralis SDK crates and demo infrastructure

This change removes the initial implementation of several core Astralis SDK components, effectively stripping the repository of its foundational runtime features. Specifically, the \astralis-cli-mockup\ demo scenarios (including cinematic boot sequences and multi-agent simulation steps) have been deleted, along with the \astralis-config\ configuration loader that handled layered TOML merging and environment variable resolution. The cryptographic security layer (\astralis-crypto\), including Ed25519 key management and signature verification, has been removed, as has the \astralis-events\ async event bus used for runtime communication. Finally, the \astralis-workspace\ crate, which defined operational boundaries, escape policies, and workspace profiles (Safe, Guided, Autonomous, CI), has been entirely deleted. Users will no longer have access to these initial security, configuration, and operational boundary features.

(repo-wide) · high confidence

Removal of legacy approval and runtime crates

The \astralis-approval\ and \astralis-runtime\ crates have been removed from the codebase. This deletion eliminates the previous allowance-based permission system, the security interceptor, and the agent orchestration runtime that coordinated LLM, MCP, and audit components. Users will no longer have access to the legacy session management, context summarization, or the specific policy and budget enforcement logic defined in these modules.

crates/astralis-approval, crates/astralis-runtime · high confidence

Security

Native process sandboxing now enforces strict credential masking and profile injection validation

The sandbox layer for spawned native processes now actively masks sensitive operator credentials (such as SSH keys, AWS/GCP credentials, and Docker tokens) and Astrid internal secrets by overlaying them with empty tmpfs or /dev/null, preventing agent processes from reading host-level secrets. On Linux, the implementation uses bubblewrap with a new probe to detect user-namespace restrictions (e.g., on Ubuntu 24.04+) and provides clear installation hints if unavailable. On macOS, it generates and validates Seatbelt (SBPL) profiles, rejecting paths with forbidden characters (quotes, backslashes, null bytes) to prevent profile injection attacks. These changes ensure that agent-executed tools are strictly confined to the worktree and cannot access the operator's home directory secrets.

crates/astrid-workspace/src/sandbox · high confidence

Per-principal capsule access control and audit logging

Capsule tool and CLI command invocations are now gated by per-principal grants, ensuring that only principals explicitly authorized (or admins with the \\\ capability) can invoke specific capsules on the user-invocable surface (\tool.v1.execute.\\, \cli.v1.command.run.\*\). The dispatcher enforces this filter at dispatch time using a lock-free \CapsuleAccessResolver\ backed by the \PrincipalProfileCache\, while internal orchestration topics remain unaffected. Additionally, sensitive host calls (filesystem, network, process) are now recorded via a bounded asynchronous \HostAuditSink\ trait, which forwards neutral events to the kernel for durable, signed, hash-chained audit logging without blocking the host call.

crates/astrid-capsule/src · high confidence

Security hardening for WASM host functions

This change introduces several security improvements to the WASM host layer. First, it adds input sanitization for the approval system, stripping control characters and enforcing length limits on action and resource strings to prevent DoS and injection issues. Second, it implements operator-consent for local-egress, requiring explicit approval for capsules accessing local network endpoints, with strict scoping by principal and capsule. Third, it adds principal verification for elicit responses, ensuring that only the originating principal can reply to interactive prompts, preventing cross-principal hijacking. Finally, it adds comprehensive tests for these security features, including audit logging for file, network, and process operations.

crates/astrid-capsule/src/engine/wasm/host · high confidence

Behavioural changes

Approval system hardening: per-capsule scoping, new action types, and risk model simplification

The approval system now enforces stricter isolation and security for agent actions. Network requests and other sensitive operations are scoped to a specific \capsule\_id\, ensuring that allowances granted to one capsule cannot be reused by another. New action types have been added to cover capsule-specific operations: \CapsuleExecution\, \CapsuleHttpRequest\, \CapsuleFileAccess\, and \CapsuleNetBind\. The previous \RiskLevel\ enum and automatic risk assessment logic have been removed from the approval request types; risk is now communicated via a human-readable reason string instead. Additionally, the budget tracker now supports refunding costs for failed or reversed actions, and the approval manager's \check\_approval\ method requires a \PrincipalId\ to correctly scope allowance lookups.

crates/astrid-approval/src · high confidence

Bundled AppArmor profile for unprivileged user namespace support

The astrid-cli crate now includes a bundled AppArmor profile that grants the necessary permissions for creating unprivileged user namespaces. This change resolves launch failures on modern Linux distributions (such as Ubuntu 23.10+) where the kernel restricts user namespace creation by default, ensuring that the bundled bubblewrap sandbox can successfully initialize native subprocess capsules.

crates/astrid-cli/apparmor · high confidence

CLI redesign with noun-verb structure and per-principal scoping

The \astrid\ CLI has been restructured to follow a noun-verb command model (e.g., \astrid agent\, \astrid capsule\, \astrid quota\) and now enforces a single process-wide principal identity for all IPC messages. This change introduces a new \--principal\ flag and \ASTRID\_PRINCIPAL\ environment variable to stamp every request with a verified identity, while adding a \cli-context.toml\ file to persist the active agent for per-agent commands. The CLI also now co-installs companion binaries like \astrid-daemon\ and \astrid-build\ alongside the main binary, and includes a new \astrid mcp\ surface for Model Context Protocol integration.

crates/astrid-cli/src · high confidence

CLI renamed to Astrid

The command-line interface has been renamed from Astralis to Astrid. This change is reflected in the crate's documentation and internal module structure, marking the rebranding of the CLI frontend.

crates/astralis-cli · high confidence

Capsule installation authority and provenance enforcement

The capsule installer now enforces strict provenance classification and authority receipts for every installed capsule. Archives are unpacked with path-traversal and symlink hardening, and their manifests are validated before installation. The system classifies artifacts as signed by the local runtime, signed by a foreign runtime, or unsigned, and requires an explicit \AuthorityDecision\ (automatic for local builds, explicit approval for others) to persist an \InstalledAuthority\ receipt. This receipt pins the approved content digest, manifest digest, and WASM executable hash, preventing post-install tampering. Legacy authority receipts from previous layouts are automatically rebound to new targets or quarantined if ambiguous. Additionally, the installer detects and warns about WIT contracts skew between installed capsules and the daemon's canonical contracts, ensuring runtime compatibility without blocking installation.

crates/astrid-capsule-install · high confidence

Configuration system renamed to Astrid with new client, gateway, and filesystem settings

The configuration crate has been renamed from Astralis to Astrid, updating all environment variable prefixes (e.g., \ASTRALIS\\\ to \ASTRID\\\) and config file paths (e.g., \\~/.astralis/\ to \\~/.astrid/\). This change introduces a new pre-mount client configuration module (\client.rs\) that manages local CLI settings like \run\_idle\_secs\ and \admin\_timeout\_secs\ with strict file validation, and a new gateway configuration module (\gateway.rs\) for MCP HTTP listener and state directory settings. The default configuration (\defaults.toml\) removes the monolithic \\[model\]\ section in favor of a \\[filesystem\]\ section for volume naming, adds \\[http\]\ host limits for operator-configurable timeouts and caps, and introduces \\[capsule\]\ concurrency settings. The configuration loader now supports explicit home directory and workspace layout overrides, and the \config show\ command reflects these structural changes.

crates/astrid-config/src · high confidence

Daemon lifecycle and signal handling improvements

The daemon now includes a standalone binary entry point that detaches into its own process session to prevent orphaning when the CLI exits, and implements a robust signal watchdog that ensures graceful shutdown even under high load by forcing an exit after a grace period if the async runtime is starved. Additionally, the daemon supports an ephemeral mode that automatically shuts down when the last client disconnects, and allows routing logs to standard error via the ASTRID\_DAEMON\_LOG\_TARGET environment variable for better integration with process supervisors and containers.

crates/astrid-daemon · high confidence

Domain-separated identifiers and atomic key storage

The crypto crate now introduces \IdentifierHash\ and \PublicKeyFingerprint\ types that use BLAKE3 domain separation to prevent cross-protocol collisions, and replaces the previous \KeyPair::load\_or\_generate\ method with a new \load\_or\_generate\_keypair\ function in \key\_storage.rs\ that atomically creates Ed25519 keys with owner-only permissions. The \ContentHash\ API is simplified by removing \hash\_multi\ and \hash\_with\_domain\ in favor of the new typed identifier wrappers, and the crate is renamed from \astralis\ to \astrid\ with stricter compiler lints enforced.

crates/astrid-crypto/src · high confidence

Durable, atomic storage for invite and pair-device tokens

The kernel now persists invite and pair-device tokens in a dedicated system-control key-value store (\system:control:invites\ and \system:control:pair-tokens\) instead of relying on legacy TOML files. This change introduces a two-step reservation workflow for pair-device provisioning: a token is first reserved (moved to a non-redeemable state) while the device profile is prepared, then either consumed or released, ensuring that only one daemon can successfully redeem a token even under concurrent access. Invite redemption uses a similar atomic prepare-then-consume pattern. Legacy invite and pair-token files are imported exactly once at boot, validated, and retired, and all token operations use domain-separated BLAKE3 hashes with constant-time comparison to prevent replay and side-channel attacks.

_crates/astrid-kernel/src/invite, crates/astrid-kernel/src/pair\token · high confidence

Extracted wasm-clean capsule types and added semantic capability presentation

The \astrid-capsule-types\ crate has been extracted into a standalone, wasm-clean library to provide a shared vocabulary for capsule manifests, identifiers, and resource limits without pulling in engine-specific runtimes like Wasmtime or Tokio. This change introduces a new \capability\_presentation\ module that translates raw manifest capability fields into human-readable actions, scopes, and impacts for CLI and dashboard consent surfaces. It also refactors the \CapabilitiesDef\ merge logic to be exhaustive, ensuring that component-level capability grants are correctly merged into the root manifest without silent drops.

crates/astrid-capsule-types · high confidence

Fix connection counter leak by moving lifecycle event emission to the host

The host now emits \client.v1.connect\ and \client.v1.disconnect\ events for inbound uplink sockets, replacing the previous proxy-based emission. This ensures that both events are stamped with the identical, host-verified principal recorded at the handshake, preventing the connection counter from leaking when the proxy previously emitted disconnects as \anonymous\. The change also introduces a two-frame principal challenge-response during the socket handshake to verify the client's identity, and implements a shared TCP listener registry to allow multiple worker stores to bind to the same port without exhausting the listener quota.

crates/astrid-capsule/src/engine/wasm/host/net · high confidence

Hooks system renamed to Astrid and event model expanded

The hooks subsystem has been renamed from Astralis to Astrid, updating all public types, environment variables (e.g., ASTRID\_SESSION\_ID), and built-in profile messages. The hook event model has been expanded with new lifecycle stages including SessionReset, ModelResolve, MessageReceived, MessageSent, AgentLoopEnd, ToolResultPersist, KernelStart, and KernelStop. Additionally, the WASM handler is now implemented via Extism rather than being a stub, and hook discovery now uses the project's workspace layout instead of hardcoded config paths.

crates/astrid-hooks/src · high confidence

Integration test crate renamed to Astrid with stricter linting

The integration test crate has been renamed from Astralis to Astrid, and its linting configuration has been tightened. The crate now enforces \missing\_docs\ and \unreachable\_pub\ as hard errors (previously warnings or absent), and explicitly denies the use of \unwrap()\ in non-test code to prevent panics, while allowing \unwrap()\ within test blocks.

crates/astrid-integration-tests/src · high confidence

Introduce secure inbound message handling for MCP client capabilities

The \astrid-mcp\ client capability layer now includes a dedicated handler (\AstridClientHandler\) and supporting modules to process inbound messages from untrusted capsule subprocesses. This change adds strict validation for channel names, payload sizes, and capsule IDs to prevent spoofing and resource exhaustion, while mapping bridge channel definitions to core uplink capabilities. It also implements the \rmcp::ClientHandler\ trait to bridge MCP server requests (sampling, roots, elicitation) to Astrid's internal capability system.

crates/astrid-mcp/src/capabilities/client · high confidence

Kernel router enforces strict caller authentication and connection tracking

The kernel management API now strictly requires an authenticated principal for all management requests, rejecting any request with a missing or invalid principal identity to prevent unauthorized access. Additionally, the router implements a robust connection tracker that accurately accounts for client connections by recognizing both typed IPC payloads and JSON-based topics, ensuring that connection counts are correctly attributed to the authenticated principal rather than defaulting to anonymous or default identities, which fixes previous connection leak issues.

_crates/astrid-kernel/src/kernel\router · high confidence

OS-level copy-on-write for non-git workspaces

Non-git workspaces now use real OS-level copy-on-write instead of an in-process overlay, ensuring that spawned processes (like cargo or build scripts) see a single merged filesystem view. On macOS, this uses APFS clonefile(2) clones; on Linux, it uses overlayfs mounts (with fuse-overlayfs as a fallback). Changes are isolated in a working tree and only committed to the pristine workspace via an explicit promote, with rollback support to discard uncommitted changes.

_crates/astrid-vfs/src/workspace\cow · high confidence

Persistent process registry with bounded resource caps and ownership isolation

The persistent process tier now uses a host-owned registry that survives instance resets, allowing a process spawned in one tool invocation to be reattached in another. Guest requests for log ring sizes, lifetimes, and labels are clamped to strict host ceilings (e.g., max 8 MB per stream, 6-hour lifetime, 128-byte labels) to prevent unbounded resource usage. Process IDs are 256-bit CSPRNG tokens hashed with a keyed BLAKE3, and every operation verifies the caller's principal and capsule ownership, returning a generic 'no-such-process' error for unauthorized access. The registry enforces global (256 entries) and per-principal (32 retained) caps, and supports both 'drop-oldest' and 'backpressure' overflow policies for log rings.

crates/astrid-capsule/src/engine/wasm/host/process/persistent · high confidence

Principal-scoped capability tokens and static policy enforcement

The capabilities system now enforces strict per-principal isolation: capability tokens are cryptographically bound to the principal they were minted for, preventing cross-principal reuse, and the signing format has been upgraded to version 2 to include this binding. Additionally, a new static policy engine (\CapabilityCheck\) evaluates management-API permissions based on principal profiles, group memberships, and per-device scopes, with revokes taking precedence over grants. The capability store also now supports persistent token storage via \SurrealKvStore\ and introduces cryptographic handles (\DirHandle\, \FileHandle\) for VFS directory and file access.

crates/astrid-capabilities/src · high confidence

Refactored config merging into modular submodules with strict security enforcement

The configuration merge logic in \crates/astrid-config/src/merge\ has been decomposed from a single file into focused submodules (\deep.rs\, \enforce.rs\, \restrict.rs\, \servers.rs\, \path.rs\, \types.rs\). This refactoring introduces a robust security model where workspace-level configurations are strictly constrained: they can only tighten security settings (e.g., reducing budget limits, tightening escape policies, or decreasing rate limits) and are blocked from overriding operator-defined critical fields like HTTP host limits, uplink allowlists, and server command/args. Additionally, workspace-injected servers are automatically forced to be untrusted and non-auto-starting, ensuring that project-level configs cannot escalate privileges or alter core runtime behavior.

crates/astrid-config/src/merge · high confidence

Rename astralis to astrid and tighten handler visibility

The hook handler module has been renamed from \astralis-hooks\ to \astrid-hooks\, updating all internal references, environment variable names (e.g., \ASTRID\_HOOK\_EVENT\), and system prompts to reflect the new product name. Additionally, the visibility of the handler modules (\agent\, \command\, \http\, \wasm\) and their public types has been restricted from \pub\ to \pub(crate)\, and the \HandlerExecutor\ trait has been removed, indicating a shift toward internal-only implementation details for hook execution.

crates/astrid-hooks/src/handler · high confidence

Renamed test crate to Astrid and expanded test utilities

The \astralis-test\ crate has been renamed to \astrid-test\ to align with the project's rebranding. This change introduces new test fixtures for core types such as \AgentId\, \SessionId\, \ApprovalRequest\, and \ElicitationRequest\, along with a \TestContext\ harness for managing temporary directories and files. A \MockEventBus\ has been added to capture and verify emitted events during tests. The crate's strictness has also increased by enforcing \deny(missing\_docs)\, \deny(unreachable\_pub)\, and \deny(clippy::unwrap\_used)\ (with a test-only allow), and the public API now exposes these new utilities via a prelude module.

crates/astrid-test/src · high confidence

Routed event subscriptions now support per-principal isolation and strict delivery guarantees

The event bus routing layer has been rewritten to introduce \RouteEntry\ state machines that manage per-principal fan-out, Deficit Round Robin (DRR) scheduling, and byte-budget eviction. Subscriptions can now be scoped to a specific owner principal, ensuring that foreign-principal events are rejected at enqueue time and cannot evict the owner's own messages from the queue. To prevent data loss during high-rate bursts (such as LLM token streams), the per-principal message count cap has been increased from 256 to 16,384, and the system now guarantees loss-free receive by handling concurrent dispatch and preventing event drops during drain operations. Additionally, a new \RouteAdmissionGate\ allows staged runtimes to prepare subscriptions before atomically publishing them, ensuring no events are lost or delivered prematurely during initialization.

crates/astrid-events/src/route · high confidence

TUI restructured with multi-line paste support and terminal color inheritance

The TUI module has been restructured into a new modular layout (headless, input, state, render, theme) within the \astrid-cli\ crate. Users can now paste multi-line text blocks into the input buffer, which are treated as atomic segments for editing. The default color theme has been updated so that primary text and the cursor inherit the terminal's foreground color (using \Color::Reset\) instead of forcing white, ensuring better visibility on light terminal backgrounds. Additionally, a new headless snapshot mode has been added to render TUI frames to an in-memory buffer for automated testing.

crates/astrid-cli/src/tui · high confidence

Telemetry crate renamed to Astrid with stricter linting and logging improvements

The telemetry crate has been renamed from \astralis\_telemetry\ to \astrid\_telemetry\, updating all public API references, documentation, and default log file prefixes to reflect the new product name. The crate now enforces stricter Rust linting by denying \missing\_docs\, \unreachable\_pub\, and \unwrap\_used\ (except in tests), and removes the \setup\_default\_logging\ convenience function. The \RequestGuard\ type has been removed, simplifying the request lifecycle management. Additionally, file logging now explicitly disables ANSI color codes for cleaner log output and uses a builder pattern for rolling file appenders with a configurable maximum file count (defaulting to 7). A new \log\_config\_from\ function is available when the \config\ feature is enabled to convert application configuration into telemetry settings.

crates/astrid-telemetry/src · high confidence

WASM engine migration to Wasmtime Component Model with per-principal isolation and async host functions

The WASM engine has been migrated from the Extism runtime to the Wasmtime Component Model, introducing a new per-domain WIT host ABI that replaces the previous WASI-based interface. This change enables strict per-principal isolation for KV stores, filesystem mounts, and secrets, ensuring that data and resources are scoped to the invoking user or agent. To prevent worker-pool exhaustion during high-concurrency LLM streaming, key host functions for IPC reception and HTTP requests are now executed asynchronously, allowing the runtime to handle multiple concurrent operations without blocking. The engine also supports multi-version host packages (e.g., HTTP 1.0.0 and 1.1.0) for backward compatibility and includes new security gates for content-addressed WASM loading and principal-scoped cancellation tokens.

crates/astrid-capsule/src/engine/wasm · high confidence

Fixes

Fix init process to preserve optional credentials and ensure daemon stability

The init command now correctly handles optional secret credentials by skipping the persistence of empty values, preventing the overwriting of existing credentials with blank entries. Additionally, the initialization process ensures the runtime daemon remains active throughout the provisioning lifecycle, avoiding premature disconnection that could interrupt capsule installation or post-install operations.

crates/astrid-cli/src/commands/init · high confidence

Fixes to storage mount reliability, capacity, and large-file handling

This update resolves several issues in the storage mount subsystem: it ensures the runtime tree is correctly packed (including WASM components) so that the system stops with the expected 'astrid.volume' state; it prevents the system from wedging when a native process storage provider's control endpoint is absent or stale by properly reaping the child process; it allows mounted files to exceed the callback payload limit by streaming large file writes instead of blocking on size; and it provides accurate physical backing capacity information for the volume on Unix systems.

_crates/astrid-kernel/src/storage\mount · high confidence

Improved daemon startup reliability and shutdown cleanup

The daemon command now handles startup and shutdown more robustly. Startup waits for the daemon to become ready using a configurable timeout (defaulting to 10 minutes) instead of a hardcoded 60 seconds, and if the daemon is still running after the timeout, it is disowned rather than forcefully killed, preventing data loss during long initializations like layout migrations. Shutdown processes now ensure that the runtime is fully finalized before allowing a new instance to start, and they correctly clean up all runtime markers (socket, PID, ready, token) only when the daemon is truly stopped, avoiding conflicts with live listeners or singleton locks. Additionally, workspace identity checks now correctly handle the Astrid home directory, allowing it to be recognized regardless of whether it uses the \.aos\ or \.astrid\ layout.

crates/astrid-cli/src/commands/daemon · high confidence

Introduces a strict layout migration barrier to prevent data loss during v1-to-v2 upgrades

The \legacy\_migration\_barrier\ module now enforces a deterministic, ledger-bound migration process for users upgrading from the legacy layout (v1) to the new layout (v2). Instead of independent best-effort imports, the system now snapshots all legacy sources (environment variables, secrets, audit logs, and dedicated directories) before any destructive operations, verifies that every component has been successfully imported via a completion ledger, and only then retires the old sources. This ensures that a crash or interruption during migration does not leave the application in an inconsistent state where legacy data is partially deleted but not yet migrated. The barrier also tightens permissions on legacy \kv\, \tokens\, and \tmp\ directories to \0700\ and quarantines non-empty legacy audit trees that cannot be automatically imported, ensuring a fail-safe transition for all principal homes.

_crates/astrid-kernel/src/legacy\_migration\barrier · high confidence

Isolate capsule loading and enforce secure principal admission in the event dispatcher

The event dispatcher now isolates capsule execution by principal using per-(capsule, principal) chain locks to serialize dispatches safely while allowing concurrent execution for distinct keys. Additionally, it replaces the previous method of resolving the Astrid home directory from the process environment with a secure, in-memory admission cache that validates principal strings without creating or inspecting native filesystem paths, preventing unauthenticated directory creation from arbitrary IPC messages.

crates/astrid-capsule/src/dispatcher · high confidence

Isolate executable capsules by authority

The capsule registry now distinguishes between system-resident and principal-owned runtimes to enforce authority-based isolation. New types (\RuntimeScope\, \RuntimeKey\, \WasmHash\) and methods (\register\_owned\_by\_default\, \replace\_principal\_runtime\, \replace\_system\_runtime\) ensure that system capsules are treated as neutral kernel services while principal capsules are scoped to specific users. The registry also introduces uplink management to track and validate inter-capsule dependencies, preventing unauthorized access or duplicate registrations during runtime replacements.

crates/astrid-capsule/src/registry · high confidence

Prevent shell profile modifications in isolated Astrid home environments

The self-update and initialization logic now detects when the \ASTRID\_HOME\ environment variable points to a non-default location. In these isolated scenarios, the CLI skips writing to shell configuration files (such as \.bashrc\ or \.zshrc\) to avoid polluting the user's global shell environment with PATH entries intended only for the isolated runtime. This ensures that account-level PATH setup only occurs when using the standard default home directory.

_crates/astrid-cli/src/commands/self\update · high confidence

Test coverage

Add structured fuzz testing infrastructure; Added Windows named-pipe security validation tests; Added adversarial capsule fixture for e2e testing; Added integration test suite for security, daemon, and gateway components; Added integration tests for gateway CORS, model routing, revocation durability, and router middleware; Added regression tests for BLAKE3 hashing contract; Added test coverage for daemon lifecycle, security contracts, and self-update verification; Added test for Windows named-pipe authenticated handshake; Added tests for secret isolation and elicit wait-loop behavior; Added tests for workspace branch service isolation and durability; New e2e runtime coverage manifests and concurrency verification; New runtime E2E smoke test suite and test infrastructure; Removed integration test suite for agent runtime and security subsystems.

Dependencies

Initial dependency lock and workspace manifest structure

The repository now includes a generated \Cargo.lock\ file and a set of \Cargo.toml\ manifests for the Astrid workspace crates (including \astrid-build\, \astrid-capsule\, \astrid-cli\, \astrid-core\, \astrid-daemon\, \astrid-gateway\, \astrid-kernel\, \astrid-storage\, and others). This establishes the dependency graph and version constraints for the secure agent runtime, CLI, and kernel components.

(dependencies) · high confidence

Housekeeping

Changelog fragment infrastructure and initial MCP changelog entry

The repository now includes a \changes/\ directory with a \.gitkeep\ file to support the collection of changelog fragments, alongside the addition of a specific changelog entry (1919.added.md) documenting the new opt-in, bearer-authenticated loopback MCP Streamable HTTP endpoint using RMCP 3.2.0.

changes · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 52.

Lenses

  • Code Health 86
  • Architecture 88
  • Maturity 87
  • Readiness 88
  • Security 88
  • Domain Modelling 100
  • Event-Driven 10
  • Event Sourcing 100

Changes since last survey

  • 300 commits — 159 feature/other, 141 fixes

By area

  • (root) — 71 commits
  • crates/astrid-cli — 41 commits
  • crates/astrid-storage — 38 commits
  • crates/astrid-capsule — 35 commits
  • .github/workflows — 22 commits
  • crates/astrid-kernel — 19 commits
  • crates/astrid-storage-engine — 10 commits
  • crates/astrid-gateway — 7 commits
  • crates/astrid-core — 6 commits
  • crates/astrid-audit — 5 commits
  • crates/astrid-capsule-install — 5 commits
  • crates/astrid-storage-model — 4 commits
  • docs/astrid-ai-native-os-workplan.md — 4 commits
  • crates/astrid-build — 2 commits
  • crates/astrid-config — 2 commits
  • crates/astrid-daemon — 2 commits
  • crates/astrid-storage-provider-fuse — 2 commits
  • native/macos — 2 commits
  • scripts/ci — 2 commits
  • .cargo/audit.toml — 1 commit

Notable commits

  • fix: Fix neutral runtime setup guidance (#1227)
  • fix: fix(audit)!: make the audit storage surface genuinely async so it works on wasm32 (#1155)
  • fix: fix(audit): blind payload MOVE into native TreeKvStore (#1597)
  • fix: fix(audit): freeze layout-1 source during MOVE (#1599)
  • fix: fix(audit): isolate chains and bound session indexing (#1489)
  • fix: fix(audit): move layout-1 history with batched native ingest (#1588)
  • fix: fix(build): resolve capsule artifacts from Cargo target dir (#1842)
  • fix: fix(capabilities)!: make CapabilityStore persistence genuinely async so the kernel boots on wasm32 (#1153)
  • fix: fix(capsule)!: serve astrid:process 1.0.0 and 1.1.0 dual-version — restore compat with sdk-0.7.x capsules (#1108)
  • fix: fix(capsule): bind run loops to typed owner context (#1380)
  • fix: fix(capsule): bound WASM growth and in-flight fuel (#1553)
  • fix: fix(capsule): bound framed socket writes so a stalled uplink client cannot freeze the CLI proxy (#1149)
  • fix: fix(capsule): bound process file injections (#1554)
  • fix: fix(capsule): inject AstridHome into EventDispatcher instead of resolving from process env (#1151)
  • fix: fix(capsule): make component→root capability merge exhaustive (#1232) (#1381)
  • fix: fix(capsule): preserve device attenuation in dispatch (#1240)
  • fix: fix(capsule): retire relocated leftover authority receipts (#1585)
  • fix: fix(capsule): skip CoW overlay for git-managed workspaces (#1169)
  • fix: fix(capsule): skip completed principal-scoped installs before InstallCapsule (#1844)
  • fix: fix(ci): cancel superseded pull-request runs (#1839)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

astrid-runtime/astrid was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 12 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0bb64c57a8ec64bc27cc491dc39be9989074a04f — the exact code this score is about.
  • Scored under rubric-2026.09.8 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d1e8be829218.