Skip to content

Commit 7f4eb0b

Browse files
authored
chore(release): prepare Hawk v0.2.0 (#94)
1 parent 1524208 commit 7f4eb0b

5 files changed

Lines changed: 34 additions & 21 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,22 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
77

88
## [Unreleased]
99

10+
## [0.2.0] — 2026-07-13
11+
1012
### Changed
13+
- **Hawk/Eyrie production boundary completed**: Hawk owns the product face,
14+
sessions, tools, permissions, and public schemas while Eyrie v0.2.1 owns
15+
credentials, catalog resolution, provider transport, resilience, and usage
16+
telemetry behind the stable `eyrie/engine` facade.
17+
- **Provider routing and usage attribution hardened**: resolved route changes,
18+
continuation segments, and terminal usage are propagated without duplicate
19+
accounting, and production Eyrie calls use exactly one resilience layer.
20+
- **Daemon conversations are durable**: JSON and SSE chat requests create or
21+
resume persisted sessions, expose stable session IDs, preserve metadata, and
22+
distinguish invalid, missing, and corrupt state.
23+
- **Release and supply-chain gates strengthened**: exact ecosystem Gitlinks,
24+
module/tag parity, Trivy enforcement, public-module builds, SBOM generation,
25+
and cross-platform artifacts are part of the release path.
1126
- **Fixed `/mode auto` misclassifying plain English as shell commands**: `shellmode.ClassifyInput` trusted `exec.LookPath(firstWord)` alone, so any sentence starting with a word that's also a real Unix binary (`make sure this works`, `find the bug in this file`, `kill the old branch`, `sort out the imports`...) was silently executed as a shell command instead of being sent to the model — confirmed 18 of 20 sampled sentences misclassified before the fix. Now a curated allowlist of unambiguous dev-tool names (`git`, `npm`, `docker`, `ls`, `cat`, ...) is trusted immediately, while every other PATH match requires real shell-syntax evidence (a flag, a path, a file extension, or an operator like `|`/`>`/`&&`) before being trusted as a shell command — matching the same ambiguity Warp's own terminal autodetect documents and resolves with a user-configurable denylist.
1227
- **Permission system unified into two independent axes**: the old `PermissionMode` (`default`/`acceptEdits`/`bypassPermissions`/`dontAsk`/`plan`) is removed. `/autonomy` now controls the 5-tier trust ladder (`Always Ask`/`Scout`/`Builder`/`Operator`/`Autonomous`, bare `/autonomy` opens a picker), and `/spec` controls an independent, orthogonal spec-driven workflow gate (`Specify → Plan → Tasks → ApproveImplementation`, bare `/spec` opens a picker) that blocks Write/Edit/Bash regardless of trust tier — including at Autonomous. Fixes a real bug where the old Plan Mode's write-block could be silently bypassed at high autonomy tiers, since tier and mode were checked independently with no ordering guarantee.
1328
- **Fixed `PermissionService.SetAutonomy`/`Autonomy()`**: previously wrote to/read from a shadow field the permission engine's `CheckTool` never consulted, meaning autonomy tier changes may not have reliably taken effect. Now both read/write the same `PermissionEngine.Autonomy` field the check logic uses.

‎README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,7 @@ See [docs/SECURITY-DEVELOPER.md](docs/SECURITY-DEVELOPER.md) for the credential
5959
Optional for contributors:
6060

6161
```bash
62-
go install github.com/GrayCodeAI/hawk@latest # only after Hawk and support repo tags are published
62+
go install github.com/GrayCodeAI/hawk/cmd/hawk@latest
6363
```
6464

6565
## Features

‎VERSION‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
0.1.0
1+
0.2.0

‎docs/architecture/hawk-eyrie-engine-migration.md‎

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -124,9 +124,7 @@ readers remain backward-compatible for at least one release cycle.
124124

125125
## Verification and release status
126126

127-
See `verification-status-2026-07-13.md` for the current evidence ledger and
128-
remaining blockers. In particular, the audited workspace's committed Eyrie
129-
Gitlink, checked-out submodule and `go.mod` module revision do not match. The
130-
source boundary is implemented locally, but that mismatch must be resolved and
131-
verified in both workspace and `GOWORK=off` builds before the migration can be
132-
called release-complete.
127+
See `verification-status-2026-07-13.md` for the evidence ledger. The committed
128+
Eyrie Gitlink, checked-out submodule, and `go.mod` revision now converge on the
129+
published Eyrie v0.2.1 commit. Hawk passed both workspace and `GOWORK=off`
130+
verification, and the final migration revision passed hosted CI before merge.

‎docs/architecture/verification-status-2026-07-13.md‎

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22

33
## Verdict
44

5-
The audited revision set now has a release-aligned Hawk-face/Eyrie-engine
6-
boundary. Local gates and Eyrie's hosted release gates are green; the final
7-
Hawk revision still requires successful hosted CI before the ecosystem can be
8-
declared production-ready.
5+
The audited revision set has a release-aligned Hawk-face/Eyrie-engine boundary.
6+
Local gates, Eyrie's release gates, and Hawk's final hosted pull-request gates
7+
are green. The remaining publication step is the signed Hawk release tag and
8+
its generated artifacts.
99

1010
The architecture and focused hardening tests support this responsibility split:
1111

@@ -25,9 +25,9 @@ Eyrie engine facade
2525
model providers
2626
```
2727

28-
The prior Eyrie release-parity mismatch is resolved by v0.2.1. Final Hawk
29-
hosted CI on the reviewable commit remains the publication gate for a
30-
whole-ecosystem production-readiness claim.
28+
The prior Eyrie release-parity mismatch is resolved by v0.2.1. Hawk PR #92 and
29+
its follow-up documentation sync in PR #93 passed their hosted checks and were
30+
merged to `main`.
3131

3232
## Verified responsibility boundary
3333

@@ -186,7 +186,7 @@ replace final remote CI.
186186
| Python SDK | 288 tests, Ruff check/format and strict mypy | Passed |
187187
| Hawk Cloud queue | focused and full tests, type-check, format, Wrangler checks, direct SQLite check | Passed |
188188
| Hawk full integration | isolated full tests, full race tests, vet and all architecture guards against the completed workspace | Passed |
189-
| Published release graph | Eyrie v0.2.1 gitlink/module parity; two full Hawk passes in workspace and `GOWORK=off` modes | Passed locally; final Hawk hosted CI pending |
189+
| Published release graph | Eyrie v0.2.1 gitlink/module parity; two full Hawk passes in workspace and `GOWORK=off` modes | Passed locally and in Hawk hosted CI |
190190
| Community skills | 303 tests; 12,167 skills passed; zero failures and zero warnings; Ruff, boundary and registry gates | Passed locally with a zero-warning budget |
191191
| Adjacent GrayCode Core | forced 266-test run, lint, type-check, production build, Hawk Cloud contract comparison and package audit | Passed; not a runtime dependency |
192192

@@ -227,12 +227,12 @@ workspace race-and-coverage run passed at 69.0% total statement coverage. Vet,
227227
lint, formatting, all architecture guards, module verification and both
228228
workspace/module vulnerability scans passed.
229229

230-
### Final Hawk hosted CI remains
230+
### Hawk hosted CI passed
231231

232-
The completed local change set must still be committed and exercised by Hawk's
233-
hosted pull-request CI. A production-ready claim depends on those hosted test,
234-
race, coverage, boundary, security, public-module and submodule-parity jobs
235-
passing on the exact reviewable Hawk revision.
232+
The completed architecture change set passed Hawk's hosted test, race,
233+
coverage, boundary, security, public-module, compatibility-matrix, Docker, and
234+
submodule-parity gates on the exact reviewable revision before merge. Release
235+
publication still independently verifies the tagged revision and artifacts.
236236

237237
## Production-readiness exit criteria
238238

0 commit comments

Comments
 (0)