v3.17.2¶
A patch release about proof: what a run recorded, and whether you can still check it afterwards.
Receipts you can re-derive¶
A gate verdict is three-valued, but receipts stored only the outcome, so an auditor re-running the check offline could not tell a refusal from an abstention. Receipts carry the verdict now, and it re-derives without the run (#4182).
Spawn context was assembled from a dozen sources and hashed as one blob. Each part now gets its own content hash in a receipt, in prompt order, so a prompt that changed can be narrowed to the section that changed it (#4303). An agent working inside a subtree is handed that subtree's .sdd/project.md rather than only the root's (#4304). The breakdown surface that never got populated is gone (#4422).
A persistent-agent adapter carries state Bernstein never hashed, so replaying its inputs proves nothing. Those runs mark their artifacts unverifiable rather than verified (#4290), and letta_code declares itself as one (#4289).
The receipt ledger has a pure active-set closure (#4183). LineageGate.check verifies who wrote a permission-bearing file, not what the write grants — the two are different questions and it was answering the wrong one (#3768). Admission receipts were never written at all for an adapter whose name contains a space; the filename is slugged now (#4363). A CAS sidecar read skipped the anchored walk on an assumption nothing enforced (#3582).
Runs that lied about themselves¶
A planning task that decomposed into nothing reported the run as successful. It fails now (#4401). Three /status surfaces counted live agents three different ways, so the same run read as busy on one and idle on another (#4360). A task stranded by a failed dependency stayed stranded after that dependency was retried and succeeded (#4376).
A skip-worktree CLAUDE.md left by a killed run survived reset --hard and poisoned every later run in that checkout (#4394).
Models and transport¶
Every 429 was backed off as a rate limit, including standing account caps that no retry can clear — the agent spent its budget waiting for a wall to move (#4378). The last-green adapter table showed a never-probed adapter as merely stale (#4387).
The assembled system prompt now has a spawn-time budget: over a configurable share of the model's context window it warns, naming the sections responsible (#4377).
Security¶
A resume whose grant moved is refused before the first side effect, not after (#3834). The skills and MCP catalog fetchers reject internal-host destinations (#4301, #4302).
Also¶
RPM never published when the install smoke outran PyPI index propagation (#4383). The metric buffer dropped every target's lines when one target's write failed (#3710). Coverage baseline is 84.08%. Agent working notes under scratch/ no longer ride along in unrelated commits.
Soundtrack: https://suno.com/s/mlHRUsFOZfhEUL96