Skip to content

sheawinkler/ContextLattice

v3.4.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agent-framework agent-orchestration ai-infra ai-interface context-engineering context-management
+4 more
go long-horizon-agents long-horizon-intelligence rust

Affected surfaces

deps

ReleasePort's take

Moderate signal
editorial:auto 1mo

The release upgrades PyArrow to 23.0.1, which resolves CVE‑2026‑25087 in the LanceDB adapter.

Why it matters: CVE‑2026‑25087 (severity 90) is fixed by upgrading PyArrow; operators using the LanceDB adapter must upgrade to v3.4.1 immediately.

Summary

AI summary

Bumps PyArrow to 23.0.1 fixing CVE‑2026‑25087 in the LanceDB adapter.

Changes in this release

Security Critical

Bumped PyArrow to 23.0.1 fixing CVE-2026-25087 vulnerability.

Bumped PyArrow to 23.0.1 fixing CVE-2026-25087 vulnerability.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

`gateway-go` now receives `ORCH_STORAGE_GOVERNANCE_DISK_ROOT` from Compose and defaults to `/data`.

`gateway-go` now receives `ORCH_STORAGE_GOVERNANCE_DISK_ROOT` from Compose and defaults to `/data`.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

Storage‑governance status path defaults to mounted memory lane instead of container overlay filesystem.

Storage‑governance status path defaults to mounted memory lane instead of container overlay filesystem.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

`scripts/verify_storage_mounts.sh` checks that gateway storage‑governance root is `/data` or under `/data`.

`scripts/verify_storage_mounts.sh` checks that gateway storage‑governance root is `/data` or under `/data`.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

Verifier rejects unset, relative, `/`, or overlay‑oriented roots when mounted data lane is intended storage root.

Verifier rejects unset, relative, `/`, or overlay‑oriented roots when mounted data lane is intended storage root.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

Added Codex session‑store audit resolving realpaths before blaming local paths and reporting access status.

Added Codex session‑store audit resolving realpaths before blaming local paths and reporting access status.

Source: llm_adapter@2026-06-06

Confidence: low

Bugfix Low

Added Codex session‑store audit that resolves realpaths and reports read/list/write/traverse status for session directories.

Added Codex session‑store audit that resolves realpaths and reports read/list/write/traverse status for session directories.

Source: granite4.1:30b@2026-06-06-audit

Confidence: low

Full changelog

ContextLattice v3.4.1 - Runtime Hardening + Security Patch

Release date: 2026-06-06

This patch release tightens the v3.4 agent runtime contract after real local operator pressure: storage governance now measures the mounted memory lane, Codex session-store failures are diagnosed before they look like corruption, and the public LanceDB adapter clears the open PyArrow security alert.

v3.4.1 keeps the v3.4 public boundary intact. No external memory API break. No v4 tuning-lane promotion. This is the patch that makes the new runtime contract safer to run on real machines.

What Changed

1) Storage governance follows the data lane

  • gateway-go now receives ORCH_STORAGE_GOVERNANCE_DISK_ROOT=${ORCH_STORAGE_GOVERNANCE_DISK_ROOT:-/data} from Compose.
  • The storage-governance status path now defaults to the mounted memory lane instead of the container overlay filesystem.
  • scripts/verify_storage_mounts.sh now checks that the gateway storage-governance root is /data or under /data.
  • The verifier rejects unset, relative, /, or overlay-oriented roots when the mounted data lane is the intended storage root.

This matters for local-first installs with external drives: ContextLattice should not claim the memory store is under internal-disk pressure when the live memory data is mounted elsewhere.

2) Codex session-store doctor hardening

  • Added a Codex session-store audit that resolves ~/.codex/sessions realpaths before blaming visible local paths.
  • Detects symlinked session directories and transcript samples that cross into /Volumes or TCC/cloud-managed locations.
  • Reports read/list/write/traverse status and concrete failing paths.
  • Wires the check into agent context audits and startup policy so advanced transcript storage does not look like mysterious resume corruption.

Default local ~/.codex/sessions remains the safe path. External or symlinked transcript storage is treated as advanced mode that deserves explicit doctor output.

3) PyArrow security fix for LanceDB adapter

  • Bumped services/lancedb_spike_adapter/requirements.txt from pyarrow==21.0.0 to pyarrow==23.0.1.
  • Resolves Dependabot alert #66 / GHSA-rgxp-2hwp-jwgg / CVE-2026-25087.
  • Vulnerable range was >=15.0.0,<23.0.1.

Public Position

v3.4.1 is the hardening patch for ContextLattice as the local memory spine under agent work.

The product story stays simple: durable memory, scoped recall, checkpoints, handoffs, objective state, behavior provenance, and runtime policy belong behind one local contract. This release makes that contract harder to misread and safer to install.

Validation

Recommended release validation:

scripts/verify_storage_mounts.sh
scripts/agent/audit-codex-session-store --pretty
scripts/agent/audit-agent-runtime-contract --pretty
scripts/agent/audit-universal-agent-adapter --pretty
scripts/agent/audit-agent-output-contracts --pretty
python3 -m py_compile scripts/agent/contextlattice-session scripts/agent/contextlattice-agent-adapter
git diff --check
python3 scripts/submission_preflight.py

For live local validation when the gateway is running:

curl -fsS http://127.0.0.1:8075/status | jq '.ok, .serviceHealth, .storageGovernance.diskRoot, .storageGovernance.pressureBand'
scripts/agent_hooks/native_endpoint_smoke.sh --project context-lattice-private --soft

Expected live storage-governance output for the full local stack:

diskRoot=/data
pressureBand=healthy

Version Boundary

  • Public v3.4.1: patch-level runtime hardening, security fix, and local install diagnostics.
  • Public v3.4.0: stable public agent runtime contract and universal adapter surface.
  • Private v4: tuning, experiments, and promotion candidates that still require benchmark, recall, and soak gates.

Security Fixes

  • CVE-2026-25087 — Bumped pyarrow from ==21.0.0 to ==23.0.1 in services/lancedb_spike_adapter/requirements.txt (Dependabot #66, GHSA-rgxp-2hwp-jwgg)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track sheawinkler/ContextLattice

Get notified when new releases ship.

Sign up free

About sheawinkler/ContextLattice

Private-by-default memory and context layer for agents with Go/Rust runtime, staged retrieval across fused data backends, and long-horizon context continuity.

All releases →

Related context

Related CVEs

Earlier breaking changes

  • v3.17.3 Agent guidance now mandates the `/agents/tasks` route family.
  • v3.17.3 Task worker now checks approval before any execution steps.

Beta — feedback welcome: [email protected]