Documented changes
18 typed entries
Verified contributors
Credits being verified. Attribution coverage is unknown.
Attribution coverage
attribution not yet verified; history inventory partial.
Install
Scope
Guard v3.32.0 is a stable release published 2026-10-07. Upstream documents: Guard 3.32.0 is a stable release cut from [`ea92f41`](https://github.com/hashgraph-online/hol-guard/commit/ea92f414825e2414cf4df67bd0ba49f9b2c8bc90). **8 commits • 6 merged pull requests • 3 contributors** since [Guard 3.31.0](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.31.0). Its comparison base is v3.31.0. Attribution for this release is being verified.
Changes
Added
6- **gauntlet**: Run the Guard Gauntlet on Windows hosts ([#3727](https://github.com/hashgraph-online/hol-guard/pull/3727)) Evidence for: **gauntlet**: Run the Guard Gauntlet on Windows hosts ([#3727](https://github.com/hashgraph-online/hol-guard/pull/3727))
- Run the Gauntlet agent host on Windows inside a kill-on-close Job Object (`ci/gauntlet/windows_job.py`). The host starts suspended and is assigned to the job before it resumes, so every descendant is contained and… Evidence for: Run the Gauntlet agent host on Windows inside a kill-on-close Job Object (`ci/gauntlet/windows_job.py`). The host starts suspended and is assigned to the job before it resumes, so every descendant is contained and…
- Give Windows hosts a fixture-scoped environment. `APPDATA`, `LOCALAPPDATA`, `TEMP`, `TMP` and `TMPDIR` point inside the fixture home, and only the process-launch variables Windows needs are passed through. A host that… Evidence for: Give Windows hosts a fixture-scoped environment. `APPDATA`, `LOCALAPPDATA`, `TEMP`, `TMP` and `TMPDIR` point inside the fixture home, and only the process-launch variables Windows needs are passed through. A host that…
- Bound authenticated daemon calls with a joined worker thread where `SIGALRM` does not exist; the bounded daemon calls now live in `ci/native_runtime/probe_daemon_calls.py`. Evidence for: Bound authenticated daemon calls with a joined worker thread where `SIGALRM` does not exist; the bounded daemon calls now live in `ci/native_runtime/probe_daemon_calls.py`.
- **review**: Show saved business requests in local review ([`f2f76d6`](https://github.com/hashgraph-online/hol-guard/commit/f2f76d675754019ec7f7a4b77aeb3483fca00c34)) Evidence for: **review**: Show saved business requests in local review ([`f2f76d6`](https://github.com/hashgraph-online/hol-guard/commit/f2f76d675754019ec7f7a4b77aeb3483fca00c34))
- **extensions**: Add command.showtime command source ([#3302](https://github.com/hashgraph-online/hol-guard/pull/3302)) Evidence for: **extensions**: Add command.showtime command source ([#3302](https://github.com/hashgraph-online/hol-guard/pull/3302))
Fixed
8- **guard**: Keep existing workspaces admitted while a new workspace policy publishes ([#3726](https://github.com/hashgraph-online/hol-guard/pull/3726)) Evidence for: **guard**: Keep existing workspaces admitted while a new workspace policy publishes ([#3726](https://github.com/hashgraph-online/hol-guard/pull/3726))
- Registering a new workspace no longer withdraws the ACKed native policy snapshot for every workspace or bumps the publish epoch. Only the new workspace waits for an ACK whose compile included its overlay. Workspaces… Evidence for: Registering a new workspace no longer withdraws the ACKed native policy snapshot for every workspace or bumps the publish epoch. Only the new workspace waits for an ACK whose compile included its overlay. Workspaces…
- The background reconcile loop ignores overlays of workspaces still waiting for their first ACK. Before, a new workspace with a stricter overlay looked like an effective policy change for everyone, withdrew the ACK… Evidence for: The background reconcile loop ignores overlays of workspaces still waiting for their first ACK. Before, a new workspace with a stricter overlay looked like an effective policy change for everyone, withdrew the ACK…
- Publication compiles exactly the workspace set its ACK releases. A workspace registered while a compile is running stays pending for the next publish. Before, its overlay could reach the ACKed snapshot early, so the… Evidence for: Publication compiles exactly the workspace set its ACK releases. A workspace registered while a compile is running stays pending for the next publish. Before, its overlay could reach the ACKed snapshot early, so the…
- **guard**: Review Windows source reads through a handle-bound path walk instead of blocking every read ([#3718](https://github.com/hashgraph-online/hol-guard/pull/3718)) Evidence for: **guard**: Review Windows source reads through a handle-bound path walk instead of blocking every read ([#3718](https://github.com/hashgraph-online/hol-guard/pull/3718))
- On Windows the native runtime's `secure_open` always returned `PathChanged`, so every PostToolUse source review failed. Each ordinary file read by Pi/omp came back as `no_output_to_review` and its output was blocked. Evidence for: On Windows the native runtime's `secure_open` always returned `PathChanged`, so every PostToolUse source review failed. Each ordinary file read by Pi/omp came back as `no_output_to_review` and its output was blocked.
- `secure_open` now walks the canonical path through `guard_runtime_windows_process::open_bound_regular_file`, in the new `bound_open.rs`. Evidence for: `secure_open` now walks the canonical path through `guard_runtime_windows_process::open_bound_regular_file`, in the new `bound_open.rs`.
- Each ancestor directory is opened with `FILE_TRAVERSE | FILE_READ_ATTRIBUTES` and held without delete sharing until the leaf is open, so no component can be renamed or swapped for a link mid-walk. Evidence for: Each ancestor directory is opened with `FILE_TRAVERSE | FILE_READ_ATTRIBUTES` and held without delete sharing until the leaf is open, so no component can be renamed or swapped for a link mid-walk.
Other changes
4- Documented change: Guard 3.32.0 is a stable release cut from [`ea92f41`](https://github.com/hashgraph-online/hol-guard/commit/ea92f414825e2414cf4df67bd0ba49f9b2c8bc90). **8 commits • 6 merged pull requests • 3 contributors** since [Guard 3.31.0](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.31.0). Evidence for: Documented change: Guard 3.32.0 is a stable release cut from [`ea92f41`](https://github.com/hashgraph-online/hol-guard/commit/ea92f414825e2414cf4df67bd0ba49f9b2c8bc90). **8 commits • 6 merged pull requests • 3 contributors** since [Guard 3.31.0](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.31.0).
- **guard**: Reset cwd compound fixtures before reuse ([#3729](https://github.com/hashgraph-online/hol-guard/pull/3729)) Evidence for: **guard**: Reset cwd compound fixtures before reuse ([#3729](https://github.com/hashgraph-online/hol-guard/pull/3729))
- **runtime**: Verify durable business budgets across stores and processes ([`de7b62f`](https://github.com/hashgraph-online/hol-guard/commit/de7b62f0f8ceaecc34bc2c6e69f50177c097eff0)) Evidence for: **runtime**: Verify durable business budgets across stores and processes ([`de7b62f`](https://github.com/hashgraph-online/hol-guard/commit/de7b62f0f8ceaecc34bc2c6e69f50177c097eff0))
- **release**: 3.32.0 ([#3723](https://github.com/hashgraph-online/hol-guard/pull/3723)) Evidence for: **release**: 3.32.0 ([#3723](https://github.com/hashgraph-online/hol-guard/pull/3723))
Upgrade and compatibility
None documented.
Compare with the previous release
Predecessor on the same channel: v3.31.0
Verified contributors
Credits derive from public pull-request authorship, verified commit authorship, or verified co-authorship — never from thanks text or release metadata. Each distinct contributor is listed once; the evidence ledger paginates every published credit record.
Evidence ledger0 credits
No credits are published for this release yet.