October 2, 2026
Release Notes: New App Shell, Bench Campaign Mode, and a GDPR Fix
v0.3.227 shipped October 1. The headline is a full redesign of the logged-in Cloud portal, but the release also brings campaign mode to bench-chunked, fixes GDPR account erasure for users with audit-log rows, and clears two wasmtime security advisories. Here's what changed and why.
A calmer app shell
The post-login portal grew organically, and it showed: inconsistent headers, a search box that didn't search much, and a dashboard that cheerfully reported "All Systems Operational" no matter what. We rebuilt the shell around a denser, calmer product-UI system.
- Task-based sidebar. Navigation is grouped by what you're doing — Mocks, Protocols, Flows, Observe, Test & Verify, Resilience, AI, Ecosystem, Settings — with groups that fold and remember their state. There's a workspace switcher and the user menu moved to the sidebar footer.
- Command palette.
⌘K/Ctrl+Kreplaces the old header search: pages (including keywords and section names), recent pages, workspace switching, theme and refresh actions, and free-text log or service search that honors your default-scope preference. - Dashboard that tells the truth. KPIs come first, then latency distribution, status breakdown, and servers/traffic. Health is now derived from server state and error rate instead of a hardcoded banner. Latency percentiles also render correctly now (p50 vs a bare "ms").
- Design-system cleanup. Refined neutral tokens in light and dark, calmer primitives (buttons, cards, metric cards with tabular figures), one input spec across every form, and
prefers-reduced-motionhonored globally. Dark mode got real fixes too — World State nodes, the Orchestration Builder panel, and the Registry Admin code block were hardcoded to light colors.
Around forty pages were normalized onto the new shell in a follow-up pass: consistent page titles, aligned padding, readable badge contrast, and an error boundary that stays inside the shell with collapsible dev details. Cloud builds also stop showing a phantom "Disconnected" status.
Campaign mode for bench-chunked
The Reality benchmarking side keeps gaining parity with mockforge bench. bench-chunked now supports --rps N (per-target cap on request starts per second) and --cps (new TCP/TLS connection per request), plus campaign mode: --rounds N or --repeat-until <duration> re-runs the whole pass into <output>/round_N/, with per-round stats in campaign.jsonl and round-summaries/, and --keep-rounds N rotating old round directories.
There was also a timing bug worth mentioning: --chunk-interval-ms used to wait before the first chunk and then send the last two back to back. It now sends the first chunk immediately and waits only between chunks, which is what the flag always promised.
GDPR erasure that actually erases
Account erasure no longer fails for users who have audit-log rows. This is the kind of bug that quietly breaks a compliance promise: the delete path worked in testing, then failed in production for exactly the long-lived accounts most likely to request erasure. If you run a hosted service with an audit trail, it's worth checking that your own erasure path handles the rows your audit trail creates.
Security hygiene: wasmtime 36.0.16
A lockfile-only bump clears RUSTSEC-2026-0314 and RUSTSEC-2026-0316, including a wasmtime-wasi issue where a guest could panic the host through a filesystem datetime overflow. Our security-audit CI job caught it; the fix was a patch release with no code changes.