Changelog
Preserved release history and version provenance.
0.8.0 - 2026-09-25#
See release notes for changes, availability and current limits.
Release safety#
- Update both Rust lockfiles to rustls 0.23.45 for RUSTSEC-2026-0285, retaining dependency security checks rather than suppressing the advisory.
- Keep Python shutdown hooks and their acknowledgements ahead of a subsequent stdin EOF, while preserving the bounded drain for a non-cooperative hook.
- Retain Rust 1.86 compatibility in process event-bus response admission.
Interaction#
Accept owner-bound
/subagents stop <name|all>during active responses without blocking input or mistaking interruption acknowledgement for worker settlement. Show compact K/M/B/T token counts, visible stop guidance, and continuation rows aligned with Thinking, while preserving exact accounting and native scrollback.Offer first-run setup in the order API key, supported OAuth subscription, then local/self-hosted models. API keys use masked input and explicit review, with recoverable owner-private storage rather than hashes or an encryption claim. ChatGPT (Codex) and GitHub Copilot reuse host-owned device login; configured launches and noninteractive modes do not reopen onboarding.
Silence routine session lookup/replay/fork progress during startup, including resumed launches. Keep input, setup, errors, and coordinated shutdown live. Fresh launches skip the unnecessary session-replay worker and full-config copy.
Quiet routine reload output: remove the startup arming banner, queued-path chatter, and automatic success summaries. Only explicit reload commands get a completion summary. Host, worker-deferral, extension, provider-catalog, and watch-limit problems appear once per component/condition and reappear after a successful check clears them; skipped components retain their diagnostics. Resource/bootstrap and keybinding checks now use the same checked-component recurrence rule, without hiding explicit command diagnostics. Actual work losses are always reported, counting only discarded extension host requests. Automatic permission paths never open a picker or probe an unconsented replacement; explicit consent remains required. Watch/timing details remain available through
/reload --dry-run.Hide the root elapsed clock while retry status is active, including after its countdown expires, while keeping the interrupt hint. Normal Working/Thinking elapsed clocks are unchanged.
Ease the resting activity colours off the profile extremes: the dark theme's Working/Thinking label now rests at a slightly greyed off-white (about #f9 instead of #fd) and the light theme's rests at a soft near-black (about #16 instead of #00), each with the sweep ceiling moved to keep the travelling band and the margin dot's pulse at their previously pinned separations. The light bound is measured, not chosen: a 0.009 rest fails the pinned 1.7:1 worst-case cell separation for a blue identity after ANSI256 quantization, so the rest sits at 0.0085 and the light sweep ceiling moves 0.09 -> 0.095 to preserve the pinned 0.08 relative-luminance travel.
Add the hidden
/debugcommand (exact name only; absent from the popup and/help). It writes an owner-private~/.octet/octet-debug.logwith the terminal size, every rendered line plus its visible width and the agent messages as JSONL, then reports the path; an in-flight run is read through the inspection snapshot, so the dump never disturbs the frame coalescer.Add
/session, reporting the session file, id, title, head, entry and active-branch message counts, checkpoints, usage records, the token buckets and exact cost, and marking unknown exposure as a known subtotal instead of presenting it as exact.Add
/settings(defaults, theme, images and default model/reasoning; the transport and editor padding are reported as read-only route/theme facts) and/scoped-models(ordered Ctrl+P scope persisted as the usermodelskey), and!command/!!commandlocal shell escapes that record their result as model-visible or explicitly excluded from model context.Withdraw the
/treeand/checkoutslash commands (maintainer decision) with their keybinding: the durable connector tree stays available throughoctet sessions inspect, and branch movement stays available through the session surfaces that own it./quitis renamed/exit;/quitis no longer parsed.Restore the full
/modelpicker for a launch that pinned a built-in model. Startup narrows the catalog to the selected route for latency, and the picker rendered that narrowed catalog, so a DeepSeek launch listed only DeepSeek models even with other provider credentials in the environment. The picker now completes the deferred provider inventories (and refreshes the scoped-model cycle) before it lists, and an active run defers the picker to the next idle boundary instead of showing a partial provider list.Slash commands now work while a run is active.
/help,/cost,/cache,/tree,/context,/update,/name,/export,/extensions status,/extensions inspectand/thinkingrender or open their real surface immediately instead of being queued to the next idle boundary;/modelopens its picker inline. Previously these commands were unusable during streaming.Add platform-aware discoverability hints, including the queued-follow-up edit binding (
option+↑on macOS,alt+↑elsewhere).Keep startup silent and the composer editable while extensions initialize; defer model-context notices until terminal teardown.
Let
/goalmutate and report the durable goal during an active response.Give activity shimmer a complete sweep and rest phase. Working and Thinking share a model-derived hue family; neutral identities stay neutral in both appearances. Physical-terminal appearance remains a separate acceptance gate.
Display plain-dollar footer costs without weakening durable uncertainty or budget accounting.
Redesign the
/subagentspanel: group by state with counts, collapse terminal groups by default, aligned columns with a header row, bounded failure reasons and bounded rendering.Stop rendering absence as text in subagent rows:
no ceiling,inherited no ceilingand every?placeholder are gone, elapsed and token counts are human-formatted, and no internal Rust API or operation id is printed into the transcript.Add the interactive live-reload supervisor: the prompt samples the skill, prompt, theme, context-file, keybinding, settings, and extension roots in use plus the resolved executable (
current_exe()re-resolved every poll) on a bounded 1000 ms metadata poll, and applies a pass only at the idle prompt in the order host eligibility/consent → resources → extensions; an admitted host replacement supersedes in-process rebuilding. Saves are debounced (200 ms, 2 s hard ceiling) and coalesced; a pass is never admitted while a run owns the session, so evidence queued behind a busy boundary is applied at the next idle prompt. It is enabled silently by default;/reload --dry-runexposes watch settings and per-layer details, while automatic passes omit success summaries;reload,reload_poll_ms,reload_debounce_ms, andreload_max_filesare user-level settings,/reload --dry-runpreviews a pass without changing anything, and/reload --forcetakes one at the idle boundary while previewing possible interruptions from currently pending host requests and workers. Plain/reloadrebuilds resources/extensions without selecting the host layer./reloadnow also reloads the host binary. When the executable on disk changed, the candidate is validated first with a side-effect-free internal probe (--internal-reexec-probe, which initializes no provider, extension, workspace or network work) and its generation is re-stated immediately before the jump, so a build replaced mid-probe is never executed. The reload happens at an idle boundary only and refuses while a model turn, tool call, shell child, effect approval or in-flight session write is live; live delegated workers become an explicit opt-in that flushes their durable records and detaches them for reattachment. The new image keeps the same PID and resumes exactly the session that was running (--resume <id>), extension children are stopped through the bounded path, session-lock descriptors areCLOEXECso the new image can re-lock its own session, and nothing ever locks the executable — so several panes and a runningservereload independently.Late
providers/register,providers/updateandproviders/unregistertake effect in the running session without a reload. Credentials, endpoints, headers, transports, callbacks and OAuth payloads stay host-owned; a late registration never overrides a built-in the user did not opt into; pricing and capability validation still run before a model becomes routable; and an in-flight request is never mutated — the change applies at the next request boundary.
Codex subscription behaviour#
- Make the deliberate 272K Codex request cap visible and overridable instead of silent. It remains the default because OpenAI recommends a 272K Codex context limit, usage above 272K is double-priced, and oversized long-running sessions can drop the Codex websocket.
- Emit at most one bounded clamp notice per session, for the effective model only, and only when that model is a Codex route.
- Add an explicit opt-in override (
--codex-context-window, the equivalent environment variable, and the reasoning/effort menu) that requires the Pro/ProLite entitlement and a separate acknowledgement naming both consequences; un-acknowledged or above-entitlement values fail closed. - Record cost and usage above 272K as uncertain rather than exact
(
Session::record_usage_uncertainty), since the whole request is priced at the long-context tier rather than only the excess. - Keep WebSocket connection-limit retries in the host's physical-attempt budget instead of secretly resending inference in the transport. Stored-response cursor recovery is bounded; ordinary non-stored Codex responses cannot be resumed by inventing a new request after output has begun.
Subagents#
- Keep the live worker roster in bounded pinned chrome above the composer while
any retained worker is active, independently of root-run activity and app-owned
history navigation. Hide it after settlement while retaining telemetry,
accounting, and the
/subagentsinspector. Metric changes do not dirty history; raw first-party orchestration calls/results and worker transitions add no automatic transcript or copy notices. Ordinary failures and approvals retain their existing owners. Native-scroll regression coverage retains interleaved commands, results, and answers exactly once, rather than clipping them into a pending-tool preview. - Bound the strip to one third of terminal height and available space; omitted
rows point to
/subagents. Native terminal scrollback cannot overlay chrome. - Stop truncating worker model ids: worker/state/model are mandatory columns
that never ellipsize, optional metrics drop first, and the compact fallback
line still prints the full model. The
/subagentspicker header is now the stable surface nameSubagents, with counts in rows/status rather than the title. - Remove the
completed with warningsstate from the TUI: both completed variants render the same✓ completed · <duration> · <rate> tok/sline and the same success role, and the counts stay in the model for exit status and telemetry. A completed turn with live workers now shows one subduedsubagents are running; inspect them in the /subagents menu.line. - Add bounded
/subagents open-all tmux|herdrplanning and multiplexer adapters. Product pane execution is disabled for all workers and the parent until the host provides atomic writer claim/settlement. An opaque handle or fresh launchability snapshot is not a writer lease; adapters are directly tested, not qualified live handover. - Keep API 0.2 child model execution inherited. Requested provider/model/reasoning metadata does not establish multimodel execution; unsupported selections fail closed rather than silently selecting another model.
- Workers survive the parent turn: durable child records are owned by the session rather than the run, with reattachment on a later turn and an explicit parent wait. A detached worker parks at the approval boundary in a bounded state instead of mutating unattended.
Providers, codecs and tools#
Refresh reviewed models.dev metadata to 895 pricing routes, 385 canonical names, and 916 capability routes; preserve the source provenance. Builds and runtime remain offline, direct DeepSeek schedule pricing remains excluded/unknown, and public metadata does not establish live inference acceptance.
Decode OpenRouter's per-model
reasoningobject (mandatory,default_enabled,supported_efforts,default_effort) instead of treating the presence of areasoning_effortparameter as proof that reasoning is optional. A mandatory model no longer receives a disablingreasoning.effort=none, which OpenRouter rejected with HTTP 400; it receives the endpoint's default effort or an advertised exact effort, and a savedoffis clamped to a supported choice. Advertised effort strings are sent verbatim.Share a 64 MiB / 32-file Bash spill budget per owner, including active captures; evict oldest files and move disk capture/cleanup off the async path. Keep the 16 MiB per-stream cap and distinguish expired, partial, and complete spills.
Advance Responses replay/capacity projections by suffix, retain control-queue reservations through delivery, and cap combined extension schemas at 4 MiB.
Decode the reasoning a provider advertises through accepted request parameters (
supported_parameterscontainingreasoning,reasoning_effortorreasoning.effort). It was read as an undecodable assertion, so a newly released gateway model had thinking permanently Off until the pinned metadata snapshot was refreshed and the binary rebuilt. An explicit negative assertion still wins.Name the reasoning-only failure separately: a turn that finishes normally with thinking but no answer text now reports "provider returned reasoning but no answer text" instead of the generic empty-content message.
Reserve bounded headroom (1% of the window, 256–4096 tokens) between octet's input-token estimate and the provider's own count when deriving a request's output cap. Sizing the request as exactly
window − estimateput real local servers one token over the limit, which they reject outright.Recover a size rejection instead of failing the turn: local compaction now runs and the request is retried for HTTP 400/413/422 responses that carry a numeric provider code, which previously took the permanent-failure branch. Named policy, auth, quota and rate-limit rejections still fail closed without compacting, and a session with nothing reducible reports the limit.
Add strict JSON-schema and grammar/regex request declarations, and remove a declared-but-unimplemented deferred-tool capability claim. Grammar custom-call decoding and history/result replay remain incomplete; declarations alone do not establish complete codec support.
Land Anthropic caller-beta merge, refusal fallbacks, and the Mistral Conversations finish/base-URL classification fixes that previously failed assertions.
Wire the agent's optional service tier into live
ResponsesOptions, gated by the declared route capability, and select it through/fast. Tier-aware settlement applies the declared Codex tariffs to the provider's echoed tier, and the conservative reservation prices the same worst case; the command retains its durable priority-uncertainty marker and does not clear historical exposure.Let sparse built-in inventories inherit the pinned models.dev input modalities and context/output limits — but only where the endpoint asserts nothing. Direct DeepSeek publishes identifiers only, so
deepseek-flash(V4.1 Flash) previously registered without image input (attachments failed closed with "Image input is unsupported") and with the generic 128K/64K placeholder instead of its documented 1M context / 384K output, silently capping the usable window. An endpoint that asserts any modality or limit — including an explicit text-only list or a smaller window — still wins, a snapshot entry that declares text-only input keeps that decision (deepseek/deepseek-v4-prostays text-only), and a model absent from the pinned record keeps the conservative fallback.Add an assistant-message frame encoder/reducer and a bounded partial-message journal. Partial recovery observations do not replace authoritative usage or tool-outcome records.
Add typed provider declarations covering sampling params, headers,
vllmPriority,supportsMaxOutputTokens, thinking-token budget fields,$varchat-template interpolation and bearer-token credential aliases.Tool behaviours: bash output spill, bounded interval checkpoints and the session environment contract; original-file non-overlapping multi-edit with legacy normalization; preview coalescing and unanimous finalized-result batch termination; invocation-memo and deferred-handle primitives; summarization retry distinct from compaction failure. The agent tool surface stays
read/write/edit/bashwith opt-in ripgrep-backedsearch;ls,find, andgrepoperations usesearch(rg) orbash.
CLI and sessions#
Remove the 64 MiB session-catalog cliff; use indexed substring search, targeted lookups, and bounded maintenance batches without capping total disk.
Add
--powershell(additive Windowspowershellopt-in, reported inert on other hosts, conflicting with an exclusive--tools/--no-toolslist) and ordered--modelspatterns that resolve a literalprovider/model/bare-id reference exactly before globs, preserve the requested order and keep each:levelreasoning suffix.Add
--mode jsonsession-event JSONL,--list-modelssearch,--session-id/--name, sequential positional prompts with bounded@fileand media expansion, and piped stdin in every mode.Keep
--no-sessiontranscripts ephemeral while preserving usage from every RPC session; failed accounting appends retain private accounting-only recovery and retry idempotently without restoring conversation data.Add incremental session/entry search backed by a disposable SQLite projection that re-reads only changed transcripts, and fail-closed catalog publish gates (checksum, count, schema, minimum client version, required providers) with an immutable install path.
Add single-file HTML session export with a script-free escaping CSP.
Accept a session name when starting
octet serve.Split configuration diagnostics into a dedicated module without behaviour change.
Telemetry#
Move optional JSONL writes to an ordered 256-record / 1-MiB worker with observable loss/failure and bounded lifecycle drain; durable accounting stays authoritative and unchanged.
Add a callback-based, vendor-neutral telemetry substrate (
TelemetryContext/TelemetrySpan, NOOP and InMemory implementations, serializable typed schema and a span-assertion harness) with no global and no exporter, and wire run, turn, provider-request, provider-stream, tool, compaction, summary and delegation span boundaries.Keep accounting independent of observation: the JSONL observer and the fail-closed uncertain-usage path are unchanged, and identical business outcomes are asserted under NOOP and InMemory.
Fold tool and summary usage into totals with a cache-hit rate and a distinct
cacheWrite1hbucket, preserving uncertainty.
Editor and TUI#
Make Option+Up/Alt+Up recall the newest editable pending message instead of only local follow-ups: a Ctrl+S live-steering submission is now withdrawn from the agent before persistence, releasing its reserved control budget, so the recalled text is never also delivered. Recall is arbitrated by that submission's own receipt rather than the delayed delivery event, so it fails closed once the agent has claimed the input for the session. Sticky
/answerinput remains deliberately non-retractable, and the pending-state hint only advertises the affordance while an editable entry exists.Render Pi-style
$…$,$$…$$,\(…\), and\[…\]math through the existing LaTeX engine, preserving currency, code, incomplete expressions, and unsupported source rather than displaying partial art. Broaden bounded Mermaid flowcharts with upstream layout, subgraphs, reverse directions, node lists, and labelled links. Unsupported diagrams retain source with a visible reason; diagrams wider than the viewport show source rather than cropped art. Explicit grok-mermaid oracle fixtures do not establish full Pi renderer equivalence.Keep active inspection and consent panels inside the polling run loop. Use shared semantic snapshots and renderer-private layout, with post-write revision-fenced geometry and consent receipts instead of a long-held input lock.
Bound undo and redo to 64 snapshots / 4 MiB each, with oversized-edit barriers.
Add reusable keybinding parsing/conflict detection, editor undo/redo, kill/yank, word/line actions and OSC 133 zone primitives. Product key dispatch, user-binding loading and viewport prompt jumps remain incomplete.
Preserve focus reporting with focus-out interaction reset.
Port LaTeX rendering (symbol tables, parser, fraction/operator/matrix layout) and add a bounded, self-contained Mermaid box-drawing engine; both fail closed on unsupported syntax instead of misrendering it.
Herdr integration#
Report octet's agent lifecycle to Herdr from the interactive frontend, so a pane running octet appears as a first-class agent in the sidebar, agent list, state rollups, notifications, and waits. The implementation follows Herdr's official Pi integration (integration version
- on the documented custom-agent surface:
pane.report_agentfor semanticidle/working/blockedstate,pane.report_agent_sessionfor session identity, andpane.release_agenton exit, with a strictly increasingseqseeded from wall-clock milliseconds so a restarted process cannot report stale sequence numbers.
State comes from the run stream itself — ready at startup,
workingfrom the moment a prompt is accepted,blockedwhile an approval or input prompt is on screen, andidlewhen the run settles — so the pane cannot disagree with octet. Reporting is bounded to one 500 ms socket attempt plus one 1500 ms retry, silent on every failure, and active only whenHERDR_ENV=1with a pane id and transport, so it is a complete no-op outside Herdr. A slow Herdr server can add at most the bounded delivery attempts at a report boundary. Only the opaque session id (never a transcript path) and the bounded on-screen approval prompt leave the process; display-only presentation stays withherdr pane report-metadata.Transports are direct socket IPC on
HERDR_SOCKET_PATH(Linux/macOS) and the documentedHERDR_BIN_PATHCLI wrapper (Windows), each as an argv list with no shell.- on the documented custom-agent surface:
Resume octet sessions in restored Herdr panes without a Herdr-side change, using Herdr's documented plugin surface instead of a native agent kind. While octet runs in a pane it keeps one small owner-private record (
pane id, Herdr session scope, session id, cwd, session-store root, workspace, pid) under~/.octet/herdr/panes/, andoctet herdr install-plugingenerates a manifest whose single[[startup]]hook isoctet herdr restore— no events, actions, panes, build steps, or state outside octet's own directories. Herdr runs startup hooks after it restores the session and the API socket is ready, so that pass reopens each recorded pane withoctet --resume <id>and the recorded--session-dirand--workspacescope.The pass is bounded and fails closed: records are capped, size-limited, owner-private, written atomically, pruned after 14 days or when their pane is gone, and only resumed when the record belongs to this Herdr session, the pane still exists, it currently hosts no agent, and its directory still matches the recorded one. At most 16 panes per start; every skip is reported with its reason; session ids are token-validated and absolute paths are bounded and shell-quoted. The pane-list response is drained concurrently and capped. The record survives a Herdr server stop (
SIGHUPto the pane, measured against Herdr 0.9.0) and is dropped on a deliberate exit, so a later restore never resurrects a session the user closed. Seedocs/herdr.md.
Repository tooling and docs#
- Add
scripts/changelog.py(release extraction and link repair) andscripts/create-source-archive.py(deterministic source artifact). - Add Codex context documentation; remove obsolete planning, comparison, and task-handoff records from public documentation. Remove accidentally tracked Swift build caches and reject them in deterministic source archives.
- Keep benchmark measurement verdicts separate from release approval: an external PID snapshot cannot satisfy inference attribution or cross-platform review.
Candidate limits#
This candidate is not published or live-qualified. Native companion apps remain source-only; signed installation, real-terminal behavior, Windows PowerShell, and live-provider acceptance are not established by deterministic fixtures. The candidate notes describe remaining scope limits.
0.7.6#
- Fix stale models.dev integration for discovered names, context/output limits and advertised thinking, preserving explicit provider API assertions.
- Recognize DeepSeek V4.1 Flash correctly; refresh and review the checked-in rich metadata snapshot before release, without network access during compilation.
- Remove the duplicate working-directory line from the TUI splash while keeping the footer path and narrow-terminal behavior.
- Align active first-party distribution versions to 0.7.6; independent API, protocol, example and historical-release identities remain unchanged.
- See hotfix notes and the exact GitHub release for validation, signed publication and public-install results. No all-provider or live-inference qualification is claimed.
0.7.5 - 2026-09-11#
- Repair stale startup splash rows after model switches.
- Keep activity and compaction shimmer on a monotonic clock, skipping missed frames instead of replaying them in bursts.
- Group live model, reasoning, context and cumulative cost in the default footer, with the working directory right-aligned and safe narrow-terminal fallbacks.
- Add honest installer/updater progress on stderr; success requires the exact installed version, not just a completed download.
- Add a quiet, non-blocking startup update notice and a rich, scrollable
/changelogcommand with a splash reminder. - Avoid misleading project-skill warnings when the same root is already a user skill directory, without relaxing actual project trust checks.
- Correct stale publication-status documentation shipped with 0.7.4, and retain linked public reference files across documentation package layouts.
- Bound installer-script downloads independently of curl's version, and bound both pre- and post-install version checks by time and output size.
0.7.4 - 2026-09-11#
- Add host-qualified Codex interrupted-inference recovery and separately paced, cancellable pre-send waiting without restarting tasks or replaying committed tools.
- Preserve accepted controls and durable failed-attempt usage uncertainty across resume, including truthful known subtotals and hard-budget enforcement.
- Keep API-wait presentation responsive with attempt-owned rollback, operation-scoped recovery status and length-adaptive activity shimmer.
- Fix three medium-severity Vitest alerts and scoped maintenance (#411).
- Overlap independent provider discovery in bounded batches and reduce usage reconciliation allocation; retain matched measurement limits.
- Improve ANSI256 Light added-diff contrast and limited-colour splash logos.
- Publish signed native/Serve packages and four exact-host executable bundles. Independent APIs and schemas remain unchanged; registry channels are separate.
- See release verification and the documentation correction. A subsequently reported Ghostty-to-SSH model-switch regression is addressed in 0.7.5; weeks-long endurance and full Codex parity are not claimed.
0.7.3 - 2026-09-09#
See the release notes for scope and remaining terminal qualification limits.
Fixed#
- Apply contrast-aware 256-colour approximation across the full TUI while preserving true-colour, ANSI16, and no-colour behavior.
- Preserve streaming work and stabilize Markdown rendering, compact subagent presentation, model picker navigation, and composer chip editing.
- Enforce safe tool ordering and repair the Browse setup-test readiness race.
Added#
- OpenRouter batch handling and Luna model support.
Changed#
- Align product, SDK, Serve, and first-party bundle versions to 0.7.3.
- Resize and genuine historical updates can still clear/replay scrollback; full terminal qualification remains open.
0.7.2 - 2026-09-08#
See the release notes for verified signed Native/Serve publication, public-install checks, and known terminal-protocol limits.
Fixed#
- Defer the first branded startup frame until model/setup state, workspace, and appearance are resolved; start its animation at readiness.
- Consume late terminal background replies and recognized fragmented OSC 11 bodies before editor input; retain bounded Escape-key ambiguity handling.
- Navigate path and
@file completions with Up/Down and accept the selected result with Tab, preserving editor movement when no menu is visible. - Indent subagent transcript rows beneath their heading and omit per-worker call counts without removing state, tokens, cost, or underlying telemetry.
- Limit terse Bash command previews to three visual lines plus a hidden-line count; Ctrl+O reveals the full retained command.
Changed#
- Full access implicitly trusts explicitly enabled executable extensions; installed bundles remain disabled by default. Safe mode retains its permission/execution boundaries and does not inherit implicit trust.
- Align product, SDK, Serve, and first-party distribution versions to 0.7.2; independent extension APIs and native-host protocol versions are unchanged.
0.7.1 - 2026-09-07#
See the release notes for publication and verification evidence.
Added#
- Added first-install Auto/Light/Dark appearance selection with preview and
persistence, plus
/themefor later changes; configured and non-TUI launches do not reopen onboarding.
Fixed#
- Made startup presentation capability-safe and refreshed the welcome prefix across animation, overlays, theme/model changes and redraws (#367).
- Suppressed duplicate prompt replay in interactive plain mode while preserving explicit one-shot and piped prompt output (#368).
- Added bounded retries across trusted release GET headers and streamed bodies for transient timeouts and HTTP 408/429/5xx; validation failures are never retried (#369).
- Preserved application-viewport scroll anchors across coalesced tool and subagent updates, including worker-roster insertion and reflow.
- Selected model-supported reasoning for local compaction and auxiliary requests instead of forcing unsupported Off; explicit user selections remain unchanged (#370).
Changed#
- Use the canonical
skaft-software/octetsource/release repository after #366; immutable v0.7.0 assets retain their original signing identity. - Aligned product, SDK and first-party extension distribution versions to 0.7.1; extension API and native-host protocol versions are unchanged.
0.7.0 - 2026-09-06#
Added#
- Added repository documentation, usage examples, and the octet Brand Kit.
Changed#
- Adopted the octet product name,
octetandoctet-hostbinaries,octet-*packages,OCTET_*settings, and.octetdirectories.
Fixed#
- Fixed provider-start retry handling, typed-media validation, and local compaction replay.
- Fixed narrow terminal layouts and duplicate startup rendering.
0.6.7 - 2026-09-02#
Fixed#
- Keep remote Streamable HTTP MCP unavailable by default: only the one-shot
process-owner CLI opt-in
--experimental-streamable-http-mcpcan pass the gate to the first-party bridge. Project/global/session configuration, environment, and manifests cannot activate it; stdio MCP is unaffected. - Fully neutralize Git clean/process filters from repository, worktree, and included configuration during Serve status refresh. Filter names that cannot be represented safely, including invalid UTF-8 and delimiter-bearing names, now fail closed before Git status can execute them.
0.6.6 - 2026-09-02#
Added#
- Add deterministic, no-lifecycle npm packages for the native launcher and supported runtimes, with exact global-update detection and protected trusted publishing/recovery gates.
- Add an offline Homebrew formula generator and protected tap handoff driven by signed immutable release metadata.
- Print an exact, shell-quoted session resume command after clean interactive exits and shutdown signals.
Changed#
- Cap authenticated Codex model and request budgeting at 272,000 tokens by default, matching Pi. Smaller provider windows remain authoritative while larger advertised maxima remain available as discovery metadata.
- Preserve DeepSeek V4 discovery context and modality metadata instead of replacing it with placeholder defaults.
- Reuse the durable session catalog and an incremental transcript-search index when Serve lists and searches session history.
Fixed#
- Bound environment credential reads, validate repaired tool arguments against their selected schemas, and retry transient remote reads with bounded backoff.
- Detect half-open Responses WebSockets, report closure progress, and prevent search subprocesses from stalling on saturated output pipes.
- Classify subagent turn-limit settlement as bounded completion and preserve the parent result.
- Isolate ordinary repository-local clean filters from status refreshes and serialize durable goal updates across independently opened processes.
- Resolve and launch Serve's GitHub CLI through a hardened environment and clean up its complete descendant process tree after cancellation or timeout.
- Keep web session selection and stalled resynchronization monotonic and bounded, without replaying stale snapshots over newer live state.
- Reconcile inline terminal scrollback after long transcript shrinkage without corrupting retained rows.
0.6.5 - 2026-08-30#
Added#
- Added
/answer [instruction]to request an immediate final response from gathered evidence. Idle runs begin without tools; active runs persist the directive at the next safe boundary and expose no tools thereafter.
Changed#
Keep authenticated Codex routes on the provider's full advertised context window by default for in-context learning;
compaction.max_active_tokens(for example 272000) optionally constrains the active working set.Reconcile
/contextwith the agent's provider-reconciled semantic context breakdown, including adaptive capacity grids for large model windows.Raise the default model-visible tool-result cap from 16 KiB to 50 KiB while retaining bounded output capture and policy enforcement.
Keep the Responses Lite wire contract serial while host admission overlaps explicitly parallel-safe pure/workspace-read calls; arbitrary shell and mutating effects remain ordered.
Reduce Codex tool-loop latency by enabling provider-advertised tool-call batching without relaxing host-side effect ordering.
Fixed#
- Correct GPT-5.6 Luna and Terra pricing across the OpenAI, OpenCode, and Codex pricing tables to OpenAI's published standard costs ($0.20/$1.20/$0.02/$0.25 and $2/$12/$0.20/$2.50 per million tokens, with matching long-context tiers); previously displayed session costs were about 5x too high for Luna.
- Preserve GPT-5.4 Pro and GPT-5.5 Pro long-context pricing on Codex routes,
exclude OpenAI's rejected base
gpt-5.6alias, and refresh the checked-in models.dev pricing and display-name snapshots together. - Retire a preferred Responses WebSocket before publishing a pre-generation connection-lifetime failure and retry that request through the HTTP fallback; post-generation disconnects remain terminal.
- Use the active model's adaptive accent consistently for slash completion, model selection, session resume, and other picker focus controls.
0.6.4 - 2026-08-30#
Added#
- Added the optional extension
runtime_commandsnegotiation feature so a compatibility process can expose its bounded initialization-time slash-command catalog without duplicating those names in a generated manifest. - Added source-fingerprinted, version-pinned Pi compatibility links for the supported Pi 0.84.4 profile. Generated links remain disabled and untrusted until explicitly activated, reject changed source before import, and report unsupported compatibility surfaces instead of silently accepting them.
Changed#
Estimate the complete next provider request before each model turn. The default compaction threshold now uses the context window with a fixed 16K coding-turn reserve (or larger advertised reasoning floor), while the provider's advertised output maximum remains the request ceiling and is reduced only by actual remaining context capacity.
Reworked the default terminal presentation around one responsive horizontal grid for transcript blocks, prompt cards, composer, footer, and pickers. Submitted prompts retain their original model provenance colour, queued steering stays bounded, and narrow approval and picker layouts preserve the action or identity needed to use them safely.
Keep one authoritative
Workingactivity row until the owning run settles, including after public assistant text, and distinguish normal completion, completion with warnings, interruption, and failure after animation stops.Advance context-capacity estimates incrementally across appended session messages and re-anchor them to authoritative provider usage, avoiding repeated whole-history reconstruction during ordinary multi-turn and tool-heavy runs.
Reduced avoidable transcript reflow and kept active status invalidation local while preserving the complete retained-frame renderer contract.
Fixed#
- Never execute a tool call whose arguments may have been cut off by the provider's output-token limit. Ygg retains the call envelope, discards partial arguments, persists a paired failure result, and asks the model to reissue the complete call.
- Serialize durable goal-store transactions across independent handles and revalidate the lock identity before publication so concurrent goal turns and revisions cannot overwrite one another.
- Keep bounded actionable reasons visible for collapsed run and tool failures, preserve warning outcomes instead of painting them as success, and prevent an approval from being confirmed when its selected action is not visible.
- Bound nested Pi extension-manifest traversal and fail closed on incomplete or replaced migration inputs.
0.6.3 - 2026-08-28#
Added#
- Added opt-in owner-only
ygg.telemetry.v1JSONL measurements for model latency/TTFT, disjoint usage buckets, retries, tool timing, compaction, and bounded run outcomes without recording prompts, arguments, results, or provider payloads. - Added
ygg doctorfor read-mostly local prerequisite, provider, and model visibility diagnostics. - Added reproducible systems-benchmark and Harbor analysis tooling and a compact checksummed Terminal-Bench 2.1 evidence package with explicit surrogate-adjudication limits.
Changed#
- Render active
Workingand fixedThinkingheaders with a bounded, model-adaptive shimmer. The latest explicit reasoning heading and plainCtrl+Ohint now stay on the subdued detail row without changing geometry. - Reconciled provider, session, telemetry, and Harbor token accounting around disjoint uncached/cache-read/cache-write input buckets. Harbor totals now include every durable usage operation and cache writes without adding the cache-hit detail twice.
- Gave every physical retry its own request timing/TTFT lifecycle and labeled telemetry usage as request, operation, or cumulative scope.
Fixed#
- Fail normal terminal responses that contain no visible text, media, or tool call instead of silently reporting success.
- Keep a truthful TUI lifecycle for every active run: open with
Working, promote toThinkingonly on actual reasoning deltas, use visibly streaming assistant text as the liveness signal, restoreWorkingafter a completed turn when the run continues, and settle only at the authoritative run boundary. - Replace transient tail activity with an incoming tool row without invalidating and reflowing long transcript history, keeping renderer animation and composer input responsive at the reasoning-to-tool boundary.
- Removed timer-only repaint from otherwise static transcript markers;
intentional
Working/Thinkinganimation invalidates only its active status block and leaves tool/shell dot cadence unchanged. - Decode observed Codex Responses error envelopes with a nullable provider code while still rejecting a missing or nullable error message.
- Retire a preferred Responses WebSocket before publishing a provider connection-lifetime error, then allow a bounded pre-generation retry through the HTTP fallback instead of racing the poisoned socket. Never replay a request after generated output has been observed, and close the active socket when its owning response is dropped.
- Keep repeated-call diagnostics out of same-response batches and preserve machine-readable JSON tool results.
- Run Harbor's Docker adapter in an independently cleanable process group, perform TERM→KILL descendant cleanup before artifact conversion/finalization, and fail closed if process death cannot be verified.
0.6.2 - 2026-08-27#
Fixed#
- Preserved bounded subagent summaries, fatal errors, usage, and the complete
sibling roster when owning-run cleanup removes the live host tree. Missing
active workers now settle as explicit
orphaneddiagnostic records instead of making every worker disappear; an identical explicit retry can replace its matching orphaned cache entry. - Skipped Apple Foundation Models
/v1/modelsdiscovery when the optionalfm servehealth probe says the local server is absent, eliminating the routine loopback connection warning without hiding errors from other custom providers. - Kept the interactive composer's hardware cursor visible in both retained-frame renderers, including after panels, resize replays, renderer resumes, and extreme narrow-width fallback rendering.
- Rendered every bounded subagent in the persistent TUI transcript event and the
compatibility activity path regardless of ordinary
Ctrl+Otool disclosure. - Added the one-time v0.6.2 managed-package migration so v0.6.0/v0.6.1 first-party bundles and Ygg Serve refresh to the exact hotfix version during startup.
0.6.1 - 2026-08-27#
Changed#
- Replaced Ygg's experimental semantic-commit/native-scrollback renderer with a direct Rust port of Pi's retained-frame algorithm. First render, changed-range updates, append/shrink, resize and offscreen-change replay, cursor bookkeeping, CSI 2026 framing, and Kitty cleanup now follow the pinned Pi control flow; terminal-owned resume eagerly materializes its complete active branch.
- Removed dead public API surface across the workspace and obsolete unused TUI
compatibility adapters in
sexy-tui-rs. - Flattened the internal tool trait stack:
Toolbecame the object-safeErasedToolform andTypedToolwas removed. - Retired the
show_turn_costflag. - Disabled
/themeand theme-file discovery; v0.6.1 exposes only the compiled default theme in terminal and graphical Serve surfaces. - Hoisted protocol helpers that were duplicated across crates into
ygg-ai. - Fixed concurrency bottlenecks so
Session::persistandDelegationManagerjournal writes no longer block under load. - Removed roughly 19 GB of accumulated workspace junk from the repository tree.
- Fixed documentation drift: subagent worker tool-scope and limit wording in
README.md,docs/extensions.md, anddocs/design/ygg-agent.md, plus the supported-fixes target inSECURITY.md. - Added a zero-token
ygg migrate pi --dry-runinventory that resolves bounded Pi user/project packages and resources, hashes source and lock inputs, parses JavaScript/TypeScript API use without executing package code, and emits human or schema-versioned JSON compatibility classifications. - Added
ygg pi install/listand the persistentygg-pi-compatsubprocess for explicitly trusted local Pi tools, commands, lifecycle, notification, input, and confirmation compatibility.
0.6.0 - 2026-08-23#
Added#
Deferred tool-schema loading, ported from Pi's deferred-tools design: tool results can now carry
added_tool_names— the set of tools that became available as a consequence of that execution (for example an extension or MCP server registering tools on first use). Models advertising the newdeferred_tool_loadingcapability stop re-sending announced schemas in the static request tool set; providers without the capability are unaffected. This is the load-bearing prerequisite for lazily registered extension and MCP tool schemas.Delegated workers now expose a bounded rolling
recent_toolsactivity ring (last six tool calls with flattened argument summaries, host timestamps, and an error flag) on everyagent/listrecord, and the/subagentspicker rows, inspect detail, and headless list render the latest action live — so each worker answers "what is it doing right now" without opening its transcript.Terminal-gate rejections (
CandidateRejected) now carry cumulative session cost alongside run cost, so delegated-worker spend tracks token usage between accepted turns instead of jumping at settlement.Added checksum-verified, bounded, atomic executable-extension bundles for the small first-party release catalog and offline/local archives.
ygg extension install,list,update, andremovenow manage API0.2bundles without enabling or trusting them; managed nested skills are discoverable but remain inactive until explicitly loaded.Added deterministic release packaging, complete tracked-file inclusion checks, local install/remove smoke coverage, and post-publication install/update smoke coverage for every catalog bundle.
Added an interactive
/extensionsinstalled-bundle activation menu that persists only enablement, never trust, rebuilds the extension host at the idle boundary, and becomes read-only when a higher-precedence activation source is authoritative.Added a native
/subagentsworker browser with arrow-key selection, owner-bound authoritative live refresh, stable-ID focus, and scrollable, owner-authorized read-only delegated transcripts.Added
subagent_continueto the first-partyygg-subagentsextension: it steers an active worker throughagent/messageor resumes a settled worker as a new run of its durable session throughagent/follow_up. A resumed worker keeps its conversation context, and the host clears the stale completion timestamp and re-anchors an elapsed wall deadline so the new run owns a fresh budget.Workers in
ygg-subagentscan now be grantededit,write, andbashper spawn through the spawntoolslist. The host's scoped tool snapshot is the enforcement boundary; the default remains the read-onlyread/searchpair.Cargo-installed binaries now embed the text documentation and materialize a versioned
share/ygg/tree that refreshes after Cargo-channel updates.
Changed#
- Subagents now inherit the parent's full standard tool scope (
read,search,edit,write,bash) by default, matching Claude Code's Task workers; passtools: [read, search]to keep a worker read-only. Worker prompts, profiles, the spawn schema, and skill guidance were updated accordingly. - The interactive composer's slash-command list refreshes when extension contributions change, and an unknown slash command now names enabled extensions that are not ready instead of failing with a bare error.
- Kept the target-specific Ygg Serve
package.tomlapplication archive distinct from generic executable-extensionextension.tomlbundles. - Removed ambient executable-extension header/status/footer and presentation activity from TUI chrome; extension and worker state now appears only in explicit interactive views.
- Routed the coding product's in-harness child sessions through the trusted,
owner-bound
ygg-subagentsextension. Ultra is now unavailable without its live observation service, and the root no longer receives a parallel native collaboration tool surface. - Removed the fixed aggregate subagent token/cost reservation pool. First-party children now have fresh contexts and inherit the parent's context/output and optional session-token settings exactly; an unlimited parent remains unlimited.
- Raised first-party subagent limits from 2 active/16 retained children per owner to 8 active/32 retained, with explicit ceilings of 256 turns, 50,000,000 microdollars, and 24 hours of wall time.
- Made per-child turn, cost, and wall-time ceilings optional in
agent/spawn.policy:null(or omitted) inherits the parent session's ceiling, so an unlimited parent policy with no ceiling produces an unlimited child. - Reworked the TUI composer-adjacent subagent activity strip: it appears only
while workers are pending or running, uses
•/└glyphs with model-matched colours, andCtrl+Oexpands it from the two to the five most recent workers while it is visible (falling back to the verbose tool-output toggle only when no strip is shown). agent/follow_upon a settled extension child is now a resume instead of a rejection: the child's persistent worker task and durable transcript survive between runs, the stale completion timestamp is cleared, and an elapsed wall deadline is re-anchored from the child's requested timeout.
Fixed#
- Clear composer-adjacent subagent activity when hydrating a different session, so worker telemetry cannot persist across a session switch.
0.5.0 - 2026-08-19#
Added#
- Added executable-extension API
0.2with exact feature negotiation, host-capped concurrency, one serialized writer, cooperative cancellation with bounded tombstones/escalation, request-scoped progress, and correlated child requests, including ephemeral text/secret input that is never logged or persisted. - Added typed text/image/audio tool-result parts, declared output schemas, validated structured content and retained metadata, plus generation-scoped artifact publication from bounded inline data or a verified scratch path.
- Added best-effort session, turn, and tool lifecycle observations; host-owned policy-intent classification (currently default-deny without a domain adapter); optional original-intent-bound single-use approval redemption; manifest-allowlisted, owner-scoped secret brokerage; host-derived session/process ownership; inspectable process health; and deadline-bounded drain/reload.
- Added transactional
tools/registerandtools/unregister, per-process catalog epochs, provider-turn schema/implementation snapshots, and stable owner ordering so long-lived extensions can publish changing tool catalogs without rebuilding the agent. - Added optional extension-to-host child-agent sessions with scoped spawn, message, follow-up, list, wait, and interrupt operations. Ownership is derived from the parent request rather than trusted child JSON.
- Added automatic supervision after a successful extension handshake: crashes withdraw live tools, restart with bounded jittered exponential backoff, and remain fenced from explicit shutdown and stale generations.
- Added dependency-free Python SDK
0.2support for negotiation, concurrent dispatch, cancellation tokens, progress, artifacts, lifecycle handlers, policy/approval requests, secret lookup, live tool catalogs, child-agent sessions, and graceful drain while retaining API0.1wire support. - Migrated the Caffeinate example to a supervised API
0.2lifecycle extension that reference-counts active turns. Sleep inhibition is no longer native agent-kernel behavior. - Added durable, provider-neutral session goals: a per-session objective with a
bounded turn budget, stored owner-only in the session's private
.serve/goalsdirectory, that the agent continues toward after each settled turn until it reports explicit completion or becomes blocked./goal <objective>,/goal status,/goal pause,/goal resume, and/goal clearmanage the goal in the terminal, and the graphical Serve shows the same goal with a badge and a composer command. - Added metadata-gated Ultra reasoning with automatic bounded V2 task delegation, including spawn, follow-up, peer messaging, race-free waiting, interruption, descendant cancellation, and inheritance of the root's approved tools and execution policies.
- Added isolated child sessions and descriptor-relative private team storage
with synced
provenance.jsonl; delegation fails closed if provenance cannot be persisted. - Added
ygg updatewith install-method detection, release checks, and pinned installer or Cargo execution outside the running process.
Changed#
Froze executable-extension API
0.1as a backward-compatible, text-oriented contract. Its optional tool metadata remains accepted but is discarded, and itsafter_responsehook remains completion-only.Superseded the earlier host-owned capability design with a tiny agent kernel: JSON-RPC subprocess extensions own MCP, browser, web-search, computer-use, memory, LSP, subagent-orchestration, and caffeinate domain behavior.
Replaced the obsolete OpenAI Codex Pro wire mode with provider-advertised
ultraeffort. Persisted Pro selections remain readable and migrate only when the route advertises Ultra plus V2 collaboration and the host can execute it; no codec emitsreasoning.mode.Updated authenticated Codex discovery to parse advertised reasoning levels,
use_responses_lite, andmulti_agent_version: "v2"using cache schema 2 and client version0.147.0. Offline or incomplete metadata does not infer those capabilities from model names or OAuth plans.Matched current Responses Lite ordinary and compact requests, including explicit
parallel_tool_calls: false, developer-message instructions, input-itemadditional_tools,reasoning.context: "all_turns", and narrow removal of image-detail hints.Swapped the safety default to full host access (
UnsafeHost) and replaced--safewith canonical--safe-modefor approval-required execution. The obsolete--yoloflag and its configuration/environment aliases are no longer accepted;--saferemains a hidden compatibility alias for--safe-mode.Rewrote bash safety classification with tree-sitter parsing: a strict word-only command allowlist joined by
&&,||,;, and|, with bounded recursion through shell wrapper invocations, decides whichbashcommands theControlledprofile auto-approves as read-only; anything else still requires one-shot approval.Reworked local compaction around Pi-style token retention: the most recent 20,000 tokens of conversation are kept verbatim (
compaction.keep_recent_tokens), a turn that crosses the retention boundary is split so its older prefix is summarized with its own bounded output budget while its recent suffix is retained, and the checkpoint summary uses a bounded output budget. Legacy compaction mode and policy settings remain accepted.Moved TUI liveness out of the composer: the composer now sits in a static model-accent frame while the transcript owns animation, inline slash, file, and
@completions render below the composer, and reasoning presentation uses compactWorkingandCompacting contextlabels instead of animated shimmer.Session discovery now keeps JSONL transcripts authoritative while caching bounded title projections in a disposable workspace SQLite catalog, and streams transcript replay and metadata scans so large sessions no longer need a second whole-file buffer.
Reduced per-frame rendering work in long TUI sessions.
Fixed#
- Kept slash/path completion, panel, and report surfaces out of
terminal-owned history, and reconciled streamed-layout contractions without
punching blank rows into the live grid.
/contextnow repaints completely after a tall slash popup while finalized transcript rows remain exactly once in native scrollback. - Made delegated mailbox delivery transactional: bounded UTF-8 pages remain leased until an untruncated tool result is durably appended, and failed or truncated persistence restores the page.
- Preserved accepted steering, queued prompt messages, and follow-ups across interruption, backpressure, and failed runs, retaining queue reservations until durable prompt delivery; rejected oversize or overflowing durable tasks and messages instead of truncating, evicting, or silently releasing them.
- Rejected stale, future-dated, malformed, incomplete, and inconsistent Codex cache metadata before capability activation, stripped dynamic capabilities offline, and applied legacy-Pro migration precedence consistently at rebuilds.
- Propagated the effective current root prompt to newly spawned children and securely rolled failed delegation activation back to its exact empty private team directory.
- Omitted
tool_choicefrom OpenAI Chat requests when no tools are enabled so the field is no longer sent without a tool list. - Made the signed binary installer portable across supported macOS and Linux targets, and added replacement coverage proving a v0.4.0 installation upgrades both binaries and packaged documentation without touching user data.
- Surfaced terminal provider failures in the Serve web UI and retained failed-provider diagnostics after later work.
- Bounded the Caffeinate example's sleep inhibition: if Ygg cannot report a terminal outcome, such as an interrupted run, the inhibitor now expires after 30 minutes.
The 0.2 foundation does not yet ship first-party MCP, browser, web-search,
computer-use, memory, LSP, or subagent-orchestration packages. Supervision
begins only after a successful initial handshake and does not yet detect a hung
but still-open child; a full application rebuild still recreates extension
processes. The coding product does not yet configure an approval UI adapter or
secret provider. OS-level CPU/RSS/FD/PID quotas also remain future kernel work.
0.4.0 - 2026-08-10#
Added#
- Added an exception-driven Fleet command center that aggregates active and attention-needed sessions, supports task and project search, and returns directly to focused work.
- Added live session activity indicators in the Serve sidebar and line numbers in the graphical source-file viewer.
- Added checkout-aware self-documentation guidance to
/helpand the system prompt when Ygg is run from its own source tree. - Added the
ygg_sdkRust library andygg-hostprotocol-v1 NDJSON process interface for native integrations, including bounded streaming, inline and configured providers, typed media, seeded history, and durable sessions. - Added first-use, owner-only Codex credential migration from legacy Codex and Hamr stores without modifying the source credentials.
- Added both Ygg binaries to deterministic, Git-tracked release archives, binary/source installers, containers, and release smoke tests.
- Added credential-free configured-provider acceptance for Serve covering authentication/model selection, streaming, tool replay, retries, explicit compaction, restart/resume, cancellation, and secret-safe failures, plus an optional protected live-provider acceptance workflow.
- Added a deeply nested PDF regression proving Ygg's bounded iterative preflight rejects hostile nesting before parser entry.
Changed#
Made graphical prompts submitted during an active run steer by default instead of becoming queued follow-ups.
Removed the redundant interactive
/tool,/docs,/sessions, and/cycle-modelcommands. The top-levelygg sessionscommand remains available.Rounded compact TUI footer costs to three significant figures.
Made headless native-host interactions fail closed: tool confirmations are denied, typed input requests are cancelled, protocol frames are bounded, and session/image/provider inputs are validated at their system boundaries.
Enforced dependency review, high-severity npm audit, plus
cargo auditandcargo denyfor both lockfiles on pull-request and release paths.Replaced broad Serve session inventory replays with bounded, targeted catalog scans and carried an authorized resume session into the worker by descriptor. On the isolated 891-transcript fixture, startup improved from 43.01 seconds to 19.41 seconds; direct resume of the large-session fixture completed in 2.39 seconds.
Fixed#
- Made
/overviewbootstrap from session inventory without creating or opening a provisional task, including anchorless reconnect refresh and cancellation of stale session-selection navigation. - Kept the focused session surface and route mode stable when session selection or creation fails or is retried.
- Hardened Serve catalog and resume selection against corrupt or symlinked transcripts, trashed sessions, unsafe sidecar metadata, inactive-branch configuration, and pathname replacement after resume authorization.
- Prevented no-color line truncation from appending an ANSI reset sequence to otherwise plain terminal output.
- Preserved launcher configuration, model selection, and provider credential
environment variables when
ygg servedispatches to the exact-version first-party package runtime.
0.3.2-alpha - 2026-08-01#
Added#
Added target-specific prebuilt Ygg binaries and a version-pinned installer for GNU/Linux x86-64, macOS x86-64, and macOS Apple silicon; compiling with Cargo remains an explicit
--from-sourceoption.Added the minimal first-party application-extension workflow:
ygg extension install,list,update, andremovedownload or accept a local package, verify its checksums and exact Ygg compatibility, and install it atomically.Added external
ygg servedispatch to the separately installed, loopback-only Ygg Serve runtime. The ordinary Ygg binary does not include the Serve backend or web application.Added source-located diagnostics for unknown global and trusted-project config keys, typo suggestions, and strict rejection through
--strict-config,strict_config, orYGG_STRICT_CONFIG.Added
SessionRunOutcomepersistence, root-head checkpoints, durable run terminal state, and independent display metadata for steering and follow-up inputs.Added the loopback-only Ygg Serve backend under
extensions/ygg-serve/, with bounded host/session contracts, deterministic snapshots and replay, authenticated HTTP/WebSocket transport, session supervision, evidence and attachment storage, document and test-result ingestion, repository context, project files, terminals, transcript search, runtime status, and prompt context.Added the React 19 and TypeScript web client under
apps/web/, with responsive session navigation, transcript and activity views, composer controls, attachments, completion review, branching, project files, terminal access, usage and context views, settings, search, local themes and fonts, and Playwright acceptance coverage.Added the feature-gated adapter in
crates/ygg-coding-agent/src/extensions/serve.rs, boundary enforcement, deterministic embedded assets, installed-runtime smoke coverage, and target-specific release packaging for GNU/Linux x86-64 and both supported macOS architectures.Added architecture, current-state, lifecycle safety, LAN pairing, native delivery, P0/P1 delivery, and web acceptance documentation for Ygg Serve.
Changed#
Kept
autoon the terminal-owned renderer so native scrollback, drag selection, logical-height chrome, stable-prefix suffix updates, and full retained-transcript replay on resize remain the defaults.--mouse appexplicitly opts into the bounded, anchored semantic viewport.Preserved the
0.3.1-alphadefault prompt alignment, event rows, transcript surfaces, and composer spacing; this experiment changes terminal behavior, not the visual layout.Reconciled the vendored renderer's
0.3.1package metadata and provenance with the Ygg workspace while keeping its unsynchronized standalone baseline explicit.Added PTY coverage proving only explicit
appmode negotiates mouse ownership;auto/terminal/offleave it to the terminal, and all four restore terminal state.Added regressions that grow one live Markdown block while scrolled above the tail and reflow cached transcript rows across consecutive wide and narrow renders.
Fixed#
Replaced line-based configuration updates with structural, comment-preserving TOML editing so multiline values, similarly prefixed keys, and table sections cannot be corrupted when Ygg persists model or reasoning selections.
Rebuilt cached transcript rows whenever the requested width changes, even when no content block is dirty, preventing wide rows from leaking into a narrow render.
Sanitized user input before Markdown parsing so terminal protocols cannot expand differently from the semantic copy projection or destabilize prompt geometry.
Prevented OpenAI Responses, OpenAI Chat Completions, and Anthropic Messages POSTs from being replayed after full transport timeouts or ambiguous failures while sending the request or awaiting response headers; replay-safe connection failures remain visible, cancellable, and bounded.
Enforced
#![forbid(unsafe_code)]across the vendoredsexy-tui-rscrate.
0.3.1-alpha - 2026-07-26#
Changed#
- Replaced width-dependent commit row bookkeeping with stable semantic cursors that remap after reflow, including list-item and table-row boundaries for large streamed Markdown blocks.
- Kept deferred-history prepends and cancelled streaming retries on the same append-only semantic tape without renumbering retained commit identities.
- Added terminal-emulator regressions for streaming layout shrink, nonzero scrollback offsets, synchronized output, and width changes during generation.
Fixed#
- Prevented finalized streamed output from being duplicated, omitted, or overwritten in native terminal scrollback when Markdown rows shrink, the terminal is resized, or scrolling and resizing overlap with generation.
- Preserved terminal-owned history across theme and disclosure repaints without clearing scrollback or replaying the committed transcript.
0.3.0-alpha - 2026-07-25#
Added#
- Failed interactive runs now retain the compact lifecycle row and show a bounded, terminal-safe diagnostic that can be copied for troubleshooting.
Changed#
- Made fenced Markdown code copy-safe with borderless, terminal-adaptive shading.
- Kept the default prompt composer unfilled and restrained at rest, with a model-colored perimeter shimmer only while work is active; explicit themes retain their authored chrome.
- Refreshed the project identity, terminal demo, installation references, and
release documentation for the
0.3.0-alphaline.
Fixed#
- Redacted request credentials and terminal controls from bounded provider and transport diagnostics before they can be persisted or printed.
- Serialized ChatGPT credential refresh across processes and bounded OAuth responses, update metadata, and other remote discovery inputs.
- Prevented atomic new-file publication from replacing a concurrently created target and retired extension RPC connections after interrupted framed writes.
- Centralized terminal-safe human-facing command output and strengthened session export redaction without changing provider-visible conversation context.
0.2.0-alpha - 2026-07-25#
Added#
Added durable Responses replay and multimodal reads.
Added persistence for authoritative raw output.
Added native compaction transport and pro mode.
Added support for labeled custom OpenAI providers, including tool calling with macOS 27 Apple Foundation Models: system and private cloud compute (PCC).
Added PDF attachment handling that resolves to a workspace path for file tools instead of pretending PDFs are supported as multimodal payloads.
Showcased sexy-tui-rs themes and added the ygg demo to the README.
Updated installation, security-support, and release references for this alpha.
Changed#
- Refined reasoning status presentation and hardened native Responses integration.
- Improved bounded, sanitized tool-output projections and edit/write diffs in the TUI while keeping raw evidence out of transcript copy.
- Updated the startup identity and release metadata for the
0.2.0-alphaline.
Fixed#
- Prevented the shell prompt from overwriting the inline composer or leaving a stale footer after exiting the interactive TUI.
- Fixed release-blocking image/audio ingestion and media capability handling.
0.1.1-alpha - 2026-07-24#
Added#
- Restored the animated, model-tinted braille-tree startup identity. The startup card reports the package version, selected model, reasoning configuration, and workspace without taking over the terminal background.
- Added entitlement-gated GPT-5.6 Pro reasoning mode for ChatGPT OAuth Pro routes, with independent CLI, configuration, session persistence, picker, and OpenAI Responses wire support.
- Added
shell_path,--shell-path, andYGG_SHELL_PATHfor explicit Bash-compatible shell selection. - Added syntax-aware inline Bash command rendering, including distinct command names, strings, operators, flags, and arguments.
Changed#
Renamed the model command tool from
exectobash. Every command is now passed intact to one Bash-compatible shell with-c, matching Pi's Unix semantics: explicitshell_path,/bin/bash,bashonPATH, thensh. Ygg does not consult$SHELL.Renamed the primary execution limit to
bash_timeout_secs,--bash-timeout-secs, andYGG_BASH_TIMEOUT_SECS. The prior configuration, CLI, and environment spellings remain compatibility aliases.Reworked the transcript hierarchy around a fixed two-row live reasoning status that exposes only the model's latest explicit Markdown heading, uses a blinking model-colored dot beside a plain model-colored label, and falls back to
Thinking, alongside in-place activity, bold neutral tool names, restrained metadata, quieter collapsed-output hints, consistent spacing, and model-provenance user prompts.Tool lifecycle dots now blink in lockstep while work is active, settle dimly, use green only for successful Bash commands, and reserve red for failures.
Completed reasoning disappears by default and remains available through the global verbose disclosure mode.
Active context telemetry now accounts for newly persisted tool results before the next provider usage report, so an imminent auto-compaction no longer appears to trigger against a stale pre-tool token count.
Ported Pi-compatible terminal input, selection, paste, key-repeat, and overlay behavior while preserving native terminal selection and scrollback.
Long-session rendering now hydrates a bounded tail, caches stable transcript rows, and avoids replaying or repainting committed native scrollback.
Simplified tool output presentation: Bash output remains neutral, file tools expose diffs when relevant, and completed tool evidence stays collapsed unless explicitly expanded.
Existing sessions containing historical
execcalls continue to render as Bash events; new provider schemas advertise onlybash.Command cancellation and timeouts retain process-group cleanup, bounded stdout/stderr capture, live progress, and detached-descendant supervision.
Added regression coverage for shell selection and Bash expansion, Pro-mode entitlement and persistence, synchronized event-dot animation, startup version display, reasoning cleanup, command syntax styling, and transcript lifecycle.
Reduced development-profile codegen units to limit incremental artifact accumulation without disabling incremental compilation.
0.1.0-alpha - 2026-07-22#
Added#
Interactive TUI, chronological plain mode, and response-only print mode.
OpenAI Chat, OpenAI Responses, and Anthropic Messages protocol support.
Local OpenAI-compatible endpoint configuration and cloud/provider discovery.
Branchable append-only sessions, usage/cost records, checkpoints, resume, and compaction.
Bounded
read,search,edit,write, andexectools plus skill discovery/activation tools.Complete CLI tool allowlist/deny controls, offline startup, context-file disable switch, workspace trust gate, and
--version.Deterministic checked-in model metadata and Unix containment profile.
Project configuration/resources are ignored unless the workspace is explicitly trusted; project settings cannot relax global authority floors.
Disabled tools are absent from provider schemas and execution dispatch.
--no-editdisables both mutation tools.Descriptor-relative no-follow file operations close parent-symlink replacement races and compare target state immediately before rename.
File/context/config/credential/session/discovery/provider-stream inputs have hard byte/count limits; special files are rejected.
Arbitrary process and shell execution use one truthful authority gate.
Unresolved mutating calls are never replayed after a crash.
Session appends use interprocess locking, stale-generation detection, private permissions, and synced writes; listing is read-only.
Cancellation propagates through autonomous compaction and prevents post-cancel summary/usage commits.
TTY print output neutralizes terminal control sequences.
Added root installation/security documentation, MIT and third-party notices, checked-in architecture docs, reproducible release gates, dependency policy, a fuzz target, and complete package metadata.
Release builds enable ThinLTO, one codegen unit, symbol stripping, and abort-on-panic to reduce startup work and binary/RSS footprint.
The alpha release target is macOS and Linux; command execution is explicitly Unix-only.
Changed#
- Session resume hydrates and paints only a bounded tail instead of cloning, parsing, and rendering the entire transcript; older history materializes on demand for PageUp/PageDown, wheel navigation, selection, and semantic copy.
- Session discovery uses bounded lightweight metadata scans, and direct resume-by-id avoids parsing unrelated session bodies.
- TUI redraws emit exact changed rows, clear stale Kitty images, coalesce composer border colour runs, anchor scrolled readers while output arrives, and repeat only editing/navigation keys (never submit, close, or toggle actions).
- Provider model inventories use private, scoped cache-first startup. Built-in inventories refresh in the background; stale custom inventories refresh before catalog construction so the current launch sees server changes while retaining last-known-good models on failure.
- Connection setup and response headers have separate bounds. Custom endpoints have a configurable cold-start header allowance, while non-timeout network loss retries visibly and cancellably up to five times; a full transport timeout is not multiplied automatically.
- Ordinary final answers no longer trigger a hidden second completion-confirmation inference.
- Request sizing and transformation avoid temporary whole-history buffers and redundant context reconstruction during resume and send.
- Codex Responses requests use zstd compression, low text verbosity, and capability-gated parallel tool-call declarations without changing generic OpenAI-compatible routes.
- Streaming parsers use bounded linear scans and aggregate response budgets, including adversarial one-byte compatibility streams, pre-ID tool arguments, and Anthropic signatures.
- Interactive shell commands drain stdout and stderr concurrently under a fixed output budget, enforce the execution timeout, and terminate the complete process group on cancellation.
- Native terminal selection and scrollback are the default again; stable-prefix frame updates avoid redrawing committed history, while application-owned semantic mouse behavior remains available through
--mouse app. - Semantic transcript blocks use one consistent breathing row between actions without separating a tool header from its result or diff.
- Custom hlid/llama.cpp discovery reads the active nested
meta.n_ctxcontext window instead of falling back to training limits or a generic default. - Custom endpoint reasoning controls are authoritative: off-only, binary, and level-based metadata produce exactly the corresponding picker choices and wire values.
- Reasoning is collapsed by default into a stable two-line, model-colored status that surfaces only explicit model-emitted Markdown headings, falls back to
Thinking, disappears on completion, and expands withCtrl+O. - Every bundled theme retains its authored palette, while the compiled default follows the selected model lab and resets cleanly after theme switches.
- Batched tool results retain independent bounded output allowances so a large early result cannot starve later calls in the same turn.