Latest release

Changes, verification and known limitations in the latest stable release.

This release focuses on responsive interaction, bounded recovery, and host-owned extension contracts for a small, model-flexible coding agent.

Highlights#

  • Keep startup silent and editable, restore the full /model picker, and keep inspection commands and /goal responsive during streaming.
  • Improve activity shimmer, tool disclosure, worker presentation, and usage visibility without replacing durable accounting with display estimates.
  • Accept owner-bound /subagents stop <name|all> during an active response, keep input responsive while stopping, and show compact token counts with the same continuation alignment as Thinking. A stop request is not terminal settlement.
  • Preserve native scrollback after an active subagent roster instead of clipping unrelated commands, results, and answers into a pending-tool preview.
  • Add /settings, /scoped-models, /session, hidden /debug, capability-gated /fast, and !command / !!command shell escapes. Withdraw /tree and /checkout; rename /quit to /exit.
  • Add ordered --models selection and opt-in Windows --powershell, plus bounded HTML session export, local-model evaluation profiles, and tool checkpoints.
  • Repair request headroom, provider size-rejection recovery, sparse discovery metadata, reasoning capability decoding, and host-budgeted transport retries.
  • Refresh reviewed models.dev names, pricing, and capabilities without adding build/runtime metadata fetches. Direct DeepSeek schedule pricing stays unknown; public catalog evidence is not live inference acceptance.
  • Keep interrupted-attempt partial text in RecoveredOutput, separate from the current answer, provider replay, and usage accounting.
  • Update rustls to 0.23.45 for RUSTSEC-2026-0285. Preserve an admitted Python shutdown hook and acknowledgement when stdin closes, within the EOF drain budget.
  • Keep manual-compaction provider retry state off the nested caller futures to prevent Serve /compact from overflowing a normal Tokio worker stack.
  • Retain Serve, Browse, MCP, host-owned subagents, web search, and protocol safety/conformance. API 0.4 is the current extension wire; the separately supported canonical API 0.3 includes a session-isolated process event bus.
  • Remove Pi extension execution and its CLI entrypoint; retain Pi dry-run inventory and portable import/restore. Remove obsolete internal planning, comparison, and task-handoff documentation.

Additional reconciled changes#

  • Keep model/thinking/subagent and consent surfaces inside the active run loop; renderer layout and terminal writes no longer hold the semantic input lock.
  • Bound Bash spill storage and editor history, move optional telemetry writes off the agent path, and advance session/replay projections incrementally.
  • Expose qualified native Responses steering and asynchronous tools with durable intent, settlement and fail-closed accounting; unsupported routes retain queued steering. Host model selection for workers remains owner-bound.
  • Keep worker activity in a bounded, mutable transcript roster, with full details in /subagents; raw orchestration calls and state transitions add no transcript notices. Full-access MCP mutations use host-owned policy checks; controlled policies still refuse them.
  • Offer first-run API-key, supported OAuth, and local-model setup in that order.

Reload#

Interactive resource/extension reload is enabled silently by default and applies at idle boundaries. /reload --dry-run previews changes. Host replacement requires /reload --force or explicit reload_host = true, and a replaced binary requires confirmation before its first probe execution. Resource rebuilds refuse while host worker tasks remain attached, including retained idle receivers; force/watch passes cannot bypass that refusal. Finish or stop work, then exit and resume the session to replace that owning host. In-flight provider calls are not silently replayed. A separate running octet serve process needs its own restart to use a new binary.

Limits and availability#

Native iOS/macOS companions remain source-only, not supported live connection paths or signed installable releases. Product open-all remains fail-closed without atomic writer handover. /fast is session/process scoped and does not promise provider acceptance or clear historical cost uncertainty. Optional protocol services do not imply a product UI or broader host authority.

This release does not claim every review finding resolved. Terminal layout, Mermaid, notification wording, native-app delivery, live-provider acceptance, and physical-terminal qualification remain separate from this release-gate scope. Deterministic tests do not establish all-provider, physical-terminal, or long-duration acceptance.

The version-pinned GitHub release records validation, signed native assets, exact-version Serve and executable bundles, and public-install results. See installation for version-matched commands and CHANGELOG.md for detailed changes. The RC qualification record retains its historical, bounded evidence; source checks alone do not establish publication.

npm, Homebrew, crates.io and SDK registries remain separate, unpublished channels. Live-provider/audio and physical-terminal acceptance were not run as release gates.