Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
162 commits
Select commit Hold shift + click to select a range
f8b35d2
Remove native monitoring integrations while preserving upgrade compat…
Calmingstorm Sep 29, 2026
5630a28
fix(skills): preserve activation and loaded artifact identity
Calmingstorm Sep 29, 2026
e21d4b8
fix(governor): admit skill helpers and selected skills through inheri…
Calmingstorm Sep 29, 2026
b332534
docs: correct provider, auth, restart and inventory guidance
Calmingstorm Sep 29, 2026
a5a59ee
docs: record documentation campaign results
Calmingstorm Sep 29, 2026
781600a
Include rebuilt WebUI asset for monitoring removal
Calmingstorm Sep 29, 2026
8bc101f
fix(codex): securely publish complete credentials and merge manual lo…
Calmingstorm Sep 29, 2026
8766010
fix(codex): fence account mutations and serialize admin token rotations
Calmingstorm Sep 29, 2026
1281b7d
Fix next-clock DST admission and clock parsing bounds (#414 #415 #416)
Calmingstorm Sep 29, 2026
1e8c0f8
Fence queued scheduler effects, validate trigger filters and stamp re…
Calmingstorm Sep 29, 2026
9482e2e
Preserve deferred workflow conditions, failures, target contracts and…
Calmingstorm Sep 29, 2026
3163896
Retire native Grafana triggers without breaking stored schedules
Calmingstorm Sep 29, 2026
c2a8779
Cover concrete deferred host contracts and nested skill wire decoding
Calmingstorm Sep 29, 2026
66b9ed7
Preserve templated skill selection and manual paused-run admission
Calmingstorm Sep 29, 2026
e85dc5b
Bound validation regex work and distinguish refused probes from execu…
Calmingstorm Sep 29, 2026
8dfddf7
Preserve dispatch uncertainty and typed failure metadata across tool …
Calmingstorm Sep 29, 2026
7ac3152
Pin approved SSH retry behavior alongside durable uncertainty
Calmingstorm Sep 29, 2026
9a10fc4
Reap streamed children when an output consumer fails
Calmingstorm Sep 29, 2026
f822bc8
Fix scoped memory reads, ranked fusion payloads and cold embedding lo…
Calmingstorm Sep 29, 2026
4fa5b53
Preserve knowledge identities and authoritative diffs; order fallback…
Calmingstorm Sep 29, 2026
886f0aa
Preserve compacted context and eligible history; keep API executions …
Calmingstorm Sep 29, 2026
ecc48ab
Fence ephemeral clears and bound globally ordered fallback matches
Calmingstorm Sep 29, 2026
1b8404a
Assert version summaries agree with authoritative snapshot diffs
Calmingstorm Sep 29, 2026
0f32ca0
fix(computer): revoke focus input despite receipt storage failure (#510)
Calmingstorm Sep 29, 2026
2d580c2
fix(computer): preserve emergency release recovery lineage (#511)
Calmingstorm Sep 29, 2026
ba56396
fix(computer): archive qualified absence before resolving recovery (#…
Calmingstorm Sep 29, 2026
1d9a7f5
fix(computer): reconcile private evidence crash orphans (#513)
Calmingstorm Sep 29, 2026
9b4a0c8
fix(computer): rebind native recovery context on clean resume (#514)
Calmingstorm Sep 29, 2026
484f61b
fix(computer): expose bounded native recovery status and next steps (…
Calmingstorm Sep 29, 2026
f6c10b9
fix(computer): retire expired inventory and settled session caches (#…
Calmingstorm Sep 29, 2026
e89ec7b
fix(computer): accept clean native pre-input rejection ledger (#619)
Calmingstorm Sep 29, 2026
4f59c34
fix(computer): recognize direct X11 pre-input refusals (#620)
Calmingstorm Sep 29, 2026
75c68a9
fix(computer): require sudo only for privileged isolated launches (#621)
Calmingstorm Sep 29, 2026
3b39b89
test(computer): harden recovery archival and evidence writer coverage
Calmingstorm Sep 29, 2026
5998cac
fix(learning): scope lesson identity and supersession to ownership
Calmingstorm Sep 29, 2026
940f402
fix(learning): expire lessons from newest valid activity
Calmingstorm Sep 29, 2026
6dedf2a
fix(audit): summarize stable retained generations for log filters
Calmingstorm Sep 29, 2026
6194cce
fix(observability): aggregate full retained audit snapshots
Calmingstorm Sep 29, 2026
dad9695
fix(observability): count injected learned context in prompt totals
Calmingstorm Sep 29, 2026
2cdd293
fix(audit): preserve unified diff line framing and EOF markers
Calmingstorm Sep 29, 2026
b511eef
fix(usage): settle owned lock and connection on database open failures
Calmingstorm Sep 29, 2026
d36f9c8
fix(monitoring): scan actual session manager persistence directory
Calmingstorm Sep 29, 2026
b96fcde
fix(health): validate knowledge database integrity at startup
Calmingstorm Sep 29, 2026
eccf202
fix(health): diagnose effective static and dynamic API credentials
Calmingstorm Sep 29, 2026
ace5a40
fix(health): treat unconfigured Discord gateway as dormant
Calmingstorm Sep 29, 2026
7191e61
fix(observability): label prefix stability unmeasured instead of cach…
Calmingstorm Sep 29, 2026
15241d2
test(observability): verify retained failure API and type-safe ownership
Calmingstorm Sep 29, 2026
50ce835
Fix packaging and deployment regressions
Calmingstorm Sep 29, 2026
cc1512f
Preserve legacy Compose config on upgrade
Calmingstorm Sep 29, 2026
2ef93a0
Fix provider settlement, model dispatch, accounting and reload lifecy…
Calmingstorm Sep 29, 2026
4edef00
Keep half-open provider probe reserved through internal retry settlement
Calmingstorm Sep 29, 2026
96d1f43
Fix patch snapshot ownership, nonblocking opens and byte-preserving l…
Calmingstorm Sep 29, 2026
f07d9ef
Preserve host quarantine, serialize test publication and enroll signi…
Calmingstorm Sep 29, 2026
c6725e4
Retain SSH master ownership across cancelled closure (#550)
Calmingstorm Sep 29, 2026
4bd9045
Verify CA endpoint principals and persisted-disable race (#552 #553)
Calmingstorm Sep 29, 2026
f24f8df
Fence process admission and require whole-execution cleanup proof (#4…
Calmingstorm Sep 29, 2026
e763acb
Extend ownership and cancellation regression coverage with truthful r…
Calmingstorm Sep 29, 2026
6408cd4
Persist affirmative process cleanup evidence for restored generations
Calmingstorm Sep 29, 2026
749a0f5
fix(web): restore operator files on self-update exceptions
Calmingstorm Sep 29, 2026
725e229
fix(web): bind sessions to credential origin and generation
Calmingstorm Sep 29, 2026
953bdd8
fix(web): report verified process termination outcomes
Calmingstorm Sep 29, 2026
a88fc7e
test(web): qualify auth carriers and rollback failure matrix
Calmingstorm Sep 29, 2026
db8bf16
test(web): use actual process registry success reply
Calmingstorm Sep 29, 2026
e3cd532
Fix autonomous iteration outcomes, terminal findings and completion t…
Calmingstorm Sep 29, 2026
a4e96d4
Type autonomous failure metadata and pin uninterrupted successful gen…
Calmingstorm Sep 29, 2026
bf7d712
Reserve outbound target admission and admit first events on young hosts
Calmingstorm Sep 29, 2026
e9236e6
Select requester-owned preserved work before explicit resume rejection
Calmingstorm Sep 29, 2026
8daae35
Bound scheduled digest fallback sends including annotations
Calmingstorm Sep 29, 2026
5389cae
Preserve complete authorized attachment evidence and buffered bot files
Calmingstorm Sep 29, 2026
0e4f566
Pin successful autonomous recovery resetting the consecutive failure …
Calmingstorm Sep 29, 2026
3f87548
Exercise startup diagnostics with the real credential inventory contract
Calmingstorm Sep 29, 2026
8a0fe98
fix(config): preserve startup compatibility and fence migration rewrites
Calmingstorm Sep 29, 2026
1d88062
fix(config): serialize partial settings saves and honor effective sel…
Calmingstorm Sep 29, 2026
5cc6a26
test(config): align agent API validation with canonical root policy
Calmingstorm Sep 29, 2026
0d25108
fix(config): tolerate read-only migration completion repairs
Calmingstorm Sep 29, 2026
eebbecc
fix(config): adapt file-mounted image defaults without preparing a re…
Calmingstorm Sep 29, 2026
b607eac
fix(webui): fence asynchronous ownership and repair operational controls
Calmingstorm Sep 29, 2026
f6d217b
fix(webui): bound raw paused evidence and honor turn attribution
Calmingstorm Sep 29, 2026
63c8792
fix(webui): explain signing CA fingerprints for host enrollment
Calmingstorm Sep 29, 2026
8e195a0
fix(execution): separate stream ownership from model-local call IDs
Calmingstorm Sep 29, 2026
959ce41
fix(governor): recognize remaining standard systemctl global options
Calmingstorm Sep 29, 2026
6dd6458
fix(codex): preserve explicit reauthentication across cold pool reloads
Calmingstorm Sep 29, 2026
902df5c
Remove stale native monitoring assumptions
Sep 29, 2026
b6e686a
Align native monitoring tests with removed routes
Sep 29, 2026
869e284
Fix component health wiring regression fixture
Sep 29, 2026
b1f600e
Exercise process kill outcomes with integrated request ownership
Calmingstorm Sep 29, 2026
c1c0b22
Rebuild integrated WebUI and retire coverage entries only for deleted…
Calmingstorm Sep 29, 2026
ea55be9
fix(email): verify TLS and preserve accepted mail across cleanup fail…
Calmingstorm Sep 29, 2026
f68dc61
fix(mcp): isolate invalid headers and retain mixed structured results
Calmingstorm Sep 29, 2026
ef5173f
fix(catalog): gate optional backends and enforce computer disablement
Calmingstorm Sep 29, 2026
67eb20f
fix(images): decode complete PNGs and fail undelivered generation
Calmingstorm Sep 29, 2026
2dcab3e
fix(agents): digest full evidence and settle unstarted cancellation
Calmingstorm Sep 29, 2026
a1ba3e5
style: normalize campaign regression imports and lines
Calmingstorm Sep 29, 2026
33c1688
test: exercise discovery email retrieval and computer management paths
Calmingstorm Sep 29, 2026
3ee7707
fix: preserve full binary evidence identity and avoid fenced JSON dup…
Calmingstorm Sep 29, 2026
c1134f2
test(images): reject truncated terminal response without retry
Calmingstorm Sep 29, 2026
6fefecc
test(agents): await and verify unstarted cancellation trajectory
Calmingstorm Sep 29, 2026
1ad194d
test(catalog): reject disabled computer calls at native dispatch
Calmingstorm Sep 29, 2026
1b00357
Finish packaging runtime qualification and safe upgrade repairs
Calmingstorm Sep 29, 2026
04d2131
test: assert independent conservative OpenRouter route limits
Calmingstorm Sep 29, 2026
a3a814e
fix: retain remote evidence deadline without claiming cleanup
Calmingstorm Sep 29, 2026
e280588
fix: settle explicit local kills with owned cleanup proof
Calmingstorm Sep 29, 2026
606cfcd
test: preserve unknown kill settlement and verify cleanup attempt
Calmingstorm Sep 29, 2026
7947290
docs: record independent lifecycle review evidence and limits
Calmingstorm Sep 29, 2026
38b03dd
docs: track v4.10.0 campaign status and release notes
Calmingstorm Sep 29, 2026
d3f3e39
docs: refresh campaign ledger from completed worker reports
Calmingstorm Sep 29, 2026
72bac2a
docs: update campaign report availability and cautions
Calmingstorm Sep 29, 2026
60d2961
docs: finalize completed lane accounting
Calmingstorm Sep 29, 2026
7080d87
docs: add specific config and webui campaign outcomes
Calmingstorm Sep 29, 2026
06fcbd4
docs: document config and webui release behavior
Calmingstorm Sep 29, 2026
1c0e878
docs: clarify remaining lane evidence status
Calmingstorm Sep 29, 2026
42f75d5
docs: complete v4.10.0 issue status ledger
Calmingstorm Sep 29, 2026
e9f5057
docs: add remaining campaign release notes
Calmingstorm Sep 29, 2026
ccdfacc
docs: correct packaging regression mappings
Calmingstorm Sep 29, 2026
210d2ab
Keep integrated documentation and monitoring regressions lint-clean
Calmingstorm Sep 29, 2026
c80f496
fix: make websocket revocation terminal and preserve mapping entry al…
Calmingstorm Sep 29, 2026
b7e1de0
test: reconcile process lease fixtures with proven cleanup
Calmingstorm Sep 29, 2026
7ec03b9
Document independent integration repairs and upgrade behavior
Calmingstorm Sep 30, 2026
46d8dcd
fix(evidence): preserve full identity and nested outcome provenance
Calmingstorm Sep 30, 2026
1bc6944
Bound oversized evidence identity and align reviewed capability contr…
Calmingstorm Sep 30, 2026
0507524
Preserve streamed timeout evidence and reconcile real dispatch test c…
Calmingstorm Sep 30, 2026
4bf1d9e
test: reconcile auth provenance and provider lifecycle integration fi…
Calmingstorm Sep 30, 2026
73d5b1d
Record incomplete campaign gate evidence and remaining integration work
Calmingstorm Sep 30, 2026
87d16fa
Finish portable CLI names and safe legacy migration guidance for #490
Calmingstorm Sep 30, 2026
1fc99c7
Make odin the API client and safely refuse obsolete server invocation…
Calmingstorm Sep 30, 2026
74911f0
Synchronize shared refresh regression on real admin admission instead…
Calmingstorm Sep 30, 2026
1c2074a
test: model proven process cleanup in fixtures
Calmingstorm Sep 30, 2026
491b919
Preserve missing-handle cleanup uncertainty and isolate shutdown barr…
Calmingstorm Sep 30, 2026
3c63d80
Make local kill publication tests depend on explicit cleanup verdicts
Calmingstorm Sep 30, 2026
7252fb9
test: cover inert process cleanup proof and SSH cancellation branches
Calmingstorm Sep 30, 2026
0b268cb
Reconcile retained process evidence tests with group-only cleanup unc…
Calmingstorm Sep 30, 2026
659c50c
test: keep cleanup proof unconfirmed after failed or cancelled leader…
Calmingstorm Sep 30, 2026
d225502
test: exercise lifetime retirement and SSH retry settlement edge cases
Calmingstorm Sep 30, 2026
1b08631
Publish cleanup proof only after affirmative leader reaping
Calmingstorm Sep 30, 2026
b3e85de
test: restore tool outcome and retention boundary coverage
Calmingstorm Sep 30, 2026
6431dac
test: cover system handler authorization and effect settlement
Calmingstorm Sep 30, 2026
eba2ac0
test: keep stale-frame clock independent of retired session
Calmingstorm Sep 30, 2026
585a8d2
test: cover durable reconnect fencing and attachment trust failures
Calmingstorm Sep 30, 2026
01472a6
test: keep reconnect regression assertions within lint limit
Calmingstorm Sep 30, 2026
759ff63
test: exercise attachment secret scrub before conversational dispatch
Calmingstorm Sep 30, 2026
8dd89b7
Use inert supervisor settlement in process authority regressions
Calmingstorm Sep 30, 2026
c0b2d4e
test(config,llm): cover upgrade fallback and recovery ownership contr…
Calmingstorm Sep 30, 2026
aece379
test: cover learned integrity audit scan failures and scheduler trans…
Calmingstorm Sep 30, 2026
8014051
test(learning): prove failed consolidation preserves rules and disabl…
Calmingstorm Sep 30, 2026
9a80cdc
test(config): reject implicit webhook insertion without submitted intent
Calmingstorm Sep 30, 2026
723701c
test(config): validate serving selectors local authority and legacy a…
Calmingstorm Sep 30, 2026
522a33c
Restore API coverage for auth fences, credential failures and update …
Calmingstorm Sep 30, 2026
82b3cc9
Cover provider revalidation, signed webhooks and updater preservation…
Calmingstorm Sep 30, 2026
a978f19
Record passing integrated campaign gates and approved CLI migration
Calmingstorm Sep 30, 2026
d997dc5
Tolerate removed Grafana config and re-raise secured HTTP exceptions
Calmingstorm Sep 30, 2026
c951183
docs: remove stale inventory counts
Calmingstorm Sep 30, 2026
caf9d3b
Preserve safe compatibility for URL-less legacy PDF sources
Calmingstorm Sep 30, 2026
5f36db6
Regenerate API reference after middleware line shifts
Calmingstorm Sep 30, 2026
3cb69a6
Report successful retries independently of dispatch uncertainty
Calmingstorm Sep 30, 2026
f293b00
fix(computer): resolve released input uncertainty without reconciliation
Calmingstorm Sep 30, 2026
2b06c96
fix(process): settle verified remote group cleanup with scoped caveat
Calmingstorm Sep 30, 2026
ad9b51b
Document campaign review corrections and fix inventory test lint
Calmingstorm Sep 30, 2026
7db8c15
test(process): prove remote group-only settlement with live escapee
Calmingstorm Sep 30, 2026
3047c46
test(turn-state): synchronize cancellation at recovery wait
Calmingstorm Sep 30, 2026
5185ee6
fix(time): preserve uppercase AM/PM clock markers
Calmingstorm Sep 30, 2026
59b7b5d
fix(time): reject unconsumed bare-clock tails and parse dotted meridiem
Calmingstorm Sep 30, 2026
a5322b4
fix(processes): exempt restored remote evidence from shutdown veto
Calmingstorm Sep 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
208 changes: 208 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,214 @@ Each GitHub release body is the matching section of this file.

## [Unreleased]

### Fixed

- Campaign review corrections: successful SSH or executor recovery retries now
report success while retaining uncertainty about earlier dispatches. Emergency
input release clears an `unknown_release` fence when the guardian ledger says
released, with fresh consent still required; native target-continuity loss
remains quarantined. Verified-empty remote process groups report clean exit
or kill with an explicit process-group-only containment caveat, not a blanket
unknown outcome. Unchanged durable legacy PDF imports reuse their basename
source; changed or unverifiable legacy content requires an explicit source
choice because historical imports did not retain originating URLs. Removed
`grafana_alerts` config is silently tolerated, secured HTTP exceptions are
re-raised rather than returned, and overview docs link authoritative inventory
sources instead of stale totals and list all four computer-use handoffs.
- Missing local process handles no longer count as proof that descendants have
exited. Unsettled records retain their host authority and block clean shutdown;
restored read-only evidence does not attempt to terminate an old execution.
A group-empty scan also stays unproven until the leader has been reaped, so a
reap timeout or cancellation cannot publish a premature cleanup verdict.
- Scheduler reservations are revalidated against current identity and pause
state before execution; malformed trigger filters no longer block valid
schedules. Empty trigger subscriptions are rejected. Retry timestamps reflect
the retry, clock-only reminders handle both daylight-saving fall-back
instants, invalid 12-hour values are rejected, and 24-hour clocks may precede
the day text. Workflow conditions run after empty successful output, scheduled
native errors remain failures, deferred host defaults follow each tool's
contract, nested skill inputs are checked against the selected skill schema,
and `update_schedule` exposes workflow condition/failure-policy fields.
- Provider-declared incomplete Codex and Ollama responses are marked incomplete
and failed without discarding partial text or retrying it away; complete long
replies remain unchanged. Empty native Ollama output is an error. DeepSeek
overflow classification applies to production-created clients, schema
sanitization preserves keyword-named parameters, and bounded auxiliary
qualification accepts expected truncated/empty probe responses. Compatible
and Ollama accounting uses response-scoped model/token facts; canonical model
selection reaches covered requests, borrowed auxiliary wrappers survive
reloads, and one settled half-open circuit-breaker probe is admitted at a
time. OpenRouter fallback limits account for every permitted route.
- Codex credential publication uses exclusive private temporary files and
completes partial writes before replacing the destination. Manual login
merges accounts rather than replacing the pool; failed merged writes preserve
existing accounts. Refresh, administration and quota checks are fenced against
account deletion, reordering, re-authentication and reloads. Authentication
failure rotates away from a manually selected account, and displayed account
indexes continue to identify the intended valid record when malformed entries
are present.
- Tool execution preserves outcome uncertainty after ambiguous dispatch, inner
timeouts and later retries; output text cannot forge execution metadata.
Typed tool failures survive native, deferred and validation routes, retry exit
status remains authoritative, `max_retries=0` still makes the initial SSH
attempt, and streaming handles long lines and reaps children when consumers
fail. Validation regexes run with a deadline off the event loop; numeric zero
compares correctly, refused probes are not reported as executed, invalid HTTP
probes acquire no host lease, and truncation/risk metadata tracks delivery and
shared action-aware classification.
- Skills persist activation before publication; editing disabled skills keeps
them disabled, and edit/delete operations target the loaded artifact.
Requirements honor installed versions and extras, accept valid compound PEP
508 constraints and reject unsafe forms. Skill host commands and selected
skill invocation pass inherited admission and current-scope checks; validation
uses requester tier and effective host. `systemctl` global options no longer
hide lifecycle verbs from risk classification. Unsupported generic
`SkillContext` calls are refused, its helper documentation distinguishes
synchronous from asynchronous methods, and authorized retained results keep
the complete output.
- Scoped memory reads and deletes honor explicit personal/global scope while
omitted scope retains its previous behavior. Empty compaction uses a
deterministic nonempty fallback; history eligibility is applied before
result limits, and cross-channel fallback selects globally newest eligible
records. API execution sessions remain ephemeral, owned scoped searches are
available to their owner, and foreign scopes are rejected. PDF imports use URL
identity by default; knowledge summaries compare authoritative snapshots,
duplicate identifiers remain lossless, rolling summaries are recognized by
APIs and metrics, cold embedding initialization leaves the event loop
responsive, and hybrid fusion keeps the best-ranked payload.
- Learned entries with matching keys remain isolated by owner; edits and use
extend expiry. Audit search/statistics and failure aggregates include retained
rotations with stable coverage metadata, complete captured files and correctly
framed diffs. Prompt totals include learned context. Prefix metrics identify
unmeasured values instead of claiming upstream cache hits. Startup diagnostics
validate knowledge database integrity and recognize static and dynamic API
credentials without disclosure; tokenless HTTP readiness no longer depends
on an unconfigured Discord gateway. Usage ingestion releases its lock after
database-open failures, and resource counts use the configured session path.
- Computer recovery preserves incident lineage through emergency release,
validates and archives qualified absence evidence, and reconciles only owned
private evidence orphans. Clean resume publishes current recovery authority;
status exposes bounded native recovery guidance without private handles.
Expired inventory proofs and settled terminal caches are retired safely.
Proven pre-input refusals restore eligible observations without weakening
held-input or unknown-release fences, and isolated X11 preflight requires
privilege only when configured to use it.
- Background process admission includes pending starts and unresolved owned
executions. Process lifetimes bind exact generations; persistence failures
trigger cleanup without abandoning lifecycle ownership, local leader exit is
not completion until descendants settle, and remote cleanup failures remain
explicitly unknown. Verified-empty remote process groups settle with a
process-group-only caveat, not a claim that escaped descendants ended.
Completed remote evidence retains its bounded retrieval deadline even when
execution cleanup remains unknown. Explicit local termination claims success
only after owned cleanup is proved. Remote stdin reports accepted bytes after
partial writes, and cancelled SSH master
closure retains its ownership handle for retry. Host-key mismatch quarantine
survives unrelated inventory publication, host management publication is
serialized, and CA enrollment verifies signing authorities and endpoint
principals. `apply_patch` preserves untouched text boundaries, rejects
nonregular files without blocking on FIFO open, and closes snapshots on
semantic rejection.
- HTTP browser sessions are bound to credential origin and generation, expire
when the originating credential is revoked or rotated, and lose anonymous
development authority when authentication is enabled. Invalid static token
tiers are refused rather than treated as administrator. Supported WebSocket
authentication carriers use consistent credential precedence, login handles
malformed JSON shapes, security headers cover raised HTTP responses, expired
sessions are retired, and reconnecting WebSockets remain subject to chat rate
limits. Process termination reports acknowledged outcomes. Failed self-update
paths restore operator files. Observed WebSocket credential revocation is
terminal for that transport, even if an old credential is later restored;
schema-aliased mapping fields survive partial configuration saves and reload.
- Autonomous loop failures count toward the configured consecutive-failure
limit; terminal findings and natural completion timing are preserved. Outbound
per-target admission is serialized and first events work on young hosts.
Scheduled digest fallback stays within message limits, resume selects the
requester's own preserved work, and buffered intake retains attachments.
Authorized retrieval preserves complete truncated text/PDF evidence while
retaining existing ownership, channel, quota and expiry fences. Generated
images reject incomplete PNGs and report upload failures as failures.
- Incus deployment syntax and required UI assets, wheel model-hint data, CLI
failure exit codes, browser dependencies in official install paths, and the
Debian SSH-key default and safe default-only upgrades are corrected. Browser
runtimes are provisioned and qualified without enabling new capabilities;
custom SSH keys remain untouched. Compose now supports atomic config
persistence and safely migrates an existing single-file config without
overwriting a newer directory config, preserving setup state and listener
consent during relocation. Portable `odin-server` and `odin-client` commands
are provided for every package type with documented migration guidance;
`odin` now runs the API client consistently on every install type and the
server uses `odin-server`. Old server-style `odin` invocations with a config
file, `-c`, `--config` or `--env-file` refuse to send a prompt, explain the
new server command, and exit nonzero. Existing Python/source server scripts
and units must switch to `odin-server`; Debian client usage is unchanged.
- Configuration migrations no longer require an adjacent write for no-op
completion, and ceiling migration preserves a newer acknowledged edit.
Retired Codex model migration now covers canonical agent selectors,
allowlists and hints. Existing legacy model/effort pairs continue to load with
a warning when invalid; saves validate the effective canonical selector.
Partial config saves update submitted leaves only; deleting a mapping entry
requires the explicit `{ "$delete": true }` marker, while JSON `null` remains
a value. Provider enable routes parse booleans correctly. Nonpositive tool
timeouts and negative archive caps are rejected on save and tolerated at
startup with warnings and safe defaults; explicit zero archive retention
still means retain nothing. Legacy Kimi timeout adaptation is bounded, and
legacy configs with an absent provider keep their selected main model.
- The WebUI coalesces model-save intent, fences stale provider/MCP/operational
page requests, keeps Discord identity fields consistent, and supports native
keyboard activation of user selection. Skill source highlighting preserves
original text. Paused Live Tail retains at most 2,000 raw records and reports
drops; relative-time filters advance only while active. Live Tail uses bounded
RE2 syntax, with unsupported lookaround/backreferences reported rather than
silently accepted. Trace filtering precedes result limits, schedule forms can
submit workflow steps, and missed terminal events become explicitly unknown
history rather than fabricated running or successful results. Stream
correlation uses unique backend registry IDs and full invocation attribution.
- Agent repetition detection hashes the full canonical scrubbed evidence before
delivery, so changing envelope IDs, cursors or previews cannot bypass the
guard. Cancellation before an agent coroutine starts is durably settled as a
killed trajectory. The default Codex agent catalog honors authored model
selection hints.
- Tool catalogs now hide browser and knowledge tools when their backends are
disabled; email visibility follows executor-effective startup configuration,
and dynamic computer tools participate in built-in disablement. MCP discovery
isolates invalid header schemas to the affected tool, rejects terminal
newlines in header values, and preserves structured results without repeating
equivalent JSON summaries. SMTP acceptance is retained across QUIT cleanup
failures, failed IMAP searches are not reported as empty results, and image
validation decodes complete PNG data under size limits before delivery.
- Removed native monitoring references were audited through current source,
tests and documentation tooling; generated API references remain to be
regenerated after campaign integration. Generic internal resource/token/pool
metrics and `/api/pools` remain; no native Prometheus formatter or endpoint is
implied by this removal.

### Changed

- Documentation now describes setup-wizard restart behavior, supported
WebSocket authentication, managed Hyprland first use, current provider/model
capabilities, Codex refresh behavior, tool/loop iteration limits and retired
model migration accurately. Stale inventory counts and removed monitoring
claims were removed.
- SMTP and IMAP verify server certificates and hostnames by default; operators
using self-signed mail servers must explicitly opt out. Accepted email is not
misreported if QUIT cleanup fails, and IMAP search failures are not treated as
proof of message absence.
- The WebUI prevents stale responses from replacing newer selections and
operational state; live-tail retention/filtering is bounded, trace filtering
precedes result limits, schedule forms submit workflow steps, and execution
call correlation uses complete invocation identity. Host CA enrollment UI
identifies the expected fingerprint as the signing CA fingerprint.

### Removed
- Removed native Grafana alert receiving, remediation, management routes and
scheduler trigger publication, the unauthenticated Prometheus `/metrics`
endpoint and its exporters, and `SkillContext.query_prometheus`. Existing
configuration keys are tolerated and ignored; component checks remain on
`/health`. Legacy removed-source schedules remain readable but inert.
External operator-configured MCP integrations are unchanged. There was no
native Loki integration to remove.

## [4.10.0] - 2026-09-29

### Added
Expand Down
10 changes: 7 additions & 3 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -2,15 +2,19 @@ FROM python:3.12-slim

WORKDIR /app

# Install dependencies first for better layer caching
# Include source in the distribution so console entrypoints work outside /app.
COPY pyproject.toml .
COPY src/ src/
# .[pdf] — analyze_pdf needs PyMuPDF; without it the catalog gate hides the
# tool, so an official image would ship without a capability it advertises.
RUN pip install --no-cache-dir ".[pdf]"
RUN pip install --no-cache-dir ".[pdf,browser]"
ENV PLAYWRIGHT_BROWSERS_PATH=/app/.cache/ms-playwright
COPY scripts/install-browser-runtime.sh /app/install-browser-runtime.sh
RUN sh /app/install-browser-runtime.sh python --with-deps

# Copy application source
COPY src/ src/
COPY ui/ ui/
COPY scripts/docker-compose-entrypoint.sh /app/docker-compose-entrypoint.sh

# Working directory for local user commands (tools.local_working_dir).
# Deliberately OUTSIDE the install root (/app here) and outside the data dir:
Expand Down
Loading
Loading