Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
386 commits
Select commit Hold shift + click to select a range
ff226af
docs(architecture): align managed resume status (#4034)
zhiiw Aug 27, 2026
3e98eb2
fix(release): attest and verify desktop updates end to end (#4008)
M4n5ter Aug 28, 2026
2b5dd8a
feat(runtime-host): add managed SSH on-demand activation (#3985)
M4n5ter Aug 28, 2026
172bcfd
refactor(runtime-host): share the client peer endpoint (#4036)
M4n5ter Aug 28, 2026
a817008
docs: add DeepWiki badge (#4035)
kowanietz Aug 28, 2026
3bbc458
docs: clarify DeepWiki disclosure (#4052)
M4n5ter Aug 28, 2026
b6b647c
perf(storage): resolve artifact purge paths with bounded concurrency …
me2seeks Aug 28, 2026
10470e6
feat(runtime-host): add peer mesh membership (#4048)
M4n5ter Aug 28, 2026
9343da9
fix(runtime): avoid OpenAI tool_search name collision (#3958)
liugddx Aug 28, 2026
7090d9e
feat(ui): add UI and terminal font size settings to Appearance (#4024)
liugddx Aug 28, 2026
c848fcb
fix(runtime): persist contextRemaining on the stored TokenUsageMessag…
me2seeks Aug 28, 2026
e85a61a
fix(cli): split MCP capability provider to avoid pulling runtime-host…
me2seeks Aug 28, 2026
e0aedcc
fix(cli): surface parked /resume plans as informational notices, not …
me2seeks Aug 28, 2026
98d3965
feat(cli): coordinate npm-global Runtime Host updates (#3925)
me2seeks Aug 28, 2026
70a66ac
feat(cli): confirmed second Ctrl+O/Ctrl+T collapses blocks stranded a…
me2seeks Aug 28, 2026
2f7e389
fix: surface and render OpenAI and Claude reasoning summaries (#2645)
hqhq1025 Aug 28, 2026
fd31c92
docs: align the DeepWiki badge with the badge row (#4056)
Astro-Han Aug 28, 2026
5dfe4f6
feat(cli): add Runtime Host-backed user commands (#3210)
me2seeks Aug 28, 2026
1ab7638
docs(contributing): document issue assignment commands (#4045)
jackeyfaker77 Aug 28, 2026
cf50fad
docs(architecture): audit context compaction (#4046)
fxl112233 Aug 28, 2026
173cb1b
fix(core): add DeepSeek V4 Flash Vision to model metadata (#3605)
yunaremaia Aug 28, 2026
e8028fc
fix(ui,cli): count down provider retry wait from the event timestamp …
me2seeks Aug 28, 2026
a956b1a
feat(runtime-host): establish canonical managed lifecycle transaction…
M4n5ter Aug 28, 2026
a6a08b8
feat(workhub): persist delegation linkage (#3935)
ARE404 Aug 28, 2026
4b20261
feat(runtime-host): support WSL as a local environment (#4064)
M4n5ter Aug 28, 2026
6aa8f38
feat(runtime-host): discover peer mesh routes (#4055)
M4n5ter Aug 28, 2026
3098674
fix(desktop): state a failed turn's outcome where it happened (#4073)
Astro-Han Aug 28, 2026
590d37c
feat(tui): manage MCP servers from /mcp (#4062)
me2seeks Aug 28, 2026
9baa499
fix(runtime-host): recover WSL roots after remount (#4084)
M4n5ter Aug 28, 2026
cb60d41
feat(runtime-host): target development host packages (#4087)
M4n5ter Aug 28, 2026
30adc0d
feat(desktop): drop the rail-footer build stamp (#4086)
Astro-Han Aug 28, 2026
b58428a
fix(ui): drop the reasoning body's left rail, restore upstream geomet…
Astro-Han Aug 28, 2026
3b9a470
feat(runtime): bind new sessions to connection identity (#3864)
me2seeks Aug 28, 2026
1975adb
fix(runtime-host): update existing WSL deployments (#4095)
M4n5ter Aug 28, 2026
a0062ff
docs(release): align source-only release records (#4067)
Astro-Han Aug 28, 2026
981f7e0
refactor: shrink the renderer's first-load chunk and remove three dup…
Astro-Han Aug 28, 2026
4e85f51
feat(runtime): defer non-direct tools by default (#4098)
Astro-Han Aug 28, 2026
a94d077
docs(desktop): record the workbar stories entry (#4104)
Astro-Han Aug 28, 2026
2c06631
fix(ui): state an aborted turn's outcome after its timeline (#4090)
Astro-Han Aug 28, 2026
b699a2e
fix(desktop): offer safe resume after completed tool timeout (#4075)
liugddx Aug 29, 2026
2eb4f1a
fix(desktop): deliver mid-session tail append after loading history (…
liugddx Aug 29, 2026
bc2f74b
feat(runtime-host): manage peer meshes from Desktop (#4092)
M4n5ter Aug 29, 2026
53a4aa7
fix(desktop): clarify partial transcript ranges (#3880)
Sun-GLiang Aug 29, 2026
9deee2a
fix(scripts): encode direct entrypoint paths (#4077)
orangeCatDeveloper Aug 29, 2026
a2fcc25
fix(inspector): align cost summary style (#4122)
Phoenix500526 Aug 29, 2026
ff07d1b
test(cli): reuse shared wait budget in tui-mcp-control (#4106)
bferanmi806-sketch Aug 29, 2026
e0c0b60
fix(models): load generated TypeScript on Node 26 (#4076)
orangeCatDeveloper Aug 29, 2026
d144511
feat(inspector): collapse loaded history (#4120)
Phoenix500526 Aug 29, 2026
da7a3a8
docs(security): align sandbox boundary claims (#4065)
Sun-GLiang Aug 29, 2026
17aae7c
fix(desktop): keep session workspace action identities fixed (#4110)
Astro-Han Aug 29, 2026
ed61501
fix(runtime-host): align enabled model limit (#4124)
Phoenix500526 Aug 29, 2026
b69898c
feat: add Desktop Nightly update channel (#4108)
Astro-Han Aug 29, 2026
1bd5cef
fix(runtime): classify post-tool model timeouts (#4118)
liugddx Aug 29, 2026
3bfe20a
perf(desktop): reduce UI stalls during tool output (#3921)
Colafornia Aug 29, 2026
16d06f2
docs(computer-use): document package boundaries (#4016)
yuzhiyang1 Aug 29, 2026
c314e9e
fix(runtime-host): surface session copy failure cause (#4044)
fxl112233 Aug 29, 2026
098415a
feat(runtime-host): discover coordination relays automatically (#4126)
M4n5ter Aug 29, 2026
b213922
refactor(desktop): make the session UI store the only pending authori…
Astro-Han Aug 29, 2026
2800680
fix(runtime-host): recover settled scheduled task runs (#4135)
me2seeks Aug 29, 2026
82b36dc
fix(runtime): preserve Plan final responses (#3886)
Sun-GLiang Aug 29, 2026
68b71c5
perf(desktop): give the shell's state the scope of its readers (#4125)
Astro-Han Aug 29, 2026
c3d1c53
feat(release): publish npm nightly snapshots (#4131)
M4n5ter Aug 29, 2026
496cce4
fix(desktop): prepare peer support in development (#4134)
M4n5ter Aug 29, 2026
724672a
fix(computer-use): require explicit lab root (#4072)
orangeCatDeveloper Aug 29, 2026
2bde4ea
test(macos): isolate environment-dependent fixtures (#4141)
Sun-GLiang Aug 29, 2026
01369b0
fix(desktop): simplify partial history notice (#4140)
Sun-GLiang Aug 29, 2026
1c6b68e
fix(runtime-host): handle question cancellation during drain (#4013)
yuzhiyang1 Aug 29, 2026
319b7ed
refactor(storage): retire unread workflow projection tables (#3937)
Sun-GLiang Aug 29, 2026
b16376d
refactor(runtime-host): remove the uncalled execution.inspect.resolve…
liuxiaocs7 Aug 29, 2026
8237a9a
refactor(storage): remove the unused legacy Usage session scanner (#4…
heeoneie Aug 29, 2026
35a015e
fix(desktop): align MCP editor choice icons with radio and label (#4149)
liuxiaocs7 Aug 29, 2026
f701b8d
refactor(storage): add SQLite context offload foundation (#4078)
likun666661 Aug 29, 2026
4638e64
refactor(desktop): remove internal compatibility facades (#4151)
Astro-Han Aug 29, 2026
8b93dd5
refactor(storage): add bounded context offload lifecycle (#4159)
likun666661 Aug 29, 2026
bd2ec47
refactor(runtime): remove unused preview APIs (#4158)
Astro-Han Aug 29, 2026
e520561
refactor(storage): add context offload root authority (#4165)
likun666661 Aug 29, 2026
a84486e
refactor(desktop): remove expired local compatibility migrations (#4157)
Astro-Han Aug 29, 2026
afc1a75
refactor(ui): make the transcript the only writer of its scroll posit…
Astro-Han Aug 29, 2026
8c15861
fix(desktop): stabilize local peer recovery (#4146)
M4n5ter Aug 29, 2026
fdef796
refactor(release): project manifests from shipped files (#4152)
Astro-Han Aug 29, 2026
2fa1f78
feat(ui): render session attachment images in Markdown (#4137)
Astro-Han Aug 29, 2026
a57d42c
refactor(computer-use): remove obsolete experiment commands (#4170)
Astro-Han Aug 29, 2026
104d5fc
build: generate model metadata from committed snapshot (#4166)
Astro-Han Aug 29, 2026
2cab093
fix(ui): guide legacy session account recovery (#4102)
me2seeks Aug 29, 2026
5d2df91
refactor(storage): separate Read image values from SQLite (#4168)
likun666661 Aug 29, 2026
20f256c
fix(runtime-host,ui,cli): name ordinary tool calls during the live wi…
me2seeks Aug 29, 2026
f689c34
refactor: remove dormant Git workspace write path (#4174)
Astro-Han Aug 29, 2026
c3d4eae
feat(desktop): manage the supervised Local Host (#4161)
M4n5ter Aug 29, 2026
d83a082
refactor(runtime): remove legacy child AgentRun control (#4173)
Astro-Han Aug 29, 2026
3a8d600
feat(runtime-host): add bounded peer transit (#4142)
M4n5ter Aug 29, 2026
555a62c
feat(runtime-host): reconcile peer Mesh transit (#4144)
M4n5ter Aug 29, 2026
f25b5d2
feat(runtime-host): expose peer Mesh transit controls (#4147)
M4n5ter Aug 29, 2026
be78daf
feat(providers): add Alibaba Token Plan Responses compatibility (#3255)
MoonOld Aug 29, 2026
1ae4541
feat(workhub): project delegated execution status (#4115)
ARE404 Aug 29, 2026
6b75a72
fix(runtime-host): recover legacy Root source messages (#3923)
Sun-GLiang Aug 29, 2026
00a15ab
fix(desktop): ignore slash path separators (#3865)
Sun-GLiang Aug 29, 2026
6fca2f5
feat(storage): read durable Session context refs (#4182)
likun666661 Aug 29, 2026
d7efbb4
feat(runtime-host): own multi-account API-key onboarding (#3882)
me2seeks Aug 29, 2026
8aed381
refactor: remove the ExploreAgent tool (#4176)
Astro-Han Aug 29, 2026
7980263
test(desktop): cover renderer crash fallback states (#3947)
liuxiaocs7 Aug 29, 2026
bb12562
fix: align protocol compatibility declaration epoch (#4204)
Astro-Han Aug 29, 2026
9db7abb
fix(desktop): replace conflicting Local Runtime Host during startup (…
M4n5ter Aug 29, 2026
aa58623
fix(desktop): truncate long file paths in the changes panel (#4155)
liuxiaocs7 Aug 29, 2026
593efb9
fix(desktop): stabilize WorkHub projection checkpoints (#4210)
Astro-Han Aug 29, 2026
827b3fd
test(ui): keep the composer's inline-completion seam closed (#4208)
abhinav-phi Aug 29, 2026
6240246
perf(ui): scope prompt rail observation to mounted turns (#4203)
Astro-Han Aug 30, 2026
c959b40
feat(runtime-host): add session guest authority (#4194)
M4n5ter Aug 30, 2026
8f33dcc
perf(ui): incrementally prepare streamed Markdown math (#4207)
Astro-Han Aug 30, 2026
b79cd01
feat(runtime-host): scope shared session observation (#4195)
M4n5ter Aug 30, 2026
cfe87ba
feat(desktop): share Runtime Host sessions with guests (#4196)
M4n5ter Aug 30, 2026
ce2052a
feat(runtime-host): admit approved guest Turn requests (#4197)
M4n5ter Aug 30, 2026
847e3c9
feat(desktop): approve guest Turn requests (#4198)
M4n5ter Aug 30, 2026
d234670
fix(desktop): enable relay discovery for Peer Mesh (#4229)
M4n5ter Aug 30, 2026
d093ba5
feat(runtime-host): separate queued successor turns (#4130)
me2seeks Aug 30, 2026
2bf7ced
fix(desktop): report the model actually tested when Test Connection f…
liuxiaocs7 Aug 30, 2026
c33617f
perf(desktop): bound transcript rendering and eliminate scroll LoAF (…
Astro-Han Aug 30, 2026
b324c1f
fix(runtime-host): preserve complete transcript edge turns (#4244)
Astro-Han Aug 30, 2026
80ffda4
test(desktop): stop the picker spec racing two upstream guards (#4225)
orangeCatDeveloper Aug 30, 2026
e864f8f
test(desktop): story-cover browser panel edge and navigation-failure …
liuxiaocs7 Aug 30, 2026
563452d
refactor(desktop): lock renderer root architecture (#4088)
chihumyum Aug 30, 2026
8c491e6
feat(runtime): establish managed mutation lifecycle authority (#3741)
zhiiw Aug 30, 2026
9ff2675
fix(desktop): ratchet renderer debt against the base tree, not its le…
liuxiaocs7 Aug 30, 2026
bdb103d
fix(desktop): remove first-send empty hero flash (#4246)
Sun-GLiang Aug 30, 2026
838936c
fix(desktop): retire consumed steering queue cards (#4232)
Sun-GLiang Aug 30, 2026
1451071
test(desktop): cover model picker failure and edge states (#4162)
liuxiaocs7 Aug 30, 2026
1f95a37
test(desktop): cover toast error and edge states (#4167)
liuxiaocs7 Aug 30, 2026
2db04c2
fix(desktop): preserve external-session rows across source switches (…
liuxiaocs7 Aug 30, 2026
7eb1ea4
fix(core): quarantine retired OpenCode Free model (#4216)
liuxiaocs7 Aug 30, 2026
2e2c552
test(desktop): cover change panel failure and edge states (#4169)
liuxiaocs7 Aug 30, 2026
19e211e
fix: align Desktop Nightly with the Infra rsync contract
Astro-Han Aug 30, 2026
2b82b9d
fix(runtime): fall back when Codex compaction is rejected (#4253)
liugddx Aug 30, 2026
f2e1033
fix(runtime): allow reading workspace ancestor directories under macO…
jsiu93 Aug 30, 2026
0c43678
fix(core,storage): unify the Codex thread source gate (#3702)
cat0825 Aug 30, 2026
ef073ff
refactor(cli): centralize localized TUI copy (#3990)
orangeCatDeveloper Aug 30, 2026
d50efcf
fix(desktop): stop Runtime Host after launcher loss (#4114)
hydraxman Aug 30, 2026
4c8b37c
fix(cli): wait for Host readiness before pairing (#4230)
orangeCatDeveloper Aug 30, 2026
c62980c
fix(runtime): discover contained symlinked skill directories (#4116)
Sun-GLiang Aug 30, 2026
3c52d2c
refactor(core): report capability audit facts directly (#3815)
joebasrawi Aug 30, 2026
be3a029
fix(desktop): realign renderer architecture ledger with source (#4255)
liuxiaocs7 Aug 30, 2026
1c52241
fix(core): refuse models whose declared output has no text (#4243)
Joob1n Aug 30, 2026
8f31305
feat(runtime-host): bind capability providers to Client owners (#4187)
me2seeks Aug 30, 2026
296b05a
ci: declare the Desktop Nightly environment (#4260)
Astro-Han Aug 30, 2026
d07ff87
feat(runtime-host): add Gitoxide candidate and accepted-tree read dat…
zhiiw Aug 30, 2026
95c80a7
feat(runtime): guide Auto tool selection by final tool surface (#3705)
testikun Aug 30, 2026
7bc66fd
test(core): unit-test the shared Unicode sanitizer (#3692)
rekcilyssup Aug 30, 2026
2cb1044
fix(desktop): show the Codex device sign-in code on connection-detail…
sosyz Aug 30, 2026
03ff1bc
test(desktop): story-cover Daily Review edge states (#4220)
liuxiaocs7 Aug 30, 2026
99c8705
test(desktop): story-cover Agent Graph edge states (#4212)
liuxiaocs7 Aug 30, 2026
aafc095
test(desktop): story-cover chat transcript edge states (#4211)
liuxiaocs7 Aug 30, 2026
be8608e
refactor: remove unvalidated review additions (#4264)
Astro-Han Aug 30, 2026
9582ce3
fix(runtime): canonicalize macOS sandbox temp roots (#4234)
jsiu93 Aug 30, 2026
4cbe224
fix(desktop): connect shared sessions through Peer Mesh (#4238)
M4n5ter Aug 30, 2026
b832348
fix: pin Desktop Nightly feed channel (#4266)
Astro-Han Aug 30, 2026
9793520
refactor(cli): ship one Eval runtime in the npm CLI package (#3946)
liuxiaocs7 Aug 30, 2026
60cb8b7
fix(build): derive Astryx surface inventory from @astryxdesign/core (…
liuxiaocs7 Aug 30, 2026
5058b29
fix(cli): refresh connection identities after /setup saves a connecti…
jsiu93 Aug 30, 2026
5d519d6
fix: bootstrap the Desktop Nightly destination (#4271)
Astro-Han Aug 30, 2026
756b34e
fix: support rsync 3.1 for Nightly bootstrap (#4280)
Astro-Han Aug 30, 2026
462a861
perf(runtime): remove generic turn tail injection (#4278)
Astro-Han Aug 30, 2026
66e6f4e
test: make Desktop Nightly validation deterministic (#4282)
Astro-Han Aug 30, 2026
8f797cf
fix(ui): allow composer attachments while a turn is running (#4231)
Sun-GLiang Aug 31, 2026
ac59b47
测试:扩展桌面端无障碍行为覆盖 (#4202)
1625567290 Aug 31, 2026
bc1b1d6
docs(readme): link Desktop Nightly downloads (#4294)
Astro-Han Aug 31, 2026
4a2e081
test(desktop): story-cover the terminal panel's failure and edge stat…
liuxiaocs7 Aug 31, 2026
f66e7ad
fix(desktop): name the session in the usage activity task column (#4219)
liuxiaocs7 Aug 31, 2026
c5bb068
docs(eval): restructure README with navigation and a troubleshooting …
amaldevcm Aug 31, 2026
1340990
feat(storage): define quiescent session snapshot boundary (#2968)
MicroGery Aug 31, 2026
4050099
feat(cli): reconcile externally replaced npm Runtime Hosts (#4069)
me2seeks Aug 31, 2026
28bdbc6
feat(runtime-host): bind OAuth login to Connection entities (#3924)
me2seeks Aug 31, 2026
e160eed
refactor(desktop): separate shared sessions from Runtime Host profile…
M4n5ter Aug 31, 2026
00389bd
refactor(runtime-host): reconcile Peer Mesh membership state (#4274)
M4n5ter Aug 31, 2026
a5610a5
feat(runtime-host): project peer Host reachability (#4275)
M4n5ter Aug 31, 2026
1d380b2
feat(desktop): make Peer Mesh operations responsive (#4276)
M4n5ter Aug 31, 2026
1e75800
feat(desktop): manage WSL host projects (#4306)
M4n5ter Aug 31, 2026
ef94235
fix(runtime-host): copy user-uploaded attachments when branching a co…
liuxiaocs7 Aug 31, 2026
6e6af95
chore(desktop): drop the completed hook transition section (#4332)
Astro-Han Aug 31, 2026
c54092e
feat(desktop): migrate Nightly to GitHub Releases (#4317)
Astro-Han Aug 31, 2026
bd951aa
refactor(runtime): persist durable Tool Result projections (#4287)
Astro-Han Aug 31, 2026
29d02dc
fix: preserve skill outcomes across queued-message recovery
Sun-GLiang Aug 31, 2026
316ff5a
ci: cache Rust builds with Kache (#4322)
M4n5ter Aug 31, 2026
ef2ce44
docs: remove immutable releases Nightly prerequisite (#4347)
Astro-Han Aug 31, 2026
93d2178
feat(attachments): preserve image Read references for non-vision mode…
me2seeks Aug 31, 2026
4ccaa18
feat(tui): publish MCP tools to remote Runtime Hosts (#4200)
me2seeks Aug 31, 2026
064c3b2
feat(desktop): expose OAuth connection accounts (#4314)
me2seeks Aug 31, 2026
a8597ec
refactor: collapse duplicate test infrastructure (#4323)
Astro-Han Aug 31, 2026
36f058c
refactor(runtime): budget and compact effective model history (#4348)
Astro-Han Aug 31, 2026
d0e238c
feat(storage): add dormant SessionTodo foundation (#4340)
me2seeks Aug 31, 2026
c4c4072
fix: select update signature digests at crypto owners (#4356)
Astro-Han Aug 31, 2026
802c827
refactor(runtime): make dispatched attempts own request observations …
Astro-Han Aug 31, 2026
89d4b0e
feat(core,storage): add user-overridable model facts (#3129)
Nyvo-io Aug 31, 2026
6b53667
fix(runtime): gate provider reasoning replay by source model (#4286)
Astro-Han Aug 31, 2026
cdedfa0
test(cli): qualify released Runtime Host State Roots (#4313)
me2seeks Aug 31, 2026
6ef9b7d
refactor(runtime): unify durable model-context projection authority (…
Astro-Han Aug 31, 2026
bcbea00
feat(desktop): show project and task details on hover (#4310)
ARE404 Aug 31, 2026
6b9d16f
feat(runtime): cut over SessionTodo to Runtime Host authority (#4351)
me2seeks Aug 31, 2026
32cdb87
fix(desktop): preserve Git filenames in @ search (#4341)
liuxiaocs7 Aug 31, 2026
21bdf23
fix(desktop): resolve packaged license and electron paths without ass…
liuxiaocs7 Aug 31, 2026
c76fbda
feat(desktop): warn that deleting a parent keeps and archives its sub…
liuxiaocs7 Aug 31, 2026
8b0e43f
feat(workhub): add linked delegation correction (#4242)
ARE404 Aug 31, 2026
9493109
refactor(runtime-host): fence peer connection attempts (#4403)
M4n5ter Sep 1, 2026
ce25d6b
feat(runtime-host): accept WebRTC direct upgrades (#4404)
M4n5ter Sep 1, 2026
93a3fe2
feat(runtime-host): race WebRTC direct upgrades (#4405)
M4n5ter Sep 1, 2026
9249bf3
feat(desktop): surface adaptive peer connectivity (#4406)
M4n5ter Sep 1, 2026
0b653da
feat(desktop): add host-bound folder references to the composer (#4097)
sunrioa Sep 1, 2026
279c2e8
docs(eval): publish the nine-arm Terminal-Bench 2.1 leaderboard
hqhq1025 Sep 1, 2026
8098ee5
feat(desktop): simplify Peer Mesh management (#4410)
M4n5ter Sep 1, 2026
8fa1e89
feat(runtime): add Plugin Platform foundation (#3729)
xxhZs Sep 1, 2026
b9128e1
feat(storage): implement production session snapshots (#4361)
MicroGery Sep 1, 2026
da84f88
fix(release): pin the Windows upgrade baseline to a published build (…
Astro-Han Sep 1, 2026
3db83c2
chore: retire the Task Ledger domain and drop its storage (#4400)
Astro-Han Sep 1, 2026
54015e4
feat(desktop): select several tasks in the Session rail (#4365)
Joob1n Sep 1, 2026
aebcef8
ci: manage inactive issues and pull requests (#4391)
liugddx Sep 1, 2026
409c71a
feat(desktop): authorize client capabilities in managed sessions (#4143)
YayoiNanoka Sep 1, 2026
8bc4846
fix(desktop): recover managed Runtime Host startup (#4420)
M4n5ter Sep 1, 2026
2de641b
ci: skip heavy validation for documentation-only pull requests (#4172)
jackeyfaker77 Sep 1, 2026
c03dfce
chore(deps): bump @astryxdesign/core from 0.5.0 to 0.5.2 (#4372)
me2seeks Sep 1, 2026
fd55704
feat(desktop): import several conversations in one pass (#4437)
Joob1n Sep 1, 2026
460d982
fix(storage): preserve packed Bundle cleanup outcome (#4419)
MicroGery Sep 1, 2026
920d714
fix(cli): localize remaining TUI copy (#4422)
orangeCatDeveloper Sep 1, 2026
49858c4
refactor(runtime-host): make the Host the authority for the model cat…
Astro-Han Sep 1, 2026
a5ede6b
refactor(desktop): move Goal controller ownership below AppShell (#4316)
chihumyum Sep 1, 2026
0d3265e
fix(runtime-host): separate the persisted grant record from the autho…
Astro-Han Sep 1, 2026
5c1bbe3
refactor(runtime-host): derive dispatcher operation groups from spec …
liuxiaocs7 Sep 1, 2026
dfe457e
refactor(desktop): retire dead Task Ledger CSS and align it with Sess…
liuxiaocs7 Sep 1, 2026
6668af3
ci: allocate a runner only when its inputs changed (#4461)
Astro-Han Sep 1, 2026
afbcabd
fix(runtime-host): page oversized transcript Turns (#4433)
Sun-GLiang Sep 1, 2026
0571d7b
feat(desktop): route standard API key onboarding through Runtime Host…
me2seeks Sep 1, 2026
2e37fea
fix(desktop): sniff attachment types from content (#4442)
liuxiaocs7 Sep 1, 2026
98fc505
feat(tui): add /copy to copy the last reply or transcript to the clip…
liuxiaocs7 Sep 1, 2026
33e2bd6
ci: schedule model metadata upkeep and check the snapshot against ups…
Astro-Han Sep 1, 2026
472fea0
docs(architecture): audit bot onboarding runtime (#4345)
ggbdpq Sep 1, 2026
1a32afa
test(eval): bound fragmented-handshake recv by the handshake deadline…
ggbdpq Sep 1, 2026
5013f90
fix(cli): abbreviate home-relative Windows paths in the status line (…
ggbdpq Sep 1, 2026
259aefc
ci: name the Ubuntu image instead of asking for the queue (#4483)
Astro-Han Sep 1, 2026
9378641
ci: pin the model metadata upkeep runner (#4492)
Astro-Han Sep 1, 2026
195fa15
fix(desktop): show platform-correct shortcut labels on Windows and Li…
ggbdpq Sep 1, 2026
639ee3d
fix(desktop): remove the doubled titlebar inset on module pages
andotorg Sep 1, 2026
e0fdd32
feat(runtime-host): refresh the models.dev catalog at Host startup (#…
Astro-Han Sep 1, 2026
40201ed
fix(ui): remove project task-count badges
Phoenix500526 Sep 1, 2026
d3df057
ci: give the full-suite fallback's biggest buckets their real owners …
Astro-Han Sep 1, 2026
a89804a
fix(cli): project turn.stop inputs to protocol fields
jsiu93 Sep 1, 2026
6b3f38d
test(core): cover focused path helper contracts
yuzhiyang1 Sep 1, 2026
6b9de44
fix(desktop): declare a mode for Bot sessions
orangeCatDeveloper Sep 1, 2026
f596fc0
refactor(design-system): converge status surfaces and the radius ladd…
Astro-Han Sep 1, 2026
471aa1d
fix(desktop): hide raw renderer exceptions (#4459)
orangeCatDeveloper Sep 1, 2026
777b2ce
chore(cli): enforce locale copy boundaries (#4462)
orangeCatDeveloper Sep 1, 2026
e2e597c
fix(ci): restore main validation after concurrent merges (#4504)
liuxiaocs7 Sep 2, 2026
9b55886
fix(peer): keep Mesh and shared-session routes live (#4444)
M4n5ter Sep 2, 2026
622d6fe
feat(desktop): replace native recovery dialogs (#4474)
M4n5ter Sep 2, 2026
019dea8
fix(desktop): stop polling unavailable collaboration authority
Sep 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
49 changes: 38 additions & 11 deletions .asf.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -62,11 +62,18 @@ github:
required_approving_review_count: 1
required_status_checks:
strict: false
# test is the single job in .github/workflows/ci.yml, covering lint,
# format, build, tsc, knip, the selected workspace suites, e2e and
# Storybook. Renaming it there, or adding a paths filter that stops
# ci.yml from running, freezes every pull request: the check never
# reports and no committer can override it.
# test is the single unconditional job in .github/workflows/ci.yml. It
# runs the install-free contract checks on every change and installs the
# toolchain only for the validation its own planning step selects, so a
# documentation-only change still reports without paying for a build.
# Renaming the job there, adding a paths filter that stops ci.yml from
# running, or splitting the work back across jobs so this context comes
# from an aggregator that can be skipped, freezes every pull request:
# the check never reports and no committer can override it.
# A required context must report on every pull request, so a lane
# behind a paths filter cannot be listed here: the filter would keep
# the workflow from starting and the check would stay pending forever.
# windows_recovery is filtered and therefore deliberately absent.
contexts:
- test

Expand All @@ -81,9 +88,11 @@ github:
restrict_force_push: true

environments:
# These environments are the external human gates around signing secrets
# and npm OIDC. Naming an environment here replaces its settings wholesale,
# so keep every protection rule in this declarative authority.
# These environments are the deployment boundaries around signing secrets
# and npm OIDC. Release publication adds human review; scheduled npm
# Nightly relies on exact ref admission instead. Naming an environment here
# replaces its settings wholesale, so keep every protection rule in this
# declarative authority.
release:
required_reviewers:
- id: M4n5ter
Expand All @@ -95,7 +104,25 @@ github:
policies:
- name: "v*-incubating-rc*"
type: tag
npm-release:
npm-publication:
required_reviewers: []
wait_timer: 0
prevent_self_review: false
deployment_branch_policy:
protected_branches: false
policies:
- name: main
type: branch
nightly:
required_reviewers: []
wait_timer: 0
prevent_self_review: false
deployment_branch_policy:
protected_branches: false
policies:
- name: main
type: branch
product-release:
required_reviewers:
- id: M4n5ter
type: User
Expand All @@ -104,8 +131,8 @@ github:
deployment_branch_policy:
protected_branches: false
policies:
- name: "v*"
type: tag
- name: main
type: branch

notifications:
commits: commits@maka.apache.org
Expand Down
5 changes: 5 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -10,3 +10,8 @@
/.claude export-ignore
/.maka-shots export-ignore
/maka-proposal-zh-review.txt export-ignore

# DeepSeek Harness remains available to repository development and benchmarks,
# but its external runtime dependency closure is not an ASF source-release input.
/packages/eval/harbor/deepseek-harness-toolchain/package.json export-ignore
/packages/eval/harbor/deepseek-harness-toolchain/package-lock.json export-ignore
6 changes: 3 additions & 3 deletions .github/ASF_NPM_RELEASE.md
Original file line number Diff line number Diff line change
Expand Up @@ -72,9 +72,9 @@ registry side effects.

After both source-release votes approve the candidate, the product Release
workflow creates `v<version>` at that approved commit. The npm Stage workflow
then builds and validates one tarball from that final tag, submits those exact
bytes to npm staging through the protected `npm-release` Environment and OIDC,
and records the stage identity. Human approval with npm 2FA makes the package
then builds and validates one tarball from that final tag in jobs without OIDC. The OIDC job runs
only reviewed `main` publisher code, submits those exact bytes through the main-restricted
`npm-publication` Environment, and records both product-source and publisher identities. Human approval with npm 2FA makes the package
public; Finalize verifies the registry bytes, integrity, signature, provenance,
and dist-tag.

Expand Down
11 changes: 3 additions & 8 deletions .github/ASF_SOURCE_RELEASE.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,14 +19,9 @@

# Apache Maka source release runbook

This runbook prepares the official Apache Incubator source-release component.
The first Maka release also requires npm and Desktop convenience artifacts, but
those artifacts have separate build, licensing, signing, and acceptance gates.
They must be built from the exact IPMC-approved source release produced here.

The workflow implements release mechanics; it does not establish that a commit
is legally ready to release. Before starting a vote, the PPMC and mentors must
confirm the candidate's provenance and release documents.
This runbook prepares the official Apache Incubator source release. npm, Desktop, and other convenience artifacts use separate build, licensing, signing, and acceptance processes; they are not part of this source candidate or its release vote. Stable convenience artifacts, when provided, are built from the approved source release and tag.

The workflow implements release mechanics; it does not replace the human review of candidate provenance and release documents performed through the project's release vote.

## Candidate contract

Expand Down
41 changes: 41 additions & 0 deletions .github/DESKTOP_NIGHTLY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
<!--
Licensed to the Apache Software Foundation (ASF) under one
or more contributor license agreements. See the NOTICE file
distributed with this work for additional information
regarding copyright ownership. The ASF licenses this file
to you under the Apache License, Version 2.0 (the
"License"); you may not use this file except in compliance
with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing,
software distributed under the License is distributed on an
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
KIND, either express or implied. See the License for the
specific language governing permissions and limitations
under the License.
-->

# Desktop Nightly

Desktop Nightly is an ephemeral developer snapshot, not an Apache release. It builds the current `main` commit every day so contributors can try recent Desktop changes and report problems without waiting for an ASF source-release vote.

The npm publication workflow gives each snapshot an immutable version such as `0.2.0-dev.42.20260829`. The run number is the sole ordering authority. After that exact npm version is public, it triggers Desktop Nightly with a version-only artifact; the authenticated workflow event supplies the exact source commit and upstream run. Each fresh Desktop Nightly creates a `v<version>` tag protected by the checked-in `Immutable release tags` ruleset and one GitHub draft prerelease containing the macOS and Windows packages, blockmaps, `dev-mac.yml`, `dev.yml`, and one offline Sigstore bundle. The workflow verifies every remote asset before it publishes the prerelease as non-Latest. Packaged Nightlies use the GitHub `dev` channel and verify that downloaded bytes were attested by `.github/workflows/desktop-nightly.yml` on `main`. A formal Desktop build uses the separate stable GitHub Release channel and formal product-release attestation identity.

Nightly currently uses the same application identity as the formal Desktop. Installing it replaces the existing Maka installation rather than creating a second side-by-side app. Its user data remains in the same location. Testers who need the formal build should reinstall that build before returning to the formal channel. Builds previously downloaded from `nightlies.apache.org` do not migrate automatically; testers must install the newest GitHub prerelease once, after which GitHub Nightlies update automatically.

## One-time setup

1. After the checked-in `.asf.yaml` reaches `main`, verify that ASF reconciliation created the `nightly` GitHub Environment with only `main` permitted and no approval gate. Do not maintain that policy manually in GitHub. Configure its macOS signing and notarization secrets: `CSC_LINK`, `CSC_KEY_PASSWORD`, `APPLE_API_KEY`, `APPLE_API_KEY_ID`, and `APPLE_API_ISSUER`. Do not expose these secrets to repository-wide or pull-request workflows.
2. Configure npm Trusted Publishing for `apache/maka` and `.github/workflows/npm-publication.yml`, restricted to the `npm-publication` Environment and with both `npm publish` and `npm stage publish` allowed. Do not create or store a long-lived npm token.
3. After npm Trusted Publishing is ready, set `NPM_NIGHTLY_ENABLED` to `true`, run `npm publication` from `main` with `channel=nightly`, and verify the exact npm version and `nightly` dist-tag.
4. Set `DESKTOP_NIGHTLY_ENABLED` to `true` and manually dispatch a fresh npm Nightly. Confirm that its successful run triggers `Desktop Nightly`. Do not rerun a failed attempt in place.
5. Verify that `v<version>` points to the exact source SHA and that its GitHub Release is published with Draft off, Prerelease on, Latest off, and exactly the nine expected assets. Install that prerelease on both platforms.
6. Publish one later fresh Nightly and confirm a GitHub-to-GitHub automatic and differential update on both platforms before sharing the channel with testers.

The npm schedule starts at 18:17 UTC. Before changing the npm tag, the workflow requires its run number to exceed the current `nightly` version. Desktop assembles and verifies a draft before one publish mutation; a packaging, attestation, tag, upload, or digest failure leaves no partially published GitHub Release. Never rerun a failed workflow attempt in place; dispatch a fresh npm Nightly with a newer version.

GitHub Release retention is intentionally outside this workflow. Do not delete an old Nightly prerelease or its tag while any installed client may need its payload or blockmap. One Nightly is additionally pinned by tag, asset name, and SHA-256 in `scripts/windows-upgrade-baseline.json` as the Windows upgrade gate's baseline: deleting that prerelease fails the gate on every pull request that touches the Windows release path until the pin moves to another published build. Disabling `DESKTOP_NIGHTLY_ENABLED` stops new Desktop publication without mutating tags or releases.

Remote Runtime Host setup uses the exact `maka-agent@<nightly-version>` package embedded in the Desktop manifest. The npm package is verified before Desktop artifacts become visible, so clean remote setup never depends on an unpublished Runtime Host version.
69 changes: 47 additions & 22 deletions .github/RELEASE_CHECKLIST.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,9 +19,10 @@

# Product release checklist

The `Release` workflow is Maka's convenience-artifact release entry point. Desktop and CLI/TUI are
The IPMC-approved source archive on ASF distribution infrastructure is the Apache release. The
`Release` workflow is Maka's convenience-artifact distribution entry point. Desktop and CLI/TUI are
built from the exact IPMC-approved ASF source candidate commit. They share that source commit, the
root product version, one convenience tag, one GitHub Release, one Draft decision, and one release
root product version, one convenience tag, one GitHub Release, one Draft decision, and one distribution
gate. The workflow creates no Draft until every required artifact job succeeds.

Phase 1 requires:
Expand All @@ -31,9 +32,9 @@ Phase 1 requires:
- the signed, notarized, relocatable Apple Silicon CLI/TUI ZIP;
- checksums generated after each artifact reaches its final form.

The ASF Desktop artifacts must not contain a Git runtime, a bundled-Git manifest, or Git/Dugite
redistribution notices. Managed-workspace execution remains unavailable until a separately reviewed,
ASF-compatible verified runtime is connected before admission/T1.
The convenience Desktop artifacts must not contain a Git runtime, a bundled-Git manifest, or Git/Dugite
redistribution notices. The retired Git executable-backed managed-workspace path must not be restored;
future workspace execution requires a separately reviewed Gitoxide production composition before admission/T1.

The first product release also requires the exact `maka-agent@<version>` npm package. The product
tag and Draft must exist before npm staging, but the Draft must remain unpublished until npm is
Expand All @@ -60,10 +61,17 @@ must never be exposed to fork or ordinary pull-request jobs.
Before the first product release, confirm the checked-in `.asf.yaml` has reconciled the live repository:

- the `Immutable release tags` ruleset blocks updates, force-pushes, and deletions of `v*` tags;
- the `release` and `npm-release` Environments accept only their declared tag patterns and require a reviewer other than the triggering user;
- enable immutable releases so assets and the associated tag cannot change after publication.

These controls close the check-to-upload and check-to-stage windows. Keep the Release in Draft while assets and acceptance are incomplete; publishing early must make subsequent mutation fail closed.
- the `release` Environment accepts only its declared source-candidate tag pattern and requires a
reviewer other than the triggering user;
- `npm-publication`, `nightly`, and `product-release` accept only `main`; `product-release` requires
a reviewer other than the triggering user. `npm-publication` and `nightly` have no GitHub approval
gate because scheduled npm and Desktop Nightly publication is automatic; formal npm publication
still requires human 2FA approval after staging.

These controls close the check-to-upload and check-to-stage windows. Finalize uses GitHub Actions
OIDC rather than a stored signing key to attest every convenience artifact. Keep the Release in
Draft while assets and acceptance are incomplete; Desktop rejects downloaded updates whose exact
bytes and expected filename are not covered by that protected workflow identity.

## Create the complete Draft

Expand All @@ -79,8 +87,8 @@ These controls close the check-to-upload and check-to-stage windows. Keep the Re
5. Confirm `release-identity`, both Desktop matrix entries, `cli-macos-arm64`, and
`publish` pass. A skipped or failed required job must prevent Draft creation.
6. Confirm one Draft named `v<version>` targets the approved source SHA, identifies the ASF source
reference in its notes, is marked as a GitHub prerelease exactly when the product version is a
prerelease, is not marked Latest while it remains a Draft, and contains exactly the manifest
reference in its notes, is not marked as a GitHub prerelease or Latest while it remains a Draft,
and contains exactly the manifest
reported by `node scripts/product-release-artifacts.mjs list`. The manifest covers both Desktop
platforms and update metadata, the standalone CLI/TUI, and their required checksums.
7. Inspect the CLI ZIP. It must contain `bin/maka`, `RELEASE.json`, `DISCLAIMER-WIP`, `LICENSE`, `NOTICE`,
Expand All @@ -106,17 +114,22 @@ then rerun. If only the tag exists, the retry creates the missing Draft.

Follow [the npm release runbook](../docs/cli-npm-release.md) against the exact product tag and Draft:

1. Run **Stage CLI npm release** from `v<version>` and record its successful run ID and attempt.
1. Record the successful **Release** workflow run ID and attempt that built the Draft assets. Run
**npm publication** with `channel=formal` from `main` and record its successful run ID and
attempt.
2. Inspect the staged tarball and provenance, then approve that exact stage with npm 2FA.
3. Run **Finalize CLI npm channel** from `main` and confirm it verifies the public package bytes,
provenance, signature, and release dist-tag.
3. Run **Finalize product release** from `main`. Its first job verifies the public package
bytes, provenance, signature, and release dist-tag.
4. Install the exact public version on each release platform and complete the npm acceptance steps.

Keep the GitHub Release in Draft throughout this sequence. A failed or rejected npm candidate
requires a new product version; never publish the Draft to work around npm state.

When every npm and cross-machine acceptance check has passed, publish the Draft. Mark a stable
release as Latest at that final publication boundary; prereleases must remain non-Latest.
Keep the GitHub Release in Draft throughout this sequence. The final workflow job waits at the
`product-release` Environment. Approve it only after every npm and cross-machine acceptance check
has passed. It verifies the live Draft digests against the immutable publication record from the
exact successful Release run, creates Sigstore provenance and an offline
`Maka-<version>-attestation.sigstore.json` bundle, then publishes the convenience Release and makes a
stable release Latest in the same GitHub operation. Do not publish or
change the Latest designation manually. A failed or rejected npm candidate requires a new product
version; never publish the Draft to work around npm state.

## Acceptance on another Apple Silicon Mac

Expand Down Expand Up @@ -155,8 +168,20 @@ Download the installer, Windows Desktop ZIP, and both checksum files through a b
7. Add a clean remote Runtime Host from the packaged Desktop app. Confirm setup installs the exact
public `maka-agent@<version>` package and the remote session completes one model turn.

Immediately before publication, reverify that the approved ASF candidate tag and convenience
`v<version>` tag still resolve to the same recorded commit. Publish only after npm Finalize and both
independent-machine acceptance passes. If any required artifact, npm step, or
Immediately before approving the `product-release` Environment, reverify that the approved ASF
candidate tag and convenience `v<version>` tag still resolve to the same recorded commit. Approve
only after npm verification and both independent-machine acceptance passes. If any required artifact, npm step, or
acceptance step fails, keep the Draft unpublished, fix the issue, increment the root product
version, and run the full workflow again. Never replace an existing release identity.

After Finalize publishes the convenience Release, download its attestation bundle and verify each
installer or archive independently:

```sh
gh attestation verify path/to/Maka-<version>-mac-arm64.zip \
--bundle path/to/Maka-<version>-attestation.sigstore.json \
--repo apache/maka \
--signer-workflow apache/maka/.github/workflows/release-cli-finalize.yml
```

Desktop performs the same trust decision before exposing a downloaded update for installation.
Loading
Loading