Latest release
Changes, verification and known limitations in the latest stable release.
This release focuses on responsive interaction, bounded recovery, and host-owned extension contracts for a small, model-flexible coding agent.
Highlights#
- Keep startup silent and editable, restore the full
/modelpicker, and keep inspection commands and/goalresponsive during streaming. - Improve activity shimmer, tool disclosure, worker presentation, and usage visibility without replacing durable accounting with display estimates.
- Accept owner-bound
/subagents stop <name|all>during an active response, keep input responsive while stopping, and show compact token counts with the same continuation alignment as Thinking. A stop request is not terminal settlement. - Preserve native scrollback after an active subagent roster instead of clipping unrelated commands, results, and answers into a pending-tool preview.
- Add
/settings,/scoped-models,/session, hidden/debug, capability-gated/fast, and!command/!!commandshell escapes. Withdraw/treeand/checkout; rename/quitto/exit. - Add ordered
--modelsselection and opt-in Windows--powershell, plus bounded HTML session export, local-model evaluation profiles, and tool checkpoints. - Repair request headroom, provider size-rejection recovery, sparse discovery metadata, reasoning capability decoding, and host-budgeted transport retries.
- Refresh reviewed models.dev names, pricing, and capabilities without adding build/runtime metadata fetches. Direct DeepSeek schedule pricing stays unknown; public catalog evidence is not live inference acceptance.
- Keep interrupted-attempt partial text in
RecoveredOutput, separate from the current answer, provider replay, and usage accounting. - Update rustls to 0.23.45 for RUSTSEC-2026-0285. Preserve an admitted Python shutdown hook and acknowledgement when stdin closes, within the EOF drain budget.
- Keep manual-compaction provider retry state off the nested caller futures to
prevent Serve
/compactfrom overflowing a normal Tokio worker stack. - Retain Serve, Browse, MCP, host-owned subagents, web search, and protocol safety/conformance. API 0.4 is the current extension wire; the separately supported canonical API 0.3 includes a session-isolated process event bus.
- Remove Pi extension execution and its CLI entrypoint; retain Pi dry-run inventory and portable import/restore. Remove obsolete internal planning, comparison, and task-handoff documentation.
Additional reconciled changes#
- Keep model/thinking/subagent and consent surfaces inside the active run loop; renderer layout and terminal writes no longer hold the semantic input lock.
- Bound Bash spill storage and editor history, move optional telemetry writes off the agent path, and advance session/replay projections incrementally.
- Expose qualified native Responses steering and asynchronous tools with durable intent, settlement and fail-closed accounting; unsupported routes retain queued steering. Host model selection for workers remains owner-bound.
- Keep worker activity in a bounded, mutable transcript roster, with full
details in
/subagents; raw orchestration calls and state transitions add no transcript notices. Full-access MCP mutations use host-owned policy checks; controlled policies still refuse them. - Offer first-run API-key, supported OAuth, and local-model setup in that order.
Reload#
Interactive resource/extension reload is enabled silently by default and applies
at idle boundaries. /reload --dry-run previews changes. Host replacement
requires /reload --force or explicit reload_host = true, and a replaced
binary requires confirmation before its first probe execution. Resource rebuilds
refuse while host worker tasks remain attached, including retained idle receivers;
force/watch passes cannot bypass that refusal. Finish or stop work, then exit and
resume the session to replace that owning host. In-flight provider calls are not
silently replayed. A separate running octet serve process needs its own restart
to use a new binary.
Limits and availability#
Native iOS/macOS companions remain source-only, not supported live connection
paths or signed installable releases. Product open-all remains fail-closed
without atomic writer handover. /fast is session/process scoped and does not
promise provider acceptance or clear historical cost uncertainty. Optional
protocol services do not imply a product UI or broader host authority.
This release does not claim every review finding resolved. Terminal layout, Mermaid, notification wording, native-app delivery, live-provider acceptance, and physical-terminal qualification remain separate from this release-gate scope. Deterministic tests do not establish all-provider, physical-terminal, or long-duration acceptance.
The version-pinned GitHub release
records validation, signed native assets, exact-version Serve and executable
bundles, and public-install results. See installation for
version-matched commands and CHANGELOG.md for detailed changes. The
RC qualification record retains its
historical, bounded evidence; source checks alone do not establish publication.
npm, Homebrew, crates.io and SDK registries remain separate, unpublished channels. Live-provider/audio and physical-terminal acceptance were not run as release gates.