Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
227 commits
Select commit Hold shift + click to select a range
2f6c9bd
fix(auth): compare runtime tokens in constant time through one helper
Sep 25, 2026
e3a218e
fix(cli): `codewhale logout` asks before deleting every provider key
Sep 25, 2026
ecdc840
fix(approval): session shell grants fail closed on compound, wrapper …
Sep 25, 2026
d0e3158
fix(notes): keep the auto-approved note tool inside the workspace
Sep 25, 2026
c1d3f19
fix(approval): report an expired approval as a timeout and refund its…
Sep 25, 2026
294b616
fix(skills): project skills load only in a trusted workspace
Sep 25, 2026
9253eff
fix(commands): workspace commands need trust and never replace protec…
Sep 25, 2026
000ab6b
fix(security): redact tool output as it enters the transcript; doctor…
Sep 25, 2026
133a8a2
fix(notes): flush the appended note before reporting success
Sep 25, 2026
4c37623
chore(deps): bump actions/setup-python from 6 to 7
dependabot[bot] Sep 25, 2026
1f07587
fix(security): mask tool metadata and compact JSON; scrub under the s…
Sep 25, 2026
a8755ae
fix(trust): grants key code-running options; /note stays in the works…
Sep 25, 2026
9666486
Merge origin/main into fix/broken-now-and-trust
Sep 25, 2026
8ce605a
Merge branch 'main' into dependabot/github_actions/actions/setup-pyth…
Hmbown Sep 25, 2026
b29ed34
Merge origin/main into fix/broken-now-and-trust
Sep 25, 2026
378b376
Merge pull request #6595 from Hmbown/dependabot/github_actions/action…
Hmbown Sep 26, 2026
0c5dc98
Merge origin/main into fix/broken-now-and-trust; fix PR #6601 CI
Sep 26, 2026
cbfbcb6
fix(catalog): upstream-keyed canonical entries join offline (#6396 sl…
Sep 26, 2026
5be47bc
revert: drop the session-grant key and /note path changes from a8755ae00
Sep 26, 2026
565b8dc
revert: drop the notes path change from d0e31586a
Sep 26, 2026
cb268d5
revert: drop the session-grant key change from ecdc8405b
Sep 26, 2026
3df5c6c
Merge remote-tracking branch 'origin/main' into fix/broken-now-and-trust
Sep 26, 2026
f53a1aa
fix(ci): trusted runtime-contract fixture, scrub counts from the read…
Sep 26, 2026
2ab4abf
Merge remote-tracking branch 'origin/main' into fix/broken-now-and-trust
Sep 26, 2026
0be8f10
fix(catalog): Codewhale corrections hold online, not only offline (#6…
Sep 26, 2026
659811e
merge: #6618 and #6620 (corrections) into #6612's branch
Sep 26, 2026
b7e09ab
fix(catalog): reasoning controls Codewhale records hold online too (#…
Sep 26, 2026
989af6e
merge: #6620 reasoning corrections into #6612's branch
Sep 26, 2026
d333c33
fix(catalog): keep hosted DeepSeek on the reviewed price table (#6396)
Sep 26, 2026
45b1d5a
merge: #6620 hosted DeepSeek and grok-4.3 corrections into #6612's br…
Sep 26, 2026
43e3cb0
fix(catalog): keep GLM-5.3 unpriced on the Coding Plan route (#6396)
Sep 26, 2026
2cd1bbc
merge: #6620 GLM-5.3 hold into #6612's branch
Sep 26, 2026
6227825
feat(catalog): generate the offline seed from a reviewed spec and a l…
Sep 26, 2026
cd5e643
fix(catalog): regenerate the offline seed from Models.dev (#6396)
Sep 26, 2026
ac7881c
docs(config): keep model_bound paragraphs under their own section
Sep 26, 2026
fbd0caa
fix(pricing): GPT-5.6 Sol table matches OpenAI's current rates (#6396)
Sep 26, 2026
e021222
Merge origin/main into fix/broken-now-and-trust
Sep 26, 2026
9ddf26b
fix(tui): a fork continues when a turn lost its tool call
gaord Sep 26, 2026
45017fa
test(tui): isolate full-suite approval and policy fixtures
Sep 27, 2026
a21fc86
fix(hooks): pass the tool exit code to Runtime API tool_call_after
Sep 26, 2026
e8e0d4e
fix(hooks): give hooks the exit code and status of failing bash commands
Sep 26, 2026
0d68bb9
runtime_api: end every server-initiated thread stream with stream.end
Hmbown Sep 26, 2026
8d3c1b7
mobile: keep reconnecting through an unreachable Runtime; back off re…
Hmbown Sep 26, 2026
ebe0d94
runtime_api: optional preconditions on git stage/unstage/discard/commit
Hmbown Sep 26, 2026
6c86c21
fix(runtime): threads own the restore points on their turns; undo res…
Sep 26, 2026
a495e1b
fix(runtime): bound undo to the turn's own tool spans; keep its resto…
Sep 26, 2026
dfc60b6
fix(provider): show bundled descriptors' console, docs and guidance; …
Sep 26, 2026
14d24fd
fix(sessions): stop orphaning sessions at their writers and repair ex…
Sep 26, 2026
dfb9a81
fix(sessions): keep export off the source session, reuse only full-co…
Sep 26, 2026
68e544c
fix(sessions): move held Runtime stores entry by entry so Windows can…
Sep 26, 2026
cf42682
fix(sessions): hold a Runtime store's lock through its whole set-asid…
Sep 26, 2026
abca3fa
fix(tui): the dock's GIT, FILES and NOTES views are real, on one git …
Sep 26, 2026
ff7e4e0
fix(compaction): write the handoff note in our own words and keep it …
Sep 26, 2026
0bea70e
fix(compaction): make the handoff header say what is actually kept
Sep 26, 2026
783d599
fix(catalog): Codewhale corrections hold online, not only offline (#6…
Sep 26, 2026
72c179e
fix(catalog): reasoning controls Codewhale records hold online too (#…
Sep 26, 2026
d1ac549
fix(catalog): keep hosted DeepSeek on the reviewed price table (#6396)
Sep 26, 2026
56941d8
fix(catalog): keep GLM-5.3 unpriced on the Coding Plan route (#6396)
Sep 26, 2026
3e39820
fix(tools): one recoverable size budget for tool output (#6508)
Sep 26, 2026
380df06
fix(tools): delete the per-tool output caps in run_tests, git and ver…
Sep 26, 2026
85f884d
fix(search): native search answers are no longer capped at 2-4K token…
Sep 26, 2026
1a59a3f
fix(verifier): keep the end of long gate output and save the whole st…
Sep 26, 2026
a3b5e06
docs(changelog): tool output is no longer cut off where it can't be r…
Sep 26, 2026
9c7a2d6
fix(search): give native search time to generate the answer it asks f…
Sep 26, 2026
fb7227d
test(tui): update /cache inspect budget test for the 100k wire backst…
Sep 26, 2026
1cdaeac
fix(audit): write Auto-Review verdicts and network audits to audit.log
Sep 25, 2026
9150949
feat(receipts): list what a session did, from the records it already …
Sep 25, 2026
c515689
wip: unfinished review fix-up (interrupted by the session usage limit)
Sep 25, 2026
6890e1b
fix(receipts): report blocked calls as blocked, list shell file chang…
Sep 25, 2026
536a137
fix(receipts): only Codewhale's own words mark a call blocked; escape…
Sep 25, 2026
76aeeb3
runtime: record typed artifact refs on tool-call items
Hmbown Sep 26, 2026
465e485
runtime: settle each turn's workspace delta into its artifact aggregate
Hmbown Sep 26, 2026
153ca69
runtime_api: read turn artifacts by reference through one shared reso…
Hmbown Sep 26, 2026
392933a
docs: document turn artifacts; confine file refs without blocking the…
Hmbown Sep 26, 2026
8580b0e
fix(execpolicy): judge read-only chains segment by segment and name t…
Sep 26, 2026
471d936
fix(fleet): one read-only shell authority with actionable, counted re…
Sep 26, 2026
c60ac29
fix(subagent): a queued agent that never starts says so; its work clo…
Sep 26, 2026
c057499
docs(fleet): read-only shell grammar, refusals and launch clock (#6015)
Sep 26, 2026
83eba45
fix(execpolicy): judge gh and npm view reads after a leading cd (#6015)
Sep 26, 2026
0c4b542
fix(subagent): save the launch-restarted deadline to the worker recor…
Sep 26, 2026
1ef3fdb
test(subagent): gate the readonly_shell_6015 git helper to unix (#6015)
Sep 26, 2026
fe925cf
test(tui): capture honest website terminal frames from a home-relativ…
Sep 26, 2026
049f6ba
web: render real PTY captures as live text; README image from the sam…
Sep 26, 2026
4814029
web: keep the whale-road look, restore the old site's strengths
Sep 26, 2026
9359897
docs(readme): restamp translations for the new terminal image
Sep 27, 2026
e22c862
refactor(rlm): delete dead run_rlm_turn / run_rlm_turn_with_root entr…
Sep 26, 2026
4f3f07d
fix(tui): mobile shows agent progress; sub-agent cache counts in sess…
Sep 26, 2026
a6222e6
fix(tui): background work tells you when it ends, and how
Sep 26, 2026
364f037
fix(tui): keep the sub-agent idle clock out of serialized listings
Sep 26, 2026
da2e8b4
fix(tui): no false quiet, no double notice, no stale task holding it
Sep 26, 2026
ff10c26
fix(snapshot): hash the work-tree file by a path Git for Windows can …
Sep 27, 2026
7a5d88e
fix(runtime_web): register turn.artifacts; wait for the event in the …
Sep 27, 2026
11ed3a2
Merge remote-tracking branch 'origin/main' into fix/broken-now-and-trust
Sep 27, 2026
708c6f1
Merge remote-tracking branch 'origin/main' into fix/runtime-hook-exit…
Sep 27, 2026
bd41838
Merge remote-tracking branch 'origin/fix/6396-catalog-corrections' in…
Sep 27, 2026
821849f
fix(tui): every Ctrl+T press changes the effective thinking tier (#6650)
Sep 27, 2026
77eb570
Merge branch 'main' into fix/fork-rebuild-lost-tool-call
Hmbown Sep 27, 2026
19a4f8a
Merge branch 'main' into fix/6665-linux-full-gate
Hmbown Sep 27, 2026
0184909
fix(tui): scrolling a long transcript no longer re-flattens its tail …
Sep 27, 2026
4a3bd8a
fix(tui): hide the composer caret while another view covers it (#6545)
Sep 27, 2026
0afa6c7
test(runtime): build the undo fixture's legacy credentials with with_…
Sep 27, 2026
95823d2
fix(approval): scope session shell grants to the command they were gi…
Sep 27, 2026
ead5f74
fix(tasks): delegated tasks and automations run with no more authorit…
Sep 27, 2026
1c6d71d
test(sessions): build the reconcile fixture's credentials with with_l…
Sep 27, 2026
b757b52
test(fleet): build the scout fixtures' credentials with with_legacy_root
Sep 27, 2026
89ff627
fix(tui): start model-run child processes from the scrubbed environment
Sep 27, 2026
e7deca4
fix(receipts): keep the runtime -> UI ratchet flat
Sep 27, 2026
67d84ee
Merge PR #6643 (fix/aicraft-descriptor-6616) into integrate/0.10.1
Sep 27, 2026
d02061c
Merge PR #6638 (fix/6565-mobile-cache) into integrate/0.10.1
Sep 27, 2026
490f4fc
Merge PR #6636 (fix/6565-dock-views) into integrate/0.10.1
Sep 27, 2026
54a11b5
Merge PR #6622 (feat/original-compaction-handoff) into integrate/0.10.1
Sep 27, 2026
6ee7926
Merge PR #6620 (fix/6396-catalog-corrections) into integrate/0.10.1
Sep 27, 2026
737e8b9
Merge PR #6612 (ms2-6396-seed-regen) into integrate/0.10.1
Sep 27, 2026
c2539e6
Merge PR #6619 (fix/6508-one-tool-output-budget) into integrate/0.10.1
Sep 27, 2026
2727c5d
Merge PR #6613 (site/whale-road-merge) into integrate/0.10.1
Sep 27, 2026
b753aa5
Merge PR #6611 (ms-6511-rlm-dead-entry) into integrate/0.10.1
Sep 27, 2026
6f9dc5d
fix(approval): tighten shell family grants, stored automation authori…
Sep 27, 2026
a12cbc6
docs(runtime-api): describe the narrower shell grant rule and delegat…
Sep 27, 2026
52b1c10
fix(tui): scrub env for git, language servers and runtimes; keep buil…
Sep 27, 2026
60a2c98
fix(runtime): address stream-end client review findings
Sep 27, 2026
0431788
fix(tui): preserve background completion receipts and privacy
Sep 27, 2026
0a948e4
fix(runtime): harden git write precondition fingerprints
Sep 27, 2026
e49285d
fix(tui): gate inline repl fences like code_execution
Sep 27, 2026
6b40549
fix(shell): kill managed background shells when the TUI dies (#6654)
Sep 27, 2026
9b926b7
fix(trust): mask configured secrets in runtime receipts, honest docto…
Sep 27, 2026
74ec2e4
fix(tui): admit repl fences through the code_execution planning path
Sep 27, 2026
f489f74
fix(shell): stop a background shell's whole process group when the TU…
Sep 27, 2026
b7abbe2
fix(execpolicy): fail closed on run-time command words and tighten pr…
Sep 27, 2026
4d084eb
fix(tui): harden MCP server approvals, shell denial and tool-call retry
Sep 27, 2026
9e3ab34
test(tui): follow #6612's GLM-5.3 effort ladder in the Auto dispatch …
Sep 27, 2026
3a9e4d8
fix(runtime): harden browser sessions and tool trust boundaries
Sep 27, 2026
c013203
fix: preserve state and report audit failures
Sep 27, 2026
0b76063
fix(execpolicy): close remaining gaps in shell parsing for deny rules
Sep 27, 2026
b25ff32
fix(tui): replay MCP tool calls only on a typed session refusal
Sep 27, 2026
a85ad10
fix(subagent): keep sub-agent worktrees under their root and harden w…
Sep 27, 2026
7fa8d44
fix(workflow): refuse fleet and router names that leave their directory
Sep 27, 2026
d87f4c3
fix(tools): apply the read guards to pandoc_convert and image_ocr
Sep 27, 2026
433bae9
fix(computer-use): keep capture output paths in the recordings directory
Sep 27, 2026
68d1377
docs(changelog): note path containment hardening for v0.10.1
Sep 27, 2026
92a44ba
fix(skills): validate registry keys before using them as cache direct…
Sep 27, 2026
309f329
fix(tasks): stop idle workers polling the shared task store (#6573)
Sep 27, 2026
453171a
fix(tasks): fingerprint only the task queue for idle claims (#6573)
Sep 27, 2026
442397c
fix(tools): name the pandoc version --sandbox needs and pin the flag …
Sep 27, 2026
7eddbe5
fix(computer-use): one recordings directory and backend-level capture…
Sep 27, 2026
9226111
fix(tui): dedupe the Ctrl+T ladder by the tier receipts report
Sep 27, 2026
a10ef1c
fix(tui): repaint the scroll hint in place while a reply streams (#6652)
Sep 27, 2026
6fae324
fix: harden project config, repository reads, fetch refspecs and down…
Sep 27, 2026
e449c21
fix: keep blame, working-tree reads and fetch tags from running repo …
Sep 27, 2026
1bc01b6
chore(ci): lock in dead-code budget at 260 (was 273)
Sep 27, 2026
6ac8a66
fix(tui): correct git, cache, restored output and file activity
Sep 27, 2026
3cf3358
fix(tui): clear clippy -D warnings on background digest branch
Sep 27, 2026
97b3cd9
fix(tui): drop eprintln! skip messages from env-scrub tests (clippy)
Sep 27, 2026
bc102d0
test(runtime): prove unbound threads keep one engine session id (#6659)
Sep 27, 2026
fad53fa
fix(runtime): preserve browser recovery and SSH compatibility
Sep 27, 2026
94a3c69
fix(runtime): satisfy clippy cloned_ref_to_slice_refs in git precondi…
Sep 27, 2026
31376a4
test(tui): build repl-fence auto-review policy via config, not tui::
Sep 27, 2026
0a27090
fix(subagent): compare worktree paths in one form on Windows
Sep 27, 2026
d94d261
test(commands): count /receipts in the debug group ownership pin
Sep 27, 2026
03f22c1
fix(tui): correct trust scope and legacy credential cleanup
Sep 27, 2026
1702eec
fix(tui): scope /undo to the paths the undone step changed (#6644)
Sep 27, 2026
97ca2b6
fix(tui): scope completion receipts to fresh background work
Sep 27, 2026
b36eb3c
chore(scrub): record session_secret_scrub's blocking fs sites in the …
Sep 27, 2026
f96f2dd
fix(tui): preserve tool output and complete cache and file accounting
Sep 27, 2026
7dc1c4f
fix: complete logout revocation and enforce audit safeguards
Sep 27, 2026
29faeaa
fix(tui): /undo waits for the post-turn snapshot and skips non-regula…
Sep 27, 2026
34ef01a
merge: stack turn artifacts on #6645's thread snapshot ownership
Sep 27, 2026
8b8f187
fix(runtime): keep git status best-effort with fail-closed guards
Sep 27, 2026
f16a5f6
Merge PR #6645 (fix/6621-thread-snapshot-ownership) into integrate/0.…
Sep 27, 2026
751d44a
Merge PR #6682 (fix/6644-tui-undo-path-scoped) into integrate/0.10.1
Sep 27, 2026
01b1eee
Merge PR #6660 (feat/turn-artifacts) into integrate/0.10.1
Sep 27, 2026
763c675
Merge PR #6640 (fix/6144-session-orphans) into integrate/0.10.1
Sep 27, 2026
11081ba
Merge PR #6649 (fix/runtime-stream-end) into integrate/0.10.1
Sep 27, 2026
0ce7fda
Merge PR #6648 (feat/git-write-preconditions) into integrate/0.10.1
Sep 27, 2026
5523643
Merge PR #6637 (fix/6015-readonly-shell) into integrate/0.10.1
Sep 27, 2026
53e13fe
Merge PR #6635 (fix/6565-background-digest) into integrate/0.10.1
Sep 27, 2026
68a84a3
Merge PR #6601 (fix/broken-now-and-trust) into integrate/0.10.1
Sep 27, 2026
8e6d434
Merge PR #6591 (feat/session-receipts) into integrate/0.10.1
Sep 27, 2026
d1abb9f
Merge PR #6656 (fix/runtime-hook-exit-code) into integrate/0.10.1
Sep 27, 2026
a0d3243
Merge PR #6667 (fix/6650-ctrl-t-effort-cycle) into integrate/0.10.1
Sep 27, 2026
b284f17
Merge PR #6668 (fix/6652-transcript-scroll-cost) into integrate/0.10.1
Sep 27, 2026
f5afce8
Merge PR #6669 (fix/6545-hidden-composer-cursor) into integrate/0.10.1
Sep 27, 2026
b733ba3
Merge PR #6670 (fix/task-and-grant-approval-scope) into integrate/0.10.1
Sep 27, 2026
967023c
Merge PR #6671 (fix/child-env-scrub) into integrate/0.10.1
Sep 27, 2026
4066dfe
Merge PR #6673 (fix/repl-fence-gate) into integrate/0.10.1
Sep 27, 2026
1999f63
Merge PR #6674 (fix/6654-background-shell-parent-death) into integrat…
Sep 27, 2026
aa5f726
Merge PR #6675 (fix/shell-policy-parsing) into integrate/0.10.1
Sep 27, 2026
bab13c1
Merge PR #6676 (fix/mcp-server-approval-and-replay) into integrate/0.…
Sep 27, 2026
79fe720
Merge PR #6677 (fix/6573-task-store-idle-spin) into integrate/0.10.1
Sep 27, 2026
863f501
Merge PR #6678 (fix/path-containment) into integrate/0.10.1
Sep 27, 2026
e0f0e87
Merge PR #6679 (fix/project-config-and-fetch-hardening) into integrat…
Sep 27, 2026
7b33fd8
fix(rlm): bound recursive turns by the child wall-clock budget
Sep 27, 2026
a7a3e3b
Merge PR #6680 (fix/audit-quick-wins) into integrate/0.10.1
Sep 27, 2026
c7834fa
fix(runtime): expose replay progress and enforce SDK type checks
Sep 27, 2026
c48b50f
Merge PR #6681 (fix/runtime-surface-hardening) into integrate/0.10.1
Sep 27, 2026
2d63c86
Merge PR #6664 (fix/fork-rebuild-lost-tool-call) into integrate/0.10.1
Sep 27, 2026
89a456b
Merge PR #6666 (fix/6665-linux-full-gate) into integrate/0.10.1
Sep 27, 2026
9ded781
fix(tui): confine workspace context, note and anchor file access
Sep 27, 2026
983bcf2
fix(integrate): compile and gate fixes after the round-2 merges
Sep 27, 2026
68a8c93
fix(integrate): address Codex review of the round-2 merge resolutions
Sep 27, 2026
25d27d8
fix: address catalog and TUI review regressions
Sep 27, 2026
705fe81
Merge PR #6649 (fix/runtime-stream-end) into integrate/0.10.1
Sep 27, 2026
4e63e64
Merge PR #6684 (fix/6511-rlm-wall-clock) into integrate/0.10.1
Sep 27, 2026
1db50bc
fix(tui): keep longer reasoning labels in the footer
Sep 27, 2026
e60e38f
Merge PR #6685 (fix/confined-workspace-reads) into integrate/0.10.1
Sep 27, 2026
b6e14bd
Merge PR #6686 (fix/footer-xhigh-label) into integrate/0.10.1
Sep 27, 2026
f1c7f69
fix(tui): keep configured routes during first-run discovery
Sep 27, 2026
f45d1df
Merge PR #6687 (fix/first-run-keeps-configured-provider) into integra…
Sep 27, 2026
eba1d7a
fix(tui): keep first-launch discovery for generated configs; honor en…
Sep 28, 2026
2a843ad
fix(tools): fit the Git and revert_turn schema text back under budget
Sep 28, 2026
ebcbe8a
ci: classify docs/zh_hans/FLEET.md as a Rust input
Sep 28, 2026
e4c94c8
chore(scripts): name the catalog field scrubber for what it strips
Sep 28, 2026
de522ec
fix(tui): acknowledge configured first-run routes
Sep 28, 2026
2412a6e
fix(pricing): price OpenRouter turns from the lake and declared rates
Sep 28, 2026
d0b42c2
fix(exec): read the prompt from --prompt-file or stdin (#6688)
Sep 28, 2026
1394c29
fix(provider): keep a root default model with the provider that owns it
Sep 28, 2026
002bbe9
docs(changelog): link the provider-switch fix to its PR
Sep 28, 2026
77c1523
Merge PR #6694 (fix/first-run-configured-route-skips-picker) into int…
Sep 28, 2026
79d9815
fix(pricing): keep the OpenRouter roster when one row is bad
Sep 28, 2026
eb48db7
fix(provider): clear the shadowed legacy root model with the root def…
Sep 28, 2026
9a775fb
fix(exec): keep a positional `-` prompt literal; test the exec dispat…
Sep 28, 2026
3a4b961
Merge PR #6691 (fix/6690-openrouter-session-cost) into integrate/0.10.1
Sep 28, 2026
da90fd2
Merge PR #6692 (fix/6688-exec-prompt-stdin) into integrate/0.10.1
Sep 28, 2026
aaaadfe
Merge PR #6693 (fix/provider-switch-keeps-configured-model) into inte…
Sep 28, 2026
3ce6721
fix(tui): clear launch missing-key state when a provider switch lands…
Sep 28, 2026
776e3fe
Merge PR #6696 (fix/first-run-configured-route-e2e) into integrate/0.…
Sep 28, 2026
fa7ec4c
fix(tui): skip ambiguous OpenRouter rows; align first-run test with #…
Sep 28, 2026
2ea4858
test(fleet): read the documented SSH worker example with CRLF normalized
Sep 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
14 changes: 13 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -155,7 +155,7 @@ jobs:
scripts/release/npm-wrapper-smoke.js|scripts/mobile-smoke.sh|scripts/check-provider-registry.py)
heavy=true
;;
crates/*|docs/HOOKS.md|docs/KEYBINDINGS.md|docs/TELEMETRY.md|docs/FLEET_WORKFLOW_TUTORIAL.md|docs/2512.24601v2.pdf|docs/cloud-facts/*|docs/examples/*)
crates/*|docs/HOOKS.md|docs/KEYBINDINGS.md|docs/TELEMETRY.md|docs/FLEET_WORKFLOW_TUTORIAL.md|docs/zh_hans/FLEET.md|docs/2512.24601v2.pdf|docs/cloud-facts/*|docs/examples/*)
heavy=true
;;
docs/*|*.md|packaging/aur/*|.github/PULL_REQUEST_TEMPLATE.md|.github/ISSUE_TEMPLATE/*|.github/scripts/agent-task-metadata.test.sh|.github/workflows/agent-task-labels.yml|.github/workflows/auto-tag.yml|.github/workflows/stale.yml|.github/workflows/triage.yml|scripts/release/check-versions.sh|scripts/release/check-ohos-deps.sh|scripts/release/install-dogfood.sh|scripts/release/install-dogfood.test.sh|scripts/release/prepare-release.sh|scripts/release/prepare-release.test.sh|scripts/dev-cache.sh|scripts/dev-cache.test.sh|scripts/dev-cargo.sh|scripts/dev-test.sh)
Expand Down Expand Up @@ -295,6 +295,10 @@ jobs:
- uses: actions/setup-node@v7
with:
node-version: 22
- name: Run Runtime SDK runtime and type tests
run: |
npm ci --ignore-scripts --workspace @codewhale/runtime-sdk
npm test --workspace @codewhale/runtime-sdk
- name: Run chat-bridge suites
# All four bridges + bridge-core ship dependency-free node --test
# suites that no workflow ran. weixin has no lockfile by design
Expand Down Expand Up @@ -487,6 +491,14 @@ jobs:
- name: Check provider registry drift
if: needs.changes.outputs.heavy == 'true'
run: python3 scripts/check-provider-registry.py
- name: Check the offline model seed is generated
if: needs.changes.outputs.heavy == 'true'
# crates/config/assets/models_dev.bundled.json is rendered from
# scripts/catalog/models_dev_seed.toml and its lock (#6396). A hand edit
# fails here; docs/CATALOG_REFRESH.md has the regenerate steps.
run: |
python3 scripts/catalog_models_dev.py seed render --check
python3 -m unittest scripts/catalog_models_dev_test.py
- name: Check command-contract prototype boundary
if: needs.changes.outputs.heavy == 'true'
# The runtime -> UI ratchet baseline is compared with the one at the
Expand Down
527 changes: 526 additions & 1 deletion CHANGELOG.md

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Changelog entries land before the merge

The repository workflow reserves changelog edits for main after merging. This integration carries both changelogs; confirm the release process explicitly permits that exception.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions README.ar.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale وكيل مفتوح المصدر يقرأ مشروعك ويعدّل الملفات ويشغّل الأوامر ويتحقق من عمله باستخدام نموذج مستضاف أو محلي تختاره. ابدأ بمهمة واحدة في الطرفية. وللأعمال الأكبر، وزّع أجزاء العمل على وكلاء بنماذج وأدوار مختلفة.

![Codewhale يعمل في طرفية](web/public/codewhale-tui-d7a9a1c.png)
![Codewhale يعمل في طرفية](web/public/codewhale-tui-5765d80.png)

*معاينة للطرفية من بنية تطوير للإصدار v0.10.0.*

Expand Down
4 changes: 2 additions & 2 deletions README.ca.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale és un agent de codi obert que llegeix el teu projecte, edita fitxers, executa ordres i comprova la seva feina amb un model allotjat o local que tu tries. Comença amb una tasca al terminal. Per a una feina més gran, assigna parts de la feina a agents amb models i rols diferents.

![Codewhale executant-se en un terminal](web/public/codewhale-tui-d7a9a1c.png)
![Codewhale executant-se en un terminal](web/public/codewhale-tui-5765d80.png)

*Previsualització del terminal d’una compilació de desenvolupament de la v0.10.0.*

Expand Down
4 changes: 2 additions & 2 deletions README.de.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale ist ein Open-Source-Agent, der dein Projekt liest, Dateien bearbeitet, Befehle ausführt und seine Arbeit mit einem gehosteten oder lokalen Modell deiner Wahl prüft. Starte mit einer Aufgabe im Terminal. Teile eine größere Aufgabe auf Agenten mit verschiedenen Modellen und Rollen auf.

![Codewhale in einem Terminal](web/public/codewhale-tui-d7a9a1c.png)
![Codewhale in einem Terminal](web/public/codewhale-tui-5765d80.png)

*Terminalvorschau aus einem Entwicklungsbuild von v0.10.0.*

Expand Down
4 changes: 2 additions & 2 deletions README.es-419.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale es un agente de código abierto que lee tu proyecto, edita archivos, ejecuta comandos y comprueba su trabajo con un modelo alojado o local que tú eliges. Empieza con una tarea en la terminal. Para un trabajo más grande, asigna partes del trabajo a agentes con distintos modelos y roles.

![Codewhale ejecutándose en una terminal](web/public/codewhale-tui-d7a9a1c.png)
![Codewhale ejecutándose en una terminal](web/public/codewhale-tui-5765d80.png)

*Vista previa de la terminal de una compilación de desarrollo de v0.10.0.*

Expand Down
4 changes: 2 additions & 2 deletions README.fr.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale est un agent open source qui lit votre projet, modifie des fichiers, exécute des commandes et vérifie son travail avec un modèle hébergé ou local de votre choix. Commencez par une tâche dans votre terminal. Pour un travail plus important, confiez-en des parties à des agents utilisant différents modèles et rôles.

![Codewhale en cours d’exécution dans un terminal](web/public/codewhale-tui-d7a9a1c.png)
![Codewhale en cours d’exécution dans un terminal](web/public/codewhale-tui-5765d80.png)

*Aperçu du terminal dans une version de développement de la v0.10.0.*

Expand Down
4 changes: 2 additions & 2 deletions README.hi.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale एक ओपन सोर्स एजेंट है जो आपकी पसंद के होस्ट किए गए या लोकल मॉडल से आपका प्रोजेक्ट पढ़ता है, फ़ाइलें संपादित करता है, कमांड चलाता है और अपने काम की जाँच करता है। टर्मिनल में एक काम से शुरुआत करें। बड़े काम के हिस्से अलग-अलग मॉडल और भूमिकाओं वाले एजेंटों को सौंपें।

![टर्मिनल में चलता Codewhale](web/public/codewhale-tui-d7a9a1c.png)
![टर्मिनल में चलता Codewhale](web/public/codewhale-tui-5765d80.png)

*v0.10.0 के विकासाधीन बिल्ड से टर्मिनल का पूर्वावलोकन।*

Expand Down
4 changes: 2 additions & 2 deletions README.id.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale adalah agen sumber terbuka yang membaca proyek, mengedit berkas, menjalankan perintah, dan memeriksa hasil kerjanya dengan model yang dihosting atau model lokal pilihan Anda. Mulailah dengan satu tugas di terminal. Untuk pekerjaan yang lebih besar, bagikan sebagian pekerjaan kepada agen dengan model dan peran yang berbeda.

![Codewhale berjalan di terminal](web/public/codewhale-tui-d7a9a1c.png)
![Codewhale berjalan di terminal](web/public/codewhale-tui-5765d80.png)

*Pratinjau terminal dari build pengembangan v0.10.0.*

Expand Down
4 changes: 2 additions & 2 deletions README.it.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale è un agente open source che legge il tuo progetto, modifica file, esegue comandi e verifica il proprio lavoro usando un modello ospitato o locale a tua scelta. Parti da un’attività nel terminale. Per un lavoro più grande, assegna parti del lavoro ad agenti con modelli e ruoli diversi.

![Codewhale in esecuzione in un terminale](web/public/codewhale-tui-d7a9a1c.png)
![Codewhale in esecuzione in un terminale](web/public/codewhale-tui-5765d80.png)

*Anteprima del terminale da una build di sviluppo della v0.10.0.*

Expand Down
4 changes: 2 additions & 2 deletions README.ja-JP.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale は、選んだホスト型またはローカルのモデルを使ってプロジェクトを読み、ファイルを編集し、コマンドを実行して、自分の作業結果を確認するオープンソースのエージェントです。まずはターミナルで一つのタスクから始めましょう。大きな仕事では、異なるモデルや役割を持つエージェントに作業の一部を分担させられます。

![ターミナルで動作する Codewhale](web/public/codewhale-tui-d7a9a1c.png)
![ターミナルで動作する Codewhale](web/public/codewhale-tui-5765d80.png)

*v0.10.0 の開発ビルドによるターミナルのプレビュー。*

Expand Down
4 changes: 2 additions & 2 deletions README.ko-KR.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale은 사용자가 선택한 호스팅 모델이나 로컬 모델로 프로젝트를 읽고, 파일을 편집하고, 명령을 실행하며, 작업 결과를 확인하는 오픈 소스 에이전트입니다. 터미널에서 하나의 작업으로 시작하세요. 더 큰 작업은 서로 다른 모델과 역할을 가진 에이전트에게 나누어 맡길 수 있습니다.

![터미널에서 실행 중인 Codewhale](web/public/codewhale-tui-d7a9a1c.png)
![터미널에서 실행 중인 Codewhale](web/public/codewhale-tui-5765d80.png)

*v0.10.0 개발 빌드의 터미널 미리보기입니다.*

Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,8 @@ agents with different models and roles.
[![Discord](https://img.shields.io/badge/Discord-join-5865F2?logo=discord&logoColor=white)](https://discord.gg/37gfS3ksug)

<picture>
<source media="(prefers-color-scheme: dark)" srcset="web/public/codewhale-tui-d7a9a1c.png">
<img src="web/public/codewhale-tui-d7a9a1c.png" alt="A Codewhale terminal session" width="720">
<source media="(prefers-color-scheme: dark)" srcset="web/public/codewhale-tui-5765d80.png">
<img src="web/public/codewhale-tui-5765d80.png" alt="A Codewhale terminal session" width="720">
</picture>

*Terminal preview from a v0.10.0 development build.*
Expand Down
4 changes: 2 additions & 2 deletions README.pl.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale to agent o otwartym kodzie źródłowym, który czyta Twój projekt, edytuje pliki, wykonuje polecenia i sprawdza swoją pracę przy użyciu wybranego przez Ciebie modelu hostowanego lub lokalnego. Zacznij od jednego zadania w terminalu. Przy większej pracy powierz jej części agentom korzystającym z różnych modeli i pełniącym różne role.

![Codewhale działający w terminalu](web/public/codewhale-tui-d7a9a1c.png)
![Codewhale działający w terminalu](web/public/codewhale-tui-5765d80.png)

*Podgląd terminala z rozwojowej kompilacji v0.10.0.*

Expand Down
4 changes: 2 additions & 2 deletions README.pt-BR.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale é um agente de código aberto que lê seu projeto, edita arquivos, executa comandos e verifica o próprio trabalho usando um modelo hospedado ou local à sua escolha. Comece com uma tarefa no terminal. Para um trabalho maior, distribua partes do trabalho entre agentes com diferentes modelos e funções.

![Codewhale em execução em um terminal](web/public/codewhale-tui-d7a9a1c.png)
![Codewhale em execução em um terminal](web/public/codewhale-tui-5765d80.png)

*Prévia do terminal em uma build de desenvolvimento da v0.10.0.*

Expand Down
4 changes: 2 additions & 2 deletions README.ru.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale — агент с открытым исходным кодом, который читает ваш проект, редактирует файлы, выполняет команды и проверяет свою работу с помощью выбранной вами облачной или локальной модели. Начните с одной задачи в терминале. Для большой работы поручайте её части агентам с разными моделями и ролями.

![Codewhale работает в терминале](web/public/codewhale-tui-d7a9a1c.png)
![Codewhale работает в терминале](web/public/codewhale-tui-5765d80.png)

*Предварительный вид терминала из сборки v0.10.0, находившейся в разработке.*

Expand Down
4 changes: 2 additions & 2 deletions README.tr.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale, seçtiğiniz barındırılan veya yerel bir modeli kullanarak projenizi okuyan, dosyaları düzenleyen, komutları çalıştıran ve yaptığı işi kontrol eden açık kaynaklı bir ajandır. Terminalde tek bir görevle başlayın. Daha büyük bir işte, işin bölümlerini farklı model ve rollere sahip ajanlara verin.

![Terminalde çalışan Codewhale](web/public/codewhale-tui-d7a9a1c.png)
![Terminalde çalışan Codewhale](web/public/codewhale-tui-5765d80.png)

*v0.10.0 geliştirme derlemesinden terminal önizlemesi.*

Expand Down
4 changes: 2 additions & 2 deletions README.uk.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale — агент із відкритим кодом, який читає ваш проєкт, редагує файли, виконує команди й перевіряє свою роботу за допомогою обраної вами хмарної або локальної моделі. Почніть з одного завдання в терміналі. Для великої роботи доручайте її частини агентам із різними моделями й ролями.

![Codewhale працює в терміналі](web/public/codewhale-tui-d7a9a1c.png)
![Codewhale працює в терміналі](web/public/codewhale-tui-5765d80.png)

*Попередній вигляд термінала зі збірки v0.10.0, що перебувала в розробці.*

Expand Down
4 changes: 2 additions & 2 deletions README.vi.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale là tác nhân mã nguồn mở có thể đọc dự án, chỉnh sửa tệp, chạy lệnh và kiểm tra công việc của mình bằng mô hình do nhà cung cấp lưu trữ hoặc mô hình cục bộ mà bạn chọn. Hãy bắt đầu với một tác vụ trong terminal. Với công việc lớn hơn, bạn có thể giao từng phần cho các tác nhân dùng mô hình và đảm nhiệm vai trò khác nhau.

![Codewhale đang chạy trong terminal](web/public/codewhale-tui-d7a9a1c.png)
![Codewhale đang chạy trong terminal](web/public/codewhale-tui-5765d80.png)

*Hình xem trước terminal từ bản dựng phát triển v0.10.0.*

Expand Down
4 changes: 2 additions & 2 deletions README.zh-CN.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale 是一款开源智能体,可使用你选择的托管模型或本地模型读取项目、编辑文件、运行命令并检查自己的工作。从终端中的一项任务开始。对于较大的工作,可以将其中的部分任务交给使用不同模型、承担不同角色的智能体。

![Codewhale 在终端中运行](web/public/codewhale-tui-d7a9a1c.png)
![Codewhale 在终端中运行](web/public/codewhale-tui-5765d80.png)

*终端预览截图来自 v0.10.0 的开发构建。*

Expand Down
4 changes: 2 additions & 2 deletions README.zh-TW.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
<!-- source: README.md sha256:bbb8bfb61e57 -->
<!-- source: README.md sha256:ccb7a0b00317 -->
# Codewhale

Codewhale 是一款開源代理,可使用你選擇的託管模型或本機模型讀取專案、編輯檔案、執行指令,並檢查自己的工作。從終端機中的一項任務開始。對於較大的工作,可以將部分任務交給使用不同模型、擔任不同角色的代理。

![Codewhale 在終端機中執行](web/public/codewhale-tui-d7a9a1c.png)
![Codewhale 在終端機中執行](web/public/codewhale-tui-5765d80.png)

*終端機預覽截圖來自 v0.10.0 的開發建置版本。*

Expand Down
11 changes: 7 additions & 4 deletions config.example.toml
Original file line number Diff line number Diff line change
Expand Up @@ -1377,10 +1377,13 @@ base_url = "https://integrate.api.nvidia.com/v1"
# off: disable banners; an explicit completion sound is independent
# threshold_secs = 30 # only notify when the turn took >= this many seconds
# include_summary = false # include elapsed time + cost in the notification body
# subagent_completion = "final-only" # always | final-only | off — per-subagent
# notifications during fleet/workflow runs. final-only
# (default) stays quiet mid-run and fires once when the
# batch drains; off silences them entirely.
# subagent_completion = "final-only" # always | final-only | off — notices when
# background work finishes: sub-agents, background
# shells and durable tasks. final-only (default) sends
# one notice naming everything that finished once no
# agent, workflow or durable task is still running (a
# running shell such as a dev server never holds it
# back); off silences them entirely.
# completion_sound = "off" # off | beep | bell | file — opt-in turn-completion sound
# sound_file = "E:\\google\\downloads\\notify.wav" # WAV used when completion_sound = "file" (Windows)
[notifications]
Expand Down
16 changes: 3 additions & 13 deletions crates/app-server/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -917,7 +917,9 @@ async fn require_app_server_token(
.get(header::AUTHORIZATION)
.and_then(|value| value.to_str().ok())
.and_then(|raw| raw.strip_prefix("Bearer "))
.is_some_and(|token| constant_time_eq(token.as_bytes(), expected.as_bytes()));
.is_some_and(|token| {
codewhale_core::secret_eq::constant_time_eq(token.as_bytes(), expected.as_bytes())
});

if authorized {
next.run(req).await
Expand All @@ -935,18 +937,6 @@ async fn require_app_server_token(
}
}

/// Compares the full length of both inputs regardless of where they first
/// differ, so auth failures don't leak the matching prefix length via timing.
fn constant_time_eq(a: &[u8], b: &[u8]) -> bool {
let mut diff = a.len() ^ b.len();
for i in 0..a.len().max(b.len()) {
let x = a.get(i).copied().unwrap_or(0);
let y = b.get(i).copied().unwrap_or(0);
diff |= usize::from(x ^ y);
}
diff == 0
}

fn params_or_object(params: Value) -> Value {
if params.is_null() { json!({}) } else { params }
}
Expand Down
Loading
Loading