nafjan/summon
Cross-vendor sub-agent broker with structured envelopes, council, governed deliberation, and authenticated local browser surfaces; optional MCP facade and provider drivers (CLI + openai-compat + arkcli).
Changelog
This file lists user-visible changes to Summon. For the certification record, regression notes, and test evidence, see the detailed engineering history.
[Unreleased]
No unreleased changes.
[3.2.1] - 2026-08-22
- Codex certification scope clarified: Codex remains a supported first-class backend.
Only provenance-required named-model claims, such as
sol-review, are blocked when the CLI does not emit authoritativemodel.servedevidence. Summon records the requested and targeted model, leavesservedunset, and never silently substitutes Luna. Certification requires a provider-authored terminal receipt plus match, mismatch, and missing-receipt fixtures and a fresh live run. - Kimi K3 defaults:
kimi-workerandkimi-codernow pin K3 with maximum supported thinking through the isolated profile. The former K2.7 coding seat remains available askimi-k27-coder. Kimi effort is now exposed as requested profile configuration rather than silently discarded; it is not treated as provider-authored served-model evidence. - OpenCode gateway: added an
opencodesubprocess backend with JSON event parsing, model/variant/session boundary enforcement, per-tier permission policies, live model discovery, and a bundled OpenRouter OX Alpha seat. OpenCode provides a tool/file loop for compatible providers; directopenai-compatseats remain text-only. Model and provider context limits still apply. - OpenRouter routers through OpenCode: OpenCode seats can use the OpenRouter
auto,free, andfusionaliases. A boundedopenrouter_optionsfield carries documented Auto Router and Fusion plugin settings, includinggeneral-high,general-budget, andgeneral-fast, without allowing arbitrary request-body or permission overrides. - OpenCode startup isolation: headless OpenCode dispatches now disable repository-level config/plugins and external skill discovery before any private provider credential is bridged into the child process.
[3.2.0] - 2026-08-22
- Codex model routing guard: explicit Codex model requests now collapse agreeing
-m/--model/-c model=...selectors into one canonical launch selector. Conflicting selectors are refused before provider contact. An explicit pin without an authoritative terminal served-model receipt is blocked rather than reported as a successful, verified run; these trust failures are not retried or silently rerouted. - Codex identity display: an explicit model request no longer inherits the ambient
Codex default in legacy
model.resolvedwhen no handshake or served-model identity is emitted. The envelope now makes the missing evidence visible instead of making a Sol request appear to have run on Luna. - Named model seats: added explicitly pinned
sol-review(gpt-5.6-sol),terra-review(gpt-5.6-terra), andluna-review(gpt-5.6-luna) seats.--list --jsonnow shows each seat's declared backend, permission, model, and effort so an unpinned seat cannot be mistaken for a named model. Terra remains a candidate until its receipt provesmodel.served; Luna remains a separate, explicit cost-efficient lane. - Conversation atlas stability: the local chat surface now reserves status and activity space, gives the timeline its own scroll owner, preserves a visible feed anchor during updates, and keeps role/name/version/model/provider identity together in agent choices. The atlas remains subject to rendered-browser and lifecycle gates before chat GA.
- Next-release contract: added
docs/SUMMON_3.2_PLAN.md, which defines Codex resume fencing, live served-model evidence, roster freshness, privacy boundaries, and the fixed-shell chat acceptance gates. - Authentication recovery: expired or invalid provider credentials now produce a typed,
actionable repair plan.
summon auth statusis read-only;summon auth repair BACKENDrequires--allow-auth-repair, never captures credentials, and never retries the failed dispatch implicitly. - Kimi OAuth refreshes: isolated Kimi dispatch homes now persist a validated provider token rotation back to the source credential file atomically, while refusing to overwrite a newer login or concurrent refresh. Kimi authentication failures and rate limits are terminal, clearly explained, and never trigger a hidden retry or provider switch.
- Telemetry clarity: permission-tier refusals now have their own bounded failure class, so local diagnostics distinguish an unenforceable permission request from authentication, quota, and generic backend failures.
- Telemetry operation audit: added a schema-2, opt-in, local-only operation-terminal event contract with immutable operation context, bounded HMAC correlation, strict public report validation, malformed-input fail-soft handling, and an offline audit that rejects unbound model/auth evidence. This release does not claim signed evidence provenance or production attempt/turn metrics.
- Roster freshness:
summon models --refreshexplicitly refreshes provider rosters where supported. Cached, configured, static, and live sources are distinguished, while exactmodel.servedevidence remains the authority for what ran. ArkCLI is now a first-class discovery/auth lane; Codex candidates remain advisory when its CLI cannot enumerate models. - CI reliability: release evidence now checks the current 3.2.0 version, includes the telemetry audit suite, and the Windows deliberation UI syntax test validates a temporary JavaScript file instead of waiting on a stdin EOF path that can hang on Windows.
[3.1.0] - 2026-08-20
- Dispatch evidence guard: ACP and subprocess completions that claim success without
a usable result are now reported as the typed
empty_terminal_resulterror instead of silently completing. - Model provenance: envelopes distinguish
reported,inferred, andabsentserved_model_evidence; malformed model identifiers are omitted from public metadata. - Retry safety: typed empty results are not retried by fan-out or resume. The explicit
--retry-nonretryablecontrol permits one deliberate fresh attempt; a second empty result remains suppressed. - Deliberation ballot isolation: live provider turns use a compact, non-interactive ballot-only system context instead of inheriting ordinary agent instructions for tools, plan mode, or long report blocks. This prevents live-boundary hangs while preserving the frozen roster and receipt identity used by ordinary deliberation planning.
- Live-provider certification: a bounded Claude Opus matrix covers a decided normal
run, durable cancellation after provider contact, and conservative deadline handling
with
uncertain_spend=true. The source-bound receipt records exact served-model, profile, consent, owner/deadline/cancel fences, no fallback/retry, and clean teardown. - Release posture: this is the 3.1.0 GA release for the evidence-integrity and governed-deliberation lane. Chat/swarm previews and other provider routes retain their own explicit boundaries; no provider claim is inferred from an editorial model label.
- Documentation: clarified the 3.1 GA boundary, unmanaged-copy policy, local diagnostics, and the distinction between chat turns, council context, and deliberation authority. Public docs contain no workstation-specific drift details.
[3.0.0-ga] - 2026-08-18
-
Claude route isolation: default Claude dispatches now pass an empty
--setting-sourcesboundary so unrelated user/projectANTHROPIC_*settings (including a custom endpoint, model, or token) cannot silently reroute a subscription-backed Claude invocation. Intentional custom Claude-compatible routes remain available through an explicitly named private profile. -
Release contract: the source-bound version/migration contract, fixed gate registry, and immutable release evidence are now part of the 3.0.0 GA path.
-
Claude live-provider gate: a reviewed read-only Opus matrix now covers a decided normal run, durable cancellation, and conservative deadline/uncertain-spend handling; the redacted schema-2 receipt is source-bound and other providers remain independently gated.
-
One open product: Summon deliberation is part of the same public product as dispatch, council, and the browser observer. The public
/summon deliberatecommand and thin/deliberatecompanion skill share the same receipt, journal, replay, recovery, and browser observer contracts. -
Explicit governed-decision guidance: agent instructions now distinguish dispatch, manifest, council, and deliberate, and require options, seats, quorum, rounds, attempt budget, deadline, and human-approval policy to be stated rather than inferred.
-
Fresh deliberation lane: the public
deliberatecommand now admits only a receipt-bound, one-round, one-attempt-per-seat run of enforceable read-only subprocess seats with executable evidence. The owner journals a queued cancel at the replay-safe attempt boundary; approval, resume, ACP/HTTP, Kimi, text-only, writable, and full-bypass routes remain explicitly gated. -
Install convergence: managed hosts receive the marked
/deliberatecompanion without clobbering a foreign skill; provider-inert and live-gated readiness labels are now used consistently in the product docs. -
Conversation atlas: the authenticated loopback room now uses a dependency-free, Chatpack-informed messenger layout: searchable project/initiator rooms, grouped human/agent/lifecycle events, role/name/version identity chips, a redacted evidence drawer, cursor-aware reconnect, and separate context versus roster-agent turn composers.
chat open --chat-browser auto|builtin|ide|system|linkstarts or reuses one surface;linkis non-launching for CI/SSH. Chatpack itself is not installed. -
Chat safety/readability slice: live turn claims now use a journal cursor compare-and-swap across runtime instances; human messages expose bounded redacted previews to the atlas; continuation forks preserve the prompt that caused the fork; generic Authorization/Bearer/Basic/Cookie material is redacted and cancellation is recorded as a durable
turn_cancel_requestedcommand observable by another runtime. -
Chat lifecycle fencing: participant leases and process records now reject symlink/junction redirection, bind atlas reuse to project/explicit-roster digests, fence PID reuse with birth tokens, serialize Python 3.13 pipe cleanup, and use the shared Windows Job Object/POSIX process-group teardown path. Windows turns fail closed when the Job Object cannot be attached; this remains a local preview capability gate.
-
Transport evidence: chat dispatch forwards the roster-declared subprocess/ACP transport to the actual dispatcher boundary instead of silently defaulting to subprocess while claiming ACP.
-
Swarm contract preview: documented and validated the versioned
summon.swarm/v1stdio frame boundary for future worker claims, leases, directed messages, fenced artifacts, and cancellation. Completion/artifact frames carry the task/attempt/lease-generation/request digest fence and unknown authority fields are rejected. This is a protocol contract only; the currentmanifestcommand remains batch fan-out and no native IDE swarm attachment is implied. -
Model identity catalog: role, name, version, and editorial frontier labels are now explicit display metadata; exact
model.servedevidence remains separate and unknown models never become dispatchable by implication.
Certification and installation
- GA certification: published the clean source-bound
v3.0.0-garelease after all 17 fixed suites (1,138/1,138) and all eight release gates passed. - Ark roster refresh: the catalog now lists DeepSeek V4 Pro GA as the fifth editorial frontier lane and GLM 5.2 and DeepSeek V4 Flash GA as near-frontier value lanes. These labels are routing metadata, not live availability or served-model evidence.
- Reviewed Claude pilot: certified the bounded
claude-opus-5normal, durable-cancel, and deadline/uncertain-spend cases with exact served-model, profile, account-evidence, cleanup, and consent receipts. - Install convergence: all eight managed host copies match the release
payload at 3.0.0. Unmanaged local copies are preserved and reported by
doctor; this release record contains no workstation-specific drift data. - Engineering record: the full certification, migration, rollback, and
release-manifest evidence is recorded in
docs/ENGINEERING_CHANGELOG.md.
The pre-existing v3.0.0 entry below is retained as the historical
provider-inert/public-preview baseline. Fable, Gemini, Kimi, and other provider
routes remain independently gated.
[3.0.0] - 2026-08-15
- Synchronized the plugin, dispatcher, and MCP companion to the 3.0.0 contract.
- This immutable tag is the historical provider-inert/public-preview baseline.
The later
v3.0.0-gatag carries the clean source-bound GA certification. - Multi-provider live deliberation, automatic fallback/retry, remote hosting, and unproven live continuation remain explicitly deferred. Provider expansion still requires an independent receipt and gate.
[2.2.0] - 2026-08-12
Highlights
- Opt-in diagnostics:
summon telemetry enablecaptures bounded, categorized local dispatch metadata (including deterministic SHA-256 fingerprints for local correlation);summon bug-reportcreates a reviewable Markdown report. A second, explicit--submit-github --from REVIEWED_REPORT.mdcommand submits that exact file through authenticatedgh. Telemetry is disabled by default, contains no prompt/result text or credentials/absolute paths, and never phones home. Fingerprints can still correlate or reveal low-entropy values, so review before sharing.
Fixed
- Council setup and overall-timeout exits now leave categorized local diagnostic events when telemetry is enabled; spool locking, bounded reads, and reviewed-report submission are ownership- and snapshot-safe.
Install / upgrade
npx skills add Nafjan/summon
[2.1.0] - 2026-08-11
Highlights
- Named local profiles: route a Claude agent to an operator-owned config directory and, when needed, a pinned executable without putting machine paths or credentials in the public roster. Receipts carry the profile name and integrity digests.
- Strict roster provenance: add
--strict-agents-dirto make governance-controlled dispatch fail closed when a named role is absent, while keeping the normal bundled/plugin fallback convenient by default. - Private role aliases (experimental): propose and explicitly approve operator-owned
aliases for existing roster definitions, then opt into them with
--enable-roles. Exact names win; target and approval hashes are checked before dispatch and only digest-based provenance appears in receipts.
Maintenance
- Added request-identity and background forwarding coverage for profile selection. Automatic cross-account retries remain intentionally out of scope because they can duplicate work.
- Background, manifest, and council role propagation is covered; malformed, chained, or retargeted aliases fail closed rather than silently falling back.
[2.0.5] - 2026-08-09
Highlights
- Headless Windows launches: dispatcher, utility, detached, and nested AGY
processes now request both
CREATE_NO_WINDOWand a hidden startup state, so routine Summon work no longer flashes black console windows. The skill and README include a caller checklist for bypassing visibleStart-Process/cmd /c startwrappers and the legacy AGY PTY override.
Fixed
- ACP timeout cleanup: Kimi and other ACP children are tree-killed before their leader can orphan a backend process; timeout envelopes now show one correct unit and the protocol phase Summon can prove.
- Privacy hygiene: parsed handoff fields and dry-run previews are redacted before they enter envelopes or debug artifacts; gate handoff declarations remain visible to the caller.
- Health checks:
doctornow allows up to 45 seconds for a CLI's first--versionresponse, preventing healthy but slow AGY/Gemini Windows starts from being reported as broken.
Install / upgrade
npx skills add Nafjan/summon
[2.0.4] - 2026-08-08
Kill the leftover "agy cannot read --cwd" myth in code comments; clarify why
researcher is omitted from council defaults.
Fixed
- DEFAULT_MEMBERS comments no longer list Antigravity in the default set or claim
agy "reports no telemetry" absolutely — Summon's default subprocess path simply does
not surface usage/
model.served; read-only needsSUMMON_ALLOW_UNENFORCED_READONLY=1. - Removed dead
_AGY_FILE_READ_RE/_agy_prompt_references_file(unused since the retired no-cwd warning was deleted). - Tests assert the myth string and dead regex stay gone.
[2.0.3] - 2026-08-08
Docs clarity for reasoning effort / thinking levels (no runtime behavior change).
Added
- references/effort.md: per-backend matrix for
who honors
--effort, Summon defaulthigh(claude/codex), agy Gemini explicit-only suffixes, and backends that ignore the flag (cursor/kimi/openai-compat/arkcli). Linked from SKILL.md, customizing, models, fan-out, and--help.
[2.0.2] - 2026-08-08
Patch on 2.0.1 from round-2 adversarial review (GLM-5.2 + DeepSeek-V4-Flash via arkcli, AGY Flash 3.6 via summon).
Fixed
- Text-seat
--outfingerprint now treats agent frontmattercapability: text-onlyas opted-in (same as--allow-text-only/SUMMON_ALLOW_TEXT_ONLY=1), using the already-loaded definition snapshot — so consent identity matches the gate. install.py --hostsapplies the sameos.path.isdirhost-root filter as the profile-only path; refuses with a clear error when none of the requested roots exist.- Council chairman clamp matches only known stages (
chairman,chairman-fallback) after thegN-prefix — not every tag whose suffix merely starts withchairman.
[2.0.1] - 2026-08-07
Patch on 2.0.0: text-seat honesty, T3 Summon-side support, timeout/PAYG budget hardening, and adversarial-review fixes (Kimi K3 + GPT-5.6 Sol + Claude Opus).
Added
-
T3 Code support (Summon-side):
python install.py --profile t3installs into Claude/Codex/Cursor skill roots T3 discovers;doctor/onboardreport at3_codereadiness section; guide atskills/summon/references/t3-code.md. Not a native T3 plugin and not an upstream T3 PR — Summon rides provider skill discovery.--profile t3 --hostsis intersected with the profile set (out-of-profile hosts refused). -
Council/manifest text-seat gate: ModelArk /
openai-compat/arkclimembers are auto-rejected in fan-out unlessSUMMON_ALLOW_TEXT_ONLY=1(capability /--allow-text-onlyremain single-dispatch only). Pure-text councils still work with the env set deliberately. Fan-out children get--require-toolswhen that env is unset (blocks mid-run definition mutation tocapability: text-only).SUMMON_REQUIRE_TOOLS=1also refuses fan-out text seats. -
Banner:
assets/banner.svglists kimi and modelark alongside the other backends. -
Text-seat honesty:
openai-compatand Summonarkclirefuse by default unless--allow-text-only/SUMMON_ALLOW_TEXT_ONLY=1/capability: text-only. Machine-readableblocked_reason: text_seat_no_tools+text_seatrecovery object (PATH-filteredsuggested_reroutes). Opt-in still warns every run;--require-tools/SUMMON_REQUIRE_TOOLS=1overrides opt-in. House chat agents (byteplus-coder,openrouter-example,fable-api) declarecapability: text-only. Migration: existing one-shot openai-compat scripts must pass the flag or set capability; do not auto-retry blocked text seats with--allow-text-only.
Fixed
- Timeout hardening: Coding Plan → PAYG retry spends only the remaining
wall-clock budget; skip PAYG when remaining is under 1s. Council
--overall-timeoutclamp reserves the parent watchdog margin and excludes stages that cannot afford child+margin. - Chairman read-only clamp now matches generation-prefixed tags (
gN-chairman). - Text-seat consent is part of request identity for
--outreuse (opt-in / require-tools cannot be skipped via a cached success). - Manifest text-seat gate fails closed (no ImportError swallow; honest CLI resolve).
[2.0.0] - 2026-08-07
Product 2.0: Agent Plugin distribution + optional MCP facade + provider-driver SPI
on the same broker (envelope schema still 1). Includes everything that landed as
the 1.2 onboard train, plus pack discovery wired into --list / load paths and an
explicit MCP local-trust ADR section.
Added
-
Agent Plugin packaging: root
plugin.json(Agent Plugins 1.0.0) plus optionalmcp.jsonstdio facade; keepinstall.pyfor skill-dir hosts. See docs/ADR-mcp-facade.md. -
Provider-driver SPI: thin
cli/openai-compat/arkcli/acpregistry with additive envelope fields (backend_type,served.via,provider.driver) and a dual-wirerun-agent: arkclibackend (arkcli +chat). See docs/ADR-provider-drivers.md. -
Agent packs: optional
com.summon.agents/extension namespace for third-party roster packs. -
Streaming partials:
SUMMON_STREAM_PARTIALS=1emits JSONL progress on stderr without changing the final envelope. -
Onboard (
--onboard): detect CLIs, record subscription prefs in~/.agents/summon.json, and surface them indoctor(never stores API secrets). -
BytePlus key auto-resolve:
BYTEPLUS_CODING_API_KEYfrom env or local arkcli profile when unset; doctor reports presence and source only. -
Dry-run hints:
native_prefer_hintwhen the host CLI matches the target backend, or whenopenai-compatis a single-shot chat seat. -
Envelope telemetry: additive
backend_type,served_via, andprovider.driveron dispatch results. -
Agent tags: optional frontmatter
capability:/billing:copied to dry-run and result asagent_tags. -
Transient retries:
--transient-retries/SUMMON_TRANSIENT_RETRIES=1for one conservative retry on timeout/5xx-style failures (never auth). -
BytePlus ModelArk: built-in
byteplus-codingprovider for Coding Plan (/api/coding/v3) withBYTEPLUS_CODING_API_KEY, bundledbyteplus-coderagent, subscription billing on successful Coding Plan calls, live roster cache from arkcli, and consent-gated one-shot PAYG (/api/v3) fallback (--allow-payg/ env / prefs). Platform PAYG remains available via inlineopenai-compatbase_urlwithout the Coding Plan provider. -
Environment handoff: every bundled agent now reports
LEFT_BEHIND, and each envelope exposes it asenvironment_handoffso its caller can decide what to retain or clean up. This covers temporary paths, processes, servers, VMs, and container resources; summon never deletes them automatically. -
Purposeful Kimi roster roles:
kimi-workernow identifies K3 as the high-context architecture/review worker, whilekimi-coderpins K2.7 Coding for scoped implementation and debugging. Both retain Kimi's explicit full-authority worktree requirement.
[1.1.0] - 2026-07-31
Kimi Code joins Summon, alongside a more dependable AGY path.
Highlights
- Use Summon directly in Kimi Code:
install.py --hosts kimiinstalls the complete skill at~/.kimi-code/skills/summon, ready for Kimi’s native/skill:summonworkflow. - Call Kimi from any supported host: the new
kimibackend uses Kimi’s nativestream-jsonprotocol, supports model pins such askimi-code/k3andkimi-code/kimi-for-coding, and returns the same structured Summon envelope as the other CLI backends. - Safer Kimi one-shots: each Kimi child receives a fresh, ACL-locked runtime profile with no inherited sessions, logs, user skills, or MCP configuration. Because Kimi’s prompt mode has no enforceable workspace sandbox, Summon refuses misleading
read-onlyandsafe-editdeclarations; the explicitkimi-workeris for trusted isolated worktrees. - AGY reliability pass: a built-in cross-platform stream proxy replaces fragile terminal scraping where AGY exposes JSONL, with stronger event parsing and model-alias handling.
Also improved
- ACP transport (phase 1):
gemini,kimi, andcursor-agentcan run over the Agent Client Protocol (JSON-RPC stdio) instead of a one-shot argv spawn. Three engagements: automatic recovery attempt when a subprocess dispatch fails in a transport-fixable way (narrow predicate — never for auth/spawn/structural failures), automatic routing for prompts over the OS argv limit, and explicit opt-in viatransport: acpfrontmatter or--transport acp. New flags:--transport,--no-acp-fallback(envSUMMON_ACP_FALLBACK=0). Envelopes recordtransport,fallback(the recovery attempt, doubling as telemetry for scoping ACP phase 2 — claude/codex adapters — on measured fallback rates), andacp.session_id(telemetry only; the resume lane stays empty). ACP is yolo-only: permission flags cannot travel over the protocol, soread-only/safe-editare refused rather than run with reactive-only containment (within yolo, permission requests are auto-answered allow-once only, fail closed); model pinning is best-effort with a warning.--doctorreports per-CLI ACP support. - Hardened debug argument redaction and boundary-flag handling.
- Clarified wrapper readiness in diagnostics.
- Accept markdown-bold report fields (
**STATUS:**) from markdown-rendered backends such as AGY, avoiding an unnecessary corrective resume.
Release certification remains separate: three clean cross-vendor rounds are still required before these additions earn a certification claim.
[1.0.0] - 2026-07-29
Summon any AI, from any CLI. Version 1.0 establishes the stable public contract for the capabilities built throughout the 0.x series. The highlights below are a milestone recap; the final release also corrects plan-dependent Fable billing telemetry.
Highlights
- Cross-vendor orchestration from the tool you already use. Send work to Claude, Codex, Cursor, Gemini, Antigravity, an OpenAI-compatible API, or a local model without leaving your current CLI or agent app.
- Councils for decisions, swarms for scale. Run vendor-diverse deliberations with anonymized peer ranking, or fan out resumable manifest jobs with per-backend concurrency.
- Safer parallel implementation. Isolate editing agents in Git worktrees, preview resolved runs before spending tokens, clamp permissions on backends that enforce them, and require an independent gate before the child agent runs.
- Results built for automation. Every run returns a stable JSON envelope separating execution state from the agent's verdict, with model provenance, warnings, resume state, and structured report or handoff data when available.
- Reliable structured output. Validate responses against summon's documented JSON
Schema subset, surface unsupported keywords in
parse_warnings, and use a corrective retry on backends that support resume. - Auditable work beyond Git. Track loose documents by SHA-256, detect changes during a run, and use the bundled document-audit templates for claim-led reviews.
- Operational confidence. Background jobs survive the parent session,
doctorsurfaces backend readiness and installation drift, and every dispatch identifies the exact installed script copy that ran. - A small core. The dispatcher is standard-library Python and needs no summon server.
The optional Antigravity PTY bridge uses
pywinptyandpyte.
Stable contract
The documented CLI, agent definitions, report fields, and exit codes are now public API.
The response envelope remains independently versioned as envelope: 1, allowing
backward-compatible additions throughout the 1.x line.
Fixed
- Reported Fable billing as plan-dependent instead of assuming every Claude plan includes it.
Release confidence
The corrected runtime surface earned three consecutive clean cross-vendor adversarial reviews after a clean manual security audit. The final release passes 429 discovery tests and 22 installer tests. The exact acceptance criteria and evidence are documented in Versioning and 1.0 criteria.
[0.19.2] - 2026-07-29
Fixed
- Kept the executor's status authoritative through report reconciliation.
- Represented unreadable post-run artifact state as unknown instead of unchanged.
- Contained worktree cleanup by resolved path, including through symlinks.
[0.19.1] - 2026-07-29
Fixed
- Prevented
jobs waitfrom losing a result published as its child exited. - Stopped treating a failed artifact read as an observed file change.
[0.19.0] - 2026-07-29
Added
- Separated successful execution from a reviewing agent's
pass,conditional, orblockverdict. - Added resume reporting, loose-file provenance, document-audit templates, and liveness-aware background jobs.
Fixed
- Preserved worktrees when a denied run contained new or ambiguous work.
- Corrected background-job liveness and stale-state reporting.
[0.18.0] - 2026-07-28
Security
- Restricted Antigravity cleanup to structurally verified generated logs and rechecked file identity immediately before deletion.
Added
- Added roster permission lint and agent-definition provenance to dry runs and diagnostics.
Fixed
- Corrected gate timeout parsing, worktree teardown, and timeout-cause reporting.
Earlier development releases
The earlier 0.x series established the core dispatcher, six backend families, agent rosters, structured reports, councils, manifest swarms, background jobs, isolated worktrees, permission gates, model discovery, and installation diagnostics. Its detailed release history remains available, version by version, in the engineering archive.