Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
289 commits
Select commit Hold shift + click to select a range
6897bf4
feat: add live team map (#434)
milind-soni Aug 24, 2026
077f186
feat: add section-scoped shared context (#435)
milind-soni Aug 24, 2026
f64ea65
feat: preview image attachments inside the app (#436)
milind-soni Aug 24, 2026
3669f75
feat: add find-in-chat and flat replies (#437)
milind-soni Aug 24, 2026
1602f97
feat(pi): image attachments and reasoning-effort levels (#438)
cjpraia Aug 24, 2026
7fbbd22
Paint the resting face when a mascot mounts paused (#444)
milind-soni Aug 24, 2026
f71c763
fix(composio): preload connected account state (#445)
milind-soni Aug 24, 2026
a5b7de5
chore(release): bump version to 0.1.33 (#446)
milind-soni Aug 24, 2026
ba3ad4b
Add portable BotMRR Markdown playbooks (#426)
milind-soni Aug 24, 2026
4afd5ec
fix(composio): accept empty authorization bodies (#451)
milind-soni Aug 25, 2026
8ab76cc
ci: stop retaining disposable Linux packages (#452)
milind-soni Aug 25, 2026
bbced13
fix(linux): harden Ubuntu upgrades and Xorg local control (#346)
KesleyDavid Aug 25, 2026
4cd59ed
Let Antigravity models control computers (mount the computer MCP) (#447)
milind-soni Aug 25, 2026
336fec3
feat(electron): right-click context menu with clipboard and spellchec…
johnsonAyo Aug 25, 2026
a0ca53b
feat(ui): composer attach button and per-bot permission mode selector…
johnsonAyo Aug 25, 2026
2eac40c
fix(drivers): scope local-computer approvals to real desktop-control …
johnsonAyo Aug 24, 2026
56d116b
fix(drivers): guard ask.tool is a string before scoping approvals (Co…
johnsonAyo Aug 24, 2026
ae6906f
feat(computer): open live desktop from preview
milind-soni Aug 25, 2026
50f82cd
fix(drivers): drop resolved asks from the pending-tool map (CodeRabbit)
johnsonAyo Aug 25, 2026
e40954b
Merge pull request #455 from milind-soni/codex/click-preview-live-des…
milind-soni Aug 25, 2026
b7dcd8d
fix(ios): pair through the first reachable trusted route
milind-soni Aug 25, 2026
70f8591
Merge pull request #456 from milind-soni/codex/connectivity-foundation
milind-soni Aug 25, 2026
7094598
feat(companion): advertise typed connection endpoints
milind-soni Aug 25, 2026
0c07f52
feat(ios): dial typed HTTPS companion endpoints
milind-soni Aug 25, 2026
e1c7535
fix(ios): fail over when hosted routes break
milind-soni Aug 25, 2026
8c01506
fix(companion): tolerate invalid advisory routes
milind-soni Aug 25, 2026
d5b02fa
Merge pull request #457 from milind-soni/codex/typed-companion-endpoints
milind-soni Aug 25, 2026
cd3221d
feat(computer): add secure VPS parity and companion uptime
milind-soni Aug 25, 2026
38d1cbf
feat(auth): add Better Auth D1 control plane
milind-soni Aug 25, 2026
17e4dbe
fix(auth): validate control-plane health configuration
milind-soni Aug 25, 2026
b8362a2
Merge pull request #459 from milind-soni/codex/control-plane-auth
milind-soni Aug 25, 2026
b5c7938
fix(companion): harden public tunnel responses
milind-soni Aug 25, 2026
1db843e
feat(desktop): add authenticated control-plane client
milind-soni Aug 25, 2026
01a2dd2
fix(desktop): serialize encrypted credential updates
milind-soni Aug 25, 2026
a57e4e9
feat(companion): add email setup for hosted access
milind-soni Aug 25, 2026
1aa2f4d
feat(companion): expose narrow account onboarding bridge
milind-soni Aug 25, 2026
bce7f65
build: bundle pinned cloudflared connector
milind-soni Aug 25, 2026
72a3c7a
feat(companion): manage secure hosted connector
milind-soni Aug 25, 2026
916fe52
fix(companion): honor Windows credential directory ACLs
milind-soni Aug 25, 2026
7c26635
feat(control-plane): provision managed companion endpoints
milind-soni Aug 25, 2026
c3133c8
fix(companion): tie public health to the harness
milind-soni Aug 25, 2026
17bdf53
feat(companion): add hosted account onboarding service
milind-soni Aug 25, 2026
2dd8b31
docs(control-plane): match provider timeout
milind-soni Aug 25, 2026
09a6cc4
Add Polar funding: Sponsor button, README support section
milind-soni Aug 25, 2026
a9a636a
Merge pull request #460 from milind-soni/feat/polar-funding
milind-soni Aug 25, 2026
b4b7eb2
fix(companion): preserve hosted setup recovery
milind-soni Aug 25, 2026
d206bca
Merge pull request #458 from milind-soni/codex/vps-parity-companion-a…
milind-soni Aug 25, 2026
6dc8fc4
Merge pull request #440 from johnsonAyo/fix/always-allow-non-computer…
milind-soni Aug 25, 2026
4460fa7
fix(companion): complete interrupted account cleanup
milind-soni Aug 25, 2026
1c124b6
fix(companion): preempt tunnel startup on stop
milind-soni Aug 25, 2026
b1afb93
Give the support link a big badge under the download buttons
milind-soni Aug 25, 2026
03547da
Merge pull request #461 from milind-soni/feat/support-badge
milind-soni Aug 25, 2026
2f7ad3d
Merge origin/main into codex/managed-companion-tunnel
milind-soni Aug 25, 2026
5323e3a
fix(companion): reconcile lost hosted installations
milind-soni Aug 25, 2026
b7541a2
docs(ios): disclose optional hosted companion access
milind-soni Aug 25, 2026
356adf7
fix(companion): distinguish configured hosted address
milind-soni Aug 25, 2026
3648de3
fix(companion): bind hosted tunnel to owned sidecar
milind-soni Aug 25, 2026
d199a12
fix(companion): gate hosted onboarding on service health
milind-soni Aug 25, 2026
722958a
fix(control-plane): fence managed endpoint cleanup
milind-soni Aug 25, 2026
1948e72
feat(companion): refresh live connection endpoints
milind-soni Aug 25, 2026
18d3124
docs(companion): document hosted trust boundary
milind-soni Aug 25, 2026
1fc9524
fix(ios): keep companion credentials on trusted routes
milind-soni Aug 25, 2026
55be0a1
Merge remote-tracking branch 'origin/main' into codex/managed-compani…
milind-soni Aug 25, 2026
596391a
chore(desktop): clean credential state source
milind-soni Aug 25, 2026
83db55f
fix(companion): bound hosted availability checks
milind-soni Aug 25, 2026
3618d2f
fix(companion): stop hosted access before sign-out cleanup
milind-soni Aug 25, 2026
b0d9f69
fix(companion): keep packaged control dependency-free
milind-soni Aug 25, 2026
5a87fab
fix(electron): remove packaged zod dependency
milind-soni Aug 25, 2026
93ed93d
fix(companion): surface account action failures
milind-soni Aug 25, 2026
13c81a4
fix(companion): settle origin failure paths
milind-soni Aug 25, 2026
55c8e79
fix(control-plane): harden provider cleanup retries
milind-soni Aug 25, 2026
2a17d42
fix(companion): isolate account status polling
milind-soni Aug 25, 2026
3557e74
Merge pull request #462 from milind-soni/codex/managed-companion-tunnel
milind-soni Aug 25, 2026
faef86f
chore: configure production control plane
milind-soni Aug 25, 2026
5541233
fix(chat): make local file links in bot messages save to Downloads
johnsonAyo Aug 25, 2026
664fabf
refactor(chat): harden local file saving after review
johnsonAyo Aug 25, 2026
f847a42
fix(chat): make local file saving work on Windows
johnsonAyo Aug 25, 2026
8541317
test(save-file): compare against fs.promises.realpath on Windows
johnsonAyo Aug 25, 2026
0f8e85d
fix(chat): correct the root cause, and close the remaining review gaps
johnsonAyo Aug 25, 2026
a332f0e
feat(chat): ask where to save instead of silently using ~/Downloads
johnsonAyo Aug 25, 2026
46bd7ef
fix(chat): copy local files from stable source handles
johnsonAyo Aug 25, 2026
a79dcb8
fix(chat): harden Windows source validation
johnsonAyo Aug 25, 2026
cf8ccfd
fix(chat): preserve Windows file identity precision
johnsonAyo Aug 25, 2026
dae7631
Merge pull request #463 from milind-soni/codex/cloudflare-production-…
milind-soni Aug 25, 2026
7ac0d65
fix(mdns): keep the cache-flush bit off shared PTRs and legacy replies
KesleyDavid Aug 25, 2026
04e10c2
chore(release): bump version to 0.1.34
milind-soni Aug 25, 2026
995f529
Merge pull request #472 from milind-soni/codex/bump-0.1.34
milind-soni Aug 25, 2026
2707181
fix(control-plane): support Worker redirect handling (#473)
milind-soni Aug 25, 2026
bb087fa
fix companion auth error handling (#474)
milind-soni Aug 25, 2026
cad9579
feat(composer): edit pasted text in chat box
OWConnoi Aug 25, 2026
c2c728a
chore(composer): document pasted text flow
OWConnoi Aug 25, 2026
9f8e00b
docs(composer): satisfy review coverage
OWConnoi Aug 25, 2026
82c9062
docs(composer): document pasted text test cases
OWConnoi Aug 25, 2026
c4874c1
fix: replace hardcoded light fills in provider icons with var(--color…
AzharShaikhSE Aug 25, 2026
e51026e
fix(control-plane): preserve Worker fetch receiver (#476)
milind-soni Aug 26, 2026
16c9ccd
fix: wait for hosted endpoint before pairing (#477)
milind-soni Aug 26, 2026
8caa9b3
chore(release): bump version to 0.1.35 (#483)
milind-soni Aug 26, 2026
2b7c1b8
Merge pull request #480 from AzharShaikhSE/fix/provider-logos-theme-i…
milind-soni Aug 26, 2026
de376ae
Merge pull request #475 from OWConnoi/feat/display-pasted-text-in-chat
milind-soni Aug 26, 2026
6510ca1
Merge pull request #471 from KesleyDavid/KesleyDavid/mdns-cache-flush
milind-soni Aug 26, 2026
4fcd2b0
Merge pull request #464 from johnsonAyo/fix/local-file-download-links
milind-soni Aug 26, 2026
ddccdcf
fix(connectors): never show a connected app as disconnected
aivsomkar Aug 25, 2026
d8c9f67
fix(connectors): preserve credential and cache authority
milind-soni Aug 26, 2026
6a703d3
fix(computer): address VPS and Companion review gaps
milind-soni Aug 26, 2026
d571fb8
Merge pull request #470 from milind-soni/fix/connectors-never-look-di…
milind-soni Aug 26, 2026
a682033
Merge pull request #484 from milind-soni/codex/vps-parity-companion-a…
milind-soni Aug 26, 2026
3a4635c
fix(openai-compat): support reasoning models and fix openaiCompat con…
ericmaddox Aug 26, 2026
b95c0c5
fix(openai-compat): preserve endpoint and reasoning contracts
milind-soni Aug 26, 2026
5d97c69
fix(openai-compat): keep instance defaults transient
milind-soni Aug 26, 2026
6f174b8
Merge pull request #482 from ericmaddox/fix/openai-compat-reasoning-a…
milind-soni Aug 26, 2026
08a8629
feat(voice): built-in Mac voices — calls with no ElevenLabs key
OWConnoi Aug 23, 2026
16ea254
fix(voice): keep ElevenLabs recovery available
milind-soni Aug 26, 2026
b3a96a2
Merge pull request #415 from OWConnoi/feat/system-voice-tts
milind-soni Aug 26, 2026
5ba60e0
fix(diagnostics): redact OpenAI-compatible environment
milind-soni Aug 26, 2026
acadce4
Merge pull request #485 from milind-soni/codex/openai-compat-diagnost…
milind-soni Aug 26, 2026
0071876
fix(voice): keep system runner testable cross-platform
milind-soni Aug 26, 2026
84e1e6f
Merge pull request #486 from milind-soni/codex/system-voice-runner-ci
milind-soni Aug 26, 2026
2b3ee8a
feat(chat): fold a stretch of tool chips into one row
aivsomkar Aug 23, 2026
e15f099
fix(chat): preserve activity run boundaries
milind-soni Aug 26, 2026
418c3cb
Merge pull request #394 from milind-soni/feat/collapse-tool-runs
milind-soni Aug 26, 2026
5326fa5
Per-turn workspace checkpoints with rollback (shadow git)
milind-soni Aug 24, 2026
80be94e
fix(checkpoints): preserve pre-turn safety boundary
milind-soni Aug 26, 2026
2b01764
fix(checkpoints): scope snapshots to project turns
milind-soni Aug 26, 2026
ad7ac33
fix(checkpoints): make restores exclusive and lossless
milind-soni Aug 26, 2026
7417725
Merge pull request #433 from milind-soni/feat/turn-checkpoints
milind-soni Aug 26, 2026
300b30b
feat: simplify phone pairing onboarding
milind-soni Aug 26, 2026
1ea2f86
fix: harden phone setup states
milind-soni Aug 26, 2026
0ca043d
fix: authorize native companion sign-in
milind-soni Aug 26, 2026
0f3a769
fix: rebase phone pairing device baseline
milind-soni Aug 26, 2026
409f559
fix: honor direct Wi-Fi pairing route
milind-soni Aug 26, 2026
dfdb5ef
feat: surface phone status in sidebar
milind-soni Aug 26, 2026
bb39c03
fix: harden phone pairing and live status
milind-soni Aug 26, 2026
4d2ecfb
fix: harden secure phone pairing attempts
milind-soni Aug 26, 2026
4b7c1f9
fix: harden phone connection lifecycle
milind-soni Aug 26, 2026
9a9f4ff
fix: commit phone pairing callback safely
milind-soni Aug 26, 2026
6a03b4c
Merge pull request #487 from milind-soni/codex/phone-onboarding-ui
milind-soni Aug 26, 2026
87d87f8
feat(ios): simplify companion onboarding and settings
milind-soni Aug 26, 2026
fdf65f6
fix(ios): align phone setup routing and copy
milind-soni Aug 26, 2026
4cd81d0
docs(ios): clarify QR pairing routes
milind-soni Aug 26, 2026
030ebb6
fix(ios): harden companion onboarding flow
milind-soni Aug 26, 2026
ba0e417
Merge pull request #488 from milind-soni/codex/ios-onboarding-pass
milind-soni Aug 26, 2026
598fb88
chore(release): bump version to 0.1.36
milind-soni Aug 26, 2026
13691e7
Merge pull request #489 from milind-soni/codex/bump-0.1.36
milind-soni Aug 26, 2026
cbc1ac1
docs: point downloads at v0.1.36
milind-soni Aug 26, 2026
40e0638
Merge pull request #490 from milind-soni/codex/readme-0.1.36
milind-soni Aug 26, 2026
f0b52f9
fix(phone): keep automatic pairing on HTTPS
milind-soni Aug 26, 2026
fa35224
Merge pull request #491 from milind-soni/codex/https-only-phone-pairing
milind-soni Aug 26, 2026
6f34534
chore(release): bump version to 0.1.37
milind-soni Aug 26, 2026
1ce74c4
Merge pull request #492 from milind-soni/codex/release-0.1.37
milind-soni Aug 26, 2026
ba23cd5
docs: update downloads for 0.1.37
milind-soni Aug 26, 2026
9e61a33
fix: remove redundant ready to pair status
milind-soni Aug 26, 2026
1f6f25d
fix: stage companion connector for desktop development
milind-soni Aug 26, 2026
d0e5592
Merge pull request #493 from milind-soni/codex/remove-ready-to-pair-pill
milind-soni Aug 26, 2026
4d50d57
Merge pull request #494 from milind-soni/codex/readme-0.1.37
milind-soni Aug 26, 2026
667af71
Merge pull request #495 from milind-soni/codex/stage-cloudflared-for-dev
milind-soni Aug 26, 2026
94d9d10
fix(desktop): stop the recorder helper during the Accessibility prompt
santhiprakash Aug 26, 2026
5e5c652
fix(ios): cancel the linger sleeper when the companion reconnects
santhiprakash Aug 26, 2026
ea636fe
fix(ios): keep a protected companion route first after restart
santhiprakash Aug 26, 2026
544d7b2
fix(composio): answer MCP initialize locally so OpenCode can mount tools
santhiprakash Aug 26, 2026
7c8d35f
fix(chat): keep jump-to-latest control stationary
08820048 Aug 26, 2026
cfa9c82
fix(connectors): bound MCP initialize handshake
lightcloud00 Aug 26, 2026
21d36fa
feat(claude): scope built-in tools per instance
lightcloud00 Aug 26, 2026
77447bd
Merge upstream main and document dual VM setup
lightcloud00 Aug 26, 2026
bd277ba
fix: give the packaged server a wall-clock boot budget instead of kil…
santhiprakash Aug 26, 2026
cd13a1b
docs(local-vm): add Windows capacity preflight
lightcloud00 Aug 26, 2026
964fe58
fix: bound health probes by the boot deadline and report port conflicts
santhiprakash Aug 26, 2026
76e2d3d
docs(local-vm): link multi-host Windows tracking
lightcloud00 Aug 26, 2026
38041de
fix(settings): keep long setup commands inside the Local VM panel
Maksim-Burtsev Aug 26, 2026
c931ed2
docs: add OUR-DELTA.md documenting fork changes vs upstream
cursoragent Aug 26, 2026
8f540cf
fix(pi): register approval asks before auto-approval
Aug 25, 2026
1f6ab4e
docs: add skeptical review of fork UI and architecture (review-only)
cursoragent Aug 26, 2026
3207332
docs: fold exploration corrections into skeptical review (action coun…
cursoragent Aug 26, 2026
dc31935
fix: read the server child pid at response time so the boot probe can…
santhiprakash Aug 27, 2026
e5fcd8b
fix(ios): hoist the protected active route only above cleartext heads
santhiprakash Aug 27, 2026
1426206
fix(openai-compat): fall back to reasoning text in streaming turns wh…
ericmaddox Aug 27, 2026
514c6c6
feat(mcp): add Model Context Protocol server for external agent orche…
ericmaddox Aug 27, 2026
280921e
fix(mcp): clamp message limits, encode URL parameters, and map room b…
ericmaddox Aug 27, 2026
36e9119
fix(pi): harden MCP extension schema conversion and tool lifecycle
Aug 27, 2026
1c70075
fix(ios): read the two fields the server already sends
KesleyDavid Aug 27, 2026
562e351
Merge pull request #502 from 08820048/codex/fix-jump-to-latest-jitter
milind-soni Aug 27, 2026
cc99579
Merge pull request #512 from cjpraia/fix/pi-always-allow-race
milind-soni Aug 27, 2026
ec86c41
Merge pull request #515 from ericmaddox/fix/openai-compat-reasoning-f…
milind-soni Aug 27, 2026
e5b5c4f
Merge pull request #511 from Maksim-Burtsev/fix/local-vm-setup-step-o…
milind-soni Aug 27, 2026
d19a81e
fix(recorder): hand stop polling to the active session
milind-soni Aug 27, 2026
ac45596
Merge pull request #514 from lightcloud00/codex/claude-tool-scope-ups…
milind-soni Aug 27, 2026
0edd988
fix(updater): classify deadline-aborted health bodies as timeouts
milind-soni Aug 27, 2026
10ddae1
fix(recorder): synchronize stop watcher handoff
milind-soni Aug 27, 2026
746350d
Merge pull request #507 from santhiprakash/fix/server-boot-window
milind-soni Aug 27, 2026
aa0dc5e
Merge pull request #501 from santhiprakash/fix/composio-mcp-initializ…
milind-soni Aug 27, 2026
c83f75b
Merge pull request #498 from santhiprakash/fix/recorder-stop-before-a…
milind-soni Aug 27, 2026
78b8509
Merge pull request #518 from cjpraia/fix/pi-mcp-schema-and-lifecycle
milind-soni Aug 27, 2026
9b408cd
Merge pull request #520 from KesleyDavid/KesleyDavid/ios-server-fields
milind-soni Aug 27, 2026
48f8749
fix(ios): handle refused linger background tasks
milind-soni Aug 27, 2026
7e1eaa1
fix(ios): filter route policy before trust ordering
milind-soni Aug 27, 2026
36e62ea
Merge pull request #499 from santhiprakash/fix/ios-cancel-stale-linge…
milind-soni Aug 27, 2026
6951c40
Merge pull request #500 from santhiprakash/fix/ios-trust-ratchet-surv…
milind-soni Aug 27, 2026
43fb133
fix(redact): content-redact ACP env entries whose name is not secret-…
santhiprakash Aug 27, 2026
007b724
fix(routines): preserve original scheduled time for past once routines
santhiprakash Aug 27, 2026
84c5c2a
fix(webhooks): paint the Terminal card with skin tokens, not a fixed …
Maksim-Burtsev Aug 27, 2026
d5314f8
feat(chat): mascot presence, full-width composer, opt-in tool chips
Aug 27, 2026
081feb9
feat(pi): inject live local models into Custom
Aug 27, 2026
3d820ca
feat(chat): show Working sheen beside the waiting mascot
Aug 27, 2026
bfd6fba
Merge pull request #521 from santhiprakash/fix/redact-acp-env-content…
milind-soni Aug 27, 2026
6086b94
Merge pull request #522 from santhiprakash/fix/routine-once-past-time…
milind-soni Aug 27, 2026
c0d5e0e
Merge pull request #523 from Maksim-Burtsev/fix/webhook-terminal-card…
milind-soni Aug 27, 2026
d0db158
fix(pi): avoid credential temp files before model setup
milind-soni Aug 27, 2026
d8bf8a9
Merge pull request #525 from maxkongerskov/maxkongerskov/pi-local-inject
milind-soni Aug 27, 2026
984d6c3
fix(usage): name the cached share of a turn's tokens so "100k for 5 m…
milind-soni Aug 27, 2026
59702d8
fix(composio): use a project's own auth configs so no-managed-auth to…
milind-soni Aug 27, 2026
2b1c0a2
fix(win): recolor the caption-button overlay to the active skin so no…
milind-soni Aug 27, 2026
43d1443
fix(chat): surface live agent activity
milind-soni Aug 27, 2026
f0bd967
Merge pull request #524 from maxkongerskov/maxkongerskov/chat-presence
milind-soni Aug 27, 2026
d3813b1
fix(win): synchronize skin before showing window
milind-soni Aug 27, 2026
00f7b76
fix(composio): preserve session identity during auth retry
milind-soni Aug 27, 2026
312db32
fix(usage): preserve unknown cache data and clamp totals
milind-soni Aug 27, 2026
0293b2c
Merge pull request #530 from milind-soni/fix/win-titlebar-overlay-skin
milind-soni Aug 27, 2026
f4069a1
Merge pull request #529 from milind-soni/fix/composio-custom-auth-con…
milind-soni Aug 27, 2026
ec7b487
Merge pull request #528 from milind-soni/fix/usage-cached-tokens
milind-soni Aug 27, 2026
a7a4e4f
fix(onboarding): use the success and warning tokens for status badges
Maksim-Burtsev Aug 27, 2026
5fcc3ce
fix(mcp): suppress notification output, validate payloads, and drain …
ericmaddox Aug 27, 2026
478764a
fix(mcp): refine async request drain cleanup
ericmaddox Aug 27, 2026
1edb576
fix(tasks): let the header picker actually rename
Aug 27, 2026
8fd706b
fix: enforce jsonrpc 2.0 envelope and use spec-compliant version nego…
ericmaddox Aug 27, 2026
8272bed
fix: validate message.id accepting string or number and reject invali…
ericmaddox Aug 27, 2026
0d0d2da
fix(tasks): show the rename pencil on keyboard focus
maxkongerskov Aug 27, 2026
4d06d98
fix: enforce URL security, request timeout, and null ID on invalid js…
ericmaddox Aug 27, 2026
743ce8e
Merge pull request #535 from Maksim-Burtsev/fix/onboarding-status-ski…
milind-soni Aug 28, 2026
4942da1
Merge pull request #536 from maxkongerskov/fix/task-picker-rename
milind-soni Aug 28, 2026
6f06f2b
fix(local-vm): bound hidden-window layout wait
milind-soni Aug 28, 2026
831bbac
Merge pull request #365 from lightcloud00/codex/chief-dual-vm-20260822
milind-soni Aug 28, 2026
1777061
feat(channels): add separate task conversations
milind-soni Aug 28, 2026
9e0b1dd
Merge pull request #537 from milind-soni/codex/channel-tasks
milind-soni Aug 28, 2026
62eb35d
Merge remote-tracking branch 'origin/main' into codex/pr517-review
milind-soni Aug 28, 2026
e7f4441
feat: review routine approvals safely
milind-soni Aug 28, 2026
bd57e09
fix: fail closed on review orchestration errors
milind-soni Aug 28, 2026
84140ba
Merge pull request #468 from milind-soni/feat/parity-round-3
milind-soni Aug 28, 2026
f39852d
feat(mcp): harden and expand orchestration server
milind-soni Aug 28, 2026
a4e0928
Merge remote-tracking branch 'origin/main' into codex/pr517-review
milind-soni Aug 28, 2026
6b1e8b0
fix(mcp): harden orchestration edge cases
milind-soni Aug 28, 2026
25a0521
Merge pull request #517 from ericmaddox/feat/mcp-server
milind-soni Aug 28, 2026
55ea6cf
feat(routines): create and manage routines from chat (#540)
milind-soni Aug 28, 2026
7983055
chore(release): bump version to 0.1.38 (#541)
milind-soni Aug 28, 2026
875fac4
fix(routines): survive provider schema-mangling — flat schedule schem…
milind-soni Aug 28, 2026
8281325
feat(chat): dock the composer over the transcript (#545)
maxkongerskov Aug 28, 2026
952a1a9
fix(win): keep caption controls outside app content (#543)
rahul-vanyar Aug 28, 2026
5bd79bc
fix(harness): report event log write failures (#542)
rahul-vanyar Aug 28, 2026
677538e
docs(contributing): MCP tool schemas must stay flat — provider conver…
milind-soni Aug 28, 2026
8da917f
Merge remote-tracking branch 'upstream/main' into cursor/sync-upstrea…
cursoragent Aug 28, 2026
c0aa94d
docs: record 2026-08-28 upstream sync in OUR-DELTA.md
cursoragent Aug 28, 2026
76e4d92
Merge branch 'cursor/sync-upstream-9dfe' into cursor/skeptical-review…
cursoragent Aug 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 2 additions & 0 deletions .github/FUNDING.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
polar: supamaus
custom: ["https://buy.polar.sh/polar_cl_EEzWmormSVBD151HkmkyId9j0GPXina0KurfS1fYYcO"]
53 changes: 42 additions & 11 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,24 @@ jobs:
if: matrix.os == 'ubuntu-latest'
run: pnpm exec vite build

control-plane:
name: control-plane check + workerd tests + dry run
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: pnpm/action-setup@ff378ebe6b225b0680b81c1ad4498ae0d1d3a5e3 # v6.0.10
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm control-plane:check
- run: pnpm control-plane:test
- run: pnpm control-plane:dry-run

package-linux:
name: package + smoke (Ubuntu 24.04 x64)
runs-on: ubuntu-24.04
Expand All @@ -55,13 +73,30 @@ jobs:
- name: Install package validation and native smoke tools
run: >-
sudo apt-get update && sudo apt-get install -y
at-spi2-core dbus-x11 desktop-file-utils libxi6 libxkbcommon0 squashfs-tools xvfb
at-spi2-core dbus-x11 desktop-file-utils libxi6 libxkbcommon0 squashfs-tools x11-utils xdotool xvfb
- run: pnpm install --frozen-lockfile
- name: Stage the pinned CUA runtime
run: pnpm build:cua:linux
- name: Prove overlay-free X11 input routing
run: dbus-run-session -- xvfb-run -a pnpm smoke:cua-x11-input
- name: Package from the verified offline CUA stage
run: pnpm package:linux:offline
- run: node scripts/verify-linux-package.mjs
- name: Match a normal Ubuntu package parent on the ephemeral runner
run: |
test ! -L /opt
test "$(stat -c '%F %U:%G' /opt)" = "directory root:root"
case "$(stat -c '%a' /opt)" in
755) ;;
775|777) sudo chmod 0755 /opt ;;
*) echo "Unexpected /opt mode: $(stat -c '%a' /opt)" >&2; exit 1 ;;
esac
test "$(stat -c '%U:%G %a' /opt)" = "root:root 755"
- name: Reproduce and verify an in-place DEB upgrade
run: |
deb=(release/*.deb)
test "${#deb[@]}" -eq 1
sudo --preserve-env=CI,RUNNER_TEMP node scripts/smoke-deb-upgrade.mjs "${deb[0]}"
- name: Configure Chromium sandbox for the unpacked app
run: |
sudo chown root:root release/linux-unpacked/chrome-sandbox
Expand All @@ -70,26 +105,22 @@ jobs:
- name: Launch packaged app and verify lifecycle
env:
OMB_KEEP_SMOKE_DIR: "1"
OMB_SMOKE_INSTALLED_DEB: "1"
run: pnpm smoke:linux-package
- name: Remove the installed upgrade fixture
if: always()
run: sudo dpkg --purge openmausbot || true
- name: Upload smoke diagnostics on failure
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: failure()
with:
name: openmausbot-ubuntu-smoke-diagnostics
path: |
${{ runner.temp }}/omb-linux-smoke-*
${{ runner.temp }}/omb-linux-smoke-runtime-*
/tmp/omb-linux-smoke-*
/tmp/omb-linux-smoke-runtime-*
if-no-files-found: warn
include-hidden-files: true
retention-days: 7
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: always()
with:
name: openmausbot-ubuntu-x64
path: |
release/*.deb
release/*.AppImage
if-no-files-found: error

ios:
name: Swift tests + iOS build
Expand Down
27 changes: 24 additions & 3 deletions .github/workflows/package-linux.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,16 +36,33 @@ jobs:
- name: Install package validation and native smoke tools
run: >-
sudo apt-get update && sudo apt-get install -y
at-spi2-core dbus-x11 desktop-file-utils libxi6 libxkbcommon0 squashfs-tools xvfb
at-spi2-core dbus-x11 desktop-file-utils libxi6 libxkbcommon0 squashfs-tools x11-utils xdotool xvfb
- run: pnpm install --frozen-lockfile
- name: Clean generated output
run: pnpm clean
- name: Stage the pinned CUA runtime
run: pnpm build:cua:linux
- name: Prove overlay-free X11 input routing
run: dbus-run-session -- xvfb-run -a pnpm smoke:cua-x11-input
- name: Package from the verified offline CUA stage
run: pnpm package:linux:offline
- name: Verify package contents and metadata
run: node scripts/verify-linux-package.mjs
- name: Match a normal Ubuntu package parent on the ephemeral runner
run: |
test ! -L /opt
test "$(stat -c '%F %U:%G' /opt)" = "directory root:root"
case "$(stat -c '%a' /opt)" in
755) ;;
775|777) sudo chmod 0755 /opt ;;
*) echo "Unexpected /opt mode: $(stat -c '%a' /opt)" >&2; exit 1 ;;
esac
test "$(stat -c '%U:%G %a' /opt)" = "root:root 755"
- name: Reproduce and verify an in-place DEB upgrade
run: |
deb=(release/*.deb)
test "${#deb[@]}" -eq 1
sudo --preserve-env=CI,RUNNER_TEMP node scripts/smoke-deb-upgrade.mjs "${deb[0]}"
- name: Configure Chromium sandbox for the unpacked app
run: |
sudo chown root:root release/linux-unpacked/chrome-sandbox
Expand All @@ -54,7 +71,11 @@ jobs:
- name: Launch packaged app and verify lifecycle
env:
OMB_KEEP_SMOKE_DIR: "1"
OMB_SMOKE_INSTALLED_DEB: "1"
run: pnpm smoke:linux-package
- name: Remove the installed upgrade fixture
if: always()
run: sudo dpkg --purge openmausbot || true
- name: Prepare release assets
id: release
shell: bash
Expand Down Expand Up @@ -86,8 +107,8 @@ jobs:
with:
name: openmausbot-ubuntu-smoke-diagnostics
path: |
${{ runner.temp }}/omb-linux-smoke-*
${{ runner.temp }}/omb-linux-smoke-runtime-*
/tmp/omb-linux-smoke-*
/tmp/omb-linux-smoke-runtime-*
if-no-files-found: warn
include-hidden-files: true
retention-days: 7
Expand Down
14 changes: 14 additions & 0 deletions .github/workflows/package-win.yml
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,20 @@ jobs:
[ -f "$res/server/index.js" ] || { echo "::error::missing $res/server/index.js"; fail=1; }
# missing → the server has nothing to serve → black window
[ -f "$res/ui/index.html" ] || { echo "::error::missing $res/ui/index.html"; fail=1; }
[ -f "$res/cloudflared/cloudflared.exe" ] || {
echo "::error::missing $res/cloudflared/cloudflared.exe"; fail=1; }
[ -f "$res/licenses/cloudflared-LICENSE.txt" ] || {
echo "::error::missing cloudflared Apache 2.0 license"; fail=1; }
[ -f "$res/licenses/cloudflared-README.md" ] || {
echo "::error::missing cloudflared release provenance"; fail=1; }
if [ -f "$res/cloudflared/cloudflared.exe" ]; then
expected=c29eee2b121f5436a642eed69fd9767da7e7b8c510fa50aaa130337f931357b5
actual=$(sha256sum "$res/cloudflared/cloudflared.exe" | cut -d' ' -f1)
[ "$actual" = "$expected" ] || {
echo "::error::packaged cloudflared hash is $actual"; fail=1; }
"$res/cloudflared/cloudflared.exe" version | grep -Fq "cloudflared version 2026.8.2 " || {
echo "::error::packaged cloudflared has the wrong version"; fail=1; }
fi
[ -f "$res/app-update.yml" ] || { echo "::error::missing $res/app-update.yml"; fail=1; }
if [ -f "$res/app-update.yml" ]; then
grep -q "openmausbot-releases" "$res/app-update.yml" || {
Expand Down
53 changes: 52 additions & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -106,6 +106,17 @@ jobs:
run: |
for app in release/mac-arm64/OpenMausBot.app release/mac/OpenMausBot.app; do
codesign --verify --deep --strict "$app"
bin="$app/Contents/Resources/cloudflared/cloudflared"
test -x "$bin" || { echo "::error::missing executable $bin"; exit 1; }
test -f "$app/Contents/Resources/licenses/cloudflared-LICENSE.txt" \
|| { echo "::error::missing cloudflared license in $app"; exit 1; }
test -f "$app/Contents/Resources/licenses/cloudflared-README.md" \
|| { echo "::error::missing cloudflared provenance in $app"; exit 1; }
codesign --verify --strict "$bin"
app_team=$(codesign -dv --verbose=4 "$app" 2>&1 | sed -n 's/^TeamIdentifier=//p')
bin_team=$(codesign -dv --verbose=4 "$bin" 2>&1 | sed -n 's/^TeamIdentifier=//p')
test -n "$app_team" && test "$bin_team" = "$app_team" || {
echo "::error::cloudflared is not signed by the app's Developer ID team in $app"; exit 1; }
echo "ok: $app"
done

Expand Down Expand Up @@ -133,6 +144,15 @@ jobs:
lipo -archs "$bin" | grep -q "x86_64" || { echo "::error::$bin lacks x86_64"; exit 1; }
lipo -archs "$bin" | grep -q "arm64" || { echo "::error::$bin lacks arm64"; exit 1; }
done
cloudflared="$res/cloudflared/cloudflared"
expected_arch=x86_64
case "$app" in *mac-arm64*) expected_arch=arm64 ;; esac
test "$(lipo -archs "$cloudflared")" = "$expected_arch" || {
echo "::error::$cloudflared is not the expected $expected_arch executable"; exit 1; }
if [ "$(uname -m)" = "$expected_arch" ]; then
"$cloudflared" version | grep -Fq "cloudflared version 2026.8.2 " || {
echo "::error::$cloudflared has the wrong version"; exit 1; }
fi
done

- name: Notarize all four artifacts
Expand Down Expand Up @@ -213,6 +233,14 @@ jobs:
res=release/win-unpacked/resources
[ -f "$res/server/index.js" ] || { echo "::error::missing server/index.js"; exit 1; }
[ -f "$res/ui/index.html" ] || { echo "::error::missing ui/index.html"; exit 1; }
[ -f "$res/cloudflared/cloudflared.exe" ] || { echo "::error::missing cloudflared.exe"; exit 1; }
[ -f "$res/licenses/cloudflared-LICENSE.txt" ] || { echo "::error::missing cloudflared license"; exit 1; }
[ -f "$res/licenses/cloudflared-README.md" ] || { echo "::error::missing cloudflared provenance"; exit 1; }
expected=c29eee2b121f5436a642eed69fd9767da7e7b8c510fa50aaa130337f931357b5
actual=$(sha256sum "$res/cloudflared/cloudflared.exe" | cut -d' ' -f1)
[ "$actual" = "$expected" ] || { echo "::error::cloudflared hash is $actual"; exit 1; }
"$res/cloudflared/cloudflared.exe" version | grep -Fq "cloudflared version 2026.8.2 " || {
echo "::error::cloudflared has the wrong version"; exit 1; }
[ -f "$res/app-update.yml" ] || { echo "::error::missing app-update.yml"; exit 1; }
grep -q "openmausbot-releases" "$res/app-update.yml" || { echo "::error::wrong update repo"; exit 1; }
if grep -q "publisherName" "$res/app-update.yml"; then
Expand Down Expand Up @@ -262,13 +290,32 @@ jobs:
- name: Install package validation and native smoke tools
run: >-
sudo apt-get update && sudo apt-get install -y
at-spi2-core dbus-x11 desktop-file-utils libxi6 libxkbcommon0 squashfs-tools xvfb
at-spi2-core dbus-x11 desktop-file-utils libxi6 libxkbcommon0 squashfs-tools x11-utils xdotool xvfb
- run: pnpm install --frozen-lockfile
- name: Clean generated output
run: pnpm clean
- name: Stage the pinned CUA runtime
run: pnpm build:cua:linux
- name: Prove overlay-free X11 input routing
run: dbus-run-session -- xvfb-run -a pnpm smoke:cua-x11-input
- run: pnpm package:linux
- name: Verify package contents and metadata
run: node scripts/verify-linux-package.mjs
- name: Match a normal Ubuntu package parent on the ephemeral runner
run: |
test ! -L /opt
test "$(stat -c '%F %U:%G' /opt)" = "directory root:root"
case "$(stat -c '%a' /opt)" in
755) ;;
775|777) sudo chmod 0755 /opt ;;
*) echo "Unexpected /opt mode: $(stat -c '%a' /opt)" >&2; exit 1 ;;
esac
test "$(stat -c '%U:%G %a' /opt)" = "root:root 755"
- name: Reproduce and verify an in-place DEB upgrade
run: |
deb=(release/*.deb)
test "${#deb[@]}" -eq 1
sudo --preserve-env=CI,RUNNER_TEMP node scripts/smoke-deb-upgrade.mjs "${deb[0]}"
- name: Configure Chromium sandbox for the unpacked app
run: |
sudo chown root:root release/linux-unpacked/chrome-sandbox
Expand All @@ -277,7 +324,11 @@ jobs:
- name: Smoke the packages
env:
OMB_KEEP_SMOKE_DIR: "1"
OMB_SMOKE_INSTALLED_DEB: "1"
run: pnpm smoke:linux-package
- name: Remove the installed upgrade fixture
if: always()
run: sudo dpkg --purge openmausbot || true
- name: Stable-named copies and checksums
run: |
v=$(node -p "require('./package.json').version")
Expand Down
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,9 @@ release
.wrangler/
.dev.vars
.dev.vars.*
!cloudflare/control-plane/.dev.vars.example
cloudflare/composio-broker/worker-configuration.d.ts
cloudflare/control-plane/worker-configuration.d.ts
.claude/worktrees/
.vercel/
.pi/
38 changes: 35 additions & 3 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,13 +39,21 @@ pnpm package:mac # DMG + ZIP; requires Swift/Xcode tools
pnpm package:linux # Ubuntu x64 .deb + AppImage; no Swift required
```

`pnpm dev:desktop` downloads and verifies the pinned Cloudflare Tunnel connector for the current
platform and architecture before Electron starts. Later launches re-verify and reuse the staged
binary. Packaging continues to use `pnpm build:cloudflared`, which stages every architecture the
host's desktop package build requires. To stage only the current development target without
launching Electron, run `node scripts/prepare-cloudflared.mjs --current`.

For Ubuntu installation and real desktop checks, see [`docs/linux-desktop.md`](docs/linux-desktop.md).

## Ubuntu release checklist

Ubuntu release packages must come from the manual **Package Ubuntu** workflow on an exact release commit or tag,
not from a developer workstation. The Ubuntu 24.04 runner builds and verifies both formats, launches the unpacked
app and AppImage, exercises the bundled Cua lifecycle, and produces one release artifact containing:
app and AppImage, routes `click` and `type_text` through the overlay-free bundled Cua runtime on Xorg, runs the
fail-closed Wayland CUA smoke,
and produces one release artifact containing:

- the versioned `.deb` and AppImage;
- stable `OpenMausBot-amd64.deb` and `OpenMausBot.AppImage` copies used by the latest-download links;
Expand Down Expand Up @@ -110,6 +118,24 @@ The SPI in [`server/contracts.ts`](server/contracts.ts) is deliberately small. A
failed spawn as a failed turn — never a hang, never a crash.
5. Bring a contract test following the fake-CLI pattern (scripted fake process + `recordEvents`).

## MCP tool schemas

Tool `inputSchema`s travel through every engine's own MCP-to-provider conversion before a model
sees them, and those converters are lossy: composition keywords get flattened, dropped, or pruned
by size-compaction passes (codex only began preserving `oneOf` in mid-2026; others simplify
harder). A model that never saw your schema's branches guesses shapes forever — that is exactly
how chat routine proposals failed in the field hours after 0.1.38 shipped (#544).

- **Never use `oneOf`, `anyOf`, `allOf`, `const`, or `format` in a tool `inputSchema`.** Advertise
one flat object; put per-variant rules in `description`s. `enum` on plain strings is fine.
- **Coerce before you reject.** Models stringify nested objects, shorten enum values, and vary
case. If an input has one obvious meaning, accept it and normalize on the wire.
- **Errors must teach.** When you refuse an input, the message states the supported shapes with a
literal example the model can copy. "Invalid discriminator value" burns a turn; an example
fixes the next call.
- A schema test should assert the tool surface stays flat
(see `server/drivers/agents-proxy.test.ts` — it regexp-guards the serialized schema).

## Platform rules

- The harness (`server/`) must stay portable Node. Anything macOS-only (TCC, Swift helpers,
Expand All @@ -119,8 +145,14 @@ The SPI in [`server/contracts.ts`](server/contracts.ts) is deliberately small. A
independent capabilities.
- Test Ubuntu platform claims on a real GNOME session. Xvfb proves packaging and fake-driver orchestration, not
Wayland portal behavior or real CUA inspection/input delivery.
- Linux local control must remain explicit: global opt-in plus per-bot **This computer**. Linux Auto, provider
full-auto/bypass modes, remembered grants, and cloud approvals must never authorize the user's desktop.
- Linux local control is enabled only on GNOME/Xorg after explicit opt-in. The owned daemon must start with
`--no-overlay`: the decorative full-screen Cua cursor surface is not part of the product contract and must never
sit between the person and their desktop. GNOME/Wayland must clear a legacy durable opt-in, report
`linux-wayland-seat-safety-blocked`, and never start Cua until it independently passes the real-seat matrix in
#345. Xvfb proves the overlay-free arguments, lifecycle, and input routing; it does not waive real-seat evidence.
An unrelated app must remain clickable/typeable before any approved action. Global opt-in plus per-bot
**This computer** remains mandatory; Linux Auto, full-auto/bypass modes, remembered grants, and cloud approvals
must never authorize the user's desktop.
- Keep CUA discovery shell-free and pin accepted archive, inner-file, manifest, and driver contracts. Packaged Linux
builds must prefer their reviewed outside-ASAR runtime and fail closed instead of executing ambient PATH code;
source/dev builds may use the validated explicit/user-local paths. Never add a runtime downloader/self-updater or
Expand Down
Loading
Loading