# Changelog

## 0.13.9 - 2026-09-25

### Fixed

- Read Claude Code `2.1.282`'s native `/status` panel when it includes the `Auto mode server` row or a bounded `System diagnostics` section. Diagnostic prose is excluded from returned status fields and excerpts.

### Security

- Keep Codex `0.157.0` and Claude Code `2.1.282` on unverified runtime profiles without granting version-bound model-control or questionnaire actions. Claude native status still requires exact session, workspace, and fresh-screen evidence and rejects unprofiled fields or diagnostics.

## 0.13.8 - 2026-09-21

### Added

- Add typed Codex `0.154.0` and `0.155.1` support for running `request_user_input_async` questions across managed Monitor and exact Terminal Watch, while the coding task remains working.
- Project single-select and bounded free-text steps through the existing semantic interaction contract, with explicit `steer_current_turn` and `queue_next_turn` delivery modes and no public raw-key or menu-index surface.

### Fixed

- Recognize the exact styled GPT-6 Astra animated empty Composer during managed Send, including the candidate-acceptance path that previously dropped the running Codex version and unnecessarily downgraded delivery to an unmanaged Watch.
- Keep Host-profile callback notifications pending for their matching runtime instead of allowing an unrelated background worker to claim and permanently fail them.
- Treat only the independently parsed countdown repaint digest as non-semantic when reopening the same collapsed asynchronous question; question, task, terminal, pending-count, and key-binding drift still reject before input.

### Security

- Bind every asynchronous answer to the exact terminal incarnation, native task, current question, semantic option, callback owner, and versioned TUI profile. Unknown or clipped surfaces, competing responders, state drift, and uncertain input remain fail-closed and are never retried automatically.

## 0.13.7 - 2026-09-20

### Added

- Add exact Codex CLI `0.155.1` lifecycle, native `/status`, transition-settlement, blocking questionnaire, and typed model-control profiles based on the installed client and official tagged source.
- Recognize the native user-verification surface as an input-owning, non-approvable prompt that requires direct user handling.

### Fixed

- Recognize Codex `0.155.1`'s exact styled `/model` completion surface without relying on the viewport-wide background paint used by `0.154.0`, so typed model discovery can open, parse, and safely dismiss the native picker.
- Resolve the native model catalog from the exact running profiled Codex executable, while retaining complete `0.154.0` compatibility and rejecting adjacent unverified versions.

### Security

- Bind the new footerless model-control surface to the exact `0.155.1` profile and exact terminal styles. Plain transcript lookalikes, missing or displaced styles, unknown rows, active approvals or questionnaires, and terminal/process drift remain zero-input failures; any post-input uncertainty remains non-retryable.

## 0.13.6 - 2026-09-20

### Changed

- Extend the advertised `terminal_user_explicit` `replace_current_composer_and_submit` policy to Claude Code. After the live input-safety checks pass, Claude Code uses a sentinel-backed native `C-s` stash-clear transaction that is independent of the cursor position and does not interrupt an active turn, proves the main Composer empty, then injects the new request, waits through the paste window, and dispatches Enter exactly once. An existing draft, parsed working activity, or ordinary Composer visibility, stability, or exactness does not veto the human's explicit Send.
- Advance the structured List action contract to v29 with the agent-neutral `terminal_user_explicit_composer_policy`; retain `codex_terminal_user_explicit_composer_policy` as a v28 compatibility alias.

### Security

- Preserve zero-input, fail-closed boundaries for blocked approvals, input-owning questionnaires, editors or menus, read-only viewers, and terminal/process drift. Once Claude Code clear or request input may have occurred, an uncertain outcome is never retried automatically.
- Return structured `submission_uncertain` and `do_not_retry` evidence through Host tools after any possible replacement input, and retain the durable message intent so the same request cannot be replayed blindly.

## 0.13.5 - 2026-09-17

### Fixed

- Recognize Codex 0.154.0 GPT-6 Astra's animated Braille sparkle empty-Composer frame as diagnostic idle when the exact placeholder and a complete supported footer remain visible.
- Reuse the same observed coding-agent version for terminal status parsing and List capability projection, preventing versionless screen-classification drift.

### Security

- Keep animated idle classification separate from exact empty-Composer authority. Unsupported versions, unknown glyphs, clipped or changed footers, real drafts, working, approval, questionnaire, and model-picker surfaces remain fail-closed; native lifecycle, new-thread, and model-control actions still require independent exact-Composer proof.

## 0.13.4 - 2026-09-15

### Changed

- Make typed model control use one shared source of truth for native profile support, terminal subject normalization, input-owning surface classification, action availability, private authority, and transaction phase. List and execution now make the same fail-closed decision for ordinary, residual-continuation, and repair flows.
- Run managed Monitor and Terminal Watch questionnaire responses through the same reservation, live-revalidation, dispatch, settlement, and `response_uncertain` transaction semantics while preserving their distinct ownership and task-completion models.
- Keep OpenClaw, Pi, and DeepSeek Harness integrations aligned through one Host-neutral 22-tool semantic catalog, one canonical bundled Skill, a versioned capability handshake, and shared connector package verification.
- Restructure terminal discovery into immutable facts, centralized action policy, and compact public projection. Split terminal Send, approval, retry, native inspection, model control, Watch storage, callback routing, and Herdr transport into focused modules behind compatibility facades.
- Add typed model-control UI goldens, an in-process List-to-catalog-to-set-model contract, architecture-health ratchets, focused contract suites, and separate current-architecture and historical design records.

### Security

- Preserve exact pane, process-birth, cwd, agent, version, mutation-lock, and durable pre-input reservation checks across the new module boundaries. Private authority remains isolated, historical Store formats remain readable, and any possible input with an unproven postcondition remains non-retryable.

## 0.13.3 - 2026-09-14

### Added

- Add typed, catalog-bound model control for supported idle Codex and Claude Code panes. Callers can inspect native model/reasoning choices, select only an advertised semantic tuple, and receive separate effective-current-session and future-session-default postconditions without exposing raw slash commands, keys, menu indexes, or private authority.
- Add a narrowly scoped Codex model-control repair action for an exactly recognized stale `/model` completion surface, bare Composer command, or native picker. The cleanup action never selects a model or submits work and must prove the main Composer empty before returning success.

### Changed

- Replace the structured List response's repeated action contract and verbose diagnostics with a compact terminal-first projection shared by OpenClaw, Pi, and DeepSeek Harness. It retains live resource identities, current state, action names, and dynamic semantic inputs; static action meanings and safety rules live in the bundled `agent-knock-knock` skill.
- Bundle that same canonical skill with the OpenClaw plugin and export one Host-neutral List projection contract so native controller connectors do not maintain separate field-pruning logic.

### Fixed

- Let exact, idle Codex `0.154.0` zero-rollout panes discover and change native model settings without first fabricating a Session identity, while preserving exact pane/process/cwd, empty-Composer, interaction, active-Turn, and postcondition checks.
- Recognize the standard and narrow Codex `Select Model and Effort` picker, including the nested `More reasoning…` flow, as a model-control surface instead of generic busy activity. List no longer advertises ordinary idle mutations while that picker owns input.
- Normalize terminal/process incarnation authority across List and typed model-control execution, preserve a safe continuation action for exact residual `/model` state, and keep uncertain input outcomes non-retryable.

### Security

- Revalidate the exact terminal, process birth, screen generation, native catalog, Composer/input-owning surface, and current action offer under one mutation lock. Approval, questionnaire, editor, viewer, active Turn, unknown content, and identity drift remain zero-input failures; any post-input uncertainty remains `do_not_retry`.

## 0.13.2 - 2026-09-12

### Added

- Add exact Codex CLI `0.154.0` lifecycle, native `/status`, transition-settlement, and legacy blocking `request_user_input` questionnaire profiles, backed by isolated tmux probes and the official tagged source and snapshots.

### Changed

- Keep human-priority Send available while Codex is working, showing ordinary queued messages, or presenting a collapsed asynchronous question summary. Refuse input before mutation when the asynchronous question editor is expanded, clipped, or otherwise owns terminal input.
- Recognize the Codex `0.154.0` active-writer resume viewer, including narrow layouts and remapped or disabled transcript shortcuts, so AKK never injects input into its read-only surface.
- Preserve legacy questionnaire settlement and bounded session excerpts around the new `retained_context` rollout record. Non-blocking `request_user_input_async` response automation remains explicitly unsupported until it has a separate lifecycle contract.

### Security

- Revalidate asynchronous-question input ownership both before and after the Send reservation. Expanded or ambiguous editors, approval surfaces, read-only viewers, and terminal identity drift remain zero-input failures; ordinary drafts and collapsed questions retain the explicit human Send guarantee.

## 0.13.1 - 2026-09-10

### Fixed

- Reconcile owner-released historical Turns without attempting obsolete native-identity recovery, while preserving active, stalled, malformed, ambiguous, and tampered records for explicit handling.
- Read and safely upgrade exact v1/early-v2 Terminal Watch callback presentations, and recognize an accepted historical completion receipt only when a newer terminal dispatch has strictly superseded its top-level ledger entry. The repaired Store now reconciles 222 Turns and scans 80 Watches with zero errors.
- Add exact lifecycle, native-status, and AskUserQuestion profiles for Claude Code `2.1.266` and `2.1.267`, including the optional `Organization policy` Status row introduced in `2.1.261`. The field is also accepted by the `2.1.263` profile and its value is always redacted.
- Keep Codex `0.153.4` as the latest exact regression-tested stable profile after reviewing the installed client and official release behavior; the newer `0.154.0` builds remain prereleases and are not promoted.

### Security

- Bind Claude questionnaire identities and prompt fingerprints to the exact client version, reject malformed or inherited version-registry keys, and send no terminal input when a saved interaction crosses a client-version change.
- Preserve Store repair idempotency and historical data: compatibility recovery requires exact receipts, process and path evidence, and never deletes valid active Sessions, Turns, or Watches.

## 0.13.0 - 2026-09-10

### Added

- Promote terminal-scoped Codex sends from a frozen open-rollout candidate set after exactly one rollout durably accepts the request, including the first task after `/clear` when the foreground rollout does not exist before Enter.
- Add explicit `identify_foreground` and atomic `identify_and_send` operations for safely resolving an ambiguous foreground Codex rollout without weakening ordinary human-priority Send.
- Notify the owning controller when an unmanaged fallback Watch observes a native questionnaire that requires manual TUI input, without granting that Watch response or key-dispatch authority.
- Let newly created exact Terminal Watches notify and answer supported native Codex and Claude Code questionnaires through the same owner-bound `respond_interaction` contract used by managed Turns. Activity/best-effort Watches and migrated legacy records remain notification-only.

### Changed

- Make human-explicit Send results distinguish physical terminal dispatch, native agent acceptance, managed ownership, and observation mode. Legacy delivery fields remain available as compatibility aliases during the 0.13 transition.
- Continue candidate acceptance across the frozen pre-send roots and the current root inventory, so a rollout whose original FD closes can still be proven by its unchanged path, device, inode, and byte boundary.

### Fixed

- Retry a short-lived duplicate Codex file descriptor for the same exact rollout only inside bounded post-send identity and acceptance polling, so native-thread creation can settle without stalling the managed Turn; conflicting identities remain immediately uncertain and no descriptor is selected while the overlap persists.
- Give human-explicit Send a bounded one-second Store/state lock grace while keeping terminal acquisition non-blocking, so brief monitor-supervision writer leases do not unnecessarily downgrade an otherwise manageable questionnaire to a notification-only Watch.
- Preserve the exact pre-send Codex rollout candidates as Turn-scoped monitor companions after one rollout accepts the request, so a still-open predecessor does not suppress questionnaire discovery or response authority after managed promotion.
- Transfer one unchanged detached Session claim to the provisional managed Session when its exact source-less Codex candidate accepts the new Send, so a closed prior Turn cannot stall the next questionnaire on the same native thread.
- Preserve managed Codex continuation after a released Turn leaves an obsolete completion callback pending or failed: an exact human-selected Send may fence only that unaccepted callback retry debt, then continue through the existing managed authority path with interaction response enabled.
- Pass the private managed binding token from OpenClaw's freshly reconciled terminal action into the CLI, and report managed-authority conflicts separately from genuinely stale physical terminal authority.
- Settle fallback Watches on their exact Codex `turn_aborted` record or invalidate them when a later native turn overtakes the accepted task, so an old Watch cannot repeatedly attribute new questionnaires to an abandoned Send.
- Attribute questionnaire notifications during multi-rollout ambiguity only when the accepted rollout contains the unique pending `request_user_input` whose step, prompt, and options match the live TUI; paired outputs, changed rollouts, duplicate signatures, and unreadable evidence remain silent.

### Security

- Keep physical target, process incarnation, composer/interaction, and duplicate-dispatch checks fail-closed while preventing rollout, Session, Store, or callback uncertainty from vetoing an explicitly selected human Send. Replaced, deleted, ambiguous, multiply accepting, or unreadable rollout evidence remains uncertain and is never replayed automatically.
- Bind detached-claim transfer to the frozen v3 acceptance anchor and CAS-fenced Session state. Claim drift, blocking work, ambiguous owners, or changed terminal/workspace authority remains post-dispatch uncertainty with no automatic resend.
- Limit callback-debt supersession to the exact released binding generation with a validated terminal, native thread, rollout, submission receipt, and final lifecycle message. Active interactions, approvals, transitions, in-flight callbacks, accepted transports, stale managed tokens, and cross-Turn evidence remain fail-closed; an explicitly overridden uncertain callback is retained as audit evidence and is never retried.
- Revalidate controller ownership, terminal/process/native-task identity, prompt surface, and responder priority immediately before Watch input. Managed Turns take precedence, while stale, reserved, uncertain, consumed, manual-only, or ambiguous interactions remain fail-closed without replay.

## 0.12.37 - 2026-09-08

### Fixed

- Derive a guarded Codex custom-text choice when `0.153.4` renders only its client-generated `None of the above` row. The derived action uses native Other's Accept-to-Notes path, while the native Other semantic choice keeps its distinct direct-submit behavior.
- Join Codex option-description continuations only when a narrow pane wraps them at the exact native description column without crossing a physical blank frame boundary, so final `enter to submit all` questions remain actionable without accepting ambiguous layouts.
- Treat an elapsed interaction projection timestamp as a mandatory live-recapture boundary instead of terminal-questionnaire death. OpenClaw and CLI responses proceed only when the same Turn, owner, terminal identity, prompt fingerprint, semantic projection, and action plan are proven again under lock.

### Security

- Keep the public expiry validator fail-closed by default and allow stale-shape validation only in internal dispatch paths that always perform exact live terminal recapture before reservation or input. Changed or missing prompts continue to send zero input.

## 0.12.36 - 2026-09-08

### Fixed

- Treat a guarded Codex `0.153.4` `Type something.` alias beside the exact native Other row as a two-step custom-answer flow: bounded cursor movement selects native Other and opens Notes without submitting the alias literally, then a fresh `free_text` interaction sends the user's text. Native Other itself remains directly selectable without Notes.

### Security

- Accept Codex custom text only from the exact empty `Add notes` editor and known footer, keeping changed Other rows, existing human drafts, unknown layouts, and uncertain multi-key delivery fail-closed.

## 0.12.35 - 2026-09-08

### Fixed

- Run OpenClaw plugin CLI relays asynchronously so `list --reconcile`, Send, Status, questionnaire responses, and callback-side approval work cannot freeze the Gateway event loop while a monitor reconnects.
- Propagate OpenClaw invocation cancellation through asynchronous relay work, and give Gateway callback, chat, session, and wait calls an explicit 25-second CLI deadline inside AKK's 30-second delivery watchdog.

### Changed

- Keep routine releases focused on the build-pinned OpenClaw version. The slower minimum-host and Plugin API boundary matrix remains available through `npm run compat:openclaw` for periodic compatibility review and compatibility-floor changes.

## 0.12.34 - 2026-09-08

### Fixed

- Recognize Codex `0.153.4` questionnaire footer tips when the terminal wraps them across exact tip boundaries, and accept the verified `enter to submit all` footer on the final option or free-text question, so multi-step questionnaires remain actionable instead of falling back to `manual_required`.

### Security

- Keep questionnaire footer matching fail-closed: only exact known tips in their expected order are accepted, while the raw physical footer layout remains part of the prompt fingerprint so a resize or redraw between Status and dispatch invalidates stale response authority.

## 0.12.33 - 2026-09-07

### Added

- Notify the owning OpenClaw conversation whenever a managed Claude Code or Codex Turn reaches a supported native questionnaire step, then resume monitoring so sequential questions and final confirmation each receive their own durable callback.

### Fixed

- Expose portable OpenClaw response schemas for single-select, bounded free-text, and confirmation answers while retaining strict semantic validation against the current terminal question.
- Treat a durable interaction reservation as the expiry acceptance boundary, preventing a questionnaire recapture that crosses a ten-minute lease bucket from being falsely reported as changed and stalling the Turn. Proven zero-input failures now release only their exact reservation and require a fresh Status; genuinely uncertain terminal input remains fail-closed.

### Security

- Keep interaction callbacks notification-only: the owning controller must obtain a fresh Status-bound private offer before responding, and multi-select, stale, secret-bearing, changed, or uncertain prompts remain non-actionable.

## 0.12.32 - 2026-09-07

### Fixed

- Adopt OpenClaw 2026.9.2's portable `assets/icon.png` plugin branding convention and remove the unsupported top-level manifest icon URL, keeping the AKK icon packaged locally while restoring a warning-free ClawHub validation result.

## 0.12.31 - 2026-09-07

### Added

- Promote Codex `0.153.4` and Claude Code `2.1.263` to exact regression-tested lifecycle and native-status profiles, alongside their interactive-questionnaire profiles, after isolated real-TUI validation.

### Fixed

- Recognize the current terminal-scoped Send projection in the isolated lifecycle smoke while keeping its dispatch on the strict managed-only path and all terminal authority out of published evidence.
- Preserve exact committed Codex lifecycle companion fences through submission acceptance and monitor recovery, so a first Send after `/new` is not falsely stalled when Codex keeps the predecessor rollout open; unknown roots remain fail-closed.

## 0.12.30 - 2026-09-07

### Added

- Add an owner-bound `agent_knock_knock_respond_interaction` contract for exact native Claude Code and Codex questionnaires, including opaque single-select choices, stepwise multi-question flows, bounded free-text replies, and final confirmation or cancellation.
- Add semantic `approve_once` and `reject` approval decisions when the current exact terminal prompt advertises a proven native rejection action.

### Security

- Bind every interactive response to the managed Turn, controller session, terminal and process incarnation, exact versioned screen fingerprint, expiry, and durable one-shot reservation. Unknown layouts, secret-bearing questions, stale offers, and uncertain post-input outcomes remain fail-closed without automatic retry.

## 0.12.29 - 2026-09-07

### Fixed

- Let an exact-empty managed Claude tmux send recognize the stable `[Pasted text #N +M lines]` composer produced by its single successful multiline paste. AKK now revalidates the same terminal incarnation, line count, closed frame/footer profile, and placeholder before dispatching exactly one Enter, instead of stalling while the collapsed draft is safe to submit.

## 0.12.28 - 2026-09-04

### Security

- Update the verified OpenClaw build dependency to `2026.9.1` and ClawHub release tooling to `0.23.3`, then refresh the root and DeepSeek connector dependency locks to remove the reported vulnerable transitive versions without raising AKK's supported OpenClaw host floor.

### Fixed

- Let the OpenClaw compatibility and release matrix detect capability-consent support and accept the plugin's declared capabilities on hosts that require explicit consent.
- Create the matrix's isolated callback session before asserting durable next-turn injection, matching the stricter persisted-session contract in current OpenClaw without weakening the minimum-host check.
- Omit absent optional state and log paths from callback injection metadata so the payload remains valid JSON under current OpenClaw's strict plugin-hook validation.

## 0.12.27 - 2026-09-04

### Added

- Add exact Codex `0.153.0` and Claude Code `2.1.259` lifecycle and native-status profiles after isolated real-TUI validation of status inspection, prompt submission, durable session identity, new-thread, and exact-resume behavior.

### Fixed

- Exclude Codex `0.153.0` management and non-interactive subcommands from terminal discovery while preserving interactive prompts, option values, resume, and fork invocations.
- Recognize Claude Code `2.1.259` value-taking CLI options and its Bash permission footer without the removed Ctrl+E hint; safely correlate the canonical auto-mode tip when it wraps at 80 columns without ever joining wrapped command text.
- Give the exact Codex `0.153.0` profile the bounded MCP restart settlement used by verified current lifecycle transitions.

## 0.12.26 - 2026-09-01

### Added

- Add structured Herdr session, pane-process, process-association, and exact-terminal discovery diagnostics so a missing terminal row can be localized without logging terminal contents or coding-agent commands.

### Fixed

- Preserve authoritative PID and ancestry rows when `ps` elapsed metadata is temporarily unavailable, and select the interactive Codex root through the complete process tree so nested helper processes cannot replace the terminal's stable PID.
- Keep exact Terminal Watch observation bound to its requested PID even when a nested Codex process appears first, preventing a live Herdr pane from being misreported as `terminal_process_unavailable`.
- Resolve the read-only physical Codex identity from a complete unique same-PID, same-incarnation open-root inventory when a stale managed Session preference rejects the current thread. Managed binding conflicts remain independently visible, while ambiguous roots and every mutation path continue to fail closed.

## 0.12.25 - 2026-08-31

### Fixed

- Let the npm OpenClaw installer detect capability-consent support and pass `--accept-capabilities` through both fresh linked installs and trusted replacement installs. Older OpenClaw versions keep the existing argument shape, while installation receipts now report whether capability consent was accepted.

## 0.12.24 - 2026-08-31

### Added

- Add an exact Codex `0.151.0` native lifecycle and `/status` inspection profile after validating its Composer, rollout identity, slash-popup, status-card, clear, exact-resume, and terminal Send surfaces in an isolated real TUI.

### Fixed

- Let Codex `0.151.0` and forward-compatible lifecycle verification wait safely for a resumed thread's bounded MCP startup to restore the exact empty Composer before sending the single post-resume `/status` probe. A proven `not_started` Composer observation is retried without terminal input only for those profiles; historical profiles and other failures retain their existing fail-closed behavior.
- Preserve a bounded stable-recapture opportunity when the first exact native `/status` Composer capture itself exceeds the wall-clock settle deadline on a busy tmux server; mismatched or disappearing candidates still fail closed without Enter.

## 0.12.23 - 2026-08-30

### Fixed

- Give user-explicit unmanaged fallback Watches their own `chat.send` callback profile instead of reusing the managed Send Gateway method. Recover the exact historical pre-I/O profile-mismatch receipts with their original idempotency keys, preserve ambiguous or delivered evidence, and expose callback delivery failures in Watch status.

## 0.12.22 - 2026-08-30

### Added

- Add an exact Claude Code `2.1.251` lifecycle, transcript, Bash approval, and `/status` inspection profile after real TUI validation.

### Fixed

- Treat Claude Code `2.1.251` `agents` rows reported as `waiting` without a wait reason as input-ready, while preserving non-empty permission/background wait reasons as blocked or active states.
- Recognize the strict three- or four-choice Claude Bash approval variants that offer auto mode, approve only a highlighted one-time `Yes`, and exclude the auto-mode tip from exact transcript command correlation.
- Exclude the new Claude Code management subcommands from interactive terminal discovery and accept the newly profiled Status fields without exposing the peer address.

## 0.12.21 - 2026-08-30

### Added

- Add an exact Codex `0.150.1` native lifecycle and `/status` inspection profile after verifying its Composer, rollout, slash-popup, status-card, clear, and exact-resume surfaces.

## 0.12.20 - 2026-08-28

### Added

- Add a durable `terminal_activity` / `best_effort` Watch fallback for an exact user-selected terminal when no unique provider task anchor is available. It arms on observed work or approval and reports stable idle only after two consecutive supervision sweeps.

### Fixed

- Keep an explicit read-only Watch available across managed ownership, missing action advertisement, lifecycle-binding gaps, agent/artifact version drift, an existing Watch, and malformed unrelated Watch records; these conditions now warn, reuse, or degrade instead of vetoing the user.
- Recognize the Codex 0.149.1 `item_completed` `UserMessage` record as exact human-root evidence, including exact text and turn-identity validation.

### Changed

- Allow independent controller callback authorities to observe the same terminal while keeping same-target, same-controller Watch creation idempotent. Existing active Watches no longer hide the Watch action on terminal rows.
- Expose immutable Watch warnings plus `watch_mode` and `confidence` in status and callbacks so exact task completion remains distinct from best-effort terminal activity becoming idle.

### Security

- Keep manual Watch observation-only: it acquires no terminal mutation authority, sends no input, changes no managed ownership, and never auto-approves. Creation still fails when the exact terminal is absent or unobservable, neither an exact anchor nor screen-status path exists, or durable Watch state cannot be written.

## 0.12.19 - 2026-08-27

### Added

- Attach a durable Terminal Watch after a successful `terminal_user_explicit` unmanaged physical Send, restoring completion, failure, invalidation, and timeout callbacks without fabricating a managed Turn.

### Changed

- Advance the model-facing action contract to 23, Terminal Watch schema to v2, and Store writer protocol to 6 with compatible migration and normalization of existing records.

### Security

- Keep the user's explicit Send authoritative: Watch attachment and observation are best-effort, warning-only follow-up work and can never block, revoke, or automatically replay accepted terminal input.
- Bind fallback callbacks to the exact Codex rollout or Claude transcript task accepted after the Send, including same-request races and completion before the first Watch sweep. Automatic fallback Watches do not emit approval callbacks; approval input remains manual.

## 0.12.18 - 2026-08-27

### Fixed

- Make an explicit Codex Send independent of Composer visibility, stability, and exactness. Physical fallback now replaces the current Composer with one `C-u`, injects the new request, waits through the paste window, and dispatches Enter exactly once without a post-text Composer veto. Claude Code remains exact-empty-only.

### Changed

- Treat Codex and Claude Code version profiles as regression-test evidence rather than runtime allowlists. A complete but unverified `x.y.z` version keeps every otherwise eligible Watch, native status, new-thread, candidate-list, and exact-resume action available through a generic compatibility profile, with explicit warnings in List, action, doctor, and command results.
- Advance the model-facing action contract to 22 so Hosts preserve compatibility warnings and advertise Codex `replace_current_composer_and_submit` while continuing to pass only semantic action arguments.

### Security

- Preserve exact terminal/process, native-thread, workspace, artifact, approval, composer, candidate, and postcondition checks for unverified versions. Real UI or schema drift fails at runtime, and any result after possibly sending input remains uncertain and must not be retried automatically.
- Preserve the exact live terminal/process and scanned, non-blocked approval boundary for Codex user-explicit Send. Once its sole mutation sequence begins, an uncertain result must not be retried automatically.

## 0.12.17 - 2026-08-26

### Fixed

- Keep an explicit user Send available for a verified mutable Codex prompt even when its composer already contains a stable draft. An empty composer receives the new request, an identical draft receives exactly one Enter without duplicate text injection, and a different draft is cleared once, replaced by the new request, and then submitted once.
- Use one shared prepared timestamp for a deferred foreground transfer, its Turn submission receipt, and its dispatch ledger, preventing real-clock drift from producing a half-submit authority mismatch between otherwise identical evidence.

### Changed

- Advance the model-facing action contract to 20 and add the first Codex nonempty-Composer user-explicit policy, later superseded by the v22 replace-current-Composer behavior. Claude Code user-explicit Send, native inspection, and native lifecycle input remain restricted to a verified empty Composer.

### Security

- Revalidate the exact Codex terminal/process identity, non-approval state, stable composer digest, and user request immediately around clear, text, and Enter boundaries. Live working activity remains diagnostic rather than a veto for this user-explicit path. A failure after the sole draft-clear key is uncertain and must not be retried automatically; draft text and opaque composer authority remain outside model-facing actions and durable receipts.

## 0.12.16 - 2026-08-26

### Added

- Add a Host-owned foreground MCP/stdio Bridge that exposes the existing 16 semantic AKK tools without introducing a second state or tool model.
- Add strict Host Profile v1 configuration with trusted environment session binding, a shell-free `command_json_v1` callback driver, compatibility/doctor commands, a published JSON Schema, and a starter user Profile.
- Add the public `./host-adapter` facade used by native controller integrations, with exact per-controller command/tool authority and one shared Host-owned lifecycle.
- Add a first-party DeepSeek Harness Web connector package that derives the controller route from the exact invoking Agent, registers `/akk` plus all 16 semantic tools, and returns callbacks through idle `followup` or running `inject` without a user-visible bind step.

### Changed

- Reuse the shared Host lifecycle and existing durable callback route, outbox, retry, and settlement core for configuration-only Hosts while preserving the native OpenClaw adapter unchanged.
- Persist complete route-bound Terminal Watch callback authority and keep callbacks pinned to the initiating Host/Agent incarnation instead of redirecting them after replacement or restart.

### Security

- Keep Profile selection, controller identity, executable, arguments, credentials, and acknowledgement rules outside model-facing tool inputs; exact route fingerprints and delivery/message acknowledgements fail closed on drift.
- Keep DeepSeek session routing outside slash/tool arguments, authenticate its private callback socket, and reject disposed or replaced Agent objects rather than trusting a reused session-id string.

## 0.12.15 - 2026-08-25

### Added

- Add the `terminal_user_explicit` physical Send authority domain, global message intent, and immutable omitted-target binding so an explicit user Send remains actionable independently of AKK management state.

### Fixed

- Prevent stale, stalled, deferred, corrupt, or missing Store, Session, Turn, transfer, activity, and dispatch-ledger state from vetoing an explicit user Send. When a zero-wait managed attempt proves that no input was submitted, fall back once to exact physical delivery and leave subsequent observation to Terminal Watch.
- Detach an exact same-incarnation bound Session left behind by failed managed preparation after physical fallback when no live blocking Turn remains, so a later Terminal Watch can attach normally.
- Retire an exact same-incarnation ordinary dispatch ledger whose owner Turn is gone after physical fallback, so a refreshed List can advertise Watch again; unresolved native lifecycle ledgers remain preserved.
- Reject ordinary native slash-command text before selector discovery, avoiding terminal or host-process scans for an invalid Send or Respond.
- Make OpenClaw doctor skill verification compatible with multi-agent installations that require an explicit `main` owner.
- Scope durable omitted-target delegate bindings to the active runtime directory, preventing in-process hosts with scoped `AKK_RUNTIME_DIR` values from sharing message-ID state.
- Bind explicit physical Send authority to the exact operating-system process incarnation and reject stale supplied authority before managed preparation or terminal input.

### Changed

- Advance the action contract to 19 and expose Send readiness from physical terminal evidence while retaining the existing Store format and writer protocol.

### Security

- Continue to require exact live terminal and process identity, approval eligibility, an empty composer, and unambiguous input evidence before physical Send. Possible prior input, true concurrency, or same-message ambiguity remains fail-closed and never triggers duplicate delivery.
- Keep fallback delivery free of synthetic Turns or callbacks, and treat post-delivery bookkeeping or cleanup failures as warnings without automatically replaying user input.
- Preserve a Session still named by an unresolved native lifecycle ledger instead of fabricating a transition outcome; the physical Send remains delivered and cleanup reports the retained recovery boundary.

## 0.12.14 - 2026-08-24

### Added

- Add an exact Codex `0.149.1` native lifecycle and `/status` inspection profile, retaining fail-closed handling for adjacent and future unverified versions.
- Add a versioned, host-neutral callback route and transport boundary with durable routing and idempotency authority while retaining OpenClaw as the concrete host adapter.

### Fixed

- Distinguish the exact Codex root user row from same-turn synthetic user-role context, preserving Terminal Watch until a later native task actually supersedes it.
- Safely recover eligible uncertain Send submissions through exact one-shot retry and reconciliation without replaying accepted input or replacing the original request.
- Make explicit Close honor the user's management-release decision first, with best-effort linked cleanup, warning-only cleanup conflicts, no terminal or coding-agent interruption, and immediate eligibility for a fresh Watch.

### Security

- Freeze callback routing and idempotency authority durably, fail closed on route drift or ambiguous recovery, and keep model-facing callback and retry contracts free of opaque authority material.
- Require exact adjacent native-event evidence and a privacy-safe content hash when identifying Codex root user rows; missing, duplicate, orphaned, or mismatched evidence fails closed.

## 0.12.13 - 2026-08-22

### Added

- Add durable Terminal Watch for exact human-started Codex and Claude Code tasks, with restart-safe OpenClaw callbacks for approval, completion, failure, timeout, invalidation, and cancellation.
- Add `agent_knock_knock_watch` / `agent_knock_knock_unwatch`, `/akk watch` / `/akk unwatch`, and watch-aware list/status output without creating an AKK Session or Turn or sending terminal input.

### Fixed

- Derive Watch and Send authority from exact terminal IDs inside the trusted plugin/CLI boundary, so OpenClaw models never need to copy opaque tokens or fingerprints.
- Keep Watch activity authoritative when Codex's transient screen markers look idle, support large historical rollouts with incremental checkpoints, and isolate corrupt historical Watch records without starving healthy watches or callbacks.
- Restore follow-current Send across tmux route renumbering, stale legacy dispatch ledgers, long-lived Sessions with released earlier binding epochs, and interrupted v1-to-v2 ledger migration without replaying terminal input.

### Changed

- Advance the action contract to 18 and expand the OpenClaw plugin contract to 16 tools. Model-facing actions now carry semantic IDs only; opaque freshness and confirmation authority remains private to the plugin and CLI. Store writer protocol remains 5; Terminal Watch uses its own schema-v1 aggregate.

### Security

- Pin each Watch to exact terminal, process, native-task, runtime-version, rollout/transcript file, and privacy-safe request-hash evidence; drift fails closed and approval observations never authorize automatic input.
- Revalidate private Send, lifecycle, handoff, reconciliation, and approval authority under canonical terminal and Store locks; stale, split, replayed, cross-session, or callback-mismatched evidence sends zero terminal input.

## 0.12.12 - 2026-08-21

### Added

- Add exact native lifecycle and status compatibility for Codex `0.148.0` and Claude Code `2.1.237`, while retaining the previously verified profiles.
- Report exact native-profile support in CLI and OpenClaw doctor output without blocking ordinary terminal work for an otherwise available but unprofiled coding-agent executable.

### Changed

- Decompose the orchestration runtime into typed, ownership-checked domain facades and services while preserving action contract 16, Store writer protocol 5, public CLI/OpenClaw contracts, lock ordering, and durable-write ordering.
- Strengthen architecture enforcement with bounded production functions, canonical status authorities, targeted affected-test selection, and reproducible refactor evidence.
- Clarify the TUI-first handoff model and make fast tests the normal development/local-install gate while reserving the full release suite for actual npm and ClawHub publication.

### Security

- Keep adjacent unknown Codex and Claude Code versions fail-closed for native inspection and lifecycle operations, and enforce one-way Claude transcript resume compatibility across verified profiles.
- Preserve exact terminal identity, binding, approval, acceptance, callback, retry, and uncertainty fences across the internal architecture refactor.

## 0.12.11 - 2026-08-14

### Fixed

- Allow managed close to retire a Turn when its exact bound Codex or Claude Code process is conclusively absent, without falling into the managed/raw close deadlock.
- Stop terminal-monitor relaunch loops for verified-dead accepted Turns, while preserving completion-first settlement when the exact rollout or transcript already contains a durable result.
- Recover verified-dead stall and close transitions idempotently across event/state/ledger crash windows without replaying terminal input.

### Security

- Require a complete process inventory, exact Session and Turn binding generation, canonical terminal endpoint, process incarnation, dispatch ledger, and append-only native-acceptance receipts before dead-process cleanup; malformed, partial, conflicting, or unavailable evidence remains fail-closed.
- Distinguish durable completion as present, absent, or unverifiable for both Codex rollouts and Claude transcripts. Unverifiable evidence may stop orphan-monitor churn but cannot resolve the dispatch, renew the Turn, or trigger terminal input.

### Changed

- Keep action contract 16 and Store writer protocol 5 unchanged; no new public action or Store authority is introduced.

## 0.12.10 - 2026-08-13

### Fixed

- Scope Codex and Claude Code approval fingerprints to one adapter-isolated, exact unredacted prompt region, so unrelated terminal output can continue scrolling across review, authorization, and dispatch reservation without invalidating the same visible request.
- Normalize managed approval locking to terminal, Store writer, then Turn state order, eliminating the writer/state inversion that could amplify approval delays under concurrent monitor activity.
- Support the complete Codex 0.147 command, edit, permission, and MCP approval menus, including multi-choice decline/cancel rows and the permission deny shortcut.

### Changed

- Publish action contract 16. Whole-screen digests and excerpts are diagnostic only; v15 approval fingerprints and terminal-scoped approval tokens require a fresh `list` or `status` after upgrade.
- Store writer protocol remains 5.

### Security

- Revalidate the exact prompt-region digest with terminal, process, action, request, policy, and working-directory authority before approval input; missing, incomplete, duplicated, reordered, spoofed, or changed prompt evidence sends zero keys.
- Keep raw prompt text local to the adapter and out of status, Store records, tokens, logs, and failure diagnostics; only its SHA-256 digest participates in authorization.

## 0.12.8 - 2026-08-13

### Fixed

- Route every eligible quiescent rollout-backed Codex pane through terminal-follow-current candidate attribution, including single-root and multi-root inventories with resolved or unavailable foreground identity, then bind only the unique post-submit acceptor.
- Keep the Codex `/clear` resume hint advisory, so a valid fresh candidate action remains usable after the hint scrolls out of view while exact terminal, process, Store, inventory, and composer authority remains unchanged.
- Restore idempotent retry after a conclusively zero-input candidate-send abort without reusing the abandoned provisional Session or allowing binding drift.

### Changed

- Publish action contract 15. Rollout-backed Codex rows advertise `terminal_follow_current` instead of `session_exact`, and cached direct `session_id` sends reject before task input.
- Store writer protocol remains 5.

### Security

- Require a complete nonempty open-root inventory, exclusive candidate ownership, exact process and terminal incarnation, frozen source history and dispatch ledger, an idle empty composer, and no blocking Turn before candidate input; stale, incomplete, claimed, or ambiguous state remains fail-closed.

## 0.12.7 - 2026-08-12

### Fixed

- Follow a supported manual Codex `/clear` through a fresh terminal-scoped candidate send, binding only the rollout with one unique post-anchor acceptance without an internal `/status` probe.
- Restore future-send liveness after explicitly closing an uncertain predecessor when its resolved close ledger, append-only uncertain receipt, frozen Turn history, absent old rollout, and unclaimed current inventory remain exact.
- Recognize the supported Codex resume hint when its UUID wraps across lines in a narrow pane, while keeping the hint as routing evidence rather than native-identity authority.
- Ignore closed detached Codex companions when one exact current rollout is open, and release completed Claude Turns for a fresh message ID while retaining immutable acceptance receipts.

### Changed

- Publish action contract 14. Store writer protocol remains 5.

### Security

- Revalidate candidate inventory, terminal and process identity, abandonment proof, and source/target lineage before input, commit, and crash recovery; ambiguous, drifted, or uncertain native acceptance remains non-retryable.

## 0.12.6 - 2026-08-12

### Added

- Add manual-only terminal-scoped Codex approval for one exact visible prompt when a human-entered task has no AKK dispatch owner or usable foreground UUID, while requiring a fresh list token, status fingerprint, and explicit confirmation.

### Fixed

- Let an advertised ordinary Codex task proceed once in a narrow pane when AKK has a complete but foreground-unbound rollout inventory, then bind only the rollout that uniquely accepts the exact request without an internal `/status` probe.
- Reconcile callbackless terminal completion locally, release the exact dispatch ledger, and restart pending candidate monitors after a crash without creating a Gateway outbox or replaying terminal input.

### Changed

- Publish action contract 12 and Store writer protocol 5. Protocol 4 Stores upgrade through an atomic manifest-only writer fence.

### Security

- Freeze released predecessor Turn history throughout deferred candidate binding, preserve separate same-UUID and different-UUID Session lineages, and keep zero, multiple, drifted, or uncertain request acceptance non-retryable.
- Revalidate manual approval and cancellation against the canonical terminal endpoint, process incarnation, dispatch snapshot, Session revision, and prompt immediately before terminal keys, while keeping auto-approval and provisional managed controls unavailable.
- Serialize deferred recovery as terminal-to-writer-to-state and treat Store or state-lock contention as monitor backoff rather than native-acceptance uncertainty.

## 0.12.5 - 2026-08-12

### Fixed

- Let an advertised terminal-scoped ordinary Codex first task proceed in a narrow pane without an internal `/status` probe when the existing status-card-only context has a verified zero rollout, then bind the new AKK Session to the exact rollout that accepts the request.
- Preserve strict UUID proof for explicit Session sends, responses, approvals, cancellations, lifecycle operations, and native inspection while keeping uncertain terminal input non-retryable.

### Security

- Isolate deferred foreground sends in a zero-UUID provisional Session and require exact process, terminal, request-acceptance, ownership, and binding-generation evidence before promoting it to the native thread.
- Add Store protocol 4 writer fencing plus crash-safe deferred-transfer receipts and recovery across pre-input aborts, post-input uncertainty, same-thread handoff, acceptance backfill, and downgrade attempts without replaying terminal input.

## 0.12.4 - 2026-08-11

### Fixed

- Submit every internal Codex `/status` through one exact-version closed path with bracketed-paste settling, current-composer proof, one Enter, and same-depth freshness, so narrow or stale Herdr screens cannot masquerade as a complete current Session.
- Stop uncertain terminal dispatches from collateral-stalling already completed Claude Turns, and strictly repair legacy false stalls only when completion, callback, dispatch-fence, and closed-owner evidence agree.
- Preserve exact Claude composer text across Herdr visual soft wraps while ignoring historical prompts outside the current bottom composer frame.

### Security

- Fence Codex status probes with exact tmux or kernel PTY viewport evidence, terminal route, process birth, TTY device identity, native identity, and final composer revalidation before the single Enter.
- Apply terminal-incarnation blockers consistently across list, send, lifecycle, and native inspection, while keeping human-handoff source Turns behind snapshot-bound close decisions and retaining typed Store-only close for genuinely unavailable terminals.

## 0.12.3 - 2026-08-11

### Fixed

- Recover a same-process Codex terminal after the previously bound rollout has conclusively ended by detaching the old Session and creating a separate virgin Session for the next exact terminal-scoped send.
- Parse only Claude Code's current bottom composer frame, so a historical `/clear` prompt does not block Herdr handoff and exact soft-wrapped drafts can still receive one verified Enter.

### Security

- Keep generic unverifiable native identity and explicit Session-scoped sends fail-closed, while requiring the exact endpoint, PID, process birth, cwd, owner, source binding, idle state, and styled-empty composer before adopting a verified zero-rollout Codex context.
- Preserve character-exact draft checks, repeated pre-text and pre-Enter identity revalidation, single-Enter dispatch, isolated Session history, and no blind retry after text may have reached the terminal.

## 0.12.2 - 2026-08-11

### Added

- Let terminal-scoped sends absorb an exact, verified native-thread switch made by a human through Codex or Claude Code, including `/clear`, new-thread, and Resume flows across tmux and Herdr.
- Restore a uniquely matching historical Session with its own binding generation, or create a separate Session for a previously unseen native thread, without merging conversation history.

### Changed

- Keep explicit Session-scoped sends pinned to their original native context, while active Turns expose a snapshot-bound handoff decision that requires explicit confirmation before the current human context is adopted.

### Security

- Revalidate the native UUID, process birth, terminal endpoint, cwd, exclusive ownership, idle state, and exact composer immediately around terminal input, while preserving single-Enter and no-blind-retry guarantees.
- Persist human-observed handoffs through fenced lifecycle transitions and ledgers with crash recovery, stale-decision rejection, and strict isolation for prior Turns, monitors, callbacks, approvals, and dispatch receipts.

## 0.12.1 - 2026-08-11

### Fixed

- Allow a genuinely virgin Codex TUI to accept its first AKK send by pinning the exact process incarnation before input, then atomically refining the Session and Turn to the newly materialized native UUID, rollout, and request evidence after the single Enter.
- Recover both post-Enter virgin-binding crash windows without replaying terminal text or Enter, while preserving the existing ownership, binding-generation, process, pane, cwd, rollout, and request-hash fences.
- Preserve tmux `pane_current_path` when extended eight-field pane output is collapsed to whitespace or underscores, rejecting ambiguous or truncated records instead of appending the server socket and pane ID to the workspace.
- Preserve Codex composer ANSI styling through Herdr's visible screen buffer so an empty dim placeholder is not mistaken for authored draft text, while leaving ordinary monitor and status reads on Herdr's agent-aware detection buffer.

## 0.12.0 - 2026-08-10

### Added

- Add exact local Herdr `0.8.0` / protocol 19 support as a second terminal provider alongside tmux, including discovery, screen capture, bracketed-paste-aware text delivery, key dispatch, lifecycle state, Resume snapshots, native inspection, monitoring, and OpenClaw actions.
- Add a routed terminal-provider registry, Herdr-aware doctor diagnostics, packaged setup documentation, and provider-neutral terminal identities throughout the Store and public terminal list.

### Changed

- Split the CLI entrypoint from its injectable command core, move the slowest lifecycle and rollout semantics into deterministic in-process fixtures while retaining their real-process contract tests, and add a fail-closed affected-test runner for faster local iteration.
- Isolate terminal-provider discovery and diagnostics failures so an unavailable Herdr session contributes no candidates without hiding healthy tmux terminals.

### Security

- Bind Herdr control to the local Unix-socket incarnation, stable `terminal_id`, refreshable pane route, shell and agent process ancestry, cwd, native coding-agent identity, and the existing Session/Turn binding fences before every side effect.
- Preserve the durable `prepared → text_injected → enter_dispatched → agent_accepted` boundary, keep lost acknowledgements uncertain without blind retries, fail closed when multiple providers could own one process, and isolate a failed provider discovery without hiding healthy transports.

## 0.11.7 - 2026-08-10

### Changed

- Establish a provider-neutral terminal-control boundary that separates stable endpoint/resource identity, mutable delivery routes, and process-incarnation evidence while preserving the existing tmux CLI, OpenClaw tools, and agent lifecycle behavior.
- Route terminal discovery, capture, text injection, and key delivery through an injectable provider registry with fresh resource resolution and explicit transport capabilities.
- Derive binding tokens, terminal locks, dispatch ledgers, receipts, approval fingerprints, and Resume snapshots from one canonical endpoint identity, while monotonically refining existing v0.11.x records and atomically promoting legacy ledgers without duplicate owners.

### Security

- Fail closed when provider identity, process anchors, or required capabilities cannot be revalidated, and preserve the distinction between input proven not sent and a potentially submitted uncertain outcome without blind retries.
- Use stable tmux server/socket and pane identities for namespace isolation and route-renaming safety while retaining exact legacy binding-token and approval-fingerprint compatibility boundaries.

## 0.11.6 - 2026-08-10

### Added

- Add exact lifecycle and native `/status` behavior profiles for Codex 0.147.0 and Claude Code 2.1.226 while preserving Codex 0.146.0/0.146.1 and Claude Code 2.1.218 support.
- Let Claude Code 2.1.226 discover and exactly resume same-workspace 2.1.218 history through source-version-bound v2 candidate tokens and the existing full UUID, ownership, binding, and identity fences.

### Fixed

- Match Codex 0.147.0's exact ordered two-row `/status` completion surface and Claude Code 2.1.226's `Session kind: interactive` Status panel.
- Keep Claude native inspection closed and reliable across narrow panes by accepting only exact profiled rows or their explicit Unicode-ellipsis prefixes, with a version-owned bounded settle deadline before the single Enter dispatch.

## 0.11.5 - 2026-08-09

### Added

- Extend the closed `native_inspect(status)` action to exact Claude Code 2.1.218 with an adapter-owned `/status` plan, a separately measured 80 ms composer-stability boundary, bounded and redacted Status-panel parsing, and safe return to the original idle composer.

### Security

- Fence Claude inspection with a fresh snapshot token, the shared terminal lock, exact pane, PID, process birth, cwd, binding, unique `claude agents --json --all` Session identity, and exclusive active ownership before and across terminal input.
- Keep ordinary `send` and `respond` slash-command rejection intact, issue at most one Enter and one Escape without blind retries, create no AKK lifecycle state, and leave `/usage`, `/cost`, `/stats`, and `/usage-credits` unavailable.

## 0.11.4 - 2026-08-09

### Added

- Add an adapter-owned, version-scoped native status inspection for Codex 0.146.0 and 0.146.1, exposed through a closed `native_inspect(status)` action that returns a bounded and redacted fresh `/status` result without creating a Session, Turn, receipt, monitor, callback, or Store state.

### Security

- Keep ordinary `send` and `respond` slash-command rejection intact while serializing native inspection with terminal mutations, revalidating the exact terminal, process, binding, version, idle composer, and ownership state, and dispatching at most one Enter only after the versioned 121 ms materialization boundary.
- Fail closed after identity drift, ambiguous or stale status evidence, and uncertain submission outcomes without blind retries or a second Enter.

## 0.11.3 - 2026-08-08

### Fixed

- Make virgin Codex raw-terminal attachment atomic by persisting its managed Session only after read-only pre-input checks pass, then CAS-detaching the provisional binding after every conclusively pre-input failure so a failed first send cannot strand a bound orphan.
- Add exact snapshot-fenced `reconcile-binding` recovery for eligible provisional and same-process external-thread conflicts while keeping ambiguous identity, PID, Turn, transition, and dispatch cases fail-closed and suppressing control actions that are already known to fail.
- Distinguish definite tmux no-input failures from uncertain submission outcomes so safe retries remain available without risking duplicate terminal injection.

## 0.11.2 - 2026-08-08

### Fixed

- Filter Codex resume candidates by workspace, source, archive state, and provider before applying the SQLite result limit, so older same-workspace threads are not dropped by unrelated global history.
- Keep the current adapter version separate from each candidate's source agent version, allowing historical Codex threads to remain resumable when their rollout metadata agrees while preserving the complete snapshot, ownership, binding, and identity safety fences.

## 0.11.1 - 2026-08-07

### Fixed

- Harden Codex resumable-thread discovery across transient SQLite WAL/SHM creation, replacement, and checkpoint windows with one read transaction, identity-checked bounded `SQLITE_CANTOPEN` recovery, and a query-only sidecar-materialization fallback that does not use `immutable=1`.
- Forward configured `codexHome` to Codex lifecycle discovery, new, and resume paths in OpenClaw tools and `/akk` commands.

## 0.11.0 - 2026-08-07

### Added

- Add snapshot-bound native Resume navigation with deterministic numbers, collision-safe display-only short IDs, opaque five-minute handles, and a `previous` / `刚才那个` shortcut derived from the current Session's latest committed lifecycle transition.

### Security

- Resolve every Resume shortcut back to the complete UUID and exact evidence tuple, then fail closed if the terminal action generation, process, workspace, binding, ordered candidate snapshot, ownership, or TTL changed before native input.

## 0.10.4 - 2026-08-07

### Fixed

- Recognize exact Codex multiline drafts across TUI-painted visual wraps before dispatching Enter once, while preserving authored newlines, indentation, repeated spaces, stable-capture checks, and fail-closed content drift detection.

## 0.10.3 - 2026-08-07

### Added

- Supervise active terminal bridge monitors from the OpenClaw plugin every five seconds and automatically recreate an unexpectedly exited owner without requiring `list` or `status`.
- Retain redacted durable-completion detector limitation and recovery diagnostics in each Turn's event history.

### Fixed

- Treat Store writer-lock timeouts as transient monitor deferrals with bounded backoff while preserving the hard fence for a genuinely superseded Session binding generation.
- Complete accepted Codex turns from their exact bound rollout and native turn UUID beyond the legacy recent-turn window, while preserving the existing exactly-once completion claim across recovery.

## 0.10.2 - 2026-08-07

### Fixed

- Require exact post-anchor Codex rollout or owner-private Claude transcript evidence before reporting a terminal submission as delivered; tmux transport success alone now remains pending or uncertain and is never automatically retried.
- Track durable `prepared → text_injected → enter_dispatched → agent_accepted` proof, preserve that exact proof level across replay and recovery, and fence stable OpenClaw retries to their original Store, Session, Turn, message, binding, and terminal incarnation.
- Settle an exact multiline Codex composer before dispatching Enter once, promptly report an unchanged exact draft as not accepted, and extend the opt-in lifecycle smoke payload to verify multilingual multiline native acceptance.
- Keep append-only submission receipts bound to the pane incarnation that received their input while allowing a replacement tmux pane to establish a new dispatch generation.

## 0.10.1 - 2026-08-06

### Added

- Add an opt-in native lifecycle live-smoke diagnostic that records redacted, commit-bound Codex and Claude Code `new → send → resume` evidence.
- Add an exact Codex 0.146.1 native lifecycle behavior profile while preserving 0.146.0 support.

### Fixed

- Let the lifecycle diagnostic attest a persisted unmanaged Codex 0.146.1 thread whose identity is first proved by New's locked, fresh `/status` probe, then fail before `/clear` unless that exact origin remains a uniquely owned, revalidated resume candidate; ordinary list and New behavior remain unchanged outside the opt-in diagnostic.
- Keep the semantic Turn phase independent from callback transport delivery, so a failed or pending `done` notification leaves the Turn idle and a failed or pending `question` or `blocked` notification remains actionable through respond or cancel.
- Treat accepted OpenClaw injection and wake acknowledgements as durable delivery while keeping `agent.wait` timeout, error, or malformed output as observation-only evidence that cannot replay an accepted callback.
- Serialize callback claims with exact in-flight diagnostics, preserve immutable outbox delivery across close and Session binding-generation changes, and migrate valid legacy callback-owned statuses without letting malformed records poison Store-wide listing.

### Changed

- Keep the native lifecycle smoke optional during rapid iteration: npm and ClawHub publishing no longer require an annotated-tag attestation, while the manual runner and evidence verifier remain available for diagnostics.

## 0.10.0 - 2026-08-06

### Added

- Add capability-scoped native-thread lifecycle controls for starting or clearing context, listing verified same-workspace resume candidates, and resuming one exact Codex or Claude Code native thread in the existing tmux pane.
- Add the optional OpenClaw tools `agent_knock_knock_new_thread`, `agent_knock_knock_list_resumable_threads`, and `agent_knock_knock_resume_thread`, plus `/akk new-thread`, `/akk clear-thread`, `/akk threads`, and `/akk resume-thread` human-facing commands.
- Publish the v5 list/action contract with exact terminal lifecycle targets, complete native-thread identities, fresh compare-and-swap binding tokens, per-candidate evidence fingerprints, and capability-gated availability.

### Changed

- Keep ordinary sends scoped to the current native context: each accepted send creates a new Turn, while a successful native lifecycle transition creates or activates an AKK Session and creates no Turn.
- Treat a sole historical Session whose recorded coding-agent PID has conclusively exited as resumable on the next lifecycle listing; the resume mutation compare-and-swap detaches that stale binding before terminal input, without background polling.
- Let human-facing lifecycle slash commands fetch a fresh binding token internally immediately before mutation; plugin tools retain the explicit token so OpenClaw follows an auditable list-then-mutate flow.
- Record terminal binding generations and native-thread transition lineage so sends after new/clear or resume target only the newly verified context.
- Upgrade the Store writer protocol to v3. The first mutation of a v1 or v2 predecessor durably materializes authoritative Session records before publishing the new manifest, quarantines ambiguous bindings, and leaves existing Turn state and event logs unchanged.

### Security

- Serialize native-thread transitions against sends, approvals, monitors, callbacks, and recovery; require an exact idle terminal with no unresolved Turn and fail closed on unsupported, ambiguous, stale, active-elsewhere, or unverifiable native identity evidence.
- Fence old monitors, receipts, approvals, callbacks, and recovery mutations to their original terminal incarnation, native thread, AKK Session, Turn, and binding generation.
- Reject every first-line native slash command at the ordinary send/respond boundary before creating Session, Turn, ledger, or terminal side effects, including lifecycle-changing `/clear`, `/new`, `/resume`, Codex `/fork`/side threads, and Claude `/branch`.

## 0.9.0 - 2026-08-05

### Added

- Add a durable AKK `session_id` for the continuing native coding-agent context and a unique `turn_id` for every accepted terminal dispatch.
- Add an explicit `respond(turn_id, answer)` path for questions and blocked requests that must continue the same in-flight turn.

### Changed

- Make ordinary sends to an existing AKK Session target its `session_id` and create a new Turn, while managed status, approval, cancellation, retry, renewal, and close operations target an exact `turn_id`.
- Keep first attach and raw-terminal control compatibility narrow and list-driven: an unmanaged row may prefill its own `selector` for initial send or `conversation_id` for an advertised raw status, approval, cancellation, or orphan-close action; callers must never construct, guess, or reuse either value.
- Publish the v4 list/action contract with terminal → session → turn history, and include both identities in messages, callbacks, delivery ledgers, and recovery output.
- Treat existing `conversation_id` values as legacy Store aliases; new records keep `conversation_id` equal to `turn_id`, while legacy records receive in-memory identity fallbacks.
- Upgrade the Store writer protocol to v2 and atomically migrate exact v1 manifests on the first mutation while preserving legacy Turn records.

### Security

- Fail closed when native Codex or Claude Code session evidence is unavailable or changes, when persisted identity fields conflict, or when callback identity sources disagree.
- Fence terminal receipts and late callbacks to the exact Store, Session, Turn, message, and native process incarnation so stale work cannot cross execution boundaries.

## 0.8.1 - 2026-08-03

### Fixed

- Keep automatic and manual callback retries config-routed when no durable Gateway token exists, instead of restoring a tokenless explicit URL that OpenClaw rejects.
- Preserve persisted, explicitly authenticated Gateway URL and token pairs across retries without copying credentials into callback delivery state.

## 0.8.0 - 2026-08-01

### Changed

- Make `AKK list` terminal-first: every discovered tmux pane is a single primary `terminals[]` resource with its authoritative current turn or latest retained turn nested below it.
- Replace ambiguous managed-turn `send` hints with `follow_up`, keep historical turns explicitly addressable, and limit default selectors to physical terminal candidates.
- Determine current terminal ownership from the dispatch ledger and suppress side effects when ownership is unresolved, while keeping the pane visible.

### Removed

- Remove the public `delegated[]`, `terminal_controlled[]`, `tasks[]`, legacy `commands`, and `source: "akk_delegate"` list compatibility model.

## 0.7.0 - 2026-08-01

### Changed

- Move managed task state to the permanent `~/.agent-knock-knock/store` root, with a compatibility manifest and conversation data under `conversations/`.
- Let OpenClaw-triggered `list` reconcile all managed tasks and `status` reconcile only its selected task. Standalone shell `list` and `status` stay read-only by default, expose reconciliation only through explicit `--reconcile`, and never change state while resolving a selector.
- Leave the former `~/.agent-knock-knock/conversations` store untouched and ignored. This release does not migrate old managed task records; existing tmux panes remain discoverable for new work.

### Security

- Refuse incompatible Store writers before changing managed state or performing terminal and Gateway side effects.
- Always use the plugin package's bundled relay and remove the configurable external `binPath` override.

## 0.6.2 - 2026-07-31

### Changed

- Publish `AKK list` action contract v2 with machine-readable field semantics that distinguish managed task lifecycle, terminal process liveness, parsed screen activity, deprecated compatibility flags, and the authoritative `available_actions` snapshot.

### Fixed

- Recognize both current `»` and legacy `›` Codex composer markers across idle detection, approval parsing, stale-prompt rejection, completion boundaries, and terminal artifact cleanup while preserving fail-closed working and approval precedence.

## 0.6.1 - 2026-07-30

### Added

- Return per-session `available_actions` and a versioned action contract from `AKK list`, including exact tool names, authoritative target arguments, fresh-status approval prerequisites, and recovery message IDs when currently available.

### Fixed

- Exclude unsupported and retired ACPX executor records from session discovery so historical Cursor or pre-tmux state cannot break valid Codex and Claude Code routing, while active legacy ownership still fences its pane against double dispatch.
- Keep idle cleanup logging safe when it closes an unsupported legacy executor record.

## 0.6.0 - 2026-07-30

### Changed

- Discover and control verified Codex and Claude Code tmux panes across workspaces without project-specific plugin configuration.
- Keep bare delegation fail-closed when multiple idle panes exist, while allowing exact selectors to route safely across projects.
- Revalidate the coding-agent PID, tmux pane identity, and matching process/pane working directory before terminal operations.
- Simplify ClawHub and npm installation, diagnostics, and first-run guidance by removing the top-level workspace setup step.

### Security

- Keep automatic approval disabled by default and scoped only by each trusted rule's exact commands, agents, and one or more `autoApprove.rules[].workspaces` roots.

### Removed

- Remove the top-level plugin `workspace` setting and the corresponding `install-openclaw` and `doctor` workspace options.

## 0.5.2 - 2026-07-30

### Fixed

- Keep macOS tmux workspace revalidation reliable when `lsof` returns usable cwd rows with a partial-failure status.
- Limit cwd lookups to the expected coding-agent PID while retaining ancestry checks and failing closed when target cwd evidence is absent.

## 0.5.1 - 2026-07-29

### Changed

- Put one complete ClawHub-first path from installation through workspace setup, Gateway restart, tmux startup, diagnostics, and the first task at the top of the README.
- Separate direct `/akk` usage from optional natural-language tool access and keep the npm installer as an alternative path.

### Fixed

- Fail closed with actionable setup guidance when the plugin workspace is missing or non-absolute instead of falling back to the Gateway working directory.
- Keep `/akk doctor` available to diagnose invalid workspace configuration.

## 0.5.0 - 2026-07-29

### Changed

- Make already-running, verified-idle Codex and Claude Code tmux panes the only delegation targets.
- Resolve bare `/akk <task>` only when exactly one eligible idle pane exists in the configured workspace, and use `/akk <selector>: <message>` for an explicit target.
- Enforce the configured workspace as a hard boundary even for explicit terminal IDs and recovery operations.
- Keep the main command surface focused on task routing, listing, status, and cancellation; keep diagnostics, approvals, and recovery operations in their relevant workflows.

### Removed

- Remove configuration-based default-agent routing and the `--default-agent` installer option.
- Remove obsolete session inspection and attachment surfaces from the user-facing workflow.

## 0.4.0 - 2026-07-29

### Changed

- Focus Agent Knock Knock on one transparent execution path: shared tmux terminals for Codex and Claude Code.
- Reuse exactly one idle agent pane in the configured workspace and fail closed when no unique safe target exists.
- Prevent a new terminal generation from replacing an active task, persist exact dispatch receipts across stores, and fence uncertain submissions until their owner is explicitly closed.
- Simplify installation, diagnostics, plugin tools, the bundled skill, and documentation around the tmux handoff workflow.

### Removed

- Remove the alternative managed execution stack, blanket background approval, non-tmux agent integration, model/proxy overrides, and callback bootstrap contract.
- Remove obsolete quickstarts, smoke tests, simulations, modules, and maintenance assets for unsupported execution paths.

## Earlier releases

The pre-0.4 history remains available in [GitHub Releases](https://github.com/scotthuang/agent-knock-knock/releases).
