# Changelog

## 1.0.69 — 2026-09-13

- 데스크탑 v1.2.1 코어(desktop-core v18, 저장소 스키마 119)를 벤더링합니다. Antigravity(agy)에 사용자가 직접 등록한 같은 이름의 MCP 항목이 있어도 실행을 거절하지 않고 그 항목만 빼고 돌며, One 이 등록한 자동화의 예약 실행이 저장된 모델 선택 때문에 멈추지 않습니다.

## 1.0.68 — 2026-09-13

- 데스크탑 v1.2.0 코어(desktop-core v17, 저장소 스키마 119)를 벤더링합니다. 첫 실행 부트스트랩이 스키마 119 를 만들고, 데스크탑이 아직 1.1.x 이면 정직하게 `AGENTLAS_STORE_SCHEMA_TOO_OLD` 로 멈춥니다.

## 1.0.67 — 2026-08-30

- Cloud local state, source markers, and project credential imports now use
  anchored no-follow atomic publication and fail closed on directory/file swaps
  or unexpected successors.
- ACP JSON-RPC notifications no longer receive responses, while explicit
  `id: null` requests retain normal request semantics.
- CLI build/MCP output now keeps JSON, YAML, quiet, header, and color modes
  consistent and returns typed errors for contradictory machine-format input.
- Workforce candidate sets now require the exact WorkOrder ontology version,
  and Experience packs reject duplicate MCP requirement identifiers before
  they can persist invalid state.
- MCP consent is bound to the command, arguments, and relevant environment
  material at approval time, while Hub installs recheck managed parents and
  publish atomically without following path swaps.

## 1.0.66 — 2026-08-30

- API 스트리밍 요청이 연결·본문 읽기 중 실패하거나 취소돼도 부모 취소 리스너와 idle 타이머를 즉시 정리해, 오래 실행한 Terminal 세션에 실패한 요청의 리스너가 누적되지 않게 했습니다.
- MCP 정책·동의·Experience 상태 JSON은 이제 no-follow 파일 디스크립터와 읽기 전후 identity 검증을 사용하며, private-state 잠금은 살아 있는 소유자를 시간만으로 탈취하거나 이전 소유자가 후속 잠금을 지울 수 없게 했습니다.
- `read` 권한의 Memory Event는 One 영구 원장에 기록되지 않으며, 쓰기 권한에서도 큐레이션을 통과한 제한된 후보만 안전한 원장 경로와 소유자 검증 잠금 안에서 중복 없이 전달됩니다.
- CLI 환경설정도 같은 bounded no-follow JSON 및 live-owner 잠금을 사용해, 오래 실행 중인 설정 저장을 시간만으로 탈취하거나 링크 경로에서 설정을 읽지 않습니다.
- Graph 인터뷰는 명시 또는 역할 기본값으로 선택한 Ollama를 이제 로컬 API 루프로 실제 실행하며, `bin`이 없다는 이유로 선택을 버리거나 다른 CLI로 바꾸지 않습니다.
- ACP client 연결이 닫히면 진행 중 child뿐 아니라 대화 유지를 위해 남아 있던 idle Session과 Orchestrator도 모두 종료해 편집기 재연결 뒤 좀비 런타임이 쌓이지 않게 했습니다.
- Workforce·Storm이 쓰는 Core JSON 캡처는 stdout을 16MiB로 제한하고 기본 120초 안에 끝나지 않는 Python 호출을 종료해, 손상된 Core 응답이 Terminal 메모리나 실행을 무기한 점유하지 않습니다.
- 자동화 on/off/run/remove의 ID 접두사는 `%`·`_`를 와일드카드로 해석하지 않고, 여러 자동화와 겹치면 임의 행을 조작하는 대신 전체 ID를 요구합니다.
- 직접 생성한 Operational RunReceipt도 반환된 실제 생성 시각을 fallback run identity에 사용해, `createdAt`을 생략한 호출이 모두 같은 `undefined` 기반 ID로 합쳐지지 않습니다.
- Desktop이 저장한 자동화의 `antigravity`/backend/source/model/effort 핀을 Terminal도 같은 실행 정체성으로 해석하고, 정확 핀 실패 시 Dashboard 역할 풀의 다른 공급자로 넘어가지 않습니다.
- Memory Event 큐레이션은 후보 수·본문·증거를 제한하고 단일 원자 SQL로 중복을 막으며, 기존 private 프로젝트 디렉터리의 regular 단일-link JSONL에만 bounded append합니다.
- Experience 적립은 누락·잘못된 권한을 read로 막고, 부분적으로만 전달된 exact agent binding을 설치본이나 로컬 해시 정체성으로 조용히 대체하지 않습니다.
- Provider resume ID 저장은 시작 시 읽은 ID를 compare-and-swap 조건으로 사용해, 같은 채팅의 늦게 끝난 이전 턴이 더 최신 세션 연속성을 덮어쓰지 않습니다.
- Hub 응답은 stream-readable 본문만 16MiB 안에서 읽고, CLI 세션 파일도 bounded no-follow identity 검증을 통과한 private JSON만 인증 증거로 사용합니다.
- Project 초기 시드는 실제 private `.agentlas` 디렉터리와 single-link regular 파일만 만들거나 재사용해, 미리 놓인 symlink/hardlink를 따라 외부 파일을 쓰지 않습니다.
- Project 팀 연결은 Desktop의 현재 agent/team 정본과 레거시 행을 명시적으로 구분하고, 정확 릴리스가 로컬에 증명된 컨트롤러만 최대 64개 bounded 팀에서 실행합니다.
- Cloud 설치·복구는 private 실제 설치 루트와 bounded single-link 저널만 신뢰하고, 심링크·하드링크·특수 엔트리로 바뀐 destination/staging/backup을 재귀 삭제하거나 교체하지 않습니다.
- Project 활성화는 canonical 루트와 현재 private-state 무결성을 매번 확인하고, Desktop의 `antigravity` 선택을 일반 Terminal 실행에서도 `agy`로 보존하며, 능력 승인 프리픽스는 토큰 경계를 넘어 비슷한 명령을 허용하지 않습니다.
- Workforce는 누락·손상 권한을 read로 막고 `--parallel`의 실제 8개 상한을 지키며, Dashboard 역할 풀에서 첫 가용 런타임을 우선순위대로 선택하고 빈 Worker 풀은 Orchestrator 풀을 상속합니다.
- 설치 에이전트 라우팅은 BYOK·Ollama 판정의 인증·한도·연결 오류를 빈 응답으로 지우지 않고, CLI 런타임과 같이 실제 실패 사유를 보존합니다.
- 명시값·환경설정의 Desktop `antigravity` 런타임도 Terminal `agy`로 일관되게 실행하며, 정상 답변의 기술 용어 `rate-limit`을 한도 거절로 오인하지 않습니다.
- Native 모델 stdout을 16MiB로 제한하고, 생성·재사용하는 MCP 설정은 실제 private 디렉터리와 bounded single-link 파일만 허용해 비정상 스트림·링크 경로를 따라가지 않습니다.
- node:sqlite fallback도 실제 `BEGIN IMMEDIATE`/rollback과 중첩 savepoint를 사용해, 예외가 난 다중 쓰기를 부분 커밋하지 않습니다.
- Runtime capability 변환은 Desktop `antigravity`를 `agy`로 보존하고 ACP CLI를 API backend로 오분류하거나 알 수 없는 runtime spec을 제조하지 않습니다.
- Local Core Workforce 어댑터는 search→validate→prepare의 WorkOrder·Selection을 정확히 묶고, 과도하게 깊거나 큰 응답 및 prototype key를 경계에서 거절합니다.
- 로컬 모델의 파일 도구는 8MiB를 넘는 텍스트를 전체 메모리에 읽거나 쓰지 않으며, Terminal 설정 화면은 이미 제공되는 멀티모달 설정 명령을 Desktop 전용으로 잘못 안내하지 않습니다.
- 희소 cron 탐색은 긴 분 단위 루프 대신 로컬 달력의 불일치 날짜를 건너뛰며 8년 범위를 확인해, 비윤년 직후 등록한 2월 29일 일정도 다음 윤년 실행 시각을 잃지 않습니다.
- 저장 권한이 없을 때의 제품 기본값과 손상된 권한 값을 구분해 후자는 read로 막고, CLI 런타임 탐지는 PATH의 `which` 프로그램을 실행하지 않고 실제 실행 파일을 직접 확인합니다.
- Hephaestus 캡처는 시간·출력 상한이나 사용자 중단 뒤 응답 없는 child를 강제 종료하고 부분 JSON을 결과처럼 렌더링하지 않으며, bounded no-follow CLI history와 그 잠금은 살아 있는 소유자를 시간만으로 탈취하거나 이전 소유자가 후속 잠금을 지우지 않습니다.
- Graph 패키지는 중첩 비밀값까지 재귀 치환하고 그래프·매니페스트 지문을 모두 검증하며, 같은 MCP 서버를 쓰는 모든 노드를 의존성에 보존합니다.
- 모델 카탈로그와 라우팅 영수증은 bounded no-follow 단일-link 파일로만 읽고 쓰며, `route`·`call`·`hep` 요청 안의 일반 단어 `help`를 명령 도움말로 가로채지 않습니다.
- Desktop Core 캐시는 live-owner 버전 잠금과 streaming 크기·해시 검증을 사용하고, 경로 이탈·링크·특수 엔트리가 든 archive를 풀기 전에 거절합니다.

- CLI output and argument contracts now fail closed across list, run, build,
  One, roles, variants, graphs, firms, search, automations, credentials, MCP,
  Experience, Ontology, Storm, Swarm, Workforce, Cloud/upload, doctor,
  install/update/import/uninstall, login/logout/setup, project/billing,
  ACP/multimodal/memory, browser/document/plugin, environment/account, and
  connection commands instead
  of silently accepting unknown or contradictory input. Invalid commands stop
  before model, network, project, or credential mutations. JSON, YAML, quiet,
  no-header, and no-color modes now match their documented behavior.
- Help now rejects undocumented flags and trailing arguments, and the compact
  startup banner stays within the actual terminal width on narrow screens.
- Research now exposes the complete Agentlas OS 1.2.37 diagnostic, proof,
  browser-hardpoint, module, loadout, planning, read, search, and gather command
  set instead of rejecting every subcommand outside the legacy five.
- Async native help now waits for its child output, and the Local Core MCP
  transport bounds unterminated stdout responses instead of growing memory
  without limit.
- MCP connection probes now refuse malformed runtime arguments and handle
  asynchronous child-stdin failures as a failed preflight instead of risking
  an unhandled stream error.
- REPL shell commands now participate in shutdown tracking, stop on Ctrl-C or
  quit, escalate stubborn process groups to SIGKILL, and cannot survive the
  parent process as detached zombies.
- Persistent model-role changes now cover multimodal, keep Dashboard pools and
  the resolved selection in sync, and bind resumed provider sessions to the
  selected model (plus ACP permission identity where the protocol requires it).
  An explicit stop no longer launches the next fallback model, while a genuine
  ACP recovery receives its own current fingerprint and cancellation signal.
- Project credential/env files, Telegram token files, MCP consent/inventory,
  child-process shutdown, session event sinks, and generated output paths now
  enforce bounded, no-follow, project-scoped storage and cleanup contracts.
  Native context preparation also refuses broad, missing, or symbolic-link
  agent source folders instead of recreating or writing through them.
- Cloud packaging, agent evolution, route persistence, Storm/Swarm fan-out, and
  Oberon rendering now reject ambiguous or stale state rather than reporting a
  partial operation as complete.
- Concurrent Cloud list/save/delete/bind and source-marker updates now preserve
  every observed revision under private locks, reject corrupted tombstones, and
  compare receipt times chronologically instead of as text.
- Terminal palettes no longer advertise the retired `career-graph` command. Its
  project data remains preserved, while users are directed to `ontology` for
  sources and the Agentlas OS runtime for derived indexing.

## 1.0.65 — 2026-08-29

- Browser, document, and Telegram CDP flows now create and track an Agentlas-owned
  tab instead of attaching to the first page exposed by the debugging port. Existing
  pages require explicit target selection, owned temporary pages are cleaned up, and
  WebSocket attachment has a bounded open timeout.
- First-run SQLite bootstrap now starts at schema `user_version=106`, generated from
  the Desktop migration ladder, including the multimodal model-role constraint.

## 1.0.64 — 2026-08-29

- First-run database bootstrap now refuses symbolic links and non-file entries
  at `agentlas.sqlite` instead of following them for permission changes and
  runtime access.
- A competing bootstrap is accepted only after its winning database path is a
  real, non-empty file; undeletable empty placeholders now fail with the exact
  cause instead of being reported as a successful concurrent initialization.
- The public runtime guidance now reflects that Kimi, Grok, and Cursor execute
  through the shared ACP driver instead of describing their retired refusal.

## 1.0.63 — 2026-08-29

- `agentlas update --json` now reads the centralized output-mode context after
  global flags are consumed, so it emits the promised JSON document instead of
  falling back to human-readable lines.

## 1.0.62 — 2026-08-29

- Terminal sessions now preserve ACP conversation identity and history across
  editor turns, propagate cancellation and consented MCP configuration to
  Cursor/Grok/Kimi, and reject overlapping prompts instead of cross-streaming
  two JSON-RPC requests.
- Automation leases, Telegram pairing, cloud session storage, Local Core
  transport, evolution writes, experience events, project path matching, and
  memory ownership now fail closed under races and partial failures.
- The on-demand Desktop core cache is bound to the exact release SHA, includes
  every built-in plugin runtime package, and is published as the audited
  `desktop-core-v15` asset without dependency tests, fixtures, or local paths.
- npm packages exclude the generated Desktop core tree and tarball, shrinking
  the install artifact from roughly 36 MB to under 1 MB while retaining the
  checksummed v15 fetch manifest. The publication workflow enforces this
  boundary.
- `agentlas update` now bounds registry connection and body parsing so a stalled
  npm request cannot hang the CLI indefinitely.

- `agentlas acp` — Agentlas as an Agent Client Protocol agent (Phase B-3). Zed,
  JetBrains IDEs and other ACP clients can run the project controller (or an
  installed agent via `_meta.agentlas.agent`) on the runtime you subscribe to,
  with tool calls and streamed text projected onto ACP. `--info` prints the
  registry-style descriptor. CLI-only (stdout is the wire).
- kimi, grok, and cursor run through the desktop core's generic ACP runner
  (`engine/runtimes/acp-driver.cjs`) instead of being refused as "no v2
  streaming driver". Same file, same tool-call vocabulary as Desktop; an old
  core without `electron/runtime/acp.js` still refuses honestly with a repair
  hint. `agentlas doctor` lists the newly executable runtimes.
- `npm test` is the smoke gate; the stale `.internal` copy of the architecture
  sync script is gone (one canonical script under `scripts/`).


## 1.0.47 — 2026-08-14

Antigravity and the shared runtime contracts now reach the independent
Terminal surface.

- `agy` is recognized as a first-class runtime in capabilities, detection,
  resolution, permissions, and the interactive shell.
- Terminal model and runtime choices use the same runtime contract as Desktop,
  including honest no-runtime stops and project-scoped execution.
- Workforce capture, local Core transport, graph commands, and the native host
  preserve the synchronized Agentlas architecture without copying Desktop-only
  SaaS state into Terminal.

Verification: the local smoke suite passed 100 cases with 0 failures. The npm
publication gate remains the authority for whether this tag is visible in the
registry.

## 1.0.46 — 2026-08-11

Pick from a list instead of retyping a slug.

- `/search` in the shell now shows its results as a list you move through with the
  arrow keys; Enter installs the one you chose. `/graph` does the same and runs the
  graph you pick. Escape cancels either.
- Search results say what the listing actually means for you — "callable without
  installing" or "install to use" — rather than repeating the server's own enum.
- Commands now know which surface you are standing on, so the next step they print is
  one you can actually type there. Inside the shell, `search` ends with `/install <slug>`
  instead of `agentlas install <slug>`, which the shell would have refused.

## 1.0.45 — 2026-08-11

The command surface was rebuilt from one catalog, and failures stopped printing JSON.

- **Commands.** The same list used to be maintained by hand in four places, and they
  disagreed: an English screen advertised a Korean argument hint, one feature was sold
  twice under two names, and a de-duplication pass then hid `/switch`, `/list` and
  `/exit` entirely. There is now a single catalog. Aliases are a field on a command,
  never a row of their own, so a duplicate can no longer appear or be silently dropped.
- **Help.** `/help` is grouped and short — 25 lines in the terminal instead of 133 —
  ordered by what a new user needs first. `help all` lists everything; `help <command>`
  answers about that one command instead of dumping the whole list. The CLI, the classic
  REPL and the interactive shell now call the same renderer, so they cannot drift apart.
- **Removed.** `journal` reported success for runs that did not exist and read the wrong
  folder; `career-graph`'s read commands silently created project state; `plugins` was a
  second name for `plugin`. All three now stop with the exact replacement command instead
  of leaking into a paid model turn.
- **Failures.** A failed staffing run used to print a machine code followed by a raw JSON
  object, with the one useful sentence — run `agentlas login` — buried inside it and cut
  mid-escape by two stacked truncations. The sentence now comes first and the code last;
  no JSON reaches a human. Sign-in expiry is relayed intact instead of being re-wrapped.
- **Shell layout.** Output now stays above the input box instead of below it,
  the box shows what to type, the whole terminal width is used, blank lines survive,
  and `/permission` `/model` `/runtime` `/effort` work where they were only autocompleted.

## 1.0.44 — 2026-08-11

Turn the interactive shell on once and keep it.

- `/shell on` saves the choice, so plain `agentlas` opens the interactive shell
  from then on; `/shell off` returns to the classic REPL. Both shells accept the
  command, so you can always get back out.
- `AGENTLAS_TUI=1` still works and takes precedence for a single run.

## 1.0.43 — 2026-08-11

Zero runtime dependencies. The renderer now lives in this repository.

- The terminal shell's renderer and diagram sources are vendored into
  `engine/vendor/` and `package.json` declares no runtime dependencies at all.
  An exact version pin already prevented drift and tampering, but a package
  removed from the registry would still have broken installs; that last failure
  mode is now gone, and the code is ours to fix.
- Upstream copyright notices are preserved beside each vendored tree, as the
  MIT and Apache-2.0 terms require. The vendoring script refuses to run if a
  notice is missing.
- New release gate `vendor-tui-sync` fails when the vendored tree and its
  upstream differ, so the copy cannot rot silently.

## 1.0.42 — 2026-08-11

Projects, automations and firms reach the interactive shell; the shell is
enabled with `AGENTLAS_TUI=1`.

- `/projects` — every connected project with chat/task counts, and a clear
  marker for the one this folder belongs to (or an explicit warning when the
  folder is not connected).
- `/automations` — the full list with schedule, next run, run count and failure
  count; `/automations <name>` opens the detail view with recent run outcomes
  and the exact commands to run or toggle it.
- `/firms` — teams with member counts; `/firms <slug>` shows the roster.
- Table layout no longer inflates narrow status columns when a row overflows
  the terminal width.
- The shell is now enabled with `AGENTLAS_TUI=1`. Renderer internals are an
  implementation detail and no longer appear in commands, environment
  variables, or on screen.

## 1.0.41 — 2026-08-11

Desktop surfaces, measured against the desktop inventory and rebuilt for the terminal.

- `/dashboard` now mirrors the desktop control panel: a **Needs attention**
  section (waiting approvals and runs that stalled without a terminal state),
  run activity that states failures out loud (e.g. "8/11 failed" rather than a
  quiet list), automations with next-run times, most-used agents, and evolution
  proposal counts.
- `/library` — installed agents with role/kind, MCP server count, and pointers
  to env, credentials, and plugins.
- `/marketplace` (also `/bookmarks`) — Hub bookmarks and borrowed-agent careers
  held locally, with search/install/credit pointers.
- `/settings` — language, permission, active runtime, installed CLIs, and the
  resolved orchestrator/worker model roles; names what remains Desktop-only
  instead of implying parity.
- Those five honest stops now point at the interactive shell instead of claiming the
  surface is unreachable from the terminal.

## 1.0.40 — 2026-08-11

Desktop surfaces reach the interactive shell: dashboard and graph view.

- `/dashboard` (interactive shell): agents/firms/telegram badges + automations panel
  (enabled state, last run) from the local store — first of the thirteen
  Desktop-only honest stops to be lifted.
- `/graph show <name>` (interactive shell): the automation graph renders as Unicode
  box art (grok-mermaid) — condition branches, loop-back edges, and Korean
  labels align correctly. No canvas emulation; editing stays declarative.
- First-run onboarding now runs before the interactive shell starts (sequential, no stdin contention), so `AGENTLAS_TUI=1` works for
  brand-new installs too.

## 1.0.39 — 2026-08-11

Interactive shell increment 2 + architecture mirror sync.

- Experimental interactive shell (`AGENTLAS_TUI=1`): persisted history (cli-history.json
  v2 contract), Shift-Tab permission cycling (same two-step FULL arming state
  machine as the classic REPL), `!` shell passthrough (full-permission gate,
  secret masking), and `/s` `/switch` `/kill` `/rm` `/sessions` `/tree` session
  observation wired to the same orchestrator/renderer pair.
- Streaming display masks the Memory Events envelope (runtime contract, not
  user-facing text); the harvest pipeline is unchanged.
- ARCHITECTURE_VERSION mirror synced 1.7.0 → 1.7.1 (vendor regenerated from
  the desktop dist, value-level parity gate green).

## 1.0.38 — 2026-08-11

Silence was the worst failure mode — this release makes failures speak.

- The presentation boundary (`Ui.error`) now has conditions. Machine-coded
  messages (usage guidance, honest stops, server relays) pass through; only
  uncoded raw provider text is still replaced by the neutral recovery line.
  Previously every failure — including usage help for eight argless slash
  commands — collapsed into the same "One is recovering" sentence.
- `/s` `/switch` `/kill` `/rm` `/runtime` `/model` `/effort` `/permission`
  without arguments now print their usage line instead of a recovery notice.
- Workforce sign-in expiry is relayed honestly: the server's `auth_required`
  guidance reaches the user (run `agentlas login`), instead of being
  misreported as an invalid continuity receipt and then swallowed.
- `doctor` verifies the cloud session against the server instead of only
  checking that a session file exists. Expired sessions are reported as a
  warning with the login hint; offline is reported as "unverified", never as
  a false all-clear. `--json` output remains observation-only.
- Authored guidance in storm/swarm/workforce flows (planner refusals, unknown
  options, persisted receipt issues) is no longer swallowed by the boundary.
- `npm run sync:architecture` works again — the script was restored to
  `scripts/` where its relative paths are correct.

## 1.0.37 — 2026-08-10

Agentlas One can now carry its owner-bound identity and curated memory tickets
across Terminal sessions without turning the agent into the owner of a project.

- When One is explicitly enabled, Terminal loads its bounded directive at the
  per-turn system boundary and forwards only `agent_repo` and `user_identity`
  memory candidates to One's existing ledger. Project memory stays with the
  project, and a missing or disabled One workspace remains a no-op.
- The Memory Events parser accepts both the canonical ticket envelope and the
  legacy array form, so valid candidates are no longer silently discarded.
- Global `--json` output now reaches doctor, list, roles, Cloud restore, and
  upload commands consistently; machine-readable output is no longer prefixed
  by human status text.
- The built-in architecture projection includes Agentlas One as a hidden
  orchestrator rather than a top-level project or user-facing worker.

## 1.0.34 — 2026-08-06

Telegram, standalone. The terminal can now connect a Telegram bot with no desktop app.

- `connect telegram <agent|firm>` reads a bot token from stdin (never argv), verifies it
  against api.telegram.org, stores it 0600, polls getUpdates and pairs the first private
  chat, then sends a confirmation.
- `connect test <id>` / `connect remove <id>` / `connect status`. The connection core is
  plain HTTPS ported from the desktop; no Electron, no plugin, no raw JSON dump.

Not yet standalone: auto-creating the bot by piloting BotFather in a browser (the CDP
browser hardpoint makes this a tractable next layer; it needs a live Telegram web session).

## 1.0.33 — 2026-08-06

Defect sweep: ran every command with a real prompt and fixed what dumped or stalled.

- `connect telegram` / `connect status` no longer dump the raw Hephaestus router JSON —
  they show the local Telegram binding table and honestly note that bot issuance/pairing
  still live in Desktop Connect.
- `route "<request>"` shows a progress spinner during its ~13s Hub round-trip instead of
  sitting silent.

## 1.0.32 — 2026-08-06

Standalone: the terminal no longer requires Desktop or the plugin for its core flows.
(They share artifacts and settings; they are not a prerequisite.)

- `project use <agent>` / `project team <agent>…` connect the current folder as a
  project and set an ordered team, entirely from the terminal — so `run "<task>"` and
  plain REPL input work without ever opening Desktop. `project status` shows the team.
- `build "<request>"` now builds locally: the terminal runtime produces an installable
  agent package (AGENTS.md + manifest.md + README.md) and auto-installs it, instead of
  printing "open the Claude Code / Codex plugin and run /hep-build".
- Honest-stops in a project-less folder point at `project use`, not "open Desktop".

Verified standalone end-to-end: project use → run answered correctly; build produced and
installed an agent that then ran correctly.

## 1.0.31 — 2026-08-06

Interactive UX, measured against first-class REPLs with a real PTY.

- The empty prompt now guides: a dim ghost hint ("type a task · / commands · @ files
  · ? shortcuts"), `?` prints a shortcuts card, a second empty Enter points the way.
- Tab-completing a command that takes arguments appends the space, so you can type the
  argument immediately; no-arg commands are unchanged.
- A plain-language task in a folder with no connected project now says exactly why and how
  to run anyway (localized), instead of a single "recovering…" line that hid the reason.
  Every controller honest-stop carries a machine code so this can never be swallowed again.
- New PTY-driven gates (repl-guidance, honest-stop-not-swallowed) — these paths live inside
  the readline session and are invisible to spawnSync tests.

## 1.0.30 — 2026-08-06

CLI-conventions hardening, measured against clig.dev and first-class CLIs.

- A closed pipe is a reader saying stop: `agentlas … | head` no longer crashes with EPIPE.
- Unexpected crashes now print a one-line summary and a pre-filled GitHub issue URL, not just a raw stack.
- `TERM=dumb` disables ANSI colors (editor shells, some CI).
- Secrets stop landing in shell history: `creds save --value -` reads the secret from stdin;
  passing it via argv now prints an exposure notice.
- `list --json`, `doctor --json`, `roles --json` — machine contracts for scripts.
- Workforce staffing survives transient API failures: a typed transient error
  (connection closed mid-response, timeouts, overload) on a no-authority/read-only stage
  is retried exactly once; write-capable stages are never retried. A 40-minute, 2.1M-token
  live run previously died on the final re-verification call for exactly this.
- New gate: clig-conventions-contract; retry contract added to the workforce runtime gate.

## 1.0.29 — 2026-08-05

Terminal-wide audit release. Every command was executed for real; what follows fixes what that audit found.

- Native federated staffing: `hep-network` / `hep-local` / `hep-cloud` / `hep-hub` now run this
  terminal's own workforce loop with the local Agentlas-OS core federating the declared source scope.
  (They previously passed through to an external CLI stub that always answered exit 3.)
  Honest stop with install guidance when the local core is missing — no silent fallback to the public Hub.
- `workforce` now declares its sourceScope ("hub") explicitly instead of relying on the server default.
- `doctor` distinguishes installed from signed-in: local sign-in evidence per runtime, a warning
  (not "all clear") when the active runtime has none.
- New `roles` command: view and set orchestrator/worker model roles from the terminal
  (`roles set <role> <runtime> [--model id] [--effort lv]`, `roles set worker --inherit`).
  REPL `/model`·`/runtime` now say they are session-scoped and point to `agentlas roles`.
- Setup wizard prints install/sign-in guidance when the chosen runtime is missing or unauthenticated.
- `creds list` (names and stores only — values never printed), `mcp list`, Korean `help` body.
- The graph command group ships in the npm package for the first time (it landed after 1.0.28 was published).
- New gates: user-scenarios (93 real CLI invocations), local-core transport wire contract,
  doctor auth-evidence, roles round-trip, onboarding guidance, EN/KO help sync.
- `agentlas <command> --help` reaches the command's own help. It printed a two-line stub
  scraped from the help table, so `graph --help` never showed the eight lines `graph help` has —
  and that is the spelling people try first. (The gate had pinned the stub as correct; its
  contract now asks whether real help was shown.)
- `graph install --name "<new name>"` works. The documented flag had never worked: its value was
  appended to the file path, so the install died with "no such file".
- `graph show` stops indenting a straight chain deeper at every step — fourteen steps meant
  twenty-eight columns. Depth now marks real branches (a fork, a failure exit).
- Building a graph follows your language setting. One Korean character anywhere in the request
  forced the interview to Korean while `graph show`, the list, and errors stayed English.
- Graph steps written as code declare the pip packages they import, and a verification step is
  now required whenever a step that changes something outside sends out a value an earlier step
  computed — an unattended run must not ship an empty or invented result.

## 1.0.26 — 2026-08-03

- **`agentlas list` stops letting the terminal cut its own output.** Slugs were
  padded to a fixed width, so a longer one pushed that row's description out of
  alignment, and the tagline had no bound at all — the terminal cut it mid-word
  with no marker, so a short description and a truncated one looked identical.
  Rows reached 109 display columns in an 80-column terminal. The slug column now
  sizes to the widest slug present and the tagline is truncated on a word
  boundary with an explicit ellipsis, measured in display cells so Korean and
  other wide characters are counted at their real width. COLUMNS is honoured when
  stdout is not a TTY.

## 1.0.25 — 2026-08-02

- **Every Terminal session now closes a governed learning episode.** Direct
  agent runs, project sessions, automation, and firm orchestration share the
  same turn receipt, Memory Ticket, curator, scoped-memory, and Experience
  intake boundary instead of merely printing or discarding `Memory Events`.
- Hidden control envelopes are removed from `run --print` and every downstream
  consumer while firm-owned delegation remains available to the firm
  orchestrator through a private control channel.
- Successful exact-agent runs use a no-authority connected-model judgment for
  canonical task classes. No keyword dictionary or default task class is used;
  valid judgments create run receipts even when no durable memory candidate is
  promoted.
- Memory emitter turn IDs are separated from punctuation, and the Experience
  bridge now accepts structured task signatures from both current sessions and
  legacy runtime loadouts.

## 1.0.24 — 2026-08-02

- **Firm runs now finish the real dependency chain.** Independent production
  roles still run in parallel, integration waits for their files, and release
  verification runs only after the integrated surface exists.
- **A verification failure triggers one bounded repair and re-check.** Terminal
  no longer ends with a truthful failure report while leaving a fixable product
  defect unresolved, and the newest result for each role determines completion.
- Firm names/slugs are directly callable from `agentlas list`, and final user
  output removes orchestration fences, internal skill reports, and verification
  control tags.

## 1.0.23 — 2026-08-01

- **Semantic routing stays with the connected model.** Image-capability and
  installed-agent routing no longer retain regex hints, keyword glossaries,
  deterministic role vetoes, or caller-authored fallback labels. If the model
  cannot return a valid judgment, the decision remains unavailable.
- **Fresh Terminal databases match Desktop schema 86.** The retired
  chat-level hired-agent roster is absent from the bootstrap schema; project
  order and current-turn task-force targets own controller and helper binding.

## 1.0.22 — 2026-08-01

- **Task classes no longer come from a fixed keyword dictionary.** An explicit
  user/project declaration remains authoritative; otherwise only the connected
  model may classify the full request, and an unavailable or invalid judgment
  stays unresolved.
- Preserve an explicit `declaredTaskClasses` value across the Desktop loadout
  boundary so removing the dictionary fallback does not discard user-owned
  structured intent.

## 1.0.21 — 2026-08-01

- Align the independent Terminal sentence with the exact cross-surface
  architecture-sync marker used by the Web release gate.

## 1.0.20 — 2026-08-01

- Restore the explicit independent-Terminal and private Cloud list/restore
  guidance required by the cross-surface architecture contract. This corrects
  the public README without changing the v1.0.19 runtime behavior.

## 1.0.19 — 2026-08-01

- **Ordinary runs now honor Desktop Work project ownership.** From a connected
  project folder, the first member of the saved ordered agent pool is the task
  controller and the remaining members are task-scoped sub-agent candidates.
  Missing projects, empty teams, remote-only controllers, and unavailable
  controller releases stop without silently selecting a default agent.
- Exact-agent invocation remains available as an explicit advanced path. The
  separate route preview is judged by the connected model against the installed
  roster and remains unresolved when the evidence or model is unavailable;
  regex intent gates, keyword dictionaries, and lexical fallback selection were
  removed.
- The fresh Terminal schema now matches Desktop project-first schema v85,
  including ordered project pools and AutomationSession transcript ownership.
- The npm publication gate now verifies against the exact Agentlas OS v1.1.92
  source commit used by Desktop instead of an older Core snapshot.
- Documentation now distinguishes verified macOS behavior, Linux CI coverage,
  and the provided but not independently end-to-end verified Windows launcher.

## 1.0.18 — 2026-07-31

- **Private Agent Cloud inventory is readable by default.** `agentlas cloud
  list` now identifies the owner-private scope, shows how many rows are
  displayed, and labels slug, kind, callability, update date, and name instead
  of dumping an unlabeled TSV stream.
- The inventory ends with exact next actions for machine-readable revision
  inspection and restoring one selected package. `--json` remains the stable
  full-fidelity contract.

## 1.0.17 — 2026-07-31

- **Terminal requires the verification-aware Context Map engine.** Context
  commands now select Agentlas OS 1.1.86 or newer, whose impact graph connects
  code changes to tests, test commands, CI workflows, and product-version
  contracts, including local test files intentionally excluded from Git.
- A stale Core can no longer satisfy the Terminal context capability merely by
  exposing the old module path; the version gate fails closed before execution.

## 1.0.16 — 2026-07-30

- **Project-scoped plugin listing now fails closed.** A missing, unsafe, or
  uninitialized `--project` path returns a clear error instead of silently
  showing the global Hub catalog as if project compatibility had been checked.
- Plugin listing names its actual scope: the global Hub catalog does not claim
  to evaluate project compatibility or local installation state.
- Unknown, conflicting, or incomplete plugin flags now return usage errors
  instead of being ignored.

## 1.0.15 — 2026-07-29

- **Agent Cloud saves work from a new machine or fresh clone.** Before writing,
  the terminal resolves the signed-in owner's exact asset revision by
  `slug` and scope, then keeps the conditional-write guard on that revision.
  A missing local receipt no longer turns an owned asset into a false create
  conflict.
- **A real stale-copy conflict stays fail-closed.** The terminal stops before
  replacing a newer server revision, reports its identity, and offers an
  explicit `--overwrite` only when the owner deliberately chooses the current
  folder over the newer copy.
- Conflict messages now describe ownership and the next command instead of
  exposing storage precondition terminology.

## 1.0.14 — 2026-07-29

- **Write-capable commands now prepare every project automatically.** The first
  `run`, `storm`, `swarm`, or workforce execution in any folder installs the
  same private, merge-only Agentlas project infrastructure through Core. This
  is based on the folder the user opened, not on the Agentlas source checkout.
  Read-only commands remain passive and do not create files.
- **Per-command help works before database startup.** Commands such as
  `agentlas run --help` and `agentlas workforce --help` no longer require an
  SQLite driver or open the project database just to print usage.

## 1.0.13 — 2026-07-28

- **MCP servers reach the chat again.** `runNativeTurn` only injects them at
  `full` permission and that gate was right, but `sessions/session.cjs` never
  put `mcpServers` in the request — zero callers — so no CLI ever received a
  server. `agentlas mcp probe` printed "connected" while the turn that followed
  could not use it. Turns now carry servers the user already consented to;
  nothing new is asked mid-turn, because a turn is not a place a user can answer.
- **The shared database stops taking a write lock every turn.** Four
  `CREATE TABLE IF NOT EXISTS`, five indexes and an `ALTER TABLE` ran on every
  single turn against the file Desktop also uses. All idempotent, all taking the
  lock; during a Desktop migration that burns the 15s busy timeout and every
  call site swallowed the failure. Schema repair is once per connection now, and
  the three copies of `ensureMemoryContextColumn` are one function.
- **Rows written here are checked for referential integrity.** `foreign_keys` is
  a connection property, not a file property — Desktop opened with it ON and the
  terminal did not, so terminal writes skipped the check on shared tables.
- **A zero-byte database file no longer blocks first run forever.** One stray
  `sqlite3 <missing-path>` left an empty file, and every run after that read
  "already exists" and died on `no such table` with nothing visible to explain it.
- **Bootstrap schema is current again** (v81; it was a v45 snapshot from
  2026-07-07), and a mismatch with Desktop's migration target now fails a gate.
- **An engine update landing mid-run cannot mix two releases.** Core roots
  resolve to their real path, so a long run keeps the modules it started with.
  The next call still picks up the new release.
- `/ontology` says what it manages — this project's knowledge sources, not the
  engine's knowledge runtime. The command itself is unchanged.

## 1.0.12 — 2026-07-28

- **Orchestrator/worker model roles now resolve from ordered candidate
  pools.** The shared `model_role_members` table (Desktop schema v80) holds
  n candidates per role in priority order; the terminal picks the first
  member that is actually executable here, records every skipped member
  with its reason, and never silently substitutes a lower-priority runtime
  when all members are unavailable — the head member is used and the skip
  list is preserved. An empty worker pool inherits the orchestrator pool,
  matching the single-row inherit contract, and databases without pools
  keep resolving through the v79 single-row and legacy `active_runtime`
  ladders unchanged.
- **Workforce escalation is bounded and receipted end to end.** A worker
  that violates the handoff output contract twice — or is named in two
  consecutive verifier failures — gets exactly one orchestrator-role
  retry, stamped with `escalated-after-failure`, the failure count, and
  the attempt number; a failing escalation stops honestly instead of
  looping or downgrading.
- **BYOK Anthropic calls mark the system prefix as a prompt-cache
  breakpoint.** Real Anthropic endpoints receive the system prompt as one
  `cache_control: ephemeral` block (~90% cheaper cached input on hits;
  a silent no-op below the per-model minimum). Anthropic-compatible
  endpoints (GLM/Kimi/DeepSeek) keep the plain string form they expect.
- Model-allocation receipts split "no allocation was provided"
  (`allocation_not_provided`) from "the allocation was malformed"
  (`invalid_ai_allocation`), and real invocations now retain the
  provider-reported token usage per role instead of discarding it.

## 1.0.11 — 2026-07-27

- **The slash palette repaints in place instead of stacking copies of
  itself.** Every keystroke left the previous frame on screen, so a few
  arrow presses filled the terminal with duplicate palettes and pushed the
  prompt out of view. Two causes, both measured on an emulated terminal:
  the frame was drawn with the cursor saved and restored by absolute
  position, and the frame was 18 lines tall with no regard for the window.
  In a REPL the prompt sits at the bottom of the screen, so drawing below
  it always scrolls — and after a scroll the saved absolute row points at
  different content, so the next repaint erased the wrong region and left
  the old frame behind. The palette now returns to the prompt with a
  relative cursor move, which survives scrolling, and never draws a frame
  taller than the window: the list shrinks around the highlighted entry,
  and the selection detail folds away before the list does, so the
  highlighted row and the controls hint survive at any height. Verified at
  14, 18, 24 and 50 rows — one palette on screen, prompt intact.
- Quitting no longer announces a wait for commands that finish in
  milliseconds; the notice now appears only after 400ms.

## 1.0.10 — 2026-07-27

Four defects in the REPL's slash surface, all found by sweeping for the shape
that produced 1.0.8: a v2 caller using a v1-era contract.

- **Quoted arguments survive.** Slash arguments were split on whitespace, so
  the quotes the palette itself advertises (`/search "<what you need>"`) were
  passed through as part of the query — `/search "hello world"` searched for
  `"hello`. The quote-aware tokenizer the top-level CLI uses was exported but
  had no call sites; the REPL now uses it.
- **Aliases work inside the REPL.** `agentlas hep-network …` was accepted
  while `/hep-network …` answered "unknown", because alias resolution lived
  only in the top-level dispatcher. Both surfaces now resolve the same names,
  and a test pins every alias to a command that actually exists.
- **A command issued just before `/quit` is no longer discarded.** Slash
  commands are async and were fire-and-forget, so closing the prompt resolved
  immediately and the process exited mid-flight: `/search …` followed by
  `/quit` printed nothing at all, while the same pair typed 25 seconds apart
  worked. In-flight commands are now awaited — bounded at 30s, so quitting
  can never hang — and the wait is announced rather than silent.
- **The first-run wizard's language applies to the whole session.** Choosing a
  language wrote it to preferences and to `ui.lang`, but not to `ctx.lang`, so
  the banner switched while `/help`, the palette, orchestrator notices and the
  shortcut hints stayed in the OS-locale language until the next launch.

## 1.0.9 — 2026-07-27

Three repairs of one mistake, found by a live run that a 4-agent task force
(two of them managers over 8 and 10 sub-workers) completed in full before the
result was thrown away.

- **Field bounds are now stated in the prompt that must obey them.** A nested
  manager wrote a synthesis brief over 2,000 characters and the whole run —
  20 model calls, 14 minutes, every worker's finished output — was discarded
  on a contract error. The engine enforced that ceiling and had never told the
  manager it existed, so the one repair attempt it does allow failed the same
  way. Every enforced bound now appears in the stage's schema requirements
  with headroom (1,900 against a 2,000 ceiling).
- **An empty worker deliverable reaches its retry.** The corrective re-run had
  always existed but a contract assertion fired first, so it was dead code.
- **A failed nested team leaves a real ledger.** Nested executions were
  recorded only on success, so a mid-flight failure left `nestedExecutions`
  empty while 20 model calls had already been billed, and the failure receipt
  minted an `invocationId` with `crypto.randomUUID()` that had never named a
  real call. Nested runs are now written as `running` when they start and
  updated per stage; stages that never ran stay `null` rather than invented,
  and failures carry the real invocation id.

These four defects (with the verifier overflow in 1.0.7) share one shape: a
fail-closed assertion placed ahead of the repair path it makes unreachable,
enforcing a limit the other side was never told. Four regression tests pin it.

## 1.0.8 — 2026-07-27

- **Arrow keys navigate the slash palette instead of collapsing it.** Moving
  the highlight also wrote the highlighted command into the input line, and
  the candidate list is derived from that line — so the list became a function
  of the selection rather than of what you typed. Typing `/s` offered nine
  commands; two presses of Down rewrote the line to `/switch` and cut the list
  to two, leaving `/spawn`, `/steer`, `/search`, `/storm` and `/swarm`
  unreachable no matter how many keys you pressed. Arrows now move the
  highlight only and leave your query alone. Deleting the line rewrite was not
  enough on its own: readline treats Up/Down as history navigation and a
  prepended keypress listener runs first but cannot suppress that default, so
  the query is now restored if readline moved through history.

## 1.0.7 — 2026-07-27

- **The selection prompt no longer carries the whole candidate set.** Measured
  on a live 30-candidate search, the complete set was 116KB — roughly 30k
  tokens shipped on the single most expensive call of every run — while the
  leader only reads names, communities, roles and top skills to staff a team.
  Digests, package hashes and qualification evidence were paying for prompt
  space and then being re-verified in full by the Hub anyway. The leader now
  receives a projection: **2.8k tokens, a 91% reduction**, with every exact
  `agentReleaseId` preserved so the leader still authors its own exact
  selection and the Hub still validates against the complete set.
- A verifier that reports absence as `[""]`, `[null]` or `[{}]` no longer
  fails the run on a contract error; non-empty non-string issues are
  serialized rather than dropped, and oversized issues still go through the
  bounded schema repair that shortens them without losing intent.

## 1.0.6 — 2026-07-27

- **The startup banner is back.** The v2 REPL called `renderBanner` with the
  v1 contract — no `ui`, and using the return value as a string — so it threw
  a TypeError on every launch, and an argument-less `catch` disguised the
  crash as a one-line `agentlas <version>` fallback. Nobody could see it,
  including the tests. A banner contract test now guards it.
- **Per-stage model assignment.** One workforce run has stages with very
  different demands: the leader must author a large exact schema (measured:
  Haiku failed it twice in a row), while a worker writes one packet of prose
  (measured: Haiku workers produced real code patches in the SWE run). The
  engine used a single model for all of them. Stages now resolve their model
  independently:
  `AGENTLAS_WORKFORCE_MODEL_LEADER` (leader/selection/planner/refinement),
  `AGENTLAS_WORKFORCE_MODEL_WORKER`, `AGENTLAS_WORKFORCE_MODEL_SYNTHESIS`,
  `AGENTLAS_WORKFORCE_MODEL_VERIFIER`. Unset stages inherit the leader
  setting, and with nothing set the behaviour is byte-identical to before.

## 1.0.5 — 2026-07-27

- A verifier that reports "no issues" as `[""]` instead of `[]` no longer
  fails the run on a contract error. An empty string is a mis-spelling of
  absence, not content, so it is normalized away before the issue contract
  is checked — a passing verification stopped the last step of a real run
  this way.

## 1.0.4 — 2026-07-27

**The hub boundary stops guessing.** Owner decision after live runs: rules
that infer private data from shape were removed rather than tuned, because
each one refused work orders whose flagged phrase *was* the task — a slash
between Korean words read as a file path, "멱등키 설계" read as a credential
assignment, "고객 ID를 조회하는 API" read as a labeled identifier. No repair
was possible, so the request simply died.

- Gone: path inference from a slash, labeled-identifier inference, UUID/IP/
  phone shape matching, keyword-adjacency credential matching.
- Kept: forms that can only be one thing — issuer-prefixed provider tokens,
  PEM headers, JWTs, credentials embedded in a URL, email addresses.
- Those are now **redacted from the outgoing text instead of refusing the
  run**, and the redaction is printed, so a pasted secret never leaves the
  machine and the task still proceeds. `AGENTLAS_HUB_BOUNDARY=off` sends
  text verbatim.
- Upload and packaging are unchanged: they already block by file identity
  (`.env*`, `*.pem/key/p12`, `credentials*`, `id_rsa`), which is fact rather
  than inference.

Shared fixtures (`privacy-guard-fixtures/`) and `scripts/sync-privacy-guard.sh`
now pin this contract across the terminal engine and the server.

## 1.0.3 — 2026-07-27

Live `workforce` runs surfaced four defects that no unit gate could reach.

- **A slash after Korean/Japanese/Chinese text no longer reads as a file
  path.** The hub-boundary guard's absolute-path lookbehind excluded only
  ASCII, so ordinary phrases ("진단/멱등키", "한국어/영어") were rejected as
  private paths — and the phrase being the task itself meant no repair was
  possible. Shared fixtures now pin this in both this engine and the server
  (`scripts/sync-privacy-guard.sh`).
- **Bundle preparation is no longer killed by the connect timeout.** The
  15s "connect" budget actually measured time-to-response-headers, and the
  server computes a multi-slot roster before its first byte, so preparation
  died as a transport error. Workforce calls now use their own budget.
- **Selection cycle rules match the Hub exactly.** Local validation only
  checked handsOffTo/reportsTo, so a `reviews` cycle passed locally and came
  back as a Hub rejection. All relations and self-edges now count.
- **A worker that exits non-zero reports its stdout tail too**, so a failure
  whose stderr holds only unrelated warnings is no longer a dead end.

Also in this release:

- **Live narration**: a `workforce` run now prints the slot count and hub
  menu size, the picked agent per slot by name, hub acceptance, each worker
  as it starts, and the synthesis→verification transition.
- **One name per feature across platforms**: `hep-network`, `hep-cloud`,
  `hep-build`, `hep-call`, `hep-search`, `hep-upload`, `hep-storm`,
  `hep-browser`, `hep-connect` now work as terminal commands, matching the
  skill names used from Claude Code and Codex. The typo guard suggests them.

## 1.0.2 — 2026-07-27

Workforce execution-contract fixes. Every worker in a `workforce` run now
knows its exact execution authority, and the run recovers honestly instead
of shipping broken output:

- Tool-less (no-authority) workers are told explicitly that zero tools are
  granted and that the deliverable must be authored directly in the reply.
  Previously a borrowed worker was silently stripped of tools, tried to
  call them anyway, leaked raw tool-call markup into deliverables, and
  produced empty output on content-type tasks.
- Worker handoffs are gated: leaked tool-call markup or an empty
  deliverable triggers exactly one corrective re-run with a repair
  directive; a repeat violation stops the run honestly with
  `worker_output_contract_violation` (never a silent cleanup).
- A verifier rejection now triggers exactly one corrective synthesis pass
  with the verifier's issues attached, then a re-verification. A second
  rejection still fails honestly (`workforce_verification_failed`), now
  reporting both attempts' issues.
- Selection handoff graphs are validated locally for circular
  handsOffTo/reportsTo chains, so the structured repair loop fixes a cyclic
  task force before the Hub sees it (previously a `task_force_cycle`
  round-trip rejection).
- Failure display: verifier/server `issues` arrays are printed line by line
  instead of being truncated inside a capped JSON blob.

## 1.0.1 — 2026-07-27

- Fixes the two gates that failed on the v1.0.0 tag (never published):
  project bootstrap no longer applies the context-map minimum-version gate
  when probing Core capability — the real probe is
  `agentlas_cloud/project_bootstrap.py`, and a source checkout without
  version metadata (exactly what CI pins) was being filtered out, skipping
  bootstrap entirely; and the smoke gate now asserts that `doctor` produces
  a report rather than that the machine happens to have an agent CLI
  installed (`doctor` still exits non-zero when it finds problems, which is
  what scripts want).

## 1.0.0 — 2026-07-27 (tagged, not published)

- The 13,347-line v1 engine monolith is replaced by a modular v2 engine
  (one concern per module: core/ runtimes/ agents/ sessions/ ui/ commands/
  cloud/ hub/ mcp/ automation/ workforce/ storm/ experience/ project/
  hephaestus/ oberon/ cloud-assets/). The full v1 command surface (56
  commands, plus `uninstall` and `billing`) is live; nothing is stubbed and
  there are no facades. The complete v1 engine remains recoverable at git
  tag `legacy-v1-engine-snapshot`.
- Multi-session subagent orchestration (Orca) is first-class: every run —
  foreground chat, one-shot, storm/swarm worker, automation run — is a
  session owned by one orchestrator. Subagent sessions persist as Desktop
  division sub-chats (`kind='division'` + `parent_chat_id`). In the REPL:
  `/spawn /sessions /tree /s /steer /kill /rm /broadcast`; typing during a
  running turn queues steering on the resume session; ctrl-c interrupts the
  turn. Background turn completions surface as one-line notices.
- Cross-product contracts preserved and gated: shared Desktop SQLite schema
  (user_version=45) and userData; runtime-doctor 3-product parity
  (sync-runtime-doctor.sh PASS); experience taxonomy checksum;
  desktop-terminal ontology loadout v2; portable Experience Bundle v1;
  workforce ontology digests; mcp-child-launch env boundary; pinned
  Agentlas OS Core harness. The known dev-only Hephaestus root defect and
  the terminal-owned Desktop .app self-updater were removed (the latter
  belongs to Desktop; `agentlas update` is npm-channel only).
- Product-model parity with the current Desktop, not with v1: the Hub is
  borrow-first, so `install` refuses call-only listings (bookmark or
  `agentlas call`), instruction-less packages, trust grades below A/B, and
  web-only agents, with Desktop's exact wording; `uninstall` mirrors
  Desktop's firm-membership guard. Hub plugins register stdio servers
  disabled and needing approval (the table is shared with Desktop, so an
  auto-enabled row would have bypassed Desktop's own gate); remote MCP
  endpoints must be https and a real `/mcp`|`/sse` path. Automation runs
  execute in Desktop-identical hidden division sessions and skip
  hub/browser/computer-use rows without consuming the lease or the
  scheduled occurrence.
- New-user protection: an unknown one-word argument is refused with an
  edit-distance suggestion instead of being spent as a model call (a typo
  used to start an agent and run shell); Desktop-only screen names
  (site, trex, prompts, dashboard, marketplace, settings…) stop honestly;
  invalid `--permission` values are refused before any model call instead
  of being silently downgraded to read; `no_runtime` now prints the exact
  CLI install commands.
- Release validation pins Agentlas Core v1.1.67 commit
  `04258b7541f604479dc04279146a506e363ad85e` (carried from 0.9.10).
- smoke gate: 54 checks (surface, no-arg guards, fresh bootstrap, 30+
  restored/new contract tests, runtime-doctor 3-product parity) — all
  green. Verified end to end against a packed tarball installed with
  `npm i -g` into a clean prefix and a pristine userData.

## 0.9.10 — 2026-07-26

- `agentlas context refresh|refs|slice|impact|verify` now invokes the installed
  Agentlas Core module directly. Context commands no longer fall through the
  natural-language Hephaestus command route.
- Context Slice generation refreshes the project fingerprint before each
  concrete Terminal task, so a long-running Terminal session sees newly added
  or changed CommonJS, ESM, TypeScript, and JavaScript files.
- Release validation pins Agentlas Core v1.1.67 commit
  `04258b7541f604479dc04279146a506e363ad85e`, including Code Map v2 backlinks,
  functional Sitemap dependencies, and fail-closed impact verification.

- Concurrent Terminal work against the Desktop-shared SQLite database now uses
  one bounded lock policy. Every Terminal write transaction acquires writer
  authority before reading mutable shared state, preventing deferred
  read-to-write upgrades from failing with `database is locked` after a
  provider already completed the user's work.
- One-shot runs now honor the saved read/write boundary across run, firm,
  Stormbreaker, swarm, build, Workforce, and context surfaces; an explicit
  `--permission` remains a session-only override.
- `agentlas context` invokes the compatible Agentlas Core context-map
  capability directly and fails closed when it is unavailable. Older
  Hephaestus launchers can no longer reinterpret `context verify` as a Hub
  search. When multiple local Core installations coexist, Terminal now checks
  bounded version metadata and skips an earlier runtime that cannot satisfy the
  v1.1.66 context contract.
- Scheduled automation output now renders only the model's final answer instead
  of leaking Claude or Gemini stream-protocol JSON. The slash palette also
  respects a real 40-column terminal while preserving arrow-key selection.
- Top-level runtime failures follow the saved Terminal language, including
  unknown runtime names and the no-runtime-available recovery message.
## 0.9.9 — 2026-07-26

- In an explicitly initialized project, ordinary runs, firms, Stormbreaker, and
  Workforce now receive the same local Context Slice from Agentlas OS v1.1.66
  after the task is concrete. The slice carries inherited goals and constraints
  plus exact definitions, backlinks, and structurally related files without
  sending the project map to Hub or Cloud.
- Read, write, and full task permission no longer doubles as consent to create
  `.agentlas/` or edit `.gitignore`. `agentlas project status` is passive, and
  only the explicit `agentlas project init` boundary creates private project
  state after announcing the side effects.
- Workload-routing receipts now conform to the public v1 nested schema, treat a
  missing model/runtime pair as unresolved, and fail closed on unknown required
  metadata or ambiguous duplicate model identifiers.
- The shared architecture seeder is monotonic: it preserves newer or
  unparseable shared state, upgrades older state atomically, and repairs only
  missing built-ins at an equal version instead of flipping the Desktop-shared
  database back to an older Terminal bundle.
- Interactive output is append-only while a task runs, preserves long streamed
  output and scrollback through resize/cancellation, wraps command meaning at
  narrow widths, and keeps saved runtime, permission, lifecycle, and Korean/
  English status text truthful.
- Release validation targets the exact Agentlas OS v1.1.66 contract commit
  `3f6f9ac3929b9238330de18c758ba200fb371017`.

## 0.9.8 — 2026-07-25

- No more silent keyword fallback. When the connected model can't judge a route
  (no runtime, or the model timed out / returned junk), Agentlas no longer picks
  a specialist by keyword — it answers with the plain assistant and says why. The
  note distinguishes "no model connected" (connect one) from "the model didn't
  answer in time" (retry / check it), so a transient timeout isn't mistaken for a
  missing model. Image-capability routing is likewise model-only: a keyword guess
  never hijacks which runtime an agent runs on.
- The embedded Agentlas OS runtime's own judge (content-guard, pipeline,
  research, privacy) now uses this host's connected model too, via a universal
  callback — so provider/CLI users, not only local Ollama, get real judgment
  there, with no model hardcoded. Pins Agentlas OS v1.1.62.

## 0.9.7 — 2026-07-25

- Fix: the resident judge now reaches API/Ollama/BYOK runtimes, not only CLI
  subprocess runtimes. Previously, when your connected runtime was Ollama or a
  BYOK API model, every route, intent, and classification silently used the
  deterministic wordlist fallback because the judge was wired to null — so a
  non-English request the keyword lists could not read never got a model
  verdict. The judge now runs on whatever runtime you actually have connected,
  and its timeout signal aborts the underlying request cleanly.
- Fix: the judge is installed at startup, before the first routing decision.
  It was previously wired only inside the run turn, which happens after routing,
  so the very first auto-route in a one-shot always fell back.
- Routing gives the model a more generous deadline (a one-shot pre-run gate), so
  a slower local model is judged rather than frequently falling back. When it
  still cannot answer in time, the route receipt says so explicitly.

## 0.9.6 — 2026-07-25

- Agent and App Builder routing is now decided by the connected model: lexical
  scores only recruit candidates, and the model can route a request the keyword
  lists never matched (any language). The App Builder consent handshake is
  unchanged, and every route receipt says whether the connected model or the
  deterministic fallback decided.
- Whether an agent produces images (and therefore which runtime runs it) is now
  judged by the connected model from the agent's own identity, with the old
  keyword list demoted to reference hints. Conservative non-image vetoes stay.
- Task classification, routing, and image judgments all fail over to the
  previous deterministic behavior — explicitly labeled — when no connected
  model is available.
- Publication gates pin the Agentlas OS v1.1.61 runtime commit, which ships the
  same judgment-engine migration across the bundled Core runtime.

## 0.9.4 — 2026-07-23

- `plugin add` no longer registers a code-hosting page (GitHub/GitLab/Bitbucket
  repo or homepage URL) as if it were a live MCP server, even when a manifest
  row explicitly claims `transport:"http"`. A connectorless catalog entry now
  refuses honestly with its docs link instead of writing an unreachable
  server into the local MCP config.
- stdio rows (`command`+`args`+`envKeys`) from a plugin manifest now install
  correctly into the local MCP server registry.
- `plugin-add-contract` runs as part of the regular smoke suite.

## 0.9.3 — 2026-07-20

- Preserve the terminal UI spinner lifecycle through the memory-output guard,
  so completed one-shot Claude/Codex turns exit cleanly instead of throwing
  after the model result has already been printed.
- Keep Agentlas Terminal focused on independent agent and team execution; this
  release does not add an Agentlas One surface.

## 0.9.2 — 2026-07-20

- Require the installed or Desktop-bundled Agentlas Core runtime to include the
  canonical Workforce WorkOrder and Selection schemas before Terminal selects
  it. Incomplete older bundles are skipped so another valid runtime candidate
  can be used instead of failing immediately before execution.
- Pin cross-platform and npm publication gates to the same Agentlas OS v1.1.50
  commit shipped by Agentlas Desktop 0.8.58.

## 0.9.1 — 2026-07-16

- Record exactly one compact Memory Ticket receipt for every completed,
  failed, or cancelled user turn, including turns with zero durable memory
  candidates and resumed Claude/Codex sessions.
- Run semantic curation as a separate no-tools advisory pass, then apply
  deterministic privacy, permission, owner, and scope gates before any durable
  write. Read-only turns keep the central receipt but never write project files
  or durable memory.
- Add owner-isolated user-global, team, agent, and project timeline lanes with
  idempotent completion and redacted Core-compatible JSONL mirrors. Raw prompts,
  transcripts, secrets, and absolute paths are rejected from logs and payloads.
- Restrict npm artifacts to the runtime allowlist; tests, fixtures, benchmarks,
  internal docs, credentials, and signing material remain unpublished.

## 0.9.0 — 2026-07-16

- Add `agentlas plugin add <slug>` and `agentlas plugin list`. The Hub has
  advertised `npx agentlas@latest plugin add <slug>` on every catalog plugin
  and serves the manifest for it, but the subcommand did not exist, so every
  listing pointed at a command that could not run. (`agentlas install` is
  agent-only and fails with "Hub agent not found" on a plugin slug.)
- Register a plugin's MCP servers from its published manifest, separating stdio
  launch commands from remote URLs so a mixed entry cannot violate the codex
  config.toml schema and take the runtime down. Reinstalling is idempotent, and
  a plugin that ships no MCP server is refused instead of reported installed.
- Translate remaining Korean runtime messages to English across the launcher,
  doctor, parity, bootstrap schema, and tests.

## 0.8.5 — 2026-07-16

- Preserve the exact bounded, host-authored contract diagnostic in each local
  model's one allowed structured-output repair prompt. The host still never
  mutates model output or replays private stage inputs, but a model can now see
  which exact Selection, WorkOrder, or planner field failed instead of receiving
  only a generic schema error.
- Keep Codex CLI Workforce execution fail-closed before the first model or Hub
  call because Codex 0.144.4 continued to expose collaboration authority after
  every available isolation flag and an isolated `CODEX_HOME` were applied.
- Pin both release workflows to Agentlas OS v1.1.45 at immutable commit
  `49752a783e944c898ea023705104661b3beb87b2`, whose finite 23-code Hub
  coverage-gap contract accepts the live aggregate response while rejecting
  unknown or identity-bearing reasons.

## 0.8.4 — 2026-07-16

- Make Workforce Ontology the default for ordinary direct, goal-like work on
  new or untouched installs while preserving an explicit `network off` opt-out.
  Sparse legacy role/tool declarations are optional semantic evidence instead
  of accidental zero-candidate hard requirements.
- Persist every benchmark run as a scorer-ready, private JSON artifact with the
  work order, content-only candidate set, host selection, three MCP receipts,
  and real planner/worker/synthesis/verifier execution evidence.
- Give the host LLM one bounded schema-only repair attempt per structured phase
  for malformed work orders, selections, or delegation plans, plus at most two
  total semantic WorkOrder refinements from redacted required-cardinality gaps
  or one valid `requestExpansionForSlots` content-expansion decision. Each
  refinement has its own audited phase, re-searches the Hub, and supersedes the
  prior search without exposing candidate identities, content, rankings, or
  history to the refinement prompt. A repeated expansion or exhausted budget
  fails closed; Terminal never fills a missing hard field, coerces expansion
  through schema repair, falls back to a lexical router, or persists raw prior
  model output. Only the idempotent Hub search may replay once after an outer
  transport/JSON ambiguity; validation and preparation remain single-shot.
- Treat `consumes` and `produces` as exact candidate-profile declaration gates,
  not ordinary workflow handoffs, and explain each hard-skill/tool/artifact or
  entity-kind coverage gap to the same host LLM. General HR decomposition now
  keeps any explicitly named specialized domain with distinct accountability
  in its own slot instead of collapsing it into generic implementation work.
- Recompute every prepared roster row's domain-separated runtime bundle digest
  from the exact selected release identity and complete directive bundle before
  execution. Only execution-plan v5 with the explicit v4 digest-schema marker
  is accepted. The shared Python/JavaScript domain rejects numbers, lone
  surrogates, unsafe keys including `__proto__`, and non-JSON values; every row
  must expose a nonblank top-level `systemPrompt`, `instructions`, or `agentMd`.
  Directive or identity tampering now fails closed, while the sanitized nested
  runtime package hash remains separate from the AgentRelease upload package
  hash.
- Execute team releases as their declared manager and every graph worker in
  exact order, followed by manager synthesis. A missing worker, flattened team,
  unparseable manager plan, or fallback plan now rejects the v2 execution
  receipt instead of masquerading as a successful team run.
- Build the local `tools/list` inventory only after Hub discovery, bind required
  capabilities through the active host LLM, and validate the private inventory
  and capability-binding plan against the public pair-scoped receipt. Raw local
  tool inventory never crosses the Hub boundary.
- Probe Codex Workforce isolation and fail closed before the first model or Hub
  call when Codex still exposes collaboration authority. Claude workforce
  subprocesses run without inherited tool authority, API and Ollama workers are
  zero-tool, and Gemini workforce execution fails closed until equivalent
  isolation is proven. Required-tool work cannot start without an exact
  policy-filtered native grant.
- Require direct WorkOrder and Selection objects from the active host LLM and
  reject ceremonial tool-call envelopes, unknown keys, contradictory community
  exclusions, and exhaustive "everything else" exclusion lists. Explicit user
  prohibitions remain hard constraints while unused or adjacent communities do
  not become accidental disqualifiers.
- Validate every Hub CandidateSet, slot, candidate, semantic snapshot,
  evidence row, and operational card against exact keys before candidate text
  reaches the selection prompt. Candidate metadata remains explicitly
  untrusted data; unknown prompt-bearing fields fail closed. Structured repair
  receipts persist fixed error-code messages instead of fragments copied from
  rejected model output.
- Parse the Terminal Hub transport's bounded buffered `{ status, headers, text }`
  response shape at the Workforce adapter boundary. This keeps real Hub MCP
  JSON from being misclassified as invalid merely because it is not a native
  Fetch `Response` object, and is covered by an end-to-end adapter regression.
- Ordinary `/network`, `/taskforce`, and `/workforce` requests now use the
  Agent Workforce Ontology protocol. The active host LLM creates the pinned
  work order and selects exact AgentRelease IDs from the Hub candidate menu;
  Terminal only validates and executes that choice.
- Require the exact three workforce MCP calls, a real manager plan, distinct
  pinned worker executions, synthesis, verifier, and auditable receipts. Stale
  ontology versions, history or popularity influence, silent substitution,
  planner fallback, and single-model masquerading fail closed.
- Keep the retired lexical router available only through explicit
  `/legacy-network`. Cross-platform and npm release gates now exercise the
  workforce runtime contract on Agentlas OS v1.1.44 at immutable commit
  `f29381f15c0ee4f244c2bac253bbb992765bc859`, including canonical ontology
  `awo:2026-07-15.2` and its reviewed singular payment/security aliases.
- This source commit does not prove a GitHub release or npm publication; both
  remain separate immutable-tag gates.

## 0.8.3 — 2026-07-14

- Pin all release and npm publication gates to Agentlas OS v1.1.28 commit
  `d741da796289678c38fac1059f0473f271d0f7e9`. Codex, Claude Code, MCP,
  Network, owner Cloud, and Storm plugin contacts now synchronously install the
  same Core-owned project soul memory, code map, ontology runtime, CareerGraph,
  and full `.agentlas/` privacy block before agent work starts.
- Ship the repository's npm OIDC trusted-publishing workflow. It accepts only
  an exact immutable release tag, reruns the Core contracts and 45-case smoke
  suite, and verifies registry visibility without storing a long-lived npm
  publish token in GitHub.

## 0.8.2 — 2026-07-14

- Include the post-`v0.8.1` hardened execution boundary: read-only discovery
  remains passive, while the first real write/full run installs the complete
  Core-owned project soul, memory, code map, ontology, Career Graph, and
  privacy-first `.gitignore` contract.
- Fail closed when the parent AI's exact model choice is absent from live
  inventory, exceeds a cost ceiling, or lacks required capabilities/context;
  no provider alias or tier-to-model table chooses a model for the AI.
- Pin the cross-platform release gate to Agentlas OS v1.1.27 commit
  `e024b68821b28aa40c7a22c94ac3832fed4155dd`, including the Windows ACL/POSIX
  mode correction, and require the same Goal + UltraCode prompt bytes on all
  three operating systems.

GitHub and npm publication remain separate operations. The registry version is
authoritative for `npm install -g agentlas` and must be verified after publish.

## 0.8.1 — 2026-07-14

- Load the canonical, digest-addressed Stormbreaker Goal + UltraCode harness
  from Agentlas OS instead of maintaining a Terminal-local prompt variant.
- Verify byte-identical harness behavior across macOS, Linux, and Windows, and
  fail closed when the Core digest or runtime contract does not match.
- Isolate Windows test hosts and ACL-specific cleanup behavior so successful
  product assertions are not misreported as failures by platform-only process
  or temporary-directory semantics.
- Select only exact models advertised by the live host inventory; when that
  inventory is unavailable, preserve the active model instead of inventing a
  provider-specific model ID or effort level.
- Bootstrap canonical Core project memory on the first real write/full Terminal
  execution while keeping read-only and discovery commands non-mutating. The
  complete `.agentlas/` namespace is ignored and owner-only even during the
  compatibility fallback to an older Core.
- Gate the Terminal release contract on the pinned Agentlas Core
  project-bootstrap surface across macOS, Linux, and Windows.

GitHub tag: `v0.8.1`. The npm registry remained on `0.7.0`; the attempted
`0.8.1` publication was rejected by the registry's OTP gate and was never
reported as installed.

## 0.8.0 — 2026-07-13

- Added separately owned Portable Experience/Taste assets, exact loadout and
  receipt validation, privacy-filtered local experience candidates, and
  explicit Desktop loadout opt-in.
- Added system-global-first MCP planning with one-pass consent, key-presence
  checks, ordered alternatives, isolated failures, and valid empty-MCP mode.
- Added AI-authored model allocation receipts with live runtime inventory,
  exact model/effort selection, explicit pins, cost ceilings, and visible
  fallback reasons.

GitHub release: `v0.8.0`. npm publication is a separate registry action and is
not implied by the tag or GitHub asset.
