# BLUN King Changelog

## 9.1.605

- Batch local session replay and locate archived display pages without scanning every earlier chunk. Preserve complete stored history, archive integrity checks and existing recovery behavior.
- Keep duplicate-tool-result projection stable between recorded compaction rounds. Retain complete local outputs and existing read permissions; do not offload output that the promised recovery path cannot return.
- Require final automatic compaction to reduce the same history estimate before replacing active context. Preserve the original history on rejection. Add an optional max_request_history_bytes trigger through the existing compaction owner; it is disabled by default and is not a provider-body limit.
- Extend context diagnostics with distinct views and source attribution for instructions, memory, skills and historical messages. Keep serialized bytes, local token estimates and reported usage separate.
- Preserve session ownership across queued work, delayed events, questions and configuration changes. Reject a second active writer to the same session instead of allowing concurrent transcript mutation.
- Remove the extra agent/session footer line while retaining explicit session controls and diagnostics. Preserve the existing King interface, managed models and permission boundaries.
- Add --message for one initial interactive message after startup consent and session selection. Use normal message admission and queueing; do not interpret its contents as a slash or shell command.
- Keep the bundled Guard service contract unchanged. This release does not establish faster live responses, lower provider bills, complete OpenClaw parity, or bounded initial transcript reading.

## 9.1.604

- Add request diagnostics to /context doctor, /context-doctor and /tokens: separate serialized request bytes from token estimates and attribute supported prompt files, memory, skills and tool definitions to their actual rendered contributions. Unknown provenance remains unknown.
- Generate a fresh x-request-id for each HTTP attempt and retain it in transport diagnostics. Preserve caller-supplied IDs; do not log their arbitrary values or change billing behavior.
- Defer medium-sized tool catalogs through the existing search and disclosure mechanism. Keep tools discoverable and executable without reducing the model context window.
- Add session-scoped /queue controls for steer, followup, collect and interrupt, with debounce and batch settings. Preserve excess queued input and forum-topic routing. Ordinary queued messages no longer use the former automatic 30-second interruption.
- Resolve /session and explicit startup targets by exact ID or title, then unambiguous ID prefix. Keep ambiguous choices in the existing picker and preserve queue ownership across session transitions.
- Preserve multiline input as message content, retain pending questions when their dialog is collapsed, and offer /question to reopen them.
- Add session-persisted usage display modes, include response-review usage in the turn footer, and discard diagnostic results after a session change.
- Add local display controls to /settings, show the bound agent and session in the footer, coalesce tool-progress repaints, and stop formatting unused private thinking payloads.
- Suppress repeated unchanged blocked-Cron warnings and recheck cleanup deadlines after early timer wakes without extending the cleanup budget.
- Keep the pinned AgentSpine and Translate Native component versions unchanged. These changes do not establish lower provider bills, faster live responses, a repaired external Guard service, or complete OpenClaw feature parity.

## 9.1.603

- Open a native Windows folder chooser when selecting a different startup workspace. Keep explicit path entry available, return to the workspace menu on cancellation, and fall back to path entry when a desktop dialog is unavailable.
- Offer the user's home folder instead of an inherited or previously remembered Windows system directory such as System32. Explicitly entered workspace paths still use the existing validation.
- Preserve exact prompt and bundled-component fixture bytes across Windows checkouts, and require folder-selection regression checks in the release gate. Bundled AgentSpine and Language Guard versions are unchanged from 9.1.602.

## 9.1.602

- Give historical tool-output recovery its own private storage root, so existing ordinary tool-output folders with inherited permissions do not silently disable lossless context reduction. Existing files and permissions remain unchanged.
- Retain complete archived output, read-permission checks, integrity verification, and fallback to full context when recovery is unavailable. Bundled AgentSpine and Language Guard versions are unchanged from 9.1.601.

## 9.1.601

- Keep terminal input queued when background work wins admission, preserving order and showing each input only once.
- Replace eligible older tool outputs with verified private-file references in model requests while preserving complete history and current-turn results.
- Retain full output when recovery is unavailable, denied, altered, or no longer matches the active context.
- Require source and compiled-program checks for recovery, permission boundaries, and retained-history accounting.
- Retry one rate-limited native response review using the persisted provider cooldown and the unchanged candidate; never replay completed tools or release unchecked text.
- Reserve up to 2,048 output tokens for input-estimation differences without shrinking the model context window or changing smaller explicit output caps. Larger differences remain subject to bounded context-error recovery.

## 9.1.600

- Bound each response-review attempt to 120 seconds while retaining the 30-second default for generic reviewers and the existing maximum of two outer attempts.
- Allow up to 90 seconds for first meaningful native-review text once per attempt, then renew a 30-second idle budget on meaningful text and ordered release and verification stages without extending the absolute deadline.
- Preserve cancellation, exact response binding, receipt expiry, and authorization; these changes do not establish a fix for live HTTP 502 errors.
- Pin AgentSpine 0.73.0 and Translate Native 6.155.0; keep the guard protocol at 6.20.0.

## 9.1.599

- Show localized personal-memory actions and complete previews of settings changes or remembered text, with terminal control characters escaped.
- Offer one-shot approval for valid memory changes and rejection only for invalid inputs.
- Prevent session-wide approval from automatically accepting queued requests that require individual approval.

## 9.1.598

- Distinguish lower-bound input counts from exact counts in upstream context rejections.
- Reduce the output allowance once for a lower-bound rejection without discarding messages or tools; retain cancellation and bounded retry behavior.
- Verify moving tokenization thresholds and exact-count counterexamples in the compiled program.
- Include the previously missing package notes for 9.1.595 through 9.1.597.
- Restore the original 150 rotating activity words without additional model requests.
- Keep media payloads out of AgentSpine's text-only hook input while preserving complete model attachments and policy checks.

## 9.1.597

- Classify explicit context-limit errors wrapped in HTTP 502 and allow one corrected request with a smaller output allowance.
- Preserve messages, tools, cancellation, and the rule against replaying an already-started response.
- Known limitation: this initial correction treated lower-bound input counts as exact. The additional correction is included in 9.1.598.

## 9.1.596

- Distinguish owner cancellation from automatic turn interruption.

## 9.1.595

- Defer tool and skill descriptions until they are needed, while keeping discovery available.
- Bound greeting context without deleting saved task history or weakening permissions.

## 9.1.594

- Preserve private Telegram replies while group messages wait, and retain slash-command routing.
- Honor long Retry-After delays and restore remaining cooldowns after resuming a session.
- Continue one settled tool step after rejected narration without publishing that narration or weakening final-answer review.
- Restore bounded write-continuation recovery, shell timeouts, task controls and session recovery.
- Keep input, quota rows, activity, task expansion and source-labelled tool output visible during streaming and history navigation.
- Require complete console regression evidence before packaging and verify matching public update metadata.

## 9.1.593

- Keep the input and both status rows visible after delayed startup messages, without clearing terminal scrollback.

## 9.1.592

- Preserve explicit startup permissions and remember deliberate permission selections for new sessions.
- Prevent overlapping session selections from closing the session being resumed.
- Restore rotating activity words, cumulative usage, step number and local date/time alongside live timing and token estimates.
- Allow protected-source reads redirected to literal null sinks without removing protected-write checks.
- Include the bounded startup and reload corrections prepared in 9.1.591.

## 9.1.591

- Finish the managed model refresh before opening a session, with a bounded catalog request.
- Reopen continued sessions through one reload so an overdue loop cannot race a second reload.
- Preserve additional workspace directories through the reload path.
- Keep the existing input, footer, quota rows, loop countdown and compaction display unchanged.

## 9.1.590

- Retain complete bounded instructions without the extra 8 KiB AgentSpine rejection.
- Keep routine AgentSpine preparation out of the visible transcript while retaining source and receipt checks.
- Preserve the active King profile when unrelated host settings are inherited.
- Restore the loop countdown and replace the previous recurring loop when scheduling a new one.
- Retain the approved compaction display and queued reload behavior.

## 9.1.589

- Bundle reviewed AgentSpine and Translate Native sources with verified update manifests.
- Preserve the active King profile when loading agent context.
- Keep required response-review tools available and record generated-response usage even when review rejects the response.
- Apply mention-required group routing in the managed channel integration.
- Show compaction activity and effective thresholds in the terminal.
- Preserve the early-compaction working budget and request-boundary safety margin across updates.
- Use the selected language throughout the startup update dialog, progress and queued-update messages.
- Keep technical integration identifiers and licenses intact while neutralizing visible runtime error messages.

Installation does not restart existing sessions. A running session loads the new code on its next start.
