Skip to content
Open
Show file tree
Hide file tree
Changes from 13 commits
Commits
Show all changes
234 commits
Select commit Hold shift + click to select a range
055aabc
copy(errors): warmer, shorter failure and status receipts
Sep 2, 2026
a00a8a2
copy(pickers): clearer picker, config, and plugin copy
Sep 2, 2026
c665b6c
copy(launch): warmer launch, setup, and help copy
Sep 2, 2026
d85055a
feat(fleet): surface worker deliverables via summary and saved-sessio…
gaord Sep 6, 2026
4de6dc1
fix(fleet): worker deliverable rework — excerpt at the emitter, parse…
Sep 7, 2026
a6dcdf2
Merge branch 'main' into feat/fleet-worker-deliverable
Hmbown Sep 7, 2026
8a6288f
feat(tui): compact and hidden presets for the bottom chrome (#5950)
Sep 6, 2026
d3b333b
chore(ci): retrigger buildkite (suspected base flake, see #5929)
Sep 7, 2026
c9c7adb
Merge branch 'main' into feat/bottom-chrome-presets-5950
Hmbown Sep 7, 2026
edfb317
chore(ci): retrigger buildkite (known intermittent macOS workspace fl…
Sep 7, 2026
59fb0c7
feat(config,tui): confirmed opt-out for model-bound key redaction
SparkofSpike Sep 5, 2026
0983f67
fix(test): derive the prune cut from recorded timestamps, not a fixed 6s
Sep 7, 2026
c8e703f
Merge branch 'main' into feat/fleet-worker-deliverable
gaord Sep 7, 2026
f94684c
fix(fleet): the receipt excerpt is the final assistant reply, not the…
gaord Sep 7, 2026
853d60d
docs(config): document R1 turn budgets and the goal loop example
7jrxt42BxFZo4iAnN4CX Sep 7, 2026
b0c5241
feat(config,tui): confirmed opt-out for model-bound key redaction
SparkofSpike Sep 5, 2026
f72f29b
Merge PR #5982 with config-bound redaction confirmation
Sep 7, 2026
0efa843
Merge PR #5973 bottom chrome presets into 0.9.13 integration
Sep 7, 2026
fc1ba77
Reconcile rebased PR #5982 history with tested integration
Sep 7, 2026
6325c52
Merge PR #5996 configuration budget reference
Sep 7, 2026
ea5358a
Merge PR #5990 snapshot prune fixture correction
Sep 7, 2026
13c0f4a
Remove premature ShannonNet execution integration from 0.9.13
Sep 7, 2026
c37a005
Fix the existing VS Code package compatibility gate
Sep 7, 2026
8a652fa
fix(mcp): preserve desktop routing and graceful session cleanup
Sep 7, 2026
154e04b
feat(computer): ship the reviewed native helper with the builtin plugin
Sep 7, 2026
5b66afd
fix(mcp): expose selected tools before inference and refresh live dis…
Sep 7, 2026
9990987
feat(computer): include compact observations and local window OCR
Sep 7, 2026
050f916
fix(computer): re-vendor Computer Use plugin at eb5eac7 with verified…
Sep 7, 2026
8c9c8ee
Harden runtime authority and security boundaries for 0.9.13
Sep 8, 2026
f602804
Strengthen reliability, queue durability, and MCP login UX for 0.9.13
Sep 8, 2026
5227cc3
Make the model picker responsive and coherent (#5975)
Sep 8, 2026
f5755a8
Report throughput and cost truthfully and make goals durable (#5977 #…
Sep 8, 2026
cd9863f
Regenerate the web icon family in the current brand treatment
Sep 8, 2026
80c3b83
test(tui): exercise offline queue with late raw keyboard submits (#5999)
Sep 8, 2026
67430af
Merge verified contributor and Computer Use source for 0.9.13
Sep 8, 2026
45ceed5
merge: complete interrupted 0.9.13 contributor integration
Sep 8, 2026
d6698f1
merge: land verified 0.9.13 release candidate locally
Sep 8, 2026
7b72c44
merge: integrate Fleet worker deliverables with verified session capture
Sep 8, 2026
6db671f
fix(tui): retain submitted commands and surface active user waits
Sep 8, 2026
86d6bd9
feat(context): offload purge messages into retained session evidence
Sep 8, 2026
b262bde
docs: the legacy project was DeepSeek-TUI, not "DeepSeek CLI"
Sep 7, 2026
59c31a6
chore(gh): admit goransh-walia through contributor intake
Sep 7, 2026
f7b5c41
feat(openrouter): pin upstream vendors across request paths
Sep 8, 2026
068cb5d
fix(acp): filter durable session history by requested working directory
Sep 8, 2026
5374c7f
Merge contributor TUI copy with current delivery and consent wording
Sep 8, 2026
0d3433c
Integrate verified OpenRouter vendor pinning for 0.9.13
Sep 8, 2026
800474b
fix(runtime): preserve history, controls, and partial MCP frames
Sep 8, 2026
daf2cd2
Expose resolved worker routes and per-task model controls
Sep 8, 2026
8b3cdce
Keep printable keys in terminal modal search
Sep 8, 2026
e9734ed
Exclude the C allocator from explicit Rust allocator builds
Sep 8, 2026
b32bbee
Integrate verified Runtime history and admitted-control recovery
Sep 8, 2026
ef822bc
Integrate terminal modal search ownership for 0.9.13
Sep 8, 2026
7e18d29
Clarify website onboarding and model choice; use transparent brand mark
Sep 8, 2026
2b4f40e
fix(fleet): bind saved profiles in direct agent dispatch
Sep 8, 2026
203b110
merge: integrate reviewed website onboarding and brand copy
Sep 8, 2026
5ee4346
fix(tui): retain snapshot availability and warn once per session (#5930)
Sep 8, 2026
768980b
feat(tui): persist contextual tips opt-out
Sep 8, 2026
cb4b02e
fix(fleet): expose and constrain selected task model routes
Sep 8, 2026
2a76c29
merge: integrate per-session snapshot status repair
Sep 8, 2026
29592e3
merge: integrate durable contextual tips preference
Sep 8, 2026
7c4bab4
feat(catalog): persist exact routes and settle auxiliary usage once
Sep 8, 2026
ab38e43
feat(tui): let the active agent draft local issue reports
Sep 8, 2026
f2fe7f4
merge: integrate live provider catalogs and durable usage receipts
Sep 8, 2026
c7935b7
Merge private agent issue drafts into the 0.9.13 candidate
Sep 8, 2026
8e3bade
feat(catalog): verify signed cloud facts and freeze dispatch prices
Sep 8, 2026
f614104
fix(automations): persist occurrence admission and recover bound tasks
Sep 8, 2026
79730f4
fix(permissions): enforce denials across delegated execution
Sep 8, 2026
25c689f
fix(cli): carry temporary runtime overrides through dedicated flags
Sep 8, 2026
29ca2f1
Merge signed provider facts into the 0.9.13 candidate
Sep 8, 2026
0d639be
feat(config): unify notification settings and audio policy
Sep 8, 2026
50a39ce
Improve product copy and use the founder terminal screenshot
Sep 8, 2026
c1009c0
Merge durable automation occurrence recovery into0.9.13
Sep 8, 2026
1af7c4a
test(engine): cover next user turn after terminal SSE loss
Sep 8, 2026
06b67e4
Merge CLI override dispatch fixes into 0.9.13
Sep 8, 2026
931d9d1
Merge shared notification settings and quiet audio policy
Sep 8, 2026
cf26339
Merge capability-led website copy and founder terminal capture
Sep 8, 2026
a268dd8
Merge real HTTP SSE next-turn regression coverage
Sep 8, 2026
d8b094f
fix(plugins): validate opened catalog documents and actual read bounds
Sep 8, 2026
0c0458b
fix(operate): preserve saved provider routes and lead labels
Sep 8, 2026
cb42133
fix(tui): bind redaction consent to the loaded config and restore res…
Sep 8, 2026
24b1351
fix(tui): deduplicate command recall before restart
Sep 8, 2026
e8386bd
fix(tui): settle localized notices without losing warnings
Sep 8, 2026
1cce194
Merge consent recovery and exact Operate execution routes
Sep 8, 2026
9e77950
fix(catalog): collect complete bounded provider model lists
Sep 8, 2026
41f27af
fix(tui): integrate localized notification and gate notice lifecycles
Sep 8, 2026
cb3af27
fix(opencode-go): refresh shared Chat model compatibility roster
Sep 8, 2026
69d246c
fix(deps): patch affected web and telemetry development dependencies
Sep 8, 2026
6d333a4
Expose shared device alert settings and authenticated event preparation
Sep 8, 2026
7e8bda4
fix(runtime): prevent stale notification and sound decisions
Sep 8, 2026
49f9d19
Integrate provider catalog, native notification contract and TUI sett…
Sep 8, 2026
d9cd90d
fix(runtime): fence shared task-store execution ownership
Sep 8, 2026
365bd52
Merge native notification race followup for combined release verifica…
Sep 8, 2026
278c259
Credit issue reporters and contributor work in the 0.9.13 release
Sep 8, 2026
3408ea6
Sync bundled Computer Use to checked Windows input source
Sep 8, 2026
3703485
Prepare startup integrity, session busy hooks and exact DeepSeek fact…
Sep 8, 2026
4ff955d
Fix Fleet shortlist enrollment and authoritative role pins (#5915)
Sep 8, 2026
7f33a35
Integrate shared task-store ownership for combined release verification
Sep 8, 2026
cbd4531
feat(runtime): preserve validated images through existing turns
Sep 8, 2026
967aec6
Integrate Fleet role ownership and shortlist fixes for final gate
Sep 8, 2026
36f11b8
Integrate Runtime images with task ownership and notification lifecycle
Sep 8, 2026
9176880
feat(runtime): enforce optional per-turn output allowances
Sep 8, 2026
5f77cd2
Report both tool origins on registration collisions (#5934)
Sep 8, 2026
1b91e2f
fix(runtime): publish saved route catalog in headless sessions
Sep 8, 2026
63bc02e
Integrate per-turn output limits with durable image recovery
Sep 8, 2026
2763dc1
Integrate contributor-requested tool collision origins
Sep 8, 2026
7484ff4
Publish cached route capabilities on headless Runtime startup
Sep 8, 2026
86dd8c4
test(pricing): guard shipped default route coverage (#5976)
Sep 8, 2026
ab022e3
feat(runtime): look up accepted turns by operation key
Sep 8, 2026
9f14575
Guard pricing coverage for shipped default routes
Sep 8, 2026
18ced89
Bundle validated Computer Use target selection fixes
Sep 8, 2026
647922b
Expose exact accepted-turn lookup for cancellation recovery
Sep 8, 2026
7ab408a
test(tui): cover next manual turn after exhausted SSE loss
Sep 8, 2026
a457818
Keep uncatalogued DeepSeek models on Chat
Sep 8, 2026
08f8edc
fix(client): retain admitted catalog binding for the same model
Sep 8, 2026
72c101e
Preserve exact DeepSeek preview routing and admitted catalog bindings
Sep 8, 2026
33cadd1
Exercise a next manual TUI turn after exhausted network retries
Sep 8, 2026
15dd4ec
fix(config): retain exact provider catalog output limits
Sep 8, 2026
f20161b
Resolve combined-gate provider and fixture regressions
Sep 8, 2026
0c8436f
chore(repo): remove unreferenced debris and map contributor layout
Sep 8, 2026
e599a82
Repair Runtime recovery fixtures for validated images and owned sessions
Sep 8, 2026
dfd7d89
test(client): expect canonical v1 DeepSeek Chat endpoints
Sep 8, 2026
69764bc
Integrate canonical DeepSeek endpoint regression expectations
Sep 8, 2026
3e7fb64
Isolate personal Fleet state in hosted fixtures
Sep 8, 2026
268b81a
Repair release inventory, generated facts and platform lint failures
Sep 8, 2026
5244c03
feat(plugins): add portable conversion and native authoring guides
Sep 8, 2026
fea4890
Integrate hosted Fleet isolation and full-TUI fixture corrections
Sep 8, 2026
96825a9
Pin read-only pipeline fixtures to supported and refused shells
Sep 8, 2026
eb9e541
Expose observed turn stops and parent request retries
Sep 8, 2026
9cc537f
Integrate native plugin authoring and portable configuration conversion
Sep 8, 2026
ad2a790
Integrate reviewed public repository documentation cleanup
Sep 8, 2026
4467d41
Integrate observed turn-stop and request-retry diagnostics
Sep 8, 2026
a58cc8c
fix(review): collect complete PR diffs beyond GitHub's file limit
Sep 8, 2026
7c556ad
Print the complete validated approval link during CLI login
Sep 8, 2026
61e22f8
Integrate complete pinned PR diff collection across review consumers
Sep 8, 2026
134a751
Integrate usable manual Codewhale account approval links
Sep 8, 2026
1dc9e30
Align Fleet and stream-recovery fixtures with current UI state
Sep 8, 2026
b966524
Integrate observable Fleet and full TUI recovery fixture assertions
Sep 8, 2026
e719fa1
fix(review): project binary metadata into model input
Sep 8, 2026
68ffb9e
Keep binary patch payloads out of model review context with explicit …
Sep 8, 2026
c9b11b5
Describe binary model input coverage without claiming a saved raw art…
Sep 8, 2026
50a9dae
Update existing PR prompt fixtures for complete admitted input
Sep 8, 2026
9d892ce
fix(review): preserve account credential boundaries and complete PR i…
Sep 8, 2026
879428a
Integrate credential-safe review workflow and complete diff checkout
Sep 8, 2026
d8a3623
fix(deps): replace yanked chacha20 with SSE2 backend patch
Sep 8, 2026
632df4b
Credit plugin guide and premature-turn-stop reports for 0.9.13
Sep 8, 2026
9c0d664
Integrate public report credits and synced changelog projections
Sep 8, 2026
8c58f69
Integrate patched chacha20 lock entry after full workspace gate
Sep 8, 2026
106d893
fix(tui): resolve final release Clippy diagnostics
Sep 8, 2026
c0b85fe
Integrate scoped final lint corrections
Sep 8, 2026
693ba2c
fix(review): reject oversized local diffs before review receipts
Sep 8, 2026
2eb5022
Reject oversized local review input before receipts can claim coverage
Sep 8, 2026
02ef201
Make final test fixtures pass the exact all-targets CI lint gate
Sep 8, 2026
43e5066
docs(release): label 0.9.13 as an unreleased source candidate
Sep 8, 2026
52d3cf9
Mark 0.9.13 as an unreleased candidate until publication is approved
Sep 8, 2026
68de61b
fix(runtime-web): subscribe to request usage receipts
Sep 8, 2026
323278a
Subscribe built-in Runtime web client to usage events without alterin…
Sep 8, 2026
3ca2837
Require dated release notes before CNB publication
Sep 8, 2026
0eb8f85
docs(readme): synchronize 18 translations with the current English guide
Sep 8, 2026
8fbdc5f
Integrate all 18 README translations of the current public guide
Sep 8, 2026
a9d192b
fix(plugins): reject OpenCode policies that cannot survive conversion
Sep 8, 2026
73153dc
Reduce repeated guidance in the active tool catalog
Sep 8, 2026
ce55496
test: make hook docs and Runtime lookup fixtures Windows-safe
Sep 8, 2026
cbd6813
Describe native plugin conversion and current Computer Use candidate
Sep 8, 2026
1f18e4f
Pin the runtime tool metric to an explicit shell profile
Sep 8, 2026
17a56d5
Preserve sanitized provider causes in root-turn failures
Sep 8, 2026
e27735b
Preserve reviewed Computer Use element identity through native clicks
Sep 8, 2026
ff073b4
Reconcile reviewed runtime tool budgets to measured candidate
Sep 8, 2026
5978f41
Check agent lifecycle guidance at its model-facing field
Sep 8, 2026
2c1c7d2
Honor the earliest known OAuth access-token expiry
Sep 8, 2026
a2a7a45
docs(release): reconcile Computer Use provenance and click intent
Sep 8, 2026
68bfb0c
Constrain provider HTTP host trust and OAuth redirects
Sep 8, 2026
e07cb47
fix(fleet): confine and verify receipt artifact I/O
Sep 8, 2026
f0aa3ec
fix(plugins): keep background Computer Use off the shared pointer
Sep 8, 2026
9d3341d
fix(fleet): confine ledger files and atomic compaction
Sep 8, 2026
8c5b813
fix(review): collect large binary diffs within budget
Sep 8, 2026
4d012b0
fix(plugins): publish stable built-in bundle snapshots
Sep 8, 2026
142ec37
fix(plugins): preserve user-selected home aliases
Sep 8, 2026
fc23fa4
fix(tui): accept UI dispatch before Engine execution
Sep 8, 2026
d7a3338
fix(runtime): persist terminal request diagnostics
Sep 8, 2026
563b5a3
fix(runtime): keep request diagnostics schema-compatible
Sep 8, 2026
5f3078d
fix(auth): validate OAuth endpoints before transport
Sep 8, 2026
472a9bf
fix(session): derive titles from user prompts across save, import and…
Sep 8, 2026
c20dd58
docs(release): credit title recovery and clarify request diagnostics
Sep 8, 2026
565bf62
feat(review): admit bounded whole-PR passes
Sep 8, 2026
c2d150e
feat(config): preserve exact endpoint model declarations through runtime
Sep 8, 2026
9f740f2
test(runtime): initialize optional request diagnostics in API fixtures
Sep 8, 2026
9ffefe1
test(engine): measure loopback SSE request diagnostics
Sep 8, 2026
093a066
feat(web): use local Shannon Sans for website sans roles
Sep 8, 2026
eeeb74d
feat(cli): report runtime request receipts
Sep 8, 2026
8a2f48f
fix(engine): heap-pin turn future at event-loop boundary
Sep 8, 2026
5d97b75
docs(release): synchronize typography and request diagnostics notes
Sep 8, 2026
992f59b
fix(review): retain usage through CLI finalization
Sep 8, 2026
8ec35bb
fix(tui): reserve scrollbar column before wrapping chat
Sep 8, 2026
1844724
fix(provider): preserve declared model identity across runtime consumers
Sep 8, 2026
92e903d
style(tui): format profile metadata assertions
Sep 8, 2026
f74365d
test(tui): exclude continuation rails from hash reconstruction
Sep 8, 2026
9dddde0
fix(engine): heap-pin send-message future at event loop
Sep 8, 2026
2ae7460
fix(shell): stop foreground work when tool futures are dropped
Sep 8, 2026
51f4b2c
docs: clarify first tasks, client roles, and release availability
Sep 8, 2026
0c6bfa8
fix(fleet): preserve declared case identity through selected Pod binding
Sep 8, 2026
3a310ad
fix(fleet): preserve exact saved model identities across consumers
Sep 8, 2026
b7e0d1d
fix(subagent): preserve named provider identity in spawn selectors
Sep 8, 2026
41958c8
chore(release): refresh candidate notes and expose bounded review passes
Sep 8, 2026
1a26d00
fix(engine): box run future before supervised spawn
Sep 8, 2026
fd1cc49
chore(release): satisfy current lint and preserve upstream font licen…
Sep 8, 2026
27aa8f6
fix(runtime): preserve Astra effort tiers on current route catalog
Sep 8, 2026
496fa22
fix(setup): preserve environment-controlled execution policy
Sep 8, 2026
5042c19
fix(tests): adopt shared home isolation in test entry points
Sep 8, 2026
c9dae9e
fix(config): make Config the saved provider and model authority
Sep 8, 2026
d68964a
test(tui): cover statusline transitions in narrow full frames
Sep 8, 2026
08eb61c
fix(cu): reconcile bound computer routes through dispatch failure
Sep 8, 2026
e1895bb
fix(runtime): preserve typed worker lifecycle outcomes
Sep 8, 2026
a7c0fb4
fix: stabilize provider preferences and approval coordination
Sep 9, 2026
194ff73
fix(engine): make model-step ceilings explicit
Sep 8, 2026
a7ba89a
fix(fleet): bound repeated permission-denial recovery
Sep 8, 2026
36b5b5d
fix(fleet): admit bounded sed inspection through worker authority
Sep 8, 2026
6519a29
Trim unused syntax loaders and obsolete advisory exceptions
Sep 9, 2026
51849b9
Report worker outcomes honestly in CLI metrics
Sep 9, 2026
69a1861
Align Chinese agent-depth guidance with the current Runtime contract
Sep 9, 2026
52d66ed
fix: redact plugin review URLs and clarify review guidance
Sep 9, 2026
09a7b82
fix: clarify remaining contributor review follow-ups
Sep 9, 2026
0f78789
fix: keep acceptance test modules lint-clean
Sep 9, 2026
3719974
fix(ci): bypass sccache inside isolated Windows tests
Sep 9, 2026
5dfa949
fix(i18n): use the public Codewhale name in gate actions
Sep 9, 2026
45a8b08
fix: make tool paths and operate goals follow user intent
Sep 9, 2026
4399390
fix: validate saved provider routes and refuse unreadable preference …
Sep 9, 2026
baf133b
fix(tui): share consent gate bindings between hints and handlers
Sep 9, 2026
19f8ebf
ci: retire the Buildkite pipeline
Sep 9, 2026
982ac76
fix: preserve provider selections and repair release regressions
Sep 9, 2026
56d2b12
fix(review): preserve complete hunks across oversized PR passes
Sep 9, 2026
b99e274
integrate: reconcile recovered Core support fixes
Sep 9, 2026
7b558bf
integrate: recover reviewed Core support work
Sep 9, 2026
5d6372c
test: align metadata and startup assertions with current behavior
Sep 9, 2026
b706304
fix(ci): give native Windows tests valid isolated home paths
Sep 9, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 12 additions & 23 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,10 @@ with an accessibility-first pointer.

### Fixed

- Bottom-chrome effort is omitted when the route cannot prove an effective
tier; `/status` retains the full explanation. Cost remains visible when
known, and `cost: unknown` remains on metered routes lacking a reading (#5950).

- Pasting multiline text is one paste again. 0.9.12 gated the
paste-burst heuristic off whenever bracketed paste was *requested*, but
a terminal can accept `EnableBracketedPaste` and still deliver a paste
Expand Down Expand Up @@ -173,6 +177,14 @@ with an accessibility-first pointer.

### Added

- `[tui].posture_bar` and `[tui].metrics_line` accept `full`, `compact`, or
`hidden`, also available through `/config`. Compact preserves the existing
rows' essential fields; hidden returns their space to the transcript (#5973).
- Optional model-bound tool-output redaction opt-out, with two explicit startup
confirmations and a receipt bound to the readable config contents and
modification time. Unconfirmed requests keep masking enabled; routing and
stored goal summaries remain redacted (#5982, thanks @SparkofSpike).
Comment on lines +245 to +248

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Preserve the harvested contributor trailer

This single-parent commit lands the model-bound redaction work from PR #5982 and explicitly credits @SparkofSpike here, but its commit message has neither the required Harvested from PR #5982 by @SparkofSpike line nor the canonical Co-authored-by trailer from .github/AUTHOR_MAP. A changelog thanks does not drive auto-close-harvested.yml or the contribution graph, so add the required mechanical credit before landing.

AGENTS.md reference: AGENTS.md:L201-L206

Useful? React with 👍 / 👎.


- The `rusty-alloc` cargo feature on `codewhale-tui` and `codewhale-cli`
opts the binaries into the `rusty_alloc` global allocator (the mimalloc
v2.4.5 architecture remade in pure Rust — no C compiler or build script
Expand Down Expand Up @@ -225,29 +237,6 @@ with an accessibility-first pointer.
three explicitly. `--use` saves the new secret as this machine's local
`codewhale` provider credential in the same secret store `codewhale auth`
uses; nothing is uploaded.
- `sandbox_backend = "shannon"`: shell commands run as signed ShannonNet
capability invocations (`cap://sandbox/exec`) on a worker that may live on
another tailnet node. Codewhale opens a Task World per session for its
durable `codewhale` Agent and every command leaves a receipt in
`shannon trace`. New keys `sandbox_shannon_home` and
`sandbox_shannon_capability`; tool metadata now reports the actual
external backend kind instead of always `opensandbox`.
- `/shannon [world|trace|children]` inspects the session's ShannonNet
World: agent, projected capabilities, children, and receipts.
- ShannonNet sub-agents get compiled context: the session's native-memory
hits are imported with provenance and the child's projected World decides
what it sees (confidential notes never cross); the session World is
checkpointed and closed when the backend drops.
- Sub-agents under delegated authority: with the ShannonNet backend the
`agent` tool spawns a child identity with a World projected from the
session World, the child's shell commands are signed as that child, and a
join receipt is recorded when it finishes. `SandboxBackend::for_child` /
`child_joined` default to sharing the parent backend for other backends.
- Workspace sync for the ShannonNet backend (`sandbox_shannon_sync`, default
on): the session's non-ignored files are shipped into the worker's
per-World session container before each command — full tree first, then
only changes and deletions — so remote builds and tests run on the files
just edited locally and their outputs persist across commands.
- `Git` grows a `commit_plan` action: a propose-only planner that splits the
working tree into ordered atomic commits (#3999). It groups whole files —
lock files ride with their manifest, tests ride with the source they name —
Expand Down
73 changes: 53 additions & 20 deletions config.example.toml
Original file line number Diff line number Diff line change
Expand Up @@ -206,6 +206,33 @@ memory_path = "~/.codewhale/memory.md"
# max_reprompts = 2
# reprompt_message = "So, what's up ? Keep running !"

# ───────────────────────────────────────────────────────────────────────────
# Model-bound key redaction ([redaction])
# ───────────────────────────────────────────────────────────────────────────
# Codewhale masks credential-looking values in tool output before it reaches
# the model (the "model boundary"), so a file that contains a configured API
# key, a bare provider token, or a credential-shaped opaque string never leaks
# those bytes to the model. Leave this enabled unless the model must read and
# edit files that contain real credentials.
#
# Disabling is a security decision, so it is never a plain flag:
# * Set model_bound = "disabled" here, restart Codewhale, and the startup
# gate asks twice - a first confirmation, then a red "are you really
# sure?" stage. Only the second confirmation takes effect, and it applies
# on later launches while model_bound stays "disabled".
# * Going back to "enabled" - or rewriting config.toml after the
# confirmation - invalidates it: requesting "disabled" again always
# asks for a fresh confirmation.
# * Until a confirmation exists - including in non-interactive/headless
# runs, which never confirm anything - masking stays on regardless of
# this key. Choosing "keep masking on" on the gate leaves the key
# untouched, so the next launch asks again.
# * The value is forgiving: false/"off" mean "disabled"; true/"on" mean
# "enabled".
# [redaction]
# model_bound = "enabled" # mask keys before they reach the model (default)
# model_bound = "disabled" # request the opt-out (restart + confirm required)

# Native tool catalog controls (#2076). By default only the core tool surface
# is loaded into the model context; less common native tools are discoverable
# through ToolSearch and loaded on first use.
Expand Down Expand Up @@ -424,26 +451,6 @@ sandbox_mode = "workspace-write" # read-only | workspace-write | danger-full-acc
# The backend uses a 30-second HTTP timeout. Background, interactive, and
# TTY modes are not supported with external backends — all commands run
# synchronously via HTTP.
#
# ShannonNet backend: each shell command becomes a signed capability
# invocation on a ShannonNet worker (which may run on another tailnet node).
# At session start Codewhale resolves its durable `codewhale` Agent, creates
# a Task World named after the workspace, and attaches the capability; every
# command then leaves a signed receipt (`shannon trace`). Requires the
# `shannon` CLI on PATH (or `$SHANNON`) and an admitted provider for the
# capability (`shannon cap advertise`).
#
# sandbox_backend = "shannon"
# sandbox_shannon_home = "~/.shannon" # default: $SHANNON_HOME or ~/.shannon
# sandbox_shannon_capability = "cap://sandbox/exec" # default
# sandbox_shannon_sync = true # default: ship the workspace's
# # non-ignored files into the worker's per-World session container before
# # each command (a full archive first, then only changes), so remote builds
# # and tests run on the files just edited here. false runs each command in
# # a throwaway container against the worker's own read-only checkout.
#
# Env-var overrides: CODEWHALE_SANDBOX_SHANNON_HOME, CODEWHALE_SANDBOX_SHANNON_CAPABILITY,
# CODEWHALE_SANDBOX_SHANNON_SYNC.
# ─────────────────────────────────────────────────────────────────────────────────
# Bubblewrap (Linux only, additional filesystem isolation)
# ─────────────────────────────────────────────────────────────────────────────────
Expand Down Expand Up @@ -1126,6 +1133,17 @@ osc8_links = true # emit OSC 8 escapes around URLs (Cmd+click in iTer
# git_branch, last_tool_elapsed, rate_limit — they drove nothing. Old files
# keep loading; the retired keys are ignored.
# status_items = ["mode", "model", "context_percent", "cost", "tokens"]
# Size presets for the two rows themselves (#5950) — composition stays in
# status_items; these only decide how much of a row paints:
# posture_bar = "full" # full | compact | hidden (default full)
# # compact keeps the posture chips (and the cap
# # warning) and drops the clocks, counts and hint;
# # hidden gives the row to the transcript.
# metrics_line = "full" # full | compact | hidden (default full)
# # compact keeps the route, context reading, cost
# # and balance and drops the telemetry and the
# # help hint; hidden gives the row to the transcript.
# # Also settable at runtime: /config posture_bar compact
# notification_condition = "unfocused" # unfocused | always | never
# "unfocused" = notify only after this terminal has been
# in the background for two seconds (default);
Expand Down Expand Up @@ -1195,6 +1213,21 @@ initial_delay = 1.0
max_delay = 60.0
exponential_base = 2.0

# ─────────────────────────────────────────────────────────────────────────────────
# Goal loop (`[goal]`) — operate-mode persistent goals
# ─────────────────────────────────────────────────────────────────────────────────
# Operate-mode goals run to their completion gate with no default token, time,
# or continuation ceiling. Token/time budgets, when supplied, are telemetry
# only and do not stop a goal. The keys below are the opt-in circuit breakers.
# [goal]
# Optional safety backstop on automatic goal continuation passes.
# Default: 0 (unlimited). Set a positive value to opt into a ceiling.
# max_continuations = 100
# Optional cancellable quiet period between successful turns, useful for
# coordinator goals that poll on a cadence instead of keeping one provider
# turn open. Default: 0 (continue immediately). Cap: 86400 (24h).
# continuation_delay_seconds = 300

# ─────────────────────────────────────────────────────────────────────────────────
# Context Compaction
# ─────────────────────────────────────────────────────────────────────────────────
Expand Down
20 changes: 20 additions & 0 deletions crates/config/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ pub mod provider;
mod provider_defaults;
mod provider_kind;
pub mod provider_templates;
pub mod redaction;
pub mod resolve;
pub mod route;
pub mod settings_schema;
Expand Down Expand Up @@ -920,10 +921,29 @@ pub struct ConfigToml {
/// [`WorkflowConfigToml::default`].
#[serde(default)]
pub workflow: Option<WorkflowConfigToml>,
/// Model-bound credential redaction policy (`[redaction]`). When absent,
/// masking is enabled — the shipped security default.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub redaction: Option<crate::redaction::RedactionToml>,
#[serde(flatten)]
pub extras: BTreeMap<String, toml::Value>,
}

impl ConfigToml {
/// The requested model-bound masking mode, defaulting to enabled.
///
/// The request only takes effect once the interactive TUI has recorded a
/// confirmation on its startup gate; see
/// [`crate::redaction::effective_masking`].
#[must_use]
pub fn redaction_model_bound_masking(&self) -> crate::redaction::ModelBoundMasking {
self.redaction
.as_ref()
.map(crate::redaction::RedactionToml::model_bound_masking)
.unwrap_or_default()
}
}

#[derive(Debug, Clone, Copy, PartialEq, Eq)]
enum ProviderConfigField {
ApiKey,
Expand Down
Loading
Loading