This repository was archived by the owner on Sep 16, 2026. It is now read-only.
Repository navigation
Releases: Jafa7/OrchestratorEngine
Releases · Jafa7/OrchestratorEngine
Release list
OrchestratorEngine v1.11.0
- Added opt-in operational feedback with explicit destination and field
allowlists, bounded local observations, cause-based coalescing and frozen FYI
snapshots sent through the existing continuity outbox. Feedback grants no
product, Git or publication authority; retained sends remain idempotent after
product completion without suggesting a competing fallback delivery. - Preserved pinned reply completion across early and late replies, independent
acknowledgement and owner recovery. Explicit result replay decisions now
survive stop/resume and endpoint rebinding; pre-replay claims cannot consume
a pending replay, and diagnostics share the same completion-route predicate. - Preserved ordinary assignee routes across fenced ownership transfer and added
deterministic self-check diagnosis and repair for missing unclaimed routes,
without bypassing explicit stop controls or assignment generations. - Allowed an assignee to acknowledge a claimed result from its previous wait
while moving to a different wait source. Foreign outcomes remain rejected,
and explicit replay remains scoped to the new wait. - Let retained terminal CI observation failures satisfy continuity waits for
inspection without treating an unknown remote CI outcome as success. Matching
monitor identity, supported artifacts and terminal event hashes are required;
configurable state paths are compared by their resolved physical identity. - Made persisted headless delivery ambiguity require operator action, like live
queue ambiguity. Explicit retry rearms either transport once; uncertain
delivery still blocks automatic retransmission. - Aligned token coverage with token-accounting capability and measurement
provenance. Unknown or partial usage is not complete coverage; a verified
zero remains a real measurement and shared quota remains separate. - Made successful matching duration history supersede bootstrap check estimates,
while retaining explicit execution overrides and resource-managed dispatch.
Same-ID check replays compare retained requested options before planning, so
newer history cannot change an existing operation's execution or wake route. - Removed implicit Desktop activation from the legacy App Server fallback and
made successful delivery receipts recordactivation: not_requestedby
default. Explicit adapter activation remains opt-in; host UI behavior is not
guaranteed by this receipt. - Rejected contradictory
completecheckpoints with a next action in both
continuity and workstreams. Clarified accepted-plan continuation and the
single managed wake route for checks, avoiding duplicate direct notifications. - Retained an explicit Codex launcher in actor routes for host-local delivery.
Existing durable JSON schema version 1 and continuity database schema version
3 remain unchanged.
Installation
Install from the immutable tag or the attached wheel. See the upgrade guide.
OrchestratorEngine v1.10.0
- Kept acknowledged Codex session-queue wakeups in the background so watcher
delivery no longer changes the user's active window or task. Explicit host
actions can still open a task when requested. - Added an opt-in transactional multi-chat continuity authority with dynamic
actor endpoints, fenced work ownership, explicit peer obligations, typed
any/allwaits, handled-result cursors, activation claims, durable outbox
recovery, endpoint delivery admission, claim-independent bounded reminders,
bounded compact entry packets and a deterministic self-check. - Hardened continuity with explicit handled-result acknowledgement, retained
source reconciliation independent of watcher receipts, assignment-generation
claims, immutable completion, paginated obligation history, revisioned notes,
bounded evidence facts and auditable diagnostic disposition. - Added assignment-scoped handled-result ledgers, resumable paused assignments,
return-actor reply recovery, communication-preserving work transitions and
project/actor/work controls that suppress and deterministically re-arm all
covered requests and continuations. Recovery reconciliation now isolates
malformed incident timestamps so healthy peers continue fairly. - Preserved communication authority across completion, endpoint replacement and
stop/resume transitions. Paused assignments now receive endpoint-fenced
control activations after rebinding, stale claimed requests are re-routed once,
owner continuations match the current endpoint generation, completed
non-request waits cannot emit dead product wakeups, and owner checkpoints no
longer resolve or reset unrelated reply recovery. - Made continuity acknowledgement durable across pause, continue, source-set
changes and ownership handoff; current claimed activations now fence repeated
reconciliation, partially handledallwaits deliver only new work, retained
evidence enriches a stable outcome identity, and v1 database migration
preserves live assignment generations with safe named-column writes. - Fenced claimed continuations by actor endpoint generation so an owner rebind
reissues unhandled work, and normalized legacy result identities, cursors and
activation manifests without invalidating previously published outcome IDs. - Added watcher integration that records managed terminal results and publishes
exactly addressed continuity activations without model polling. Stopped or
silent chats are not treated as authoritative state transitions. - Hardened terminal publication, deterministic event replay, Codex headless
ambiguity handling, watcher acknowledgement races, GitHub Actions terminal
reconciliation and retained-target replay. - Made resource subscriber identity stable across recapture and unsubscribe /
re-add generations, reconciled interrupted configuration publication,
removed the authority-wide lock from slow result projection and made nested
selector search lazy. - Corrected usage provenance and workstream terminal normalization in metrics,
collapsed logical history before cohort filtering and made watcher / metrics
history traversal bounded by new records rather than parsed retained history. - Added recoverable incremental indexes for metrics candidates, observation
identities and aggregate worker-task diagnostics. Initial rebuild cost is
reported separately; steady-state status refreshes only changed and active
tasks while durable terminal artifacts remain available to direct diagnostics. - Added per-publication recovery markers for metrics and task-summary indexes.
A failed candidate-journal append or crash after authoritative publication now
triggers an observable index reconstruction instead of silently hiding the
retained artifact from a warm projection. Marker hashes and authoritative
JSON now use the same UTF-8 bytes on POSIX and Windows. - Pruned impossible nested resource bundles before Cartesian expansion regardless
of member naming, including mandatory leaves excluded by policy or occupied by
an incompatible holder, or leaves whose own capacity cannot satisfy the claim. - Expanded host capability output with endpoint addressability, durable enqueue,
consumer-claim, sequential queue, lifecycle observation, missed-event recovery
and truthful native-subagent observation fields. - Added atomic managed request/reply envelopes: marked sends create their reply
obligation and outgoing intent together; receipt and progress remain
non-terminal; saved terminal replies return through the durable outbox and
require separate handling acknowledgement. - Added assignment-scoped checkpoints, typed waits and pauses so one blocked
peer task does not freeze independent obligations. Continuity database schema
v3 migrates accepted v2 authority state without silently arming old work. - Added opt-in default recovery observation for new work, explicit adoption for
existing work, project/actor/work stop controls, capability-qualified recovery
inspections, causal deduplication, persisted backoff and bounded backlog
visibility without model polling or inferred abandonment.
Installation
Install from the immutable tag or the attached wheel. See the upgrade guide.
OrchestratorEngine v1.9.3
- Windows managed-process barriers now propagate
CREATE_NO_WINDOWto the
admitted command and reject creation flags that would allocate a console.
The resource-authority guide also documents the safe external launcher flags
so long checks do not open an empty Windows Terminal window.
Installation
Install from the immutable tag or the attached wheel. See the upgrade guide.
OrchestratorEngine v1.9.2
- Reissued the resource terminal-delivery fix with a complete workflow-owned
release bundle after thev1.9.1GitHub Release was published prematurely
without assets. Runtime and durable-data contracts are unchanged from
v1.9.1. - Clarified that maintainers and agents must not create a GitHub Release before
the tag workflow creates and verifies its draft.
Installation
Install from the immutable tag or the attached wheel. See the upgrade guide.
v1.9.1
- Resource runners now project their durable terminal outbox before exiting,
under the same interprocess delivery lock as the authority service. A result
and follow-up event therefore survive an authority process lost at the native
containment boundary, while failed projection remains safely retriable. - Documented that a resource authority must be owned outside recipe, check and
worker process trees; ordinary detached flags do not escape owned native
containment.
OrchestratorEngine v1.9.0
- Added a public retained resource input contract and CLI flow for delayed or
orphan-prone launchers. Exact replay remains idempotent, changed contracts
conflict, and first admission still verifies and captures the registered
live root. - Native loopback socket aborts are normalized as public
ResourceError
failures instead of leaking platform-specificOSErrorsubclasses.
Installation
Install from the immutable tag or the attached wheel. See the upgrade guide.
OrchestratorEngine v1.8.1
- Native Windows watcher health now accepts a heartbeat from a process proven
to belong to the service's exact recorded Job Object. Unrelated, unavailable
and stale process identities remain fail-closed.
Installation
Install from the immutable tag or the attached wheel. See the upgrade guide.
OrchestratorEngine v1.8.0
- Added point-in-time completion-delivery admission for workers, local checks,
GitHub Actions and pull-request monitors, and workstream continuations. The
newoff,warnandrequire-readymodes let autonomous dispatch fail
before the host turn ends when its callback service or session stream is not
ready. - Added bounded append-only delivery-preflight sidecars, read-only history,
retention that preserves each operation's newest sample, queue-batch probe
reuse and host capabilitychannel_lifecyclemetadata. - Claude setup now requires a session-length Monitor (
persistent: true) and
explicitly documents thatwatcher streammust be re-armed for every host
session. Follow-up prompts remind agents to verify that channel before the
next wake-enabled dispatch. - Added a read-only
release preflightreport for version, Git state,
untracked whitespace, tag, GitHub CLI and completion-delivery readiness. - Added
ci watch --expected-head-from-git REFto resolve an immutable full
commit SHA before monitor admission. - Added idempotent
watcher service ensure, which recovers only non-running
services and refuses to replace a live degraded process. Without an
explicit--hostit now arms the bound callback host, and refuses a
stream-only, missing or unreadable binding instead of starting a channel
that cannot reach it. Legacynotifybehavior remains available only when
requested explicitly or recovered from an existing service. release preflightnow proves the completion channel through the same
check asdoctor, so a stream host reports its armed stream instead of
being reported as unprovable and blocking--require-watcher.- Adopter-authored TOML configuration is read as
utf-8-sig, so a file
saved with a UTF-8 byte order mark by a Windows editor no longer fails
as a syntax error at line 1, column 1. - The WSL
/mnt/cinterop probes are skipped on native Windows and never
propagate a filesystem error, sobind --host codexworks off WSL. - Worker supervisors now release their ownership lease only after final queue
promotion, so cleanup and takeover cannot race with a late supervisor write.
Installation
Install from the immutable tag or the attached wheel. See the upgrade guide.
OrchestratorEngine v1.7.0
- Added phase-scoped resource maintenance capabilities so a cancelled current
owner can run registered cleanup and quiescence probes without retaining work
authority; private capabilities remain absent from public status and events. - Added operation-scoped wake-target files for worker and check dispatch, plus a
revision-guarded, stopped-and-drained resource configuration update command. - Added privacy-safe native acceptance reports, installed-wheel CI soaks for
Windows and macOS, and explicit Desktop/environment field-test boundaries.
Installation
Install from the immutable tag or the attached wheel. See the upgrade guide.
OrchestratorEngine v1.6.1
- Hardened local resource transport by creating credential files atomically with
private permissions, validating the recorded authority process identity before
sending project credentials, and refusing unusable endpoints. - Enforced private POSIX authority and ledger permissions, made replay subscriber
attachment deterministic, removed concurrent snapshot leaks, and kept shared
generic results subscriber-neutral.
Installation
Install from the immutable tag or the attached wheel. See the upgrade guide.