Skip to content

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 12:00
· 89 commits to main since this release
a2cda0c

Desk v0.3.0

Desk now holds a chat draft to what it rests on before it becomes a pack, searches the whole of a Google Drive, runs natively on macOS, and moves to Runtime v0.24.0, Gateway v0.8.0 and Runner's first stable release.

What an owner must do

  • Reconnect Google Drive. A Drive connection made by an earlier Desk asked for drive.file. This release asks for the whole of the person's Drive, so the first request of an old connection is answered reconnect-required while its status still says connected. Connect again from Admin.
  • Update your Google Cloud project if you registered your own Drive client. Enable the Google Drive API only; the Google Picker API is no longer used. In the consent screen's Data access, add https://www.googleapis.com/auth/drive in place of drive.file. Google restricts this scope: an owner using their own registration, within their organization or as a named test user, needs no verification by Google; a registration offered to the public would. The setup guide in Admin says the same.
  • Nothing else is required. Saved chats, packs and jobs carry over. This release keeps state epoch 1, so rolling back changes which programs run and not your data.

Pack authoring

  • A chat draft is ready only when what it rests on holds. Every citation must trace to a document kept in the chat:
    • the page it names is one of that document's selected pages;
    • the document verifies under the gateway pin;
    • the quoted text is on that page;
    • for a web page, the address is the one in the signed record.
  • The citation rules per mode. A web-research draft needs at least one traced citation. A draft that cites nothing says so in words: "This pack cites no source. It rests on what you told the assistant." Reopened drafts re-check their citations before anything reads them.
  • Test cases written without the draft's rules. In both chat modes Desk asks for test cases written without sight of the draft's rules. Each rests on a traced citation's quote or on one of your own messages, never on the assistant's turns. A disagreement between the draft and those cases comes to you; Desk does not repair the draft on its own. A saved draft without cases offers a button to write them. The created pack carries its cases.
  • The creation dialog states, beside the button, how many citations are traced and how many cases agree.
  • New packs declare the version the evaluator admits, taken from the runtime itself. Examples are served in that version, and a draft declaring another is corrected before it is finalized.
  • The test case editor states the expected handoff target and keeps it through an edit (absent, null, or a kind and a name), and says when a change of expected result removes it.

Connections

  • Google Drive is searched and selected in Desk in place of Google's chooser. Search results are not model context until you select them. A grant now says that Desk asked to read a file; your choice is held in Desk's own interface.

Jobs

  • An installation can refuse jobs from untested releases. Started with --runner-require-tested-releases, Runner refuses to create a job from a release whose tests never ran. Desk keeps its warning and shows Runner's refusal in place of a created job, for both creation paths. Off by default.
  • A trigger's caller can read its own result. GET /api/job-events/{trigger}/occurrences/{occurrence} with the trigger's token answers that occurrence's state and, once its run completes, its disposition and handoff target, and nothing else. It refuses browser requests, any query or body, and any shape but the one route. Runner's 401 and 404 answers pass through unchanged, so nothing tells whether an occurrence exists. The Triggers screen does not describe the read yet.

Releases and repository

  • Native macOS archives for Apple Silicon and Intel, each built and run on a native runner before publication, beside Linux. The managed installer selects your platform and refuses another's archive.
  • Component pins are proposed by Renovate, and package and action updates by Dependabot. A security policy names the private route for vulnerability reports. The README describes the pages the routes actually serve.
Component Pin
Runtime v0.24.0
Runner and source worker v0.2.0
Gateway and required Desk adapters v0.8.0

See installation and updates.

Platforms

This release contains complete Linux/amd64, macOS Apple Silicon (arm64), and
macOS Intel (amd64) archives. All three archives were built and smoke-tested on
native GitHub-hosted runners before publication; neither macOS archive is merely
cross-compiled. Component versions come from the same release lock.

macOS executables are not Developer ID signed or notarized. Gatekeeper may block
downloaded executables; verify the release and checksums, then use Apple's
Privacy & Security → Open Anyway procedure
for the blocked executable. Native CI does not exercise these dialogs. The Codex
subscription subprocess bridge remains Linux-only.

No Windows archive is published. Windows execution is untested, and the managed
installer supports only Linux and macOS.