Releases: RedRobotKK/Replay
Release list
v0.6.0
Changelog
Fixes
- 61af7ff: fix(otlp): OT6 grepped four literals, so an os/exec courier passed it (#227) (@RedRobotKK)
- 2653149: fix(proxy): parse gzip OpenAI SSE with the OpenAI parser (#220) (@RedRobotKK)
- 067891d: fix(route): the one value command with no funding line, behind a subtest that skipped forever (#228) (@RedRobotKK)
- 310d7c7: hotfix: main is lint-red from #221, two unused handler parameters (#224) (@RedRobotKK)
- 2d9498d: prefix: say that tool churn is a known mechanism, not this setup (@saitodaniel)
- 6bf3a5d: prefix: state the shape, not the counts, and freeze that (#214) (@RedRobotKK)
Documentation
- b02f924: docs(adr): 0021 states the table correctly and then argues from its opposite (#265) (@RedRobotKK)
- 38bb59b: docs(adr): compile the merge, not the branch (@saitodaniel)
- 4fb7e82: docs(adr): unknown-model cache-read multiple is two questions (#253) (@RedRobotKK)
- f3755cf: docs: ADR-0018, the instrument rules the last nine defects were all instances of (#123) (@RedRobotKK)
- c8d7707: docs: ADR-0019, and the surface claims the frozen harness rejected (#140) (@RedRobotKK)
- 3e1aecc: docs: a preprint and launch copy that cite the corpus they actually have (#207) (@RedRobotKK)
- 8ee65a5: docs: a week with no defined deliverable is a week of whatever the operator found interesting (#256) (@RedRobotKK)
- 55e2fef: docs: four agent CLIs, at three different standards of proof (#109) (@RedRobotKK)
- 5669761: docs: index the external research, and gate ideas before calling them defensible (#156) (@RedRobotKK)
- 3bb59cb: docs: narrow two promises to what they meant (#101) (@RedRobotKK)
- b1b9c3e: docs: public surfaces brought current, and a coverage gate that earns its badge (#231) (@RedRobotKK)
- ca805e7: docs: repair main, and land the retraction the index already cited (@saitodaniel)
- 7c8d75c: docs: say which currency each figure is in (#99) (@RedRobotKK)
- d36654c: docs: the Grok withdrawal was wrong, for the reason it was written to fix (#108) (@RedRobotKK)
- a86575d: docs: the concurrency caveat was wrong, and usefully so (#100) (@RedRobotKK)
- a428538: docs: the flag surface stated each archetype's size twice and five of six disagreed with the table (#247) (@RedRobotKK)
- 58df0fd: docs: the index's top-ranked idea was refuted by our own corpus (#198) (@RedRobotKK)
- 1048bf8: docs: two audits of what this repository does not check (#113) (@RedRobotKK)
- dc40b35: docs: two of the three abort conditions do not need a billed week to answer (#260) (@RedRobotKK)
Other
- f72e3f8: 0.6.0: build identity in the corpus payload, and the launch-readiness defects the panel found (#293) (@RedRobotKK)
- f72e234: 1.0 gate: v0.5.4 reproduces byte for byte, and the three deferred findings closed (#297) (@RedRobotKK)
- b033c6b: A retracted corpus figure was withdrawn in one file and published in six others (#230) (@RedRobotKK)
- 9b3e4c2: Audit of five reviewer claims: a wrong price, a negative published count, and two instruments that did not say what they measured (#212) (@RedRobotKK)
- 447d2a7: Licence: the canonical BUSL-1.1 text in full, and the README says the licence in words because GitHub cannot (#294) (@RedRobotKK)
- feb1527: Merge main: keep both additions to guardcheck.go (@saitodaniel)
- e187c9b: Merge pull request #185 from RedRobotKK/perf/decode-content-once (@RedRobotKK)
- 73df357: Merge pull request #190 from RedRobotKK/perf/measure-content-without-decoding (@RedRobotKK)
- fbee758: Merge pull request #191 from RedRobotKK/fix/duplicate-benchmark (@RedRobotKK)
- cdea53e: Merge pull request #192 from RedRobotKK/land/chain-truncate-label (@RedRobotKK)
- 1b3a90e: Merge pull request #200 from RedRobotKK/perf/measure-source-once (@RedRobotKK)
- 9ead646: Merge pull request #202 from RedRobotKK/tools/merge-guard (@RedRobotKK)
- 260f50b: Merge pull request #203 from RedRobotKK/docs/cite-tool-prefix (@RedRobotKK)
- 0fa5594: Merge pull request #204 from RedRobotKK/docs/adr-0020-merge-guard (@RedRobotKK)
- 762abd1: Merge pull request #205 from RedRobotKK/fix/tui-body-budget (@RedRobotKK)
- 0e22e39: README: the break-cause table rotted three times in five days, and the last re-run reversed it (#222) (@RedRobotKK)
- 2395789: README: the install matrix is generated from the channel manifest, and doc.go carries the package documentation for pkg.go.dev (#295) (@RedRobotKK)
- fed6cd6: Revert doctor agent discovery from main, pending review (@saitodaniel)
- 0f04263: Revert the self-update feature swept onto main by a docs commit (@saitodaniel)
- 5629d33: The match rate never said how much of it was exact (#209) (@RedRobotKK)
- efeb0ee: Windows path keys, and two commands that answered with a swallowed error (#155) (@RedRobotKK)
- 18cce1b: adr: 0021 said Accepted while its own index said superseded (#273) (@RedRobotKK)
- 838ee1f: adr: record that 0019 produces 0013's moat, and gate the freshness claim (#146) (@RedRobotKK)
- a4dafe6: advise: attribute unused tools to the server that defines them (#102) (@RedRobotKK)
- bbd361c: advise: name the Ollama surface instead of reporting an empty corpus (#199) (@RedRobotKK)
- 310e32a: advise: say how much of the report the verifier cannot reach (#195) (@RedRobotKK)
- 44af39f: advisor: a session that did not use a tool is not a session that stopped (#119) (@RedRobotKK)
- 8f32a31: advisor: a status the reader sets, not one inferred from the corpus moving (#114) (@RedRobotKK)
- 2e1a78b: advisor: test the join that fills unused-tools, and scope what it claims (#196) (@RedRobotKK)
- d4c1949: analysis: a transcript answering "not mixed" was answering a question nothing asked (#264) (@RedRobotKK)
- e2f4787: analysis: an error bar nobody measured stops printing as one (#120) (@RedRobotKK)
- be00c88: analysis: name the estimate that steps outside the fit, and drop its borrowed bar (#121) (@RedRobotKK)
- a6b259b: analysis: sigma's band was the estimator describing itself (#96) (@RedRobotKK)
- 6283877: analysis: stop charging a turn's write to blocks that cannot account for it (#125) (@RedRobotKK)
- e5b05c0: analysis: the retracted trial's figures survived in the file that produced them (#153) (@RedRobotKK)
- 5649cd7: budget: reach the refusal that was never reached, and pin the one that cannot fire (#128) (@RedRobotKK)
- ef24372: budget: the refusal is a function, so all three branches can be reached (#129) (@RedRobotKK)
- fb89961: budget: the standing cost of a setup, as a file you can commit (#103) (@RedRobotKK)
- 2eab748: burn: say what a cache hit rate looks like elsewhere (#176) (@RedRobotKK)
- e3d538c: cachemodel: a stated discount reaches the price the tool prints (#218) (@RedRobotKK)
- 302795b: cachemodel: the unknown-model multiple names a rule now, and the rule moved it (#271) (@RedRobotKK)
- 7c9c5e7: cause: stop naming a predecessor the wire never named (#158) (@RedRobotKK)
- 01e5c23: ceiling: make the cache-blind finding runnable, in the reader's billing basis (#145) (@RedRobotKK)
- e9b14bc: ci: a reviewer that disables each guard a change touches (#130) (@RedRobotKK)
- 6f7ff4a: ci: check whether the hosted installer is the one in this repository (#95) (@RedRobotKK)
- 2145c07: ci: run the frozen mutant catalogue, which had never run (#116) (@RedRobotKK)
- 9b8312e: ci: stop cancelling main's runs (#152) (@RedRobotKK)
- 784bc11: ci: the CLI reference embedded today, so every branch failed at midnight (#179) (@RedRobotKK)
- 3646535: ci: the merge guard has failed on every push to main since it was written (#290) (@RedRobotKK)
- 88dd2ea...
v0.5.4
Changelog
Features
- bea44d0: feat(install): --no-tui, so the last step is declinable from the command line (#91) (@RedRobotKK)
- 744921b: feat(tui): the last four screens read this machine (#94) (@RedRobotKK)
Documentation
- 3da41f7: docs: half the TUI screens describe nobody, and the analysis already exists (#92) (@RedRobotKK)
- 4dcfb9f: docs: record 0.5.4 (@saitodaniel)
Other
- 9b7533f: tui: the advise screen reads this machine (#93) (@RedRobotKK)
Verify a download
Every release ships checksums.txt signed with Sigstore keyless signing. Verify before running anything:
cosign verify-blob --certificate checksums.txt.pem --signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/RedRobotKK/Replay/.*' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com checksums.txt
sha256sum --check --ignore-missing checksums.txtv0.5.3
Changelog
Features
- af35dc1: feat(cost): fail the build when avoidable spend is over a ceiling (#90) (@RedRobotKK)
Documentation
- 9be9ed6: docs: record 0.5.3 (@saitodaniel)
Verify a download
Every release ships checksums.txt signed with Sigstore keyless signing. Verify before running anything:
cosign verify-blob --certificate checksums.txt.pem --signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/RedRobotKK/Replay/.*' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com checksums.txt
sha256sum --check --ignore-missing checksums.txtv0.5.2
Changelog
Features
- b0473b8: feat(since): what ran and what it cost while you were away (#86) (@RedRobotKK)
Fixes
- d696e6d: fix(tui): the width is a measurement, not a constant (#88) (@RedRobotKK)
- 219981e: fix(tui): wrap prose at the output boundary, 72 overflows to 30 (#89) (@RedRobotKK)
- 7ecf318: replay prefix: gate a change that voids the cached prefix, before it merges (#85) (@RedRobotKK)
Documentation
- c295089: docs: generate the CLI reference from the binary, and check it in CI (#84) (@RedRobotKK)
- ced1306: docs: record 0.5.2, and 0.5.1 which was tagged without an entry (@saitodaniel)
Other
- 6dcd470: A local model cannot report a 100% cache hit, and burn stops claiming it (@saitodaniel)
- da7e9ef: An Ollama request with no n_past line has an unknown prefix, not a zero one (@saitodaniel)
- 43454fc: Build the semantic colour layer the layout already specified (@saitodaniel)
- 201b1b7: Colour the cursor and the breaks column, and stop the colours nesting (@saitodaniel)
- 0607967: Date the installer's corpus figures, and check they still match (@saitodaniel)
- c69c875: Fetch vendor facts, verify them, and refuse to believe them (@saitodaniel)
- b1bc003: Generate the screens as images, and check they still match (@saitodaniel)
- 1e1124c: Give the currency screen tests a corpus of their own (@saitodaniel)
- 5dc3bec: Keep unsourced figures out of the installer, comments included (@saitodaniel)
- 7e80325: Make the kill matrix run, and kill the mutant nothing was killing (#81) (@RedRobotKK)
- 38deffb: Make the live screen reachable (@saitodaniel)
- 433be3b: Merge pull request #71 from RedRobotKK/fix/diff-lane-scope (@RedRobotKK)
- 966fd59: Merge pull request #72 from RedRobotKK/feat/tui-color (@RedRobotKK)
- 91dbfba: Merge pull request #73 from RedRobotKK/feat/currency (@RedRobotKK)
- a8d7ab8: Merge pull request #74 from RedRobotKK/feat/tui-currency (@RedRobotKK)
- c405b4e: Merge pull request #75 from RedRobotKK/feat/signed-feed (@RedRobotKK)
- a7d3a59: Merge pull request #76 from RedRobotKK/test/x402-e2e (@RedRobotKK)
- 3213562: Merge pull request #77 from RedRobotKK/fix/ollama-parse (@RedRobotKK)
- f89187d: Merge pull request #78 from RedRobotKK/feat/live-screen (@RedRobotKK)
- 2b05de1: Merge pull request #79 from RedRobotKK/docs/screens (@RedRobotKK)
- 5a69848: Merge pull request #80 from RedRobotKK/fix/tipline (@RedRobotKK)
- d101838: Pin the screen images to something a runner can reproduce (@saitodaniel)
- 9804149: Retract "no local transcript": Grok keeps 3.8 GB on disk (#82) (@RedRobotKK)
- 8373f3d: Run the x402 lifecycle against the real binary, in CI (@saitodaniel)
- cb6b470: Say how much of a session the report actually covers (@saitodaniel)
- 480ca3e: Show the figure in the reader's own currency, beside the dollars (@saitodaniel)
- 5b195e6: Show the reader's currency on the TUI cost screen too (@saitodaniel)
- a4b98fc: The tip line asked /dev/null whether it was a terminal (@saitodaniel)
- 6c40a6b: ledger-bench: before and after, for every product that meters agent spend (#83) (@RedRobotKK)
- 136d3eb: tui-audit: render every screen and check it, in CI (#87) (@RedRobotKK)
Verify a download
Every release ships checksums.txt signed with Sigstore keyless signing. Verify before running anything:
cosign verify-blob --certificate checksums.txt.pem --signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/RedRobotKK/Replay/.*' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com checksums.txt
sha256sum --check --ignore-missing checksums.txtv0.5.1
Changelog
Other
- 7d6b280: Answer an agent's questions mid-session, over MCP on stdio (@saitodaniel)
- b61a24d: Consolidate what a day of measuring the product and the site turned up (@saitodaniel)
- 562a145: Correct the licence statement to contributors, and de-drift the docs (@saitodaniel)
- 2e13e3e: Count a task as a session, not as an agent lane (@saitodaniel)
- 9bd3621: Discover the desktop app's sandbox transcripts, and keep them out of the total (@saitodaniel)
- 5b3dd0e: Draw the running proxy, and correct a false claim in the security surface (@saitodaniel)
- 4694b34: Guard the command list against the switch, not against the help text (@saitodaniel)
- a015a73: Make the branch pass its own gates (@saitodaniel)
- 5944ba4: Merge pull request #70 from RedRobotKK/feat/source-provenance (@RedRobotKK)
- bcde3a7: Meter Ollama, whose total means something different from everyone else's (#68) (@RedRobotKK)
- c37feb8: Pin vendor behaviour to the version it was read against (@saitodaniel)
- c112bea: Read the provider's pricing page, and price five models it lists (#67) (@RedRobotKK)
- 845f1ea: Remove two scratch benchmarks that were committed by accident (@saitodaniel)
- 6395ea1: Render the share card as a PNG, in two registers, with a screen to preview it (@saitodaniel)
- 4452370: Report the subscription window beside the metered spend (@saitodaniel)
- 0d21b53: Report which directories hold a project's records, before the search (@saitodaniel)
- fc7ba96: Say how to wire Replay into anything, in one place (@saitodaniel)
- ebbf3e2: Serve one MCP vocabulary, from the binary, and say which answers need a network (@saitodaniel)
- 48dba3f: Stop forwarding a secret when the vault cannot store its mapping (@saitodaniel)
- 68bc782: Stop reporting what was never measured as a passing result (@saitodaniel)
- 5e18ad6: Stop the source block crashing, and bound what it costs per session (@saitodaniel)
- b521772: The MCP snippet was not valid JSON on Windows (@saitodaniel)
- 307b09a: Warn when every file a session read came from one directory (@saitodaniel)
- 72a9fdc: Write a boot block naming where this project keeps its records (@saitodaniel)
- 347c90a: replay burn: three surfaces, three units, and no total across them (#69) (@RedRobotKK)
Verify a download
Every release ships checksums.txt signed with Sigstore keyless signing. Verify before running anything:
cosign verify-blob --certificate checksums.txt.pem --signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/RedRobotKK/Replay/.*' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com checksums.txt
sha256sum --check --ignore-missing checksums.txtv0.5.0
Changelog
Documentation
- eb781bf: docs: four options for live context visibility, and no recommendation (#39) (@RedRobotKK)
- a200006: docs: the money path, priced against our own measurements (#40) (@RedRobotKK)
Other
- 2ada402: --check-prices never compared the cache-read price it parsed (#55) (@RedRobotKK)
- f0236bb: A ledger must read in the order it was written (#56) (@RedRobotKK)
- 5d9e2e3: A registry of CLI surfaces where a status cannot outrun its evidence (#30) (@RedRobotKK)
- b469d23: A test variable named real shadowed the builtin (#45) (@RedRobotKK)
- 0b9ba73: Clear the golangci-lint backlog, and stop it hiding the next one (#35) (@RedRobotKK)
- d046a7f: Correct three docs that claimed Windows was verified (@saitodaniel)
- 6ebc48d: Enforce the context-budget conservation laws in CI (#42) (@RedRobotKK)
- 0f63d3a: Evidence: lane isolation, and the headline retracted the same day (@saitodaniel)
- ce9954b: Explain an empty machine from cost and corpus, not just bare replay (#64) (@RedRobotKK)
- 717a46e: Freeze the defects, including the one that had to survive to be believed (#43) (@RedRobotKK)
- 3715beb: Generate the storyboard from the formatter that will draw it (#46) (@RedRobotKK)
- 71378af: Live dashboard design, and a width rule that is a test rather than a promise (#36) (@RedRobotKK)
- 84ccd2f: Measure the routing baseline, and split "blocked on n=1" in two (#38) (@RedRobotKK)
- a45a3f5: Nobody is going to type a flag, so stop designing for the person who would (#50) (@RedRobotKK)
- 0d852b7: One screen reads the machine now, and says which parts (#59) (@RedRobotKK)
- 44ef12a: Outreach material for the Grok wire findings, scoped to what was measured (#33) (@RedRobotKK)
- 8731767: Pick the task that cost you and ask why (#62) (@RedRobotKK)
- 4392696: Pin cosign and syft, because the SHA pins the action and not the tool (#66) (@RedRobotKK)
- 31a95d2: README: record today's correction where the other ones live (@saitodaniel)
- 249362b: README: say the tip-jar line plainly (@saitodaniel)
- 4ebea84: Rows, and the keys that were removed for not having any (#61) (@RedRobotKK)
- 0fa77aa: Say when a context report covers one lane of several (@saitodaniel)
- 98f652c: Say when the estimate borrowed a constant instead of measuring one (#32) (@RedRobotKK)
- e25d776: Search for the corpus everywhere it might be, then say where you looked (#37) (@RedRobotKK)
- d1d919e: Seventy-two flags, six kinds of screen element (#49) (@RedRobotKK)
- 3a9de5e: Sigma's band was describing the estimator, not the corpus (#41) (@RedRobotKK)
- e55114e: Stop building Windows archives (@saitodaniel)
- 28af2f7: Stop the installer claiming a replacement it did not make (#65) (@RedRobotKK)
- f89bf28: The TUI runs now (#57) (@RedRobotKK)
- 8feb34e: The TUI was showing numbers nobody measured (#58) (@RedRobotKK)
- 62a4a78: The Windows job passes now, and that is not the same as supported (#47) (@RedRobotKK)
- c1594a6: The abort test waited for the ledger and asserted on the log (#44) (@RedRobotKK)
- 126f22f: The cost screen adds up the real corpus, and says so while it counts (#60) (@RedRobotKK)
- 8fb6617: The installer told every new user a retracted number (#29) (@RedRobotKK)
- 88b235d: Three wire families, not two, and a headline retracted the same day (#31) (@RedRobotKK)
- de1cb81: Windows could never record a consent decision, and eviction was not an LRU (#34) (@RedRobotKK)
- 831d0c7: build(deps): bump actions/stale from 9.1.0 to 11.0.0 (#51) (@dependabot[bot])
- 9926427: build(deps): bump anchore/sbom-action/download-syft (#52) (@dependabot[bot])
- c31d026: build(deps): bump sigstore/cosign-installer from 3.9.1 to 4.1.2 (#53) (@dependabot[bot])
- 8d2f76e: tip: ask straight, and name what the waste would have bought (@saitodaniel)
- 3d8159c: v0.5.0: BUSL 1.1, Codex support, and a TUI that reports its own version (#63) (@RedRobotKK)
Verify a download
Every release ships checksums.txt signed with Sigstore keyless signing. Verify before running anything:
cosign verify-blob --certificate checksums.txt.pem --signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/RedRobotKK/Replay/.*' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com checksums.txt
sha256sum --check --ignore-missing checksums.txtv0.4.0
The number in this release was retracted the same day it shipped
At 09:40 this morning Replay measured a fan-out session and reported that 98.8% of its re-billed tokens came from one cause. That went into a commit message as fact.
By 17:50 the number was 4.2%.
Nothing about the workload changed. The instrument was wrong. stats.observe compared each request's cacheable prefix against one session-wide field, so in a session running parallel sub-agents, lane A's request overwrote it and lane B was judged against lane A. Neither had changed anything. Both were recorded as having changed. Thirty-one of the thirty-four events had never happened.
Both figures are in the git history. The wrong one is still there.
What was actually broken
Six fields compared "this request" against "the previous one" while holding a single session-wide slot. cachemodel's own vocabulary always said lane — ReadFirst is documented as "the first request in a lane; nothing to compare against" — and the proxy gated it on a session-wide request count.
| Field | What it broke |
|---|---|
prefixHash |
Phantom prefix changes, and every break attributed to them |
last |
ClassifyRead measured one lane's usage against another's, manufacturing breaks and overruns |
model, lastSeen |
An opus main loop with haiku sub-agents reported "model changed between requests" for lanes that never changed model |
context, whatIf, reReads |
A quiet sub-agent erased a busy one's live breakdown on /replay/status |
| the first-request gate | Every sub-agent's opening request scored as a cache hit that never happened |
The last one is the one to take away. It produced no error, no break and no anomaly. It only inflated a success metric — the direction nobody audits — and it was found by a mutation that survived, not by anyone reading the code.
The lesson was already written down, against a seventh field, with a comment explaining exactly why it had to be keyed per lane. It had been applied to one field out of six.
Your breaks now name the tool that caused them
"System prompt or tool definitions changed" covered every prefix change and named a cause that mostly did not happen: across the entire trial, system_bytes never moved once.
cache break session=a3f2 lane=main: read 0 of 157080 expected, 157080 tokens
re-billed; likely cause: tool definitions changed (added 3 tool(s):
mcp__claude_ai_Otter_ai__otter_fetch, otter_get_user_info, otter_search;
removed 1 tool(s): WaitForMcpServers)
157,080 tokens re-billed because three Otter.ai tools finished connecting. A cached prefix is keyed on content, so a connector completing its handshake mid-session voids everything before it. All three real breaks in the corrected trial were exactly this shape.
If you load MCP tools dynamically, this is the line worth grepping for.
Also in 0.4.0
- Per-lane telemetry on
/replay/status—context_by_lane,re_reads_by_lane,what_if_by_lane. Added additively: the existing keys keep their shapes and now mean the main loop specifically, because the endpoint carries no schema version and a consumer has nothing to branch on. - A pre-flight deficit warning, off by default. Warns before a changed prefix is re-billed. A ceiling landing inside the estimate's own ±15% band suppresses the refusal rather than deciding it.
- A throughput guard for
rescore, which re-walks the whole lane per request. Measured at 17.8 ms of proxy CPU for a 200-request session. Measured, not fixed. - Two data races fixed. Introduced this morning by the lane-map change; no tagged release ever carried them.
Windows is unsupported, and has never been tested
Not a gap in the roadmap. The CI job listed Windows and failed earlier, at go vet, on a helper behind //go:build unix. Fixing that today produced the first Windows test run there has ever been. Fourteen tests failed, and the ones that matter assert Unix file-mode semantics guarding the ledger and the masking vault.
A Windows binary that runs while not keeping those promises is worse than no Windows binary. macOS and Linux are tested on every push with go vet and go test -race. WSL works.
Install
curl -fsSL https://redrobot.jp/replay.sh | sh
Zero dependencies. go.mod is 45 bytes with no require block.
Full evidence: Lane isolation, 2026-09-06 · Changelog · Release criteria
v0.3.0
Changelog
Features
- 4c04609: feat(doctor): name the flags that fix an unenforced cap (@saitodaniel)
- 2f3e839: feat(doctor): stop telling people to add a cap they already have (@saitodaniel)
- 8965c5f: feat(proxy): read streamed OpenAI responses, and ask for the usage they omit (@saitodaniel)
- 94c24ff: feat(proxy): read, guard and ledger OpenAI-compatible requests (@saitodaniel)
- ab9e64d: feat(rules): carry what the provider documents beside what traffic showed (@saitodaniel)
- d79a7dd: feat(usage): defend the inclusive-versus-exclusive counting trap, and record the Cursor spike (@saitodaniel)
- b18e6c4: feat(usage): normalise the usage record, and keep the provider's payload verbatim (@saitodaniel)
Fixes
- 9a88df0: fix(install): run the binary before reporting that it installed (@saitodaniel)
- 52cb683: fix(lint): check the writes in writeTrimNotes (@saitodaniel)
- 445d260: fix(lint): the last five findings, and unorphan a doc comment (@saitodaniel)
- 13fad0b: fix(metrics): four counters were summed over a map that evicts (@saitodaniel)
- f005e2d: fix(proxy): say when a request was forwarded without being read (@saitodaniel)
- ad7e884: fix(test): assert the invariant the boundary has, not the one darwin happens to show (@saitodaniel)
- aef15fd: fix: green the CI that has been red since before this release (@saitodaniel)
Documentation
- 24d54d5: docs: a metrics reference, and why none of them is labelled by session (@saitodaniel)
- 605b42c: docs: add a CLA so the licence stays a decision rather than an accident (@saitodaniel)
- 94ed17f: docs: alerting expressions, and the two thresholds you should not copy (@saitodaniel)
- 7a89146: docs: catch the guide, the evidence index and the architecture note up with what shipped (@saitodaniel)
- 4a02ccf: docs: date the figures that come from a corpus that keeps growing (@saitodaniel)
- 2ecdf04: docs: lay the README out for a public front page, and kill the last stale claim (@saitodaniel)
- f18b2ab: docs: mark v0.2.0 released, and correct two roadmap statuses spike 4 disproved (@saitodaniel)
- c5af963: docs: record what the metrics requirement asked for and what shipped instead (@saitodaniel)
- 4058781: docs: the proxy was never agnostic, and the README said it was (@saitodaniel)
Other
- 18ad452: test(masking): an adversarial matrix against the rehydration boundary (@saitodaniel)
- f2c77cb: test(masking): assert which denial reason, not just that one was denied (@saitodaniel)
Verify a download
Every release ships checksums.txt signed with Sigstore keyless signing. Verify before running anything:
cosign verify-blob --certificate checksums.txt.pem --signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/RedRobotKK/Replay/.*' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com checksums.txt
sha256sum --check --ignore-missing checksums.txtv0.2.0
Changelog
Features
- 359bfe5: feat(context): attribute what entered a session's context, by tool (@saitodaniel)
- 8d258e2: feat(context): measure the eviction gap instead of disclaiming it (@saitodaniel)
- 7e06e98: feat(cost): --compare, the one measurement an invoice could contradict (@saitodaniel)
- c2aa5a5: feat(guards): make the guards visible, and derive their thresholds from your own ledger (@saitodaniel)
- 98914d0: feat(route): the structural half of a model switch, without the fabricated constant (@saitodaniel)
- 4f5ac9c: feat(trim): score a byte cap offline, and probe whether it would have hurt (@saitodaniel)
Fixes
- 1c8c594: fix(proxy): the error budget divided one lane's errors by every lane's tokens (@saitodaniel)
- 1d7c78a: fix(route): the sigma gate was guarding a figure nothing computed (@saitodaniel)
- 2b30b0d: fix(rules): refuse a priced model whose cache reads are free (@saitodaniel)
- 465906a: fix(trial): breaches reverted whichever policy happened to be current (@saitodaniel)
Documentation
- 0a9bb10: docs: document the forensics commands and the four guards (@saitodaniel)
- badc628: docs: document the new commands and say who this is actually for (@saitodaniel)
Other
- f650725: spike 4: the proxy runs against the real provider, and refusals get attributed (@saitodaniel)
Verify a download
Every release ships checksums.txt signed with Sigstore keyless signing. Verify before running anything:
cosign verify-blob --certificate checksums.txt.pem --signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/RedRobotKK/Replay/.*' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com checksums.txt
sha256sum --check --ignore-missing checksums.txtv0.1.2
Changelog
Features
- c04eac1: feat(advise): --apply proposes the one setting evidence can decide (@saitodaniel)
- 26472c4: feat(cost): cost per task, and reposition the README around unit economics (@saitodaniel)
- 7907354: feat(rules): provider rules become a dated document, not compiled constants (@saitodaniel)
- 3aedc8e: feat(statusline): price the cache misses while the session is still running (@saitodaniel)
Fixes
- 01506ee: fix(install): close two verification bypasses in the installer (@saitodaniel)
- 9300e20: fix(learn): stamp and check the rules actually in effect (@saitodaniel)
- d52f9e8: fix: refuse symlinked archive members, and stop learn -out clobbering files (@saitodaniel)
- fc5a7b0: fix: work the rest of the red and blue findings (@saitodaniel)
Other
- a02fdc2: Publish a 1363-session corpus, and stop understating it by two orders of magnitude (@saitodaniel)
Verify a download
Every release ships checksums.txt signed with Sigstore keyless signing. Verify before running anything:
cosign verify-blob --certificate checksums.txt.pem --signature checksums.txt.sig \
--certificate-identity-regexp 'https://github.com/RedRobotKK/Replay/.*' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com checksums.txt
sha256sum --check --ignore-missing checksums.txt