You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
New
Sessions: a chat-style New session screen on desktop and phone, with live Jev/Laya suggestions and suggestion preferences.
Sessions: a Git view from the session header — changes, history and compare.
Sessions: "Debug with an agent" on a session that ended in an error, and a live "Starting session…" row while one starts.
Sessions: experimental opt-in for automatic spawn routing.
ACP: live chat sessions come back after a reboot, and a stale daemon under idle chats is refreshed.
Status bar: a desktop status bar with provider usage and admin diagnostics; it keeps the host awake while sessions work.
Computer use: connect GL.iNet IP KVM targets, and set up computers from trusted SSH hosts and view their screens.
RAN: attach photos to chat sessions, use configured providers and delegated workspaces, and launch from the CLI with sessions spawn --ran.
Models: install remote Ollama, llama.cpp and vLLM servers from the host picker. Guided CLM setup and the System One provider.
Windows: paired Windows hosts are prepared for CLM and Laya in WSL.
Chat: private session artifacts can be downloaded from chat.
Fixes
Desktop: the Windows self-updater builds its own environment, bounds every phase and hands the restart to the supervisor. The updater handoff is hardened.
Web: the app no longer freezes over plain http on a non-localhost origin.
Security: session control tokens are refused on 2FA, PAT management and CLI-login approval. 2FA enrollment can no longer replace an active authenticator.
Security: private projects' knowledge summaries stay private, and every knowledge route checks workspace membership.
Security: remote hosts are workspace-scoped everywhere, and the saved SSH password is no longer leaked.
Security: automations stay inside the repos and projects the caller can edit; file browsing is judged by where a path lands.
Sessions: model picks stay independent of suggested agents; interrupting a background subagent ends its pill.
ACP: unanswered permission requests are refused with reject, not cancelled. Short prompts keep their name.
Mobile: session view alignment, friendly model names and readable launcher pickers.
Knowledge: the self-learning wiki works again.
Auth: the picked SSO provider wins over the session already in the browser.
Known issues
macOS builds are Apple Silicon (arm64) only.
Windows installers are signed (Restart Labs LLC), but SmartScreen may still warn while the publisher builds reputation.
.deb installs don't auto-update; update through your package manager. The AppImage, Windows and macOS builds auto-update.