Repository navigation
TerminalAI v0.10.0 — a control surface for running many Claude Code and Codex sessions at once.
Windows installers below are unsigned. SmartScreen will warn on first launch: choose More
info, then Run anyway, and only if you got this from a build or release source you trust.
Fixed
Choosing "accept edits" put a Codex session in Codex's most interrupting approval mode. The
control mapped to --ask-for-approval untrusted, which runs only known-safe read operations without
asking and requires approval for anything that mutates state — so it prompted more than "Ask"
(on-request) did, and the permission ladder ran backwards for one agent. The shipped
"Codex · Build" preset, described as writing inside the workspace, was launching that way. Accept
edits now maps to Codex's own documented auto preset: on-request approvals paired with the
workspace-write sandbox. Accept edits together with the read-only sandbox is refused by name
rather than launching a session that would fail on its first write. A test ranks each agent's
emitted approval value by how often the vendor documents it as prompting and asserts the ladder
cannot invert again.
v0.9.0 shipped with no changelog entry. The release commit renamed [Unreleased] to [0.9.0]
and the next commit renamed it straight back rather than opening a new section, so "0.9.0" appeared
nowhere in CHANGELOG.md while four manifests and the README badge declared it. The section is
restored and post-release entries moved back where they belong.
Added
scripts/verify-release-metadata.ps1 — a gate for the claims a release makes about itself. It
refuses a release whose declared version strings disagree (including the version pins workspace
crates use on each other), whose version has no changelog section, whose version sections repeat a
subsection, or whose README states test counts the suites do not report. Run against the tree as
found, it caught three real drifts. scripts/verify-installer.ps1 now runs it too.
Per-session agent credentials and config directory. The child-environment allowlist carries no
credential of any kind — right as a default, but it left API-key, Bedrock and Vertex operators with
an agent that could not authenticate and a symptom that read as an expired login. A launch may now
set CLAUDE_CONFIG_DIR / CODEX_HOME (two directories are two accounts) and name parent variables
to inherit, one at a time. Nothing is inherited by being present in the parent, and a name that is
malformed, reserved to the supervisor, or unset refuses the launch rather than producing a session
quietly missing its credential. terminalai-probe start takes --agent-home and a repeatable
--env-passthrough.
Changed
The permission mode is open, the way reasoning effort already was. Claude Code has added auto,
dontAsk and manual since this launcher's four modes were written, and a closed list did not
merely fail to offer them: a preset naming one was silently rewritten, and the launcher's <select>
reduced it to an empty value that launched with no mode at all. An unmodelled mode now reaches the
agent verbatim with a warning and round-trips visibly in the dropdown. Repository-declared templates
keep the closed vocabulary on purpose — an operator choosing an unmodelled mode is informed consent,
a file that arrives with a clone choosing one is not.
Verification
528 Rust tests (531 with all features) and 303 frontend tests, cargo clippy --workspace --all-targets clean, cargo deny check advisories ok, on Windows 11 26100.