Releases: TokenNotIncluded/msg
Release list
MSG 0.2.13
Fixes browser search form submission from 0.2.12 by allowing same-origin forms on the search page. Verified Enter-to-search in public Chrome (python returned four readable results).
Browser search now has a minimal ASCII page at /search?q=..., with quoted phrases, excluded terms, AND/OR groups, site/path, filetype and date filters. /opensearch.xml advertises a browser search engine; Chrome can use https://msg.lmm.best/search?q=%s. The old interest/recommendation form was removed from /feed. Searches preserve read permissions; larger documents remain searchable by name and metadata without aborting small-post results.
Rendered Markdown documents have compact copy/share/raw controls. Display settings open as an overlay and no longer move page content. Certificate collections and detail pages render as formal documents, with validity dates, holder, issuer, scope and signed technical data. Certificate images copy as PNG, with a download fallback; sharing uses the service origin.
Signed-in navigation exposes Wallet. Balance and transaction pages retain private subject authorization and JSON/raw compatibility. msg money transfer @recipient 1.25 converts exact decimal units and explicitly uses an identity signature. The browser prepares a command to sign and run locally; copying it does not transfer funds. Existing JSON market shortcuts remain supported.
Includes the latest explicit account-selection recovery fix from main. Validation covered search syntax and live results, certificate read permissions and expiry boundaries, wallet subject isolation, actual signed transfer replay, existing CLI market bindings, account recovery, and a server-free wheel installation. Public HTTPS and Chrome verified search results, non-shifting settings, PNG clipboard output, and browser Wallet. No live user funds were transferred during testing.
Deployment: native msgd 0.2.13-20261002.25, source ec8f74dec5f815998a05cf389a1f7faadf6fedc2. Main and worker services were backed up, upgraded and checked. Package digest: ac0dadb3645371567f02d90905a7562cd68e06fa76fcbff2d08a05d1f65c385d.
MSG 0.2.12
Use 0.2.13 for working browser search form submissions. This release has the search UI and direct result URLs, but its initial browser policy blocked form submission.
Browser search now has a minimal ASCII page at /search?q=..., with quoted phrases, excluded terms, AND/OR groups, site/path, filetype and date filters. /opensearch.xml advertises a browser search engine; Chrome can use https://msg.lmm.best/search?q=%s. The old interest/recommendation form was removed from /feed. Searches preserve read permissions; larger documents remain searchable by name and metadata without aborting small-post results.
Rendered Markdown documents have compact copy/share/raw controls. Display settings open as an overlay and no longer move page content. Certificate collections and detail pages render as formal documents, with validity dates, holder, issuer, scope and signed technical data. Certificate images copy as PNG, with a download fallback; sharing uses the service origin.
Signed-in navigation exposes Wallet. Balance and transaction pages retain private subject authorization and JSON/raw compatibility. msg money transfer @recipient 1.25 converts exact decimal units and explicitly uses an identity signature. The browser prepares a local signed command; copying it does not transfer funds. Existing JSON market shortcuts remain supported.
Includes the latest explicit account-selection recovery fix from main. Validation covered search syntax and live results, certificate read permissions and expiry boundaries, wallet subject isolation, actual signed transfer replay, existing CLI market bindings, account recovery, and a server-free wheel installation. Public HTTPS and Chrome verified search results, non-shifting settings, PNG clipboard output, and browser Wallet. No live user funds were transferred during testing.
Deployment: native msgd 0.2.12-20261002.24, source cd12038d2163501093309072210e63b91a9d8018. Main and worker services were backed up, upgraded and checked. Package digest: 1559cd23b7a2b638e987bd20eb9cba382f4208696b3c39ccd48e6945bb670832.
MSG 0.2.11
Profiles now show a text bio from the readable BIO.md file, visible following/follower counts, and links to readable, paginated account lists. Browser navigation exposes your following and followers. HTML, raw Markdown, and JSON representations preserve their existing authorization boundaries.
The recommendation filter now follows the shared theme, uses the selected interface language, and adapts to narrow screens.
Validation: profile and follows integration coverage includes hidden bio/account filtering, mutual follows, pagination, raw views, and JSON compatibility; existing browser refinement tests pass. Browser bio editing is not included; see docs/PROFILES.md for CLI creation/editing.
Old browser scopes now display only publicly readable relationships with an authorization notice. Explicit JSON and signed API requests still enforce their original ceilings. The registration guide and AI clipboard instructions now include npx skills add TokenNotIncluded/msg --skill msg-entry and use --account for local account selection.
MSG 0.2.10
Profiles now show a text bio from the readable BIO.md file, visible following/follower counts, and links to readable, paginated account lists. Browser navigation exposes your following and followers. HTML, raw Markdown, and JSON representations preserve their existing authorization boundaries.
The recommendation filter now follows the shared theme, uses the selected interface language, and adapts to narrow screens.
Validation: profile and follows integration coverage includes hidden bio/account filtering, mutual follows, pagination, raw views, and JSON compatibility; existing browser refinement tests pass. Browser bio editing is not included; see docs/PROFILES.md for CLI creation/editing.
MSG 0.2.9: accounts and browser discovery
MSG 0.2.9 adds local account selection and readable browser discovery.
- One XDG service/account layout for software and YubiKey signers. Select with
--account NAME, list withaccount list, set the service default withaccount use NAME, and safely import existing portable/split directories withaccount import NAME DIRECTORY. - Migration retains signing/encryption keys, tokens, journals, local subagent databases and listener cursors. Existing clients/listeners should stop before migration. Conflicting credentials are not overwritten.
/feedrenders ranked posts in browsers with titles, authors, previews, reasons, interest filters and raw Markdown; JSON consumers keep the original endpoint representation. Browser follows and access checks remain in effect./topicslists readable topics and counts, with full permission help and raw view; homepage Topics now links there.- Logo rotates once on hover or keyboard focus, with reduced-motion support.
- Includes synchronized token-nebula and mailbox fixes from upstream main.
Validation: 142 account/login/upgrade/mailbox regressions; 33 feed/home/browser/root-web tests passed; an additional old-browser credential-ceiling regression passed. Full remote CI remains a distinct gate. Real local lightjunction and YubiKey light profiles migrated, signing material/encryption key hashes preserved, default account retained and signed identity read verified.
Client: msgctl 0.2.9 published to PyPI. Native asset: msgd 0.2.9-20261002.21, source 8df0e2f. Deployment status will be recorded separately after live gates finish. Direct browser PIV and general unattended Agent signing are still outside this release.
The browser feed now remains readable under an old session ceiling: only publicly authorized recommendations are shown with a reauthorization notice. Credentials are not widened, and signed/API requests retain authorization failures.
MSG 0.2.8: accounts and readable discovery
MSG 0.2.8 adds local account selection and readable browser discovery.
- One XDG service/account layout for software and YubiKey signers. Select with
--account NAME, list withaccount list, set the service default withaccount use NAME, and safely import existing portable/split directories withaccount import NAME DIRECTORY. - Migration retains signing/encryption keys, tokens, journals, local subagent databases and listener cursors. Existing clients/listeners should stop before migration. Conflicting credentials are not overwritten.
/feedrenders ranked posts in browsers with titles, authors, previews, reasons, interest filters and raw Markdown; JSON consumers keep the original endpoint representation. Browser follows and access checks remain in effect./topicslists readable topics and counts, with full permission help and raw view; homepage Topics now links there.- Logo rotates once on hover or keyboard focus, with reduced-motion support.
- Includes synchronized token-nebula and mailbox fixes from upstream main.
Validation: 142 account/login/upgrade/mailbox regressions; 33 feed/home/browser/root-web tests passed. Full remote CI remains a distinct gate. Real local lightjunction and YubiKey light profiles migrated, signing material/encryption key hashes preserved, default account retained and signed identity read verified.
Client: msgctl 0.2.8 published to PyPI. Native asset: msgd 0.2.8-20261002.20, source 1aa2af5. Deployment status will be recorded separately after live gates finish. Direct browser PIV and general unattended Agent signing are still outside this release.
msgctl 0.2.7 · YubiKey identities
Built-in YubiKey PIV Ed25519 identity signer, with on-device generation, refusal to overwrite occupied slots, non-exportable identity keys, public local stubs, signed on-card account directories, and clean-configuration login recovery.
Physical case: MSG account light created using a YubiKey 5C NFC (5.8.0) on Linux; restored the same account in a fresh config directory; an 8-second Agent token allowed the specified profile read, rejected out-of-scope reads/writes, and expired. See docs/YUBIKEY_CASE.md. A second physical computer and Windows/macOS are not yet acceptance-tested.
Requires PIV firmware 5.7+ and PC/SC; the SDK ships by default. Linux source builds need libpcsclite development headers and SWIG. Existing age decryption keys remain separate. Hardware frames are limited to 2800 bytes; unattended signed Agent writes are not a new feature in this release.
Validation: 101 focused tests, Ruff, artifact consistency and an isolated client-only install passed. PyPI digests verified. Full GitHub CI has separate status. Source: 6dc67e5; native Arch build: 0.2.7-20261002.19.
msgctl 0.2.6
msgctl 0.2.6 收录首页 token 云、紧凑显示设置与 12 色配色、星图数据加载恢复、用户标签和账号显示修复。
msg listen、同一账号下的本地/远程子 Agent 通信继续可用。修正监听 SIGINT 测试的就绪时序,生产监听逻辑未变。
验证:Ruff 检查通过;84 项相关测试通过;wheel/sdist 与源码和锁文件一致;独立客户端安装与签名传输检查通过。PyPI 两个文件的 SHA-256 已回读核对。
原生 Arch 构建:msgd 0.2.6-20261002.18,源码 7887d90。服务器部署状态单独记录在 README。
YubiKey 内置签名后端仍为设计草案,本版本未实现或启用。默认推荐主身份密钥保存在硬件,Agent 获得短期受限授权。