Skip to content

v1.7.2

Choose a tag to compare

@github-actions github-actions released this 25 Aug 03:24
· 16 commits to main since this release

Same code as v1.7.0 and v1.7.1 — this release exists to fix how release notes are produced.

No functional change since v1.7.0: the only commits since are to the release
workflow itself, so the binaries are equivalent. v1.7.0 published its last commit
message as the release body and v1.7.1 published generated notes, both because the
annotation was read from the checked-out repo. actions/checkout resolves the ref to
a commit and force-fetches it over refs/tags/, so the annotation is unreachable
locally no matter how checkout is configured. The notes are now read over the API
instead. If you are reading this text on the release page, that fix works.

The full contents of the 1.7.x line:

  • Tool-call events. IToolCallSink publishes a started/completed pair around every
    tool invocation, carrying job id, depth, tool name, duration, outcome and result size.
    Published from LlmAgent.WrapTools, so it covers the streaming and non-streaming turn
    paths alike — CLI mode and the non-streaming /jobs endpoints previously produced no
    tool activity at all. Events carry no raw arguments: ArgsDigest is the argument names
    plus a hash of the values, so a repeated call stays recognisable without arguments
    reaching a display. Subscribe by resolving ToolCallSink.

  • Tools.CliDelegationTimeoutSeconds (default 300, runtime-tunable). A delegated
    claude/codex/copilot run was previously bounded only by the parent agent's cancellation.

  • Tool-result offloading never fired. OffloadingAIFunction tested result as string,
    but AIFunctionFactory marshals return values through System.Text.Json and hands back a
    JsonElement, so the test was null every time. MaxToolResultChars and the
    read_tool_result / head_tool_result / tail_tool_result / grep_tool_result family
    had been inert for every built-in tool.

  • Delegated CLI sessions did not survive a restart. CliSessionStore was in-memory, so
    a restart silently dropped every delegated conversation's session_id and the next call
    cold-started an amnesiac CLI. Now backed by a cli_sessions table, cleared with its job.

  • Timed-out child processes discarded their output. exec_shell and CLI delegation read
    their pipes with a cancellation token, and ReadToEndAsync throws its whole buffer away
    when that fires — so a command that ran the full timeout returned nothing at all. The
    kill now closes the pipes and the captured output is returned with the error.

  • Two high-severity advisories. Microsoft.Data.Sqlite to 10.0.11 (clears
    GHSA-2m69-gcr7-jv3q via SQLitePCLRaw 2.1.12) and a direct Microsoft.Bcl.Memory 10.0.11
    pin overriding the vulnerable 9.0.4 that Microsoft.ML.Tokenizers.Data.O200kBase pins
    (GHSA-73j8-2gch-69rq).

  • Release notes ignored the tag annotation (this release).

Offloading becoming active is a real behaviour change. At the default 16 000 characters a
wide grep or a large read_file now returns a placeholder and the model must fetch the
content via the tool-result tools. Raise Tools.MaxToolResultChars to tune it, or set 0
to disable.