Skip to content

v2.0.0

Choose a tag to compare

@agentconnect-release agentconnect-release released this 28 Sep 10:39
· 107 commits to main since this release
d82c2f1

Summary

  • Decisions — Define reusable questions that a model answers to route work: gate a conversation, route a shared bot's messages, pick a session's runtime and model, or route GitHub, GitLab, and Gitea events to repositories. Decisions can be chained, tried against sample messages, and reviewed through their recent evaluations, and are now available in every console.
  • Daemon Groups — Spread sessions across a group's daemons by capacity and run isolated sessions on another member's executor. Self-hosted daemons can share a PostgreSQL session store, and daemon groups no longer require a feature flag.
  • Session Modes and !new — Choose how each conversation maps messages to sessions, and use !new to start over in a conversation.
  • More Messaging Platforms — QQ official bots support private chats, group mentions, user profiles, and file attachments. Google Chat, including Chat apps built as Workspace add-ons, is available as a preview behind the google-chat console flag.
  • Repository Access — Authorize or watch every repository an installation covers, lower a grant's access in place, and choose whether each additional repository is always checked out or made available on demand.
  • Release Triggers — Trigger agents when GitHub, GitLab, or Gitea releases are published, and configure installation-wide GitHub triggers.
  • Scoped API Keys — Limit a personal API key to read-only or agent-chat access, restrict it to selected agents, and edit or regenerate it after creation.
  • Slack Channel Reach — Slack agents can read and post in any public channel on demand and reply in existing threads. Private channels and DMs remain limited to the conversation that invoked the agent.
  • Console Updates — The console adds a draft Simplified Chinese translation, follows the system color scheme, and has a redesigned Knowledge page.

This release also improves sandbox and Kubernetes session reliability, resumes admitted turns after a daemon restart, and adds Gemini CLI model selection.

Behavior change: Organization owners can now view, edit, and re-share every resource in their organization, including restricted ones. Slack bots join public channels on demand by default; this can be turned off per bot in the console. New session branches use the a10t/ prefix. Requests authenticated with an API key can no longer create organizations or manage API keys or daemon credentials.

Features

  • add Decision contracts and mock UI service (#2236) (ce918da)
  • add organization provider key configuration (#2241) (342f4a7)
  • authz: let organization owners see every resource, restricted ones included (#2244) (4e2bf05)
  • choose repositories by decision from the console (#2479) (fd31564)
  • configure By decision on a conversation, held until the gate lands (#2306) (407e497), closes #2228
  • configure By decision routing on a shared bot, held until it runs (#2354) (3b97d26), closes #2228
  • configure run settings for decision targets (#2348) (d5391db)
  • connect Decision Console to persistence and daemon previews (#2265) (e5cbfe5)
  • console: wake a session's own sandbox, and say when it was removed (#2317) (4795d56), closes #1896
  • console: wake a sleeping session pod from the Git tab and a merge-when-ready arm (#2353) (f372534), closes #2346 #2329 #1896
  • control-plane: add the Google Chat platform provider (#2574) (9d4416f)
  • control-plane: an agent placed on a group keeps its managed memory in the Control Plane (#2190) (657bef3)
  • control-plane: API key permissions and agent selection (#2578) (c726ba1)
  • control-plane: authorize every repository an installation covers (#2456) (340eec1)
  • control-plane: carry a per-conversation session mode to the daemon (#2192) (edd7c2c)
  • control-plane: choose how each additional repository is materialized (#2417) (c9f2d73)
  • control-plane: edit and regenerate personal API keys after minting (#2584) (d7b1105)
  • control-plane: expose Decisions through the AgentConnect MCP (#2544) (22ac8c3)
  • control-plane: let a Google Chat DM's sender open it in the console (#2602) (cec0802)
  • control-plane: let a webchat conversation change its own host agent (#2585) (33ea0c8)
  • control-plane: lower a repository or installation grant's access in place (#2498) (d37ac0c)
  • control-plane: name an agent's repository selector and answer its candidates (#2469) (fb4c0fa)
  • control-plane: serve the OpenAPI document as the public contract (#2536) (4213154)
  • daemon: a host-strategy shim launcher and root-relative sandbox paths (#2182) (29a1e14)
  • daemon: add !new — start over, in whichever way this conversation means it (#2214) (4dc0b20)
  • daemon: add bounded PR context to model selection (#2373) (d510550)
  • daemon: add the Google Chat platform module (#2579) (f888bec)
  • daemon: answer QQ elicitations from a quoted reply (#2604) (b3228a3), closes #2331
  • daemon: bind local microsandbox VMs through the in-process executor entry (M4) (#2457) (ebabbd4)
  • daemon: check out only the additional repositories marked always (#2426) (d6a6713)
  • daemon: executor facet — host a group member's session behind a TLS-PSK pipe (#2186) (19caaae)
  • daemon: find the Kimi Code CLI in its installer's bin dir (#2624) (3b7a1aa)
  • daemon: fold Slack minimal mode's interim replies into the chrome stream (#2224) (c9ffbc1), closes #1793
  • daemon: give Gemini CLI a model catalog and launch-time model selection (#2208) (b2a5aff), closes #2149
  • daemon: give thread affinity its own record, off the session row (#2193) (6c4e4f2)
  • daemon: judge a Decision's target where the session could land, in its strategy's catalog (S2c) (#2434) (ca31615)
  • daemon: judge By decision messages before they reach the agent (#2323) (19aa859), closes #2228
  • daemon: keep each session's birth strategy durable (S2b) (#2436) (e97cd82)
  • daemon: key a conversation's messages onto one session where it appends (#2204) (a5513a6)
  • daemon: let a self-hosted daemon run the shared PostgreSQL store (#2240) (0a89110), closes #2188 #2231 #2188
  • daemon: let a Telegram agent take one of its messages back (#2237) (c4d8ddb)
  • daemon: let running turns finish before a config change respawns the host (#2340) (f3810b7)
  • daemon: make the transcript a channel record with per-session admissions (#2273) (23de884)
  • daemon: offer an installation grant's repositories on demand (#2461) (71f6f6a)
  • daemon: offer the microsandbox strategy on the executor facet (#2200) (b320d9f), closes #2203
  • daemon: place spread sessions by capacity utilization (#2391) (e193774), closes #2332
  • daemon: probe the VM image's models in the background and carry them across upgrades (#2508) (b5f840c)
  • daemon: re-probe a cluster pool's runtimes on a timer and on request (#2327) (50c267d)
  • daemon: record every inbound message before routing it (#2299) (f283c8c)
  • daemon: run a confined srt session's workspace Git and files in its shim (R1b-2a) (#2491) (100fa4e)
  • daemon: run an isolated session on a group member's executor (#2198) (919c2d7)
  • daemon: run confined local srt sessions through the in-process entry (R1b-1) (#2478) (89ea553)
  • daemon: run every local srt host in its own shim (R1b-2b) (#2493) (07cfd5b)
  • daemon: run local microsandbox Git over the VM shim (#2408) (9b11a82)
  • daemon: run srt sessions on executors inside an SRT-wrapped shim (R1a) (#2468) (2b8ea49)
  • daemon: select a session's repositories by decision before it starts (#2476) (729a2cd)
  • daemon: support runtime-specific Kubernetes API keys (#2446) (d9648cb)
  • daemon: sync the workspace to its configured branch instead of pulling (#1829) (f19b8cc)
  • daemon: the sandbox strategy table, launch dispatch on the agent's strategy (S2a) (#2422) (cc55000)
  • daemon: the strategy launcher takes an environment descriptor (M3) (#2433) (12adda2)
  • daemon: use chat history for decision model selection (#2362) (e28eb27)
  • daemon: watch an isolated session's merge-when-ready in its own pod (#2329) (c61c35f), closes #1896
  • decisions: add daemon Jev evaluation with provider credentials (#2256) (3fd5f31)
  • decisions: chain result branches across decision consumers (#2395) (0f7309f)
  • decisions: include per-file pull request context (#2549) (d44b505)
  • decisions: recent evaluations drawer with Jev model result and raw JSON (#2377) (8b77e07)
  • decisions: record model selection evaluations (#2535) (c4cd0c3)
  • decisions: show a routed code-host turn's verdict in the session flow (#2407) (dd5b902)
  • decisions: support Cloud and daemon group preview targets (#2278) (f95c815)
  • executor: protect a hosted VM's credentials with the local preparers (#2420) (bb33458)
  • executor: the agent's execution strategy, checked against the placement's tables (#2410) (c78f9f3)
  • github: show review preparation in checks (#2380) (6e05928)
  • googlechat: answer agent questions from an in-thread card (#2607) (e9de88a)
  • googlechat: claim Google Workspace customers on the multi-tenant deployment app (#2600) (deb2c55)
  • googlechat: fence rows by tenant, budget writes per app, release freed customers (#2603) (903bc14)
  • googlechat: serve Chat apps built as Workspace add-ons (#2619) (9b6099d)
  • googlechat: serve every Workspace organization from the deployment app (#2608) (dd07906)
  • hooks: installation-wide GitHub trigger rows in the Control Plane (#2530) (b335b84)
  • hooks: watch GitHub releases as a fifth subject family (#2402) (b6a7b3c)
  • hooks: watch GitLab and Gitea releases (#2409) (1297d9c)
  • let agents evaluate explicitly attached Decisions (#2298) (7c016d0)
  • mcp: let webchat's createAgent hand over a prefilled dialog, not an approval (#2170) (30b11cb)
  • memory: conditional entry mutations on native-writable managed homes (#2168) (a4de325)
  • message: normalize Google Chat interaction events (#2568) (4ef838a)
  • protocol,control-plane: session executor facts, candidates and a relayed prepare (#2185) (7b37e36)
  • protocol: typesafe dialect and an invalid_request code for the key server (#2249) (9419e08)
  • qq: add official bot private chats and group mentions (#2189) (9d80c0a)
  • qq: add user profiles and inbound file attachments (#2251) (0c1c777)
  • relay,daemon: expose strict im admission through the host seam (#2571) (a000060)
  • relay: add the Google Chat ingress module (#2576) (3912ee9)
  • relay: demux Google Chat by tenant and answer unclaimed tenants with the claim prompt (#2599) (c33fd27)
  • relay: fire installation-wide GitHub trigger rows (#2532) (33e8e70), closes #2530
  • relay: probe bot credentials periodically and report two evidence tiers (#2314) (24a4be1), closes #1869 #1869
  • relay: serve AI SDK chat turns over /ai-sdk/chat/:conversationId (#2572) (804d321)
  • review: let an authorized PR conversation turn amend the sealed review verdict (#2531) (2fdbc7d)
  • route a shared bot's By decision conversations through one evaluation (#2359) (30928ac), closes #2228
  • route GitHub hooks by a repository Decision and gate Linear by decision (#2384) (48279d5), closes #2383
  • route GitLab and Gitea hooks by a repository Decision (#2396) (a1c0f01)
  • select session runtime and model with Decisions (#2312) (56e14d8)
  • session-executors: the executor owns the generation, and nothing needs a shared store (#2197) (2f2352f), closes #2188
  • setup: configure the deployment-owned Google Chat app (#2569) (057df71)
  • show Decision evaluations by source (#2540) (e95fa5b)
  • skills: add the agentconnect-debug skill (#2533) (9a082ce), closes #898 #2240
  • slack: reach any public channel on demand, with a per-bot switch; fix workspace search (#2180) (f8079c4), closes #1661
  • slack: record how a bot credential was lost, and mark an ambiguous rejection (#2297) (a2ee7e6), closes #1869
  • slack: replace a custom Slack app's bot token in place (#2284) (17b1517), closes #1869
  • slack: revoke a socket-mode bot when Slack uninstalls it or revokes its token (#2285) (229ae3b), closes #1869
  • title each Decision evaluation row by what it judged (#2552) (8717f43)
  • title model selection evaluations by session and name mentions in titles (#2562) (ee478ad)
  • try a By decision gate and read its recent evaluations (#2349) (8c94f72), closes #2228
  • web: add the Decisions console and the By decision channel gate (#2242) (05f9459)
  • web: add the Google Chat console module (#2580) (00723b6)
  • web: align By decision surfaces with the console design (#2383) (fdd2eb4)
  • web: authorize a whole installation from Authorize repository (#2509) (c75f180)
  • web: authorize every repository of an installation (#2467) (813fe52)
  • web: bind a conversation By decision from the console (#2337) (266fdcb), closes #2228
  • web: choose Always or On demand for each additional repository (#2440) (1ded8f6)
  • web: compact By decision rule tables to match the console design (#2388) (a6918a2)
  • web: complete console i18n migration (#2239) (ed884e3)
  • web: configure, test, and review a shared bot's By decision routing (#2367) (00464b2), closes #2228
  • web: drop the executor chips from the daemon card (#2232) (76b7ea1)
  • web: drop Try a message from the shared-bot routing rules modal (#2616) (5a78469)
  • web: follow the system color scheme for the console theme (#2617) (c679649), closes #2477
  • web: gate the Google Chat console entry points behind a feature flag (#2614) (82441ec)
  • web: gate the QQ integration behind a qq feature flag (#2211) (53de53c), closes #2189
  • web: give the group Runtimes card one tab per strategy (#2515) (c5653fb)
  • web: group Authorize repository's GitHub picker by account (#2511) (3006f6a)
  • web: group integration choices into chat and workflow (#2233) (4385265)
  • web: let a native card wait for the reader instead of opening itself (#2173) (b7ffdc6)
  • web: let an operator choose how a conversation keys its sessions (#2221) (520f20d)
  • web: list the agents bound to each external-memory connection (#2207) (e727215)
  • web: localize the console with an en source catalog and a zh-CN draft (#2196) (9896f47)
  • web: mark a bound Decision chip editable and fill the dispatch menu (#2415) (7f7b866)
  • web: merge a Decision's places and recent evaluations into one card (#2561) (142bff1)
  • web: move the language switcher to the account menu and restore migrated copy (#2261) (c6a30f9)
  • web: name execution strategies plainly and list runtimes per strategy (#2454) (6281f74), closes #2438
  • web: name the Decision where an agent's model is picked by one (#2399) (ebe3547)
  • web: name the group members that need a runtime login (#2397) (2821801)
  • web: notify when an integration is revoked (#2291) (7935be7)
  • web: offer a revoked Slack app's repair where it shows (#2293) (ea1b69d), closes #1869
  • web: offer Decision examples on an empty Decisions page (#2546) (ce1ff12)
  • web: one settings popover for a conversation's trigger and session mode (#2264) (95cbc2d), closes #2221
  • web: one-row Workspace card with an editable repository dropdown (#2496) (37a6528)
  • web: pick the agent's execution strategy per placement (S3) (#2438) (fa41912)
  • web: pick the console language from a submenu (#2335) (3bca3b1)
  • web: put the By decision checkout behind a console flag (#2528) (7e4b0c5)
  • web: redesign the Knowledge console around a list and an entry page (#2209) (f300b6c)
  • web: remove daemon groups feature flag (#2489) (079a02b)
  • web: remove the decisions feature flag (#2374) (3c7ad43)
  • web: render external-memory settings from the plugin's own schema (#2303) (3577ebc)
  • web: return along a Decision chain and draw its steps as chips (#2423) (c4506c4)
  • web: review a Dream suggestion from its opened row (#2300) (e12200e)
  • web: share the provider/model picker parts and show details on hover (#2363) (8a3ce93)
  • web: show a session's By decision results in its message flow (#2385) (166193b)
  • web: show external-memory connections as rows with details on demand (#2219) (d9421a7)
  • web: show model evaluations in the By decision editor and hover card (#2543) (a7090b7)
  • web: show where a session runs, and let a group spread them (#2201) (bbc6a0b)
  • web: stack each later Decision of a chain as a sheet over its parent (#2431) (3a1f1e4)
  • web: tag the page's own agent in routing target pickers (#2462) (d0e911b)
  • web: title and align every Recent evaluations list with the places card (#2575) (230ab29)
  • web: unify the Decision chip on the mirrored-pair design (#2394) (d30af04)
  • web: use the console dropdown and agent icons in the API key dialog (#2626) (ff95300)
  • web: watch every repository of an installation from Add integration (#2534) (0833043), closes #2530 #2532
  • web: word Decision questions in plain language (#2550) (00bd139)
  • web: wrap long lines and preview Markdown in the session file viewer (#2618) (d28f69a)

Bug Fixes

  • approvals: let the console choose any option a permission request offers (#2611) (76de1ef), closes #1969
  • auth: align owner usage attribution and approval authority (#2263) (3ef7f46)
  • chart: expose the temporary Decisions console flag (#2270) (6f4a700)
  • chart: project model egress clients by consuming host (#2274) (d77c4dc)
  • chart: route /ai-sdk/chat to the relay pool (#2582) (d0b6746), closes #2572
  • chart: route /googlechat/events to the relay pool (#2586) (6c14165), closes #2576
  • ci: add standalone Conventional PR check (#2437) (887d15c)
  • ci: gate microsandbox VM failures (#2418) (129369b)
  • ci: run microsandbox VM in release gate (#2445) (d54e6c5)
  • cli: grant unit control through sudoers where polkit has no rules.d (#2305) (cb444f7)
  • cli: skip the polkit tty agent where no polkit rule can grant (#2325) (9ce887d)
  • cli: suggest the command the operator ran, and keep a bare --root off the default service (#2336) (9e91be8)
  • connect GitHub repository access across accounts (#2379) (384fe4d)
  • control-plane: arm merge-when-ready through the member serving the agent (#2234) (44c976d)
  • control-plane: block merges on incomplete PR reviews (#2448) (93d25c8)
  • control-plane: block the connector catalog's Google Chat by its real service id (#2615) (0b78429)
  • control-plane: find an installation row's sessions under their repository (#2556) (ada056f)
  • control-plane: hint a session's executor from the relayed ready prepare (#2393) (7f9b6e7)
  • control-plane: keep a review verdict that arrives after the run reaper (#2252) (8d13354), closes #2247
  • control-plane: let a routing save add an Off channel (#2404) (3764140)
  • control-plane: let an installation-wide row publish its review Check (#2551) (6a81647)
  • control-plane: persist the GitHub no-run redelivery cap per GUID (#2486) (482319c)
  • control-plane: refuse daemon credential management from API-key requests (#2627) (6146aa0)
  • control-plane: refuse organization creation and key management from API-key requests (#2620) (e4ff4d4)
  • control-plane: run integration tests in forked workers (#2470) (9517a80)
  • control-plane: stop retrying session PR-link captures forever (#2344) (fcffeae), closes #1896
  • control-plane: wake a PR session at most once per feedback delivery (#2484) (53cf865)
  • daemon,web: keep Gemini's model picker in step with its catalog (#2216) (3e4e412), closes #2208
  • daemon: a host shim must not outlive the daemon that started it (#2187) (9dc9a58)
  • daemon: accept agentd's protocol generation on exec and TCP replies (#2419) (22b536b)
  • daemon: age out a moved-away agent's sessions behind its lasting fence (#2269) (3662de1)
  • daemon: age out a no-longer-served agent's sessions on a private store (#2260) (f8378a6), closes #1032 #2246
  • daemon: agent-authored text on a chat card never becomes a link (#2625) (2312514), closes #1809
  • daemon: apply configured agent model to memory dream extraction … (#2381) (7a27feb), closes #2277
  • daemon: audit a clone's repository config before retention inspects it (#2430) (9404162), closes #2246
  • daemon: auto-allow only requests that name a built-in tool exactly (#2220) (4234ed6)
  • daemon: cancel turns when their integration is removed (#2177) (8d1f30e)
  • daemon: cancel workspace Git when the shutdown drain gives up (#2320) (99cb042)
  • daemon: collect a session directory whose row is gone (#2283) (#2310) (bdb9d9b), closes #2294
  • daemon: collect the sandbox image cache after retention, including flat leftovers (#2289) (02509a2), closes #2282
  • daemon: compose a placed session's launch in its executor's coordinates (#2203) (c4bccd4)
  • daemon: count a holder's isolated sessions by their live runtimes (#2225) (069b348)
  • daemon: count a holder's own isolated sessions from their rows (#2212) (3845a4b)
  • daemon: drop a runtime title that echoes only the prompt's first line (#2525) (409f5b7)
  • daemon: exit a CP-commanded restart even when shutdown never settles (#2302) (f7502c0)
  • daemon: extend review fetch timeout to 60 seconds (#2366) (4bf385f)
  • daemon: fail closed when an off-disk workspace has no bound sandbox (#2308) (3574f00)
  • daemon: fence sandbox acquisition across ownership changes (#2442) (9274ab4)
  • daemon: fence sandbox reacquisition after duty revoke (#2487) (224a617)
  • daemon: finish a host stop whose VM still runs another execution (#2318) (fc8d8c4)
  • daemon: finish composing a placed session's launch where it runs (#2206) (cdd003d)
  • daemon: give each OpenCode session its own ACP host (#2328) (802638b)
  • daemon: keep /dev usable under Codex full access in a sandbox (#2217) (7acc132), closes openai/codex#16451
  • daemon: keep a pool pod up while a merge-when-ready watcher is armed in it (#2290) (aec99df), closes #1896
  • daemon: keep a session home only where its runtime can authenticate (#2400) (e4f3362)
  • daemon: keep a session's runtime and model a consistent pair across runtime changes (#2521) (c7b64e1)
  • daemon: keep an isolated session in its birth strategy after the agent's changes (#2517) (4a1537e)
  • daemon: keep an isolated session's cwd record in its own directory (#2311) (6888cd8)
  • daemon: keep dream inputs out of reach of the agent's sessions (#2622) (5a156e6)
  • daemon: keep isolated pool sessions' per-turn work off the agent pod (#2315) (70b3907), closes #1896
  • daemon: keep running turns when additional repositories change (#2512) (24ee4dd)
  • daemon: let work spawned inside a shared start wait on it without observing itself (#2179) (992fd85)
  • daemon: mount an overlay base read-only under srt (#2501) (08a7662)
  • daemon: move session branches to a10t/ so a repository's dev branch cannot block them (#2347) (10db20e)
  • daemon: name a Google Chat DM row after the person in it (#2589) (a550b5d)
  • daemon: name the AppArmor user-namespace restriction in the SRT probe reason (#2465) (6ddab7a)
  • daemon: name the session by its outward id on the code-host hook/start barrier (#2166) (41630fe)
  • daemon: never follow a link or wait on a pipe the runtime left in a checkout (#2316) (d131e85)
  • daemon: never run this host's Git in a VM's orphaned session directory (#2449) (e50b7aa)
  • daemon: never signal a shim runtime that failed to spawn (#2163) (3aebaba)
  • daemon: post no startup notice on non-webchat chat platforms (#2392) (ac7d32e)
  • daemon: pre-warm an additional repository's own credential (#2215) (2d3e4be), closes #2210
  • daemon: prepare a new pool session before its first key-server launch (#2365) (671b7eb)
  • daemon: prepare an isolated pool session without waking the agent pod unless work is due (#2326) (d6d055b)
  • daemon: prepare the share of a session that joins a shared cold start (#2555) (569436f), closes #2542
  • daemon: prepare the starting session's share when a shared host cold-starts (#2542) (23a87b0)
  • daemon: preserve replies during background tool updates (#2441) (b1bccd6)
  • daemon: preserve sandbox ownership across handoff and channel loss (#2447) (fed3249)
  • daemon: reach a spread session's files on its executor, and list a key-server host's clones (#2351) (2758f77), closes #1896 #2206
  • daemon: read a spread session's console files on its executor (#2355) (8dd9e12)
  • daemon: reap the agent's shared host by its own work, not isolated traffic (#2352) (e327067)
  • daemon: reclaim idle session sandboxes independently (#2432) (7e276ac)
  • daemon: recover missing Kubernetes sandbox launches (#2429) (189d83f)
  • daemon: recover reclamation after lost fencing replies (#2451) (7c765ee)
  • daemon: refresh sandbox endpoints during shim retries (#2471) (b935b07)
  • daemon: refuse a FIFO or device a runtime left where the daemon reads a file (#2321) (5e58777)
  • daemon: register a verified runtime-memory policy for DeepSeek Harness (#2587) (ced3856)
  • daemon: release a session row a dead process left mid-turn (#2250) (ffd0ce4), closes #2245
  • daemon: renew the local VM's shim channel daily, not every five minutes (#2165) (df47c31)
  • daemon: replay the agent's own replies when its runtime session is recreated (#2519) (c47b2af)
  • daemon: report a cold session as resuming until its turn starts (#2338) (5290fa2)
  • daemon: report a refused repository as a refusal, not an outage (#2412) (e8ac6af)
  • daemon: report a shim bind that ran out of time as a timeout under load (#2466) (db75878)
  • daemon: report a turn the daemon failed to admit instead of calling the agent busy (#2267) (cfe74bf)
  • daemon: report pinned decision run settings (#2358) (cc78815)
  • daemon: resolve a confined session's additional repositories on the session side (#2319) (d84c751)
  • daemon: resume admitted turns after restart (#2370) (bf60986)
  • daemon: rethrow an unreached checkout probe instead of recloning (#2309) (e9f8965), closes #1896
  • daemon: retire a session whose workspace is only sandbox mountpoints (#2255) (573ae44), closes #2246
  • daemon: retire microsandbox session VMs whose session row is gone (#2294) (9ea0a65), closes #2282
  • daemon: retry failed Kubernetes sandbox takeovers (#2435) (7bd4a91)
  • daemon: review a grant-covered repository at an exact checkout (#2506) (a16a411)
  • daemon: round the Decision evaluator timeout to whole milliseconds (#2343) (590bedb)
  • daemon: route a GitHub additional repository to GitHub on gitlab and gitea workspaces (#2223) (4168aa1), closes #2215
  • daemon: run a spread session's console Git on its executor (#2357) (d382301)
  • daemon: run an isolated pool session on its own pod alone (#2330) (b16a62c), closes #1896
  • daemon: seed Claude's first-start bookkeeping into the private config (#2594) (9bd003b)
  • daemon: seed Kimi Code's environment-scoped login into private HOMEs (#2628) (d82c2f1)
  • daemon: serve an agent a duty grant re-adds after a register detach (#2292) (778ede3)
  • daemon: start a confined pool session's host without preparing the agent checkout (#2313) (0525ffc)
  • daemon: stop a session's own VM when its directory is removed (#2254) (bbabd2f), closes #2246
  • daemon: stop a workspace read from resuming a sleeping session pod (#2346) (a4c8554), closes #2317 #1896
  • daemon: suspend a sandbox pod again when its wake never binds (#2279) (33946a1), closes #2275
  • daemon: take back a microsandbox VM name a failed create left claimed (#2268) (a1b329a)
  • daemon: tell QQ conversations apart by their openid tails (#2230) (0fd94ce)
  • daemon: tell the model a replayed delivery may have been interrupted (#2301) (e6e3f57)
  • daemon: wait for an agent to load before retiring its expired sessions (#2271) (5576f23)
  • daemon: warn when microsandbox state outlives a backend switch (#2288) (aa2bceb), closes #2282
  • decisions: preserve code-host subject attribution (#2537) (c01313a)
  • deps: bump undici to 8.11.2 so native fetch decodes responses again (#2514) (ab679a0), closes #2504 nodejs/undici#5865 #5858
  • googlechat: learn the app identity from traffic, never from members/app (#2588) (82ee063)
  • googlechat: open the claim page from the welcome card's button (#2609) (60a7874)
  • hooks: link cleanup deliveries to sessions (#2439) (ce5b38e)
  • keep repository access raise-only (#2502) (6af19a0)
  • name a deployment row's cadence as it runs, and capitalize the grant refusal (#2553) (4328da0)
  • qq: stream runtime-independent replies and label apps by ID (#2266) (1a8ad18)
  • relay: apply the CP replay that arrives with rc/registered (#2164) (6b1485c)
  • relay: ignore Linear delegation boilerplate during routing (#2175) (0fd3d3a)
  • relay: ignore PR auto-merge toggle events (#2428) (e9b25a5)
  • release: omit duplicate version heading from release notes (#2610) (b62b396)
  • restore code-host parent replies (#2195) (15e7770)
  • setup: place the Google Chat card under the Google OAuth card (#2583) (1532f1a)
  • setup: say the Google Chat card's app installs on one agent at a time (#2591) (5e89cd6)
  • show selected runtime in sessions and review footers (#2378) (3829e54)
  • web,control-plane: bring QQ's copy in line with the other platforms' (#2229) (ce6b897)
  • web: align decision navigation and model selectors (#2334) (f222c3f)
  • web: allow returning to login after sign-in failure (#2595) (e9a0003)
  • webchat: keep a turn streaming to its requester when a watcher resumes it (#2621) (c96f61a)
  • webchat: preserve streamed reply boundaries (#2425) (7778a43)
  • webchat: refuse a turn on a member that does not hold the conversation (#2231) (5f2b4e6)
  • webchat: retire silent turn work after history sync (#2427) (0f97829)
  • web: clarify organization owner access in sharing controls (#2259) (25cadf9)
  • web: dispatch picks leave routing, and By decision on Off channels (#2386) (8b31297)
  • web: drop leading zeros from the rule min-probability input (#2460) (d6c960e)
  • web: drop the access badge from the file browser's repository picker (#2503) (6f0f4a8)
  • web: drop the duplicate Stop using decision item from the code-host row menu (#2474) (6875763)
  • web: fill the Add integration platform rows and name only the agent (#2464) (75e27b2)
  • web: give Provider keys the same section header as the daemon lists (#2483) (640d8d6)
  • web: give QQ's secret field its label back (#2235) (877d82a), closes #2229
  • web: hide duplicate session executor row (#2375) (e6aed78)
  • web: hide redundant daemon memory session reason (#2371) (613ce46)
  • web: hide the OpenRouter and Cloudflare provider keys until something consumes them (#2563) (b30b954)
  • web: hide the Provider keys count while the list shows a load error (#2485) (a02a49d)
  • web: hold approval notifications until the agent roster has loaded (#2296) (d35560f)
  • web: keep a long evaluation answer within its row (#2577) (a9f5ffa)
  • web: keep each integration group on one row in the empty state (#2458) (e67d0a8)
  • web: keep integration tile groups to two rows and center the empty-state grid (#2482) (2c30efb)
  • web: keep the Git URL workspace tile on one row with the others (#2455) (504c1fc)
  • web: keep the GitHub triggers card titled by the host (#2522) (425e7f5)
  • web: keep the runtime icon before a Decision-picked model (#2411) (86fd452)
  • web: lay out the QQ bot pane like the other platforms' (#2222) (e0eeebb)
  • web: let Save commit a trusted user typed but never entered (#2181) (9078eae)
  • web: match a repo's grant row by numeric id in the integration dialog (#2613) (6cb7b21)
  • web: match the decision runtime table and model picker to the design (#2342) (4ea4838)
  • web: move decision Visibility below Criteria (#2459) (4b573c9)
  • web: move provider guidance into Infra header (#2490) (40866bf)
  • web: name the runtime default model in session Details and composer (#2452) (427c4a5)
  • web: offer no trusted users on an installation-wide row (#2557) (462514e)
  • web: one run-settings row in every model picker (#2350) (185edd8), closes #2348 #2334
  • web: pick a row's checkout from a menu so repository names fit (#2488) (6de72ec)
  • web: pick an agent's models from its strategy's catalog (#2510) (75e6444)
  • web: place delivery session links beside IDs (#2443) (0e525d8)
  • web: recover from cached JWKS after key rotation (#2597) (f5e4d1e)
  • web: refetch session lists on session events (#2524) (1e5c0aa)
  • web: refresh an open session's runtime and model after its snapshot changes (#2523) (941b9ed)
  • web: report a native dialog's outcome on the conversation's own turn frame (#2172) (9608f3e)
  • web: resume a group agent's session on the member holding it (#2213) (e411a57)
  • web: right-align the model editor's pickers with the fallback and hide an inert remove (#2581) (b4d1a24)
  • web: say "Messaging apps" in the Integrations description to match its section heading (#2565) (6eae75c)
  • web: say Otherwise covers only unmatched answers (#2564) (3d95dff)
  • web: say why By decision is unavailable, not only that it is (#2507) (e286d8d)
  • web: send a continued conversation's turn to the picked participant (#2499) (852f1e4)
  • web: show a daemon that never came back from a relaunch as offline (#2322) (86f2824)
  • web: show a Decision's places by their marks and a hidden place as hidden (#2573) (4c7b779)
  • web: show a pointer cursor on the review access button (#2612) (19fbdf0)
  • web: show a revoked or offline integration honestly on the agent side (#2281) (9f970b0)
  • web: show an answer's tooltip only when its text is cut off (#2545) (66e1607)
  • web: show pending decision runtime selection (#2356) (205a27c)
  • web: show TypeSafe icon for Jev models (#2287) (56924d8)
  • web: tighten the decision sample panel to the design (#2345) (fd4527b)
  • web: translate the webchat approval card buttons (#2598) (37fc825)
  • web: trim the agent empty-integrations hint to one sentence (#2475) (6551e60)
  • web: warn before changing answers in a used Decision (#2304) (f8521a8)

Internal

  • chart: bump open-connector to v1.6.5 (#2372) (c4c987e)
  • daemon: derive the shim's runtime paths from one root (#2155) (204e3b3)
  • daemon: drop the Git config audit and let srt runtimes write .git/config (#2473) (9b772dd)
  • daemon: drop the Linux gates R1b-2a added around srt (#2492) (abbc86f)
  • daemon: move the Kubernetes-free shim dial layer out of k8s/ (#2154) (d11e89b)
  • daemon: move the relay-ingress strategy onto the platform contract (#2567) (1fd8dcd)
  • daemon: name a host's local environment in one place (#2494) (531cd45)
  • daemon: pin microsandbox 0.7.2 (#2416) (e1fb4b5)
  • daemon: place workspaces per scope instead of by a process-wide mode (#2160) (5f1fd22)
  • daemon: read the workspace seam only through the bounded helper (#2324) (46edaec)
  • daemon: resolve the execution plane per host key behind one interface (#2158) (a11d38d)
  • daemon: retire the direct srt launch for daemon hosts (R1b-2c) (#2497) (5b8e810)
  • daemon: run the microsandbox runtime and its helper tunnels through the shim (#2161) (79ea3f6)
  • daemon: separate obtaining a shim endpoint from dialing and driving it (#2157) (b147ba5)
  • daemon: update ACP SDK to 1.5.0 (#2376) (3c207d6)
  • decisions: separate code-host state policy (#2516) (99b05df)
  • decisions: unify code-host state construction (#2513) (e6caabe)
  • deps-dev: bump dotenv from 17.4.2 to 18.0.2 (#2505) (a02243b)
  • deps: bump the npm-minor-and-patch group with 19 updates (#2504) (c626f96)
  • docker: pin codex-acp 1.12.0-agentconnect.2 in the sandbox image (#2171) (477f843), closes #2151
  • docs: Update README.md (#2169) (c9b3007)
  • escape raw NUL bytes so git diffs these files as text (#2162) (a921fd2)
  • runtime: bump DeepSeek ACP to 0.4.33 (#2191) (76b37d0)
  • runtime: refresh all sandbox runtime pins (#2472) (22bd8d4)
  • runtime: refresh Claude and Codex ACP pins (#2368) (71b1849)
  • web: ignore the agent files next dev generates (#2202) (cd2c8c9)
  • web: one Decision picker for channel gates and agent runtimes (#2369) (fdbabce)
  • web: retire the Memory tab's compatibility views (#2167) (fda280f), closes #2098 #2100

Full Changelog: v1.60.0...v2.0.0