Repository navigation
Releases: aiii-dot-id/aii-os
Release list
AII OS 0.1.15
AII OS 0.1.15
This beta release adds recall by meaning from a source you choose (the
provider the identity thinks with, or a plugin that computes vectors on the
machine), hardens the plugin sandbox and the updater, makes the limits that
were compiled into the program into settings, and corrects voice, memory and
shutdown faults found by running and reviewing 0.1.14. It is published for
Ubuntu, macOS and Windows together.
Plugins
- A plugin can declare a model that only some values of one of its settings need, for example
a language pack. AII OS downloads it when the setting comes to need it, also while the
plugin is running, and the setting shows where the download stands. A package that uses
this asks for AII OS 0.1.15 or later. - Plugin revocation lists are kept on disk in the identity's trust directory and are held to
the newest list the identity has accepted. A missing list can no longer bring an older one
back. - On macOS and Linux a native plugin's sandbox now also refuses the machine's own local
services: other programs' sockets, the system's service lookups, opening an address or
starting a program through the desktop, the terminal, the kernel keyring. - A plugin's settings and its own files are read without waiting for the record of the read
to be written. On a busy disk that wait could make a voice engine refuse a session. - A package can be a source of vectors for memory (see Memory, below). Such a package declares
no permission of any kind and asks for AII OS 0.1.15 or later. - A plugin's request for one more streamed reply than it may hold open is refused before it is
sent (NET_STREAM_LIMIT_EXCEEDED). Before, the request was sent and then refused. - Two downloads of the same model or runtime no longer write one file at once.
- The store says when a plugin's build needs a newer macOS or Windows than yours, where it
would offer Install, and downloads nothing. - A plugin is no longer told to wait for memory that a plugin already running holds. A
second engine starts beside the first when the machine has room for both. - The log says when a plugin's call on this machine's storage took a second or longer
(plugins.runtime.slow_storage_call_msinconfig.json).
Memory
- Recall by meaning can be turned on and seen from the page. Two things can make the vectors
it needs: the provider the identity thinks with, when you name an embeddings model on it
(Settings → Providers → Advanced), or a plugin that computes them on this machine. The
Memory view says which is in use, how much of the record it covers, and is where you
choose. With a provider, each memory's text is sent to that provider once to be embedded;
with a plugin it stays on the machine. - AII Meaning (
id.aiii.meaning, beta) is the first plugin that is such a source: a
multilingual embedding model run on the processor, for Linux x86-64 and macOS Apple Silicon
(macOS 26.5 or later). Install it from Plugins when the catalog lists it. - AII OS does not change by itself what reads the memories. What is in use stays in use until
you choose otherwise; a plugin that stops is not replaced by the provider; and when both are
there and you have not chosen, the Memory view asks. - A recall says the similarity floor it used, which belongs to the model that made the
vectors. - A recall's first line says whether the meaning layer read your cue. Each hit's mark says
which layers found it (both (words+meaning)andboth (words+fuzzy)are different
things), with a line that defines the marks; every source states how many it matched and
how many it shows. - An identity can read its beliefs, intentions, commitments, relationships and inbound
messages ranked and alone (source=beliefsand so on), so a section an answer cut can be
read to its end. - A plugin's own memories are read by meaning too, when the identity has a source of vectors.
Until now a plugin's recall was answered by words alone, whatever was installed. - With a plugin that makes the vectors on your machine, every turn of the conversation is
read by meaning. Before, only the newest 2,000 were. A provider's embeddings model still
reads the newest 2,000 (memory.conversation_vector_windowinconfig.json), and the
Memory view says how many older turns that leaves to words alone. - Words you spoke while the identity was busy are no longer lost when the voice session ends
or is closed before it has answered them: they are recorded and answered in their order. - A memory whose text changes is found by what it says now. Its vector is made again at the
next pass, and recall does not use the old one meanwhile. - When you change provider, vectors are no longer kept under the name of a provider that did
not make them. - A message with no text (a picture, a blank reply) is no longer counted as a memory the
layer could not read. - One memory a provider's embeddings model refuses (one too long for it, for example) no
longer keeps the memories beside it from being read by meaning. - A source of vectors that runs on this machine reads a large record much sooner: it is given
two minutes of its own work every ten, where it was given 256 memories. The numbers are
settings undermemoryinconfig.json(backfill_seconds,backfill_rows,
backfill_local_seconds,embed_cue_seconds,embed_memory_seconds,
source_check_retry_seconds,reply_hold_seconds).
Updates and installers
- The Ubuntu package is signed by the release, like every update archive. An installed AII
OS downloads the next package itself, verifies it, and Settings → Updates gives the install
command for the verified file. (This begins with the release after this one: 0.1.14 does
not verify packages.) - Every archive and installer carries
THIRD_PARTY_LICENSES, the licence texts of the
software AII OS is built from. - A package upgrade restarts the identities that are running, each in its own account.
Voice
- A spoken approval of a change to an identity's charter counts only when the speech engine
identified the speaker as the operator's own enrolled voice, which the operator lists.
Until a voice is listed, a typed approval is asked for. - What the recognizer heard is kept beside a corrected transcript, and is shown where a
charter change cites spoken words. - Words spoken while the identity is busy with its own work are kept and answered, and the
page shows them waiting, as it shows a typed message. - When the voice you chose cannot speak a reply, the page says so and shows the reply as
text. The browser's own voice no longer reads it in the chosen voice's place. - With several pages open, the page you are using takes the voice; a page that does not have
it says which machine's page does.
Providers and models
- An API key variable is sent only to the provider it is for. Before, a key in the default
variable could be sent to other providers. If you run your own endpoint and relied on that,
name the variable on its entry (api_key_env) inproviders.json. - A provider's summary of a model's reasoning is kept beside the reply and can be read on the
page; reasoning effort is asked for in the form each model accepts. - Long generations on the Responses interface are no longer cut off while still producing.
The identity's own record
- A belief is confirmed by three distinct sources that rest on three distinct origins; a
belief's standing shows what it rests on. A belief is not confirmed by the length of its
own derivation: the standing says when it could not follow every source to its origin, and
counts only what it found. - The size a self-portrait may be is a setting,
prompt.self_model_max_tokensin
config.json(2000 where you name none). A portrait already accepted stays, whatever you
set later. - Consolidation no longer marks experiences as read when the model answered with more
changes than one pass records; it asks again for fewer. Dreaming no longer stops for good
when what waits does not fit the model: it reads what fits. - A change to the charter cites the operator's own words and tells the operator each time.
Tools
- The shell takes a working directory; a command's exit status is recorded; a tilde inside a
word is no longer refused. - Reading a very long file no longer ends with a line to continue at that the tool then
refuses. - A release of AII OS that its publisher has withdrawn is refused by the updater. Before, no
release could be withdrawn. - Stopping or restarting no longer waits on a browser that has stopped answering: after five
seconds (dashboard.stop_drain_seconds) the dashboard closes its connections and the
identity stops. - A plugin that will not stop when the identity stops is named in the log.
- If an update does not start and the previous version is put back, your settings are put
back as that version left them; what the newer version had written is kept beside them as
config.json.rolled-back.
macOS
- An identity runs as interactive work, not at background priority. Identities registered
before this release: runaii register <slot>again and restart.
Known limitations
Known limitations are listed in the documentation, among them: on the machine itself the
dashboard asks for no access token unless you turn one on (Settings → Dashboard), and a native
plugin can still read most of what your account can read.
AII OS 0.1.14
AII OS 0.1.14
This release makes identities and their updates safer to start, run and
recover, extends the file tools, corrects voice routing and interruption, and
measures Vulkan device memory for plugin component selection. It includes the
changes prepared for 0.1.13, which was not released.
Identities and the record
- A second start of an identity that is already running is refused before it
changes anything: the running process keeps its update state, any pending
restore and its key. Two first starts of one empty directory cannot both
create an identity. - A start's update rollback check waits while another process is replacing the
program, so starting an identity during an update no longer removes the
update's rollback copy. - Records written while the witness answers no longer leave a misplaced witness
record. Writes pause for at most two seconds during each witness pass, and the
witness's first receipt is kept beside the ledger until the record carries it. - A witness key is checked against the time a record was witnessed, so earlier
witnessed records stay verifiable. - On Windows, a new identity's folder is created closed to other accounts.
- Configuration, keys, credentials, certificates and update state are written
as whole files that are synced and renamed into place. - Opening a large store is faster: startup replay finds the records that refer
to the ledger by index. Plugin receipts are kept for 90 days.
Tools
writealso deletes, moves and copies, and creates missing parent folders. A
copy that is stopped part-way reports what its destination now holds.lsrecurses, filters by name and sorts by time;readshows numbered lines;
grepaccepts the common flags of the shell's grep and reports totals.- A delete or move never removes a granted root folder. A call refused by a
safety check, or missing a required argument, is recorded as refused; a call
the operator stopped is recorded as cancelled. - Stopping a turn reaches calls waiting to run and the final round's calls.
Voice
- The speech engine or service chosen in Settings is the one that hears and
speaks, including for typed replies, and a voice that cannot speak a reply
falls back to the browser's. Stopping a reply to start a new one no longer
suppresses the new reply, and a replaced reply reports the audio it played. - An engine message that cannot be read is withheld, counted and logged.
- A reply that could not be recorded is still shown, spoken and delivered, and
says that it was not recorded.
Plugins and updates
- Vulkan device memory budgets are read by a bounded driver probe: on Linux by
aii-vulkan-probe, installed beside a single staticaii; on Windows inside
aii.exe. Component selection uses them, counts reclaimable macOS memory, and
skips a set whose signed runtime exceeds the operator's runtime limits before
applying preference or downloading anything. A runtime that declares a size
beyond those limits is refused before it is downloaded. - In-app updates install the Vulkan probe an update archive carries before the
newaiireplaces the old one. An update already installed for the same
program, for example by another identity, is not installed again. - A plugin process that exits unexpectedly is logged with its last error output.
- Windows executables and the installer are Authenticode-signed.
Dashboard
- A dashboard customization update waits for unsaved work before the page
reloads, and a customization that stops the page from starting links to the
dashboard as shipped. - Home's projects, a project's files and the file viewer work by keyboard.
Plugin SDK
Session.Flushreturns once every frame the session accepted before the call
has been written.- A runtime declaration carries its size and depth, so a host can refuse it
before downloading.
Compatibility
On its first start, 0.1.14 updates the store once: it removes the separate
tool-event table and three unused skill-proposal columns, rebuilds the store's
copy of the ledger from the signed record, and adds indexes. The signed record
itself is not changed. On Linux, the .deb depends on libc6 for the Vulkan
probe; aii itself has no library dependencies.
Plugin packages that declare runtime sizes or need Vulkan measurement may
require AII OS 0.1.14 or later.
Copyright (c) AI Identity Incorporated.
AII OS 0.1.12
AII OS 0.1.12
This release improves database maintenance, recovery, plugin integration and
desktop reliability.
- Optional compression-level optimization and local dictionary learning use the
existing maintenance schedule. Both options default to off. A rewritten
container is adopted only when its total stored size is smaller. - Native compressed-database I/O uses buffers owned by the native interface,
correcting a pointer-checking failure across supported platforms. - Verified startup recovery handles an intact sealed record with a missing empty
tail, while preserving evidence when acknowledged history is missing. - Plugin packages can express ordered component preferences with resource
eligibility and a minimum compatible host version. - Plugin account connections, authenticated push delivery and scheduled adapter
operations provide more complete channel integration. - Protected-file checks preserve literal folder spelling and quoted granted
paths. Credential-path reads share the configuration owner's lock. - Standing inspection and user-interface readback more accurately describe
recorded state and available operations.
Compatibility
Databases written using learned compression dictionaries require a reader with
dictionary support. Update every binary that opens such a database before
enabling dictionary learning. Export an ordinary SQLite copy when another tool
requires it. Existing identity keys, records and configuration remain owned by
their existing directories; package removal does not remove identity data.
Packages using component-set preferences require AII OS 0.1.12 or later.
Copyright (c) AI Identity Incorporated.