Releases: amontlabs/silo
Release list
Silo 0.11.1
| Download | |
|---|---|
| macOS (Apple Silicon) | DMG |
| Linux x86-64 | AppImage · Debian package |
| Linux ARM64 | AppImage · Debian package |
0.11.0 was not published separately, so this release also contains all of its changes, listed below.
Before upgrading
- Debian package users: Silo's APT repository moved. Run this once, then update as usual:
sudo sed -i 's#https://0xpolarzero.github.io/silo/apt#https://apt.silo.amontlabs.com/apt#' /etc/apt/sources.list.d/silo.sources - GitHub access: the Silo GitHub App is now
silo-amont-labs. Earlier versions can't find it, so update to keep using GitHub repository access. - Remote computers: update Silo on every computer you manage remotely; this release changes the remote protocol.
All changes (563)
Patch Changes
- c6b16ed: Fixed LCU failing to download on macOS 15 with "Silo could not save LCU".
Changes from 0.11.0
Minor Changes
- 363cd18: Agents installed later in a sandbox are now set up for computer use automatically. Claude Code and Codex are registered up front, and Pi, OMP and Hermes are registered as soon as you install them, so the "Set up computer use for new agents" menu item is gone.
- 2e05df9: Silo now prepares the VM image, the LCU archive and ChatGPT for Linux in the background at launch, with one non-blocking notification that shows progress, offers Retry when something fails, and stays out of the way once everything is ready.
- ff2cbc6: New sandboxes use the v4 guest image, which includes the built-in Linux desktop, and get agent computer use with no setup. Silo downloads the official ChatGPT app for Linux from OpenAI by itself in the background on every computer that runs it (nothing to accept, retried automatically, never blocking sandbox creation or start) and shares it read-only with that computer's sandboxes; each sandbox installs LCU against it at boot, so computer use becomes ready automatically once that one-time background download and the sandbox's setup complete, and Claude Code, Codex and other agents can then use the desktop. Settings, Computers shows the download state on each computer and offers Retry after a failure. A per-sandbox switch lets computer-use actions run without asking first, and "Set up computer use" reruns setup after you install a new agent. Sandboxes created before this version keep their current desktop; create a new sandbox to use computer use.
- 18e6df1: Silo now calls the environments agents use "computers" and the Macs and Linux machines running Silo "devices", and remote management is now "Connections". SSH-only computer entries are no longer offered, and any saved ones are dropped. Saved data is converted automatically on first launch. Connected devices must run the same Silo version, and when they do not, the message names the device to update. Exports from earlier versions cannot be imported.
- fdb04bd: Settings → Computers no longer lists ChatGPT for Linux for every computer. Silo still downloads it in the background; a Computer use components section now appears only when a computer's download fails or its status cannot be read, with Retry or Refresh. A new switch, Allow agents to use the computer without asking in new sandboxes, sets the starting choice for sandboxes you create or import (off by default).
- b402a48: Creating a sandbox now finishes everything, so Created means it is ready and the first start is just a start. The creation notification waits for the VM image and for ChatGPT for Linux (with its download progress) without blocking other sandbox actions or Quit, then sets up the desktop and computer use. If the download fails you can retry or finish without computer use, and anything left over completes at first start.
- 2426f41: Remote management keys no longer carry owner forwarding privileges, and published ports on remote computers now go through guest SSH. This changes the remote protocol: a computer running this version cannot be managed by, or manage, a computer running an older Silo, so update Silo on both computers before reconnecting.
- 3d5600f: New Linux desktops no longer install Luda agent tools, and the desktop viewer no longer offers "Repair agent tools". LCU is the supported computer-use integration. New v4 sandboxes set it up automatically; for a desktop created before v4, set LCU up from the running desktop. Existing desktops that already have Luda are left untouched.
- c15a9b7: Sandboxes on other computers can now be dragged into place in the sandbox list too. Each computer keeps its own order of the list, for its own sandboxes and remote ones, and reordering no longer changes the sandbox configuration. Sandboxes that need attention still stay at the top. A sandbox's ⋯ menu also has SSH, after Storage, to open its SSH tab.
- 7c13124: Creating a sandbox now shows its current step in the notification from the start, including the one-time image preparation on a new computer. When it finishes, the notification says the sandbox was created and lets you turn on Allow without asking for computer use right there.
- 6f8e47e: A sandbox's computer use is now just the "Allow without asking" switch, which works whether or not the sandbox is running. Status, versions and download progress appear only when something goes wrong, with Try again or Retry. "Set up computer use for new agents" moved to the sandbox's actions menu, and the sandbox editor no longer describes the built-in desktop.
Patch Changes
- 01fdaec: Avoid starting an export-file check after its import request has already been cancelled.
- 169e92e: Reduce repeated accessibility checks when a sandbox's accessibility service is unavailable, and resume frequent checks when application content changes.
- 39a836f: Keep Start, Stop, Restart, and Quit working when activity history cannot be read or saved. Show a warning in Activity, preserve damaged history, and clear completed or cancelled actions independently of history writes.
- 79a39a4: A sandbox row's status, message and Dismiss button now line up on one line instead of sitting at slightly different heights.
- 17600b2: Keep all system notification messages on one line and within 200 characters.
- 2ab3446: Cancel system notices invalidated by sandbox deletion while notification policy is being checked, before submitting them to the OS.
- 42b20a5: Recheck window focus and notification preferences after queued notifications finish waiting, so disabled notifications do not submit using stale settings.
- 4d3e17c: Keep newer system notifications from being replaced by delayed older results, and prevent duplicate notifications for the same action.
- 527ae7a: Remove system notifications when their sandbox is deleted, including notifications still waiting to appear.
- 2178cd6: Keep older notifications withdrawable when a replacement is skipped because system notification permission or the desktop notification service is unavailable.
- ff493c1: Prevent AppImage libraries from interfering with external Linux applications, even when folder paths contain unusual characters or repeated slashes.
- 1052cc8: Keep your latest application preference when an older app chooser finishes, and ignore results after you leave the settings.
- be72a8b: Keep newer system application defaults when an older application discovery response arrives later.
- 1510ec7: Preserve Linux editor launch options when the launcher separates options from file paths.
- bdd8267: Preserve environment assignments and isolation options from Linux editor desktop entries when opening a sandbox.
- 1e96618: Include Linux editor and terminal launchers that clear selected environment variables.
- 9e62895: Preserve the selected Flatpak editor's branch, architecture, installation, and command when opening a sandbox.
- 9ad90fa: Open the selected Ghostty app when multiple copies are installed.
- 89d1d34: Report an unavailable editor when its macOS bundled command has lost execute permission.
- e808832: Preserve Linux editor desktop-entry options, including isolated user-data and extension directories, when opening a sandbox.
- 94734eb: Keep editor SSH aliases available when the runtime directory contains brackets, question marks, asterisks, or backslashes.
- 3e38bba: Exclude Linux editor entries whose resolved command launcher is missing or no longer executable.
- 330a974: Stop suggesting Linux terminals whose command has been removed or lost execute permission.
- e4a80d7: Preserve installed desktop services and account configuration when a migration file write is interrupted, and flush generated files before completing setup.
- ef546c7: Allow home migration to retry interrupted file copies without leaving incomplete credentials or launchers at their final paths.
- 309a5f6: Preserve existing shell files during interrupted home migration and avoid changing files outside the new home through hardlinks.
- 60abee0: Clear notifications when their sandbox is deleted, even when another computer has a sandbox with the same name.
- f144534: Keep delayed export or import cancellation from marking a later transfer as cancelled after relaunch.
- b729dc2: Skip pending import file checks after you close the review, and keep them from interfering with a new review.
- 07d1680: Keep each export's result separate so a new export cannot return an earlier file.
- da51ab3: Keep imported disks and recovery records when a settings write fails and Silo cannot verify whether the sandbox was saved.
- 653e32e: Keep the pre...
Silo guest image v4: corresponding source
Corresponding source for the third-party GPL and LGPL components redistributed in the Silo guest image guest-ubuntu-24.04-v4.
This covers Selkies 2.0.0 with its pixelflux and pcmflux 2.1.0 extensions, the x264, x265 and FFmpeg n8.1 libraries bundled in pixelflux (plus kvazaar, libvpx, SVT-AV1 and dav1d), and the AlmaLinux 8 libraries bundled in pcmflux. SOURCES.md and sources.json list the exact versions, commits, build configuration and SHA-256 values; SHA256SUMS covers every file. Ubuntu packages in the image are not included: their source is in the Ubuntu archive.
To request any of this source in another form, open an issue at https://github.com/0xpolarzero/silo/issues.
Silo guest Ubuntu 24.04 v4
Ubuntu 24.04 with curl, Git, Git LFS, gh, sudo, Python, OpenSSH SFTP server, an Xfce desktop with the Selkies streamer, Linux computer-use system libraries and Silo integration. Working-account creation is offline. Exact bundled archives, package inventories and image config digests are attached. Standard OCI images: ghcr.io/0xpolarzero/silo-guest:ubuntu-24.04-v4. No credentials or user data.
Third-party components
This image contains third-party software under its own licenses: Ubuntu 24.04 packages (see /usr/share/doc/<package>/copyright in the image), the Selkies 2.0.0 desktop streamer (MPL-2.0), and, bundled inside Selkies' pixelflux and pcmflux extensions, x264 and x265 (GPL-2.0-or-later), FFmpeg n8.1 built with GPL options (GPL-2.0-or-later), AlmaLinux 8 libraries such as libpulse, libsndfile, libgcrypt and libsystemd (LGPL-2.1-or-later), and kvazaar, libvpx, SVT-AV1 and dav1d (BSD). The H.264 and H.265 codecs are covered by patents that these licenses do not grant.
The exact corresponding source, versions and build information are in the source release. The notices are in THIRD-PARTY-NOTICES.md.
Written offer: for at least three years from 2026-10-02, and for as long as this image is offered for download, we will give anyone who received it the complete corresponding source of these components on request, for no more than the cost of providing it. Open an issue at https://github.com/0xpolarzero/silo/issues. For the Ubuntu packages, the source for the versions listed in /usr/local/share/silo-packages.txt in the image is in the Ubuntu archive, and the same offer applies.
Silo 0.10.0
| Download | |
|---|---|
| macOS (Apple Silicon) | DMG |
| Linux x86-64 | AppImage · Debian package |
| Linux ARM64 | AppImage · Debian package |
Highlights
- New VM runtime and one-time migration. Silo now bundles MicroSandbox 0.7.4. The first launch converts existing sandboxes to the new storage and keeps the previous storage as a pre-upgrade backup for 14 days (Settings → General → Storage shows it and can delete it sooner). Sandboxes from older versions move to the
siloaccount on their own the next time they start. - Checkpoints. Take manual checkpoints, fork a sandbox into a stopped copy you start yourself, restore with an automatic recovery checkpoint, and delete checkpoints you no longer need. Each one shows its size.
- A page for each sandbox. Click a sandbox to open its Overview, Checkpoints, Storage and Access tabs. Edit, delete, and manage secrets and ports from there. The sidebar and title bar have a refreshed frosted look.
- Actions queue up instead of failing. When another operation is running, an action waits its turn and shows what it is waiting for. Queued operations, and some running ones, can be cancelled. Confirmations open next to the button you used, and results come through notifications that stay until you dismiss them.
- Export and import. These replace the Backup tab: Export… saves a sandbox or a single checkpoint to a
.silo-backupfile, and Import… in the sandbox list brings it back. Both run as background notifications. - Remote computers. Changes to different sandboxes on another computer run in parallel. SSH to a remote sandbox uses a key that belongs to the connecting computer, and turning SSH access off revokes it.
- Safer handoffs. Push asks you to confirm the repository, branch and commit before sending. Each published website opens at its own
*.localhostaddress so its cookies stay separate. VS Code opens sandboxes in a separate "Silo" profile. - Quit asks before stopping running sandboxes and names them.
Before you upgrade
- Exports made with Silo 0.9.0 or earlier can't be imported into 0.10.0. To move a sandbox to another computer, export it again after upgrading.
- Remote management between two computers requires 0.10.0 on both.
- On Linux the pre-upgrade backup can be as large as all your sandboxes. Once you have checked your sandboxes, you can free that space from Settings → General → Storage.
All changes (381)
Minor Changes
-
a118707: Sandboxes from older Silo versions now move to the silo account by themselves the next time they start, instead of refusing to start. Their home files are copied into the new account and the originals stay in place. Checkpoints and exports taken before the move are set up the same way when they first start.
-
2762e1c: Push now asks for confirmation naming the GitHub repository, branch and commit before anything is sent, and publishes exactly that commit to that branch. If the sandbox's origin, branch or commit changes after you confirm, the push stops with "The repository changed after you confirmed the push" instead of publishing something else. Retrying a failed push from its row confirms the repository's current state again. Repositories without a GitHub origin can no longer start a push. Pushing to a sandbox on another computer requires Silo on both computers to include this change.
-
ab70269: Background actions such as GitHub settings, pushes, checkpoints, storage reclaim, ports, log export, and sandbox start or stop failures now report through notifications that stay until you dismiss them, with Retry on failures. The Network page disables adding ports while the sandbox is stopped and names the forward action "Forward to this Mac".
-
be381f0: Queued operations can now be cancelled, and some running operations (starting or restarting a VM, capturing a checkpoint, backing up, setting up guest tools or the desktop, and applying GitHub access or secrets) can be cancelled while they run. Operations that run longer than expected are flagged as "Taking longer than expected", and safe actions like starting, stopping, or restarting a VM retry automatically after a temporary failure. Failed lifecycle actions offer a Retry that re-runs the same intent against fresh state.
-
36ed3de: Use the saved application preferences instead of runtime placeholders, exclude legacy SSH entries from startup choices, and show their state as unavailable with guidance to connect the computer.
-
d0eafeb: Checkpoints can now be deleted from a sandbox's Checkpoints tab, after a confirmation. Each checkpoint shows its size, and one that a fork, a later checkpoint or the sandbox itself still builds on shows what uses it and why it can't be deleted yet. Deleting a sandbox now also removes the checkpoint data only it used, a failed checkpoint no longer leaves its data behind, and Silo clears checkpoint data no sandbox uses any more. The Storage tab shows how much space checkpoints take.
-
6872e33: Keep desktop sessions running when the viewer disconnects, recover the display without restarting graphical applications, and let users explicitly update a stopped legacy desktop. Show LCU readiness separately from Luda and allow explicit setup against a running guest session without starting or reconnecting its display stream.
-
b78710e: Edit and delete a sandbox directly from its detail page. Choosing Edit (the Resources row button or the ⋯ menu) now opens the sandbox editor in place — below the header, with the tabs hidden — instead of returning to the list, and saving keeps you on the same sandbox. Deleting a sandbox asks for confirmation in a dialog on the page and returns to the list once it is removed. The editor behaves exactly like the one in the list, including the stale-edit conflict review.
Add "View all" links to the Overview tab: Repositories jumps to Files, Ports jumps to Network (both filtered to the sandbox), and Secrets opens the Secrets tab.
-
2cfdcc8: Export and import now run as background notifications instead of inline panels. Starting an export from a sandbox, its detail page, or a checkpoint opens the folder picker and then reports progress, and completion, as a toast that survives navigation. A finished export offers Show in Finder (macOS) or Show in folder (Linux) to locate the
.silo-backupfile; Silo only reveals exports it created and still tracks. Importing opens a dialog to validate the export, pick a sandbox when several are present, and name the new one, after which progress continues in a toast with Open to jump to the imported sandbox. Failures stay until dismissed and offer Retry; cancelling an import confirms first, since it removes the incomplete sandbox. -
94d2c61: Refresh Silo with a frosted sidebar and title bar over a subtle teal background, clearer content surfaces, and coordinated light and dark navigation states. Tighten the logo spacing and keep submenu guides clear of highlighted items. Respect system preferences for reduced transparency and increased contrast.
-
dd5cb50: Sandbox actions now wait their turn instead of failing when another operation is running. Silo shows what each pending action is waiting for: a per-sandbox "Waiting for…" status and a compact indicator listing running and waiting operations with elapsed time, flagging any operation that has been running unusually long.
-
ae452d9: Confirmations and small forms (restore, fork, delete, new checkpoint, import) now open next to the button you used instead of blocking dialogs. Long actions show a progress notification with the current step, elapsed time and Cancel where possible, and end in a notification that stays until you close it.
-
bd52631: After an upgrade converts your sandboxes to the new storage, Silo keeps the previous storage as a pre-upgrade backup, tells you its size and the date it will delete it (14 days later), and deletes it automatically. On Linux the backup can be as large as all your sandboxes, so you can free that space sooner: Settings, General, Storage has Show and Delete now. Silo only deletes it after every sandbox was converted, never after you continued past a failed migration.
-
1ddd345: System notifications now arrive as soon as something happens, and only while Silo is in the background: while you are using Silo, results appear in the app instead. Each notification names the sandbox, opens it when clicked, and replaces the older one for the same event. Silo no longer notifies you about a start, stop, or restart you asked for. Notifications are now grouped as Failures, Unexpected sandbox changes, and Long tasks finished, so work that took more than a few seconds tells you when it is done even if you have switched to another app. Failed pushes, GitHub changes, port changes, checkpoints, and log exports now reach you too.
-
14eed4e: Quitting from the menu bar now asks "Quit Silo?" and names the running sandboxes it will stop, with Quit and stop or Cancel. Silo quits without asking when nothing is running.
-
fb493ca: Changes sent to another computer no longer wait behind every other remote change: changes to different sandboxes run at the same time, and changes to the same sandbox wait their turn in that computer's queue like local work. A queued change that has not started before its request expires, or whose computer disconnected, is dropped instead of running later, and Silo reports that nothing changed. After a brief connection loss Silo asks again for the same change and receives its result instead of ...
Silo 0.9.0
Silo 0.9.0
Minor Changes
-
38f096a: Install Luda's desktop-control tools and skill for all supported agents when adding the Linux desktop, including agents installed later. Add setup and repair actions for existing desktops.
-
38f096a: Require one
siloaccount for terminals, SSH, editors, files, and the Linux desktop. Older VMs require explicit migration or recreation instead of falling back to root. Before starting an older VM, close Silo and follow the migration instructions, or recreate the VM. New VMs already use this account.Correct the release version to 0.9.0. The identical application changes were previously published as 1.0.0 in error; that release is superseded. Existing 1.0.0 installations require manual installation of 0.9.0.
Silo 0.8.0
Silo 0.8.0
Minor Changes
- a9827c2: New VMs use the same Linux account for terminals, SSH, editors, file transfers, and the optional desktop, with passwordless sudo for administration. Existing VMs retain their accounts. Account and file-transfer tools are bundled in the guest image, so creating the working account needs no package downloads. Optional desktop installation still requires downloads. For new VMs on a remote computer, update Silo on both computers before using terminal, editor, or SSH access.
Silo guest Ubuntu 24.04 v3
Ubuntu 24.04 with curl, Git, Git LFS, gh, sudo, Python, OpenSSH SFTP server and Silo integration. Working-account creation is offline. Exact bundled archives, package inventories and image config digests are attached. Standard OCI images: ghcr.io/0xpolarzero/silo-guest:ubuntu-24.04-v3. No credentials or user data.
Silo 0.7.2
Silo 0.7.2
Patch Changes
- Fix storage measurements and manual space reclamation being blocked by desktop permissions.
Silo 0.7.1
Silo 0.7.1
Minor Changes
- 7e7fb3e: Add an optional interactive Linux desktop to new or existing sandboxes, with automatic or manual startup and a dedicated desktop viewer. Closing the viewer keeps graphical applications running.
- 2e6d920: Automatically reclaim unused local workspace disk space after seven days and before stopping when the last reclaim was at least a day ago, with bounded attempts that do not prevent shutdown. Add a Storage panel showing host disk allocation, workspace usage, manual reclamation, and a collapsed history of the latest 50 attempts, with measurement tooltips and reclaim progress. Fix a runtime bug that shortened disk images when reclaiming their unused tail.
- 6d5467c: Search all retained sandbox logs, browse older pages, filter by time and source, follow new output, inspect surrounding records, and export matching diagnostics with timestamps and computer, sandbox, source, and session details. Failed activities link to their diagnostic time window; unavailable computers show explicit errors.
Patch Changes
- 2e6d920: Add Linux desktop directly from a sandbox's more-actions menu, with automatic startup enabled by default.
- 7acd6e7: Distinguish local and remote VMs with monitor and server icons, keeping the remote computer name in a neutral badge. Show one SSH badge: neutral for host-only access and blue with a network icon for access from other computers. Keep address copying in the expanded SSH controls.
- 020a8e0: Keep the Logs view focused on records and actionable errors by removing retention and search-scope commentary.
- 6b32d76: Distinguish local and remote VMs with monitor icons and a network marker, and local and network SSH access with server icons and the existing top-right network marker pattern. Keep SSH badge text compact, with scope explained in tooltips. Show the host computer name on remote VM rows, wrap connection labels and actions in narrow windows, and keep SSH settings expandable in the read-only website demo.
- e8c507c: Add a shortcut at the end of GitHub repository search results to authorize more repositories, and automatically load them when returning from GitHub.
- e8c507c: Clear GitHub settings progress when a newer settings revision completes with the same result as the previous save.
- 589702d: Add a refresh button before the Repositories caret in Files. Manual refresh bypasses cached repository scans on local and connected computers and shows progress while loading.
- 4d864a9: Match remote computer badges to local VM badges with the same rounded, borderless muted appearance.
- 77d34d1: Allow the main desktop window to search retained logs and export or cancel log exports.
- 7e7fb3e: Route Quit Silo on macOS through the shutdown flow so local sandboxes stop and pending settings save before the app exits.
- e5807fe: Make source and date filters optional, with removable chips and a Clear action. Simplify the logs empty state and show date controls only when adding or editing a date filter.
- 2e6d920: Group sandbox menu actions with desktop access, Restart and Storage first, followed by configuration actions and Delete.
- 12696cd: Use plain Search logs, Copy, and Export labels, with tooltips explaining what is copied or saved.
- 589702d: Refresh repository rows automatically while Silo is visible, so changes inside local VMs appear without switching windows. Avoid overlapping periodic reads when a scan is slow.
- 777e109: Remove the start-VM caption from waiting ports in the Network view.
- 72e4bb8: Retain runtime, execution, and kernel logs together for up to seven days within a 250 MiB sandbox budget. Rotate daily or at 10 MiB, remove the oldest segments first, and apply the same limits to kernel output and stopped sandboxes.
- 0a2e60c: Keep sandbox controls beside the name and status when there is room, instead of forcing them onto another line in moderately narrow windows.
- 6b32d76: Keep sidebar icons at the same position and size when expanding or collapsing the sidebar. Use compact circular backgrounds behind network corner markers so they remain legible without obscuring the VM or SSH icon.
Silo 0.6.3
Silo 0.6.3
Patch Changes
- 3eacd00: Use standard Git and Git LFS transfers for explicit pushes, including empty files and historical LFS data. Reuse a bounded publishing cache without giving sandboxes GitHub write access. Keep push progress and results across remote disconnections, prevent duplicate requests, and identify unknown outcomes after a host restart. Update Silo on both computers to use the new remote push flow.
- 298879d: Keep the status menu fully visible when sandbox content changes or loads, including the Open Silo and Quit controls.
- a1c0565: Place the smaller crash Dismiss button beside the sandbox error message.