Releases: androidStern/nutshell
Release list
v0.1.27 — reset UX and app-owned setup refresh
Reset UX + app-owned setup refresh
This release publishes the latest main HEAD after v0.1.26.
- Adds the user-facing reset flow:
nutshell reset,reset data,reset source,reset logs, andreset all. Reset only clears Nutshell-owned local state; it does not delete Chrome login, Keychain items, macOS permissions, or browser profiles. - Refreshes task-oriented help and sync wording around automatic sync, keeping implementation details out of normal user copy.
- Changes setup completion to run a bounded app-owned connection check instead of foreground recent ingestion.
- Keeps protected macOS access behind
Nutshell.appand promotes the stable user app path for Homebrew/tarball installs. - Improves YouTube My Activity handling for Google redirect/session cookies and identity-verification interstitials.
Validation before publish:
bun run typecheckbun test— 270 passingbun run buildbun run build:compilebun run build:macos-appbun run build:tarballbun run certify:release— pass, including dual-arch tarball checks and x64 Rosetta smoke
Install path remains Homebrew tap or release tarball. npm/Bun registry publishing remains deferred.
v0.1.26 — honest YouTube state + setup polish
Honest YouTube state + setup UX polish
Field-caught on a real multi-account Mac. Fixes and improvements:
- YouTube no longer falsely reports "signed out." With multiple signed-in
Google accounts, the My Activity probe never said which account to use, so
Google bounced to its account-chooser and the product mislabeled that as
signed-out. The probe now sends the account (configurable
plugins.youtube.authUser, default 0). When Google interposes an
identity-verification page on programmatic access — which an established
account does even with valid cookies — the product names that honestly
(youtube_session_unverifiable) and routes to the official export import,
instead of lying or erroring cryptically. The reliable route for YouTube
history remainsnutshell import youtube <google-export.zip>. - Setup step wording: headers name the state ("YouTube My Activity — needs
login") instead of a vague "needs attention," and the problem/fix lines no
longer restate each other. - Permission window: the draggable app icon now shows a persistent
move-arrows badge and the standard open-hand drag cursor.
Product behavior is otherwise v0.1.25 (dual-architecture, macOS 14+). All v0.1.24
behavior gates still hold; the YouTube classification change is covered by new
regression tests and verified against a real multi-account browser. Install:
Homebrew tap or tarball, Apple Silicon + Intel. npm deferred.
v0.1.25 — Intel + Apple Silicon
Intel support — one formula, both architectures
This release adds darwin-x64 artifacts alongside darwin-arm64. The Homebrew
formula now carries on_arm/on_intel blocks, so brew install androidStern/nutshell/nutshell automatically installs the right build for the
host. The formula declares depends_on macos: :sonoma — the true floor of the
shipped binaries (Swift deployment target macosx14.0); brew refuses cleanly on
older systems instead of installing an app that cannot launch.
Product changes: none — the product source is identical to v0.1.24 apart
from the version string. This is a packaging release: per-arch build pipeline
(Bun cross-compile with the baseline x64 target, since Rosetta lacks AVX;
swiftc -target per arch; per-arch signing), dual-tarball + dual-SHA formula
generation, and certification that verifies both architectures including a
real Rosetta smoke run of the Intel CLI and app.
Validation status: v0.1.24's full gate ledger (imports, signed-out,
signed-in, permissions-pre, permissions-post, live-sync/dashboard — all PASS)
carries to the product behavior, which is unchanged. The arm64 artifact is
certified identically to v0.1.24. The x64 artifact is certified and
Rosetta-smoked; it has not run on physical Intel hardware yet — the first
Intel install will be its first real-hardware validation. Dependency
fence: unchanged (host bun upgraded 1.3.6→1.3.14 to fix a bun codesigning
bug affecting re-signed x64 binaries; bun is an approved host tool).
Install paths: Homebrew and tarball; npm deferred.
v0.1.24 — gate-caught classification fixes
Gate-caught classification fixes
The v0.1.23 VM release gates caught two honesty bugs in the published artifact;
this release fixes them and re-runs the gates.
What was broken (user-visible):
- A signed-out X user was told "Retry shortly — this is usually a temporary X
or network failure" instead of "Open x.com in Chrome and sign in". The
product's own "auth cookies missing" message wasn't recognized as a
signed-out state, so it mis-classified asblocked_buginstead of
needs_auth. - Before the Notes automation prompt is answered, Apple events time out with
AppleEvent -1712; this classified asblocked_bug("looks like a Nutshell
bug") instead ofneeds_permissionwith the approve-automation fix.
Root cause: classification regexes in the X session checker and the Notes
permission-error matcher missed these two real-world strings; both were found
by the signed-out and permissions-pre VM gates running against v0.1.23, with
frozen evidence reports.
Also fixed (harness, not product): the permissions-pre gate contract now
encodes macOS reality — Chrome's cookie store is not Full-Disk-Access
protected (browser sources may legitimately pass pre-grant) and a fresh VM has
no Podcasts library; the gate asserts the FDA root cause, Notes
needs_permission, and Podcasts needs_permission-or-honest-no-library. The
signed-out gate now accepts only *_signed_out codes with needs_auth
guidance. New contracts were replay-verified against the frozen v0.1.23
evidence before this release.
Validation status: local certification passed (typecheck, 246 tests, lint,
builds, tarball, certify). Split gates re-run against this artifact follows;
permissions-post + live-sync remain queued on the one-time post-permission
snapshot session. Install paths: Homebrew tap and tarball (npm deferred).
Dependency fence: unchanged.
v0.1.23 — honest setup
Honest setup, end to end
nutshell setup now verifies every source with its real probe through the
Nutshell.app identity — "ready" is impossible without proof. Each source step
is one loop with three verbs: probe, retry (optionally opening the sign-in
page), or skip honestly. Re-running setup opens with a status table refreshed
by real probes and only walks what needs attention.
What was broken: setup previously marked every selected source "ready"
without verifying anything (the plugin setup hooks were no-ops), and the Full
Disk Access step ran after source verification instead of before it, so real
failures only surfaced later in doctor/sync with no guidance.
What changed in the shipped product:
- Every problem finding carries machine-readable guidance: a user-state
classification (needs_auth,needs_permission,blocked_bug, …), the
concrete fix, and the command that confirms it — rendered on every surface
(setup, doctor, health, sync output, dashboard) and enforced by a CI
invariant over every emittable finding code. - Setup: permission step before verification; probe/retry/skip loop;
re-run resume; honest per-source summary with comeback commands; a real
bounded smoke sync through the app identity (the old "initial sync handed
off" message was wording, not an action — it is gone). - Scheduler self-heals: a degraded source gets one bounded probe per scheduled
run; a passing probe flips it back to ready and syncs — sign in days later
and the next sync just works, no setup re-run. Rate limits back off. - Doctor: root-cause-first (app/FDA issues lead; permission symptoms collapse
into one line), source aliases (x,notes,podcast), and a no-argument
mode.syncprints a human summary with skipped-source fixes first. - Catch-all auth findings split one-code-one-state: keychain-blocked is
needs_permission, neverneeds_auth.
Validation status (split gates, verdict vocabulary per
docs/release-validation-gates.md): local certification suite passed
(typecheck, 238 tests incl. pty-driven golden journeys of the real interactive
setup, lint, builds, tarball, certify:release). Public-install gates run
against this artifact next; the permissions-post and live-sync gates are
queued on the one-time post-permission snapshot session. This release is
published, not yet fully gate-validated.
Install paths: Homebrew tap and tarball. The npm/Bun registry path is
deferred and not published. Dependency fence: unchanged. Reboot
persistence: covered by the final layer-4 rehearsal, queued.
v0.1.22
Bugfix release for the split release-validation gates. Removes the private Chrome Safe Storage fixture path, bounds Chrome Safe Storage Keychain reads, and reports YouTube/X signed-in-but-Keychain-blocked states explicitly instead of hanging or asking the user to sign in again.
v0.1.21
Reverts the v0.1.20 private Chrome Safe Storage password-file bypass. Nutshell no longer reads a restored private fixture file for Chrome cookies; browser auth validation must use the normal macOS Keychain/product path. Keeps rehearsal docs aligned so the rejected bypass is not used as release proof.
v0.1.20
Fix restored browser auth seeds by carrying Chrome Safe Storage as a private fixture, so authenticated clean-VM rehearsals can decrypt restored Chrome cookies without keychain prompts. Tighten strict rehearsal checks to require that fixture before auth-present browser proof.
v0.1.19
Fresh-install rehearsal fix: avoid recursive Launch Services app opens during app-owned health/status checks, and wait briefly for app command result JSON after open -W returns. This addresses the v0.1.18 clean VM failure where the first installed nutshell health --json app handoff returned without a result file.\n\nRelease certification passed: full tests, macOS app build, compiled CLI, tarball, version/package install checks, and protected-command app handoff checks.
v0.1.18
Fresh-install rehearsal fix: extend the macOS setup Full Disk Access handoff window to one hour, with NUTSHELL_SETUP_PERMISSION_TIMEOUT_MS override, so a real user/VM permission grant is not cut off by the CLI before completion. Also updates the VM rehearsal playbook with Tart UI/auth-seed operating notes.\n\nRelease certification passed for version, packaged CLI/app, Homebrew-style install, and protected-command app handoff checks.