Skip to content

v0.99.19

Choose a tag to compare

@github-actions github-actions released this 26 Aug 17:22

Changed

  • Let embedded hubs bind port 0 atomically and report the kernel-assigned
    address through bound_address and wait_until_serving(). The installed,
    coding-fleet, source-checkout, LLM-worker, and benchmark paths now consume
    that live address instead of reserving and releasing a guessed free port.
  • Make the installed golden demo provider-honest on every public and translated
    surface. CLAUDE and CODEX are now explicitly scripted in-process
    SynapseAgent identities, not vendor runtimes; runtime-owned labels and the
    seven-step narration sequence are enforced by documentation contract tests.
  • Remove the deferred gitclaim/path_identity and hub/hub_config import
    inversions through dependency-neutral runtime/default modules. Consolidate
    the shared Claude, Codex, Gemini, and Grok claim-hook command shell and the
    repeated JSON recipe envelope while preserving every provider's matcher,
    timeout unit, denial payload, executable form, and rendered output. Kimi's
    provider-specific TOML install lifecycle remains independent.

Fixed

  • Make the canonical Compose profile fail closed on missing owner-custody
    inputs and require token-file authentication, native TLS, and a SQLCipher
    database key without either insecure hub override. The former loopback-only
    downgrade and plaintext relay log now live only in the loudly named
    local-development profile; CI boots and probes the real secured container
    path.
  • Prevent global priority and CEO broadcasts from activating interactive
    agent-tmux pane bridges. The messages remain durable passive inbox traffic,
    while only exact identity, role, or group targets may inject the fixed wake
    prompt into a verified idle provider pane. A real hub, tmux pane, CLI process,
    and recording provider acceptance test covers both the suppressed broadcast
    and the preserved exact-target wake.
  • Restore the real JetBrains/OpenCode ACP acceptance path against current IDE
    defaults: isolate bundled and external agent registries, select the pinned
    OpenCode mode through the owning settings surface, submit from the composer,
    and verify the emitted protocol-v1 request instead of substituting a mock
    editor transport.
  • Keep the MCP Registry uvx --with requirement exactly aligned with the
    package's audited mcp==1.28.1 extra. The repository audit now parses both
    PEP 508 requirements and rejects stale floors, broad MCP v2 ranges, malformed
    constraints, and documentation drift.
  • Clarify three operator-facing timing and identity contracts: dead WebSocket
    names can persist for the 15-second ping interval plus the 15-second pong
    timeout, bare synapse who connects as literal USER while syn who
    resolves the project/session identity, and multi-host signed-frame deployments
    require monitored clock synchronization inside the asymmetric skew budget.
  • Withhold every service-restart command from the default release-redeploy
    checklist. Rendering a disruptive step now requires an explicitly authorised
    exact hub PID; the command rechecks that PID while holding a fail-fast
    host-local custody lock before one combined hub, presence, and waiter restart.
    Release operations now state the mandatory dogfooding gate: every new tag is
    adopted by the local hub immediately and verified through that bounded path.

Artifact checksums (SHA-256)

a053f5d2437eb204a00fa74e58662f768241248d1080086735c107bf13e39d75  synapse_channel-0.99.19-py3-none-any.whl
3d31e46f60e60ea5d664e1753e9c594aac66d5692d566ace7e0a0f297b15fe13  synapse_channel-0.99.19.tar.gz
f811a1cfdcbd0150405ff05d8759c046d99d6845d729d0c3ecb30a8060938e6b  synapse-channel-v0.99.19-sbom.cdx.json