Skip to content

Releases: blechschmidt/cloop

Release list

v0.0.4

Choose a tag to compare

@github-actions github-actions released this 27 Sep 07:07

The first release that ships 0.0.2's installer fix. 0.0.2 was tagged on
2026-09-17 to publish unversioned asset names and never reached GitHub
Releases: its publish step failed partway through the uploads, the tag stayed
behind with no release, and releases/latest/download kept serving 0.0.1's
versioned names — so every device the installer was pointed at still got a
404. 0.0.3, tagged to publish it, stopped earlier still: its binaries did not
build for 32-bit linux/arm. What 0.0.2 was cut for is released here for the
first time: unversioned cloop_<os>_<arch>.tar.gz assets that
latest/download resolves, each with the Sigstore bundle the installer and
cloop upgrade verify its provenance against (0.0.1 published none), linux/arm
builds, and a daily check that the published release still installs — see 0.0.2
in CHANGELOG.md for the detail.

Added

  • Parallel features. cloop feature new — and + New feature on a
    project's Overview — starts a line of work in its own git worktree on branch
    cloop/feature/<slug>, with its own task list and its own auto-evolve,
    innovate and parallel settings. Features run at the same time as their project
    and as each other; the dashboard nests them under their project, and each is
    otherwise an ordinary project with its own run, tasks and options. When one is
    done, Open pull request (cloop feature pr) pushes its branch and opens a
    GitHub pull request into the branch it was cut from — or the hub does it by
    itself on completion when the feature asked for that. A feature runs on its
    project's executor with its project's grants and roles, by a mapping read from
    its path so that it fails closed. See docs/guides/features.md.

Changed

  • The dashboard's script ships without its comments. Whole-line //
    comments were over a third of its wire bytes; they are now stripped when the
    bundle is built, keeping every line number, by a lexer that refuses — and
    serves the source unchanged — whenever it cannot prove a line is a comment.
    First paint fell from 279 KB to 213 KB, the parallel-features UI included.
  • Stop, the running indicator and run re-entrancy treat a feature as its own
    project.
    A run in .cloop/features/<slug> no longer marks its parent as
    running, and the parent's Stop no longer signals it.
  • cloop clean refuses while the project has features unless --force, which
    removes them through git first; snapshots neither archive feature worktrees
    nor touch them on restore; disk-usage reports no longer count them.
  • cloop watch applies one batch of changes at a time. Every debounce
    window used to start a batch of its own, so a burst of edits applied several
    at once: their state saves raced — one could put back a task another had just
    reset — --auto-run ran cloop run --pm concurrently with itself, and
    stopping the watcher waited for the whole backlog. Changes that arrive while
    a batch is applied now make up the next one, and nothing starts after Ctrl+C.

Fixed

  • cloop builds for 32-bit ARM again. A token ceiling of 1<<40 did not fit
    in an int on linux/arm, the armv7 build the installer serves to Raspberry
    Pi-class devices, so nothing since 2026-09-26 compiled there. CI now builds
    the release binary for every published platform on every push, so a tag is no
    longer the first build to try one.
  • A release publishes, or can be resumed. The release job now creates the
    release as a draft, uploads one asset at a time with retries, and marks it
    latest only once every asset is there. 0.0.2 was lost to a single upload
    error from GitHub with all twelve uploads running at once.
  • A terminal on an edge device no longer loses a short command's output.
    A command that printed and exited at once — pwd, echo — sent its output
    and its close back to back, and the hub closed the session before relaying
    the output, so cloop task attach showed an empty transcript. The device
    also reaped such a command twice, a data race, and could hold one of its
    terminal slots for a session that had already ended; an attach the device
    refused left a goroutine behind on the hub.
  • A workload stopped on reconnect reports how it ended. When the control
    plane refuses to take a workload back after a reconnect, the device stops it
    — but it used to signal it before the new session was ready, so a workload
    that died promptly had nowhere to send its last output or its exit status.
  • An exit reported as the link drops is kept. The device counted a
    workload's final status as delivered before writing it, so a status written
    to a closing session was lost, and the control plane later read a clean exit
    as a lost workload. It is now delivered on the next session.
  • A revocation is sent to a reconnecting device once. One recorded as the
    device reconnected could be sent twice, and the reply to the first could be
    taken by the second, reporting a reachable device as unreachable.
  • Push-to-talk no longer sends a clip it meant to discard. A tap too short
    to be speech is thrown away, but its recorder stopped asynchronously, and a
    press landing before it had — a second tap at once, or any press on a slow
    device — let the discarded clip upload after all, often transcribed as a
    hallucinated title. A release the page got to late could also stretch a tap
    past the minimum hold. Holds are now timed by the pointer events themselves,
    on the dashboard and the glasses link alike.
  • cloop chaos suite gives every fault its full window. Windows were
    measured from when the suite was built, so the last faults ran with a
    fraction of theirs — the SQLite one with under half a second of its two —
    and a slow disk reported them degraded.

Security

  • gRPC 1.83.2 for GO-2026-6348, heap exhaustion through fragmented HTTP/2
    DATA frames, which the hub's metrics collectors can reach. OpenTelemetry
    moves to 1.44.0 with it.

Full Changelog: v0.0.3...v0.0.4

v0.0.1

Choose a tag to compare

@github-actions github-actions released this 13 Sep 11:02

First tagged release. Everything below already existed; what is new is that it
is now installable as a versioned binary rather than only from source.

Added

  • Autonomous task loop. cloop init turns a goal into a plan and
    cloop run executes it: decompose into tasks, run each against an AI
    provider, detect completion from the agent's own output, and — with
    --auto-evolve — discover follow-up work and keep going.
  • Multiple providers. Anthropic, OpenAI (including OpenAI-compatible
    endpoints), Ollama for local models, and the Claude Code CLI. Selection is
    layered: --provider flag, then .cloop/config.yaml, then project state.
    Retries use exponential backoff with jitter behind a circuit breaker.
  • Isolated executors. The hub never spawns a harness on the host unless
    explicitly configured to. Backends: local process, Docker/Podman containers,
    Kubernetes pods, Kata Containers VMs, and remote agents that enrol
    themselves outbound — so an edge device behind NAT needs no inbound
    reachability. Placement is capability-aware with liveness, cordon/drain and
    automatic failover.
  • Scoped secret brokering. GitHub repositories and PATs, kubeconfigs, and
    the hub's own Internet connection are leased to executors with a TTL rather
    than copied in. Leases are revoked on the running executor rather than at
    task exit, payloads are envelope-encrypted with online key rotation, and
    material is wiped on exit and swept at startup.
  • Enterprise hub. OIDC authentication with claim-based RBAC that is
    deny-by-default on every mutating endpoint, durable sessions with idle
    timeout and admin revocation, scoped API tokens for non-interactive access,
    per-identity quotas and admission control, a hash-chained audit trail with
    SIEM export, and a container image trust policy (registry allowlist, digest
    pinning, signature verification).
  • Web dashboard. Multi-project oversight over a WebSocket event stream,
    with kanban, dependency graph, timeline, analytics, knowledge base, and
    panels for executors, secrets, grants and audit.
  • Packaging. A distroless container image, a docker-compose evaluation
    stack that runs a real task through a remote executor, a Helm chart, and
    cloop hub bootstrap / cloop hub doctor.
  • Roughly 115 CLI commands covering planning, analysis, forecasting,
    reporting and integration. cloop --help groups them; cloop doctor
    checks the environment.

Known limitations

  • No Windows build. The process-group supervision used to stop harnesses
    is POSIX-only, so releases carry linux and darwin binaries (amd64 and arm64)
    only. cloop upgrade already knows how to unpack a cloop.exe; the
    platform needs a port, not a packaging change.
  • The version is 0.0.1 in the sense SemVer intends: interfaces are not yet
    stable, and upgrades between 0.0.x releases may require configuration
    changes.

Full Changelog: https://github.com/blechschmidt/cloop/commits/v0.0.1