Skip to content

v0.6.2

Choose a tag to compare

@github-actions github-actions released this 10 Sep 23:54
· 4 commits to main since this release

qntm v0.6.2

This release brings gateway actions to the terminal and native OpenClaw integration, adds the Python charter library, and fixes client validation, backup and restart behavior.

Gateway workflows across clients

The terminal now supports gateway admission, requests, approvals, vote withdrawals, sealed credentials and governance changes. Complete paged reviews show what will be sent; confirmation checks current permissions and conversation state again. Terminal checkpoints preserve authenticated membership, keys, history and relay progress together.

OpenClaw provides the optional qntm_gateway tool with a prepare/commit review bound to the host session and conversation. Local configuration controls the permitted actions. Signed acceptance in the chat establishes gateway authority. The integration targets OpenClaw 2026.9.3 and requires Node 24.16.0 or later in the 24.x line, or Node 26.1.0 or later. Its private delivery queue survives host restart and failed handoffs; delayed replies use current keys.

Real Python, TypeScript, browser, terminal and installed OpenClaw journeys cover execution, governance, rekey, removal and restart. These tests establish protocol and host compatibility, not the judgment of an agent using the tools. See the compatibility table and OpenClaw configuration.

Client safety and privacy

Browser backup downloads are password encrypted. Restore validates the contents, previews replacements and destinations, and requires confirmation before replacing local data. Legacy plaintext imports remain supported. Keep the backup password separately; see backup handling.

Browser, Python and terminal invite links now keep their bootstrap secret in the URL fragment. Library URL builders discard existing query parameters, and pasted fragment links tolerate wrapping whitespace. Old query links remain readable, but cannot erase their earlier exposure to HTTP logs.

Python and TypeScript now agree on expiry and future timestamp bounds. Normal decryption rejects expired messages; inspecting saved history requires an explicit option that retains all other authentication checks. Both clients and the relay also apply the charter registry's strict Ed25519 verification profile. Normally generated keys and wire formats are unchanged; weak keys and previously tolerated malformed signatures are rejected.

Gateway setup requests have bounded duration and response size, reject redirects, and support cancellation. A failed setup POST is not automatically retried. Browser settings and navigation fixes keep restore reviews reachable, collapsed sidebar controls no longer capture keyboard focus, and long gateway responses can be expanded without discarding their contents.

Python charter support

The opt-in qntm.charter library joins the TypeScript library and Go registrar. It supports self-certification, parent and threshold governance, canonical signing, authority replay, pinned HTTP access and proof verification. Python/TypeScript/Go tests cover historical evidence, authority changes and server restart.

The registry remains experimental and has no independent witnesses. Applications retain responsibility for checkpoint persistence and freshness. See the Python guide.

Operations and release checks

The private relay dashboard reports message-post totals, rolling active conversations, synthetic probe results and certificate health. Conversation counts include direct chats and groups. Aggregate telemetry uses bounded, deduplicated delivery and seven-day retention. The metadata specification describes exactly what the relay, metrics and providers can observe; monitoring does not inspect message plaintext.

Optional WebSocket challenge authentication now accepts correctly sized Ed25519 public keys. Relay rate-limit memory is bounded, and fixed error responses avoid exposing request-derived exception details. Independent encrypted delivery and replay probes, HTTPS checks, and encrypted off-host charter backups are documented. Outbound paging recipients remain unconfigured; the Mac backup schedule requires the machine to be awake, logged in and online.

The release gate includes maintained-client tests, real host journeys, installed-package checks, README command coverage and dependency audits. Some infrastructure improvements were deployed before this package release; the operations guides distinguish account configuration from shipped code.

Upgrade and remaining boundaries

pip install --upgrade qntm==0.6.2
npm install @corpollc/qntm@0.6.2

Contact-based group welcomes and their recovery controls remain on a separate feature branch. Guidance intake/routing endpoints and universal native harness insertion are not included. OpenClaw is the maintained agent integration target; NanoClaw source is retained without new host-support commitments. No stranger-entry token mechanism is included.