Releases: dengmengmian/CodeLeveler
Release list
v1.0.10
CodeLeveler v1.0.10
English
This release rebuilds how a model request is assembled, folded, and paid for.
The control context is now separate from the transcript, every delivered prompt
segment has one source and one authority, and every model attempt is recorded in
the request ledger.
Installed stable builds can update automatically, or use leveler update
or /update.
Changed
- Prompt construction gives every delivered segment a single source, authority,
and lifecycle. Providers may change how a segment is represented on the wire
(a system message or a top-level system field) but not its order, source, or
authority, and the control context no longer travels as part of the transcript. - Wire encoding and context statistics read the same projected request, so the
reported input size and the bytes actually sent cannot disagree. Folding
pressure follows the projected request, project rules scoped to a directory
survive a fold verbatim, and historical reasoning follows the route's replay
contract. - Every model attempt is recorded in the request ledger and the resource budget,
including failures, retries, compaction summaries, and child task calls.
Consumption is rebuilt from a scope's persisted request facts on recovery, so a
background child can no longer keep spending a stale balance snapshot. - Rule delivery is budgeted against the request: every rule stays authoritative
even when only part of a rule file fits verbatim. - The repository's
./devdevelopment entry point is documented in the release
archives, for local verification and release qualification.
Fixed
- A reduced-context route can declare
max_output_tokenslarger than its own
context_window. Reserving that full completion against the window used to
saturate the usable input capacity to0, so every request looked over the hard
capacity and the run aborted withcontext management failure: ... capacity 0
after the first tool batch. A bound of zero is not a bound the model declared,
so folding now follows the quality boundary alone. Routes whose reservation
fits their window are unchanged. - The context snapshot produced before a request reaches the caller's observer
instead of being dropped. - A model-spend scope change no longer discards the task epoch's remaining
command budget. - The spend of a completed command is flushed when a batch is cancelled
mid-round, instead of being lost with the cancelled round. - A child task's rendered spawn brief is persisted on the child spec and reused
on resume, so a resumed child sees the brief it started with. /btwread-only calls pass through the ToolHost admission pipeline instead of
bypassing it.- Background task writes are constrained to the OS execution boundary, task
mutation settles only after the whole workload ends, and the live stdout and
stderr channels are capped with an explicit truncation marker rather than
growing without bound.
Known limits
- Prebuilt binaries are not Apple- or Microsoft-signed. macOS or Windows may
block the first run until you allow it - Windows cannot deny network access per command. A command that requires that
isolation is refused rather than run with the network open - Windows has no local daemon socket. Sessions and
resumestill work - A confined Windows
!commandprints its output when it finishes, not while
it runs
Install and usage: README.
Updates: README § Updates.
How the system is layered: Architecture.
中文
这一版重做了模型请求的组装、折叠和计量方式:控制上下文与会话记录分离,
每一段提示词都有唯一的来源和权威,每一次模型尝试都记入请求账本。
已安装的稳定版可以自动更新,也可以执行 leveler update 或 /update。
变更
- 提示词组装让每一段投递内容都有唯一的来源、权威和生命周期。Provider 可以
改变某一段在链路上的表示形式(system message 或顶层 system 字段),但不能
改变它的顺序、来源或权威;控制上下文不再作为会话记录的一部分传递。 - 链路编码与上下文统计读取同一个「已投影请求」,报告出的输入规模与实际发送的
字节不会再互相矛盾。折叠压力按已投影请求判定,作用于某个目录的项目规则在
折叠后被逐字保留,历史推理遵循路由自己的回放契约。 - 每一次模型尝试都记入请求账本和资源预算,包括失败、重试、压缩摘要和子任务
调用。恢复时消费量由该作用域已持久化的请求事实重建,后台子任务不会再继续
花费过期的余额快照。 - 规则投递按请求额度分配:即使规则文件只有一部分能逐字放入,每条规则仍保持
权威。 - 发布产物中记录了仓库的
./dev开发入口,用于本地验证和发布资格判定。
修复
- 缩减上下文的 route 可以声明比自身
context_window更大的
max_output_tokens。把整段补全预留在窗口上,曾把可用输入容量压到0,
于是每个请求都被判为超出硬容量,运行在第一批工具调用后即以
context management failure: ... capacity 0中止。容量为 0 不是模型声明的
界限,因此现在只按质量边界折叠;预留能放进窗口的 route 行为不变。 - 请求前产生的上下文快照现在会送达调用方的 observer,不再被丢弃。
- 模型消费作用域切换时,不再丢弃当前任务纪元剩余的命令预算。
- 批次在一轮中途被取消时,已完成命令的消费会被结清,不再随被取消的那一轮丢失。
- 子任务渲染出的 spawn brief 会持久化在子任务 spec 上并在 resume 时复用,
恢复后的子任务看到的是它启动时的那份 brief。 /btw的只读调用改为通过 ToolHost 准入管线,不再绕过它。- 后台任务写入被限制在 OS 执行边界内,任务变更在整个工作负载结束后才结算,
运行中的 stdout、stderr 通道设有上限,并在截断处给出明确标记,不会无限增长。
已知限制
- 预编译包没有苹果或微软的官方签名。macOS 或 Windows 第一次运行时可能
会拦截,需要你允许一次 - Windows 还不能按命令断开网络。需要断网隔离的命令会被拒绝,而不会在
网络仍开放时继续跑 - Windows 没有本地 daemon 套接字。会话和
resume仍然可用 - Windows 上受隔离的
!command结束后才打印输出,不会边跑边刷
安装与使用见 README。
更新见 README · 更新。
系统怎么分层见 架构说明。
v1.0.9
CodeLeveler v1.0.9
English
This release rebuilds how a model request is assembled, folded, and paid for.
The control context is now separate from the transcript, every delivered prompt
segment has one source and one authority, and every model attempt is recorded in
the request ledger.
Installed stable builds can update automatically, or use leveler update
or /update.
Changed
- Prompt construction gives every delivered segment a single source, authority,
and lifecycle. Providers may change how a segment is represented on the wire
(a system message or a top-level system field) but not its order, source, or
authority, and the control context no longer travels as part of the transcript. - Wire encoding and context statistics read the same projected request, so the
reported input size and the bytes actually sent cannot disagree. Folding
pressure follows the projected request, project rules scoped to a directory
survive a fold verbatim, and historical reasoning follows the route's replay
contract. - Every model attempt is recorded in the request ledger and the resource budget,
including failures, retries, compaction summaries, and child task calls.
Consumption is rebuilt from a scope's persisted request facts on recovery, so a
background child can no longer keep spending a stale balance snapshot. - Rule delivery is budgeted against the request: every rule stays authoritative
even when only part of a rule file fits verbatim. - The repository's
./devdevelopment entry point is documented in the release
archives, for local verification and release qualification.
Fixed
- A reduced-context route can declare
max_output_tokenslarger than its own
context_window. Reserving that full completion against the window used to
saturate the usable input capacity to0, so every request looked over the hard
capacity and the run aborted withcontext management failure: ... capacity 0
after the first tool batch. A bound of zero is not a bound the model declared,
so folding now follows the quality boundary alone. Routes whose reservation
fits their window are unchanged. - The context snapshot produced before a request reaches the caller's observer
instead of being dropped. - A model-spend scope change no longer discards the task epoch's remaining
command budget. - The spend of a completed command is flushed when a batch is cancelled
mid-round, instead of being lost with the cancelled round. - A child task's rendered spawn brief is persisted on the child spec and reused
on resume, so a resumed child sees the brief it started with. /btwread-only calls pass through the ToolHost admission pipeline instead of
bypassing it.- Background task writes are constrained to the OS execution boundary, task
mutation settles only after the whole workload ends, and the live stdout and
stderr channels are capped with an explicit truncation marker rather than
growing without bound.
Known limits
- Prebuilt binaries are not Apple- or Microsoft-signed. macOS or Windows may
block the first run until you allow it - Windows cannot deny network access per command. A command that requires that
isolation is refused rather than run with the network open - Windows has no local daemon socket. Sessions and
resumestill work - A confined Windows
!commandprints its output when it finishes, not while
it runs
Install and usage: README.
Updates: README § Updates.
How the system is layered: Architecture.
中文
这一版重做了模型请求的组装、折叠和计量方式:控制上下文与会话记录分离,
每一段提示词都有唯一的来源和权威,每一次模型尝试都记入请求账本。
已安装的稳定版可以自动更新,也可以执行 leveler update 或 /update。
变更
- 提示词组装让每一段投递内容都有唯一的来源、权威和生命周期。Provider 可以
改变某一段在链路上的表示形式(system message 或顶层 system 字段),但不能
改变它的顺序、来源或权威;控制上下文不再作为会话记录的一部分传递。 - 链路编码与上下文统计读取同一个「已投影请求」,报告出的输入规模与实际发送的
字节不会再互相矛盾。折叠压力按已投影请求判定,作用于某个目录的项目规则在
折叠后被逐字保留,历史推理遵循路由自己的回放契约。 - 每一次模型尝试都记入请求账本和资源预算,包括失败、重试、压缩摘要和子任务
调用。恢复时消费量由该作用域已持久化的请求事实重建,后台子任务不会再继续
花费过期的余额快照。 - 规则投递按请求额度分配:即使规则文件只有一部分能逐字放入,每条规则仍保持
权威。 - 发布产物中记录了仓库的
./dev开发入口,用于本地验证和发布资格判定。
修复
- 缩减上下文的 route 可以声明比自身
context_window更大的
max_output_tokens。把整段补全预留在窗口上,曾把可用输入容量压到0,
于是每个请求都被判为超出硬容量,运行在第一批工具调用后即以
context management failure: ... capacity 0中止。容量为 0 不是模型声明的
界限,因此现在只按质量边界折叠;预留能放进窗口的 route 行为不变。 - 请求前产生的上下文快照现在会送达调用方的 observer,不再被丢弃。
- 模型消费作用域切换时,不再丢弃当前任务纪元剩余的命令预算。
- 批次在一轮中途被取消时,已完成命令的消费会被结清,不再随被取消的那一轮丢失。
- 子任务渲染出的 spawn brief 会持久化在子任务 spec 上并在 resume 时复用,
恢复后的子任务看到的是它启动时的那份 brief。 /btw的只读调用改为通过 ToolHost 准入管线,不再绕过它。- 后台任务写入被限制在 OS 执行边界内,任务变更在整个工作负载结束后才结算,
运行中的 stdout、stderr 通道设有上限,并在截断处给出明确标记,不会无限增长。
已知限制
- 预编译包没有苹果或微软的官方签名。macOS 或 Windows 第一次运行时可能
会拦截,需要你允许一次 - Windows 还不能按命令断开网络。需要断网隔离的命令会被拒绝,而不会在
网络仍开放时继续跑 - Windows 没有本地 daemon 套接字。会话和
resume仍然可用 - Windows 上受隔离的
!command结束后才打印输出,不会边跑边刷
安装与使用见 README。
更新见 README · 更新。
系统怎么分层见 架构说明。
v1.0.8
CodeLeveler v1.0.8
English
This patch release improves long-running task convergence, background-task
control, and command safety.
Installed stable builds can update automatically, or use leveler update
or /update.
Changed
- Pasted file references take less space in the TUI composer.
- The agent runtime no longer imposes a host-owned verification gate on task completion.
Fixed
- Running background tasks now have visible Stop buttons in the TUI list and
detail view. Stopping one task does not cancel the whole session. Closing a
TUI attached to a daemon still leaves its background tasks running. - CLI approval prompts show the operation and reason carried in the request
description, with terminal control characters sanitized. - The shell preflight treats comments as ending at the newline. Valid multiline
scripts are no longer rejected because of commands on later lines, and
later background commands and sensitive paths remain checked. - Goal-mode runs receive one runtime-owned delivery reminder after an initial
read-only round, preventing repeated self-audits from starving requested
workspace edits. - Redirects to
/dev/null,/dev/stdout, and/dev/stderrno longer request
unnecessary write elevation. Other absolute device paths remain protected. - Repository metadata writes can be persistently approved without granting
unrestricted filesystem access, so local Git commits work in assisted mode
while writes outside the workspace remain confined. - Background-task output identifies each retained stdout and stderr chunk,
preserving the source of interleaved logs.
Known limits
- Prebuilt binaries are not Apple- or Microsoft-signed. macOS or Windows may
block the first run until you allow it - Windows cannot deny network access per command. A command that requires that
isolation is refused rather than run with the network open - Windows has no local daemon socket. Sessions and
resumestill work - A confined Windows
!commandprints its output when it finishes, not while
it runs
Install and usage: README.
Updates: README § Updates.
How the system is layered: Architecture.
中文
这一补丁版本改进长任务收敛、后台任务控制和命令检查。已安装的稳定版可以
自动更新,也可以执行 leveler update 或 /update。
变更
- TUI 中粘贴的文件引用占用更少空间。
- Agent 运行时不再由宿主维护任务完成时的验证闸门。
修复
- TUI 后台任务列表和详情页为运行中的任务显示停止按钮,可单独停止任务,
不会取消整个会话。连接 daemon 时,关闭 TUI 仍不会停止后台任务。 - CLI 审批提示展示请求中的操作与原因,并清理终端控制字符。
- Shell 预检将注释范围限定在当前行:正常的多行脚本不再因后续命令被误拒,
后续行的后台启动和敏感路径也会继续检查。 - Goal 模式首轮只读后由运行时注入一次交付提醒,避免反复自检导致用户要求的
工作区修改长期得不到执行。 - 重定向到
/dev/null、/dev/stdout和/dev/stderr不再请求不必要的写权限;
其他绝对设备路径仍受保护。 - 仓库元数据写入可以单独持久授权,无需开放整个文件系统;assisted 模式可
完成本地 Git 提交,同时仍禁止写出工作区。 - 后台任务保留的 stdout、stderr 日志块会标明来源,交错输出不再丢失流信息。
已知限制
- 预编译包没有苹果或微软的官方签名。macOS 或 Windows 第一次运行时可能
会拦截,需要你允许一次 - Windows 还不能按命令断开网络。需要断网隔离的命令会被拒绝,而不会在
网络仍开放时继续跑 - Windows 没有本地 daemon 套接字。会话和
resume仍然可用 - Windows 上受隔离的
!command结束后才打印输出,不会边跑边刷
安装与使用见 README。
更新见 README · 更新。
系统怎么分层见 架构说明。
v1.0.7
CodeLeveler v1.0.7
English
This patch release improves long-running task convergence, background-task
control, and command safety.
Installed stable builds can update automatically, or use leveler update
or /update.
Changed
- Pasted file references take less space in the TUI composer.
- The agent runtime no longer imposes a host-owned verification gate on task completion.
Fixed
- Running background tasks now have visible Stop buttons in the TUI list and
detail view. Stopping one task does not cancel the whole session. Closing a
TUI attached to a daemon still leaves its background tasks running. - CLI approval prompts show the operation and reason carried in the request
description, with terminal control characters sanitized. - The shell preflight treats comments as ending at the newline. Valid multiline
scripts are no longer rejected because of commands on later lines, and
later background commands and sensitive paths remain checked. - Goal-mode runs receive one runtime-owned delivery reminder after an initial
read-only round, preventing repeated self-audits from starving requested
workspace edits. - Redirects to
/dev/null,/dev/stdout, and/dev/stderrno longer request
unnecessary write elevation. Other absolute device paths remain protected. - Repository metadata writes can be persistently approved without granting
unrestricted filesystem access, so local Git commits work in assisted mode
while writes outside the workspace remain confined. - Background-task output identifies each retained stdout and stderr chunk,
preserving the source of interleaved logs.
Known limits
- Prebuilt binaries are not Apple- or Microsoft-signed. macOS or Windows may
block the first run until you allow it - Windows cannot deny network access per command. A command that requires that
isolation is refused rather than run with the network open - Windows has no local daemon socket. Sessions and
resumestill work - A confined Windows
!commandprints its output when it finishes, not while
it runs
Install and usage: README.
Updates: README § Updates.
How the system is layered: Architecture.
中文
这一补丁版本改进长任务收敛、后台任务控制和命令检查。已安装的稳定版可以
自动更新,也可以执行 leveler update 或 /update。
变更
- TUI 中粘贴的文件引用占用更少空间。
- Agent 运行时不再由宿主维护任务完成时的验证闸门。
修复
- TUI 后台任务列表和详情页为运行中的任务显示停止按钮,可单独停止任务,
不会取消整个会话。连接 daemon 时,关闭 TUI 仍不会停止后台任务。 - CLI 审批提示展示请求中的操作与原因,并清理终端控制字符。
- Shell 预检将注释范围限定在当前行:正常的多行脚本不再因后续命令被误拒,
后续行的后台启动和敏感路径也会继续检查。 - Goal 模式首轮只读后由运行时注入一次交付提醒,避免反复自检导致用户要求的
工作区修改长期得不到执行。 - 重定向到
/dev/null、/dev/stdout和/dev/stderr不再请求不必要的写权限;
其他绝对设备路径仍受保护。 - 仓库元数据写入可以单独持久授权,无需开放整个文件系统;assisted 模式可
完成本地 Git 提交,同时仍禁止写出工作区。 - 后台任务保留的 stdout、stderr 日志块会标明来源,交错输出不再丢失流信息。
已知限制
- 预编译包没有苹果或微软的官方签名。macOS 或 Windows 第一次运行时可能
会拦截,需要你允许一次 - Windows 还不能按命令断开网络。需要断网隔离的命令会被拒绝,而不会在
网络仍开放时继续跑 - Windows 没有本地 daemon 套接字。会话和
resume仍然可用 - Windows 上受隔离的
!command结束后才打印输出,不会边跑边刷
安装与使用见 README。
更新见 README · 更新。
系统怎么分层见 架构说明。
v1.0.6
CodeLeveler v1.0.6
English
A WebUI packaging and Apple Terminal compatibility release on top of 1.0.5.
Installed stable builds can pick it up automatically, or run leveler update
/ /update.
Fixed
- Release builds now compile the WebUI before the Rust binary, so
leveler web
serves the embedded frontend instead of returning “WebUI assets are not
built” - The release contract fails when the frontend install/build steps are absent
or run after Rust compilation - Source-install instructions now include the required Node.js frontend build
beforecargo install - Apple Terminal before macOS 26 now receives a nearest-colour xterm-256
palette, avoiding broken RGB rendering while preserving dark/light theme
polarity and contrast calculations - The active-goal header now keeps its detail affordance one column away from
the terminal's right edge
Known limits
- Prebuilt binaries are not Apple- or Microsoft-signed. macOS or Windows may
block the first run until you allow it - Windows cannot deny network access per command. A command that requires that
isolation is refused rather than run with the network open - Windows has no local daemon socket. Sessions and
resumestill work - A confined Windows
!commandprints its output when it finishes, not while
it runs
Install and usage: README.
Updates: README § Updates.
How the system is layered: Architecture.
中文
1.0.5 之上的 WebUI 打包与 Apple Terminal 兼容性修复。已安装的稳定版可以
自动更新,也可以执行 leveler update 或 /update。
修复
- Release 现在会先构建 WebUI、再编译 Rust 二进制;
leveler web会提供已
嵌入的前端,不再返回“WebUI assets are not built” - 发布契约会在缺少前端安装/构建步骤,或前端晚于 Rust 编译时失败
- 源码安装说明补齐了
cargo install前所需的 Node.js 前端构建步骤 - macOS 26 之前的 Apple Terminal 现在使用最接近的 xterm-256 色板,避免
RGB 颜色显示异常,同时保留深色/浅色主题极性与对比度计算 - 活动目标标题的详情入口现在会与终端右边缘保留一列间距
已知限制
- 预编译包没有苹果或微软的官方签名。macOS 或 Windows 第一次运行时可能
会拦截,需要你允许一次 - Windows 还不能按命令断开网络。需要断网隔离的命令会被拒绝,而不会在
网络仍开放时继续跑 - Windows 没有本地 daemon 套接字。会话和
resume仍然可用 - Windows 上受隔离的
!command结束后才打印输出,不会边跑边刷
安装与使用见 README。
更新见 README · 更新。
系统怎么分层见 架构说明。
v1.0.5
CodeLeveler v1.0.5
English
A first-run and idle-experience release on top of 1.0.4. Installed stable builds pick it up automatically, or run leveler update / /update.
Added
- Running
levelerwith no configuration now starts the same first-run setup asleveler login, beginning with an explicit language choice (English / 中文) that is written to the config aslang - A fresh install enables start-up auto-update by default; package-manager users opt out with
[update] auto_update = false - The config written by
leveler loginandleveler initcarries bilingual comments for every setting it emits - The TUI predicts the user's next message as a transient ghost after a turn, and on opening an empty session it derives a starter from repository context. Tab accepts, Esc dismisses; nothing is persisted or submitted on its own
- After three idle minutes in a substantial conversation, the TUI shows one muted recap of where the work reached and what comes next
- The client protocol adds
RequestPromptSuggestion/RequestAwaySummaryand thePromptSuggestion/AwaySummaryevents (protocol minor 1.12); the remote surface refuses both commands
Changed
- Durable memory follows Claude Code-style boundaries: extraction classifies each candidate as user, feedback, project, reference, derived or task_state, and repository-derived truth and short-lived task state are refused rather than saved
- Memory confirmations read as one calm sentence per batch instead of listing candidate ids, and the memory-change notes in Conversation are phrased as plain sentences
- A fully settled plan checklist is no longer kept as conversation history after its turn ends
Fixed
- A late model-generated suggestion or recap can no longer appear after the user has started typing or a new turn has begun
- An idle recap is one-shot: a consumed deadline never fires again, and it is refused while a turn is running or text is staged
Known limits
- Prebuilt binaries are not Apple- or Microsoft-signed. macOS or Windows may block the first run until you allow it
- Windows cannot deny network access per command. A command that requires that isolation is refused rather than run with the network open
- Windows has no local daemon socket. Sessions and
resumestill work - A confined Windows
!commandprints its output when it finishes, not while it runs
Install and usage: README.
Updates: README § Updates.
How the system is layered: Architecture.
中文
1.0.4 之上的首次启动与空闲体验更新。已安装的稳定版会自动更新,也可以用 leveler update 或 /update。
新增
- 没有配置时直接运行
leveler会进入与leveler login相同的首次设置引导,第一步是显式选择语言(English / 中文),选择结果会以lang写入配置 - 全新安装默认开启启动自动更新;用包管理器安装的用户可以通过
[update] auto_update = false关闭 leveler login和leveler init写出的配置会为每个设置附带中英双语注释- TUI 会在每轮结束后预测用户下一句话,作为临时提示显示;打开空会话时则依据仓库上下文生成一条起步建议。Tab 采纳,Esc 忽略,它不会被保存,也不会自行提交
- 对话有一定内容后,空闲三分钟会在 TUI 中显示一条弱化的回顾,说明工作进展到哪一步、接下来做什么
- 客户端协议新增
RequestPromptSuggestion/RequestAwaySummary命令和PromptSuggestion/AwaySummary事件(协议 minor 1.12);远程控制面会拒绝这两个命令
变更
- 持久记忆遵循 Claude Code 式的边界:提取时会把每条候选归类为 user、feedback、project、reference、derived 或 task_state,仓库里已经能查到的事实和短期任务状态会被拒绝保存
- 记忆确认改为每批一句话,不再罗列候选 id;Conversation 中的记忆变更提示也改成自然语句
- 全部完成的计划清单在回合结束后不再作为对话历史保留
修复
- 用户已经开始输入、或新一轮已经开始后,迟到的模型提示和回顾不会再出现
- 空闲回顾只触发一次:已经消费的截止时间不会重复触发,任务运行中或已输入内容时也会被拒绝
已知限制
- 预编译包没有苹果或微软的官方签名。macOS 或 Windows 第一次运行时可能会拦截,需要你允许一次
- Windows 还不能按命令断开网络。需要断网隔离的命令会被拒绝,而不会在网络仍开放时继续跑
- Windows 没有本地 daemon 套接字。会话和
resume仍然可用 - Windows 上受隔离的
!command结束后才打印输出,不会边跑边刷
安装与使用见 README。
更新见 README · 更新。
系统怎么分层见 架构说明。
v1.0.4
CodeLeveler v1.0.4
English
A correctness-focused patch release for task continuation and durable memory. Installed stable builds pick it up automatically, or run leveler update / /update.
Changed
- Resumed work now keeps an explicit objective anchor, root turn and goal identity, so later instructions amend the same lineage instead of being mistaken for unrelated work
- Durable-looking memory candidates wait for confirmation, while explicit
remembercommands still save immediately - A later explicit preference that conflicts with the same remembered subject supersedes the old value and reports that the stale memory was updated
- Routine memory recall is shown once in Conversation instead of being duplicated as both a transcript note and a toast
Fixed
- Goal checkpoints are scoped to their exact continuation lineage and cannot be consumed by unrelated chats or goals
- Restart recovery and explicit continuation preserve the authoritative goal identity, including reopening the exact settled goal when needed
- Repeated pending candidates for the same memory subject keep only the latest value; corrections also supersede compatible keyless direct memories from older builds, and retries cannot restore stale preferences out of order
- API keys, tokens, passwords and other credential-shaped values are rejected at the memory write boundary
- Sensitive entries left by older versions are hidden from automatic recall and from every model-facing memory action, including list, read, lexical search and vector search
- Memory consolidation only considers fresh user-authored turns, avoiding replay or internal-turn candidates
Known limits
- Prebuilt binaries are not Apple- or Microsoft-signed. macOS or Windows may block the first run until you allow it
- Windows cannot deny network access per command. A command that requires that isolation is refused rather than run with the network open
- Windows has no local daemon socket. Sessions and
resumestill work - A confined Windows
!commandprints its output when it finishes, not while it runs
Install and usage: README.
Updates: README § Updates.
How the system is layered: Architecture.
中文
这是一次聚焦任务续跑正确性和持久记忆的小版本更新。已安装的稳定版会自动更新,也可以用 leveler update 或 /update。
变更
- 续跑任务现在会持久化明确的目标锚点、根 turn 和 goal 身份;后续指令只会修订同一条工作链路,不再被误当成无关任务
- 看起来值得长期保存的记忆先等待确认;明确的
remember指令仍会立即保存 - 用户明确修改同一主题的偏好时,新值会替代旧值,并提示已有记忆可能过时、已经更新
- 普通记忆召回只在 Conversation 中显示一次,不再同时出现记录和 toast
修复
- Goal checkpoint 现在严格绑定对应的续跑链路,不会被无关聊天或其他目标消费
- 重启恢复和明确续跑会保留权威 goal 身份,必要时重新打开准确的已结算 goal
- 同一记忆主题被多次提出时,待确认区只保留最新值;更正也能替换旧版本保存的无 key 直接记忆,失败重试不会再乱序恢复过时偏好
- API Key、Token、密码及其他凭证形态会在记忆写入边界被拒绝
- 旧版本已经留下的敏感记忆会从自动召回和模型可用的所有记忆动作中隐藏,包括列表、读取、关键词搜索和向量搜索
- 记忆整理只处理新鲜的用户 turn,避免从回放或内部 turn 中生成候选
已知限制
- 预编译包没有苹果或微软的官方签名。macOS 或 Windows 第一次运行时可能会拦截,需要你允许一次
- Windows 还不能按命令断开网络。需要断网隔离的命令会被拒绝,而不会在网络仍开放时继续跑
- Windows 没有本地 daemon 套接字。会话和
resume仍然可用 - Windows 上受隔离的
!command结束后才打印输出,不会边跑边刷
安装与使用见 README。
更新见 README · 更新。
系统怎么分层见 架构说明。
v1.0.3
CodeLeveler v1.0.3
English
A focused TUI usability release on top of 1.0.2. Installed stable builds pick it up automatically, or run leveler update / /update.
Changed
- Successful
wait_taskandget_taskpolling no longer adds repeated rows to Conversation; the background task remains represented once by its command row, footer and detail view - Background command status now reads “running in background” / “后台运行” to describe the live state directly
Fixed
- Failed background task waits remain visible with their task details instead of being hidden with successful scheduling polls
- Replayed sessions use the same background polling visibility rules as live sessions without dropping durable tool-call history
- Self-update now validates both legacy and current
--versionoutput formats, rejects failed version probes, and lets older installations accept the rebuilt v1.0.3 binary
Known limits
- Prebuilt binaries are not Apple- or Microsoft-signed. macOS or Windows may block the first run until you allow it
- Windows cannot deny network access per command. A command that requires that isolation is refused rather than run with the network open
- Windows has no local daemon socket. Sessions and
resumestill work - A confined Windows
!commandprints its output when it finishes, not while it runs
Install and usage: README.
Updates: README § Updates.
How the system is layered: Architecture.
中文
1.0.2 之上的 TUI 易用性更新。已安装的稳定版会自动更新,也可以用 leveler update 或 /update。
变更
- 成功的
wait_task和get_task轮询不再反复占用 Conversation 行;后台任务仍由命令行、底栏和详情页唯一呈现 - 后台命令状态改为“后台运行” / “running in background”,直接描述当前状态
修复
- 后台任务等待失败时仍会显示错误和任务详情,不会随成功的调度轮询一起隐藏
- 会话回放与实时会话使用相同的后台轮询显示规则,同时保留完整、持久化的工具调用历史
- 自更新现在兼容新旧两种
--version输出格式,拒绝版本探测失败,并允许旧版本安装重新构建的 v1.0.3
已知限制
- 预编译包没有苹果或微软的官方签名。macOS 或 Windows 第一次运行时可能会拦截,需要你允许一次
- Windows 还不能按命令断开网络。需要断网隔离的命令会被拒绝,而不会在网络仍开放时继续跑
- Windows 没有本地 daemon 套接字。会话和
resume仍然可用 - Windows 上受隔离的
!command结束后才打印输出,不会边跑边刷
安装与使用见 README。
更新见 README · 更新。
系统怎么分层见 架构说明。
v1.0.2
CodeLeveler v1.0.2
English
A feature and compatibility release on top of 1.0.1. Installed stable builds pick it up automatically, or run leveler update / /update.
Added
- First-class Zhipu BigModel Coding Plan setup for
glm-5.3andglm-5.3-flash, including reasoning, vision and 1M-context model profiles - Current DeepSeek profiles for
deepseek-flashanddeepseek-v4-pro, with vision and parallel-tool capabilities where supported - A unified skills registry, skill inspection and guarded skill-authoring workflow
- Background activity, detail and plan views in the TUI
- Durable semantic memory extraction with bounded reasoning, asynchronous batching and lifecycle recovery
Changed
- Session continuation, cancel and resume now share one explicit runtime protocol across the CLI, TUI, host and remote-control surfaces
leveler loginand the defaultleveler initpath write complete built-in model capabilities instead of generic placeholders- The retired
deepseek-v4-flashconfiguration is replaced bydeepseek-flash
Fixed
- DeepSeek thinking-mode conversations now return
reasoning_contentfor every historical assistant message when tools are present, preventing multi-turn tool requests from being rejected - DeepSeek forced tool choices disable thinking without silently dropping an explicitly supplied temperature
- Dynamic DeepSeek peak/off-peak and cache pricing is no longer represented as an inaccurate static USD price
Known limits
- Prebuilt binaries are not Apple- or Microsoft-signed. macOS or Windows may block the first run until you allow it
- Windows cannot deny network access per command. A command that requires that isolation is refused rather than run with the network open
- Windows has no local daemon socket. Sessions and
resumestill work - A confined Windows
!commandprints its output when it finishes, not while it runs
Install and usage: README.
Updates: README § Updates.
How the system is layered: Architecture.
中文
1.0.1 之上的功能与兼容性更新。已安装的稳定版会自动更新,也可以用 leveler update 或 /update。
新增
- 原生支持智谱 BigModel Coding Plan 的
glm-5.3和glm-5.3-flash,包含推理、视觉和 1M 上下文模型配置 - 支持当前 DeepSeek 模型
deepseek-flash和deepseek-v4-pro,并按模型声明视觉与并行工具能力 - 统一的 Skills 注册表、检查命令和受保护的 Skill 创建流程
- TUI 后台活动、详情页和计划视图
- 持久化语义记忆提取,支持受限推理、异步批处理和生命周期恢复
变更
- 会话续接、取消和恢复在 CLI、TUI、主机与远程控制之间共用一套明确的 runtime 协议
leveler login和默认leveler init会写入完整的内置模型能力,不再使用通用占位配置- 退役的
deepseek-v4-flash配置由deepseek-flash替代
修复
- DeepSeek 思考模式在携带工具时会为全部历史 assistant 消息回传
reasoning_content,避免多轮工具请求被拒绝 - DeepSeek 强制工具选择会关闭思考模式,但不会静默丢弃调用方显式提供的 temperature
- 不再把 DeepSeek 动态峰谷价和缓存价格错误表示为固定美元价格
已知限制
- 预编译包没有苹果或微软的官方签名。macOS 或 Windows 第一次运行时可能会拦截,需要你允许一次
- Windows 还不能按命令断开网络。需要断网隔离的命令会被拒绝,而不会在网络仍开放时继续跑
- Windows 没有本地 daemon 套接字。会话和
resume仍然可用 - Windows 上受隔离的
!command结束后才打印输出,不会边跑边刷
安装与使用见 README。
更新见 README · 更新。
系统怎么分层见 架构说明。
v1.0.1
CodeLeveler v1.0.1
English
A bug-fix release on top of 1.0.0. Installed 1.0.0 builds pick it up automatically, or run leveler update / /update.
Fixed
- Starting the TUI while an older local runtime is still busy no longer fails after 10 seconds: the client waits for the old runtime to finish and hands over to the new one
- A handover no longer hangs when another client has already started the replacement runtime
- A development build is recognised by the runtime it started, so it no longer restarts an identical runtime on every launch
- An idle background runtime shuts itself down once no client is attached and no work is running
- Every visible tool row in the TUI names what ran
- A message typed while a turn runs is sent automatically as the next turn once the runtime is ready, in order and only into the session it was written for; waiting no longer shows as "status unknown"
- Option lists in questions, pickers and approvals are numbered, and labels stay aligned when moving the cursor or past 9 → 10
Known limits
- Prebuilt binaries are not Apple- or Microsoft-signed. macOS or Windows may block the first run until you allow it
- Windows cannot deny network access per command. A command that requires that isolation is refused rather than run with the network open
- Windows has no local daemon socket. Sessions and
resumestill work - A confined Windows
!commandprints its output when it finishes, not while it runs
Install and usage: README.
Updates: README § Updates.
How the system is layered: Architecture.
中文
1.0.0 之上的修复版。已安装的 1.0.0 会自动更新,也可以用 leveler update 或 /update。
修复
- 旧的本地 runtime 还在忙时启动 TUI,不再等 10 秒后失败:客户端会等旧 runtime 做完,再交接给新的
- 另一个客户端已经拉起替代 runtime 时,交接不再卡住
- 开发构建能认出自己启动的 runtime,不会每次启动都重启一个相同的 runtime
- 没有客户端连接、也没有任务在跑时,空闲的后台 runtime 会自行退出
- TUI 里每一行可见的工具记录都写明执行了什么
- 任务运行中输入的消息,会在 runtime 就绪后按顺序自动作为下一轮发送,且只发往写它时所在的会话;排队等待不再显示为"状态未知"
- 提问、选择器和批准里的选项带编号,移动光标或从 9 到 10 时标签不再错位
已知限制
- 预编译包没有苹果或微软的官方签名。macOS 或 Windows 第一次运行时可能会拦截,需要你允许一次
- Windows 还不能按命令断开网络。需要断网隔离的命令会被拒绝,而不会在网络仍开放时继续跑
- Windows 没有本地 daemon 套接字。会话和
resume仍然可用 - Windows 上受隔离的
!command结束后才打印输出,不会边跑边刷
安装与使用见 README。
更新见 README · 更新。
系统怎么分层见 架构说明。