Skip to content

Releases: divisionseven/opencode-mesh

Release list

v1.1.0

Choose a tag to compare

@github-actions github-actions released this 21 Sep 08:29
v1.1.0
6b6e893
OpenCode-Mesh Logo

OpenCode-Mesh v1.1.0

Released September 21, 2026


What's Changed

Added

  • CLI grew a gc verb with --json output, per-verb --help on every verb, multiword send text, --json flags on peers and send, snapshot restore on uninstall, and a purge fallback that reports its method (gate: E2E suite spawning the real binary plus codecov/patch green)
  • Keychain reads gained a non-blocking path with Linux secret-tool fallback sharing the existing TTL cache, wired into the enumerate probe (gate: fallback tests failing before, green after)
  • Enumerate probes cap response bodies at 1MB, hashing over-cap bodies empty while small bodies fingerprint byte-identical (gate: over-cap and completion tests failing before, green after)
  • Install docs lead with the platform path (plugin entry plus skill by name) with the custom installer kept as a documented alternate (gate: skills CLI discovery verified live against this repo)

Fixed

  • Fix fresh installs writing invalid JSON on empty plugin configs by taking a no-leading-comma branch on blank object bodies (gate: matrix test asserting JSON.parse over three empty shapes)
  • Fix corrupt registry wipes by refusing writes on present-but-unparseable stores with STORAGE_CORRUPT, leaving entries intact (gate: garbage-seed test asserting survival plus the throw)
  • Fix GC deleting concurrent joins by snapshotting candidates read-only and re-validating inside the single writer (gate: mid-sweep join repro asserting survival)
  • Fix per-sweep trashing of live state by gating deletion behind legacy-directory detection, leaving live outbox and token paths alone (gate: live-plus-legacy seed test)
  • Fix transient direct failures dropping by routing 429, 5xx, and network faults to the claim leg; 404 misses keep PEER_NOT_FOUND with didYouMean, 401 keeps UNAUTHORIZED, and direct 429 now queues instead of surfacing (gate: two-leg test with typo target plus stubbed 500 and 429)
  • Fix broadcast dropping its tail by removing the mid-fanout 413 rethrow and reporting every peer in the failed list (gate: three-peer fan-out with middle failure)
  • Fix sandboxed roots sharing the live lock by threading an optional root through withRegistryLock from every writer (gate: two-root test asserting per-root lock files)
  • Fix forged direct senders by re-attesting the sender against the live registry on the direct leg, marking unknown senders quarantined (gate: unknown-agent send asserting the marker)
  • Fix status-only sessions reading as attached by conferring attached from the ps oracle alone (gate: ps-plus-status feed asserting only ps ids attach)
  • Fix empty status views clearing markers by treating null and empty maps as no-evidence past grace (gate: marker held across an empty view)
  • Fix permission faults misclassified as contention by narrowing isLockContention and the lock loop to EEXIST only, so EACCES throws loud instead of degrading register to busy: true (gate: injected EACCES asserting the loud throw)
  • Fix delivered rows re-claimable in the take window by adding the delivered_at IS NULL exclusion as defense-in-depth (gate: deliver-then-claim asserting zero rows)
  • Fix leading lookalike markers passing quarantine by tagging at any position when enabled (gate: index-zero feed asserting the tag)
  • Fix peers display mutating the registry by removing the persist from the read path, output byte-identical (gate: dead-id list asserting byte-identical registry)
  • Fix full-disk misses on the Node driver by also mapping numeric errcode 13 to STORAGE_FULL, proven against real full disks on both drivers with no permission shape colliding (gate: exact Node error-shape replay)
  • Fix unknown commands exiting 1 by printing usage and exiting 2 under the usage contract (gate: E2E spawn asserting code plus stderr)
  • Replace the dependency-review deny list with the allow list for MIT, Apache-2.0, ISC, BSD-3-Clause, MPL-2.0 (gate: CI green)

Removed

  • Drop the broadcast mutant probe and registry retention probe: both read repo source and asserted on text, banned under the vitest rules, with behavior already owned by gate and prune tests (gate: full suite green minus two plus a repo-wide source-read sweep)

📖 41 Commits since v1.0.1
Commit Description Author
6b6e893 chore: cut 1.1.0 release prep Division 7
202baae docs: correct 22 inaccuracies since 1.0.1 Division 7
bfcddcb docs: changelog entries for all changes since 1.0.1 Division 7
06c62bd docs: platform install primary, custom installer alternate Division 7
c1617c2 docs: platform install primary, custom installer alternate Division 7
1b327ef test: drop redundant keychain fork-count assert Division 7
2aaa0c8 test: drop source-scraping probes, behavior tests own the pins Division 7
cbc3d94 fix: unknown command exits 2 with usage Division 7
a2f6928 fix: map node driver errcode 13 to STORAGE_FULL Division 7
42e3e1e fix: contention helper reads EEXIST only, EACCES throws loud Division 7
095f977 test: cover keychain async success and bare-variant legs Division 7
9af24a8 fix: async keychain read with secret-tool fallback Division 7
959f294 test: cover enumerate stream completion and small-body legs Division 7
0592705 fix: bound enumerate response body to 1MB Division 7
09faf23 test: cover purge tiers and empty snapshot lookup Division 7
fa000bf test: cover snapshot lookup paths Division 7
849cc7d test: cover restore without snapshots Division 7
1492c51 feat(cli): snapshot restore plus purge fallback Division 7
fa5f7be chore: stamp build version Division 7
3d2cc7b feat(cli): flags, multiword send, per-verb help Division 7
6f01446 docs: update docs to link agent skill Division 7
463e8a7 feat(cli): add gc verb with json output Division 7
39dba56 fix(peers): display never mutates the registry Division 7
3a9bdd9 ci: replace deprecated deny-licenses with allow-licenses Division 7
13b842b fix(quarantine): tag lookalikes at any position Division 7
088364c fix(outbox): exclude delivered rows in claim take Division 7
32f16b4 fix(lock): permission denial fails fast, not contention Division 7
8f5cf51 fix(attach): empty views keep markers for lack of evidence Division 7
3b58fc8 fix(attach): attach from ps only, never status Division 7
8bdef0e docs: restructure install instructions Division 7
[`8d8620...
Read more

v1.0.1

Choose a tag to compare

@github-actions github-actions released this 19 Sep 20:07
v1.0.1
6ae6f05
OpenCode-Mesh Logo

OpenCode-Mesh v1.0.1

Released September 19, 2026


What's Changed

Added

  • Hardened timing-sensitive tests to deterministic outcomes (lock contention re-race, minute-boundary assertions, heartbeat stamp polling), so CI results are reliable run to run.
  • Added regression tests pinning outbox failure vocabulary, claimer poll behavior, send resolution, peers display, plugin tool paths, store shapes, and garbage-collection edges.

Fixed

  • Fix purge logs to omit the resolved path and keep only the provenance label, so env-derived paths never reach clear-text output (gate: CodeQL clear-text logging check)
  • Fix garbage collection to remove legacy outbox and token paths with filesystem removal when the trash binary is absent, so pruning still completes on minimal hosts (gate: trash policy script)
  • Fix CI to run shell steps under bash, install ripgrep before gates, and build the plugin before typecheck and tests (gate: CI green on Node 22 and 24)
  • Fix CI reliability with pinned actions, step timeouts, permission checks, and pack leak gates (gate: CI green with artifact upload)

📖 35 Commits in this release
Commit Description Author
d3b8b92 chore(release): cut 1.0.1 Division 7
b73693f chore(contact): update D7 contact info Division 7
0c0ac5a test: cover last-action tracker legs Division 7
8502ae9 test: cover pure-unit predicates and parsers Division 7
8e9652e test: cover stow detection, census, and writes Division 7
5a0d5a5 test: cover register contention and generic touch Division 7
46b16b2 test: cover filesystem edge failures Division 7
737291a test: cover discovery store shapes Division 7
a96c3b5 test: cover plugin tool-path behaviors Division 7
6a30bd6 test: cover peers display ranking and defaults Division 7
02958a2 test: cover send resolution and broadcast behavior Division 7
6b64578 test: cover clientless direct-post fallback Division 7
822f5f7 test: cover claimer poll matrix over scripted deps Division 7
1cbfc00 test: cover outbox cap, races, receipts, vacuum Division 7
3011530 test: cover outbox loader fail-closed mappings Division 7
b8494fc test: cover outbox storage-error vocabulary Division 7
f19773c test: single-evaluation imports for attribution Division 7
0a765df test: cover inbox drain edges and gc cli entry Division 7
5b14992 test: re-race exhausted lock waiters instead of failing Division 7
c934468 chore(actions): bump codeql-action init, autobuild, analyze to v4.38.0 (#13) Division 7
ab0572b test: deflake minute-boundary assert plus heartbeat stamp poll (#12) Division 7
6586352 chore(deps): pair vitest 4.1.11 with coverage-v8 4.1.11 (CVE GHSA-82fw) (#11) Division 7
43778a8 chore(docs): improve orchestrator example description in root readme Division 7
6b480e3 chore(docs): refine the caption on the orchestrator mermaid chart in root readme Division 7
d166ed6 fix(security): purge logs omit resolved path Division 7
0650b0c chore: remove npm badge from root readme until registry updates Division 7
a56d16e ci(release): trusted publishing OIDC, Node 24 Division 7
0b8980c test: direct fallback, presence, lastAction behaviors Division 7
8487c4a docs: add visual npm deps graph to readme Division 7
0ea728e fix(publish): bin path without ./ prefix Division 7
d5aa013 fix(gc): fallback delete when trash absent Division 7
47faa7d docs: update root readme Division 7
f88e2dd fix(ci): bash port, rg install, build step, hardening Division 7
dd83ad9 fix(ci): valid upload-artifact pin, quote labels Division 7
2b0633d init: transition to prod repo Division 7

View Complete Changelog →