Skip to content

Releases: eric-wien/ogma

Ogma v2.8.0

Choose a tag to compare

@eric-wien eric-wien released this 19 Aug 09:04

Added

  • Shared memory is now portable with host backups. Backup includes configured external memory, fingerprints its changes, supports memory-only backups, and restore remains compatible with older archives.

Changed

  • Fresh Codex-only installs use provider-neutral memory. Existing configured memory paths remain shared across harness switches.
  • Removed the completed implementation roadmap; released behavior remains documented in the README, workflow guide, and changelog.

Security

  • Backup archives, temporary staging data, and newly created memory directories are private from creation. Partial memory copies fail closed, and the documentation warns that off-host archives require protection.

Full Changelog: v2.7.1...v2.8.0

Ogma v2.7.1

Choose a tag to compare

@eric-wien eric-wien released this 25 Jul 09:02

Fixed

  • Nightly dream now follows the selected assistant harness. Fresh installs and harness switches keep OGMA_DREAM_MODEL aligned with the configured Claude or Codex model, setup detects cross-provider mismatches, and the dream runner safely ignores stale provider-incompatible values.

Full Changelog: v2.7.0...v2.7.1

Ogma v2.6.0

Choose a tag to compare

@eric-wien eric-wien released this 21 Jul 07:59

OpenAI Codex is now available as a parallel assistant harness alongside Claude Code. This release adds resumable headless Codex sessions, shared memory/persona/skills, provider-aware briefing and dream routines, Codex setup and sandbox configuration, and unit-test coverage for session persistence and isolation.\n\nSwitch an existing installation with: bin/setup --reconfigure llm,model,overlays\n\nSee CHANGELOG.md for full details.

v2.5.0 — Matrix image/vision support

Choose a tag to compare

@eric-wien eric-wien released this 10 Jul 12:30

Images sent to the bot over Matrix now reach the assistant layer: the transport yields media messages (mxc url, filename, mimetype, caption) and downloads them via the authenticated media endpoint (legacy fallback included); the gateway saves images into the LLM workspace and Claude views them natively with its Read tool — captions included. Non-image files get a notice; size capped at 10 MB, saved copies pruned after 14 days. Encrypted media stays out of scope (no-E2EE design). CI now also syntax-checks transport_matrix.py.

See CHANGELOG.md for details.

v2.4.0 — Matrix command list as room topic

Choose a tag to compare

@eric-wien eric-wien released this 09 Jul 18:38

Added

  • Matrix: command list published as the room topic. Element (X) has no bot-command menu UI, so Matrix users had no way to discover commands beyond knowing /help. The matrix transport's register_menu now formats the command list as a one-line topic (Commands: /help /status … | /help for details) and sets it in every joined room on gateway startup, and in rooms joined via invite — commands change only across a restart, so the topic stays current automatically. The update is skipped when the topic already matches (no "changed the topic" notice per restart). Setting a topic needs power level ≥ 50 in the room; where the bot is a plain member the failure is logged and everything else proceeds.

v2.3.0 — transport-aware notifications

Choose a tag to compare

@eric-wien eric-wien released this 09 Jul 18:19

Companion to v2.2.0's Matrix transport: scheduled routines now deliver alerts over whatever transport the gateway runs on.

  • New bin/notify replaces bin/tg-send as the delivery tool for timers and watchers (backup, health-check, briefing, custom checks). It dispatches on OGMA_TRANSPORT with the gateway's config precedence (real env > .env > config/matrix_bot.env.local).
  • New setting MATRIX_NOTIFY_ROOM — the room scheduled notifications are posted to (the bot must be a member).
  • Credentials reach curl via --config on a private fd, never argv.
  • bin/tg-send remains as a deprecated shim (exec notify "$@"), so host-local scripts keep working unchanged.

v2.2.0 — Matrix transport

Choose a tag to compare

@eric-wien eric-wien released this 09 Jul 18:12

The gateway can now run over your own Matrix homeserver instead of Telegram: set OGMA_TRANSPORT=matrix, drop the bot credentials in config/matrix_bot.env.local, and the whole channel stays on infrastructure you control.

  • New transport_matrix.py — same six-method transport seam, still Python stdlib only: long-polled /sync with a persisted since-token, chunked sends, long output via media-repo upload, typing indicator.
  • Safety first: the first sync skips the room backlog (a stale message is never replayed as a fresh command), room invites are auto-joined only when the inviter is on the allow-list, and authorization always targets the sender — never the room.
  • Per-backend allow-lists: MATRIX_ALLOWED_USERS / MATRIX_GUEST_USERS mirror their Telegram counterparts.
  • No E2EE by design (would need native olm bindings) — pair it with a self-hosted, federation-off homeserver you trust. See .env.example for setup.

Transports now yield an explicit actor field; Telegram behavior is unchanged. E2E-tested against a live Continuwuity server.

v2.1.0 — backup delta-skip & fail-closed .gitignore

Choose a tag to compare

@eric-wien eric-wien released this 09 Jul 06:05

Added

  • Backups skip when nothing changed. bin/backup fingerprints its manifest (path, size and mtime of every host-local file) and compares it to the fingerprint recorded after the last successful run (stored in the backup directory, outside the repo). On a match the archive is skipped entirely; a timer run posts a one-line "skipped" note instead. New --force flag archives regardless, and a stale fingerprint never suppresses the first backup after the archives were deleted.

Security

  • Fail-closed .gitignore. Host-local files used to be ignored one by one — forgetting an entry meant a private file could be committed to a fork. The rules are now pattern-based and fail closed: anything with .local in its name is ignored wherever it lives, and bin/, config/ and systemd/ are default-deny with an explicit whitelist of the public files. Also widened: .env* (catches .env.bak copies; .env.example stays tracked) and sessions.json*. The tracked file set is unchanged. Adding a new public file to one of the three directories now requires a whitelist entry — the worst forgetting can do is leave a file out of the repo, not leak one in.

Full Changelog: v2.0.1...v2.1.0

v2.0.1 — README rewrite for clarity

Choose a tag to compare

@eric-wien eric-wien released this 02 Jul 11:16

Changed

  • README rewritten for clarity — same content, stricter structure: what it is → how it works → security → setup → daily use → maintenance. Duplicated self-host notes and scattered doc pointers consolidated into a single "Where to find things" documentation map; the systemd User= warning moved to the systemd step. No information removed.

Docs-only release; no code changes.

v2.0.0 — Ogma is now a secure remote command runner (Claude optional)

Choose a tag to compare

@eric-wien eric-wien released this 02 Jul 10:53

The repositioning release. Ogma's core is now a secure remote command runner: chat-driven execution of commands you predefine on your own machine — deterministic, shell-free, double-gated. Claude Code is now an optional layer (OGMA_LLM=claude|off): keep it for a conversation partner that can perform tasks and analyze, or run commands-only with zero LLM dependency (Python stdlib is then the only requirement).

Three tiers, each optional on top of the one below:

  1. Core — gateway + command runner (/status, /health, your own commands via ogmactl.local + commands.local.json — see the new extending tutorial)
  2. LLM layer — free-text chat via headless Claude Code sessions
  3. Assistant layer — persona, memory, briefing, dream, skills

⚠️ Breaking changes

  • /restart requires /confirm — protected commands arm instead of firing (window: 180s, OGMA_CONFIRM_TTL; also available for your own commands via "confirm": true).
  • Group chats authorize the sender, not the chat — each user ID must be allow-listed individually.
  • Long command output (>~8k chars) arrives as a document, not chunked text.
  • bin/setup --reconfigure numeric section IDs shifted (names unchanged).
  • A missing claude CLI no longer aborts startup — the gateway runs command-only instead.
  • Internals reorganized for patch-carriers: Claude specifics → llm_claude.py, Telegram specifics → transport_telegram.py.

No .env migration needed — defaults preserve existing behavior.

Hardening (Phase 2)

  • Two-step /confirm for destructive commands, per-argument regex validation (fails closed), append-only audit log (state/audit.log, view via /logs audit), guest role (TELEGRAM_GUEST_USERS: read-only subset), delivery-lag-aware confirm windows, group sender checks.

Signal-ready (Phase 3)

  • All Telegram specifics live behind a six-method transport surface (transport_telegram.py). A signal-cli backend is now an implementation, not a rewrite.

Also

  • Command completion + duration logging; inbound delivery lag surfaced in the log; ogmactl restart timer no longer fires up to a minute late (AccuracySec=1s); assistant scripts (briefing/dream) are clean no-ops on command-only installs.

Full details in the CHANGELOG and the roadmap this release implements.

🤖 Generated with Claude Code

https://claude.ai/code/session_01BpU5gQZgDocjfqqhNWJZvP