Repository navigation
Releases: eric-wien/ogma
Release list
Ogma v2.8.0
Added
- Shared memory is now portable with host backups. Backup includes configured external memory, fingerprints its changes, supports memory-only backups, and restore remains compatible with older archives.
Changed
- Fresh Codex-only installs use provider-neutral memory. Existing configured memory paths remain shared across harness switches.
- Removed the completed implementation roadmap; released behavior remains documented in the README, workflow guide, and changelog.
Security
- Backup archives, temporary staging data, and newly created memory directories are private from creation. Partial memory copies fail closed, and the documentation warns that off-host archives require protection.
Full Changelog: v2.7.1...v2.8.0
Ogma v2.7.1
Fixed
- Nightly dream now follows the selected assistant harness. Fresh installs and harness switches keep
OGMA_DREAM_MODELaligned with the configured Claude or Codex model, setup detects cross-provider mismatches, and the dream runner safely ignores stale provider-incompatible values.
Full Changelog: v2.7.0...v2.7.1
Ogma v2.6.0
OpenAI Codex is now available as a parallel assistant harness alongside Claude Code. This release adds resumable headless Codex sessions, shared memory/persona/skills, provider-aware briefing and dream routines, Codex setup and sandbox configuration, and unit-test coverage for session persistence and isolation.\n\nSwitch an existing installation with: bin/setup --reconfigure llm,model,overlays\n\nSee CHANGELOG.md for full details.
v2.5.0 — Matrix image/vision support
Images sent to the bot over Matrix now reach the assistant layer: the transport yields media messages (mxc url, filename, mimetype, caption) and downloads them via the authenticated media endpoint (legacy fallback included); the gateway saves images into the LLM workspace and Claude views them natively with its Read tool — captions included. Non-image files get a notice; size capped at 10 MB, saved copies pruned after 14 days. Encrypted media stays out of scope (no-E2EE design). CI now also syntax-checks transport_matrix.py.
See CHANGELOG.md for details.
v2.4.0 — Matrix command list as room topic
Added
- Matrix: command list published as the room topic. Element (X) has no bot-command menu UI, so Matrix users had no way to discover commands beyond knowing
/help. The matrix transport'sregister_menunow formats the command list as a one-line topic (Commands: /help /status … | /help for details) and sets it in every joined room on gateway startup, and in rooms joined via invite — commands change only across a restart, so the topic stays current automatically. The update is skipped when the topic already matches (no "changed the topic" notice per restart). Setting a topic needs power level ≥ 50 in the room; where the bot is a plain member the failure is logged and everything else proceeds.
v2.3.0 — transport-aware notifications
Companion to v2.2.0's Matrix transport: scheduled routines now deliver alerts over whatever transport the gateway runs on.
- New
bin/notifyreplacesbin/tg-sendas the delivery tool for timers and watchers (backup, health-check, briefing, custom checks). It dispatches onOGMA_TRANSPORTwith the gateway's config precedence (real env >.env>config/matrix_bot.env.local). - New setting
MATRIX_NOTIFY_ROOM— the room scheduled notifications are posted to (the bot must be a member). - Credentials reach curl via
--configon a private fd, never argv. bin/tg-sendremains as a deprecated shim (exec notify "$@"), so host-local scripts keep working unchanged.
v2.2.0 — Matrix transport
The gateway can now run over your own Matrix homeserver instead of Telegram: set OGMA_TRANSPORT=matrix, drop the bot credentials in config/matrix_bot.env.local, and the whole channel stays on infrastructure you control.
- New
transport_matrix.py— same six-method transport seam, still Python stdlib only: long-polled/syncwith a persisted since-token, chunked sends, long output via media-repo upload, typing indicator. - Safety first: the first sync skips the room backlog (a stale message is never replayed as a fresh command), room invites are auto-joined only when the inviter is on the allow-list, and authorization always targets the sender — never the room.
- Per-backend allow-lists:
MATRIX_ALLOWED_USERS/MATRIX_GUEST_USERSmirror their Telegram counterparts. - No E2EE by design (would need native olm bindings) — pair it with a self-hosted, federation-off homeserver you trust. See
.env.examplefor setup.
Transports now yield an explicit actor field; Telegram behavior is unchanged. E2E-tested against a live Continuwuity server.
v2.1.0 — backup delta-skip & fail-closed .gitignore
Added
- Backups skip when nothing changed.
bin/backupfingerprints its manifest (path, size and mtime of every host-local file) and compares it to the fingerprint recorded after the last successful run (stored in the backup directory, outside the repo). On a match the archive is skipped entirely; a timer run posts a one-line "skipped" note instead. New--forceflag archives regardless, and a stale fingerprint never suppresses the first backup after the archives were deleted.
Security
- Fail-closed
.gitignore. Host-local files used to be ignored one by one — forgetting an entry meant a private file could be committed to a fork. The rules are now pattern-based and fail closed: anything with.localin its name is ignored wherever it lives, andbin/,config/andsystemd/are default-deny with an explicit whitelist of the public files. Also widened:.env*(catches.env.bakcopies;.env.examplestays tracked) andsessions.json*. The tracked file set is unchanged. Adding a new public file to one of the three directories now requires a whitelist entry — the worst forgetting can do is leave a file out of the repo, not leak one in.
Full Changelog: v2.0.1...v2.1.0
v2.0.1 — README rewrite for clarity
Changed
- README rewritten for clarity — same content, stricter structure: what it is → how it works → security → setup → daily use → maintenance. Duplicated self-host notes and scattered doc pointers consolidated into a single "Where to find things" documentation map; the systemd
User=warning moved to the systemd step. No information removed.
Docs-only release; no code changes.
v2.0.0 — Ogma is now a secure remote command runner (Claude optional)
The repositioning release. Ogma's core is now a secure remote command runner: chat-driven execution of commands you predefine on your own machine — deterministic, shell-free, double-gated. Claude Code is now an optional layer (OGMA_LLM=claude|off): keep it for a conversation partner that can perform tasks and analyze, or run commands-only with zero LLM dependency (Python stdlib is then the only requirement).
Three tiers, each optional on top of the one below:
- Core — gateway + command runner (
/status,/health, your own commands viaogmactl.local+commands.local.json— see the new extending tutorial) - LLM layer — free-text chat via headless Claude Code sessions
- Assistant layer — persona, memory, briefing, dream, skills
⚠️ Breaking changes
/restartrequires/confirm— protected commands arm instead of firing (window: 180s,OGMA_CONFIRM_TTL; also available for your own commands via"confirm": true).- Group chats authorize the sender, not the chat — each user ID must be allow-listed individually.
- Long command output (>~8k chars) arrives as a document, not chunked text.
bin/setup --reconfigurenumeric section IDs shifted (names unchanged).- A missing
claudeCLI no longer aborts startup — the gateway runs command-only instead. - Internals reorganized for patch-carriers: Claude specifics →
llm_claude.py, Telegram specifics →transport_telegram.py.
No .env migration needed — defaults preserve existing behavior.
Hardening (Phase 2)
- Two-step /confirm for destructive commands, per-argument regex validation (fails closed), append-only audit log (
state/audit.log, view via/logs audit), guest role (TELEGRAM_GUEST_USERS: read-only subset), delivery-lag-aware confirm windows, group sender checks.
Signal-ready (Phase 3)
- All Telegram specifics live behind a six-method transport surface (
transport_telegram.py). Asignal-clibackend is now an implementation, not a rewrite.
Also
- Command completion + duration logging; inbound delivery lag surfaced in the log;
ogmactl restarttimer no longer fires up to a minute late (AccuracySec=1s); assistant scripts (briefing/dream) are clean no-ops on command-only installs.
Full details in the CHANGELOG and the roadmap this release implements.
🤖 Generated with Claude Code