Skip to content

Releases: fakechris/lumenbox

LumenBox 0.3.6

Choose a tag to compare

@fakechris fakechris released this 03 Oct 06:11

LumenBox 0.3.6

  • Improve durable work admission, crash recovery and caller identity isolation (INV-884, #320).
  • Include pinned Office/PDF document libraries; box-doctor generates and reopens DOCX, XLSX, PPTX and PDF (INV-713, #321).
  • Include scoped sensitive-input approval reuse and executor validation (INV-955, #326).
  • Include personal Docker Box provisioning, durable quota reservations and scoped directory access from latest main (INV-964, #330/#331).

Downloads: signed macOS Apple Silicon and Intel DMG/ZIP packages. SHA256SUMS is included. Docker: fakechris/lumenbox:0.3.6 (linux/arm64). Recreate an existing Box to load the new runtime.

Packages are Developer ID signed and are not notarized. Office read-back checks content and structure; visual layout and real-model workflow acceptance are separate.

LumenBox 0.3.5

Choose a tag to compare

@fakechris fakechris released this 03 Oct 03:56

LumenBox 0.3.5 improves sensitive form input and personal/team Box access.

  • Confirm repeated sensitive input once per turn. The same approved value can be reused for the same data category and origin within the same user, conversation, turn and desktop. Changed scope, expiry and restarts require a new approval. Writes are bound to the checked field, so page focus handlers cannot redirect the input.
  • Personal Boxes and template access. Personal Box provisioning and delivery are integrated with membership checks; template reads and imports respect Box membership.
  • Team administration. Directory synchronization, department Box quotas and authenticated first-administrator enrollment have been added.
  • Managed skills. Five maintained skill packages cover site playbooks, errands, acting on the user’s behalf, routines and skills, and code work.

Build: afa0f2116299cd300ec8821c68ff0d21675ad087. Includes INV-955 / PR #326 and the changes merged since 0.3.4.

Validation: 2,290 tests and release CI passed; npm run release:check passed against these four installers and the published Docker image. A fresh 0.3.5 Box passed 42/42 smoke checks. Both signed macOS packages passed signature verification, packaged CLI launch and source/build-stamp checks; each ZIP carries all 66 required runtime packages. INV-955 also passed real Chromium tests for approval reuse, scope changes, expired consent, focus redirection and repeated rich-text input. Real-model workflows, live directory-provider integration and clean-machine native UI acceptance were not run for this release.

Downloads: signed macOS ARM64 and Intel DMG/ZIP (not notarized). Docker: fakechris/lumenbox:0.3.5 and latest, linux/arm64. Existing Box containers need recreation to use the new daemon.

LumenBox 0.3.4

Choose a tag to compare

@fakechris fakechris released this 02 Oct 02:26
19ba61e

LumenBox 0.3.4 makes connected services usable by the default team and makes the record honest about what delegated engines, retries and metering actually did.

  • Connected services reach the default team. Tool lists can name an MCP service (notion__*) or every service the box carries (mcp:*). The starter team and the catalog experts get mcp:*, except the two reviewers. Existing agents are not widened automatically; add mcp:* to one in its settings.
  • A delegation is done only when the engine says so. Claude Code, pi and opencode now run in their machine-readable modes, and the outcome comes from the engine's own completion report: done, failed, stopped, or unknown. Measured on the pinned versions, pi exits 0 on a provider error and Claude reports a 400 as "success" with is_error; neither counts as done any more. A thread Claude cannot resume is started fresh, with the reason.
  • One retry layer. The model SDK no longer retries on its own underneath the host, so every retry is visible and counted once.
  • Metering does not record nothing. The relay records a conservative estimate when a provider reports no usage or a stream is cut, counts it against the ceiling, and reports it apart from measured usage.
  • Approvals stay on the record. The policy log archives instead of dropping old approvals, and the audit export now carries who asked, who approved or denied, and what delegated engines called.
  • Two timing-dependent tests now assert order instead of milliseconds.

Validation: 2241 tests passed; typecheck and lint clean; npm run release:check passed against these artifacts and the published image; npm run smoke passed 42/42 against a fresh box from the 0.3.4 image. The engine outcomes were measured against a stub model server on claude 2.1.250, pi 0.85.1 and opencode 1.18.25; long real-model runs with tool calls were not measured.

Downloads: signed macOS ARM64 and x64 DMG/ZIP (not notarized). Docker: fakechris/lumenbox:0.3.4 and latest, linux/arm64.

LumenBox 0.3.3

Choose a tag to compare

@fakechris fakechris released this 01 Oct 15:44
e1aaa34

LumenBox 0.3.3 reduces idle desktop overhead and adds visibility into box resources.

  • Reclaim newly opened, unused desktops after 15 idle minutes. Used, adopted, viewed, pinned, or uncertain sessions stay alive. Files and profiles are preserved.
  • Show running, retained and failed desktops, container memory, and a session pin in Settings.
  • Avoid orphaned VNC shared memory during reclamation and keep warm readiness checks out of the cold-start queue.

Validation: 2200 tests passed. A 12-agent idle comparison measured 88.54% lower median memory than eager desktop startup. After sustained workload warmup, 100 reclaim cycles passed with 11.1 MiB total memory growth and 2.86-second cold-interaction p95; no orphan IPC accumulation. An earlier cold-cache run exceeded the total-memory bound due primarily to file-cache growth and remains a known measurement limitation.

The eight-hour soak is still running at publication time; this release does not establish absence of a slow memory leak.

Downloads: signed macOS ARM64 and x64 DMG/ZIP (not notarized). Docker: fakechris/lumenbox:0.3.3 and latest, linux/arm64.

LumenBox 0.3.2

Choose a tag to compare

@fakechris fakechris released this 01 Oct 12:36
5aeb70a

Agent desktops now start when you open a desktop or run a GUI tool. Starting the app, reconnecting a box, and ordinary text/file tasks no longer prewarm every agent desktop. Concurrent requests share one startup, with at most two desktop startups in flight.

  • Keep hidden desktop panes disconnected until explicitly opened.
  • Restore only the requested desktop on HTTP or WebSocket reconnect.
  • Hide the GUI shell option from headless side conversations.

Includes signed macOS Apple Silicon and Intel DMG/ZIP installers. macOS notarization was not configured for this build.

Box image: docker.io/fakechris/lumenbox:0.3.2 (linux/arm64), also published as latest.
Digest: sha256:bc6da73665b70c17ebecd89217c7dd75c4693521da560bcee455e864872a1960.

Validation: 2,189 tests passed; CI passed; packaged dependency closure and Docker Hub tag checks passed; isolated real-container smoke: 42 passed, 0 failed. Automatic idle reclamation and long-duration leak verification are not part of this release.

PR: #310
Commit: 5aeb70a8e730de15efab73508d0f49bd3cc1938f

LumenBox 0.3.1 — the first run, unblocked

Choose a tag to compare

@fakechris fakechris released this 29 Sep 07:40
2fc1262

LumenBox 0.3.1 — the first run, unblocked

Cut on 2026-09-29 from commit 1b5152c (main). This is the release 0.3.0 meant to be:
0.3.0's installers shipped broken and were re-published once already; this one was built
through the release gates that exist because of that incident (docs/27). The drop-in and
bridge are unchanged — fetch them from the 0.3.0 release if you need them.

What changed since 0.3.0

  • The first run says what is wrong. The Box section now distinguishes docker is not
    installed
    (it names Docker Desktop and OrbStack, with links), Docker is installed but
    not running
    (start it and press again), and the engine being fine (INV-855, #290).
  • The first image pull announces itself — roughly 750MB, a few minutes — and a failed
    pull says which failure it was: the registry has no such tag (update the app), or the
    registry never answered (network; point Settings → Box at a mirror, which is now a
    setting — boxImage in config.json) (INV-856, #291).
  • The setup card asks for the model key first. The welcome note always promised "a
    provider with a key and a box"; now the card grades both, and first run shows only
    Save & restart, so the first save is one that takes effect (INV-857, #292).
  • The box image is published per app version (fakechris/lumenbox:0.3.1) and the app
    pulls exactly that tag on first start (#289).
  • Right-pane display fixes: context and waiting items stay readable (#288).
  • Release-side: release:check now refuses installers with an incomplete dependency tree
    and apps whose image tag is not on Docker Hub (#293). That gate is for us, but it is
    why this page's files work.

Install on macOS

Download the disk image for this Mac, open it, drag LumenBox to Applications.

  • LumenBox-0.3.1-arm64.dmg — Apple Silicon
  • LumenBox-0.3.1-x64.dmg — Intel

The app is signed with an Apple Developer ID certificate but is not notarized.
Gatekeeper will say it cannot be checked. Do one of:

  • right-click the app in Applications → Open → Open (once), or
  • in Terminal: xattr -dr com.apple.quarantine /Applications/LumenBox.app

Then it opens normally. It needs a model key (the setup card asks first) and a box:
Docker Desktop or OrbStack on this Mac, Docker on another machine, or a Grok Bot's box
through the bridge. The walkthrough is Getting started.

Coming from broken 0.3.0?

If the app said "The LumenBox server will not stay up" on first launch, your download
predates the 2026-09-29 re-publish — install this 0.3.1 instead. Your ~/.agentbox
settings and keys survive the swap.

LumenBox 0.3.0 — a goal that keeps going

Choose a tag to compare

@fakechris fakechris released this 28 Sep 08:29
4c6a75e

LumenBox 0.3.0 — a goal that keeps going

Cut on 2026-09-28. The tag is 4c6a75e. This release is the desktop app, the drop-in, and the bridge script.

2026-09-29 re-publish. The four app files first published under this release were broken —
they shipped without the bundled node dependencies and crashed on first launch
("The LumenBox server will not stay up"). They have been replaced with a clean rebuild from
commit 203cdb4 (the tag plus the image-pull fix in #285/#286, which the install steps below
depend on). If you downloaded before 2026-09-29 and the app will not start, download again.

The image-pull feature means a fresh machine no longer needs a local image build: pressing
Start the box pulls fakechris/lumenbox:0.3.0 from Docker Hub.

Install on macOS

Download the disk image for this Mac, open it, drag LumenBox to Applications.

  • LumenBox-0.3.0-arm64.dmg — Apple Silicon
  • LumenBox-0.3.0-x64.dmg — Intel

The app is signed with an Apple Developer ID certificate but is not notarized. Gatekeeper will say it cannot be checked.
Do one of:

  • right-click the app in Applications → Open → Open (once), or
  • in Terminal: xattr -dr com.apple.quarantine /Applications/LumenBox.app

Then it opens normally. It needs a model key (Settings asks) and a box: Docker Desktop or
OrbStack on this Mac, Docker on another machine, or a Grok Bot's box through the bridge.
The walkthrough is Getting started.

Windows and Linux installers are not in this release.

What changed since 0.2.1

  • A goal the agent pursues. /goal beside /new. The host keeps waking while the
    conversation is quiet, stops for four reasons, and the only way out is a finish report.
    Whether the goal is done is a gate the worker does not grade: a claim, the host's checks,
    a verifier that never saw the work. A budget, counted in input-token equivalents, sits on
    the board. Silence does not archive a goal.
  • A turn survives the host dying. A checkpoint is written before a tool call and while an
    approval is waiting. After a restart the same turn continues from that step. What already
    finished is not run again.
  • The desktop acts on what it saw. Native actions go through AT-SPI. A target has to match
    the observation it was taken from, and a write that does not match is refused.
  • Memory keeps what the person said. A flush before compaction keeps their words. A
    maintenance pass may propose a merge, a retirement, or a rewrite, and the code checks the
    proposal before applying it. A credential is refused at every door. Memory derived from a
    source can be revoked with that source.
  • A message that arrives mid-task is its own task. Only a plain continuation steers the
    one already running. A reply that was not confirmed as delivered is a failure, not a sent
    message. A Feishu reply carries the message it is answering.
  • The thread is easier to come back to. Unread is per message. A long thread can jump to
    a day. An edit is shown as a diff, live and on replay.
  • A published install refuses plain HTTP. The token key comes from a secret, not from the
    directory it protects. A spend ceiling is enforced at the relay, and the box cannot raise it.
  • Routines can choose not to deliver. Standing files (AGENTS.md, SOUL.md, USER.md,
    HEARTBEAT.md) are injected each turn, and a change is shown as a diff. A skill says when
    it applies and when it does not. Standing directories are keyed by the agent, and a
    writable mirror is checked again on every sync.
  • A resumed call is not a free pass. It goes back through the policy gate. Only a call
    the executor can safely repeat is replayed. An approval stays open until it is answered.
  • Silence stays silent on the way out. A deliberate NothingToSay is not rewritten into
    a completion line by the channel manager.
  • A memory rewrite cannot invent a date. A rewrite may only resolve a relative date, and
    a retirement has to match the source date. An anchor that says the person said something
    needs a person behind it, and a flush that already timed out cannot write afterwards.
  • The bridge skill keeps Tailscale state across a restart, and the box notes a boot
    recovery path for sshd and the bridge's own dependencies. That lives in share/grok-bridge;
    the lumen-bridge.sh asset attached here is the installer script, unchanged by that work.

Also in this release

  • lumen-dropin.tar.gz — the box daemon and its desktop scripts, for a machine that is not
    a Docker image of ours.
  • lumen-bridge.sh — the installer a Grok Bot runs from the bridge template, or you run
    yourself.

The app still pulls agentbox/box:latest the first time a box starts. That image is not
part of this GitHub release. A box you already have keeps the image it has until you upgrade
it.

Known limits

  • macOS only, Apple Silicon and Intel. No Windows or Linux installer.
  • Not notarized, and not signed with a Developer ID (see above). Gatekeeper rejects the
    signature (spctl: rejected, origin Lumen Local Codesign). The quarantine command above
    is how it opens.
  • The Docker image is large; the first Start the box takes minutes.

LumenBox 0.2.1 — after the laptop sleeps

Choose a tag to compare

@fakechris fakechris released this 05 Sep 12:11
491535f

LumenBox 0.2.1 — after the laptop sleeps

Found on the first morning after 0.2.0: the laptop slept overnight, the Feishu socket died
but still said "connected", and a message in the group got no reply for fourteen minutes —
until a restart's catch-up replayed it. Three fixes and a diagnosis aid:

  • Sweep on wake. When the machine resumes from sleep, the app asks the server to check every
    chat channel against the vendor's message history at once; the periodic sweep now runs every
    five minutes instead of ten.
  • A server log on disk. ~/Library/Logs/LumenBox/server.log (rotated at 5 MB). Until now a
    Finder-launched app's server output went nowhere, and there was nothing to read.
  • Docker errors say why. A silent docker inspect failure now carries the exit code and
    the head of the PATH it ran under.
  • The catch-up says what it did. Every quiet exit has a reason in the log, and one line
    says how many chats, threads and messages a sweep looked at.

Same install notes as 0.2.0: Apple Silicon, signed but not notarized — right-click → Open
once, or xattr -dr com.apple.quarantine /Applications/LumenBox.app.

One thing that is not a bug but looks like one: a reply to a message in a Feishu group lands
in a thread under that message
, collapsed until you open it. If the bot seems silent, open
the message's thread first.

LumenBox 0.2.0 — the first release for anyone

Choose a tag to compare

@fakechris fakechris released this 04 Sep 06:59
5a7a048

LumenBox 0.2.0 — the first release for anyone

The first build meant for a person who has never seen the project: a macOS app, a getting-started
guide, and a way to bring a box of your own.

Install on macOS

Download LumenBox-0.2.0-arm64.dmg (Apple Silicon), open it, drag LumenBox to Applications. An
Intel build is not in this release: the toolchain's download of the Intel runtime kept aborting on
the release machine; it follows as 0.2.1 when it builds.

The app is signed with a Developer ID but not notarized. Gatekeeper will say it cannot be
checked. Do one of:

  • right-click the app in Applications → Open → Open (once), or
  • in Terminal: xattr -dr com.apple.quarantine /Applications/LumenBox.app

Then it opens normally. It needs a model key (Settings asks) and a box: Docker Desktop or
OrbStack on this Mac, Docker on another machine, or a Grok Bot's box through the
LumenBox Bridge template. Everything is in
Getting started.

What is in it

  • A team of agents with their own desktops, browsers and shells in one Linux box; watch and
    take over any desktop.
  • Feishu and DingTalk as chat surfaces, with cards, files and button approvals.
  • Memory in plain files; skills in SKILL.md folders; bot templates that pack and share.
  • The turn engine minds the person: the opening line reaches the chat while tools run, read-only
    tools run in parallel, a verdict from memory is sent back to check.
  • Forks and delegated jobs survive a restart; delegated engines can be lent host MCP tools
    without a credential entering the box; hot-reloadable extensions.
  • Launch at login.

Also in this release

  • lumen-dropin.tar.gz — the box daemon and its desktop scripts, for a box that is not a Docker
    container of ours (a Grok Bot's VM, any Linux machine).
  • lumen-bridge.sh — the installer a Grok Bot runs from the Bridge template, or you run yourself.

Known limits

  • Apple Silicon macOS only in this release; Intel next, Windows and Linux builds are unproduced.
  • Not notarized (see above).
  • The Docker box image is pulled on first start and is large; the first Start the box takes minutes.

LumenBox drop-in for Grok Bot boxes (2026-09-03)

Choose a tag to compare

@fakechris fakechris released this 04 Sep 03:03
28ae0c9

The box daemon plus lumen-bridge.sh, the in-box installer a Grok Bot runs from the LumenBox Bridge skill (docs/35). Unpacks under ~/.lumen, starts a desktop of its own at :10 and the daemon on the box's tailnet address; nothing of the host bot's is touched.