Releases: fakechris/lumenbox
Release list
LumenBox 0.3.6
LumenBox 0.3.6
- Improve durable work admission, crash recovery and caller identity isolation (INV-884, #320).
- Include pinned Office/PDF document libraries; box-doctor generates and reopens DOCX, XLSX, PPTX and PDF (INV-713, #321).
- Include scoped sensitive-input approval reuse and executor validation (INV-955, #326).
- Include personal Docker Box provisioning, durable quota reservations and scoped directory access from latest main (INV-964, #330/#331).
Downloads: signed macOS Apple Silicon and Intel DMG/ZIP packages. SHA256SUMS is included. Docker: fakechris/lumenbox:0.3.6 (linux/arm64). Recreate an existing Box to load the new runtime.
Packages are Developer ID signed and are not notarized. Office read-back checks content and structure; visual layout and real-model workflow acceptance are separate.
LumenBox 0.3.5
LumenBox 0.3.5 improves sensitive form input and personal/team Box access.
- Confirm repeated sensitive input once per turn. The same approved value can be reused for the same data category and origin within the same user, conversation, turn and desktop. Changed scope, expiry and restarts require a new approval. Writes are bound to the checked field, so page focus handlers cannot redirect the input.
- Personal Boxes and template access. Personal Box provisioning and delivery are integrated with membership checks; template reads and imports respect Box membership.
- Team administration. Directory synchronization, department Box quotas and authenticated first-administrator enrollment have been added.
- Managed skills. Five maintained skill packages cover site playbooks, errands, acting on the user’s behalf, routines and skills, and code work.
Build: afa0f2116299cd300ec8821c68ff0d21675ad087. Includes INV-955 / PR #326 and the changes merged since 0.3.4.
Validation: 2,290 tests and release CI passed; npm run release:check passed against these four installers and the published Docker image. A fresh 0.3.5 Box passed 42/42 smoke checks. Both signed macOS packages passed signature verification, packaged CLI launch and source/build-stamp checks; each ZIP carries all 66 required runtime packages. INV-955 also passed real Chromium tests for approval reuse, scope changes, expired consent, focus redirection and repeated rich-text input. Real-model workflows, live directory-provider integration and clean-machine native UI acceptance were not run for this release.
Downloads: signed macOS ARM64 and Intel DMG/ZIP (not notarized). Docker: fakechris/lumenbox:0.3.5 and latest, linux/arm64. Existing Box containers need recreation to use the new daemon.
LumenBox 0.3.4
LumenBox 0.3.4 makes connected services usable by the default team and makes the record honest about what delegated engines, retries and metering actually did.
- Connected services reach the default team. Tool lists can name an MCP service (
notion__*) or every service the box carries (mcp:*). The starter team and the catalog experts getmcp:*, except the two reviewers. Existing agents are not widened automatically; addmcp:*to one in its settings. - A delegation is done only when the engine says so. Claude Code, pi and opencode now run in their machine-readable modes, and the outcome comes from the engine's own completion report: done, failed, stopped, or unknown. Measured on the pinned versions, pi exits 0 on a provider error and Claude reports a 400 as "success" with
is_error; neither counts as done any more. A thread Claude cannot resume is started fresh, with the reason. - One retry layer. The model SDK no longer retries on its own underneath the host, so every retry is visible and counted once.
- Metering does not record nothing. The relay records a conservative estimate when a provider reports no usage or a stream is cut, counts it against the ceiling, and reports it apart from measured usage.
- Approvals stay on the record. The policy log archives instead of dropping old approvals, and the audit export now carries who asked, who approved or denied, and what delegated engines called.
- Two timing-dependent tests now assert order instead of milliseconds.
Validation: 2241 tests passed; typecheck and lint clean; npm run release:check passed against these artifacts and the published image; npm run smoke passed 42/42 against a fresh box from the 0.3.4 image. The engine outcomes were measured against a stub model server on claude 2.1.250, pi 0.85.1 and opencode 1.18.25; long real-model runs with tool calls were not measured.
Downloads: signed macOS ARM64 and x64 DMG/ZIP (not notarized). Docker: fakechris/lumenbox:0.3.4 and latest, linux/arm64.
LumenBox 0.3.3
LumenBox 0.3.3 reduces idle desktop overhead and adds visibility into box resources.
- Reclaim newly opened, unused desktops after 15 idle minutes. Used, adopted, viewed, pinned, or uncertain sessions stay alive. Files and profiles are preserved.
- Show running, retained and failed desktops, container memory, and a session pin in Settings.
- Avoid orphaned VNC shared memory during reclamation and keep warm readiness checks out of the cold-start queue.
Validation: 2200 tests passed. A 12-agent idle comparison measured 88.54% lower median memory than eager desktop startup. After sustained workload warmup, 100 reclaim cycles passed with 11.1 MiB total memory growth and 2.86-second cold-interaction p95; no orphan IPC accumulation. An earlier cold-cache run exceeded the total-memory bound due primarily to file-cache growth and remains a known measurement limitation.
The eight-hour soak is still running at publication time; this release does not establish absence of a slow memory leak.
Downloads: signed macOS ARM64 and x64 DMG/ZIP (not notarized). Docker: fakechris/lumenbox:0.3.3 and latest, linux/arm64.
LumenBox 0.3.2
Agent desktops now start when you open a desktop or run a GUI tool. Starting the app, reconnecting a box, and ordinary text/file tasks no longer prewarm every agent desktop. Concurrent requests share one startup, with at most two desktop startups in flight.
- Keep hidden desktop panes disconnected until explicitly opened.
- Restore only the requested desktop on HTTP or WebSocket reconnect.
- Hide the GUI shell option from headless side conversations.
Includes signed macOS Apple Silicon and Intel DMG/ZIP installers. macOS notarization was not configured for this build.
Box image: docker.io/fakechris/lumenbox:0.3.2 (linux/arm64), also published as latest.
Digest: sha256:bc6da73665b70c17ebecd89217c7dd75c4693521da560bcee455e864872a1960.
Validation: 2,189 tests passed; CI passed; packaged dependency closure and Docker Hub tag checks passed; isolated real-container smoke: 42 passed, 0 failed. Automatic idle reclamation and long-duration leak verification are not part of this release.
PR: #310
Commit: 5aeb70a8e730de15efab73508d0f49bd3cc1938f
LumenBox 0.3.1 — the first run, unblocked
LumenBox 0.3.1 — the first run, unblocked
Cut on 2026-09-29 from commit 1b5152c (main). This is the release 0.3.0 meant to be:
0.3.0's installers shipped broken and were re-published once already; this one was built
through the release gates that exist because of that incident (docs/27). The drop-in and
bridge are unchanged — fetch them from the 0.3.0 release if you need them.
What changed since 0.3.0
- The first run says what is wrong. The Box section now distinguishes docker is not
installed (it names Docker Desktop and OrbStack, with links), Docker is installed but
not running (start it and press again), and the engine being fine (INV-855, #290). - The first image pull announces itself — roughly 750MB, a few minutes — and a failed
pull says which failure it was: the registry has no such tag (update the app), or the
registry never answered (network; point Settings → Box at a mirror, which is now a
setting —boxImagein config.json) (INV-856, #291). - The setup card asks for the model key first. The welcome note always promised "a
provider with a key and a box"; now the card grades both, and first run shows only
Save & restart, so the first save is one that takes effect (INV-857, #292). - The box image is published per app version (
fakechris/lumenbox:0.3.1) and the app
pulls exactly that tag on first start (#289). - Right-pane display fixes: context and waiting items stay readable (#288).
- Release-side:
release:checknow refuses installers with an incomplete dependency tree
and apps whose image tag is not on Docker Hub (#293). That gate is for us, but it is
why this page's files work.
Install on macOS
Download the disk image for this Mac, open it, drag LumenBox to Applications.
LumenBox-0.3.1-arm64.dmg— Apple SiliconLumenBox-0.3.1-x64.dmg— Intel
The app is signed with an Apple Developer ID certificate but is not notarized.
Gatekeeper will say it cannot be checked. Do one of:
- right-click the app in Applications → Open → Open (once), or
- in Terminal:
xattr -dr com.apple.quarantine /Applications/LumenBox.app
Then it opens normally. It needs a model key (the setup card asks first) and a box:
Docker Desktop or OrbStack on this Mac, Docker on another machine, or a Grok Bot's box
through the bridge. The walkthrough is Getting started.
Coming from broken 0.3.0?
If the app said "The LumenBox server will not stay up" on first launch, your download
predates the 2026-09-29 re-publish — install this 0.3.1 instead. Your ~/.agentbox
settings and keys survive the swap.
LumenBox 0.3.0 — a goal that keeps going
LumenBox 0.3.0 — a goal that keeps going
Cut on 2026-09-28. The tag is 4c6a75e. This release is the desktop app, the drop-in, and the bridge script.
2026-09-29 re-publish. The four app files first published under this release were broken —
they shipped without the bundled node dependencies and crashed on first launch
("The LumenBox server will not stay up"). They have been replaced with a clean rebuild from
commit 203cdb4 (the tag plus the image-pull fix in #285/#286, which the install steps below
depend on). If you downloaded before 2026-09-29 and the app will not start, download again.
The image-pull feature means a fresh machine no longer needs a local image build: pressing
Start the box pulls fakechris/lumenbox:0.3.0 from Docker Hub.
Install on macOS
Download the disk image for this Mac, open it, drag LumenBox to Applications.
LumenBox-0.3.0-arm64.dmg— Apple SiliconLumenBox-0.3.0-x64.dmg— Intel
The app is signed with an Apple Developer ID certificate but is not notarized. Gatekeeper will say it cannot be checked.
Do one of:
- right-click the app in Applications → Open → Open (once), or
- in Terminal:
xattr -dr com.apple.quarantine /Applications/LumenBox.app
Then it opens normally. It needs a model key (Settings asks) and a box: Docker Desktop or
OrbStack on this Mac, Docker on another machine, or a Grok Bot's box through the bridge.
The walkthrough is Getting started.
Windows and Linux installers are not in this release.
What changed since 0.2.1
- A goal the agent pursues.
/goalbeside/new. The host keeps waking while the
conversation is quiet, stops for four reasons, and the only way out is a finish report.
Whether the goal is done is a gate the worker does not grade: a claim, the host's checks,
a verifier that never saw the work. A budget, counted in input-token equivalents, sits on
the board. Silence does not archive a goal. - A turn survives the host dying. A checkpoint is written before a tool call and while an
approval is waiting. After a restart the same turn continues from that step. What already
finished is not run again. - The desktop acts on what it saw. Native actions go through AT-SPI. A target has to match
the observation it was taken from, and a write that does not match is refused. - Memory keeps what the person said. A flush before compaction keeps their words. A
maintenance pass may propose a merge, a retirement, or a rewrite, and the code checks the
proposal before applying it. A credential is refused at every door. Memory derived from a
source can be revoked with that source. - A message that arrives mid-task is its own task. Only a plain continuation steers the
one already running. A reply that was not confirmed as delivered is a failure, not a sent
message. A Feishu reply carries the message it is answering. - The thread is easier to come back to. Unread is per message. A long thread can jump to
a day. An edit is shown as a diff, live and on replay. - A published install refuses plain HTTP. The token key comes from a secret, not from the
directory it protects. A spend ceiling is enforced at the relay, and the box cannot raise it. - Routines can choose not to deliver. Standing files (
AGENTS.md,SOUL.md,USER.md,
HEARTBEAT.md) are injected each turn, and a change is shown as a diff. A skill says when
it applies and when it does not. Standing directories are keyed by the agent, and a
writable mirror is checked again on every sync. - A resumed call is not a free pass. It goes back through the policy gate. Only a call
the executor can safely repeat is replayed. An approval stays open until it is answered. - Silence stays silent on the way out. A deliberate NothingToSay is not rewritten into
a completion line by the channel manager. - A memory rewrite cannot invent a date. A rewrite may only resolve a relative date, and
a retirement has to match the source date. An anchor that says the person said something
needs a person behind it, and a flush that already timed out cannot write afterwards. - The bridge skill keeps Tailscale state across a restart, and the box notes a boot
recovery path for sshd and the bridge's own dependencies. That lives inshare/grok-bridge;
thelumen-bridge.shasset attached here is the installer script, unchanged by that work.
Also in this release
lumen-dropin.tar.gz— the box daemon and its desktop scripts, for a machine that is not
a Docker image of ours.lumen-bridge.sh— the installer a Grok Bot runs from the bridge template, or you run
yourself.
The app still pulls agentbox/box:latest the first time a box starts. That image is not
part of this GitHub release. A box you already have keeps the image it has until you upgrade
it.
Known limits
- macOS only, Apple Silicon and Intel. No Windows or Linux installer.
- Not notarized, and not signed with a Developer ID (see above). Gatekeeper rejects the
signature (spctl: rejected, originLumen Local Codesign). The quarantine command above
is how it opens. - The Docker image is large; the first Start the box takes minutes.
LumenBox 0.2.1 — after the laptop sleeps
LumenBox 0.2.1 — after the laptop sleeps
Found on the first morning after 0.2.0: the laptop slept overnight, the Feishu socket died
but still said "connected", and a message in the group got no reply for fourteen minutes —
until a restart's catch-up replayed it. Three fixes and a diagnosis aid:
- Sweep on wake. When the machine resumes from sleep, the app asks the server to check every
chat channel against the vendor's message history at once; the periodic sweep now runs every
five minutes instead of ten. - A server log on disk.
~/Library/Logs/LumenBox/server.log(rotated at 5 MB). Until now a
Finder-launched app's server output went nowhere, and there was nothing to read. - Docker errors say why. A silent
docker inspectfailure now carries the exit code and
the head of the PATH it ran under. - The catch-up says what it did. Every quiet exit has a reason in the log, and one line
says how many chats, threads and messages a sweep looked at.
Same install notes as 0.2.0: Apple Silicon, signed but not notarized — right-click → Open
once, or xattr -dr com.apple.quarantine /Applications/LumenBox.app.
One thing that is not a bug but looks like one: a reply to a message in a Feishu group lands
in a thread under that message, collapsed until you open it. If the bot seems silent, open
the message's thread first.
LumenBox 0.2.0 — the first release for anyone
LumenBox 0.2.0 — the first release for anyone
The first build meant for a person who has never seen the project: a macOS app, a getting-started
guide, and a way to bring a box of your own.
Install on macOS
Download LumenBox-0.2.0-arm64.dmg (Apple Silicon), open it, drag LumenBox to Applications. An
Intel build is not in this release: the toolchain's download of the Intel runtime kept aborting on
the release machine; it follows as 0.2.1 when it builds.
The app is signed with a Developer ID but not notarized. Gatekeeper will say it cannot be
checked. Do one of:
- right-click the app in Applications → Open → Open (once), or
- in Terminal:
xattr -dr com.apple.quarantine /Applications/LumenBox.app
Then it opens normally. It needs a model key (Settings asks) and a box: Docker Desktop or
OrbStack on this Mac, Docker on another machine, or a Grok Bot's box through the
LumenBox Bridge template. Everything is in
Getting started.
What is in it
- A team of agents with their own desktops, browsers and shells in one Linux box; watch and
take over any desktop. - Feishu and DingTalk as chat surfaces, with cards, files and button approvals.
- Memory in plain files; skills in
SKILL.mdfolders; bot templates that pack and share. - The turn engine minds the person: the opening line reaches the chat while tools run, read-only
tools run in parallel, a verdict from memory is sent back to check. - Forks and delegated jobs survive a restart; delegated engines can be lent host MCP tools
without a credential entering the box; hot-reloadable extensions. - Launch at login.
Also in this release
lumen-dropin.tar.gz— the box daemon and its desktop scripts, for a box that is not a Docker
container of ours (a Grok Bot's VM, any Linux machine).lumen-bridge.sh— the installer a Grok Bot runs from the Bridge template, or you run yourself.
Known limits
- Apple Silicon macOS only in this release; Intel next, Windows and Linux builds are unproduced.
- Not notarized (see above).
- The Docker box image is pulled on first start and is large; the first Start the box takes minutes.
LumenBox drop-in for Grok Bot boxes (2026-09-03)
The box daemon plus lumen-bridge.sh, the in-box installer a Grok Bot runs from the LumenBox Bridge skill (docs/35). Unpacks under ~/.lumen, starts a desktop of its own at :10 and the daemon on the box's tailnet address; nothing of the host bot's is touched.