Skip to content

LumenBox 0.3.0 — a goal that keeps going

Choose a tag to compare

@fakechris fakechris released this 28 Sep 08:29
4c6a75e

LumenBox 0.3.0 — a goal that keeps going

Cut on 2026-09-28. The tag is 4c6a75e. This release is the desktop app, the drop-in, and the bridge script.

2026-09-29 re-publish. The four app files first published under this release were broken —
they shipped without the bundled node dependencies and crashed on first launch
("The LumenBox server will not stay up"). They have been replaced with a clean rebuild from
commit 203cdb4 (the tag plus the image-pull fix in #285/#286, which the install steps below
depend on). If you downloaded before 2026-09-29 and the app will not start, download again.

The image-pull feature means a fresh machine no longer needs a local image build: pressing
Start the box pulls fakechris/lumenbox:0.3.0 from Docker Hub.

Install on macOS

Download the disk image for this Mac, open it, drag LumenBox to Applications.

  • LumenBox-0.3.0-arm64.dmg — Apple Silicon
  • LumenBox-0.3.0-x64.dmg — Intel

The app is signed with an Apple Developer ID certificate but is not notarized. Gatekeeper will say it cannot be checked.
Do one of:

  • right-click the app in Applications → Open → Open (once), or
  • in Terminal: xattr -dr com.apple.quarantine /Applications/LumenBox.app

Then it opens normally. It needs a model key (Settings asks) and a box: Docker Desktop or
OrbStack on this Mac, Docker on another machine, or a Grok Bot's box through the bridge.
The walkthrough is Getting started.

Windows and Linux installers are not in this release.

What changed since 0.2.1

  • A goal the agent pursues. /goal beside /new. The host keeps waking while the
    conversation is quiet, stops for four reasons, and the only way out is a finish report.
    Whether the goal is done is a gate the worker does not grade: a claim, the host's checks,
    a verifier that never saw the work. A budget, counted in input-token equivalents, sits on
    the board. Silence does not archive a goal.
  • A turn survives the host dying. A checkpoint is written before a tool call and while an
    approval is waiting. After a restart the same turn continues from that step. What already
    finished is not run again.
  • The desktop acts on what it saw. Native actions go through AT-SPI. A target has to match
    the observation it was taken from, and a write that does not match is refused.
  • Memory keeps what the person said. A flush before compaction keeps their words. A
    maintenance pass may propose a merge, a retirement, or a rewrite, and the code checks the
    proposal before applying it. A credential is refused at every door. Memory derived from a
    source can be revoked with that source.
  • A message that arrives mid-task is its own task. Only a plain continuation steers the
    one already running. A reply that was not confirmed as delivered is a failure, not a sent
    message. A Feishu reply carries the message it is answering.
  • The thread is easier to come back to. Unread is per message. A long thread can jump to
    a day. An edit is shown as a diff, live and on replay.
  • A published install refuses plain HTTP. The token key comes from a secret, not from the
    directory it protects. A spend ceiling is enforced at the relay, and the box cannot raise it.
  • Routines can choose not to deliver. Standing files (AGENTS.md, SOUL.md, USER.md,
    HEARTBEAT.md) are injected each turn, and a change is shown as a diff. A skill says when
    it applies and when it does not. Standing directories are keyed by the agent, and a
    writable mirror is checked again on every sync.
  • A resumed call is not a free pass. It goes back through the policy gate. Only a call
    the executor can safely repeat is replayed. An approval stays open until it is answered.
  • Silence stays silent on the way out. A deliberate NothingToSay is not rewritten into
    a completion line by the channel manager.
  • A memory rewrite cannot invent a date. A rewrite may only resolve a relative date, and
    a retirement has to match the source date. An anchor that says the person said something
    needs a person behind it, and a flush that already timed out cannot write afterwards.
  • The bridge skill keeps Tailscale state across a restart, and the box notes a boot
    recovery path for sshd and the bridge's own dependencies. That lives in share/grok-bridge;
    the lumen-bridge.sh asset attached here is the installer script, unchanged by that work.

Also in this release

  • lumen-dropin.tar.gz — the box daemon and its desktop scripts, for a machine that is not
    a Docker image of ours.
  • lumen-bridge.sh — the installer a Grok Bot runs from the bridge template, or you run
    yourself.

The app still pulls agentbox/box:latest the first time a box starts. That image is not
part of this GitHub release. A box you already have keeps the image it has until you upgrade
it.

Known limits

  • macOS only, Apple Silicon and Intel. No Windows or Linux installer.
  • Not notarized, and not signed with a Developer ID (see above). Gatekeeper rejects the
    signature (spctl: rejected, origin Lumen Local Codesign). The quarantine command above
    is how it opens.
  • The Docker image is large; the first Start the box takes minutes.