Repository navigation
LumenBox 0.3.0 — a goal that keeps going
LumenBox 0.3.0 — a goal that keeps going
Cut on 2026-09-28. The tag is 4c6a75e. This release is the desktop app, the drop-in, and the bridge script.
2026-09-29 re-publish. The four app files first published under this release were broken —
they shipped without the bundled node dependencies and crashed on first launch
("The LumenBox server will not stay up"). They have been replaced with a clean rebuild from
commit 203cdb4 (the tag plus the image-pull fix in #285/#286, which the install steps below
depend on). If you downloaded before 2026-09-29 and the app will not start, download again.
The image-pull feature means a fresh machine no longer needs a local image build: pressing
Start the box pulls fakechris/lumenbox:0.3.0 from Docker Hub.
Install on macOS
Download the disk image for this Mac, open it, drag LumenBox to Applications.
LumenBox-0.3.0-arm64.dmg— Apple SiliconLumenBox-0.3.0-x64.dmg— Intel
The app is signed with an Apple Developer ID certificate but is not notarized. Gatekeeper will say it cannot be checked.
Do one of:
- right-click the app in Applications → Open → Open (once), or
- in Terminal:
xattr -dr com.apple.quarantine /Applications/LumenBox.app
Then it opens normally. It needs a model key (Settings asks) and a box: Docker Desktop or
OrbStack on this Mac, Docker on another machine, or a Grok Bot's box through the bridge.
The walkthrough is Getting started.
Windows and Linux installers are not in this release.
What changed since 0.2.1
- A goal the agent pursues.
/goalbeside/new. The host keeps waking while the
conversation is quiet, stops for four reasons, and the only way out is a finish report.
Whether the goal is done is a gate the worker does not grade: a claim, the host's checks,
a verifier that never saw the work. A budget, counted in input-token equivalents, sits on
the board. Silence does not archive a goal. - A turn survives the host dying. A checkpoint is written before a tool call and while an
approval is waiting. After a restart the same turn continues from that step. What already
finished is not run again. - The desktop acts on what it saw. Native actions go through AT-SPI. A target has to match
the observation it was taken from, and a write that does not match is refused. - Memory keeps what the person said. A flush before compaction keeps their words. A
maintenance pass may propose a merge, a retirement, or a rewrite, and the code checks the
proposal before applying it. A credential is refused at every door. Memory derived from a
source can be revoked with that source. - A message that arrives mid-task is its own task. Only a plain continuation steers the
one already running. A reply that was not confirmed as delivered is a failure, not a sent
message. A Feishu reply carries the message it is answering. - The thread is easier to come back to. Unread is per message. A long thread can jump to
a day. An edit is shown as a diff, live and on replay. - A published install refuses plain HTTP. The token key comes from a secret, not from the
directory it protects. A spend ceiling is enforced at the relay, and the box cannot raise it. - Routines can choose not to deliver. Standing files (
AGENTS.md,SOUL.md,USER.md,
HEARTBEAT.md) are injected each turn, and a change is shown as a diff. A skill says when
it applies and when it does not. Standing directories are keyed by the agent, and a
writable mirror is checked again on every sync. - A resumed call is not a free pass. It goes back through the policy gate. Only a call
the executor can safely repeat is replayed. An approval stays open until it is answered. - Silence stays silent on the way out. A deliberate NothingToSay is not rewritten into
a completion line by the channel manager. - A memory rewrite cannot invent a date. A rewrite may only resolve a relative date, and
a retirement has to match the source date. An anchor that says the person said something
needs a person behind it, and a flush that already timed out cannot write afterwards. - The bridge skill keeps Tailscale state across a restart, and the box notes a boot
recovery path for sshd and the bridge's own dependencies. That lives inshare/grok-bridge;
thelumen-bridge.shasset attached here is the installer script, unchanged by that work.
Also in this release
lumen-dropin.tar.gz— the box daemon and its desktop scripts, for a machine that is not
a Docker image of ours.lumen-bridge.sh— the installer a Grok Bot runs from the bridge template, or you run
yourself.
The app still pulls agentbox/box:latest the first time a box starts. That image is not
part of this GitHub release. A box you already have keeps the image it has until you upgrade
it.
Known limits
- macOS only, Apple Silicon and Intel. No Windows or Linux installer.
- Not notarized, and not signed with a Developer ID (see above). Gatekeeper rejects the
signature (spctl: rejected, originLumen Local Codesign). The quarantine command above
is how it opens. - The Docker image is large; the first Start the box takes minutes.