Releases: hieuphung97/dely
Release list
v0.23.0
Dely 0.23.0 adds Pi as a harness, supports GitHub Copilot CLI, Antigravity CLI and Grok Build, and shows in README which harness can take which role.
- Choose a harness for each role. README has a harness × role table (Control, implementer, reviewer) with ✓ / ⚠ / ✗ marks and short caveats. The rows are derived from
harnesses.json(status,controlWake, and role-prefixedlimits), and a closure gate fails if README drifts from the data.setupprints each harness's caveats when it offers it. - Install Dely only in the harness you use as Control. Workers need Orca and their own login. A pinned OMP or Pi worker also needs that harness's Dely install, which loads
extensions/dely-pin.ts. - Pi works as a worker and as Control. It shares OMP's package and pin extension; its pin is a spec line that Orca cannot confirm, so check the model in Pi's session log.
- Copilot, Antigravity and Grok are supported, each with stated limits (Copilot's first-launch app prompt and folder trust; Antigravity's first launch on a new folder; Grok's per-project trust and free-tier usage limit). Kiro stays unsupported.
- Helper:
- it ignores messages Orca rejected;
dely wait/wait-bgtake--ack <deliveryId>(Orca's one-call form);- it stops with
ERRORwhen run outside an Orca terminal; - it appends hints to two common Orca errors;
--reporesolves to an absolute path.
- Pin extension: it fails closed on an unparseable
dely-pin:line or a throwingsetModel. - Checklist: live rows run by what changed, with an argv stub row that compares launches against the previous release.
Known limits:
- OMP 18.4 workers do not start under Orca 1.4.217 or later until stablyai/orca#24068 is fixed.
- Codex 0.159.2 workers need Orca 1.4.217 or later.
Decision records: docs/decisions.md, sections 2026-09-28, 2026-09-30 and 2026-10-01.
Full Changelog: v0.22.0...v0.23.0
v0.22.0
Dely 0.22.0 supports OMP (Oh My Pi) as a harness, as a worker and as Control.
harnesses.jsonhas a supportedompentry. Control wakes bywaker, and models and effort levels are discovered fromomp models --json.- Orca does not yet accept
worker-start --modelforomp(stablyai/orca#23388). Until it does, a pin travels as adely-pin: <selector> [effort]spec line, applied by the shipped extensionomp/dely-pin.tsbefore the first request. After the worker acknowledges,dely dispatchchecks the model Orca reports and fails withFAILED … pin not appliedon a mismatch. A pin OMP cannot resolve stops the worker before any request and surfaces asNO_ACK. - For Claude Code, Codex CLI and Cursor Agent CLI,
worker-startargv, spec and output are unchanged from 0.20.1. - OMP installs from a dedicated clone with
omp plugin install <clone>; see README. It has no workspace-trust gate, and its approvals followtools.approvalMode. - Closure gates now cover the root
package.json. The live release floor is ten rows.
Version note: the v0.21.1 release points at code whose manifests say 0.20.1. This release's manifests say 0.22.0.
Decision record: docs/decisions.md, "2026-09-27 — OMP is a supported harness, and its model pin travels in the spec".
Full Changelog: v0.21.1...v0.22.0
v0.21.1
What's Changed
- Control learns helper usage from dely; checklist checks the waker path by event order (0.20.1) by @hieuphung97 in #58
- Run live verification before review and record the review-round cost by @hieuphung97 in #59
Full Changelog: v0.20.0...v0.21.1
v0.20.0
What's Changed
- Pin review to Codex CLI gpt-5.6-sol by @hieuphung97 in #52
- Rewrite README as a newcomer how-to by @hieuphung97 in #53
- Play the Dely demo inline on the GitHub README by @hieuphung97 in #54
- Retire the structural suite and narrow Dely to the harnesses it can support (0.19.0) by @hieuphung97 in #55
- Move harness facts to harnesses.json, cut the skill to protocol, and make the log machine-readable (0.20.0) by @hieuphung97 in #57
Full Changelog: v0.17.8...v0.20.0
v0.17.8
A controlled probe confirmed 0.17.7 works on its target. Under the previous
release a coordinator wrote into its reviewer's prompt: "If the implementation
meets the requirement and the instrument passes, return role disposition ACCEPT."
Under 0.17.7, with the same coordinator, the same brief and the same task, it
wrote only: "Return exactly one role disposition: ACCEPT or CHANGES_REQUESTED" —
the protocol's own phrasing, relayed rather than invented.
One observation, one harness, a nondeterministic model. A signal, not a proof.
The defect underneath
With the coordinator no longer overriding the contract outright, a second defect
became visible: it relayed the counterexample and corrupted it.
The source required the instrument to reject an implementation producing an
unpadded value. The coordinator wrote that the script must reject that value as
input. The implementer then reasoned about its own code rather than observing
anything, and the reviewer "verified" by passing the value as an argument and
seeing an arithmetic error — a property of the shell, not of the candidate — and
accepted.
The failure had moved from omission to corruption. It was invisible while the
larger defect masked it.
Why it is specific to the smaller shape
An implementer reads the decision record, the plan and the baseline. Where the
design contract is a committed artefact, the acceptance table is a file the worker
reads and the coordinator relays nothing. Where the design is approved in
conversation, the row is real but not durable, and must pass through the
coordinator's prose.
What changed
One sentence: where the design contract states an acceptance row — its instrument,
its counterexample, and what was observed — the prompt carries that row as written
rather than a restatement of it.
The contract check binds it to the section a coordinator reads while composing a
prompt, as it already does for the disposition rule; relocating the paragraph fails
the suite.
The obvious objection was that the rule is conditioned on an acceptance row that
in-conversation designs might not have. Review settled it on the text: the
acceptance contract is unscoped and requires one table, so a design without a row
is already non-conforming rather than a case the rule silently declines to cover.
What this does not do
Nothing observes a coordinator writing a prompt. Only a further probe tests this,
and one probe is one observation. The decision record says so rather than implying
otherwise.
v0.17.7
A controlled probe repeated an earlier harness round against the current protocol —
same configuration, same brief, same task, one variable changed. The reviewer
accepted a change whose counterexample had never been observed: the same failure
three earlier releases had each been written to close.
The reviewer was not at fault. Its coordinator's dispatch prompt told it that if
the instrument passes, return ACCEPT — an acceptance criterion the coordinator
invented, contradicting the protocol. The reviewer complied with what it was given.
Measured before changing anything
A Spike measured what actually reaches a dispatched worker.
The execution plane's injected preamble has exactly three sections, all authored by
the plane, with no slot this protocol or a project can extend. The only
project-controlled content is the prompt the coordinator writes.
Separately, four harnesses were each asked for a token planted in AGENTS.md,
under instructions not to read, open, search or grep any file. All four returned
it. AGENTS.md auto-loads into a dispatched worker's context; the skill does not.
Those are the only two routes to a worker, and this change takes neither.
What changed
Two sentences in the worker-launch section: the dispatch prompt carries the task,
its scope and the evidence required, and does not define the role dispositions or
the conditions for reaching one.
The review section is byte-identical to the previous release. Three releases have
edited it to fix this; this one does not.
The distinction is addressee, not readership. The review section was in the
coordinator's context on all three prior attempts, since the skill loads in full.
What changed is that those regulated the reviewer while the observed failure was
the coordinator — and a dispatched reviewer may not have the skill loaded at all,
so that section could not have reached it in any case.
The check binds placement
The first version of the contract check searched the whole file, so the sentences
could be moved verbatim into an unrelated section with everything still green —
though placement is the entire claim, since the rule exists to be met while a
prompt is being composed. The check now extracts the section and asserts the
sentences are inside it.
What this does not do
Nothing here observes a coordinator writing a prompt. This change is not verified
by its own delivery; only a further probe tests it, and the decision record says so
rather than implying otherwise.
v0.17.6
Three releases required the reviewer to locate the counterexample's red run in the
implementer's dispatch record, adding escape branches when that proved impossible.
A Spike measured the lookup instead of extending it again.
What was measured
worker-read across ten settled dispatches returns one of two shapes. One harness
gives a bounded terminal window — 120 lines, truncated, with no cursor to page
backwards. Another gives a transcript, warning that older messages were omitted.
Searching an implementer's retained window for its own evidence found the fixture
command 0 times and the failing output 0 times. Those lines are the
worker's closing summary, not the middle of the session where the counterexample
ran. Where that harness is pinned for implementation, the record structurally
cannot hold the red run.
Across the five reviews written under the rule, none located it. All five
reproduced the counterexample themselves.
What changed
The lookup is deleted with both escapes. The surviving obligation joins the rule
it always belonged to: the reviewer observes the counterexample discriminate for
itself, and an instrument red only because the behaviour was absent is not that
observation.
Review's opening no longer describes worker-read; the evidence and handoff
sections already carry that machinery. Removing the dependency on plane retention
also removes the need for a third branch that had been queued.
The ## Review section falls from 353 words to 206. It remains 26 words larger
than before the lookup existed — a reduction against the peak, not a return to the
starting point.
What this does not do
It does not make a reviewer look. Nothing in the repository observes that. A later
controlled probe confirmed the limit is sharper still: a dispatched worker reads
the task spec its coordinator writes, not this protocol, so a rule placed here
reaches the role it governs only when the coordinator relays it.
v0.17.5
0.17.3 required a disposition to wait until the reviewer had located the
counterexample's red run in the implementer's dispatch record, with an escape for
a record the execution plane cannot recover.
A delivery then hit a case that escape does not cover: the record was recoverable
and the red run was unproducible, because the error under test is returned only
to a coordinator. A dispatched worker attempting the same call hits a role fence
that fires before the condition is evaluated at all. The clause never fired, and a
literal reading left the disposition unreachable although nobody had erred.
What changed
The escape branches on authority as well as recoverability. Where the
implementer had no authority to produce the counterexample, locating that run in
its record is not required — but the observation is valid only when a role that
does have that authority recorded it as that role's observation. The reviewer
verifies what its own seat reaches and records the remainder as not verified.
It relieves only the location of the run, never the observation: an implementer
claiming it must produce a harder artifact, not skip a step.
Superseded
0.17.6 deletes this clause and its branches entirely, after measurement showed
the lookup they were rescuing had never once succeeded. This release is the last
state before that deletion.
v0.17.4
Three places where the protocol asserted more than anyone had observed. All three
were found by running the tool rather than reading it, and one of them shipped in
0.17.3 earlier the same day.
What changed
worker-read does not always give a typed reason. The text promised bounded
terminal output "with a typed fallbackReason". Observed: sometimes
session_not_reported, sometimes null. This mattered because 0.17.3 had just
made the reviewer responsible for saying why a dispatch record could not be
recovered — and a reviewer promised a typed reason has nothing to write when the
field is absent.
A dispatched receipt is not evidence of life. The protocol covered one
direction, that a failed receipt is not evidence a worker is progressing, and
omitted the converse. A worker's turn ended on a harness spend limit; the dispatch
stayed dispatched, the worker read ready, no heartbeat ever arrived, and retry
was refused as task_not_startable.
Reproducing it produced a stronger rule than the incident. A retry against a
dispatch whose worker was alive and progressing is refused identically — so the
refusal is not about the worker's state at all. Retry is refused while the plane
still considers the dispatch live, whether or not the worker still is; the live
terminal is re-engaged instead.
A two-half repair was documented as one half. The Cursor marketplace refresh
needs Uninstall from the Installed tab then install from the Marketplace
tab, and the same section already noted that removing a marketplace leaves the
plugin installed.
How it was verified
The counterexample for the first item is the protocol text of 0.17.3 itself. It
parses, that release's own contract script is green on it, and a keyword check for
fallbackReason passes on it — present, running, returning a pass, and asserting
what the execution plane contradicts. The verbatim pin separates the two releases;
a keyword check does not.
A limit recorded rather than hidden
One correction rests on a single observation that only a coordinator can make: the
error belongs to a role that dispatched workers do not hold, and a worker attempting
it hits a role fence that fires before liveness is evaluated. The review recorded
this as an explicit non-verification rather than letting its own inability to reach
the error read as agreement.
That also exposed a gap in the rule shipped in 0.17.3, which branches on whether
a record can be recovered. Here the record was recoverable and the red run was
unproducible, so the clause never fires. It is recorded and gets its own change.
v0.17.3
A harness-matrix probe ran a full Bounded delivery across three coding agents.
The implementer used its instrument's failure against an absent feature as the
baseline — which the protocol says in as many words does not count — and neither
the control session nor the reviewer caught it. The reviewer accepted.
None of the three broke a rule. The rules did not join up: the obligation sat
entirely on the implementer as prose in a handoff field nothing could check,
review received dispatch evidence passively, and "Reproduce, do not accept" was
scoped to gates.
What changed
The reviewer now reads the implementer's dispatch record itself rather than being
handed a summary of it, and a disposition is not reachable until it has located,
in that record, the run where the counterexample was observed red. An instrument
red because the behaviour was absent is not that run. Where the execution plane
cannot recover the record, the reviewer says so with the reason the plane gave,
and the counterexample rests on the implementer's account rather than on evidence.
No new mechanism was introduced. worker-read already returns the hook-reported
transcript when the session can be proven, with a typed fallback reason otherwise;
the change is which role goes and fetches it.
How this one was verified
The new text is pinned verbatim in the contract script. The counterexample is a
weakened variant of the sentence itself — "should read the dispatch record" —
which keeps every distinctive keyword, passes plausible keyword checks, and fails
the pin. Deleting the paragraph outright also passes those keyword checks, so the
absence of the text is provably not the discriminator.
What this does not do
The pin stops the sentence being silently weakened later. It cannot make a future
reviewer look. No instrument available in the repository can observe that, and the
decision record says so rather than implying otherwise.
Also
The contract script's line ceiling rises from 250 to 280 to make room for the pin;
the script is now 260 lines. The ceiling exists to stop that script becoming a test
suite, and raising it deliberately keeps that intent.