Releases: hraness/desktop-foundation
Release list
desktop-foundation v2.0.0
All on-screen UI is gone. There is no terminal UI, no native notice or
prompt dialog, and no dialog capability probe. Products present everything
in the terminal they already own (status --json for scripts, prePrompt
and renderRecovery for people), and hraness-helper exists only to
assemble, sign and launch the macOS local app. The headless control kit —
registry, owner sockets, human gate, audience, permissions, login items and
retirement — is unchanged. Every product pins an exact release, so nothing
changes until a product bumps.
Changes
- Removed the
./tuiSDK subpath and thehraness-control-kittui
feature, with their ratatui, crossterm and ratatui-textarea
dependencies.runTuiandrenderSnapshotare gone;<product> status --jsonis the view for scripts and the basis for any product's
own terminal listing. - Removed the native dialog helper modes.
--notice,--promptand
--prompt-probenow answerinvalid-arguments(exit 1) like any unknown
argv, andcontract/helper-argv.v0.8.1.jsonpins exactly that. This drops
the GTK 3 dependency on Linux, the AppKit dialogs on macOS and the Win32
dialog on Windows, and with them theobjc2,windowsandzeroize
dependency trees. - Removed the SDK dialog surface:
sdk/src/notice.ts,
sdk/src/prompt.tsandsdk/src/tui.tsare deleted, including
promptNative,promptTui,promptCapability,promptSecret,
permissionNoticeRequest,NoticeRequest,NoticeResult,
PermissionNoticeRequestand the injectablenoticehook on the
permission renderer. Surface/Surface::Dialogis gone.renderPrePromptand
renderRecoveryare terminal-only:renderPrePrompt(need, env)and
renderRecovery(need, state, env)in TypeScript, and the same signatures
without a surface argument in Rust.- Removed
scripts/prompt-smoke.mjsand the dialog-capability check in
CI, plus the orphanedtui-statusgoldens undersdk/test/golden/and
crates/hraness-control-kit/tests/golden/. - Unchanged:
hraness-helperkeeps--version,--assemble-app,
--signing-identityand--launch, so the macOS local app and Ghostget's
Safe Storage cookie reader keep working.hraness-companionremains an
alias that prints byte-identical output for the retained modes and still
refuses the 0.x menu bar argv with exit 2 andtray-removed; the stderr
line now points to<product> status --json.packagedManifest,
resolveHelperand every other SDK subpath (./audience,./cli-style,
./control,./helper,./human-gate,./login,./permissions,
./registry,./retire) keep their APIs. Terminal permission copy,
settings links, permission probes, JSON error envelopes and the shared
golden files are unchanged; the golden files now cover terminal output
only.
Install
npm install https://github.com/hraness/desktop-foundation/releases/download/v2.0.0/hraness-desktop-foundation-2.0.0.tgzRust products pin the tag: desktop-foundation = { git = "https://github.com/hraness/desktop-foundation", tag = "v2.0.0" }.
Verify
Checksums for every asset are in SHA256SUMS. The source commit is 798be31fca87bbe9195e351cdf358c4d14eb42d4. Each asset has a GitHub build attestation: gh attestation verify <file> --repo hraness/desktop-foundation. See the installation guide.
desktop-foundation v1.1.2
The Rust CLI kit can now be published separately to crates.io. Its runtime API
and behavior are unchanged from 1.1.1.
Changes
- Made
hraness-cli-kitpublishable with its source, README, and MIT license. - Added crates.io trusted publishing after the existing release checks. It
stays disabled until the first publication and registry setup are complete;
later releases use GitHub OIDC without a stored token or human approval.
Install
npm install https://github.com/hraness/desktop-foundation/releases/download/v1.1.2/hraness-desktop-foundation-1.1.2.tgzRust products pin the tag: desktop-foundation = { git = "https://github.com/hraness/desktop-foundation", tag = "v1.1.2" }.
Verify
Checksums for every asset are in SHA256SUMS. The source commit is c6003c05a86ab9a188b8bc20dd4de5fe459affab. Each asset has a GitHub build attestation: gh attestation verify <file> --repo hraness/desktop-foundation. See the installation guide.
desktop-foundation v1.1.1
Fixes from the review of 1.1.0. Exit codes, schema ids, error codes and the envelope shape are unchanged. Some behaviour, message text and helper signatures did change, and every change is listed below.
Changes
helpis a command only as the first word (after--jsonat most). In 1.1.0runCliremoved the firsthelpanywhere in the command line, soapprovals decide a1 --digest help denylost its--digestvalue, and-- helpprinted help. Now a flag's value and every word after--are left alone.--debugworks likeHRANESS_DEBUG=1, asCLI_MENU_STYLE.mdD5 says: a text error adds the code and detail.runClitakes--debug(before any--) out of the command line, unless one of the product's verbs declares its owndebugflag, in which case it stays that verb's flag and the other verbs reject it as before. 1.1.0 answered--debugwith an unknown-option error.- An undeclared code no longer shows its code to a person. The
internalerror readsThe command failed with an error it did not declare., and the code moved todetailasUndeclared code <code>., which text mode shows only with--debugorHRANESS_DEBUG=1. In 1.1.0 the message wasThe command answered an undeclared code <code>.This changes--jsonerror.messageand addserror.detail. - A wrong or expired code points at the same command.
gate-failedandgate-expiredfromrunClinow have onenextstep for a person, the same command again, so the→line re-runs it. In 1.1.0 they had nonext, and the→line pointed at--help. This addserror.nextto those--jsonenvelopes. T3unsupported-platformstill points at--help, since running it again cannot succeed in this release. help commands --jsonlists one descriptor forcommandsindata.verbsinstead of an empty list.error.permissionis built the same way by both kits. In 1.1.0 TypeScript kept only the known System Settings panes, while Rust kept anyx-apple.systempreferences:link.- Both now keep only the twelve panes in
contract/names.jsonsettingsUrls. Rust exports them asSETTINGS_URLS. - Both leave
permissionout for a kind outside^[a-z][a-z0-9-]*$(validPermissionKind,valid_permission_kind). contract/golden/error-permission-cases.jsonchecks that both kits print the same bytes.errorPermissionnow returnsErrorPermission | undefined. TypeScript code that assigns its result to anErrorPermissionmust handleundefined.- Rust
ErrorPermission::with_settings_urldrops a link that is not one of the twelve panes, andErrorBody::with_permissiondrops a permission with an invalid kind. - The Rust reader now rejects a
permissionwhose kind or link the schema rejects. 1.1.0 accepted it. permissionErrorJsonkeeps its 1.0 shape. Itserror.permissionis now tested to hold the same kind and link aserrorPermissionand to pass the schema.
- Both now keep only the twelve panes in
- Documented from 1.1.0: an agent that runs a
decideverb without--jsongetshuman-required(exit 3) and no prompt. In 1.0 only--jsondid that, and an agent without it was prompted at/dev/tty. The 1.1.0 notes left this out. A person who wants to decide runs the command at their own terminal, as thenextstep says.
Install
npm install https://github.com/hraness/desktop-foundation/releases/download/v1.1.1/hraness-desktop-foundation-1.1.1.tgzRust products pin the tag: desktop-foundation = { git = "https://github.com/hraness/desktop-foundation", tag = "v1.1.1" }.
Verify
Checksums for every asset are in SHA256SUMS. The source commit is 5a76ba99a90c5754be50244c7d0ef8a9b4120f9b. Each asset has a GitHub build attestation: gh attestation verify <file> --repo hraness/desktop-foundation. See the installation guide.
desktop-foundation v1.1.0
Command-line errors and help from ./registry now follow CLI_MENU_STYLE.md, agents get JSON without asking for it, and an error can name the macOS permission behind it. Exit codes, schema ids, error codes, the envelope shape and the order of next are unchanged. Some message text did change, and every change is listed below.
Changes
- A person at a terminal sees a text error as two lines on stderr:
✗and one sentence, then→and the one command to run next (FAILand->without UTF-8). A mistyped command addsDid you mean "status"?, andHRANESS_DEBUG=1adds the error code. - Help starts with
Usage:. It says in plain words when a person has to decide, instead of the[decide T1T2]tags.<product> help <command>works like<command> --help, andhelp helpprints the root help. User-facing text no longer says "gate". - When
detectAudiencereports an agent,runCliprints the JSON envelope even without--json. Raw verbs still see only the--jsonthe caller passed. - A single-dash option such as
-x, before or after the command, is a usage error (exit 2), and the command does not run. In 1.0 it reached the verb as a word. After--, and for a bare-or-5, it is still a word. error.permissionis new and optional:{ kind, settingsUrl }, the macOS permission behind the failure and the System Settings pane that fixes it.- It is in
contract/envelope.schema.json, the TypeScriptErrorBodyandHranessError, and the RustErrorBody. - New helpers:
errorPermission(kind, settingsUrl)in TypeScript, andErrorPermission::new(kind).with_settings_url(url)withErrorBody::with_permissionin Rust. Both drop a link outside System Settings; TypeScript also keeps only the known panes, and Rust checks thex-apple.systempreferences:prefix. permissionErrorJsonkeeps its 1.0 shape.
- It is in
- Scripts (the quiet audience: no terminal, no agent) get what 1.0 gave them. A failure still prints the error envelope on stdout. The stderr line carries
code: messageafter a plainFAIL, in ASCII whatever the locale:FAIL usage: Unknown command "x".then-> example --help. A grep anchored at the line start (^human-required:) must allow for theFAILprefix. The 1.0next:lines are gone. --jsonoutput has the same shape, with these message changes:- An unknown command reads
Unknown command "x".instead ofUnknown command: x., addsDid you mean …?when there is a close match, and has twonextsteps (agent first, as before, then<product> --helpfor a person). Name a command after "approvals".is new for a group name typed with no command after it.- Unknown options read
Unknown option "--x" for "example status", so nothing ran., and a malformed one readsUnknown option "--Bad", so nothing ran. Put options after "example status".uses quotes instead of backticks.- Messages that ended with "… . Nothing changed." now end with ", so nothing changed." This covers
human-required,gate-failed,gate-expiredand T3unsupported-platform, in TypeScript and Rust. The T3 message now readsDeciding with your macOS login is not supported yet, so nothing changed. - An undeclared code reads
The command answered an undeclared code …instead ofThe verb answered …. - Match on
error.code, never on message text.
- An unknown command reads
commandstext output is aUsage:line and aCommandslist without class tags. It is no longer one bare line per verb. Scripts should readcommands --json.- 1.0 readers reject
error.permission. The 1.0 schema'serrorhasadditionalProperties: false, and the 1.0 RustErrorBodydenies unknown fields. An envelope without it is byte-identical to 1.0. Set it only when every reader is on 1.1. - Rust
ErrorBodyhas a new public field,permission. Code that buildsErrorBodywith a struct literal, or destructures it without.., must add the field or useErrorBody::new. No Hraness repository does either.
Install
npm install https://github.com/hraness/desktop-foundation/releases/download/v1.1.0/hraness-desktop-foundation-1.1.0.tgzRust products pin the tag: desktop-foundation = { git = "https://github.com/hraness/desktop-foundation", tag = "v1.1.0" }.
Verify
Checksums for every asset are in SHA256SUMS. The source commit is 5e9202c664a79f618da6a39314ff63ac1272724c. Each asset has a GitHub build attestation: gh attestation verify <file> --repo hraness/desktop-foundation. See the installation guide.
desktop-foundation v1.0.0
The menu bar is gone. Products run through the owner process, status --json, tui and the verbs that 0.9 added; hraness-helper handles the few things a terminal cannot. Every product already moved off the tray, and each pins an exact release, so nothing changes until a product bumps. See docs/migration-1.0.md.
Changes
- Removed the tray runner.
hraness-companionis now an alias ofhraness-helper: for--version,--prompt-probe,--assemble-app,--signing-identity,--launch,--noticeand--promptit prints the same bytes and exits with the same status (only--versionnames the binary), checked againstcontract/helper-argv.v0.8.1.jsonand the newcontract/companion-alias.v1.json. Local apps assembled from the companion, including Ghostget's Safe Storage cookie reader, keep working. - Given the old menu bar argv (
--state-dir,--check-protocolor--foreground) or no arguments, the alias draws nothing and exits 2 with atray-removederror that points to<product> tuiand<product> status --json. - Removed
./menu-kit, thecompanionCLI, the companion lifecycle calls (runCompanion,startCompanion,stopCompanion,companionStatus,handleCompanionCommand), the menu snapshot protocol and its validators,openBrowserandpermissionMenuItems. The Rust crate dropsMenuModel,Host,run,outputsand the Tauri, WebKitGTK and AppIndicator dependencies, and re-exportshraness-local-appandhraness-cli-kit. diagnosePlatformon Linux reports only what the helper needs: GTK 3, and a display for dialogs (graphical_session_missingis now a warning, since prompts fall back to the terminal). Thesession_bus_missingandtray_host_unverifiedcodes are gone.- The login-item notice now says the product starts in the background and shows no window or icon, instead of describing a menu bar icon.
resolveHelperand the prompt calls look forhraness-helperfirst. The release manifest keeps bothassets(the alias) andhelperAssets, so an SDK 0.9 can still read it.
Install
npm install https://github.com/hraness/desktop-foundation/releases/download/v1.0.0/hraness-desktop-foundation-1.0.0.tgzRust products pin the tag: desktop-foundation = { git = "https://github.com/hraness/desktop-foundation", tag = "v1.0.0" }.
Verify
Checksums for every asset are in SHA256SUMS. The source commit is 878bfae8af59cbc0693ebb3156ad006b97fb4938. Each asset has a GitHub build attestation: gh attestation verify <file> --repo hraness/desktop-foundation. See the installation guide.
desktop-foundation v0.9.0
Products can now run without a menu bar: one owner process per product, short-lived commands that print JSON, a human gate for decisions a person owns, and terminal views in place of the menu. Everything is additive; the tray, ./menu-kit and the companion lifecycle calls work as before.
Changes
- New SDK subpaths
./registry,./control,./human-gate,./tui,./login,./retireand./helper, with a new Rust crate,hraness-control-kit, that matches them. Both read the shared contract incontract/, which now ships in the package. - Every
--jsoncommand prints one envelope with a stable error code and exit code: 2 usage, 3 needs a person, 4 owner not running, 5 conflict.commands --jsonlists every verb with its operation class. - A
decideverb needs a person at a foreground terminal who types back a one-time code shown on/dev/tty. Run from an agent with--json, it exits 3 with the command a person should run, and never prompts. This stops accidental approvals, not a determined process running as the same user; seedocs/human-gate.md. - The owner listens on an agent socket and an admin socket in a 0700 directory.
ensureOwnerstarts it on demand, andcontrolStatusreports it without sending signals. tuiviews render interactively on a terminal, as a plain-text snapshot when piped, or as the same JSONstatus --jsonprints.retireLegacyLoginItemmoves a product's old menu bar login item aside after checking it is the product's own, andinstallLoginItemadds an opt-in login item for the owner.- A new
hraness-helper-<target>executable runs the one-shot modes (--notice,--prompt,--launch,--assemble-appand the others) with the same arguments and output ashraness-companion, without the tray. macOS builds are ad-hoc signed. The release manifest lists it underhelperAssets, andresolveHelperfalls back to the companion for older manifests. SDK 0.8.x refuses the new field, so use a 0.9.0 or later manifest only with SDK 0.9.0 or later; the manifest that ships in the package always matches. - The macOS local app, login items and one-shot dialogs moved into the
hraness-local-appcrate, which has no Tauri dependency. Thedesktop-foundationcrate's public API is unchanged.
Install
npm install https://github.com/hraness/desktop-foundation/releases/download/v0.9.0/hraness-desktop-foundation-0.9.0.tgzRust products pin the tag: desktop-foundation = { git = "https://github.com/hraness/desktop-foundation", tag = "v0.9.0" }.
Verify
Checksums for every asset are in SHA256SUMS. The source commit is 6174033a51cd0fa4f5259c8c2492b9a28b942602. Each asset has a GitHub build attestation: gh attestation verify <file> --repo hraness/desktop-foundation. See the installation guide.
v0.8.1
Unsigned, unbundled CLI companions for macOS, Windows and Linux. Includes a pinned SDK manifest and GitHub build attestations. See docs/installation.md for human OS approval guidance. Native event-loop tests do not establish clean-machine visual acceptance.
v0.8.0
Unsigned, unbundled CLI companions for macOS, Windows and Linux. Includes a pinned SDK manifest and GitHub build attestations. See docs/installation.md for human OS approval guidance. Native event-loop tests do not establish clean-machine visual acceptance.
v0.7.0
Unsigned, unbundled CLI companions for macOS, Windows and Linux. Includes a pinned SDK manifest and GitHub build attestations. See docs/installation.md for human OS approval guidance. Native event-loop tests do not establish clean-machine visual acceptance.
v0.6.1
Unsigned, unbundled CLI companions for macOS, Windows and Linux. Includes a pinned SDK manifest and GitHub build attestations. See docs/installation.md for human OS approval guidance. Native event-loop tests do not establish clean-machine visual acceptance.