Repository navigation
Clio Coder 0.6.1 brings a desktop app (alpha) with a setup wizard, a task rail and a Session column. A new installer brings its own Node.js to Linux, macOS and Windows. Approvals say what a command would do, and dispatched workers run under immutable permits, with OS sandboxing for native worker commands when a backend is available. Queued messages are held in Clio, where you can reorder, edit or send them now. Editors get live usage, plan and workspace telemetry over ACP. Experimental additions are SSH worker nodes, docks for workers, files and music, and steering triage. The Pi SDK moves to 1.0.0. This release supersedes 0.6.0, whose installer failed on native Windows and refused some upgrades.
Installation and upgrade
- A native Windows install of 0.6.0 stopped at activation with
EPERM. The installer helper now flushes its launcher record through a writable handle, and file edits on Windows no longer carry a durability warning on every call. - Native Windows installers stage local tarballs before npm, including packages accessed through WSL UNC paths. Installer validation reports incomplete records and rejects malformed Node tarball names before writes. Concurrent desktop setup gives a retry instruction; configure keeps plaintext-key warnings inside its frame, and lifecycle commands consistently name managed installs as installer installs.
- The website installer bootstraps follow the latest GitHub release, and the release installer assets come from the same qualified tarball published to npm.
- A settings file holding a key that was retired without a replacement no longer refuses to load, which had blocked upgrades of 0.5.x homes with an interop setup. The key is ignored and
clio-coder doctornames it as a warning. - An upgrade refused over a setting the installed version cannot repair, such as
safety.autonomy: auto-editfrom 0.4.x, was a dead end, because the advisedclio-coder doctor --fixran the old version. The installer now prints the new version's own repair command. - Installers direct a failed candidate check to
clio-coder doctor --fixinstead of reset, and explain how to keep a source-checkout launcher or replace it with a managed release. - Linux installers reclaim unused refused candidates and versions older than seven days while retaining the active version, rollback version and versions used by live sessions. If process ownership cannot be checked, versions are retained. Replacing an npm-linked launcher names the npm prefix to uninstall from.
clio-coder doctor --fixrepairs file modes, removes retired settings keys, corrects YAML on/off booleans, and asks before replacing a stale model ID with the nearest provider catalog match.- Every doctor warning or failure names a concrete next command, including the sign-in command for expired credentials.
- Doctor detects missing checkout build files and running sessions that need a restart after a rebuild, and
clio-coder doctor --fixrebuilds an incomplete checkout. clio-coder gui background install --handover, the installer's--gui, andclio-coder doctor --fixcan transfer a verified idle background service between installations while preserving its address and credentials.clio-coder gui background restart --if-idlerestarts while conversations are resting and preserves active work. The app and doctor show when a session is still using a version replaced by upgrade or rollback.- Under WSL, Windows shortcuts call the stable
clio-coderlauncher. Opening the app selects the activated service executable after upgrade or rollback, restarts only when idle, and reports browser launch failures. - Background apps keep their web manifest available to installed browser apps. Hiding the manifest did not prevent duplicate browser installations. WSL shortcuts now open one managed desktop identity using a dedicated Chrome or Edge profile; repeated or simultaneous launches focus the existing window. Launch failures display the captured error; uninstall removes the owned Windows launch scripts, shortcuts and browser profile. Taskbar pinning remains a user action.
- Desktop app launches deliver the current address and token, and reconnecting with a fresh local launch link moves the browser to the correct port.
- Windows uninstall removes the private runtime and installed versions after Clio exits, and uninstall reports the shell configuration lines left for manual removal.
Upgrade notes
- Settings from 0.5.9 load unchanged and no key is retired. New keys include
safety.sandbox,safety.sandboxNetwork,interface.exitSummary,integrations.music.*,chat.steering.triage.*andfleet.defaultNode, andfleet.permissions.modeacceptsmain.settings.yamlis now written owner-only, andclio-coder doctorwarns about a wider mode thatdoctor --fixtightens. - Project extensions and plugins load only after the workspace is approved with
clio-coder config trust extensionsorplugins. An unapproved project copy stays listed but unloaded and no longer shadows your own copy. Your first project install approves its own surface; later installs, enables and removes ask again. - A dispatched worker's own commands (
bash,run_script, verification) run under an OS sandbox whensafety.sandboxisauto(the default) and a backend exists, which is bubblewrap on Linux and Seatbelt on macOS. Writes land only in the worker's roots,.gitand.clio-coderstay read-only, and network is off unless the run holdsweb_fetchorsafety.sandboxNetworkis true.requiredrefuses commands without a backend andoffdisables it. Main-agent commands are not sandboxed. A worker confined to narrow write roots losesbashandverifywhen no sandbox is active. - External agents that run their own tool loop (the Claude Code, Codex, OpenCode, Pi and Antigravity runtimes, and ACP peers with
toolGovernance: agent-managed) are refused write-capable work unless the target or entry setstrustedUnmediated: true. Read-only runs are unaffected. - Under the default
fleet.permissions.mode: deny, a worker's refused command returns to the model, and the third refusal ends the run aspermission_requirednaming every refused command. The denial names the tool, the command (clipped, secrets redacted) and the rule. The Claude SDK runtime still ends at its first refusal. A worker change that removes existing test cases or deletes a test file is withheld from the merge (merge_withheld), and a current-tree run fails withworker_removed_tests, unless the task asked for the removal. Ctrl+Qno longer queues for the end of the turn andclio-coder.message.followUpis retired. A keybindings file that names it reports the replacement. Enter queues for the next slot,Alt+Kopens the queue navigator,Alt+Ssends now, andAlt+Atoggles the music dock.Alt+EandAlt+Wnow hide and show docks, and a second tap within 400 ms closes them.- A clean interactive exit prints a session summary.
interface.exitSummaryisautoby default and followsinterface.outputDetail;brief,standard,reportandoffoverride it. safety.limits.sessionCostUsd: 0means no session ceiling in every path, including dispatch plans, fleet previews andclio-coder configure.- The installer no longer fetches the Claude Agent SDK. Pass
--include-claude-sdk, or accept the one-time prompt on first use, which installs it into Clio's own package root or prints the package-manager command. - On sessions that attach
bash,findandlssit behind the gateway, and bash output keeps 16 KiB in model context, split between its head and tail. - Prompt templates follow Pi 1.0 argument semantics (
$1,$@,${@:N},${N:-default}), and bare$ARGUMENTSinserts the text after the command unchanged. - The packaged local model catalog now holds five profiles checked against their upstream Hugging Face model cards and templates: gpt-oss-20b, Qwen3.8-27B, Gemma 4 26B-A4B, Nemotron 3.5 Lightning 30B-A3B and Qwen3.5-4B. These are upstream capability and thinking-control records, not runtime benchmarks. Earlier profiles for finetunes are no longer packaged; keep any you rely on in your config directory's
model-profiles.yaml, which merges over the packaged entries by id.
Desktop app (alpha)
- The app is organized as a rail of tasks per project and one Session column holding the chat's model and health, context and spend, branches, sealed evidence, artifacts and workers. A first run goes through a setup wizard. A machine that has used Clio, with a provider key in the environment, a stored login or a local server on a default port, lands in chat with a notice naming the route.
- Any number of tasks stay open. A task idle for 5 minutes is parked and resumes when shown again, and at most 4 turns run at once, with later turns shown as "Waiting for a slot". Closed tasks stay in the rail as saved tasks.
- One app window: launching focuses the open window, in an installed Chrome or Edge app and through the Start Menu shortcut under WSL, and "Open in new window" or
Ctrl/Cmd+Shift+Nopens another on purpose.clio-coder gui background installkeeps the app on port 4343, or 7373 while another program holds it. - In the composer,
@completes workspace files,↑recalls earlier messages,/commandscomplete from their grammar, and@agent textsteers a running worker. A message that starts with!runs as a shell line between turns, and!!keeps its output out of Clio's context. Each queued message has Send now, move, Now or After, Edit and Remove. - Worker blocks, the Agents view and Evidence show each run's receipt outcome, contract conformance, trust verdict and validation, and an Artifacts page lists a session's
/viewartifacts. Ignored untrusted project surfaces appear under Project trust in the Session column with the trust command to run.Esctwice in the composer stops the running turn. - Tool output keeps the colours a command printed, tables keep their header and offer "Copy table", diffs mark the changed part of a line, and a wide Mermaid diagram offers "Full size". Images embedded in a reply as data are drawn; images at a web address are never loaded.
- Session notices move out of the conversation into the Session column: thinking guidance sits with the model, project-instruction coverage with context, and other notices under Session notes.
- Settings is rebuilt as a few pages, Library has its own page, and "Sign out" under Settings, Models removes the credential Clio stored for a connection. A settled turn closes with one line: Done, Failed or Stopped, then duration, tool calls and tokens.
- Limits: on native Linux the desktop launcher still opens a browser tab per launch, because focusing an existing window needs the installed Chrome or Edge app, and the limit of 4 running turns has no setting.
Install, upgrade and first run
install.shinstalls a private Node.js 24 and the package under a versioned prefix with no root and no system Node. Downloads are checked against Node.js's published checksums; release-signature verification is attempted whengpgvorgpgis present, with a warning if it cannot be completed and a hard failure for a bad signature. Older x64 Linux gets a glibc 2.17 build, Alpine a musl build, and--modify-pathis the only way it edits a shell startup file.install.ps1andinstall.cmddo the same on Windows, where support remains best effort and the native Windows installed-package flow is not CI-verified.install.shoffers the desktop app at the end (--guior--no-gui).clio-coderchecks the Node version before loading and honoursCLIO_CODER_NODEfor hosts whose defaultnodeis too old.clio-coder upgrade --rollbackrestores the previous version. A pinned install shows its pin, and/upgradefollows the recorded channel, leaves a pin alone and tells a source checkout to update through Git. Pre-release builds name their commit and say they are unreleased, and they hear about newer beta and latest releases.- A new home starts directly at "Welcome to Clio Coder" and the first question. A home with no usable chat route tries configured targets, environment keys, Clio's stored logins and local servers on default ports, and saves a route only when none exists.
/configruns configure inside the TUI and applies saved routing live. Peer agents enlist through current ACP recipes, including@agentclientprotocol/claude-agent-acpfor Claude andcopilot --acp. clio-coder resetanduninstallalso remove the desktop app, anduninstallreports.zshrcand fish config lines that mention clio-coder. After a native upgrade,clio-coder guiandgui background restartaccept the desktop app the previous version installed.clio-coder doctorleads with whether chat can run.clio-coder library register|pin|driftprint text unless--json, andclio-coder tools list|statussay when a pin bump superseded a vendored tool.
Release qualification and platforms
- A manually dispatched release workflow gates the selected commit on CI and exact-package qualification, verifies the tarball checksum, publishes those bytes to npm with provenance, and creates the GitHub release and tag last. A failed qualification leaves the release tag unused.
- CI gates root contract and smoke tests, GUI checks and tests, maintenance checks, and installed-package tests on Linux with Node 22. The platform matrix builds and boots on macOS and Windows with Node 22, and Linux with Node 24 and the minimum Node 22.19.0; installed-package checks also run on those macOS and Linux legs. Windows runs selected subprocess contracts but explicitly skips the installed-package test. Node 24 also runs lifecycle, provider-transport and session-durability contracts.
Approvals, trust and worker safety
- A permission approval renders inside the editor's own rails. The top rail names the decision and its kind, the card lists tool, target, effect, requester and worker authority, and
Alt+Topens the full terms andAlt+Vthe full invocation. Bash approvals state what the command would do. A draft you were typing stays editable under the card. - Every worker attempt runs under an immutable permit that fixes its asks, tools and Git allowance.
clio-coder run --delegate-toolssets what dispatched workers may hold, separately from the main agent's--allow-tools. fleet.permissions.mode: mainis a new opt-in. The main agent grants ordinary worker asks on native local workers atyoloand forwards them to you at any other autonomy level. Asks that need operator authority always reach you, and an ask no one can answer is denied.- Workers in a task worktree commit on their task branch through a typed
gitcapability (status,diff,log,show,add,commit) that refuses fields an operation does not take. Clio asks an attached operator before withholding a task worktree merge. A task worktree Clio created inherits package trust while its package state is unchanged. Model-runclio-coder library import,pushandremoteask for confirmation like other library mutations, and--dry-runnever asks. - Information flow (advanced and opt-in) keeps named content with the models you chose. Source rules in
.clio-coder/safety.yamlunderinformationFlowname paths or tools and their allowed recipients, andclio-coder config trust safetyapproves them. Refusals hold atyolo, restrictions travel through workers, resume and compaction, and a project with no rules behaves as before. The policy format may change.
Terminal
- Partial project-instruction coverage appears once per workspace as an expiring footer notice, instead of a persistent welcome row.
- Messages sent during a run are held in Clio and handed over at the next steering slot. The queue navigator (
Alt+K) reorders, edits, removes, switches an entry to end-of-turn and sends it now, andAlt+Sinterrupts the run with your draft./resume <id>resumes a session directly, and a clean exit prints the resume line. CLI--resumeand--continuestay refused (#191). - The exit summary shows identity, model, tokens, cost provenance, wall time and resume instructions in brief form, and adds turns, files changed, tools, worker outcomes and compactions in standard and report form.
- An edit's diff shows once its arguments close, before the call runs.
/compact <instructions>binds the summarizer and keeps the instructions verbatim. The wheel scrolls the transcript while an overlay is open and never moves list choices. - Each substantive turn ranks installed skills, gateway capabilities and agents, and the reminder names up to five likely skills and three capabilities without changing the tool set between turns.
clio-coder fleet view <runId>shows the requested model beside the provider-reported one, with cost provenance, and--jsonprints the snapshot with its authenticated receipt.
Fleet and tools
clio-coder fleet nodes add|list|remove|test|discover|installmanages SSH worker nodes (experimental).install <id> --yesinstalls the exact client build you run,discoverlists Tailscale peers, and a node needs a passing recordedtest --recordbefore dispatch.fleet.defaultNodesets a standing preference, and edits from a separate checkout return through isolated task branches.clio-coder fleet cancel <runId>cancels a run from any terminal.readlists zip and tar archives and reads one text member, extracts PDF text by page (needs poppler'spdftotextandpdfinfo), and renders Jupyter notebooks. Thedatatool reads SQLite databases read-only.- The per-turn observation pool scales with the active context window. Automatic compaction pauses after three consecutive failures, while
/compactand overflow recovery still run. A fleet loop's check step also runs the test files its workspace changed, and a failure feeds the repair loop. - Headless runs and the coder agent map each task clause to evidence before finishing. Unattended runs and workers install only dependencies that were never installed and report failures confined to files they did not touch. When Clio needs one-off routing for a dispatch, she pins the dispatch's
targetandmodelfields instead of editing routing settings. - Headless
clio-coder run --agentprints a "Not verified:" block from the sealed result. Codex, OpenAI Responses and Azure Responses calls record the model the provider reports.
Editors and ACP
- ACP pushes
usage_update(at most one per model response),planafter board changes and_meta["clio-coder/workspace"], so clients stop polling. It serves/viewartifacts through_clio-coder/artifacts/listandread, sealed receipt facts on terminal fleet frames and replay, and ignored untrusted project surfaces in_meta["clio-coder/trust"]. _clio-coder/session/shellruns an operator shell line with the terminal's!and!!semantics, and_clio-coder/session/queue_editremoves, restores, moves, retypes and sends queued entries, with_clio-coder/session/queue_changednotifications for clients that opt in. Worker permission asks,ask_userand harness cards reach an attended ACP client, and bash asks carry the command's consequence line.session/loadreplay does not yet show shell lines.
Experimental
- Docks need Herdr and are off by default.
Alt+Wopens a live workers dashboard (clio-coder fleet view --watch),Alt+Ethe Yazi files pane (interface.panes.files.enabled), andAlt+Athe music pane. A hidden dock keeps running, and a second tap within 400 ms closes it./panesand/filesreport and control docks. /musicand the opt-inmusictool drive cliamp 1.63.2 as focus radio. They needintegrations.music.enabled: true,integrations.music.agentControlfor the tool, andclio-coder tools install cliampor a package-manager install.- System One gains per-model capability profiles (
systemOne.engines.<name>.profile), per-task routing under a site binding, asteersite and category hierarchies for recipes and catalogs. Its sites, keys and cuts may change between releases. chat.steering.triage(off by default) lets a side model read queued messages once the queue settles and relabel them. An unrelated task waits for the end of the turn, and a confident stop may interrupt the run.fleet.speculativeDispatchstays experimental.
Fixed
- A turn that only writes Markdown, reStructuredText, AsciiDoc or Mermaid source finishes as prose-only instead of "change not verified". Stopping at an approval card says the turn stopped and the tool did not run.
- Redaction no longer treats code such as
token = getToken()or a pure$NAMEreference in an assignment as a credential, while literal secrets still redact, and durable trace payloads stay valid JSON after redaction. - Python verification resolves
pythonorpython3once, refuses a uv project without.venv, and recognizesPYTHONPATH=<relative paths>test forms. A check that cannot start is reported as unavailable and not retried. - Typed Git refuses fields an operation does not take, and the loop guard keys repeated Git calls on the arguments that run.
- A new desktop task opens when its model target is down instead of failing with "Clio ACP process is unavailable".