Releases: lee77840/omniconductor
Releases · lee77840/omniconductor
Release list
v1.1.2
Fixed
- Hookify customization and diagnostics agree — the Claude output validator now
accepts the plugin's documentedenabled: falserule toggle as a non-failing warning,
while still rejecting malformed booleans and unsupported events. Doctor retains its
D5 checked-file summary during warning-only runs and refuses to treat a plugin-list
entry with another checkout'sprojectPathas locally active, regardless of scope. - Modified-settings uninstall behavior is explicit — the migration guide now states
that checksum-safe uninstall preserves a post-install edited.claude/settings.json,
which can intentionally leave the semantically merged Hookify/core-hook entries. - Release comparison follows the registry — the local release gate now exercises
upgrades from the actual latest published1.1.1package to the1.1.2candidate;
its fixture setup is version-aware for the v1.1+ explicit model-routing contract
and remains safe under Bash 3.2set -uwhen testing pre-1.1 releases. - Required runtime source cannot be omitted from a commit — the release gate now
fails before packing unlessbin/claude-hookify.js, required by doctor and the
validator, is present in the Git index.
v1.1.0
Added — one-time six-tool model setup
- First-install model wizard —
omniconductor initnow presents one summary
for all selected adapters, accepts the recommended Tier 1/2/3 mappings with one
confirmation, and asks three values only for adapters the user customizes. - Project-saved routing state —
.conductor/model-routing.jsonrecords a
revisioned, adapter-validated mapping plus configured-vs-enforced metadata.
omniconductor models show/configureinspects or explicitly changes it;
installed native roles are regenerated while preserving immutable Tier triggers. - Strict automation contract — unconfigured
--no-promptrole installs fail
before managed writes. Non-interactive automation opts in with
--accept-model-defaults. Dry-run remains
zero-write, recipes-only remains model-independent, and all six public
transform.shentry points delegate to the same Node setup transaction. Each
adapter also reloads the saved mapping immediately before writes, so forged child
markers and inherited model environment values cannot bypass setup or replace it. - Provider-native defaults — Claude recommends Opus/Sonnet/Haiku; Codex
Sol/Terra/Luna plus high/medium/low effort; Gemini pro/flash/flash-lite; Cursor
and Copilot saved exact native fields with provider-policy caveats; Windsurf
Adaptive is explicitlyadvisory-session, never falsely marked enforced. - Routing and path safety suite — customization, missing-config fail-closed
behavior, transactional role/manifest refresh, forced-failure rollback, crash
recovery, stale-lock reclamation, installed concurrency, user-edit conflicts,
manifest traversal, managed-surface containment, symlink/hardlink rejection,
forged dispatch environment/FD attempts, reinstall, and uninstall-choice retention
are regression-tested by the local suite and retained in the manual Linux CI
definition. - Local release and real npm-upgrade gate —
npm run release:verify:local
runs the complete regression suite, static checks, exact packed-candidate fresh
install, all-six validation/doctor/uninstall, published1.0.1→ candidate
upgrades for six single-tool projects and a legacy six-tool project, and
npm publish --dry-run. A clean-tree strict mode also verifies the filtered
public snapshot. It never pushes, dispatches GitHub Actions, or publishes. - Manual-only GitHub workflows — both Actions definitions now accept only
workflow_dispatch; their remote state remains disabled and there is no scheduled
reactivation. Local validation is required, with optional manual CI only directly
before a necessary release.
Fixed — multi-tool runtime hardening
- Vendor-neutral difficulty routing — the unchanged Tier 1/2/3 task
thresholds now live in universaldifficulty_tiermetadata. Before role emission,
the CLI saves each selected adapter's explicit Tier translation: Claude family
aliases; Codex Sol/Terra/Luna plus high/medium/low reasoning; Gemini semantic
aliases; exact Cursor/Copilot native model fields with provider-policy caveats;
and an honest Windsurf Adaptive session advisory. Model selection never changes
the immutable task classification. - Independent ownership for all six adapters — authoritative manifests now live at
.conductor/manifests/<adapter>.json; the root manifest is an aggregate projection.
Sequential installs, repeat installs, scoped uninstall, and--target=allno longer
overwrite another adapter's ownership or remove shared files still in use. - Order-independent reinstall/uninstall ownership — an idempotent reinstall now
carries forward every still-present owned entry, and every baseline adapter imports
the original shared docs/profile ownership record. Manifest ownership remains stable
across repeat installs, and removing adapters in either install or reverse order
leaves zero managed residue while retaining the original user backup chain. - No untracked
.gitignoremutation — Reflector trajectory payloads are ignored by
the managed.conductor/trajectories/.gitignore; the installer no longer appends an
unmanifested block to the adopter's top-level.gitignore, preserves a user-owned
nested ignore file, and removes the exact legacy CONDUCTOR block during migration. - Native runtime contracts and roles — all adapters emit eight verified role entry
points including a distinct post-implementationcode-reviewerand Tier 3utility. Codex emits native
agent TOML plus its verifiedPreToolUse/Stopsubset and never activates Claude's
unsupportedpermissionDecision: "ask"contract. - Fail-closed managed paths and atomic model refresh — installers reject
symlinked/hard-linked managed roots and leaves plus untrusted manifest paths before
mutation. Model changes verify manifest ownership/checksums, journal the old config,
role files, and manifests under one lock, commit config last, and recover the last
complete state after failure or process death. Installation holds the same lock
through every real adapter write, including cross-mode recipes-only updates,
preventing a concurrent reconfiguration from leaving saved routing and emitted
roles on different revisions. Doctor derives routing requirements from actual role
ownership rather than the latest manifest mode label. - Bounded Codex project instructions — native
codex debug prompt-inputinspection
proved the former 68 KiBAGENTS.mdwas truncated. Codex now gets a 6.7 KiB
always-loaded kernel and complete manifest-owned rule/recipe references under
.codex/conductor/; validator and doctor enforce 24 KiB/32 KiB safety budgets. - Semantic doctor and portable hooks — doctor now audits every manifest, checksums,
footprints, hook dialects, agent TOML contracts, Git tracking, project profile, and
structured CURRENT_WORK drift. Shared hooks are BSD/GNU awk compatible and normalize
zero counters deterministically. - Release-candidate regressions — five modes across six adapters, 24 multi-tool
runtime contracts, local native Codex prompt-input verification, and a freshly packed
npm artifact install/validate/doctor/reinstall/forward-and-reverse-uninstall lifecycle
are covered. - Offline validation latency — the advisory npm-registry check is retry-free,
capped at three seconds, and explicitly skippable for deterministic offline runs. - Published-version migration compatibility — upgrading the actual npm
1.0.1
package now preserves and snapshots user edits, ignores historical backup files
during current-output isolation checks, replaces Windsurf files only when legacy
ownership proves they are managed, and converts the old shared root manifest to
six authoritative adapter manifests before an all-target upgrade. Previewing that
legacy migration with--dry-runremains byte- and path-zero-write.
v1.0.1
Fixed — manifest safety follow-up
- Checksum-protected uninstall on all six adapters — normal manifest entries now record the emitted file's SHA-256.
--uninstallremoves or restores only an unchanged emitted file; a user-modified file (and legacy manifest entries without a checksum) is preserved with a warning instead of being deleted. - Lossless full-mode re-install — an unmodified re-install retains the original pre-CONDUCTOR backup rather than replacing it with the prior generated bundle. Backup names are collision-safe within the same second. If a generated file was edited before an update, that edit is backed up before replacement.
- Owned marked blocks only — Gemini/Codex replace an existing
conductor:blockonly when exactly one matching marker pair is present, the current manifest owns it, and its content hash is unchanged. Foreign, malformed, duplicate, or customized markers abort without changing the host file. - Regression coverage —
tools/test-install-modes.shnow asserts original-baseline restoration after two full installs, preservation of user edits during uninstall for every adapter, and non-destructive foreign-marker rejection for Gemini/Codex. - Private-source/public-mirror policy — the source repository remains private; a fail-closed filtered snapshot is the only route to the public mirror and npm release.
sync-public.sh HEAD --checkis network-free and runs in CI to reject denied paths or private tokens before merge. Seedocs/PUBLICATION-POLICY.md.
v1.0.0
Added — install modes (audit follow-up #4; the final pre-1.0 feature)
--mode=full|minimal|strict|recipes-only|reflector-onlyon all six adapters (npx CLI forwards it; manifest stamps"mode").full= unchanged default.minimal= discipline text + docs only (no agents/hooks/Reflector runtime).strict= abort (exit 3) instead of touching an existing baseline.recipes-only= à la carte (requires--recipes=).reflector-only= the self-improvement loop standalone — the least-conflicting install for projects already on Spec Kit / BMAD. — ADR-044.- Marked append-blocks for single-file tools (Gemini/Codex) — à-la-carte modes APPEND
<!-- conductor:block … -->to an existingGEMINI.md/AGENTS.mdinstead of overwriting; the manifest trackstype: block+ contentsha256+created_file, and--uninstallstrips the block only when unmodified (a customized block is left in place with a warning). Windsurf needed no blocks — its rules are per-file under.devin/rules/. - Framework detection — the installer detects Spec Kit (
.specify/) / BMAD (_bmad/.bmad-core) and suggests an à-la-carte mode. Suggest only; never auto-switches. tools/test-install-modes.sh— per-tool mode-behavior harness (strict abort incl. secondary rules surfaces, à-la-carte emission sets, byte-lossless block round-trips (checksum-asserted), cross-mode block cleanup, customized-block preservation, zero-valid-recipes failure); CI jobinstall-modesruns it for all six adapters.install.ala_cartein adapter metadata — the block-vs-per-file à-la-carte strategy is single-sourced inmetadata.json(new M9 consistency check + a column in the generated outputs table). npm-registry lag now surfaces as a non-fatalWARN[A3]in the stale-token check.
Changed
- ROADMAP P4 marked Done — v1.0.0 is the public release (beta feedback + marketplace listing move post-1.0). COMPARISON's "pre-1.0" maturity framing retired (tokenized per the ADR-039 process rule).
- Claude adapter:
INSTALLED_HOOKSinitialized before mode branches; recipes step creates.claude/rules/itself (à-la-carte no longer depends on step 1).
Milestone
- v1.0.0 — all five features from the 2026-07-09 audit-follow-up plan are shipped (#3 stale-token CI + #2 metadata single-source in 0.7.0; #1 doctor + #5 live-verify + #2 slice 2 doc generation in 0.8.0; #4 install modes here). The anti-drift system is closed-loop: metadata is the single source, CI regenerates and verifies the docs, doctor checks installs, live-verify records reality.
v0.8.0
Added — metadata consumers (audit follow-up #1 + #5 + #2 slice 2)
omniconductor doctor <target>(3rd CLI command) — read-only installed-project health check anchored on.conductor-manifest.json. Seven groups: manifest validity · version drift (install stamp vs running CLI) · file integrity · stale legacy paths (from adaptermetadata.json,--legacy-cursorrulesaware) · hook validity (.jsonparses,.shexecutable +bash -n) · doc-link liveness · stale-claim scan (reusestools/stale-tokens.txtsemantics). OK/WARN/FAIL → exit 0/1/2,--jsonfor machines. CI runs a positive + negative doctor smoke per adapter. Prior-art differentiated by scope (per-project asset health), not name. — ADR-041.- Generated doc regions from metadata (
tools/generate-adapter-docs.js) — the live-verification status table (docs/ADAPTER-LIVE-VERIFICATION.md) and a new "Adapter outputs at a glance" table (docs/COMPATIBILITY-MATRIX.md) are now rendered fromadapters/*/metadata.json;--checkfails CI on drift. All remaining hand-written live-verification dates/CLI versions on living surfaces replaced with date-free pointers to the generated table (milestone history keeps "first live-verified" dates). — ADR-042. tools/live-verify.sh— automated live rule-loading verification — per tool: throwaway install → headless probe (read-only) → deterministic grade (≥3/5 universal rule names + CURRENT_WORK; no LLM judge) → writeslive_verificationintometadata.jsonand regenerates the doc tables. Honest SKIP when a CLI isn't installed; >90-day freshness WARN; local-first (CI can't hold six authenticated CLIs). First run: Claude Code newly live-verified (5/5 rules, Claude Code 2.1.205) and Codex re-verified (4/5, codex-cli 0.144.0), both 2026-07-09. — ADR-043.
Changed
- Claude adapter manifest now stamps
"adapter": "claude"(the other five adapters already stamped theirs) — doctor uses it; footprint inference covers pre-0.8 installs. bin/omniconductor.jsusage/comments:doctoradded; stale "ADR-018" citation corrected to ADR-002/023/025.
v0.7.0
Added — anti-drift guards (audit follow-up #3 + #2 slice 1)
- CI stale-token + version-stamp check —
tools/check-stale-tokens.sh+ data filetools/stale-tokens.txt(pattern⇥reason⇥hint⇥allow_regex, inlinestale-ok:waivers) as a new CI job. Class A mechanizes the R7 stamps (README status line must stamp the exactpackage.jsonversion — now re-stamped on every release, patches included; CHANGELOG must have the section). Class B fails CI on known-false claims (seeded ~15 tokens from the verified drift inventory:.codex/codex.md-as-current, unqualified.windsurf/rules, "no npx", "❌ No hooks/sub-agents", "Single model per session", …). Process rule: a change that flips a fact adds the now-false claim to the token list in the same PR. — ADR-039. - Adapter metadata single-source —
adapters/<tool>/metadata.json×6 (outputs / reflector outputs / legacy paths / tier / two-axis capabilities per ADR-031 / live-verification / headless CLI) +tools/check-adapter-metadata.shCI job asserting 8 invariants (paths exist intransform.shand the validator; legacy paths handled in code; verified-status dates single-sourced indocs/ADAPTER-LIVE-VERIFICATION.md; headless CLIs known torun-weekly.sh; matrix tier rows agree). The bash transforms stay dependency-free — metadata validates them, never drives them (ADR-002/023/025). — ADR-040.
Fixed (residual doc drift the 0.6.1 point-fix missed — found by re-verification + the new checker itself)
- 5 non-Claude adapter READMEs rewritten to the ADR-031 capability-vs-emission framing (were still "❌ No sub-agent / No hooks / single model" as tool limitations, with pre-P1 rule names in the install trees, "npx not yet available", and a Codex tier contradiction (README said T3, matrix says T2)); Reflector emission (
--recipes=self-improvement) now documented per adapter. core/**reference tables —.codex/codex.md→AGENTS.mdand.windsurf/rules/→.devin/rules/in universal-rules/recipes READMEs, spec-as-you-go, anti-pattern examples; meta-discipline cross-tool enforcement table de-staled.- docs/ — ARCHITECTURE (adapter output map, always-loaded row, orchestrator paragraph), INDEX (package row, adapter rows, Codex live-verified, P4 row: npm published), MANUAL-INSTALL (all-6-adapters decision table, "until adapter ships" headers, "No hooks, no sub-agents" limitations), MIGRATION (modern
.mdcflow, guard-hook phrasing), HOW-IT-WORKS (Gemini/Windsurf lost-feature tables), VISION (.devin/rules/tree). - First machine-scan catches (missed by two human sweeps + a 3-agent verification pass):
adapters/codex/transform-spec.mdbody still specced.codex/codex.md,VISION.mdtree, and two "(planned / roadmap — not yet available): npx …" blocks in adapter READMEs — including a claude README pointer to the retired v0.1 archive installer.
Changed
- Version-stamp policy: patch releases now re-stamp the README status line (supersedes the 0.6.1 "feature-baseline stamp" stance) — enforced by CI. — ADR-039.
- README's "New in" blockquote now carries only the current release (older summaries drift and were an unguarded second changelog); history lives here.
Notes
- npm registry skips 0.6.1: 0.6.1 was tagged + released on GitHub but never
npm publish-ed; the registry goes 0.6.0 → 0.7.0 directly. Everything in 0.6.1 is contained in 0.7.0.
v0.6.1
Fixed (documentation + adapter output truth-source; from an external audit)
- Manifest version bug — all 6 adapters hardcoded
"version": "v0.2.0"in the emitted.conductor-manifest.json; now read dynamically frompackage.json(installs stamp the real version). Fixes bogus install-history / rollback / bug-report data. - Adapter capability strings — Codex/Gemini/Windsurf/Copilot emitted output claimed the tool has "no hooks / no sub-agents / single model"; corrected to the ADR-031 capability vs CONDUCTOR-emission framing (the tools support these; CONDUCTOR emits rule text + the Reflector loop, full emission Phase 2).
- Doc drift to v0.6.0 reality — README/ROADMAP/COMPARISON/HOW-IT-WORKS/ARCHITECTURE/VISION/COMPATIBILITY-MATRIX/ADAPTER-LIVE-VERIFICATION/SUPPORTED-FEATURES: all 6 tools have working adapters (not "adapter-less"), npm package exists (no "no npx"), Codex output is
AGENTS.md(not.codex/codex.md), Windsurf emits.devin/rules/(not "pending"), Codex is live-verified (single-sourced across docs), Claude hook count reconciled (10 hooks / 5 PreToolUse + 5 Stop). - npm completeness —
package.jsonfilesnow ships the docs the README links to (COMPATIBILITY-MATRIX, ADAPTER-LIVE-VERIFICATION, PUBLISH-GUIDE, DESIGN-DECISIONS, COMPARISON), so npm-installed users don't hit dead links.
v0.6.0
Added
loop-engineeringrecipe +pretool-loop-guardPreToolUse hook — opt-in discipline for bounded, externally-verified agent loops (G1–G6): explicit done-criterion, iteration+token budget, require-progress, escalate-on-stall, verify externally never by self-judgment, oscillation/infinite-loop guard. Grounded in a 5-source verification pass (Huang/DeepMind "Cannot Self-Correct Yet", CRITIC, Reflexion, "When Agents Do Not Stop", Anthropic Building Effective Agents — verify hierarchy rules/tests > visual > LLM-judge). The Claude hook is a non-blockingpermissionDecision: asksoft-warn that self-gates on the recipe, detects same-action-repeat / runaway tool-call budget, is fail-open, and honorsCONDUCTOR_SKIP_LOOP_GUARD/CONDUCTOR_LOOP_REPEAT_MAX/CONDUCTOR_LOOP_BUDGET/CONDUCTOR_LOOP_COOLDOWN_SECONDS. Recipe count 12 → 13, hook templates 9 → 10. Hook is Claude-only (ADR-034); other tools use the rule text. — ADR-038.
v0.5.0
Added
git-hygienerecipe +stop-git-hygiene-guardStop hook — opt-in shared-repo discipline (G1–G7): no unrequested worktrees, push-don't-hoard, merge=delete-branch, backup≠applied (verify by real code), no reckless force/rebase on shared repos, bundle PRs for CI, session-end hygiene check. Prevents the failure where merged work looks lost (orphan worktrees / local-only commit hoarding / stale merged branches) and burns reconciliation time. Recipe body installs on all six tools; the Stop-hook reminder is Claude-only (ADR-034), non-blocking, self-gated on the recipe. Recipe count 11 → 12, hook templates 7 → 9 (the 0.3.0stop-trajectory-logcount was also un-synced). — ADR-037.
v0.4.1 — docs patch (accurate npm README)
Fixed (docs)
- README status line corrected to v0.4.0 and the instruction-fidelity token-economy work re-labelled from "unreleased" to shipped (it landed in 0.4.0) — the 0.4.0 npm package page had still shown v0.3.0.
- Public GitHub Releases backfilled (v0.3.0, v0.4.0) so the repo's Latest release matches the npm version.