Repository navigation
Releases: lemma-ventures/captaincode
Release list
Captain Code v0.3.7
Privacy
- Private names stay out.
captain leakcheckchecks staged lines and paths, a commit message, and every commit a push would send, against a list kept outside every repository (~/.config/captain/private-names). The.githookspre-commit, commit-msg and pre-push hooks run it, and the launcher turns the hooks on at every start. A captain that predates the command is never called. - The list grows on its own. Once a day per folder, on this machine only, captain proposes names from the folders its TUIs work in; a repository GitHub reports private, or one with no remote, gets its name on the spot.
/privatein a TUI andcaptain private-nameson the command line list, add, dismiss or remove a name. A list line starting with!is an allowed phrase.CAPTAIN_PRIVATE_CURATE=0turns curation off. - Workers carry the line. Every worker prompt, OpenShell sandboxes included, carries a private-names line (
CAPTAIN_WORKER_PRIVATE_NAMES=0drops it).keep-private-names-private, a published skill, is always stocked.
Skills
research-writing-style-1is published. A writing skill for security and cryptography papers: the service before the mechanism, assumptions attached to claims, evidence-specific verbs, and prose a mixed audience understands on first read. The examples use one invented running case and name no author, paper or project.
Routing
- OpenRouter hosts per band. A leg's overlay entry can set
hostsper band (OpenRouter's provider block). The brain's proxy adds it to each request for that band's model, unless the request already names its hosts (a/deterministicpin).
TUI
- The sidebar lists harness-provider. A row is
claude-cli,codex-cli,grok-xaioropenshell-nvidia, with its perf and run count. Version and effort are not on that list: a run readsharness:model@effort:xon Last Runs and in the session header.lunais not a row — it isgpt-6-luna, a version of thecodex-cliharness. - The exit screen resumes through the launcher. On close the TUI prints
<launcher> -s <id>, not bareopencode, which starts without the routing plugin. The exit wordmark is Captain Code's.
Euclid
- The dashboard search honors scope and the journal flag.
/api/searchpassesscopeandinclude_journalsto the engine; an unknown option is a 400 with no result text.lane=allreads as both, andlane=gitreaches the git recall. Journals stay off by default, as the MCP search serves them.
Tests
go test ./...passes inside a captain session again: the suite no longer inherits the session'sCAPTAIN_EUCLID_MCP_CONFIG/CAPTAIN_EUCLID_MEMORY_CONFIG, and a test that wants MCP sets its own path.
Still open: mixed host and sandbox stages, and the upstream VM-driver vouch (NVIDIA OpenShell discussion #4079, PR #3940 still closed).
Install or update: go install github.com/lemma-ventures/captaincode/cmd/captaincode@latest.
If the module proxy still serves an older tag, use GOPROXY=direct go install github.com/lemma-ventures/captaincode/cmd/captaincode@v0.3.7.
Captain Code v0.3.6
Euclid search
- Workers can search files and code.
captain euclid search,captain euclid code, and the MCPsearch/file_searchtools. Default documents exclude journals.include_journalsadds them. Config search returns tracked paths and no file values. - CodeIntel is behind code search. Euclid asks CodeIntel for declaration hits and fuses them into the code lane. The chain stops at four nested MCP launches. A config file cannot reset that count. CodeIntel's MCP endpoint rejects a callback into Euclid.
- A failed search is an error. It is not reported as zero matches. If CodeIntel is slow or down, Euclid keeps its local hits.
- Plain
-rrrefuses a mismatch. IfCAPTAIN_EUCLID_MCP_CONFIGis set and the revision has noEngineSearchOptions, the launcher stops before it replaces the binary or stops the brain. Use-rr --checkoutonly for a reviewed working tree.
OpenShell
- Confirm the sandbox from the prompt. If
CAPTAIN_OPENSHELL_ALLOWEDorCAPTAIN_OPENSHELL_VERIFYis unset, the sandbox does not start. Captain prints the files the task cites that exist atHEAD, and a test command detected from the repo. You start the run by prefixing the task:confirm allowed=file.go verify=["go","test","./..."]. A path only a model added is not accepted.CAPTAIN_OPENSHELL_PREPAREDandCAPTAIN_OPENSHELL_PILOTstay machine settings. - A strict cap prices the director. The reservation is $0.05 per planner call (
CAPTAIN_OPENSHELL_DIRECTOR_USD). It is taken out of the worker budget before the sandbox starts./team /openshellis no longer refused only because the planner call had no price. - Shield's committed spend is charged. When the provider bill is incomplete and every started worker has a Shield budget, that committed amount is the ledger charge. A complete bill still wins. An incomplete bill with no Shield budget stays unknown.
- A strict-capped run can resume. Spent commitments and the director reservation are subtracted from the saved cap. The remainder is split across the stages that are left.
- A crash mid-stage reruns that stage. A stage that finished but whose checkpoint is stale is reused. A stage that was still running, and does not revalidate, is set aside and rerun. The crashed directory is not the verified export. Deleting a completed stage's
run.jsonstill refuses the resume.
Docs
- The M3.7 sections of
docs/ROADMAP.mdsay shipped in v0.3.0, not unreleased.
Still open: mixed host and sandbox stages, and the upstream VM-driver vouch (NVIDIA OpenShell discussion #4079, PR #3940 still closed).
Install or update: go install github.com/lemma-ventures/captaincode/cmd/captaincode@latest.
If the module proxy still serves an older tag, use GOPROXY=direct go install github.com/lemma-ventures/captaincode/cmd/captaincode@v0.3.6.
Captain Code v0.3.5
Fixes
- Busy workers are no longer killed. Every opencode-served leg (step, glm, kimi, ds4-flash and others) died at exactly 30 minutes, even mid-tool, because the HTTP client had a hidden 30-minute timeout. Past its base budget, a run was also cut after 90 seconds without events, even when the model had already paused longer between steps. Now a run past its budget ends only when it has been quiet longer than its own earlier pauses (at least 90 seconds), and the error says how long it actually ran.
- One folder never gets another folder's answer. The same prompt on the same leg in two folders (for example "continue where we stopped") joined the other folder's run and showed its answer. Now runs are matched per folder, both live and when an answer is recovered after a restart. This also fixes a data race on the per-task budget.
- The brain no longer runs without its egress proxy. If the proxy port is taken, the brain retries for 15 seconds and then exits, so the supervisor can start a complete brain. Before, every opencode call failed with "Cannot connect to API".
- A source name without
--sourceis refused.captain skills sync <name>used to ignore the name and every flag after it, and silently syncedanthropics/skills.
Plain writing by default
- On for every worker. The
public-clarity-outputskill is now stocked for every task, likesecurity-audit. Every worker prompt gets a short plain-writing rule: simplified technical English, short sentences, active voice, no filler. That covers solo,/frontier,/team, workflow and/repeatworkers. OpenShell sandbox workers get the rule inline, because they can't read the host's skills. - Turning it off: set
CAPTAIN_WORKER_NOSLOP=0. /noslopturns it back on for one turn, before or after any command:/noslop /openshell …,/team /noslop ….
Launcher
./captaincode.sh -rralways builds the latestmain: the newer of the local andorigincopies, whatever branch the checkout is on. The checkout is never touched, and the binary still records which revision it was built from.- Building something else:
-rr --branch <name>builds another branch.-rr --checkoutbuilds the working tree, uncommitted edits included. - Restarts now stop every supervisor, including orphaned ones. An old supervisor could start a second brain at the same moment as a restart.
Docs
docs/ROUTING.mdexplains how a prompt without a/command is routed: the rating, the second opinion, the fast path and the director. It includes two weeks of picks and the known weak points.
Install or update: go install github.com/lemma-ventures/captaincode/cmd/captaincode@latest.
Captain Code v0.3.4
Retract v0.3.0 to v0.3.2
v0.3.0, v0.3.1 and v0.3.2 can freeze the brain: the triage-shadow deadlock fixed in v0.3.3. Their tags and releases have been removed, and go.mod now retracts them, so go get warns anyone still on them and @latest never resolves to them.
The code is the same as v0.3.3; see its notes for the fix.
Install or update: go install github.com/lemma-ventures/captaincode/cmd/captaincode@latest.
Captain Code v0.3.3
Fix: the brain could stop answering
v0.3.3 fixes a deadlock that froze the shared brain. Every TUI then showed "still working" on turns whose workers had already finished. Upgrade if you use a jev decision leg.
The deadlock
- After a confidently routed turn, the brain sometimes asks jev in the background how it would have routed the same turn. By default 1 in 5 such turns is sampled. When jev answered, the brain charged the call while still holding its main lock, and the charge waits for that same lock, so it waited forever.
- Every sidebar poll and every finishing turn then queued behind that lock. Finished answers never reached the TUI, and thousands of connections piled up. The bug was in every release since v0.2.4.
- The check is now recorded, the lock released, and only then is the call charged. A regression test covers it.
- To turn the background check off on older versions, set
CAPTAIN_TRIAGE_SHADOW_RATE=0.
Seeing and stopping a stuck brain
- The brain's main lock now remembers which code took it. If it's held for more than a minute, the brain log names that code and later says when the lock is released.
- A brain asked to stop (SIGTERM) now waits at most 10 seconds for the lock, then ends its workers and exits anyway. Before, a stuck brain ignored SIGTERM, so a restart couldn't replace it.
captaincode.shnow waits for the old brain to exit after asking it to stop. If it still answers, it allows up to 4 minutes for cleanup; if it answers nothing, it kills it.
Install or update: go install github.com/lemma-ventures/captaincode/cmd/captaincode@latest.
Captain Code v0.2.5
What's in v0.2.5
The brain stops leaking idle connections, same-file conflicts have one owner, and three skills ship for other harnesses.
Highlights
- The brain stays up. Idle HTTP connections are reaped (90s,
CAPTAIN_HTTP_IDLE_TIMEOUT). A grade no longer holds the global lock across a provider call, and sidebar polls give up after 2.5s./v1/statsreportshttp_conns. - Same-file conflicts have one owner.
/teamand a workflow stage capture each worker's diff before the worktree closes. Changes to different files land together. When workers edit the same file, the director names one of them: that worker's changes land whole, and every other worker who touched a contested file is set aside (diffs kept under~/.captaincode/runs/diffs). No usable ruling means nothing is applied.captain task artifacts <id>shows the call. Every diff is checked before any is written. - Run records. docs/RUN_RECORDS.md maps which agent got the task, what it ran, files changed, the last error, and the handoff, to the files in
~/.captaincode/. - Skills other harnesses can load. land-parallel-agent-work, verify-with-verdicts, audit-public-claims. No scripts. They do not need Captain installed.
Install
go install github.com/lemma-ventures/captaincode/cmd/captaincode@latest
# or pin this release
go install github.com/lemma-ventures/captaincode/cmd/captaincode@v0.2.5Full changelog: v0.2.4...v0.2.5
Site: https://captaincode.ai
Captain Code v0.2.4
What's in v0.2.4
Routing no longer parks a whole lane on one leg. Each leg answers cheap, quality and frontier with the model its own login offers.
Highlights
- Lanes keep count.
/frontier,/qualityand/saverecord where recent turns went and send the next one to the leg behind its share, among legs scoring within 85% of the lane's best./frontieralternates the strongest legs by the perf index./qualityspreads the top quality scores./savestays on open-weight legs, each at its own model. A forced leg or a named model is not counted./qat the start of a prompt counts as/quality. - Per-leg tiers. Cheap, quality and frontier are models on that leg's login. Codex runs Luna, Sol and Astra.
captain upgrade --checkprints the table. - Standing mix.
/captain more|less <axis>, assignments such asoss=30%,/captain targetsand/captain mix resetset how unprefixed turns are shared. An explicit/quality,/speed,/save,/frontier,/ossor/deterministicstill wins. - Security guidance is on every shelf. Solo, team, workflow and
/frontierturns stock Cloudflare'ssecurity-auditskill once it is synced.captain skills unstageremoves only Captain-staged shelves, andcaptain doctorreports whether the skill is present. - Docs.
docs/CLI.mdcovers every command. Newdocs/TUI.md.
Install
go install github.com/lemma-ventures/captaincode/cmd/captaincode@latest
# or pin this release
go install github.com/lemma-ventures/captaincode/cmd/captaincode@v0.2.4Full changelog: v0.2.3...v0.2.4
Site: https://captaincode.ai
Captain Code v0.2.3
What's in v0.2.3
Packages the two merged PRs on top of v0.2.2, plus a small doctor-test isolation fix.
Highlights
- Legs that cannot run say why, and are never dispatched (#1). Failures are typed and benched; the ladder names every leg with its own cause. Same task dropped from ~92s of opaque failures to ~19s with unrunnable legs skipped up front.
- One readiness verdict, shared by
captain doctor, the director picker, the brain router and the CLI ladder. A provider named inopencode.jsoncis not a credential; an installed CLI binary is not a logged-in session. Doctor and dispatch now agree. - Agent-followable setup + README rewrite (#2). New
AGENT_SETUP.mdfor paste-into-your-agent installs; README opens on quickstart, explains jev as the decision leg (triage acts; gate/supervise/shadow record by default). - Doctor tests stay honest next to a live brain. Injected
ServeRoster+ cleared provider keys so a local serve cannot flip legs to ready in unit tests.
Install
go install github.com/lemma-ventures/captaincode/cmd/captaincode@v0.2.3
# or clone for the full terminal (plugins + captaincode.sh)
git clone https://github.com/lemma-ventures/captaincode && cd captaincode
go build -o ~/.local/bin/captain ./cmd/captaincode
(cd plugin/captain-ui && bun install) && captain init && ./captaincode.shFull changelog: v0.2.2...v0.2.3
Site: https://captaincode.ai · ADI: https://lemma-ventures.github.io/agentic-determinism-index/
Captain Code v0.2.2
What's in v0.2.2
One fix on top of v0.2.1.
Highlights
- Director refusals name the standing helm.
/captain <agent>that cannot direct (for example/captain codex-cli) no longer stops at "cannot direct". The reply states that the current helm and mode are unchanged, and when the same vendor has a judge on the same credential it points at it (/captain codexfor the ChatGPT subscription; Cursor Composer has nowhere else to go and gets no suggestion).
Install
go install github.com/lemma-ventures/captaincode/cmd/captaincode@v0.2.2
# or clone for the full terminal (plugins + captaincode.sh)
git clone https://github.com/lemma-ventures/captaincode && cd captaincode
go build -o ~/.local/bin/captain ./cmd/captaincode
(cd plugin/captain-ui && bun install) && captain init && ./captaincode.shFull changelog: v0.2.1...v0.2.2
Site: https://captaincode.ai · ADI: https://lemma-ventures.github.io/agentic-determinism-index/
Captain Code v0.2.1
What's in v0.2.1
Five changes on top of v0.2.0, all in routing and the decision leg.
Highlights
/frontierreaches every leg's ceiling. In front of a leg or a workflow it is a modifier, so/frontier /claude X > /grok > /codex-cliruns each leg at its most performant settings rather than the pseudo-leg with the rest as its prompt.- Grok 4.7 on the legs that can run it.
/frontier /grokupgrades the burner togrok-4.7,/frontier /cursorpinsgrok-4.7-xhigh(CAPTAIN_CURSOR_FRONTIER_MODELoverrides), and/grok-maxand the grok director are 4.7. Worker tabs now name the model actually dispatched. - A queue of prompts is a sequence. Prompts typed while a turn runs reach the brain together; each now runs as its own turn, in the order typed, with its own head, routing and worker, streamed under a
[captain] queued k/nline. - An open decision backend beside the vendor's.
CAPTAIN_SYSTEMONE_OPEN_URLadds a local System One-shaped sidecar (sidecars/laya, ~200 lines, laya-mlx) beside jev instead of replacing it. It decides nothing until you promote it with a bar read off its own rows (CAPTAIN_SYSTEMONE_OPEN_FOR=triage=0.85);gate,superviseandkeepare never promotable, and a state too large for it goes to the backend that holds it whole.captain jev shadow --backend <host>reads one backend's rows alone. - A connector after a paragraph break is pasted content, not topology — a prompt quoting
>in trailing text no longer compiles into a workflow.
Install
go install github.com/lemma-ventures/captaincode/cmd/captaincode@v0.2.1
# or clone for the full terminal (plugins + captaincode.sh)
git clone https://github.com/lemma-ventures/captaincode && cd captaincode
go build -o ~/.local/bin/captain ./cmd/captaincode
(cd plugin/captain-ui && bun install) && captain init && ./captaincode.shlaya-mlx is optional and not a dependency: without it, nothing about captain changes.
Full changelog: v0.2.0...v0.2.1
Site: https://captaincode.ai · ADI: https://lemma-ventures.github.io/agentic-determinism-index/