Skip to content

v1.16.0

Latest

Choose a tag to compare

@github-actions github-actions released this 05 Oct 15:16

Changelog

  • fbc93f4 Add project content, live invalidations and conditional viewer layouts
  • 9db8a36 Bound content watch registrations per credential across streams
  • 83f3e22 Clarify persisted session revocation and service state
  • e3c0812 Clear stale HTTP test connections before API restart
  • e733ee8 Decide API path containment only through os.Root
  • 6c65ac5 Document workspace SDK and element consumer semantics
  • 79c69ae Expire obsolete proof fixture timers deterministically
  • 335af64 Expose owning content workspace selectors and preserve alias-root shell state
  • a4ed64d Fix project alias identity found during U4-c review
  • 1152bf1 Persist browser sessions and refresh rebuilt UI roots
  • 046fcad Preserve config recovery and privacy in UI service setup
  • 00bc85e Preserve opaque viewer attachments and disambiguate origin panes
  • ac3bbcf Preserve tree directory errors and distinguish layout storage failures
  • a7bfa97 Project managed shells into their durable owning worktree
  • ff0e574 Purge browser bearers after eviction and revocation
  • feb4f23 Refuse malformed UTF-8 before decoding viewer layouts
  • 3e06d74 Refuse missing content watch targets beneath escaping symlinks
  • 70beb87 Require browser key proof for memory-only session bearers
  • d207cfd Resolve diff parents to commit ids before they reach git
  • 9de675c Simplify UI service setup and document custom Sidecar clients
  • 5975e93 Synchronize blocked persistence and load-sensitive proof fixtures
  • 19a9461 Verify shell sockets and preserve legacy workspace fallback
  • 590d92b Verify the loopback startup deadline at the CLI boundary
  • 7ce83e4 deps: tasks v1.19.0
  • d129b87 feat(api): manage per-user services and restart on binary replacement
  • cebb198 feat(api): reserve service listeners across binary restarts
  • dd85281 feat(mobile): arbitrate presence and deliver negotiated v1 terminals
  • 37a49a4 feat(mobileproto): define negotiated terminal v1 contract and fixtures
  • b432a31 feat(mobileproto): pin the reset reason vocabulary
  • 308447d feat(ui-api): serve project workspaces and guarded operations
  • 6d851fc feat(uiapi): generate public schemas and serve deterministic fixtures
  • 4cbb8c0 feat(uiapi): integrate events spec and catalog owner paths
  • 5cb45d0 feat(uiapi): push Sessions, attention and terminal events
  • c8f58e1 feat(uiapi): relay agent pane requests to the focused API viewer
  • 5653c34 feat(uiapi): revoke browser sessions without restarting the server
  • c07b783 feat(uiapi): revoke paired origin terminals and unused tickets
  • 3cc2f4f feat(uiapi): sidecar api serve with guarded listeners, pairing and terminal WebSocket
  • 1db6671 fix(agent): preserve literal arguments after terminator (td-66d7e3)
  • 441e488 fix(agentcontrol): observe provider exits between startup polls
  • 3eecc67 fix(agents): isolate Codex launches and refuse conflicting caller identity
  • 7a026d0 fix(api): candidate refresh reads current shell reservations
  • fd0958b fix(api): project reads ignore TUI instance count; hub lookup failures retry
  • 1f6154a fix(api): project routes accept the project key or its name (td-778992)
  • 8ae95c0 fix(api): re-derive worktree candidates per request from a fresh pane listing
  • 86b6cbf fix(api): refuse service installation beside undiscovered foreground servers
  • b0f5d9c fix(api): reinstalling a running service waits for launchd to release it
  • 8dbf290 fix(api): review fixes for workspace hub rows, owner refusals and the activation probe (td-8893e8)
  • f9bb517 fix(api): saved layouts accept hub-scoped terminal identities
  • b09b3b8 fix(api): share collected catalog data, never authorization state
  • 8c056ec fix(api): the launchd service starts and reports itself on current macOS
  • b63073d fix(api): validate activated socket family and stream type
  • 4c5ef8e fix(api): workspace terminals attach through the hub like /sessions rows
  • 3412142 fix(apiservice): keep only owner-controlled PATH entries in the service
  • 63ebe48 fix(apiservice): use the com.haplab.sidecar.api label, matching the app's bundle namespace
  • 4cd7058 fix(cli): an unfocused API viewer no longer blocks the remote lease relay
  • 9ac6bb2 fix(cli): keep caller files absolute for an unrooted destination
  • be7892f fix(cli): resolve existing relative open files from the caller
  • 957f73a fix(content): preserve Git-quoted diff file paths
  • bc9ec34 fix(mobile): a foreign resize ends the wait for an expected geometry
  • dfdb629 fix(mobile): bound the one-shot sessions query's backend setup
  • 03312c1 fix(mobile): end the reseed when a capture's target is gone
  • cb40435 fix(mobile): normalize server paste boundaries and line endings
  • 6ae0f31 fix(mobile): reseed after a capture failure; a failed release keeps its sequence
  • 49b9335 fix(mobile): revalidate capture failures independently of dead transport
  • 7b1b548 fix(mobilehub): a finished owner catalog keeps its slot until it is charged
  • aac7f3a fix(mobilehub): charge owner catalogs against the aggregate bound on arrival
  • 53d8de5 fix(mobilehub): never report a busy local owner offline at the remote bound
  • 9eedf7e fix(overview): preserve operation authority when projects reorder
  • 9b27732 fix(overview): refresh reordered projects without retiring operations
  • e9c5787 fix(proof): isolate UI API creation from inherited caller identity
  • ba7f51c fix(sessions): preserve valid completions across replacement dialogs
  • 0a5911c fix(sessions): stamp the picker source root before dispatch
  • cf63c60 fix(shells): give new managed sessions distinct comms identities
  • 4f497d4 fix(shellstate): refuse incompatible future schemas before recovery
  • 6af48fd fix(terminal): restore focused geometry and show the peer holder
  • 933f680 fix(tmux): preserve metadata across supported versions
  • c2b2451 fix(tmux): recognize hosting socket path aliases
  • bdb8b67 fix(tmux): scope the hosting-pane guard to its server
  • f576ae6 fix(tooling): allow parallel lint gates across worktrees
  • 881d93c fix(tty): release mobile leases after capture transport loss
  • 4a1bb46 fix(ui-api): close owned listeners before releasing the instance lock
  • 5055bea fix(ui-api): fence deletions and preserve remote operation outcomes
  • d9621ce fix(uiapi): bearer clients may omit Origin; refuse a terminal over the cap with 4429
  • 13adafd fix(uiapi): bound keepalive exemptions and cancel stalled streams
  • cf64339 fix(uiapi): compare the tailnet host allowlist case-insensitively
  • f3d875f fix(uiapi): describe served HEAD methods in OpenAPI
  • 1d72459 fix(uiapi): forbid cross-site framing of the static UI
  • c742d7c fix(uiapi): include evicted session streams in sign-out
  • f7c4b06 fix(uiapi): interrupt event writes on credential revocation
  • ab98ee4 fix(uiapi): isolate fixture server authority from real state
  • cb23a7c fix(uiapi): keep catalog event observation free of state writes
  • 611c062 fix(uiapi): keepalive excuses a pong missed behind a blocked inbound pump
  • 87f34c4 fix(uiapi): only Authorization: Bearer with a token may omit Origin
  • 6ed8182 fix(uiapi): origin-bound bearer sessions, WebSocket keepalive and per-client limits
  • 0bc44e6 fix(uiapi): paired origins need their own token on the tailnet listener
  • 7c8382c fix(uiapi): preserve layout planner refusal item verdicts
  • 07e3c17 fix(uiapi): preserve shutdown close when keepalive exits
  • d1794a7 fix(uiapi): re-pairing an origin closes the old token's streams
  • f8c3c0a fix(uiapi): reject fixtures exceeding the byte limit
  • 7d3649b fix(uiapi): reject stale and replaced worktree roots
  • 1da9cf0 fix(uiapi): reject tickets authorized before session revocation
  • 1d6c64d fix(uiapi): renew viewer credentials, decline --sessions, strip control sequences
  • 340a180 fix(uiapi): require remote ticket credentials in the spec
  • 663243f fix(uiapi): revoke events with their credential
  • edcc9af fix(uiapi): scope viewer layouts to selected worktrees
  • edfc00c fix(uiapi): serve --ui files through os.Root so symlinks cannot escape DIR
  • 63535a3 fix(uirequest): keep API-viewer-pinned requests off every TUI and remote relay
  • c97d15d fix(workspace): activate geometry on live pane handoffs
  • 7ab6038 fix(workspace): close cross-project shells on worktree deletion (td-17b5e2)
  • f748bc2 fix(workspace): fence asynchronous completions to their requesting project
  • 23c9bbc fix(workspace): snapshot manifest projections under the writer lock
  • 69d4326 fix(worktrees): preserve live and unknown associated sessions during prune
  • 35fca70 fix(worktrees): preserve sessions when pane directories are unknown
  • 90628ed fix: allocate fresh shell identities atomically across processes
  • 6525240 fix: bound contention on the project registry lock
  • b537adb fix: bound diff reads and protect API Git metadata
  • 990b38b fix: bound tmux work during atomic shell allocation
  • 6eca18c fix: close selected diff pathspec metadata bypass
  • f41b369 fix: integrate shell allocation error and registry contracts
  • a0a4fae fix: keep shell operation identities exact across surfaces
  • 818dee2 fix: preserve bare display-name target compatibility
  • d375077 fix: select shells only after their allocated identity returns
  • 4c1e745 fix: synchronize agent startup and share legacy holder observations
  • 75fa069 merge: bring main into U1-b before contract handoff
  • 6b0c51e merge: integrate main before U3-c server review
  • 1daec11 merge: integrate main before shell allocation review
  • dffb83d merge: integrate reviewed U0 fixes and schema for browser session revocation
  • 5c90a70 merge: integrate service-install lane before U1-b review
  • 1aa1634 perf(api): collect the workspace and hub catalogs concurrently
  • a3e8cf3 perf(api): share one local catalog collection between concurrent requests
  • 03df264 perf(hostserve): read each cycle's status panes through one tmux client
  • a11d503 perf(managedtarget): list project worktrees concurrently for orphan marking
  • 7b154a9 perf(mobile): collect the local catalog without per-row subprocesses
  • 5162386 refactor(shellstate): share manifest persistence across surfaces
  • 818a38b refactor(workspace): share CLI result types with API clients
  • c827569 refactor: finalize deletion recovery through workspace service
  • e750c2c refactor: share agent target resolution policy
  • 07b723f refactor: share state-free workspace list projection rules
  • ca088e7 refactor: share workspace mutation and launch orchestration
  • cf18294 release: prepare v1.16.0
  • 605c8fc test(agents): isolate remaining real-shell integration fixtures
  • 7c17f4c test(agents): keep shell proof fixtures deterministic under load
  • 6af667e test(api): guard service packaging and bound status discovery
  • a6a74e7 test(cli): cover sidecar api verbs, usage errors and tailnet options
  • 725456a test(notify): control the cancellation-ordering deadline
  • 0a9dab0 test(sessionrestore): synchronize real shell prompt fixtures
  • ce721db test(tooling): synchronize report publication and shutdown proofs
  • 75e8db0 test(tooling): use semantic barriers and canonical fixture order
  • 191d336 test(tty): a reseed restart is deduped and never outlives its consumer or manager
  • 23a2469 test(tty): holder labels cannot inject tmux commands
  • 154ef17 test(ui-api): prove named shell creation refusals over HTTP
  • 1be0404 test(ui-api): prove one shell across three real viewers
  • f5d478d test(uiapi): adversarial guard coverage; warn about --tailnet-port trust
  • 6e05ca3 test(uiapi): adversarially verify presence paste and compression
  • 202ee1f test(uiapi): align event fixtures with stream transition ordering
  • 23ce4bc test(uiapi): drive the fragment pairing exchange and a session-ticket terminal in the live proof
  • 9656ed3 test(uiapi): hold keepalive off in the evicted-session revocation test
  • 6c51c89 test(uiapi): live terminal round trip over the API, plus an isolated proof script
  • 2f8e600 test(uiapi): prove fixture catalog identity and reconnect continuity
  • 900fb82 test(uiapi): prove session revocation in the live UI API proof
  • 0c34998 test(uiapi): prove v1 terminals and measure negotiated compression
  • a3a3cfa test(uiapi): run the served pairing script under Node and a no-Origin bearer terminal in the proof
  • 55d5db9 test(uiapi): use the enclosing deadline for holder synchronization
  • 0ef527c test(uiapi): verify competing fixture presence across connections
  • a63cf2d test(workspace): complete roots across persistence fixtures (td-17b5e2)
  • 3792a4e test(workspace): count tmux invocations with multiline formats
  • 9424072 test(workspace): use valid project roots in modal fixtures (td-17b5e2)