Skip to content

Releases: mosttt/ternilo

Ternilo v0.2.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 05:10

Ternilo v0.2.0

本版完善多电脑工作台、账号与自动化身份,以及跨电脑和托管会话的模型授权。

工作台与电脑

  • 默认按电脑分组,在线状态显示在电脑行。可选择只显示在线电脑,后端按需加载对应工作区、会话、搜索和归档;切回全部后再加载其余内容。
  • 会话切换使用缓存和增量续读,长单轮思考保留完整开头;停止并发送支持持久队列续发。目标仅由用户显式 /goal 启用。
  • 电脑使用系统生成的固定 ID 与可修改的唯一名称。支持详情、备注、暂停/恢复、吊销、保留历史的移除登记及恢复原身份;普通重连保留原电脑身份。
  • 本机、Server 与可选 Worker 使用分类配置/数据目录;Server 和 Worker 通过 --config-dir 指向配置目录。ternilo serve --open-browser 在服务就绪后打开浏览器。
  • 单用户模式隐藏注册入口,切换页面关闭旧菜单;改进慢响应时的模型菜单稳定性与 Worker 目录读取等待。

身份与模型

  • 本站密码与 OIDC 会话统一管理,支持活动信息、稳定刷新身份和撤销。
  • 原生账号可在用户设置验证当前密码后自助改密,撤销已有本站浏览器登录并保留身份、电脑与资源。
  • 实例所有者可配置 SMTP;账号支持邮箱验证及一次性邮件密码找回,包含 OIDC 登录返回、请求限流和旧登录撤销。
  • 原生账号支持验证器与一次性恢复码;密码和关联 OIDC 登录均验证第二因素,邮件改密保留 MFA,并提供私有运维恢复。
  • 跨电脑模型转发支持整月汇总与 CSV,独立保留执行电脑、来源电脑、提交者和模型所有者,区分逻辑请求与实际重试。
  • 设备直连 Provider 用量支持整月汇总和 CSV 导出,保留未知计数及上报覆盖率,包含所有明细分页。
  • Server 模型请求支持全站和实际提交账号的滚动频率/并发限制、账号默认值和普通/服务账号覆盖;平台模型、账号 Provider 与电脑转发共用准入,超限返回 429 和重试提示。
  • 服务账号拥有独立凭据、空间范围和工作区显式授权,支持 HTTP、Live、Python/TypeScript SDK 及模型工具任务。
  • Server 远程会话可使用另一台电脑的模型:执行电脑运行工具,来源电脑使用自己的 Key 调用上游,Server 授权与转发。支持跨 Server 流式传输、取消、重试许可及独立设备用量记录;不开放独立客户端的本地跨电脑入口。
  • 托管协作者可明确提供自己的账号模型或平台授权。模型提供者、实际提交者与资源原所有者分别校验、记账,包含服务账号;来源撤权停止调用,不回退同名模型。Worker 不取得上游 Key。
  • 支持团队资源管理权交接,保留原存储和执行身份;这不等于迁移文件或跨主机接管。
  • Claude 模型发现核对官方路径、鉴权和分页;失败提示区分上游状态、连接、超时和目录格式,不暴露凭据或原始错误正文。
  • 搜索插件增加 Brave 和 Tavily,沿用 SearXNG 的结果展示,支持凭据引用、请求取消、有界结果和安全错误提示。
  • 外部 ACP 代理支持凭据引用、显式认证及模式选择;提供 Gemini CLI 和 Claude Agent ACP 配置示例,并验证实际程序的 ACP v1 握手。
  • Claude 可显式启用供应商托管搜索/读取,支持暂停续传、引用保存、本机工具混用和保守预算预留;本机、Server、电脑转发及模型专用客户端四条路径已验收。
  • SQLite 写请求使用独立队列,保留读取连接,修复持续模型负载下的写锁 500;增加并发读取、模型流式/取消和持续写入验证。
  • Wasmtime 更新至 48.0.5,依赖安全检查通过。

交付与边界

提供 Linux x86_64/ARM64、Windows x86_64/ARM64、macOS Apple Silicon 和 macOS Intel 的 CLI/Server 程序及 Desktop 安装器。Windows 程序归档为 ZIP,Linux/macOS 为 tar.gz;桌面提供 DEB/AppImage、Windows x86_64 EXE/MSI、Windows ARM64 EXE 和 DMG。

Server 镜像为 ghcr.io/mosttt/ternilo-server:0.2.0,平台 linux/amd64/linux/arm64。附带 Compose 直接拉取镜像,不需要本地构建。校验来源和镜像摘要见 SOURCE、SHA256SUMS 与 server-image.txt。

Server、Node 与可选 Worker 使用同一版本,执行器协议为 48。桌面安装器尚未进行发行者签名/公证,自动更新未启用;资源搬迁/存储故障转移与更大规模、长时间容量验证继续按计划推进。电脑凭据轮换后移,ternilo-work 仍为设计预留。

核心流程已在 SQLite、受限 PostgreSQL、真实浏览器、双 Node/双 Server 及 Bubblewrap Worker 中验收。构建与公开产物以此版本的 GitHub Actions 和 Release 实际结果为准。


Ternilo v0.2.0

This release expands the multi-computer workbench, account and automation identities, and model authorization for remote and managed sessions.

Workbench and computers

  • Computer grouping is the default, with status on the computer row. Online-only filtering loads matching workspaces, sessions, search and archives on demand; choosing all computers loads the rest.
  • Session switching uses cached history and incremental updates. Long thinking turns retain their beginning; stop-and-send supports durable queued continuation. Goals require an explicit user /goal.
  • Computers have immutable generated IDs and unique editable names. Management includes details, notes, pause/resume, revocation, history-preserving removal and identity recovery. Normal reconnection retains identity.
  • Local, Server and optional Worker instances organize configuration and data into directories. Server and Worker accept --config-dir; ternilo serve --open-browser opens the browser after readiness.
  • Single-user mode hides registration. Navigation dismisses old menus; model menus remain stable during refresh, and Worker inspection waits follow command deadlines.

Identities and models

  • Native-password and local OIDC sign-in sessions share management, activity information, stable refresh identity and revocation.
  • Native accounts can change their password after verifying the current one, revoking existing site browser sign-ins while preserving identity, computers and resources.
  • Owners can configure SMTP for email verification and one-time password recovery, including OIDC return navigation, request limits and old-session revocation.
  • Native accounts support authenticators and one-time recovery codes, enforced for password and linked OIDC sign-ins. Email password recovery retains MFA; private operator recovery is available.
  • Forwarded-computer model usage adds monthly summaries and CSV with execution/source computers, submitters and model owners retained, and logical requests separate from retry attempts.
  • Direct-device Provider usage includes full-month summaries and CSV export with unknown counters and reporting coverage preserved across all detail pages.
  • Server model traffic supports platform and actual submitting-account rate/concurrency limits, defaults and user/service-account overrides. Platform, account Provider and forwarded-computer calls share admission, with HTTP 429 and retry hints.
  • Service accounts have separate credentials, space scopes and explicit workspace grants, covering HTTP, Live, Python/TypeScript SDKs and real model/tool tasks.
  • Server-managed remote sessions can use another computer's model. The execution computer runs tools; the source computer calls its upstream with its own key. Server authorizes and relays streams, including across Server instances, with cancellation, retry permission and separate device usage records. Standalone local clients do not gain a cross-computer entry.
  • Managed collaborators can explicitly provide their own account models or platform grants. Model owner, actual submitter and original resource owner remain distinct, including for service-account tasks. Revocation stops calls without same-name fallback. Workers receive no upstream key.
  • Team resource management can be handed over while preserving storage and execution identity; this does not migrate files or provide storage failover.
  • Claude discovery follows the official endpoint, authentication and pagination contract. Safe diagnostics distinguish upstream status, connectivity, timeout and catalog-format failures without exposing keys or raw error bodies.
  • Search plugins add Brave and Tavily alongside SearXNG, with credential references, cancellation, bounded results and safe error messages.
  • External ACP agents support credential references, explicit authentication and session modes. Gemini CLI and Claude Agent ACP profiles include actual ACP v1 startup verification.
  • Claude can explicitly enable provider-hosted search/fetch, with pause continuation, persistent source links, local tool mixing and conservative token reservations across local, Server, forwarded-computer and model-only client paths.
  • SQLite writers use a dedicated queue while retaining read connections, fixing lock-related HTTP 500s under sustained model load. Repeatable read, streaming/cancellation and write-load drivers are included.
  • Wasmtime is updated to 48.0.5 and dependency security checks pass.

Delivery and boundaries

CLI/Server programs and Desktop installers cover Linux x86_64/ARM64, Windows x86_64/ARM64, macOS Apple Silicon and macOS Intel. Windows archives use ZIP; Linux/macOS use tar.gz. Desktop formats are DEB/AppImage, Windows x86_64 EXE/MSI, Windows ARM64 EXE and DMG.

The Server image is ghcr.io/mosttt/ternilo-server:0.2.0 for linux/amd64 and linux/arm64. The attached Compose file pulls it directly, without a local build. SOURCE, SHA256SUMS and server-image.txt record source identity, checksums and the image digest.

Server, Node and optional Worker use matching versions and executor protocol 48. Publisher signing/notarization and automatic desktop updates remain unavailable. Resource migration/storage failover and larger, longer capacity validation remain planned. Computer credential rotation is deferred; ternilo-work remains a design reserve.

Core flows were verified with SQLite, restricted PostgreSQL, real browsers, two Nodes/two Servers and a Bubblewrap Worker. Actual build and public artifact status is determined by this version's GitHub Actions and Release results.
Server image: ghcr.io/mosttt/ternilo-server:0.2.0 (linux/amd64, linux/arm64).

Ternilo v0.1.3

Choose a tag to compare

@github-actions github-actions released this 30 Sep 22:01

Ternilo v0.1.3

本版补齐 Node 账号停用后的持久任务清理和完成确认,并修复组织登录的浏览器地址校验。

  • 封禁或注销账号时,Server 持久登记 Node 清理请求。Node 按输入的账号、状态版本和接收凭据清理排队消息、运行任务、提醒、持续目标及受管进程,保留其他账号和本机的独立工作。解封不会恢复旧任务授权。
  • Node 启动时同步授权,持久保存接收证据、撤销状态及清理回执。每个凭据绑定一个数据目录,空目录或新凭据不能替原实例确认任务已清理。
  • Shell、job、terminal 和外部 ACP 使用独立进程监督。Windows 在子进程执行前绑定 Job Object;只有受管进程退出、目录占用释放和任务状态写入后才确认完成。离线或无法核实旧进程时保持待确认。
  • 平台账号页新增“电脑任务清理”,显示电脑、空间、请求及确认时间和未完成原因,支持桌面与手机查看及手动刷新。
  • 清理归档会话不启动其运行时;事件序号校验避免覆盖其他作者的新目标或重复删除提醒。账号撤销不会暂停其他作者的队列,人工对子任务的独立跟进也保留自己的授权来源。
  • OIDC 登录前检查浏览器加密能力和回调来源,提供中英文操作提示。公网地址拒绝 0.0.0.0/:: 等监听地址;已保存的错误地址保留密码登录入口,便于修正设置。
  • 共享授权、权限组及项目继承的变更可以通知连接同一数据库的其他 Server。网页自动更新资源列表,撤权后清空已打开的历史并停止旧订阅;这不代替跨 Server 的 Node 命令路由。

发行提供 Linux x86_64、Windows x86_64、macOS Apple Silicon、macOS Intel 的客户端、Server 二进制及 Desktop 安装器。Windows CLI 使用 ZIP,Linux/macOS CLI 使用 tar.gz,用户文档包含 docs/zh-CN/ 和 docs/en/。Desktop 安装器未签名/公证,自动更新关闭。

Node、Server 和独立 Worker 应使用相同发行版本。PostgreSQL 通过 schema owner 初始化 node_account_cleanup 和 resource_live 组件,服务继续使用受限 runtime 身份。清理确认覆盖 Ternilo 登记的执行资源,不回滚任务已经造成的外部效果。

Server 镜像为 ghcr.io/mosttt/ternilo-server:0.1.3(linux/amd64),附带 Compose 直接拉取镜像。SOURCE、SHA256SUMS 和 server-image.txt 分别记录来源、附件校验和镜像摘要。本版发布 Server 镜像,Work 保留独立设计空间。


Ternilo v0.1.3

This release adds durable Node cleanup and completion receipts for suspended accounts, and fixes browser-origin checks for organization sign-in.

  • Account bans and removal persist cleanup requests. Nodes cancel the account's queued inputs, active work, schedules, goals and supervised resources while preserving unrelated accounts and local work. Unbanning does not authorize old tasks.
  • Nodes synchronize authority before restoring remote work and persist input evidence, revocation state and receipts. Credentials bind a local data directory; a replacement directory or credential cannot confirm work from the original instance.
  • Shell, jobs, terminals and external ACP tasks use independent process supervision. Windows assigns Job Objects before child execution. Confirmation requires supervised processes to exit, workspace ownership to be released and task state to be persisted. Offline Nodes and unknown prior process state remain pending.
  • Account administration displays computer cleanup requests, scope, timestamps and outstanding errors, with desktop/mobile layouts and manual refresh.
  • Archived cleanup does not start a session runtime. Conditional event writes preserve other authors' goals and avoid duplicate schedule deletion. Independent human follow-ups keep their own authorization origin.
  • OIDC checks browser cryptography and callback origin before redirecting, with actionable Chinese and English messages. Public URLs reject wildcard listening addresses such as 0.0.0.0 and ::; password access remains available to correct an invalid saved URL.
  • Sharing, permission-group and project-inheritance changes notify other Servers using the same database. Browsers refresh resource lists automatically; revocation clears open history and stops the previous subscription. This does not replace cross-Server Node command routing.

Client and Server binaries plus Desktop installers are provided for Linux x86_64, Windows x86_64, Apple Silicon and Intel macOS. Windows CLI archives use ZIP; Linux/macOS use tar.gz. User documentation includes docs/zh-CN/ and docs/en/. Desktop installers are unsigned/not notarized and automatic updates are disabled.

Use the same release for Node, Server and an independent Worker. PostgreSQL initializes the node_account_cleanup and resource_live components through the schema-owner connection, then serves with the restricted runtime identity. Cleanup confirmation covers registered execution resources and does not roll back external effects.

The Server image is ghcr.io/mosttt/ternilo-server:0.1.3 for linux/amd64. The attached Compose file pulls it directly. SOURCE, SHA256SUMS and server-image.txt record provenance, asset checksums and image digest. This release publishes the Server image; Work retains its separate design scope.
Server image: ghcr.io/mosttt/ternilo-server:0.1.3 (linux/amd64).

Ternilo v0.1.2

Choose a tag to compare

@github-actions github-actions released this 30 Sep 13:47

Ternilo v0.1.2

本版补齐账号封禁/注销后的托管运行取消,并隔离不同作者与执行授权账号的队列批次。

  • 账号停用、凭据撤销和托管任务取消在同一事务完成,覆盖全部租户及派生运行。排队和未启动的任务取消并释放预留;运行中的任务收到持久停止命令,等待 Worker 实际收尾回执。
  • 按当前执行授权账号处理取消,保留同一会话其他账号的独立任务。排队消息被其他成员编辑后,执行授权属于编辑者,历史消息保留最初作者。解封不会恢复已取消的任务,历史文件效果和实际用量保留。
  • Local/Cloud 队列只合并连续且身份明确的同作者消息。Cloud 同时要求执行授权相同;未知来源和无法证明共同作者的自动任务单条执行,不跨越其他作者的消息合并。
  • 提交、编辑和启动前复核账号访问状态。批量取消先取得所需会话锁,争用时整事务回滚并有限重试,避免与提交或子任务调度形成锁环。
  • 管理页面的中英文确认说明同步显示任务取消影响。CI 增加 SQLite、受限 PostgreSQL 的清理/作者隔离契约,以及真实管理页面的桌面和手机验收。

发行提供 Linux x86_64、Windows x86_64、macOS Apple Silicon、macOS Intel 的客户端和 Server 二进制及 Desktop 安装器。Windows CLI 使用 ZIP,Linux/macOS CLI 使用 tar.gz;文档按 docs/zh-CN/、docs/en/ 分类。Desktop 安装器未签名/公证,自动更新关闭。

Server 镜像为 ghcr.io/mosttt/ternilo-server:0.1.2(linux/amd64),附带的 Compose 直接拉取镜像。SOURCE、SHA256SUMS 和 server-image.txt 提供来源、附件校验和镜像摘要。PostgreSQL 由 schema owner 初始化 cloud_account_cleanup 组件,服务使用受限 runtime 身份。

Node 已开始的任务、持续目标和离线队列清理仍需执行端确认;账号停用不代表所有外部进程已停止。资源交接与跨 Server 路由继续推进,Work 保持设计预留,本版发布 Server 镜像。


Ternilo v0.1.2

This release adds managed-run cancellation when accounts are banned or closed and separates queued work by author and execution authorization.

  • Account status changes, credential revocation and managed-run cancellation commit atomically across tenants and derived runs. Queued and unstarted tasks are cancelled and release reservations. Running tasks receive durable stop commands and retain their pending state until the Worker reports the actual end.
  • Cancellation follows the current execution account and preserves other accounts' independently authorized tasks in the same session. Editing another member's queued message authorizes execution as the editor while keeping the original message author. Unbanning does not revive cancelled work; file effects and actual usage remain.
  • Local and Cloud combine only consecutive messages with a provable common author. Cloud also requires matching execution accounts. Unattributed inputs and automated tasks without a common author run individually and cannot jump over another author's messages.
  • Submission, editing and starting recheck account access. Batch cancellation acquires the required session locks before changing reservations; contention rolls back the entire transaction with bounded retries, avoiding deadlocks with admission and subagent scheduling.
  • Chinese and English administration confirmations explain the task effects. CI covers SQLite, restricted PostgreSQL, author boundaries and actual desktop/mobile administration in Chromium.

Client and Server binaries and Desktop installers cover Linux x86_64, Windows x86_64, macOS Apple Silicon and macOS Intel. Windows CLI archives use ZIP; Linux/macOS use tar.gz. Documentation is organized under docs/zh-CN/ and docs/en/. Desktop installers are unsigned and automatic updates remain disabled.

The Server image is ghcr.io/mosttt/ternilo-server:0.1.2 for linux/amd64. The attached Compose file pulls it directly. SOURCE, SHA256SUMS and server-image.txt record source provenance, asset checksums and the image digest. PostgreSQL requires schema-owner initialization of cloud_account_cleanup; the service uses its restricted runtime identity.

Running Node tasks, persistent goals and offline Node queues still need executor cleanup confirmation. Account suspension is not proof that every external process has stopped. Resource handoff and routing across Server replicas remain in progress. Work remains a design reservation; this release publishes the Server image.
Server image: ghcr.io/mosttt/ternilo-server:0.1.2 (linux/amd64).

Ternilo v0.1.1

Choose a tag to compare

@github-actions github-actions released this 30 Sep 05:23

Ternilo v0.1.1

本版修复 Windows 本机使用、历史浏览与工作区预览,并补齐客户端、Server、Desktop 和 Server 镜像的发行交付。

  • 多电脑打开同名文件夹时,默认工作区名称加入电脑 ID;显式重名返回明确提示。打开工作区弹窗使用首次加载和手动刷新,不持续轮询。
  • Windows 预设、工作目录、附件、配置与分叉保存不再使用 Unix 目录句柄同步方式;完整退出会等待指令收尾并释放五类本地数据库。Desktop 使用 GUI subsystem,启动时不再附带控制台窗口。
  • 界面主题默认跟随系统,并实时响应系统主题变化。Node 启动命令采用单行 CLI 参数,新凭据使用 ter_n_/ter_e_ 前缀。
  • 原生浏览器登录会话显示浏览器/系统、首次和最近来源 IP、最后活动及登录/到期时间。浏览器不提供的真实主机名不会被虚构;转发 IP 只接受显式配置的可信代理。
  • 普通历史自动补齐,较大历史每次读取最多 5,000 条底层事件;保留每个请求 1,000 条的上限。修复手机轨迹虚拟列表的重复测量和触摸时追尾。
  • 修复 Server 工作区图片预览的 CSP 配置。HTML 预览移除外部资源并隔离脚本;远程读取完成后重新核验工作区共享权限。
  • 客户端归档统一使用 ternilo- 名称。Windows 为 ZIP,Linux/macOS 为 tar.gz;Desktop 提供各平台安装器。正式文档在源码与便携包中按 docs/zh-CN/、docs/en/ 分类,开发记录不进入发行包。
  • Server 镜像发布至 ghcr.io/mosttt/ternilo-server:0.1.1(linux/amd64)。附带的 Compose 直接拉取镜像,不要求用户本地构建。server-image.txt 保存镜像摘要,SOURCE 和 SHA256SUMS 保存来源与校验信息。
  • 包含原生账号恢复、远程 Python/TypeScript SDK、项目共享继承、未知模型用量核对、设备 Provider 用量观察,以及 Server 模型连接的 Gemini/Anthropic 协议支持。
  • MCP 处理工具列表变更通知;可选重连默认关闭、最多 10 次,旧 handler 失效且失败调用不重放。
  • Wasmtime 升级到 48.0.3,修复 RUSTSEC-2026-0315 与 RUSTSEC-2026-0316。

支持 Linux x86_64、Windows x86_64、macOS Apple Silicon 和 macOS Intel。Linux 便携二进制基于 Ubuntu 24.04,不承诺更早 glibc 版本;桌面安装器暂未签名/公证,自动更新关闭。Windows CLI 包中的 ternilo-sandbox-windows.exe 应与 ternilo.exe 保持同目录。

升级时保留数据库、配置、实例主密钥及各电脑的项目/数据目录。PostgreSQL 首次初始化新的会话详情组件需要 schema-owner 连接,随后继续使用受限 runtime 账号。Work 容器产品仍为预留设计,本版只发布 Server 镜像。


Ternilo v0.1.1

This release fixes Windows persistence, history browsing and workspace previews, and completes client, Server, desktop and Server-image delivery.

  • Same-named folders on different computers receive distinct default workspace names. Explicit duplicates return a clear validation error; the workspace dialog loads on open and refreshes on request without continuous polling.
  • Windows state, presets, workspace registration, attachments and forks no longer use POSIX directory synchronization. Final shutdown drains accepted commands and closes all five local database stores. Release desktop builds use the GUI subsystem without an attached console window.
  • Theme defaults to System and responds to OS appearance changes. Node launch commands use single-line CLI arguments; new credentials use ter_n_ and ter_e_ prefixes.
  • Native browser sessions show browser/OS, first/latest source IP, last activity, sign-in time and expiry. Unavailable real hostnames are stated honestly; forwarding headers are accepted only from explicitly trusted proxies.
  • Ordinary histories load automatically; large histories load up to 5,000 underlying events per batch while individual requests remain bounded to 1,000. Mobile trajectory lists retain measurements and stop tail-following during touch gestures.
  • Server CSP now permits authenticated workspace image previews. HTML previews remove external resources and isolate scripts. Workspace permission is rechecked after delayed remote reads.
  • Client archive names use ternilo-. Windows uses ZIP; Linux/macOS use tar.gz; desktop retains native installers. Source and portable packages organize formal guides under docs/zh-CN/ and docs/en/; development records are excluded.
  • Server image: ghcr.io/mosttt/ternilo-server:0.1.1 (linux/amd64). Attached Compose pulls it without a local build. server-image.txt, SOURCE and SHA256SUMS record image digest, provenance and checksums.
  • Includes native account recovery, remote Python/TypeScript SDKs, project sharing inheritance, unknown model-usage reconciliation, device-provider usage observations and Gemini/Anthropic protocols for connected Server model sources.
  • MCP refreshes notified tool catalogs and supports opt-in reconnection capped at 10 attempts. Stale handlers are invalidated; failed calls are never replayed.
  • Wasmtime 48.0.3 addresses RUSTSEC-2026-0315 and RUSTSEC-2026-0316.

Platforms: Linux x86_64, Windows x86_64, macOS Apple Silicon and Intel. Portable Linux binaries target Ubuntu 24.04 and do not promise earlier glibc compatibility. Desktop installers are currently unsigned/unnotarized, with automatic updates disabled. Keep ternilo-sandbox-windows.exe beside ternilo.exe in Windows portable installations.

Preserve database/configuration/master-key backups and each computer's project/state directories when upgrading. Initializing the new PostgreSQL session-details component requires the schema-owner connection before restricted runtime use. Work containers remain a reserved design; this release publishes the Server image only.
Server image: ghcr.io/mosttt/ternilo-server:0.1.1 (linux/amd64).

Ternilo v0.1.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 13:00

Ternilo 首个发行版本,提供独立本机客户端 ternilo、远程入口 ternilo-server 和桌面安装包。

平台 客户端 CLI Server Desktop
Linux x86_64 ternilo-local-0.1.0-x86_64-unknown-linux-gnu.tar.gz ternilo-server-0.1.0-x86_64-unknown-linux-gnu.tar.gz DEB、AppImage
Windows x86_64 ternilo-local-0.1.0-x86_64-pc-windows-msvc.tar.gz ternilo-server-0.1.0-x86_64-pc-windows-msvc.tar.gz EXE、MSI
macOS Apple Silicon ternilo-local-0.1.0-aarch64-apple-darwin.tar.gz ternilo-server-0.1.0-aarch64-apple-darwin.tar.gz ARM64 DMG
macOS Intel ternilo-local-0.1.0-x86_64-apple-darwin.tar.gz ternilo-server-0.1.0-x86_64-apple-darwin.tar.gz x64 DMG

ternilo-local 归档包含 bin/ternilo 和插件 CLI;Windows 另包含必要的沙箱辅助程序。Server 归档包含 bin/ternilo-server。请下载这些附件;GitHub 自动生成的 Source code 仅为源码。

Server 镜像已公开,可直接拉取(linux/amd64):

docker pull ghcr.io/mosttt/ternilo-server:0.1.0

固定摘要:ghcr.io/mosttt/ternilo-server@sha256:37ce755dd4c2af314c0f706113a1da26260eda3b6c7574f7855b41e6459a788d。镜像首次运行需初始化私有配置和持久卷,参见部署指南。

本版本采用 Apache-2.0,包含原生账号维护恢复、有界历史分页、工作区/会话共享、五种模型协议、用量核对、设备 Provider 用量报告和本机 Python/TypeScript stdio SDK。

四平台构建与全部发布检查通过,Server 镜像通过初始化、登录、非 root 运行、只读根文件系统及重启持久化验收。桌面安装器尚未进行发行者签名/公证,自动更新关闭;未宣称完成 Windows/macOS 实机安装验收。Linux 便携包基于 Ubuntu 24.04,本机执行需要 bubblewrap 和 ripgrep(DEB 已声明依赖)。

SHA256SUMS 覆盖全部交付附件,SOURCE 记录 Ternilo 与 Linorun 提交,server-image.txt 记录镜像摘要。版本固定在 0ce6ba4bf37e9dc668c5339dd9fc0eb201e65f88;之后主分支增加的远程 Server SDK、项目共享继承、账号命令补发修复及日志维护不包含在此版本中。

部署指南 · 安装与恢复 · 发布验证


The first Ternilo release includes CLI client and Server archives plus desktop installers for Linux x86_64, Windows x86_64, Apple Silicon and Intel macOS. Download the attached binaries; GitHub's Source code archives contain sources only. The ternilo-local archive contains the ternilo executable.

The public Server image is ghcr.io/mosttt/ternilo-server:0.1.0 (linux/amd64), with its immutable digest in server-image.txt. Initialize persistent configuration before serving. All release checks, platform builds and the actual image smoke test passed. Desktop installers are unsigned and not notarized; automatic updates are disabled. Windows/macOS installation on physical machines has not been certified. Linux portable binaries use the Ubuntu 24.04 runtime baseline.

Verify downloads with SHA256SUMS; SOURCE records pinned source revisions. Later main-branch features are outside this immutable snapshot.