Skip to content

Ternilo v0.2.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 05:10
· 16 commits to main since this release

Ternilo v0.2.0

本版完善多电脑工作台、账号与自动化身份,以及跨电脑和托管会话的模型授权。

工作台与电脑

  • 默认按电脑分组,在线状态显示在电脑行。可选择只显示在线电脑,后端按需加载对应工作区、会话、搜索和归档;切回全部后再加载其余内容。
  • 会话切换使用缓存和增量续读,长单轮思考保留完整开头;停止并发送支持持久队列续发。目标仅由用户显式 /goal 启用。
  • 电脑使用系统生成的固定 ID 与可修改的唯一名称。支持详情、备注、暂停/恢复、吊销、保留历史的移除登记及恢复原身份;普通重连保留原电脑身份。
  • 本机、Server 与可选 Worker 使用分类配置/数据目录;Server 和 Worker 通过 --config-dir 指向配置目录。ternilo serve --open-browser 在服务就绪后打开浏览器。
  • 单用户模式隐藏注册入口,切换页面关闭旧菜单;改进慢响应时的模型菜单稳定性与 Worker 目录读取等待。

身份与模型

  • 本站密码与 OIDC 会话统一管理,支持活动信息、稳定刷新身份和撤销。
  • 原生账号可在用户设置验证当前密码后自助改密,撤销已有本站浏览器登录并保留身份、电脑与资源。
  • 实例所有者可配置 SMTP;账号支持邮箱验证及一次性邮件密码找回,包含 OIDC 登录返回、请求限流和旧登录撤销。
  • 原生账号支持验证器与一次性恢复码;密码和关联 OIDC 登录均验证第二因素,邮件改密保留 MFA,并提供私有运维恢复。
  • 跨电脑模型转发支持整月汇总与 CSV,独立保留执行电脑、来源电脑、提交者和模型所有者,区分逻辑请求与实际重试。
  • 设备直连 Provider 用量支持整月汇总和 CSV 导出,保留未知计数及上报覆盖率,包含所有明细分页。
  • Server 模型请求支持全站和实际提交账号的滚动频率/并发限制、账号默认值和普通/服务账号覆盖;平台模型、账号 Provider 与电脑转发共用准入,超限返回 429 和重试提示。
  • 服务账号拥有独立凭据、空间范围和工作区显式授权,支持 HTTP、Live、Python/TypeScript SDK 及模型工具任务。
  • Server 远程会话可使用另一台电脑的模型:执行电脑运行工具,来源电脑使用自己的 Key 调用上游,Server 授权与转发。支持跨 Server 流式传输、取消、重试许可及独立设备用量记录;不开放独立客户端的本地跨电脑入口。
  • 托管协作者可明确提供自己的账号模型或平台授权。模型提供者、实际提交者与资源原所有者分别校验、记账,包含服务账号;来源撤权停止调用,不回退同名模型。Worker 不取得上游 Key。
  • 支持团队资源管理权交接,保留原存储和执行身份;这不等于迁移文件或跨主机接管。
  • Claude 模型发现核对官方路径、鉴权和分页;失败提示区分上游状态、连接、超时和目录格式,不暴露凭据或原始错误正文。
  • 搜索插件增加 Brave 和 Tavily,沿用 SearXNG 的结果展示,支持凭据引用、请求取消、有界结果和安全错误提示。
  • 外部 ACP 代理支持凭据引用、显式认证及模式选择;提供 Gemini CLI 和 Claude Agent ACP 配置示例,并验证实际程序的 ACP v1 握手。
  • Claude 可显式启用供应商托管搜索/读取,支持暂停续传、引用保存、本机工具混用和保守预算预留;本机、Server、电脑转发及模型专用客户端四条路径已验收。
  • SQLite 写请求使用独立队列,保留读取连接,修复持续模型负载下的写锁 500;增加并发读取、模型流式/取消和持续写入验证。
  • Wasmtime 更新至 48.0.5,依赖安全检查通过。

交付与边界

提供 Linux x86_64/ARM64、Windows x86_64/ARM64、macOS Apple Silicon 和 macOS Intel 的 CLI/Server 程序及 Desktop 安装器。Windows 程序归档为 ZIP,Linux/macOS 为 tar.gz;桌面提供 DEB/AppImage、Windows x86_64 EXE/MSI、Windows ARM64 EXE 和 DMG。

Server 镜像为 ghcr.io/mosttt/ternilo-server:0.2.0,平台 linux/amd64/linux/arm64。附带 Compose 直接拉取镜像,不需要本地构建。校验来源和镜像摘要见 SOURCE、SHA256SUMS 与 server-image.txt。

Server、Node 与可选 Worker 使用同一版本,执行器协议为 48。桌面安装器尚未进行发行者签名/公证,自动更新未启用;资源搬迁/存储故障转移与更大规模、长时间容量验证继续按计划推进。电脑凭据轮换后移,ternilo-work 仍为设计预留。

核心流程已在 SQLite、受限 PostgreSQL、真实浏览器、双 Node/双 Server 及 Bubblewrap Worker 中验收。构建与公开产物以此版本的 GitHub Actions 和 Release 实际结果为准。


Ternilo v0.2.0

This release expands the multi-computer workbench, account and automation identities, and model authorization for remote and managed sessions.

Workbench and computers

  • Computer grouping is the default, with status on the computer row. Online-only filtering loads matching workspaces, sessions, search and archives on demand; choosing all computers loads the rest.
  • Session switching uses cached history and incremental updates. Long thinking turns retain their beginning; stop-and-send supports durable queued continuation. Goals require an explicit user /goal.
  • Computers have immutable generated IDs and unique editable names. Management includes details, notes, pause/resume, revocation, history-preserving removal and identity recovery. Normal reconnection retains identity.
  • Local, Server and optional Worker instances organize configuration and data into directories. Server and Worker accept --config-dir; ternilo serve --open-browser opens the browser after readiness.
  • Single-user mode hides registration. Navigation dismisses old menus; model menus remain stable during refresh, and Worker inspection waits follow command deadlines.

Identities and models

  • Native-password and local OIDC sign-in sessions share management, activity information, stable refresh identity and revocation.
  • Native accounts can change their password after verifying the current one, revoking existing site browser sign-ins while preserving identity, computers and resources.
  • Owners can configure SMTP for email verification and one-time password recovery, including OIDC return navigation, request limits and old-session revocation.
  • Native accounts support authenticators and one-time recovery codes, enforced for password and linked OIDC sign-ins. Email password recovery retains MFA; private operator recovery is available.
  • Forwarded-computer model usage adds monthly summaries and CSV with execution/source computers, submitters and model owners retained, and logical requests separate from retry attempts.
  • Direct-device Provider usage includes full-month summaries and CSV export with unknown counters and reporting coverage preserved across all detail pages.
  • Server model traffic supports platform and actual submitting-account rate/concurrency limits, defaults and user/service-account overrides. Platform, account Provider and forwarded-computer calls share admission, with HTTP 429 and retry hints.
  • Service accounts have separate credentials, space scopes and explicit workspace grants, covering HTTP, Live, Python/TypeScript SDKs and real model/tool tasks.
  • Server-managed remote sessions can use another computer's model. The execution computer runs tools; the source computer calls its upstream with its own key. Server authorizes and relays streams, including across Server instances, with cancellation, retry permission and separate device usage records. Standalone local clients do not gain a cross-computer entry.
  • Managed collaborators can explicitly provide their own account models or platform grants. Model owner, actual submitter and original resource owner remain distinct, including for service-account tasks. Revocation stops calls without same-name fallback. Workers receive no upstream key.
  • Team resource management can be handed over while preserving storage and execution identity; this does not migrate files or provide storage failover.
  • Claude discovery follows the official endpoint, authentication and pagination contract. Safe diagnostics distinguish upstream status, connectivity, timeout and catalog-format failures without exposing keys or raw error bodies.
  • Search plugins add Brave and Tavily alongside SearXNG, with credential references, cancellation, bounded results and safe error messages.
  • External ACP agents support credential references, explicit authentication and session modes. Gemini CLI and Claude Agent ACP profiles include actual ACP v1 startup verification.
  • Claude can explicitly enable provider-hosted search/fetch, with pause continuation, persistent source links, local tool mixing and conservative token reservations across local, Server, forwarded-computer and model-only client paths.
  • SQLite writers use a dedicated queue while retaining read connections, fixing lock-related HTTP 500s under sustained model load. Repeatable read, streaming/cancellation and write-load drivers are included.
  • Wasmtime is updated to 48.0.5 and dependency security checks pass.

Delivery and boundaries

CLI/Server programs and Desktop installers cover Linux x86_64/ARM64, Windows x86_64/ARM64, macOS Apple Silicon and macOS Intel. Windows archives use ZIP; Linux/macOS use tar.gz. Desktop formats are DEB/AppImage, Windows x86_64 EXE/MSI, Windows ARM64 EXE and DMG.

The Server image is ghcr.io/mosttt/ternilo-server:0.2.0 for linux/amd64 and linux/arm64. The attached Compose file pulls it directly, without a local build. SOURCE, SHA256SUMS and server-image.txt record source identity, checksums and the image digest.

Server, Node and optional Worker use matching versions and executor protocol 48. Publisher signing/notarization and automatic desktop updates remain unavailable. Resource migration/storage failover and larger, longer capacity validation remain planned. Computer credential rotation is deferred; ternilo-work remains a design reserve.

Core flows were verified with SQLite, restricted PostgreSQL, real browsers, two Nodes/two Servers and a Bubblewrap Worker. Actual build and public artifact status is determined by this version's GitHub Actions and Release results.
Server image: ghcr.io/mosttt/ternilo-server:0.2.0 (linux/amd64, linux/arm64).