Skip to content

OpenRig v0.6.2 — first-project and recovery fixes

Choose a tag to compare

@mvschwarz mvschwarz released this 30 Sep 05:32
· 134 commits to main since this release
f8f3aff

Published: @openrig/cli@0.6.2 is available on npm as latest.

npm install -g @openrig/cli@0.6.2

OpenRig v0.6.2 — first-project and recovery fixes

Choose your providers, give an owner one useful change in your repository, and
have a second agent check the result. OpenRig 0.6.2 adds first-project choices,
clearer permission guidance and repairs for bundle installation and agent delivery.

A small team and one useful result

The first-use guide offers the same owner and
checker workflow with three recipes:

Team Recipe
Two Codex agents first-project
Two Claude Code agents first-project-claude
Claude owner and Codex checker first-project-mixed

Use the accounts you already have; an unused provider's installation or login is
not a prerequisite. Codex seats retain gpt-6-astra; Claude seats use the native
configured default. Check model access before launching. Automatic kernel startup
continues to select independently from available authenticated providers.

Agent-guided setup asks once whether to allow OpenRig commands without repeated
permission prompts, with Yes recommended. An explicit Yes authorizes native
rig command rules at personal project scope unless you choose user-wide scope.
No or no answer leaves settings unchanged. The allowance includes lifecycle and
configuration commands, but does not grant general shell access or change sandbox
and network settings. The guide covers applying, checking and undoing the rules;
bootstrap does not silently apply them
(#147).

Bundle files stay where you install them

Schema-version-2 bundles now copy their verified contents into --target and
launch from there, keeping relative working directories and agent references
available after temporary extraction is removed. Different files at a bundle
path cause target_conflict before copying; identical files can be reused.

Without --target, rig up <file>.rigbundle installs into your current directory, so run it from the project folder you want.

rig bundle create|inspect|install and local rig up --target resolve relative
paths against your current directory. Files still live on the daemon's host;
this is not an upload. Install launches the rig. Legacy version-1 behavior and
the separate --cwd override are unchanged. See the
bundle guide
(#146).

Delivery and restore diagnostics

Managed launches after a tmux/host restart preserve the named launch target
instead of confusing it with an old bare pane binding. The existing identity
checks still apply to each write. Thanks to
@diaztunjano for reporting
#141, addressed by
#151. Actual reboot and power-loss
recovery remain subject to the verification limits below.

Message delivery now refuses a known bare-shell foreground when an agent runtime
should be running, so the message is not entered as shell commands. Terminal-only
seats still receive text; unreadable or unknown foregrounds retain the existing
advisory behavior (#150, fixes
#142).

Community fixes

  • Local sender identity: recognize a sender qualified with this daemon's own
    host ID as its local seat, avoiding false ownership refusals. Foreign host
    qualifiers and destination handling stay unchanged. Thanks to
    @korallis for
    #135, and
    @Yi-111-a for the additional cases from
    #137, included through
    #144.
  • Terminal and status details: parse tmux window fields with printable
    separators (#101); distinguish
    health that was not requested from a failed read
    (#102); use native realpath for
    Codex hook trust (#103); pass
    known Claude/Codex runtime hints to Herdr
    (#106); report missing fresh
    startup context or adapters as needing attention
    (#107); accept numeric Claude
    rate-limit reset timestamps (#108).
    Thanks to @dajiaohuang.
  • Pi input and portable checks: retain line editing with TERM=dumb, and
    correct macOS path and timezone assumptions in tests. Thanks to
    @shravansumanthanan for
    #123.
  • Configured restore paths: restore-check uses the configured shared-docs
    root. This does not repair every issue in
    #130. Thanks to
    @jbaehova for
    #139.
  • Anthropic gateways: permit ANTHROPIC_BASE_URL in configured provider-auth
    environment forwarding. Thanks to @FenjuFu for
    #143.
  • Terminal authentication maintenance: reuse the shared token-comparison
    helper. Thanks to @Sunil56224972 for
    #145.

Also in this release

  • Mixed Claude/Codex projects: shared skills are now also placed where Codex
    looks for them, even when a matching Claude copy exists. Edited Codex skills are
    kept unless you force an overwrite. Thanks to @a4w-h4y
    for diagnosing #159, fixed by
    #162.
  • Slow polling no longer piles up: identity and transcript polling no longer start
    overlapping work on every tick when a sweep runs slowly. This prevents accumulated
    overlap; it is not a measured overall CPU reduction, and polling cadence is
    unchanged. Thanks to @korallis for reporting
    #161, addressed in part by
    #169.
  • Codex behind managed shell wrappers: messages and queue nudges reach a ready
    Codex seat launched through a managed shell wrapper, instead of being refused as a
    bare shell. The existing process-identity and input-readiness checks are retained
    (#171).

Upgrade and verification limits

Node.js 22 and 24 remain supported; Node 20 is unsupported. This maintenance
change adds no dependency, engine or database-migration change. Follow the
existing upgrade procedure.

Verified on an installed 0.6.2 test machine: a two-agent Codex team (owner and
checker) completed a native handoff, an independent review and the owner's closure.
After a graceful reboot, and again after a hard power-off, the same Codex pair resumed
useful, reviewed work. Recovery used a manual daemon start and resuming the existing
rig; it was not automatic. Checked task files, queue records and saved history prefixes
were preserved, but a checkpoint written just before the hard power-off was lost, so
this is not a general crash-durability guarantee.

Not yet verified: Claude-only and mixed-runtime starters; the scope, loading and
revocation of the OpenRig command-permission rules; and any overall CPU improvement.

Slack app manifest/setup assistance and Rig Stream classification remain
experimental, with no new real-app or provider-run validation here. The existing
Slack connector is not experimental. See the
retained limitations.

Release commit: f8f3aff68bf425735173df9e2c5ac5ef19716f5b.