Skip to content

OpenRig v0.6.4

Latest

Choose a tag to compare

@mvschwarz mvschwarz released this 02 Oct 05:45
· 225 commits to main since this release
6342862

OpenRig 0.6.4

0.6.4 is the code tested and published as the 0.6.4-rc.1 release candidate, now the normal release. Only its version and these notes changed.

npm install -g @openrig/cli

It was cut from main at afde814f, and since then it has changed only by the bounded changes described here: the repairs below, the web UI default, and browser access with its docs page. If something breaks for you, please open an issue.

Two changes you might notice

The web UI is off by default. The daemon no longer serves the web UI's pages or its terminal connection unless you turn it on with rig config set ui.enabled true and then stop and start the daemon. While it's off, opening the page shows those steps, and rig ui open prints them. The web UI is in maintenance mode; the CLI and the TUI are the supported ways to use OpenRig.

The daemon checks which address and which web page a request comes from. Nothing changes for the CLI, the TUI, agents, the queue, Slack, or other OpenRig hosts that reach this machine by its IP address, its own hostname or its own Tailscale name. Two cases now need one setting:

  • If you reach the daemon by a custom DNS name, an /etc/hosts alias or a reverse-proxy domain, add that name to OPENRIG_ALLOWED_HOSTS.
  • If a local app or development server on another port calls the daemon from a browser, add its origin to OPENRIG_ALLOWED_ORIGINS.

Each refusal says which setting to add, and both need a daemon restart. The details are in Browser access and allowed addresses (#358, #372).

Repairs made after the candidate was cut

These repairs went into the candidate after it was cut.

  • Bundles keep binary files intact. rig bundle create re-encoded binary files in agent packages (#245, #257).
  • Local commands reach the daemon you started. A daemon started with rig daemon start --port is now the one other commands talk to (#246, #266).
  • A rig's only seat can be relaunched fresh. rig seat launch --fresh --stop on a single-seat rig no longer refuses after stopping the seat ended the tmux server (#265, #267).
  • More time for Claude's capability check. A managed Claude launch with an explicit permission mode first reads claude --help. That check now gets five seconds instead of one. Answers arriving within the longer budget can succeed; a timeout can still refuse the launch. Slow answers were reported when several seats started at once (#260, #271).
  • Seats launch after an upgrade removes the old version. Fresh launches and restores use the running version's built-in startup files instead of failing on paths into the removed install (#261, #269).
  • Claude seats take messages after a full down and up. When a managed Claude seat resumes in auto mode, it accepts ordinary messages again once OpenRig confirms the same Claude process is running in its pane. A resume it can't confirm asks for your attention instead of starting a fresh conversation (#287, toward #273).
  • Natively installed Claude is recognized. OpenRig recognizes a native Claude install behind its managed shell wrapper, including versioned install paths. When it can't observe the runtime, ordinary delivery goes ahead with a warning; a pane that is plainly an idle shell, or the wrong recipient, is still refused (#310, a follow-up to #197).
  • Restoring an older Claude seat keeps an uncertain launch. If the resume check can't tell whether the conversation came back, the restore keeps the new session and asks for attention instead of closing it (#345, #346).
  • Replacing proof files doesn't write through links. rig proof add --replace now swaps in a new file, so a symlinked or hard-linked artifact no longer overwrites the other path's contents (#307).
  • Slack keeps long messages, and retry errors stay contained. A message from a registered person is stored with its complete text; before, anything past 1,800 characters was lost. A storage error while the gateway retries undelivered events is now logged instead of escaping (#361, #375, #404).

Everything else since 0.6.3

Messaging and delivery. An unverified runtime is reported separately from a stopped agent (#240). tmux reads use printable separators and a shell-free command path (#179, #167). Native process checks no longer depend on your locale (#239). Event subscriptions cancelled during replay are released (#233). CLI request deadlines cover the whole response, and a body that fails after its headers is reported as an unknown outcome (#201).

Queue, seats and rigs. A blocked row keeps its park timer through a seat handover, and a rerouted row's periodic timer is retired (#242). Closed queue items show the right pickup state (#176). Discovery claims survive background rescans (#237). A seat launch that times out reports an unknown outcome (#191). Attaching accepts runtime guards for existing nodes (#228). Kernel Claude seats get the shared activity hooks (#178). An unset native Claude config selection stays unset (#225). Importing YAML over a stopped rig with the same name archives the old one and shows its ID and unarchive command (#196).

Files, transfer and context. SSH, rsync and Herdr output keeps UTF-8 intact across chunks (#230, #241). Local rsync directory operands are preserved (#231). Atomic file edits keep the executable bit (#235). File-shaped entries are projected instead of failing (#185). Oversized suffix ranges are clamped (#234). Headings inside fenced examples aren't treated as context addresses (#236). rig env status says when a service receipt is stale (#232).

Platform and setup. Codex readiness works with providers other than OpenAI (#222). Removing Codex activity hooks leaves the rest of your config untouched (#186). Daemon liveness on Windows no longer uses ps (#173). Module URLs and transcript paths are portable (#168). ps rows whose command name contains spaces are kept (#82).

Onboarding and repository. The onboarding text that new seats read now covers both ways a build goes wrong, and the skills router says a project, rig or machine may add its own skills (#303). Release checks skip tag diffs when old tags are absent (#152), and security and integration PRs are asked for practical scenarios (#224).

Fixes merged to main after this candidate was cut, including many community contributions, aren't in this release. They'll ship in the next release, with their credits.

How it was tested

Most installed and real-agent results below come from earlier builds of this candidate. The final package received the package-content/stock check and the affected Slack component checks; unchanged-path evidence was carried forward through checked package deltas.

  • Required checks: the integrated release changes passed their recorded CI runs. The release checks cover build and packaging, types, repository checks, package test suites and an installed-package scenario.
  • Scripted checks without real agents: installed copies of candidate builds ran the repository's scripted checks. Three known failures remain: two cases in plugin usage reporting (#251, fixed on main for the next release), and rig proof add --file dropping a leading byte order mark from the stored file (#250).
  • A fresh first-time install ran Claude-only, Codex-only and mixed teams through useful work, with seats handing work and review results to each other, then a warm resume and a graceful reboot. The tester approved the providers' ordinary permission prompts as a first-time user would.
  • Real Claude Code agents on a test server: after a full down and up, a Claude seat took and answered an ordinary message, carried on with its own queue work, and kept its conversation through a daemon restart.
  • The final package's Slack checks: tests of the installed Slack components kept long inbound messages whole. In both retry-fault cases, the gateway logged the error, kept running and delivered the event once on the next automatic retry. These used synthetic connections on Linux with the package's existing dependencies. They aren't a live Slack test or a fault trial of the whole daemon.

Tested environments, from the run receipts. Unlisted versions are not established by this summary.

Run Platform Versions
Fresh install macOS on Apple silicon Claude Code 2.1.286, then 2.1.287 after the warm resume (the launcher version changed between phases); Codex 0.159.3; Node 24.21.0
Test server Ubuntu Linux, x86-64 Claude Code 2.1.220, Codex 0.145.0
Final Slack checks Linux, x86-64 Node 22.22.1; no providers

The tested release-candidate package's SHA-256 is 5344a48a747629f71d4427ce52d24e6e1034e9097b4d5d34ec125d5396fa66b6; 0.6.4 differs from it only in its version and release notes. The 0.6.4 package SHA-256 is 251f3622587eef7f84289292a90547dec3cc5b53a89c93600c3296da91d7445f.

Known limits

  • A restore can report a problem with a seat that works. In the test-server run, rig up after a full down exited with an error, reporting that the Claude seat needed attention, while that seat went on to take and answer an ordinary message. rig restore-check also reported a failure for that rig (#273).
  • Codex under its default sandbox. In the test-server run, Codex 0.145.0 under its default workspace-write sandbox could not reach the local daemon, blocking its queue work (#275). That run did not prove cross-seat queue handoffs; its successful queue continuation was Claude working its own row.
  • After a reboot the daemon doesn't come back on its own. Start it with rig daemon start, then bring your rig back with rig up <name>.
  • Stopping the daemon can report a timeout while closing connections (#166).
  • Setup's optional cmux step can report an error.
  • Browser access protects against unknown web pages and names. It isn't complete browser isolation, so keep the daemon on loopback or your tailnet. The browser-access page lists its other limits.
  • Windows wasn't tested.

Thanks

To the people whose pull requests are in this release: @rudycelekli, @nvtoan0201-swe, @MTG-Thomas, @hobostay, @hoklims, @mvdpoel, @oodadoudou and @Coder8124.

And to the people whose reports shaped it: @m3ac-AllbrittenJ for #260 and #261, @rudycelekli for #361 and #375 and their fixes, @korallis for the park-timer finding in korallis/agent-stack#61, and @dmelo for #197.