Skip to content

OpenRig v0.6.7

Choose a tag to compare

@mvschwarz mvschwarz released this 08 Oct 12:46
· 33 commits to main since this release
b3c3c85

OpenRig 0.6.7

0.6.7 is about the first hour. When your agent installs or starts OpenRig, it now opens the OpenRig TUI and the kernel's operator in front of you as the next step, laid out for your terminal's width. rig setup installs herdr for that view, the kernel's operator stops asking permission for routine checks, and a message or wake no longer answers a question that is waiting for you. Forty-two of this release's 120 changes came from ten outside contributors.

npm install -g @openrig/cli

It is built from main at b3c3c857 (after #1014). Work merged to main after that point isn't in this release. If something breaks for you, please open an issue.

Before you upgrade

Restart the daemon after upgrading the CLI. The running daemon keeps its old build until it restarts: run rig daemon stop, then rig daemon start. On its first start the daemon:

  • runs two database migrations: it records each team's install folder (#901) and adds a table that maps a Slack ask's thread replies back to the ask (#947);
  • installs the bundled openrig-core plugin at version 0.1.8 (#928, #965, #972, #975). Running seats pick it up when they next launch;
  • copies two skills for your own Claude Code and Codex sessions into ~/.claude/skills and ~/.agents/skills: rigs, which takes an agent from installing OpenRig to a team doing the work (#967), and refocusing (#928). They're refreshed on every upgrade. A rigs copy you added earlier with npx skills add has no OpenRig marker, so it's left alone and not refreshed; remove it if you want OpenRig to keep it current.

rig setup installs herdr by default on macOS and Linux, by running herdr's own installer (curl -fsSL https://herdr.dev/install.sh | sh, into $HERDR_INSTALL_DIR or ~/.local/bin). Pass --no-herdr to decline it. If the install fails, setup warns and the view uses plain tmux. On a Mac, setup offers Ghostty once and installs it with Homebrew only when you pass --ghostty; --no-ghostty declines. Setup no longer installs or configures cmux, and an existing cmux keeps working. In rig setup --json, the cmux_install step is gone and herdr_install and ghostty_install appear (#936).

rig terminal open <view> opens a desktop window by default. To add tiles to a herdr or cmux workspace that is already open, pass --provider herdr or --provider cmux (#954). The default saved:kernel view's layout now depends on your terminal's width; a kernel view you saved yourself still wins (#978, #998). If you have your own herdr config, OpenRig uses it unchanged (#969, #998).

rig doctor checks Claude Code and Codex installs, and a login or configured provider credential for each, the way rig setup does, and exits 1 when either is missing or has neither, including a harness you don't use. Its output, and --json, gain claude_install, claude_auth, codex_install and codex_auth rows. A pass means a login or configured provider credential is available locally, not that a provider accepts the credential or that an agent can work (#924).

Defaults that changed:

  • agents.advisor_session now defaults to the kernel's advisor seat, which every install has. rig restore-packet write without flags targets the seat's own rig (#937).
  • rig bundle create, and rig up <GitHub link>, name a bundle after the name in its rig.yaml instead of my-bundle or github-bundle; --name still wins (#985).
  • A periodic reminder first fires one interval after you register it, not immediately (#860).
  • rig package validate, plan and install resolve relative paths, and the default --target ., from the folder you run them in, not the daemon's (#754).
  • Managed Codex launches pass -c check_for_update_on_startup=false, so a Codex seat doesn't stop at Codex's update offer. Updating Codex is left to you or the operator (#986).

Claude seat settings that OpenRig rewrites: at a Claude seat's next launch, its status-line command in .claude/settings.local.json is written with quoted paths (#852), and its activity hook points at $OPENRIG_HOME/state/claude-activity-hooks/ instead of a script inside the project (#870). Claude team seats get a command hook in their launch settings that lets lifecycle help run without a prompt (#927), and the kernel's Claude seats get it too, with a wider allowance (#983). No settings file is written for either.

Highlights

Your agents open in front of you. After your agent installs or starts OpenRig, it now opens the OpenRig TUI and the kernel's operator for you as the next step, with rig terminal open saved:kernel --window, instead of waiting for you to ask (#998). The same command brings your agents back later.

  • The layout follows your terminal's width. Under 120 columns the operator fills the first tab; from 120 columns the dashboard and the operator share it; the advisor always has its own tab (#978, #998).
  • It opens where your agent runs. Inside herdr it opens as a focused openrig kernel space; in Terminal as a new window that copies the size of your front window when it can; in Ghostty as a new tab. From Claude Desktop, iTerm or VS Code on a Mac it opens a new Ghostty (1.3 or newer) or Terminal window at that app's default size, and macOS may ask you to allow that (#970, #998). On a Linux desktop it uses GNOME Terminal, Konsole or xterm and asks for a readable size (#952, #970). Opening the same herdr view again reuses the open workspace (#957), and your existing windows are never resized (#958).
  • When no window can open, over SSH, in CI or with no display, the command says why and prints the exact command to run instead (#954, #970).
  • In the TUI, the Open terminals action uses the same launcher, works without herdr, and shows per-seat attach commands when no window can open (#959).
  • Your own agent knows how. The rigs skill, now installed for your Claude Code and Codex sessions (#967), carries the whole route from install to the operator: when the install is finished, how to hand the operator your goal, folder and branch, how to relay the operator's questions to you, and what to give you when no window can open (#909, #964, #971, #982, #988). CLI help, setup's next steps and onboarding point "show me my agents" and "the welcome screen" to the same command (#950).

Install with one command, preview first. The README, the getting-started guide and the help guide show a one-command install with a stable link, and a --dry-run preview that prints its four steps and changes nothing. If only provider sign-ins are left, the install itself finished (#917). If the agent installing OpenRig has a tool call refused by its own permission rules, the guides tell it to show you the refusal rather than report a failure (#950).

Fewer permission prompts.

  • In Claude team seats, help on lifecycle commands, such as rig down --help and rig bundle install -h, runs without a prompt, and common spellings of allowed commands match too (quoted or absolute paths, env, command and exec, a project's vitest and jest). Real lifecycle actions still ask (#927).
  • The kernel's operator runs routine inspection (cd, pwd, echo, wc, sort, python, command -v and WebFetch) without asking (#983), reads /rigs pages with WebFetch (#994), and runs its first-boot checks as separate commands (#932).
  • Setup's permission question now matches the team default: it recommends keeping it and offers extra remembered allowances only if you want them (#916). If prompts are slowing you down, the operator and the guides point to the workshop team and say plainly what access it takes (#939).

A wake no longer answers a question for you. When a Claude seat is waiting at a question menu or an approval that OpenRig can't read on screen, a rig send or a watchdog wake is now refused if the seat's latest hook said it was waiting for you, and the wake goes up the usual escalation path. Before, the message's Enter could pick the first option (#1001). After a daemon restart, a seat waiting at an approval keeps showing as needing attention (#885).

Slack: a channel per team, reactions, long asks.

  • rig slack channel-map set <rig-or-seat> <channel>, list and remove send a rig's or a seat's posts to its own channel. A seat entry wins over a rig entry; anything unmapped uses the default channel. rig slack verify checks the app is in every mapped channel, and the TUI shows the map (#944).
  • An emoji reaction on any message OpenRig posted for an ask now reaches the agent that asked, as a task saying who reacted and with what. It doesn't answer or close the ask. An existing Slack app needs the reactions:read scope and the reaction_added event added, then a reinstall; rig slack verify warns while the scope is missing; it doesn't check the event (#931, #947).
  • An ask too long for one message is posted as numbered replies in its thread. If it still can't be posted, the agent gets a task saying so instead of the ask silently not arriving (#929).
  • A reply sent with "Also send to #channel" ticked now reaches the agent that asked (#910). If Slack's connection stalls while reconnecting, the daemon retries instead of going quiet (#942).

What changed, written for your agents. An agent on an upgraded install can read what behaves differently, and what to do, with rig context get reference/whats-new.md (or $OPENRIG_HOME/reference/whats-new.md with no daemon running). The openrig-upgrade skill ends by reading it and telling you what affects you (#934, #1010). The capability map agents read to learn what OpenRig can do is refreshed for 0.6.6 (#905) and 0.6.7 (#1010).

Handover, compaction and refocus.

  • rig seat handover <seat> works on the same seat again and again, and running it again recovers a seat left half handed over (#987).
  • The handover and compaction skills teach seats to write their recap with rig context recap-write before a handover or compaction (#1002). A seat taking over from a Codex predecessor now sees its messages in the recap (#848).
  • After a managed Claude compaction, the seat's refocus context arrives with the restore request instead of being lost to the acknowledgement prompt, also when the request arrives wrapped as pasted text. If refocus fails three times in a row for a seat, one issue appears on the stream (rig stream list --tag refocus) (#928, #972, #975).
  • The daemon itself moves a finished restore map into place before compacting, so the seat no longer needs a shell rename that could stop at a permission prompt (#965).

Teams you can find and share. The built-in starter and factory leads publish their team's roster at first start, so rig roster find <topic> knows those teams (#918). While presenting the first-team choices, the operator shows each team's graph in the shared TUI (#948). rig bundle check names the file in each finding (#985). rig context add --git retrieves only the current commit by default, falling back to a full clone with a warning when the server refuses, and the docs name openrig-registry as the place to submit a team (#951).

Behaviour changes to know about

  • Bundles. Reinstalling over a stopped team backs up and replaces conflicting files only in the folder the team was installed into; another folder gets first-install behaviour, refusing conflicting files before anything is written. Teams installed before 0.6.7 have no recorded folder until their next bundle install (#901). rig bundle install --skip-version-check --force still runs the bundle's safety check (#876). A bundle install refused for a conflicting file returns HTTP 400 with a code, and other known refusals carry theirs with 409 (#926).
  • Queue. Claiming a parked task clears its blocker; rig queue update <id> --state blocked without --blocked-on re-parks it on the previous one (#761). A parked task's wake shows when it will really fire, never as a 1970 date (#946). An invalid --wake-after, such as 7d, prints an error instead of exiting silently; use hours, such as 168h (#945).
  • Workflows. When a step that was sent back completes again, the steps that depend on it run again, including ones that had passed (#817). rig workflow resume --occurrence with an ID that matches no unresolved failure is refused instead of redriving a different one (#757). rig workflow run and watch exit 3 for an aborted run instead of waiting forever (#847). rig workflow validate, instantiate and run use the file in your current folder (#845).
  • Exit codes and output. rig down --host exits 2 when the remote teardown reports errors (#756). Human-mode rig down prints one line with each agent's last known activity before stopping (#922). rig chatroom wait --timeout exits 1 at its deadline instead of printing a late message (#968). rig chatroom history --since with a value it can't read fails instead of printing "No messages." (#930), and the error shows control characters as text (#991). rig skill audit passes on a clean install, with new --json fields (#807). rig spec validate reports malformed pods, members and edges as ordinary errors (#846). rig gateway human messages say OpenRig supports one configured human (#961).
  • Seat inventory. A running seat whose current pane fails its identity check reads attention_required; the stored startup result moves to storedStartupStatus, and rig restore-check names the verdict and what to do (#940).
  • Context addresses. In rig context get <pack>/<file>#section, an inline triple-backtick span no longer hides later headings, and an empty heading ends the section above it (#962).
  • Missions. A mission can declare arrangement.source.integration_ref in mission.yaml so rig view execution checks landed work against that ref instead of main; a ref that's invalid or can't be resolved reads INDETERMINATE (#682).

Dependency and install-script changes

  • npm dependencies: none added, removed or changed. The package's dependency ranges and every external entry in the lockfile are the same as in 0.6.6; only OpenRig's own package versions moved to 0.6.7 (#1005). The Node requirement is unchanged (node >=22).
  • Install scripts: unchanged. The package's only lifecycle script is still postinstall: node scripts/check-abi.mjs.
  • rig setup runs a third-party installer by default: herdr's (curl -fsSL https://herdr.dev/install.sh | sh), unless you pass --no-herdr. It runs brew install --cask ghostty only with --ghostty, and no longer installs cmux (#936).
  • The repository's install script (scripts/install.sh, not in the package) is now published with a stable link (#917); its closing and plan text changed (#916, #950).
  • Database: two migrations, 096_rig_install_root (#901) and 097_thread_part_map (#947).
  • Bundled plugin: openrig-core 0.1.8 (#928, #965, #972, #975).
  • Files OpenRig writes outside your project: the rigs and refocusing skills in ~/.claude/skills and ~/.agents/skills (#967, #928); a per-seat refocus health file under $OPENRIG_HOME/refocus/ (#928); the Claude activity relay under $OPENRIG_HOME/state/claude-activity-hooks/ (#870); and, only when you have no herdr config, a private .openrig-herdr-<hash>.toml in herdr's config folder (#998). Files generated under .codex/plugins/shared:openrig-core/ are added to the repository's .git/info/exclude block (#919).

Everything else since 0.6.6

Kernel, setup and first run. The operator explains a Codex seat that needs a newer Codex and offers to update it (#916). For "stop everything", the operator and the getting-started guide give the order: each rig with rig down, kernel last, then you run rig daemon stop (#932). Help examples and reference guides no longer use retired team names (#935).

Claude. OpenRig reads a Claude seat's session from its process correctly when permission settings are passed inline, so a running seat isn't misread as needing attention; this fixes 0.6.6's known issue #921 (#933). The resume token is quoted when OpenRig types a resume command (#798). Guidance text containing $$ or similar stays as written when OpenRig rewrites its managed blocks (#908).

Codex. A sign-in or incompatible-client notice that appears at the last moment of a Codex restore is reported as needing attention with the screen's last lines, and a late "no saved session" retries fresh (#759). OpenRig finds a Codex seat's conversation when its home path contains spaces (#851).

Pi. Launch preflight reports the Pi version against the tested baseline, and a Pi seat says at start whether it has a stored sign-in or provider key, and how to provide one (#938). Pi seats on minimax/<id> models can receive MINIMAX_API_KEY when it's in recovery.provider_auth_env_allowlist (#891).

Launch, restore and seats. rig up restores a seat that was launched fresh and then stopped with a clean rig down, instead of refusing with no_snapshot (#955). A plugin skill copy whose remembered source can no longer be projected is kept, with a plugin_skill_kept warning, instead of failing the launch; a seat selecting that plugin refreshes it at its next launch (#819). Seat, node, pod and agent-image names containing % are looked up correctly (#844). Discovery and capture keep tmux session names containing | or edge spaces (#752), and OpenRig reads a seat's launch settings from exactly its own tmux session (#755). rig terminal open waits up to 45 seconds for a larger view to finish opening instead of reporting a timeout at 5 (#758). With the web UI on, a terminal view that fails to attach closes that viewer instead of stopping the daemon (#907).

Chat, usage, transcripts and retention. rig chatroom watch keeps messages in order while switching from history to live (#760). rig usage top no longer mixes up seats that reused a name (#835), and rig usage series --since/--until compare times as moments, not text (#840). rig transcript --tail and --grep read a consistent copy while the file is being replaced (#843). Watchdog history keeps the right entries at tied timestamps (#753), and a very long snapshot history no longer breaks retention (#836).

Scope. rig scope slice move, ship and close work when the workspace path starts with - (#974), don't change a mission's membership when they fail (#976), and check the slice folder by its literal path (#1003). rig scope mission create and slice create copy your text exactly (#977), frontmatter updates keep keys, comments and quoting as written (#979), and a bare slice name with --mission resolves past an unrelated folder of the same name (#1004).

Projects. A project declared at / no longer ties with a deeper project when OpenRig picks one from your working folder (#857).

TUI. A rig, host, pod or agent address works from any page (#984).

Docs. The reference guides were brought to the 0.6.6 release (#903), the architecture docs restamped to it (#902), and CHANGELOG.md gained its 0.6.6 section (#906). The getting-started guide covers kernel seats that fail at first start on a tmux build that crashes, with a check and a recovery (#999). WSL2 is the way to run OpenRig on Windows: the guide records one user's working setup and both ways a Pi seat can get credentials (#960, #963). The README and reference guides were brought to 0.6.7 (#1009).

How it was tested

  • The final package: openrig-cli-0.6.7-b3c3c857.tgz, 4,126 files, SHA-256 07b71126eeb849afa3dde9350e7b603bc8a774eabcd75aad779f191b901a65ab, built from b3c3c857. Compared file by file with the pre-release build below, 17 files changed: the packaged reference guides, what-changed note and capability map from #1009 and #1010, and the two build stamps. No code changed. Installed into a fresh Linux server: the CLI and daemon reported 0.6.7 at b3c3c857, clean; rig ps, help and specs ran; the starter and factory launch plans listed 2 and 7 seats; the workshop's create, inspect and install plan from the current registry passed; and the installed package served the 0.6.7 what-changed note and the capability map for 0.6.7. No agents were launched in this check. The automated tests passed on b3c3c857.
  • The pre-release build at 2caac7dd (version 0.6.7): 4,126 files, SHA-256 2ce1d1c6b4768970af1711bbbaec50cb482a279a54454a202bb4ce57150eedac. Compared with the earlier candidate build at 7bdc0736, exactly 79 files changed, all traced to #1001, #1004 and the version change. Installed into a fresh Linux server: the CLI and daemon reported 0.6.7 at 2caac7dd, clean; rig ps, help and specs ran; the starter and factory launch plans listed 2 and 7 seats; and the workshop's create, inspect and install plan from the current registry passed. No agents were launched in this check. The automated tests passed on 2caac7dd, the pre-release build's source.
  • Opening your agents: journeys from a natural first prompt with herdr, Terminal and Ghostty, and the handoff after install on a test Mac, where the view opened without being asked within 15 seconds.
  • Sharing a team: the share journey passed, and a merged registry listing reached openrig.dev/rigs.
  • The kernel operator's allowances: in a live Claude session on main, the operator hit one prompt in nine calls (#983).
  • Help without a prompt in Claude team seats: one selected lifecycle-help command was checked in a live Claude session; source and parser coverage is broader (#927).
  • Refocus after compaction: checked on a fresh test install.
  • Not tested: the full first install from nothing; Linux desktop windows; opening the view from Claude Desktop; the plain-tmux layout without herdr; live Slack for the channel map, reactions and long asks; Pi seats beyond automated tests; Windows and WSL2 in automated tests.

Known issues

  • Not yet proven on a real machine: opening the view from Claude Desktop, and the plain-tmux layout without herdr. The full first install from nothing, and a Linux run, come after this release.
  • Help without a prompt has been checked in a live Claude session for only one selected lifecycle-help command (#927).
  • Codex team seats don't yet ask before lifecycle commands such as rig up and rig down. Claude Code team seats do.
  • The send gate trusts the latest recorded hook. If a seat's hooks are recorded out of order, a send can be held for a question that's already answered, or let through to one that's waiting. A fix is planned for the next release.
  • A Codex seat whose permission request was approved automatically can still read "needs input" (#896).
  • A launched team still writes its skills into its working folder.
  • rig scope mission approve writes its stamp into the daemon's workspace and ignores --workspace (#995). The fix follows this release.
  • After a restart, rig status shows Kernel: skipped whatever the kernel seats' state. Read them with rig ps --nodes --rig kernel --full.
  • rig doctor fails for a harness you don't use. Only the harnesses your teams use need a login (#924).
  • Slack channel map: replies are matched to a thread by its timestamp alone, so two mapped threads with the same timestamp in different channels could route a reply to the wrong seat. Missed-message recovery covers the default channel only, and private channels and direct messages aren't supported targets (#944). A reaction on a reply in an ask's thread, rather than on OpenRig's own messages, is ignored (#931).
  • openrig.dev/rigs doesn't yet show what OpenRig tested for each team, and has no Pi badge. That follows this release.
  • Refocus after compaction hasn't been proven on a long-running install.
  • The starter's Codex reviewer needs a Codex newer than 0.145, as in 0.6.6. The operator now offers to update Codex.
  • A restore can report a problem with a seat that works (#273), as in 0.6.6.
  • A claude alias or function defined only in a nushell rc doesn't resolve for classic Claude launches, as in 0.6.6.
  • After a reboot the daemon doesn't come back on its own. Start it with rig daemon start, then bring your rig back with rig up <name> --existing.
  • The web UI's file preview runs scripts, as in 0.6.6. The web UI is off by default; preview only files you trust.
  • Browser access protects against unknown web pages and names. It isn't complete browser isolation, so keep the daemon on loopback or your tailnet.
  • Codex network inside the sandbox hasn't been checked with real logins, managed policy bundles or on Linux, as in 0.6.6.

Thanks

To the people whose pull requests are in this release: @awss1i, @bobbiejaxn, @bpamiri, @Coder8124, @DeryFerd, @lab1207, @oodadoudou, @opencode13241-eng, @rudycelekli and @tianqizhao0704.

And to the people whose reports shaped fixes here: @aanestesia (#402), @AdamWhitehurst (#809, #953), @csaxton171 (#996), @d3fvxl (#774, #801, #802), @dajiaohuang (a working WSL2 setup, on #88), @floynk-agent (#897, #899), @HSJ-BanFan (#921), @jajabong (#914, #915), @jmrichardson (#88), @Kero-66 (#981), @MichelMabinuola (#980), @mlc-factory-bot (#192), @puniserv (#875), @readybuilderone (#194) and @z4cc (#739); and to @adampog and @oSquashBlossomo, in whose forks two of these fixes were first found (#908, #907).