Repository navigation
Releases: nlink-jp/lagent
Release list
v0.19.0
Added
- A model tier for write-lane shell commands (ADR-0032), opt-in with
[approval].model_tier = "shell". Under auto-approve, a judge model on the
same server decides theshell_execcalls in the write lane that the rule
tier leaves at Review, with gem-agent's prompt, two rounds and 0.8
confidence bar: approved ones run unasked, the rest are asked about with the
judge's reason. MCP calls, the operator lane and every other Review still
ask. The judge reads yourrisk-rules.mdbesideconfig.toml;
[llm].risk_modeland[llm].risk_reasoning_effort(defaultnone) set its
model and thinking. Records follow gem-agent's:auto_decisionnames the
judge's model, the bar and the confidence, and the judgment's tokens are a
riskusage record, and/settingsshows the tier and the judge. Measured
on a month of the operator's own write-lane prompts: about half would have
run unasked, and no exfiltration or injection case passed. A lookup the
operator had refused for their own reasons passed once in five until one
line inrisk-rules.mdsaid so — write such rules there.
v0.18.0
Added
- mlx-serve is a supported backend (ADR-0031), adopted on the task bench and
a server measurement with the same Qwen 3.6 weights under mlx-serve and LM
Studio: the speed comes from the MTP head of mlx-serve's own model builds, not
the runtime; a 122k-token prompt completes. The ADR records the residual risk
of running it — chiefly that 26.10.1 listens on every interface with no key
by default — and that its default 2 GB prefix cache re-reads long sessions
every turn: with an 8 GB cap a 122k resend took 1.1 s instead of 207 s. bench servemeasures a model server: cold prompt reading per size,
reuse on a resend and the next turn, decode speed, alternating conversations
and two streams at once, logged raw;bench serve-reportrecounts a run.[llm].provider = "mlxserve"for
mlx-serve. The context window is
read from its/v1/modelsat startup, so leave[model].context_windowat
0 for it — a set window skips the lookup. A[llm].modelthat list does not
carry is reported at startup: mlx-serve answers a chat request for any model
name with the model it has loaded, so a mistyped id otherwise runs silently
against whatever is resident.
Fixed
- A completion of only blank lines is asked again, as an empty one is
(ADR-0007, amended by ADR-0031). Under LM Studio, Qwen 3.6 starts its answer
with the blank lines after its thinking; one bench run's entire final answer
was\n\n, which was returned as the answer.
v0.17.1
Fixed
- A resumed session is told when it began (ADR-0030, from gem-agent
ADR-0097). The facts message sent on resume said "session started" on the
resume day, beside the restored conversation's own facts message with the day
it really began. It now reads- resumed: <day>; the conversation above began on <day>. The date is also captured once per session, so an MCP reload after
midnight no longer states a new one. - When
/clearcannot open a new transcript and clears the history in place,
a fresh facts message is sent: the clear had changed the isolation tag
without telling the model its new name.
Documentation
- The README says where an operator's procedures go: a skill arrives as
instructions, every tool result — a knowledge-vault server's notes
included — as data, so a procedure meant to be followed is a skill
(from gem-agent ADR-0096 §7).
v0.17.0
Changed
- A saved MCP result shows its tail as well as its head (ADR-0029,
from gem-agent ADR-0096 §1). A text block too large to hold inline is
previewed by its first 600 and last 200 characters, and the notice names
the byte spans shown and the route to the rest (read_file
offset/length). Metadata a server appends —"truncated": true, a row
total — arrives as the last bytes and was never visible before. shell_execkeeps the tail of long output and saves all of it
(ADR-0029, from gem-agent ADR-0096 §3). Past 20,000 bytes the model sees
the first 15,000 and the last 5,000 bytes — a script's totals come last
and used to be lost — and the whole output is saved to the work directory
(up to 32 MiB), named in the note. The runtime writes the file, privately
(0600), so no lane's reach changes. The operator lane is not saved, nor
is any lane when the shell runs without the sandbox, and the note says so.search_filescounts every file it did not search (ADR-0029, from
gem-agent ADR-0096 §4). Files over 2 MB (named, up to five), binary
files, images, unreadable files and directories that could not be listed
are counted in a closing line; size and image skips were silent, so a
"no matches" could hide a large log that was never read. Refusals past the
five named are counted too.
Added
read_filereads by bytes (ADR-0029, from gem-agent ADR-0096 §2).
offset/lengthtake a byte window — a negative offset counts from the
end — so the tail of a long single-line file is reachable, which a line
window never was: a tool result saved to the work directory past 200 KB
could not be read to its end by the tool its notice named. The note names
the bytes returned, moved to rune boundaries. A plain read cut at 200 KB
now says where to read on.
v0.16.1
Fixed
- The bench writes a suite run's request trace beside the run when
--outis a relative path. Before, the trace landed inside the run's
project, and the injection suite's payload check read an empty
directory.
Added
- Bench: a
ticketspersona for the MCP fixture (nine tools with
strictly validated schemas), themcp-loadsuite that uses it, and an
arg errorscolumn inbench report.
Documentation
- ADR-0028, rejected: putting a loaded server's schemas into the
conversation, called through amcp_callproxy, keeps the prompt
cache. On a real server's sibling tools the model then mixed up
arguments. Measured on a prototype that was not merged.
v0.16.0
v0.15.1
v0.15.0
Mind maps in replies are drawn as pictures where the terminal draws images (mermaid-render v0.5.0): the tree on two sides of the root, a colour per branch, every node shape, labels wrapped as mermaid wraps them. A label with emphasis, an icon in its text or math shows the source with a note. Fixed: an ER or state label with emphasis the previous rule missed (snake_case) shows the source instead of a picture with the underscores. See CHANGELOG.md.
v0.14.0
Gantt charts in replies are drawn as pictures where the terminal draws images (mermaid-render v0.4.0): sections, tasks placed by dates, durations, after / until and excluded days, milestones, vert markers, the time axis. A chart whose picture would depend on the day it is drawn shows the source with a note. See CHANGELOG.md.
v0.13.0
State diagrams in replies are drawn as pictures where the terminal draws images (mermaid-render v0.3.0): composite states as frames, concurrent regions, choice / fork / join, notes on the side they name. A transition crossing a composite's frame shows the source with a note. See CHANGELOG.md.