Skip to content

acpx 0.18.0

Choose a tag to compare

@steipete steipete released this 20 Sep 20:58
· 158 commits to main since this release
v0.18.0
8699be1

Highlights

  • Shared-session controls: change modes, models, and configuration through the shared runtime, and inspect capabilities without shelling out to the CLI.
  • More reliable sessions: preserve final output, usage, and accepted settings across cancellation, timeouts, reconnects, and owner transitions.
  • Safer permissions: keep interactive approvals separate, reject stale requests, and recheck authority before file writes or terminal launches.

Changes

  • Runtime/shared sessions: add setMode(), setModel(), setConfigOption(), and getCapabilities() to createSharedAcpRuntime(). Settings are applied by the running queue owner; without one, control requests fail with ACP_BACKEND_UNAVAILABLE. Thanks @saariuslystoned.

Upgrade notes

  • Shared sessions: update all participating clients and let older queue owners expire while idle before resuming work. The stronger ownership guards and control-persistence guarantees require updated clients and owners; mixed versions retain the older race conditions.
  • Replay viewer: wildcard binds (--host 0.0.0.0 or --host ::) now reject unconfigured DNS aliases with HTTP 403. Use a numeric interface address, or bind with --host <hostname> to keep using that hostname.

Fixes

  • Sessions/timeouts: require a final ACP response before reporting completion, preserve late response outcomes, and retire unfinished connections before queued successors resume the saved session.
  • Sessions/cancellation: stop retries cancelled during backoff or prompt admission without discarding completed responses or cancelling independent queued turns. Soft-closing an active session preserves its final cancellation output, usage, and configuration updates.
  • Sessions/controls: apply settings on the retained adapter even while idle, save accepted mode, model, and configuration changes before acknowledgement, and preserve them through prompt completion, timeout cleanup, and close.
  • Runtime/controls: preserve completed output, usage, and accepted settings when control responses overlap turn finalization; wait for admitted controls before one-shot cleanup.
  • Runtime/sessions: reject incompatible replacement while turns or controls remain unfinished, preserve live state during compatible ensureSession() calls, and retire old owners before publishing replacements. Do not reuse closed one-shot owners.
  • Sessions/ownership: serialize abandoned turn recovery and final cleanup across processes, preserve live owners, and prevent cancelled waiters from acquiring a later turn.
  • Sessions/queue: serialize owner handoffs, heartbeats, and stale cleanup so an old cleanup cannot delete a replacement lease or socket. Preserve owners when process liveness is uncertain and drain shutdown after guard cleanup failures.
  • Model controls: validate selections against the connected session's advertised models, including after reconnect, while preserving exact IDs, Cursor's unique aliases, and the accepted configuration response.
  • Permissions: serialize interactive tool, file-write, and terminal questions so one answer cannot approve multiple requests; deny waiting questions when stdin closes.
  • Permissions/runtime: retire pending tool, file, and terminal requests with their owning prompt or ACP request, reject late approvals, and recheck authority before filesystem mutations and every terminal spawn attempt.
  • Permissions/output: infer tool kinds from complete leading action words, so read-like substrings in edit or command titles neither grant read approval nor hide their output.
  • Filesystem: preserve symlink and parent-directory traversal when reading or writing ACP paths, including aliased working directories, instead of accessing an unrelated lexical target.
  • Sessions/prune: recheck saved closed and agent state before pruning, and preserve neighboring sessions whose IDs overlap history filenames.
  • CLI/config: load project permissions and relative MCP configuration from the final top-level --cwd and --mcp-config values. Preserve custom agent names such as constructor and __proto__ in resolution, listing, and config display.
  • CLI/output: honor explicit JSON and quiet output flags for configuration startup errors instead of printing an uncaught stack trace.
  • Compare: honor prompt delimiters with files or stdin, and resolve project configuration and relative input paths from the command's working directory. On interruption, stop launching agents, await active cleanup, and exit with code 130.
  • Replay viewer: reject foreign Host and Origin headers before HTTP access, WebSocket subscriptions, or shutdown, while preserving native clients without an Origin header. Fix IPv6 listener URLs and status/stop commands.

Package and verification

  • npm acpx 0.18.0; latest points to 0.18.0.
  • Registry tarball
  • Integrity: sha512-O5L2ldiSijytxsot9IIuViHCeZGNZpexlWKTD6za/flqrswotfl7RJ5Ch0NaU6ceSxFqAnLT/KVPwUF9KGVZlQ==
  • Published: 2026-09-20T20:55:44.549Z
  • Source commit; signed tag v0.18.0 verified.
  • Release CI: all 12 jobs passed, including Node 22/24/26, coverage, mutation, conformance, Slophammer, and docs.
  • Trusted publication with provenance; npm attestations match the published integrity and source commit.
  • Local pnpm run check: 1,580 tests passed, two skipped, and all 170 coverage tests passed; the configured 85% coverage gates passed. pnpm run check:docs, changelog formatting/lint, and isolated autoreview also passed.
  • Fresh installs of the prepared and published tarballs passed CLI version/help, public runtime/flows/registry imports, shared-session controls/capabilities, and shutdown checks. All 40 packaged files match; downloaded integrity matches npm.