Skip to content

v0.165.0

Choose a tag to compare

@github-actions github-actions released this 12 Sep 09:44
· 403 commits to main since this release
a614221

v0.165.0 cleans up agent processes a crashed or force-killed server left running, turns on the Cowork document skills (and with them Python execution) by default, keeps background work visible in the chat, and brings Word attachments and the Agent Browser into protoAgent itself.

Chat

  • A delegation is one row in the chat — the delegate, a one-line summary, and a spinner that becomes ✓ or ✕ — with the full prompt behind Show brief. While a chat has background jobs running, a strip above the message box lists them and the chat's tab shows it's busy (#3447).
  • A reply to background reports stays an ordinary message while you read it, instead of folding into a card the moment it finishes (#3443).
  • Chat messages show when they were sent: hover or keyboard-focus the clock for the full date and time (#3458).
  • A message typed into a background, scheduled or watch-triggered turn lands in the chat instead of sitting "queued" forever (#3446).
  • An @-addressed member's answer no longer appears twice (#3449).
  • A chat rebuilt from the server shows your questions again, and its answers read as paragraphs (#3439).
  • A chat no longer stays stuck "streaming" — with Stop showing and Send disabled — after its turn has ended: reloading mid-turn, a background answer arriving during another turn, and a sixth chat with a turn in flight at load all return to idle once nothing is running, and a turn still waiting on the server is never cut loose (#3474, #3478).
  • Expanding a tool card mid-turn no longer collapses it when the turn finishes (#3438).

Agents & processes

  • Agent processes no longer run on forever after their server is force-killed or crashes. Each server records the process trees it owns, and every server sweeps a dead owner's trees at startup and every 10 minutes — killing only trees it can prove are still the ones recorded (#3465).

Attachments & Knowledge

  • Word .docx files attach in chat and ingest into Knowledge, and the desktop runtime can read PDFs again (#3444). python-docx is now a core dependency, so a plain server or Docker install reads .docx out of the box (#3462).
  • An attached file can no longer forge its own attachment block to spoof a second, trusted-looking file, and the pypdf floor is raised to 6.8 for its decompression-bomb limits (#3448).

Plugins

  • The Agent Browser plugin ships with protoAgent (off by default), installs its own pinned CLI on first use, and its setup banners can fix what they report; it adds a page→PDF tool and fences screenshots to its own directory (#3451, #3464).
  • The Cowork knowledge-work skill pack (Word, Excel, PowerPoint and PDF skills, plus daily-brief and drop-folder habits) ships with protoAgent and is on by default. Its document skills run Python, so a default agent now also has execute_code: it runs in a child process with a scrubbed environment and a hard timeout, which is isolation, not a true sandbox. Turn it off with plugins: { disabled: [execute_code] }, or turn Cowork off with plugins: { disabled: [cowork] } (#3450).
  • A plugin whose Python packages aren't installed now says so, and installing them clears it without a restart (#3450).
  • Install deps runs one pip at a time per environment — a second install into the same Python is refused with a message naming the one running, across tabs, the CLI and fleet members — and Discover shows a bundled plugin's real state ("bundled · on", or why it's on) and never offers Install for one. The unused cowork.output_dir setting is gone (#3477).
  • A bundled plugin can supersede a git-installed copy of the same plugin, so a plugin can move into protoAgent without breaking existing installs (#3445); uninstalling a superseded copy works under a custom plugins.dir (#3452), and a plugin you placed by hand stays visible and removable (#3455).
  • Plugins ▸ Discover shows what each plugin adds and links its docs, lists Social Studio and Blood Bowl, and the directory now covers every protoLabs plugin with an honest status (#2910).
  • Plugin setup-gap banners now actually appear, with their Configure button and dismiss (#3438).
  • One plugin route can no longer take down /openapi.json, and routes in a plugin's nested sub-router get the structured error envelope again (#3437).

Artifacts

  • Artifacts can be pinned so history eviction never drops them (pin_artifact, capped by a new Pinned artifacts setting) (#3456).
  • The artifact store no longer loses writes between processes, a stuck writer can no longer block every other one, and an evicted file can no longer cut a download short (#3460, #3475).
  • The panel acknowledges a Download you started (#3454), and an html artifact's own doctype and <head> survive the panel (#3457).

Under the hood

  • The MCP quick-add catalog is checked against upstream every week (#2910), and two console e2e flakes are gone — one at local midnight, one when a mocked request outlived its test (#3453, #3459).

What's Changed

  • feat(plugins): the directory is the full census, and status decides where each plugin shows (#2910) by @mabry1985 in #3436
  • fix(plugins): plugin routes can no longer take down /openapi.json by @mabry1985 in #3437
  • test(windows): give the cert-store PowerShell helpers 120s, not 30s by @mabry1985 in #3442
  • ci(mcp): check the quick-add catalog against upstream, weekly and on catalog PRs (#2910) by @mabry1985 in #3441
  • feat(plugins): Discover cards show what a plugin adds and link its docs (#2910) by @mabry1985 in #3440
  • fix(chat): a reply to background reports settles in place, not into a card by @mabry1985 in #3443
  • feat(ingestion): accept Word .docx as chat + Knowledge attachments; ship pypdf in the desktop runtime baseline by @mabry1985 in #3444
  • fix(chat): durable turns keep the operator's prompt and their paragraph breaks (ADR 0104) by @mabry1985 in #3439
  • feat(chat): a delegation is one row with a summary; the chat shows its background work by @mabry1985 in #3447
  • feat(plugins): a bundled plugin can supersede a git-installed copy of the same id by @mabry1985 in #3445
  • fix(plugins): the live plugins dir IS the loader's root, and a failed removal is an InstallError by @mabry1985 in #3452
  • test(e2e): build now-relative fixtures per request, not at module load by @mabry1985 in #3453
  • fix(chat): settle, cancel and deliver interjections into attended server turns by @mabry1985 in #3446
  • feat: fix(artifact): acknowledge successful downloads in the panel by @mabry1985 in #3454
  • fix(console): setup-gap banners read setup_gaps[]; a single-tool card survives the settle by @mabry1985 in #3438
  • fix(ingestion): bound the work a hostile .docx can cost, and fence attachment text by @mabry1985 in #3448
  • feat(chat): hoverable sent timestamps on chat message footers by @mabry1985 in #3458
  • feat(artifact): pin_artifact — exempt a long-lived artifact from history eviction by @mabry1985 in #3456
  • fix(plugins): every root reader honours plugins.dir, and a hand-placed copy is visible and removable by @mabry1985 in #3455
  • test(e2e): snapshot patched mock bodies instead of proxying route.fetch() per request by @mabry1985 in #3459
  • test(ingestion): skip the lying-size docx test when python-docx is absent by @mabry1985 in #3461
  • fix(artifact): serialise store writes across processes, not just threads by @mabry1985 in #3460
  • fix(chat): an addressed delegate's answer renders once, not twice by @mabry1985 in #3449
  • fix(artifact): keep an html artifact's doctype and first in the panel srcdoc by @mabry1985 in #3457
  • feat(agent_browser): vendor the browser plugin into core, superseding its repo by @mabry1985 in #3451
  • build(deps): promote python-docx to a core dependency by @mabry1985 in #3462
  • feat(agent_browser): download the pinned agent-browser CLI on first use; one-click setup-gap buttons by @mabry1985 in #3464
  • feat(cowork): vendor the knowledge-work skill pack into core, superseding its repo by @mabry1985 in #3450
  • fix(web): a cancelled reattach releases the streaming status it set by @mabry1985 in #3474
  • fix(artifact): bound the store lock, warn each lock degrade, stream blob downloads from an open handle (#3460 follow-ups) by @mabry1985 in #3475
  • docs(adr): 0110 — plugin setup steps, the host-run setup-gap button (#3464) by @mabry1985 in #3476
  • fix(proc): sweep the trees of an owner that was SIGKILLed or crashed (#3463) by @mabry1985 in #3465
  • fix(web): one reconciler hands back a chat left "streaming" with nothing live by @mabry1985 in #3478
  • fix(plugins): one Install-deps pip per environment; Discover shows bundled state; drop dead cowork.output_dir (#3450 follow-ups) by @mabry1985 in #3477

Full Changelog: v0.164.0...v0.165.0