Skip to content

v0.184.1

Choose a tag to compare

@github-actions github-actions released this 27 Sep 05:18
· 269 commits to main since this release
1ae2aca

v0.184.1 fixes the Windows desktop build that stopped v0.184.0 from shipping, hardens open (tokenless) instances and hubs, fixes chats that delegated to a peer agent on Anthropic models, and turns on remote-agent pairing in Settings ▸ Devices.

Upgrading from v0.183.1

  • v0.184.0 never reached the desktop app (its Windows build failed), so desktop users go straight from v0.183.1 to v0.184.1. Everything else new since v0.183.1 is in the v0.184.0 release notes.
  • If other containers call an open agent by its compose service name, or you reach it through a reverse-proxy name, add that name to PROTOAGENT_TRUSTED_HOSTS, or those requests now get a 403.

Fixes

  • The CLI no longer crashes on a Windows cp1252 console. fleet --help said "Settings ▸ Devices", which cp1252 can't encode, and that failed the v0.184.0 Windows desktop build. The protoagent and python -m server entrypoints now print an unencodable glyph as "?" instead of aborting, and CLI text uses ">" and "->" (#3675).
  • A chat that used @peer / delegate_to no longer fails every later turn on Anthropic models with a 400 (tool_use without an immediately following tool_result). The tool result is now recorded first, and chats already in that state heal on their next turn; the stored transcript is left as it was (#3676).
  • A paired hub now shows up on the remote under its own name (identity.name, then AGENT_NAME) instead of "protoagent (fleet hub)". Re-pair an existing hub to update its entry (#3671).

Security

  • An open hub no longer lends a paired remote's token to other web pages. For remote members on a hub with no token (the desktop default), the fleet proxy now refuses cross-site requests, a foreign Origin and an untrusted Host (DNS rebinding) with a 403 before contacting the remote. The console, desktop app, curl and delegates are unaffected, as are local members and token-gated hubs (#3662).
  • A tokenless instance now answers only its own host names and its own console. A Host allowlist admits IP literals, localhost, *.ts.net, this machine's .local name, a named bind and the hosts in A2A_ALLOWED_ORIGINS / PROTOAGENT_TRUSTED_HOSTS. State-changing requests and WebSockets must come from the console's own origin, the desktop app, a loopback origin or a non-browser client, and requests with a body to /a2a and /v1/* must send a JSON content type (415 otherwise). Token-gated instances are unchanged (#3668).

Pair remote agents (ADR 0113)

  • Remote protoAgents on your LAN or tailnet now pair by code: Settings ▸ Devices ▸ Pair an agent shows a short XXXXX-XXXXX code, and on the hub Pair… (discovered rows or Pair by URL…) or Re-pair redeems it. Fleet rows show each remote's auth state (paired / not paired / token rejected / open), and plain http:// to a non-tailnet LAN address asks you to confirm sending it unencrypted (#3664).
  • Settings ▸ Devices is on for everyone; the settings.devices developer flag is gone. New guide: docs/guides/pairing.md covers phones, agents, revoking and delegating to a paired remote (#3672).

What's Changed

  • fix(fleet): open hub refuses cross-site and rebound requests to remote members (#3662) by @mabry1985 in #3667
  • feat(settings): Devices graduates — remove the settings.devices flag; pairing guide (ADR 0113 S7) by @mabry1985 in #3672
  • fix(fleet): name the hub on a paired remote by its agent-card identity; pair-route + advertise tests (ADR 0113) by @mabry1985 in #3671
  • feat(console): pair a remote agent by code; auth badges; hub-safe delegate links (ADR 0113 S6) by @mabry1985 in #3664
  • fix(delegates): tool result before room envelopes; heal out-of-order histories by @mabry1985 in #3676
  • fix(auth): harden tokenless instances — Host allowlist, cross-site rule, JSON content type (#3668) by @mabry1985 in #3674
  • fix(cli): don't crash on Windows cp1252 consoles (v0.184.0 desktop build) by @mabry1985 in #3675

Full Changelog: v0.184.0...v0.184.1