v0.184.1
v0.184.1 fixes the Windows desktop build that stopped v0.184.0 from shipping, hardens open (tokenless) instances and hubs, fixes chats that delegated to a peer agent on Anthropic models, and turns on remote-agent pairing in Settings ▸ Devices.
Upgrading from v0.183.1
- v0.184.0 never reached the desktop app (its Windows build failed), so desktop users go straight from v0.183.1 to v0.184.1. Everything else new since v0.183.1 is in the v0.184.0 release notes.
- If other containers call an open agent by its compose service name, or you reach it through a reverse-proxy name, add that name to
PROTOAGENT_TRUSTED_HOSTS, or those requests now get a403.
Fixes
- The CLI no longer crashes on a Windows cp1252 console.
fleet --helpsaid "Settings ▸ Devices", which cp1252 can't encode, and that failed the v0.184.0 Windows desktop build. Theprotoagentandpython -m serverentrypoints now print an unencodable glyph as "?" instead of aborting, and CLI text uses ">" and "->" (#3675). - A chat that used
@peer/delegate_tono longer fails every later turn on Anthropic models with a 400 (tool_usewithout an immediately followingtool_result). The tool result is now recorded first, and chats already in that state heal on their next turn; the stored transcript is left as it was (#3676). - A paired hub now shows up on the remote under its own name (
identity.name, thenAGENT_NAME) instead of "protoagent (fleet hub)". Re-pair an existing hub to update its entry (#3671).
Security
- An open hub no longer lends a paired remote's token to other web pages. For remote members on a hub with no token (the desktop default), the fleet proxy now refuses cross-site requests, a foreign
Originand an untrustedHost(DNS rebinding) with a403before contacting the remote. The console, desktop app, curl and delegates are unaffected, as are local members and token-gated hubs (#3662). - A tokenless instance now answers only its own host names and its own console. A
Hostallowlist admits IP literals,localhost,*.ts.net, this machine's.localname, a named bind and the hosts inA2A_ALLOWED_ORIGINS/PROTOAGENT_TRUSTED_HOSTS. State-changing requests and WebSockets must come from the console's own origin, the desktop app, a loopback origin or a non-browser client, and requests with a body to/a2aand/v1/*must send a JSON content type (415otherwise). Token-gated instances are unchanged (#3668).
Pair remote agents (ADR 0113)
- Remote protoAgents on your LAN or tailnet now pair by code: Settings ▸ Devices ▸ Pair an agent shows a short
XXXXX-XXXXXcode, and on the hub Pair… (discovered rows or Pair by URL…) or Re-pair redeems it. Fleet rows show each remote's auth state (paired / not paired / token rejected / open), and plainhttp://to a non-tailnet LAN address asks you to confirm sending it unencrypted (#3664). - Settings ▸ Devices is on for everyone; the
settings.devicesdeveloper flag is gone. New guide:docs/guides/pairing.mdcovers phones, agents, revoking and delegating to a paired remote (#3672).
What's Changed
- fix(fleet): open hub refuses cross-site and rebound requests to remote members (#3662) by @mabry1985 in #3667
- feat(settings): Devices graduates — remove the settings.devices flag; pairing guide (ADR 0113 S7) by @mabry1985 in #3672
- fix(fleet): name the hub on a paired remote by its agent-card identity; pair-route + advertise tests (ADR 0113) by @mabry1985 in #3671
- feat(console): pair a remote agent by code; auth badges; hub-safe delegate links (ADR 0113 S6) by @mabry1985 in #3664
- fix(delegates): tool result before room envelopes; heal out-of-order histories by @mabry1985 in #3676
- fix(auth): harden tokenless instances — Host allowlist, cross-site rule, JSON content type (#3668) by @mabry1985 in #3674
- fix(cli): don't crash on Windows cp1252 consoles (v0.184.0 desktop build) by @mabry1985 in #3675
Full Changelog: v0.184.0...v0.184.1