Releases: replygirl/kuru
Release list
v0.9.0
v0.9.0: Compacting Context Without Losing History
This release adds automatic and manual context compaction, so long-running conversations stay within a model's context window without discarding conversation history.
Added
-
Context compaction (#85, @replygirl). When a turn's request grows large, Kuru can now summarize older context into a durable, bounded rolling summary instead of simply omitting rows to fit the model's window. The summary carries exact actor, session, view and source-range provenance and advances a cursor atomically; the original conversation rows remain stored and readable. Compaction is triggered automatically once a request crosses a configurable threshold, and can also be run manually:
/compact # compact all active identities with eligible history /compact ID # compact one identityCompaction uses its own accounted provider request and output reserve, separate from the ordinary answer request. It preserves candidate isolation, independent peer writes, and producer-private reasoning sidecars, and a canceled or failed attempt leaves the prior projection unchanged.
-
Two new configuration keys govern the behavior:
context_compaction_threshold_percent = 75 # 50-95, percent of window that triggers compaction context_compaction_output_reserve_tokens = 1024 # 1-2,000,000, reserved for the compaction request
-
Same-actor rolling summaries from other sessions can now be admitted into a request through the mode's existing own-history visibility, while the current session's own summary and raw suffix stay authoritative; older shared summaries are omitted as whole records when needed to fit the budget, and another session's raw rows or private reasoning are never projected.
Changed
- The TUI's context-omission notice now separately reports omitted shared-summary rows alongside public, private, and note rows, and the status bar labels an active compaction request as its own usage phase.
This release also includes an internal fix to the release delivery pipeline's post-publish Windows verification step (#86), which has no effect on installed Kuru behavior.
Full Changelog: https://github.com/replygirl/kuru/commits/v0.9.0
v0.8.0
v0.8.0: Verified File Edits, Parallel Reads, and a Hardened Memory Service
This release strengthens Kuru's file-tool safety, speeds up independent read-heavy turns, extends MCP with recoverable catalogs and native OAuth, and rebuilds core memory internals (a per-project service, private reasoning summaries, and session-scoped provenance) that make Kuru's storage layer more resilient to crashes and concurrent access.
Highlights
- Safer, faster tool execution. A new checkpointed
file_edit/file_write/file_deletepath adds durable before/after receipts with selected undo, while independent reads (file_read,file_list,grep,glob,web_fetch) now run in bounded concurrent waves instead of one at a time. - More capable MCP. Configured servers gain per-alias enable/disable, tool allow/deny filters, a recoverable stale-metadata cache, and native OAuth authorization for HTTP aliases with OS-backed credential storage.
- A hardened memory foundation. A dedicated per-project memory service now owns the writable Dolt store independently of any single conversation process, and storage rows gain explicit session provenance plus a private, durable record for provider reasoning summaries.
Added
- Verified file edit checkpoints:
file_writeandfile_delete(and a newfile_edittool) record actor-attributed before/after receipts before mutating a file, enabling exact selected undo and crash recovery that only ever touches the precise matching edit (#71, @replygirl). - Bounded parallel tool reads: independent
file_read,file_list,grep,glob, andweb_fetchcalls proposed in the same turn now execute concurrently up tomax_parallel, while returning results to the provider in original call order; mutations, shell, and MCP calls remain serial (#78, @replygirl). - MCP catalog controls: each configured server now has explicit enabled/disabled state, bounded
allow_tools/deny_toolsfilters, and a private discovery cache so a server that goes offline can still be inspected asstalerather than disappearing;kuru tools//toolsreport one shareddisabled/live/stale/degradedstate per alias (#79, @replygirl). - Native OAuth for HTTP MCP: HTTP MCP aliases can authorize through browser or device OAuth flows, with credentials stored in Kuru's OS-native secret store and scoped to their alias, resource, issuer, and client; use
kuru mcp login|status|logout ALIAS(#80, @replygirl). - Per-project memory service: a private service now owns each project's writable Dolt lifecycle independently of any single client process, so one conversation exiting no longer tears down memory for another attached client, and idle service authority is reclaimed safely (#73, @replygirl).
- Producer-private reasoning summaries: provider-delivered reasoning summaries are now recorded durably under the admitted session/turn/actor/call identity, kept out of transcripts and future prompt context, with exact-retry idempotency (#81, @replygirl).
- Session-scoped memory provenance: actor history and checkpoint-summary rows now carry explicit session attribution, with session-scoped reads, bounded pagination, and atomic summary-plus-cursor checkpoints; legacy and sibling-session rows stay inspectable in full export without leaking into another session's prompt (#82, @replygirl).
Changed
- Local storage schema advances again (building on prior schema work) to carry session provenance and checkpoint/cursor records; older Kuru binaries refuse to open a store upgraded by this release rather than silently downgrading it.
v0.7.0
v0.7.0: Slash Commands, Skills, and Custom Prompts
This release focuses on the terminal experience: a proper slash-command registry with completion, two new local-only commands, and a skills/custom-prompt system for extending the actor's available prompts. It also lands a storage schema upgrade and a couple of memory-lifecycle reliability fixes.
Added
- A unified slash-command registry now drives help text, parsing, and dispatch, and Tab/Shift+Tab cycles matching command names before the first argument (@replygirl, #65).
/clearclears the visible terminal conversation only; stored history, usage, and the session identity are untouched and remain available after resume (#65)./statusshows the current session, project, model/effort/mode selections, turn count, and known usage from the local view, with no provider call (#65).- Skills and custom prompt commands: put a skill at
.agents/skills/NAME/SKILL.md(project) orskills/NAME/SKILL.md(user config), and the actor can select it with theskill_loadtool; project skill metadata and material go through the existing workspace-trust review before use (@replygirl, #70).Custom terminal commands work the same way: a.kuru/commands/review.md # project custom command commands/review.md # user-config custom command.kuru/commands/NAME.mdor user-configcommands/NAME.mdfile withname/descriptionfrontmatter registers/NAME, which sends its Markdown body plus any typed arguments as an ordinary literal-text turn. Built-in names always win collisions, and both catalogs only appear in/help/Tab after trust preflight. Skills and custom commands never grant file, shell, MCP, or network capability on their own (#70).
Changed
- Memory storage moved to schema 4, which retains compact indexed operation receipts across later writes so a lost reply can be reconciled without duplicating its effect, while historical schema 1–3 branches keep their old receipt shape unchanged (#68).
- Added the internal foundation for a private, per-project memory-owner process (authenticated local attachment, typed bounded requests, idle cleanup). This lands the plumbing only; ordinary CLI and TUI use still go through the existing local store in this release (@replygirl, #56).
Fixed
- Memory shutdown now retries the pool drain after the owned Dolt engine has actually reaped, instead of reporting a stale close-deadline error when the last idle connection was still finishing teardown (@replygirl, #67).
- A retained file handle whose name was unlinked is now classified as ordinary absence rather than the same error used for extra hardlinks, so memory-service endpoint retirement is observed correctly (@replygirl, #75).
Breaking Changes
- Storage schema 4 is required to open a memory store upgraded by this release. An older Kuru binary that only understands schema 3 will refuse to open that store rather than downgrading it; use a compatible Kuru version to keep working with the same project data.
Full Changelog: https://github.com/replygirl/kuru/commits/v0.7.0
v0.6.0
v0.6.0: Web fetch, calibrated token estimates, and project instruction discovery
This release adds a new permission-gated web fetch tool, replaces Kuru's byte-based token estimate with a calibrated tokenizer for supported models, extends project instruction discovery to CLAUDE.md and imports (with new configuration layers), and fixes a Windows CLI startup crash.
Added
web_fetchnative tool (#59, @replygirl): a permission-gated tool for retrieving bounded UTF-8 text from public HTTP(S) destinations. Every connection and redirect is revalidated against destination policy (loopback, private, link-local, multicast, and other special-purpose addresses are refused), redirects are capped at five hops, and responses are bounded to 2 MiB read / 64 KiB returned. Fetched text is always untrusted tool data — it cannot add instructions or expand permissions — and provider/MCP credentials are never forwarded to the fetched origin. Like other tools, it defaults toaskand can be governed with[[permissions]]rules usingselector = { kind = "native", name = "web_fetch" }.CLAUDE.mdand Markdown import support (#60, @replygirl): project instruction discovery now composes ancestor/rootAGENTS.mdandCLAUDE.mdfiles, including bounded@relative/file.mdimports (cycle-safe, deduplicated, capped at 1 MiB combined / 128 sources / 8 import edges). Over-cap sources are omitted with a visible notice rather than failing the whole project.- New configuration layers:
KURU_MANAGED_CONFIGfor externally provisioned defaults and locked constraints, an untracked.kuru/config.local.tomlat the project root, and repeatable-c key=valueCLI overrides (#60, @replygirl). - Nested instruction activation (#63, @replygirl): when an actor's file tool reaches a newly authorized subdirectory containing its own instructions, Kuru now asks for a separate workspace-trust review (once, persist, or deny) before those instructions take effect, and a newly instructed write/delete returns a replan result before changing anything. Direct
kuru toolcommands are unaffected.
Changed
- Token estimates now use a real tokenizer where possible (#57, @replygirl): for catalogued GPT-5.6 models on the OpenAI Responses and ChatGPT subscription routes, Kuru counts the final serialized request locally with an embedded
o200k_basetokenizer plus a structural allowance, rather than the previous bytes/2 heuristic. Unknown models and custom Responses endpoints keep the historical byte-based fallback. All figures remain labelled estimates, not exact provider counts. - Shared prompt prefixes: common mode rules and reviewed project instructions are now assembled before actor-specific identity and transcript content, giving providers a stable, reusable prefix without mixing private actor histories. Reported cache usage is only shown when a provider actually reports cached input tokens.
- The context status line and composer meter now name the sizing method (tokenizer-derived vs. byte fallback) alongside the existing window provenance.
Fixed
- Windows CLI stack overflow (#61, @replygirl): the CLI's async entry future is now heap-boxed before being awaited, preventing a main-thread stack overflow that could crash
kuruon Windows. - A cancellation test fixture for web fetch was hardened to prove cancellation after request dispatch rather than relying on a timing sleep (#64, @replygirl).
v0.5.0
v0.5.0: Native Search and Paged Reads
This release adds native grep and glob search tools and paged file_read, ships internal groundwork for a future project-memory service, and hardens the release verification pipeline. There are no breaking changes for existing configurations.
Added
- Native
grepandglobtools let peers search project files without needing an installedrgexecutable or shell access (@replygirl, #55). Both use bundled, pinned ripgrep-family Rust crates (ignore,grep-regex,grep-searcher), traverse only beneath the checked project root, never follow symlinks, and exclude hidden and repository-ignored paths by default (setinclude_hidden/include_ignoredto opt in). Every discovered candidate gets its own exact permission check, so a broadgrepcannot bypass a more specificdenyrule on one file. Results are bounded (10,000 candidate files, 2 MiB per file, 8 KiB per matched line, 2,000 matches) and omissions are reported by category without leaking denied paths or content. file_readnow accepts optionaloffsetandlimitto page through large UTF-8 text files by one-based logical line, returningnext_offsetfor continuation alongside the existing unpagedtextresponse. Invalid ranges or binary content fail cleanly rather than returning partial page metadata.- Tool permission configuration (
[[permissions]]) and the published configuration schema now recognizegrepandglobas native selectors, so they can be individually allowed, asked, or denied like other file tools.
Changed / Internal
- Added a private, owner-checked local IPC primitive (Unix domain socket wrapper and a repeatable Windows named-pipe listener) used internally to support a future storage-owner process that serves successive local clients (@replygirl, #53). This groundwork is not yet wired into ordinary Kuru behavior and does not change current memory or conversation behavior.
- Hardened Windows release verification: the release pipeline now downloads and checksum-verifies the published Windows assets and its release receipt after publication (@replygirl, #52).
- Fixed a flaky Windows memory test by waiting for a removed fixture binary to be confirmed absent before recreating it, avoiding a transient "delete pending" filesystem race (@replygirl, #51).
Full Changelog: https://github.com/replygirl/kuru/commits/v0.5.0
v0.4.2
v0.4.2: Critical fixes for ChatGPT subscription streaming and tool calls
This patch release fixes a critical regression that broke every conversational turn on the codex (ChatGPT subscription) provider, along with a related tool-call decoding bug and a small usability fix for permission prompts.
Fixed
- codex provider: every turn failed with "completed response omits streamed output". The subscription route streams items (reasoning, then message) as completed, and its final
response.completedpayload carries an emptyoutputarray rather than restating delivered items. The decoder previously required positional index equality between streamed items and that final array, so the very first streamed item failed every turn. Streamed items are now reconciled against the terminal output by item id instead of position, so reordered, dropped, or replaced items no longer fail a turn, while text that is visible to the user still must exist and match by id in the terminal output. (#49, @replygirl) - codex provider: tool-calling turns failed with "completed function arguments lack name". The backend announces a function call's name and call ID on
output_item.added(with empty arguments), then sendsfunction_call_arguments.donewithout the name or call ID. The decoder now resolves a function call's identity from the announcement or the terminaloutput_item.done, in either order, while still requiring a non-empty name, call ID, and JSON-valid arguments before dispatch. (#50, @replygirl) - Permission prompts in the terminal now accept plain digit keys (
1-4) to answer once/session/always/deny, in addition to Alt+1-4, matching the displayed hint. (#50, @replygirl) - Test suite: a TUI test that depends on
kuru-core's cost-catalog test seam failed with a false "not applied: invocation price" error when run without--all-features. The seam is now declared as a dev-dependency feature so it's available to every test binary without affecting the shipping binary. (#48, @replygirl)
Changed
- Added a redaction-safe
responses-stream-reconciledebug trace (item ids, types, indexes, and text length only), available under--debug, to aid diagnosis of future streaming issues.
v0.4.1
v0.4.1: Truthful activity, honest cleanup
A small patch release focused on reliability: the terminal UI now reports tool activity and cost more accurately, and two Windows memory-startup edge cases no longer interrupt a conversation.
Fixed
- TUI activity label and cost display (#42, @replygirl). The status bar now renders the known cost from a priced invocation end to end, and the activity line tells the truth while a tool call streams: it names the facing tool call, returns to "Responding" once a tool call is followed by text in the same round, tracks parallel tool calls independently, and clears by the actor that started the call rather than whichever actor settles last.
- Windows install cleanup no longer misreports success as failure (#43, @replygirl). Checked removal of a private staging directory now treats a target that has already vanished as completed removal instead of a rejection. This closes a race where a just-published
dolt.execopy could finish a pending delete between enumeration and removal, previously surfacing as a spuriousRejected removal … (os error 2). - A stuck post-publication cleanup no longer fails memory open (#46, @replygirl). If Kuru's bundled engine is already published and verified but a leftover private install stage can't be removed immediately (for example, held open by another process on Windows), Kuru now keeps that stage with a receipt, reports it once on standard error and in diagnostics, and sweeps it on a later open instead of failing the current conversation.
Changed
- Additional internal test-reliability fixes stabilize Windows and macOS CI runs (#44, #45, #47, @replygirl); these have no effect on shipped behavior.
v0.4.0
v0.4.0: Typed Messages, Streaming Answers, and Tool Permissions
v0.4.0 is a foundation release: it reworks how Kuru stores conversation content, streams provider responses into the terminal, gates tool use with explicit rules, and completes the mode-policy contract behind the four built-in frameworks.
Highlights
- Typed messages everywhere. Messages and completions now use ordered content blocks instead of embedding tool calls and results in plain text, so provenance and JSON values survive runtime handling and memory storage intact (#32).
- A real permission engine. File, shell, MCP, and A2A tool calls now get explicit allow/ask/deny decisions, with once/session/always grants reviewable from the TUI (#37).
- Visible cost, context, and streaming. Answers stream into the terminal as they arrive,
/costreports session usage and price estimates, and the model catalog now carries sourced limits and prices (#36, #38, #33). - Mode policies now drive the runtime. IFS, Polyvagal, Freudian, and Jungian each have validated Roles/Peering/Flow/Facing/Visibility/Memory profiles that the runtime dispatches through end to end, while keeping their existing behavior (#34, #39, #40).
Added
/permissionsand F5 to inspect and revoke stored tool grants; unattended callers get a typed refusal instead of a silent failure (#37)./costto see known session token usage alongside frozen API or subscription-equivalent price estimates, with explicit unknown/incomplete markers (#38).- A sourced model catalog that enriches provider-reported models with route-specific context limits, capabilities, and prices, plus a published Configuration Schema v1 (#33).
Changed
- Native provider responses stream into a provisional TUI answer before settling, with cancellation and tool-call gating preserved (#36).
- Runtime activity is now built from typed semantic events, including bounded, redacted tool outcomes with byte counts, digest, and elapsed time; turn journals move to format 2 while legacy journals remain readable (#35).
- The runtime now dispatches turn handling, context/visibility decisions, private namespaces, and dreaming entirely through each mode's policy profile, completing the mode contract without changing the four frameworks' observed behavior (#39, #40).
- Kuru checks a fully prepared provider request against an estimated context budget before sending it and tracks usage per deliberation, speaking, consultation, and dream (#38).
Breaking Changes
- The Dolt schema advances to version 3 to store typed message content; older Kuru binaries refuse to open an upgraded store instead of downgrading it. Memory exports move to format version 2 and include a content-format discriminator (#32).
- Legacy
allow_write = false/allow_shell = false(including the unset default) no longer hard-block writes and shell calls. They now behave as the "ask" fallback: an interactive prompt in the TUI, or a structured refusal for headless callers. To keep the old hard block, add an explicitdenypermission rule for that tool (#37).
Full Changelog: https://github.com/replygirl/kuru/commits/v0.4.0
v0.3.4
v0.3.4: Wider Private-Directory Guidance
A small maintenance release that extends an existing safety diagnostic to more memory-related directories and documents speaker-selection behavior that was already shipping.
Fixed
- Owner-owned Unix directories with unsafe group/other permissions now get the same exact-path "restrict to mode 0700" guidance across all memory-owned locations, not just the primary data directory. This includes the managed Dolt cache and version directories, cold-probe and installation destinations, and private server (lifecycle) directories. As before, Kuru never changes permissions automatically, and links or foreign-owned paths still receive no such guidance (@replygirl, #29).
- Test-only fix: two MCP malformed-peer regression tests could flake because cleanup could reap the peer before a fixture completion marker was written. The tests now wait deterministically and verify the full initialize transcript; no production behavior changed (@replygirl, #30).
Documentation
- The frameworks and architecture docs now describe the existing "who speaks" tie-break rules in full: explicit targeting and active focus take precedence, then highest activation, then continuity of the previous speaker, and only a remaining tie falls back to each framework's authored part order (Self, Connection, Desire, or Continuity first). These fallbacks are recorded as
mode-authored-orderorstable-id-orderin the selection event and grant no supervisory authority to the chosen part (@replygirl, #29). - Memory documentation now consistently refers to "memory-owned directories" to reflect the broadened scope of the private-directory check.
This release has no breaking changes.
v0.3.3
v0.3.3: Exact Retry, Durable Interruption Markers, and Trust Coverage for Instructions
This release closes a set of Phase 0 gaps: exact turn retry now works end to end, interrupted turns leave a durable trace, AGENTS.md instruction sources are brought under workspace trust, credential redaction is broader, and a Windows cold-start Dolt activation bug is fixed alongside bounded Unix shell cleanup.
Added
kuru run --turn-id IDand the terminal/retrycommand let you safely retry the last local submission (#28, @replygirl). A completed turn is replayed from the durable journal with no new provider or tool call; a turn that may have dispatched external work refuses replay instead of duplicating it.kuru --resume SESSION_ID run "Continue from our last turn." --turn-id TURN_ID- Interrupted turns now store a fixed durable marker ("Turn interrupted; no completed answer was committed.") that remains visible after later turns and resume, while staying out of provider context (#28).
- JSON turn output adds
limit_reasons(tool-calls,peer-rounds,legacy-unspecified) andresponse_outcome(includingempty), replacing the old genericlimitedflag for diagnosis (#28). The TUI surfaces these as distinct labels instead of one generic "limited result" marker. --debugnow prints one JSON line naming the resolved per-project diagnostics ring directory on stderr, without changing command output (#28).- Workspace trust now reviews every ordered ancestor
AGENTS.mdsource, including the project root, before its bytes reach a prompt;trust statuslists the reviewed sources without printing their contents (#27).
Fixed
- A Windows cold-start activation failure is fixed: first-time Dolt provisioning now copies the fully verified engine to a private probe sibling, re-verifies it, and executes only that copy, instead of denying the checked move (#27).
- Warm Dolt cache opens now verify concurrently instead of serializing behind the install lock; the lock is reserved for missing-cache extraction and publication (#27).
- The private data-directory
0700remedy now applies to any rejected, real, current-user-owned unsafe directory, not only when legacy SQLite is present, and is never offered for a symlink or foreign-owned path (#27). - Retained Unix shell cleanup is now bounded process-wide (a fixed admission cap) with capped exponential backoff for unconfirmed observations, instead of growing unbounded worker/process ownership (#27).
- Unix and Windows shell failures now report the same fixed operational categories with bounded, redacted stderr, distinguishing a pending (incomplete) EOF from returned bytes; ordinary nonzero exits still return full structured output (#28).
- Automatic speaker selection now breaks activation ties using the framework's authored part order rather than raw ID order (#28).
Changed
- Credential redaction now also recognizes Slack and GitLab tokens, JWT-shaped values, URL userinfo credentials, and bare
token/secretfield names, in addition to existing OpenAI, GitHub, AWS, and PEM forms (#27). - The turn journal is documented as durable, no-expiry safety/idempotency history, separate from the bounded operational diagnostics ring (#28).
Full Changelog: https://github.com/replygirl/kuru/commits/v0.3.3