Repository navigation
Releases: sametbasbug/equinox-local
Release list
Equinox Local 6.0.4
Changed
- Public installers automatically enroll the trusted Main update stream after verified signed Stable first activation. Existing Stable users will receive a one-time signed bridge that performs exact-SHA Main enrollment and health verification, reverting to the healthy signed Stable baseline if enrollment fails.
Fixed
- Windows tunnel disconnects and failed tunnel initialization no longer leave a configured managed installation indefinitely stranded in local-only mode. An independently supervised local Control Center stays reachable during bounded retry preflight (30 seconds up to 10 minutes of backoff); after the verified tunnel preflight succeeds, only its owned local-only server is gracefully stopped before re-entering tunnel mode. Explicit shutdown does not trigger reconnect, and missing/unsafe tunnel configuration still fails closed.
- Windows native shell now records only fixed, privacy-safe tunnel lifecycle phases in its bounded runtime diagnostic log, without recording raw tunnel-client stderr or user credentials.
- Owned runtime stdin EOF is consumed reliably for a graceful local-only → tunnel handoff without restarting the entire WPF app.
- Fixed Windows Agent Browser startup failing with
spawn powershell.exe ENOENTafter Windows native runtime sanitizesPATH. Agent Browser now uses absolute, SystemRoot-pinned Windows PowerShell and taskkill executable paths for isolated Chrome launch, process inventory, and exact-process shutdown; missing trusted roots fail closed rather than searching ambient PATH. - Added regression tests for scrubbed Windows environments and PATH-hijack avoidance, including a Windows-native launch acceptance.
Equinox Local 6.0.3
Fixed
- Fixed Windows Agent Browser failing to find installed Google Chrome after the managed runtime sanitizes its environment. The trusted Chrome discovery path now also derives the two standard Program Files locations from the absolute Windows SystemRoot drive, without following ambient PATH or another Chrome profile.
- Fixed Windows native WPF shell integrity failures caused by WebView2 and Windows runtime caches being written alongside the signed native application. New WebView2 profiles live in per-user Equinox Local state; already-installed 6.0.2 shells tolerate only two known historical cache subtrees with bounded, symlink-safe validation, while release payloads and all signed binary hashes remain strictly checked.
- Corrected Windows System Doctor, capability catalog and Control Center to show the actual Microsoft winapp desktop bridge rather than treating macOS Peekaboo as the Windows desktop engine, including across dashboard refreshes.
- Added actionable Agent Browser startup failure incidents to runtime diagnostics and platform-focused regression coverage.
- Added a guarded, audit-first Windows recovery utility for interrupted Stable update/uninstall paths; resets quarantine, rather than delete, verified product-owned directories.
Equinox Browser remains at Chrome Web Store version 1.0.0. These changes repair observed 6.0.2 Windows onboarding issues without switching installed Stable users to Main or redesigning the WPF UI.
Equinox Local 6.0.2
Fixed
- Fixed Windows Tunnel reconnect after Save & connect: the bundled tunnel-client treats backslashes in quoted
--mcp-commandpaths as escape sequences, so the Windows native shell now passes forward-slash-normalized absolute Node and MCP server paths. Real packaged tunnel-client offlineinitacceptance tests cover both Windows x64 and ARM64, reproducing the old error before the fix and passing afterward. - Added guarded recovery for a missing product-owned Windows Chrome Native Messaging manifest when the managed install ownership and launcher have been positively verified. Unrecognized, foreign or symlinked registrations remain protected; no registry hijacking or antivirus exception is involved.
- The Windows website bootstrapper now warns early when an installed numbered Stable version requires an in-app update instead of downloading a new release for an unsupported cross-version first-install operation.
- Removed the redundant Copy Tunnel ID button from the card where users enter their own Tunnel ID. Improved reconnect failure messages to distinguish a local-only restart from an unreachable Control Center without exposing credentials.
- Added privacy-preserving Windows Tunnel diagnostics and real packaged tunnel-client
inittests to guard against future Windows command-line parser incompatibilities.
This maintenance release does not change Equinox Browser 1.0.0, does not reintroduce the deferred WPF/WebView2 visual redesign, and preserves the signed 6.0.1 archives unchanged. A user Windows Tunnel connection and first actual MCP tool invocation must still be verified after installing 6.0.2.
Equinox Local 6.0.1
Fixed
- Fixed Windows Tunnel onboarding after entering the Tunnel ID and Runtime API Key: the native shell now supervises the verified tunnel-client rather than forcing local-only mode, and managed restarts use the Windows Shell IPC instead of macOS
launchctl. - Protected Windows onboarding credentials with current-user ACLs, including temporary files, and verified the ACL when reading the Runtime API Key.
- Made Windows installer ZIP extraction errors actionable without printing secrets or unchecked user file paths. ESET's previously reported detection of two native helpers was independently confirmed and corrected by ESET; no antivirus exclusion is necessary.
- Registered the Windows native app in the current user's Start menu and Installed Apps (including a guarded, data-preserving default uninstall entry), with real x64/ARM64 installation and cleanup acceptance.
- Corrected the bilingual ChatGPT Plugins setup instructions to Add custom MCP server → Tunnel → Authentication: No authentication; the Tunnel ID is automatically populated in ChatGPT and must not be entered twice.
- Changed the default Browser turn-identity fallback idle timeout from 5 minutes to 2 minutes without overriding existing saved user settings.
The WPF/WebView2 visual redesign is reserved for a later release. This maintenance release covers macOS and Windows on ARM64/x64 and does not change the separate Equinox Browser 1.0.0 Chrome Web Store version.
Equinox Local 6.0.0
Release highlights
-
Major milestone for Equinox Local and Equinox Browser 1.0.0 interoperability, including current ChatGPT Web send/continuation flows, Task Capsules, Telegram New Task and exact-bound follow-up chats.
-
Redesigned Control Center updates UX with compact sidebar notices, explicit Main SHA display, periodic background update awareness and independent Stable/Main notices without silent channel switching.
-
Expanded native Windows x64 and ARM64 installation, lifecycle, rollback and guarded desktop automation support, alongside macOS ARM64/x64 package and update paths.
-
Updated verified dependencies: Node 26.11.1, MCP SDK 1.32.1, PDF.js 6.4.299, Tunnel Client 0.0.16 and macOS Peekaboo 4.9.0.
-
Prepared Equinox Browser 1.0.0 Store review candidate: updated ChatGPT Web native composer submit selectors for Telegram new-task, Fresh Chat Resume and bound Chat Bridge; reused modern Auto Continue turn observation for bound chats and exact assistant-response extraction, without relaxing existing send/receipt guards.
-
Fixed the managed Stable release update validator refusing canonical packages whose
release.jsonincludes a validated 40-hexsourceSha; historical source-less Stable archives and strict metadata shape checks remain supported. -
Fixed real macOS
artifact_requiredMain upgrades: the detached launchd worker preserves non-secret managed installation paths for future updates and independently reconstructs an exact trusted managed installation from its own HOME, transaction root and current native release pointer when an older A scheduler drops those fields; credentials remain excluded and foreign paths are rejected. -
Fixed the macOS native LaunchAgent runtime host using the OS account home instead of the exact managed
EQUINOX_LOCAL_INSTALL_ROOTunder its declaredHOME; isolated managed users and native app refreshes now resolve the trusted runtime wrapper consistently, while foreground launches retain the normal account-home fallback. -
Require the restarted native Main Control Center itself to identify as
managed-sourceat the exact target SHA before completing update health verification, preventing the still-running old A runtime from being mistaken for healthy B; preserve pinned Windows shell identity in detached worker recovery. -
Fixed a real native Main update apply failure: the pinned prebuilt dependency and staged-source validator functions were used without being imported by the transaction engine. Exercised the real default pinned Node/npm lifecycle path in regression tests and propagated the owned Windows POSIX shell for staged-source validation.
-
Validate the bundled macOS Git HTTPS helper and template directory during pinned toolchain install/reuse, rejecting incomplete or tampered archives before managed-source enrollment.
-
Fixed the pinned macOS Dugite Git distribution's root-relative helper discovery: managed-source enrollment and Main update transactions now explicitly select product-owned
libexec/git-core/share/git-core/templates, allowing HTTPS clone/fetch without ambient system Git. Proven using the exact SHA-256-pinned Git 2.53.0-4 archive after a real isolated macOS installation smoke foundgit-remote-httpsmissing. -
Added an opt-in GitHub-hosted macOS ARM64 installed-Main upgrade smoke: build a separately admitted source-A package, launch the real private-user native LaunchAgent and Control Center, upgrade through the production Update & restart API to the latest admitted Main snapshot, and verify the detached worker receipt plus healthy source-B runtime without touching developer machines. This is the positive-path first phase; forced-failure/rollback and Windows installed-host acceptance remain pending.
-
Fixed workflow terminal state visibility racing ahead of its durable JSON publication, including completed, failed, paused and cancelled transitions; added repeated immediate-disk-read regression coverage.
-
Added real Git A→B Control Center loopback check/apply acceptance with durable Main source transactions, fresh subprocess SHA/health inspection, reusable native versus artifact-required handoff, and forced rollback-to-A coverage on macOS plus native Windows x64/ARM64 CI. Full native desktop lifecycle remains a separate M8 exit gate.
-
Updated Windows managed release build to invoke fixed relative batch script names under the exact build working directory instead of interpolating an environment-derived absolute
.cmdpath intocmd.exe /c(CodeQL Medium #49 follow-up). -
Guarded legacy 5.2.x Stable-to-Main migration: an existing numbered Stable installation is never enrolled by a routine installer retry, and explicit
--enroll-existing-mainrequires matching source provenance in the already installed and staged Stable release before any lifecycle mutation. Windows native lifecycle acceptance covers the opt-in rejection path. -
Restricted dynamically generated Windows MSVC
.cmdbatch operands to validated absolute drive paths without CMD metacharacters, addressing CodeQL Medium alert #49 without weakening x64/ARM64 packaging. -
Hardened legacy 5.2.x and managed-source uninstall ownership: preserve-data mode removes product-owned runtime/toolchain and admitted Main source/update state while keeping workspace/config, refuses foreign source pointers and symlinked runtime directories, and leaves unstamped unknown state untouched. Full uninstall still removes the exact managed application-data boundary.
-
Control Center runtime restart now flushes dirty Turn Budget settings before scheduling the restart and disables restart while that save is in flight, so custom fallback-idle and Auto Continue hop limits cannot be lost to the previously persisted values during restart.
-
Refreshed the pre-release dependency/runtime baseline: MCP SDK
1.31.0, patched transitivefast-uri/ip-addresslock entries, Microsoft WebView21.0.4258.31, and the Windows shell/CI toolchain to .NET10LTS withactions/setup-dotnet@v6. Peekaboo remains pinned to the last verified universal4.5.0because upstream4.6.0fails on supported Intel macOS; Node26.10.0, tunnel-client0.0.15, node-pty1.2.0-beta.15, pdfjs-dist6.3.289, pngjs7.0.0, Zod4.6.5, and the current Actions major pins were already current. -
Added first-release Windows Desktop automation through pinned Microsoft winapp CLI
0.7.1on native x64 and ARM64, covering practical UI Automation inspection/search/read/write/wait, mouse/keyboard/drag/hover/scroll, screenshots and workflow arbitration while keeping niche touch/pen and recording outside the initial agent surface. -
Windows managed screenshots now return validated native MCP image content directly when no explicit output path is requested, so the model can see a captured app/window/control without a separate file-transfer or attachment step.
-
Added practical Windows clipboard parity: bounded Unicode get/set/clear plus targeted paste through the pinned winapp desktop engine; clipboard operations use a fixed packaged STA helper rather than arbitrary PowerShell commands.
-
Added a real native Windows ARM64 shared-parity gate covering the existing headless runtime/process/ConPTY/Browser/tunnel smoke plus Task Capsules, Turn Budget, continuation, Telegram, Authenticated HTTP, file-transfer and private-state suites.
-
Extended the ownership-safe Windows managed uninstall/reinstall transaction to the exact native ARM64 target, including preserve-data/full cleanup, foreign registry ownership guards, native shell handoff, and clean-environment startup-registry reads that do not depend on PowerShell provider/module autoloading.
-
Accepted the native Windows ARM64 managed fresh-install path on real GitHub-hosted ARM64 Windows: the public PowerShell installer selects
win32-arm64, promotes the verified release, registers Native Messaging, launches the ARM64 stable shell and reaches matching runtime health. ARM64 uninstall/reinstall remains a separate W8 acceptance slice. -
Fixed Windows native-shell crash recovery by avoiding synchronous
Process.WaitForExit()inside the gateExitedcallback while asynchronous stdout/stderr drains are active; the bounded real-Windows supervision harness now proves crash recovery, stop, descendant drain and disposal complete without deadlock. -
Keep the Windows native runtime gate stdin pipe open after ownership release so the MCP runtime does not interpret an immediate inherited stdin EOF as a clean shutdown; stop/restart ownership remains Job Object-driven.
-
Retry verified Windows first-install release promotion only for bounded transient NTFS lock errors (
EACCES,EBUSY,EPERM), reusing the accepted stable-shell replacement policy while leaving macOS promotion single-attempt and all containment/integrity checks unchanged. -
Preserve bounded Windows runtime-gate stderr on unexpected exits so native startup crashes can be diagnosed without changing restart or ownership behavior.
-
Add bounded Windows runtime-start phase diagnostics so ARM64 first-install acceptance can distinguish helper readiness, Job Object assignment, and gate release without logging local paths.
-
Added a bounded path-free Windows shell startup discovery diagnostic (
arch, managed-pointer visibility and supervisor creation) so first-install acceptance can distinguish managed-install discovery from runtime-start failures without exposing local paths. -
Made the Windows Job Object PowerShell 5.1 helper ARM64-safe by removing its runtime
System.ComponentModel.Win32ExceptionAdd-Type dependency while preserving bounded Win32 error codes, Job Object ownership and kill-on-close behavior. -
Hardened Windows Job Object helper startup diagnostics on x64/ARM64: protocol waits remain bounded at 30 seconds with exact lifecycle-phase timeout messages, and a helper that exits before replying now reports only its bounded, control-character-sanitized stderr plus exit code for actionable startup diagnosis.
-
Added bounded Window...
Equinox Local 5.2.0
- Fixed Turn Budget fallback accounting when Browser turn identity is unavailable: fallback work now becomes Idle after configurable Local inactivity instead of counting forever, and Control Center exposes a
Fallback idle timeoutsetting (default 5 minutes, bounded to the safety cutoff). - Hardened Telegram pairing/inbox persistence by canonicalizing bounded network-derived state on both write and read boundaries; this resolves the outstanding Medium
js/http-to-file-accessCodeQL finding without removing restart-safe Telegram state. - Updated the bundled OpenAI
tunnel-clientruntime from0.0.14to0.0.15for Apple Silicon and Intel managed releases using the upstream release checksums; the verified tunnel bundle carries cloudflared2026.8.2. - Hardened fresh managed installation: first activation now gets a 60-second health budget, preserves the verified
currentrelease on startup failure instead of deleting the backend underneath an installed native app, stops the failed LaunchAgent cleanly, and reports bounded LaunchAgent/error-log diagnostics so a retry is recoverable and actionable. - Managed release smoke now exercises a real isolated macOS
launchctl -> runtime host -> app runtime wrapper -> supervisor -> serverlifecycle instead of stubbing both LaunchAgent activation and health verification.
Equinox Local 5.1.0
- Peekaboo permission probes no longer invalidate active UI snapshots between observation and mutation, and delivered-but-unconfirmed foreground outcomes are surfaced as ambiguous results that require observation instead of hard tool errors.
- Desktop automation now runs the pinned Peekaboo 4.5+ MCP surface with explicit foreground authority, exposing 22 native desktop tools including coordinate input, move/drag, dialogs, paste, capture, clipboard mutation, app/window/Space lifecycle and verify_state while keeping duplicate Peekaboo AI/browser stacks out of the gateway.
- MCP replay suppression now treats transport request IDs as recyclable hints: only in-flight/same-signal redelivery is exact-deduplicated, while a settled ID reused for a new call executes normally.
- Source-restart recovery explicitly forbids
launchctl submitone-shot wrappers because macOS infers submitted jobs as KeepAlive and can loop successful restarts. - Source restart now preserves the whitespace-free private Node alias instead of forwarding Node's resolved
process.execPath, preventing preflight rejection when the real runtime lives underApplication Support. - Source-checkout runtime restart is now single-flight, waits for helper spawn acknowledgement, bounds launch/tunnel lifecycle commands, and records the exact failure stage instead of silently stalling after restart scheduling.
- MCP tool delivery is now replay-safe: duplicate transport delivery reuses the original invocation/result instead of re-running side effects, while intentional new identical calls still execute normally.
- Source-checkout restart now automatically prefers the stable whitespace-free developer Node alias at
~/.local/share/equinox-local-developer/bin/nodeand rejects whitespace-bearing Node executable paths before tunnel startup, preventingApplication Support/...command-path splitting from breaking Local. - Refreshed current runtime dependencies to Node
26.10.0and Peekaboo4.5.0;fast-urinow follows the normal compatible^4.2.1range instead of an unnecessary exact pin. tunnel-client remains current at0.0.14, andnode-ptyremains on1.2.0-beta.15because npm'slatesttag still points to the older1.1.0line. - Fixed native Control Center confirmation actions such as Task Mark complete / Cancel task by wiring trusted same-origin
window.confirm()calls to a macOS sheet.
Added
- Added a default-on Telegram remote control switch in Control Center → Services. Turning it off keeps outbound Telegram delivery available while inbound updates are acknowledged and discarded without delayed replay; browser-bound active assistant turns refresh Telegram's short-lived
typingindicator from the existing Turn Budget signal. - Fixed Telegram task-card reconciliation so Bot API
message is not modifiedresponses are treated as idempotent success; Local now refreshes the persisted display key, emits a recovered observability event, and stops repeated Activity/health warnings. - Hardened Telegram New task creation against ChatGPT startup ref/hydration churn: startup composer replacement, empty/missing transient composers, and stale refs are recovered only while the live composer proves no prompt has been submitted; staged prompt text is postcondition-checked before the trusted send-button click, duplicate typing is avoided, and safe pre-submit failure still rolls back the temporary Task/tab. New Task bootstrap uses the real ChatGPT send control instead of relying on Enter; successful creation auto-selects the Task chat and its Task card exposes Unbind. Transitional
/c/routes are ignored until the URL exposes a conversation id that satisfies the same binding contract as Task Capsule storage. - Added Telegram Chat Bridge round-trip with exact Task chats and local-file handoff.
/tasksis the interactive Task control hub and includes ➕ New task; every active Task exposes Continue / Mark complete / Cancel, while verified/current chats add Use for chat / Unbind / Open in ChatGPT; selected/current Task chat cards expose ↗ Open in ChatGPT and 🔌 Unbind; only that explicit Task-creation flow opens one new root ChatGPT conversation and binds it to the new Task Capsule. Normal unbound Telegram messages never create chats. Task-bound turns carry only user text +task_id+ optionallocal_file. The earlier opaque Chat Bridge attachment resolver layer was removed. Chat Bridge v9 supports the new Task conversation's first assistant response with a null previous-assistant key. Browser-side file re-upload remains removed; guardedInput.insertText, real send-button submission, exact user-epoch confirmation, unique stale-tab reacquire and fail-closed ambiguity remain. - Added Telegram Remote Control for the paired private user: chat-scoped native
/status,/tasksand/helpcommand discovery, with/tasksacting as an interactive Task control hub instead of a chat-only selector, a sectioned phone-friendly/statuscard, Mark complete plus bounded next-step/terminal-state polish on durable Task Capsule cards, and short-lived/statuscontrols for Emergency Stop / Resume / Restart. Emergency Stop and Restart use action-specific two-step confirmation with bounded expiry; the controls reuse the same Agent Control/runtime restart services as Control Center and keep restart-ambiguous mutations fail-closed. - Added generic Authenticated HTTP Profiles under
integrations_call. Agents can discover safe profile metadata, create/update/delete profile structure and issue bounded authenticated requests without receiving credential values. Control Center provides profile CRUD, Ready/Needs credential state, a default-on agent-management toggle and a write-only credential field. - Added Bearer and validated secret-header authentication profiles with exact HTTPS origin + base-path scoping, allowed HTTP methods/path prefixes, optional allowed agent headers, bounded query/body/response/timeout handling and redirect refusal.
- Added short-lived HTTP Response Bindings for multi-step authenticated JSON APIs. A response exposes an opaque
response_id; preferred chaining keeps reuse metadata outside the body throughresponse_bindingswith source/target RFC 6901 pointers. Local injects the same-profile/same-trust string only immediately before fetch. The inline$equinox_response_refform remains supported for compatibility. - Replaced the old dashboard onboarding card with a dedicated First-time Setup Mode. Fresh managed installs keep normal Control Center sections locked while guiding Tunnel ID + restricted Runtime API key creation, ChatGPT tunnel connector setup, required Equinox Browser consent/control, and a final real ChatGPT→Mac MCP verification call. Setup completion is persisted privately and later connection failures do not reopen onboarding; pre-milestone managed upgrades are treated as legacy-complete.
- Added layered Control Center auto-refresh so task completion, runtime/browser state, activity, onboarding, Doctor/integrations and cached config/update changes appear without pressing Refresh. Polling pauses while hidden, refreshes immediately on focus, suppresses overlap/transient errors and preserves active local edit drafts.
- Fixed three Control Center live-refresh regressions: Overview no longer derives live ChatGPT/MCP connection status from onboarding availability, fast partial status refreshes no longer erase richer Peekaboo version/readiness state, and background auto-refresh GETs and the native menu-bar heartbeat no longer inflate the user-facing Control Center request counter.
- Added secure Telegram private-user pairing and first-time Setup guidance. Telegram is optional but marked Recommended; Setup teaches BotFather
/newbot, token copy, bot/start, detected-account confirmation and an explicit Skip for now path. Manual Telegram user-ID entry is no longer required by the UI. - Added a private bounded Telegram inbound-update foundation with persisted next-update offsets, private-user-only filtering, restart-safe replay prevention and a 50-message local queue. The agent surface still exposes no generic Telegram inbox/read operation.
- Added the Telegram task inbox layer: one durable/editable Telegram card per changed Task Capsule, bounded Continue/Cancel/Open-in-ChatGPT controls, reply→Task Capsule
humanInputrouting, private exact ChatGPT task binding and guarded bound Auto Continue for replies/Continue actions. Telegram task-message mappings and action reservations are durable; processing actions interrupted by restart become ambiguous and are never replayed automatically. - Added bounded Telegram file/photo exchange. A photo/document attached to an exact mapped task-card reply is downloaded through Bot API
getFileand exposed to the task only as opaque attachment metadata;telegram_attachment_openrequires the exact task + attachment id. Agents can send accessible local files/photos back withtelegram_send_file, which keeps the paired recipient fixed and reuses Local's normal file-export access policy. - Telegram inbound files now default to the visible
~/Downloads/Equinox Local/Telegram/folder. Control Center can switch the destination or reset it to default without restart; prior roots remain known so existing task attachments keep working, and user-visible downloads are not auto-deleted or removed on Telegram disconnect. - Web file transfer imports now default to the visible
~/Downloads/Equinox Local/Web/folder whenfile_importhas no explicit destination. Control Center can change/reset that default immediately, and user-visible imported files are not auto-deleted.
Fixed
- Resolved release-gate CodeQL findings in authenticated-HTTP and Telegram tests, and documented the intentionally bounded/private persistence boundary for validated Telegram network state.
- Removed a host-PID collision from the process-manager stop regression t...
Equinox Local 5.0.0
Added
- Added durable bounded Task Capsules for long-running agent work. Capsules persist human-readable objective/completed/next/reference state plus monotonic checkpoint revisions without duplicating ChatGPT transcripts. The store retains at most 50 capsules by default, prunes only oldest terminal records under capacity pressure, and Control Center supports bounded inspection, revision-guarded edits, completion/cancellation, pending-continuation cancellation and confirmed permanent deletion of completed/cancelled capsules.
- Added explicitly armed one-shot Auto Continue for ChatGPT tasks. Each automatic hop binds the exact Browser/profile/tab/conversation/user-turn identity, has a TTL, survives safe Local restarts while still armed, and must be explicitly re-armed; automatic chains are capped at three hops.
- Added a profile-local Equinox Browser popup selector for Auto Continue targeting: automatic current generating task by default, or one human-pinned open ChatGPT conversation.
- Added guarded Fresh Chat Resume for moving an active Task Capsule into one fresh ChatGPT conversation while preserving root/project scope, durable at-most-once transition state and confirmed destination rebinding without transcript copying.
- Added Task Recovery UX in Control Center for Fresh Chat Resume waiting/cancelled/ambiguous states, including explicit cancel/clear actions and human-readable stop reasons.
Changed
- Refreshed the 5.0 runtime baseline to Node
26.8.2, Peekaboo4.4.0, and Zod4.6.5; tunnel-client remains current at0.0.14, MCP SDK remains current at1.30.0, andnode-ptyintentionally stays on the current1.2.0-beta.15beta tag rather than regressing to npm's older1.1.0stable tag. - Reduced the agent-facing MCP connector surface from 15 top-level tools to 7 without removing capabilities: one unified read-only
capabilitiesdiscovery tool plusruntime_call,files_call,browser_call,desktop_call,release_callandintegrations_call. The empty Git gateway and duplicated*_toolscatalogs are removed; release QA/deployment share one domain; desktop maintenance is explicit; Browser exposes short operation aliases while retaining internal compatibility. - Control Center task rows and task details now show the durable
task-...Task Capsule ID so humans can match a visible task to agent handoff/resume instructions without guessing from the title. - Control Center navigation now includes Tasks alongside Overview, Projects, Browser, Safety, Services and Activity. Emergency Stop refreshes Task state after retiring pending continuations.
- The public source projection now includes the Task Capsule and Auto Continue runtime modules plus their regression coverage.
Fixed
- Fixed PTY natural-exit cleanup so background jobs that detach from the controlling TTY remain owned through their kernel POSIX session and are drained before the terminal session finalizes.
- Fixed macOS login/reboot startup so the LaunchAgent runtime host automatically restores one foreground Equinox Local shell when none is registered, bringing back the menu bar and Nyx companion without duplicating an already-running shell.
- Unified native Quit handling so menu-bar Quit, app-menu/Cmd-Q, Dock > Quit, and other normal macOS termination requests all pass through the same verified fail-closed LaunchAgent hard-stop lifecycle. Force Quit remains outside that graceful lifecycle guarantee.
Security
- Auto Continue is human-first and fail-closed: composing/new user input, Emergency Stop, explicit cancellation, target drift, a closed/navigated pin or an unsafe/non-empty composer prevents the next automatic turn. Stale explicit pins never fall back to another tab/profile. Delivery is reserved before browser mutation, the extension claims a bounded receipt before submission, and ambiguous delivery is never blindly retried.
- Fresh Chat Resume uses the same fail-closed boundary: destination creation/submission is receipt-guarded and at-most-once, only
preparedwork resumes after restart, and ambiguous browser mutation has no automatic or Control Center retry path. Clearing recovery state never replays the uncertain browser action.
Equinox Local 4.8.0
Added
- Added a native macOS menu-bar controller with live Active/Paused/Needs Attention state, Local-managed Terminal/process counts, Open Control Center, Agent Browser status/launch, Restart, Emergency Stop/Resume and safe Quit. Closing Control Center now keeps the menu-bar controller alive while removing the Dock icon; reopening restores the normal Dock/window presence.
- Added bounded
image_viewsupport to the Files gateway so an agent can visually inspect a user-supplied local PNG, JPEG or WebP path as real MCP image content. The capability follows structured Agent Access root rules, blocks protected/sensitive paths and symlinks, and enforces byte, dimension and pixel budgets without restoring generic file-read wrappers. - Added Control Center Emergency Stop / Resume with bounded Active Work counts and a global paused-state banner. Emergency Stop immediately marks the agent paused, blocks new mutating MCP operations, stops Equinox Local-managed Terminal/process work, keeps read-only status available, and records metadata-only audit events. Resume never restarts stopped work.
Changed
- Rebuilt Control Center around clearer workspace/system navigation, a focused runtime overview, explicit ChatGPT-to-Mac connection state, collapsible lower-priority diagnostics and persistent
System / Light / Darkappearance selection. System mode follows macOS theme changes, and small secondary/metadata text was enlarged for better readability at the native window size. - Reframed Control Center access around the terminal-first architecture: Local Execution is shown as the core logged-in-user capability; Browser and Desktop remain separate controls; structured Full/Selected scope and Terminal disable stay under Advanced restricted mode instead of being presented as a general sandbox.
- The menu-bar status item uses a compact native
ELmonogram for clear Equinox Local recognition while preserving Active/Paused/Offline opacity and tooltip cues.
Fixed
Quit Equinox Localnow performs a real fail-closed hard stop: it validates the trusted LaunchAgent, boots it out, stops the source-checkout tunnel-owned runtime when applicable, waits boundedly for Control Center to go offline, and only then exits the native app. Reopening the app safely bootstraps the trusted LaunchAgent without starting source and managed runtimes together.
Equinox Local 4.7.0
Added
- Added bounded
process_waitcontinuation for finite managed Terminal work, allowing agents to wait on the exact promoted process without polling log calls or restarting the command.
Changed
- Completed the terminal-first second-wave pruning: ordinary GitHub/Actions convenience wrappers, the retired asset inbox, rollback/recovery convenience reads and recipe discovery were removed while special release/deploy/runtime audit capabilities remain explicit. The retained non-Browser surface is 37 operations.
- Raised the supported Node.js floor and bundled managed runtime from Node
24.20.0to current Node26.8.1for Apple Silicon and Intel; public CI, release validation and future reviewer packages now use the same pinned runtime line. - Updated the bundled universal Peekaboo runtime from
4.3.0to4.3.3with the verified OpenClaw Developer ID/Team ID and new pinned upstream SHA-256. - Updated the direct
fast-uridependency from3.1.6to4.1.4;node-ptyintentionally remains on the newer1.2.0-beta.15line rather than regressing to the older1.1.0npm stable tag. - Refreshed npm lockfiles and compatible transitive dependencies while retaining current
@modelcontextprotocol/sdk,pixelmatch,pngjs,zodandtunnel-clientversions where upstream already matches the repository.
Fixed
- Fixed fresh-install Control Center launch so the verified native app executable starts directly with a clean detached environment before LaunchServices/browser fallbacks, avoiding first-launch races that could open localhost in Chrome even though the native app was healthy.