Releases: scottconverse/wagalo
Release list
Wagalo v0.3.3
Wagalo v0.3.3
This release turns the focused-mode containment added in 0.3.2 into a materially better research path.
Wagalo now decomposes multi-jurisdiction questions into explicit requirements, uses short official-source queries, ranks operative government and court records above generic coverage, follows linked public legal instruments, and preserves legal captions and filing metadata in its evidence excerpts. When a decisive primary document is partial, the focused packet recommends one retained inspection. That call returns up to 26,000 stored characters without downloading the document again or repeating the full evidence ledger.
The unchanged unassisted Codex benchmark made two Wagalo calls and used 199,335 input tokens, including 145,920 cached tokens. The original failure made 247 calls and used 9,661,583 input tokens. In the final run, Codex selected the Deere court filing and accurately reported its court, parties, docket, ECF history, allegations, antitrust basis, settlement posture, repair-access terms, and $1 million cost payment while declining to mislabel the payment as a penalty or the case as enforcement of a state repair statute.
Native Windows verification passed 135 core tests, TypeScript checking, changed-file lint, the security gate, and the production build. The benchmark still lacked primary records for several requested jurisdictions, so it correctly described those fields as not established and did not claim exhaustive nationwide recall.
All 29 full-profile tools remain available. Focused mode still advertises only research, search, and fetch, and retains the 0.3.2 connection-wide call, response-size, and time ceilings.
Wagalo v0.3.2
Wagalo v0.3.2
This release closes an installed-path containment defect in focused MCP mode.
The stdio proxy now sends its requested profile to the daemon. A focused desktop client connected to a full research daemon discovers only research, search, and fetch; the daemon rejects hidden tools and never lets a client elevate its capability profile.
Focused connections also have hard limits independent of model-supplied research run IDs: 25 accepted calls, 240,000 returned evidence characters, and 30 minutes by default. A stopped connection resets after 10 minutes without a tool call. Full research and action profiles still expose all 29 tools, and existing jobs, watches, evidence, credentials, HTTP transports, action mode, and operator data remain available.
Native Windows verification connected the real stdio proxy to a live research-profile daemon. It initialized as focused, listed exactly three tools, rejected a hidden cache call, accepted 25 bounded calls, and stopped call 26. The full 117-test core suite, 204-test application/tooling suite, TypeScript check, production build, and dependency audit passed.
This release does not claim control over a host model's internal reasoning or unrelated tools. DSH remains on Wigolo while Wagalo continues candidate evaluation.
Wagalo v0.3.1
Wagalo v0.3.1
Wagalo 0.3.1 completes the convergence plan’s compaction, deployment, and operator-diagnostic work while tightening the focused research path introduced in 0.3.0.
Focused clients now inherit one finite research run across research, search, and fetch, even when a constrained model drops the runId. Equivalent searches and unchanged fetches reuse retained evidence; failed fetches consume budget; saturated or exhausted runs return an answer-now contract. Multi-part research results omit raw discovery payloads and return bounded excerpts, exact source URLs, requirements, missing facts, contradiction candidates, budget state, and explicit rules against inventing absent values.
Targeted search now preserves important technical terms such as llama.cpp and gfx1151, avoids routing AMD hardware questions to JavaScript package registries, and uses repository-scoped GitHub issue and release discovery for provenance work. Unresolved requirements receive fair search turns, and the fetch budget is divided across those turns.
The Research Desk shows retained run diagnostics: normalized query fingerprints, new URL/domain counts, overlap, repeated search/fetch use, requirement coverage, budgets, estimated response characters, and stop reasons. Stdio supports proxy, embedded, and auto; auto mode uses an authenticated daemon health probe and falls back to embedded operation without changing the selected capability profile. Initialization and health metadata identify the active mode.
Compatibility
All 29 existing MCP names remain available in the full research and action profiles. The focused profile still exposes research, search, and fetch. Existing daemon, HTTP, proxy stdio, embedded stdio, Research Desk, jobs, watches, evidence, auth vault, local targets, and explicit action controls remain intact.
Verification
- 112 core tests and 204 detailed-console/tooling tests passed on native Windows before the release build.
- TypeScript and the production security checker passed.
- Cold deterministic benchmark: 2 searches, 3 fetches, 5 operations, 6,211 response characters,
requirements_resolved. - Warm continuation: same retained run, zero network operations, 2,602 response characters.
- Focused embedded and automatic fallback stdio initialize and discover
research,search, andfetch; full protocol checks retain all 29 names.
The deterministic benchmark proves convergence and accounting against a controlled corpus. Recent live DSH candidates finished within the plan’s time, tool-call, and projected-token ceilings, but the tested local model still omitted exact URLs for some material claims. That evidence-quality acceptance gate remains open and is documented in docs/TEST-EVIDENCE.md.
Wagalo v0.3.0
Wagalo v0.3.0
Wagalo 0.3.0 makes local agent research finite, inspectable, and easier for constrained models to use. A new focused MCP profile exposes three clear tools—search, fetch, and research—while the existing research and action profiles retain all 29 tool names and capabilities.
Research runs now carry a durable run ID, explicit requirements, evidence ledgers, search and fetch budgets, unresolved facts, possible contradiction candidates, and a recorded stop reason. Repeated equivalent queries and unchanged URLs reuse earlier evidence within a run unless the caller explicitly requests a refresh. Bounded research stops when its requirements are resolved, results saturate, its budget is exhausted, or its deadline is reached.
For desktop clients, WAGALO_MCP_MODE=embedded runs the MCP server directly over stdio without requiring the HTTP daemon. Proxy stdio remains the default, and the daemon, Research Desk, HTTP transports, watches, jobs, security controls, provider choices, and action tools remain available.
The Research Desk now shows agent research runs with budgets, unresolved requirements, stop reasons, and evidence details. Focused initialization instructions are shorter and include explicit stop and resume guidance for models with limited context.
Configure focused embedded stdio
Set the MCP command to an absolute node.exe path, pass the absolute bin/wagalo-mcp.mjs path, use the Wagalo repository as cwd, and set:
WAGALO_MCP_MODE=embedded
WAGALO_PROFILE=focused
Existing proxy configurations continue to work without these changes.
Verification
- 95 core tests and 204 sandbox tests passed locally.
- TypeScript checking, the development build, package dry run, dependency audit, current-tree secret scan, and security checks passed.
- Official MCP SDK protocol checks passed for proxy stdio, Streamable HTTP, and embedded focused stdio.
- Native Windows CI, Windows and Ubuntu tests, security matrices, and the optional ColBERT job passed on the release candidate.
- The deterministic DSH fixture completed in 22 ms with one search, three fetches, four total tool calls, all requirements resolved, and the
requirements_resolvedstop reason.
The deterministic fixture validates convergence and response shape; it is not a live DSH model-quality claim. A credential from older public history remains documented in GAP.md and still requires issuer-side rotation. Windows setup artifacts are unsigned.
Wagalo v0.2.1
Wagalo v0.2.1
Wagalo now identifies itself in every MCP tool description. This helps clients distinguish its web_search and web_fetch tools from their built-in search tools, including when the client omits the MCP server namespace.
Initialization instructions clarify that an explicit request to use Wagalo refers to this MCP server. Clients should report an unavailable connection rather than silently substituting another provider. All 29 tool names, schemas, aliases, and existing capabilities are retained.
Verification
- 77 local automated tests passed; TypeScript checking passed.
- Claude Desktop, Antigravity, LM Studio, Bionic, and OpenCode saved connections each discovered all 29 updated descriptions and fetched a test page.
- Native Codex discovery and an actual Codex Wagalo fetch passed.
- These connection checks do not prove natural-language tool selection in every application's model conversation. Bionic's earlier misselection is documented, but this release does not claim universal end-to-end client acceptance. The native OpenCode model test did not produce a result during its bounded check.
Reconnect or refresh the MCP server in clients that cache tool descriptions. No slash command is inherently required, but each client must expose Wagalo's tools to the conversation.
Windows setup is unsigned. The release workflow publishes the source archive and Windows setup archive with its checksum. This patch does not change model context settings or other search providers.
Wagalo v0.2.0
Verified downloads
- Windows setup: 44 MB ZIP with Node LTS and launcher; installs locked dependencies and models. Run
windows/Install.ps1after extraction. - Windows offline: 1.11 GB ZIP with Node, native packages, Chromium, ColBERT and English OCR. Run
windows/Install.ps1 -Offlineafter extraction. - Both packages were installed and tested on native Windows. Executables are unsigned. Checksum files accompany each ZIP.
- Read the final release acceptance record, including test counts, actual package verification, live DSH results, and remaining limits.
Wagalo 0.2.0 — capabilities and remaining limits
0.2.0 closes the unfinished tool, persistence, evidence and Windows containment gaps recorded for 0.1.3. Existing functionality and all 29 MCP names/aliases are preserved. This document distinguishes implemented behavior from external dependencies and unproven operating conditions; it is not a blanket parity claim.
Implemented and tested
| Area | Current behavior and evidence |
|---|---|
| Tool correctness | Line replacements and both diff inputs, raw JSON-LD, research page envelopes, content similarity, cache writes and pagination have behavioral tests. |
| Browser ownership | Windows worker enters its Job Object before Chromium launches. Native cancellation, concurrent-browser independence and forced-parent-death cleanup pass. Reattached parked sessions also respect cancellation. |
| Jobs and watches | SQLite checkpoints survive restart; paused/cancelled states are retained. Scheduled watches record baselines, content diffs and deduplicated history. They resume when the daemon starts. |
| Documents | Bounded binary download, PDF text with page references, scan OCR, full retained text and paginated retrieval. Native text/scanned-PDF fixtures pass. |
| Evidence | Unique snapshot IDs, retrieval dates, original/final URLs, content hashes, offline paging and full-text export. Old databases migrate without discarding operator data. |
| MCP | Existing stdio and /mcp bridge remain; /mcp/stream implements standard Streamable HTTP through the official SDK. Both discover the same 29 tools. |
| Operator experience | Research desk includes job controls, watches/history, evidence reading/export and diagnostics. Desktop/mobile browser checks pass. The older detailed console remains. |
| Research quality | Eight broader live queries found the expected domain in the top eight, with 16/16 selected pages retrieved. This is retrieval evidence, not a human relevance/recall evaluation. |
| Native dependencies | Security overrides remain sharp 0.35.4 / adm-zip 0.6.1; native Windows model/image/document tests are distinct from unit tests. |
See test evidence for exact acceptance stages and Windows delivery for packaging status.
Windows delivery
The repository contains a compiled-launcher builder, setup/offline package builder, checksum-verified Node LTS bootstrap, strict online/offline installation, Doctor, Repair, Uninstall and Rollback. The normal installation runs as the current user and starts at logon. Data, model choices, action mode and existing MCP integration are preserved.
Optional WinSW service configuration supports a separate LocalService data directory and automatic startup. Config generation has been tested. Installing and running that service requires a Windows administrator token; this development session did not have one. Service execution and signed-out endurance are therefore experimental, not claimed as verified. No automatic reboot or sign-out was performed.
Windows executables are unsigned. Code signing requires a publisher certificate and signing arrangement; no certificate is invented or silently purchased. Full offline assets are large. Asset build and installation outcomes are recorded with each release rather than inferred from a source build.
Remaining operational limits
- HTML search providers and remote sites can change, throttle or block requests. Failures stay visible in telemetry; no invented results. Key-gated providers still require operator credentials.
- Stealth/challenge waiting and the existing solver hook remain available. There is no guaranteed CAPTCHA/WAF bypass. A paid solver is an optional operator choice; none is silently enabled or purchased.
- Watches run while the daemon is running; missed downtime cannot reconstruct intermediate page versions. History is a local change record, not an external email/Slack notification service.
- Retained page/search evidence defaults to 30 days; a cursor or export can report expired evidence. OCR quality depends on the scan and language data. Worker limits can reject unusually large documents.
- Four browser sessions, operation deadlines and bounded network/document work protect resource usage. A shared ONNX call may finish native inference after request cancellation. This is not an OS-enforced CPU/RAM quota for the entire daemon.
- Optional synthesis validates referenced evidence IDs, not the truth of each generated sentence. It sends only explicitly requested research to the operator-configured model endpoint.
- Stdio remains a proxy to the daemon. A daemon-free standalone engine is a different deployment option, not required for MCP compatibility.
- The local benchmark is small. Aggregators sometimes outrank official technical sources. Longer relevance evaluation and multi-day field endurance remain ongoing product measurement.
- The old optional-console template contained a shared Grok preview credential in public source. The current source uses environment/private configuration and preserves the sign-in implementation. The issuer must rotate the old exposed credential; old Git history is not silently rewritten.
Compatibility contracts retained
Research is the default; action mode remains explicitly selectable. web_act and fetch actions still obey the selected profile. The auth vault and named local targets remain. Search/fetch cursors remain signed and tool-bound; missing snapshots never trigger a hidden new request. /mcp is never advertised as Streamable HTTP. See CHANGELOG.md for previous releases.
Wagalo v0.1.3
Wagalo 0.1.3 — honest gaps
This file is the release notes. If an auditor opens the repo looking for “combined parity with Halo + Wigolo,” start here.
0.1.3 completes the native Windows security and installation handoff. Same 29 tools, research default and ColBERTv2 default. No combined-parity claim. Health reports version, startup Git commit, installed sharp/adm-zip and current rerank state.
New in this release
- Shell-free Windows npm CLI invocation fixes the security gate. Sharp 0.35.4 and adm-zip 0.6.1 remain flattened; transformers/ONNX versions are unchanged.
- Installer runs npm ci, Playwright installation and strict ColBERT warmup before provenance, logon task or shortcut. Live failure fixtures cover each of those three prerequisite steps.
- ColBERT warmup executes two-item neural reranking; disabled, lexical or MiniLM fallback does not pass. One Windows Node 22 CI job repeats it with cached weights, independently of existing unit and security jobs.
- Current-user logon task runs the detached Start.ps1. Stop.ps1 does not unregister it.
- BrowserServer PID is attached to a Job Object and tracked before Playwright connects. Real Windows browser fetch and killTracked verified attachment and disconnection. launchServer can create Chromium children before it returns: inheritance of every earlier grandchild remains unproven.
- Official absolute-path DSH Cordis overlay example uses stdio; /mcp is not Streamable HTTP.
Windows regressions carried forward (measured on Windows 11, Node 24 and 25)
Soak report: HTTP contracts, DSH attach, ColBERT rerank, SQLite persistence, and koffi Job Object attach-when-given-a-PID all passed. Three product bugs did not.
| Id | Defect | Fix |
|---|---|---|
| W1 | bin/wagalo-mcp.mjs called process.exit(0) on stdin EOF. Windows libuv aborted with UV_HANDLE_CLOSING / exit 3221226505 (0xC0000409) after a successful initialize + tools/list. DSH's long-lived proxy was fine; standalone EOF was not. |
Drain pending fetches, close the undici agent, set exitCode = 0. Never process.exit(). Guard stdout EPIPE. |
| W2 | chromium.launch() Browser has no process(). Parked sessions registered no PID, so killTracked left Chromium connected. koffi Job Objects worked on a disposable Node child. |
chromium.launchServer() + connect(). PID from BrowserServer.process(). Attach at open, not only park. killTracked still process.kills tracked PIDs if the job is empty. |
| W3 | Start.ps1 ran npm start in the foreground. WM_CLOSE on that console killed the daemon and left wagalo.pid. |
Start-Process detached node. Start.ps1 returns. Closing the launcher must not kill 8787. Shutdown unlinks the pid file. |
| W4 | npm audit 4 high on @huggingface/transformers / onnxruntime-node / adm-zip / sharp. |
Root overrides: sharp@0.35.4, adm-zip@0.6.1 (not 0.6.0). onnxruntime-node is pinned to that adm-zip. scripts/check-security.mjs + security-regression workflow. Do not bump transformers/ONNX unless those overrides fail compatibility. |
Relative bin/wagalo-mcp.mjs from C:\ still fails (expected). Absolute proxy path does not require repo cwd; DSH overlay should keep both absolute args and cwd anyway.
What 0.1.1 added over 0.1.0
- Default reranker: ColBERTv2 MaxSim after a 55-query / 24-candidate developer bake-off (
docs/rerank-q2d-web.md). MiniLM is the load fallback. RRF fusion is unchanged. - Swappable via
WAGALO_RERANK_MODEL/config.jsonrerank.model.WAGALO_RERANK=offstays lexical. - CI actually green: Wagalo tests only,
WAGALO_RERANK=offso runners do not download ONNX weights. - Release workflow is idempotent if the GitHub Release for the tag already exists.
What this tag does include
- MCP JSON-RPC over HTTP and stdio NDJSON
- Halo-style evidence envelopes and public/local split
- HMAC-signed, tool-bound cursors persisted in SQLite. Cursor-only is immutable: no silent re-search,
CURSOR_CACHE_MISSis terminal - Fetch ladder HTTP → TLS (
impit) → Playwright → stealth → challenge sit - Research profile default; action profile is an explicit env flag
- SQLite jobs, snapshots, FTS cache, local named targets
- Auth vault using the on-disk
master.key(AES-256-GCM), not a fixed string - Engine catalog including Marginalia, Mojeek, DevDocs, Bing News, GitHub repos, GitHub code (token)
- Windows
Install.ps1/Start.ps1/Stop.ps1 - Unit tests for SSRF, profiles, cursors, vault, jobs, MCP catalog, rerank config
- AGPL-3.0-or-later
What it does not claim
| Area | 0.1.3 status |
|---|---|
| Combined Halo+Wigolo product parity | Not claimed. Foundation plus tests. |
Compiled Windows .exe |
Not shipped. Installer is PowerShell + Node 22. A source zip is the GitHub Release asset. |
| Windows Job Objects | koffi attach works when given a PID (soak). Playwright PID now comes from launchServer(). Chromium grandchildren launched before assign may still sit outside the job. |
| ONNX rerank | ColBERTv2 is the default after a 55-query developer bake-off (docs/rerank-q2d-web.md). MiniLM is the load fallback. EmbeddingGemma-300M (best small Q2D-Web dense we could run) tied MiniLM on nDCG@10 and missed the latency budget (5.2s / 1.6GB). Existing unit tests remain isolated; the separate Windows Node 22 ColBERT job loads the real model and executes neural reranking without disabling it. |
| Playwright stealth vs real WAFs | Implemented. Not an adversarial bypass guarantee. |
| Captcha solver | Hook only (solver.ts). No 2captcha/AntiCaptcha client. |
| Halo Python daemon budgets / Windows service | Node process. Not a service wrapper, not Halo’s original budget daemon. |
| Wigolo per-session stdio-only (no daemon) | Daemon + stdio proxy. The proxy does not spawn engines itself. |
| Engine HTML scrapers (Bing, DDG, Mojeek, Bing News) | Best-effort. Markup drift is ENGINES_DEGRADED, not invented hits. |
| GitHub code search | Implemented; skipped without GITHUB_TOKEN. |
| Brave / Exa | Implemented; skipped without keys. |
document_extract PDF |
unpdf then heuristic literals. Empty body stays empty — no fake prose. |
| Watch / diff / find_similar | Implemented at foundation depth. Watch is in-process, dies with the daemon. |
| Operator console | TanStack Start UI in this repo. Optional. Daemon does not require it. |
| Cross-compilation from Linux to a signed Windows binary | Not done. GitHub Actions windows-latest runs tests, it does not emit an .exe. |
Cursor contract (testable)
web_searchwith emptyqueryand nocursor→{ ok: false, code: "EMPTY_QUERY" }.web_searchwith a valid cursor and no stored snapshot →{ ok: false, code: "CURSOR_CACHE_MISS" }. Must not run engines.web_searchwith a valid cursor and a stored snapshot → page slice +CURSOR_PAGE. Query is ignored.
Profile contract (testable)
- Default profile denies
web_actwithPROFILE_RESEARCH_READONLY. web_fetchwithactions[]in research profile is denied the same way.WAGALO_PROFILE=actionallows both.
If you are installing on Windows
Install.ps1 is the supported path. After Start.ps1, GET /api/health must return "version": "0.1.3". The daemon is detached; Stop.ps1 is how it dies. If Playwright was skipped, js=true / stealth fetches will fail closed with a named warning, not hang.
Next
A later tag can add a real Windows launcher, a service wrapper, freeze ColBERT ONNX in the release zip, and assign Chromium to the job before it spawns children. None of that is hiding in 0.1.3 under a parity banner.
Wagalo v0.1.2
Wagalo 0.1.2 — honest gaps
This file is the release notes. If an auditor opens the repo looking for “combined parity with Halo + Wigolo,” start here.
0.1.2 is 0.1.1 plus the Windows soak (2026-09-11). Same foundation, same ColBERTv2 default, no combined-parity claim. Health must return "version": "0.1.2".
What 0.1.2 fixes (measured on Windows 11, Node 24 and 25)
Soak report: HTTP contracts, DSH attach, ColBERT rerank, SQLite persistence, and koffi Job Object attach-when-given-a-PID all passed. Three product bugs did not.
| Id | Defect | Fix |
|---|---|---|
| W1 | bin/wagalo-mcp.mjs called process.exit(0) on stdin EOF. Windows libuv aborted with UV_HANDLE_CLOSING / exit 3221226505 (0xC0000409) after a successful initialize + tools/list. DSH's long-lived proxy was fine; standalone EOF was not. |
Drain pending fetches, close the undici agent, set exitCode = 0. Never process.exit(). Guard stdout EPIPE. |
| W2 | chromium.launch() Browser has no process(). Parked sessions registered no PID, so killTracked left Chromium connected. koffi Job Objects worked on a disposable Node child. |
chromium.launchServer() + connect(). PID from BrowserServer.process(). Attach at open, not only park. killTracked still process.kills tracked PIDs if the job is empty. |
| W3 | Start.ps1 ran npm start in the foreground. WM_CLOSE on that console killed the daemon and left wagalo.pid. |
Start-Process detached node. Start.ps1 returns. Closing the launcher must not kill 8787. Shutdown unlinks the pid file. |
| W4 | npm audit 4 high on @huggingface/transformers / onnxruntime-node / adm-zip / sharp. |
Not patched. Audit is not a demonstrated exploit. Do not bump transformers without a rerank bake-off. |
Relative bin/wagalo-mcp.mjs from C:\ still fails (expected). Absolute proxy path does not require repo cwd; DSH overlay should keep both absolute args and cwd anyway.
What 0.1.1 added over 0.1.0
- Default reranker: ColBERTv2 MaxSim after a 55-query / 24-candidate developer bake-off (
docs/rerank-q2d-web.md). MiniLM is the load fallback. RRF fusion is unchanged. - Swappable via
WAGALO_RERANK_MODEL/config.jsonrerank.model.WAGALO_RERANK=offstays lexical. - CI actually green: Wagalo tests only,
WAGALO_RERANK=offso runners do not download ONNX weights. - Release workflow is idempotent if the GitHub Release for the tag already exists.
What this tag does include
- MCP JSON-RPC over HTTP and stdio NDJSON
- Halo-style evidence envelopes and public/local split
- HMAC-signed, tool-bound cursors persisted in SQLite. Cursor-only is immutable: no silent re-search,
CURSOR_CACHE_MISSis terminal - Fetch ladder HTTP → TLS (
impit) → Playwright → stealth → challenge sit - Research profile default; action profile is an explicit env flag
- SQLite jobs, snapshots, FTS cache, local named targets
- Auth vault using the on-disk
master.key(AES-256-GCM), not a fixed string - Engine catalog including Marginalia, Mojeek, DevDocs, Bing News, GitHub repos, GitHub code (token)
- Windows
Install.ps1/Start.ps1/Stop.ps1 - Unit tests for SSRF, profiles, cursors, vault, jobs, MCP catalog, rerank config
- AGPL-3.0-or-later
What it does not claim
| Area | 0.1.2 status |
|---|---|
| Combined Halo+Wigolo product parity | Not claimed. Foundation plus tests. |
Compiled Windows .exe |
Not shipped. Installer is PowerShell + Node 22. A source zip is the GitHub Release asset. |
| Windows Job Objects | koffi attach works when given a PID (soak). Playwright PID now comes from launchServer(). Chromium grandchildren launched before assign may still sit outside the job. |
| ONNX rerank | ColBERTv2 is the default after a 55-query developer bake-off (docs/rerank-q2d-web.md). MiniLM is the load fallback. EmbeddingGemma-300M (best small Q2D-Web dense we could run) tied MiniLM on nDCG@10 and missed the latency budget (5.2s / 1.6GB). CI still sets WAGALO_RERANK=off so unit tests do not download weights. |
| Playwright stealth vs real WAFs | Implemented. Not an adversarial bypass guarantee. |
| Captcha solver | Hook only (solver.ts). No 2captcha/AntiCaptcha client. |
| Halo Python daemon budgets / Windows service | Node process. Not a service wrapper, not Halo’s original budget daemon. |
| Wigolo per-session stdio-only (no daemon) | Daemon + stdio proxy. The proxy does not spawn engines itself. |
| Engine HTML scrapers (Bing, DDG, Mojeek, Bing News) | Best-effort. Markup drift is ENGINES_DEGRADED, not invented hits. |
| GitHub code search | Implemented; skipped without GITHUB_TOKEN. |
| Brave / Exa | Implemented; skipped without keys. |
document_extract PDF |
unpdf then heuristic literals. Empty body stays empty — no fake prose. |
| Watch / diff / find_similar | Implemented at foundation depth. Watch is in-process, dies with the daemon. |
| Operator console | TanStack Start UI in this repo. Optional. Daemon does not require it. |
| Cross-compilation from Linux to a signed Windows binary | Not done. GitHub Actions windows-latest runs tests, it does not emit an .exe. |
Cursor contract (testable)
web_searchwith emptyqueryand nocursor→{ ok: false, code: "EMPTY_QUERY" }.web_searchwith a valid cursor and no stored snapshot →{ ok: false, code: "CURSOR_CACHE_MISS" }. Must not run engines.web_searchwith a valid cursor and a stored snapshot → page slice +CURSOR_PAGE. Query is ignored.
Profile contract (testable)
- Default profile denies
web_actwithPROFILE_RESEARCH_READONLY. web_fetchwithactions[]in research profile is denied the same way.WAGALO_PROFILE=actionallows both.
If you are installing on Windows
Install.ps1 is the supported path. After Start.ps1, GET /api/health must return "version": "0.1.2". The daemon is detached; Stop.ps1 is how it dies. If Playwright was skipped, js=true / stealth fetches will fail closed with a named warning, not hang.
Next
A later tag can add a real Windows launcher, a service wrapper, freeze ColBERT ONNX in the release zip, and assign Chromium to the job before it spawns children. None of that is hiding in 0.1.2 under a parity banner.
Wagalo v0.1.1
Wagalo 0.1.1 — honest gaps
This file is the release notes. If an auditor opens the repo looking for “combined parity with Halo + Wigolo,” start here.
0.1.1 is a foundation plus a measured reranker. Implemented, tested on Linux and Windows in GitHub Actions (npm test = Wagalo unit tests). It is not a claim that every item on a 60-row union checklist is production-proven on an installed Windows box.
0.1.0 CI was red. Eight leftover grok-pwa sandbox tests read .grok/ files that are gitignored from this public repo. Those tests still exist as npm run test:sandbox. They are not a Wagalo product gate. Default npm test and CI run src/lib/wagalo/*.test.ts only.
What this tag adds over 0.1.0
- Default reranker: ColBERTv2 MaxSim after a 55-query / 24-candidate developer bake-off (
docs/rerank-q2d-web.md). MiniLM is the load fallback. RRF fusion is unchanged. - Swappable via
WAGALO_RERANK_MODEL/config.jsonrerank.model.WAGALO_RERANK=offstays lexical. - CI actually green: Wagalo tests only,
WAGALO_RERANK=offso runners do not download ONNX weights. - Release workflow is idempotent if the GitHub Release for the tag already exists.
What this tag does include
- MCP JSON-RPC over HTTP and stdio NDJSON
- Halo-style evidence envelopes and public/local split
- HMAC-signed, tool-bound cursors persisted in SQLite. Cursor-only is immutable: no silent re-search,
CURSOR_CACHE_MISSis terminal - Fetch ladder HTTP → TLS (
impit) → Playwright → stealth → challenge sit - Research profile default; action profile is an explicit env flag
- SQLite jobs, snapshots, FTS cache, local named targets
- Auth vault using the on-disk
master.key(AES-256-GCM), not a fixed string - Engine catalog including Marginalia, Mojeek, DevDocs, Bing News, GitHub repos, GitHub code (token)
- Windows
Install.ps1/Start.ps1/Stop.ps1 - Unit tests for SSRF, profiles, cursors, vault, jobs, MCP catalog, rerank config
- AGPL-3.0-or-later
What it does not claim
| Area | 0.1.1 status |
|---|---|
| Combined Halo+Wigolo product parity | Not claimed. Foundation plus tests. |
Compiled Windows .exe |
Not shipped. Installer is PowerShell + Node 22. A source zip is the GitHub Release asset. |
| Windows Job Objects | koffi + CreateJobObjectW bindings are in containment.ts. Untested on a real Windows box in this tag. POSIX path is tracked PIDs. |
| ONNX rerank | ColBERTv2 is the default after a 55-query developer bake-off (docs/rerank-q2d-web.md). MiniLM is the load fallback. EmbeddingGemma-300M (best small Q2D-Web dense we could run) tied MiniLM on nDCG@10 and missed the latency budget (5.2s / 1.6GB). CI still sets WAGALO_RERANK=off so unit tests do not download weights. |
| Playwright stealth vs real WAFs | Implemented. Not an adversarial bypass guarantee. |
| Captcha solver | Hook only (solver.ts). No 2captcha/AntiCaptcha client. |
| Halo Python daemon budgets / Windows service | Node process. Not a service wrapper, not Halo’s original budget daemon. |
| Wigolo per-session stdio-only (no daemon) | Daemon + stdio proxy. The proxy does not spawn engines itself. |
| Engine HTML scrapers (Bing, DDG, Mojeek, Bing News) | Best-effort. Markup drift is ENGINES_DEGRADED, not invented hits. |
| GitHub code search | Implemented; skipped without GITHUB_TOKEN. |
| Brave / Exa | Implemented; skipped without keys. |
document_extract PDF |
unpdf then heuristic literals. Empty body stays empty — no fake prose. |
| Watch / diff / find_similar | Implemented at foundation depth. Watch is in-process, dies with the daemon. |
| Operator console | TanStack Start UI in this repo. Optional. Daemon does not require it. |
| Cross-compilation from Linux to a signed Windows binary | Not done. GitHub Actions windows-latest runs tests, it does not emit an .exe. |
Cursor contract (testable)
web_searchwith emptyqueryand nocursor→{ ok: false, code: "EMPTY_QUERY" }.web_searchwith a valid cursor and no stored snapshot →{ ok: false, code: "CURSOR_CACHE_MISS" }. Must not run engines.web_searchwith a valid cursor and a stored snapshot → page slice +CURSOR_PAGE. Query is ignored.
Profile contract (testable)
- Default profile denies
web_actwithPROFILE_RESEARCH_READONLY. web_fetchwithactions[]in research profile is denied the same way.WAGALO_PROFILE=actionallows both.
If you are installing on Windows
Install.ps1 is the supported path. After Start.ps1, GET /api/health must return "version": "0.1.1". If Playwright was skipped, js=true / stealth fetches will fail closed with a named warning, not hang.
Next
A later tag can add a real Windows launcher, a service wrapper, Job Object soak tests on hardware, and a frozen ColBERT ONNX in the release zip. None of that is hiding in 0.1.1 under a parity banner.
Wagalo 0.1.0
Wagalo 0.1.0 — honest gaps
This file is the release notes. If an auditor opens the repo looking for “combined parity with Halo + Wigolo,” start here.
0.1.0 is a foundation. Implemented, tested on Linux in CI, Windows-targeted with PowerShell scripts and a windows-latest CI job. It is not a claim that every item on a 60-row union checklist is production-proven on an installed Windows box.
What this tag does include
- MCP JSON-RPC over HTTP and stdio NDJSON
- Halo-style evidence envelopes and public/local split
- HMAC-signed, tool-bound cursors persisted in SQLite. Cursor-only is immutable: no silent re-search,
CURSOR_CACHE_MISSis terminal - Fetch ladder HTTP → TLS (
impit) → Playwright → stealth → challenge sit - Research profile default; action profile is an explicit env flag
- SQLite jobs, snapshots, FTS cache, local named targets
- Auth vault using the on-disk
master.key(AES-256-GCM), not a fixed string - Engine catalog including Marginalia, Mojeek, DevDocs, Bing News, GitHub repos, GitHub code (token)
- Windows
Install.ps1/Start.ps1/Stop.ps1 - Unit tests for SSRF, profiles, cursors, vault, jobs, MCP catalog
- AGPL-3.0-or-later
What it does not claim
| Area | 0.1.0 status |
|---|---|
| Combined Halo+Wigolo product parity | Not claimed. Foundation plus tests. |
Compiled Windows .exe |
Not shipped. Installer is PowerShell + Node 22. A source zip is the GitHub Release asset. |
| Windows Job Objects | koffi + CreateJobObjectW bindings are in containment.ts. Untested on a real Windows box in this tag. POSIX path is tracked PIDs. |
| MiniLM ONNX rerank | @huggingface/transformers + Xenova/all-MiniLM-L6-v2 is attempted. Missing model cache falls back to lexical rerank with a warning. CI sets WAGALO_RERANK=off. |
| Playwright stealth vs real WAFs | Implemented. Not an adversarial bypass guarantee. |
| Captcha solver | Hook only (solver.ts). No 2captcha/AntiCaptcha client. |
| Halo Python daemon budgets / Windows service | Node process. Not a service wrapper, not Halo’s original budget daemon. |
| Wigolo per-session stdio-only (no daemon) | 0.1.0 is daemon + stdio proxy. The proxy does not spawn engines itself. |
| Engine HTML scrapers (Bing, DDG, Mojeek, Bing News) | Best-effort. Markup drift is ENGINES_DEGRADED, not invented hits. |
| GitHub code search | Implemented; skipped without GITHUB_TOKEN. |
| Brave / Exa | Implemented; skipped without keys. |
document_extract PDF |
unpdf then heuristic literals. Empty body stays empty — no fake prose. |
| Watch / diff / find_similar | Implemented at foundation depth. Watch is in-process, dies with the daemon. |
| Operator console | TanStack Start UI in this repo. Optional. Daemon does not require it. |
| Cross-compilation from Linux to a signed Windows binary | Not done. GitHub Actions windows-latest runs tests, it does not emit an .exe. |
Cursor contract (testable)
web_searchwith emptyqueryand nocursor→{ ok: false, code: "EMPTY_QUERY" }.web_searchwith a valid cursor and no stored snapshot →{ ok: false, code: "CURSOR_CACHE_MISS" }. Must not run engines.web_searchwith a valid cursor and a stored snapshot → page slice +CURSOR_PAGE. Query is ignored.
Profile contract (testable)
- Default profile denies
web_actwithPROFILE_RESEARCH_READONLY. web_fetchwithactions[]in research profile is denied the same way.WAGALO_PROFILE=actionallows both.
If you are installing on Windows
Install.ps1 is the supported path. After Start.ps1, GET /api/health must return "version": "0.1.0". If Playwright was skipped, js=true / stealth fetches will fail closed with a named warning, not hang.
Next
A later tag can add a real Windows launcher, a service wrapper, Job Object soak tests on hardware, and a frozen MiniLM model in the release zip. None of that is hiding in 0.1.0 under a parity banner.