Headline: durable outbound delivery, and integrity stamps on every task writer. A shared Delivery Core gives outbound work one claim/recovery policy with three explicit outcomes, and every production task writer now stamps an HMAC envelope over the task — including its access_tier — with a census measuring readiness to enforce. The same release hardens the live voice, vision, startup, and channel paths around those boundaries.
220 PRs since v0.11.0: 43 features, 122 fixes.
Added
- A channel-neutral Delivery Core owns outbox claims, recovery, receipts, reconciliation, and terminal disposition; Discord is the first production provider, and Design C supplies the alternate namespace backend behind the same contract. (#2975, #3013, #3092, #3095, #3104, #3123)
- HMAC task envelopes stamp task text — including
access_tier— at every production writer: the gateway, Discord, Telegram, Slack, cron, workstream, and TypeScript edges. A soak census reports how much live traffic would pass verification. Stamping only in this release; nothing verifies or rejects at ingress yet. (#3014, #3041, #3044, #3046, #3058) - Proactive results can carry an explicit destination, and AG2 Space is a first-class proactive channel with claim and wake-catch-up behavior. (#2877, #3113)
- Voice reliability gains audio-progress and upstream ledgers, a health matrix, bounded vision egress, CONNECTING recovery, event-driven redial, and an ACTIVE-silence watchdog in shadow mode. (#2885, #2902, #2963, #3130, #3132, #3138, #3139, #3143)
- Operator surfaces gain a one-command
./start.sh, bounded provider reads for local apps, mechanical cron execution, Discord edit/reply commands, Room Opssay/members, a packaged pointer overlay, and display selection for vision. (#2753, #2760, #2969, #2976, #2987, #3049, #3053, #3068, #3159, #3168)
Fixed
- 122 fixes across delivery, startup, health, voice, vision, and channel bridges. Notable: gateway/bridge processes now recover without destroying work (#2819, #2867, #2900, #3011, #3147); ambiguous or suppressed results keep the correct ownership and delivery semantics (#2936, #3018, #3108, #3109, #3141, #3176, #3187); and context-drop releases the triggering modifiers before synthesizing Copy in webviews (#3173).
- Vision and screen-control paths now enforce their documented frame/cadence bounds, stop terminally on disconnect, report denials honestly, and target the display the caller measured. (#2885, #2942, #2961, #3088, #3089, #3090, #3139, #3163, #3164, #3169)
- Health reporting no longer turns stale, future-dated, running, or unknown observations into false all-clears, and can restart failed channel bridges under the shared launch policy. (#2316, #2743, #2874, #2905, #2906, #2978, #3000, #3052, #3059, #3062, #3071, #3078, #3118, #3161, #3190)
Security
- Secret-bearing room reads and taskify writes are redacted at ingress; pairing codes stay in the owner's DM; and the moderation judge wraps untrusted text in explicit delimiters. (#1986, #2158, #2893, #2955, #2956, #2957)
- Corrupt envelope keys fail loudly or as unverifiable, never as empty keys, and collaborator output remains governed by the owner-review flow. (#2983, #3065, #3141)
Changed
- No breaking changes and no new numbered workspace migrations. The existing workspace migration now preserves owner-custom tools under
<workspace>/scripts/, with collision retention and idempotency coverage. Upgrading from v0.11.0 requires no manual action; rollback isgit checkout v0.11.0. (#3036)
Full commit range: v0.11.0...v0.12.0