Repository navigation
Talos 0.20.0-beta.4 — Safer tool protocol and model catalog sync
Pre-releaseSafer tool protocol, bounded QMP plan, and automatic model catalogues
Talos 0.20.0-beta.4 hardens how model output becomes a tool proposal. Tool results
remain explicitly untrusted, duplicate JSON keys and malformed top-level arguments
are rejected, only one final unfenced TOOL_CALL is accepted, and all repair paths
share one bounded budget. A malformed proposal still cannot bypass the deterministic
permission kernel.
Configured provider model catalogues now refresh in a background thread, outside the
startup and reply paths. Complete, validated API or local-server snapshots can remove
retired models. Partial CLI, OAuth and Hermes listings are additive only. Failed
refreshes preserve the last known-good cache, provider credentials keep their existing
routes, and Talos never silently replaces an active model that disappears.
The QMP work is now a generic QmpInputAdapter plus a deliberately narrow deployment
plan: one fixed x86_64 Debian/Hyprland guest at 1440×900 under QEMU TCG on Apple
silicon. The plan excludes HVF, inbound forwarding, bridged or tap networking, host
folders, clipboard sharing and host credentials. Talos does not bundle or download
QEMU or a guest disk. This target is prepared and unit-tested, but not yet
hardware-qualified and therefore is not offered as a supported Mac app Computer.
Beta does not mean error-free operation. This release changes neither the frozen
operator contract nor the rule that the model proposes and the kernel decides.
Updating
Review this release, then use talos update when ready. Publication alone does not
upgrade or restart an existing installation. The signed updater preserves operator
configuration, conversation data and schedules and retains the previous tree for
rollback.
For a new installation, use the instructions at https://talos-agent.ch/.
The attached archive is accompanied by a SHA-256 digest and an Ed25519 signature.
Python 3.11–3.13, Linux and macOS are supported.
Release evidence
- Public source commit:
ae1e12a36e4c8be7575cf2a72b3bd6fcda18e112 - Archive SHA-256:
5c9c07bdf98d1504aef66a91c6d60df14a111da2c130123251a72eb9535e7c05 - Hosted CI: Ubuntu and macOS completed successfully, including 3,214 passed tests,
two expected skips, 263/263 adversarial cases, desktop-boundary tests, and the
source-built macOS preview - Local release gate: 3,215 passed tests, one expected skip; 263/263 adversarial
cases; 44/44 real-model cases; Swift tests 3/3 - Two clean installs and two signed Beta.3 → Beta.4 upgrade, migration and rollback
rehearsals passed from the exact attached archive - OSV: zero findings in all shipped Python locks and the Swift resolution
- Public hygiene and staged secret scan: zero findings; all 441 archive members were
inspected and the signature rejected a tampered archive