Releases: umeranjum17/byokit
Release list
@byokit/usage 0.7.0
- FIX: Subscription usage views now derive today, activity and people from one account-scoped call snapshot, preserve unknown token counts and distinguish quota polling failures from exhaustion; plan and model labels use plain names.
npm: @byokit/usage@0.7.0
@byokit/openclaw 0.6.1
- FIX: Let apps declare
appOwnedSessions.keyPrefixesbefore Gateway startup so caller-requeued task sessions do not also receive an engine-started recovery turn. Preserve session history, policy gates, API-key session mapping and stock recovery for other namespaces. - FIX: Launch each broker's Chromium with its own short mode-0700 temp directory under the caller's temp directory, removed on close, instead of using the profile path as TMPDIR; deep app profile paths overflowed Chromium's singleton socket path and aborted startup.
- FIX: A controlling viewer ignores frames from a previous target and drops input until the current private target has delivered its first image, so popup switches cannot map input with stale coordinates.
- FIX: The broker's browser endpoint and
/json/versionnow use Chromium's canonical/devtools/browser/<id>?token=shape, so the pinned engine's CDP discovery finds/json/listinstead of failing with HTTP 404; token, host and origin guards are unchanged and the old bare path is refused. - FIX: Chromium's sandbox stays on; a launch refused for no usable sandbox (for example where unprivileged user namespaces are disabled) now fails with typed
BrowserSandboxUnavailableinstead of a generic failure, and is never retried unsandboxed. Startup stderr is used only in memory for that check. - FIX: Wire opt-in member browsers to the shipped bridge and stock engine, with a dead default profile, member-pinned browser actions, kit browser invalidation events and scoped browser-engine checks. Sign-in handoff remains
handoff-unprotected; no recovery-protection or automatic resume redispatch claim is made. - SECURITY: Register the published awaited OpenClaw/Codex tool-result middleware, scrub owned broker capabilities before live model feedback, recheck session admission per result, and terminate on refusal or unavailable protection. Transcript hooks are supplementary; actual full privacy/recovery qualification remains pending.
- FIX: Honor the stock allow/alsoAllow schema, create model-free audit sessions for effective-tool checks, and acknowledge redacted CDP profiles only against an unchanged exact host-owned endpoint and matching applied-source revisions.
- FIX: Explicitly clear hostile node selection across the stock hook's shallow parameter merge; browser proof fixtures distinguish normal model completion from successful tool execution.
- SECURITY: A definite failed sign-in resume no longer permits arbitrary recovery turns: replacement requires a fresh live kit registration matching the exact engine run id and session, revoked on release or bridge shutdown. Source controls cover parked and every unproved resume state; actual engine qualification remains pending. Reconnect keeps tool subsets but revokes submission authority, and waits for old Unix socket teardown before rebinding; shutdown cancels outstanding calls.
- SECURITY: Browser use requires a closed explicit safe tool policy across every engine agent, account agent and delegate; unsafe and unknown effective tools refuse every browser, model-facing profile management/evaluation is blocked before app approval, and raw agent/plugin/config policy mutations require the guarded config path.
- FEAT: Portable types for the browser sign-in handoff and live view (
NeedSignIn,BrowserState,LiveViewState,BrowserHost,BrowserDeviceand friends) from.and./device, per spec 5.17. Types only: no runtime ships yet, and handoff stays refused until parked sessions are protected. - Allow the internal browser host to attach newly created owned-member browsers and replace exact owned endpoints with stale-identity guards, private-target cleanup barriers and read-only versioned bindings for guarded configuration publication. Request bounded thumbnails through the owned viewer. Production sign-in handoff remains blocked pending qualification.
- Add the internal browser handoff host, durable settlement and conservative resume bookkeeping, with offline synthetic fixtures. Production sign-in remains blocked pending recovery-protection qualification.
- Add member-scoped browser sign-in actions, private browser live view and portable device helpers. Browser frames and lease capabilities travel on transient encrypted streams, outside durable link answer caches; control requires the host's immediate grant-revocation seam. Watching or reconnecting never dispatches a model run.
- FIX: Preserve browser reply and event order when messages arrive together, so page evaluation can receive its initial context instead of waiting indefinitely.
- SECURITY: Ship a content-addressed bundled-engine patch manifest and the pinned OpenClaw MIT notice. Fully verified read-only sibling engine sets replace in-place installation; base and existing set bytes are never changed, even when shared Gateways are live.
KitState.patchSetandwhy: 'engine-patch'expose provenance; rollback selects verified stock offline, while stock drift may need registry access. The initial patch set is empty. getConfigKey/setConfigKeyread and write exactly one dotted config key in the fileprepare()owns, so an app can narrow-read and restore a value (for exampleskills.workshop.autonomous.mode) around a boot without a wholeconfig.get, whose result redacts token-bearing values. Only that key changes, the write is atomic inprepare()'s exact shape and happens only when the bytes change, andundefinedremoves the key.- FIX: Persist detached Workshop review usage, including reported usage on failed outcomes, without double-counting memory flushes, recovery resumes or run results. Per-boot/month attempt counters, fsynced launch and clean-stop records, phase deduplication and bounded month reads preserve failure holes and crash incompleteness.
- SECURITY: The bundled checksum-pinned Gateway Workshop patch and operator-read usage RPC write/read accounting identities, times and reported counters only, never prompts, outputs, tool arguments or credentials. Device reads stay member-scoped and never access host files; unknown costs and unverified billing identity are not guessed.
- FIX:
stop()now signals only the pids the kit itself spawned and never a process group, so shutdown no longer reaches processes the kit never started. Every spawn is recorded when it starts and dropped when it exits; the gateway is left to shut its own sessions down on its own SIGTERM. - Unreleased source dependency metadata: pin @byokit/seal 0.3.0 and @byokit/relay 0.5.2; this package's existing version is not republished. Previously published consumer metadata remains unchanged.
- SECURITY: Sensitive subscription sign-in tokens stay out of sign-in views and results, including engine errors, links and codes after token entry.
- FIX: Subscription setup-token sign-in now answers sensitive wizard text steps from the existing paste channel, once per step, with cancellation and timeout preserved. API key (billed per use) entry still requires explicit selection.
npm: @byokit/openclaw@0.6.1
@byokit/infer 0.1.0
- FIX: Express the summary prompt's success/insufficient branches in the native JSON grammar schema as well as JS validation: true requires 3–4 single-line strings; false requires an empty array. The exact native false-with-four-lines regression stays invalid; no Boolean coercion or contradictory-output acceptance.
- Improved: Serialize summary lines before the adequacy flag so the local decoder produces facts first. The same strict true/3–4-lines and false/empty union, parser and honest refusal remain unchanged.
- FIX: State the successful summary protocol explicitly instead of only giving a negative JSON example. Enforce enough:true with 3–4 single-line strings or enough:false with an empty array; contradictory flags, newlines, extra fields and overlong strings are invalid, never coerced into success.
- FIX: Model-install storage checks now report a typed failure and truthful failed state when size, free-space or an existing-file hash cannot be read, instead of leaving the app looking not-installed with no usable error.
- SECURITY: Only the pinned model file is ever downloaded; inference has no network path, telemetry or remote fallback. Pane text is redacted, stripped of terminal escapes and treated as untrusted data; a cut-off or malformed answer is never returned as a summary.
- FIX: Pane summaries accept only the expected leading assistant header and whole enclosing JSON markdown fence before strict JSON/body/line validation. Insufficient output stays insufficient; trailing garbage and malformed output are rejected. The failed pure-content native option is not used.
- FIX: Install and generation cancellation work with stock React Native AbortSignal without a global polyfill. A supplied cancellation reason is preserved; runtimes without reasons reject with a fixed-message AbortError, and cancelled storage checks never start a model download.
- NEW: Pin the official Qwen2.5-1.5B-Instruct Q4_K_M default candidate with exact revision, bytes, SHA-256, Apache-2.0 licence and native-asset fixture. Smol360M remains catalogued but is no longer offered after its realistic pane run returned insufficient output; no automatic model fallback.
- FIX: Encode insufficient summary lines as a literal empty array and string bounds in the pattern itself. Stock schema-to-grammar conversion ignores array bounds without
itemsand string length keywords alongsidepattern; real b10256 grammar counterfactuals now reject the exact native false-with-four-lines sample, without changing its meaning or coercing its flag. - FIX: Give rejected summary output its own truthful “The summary was not usable. Try again.” wording, distinct from runtime failure. The Expo demo shows raw completion receipts only with explicit probe opt-in in a development build, never in product UI.
npm: @byokit/infer@0.1.0
@byokit/decide 0.6.1
- Dependency update: pins @byokit/accounts 0.18.0.
- FIX: (from @byokit/accounts 0.18.0) The README no longer claims browsers can reach Claude's token endpoint directly; a web page sends it through the app's own server.
- FIX: (from @byokit/accounts 0.18.0) Discover every pinned provider and sign-in method with billing and platform readiness; qwen and MiniMax leave the default offer until their flows exist. Legacy provider IDs and explicit offer lists stay compatible.
npm: @byokit/decide@0.6.1
@byokit/browser 0.1.0
- Initial public Node kit for PNG screenshots through an installed Chromium or Chrome, with private temporary profiles, explicit browser selection, and offline fakes.
npm: @byokit/browser@0.1.0
@byokit/audio 0.1.0
- Initial public
@byokit/audio: shared on-device audio detection with one streaming speech detector over a pinned, content-verified Silero VAD v5.1 graph (MIT). The kit owns the window framing, the recurrent state, the threshold, the hangover and the padding; the app supplies the inference session and the model bytes. No network, no keys, no microphone. @byokit/audio/noderuns that pinned graph on publishedonnxruntime-node, CPU only and one thread by default. Bytes that are not the pinned graph are rejected before any inference runs.
npm: @byokit/audio@0.1.0
@byokit/accounts 0.18.0
- Dependency update: pins @byokit/usage 0.7.0.
- The README points to the shared account-route vocabulary (D18); pinned discovery metadata does not imply additional implemented authentication flows.
- Name the Claude plan:
plan(member, 'claude')reads it once per sign-in from Claude's profile with the stored access, never refreshing it (an empty plan, never a failure, when it doesn't say);planLabelsays "ChatGPT Plus" or "Claude Max". The PWA and Expo examples sign in to Claude by its page and pasted code, show a connected card naming the plan, and stream an answer. - FIX: The README no longer claims browsers can reach Claude's token endpoint directly; a web page sends it through the app's own server.
- FIX: Discover every pinned provider and sign-in method with billing and platform readiness; qwen and MiniMax leave the default offer until their flows exist. Legacy provider IDs and explicit offer lists stay compatible.
npm: @byokit/accounts@0.18.0
@byokit/seal 0.3.0
@byokit/seal 0.3.0 (2026-10-02)
- Add a Swift notice opener for iOS Notification Service Extensions (
ios/Sources/ByokitSeal, CryptoKit only):ByokitSeal.openNoticeopenssealNoticeenvelopes with the same bytes and failures as the TypeScriptopenNotice, from an envelope or an Expo notification'suserInfo, andkeychainSecretreads the app's notice secret from one item in a shared keychain access group. Parity vectors are made by the TypeScript tests and opened by libsodium. - New: Ship ByokitSeal.openNotice for envelope and Expo userInfo input plus keychainSecret for one app-owned shared-group keychain item; the kit never stores notice keys.
- Fixed: No additional fixes in this release.
- Improved: Stock pinned Linux Swift 5.10.1 passes all 35 TypeScript-owned notice vectors and Expo userInfo extraction. Existing TypeScript formats and portable APIs remain unchanged.
- Known issues: Linux parity does not prove Apple SDK compilation, Security/keychain entitlements, an iOS Notification Service Extension or killed-app/device delivery. Apps must integrate and qualify their own NSE; platform delivery remains best-effort with generic-alert fallback. Lone UTF-16 surrogates open in TypeScript but are nil in Swift; seal well-formed text.
npm: @byokit/seal@0.3.0
@byokit/relay 0.5.2
@byokit/relay 0.5.2 (2026-10-02)
- FIX: Pass optional
mutableContent,categoryIdanddataOnlyfromNotificationto Expo instead of dropping native delivery options: iOS alerts can be rewritten by the app's Notification Service Extension and show the app's category, and Android tokens get a data-only message with no visible title, body or sound. Expo subscriptions take an optionalplatform('ios'or'android'); only Android tokens get data-only messages, so older subscriptions keep the visible alert. - New: Optional Expo subscription platform tags distinguish Android data-only delivery from iOS and older visible subscriptions.
- Fixed: Native delivery options are retained as described above; omitted options keep the existing visible Expo message unchanged.
- Improved: Explicit false mutableContent survives forwarding; contentFreeNotify strips native options and content, and includeContent remains opt-in. Web Push is unchanged.
- Known issues: Data-only delivery is best-effort under Android Doze and force-stop. iOS SDK, keychain entitlements, NSE and killed-app/device delivery are not qualified; mutableContent alone does not install an extension. categoryId currently uses the documented conservative 64-character syntax.
npm: @byokit/relay@0.5.2
@byokit/openclaw 0.5.1
@byokit/openclaw 0.5.1
Install: npm install @byokit/openclaw@0.5.1
Fixed
- FIX: ChatGPT sign-in now interrupts abandoned wizard/paste waits on gateway disconnect and reconfirms a new, usable OAuth profile for the selected member through the reconnected engine. Recovery is bounded and fails closed for unknown, missing, pre-existing or unrelated credentials, cancellation and expiry. A synchronous cleanup error during reconnect no longer suppresses the terminal sign-in view.
Improved
- The README points to the shared account-route vocabulary (D18); the frozen release's route table is unchanged.
New
- No new provider/authentication flows or later browser/managed-Pi/usage features in this frozen patch.
Known limits
- Reconfirmation requires a NEW usable selected-member ChatGPT OAuth profile ID; re-login to an existing profile fails closed. Unknown, missing, unrelated, expired or API-key profiles are not success; cancellation remains cancellation.
- Historical desktop-hang cause remains unknown. Consumer desktop retest, real-provider authentication, native working-step/Pi readiness and later browser/W7 production protection are not qualified by this release.
- The installed-public SDK proof uses an isolated credential-free HOME, offline fake Gateway and synthetic profile/reconnect cases; it is not live account or consumer adoption proof. Its first fixture timeout is retained and traced to waiting for a view that text steps do not emit; corrected RPC-step readiness succeeds.
- Later landed source/features and planned Accounts0.19/Herdr0.7/OpenClaw0.6 cohorts are not included in0.5.1 and need an independent actual-source cut and artifact qualification.
- Local publication has no OIDC provenance claim; source linkage is the frozen source/gate receipts and exact public tar/every-file identity, not optional registry gitHead metadata.
Qualified source and artifacts
Frozen source: a83760844c6d83151be996771f73584f8015dce6 (source #251; preparation #255).
Exact-main CI36963595008:14/14; mandatory local1645pass/26skip/0fail,22/22pack smoke, all22 original/final packs equal.
One original PUT returned404; one explicitly authorized frozen-tar resubmission succeeded. No blind retry or additional helper/login/default npm config mutation.
Public tar SHA256: 00280d6b5c19451aad8dab1bb5c4d07f030ae950beea362780e022b018dd1e5c.
SHA1: ebcee97717c75cc2d54c5ff7a134a1ecfa1b4c70.
SRI: sha512-rlm/vnf3mqBfqrDLQ3KRABY9iBCLzdObX1lTjEWCzj0z7MKEjzstZO6cWduEFo/WqPamx8Vqp/hwQNFa15DB9w==.
All76file contents/type/mode/link and runtime pins match the qualified frozen pack; shipped dist recovery checked. Fresh installed package lock SRI and all76 installed files match that same public tar. Previous0.5.0 public bytes remain unchanged.
Registry: https://registry.npmjs.org/@byokit%2fopenclaw/0.5.1
Tar: https://registry.npmjs.org/@byokit/openclaw/-/openclaw-0.5.1.tgz
npm: https://www.npmjs.com/package/@byokit/openclaw/v/0.5.1